{
  "schema": "sosec.july-2026-cve-census.v1",
  "edition": "2026-07",
  "evidence_cutoff": "2026-08-05T00:00:00+08:00",
  "purpose": "A complete CVE Program datePublished census for July 2026 with one bounded cause review per active record. Inclusion is a disclosure-cohort fact, not proof of exposure, exploitability, or patch priority.",
  "scope": {
    "cveProgramDatePublishedStart": "2026-07-01T00:00:00+00:00",
    "cveProgramDatePublishedEndExclusive": "2026-08-01T00:00:00+00:00",
    "corpusCount": 9808,
    "activeCount": 9763,
    "rejectedCount": 45,
    "nvdJulyExcludedCount": 111,
    "cvelistSnapshotCommit": "a373dbeddf97334f61e32d748cc24096303612ab"
  },
  "evidence_receipts": {
    "nvd": [
      {
        "file": "nvd-00000.json",
        "timestamp": "2026-08-04T16:13:48.176",
        "startIndex": 0,
        "count": 2000,
        "bytes": 7674554,
        "sha256": "82bdce58a78192a8091c65e760ad87780bd0bbcc23d6aeb337a37dff08245ad4"
      },
      {
        "file": "nvd-02000.json",
        "timestamp": "2026-08-04T16:14:17.252",
        "startIndex": 2000,
        "count": 2000,
        "bytes": 8775776,
        "sha256": "1ffdde1e961ee49226e4fc1af795f19cbd3e46cff96bed3f7bad67fa7b99e05f"
      },
      {
        "file": "nvd-04000.json",
        "timestamp": "2026-08-04T16:15:45.459",
        "startIndex": 4000,
        "count": 2000,
        "bytes": 6688441,
        "sha256": "861763af1836d1676f660feb35a27649ddda72254c3fc4feb5849ee5b217d5f8"
      },
      {
        "file": "nvd-06000.json",
        "timestamp": "2026-08-04T16:16:52.553",
        "startIndex": 6000,
        "count": 2000,
        "bytes": 5741981,
        "sha256": "1e56d1ed25e0c6a9435378a4364b809d36c63fb47c328d4562d6fe12ea52cd26"
      },
      {
        "file": "nvd-08000.json",
        "timestamp": "2026-08-04T16:17:17.935",
        "startIndex": 8000,
        "count": 1919,
        "bytes": 5129856,
        "sha256": "e4dcddc3bd06874d199f2cd3e31ff8dbea2f35eef63913f867b85134123b1299"
      }
    ],
    "cwe": {
      "version": "4.20",
      "date": "2026-04-30",
      "entryCount": 969,
      "archiveBytes": 2021351,
      "archiveSha256": "3976f599e5e5200219a3108bb896d06e2a88fbb293369e1883cb423a5e9d7d50",
      "member": "cwec_v4.20.xml",
      "memberSha256": "1f5a78bd62e00f86436b4fe32d5034a57e8f0da88e4063b2072b664ae510912e"
    },
    "epss": {
      "header": "#model_version:v2026.06.15,score_date:2026-08-04T12:00:14Z",
      "scoreCount": 355094,
      "bytes": 2511575,
      "sha256": "6bb2c86d54ac209b1a8e717370e88bf54b198a8ce6e0c8313804c7bf6fbb158a"
    },
    "cisaKev": {
      "catalogVersion": "2026.08.03",
      "dateReleased": "2026-08-03T18:55:09.067Z",
      "count": 1657,
      "parsedCount": 1657,
      "bytes": 1569586,
      "sha256": "16acee8334e59e44ccbaed4da7d02b409144061542b64ad74a9443fb7842a828"
    },
    "nvdSources": {
      "timestamp": "2026-08-04T16:27:32.667",
      "sourceCount": 496,
      "identifierCount": 799,
      "bytes": 168587,
      "sha256": "7c6411b0a26f82d6f251472ca2612bee02b8879639ee39441181ff94606dbb1c"
    }
  },
  "method": {
    "cohort_definition": "Records whose CVE Program cveMetadata.datePublished is at or after 2026-07-01T00:00:00Z and before 2026-08-01T00:00:00Z in cvelistV5 commit a373dbeddf97334f61e32d748cc24096303612ab. Current rejection state is retained.",
    "nvd_comparison": "The NVD API pubStartDate/pubEndDate result is a separate added-to-NVD cohort used for enrichment and boundary comparison; it does not redefine the CVE Program month.",
    "cause_rule": "The review selects the earliest engineering failure supported by public evidence, records one primary family, and marks UNDETERMINED when only impact or a broad label is public. No exploit reproduction is implied.",
    "cause_families": {
      "AUTHORITY_BINDING": "Identity, role, ownership, tenant scope, privilege, object, or action is bound incorrectly.",
      "CONFIG_UPDATE_DEPENDENCY": "An insecure default, permission, debug path, load path, dependency, build, package, update, or deployment control creates exposure.",
      "CRYPTO_SECRET": "A credential, signature, certificate, key, nonce, password, token, randomness, encryption, rotation, or revocation rule fails.",
      "EXPOSURE_OUTPUT": "Protected data reaches a response, log, cache, object, side channel, or observer without the required disclosure boundary.",
      "FILE_OBJECT_SELECTION": "Attacker-controlled path, name, archive member, link, upload, device, or object escapes the intended namespace.",
      "HARDWARE_PHYSICAL": "Hardware design, microarchitectural state, a physical interface, fault condition, or side channel is the enabling cause.",
      "INTERPRETER_BOUNDARY": "Untrusted data crosses into SQL, shell, code, markup, template, serialization, or another interpreted grammar.",
      "MEMORY_LIFETIME": "A bounds, size, type, initialization, ownership, reference, or lifetime invariant fails before memory access.",
      "OTHER_SPECIFIC": "The public record gives a concrete engineering cause outside the other families.",
      "REQUEST_CHANNEL_TRUST": "A host, origin, redirect, request boundary, DNS result, upstream response, or cross-domain channel is trusted incorrectly.",
      "RESOURCE_CONTROL": "Finite work, memory, recursion, queue, connection, descriptor, retry, or lifetime lacks an effective bound or release.",
      "STATE_SEQUENCE": "A race, stale state, replay, cancellation, workflow order, or lifecycle transition breaks a multi-step invariant.",
      "UNDETERMINED": "The public material does not support an engineering cause beyond impact or broad marketing language."
    },
    "precision_levels": {
      "BROAD_RECORD": "The public material supports only the cause family, not the failing check, parser, state transition, or memory operation.",
      "DESCRIPTION_SPECIFIC": "The prose states a concrete mechanism while structured CWE data is absent, too abstract, discouraged, or mismatched.",
      "SOURCE_TRACED": "An official advisory and public source or patch expose the causal check, transition, or lifetime error.",
      "SPECIFIC_RECORD": "The record contains an allowed Base or Variant CWE and prose supporting that exact mechanism.",
      "UNDETERMINED": "The public material cannot support a cause classification."
    },
    "score_roles": {
      "CISA_KEV": "Catalog evidence that exploitation is known; asset match, affected configuration, vendor repair, and incident review still determine the local action.",
      "CVSS": "Technical severity under the named source's vector and version; source-attributed rows are preserved.",
      "EPSS": "Probability estimate from the named model snapshot; useful for ordering, not an exposure or exploitation finding."
    },
    "limitations": [
      "The census exhausts the named public corpus and snapshots, not private vendor cases, embargoed patches, telemetry, or every later record update.",
      "A CVE is a record identifier. Shared advisories, duplicate prose, delayed assignment, rejection, and batch publication mean record count is not a count of independent root causes, patches, products, or exposed assets.",
      "Broad and undetermined reviews preserve public uncertainty; they must not be promoted to source-level root-cause claims.",
      "Raw descriptions are omitted from this public ledger to avoid duplicating exploit-oriented text. Pinned source references remain attached to each active record."
    ]
  },
  "counts": {
    "all_records": 9808,
    "active_records": 9763,
    "rejected_records": 45,
    "reviewed_active_records": 9763,
    "cause_undetermined": 283,
    "primary_source_deep_dives": 376
  },
  "aggregates": {
    "cause_families": [
      {
        "name": "AUTHORITY_BINDING",
        "count": 2449
      },
      {
        "name": "MEMORY_LIFETIME",
        "count": 1817
      },
      {
        "name": "INTERPRETER_BOUNDARY",
        "count": 1770
      },
      {
        "name": "REQUEST_CHANNEL_TRUST",
        "count": 761
      },
      {
        "name": "RESOURCE_CONTROL",
        "count": 607
      },
      {
        "name": "FILE_OBJECT_SELECTION",
        "count": 589
      },
      {
        "name": "STATE_SEQUENCE",
        "count": 477
      },
      {
        "name": "CRYPTO_SECRET",
        "count": 310
      },
      {
        "name": "EXPOSURE_OUTPUT",
        "count": 308
      },
      {
        "name": "UNDETERMINED",
        "count": 283
      },
      {
        "name": "OTHER_SPECIFIC",
        "count": 184
      },
      {
        "name": "CONFIG_UPDATE_DEPENDENCY",
        "count": 181
      },
      {
        "name": "HARDWARE_PHYSICAL",
        "count": 27
      }
    ],
    "precision_levels": [
      {
        "name": "SPECIFIC_RECORD",
        "count": 5084
      },
      {
        "name": "DESCRIPTION_SPECIFIC",
        "count": 2573
      },
      {
        "name": "BROAD_RECORD",
        "count": 1808
      },
      {
        "name": "UNDETERMINED",
        "count": 283
      },
      {
        "name": "SOURCE_TRACED",
        "count": 15
      }
    ],
    "confidence_levels": [
      {
        "name": "high",
        "count": 7291
      },
      {
        "name": "medium",
        "count": 2151
      },
      {
        "name": "low",
        "count": 321
      }
    ],
    "publishers": [
      {
        "name": "GitHub_M",
        "count": 1298
      },
      {
        "name": "oracle",
        "count": 1108
      },
      {
        "name": "Linux",
        "count": 837
      },
      {
        "name": "VulnCheck",
        "count": 705
      },
      {
        "name": "microsoft",
        "count": 648
      },
      {
        "name": "Chrome",
        "count": 487
      },
      {
        "name": "Patchstack",
        "count": 481
      },
      {
        "name": "Wordfence",
        "count": 454
      },
      {
        "name": "VulDB",
        "count": 440
      },
      {
        "name": "mitre",
        "count": 299
      },
      {
        "name": "WPScan",
        "count": 222
      },
      {
        "name": "apache",
        "count": 181
      },
      {
        "name": "apple",
        "count": 168
      },
      {
        "name": "redhat",
        "count": 164
      },
      {
        "name": "adobe",
        "count": 107
      },
      {
        "name": "Joomla",
        "count": 106
      },
      {
        "name": "ibm",
        "count": 105
      },
      {
        "name": "CPANSec",
        "count": 77
      },
      {
        "name": "mozilla",
        "count": 71
      },
      {
        "name": "TR-CERT",
        "count": 68
      },
      {
        "name": "HCL",
        "count": 60
      },
      {
        "name": "icscert",
        "count": 57
      },
      {
        "name": "CERT-PL",
        "count": 53
      },
      {
        "name": "drupal",
        "count": 46
      },
      {
        "name": "dell",
        "count": 43
      },
      {
        "name": "nvidia",
        "count": 43
      },
      {
        "name": "Gitea",
        "count": 40
      },
      {
        "name": "certcc",
        "count": 39
      },
      {
        "name": "hackerone",
        "count": 39
      },
      {
        "name": "EEF",
        "count": 38
      },
      {
        "name": "GitLab",
        "count": 35
      },
      {
        "name": "ProgressSoftware",
        "count": 33
      },
      {
        "name": "CERTVDE",
        "count": 31
      },
      {
        "name": "XEN",
        "count": 29
      },
      {
        "name": "Foxit",
        "count": 28
      },
      {
        "name": "elastic",
        "count": 28
      },
      {
        "name": "zephyr",
        "count": 28
      },
      {
        "name": "JetBrains",
        "count": 27
      },
      {
        "name": "vmware",
        "count": 27
      },
      {
        "name": "mongodb",
        "count": 26
      },
      {
        "name": "CSA",
        "count": 25
      },
      {
        "name": "wikimedia-foundation",
        "count": 25
      },
      {
        "name": "NLnet Labs",
        "count": 24
      },
      {
        "name": "zdi",
        "count": 23
      },
      {
        "name": "AMZN",
        "count": 22
      },
      {
        "name": "juniper",
        "count": 22
      },
      {
        "name": "eclipse",
        "count": 21
      },
      {
        "name": "suse",
        "count": 20
      },
      {
        "name": "GV",
        "count": 19
      },
      {
        "name": "Rockwell",
        "count": 19
      },
      {
        "name": "SamsungMobile",
        "count": 19
      },
      {
        "name": "cisco",
        "count": 19
      },
      {
        "name": "openjs",
        "count": 19
      },
      {
        "name": "CIRCL",
        "count": 18
      },
      {
        "name": "curl",
        "count": 18
      },
      {
        "name": "WatchGuard",
        "count": 17
      },
      {
        "name": "JFROG",
        "count": 16
      },
      {
        "name": "SolarWinds",
        "count": 16
      },
      {
        "name": "sap",
        "count": 16
      },
      {
        "name": "Mattermost",
        "count": 15
      },
      {
        "name": "DEVOLUTIONS",
        "count": 14
      },
      {
        "name": "INCIBE",
        "count": 14
      },
      {
        "name": "palo_alto",
        "count": 14
      },
      {
        "name": "ASUS",
        "count": 13
      },
      {
        "name": "NCSC.ch",
        "count": 13
      },
      {
        "name": "Absolute",
        "count": 12
      },
      {
        "name": "CyberDanube",
        "count": 12
      },
      {
        "name": "HashiCorp",
        "count": 12
      },
      {
        "name": "fortinet",
        "count": 12
      },
      {
        "name": "jpcert",
        "count": 12
      },
      {
        "name": "cisa-cg",
        "count": 11
      },
      {
        "name": "huawei",
        "count": 11
      },
      {
        "name": "qualcomm",
        "count": 11
      },
      {
        "name": "securin",
        "count": 11
      },
      {
        "name": "@huntr_ai",
        "count": 10
      },
      {
        "name": "DIVD",
        "count": 10
      },
      {
        "name": "TPLink",
        "count": 10
      },
      {
        "name": "twcert",
        "count": 10
      },
      {
        "name": "Google",
        "count": 9
      },
      {
        "name": "Secur0",
        "count": 9
      },
      {
        "name": "imaginationtech",
        "count": 9
      },
      {
        "name": "isc",
        "count": 9
      },
      {
        "name": "lenovo",
        "count": 9
      },
      {
        "name": "ASUSTOR1",
        "count": 8
      },
      {
        "name": "GRAFANA",
        "count": 8
      },
      {
        "name": "OpenVPN",
        "count": 8
      },
      {
        "name": "PostgreSQL",
        "count": 8
      },
      {
        "name": "f5",
        "count": 8
      },
      {
        "name": "MediaTek",
        "count": 7
      },
      {
        "name": "Nozomi",
        "count": 7
      },
      {
        "name": "SRA",
        "count": 7
      },
      {
        "name": "canonical",
        "count": 7
      },
      {
        "name": "jci",
        "count": 7
      },
      {
        "name": "runZero",
        "count": 7
      },
      {
        "name": "sba-research",
        "count": 7
      },
      {
        "name": "siemens",
        "count": 7
      },
      {
        "name": "tenable",
        "count": 7
      },
      {
        "name": "NETGEAR",
        "count": 6
      },
      {
        "name": "SNOWFLAKE",
        "count": 6
      },
      {
        "name": "TML",
        "count": 6
      },
      {
        "name": "blackberry",
        "count": 6
      },
      {
        "name": "hikvision",
        "count": 6
      },
      {
        "name": "hpe",
        "count": 6
      },
      {
        "name": "samsung.tv_appliance",
        "count": 6
      },
      {
        "name": "Deltaww",
        "count": 5
      },
      {
        "name": "Docker",
        "count": 5
      },
      {
        "name": "ERIC",
        "count": 5
      },
      {
        "name": "Sonatype",
        "count": 5
      },
      {
        "name": "WSO2",
        "count": 5
      },
      {
        "name": "airbus",
        "count": 5
      },
      {
        "name": "3DS",
        "count": 4
      },
      {
        "name": "BT",
        "count": 4
      },
      {
        "name": "EDB",
        "count": 4
      },
      {
        "name": "ESET",
        "count": 4
      },
      {
        "name": "Esri",
        "count": 4
      },
      {
        "name": "GitHub_P",
        "count": 4
      },
      {
        "name": "Go",
        "count": 4
      },
      {
        "name": "GoogleCloud",
        "count": 4
      },
      {
        "name": "TQtC",
        "count": 4
      },
      {
        "name": "Tanium",
        "count": 4
      },
      {
        "name": "Zoom",
        "count": 4
      },
      {
        "name": "php",
        "count": 4
      },
      {
        "name": "rami.io",
        "count": 4
      },
      {
        "name": "ABB",
        "count": 3
      },
      {
        "name": "Arista",
        "count": 3
      },
      {
        "name": "Checkmk",
        "count": 3
      },
      {
        "name": "Ciena",
        "count": 3
      },
      {
        "name": "DSF",
        "count": 3
      },
      {
        "name": "Eaton",
        "count": 3
      },
      {
        "name": "Gallagher",
        "count": 3
      },
      {
        "name": "HDFG",
        "count": 3
      },
      {
        "name": "Kong",
        "count": 3
      },
      {
        "name": "OX",
        "count": 3
      },
      {
        "name": "PRJBLK",
        "count": 3
      },
      {
        "name": "PSF",
        "count": 3
      },
      {
        "name": "Tigera",
        "count": 3
      },
      {
        "name": "Zohocorp",
        "count": 3
      },
      {
        "name": "atlassian",
        "count": 3
      },
      {
        "name": "autodesk",
        "count": 3
      },
      {
        "name": "bosch",
        "count": 3
      },
      {
        "name": "checkpoint",
        "count": 3
      },
      {
        "name": "cloudflare",
        "count": 3
      },
      {
        "name": "hp",
        "count": 3
      },
      {
        "name": "libreswan",
        "count": 3
      },
      {
        "name": "schneider",
        "count": 3
      },
      {
        "name": "snyk",
        "count": 3
      },
      {
        "name": "BLSOPS",
        "count": 2
      },
      {
        "name": "BlackDuck",
        "count": 2
      },
      {
        "name": "BombadilSystems",
        "count": 2
      },
      {
        "name": "CERT-In",
        "count": 2
      },
      {
        "name": "Citrix",
        "count": 2
      },
      {
        "name": "Cribl",
        "count": 2
      },
      {
        "name": "Digi",
        "count": 2
      },
      {
        "name": "ENISA",
        "count": 2
      },
      {
        "name": "ExtremeNetworks",
        "count": 2
      },
      {
        "name": "FTI",
        "count": 2
      },
      {
        "name": "Fluid Attacks",
        "count": 2
      },
      {
        "name": "Honeywell",
        "count": 2
      },
      {
        "name": "Meta",
        "count": 2
      },
      {
        "name": "Pega",
        "count": 2
      },
      {
        "name": "Perforce",
        "count": 2
      },
      {
        "name": "alibaba",
        "count": 2
      },
      {
        "name": "arcinfo",
        "count": 2
      },
      {
        "name": "bcorg",
        "count": 2
      },
      {
        "name": "bizerba",
        "count": 2
      },
      {
        "name": "illumos",
        "count": 2
      },
      {
        "name": "ivanti",
        "count": 2
      },
      {
        "name": "seal",
        "count": 2
      },
      {
        "name": "sonicwall",
        "count": 2
      },
      {
        "name": "symantec",
        "count": 2
      },
      {
        "name": "Altium",
        "count": 1
      },
      {
        "name": "Bitdefender",
        "count": 1
      },
      {
        "name": "Caliptra",
        "count": 1
      },
      {
        "name": "Canon_EMEA",
        "count": 1
      },
      {
        "name": "Cato",
        "count": 1
      },
      {
        "name": "Centreon",
        "count": 1
      },
      {
        "name": "Genetec",
        "count": 1
      },
      {
        "name": "LGE",
        "count": 1
      },
      {
        "name": "Milestone",
        "count": 1
      },
      {
        "name": "Mitsubishi",
        "count": 1
      },
      {
        "name": "OAI",
        "count": 1
      },
      {
        "name": "Octopus",
        "count": 1
      },
      {
        "name": "Omnissa",
        "count": 1
      },
      {
        "name": "SICK AG",
        "count": 1
      },
      {
        "name": "SN",
        "count": 1
      },
      {
        "name": "SailPoint",
        "count": 1
      },
      {
        "name": "Silabs",
        "count": 1
      },
      {
        "name": "Spotfire",
        "count": 1
      },
      {
        "name": "Supermicro",
        "count": 1
      },
      {
        "name": "TCS-CERT",
        "count": 1
      },
      {
        "name": "THA-PSIRT",
        "count": 1
      },
      {
        "name": "TV",
        "count": 1
      },
      {
        "name": "TXOne",
        "count": 1
      },
      {
        "name": "TYPO3",
        "count": 1
      },
      {
        "name": "ThinkstAppliedResearch",
        "count": 1
      },
      {
        "name": "Toreon",
        "count": 1
      },
      {
        "name": "Unisoc",
        "count": 1
      },
      {
        "name": "ZUSO ART",
        "count": 1
      },
      {
        "name": "Zyxel",
        "count": 1
      },
      {
        "name": "dotCMS",
        "count": 1
      },
      {
        "name": "fedora",
        "count": 1
      },
      {
        "name": "harborist",
        "count": 1
      },
      {
        "name": "kubernetes",
        "count": 1
      },
      {
        "name": "netapp",
        "count": 1
      },
      {
        "name": "rapid7",
        "count": 1
      },
      {
        "name": "redhat-cnalr",
        "count": 1
      },
      {
        "name": "trellix",
        "count": 1
      },
      {
        "name": "zte",
        "count": 1
      }
    ],
    "id_years": [
      {
        "name": "2026",
        "count": 9572
      },
      {
        "name": "2025",
        "count": 161
      },
      {
        "name": "2024",
        "count": 57
      },
      {
        "name": "2021",
        "count": 6
      },
      {
        "name": "2023",
        "count": 5
      },
      {
        "name": "2022",
        "count": 4
      },
      {
        "name": "2011",
        "count": 1
      },
      {
        "name": "2016",
        "count": 1
      },
      {
        "name": "2019",
        "count": 1
      }
    ],
    "publication_days": [
      {
        "date": "2026-07-01",
        "count": 365
      },
      {
        "date": "2026-07-02",
        "count": 266
      },
      {
        "date": "2026-07-03",
        "count": 180
      },
      {
        "date": "2026-07-04",
        "count": 72
      },
      {
        "date": "2026-07-05",
        "count": 87
      },
      {
        "date": "2026-07-06",
        "count": 196
      },
      {
        "date": "2026-07-07",
        "count": 166
      },
      {
        "date": "2026-07-08",
        "count": 364
      },
      {
        "date": "2026-07-09",
        "count": 277
      },
      {
        "date": "2026-07-10",
        "count": 348
      },
      {
        "date": "2026-07-11",
        "count": 79
      },
      {
        "date": "2026-07-12",
        "count": 63
      },
      {
        "date": "2026-07-13",
        "count": 336
      },
      {
        "date": "2026-07-14",
        "count": 1007
      },
      {
        "date": "2026-07-15",
        "count": 269
      },
      {
        "date": "2026-07-16",
        "count": 247
      },
      {
        "date": "2026-07-17",
        "count": 290
      },
      {
        "date": "2026-07-18",
        "count": 81
      },
      {
        "date": "2026-07-19",
        "count": 466
      },
      {
        "date": "2026-07-20",
        "count": 270
      },
      {
        "date": "2026-07-21",
        "count": 1474
      },
      {
        "date": "2026-07-22",
        "count": 200
      },
      {
        "date": "2026-07-23",
        "count": 377
      },
      {
        "date": "2026-07-24",
        "count": 192
      },
      {
        "date": "2026-07-25",
        "count": 284
      },
      {
        "date": "2026-07-26",
        "count": 15
      },
      {
        "date": "2026-07-27",
        "count": 449
      },
      {
        "date": "2026-07-28",
        "count": 259
      },
      {
        "date": "2026-07-29",
        "count": 275
      },
      {
        "date": "2026-07-30",
        "count": 669
      },
      {
        "date": "2026-07-31",
        "count": 185
      }
    ],
    "top_publisher_day_batches": [
      {
        "date": "2026-07-21",
        "publisher": "oracle",
        "records": 1097,
        "unique_products": 262,
        "unique_references": 1,
        "top_cwes": [
          {
            "name": "CWE-284",
            "count": 678
          },
          {
            "name": "CWE-306",
            "count": 252
          },
          {
            "name": "CWE-269",
            "count": 125
          },
          {
            "name": "CWE-200",
            "count": 110
          },
          {
            "name": "CWE-287",
            "count": 72
          }
        ]
      },
      {
        "date": "2026-07-14",
        "publisher": "microsoft",
        "records": 570,
        "unique_products": 104,
        "unique_references": 576,
        "top_cwes": [
          {
            "name": "CWE-416",
            "count": 131
          },
          {
            "name": "CWE-122",
            "count": 111
          },
          {
            "name": "CWE-125",
            "count": 56
          },
          {
            "name": "CWE-362",
            "count": 56
          },
          {
            "name": "CWE-200",
            "count": 29
          }
        ]
      },
      {
        "date": "2026-07-19",
        "publisher": "Linux",
        "records": 431,
        "unique_products": 1,
        "unique_references": 2276,
        "top_cwes": [
          {
            "name": "CWE-416",
            "count": 13
          },
          {
            "name": "CWE-476",
            "count": 7
          },
          {
            "name": "CWE-125",
            "count": 5
          },
          {
            "name": "CWE-401",
            "count": 5
          },
          {
            "name": "CWE-129",
            "count": 2
          }
        ]
      },
      {
        "date": "2026-07-30",
        "publisher": "Chrome",
        "records": 370,
        "unique_products": 1,
        "unique_references": 371,
        "top_cwes": [
          {
            "name": "CWE-20",
            "count": 74
          },
          {
            "name": "CWE-346",
            "count": 63
          },
          {
            "name": "CWE-416",
            "count": 51
          },
          {
            "name": "CWE-451",
            "count": 33
          },
          {
            "name": "CWE-693",
            "count": 20
          }
        ]
      },
      {
        "date": "2026-07-25",
        "publisher": "Linux",
        "records": 274,
        "unique_products": 1,
        "unique_references": 1572,
        "top_cwes": []
      },
      {
        "date": "2026-07-27",
        "publisher": "apple",
        "records": 164,
        "unique_products": 6,
        "unique_references": 11,
        "top_cwes": [
          {
            "name": "CWE-119",
            "count": 23
          },
          {
            "name": "CWE-200",
            "count": 18
          },
          {
            "name": "CWE-787",
            "count": 17
          },
          {
            "name": "CWE-125",
            "count": 13
          },
          {
            "name": "CWE-416",
            "count": 13
          }
        ]
      },
      {
        "date": "2026-07-23",
        "publisher": "Patchstack",
        "records": 156,
        "unique_products": 129,
        "unique_references": 156,
        "top_cwes": [
          {
            "name": "CWE-862",
            "count": 47
          },
          {
            "name": "CWE-79",
            "count": 44
          },
          {
            "name": "CWE-89",
            "count": 15
          },
          {
            "name": "CWE-352",
            "count": 13
          },
          {
            "name": "CWE-497",
            "count": 8
          }
        ]
      },
      {
        "date": "2026-07-13",
        "publisher": "Patchstack",
        "records": 149,
        "unique_products": 136,
        "unique_references": 149,
        "top_cwes": [
          {
            "name": "CWE-79",
            "count": 51
          },
          {
            "name": "CWE-862",
            "count": 33
          },
          {
            "name": "CWE-98",
            "count": 18
          },
          {
            "name": "CWE-89",
            "count": 13
          },
          {
            "name": "CWE-502",
            "count": 8
          }
        ]
      },
      {
        "date": "2026-07-08",
        "publisher": "GitHub_M",
        "records": 126,
        "unique_products": 53,
        "unique_references": 434,
        "top_cwes": [
          {
            "name": "CWE-22",
            "count": 13
          },
          {
            "name": "CWE-407",
            "count": 11
          },
          {
            "name": "CWE-79",
            "count": 10
          },
          {
            "name": "CWE-863",
            "count": 9
          },
          {
            "name": "CWE-345",
            "count": 5
          }
        ]
      },
      {
        "date": "2026-07-15",
        "publisher": "GitHub_M",
        "records": 115,
        "unique_products": 50,
        "unique_references": 322,
        "top_cwes": [
          {
            "name": "CWE-287",
            "count": 12
          },
          {
            "name": "CWE-862",
            "count": 11
          },
          {
            "name": "CWE-863",
            "count": 11
          },
          {
            "name": "CWE-79",
            "count": 9
          },
          {
            "name": "CWE-639",
            "count": 8
          }
        ]
      },
      {
        "date": "2026-07-10",
        "publisher": "GitHub_M",
        "records": 114,
        "unique_products": 35,
        "unique_references": 388,
        "top_cwes": [
          {
            "name": "CWE-79",
            "count": 11
          },
          {
            "name": "CWE-863",
            "count": 11
          },
          {
            "name": "CWE-918",
            "count": 9
          },
          {
            "name": "CWE-862",
            "count": 8
          },
          {
            "name": "CWE-639",
            "count": 7
          }
        ]
      },
      {
        "date": "2026-07-20",
        "publisher": "GitHub_M",
        "records": 99,
        "unique_products": 40,
        "unique_references": 158,
        "top_cwes": [
          {
            "name": "CWE-22",
            "count": 11
          },
          {
            "name": "CWE-79",
            "count": 9
          },
          {
            "name": "CWE-862",
            "count": 7
          },
          {
            "name": "CWE-285",
            "count": 6
          },
          {
            "name": "CWE-287",
            "count": 6
          }
        ]
      },
      {
        "date": "2026-07-14",
        "publisher": "GitHub_M",
        "records": 98,
        "unique_products": 46,
        "unique_references": 284,
        "top_cwes": [
          {
            "name": "CWE-79",
            "count": 12
          },
          {
            "name": "CWE-400",
            "count": 10
          },
          {
            "name": "CWE-693",
            "count": 10
          },
          {
            "name": "CWE-863",
            "count": 9
          },
          {
            "name": "CWE-1333",
            "count": 6
          }
        ]
      },
      {
        "date": "2026-07-02",
        "publisher": "Patchstack",
        "records": 97,
        "unique_products": 91,
        "unique_references": 97,
        "top_cwes": [
          {
            "name": "CWE-79",
            "count": 44
          },
          {
            "name": "CWE-862",
            "count": 15
          },
          {
            "name": "CWE-352",
            "count": 8
          },
          {
            "name": "CWE-89",
            "count": 7
          },
          {
            "name": "CWE-98",
            "count": 6
          }
        ]
      },
      {
        "date": "2026-07-16",
        "publisher": "GitHub_M",
        "records": 94,
        "unique_products": 40,
        "unique_references": 255,
        "top_cwes": [
          {
            "name": "CWE-22",
            "count": 14
          },
          {
            "name": "CWE-94",
            "count": 11
          },
          {
            "name": "CWE-862",
            "count": 10
          },
          {
            "name": "CWE-400",
            "count": 7
          },
          {
            "name": "CWE-20",
            "count": 5
          }
        ]
      },
      {
        "date": "2026-07-14",
        "publisher": "adobe",
        "records": 88,
        "unique_products": 22,
        "unique_references": 12,
        "top_cwes": [
          {
            "name": "CWE-787",
            "count": 18
          },
          {
            "name": "CWE-79",
            "count": 14
          },
          {
            "name": "CWE-20",
            "count": 9
          },
          {
            "name": "CWE-863",
            "count": 9
          },
          {
            "name": "CWE-22",
            "count": 5
          }
        ]
      },
      {
        "date": "2026-07-09",
        "publisher": "GitHub_M",
        "records": 78,
        "unique_products": 23,
        "unique_references": 258,
        "top_cwes": [
          {
            "name": "CWE-862",
            "count": 11
          },
          {
            "name": "CWE-200",
            "count": 8
          },
          {
            "name": "CWE-22",
            "count": 6
          },
          {
            "name": "CWE-79",
            "count": 6
          },
          {
            "name": "CWE-94",
            "count": 6
          }
        ]
      },
      {
        "date": "2026-07-17",
        "publisher": "GitHub_M",
        "records": 78,
        "unique_products": 53,
        "unique_references": 279,
        "top_cwes": [
          {
            "name": "CWE-770",
            "count": 15
          },
          {
            "name": "CWE-862",
            "count": 6
          },
          {
            "name": "CWE-400",
            "count": 5
          },
          {
            "name": "CWE-79",
            "count": 5
          },
          {
            "name": "CWE-918",
            "count": 4
          }
        ]
      },
      {
        "date": "2026-07-05",
        "publisher": "VulDB",
        "records": 74,
        "unique_products": 32,
        "unique_references": 405,
        "top_cwes": [
          {
            "name": "CWE-74",
            "count": 44
          },
          {
            "name": "CWE-89",
            "count": 41
          },
          {
            "name": "CWE-284",
            "count": 5
          },
          {
            "name": "CWE-285",
            "count": 5
          },
          {
            "name": "CWE-434",
            "count": 5
          }
        ]
      },
      {
        "date": "2026-07-06",
        "publisher": "GitHub_M",
        "records": 69,
        "unique_products": 18,
        "unique_references": 132,
        "top_cwes": [
          {
            "name": "CWE-78",
            "count": 8
          },
          {
            "name": "CWE-22",
            "count": 6
          },
          {
            "name": "CWE-918",
            "count": 5
          },
          {
            "name": "CWE-306",
            "count": 4
          },
          {
            "name": "CWE-59",
            "count": 4
          }
        ]
      },
      {
        "date": "2026-07-21",
        "publisher": "GitHub_M",
        "records": 66,
        "unique_products": 28,
        "unique_references": 120,
        "top_cwes": [
          {
            "name": "CWE-639",
            "count": 9
          },
          {
            "name": "CWE-862",
            "count": 9
          },
          {
            "name": "CWE-269",
            "count": 6
          },
          {
            "name": "CWE-22",
            "count": 5
          },
          {
            "name": "CWE-284",
            "count": 5
          }
        ]
      },
      {
        "date": "2026-07-21",
        "publisher": "mozilla",
        "records": 64,
        "unique_products": 2,
        "unique_references": 74,
        "top_cwes": [
          {
            "name": "CWE-119",
            "count": 11
          },
          {
            "name": "CWE-693",
            "count": 11
          },
          {
            "name": "CWE-200",
            "count": 8
          },
          {
            "name": "CWE-269",
            "count": 7
          },
          {
            "name": "CWE-346",
            "count": 7
          }
        ]
      },
      {
        "date": "2026-07-27",
        "publisher": "Patchstack",
        "records": 64,
        "unique_products": 61,
        "unique_references": 64,
        "top_cwes": [
          {
            "name": "CWE-79",
            "count": 23
          },
          {
            "name": "CWE-862",
            "count": 15
          },
          {
            "name": "CWE-89",
            "count": 8
          },
          {
            "name": "CWE-918",
            "count": 5
          },
          {
            "name": "CWE-497",
            "count": 4
          }
        ]
      },
      {
        "date": "2026-07-07",
        "publisher": "GitHub_M",
        "records": 62,
        "unique_products": 16,
        "unique_references": 172,
        "top_cwes": [
          {
            "name": "CWE-78",
            "count": 12
          },
          {
            "name": "CWE-639",
            "count": 6
          },
          {
            "name": "CWE-863",
            "count": 6
          },
          {
            "name": "CWE-285",
            "count": 4
          },
          {
            "name": "CWE-862",
            "count": 4
          }
        ]
      },
      {
        "date": "2026-07-23",
        "publisher": "VulnCheck",
        "records": 59,
        "unique_products": 25,
        "unique_references": 135,
        "top_cwes": [
          {
            "name": "CWE-79",
            "count": 18
          },
          {
            "name": "CWE-22",
            "count": 13
          },
          {
            "name": "CWE-787",
            "count": 4
          },
          {
            "name": "CWE-639",
            "count": 3
          },
          {
            "name": "CWE-131",
            "count": 2
          }
        ]
      },
      {
        "date": "2026-07-28",
        "publisher": "GitHub_M",
        "records": 56,
        "unique_products": 24,
        "unique_references": 147,
        "top_cwes": [
          {
            "name": "CWE-200",
            "count": 6
          },
          {
            "name": "CWE-22",
            "count": 6
          },
          {
            "name": "CWE-918",
            "count": 6
          },
          {
            "name": "CWE-94",
            "count": 6
          },
          {
            "name": "CWE-400",
            "count": 5
          }
        ]
      },
      {
        "date": "2026-07-20",
        "publisher": "VulnCheck",
        "records": 54,
        "unique_products": 18,
        "unique_references": 131,
        "top_cwes": [
          {
            "name": "CWE-918",
            "count": 8
          },
          {
            "name": "CWE-863",
            "count": 7
          },
          {
            "name": "CWE-639",
            "count": 3
          },
          {
            "name": "CWE-674",
            "count": 3
          },
          {
            "name": "CWE-862",
            "count": 3
          }
        ]
      },
      {
        "date": "2026-07-11",
        "publisher": "Wordfence",
        "records": 53,
        "unique_products": 49,
        "unique_references": 383,
        "top_cwes": [
          {
            "name": "CWE-79",
            "count": 15
          },
          {
            "name": "CWE-862",
            "count": 13
          },
          {
            "name": "CWE-89",
            "count": 6
          },
          {
            "name": "CWE-200",
            "count": 4
          },
          {
            "name": "CWE-22",
            "count": 2
          }
        ]
      },
      {
        "date": "2026-07-17",
        "publisher": "VulnCheck",
        "records": 53,
        "unique_products": 15,
        "unique_references": 116,
        "top_cwes": [
          {
            "name": "CWE-863",
            "count": 12
          },
          {
            "name": "CWE-862",
            "count": 8
          },
          {
            "name": "CWE-918",
            "count": 6
          },
          {
            "name": "CWE-639",
            "count": 4
          },
          {
            "name": "CWE-306",
            "count": 3
          }
        ]
      },
      {
        "date": "2026-07-01",
        "publisher": "Chrome",
        "records": 52,
        "unique_products": 1,
        "unique_references": 53,
        "top_cwes": [
          {
            "name": "CWE-416",
            "count": 11
          },
          {
            "name": "CWE-125",
            "count": 8
          },
          {
            "name": "CWE-20",
            "count": 7
          },
          {
            "name": "CWE-457",
            "count": 7
          },
          {
            "name": "CWE-787",
            "count": 7
          }
        ]
      },
      {
        "date": "2026-07-10",
        "publisher": "Wordfence",
        "records": 51,
        "unique_products": 49,
        "unique_references": 292,
        "top_cwes": [
          {
            "name": "CWE-79",
            "count": 16
          },
          {
            "name": "CWE-862",
            "count": 11
          },
          {
            "name": "CWE-89",
            "count": 8
          },
          {
            "name": "CWE-434",
            "count": 3
          },
          {
            "name": "CWE-352",
            "count": 2
          }
        ]
      },
      {
        "date": "2026-07-15",
        "publisher": "VulnCheck",
        "records": 50,
        "unique_products": 16,
        "unique_references": 116,
        "top_cwes": [
          {
            "name": "CWE-401",
            "count": 10
          },
          {
            "name": "CWE-20",
            "count": 3
          },
          {
            "name": "CWE-22",
            "count": 3
          },
          {
            "name": "CWE-287",
            "count": 3
          },
          {
            "name": "CWE-639",
            "count": 3
          }
        ]
      },
      {
        "date": "2026-07-31",
        "publisher": "GitHub_M",
        "records": 49,
        "unique_products": 24,
        "unique_references": 135,
        "top_cwes": [
          {
            "name": "CWE-22",
            "count": 8
          },
          {
            "name": "CWE-200",
            "count": 5
          },
          {
            "name": "CWE-400",
            "count": 4
          },
          {
            "name": "CWE-863",
            "count": 4
          },
          {
            "name": "CWE-918",
            "count": 4
          }
        ]
      },
      {
        "date": "2026-07-24",
        "publisher": "Linux",
        "records": 48,
        "unique_products": 1,
        "unique_references": 241,
        "top_cwes": []
      },
      {
        "date": "2026-07-29",
        "publisher": "GitHub_M",
        "records": 48,
        "unique_products": 19,
        "unique_references": 98,
        "top_cwes": [
          {
            "name": "CWE-918",
            "count": 10
          },
          {
            "name": "CWE-74",
            "count": 5
          },
          {
            "name": "CWE-770",
            "count": 5
          },
          {
            "name": "CWE-1336",
            "count": 4
          },
          {
            "name": "CWE-522",
            "count": 4
          }
        ]
      },
      {
        "date": "2026-07-01",
        "publisher": "GitHub_M",
        "records": 46,
        "unique_products": 20,
        "unique_references": 63,
        "top_cwes": [
          {
            "name": "CWE-79",
            "count": 8
          },
          {
            "name": "CWE-400",
            "count": 6
          },
          {
            "name": "CWE-280",
            "count": 3
          },
          {
            "name": "CWE-862",
            "count": 3
          },
          {
            "name": "CWE-1321",
            "count": 2
          }
        ]
      },
      {
        "date": "2026-07-10",
        "publisher": "drupal",
        "records": 46,
        "unique_products": 36,
        "unique_references": 46,
        "top_cwes": [
          {
            "name": "CWE-79",
            "count": 13
          },
          {
            "name": "CWE-862",
            "count": 9
          },
          {
            "name": "CWE-915",
            "count": 8
          },
          {
            "name": "CWE-863",
            "count": 3
          },
          {
            "name": "CWE-287",
            "count": 2
          }
        ]
      },
      {
        "date": "2026-07-13",
        "publisher": "VulDB",
        "records": 44,
        "unique_products": 31,
        "unique_references": 262,
        "top_cwes": [
          {
            "name": "CWE-74",
            "count": 8
          },
          {
            "name": "CWE-89",
            "count": 7
          },
          {
            "name": "CWE-94",
            "count": 7
          },
          {
            "name": "CWE-119",
            "count": 5
          },
          {
            "name": "CWE-22",
            "count": 5
          }
        ]
      },
      {
        "date": "2026-07-03",
        "publisher": "microsoft",
        "records": 43,
        "unique_products": 1,
        "unique_references": 43,
        "top_cwes": [
          {
            "name": "CWE-416",
            "count": 8
          },
          {
            "name": "CWE-843",
            "count": 6
          },
          {
            "name": "CWE-284",
            "count": 3
          },
          {
            "name": "CWE-79",
            "count": 3
          },
          {
            "name": "CWE-918",
            "count": 3
          }
        ]
      },
      {
        "date": "2026-07-12",
        "publisher": "VulDB",
        "records": 42,
        "unique_products": 27,
        "unique_references": 212,
        "top_cwes": [
          {
            "name": "CWE-74",
            "count": 12
          },
          {
            "name": "CWE-266",
            "count": 9
          },
          {
            "name": "CWE-89",
            "count": 9
          },
          {
            "name": "CWE-77",
            "count": 8
          },
          {
            "name": "CWE-285",
            "count": 7
          }
        ]
      },
      {
        "date": "2026-07-08",
        "publisher": "VulnCheck",
        "records": 41,
        "unique_products": 23,
        "unique_references": 112,
        "top_cwes": [
          {
            "name": "CWE-79",
            "count": 4
          },
          {
            "name": "CWE-863",
            "count": 4
          },
          {
            "name": "CWE-125",
            "count": 3
          },
          {
            "name": "CWE-200",
            "count": 3
          },
          {
            "name": "CWE-862",
            "count": 3
          }
        ]
      },
      {
        "date": "2026-07-13",
        "publisher": "VulnCheck",
        "records": 41,
        "unique_products": 16,
        "unique_references": 92,
        "top_cwes": [
          {
            "name": "CWE-863",
            "count": 9
          },
          {
            "name": "CWE-862",
            "count": 4
          },
          {
            "name": "CWE-918",
            "count": 4
          },
          {
            "name": "CWE-22",
            "count": 3
          },
          {
            "name": "CWE-79",
            "count": 3
          }
        ]
      },
      {
        "date": "2026-07-29",
        "publisher": "apache",
        "records": 41,
        "unique_products": 4,
        "unique_references": 9,
        "top_cwes": [
          {
            "name": "CWE-121",
            "count": 5
          },
          {
            "name": "CWE-444",
            "count": 5
          },
          {
            "name": "CWE-787",
            "count": 5
          },
          {
            "name": "CWE-20",
            "count": 3
          },
          {
            "name": "CWE-400",
            "count": 3
          }
        ]
      },
      {
        "date": "2026-07-03",
        "publisher": "Gitea",
        "records": 40,
        "unique_products": 1,
        "unique_references": 87,
        "top_cwes": [
          {
            "name": "CWE-284",
            "count": 14
          },
          {
            "name": "CWE-863",
            "count": 8
          },
          {
            "name": "CWE-862",
            "count": 4
          },
          {
            "name": "CWE-200",
            "count": 3
          },
          {
            "name": "CWE-639",
            "count": 3
          }
        ]
      },
      {
        "date": "2026-07-04",
        "publisher": "VulDB",
        "records": 40,
        "unique_products": 19,
        "unique_references": 231,
        "top_cwes": [
          {
            "name": "CWE-74",
            "count": 15
          },
          {
            "name": "CWE-89",
            "count": 15
          },
          {
            "name": "CWE-404",
            "count": 7
          },
          {
            "name": "CWE-79",
            "count": 4
          },
          {
            "name": "CWE-94",
            "count": 4
          }
        ]
      },
      {
        "date": "2026-07-06",
        "publisher": "apache",
        "records": 39,
        "unique_products": 16,
        "unique_references": 73,
        "top_cwes": [
          {
            "name": "CWE-20",
            "count": 21
          },
          {
            "name": "CWE-502",
            "count": 7
          },
          {
            "name": "CWE-918",
            "count": 5
          },
          {
            "name": "CWE-200",
            "count": 4
          },
          {
            "name": "CWE-639",
            "count": 4
          }
        ]
      },
      {
        "date": "2026-07-09",
        "publisher": "Wordfence",
        "records": 38,
        "unique_products": 34,
        "unique_references": 267,
        "top_cwes": [
          {
            "name": "CWE-862",
            "count": 13
          },
          {
            "name": "CWE-79",
            "count": 10
          },
          {
            "name": "CWE-639",
            "count": 4
          },
          {
            "name": "CWE-287",
            "count": 3
          },
          {
            "name": "CWE-22",
            "count": 2
          }
        ]
      },
      {
        "date": "2026-07-10",
        "publisher": "VulnCheck",
        "records": 38,
        "unique_products": 18,
        "unique_references": 100,
        "top_cwes": [
          {
            "name": "CWE-22",
            "count": 4
          },
          {
            "name": "CWE-79",
            "count": 4
          },
          {
            "name": "CWE-862",
            "count": 3
          },
          {
            "name": "CWE-639",
            "count": 2
          },
          {
            "name": "CWE-693",
            "count": 2
          }
        ]
      },
      {
        "date": "2026-07-14",
        "publisher": "VulDB",
        "records": 37,
        "unique_products": 19,
        "unique_references": 222,
        "top_cwes": [
          {
            "name": "CWE-119",
            "count": 7
          },
          {
            "name": "CWE-121",
            "count": 7
          },
          {
            "name": "CWE-918",
            "count": 6
          },
          {
            "name": "CWE-94",
            "count": 6
          },
          {
            "name": "CWE-1321",
            "count": 4
          }
        ]
      },
      {
        "date": "2026-07-18",
        "publisher": "VulDB",
        "records": 37,
        "unique_products": 14,
        "unique_references": 222,
        "top_cwes": [
          {
            "name": "CWE-918",
            "count": 7
          },
          {
            "name": "CWE-285",
            "count": 6
          },
          {
            "name": "CWE-863",
            "count": 6
          },
          {
            "name": "CWE-74",
            "count": 4
          },
          {
            "name": "CWE-94",
            "count": 4
          }
        ]
      }
    ],
    "top_shared_references": [
      {
        "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
        "records": 1108
      },
      {
        "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
        "records": 370
      },
      {
        "url": "https://support.apple.com/en-us/128067",
        "records": 149
      },
      {
        "url": "https://support.apple.com/en-us/128071",
        "records": 122
      },
      {
        "url": "https://support.apple.com/en-us/128072",
        "records": 112
      },
      {
        "url": "https://support.apple.com/en-us/128066",
        "records": 83
      },
      {
        "url": "https://support.apple.com/en-us/128069",
        "records": 66
      },
      {
        "url": "https://support.apple.com/en-us/128070",
        "records": 66
      },
      {
        "url": "https://support.apple.com/en-us/128068",
        "records": 64
      },
      {
        "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
        "records": 63
      },
      {
        "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
        "records": 61
      },
      {
        "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
        "records": 52
      },
      {
        "url": "https://www.sourcecodester.com/",
        "records": 49
      },
      {
        "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
        "records": 38
      },
      {
        "url": "https://code-projects.org/",
        "records": 33
      },
      {
        "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
        "records": 33
      },
      {
        "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
        "records": 32
      },
      {
        "url": "https://regularlabs.com/",
        "records": 29
      },
      {
        "url": "https://www.foxit.com/support/security-bulletins.html",
        "records": 28
      },
      {
        "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
        "records": 27
      },
      {
        "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
        "records": 27
      },
      {
        "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
        "records": 25
      },
      {
        "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
        "records": 23
      },
      {
        "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
        "records": 23
      },
      {
        "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
        "records": 22
      },
      {
        "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
        "records": 21
      },
      {
        "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
        "records": 20
      },
      {
        "url": "https://cna.openjsf.org/security-advisories.html",
        "records": 19
      },
      {
        "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
        "records": 19
      },
      {
        "url": "https://www.geovision.com.tw/cyber_security.php",
        "records": 19
      },
      {
        "url": "https://itsourcecode.com/",
        "records": 18
      },
      {
        "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
        "records": 17
      },
      {
        "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
        "records": 17
      },
      {
        "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
        "records": 16
      },
      {
        "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
        "records": 16
      },
      {
        "url": "https://url.sap/sapsecuritypatchday",
        "records": 16
      },
      {
        "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
        "records": 16
      },
      {
        "url": "https://blog.gitea.com/release-of-1.25.5/",
        "records": 15
      },
      {
        "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
        "records": 15
      },
      {
        "url": "https://codeastro.com/",
        "records": 15
      },
      {
        "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
        "records": 15
      },
      {
        "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
        "records": 15
      },
      {
        "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
        "records": 15
      },
      {
        "url": "https://mattermost.com/security-updates",
        "records": 15
      },
      {
        "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
        "records": 14
      },
      {
        "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
        "records": 14
      },
      {
        "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
        "records": 14
      },
      {
        "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
        "records": 14
      },
      {
        "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
        "records": 14
      },
      {
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
        "records": 14
      },
      {
        "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
        "records": 14
      },
      {
        "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
        "records": 13
      },
      {
        "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
        "records": 13
      },
      {
        "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
        "records": 13
      },
      {
        "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
        "records": 13
      },
      {
        "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
        "records": 13
      },
      {
        "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
        "records": 13
      },
      {
        "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
        "records": 13
      },
      {
        "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
        "records": 13
      },
      {
        "url": "https://github.com/nextlevelbuilder/goclaw/",
        "records": 13
      },
      {
        "url": "https://github.com/sipeed/picoclaw/",
        "records": 13
      },
      {
        "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
        "records": 13
      },
      {
        "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
        "records": 13
      },
      {
        "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
        "records": 12
      },
      {
        "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
        "records": 12
      },
      {
        "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
        "records": 12
      },
      {
        "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
        "records": 12
      },
      {
        "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
        "records": 12
      },
      {
        "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
        "records": 12
      },
      {
        "url": "https://www.balbooa.com/gridbox",
        "records": 12
      },
      {
        "url": "https://consumer.huawei.com/en/support/bulletin/2026/7/",
        "records": 11
      },
      {
        "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html",
        "records": 11
      },
      {
        "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5841",
        "records": 11
      },
      {
        "url": "https://github.com/discourse/discourse/releases/tag/v2026.1.5",
        "records": 11
      },
      {
        "url": "https://github.com/discourse/discourse/releases/tag/v2026.4.2",
        "records": 11
      },
      {
        "url": "https://github.com/discourse/discourse/releases/tag/v2026.5.1",
        "records": 11
      },
      {
        "url": "https://github.com/discourse/discourse/releases/tag/v2026.6.0",
        "records": 11
      },
      {
        "url": "https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/",
        "records": 11
      },
      {
        "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
        "records": 11
      },
      {
        "url": "https://access.redhat.com/errata/RHSA-2026:42922",
        "records": 10
      },
      {
        "url": "https://github.com/dataease/dataease/releases/tag/v2.10.23",
        "records": 10
      },
      {
        "url": "https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1",
        "records": 10
      },
      {
        "url": "https://github.com/ultravnc/UltraVNC",
        "records": 10
      },
      {
        "url": "https://support.apple.com/en-us/128073",
        "records": 10
      },
      {
        "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787",
        "records": 10
      },
      {
        "url": "https://uvnc.com/",
        "records": 10
      },
      {
        "url": "https://csirt.divd.nl/DIVD-2026-00001/",
        "records": 9
      },
      {
        "url": "https://downloads.isc.org/isc/bind9/9.20.26",
        "records": 9
      },
      {
        "url": "https://gfi.ai/products-and-solutions/network-security-solutions/archiver/resources/documentation/product-releases",
        "records": 9
      },
      {
        "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b",
        "records": 9
      },
      {
        "url": "https://github.com/radareorg/radare2/",
        "records": 9
      },
      {
        "url": "https://github.com/vercel/next.js/releases/tag/v16.2.11",
        "records": 9
      },
      {
        "url": "https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html",
        "records": 9
      },
      {
        "url": "https://www.cyrusimap.org/imap/download/release-notes/index.html",
        "records": 9
      },
      {
        "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
        "records": 9
      },
      {
        "url": "https://blog.gitea.com/release-of-1.26.2/",
        "records": 8
      },
      {
        "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53902",
        "records": 8
      },
      {
        "url": "https://cyberdanube.com/security-research/multiple-vulnerabilities-in-autel-maxi-charger/",
        "records": 8
      },
      {
        "url": "https://downloads.isc.org/isc/bind9/9.21.24",
        "records": 8
      },
      {
        "url": "https://github.com/better-auth/better-auth/releases/tag/v1.6.11",
        "records": 8
      }
    ],
    "nvd_statuses": [
      {
        "name": "Analyzed",
        "count": 3702
      },
      {
        "name": "Deferred",
        "count": 3581
      },
      {
        "name": "Awaiting Analysis",
        "count": 1318
      },
      {
        "name": "Undergoing Analysis",
        "count": 581
      },
      {
        "name": "Received",
        "count": 471
      },
      {
        "name": "Modified",
        "count": 110
      }
    ],
    "rejected_reasons": [
      {
        "name": "not_a_security_issue",
        "count": 33
      },
      {
        "name": "duplicate",
        "count": 5
      },
      {
        "name": "withdrawn_without_specific_public_reason",
        "count": 5
      },
      {
        "name": "erroneous_determination",
        "count": 1
      },
      {
        "name": "outside_component_threat_model",
        "count": 1
      }
    ],
    "reservation_to_publication_lag": {
      "count": 9763,
      "p50_days": 13.2,
      "p90_days": 82.7,
      "p99_days": 302.3,
      "max_days": 1982,
      "over_one_year": 76,
      "over_five_years": 6,
      "percentile_method": "Linear interpolation at p*(n-1) over the complete July cohort (the inclusive empirical distribution)."
    },
    "exact_duplicate_text": {
      "distinct_titles": 6801,
      "records_in_duplicate_title_clusters": 802,
      "duplicate_title_clusters": 227,
      "largest_title_cluster": 25,
      "distinct_descriptions": 9273,
      "records_in_duplicate_description_clusters": 752,
      "duplicate_description_clusters": 262,
      "largest_description_cluster": 32
    },
    "cvss_observed": {
      "maximum_observed_score_buckets": {
        "critical": 1447,
        "high": 4294,
        "low": 292,
        "medium": 3376,
        "none": 354
      },
      "records_with_source_score_spread_gte_1": 1268,
      "records_with_source_score_spread_gte_2": 640,
      "records_with_source_score_spread_gte_3": 374,
      "qualification": "Each record is bucketed by the maximum score observed across all retained CNA, ADP, and NVD rows. Scores can use different CVSS versions or assumptions; the source rows, vectors, and spread are retained and the maximum is not presented as a single official truth."
    }
  },
  "records": [
    {
      "cve_id": "CVE-2011-10043",
      "id_year": 2011,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T11:47:35.949Z",
      "date_published": "2026-07-07T11:46:13.575Z",
      "date_updated": "2026-07-07T16:04:29.197Z",
      "publisher": "CPANSec",
      "title": "Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded",
      "affected": {
        "vendors": [
          "BINGOS"
        ],
        "products": [
          {
            "vendor": "BINGOS",
            "product": "Module::Load"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-145",
          "name": "Improper Neutralization of Section Delimiters",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00447,
        "percentile": 0.36738
      },
      "nvd": {
        "published": "2026-07-07T12:16:24.880",
        "lastModified": "2026-07-07T17:16:31.890",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2011-10043",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Module::Load treats a leading :: in a caller-supplied module name as a path delimiter and can load executable Perl code outside @INC.",
        "basis": [
          "CNA",
          "CWE-145"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://blogs.perl.org/users/michael_g_schwern/2011/10/how-not-to-load-a-module-or-bad-interfaces-make-good-people-do-bad-things.html",
          "host": "blogs.perl.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "https://metacpan.org/release/BINGOS/Module-Load-0.22/diff/BINGOS/Module-Load-0.20/lib/Module/Load.pm",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/BINGOS/Module-Load-0.22/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2016-20096",
      "id_year": 2016,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T18:49:01.724Z",
      "date_published": "2026-07-21T18:59:52.802Z",
      "date_updated": "2026-07-22T19:06:24.973Z",
      "publisher": "VulnCheck",
      "title": "Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp",
      "affected": {
        "vendors": [
          "Kunshi Network Technology Co., Ltd."
        ],
        "products": [
          {
            "vendor": "Kunshi Network Technology Co., Ltd.",
            "product": "Linknat VOS3000"
          },
          {
            "vendor": "Kunshi Network Technology Co., Ltd.",
            "product": "Linknat VOS2009"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30945
      },
      "nvd": {
        "published": "2026-07-21T19:17:07.357",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2016-20096",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The login endpoint inserts the attacker-controlled name parameter into an SQL command without separating data from SQL syntax.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://web.archive.org/web/20160601102456/http://www.wooyun.org/bugs/wooyun-2010-0145458",
          "host": "web.archive.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://packetstorm.news/files/id/137159",
          "host": "packetstorm.news",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.linknat.com/",
          "host": "www.linknat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/linknat-vos3000-vos2009-sql-injection-via-login-jsp",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 473,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2019-25764",
      "id_year": 2019,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T07:34:36.865Z",
      "date_published": "2026-07-17T06:00:10.806Z",
      "date_updated": "2026-07-17T10:10:36.305Z",
      "publisher": "ASUS",
      "title": "**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation.",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "AURA SYNC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-782",
          "name": "Exposed IOCTL with Insufficient Access Control",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0009,
        "percentile": 0.00541
      },
      "nvd": {
        "published": "2026-07-17T07:16:37.193",
        "lastModified": "2026-07-17T18:10:29.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2019-25764",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The AURA SYNC driver exposes IOCTL dispatch to a local user without an access check that limits the caller to the intended privileged subject.",
        "basis": [
          "CNA",
          "CWE-782"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 364,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2021-27137",
      "id_year": 2021,
      "state": "PUBLISHED",
      "date_reserved": "2021-02-10T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-22T03:55:45.793Z",
      "publisher": "mitre",
      "title": "An issue was discovered in router/upnp/src/ssdp.",
      "affected": {
        "vendors": [
          "DD-WRT"
        ],
        "products": [
          {
            "vendor": "DD-WRT",
            "product": "DD-WRT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.16488,
        "percentile": 0.9667
      },
      "official_kev": {
        "cveID": "CVE-2021-27137",
        "vendorProject": "DD-WRT",
        "product": "DD-WRT",
        "vulnerabilityName": "DD-WRT Stack-Based Buffer Overflow Vulnerability",
        "dateAdded": "2026-07-21",
        "shortDescription": "DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-07-24",
        "knownRansomwareCampaignUse": "Unknown",
        "notes": "This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://svn.dd-wrt.com/changeset/45724 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-27137",
        "cwes": [
          "CWE-121"
        ]
      },
      "nvd": {
        "published": "2026-07-16T18:16:39.113",
        "lastModified": "2026-07-22T05:17:07.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2021-27137",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ssdp_msearch path copies attacker-controlled M-SEARCH data with strcpy into a fixed stack buffer without a length bound.",
        "basis": [
          "CNA",
          "CWE-121",
          "CISA KEV feed"
        ],
        "deepDive": true,
        "notes": "Inspected the CISA KEV feed at https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; the linked DD-WRT patch at https://svn.dd-wrt.com/changeset/45724 was blocked by an Anubis browser challenge, so no source-traced claim is made."
      },
      "references": [
        {
          "url": "https://svn.dd-wrt.com/changeset/45724",
          "host": "svn.dd-wrt.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/",
          "host": "ssd-disclosure.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://securityaffairs.com/193290/uncategorized/iot-botnet-c0xmo-adds-competitor-killing-capability.html",
          "host": "securityaffairs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/",
          "host": "www.bleepingcomputer.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo",
          "host": "www.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27137",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 427,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2021-32084",
      "id_year": 2021,
      "state": "PUBLISHED",
      "date_reserved": "2021-05-06T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_updated": "2026-07-28T14:55:09.026Z",
      "publisher": "mitre",
      "title": "An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25209
      },
      "nvd": {
        "published": "2026-07-27T22:16:56.543",
        "lastModified": "2026-08-03T14:31:11.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2021-32084",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The appliance applies an IP allowlist to its web console but leaves API endpoints outside that network restriction.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.quest.com/download-product-select",
          "host": "support.quest.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://support.quest.com/kace-systems-management-appliance/kb/4293505/quest-response-to-criticalstart-vulnerability-report",
          "host": "support.quest.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2021-32085",
      "id_year": 2021,
      "state": "PUBLISHED",
      "date_reserved": "2021-05-06T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_updated": "2026-07-28T14:55:00.720Z",
      "publisher": "mitre",
      "title": "An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21572
      },
      "nvd": {
        "published": "2026-07-27T22:16:57.500",
        "lastModified": "2026-08-03T14:31:07.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2021-32085",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The appliance creates database accounts with a publicly known default password that remains valid until an operator changes it.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.quest.com/download-product-select",
          "host": "support.quest.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://support.quest.com/kace-systems-management-appliance/kb/4293505/quest-response-to-criticalstart-vulnerability-report",
          "host": "support.quest.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2021-32086",
      "id_year": 2021,
      "state": "PUBLISHED",
      "date_reserved": "2021-05-06T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_updated": "2026-07-28T14:54:54.862Z",
      "publisher": "mitre",
      "title": "An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-321",
          "name": "Use of Hard-coded Cryptographic Key",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.0895
      },
      "nvd": {
        "published": "2026-07-27T22:16:57.613",
        "lastModified": "2026-08-03T14:30:59.897",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2021-32086",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "the affected component uses the same embedded credential or cryptographic key across installations instead of a per-deployment secret.",
        "basis": [
          "CNA",
          "CWE-321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.quest.com/download-product-select",
          "host": "support.quest.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://support.quest.com/kace-systems-management-appliance/kb/4293505/quest-response-to-criticalstart-vulnerability-report",
          "host": "support.quest.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 448,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2021-32087",
      "id_year": 2021,
      "state": "PUBLISHED",
      "date_reserved": "2021-05-06T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_updated": "2026-07-28T18:47:08.899Z",
      "publisher": "mitre",
      "title": "An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21572
      },
      "nvd": {
        "published": "2026-07-27T22:16:57.723",
        "lastModified": "2026-08-03T14:31:17.597",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2021-32087",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component in CVE-2021-32087 ships a known default credential, allowing any caller who knows the published value to authenticate as the built-in account.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.quest.com/download-product-select",
          "host": "support.quest.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://support.quest.com/kace-systems-management-appliance/kb/4293505/quest-response-to-criticalstart-vulnerability-report",
          "host": "support.quest.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 433,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2021-32088",
      "id_year": 2021,
      "state": "PUBLISHED",
      "date_reserved": "2021-05-06T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_updated": "2026-07-28T16:01:46.198Z",
      "publisher": "mitre",
      "title": "An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-384",
          "name": "Session Fixation",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20916
      },
      "nvd": {
        "published": "2026-07-27T22:16:57.840",
        "lastModified": "2026-08-03T14:30:47.763",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2021-32088",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The API rate limiter binds its state to the optional kboxid cookie, so removing that attacker-controlled identity marker bypasses the throttle.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-384",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Quest's official advisory at https://support.quest.com/kace-systems-management-appliance/kb/4293505/quest-response-to-criticalstart-vulnerability-report; it identifies K1-30594 and the 11.1 repair but does not publish the limiter implementation, so the cookie-keyed mechanism remains bounded to the embedded CNA description."
      },
      "references": [
        {
          "url": "https://support.quest.com/download-product-select",
          "host": "support.quest.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://support.quest.com/kace-systems-management-appliance/kb/4293505/quest-response-to-criticalstart-vulnerability-report",
          "host": "support.quest.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2022-4989",
      "id_year": 2022,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T05:59:50.869Z",
      "date_published": "2026-07-03T02:01:02.599Z",
      "date_updated": "2026-07-17T06:00:27.417Z",
      "publisher": "ASUS",
      "title": "** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation.",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "AI Suite 3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00103,
        "percentile": 0.01166
      },
      "nvd": {
        "published": "2026-07-03T03:16:22.100",
        "lastModified": "2026-07-17T07:16:37.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2022-4989",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AI Suite 3 accepts an IOCTL quantity without validating it against the permitted memory region, allowing access outside the intended range.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2022-4990",
      "id_year": 2022,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T06:00:30.357Z",
      "date_published": "2026-07-03T02:00:47.500Z",
      "date_updated": "2026-07-17T06:00:36.108Z",
      "publisher": "ASUS",
      "title": "** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to...",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "AI Suite 3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00096,
        "percentile": 0.00816
      },
      "nvd": {
        "published": "2026-07-03T03:16:23.087",
        "lastModified": "2026-07-17T07:16:37.490",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2022-4990",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The AI Suite driver accepts crafted IOCTL quantity values without validating them before using them to select restricted memory blocks.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2022-4994",
      "id_year": 2022,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T09:16:34.860Z",
      "date_published": "2026-07-30T09:18:06.591Z",
      "date_updated": "2026-07-30T09:18:06.591Z",
      "publisher": "Linux",
      "title": "KVM: x86: wean fast IN from emulator_pio_in",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00182,
        "percentile": 0.08011
      },
      "nvd": {
        "published": "2026-07-30T10:16:34.270",
        "lastModified": "2026-07-30T10:16:34.270",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2022-4994",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record describes a no-op KVM PIO call-path cleanup and does not disclose an exploitable failure or causal invariant.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/dc7a4bfde507ffe1d8bef49aba1322f1d20c2cb3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 1,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2022-50973",
      "id_year": 2022,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-11T13:34:26.334Z",
      "date_published": "2026-07-02T17:04:20.487Z",
      "date_updated": "2026-07-02T19:44:37.756Z",
      "publisher": "VulnCheck",
      "title": "Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet",
      "affected": {
        "vendors": [
          "Yonyou Network Technology Co., Ltd."
        ],
        "products": [
          {
            "vendor": "Yonyou Network Technology Co., Ltd.",
            "product": "KSOA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.0086,
        "percentile": 0.54977
      },
      "nvd": {
        "published": "2026-07-02T17:16:56.947",
        "lastModified": "2026-07-02T20:16:59.920",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2022-50973",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unauthenticated ImageUpload servlet accepts an arbitrary upload without constraining the stored file to the intended file namespace.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cn-sec.com/archives/1329088.html",
          "host": "cn-sec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://buaq.net/go-167023.html",
          "host": "buaq.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.cnblogs.com/yang-miemie/p/17714927.html",
          "host": "www.cnblogs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.yonyou.com/",
          "host": "www.yonyou.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/yonyou-ksoa-unauthenticated-file-upload-rce-via-imageupload-servlet",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 681,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2023-37507",
      "id_year": 2023,
      "state": "PUBLISHED",
      "date_reserved": "2023-07-06T16:11:40.095Z",
      "date_published": "2026-07-21T05:00:33.303Z",
      "date_updated": "2026-07-21T15:02:40.439Z",
      "publisher": "HCL",
      "title": "An information disclosure vulnerability affects HCL DevOps Plan",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "DevOps Plan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16319
      },
      "nvd": {
        "published": "2026-07-21T06:16:27.113",
        "lastModified": "2026-07-29T20:50:23.543",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2023-37507",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says HCL DevOps Plan reveals system information, while the exposed field and failing access boundary remain undisclosed.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132309",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2023-37508",
      "id_year": 2023,
      "state": "PUBLISHED",
      "date_reserved": "2023-07-06T16:11:40.095Z",
      "date_published": "2026-07-21T04:34:15.196Z",
      "date_updated": "2026-07-21T13:27:06.182Z",
      "publisher": "HCL",
      "title": "HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "DevOps Plan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03006
      },
      "nvd": {
        "published": "2026-07-21T05:16:33.263",
        "lastModified": "2026-07-29T20:43:39.393",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2023-37508",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132308",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2023-49899",
      "id_year": 2023,
      "state": "PUBLISHED",
      "date_reserved": "2023-12-01T08:19:11.319Z",
      "date_published": "2026-07-16T10:11:32.404Z",
      "date_updated": "2026-07-18T02:46:07.283Z",
      "publisher": "CERTVDE",
      "title": "Origin Validation Error in X-Rite MA-T6",
      "affected": {
        "vendors": [
          "X-Rite"
        ],
        "products": [
          {
            "vendor": "X-Rite",
            "product": "MA-T6"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11371
      },
      "nvd": {
        "published": "2026-07-16T11:16:35.597",
        "lastModified": "2026-07-18T03:16:34.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2023-49899",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The device accepts a privileged communication channel without verifying its origin; the public record does not identify the channel or the omitted check.",
        "basis": [
          "CNA",
          "CWE-346",
          "https://claroty.com/team82/disclosure-dashboard/cve-2023-49899"
        ],
        "deepDive": true,
        "notes": "Reviewed https://claroty.com/team82/disclosure-dashboard/cve-2023-49899. The researcher dashboard repeats the origin-validation category and affected firmware but does not publish the channel check or patch."
      },
      "references": [
        {
          "url": "https://claroty.com/team82/disclosure-dashboard/cve-2023-49899",
          "host": "claroty.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 151,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2023-49900",
      "id_year": 2023,
      "state": "PUBLISHED",
      "date_reserved": "2023-12-01T08:19:11.319Z",
      "date_published": "2026-07-16T10:11:11.925Z",
      "date_updated": "2026-07-16T15:11:14.497Z",
      "publisher": "CERTVDE",
      "title": "Origin Validation Error in X-Rite MA-T6",
      "affected": {
        "vendors": [
          "X-Rite"
        ],
        "products": [
          {
            "vendor": "X-Rite",
            "product": "MA-T6"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00536,
        "percentile": 0.42165
      },
      "nvd": {
        "published": "2026-07-16T11:16:36.597",
        "lastModified": "2026-07-16T16:17:18.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2023-49900",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled command data reaches a command interpreter without safe argument separation or complete command-language neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://claroty.com/team82/disclosure-dashboard/cve-2023-49900",
          "host": "claroty.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 144,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2023-54366",
      "id_year": 2023,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T21:54:30.246Z",
      "date_published": "2026-07-18T13:10:00.190Z",
      "date_updated": "2026-07-28T01:47:40.301Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 1.0.1 Insecure Default Table Permissions",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19962
      },
      "nvd": {
        "published": "2026-07-18T14:17:07.603",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2023-54366",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Installation or startup assigns a broader default permission than the product's intended private scope.",
        "basis": [
          "CNA",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-x5fr-7hhj-34j3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-insecure-default-table-permissions",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 351,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2024-1248",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-02-06T04:46:46.449Z",
      "date_published": "2026-07-04T20:38:49.590Z",
      "date_updated": "2026-07-06T13:50:13.770Z",
      "publisher": "WSO2",
      "title": "Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation",
      "affected": {
        "vendors": [
          "WSO2"
        ],
        "products": [
          {
            "vendor": "WSO2",
            "product": "WSO2 API Manager"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 Identity Server"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 Identity Server as Key Manager"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 Open Banking AM"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 Open Banking IAM"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-298",
          "name": "Improper Validation of Certificate Expiration",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:ed10eef1-636d-4fbe-9993-6890dfa878f8",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00182,
        "percentile": 0.0805
      },
      "nvd": {
        "published": "2026-07-04T21:17:13.793",
        "lastModified": "2026-07-09T18:47:41.403",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2024-1248",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Silent JIT provisioning matches a federated identity to an existing local username and overwrites the local account roles with the federated role set.",
        "basis": [
          "CNA",
          "CWE-298"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3179/",
          "host": "security.docs.wso2.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 816,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2024-5300",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-05-23T21:58:22.809Z",
      "date_published": "2026-07-21T14:00:51.066Z",
      "date_updated": "2026-07-22T18:28:16.818Z",
      "publisher": "canonical",
      "title": "AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd",
      "affected": {
        "vendors": [
          "Canonical"
        ],
        "products": [
          {
            "vendor": "Canonical",
            "product": "Ubuntu 26.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 24.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 22.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 20.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 18.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 16.04 LTS"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-212",
          "name": "Improper Removal of Sensitive Information Before Storage or Transfer",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@ubuntu.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00099,
        "percentile": 0.00951
      },
      "nvd": {
        "published": "2026-07-21T15:16:29.027",
        "lastModified": "2026-07-22T19:16:53.303",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-5300",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The base AppArmor profile lets a confined root process reach systemd-userdbd sockets, whose authorization does not distinguish sandboxed root from host root.",
        "basis": [
          "CNA",
          "CWE-212"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://ubuntu.com/security/CVE-2024-5300",
          "host": "ubuntu.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1231,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2024-6228",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-06-20T20:27:35.683Z",
      "date_published": "2026-07-06T06:00:01.064Z",
      "date_updated": "2026-07-06T12:09:45.862Z",
      "publisher": "WPScan",
      "title": "WANotifier < 2.6 - Subscriber+ LFI",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Notifications for Forms & WordPress Actions"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24279
      },
      "nvd": {
        "published": "2026-07-06T08:16:34.057",
        "lastModified": "2026-07-06T18:37:01.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-6228",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A subscriber-controlled value is used to build a server-side include path without restricting the resolved file to the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/6382bfea-6265-4f4b-b26e-4219d9ed78aa/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 307,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-7708",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-08-12T16:15:04.741Z",
      "date_published": "2026-07-14T09:01:53.869Z",
      "date_updated": "2026-07-14T12:17:11.635Z",
      "publisher": "eclipse",
      "title": "For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak.",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Jetty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16631
      },
      "nvd": {
        "published": "2026-07-14T09:16:39.453",
        "lastModified": "2026-07-14T20:56:01.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2024-7708",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A request-body read that returns zero bytes leaves its buffer unreleased, so slow or 100-Continue requests can steadily exhaust memory.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/29",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2024-14037",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:40:17.092Z",
      "date_published": "2026-07-02T17:03:23.307Z",
      "date_updated": "2026-07-02T18:20:10.126Z",
      "publisher": "VulnCheck",
      "title": "Redsea Cloud eHR Unauthenticated File Upload RCE via PtFjk.mob",
      "affected": {
        "vendors": [
          "Guangzhou Red Sea Cloud Computing Co., Ltd."
        ],
        "products": [
          {
            "vendor": "Guangzhou Red Sea Cloud Computing Co., Ltd.",
            "product": "Red Sea Cloud eHR"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00708,
        "percentile": 0.49945
      },
      "nvd": {
        "published": "2026-07-02T17:16:57.360",
        "lastModified": "2026-07-02T19:16:58.693",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-14037",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload endpoint accepts an attacker-named executable JSP as an image and stores it at a web-reachable path without restricting the dangerous file type.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cn-sec.com/archives/2734791.html",
          "host": "cn-sec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://cn-sec.com/archives/3003231.html",
          "host": "cn-sec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://redseacloud.com/",
          "host": "redseacloud.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/redsea-cloud-ehr-unauthenticated-file-upload-rce-via-ptfjk-mob",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 598,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-14040",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-26T06:29:25.532Z",
      "date_published": "2026-07-26T06:30:17.607Z",
      "date_updated": "2026-07-27T12:51:09.812Z",
      "publisher": "Linux",
      "title": "net: nexthop: Increase weight to u16",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0011,
        "percentile": 0.01505
      },
      "nvd": {
        "published": "2026-07-26T07:16:39.583",
        "lastModified": "2026-07-27T14:16:51.257",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-14040",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An 8-bit next-hop weight cannot represent required ECMP ratios, so the repair widens and audits the weight representation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b72a6a7ab9573e06d5c2fcb92eaa28614a735bfd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3089,
        "referenceCount": 1,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2024-14041",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T05:07:53.475Z",
      "date_published": "2026-07-28T08:05:35.310Z",
      "date_updated": "2026-07-28T12:55:43.574Z",
      "publisher": "bcorg",
      "title": "ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and ciphertext compression (KyberSlash)",
      "affected": {
        "vendors": [
          "Legion of the Bouncy Castle Inc."
        ],
        "products": [
          {
            "vendor": "Legion of the Bouncy Castle Inc.",
            "product": "BC-JAVA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/U:Amber"
        },
        {
          "source": "NVD:91579145-5d7b-4cc5-b925-a0262ff19630",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19643
      },
      "nvd": {
        "published": "2026-07-28T08:17:12.367",
        "lastModified": "2026-07-30T16:27:52.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-14041",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Secret-derived ML-KEM coefficients pass through non-constant-time division, making decapsulation timing depend on the private key.",
        "basis": [
          "CNA record",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bcgit/bc-java/wiki/CVE-2024-14041",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/bcgit/bc-java/commit/5adb2c5c5b462a332b01a012bea0784b40b904e5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/bcgit/bc-java/commit/1590247178f2280defa36421475f015175dfbe9e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://kyberslash.cr.yp.to/",
          "host": "kyberslash.cr.yp.to",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 642,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23564",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:56.729Z",
      "date_published": "2026-07-17T13:25:40.588Z",
      "date_updated": "2026-07-17T13:54:47.286Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-326",
          "name": "Inadequate Encryption Strength",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08685
      },
      "nvd": {
        "published": "2026-07-17T14:17:16.513",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23564",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The initial request validates UserId, but the password-email request omits the same identity check and lets the caller redirect the password to another address.",
        "basis": [
          "CNA",
          "CWE-326"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23565",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:56.729Z",
      "date_published": "2026-07-17T13:36:31.972Z",
      "date_updated": "2026-07-17T15:15:03.298Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-799",
          "name": "Improper Control of Interaction Frequency",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14862
      },
      "nvd": {
        "published": "2026-07-17T14:17:16.647",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23565",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The password-reset endpoint accepts an unbounded number of email requests, allowing one caller to exhaust mail-handling capacity.",
        "basis": [
          "CNA",
          "CWE-799"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23566",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:56.729Z",
      "date_published": "2026-07-17T13:32:42.289Z",
      "date_updated": "2026-07-17T15:13:56.784Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-804",
          "name": "Guessable CAPTCHA",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05565
      },
      "nvd": {
        "published": "2026-07-17T14:17:16.760",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23566",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The login path permits automated guesses without an effective CAPTCHA or equivalent attempt-control gate.",
        "basis": [
          "CNA",
          "CWE-804"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23567",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:56.729Z",
      "date_published": "2026-07-17T13:28:43.206Z",
      "date_updated": "2026-07-17T13:54:13.031Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-804",
          "name": "Guessable CAPTCHA",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.0779
      },
      "nvd": {
        "published": "2026-07-17T14:17:16.877",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23567",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Sensitive values are placed in URL parameters, making them visible in browser history, server logs, and other URL-observing surfaces.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-804"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 324,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23568",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:56.729Z",
      "date_published": "2026-07-17T13:38:28.022Z",
      "date_updated": "2026-07-17T15:17:21.200Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14862
      },
      "nvd": {
        "published": "2026-07-17T14:17:16.990",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23568",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The web server returns its software version to unauthenticated clients, exposing a banner that identifies potentially vulnerable server builds.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 351,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23569",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:56.729Z",
      "date_published": "2026-07-17T13:49:12.238Z",
      "date_updated": "2026-07-17T15:22:26.200Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection\" header",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-692",
          "name": "Incomplete Denylist to Cross-Site Scripting",
          "abstraction": "Compound",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.0715
      },
      "nvd": {
        "published": "2026-07-17T14:17:17.110",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23569",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Aftermarket EPC server omits the X-XSS-Protection response header, leaving the browser-side filter configuration at its ambient default.",
        "basis": [
          "CNA",
          "CWE-692"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23570",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:59.076Z",
      "date_published": "2026-07-17T13:50:42.412Z",
      "date_updated": "2026-07-17T15:23:23.683Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.0606
      },
      "nvd": {
        "published": "2026-07-17T14:17:17.223",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23570",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The page can be framed by an attacker-controlled site because the response does not enforce an effective anti-framing policy.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 339,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23571",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:59.076Z",
      "date_published": "2026-07-17T13:42:48.152Z",
      "date_updated": "2026-07-17T15:18:44.014Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-525",
          "name": "Use of Web Browser Cache Containing Sensitive Information",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.0715
      },
      "nvd": {
        "published": "2026-07-17T14:17:17.343",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23571",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Aftermarket EPC response lacks a restrictive browser-cache policy, leaving sensitive fields recoverable from a shared local cache.",
        "basis": [
          "CNA",
          "CWE-525"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 364,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23572",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:59.076Z",
      "date_published": "2026-07-17T13:51:11.203Z",
      "date_updated": "2026-07-17T15:24:11.725Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-614",
          "name": "Sensitive Cookie in HTTPS Session Without 'Secure' Attribute",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00086,
        "percentile": 0.00398
      },
      "nvd": {
        "published": "2026-07-17T14:17:17.460",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23572",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The session-token cookie is issued without the Secure attribute, allowing transport outside the intended HTTPS channel.",
        "basis": [
          "CNA",
          "CWE-614"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23573",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:59.076Z",
      "date_published": "2026-07-17T13:42:13.216Z",
      "date_updated": "2026-07-17T15:17:56.645Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-425",
          "name": "Direct Request ('Forced Browsing')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05181
      },
      "nvd": {
        "published": "2026-07-17T14:17:17.573",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23573",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The record identifies a Lucky 13 timing oracle in TLS CBC processing, while the mismatched CWE-425 label and public advisory do not identify the variable-time operation.",
        "basis": [
          "CNA",
          "CWE-425"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23574",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:59.076Z",
      "date_published": "2026-07-17T13:45:33.068Z",
      "date_updated": "2026-07-17T15:20:50.789Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-204",
          "name": "Observable Response Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09731
      },
      "nvd": {
        "published": "2026-07-17T14:17:17.693",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23574",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The login response reveals whether a supplied account exists, enabling remote user enumeration.",
        "basis": [
          "CNA",
          "CWE-204"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23575",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:59.076Z",
      "date_published": "2026-07-17T13:43:25.535Z",
      "date_updated": "2026-07-17T15:19:29.809Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09731
      },
      "nvd": {
        "published": "2026-07-17T14:17:17.810",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23575",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23577",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:59.077Z",
      "date_published": "2026-07-17T13:46:04.378Z",
      "date_updated": "2026-07-17T15:21:21.423Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.0715
      },
      "nvd": {
        "published": "2026-07-17T14:17:17.947",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23577",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "HCL Leap accepts a request Host value without publishing the exact canonicalization or allowlist check that fails.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-23578",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-01-18T07:29:59.077Z",
      "date_published": "2026-07-17T13:50:08.817Z",
      "date_updated": "2026-07-17T15:22:55.528Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-692",
          "name": "Incomplete Denylist to Cross-Site Scripting",
          "abstraction": "Compound",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        },
        {
          "id": "CWE-942",
          "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.0236
      },
      "nvd": {
        "published": "2026-07-17T14:17:18.063",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-23578",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CORS policy grants browser cross-origin access to any requesting domain instead of an approved origin set.",
        "basis": [
          "CNA",
          "CWE-692",
          "CWE-942"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-25039",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-02-03T14:49:24.713Z",
      "date_published": "2026-07-30T18:14:16.220Z",
      "date_updated": "2026-07-31T23:05:09.914Z",
      "publisher": "ibm",
      "title": "IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Engineering Requirements Management DOORS and DOORS Web Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17961
      },
      "nvd": {
        "published": "2026-07-30T19:16:56.507",
        "lastModified": "2026-07-31T23:17:22.570",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-25039",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The HTTP service leaves Slowloris connections open without an effective length or duration bound, allowing connection slots to be exhausted.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279145",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2024-32385",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-04-12T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-17T13:34:16.641Z",
      "publisher": "mitre",
      "title": "An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AC:L/AV:A/A:N/C:L/I:N/PR:N/S:U/UI:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11023
      },
      "nvd": {
        "published": "2026-07-16T21:17:17.510",
        "lastModified": "2026-07-17T18:11:59.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-32385",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "The product exposes board and revision identifiers to a remote requester, but the public record does not identify the missing disclosure control.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.kerlink.com/",
          "host": "www.kerlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.bdosecurity.de/de-de/advisories/cve-2024-32385",
          "host": "www.bdosecurity.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 173,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-32386",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-04-12T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-17T13:41:06.510Z",
      "publisher": "mitre",
      "title": "Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AC:L/AV:A/A:N/C:H/I:H/PR:N/S:U/UI:R"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00522,
        "percentile": 0.41416
      },
      "nvd": {
        "published": "2026-07-16T21:17:18.547",
        "lastModified": "2026-07-17T18:11:59.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-32386",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SNMP update mechanism accepts traversal segments that select files outside its intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.kerlink.com/",
          "host": "www.kerlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.bdosecurity.de/de-de/advisories/cve-2024-32386",
          "host": "www.bdosecurity.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-32387",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-04-12T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-17T13:42:03.575Z",
      "publisher": "mitre",
      "title": "An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AC:L/AV:A/A:N/C:H/I:N/PR:N/S:U/UI:R"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10363
      },
      "nvd": {
        "published": "2026-07-16T21:17:18.670",
        "lastModified": "2026-07-17T18:11:59.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-32387",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The device relies on a fixed or embedded SNMP community credential that can be used to obtain protected information, although the exposure path is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.kerlink.com/",
          "host": "www.kerlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.bdosecurity.de/de-de/advisories/cve-2024-32387",
          "host": "www.bdosecurity.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-32389",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-04-12T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-17T13:40:20.550Z",
      "publisher": "mitre",
      "title": "Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AC:L/AV:A/A:N/C:L/I:N/PR:N/S:U/UI:R"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11179
      },
      "nvd": {
        "published": "2026-07-16T21:17:18.777",
        "lastModified": "2026-07-17T18:11:59.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-32389",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component path copies input without enforcing the destination buffer size.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.kerlink.com/",
          "host": "www.kerlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.bdosecurity.de/de-de/advisories/cve-2024-32389",
          "host": "www.bdosecurity.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-34268",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-05-02T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-17T13:39:24.468Z",
      "publisher": "mitre",
      "title": "EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AC:L/AV:A/A:L/C:N/I:H/PR:N/S:U/UI:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10806
      },
      "nvd": {
        "published": "2026-07-16T21:17:18.890",
        "lastModified": "2026-07-17T18:11:59.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-34268",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The thermostat accepts Bluetooth control connections without requiring the peer to authenticate.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.bdosecurity.de/de-de/advisories/cve-2024-34268",
          "host": "www.bdosecurity.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.eq-3.com",
          "host": "www.eq-3.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-40683",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-07-08T19:30:52.530Z",
      "date_published": "2026-07-30T18:11:56.676Z",
      "date_updated": "2026-07-30T19:22:14.290Z",
      "publisher": "ibm",
      "title": "IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allowing active sessions to persist beyond a password change",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Operations Analytics - Log Analysis"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05041
      },
      "nvd": {
        "published": "2026-07-30T19:16:57.767",
        "lastModified": "2026-07-30T20:16:50.313",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-40683",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A credential-state change in Operations Analytics - Log Analysis leaves an earlier session or token valid after it should have been withdrawn.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279877",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2024-42214",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-07-29T21:32:16.371Z",
      "date_published": "2026-07-17T13:45:04.678Z",
      "date_updated": "2026-07-17T15:20:14.969Z",
      "publisher": "HCL",
      "title": "HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Aftermarket EPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-692",
          "name": "Incomplete Denylist to Cross-Site Scripting",
          "abstraction": "Compound",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09732
      },
      "nvd": {
        "published": "2026-07-17T14:17:18.863",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-42214",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Aftermarket EPC enables or exposes a server method in its deployed configuration without the restriction needed to keep that capability outside untrusted reach.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-692"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-51311",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-10-28T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-21T14:58:33.718Z",
      "publisher": "mitre",
      "title": "The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00427,
        "percentile": 0.35183
      },
      "nvd": {
        "published": "2026-07-20T21:16:46.153",
        "lastModified": "2026-07-21T18:55:59.253",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-51311",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SetNetControlList handler writes attacker-controlled data beyond a stack buffer in sub_4418CC.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tendacn.com/download/detail-4515.html",
          "host": "www.tendacn.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitee.com/GXB0_0/iot-vul/blob/master/Tenda/TX9/20/SetNetControlList.md",
          "host": "gitee.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-51312",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-10-28T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-21T14:58:22.886Z",
      "publisher": "mitre",
      "title": "The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34475
      },
      "nvd": {
        "published": "2026-07-20T22:17:02.500",
        "lastModified": "2026-07-21T18:55:59.253",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-51312",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "the affected component copies attacker-controlled data past a fixed stack buffer because the input length is not bounded to the destination size.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tendacn.com/download/detail-4515.html",
          "host": "www.tendacn.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitee.com/GXB0_0/iot-vul/blob/master/Tenda/TX9/20/SetStaticRouteCfg.md",
          "host": "gitee.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-51313",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-10-28T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-21T14:58:28.306Z",
      "publisher": "mitre",
      "title": "The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34475
      },
      "nvd": {
        "published": "2026-07-20T21:16:46.297",
        "lastModified": "2026-07-21T18:55:59.253",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-51313",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SetVirtualServerCfg handler copies attacker-controlled data into a fixed stack buffer in sub_42EA38 without an effective length bound.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tendacn.com/download/detail-4515.html",
          "host": "www.tendacn.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitee.com/GXB0_0/iot-vul/blob/master/Tenda/TX9/20/SetNetControlList.md",
          "host": "gitee.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-51314",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-10-28T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-21T14:58:17.255Z",
      "publisher": "mitre",
      "title": "The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34475
      },
      "nvd": {
        "published": "2026-07-20T22:17:03.440",
        "lastModified": "2026-07-21T18:55:59.253",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-51314",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The setMacFilterCfg handler reaches sub_424CE0 with data that overflows a stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tendacn.com/download/detail-4515.html",
          "host": "www.tendacn.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitee.com/GXB0_0/iot-vul/blob/master/Tenda/TX9/20/setMacFilterCfg.md",
          "host": "gitee.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-51315",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-10-28T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-21T14:58:11.507Z",
      "publisher": "mitre",
      "title": "The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34474
      },
      "nvd": {
        "published": "2026-07-20T22:17:03.550",
        "lastModified": "2026-07-21T18:55:59.253",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-51315",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A request to SetOnlineDevName reaches sub_425964 with data that exceeds a stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tendacn.com/download/detail-4515.html",
          "host": "www.tendacn.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitee.com/GXB0_0/iot-vul/blob/master/Tenda/TX9/20/SetOnlineDevName_mac.md",
          "host": "gitee.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-51316",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-10-28T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-21T14:58:05.589Z",
      "publisher": "mitre",
      "title": "The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26968
      },
      "nvd": {
        "published": "2026-07-20T22:17:03.657",
        "lastModified": "2026-07-21T18:55:59.253",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-51316",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record identifies a denial of service in update_dev_name without disclosing whether the trigger is resource exhaustion, memory corruption, or another implementation failure.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tendacn.com/download/detail-4515.html",
          "host": "www.tendacn.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitee.com/GXB0_0/iot-vul/blob/master/Tenda/TX9/20/SetOnlineDevName_devName.md",
          "host": "gitee.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-56141",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2024-12-16T18:04:39.982Z",
      "date_published": "2026-07-06T23:17:54.978Z",
      "date_updated": "2026-07-08T19:41:44.619Z",
      "publisher": "GitHub_M",
      "title": "Minosoft has IV equal to key",
      "affected": {
        "vendors": [
          "Bixilon"
        ],
        "products": [
          {
            "vendor": "Bixilon",
            "product": "Minosoft"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-329",
          "name": "Generation of Predictable IV with CBC Mode",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00111,
        "percentile": 0.01544
      },
      "nvd": {
        "published": "2026-07-07T00:16:33.607",
        "lastModified": "2026-07-08T20:16:46.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-56141",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CryptManager uses the AES key itself as the CBC initialization vector, making the IV predictable and coupled to the secret key.",
        "basis": [
          "CNA",
          "CWE-329"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Bixilon/Minosoft/security/advisories/GHSA-rvr6-48rj-c94j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Bixilon/Minosoft/blob/3a608abe2d0999e4e702cc1b2d28366884c7f31e/src/main/java/de/bixilon/minosoft/protocol/protocol/encryption/CryptManager.kt#L72",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 726,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-58023",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T07:45:15.711Z",
      "date_published": "2026-07-23T07:52:32.395Z",
      "date_updated": "2026-07-23T13:59:46.842Z",
      "publisher": "bosch",
      "title": "Information disclosure in Bosch Configuration Manager in Version 7.",
      "affected": {
        "vendors": [
          "Bosch"
        ],
        "products": [
          {
            "vendor": "Bosch",
            "product": "Bosch Configuration Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-312",
          "name": "Cleartext Storage of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@bosch.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00079,
        "percentile": 0.00195
      },
      "nvd": {
        "published": "2026-07-23T09:16:26.290",
        "lastModified": "2026-07-23T15:48:25.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58023",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The product stores or transmits a security secret in cleartext where an unauthorized observer can recover it.",
        "basis": [
          "CNA",
          "CWE-312"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://psirt.bosch.com/security-advisories/BOSCH-SA-981803.html",
          "host": "psirt.bosch.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-58330",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T07:45:15.716Z",
      "date_published": "2026-07-23T07:56:34.646Z",
      "date_updated": "2026-07-23T13:59:27.140Z",
      "publisher": "bosch",
      "title": "A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.",
      "affected": {
        "vendors": [
          "Bosch"
        ],
        "products": [
          {
            "vendor": "Bosch",
            "product": "Camera Firmware"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@bosch.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21343
      },
      "nvd": {
        "published": "2026-07-23T09:16:26.430",
        "lastModified": "2026-07-23T15:48:25.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58330",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://psirt.bosch.com/security-advisories/BOSCH-SA-659648.html",
          "host": "psirt.bosch.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 153,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2024-58352",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T15:20:35.497Z",
      "date_published": "2026-07-02T17:05:10.709Z",
      "date_updated": "2026-07-28T01:47:44.539Z",
      "publisher": "VulnCheck",
      "title": "Landray OA Unauthenticated HQL Injection via wechatLoginHelper.do",
      "affected": {
        "vendors": [
          "Shenzhen Landray Software Co., Ltd."
        ],
        "products": [
          {
            "vendor": "Shenzhen Landray Software Co., Ltd.",
            "product": "Landry Office Automation (OA)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-564",
          "name": "SQL Injection: Hibernate",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00564,
        "percentile": 0.43656
      },
      "nvd": {
        "published": "2026-07-02T17:16:57.557",
        "lastModified": "2026-07-02T18:16:48.033",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58352",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a Landry Office Automation (OA) database query without safe parameter binding, allowing query syntax injection.",
        "basis": [
          "CNA",
          "CWE-564"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cn-sec.com/archives/2532828.html",
          "host": "cn-sec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://blog.csdn.net/fushuang333/article/details/136377020",
          "host": "blog.csdn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://blog.csdn.net/qq_39342001/article/details/137354047",
          "host": "blog.csdn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/landray-oa-unauthenticated-hql-injection-via-wechatloginhelper-do",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 647,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-58353",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T15:20:35.497Z",
      "date_published": "2026-07-23T21:16:42.870Z",
      "date_updated": "2026-07-28T01:47:45.196Z",
      "publisher": "VulnCheck",
      "title": "Cal.com through 4.7.15 Cross-Site Scripting via booking questions",
      "affected": {
        "vendors": [
          "calcom"
        ],
        "products": [
          {
            "vendor": "calcom",
            "product": "cal.diy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-80",
          "name": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22035
      },
      "nvd": {
        "published": "2026-07-23T22:16:51.080",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58353",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A booking-question label reaches dangerouslySetInnerHTML without sanitization, so stored markup is executed in a visitor's browser.",
        "basis": [
          "CNA",
          "CWE-80"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/calcom/cal.diy/security/advisories/GHSA-vgj7-76cw-h6f8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/calcom/cal.diy/commit/00689fda0a30b8f933c096f02c1fe092a4206def",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cal-com-through-cross-site-scripting-via-booking-questions",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-58354",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T15:20:35.497Z",
      "date_published": "2026-07-23T21:16:43.545Z",
      "date_updated": "2026-07-24T21:35:07.962Z",
      "publisher": "VulnCheck",
      "title": "cal.com Repository Takeover via pull_request_target Workflow",
      "affected": {
        "vendors": [
          "calcom"
        ],
        "products": [
          {
            "vendor": "calcom",
            "product": "cal.diy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31318
      },
      "nvd": {
        "published": "2026-07-23T22:16:51.380",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58354",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A pull_request_target workflow grants a write-capable token and then checks out and executes contributor-controlled pull-request code.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/calcom/cal.diy/security/advisories/GHSA-p3f6-52gv-cj7m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/calcom/cal.diy/commit/9aa60fae41a6b6b101c86bf430754b439f440871",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cal-com-repository-takeover-via-pull-request-target-workflow",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 835,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2024-58355",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T15:20:35.497Z",
      "date_published": "2026-07-23T21:16:44.180Z",
      "date_updated": "2026-07-28T01:47:45.864Z",
      "publisher": "VulnCheck",
      "title": "Cal.com through 4.7.15 Cross-Site Scripting via booking questions",
      "affected": {
        "vendors": [
          "calcom"
        ],
        "products": [
          {
            "vendor": "calcom",
            "product": "cal.diy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-80",
          "name": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21377
      },
      "nvd": {
        "published": "2026-07-23T22:16:51.533",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58355",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A booking-question label reaches dangerouslySetInnerHTML without sanitization, so stored attacker markup executes in the booking view.",
        "basis": [
          "CNA record",
          "CWE-80"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/calcom/cal.diy/security/advisories/GHSA-vgj7-76cw-h6f8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/calcom/cal.diy/commit/00689fda0a30b8f933c096f02c1fe092a4206def",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cal-com-through-cross-site-scripting-via-booking-questions-2",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 491,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2024-58356",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T15:20:35.497Z",
      "date_published": "2026-07-18T13:10:00.884Z",
      "date_updated": "2026-07-28T01:47:46.525Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.1.4 Permission Bypass via DEFINE TABLE OVERWRITE",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18271
      },
      "nvd": {
        "published": "2026-07-18T14:17:08.363",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58356",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DEFINE TABLE OVERWRITE silently retains the prior permission definition for relation tables instead of applying the replacement definition.",
        "basis": [
          "CNA",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-27vq-hv74-7cqp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-permission-bypass-via-define-table-overwrite",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2024-58357",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T15:20:35.497Z",
      "date_published": "2026-07-18T13:10:01.549Z",
      "date_updated": "2026-07-28T01:47:47.190Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.1.0 Denial of Service via rand::time()",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00307,
        "percentile": 0.2298
      },
      "nvd": {
        "published": "2026-07-18T14:17:08.503",
        "lastModified": "2026-07-22T20:16:41.810",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58357",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The rand::time path unwraps an absent value instead of handling it, so crafted input raises an uncaught panic that terminates the service.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-h4f5-h82v-5w4r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-rand-time",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2024-58358",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T15:20:35.497Z",
      "date_published": "2026-07-18T13:10:02.254Z",
      "date_updated": "2026-07-28T01:47:47.875Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.1.0 Denial of Service via Nonexistent Role",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00329,
        "percentile": 0.25381
      },
      "nvd": {
        "published": "2026-07-18T14:17:08.643",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58358",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SurrealDB accepts a nonexistent role when defining a user and later panics instead of handling that invalid role during sign-in.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-jc55-246c-r88f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-nonexistent-role",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 280,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2024-58359",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T15:20:35.497Z",
      "date_published": "2026-07-18T13:10:02.920Z",
      "date_updated": "2026-07-28T01:47:48.525Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.1.0 Denial of Service via rand() Sorting",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00307,
        "percentile": 0.2298
      },
      "nvd": {
        "published": "2026-07-18T14:17:08.780",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58359",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Malformed input raises an exception that escapes the request-handling boundary and terminates the affected process.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-m52v-24p8-654f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-rand-sorting",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2024-58360",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:22:08.178Z",
      "date_published": "2026-07-16T12:23:14.567Z",
      "date_updated": "2026-07-18T02:49:27.174Z",
      "publisher": "VulnCheck",
      "title": "stoatchat before 0.7.8 Unrestricted Account Creation",
      "affected": {
        "vendors": [
          "stoatchat"
        ],
        "products": [
          {
            "vendor": "stoatchat",
            "product": "stoatchat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1173",
          "name": "Improper Use of Validation Framework",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17496
      },
      "nvd": {
        "published": "2026-07-16T13:16:23.000",
        "lastModified": "2026-07-18T03:16:34.433",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58360",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The registration path fails to enforce invite-only, email-verification, CAPTCHA, and shield-verification gates, allowing unrestricted creation of unverified accounts.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1173"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-f26h-rqjq-qqjq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/stoatchat/stoatchat/commit/eda36436a862bcab92f7ac2cf1c2dd88c41e52a4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/stoatchat-before-unrestricted-account-creation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2024-58361",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:40:52.916Z",
      "date_published": "2026-07-18T13:10:03.607Z",
      "date_updated": "2026-07-28T01:47:49.210Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.0.4 Denial of Service via Parser Exception",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16258
      },
      "nvd": {
        "published": "2026-07-18T14:17:08.917",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58361",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The surrealdb request path lets attacker-controlled input reach an uncaught exception that terminates service processing.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-qjrv-v6qp-x99x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-parser-exception",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2024-58362",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:40:52.916Z",
      "date_published": "2026-07-18T13:10:04.263Z",
      "date_updated": "2026-07-28T01:47:49.887Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 1.5.5 Query Injection via RPC API",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-75",
          "name": "Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00367,
        "percentile": 0.29415
      },
      "nvd": {
        "published": "2026-07-18T14:17:09.047",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58362",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A crafted bincode object embeds a subquery that the sign-in or sign-up path executes with system or editor authority.",
        "basis": [
          "CNA",
          "CWE-75"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-64f8-pjgr-9wmr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-query-injection-via-rpc-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 772,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2024-58363",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:40:52.916Z",
      "date_published": "2026-07-18T13:10:04.938Z",
      "date_updated": "2026-07-28T01:47:50.565Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 1.5.4 Authentication Bypass via Database Switch",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00194,
        "percentile": 0.0933
      },
      "nvd": {
        "published": "2026-07-18T14:17:09.187",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58363",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The surrealdb access path accepts an identity or request signal that is insufficient to authenticate the actor for the requested operation.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-gh9f-6xm2-c4j2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-authentication-bypass-via-database-switch",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 370,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2024-58364",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:40:52.916Z",
      "date_published": "2026-07-18T13:10:05.569Z",
      "date_updated": "2026-07-28T01:47:51.243Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 1.2.1 Denial of Service via Parsing Error",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16257
      },
      "nvd": {
        "published": "2026-07-18T14:17:09.320",
        "lastModified": "2026-07-22T19:16:51.900",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58364",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SurrealDB span rendering throws an uncaught exception when a malformed query places an error on a line terminator.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-8xff-473h-f863",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-parsing-error",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 314,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2024-58365",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:40:52.916Z",
      "date_published": "2026-07-18T13:10:06.241Z",
      "date_updated": "2026-07-28T01:47:51.921Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 1.2.0 Denial of Service via Nonexistent Function",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16258
      },
      "nvd": {
        "published": "2026-07-18T14:17:09.460",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58365",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-6wr5-jmpr-mjcx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-nonexistent-function",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 277,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2024-58366",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:40:52.916Z",
      "date_published": "2026-07-18T13:10:06.939Z",
      "date_updated": "2026-07-28T01:47:52.571Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 1.1.1 Format String via Scripting Functions",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-134",
          "name": "Use of Externally-Controlled Format String",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22223
      },
      "nvd": {
        "published": "2026-07-18T14:17:09.600",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58366",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "rquickjs passes attacker-controlled text as a format string instead of as inert data.",
        "basis": [
          "CNA",
          "CWE-134"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-q3gg-m8hr-h4x4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-format-string-via-scripting-functions",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 298,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2024-58367",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:40:52.916Z",
      "date_published": "2026-07-18T13:10:07.604Z",
      "date_updated": "2026-07-28T01:47:53.305Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.0.4 Improper Authorization via SELECT Permissions",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12
      },
      "nvd": {
        "published": "2026-07-18T14:17:09.737",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58367",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SurrealDB applies field permissions inconsistently across projections, aliases, expressions, filters, and mutation return paths, so denied field values remain observable.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-9722-9j67-vjcr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-improper-authorization-via-select-permissions",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2024-58368",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:40:52.917Z",
      "date_published": "2026-07-18T13:10:08.303Z",
      "date_updated": "2026-07-28T01:47:54.003Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 1.1.0 Denial of Service via HTTP Headers",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00376,
        "percentile": 0.30338
      },
      "nvd": {
        "published": "2026-07-18T14:17:09.867",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58368",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SurrealDB lets malformed ID, database, or namespace headers raise an uncaught exception, terminating request handling instead of returning a bounded error.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-m24x-r6q3-2vp9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-http-headers",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 282,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2024-58369",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:40:52.917Z",
      "date_published": "2026-07-18T13:10:08.965Z",
      "date_updated": "2026-07-28T01:47:54.726Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 1.1.1 Denial of Service via Global Parameters",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16259
      },
      "nvd": {
        "published": "2026-07-18T14:17:10.003",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58369",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The router permits custom parameters or functions at root and namespace levels where they are unsupported, and the resulting uncaught exception panics the server.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-jm4v-58r5-66hj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-global-parameters",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2024-58370",
      "id_year": 2024,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:40:52.917Z",
      "date_published": "2026-07-18T13:10:09.658Z",
      "date_updated": "2026-07-28T01:47:55.449Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 1.1.0 Uncontrolled Recursion Denial of Service",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19622
      },
      "nvd": {
        "published": "2026-07-18T14:17:10.140",
        "lastModified": "2026-07-22T19:16:53.173",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2024-58370",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SurrealQL parser recursively handles nested IF, RELATE, and attribute expressions without a depth limit, allowing stack exhaustion.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-6r8p-hpg7-825g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-uncontrolled-recursion-denial-of-service",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 277,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-0152",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2024-12-31T19:08:58.246Z",
      "date_published": "2026-07-30T16:57:15.862Z",
      "date_updated": "2026-07-30T17:40:37.424Z",
      "publisher": "ibm",
      "title": "IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Engineering Requirements Management DOORS and DOORS Web Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05861
      },
      "nvd": {
        "published": "2026-07-30T19:16:57.910",
        "lastModified": "2026-07-30T19:31:02.643",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-0152",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unauthenticated input is embedded in the DOORS web interface as executable browser script without the required HTML or JavaScript escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279145",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 376,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-3110",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-02T07:56:08.672Z",
      "date_published": "2026-07-08T16:19:38.337Z",
      "date_updated": "2026-07-08T16:30:47.077Z",
      "publisher": "OpenVPN",
      "title": "OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy",
      "affected": {
        "vendors": [
          "OpenVPN"
        ],
        "products": [
          {
            "vendor": "OpenVPN",
            "product": "Access Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security@openvpn.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17542
      },
      "nvd": {
        "published": "2026-07-08T17:17:19.650",
        "lastModified": "2026-07-10T17:00:29.527",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-3110",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Access Server HTTP parser accepts a message boundary that a front-end proxy can interpret differently, enabling request desynchronization.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://openvpn.net/as-docs/as-3-2-release-notes.html",
          "host": "openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-5017",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-05-20T20:41:45.614Z",
      "date_published": "2026-07-11T05:35:47.239Z",
      "date_updated": "2026-07-14T14:27:57.432Z",
      "publisher": "Wordfence",
      "title": "Catalyst Connect Zoho CRM Client Portal <= 2.2.0 - Authenticated (Administrator+) SQL Injection via uid Parameter",
      "affected": {
        "vendors": [
          "catalyst2020"
        ],
        "products": [
          {
            "vendor": "catalyst2020",
            "product": "Catalyst Connect Zoho CRM Client Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17413
      },
      "nvd": {
        "published": "2026-07-11T07:16:44.453",
        "lastModified": "2026-07-14T15:16:54.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-5017",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Catalyst Connect Zoho CRM Client Portal, attacker-controlled values reach an SQL statement without the required escaping or parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/37ce28de-f41d-42f8-8467-0af5e643a739?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://wordpress.org/plugins/catalyst-connect-client-portal/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/BFS-Lab/BFSDV/blob/main/client%20portal%20SQL%20injection-1.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 524,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-6784",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-06-27T12:28:50.508Z",
      "date_published": "2026-07-11T05:35:44.591Z",
      "date_updated": "2026-07-13T14:28:15.594Z",
      "publisher": "Wordfence",
      "title": "Code Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution",
      "affected": {
        "vendors": [
          "tigroumeow"
        ],
        "products": [
          {
            "vendor": "tigroumeow",
            "product": "Code Engine – PHP Snippets, AI Functions & Automation for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00469,
        "percentile": 0.38157
      },
      "nvd": {
        "published": "2026-07-11T07:16:44.637",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-6784",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A contributor can invoke the code-engine feature because the action is not restricted to the role intended to execute code.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1a5f970a-e6a0-4dc7-8e99-342a32f5fd49?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3345666",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 376,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-8412",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-07-31T09:41:28.725Z",
      "date_published": "2026-07-14T07:42:47.016Z",
      "date_updated": "2026-07-14T12:31:14.506Z",
      "publisher": "suse",
      "title": "VMDP: Potential buffer overflow in the RtlQueryRegistryValues function",
      "affected": {
        "vendors": [
          "SUSE"
        ],
        "products": [
          {
            "vendor": "SUSE",
            "product": "Virtual Machine Driver Pack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0009,
        "percentile": 0.00545
      },
      "nvd": {
        "published": "2026-07-14T09:16:39.637",
        "lastModified": "2026-07-15T21:00:44.900",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-8412",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation fails to preserve a valid bound, initialization state, type, ownership rule, or object lifetime before memory access.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-8412",
          "host": "bugzilla.suse.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-8591",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-08-05T11:53:15.931Z",
      "date_published": "2026-07-06T10:16:53.685Z",
      "date_updated": "2026-07-06T11:05:59.157Z",
      "publisher": "WSO2",
      "title": "Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification",
      "affected": {
        "vendors": [
          "WSO2"
        ],
        "products": [
          {
            "vendor": "WSO2",
            "product": "WSO2 Identity Server"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 API Manager"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 API Control Plane"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 Traffic Manager"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 Universal Gateway"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 Open Banking AM"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 Identity Server as Key Manager"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 Open Banking IAM"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 30,
        "versionRangeCount": 30,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:ed10eef1-636d-4fbe-9993-6890dfa878f8",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05789
      },
      "nvd": {
        "published": "2026-07-06T11:16:25.713",
        "lastModified": "2026-07-09T13:04:39.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-8591",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches WSO2 Identity Server page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4343/",
          "host": "security.docs.wso2.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 30
      }
    },
    {
      "cve_id": "CVE-2025-9205",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-08-19T17:53:39.009Z",
      "date_published": "2026-07-24T02:31:59.945Z",
      "date_updated": "2026-07-24T12:23:09.617Z",
      "publisher": "Wordfence",
      "title": "MapSVG Lite <= 8.14.0 - Authenticated (Contributor+) Stored Cross-Site Scripting",
      "affected": {
        "vendors": [
          "oyatek"
        ],
        "products": [
          {
            "vendor": "oyatek",
            "product": "MapSVG – Vector maps, Image maps, Google Maps"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08529
      },
      "nvd": {
        "published": "2026-07-24T04:16:50.297",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-9205",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Map option attributes are stored without sufficient sanitization or output escaping and later execute as browser script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a2dab9d3-a890-4c66-a825-e30329e37a60?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mapsvg-lite-interactive-vector-maps/tags/8.7.5/php/Admin/Admin.php#L233",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3608308%40mapsvg-lite-interactive-vector-maps&new=3608308%40mapsvg-lite-interactive-vector-maps",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-10656",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-17T20:34:13.390Z",
      "date_published": "2026-07-29T08:32:35.881Z",
      "date_updated": "2026-07-29T15:08:20.019Z",
      "publisher": "Wordfence",
      "title": "Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Missing Authorization to Unauthenticated Privilege Escalation via Admin Account Creation",
      "affected": {
        "vendors": [
          "holest"
        ],
        "products": [
          {
            "vendor": "holest",
            "product": "Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00492,
        "percentile": 0.39621
      },
      "nvd": {
        "published": "2026-07-29T10:16:31.407",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-10656",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The unauthenticated user_filter path creates administrator accounts without an authorization check.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1f891b68-72c4-4f94-bd49-52576ad710f9?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/excel-like-price-change-for-woocommerce-and-wp-e-commerce-light/trunk/sellingcommander.php#L3725",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-11698",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-13T16:23:13.209Z",
      "date_published": "2026-07-14T15:05:32.682Z",
      "date_updated": "2026-07-14T15:53:19.355Z",
      "publisher": "Rockwell",
      "title": "CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "CompactLogix® 5380 Recovery Image      Compact GuardLogix® 5380 Recovery Image      CompactLogix® 5480 Recovery Image      ControlLogix® 5580 Recovery Image      GuardLogix® 5580 Recovery Image"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.2266
      },
      "nvd": {
        "published": "2026-07-14T16:16:41.837",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-11698",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Controller boot firmware copies attacker-supplied file data into a fixed buffer without enforcing the destination size.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1781.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-11977",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-20T16:45:21.982Z",
      "date_published": "2026-07-10T07:48:44.939Z",
      "date_updated": "2026-07-10T10:07:52.289Z",
      "publisher": "Wordfence",
      "title": "HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion",
      "affected": {
        "vendors": [
          "happyforms"
        ],
        "products": [
          {
            "vendor": "happyforms",
            "product": "Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00501,
        "percentile": 0.40134
      },
      "nvd": {
        "published": "2026-07-10T09:16:51.153",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-11977",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "happyforms_get_form_partial accepts an attacker-selected partial path and includes the resulting PHP file without confining it to the intended template set.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e31119ab-963d-48a4-9948-0a0dce761918?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.svn.wordpress.org/happyforms/trunk/core/classes/class-wp-customize-form-manager.php",
          "host": "plugins.svn.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.svn.wordpress.org/happyforms/trunk/core/helpers/helper-form-templates.php",
          "host": "plugins.svn.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3494912%40happyforms&new=3494912%40happyforms",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 626,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-12011",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-21T12:56:46.593Z",
      "date_published": "2026-07-14T15:03:11.708Z",
      "date_updated": "2026-07-14T15:26:29.661Z",
      "publisher": "Rockwell",
      "title": "CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "CompactLogix® 5370      Compact GuardLogix® 5370      ControlLogix® 5570      GuardLogix® 5570"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22661
      },
      "nvd": {
        "published": "2026-07-14T15:16:53.323",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-12011",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A malformed controller project reaches a fixed-size project-processing buffer without a sufficient bounds check, producing the classic buffer-overflow condition that forces 5370/5570 controllers into a major non-recoverable fault.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-120",
          "Rockwell Automation advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Rockwell Automation advisory https://www.rockwellautomation.com/es-es/trust-center/security-advisories/advisory.SD1781.html; it confirms invalid-project input, CWE-120, affected firmware, and corrected firmware, but it does not disclose the copy site, buffer bounds, or patch diff."
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1781.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-12012",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-21T12:58:15.696Z",
      "date_published": "2026-07-14T15:04:18.725Z",
      "date_updated": "2026-07-14T15:26:00.338Z",
      "publisher": "Rockwell",
      "title": "CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "CompactLogix® 5370      Compact GuardLogix® 5370      ControlLogix® 5570      GuardLogix® 5570"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.2266
      },
      "nvd": {
        "published": "2026-07-14T15:16:54.210",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-12012",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Invalid controller file data can exceed a destination buffer and force the controller into a major non-recoverable fault, although the copy site is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-120",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Rockwell Automation advisory SD1781 at https://www.rockwellautomation.com/es-es/trust-center/security-advisories/advisory.SD1781.html; it confirms CWE-120, invalid file data, affected and corrected firmware, and MNRF impact, but it does not identify the destination buffer or copy site."
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1781.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-12506",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-30T14:05:29.287Z",
      "date_published": "2026-07-08T20:47:28.863Z",
      "date_updated": "2026-07-09T13:53:34.205Z",
      "publisher": "GitLab",
      "title": "Use of Incorrectly-Resolved Name or Reference in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-706",
          "name": "Use of Incorrectly-Resolved Name or Reference",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00187,
        "percentile": 0.0856
      },
      "nvd": {
        "published": "2026-07-08T21:16:44.493",
        "lastModified": "2026-07-09T20:17:33.973",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-12506",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GitLab resolves a repository reference differently for web display and archive download, so one repository name can select different content across the two paths.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-706"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://hackerone.com/reports/3351460",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/578988",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2025-12799",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-06T11:15:12.378Z",
      "date_published": "2026-07-07T16:18:57.555Z",
      "date_updated": "2026-07-29T16:24:51.191Z",
      "publisher": "redhat",
      "title": "Jastow: jastow cross-site scripting attack due to unsanitized uri",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform 8.1.7.GA"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 240,
        "versionEntryCount": 229,
        "versionRangeCount": 229,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16009
      },
      "nvd": {
        "published": "2026-07-07T17:16:34.640",
        "lastModified": "2026-07-29T17:16:49.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-12799",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Under the affected Undertow and Jastow configuration, unescaped URI characters reach generated HTML and can become executable script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36342",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36343",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36344",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36345",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2025-12799",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2413071",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 229
      }
    },
    {
      "cve_id": "CVE-2025-13146",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-13T20:03:00.603Z",
      "date_published": "2026-07-22T11:35:15.786Z",
      "date_updated": "2026-07-22T12:19:54.699Z",
      "publisher": "Wordfence",
      "title": "Contact Form 7 – Dynamic Text Extension <= 5.0.6 - Unauthenticated Arbitrary Shortcode Execution",
      "affected": {
        "vendors": [
          "sevenspark"
        ],
        "products": [
          {
            "vendor": "sevenspark",
            "product": "Contact Form 7 – Dynamic Text Extension"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19622
      },
      "nvd": {
        "published": "2026-07-22T12:16:54.763",
        "lastModified": "2026-07-22T16:30:26.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-13146",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated value reaches WordPress do_shortcode without validation, so shortcode syntax is interpreted.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3e5ad3a7-03c5-4085-b330-bc77e7e46cea?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/trunk/contact-form-7-dynamic-text-extension.php#L765",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/trunk/contact-form-7-dynamic-text-extension.php#L782",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/trunk/includes/utilities.php#L265",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3430784/",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-13475",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-20T12:17:18.234Z",
      "date_published": "2026-07-04T12:49:06.782Z",
      "date_updated": "2026-07-06T13:55:26.159Z",
      "publisher": "WSO2",
      "title": "Cross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Products Allows Unauthorized Data Exposure",
      "affected": {
        "vendors": [
          "WSO2"
        ],
        "products": [
          {
            "vendor": "WSO2",
            "product": "WSO2 Identity Server"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 API Manager"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:ed10eef1-636d-4fbe-9993-6890dfa878f8",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05427
      },
      "nvd": {
        "published": "2026-07-04T13:16:30.083",
        "lastModified": "2026-07-09T17:55:35.993",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-13475",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Consent is keyed by application name without tenant scope, so consent from one tenant is reused for a same-named application in another tenant.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-1613/",
          "host": "security.docs.wso2.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 690,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2025-13968",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-03T15:29:18.491Z",
      "date_published": "2026-07-11T03:44:23.106Z",
      "date_updated": "2026-07-15T13:37:26.829Z",
      "publisher": "Wordfence",
      "title": "Starboard Suite Reservation Calendars <= 3.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "affected": {
        "vendors": [
          "starboardsuite"
        ],
        "products": [
          {
            "vendor": "starboardsuite",
            "product": "Starboard Suite Reservation Calendars"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09474
      },
      "nvd": {
        "published": "2026-07-11T05:16:30.190",
        "lastModified": "2026-07-15T14:17:00.773",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-13968",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6e8a3628-b7cf-4f1a-89dc-d7e58257b2e4?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/starboard-suite-reservation-calendars/trunk/starboard-suite.php#L64",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/starboard-suite-reservation-calendars/tags/3.0.0/starboard-suite.php#L64",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/starboard-suite-reservation-calendars/trunk/starboard-suite.php#L78",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/starboard-suite-reservation-calendars/tags/3.0.0/starboard-suite.php#L78",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3551037%40starboard-suite-reservation-calendars&new=3551037%40starboard-suite-reservation-calendars",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 475,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-14562",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-12T10:03:51.120Z",
      "date_published": "2026-07-29T19:02:26.038Z",
      "date_updated": "2026-07-29T19:33:59.228Z",
      "publisher": "GitLab",
      "title": "Incorrect Authorization in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13205
      },
      "nvd": {
        "published": "2026-07-29T20:17:00.067",
        "lastModified": "2026-08-03T13:44:10.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-14562",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to commit changes to a project after being removed as a member, due to improper authorization checks on merge request collaboration settings.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://hackerone.com/reports/3460445",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/583889",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 382,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2025-14785",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-16T14:13:31.998Z",
      "date_published": "2026-07-08T11:30:34.021Z",
      "date_updated": "2026-07-08T17:09:49.942Z",
      "publisher": "Wordfence",
      "title": "Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'seedprodnestedmenuwidget' Shortcode",
      "affected": {
        "vendors": [
          "seedprod"
        ],
        "products": [
          {
            "vendor": "seedprod",
            "product": "Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04824
      },
      "nvd": {
        "published": "2026-07-08T12:17:18.223",
        "lastModified": "2026-07-08T18:16:28.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-14785",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ba751f98-f86c-451b-8a12-a2e9e76768e5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3565979/coming-soon/trunk/app/nestednavmenu.php?old=3422960&old_path=coming-soon%2Ftrunk%2Fapp%2Fnestednavmenu.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 553,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-15646",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T10:47:01.107Z",
      "date_published": "2026-07-01T14:38:03.727Z",
      "date_updated": "2026-07-01T18:09:08.371Z",
      "publisher": "CPANSec",
      "title": "HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion",
      "affected": {
        "vendors": [
          "BPS"
        ],
        "products": [
          {
            "vendor": "BPS",
            "product": "HTML::Gumbo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00512,
        "percentile": 0.40821
      },
      "nvd": {
        "published": "2026-07-01T16:16:29.657",
        "lastModified": "2026-07-02T17:39:57.427",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-15646",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HTML::Gumbo treats a template element as a text node and calls strlen() on the incompatible object, reading past the heap allocation and serializing those bytes.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bestpractical/HTML-Gumbo/commit/15c0598909d4a64f47ef0a1abc5051f4e113c186.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/release/BPS/HTML-Gumbo-0.19/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://bugs.debian.org/1104789",
          "host": "bugs.debian.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 652,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-15662",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T14:04:23.537Z",
      "date_published": "2026-07-27T06:00:01.242Z",
      "date_updated": "2026-07-27T15:52:23.770Z",
      "publisher": "WPScan",
      "title": "Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthenticated Arbitrary File Read and Server-Side Request Forgery",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Printcart Web to Print Product Designer for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17707
      },
      "nvd": {
        "published": "2026-07-27T07:16:23.680",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-15662",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server accepts an attacker-controlled destination without constraining the resolved request target to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/6294afde-d23a-4634-a49a-168ce463278c/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-15665",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T11:11:48.893Z",
      "date_published": "2026-07-14T06:00:01.908Z",
      "date_updated": "2026-07-14T12:47:58.589Z",
      "publisher": "WPScan",
      "title": "BEAF < 4.7.1 - Admin+ Stored XSS via Widget Shortcode Field",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Ultimate Before After Image Slider & Gallery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03236
      },
      "nvd": {
        "published": "2026-07-14T06:16:41.087",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-15665",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Ultimate Before After Image Slider & Gallery page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/754f0960-efc8-426f-bb1d-7cceec920910/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-15666",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T04:58:39.190Z",
      "date_published": "2026-07-01T05:45:06.959Z",
      "date_updated": "2026-07-01T14:25:58.436Z",
      "publisher": "VulDB",
      "title": "Open Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based overflow",
      "affected": {
        "vendors": [
          "Open Asset Import Library"
        ],
        "products": [
          {
            "vendor": "Open Asset Import Library",
            "product": "Assimp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02487
      },
      "nvd": {
        "published": "2026-07-01T07:16:21.077",
        "lastModified": "2026-07-01T15:16:23.077",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-15666",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled model dimensions can make SceneCombiner::Copy write beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/374595",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/374595/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2025-15666",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844487",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/assimp/assimp/issues/6079",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2025-15667",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T05:16:18.510Z",
      "date_published": "2026-07-06T11:15:08.893Z",
      "date_updated": "2026-07-06T18:50:01.768Z",
      "publisher": "VulDB",
      "title": "GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "GPAC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00112,
        "percentile": 0.0161
      },
      "nvd": {
        "published": "2026-07-06T12:16:38.457",
        "lastModified": "2026-07-06T19:16:53.743",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-15667",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The nalu_out_bs cleanup path can free the same allocation twice.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376292",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376292/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2025-15667",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846839",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/issues/3403",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/TimChan2001/pocs/raw/refs/heads/main/poc-gpac-1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/commit/f29f955f2a3b5e8e507caad3e52319f961bf37bf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 473,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-15668",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T05:16:20.854Z",
      "date_published": "2026-07-06T11:45:07.439Z",
      "date_updated": "2026-07-07T14:03:00.156Z",
      "publisher": "VulDB",
      "title": "GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "GPAC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02563
      },
      "nvd": {
        "published": "2026-07-06T12:16:39.630",
        "lastModified": "2026-07-07T15:16:41.887",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-15668",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted sgpd entry drives sgpd_del_entry beyond its heap buffer bounds.",
        "basis": [
          "CNA record",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376293",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376293/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2025-15668",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846851",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/issues/3398",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/TimChan2001/pocs/raw/refs/heads/main/poc-gpac-0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/commit/f29f955f2a3b5e8e507caad3e52319f961bf37bf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 474,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-23350",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-01-14T01:07:21.737Z",
      "date_published": "2026-07-01T14:36:19.755Z",
      "date_updated": "2026-07-01T16:03:30.696Z",
      "publisher": "nvidia",
      "title": "NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "BlueField GA"
          },
          {
            "vendor": "NVIDIA",
            "product": "BlueField LTS22"
          },
          {
            "vendor": "NVIDIA",
            "product": "BlueField LTS23"
          },
          {
            "vendor": "NVIDIA",
            "product": "BlueField LTS24"
          },
          {
            "vendor": "NVIDIA",
            "product": "ConnectX GA"
          },
          {
            "vendor": "NVIDIA",
            "product": "ConnectX LTS22"
          },
          {
            "vendor": "NVIDIA",
            "product": "ConnectX LTS23"
          },
          {
            "vendor": "NVIDIA",
            "product": "ConnectX LTS24"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18874
      },
      "nvd": {
        "published": "2026-07-01T16:16:29.767",
        "lastModified": "2026-07-01T18:32:29.917",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-23350",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BlueField GA lets attacker-controlled input reach an out-of-bounds write.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23350",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-23350",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5699",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2025-23351",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-01-14T01:07:21.737Z",
      "date_published": "2026-07-01T14:39:03.200Z",
      "date_updated": "2026-07-01T16:03:10.537Z",
      "publisher": "nvidia",
      "title": "NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "BlueField GA"
          },
          {
            "vendor": "NVIDIA",
            "product": "BlueField LTS22"
          },
          {
            "vendor": "NVIDIA",
            "product": "BlueField LTS23"
          },
          {
            "vendor": "NVIDIA",
            "product": "BlueField LTS24"
          },
          {
            "vendor": "NVIDIA",
            "product": "ConnectX GA"
          },
          {
            "vendor": "NVIDIA",
            "product": "ConnectX LTS22"
          },
          {
            "vendor": "NVIDIA",
            "product": "ConnectX LTS23"
          },
          {
            "vendor": "NVIDIA",
            "product": "ConnectX LTS24"
          },
          {
            "vendor": "NVIDIA",
            "product": "ConnectX-4"
          },
          {
            "vendor": "NVIDIA",
            "product": "ConnectX-4 LX"
          }
        ],
        "affectedBlockCount": 10,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18875
      },
      "nvd": {
        "published": "2026-07-01T16:16:29.903",
        "lastModified": "2026-07-01T18:32:29.917",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-23351",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The device command interface writes beyond its destination buffer when a virtual-function user supplies crafted command input.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23351",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-23351",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5699",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 10,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2025-27462",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-02-26T09:16:54.461Z",
      "date_published": "2026-07-09T14:27:03.467Z",
      "date_updated": "2026-07-09T16:06:58.873Z",
      "publisher": "XEN",
      "title": "WinPVDrivers: Excessive permissions on user-exposed devices",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Windows PV drivers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@xen.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05433
      },
      "nvd": {
        "published": "2026-07-09T16:16:33.070",
        "lastModified": "2026-07-09T17:16:56.323",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-27462",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The XenCons user-facing device has no security descriptor, so its facilities inherit access that is broader than intended for unprivileged Windows users.",
        "basis": [
          "CNA",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xen.org/xsa/advisory-468.html",
          "host": "xenbits.xen.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 401,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-27463",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-02-26T09:16:54.461Z",
      "date_published": "2026-07-09T14:29:49.625Z",
      "date_updated": "2026-07-09T15:52:14.394Z",
      "publisher": "XEN",
      "title": "WinPVDrivers: Excessive permissions on user-exposed devices",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Windows PV drivers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@xen.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05433
      },
      "nvd": {
        "published": "2026-07-09T16:16:33.203",
        "lastModified": "2026-07-09T17:16:56.437",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-27463",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The product installs or enables a capability with default permissions that expose it to subjects outside the intended trust boundary.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xen.org/xsa/advisory-468.html",
          "host": "xenbits.xen.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-27464",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-02-26T09:16:54.461Z",
      "date_published": "2026-07-09T14:35:38.440Z",
      "date_updated": "2026-07-09T16:07:40.763Z",
      "publisher": "XEN",
      "title": "WinPVDrivers: Excessive permissions on user-exposed devices",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Windows PV drivers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@xen.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05433
      },
      "nvd": {
        "published": "2026-07-09T16:16:33.313",
        "lastModified": "2026-07-09T17:16:56.547",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-27464",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The XenBus user-facing device is created without a security descriptor, so its facilities inherit permissions that expose them to unprivileged users.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xen.org/xsa/advisory-468.html",
          "host": "xenbits.xen.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-30007",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-03-13T17:27:08.113Z",
      "date_published": "2026-07-10T17:50:33.868Z",
      "date_updated": "2026-07-14T22:25:37.912Z",
      "publisher": "VulnCheck",
      "title": "HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Management",
      "affected": {
        "vendors": [
          "hestiacp"
        ],
        "products": [
          {
            "vendor": "hestiacp",
            "product": "hestiacp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.01986,
        "percentile": 0.78631
      },
      "nvd": {
        "published": "2026-07-10T19:17:18.130",
        "lastModified": "2026-07-20T13:04:01.073",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-30007",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The hestiacp path inserts attacker-controlled text into an operating-system command without preserving the command grammar.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hestiacp/hestiacp/releases/tag/1.9.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/hestiacp/hestiacp/pull/5197",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/hestiacp/hestiacp/commit/a74babb739aa92e52b12d6ef52b6b9428ffbbb67",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/hestiacp-authenticated-os-command-injection-via-dns-record-management",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-30008",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-03-13T17:27:08.113Z",
      "date_published": "2026-07-10T17:51:07.679Z",
      "date_updated": "2026-07-14T22:25:38.598Z",
      "publisher": "VulnCheck",
      "title": "HestiaCP < 1.9.5 Stored XSS via DNS Record Management Interface",
      "affected": {
        "vendors": [
          "hestiacp"
        ],
        "products": [
          {
            "vendor": "hestiacp",
            "product": "hestiacp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07531
      },
      "nvd": {
        "published": "2026-07-10T19:17:19.243",
        "lastModified": "2026-07-20T12:57:39.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-30008",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unescaped DNS value breaks out of a data-sort-value HTML attribute because that output is not encoded with htmlspecialchars.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hestiacp/hestiacp/releases/tag/1.9.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/hestiacp/hestiacp/pull/5196",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/hestiacp/hestiacp/commit/07dda18ef0087ea981ff84d4d5757774cf2124b0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/hestiacp-stored-xss-via-dns-record-management-interface",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 514,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-32781",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-10T12:51:12.278Z",
      "date_published": "2026-07-15T16:31:56.122Z",
      "date_updated": "2026-07-15T17:29:51.557Z",
      "publisher": "GitHub_M",
      "title": "Apollo: Apollo Portal release endpoint allows cross-application configuration disclosure via releaseId",
      "affected": {
        "vendors": [
          "apolloconfig"
        ],
        "products": [
          {
            "vendor": "apolloconfig",
            "product": "apollo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22751
      },
      "nvd": {
        "published": "2026-07-15T17:16:45.317",
        "lastModified": "2026-07-15T18:16:44.063",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-32781",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apollo Portal retrieves a release by identifier without binding the release's application and namespace to the caller's permissions.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apolloconfig/apollo/security/advisories/GHSA-jxpj-9j24-w337",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/apolloconfig/apollo/pull/5378",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/apolloconfig/apollo/commit/362735ded4f13b62f6ab9df135d7096066e8e291",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/apolloconfig/apollo/releases/tag/v2.5.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 599,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-36298",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-15T21:16:48.650Z",
      "date_published": "2026-07-30T14:21:48.973Z",
      "date_updated": "2026-07-31T22:54:44.854Z",
      "publisher": "ibm",
      "title": "Security Vulnerability in Ebics server affects IBM Sterling B2B Integrator and IBM Sterling File Gateway",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Sterling B2B Integrator"
          },
          {
            "vendor": "IBM",
            "product": "Sterling File Gateway"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05827
      },
      "nvd": {
        "published": "2026-07-30T15:16:22.110",
        "lastModified": "2026-07-31T23:17:22.727",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-36298",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says attacker-controlled input reaches executable syntax in Sterling B2B Integrator, while the input field and interpreter sink are not public.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280668",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 551,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2025-36374",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-15T21:16:56.325Z",
      "date_published": "2026-07-30T17:55:11.095Z",
      "date_updated": "2026-07-30T18:49:22.675Z",
      "publisher": "ibm",
      "title": "IBM DataPower Gateway affected by XML external entity injection",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "DataPower Gateway 10.6CD"
          },
          {
            "vendor": "IBM",
            "product": "DataPower Gateway 10.5.0"
          },
          {
            "vendor": "IBM",
            "product": "DataPower Gateway 10.6.0"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15319
      },
      "nvd": {
        "published": "2026-07-30T19:16:58.867",
        "lastModified": "2026-07-30T19:31:02.643",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-36374",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The XML parser resolves attacker-supplied external entities while processing a crafted document.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278748",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2025-36431",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-15T21:17:03.968Z",
      "date_published": "2026-07-30T14:36:56.833Z",
      "date_updated": "2026-07-30T16:14:23.516Z",
      "publisher": "ibm",
      "title": "XSS Security Vulnerability in response header affects IBM Sterling B2B Integrator and IBM Sterling File Gateway",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Sterling B2B Integrator"
          },
          {
            "vendor": "IBM",
            "product": "Sterling File Gateway"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05827
      },
      "nvd": {
        "published": "2026-07-30T15:16:23.057",
        "lastModified": "2026-07-30T17:16:27.480",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-36431",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280647",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 358,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-40945",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-16T09:06:15.879Z",
      "date_published": "2026-07-14T09:19:08.857Z",
      "date_updated": "2026-07-14T12:16:59.871Z",
      "publisher": "siemens",
      "title": "A vulnerability has been identified in COMOS V10.",
      "affected": {
        "vendors": [
          "Siemens"
        ],
        "products": [
          {
            "vendor": "Siemens",
            "product": "COMOS V10.4.5"
          },
          {
            "vendor": "Siemens",
            "product": "COMOS V10.6"
          },
          {
            "vendor": "Siemens",
            "product": "Designcenter NX"
          },
          {
            "vendor": "Siemens",
            "product": "Simcenter 3D"
          },
          {
            "vendor": "Siemens",
            "product": "Simcenter Femap V2506"
          },
          {
            "vendor": "Siemens",
            "product": "Simcenter Femap V2512"
          },
          {
            "vendor": "Siemens",
            "product": "Simcenter Nastran"
          },
          {
            "vendor": "Siemens",
            "product": "Simcenter STAR-CCM+"
          },
          {
            "vendor": "Siemens",
            "product": "Solid Edge SE2025"
          },
          {
            "vendor": "Siemens",
            "product": "Solid Edge SE2026"
          },
          {
            "vendor": "Siemens",
            "product": "Teamcenter Visualization V2412"
          },
          {
            "vendor": "Siemens",
            "product": "Teamcenter Visualization V2506"
          },
          {
            "vendor": "Siemens",
            "product": "Teamcenter Visualization V2512"
          },
          {
            "vendor": "Siemens",
            "product": "Tecnomatix Plant Simulation V2404"
          },
          {
            "vendor": "Siemens",
            "product": "Tecnomatix Plant Simulation V2504"
          },
          {
            "vendor": "Siemens",
            "product": "Tecnomatix Process Simulate"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-426",
          "name": "Untrusted Search Path",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 1.7999999999999998,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01566
      },
      "nvd": {
        "published": "2026-07-14T10:16:30.783",
        "lastModified": "2026-07-15T20:27:37.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-40945",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Siemens Industrial Edge Management searches an attacker-writable location when loading a dynamic library into a privileged process.",
        "basis": [
          "CNA",
          "CWE-426"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-288252.html",
          "host": "cert-portal.siemens.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 995,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2025-43892",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-18T14:46:53.847Z",
      "date_published": "2026-07-14T15:19:51.080Z",
      "date_updated": "2026-07-16T14:00:36.002Z",
      "publisher": "fortinet",
      "title": "A buffer over-read vulnerability in Fortinet FortiOS 7.",
      "affected": {
        "vendors": [
          "Fortinet"
        ],
        "products": [
          {
            "vendor": "Fortinet",
            "product": "FortiOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:psirt@fortinet.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00318,
        "percentile": 0.24186
      },
      "nvd": {
        "published": "2026-07-14T16:16:42.340",
        "lastModified": "2026-07-16T15:16:29.423",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-43892",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A length, offset, or termination error makes the program read beyond the end of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fortiguard.fortinet.com/psirt/#5944",
          "host": "fortiguard.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2025-44089",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-22T00:00:00.000Z",
      "date_published": "2026-07-22T00:00:00.000Z",
      "date_updated": "2026-07-24T19:04:11.077Z",
      "publisher": "mitre",
      "title": "An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21015
      },
      "nvd": {
        "published": "2026-07-22T21:17:10.460",
        "lastModified": "2026-07-24T20:16:59.877",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-44089",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says a crafted archive can lead ExpressZip to execute code but does not identify the parser, file-selection rule, or executable boundary that fails.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OV-0-VO/Public-references/blob/main/CVE-2025-44089.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-44090",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-22T00:00:00.000Z",
      "date_published": "2026-07-22T00:00:00.000Z",
      "date_updated": "2026-07-24T19:03:57.818Z",
      "publisher": "mitre",
      "title": "An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21571
      },
      "nvd": {
        "published": "2026-07-22T21:17:11.420",
        "lastModified": "2026-07-24T20:17:01.097",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-44090",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record says a crafted archive is downloaded and executed but does not identify the engineering failure that permits code execution.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://ohsoft.net/update/download.php",
          "host": "ohsoft.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/OV-0-VO/Public-references/blob/main/CVE-2025-44090.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-45422",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-22T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T17:27:54.190Z",
      "publisher": "mitre",
      "title": "Incorrect access control in Proximus b-box v8c.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30207
      },
      "nvd": {
        "published": "2026-07-09T21:16:54.167",
        "lastModified": "2026-07-10T18:53:55.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-45422",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An authenticated b-box user can change port-forwarding rules without the privilege required for that administrative action, although the exact check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "http://proximus.com",
          "host": "proximus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://b-box.com",
          "host": "b-box.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H/RL:U/RC:C/CR:H/IR:H/AR:H/MAV:N/MAC:L/MPR:N/MUI:N/MS:C/MC:H/MI:H/MA:H&version=3.1",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/Cedrico03/CVE-2025-45422---Bbox",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 165,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-45868",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-22T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-20T16:03:19.761Z",
      "publisher": "mitre",
      "title": "LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20361
      },
      "nvd": {
        "published": "2026-07-16T16:18:58.563",
        "lastModified": "2026-07-20T17:17:02.597",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-45868",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ComparisonServlet incorporates authenticated user input into a SQL query without preserving the boundary between data and SQL syntax.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.logicaldoc.com/",
          "host": "www.logicaldoc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/netero1010/Vulnerability-Disclosure/blob/main/CVE-2025-45868/README.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-45869",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-22T00:00:00.000Z",
      "date_published": "2026-07-13T00:00:00.000Z",
      "date_updated": "2026-07-13T19:29:41.809Z",
      "publisher": "mitre",
      "title": "LogicalDOC Enterprise Version up to and before v9.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.10018
      },
      "nvd": {
        "published": "2026-07-13T19:16:36.360",
        "lastModified": "2026-07-13T20:37:48.157",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-45869",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component request path lets a caller choose a server-side destination outside the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.logicaldoc.com/",
          "host": "www.logicaldoc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/netero1010/Vulnerability-Disclosure/blob/main/CVE-2025-45869/README.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-45870",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-04-22T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-20T15:33:25.104Z",
      "publisher": "mitre",
      "title": "LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized acc...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28959
      },
      "nvd": {
        "published": "2026-07-16T17:16:53.157",
        "lastModified": "2026-07-20T16:16:53.563",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-45870",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The fileExt parameter can select a path outside the OnlyOfficeEditor servlet's intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.logicaldoc.com/",
          "host": "www.logicaldoc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/netero1010/Vulnerability-Disclosure/blob/main/CVE-2025-45870/README.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-50324",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-06-16T00:00:00.000Z",
      "date_published": "2026-07-22T00:00:00.000Z",
      "date_updated": "2026-07-24T19:05:41.692Z",
      "publisher": "mitre",
      "title": "An issue in Milos Paripovic OneCommander v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00363,
        "percentile": 0.29035
      },
      "nvd": {
        "published": "2026-07-22T21:17:11.530",
        "lastModified": "2026-07-24T20:17:01.277",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-50324",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2025-50324 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.onecommander.com/",
          "host": "www.onecommander.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/OV-0-VO/Public-references/blob/main/CVE-2025-50324.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-50325",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-06-16T00:00:00.000Z",
      "date_published": "2026-07-22T00:00:00.000Z",
      "date_updated": "2026-07-24T19:17:11.474Z",
      "publisher": "mitre",
      "title": "BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20802
      },
      "nvd": {
        "published": "2026-07-22T21:17:11.647",
        "lastModified": "2026-07-24T20:17:01.467",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-50325",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says Bandizip can bypass Mark-of-the-Web protection but does not disclose the file, metadata, or state transition that fails.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://en.bandisoft.com/bandizip/help/zone-identifier/",
          "host": "en.bandisoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://en.bandisoft.com/bandizip/history/",
          "host": "en.bandisoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/OV-0-VO/Public-references/blob/main/CVE-2025-50325.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-50327",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-06-16T00:00:00.000Z",
      "date_published": "2026-07-22T00:00:00.000Z",
      "date_updated": "2026-07-24T19:15:23.122Z",
      "publisher": "mitre",
      "title": "An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31325
      },
      "nvd": {
        "published": "2026-07-22T21:17:11.760",
        "lastModified": "2026-07-24T20:17:01.633",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-50327",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record says Mark-of-the-Web can be bypassed but does not identify which file-handling or trust decision drops or ignores the mark.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fcorbelli/zpaqfranz/releases/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/OV-0-VO/Public-references/blob/main/CVE-2025-50327.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-50329",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-06-16T00:00:00.000Z",
      "date_published": "2026-07-22T00:00:00.000Z",
      "date_updated": "2026-07-24T19:13:10.771Z",
      "publisher": "mitre",
      "title": "An issue in ConeXware, Inc Power Archiver v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0057,
        "percentile": 0.43948
      },
      "nvd": {
        "published": "2026-07-22T21:17:11.873",
        "lastModified": "2026-07-24T20:17:01.797",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-50329",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record states that powerarc.exe permits remote privilege escalation and code execution but does not disclose the enabling check, parser, or memory error.",
        "basis": [
          "CNA",
          "CWE-693",
          "https://www.powerarchiver.com/"
        ],
        "deepDive": true,
        "notes": "Primary source inspected: https://www.powerarchiver.com/. The vendor site exposes no CVE advisory, patch, vulnerable code path, or causal check, so the archive-memory cause remains undetermined."
      },
      "references": [
        {
          "url": "https://www.powerarchiver.com/",
          "host": "www.powerarchiver.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/OV-0-VO/Public-references/blob/main/CVE-2025-50329.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/OV-0-VO/Public-references/commit/20437207859288ad1502fed2caebc38be27a3450",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-50330",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-06-16T00:00:00.000Z",
      "date_published": "2026-07-22T00:00:00.000Z",
      "date_updated": "2026-07-24T19:11:13.648Z",
      "publisher": "mitre",
      "title": "An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00363,
        "percentile": 0.29034
      },
      "nvd": {
        "published": "2026-07-22T21:17:11.983",
        "lastModified": "2026-07-24T20:17:01.963",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-50330",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record reports privilege escalation and code execution through zipgenius.exe but does not disclose the enabling engineering failure.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://zipgenius.it/en/downloads-2/",
          "host": "zipgenius.it",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/OV-0-VO/Public-references/blob/main/CVE-2025-50330.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 158,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-50455",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-06-16T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_updated": "2026-07-27T17:40:00.291Z",
      "publisher": "mitre",
      "title": "SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00552,
        "percentile": 0.4306
      },
      "nvd": {
        "published": "2026-07-27T16:16:58.860",
        "lastModified": "2026-07-30T19:32:25.133",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-50455",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The customers search endpoint incorporates the order_by parameter into SQL without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.linkedin.com/posts/michael-chesang_cve-securityadvisory-appsec-activity-7360754900827365376-Z-IY",
          "host": "www.linkedin.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/threatlance-org/security-advisories/blob/main/CVE-2025-50455/advisory.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/threatlance-org/security-advisories/blob/main/CVE-2025-50455/poc.py",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-51677",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-06-16T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-20T18:14:01.358Z",
      "publisher": "mitre",
      "title": "An issue was discovered in openRISC OR1200 commit 83ac6b.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35519
      },
      "nvd": {
        "published": "2026-07-17T20:17:13.763",
        "lastModified": "2026-07-23T18:17:51.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-51677",
        "family": "HARDWARE_PHYSICAL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The synthesized OR1200 load-store-unit netlist produces a du_lsu_load_dat output that diverges from the RTL design under the same stimulus.",
        "basis": [
          "CNA",
          "CWE-116",
          "GitHub issue openrisc/mor1kx#160",
          "arXiv:2504.18812"
        ],
        "deepDive": true,
        "notes": "Inspected https://github.com/openrisc/mor1kx/issues/160 and https://arxiv.org/abs/2504.18812; both confirm RTL/netlist divergence found with Synopsys DC and Cadence Genus, while neither identifies a repaired RTL statement or synthesis transformation."
      },
      "references": [
        {
          "url": "https://github.com/openrisc/mor1kx/issues/160#issuecomment-2585618940",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.arxiv.org/abs/2504.18812",
          "host": "www.arxiv.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://mason.gmu.edu/~rsaravan/projects/synfuzz/cve/cve.html",
          "host": "mason.gmu.edu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-51678",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-06-16T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-20T17:56:52.867Z",
      "publisher": "mitre",
      "title": "An issue was discovered in RISC-V PicoRV32 commit 87c89a.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-704",
          "name": "Incorrect Type Conversion or Cast",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35518
      },
      "nvd": {
        "published": "2026-07-17T20:17:13.887",
        "lastModified": "2026-07-23T18:17:51.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-51678",
        "family": "HARDWARE_PHYSICAL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The processor can associate a PCPI instruction with the wrong memory address, producing an invalid hardware state transition.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-704"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/YosysHQ/picorv32/issues/269",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.arxiv.org/abs/2504.18812",
          "host": "www.arxiv.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://mason.gmu.edu/~rsaravan/projects/synfuzz/cve/cve.html",
          "host": "mason.gmu.edu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 137,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-51684",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-06-16T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T19:11:17.155Z",
      "publisher": "mitre",
      "title": "CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12231
      },
      "nvd": {
        "published": "2026-07-30T20:16:51.793",
        "lastModified": "2026-07-31T20:16:44.277",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-51684",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CleverTap/clevertap-web-sdk/issues/416",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-53379",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-06-27T15:44:12.816Z",
      "date_published": "2026-07-14T15:13:02.254Z",
      "date_updated": "2026-07-22T13:57:33.288Z",
      "publisher": "fortinet",
      "title": "A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.",
      "affected": {
        "vendors": [
          "Fortinet"
        ],
        "products": [
          {
            "vendor": "Fortinet",
            "product": "FortiAuthenticator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C"
        },
        {
          "source": "NVD:psirt@fortinet.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00385,
        "percentile": 0.31249
      },
      "nvd": {
        "published": "2026-07-14T16:16:42.477",
        "lastModified": "2026-07-15T18:30:56.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-53379",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FortiAuthenticator can read beyond the valid bounds of an input or object allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-146",
          "host": "fortiguard.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2025-53827",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-07-09T14:14:52.530Z",
      "date_published": "2026-07-06T14:31:07.220Z",
      "date_updated": "2026-07-08T03:56:33.632Z",
      "publisher": "GitHub_M",
      "title": "ownCloud Core: Updater has an exposed dangerous method or function",
      "affected": {
        "vendors": [
          "owncloud"
        ],
        "products": [
          {
            "vendor": "owncloud",
            "product": "ownCloud Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-749",
          "name": "Exposed Dangerous Method or Function",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28874
      },
      "nvd": {
        "published": "2026-07-06T16:16:26.740",
        "lastModified": "2026-07-08T05:16:24.890",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-53827",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The updater exposes code-executing functionality to an administrator, but the public advisory does not identify the dangerous method or the missing restriction around it.",
        "basis": [
          "CNA",
          "CWE-749",
          "https://github.com/owncloud/security-advisories/security/advisories/GHSA-hvcx-ph66-mmvw"
        ],
        "deepDive": true,
        "notes": "The official advisory confirms administrator-level reachability and recommends 10.15.3 or disabling Updater, but publishes no method, request, or patch path."
      },
      "references": [
        {
          "url": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-hvcx-ph66-mmvw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-53828",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-07-09T14:14:52.530Z",
      "date_published": "2026-07-06T14:41:55.647Z",
      "date_updated": "2026-07-08T03:56:34.441Z",
      "publisher": "GitHub_M",
      "title": "SharePoint for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)",
      "affected": {
        "vendors": [
          "owncloud"
        ],
        "products": [
          {
            "vendor": "owncloud",
            "product": "SharePoint"
          },
          {
            "vendor": "owncloud",
            "product": "ownCloud 10"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14147
      },
      "nvd": {
        "published": "2026-07-06T16:16:26.903",
        "lastModified": "2026-07-08T05:16:25.877",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-53828",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SharePoint follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-4m66-rpfj-m5f6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 490,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-53829",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-07-09T14:14:52.531Z",
      "date_published": "2026-07-06T14:46:40.933Z",
      "date_updated": "2026-07-08T03:56:35.191Z",
      "publisher": "GitHub_M",
      "title": "ownCloud 10 is vulnerable to Relative Path Traversal",
      "affected": {
        "vendors": [
          "owncloud"
        ],
        "products": [
          {
            "vendor": "owncloud",
            "product": "ownCloud 10"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26026
      },
      "nvd": {
        "published": "2026-07-06T16:16:27.033",
        "lastModified": "2026-07-08T05:16:25.977",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-53829",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An administrative input can traverse outside the intended ownCloud path namespace and select code-bearing files.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-4439-4wxm-c9px",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-53830",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-07-09T14:14:52.531Z",
      "date_published": "2026-07-06T15:17:01.924Z",
      "date_updated": "2026-07-08T03:56:35.944Z",
      "publisher": "GitHub_M",
      "title": "Anti-Virus for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)",
      "affected": {
        "vendors": [
          "owncloud"
        ],
        "products": [
          {
            "vendor": "owncloud",
            "product": "Anti-Virus for ownCloud"
          },
          {
            "vendor": "owncloud",
            "product": "ownCloud 10"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17257
      },
      "nvd": {
        "published": "2026-07-06T16:16:27.157",
        "lastModified": "2026-07-08T05:16:26.073",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-53830",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A server-side request accepts an attacker-selected destination without enforcing the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-3wg4-mg27-hj4w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-53831",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-07-09T14:14:52.531Z",
      "date_published": "2026-07-06T16:23:35.257Z",
      "date_updated": "2026-07-06T18:49:06.961Z",
      "publisher": "GitHub_M",
      "title": "DrawIO for ownCloud 10 is vulnerable to Stored XSS",
      "affected": {
        "vendors": [
          "owncloud"
        ],
        "products": [
          {
            "vendor": "owncloud",
            "product": "DrawIO for ownCloud"
          },
          {
            "vendor": "owncloud",
            "product": "ownCloud 10"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06009
      },
      "nvd": {
        "published": "2026-07-06T17:16:26.870",
        "lastModified": "2026-07-06T19:16:54.250",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-53831",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DrawIO input is stored and later rendered into a web page without the escaping required for its HTML context.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/owncloud/security-advisories/security/advisories/GHSA-r9j8-fr2h-m47q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 506,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-56361",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-08-16T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-15T14:27:15.683Z",
      "publisher": "mitre",
      "title": "A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00411,
        "percentile": 0.33759
      },
      "nvd": {
        "published": "2026-07-14T22:16:50.857",
        "lastModified": "2026-07-17T03:18:44.757",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-56361",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A MoveToLevel transition followed by a conflicting OperationMode write creates a state combination that reaches an internal assertion.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/project-chip/connectedhomeip/issues/38619",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/project-chip/connectedhomeip/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 612,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-56362",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-08-16T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-15T14:23:19.667Z",
      "publisher": "mitre",
      "title": "A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26424
      },
      "nvd": {
        "published": "2026-07-14T23:17:27.193",
        "lastModified": "2026-07-17T03:10:14.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-56362",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A MoveToLevel command followed by OperationMode 2 leaves currentLevel outside the asserted range and reaches a fatal assertion.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/project-chip/connectedhomeip/issues/38618",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/project-chip/connectedhomeip/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-56363",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-08-16T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-15T14:21:50.878Z",
      "publisher": "mitre",
      "title": "A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00378,
        "percentile": 0.30545
      },
      "nvd": {
        "published": "2026-07-14T23:17:27.367",
        "lastModified": "2026-07-17T03:07:54.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-56363",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ReadRevisionAttribute dereferences a cluster delegate without first proving that the delegate pointer is non-null.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/project-chip/connectedhomeip/issues/39173",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/project-chip/connectedhomeip/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 509,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-56364",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-08-16T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-15T14:20:03.829Z",
      "publisher": "mitre",
      "title": "A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25659
      },
      "nvd": {
        "published": "2026-07-14T23:17:27.467",
        "lastModified": "2026-07-17T03:00:07.473",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-56364",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path consumes a variable or optional value before establishing that it was initialized.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/project-chip/connectedhomeip/issues/36711",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/project-chip/connectedhomeip/pull/36729",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/project-chip/connectedhomeip/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-56365",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-08-16T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-15T14:17:52.828Z",
      "publisher": "mitre",
      "title": "A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28915
      },
      "nvd": {
        "published": "2026-07-14T23:17:27.593",
        "lastModified": "2026-07-17T03:19:43.137",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-56365",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CodegenDataModelProvider::Invoke treats a nonexistent endpoint and cluster as valid, allowing the request to reach a fatal assertion in ProcessCommandDataIB.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/project-chip/connectedhomeip/issues/37184",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/project-chip/connectedhomeip/pull/37207",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/project-chip/connectedhomeip/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-58146",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-08-26T06:48:41.443Z",
      "date_published": "2026-07-09T14:42:22.690Z",
      "date_updated": "2026-07-09T16:07:56.939Z",
      "publisher": "XEN",
      "title": "XAPI UTF-8 string handling",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "XAPI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@xen.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03563
      },
      "nvd": {
        "published": "2026-07-09T16:16:33.687",
        "lastModified": "2026-07-09T17:16:56.657",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-58146",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "XAPI accepts strings under one UTF-8 rule and later processes them under stricter libraries, while some database update paths also reuse unsanitized values, allowing malformed state to stop event processing or prevent database reload.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xen.org/xsa/advisory-474.html",
          "host": "xenbits.xen.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2025/09/09/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://xenbits.xen.org/xsa/advisory-474.html",
          "host": "xenbits.xen.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 713,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-58151",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-08-26T06:48:41.444Z",
      "date_published": "2026-07-09T14:45:16.531Z",
      "date_updated": "2026-07-09T15:41:25.431Z",
      "publisher": "XEN",
      "title": "varstored: TOCTOU issues with mapped guest memory",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "varstored"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@xen.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02114
      },
      "nvd": {
        "published": "2026-07-09T16:16:33.817",
        "lastModified": "2026-07-09T17:16:56.770",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-58151",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Missing compiler barriers let the guest change a shared-buffer value after validation and before it indexes a jump table.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xen.org/xsa/advisory-478.html",
          "host": "xenbits.xen.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/01/27/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://xenbits.xen.org/xsa/advisory-478.html",
          "host": "xenbits.xen.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 479,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-58902",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-05T10:50:39.330Z",
      "date_published": "2026-07-02T11:14:39.340Z",
      "date_updated": "2026-07-02T12:51:06.576Z",
      "publisher": "Patchstack",
      "title": "WordPress Lighthouse theme <= 1.2.12 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "AncoraThemes"
        ],
        "products": [
          {
            "vendor": "AncoraThemes",
            "product": "Lighthouse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19576
      },
      "nvd": {
        "published": "2026-07-02T12:16:51.187",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-58902",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Lighthouse include path accepts an attacker-controlled filename that can select a local file outside the intended include set.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/lighthouseschool/vulnerability/wordpress-lighthouse-theme-1-2-12-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 70,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-59172",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-10T13:24:49.360Z",
      "date_published": "2026-07-27T14:03:14.214Z",
      "date_updated": "2026-07-27T15:04:04.155Z",
      "publisher": "ERIC",
      "title": "Improper Neutralization of Special Elements used in an OS Command Vulnerability",
      "affected": {
        "vendors": [
          "Ericsson"
        ],
        "products": [
          {
            "vendor": "Ericsson",
            "product": "Packet Core Controller (PCC)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:85b1779b-6ecd-4f52-bcc5-73eac4659dcf",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.078
      },
      "nvd": {
        "published": "2026-07-27T15:16:45.017",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-59172",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled command elements reach an operating-system command context in Ericsson Packet Core Controller without required neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-pcc-july-2026",
          "host": "www.ericsson.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-59177",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-10T13:24:49.361Z",
      "date_published": "2026-07-27T14:11:59.865Z",
      "date_updated": "2026-07-27T15:04:26.143Z",
      "publisher": "ERIC",
      "title": "Generation of Error Message Containing Sensitive Information Vulnerability",
      "affected": {
        "vendors": [
          "Ericsson"
        ],
        "products": [
          {
            "vendor": "Ericsson",
            "product": "Ericsson Packet Core Controller (PCC)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:85b1779b-6ecd-4f52-bcc5-73eac4659dcf",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04383
      },
      "nvd": {
        "published": "2026-07-27T15:16:45.893",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-59177",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.",
        "basis": [
          "CNA",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-pcc-july-2026",
          "host": "www.ericsson.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-59178",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-10T13:24:49.361Z",
      "date_published": "2026-07-27T14:15:45.592Z",
      "date_updated": "2026-07-27T15:06:03.400Z",
      "publisher": "ERIC",
      "title": "Exposure of Sensitive System Information to an Unauthorized Control Sphere Vulnerability",
      "affected": {
        "vendors": [
          "Ericsson"
        ],
        "products": [
          {
            "vendor": "Ericsson",
            "product": "Packet Core Controller (PCC)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:85b1779b-6ecd-4f52-bcc5-73eac4659dcf",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04383
      },
      "nvd": {
        "published": "2026-07-27T15:16:46.020",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-59178",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The endpoint returns user and system details to an observer who lacks authority to receive them.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-pcc-july-2026",
          "host": "www.ericsson.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-59180",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-10T13:24:49.362Z",
      "date_published": "2026-07-27T14:19:16.119Z",
      "date_updated": "2026-07-27T15:08:17.243Z",
      "publisher": "ERIC",
      "title": "Use of Hard-coded Credentials Vulnerability",
      "affected": {
        "vendors": [
          "Ericsson"
        ],
        "products": [
          {
            "vendor": "Ericsson",
            "product": "Packet Core Controller (PCC)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:85b1779b-6ecd-4f52-bcc5-73eac4659dcf",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00111,
        "percentile": 0.01512
      },
      "nvd": {
        "published": "2026-07-27T15:16:46.170",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-59180",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected component generates, stores, validates, or uses a credential or authenticity value without the required secrecy or binding.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-pcc-july-2026",
          "host": "www.ericsson.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-59181",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-10T13:24:49.362Z",
      "date_published": "2026-07-27T14:21:48.696Z",
      "date_updated": "2026-07-27T15:07:53.787Z",
      "publisher": "ERIC",
      "title": "Path traversal Vulnerability",
      "affected": {
        "vendors": [
          "Ericsson"
        ],
        "products": [
          {
            "vendor": "Ericsson",
            "product": "Packet Core Controller (PCC)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-35",
          "name": "Path Traversal: '.../...//'",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:85b1779b-6ecd-4f52-bcc5-73eac4659dcf",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18727
      },
      "nvd": {
        "published": "2026-07-27T15:16:46.300",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-59181",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Ericsson management endpoint lets a caller traverse outside the intended directory and change permissions on a selected filesystem object.",
        "basis": [
          "CNA",
          "CWE-35"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-pcc-july-2026",
          "host": "www.ericsson.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-59615",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-18T03:19:23.202Z",
      "date_published": "2026-07-06T20:09:31.634Z",
      "date_updated": "2026-07-07T13:11:29.305Z",
      "publisher": "qualcomm",
      "title": "Use After Free in Computer Vision",
      "affected": {
        "vendors": [
          "Qualcomm, Inc."
        ],
        "products": [
          {
            "vendor": "Qualcomm, Inc.",
            "product": "Snapdragon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 60,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:product-security@qualcomm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00064,
        "percentile": 0.0002
      },
      "nvd": {
        "published": "2026-07-06T21:16:52.077",
        "lastModified": "2026-07-07T17:03:12.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-59615",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Mapping and unmapping persistent-memory buffers can run without the synchronization needed to keep the referenced buffer alive across both operations.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html",
          "host": "docs.qualcomm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 155,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 60
      }
    },
    {
      "cve_id": "CVE-2025-59616",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-18T03:19:23.202Z",
      "date_published": "2026-07-06T20:09:32.700Z",
      "date_updated": "2026-07-07T13:11:17.423Z",
      "publisher": "qualcomm",
      "title": "Use After Free in Computer Vision",
      "affected": {
        "vendors": [
          "Qualcomm, Inc."
        ],
        "products": [
          {
            "vendor": "Qualcomm, Inc.",
            "product": "Snapdragon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 48,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:product-security@qualcomm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00064,
        "percentile": 0.00021
      },
      "nvd": {
        "published": "2026-07-06T21:16:52.513",
        "lastModified": "2026-07-07T17:00:24.487",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-59616",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Repeated IOCTL calls can reuse the same buffer file descriptor after its backing object has already been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html",
          "host": "docs.qualcomm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 48
      }
    },
    {
      "cve_id": "CVE-2025-59617",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-18T03:19:23.202Z",
      "date_published": "2026-07-06T20:09:33.799Z",
      "date_updated": "2026-07-07T13:11:08.093Z",
      "publisher": "qualcomm",
      "title": "Use After Free in Computer Vision",
      "affected": {
        "vendors": [
          "Qualcomm, Inc."
        ],
        "products": [
          {
            "vendor": "Qualcomm, Inc.",
            "product": "Snapdragon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 48,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:product-security@qualcomm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00065,
        "percentile": 0.00022
      },
      "nvd": {
        "published": "2026-07-06T21:16:52.653",
        "lastModified": "2026-07-07T16:59:44.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-59617",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Repeated IOCTL calls using the same buffer file descriptor leave an object reachable after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html",
          "host": "docs.qualcomm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 48
      }
    },
    {
      "cve_id": "CVE-2025-59866",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-22T15:00:11.102Z",
      "date_published": "2026-07-17T17:22:03.343Z",
      "date_updated": "2026-07-17T17:52:43.779Z",
      "publisher": "HCL",
      "title": "The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable f...",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "DFMPro for CATIA"
          },
          {
            "vendor": "HCLSoftware",
            "product": "DFXAnalytics"
          },
          {
            "vendor": "HCLSoftware",
            "product": "DFXServer"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00074,
        "percentile": 0.001
      },
      "nvd": {
        "published": "2026-07-17T18:17:12.643",
        "lastModified": "2026-07-17T18:30:38.987",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-59866",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The installers leave an executable writable by non-administrative users, allowing a local user to replace code that a privileged context later runs.",
        "basis": [
          "CNA",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132365",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2025-60357",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-26T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-17T16:48:37.328Z",
      "publisher": "mitre",
      "title": "AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-943",
          "name": "Improper Neutralization of Special Elements in Data Query Logic",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20873
      },
      "nvd": {
        "published": "2026-07-17T14:17:19.003",
        "lastModified": "2026-07-17T18:47:13.683",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-60357",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The eventlog/agentEvent/list endpoint incorporates attacker-controlled values into NoSQL query logic without neutralizing query operators.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-943"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://ahnlab.com",
          "host": "ahnlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/Nullbyte3117/CVE-2025-60357",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-60835",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-26T00:00:00.000Z",
      "date_published": "2026-07-22T00:00:00.000Z",
      "date_updated": "2026-07-24T19:08:43.994Z",
      "publisher": "mitre",
      "title": "An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-35",
          "name": "Path Traversal: '.../...//'",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04485
      },
      "nvd": {
        "published": "2026-07-22T21:17:12.097",
        "lastModified": "2026-07-24T20:17:02.137",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-60835",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component file operation accepts an attacker-controlled path that escapes the intended directory or storage target.",
        "basis": [
          "CNA",
          "CWE-35"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rarlab.com/rar_add.htm",
          "host": "www.rarlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.izarc.org/",
          "host": "www.izarc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/OV-0-VO/Public-references/blob/main/CVE-2025-60835.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/OV-0-VO/Public-references/commit/834a2be23292cbb305053a5d78d4d95c096e43b5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 95,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-60931",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-09-26T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-29T18:12:36.155Z",
      "publisher": "mitre",
      "title": "An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14167
      },
      "nvd": {
        "published": "2026-07-29T17:16:50.367",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-60931",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The compensation-view request trusts a caller-controlled employee identifier without checking that the caller may view that employee.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.offsecguy.com/cve/infor/vulnerability/insecure-direct-object-references-idor",
          "host": "docs.offsecguy.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-62347",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-10T09:04:27.772Z",
      "date_published": "2026-07-31T15:16:02.020Z",
      "date_updated": "2026-07-31T17:39:58.918Z",
      "publisher": "HCL",
      "title": "HCL iControl was affected by Improper Input Validation vulnerability.",
      "affected": {
        "vendors": [
          "HCL"
        ],
        "products": [
          {
            "vendor": "HCL",
            "product": "HCL iControl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00185,
        "percentile": 0.08351
      },
      "nvd": {
        "published": "2026-07-31T16:16:56.500",
        "lastModified": "2026-07-31T18:17:08.400",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-62347",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected input handler accepts a value whose runtime type does not match the type required by its security-sensitive operation.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132395",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 313,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-62675",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-20T08:07:37.650Z",
      "date_published": "2026-07-14T15:15:12.695Z",
      "date_updated": "2026-07-14T16:02:45.423Z",
      "publisher": "fortinet",
      "title": "An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.",
      "affected": {
        "vendors": [
          "Fortinet"
        ],
        "products": [
          {
            "vendor": "Fortinet",
            "product": "FortiOS"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiPAM"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiProxy"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 17,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-113",
          "name": "Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:psirt@fortinet.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0.8999999999999999,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14923
      },
      "nvd": {
        "published": "2026-07-14T16:16:42.617",
        "lastModified": "2026-07-14T18:45:16.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-62675",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FortiOS permits attacker-controlled CRLF bytes to enter an HTTP response header, allowing those bytes to be interpreted as new header or response structure.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-113"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-152",
          "host": "fortiguard.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 462,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2025-62826",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-23T11:55:45.919Z",
      "date_published": "2026-07-14T15:19:46.918Z",
      "date_updated": "2026-07-14T16:02:27.387Z",
      "publisher": "fortinet",
      "title": "An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.",
      "affected": {
        "vendors": [
          "Fortinet"
        ],
        "products": [
          {
            "vendor": "Fortinet",
            "product": "FortiPAM"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiProxy"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiOS"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 17,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-113",
          "name": "Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:psirt@fortinet.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 1.1999999999999997,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17343
      },
      "nvd": {
        "published": "2026-07-14T16:16:42.850",
        "lastModified": "2026-07-14T18:46:00.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-62826",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted captive-portal input permits CRLF bytes to create additional HTTP header fields in the generated response.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-113"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-153",
          "host": "fortiguard.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 461,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2025-63579",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-27T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-09T19:45:11.618Z",
      "publisher": "mitre",
      "title": "Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-311",
          "name": "Missing Encryption of Sensitive Data",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-326",
          "name": "Inadequate Encryption Strength",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09962
      },
      "nvd": {
        "published": "2026-07-09T19:16:57.757",
        "lastModified": "2026-07-10T18:50:20.507",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-63579",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record reports unauthenticated address-book export and decryption but does not identify whether the enabling failure is an access check, key handling, or cryptographic validation error.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-200",
          "CWE-284",
          "CWE-311",
          "CWE-326"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/barisbaydur/CVE-2025-63579",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://global.kyocera.com/",
          "host": "global.kyocera.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 592,
        "referenceCount": 2,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-63913",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-27T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_updated": "2026-07-28T13:37:44.677Z",
      "publisher": "mitre",
      "title": "An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17962
      },
      "nvd": {
        "published": "2026-07-27T23:16:39.717",
        "lastModified": "2026-07-28T14:16:32.443",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-63913",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A crafted SBI PMU request causes denial of service, but the public record does not identify the resource or termination condition that fails.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/luojia65/opensbi-pmu2-crash",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-65336",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-18T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T18:27:20.234Z",
      "publisher": "mitre",
      "title": "Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24521
      },
      "nvd": {
        "published": "2026-07-30T21:16:50.690",
        "lastModified": "2026-07-31T19:17:01.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-65336",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The show_price_by_pdtId endpoint incorporates untrusted input into an SQL statement without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/ecommercefruitsbazarmaster/20250811-ecommerce-project-with-php-and-mysqli-fruits-bazar-show_price_by_pdtid.php-pid-sqli/20250811-ecommerce-project-with-php-and-mysqli-fruits-bazar-show_price_by_pdtid.php-pid-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-65337",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-18T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T17:40:12.190Z",
      "publisher": "mitre",
      "title": "Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address field.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05135
      },
      "nvd": {
        "published": "2026-07-29T21:17:45.760",
        "lastModified": "2026-07-30T19:16:59.047",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-65337",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "pageEditMember.php renders the address field as browser markup without the required output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.sourcecodester.com/php/12258/fantastic-blog-cms-php.html",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/XSS_cve/fantasticblog/XSS1.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-65340",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-18T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T17:39:30.597Z",
      "publisher": "mitre",
      "title": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17663
      },
      "nvd": {
        "published": "2026-07-29T21:17:45.880",
        "lastModified": "2026-07-30T19:17:00.743",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-65340",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-betweendates-detailsreports.php-fromdate-sqli/20250811-hospital-management-system-betweendates-detailsreports.php-fromdate-sqli.md#injection-techniques-as-identified-by-sqlmap",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-65341",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-18T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T19:08:58.577Z",
      "publisher": "mitre",
      "title": "Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04576
      },
      "nvd": {
        "published": "2026-07-30T21:16:51.667",
        "lastModified": "2026-07-31T20:16:45.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-65341",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/XSS_cve/ecommercefruitsbazar/XSS.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-65342",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-18T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T18:45:44.327Z",
      "publisher": "mitre",
      "title": "code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04581
      },
      "nvd": {
        "published": "2026-07-30T21:16:51.777",
        "lastModified": "2026-07-31T19:17:02.480",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-65342",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/XSS_cve/bloodsystem/XSS1.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-65720",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-18T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-16T18:12:05.298Z",
      "publisher": "mitre",
      "title": "An issue in Open Source GPT Researcher v3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00722,
        "percentile": 0.50419
      },
      "nvd": {
        "published": "2026-07-15T22:16:45.417",
        "lastModified": "2026-07-16T19:16:44.107",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-65720",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Attacker-controlled command data reaches a command interpreter without safe argument separation or complete command-language neutralization.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/assafelovic/gpt-researcher",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.ox.security/blog/gpt-researcher-remote-code-execution",
          "host": "www.ox.security",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/",
          "host": "www.ox.security",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 158,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-66076",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-21T11:20:58.862Z",
      "date_published": "2026-07-02T11:14:40.329Z",
      "date_updated": "2026-07-02T14:52:09.760Z",
      "publisher": "Patchstack",
      "title": "WordPress Woostify Sites Library plugin <= 1.6.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "dylan ngo"
        ],
        "products": [
          {
            "vendor": "dylan ngo",
            "product": "Woostify Sites Library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11043
      },
      "nvd": {
        "published": "2026-07-02T12:16:52.743",
        "lastModified": "2026-07-02T15:16:55.320",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-66076",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/woostify-sites-library/vulnerability/wordpress-woostify-sites-library-plugin-1-6-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-66390",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-28T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T15:47:05.047Z",
      "publisher": "mitre",
      "title": "In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to ...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.2719
      },
      "nvd": {
        "published": "2026-07-21T14:16:32.797",
        "lastModified": "2026-07-23T18:28:35.280",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-66390",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The registration API remains callable when signup is hidden and selects the target tenant from a caller-controlled Host or tenant value, although Microsoft disputes that this behavior crosses a security boundary.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The embedded record includes the supplier position that the observed behavior was a configuration or state issue and did not cross a security boundary."
      },
      "references": [
        {
          "url": "https://github.com/bountyyfi/Azure-APIM-Cross-Tenant-Signup-Bypass",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/bountyyfi/Azure-APIM-Cross-Tenant-Signup-Bypass/security/advisories/GHSA-vcwf-73jp-r7mv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 945,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-67403",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-08T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T14:25:11.674Z",
      "publisher": "mitre",
      "title": "Sourcecodester CASAP Automated Enrollment System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17662
      },
      "nvd": {
        "published": "2026-07-29T22:16:51.033",
        "lastModified": "2026-07-30T15:16:23.200",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-67403",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The update_class.php class_name parameter is incorporated into an SQL statement without separating data from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/automated/20250811-casap-automated-enrollment-system-update_class.php-class_name-sqli/20250811-casap-automated-enrollment-system-update_class.php-class_name-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 133,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-67404",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-08T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T14:27:28.832Z",
      "publisher": "mitre",
      "title": "Sourcecodester CASAP Automated Enrollment System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.1766
      },
      "nvd": {
        "published": "2026-07-29T22:16:51.163",
        "lastModified": "2026-07-30T15:16:23.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-67404",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The fname, lname, and student_class parameters reach an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/automated/20250811-casap-automated-enrollment-system-save_stud.php-fname-sqli/20250811-casap-automated-enrollment-system-save_stud.php-fname-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 152,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-67405",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-08T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T13:34:26.035Z",
      "publisher": "mitre",
      "title": "Sourcecodester CASAP Automated Enrollment System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.0656
      },
      "nvd": {
        "published": "2026-07-29T22:16:51.283",
        "lastModified": "2026-07-30T14:16:43.797",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-67405",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The new_password parameter is incorporated into an SQL command without separating data from SQL syntax.",
        "basis": [
          "CNA record",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/automated/20250811-casap-automated-enrollment-system-update_password.php-new_password-sqli/20250811-casap-automated-enrollment-system-update_password.php-new_password-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-67406",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-08T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T13:32:40.765Z",
      "publisher": "mitre",
      "title": "https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection ...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10408
      },
      "nvd": {
        "published": "2026-07-29T22:16:51.393",
        "lastModified": "2026-07-30T14:16:44.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-67406",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CVE-2025-67406 builds an SQL statement from attacker-controlled text without parameterization or SQL-context separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/advocate/20250811-advocate-office-management-system-activate_case.php-id-sqli/20250811-advocate-office-management-system-activate_case.php-id-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1192,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-67407",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-08T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T13:30:55.794Z",
      "publisher": "mitre",
      "title": "Sourcecodester CASAP Automated Enrollment System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.0656
      },
      "nvd": {
        "published": "2026-07-29T22:16:51.510",
        "lastModified": "2026-07-30T14:16:44.260",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-67407",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The student update handler inserts the fname and student_class parameters into SQL without separating them from query syntax.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/automated/20250811-casap-automated-enrollment-system-update_student.php-fname-sqli/20250811-casap-automated-enrollment-system-update_student.php-fname-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 145,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-67408",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-08T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T13:28:28.871Z",
      "publisher": "mitre",
      "title": "Sourcecodester CASAP Automated Enrollment System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.0656
      },
      "nvd": {
        "published": "2026-07-29T22:16:51.627",
        "lastModified": "2026-07-30T14:16:44.920",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-67408",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In the affected component, attacker-controlled input reaches an SQL statement without the required parameter binding or SQL-context escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/automated/20250811-casap-automated-enrollment-system-save_user.php-status-sqli/20250811-casap-automated-enrollment-system-save_user.php-status-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 127,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-67649",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-09T19:10:43.240Z",
      "date_published": "2026-07-31T11:40:25.708Z",
      "date_updated": "2026-07-31T19:49:42.174Z",
      "publisher": "CERT-PL",
      "title": "Unauthenticated  SQL Injection in PHP Jabbers - Car Rental Script script",
      "affected": {
        "vendors": [
          "PHP Jabbers"
        ],
        "products": [
          {
            "vendor": "PHP Jabbers",
            "product": "Car Rental Script"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19535
      },
      "nvd": {
        "published": "2026-07-31T12:16:48.107",
        "lastModified": "2026-07-31T20:16:45.553",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-67649",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled query text is concatenated into an SQL statement without parameter binding or equivalent grammar separation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2025-67649/",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.phpjabbers.com/car-rental-script/",
          "host": "www.phpjabbers.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-67650",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-09T19:10:43.240Z",
      "date_published": "2026-07-31T11:40:40.346Z",
      "date_updated": "2026-07-31T19:51:58.085Z",
      "publisher": "CERT-PL",
      "title": "Authenticated SQL Injection in PHP Jabbers scripts",
      "affected": {
        "vendors": [
          "PHP Jabbers"
        ],
        "products": [
          {
            "vendor": "PHP Jabbers",
            "product": "Appointment Scheduler"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Bus Reservation System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Car Park Booking System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Car Rental Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Cinema Booking System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Event Booking Calendar"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Event Ticketing System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Hotel Booking System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Cleaning Business Software"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Equipment Rental Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Food Delivery Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Member Login Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Member Directory Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Availability Calendar"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "PHP Event Calendar"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "PHP Newsletter Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Product Comparison Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Ticket Support Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "PHP Shopping Cart"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Auto Classifieds Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Business Directory Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Availability Booking Calendar"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Time Slots Booking Calendar"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Restaurant Booking System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Shuttle Booking Software"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Meeting Room Booking System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Rental Property Booking Calendar"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Service Booking Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Limo Booking Software"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Taxi Booking Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Job Listing Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Property Listing Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Travel Tours Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Vacation Rental Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Yacht Listing Script"
          }
        ],
        "affectedBlockCount": 35,
        "versionEntryCount": 35,
        "versionRangeCount": 35,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20155
      },
      "nvd": {
        "published": "2026-07-31T12:16:48.250",
        "lastModified": "2026-07-31T20:16:45.683",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-67650",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Authenticated sorting parameters enter SQL without preserving the boundary between parameter data and SQL syntax.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2025-67649/",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.phpjabbers.com/",
          "host": "www.phpjabbers.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 35,
        "affectedVersionEntryCount": 35
      }
    },
    {
      "cve_id": "CVE-2025-67651",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-09T19:10:43.240Z",
      "date_published": "2026-07-31T11:40:44.495Z",
      "date_updated": "2026-07-31T19:52:27.724Z",
      "publisher": "CERT-PL",
      "title": "CSRF in PHP Jabbers scripts",
      "affected": {
        "vendors": [
          "PHP Jabbers"
        ],
        "products": [
          {
            "vendor": "PHP Jabbers",
            "product": "Appointment Scheduler"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Bus Reservation System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Car Park Booking System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Car Rental Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Cinema Booking System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Event Booking Calendar"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Event Ticketing System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Hotel Booking System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Cleaning Business Software"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Equipment Rental Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Food Delivery Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Member Login Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Member Directory Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Availability Calendar"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "PHP Event Calendar"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "PHP Newsletter Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Product Comparison Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Ticket Support Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "PHP Shopping Cart"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Auto Classifieds Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Business Directory Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Availability Booking Calendar"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Time Slots Booking Calendar"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Restaurant Booking System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Shuttle Booking Software"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Meeting Room Booking System"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Rental Property Booking Calendar"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Service Booking Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Limo Booking Software"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Taxi Booking Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Job Listing Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Property Listing Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Travel Tours Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Vacation Rental Script"
          },
          {
            "vendor": "PHP Jabbers",
            "product": "Yacht Listing Script"
          }
        ],
        "affectedBlockCount": 35,
        "versionEntryCount": 35,
        "versionRangeCount": 35,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06276
      },
      "nvd": {
        "published": "2026-07-31T12:16:48.520",
        "lastModified": "2026-07-31T20:16:45.923",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-67651",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected PHP Jabbers actions accept authenticated state-changing requests without a CSRF token or protective SameSite cookie boundary.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2025-67649/",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.phpjabbers.com/",
          "host": "www.phpjabbers.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 35,
        "affectedVersionEntryCount": 35
      }
    },
    {
      "cve_id": "CVE-2025-68081",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-15T10:01:29.282Z",
      "date_published": "2026-07-23T11:17:46.637Z",
      "date_updated": "2026-07-23T14:54:19.963Z",
      "publisher": "Patchstack",
      "title": "WordPress WP-Polls plugin <= 2.77.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Lester Chan"
        ],
        "products": [
          {
            "vendor": "Lester Chan",
            "product": "WP-Polls"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06853
      },
      "nvd": {
        "published": "2026-07-23T12:17:05.170",
        "lastModified": "2026-07-23T16:17:12.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-68081",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WP-Polls rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-polls/vulnerability/wordpress-wp-polls-plugin-2-77-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 72,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-68640",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-20T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T15:46:53.127Z",
      "publisher": "mitre",
      "title": "The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authenti...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20562
      },
      "nvd": {
        "published": "2026-07-21T17:17:04.183",
        "lastModified": "2026-07-23T18:28:35.280",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-68640",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A valid Private Endpoint Token can enumerate and remove offline devices without proving account ownership or completing two-factor authentication.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/akadriu98/63123df9e7e3f154b3a0d54df178bb42",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/akadriu98/OE1102082402813",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 350,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69094",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-29T11:19:21.660Z",
      "date_published": "2026-07-02T11:14:41.285Z",
      "date_updated": "2026-07-02T14:54:16.860Z",
      "publisher": "Patchstack",
      "title": "WordPress Unicamp theme <= 2.2.2 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "ThemeMove"
        ],
        "products": [
          {
            "vendor": "ThemeMove",
            "product": "Unicamp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18934
      },
      "nvd": {
        "published": "2026-07-02T12:16:53.043",
        "lastModified": "2026-07-02T15:16:56.423",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69094",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says attacker-controlled input reaches executable syntax in Unicamp, while the input field and interpreter sink are not public.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/unicamp/vulnerability/wordpress-unicamp-theme-2-2-2-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 54,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69132",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-29T11:19:37.128Z",
      "date_published": "2026-07-02T11:14:42.311Z",
      "date_updated": "2026-07-02T19:42:34.931Z",
      "publisher": "Patchstack",
      "title": "WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Zozothemes"
        ],
        "products": [
          {
            "vendor": "Zozothemes",
            "product": "Corpkit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27152
      },
      "nvd": {
        "published": "2026-07-02T12:16:53.173",
        "lastModified": "2026-07-02T20:17:00.170",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69132",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public Patchstack record says a subscriber can obtain sensitive data but does not name the data or returning operation.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/corpkit/vulnerability/wordpress-corpkit-theme-1-0-5-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 64,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69133",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-29T11:19:37.128Z",
      "date_published": "2026-07-02T11:14:43.488Z",
      "date_updated": "2026-07-02T15:53:57.062Z",
      "publisher": "Patchstack",
      "title": "WordPress Tourmaster plugin <= 5.4.5 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "GoodLayers"
        ],
        "products": [
          {
            "vendor": "GoodLayers",
            "product": "Tourmaster"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31566
      },
      "nvd": {
        "published": "2026-07-02T12:16:53.300",
        "lastModified": "2026-07-02T16:16:29.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69133",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/tourmaster/vulnerability/wordpress-tourmaster-plugin-5-4-5-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 64,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69134",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-29T11:19:41.703Z",
      "date_published": "2026-07-02T11:14:44.457Z",
      "date_updated": "2026-07-02T12:13:33.033Z",
      "publisher": "Patchstack",
      "title": "WordPress OpenAI Chatbot for WordPress – Helper plugin <= 1.1.4 - Arbitrary Content Deletion vulnerability",
      "affected": {
        "vendors": [
          "Merkulove"
        ],
        "products": [
          {
            "vendor": "Merkulove",
            "product": "OpenAI Chatbot for WordPress – Helper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21325
      },
      "nvd": {
        "published": "2026-07-02T12:16:53.450",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69134",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/helper/vulnerability/wordpress-openai-chatbot-for-wordpress-helper-plugin-1-1-4-arbitrary-content-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69152",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-29T11:19:48.753Z",
      "date_published": "2026-07-02T11:14:45.464Z",
      "date_updated": "2026-07-02T12:50:09.625Z",
      "publisher": "Patchstack",
      "title": "WordPress Artale | Wedding Photography WordPress theme <= 2.2.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "ThemeGoods"
        ],
        "products": [
          {
            "vendor": "ThemeGoods",
            "product": "Artale | Wedding Photography WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.0717
      },
      "nvd": {
        "published": "2026-07-02T12:16:53.583",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69152",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/artale/vulnerability/wordpress-artale-wedding-photography-wordpress-theme-2-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69153",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-29T11:19:48.753Z",
      "date_published": "2026-07-02T11:14:46.468Z",
      "date_updated": "2026-07-02T14:44:40.367Z",
      "publisher": "Patchstack",
      "title": "WordPress Trendy Travel theme <= 6.7 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "designthemes"
        ],
        "products": [
          {
            "vendor": "designthemes",
            "product": "Trendy Travel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.0718
      },
      "nvd": {
        "published": "2026-07-02T12:16:53.700",
        "lastModified": "2026-07-02T15:16:56.517",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69153",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Trendy Travel page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/trendytravel/vulnerability/wordpress-trendy-travel-theme-6-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 76,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69154",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-29T11:19:54.137Z",
      "date_published": "2026-07-02T11:14:47.632Z",
      "date_updated": "2026-07-02T14:54:49.155Z",
      "publisher": "Patchstack",
      "title": "WordPress SpaLab | Beauty Salon WordPress Theme theme <= 6.7 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "designthemes"
        ],
        "products": [
          {
            "vendor": "designthemes",
            "product": "SpaLab | Beauty Salon WordPress Theme"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.0717
      },
      "nvd": {
        "published": "2026-07-02T12:16:53.820",
        "lastModified": "2026-07-02T15:16:56.610",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69154",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled theme data reaches a web page without the HTML-context neutralization required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/spalab/vulnerability/wordpress-spalab-beauty-salon-wordpress-theme-theme-6-7-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69155",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-29T11:19:54.137Z",
      "date_published": "2026-07-02T11:14:48.838Z",
      "date_updated": "2026-07-02T19:42:48.313Z",
      "publisher": "Patchstack",
      "title": "WordPress Fitness Zone WordPress Theme theme <= 5.7 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Designthemes"
        ],
        "products": [
          {
            "vendor": "Designthemes",
            "product": "Fitness Zone WordPress Theme"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07197
      },
      "nvd": {
        "published": "2026-07-02T12:16:53.937",
        "lastModified": "2026-07-02T20:17:00.300",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69155",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The theme places attacker-controlled content into an HTML or script context without the required contextual neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/fitnesszone/vulnerability/wordpress-fitness-zone-wordpress-theme-theme-5-7-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 91,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69156",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-29T11:19:54.137Z",
      "date_published": "2026-07-02T11:14:49.805Z",
      "date_updated": "2026-07-02T15:53:51.784Z",
      "publisher": "Patchstack",
      "title": "WordPress Kids Zone - Children WordPress Theme theme <= 5.4 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Design themes"
        ],
        "products": [
          {
            "vendor": "Design themes",
            "product": "Kids Zone - Children WordPress Theme"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07197
      },
      "nvd": {
        "published": "2026-07-02T12:16:54.060",
        "lastModified": "2026-07-02T16:16:29.310",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69156",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The theme renders unauthenticated input as executable browser markup, although the public record does not identify the input field or output context.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/kidszone/vulnerability/wordpress-kids-zone-children-wordpress-theme-theme-5-4-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69930",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T18:24:02.594Z",
      "publisher": "mitre",
      "title": "CodeAstro Membership Management System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17661
      },
      "nvd": {
        "published": "2026-07-30T21:16:51.893",
        "lastModified": "2026-07-31T19:17:02.690",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69930",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component query path incorporates attacker-controlled input into SQL without parameter separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/codeastro/20250811-membership-management-system-print_membership_card.php-id-sqli/20250811-membership-management-system-print_membership_card.php-id-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69931",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-08-03T16:27:40.060Z",
      "publisher": "mitre",
      "title": "CodeAstro Membership Management System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17665
      },
      "nvd": {
        "published": "2026-07-30T21:16:52.007",
        "lastModified": "2026-08-03T17:16:28.340",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69931",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The id parameter in delete_membership.php reaches an SQL statement without the required query parameter separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/codeastro/20250811-membership-management-system-delete_membership.php-id-sqli/20250811-membership-management-system-delete_membership.php-id-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69933",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T19:01:01.187Z",
      "publisher": "mitre",
      "title": "CodeAstro Membership Management System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17662
      },
      "nvd": {
        "published": "2026-07-30T21:16:52.120",
        "lastModified": "2026-07-31T19:17:02.900",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69933",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In the affected component, attacker-controlled values reach an SQL statement without the required escaping or parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/codeastro/20250811-membership-management-system-memberprofile.php-id-sqli/20250811-membership-management-system-memberprofile.php-id-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69934",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T19:00:58.264Z",
      "publisher": "mitre",
      "title": "CodeAstro Membership Management System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17664
      },
      "nvd": {
        "published": "2026-07-30T21:16:52.223",
        "lastModified": "2026-07-31T19:17:03.113",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69934",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component in CVE-2025-69934 incorporates attacker-controlled values or identifiers into a SQL statement without preserving the boundary between query syntax and data.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/codeastro/20250811-membership-management-system-delete_members.php-id-sqli/20250811-membership-management-system-delete_members.php-id-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69935",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T19:00:55.601Z",
      "publisher": "mitre",
      "title": "CodeAstro Membership Management System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17663
      },
      "nvd": {
        "published": "2026-07-30T21:16:52.333",
        "lastModified": "2026-07-31T19:17:03.420",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69935",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The fromDate parameter reaches SQL in report.php and revenue_report.php without preserving the boundary between data and SQL syntax.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/codeastro/20250811-membership-management-system-revenue_report.php-fromdate-sqli/20250811-membership-management-system-revenue_report.php-fromdate-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 141,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69936",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T19:00:52.675Z",
      "publisher": "mitre",
      "title": "CodeAstro Membership Management System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17662
      },
      "nvd": {
        "published": "2026-07-30T21:16:52.453",
        "lastModified": "2026-07-31T19:17:03.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69936",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "the affected component incorporates attacker-controlled input into an SQL statement without parameterization, allowing input syntax to alter the database query.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/codeastro/20250811-membership-management-system-edit_member.php-id-sqli/20250811-membership-management-system-edit_member.php-id-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69937",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T15:59:33.038Z",
      "publisher": "mitre",
      "title": "CodeAstro Membership Management System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17663
      },
      "nvd": {
        "published": "2026-07-30T21:16:52.563",
        "lastModified": "2026-07-31T16:16:56.643",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69937",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The edit_type.php endpoint incorporates the id parameter into an SQL statement without preserving the SQL data boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/codeastro/20250811-membership-management-system-edit_type.php-id-sqli/20250811-membership-management-system-edit_type.php-id-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 125,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69938",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T14:32:12.605Z",
      "publisher": "mitre",
      "title": "CodeAstro Membership Management System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17662
      },
      "nvd": {
        "published": "2026-07-30T21:16:52.670",
        "lastModified": "2026-07-31T15:16:27.233",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69938",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The renew.php handler incorporates membershipType into an SQL statement without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/codeastro/20250811-membership-management-system-renew.php-membershiptype-sqli/20250811-membership-management-system-renew.php-membershiptype-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69941",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T15:13:35.803Z",
      "publisher": "mitre",
      "title": "SourceCodester Tailor Management System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17664
      },
      "nvd": {
        "published": "2026-07-30T21:16:52.777",
        "lastModified": "2026-07-31T16:16:56.830",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69941",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "addmeasurement.php incorporates the id parameter into an SQL statement without separating data from SQL syntax.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/tailor/20250811-tailor-ms-addmeasurement.php-id-sqli/20250811-tailor-ms-addmeasurement.php-id-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69942",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T17:39:17.241Z",
      "publisher": "mitre",
      "title": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.1766
      },
      "nvd": {
        "published": "2026-07-29T22:16:51.750",
        "lastModified": "2026-07-30T19:17:00.953",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69942",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-view-patient.php-viewid-sqli/20250811-hospital-management-system-view-patient.php-viewid-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69943",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T14:10:28.659Z",
      "publisher": "mitre",
      "title": "kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19794
      },
      "nvd": {
        "published": "2026-07-29T22:16:51.870",
        "lastModified": "2026-07-30T15:16:23.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69943",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-get_doctor.php-doctor-sqli/20250811-hospital-management-system-get_doctor.php-doctor-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-get_doctor.php-specilizationid-sqli/20250811-hospital-management-system-get_doctor.php-specilizationid-sqli.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69944",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-29T21:47:20.079Z",
      "publisher": "mitre",
      "title": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "epss": {
        "score": 0.00143,
        "percentile": 0.04086
      },
      "nvd": {
        "published": "2026-07-29T22:16:51.987",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69944",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-view-medhistory.php-viewid-sqli/20250811-hospital-management-system-view-medhistory.php-viewid-sqli.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69945",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T13:23:26.802Z",
      "publisher": "mitre",
      "title": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06559
      },
      "nvd": {
        "published": "2026-07-29T22:16:52.097",
        "lastModified": "2026-07-30T14:16:45.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69945",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-edit-patient.php-editid-sqli/20250811-hospital-management-system-edit-patient.php-editid-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 110,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69946",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-08-03T17:03:28.562Z",
      "publisher": "mitre",
      "title": "SourceCodester Modern Loan Management System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26234
      },
      "nvd": {
        "published": "2026-07-31T21:17:29.390",
        "lastModified": "2026-08-03T17:16:28.520",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69946",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/loansystem/20250811-modern-loan-management-system-ajaxdata.php-district_id-sqli/20250811-modern-loan-management-system-ajaxdata.php-district_id-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/loansystem/20250811-modern-loan-management-system-ajaxdata.php-division_id-sqli/20250811-modern-loan-management-system-ajaxdata.php-division_id-sqli.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/loansystem/20250811-modern-loan-management-system-ajaxdata.php-region_id-sqli/20250811-modern-loan-management-system-ajaxdata.php-region_id-sqli.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/loansystem/20250811-modern-loan-management-system-ajaxdata.php-ward_id-sqli/20250811-modern-loan-management-system-ajaxdata.php-ward_id-sqli.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/loansystem/20250811-modern-loan-management-system-delete_group.php-id-sqli/20250811-modern-loan-management-system-delete_group.php-id-sqli.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/um-dsp/TaintRadar",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 165,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69947",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T15:03:21.965Z",
      "publisher": "mitre",
      "title": "SourceCodester Tailor Management System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.1766
      },
      "nvd": {
        "published": "2026-07-30T21:16:52.883",
        "lastModified": "2026-07-31T16:16:56.997",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69947",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The customeredit.php endpoint incorporates its caller-controlled id value into a database query without safe parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/tailor/20250811-tailor-ms-customeredit.php-id-sqli/20250811-tailor-ms-customeredit.php-id-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69948",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-08-03T17:02:03.179Z",
      "publisher": "mitre",
      "title": "SourceCodester Modern Loan Management System 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23002
      },
      "nvd": {
        "published": "2026-07-31T21:17:30.340",
        "lastModified": "2026-08-03T17:16:28.690",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69948",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The delete_group.php id parameter is incorporated into an SQL statement without separating data from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/loansystem/20250811-modern-loan-management-system-delete_group.php-id-sqli/20250811-modern-loan-management-system-delete_group.php-id-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-check_availability.php-emailid-sqli/20250811-hospital-management-system-check_availability.php-emailid-sqli.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/um-dsp/TaintRadar",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-69949",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T13:20:48.737Z",
      "publisher": "mitre",
      "title": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07281
      },
      "nvd": {
        "published": "2026-07-29T22:16:52.213",
        "lastModified": "2026-07-30T14:16:45.340",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-69949",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An email parameter reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-check_availability.php-email-sqli/20250811-hospital-management-system-check_availability.php-email-sqli.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-check_availability.php-emailid-sqli/20250811-hospital-management-system-check_availability.php-emailid-sqli.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-70796",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T00:00:00.000Z",
      "date_published": "2026-07-10T00:00:00.000Z",
      "date_updated": "2026-07-10T18:05:47.291Z",
      "publisher": "mitre",
      "title": "An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00565,
        "percentile": 0.43701
      },
      "nvd": {
        "published": "2026-07-10T17:16:52.767",
        "lastModified": "2026-07-10T19:17:19.613",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-70796",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Traversal sequences in an unauthenticated web request select files outside the intended web root.",
        "basis": [
          "CNA record",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/LPO26/Path-Traversal-via-Web-Interface-on-WTI-Devices/blob/main/CVE%20Summary",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/LPO26/Path-Traversal-via-Web-Interface-on-WTI-Devices/tree/main",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 386,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-71342",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:48:06.735Z",
      "date_published": "2026-07-04T01:23:31.768Z",
      "date_updated": "2026-07-06T16:28:15.247Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Undetected Remote Code Execution via idlelib.run.Executive.runcode",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00427,
        "percentile": 0.3517
      },
      "nvd": {
        "published": "2026-07-04T02:16:21.387",
        "lastModified": "2026-07-06T18:19:55.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71342",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "picklescan deserializes attacker-controlled bytes with object semantics that can invoke executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-m869-42cg-3xwr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-undetected-remote-code-execution-via-idlelib-run-executive-runcode",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71343",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:48:06.735Z",
      "date_published": "2026-07-04T01:23:32.430Z",
      "date_updated": "2026-07-07T02:23:27.888Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Arbitrary Code Execution via lib2to3.pgen2.pgen.ParserGenerator.make_label Detection Bypass",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.003,
        "percentile": 0.22337
      },
      "nvd": {
        "published": "2026-07-04T02:16:21.527",
        "lastModified": "2026-07-07T04:17:17.927",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71343",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The scanner fails to recognize a ParserGenerator.make_label reduction gadget, so a malicious pickle can pass inspection and execute when deserialized.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-p9w7-82w4-7q8m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-lib2to3-pgen2-pgen-parsergenerator-make-label-detection-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 299,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71345",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:48:06.735Z",
      "date_published": "2026-07-04T01:23:33.086Z",
      "date_updated": "2026-07-06T17:08:32.862Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_autograd_prof",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00427,
        "percentile": 0.3517
      },
      "nvd": {
        "published": "2026-07-04T02:16:21.670",
        "lastModified": "2026-07-06T18:19:55.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71345",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In picklescan, attacker-controlled serialized data is converted into live objects without restricting the permitted types or behaviors.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-4whj-rm5r-c2v8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-torch-utils-bottleneck-main-run-autograd-prof",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71347",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:48:06.735Z",
      "date_published": "2026-07-04T01:23:33.794Z",
      "date_updated": "2026-07-06T20:24:07.542Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Undetected Remote Code Execution via numpy.f2py.crackfortran.param_eval",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00445,
        "percentile": 0.36529
      },
      "nvd": {
        "published": "2026-07-04T02:16:21.803",
        "lastModified": "2026-07-06T21:16:52.797",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71347",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled serialized data is passed to a native object deserializer that can instantiate executable object graphs.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-cffc-mxrf-mhh4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-undetected-remote-code-execution-via-numpy-f2py-crackfortran-param-eval",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 356,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71353",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:55:02.882Z",
      "date_published": "2026-07-04T01:23:34.482Z",
      "date_updated": "2026-07-06T13:17:52.318Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Remote Code Execution via torch._dynamo.guards.GuardBuilder.get",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.003,
        "percentile": 0.22336
      },
      "nvd": {
        "published": "2026-07-04T02:16:21.933",
        "lastModified": "2026-07-06T18:19:55.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71353",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pickle scanner does not recognize a reduce chain using torch._dynamo.guards.GuardBuilder.get, so executable pickle content passes inspection and later runs when loaded.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-86cj-95qr-2p4f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-torch-dynamo-guards-guardbuilder-get",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71356",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:55:02.882Z",
      "date_published": "2026-07-04T01:23:35.187Z",
      "date_updated": "2026-07-06T15:03:48.468Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Arbitrary Code Execution via torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.003,
        "percentile": 0.22337
      },
      "nvd": {
        "published": "2026-07-04T02:16:22.063",
        "lastModified": "2026-07-06T18:19:55.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71356",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The picklescan path permits an attacker-controlled serialized object graph to reach a code-capable deserializer.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-f4x7-rfwp-v3xw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-torch-fx-experimental-symbolic-shapes-shapeenv-evaluate-guards-expression",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71359",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:55:02.882Z",
      "date_published": "2026-07-04T01:23:35.892Z",
      "date_updated": "2026-07-06T16:27:31.500Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Unsafe Deserialization via lib2to3.pgen2.grammar.Grammar.loads",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00427,
        "percentile": 0.35171
      },
      "nvd": {
        "published": "2026-07-04T02:16:22.197",
        "lastModified": "2026-07-06T18:19:55.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71359",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Grammar.loads detector can be bypassed so an attacker-controlled pickle is deserialized as an executable object graph.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-f54q-57x4-jg88",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-unsafe-deserialization-via-lib2to3-pgen2-grammar-grammar-loads",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71360",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:55:02.882Z",
      "date_published": "2026-07-04T01:23:36.583Z",
      "date_updated": "2026-07-07T02:26:21.516Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Remote Code Execution via Undetected idlelib.calltip.get_entity",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.003,
        "percentile": 0.22336
      },
      "nvd": {
        "published": "2026-07-04T02:16:22.327",
        "lastModified": "2026-07-07T04:17:20.117",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71360",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The picklescan path permits attacker-controlled serialized data or a dangerous object graph to reach a deserializer.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-9xph-j2h6-g47v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-undetected-idlelib-calltip-get-entity",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71362",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:01:42.505Z",
      "date_published": "2026-07-04T01:23:37.271Z",
      "date_updated": "2026-07-06T17:10:32.237Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Arbitrary Code Execution via Unsafe Deserialization in numpy.f2py.crackfortran",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.003,
        "percentile": 0.22337
      },
      "nvd": {
        "published": "2026-07-04T02:16:22.457",
        "lastModified": "2026-07-06T18:19:55.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71362",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "picklescan misses pickle payloads whose NumPy f2py reconstruction path calls eval on attacker-controlled strings.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-r8g5-cgf2-4m4m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-unsafe-deserialization-in-numpy-f2py-crackfortran",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71364",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:01:42.505Z",
      "date_published": "2026-07-04T01:23:37.959Z",
      "date_updated": "2026-07-07T16:58:20.730Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Arbitrary Code Execution via Undetected asyncio.unix_events._UnixSubprocessTransport._start",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00555,
        "percentile": 0.43158
      },
      "nvd": {
        "published": "2026-07-04T02:16:22.583",
        "lastModified": "2026-07-07T18:16:33.800",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71364",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-q77w-mwjj-7mqx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-undetected-asyncio-unix-events-unixsubprocesstransport-start",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71366",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:01:42.505Z",
      "date_published": "2026-07-04T01:23:38.638Z",
      "date_updated": "2026-07-06T13:16:00.238Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_cprofile",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00445,
        "percentile": 0.3653
      },
      "nvd": {
        "published": "2026-07-04T02:16:22.707",
        "lastModified": "2026-07-06T18:19:55.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71366",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "picklescan fails to reject a callable that can execute while an unsafe pickle is deserialized.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-4r9r-ch6f-vxmx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-torch-utils-bottleneck-main-run-cprofile",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71367",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:01:42.505Z",
      "date_published": "2026-07-04T01:23:39.319Z",
      "date_updated": "2026-07-06T15:02:33.416Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Remote Code Execution via _operator.attrgetter Detection Bypass",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00445,
        "percentile": 0.3653
      },
      "nvd": {
        "published": "2026-07-04T02:16:22.833",
        "lastModified": "2026-07-06T18:19:55.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71367",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "picklescan does not recognize _operator.attrgetter as an executable reduce target, so a malicious pickle passes scanning and later executes when loaded.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-46h3-79wf-xr6c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-operator-attrgetter-detection-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71369",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:01:42.505Z",
      "date_published": "2026-07-04T01:23:40.021Z",
      "date_updated": "2026-07-06T16:26:52.279Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Unsafe Deserialization via torch.utils.data.datapipes.utils.decoder.basichandlers",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00445,
        "percentile": 0.3653
      },
      "nvd": {
        "published": "2026-07-04T02:16:22.963",
        "lastModified": "2026-07-06T18:19:55.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71369",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "picklescan's Torch detector misses a reduce invocation expressed through an alternative basic-handler representation, allowing a malicious pickle execution path to evade the scan.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-h3qp-7fh3-f8h4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-unsafe-deserialization-via-torch-utils-data-datapipes-utils-decoder-basichandlers",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71372",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:11:44.727Z",
      "date_published": "2026-07-04T01:23:40.728Z",
      "date_updated": "2026-07-07T02:27:13.076Z",
      "publisher": "VulnCheck",
      "title": "Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.getlincoef Gadget",
      "affected": {
        "vendors": [
          "Picklescan"
        ],
        "products": [
          {
            "vendor": "Picklescan",
            "product": "Picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30689
      },
      "nvd": {
        "published": "2026-07-04T02:16:23.097",
        "lastModified": "2026-07-07T04:17:20.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71372",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application deserializes attacker-controlled bytes with object semantics that can invoke executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-rrxm-2pvv-m66x",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-numpy-f2py-crackfortran-getlincoef-gadget",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71373",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:11:44.727Z",
      "date_published": "2026-07-04T01:23:41.446Z",
      "date_updated": "2026-07-06T18:16:45.056Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Remote Code Execution via operator.methodcaller Detection Bypass",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00444,
        "percentile": 0.36488
      },
      "nvd": {
        "published": "2026-07-04T02:16:23.220",
        "lastModified": "2026-07-06T19:16:54.360",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71373",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "picklescan omits operator.methodcaller from its dangerous-call detection, so a malicious pickle can pass validation and later execute attacker-chosen behavior when loaded.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-x843-g5mx-g377",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-operator-methodcaller-detection-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71375",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:11:44.727Z",
      "date_published": "2026-07-04T01:23:42.157Z",
      "date_updated": "2026-07-07T16:58:14.155Z",
      "publisher": "VulnCheck",
      "title": "picklescan - Undetected Remote Code Execution via _operator.methodcaller",
      "affected": {
        "vendors": [
          "picklescan"
        ],
        "products": [
          {
            "vendor": "picklescan",
            "product": "picklescan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00365,
        "percentile": 0.29173
      },
      "nvd": {
        "published": "2026-07-04T02:16:23.347",
        "lastModified": "2026-07-07T18:16:33.920",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71375",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pickle scanner omits _operator.methodcaller from its dangerous-call detection even though pickle loading can invoke it as executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-955r-x9j8-7rhh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/picklescan-undetected-remote-code-execution-via-operator-methodcaller",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 285,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71377",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:11:44.728Z",
      "date_published": "2026-07-16T12:19:14.582Z",
      "date_updated": "2026-07-20T22:14:11.988Z",
      "publisher": "VulnCheck",
      "title": "stoatchat before 20250210-1 Unrestricted Message History Fetch",
      "affected": {
        "vendors": [
          "stoatchat"
        ],
        "products": [
          {
            "vendor": "stoatchat",
            "product": "stoatchat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1025",
          "name": "Comparison Using Wrong Factors",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00383,
        "percentile": 0.3105
      },
      "nvd": {
        "published": "2026-07-16T13:16:24.057",
        "lastModified": "2026-07-20T23:16:55.133",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71377",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The nearby-message route accepts a limit of zero that the database interprets as unlimited, enabling parallel requests to fetch an entire channel history.",
        "basis": [
          "CNA",
          "CWE-1025"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-h7h6-7pxm-mc66",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/stoatchat/stoatchat/commit/5f84daa9dba34c103cd83a2ee1f5e5ba900bfe94",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/stoatchat-before-20250210-1-unrestricted-message-history-fetch",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71380",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:11:44.728Z",
      "date_published": "2026-07-04T01:23:42.800Z",
      "date_updated": "2026-07-06T13:13:11.151Z",
      "publisher": "VulnCheck",
      "title": "n8n - Arbitrary Command Execution via Execute Command Node",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00413,
        "percentile": 0.33979
      },
      "nvd": {
        "published": "2026-07-04T02:16:23.477",
        "lastModified": "2026-07-06T19:01:14.993",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71380",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The deployment exposes host-command execution through the Execute Command node to authenticated users without a publicly identified stronger role or policy check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-365g-vjw2-grx8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-arbitrary-command-execution-via-execute-command-node",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-71385",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T15:52:12.626Z",
      "date_published": "2026-07-02T19:37:42.359Z",
      "date_updated": "2026-07-14T22:26:10.145Z",
      "publisher": "VulnCheck",
      "title": "Netdata < 2.3.1 - Reflected Cross-Site Scripting via love Parameter in ilove.svg Endpoint",
      "affected": {
        "vendors": [
          "netdata"
        ],
        "products": [
          {
            "vendor": "netdata",
            "product": "netdata"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14803
      },
      "nvd": {
        "published": "2026-07-02T20:17:00.420",
        "lastModified": "2026-07-14T23:17:28.950",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2025-71385",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ilove.svg endpoint inserts the love query value into an SVG text node without XML or HTML escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netdata/netdata/releases/tag/v2.3.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/netdata/netdata/pull/19919",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/netdata/netdata/commit/f82554fe9b21b5ae51a8663a3f4ddce84cac16af",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/netdata-reflected-cross-site-scripting-via-love-parameter-in-ilove-svg-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Release Notes",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 762,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2025-71388",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:14:41.769Z",
      "date_published": "2026-07-16T12:19:15.310Z",
      "date_updated": "2026-07-20T22:14:12.645Z",
      "publisher": "VulnCheck",
      "title": "stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions",
      "affected": {
        "vendors": [
          "stoatchat"
        ],
        "products": [
          {
            "vendor": "stoatchat",
            "product": "stoatchat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19631
      },
      "nvd": {
        "published": "2026-07-16T13:16:24.193",
        "lastModified": "2026-07-20T23:16:55.253",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71388",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The webhook endpoint checks ViewChannel instead of ManageWebhooks before returning webhook tokens.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-8684-rvfj-v3jq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/stoatchat/stoatchat/commit/e3723d647effb81ea3d3919d848faf64dbe89829",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/stoatchat-20241213-1-webhook-token-disclosure-via-read-permissions",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71389",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:14:41.769Z",
      "date_published": "2026-07-23T21:16:44.870Z",
      "date_updated": "2026-07-28T01:48:14.200Z",
      "publisher": "VulnCheck",
      "title": "Cal.com before 5.9.9 Remote Code Execution via RSC",
      "affected": {
        "vendors": [
          "calcom"
        ],
        "products": [
          {
            "vendor": "calcom",
            "product": "cal.diy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00928,
        "percentile": 0.57074
      },
      "nvd": {
        "published": "2026-07-23T22:16:51.750",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71389",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In cal.diy, attacker-controlled serialized data is deserialized into live objects during security-sensitive processing.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/calcom/cal.diy/security/advisories/GHSA-qjx2-5xqp-cpf4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/calcom/cal.diy/pull/25592",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/advisories/GHSA-9qr9-h5gf-34mp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cal-com-before-remote-code-execution-via-rsc",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2025-71390",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:14:41.770Z",
      "date_published": "2026-07-18T13:10:10.319Z",
      "date_updated": "2026-07-28T01:48:14.882Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.3.6 deny-net Bypass via DNS Resolution",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13713
      },
      "nvd": {
        "published": "2026-07-18T14:17:10.300",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71390",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SurrealDB checks the literal host against deny-net before using DNS results, so a permitted name can resolve to a prohibited network destination after the policy decision.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-m3c3-78fh-w3w7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-deny-net-bypass-via-dns-resolution",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 558,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2025-71391",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:14:41.770Z",
      "date_published": "2026-07-18T13:10:10.977Z",
      "date_updated": "2026-07-28T01:48:15.557Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.2.2 Denial of Service via /sql endpoint",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18315
      },
      "nvd": {
        "published": "2026-07-18T14:17:10.457",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71391",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A null byte in a query to the SQL endpoint escapes the net module as an uncaught exception and terminates the database process.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-rq86-9m6r-cm3g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-sql-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2025-71392",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:14:41.770Z",
      "date_published": "2026-07-18T13:10:11.661Z",
      "date_updated": "2026-07-28T01:48:16.238Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.2.2 SurrealQL Injection via export",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15578
      },
      "nvd": {
        "published": "2026-07-18T14:17:10.580",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71392",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SurrealDB exports attacker-chosen table or field names without SurrealQL escaping, so importing the backup later executes those names as database commands.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-ccj3-5p93-8p42",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-surrealql-injection-via-export",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 628,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2025-71393",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:14:41.770Z",
      "date_published": "2026-07-18T13:10:12.360Z",
      "date_updated": "2026-07-28T01:48:16.910Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.2.2 Memory Exhaustion via Nested Functions",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.1629
      },
      "nvd": {
        "published": "2026-07-18T14:17:10.703",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71393",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Native functions can re-enter JavaScript queries without sharing the enforced recursion limit, allowing an authenticated caller to recurse until memory is exhausted.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-m7rc-8w7m-r9qr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-memory-exhaustion-via-nested-functions",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 324,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2025-71394",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:14:41.770Z",
      "date_published": "2026-07-18T13:10:13.041Z",
      "date_updated": "2026-07-28T01:48:17.603Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.2.2 Local File Read via DEFINE ANALYZER",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22671
      },
      "nvd": {
        "published": "2026-07-18T14:17:10.837",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71394",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DEFINE ANALYZER accepts a caller-selected filesystem path outside the intended data namespace and reads the selected file.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-2cvj-g5r5-jrrg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-local-file-read-via-define-analyzer",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2025-71395",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:14:41.770Z",
      "date_published": "2026-07-18T13:10:13.744Z",
      "date_updated": "2026-07-28T01:48:18.301Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.2.2 Memory Exhaustion via string::replace",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14458
      },
      "nvd": {
        "published": "2026-07-18T14:17:10.963",
        "lastModified": "2026-07-22T20:16:41.963",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71395",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SurrealDB string::replace permits a regex replacement result to grow without an effective length or allocation bound.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-3633-g6mg-p6qq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-memory-exhaustion-via-string-replace",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 323,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2025-71396",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:14:41.770Z",
      "date_published": "2026-07-18T13:10:14.441Z",
      "date_updated": "2026-07-28T01:48:18.985Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.2.2 Denial of Service via JavaScript Scripting",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20909
      },
      "nvd": {
        "published": "2026-07-18T14:17:11.087",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71396",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scripting capability is explicitly enabled (via --allow-scripting or --allow-all).",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-3824-qmfq-2qv7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-javascript-scripting",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2025-71397",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:14:41.770Z",
      "date_published": "2026-07-18T13:10:15.129Z",
      "date_updated": "2026-07-28T01:48:19.674Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.2.2 CPU Exhaustion via nested FOR loops",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20909
      },
      "nvd": {
        "published": "2026-07-18T14:17:11.220",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71397",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SurrealDB limits each FOR loop but does not bound nested loops as a whole, and configured query timeouts do not stop their execution.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-pxw4-94j3-v9pf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-cpu-exhaustion-via-nested-for-loops",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 596,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2025-71398",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:38:41.076Z",
      "date_published": "2026-07-18T13:10:15.797Z",
      "date_updated": "2026-07-28T01:48:20.325Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.2.2 SSRF via HTTP Redirect Bypass",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13714
      },
      "nvd": {
        "published": "2026-07-18T14:17:11.347",
        "lastModified": "2026-07-21T18:37:56.803",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71398",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HTTP helper validates only the initial URL and follows redirects to destinations that the deny-net policy would have rejected.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-5q9x-554g-9jgg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-ssrf-via-http-redirect-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 354,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2025-71408",
      "id_year": 2025,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T20:57:08.784Z",
      "date_published": "2026-07-24T21:07:49.610Z",
      "date_updated": "2026-07-27T17:22:48.131Z",
      "publisher": "VulnCheck",
      "title": "NLTK < 3.9.3 Eval Injection via collocations.py Command-Line Arguments",
      "affected": {
        "vendors": [
          "ntlk"
        ],
        "products": [
          {
            "vendor": "ntlk",
            "product": "ntlk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-95",
          "name": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00158,
        "percentile": 0.0541
      },
      "nvd": {
        "published": "2026-07-24T22:16:50.063",
        "lastModified": "2026-07-30T19:56:57.057",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2025-71408",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches a dynamic code-generation or evaluation path without an effective allowlist, allowing it to run as code.",
        "basis": [
          "CNA",
          "CWE-95"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://aydinnyunus.github.io/2026/06/07/command-injection-nltk-collocations-eval/",
          "host": "aydinnyunus.github.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/nltk/nltk/releases/tag/3.9.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/nltk/nltk/pull/3465",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/nltk/nltk/commit/66f14096d952ec8f04934f515e027534bd4eb0ac",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/nltk-eval-injection-via-collocations-py-command-line-arguments",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-0275",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:34.621Z",
      "date_published": "2026-07-09T19:19:24.198Z",
      "date_updated": "2026-07-14T14:32:31.774Z",
      "publisher": "palo_alto",
      "title": "Prisma Browser: Local Privilege Escalation on macOS",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Browser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 4.7,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01599
      },
      "nvd": {
        "published": "2026-07-09T20:16:24.537",
        "lastModified": "2026-07-14T16:09:22.297",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0275",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A local administrator can cross the intended filesystem authority boundary and obtain root privileges, but the exact privileged transition is not public.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0275",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-0276",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:35.481Z",
      "date_published": "2026-07-09T19:17:01.145Z",
      "date_updated": "2026-07-14T14:32:13.977Z",
      "publisher": "palo_alto",
      "title": "Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Cortex XDR Broker VM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 1.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 6.699999999999999,
      "epss": {
        "score": 0.00098,
        "percentile": 0.00913
      },
      "nvd": {
        "published": "2026-07-09T20:16:24.670",
        "lastModified": "2026-07-16T14:28:29.443",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0276",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A locally authenticated user can reach root-authority operations, but the public record does not identify the missing privilege check.",
        "basis": [
          "CNA record",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0276",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 154,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-0277",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:36.317Z",
      "date_published": "2026-07-09T19:14:50.806Z",
      "date_updated": "2026-07-10T14:19:54.495Z",
      "publisher": "palo_alto",
      "title": "Prisma Access Agent: Improper Certificate Validation on iOS",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Access Agent"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00111,
        "percentile": 0.01522
      },
      "nvd": {
        "published": "2026-07-09T20:16:24.840",
        "lastModified": "2026-07-16T14:26:06.743",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0277",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prisma Access Agent accepts a peer certificate without validating it against the intended TLS identity.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0277",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 266,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-0278",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:37.292Z",
      "date_published": "2026-07-09T19:12:11.045Z",
      "date_updated": "2026-07-11T03:55:14.977Z",
      "publisher": "palo_alto",
      "title": "Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Access Agent"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:A/V:C/RE:H/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:C/RE:H/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01244
      },
      "nvd": {
        "published": "2026-07-09T20:16:24.983",
        "lastModified": "2026-07-16T14:17:04.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0278",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says a local user can bypass a data-loss-prevention policy but does not disclose the enabling implementation failure.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0278",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-0279",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:38.280Z",
      "date_published": "2026-07-09T19:08:41.656Z",
      "date_updated": "2026-07-09T19:23:42.200Z",
      "publisher": "palo_alto",
      "title": "PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Cloud NGFW"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "PAN-OS"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Access"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 8,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 1.2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 0.4,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 5.699999999999999,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24652
      },
      "nvd": {
        "published": "2026-07-09T19:16:58.717",
        "lastModified": "2026-07-13T12:43:37.907",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0279",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Cloud NGFW, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0279",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 856,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-0280",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:39.119Z",
      "date_published": "2026-07-09T19:05:24.367Z",
      "date_updated": "2026-07-09T19:23:56.125Z",
      "publisher": "palo_alto",
      "title": "PAN-OS: IPv6 Firewall Policy Bypass",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Cloud NGFW"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "PAN-OS"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "Panorama"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Access"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-131",
          "name": "Incorrect Calculation of Buffer Size",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 1.7,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/AU:Y/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.7,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 5.5,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07909
      },
      "nvd": {
        "published": "2026-07-09T19:16:59.280",
        "lastModified": "2026-07-13T12:36:31.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0280",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports an IPv6 firewall policy bypass but does not identify the packet field, state transition, or comparison that permits the bypass.",
        "basis": [
          "CNA record",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0280",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-0281",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:40.071Z",
      "date_published": "2026-07-09T19:03:44.381Z",
      "date_updated": "2026-07-09T19:24:18.136Z",
      "publisher": "palo_alto",
      "title": "PAN-OS: Information Disclosure Vulnerability in Management Web Interface",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Cloud NGFW"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "PAN-OS"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Access"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-524",
          "name": "Use of Cache Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:A/V:D/RE:M/U:Amber"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 1.7,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:A/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 5.3999999999999995,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06103
      },
      "nvd": {
        "published": "2026-07-09T19:16:59.780",
        "lastModified": "2026-07-13T12:35:08.263",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0281",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A management-interface cache can expose a legitimate user's web session token after that user follows an attacker-supplied link.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-524"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0281",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 824,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-0282",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:41.184Z",
      "date_published": "2026-07-09T19:02:26.722Z",
      "date_updated": "2026-07-09T19:24:40.688Z",
      "publisher": "palo_alto",
      "title": "PAN-OS: File Deletion Vulnerability in Management Web Interface",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Cloud NGFW"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "PAN-OS"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Access"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 1.2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 5.3,
      "epss": {
        "score": 0.00173,
        "percentile": 0.0701
      },
      "nvd": {
        "published": "2026-07-09T19:17:00.110",
        "lastModified": "2026-07-13T12:32:59.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0282",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The PAN-OS management interface accepts an unauthenticated file-deletion request whose target can select files in a temporary directory.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0282",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 735,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-0283",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:41.929Z",
      "date_published": "2026-07-09T19:01:34.210Z",
      "date_updated": "2026-07-09T19:25:07.889Z",
      "publisher": "palo_alto",
      "title": "PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Cloud NGFW"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "PAN-OS"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Access"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 2.7,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10538
      },
      "nvd": {
        "published": "2026-07-09T19:17:00.593",
        "lastModified": "2026-07-13T12:32:07.593",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0283",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The LSVPN service accepts tunnel establishment without authenticating the connecting party.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0283",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-0284",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:42.748Z",
      "date_published": "2026-07-09T18:59:57.586Z",
      "date_updated": "2026-07-09T19:25:27.319Z",
      "publisher": "palo_alto",
      "title": "PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Cloud NGFW"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "PAN-OS"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Access"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:L/E:U/AU:N/R:A/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 5.2,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18982
      },
      "nvd": {
        "published": "2026-07-09T19:17:01.140",
        "lastModified": "2026-07-13T12:30:48.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0284",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Cloud NGFW LSVPN path inserts attacker-controlled XML elements into a downstream XML document without preserving the document grammar.",
        "basis": [
          "CNA",
          "CWE-74",
          "Palo Alto Networks advisory"
        ],
        "deepDive": true,
        "notes": "Read Palo Alto Networks advisory https://security.paloaltonetworks.com/CVE-2026-0284; it identifies LSVPN with configured satellites and malicious XML, but publishes no parser or source path, and its current CVSS base score is 7.8 rather than the shard maximum of 9.9."
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0284",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 379,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-0285",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:43.620Z",
      "date_published": "2026-07-09T18:58:14.563Z",
      "date_updated": "2026-07-09T19:25:44.255Z",
      "publisher": "palo_alto",
      "title": "PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Cloud NGFW"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "PAN-OS"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Access"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12609
      },
      "nvd": {
        "published": "2026-07-09T19:17:01.633",
        "lastModified": "2026-07-13T12:29:14.653",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0285",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PAN-OS management interface lets an authenticated administrator direct server-side requests to otherwise unreachable internal services.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0285",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 666,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-0286",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:44.429Z",
      "date_published": "2026-07-09T18:56:29.289Z",
      "date_updated": "2026-07-09T19:26:01.748Z",
      "publisher": "palo_alto",
      "title": "PAN-OS: Authenticated Command Injection in CLI",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Cloud NGFW"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "PAN-OS"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Access"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.01019,
        "percentile": 0.59987
      },
      "nvd": {
        "published": "2026-07-09T19:17:02.227",
        "lastModified": "2026-07-13T12:28:26.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0286",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says attacker-controlled input reaches executable syntax in Cloud NGFW, while the input field and interpreter sink are not public.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0286",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 511,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-0287",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:45.634Z",
      "date_published": "2026-07-09T18:51:42.539Z",
      "date_updated": "2026-07-09T19:26:20.257Z",
      "publisher": "palo_alto",
      "title": "PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Cloud NGFW"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "PAN-OS"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Access"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 7,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:C/RE:M/U:Amber"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:C/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.9000000000000004,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22786
      },
      "nvd": {
        "published": "2026-07-09T19:17:02.747",
        "lastModified": "2026-07-13T12:25:24.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0287",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "PAN-OS enters maintenance mode after crafted dataplane traffic, but the public record does not disclose the exhausted resource, invalid state, or memory error.",
        "basis": [
          "CNA",
          "CWE-754"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0287",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 408,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-0288",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T20:44:46.432Z",
      "date_published": "2026-07-08T20:14:32.405Z",
      "date_updated": "2026-07-09T18:48:32.880Z",
      "publisher": "palo_alto",
      "title": "PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent",
      "affected": {
        "vendors": [
          "Palo Alto Networks"
        ],
        "products": [
          {
            "vendor": "Palo Alto Networks",
            "product": "Cloud NGFW"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "PAN-OS"
          },
          {
            "vendor": "Palo Alto Networks",
            "product": "Prisma Access"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 7,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/AU:N/R:U/V:D/RE:M/U:Red"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:psirt@paloaltonetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Red"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.7,
      "epss": {
        "score": 0.00844,
        "percentile": 0.54417
      },
      "nvd": {
        "published": "2026-07-08T21:16:45.590",
        "lastModified": "2026-07-10T15:45:17.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-0288",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure but does not disclose the exact buffer, lifetime transition, or invalid access.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://security.paloaltonetworks.com/",
          "host": "security.paloaltonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 841,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-0487",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-09T22:06:31.239Z",
      "date_published": "2026-07-14T00:17:37.478Z",
      "date_updated": "2026-07-20T14:39:04.209Z",
      "publisher": "sap",
      "title": "DLL Hijacking vulnerability in SAProuter on Microsoft Windows",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAProuter on Microsoft Windows"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 13,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05397
      },
      "nvd": {
        "published": "2026-07-14T01:16:16.370",
        "lastModified": "2026-07-20T16:16:53.983",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-0487",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SAProuter searches an attacker-influenced directory for a DLL before a trusted system location, allowing the untrusted library to load with SAProuter's privileges.",
        "basis": [
          "CNA",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3692165",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/piuppi/Proof-of-Concepts/blob/main/SAP/CVE-2026-0487.md",
          "host": "github.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-0515",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-10T15:04:59.507Z",
      "date_published": "2026-07-14T17:13:07.258Z",
      "date_updated": "2026-07-14T23:35:27.900Z",
      "publisher": "blackberry",
      "title": "Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety",
      "affected": {
        "vendors": [
          "BlackBerry Ltd",
          "BlackBerry Ltd."
        ],
        "products": [
          {
            "vendor": "BlackBerry Ltd",
            "product": "QNX Software Development Platform"
          },
          {
            "vendor": "BlackBerry Ltd",
            "product": "QNX OS for Safety"
          },
          {
            "vendor": "BlackBerry Ltd.",
            "product": "QNX OS for Medical"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 12,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-233",
          "name": "Improper Handling of Parameters",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secure@blackberry.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01586
      },
      "nvd": {
        "published": "2026-07-14T18:17:10.650",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-0515",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SchedGet accepts a locally supplied parameter without the validation needed to reject a kernel-crashing value.",
        "basis": [
          "CNA",
          "CWE-233"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.blackberry.com/pkb/s/article/141213",
          "host": "support.blackberry.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 150,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-0667",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-07T15:42:11.892Z",
      "date_published": "2026-07-29T12:35:34.208Z",
      "date_updated": "2026-07-29T14:20:14.876Z",
      "publisher": "schneider",
      "title": "CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.",
      "affected": {
        "vendors": [
          "Schneider Electric"
        ],
        "products": [
          {
            "vendor": "Schneider Electric",
            "product": "SCADAPack 47x"
          },
          {
            "vendor": "Schneider Electric",
            "product": "SCADAPack 47xi"
          },
          {
            "vendor": "Schneider Electric",
            "product": "SCADAPack 57x"
          },
          {
            "vendor": "Schneider Electric",
            "product": "RemoteConnect"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cybersecurity@se.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29569
      },
      "nvd": {
        "published": "2026-07-29T13:17:29.180",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-0667",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public notice attributes the Modbus TCP flaw to an exceptional-condition check but does not disclose the condition, parser state, or failing branch.",
        "basis": [
          "CNA",
          "CWE-754",
          "Schneider Electric security notification"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.se.com/us/en/download/document/SEVD-2026-041-01/; the official notice names the RTUs, Modbus TCP context, CWE-754, impact, and fixed releases but does not disclose the exceptional condition or failing branch."
      },
      "references": [
        {
          "url": "https://download.se.com/files?p_Doc_Ref=SEVD-2026-041-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-041-01.pdf",
          "host": "download.se.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-1239",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-20T17:56:47.784Z",
      "date_published": "2026-07-01T05:35:30.183Z",
      "date_updated": "2026-07-01T10:42:10.311Z",
      "publisher": "Wordfence",
      "title": "Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint",
      "affected": {
        "vendors": [
          "kstover"
        ],
        "products": [
          {
            "vendor": "kstover",
            "product": "Ninja Forms – The Contact Form Builder That Grows With You"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22107
      },
      "nvd": {
        "published": "2026-07-01T07:16:22.983",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1239",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/973ebafc-85c0-4cc5-b307-2fdb0a4a7577?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3489168/ninja-forms",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 400,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-22T21:20:10.240Z",
      "date_published": "2026-07-11T07:47:54.892Z",
      "date_updated": "2026-07-13T14:27:24.334Z",
      "publisher": "Wordfence",
      "title": "Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+) Incorrect Authorization to Privilege Escalation via theopt",
      "affected": {
        "vendors": [
          "genolve"
        ],
        "products": [
          {
            "vendor": "genolve",
            "product": "Genolve – Genolve AI Business Graphics, AI Images"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22848
      },
      "nvd": {
        "published": "2026-07-11T09:16:16.020",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1359",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "genolve_setOpt lacks a capability check and lets a contributor change security-sensitive global WordPress options.",
        "basis": [
          "CNA record",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8f64361a-e5b5-4481-b25c-bdffeb80c198?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&new=3460465%40genolve-toolkit&old=3432371%40genolve-toolkit",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 477,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1360",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-22T22:06:16.508Z",
      "date_published": "2026-07-30T04:03:14.202Z",
      "date_updated": "2026-07-30T14:03:13.114Z",
      "publisher": "Wordfence",
      "title": "BuddyPress <= 14.5.0 - Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data",
      "affected": {
        "vendors": [
          "buddypress"
        ],
        "products": [
          {
            "vendor": "buddypress",
            "product": "BuddyPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00569,
        "percentile": 0.43907
      },
      "nvd": {
        "published": "2026-07-30T05:16:34.657",
        "lastModified": "2026-07-30T15:16:31.530",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1360",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BuddyPress unserializes XProfile data without restricting the classes that the serialized stream may instantiate.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/467dd833-2f47-43cd-8d13-dffdad394b3c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/buddypress/trunk/bp-xprofile/bp-xprofile-template.php#L1000",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/buddypress/tags/14.4.0/bp-xprofile/bp-xprofile-template.php#L1000",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/buddypress/trunk/bp-xprofile/classes/class-bp-rest-xprofile-fields-endpoint.php#L866",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/buddypress/trunk/bp-xprofile/bp-xprofile-functions.php#L519",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://owasp.org/www-community/vulnerabilities/PHP_Object_Injection",
          "host": "owasp.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.php.net/manual/en/function.unserialize.php",
          "host": "www.php.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fbuddypress/tags/14.4.0&new_path=%2Fbuddypress/tags/14.5.0",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1365",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-23T08:12:17.605Z",
      "date_published": "2026-07-09T08:45:20.971Z",
      "date_updated": "2026-07-09T12:35:01.242Z",
      "publisher": "TR-CERT",
      "title": "Information Disclosure in Sayax's OSOS",
      "affected": {
        "vendors": [
          "Sayax Energy Technologies Inc."
        ],
        "products": [
          {
            "vendor": "Sayax Energy Technologies Inc.",
            "product": "OSOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18914
      },
      "nvd": {
        "published": "2026-07-09T10:16:25.573",
        "lastModified": "2026-07-09T16:21:30.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1365",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application inserts sensitive information into transmitted data that an unintended observer can receive.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0520",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1372",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-23T16:40:12.784Z",
      "date_published": "2026-07-21T07:51:21.731Z",
      "date_updated": "2026-07-22T16:08:10.195Z",
      "publisher": "Wordfence",
      "title": "Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation",
      "affected": {
        "vendors": [
          "themeum"
        ],
        "products": [
          {
            "vendor": "themeum",
            "product": "Tutor LMS Elementor Addons"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10519
      },
      "nvd": {
        "published": "2026-07-21T09:16:53.813",
        "lastModified": "2026-07-22T17:16:56.000",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1372",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The activate_tutor_free() and activate_elementor_free() admin-action handlers activate plugins without checking the caller's capability.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8a276a3e-12c3-4af7-9eb8-a25d20563de7?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor-lms-elementor-addons/tags/3.0.1/classes/Installer.php#L213",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor-lms-elementor-addons/tags/3.0.1/classes/Installer.php#L222",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor-lms-elementor-addons/tags/3.0.1/classes/Installer.php#L29",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Ftutor-lms-elementor-addons/tags/3.0.1&new_path=%2Ftutor-lms-elementor-addons/tags/3.0.2",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Ftutor-lms-elementor-addons/tags/3.0.2&new_path=%2Ftutor-lms-elementor-addons/tags/4.0.0",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 459,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-23T18:46:51.014Z",
      "date_published": "2026-07-11T05:35:47.586Z",
      "date_updated": "2026-07-14T14:28:46.630Z",
      "publisher": "Wordfence",
      "title": "fresh Podcaster <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'freshpodcaster' Shortcode Attributes",
      "affected": {
        "vendors": [
          "freshlabs"
        ],
        "products": [
          {
            "vendor": "freshlabs",
            "product": "fresh Podcaster"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08635
      },
      "nvd": {
        "published": "2026-07-11T07:16:46.307",
        "lastModified": "2026-07-14T15:17:01.190",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1382",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The fresh Podcaster rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4bf80767-4b11-49cd-acf5-7437aa89cc0f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fresh-podcaster/trunk/public/class-fresh-podcaster-shortcodes.php#L73",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fresh-podcaster/trunk/public/partials/fresh-podcaster-public-display.php#L25",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fresh-podcaster/tags/1.0.7/public/partials/fresh-podcaster-public-display.php#L25",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-26T12:49:23.159Z",
      "date_published": "2026-07-06T08:12:49.571Z",
      "date_updated": "2026-07-06T18:54:02.174Z",
      "publisher": "Canon_EMEA",
      "title": "uniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensitive Information Leads to Information Disclosure",
      "affected": {
        "vendors": [
          "NT-ware"
        ],
        "products": [
          {
            "vendor": "NT-ware",
            "product": "uniFLOW ULM (Universal Login Manager) Standalone"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:4586e0a2-224d-4f8a-9cb4-8882b208c0b3",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11073
      },
      "nvd": {
        "published": "2026-07-06T09:16:34.877",
        "lastModified": "2026-07-06T19:17:00.013",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1433",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.canon-europe.com/psirt/advisory-information",
          "host": "www.canon-europe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://ntware.atlassian.net/wiki/spaces/SA/pages/13659504652/2026+Security+Advisory+ULM+Potential+Information+Disclosure",
          "host": "ntware.atlassian.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "mitigation",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1562",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-28T19:59:23.519Z",
      "date_published": "2026-07-15T16:37:13.384Z",
      "date_updated": "2026-07-15T18:13:03.446Z",
      "publisher": "Pega",
      "title": "Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.",
      "affected": {
        "vendors": [
          "Pegasystems"
        ],
        "products": [
          {
            "vendor": "Pegasystems",
            "product": "Pega Infinity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@pega.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06977
      },
      "nvd": {
        "published": "2026-07-15T17:16:46.737",
        "lastModified": "2026-07-21T16:55:39.150",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-1562",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Pega Infinity, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.pega.com/support-doc/pega-security-advisory-e26-vulnerability-remediation-note",
          "host": "support.pega.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1563",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-28T19:59:24.829Z",
      "date_published": "2026-07-15T16:38:21.778Z",
      "date_updated": "2026-07-15T18:12:40.935Z",
      "publisher": "Pega",
      "title": "Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.",
      "affected": {
        "vendors": [
          "Pegasystems"
        ],
        "products": [
          {
            "vendor": "Pegasystems",
            "product": "Pega Infinity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@pega.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06976
      },
      "nvd": {
        "published": "2026-07-15T17:16:46.863",
        "lastModified": "2026-07-21T16:54:21.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-1563",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.pega.com/support-doc/pega-security-advisory-e26-vulnerability-remediation-note",
          "host": "support.pega.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1609",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-29T12:08:57.214Z",
      "date_published": "2026-07-16T00:26:10.772Z",
      "date_updated": "2026-07-16T15:11:51.549Z",
      "publisher": "redhat",
      "title": "Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt authorization grant with disabled users",
      "affected": {
        "vendors": [
          "Keycloak",
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Keycloak",
            "product": "Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00506,
        "percentile": 0.4045
      },
      "nvd": {
        "published": "2026-07-16T01:16:30.380",
        "lastModified": "2026-07-16T16:19:01.120",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1609",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The JWT authorization-grant preview path validates an external assertion without checking that the mapped local user is still enabled.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-1609",
          "host": "access.redhat.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2435257",
          "host": "bugzilla.redhat.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/keycloak/keycloak/issues/46144",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/keycloak/keycloak/releases/tag/26.5.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1609.json",
          "host": "security.access.redhat.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "x_sadp-csaf-vex"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 494,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1617",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-29T13:28:08.249Z",
      "date_published": "2026-07-21T11:07:22.695Z",
      "date_updated": "2026-07-21T12:13:03.826Z",
      "publisher": "TR-CERT",
      "title": "SQLi in Turkmesh's Turkhotspot 5651 Loglama",
      "affected": {
        "vendors": [
          "Turkmesh Communication Services Inc."
        ],
        "products": [
          {
            "vendor": "Turkmesh Communication Services Inc.",
            "product": "Turkhotspot 5651 Loglama"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17659
      },
      "nvd": {
        "published": "2026-07-21T12:17:21.173",
        "lastModified": "2026-07-21T17:08:18.343",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1617",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled Turkhotspot input reaches an SQL command without the required SQL-context separation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0584",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1667",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-29T21:38:19.441Z",
      "date_published": "2026-07-10T16:32:13.358Z",
      "date_updated": "2026-07-10T18:17:29.926Z",
      "publisher": "Wordfence",
      "title": "SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost()",
      "affected": {
        "vendors": [
          "cifi"
        ],
        "products": [
          {
            "vendor": "cifi",
            "product": "GEO Plugin by Squirrly SEO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08415
      },
      "nvd": {
        "published": "2026-07-10T17:16:54.597",
        "lastModified": "2026-07-10T19:17:21.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1667",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The plugin leaks an API token that an unauthenticated attacker can reuse to create posts, with unsanitized post content also reaching a stored HTML output path.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/aebdd464-10b9-4d43-bf38-f0e8ae25625f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&new=3586051%40squirrly-seo&old=3474256%40squirrly-seo",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 505,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-02T16:15:31.315Z",
      "date_published": "2026-07-21T07:51:22.165Z",
      "date_updated": "2026-07-22T13:59:17.647Z",
      "publisher": "Wordfence",
      "title": "MapSVG <= 8.14.0 - Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint",
      "affected": {
        "vendors": [
          "oyatek"
        ],
        "products": [
          {
            "vendor": "oyatek",
            "product": "MapSVG – Vector maps, Image maps, Google Maps"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00586,
        "percentile": 0.4469
      },
      "nvd": {
        "published": "2026-07-21T09:16:53.947",
        "lastModified": "2026-07-22T15:16:54.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1771",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An incorrect condition skips file-type validation in SVGFile and permits an administrator to store an executable upload.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c7f098b9-eca3-41c7-9c74-0f4b3f75c915?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mapsvg-lite-interactive-vector-maps/trunk/php/Domain/SVGFile/SVGFile.php#L24",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mapsvg-lite-interactive-vector-maps/tags/8.9.1/php/Domain/SVGFile/SVGFile.php#L24",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mapsvg-lite-interactive-vector-maps/tags/8.9.1/php/Router.php#L641",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mapsvg-lite-interactive-vector-maps/tags/8.9.1/php/Domain/File/FilesRepository.php#L166",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3608308/mapsvg-lite-interactive-vector-maps/trunk/php/Domain/SVGFile/SVGFile.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fmapsvg-lite-interactive-vector-maps/tags/8.14.0&new_path=%2Fmapsvg-lite-interactive-vector-maps/tags/8.14.1",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1832",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-03T14:48:59.230Z",
      "date_published": "2026-07-11T03:44:25.835Z",
      "date_updated": "2026-07-13T14:18:51.341Z",
      "publisher": "Wordfence",
      "title": "ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Cache Deletion",
      "affected": {
        "vendors": [
          "thrivedesk"
        ],
        "products": [
          {
            "vendor": "thrivedesk",
            "product": "Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10553
      },
      "nvd": {
        "published": "2026-07-11T05:16:33.043",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1832",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ec4bc1d4-2f14-4f3e-85ed-8737c56f905c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/thrivedesk/trunk/includes/helper.php#L238",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/thrivedesk/tags/2.1.5/includes/helper.php#L238",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://cwe.mitre.org/data/definitions/862.html",
          "host": "cwe.mitre.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3512748%40thrivedesk&new=3512748%40thrivedesk",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/thrivedesk/tags/2.2.0/includes/helper.php#L238",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 375,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1918",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-04T16:31:22.993Z",
      "date_published": "2026-07-28T19:45:06.755Z",
      "date_updated": "2026-07-29T15:24:46.500Z",
      "publisher": "ibm",
      "title": "IBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive information in a log file",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Sterling B2B Integrator"
          },
          {
            "vendor": "IBM",
            "product": "Sterling File Gateway"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21182
      },
      "nvd": {
        "published": "2026-07-28T20:17:24.377",
        "lastModified": "2026-08-03T14:45:44.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-1918",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Sterling writes potentially sensitive values to log files readable by privileged users.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280658",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-1946",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-04T22:01:50.781Z",
      "date_published": "2026-07-10T07:48:42.276Z",
      "date_updated": "2026-07-14T01:34:54.013Z",
      "publisher": "Wordfence",
      "title": "GW AI Website Builder <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion",
      "affected": {
        "vendors": [
          "nandhiniwp"
        ],
        "products": [
          {
            "vendor": "nandhiniwp",
            "product": "GW AI Website Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12801
      },
      "nvd": {
        "published": "2026-07-10T09:16:53.540",
        "lastModified": "2026-07-14T02:16:54.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1946",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GW AI Website Builder exposes its disconnect handler without the capability check required for the state-changing action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/49405ba1-b0fd-429b-a30a-95c8d3f26545?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gw-ai-website-builder/trunk/API/api-functions.php#L4069",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gw-ai-website-builder/tags/1.0.1/API/api-functions.php#L4069",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gw-ai-website-builder/trunk/API/api-functions.php#L4253",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gw-ai-website-builder/tags/1.0.1/API/api-functions.php#L4253",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3481065%40gw-ai-website-builder&new=3481065%40gw-ai-website-builder",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 426,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-05T14:44:02.400Z",
      "date_published": "2026-07-30T03:03:21.778Z",
      "date_updated": "2026-07-30T15:51:47.194Z",
      "publisher": "Wordfence",
      "title": "Persian Elementor (المنتور فارسی) <= 2.8.1 - Unauthenticated Price Manipulation via ZarinPal Widget",
      "affected": {
        "vendors": [
          "mohammadr3z"
        ],
        "products": [
          {
            "vendor": "mohammadr3z",
            "product": "المنتور فارسی"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-472",
          "name": "External Control of Assumed-Immutable Web Parameter",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09501
      },
      "nvd": {
        "published": "2026-07-30T03:16:24.647",
        "lastModified": "2026-07-30T16:17:10.337",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1982",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price.",
        "basis": [
          "CNA",
          "CWE-472"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/da675a50-c7ac-4859-9795-4b0f1dc56c7b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3613858/persian-elementor",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-1989",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-05T15:22:11.030Z",
      "date_published": "2026-07-09T08:56:37.717Z",
      "date_updated": "2026-07-09T12:33:51.423Z",
      "publisher": "TR-CERT",
      "title": "IDOR in PAVO Inc.'s PAVO Pay",
      "affected": {
        "vendors": [
          "PAVO Financial Technology Solutions Inc."
        ],
        "products": [
          {
            "vendor": "PAVO Financial Technology Solutions Inc.",
            "product": "PAVO Pay"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16497
      },
      "nvd": {
        "published": "2026-07-09T10:16:25.710",
        "lastModified": "2026-07-09T16:21:30.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-1989",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PAVO Pay accepts a user-controlled record key without binding the requested object to the caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0521",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 298,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-2342",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-11T13:38:05.266Z",
      "date_published": "2026-07-09T09:07:24.403Z",
      "date_updated": "2026-07-09T12:32:19.467Z",
      "publisher": "TR-CERT",
      "title": "XSS in Oceanicsoft's ValeApp",
      "affected": {
        "vendors": [
          "OceanicSoft Informatics Systems Ltd."
        ],
        "products": [
          {
            "vendor": "OceanicSoft Informatics Systems Ltd.",
            "product": "ValeApp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12666
      },
      "nvd": {
        "published": "2026-07-09T10:16:25.833",
        "lastModified": "2026-07-09T16:21:30.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-2342",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ValeApp page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0522",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-2354",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-11T16:47:19.850Z",
      "date_published": "2026-07-11T03:44:21.070Z",
      "date_updated": "2026-07-13T14:39:51.179Z",
      "publisher": "Wordfence",
      "title": "Swiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()",
      "affected": {
        "vendors": [
          "wpmessiah"
        ],
        "products": [
          {
            "vendor": "wpmessiah",
            "product": "Swiss Toolkit For WP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00537,
        "percentile": 0.42243
      },
      "nvd": {
        "published": "2026-07-11T05:16:33.777",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-2354",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Swiss Toolkit For WP accepts an uploaded file without enforcing the type, destination, or execution restrictions required for that upload boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/06bccd2e-6891-433a-9f5b-3ec0c30afef4?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/swiss-toolkit-for-wp/tags/1.4.2/includes/plugins/class-boomdevs-swiss-toolkit-extension-supports.php#L95",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/swiss-toolkit-for-wp/tags/1.4.2/includes/plugins/class-boomdevs-swiss-toolkit-extension-supports.php#L49",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/swiss-toolkit-for-wp/trunk/includes/plugins/class-boomdevs-swiss-toolkit-extension-supports.php#L95",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/swiss-toolkit-for-wp/trunk/includes/plugins/class-boomdevs-swiss-toolkit-extension-supports.php#L49",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 787,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-2387",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-12T00:39:03.296Z",
      "date_published": "2026-07-01T04:32:26.499Z",
      "date_updated": "2026-07-01T10:42:11.421Z",
      "publisher": "Wordfence",
      "title": "Event Organiser <= 3.12.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via eo_events Shortcode",
      "affected": {
        "vendors": [
          "stephenharris"
        ],
        "products": [
          {
            "vendor": "stephenharris",
            "product": "Event Organiser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04826
      },
      "nvd": {
        "published": "2026-07-01T05:16:19.600",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-2387",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3f417afd-2822-412f-b68a-f09c013d6049?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3589132/event-organiser",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 483,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-2395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-12T12:48:07.234Z",
      "date_published": "2026-07-22T14:02:07.808Z",
      "date_updated": "2026-07-30T11:25:33.239Z",
      "publisher": "TR-CERT",
      "title": "SQLi in Xpoda Türkiye Informatics Technology's No Code Platform",
      "affected": {
        "vendors": [
          "Xpoda Türkiye Informatics Technology Inc."
        ],
        "products": [
          {
            "vendor": "Xpoda Türkiye Informatics Technology Inc.",
            "product": "No Code Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28117
      },
      "nvd": {
        "published": "2026-07-22T15:16:54.193",
        "lastModified": "2026-07-30T12:18:02.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-2395",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a No Code Platform database query without safe parameter binding, allowing query syntax injection.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0608",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-2397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-12T12:58:46.087Z",
      "date_published": "2026-07-10T17:29:42.453Z",
      "date_updated": "2026-07-16T12:58:22.125Z",
      "publisher": "TR-CERT",
      "title": "SQLi in AdamPOS' MobilMen 20T",
      "affected": {
        "vendors": [
          "Adam Retail Automation Ltd."
        ],
        "products": [
          {
            "vendor": "Adam Retail Automation Ltd.",
            "product": "MobilMen 20T"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.1822
      },
      "nvd": {
        "published": "2026-07-10T18:16:20.613",
        "lastModified": "2026-07-10T19:17:22.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-2397",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MobilMen 20T incorporates attacker input into an SQL statement without separating data from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0526",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-2398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-12T12:58:51.972Z",
      "date_published": "2026-07-10T17:02:34.594Z",
      "date_updated": "2026-07-16T12:59:18.926Z",
      "publisher": "TR-CERT",
      "title": "IDOR in AdamPOS' MobilMen 20T",
      "affected": {
        "vendors": [
          "Adam Retail Automation Ltd."
        ],
        "products": [
          {
            "vendor": "Adam Retail Automation Ltd.",
            "product": "MobilMen 20T"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16473
      },
      "nvd": {
        "published": "2026-07-10T17:16:56.320",
        "lastModified": "2026-07-10T18:16:20.733",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-2398",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A request selects another user's object without an ownership check.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0526",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 286,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-2406",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-12T13:25:58.515Z",
      "date_published": "2026-07-22T08:51:21.311Z",
      "date_updated": "2026-07-22T08:51:21.311Z",
      "publisher": "TR-CERT",
      "title": "IDOR in Universe Software's Online Registration and Workflow Management System",
      "affected": {
        "vendors": [
          "Universe Software Computer Marketing Trade and Industry Inc."
        ],
        "products": [
          {
            "vendor": "Universe Software Computer Marketing Trade and Industry Inc.",
            "product": "Online Registration and Workflow Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21365
      },
      "nvd": {
        "published": "2026-07-22T09:16:28.903",
        "lastModified": "2026-07-22T16:21:53.517",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-2406",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Online Registration and Workflow Management System handler trusts a caller-controlled object identifier without binding it to the caller's permitted objects.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0594",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-2445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-13T07:48:55.362Z",
      "date_published": "2026-07-20T08:06:39.095Z",
      "date_updated": "2026-07-20T13:52:59.977Z",
      "publisher": "WSO2",
      "title": "Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification",
      "affected": {
        "vendors": [
          "WSO2"
        ],
        "products": [
          {
            "vendor": "WSO2",
            "product": "WSO2 API Manager"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 API Control Plane"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 Identity Server"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:ed10eef1-636d-4fbe-9993-6890dfa878f8",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04579
      },
      "nvd": {
        "published": "2026-07-20T08:16:30.143",
        "lastModified": "2026-07-23T15:27:53.473",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-2445",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Reflected input is rendered without the browser-context separation required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5059/",
          "host": "security.docs.wso2.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-2482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-13T18:39:00.390Z",
      "date_published": "2026-07-29T18:19:36.707Z",
      "date_updated": "2026-07-30T15:19:30.028Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server Liberty is affected by a cross-site request forgery",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 5.700000000000001,
      "epss": {
        "score": 0.00086,
        "percentile": 0.00404
      },
      "nvd": {
        "published": "2026-07-29T19:16:45.597",
        "lastModified": "2026-08-04T14:10:12.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-2482",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Liberty accepts a victim browser request that can perform a state-changing action without an effective anti-CSRF check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281651",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-2594",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-16T17:19:23.910Z",
      "date_published": "2026-07-17T01:30:50.365Z",
      "date_updated": "2026-07-17T15:07:53.149Z",
      "publisher": "Wordfence",
      "title": "Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title",
      "affected": {
        "vendors": [
          "inc2734"
        ],
        "products": [
          {
            "vendor": "inc2734",
            "product": "Smart Custom Fields"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15188
      },
      "nvd": {
        "published": "2026-07-17T02:18:05.607",
        "lastModified": "2026-07-17T16:17:14.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-2594",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Smart Custom Fields stores attacker-controlled content and later emits it as active browser markup without complete sanitization and escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/110a1b28-50e0-430e-82d4-c254d73836e2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3485210/smart-custom-fields",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3609564/smart-custom-fields",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-2891",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-20T17:49:42.020Z",
      "date_published": "2026-07-01T14:08:45.511Z",
      "date_updated": "2026-07-01T14:55:54.454Z",
      "publisher": "hp",
      "title": "Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service",
      "affected": {
        "vendors": [
          "HP Inc"
        ],
        "products": [
          {
            "vendor": "HP Inc",
            "product": "CCX"
          },
          {
            "vendor": "HP Inc",
            "product": "Trio C60"
          },
          {
            "vendor": "HP Inc",
            "product": "Edge E"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:hp-security-alert@hp.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16739
      },
      "nvd": {
        "published": "2026-07-01T15:17:06.960",
        "lastModified": "2026-07-02T17:47:43.557",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-2891",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A Poly phone that connects to a malicious SIP server can be made inoperable by malformed SIP data, but the record does not identify the exhausted resource.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hp.com/us-en/document/ish_15222895-15222917-16/hpsbpy04096",
          "host": "support.hp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-3014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-23T09:28:18.635Z",
      "date_published": "2026-07-14T09:45:22.651Z",
      "date_updated": "2026-07-16T12:40:32.623Z",
      "publisher": "Milestone",
      "title": "Remote Code Execution by administrative user on the Management Server",
      "affected": {
        "vendors": [
          "Milestone Systems"
        ],
        "products": [
          {
            "vendor": "Milestone Systems",
            "product": "XProtect Management Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cf45122d-9d50-442a-9b23-e05cde9943d8",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cf45122d-9d50-442a-9b23-e05cde9943d8",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 2.6999999999999993,
      "epss": {
        "score": 0.00476,
        "percentile": 0.38632
      },
      "nvd": {
        "published": "2026-07-14T10:16:32.917",
        "lastModified": "2026-07-16T13:16:31.513",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3014",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An edit-capable Management Server user can place input into an operating-system command context without the required command-grammar separation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.milestonesys.com/article/CVE-2026-3014-potential-remote-code-execution-by-admin-user-on-Management-Server",
          "host": "support.milestonesys.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required"
          ]
        },
        {
          "url": "https://doc.milestonesys.com/en-US/bundle/sec1504_latest/page/milestone_security_advisory_CVE-2026-3014_potential_remote_code_execution_by_admin_user_on_Management_Server.html",
          "host": "doc.milestonesys.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 310,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-3031",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-23T14:42:48.259Z",
      "date_published": "2026-07-16T16:22:38.557Z",
      "date_updated": "2026-07-17T18:07:02.432Z",
      "publisher": "CPANSec",
      "title": "Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library",
      "affected": {
        "vendors": [
          "TOKUHIROM"
        ],
        "products": [
          {
            "vendor": "TOKUHIROM",
            "product": "Image::EPEG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1104",
          "name": "Use of Unmaintained Third Party Components",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.32932
      },
      "nvd": {
        "published": "2026-07-16T17:16:55.633",
        "lastModified": "2026-07-17T19:17:13.403",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3031",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Image::EPEG embeds an unsupported dependency whose security defects can no longer be reliably maintained or updated.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1104"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://backpan.metacpan.org/authors/id/T/TO/TOKUHIROM/Image-Epeg-0.15.readme",
          "host": "backpan.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://backpan.metacpan.org/authors/id/T/TO/TOKUHIROM/Image-Epeg-0.15.tar.gz",
          "host": "backpan.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://sourceforge.net/projects/enlightenment/files/OldFiles/epeg-0.9.0.tar.gz/download",
          "host": "sourceforge.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-3093",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-24T02:34:16.776Z",
      "date_published": "2026-07-29T19:02:11.038Z",
      "date_updated": "2026-07-29T19:34:59.534Z",
      "publisher": "GitLab",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14955
      },
      "nvd": {
        "published": "2026-07-29T20:17:03.137",
        "lastModified": "2026-08-03T14:04:02.133",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-3093",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://hackerone.com/reports/3539833",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/591274",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-3144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-24T19:53:12.296Z",
      "date_published": "2026-07-08T15:22:31.263Z",
      "date_updated": "2026-07-09T03:55:48.309Z",
      "publisher": "ibm",
      "title": "IBM API Connect Default Credentials",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "API Connect"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1392",
          "name": "Use of Default Credentials",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14384
      },
      "nvd": {
        "published": "2026-07-08T16:16:28.463",
        "lastModified": "2026-07-10T17:01:12.167",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-3144",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "API Connect ships known default credentials that remain usable on the deployed service.",
        "basis": [
          "CNA",
          "CWE-1392"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278909",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-3157",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-24T20:52:02.974Z",
      "date_published": "2026-07-28T19:40:18.276Z",
      "date_updated": "2026-07-29T14:03:29.656Z",
      "publisher": "ibm",
      "title": "Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure in mailbox UI",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Sterling B2B Integrator"
          },
          {
            "vendor": "IBM",
            "product": "Sterling File Gateway"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-615",
          "name": "Inclusion of Sensitive Information in Source Code Comments",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00219,
        "percentile": 0.12507
      },
      "nvd": {
        "published": "2026-07-28T20:17:24.677",
        "lastModified": "2026-08-03T14:38:50.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-3157",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mailbox source-code comments embed sensitive information that is delivered to users who can inspect the page source.",
        "basis": [
          "CNA",
          "CWE-615"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280665",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 364,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-3158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-24T20:59:24.546Z",
      "date_published": "2026-07-28T19:38:38.218Z",
      "date_updated": "2026-07-29T13:55:30.106Z",
      "publisher": "ibm",
      "title": "Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Sterling B2B Integrator"
          },
          {
            "vendor": "IBM",
            "product": "Sterling File Gateway"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-615",
          "name": "Inclusion of Sensitive Information in Source Code Comments",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07818
      },
      "nvd": {
        "published": "2026-07-28T20:17:24.823",
        "lastModified": "2026-08-03T14:27:47.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-3158",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Sensitive values are embedded in source-code comments delivered to clients.",
        "basis": [
          "CNA",
          "CWE-615"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280661",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-3182",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-25T07:08:29.976Z",
      "date_published": "2026-07-21T05:30:33.481Z",
      "date_updated": "2026-07-21T15:03:24.772Z",
      "publisher": "Zohocorp",
      "title": "Sensitive Data Exposure",
      "affected": {
        "vendors": [
          "Zohocorp"
        ],
        "products": [
          {
            "vendor": "Zohocorp",
            "product": "ManageEngine Endpoint Central"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-319",
          "name": "Cleartext Transmission of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:0fc0942c-577d-436f-ae8e-945763c79b02",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19906
      },
      "nvd": {
        "published": "2026-07-21T06:16:28.890",
        "lastModified": "2026-07-21T18:34:20.010",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3182",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Endpoint Central transmits sensitive configuration data over a cleartext channel.",
        "basis": [
          "CNA record",
          "CWE-319"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.manageengine.com/products/desktop-central/mail-configuration-data.html",
          "host": "www.manageengine.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-3183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-25T07:08:40.731Z",
      "date_published": "2026-07-21T06:58:53.375Z",
      "date_updated": "2026-07-21T12:18:37.554Z",
      "publisher": "Zohocorp",
      "title": "Multi Factor Auth Bypass",
      "affected": {
        "vendors": [
          "Zohocorp"
        ],
        "products": [
          {
            "vendor": "Zohocorp",
            "product": "ManageEngine ADSelfService Plus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:0fc0942c-577d-436f-ae8e-945763c79b02",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00481,
        "percentile": 0.38931
      },
      "nvd": {
        "published": "2026-07-21T08:16:33.880",
        "lastModified": "2026-07-21T18:34:20.010",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3183",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that ManageEngine ADSelfService Plus permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.manageengine.com/products/self-service-password/advisory/CVE-2026-3183.html",
          "host": "www.manageengine.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-3251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T08:10:20.666Z",
      "date_published": "2026-07-10T16:39:44.837Z",
      "date_updated": "2026-07-10T17:41:50.418Z",
      "publisher": "TR-CERT",
      "title": "XSS in Webremium's Mezunum Satiyorum",
      "affected": {
        "vendors": [
          "Webremium Istanbul Web Design"
        ],
        "products": [
          {
            "vendor": "Webremium Istanbul Web Design",
            "product": "Mezunum Satiyorum"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04479
      },
      "nvd": {
        "published": "2026-07-10T17:16:57.367",
        "lastModified": "2026-07-10T18:16:21.927",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3251",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted data reaches an executable interpreter grammar without the required neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0525",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-3367",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-27T20:56:31.267Z",
      "date_published": "2026-07-11T02:31:17.819Z",
      "date_updated": "2026-07-13T14:26:53.516Z",
      "publisher": "Wordfence",
      "title": "Lockme OAuth2 calendars integration <= 2.11.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'App ID' Setting",
      "affected": {
        "vendors": [
          "lustmored"
        ],
        "products": [
          {
            "vendor": "lustmored",
            "product": "Lockme calendars integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17157
      },
      "nvd": {
        "published": "2026-07-11T04:17:23.670",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3367",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Lockme calendars integration page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/800b1a44-4173-4b8e-bc69-9a64218e64d6?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lockme-calendars-integration/trunk/src/Plugin.php#L212",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lockme-calendars-integration/tags/2.9.3/src/Plugin.php#L212",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lockme-calendars-integration/trunk/src/Plugin.php#L223",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lockme-calendars-integration/tags/2.9.3/src/Plugin.php#L223",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lockme-calendars-integration/trunk/src/Plugin.php#L245",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lockme-calendars-integration/tags/2.9.3/src/Plugin.php#L245",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lockme-calendars-integration/trunk/src/Plugin.php#L256",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lockme-calendars-integration/tags/2.9.3/src/Plugin.php#L256",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lockme-calendars-integration/trunk/src/Plugin.php#L197",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lockme-calendars-integration/tags/2.9.3/src/Plugin.php#L197",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lockme-calendars-integration/trunk/src/Plugin.php#L54",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lockme-calendars-integration/tags/2.9.3/src/Plugin.php#L54",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3495564%40lockme-calendars-integration&new=3495564%40lockme-calendars-integration",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1055,
        "referenceCount": 14,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-3482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T14:50:55.686Z",
      "date_published": "2026-07-22T18:06:00.762Z",
      "date_updated": "2026-07-23T13:58:49.327Z",
      "publisher": "ibm",
      "title": "IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Sterling B2B Integrator"
          },
          {
            "vendor": "IBM",
            "product": "Sterling File Gateway"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19531
      },
      "nvd": {
        "published": "2026-07-22T19:17:03.233",
        "lastModified": "2026-07-23T14:17:12.807",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3482",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record states that a crafted HTTP request bypasses authentication, while it does not identify the user-controlled key or validation step referenced by CWE-639.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280657",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-3552",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-04T18:52:25.601Z",
      "date_published": "2026-07-11T03:44:21.730Z",
      "date_updated": "2026-07-13T17:52:58.355Z",
      "publisher": "Wordfence",
      "title": "SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 Gone URL Import via 'surfl_import_410' AJAX Action",
      "affected": {
        "vendors": [
          "surflabtech"
        ],
        "products": [
          {
            "vendor": "surflabtech",
            "product": "SurfLink – Link Manager & Backup Restore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11777
      },
      "nvd": {
        "published": "2026-07-11T05:16:33.897",
        "lastModified": "2026-07-13T19:17:06.193",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3552",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ajax_import_410 lacks both a capability check and nonce verification, allowing a subscriber to modify the global 410 URL table.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/22e0060d-7852-4326-98bc-1c49bebe6205?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/surflink/trunk/includes/class-surfl-410.php#L585",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/surflink/tags/2.4.1/includes/class-surfl-410.php#L585",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/surflink/trunk/includes/class-surfl-410.php#L513",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/surflink/tags/2.4.1/includes/class-surfl-410.php#L513",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/surflink/trunk/includes/class-surfl-410.php#L32",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/surflink/tags/2.4.1/includes/class-surfl-410.php#L32",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3542304%40surflink&new=3542304%40surflink",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 977,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-3576",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-04T21:44:03.501Z",
      "date_published": "2026-07-11T03:44:22.441Z",
      "date_updated": "2026-07-13T16:13:57.980Z",
      "publisher": "Wordfence",
      "title": "Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter",
      "affected": {
        "vendors": [
          "xtreeme"
        ],
        "products": [
          {
            "vendor": "xtreeme",
            "product": "Planyo online reservation system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0039,
        "percentile": 0.31794
      },
      "nvd": {
        "published": "2026-07-11T05:16:34.013",
        "lastModified": "2026-07-13T17:17:19.787",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3576",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The proxy allowlists localhost but fails to restrict the URL scheme, so file URLs select local resources through an HTTP-facing request.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5038d12a-e119-4ab7-aadc-69b765ae7027?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/trunk/ulap.php#L84",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/tags/2.7/ulap.php#L84",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/trunk/ulap.php#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/tags/2.7/ulap.php#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/trunk/ulap.php#L59",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/tags/2.7/ulap.php#L59",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/trunk/ulap.php#L120",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/tags/2.7/ulap.php#L120",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/trunk/ulap.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/tags/2.7/ulap.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3488647%40planyo-online-reservation-system&new=3488647%40planyo-online-reservation-system",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1065,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-3688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-06T23:43:39.850Z",
      "date_published": "2026-07-08T11:35:40.708Z",
      "date_updated": "2026-07-08T15:01:02.908Z",
      "publisher": "Wordfence",
      "title": "WCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite",
      "affected": {
        "vendors": [
          "wclovers"
        ],
        "products": [
          {
            "vendor": "wclovers",
            "product": "WCFM Membership – WooCommerce Memberships for Multivendor Marketplace"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12133
      },
      "nvd": {
        "published": "2026-07-08T12:17:20.430",
        "lastModified": "2026-07-08T16:16:28.610",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3688",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation accepts a caller-supplied object identifier without binding the selected object to the authenticated caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8a934ccd-9330-4585-9994-838940d24980?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3520777/wc-multivendor-membership",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 469,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-3821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-09T02:52:17.984Z",
      "date_published": "2026-07-22T06:15:31.648Z",
      "date_updated": "2026-07-22T12:57:22.874Z",
      "publisher": "Supermicro",
      "title": "Supermicro SMASH service contain an Arbitrary code execution issue",
      "affected": {
        "vendors": [
          "SMCI"
        ],
        "products": [
          {
            "vendor": "SMCI",
            "product": "X14DBG-DAP,X14DBI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:def9a96e-e099-41a9-bfac-30fd4f82c411",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00355,
        "percentile": 0.28206
      },
      "nvd": {
        "published": "2026-07-22T07:16:35.413",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3821",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted input crosses into an executable grammar without context-appropriate separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.supermicro.com/en/support/security_BMC_IPMI_Jul_2026",
          "host": "www.supermicro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-3842",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-09T18:04:03.609Z",
      "date_published": "2026-07-16T00:20:02.910Z",
      "date_updated": "2026-07-16T12:42:09.780Z",
      "publisher": "fedora",
      "title": "Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:patrick@puiterwijk.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02277
      },
      "nvd": {
        "published": "2026-07-16T01:16:30.697",
        "lastModified": "2026-07-16T13:51:12.157",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3842",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Red Hat Enterprise Linux 10 path computes or trusts a write extent that can exceed the destination object's bounds.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-3842",
          "host": "access.redhat.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458150",
          "host": "bugzilla.redhat.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3842.json",
          "host": "security.access.redhat.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "x_sadp-csaf-vex"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-3907",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-10T20:46:25.456Z",
      "date_published": "2026-07-10T07:48:41.019Z",
      "date_updated": "2026-07-10T14:39:09.572Z",
      "publisher": "Wordfence",
      "title": "Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode",
      "affected": {
        "vendors": [
          "prasunsen"
        ],
        "products": [
          {
            "vendor": "prasunsen",
            "product": "Hostel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17017
      },
      "nvd": {
        "published": "2026-07-10T09:16:53.677",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-3907",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Hostel page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/30339c0d-6632-4073-b4d5-3bb4a5b8a58d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hostel/tags/1.1.6/models/hostel.php#L195",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hostel/trunk/controllers/shortcodes.php#L91",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hostel/tags/1.1.6/controllers/shortcodes.php#L91",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hostel/trunk/controllers/shortcodes.php#L79",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hostel/tags/1.1.6/controllers/shortcodes.php#L79",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hostel/trunk/models/hostel.php#L195",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3480942%40hostel&new=3480942%40hostel",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 698,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4017",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-11T19:20:13.205Z",
      "date_published": "2026-07-14T17:25:13.128Z",
      "date_updated": "2026-07-14T23:36:28.181Z",
      "publisher": "blackberry",
      "title": "Buffer overflow in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety",
      "affected": {
        "vendors": [
          "BlackBerry Ltd",
          "BlackBerry Ltd."
        ],
        "products": [
          {
            "vendor": "BlackBerry Ltd",
            "product": "QNX Software Development Platform"
          },
          {
            "vendor": "BlackBerry Ltd",
            "product": "QNX OS for Safety"
          },
          {
            "vendor": "BlackBerry Ltd.",
            "product": "QNX OS for Medical"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 12,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secure@blackberry.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.0212
      },
      "nvd": {
        "published": "2026-07-14T18:17:26.820",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4017",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.blackberry.com/pkb/s/article/141213",
          "host": "support.blackberry.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-4018",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-11T19:24:46.531Z",
      "date_published": "2026-07-14T17:34:01.952Z",
      "date_updated": "2026-07-15T14:01:13.318Z",
      "publisher": "blackberry",
      "title": "TOCTOU race condition in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety",
      "affected": {
        "vendors": [
          "BlackBerry Ltd",
          "BlackBerry Ltd."
        ],
        "products": [
          {
            "vendor": "BlackBerry Ltd",
            "product": "QNX Software Development Platform"
          },
          {
            "vendor": "BlackBerry Ltd",
            "product": "QNX OS for Safety"
          },
          {
            "vendor": "BlackBerry Ltd.",
            "product": "QNX OS for Medical"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 12,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secure@blackberry.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00092,
        "percentile": 0.0062
      },
      "nvd": {
        "published": "2026-07-14T18:17:26.943",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4018",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.blackberry.com/pkb/s/article/141213",
          "host": "support.blackberry.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-4249",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T05:47:35.673Z",
      "date_published": "2026-07-06T10:16:56.055Z",
      "date_updated": "2026-07-06T11:03:48.847Z",
      "publisher": "WSO2",
      "title": "Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption",
      "affected": {
        "vendors": [
          "WSO2"
        ],
        "products": [
          {
            "vendor": "WSO2",
            "product": "WSO2 Universal Gateway"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 Traffic Manager"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 API Control Plane"
          },
          {
            "vendor": "WSO2",
            "product": "WSO2 API Manager"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 20,
        "versionRangeCount": 20,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-707",
          "name": "Improper Neutralization",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:ed10eef1-636d-4fbe-9993-6890dfa878f8",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26493
      },
      "nvd": {
        "published": "2026-07-06T11:16:30.433",
        "lastModified": "2026-07-09T13:04:57.540",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-4249",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The throttling-event handler accepts structurally invalid attacker JSON into persistent processing state, but the public advisory does not disclose the failing parser or recovery transition.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-707"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5236/",
          "host": "security.docs.wso2.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-4256",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T07:44:00.802Z",
      "date_published": "2026-07-09T13:15:55.283Z",
      "date_updated": "2026-07-09T13:42:03.407Z",
      "publisher": "TR-CERT",
      "title": "LDAP Injection in PEAKUP's PassGate",
      "affected": {
        "vendors": [
          "PEAKUP Technology Inc."
        ],
        "products": [
          {
            "vendor": "PEAKUP Technology Inc.",
            "product": "PassGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-90",
          "name": "Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11692
      },
      "nvd": {
        "published": "2026-07-09T14:16:32.640",
        "lastModified": "2026-07-09T16:21:30.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4256",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application inserts attacker-controlled text into an LDAP filter without separating the value from LDAP query syntax.",
        "basis": [
          "CNA",
          "CWE-90"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0523",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4275",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T15:20:23.202Z",
      "date_published": "2026-07-09T09:31:21.638Z",
      "date_updated": "2026-07-09T17:22:23.953Z",
      "publisher": "Wordfence",
      "title": "Divi Torque Lite <= 4.2.3 - Cross-Site Request Forgery to Arbitrary Plugin Installation via 'install_plugin' REST Endpoint",
      "affected": {
        "vendors": [
          "badhonrocks"
        ],
        "products": [
          {
            "vendor": "badhonrocks",
            "product": "Divi Torque Lite – Divi Modules for the Divi Builder & Theme"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08494
      },
      "nvd": {
        "published": "2026-07-09T11:16:39.630",
        "lastModified": "2026-07-09T18:16:52.267",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4275",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "REST install and activate routes use an always-allow permission callback, so a cross-site request can ride an administrator's cookies without a REST nonce.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8be98cba-b891-42cf-8a6c-8fe05f27c9c3?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/tags/4.2.2/includes/rest-api.php#L81",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/rest-api.php#L81",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/rest-api.php#L230",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/tags/4.2.2/includes/rest-api.php#L230",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/rest-api.php#L75",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/tags/4.2.2/includes/rest-api.php#L75",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3559041%40addons-for-divi&new=3559041%40addons-for-divi",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 722,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4298",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T19:14:02.711Z",
      "date_published": "2026-07-09T09:31:21.285Z",
      "date_updated": "2026-07-09T14:39:42.090Z",
      "publisher": "Wordfence",
      "title": "DSGVO All in one for WP <= 4.9 - Missing Authorization to Authenticated (Subscriber+) Settings Reset",
      "affected": {
        "vendors": [
          "mlfactory"
        ],
        "products": [
          {
            "vendor": "mlfactory",
            "product": "DSGVO All in one for WP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10518
      },
      "nvd": {
        "published": "2026-07-09T11:16:39.757",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4298",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "dsgvo_reset_policy_service_func resets plugin settings without either a capability check or nonce verification.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6d8a5268-03a2-48c6-9c59-840a11e7a34f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dsgvo-all-in-one-for-wp/trunk/dsgvo_all_in_one_wp.php#L1123",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dsgvo-all-in-one-for-wp/tags/4.9/dsgvo_all_in_one_wp.php#L1123",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dsgvo-all-in-one-for-wp/trunk/dsgvo_all_in_one_wp.php#L56",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dsgvo-all-in-one-for-wp/tags/4.9/dsgvo_all_in_one_wp.php#L56",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3503821%40dsgvo-all-in-one-for-wp&new=3503821%40dsgvo-all-in-one-for-wp",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 568,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4321",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-17T11:53:19.729Z",
      "date_published": "2026-07-03T08:54:03.784Z",
      "date_updated": "2026-07-06T17:30:17.328Z",
      "publisher": "TR-CERT",
      "title": "SQLi in Raera's Destekz",
      "affected": {
        "vendors": [
          "Raera - Ankara Web Design and Digital Advertising Agency"
        ],
        "products": [
          {
            "vendor": "Raera - Ankara Web Design and Digital Advertising Agency",
            "product": "Destekz"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18313
      },
      "nvd": {
        "published": "2026-07-03T10:16:32.760",
        "lastModified": "2026-07-06T18:16:46.247",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4321",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows SQL Injection.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0488",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4322",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-17T12:19:47.203Z",
      "date_published": "2026-07-03T08:58:08.339Z",
      "date_updated": "2026-07-06T17:29:49.531Z",
      "publisher": "TR-CERT",
      "title": "XSS in Raera's Destekz",
      "affected": {
        "vendors": [
          "Raera - Ankara Web Design and Digital Advertising Agency"
        ],
        "products": [
          {
            "vendor": "Raera - Ankara Web Design and Digital Advertising Agency",
            "product": "Destekz"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04576
      },
      "nvd": {
        "published": "2026-07-03T10:16:32.993",
        "lastModified": "2026-07-06T18:16:46.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4322",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0488",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4375",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-18T12:16:21.066Z",
      "date_published": "2026-07-07T06:00:01.899Z",
      "date_updated": "2026-07-07T13:18:43.079Z",
      "publisher": "WPScan",
      "title": "DoLeads Integrator <= 1.2.2 & wp2epub <= 0.65 - Unauthenticated RCE",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "DoLeads Integrator"
          },
          {
            "vendor": "Unknown",
            "product": "wp2epub"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16191
      },
      "nvd": {
        "published": "2026-07-07T06:16:22.360",
        "lastModified": "2026-07-07T14:16:32.257",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4375",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says the plugins have been used after unauthorized installation to obtain code execution but identifies no defective check or execution boundary in either plugin.",
        "basis": [
          "CNA",
          "WPScan advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://wpscan.com/vulnerability/dd043e6c-e6c6-4c8d-aab0-5265d28f5cf6/; it repeats the embedded description, withholds the proof of concept, lists no known fix, and links no vendor source."
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/dd043e6c-e6c6-4c8d-aab0-5265d28f5cf6/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 290,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-4604",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-22T20:18:40.722Z",
      "date_published": "2026-07-29T09:31:13.403Z",
      "date_updated": "2026-07-29T12:10:02.325Z",
      "publisher": "Wordfence",
      "title": "Klubraum Membership Request <= 1.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Update",
      "affected": {
        "vendors": [
          "klubraum"
        ],
        "products": [
          {
            "vendor": "klubraum",
            "product": "Klubraum Membership Request"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14486
      },
      "nvd": {
        "published": "2026-07-29T11:16:49.390",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4604",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Klubraum Membership Request fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/09e158d2-f9a6-41a6-a91f-1763a1a44b04?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/klubraum-membership-request/trunk/admin/class-klubraum-membership-request-widget-admin.php#L152",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/klubraum-membership-request/tags/1.1.0/admin/class-klubraum-membership-request-widget-admin.php#L152",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/klubraum-membership-request/tags/1.1.0/admin/class-klubraum-membership-request-widget-admin.php#L151",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3491619%40klubraum-membership-request%2Ftrunk%2Fadmin%2Fclass-klubraum-membership-request-widget-admin.php&old=2512635%40klubraum-membership-request%2Ftrunk%2Fadmin%2Fclass-klubraum-membership-request-widget-admin.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 439,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4648",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T12:50:31.162Z",
      "date_published": "2026-07-28T11:41:15.571Z",
      "date_updated": "2026-07-28T12:04:41.531Z",
      "publisher": "INCIBE",
      "title": "Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands",
      "affected": {
        "vendors": [
          "CasfID Servicios Tecnológicos"
        ],
        "products": [
          {
            "vendor": "CasfID Servicios Tecnológicos",
            "product": "NFC Wristbands"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-326",
          "name": "Inadequate Encryption Strength",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.02027
      },
      "nvd": {
        "published": "2026-07-28T12:16:36.467",
        "lastModified": "2026-07-28T16:20:10.853",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4648",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The wristband uses a weak MIFARE Classic authentication algorithm whose keys can be recovered and cloned.",
        "basis": [
          "CNA",
          "CWE-326"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/insufficient-encryption-level-casfid-servicios-tecnologicos-nfc",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 728,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4653",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T14:53:50.936Z",
      "date_published": "2026-07-09T06:52:44.374Z",
      "date_updated": "2026-07-09T14:09:46.935Z",
      "publisher": "Wordfence",
      "title": "Block, Suspend, Report for BuddyPress <= 3.6.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link' Parameter",
      "affected": {
        "vendors": [
          "bouncingsprout"
        ],
        "products": [
          {
            "vendor": "bouncingsprout",
            "product": "Block, Suspend, Report for BuddyPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09452
      },
      "nvd": {
        "published": "2026-07-09T08:16:48.373",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4653",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The BuddyPress reporting plugin stores the link parameter and later renders it as active browser markup without sufficient sanitization and escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/01cd05c3-9629-4da4-ae9d-f99003253b95?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bp-toolkit/trunk/admin/partials/report-cpt-main-metabox.php#L115",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bp-toolkit/tags/3.6.4/admin/partials/report-cpt-main-metabox.php#L115",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bp-toolkit/trunk/includes/class-bp-toolkit-report.php#L260",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bp-toolkit/tags/3.6.4/includes/class-bp-toolkit-report.php#L260",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3523211%40bp-toolkit&new=3523211%40bp-toolkit",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4661",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T16:11:31.414Z",
      "date_published": "2026-07-11T05:35:48.631Z",
      "date_updated": "2026-07-13T14:29:23.768Z",
      "publisher": "Wordfence",
      "title": "WP CTA <= 2.2.2 - Unauthenticated Time-Based Blind SQL Injection via 'fildname' Parameter",
      "affected": {
        "vendors": [
          "blendmedia"
        ],
        "products": [
          {
            "vendor": "blendmedia",
            "product": "WP CTA – Call Now Button, Sticky Button & Call to Action Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25195
      },
      "nvd": {
        "published": "2026-07-11T07:16:46.513",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4661",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WP CTA – Call Now Button, Sticky Button & Call to Action Builder data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7e963601-dc41-4218-9119-708c74e51bc2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-sticky-sidebar/tags/1.7.4/inc/ClassActions.php#L193",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-sticky-sidebar/tags/1.7.4/inc/ClassActions.php#L186",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-sticky-sidebar/tags/1.7.4/inc/ClassActions.php#L17",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3524743%40easy-sticky-sidebar&new=3524743%40easy-sticky-sidebar",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 737,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4672",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T21:03:56.356Z",
      "date_published": "2026-07-29T19:01:31.039Z",
      "date_updated": "2026-07-29T19:35:54.247Z",
      "publisher": "GitLab",
      "title": "Missing Authorization in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20753
      },
      "nvd": {
        "published": "2026-07-29T20:17:03.963",
        "lastModified": "2026-08-03T14:03:16.267",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-4672",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/594528",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3617676",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-4765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-24T11:45:47.723Z",
      "date_published": "2026-07-13T10:16:33.027Z",
      "date_updated": "2026-07-13T13:14:19.490Z",
      "publisher": "INCIBE",
      "title": "Stored Cross-Site Scripting (XSS) in Tallos Chat by RD Station Conversas",
      "affected": {
        "vendors": [
          "RD Station Conversas"
        ],
        "products": [
          {
            "vendor": "RD Station Conversas",
            "product": "Tallos Chat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.1939
      },
      "nvd": {
        "published": "2026-07-13T11:16:27.450",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4765",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Tallos Chat rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xss-tallos-chat-rd-station-conversas",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-24T12:59:26.386Z",
      "date_published": "2026-07-02T13:12:30.753Z",
      "date_updated": "2026-07-02T13:48:08.975Z",
      "publisher": "TR-CERT",
      "title": "Improper Access Control in TR7's WAF-ASP",
      "affected": {
        "vendors": [
          "TR7 Cyber ​​Defense Inc."
        ],
        "products": [
          {
            "vendor": "TR7 Cyber ​​Defense Inc.",
            "product": "WAF-ASP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25835
      },
      "nvd": {
        "published": "2026-07-02T14:16:25.527",
        "lastModified": "2026-07-02T15:17:02.350",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4767",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive function can be invoked without enforcing the caller authentication required for that operation.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0487",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-24T13:19:36.714Z",
      "date_published": "2026-07-13T06:35:01.116Z",
      "date_updated": "2026-07-13T14:44:48.962Z",
      "publisher": "CERTVDE",
      "title": "Unauthenticated Access to Internal Diagnostic Interface",
      "affected": {
        "vendors": [
          "WAGO"
        ],
        "products": [
          {
            "vendor": "WAGO",
            "product": "0765-110x/0100-0000"
          },
          {
            "vendor": "WAGO",
            "product": "0765-120x/0100-0000"
          },
          {
            "vendor": "WAGO",
            "product": "0765-150x/0100-0000"
          },
          {
            "vendor": "WAGO",
            "product": "0765-2101/0100-0000"
          },
          {
            "vendor": "WAGO",
            "product": "0765-2102/0100-0000"
          },
          {
            "vendor": "WAGO",
            "product": "0765-410x/0100-0000"
          },
          {
            "vendor": "WAGO",
            "product": "0765-420x/0100-0000"
          },
          {
            "vendor": "WAGO",
            "product": "0765-450x/0100-0000"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-912",
          "name": "Hidden Functionality",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00447,
        "percentile": 0.36717
      },
      "nvd": {
        "published": "2026-07-13T08:16:21.343",
        "lastModified": "2026-07-13T19:58:29.933",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4769",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Production devices expose an undocumented unauthenticated diagnostic service during an early boot window.",
        "basis": [
          "CNA",
          "CWE-912"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-031/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-4770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-24T13:29:09.973Z",
      "date_published": "2026-07-02T12:37:13.555Z",
      "date_updated": "2026-07-02T13:15:06.196Z",
      "publisher": "TR-CERT",
      "title": "DOM-Based XSS in TR7's WAF-ASP",
      "affected": {
        "vendors": [
          "TR7 Cyber ​​Defense Inc."
        ],
        "products": [
          {
            "vendor": "TR7 Cyber ​​Defense Inc.",
            "product": "WAF-ASP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03235
      },
      "nvd": {
        "published": "2026-07-02T13:16:55.170",
        "lastModified": "2026-07-02T15:13:11.783",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4770",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Client-side code in WAF-ASP places attacker-controlled data into an executable DOM context without sufficient sanitization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0487",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4772",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-24T13:35:28.124Z",
      "date_published": "2026-07-02T12:50:55.561Z",
      "date_updated": "2026-07-02T13:15:20.596Z",
      "publisher": "TR-CERT",
      "title": "Stored XSS in TR7's WAF-ASP",
      "affected": {
        "vendors": [
          "TR7 Cyber ​​Defense Inc."
        ],
        "products": [
          {
            "vendor": "TR7 Cyber ​​Defense Inc.",
            "product": "WAF-ASP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03236
      },
      "nvd": {
        "published": "2026-07-02T13:16:55.293",
        "lastModified": "2026-07-02T15:13:11.783",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4772",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WAF-ASP stores attacker-controlled browser content without the neutralization required before HTML rendering.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0487",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4773",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-24T13:41:44.976Z",
      "date_published": "2026-07-22T12:08:20.308Z",
      "date_updated": "2026-07-22T12:43:01.406Z",
      "publisher": "TR-CERT",
      "title": "OTP Bypass in Magarsus' IDM-MFA",
      "affected": {
        "vendors": [
          "Magarsus Consulting Ltd. Co."
        ],
        "products": [
          {
            "vendor": "Magarsus Consulting Ltd. Co.",
            "product": "IDM-MFA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1287",
          "name": "Improper Validation of Specified Type of Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24358
      },
      "nvd": {
        "published": "2026-07-22T12:18:12.587",
        "lastModified": "2026-07-22T16:21:53.517",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4773",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "IDM-MFA accepts an OTP value whose specified input type has not been validated, allowing the authentication decision to be bypassed.",
        "basis": [
          "CNA record",
          "CWE-1287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0607",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T11:38:39.477Z",
      "date_published": "2026-07-03T07:53:09.987Z",
      "date_updated": "2026-07-06T16:25:45.616Z",
      "publisher": "Wordfence",
      "title": "Zakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST API",
      "affected": {
        "vendors": [
          "themegrill"
        ],
        "products": [
          {
            "vendor": "themegrill",
            "product": "Zakra"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07493
      },
      "nvd": {
        "published": "2026-07-03T09:16:37.520",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4804",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "REST-writable post metadata bypasses sanitization and is concatenated into inline CSS without escaping, enabling stored script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bbda67a3-0413-4d8e-8157-84c9c87b8695?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://themes.trac.wordpress.org/changeset?reponame=&new=330192%40zakra%2F4.2.1&old=297420%40zakra%2F4.2.0#file39",
          "host": "themes.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 941,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4912",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-26T16:24:34.319Z",
      "date_published": "2026-07-28T18:35:52.515Z",
      "date_updated": "2026-07-28T19:37:49.185Z",
      "publisher": "Wordfence",
      "title": "Media Cleaner: Clean your WordPress! <= 7.0.3 - Authenticated (Administrator+) Server-Side Request Forgery",
      "affected": {
        "vendors": [
          "tigroumeow"
        ],
        "products": [
          {
            "vendor": "tigroumeow",
            "product": "Media Cleaner: Clean your WordPress!"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15197
      },
      "nvd": {
        "published": "2026-07-28T19:17:36.147",
        "lastModified": "2026-07-28T20:34:39.437",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4912",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Media Cleaner: Clean your WordPress! follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e9c9214d-45d4-4477-8244-7802a4901114?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/media-cleaner/tags/7.0.3/classes/core.php#L565",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/media-cleaner/tags/7.0.3/classes/core.php#L570",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/media-cleaner/tags/7.0.3/classes/rest.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&n%20ew3492257%40media-cleaner%2Ftrunk&old=3447443%40media-cleaner%2Ftrunk&sfp_ema%20il=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 619,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4932",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-26T19:43:02.211Z",
      "date_published": "2026-07-28T18:09:32.739Z",
      "date_updated": "2026-07-28T18:46:57.145Z",
      "publisher": "ibm",
      "title": "This Power System update is being released to address Insufficient Entropy",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "PowerVM Hypervisor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-331",
          "name": "Insufficient Entropy",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Primary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00081,
        "percentile": 0.00257
      },
      "nvd": {
        "published": "2026-07-28T19:17:36.287",
        "lastModified": "2026-07-28T20:36:09.267",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4932",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The memory-encryption design derives protection from insufficient entropy, weakening the secrecy of encrypted memory.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-331"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280632",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-4938",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-26T21:00:56.474Z",
      "date_published": "2026-07-17T19:34:14.956Z",
      "date_updated": "2026-07-28T18:08:00.558Z",
      "publisher": "ibm",
      "title": "Incorrect Authorization in IBM Verify Identity Access and IBM Security Verify Access",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Verify Identity Access"
          },
          {
            "vendor": "IBM",
            "product": "Security Verify Access"
          },
          {
            "vendor": "IBM",
            "product": "Verify Identity Access Container"
          },
          {
            "vendor": "IBM",
            "product": "Security Verify Access Container"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07128
      },
      "nvd": {
        "published": "2026-07-17T20:17:23.410",
        "lastModified": "2026-07-30T13:07:59.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-4938",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow an attacker with read-only privileges to make unauthorized modifications and deployments outside of their assigned permissions.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279510",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-4942",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-26T21:14:44.344Z",
      "date_published": "2026-07-17T19:32:02.440Z",
      "date_updated": "2026-07-20T13:52:49.123Z",
      "publisher": "ibm",
      "title": "IBM i is Affected by Algorithm Downgrade in Transport Layer Security []",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "i"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-757",
          "name": "Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16788
      },
      "nvd": {
        "published": "2026-07-17T20:17:23.560",
        "lastModified": "2026-07-20T17:15:53.673",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4942",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "IBM i can negotiate a TLS version that server configuration explicitly disabled when processing a crafted peer message.",
        "basis": [
          "CNA",
          "CWE-757"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278992",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-4967",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-27T08:39:20.675Z",
      "date_published": "2026-07-03T05:52:23.325Z",
      "date_updated": "2026-07-06T17:33:00.630Z",
      "publisher": "Unisoc",
      "title": "In IMS, there is a possible out of bounds read due to a missing bounds check.",
      "affected": {
        "vendors": [
          "Unisoc (Shanghai) Technologies Co., Ltd."
        ],
        "products": [
          {
            "vendor": "Unisoc (Shanghai) Technologies Co., Ltd.",
            "product": "SC7731E/SC9832E/SC9863A/T310/T610/T618/T7200/T7225/T7250/T7255/T7280/T7300/T8100/T9100/T8200/T8300"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@unisoc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33161
      },
      "nvd": {
        "published": "2026-07-03T07:16:24.333",
        "lastModified": "2026-07-06T19:46:08.807",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4967",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "IMS reads beyond an input buffer because it omits a required bounds check.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.unisoc.com/en/support/product-security-bulletin/2072920457676509185",
          "host": "www.unisoc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-4978",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-27T10:24:26.424Z",
      "date_published": "2026-07-30T14:53:36.922Z",
      "date_updated": "2026-07-30T16:10:12.292Z",
      "publisher": "TR-CERT",
      "title": "SQLi in UMAI Vision's Traffic Analysis System",
      "affected": {
        "vendors": [
          "UMAI Vision"
        ],
        "products": [
          {
            "vendor": "UMAI Vision",
            "product": "Traffic Analysis System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.1766
      },
      "nvd": {
        "published": "2026-07-30T16:17:12.933",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-4978",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-89",
          "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0703"
        ],
        "deepDive": true,
        "notes": "Reviewed https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0703. The Turkish Cyber Security Presidency page exposed no readable technical detail beyond the linked record, so the SQL construction remains undisclosed."
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0703",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5005",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-27T13:52:23.527Z",
      "date_published": "2026-07-09T14:13:00.362Z",
      "date_updated": "2026-07-14T07:43:40.417Z",
      "publisher": "TR-CERT",
      "title": "Stored XSS in Twiser's OKRs & Goals",
      "affected": {
        "vendors": [
          "Twiser Informatics Technology Consulting, Trade and Education Inc."
        ],
        "products": [
          {
            "vendor": "Twiser Informatics Technology Consulting, Trade and Education Inc.",
            "product": "OKRs & Goals"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03235
      },
      "nvd": {
        "published": "2026-07-09T15:16:40.943",
        "lastModified": "2026-07-09T16:21:30.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5005",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OKRs and Goals application stores attacker-controlled content and renders it into a browser-executable page without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0524",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5040",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-27T16:26:49.615Z",
      "date_published": "2026-07-14T18:00:32.162Z",
      "date_updated": "2026-07-15T10:27:47.808Z",
      "publisher": "TPLink",
      "title": "Weak Password Hashing Mechanism in TP-Link Deco M5",
      "affected": {
        "vendors": [
          "TP-Link Systems Inc."
        ],
        "products": [
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "Deco M5 Deco M5 V1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-916",
          "name": "Use of Password Hash With Insufficient Computational Effort",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f23511db-6c3e-4e32-a477-6aa17d310630",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00093,
        "percentile": 0.00675
      },
      "nvd": {
        "published": "2026-07-14T19:18:03.213",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5040",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The device stores passwords with a weak hash that permits practical offline brute-force or dictionary recovery after hash disclosure.",
        "basis": [
          "CNA",
          "CWE-916"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tp-link.com/us/support/download/deco-m5/v1/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.tp-link.com/en/support/download/deco-m5/v1/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.tp-link.com/us/support/faq/5190/",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 489,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5051",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-27T17:45:14.081Z",
      "date_published": "2026-07-01T17:10:56.918Z",
      "date_updated": "2026-07-01T17:54:43.314Z",
      "publisher": "HashiCorp",
      "title": "Audit Log Plugin Directory Guard Bypass via Legacy path Option",
      "affected": {
        "vendors": [
          "HashiCorp"
        ],
        "products": [
          {
            "vendor": "HashiCorp",
            "product": "Vault"
          },
          {
            "vendor": "HashiCorp",
            "product": "Vault Enterprise"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@hashicorp.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20089
      },
      "nvd": {
        "published": "2026-07-01T18:16:36.227",
        "lastModified": "2026-07-02T17:54:27.573",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5051",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.hashicorp.com/t/hcsec-2026-16-vault-audit-device-plugin-directory-guard-bypass-via-legacy-path-option/77536",
          "host": "discuss.hashicorp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-5056",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-27T18:07:56.748Z",
      "date_published": "2026-07-29T19:10:33.316Z",
      "date_updated": "2026-07-30T03:55:38.937Z",
      "publisher": "zdi",
      "title": "GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "GStreamer"
        ],
        "products": [
          {
            "vendor": "GStreamer",
            "product": "GStreamer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00426,
        "percentile": 0.35055
      },
      "nvd": {
        "published": "2026-07-29T20:17:05.337",
        "lastModified": "2026-07-30T14:19:24.857",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5056",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "qtdemux copies an attacker-supplied UncompressedFrameConfigBox length into a fixed stack buffer without validating the length.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-283/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        },
        {
          "url": "https://gitlab.freedesktop.org/api/v4/projects/gstreamer%2Fgstreamer/repository/files/security-advisories%2Fsa-2026-0016.md/raw?ref=main",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/05/01/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 676,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5057",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-27T18:08:40.710Z",
      "date_published": "2026-07-29T19:10:50.040Z",
      "date_updated": "2026-07-29T19:40:52.379Z",
      "publisher": "zdi",
      "title": "ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability",
      "affected": {
        "vendors": [
          "ATEN"
        ],
        "products": [
          {
            "vendor": "ATEN",
            "product": "Unizon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00484,
        "percentile": 0.39142
      },
      "nvd": {
        "published": "2026-07-29T20:17:05.497",
        "lastModified": "2026-07-30T14:19:24.857",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5057",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ATEN Unizon exposes the RpcProvider operation without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-272/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        },
        {
          "url": "https://www.aten.com/global/en/supportcenter/info/security-advisory/26/",
          "host": "www.aten.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5060",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-27T18:10:20.617Z",
      "date_published": "2026-07-29T09:31:14.881Z",
      "date_updated": "2026-07-29T15:07:22.056Z",
      "publisher": "Wordfence",
      "title": "MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion",
      "affected": {
        "vendors": [
          "stylemix"
        ],
        "products": [
          {
            "vendor": "stylemix",
            "product": "MasterStudy LMS WordPress Plugin – for Online Courses and Education"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12665
      },
      "nvd": {
        "published": "2026-07-29T11:16:50.093",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5060",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the `file_id` parameter before passing it to `wp_delete_attachment()`.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/de11c9ad-0b9f-4934-8dc9-dc324d77d702?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/masterstudy-lms-learning-management-system/tags/3.7.14/_core/lms/classes/user.php#L2107",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/masterstudy-lms-learning-management-system/tags/3.7.14/_core/lms/classes/user.php#L2093",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3501788%40masterstudy-lms-learning-management-system%2Ftrunk&old=3496678%40masterstudy-lms-learning-management-system%2Ftrunk&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5069",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-27T22:53:28.217Z",
      "date_published": "2026-07-10T02:30:39.977Z",
      "date_updated": "2026-07-10T18:02:38.866Z",
      "publisher": "Wordfence",
      "title": "Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id'",
      "affected": {
        "vendors": [
          "wpmanageninja"
        ],
        "products": [
          {
            "vendor": "wpmanageninja",
            "product": "Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06768
      },
      "nvd": {
        "published": "2026-07-10T04:17:52.833",
        "lastModified": "2026-07-10T19:17:27.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5069",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The subscription operation accepts an object identifier without checking that the caller owns that subscription.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e7521577-ce13-4b60-ae11-9c0f9c077cf9?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3513845/fluentform",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5114",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-29T21:55:12.924Z",
      "date_published": "2026-07-28T18:35:52.121Z",
      "date_updated": "2026-07-29T15:25:11.301Z",
      "publisher": "Wordfence",
      "title": "SpeedyCache <= 1.3.8 - Authenticated (Administrator+) Arbitrary File Read",
      "affected": {
        "vendors": [
          "softaculous"
        ],
        "products": [
          {
            "vendor": "softaculous",
            "product": "SpeedyCache – Cache, Optimization, Performance"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26636
      },
      "nvd": {
        "published": "2026-07-28T19:17:39.880",
        "lastModified": "2026-07-29T16:17:55.300",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5114",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SpeedyCache validates a CSS URL before stripping its query string, then reads the resolved non-CSS path without confining it to an allowed file type or root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cfefcc38-764d-4dd9-b098-cdcad475d634?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/speedycache/tags/1.3.7/main/css.php#L137",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/speedycache/tags/1.3.7/main/util.php#L75",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 662,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5120",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-30T07:15:44.963Z",
      "date_published": "2026-07-01T12:16:57.432Z",
      "date_updated": "2026-07-01T13:36:37.270Z",
      "publisher": "3DS",
      "title": "Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026",
      "affected": {
        "vendors": [
          "Dassault Systèmes"
        ],
        "products": [
          {
            "vendor": "Dassault Systèmes",
            "product": "BIOVIA Workbook"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:3DS.Information-Security@3ds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08845
      },
      "nvd": {
        "published": "2026-07-01T13:17:48.033",
        "lastModified": "2026-07-02T17:39:57.427",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5120",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Workbook has a race that can expose one user's data to another, but the record does not identify the shared state or interleaving.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.3ds.com/trust-center/security/security-advisories/cve-2026-5120",
          "host": "www.3ds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 161,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-5135",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-30T10:42:55.307Z",
      "date_published": "2026-07-01T14:08:39.712Z",
      "date_updated": "2026-07-01T23:53:14.087Z",
      "publisher": "redhat",
      "title": "Foreman: foreman: unauthorized modification of host configurations via broken access control",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.16 for RHEL 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.16 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.17 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.18 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.19 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18304
      },
      "nvd": {
        "published": "2026-07-01T15:17:11.740",
        "lastModified": "2026-07-09T02:39:11.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-5135",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Foreman lets a host editor retarget a lookup override by changing its nested match field without checking the new host's organization and location scope.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34365",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34366",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34367",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34368",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5135",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452230",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 465,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-5136",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-30T10:47:46.043Z",
      "date_published": "2026-07-01T13:28:00.316Z",
      "date_updated": "2026-07-02T03:56:14.203Z",
      "publisher": "redhat",
      "title": "Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.16 for RHEL 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.16 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.17 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.18 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.19 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25155
      },
      "nvd": {
        "published": "2026-07-01T14:16:47.277",
        "lastModified": "2026-07-09T02:39:36.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-5136",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Red Hat Satellite 6.16 for RHEL 8 role-assignment path grants a role that the requesting user lacks authority to assign.",
        "basis": [
          "CNA",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34365",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34366",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34367",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34368",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5136",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452970",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 459,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-5137",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-30T10:48:18.196Z",
      "date_published": "2026-07-03T09:31:52.399Z",
      "date_updated": "2026-07-06T14:44:45.786Z",
      "publisher": "Wordfence",
      "title": "RTMKit <= 2.0.7 - Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter",
      "affected": {
        "vendors": [
          "rometheme"
        ],
        "products": [
          {
            "vendor": "rometheme",
            "product": "RTMKit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18377
      },
      "nvd": {
        "published": "2026-07-03T10:16:33.113",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5137",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker can select a filesystem path outside the directory intended for the operation.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/22172d16-bcde-4516-bce0-222fbb7a76f7?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rometheme-for-elementor/tags/2.0.3/Inc/Modules/Templatekits/TemplatekitAPI.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rometheme-for-elementor/trunk/Inc/Modules/Templatekits/TemplatekitAPI.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3568335/rometheme-for-elementor/trunk/Inc/Modules/Templatekits/TemplatekitAPI.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Frometheme-for-elementor/tags/2.0.7&new_path=%2Frometheme-for-elementor/tags/2.0.8",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5138",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-30T10:53:25.776Z",
      "date_published": "2026-07-01T14:08:43.978Z",
      "date_updated": "2026-07-01T23:53:14.772Z",
      "publisher": "redhat",
      "title": "Foreman: foreman: information disclosure via improper validation of nested request parameters",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.16 for RHEL 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.16 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.17 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.18 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.19 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16256
      },
      "nvd": {
        "published": "2026-07-01T15:17:11.860",
        "lastModified": "2026-07-09T02:38:49.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-5138",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Red Hat Satellite 6.16 for RHEL 8 request path accepts an attacker-selected object identifier without binding that object to the caller's tenant, owner, or permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34365",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34366",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34367",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34368",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5138",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452971",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-5142",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-30T12:08:56.764Z",
      "date_published": "2026-07-01T14:07:55.662Z",
      "date_updated": "2026-07-01T23:53:16.614Z",
      "publisher": "redhat",
      "title": "Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypass",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.16 for RHEL 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.16 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.17 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.18 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.19 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19972
      },
      "nvd": {
        "published": "2026-07-01T15:17:11.977",
        "lastModified": "2026-07-09T02:38:36.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-5142",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34365",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34366",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34367",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34368",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5142",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2452999",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 359,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-5219",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-31T11:50:13.083Z",
      "date_published": "2026-07-30T13:43:14.891Z",
      "date_updated": "2026-07-31T13:27:29.128Z",
      "publisher": "TR-CERT",
      "title": "CSRF in Softtr's E-Commerce Pack",
      "affected": {
        "vendors": [
          "Softtr Information Technology Trade Ltd. Co."
        ],
        "products": [
          {
            "vendor": "Softtr Information Technology Trade Ltd. Co.",
            "product": "E-Commerce Pack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03318
      },
      "nvd": {
        "published": "2026-07-30T14:17:01.747",
        "lastModified": "2026-07-31T14:16:50.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5219",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A state-changing e-commerce request can be submitted from another site without a reliable request-origin token.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0702",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-31T11:56:09.964Z",
      "date_published": "2026-07-01T14:12:54.765Z",
      "date_updated": "2026-07-01T14:55:07.615Z",
      "publisher": "TR-CERT",
      "title": "Stored XSS in DivvyDrive Information Technologies' DivvyDrive",
      "affected": {
        "vendors": [
          "DivvyDrive Information Technologies Inc."
        ],
        "products": [
          {
            "vendor": "DivvyDrive Information Technologies Inc.",
            "product": "DivvyDrive"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04479
      },
      "nvd": {
        "published": "2026-07-01T15:17:12.090",
        "lastModified": "2026-07-01T16:16:52.967",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5220",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In DivvyDrive, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0475",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5268",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-31T19:44:32.296Z",
      "date_published": "2026-07-06T15:25:56.938Z",
      "date_updated": "2026-07-08T20:18:06.557Z",
      "publisher": "Ciena",
      "title": "SFTP Server Authentication Weakness",
      "affected": {
        "vendors": [
          "CIENA"
        ],
        "products": [
          {
            "vendor": "CIENA",
            "product": "6500 S-Series"
          },
          {
            "vendor": "CIENA",
            "product": "6500 T-Series"
          },
          {
            "vendor": "CIENA",
            "product": "PTS"
          },
          {
            "vendor": "CIENA",
            "product": "CPL"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0042,
        "percentile": 0.34588
      },
      "nvd": {
        "published": "2026-07-06T16:16:38.433",
        "lastModified": "2026-07-08T21:16:54.663",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5268",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Ciena's default SFTP server permits unauthenticated filesystem access, but the official advisory does not disclose the alternate path, credential decision, or failing authentication check.",
        "basis": [
          "CNA",
          "CWE-288",
          "Ciena Product Security"
        ],
        "deepDive": true,
        "notes": "https://www.ciena.com/product-security - Ciena confirms an authentication bypass in the default SFTP server, affected product lines, filesystem impact, and remediation, but does not disclose the alternate path, credential decision, or failing check."
      },
      "references": [
        {
          "url": "https://www.ciena.com/product-security",
          "host": "www.ciena.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 353,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-5269",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-31T19:44:35.713Z",
      "date_published": "2026-07-14T22:25:55.317Z",
      "date_updated": "2026-07-15T14:30:50.769Z",
      "publisher": "Ciena",
      "title": "Navigator NCS and MCP System Accounts with Default Passwords",
      "affected": {
        "vendors": [
          "CIENA"
        ],
        "products": [
          {
            "vendor": "CIENA",
            "product": "Navigator NCS"
          },
          {
            "vendor": "CIENA",
            "product": "MCP"
          },
          {
            "vendor": "CIENA",
            "product": "Planner Plus OnPrem"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1393",
          "name": "Use of Default Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19549
      },
      "nvd": {
        "published": "2026-07-14T23:17:34.453",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5269",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Navigator NCS deployment includes predictable default credentials on hidden system accounts.",
        "basis": [
          "CNA",
          "CWE-1393"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ciena.com/product-security",
          "host": "www.ciena.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 479,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-5270",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-31T19:44:41.118Z",
      "date_published": "2026-07-14T22:24:34.750Z",
      "date_updated": "2026-07-15T12:39:32.248Z",
      "publisher": "Ciena",
      "title": "Authentication Bypass in Navigator and Blue Planet Products",
      "affected": {
        "vendors": [
          "Blue Planet",
          "CIENA"
        ],
        "products": [
          {
            "vendor": "CIENA",
            "product": "Navigator NCS"
          },
          {
            "vendor": "CIENA",
            "product": "MCP"
          },
          {
            "vendor": "CIENA",
            "product": "Planner Plus OnPrem"
          },
          {
            "vendor": "Blue Planet",
            "product": "Inventory"
          },
          {
            "vendor": "Blue Planet",
            "product": "Orchestration"
          },
          {
            "vendor": "Blue Planet",
            "product": "Route Optimization & Analysis"
          },
          {
            "vendor": "Blue Planet",
            "product": "Unified Assurance & Analytics"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 18,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00452,
        "percentile": 0.3703
      },
      "nvd": {
        "published": "2026-07-14T23:17:34.570",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5270",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Ciena's authentication layer interprets crafted HTTP paths and headers inconsistently, allowing a request to bypass authentication and audit logging.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ciena.com/product-security",
          "host": "www.ciena.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 386,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-5348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T16:39:04.047Z",
      "date_published": "2026-07-02T05:35:13.968Z",
      "date_updated": "2026-07-02T14:52:06.995Z",
      "publisher": "Wordfence",
      "title": "Academy LMS <= 3.8.1 - Unauthenticated Insecure Direct Object Reference to Private Topic Disclosure",
      "affected": {
        "vendors": [
          "kodezen"
        ],
        "products": [
          {
            "vendor": "kodezen",
            "product": "Academy LMS – WordPress LMS Plugin for Complete eLearning Solution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17866
      },
      "nvd": {
        "published": "2026-07-02T06:16:14.073",
        "lastModified": "2026-07-02T15:17:11.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5348",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The topics API uses an always-allow permission callback and does not check course visibility or enrollment before returning private curriculum data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b84ae3e0-de4f-41d6-8944-fadaf6fdcf79?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/academy/trunk/includes/api/course.php#L50",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/academy/tags/3.5.3/includes/api/course.php#L50",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/academy/trunk/includes/api/course.php#L77",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/academy/tags/3.5.3/includes/api/course.php#L77",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/academy/trunk/includes/traits/courses.php#L1514",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/academy/tags/3.5.3/includes/traits/courses.php#L1514",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3592849%40academy&new=3592849%40academy&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5356",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T16:48:04.044Z",
      "date_published": "2026-07-08T12:33:15.433Z",
      "date_updated": "2026-07-08T15:02:28.830Z",
      "publisher": "Wordfence",
      "title": "LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass",
      "affected": {
        "vendors": [
          "latepoint"
        ],
        "products": [
          {
            "vendor": "latepoint",
            "product": "LatePoint – Calendar Booking Plugin for Appointments and Events"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11347
      },
      "nvd": {
        "published": "2026-07-08T13:16:56.767",
        "lastModified": "2026-07-08T16:16:34.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5356",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "LatePoint accepts a previously succeeded client-supplied PaymentIntent without binding it to the current booking amount.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1b1338c4-36a8-47b0-b3cf-c5dc690f8c1c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3509569/latepoint",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 420,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-02T22:38:21.515Z",
      "date_published": "2026-07-08T12:33:16.401Z",
      "date_updated": "2026-07-08T14:00:54.082Z",
      "publisher": "Wordfence",
      "title": "User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Subscription Overwrite",
      "affected": {
        "vendors": [
          "wedevs"
        ],
        "products": [
          {
            "vendor": "wedevs",
            "product": "User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08132
      },
      "nvd": {
        "published": "2026-07-08T13:16:56.887",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5459",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "payment_page accepts a caller-controlled user_id without binding the selected payment record to that user.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a02d9a01-1104-4935-8074-af4367c66278?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3514258/wp-user-frontend",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 510,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5487",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-03T14:31:51.826Z",
      "date_published": "2026-07-29T19:09:41.325Z",
      "date_updated": "2026-07-30T13:43:37.580Z",
      "publisher": "zdi",
      "title": "DriveLock Directory Traversal Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "DriveLock"
        ],
        "products": [
          {
            "vendor": "DriveLock",
            "product": "DriveLock"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01535,
        "percentile": 0.72361
      },
      "nvd": {
        "published": "2026-07-29T20:17:05.653",
        "lastModified": "2026-07-30T14:18:46.477",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5487",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DriveLock allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-284/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        },
        {
          "url": "https://www.drivelock.help/sb/Content/SecurityBulletins/26-003-PathValidation.htm",
          "host": "www.drivelock.help",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 580,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-03T14:32:26.162Z",
      "date_published": "2026-07-29T19:09:50.068Z",
      "date_updated": "2026-07-30T13:46:25.972Z",
      "publisher": "zdi",
      "title": "DriveLock Directory Traversal Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "DriveLock"
        ],
        "products": [
          {
            "vendor": "DriveLock",
            "product": "DriveLock"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01266,
        "percentile": 0.66863
      },
      "nvd": {
        "published": "2026-07-29T20:17:05.777",
        "lastModified": "2026-07-30T14:18:46.477",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5489",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The DriveLock web service uses a caller-supplied path in file operations without confining it to an allowed directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-285/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        },
        {
          "url": "https://www.drivelock.help/sb/Content/SecurityBulletins/26-001-DESForwarding.htm",
          "host": "www.drivelock.help",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 580,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-03T14:32:38.204Z",
      "date_published": "2026-07-29T19:09:57.872Z",
      "date_updated": "2026-07-31T03:56:15.195Z",
      "publisher": "zdi",
      "title": "DriveLock SQL Injection Privilege Escalation Vulnerability",
      "affected": {
        "vendors": [
          "DriveLock"
        ],
        "products": [
          {
            "vendor": "DriveLock",
            "product": "DriveLock"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00481,
        "percentile": 0.38945
      },
      "nvd": {
        "published": "2026-07-29T20:17:05.893",
        "lastModified": "2026-07-31T04:17:24.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5490",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-286/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        },
        {
          "url": "https://drivelock.help/sb/Content/SecurityBulletins/26-002-SQLInjection.htm",
          "host": "drivelock.help",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5491",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-03T14:32:58.570Z",
      "date_published": "2026-07-29T19:10:05.631Z",
      "date_updated": "2026-07-30T13:53:05.508Z",
      "publisher": "zdi",
      "title": "DriveLock Directory Traversal Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "DriveLock"
        ],
        "products": [
          {
            "vendor": "DriveLock",
            "product": "DriveLock"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01539,
        "percentile": 0.72433
      },
      "nvd": {
        "published": "2026-07-29T20:17:06.020",
        "lastModified": "2026-07-30T14:18:46.477",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5491",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DriveLock accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-287/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        },
        {
          "url": "https://www.drivelock.help/sb/Content/SecurityBulletins/26-003-PathValidation.htm",
          "host": "www.drivelock.help",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 580,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-03T14:33:24.878Z",
      "date_published": "2026-07-29T19:10:14.174Z",
      "date_updated": "2026-07-29T19:47:06.945Z",
      "publisher": "zdi",
      "title": "DriveLock Directory Traversal Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "DriveLock"
        ],
        "products": [
          {
            "vendor": "DriveLock",
            "product": "DriveLock"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.016,
        "percentile": 0.73387
      },
      "nvd": {
        "published": "2026-07-29T20:17:06.140",
        "lastModified": "2026-07-30T14:18:46.477",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5492",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The port 4568 web service uses an authenticated caller's path in file operations without confining it to the intended directory.",
        "basis": [
          "CNA record",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-288/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        },
        {
          "url": "https://www.drivelock.help/sb/Content/SecurityBulletins/26-003-PathValidation.htm",
          "host": "www.drivelock.help",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5523",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-04T00:04:43.797Z",
      "date_published": "2026-07-09T04:32:54.346Z",
      "date_updated": "2026-07-09T12:52:15.148Z",
      "publisher": "Wordfence",
      "title": "Divi Form Builder <= 5.1.8 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form",
      "affected": {
        "vendors": [
          "Divi Engine"
        ],
        "products": [
          {
            "vendor": "Divi Engine",
            "product": "Divi Form Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22346
      },
      "nvd": {
        "published": "2026-07-09T06:16:21.300",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5523",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Profile-update functions accept a caller-supplied user ID and check only that some user is logged in, without authorizing changes to the target profile.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cb158acc-69d7-4a7d-b356-7de1f6b37019?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://diviengine.com/divi-form-builder-changelog/",
          "host": "diviengine.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 674,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5524",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-04T01:50:49.629Z",
      "date_published": "2026-07-02T12:34:40.602Z",
      "date_updated": "2026-07-02T15:00:12.782Z",
      "publisher": "Wordfence",
      "title": "Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter",
      "affected": {
        "vendors": [
          "Divi Engine"
        ],
        "products": [
          {
            "vendor": "Divi Engine",
            "product": "Divi Form Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00723,
        "percentile": 0.50461
      },
      "nvd": {
        "published": "2026-07-02T13:17:00.587",
        "lastModified": "2026-07-02T15:17:11.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5524",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "do_image_upload lets the caller define the file-extension validation regex and stores PHP-executable extensions in a public upload directory.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9692deb2-2526-4983-8a13-93a382e230c8?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://diviengine.com/divi-form-builder-changelog/",
          "host": "diviengine.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1054,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5582",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-04T17:46:28.655Z",
      "date_published": "2026-07-30T12:05:02.762Z",
      "date_updated": "2026-07-31T22:49:40.115Z",
      "publisher": "Wordfence",
      "title": "FuseWP <= 1.1.24.2 - Cross-Site Request Forgery to Sync Rule Status Toggle",
      "affected": {
        "vendors": [
          "fusewp"
        ],
        "products": [
          {
            "vendor": "fusewp",
            "product": "FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03155
      },
      "nvd": {
        "published": "2026-07-30T12:19:03.080",
        "lastModified": "2026-07-31T23:17:25.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5582",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A state-changing request lacks a nonce or equivalent cross-site request proof.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1ff5889e-b9fd-494f-b25d-78e85e94d34c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://wordpress.org/plugins/fusewp/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fusewp/trunk/src/core/src/AjaxHandler.php#L149",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fusewp/tags/1.1.24.2/src/core/src/AjaxHandler.php#L149",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3505110@fusewp/trunk/src/core/src/AjaxHandler.php&old=3172907@fusewp/trunk/src/core/src/AjaxHandler.php&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 427,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5626",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-05T18:05:22.216Z",
      "date_published": "2026-07-29T02:31:39.742Z",
      "date_updated": "2026-07-29T14:24:16.632Z",
      "publisher": "Wordfence",
      "title": "Survey Form Block <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission Data Export",
      "affected": {
        "vendors": [
          "bplugins"
        ],
        "products": [
          {
            "vendor": "bplugins",
            "product": "Survey Form Block – collect answers and insights from your audience"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09966
      },
      "nvd": {
        "published": "2026-07-29T04:17:13.503",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5626",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The application permits a protected action without binding the caller's privilege to the requested operation.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e98d4f04-74cd-486f-bb2f-fad76895f386?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/survey-form-block/trunk/inc/SVBAjax.php#L52",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/survey-form-block/tags/1.0.1/inc/SVBAjax.php#L52",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://wordpress.org/plugins/survey-form-block/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3502334%40survey-form-block%2Ftrunk%2Finc%2FSVBAjax.php&old=3223297%40survey-form-block%2Ftrunk%2Finc%2FSVBAjax.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5674",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T09:07:33.494Z",
      "date_published": "2026-07-16T13:26:44.534Z",
      "date_updated": "2026-08-03T07:09:51.075Z",
      "publisher": "redhat",
      "title": "Pipewire: pipewire: sandbox escape and arbitrary code execution via malicious library loading",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.0273
      },
      "nvd": {
        "published": "2026-07-16T14:16:56.070",
        "lastModified": "2026-08-03T08:17:20.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5674",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Red Hat Enterprise Linux 10 runtime searches an attacker-influenced library path and can load code from outside the trusted installation.",
        "basis": [
          "CNA",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47082",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47083",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-5674",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455341",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-5730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-07T12:08:28.185Z",
      "date_published": "2026-07-07T06:45:41.937Z",
      "date_updated": "2026-07-07T13:25:37.426Z",
      "publisher": "TR-CERT",
      "title": "IDOR in Idvlabs' Ontime",
      "affected": {
        "vendors": [
          "Idvlabs Software and Consulting Services Inc."
        ],
        "products": [
          {
            "vendor": "Idvlabs Software and Consulting Services Inc.",
            "product": "Ontime"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15966
      },
      "nvd": {
        "published": "2026-07-07T08:16:25.540",
        "lastModified": "2026-07-07T14:16:34.343",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5730",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A request selects another user's object without an ownership check.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0503",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5743",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-07T13:48:55.983Z",
      "date_published": "2026-07-11T02:31:16.457Z",
      "date_updated": "2026-07-13T14:40:00.739Z",
      "publisher": "Wordfence",
      "title": "Mixed Media Gallery Blocks <= 3.3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute",
      "affected": {
        "vendors": [
          "gallerycreator"
        ],
        "products": [
          {
            "vendor": "gallerycreator",
            "product": "SimpLy Gallery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16609
      },
      "nvd": {
        "published": "2026-07-11T04:17:23.843",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5743",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A regex sanitizer removes only quoted event-handler attributes, so an unquoted handler in sliderMaxHeight survives and is rendered as executable HTML.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/29b1984d-e6da-49d5-8b40-cdf2f1bcc1bb?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-gallery-block/tags/3.3.2.2/blocks/init.php#L95",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-gallery-block/trunk/blocks/init.php#L95",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-gallery-block/trunk/blocks/init.php#L122",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-gallery-block/tags/3.3.2.2/blocks/init.php#L122",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-gallery-block/trunk/blocks/init.php#L142",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-gallery-block/tags/3.3.2.2/blocks/init.php#L142",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-gallery-block/trunk/blocks/init.php#L151",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-gallery-block/tags/3.3.2.2/blocks/init.php#L151",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3581386%40simply-gallery-block&new=3581386%40simply-gallery-block",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 846,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T13:03:45.307Z",
      "date_published": "2026-07-09T08:22:59.096Z",
      "date_updated": "2026-07-09T12:39:41.345Z",
      "publisher": "TR-CERT",
      "title": "XSS in Inrove Software's BiEticaret",
      "affected": {
        "vendors": [
          "Inrove Software and Internet Services"
        ],
        "products": [
          {
            "vendor": "Inrove Software and Internet Services",
            "product": "BiEticaret"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04571
      },
      "nvd": {
        "published": "2026-07-09T10:16:27.320",
        "lastModified": "2026-07-09T16:21:30.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5793",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BiEticaret reflects attacker-controlled input into generated HTML without the required browser-context neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0519",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T14:17:21.176Z",
      "date_published": "2026-07-07T06:49:02.017Z",
      "date_updated": "2026-07-07T13:26:51.694Z",
      "publisher": "TR-CERT",
      "title": "IDOR in Idvlabs' Ontime",
      "affected": {
        "vendors": [
          "Idvlabs Software and Consulting Services Inc."
        ],
        "products": [
          {
            "vendor": "Idvlabs Software and Consulting Services Inc.",
            "product": "Ontime"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16593
      },
      "nvd": {
        "published": "2026-07-07T08:16:25.677",
        "lastModified": "2026-07-07T14:16:34.440",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5799",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ontime accepts a caller-controlled object key without verifying that the authenticated user is authorized for the referenced object.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0503",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T14:18:28.380Z",
      "date_published": "2026-07-10T18:07:44.714Z",
      "date_updated": "2026-07-10T19:06:18.464Z",
      "publisher": "TR-CERT",
      "title": "SQLi in Semtek Informatics' SEM-PMP",
      "affected": {
        "vendors": [
          "Semtek Informatics Software Consulting Trade Ltd. Co."
        ],
        "products": [
          {
            "vendor": "Semtek Informatics Software Consulting Trade Ltd. Co.",
            "product": "SEM-PMP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00404,
        "percentile": 0.33188
      },
      "nvd": {
        "published": "2026-07-10T19:17:27.323",
        "lastModified": "2026-07-10T20:16:48.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5801",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0527",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T16:28:00.923Z",
      "date_published": "2026-07-02T05:35:07.753Z",
      "date_updated": "2026-07-02T12:37:03.815Z",
      "publisher": "Wordfence",
      "title": "Image Optimizer <= 1.7.4 - Authenticated (Author+) Arbitrary File Deletion via Post Meta Field Injection",
      "affected": {
        "vendors": [
          "elemntor"
        ],
        "products": [
          {
            "vendor": "elemntor",
            "product": "Image Optimizer – Optimize Images and Convert to WebP or AVIF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.26995
      },
      "nvd": {
        "published": "2026-07-02T06:16:14.220",
        "lastModified": "2026-07-02T13:58:56.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5821",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Image Optimizer – Optimize Images and Convert to WebP or AVIF uses an attacker-controlled filename or path directly for a filesystem operation.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a1a00374-e9d6-46f9-a28c-cb7768505787?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/image-optimization/trunk/classes/image/image-backup.php#L117",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/image-optimization/tags/1.7.3/classes/image/image-backup.php#L117",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/image-optimization/trunk/modules/backups/components/handle-backups-removing.php#L19",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/image-optimization/tags/1.7.3/modules/backups/components/handle-backups-removing.php#L19",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/image-optimization/trunk/classes/image/image-meta.php#L97",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/image-optimization/tags/1.7.3/classes/image/image-meta.php#L97",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3557772%40image-optimization&new=3557772%40image-optimization&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1131,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-5846",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T18:55:38.436Z",
      "date_published": "2026-07-30T21:12:42.825Z",
      "date_updated": "2026-07-31T20:12:49.282Z",
      "publisher": "icscert",
      "title": "Hard-coded Cryptographic Key in Watchfire Controllers",
      "affected": {
        "vendors": [
          "Watchfire"
        ],
        "products": [
          {
            "vendor": "Watchfire",
            "product": "BC550"
          },
          {
            "vendor": "Watchfire",
            "product": "BC750"
          },
          {
            "vendor": "Watchfire",
            "product": "BC760"
          },
          {
            "vendor": "Watchfire",
            "product": "BC760DC"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 12,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-321",
          "name": "Use of Hard-coded Cryptographic Key",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 1.8999999999999995,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05929
      },
      "nvd": {
        "published": "2026-07-30T22:16:55.107",
        "lastModified": "2026-07-31T16:17:08.500",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5846",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The firmware ships the same plaintext RSA private keys and certificates used to authenticate and encrypt every controller management interface.",
        "basis": [
          "CNA",
          "CWE-321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-09.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-5922",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T21:33:29.346Z",
      "date_published": "2026-07-08T21:39:06.676Z",
      "date_updated": "2026-07-09T13:53:34.577Z",
      "publisher": "hp",
      "title": "Poly Voice – Potential Unauthorized Modification of WebUI using XSS Attack",
      "affected": {
        "vendors": [
          "HP Inc."
        ],
        "products": [
          {
            "vendor": "HP Inc.",
            "product": "Poly CCX"
          },
          {
            "vendor": "HP Inc.",
            "product": "Poly Edge E"
          },
          {
            "vendor": "HP Inc.",
            "product": "Poly Trio C60"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:hp-security-alert@hp.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.1439
      },
      "nvd": {
        "published": "2026-07-08T22:17:16.193",
        "lastModified": "2026-07-09T16:39:17.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5922",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Poly CCX places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hp.com/us-en/document/ish_15255534-15255565-16/hpsbpy04108",
          "host": "support.hp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-5923",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T21:33:32.687Z",
      "date_published": "2026-07-08T21:29:42.801Z",
      "date_updated": "2026-07-09T13:53:11.528Z",
      "publisher": "hp",
      "title": "Poly Voice – Potential Unauthorized Modification of WebUI using CSRF Attack",
      "affected": {
        "vendors": [
          "HP Inc."
        ],
        "products": [
          {
            "vendor": "HP Inc.",
            "product": "Poly CCX"
          },
          {
            "vendor": "HP Inc.",
            "product": "Poly Edge E"
          },
          {
            "vendor": "HP Inc.",
            "product": "Poly Trio C60"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:hp-security-alert@hp.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03758
      },
      "nvd": {
        "published": "2026-07-08T22:17:16.480",
        "lastModified": "2026-07-09T16:39:17.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5923",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The advisory states that a stolen session cookie can authorize changes to the phone's web page, while it does not disclose the request validation or cookie binding that fails.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hp.com/us-en/document/ish_15255241-15255270-16/hpsbpy04109",
          "host": "support.hp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-5955",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-09T07:42:27.443Z",
      "date_published": "2026-07-09T08:26:06.075Z",
      "date_updated": "2026-07-09T12:35:54.233Z",
      "publisher": "TR-CERT",
      "title": "SQLi in Inrove Software's BiEticaret",
      "affected": {
        "vendors": [
          "Inrove Software and Internet Services"
        ],
        "products": [
          {
            "vendor": "Inrove Software and Internet Services",
            "product": "BiEticaret"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19678
      },
      "nvd": {
        "published": "2026-07-09T10:16:27.427",
        "lastModified": "2026-07-09T16:21:30.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-5955",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BiEticaret accepts attacker input into an SQL statement without separating data from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0519",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6070",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-10T13:34:33.261Z",
      "date_published": "2026-07-01T04:32:27.988Z",
      "date_updated": "2026-07-01T10:42:10.837Z",
      "publisher": "Wordfence",
      "title": "WP-BusinessDirectory <= 4.0.1 - Unauthenticated Arbitrary File Deletion via Path Traversal via '_filename' Parameter",
      "affected": {
        "vendors": [
          "cmsjunkie"
        ],
        "products": [
          {
            "vendor": "cmsjunkie",
            "product": "WP-BusinessDirectory – Business directory plugin for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00409,
        "percentile": 0.33617
      },
      "nvd": {
        "published": "2026-07-01T05:16:23.277",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6070",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload deletion endpoint passes a traversal-bearing _filename to unlink without containing it under the plugin directory.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d7d68f43-2a57-4352-8aae-0657b386ac7c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-businessdirectory/trunk/site/controllers/upload.php#L450",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-businessdirectory/tags/4.0.0/site/controllers/upload.php#L450",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-businessdirectory/trunk/site/controllers/upload.php#L127",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-businessdirectory/tags/4.0.0/site/controllers/upload.php#L127",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1043,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6089",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-10T15:43:59.831Z",
      "date_published": "2026-07-29T09:31:15.249Z",
      "date_updated": "2026-07-29T14:29:39.227Z",
      "publisher": "Wordfence",
      "title": "WP CTA <= 2.1.2 - Authenticated (Administrator+) Server-Side Request Forgery",
      "affected": {
        "vendors": [
          "blendmedia"
        ],
        "products": [
          {
            "vendor": "blendmedia",
            "product": "WP CTA – Call Now Button, Sticky Button & Call to Action Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19976
      },
      "nvd": {
        "published": "2026-07-29T11:16:50.423",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6089",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WP CTA – Call Now Button, Sticky Button & Call to Action Builder request path lets a caller choose a server-side destination outside the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/df5fc86f-e4ba-424b-bece-79abd763cf74?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-sticky-sidebar/trunk/inc/import-export.php#L97",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3491924%40easy-sticky-sidebar%2Ftrunk&old=3459250%40easy-sticky-sidebar%2Ftrunk&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 713,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6101",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-10T23:33:50.597Z",
      "date_published": "2026-07-07T13:32:10.414Z",
      "date_updated": "2026-07-07T14:14:00.335Z",
      "publisher": "Wordfence",
      "title": "AMP for WP <= 1.1.12 - Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font Upload",
      "affected": {
        "vendors": [
          "mohammed_kaludi"
        ],
        "products": [
          {
            "vendor": "mohammed_kaludi",
            "product": "AMP for WP – Accelerated Mobile Pages"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00628,
        "percentile": 0.46633
      },
      "nvd": {
        "published": "2026-07-07T14:16:34.543",
        "lastModified": "2026-07-07T15:16:49.807",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6101",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unsafe ZIP extraction lets an authorized author place nested files in a web-accessible location outside the intended extraction set.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b594d0e9-d805-48b9-bfd4-4cc77dd3a70e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/accelerated-moblie-pages.php#L1616",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/tags/1.1.12/accelerated-moblie-pages.php#L1616",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/includes/options/redux-core/framework.php#L2832",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/tags/1.1.12/includes/options/redux-core/framework.php#L2832",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/includes/options/admin-config.php#L1700",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/tags/1.1.12/includes/options/admin-config.php#L1700",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/includes/options/redux-core/core/panel.php#L175",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/tags/1.1.12/includes/options/redux-core/core/panel.php#L175",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3512870/",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 614,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6102",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-11T00:19:18.083Z",
      "date_published": "2026-07-29T19:09:04.626Z",
      "date_updated": "2026-07-31T03:56:14.448Z",
      "publisher": "zdi",
      "title": "MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability",
      "affected": {
        "vendors": [
          "MSI"
        ],
        "products": [
          {
            "vendor": "MSI",
            "product": "MSI Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00086,
        "percentile": 0.00422
      },
      "nvd": {
        "published": "2026-07-29T20:17:12.980",
        "lastModified": "2026-07-31T04:17:24.730",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6102",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MSI NTIOLib_X64 driver accepts privileged commands from a low-privileged local origin without validating that command source.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-430/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 602,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6212",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-13T12:17:13.977Z",
      "date_published": "2026-07-10T18:35:43.613Z",
      "date_updated": "2026-07-10T19:13:49.677Z",
      "publisher": "TR-CERT",
      "title": "IDOR in Teracity's TeraMIS",
      "affected": {
        "vendors": [
          "Teracity Software Technologies Inc."
        ],
        "products": [
          {
            "vendor": "Teracity Software Technologies Inc.",
            "product": "TeraMIS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16576
      },
      "nvd": {
        "published": "2026-07-10T19:17:27.840",
        "lastModified": "2026-07-10T20:16:49.257",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6212",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts a caller-supplied object identifier without verifying that the selected object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0528",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6230",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-13T14:27:51.115Z",
      "date_published": "2026-07-08T11:30:32.366Z",
      "date_updated": "2026-07-08T14:00:11.719Z",
      "publisher": "Wordfence",
      "title": "Tainacan <= 1.0.3 - Unauthenticated SQL Injection via 'geoquery' REST API Parameter",
      "affected": {
        "vendors": [
          "tainacan"
        ],
        "products": [
          {
            "vendor": "tainacan",
            "product": "Tainacan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19423
      },
      "nvd": {
        "published": "2026-07-08T12:17:20.660",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6230",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/241d9cd3-9331-49b2-8083-dc646070488e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/tainacan/tainacan/commit/579d28d7752b27ed3407f5197abb6349b3efc3c9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 459,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-13T19:04:06.546Z",
      "date_published": "2026-07-28T05:39:41.989Z",
      "date_updated": "2026-07-28T13:38:16.409Z",
      "publisher": "Wordfence",
      "title": "Chaty Pro <= 3.5.5 - Authenticated (Subscriber+) SQL Injection via 'widget_id' Parameter",
      "affected": {
        "vendors": [
          "Chaty"
        ],
        "products": [
          {
            "vendor": "Chaty",
            "product": "Chaty Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16262
      },
      "nvd": {
        "published": "2026-07-28T07:16:42.920",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6251",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "fetch_custom_field concatenates widget_id into SQL before checking the nonce and without parameterization or integer casting.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/582fa92d-8e52-49a9-94ce-f1b49229f591?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chaty-pro/trunk/admin/class-admin-base.php#L3626",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chaty-pro/tags/3.5.0/admin/class-admin-base.php#L3626",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chaty-pro/trunk/admin/class-admin-base.php#L3623",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chaty-pro/tags/3.5.0/admin/class-admin-base.php#L3623",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 820,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6267",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-14T08:04:23.830Z",
      "date_published": "2026-07-29T19:01:16.040Z",
      "date_updated": "2026-07-31T16:10:45.590Z",
      "publisher": "GitLab",
      "title": "Insertion of Sensitive Information Into Sent Data in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 3.2,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25841
      },
      "nvd": {
        "published": "2026-07-29T20:17:13.123",
        "lastModified": "2026-08-03T14:02:29.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6267",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says GitLab discloses protected data, but does not identify the output, cache, or memory path that exposes it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/596606",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3658324",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-6280",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-14T14:24:35.901Z",
      "date_published": "2026-07-08T08:45:18.361Z",
      "date_updated": "2026-07-08T12:09:27.160Z",
      "publisher": "TR-CERT",
      "title": "Improper Access Control in Nomysoft Informatics' Nomysem",
      "affected": {
        "vendors": [
          "NOMYSOFT Informatics Education and Consulting Inc."
        ],
        "products": [
          {
            "vendor": "NOMYSOFT Informatics Education and Consulting Inc.",
            "product": "Nomysem"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-213",
          "name": "Exposure of Sensitive Information Due to Incompatible Policies",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13532
      },
      "nvd": {
        "published": "2026-07-08T09:16:34.403",
        "lastModified": "2026-07-08T14:57:28.893",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6280",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Nomysem applies incompatible access policies that leave sensitive functionality reachable outside the intended ACL.",
        "basis": [
          "CNA",
          "CWE-213"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0516",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 341,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6283",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-14T15:03:55.739Z",
      "date_published": "2026-07-01T14:19:20.177Z",
      "date_updated": "2026-07-01T14:54:14.126Z",
      "publisher": "TR-CERT",
      "title": "Stored XSS in DivvyDrive Information Technologies' DivvyDrive",
      "affected": {
        "vendors": [
          "DivvyDrive Information Technologies Inc."
        ],
        "products": [
          {
            "vendor": "DivvyDrive Information Technologies Inc.",
            "product": "DivvyDrive"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03234
      },
      "nvd": {
        "published": "2026-07-01T15:17:12.207",
        "lastModified": "2026-07-01T16:16:53.063",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6283",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0475",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-15T09:04:52.019Z",
      "date_published": "2026-07-29T19:01:06.041Z",
      "date_updated": "2026-07-29T19:40:48.747Z",
      "publisher": "GitLab",
      "title": "Incorrect Authorization in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.16997
      },
      "nvd": {
        "published": "2026-07-29T20:17:13.270",
        "lastModified": "2026-08-03T13:58:30.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6336",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GitLab returns project import source information without the authorization check required for the requesting user.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/596762",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3661988",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-6352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-15T13:03:48.044Z",
      "date_published": "2026-07-08T20:46:43.862Z",
      "date_updated": "2026-07-09T14:13:17.427Z",
      "publisher": "GitLab",
      "title": "Incorrect Authorization in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18148
      },
      "nvd": {
        "published": "2026-07-08T21:16:54.960",
        "lastModified": "2026-07-09T20:36:00.707",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6352",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GitLab permits an auditor-role user to execute a GraphQL mutation that should be outside the auditor's read-only authority.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/596789",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3631344",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-6371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-15T16:02:57.878Z",
      "date_published": "2026-07-08T11:51:47.325Z",
      "date_updated": "2026-07-20T11:41:40.392Z",
      "publisher": "TR-CERT",
      "title": "Stored XSS in Limatek's LimRAD NAC",
      "affected": {
        "vendors": [
          "Limatek System Inc."
        ],
        "products": [
          {
            "vendor": "Limatek System Inc.",
            "product": "LimRAD NAC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04544
      },
      "nvd": {
        "published": "2026-07-08T12:17:20.780",
        "lastModified": "2026-07-20T12:19:48.690",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6371",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches LimRAD NAC page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0517",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-15T17:44:55.095Z",
      "date_published": "2026-07-06T06:00:02.217Z",
      "date_updated": "2026-07-06T11:59:43.823Z",
      "publisher": "WPScan",
      "title": "Multiple elFinder Plugins - Authenticated OS Command Injection",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "FileOrganizer"
          },
          {
            "vendor": "Unknown",
            "product": "Advanced File Manager"
          },
          {
            "vendor": "Unknown",
            "product": "File Manager Pro"
          },
          {
            "vendor": "Unknown",
            "product": "File Manager"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00902,
        "percentile": 0.5627
      },
      "nvd": {
        "published": "2026-07-06T08:16:36.447",
        "lastModified": "2026-07-06T18:37:01.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6382",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An image parameter reaches a shell command without neutralizing command-substitution syntax.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/a27f70b7-a4cc-42fa-88c1-19adfe1593a8/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 484,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-6390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-15T19:42:07.154Z",
      "date_published": "2026-07-23T03:55:42.246Z",
      "date_updated": "2026-07-23T13:43:29.133Z",
      "publisher": "redhat",
      "title": "Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling.",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-134",
          "name": "Use of Externally-Controlled Format String",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01337
      },
      "nvd": {
        "published": "2026-07-23T05:16:38.360",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6390",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Red Hat Enterprise Linux 10 error path reinterprets an attacker-controlled filename as a printf format string.",
        "basis": [
          "CNA",
          "CWE-134"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-6390",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458767",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-6423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T08:03:11.185Z",
      "date_published": "2026-07-16T07:56:20.026Z",
      "date_updated": "2026-07-16T12:34:49.159Z",
      "publisher": "ESET",
      "title": "Local privilege escalation via unauthenticated ALPC in ESET Inspect Connector",
      "affected": {
        "vendors": [
          "ESET, spol. s.r.o."
        ],
        "products": [
          {
            "vendor": "ESET, spol. s.r.o.",
            "product": "ESET Inspect Connector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@eset.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04196
      },
      "nvd": {
        "published": "2026-07-16T09:16:19.273",
        "lastModified": "2026-07-16T13:49:40.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6423",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ESET Inspect Connector accepts messages on a privileged ALPC channel without authenticating the local peer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.eset.com/en/ca8970-eset-customer-advisory-local-privilege-escalation-via-unauthenticated-alpc-in-eset-inspect-connector-for-windows-fixed",
          "host": "support.eset.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 145,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T08:13:25.859Z",
      "date_published": "2026-07-16T08:28:43.649Z",
      "date_updated": "2026-07-16T12:17:48.734Z",
      "publisher": "ESET",
      "title": "Use-after-free vulnerability in ESET security products for Linux",
      "affected": {
        "vendors": [
          "ESET, spol. s.r.o."
        ],
        "products": [
          {
            "vendor": "ESET, spol. s.r.o.",
            "product": "ESET Endpoint Antivirus for Linux"
          },
          {
            "vendor": "ESET, spol. s.r.o.",
            "product": "ESET Server Security for Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@eset.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01567
      },
      "nvd": {
        "published": "2026-07-16T09:16:19.403",
        "lastModified": "2026-07-16T13:49:40.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6424",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ESET Linux component dereferences kernel memory after the associated object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.eset.com/en/ca8972-eset-customer-advisory-use-after-free-vulnerability-in-eset-security-products-for-linux-fixed",
          "host": "support.eset.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-6440",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T18:12:33.622Z",
      "date_published": "2026-07-10T07:48:44.122Z",
      "date_updated": "2026-07-10T17:01:30.572Z",
      "publisher": "Wordfence",
      "title": "GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'",
      "affected": {
        "vendors": [
          "sovlix"
        ],
        "products": [
          {
            "vendor": "sovlix",
            "product": "GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05425
      },
      "nvd": {
        "published": "2026-07-10T09:16:53.820",
        "lastModified": "2026-07-10T17:17:03.997",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6440",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference accepts a state-changing browser request without validating an unforgeable anti-CSRF token or equivalent origin proof.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dc9e818d-811e-4732-9c74-8eb6753a1706?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/goodmeet/trunk/includes/Goodmeet_Ajax.php#L140",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/goodmeet/tags/1.1.6/includes/Goodmeet_Ajax.php#L140",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/goodmeet/trunk/includes/Goodmeet_Ajax.php#L38",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/goodmeet/tags/1.1.6/includes/Goodmeet_Ajax.php#L38",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/goodmeet/trunk/includes/Googlemeet/Goodmeet_Meet.php#L544",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/goodmeet/tags/1.1.6/includes/Googlemeet/Goodmeet_Meet.php#L544",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3525854%40goodmeet&new=3525854%40goodmeet",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 801,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T20:08:18.705Z",
      "date_published": "2026-07-24T02:31:58.797Z",
      "date_updated": "2026-07-24T12:22:43.270Z",
      "publisher": "Wordfence",
      "title": "Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute",
      "affected": {
        "vendors": [
          "firelightwp"
        ],
        "products": [
          {
            "vendor": "firelightwp",
            "product": "Firelight Lightbox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10764
      },
      "nvd": {
        "published": "2026-07-24T04:16:52.023",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6454",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8396c124-9c72-4801-8964-1cd5fbd52d20?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-fancybox/trunk/inc/fancybox-2.php#L322",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-fancybox/trunk/fancybox/2.2.0/jquery.fancybox.js#L280",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-fancybox/trunk/fancybox/2.2.0/jquery.fancybox.js#L1235",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-fancybox/tags/2.3.18/inc/fancybox-2.php#L322",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-fancybox/tags/2.3.18/fancybox/2.2.0/jquery.fancybox.js#L280",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-fancybox/tags/2.3.18/fancybox/2.2.0/jquery.fancybox.js#L1235",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3610643%40easy-fancybox&new=3610643%40easy-fancybox",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 720,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T23:08:24.493Z",
      "date_published": "2026-07-08T12:33:16.005Z",
      "date_updated": "2026-07-08T14:11:23.298Z",
      "publisher": "Wordfence",
      "title": "Essential Addons for Elementor <= 6.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup",
      "affected": {
        "vendors": [
          "wpdevteam"
        ],
        "products": [
          {
            "vendor": "wpdevteam",
            "product": "Essential Addons for Elementor – Popular Elementor Templates & Widgets"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.0794
      },
      "nvd": {
        "published": "2026-07-08T13:16:57.380",
        "lastModified": "2026-07-08T15:16:32.627",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6459",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Event titles are stored and rendered by the Elementor calendar popup without sufficient input sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5b3214a5-7044-4005-a200-c969d4487be2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://research.cleantalk.org/cve-2026-6459",
          "host": "research.cleantalk.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3519453/essential-addons-for-elementor-lite",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 513,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6509",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-17T11:33:53.261Z",
      "date_published": "2026-07-05T14:48:43.725Z",
      "date_updated": "2026-07-06T13:21:56.311Z",
      "publisher": "TR-CERT",
      "title": "Privilege Escalation in TUBITAK BILGEM's Pardus Update",
      "affected": {
        "vendors": [
          "TUBITAK BILGEM Software Technologies Research Institute"
        ],
        "products": [
          {
            "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
            "product": "Pardus Update"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00101,
        "percentile": 0.01037
      },
      "nvd": {
        "published": "2026-07-05T15:16:57.687",
        "lastModified": "2026-07-06T18:16:45.163",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6509",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Pardus Update exposes a privilege-changing operation without the authorization check required for the caller, while the exact operation is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0501",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6511",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-17T13:03:29.141Z",
      "date_published": "2026-07-16T16:48:30.481Z",
      "date_updated": "2026-07-16T17:59:36.981Z",
      "publisher": "lenovo",
      "title": "During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the sam...",
      "affected": {
        "vendors": [
          "Lenovo"
        ],
        "products": [
          {
            "vendor": "Lenovo",
            "product": "Smart Connect"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00094,
        "percentile": 0.00715
      },
      "nvd": {
        "published": "2026-07-16T17:16:58.970",
        "lastModified": "2026-07-16T19:16:51.217",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6511",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A local user can select and access files belonging to another user because the file operation is not bound to the requesting identity.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.lenovo.com/us/en/product_security/LEN-218281",
          "host": "support.lenovo.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.lenovo.com/us/en/software/smart-connect",
          "host": "www.lenovo.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-17T13:48:22.236Z",
      "date_published": "2026-07-23T17:22:26.627Z",
      "date_updated": "2026-07-24T03:56:26.762Z",
      "publisher": "Zohocorp",
      "title": "Remote Code Execution",
      "affected": {
        "vendors": [
          "Zohocorp"
        ],
        "products": [
          {
            "vendor": "Zohocorp",
            "product": "ManageEngine ADAudit Plus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:0fc0942c-577d-436f-ae8e-945763c79b02",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.04729,
        "percentile": 0.90958
      },
      "nvd": {
        "published": "2026-07-23T18:17:02.570",
        "lastModified": "2026-07-24T05:16:50.033",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6516",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "ManageEngine attributes the unauthenticated RCE to a combined Agent API authentication bypass and path traversal while the CVE record maps command injection, so the primary defect is not publicly separable.",
        "basis": [
          "CNA",
          "CWE-78",
          "ManageEngine advisory"
        ],
        "deepDive": true,
        "notes": "Read https://www.manageengine.com/products/active-directory-audit/cve-2026-6516.html; the vendor says Agent API authentication bypass and path traversal must be combined, while the embedded record assigns CWE-78, so no single primary defect or patch path is public."
      },
      "references": [
        {
          "url": "https://www.manageengine.com/products/active-directory-audit/cve-2026-6516.html",
          "host": "www.manageengine.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6540",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-17T17:41:32.750Z",
      "date_published": "2026-07-30T14:45:04.068Z",
      "date_updated": "2026-07-30T16:12:07.691Z",
      "publisher": "Tigera",
      "title": "L7 policy bypass via unnormalized HTTP path matching",
      "affected": {
        "vendors": [
          "Tigera"
        ],
        "products": [
          {
            "vendor": "Tigera",
            "product": "Calico"
          },
          {
            "vendor": "Tigera",
            "product": "Calico Enterprise"
          },
          {
            "vendor": "Tigera",
            "product": "Calico Cloud"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:psirt@tigera.io",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00368,
        "percentile": 0.29518
      },
      "nvd": {
        "published": "2026-07-30T15:16:37.533",
        "lastModified": "2026-07-30T17:16:34.467",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6540",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Calico authorizes an unnormalized HTTP path while the downstream service normalizes traversal, encoded slashes, or repeated slashes to a restricted endpoint.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/projectcalico/calico/pull/12531",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/projectcalico/calico/pull/12532",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/projectcalico/calico/pull/12533",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tigera.io/security-bulletins/tta-2026-005/",
          "host": "www.tigera.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-6541",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-17T17:54:44.831Z",
      "date_published": "2026-07-13T10:53:15.958Z",
      "date_updated": "2026-07-13T13:09:10.482Z",
      "publisher": "Mattermost",
      "title": "Unscoped updates to other playbooks' metric configuration",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04906
      },
      "nvd": {
        "published": "2026-07-13T11:16:28.080",
        "lastModified": "2026-07-13T20:39:12.303",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6541",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The request accepts an object or tenant identifier without binding that identifier to the authenticated caller's authorized scope.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 356,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-6656",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T08:08:16.230Z",
      "date_published": "2026-07-20T07:01:45.818Z",
      "date_updated": "2026-07-20T18:38:21.362Z",
      "publisher": "CPANSec",
      "title": "Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks",
      "affected": {
        "vendors": [
          "DRSTEVE"
        ],
        "products": [
          {
            "vendor": "DRSTEVE",
            "product": "Crypt::Password"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24073
      },
      "nvd": {
        "published": "2026-07-20T07:16:42.440",
        "lastModified": "2026-07-20T19:17:30.503",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6656",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crypt::Password compares password hashes with the ordinary eq operator, whose data-dependent timing can reveal matching prefixes.",
        "basis": [
          "CNA",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/DRSTEVE/Crypt-Password-0.28/source/lib/Crypt/Password.pm#L190-193",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://rt.cpan.org/Ticket/Display.html?id=180162",
          "host": "rt.cpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6682",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T15:06:18.243Z",
      "date_published": "2026-07-01T13:36:59.935Z",
      "date_updated": "2026-07-01T15:24:05.860Z",
      "publisher": "runZero",
      "title": "FatFs Integer Overflow in FAT32 Volume Mount",
      "affected": {
        "vendors": [
          "ChaN"
        ],
        "products": [
          {
            "vendor": "ChaN",
            "product": "FatFs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:44488dab-36db-4358-99f9-bc116477f914",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00428,
        "percentile": 0.35201
      },
      "nvd": {
        "published": "2026-07-01T15:17:12.313",
        "lastModified": "2026-07-02T14:37:48.377",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6682",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mount_volume multiplies the FAT size by the FAT count without overflow checking and downstream code trusts the wrapped size metadata.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.runzero.com/blog/fatfs-bugs/",
          "host": "www.runzero.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/runZeroInc/vulns-2026-fatfs-chance",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://elm-chan.org/fsw/ff/",
          "host": "elm-chan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.runzero.com/advisories/fatfs-fat32-int-of-mnt-cve-2026-6682/",
          "host": "www.runzero.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 495,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6683",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T15:06:19.048Z",
      "date_published": "2026-07-01T13:41:11.337Z",
      "date_updated": "2026-07-01T15:24:56.449Z",
      "publisher": "runZero",
      "title": "FatFs Divide-by-Zero in exFAT Sync",
      "affected": {
        "vendors": [
          "ChaN"
        ],
        "products": [
          {
            "vendor": "ChaN",
            "product": "FatFs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-369",
          "name": "Divide By Zero",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:44488dab-36db-4358-99f9-bc116477f914",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00429,
        "percentile": 0.35328
      },
      "nvd": {
        "published": "2026-07-01T15:17:12.443",
        "lastModified": "2026-07-02T14:38:07.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6683",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted exFAT metadata makes n_fatent minus two equal zero and the sync path divides by that value.",
        "basis": [
          "CNA",
          "CWE-369"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.runzero.com/blog/fatfs-bugs/",
          "host": "www.runzero.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/runZeroInc/vulns-2026-fatfs-chance",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://elm-chan.org/fsw/ff/",
          "host": "elm-chan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.runzero.com/advisories/fatfs-exfat-divide-by-zero-cve-2026-6683",
          "host": "www.runzero.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T15:06:20.061Z",
      "date_published": "2026-07-01T13:45:03.639Z",
      "date_updated": "2026-07-01T15:25:53.071Z",
      "publisher": "runZero",
      "title": "FatFs Infinite Loop in GPT Partition Scan",
      "affected": {
        "vendors": [
          "ChaN"
        ],
        "products": [
          {
            "vendor": "ChaN",
            "product": "FatFs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:44488dab-36db-4358-99f9-bc116477f914",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00429,
        "percentile": 0.35328
      },
      "nvd": {
        "published": "2026-07-01T15:17:12.553",
        "lastModified": "2026-07-02T14:38:25.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6684",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FatFs trusts the GPT partition count as an unbounded loop limit during mount-time scanning.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.runzero.com/blog/fatfs-bugs/",
          "host": "www.runzero.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/runZeroInc/vulns-2026-fatfs-chance",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://elm-chan.org/fsw/ff/",
          "host": "elm-chan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.runzero.com/advisories/fatfs-gpt-scan-loop-dos-cve-2026-6684/",
          "host": "www.runzero.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6685",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-04-20T15:06:21.250Z",
      "date_published": "2026-07-01T13:47:25.764Z",
      "date_rejected": "2026-07-16T20:11:12.305Z",
      "date_updated": "2026-07-16T20:11:12.305Z",
      "publisher": "runZero",
      "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority following a notification that the vulnerability determination was made in error.",
      "rejected_reason": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority following a notification that the vulnerability determination was made in error. After review, the CNA confirmed the erroneous finding. Thanks to David Brown for reaching out about this issue."
    },
    {
      "cve_id": "CVE-2026-6686",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T15:06:22.242Z",
      "date_published": "2026-07-01T13:55:09.072Z",
      "date_updated": "2026-07-01T15:05:27.926Z",
      "publisher": "runZero",
      "title": "FatFs Use of Uninitialized Clusters After Seek Past EOF",
      "affected": {
        "vendors": [
          "ChaN"
        ],
        "products": [
          {
            "vendor": "ChaN",
            "product": "FatFs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:44488dab-36db-4358-99f9-bc116477f914",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00378,
        "percentile": 0.30507
      },
      "nvd": {
        "published": "2026-07-01T15:17:12.763",
        "lastModified": "2026-07-02T14:38:35.823",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6686",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "f_lseek allocates clusters beyond end of file without initializing them before their previous contents can be read.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.runzero.com/blog/fatfs-bugs/",
          "host": "www.runzero.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/runZeroInc/vulns-2026-fatfs-chance",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://elm-chan.org/fsw/ff/",
          "host": "elm-chan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.runzero.com/advisories/fatfs-uninit-cluster-exposure-cve-2026-6686/",
          "host": "www.runzero.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T15:06:23.356Z",
      "date_published": "2026-07-01T13:57:54.242Z",
      "date_updated": "2026-07-01T15:06:24.705Z",
      "publisher": "runZero",
      "title": "FatFs Stack Buffer Overflow via Uncapped exFAT Label Length",
      "affected": {
        "vendors": [
          "ChaN"
        ],
        "products": [
          {
            "vendor": "ChaN",
            "product": "FatFs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:44488dab-36db-4358-99f9-bc116477f914",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00458,
        "percentile": 0.37478
      },
      "nvd": {
        "published": "2026-07-01T15:17:12.870",
        "lastModified": "2026-07-02T14:38:40.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6687",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FatFs trusts the exFAT XDIR_NumLabel value without enforcing the specification maximum before copying the label into a stack buffer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.runzero.com/blog/fatfs-bugs/",
          "host": "www.runzero.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/runZeroInc/vulns-2026-fatfs-chance",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://elm-chan.org/fsw/ff/",
          "host": "elm-chan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.runzero.com/advisories/fatfs-exfat-label-len-of-cve-2026-6687/",
          "host": "www.runzero.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 374,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T15:06:24.308Z",
      "date_published": "2026-07-01T14:01:04.915Z",
      "date_updated": "2026-07-01T15:06:59.026Z",
      "publisher": "runZero",
      "title": "FatFs Buffer Overflow via Unbounded LFN Filename Copy",
      "affected": {
        "vendors": [
          "ChaN"
        ],
        "products": [
          {
            "vendor": "ChaN",
            "product": "FatFs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:44488dab-36db-4358-99f9-bc116477f914",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00428,
        "percentile": 0.35205
      },
      "nvd": {
        "published": "2026-07-01T15:17:13.013",
        "lastModified": "2026-07-02T14:38:46.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6688",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Downstream callers copy FatFs long filenames of up to 255 characters into shorter fixed buffers without length checks.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.runzero.com/blog/fatfs-bugs/",
          "host": "www.runzero.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/runZeroInc/vulns-2026-fatfs-chance",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://elm-chan.org/fsw/ff/",
          "host": "elm-chan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.runzero.com/advisories/fatfs-long-fn-of-downstream-cve-2026-6688/",
          "host": "www.runzero.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6740",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T10:38:52.931Z",
      "date_published": "2026-07-08T12:33:17.582Z",
      "date_updated": "2026-07-08T17:09:09.937Z",
      "publisher": "Wordfence",
      "title": "Nexter Blocks <= 4.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'commentIcon' Block Attribute",
      "affected": {
        "vendors": [
          "posimyththemes"
        ],
        "products": [
          {
            "vendor": "posimyththemes",
            "product": "Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04826
      },
      "nvd": {
        "published": "2026-07-08T13:16:57.653",
        "lastModified": "2026-07-08T18:16:35.223",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6740",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Nexter Blocks stores the commentIcon value and later renders it as active browser markup without sufficient sanitization and escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f5184598-b0bd-4026-971c-da36d79497df?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3512686/the-plus-addons-for-block-editor/trunk/classes/blocks/tp-post-meta/index.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6742",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T11:31:23.394Z",
      "date_published": "2026-07-08T11:35:40.140Z",
      "date_updated": "2026-07-08T13:23:29.515Z",
      "publisher": "Wordfence",
      "title": "Advanced iFrame <= 2026.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block 'additional' Attribute",
      "affected": {
        "vendors": [
          "mdempfle"
        ],
        "products": [
          {
            "vendor": "mdempfle",
            "product": "Advanced iFrame"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04825
      },
      "nvd": {
        "published": "2026-07-08T12:17:20.893",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6742",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2b9c4ca8-e5cd-4c4f-8d81-b06367c89fd7?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3558422/advanced-iframe",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6790",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T13:47:52.520Z",
      "date_published": "2026-07-14T08:51:30.527Z",
      "date_updated": "2026-07-14T12:20:35.130Z",
      "publisher": "eclipse",
      "title": "In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present).",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Jetty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09598
      },
      "nvd": {
        "published": "2026-07-14T09:16:41.930",
        "lastModified": "2026-07-14T18:35:54.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6790",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Jetty accepts a request whose authority host and port disagree with the Host header, allowing downstream routing and URL construction to trust different destinations.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/99",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 783,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-6792",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T13:50:29.886Z",
      "date_published": "2026-07-21T12:36:49.487Z",
      "date_updated": "2026-07-28T11:35:07.021Z",
      "publisher": "TR-CERT",
      "title": "Improper Authorization in Universal Sotware's FlexCity",
      "affected": {
        "vendors": [
          "Universal Software Inc."
        ],
        "products": [
          {
            "vendor": "Universal Software Inc.",
            "product": "FlexCity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10142
      },
      "nvd": {
        "published": "2026-07-21T13:17:19.043",
        "lastModified": "2026-07-28T12:16:37.037",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6792",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The FlexCity operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0593",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T13:55:23.785Z",
      "date_published": "2026-07-20T15:25:47.546Z",
      "date_updated": "2026-07-20T18:22:48.613Z",
      "publisher": "TR-CERT",
      "title": "Stored XSS in Bifra Engineering's Q-smart NexT Poll",
      "affected": {
        "vendors": [
          "Bifra Engineering Consulting Ltd."
        ],
        "products": [
          {
            "vendor": "Bifra Engineering Consulting Ltd.",
            "product": "Q-smart NexT Poll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05827
      },
      "nvd": {
        "published": "2026-07-20T16:17:07.270",
        "lastModified": "2026-07-20T19:17:30.660",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6793",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Q-smart NexT Poll stores attacker input and later renders it without sufficient browser-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0583",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T14:48:11.329Z",
      "date_published": "2026-07-11T05:35:46.896Z",
      "date_updated": "2026-07-13T14:39:42.665Z",
      "publisher": "Wordfence",
      "title": "Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' Parameter",
      "affected": {
        "vendors": [
          "postmagthemes"
        ],
        "products": [
          {
            "vendor": "postmagthemes",
            "product": "Context Blog"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15102
      },
      "nvd": {
        "published": "2026-07-11T07:16:46.650",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6801",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The modal endpoint returns the body of a password-protected post to an unauthenticated caller without enforcing the post password.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/30f5eecd-3135-45a1-97d2-05fcbbca9e5f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://themes.trac.wordpress.org/changeset?reponame=&old=329636%40context-blog&new=329636%40context-blog",
          "host": "themes.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T14:52:47.934Z",
      "date_published": "2026-07-10T07:48:42.690Z",
      "date_updated": "2026-07-10T11:05:09.160Z",
      "publisher": "Wordfence",
      "title": "Easy Upload Files During Checkout <= 3.0.1 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' Parameter",
      "affected": {
        "vendors": [
          "fahadmahmood"
        ],
        "products": [
          {
            "vendor": "fahadmahmood",
            "product": "Easy Upload Files During Checkout"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15609
      },
      "nvd": {
        "published": "2026-07-10T09:16:53.973",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6802",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Easy Upload Files During Checkout fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5727bc4e-ee92-4913-bc8f-3d002488b383?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-upload-files-during-checkout/trunk/inc/functions.php#L587",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-upload-files-during-checkout/tags/3.0.1/inc/functions.php#L587",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-upload-files-during-checkout/trunk/inc/functions.php#L561",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-upload-files-during-checkout/tags/3.0.1/inc/functions.php#L561",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-upload-files-during-checkout/trunk/inc/functions.php#L195",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-upload-files-during-checkout/tags/3.0.1/inc/functions.php#L195",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3522887%40easy-upload-files-during-checkout&new=3522887%40easy-upload-files-during-checkout",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6803",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T14:58:51.803Z",
      "date_published": "2026-07-11T03:44:21.402Z",
      "date_updated": "2026-07-15T13:51:56.395Z",
      "publisher": "Wordfence",
      "title": "AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear'",
      "affected": {
        "vendors": [
          "wupsales"
        ],
        "products": [
          {
            "vendor": "wupsales",
            "product": "AI Copilot – Content Generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00325,
        "percentile": 0.25
      },
      "nvd": {
        "published": "2026-07-11T05:16:34.430",
        "lastModified": "2026-07-15T14:18:35.247",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6803",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The removeGroup and clear AJAX actions have no capability or nonce requirement and are also registered for unauthenticated callers.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/080740e3-ca04-48b4-8b34-64f5e42b1185?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/trunk/classes/controller.php#L133",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/controller.php#L133",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/trunk/classes/controller.php#L142",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/controller.php#L142",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/trunk/classes/frame.php#L283",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/frame.php#L283",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/trunk/classes/controller.php#L112",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/controller.php#L112",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/trunk/classes/model.php#L173",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/model.php#L173",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3582369%40ai-copilot-content-generator&new=3582369%40ai-copilot-content-generator",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 672,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T14:59:43.137Z",
      "date_published": "2026-07-11T03:44:25.168Z",
      "date_updated": "2026-07-14T14:25:22.248Z",
      "publisher": "Wordfence",
      "title": "AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions",
      "affected": {
        "vendors": [
          "wupsales"
        ],
        "products": [
          {
            "vendor": "wupsales",
            "product": "AI Copilot – Content Generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28097
      },
      "nvd": {
        "published": "2026-07-11T05:16:34.553",
        "lastModified": "2026-07-14T15:17:10.410",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6804",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The publishTasks and unpublishTasks AJAX actions accept arbitrary scenario IDs without authorization, allowing an anonymous caller to publish drafts or unpublish live posts.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b6d8ea0b-3c54-4d9d-8f14-2055510f3119?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/trunk/modules/workspace/controller.php#L141",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/modules/workspace/controller.php#L141",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/trunk/modules/workspace/controller.php#L130",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/modules/workspace/controller.php#L130",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/trunk/classes/frame.php#L283",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/frame.php#L283",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/trunk/modules/workspace/controller.php#L9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/modules/workspace/controller.php#L9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3582369%40ai-copilot-content-generator&new=3582369%40ai-copilot-content-generator",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6818",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T19:21:28.769Z",
      "date_published": "2026-07-08T11:30:31.756Z",
      "date_updated": "2026-07-08T17:09:59.950Z",
      "publisher": "Wordfence",
      "title": "VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via 'special_requests' Parameter",
      "affected": {
        "vendors": [
          "e4jvikwp"
        ],
        "products": [
          {
            "vendor": "e4jvikwp",
            "product": "VikBooking Hotel Booking Engine & PMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14721
      },
      "nvd": {
        "published": "2026-07-08T12:17:21.017",
        "lastModified": "2026-07-08T18:16:35.323",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6818",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application stores the special_requests field and renders it into HTML without the required output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/13a96e78-c83c-4ff1-a751-3dbaeb683d9d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.9/admin/helpers/widgets/booking_details.php#L684",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.9/admin/views/editorder/tmpl/default.php#L2717",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.9/admin/views/orders/tmpl/default.php#L769",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6820",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T19:25:58.842Z",
      "date_published": "2026-07-08T12:33:17.186Z",
      "date_updated": "2026-07-08T13:10:51.411Z",
      "publisher": "Wordfence",
      "title": "VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via Booking Form Email Field",
      "affected": {
        "vendors": [
          "e4jvikwp"
        ],
        "products": [
          {
            "vendor": "e4jvikwp",
            "product": "VikBooking Hotel Booking Engine & PMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13743
      },
      "nvd": {
        "published": "2026-07-08T13:16:57.780",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6820",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "VikBooking stores the booking email field and later emits it as active page markup without sufficient sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e2b4586a-f87d-4a51-8f4e-932d7254518e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.9/site/controller.php#L307",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.9/admin/controller.php#L11208",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 392,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6847",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T08:08:03.689Z",
      "date_published": "2026-07-13T13:26:20.946Z",
      "date_updated": "2026-07-14T14:32:08.791Z",
      "publisher": "CERT-PL",
      "title": "Unauthenticated Remote Code Execution in ThemisNETPanel",
      "affected": {
        "vendors": [
          "4real"
        ],
        "products": [
          {
            "vendor": "4real",
            "product": "ThemisNETPanel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00584,
        "percentile": 0.44605
      },
      "nvd": {
        "published": "2026-07-13T14:16:32.963",
        "lastModified": "2026-07-14T15:17:10.527",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6847",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ThemisNETPanel exposes a critical file-upload function without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-6847/",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 386,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6850",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T10:05:15.625Z",
      "date_published": "2026-07-13T08:13:02.883Z",
      "date_updated": "2026-07-13T13:56:16.767Z",
      "publisher": "Mattermost",
      "title": "Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15212
      },
      "nvd": {
        "published": "2026-07-13T09:16:24.890",
        "lastModified": "2026-07-13T21:42:01.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6850",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers catastrophic backtracking in the client-side markdown parser.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-6851",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T10:06:58.221Z",
      "date_published": "2026-07-14T07:11:50.520Z",
      "date_updated": "2026-07-15T04:00:51.554Z",
      "publisher": "Bitdefender",
      "title": "Improper link resolution before file access in Bitdefender Total Security via Link Following (VA-13681)",
      "affected": {
        "vendors": [
          "Bitdefender"
        ],
        "products": [
          {
            "vendor": "Bitdefender",
            "product": "Total Security"
          },
          {
            "vendor": "Bitdefender",
            "product": "Internet Security"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-requests@bitdefender.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02256
      },
      "nvd": {
        "published": "2026-07-14T08:16:24.000",
        "lastModified": "2026-07-15T05:17:25.330",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6851",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "File Shredder follows an attacker-controlled symbolic link during a race and selects a privileged file outside the caller's namespace.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.bitdefender.com/support/security-advisories/improper-link-resolution-before-file-access-via-link-following-va-13681",
          "host": "www.bitdefender.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 379,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-6854",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T12:19:28.322Z",
      "date_published": "2026-07-08T11:30:33.597Z",
      "date_updated": "2026-07-08T13:14:04.081Z",
      "publisher": "Wordfence",
      "title": "My Calendar <= 3.7.8 - Unauthenticated SQL Injection via 'mc_auth' and 'mc_host' Parameters",
      "affected": {
        "vendors": [
          "joedolson"
        ],
        "products": [
          {
            "vendor": "joedolson",
            "product": "My Calendar – Accessible Event Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19422
      },
      "nvd": {
        "published": "2026-07-08T12:17:21.137",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6854",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/aa1ed81c-04cb-4ccd-8c30-b1d943730909?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3515996/my-calendar",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 490,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6875",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T18:21:24.368Z",
      "date_published": "2026-07-13T18:17:27.508Z",
      "date_updated": "2026-07-14T03:55:45.828Z",
      "publisher": "SN",
      "title": "Sandbox Escape in ServiceNow AI Platform",
      "affected": {
        "vendors": [
          "ServiceNow"
        ],
        "products": [
          {
            "vendor": "ServiceNow",
            "product": "ServiceNow AI Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:psirt@servicenow.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.24489,
        "percentile": 0.97656
      },
      "nvd": {
        "published": "2026-07-13T19:17:36.440",
        "lastModified": "2026-07-14T05:16:19.730",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6875",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The AI platform lets unauthenticated script input escape its server-side execution sandbox, but ServiceNow does not publish the failing containment check.",
        "basis": [
          "CNA",
          "CWE-94",
          "ServiceNow KB3137947",
          "ServiceNow script-sandbox documentation"
        ],
        "deepDive": true,
        "notes": "Primary-source deep dive: https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3137947 and https://www.servicenow.com/docs/r/xanadu/platform-security/r_ScriptSandboxing.html ; ServiceNow labels this a sandbox escape and documents server-side script sandboxing, but the advisory does not publish the failing check or fixed source."
      },
      "references": [
        {
          "url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3137947",
          "host": "support.servicenow.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 815,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-6879",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T18:26:56.743Z",
      "date_published": "2026-07-28T13:46:30.650Z",
      "date_updated": "2026-07-30T17:31:30.941Z",
      "publisher": "PSF",
      "title": "Quadratic Behavior in xml.etree.ElementPath Index Predicates",
      "affected": {
        "vendors": [
          "Python Software Foundation"
        ],
        "products": [
          {
            "vendor": "Python Software Foundation",
            "product": "CPython"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cna@python.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21532
      },
      "nvd": {
        "published": "2026-07-28T15:17:51.377",
        "lastModified": "2026-07-30T19:18:37.220",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6879",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ElementPath index predicates repeatedly scan same-tag siblings, making findall and fully consumed iterfind perform quadratic work.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python/cpython/pull/152676",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/python/cpython/issues/152674",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/",
          "host": "mail.python.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6881",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T18:56:43.654Z",
      "date_published": "2026-07-28T20:03:11.667Z",
      "date_updated": "2026-07-29T13:43:54.334Z",
      "publisher": "SRA",
      "title": "Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance",
      "affected": {
        "vendors": [
          "Ellucian"
        ],
        "products": [
          {
            "vendor": "Ellucian",
            "product": "Advance Web"
          },
          {
            "vendor": "Ellucian",
            "product": "Legacy Advance"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:57dba5dd-1a03-47f6-8b36-e84e47d335d8",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10483
      },
      "nvd": {
        "published": "2026-07-28T21:17:29.427",
        "lastModified": "2026-07-29T14:16:35.623",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6881",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Advance Web data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://labs.sra.io/posts/ellucian",
          "host": "labs.sra.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 346,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-6889",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-04-23T02:58:22.972Z",
      "date_published": "2026-07-31T02:27:18.801Z",
      "date_rejected": "2026-07-31T05:07:37.432Z",
      "date_updated": "2026-07-31T05:07:37.432Z",
      "publisher": "CSA",
      "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
      "rejected_reason": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority."
    },
    {
      "cve_id": "CVE-2026-6890",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-04-23T02:58:23.248Z",
      "date_published": "2026-07-31T02:27:25.893Z",
      "date_rejected": "2026-07-31T05:09:14.254Z",
      "date_updated": "2026-07-31T05:09:14.254Z",
      "publisher": "CSA",
      "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
      "rejected_reason": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority."
    },
    {
      "cve_id": "CVE-2026-6896",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-23T05:33:12.333Z",
      "date_published": "2026-07-08T20:46:38.858Z",
      "date_updated": "2026-07-09T14:13:51.367Z",
      "publisher": "GitLab",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 3.299999999999999,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31632
      },
      "nvd": {
        "published": "2026-07-08T21:16:55.097",
        "lastModified": "2026-07-09T20:38:26.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-6896",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Developer-controlled content is insufficiently sanitized before another user's browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/597887",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3682085",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-6900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-23T08:25:59.674Z",
      "date_published": "2026-07-06T09:53:41.770Z",
      "date_updated": "2026-07-06T18:49:35.645Z",
      "publisher": "ABB",
      "title": "Improper Certificate Validation",
      "affected": {
        "vendors": [
          "B&R Industrial Automation GmbH"
        ],
        "products": [
          {
            "vendor": "B&R Industrial Automation GmbH",
            "product": "APROL"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cybersecurity@ch.abb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cybersecurity@ch.abb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04019
      },
      "nvd": {
        "published": "2026-07-06T11:16:31.297",
        "lastModified": "2026-07-06T19:35:23.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6900",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The APROL secure-channel path does not correctly validate the peer certificate before trusting the connection.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P011-661853b7.pdf",
          "host": "br-cws-assets.de-fra-1.linodeobjects.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6901",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-23T08:26:08.011Z",
      "date_published": "2026-07-06T10:01:51.893Z",
      "date_updated": "2026-07-06T11:06:28.326Z",
      "publisher": "ABB",
      "title": "Untrusted Search Path",
      "affected": {
        "vendors": [
          "B&R Industrial Automation GmbH"
        ],
        "products": [
          {
            "vendor": "B&R Industrial Automation GmbH",
            "product": "APROL"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-426",
          "name": "Untrusted Search Path",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cybersecurity@ch.abb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cybersecurity@ch.abb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02148
      },
      "nvd": {
        "published": "2026-07-06T11:16:31.433",
        "lastModified": "2026-07-06T19:35:23.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6901",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "APROL searches an untrusted path when resolving executable or library dependencies.",
        "basis": [
          "CNA",
          "CWE-426"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P011-661853b7.pdf",
          "host": "br-cws-assets.de-fra-1.linodeobjects.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6910",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-23T13:37:42.300Z",
      "date_published": "2026-07-09T06:52:52.056Z",
      "date_updated": "2026-07-09T14:39:45.983Z",
      "publisher": "Wordfence",
      "title": "Bookero.pl <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "affected": {
        "vendors": [
          "safistudio"
        ],
        "products": [
          {
            "vendor": "safistudio",
            "product": "Bookero.pl – system rezerwacji online"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10849
      },
      "nvd": {
        "published": "2026-07-09T08:16:49.210",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6910",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This is due to insufficient input sanitization and output escaping in the `bookero_products()` function — the raw attribute value is concatenated directly into an inline `<script>` block without any escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fd0e6ca6-f6a7-4e81-aea1-3b59de0173d6?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bookeropl/trunk/libraries/bookero-front.php#L174",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bookeropl/tags/2.1/libraries/bookero-front.php#L174",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bookeropl/trunk/libraries/bookero-front.php#L173",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bookeropl/tags/2.1/libraries/bookero-front.php#L173",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3524452%40bookeropl&new=3524452%40bookeropl",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 639,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6924",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-23T17:11:02.116Z",
      "date_published": "2026-07-23T21:05:22.113Z",
      "date_updated": "2026-07-24T13:40:36.220Z",
      "publisher": "Silabs",
      "title": "Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path",
      "affected": {
        "vendors": [
          "Silicon Labs"
        ],
        "products": [
          {
            "vendor": "Silicon Labs",
            "product": "Silicon Labs Matter Github"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-336",
          "name": "Same Seed in Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:product-security@silabs.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17943
      },
      "nvd": {
        "published": "2026-07-23T21:17:05.447",
        "lastModified": "2026-07-24T14:16:27.580",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6924",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SiWx917 entropy initializer gives TinyCrypt DRBG a predictable seed, causing every Matter random value to follow the same stream.",
        "basis": [
          "CNA",
          "CWE-336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/a45Vm0000009SzZIAU?operationContext=S1",
          "host": "siliconlabs.lightning.force.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/SiliconLabs/matter/tree/release_2.3.1-1.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6939",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-23T19:42:23.702Z",
      "date_published": "2026-07-11T05:35:50.032Z",
      "date_updated": "2026-07-13T17:30:54.461Z",
      "publisher": "Wordfence",
      "title": "CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter",
      "affected": {
        "vendors": [
          "corvusinfo"
        ],
        "products": [
          {
            "vendor": "corvusinfo",
            "product": "CorvusPay WooCommerce Payment Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24887
      },
      "nvd": {
        "published": "2026-07-11T07:16:46.787",
        "lastModified": "2026-07-13T18:16:30.693",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6939",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CorvusPay callback logs a failed signature check and continues, storing an attacker-controlled approval_code that is later emitted as HTML.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d8a81c01-495f-4861-b66f-000072e99512?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/trunk/includes/class-wc-order-corvuspay.php#L185",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/trunk/includes/class-wc-gateway-corvuspay.php#L202",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/trunk/includes/class-wc-gateway-corvuspay.php#L1713",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.3/includes/class-wc-gateway-corvuspay.php#L1713",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.3/includes/class-wc-order-corvuspay.php#L185",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.3/includes/class-wc-gateway-corvuspay.php#L202",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.2/includes/class-wc-gateway-corvuspay.php#L1713",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.2/includes/class-wc-order-corvuspay.php#L185",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.2/includes/class-wc-gateway-corvuspay.php#L202",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3576949%40corvuspay-woocommerce-integration&new=3576949%40corvuspay-woocommerce-integration",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 763,
        "referenceCount": 11,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-6952",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-24T08:08:46.958Z",
      "date_published": "2026-07-21T02:00:01.471Z",
      "date_updated": "2026-07-23T03:56:26.499Z",
      "publisher": "Zyxel",
      "title": "A post-authentication command injection vulnerability in the \"LogServer\" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.",
      "affected": {
        "vendors": [
          "Zyxel"
        ],
        "products": [
          {
            "vendor": "Zyxel",
            "product": "AX7501-B1 firmware"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@zyxel.com.tw",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0095,
        "percentile": 0.57813
      },
      "nvd": {
        "published": "2026-07-21T03:16:42.610",
        "lastModified": "2026-07-23T05:16:38.620",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-6952",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled command data reaches a command interpreter without safe argument separation or complete command-language neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-post-authentication-command-injection-vulnerability-in-certain-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-07-21-2026",
          "host": "www.zyxel.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 278,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7007",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-24T22:00:52.689Z",
      "date_published": "2026-07-24T13:48:24.831Z",
      "date_updated": "2026-07-24T15:04:01.152Z",
      "publisher": "zephyr",
      "title": "Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-369",
          "name": "Divide By Zero",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05191
      },
      "nvd": {
        "published": "2026-07-24T15:19:08.047",
        "lastModified": "2026-07-27T20:32:27.703",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7007",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ext2 superblock validator accepts zero blocks-per-group or inodes-per-group values that later become divisors during mount initialization.",
        "basis": [
          "CNA",
          "CWE-369"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/babc0900ed40e6c023ccc26aa1a321f9388b66af",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-wrf2-79mm-cvw5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1470,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7017",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-25T10:30:05.190Z",
      "date_published": "2026-07-07T17:41:48.989Z",
      "date_updated": "2026-07-07T20:35:36.874Z",
      "publisher": "CPANSec",
      "title": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets",
      "affected": {
        "vendors": [
          "HAARG"
        ],
        "products": [
          {
            "vendor": "HAARG",
            "product": "HTTP::Tiny"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17291
      },
      "nvd": {
        "published": "2026-07-07T19:16:55.530",
        "lastModified": "2026-07-08T15:56:29.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7017",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HTTP::Tiny follows a redirect and re-merges caller-supplied credential headers without checking whether scheme, host, and port remain the same origin.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/07/13",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 829,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7120",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-26T18:43:14.410Z",
      "date_published": "2026-07-23T02:48:35.120Z",
      "date_updated": "2026-07-23T14:15:22.625Z",
      "publisher": "openjs",
      "title": "@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths",
      "affected": {
        "vendors": [
          "@fastify/static"
        ],
        "products": [
          {
            "vendor": "@fastify/static",
            "product": "@fastify/static"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-180",
          "name": "Incorrect Behavior Order: Validate Before Canonicalize",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12721
      },
      "nvd": {
        "published": "2026-07-23T04:16:33.187",
        "lastModified": "2026-07-28T17:05:24.913",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7120",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "allowedPath evaluates a noncanonical pathname before dot segments and duplicate separators are normalized for file resolution.",
        "basis": [
          "CNA",
          "CWE-180"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fastify/fastify-static/security/advisories/GHSA-8pvw-jcv7-9cmj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 550,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-7162",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T03:13:36.806Z",
      "date_published": "2026-07-13T02:42:00.531Z",
      "date_updated": "2026-07-13T15:45:56.103Z",
      "publisher": "CSA",
      "title": "Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software.",
      "affected": {
        "vendors": [
          "WinFsp"
        ],
        "products": [
          {
            "vendor": "WinFsp",
            "product": "WinFsp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01951
      },
      "nvd": {
        "published": "2026-07-13T04:16:29.127",
        "lastModified": "2026-07-13T20:37:48.157",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7162",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An arithmetic operation in the affected software can overflow its integer range and corrupt a downstream size or index used at system privilege.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-086",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/winfsp/winfsp/releases/tag/v2.2B2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7185",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T11:08:09.070Z",
      "date_published": "2026-07-06T13:10:09.389Z",
      "date_updated": "2026-07-06T16:12:10.409Z",
      "publisher": "INCIBE",
      "title": "Unauthorized access to files in T-Systems products",
      "affected": {
        "vendors": [
          "T-Systems"
        ],
        "products": [
          {
            "vendor": "T-Systems",
            "product": "Archivo"
          },
          {
            "vendor": "T-Systems",
            "product": "MyTAO"
          },
          {
            "vendor": "T-Systems",
            "product": "eStima"
          },
          {
            "vendor": "T-Systems",
            "product": "Buroweb"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21442
      },
      "nvd": {
        "published": "2026-07-06T15:16:41.080",
        "lastModified": "2026-07-06T18:41:46.210",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7185",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "File-management or upload input can select a filesystem resource outside the TAO application's intended directory scope, although the parameter is not public.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/unauthorized-access-files-t-systems-products",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-7187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T13:08:25.778Z",
      "date_published": "2026-07-28T12:27:44.637Z",
      "date_updated": "2026-07-28T12:27:44.637Z",
      "publisher": "TR-CERT",
      "title": "Improper Authentication in Universal Sotware's UKBS",
      "affected": {
        "vendors": [
          "Universal Software Inc."
        ],
        "products": [
          {
            "vendor": "Universal Software Inc.",
            "product": "UKBS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12029
      },
      "nvd": {
        "published": "2026-07-28T13:19:08.247",
        "lastModified": "2026-07-28T16:10:09.517",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7187",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive UKBS operation can run without authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0664",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7189",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T13:09:39.937Z",
      "date_published": "2026-07-17T12:44:15.230Z",
      "date_updated": "2026-07-17T14:52:33.952Z",
      "publisher": "TR-CERT",
      "title": "Sensitive Data Exposure in Proliz's OBS",
      "affected": {
        "vendors": [
          "Proliz Software Ltd. Co."
        ],
        "products": [
          {
            "vendor": "Proliz Software Ltd. Co.",
            "product": "Proliz's OBS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15778
      },
      "nvd": {
        "published": "2026-07-17T13:19:01.490",
        "lastModified": "2026-07-17T16:17:17.653",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7189",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Proliz OBS inserts sensitive information into data sent to a caller whose ACL does not permit that information.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0571",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T16:42:07.099Z",
      "date_published": "2026-07-23T05:35:54.236Z",
      "date_updated": "2026-07-23T13:42:11.125Z",
      "publisher": "Wordfence",
      "title": "FormCraft <= 3.9.14 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Parameters",
      "affected": {
        "vendors": [
          "FormCraft"
        ],
        "products": [
          {
            "vendor": "FormCraft",
            "product": "FormCraft"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10861
      },
      "nvd": {
        "published": "2026-07-23T06:16:50.607",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7232",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Matrix values bypass both the scalar sanitization loop and the scalar-only DOMPurify check before their strings are inserted into the DOM.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6b30089a-2267-47b9-b0a5-d6eeadfe51d2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://formcraft-wp.com/changelog/",
          "host": "formcraft-wp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1087,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7260",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-28T05:07:45.654Z",
      "date_published": "2026-07-30T11:22:53.918Z",
      "date_updated": "2026-07-30T12:15:22.862Z",
      "publisher": "php",
      "title": "Stack overflow in phar with circular symlinks",
      "affected": {
        "vendors": [
          "PHP Group"
        ],
        "products": [
          {
            "vendor": "PHP Group",
            "product": "PHP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U"
        },
        {
          "source": "NVD:security@php.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06457
      },
      "nvd": {
        "published": "2026-07-30T12:19:04.300",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7260",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PHP follows circular symbolic links in a phar archive recursively without cycle detection or a depth limit, exhausting the C stack.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/php/php-src/security/advisories/GHSA-vc5h-9ppw-p5f3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-7311",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-28T12:43:26.086Z",
      "date_published": "2026-07-02T18:32:13.440Z",
      "date_updated": "2026-07-02T19:40:57.141Z",
      "publisher": "Wordfence",
      "title": "TinyPNG <= 3.6.13 - Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post Meta",
      "affected": {
        "vendors": [
          "tinypng"
        ],
        "products": [
          {
            "vendor": "tinypng",
            "product": "TinyPNG – JPEG, PNG & WebP image compression"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00651,
        "percentile": 0.47679
      },
      "nvd": {
        "published": "2026-07-02T19:17:00.127",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7311",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "delete_converted_image_size trusts convert.path from attacker-controlled attachment metadata and deletes that selected server file.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/eb8a673e-a192-41d4-b53b-7d786887242d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tiny-compress-images/tags/3.6.13/src/class-tiny-image-size.php#L245",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tiny-compress-images/tags/3.6.13/src/config/class-tiny-config.php#L12",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tiny-compress-images/tags/3.6.13/src/class-tiny-image.php#L144",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tiny-compress-images/tags/3.6.13/src/class-tiny-plugin.php#L859",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3532827/tiny-compress-images",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-28T16:55:51.837Z",
      "date_published": "2026-07-22T16:17:27.615Z",
      "date_updated": "2026-07-22T18:49:41.784Z",
      "publisher": "Caliptra",
      "title": "Unverified AXI Address in Subsystem Mode Commands Enables Denial of Service",
      "affected": {
        "vendors": [
          "Caliptra"
        ],
        "products": [
          {
            "vendor": "Caliptra",
            "product": "Core Runtime Firmware"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:b01ddd03-5ef6-483b-b2c5-acba77f1a554",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00091,
        "percentile": 0.00588
      },
      "nvd": {
        "published": "2026-07-22T17:16:59.557",
        "lastModified": "2026-07-22T20:40:57.147",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7328",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Subsystem mailbox commands accept AXI addresses without checking that the caller is authorized to target those regions.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/chipsalliance/caliptra-sw/security/advisories/GHSA-c5v4-q445-wv84",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 386,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-7362",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-28T20:09:35.647Z",
      "date_published": "2026-07-28T18:00:48.872Z",
      "date_updated": "2026-07-29T13:58:19.335Z",
      "publisher": "ibm",
      "title": "Improper Access Control Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Sterling B2B Integrator"
          },
          {
            "vendor": "IBM",
            "product": "Sterling File Gateway"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07526
      },
      "nvd": {
        "published": "2026-07-28T19:17:41.587",
        "lastModified": "2026-08-03T15:17:50.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7362",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The product exposes privileged information to an ordinary authenticated user, but the record does not identify the object or authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280849",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-7364",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-28T20:43:22.842Z",
      "date_published": "2026-07-17T19:31:02.236Z",
      "date_updated": "2026-07-20T13:59:14.531Z",
      "publisher": "ibm",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Verify Identity Access"
          },
          {
            "vendor": "IBM",
            "product": "Security Verify Access"
          },
          {
            "vendor": "IBM",
            "product": "Verify Identity Access Container"
          },
          {
            "vendor": "IBM",
            "product": "Security Verify Access Container"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 2.9999999999999996,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17523
      },
      "nvd": {
        "published": "2026-07-17T20:17:29.203",
        "lastModified": "2026-07-30T12:58:27.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7364",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "IBM Verify Identity Access accepts a caller-selected external redirect destination without restricting it to a trusted origin.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279510",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 448,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-7380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-29T07:43:24.780Z",
      "date_published": "2026-07-07T06:57:31.329Z",
      "date_updated": "2026-07-07T13:25:08.153Z",
      "publisher": "TR-CERT",
      "title": "HTML Injection in Armiya Technologies' Access Control System",
      "affected": {
        "vendors": [
          "Armiya Information Technologies Ltd. Co."
        ],
        "products": [
          {
            "vendor": "Armiya Information Technologies Ltd. Co.",
            "product": "Access Control System (GKS)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-80",
          "name": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04577
      },
      "nvd": {
        "published": "2026-07-07T08:16:25.793",
        "lastModified": "2026-07-07T14:16:34.677",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7380",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Access Control System permits attacker-controlled script-related HTML to enter an attribute context without neutralization.",
        "basis": [
          "CNA",
          "CWE-80"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0502",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-29T15:33:18.182Z",
      "date_published": "2026-07-29T09:31:14.133Z",
      "date_updated": "2026-07-29T13:41:52.099Z",
      "publisher": "Wordfence",
      "title": "WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Attribute",
      "affected": {
        "vendors": [
          "wpclever"
        ],
        "products": [
          {
            "vendor": "wpclever",
            "product": "WPC Badge Management for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09243
      },
      "nvd": {
        "published": "2026-07-29T11:16:50.553",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7436",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping on user supplied attributes.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/588e12c4-7d68-40ac-82bc-aacc5d389dee?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://wordpress.org/plugins/wpc-badge-management",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpc-badge-management/trunk/includes/class-shortcode.php#L141",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpc-badge-management/tags/3.1.5/includes/class-shortcode.php#L141",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3519100%40wpc-badge-management%2Ftrunk&old=3483376%40wpc-badge-management%2Ftrunk&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 495,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7483",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T06:28:55.139Z",
      "date_published": "2026-07-24T09:40:04.483Z",
      "date_updated": "2026-07-24T10:49:13.322Z",
      "publisher": "ESET",
      "title": "Local privilege escalation in ESET security applications for macOS",
      "affected": {
        "vendors": [
          "ESET spol. s.r.o."
        ],
        "products": [
          {
            "vendor": "ESET spol. s.r.o.",
            "product": "ESET Endpoint Security for macOS"
          },
          {
            "vendor": "ESET spol. s.r.o.",
            "product": "ESET Cyber Security for macOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@eset.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02574
      },
      "nvd": {
        "published": "2026-07-24T10:16:32.637",
        "lastModified": "2026-07-30T19:14:09.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7483",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.eset.com/en/ca8974-eset-customer-advisory-local-privilege-escalation-vulnerability-in-eset-security-applications-for-macos-fixed",
          "host": "support.eset.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 137,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-7484",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T07:07:30.821Z",
      "date_published": "2026-07-24T12:26:36.257Z",
      "date_updated": "2026-07-24T13:46:53.759Z",
      "publisher": "TR-CERT",
      "title": "Improper Access Control in Abis Technology's AVESİS",
      "affected": {
        "vendors": [
          "ABIS Technology Ltd. Co."
        ],
        "products": [
          {
            "vendor": "ABIS Technology Ltd. Co.",
            "product": "AVESİS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-472",
          "name": "External Control of Assumed-Immutable Web Parameter",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09728
      },
      "nvd": {
        "published": "2026-07-24T13:18:30.867",
        "lastModified": "2026-07-24T20:47:58.773",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7484",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-472"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0634",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T08:35:33.602Z",
      "date_published": "2026-07-17T13:07:43.542Z",
      "date_updated": "2026-07-17T13:55:14.979Z",
      "publisher": "TR-CERT",
      "title": "Sensitive Data Exposure in IKAS Technologies' E-Commerce",
      "affected": {
        "vendors": [
          "IKAS Technology Inc."
        ],
        "products": [
          {
            "vendor": "IKAS Technology Inc.",
            "product": "E-Commerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15776
      },
      "nvd": {
        "published": "2026-07-17T14:17:27.420",
        "lastModified": "2026-07-17T15:00:17.017",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7488",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected interface returns, embeds or leaves protected information visible to an observer who is not entitled to receive it.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0572",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T09:04:45.873Z",
      "date_published": "2026-07-08T20:46:33.861Z",
      "date_updated": "2026-07-09T14:14:15.159Z",
      "publisher": "GitLab",
      "title": "Missing Authorization in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16905
      },
      "nvd": {
        "published": "2026-07-08T21:16:55.213",
        "lastModified": "2026-07-09T20:37:12.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7492",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://hackerone.com/reports/3704739",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/597947",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-7494",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T12:15:30.668Z",
      "date_published": "2026-07-14T15:46:24.649Z",
      "date_updated": "2026-07-14T17:12:29.505Z",
      "publisher": "Sonatype",
      "title": "Nexus Repository - SSRF in SSL Certificate Retrieval",
      "affected": {
        "vendors": [
          "Sonatype"
        ],
        "products": [
          {
            "vendor": "Sonatype",
            "product": "Nexus Repository"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:103e4ec9-0a87-450b-af77-479448ddef11",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.043
      },
      "nvd": {
        "published": "2026-07-14T16:17:04.953",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7494",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Nexus Repository follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://help.sonatype.com/en/sonatype-nexus-repository-3-94-0-release-notes.html",
          "host": "help.sonatype.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://support.sonatype.com/hc/en-us/articles/53126069518227",
          "host": "support.sonatype.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 353,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7517",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T16:09:12.074Z",
      "date_published": "2026-07-01T04:32:25.633Z",
      "date_updated": "2026-07-01T10:32:05.050Z",
      "publisher": "Wordfence",
      "title": "Custom Payment Gateways for WooCommerce <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'alg_wc_cpg_input_fields' Parameter",
      "affected": {
        "vendors": [
          "dhruvin"
        ],
        "products": [
          {
            "vendor": "dhruvin",
            "product": "Custom Payment Gateways for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16005
      },
      "nvd": {
        "published": "2026-07-01T05:16:23.550",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7517",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unauthenticated checkout parameter is stored without sufficient sanitization or output escaping and later executes as browser script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1defa728-9f9d-4e8f-8f6c-432c615da7f5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/custom-payment-gateways-woocommerce/trunk/includes/class-alg-wc-custom-payment-gateways-input-fields.php#L86",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/custom-payment-gateways-woocommerce/tags/2.1.0/includes/class-alg-wc-custom-payment-gateways-input-fields.php#L86",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/custom-payment-gateways-woocommerce/trunk/includes/class-alg-wc-custom-payment-gateways-input-fields.php#L264",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/custom-payment-gateways-woocommerce/tags/2.1.0/includes/class-alg-wc-custom-payment-gateways-input-fields.php#L264",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/custom-payment-gateways-woocommerce/trunk/includes/class-alg-wc-custom-payment-gateways-input-fields.php#L241",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/custom-payment-gateways-woocommerce/tags/2.1.0/includes/class-alg-wc-custom-payment-gateways-input-fields.php#L241",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3578163%40custom-payment-gateways-woocommerce&new=3578163%40custom-payment-gateways-woocommerce&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7521",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T16:51:23.295Z",
      "date_published": "2026-07-28T13:58:31.551Z",
      "date_updated": "2026-07-28T14:48:13.408Z",
      "publisher": "Mattermost",
      "title": "SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20584
      },
      "nvd": {
        "published": "2026-07-28T15:17:51.510",
        "lastModified": "2026-07-29T15:06:39.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7521",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A deletion path is not confined to the configuration directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 334,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-7534",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T18:02:21.113Z",
      "date_published": "2026-07-23T05:35:53.695Z",
      "date_updated": "2026-07-23T13:43:56.021Z",
      "publisher": "Wordfence",
      "title": "SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter",
      "affected": {
        "vendors": [
          "FantasticPlugins"
        ],
        "products": [
          {
            "vendor": "FantasticPlugins",
            "product": "SUMO Reward Points for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.089
      },
      "nvd": {
        "published": "2026-07-23T06:16:50.780",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7534",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The earning endpoint grants its custom capability to unauthenticated callers and stores an unescaped reason that later executes in administrator pages.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/366b5051-d042-4425-9aad-b77d93bcd485?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://codecanyon.net/item/sumo-reward-points-woocommerce-reward-system/7791451",
          "host": "codecanyon.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 793,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7543",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T18:53:00.243Z",
      "date_published": "2026-07-16T07:51:02.905Z",
      "date_updated": "2026-07-17T12:38:09.280Z",
      "publisher": "Wordfence",
      "title": "Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting via Webhook Action Details",
      "affected": {
        "vendors": [
          "Breakdance"
        ],
        "products": [
          {
            "vendor": "Breakdance",
            "product": "Breakdance"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08898
      },
      "nvd": {
        "published": "2026-07-16T09:16:19.527",
        "lastModified": "2026-07-17T13:19:01.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7543",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Breakdance renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/64f07bca-5d04-4b28-b775-f47ed692575e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://breakdance.com/breakdance-2-7-2-security-update/",
          "host": "breakdance.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7544",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T18:53:02.173Z",
      "date_published": "2026-07-11T02:31:19.224Z",
      "date_updated": "2026-07-13T17:42:04.674Z",
      "publisher": "Wordfence",
      "title": "Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure",
      "affected": {
        "vendors": [
          "2coders"
        ],
        "products": [
          {
            "vendor": "2coders",
            "product": "Mux Video Uploader"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14885
      },
      "nvd": {
        "published": "2026-07-11T04:17:23.993",
        "lastModified": "2026-07-13T18:16:30.813",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7544",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "muxvideo_enqueue_settings_script embeds Mux API credentials in settings visible to subscriber-level users.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e462a7ba-887c-408d-87a6-9260a33dcff5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/2coders-integration-mux-video/trunk/includes/functions.php#L672",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/2coders-integration-mux-video/tags/1.1.4/includes/functions.php#L672",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/2coders-integration-mux-video/trunk/includes/functions.php#L668",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/2coders-integration-mux-video/tags/1.1.4/includes/functions.php#L668",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3543763%402coders-integration-mux-video&new=3543763%402coders-integration-mux-video",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7558",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T19:30:10.370Z",
      "date_published": "2026-07-09T06:52:49.157Z",
      "date_updated": "2026-07-09T12:47:15.822Z",
      "publisher": "Wordfence",
      "title": "Age Verification & Identity Verification by Token of Trust <= 4.0.2 - Missing Authorization to Unauthenticated Information Exposure via 'tot_export_table' Parameter",
      "affected": {
        "vendors": [
          "tokenoftrust"
        ],
        "products": [
          {
            "vendor": "tokenoftrust",
            "product": "Age Verification & Identity Verification by Token of Trust"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17866
      },
      "nvd": {
        "published": "2026-07-09T08:16:49.347",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7558",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "handle_export_table runs for unauthenticated init requests and returns donation CSV data without a capability check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c3e98eb0-3c56-46fd-839e-ff530d431e8d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/token-of-trust/trunk/integrations/woocommerce/class-donations.php#L99",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/token-of-trust/tags/3.34.2/integrations/woocommerce/class-donations.php#L99",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/token-of-trust/trunk/integrations/woocommerce/class-donations.php#L100",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/token-of-trust/tags/3.34.2/integrations/woocommerce/class-donations.php#L100",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/token-of-trust/tags/3.31.5/integrations/woocommerce/class-donations.php#L99",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/token-of-trust/tags/3.31.5/integrations/woocommerce/class-donations.php#L100",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3539532%40token-of-trust&new=3539532%40token-of-trust",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 698,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7559",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T19:33:37.479Z",
      "date_published": "2026-07-11T03:44:23.763Z",
      "date_updated": "2026-07-13T14:25:12.914Z",
      "publisher": "Wordfence",
      "title": "Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Status Modification",
      "affected": {
        "vendors": [
          "redefiningtheweb"
        ],
        "products": [
          {
            "vendor": "redefiningtheweb",
            "product": "Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affilia"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22752
      },
      "nvd": {
        "published": "2026-07-11T05:16:34.673",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7559",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Affilia exposes its only nonce on every frontend page and omits role or capability checks, allowing any authenticated subscriber to mutate referrals, commissions, and options.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/85a37373-a97f-44b7-a743-bbaaa0056a6c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/affiliaa-affiliate-program-with-mlm/trunk/admin/rtwalwm-class-wp-wc-affiliate-program-admin.php#L660",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/affiliaa-affiliate-program-with-mlm/tags/3.3.3/admin/rtwalwm-class-wp-wc-affiliate-program-admin.php#L660",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/affiliaa-affiliate-program-with-mlm/trunk/admin/rtwalwm-class-wp-wc-affiliate-program-admin.php#L812",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/affiliaa-affiliate-program-with-mlm/tags/3.3.3/admin/rtwalwm-class-wp-wc-affiliate-program-admin.php#L812",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/affiliaa-affiliate-program-with-mlm/trunk/admin/rtwalwm-class-wp-wc-affiliate-program-admin.php#L742",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/affiliaa-affiliate-program-with-mlm/tags/3.3.3/admin/rtwalwm-class-wp-wc-affiliate-program-admin.php#L742",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/affiliaa-affiliate-program-with-mlm/trunk/admin/rtwalwm-class-wp-wc-affiliate-program-admin.php#L837",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/affiliaa-affiliate-program-with-mlm/tags/3.3.3/admin/rtwalwm-class-wp-wc-affiliate-program-admin.php#L837",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/affiliaa-affiliate-program-with-mlm/trunk/public/rtwalwm-class-wp-wc-affiliate-program-public.php#L127",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/affiliaa-affiliate-program-with-mlm/tags/3.3.3/public/rtwalwm-class-wp-wc-affiliate-program-public.php#L127",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3542527%40affiliaa-affiliate-program-with-mlm&new=3542527%40affiliaa-affiliate-program-with-mlm",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 747,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7620",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T13:22:31.542Z",
      "date_published": "2026-07-11T03:44:20.239Z",
      "date_updated": "2026-07-13T14:39:54.504Z",
      "publisher": "Wordfence",
      "title": "Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Cron Modification via nftb_cron_action_set AJAX Action",
      "affected": {
        "vendors": [
          "rainafarai"
        ],
        "products": [
          {
            "vendor": "rainafarai",
            "product": "Notification for Telegram"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19392
      },
      "nvd": {
        "published": "2026-07-11T05:16:34.790",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7620",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The nftb_cron_action_set AJAX action lets a subscriber create or reschedule the plugin cron event without checking the required authorization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/01055be6-42ae-405f-9c8b-7acf5297867e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/notification-for-telegram/trunk/include/nftncron.php#L122",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5.1/include/nftncron.php#L122",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/notification-for-telegram/trunk/include/nftncron.php#L94",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5.1/include/nftncron.php#L94",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/notification-for-telegram/trunk/include/nftncron.php#L126",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5.1/include/nftncron.php#L126",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5/include/nftncron.php#L122",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5/include/nftncron.php#L94",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5/include/nftncron.php#L126",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3524838%40notification-for-telegram&new=3524838%40notification-for-telegram",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 11,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7639",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T16:03:30.275Z",
      "date_published": "2026-07-10T20:50:27.730Z",
      "date_updated": "2026-07-13T18:55:22.535Z",
      "publisher": "imaginationtech",
      "title": "GPU DDK - Page UAF read in PMMETA_PROTECT heap memory",
      "affected": {
        "vendors": [
          "Imagination Technologies"
        ],
        "products": [
          {
            "vendor": "Imagination Technologies",
            "product": "Graphics DDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-459",
          "name": "Incomplete Cleanup",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.0238
      },
      "nvd": {
        "published": "2026-07-10T21:17:00.637",
        "lastModified": "2026-07-13T19:24:52.303",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7639",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Graphics DDK failure path leaves partially released state reachable by a later operation.",
        "basis": [
          "CNA",
          "CWE-459"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
          "host": "www.imaginationtech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-7640",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T16:04:35.770Z",
      "date_published": "2026-07-14T01:30:01.579Z",
      "date_updated": "2026-07-15T14:33:22.646Z",
      "publisher": "Wordfence",
      "title": "WP Customer Area <= 8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'type' Shortcode Attribute",
      "affected": {
        "vendors": [
          "aguilatechnologies"
        ],
        "products": [
          {
            "vendor": "aguilatechnologies",
            "product": "WP Customer Area"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09704
      },
      "nvd": {
        "published": "2026-07-14T02:16:57.980",
        "lastModified": "2026-07-15T15:16:49.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7640",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The shortcode type attribute is stored and rendered without sufficient sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c6f96cec-ddcb-45b2-a28c-b4e7b6f5c719?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://wordpress.org/plugins/customer-area",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customer-area/tags/8.3.4/src/php/core-addons/shortcodes/shortcodes/protected-content-shortcode.class.php#L90",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customer-area/trunk/src/php/core-addons/shortcodes/shortcodes/protected-content-shortcode.class.php#L90",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customer-area/tags/8.3.6/src/php/core-addons/shortcodes/shortcodes/protected-content-shortcode.class.php#L88-L91",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7655",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T18:32:09.448Z",
      "date_published": "2026-07-11T04:32:59.281Z",
      "date_updated": "2026-07-15T13:38:54.348Z",
      "publisher": "Wordfence",
      "title": "SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook",
      "affected": {
        "vendors": [
          "surecart"
        ],
        "products": [
          {
            "vendor": "surecart",
            "product": "SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24434
      },
      "nvd": {
        "published": "2026-07-11T06:16:10.657",
        "lastModified": "2026-07-15T14:18:35.383",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7655",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e19f5f7b-6698-4275-a362-15e5441e0fa9?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3532438/surecart",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 603,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7667",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T20:06:08.386Z",
      "date_published": "2026-07-17T19:21:41.231Z",
      "date_updated": "2026-07-23T03:56:10.623Z",
      "publisher": "ibm",
      "title": "Path Traversal Vulnerability in API Request Component Content-Disposition Header Processing",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28645
      },
      "nvd": {
        "published": "2026-07-17T20:17:29.350",
        "lastModified": "2026-07-23T05:16:38.727",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7667",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Langflow trusts a remote Content-Disposition filename containing traversal segments and writes the downloaded content outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278931",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T02:59:50.681Z",
      "date_published": "2026-07-17T19:19:24.794Z",
      "date_updated": "2026-07-21T15:38:49.397Z",
      "publisher": "ibm",
      "title": "SSRF Protection Configuration Vulnerability",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10136
      },
      "nvd": {
        "published": "2026-07-17T20:17:29.470",
        "lastModified": "2026-07-21T16:17:21.993",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7754",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an unsafe configuration, update, or dependency state in Langflow OSS, while the enabling setting or artifact is not public.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278930",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T03:09:10.217Z",
      "date_published": "2026-07-17T19:18:26.904Z",
      "date_updated": "2026-07-23T03:56:09.818Z",
      "publisher": "ibm",
      "title": "MCP Server Configuration Validator Bypass via File Upload API",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00415,
        "percentile": 0.34161
      },
      "nvd": {
        "published": "2026-07-17T20:17:30.137",
        "lastModified": "2026-07-23T05:16:38.850",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7755",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Langflow applies incomplete validation to uploaded MCP server configuration, allowing executable configuration to pass the validator.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278932",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 156,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T13:28:13.107Z",
      "date_published": "2026-07-28T17:58:46.012Z",
      "date_updated": "2026-07-29T03:56:08.092Z",
      "publisher": "ibm",
      "title": "SQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Sterling B2B Integrator"
          },
          {
            "vendor": "IBM",
            "product": "Sterling File Gateway"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19721
      },
      "nvd": {
        "published": "2026-07-28T19:17:41.720",
        "lastModified": "2026-08-03T15:05:36.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7769",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281135",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-7771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T14:17:26.954Z",
      "date_published": "2026-07-17T19:16:03.169Z",
      "date_updated": "2026-07-21T02:03:08.521Z",
      "publisher": "ibm",
      "title": "IBM® Db2® is vulnerable to a trap when compiling specially crafted statements containing subqueries could lead to a denial of service",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Db2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00103,
        "percentile": 0.01169
      },
      "nvd": {
        "published": "2026-07-17T20:17:30.247",
        "lastModified": "2026-07-24T15:59:54.313",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7771",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input can leave a processing loop without a reachable exit condition, consuming CPU until the operation is terminated.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279480",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-7775",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T15:09:09.036Z",
      "date_published": "2026-07-28T16:01:13.214Z",
      "date_updated": "2026-07-28T16:37:48.520Z",
      "publisher": "ibm",
      "title": "Cross-site Scripting Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Sterling B2B Integrator"
          },
          {
            "vendor": "IBM",
            "product": "Sterling File Gateway"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05738
      },
      "nvd": {
        "published": "2026-07-28T16:20:21.637",
        "lastModified": "2026-07-28T17:17:08.150",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7775",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280847",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 473,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-7828",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T03:40:50.298Z",
      "date_published": "2026-07-01T03:33:21.648Z",
      "date_updated": "2026-07-09T04:36:02.166Z",
      "publisher": "securin",
      "title": "UltraVNC repeater integer overflow in win_log malloc leading to heap overflow",
      "affected": {
        "vendors": [
          "uvnc"
        ],
        "products": [
          {
            "vendor": "uvnc",
            "product": "UltraVNC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01057,
        "percentile": 0.6115
      },
      "nvd": {
        "published": "2026-07-01T05:16:23.970",
        "lastModified": "2026-07-09T06:16:21.487",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7828",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "win_log adds a URI length to the list-node size without overflow-safe arithmetic before copying the full string into the allocation.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://uvnc.com/",
          "host": "uvnc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/ultravnc/UltraVNC",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.securin.io/zero-days/cve-2026-7828-integer-overflow-win-log-malloc-ultravnc-repeater",
          "host": "www.securin.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 900,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7829",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T03:40:57.359Z",
      "date_published": "2026-07-01T03:33:22.888Z",
      "date_updated": "2026-07-09T04:35:47.621Z",
      "publisher": "securin",
      "title": "UltraVNC repeater authenticated out-of-bounds write in rule parser via oversized token",
      "affected": {
        "vendors": [
          "uvnc"
        ],
        "products": [
          {
            "vendor": "uvnc",
            "product": "UltraVNC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00571,
        "percentile": 0.44032
      },
      "nvd": {
        "published": "2026-07-01T05:16:24.087",
        "lastModified": "2026-07-09T06:16:21.617",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7829",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The rule parser writes a terminator at the unbounded token length after copying into fixed-size stack arrays.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://uvnc.com/",
          "host": "uvnc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/ultravnc/UltraVNC",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.securin.io/zero-days/cve-2026-7829-post-auth-oob-nul-write-repeater-rule-parser-ultravnc",
          "host": "www.securin.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 777,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7830",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T03:40:59.002Z",
      "date_published": "2026-07-01T03:33:24.106Z",
      "date_updated": "2026-07-09T04:35:51.099Z",
      "publisher": "securin",
      "title": "UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential interception",
      "affected": {
        "vendors": [
          "uvnc"
        ],
        "products": [
          {
            "vendor": "uvnc",
            "product": "UltraVNC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-326",
          "name": "Inadequate Encryption Strength",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12558
      },
      "nvd": {
        "published": "2026-07-01T05:16:24.210",
        "lastModified": "2026-07-09T06:16:21.760",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7830",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "UltraVNC combines a breakable 64-bit Diffie-Hellman group with a time-seeded low-state PRNG, allowing an observer to recover the session key and credentials.",
        "basis": [
          "CNA",
          "CWE-326",
          "CWE-338"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://uvnc.com/",
          "host": "uvnc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/ultravnc/UltraVNC",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.securin.io/zero-days/cve-2026-7830-31-bit-dh-weak-rng-ms-logon-credential-interception-ultravnc",
          "host": "www.securin.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 983,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7831",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T04:03:22.622Z",
      "date_published": "2026-07-01T03:33:25.314Z",
      "date_updated": "2026-07-09T04:35:54.891Z",
      "publisher": "securin",
      "title": "UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing",
      "affected": {
        "vendors": [
          "uvnc"
        ],
        "products": [
          {
            "vendor": "uvnc",
            "product": "UltraVNC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-193",
          "name": "Off-by-one Error",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0.09999999999999964,
      "epss": {
        "score": 0.00525,
        "percentile": 0.41588
      },
      "nvd": {
        "published": "2026-07-01T05:16:24.380",
        "lastModified": "2026-07-09T06:16:21.900",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7831",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ReadString writes a terminating null at index 2024 of a 2024-byte stack array when the server advertises a desktop-name length of exactly 2024.",
        "basis": [
          "CNA",
          "CWE-193",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://uvnc.com/",
          "host": "uvnc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/ultravnc/UltraVNC",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.securin.io/zero-days/cve-2026-7831-off-by-one-stack-overflow-viewer-namelength-ultravnc",
          "host": "www.securin.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 817,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7838",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T07:30:55.831Z",
      "date_published": "2026-07-01T03:33:26.501Z",
      "date_updated": "2026-07-09T04:35:58.564Z",
      "publisher": "securin",
      "title": "UltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason length",
      "affected": {
        "vendors": [
          "uvnc"
        ],
        "products": [
          {
            "vendor": "uvnc",
            "product": "UltraVNC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.01403,
        "percentile": 0.69904
      },
      "nvd": {
        "published": "2026-07-01T05:16:24.540",
        "lastModified": "2026-07-09T06:16:22.033",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7838",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Adding one to a 32-bit reason length wraps to zero, allocating a small heap buffer before the original four-gigabyte length is copied into it.",
        "basis": [
          "CNA",
          "CWE-190",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://uvnc.com/",
          "host": "uvnc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/ultravnc/UltraVNC",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.securin.io/zero-days/cve-2026-7838-heap-overflow-viewer-reasonlen-integer-overflow-ultravnc",
          "host": "www.securin.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1050,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7839",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T07:30:58.064Z",
      "date_published": "2026-07-01T03:33:27.724Z",
      "date_updated": "2026-07-09T04:35:44.027Z",
      "publisher": "securin",
      "title": "UltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin access",
      "affected": {
        "vendors": [
          "uvnc"
        ],
        "products": [
          {
            "vendor": "uvnc",
            "product": "UltraVNC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00425,
        "percentile": 0.35034
      },
      "nvd": {
        "published": "2026-07-01T05:16:24.680",
        "lastModified": "2026-07-09T06:16:22.213",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7839",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "UltraVNC creates the web administration account with the hardcoded password adminadmi2 on first run.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://uvnc.com/",
          "host": "uvnc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/ultravnc/UltraVNC",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.securin.io/zero-days/cve-2026-7839-hardcoded-default-admin-password-adminadmi2-ultravnc-repeater",
          "host": "www.securin.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 699,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7840",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T07:30:59.460Z",
      "date_published": "2026-07-01T03:33:28.957Z",
      "date_updated": "2026-07-09T04:36:16.157Z",
      "publisher": "securin",
      "title": "UltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE)",
      "affected": {
        "vendors": [
          "uvnc"
        ],
        "products": [
          {
            "vendor": "uvnc",
            "product": "UltraVNC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.01579,
        "percentile": 0.73077
      },
      "nvd": {
        "published": "2026-07-01T05:16:24.820",
        "lastModified": "2026-07-09T06:16:22.340",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7840",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HTTP error and reply functions copy a request URI of up to about 150 KB through sprintf into a fixed 1000-byte global buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://uvnc.com/",
          "host": "uvnc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/ultravnc/UltraVNC",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.securin.io/zero-days/cve-2026-7840-pre-auth-global-buffer-overflow-repeater-http-admin-ultravnc",
          "host": "www.securin.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 831,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-7849",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:57:27.620Z",
      "date_published": "2026-07-30T06:54:03.542Z",
      "date_updated": "2026-07-30T14:06:42.780Z",
      "publisher": "CERTVDE",
      "title": "Command Injection in SCM (idledisconnect parameter)",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34532
      },
      "nvd": {
        "published": "2026-07-30T07:16:59.443",
        "lastModified": "2026-07-30T15:16:37.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7849",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CHARX SEC-3150 passes attacker-controlled argument or command text into an operating-system command boundary without neutralizing the command grammar.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 184,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-7868",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T14:00:11.372Z",
      "date_published": "2026-07-28T15:59:21.082Z",
      "date_updated": "2026-07-28T17:36:01.738Z",
      "publisher": "ibm",
      "title": "This Power System update is being released to address incorrect authorization",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "OPENBMC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07128
      },
      "nvd": {
        "published": "2026-07-28T16:20:21.813",
        "lastModified": "2026-07-28T18:17:24.130",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-7868",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenBMC lets a ReadOnly user assign administrator privileges to the same account without enforcing the required role-management authority.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280641",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 163,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-7872",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T14:17:00.630Z",
      "date_published": "2026-07-17T19:15:11.349Z",
      "date_updated": "2026-07-20T13:29:18.849Z",
      "publisher": "ibm",
      "title": "Path Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication Bypass",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00363,
        "percentile": 0.28964
      },
      "nvd": {
        "published": "2026-07-17T20:17:30.377",
        "lastModified": "2026-07-20T17:59:05.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-7872",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Langflow OSS resolves attacker-controlled path components without confirming that the final path remains beneath the intended root.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278934",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8056",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T20:34:29.582Z",
      "date_published": "2026-07-17T19:13:12.736Z",
      "date_updated": "2026-07-23T03:56:09.100Z",
      "publisher": "ibm",
      "title": "Parameter Injection Vulnerability in API Graph Execution Engine",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21698
      },
      "nvd": {
        "published": "2026-07-17T20:17:30.500",
        "lastModified": "2026-07-23T05:16:38.973",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8056",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The apply_tweaks filter accepts runtime component-parameter overrides that reach executable configuration without an adequate trust boundary.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278933",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8058",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T20:45:47.792Z",
      "date_published": "2026-07-28T15:56:27.745Z",
      "date_updated": "2026-07-28T19:31:28.603Z",
      "publisher": "ibm",
      "title": "This Power System update is being released to address a sensitive information disclosure",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "OPENBMC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00358,
        "percentile": 0.28484
      },
      "nvd": {
        "published": "2026-07-28T16:20:21.987",
        "lastModified": "2026-07-28T20:17:29.070",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8058",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OPENBMC writes a password supplied with a resource-dump request into the administrator-readable audit log.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280642",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 212,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-8075",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T10:57:31.807Z",
      "date_published": "2026-07-17T10:05:06.211Z",
      "date_updated": "2026-07-17T12:53:59.567Z",
      "publisher": "Mattermost",
      "title": "Posting a malicious markdown image crashes the Mattermost Desktop App",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15184
      },
      "nvd": {
        "published": "2026-07-17T11:17:15.180",
        "lastModified": "2026-07-30T14:44:35.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8075",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Mattermost Desktop dereferences a missing headers value when rendering an attacker-controlled channel post.",
        "basis": [
          "CNA",
          "CWE-754"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-8079",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T11:23:34.754Z",
      "date_published": "2026-07-02T14:03:36.018Z",
      "date_updated": "2026-07-03T03:56:03.186Z",
      "publisher": "ProgressSoftware",
      "title": "Unintended limited set of actions with elevated privileges may be performed during PDF generation in Progress Flowmon",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Flowmon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00182,
        "percentile": 0.0796
      },
      "nvd": {
        "published": "2026-07-02T15:17:11.803",
        "lastModified": "2026-07-06T18:43:52.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8079",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Flowmon PDF generation accepts a low-privileged request and performs the requested operation with another user's privileges.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.progress.com/s/article/Flowmon-CVE-2026-8079",
          "host": "community.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 374,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-8082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T12:12:02.867Z",
      "date_published": "2026-07-21T06:00:02.300Z",
      "date_updated": "2026-07-21T13:38:15.559Z",
      "publisher": "WPScan",
      "title": "Bpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "bpost-shipping-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17918
      },
      "nvd": {
        "published": "2026-07-21T07:16:34.320",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8082",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this bpost-shipping-platform WordPress plugin before 3.2.3.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/21b31199-01d5-4c43-8699-eca4bc7e8389/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T12:29:42.256Z",
      "date_published": "2026-07-14T12:40:43.335Z",
      "date_updated": "2026-07-14T13:51:03.253Z",
      "publisher": "Rockwell",
      "title": "Rockwell Automation Arena® - Memory Corruption Vulnerability",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "Arena® Simulation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07792
      },
      "nvd": {
        "published": "2026-07-14T13:19:10.587",
        "lastModified": "2026-07-15T13:13:47.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8085",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected parser writes beyond its destination buffer because attacker-controlled size or index data is not bounded.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1784.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T02:45:28.857Z",
      "date_published": "2026-07-02T07:32:58.308Z",
      "date_updated": "2026-07-02T12:28:31.554Z",
      "publisher": "@huntr_ai",
      "title": "Authorization Bypass in mlflow/mlflow",
      "affected": {
        "vendors": [
          "mlflow"
        ],
        "products": [
          {
            "vendor": "mlflow",
            "product": "mlflow/mlflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security@huntr.dev",
          "type": "Secondary",
          "version": "3.0",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00376,
        "percentile": 0.30324
      },
      "nvd": {
        "published": "2026-07-02T09:16:19.100",
        "lastModified": "2026-07-06T16:46:06.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8147",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MLflow's request hook registers no experiment authorization validator for trace endpoints, so any authenticated user can operate on traces outside their experiments.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://huntr.com/bounties/b00c3ddd-373e-492f-9bf0-41a28bb21ed5",
          "host": "huntr.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/mlflow/mlflow/commit/f9b1eb510478570609ef451984a255775aa4b937",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8152",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T08:12:13.325Z",
      "date_published": "2026-07-22T12:21:28.977Z",
      "date_updated": "2026-07-22T18:55:07.732Z",
      "publisher": "NCSC.ch",
      "title": "Unblu Spark Open Redirect leading to DOM-Based XSS",
      "affected": {
        "vendors": [
          "Unblu inc."
        ],
        "products": [
          {
            "vendor": "Unblu inc.",
            "product": "Unblu Spark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 2.3000000000000007,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15696
      },
      "nvd": {
        "published": "2026-07-22T13:16:38.423",
        "lastModified": "2026-07-22T19:17:14.617",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8152",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled redirect value is consumed by same-origin client code as executable DOM content when siteEmbeddedSetup is enabled.",
        "basis": [
          "CNA",
          "CWE-601",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.unblu.com/latest/security-bulletins/#UBL-2026-001",
          "host": "docs.unblu.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 595,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-8155",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T08:34:41.516Z",
      "date_published": "2026-07-31T06:00:10.175Z",
      "date_updated": "2026-07-31T17:46:16.024Z",
      "publisher": "WPScan",
      "title": "BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "BuddyPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03608
      },
      "nvd": {
        "published": "2026-07-31T07:16:28.593",
        "lastModified": "2026-07-31T18:17:37.470",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8155",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BuddyPress resolves a caller-controlled object identifier without binding the selected object to the caller's authorized scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/b7dd9cbf-b46b-49ee-84a0-6b054676fccb/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8164",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T11:29:48.099Z",
      "date_published": "2026-07-28T14:01:02.028Z",
      "date_updated": "2026-07-28T14:45:32.059Z",
      "publisher": "TR-CERT",
      "title": "Search Order Hijacking in ArkSigner's ArkSigner Desktop Client",
      "affected": {
        "vendors": [
          "ArkSigner Software and Hardware Industry and Trade Inc."
        ],
        "products": [
          {
            "vendor": "ArkSigner Software and Hardware Industry and Trade Inc.",
            "product": "ArkSigner Desktop Client"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01289
      },
      "nvd": {
        "published": "2026-07-28T15:17:51.633",
        "lastModified": "2026-07-28T16:20:22.133",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8164",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ArkSigner resolves a dependency through an attacker-influenceable search-order location.",
        "basis": [
          "CNA",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0665",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8167",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T12:26:28.236Z",
      "date_published": "2026-07-28T08:22:21.237Z",
      "date_updated": "2026-07-28T12:43:39.129Z",
      "publisher": "TR-CERT",
      "title": "Reflected XSS in theWP's News Theme V8",
      "affected": {
        "vendors": [
          "THEWP Digital Solutions"
        ],
        "products": [
          {
            "vendor": "THEWP Digital Solutions",
            "product": "News Theme V8"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04575
      },
      "nvd": {
        "published": "2026-07-28T09:16:42.690",
        "lastModified": "2026-07-28T16:10:09.517",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8167",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content is rendered without the browser-context separation required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0663",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8169",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T12:59:08.619Z",
      "date_published": "2026-07-20T17:33:05.699Z",
      "date_updated": "2026-07-20T19:20:47.552Z",
      "publisher": "ExtremeNetworks",
      "title": "ExtremeXOS Debug-Mode Privilege Escalation via Weak PRNG",
      "affected": {
        "vendors": [
          "Extreme Networks"
        ],
        "products": [
          {
            "vendor": "Extreme Networks",
            "product": "Switch Engine (EXOS)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:1c053176-eef3-4d6a-ae0b-24728c86587b",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20048
      },
      "nvd": {
        "published": "2026-07-20T18:16:56.420",
        "lastModified": "2026-07-21T20:25:45.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8169",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The debug-mode challenge uses a weak pseudorandom generator, making the expected response predictable under stated conditions.",
        "basis": [
          "CNA record",
          "CWE-338"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.extremenetworks.com/support/policies/product-security",
          "host": "www.extremenetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 914,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-8170",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T12:59:11.022Z",
      "date_published": "2026-07-20T17:34:10.950Z",
      "date_updated": "2026-07-20T19:21:08.881Z",
      "publisher": "ExtremeNetworks",
      "title": "ExtremeXOS Privilege Escalation via Symlink Following in File Utilities",
      "affected": {
        "vendors": [
          "Extreme Networks"
        ],
        "products": [
          {
            "vendor": "Extreme Networks",
            "product": "Switch Engine (EXOS)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:1c053176-eef3-4d6a-ae0b-24728c86587b",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00425,
        "percentile": 0.34995
      },
      "nvd": {
        "published": "2026-07-20T18:16:56.570",
        "lastModified": "2026-07-21T20:25:45.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8170",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Switch Engine (EXOS) follows an attacker-influenced symbolic link into a filesystem object outside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.extremenetworks.com/support/policies/product-security",
          "host": "www.extremenetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 864,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-8247",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-10T12:48:43.918Z",
      "date_published": "2026-07-02T23:07:16.148Z",
      "date_updated": "2026-07-07T03:56:33.916Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox admd Out of Bounds Write Vulnerability",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10191
      },
      "nvd": {
        "published": "2026-07-03T00:16:52.773",
        "lastModified": "2026-07-07T05:16:55.517",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8247",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Fireware writes beyond an input buffer when an unauthenticated peer on the local segment sends crafted data.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00026",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-8284",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T06:58:41.546Z",
      "date_published": "2026-07-21T12:11:57.380Z",
      "date_updated": "2026-07-28T11:31:51.228Z",
      "publisher": "TR-CERT",
      "title": "Open Redirect in Universal Sotware's FlexCity",
      "affected": {
        "vendors": [
          "Universal Software Inc."
        ],
        "products": [
          {
            "vendor": "Universal Software Inc.",
            "product": "FlexCity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03905
      },
      "nvd": {
        "published": "2026-07-21T13:17:19.350",
        "lastModified": "2026-07-28T12:16:37.157",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8284",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The redirect path in FlexCity accepts an attacker-controlled destination without constraining it to an approved origin.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0593",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8285",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T06:58:58.943Z",
      "date_published": "2026-07-21T12:26:14.963Z",
      "date_updated": "2026-07-28T11:34:01.783Z",
      "publisher": "TR-CERT",
      "title": "OTP Bypass in Universal Sotware's FlexCity",
      "affected": {
        "vendors": [
          "Universal Software Inc."
        ],
        "products": [
          {
            "vendor": "Universal Software Inc.",
            "product": "FlexCity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14732
      },
      "nvd": {
        "published": "2026-07-21T13:17:19.473",
        "lastModified": "2026-07-28T12:16:37.267",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8285",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The authentication flow does not enforce an effective attempt limit, allowing repeated guesses against the protected secret or code.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0593",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8286",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T07:06:37.906Z",
      "date_published": "2026-07-03T06:14:17.541Z",
      "date_updated": "2026-07-06T17:33:50.416Z",
      "publisher": "curl",
      "title": "wrong STARTTLS connection reuse",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 113,
        "versionRangeCount": 113,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00309,
        "percentile": 0.23301
      },
      "nvd": {
        "published": "2026-07-03T07:16:24.453",
        "lastModified": "2026-07-07T19:42:11.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8286",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A STARTTLS transfer can reuse a live connection whose TLS configuration differs from the new request, preserving trust established under the wrong settings.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-8286.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8286.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3718195",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 113
      }
    },
    {
      "cve_id": "CVE-2026-8287",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T07:38:14.112Z",
      "date_published": "2026-07-23T13:48:13.049Z",
      "date_updated": "2026-07-23T14:43:14.094Z",
      "publisher": "TR-CERT",
      "title": "Unrestricted File Upload in BizimHesap Information Systems' Online Pre-Accounting Software",
      "affected": {
        "vendors": [
          "BizimHesap Information Systems Industry and Trade Inc."
        ],
        "products": [
          {
            "vendor": "BizimHesap Information Systems Industry and Trade Inc.",
            "product": "Online Pre-Accounting Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11624
      },
      "nvd": {
        "published": "2026-07-23T14:18:09.863",
        "lastModified": "2026-07-23T15:18:17.273",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8287",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Online Pre-Accounting Software path allocates attacker-driven resources without an effective bound or throttle.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0620",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8297",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T10:29:13.254Z",
      "date_published": "2026-07-17T15:50:01.404Z",
      "date_updated": "2026-07-17T16:38:29.611Z",
      "publisher": "TR-CERT",
      "title": "SQLi in GIS Informatics' GisLab Laboratory Management System",
      "affected": {
        "vendors": [
          "Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc."
        ],
        "products": [
          {
            "vendor": "Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.",
            "product": "GisLab Laboratory Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17659
      },
      "nvd": {
        "published": "2026-07-17T17:17:17.860",
        "lastModified": "2026-07-17T17:54:18.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8297",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unauthenticated input reaches an SQL command without parameterization in GisLab Laboratory Management System.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0573",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 327,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8306",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T12:00:31.251Z",
      "date_published": "2026-07-07T07:02:09.546Z",
      "date_updated": "2026-07-07T13:27:35.094Z",
      "publisher": "TR-CERT",
      "title": "Stored XSS in Armiya Technologies' Access Control System",
      "affected": {
        "vendors": [
          "Armiya Information Technologies Ltd. Co."
        ],
        "products": [
          {
            "vendor": "Armiya Information Technologies Ltd. Co.",
            "product": "Access Control System (GKS)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04572
      },
      "nvd": {
        "published": "2026-07-07T08:16:25.910",
        "lastModified": "2026-07-07T14:16:34.773",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8306",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Access Control System (GKS) rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0502",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8307",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T12:01:38.201Z",
      "date_published": "2026-07-08T12:14:08.005Z",
      "date_updated": "2026-07-09T08:54:07.196Z",
      "publisher": "TR-CERT",
      "title": "SQLi in Webbeyaz's Mediküm Web",
      "affected": {
        "vendors": [
          "Webbeyaz Web Design"
        ],
        "products": [
          {
            "vendor": "Webbeyaz Web Design",
            "product": "Mediküm Web"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18313
      },
      "nvd": {
        "published": "2026-07-08T13:16:57.903",
        "lastModified": "2026-07-09T10:16:27.537",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8307",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mediküm Web incorporates attacker-controlled input into an SQL statement without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0518",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 291,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8308",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T12:12:23.445Z",
      "date_published": "2026-07-24T14:08:21.688Z",
      "date_updated": "2026-07-24T14:53:01.526Z",
      "publisher": "TR-CERT",
      "title": "Reflected XSS Polen Media's Website Template",
      "affected": {
        "vendors": [
          "Polen Media Software and Information Services"
        ],
        "products": [
          {
            "vendor": "Polen Media Software and Information Services",
            "product": "Website Template"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04572
      },
      "nvd": {
        "published": "2026-07-24T15:19:08.187",
        "lastModified": "2026-07-24T20:47:58.773",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8308",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says attacker-controlled input reaches executable syntax in Website Template, while the input field and interpreter sink are not public.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0635",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T12:20:08.196Z",
      "date_published": "2026-07-07T07:08:28.132Z",
      "date_updated": "2026-07-07T13:28:47.344Z",
      "publisher": "TR-CERT",
      "title": "Reflected XSS in Armiya Technologies' Access Control System",
      "affected": {
        "vendors": [
          "Armiya Information Technologies Ltd. Co."
        ],
        "products": [
          {
            "vendor": "Armiya Information Technologies Ltd. Co.",
            "product": "Access Control System (GKS)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03233
      },
      "nvd": {
        "published": "2026-07-07T08:16:26.023",
        "lastModified": "2026-07-07T14:16:34.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8309",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Access Control System reflects attacker-controlled input into HTML without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0502",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8310",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T12:28:40.105Z",
      "date_published": "2026-07-08T12:19:09.073Z",
      "date_updated": "2026-07-09T08:54:45.184Z",
      "publisher": "TR-CERT",
      "title": "Reflected XSS in Webbeyaz's Mediküm Web",
      "affected": {
        "vendors": [
          "Webbeyaz Web Design"
        ],
        "products": [
          {
            "vendor": "Webbeyaz Web Design",
            "product": "Mediküm Web"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04579
      },
      "nvd": {
        "published": "2026-07-08T13:16:58.017",
        "lastModified": "2026-07-09T10:16:28.233",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8310",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0518",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 291,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8312",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T12:39:37.355Z",
      "date_published": "2026-07-14T12:43:09.839Z",
      "date_updated": "2026-07-14T13:27:53.655Z",
      "publisher": "Rockwell",
      "title": "Rockwell Automation Arena® - Memory Corruption Vulnerability",
      "affected": {
        "vendors": [
          "Rockwell Auotmation"
        ],
        "products": [
          {
            "vendor": "Rockwell Auotmation",
            "product": "Arena® Simulation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07792
      },
      "nvd": {
        "published": "2026-07-14T13:19:10.727",
        "lastModified": "2026-07-15T13:13:24.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8312",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Arena® Simulation can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1784.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8313",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T12:39:51.327Z",
      "date_published": "2026-07-14T12:45:35.910Z",
      "date_updated": "2026-07-14T13:22:29.505Z",
      "publisher": "Rockwell",
      "title": "Rockwell Automation Arena® - Memory Corruption Vulnerability",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "Arena® Simulation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07793
      },
      "nvd": {
        "published": "2026-07-14T13:19:10.863",
        "lastModified": "2026-07-15T13:12:55.757",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8313",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled input reaches a write whose destination boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1784.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8314",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T12:40:00.178Z",
      "date_published": "2026-07-14T12:47:43.969Z",
      "date_updated": "2026-07-14T13:21:44.500Z",
      "publisher": "Rockwell",
      "title": "Rockwell Automation Arena® - Memory Corruption Vulnerability",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "Arena® Simulation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07792
      },
      "nvd": {
        "published": "2026-07-14T13:19:11.010",
        "lastModified": "2026-07-15T13:12:29.590",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8314",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Arena® Simulation writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1784.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8315",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T12:45:55.574Z",
      "date_published": "2026-07-08T12:21:59.106Z",
      "date_updated": "2026-07-09T08:55:25.835Z",
      "publisher": "TR-CERT",
      "title": "Stored XSS in Webbeyaz's Mediküm Web",
      "affected": {
        "vendors": [
          "Webbeyaz Web Design"
        ],
        "products": [
          {
            "vendor": "Webbeyaz Web Design",
            "product": "Mediküm Web"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03231
      },
      "nvd": {
        "published": "2026-07-08T13:16:58.133",
        "lastModified": "2026-07-09T10:16:28.903",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8315",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Medikum Web stores attacker input and later emits it into HTML without the output neutralization needed to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0518",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8338",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T16:05:30.569Z",
      "date_published": "2026-07-29T16:38:40.944Z",
      "date_updated": "2026-07-29T18:06:23.447Z",
      "publisher": "BlackDuck",
      "title": "Authentication and Authorization Bypass in Coverity Connect",
      "affected": {
        "vendors": [
          "Black Duck"
        ],
        "products": [
          {
            "vendor": "Black Duck",
            "product": "Coverity Connect"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@synopsys.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22266
      },
      "nvd": {
        "published": "2026-07-29T17:16:54.177",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8338",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Coverity Connect accepts a specially crafted request through an alternate API path without applying the required Spring authentication and authorization controls.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.blackduck.com/s/article/Black-Duck-Product-Security-Advisory-CVE-2026-8338-Authentication-and-Authorization-Bypass",
          "host": "community.blackduck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8339",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T16:05:31.988Z",
      "date_published": "2026-07-29T16:31:23.876Z",
      "date_updated": "2026-07-29T17:54:48.048Z",
      "publisher": "BlackDuck",
      "title": "SQL Injection in Coverity Connect SOAP API",
      "affected": {
        "vendors": [
          "Black Duck"
        ],
        "products": [
          {
            "vendor": "Black Duck",
            "product": "Coverity Connect"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@synopsys.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10484
      },
      "nvd": {
        "published": "2026-07-29T17:16:54.347",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8339",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Coverity SOAP API incorporates an authenticated caller's payload into a SQL command without safe parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.blackduck.com/s/article/Black-Duck-Product-Security-Advisory-CVE-2026-8339-SQL-Injection-Vulnerability-in-Coverity-Connect-SOAP-API",
          "host": "community.blackduck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 286,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T16:41:26.786Z",
      "date_published": "2026-07-03T06:50:10.581Z",
      "date_updated": "2026-07-06T16:25:21.787Z",
      "publisher": "Wordfence",
      "title": "RTMKit <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' Parameter",
      "affected": {
        "vendors": [
          "rometheme"
        ],
        "products": [
          {
            "vendor": "rometheme",
            "product": "RTMKit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13659
      },
      "nvd": {
        "published": "2026-07-03T08:16:25.107",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8351",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The RTMKit page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3e0da463-2ba0-43ca-927c-55c12643ef32?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rometheme-for-elementor/trunk/Inc/Elements/AdvancedHeading.php#L960",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rometheme-for-elementor/tags/2.0.7/Inc/Elements/AdvancedHeading.php#L960",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rometheme-for-elementor/trunk/Inc/Elements/AdvancedHeading.php#L133",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rometheme-for-elementor/tags/2.0.7/Inc/Elements/AdvancedHeading.php#L133",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rometheme-for-elementor/tags/2.0.4/Inc/Elements/AdvancedHeading.php#L960",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rometheme-for-elementor/tags/2.0.4/Inc/Elements/AdvancedHeading.php#L133",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3568335/rometheme-for-elementor/trunk/Inc/Elements/AdvancedHeading.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Frometheme-for-elementor/tags/2.0.7&new_path=%2Frometheme-for-elementor/tags/2.0.8",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 574,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T08:45:41.295Z",
      "date_published": "2026-07-07T07:25:06.910Z",
      "date_updated": "2026-07-07T13:29:16.531Z",
      "publisher": "TR-CERT",
      "title": "Improper Authorization in Armiya Technologies' Access Control System",
      "affected": {
        "vendors": [
          "Armiya Information Technologies Ltd. Co."
        ],
        "products": [
          {
            "vendor": "Armiya Information Technologies Ltd. Co.",
            "product": "Access Control System (GKS)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09782
      },
      "nvd": {
        "published": "2026-07-07T08:16:26.127",
        "lastModified": "2026-07-07T14:16:34.963",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8377",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The access-control system exposes common-resource data without the required authorization, but the exact endpoint and check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0502",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8384",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T10:01:35.472Z",
      "date_published": "2026-07-14T08:56:17.525Z",
      "date_updated": "2026-07-14T12:18:29.831Z",
      "publisher": "eclipse",
      "title": "In Eclipse Jetty, an HTTP URI of this form: /public;/.",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Jetty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-647",
          "name": "Use of Non-Canonical URL Paths for Authorization Decisions",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13711
      },
      "nvd": {
        "published": "2026-07-14T09:16:42.050",
        "lastModified": "2026-07-14T18:39:51.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8384",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Jetty leaves a semicolon-bearing dot-segment path unresolved, so an application can authorize a different path string from the canonical target.",
        "basis": [
          "CNA",
          "CWE-647"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/108",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-8387",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T11:48:49.154Z",
      "date_published": "2026-07-01T12:26:55.616Z",
      "date_updated": "2026-07-01T13:36:02.782Z",
      "publisher": "@huntr_ai",
      "title": "Relative Path Traversal in allegroai/clearml",
      "affected": {
        "vendors": [
          "allegroai"
        ],
        "products": [
          {
            "vendor": "allegroai",
            "product": "allegroai/clearml"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@huntr.dev",
          "type": "Secondary",
          "version": "3.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00357,
        "percentile": 0.28444
      },
      "nvd": {
        "published": "2026-07-01T13:17:54.240",
        "lastModified": "2026-07-02T17:55:37.087",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8387",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "allegroai/clearml allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://huntr.com/bounties/0f69bb0b-728e-411c-8676-8f2dfaf238db",
          "host": "huntr.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/allegroai/clearml/commit/4fd611c564256e4f294a6db133705120f203f476",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 637,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T12:49:44.905Z",
      "date_published": "2026-07-17T12:20:05.038Z",
      "date_updated": "2026-07-17T12:55:54.104Z",
      "publisher": "TR-CERT",
      "title": "XXE in Netcad's NetGIS",
      "affected": {
        "vendors": [
          "Netcad Software Inc."
        ],
        "products": [
          {
            "vendor": "Netcad Software Inc.",
            "product": "NetGIS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17594
      },
      "nvd": {
        "published": "2026-07-17T13:19:01.827",
        "lastModified": "2026-07-17T15:00:17.017",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8396",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NetGIS permits XML input to resolve an external entity and link serialized data to an attacker-selected external resource.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0570",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8441",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T19:15:15.187Z",
      "date_published": "2026-07-02T09:32:03.304Z",
      "date_updated": "2026-07-02T12:36:44.057Z",
      "publisher": "Wordfence",
      "title": "WP Review Slider Pro <= 12.7.2 - Unauthenticated SQL Injection via 'notinstring' Parameter",
      "affected": {
        "vendors": [
          "https://wpreviewslider.com/"
        ],
        "products": [
          {
            "vendor": "https://wpreviewslider.com/",
            "product": "WP Review Slider Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19423
      },
      "nvd": {
        "published": "2026-07-02T10:16:28.617",
        "lastModified": "2026-07-02T13:58:56.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8441",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WP Review Slider Pro concatenates notinstring into an unquoted numeric SQL list without prepare() or integer conversion.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/396ba24f-e0f7-4374-a9ce-d9abddb87b39?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://wpreviewslider.userecho.com/knowledge-bases/2/articles/88-change-log",
          "host": "wpreviewslider.userecho.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1036,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T08:33:36.632Z",
      "date_published": "2026-07-03T06:14:42.258Z",
      "date_updated": "2026-07-06T17:32:06.018Z",
      "publisher": "curl",
      "title": "wrong reuse for different services",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 98,
        "versionRangeCount": 98,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-488",
          "name": "Exposure of Data Element to Wrong Session",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23893
      },
      "nvd": {
        "published": "2026-07-03T07:16:24.630",
        "lastModified": "2026-07-07T23:12:17.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8458",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HTTP connection pool reuses a Negotiate-authenticated connection without including the service identity in the pool key.",
        "basis": [
          "CNA",
          "CWE-488"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-8458.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8458.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3721183",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 98
      }
    },
    {
      "cve_id": "CVE-2026-8472",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T13:04:47.771Z",
      "date_published": "2026-07-08T20:46:28.855Z",
      "date_updated": "2026-07-09T14:14:43.271Z",
      "publisher": "GitLab",
      "title": "Missing Authorization in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15534
      },
      "nvd": {
        "published": "2026-07-08T21:16:55.327",
        "lastModified": "2026-07-10T13:02:22.957",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8472",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GitLab returns private-project work-item metadata to a minimally privileged user without the required project authorization check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/599987",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3615282",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 324,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-8476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T13:17:17.664Z",
      "date_published": "2026-07-17T19:11:04.751Z",
      "date_updated": "2026-07-23T03:56:08.380Z",
      "publisher": "ibm",
      "title": "Disk Cache Deserialization Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00493,
        "percentile": 0.39691
      },
      "nvd": {
        "published": "2026-07-17T20:17:30.623",
        "lastModified": "2026-07-23T05:16:39.103",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8476",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Langflow AsyncDiskCache passes attacker-influenced cache bytes to Python pickle.loads, allowing serialized opcodes to execute.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278922",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 607,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8480",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T13:48:21.232Z",
      "date_published": "2026-07-01T14:52:12.815Z",
      "date_updated": "2026-07-01T15:45:32.124Z",
      "publisher": "airbus",
      "title": "Connection possible to the Administration portal with a revoked certificate",
      "affected": {
        "vendors": [
          "Stormshield"
        ],
        "products": [
          {
            "vendor": "Stormshield",
            "product": "Stormshield Network Security"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cert@airbus.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00087,
        "percentile": 0.00439
      },
      "nvd": {
        "published": "2026-07-01T16:16:53.730",
        "lastModified": "2026-07-01T19:59:44.537",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8480",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Stormshield accepts a client certificate after its signing intermediate has been revoked, allowing the revoked credential to authenticate to the administration portal.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://advisories.stormshield.eu/2026-002/",
          "host": "advisories.stormshield.eu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 334,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-8481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T13:52:34.784Z",
      "date_published": "2026-07-17T19:10:39.229Z",
      "date_updated": "2026-07-23T03:56:07.676Z",
      "publisher": "ibm",
      "title": "Remote Code Execution via Code Validation Endpoint",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00458,
        "percentile": 0.37467
      },
      "nvd": {
        "published": "2026-07-17T20:17:30.747",
        "lastModified": "2026-07-23T05:16:39.223",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8481",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system commands with the full privileges of the Langflow server process.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278923",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 459,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T14:04:22.661Z",
      "date_published": "2026-07-02T08:42:56.777Z",
      "date_updated": "2026-07-02T12:20:17.839Z",
      "publisher": "airbus",
      "title": "Information leak in NSRPC client history",
      "affected": {
        "vendors": [
          "Stormshield"
        ],
        "products": [
          {
            "vendor": "Stormshield",
            "product": "Stormshield Network Security"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:cert@airbus.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04215
      },
      "nvd": {
        "published": "2026-07-02T10:16:28.737",
        "lastModified": "2026-07-02T17:42:54.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8482",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://advisories.stormshield.eu/2025-007/",
          "host": "advisories.stormshield.eu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 405,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-8489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T14:58:02.236Z",
      "date_published": "2026-07-03T04:30:16.942Z",
      "date_updated": "2026-07-06T15:32:47.818Z",
      "publisher": "Wordfence",
      "title": "Ultimate Member <= 2.11.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field",
      "affected": {
        "vendors": [
          "ultimatemember"
        ],
        "products": [
          {
            "vendor": "ultimatemember",
            "product": "Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.1441
      },
      "nvd": {
        "published": "2026-07-03T06:16:22.670",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8489",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/229a4e61-571c-44c6-9972-4dfc743afffe?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.11.4/includes/core/um-filters-fields.php#L271",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.11.4/includes/core/class-profile.php#L479",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.11.4/includes/core/class-fields.php#L4577",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.11.4/includes/core/class-form.php#L854",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.11.4/includes/core/um-actions-form.php#L628",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.11.2/includes/core/um-filters-fields.php#L271",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.11.2/includes/core/class-profile.php#L479",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.11.2/includes/core/class-fields.php#L4577",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.11.2/includes/core/class-form.php#L854",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.11.2/includes/core/um-actions-form.php#L628",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 11,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8497",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T18:28:12.873Z",
      "date_published": "2026-07-29T17:24:59.168Z",
      "date_updated": "2026-07-29T18:14:01.902Z",
      "publisher": "DEVOLUTIONS",
      "title": "Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "Password Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00082,
        "percentile": 0.00277
      },
      "nvd": {
        "published": "2026-07-29T18:16:58.787",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8497",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The certificate, signature, or revocation result is accepted without validating it against the exact credential and request being authenticated.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0027/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8505",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T22:04:50.617Z",
      "date_published": "2026-07-17T19:06:00.986Z",
      "date_updated": "2026-07-23T03:56:06.902Z",
      "publisher": "ibm",
      "title": "Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0056,
        "percentile": 0.43443
      },
      "nvd": {
        "published": "2026-07-17T20:17:31.417",
        "lastModified": "2026-07-23T05:16:39.340",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8505",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Langflow disables webhook API-key validation by default and therefore lets an anonymous caller execute a known flow UUID as its owner.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278921",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 456,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8590",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T08:09:31.186Z",
      "date_published": "2026-07-14T13:49:04.755Z",
      "date_updated": "2026-07-14T15:02:35.187Z",
      "publisher": "Spotfire",
      "title": "Spotfire OAuth2 PKCE Bypass for public clients",
      "affected": {
        "vendors": [
          "Spotfire"
        ],
        "products": [
          {
            "vendor": "Spotfire",
            "product": "Spotfire Enterprise"
          },
          {
            "vendor": "Spotfire",
            "product": "Spotfire Enterprise with External Consumers"
          },
          {
            "vendor": "Spotfire",
            "product": "Spotfire on Kubernetes"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 17,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:8b479ca1-d558-42a2-87eb-a4751ba58a09",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23543
      },
      "nvd": {
        "published": "2026-07-14T15:17:10.740",
        "lastModified": "2026-07-15T21:00:31.273",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8590",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Spotfire public OAuth clients can bypass PKCE proof binding, but the public record does not disclose the accepted verifier or authorization-code condition.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-july-14-2026-spotfire-cve-2026-8590-r3641/",
          "host": "community.spotfire.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 1,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-8593",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T11:33:18.585Z",
      "date_published": "2026-07-21T07:20:35.400Z",
      "date_updated": "2026-07-21T12:16:52.202Z",
      "publisher": "Checkmk",
      "title": "Fix Business Intelligence API Pack permission",
      "affected": {
        "vendors": [
          "Checkmk GmbH"
        ],
        "products": [
          {
            "vendor": "Checkmk GmbH",
            "product": "Checkmk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@checkmk.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10967
      },
      "nvd": {
        "published": "2026-07-21T08:16:35.013",
        "lastModified": "2026-07-22T20:51:36.300",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8593",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The BI packs operation omits enforcement of its required permission.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://checkmk.com/werk/16918",
          "host": "checkmk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-8595",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T12:50:43.291Z",
      "date_published": "2026-07-10T14:59:35.891Z",
      "date_updated": "2026-07-29T13:59:56.196Z",
      "publisher": "GRAFANA",
      "title": "Stored XSS in the table panel (TableNG)",
      "affected": {
        "vendors": [
          "Grafana"
        ],
        "products": [
          {
            "vendor": "Grafana",
            "product": "Grafana OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:security@grafana.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15146
      },
      "nvd": {
        "published": "2026-07-10T16:16:39.400",
        "lastModified": "2026-07-13T20:51:42.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8595",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A dashboard field name reaches the TableNG browser output without the neutralization required to prevent stored script execution.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://grafana.com/security/security-advisories/cve-2026-8595",
          "host": "grafana.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-8609",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T16:01:42.297Z",
      "date_published": "2026-07-10T14:58:33.522Z",
      "date_updated": "2026-07-29T14:00:05.742Z",
      "publisher": "GRAFANA",
      "title": "Pre-authentication denial of service via the OAuth login route",
      "affected": {
        "vendors": [
          "Grafana"
        ],
        "products": [
          {
            "vendor": "Grafana",
            "product": "Grafana OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security@grafana.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00397,
        "percentile": 0.32526
      },
      "nvd": {
        "published": "2026-07-10T16:16:39.510",
        "lastModified": "2026-07-13T20:51:48.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8609",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unique values sent repeatedly to Grafana's OAuth login route accumulate in memory without an effective retention bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://grafana.com/security/security-advisories/cve-2026-8609",
          "host": "grafana.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-8616",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T17:37:53.682Z",
      "date_published": "2026-07-17T02:31:30.556Z",
      "date_updated": "2026-07-21T01:26:04.428Z",
      "publisher": "Wordfence",
      "title": "Fense Proxy & VPN Blocker <= 3.0.1 - Missing Authorization to Unauthenticated Plugin Option/Transient Deletion via fense_bpvt_save_settings AJAX Action",
      "affected": {
        "vendors": [
          "devozon"
        ],
        "products": [
          {
            "vendor": "devozon",
            "product": "Fense Proxy & VPN Blocker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13656
      },
      "nvd": {
        "published": "2026-07-17T04:16:51.197",
        "lastModified": "2026-07-21T02:16:23.787",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8616",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "fense_bpvt_save_settings is registered for unauthenticated AJAX and deletes settings without a capability check or nonce validation.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1208ac78-4a56-4daa-b935-d579f07f8e8e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fense-block-vpn-proxy/tags/2.9.0/includes/system/fense-bpvt-header-code.php#L32",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fense-block-vpn-proxy/tags/2.9.0/includes/system/fense-bpvt-header-code.php#L48",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fense-block-vpn-proxy/tags/3.0.2/includes/system/header-code.php?rev=3574545",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 666,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8635",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T19:17:56.124Z",
      "date_published": "2026-07-17T19:02:03.977Z",
      "date_updated": "2026-07-23T03:56:06.201Z",
      "publisher": "ibm",
      "title": "Arbitrary Code Execution in Python Interpreter Component",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22347
      },
      "nvd": {
        "published": "2026-07-17T20:17:31.527",
        "lastModified": "2026-07-23T05:16:39.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8635",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Langflow's PythonREPLComponent executes user-supplied Python without sufficient sandboxing or validation, allowing direct database permission changes and system commands.",
        "basis": [
          "CNA",
          "CWE-94",
          "IBM Security Bulletin"
        ],
        "deepDive": true,
        "notes": "https://www.ibm.com/support/pages/security-bulletin-arbitrary-code-execution-python-interpreter-component - IBM identifies PythonREPLComponent, insufficient sandboxing and validation of user-supplied Python, and direct database permission changes, but provides no public source patch in the bulletin."
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278925",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8649",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T04:28:11.755Z",
      "date_published": "2026-07-08T19:41:40.969Z",
      "date_updated": "2026-07-09T13:29:22.928Z",
      "publisher": "ProgressSoftware",
      "title": "Institution scope bypass vulnerability in custom reports",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "MOVEit Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-943",
          "name": "Improper Neutralization of Special Elements in Data Query Logic",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 3.4000000000000004,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17422
      },
      "nvd": {
        "published": "2026-07-08T20:17:00.557",
        "lastModified": "2026-07-10T19:34:37.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8649",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Custom Reports accepts special query syntax that escapes the selected institution scope, while the exact report parameter is not public.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-943"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.html",
          "host": "docs.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-8650",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T04:28:13.041Z",
      "date_published": "2026-07-08T19:47:25.636Z",
      "date_updated": "2026-07-09T13:31:57.971Z",
      "publisher": "ProgressSoftware",
      "title": "Authenticated Path Traversal allows MOVEit admins to view arbitrary system files",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "MOVEit Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 3,
      "epss": {
        "score": 0.00365,
        "percentile": 0.2918
      },
      "nvd": {
        "published": "2026-07-08T20:17:00.677",
        "lastModified": "2026-07-09T19:18:57.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8650",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MOVEit Admin Settings accepts a relative traversal path and reads a system file outside the intended directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.html",
          "host": "docs.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-8651",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T04:28:13.929Z",
      "date_published": "2026-07-08T19:50:43.060Z",
      "date_updated": "2026-07-09T13:32:24.568Z",
      "publisher": "ProgressSoftware",
      "title": "IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit Transfer",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "MOVEit Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00215,
        "percentile": 0.1194
      },
      "nvd": {
        "published": "2026-07-08T20:17:00.793",
        "lastModified": "2026-07-09T19:18:09.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8651",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MOVEit Transfer authentication path accepts a spoofable identity signal in place of the normal proof of identity.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.html",
          "host": "docs.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 184,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-8678",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T13:30:01.361Z",
      "date_published": "2026-07-11T02:31:15.950Z",
      "date_updated": "2026-07-13T16:14:36.270Z",
      "publisher": "Wordfence",
      "title": "MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Data Disclosure and Modification via wcmp_get_shipment_options and wcmp_save_shipment_options AJAX Actions",
      "affected": {
        "vendors": [
          "richardperdaan"
        ],
        "products": [
          {
            "vendor": "richardperdaan",
            "product": "MyParcel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14195
      },
      "nvd": {
        "published": "2026-07-11T04:17:26.903",
        "lastModified": "2026-07-13T17:18:15.497",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8678",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Shipment AJAX handlers accept an arbitrary order without verifying that the subscriber is authorized for that order.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1a7bdae1-b28a-4fc6-9538-944ffeb32796?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-myparcel/tags/4.25.1/includes/admin/class-wcmypa-admin.php#L872",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-myparcel/tags/4.25.1/includes/admin/class-wcmypa-admin.php#L653",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-myparcel/tags/4.25.1/includes/admin/class-wcmypa-admin.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-myparcel/tags/4.24.3/includes/admin/class-wcmypa-admin.php#L872",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-myparcel/tags/4.24.3/includes/admin/class-wcmypa-admin.php#L653",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-myparcel/tags/4.24.3/includes/admin/class-wcmypa-admin.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3585914%40woocommerce-myparcel&new=3585914%40woocommerce-myparcel",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8699",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T16:55:10.477Z",
      "date_published": "2026-07-02T16:52:01.632Z",
      "date_updated": "2026-07-02T17:23:35.569Z",
      "publisher": "TPLink",
      "title": "Stored Cross-Site Scripting (XSS) in TP-Link Archer C5 Web Management Interface",
      "affected": {
        "vendors": [
          "TP-Link Systems Inc."
        ],
        "products": [
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "Archer C5 v6.8"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f23511db-6c3e-4e32-a477-6aa17d310630",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10889
      },
      "nvd": {
        "published": "2026-07-02T17:17:03.337",
        "lastModified": "2026-07-02T18:16:49.837",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8699",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Archer C5 v6.8 rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tp-link.com/en/support/faq/5165/",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 862,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8789",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-17T15:46:31.150Z",
      "date_published": "2026-07-24T14:34:50.754Z",
      "date_updated": "2026-07-24T15:31:56.280Z",
      "publisher": "Wordfence",
      "title": "Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Arbitrary Connection Deletion",
      "affected": {
        "vendors": [
          "easyappointments"
        ],
        "products": [
          {
            "vendor": "easyappointments",
            "product": "Easy Appointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.12947
      },
      "nvd": {
        "published": "2026-07-24T15:19:08.320",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8789",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Easy Appointments exposes ea_delete_multiple_connections without the capability check required to delete arbitrary connection records.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/47ed52b3-4bfe-46ce-aabc-7a4647ab7db5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3595856%40easy-appointments&new=3595856%40easy-appointments",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 477,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8791",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-17T20:50:37.972Z",
      "date_published": "2026-07-29T09:31:15.606Z",
      "date_updated": "2026-07-29T15:22:28.952Z",
      "publisher": "Wordfence",
      "title": "Booking System Trafft <= 1.0.17 - Authenticated (Subscriber+) Stored Cross-Site Scripting",
      "affected": {
        "vendors": [
          "ameliabooking"
        ],
        "products": [
          {
            "vendor": "ameliabooking",
            "product": "Booking System Trafft"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15325
      },
      "nvd": {
        "published": "2026-07-29T11:16:50.690",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8791",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Trafft lets any authenticated user update bookingWebsiteUrl because set_options checks a widely exposed nonce but no capability, and the value later becomes a site-wide script origin.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e93060cf-2df3-4d45-a1f2-304f443d58bc?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.php#L139",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.php#L139",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.php#L155",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.php#L155",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.php#L176",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.php#L176",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.php#L325",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.php#L325",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.php#L354",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.php#L354",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 964,
        "referenceCount": 11,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T02:42:58.378Z",
      "date_published": "2026-07-08T19:53:30.984Z",
      "date_updated": "2026-07-09T13:35:24.535Z",
      "publisher": "ProgressSoftware",
      "title": "Cross-Org External Token Metadata accessible to AuditUser role",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "MOVEit Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 6.1000000000000005,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11234
      },
      "nvd": {
        "published": "2026-07-08T20:17:00.913",
        "lastModified": "2026-07-09T19:17:34.223",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8800",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MOVEit AuditUser role can read external-token metadata belonging to another organization.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.html",
          "host": "docs.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-8801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T02:43:00.228Z",
      "date_published": "2026-07-08T19:56:03.468Z",
      "date_updated": "2026-07-09T13:36:42.815Z",
      "publisher": "ProgressSoftware",
      "title": "File Extension Restriction Bypass in MOVEit Transfer",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "MOVEit Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-46",
          "name": "Path Equivalence: 'filename ' (Trailing Space)",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 6.300000000000001,
      "epss": {
        "score": 0.00344,
        "percentile": 0.2705
      },
      "nvd": {
        "published": "2026-07-08T20:17:01.027",
        "lastModified": "2026-07-09T19:16:37.730",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8801",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MOVEit treats upload filenames that differ only by a trailing space as distinct at one validation step and equivalent at a later file operation.",
        "basis": [
          "CNA",
          "CWE-46"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.html",
          "host": "docs.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 167,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-8804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T05:31:00.670Z",
      "date_published": "2026-07-03T07:40:15.684Z",
      "date_updated": "2026-07-06T15:21:55.981Z",
      "publisher": "Perforce",
      "title": "Cleartext Storage of Sensitive Information for Puppet Resource API",
      "affected": {
        "vendors": [
          "Perforce"
        ],
        "products": [
          {
            "vendor": "Perforce",
            "product": "Puppet Core"
          },
          {
            "vendor": "Perforce",
            "product": "Puppet Enterprise"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 7,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-312",
          "name": "Cleartext Storage of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-313",
          "name": "Cleartext Storage in a File or on Disk",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:security@puppet.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00079,
        "percentile": 0.00184
      },
      "nvd": {
        "published": "2026-07-03T08:16:25.227",
        "lastModified": "2026-07-06T19:48:53.947",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8804",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Puppet drops a value's sensitive marker while transforming configuration data, allowing the secret to be emitted or stored as ordinary plaintext.",
        "basis": [
          "CNA",
          "CWE-312",
          "CWE-313"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://portal.perforce.com/s/cve/a91Qi000003511lIAA/cve20268804-cleartext-storage-of-sensitive-information-for-puppet-resource-api",
          "host": "portal.perforce.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 499,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-8825",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T10:49:15.314Z",
      "date_published": "2026-07-20T06:00:05.303Z",
      "date_updated": "2026-07-20T13:09:48.210Z",
      "publisher": "WPScan",
      "title": "Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Elementor Website Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14438
      },
      "nvd": {
        "published": "2026-07-20T07:16:42.553",
        "lastModified": "2026-07-20T20:39:31.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8825",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Elementor REST endpoint returns other authors' private posts and drafts without checking the requesting user's permission for each post.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/d0d6b840-790d-45a3-9b0d-8f77a229e8a9/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 368,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8848",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:45:24.005Z",
      "date_published": "2026-07-09T07:55:14.461Z",
      "date_updated": "2026-07-09T12:49:07.573Z",
      "publisher": "Wordfence",
      "title": "Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation",
      "affected": {
        "vendors": [
          "danieliser"
        ],
        "products": [
          {
            "vendor": "danieliser",
            "product": "Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0064,
        "percentile": 0.4717
      },
      "nvd": {
        "published": "2026-07-09T08:16:49.480",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8848",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The plugin-install endpoint accepts an editor-level caller because its token path does not enforce the capability required to install and activate plugins.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e05d4320-01d0-40c4-9a9a-457171ef7f5c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.22.0/classes/RestAPI/Connect.php#L520",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.22.0/classes/RestAPI/Connect.php#L330",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.22.0/classes/Controllers/RestAPI.php#L194",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.22.0/classes/Services/Connect.php#L177",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.22.0/classes/RestAPI/Connect.php#L445",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.21.5/classes/RestAPI/Connect.php#L520",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.21.5/classes/RestAPI/Connect.php#L330",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.21.5/classes/Controllers/RestAPI.php#L194",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.21.5/classes/Services/Connect.php#L177",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.21.5/classes/RestAPI/Connect.php#L445",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3589134%40popup-maker&new=3589134%40popup-maker",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 810,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8857",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T16:56:22.404Z",
      "date_published": "2026-07-01T15:08:49.425Z",
      "date_updated": "2026-07-01T15:49:55.764Z",
      "publisher": "wikimedia-foundation",
      "title": "Full RCE using EasyTimeline Extension",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "timeline"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 8.8,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31342
      },
      "nvd": {
        "published": "2026-07-01T16:16:53.847",
        "lastModified": "2026-07-09T17:20:24.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8857",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "EasyTimeline accepts attacker-influenced input that reaches executable code generation in its Perl and PHP processing path.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T426631",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8859",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T18:20:51.714Z",
      "date_published": "2026-07-17T18:58:13.948Z",
      "date_updated": "2026-07-23T03:56:05.464Z",
      "publisher": "ibm",
      "title": "Path Traversal in APIRequest Component via Content-Disposition Header",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00368,
        "percentile": 0.29499
      },
      "nvd": {
        "published": "2026-07-17T20:17:31.643",
        "lastModified": "2026-07-23T05:16:39.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8859",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Langflow joins an unsanitized Content-Disposition filename from an attacker-controlled HTTP response to its temporary directory path.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278924",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 619,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8861",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T18:50:49.014Z",
      "date_published": "2026-07-17T18:54:36.296Z",
      "date_updated": "2026-07-20T19:23:27.313Z",
      "publisher": "ibm",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Verify Identity Access"
          },
          {
            "vendor": "IBM",
            "product": "Security Verify Access"
          },
          {
            "vendor": "IBM",
            "product": "Verify Identity Access Container"
          },
          {
            "vendor": "IBM",
            "product": "Security Verify Access Container"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15235
      },
      "nvd": {
        "published": "2026-07-17T20:17:31.760",
        "lastModified": "2026-07-20T20:16:47.190",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8861",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The browser response includes a detailed technical error message containing sensitive system information.",
        "basis": [
          "CNA",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279510",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-8892",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T20:51:24.514Z",
      "date_published": "2026-07-03T04:30:19.430Z",
      "date_updated": "2026-07-06T14:45:51.832Z",
      "publisher": "Wordfence",
      "title": "CM Business Directory <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Business Address Meta Fields",
      "affected": {
        "vendors": [
          "creativemindssolutions"
        ],
        "products": [
          {
            "vendor": "creativemindssolutions",
            "product": "CM Business Directory – Optimise and showcase local business"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10848
      },
      "nvd": {
        "published": "2026-07-03T06:16:22.820",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8892",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CM Business Directory – Optimise and showcase local business page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ce3861a3-3a0f-4414-bea7-941c2d36fc39?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cm-business-directory/trunk/frontend/cm-business-directory-business-page-sc.php#L151",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cm-business-directory/trunk/frontend/cm-business-directory-business-page-sc.php#L107",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cm-business-directory/trunk/frontend/cm-business-directory-business-page-sc.php#L190",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cm-business-directory/trunk/backend/cm-business-directory-backend.php#L385",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cm-business-directory/trunk/backend/cm-business-directory-backend.php#L366",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3590314%40cm-business-directory&new=3590314%40cm-business-directory&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 818,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8919",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T05:58:10.712Z",
      "date_published": "2026-07-15T02:00:46.017Z",
      "date_updated": "2026-07-15T12:34:38.596Z",
      "publisher": "ASUS",
      "title": "Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the a...",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "GameSDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-942",
          "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22317
      },
      "nvd": {
        "published": "2026-07-15T02:22:57.653",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8919",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GameSDK accepts cross-domain requests from untrusted pages and follows a supplied UNC path that triggers local NTLM authentication.",
        "basis": [
          "CNA",
          "CWE-942"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory/",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 560,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8920",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T05:58:49.026Z",
      "date_published": "2026-07-15T02:00:56.653Z",
      "date_updated": "2026-07-15T13:12:23.878Z",
      "publisher": "ASUS",
      "title": "Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary fil...",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "Aura Wallpaper Service"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-923",
          "name": "Improper Restriction of Communication Channel to Intended Endpoints",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.00987
      },
      "nvd": {
        "published": "2026-07-15T02:22:57.790",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8920",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The local service accepts crafted commands containing an arbitrary path and performs file operations outside its intended path restrictions.",
        "basis": [
          "CNA",
          "CWE-73",
          "CWE-923"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory/",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8921",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T05:59:12.172Z",
      "date_published": "2026-07-03T02:00:34.858Z",
      "date_updated": "2026-07-06T15:42:20.031Z",
      "publisher": "ASUS",
      "title": "External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message.",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "ASUS Business Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02507
      },
      "nvd": {
        "published": "2026-07-03T03:16:23.627",
        "lastModified": "2026-07-06T18:56:27.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8921",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ASUS Business Manager accepts a file path from a tampered local IPC message and uses that path in a SYSTEM-privileged operation without constraining the selected object.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8924",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T08:11:35.441Z",
      "date_published": "2026-07-03T06:15:04.646Z",
      "date_updated": "2026-07-06T16:57:16.362Z",
      "publisher": "curl",
      "title": "trailing dot domain super cookie",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 95,
        "versionRangeCount": 95,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0056,
        "percentile": 0.43444
      },
      "nvd": {
        "published": "2026-07-03T07:16:24.793",
        "lastModified": "2026-07-07T23:06:00.797",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8924",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "curl passed trailing-dot host and cookie domains unchanged to its Public Suffix List check, so the check accepted a cookie scoped across unrelated sibling domains.",
        "basis": [
          "CNA",
          "CWE-201",
          "Vendor advisory",
          "Fixed source"
        ],
        "deepDive": true,
        "notes": "Inspected curl's advisory at https://curl.se/docs/CVE-2026-8924.html and fixed source at https://github.com/curl/curl/commit/51beed175dbfc37da3113f6acc; the patch trims trailing dots from both request and cookie domains before psl_is_cookie_domain_acceptable and adds the paired sibling-domain regression test."
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-8924.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8924.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3733905",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 95
      }
    },
    {
      "cve_id": "CVE-2026-8925",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T08:11:49.032Z",
      "date_published": "2026-07-03T06:15:25.448Z",
      "date_updated": "2026-07-06T17:04:15.411Z",
      "publisher": "curl",
      "title": "SASL double-free",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00592,
        "percentile": 0.44981
      },
      "nvd": {
        "published": "2026-07-03T07:16:24.950",
        "lastModified": "2026-07-07T23:04:29.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8925",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "curl cleans up the same allocation twice without clearing or transferring the pointer between the two paths.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-8925.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8925.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3735193",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-8926",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T08:11:58.393Z",
      "date_published": "2026-07-03T06:15:45.735Z",
      "date_updated": "2026-07-06T17:02:33.061Z",
      "publisher": "curl",
      "title": "password leak with netrc and user in URL",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00376,
        "percentile": 0.3036
      },
      "nvd": {
        "published": "2026-07-03T07:16:25.037",
        "lastModified": "2026-07-07T23:02:54.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8926",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The netrc lookup selects a password by host without ensuring that the stored username matches the requested username.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-8926.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8926.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3735184",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-8927",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T08:12:08.842Z",
      "date_published": "2026-07-03T06:16:06.376Z",
      "date_updated": "2026-07-06T17:01:06.213Z",
      "publisher": "curl",
      "title": "env-set cross-proxy Digest auth state leak",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 166,
        "versionRangeCount": 166,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0044,
        "percentile": 0.36164
      },
      "nvd": {
        "published": "2026-07-03T07:16:25.123",
        "lastModified": "2026-07-07T23:21:03.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8927",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A reused libcurl handle retains Digest proxy-authentication state and sends proxyA's header on a later transfer through proxyB.",
        "basis": [
          "CNA",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-8927.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8927.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3744543",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 394,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 166
      }
    },
    {
      "cve_id": "CVE-2026-8932",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T08:56:58.825Z",
      "date_published": "2026-07-03T06:16:30.485Z",
      "date_updated": "2026-07-06T16:59:07.104Z",
      "publisher": "curl",
      "title": "incomplete mTLS config matching in conn reuse",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 193,
        "versionRangeCount": 193,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-305",
          "name": "Authentication Bypass by Primary Weakness",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32419
      },
      "nvd": {
        "published": "2026-07-03T07:16:25.363",
        "lastModified": "2026-07-07T23:18:32.137",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-8932",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "libcurl reuses a pooled mTLS connection after private-key-related options change, carrying the old connection identity into a new configuration state.",
        "basis": [
          "CNA",
          "CWE-305"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-8932.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-8932.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3733910",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 466,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 193
      }
    },
    {
      "cve_id": "CVE-2026-8933",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T10:37:03.649Z",
      "date_published": "2026-07-21T14:02:19.758Z",
      "date_updated": "2026-07-22T18:28:05.924Z",
      "publisher": "canonical",
      "title": "snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup",
      "affected": {
        "vendors": [
          "Canonical"
        ],
        "products": [
          {
            "vendor": "Canonical",
            "product": "Ubuntu 26.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 24.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 22.04 LTS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-250",
          "name": "Execution with Unnecessary Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@ubuntu.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12032
      },
      "nvd": {
        "published": "2026-07-21T15:16:39.563",
        "lastModified": "2026-07-22T19:17:14.773",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8933",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A snap-confine installation configured with ambient set-capabilities initializes its privilege boundary incorrectly and permits local root execution.",
        "basis": [
          "CNA",
          "CWE-250"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://ubuntu.com/security/CVE-2026-8933",
          "host": "ubuntu.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 701,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-8982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T13:12:54.405Z",
      "date_published": "2026-07-21T21:01:02.360Z",
      "date_updated": "2026-07-22T19:40:35.197Z",
      "publisher": "CyberDanube",
      "title": "Hard-coded / Backdoor Accounts",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger Single"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:office@cyberdanube.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24717
      },
      "nvd": {
        "published": "2026-07-21T21:16:54.710",
        "lastModified": "2026-07-22T20:17:08.923",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8982",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cyberdanube.com/security-research/multiple-vulnerabilities-in-autel-maxi-charger/",
          "host": "cyberdanube.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8983",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T13:12:55.680Z",
      "date_published": "2026-07-21T21:03:22.675Z",
      "date_updated": "2026-07-22T19:40:28.831Z",
      "publisher": "CyberDanube",
      "title": "Backdoor Authentication Token",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger Single"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:office@cyberdanube.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25476
      },
      "nvd": {
        "published": "2026-07-21T21:16:54.837",
        "lastModified": "2026-07-22T20:17:09.050",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8983",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Firmware contains a fixed token that management endpoints accept as privileged authentication.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cyberdanube.com/security-research/multiple-vulnerabilities-in-autel-maxi-charger/",
          "host": "cyberdanube.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8984",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T13:12:56.651Z",
      "date_published": "2026-07-21T21:08:49.622Z",
      "date_updated": "2026-07-22T19:38:02.292Z",
      "publisher": "CyberDanube",
      "title": "Unauthenticated RCE",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger Single"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:office@cyberdanube.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00506,
        "percentile": 0.40482
      },
      "nvd": {
        "published": "2026-07-21T22:19:10.770",
        "lastModified": "2026-07-22T20:17:09.170",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8984",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated test endpoint downloads, extracts and executes an attacker-controlled package as root without establishing artifact provenance.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cyberdanube.com/security-research/multiple-vulnerabilities-in-autel-maxi-charger/",
          "host": "cyberdanube.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 283,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8985",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T13:12:57.548Z",
      "date_published": "2026-07-21T21:11:25.089Z",
      "date_updated": "2026-07-22T19:37:37.583Z",
      "publisher": "CyberDanube",
      "title": "Unauthenticated Command Injection",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger Single"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:office@cyberdanube.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.04193,
        "percentile": 0.89947
      },
      "nvd": {
        "published": "2026-07-21T22:19:10.893",
        "lastModified": "2026-07-22T20:17:09.280",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8985",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application places attacker-controlled data into a shell command without separating the data from command syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cyberdanube.com/security-research/multiple-vulnerabilities-in-autel-maxi-charger/",
          "host": "cyberdanube.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8986",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T13:12:58.413Z",
      "date_published": "2026-07-21T21:14:26.937Z",
      "date_updated": "2026-07-22T19:37:31.531Z",
      "publisher": "CyberDanube",
      "title": "Command Injection via Malicious OCPP Server",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger Single"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:office@cyberdanube.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01215,
        "percentile": 0.65568
      },
      "nvd": {
        "published": "2026-07-21T22:19:11.023",
        "lastModified": "2026-07-22T20:17:09.397",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8986",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value reaches operating-system command construction in MaxiCharger Single without separation from command or argument syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cyberdanube.com/security-research/multiple-vulnerabilities-in-autel-maxi-charger/",
          "host": "cyberdanube.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 280,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8987",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T13:12:59.230Z",
      "date_published": "2026-07-21T21:18:32.693Z",
      "date_updated": "2026-07-22T19:37:25.824Z",
      "publisher": "CyberDanube",
      "title": "Authenticated Heap Overflow",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger Single"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:office@cyberdanube.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00356,
        "percentile": 0.28294
      },
      "nvd": {
        "published": "2026-07-21T22:19:11.143",
        "lastModified": "2026-07-22T20:17:09.510",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8987",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The set_ap_param command accepts oversized authenticated input and writes beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cyberdanube.com/security-research/multiple-vulnerabilities-in-autel-maxi-charger/",
          "host": "cyberdanube.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8988",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T13:13:00.389Z",
      "date_published": "2026-07-21T21:21:50.327Z",
      "date_updated": "2026-07-22T19:37:20.155Z",
      "publisher": "CyberDanube",
      "title": "Access to Bootloader",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger Single"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1191",
          "name": "On-Chip Debug and Test Interface With Improper Access Control",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:office@cyberdanube.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04378
      },
      "nvd": {
        "published": "2026-07-21T22:19:11.270",
        "lastModified": "2026-07-22T20:17:09.633",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8988",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An exposed UART permits physical interruption and modification of the bootloader process.",
        "basis": [
          "CNA",
          "CWE-1191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cyberdanube.com/security-research/multiple-vulnerabilities-in-autel-maxi-charger/",
          "host": "cyberdanube.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8989",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T13:13:01.023Z",
      "date_published": "2026-07-21T21:24:28.841Z",
      "date_updated": "2026-07-22T19:37:14.371Z",
      "publisher": "CyberDanube",
      "title": "Open Recovery Mode",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger Single"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1191",
          "name": "On-Chip Debug and Test Interface With Improper Access Control",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1244",
          "name": "Internal Asset Exposed to Unsafe Debug Access Level or State",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:office@cyberdanube.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.0863
      },
      "nvd": {
        "published": "2026-07-21T22:19:11.387",
        "lastModified": "2026-07-22T20:17:09.750",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8989",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Exposed recovery pins permit unrestricted entry into the processor's recovery mode and boot of attacker-controlled memory code.",
        "basis": [
          "CNA record",
          "CWE-1191",
          "CWE-1244"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cyberdanube.com/security-research/multiple-vulnerabilities-in-autel-maxi-charger/",
          "host": "cyberdanube.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-8996",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T13:31:06.616Z",
      "date_published": "2026-07-09T06:52:51.697Z",
      "date_updated": "2026-07-09T17:29:08.760Z",
      "publisher": "Wordfence",
      "title": "Backup and Staging by WP Time Capsule <= 1.22.26 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via download_recent_decrypted_file_wptc Function",
      "affected": {
        "vendors": [
          "revmakx"
        ],
        "products": [
          {
            "vendor": "revmakx",
            "product": "Backup and Staging by WP Time Capsule"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17847
      },
      "nvd": {
        "published": "2026-07-09T08:16:49.620",
        "lastModified": "2026-07-09T18:16:58.297",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-8996",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The download_recent_decrypted_file_wptc action serves the administrator's recent decrypted database backup without checking the subscriber's authorization.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f7c39d66-f1e1-4d41-a9e4-984aec3f37dc?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-time-capsule/trunk/wp-time-capsule.php#L3764",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-time-capsule/trunk/wp-time-capsule.php#L410",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-time-capsule/trunk/Views/wptc-download-file.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-time-capsule/tags/1.22.26/wp-time-capsule.php#L3764",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-time-capsule/tags/1.22.26/wp-time-capsule.php#L410",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-time-capsule/tags/1.22.26/Views/wptc-download-file.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3563585%40wp-time-capsule&new=3563585%40wp-time-capsule",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 746,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9007",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T14:01:29.613Z",
      "date_published": "2026-07-15T15:41:34.362Z",
      "date_updated": "2026-07-15T16:04:57.687Z",
      "publisher": "TCS-CERT",
      "title": "Reflected XSS in HCL Notes",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "HCL Notes"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:64c5ae8f-7972-4697-86a0-7ada793ac795",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17371
      },
      "nvd": {
        "published": "2026-07-15T16:16:52.300",
        "lastModified": "2026-07-15T21:00:31.273",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9007",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HCL Notes reflects attacker-controlled input into generated HTML without neutralizing executable JavaScript.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.thalesgroup.com/en/search/cybersecurity/cybersecurity-services/CVE-2026-9007",
          "host": "www.thalesgroup.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9017",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T14:36:40.302Z",
      "date_published": "2026-07-11T06:50:32.516Z",
      "date_updated": "2026-07-15T13:49:19.081Z",
      "publisher": "Wordfence",
      "title": "NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action",
      "affected": {
        "vendors": [
          "webaways"
        ],
        "products": [
          {
            "vendor": "webaways",
            "product": "NEX-Forms – Ultimate Forms Plugin for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19468
      },
      "nvd": {
        "published": "2026-07-11T07:16:46.923",
        "lastModified": "2026-07-15T14:18:35.793",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9017",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public nf_send_nf_email action updates attacker-selected form entries and recipients without authenticating or authorizing the target entry.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0af9df66-8d82-4ae8-85a1-656d8ea40a7a?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.13/main.php#L5288",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.13/main.php#L4636",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.13/main.php#L2663",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/main.php#L5288",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/main.php#L4636",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/main.php#L2663",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3584399%40nex-forms-express-wp-form-builder&new=3584399%40nex-forms-express-wp-form-builder",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9021",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T15:07:10.933Z",
      "date_published": "2026-07-09T09:31:23.000Z",
      "date_updated": "2026-07-09T13:52:00.900Z",
      "publisher": "Wordfence",
      "title": "Easy Invoice <= 2.1.19 - Unauthenticated Arbitrary Quote Accept/Decline and Invoice Creation via easy_invoice_accept_quote / easy_invoice_decline_quote AJAX Actions",
      "affected": {
        "vendors": [
          "matrixaddons"
        ],
        "products": [
          {
            "vendor": "matrixaddons",
            "product": "Easy Invoice – Invoice Generator, PDF Quotes & Payments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00297,
        "percentile": 0.21982
      },
      "nvd": {
        "published": "2026-07-09T11:16:41.900",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9021",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Public quote pages expose the only nonce checked by unauthenticated accept and decline handlers, while ownership enforcement is disabled by default.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dab1c93d-e83c-4d38-be80-56d8e32f1894?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-invoice/tags/2.2.0/includes/Controllers/QuoteController.php#L1022",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-invoice/tags/2.2.0/includes/Controllers/QuoteController.php#L1453",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-invoice/tags/2.2.0/includes/Controllers/QuoteController.php#L88",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-invoice/tags/2.2.0/templates/quotes/single.php#L1462",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-invoice/tags/2.1.12/includes/Controllers/QuoteController.php#L1022",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-invoice/tags/2.1.12/includes/Controllers/QuoteController.php#L1453",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-invoice/tags/2.1.12/includes/Controllers/QuoteController.php#L88",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-invoice/tags/2.1.12/templates/quotes/single.php#L1462",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3517910/easy-invoice/trunk/includes/Controllers/QuoteController.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 820,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9027",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T15:23:17.002Z",
      "date_published": "2026-07-09T09:31:20.557Z",
      "date_updated": "2026-07-09T14:39:29.620Z",
      "publisher": "Wordfence",
      "title": "CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Improper Verification of Cryptographic Signature to Payment Bypass via /wp-json/corvuspay/success/ REST Endpoint",
      "affected": {
        "vendors": [
          "corvusinfo"
        ],
        "products": [
          {
            "vendor": "corvusinfo",
            "product": "CorvusPay WooCommerce Payment Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.1284
      },
      "nvd": {
        "published": "2026-07-09T11:16:42.017",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9027",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "corvuspay_success_handler computes signature validity but never branches on the result, reaching payment_complete for arbitrary forged signatures.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3bc9f344-b605-4257-8d77-e073f85fe344?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.4/includes/class-wc-gateway-corvuspay.php#L656",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.4/includes/class-wc-order-corvuspay.php#L188",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.4/includes/class-wc-gateway-corvuspay.php#L202",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.2/includes/class-wc-gateway-corvuspay.php#L656",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.2/includes/class-wc-order-corvuspay.php#L188",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.2/includes/class-wc-gateway-corvuspay.php#L202",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3576949%40corvuspay-woocommerce-integration&new=3576949%40corvuspay-woocommerce-integration",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1111,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9028",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T15:24:07.965Z",
      "date_published": "2026-07-09T09:31:20.926Z",
      "date_updated": "2026-07-09T12:18:39.132Z",
      "publisher": "Wordfence",
      "title": "CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Missing Authorization to Unauthenticated Arbitrary Order Cancellation via 'order_number' Parameter",
      "affected": {
        "vendors": [
          "corvusinfo"
        ],
        "products": [
          {
            "vendor": "corvusinfo",
            "product": "CorvusPay WooCommerce Payment Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21078
      },
      "nvd": {
        "published": "2026-07-09T11:16:42.140",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9028",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The CorvusPay WooCommerce Payment Gateway path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/402f1f9f-35c7-4304-891b-a07f3e84c189?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.4/includes/class-wc-gateway-corvuspay.php#L792",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.4/includes/class-wc-gateway-corvuspay.php#L206",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.4/includes/class-wc-order-corvuspay.php#L172",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.2/includes/class-wc-gateway-corvuspay.php#L792",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.2/includes/class-wc-gateway-corvuspay.php#L206",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/corvuspay-woocommerce-integration/tags/2.7.2/includes/class-wc-order-corvuspay.php#L172",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3576949%40corvuspay-woocommerce-integration&new=3576949%40corvuspay-woocommerce-integration",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9044",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T18:34:35.705Z",
      "date_published": "2026-07-31T22:20:36.166Z",
      "date_updated": "2026-08-04T03:56:21.578Z",
      "publisher": "TPLink",
      "title": "Command Injection Vulnerability in OpenVPN of TP-Link Archer AXE75",
      "affected": {
        "vendors": [
          "TP-Link Systems Inc."
        ],
        "products": [
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "AXE75 V1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:f23511db-6c3e-4e32-a477-6aa17d310630",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00973,
        "percentile": 0.58551
      },
      "nvd": {
        "published": "2026-07-31T23:17:26.767",
        "lastModified": "2026-08-04T05:16:40.213",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9044",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Special characters in an imported OpenVPN client configuration reach an operating-system command without shell neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tp-link.com/en/support/download/archer-axe75/v1/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/faq/5215/",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/download/archer-axe75/v1/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9046",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:01:33.092Z",
      "date_published": "2026-07-16T16:48:47.938Z",
      "date_updated": "2026-07-16T17:51:28.237Z",
      "publisher": "lenovo",
      "title": "A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local u...",
      "affected": {
        "vendors": [
          "Lenovo"
        ],
        "products": [
          {
            "vendor": "Lenovo",
            "product": "Legion Zone"
          },
          {
            "vendor": "Lenovo",
            "product": "App Store"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-277",
          "name": "Insecure Inherited Permissions",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.00085,
        "percentile": 0.00377
      },
      "nvd": {
        "published": "2026-07-16T17:16:59.100",
        "lastModified": "2026-07-16T19:16:51.490",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9046",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Legion Zone installation inherits writable permissions on a non-system volume and later executes attacker-replaceable content.",
        "basis": [
          "CNA",
          "CWE-277"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://iknow.lenovo.com.cn/detail/441420",
          "host": "iknow.lenovo.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-9066",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T08:42:05.343Z",
      "date_published": "2026-07-23T06:00:03.157Z",
      "date_updated": "2026-07-23T14:11:13.014Z",
      "publisher": "WPScan",
      "title": "WP Compress < 7.10.04 - Reflected XSS via test_zone",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Compress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04571
      },
      "nvd": {
        "published": "2026-07-23T07:16:32.830",
        "lastModified": "2026-07-23T15:18:18.617",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9066",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WP Compress uses an unvalidated CDN-host query value to emit script URLs that execute code from an attacker-controlled origin.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/133e2ca0-8cde-4b59-b680-0ddf95004625/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9074",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T12:31:24.875Z",
      "date_published": "2026-07-08T15:24:38.566Z",
      "date_updated": "2026-07-09T03:55:49.087Z",
      "publisher": "ibm",
      "title": "IBM API Connect SQL Injection",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "API Connect"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.7000000000000011,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20377
      },
      "nvd": {
        "published": "2026-07-08T16:16:35.050",
        "lastModified": "2026-07-10T16:59:16.577",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9074",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "IBM API Connect accepts unauthenticated password-reset input as SQL syntax, while the vendor bulletin does not publish the parameter, query construction, or database sink.",
        "basis": [
          "CNA",
          "CWE-89",
          "IBM API Connect security bulletin 7278909",
          "IBM API Connect security bulletin 7278218"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.ibm.com/support/pages/node/7278909 and https://www.ibm.com/support/pages/node/7278218. IBM confirms unauthenticated SQL injection in password reset, no workaround, and upgrades to 12.1.1.0, but publishes no parameter, query construction, or sink. IBM scores CVSS 3.1 at 9.1, while the shard maximum is NVD CVSS 3.1 at 9.8; retain the two score attributions separately."
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278909",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.ibm.com/support/pages/node/7278218",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 164,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-9079",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T12:59:41.444Z",
      "date_published": "2026-07-03T06:16:51.127Z",
      "date_updated": "2026-07-06T16:49:56.248Z",
      "publisher": "curl",
      "title": "stale proxy password leak",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00584,
        "percentile": 0.44599
      },
      "nvd": {
        "published": "2026-07-03T07:16:25.620",
        "lastModified": "2026-07-07T15:05:55.933",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9079",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "libcurl fails to clear a proxy password and reuses the stale credential on a later transfer.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-9079.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-9079.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3750295",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-9080",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T12:59:50.588Z",
      "date_published": "2026-07-03T06:17:34.905Z",
      "date_updated": "2026-07-06T16:55:16.890Z",
      "publisher": "curl",
      "title": "UAF after pause in socket callback",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21833
      },
      "nvd": {
        "published": "2026-07-03T07:16:25.713",
        "lastModified": "2026-07-07T15:05:26.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9080",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A socket callback can free a libcurl object while curl_easy_pause() continues and writes a flag through the dangling pointer.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-9080.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-9080.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3749204",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-9085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T14:26:02.795Z",
      "date_published": "2026-07-05T14:38:02.152Z",
      "date_updated": "2026-07-06T13:24:46.535Z",
      "publisher": "TR-CERT",
      "title": "DNS Hijacking in TUBITAK BILGEM's Pardus-Parental-Control",
      "affected": {
        "vendors": [
          "TUBITAK BILGEM Software Technologies Research Institute"
        ],
        "products": [
          {
            "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
            "product": "Pardus-Parental-Control"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00101,
        "percentile": 0.01038
      },
      "nvd": {
        "published": "2026-07-05T15:16:57.800",
        "lastModified": "2026-07-06T18:16:45.163",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9085",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Pardus assigns unsafe permissions to a network-sensitive configuration path, allowing an unprivileged local actor to influence DNS resolution.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0500",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T16:49:30.512Z",
      "date_published": "2026-07-17T18:49:43.340Z",
      "date_updated": "2026-07-23T03:56:04.663Z",
      "publisher": "ibm",
      "title": "Unauthenticated Superuser Token Issuance via Auto-Login Endpoint",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00411,
        "percentile": 0.33801
      },
      "nvd": {
        "published": "2026-07-17T19:17:19.277",
        "lastModified": "2026-07-23T05:16:39.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9103",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The default-enabled auto_login endpoint issues a long-lived superuser bearer token to an unauthenticated network caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278926",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9107",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:15:24.162Z",
      "date_published": "2026-07-01T03:43:35.019Z",
      "date_updated": "2026-07-01T10:32:06.754Z",
      "publisher": "Wordfence",
      "title": "Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' Parameter",
      "affected": {
        "vendors": [
          "wpchill"
        ],
        "products": [
          {
            "vendor": "wpchill",
            "product": "Kali Forms — Contact Form & Drag-and-Drop Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14411
      },
      "nvd": {
        "published": "2026-07-01T05:16:25.510",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9107",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Kali Forms — Contact Form & Drag-and-Drop Builder page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3d81e41d-e62c-49d7-bba5-6a2a0a586c84?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.11/resources/assets/js/forms/components/Builder/BuilderFormField.jsx#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.11/Inc/Backend/Posts/class-forms.php#L381",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.11/Inc/Backend/Posts/class-forms.php#L391",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.11/resources/assets/js/forms/components/Builder/BuilderFormField.jsx#L332",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.10/resources/assets/js/forms/components/Builder/BuilderFormField.jsx#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.10/Inc/Backend/Posts/class-forms.php#L381",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.10/Inc/Backend/Posts/class-forms.php#L391",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.10/resources/assets/js/forms/components/Builder/BuilderFormField.jsx#L332",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fkali-forms/tags/2.4.13&new_path=%2Fkali-forms/tags/2.4.14",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9108",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:20:44.539Z",
      "date_published": "2026-07-14T15:09:37.108Z",
      "date_updated": "2026-07-14T15:54:25.440Z",
      "publisher": "Rockwell",
      "title": "Studio 5000 Logix Designer® – Multiple Vulnerabilities",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "Studio 5000 Logix Designer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00109,
        "percentile": 0.01451
      },
      "nvd": {
        "published": "2026-07-14T16:17:05.210",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9108",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Logix Designer extracts filenames from an ACD project without rejecting traversal sequences or constraining the resolved destination.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1783.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 551,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9127",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:48:19.830Z",
      "date_published": "2026-07-14T15:10:38.749Z",
      "date_updated": "2026-07-14T15:54:46.504Z",
      "publisher": "Rockwell",
      "title": "Studio 5000 Logix Designer® – Multiple Vulnerabilities",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "Studio 5000 Logix Designer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0011,
        "percentile": 0.01495
      },
      "nvd": {
        "published": "2026-07-14T16:17:05.347",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9127",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Studio 5000 lets any authenticated user modify privileged external-tool paths that should be restricted to an administrative role.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1783.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 440,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9128",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:48:35.972Z",
      "date_published": "2026-07-14T15:12:49.393Z",
      "date_updated": "2026-07-14T15:55:42.919Z",
      "publisher": "Rockwell",
      "title": "Studio 5000 Logix Designer® – Multiple Vulnerabilities",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "Studio 5000 Logix Designer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-428",
          "name": "Unquoted Search Path or Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00096,
        "percentile": 0.00852
      },
      "nvd": {
        "published": "2026-07-14T16:17:05.487",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9128",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "External Tools stores executable paths containing spaces without quotes, letting Windows resolve and run an attacker-planted executable earlier in the search path.",
        "basis": [
          "CNA",
          "CWE-428"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1783.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 578,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9135",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:38:22.538Z",
      "date_published": "2026-07-17T18:48:55.949Z",
      "date_updated": "2026-07-23T03:56:03.838Z",
      "publisher": "ibm",
      "title": "Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0045,
        "percentile": 0.36937
      },
      "nvd": {
        "published": "2026-07-17T19:17:19.390",
        "lastModified": "2026-07-23T05:16:39.817",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9135",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Validation checks only the main component source while dynamic CodeInput fields persist attacker Python that ToolGuard later executes.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278920",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1305,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9140",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T19:35:43.256Z",
      "date_published": "2026-07-14T14:52:20.870Z",
      "date_updated": "2026-07-14T15:24:32.109Z",
      "publisher": "Rockwell",
      "title": "1718-AENTR/1719-AENTR - Denial of Service",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "1718-AENTR/1719-AENTR"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16771
      },
      "nvd": {
        "published": "2026-07-14T15:17:10.897",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9140",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The adapter has no effective throttling for a UDP unicast storm and remains overloaded until power-cycled.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1778.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 247,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T20:03:22.747Z",
      "date_published": "2026-07-02T09:32:02.913Z",
      "date_updated": "2026-07-02T15:54:04.136Z",
      "publisher": "Wordfence",
      "title": "Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'",
      "affected": {
        "vendors": [
          "crmperks"
        ],
        "products": [
          {
            "vendor": "crmperks",
            "product": "Database for Contact Form 7, WPforms, Elementor forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00308,
        "percentile": 0.23083
      },
      "nvd": {
        "published": "2026-07-02T10:16:28.850",
        "lastModified": "2026-07-02T16:16:35.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9145",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The form handler passes attacker-controlled raw_value data to PHP copy without proving it names a legitimate uploaded file or an allowed source.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2ccadf7c-b628-43b6-a6b0-828ca31ff9cc?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-entries/tags/1.5.1/contact-form-entries.php#L1380",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-entries/tags/1.5.1/contact-form-entries.php#L640",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-entries/tags/1.5.1/contact-form-entries.php#L641",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-entries/tags/1.5.1/contact-form-entries.php#L651",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1215,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T21:05:14.933Z",
      "date_published": "2026-07-18T12:46:26.694Z",
      "date_updated": "2026-08-03T19:40:13.218Z",
      "publisher": "VulnCheck",
      "title": "uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata",
      "affected": {
        "vendors": [
          "scikit-hep"
        ],
        "products": [
          {
            "vendor": "scikit-hep",
            "product": "uproot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00153,
        "percentile": 0.05012
      },
      "nvd": {
        "published": "2026-07-18T13:17:06.273",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9147",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "uproot lets attacker-controlled schema, metadata, code text, or file content cross into a code-generation or execution interpreter without the quoting, allowlisting, or neutralization needed to keep it as data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/scikit-hep/uproot5/security/advisories/GHSA-6946-mq52-g438",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/scikit-hep/uproot5/commit/c045c2824295d907d2e705f31110c742928e50e7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/scikit-hep/uproot5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/uproot-and-before-code-injection-via-tstreamerinfo-metadata",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 746,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9148",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T21:18:38.233Z",
      "date_published": "2026-07-03T06:50:12.154Z",
      "date_updated": "2026-07-06T15:32:18.602Z",
      "publisher": "Wordfence",
      "title": "Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' Field",
      "affected": {
        "vendors": [
          "advancedcoding"
        ],
        "products": [
          {
            "vendor": "advancedcoding",
            "product": "Comments – wpDiscuz"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21487
      },
      "nvd": {
        "published": "2026-07-03T08:16:25.367",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9148",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "getCommentAuthor inserts the stored comment_author_url into a single-quoted HTML attribute without esc_url or esc_attr.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f509f1c6-6094-434d-8e70-ad8419250aa2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdiscuz/tags/7.6.54/utils/class.WpdiscuzHelper.php#L1619",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdiscuz/tags/7.6.54/utils/class.WpdiscuzHelper.php#L1615",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdiscuz/tags/7.6.54/forms/wpdFormAttr/Field/DefaultField/Website.php#L119",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdiscuz/tags/7.6.54/forms/wpdFormAttr/Tools/Sanitizer.php#L14",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdiscuz/tags/7.6.48/utils/class.WpdiscuzHelper.php#L1619",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdiscuz/tags/7.6.48/utils/class.WpdiscuzHelper.php#L1615",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdiscuz/tags/7.6.48/forms/wpdFormAttr/Field/DefaultField/Website.php#L119",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdiscuz/tags/7.6.48/forms/wpdFormAttr/Tools/Sanitizer.php#L14",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3563675/wpdiscuz/trunk/utils/class.WpdiscuzHelper.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fwpdiscuz/tags/7.6.56&new_path=%2Fwpdiscuz/tags/7.6.57",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 11,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9165",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T12:54:16.202Z",
      "date_published": "2026-07-06T08:46:22.139Z",
      "date_updated": "2026-07-19T00:11:39.889Z",
      "publisher": "redhat",
      "title": "Stackrox: stackrox: unbounded graphql query depth allows authenticated denial of service",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Security 4.9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Security for Kubernetes 4.10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Security for Kubernetes 4.11"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23521
      },
      "nvd": {
        "published": "2026-07-06T09:16:39.400",
        "lastModified": "2026-07-19T01:17:02.260",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9165",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The authenticated GraphQL endpoint accepts arbitrarily deep queries, allowing nested selections to exhaust Central's processing resources.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36207",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36319",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36625",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-9165",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480505",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 359,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-9171",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T14:37:46.761Z",
      "date_published": "2026-07-17T18:26:10.326Z",
      "date_updated": "2026-07-30T15:47:51.119Z",
      "publisher": "ibm",
      "title": "Vulnerabilities in IBM WebSphere Application affects IBM PowerVM Novalink.",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "PowerVM Novalink"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23761
      },
      "nvd": {
        "published": "2026-07-17T19:17:19.520",
        "lastModified": "2026-07-30T16:17:16.647",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9171",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A crafted request causes unbounded memory consumption, but the public record does not identify the allocation or missing limit.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280226",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-9177",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T14:43:42.513Z",
      "date_published": "2026-07-29T13:46:06.383Z",
      "date_updated": "2026-07-31T05:52:15.529Z",
      "publisher": "Toreon",
      "title": "Server-Side Template Injection in SecureTransport's Apache Velocity mail templates",
      "affected": {
        "vendors": [
          "Axway"
        ],
        "products": [
          {
            "vendor": "Axway",
            "product": "SecureTransport"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:1c6b5737-9389-4011-8117-89fa251edfb2",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21058
      },
      "nvd": {
        "published": "2026-07-29T14:16:35.857",
        "lastModified": "2026-07-30T20:27:10.763",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9177",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SecureTransport evaluates administrator-controlled mail-template content as Apache Velocity expressions with access to Java execution capabilities.",
        "basis": [
          "CNA",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.axway.com/news/4882/lang/en",
          "host": "support.axway.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "customer-entitlement",
            "mitigation",
            "patch",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.toreon.com/CVE-2026-9177",
          "host": "www.toreon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "https://docs.hackjiji.org/blog/cve-2026-9177-ssti-in-securetransport-mft-gateway",
          "host": "docs.hackjiji.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 575,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9180",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T14:47:44.596Z",
      "date_published": "2026-07-03T04:30:19.902Z",
      "date_updated": "2026-07-06T12:35:03.456Z",
      "publisher": "Wordfence",
      "title": "MotoPress Appointment Booking <= 2.4.4 - Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' Parameter",
      "affected": {
        "vendors": [
          "jetmonsters"
        ],
        "products": [
          {
            "vendor": "jetmonsters",
            "product": "MotoPress Appointment Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00342,
        "percentile": 0.26787
      },
      "nvd": {
        "published": "2026-07-03T06:16:22.973",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9180",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MotoPress Appointment Booking accepts a caller-controlled booking key without binding that key to the authorized user or booking owner.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e9a6521d-39b2-48f4-834b-888047619df5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motopress-appointment-lite/tags/2.4.3/includes/rest/controllers/motopress/appointment/v1/BookingsRestController.php#L98",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motopress-appointment-lite/tags/2.4.3/includes/rest/controllers/motopress/appointment/v1/BookingsRestController.php#L308",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motopress-appointment-lite/tags/2.4.3/includes/rest/controllers/motopress/appointment/v1/BookingsRestController.php#L30",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motopress-appointment-lite/tags/2.4.3/includes/services/BookingService.php#L29",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3583168/motopress-appointment-lite/trunk/includes/rest/controllers/motopress/appointment/v1/BookingsRestController.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1289,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9181",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T14:53:07.920Z",
      "date_published": "2026-07-06T18:22:08.233Z",
      "date_updated": "2026-07-08T14:44:31.974Z",
      "publisher": "Esri",
      "title": "Directory Traversal in ArcGIS Server",
      "affected": {
        "vendors": [
          "Esri"
        ],
        "products": [
          {
            "vendor": "Esri",
            "product": "ArcGIS Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@esri.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 2.3000000000000007,
      "epss": {
        "score": 0.00944,
        "percentile": 0.57614
      },
      "nvd": {
        "published": "2026-07-06T19:17:09.553",
        "lastModified": "2026-07-08T15:16:32.720",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9181",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "ArcGIS Server accepts crafted path parameters that escape the intended directory and overwrite sensitive files.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/may-2026-arcgis-security-bulletin",
          "host": "www.esri.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9182",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T14:53:09.293Z",
      "date_published": "2026-07-06T18:21:11.940Z",
      "date_updated": "2026-07-08T15:39:35.400Z",
      "publisher": "Esri",
      "title": "Unvalidated File Upload vulnerability in ArcGIS Server.",
      "affected": {
        "vendors": [
          "Esri"
        ],
        "products": [
          {
            "vendor": "Esri",
            "product": "ArcGIS Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@esri.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27936
      },
      "nvd": {
        "published": "2026-07-06T19:17:09.680",
        "lastModified": "2026-07-08T16:16:35.167",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9182",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Esri ArcGIS Server contains an unrestricted file upload vulnerability.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/may-2026-arcgis-security-bulletin",
          "host": "www.esri.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:04:38.302Z",
      "date_published": "2026-07-02T08:33:04.439Z",
      "date_updated": "2026-07-02T19:41:53.548Z",
      "publisher": "Wordfence",
      "title": "Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 - Unauthenticated Insecure Direct Object Reference via Predictable 'edit_key' / 'appointmentkey' Parameter",
      "affected": {
        "vendors": [
          "wappointment"
        ],
        "products": [
          {
            "vendor": "wappointment",
            "product": "Appointment Bookings for Zoom GoogleMeet and more – Wappointment"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00297,
        "percentile": 0.21982
      },
      "nvd": {
        "published": "2026-07-02T10:16:28.970",
        "lastModified": "2026-07-02T20:17:08.933",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9188",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The appointment edit token is an unsalted MD5 of predictable public or enumerable fields, so it cannot serve as an authorization secret.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/07069f39-f892-4c19-8e0b-e5e17b1ffb21?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wappointment/tags/2.7.6/app/Services/AppointmentNew.php#L347",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wappointment/tags/2.7.6/app/Services/AppointmentNew.php#L190",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wappointment/tags/2.7.6/app/Models/Client.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wappointment/tags/2.7.6/app/Services/AppointmentNew.php#L40",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wappointment/tags/2.7.5/app/Services/AppointmentNew.php#L347",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wappointment/tags/2.7.5/app/Services/AppointmentNew.php#L190",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wappointment/tags/2.7.5/app/Models/Client.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wappointment/tags/2.7.5/app/Services/AppointmentNew.php#L40",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3546313%40wappointment&new=3546313%40wappointment&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1303,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9198",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:40:11.465Z",
      "date_published": "2026-07-17T17:36:11.246Z",
      "date_updated": "2026-07-18T03:55:39.789Z",
      "publisher": "ibm",
      "title": "Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01886,
        "percentile": 0.77474
      },
      "nvd": {
        "published": "2026-07-17T18:17:17.340",
        "lastModified": "2026-07-24T16:57:10.373",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9198",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Langflow's unauthenticated auto-login endpoint mints a SUPERUSER token that can then reach an exec()-based code-validation endpoint.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278927",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9202",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:53:52.649Z",
      "date_published": "2026-07-17T17:33:20.083Z",
      "date_updated": "2026-07-18T03:55:39.032Z",
      "publisher": "ibm",
      "title": "Unauthenticated User Registration Could Lead to Remote Code Execution",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20163
      },
      "nvd": {
        "published": "2026-07-17T18:17:17.490",
        "lastModified": "2026-07-24T16:57:00.977",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9202",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The registration endpoint creates accounts without authentication and can immediately activate them under NEW_USER_IS_ACTIVE, granting access to existing code-execution functions.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278929",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9230",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:35:49.663Z",
      "date_published": "2026-07-03T06:50:11.170Z",
      "date_updated": "2026-07-06T14:45:18.312Z",
      "publisher": "Wordfence",
      "title": "Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure",
      "affected": {
        "vendors": [
          "expresstech"
        ],
        "products": [
          {
            "vendor": "expresstech",
            "product": "Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22165
      },
      "nvd": {
        "published": "2026-07-03T08:16:25.483",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9230",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A quiz-scoped nonce is accepted without checking quiz ownership, allowing a contributor to modify another user quiz and notification settings.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/49c66f9e-e58c-435b-9bb0-d6b66261e789?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.1.2/php/rest-api.php#L460",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.1.2/php/rest-api.php#L513",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.1.2/blocks/block.php#L424",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.1.2/blocks/block.php#L257",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.1.2/php/rest-api.php#L862",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.1.2/mlw_quizmaster2.php#L890",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.3.5/php/rest-api.php#L460",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.3.5/php/rest-api.php#L513",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.3.5/blocks/block.php#L424",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.3.5/blocks/block.php#L257",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.3.5/php/rest-api.php#L862",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/10.3.5/mlw_quizmaster2.php#L890",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3570062%40quiz-master-next&new=3570062%40quiz-master-next&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 773,
        "referenceCount": 14,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9235",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:47:05.557Z",
      "date_published": "2026-07-09T09:31:22.329Z",
      "date_updated": "2026-07-09T12:31:09.164Z",
      "publisher": "Wordfence",
      "title": "DHL eCommerce (Benelux) for WooCommerce <= 2.2.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shipping Label Creation and Deletion via dhlpwc_label_create and dhlpwc_label_delete AJAX Actions",
      "affected": {
        "vendors": [
          "dhlparcel"
        ],
        "products": [
          {
            "vendor": "dhlparcel",
            "product": "DHL eCommerce (Benelux) for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09542
      },
      "nvd": {
        "published": "2026-07-09T11:16:42.250",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9235",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Shipping-label AJAX handlers accept any subscriber and caller-supplied order ID without capability, nonce, or per-order authority checks.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b5e0af52-3e38-4ff4-b53c-c7c35f1b956a?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dhlpwc/tags/2.2.3/includes/controller/admin/class-dhlpwc-controller-admin-order-metabox.php#L164",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dhlpwc/tags/2.2.3/includes/controller/admin/class-dhlpwc-controller-admin-order-metabox.php#L117",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dhlpwc/tags/2.2.3/includes/controller/admin/class-dhlpwc-controller-admin-order-metabox.php#L25",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3575375%40dhlpwc&new=3575375%40dhlpwc",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 627,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9237",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:50:12.010Z",
      "date_published": "2026-07-09T09:31:22.661Z",
      "date_updated": "2026-07-09T17:21:17.258Z",
      "publisher": "Wordfence",
      "title": "Employee, Leave and Recruitment Management System <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Job Deletion via crewhrm_singleJobAction AJAX Action",
      "affected": {
        "vendors": [
          "crewhrm"
        ],
        "products": [
          {
            "vendor": "crewhrm",
            "product": "Employee, Leave and Recruitment Management System – Crew HRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13489
      },
      "nvd": {
        "published": "2026-07-09T11:16:42.370",
        "lastModified": "2026-07-09T18:16:58.397",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9237",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A subscriber can obtain the nonce and supply an arbitrary job_id because the action omits a capability check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/be30e951-7c8d-4baf-9288-0d12dacc0dc2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hr-management/tags/1.2.2/classes/Controllers/JobManagement.php#L151",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hr-management/tags/1.2.2/classes/Controllers/JobManagement.php#L29",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hr-management/tags/1.2.2/classes/Setup/Dispatcher.php#L123",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hr-management/tags/1.2.2/classes/Models/User.php#L73",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hr-management/tags/1.2.2/classes/Setup/Dispatcher.php#L139",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3556031%40hr-management&new=3556031%40hr-management",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 785,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9240",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:54:54.933Z",
      "date_published": "2026-07-09T09:31:19.718Z",
      "date_updated": "2026-07-09T14:37:58.884Z",
      "publisher": "Wordfence",
      "title": "Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Modification via lpc_order_affect AJAX action",
      "affected": {
        "vendors": [
          "iscpcolissimo"
        ],
        "products": [
          {
            "vendor": "iscpcolissimo",
            "product": "Colissimo shipping methods for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09541
      },
      "nvd": {
        "published": "2026-07-09T11:16:42.483",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9240",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "updateShippingMethod accepts an arbitrary order_id without a capability check or nonce and changes another user's shipment data.",
        "basis": [
          "CNA record",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/16041d22-51ff-4fa4-99fb-20a60b557634?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/colissimo-shipping-methods-for-woocommerce/tags/2.9.0/admin/orders/lpc_admin_order_affect.php#L84",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/colissimo-shipping-methods-for-woocommerce/tags/2.9.0/admin/orders/lpc_admin_order_affect.php#L52",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/colissimo-shipping-methods-for-woocommerce/tags/2.9.0/admin/orders/lpc_admin_order_affect.php#L85",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3553367%40colissimo-shipping-methods-for-woocommerce&new=3553367%40colissimo-shipping-methods-for-woocommerce",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 808,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9253",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T20:17:35.673Z",
      "date_published": "2026-07-09T11:27:25.545Z",
      "date_updated": "2026-07-09T13:47:59.993Z",
      "publisher": "Wordfence",
      "title": "WP Cost Estimation & Payment Forms Builder (E&P Forms) <= 10.5.97 - Unauthenticated Stored Cross-Site Scripting via 'customerInfos' Parameter",
      "affected": {
        "vendors": [
          "loopus"
        ],
        "products": [
          {
            "vendor": "loopus",
            "product": "WP Cost Estimation & Payment Forms Builder"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10555
      },
      "nvd": {
        "published": "2026-07-09T12:16:25.630",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9253",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WP Cost Estimation & Payment Forms Builder renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2bf0832c-13ed-4e53-9847-d5d2110eb3f8?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.loopus-plugins.com/plugins/wp-cost-estimation-payments-forms",
          "host": "www.loopus-plugins.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-9272",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T10:44:21.456Z",
      "date_published": "2026-07-02T14:02:51.273Z",
      "date_updated": "2026-07-03T03:56:00.966Z",
      "publisher": "ProgressSoftware",
      "title": "Possibility of unintended database operations when querying data related to detected anomalies in Progress Flowmon ADS",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Flowmon ADS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16669
      },
      "nvd": {
        "published": "2026-07-02T15:17:11.937",
        "lastModified": "2026-07-07T16:37:11.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9272",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Flowmon ADS accepts crafted low-privilege request values as SQL syntax, allowing unauthorized database reads and modifications.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.progress.com/s/article/Flowmon-CVE-2026-9272",
          "host": "community.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 307,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-9282",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T14:24:54.137Z",
      "date_published": "2026-07-11T06:50:33.051Z",
      "date_updated": "2026-07-14T14:29:14.909Z",
      "publisher": "Wordfence",
      "title": "W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter",
      "affected": {
        "vendors": [
          "boldgrid"
        ],
        "products": [
          {
            "vendor": "boldgrid",
            "product": "W3 Total Cache"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02773,
        "percentile": 0.84918
      },
      "nvd": {
        "published": "2026-07-11T07:16:47.070",
        "lastModified": "2026-07-14T15:17:11.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9282",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "W3 Total Cache passes f_array paths to setupSources without confining them to the minify source root, allowing arbitrary local file reads.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e92cc06d-006f-4bba-a4ef-b23d80c00085?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.9.4/lib/Minify/Minify/Controller/MinApp.php#L163",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.9.4/lib/Minify/Minify/Controller/MinApp.php#L109",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.9.4/Minify_MinifiedFileRequestHandler.php#L191",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.9.4/Minify_Plugin.php#L132",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3585227%40w3-total-cache&new=3585227%40w3-total-cache",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9292",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T17:18:30.808Z",
      "date_published": "2026-07-14T15:05:37.008Z",
      "date_updated": "2026-07-14T15:53:41.359Z",
      "publisher": "Rockwell",
      "title": "Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site Scripting",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "FactoryTalk® DataMosaix™ Private Cloud"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00329,
        "percentile": 0.25433
      },
      "nvd": {
        "published": "2026-07-14T16:17:05.723",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9292",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1787.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9322",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:50:36.998Z",
      "date_published": "2026-07-30T16:13:03.775Z",
      "date_updated": "2026-07-30T18:00:19.093Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          },
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22833
      },
      "nvd": {
        "published": "2026-07-30T17:16:34.580",
        "lastModified": "2026-07-30T19:18:37.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9322",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A crafted HTTP request consumes an undisclosed WebSphere resource until the service becomes unavailable.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278576",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 184,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-9323",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:56:42.239Z",
      "date_published": "2026-07-18T13:51:06.021Z",
      "date_updated": "2026-07-20T19:31:48.456Z",
      "publisher": "VulnCheck",
      "title": "Insecure PRNG and Information Exposure in urwid Web Display Backend",
      "affected": {
        "vendors": [
          "urwid"
        ],
        "products": [
          {
            "vendor": "urwid",
            "product": "urwid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00421,
        "percentile": 0.3463
      },
      "nvd": {
        "published": "2026-07-18T14:17:12.170",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9323",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The urwid session path derives security tokens from a predictable non-cryptographic random generator.",
        "basis": [
          "CNA",
          "CWE-338"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/urwid/urwid/security/advisories/GHSA-rjwp-g85x-gmjv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/urwid/urwid",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/urwid/urwid/commit/24acd12f0d0598036d0d577f2ee63e4a27b4a3d9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/urwid/urwid/issues/1127",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/urwid/urwid/pull/1128",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/insecure-prng-and-information-exposure-in-urwid-web-display-backend",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1245,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9341",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-23T00:27:13.206Z",
      "date_published": "2026-07-14T11:30:42.783Z",
      "date_updated": "2026-07-14T12:45:22.307Z",
      "publisher": "Wordfence",
      "title": "Academy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'user_id' Parameter",
      "affected": {
        "vendors": [
          "kodezen"
        ],
        "products": [
          {
            "vendor": "kodezen",
            "product": "Academy LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17052
      },
      "nvd": {
        "published": "2026-07-14T12:17:14.793",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9341",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Lesson-note and completion handlers trust a user_id without verifying that it identifies the authenticated user.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1e9b094a-29ba-4be3-9033-fd915fae1820?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/academy/tags/3.7.4/includes/ajax/lesson.php#L258",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/academy/tags/3.7.4/includes/ajax/lesson.php#L253",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/academy/tags/3.7.4/includes/ajax/lesson.php#L300",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/academy/tags/3.7.4/includes/classes/abstract-ajax-handler.php#L46",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3573111/",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-25T02:48:23.519Z",
      "date_published": "2026-07-13T03:41:32.750Z",
      "date_updated": "2026-07-14T14:33:18.053Z",
      "publisher": "twcert",
      "title": "GIGABYTE｜Gigabyte Control Center  - Improper Access Control",
      "affected": {
        "vendors": [
          "GIGABYTE"
        ],
        "products": [
          {
            "vendor": "GIGABYTE",
            "product": "MBStorage"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-782",
          "name": "Exposed IOCTL with Insufficient Access Control",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00109,
        "percentile": 0.0143
      },
      "nvd": {
        "published": "2026-07-13T04:16:29.283",
        "lastModified": "2026-07-14T15:17:11.123",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9492",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MBStorage driver exposes IOCTL operations that let a local caller read and write arbitrary physical memory without an adequate hardware-access check.",
        "basis": [
          "CNA",
          "CWE-782"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.twcert.org.tw/tw/cp-132-11033-97316-1.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.twcert.org.tw/en/cp-139-11034-f7f2f-2.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9494",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-25T08:23:24.573Z",
      "date_published": "2026-07-16T12:12:27.447Z",
      "date_updated": "2026-07-16T15:11:07.229Z",
      "publisher": "canonical",
      "title": "ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line",
      "affected": {
        "vendors": [
          "Canonical"
        ],
        "products": [
          {
            "vendor": "Canonical",
            "product": "ubuntu-pro-client (ubuntu-advantage-tools)"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 26.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 24.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 22.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 20.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 18.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 16.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 14.04 LTS"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-214",
          "name": "Invocation of Process Using Visible Sensitive Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@ubuntu.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01675
      },
      "nvd": {
        "published": "2026-07-16T13:16:34.520",
        "lastModified": "2026-07-16T16:19:16.463",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9494",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ubuntu-pro-client places the repository bearer token in apt-helper command-line arguments visible through the process list.",
        "basis": [
          "CNA",
          "CWE-214"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://ubuntu.com/security/CVE-2026-9494",
          "host": "ubuntu.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 894,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-9499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-25T09:55:56.600Z",
      "date_published": "2026-07-21T13:25:27.477Z",
      "date_updated": "2026-07-22T18:28:22.217Z",
      "publisher": "TQtC",
      "title": "Out-of-bounds read in QTextCodec::codecForName() in Qt",
      "affected": {
        "vendors": [
          "Qt"
        ],
        "products": [
          {
            "vendor": "Qt",
            "product": "Qt"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:a59d8014-47c4-4630-ab43-e1b13cbe58e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22417
      },
      "nvd": {
        "published": "2026-07-21T14:16:35.843",
        "lastModified": "2026-07-23T15:25:49.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9499",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Qt, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://codereview.qt-project.org/c/qt/qt5compat/+/723911",
          "host": "codereview.qt-project.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://codereview.qt-project.org/c/qt/qt5compat/+/724348",
          "host": "codereview.qt-project.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://codereview.qt-project.org/c/qt/qt5compat/+/724995",
          "host": "codereview.qt-project.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://codereview.qt-project.org/c/qt/tqtc-qt5compat/+/725112",
          "host": "codereview.qt-project.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 916,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-9537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-25T20:46:44.842Z",
      "date_published": "2026-07-17T15:29:58.088Z",
      "date_updated": "2026-07-20T19:37:04.413Z",
      "publisher": "CPANSec",
      "title": "Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison",
      "affected": {
        "vendors": [
          "JBERGER"
        ],
        "products": [
          {
            "vendor": "JBERGER",
            "product": "Mojo::JWT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13668
      },
      "nvd": {
        "published": "2026-07-17T16:17:20.417",
        "lastModified": "2026-07-20T20:16:47.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9537",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mojo::JWT compares HMAC signatures with a data-dependent string comparison that leaks matching-prefix length through timing.",
        "basis": [
          "CNA",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jberger/Mojo-JWT/commit/b8aefb846613e44b5b12bc170898ffd5b05094a2.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/17/11",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9545",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T06:45:08.680Z",
      "date_published": "2026-07-03T06:17:55.931Z",
      "date_updated": "2026-07-06T16:53:23.396Z",
      "publisher": "curl",
      "title": "exposing HTTP/3 early data",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18822
      },
      "nvd": {
        "published": "2026-07-03T07:16:25.807",
        "lastModified": "2026-07-07T15:03:56.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9545",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "With HTTP/3 early data and a cached session, libcurl can transmit the next request before enforcing certificate failure on a replacement server.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-9545.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-9545.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3752888",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 616,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-9546",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T06:45:18.723Z",
      "date_published": "2026-07-03T06:18:14.447Z",
      "date_updated": "2026-07-06T16:51:49.410Z",
      "publisher": "curl",
      "title": "sending old referer",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00399,
        "percentile": 0.32663
      },
      "nvd": {
        "published": "2026-07-03T07:16:25.893",
        "lastModified": "2026-07-07T14:53:26.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9546",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "curl carries a Referer value from one request state into a later request after the value should have been cleared.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-9546.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-9546.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3754343",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-9547",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T06:45:27.665Z",
      "date_published": "2026-07-03T06:18:44.499Z",
      "date_updated": "2026-07-06T16:48:14.469Z",
      "publisher": "curl",
      "title": "SSH improper host validation",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 57,
        "versionRangeCount": 57,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-297",
          "name": "Improper Validation of Certificate with Host Mismatch",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00325,
        "percentile": 0.25019
      },
      "nvd": {
        "published": "2026-07-03T07:16:25.990",
        "lastModified": "2026-07-07T14:52:29.503",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9547",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SSH host-key callback accepts a server key whose type differs from the key type recorded for that host instead of rejecting the mismatch.",
        "basis": [
          "CNA",
          "CWE-297"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-9547.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-9547.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3751712",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 541,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 57
      }
    },
    {
      "cve_id": "CVE-2026-9561",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T10:32:07.026Z",
      "date_published": "2026-07-14T07:59:20.706Z",
      "date_updated": "2026-07-14T12:22:02.042Z",
      "publisher": "eclipse",
      "title": "Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provi...",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Kura"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-348",
          "name": "Use of Less Trusted Source",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-807",
          "name": "Reliance on Untrusted Inputs in a Security Decision",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10593
      },
      "nvd": {
        "published": "2026-07-14T09:16:42.180",
        "lastModified": "2026-07-14T16:38:41.077",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9561",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kura treats client-supplied X-Forwarded-For as the authoritative remote address on connectors that are not restricted to a trusted proxy.",
        "basis": [
          "CNA",
          "CWE-345",
          "CWE-348",
          "CWE-807"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/117",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 925,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9563",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T10:34:17.499Z",
      "date_published": "2026-07-02T07:33:25.218Z",
      "date_updated": "2026-07-02T12:27:25.923Z",
      "publisher": "eclipse",
      "title": "In Eclipse Parsson published Maven Central artifacts before version 1.",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Parsson"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27231
      },
      "nvd": {
        "published": "2026-07-02T09:16:19.247",
        "lastModified": "2026-07-02T17:44:12.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9563",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Parsson parses an attacker-controlled JSON document without a default maximum on total consumed characters, CPU work, or memory.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/eclipse-ee4j/parsson/pull/169",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://repo.maven.apache.org/maven2/org/eclipse/parsson/parsson/1.1.8/",
          "host": "repo.maven.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/eclipse-ee4j/parsson/tree/1.1.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/444",
          "host": "gitlab.eclipse.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 587,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9571",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T11:52:27.228Z",
      "date_published": "2026-07-13T07:50:55.793Z",
      "date_updated": "2026-07-15T04:00:07.436Z",
      "publisher": "Mattermost",
      "title": "Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-305",
          "name": "Authentication Bypass by Primary Weakness",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07077
      },
      "nvd": {
        "published": "2026-07-13T09:16:25.017",
        "lastModified": "2026-07-15T05:17:25.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9571",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mattermost deactivates an account without revoking its OAuth refresh tokens, so the stale token can mint new access tokens after deactivation.",
        "basis": [
          "CNA",
          "CWE-305"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-9577",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T12:45:31.927Z",
      "date_published": "2026-07-23T06:00:03.344Z",
      "date_updated": "2026-07-23T14:11:39.035Z",
      "publisher": "WPScan",
      "title": "Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Post Status Notifier Lite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04003
      },
      "nvd": {
        "published": "2026-07-23T07:16:32.933",
        "lastModified": "2026-07-23T15:18:19.363",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9577",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The mod URL parameter is reflected into the administrator settings page without output escaping and executes as browser script when the crafted URL is opened.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/b316e14a-4260-43c4-996c-345c7f9f7d74/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9585",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T13:03:29.116Z",
      "date_published": "2026-07-17T15:56:32.969Z",
      "date_updated": "2026-07-17T16:39:14.113Z",
      "publisher": "SRA",
      "title": "Unauthenticated Reflected Cross-Site Scripting (XSS) in Switchvox SMB Web Portal",
      "affected": {
        "vendors": [
          "Sangoma"
        ],
        "products": [
          {
            "vendor": "Sangoma",
            "product": "Switchvox SMB Edition"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:57dba5dd-1a03-47f6-8b36-e84e47d335d8",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25253
      },
      "nvd": {
        "published": "2026-07-17T17:17:17.990",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9585",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Switchvox SMB Edition page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026",
          "host": "sangomakb.atlassian.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://labs.sra.io/posts/switchvox/",
          "host": "labs.sra.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 414,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9586",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T13:03:30.901Z",
      "date_published": "2026-07-17T15:57:42.879Z",
      "date_updated": "2026-07-17T16:43:09.809Z",
      "publisher": "SRA",
      "title": "Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB",
      "affected": {
        "vendors": [
          "Sangoma"
        ],
        "products": [
          {
            "vendor": "Sangoma",
            "product": "Switchvox SMB Edition"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:57dba5dd-1a03-47f6-8b36-e84e47d335d8",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00411,
        "percentile": 0.33762
      },
      "nvd": {
        "published": "2026-07-17T17:17:18.150",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9586",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pa endpoint concatenates the XML PhoneIP value directly into PostgreSQL statements without parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026",
          "host": "sangomakb.atlassian.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://labs.sra.io/posts/switchvox/",
          "host": "labs.sra.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 498,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9587",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T13:03:31.955Z",
      "date_published": "2026-07-17T15:58:25.588Z",
      "date_updated": "2026-07-17T16:42:37.099Z",
      "publisher": "SRA",
      "title": "Authenticated Local File Inclusion (LFI) in Switchvox SMB Web Portal",
      "affected": {
        "vendors": [
          "Sangoma"
        ],
        "products": [
          {
            "vendor": "Sangoma",
            "product": "Switchvox SMB Edition"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:57dba5dd-1a03-47f6-8b36-e84e47d335d8",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.1378
      },
      "nvd": {
        "published": "2026-07-17T17:17:18.280",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9587",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file operation in Switchvox SMB Edition uses an attacker-controlled path without confining the resolved object to the intended namespace.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sangoma/security-switchvox/security/advisories/GHSA-mhp4-x83p-phh2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://labs.sra.io/posts/switchvox/",
          "host": "labs.sra.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 394,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9588",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T13:03:32.678Z",
      "date_published": "2026-07-17T15:59:23.107Z",
      "date_updated": "2026-07-17T16:42:08.470Z",
      "publisher": "SRA",
      "title": "Authenticated Stored Cross-Site Scripting (XSS) in Switchvox SMB Web Portal",
      "affected": {
        "vendors": [
          "Sangoma"
        ],
        "products": [
          {
            "vendor": "Sangoma",
            "product": "Switchvox SMB Edition"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:H/VA:N/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:57dba5dd-1a03-47f6-8b36-e84e47d335d8",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:H/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15072
      },
      "nvd": {
        "published": "2026-07-17T17:17:18.413",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9588",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Switchvox SMB Edition places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026",
          "host": "sangomakb.atlassian.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://labs.sra.io/posts/switchvox/",
          "host": "labs.sra.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9592",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T13:55:29.125Z",
      "date_published": "2026-07-17T13:51:54.486Z",
      "date_updated": "2026-07-17T15:24:58.669Z",
      "publisher": "NCSC.ch",
      "title": "Sensitive Information Disclosure in HTTP header",
      "affected": {
        "vendors": [
          "SEPPmail"
        ],
        "products": [
          {
            "vendor": "SEPPmail",
            "product": "SEPPmail Secure Email Gateway & SEPPmail Cloud"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-598",
          "name": "Use of HTTP Request With Sensitive Query String",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04981
      },
      "nvd": {
        "published": "2026-07-17T14:17:27.657",
        "lastModified": "2026-07-17T18:11:59.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9592",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The GINA portal places its reusable session token in a URL and HTTP header where another observer can capture and replay it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-598"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html#remove-login-redirect-to-prevent-disclosure-of-session-token-information",
          "host": "downloads.seppmail.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9597",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T15:15:14.343Z",
      "date_published": "2026-07-13T08:17:36.717Z",
      "date_updated": "2026-07-13T13:55:15.448Z",
      "publisher": "Mattermost",
      "title": "Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-305",
          "name": "Authentication Bypass by Primary Weakness",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00141,
        "percentile": 0.0387
      },
      "nvd": {
        "published": "2026-07-13T09:16:25.137",
        "lastModified": "2026-07-13T20:53:34.213",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9597",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mattermost creates a magic-link session without rechecking that the guest account was deactivated after the token was issued.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-305"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 339,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-9602",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T15:42:07.316Z",
      "date_published": "2026-07-17T10:03:26.292Z",
      "date_updated": "2026-07-17T12:54:25.366Z",
      "publisher": "Mattermost",
      "title": "Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15183
      },
      "nvd": {
        "published": "2026-07-17T11:17:15.297",
        "lastModified": "2026-07-30T14:38:53.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9602",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "A malformed IPC payload crashes the component, but the record does not identify a bound, lifetime error, parser transition, or other cause.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-9626",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T17:20:23.199Z",
      "date_published": "2026-07-03T04:30:19.039Z",
      "date_updated": "2026-07-06T16:35:54.457Z",
      "publisher": "Wordfence",
      "title": "JSON API User <= 4.1.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'content' Parameter",
      "affected": {
        "vendors": [
          "parorrey"
        ],
        "products": [
          {
            "vendor": "parorrey",
            "product": "JSON API User"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12779
      },
      "nvd": {
        "published": "2026-07-03T06:16:23.123",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9626",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "post_comment passes caller-controlled comment_content to storage without HTML sanitization and allows the caller to self-approve the stored script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c41b0370-2881-4053-98b1-9c70251a3b63?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/json-api-user/tags/4.1.0/controllers/User.php#L1007",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/json-api-user/tags/4.1.0/controllers/User.php#L995",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/json-api-user/tags/4.1.0/controllers/User.php#L979",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3576431/json-api-user/trunk/controllers/User.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fjson-api-user/tags/4.1.0&new_path=%2Fjson-api-user/tags/4.1.2",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 700,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9635",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T17:55:37.764Z",
      "date_published": "2026-07-23T06:52:34.356Z",
      "date_updated": "2026-07-23T14:01:09.824Z",
      "publisher": "Wordfence",
      "title": "WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute",
      "affected": {
        "vendors": [
          "mythemeshop"
        ],
        "products": [
          {
            "vendor": "mythemeshop",
            "product": "WP Shortcode by MyThemeShop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08554
      },
      "nvd": {
        "published": "2026-07-23T08:16:25.253",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9635",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WP Shortcode stores the tab title parameter and later renders it as active browser markup without sufficient sanitization and escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6f3bcf70-2900-4a13-9ed4-264a15af9725?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-shortcode/trunk/wp-shortcode.php#L774",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-shortcode/trunk/wp-shortcode.php#L766",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 613,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9636",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T18:10:55.329Z",
      "date_published": "2026-07-14T15:11:42.995Z",
      "date_updated": "2026-07-14T15:55:05.004Z",
      "publisher": "Rockwell",
      "title": "Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Module – Certificate Revocation List Vulnerability",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "ControlLogix® 5580, CompactLogix® 5380, GuardLogix® 5580, Compact GuardLogix® 5380, 1756-EN4TR"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-299",
          "name": "Improper Check for Certificate Revocation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03789
      },
      "nvd": {
        "published": "2026-07-14T16:17:05.860",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9636",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The controller accepts a certificate chain after the intermediate CA appears on the certificate revocation list.",
        "basis": [
          "CNA",
          "CWE-299"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1788.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 505,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9653",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T20:07:05.996Z",
      "date_published": "2026-07-14T15:00:06.196Z",
      "date_updated": "2026-07-14T15:25:27.797Z",
      "publisher": "Rockwell",
      "title": "1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "1756-EN2, 1756-EN3"
          },
          {
            "vendor": "Rockwell Automation",
            "product": "1756-ENBT"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-354",
          "name": "Improper Validation of Integrity Check Value",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07527
      },
      "nvd": {
        "published": "2026-07-14T15:17:11.347",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9653",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets.",
        "basis": [
          "CNA",
          "CWE-354"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1780.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-9656",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T20:23:14.339Z",
      "date_published": "2026-07-17T06:53:26.239Z",
      "date_updated": "2026-07-17T11:59:46.332Z",
      "publisher": "Wordfence",
      "title": "HubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script",
      "affected": {
        "vendors": [
          "hubspotdev"
        ],
        "products": [
          {
            "vendor": "hubspotdev",
            "product": "HubSpot All-In-One Marketing – Forms, Popups, Live Chat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05441
      },
      "nvd": {
        "published": "2026-07-17T08:16:59.043",
        "lastModified": "2026-07-17T14:59:38.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9656",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The plugin decrypts its HubSpot refresh token and embeds the plaintext value in a block-editor JavaScript object visible to contributors.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/718d7ea3-d8ba-46a0-9ab1-72657bd82c17?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/leadin/tags/11.3.45/public/admin/class-adminconstants.php#L190",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/leadin/tags/11.3.45/public/auth/class-oauth.php#L46",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/leadin/tags/11.3.45/public/admin/class-gutenberg.php#L44",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/leadin/tags/11.3.45/public/class-assetsmanager.php#L150",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fleadin/tags/11.3.62&new_path=%2Fleadin/tags/11.3.64",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 772,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9680",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T09:18:25.851Z",
      "date_published": "2026-07-28T09:05:30.652Z",
      "date_updated": "2026-07-28T16:08:06.668Z",
      "publisher": "alibaba",
      "title": "MCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-mcp-server",
      "affected": {
        "vendors": [
          "Alibaba"
        ],
        "products": [
          {
            "vendor": "Alibaba",
            "product": "Alibaba Cloud RDS OpenAPI MCP Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:alibaba-cna@list.alibaba-inc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15235
      },
      "nvd": {
        "published": "2026-07-28T09:16:42.830",
        "lastModified": "2026-07-28T20:35:20.590",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9680",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MCP server listens on all interfaces by default and exposes tool invocation to remote network callers without an explicit deployment opt-in.",
        "basis": [
          "CNA",
          "CWE-1188"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aliyun/alibabacloud-rds-openapi-mcp-server",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 212,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T11:13:55.994Z",
      "date_published": "2026-07-08T05:58:50.169Z",
      "date_updated": "2026-07-08T13:46:26.318Z",
      "publisher": "3DS",
      "title": "Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026",
      "affected": {
        "vendors": [
          "Dassault Systèmes"
        ],
        "products": [
          {
            "vendor": "Dassault Systèmes",
            "product": "DELMIA Apriso"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:3DS.Information-Security@3ds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27094
      },
      "nvd": {
        "published": "2026-07-08T07:16:46.870",
        "lastModified": "2026-07-08T15:30:04.497",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9695",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "DELMIA Apriso permits privileged server access through an undisclosed authentication failure affecting releases 2020 through 2026.",
        "basis": [
          "CNA",
          "CWE-287",
          "https://www.3ds.com/trust-center/security/security-advisories/cve-2026-9695"
        ],
        "deepDive": true,
        "notes": "The Dassault Systèmes advisory confirms the affected release range and critical severity but provides no authentication flow, endpoint, or remediation detail outside its gated support link."
      },
      "references": [
        {
          "url": "https://www.3ds.com/trust-center/security/security-advisories/cve-2026-9695",
          "host": "www.3ds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 168,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-9700",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T12:17:05.351Z",
      "date_published": "2026-07-08T05:34:08.504Z",
      "date_updated": "2026-07-08T13:58:51.010Z",
      "publisher": "Wordfence",
      "title": "Eventer <= 4.4.2 - Unauthenticated SQL Injection via 'code' Parameter",
      "affected": {
        "vendors": [
          "joe007"
        ],
        "products": [
          {
            "vendor": "joe007",
            "product": "Eventer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19423
      },
      "nvd": {
        "published": "2026-07-08T06:16:23.043",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9700",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Eventer places the caller-controlled code parameter into an existing SQL query without sufficient escaping or parameter preparation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5e3b0a3a-ce4b-40fd-9519-a81e315cee42?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://codecanyon.net/item/eventer-wordpress-event-manager-plugin/20972534",
          "host": "codecanyon.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 451,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9701",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T12:25:20.268Z",
      "date_published": "2026-07-08T04:30:50.562Z",
      "date_updated": "2026-07-08T17:10:20.940Z",
      "publisher": "Wordfence",
      "title": "Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation",
      "affected": {
        "vendors": [
          "joe007"
        ],
        "products": [
          {
            "vendor": "joe007",
            "product": "Eventer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-289",
          "name": "Authentication Bypass by Alternate Name",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20466
      },
      "nvd": {
        "published": "2026-07-08T05:16:28.977",
        "lastModified": "2026-07-08T18:16:35.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9701",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The plugin stores a password-reset key in plaintext user metadata and accepts that extracted key to reset any selected account.",
        "basis": [
          "CNA",
          "CWE-289"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bc656765-1eac-4a96-99e9-c22d64984923?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://codecanyon.net/item/eventer-wordpress-event-manager-plugin/20972534",
          "host": "codecanyon.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 699,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9708",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T13:46:27.399Z",
      "date_published": "2026-07-13T08:00:10.707Z",
      "date_updated": "2026-07-13T14:45:16.207Z",
      "publisher": "Mattermost",
      "title": "Incoming webhook user attribution via unvalidated webhook owner",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11319
      },
      "nvd": {
        "published": "2026-07-13T09:16:25.253",
        "lastModified": "2026-07-13T20:39:47.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9708",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Webhook authorization is not bound to the target team and channel selected by the caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 394,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-9713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T14:53:54.122Z",
      "date_published": "2026-07-23T06:52:34.967Z",
      "date_updated": "2026-07-23T14:54:58.178Z",
      "publisher": "Wordfence",
      "title": "Product Designer for WooCommerce WordPress | Lumise <= 2.1.1 - Unauthenticated SQL Injection via 'id' Parameter in Cart JSON Upload",
      "affected": {
        "vendors": [
          "King-Theme"
        ],
        "products": [
          {
            "vendor": "King-Theme",
            "product": "Product Designer for WooCommerce WordPress | Lumise"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19462
      },
      "nvd": {
        "published": "2026-07-23T08:16:25.390",
        "lastModified": "2026-07-23T16:17:55.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9713",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Uploaded cart JSON supplies id and table values that find_resource concatenates directly into SQL identifier and numeric contexts.",
        "basis": [
          "CNA record",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ee7555a1-18dc-4b00-81f6-b26706cfb573?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://codecanyon.net/item/lumise-product-designer-woocommerce-wordpress/21222684",
          "host": "codecanyon.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 801,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9720",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T16:07:07.814Z",
      "date_published": "2026-07-29T07:48:03.195Z",
      "date_updated": "2026-07-29T12:21:45.437Z",
      "publisher": "Wordfence",
      "title": "Facturación Electrónica Costa Rica <= 2.0.2 - Cross-Site Request Forgery to Plugin Settings Update",
      "affected": {
        "vendors": [
          "facturadorvirtual"
        ],
        "products": [
          {
            "vendor": "facturadorvirtual",
            "product": "Facturación Electrónica Costa Rica"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02855
      },
      "nvd": {
        "published": "2026-07-29T09:16:30.670",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9720",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The settings handler lacks a valid nonce check and therefore accepts an administrator's forged cross-site configuration request.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/644e2267-c90b-4517-8ded-f2b7c7ec3d27?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/factura-electronica-cr/trunk/admin/configuration.php#L87",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/factura-electronica-cr/trunk/admin/configuration.php#L52",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/factura-electronica-cr/trunk/functions.php#L17",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 630,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9725",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T16:25:00.857Z",
      "date_published": "2026-07-03T04:30:17.688Z",
      "date_updated": "2026-07-07T17:01:23.459Z",
      "publisher": "Wordfence",
      "title": "Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File Deletion",
      "affected": {
        "vendors": [
          "printcart"
        ],
        "products": [
          {
            "vendor": "printcart",
            "product": "Printcart Web to Print Product Designer for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00742,
        "percentile": 0.51142
      },
      "nvd": {
        "published": "2026-07-03T06:16:23.263",
        "lastModified": "2026-07-07T18:16:40.690",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9725",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "store_design_data builds a deletion path from nbd_item_key without removing traversal sequences and passes it to recursive deletion.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5bb962bd-9b23-4820-885e-d8095250c3c7?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/printcart-integration/tags/2.4.8/includes/class.nbdesigner.php#L3246",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/printcart-integration/tags/2.4.8/includes/class.nbdesigner.php#L3698",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/printcart-integration/tags/2.4.8/includes/class.nbdesigner.php#L214",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3593521/printcart-integration/trunk/includes/class.nbdesigner.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fprintcart-integration/tags/2.5.2&new_path=%2Fprintcart-integration/tags/2.5.3",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 817,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9726",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T16:44:28.109Z",
      "date_published": "2026-07-10T20:56:18.519Z",
      "date_updated": "2026-07-14T14:35:25.036Z",
      "publisher": "drupal",
      "title": "Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Drupal AlternativeCommerce (Basket)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23732
      },
      "nvd": {
        "published": "2026-07-10T21:17:00.737",
        "lastModified": "2026-07-14T15:17:11.463",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9726",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AlternativeCommerce permits attacker-controlled dynamic object attributes to instantiate or modify objects outside the intended object model.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-038",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T17:22:45.590Z",
      "date_published": "2026-07-23T06:52:33.814Z",
      "date_updated": "2026-07-23T16:04:51.114Z",
      "publisher": "Wordfence",
      "title": "Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'webpushr_notification_title' Post Meta Parameter",
      "affected": {
        "vendors": [
          "webpushr"
        ],
        "products": [
          {
            "vendor": "webpushr",
            "product": "Web Push Notifications – Webpushr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09241
      },
      "nvd": {
        "published": "2026-07-23T08:16:25.540",
        "lastModified": "2026-07-23T16:17:55.250",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9729",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/39286096-2efa-450b-b491-b3d40de5a4ae?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/webpushr-web-push-notifications/trunk/include/webpushr_functions.php#L513",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/webpushr-web-push-notifications/trunk/include/webpushr_functions.php#L517",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/webpushr-web-push-notifications/trunk/include/webpushr_functions.php#L699",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/webpushr-web-push-notifications/trunk/include/webpushr_functions.php#L702",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 669,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T17:24:04.304Z",
      "date_published": "2026-07-08T05:34:09.583Z",
      "date_updated": "2026-07-08T13:13:20.460Z",
      "publisher": "Wordfence",
      "title": "Wp Js Detect <= 1.0.9 - Cross-Site Request Forgery to Plugin Settings Update",
      "affected": {
        "vendors": [
          "wpkuf"
        ],
        "products": [
          {
            "vendor": "wpkuf",
            "product": "Wp Js Detect"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02854
      },
      "nvd": {
        "published": "2026-07-08T06:16:23.217",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9731",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "plugin_settings changes notification content and CSS without a valid nonce, allowing a cross-site request sent with an administrator's session to update settings.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/afca7b14-f3bb-4612-b81c-bde120b380ba?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-js-detect/trunk/wp-js-detect.php#L193",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-js-detect/trunk/wp-js-detect.php#L192",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-js-detect/trunk/wp-js-detect.php#L190",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-js-detect/trunk/wp-js-detect.php#L250",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9734",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T17:26:17.005Z",
      "date_published": "2026-07-18T04:31:44.467Z",
      "date_updated": "2026-07-22T16:09:10.179Z",
      "publisher": "Wordfence",
      "title": "W3SC Elementor to Zoho CRM <= 2.2.0 - Cross-Site Request Forgery to Settings Update",
      "affected": {
        "vendors": [
          "w3scloud"
        ],
        "products": [
          {
            "vendor": "w3scloud",
            "product": "W3SC Elementor to Zoho CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05281
      },
      "nvd": {
        "published": "2026-07-18T05:16:56.570",
        "lastModified": "2026-07-22T17:16:59.700",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9734",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The storeInfo action accepts a settings-changing request without a valid nonce, allowing a lure to submit attacker-controlled Zoho credentials in an administrator's session.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b99ba627-1d24-4be1-a4db-ff39354526f2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/w3sc-elementor-to-zoho/trunk/includes/Admin/Authdata.php#L38",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/w3sc-elementor-to-zoho/trunk/includes/Admin/Setting.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/w3sc-elementor-to-zoho/trunk/includes/Admin/Authdata.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T17:29:34.842Z",
      "date_published": "2026-07-22T19:20:40.529Z",
      "date_updated": "2026-07-23T14:24:12.843Z",
      "publisher": "mongodb",
      "title": "Find command with $meta sort can lead to crash",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14472
      },
      "nvd": {
        "published": "2026-07-22T20:17:09.863",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9737",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Query planning fails to handle a $meta sort expression in raw BSON and performs an invalid transformation that reaches an invariant failure.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-128341",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-9738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T17:30:12.106Z",
      "date_published": "2026-07-11T03:44:22.090Z",
      "date_updated": "2026-07-13T17:38:39.391Z",
      "publisher": "Wordfence",
      "title": "Print, PDF, Email by PrintFriendly <= 5.5.10 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'content_position_css' Parameter",
      "affected": {
        "vendors": [
          "printfriendly"
        ],
        "products": [
          {
            "vendor": "printfriendly",
            "product": "Print, PDF & Email by PrintFriendly"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11053
      },
      "nvd": {
        "published": "2026-07-11T05:16:34.910",
        "lastModified": "2026-07-13T18:16:30.930",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9738",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Print, PDF & Email by PrintFriendly rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/43d54cb5-7813-4d30-a081-db84e0d29030?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/printfriendly/tags/5.5.10/pf.php#L367",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/printfriendly/tags/5.5.10/pf.php#L681",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/printfriendly/tags/5.5.10/pf.php#L391",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/printfriendly/tags/5.5.8/pf.php#L367",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/printfriendly/tags/5.5.8/pf.php#L681",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/printfriendly/tags/5.5.8/pf.php#L391",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3590593%40printfriendly&new=3590593%40printfriendly",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T17:55:22.344Z",
      "date_published": "2026-07-03T07:53:09.591Z",
      "date_updated": "2026-07-06T15:31:49.905Z",
      "publisher": "Wordfence",
      "title": "GenerateBlocks <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute",
      "affected": {
        "vendors": [
          "edge22"
        ],
        "products": [
          {
            "vendor": "edge22",
            "product": "GenerateBlocks"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.10003
      },
      "nvd": {
        "published": "2026-07-03T09:16:37.640",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9756",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GenerateBlocks combines a stored profile value with a caller-selected javascript scheme and emits it as a clickable href.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/aac15273-0a5d-4107-8249-7fff7f503005?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.1/includes/blocks/class-headline.php#L809",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.1/includes/class-dynamic-content.php#L816",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.1/includes/class-dynamic-tag-security.php#L582",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.0/includes/blocks/class-headline.php#L809",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.0/includes/class-dynamic-content.php#L816",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.0/includes/class-dynamic-tag-security.php#L582",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3582036%40generateblocks&new=3582036%40generateblocks&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 778,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9762",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T18:39:32.605Z",
      "date_published": "2026-07-17T17:25:53.469Z",
      "date_updated": "2026-07-18T03:55:38.232Z",
      "publisher": "ibm",
      "title": "IBM® Data Server driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user control",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Db2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06116
      },
      "nvd": {
        "published": "2026-07-17T18:17:17.693",
        "lastModified": "2026-07-24T16:46:46.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9762",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "IBM Db2 accepts a user-controlled JDBC URL on a path that reaches code execution, while the public record does not identify the selected class, property, or loading operation.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279479",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-9765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T19:51:51.271Z",
      "date_published": "2026-07-24T12:23:14.114Z",
      "date_updated": "2026-07-24T14:47:18.667Z",
      "publisher": "GRAFANA",
      "title": "CVE-2026-9765 CVE Record",
      "affected": {
        "vendors": [
          "Grafana"
        ],
        "products": [
          {
            "vendor": "Grafana",
            "product": "Grafana IRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security@grafana.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.209
      },
      "nvd": {
        "published": "2026-07-24T13:18:31.480",
        "lastModified": "2026-07-30T19:30:33.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9765",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record describes generic cloud access-control consequences but identifies no product, resource, action, or failed check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://grafana.com/security/security-advisories/cve-2026-9765",
          "host": "grafana.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 655,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T22:00:46.491Z",
      "date_published": "2026-07-15T00:21:06.126Z",
      "date_updated": "2026-07-15T12:38:03.180Z",
      "publisher": "TPLink",
      "title": "Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link Kasa EC70 and EC71",
      "affected": {
        "vendors": [
          "TP-Link Systems Inc."
        ],
        "products": [
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "Kasa EC71 v4"
          },
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "Kasa EC70 v4"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-321",
          "name": "Use of Hard-coded Cryptographic Key",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f23511db-6c3e-4e32-a477-6aa17d310630",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19914
      },
      "nvd": {
        "published": "2026-07-15T01:17:10.387",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9770",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Every affected Kasa camera contains the same private key in read-only firmware, allowing anyone who extracts one image to impersonate devices or decrypt their traffic.",
        "basis": [
          "CNA",
          "CWE-321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tp-link.com/en/support/download/ec71/v4/#Firmware-Release-Notes",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/download/ec71/v4/#Firmware-Release-Notes",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/en/support/download/ec70/v4/#Firmware-Release-Notes",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/faq/5192/",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 509,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-9810",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T08:04:00.536Z",
      "date_published": "2026-07-17T06:00:02.801Z",
      "date_updated": "2026-07-17T12:55:39.724Z",
      "publisher": "WPScan",
      "title": "AI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation via MCP OAuth",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "AI Copilot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22611
      },
      "nvd": {
        "published": "2026-07-17T07:16:38.230",
        "lastModified": "2026-07-17T15:44:29.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9810",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "AI Copilot accepts an OAuth token that is not bound to the current WordPress user and treats it as an administrator-authorized MCP session.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/6378a370-fe2f-48e7-984f-6e6c575dba60/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9820",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T11:26:12.173Z",
      "date_published": "2026-07-13T10:51:34.023Z",
      "date_updated": "2026-07-13T13:09:31.383Z",
      "publisher": "Mattermost",
      "title": "Mattermost schemes teams endpoint exposes private team invite IDs",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04924
      },
      "nvd": {
        "published": "2026-07-13T11:16:28.203",
        "lastModified": "2026-07-13T20:38:36.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9820",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-9824",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T11:32:33.594Z",
      "date_published": "2026-07-13T10:47:33.070Z",
      "date_updated": "2026-07-13T13:10:35.463Z",
      "publisher": "Mattermost",
      "title": "Remote cluster metadata enumeration via /share-channel autocomplete",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05822
      },
      "nvd": {
        "published": "2026-07-13T11:16:28.317",
        "lastModified": "2026-07-13T20:38:00.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-9824",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The share-channel autocomplete handler returns remote-cluster metadata without checking manage_shared_channels for the authenticated caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-9830",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T12:10:08.195Z",
      "date_published": "2026-07-27T06:00:06.217Z",
      "date_updated": "2026-07-27T17:43:42.012Z",
      "publisher": "WPScan",
      "title": "BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "bookingpress-appointment-booking-pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16151
      },
      "nvd": {
        "published": "2026-07-27T07:16:30.503",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9830",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "BookingPress registers REST routes without correctly invoking their permission callback, leaving booking reads and mutations unauthenticated.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/5fded411-52fd-4dc5-9a23-b77fcd9cfed2/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9833",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T12:39:27.707Z",
      "date_published": "2026-07-20T06:00:05.477Z",
      "date_updated": "2026-07-20T13:07:10.885Z",
      "publisher": "WPScan",
      "title": "Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Tag Groups is the Advanced Way to Display Your Taxonomy Terms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.05993
      },
      "nvd": {
        "published": "2026-07-20T07:16:42.657",
        "lastModified": "2026-07-20T20:39:31.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9833",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The plugin reflects an AJAX parameter into an HTML response without escaping it for the browser context.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/75792c33-2d9d-46db-a98c-00ec40951099/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9834",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T12:40:52.573Z",
      "date_published": "2026-07-02T08:33:05.373Z",
      "date_updated": "2026-07-02T12:24:43.250Z",
      "publisher": "Wordfence",
      "title": "WP Database Backup <= 7.11 - Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter",
      "affected": {
        "vendors": [
          "databasebackup"
        ],
        "products": [
          {
            "vendor": "databasebackup",
            "product": "WP Database Backup – Unlimited Database & Files Backup by Backup for WP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01542,
        "percentile": 0.72478
      },
      "nvd": {
        "published": "2026-07-02T10:16:29.353",
        "lastModified": "2026-07-02T13:58:56.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9834",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Stored wp_db_exclude_table values are concatenated unquoted into a mysqldump shell command, leaving shell metacharacters executable when a backup runs.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0a97a217-b00b-4268-a472-8d62ae1d18e3?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-database-backup/tags/7.11/includes/admin/class-wpdb-admin.php#L2644",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-database-backup/tags/7.11/includes/admin/class-wpdb-admin.php#L2654",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-database-backup/tags/7.11/includes/admin/class-wpdb-admin.php#L216",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-database-backup/tags/7.10/includes/admin/class-wpdb-admin.php#L2644",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-database-backup/tags/7.10/includes/admin/class-wpdb-admin.php#L2654",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-database-backup/tags/7.10/includes/admin/class-wpdb-admin.php#L216",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3574273%40wp-database-backup&new=3574273%40wp-database-backup&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1321,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9838",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T12:59:23.830Z",
      "date_published": "2026-07-10T08:30:40.245Z",
      "date_updated": "2026-07-10T14:04:31.963Z",
      "publisher": "Wordfence",
      "title": "ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Parameter",
      "affected": {
        "vendors": [
          "room34"
        ],
        "products": [
          {
            "vendor": "room34",
            "product": "ICS Calendar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21876
      },
      "nvd": {
        "published": "2026-07-10T09:16:54.110",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9838",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unauthenticated AJAX path lets js_args override the stored htmltagtitle setting, which is rendered without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a4d91b01-5034-42b5-857f-c66c875dd562?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.8.4/templates/calendar-month.php#L40",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.8.4/r34ics-ajax.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.8.4/r34ics-ajax.php#L53",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.8.4/r34ics-ajax.php#L72",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.5.2/templates/calendar-month.php#L40",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.5.2/r34ics-ajax.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.5.2/r34ics-ajax.php#L53",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.5.2/r34ics-ajax.php#L72",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3563728%40ics-calendar&new=3563728%40ics-calendar",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 715,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9842",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T13:26:31.589Z",
      "date_published": "2026-07-08T04:30:49.525Z",
      "date_updated": "2026-07-08T13:01:09.142Z",
      "publisher": "Wordfence",
      "title": "Backstage <= 1.4.2 - Unauthenticated Privilege Escalation via Permissive Demo Role Capabilities",
      "affected": {
        "vendors": [
          "pixelgrade"
        ],
        "products": [
          {
            "vendor": "pixelgrade",
            "product": "Backstage – Customizer Demo Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17087
      },
      "nvd": {
        "published": "2026-07-08T05:16:29.097",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9842",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The demo role receives manage_options even though its intended Customizer access requires a narrower capability set.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5bcf1f02-0946-4e96-a81b-00c7c48d64b3?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/backstage/tags/1.4.2/includes/class-Backstage.php#L154",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/backstage/tags/1.4.2/includes/class-Backstage.php#L348",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-9857",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T15:53:49.759Z",
      "date_published": "2026-07-10T09:32:42.851Z",
      "date_updated": "2026-07-10T14:03:50.477Z",
      "publisher": "Wordfence",
      "title": "Invoice123 <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Setting Modification via s123_submit_api_key & s123_submit_invoice_settings AJAX actions",
      "affected": {
        "vendors": [
          "saskaita123"
        ],
        "products": [
          {
            "vendor": "saskaita123",
            "product": "Invoice123"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21003
      },
      "nvd": {
        "published": "2026-07-10T10:16:24.310",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-9857",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Invoice123 permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7d4e685a-0462-447f-a639-4f95d5aa27ab?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/saskaita123-lt/tags/1.7.0/includes/pages/S123_InvoiceSettings.php#L26",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/saskaita123-lt/tags/1.7.0/includes/pages/S123_InvoiceSettings.php#L65",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/saskaita123-lt/tags/1.7.0/includes/pages/S123_ApiKey.php#L29",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/saskaita123-lt/tags/1.7.0/includes/pages/S123_InvoiceSettings.php#L18",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/saskaita123-lt/tags/1.7.0/includes/pages/S123_ApiKey.php#L21",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/saskaita123-lt/tags/1.6.8/includes/pages/S123_InvoiceSettings.php#L26",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/saskaita123-lt/tags/1.6.8/includes/pages/S123_InvoiceSettings.php#L65",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/saskaita123-lt/tags/1.6.8/includes/pages/S123_ApiKey.php#L29",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/saskaita123-lt/tags/1.6.8/includes/pages/S123_InvoiceSettings.php#L18",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/saskaita123-lt/tags/1.6.8/includes/pages/S123_ApiKey.php#L21",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3594935%40saskaita123-lt&new=3594935%40saskaita123-lt",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 470,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10031",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T18:37:02.626Z",
      "date_published": "2026-07-30T22:51:31.522Z",
      "date_updated": "2026-07-31T19:15:51.991Z",
      "publisher": "VulnCheck",
      "title": "SFTPGo 2.7.4 Permission Bypass via Symbolic Link Creation",
      "affected": {
        "vendors": [
          "drakkan"
        ],
        "products": [
          {
            "vendor": "drakkan",
            "product": "SFTPGo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07945
      },
      "nvd": {
        "published": "2026-07-30T23:16:51.347",
        "lastModified": "2026-07-31T20:16:46.170",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10031",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SFTPGo authorizes a symbolic link using the link directory's permissions instead of the permissions on the dereferenced target path.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/drakkan/sftpgo",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/drakkan/sftpgo/security/advisories/GHSA-fj9v-mxr3-w75w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/drakkan/sftpgo/releases/tag/v2.7.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/sftpgo-permission-bypass-via-symbolic-link-creation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10033",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T18:52:02.895Z",
      "date_published": "2026-07-24T09:31:46.983Z",
      "date_updated": "2026-07-24T12:35:36.658Z",
      "publisher": "Wordfence",
      "title": "EventON Action User <= 2.5.14 - Missing Authorization to Unauthenticated Privilege Escalation via evoau_save_capability AJAX Action",
      "affected": {
        "vendors": [
          "EventON"
        ],
        "products": [
          {
            "vendor": "EventON",
            "product": "EventON Action User"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10356
      },
      "nvd": {
        "published": "2026-07-24T10:16:29.983",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10033",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unauthenticated AJAX actions omit the authorization check before granting EventON and upload capabilities to non-administrator roles or users.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6ca9eaf7-261b-42ab-a779-9e11dde5763b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/eventon-action-user/trunk/includes/admin/class-admin-ajax.php#L243",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 844,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10037",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T19:27:23.004Z",
      "date_published": "2026-07-08T21:18:56.577Z",
      "date_updated": "2026-07-14T14:33:19.237Z",
      "publisher": "canonical",
      "title": "Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal",
      "affected": {
        "vendors": [
          "Canonical"
        ],
        "products": [
          {
            "vendor": "Canonical",
            "product": "Ubuntu"
          }
        ],
        "affectedBlockCount": 10,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@ubuntu.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02152
      },
      "nvd": {
        "published": "2026-07-08T22:17:12.500",
        "lastModified": "2026-07-14T15:16:54.877",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10037",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Ubuntu's executable JAR MIME handler allows a sandboxed application to write an executable JAR and invoke the host handler through the OpenURI portal when mailcap is installed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugs.launchpad.net/ubuntu/+source/openjdk-25/+bug/2153100",
          "host": "bugs.launchpad.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 483,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-10041",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T19:52:33.345Z",
      "date_published": "2026-07-11T05:35:50.395Z",
      "date_updated": "2026-07-13T14:39:33.538Z",
      "publisher": "Wordfence",
      "title": "WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers",
      "affected": {
        "vendors": [
          "wclovers"
        ],
        "products": [
          {
            "vendor": "wclovers",
            "product": "WCFM – Frontend Manager for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16467
      },
      "nvd": {
        "published": "2026-07-11T07:16:44.783",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10041",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The AJAX handlers accept caller-controlled vendor and record keys without checking that the caller owns the targeted objects.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e3f88a18-5439-4759-ae9f-168f5efc3264?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-ajax.php#L746",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-ajax.php#L779",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-ajax.php#L810",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-enquiry.php#L395",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-notification.php#L1132",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-ajax.php#L746",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-ajax.php#L779",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-ajax.php#L810",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-enquiry.php#L395",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-notification.php#L1132",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3588570%40wc-frontend-manager&new=3588570%40wc-frontend-manager",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10051",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T07:28:48.617Z",
      "date_published": "2026-07-14T08:44:38.233Z",
      "date_updated": "2026-07-14T12:57:50.096Z",
      "publisher": "eclipse",
      "title": "In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first re...",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Jetty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22537
      },
      "nvd": {
        "published": "2026-07-14T09:16:39.783",
        "lastModified": "2026-07-14T18:41:52.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10051",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Jetty leaves the first request's trailer state attached to a reused connection and reports it on later requests.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/119",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 359,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-10054",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T07:35:37.279Z",
      "date_published": "2026-07-03T10:11:32.446Z",
      "date_updated": "2026-07-07T03:56:07.775Z",
      "publisher": "eclipse",
      "title": "In affected versions of Eclipse Theia (1.",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Theia"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1385",
          "name": "Missing Origin Validation in WebSockets",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05575
      },
      "nvd": {
        "published": "2026-07-03T11:16:26.847",
        "lastModified": "2026-07-07T05:16:48.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10054",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The terminal WebSocket service accepts missing or client-replaced Origin data and exposes privileged RPC without an independent service authentication gate.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-1385"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-78g8-vm3p-97c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/376",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1193,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10055",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T07:38:29.233Z",
      "date_published": "2026-07-03T10:30:57.038Z",
      "date_updated": "2026-07-06T15:23:38.516Z",
      "publisher": "eclipse",
      "title": "In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and return...",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Theia"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00297,
        "percentile": 0.21939
      },
      "nvd": {
        "published": "2026-07-03T11:16:27.600",
        "lastModified": "2026-07-06T18:56:27.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10055",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Eclipse Theia accepts an attacker-controlled destination without reapplying the network allowlist after URL parsing, redirects, or address resolution, allowing server-side requests to a prohibited target.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-2m57-xxmh-v696",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/446",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 853,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10077",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T08:49:36.686Z",
      "date_published": "2026-07-02T06:00:02.357Z",
      "date_updated": "2026-07-02T12:53:20.858Z",
      "publisher": "WPScan",
      "title": "YOOtheme Pro < 5.0.35 - Author+ Stored XSS via UIkit Data Attributes",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "yootheme"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15234
      },
      "nvd": {
        "published": "2026-07-02T06:16:12.423",
        "lastModified": "2026-07-02T15:12:53.577",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10077",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "UIkit interprets HTML attributes allowed by wp_kses_post as active markup, so author-controlled post content becomes stored script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/89877758-50f1-4a4b-a622-e417571a5b14/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10079",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T10:07:21.654Z",
      "date_published": "2026-07-31T09:08:20.223Z",
      "date_updated": "2026-07-31T14:54:31.439Z",
      "publisher": "redhat",
      "title": "Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injection",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Security 4"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06165
      },
      "nvd": {
        "published": "2026-07-31T10:16:43.190",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10079",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "RHACS trusts an encoded deployment label to replace authoritative workload identity, and a null label erases the UID, name, labels, and namespace used for policy enforcement.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-10079",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2483158",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 587,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-10081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T10:57:03.558Z",
      "date_published": "2026-07-20T06:00:01.606Z",
      "date_updated": "2026-07-20T13:19:41.624Z",
      "publisher": "WPScan",
      "title": "Unlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Google Reviews Widget",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Unlimited Elements For Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21393
      },
      "nvd": {
        "published": "2026-07-20T07:16:33.520",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10081",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Google Reviews widget renders Serp API review text without sanitizing or escaping it, so review markup executes in visitors' browsers.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e5cde405-5b34-4d3d-bfda-325402b0a5bc/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 422,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T11:01:03.755Z",
      "date_published": "2026-07-27T06:00:01.437Z",
      "date_updated": "2026-07-27T14:13:34.190Z",
      "publisher": "WPScan",
      "title": "Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcode 'ad_args' Parameter",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Advanced Ads"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04573
      },
      "nvd": {
        "published": "2026-07-27T07:16:24.183",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10082",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ad_args shortcode value is emitted into page markup without sanitization or context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/088a832d-2153-432e-849f-2c22b63a1b54/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T11:54:45.722Z",
      "date_published": "2026-07-13T08:05:42.370Z",
      "date_updated": "2026-07-13T13:57:00.893Z",
      "publisher": "Mattermost",
      "title": "Ordinary group/direct message member can enable group_constrained and remove all channel participants",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06619
      },
      "nvd": {
        "published": "2026-07-13T09:16:22.447",
        "lastModified": "2026-07-14T13:19:08.507",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10085",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Mattermost permits the group_constrained flag on channel types that do not support group synchronization, granting a configuration action outside its valid object scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 367,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-10089",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T13:27:15.359Z",
      "date_published": "2026-07-02T05:35:13.559Z",
      "date_updated": "2026-07-02T14:50:23.017Z",
      "publisher": "Wordfence",
      "title": "Insert Pages <= 3.11.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Field Keys (Meta Key Names)",
      "affected": {
        "vendors": [
          "figureone"
        ],
        "products": [
          {
            "vendor": "figureone",
            "product": "Insert Pages"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11476
      },
      "nvd": {
        "published": "2026-07-02T06:16:12.680",
        "lastModified": "2026-07-02T15:16:56.703",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10089",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This is due to insufficient output escaping in the the_meta() function: while the custom field VALUE is sanitized with wp_kses_post(), the custom field KEY ($key) is interpolated into the rendered HTML (lines 1786-1791) and echoed (line 1806) without any escaping when an inserted page is rendered with the [insert page='ID' display='all'] shortcode.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a4246181-d331-46b0-ad48-e2ece11b2f5f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/insert-pages/tags/3.11.4/insert-pages.php#L1789",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/insert-pages/tags/3.11.4/insert-pages.php#L1771",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/insert-pages/tags/3.11.4/insert-pages.php#L768",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/insert-pages/tags/3.11.3/insert-pages.php#L1789",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/insert-pages/tags/3.11.3/insert-pages.php#L1771",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/insert-pages/tags/3.11.3/insert-pages.php#L768",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3579298",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 713,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10095",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T13:57:08.455Z",
      "date_published": "2026-07-01T09:32:27.594Z",
      "date_updated": "2026-07-01T12:22:01.471Z",
      "publisher": "Wordfence",
      "title": "WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute",
      "affected": {
        "vendors": [
          "opajaap"
        ],
        "products": [
          {
            "vendor": "opajaap",
            "product": "WP Photo Album Plus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.1441
      },
      "nvd": {
        "published": "2026-07-01T11:16:21.827",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10095",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The subtext shortcode attribute is stored and rendered without sufficient sanitization or context-appropriate HTML escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/59f914e2-a671-46cc-a2b8-664816639f3e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.13.005/wppa-functions.php#L4291",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.13.005/wppa-filter.php#L1320",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.13.005/wppa-filter.php#L1301",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.13.005/wppa-filter.php#L1151",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.09.005/wppa-functions.php#L4291",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.09.005/wppa-filter.php#L1320",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.09.005/wppa-filter.php#L1301",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.09.005/wppa-filter.php#L1151",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3557877/wp-photo-album-plus/trunk/wppa-filter.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fwp-photo-album-plus/tags/9.1.13.005&new_path=%2Fwp-photo-album-plus/tags/9.2.01.001",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 618,
        "referenceCount": 11,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10096",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T14:01:46.700Z",
      "date_published": "2026-07-01T07:53:37.118Z",
      "date_updated": "2026-07-01T10:32:04.339Z",
      "publisher": "Wordfence",
      "title": "Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter",
      "affected": {
        "vendors": [
          "qodeinteractive"
        ],
        "products": [
          {
            "vendor": "qodeinteractive",
            "product": "Qi Blocks"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09541
      },
      "nvd": {
        "published": "2026-07-01T08:16:19.167",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10096",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The styles endpoint checks generic author capabilities but never binds page_id to a post, template, or widget the caller may edit.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/64251fd4-1627-49d0-831f-5cb9898c38bf?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/qi-blocks/tags/1.4.9/inc/admin/global-styles/class-qi-blocks-framework-global-styles.php#L142",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/qi-blocks/tags/1.4.9/inc/admin/global-styles/class-qi-blocks-framework-global-styles.php#L134",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/qi-blocks/tags/1.4.9/inc/admin/global-styles/class-qi-blocks-framework-global-styles.php#L82",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3572812%40qi-blocks&new=3572812%40qi-blocks&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 780,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T15:37:04.097Z",
      "date_published": "2026-07-13T07:57:11.062Z",
      "date_updated": "2026-07-14T14:32:32.714Z",
      "publisher": "Mattermost",
      "title": "Authenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channels",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04195
      },
      "nvd": {
        "published": "2026-07-13T09:16:23.653",
        "lastModified": "2026-07-14T15:16:54.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10103",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation accepts a caller-supplied object identifier without binding the selected object to the authenticated caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-10104",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T15:44:29.000Z",
      "date_published": "2026-07-02T08:33:08.053Z",
      "date_updated": "2026-07-02T15:54:15.102Z",
      "publisher": "Wordfence",
      "title": "Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter",
      "affected": {
        "vendors": [
          "nikhilgadhiya"
        ],
        "products": [
          {
            "vendor": "nikhilgadhiya",
            "product": "Product Video Gallery for Woocommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18142
      },
      "nvd": {
        "published": "2026-07-02T10:16:26.970",
        "lastModified": "2026-07-02T16:16:29.503",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10104",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f61885bc-b7da-42b8-a0d3-ba5d7d19b536?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/product-video-gallery-slider-for-woocommerce/tags/1.5.1.7/public/class-rendering.php#L379",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/product-video-gallery-slider-for-woocommerce/tags/1.5.1.7/public/class-rendering.php#L365",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/product-video-gallery-slider-for-woocommerce/tags/1.5.1.7/admin/class-video-field.php#L310",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/product-video-gallery-slider-for-woocommerce/tags/1.5.1.6/public/class-rendering.php#L379",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/product-video-gallery-slider-for-woocommerce/tags/1.5.1.6/public/class-rendering.php#L365",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/product-video-gallery-slider-for-woocommerce/tags/1.5.1.6/admin/class-video-field.php#L310",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3591727%40product-video-gallery-slider-for-woocommerce&new=3591727%40product-video-gallery-slider-for-woocommerce&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 440,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10106",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T16:06:43.719Z",
      "date_published": "2026-07-13T08:09:58.717Z",
      "date_updated": "2026-07-13T13:56:41.047Z",
      "publisher": "Mattermost",
      "title": "Unauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in Mattermost",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07146
      },
      "nvd": {
        "published": "2026-07-13T09:16:23.770",
        "lastModified": "2026-07-13T21:42:24.057",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10106",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Mattermost validates an action cookie without binding its channel to the channel containing the target post.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 402,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-10130",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T18:28:14.533Z",
      "date_published": "2026-07-18T22:15:13.688Z",
      "date_updated": "2026-07-21T14:25:19.770Z",
      "publisher": "VulnCheck",
      "title": "QueryWeaver Authentication Bypass via Email Signup Token Issuance for Existing Accounts",
      "affected": {
        "vendors": [
          "FalkorDB"
        ],
        "products": [
          {
            "vendor": "FalkorDB",
            "product": "QueryWeaver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29299
      },
      "nvd": {
        "published": "2026-07-18T23:17:00.397",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10130",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The signup route links a newly issued token to an existing identity selected only by email before checking whether the requester owns that account.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FalkorDB/QueryWeaver",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/FalkorDB/QueryWeaver/commit/e6a49f508191d0f1bdad0f146da43819e7849f18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/queryweaver-authentication-bypass-via-email-signup-token-issuance-for-existing-accounts",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 551,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-10207",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-31T06:56:00.402Z",
      "date_published": "2026-07-28T09:30:15.802Z",
      "date_updated": "2026-07-28T13:29:13.988Z",
      "publisher": "Wordfence",
      "title": "PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id' Parameter",
      "affected": {
        "vendors": [
          "pickplugins"
        ],
        "products": [
          {
            "vendor": "pickplugins",
            "product": "PickPlugins Question Answer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22755
      },
      "nvd": {
        "published": "2026-07-28T10:16:46.510",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10207",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The id parameter is concatenated directly into an SQL statement.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/178e2537-e900-4264-9b29-1bb5bac36f48?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/question-answer/trunk/templates/user-profile/user-profile-hook.php#L98",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/question-answer/tags/1.2.73/templates/user-profile/user-profile-hook.php#L98",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/question-answer/trunk/templates/user-profile/user-profile.php#L6",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/question-answer/tags/1.2.73/templates/user-profile/user-profile.php#L6",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 648,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10525",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T09:05:50.251Z",
      "date_published": "2026-07-17T06:00:01.678Z",
      "date_updated": "2026-07-17T14:50:27.413Z",
      "publisher": "WPScan",
      "title": "NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "NEX-Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07046
      },
      "nvd": {
        "published": "2026-07-17T07:16:37.650",
        "lastModified": "2026-07-17T16:17:12.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10525",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Submitted form data is stored and emitted in an administrator page without sufficient sanitization and output escaping.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/d1e191e6-ff5b-4cb8-9b12-8ae73cf0d2f0/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 395,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T11:45:31.382Z",
      "date_published": "2026-07-30T16:55:57.003Z",
      "date_updated": "2026-07-31T03:56:17.992Z",
      "publisher": "ibm",
      "title": "IBM® Db2® is vulnerable to buffer overflow in setgid helper db2flacc which can lead to privilege escalation and instance compromise from an unprivileged shell",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Db2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02289
      },
      "nvd": {
        "published": "2026-07-30T19:17:01.167",
        "lastModified": "2026-07-31T04:16:45.347",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10535",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Db2 writes attacker-controlled data beyond a stack buffer boundary.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279466",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-10536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T11:49:55.548Z",
      "date_published": "2026-07-03T06:11:15.378Z",
      "date_updated": "2026-07-06T18:29:27.171Z",
      "publisher": "curl",
      "title": "HTTP/2 stream-dependency tree UAF",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 33,
        "versionRangeCount": 33,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00507,
        "percentile": 0.40505
      },
      "nvd": {
        "published": "2026-07-03T07:16:23.563",
        "lastModified": "2026-07-07T18:02:03.890",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10536",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Resetting a libcurl easy handle frees an HTTP/2 dependency-tree object that cleanup later accesses through a stale reference.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-10536.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-10536.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3751697",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 420,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 33
      }
    },
    {
      "cve_id": "CVE-2026-10538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T12:16:09.689Z",
      "date_published": "2026-07-01T07:56:31.099Z",
      "date_updated": "2026-07-01T12:24:04.644Z",
      "publisher": "airbus",
      "title": "Improper deserialization handling in Control-M Components",
      "affected": {
        "vendors": [
          "BMC"
        ],
        "products": [
          {
            "vendor": "BMC",
            "product": "Control-M/Enterprise Manager"
          },
          {
            "vendor": "BMC",
            "product": "Control-M/Server"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cert@airbus.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cert@airbus.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00246,
        "percentile": 0.1593
      },
      "nvd": {
        "published": "2026-07-01T08:16:20.197",
        "lastModified": "2026-07-01T19:59:44.537",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10538",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Control-M/Enterprise Manager, attacker-controlled serialized data is converted into live objects without restricting the permitted types or behaviors.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=kA3cx000000GFKrCAO&type=Solution",
          "host": "bmcapps.my.site.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 375,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-10539",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T12:16:11.016Z",
      "date_published": "2026-07-01T07:55:00.615Z",
      "date_updated": "2026-07-01T12:29:09.837Z",
      "publisher": "airbus",
      "title": "Unauthenticated command injection in Control-M/Server communication command",
      "affected": {
        "vendors": [
          "BMC"
        ],
        "products": [
          {
            "vendor": "BMC",
            "product": "Control-M/Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-305",
          "name": "Authentication Bypass by Primary Weakness",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cert@airbus.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cert@airbus.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.5,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18763
      },
      "nvd": {
        "published": "2026-07-01T08:16:20.340",
        "lastModified": "2026-07-01T19:59:44.537",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10539",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Control-M passes user-controlled communication data into an operating-system command without sufficient neutralization of command syntax.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-305"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=kA3cx000000GFZNCA4&type=Solution",
          "host": "bmcapps.my.site.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 420,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-10540",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T12:16:12.516Z",
      "date_published": "2026-07-01T07:52:10.618Z",
      "date_updated": "2026-07-01T12:34:11.299Z",
      "publisher": "airbus",
      "title": "Weak password hash protection in Control-M/Entreprise Manager",
      "affected": {
        "vendors": [
          "BMC"
        ],
        "products": [
          {
            "vendor": "BMC",
            "product": "Control-M/Enterprise Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-328",
          "name": "Use of Weak Hash",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:cert@airbus.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cert@airbus.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00078,
        "percentile": 0.00157
      },
      "nvd": {
        "published": "2026-07-01T08:16:20.463",
        "lastModified": "2026-07-01T19:59:44.537",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10540",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Control-M/Enterprise Manager protects stored password hashes with a weak hash construction that permits practical offline recovery after credential-data access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-328"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=kA3cx000000GFeDCAW&type=Solution",
          "host": "bmcapps.my.site.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 327,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-10545",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T12:53:46.014Z",
      "date_published": "2026-07-30T17:59:52.140Z",
      "date_updated": "2026-07-30T18:32:22.380Z",
      "publisher": "ibm",
      "title": "IBM Planning Analytics Local is affected by Open Redirect",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Planning Analytics Local"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12774
      },
      "nvd": {
        "published": "2026-07-30T19:17:01.597",
        "lastModified": "2026-07-30T19:31:02.643",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10545",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Planning Analytics Local navigation flow accepts an attacker-selected external destination without restricting it to trusted origins.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278566",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10551",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T13:52:35.184Z",
      "date_published": "2026-07-13T06:00:01.138Z",
      "date_updated": "2026-07-13T15:54:20.284Z",
      "publisher": "WPScan",
      "title": "Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Breeze Cache"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.0457
      },
      "nvd": {
        "published": "2026-07-13T07:16:26.200",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10551",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Predictable minifier placeholders and their replacement expression let crafted input escape into an HTML attribute.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/381fb82f-2fdc-49cb-bb0d-8d70ead61d86/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 352,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10569",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T16:46:32.738Z",
      "date_published": "2026-07-30T19:06:43.723Z",
      "date_updated": "2026-07-30T19:33:20.270Z",
      "publisher": "ibm",
      "title": "IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Exposure of Sensitive Information Vulnerability",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "UCD - IBM UrbanCode Deploy"
          },
          {
            "vendor": "IBM",
            "product": "UCD - IBM DevOps Deploy"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.0735
      },
      "nvd": {
        "published": "2026-07-30T20:16:51.940",
        "lastModified": "2026-07-30T20:26:26.053",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10569",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "UrbanCode Deploy writes step-related sensitive values into plugin output logs readable by anyone with log access.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7277574",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-10570",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T16:52:24.481Z",
      "date_published": "2026-07-08T05:34:10.677Z",
      "date_updated": "2026-07-08T12:40:35.027Z",
      "publisher": "Wordfence",
      "title": "Sympl Repeater for ACF and Elementor <= 2.3 - Authenticated (Author+) Stored Cross-Site Scripting via ACF Repeater Field Values",
      "affected": {
        "vendors": [
          "idocoh"
        ],
        "products": [
          {
            "vendor": "idocoh",
            "product": "Sympl Repeater for ACF and Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07941
      },
      "nvd": {
        "published": "2026-07-08T06:16:20.720",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10570",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The plugin stores ACF repeater values and emits them as browser markup without the required sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/daa38c2c-9992-400b-acef-dcd37f9c7269?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/acf-repeater-for-elementor/tags/2.3/sympl-repeater-for-acf-and-elementor.php#L179",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/acf-repeater-for-elementor/tags/2.3/sympl-repeater-for-acf-and-elementor.php#L99",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 629,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10573",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T16:59:02.524Z",
      "date_published": "2026-07-14T14:54:39.924Z",
      "date_updated": "2026-07-14T15:25:00.754Z",
      "publisher": "Rockwell",
      "title": "1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP Object",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "1734 POINT I/O"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.1677
      },
      "nvd": {
        "published": "2026-07-14T15:16:55.097",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10573",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Rockwell reports that crafted CIP messages fault the 1734 POINT I/O module until restart, while the parser condition or resource limit that fails is not public.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1779.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10577",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:15:25.549Z",
      "date_published": "2026-07-14T12:52:40.986Z",
      "date_updated": "2026-07-14T13:19:49.516Z",
      "publisher": "Rockwell",
      "title": "Rockwell Automation 1715 Redundant IO – Access Control Vulnerability",
      "affected": {
        "vendors": [
          "Rockwell Auotmation"
        ],
        "products": [
          {
            "vendor": "Rockwell Auotmation",
            "product": "1715 EtherNet/IP Communications Module"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22685
      },
      "nvd": {
        "published": "2026-07-14T13:18:13.163",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10577",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The product exposes a network debug port whose intrusive CLI commands lack privilege enforcement.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1785.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 460,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10587",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T19:55:17.995Z",
      "date_published": "2026-07-16T16:49:51.166Z",
      "date_updated": "2026-07-16T17:35:39.421Z",
      "publisher": "lenovo",
      "title": "A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.",
      "affected": {
        "vendors": [
          "Lenovo"
        ],
        "products": [
          {
            "vendor": "Lenovo",
            "product": "Yoga Pro 7 15IPH11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IPH11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 7 16AGP11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16AGP11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16ADR10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G6 ARP BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "LOQ 15ARP10E BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Book 9 14IAH10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16AFR10H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16AFR10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16ADR10H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G4 AMN BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook Plus G6 Rollable BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15IAX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15AKP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15IRX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16IRX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook 16p G6 ADR BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15AHP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16IRX9H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 9 16IRX9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16IRU9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16IRX9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IMH9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16ARX8H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook Plus G4 IRU BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Slim 5 14APH8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook Plus G5 Tab&ThinkBook Plus G5 Station BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G4 IAH BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G5 IRL BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Pro 9 14IRP8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16IRH8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IRH8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 15AMN8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga 9 14IRP8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16ARX8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo S14 G3 IAP BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad 5 15ABA7 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook 16p G5 IRX BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G2 IJL Laptop BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Pro 9 16IMH9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook 16p G6 IAX BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 7 16IAX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16IAX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16IAX10H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16IRH10R BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15IRX9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V14 G6 ITN BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 14ITN9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16ARP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16ASP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15APH9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga 9 2-in-1 14ILL10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Book 9 13IMU9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IAH10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "LOQ 15IAX9E BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga 9 2-in-1 14IMH9 BIOS"
          }
        ],
        "affectedBlockCount": 60,
        "versionEntryCount": 60,
        "versionRangeCount": 60,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.001,
        "percentile": 0.00992
      },
      "nvd": {
        "published": "2026-07-16T17:16:53.300",
        "lastModified": "2026-07-16T18:16:40.217",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10587",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected parser writes beyond its destination buffer because attacker-controlled size or index data is not bounded.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.lenovo.com/us/en/product_security/LEN-220440",
          "host": "support.lenovo.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 57,
        "affectedVersionEntryCount": 60
      }
    },
    {
      "cve_id": "CVE-2026-10588",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T19:55:18.582Z",
      "date_published": "2026-07-16T16:49:59.775Z",
      "date_updated": "2026-07-16T17:32:27.763Z",
      "publisher": "lenovo",
      "title": "A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.",
      "affected": {
        "vendors": [
          "Lenovo"
        ],
        "products": [
          {
            "vendor": "Lenovo",
            "product": "Yoga Pro 7 15IPH11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IPH11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 7 16AGP11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16AGP11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16ADR10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G6 ARP BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "LOQ 15ARP10E BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Book 9 14IAH10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16AFR10H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16AFR10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16ADR10H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G4 AMN BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook Plus G6 Rollable BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15IAX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15AKP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15IRX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16IRX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook 16p G6 ADR BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15AHP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16IRX9H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 9 16IRX9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16IRU9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16IRX9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IMH9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16ARX8H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook Plus G4 IRU BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Slim 5 14APH8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook Plus G5 Tab&ThinkBook Plus G5 Station BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G4 IAH BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G5 IRL BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Pro 9 14IRP8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16IRH8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IRH8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 15AMN8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga 9 14IRP8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16ARX8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo S14 G3 IAP BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad 5 15ABA7 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook 16p G5 IRX BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G2 IJL Laptop BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Pro 9 16IMH9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook 16p G6 IAX BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 7 16IAX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16IAX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16IAX10H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16IRH10R BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15IRX9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V14 G6 ITN BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 14ITN9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16ARP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16ASP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15APH9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga 9 2-in-1 14ILL10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Book 9 13IMU9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IAH10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "LOQ 15IAX9E BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga 9 2-in-1 14IMH9 BIOS"
          }
        ],
        "affectedBlockCount": 60,
        "versionEntryCount": 60,
        "versionRangeCount": 60,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01367
      },
      "nvd": {
        "published": "2026-07-16T17:16:53.720",
        "lastModified": "2026-07-16T18:16:40.630",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10588",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected interface returns, embeds or leaves protected information visible to an observer who is not entitled to receive it.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.lenovo.com/us/en/product_security/LEN-220440",
          "host": "support.lenovo.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 133,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 57,
        "affectedVersionEntryCount": 60
      }
    },
    {
      "cve_id": "CVE-2026-10589",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T19:55:19.225Z",
      "date_published": "2026-07-16T16:50:06.782Z",
      "date_updated": "2026-07-16T17:31:54.634Z",
      "publisher": "lenovo",
      "title": "A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.",
      "affected": {
        "vendors": [
          "Lenovo"
        ],
        "products": [
          {
            "vendor": "Lenovo",
            "product": "Yoga Pro 7 15IPH11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IPH11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 7 16AGP11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16AGP11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16ADR10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G6 ARP BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "LOQ 15ARP10E BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Book 9 14IAH10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16AFR10H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16AFR10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16ADR10H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G4 AMN BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook Plus G6 Rollable BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15IAX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15AKP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15IRX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16IRX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook 16p G6 ADR BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15AHP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16IRX9H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 9 16IRX9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16IRU9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16IRX9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IMH9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16ARX8H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook Plus G4 IRU BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Slim 5 14APH8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook Plus G5 Tab&ThinkBook Plus G5 Station BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G4 IAH BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G5 IRL BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Pro 9 14IRP8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16IRH8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IRH8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 15AMN8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga 9 14IRP8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16ARX8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo S14 G3 IAP BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad 5 15ABA7 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook 16p G5 IRX BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G2 IJL Laptop BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Pro 9 16IMH9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook 16p G6 IAX BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 7 16IAX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16IAX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16IAX10H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16IRH10R BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15IRX9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V14 G6 ITN BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 14ITN9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16ARP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16ASP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15APH9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga 9 2-in-1 14ILL10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Book 9 13IMU9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IAH10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "LOQ 15IAX9E BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga 9 2-in-1 14IMH9 BIOS"
          }
        ],
        "affectedBlockCount": 60,
        "versionEntryCount": 60,
        "versionRangeCount": 60,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00109,
        "percentile": 0.0146
      },
      "nvd": {
        "published": "2026-07-16T17:16:54.090",
        "lastModified": "2026-07-16T18:16:41.043",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10589",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A privileged local request reaches a System Management Mode write whose destination bound is not enforced.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.lenovo.com/us/en/product_security/LEN-220440",
          "host": "support.lenovo.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 57,
        "affectedVersionEntryCount": 60
      }
    },
    {
      "cve_id": "CVE-2026-10590",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T19:55:19.840Z",
      "date_published": "2026-07-16T16:50:14.593Z",
      "date_updated": "2026-07-16T17:31:27.673Z",
      "publisher": "lenovo",
      "title": "A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.",
      "affected": {
        "vendors": [
          "Lenovo"
        ],
        "products": [
          {
            "vendor": "Lenovo",
            "product": "Yoga Pro 7 15IPH11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IPH11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 7 16AGP11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16AGP11 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16ADR10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G6 ARP BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "LOQ 15ARP10E BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Book 9 14IAH10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16AFR10H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16AFR10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16ADR10H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G4 AMN BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook Plus G6 Rollable BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15IAX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15AKP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15IRX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16IRX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook 16p G6 ADR BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15AHP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16IRX9H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 9 16IRX9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16IRU9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16IRX9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IMH9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16ARX8H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook Plus G4 IRU BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Slim 5 14APH8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook Plus G5 Tab&ThinkBook Plus G5 Station BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G4 IAH BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G5 IRL BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Pro 9 14IRP8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16IRH8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IRH8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 15AMN8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga 9 14IRP8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16ARX8 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo S14 G3 IAP BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad 5 15ABA7 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook 16p G5 IRX BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V15 G2 IJL Laptop BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Pro 9 16IMH9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "ThinkBook 16p G6 IAX BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 7 16IAX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 5 16IAX10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion Pro 7 16IAX10H BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16IRH10R BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15IRX9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Lenovo V14 G6 ITN BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 14ITN9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Slim 3 16ARP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16ASP10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Legion 5 15APH9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga 9 2-in-1 14ILL10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga Book 9 13IMU9 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "IdeaPad Pro 5 16IAH10 BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "LOQ 15IAX9E BIOS"
          },
          {
            "vendor": "Lenovo",
            "product": "Yoga 9 2-in-1 14IMH9 BIOS"
          }
        ],
        "affectedBlockCount": 60,
        "versionEntryCount": 60,
        "versionRangeCount": 60,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00111,
        "percentile": 0.01539
      },
      "nvd": {
        "published": "2026-07-16T17:16:54.407",
        "lastModified": "2026-07-16T18:16:41.283",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10590",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A privileged local caller can trigger the SMI handler through WMI without the authentication check expected at that firmware interface, but the exact check is not public.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.lenovo.com/us/en/product_security/LEN-220440",
          "host": "support.lenovo.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 1,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 4,
        "affectedProductCount": 57,
        "affectedVersionEntryCount": 60
      }
    },
    {
      "cve_id": "CVE-2026-10600",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T09:04:58.161Z",
      "date_published": "2026-07-27T14:13:29.962Z",
      "date_updated": "2026-07-27T15:04:58.593Z",
      "publisher": "Mattermost",
      "title": "Denial of service via unbounded document content extraction in Mattermost Server",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12195
      },
      "nvd": {
        "published": "2026-07-27T15:16:46.623",
        "lastModified": "2026-08-03T15:24:46.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10600",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Document extraction has no effective work bound, so cheap repeated uploads can saturate the shared extraction worker pool.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-10610",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T11:52:51.095Z",
      "date_published": "2026-07-24T11:14:51.183Z",
      "date_updated": "2026-07-24T12:34:28.790Z",
      "publisher": "ESET",
      "title": "Local privilege escalation in ESET security applications for macOS",
      "affected": {
        "vendors": [
          "ESET spol. s.r.o."
        ],
        "products": [
          {
            "vendor": "ESET spol. s.r.o.",
            "product": "ESET Endpoint Security for macOS"
          },
          {
            "vendor": "ESET spol. s.r.o.",
            "product": "ESET Cyber Security for macOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@eset.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04025
      },
      "nvd": {
        "published": "2026-07-24T12:16:45.797",
        "lastModified": "2026-07-30T19:14:09.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10610",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports local privilege escalation in ESET macOS products but does not disclose the input, object, or privileged transition that enables it.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.eset.com/en/ca8977-eset-customer-advisory-local-privilege-escalation-vulnerability-in-eset-security-applications-for-macos-fixed",
          "host": "support.eset.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-10628",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T14:19:11.159Z",
      "date_published": "2026-07-11T02:31:17.468Z",
      "date_updated": "2026-07-15T13:55:16.005Z",
      "publisher": "Wordfence",
      "title": "Points and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions",
      "affected": {
        "vendors": [
          "wpswings"
        ],
        "products": [
          {
            "vendor": "wpswings",
            "product": "Points and Rewards for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27658
      },
      "nvd": {
        "published": "2026-07-11T04:17:02.733",
        "lastModified": "2026-07-15T14:17:16.543",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10628",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Multiple AJAX handlers accept a publicly obtainable nonce without enforcing the capability or object-level authorization required for the requested points and configuration changes.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/582e15cb-b924-4c24-818e-dfc2900f82c3?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/points-and-rewards-for-woocommerce/tags/2.10.0/public/class-points-rewards-for-woocommerce-public.php#L3493",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/points-and-rewards-for-woocommerce/tags/2.10.0/admin/class-points-rewards-for-woocommerce-admin.php#L2568",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/points-and-rewards-for-woocommerce/tags/2.10.0/admin/class-points-rewards-for-woocommerce-admin.php#L1814",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/points-and-rewards-for-woocommerce/tags/2.10.0/admin/class-points-rewards-for-woocommerce-admin.php#L2657",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/points-and-rewards-for-woocommerce/tags/2.10.0/public/class-points-rewards-for-woocommerce-public.php#L191",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/points-and-rewards-for-woocommerce/tags/2.9.7/public/class-points-rewards-for-woocommerce-public.php#L3493",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/points-and-rewards-for-woocommerce/tags/2.9.7/admin/class-points-rewards-for-woocommerce-admin.php#L2568",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/points-and-rewards-for-woocommerce/tags/2.9.7/admin/class-points-rewards-for-woocommerce-admin.php#L1814",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/points-and-rewards-for-woocommerce/tags/2.9.7/admin/class-points-rewards-for-woocommerce-admin.php#L2657",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/points-and-rewards-for-woocommerce/tags/2.9.7/public/class-points-rewards-for-woocommerce-public.php#L191",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3602815%40points-and-rewards-for-woocommerce&new=3602815%40points-and-rewards-for-woocommerce",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 984,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10656",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:24:30.893Z",
      "date_published": "2026-07-05T22:23:36.983Z",
      "date_updated": "2026-07-14T18:38:41.159Z",
      "publisher": "zephyr",
      "title": "NULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlers",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.16985
      },
      "nvd": {
        "published": "2026-07-05T23:16:52.730",
        "lastModified": "2026-07-14T19:16:49.150",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10656",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A queued USB transfer-completion event can outlive the endpoint buffer it expects and dereference NULL after another control path drains the FIFO.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/a0d8f786559355fb3b38e34799e1ae491ba9545c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-58p9-6mjq-rf2m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1412,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10657",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:24:32.170Z",
      "date_published": "2026-07-05T22:23:37.533Z",
      "date_updated": "2026-07-14T18:38:40.634Z",
      "publisher": "zephyr",
      "title": "Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20739
      },
      "nvd": {
        "published": "2026-07-05T23:16:52.863",
        "lastModified": "2026-07-14T19:16:49.270",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10657",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The mDNS suffix check reads seven bytes even when fewer than seven bytes remain before the hostname buffer ends.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/448a21da12c9ea28f7fd12c6894e03a987b17a27",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-76jh-3j5f-9vq4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1304,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10659",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:24:36.650Z",
      "date_published": "2026-07-07T12:58:11.505Z",
      "date_updated": "2026-07-14T18:38:42.162Z",
      "publisher": "zephyr",
      "title": "NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03319
      },
      "nvd": {
        "published": "2026-07-07T13:16:29.043",
        "lastModified": "2026-07-14T19:16:49.500",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10659",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Dhara callbacks write an error through a caller-supplied pointer even when the journal-resume path passes that pointer as null.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/a8371b0d4719efe37a66e2abb618ad9b81792212",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-q28v-3729-f82g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1180,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10660",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:24:37.969Z",
      "date_published": "2026-07-11T17:00:13.644Z",
      "date_updated": "2026-07-14T18:38:42.678Z",
      "publisher": "zephyr",
      "title": "Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruption",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.0554
      },
      "nvd": {
        "published": "2026-07-11T17:16:23.920",
        "lastModified": "2026-07-14T19:16:49.623",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10660",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Bluetooth BAP Broadcast Assistant connections reuse one file-static reassembly buffer, allowing data and length state from one connection to corrupt memory while another connection is using the same buffer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/0cd61589ff820b6a585c73cb36f1e14b043a2795",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-73c7-3rh7-v5p9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1614,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10663",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:25:23.699Z",
      "date_published": "2026-07-12T16:16:48.576Z",
      "date_updated": "2026-07-14T18:38:44.214Z",
      "publisher": "zephyr",
      "title": "Use-after-free / double-free of the root USB device in the experimental USB host stack",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.0548
      },
      "nvd": {
        "published": "2026-07-12T17:16:23.120",
        "lastModified": "2026-07-16T19:30:34.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10663",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "usbh_device_disconnect frees the root USB device without clearing ctx->root, allowing a second removal event to reuse and free the dangling object again.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/4b87a8f161a44cb19505fa97db7cf72f64d49165",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-26q8-xjq3-f5p6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1300,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10664",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:25:25.070Z",
      "date_published": "2026-07-12T16:16:49.115Z",
      "date_updated": "2026-07-14T18:38:45.254Z",
      "publisher": "zephyr",
      "title": "Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count)",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14387
      },
      "nvd": {
        "published": "2026-07-12T17:16:24.317",
        "lastModified": "2026-07-16T19:32:01.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10664",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The nRF70 handler copies an event-provided TWT flow count into an eight-entry array without checking the count or event length.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/a2c4324acd50a5f92e492e6e460e6297af826148",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3r6j-pm38-r43m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1325,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10665",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:25:26.403Z",
      "date_published": "2026-07-12T16:16:49.648Z",
      "date_updated": "2026-07-14T18:38:44.734Z",
      "publisher": "zephyr",
      "title": "Heap buffer overflow on WireGuard receive path via unbounded incoming packet length",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36331
      },
      "nvd": {
        "published": "2026-07-12T17:16:24.433",
        "lastModified": "2026-07-16T03:24:44.553",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10665",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "wg_process_data_message passes attacker-derived data_len as both capacity and copy length when linearizing into a CONFIG_WIREGUARD_BUF_LEN buffer, enabling an out-of-bounds write.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/6d8bb28dc9064e05e52b5a00b2998ecc663e38cb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3wqm-wgx2-9367",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1470,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10666",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:25:27.847Z",
      "date_published": "2026-07-12T16:16:50.160Z",
      "date_updated": "2026-07-14T18:38:43.193Z",
      "publisher": "zephyr",
      "title": "Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00454,
        "percentile": 0.37169
      },
      "nvd": {
        "published": "2026-07-12T17:16:24.550",
        "lastModified": "2026-07-17T13:25:12.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10666",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "parse_ipv4 copies an unbounded port suffix into a fixed 17-byte stack buffer without checking the destination size.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/1c8d19a51f9a3c1be6de53854c8ad8c2720a0f48",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/6e119a636a57be449ea21e73cad762ebc6f5ff7a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-532c-7g7f-jhmh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1406,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10667",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:25:29.239Z",
      "date_published": "2026-07-12T16:16:50.693Z",
      "date_updated": "2026-07-14T18:38:45.767Z",
      "publisher": "zephyr",
      "title": "SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04859
      },
      "nvd": {
        "published": "2026-07-12T17:16:24.670",
        "lastModified": "2026-07-16T20:19:00.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10667",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Zephyr traverses and removes dynamic kernel objects under disjoint locks, allowing one thread to free a list node while another still uses it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/fdc42fa256b8c2a7b27790f032d5385f8058c4a9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-9x5j-h3rh-x579",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1772,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10668",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:25:30.579Z",
      "date_published": "2026-07-12T16:16:51.243Z",
      "date_updated": "2026-07-14T18:38:43.695Z",
      "publisher": "zephyr",
      "title": "Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 2.1999999999999997,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05479
      },
      "nvd": {
        "published": "2026-07-12T17:16:24.787",
        "lastModified": "2026-07-16T20:06:47.973",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10668",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The driver arms control Data IN before confirming an IN token or excluding a newer SETUP event, so a cancelled transfer leaves stale endpoint state that wedges later control transfers.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/48e003326873e8bbc0ee4b67334e0dd8b5fb890f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-rm28-x84j-4qrx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1464,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10669",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:25:31.939Z",
      "date_published": "2026-07-14T15:02:02.932Z",
      "date_updated": "2026-07-14T18:38:46.273Z",
      "publisher": "zephyr",
      "title": "Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validation",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01722
      },
      "nvd": {
        "published": "2026-07-14T15:16:55.210",
        "lastModified": "2026-07-14T19:16:50.410",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10669",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the architecture hook that verifies a user-mode-supplied buffer is accessible to the calling user thread with the requested permission — defaulted its return value to 0 (access permitted) and only set a denial result inside its per-MPU-region probe loop.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/3b1bdaf5482188ca110ef9a411aaa8c7d3db3b16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-4r4p-gh69-v6w4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1643,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10670",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:25:33.216Z",
      "date_published": "2026-07-14T15:02:03.452Z",
      "date_updated": "2026-07-14T18:38:47.284Z",
      "publisher": "zephyr",
      "title": "User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifier",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.00998
      },
      "nvd": {
        "published": "2026-07-14T15:16:55.330",
        "lastModified": "2026-07-14T19:16:50.513",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10670",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The syscall verifier checks the caller-supplied thread pointer instead of the NULL result from k_object_find() before dereferencing ko->type.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/491583951036bc5794a3843a4baa246453bb1ee2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-82h2-v4vm-q2g9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1372,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10671",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:25:34.550Z",
      "date_published": "2026-07-14T15:02:03.971Z",
      "date_updated": "2026-07-14T18:38:46.782Z",
      "publisher": "zephyr",
      "title": "User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`)",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-825",
          "name": "Expired Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00103,
        "percentile": 0.01139
      },
      "nvd": {
        "published": "2026-07-14T15:16:55.447",
        "lastModified": "2026-07-14T19:16:50.610",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10671",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The userspace verifier permits reinitialization of a live kernel pipe, clearing wait queues while blocked threads still retain links into the old queue state.",
        "basis": [
          "CNA",
          "CWE-825"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/4424aa681e0b80e9cbd0ae27a987d582be88cb74",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-p8w8-3x99-mg8f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1630,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10672",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:25:35.843Z",
      "date_published": "2026-07-14T15:02:04.482Z",
      "date_updated": "2026-07-14T18:38:47.765Z",
      "publisher": "zephyr",
      "title": "Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.2772
      },
      "nvd": {
        "published": "2026-07-14T15:16:55.560",
        "lastModified": "2026-07-14T19:16:50.710",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10672",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A length or termination error makes the program read beyond the end of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/99a164df5cea5af76e32b57c6d51854f018969a2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-rf6j-4mpp-j9mf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1373,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10673",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:02.427Z",
      "date_published": "2026-07-15T17:36:31.645Z",
      "date_updated": "2026-07-15T18:01:15.864Z",
      "publisher": "zephyr",
      "title": "Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14215
      },
      "nvd": {
        "published": "2026-07-15T18:16:44.180",
        "lastModified": "2026-07-15T20:15:56.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10673",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Zephyr driver copies device-supplied OA SPI chunks into a 1524-byte static buffer without checking the accumulated cursor and chunk length against that buffer.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/158df8d088316cdae20816fc07703892280b2acb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/c98321cbfef23c0e3bdf043ccf6b421067c8d508",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hm6v-4jh4-3qc4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1380,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10674",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:03.742Z",
      "date_published": "2026-07-21T21:30:53.643Z",
      "date_updated": "2026-07-22T19:37:08.367Z",
      "publisher": "zephyr",
      "title": "DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01323
      },
      "nvd": {
        "published": "2026-07-21T22:16:58.740",
        "lastModified": "2026-07-30T16:08:31.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10674",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The driver disables the LPUART clock before validating a requested configuration and returns on an unsupported value without restoring the clock.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/f56935c46fdf6559a20ad8484b29896ecac5808f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-mw68-r353-m3vf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1259,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10675",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:04.929Z",
      "date_published": "2026-07-21T21:30:54.165Z",
      "date_updated": "2026-07-22T19:37:01.018Z",
      "publisher": "zephyr",
      "title": "Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16329
      },
      "nvd": {
        "published": "2026-07-21T22:16:59.800",
        "lastModified": "2026-07-30T16:07:41.977",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10675",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The provisioning timer is reset before FCS and invalid-link checks, allowing a dead link to remain active.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/3f3c37edf80262b838ef5402fec9880c07892e4e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-4rwg-6mr4-55hc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1648,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10677",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:07.313Z",
      "date_published": "2026-07-21T21:30:54.690Z",
      "date_updated": "2026-07-22T19:36:53.593Z",
      "publisher": "zephyr",
      "title": "Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource pool",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01323
      },
      "nvd": {
        "published": "2026-07-21T22:16:59.923",
        "lastModified": "2026-07-30T15:55:39.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10677",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The syscall-verifier failure path kills the caller without releasing events_copy, allowing repeated sacrificial threads to exhaust the shared kernel heap.",
        "basis": [
          "CNA record",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/8dc7a37bc75402a0a3329397887f32f5fb4da3ad",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-r3cc-8wcr-xfj9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1024,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10678",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:08.472Z",
      "date_published": "2026-07-21T21:30:55.193Z",
      "date_updated": "2026-07-22T19:36:46.774Z",
      "publisher": "zephyr",
      "title": "NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25567
      },
      "nvd": {
        "published": "2026-07-21T22:17:00.047",
        "lastModified": "2026-07-30T15:54:58.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10678",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "zephyr lets attacker-controlled input reach an out-of-bounds write.",
        "basis": [
          "CNA",
          "CWE-476",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/9e23364261a2188c171d734d6947e02ee2a9510f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-pmwm-5rcm-39rr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1540,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10679",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:09.584Z",
      "date_published": "2026-07-21T21:30:55.714Z",
      "date_updated": "2026-07-22T19:36:39.798Z",
      "publisher": "zephyr",
      "title": "Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS)",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-369",
          "name": "Divide By Zero",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03027
      },
      "nvd": {
        "published": "2026-07-21T22:17:00.177",
        "lastModified": "2026-07-30T15:54:36.877",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10679",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SPI path accepts a zero frequency from userspace and divides by that value while calculating controller timing.",
        "basis": [
          "CNA",
          "CWE-369"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/65935885622b0e4a5dbe5b82504c30097eb75ce0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3qcm-qwh2-v4hq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1114,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10680",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:10.782Z",
      "date_published": "2026-07-21T21:30:56.255Z",
      "date_updated": "2026-07-22T19:36:33.625Z",
      "publisher": "zephyr",
      "title": "Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflow",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00111,
        "percentile": 0.01515
      },
      "nvd": {
        "published": "2026-07-21T22:17:00.303",
        "lastModified": "2026-07-30T15:54:25.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10680",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The L2CAP handlers compare the whole PDU's remaining length instead of the current command length, allowing a uint16_t option length to underflow and drive out-of-bounds reads and writes.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/1d451683377f4c8e56d7718565bea7b5c1155159",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-vrwx-p97q-8854",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1531,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-10681",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:11.951Z",
      "date_published": "2026-07-25T13:23:07.028Z",
      "date_updated": "2026-07-27T14:34:43.843Z",
      "publisher": "zephyr",
      "title": "SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00079,
        "percentile": 0.00197
      },
      "nvd": {
        "published": "2026-07-25T14:16:28.957",
        "lastModified": "2026-07-27T20:32:27.703",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10681",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Zephyr allocates SMP permission slots from a shared bitmap without holding lists_lock, so concurrent callers can receive the same slot.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/862ea2fbbeb2ccdf8ff994b03e2e3b4405f2c37d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-j693-5rh5-8g8h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1365,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10682",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:19.350Z",
      "date_published": "2026-07-27T18:30:49.447Z",
      "date_updated": "2026-07-27T19:00:21.365Z",
      "publisher": "zephyr",
      "title": "Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00101,
        "percentile": 0.01056
      },
      "nvd": {
        "published": "2026-07-27T19:17:14.070",
        "lastModified": "2026-07-27T20:32:27.703",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10682",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "z_vrfy_log_filter_set accepts a negative int16_t source ID, which is converted to a large unsigned array index and drives a supervisor-mode out-of-bounds read-modify-write.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/56a15114c6acbab2067fe406dc3adda8608f3def",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-6vqh-mg7h-58qh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1447,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10683",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:20.475Z",
      "date_published": "2026-07-27T18:30:49.935Z",
      "date_updated": "2026-07-27T19:00:53.973Z",
      "publisher": "zephyr",
      "title": "DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS)",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03864
      },
      "nvd": {
        "published": "2026-07-27T19:17:14.683",
        "lastModified": "2026-07-27T20:32:27.703",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10683",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The DesignWare I2C target driver leaves START_DET masked, so a repeated START can leave the state permanently in CMD_SEND and suppress every later write_requested callback.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/06e2053efe0e324d71cc29cdd95160fff643730a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fj9c-r5qw-3639",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1315,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:21.656Z",
      "date_published": "2026-07-29T18:03:08.771Z",
      "date_updated": "2026-07-29T18:47:20.793Z",
      "publisher": "zephyr",
      "title": "Out-of-bounds read in coredump shell when printing stored-dump target code",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.00994
      },
      "nvd": {
        "published": "2026-07-29T19:16:43.677",
        "lastModified": "2026-07-30T14:19:24.857",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10684",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unchecked tgt_code value indexes beyond an array and yields an invalid pointer that is later dereferenced as a string.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/a9226324e8bd1f8adecafb1b6e0603f781dc750c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-9fw2-4429-49q8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1122,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-10685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:22.870Z",
      "date_published": "2026-07-31T14:41:47.259Z",
      "date_updated": "2026-07-31T17:47:05.001Z",
      "publisher": "zephyr",
      "title": "Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07846
      },
      "nvd": {
        "published": "2026-07-31T15:16:27.433",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10685",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The zephyr path retains or dereferences an object after the object's storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/c7292f20223637232b6f962141725611a38f6a52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-29xh-jm2m-4qvx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1284,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10686",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T15:26:24.115Z",
      "date_published": "2026-07-31T15:49:10.405Z",
      "date_updated": "2026-07-31T17:30:15.422Z",
      "publisher": "zephyr",
      "title": "Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers",
      "affected": {
        "vendors": [
          "zephyrproject"
        ],
        "products": [
          {
            "vendor": "zephyrproject",
            "product": "zephyr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L"
        },
        {
          "source": "NVD:vulnerabilities@zephyrproject.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.1602
      },
      "nvd": {
        "published": "2026-07-31T16:16:57.283",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10686",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Zephyr forwards routed IPv6 unicast packets without decrementing the hop limit, permitting forwarding loops that never reach a protocol termination bound.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/commit/7d8f1afa7345975b58405d6fba18bb8c3f7cb12a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-4cg6-6jc4-2r6h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2163,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T16:01:12.558Z",
      "date_published": "2026-07-30T16:55:20.162Z",
      "date_updated": "2026-07-30T18:07:42.667Z",
      "publisher": "ibm",
      "title": "IBM® Db2® is vulnerable to a denial of service when running non fenced federated queries",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Db2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Primary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01983
      },
      "nvd": {
        "published": "2026-07-30T19:17:01.830",
        "lastModified": "2026-07-30T19:31:02.643",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10695",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says a non-fenced federated query can stop IBM Db2, but it does not disclose the unbounded operation, parser fault, or memory failure that causes the denial of service.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279474",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T16:42:36.544Z",
      "date_published": "2026-07-23T19:54:48.304Z",
      "date_updated": "2026-07-25T03:55:21.025Z",
      "publisher": "ProgressSoftware",
      "title": "MFA Bypass in MOVEit Transfer",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "MOVEit Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 2.3000000000000007,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21393
      },
      "nvd": {
        "published": "2026-07-23T21:17:01.597",
        "lastModified": "2026-07-30T15:50:34.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10697",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A legacy MOVEit integration endpoint did not enforce the authentication required to prevent an MFA bypass.",
        "basis": [
          "CNA",
          "CWE-287",
          "Progress MOVEit 2026.0.3 release notes"
        ],
        "deepDive": true,
        "notes": "https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.0.3.html was inspected; Progress identifies issue 103651 as authentication enforcement on a legacy integration endpoint but does not publish the request path or bypass condition."
      },
      "references": [
        {
          "url": "https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.0.3.html",
          "host": "docs.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 151,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-10698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T16:42:37.519Z",
      "date_published": "2026-07-08T14:16:25.696Z",
      "date_updated": "2026-07-09T03:55:42.859Z",
      "publisher": "ProgressSoftware",
      "title": "Table scope bypass vulnerability in custom reports",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "MOVEit Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-943",
          "name": "Improper Neutralization of Special Elements in Data Query Logic",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00496,
        "percentile": 0.39822
      },
      "nvd": {
        "published": "2026-07-08T15:16:25.040",
        "lastModified": "2026-07-10T14:33:24.257",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10698",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component lets attacker-controlled text cross into an executable or interpreted grammar without the required separation.",
        "basis": [
          "CNA",
          "CWE-943"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://community.progress.com/s/article/MOVEit-Transfer-Critical-Security-Bulletin-June-2026",
          "host": "community.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 261,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-10699",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T16:42:38.825Z",
      "date_published": "2026-07-08T14:18:00.255Z",
      "date_updated": "2026-07-08T15:09:09.431Z",
      "publisher": "ProgressSoftware",
      "title": "Memory leak in SFTP service can result in a denial of service in MOVEit Transfer",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "MOVEit Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26611
      },
      "nvd": {
        "published": "2026-07-08T15:16:25.173",
        "lastModified": "2026-07-10T14:25:58.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10699",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A MOVEit error path loses ownership of an allocated object and does not release it, allowing repeated requests to accumulate memory.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.progress.com/s/article/MOVEit-Transfer-Critical-Security-Bulletin-June-2026",
          "host": "community.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-10700",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T16:51:40.980Z",
      "date_published": "2026-07-30T16:51:24.667Z",
      "date_updated": "2026-07-31T23:02:28.146Z",
      "publisher": "ibm",
      "title": "Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorized Access to User Files",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00411,
        "percentile": 0.33841
      },
      "nvd": {
        "published": "2026-07-30T19:17:02.100",
        "lastModified": "2026-07-31T23:17:23.070",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10700",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts a caller-supplied object identifier without verifying that the selected object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279675",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 913,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10706",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T17:46:45.590Z",
      "date_published": "2026-07-08T14:06:34.842Z",
      "date_updated": "2026-07-09T15:13:42.687Z",
      "publisher": "certcc",
      "title": "Exposure of Sensitive Information to an Unauthorized attacker",
      "affected": {
        "vendors": [
          "Adalo No-Code App Builder"
        ],
        "products": [
          {
            "vendor": "Adalo No-Code App Builder",
            "product": "App Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00376,
        "percentile": 0.30333
      },
      "nvd": {
        "published": "2026-07-08T15:16:25.287",
        "lastModified": "2026-07-09T19:49:55.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10706",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Adalo accepts enumerable dbId values without binding the requested user record to an authorized app or caller, exposing complete records across applications.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.cert.org/vuls/id/849433",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10708",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T17:59:57.666Z",
      "date_published": "2026-07-08T14:05:15.678Z",
      "date_updated": "2026-07-09T15:13:00.989Z",
      "publisher": "certcc",
      "title": "Insufficiently Protected Credentials",
      "affected": {
        "vendors": [
          "Adalo No-Code App Builder"
        ],
        "products": [
          {
            "vendor": "Adalo No-Code App Builder",
            "product": "App Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        },
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09577
      },
      "nvd": {
        "published": "2026-07-08T15:16:25.377",
        "lastModified": "2026-07-09T19:49:55.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10708",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A public component returns user records while wildcard cross-origin access and long-lived unrevoked tokens let unrelated web origins harvest them.",
        "basis": [
          "CNA",
          "CWE-346",
          "CWE-522",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.cert.org/vuls/id/849433",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 408,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10714",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T19:25:13.142Z",
      "date_published": "2026-07-14T15:02:09.653Z",
      "date_updated": "2026-07-14T15:26:53.203Z",
      "publisher": "Rockwell",
      "title": "Rockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication via JWT Validation Bypass",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "FactoryTalk® Services Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1390",
          "name": "Weak Authentication",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01676
      },
      "nvd": {
        "published": "2026-07-14T15:16:55.673",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10714",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "FTSP accepts a JWT whose algorithm is none because it does not require the configured RSA signature algorithm before trusting the token identity.",
        "basis": [
          "CNA",
          "CWE-1390"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1786.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T07:56:36.024Z",
      "date_published": "2026-07-22T14:08:19.609Z",
      "date_updated": "2026-07-22T18:47:43.659Z",
      "publisher": "isc",
      "title": "Incorrect acceptance of NSEC3 records",
      "affected": {
        "vendors": [
          "ISC"
        ],
        "products": [
          {
            "vendor": "ISC",
            "product": "BIND 9"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-officer@isc.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18301
      },
      "nvd": {
        "published": "2026-07-22T15:16:51.190",
        "lastModified": "2026-07-22T20:33:11.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10723",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BIND accepts an invalid child-zone NSEC3 proof as authenticated and can therefore treat an attacker-forged NXDOMAIN response as DNSSEC-valid.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.isc.org/docs/cve-2026-10723",
          "host": "kb.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.20.26",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.21.24",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-10724",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T09:15:24.361Z",
      "date_published": "2026-07-20T06:00:01.979Z",
      "date_updated": "2026-07-20T13:17:47.950Z",
      "publisher": "WPScan",
      "title": "Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google Reviews",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Reviews Feed"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00092,
        "percentile": 0.00624
      },
      "nvd": {
        "published": "2026-07-20T07:16:34.340",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10724",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Third-party review text is rendered through WordPress shortcode processing without neutralizing embedded shortcodes.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/7def5cf4-655d-424b-b1fc-eb333465434e/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 334,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10750",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T13:54:53.609Z",
      "date_published": "2026-07-01T06:00:01.661Z",
      "date_updated": "2026-07-01T10:20:41.864Z",
      "publisher": "WPScan",
      "title": "Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Royal MCP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18683
      },
      "nvd": {
        "published": "2026-07-01T07:16:21.890",
        "lastModified": "2026-07-01T18:17:52.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10750",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Royal MCP authenticates a token but omits WordPress capability checks before its tools perform privileged actions.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/8678ef91-ff05-43a1-a8e3-6d35da548826/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T14:19:40.486Z",
      "date_published": "2026-07-20T06:00:02.224Z",
      "date_updated": "2026-07-20T13:17:03.527Z",
      "publisher": "WPScan",
      "title": "All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "All in One SEO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06481
      },
      "nvd": {
        "published": "2026-07-20T07:16:34.443",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10755",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that All in One SEO permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/cc4e83e3-b581-4f65-ac2c-24fbfb9da4b3/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T15:41:14.341Z",
      "date_published": "2026-07-10T21:41:38.602Z",
      "date_updated": "2026-07-14T14:35:01.464Z",
      "publisher": "drupal",
      "title": "LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "LocalGov Workflows"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25612
      },
      "nvd": {
        "published": "2026-07-10T22:16:38.173",
        "lastModified": "2026-07-14T15:16:55.797",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10768",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "LocalGov Workflows fails to apply the required view-access check to Service Contacts, allowing otherwise unauthorized users to force-browse names and the content items to which those contacts are assigned.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862",
          "Drupal advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Drupal SA-CONTRIB-2026-039 at https://www.drupal.org/sa-contrib-2026-039; it identifies unauthorized Service Contact viewing and the 1.6.0 repair release, but no fixed/vulnerable source line or patch-level access check was inspected."
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-039",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 159,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T15:41:15.212Z",
      "date_published": "2026-07-10T21:41:49.434Z",
      "date_updated": "2026-07-14T14:34:55.801Z",
      "publisher": "drupal",
      "title": "Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Commerce Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05828
      },
      "nvd": {
        "published": "2026-07-10T22:16:38.670",
        "lastModified": "2026-07-14T15:16:55.940",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10769",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Commerce Core stores attacker-controlled content and later renders it in a browser context without the required contextual neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-041",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T15:41:16.331Z",
      "date_published": "2026-07-10T21:42:57.867Z",
      "date_updated": "2026-07-14T14:34:48.521Z",
      "publisher": "drupal",
      "title": "Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Anti-Spam by CleanTalk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07882
      },
      "nvd": {
        "published": "2026-07-10T22:16:38.770",
        "lastModified": "2026-07-14T15:16:56.080",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10770",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Anti-Spam by CleanTalk reflects request input into HTML without context-appropriate escaping, allowing script execution after a victim opens the crafted request.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-042",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10818",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T07:00:23.213Z",
      "date_published": "2026-07-25T06:50:06.104Z",
      "date_updated": "2026-07-27T17:59:48.632Z",
      "publisher": "Wordfence",
      "title": "WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering",
      "affected": {
        "vendors": [
          "WPForms"
        ],
        "products": [
          {
            "vendor": "WPForms",
            "product": "WPForms Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0042,
        "percentile": 0.34605
      },
      "nvd": {
        "published": "2026-07-25T07:17:08.880",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10818",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The chunk finalizer writes and assembles the upload before validating its type and leaves the file in place when that later validation fails.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b267f163-966a-43f7-8a7c-67d34c2c7e9d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://wpforms.com/",
          "host": "wpforms.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 494,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10819",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T07:34:33.428Z",
      "date_published": "2026-07-27T14:15:25.000Z",
      "date_updated": "2026-07-27T15:05:28.394Z",
      "publisher": "Mattermost",
      "title": "Mattermost Server Denial of Service via Animated GIF Emoji Upload",
      "affected": {
        "vendors": [
          "Mattermost"
        ],
        "products": [
          {
            "vendor": "Mattermost",
            "product": "Mattermost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:responsibledisclosure@mattermost.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15182
      },
      "nvd": {
        "published": "2026-07-27T15:16:46.770",
        "lastModified": "2026-08-03T15:23:50.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-10819",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The custom-emoji decoder enforces neither an animated GIF frame limit nor the intended upload size cap.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mattermost.com/security-updates",
          "host": "mattermost.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-10822",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T07:51:13.246Z",
      "date_published": "2026-07-22T14:09:57.419Z",
      "date_updated": "2026-07-22T18:53:34.291Z",
      "publisher": "isc",
      "title": "Key Record using PRIVATEDNS algorithm may lead to unexpected exit",
      "affected": {
        "vendors": [
          "ISC"
        ],
        "products": [
          {
            "vendor": "ISC",
            "product": "BIND 9"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-officer@isc.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29845
      },
      "nvd": {
        "published": "2026-07-22T15:16:51.330",
        "lastModified": "2026-07-22T20:33:11.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10822",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "BIND accepts a DNS identifier length that exceeds the available record bytes and later reaches an assertion while processing the inconsistent structure.",
        "basis": [
          "CNA",
          "CWE-617",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.isc.org/docs/cve-2026-10822",
          "host": "kb.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.20.26",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.21.24",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 718,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-10830",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T10:01:02.658Z",
      "date_published": "2026-07-06T06:00:01.302Z",
      "date_updated": "2026-07-06T12:03:51.033Z",
      "publisher": "WPScan",
      "title": "AllCoach < 1.0.2 - Unauthenticated Account Takeover",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "AllCoach"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15109
      },
      "nvd": {
        "published": "2026-07-06T08:16:34.987",
        "lastModified": "2026-07-06T18:37:01.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10830",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The public registration endpoint overwrites an existing user password when the supplied email already belongs to that account, without authenticating the account owner.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/194e35d8-08ca-402d-a9bb-52383bc3dfab/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 352,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10834",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T10:36:22.209Z",
      "date_published": "2026-07-07T06:00:01.354Z",
      "date_updated": "2026-07-09T15:01:48.500Z",
      "publisher": "WPScan",
      "title": "WP Travel Engine < 6.8.1 - Subscriber+ Arbitrary Media File Move via user_profile_image",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Travel Engine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04012
      },
      "nvd": {
        "published": "2026-07-07T06:16:21.637",
        "lastModified": "2026-07-09T16:16:34.507",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10834",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the WordPress uploads directory into their own profile-image path.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/5b939f98-0fbd-4f89-9948-77dbcc67f9d3/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-10842",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T11:48:12.087Z",
      "date_published": "2026-07-30T15:57:16.828Z",
      "date_updated": "2026-07-30T17:37:19.123Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          },
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-289",
          "name": "Authentication Bypass by Alternate Name",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25183
      },
      "nvd": {
        "published": "2026-07-30T16:16:53.980",
        "lastModified": "2026-07-30T19:17:02.390",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10842",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record reports a remotely reachable alternate-name authentication bypass but does not identify the accepted alias or failing constraint.",
        "basis": [
          "CNA",
          "CWE-289"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280131",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-10865",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T14:10:06.318Z",
      "date_published": "2026-07-11T05:35:46.548Z",
      "date_updated": "2026-07-13T17:35:45.659Z",
      "publisher": "Wordfence",
      "title": "Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys",
      "affected": {
        "vendors": [
          "stylemix"
        ],
        "products": [
          {
            "vendor": "stylemix",
            "product": "Cost Calculator Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29773
      },
      "nvd": {
        "published": "2026-07-11T07:16:44.927",
        "lastModified": "2026-07-13T18:16:26.363",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-10865",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "When global payment settings are enabled, the plugin embeds plaintext payment-gateway secrets in the rendered page source available to unauthenticated visitors.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/29de766d-5e7e-46b4-acac-feec5b33589e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/4.0.5/templates/frontend/render.php#L281",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/4.0.5/templates/frontend/render.php#L61",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/4.0.5/templates/frontend/render.php#L28",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/4.0.5/includes/functions.php#L748",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/templates/frontend/render.php#L281",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/templates/frontend/render.php#L61",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/templates/frontend/render.php#L28",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/functions.php#L748",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3578557%40cost-calculator-builder&new=3578557%40cost-calculator-builder",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11321",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T20:57:26.934Z",
      "date_published": "2026-07-10T18:53:56.004Z",
      "date_updated": "2026-07-30T14:39:12.341Z",
      "publisher": "VulnCheck",
      "title": "GLPI DataInjection Plugin Authenticated SQL Injection via CSV Import",
      "affected": {
        "vendors": [
          "pluginsGLPI"
        ],
        "products": [
          {
            "vendor": "pluginsGLPI",
            "product": "datainjection"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23799
      },
      "nvd": {
        "published": "2026-07-10T20:16:45.453",
        "lastModified": "2026-07-14T15:16:56.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11321",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pluginsGLPI/datainjection/security/advisories/GHSA-57qv-j6r6-pcc4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/pluginsGLPI/datainjection/releases/tag/2.15.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/pluginsGLPI/datainjection",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/glpi-datainjection-plugin-authenticated-sql-injection-via-csv-import",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 477,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11324",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T22:10:12.885Z",
      "date_published": "2026-07-17T02:31:31.888Z",
      "date_updated": "2026-07-17T18:05:42.895Z",
      "publisher": "Wordfence",
      "title": "WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'",
      "affected": {
        "vendors": [
          "evertec"
        ],
        "products": [
          {
            "vendor": "evertec",
            "product": "WooCommerce Placetopay Gateway Belice"
          },
          {
            "vendor": "evertec",
            "product": "WooCommerce Placetopay Gateway Ecuador"
          },
          {
            "vendor": "evertec",
            "product": "WooCommerce Placetopay Gateway Colombia"
          },
          {
            "vendor": "evertec",
            "product": "WooCommerce Placetopay Gateway Uruguay"
          },
          {
            "vendor": "evertec",
            "product": "WooCommerce Placetopay Gateway"
          },
          {
            "vendor": "evertec",
            "product": "WooCommerce Placetopay Gateway Honduras"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20237
      },
      "nvd": {
        "published": "2026-07-17T04:16:50.177",
        "lastModified": "2026-07-17T19:17:12.170",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11324",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches WooCommerce Placetopay Gateway Belice page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8ca87868-357b-4d71-9bf9-cd3b15b2555d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://banco.santander.cl/uploads/000/049/181/1705c2cf-fc73-4fc4-a29d-f56f3ea88103/original/woocommerce-gateway-placetopay-2_24_1-php-8_x.zip",
          "host": "banco.santander.cl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/placetopay/woocommerce-gateway-placetopay/releases/tag/3.2.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/placetopay/woocommerce-gateway-placetopay/blob/3.2.2/src/GatewayMethod.php#L600",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/placetopay/woocommerce-gateway-placetopay/blob/3.2.2/src/GatewayMethod.php#L718",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/placetopay/woocommerce-gateway-placetopay/blob/3.2.2/src/GatewayMethod.php#L1824",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/placetopay/woocommerce-gateway-placetopay/blob/3.2.2/src/GatewayMethod.php#L1852",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://evertecinc.com/en/solution/placetopay/",
          "host": "evertecinc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-11328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T06:33:35.761Z",
      "date_published": "2026-07-07T01:28:27.566Z",
      "date_updated": "2026-07-07T13:42:09.849Z",
      "publisher": "Wordfence",
      "title": "Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title",
      "affected": {
        "vendors": [
          "timstrifler"
        ],
        "products": [
          {
            "vendor": "timstrifler",
            "product": "Exclusive Addons for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14151
      },
      "nvd": {
        "published": "2026-07-07T02:16:28.583",
        "lastModified": "2026-07-07T14:16:27.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11328",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A contributor-controlled post title is stored without sufficient sanitization or output escaping and later executes as browser script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/690fd38c-0e12-45f3-9055-51252e4809b1?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/exclusive-addons-for-elementor/tags/2.7.9.8/extensions/post-duplicator.php#L34",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/exclusive-addons-for-elementor/tags/2.7.9.8/extensions/post-duplicator.php#L19",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11331",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T07:03:42.361Z",
      "date_published": "2026-07-22T14:10:44.763Z",
      "date_updated": "2026-07-22T18:54:17.064Z",
      "publisher": "isc",
      "title": "Potential wildcard CNAME RPZ policy bypass",
      "affected": {
        "vendors": [
          "ISC"
        ],
        "products": [
          {
            "vendor": "ISC",
            "product": "BIND 9"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-790",
          "name": "Improper Filtering of Special Elements",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-officer@isc.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00416,
        "percentile": 0.34259
      },
      "nvd": {
        "published": "2026-07-22T15:16:51.457",
        "lastModified": "2026-07-22T20:33:11.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11331",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unhandled name-too-long condition during RPZ wildcard processing can bypass policy handling or terminate the service.",
        "basis": [
          "CNA",
          "CWE-790"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.isc.org/docs/cve-2026-11331",
          "host": "kb.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.20.26",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.21.24",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 490,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-11340",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T08:19:03.687Z",
      "date_published": "2026-07-07T11:01:33.542Z",
      "date_updated": "2026-07-07T12:05:14.017Z",
      "publisher": "TR-CERT",
      "title": "Authorization Bypass in HAVELSAN's Open Source Project Liman MYS",
      "affected": {
        "vendors": [
          "HAVELSAN Inc."
        ],
        "products": [
          {
            "vendor": "HAVELSAN Inc.",
            "product": "Liman MYS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09409
      },
      "nvd": {
        "published": "2026-07-07T11:16:32.247",
        "lastModified": "2026-07-07T13:19:36.010",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11340",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Liman MYS exposes functionality outside its intended ACL, but the record does not identify the affected operation or failed authorization check.",
        "basis": [
          "CNA record",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0504",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 186,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T09:05:34.611Z",
      "date_published": "2026-07-07T11:11:20.646Z",
      "date_updated": "2026-07-07T13:23:08.844Z",
      "publisher": "TR-CERT",
      "title": "Authentication Bypass in HAVELSAN's Open Source Project Liman MYS",
      "affected": {
        "vendors": [
          "HAVELSAN Inc."
        ],
        "products": [
          {
            "vendor": "HAVELSAN Inc.",
            "product": "Liman MYS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00185,
        "percentile": 0.08331
      },
      "nvd": {
        "published": "2026-07-07T12:16:28.617",
        "lastModified": "2026-07-07T14:16:27.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11348",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Liman MYS accepts signed data without correctly verifying the signature against the trusted key and message.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0504",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T09:13:52.543Z",
      "date_published": "2026-07-20T06:00:02.457Z",
      "date_updated": "2026-07-20T13:16:15.469Z",
      "publisher": "WPScan",
      "title": "Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_more",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Modern Event Calendar Pro"
          },
          {
            "vendor": "Unknown",
            "product": "Modern Events Calendar Lite"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24574
      },
      "nvd": {
        "published": "2026-07-20T07:16:34.547",
        "lastModified": "2026-07-20T20:39:31.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11349",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The event-calendar endpoint incorporates an unauthenticated request parameter into a database query without SQL parameter separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/572229cb-8a09-406d-8623-7d6b553bfdde/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-11351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T11:12:04.961Z",
      "date_published": "2026-07-29T06:00:01.926Z",
      "date_updated": "2026-07-29T12:54:59.808Z",
      "publisher": "WPScan",
      "title": "ShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information Disclosure",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "ShinyStat Analytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.1084
      },
      "nvd": {
        "published": "2026-07-29T07:16:40.130",
        "lastModified": "2026-07-30T14:16:31.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11351",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A public REST endpoint returns metadata for draft, pending, and private WooCommerce products without authorizing access to those publication states.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/cac3a0c4-e6b9-42a6-b702-abcba67038c2/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T11:23:43.389Z",
      "date_published": "2026-07-03T06:12:10.777Z",
      "date_updated": "2026-07-06T18:27:49.432Z",
      "publisher": "curl",
      "title": "QUIC zero-length UDP datagrams busy-loop",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00577,
        "percentile": 0.44304
      },
      "nvd": {
        "published": "2026-07-03T07:16:23.693",
        "lastModified": "2026-07-07T18:01:19.013",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-11352",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Malformed input can enter a loop whose exit condition is never reached, monopolizing the processing thread.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-11352.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11352.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3783438",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 364,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-11354",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T11:25:56.930Z",
      "date_published": "2026-07-24T02:32:00.774Z",
      "date_updated": "2026-07-24T21:18:17.757Z",
      "publisher": "Wordfence",
      "title": "Participants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' Parameter",
      "affected": {
        "vendors": [
          "xnau"
        ],
        "products": [
          {
            "vendor": "xnau",
            "product": "Participants Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15105
      },
      "nvd": {
        "published": "2026-07-24T04:16:51.030",
        "lastModified": "2026-07-24T22:16:50.677",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11354",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public update path accepts an attacker-selected participant ID without checking authorization or ownership, allowing an unauthenticated caller to redirect access to another participant's record.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ff1b8d09-974a-4735-8b63-15084412090d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/participants-database/tags/2.7.8.3/classes/PDb_submission/main_query/update_query.php#L57",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/participants-database/tags/2.7.8.3/participants-database.php#L2437",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/participants-database/tags/2.7.8.3/participants-database.php#L1671",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/participants-database/tags/2.7.8.3/classes/PDb_Shortcode.php#L1267",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3606851%40participants-database&new=3606851%40participants-database",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 896,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T11:36:33.315Z",
      "date_published": "2026-07-09T07:55:13.308Z",
      "date_updated": "2026-07-09T17:34:45.149Z",
      "publisher": "Wordfence",
      "title": "Memberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and Activation",
      "affected": {
        "vendors": [
          "metagauss"
        ],
        "products": [
          {
            "vendor": "metagauss",
            "product": "Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15961
      },
      "nvd": {
        "published": "2026-07-09T08:16:45.467",
        "lastModified": "2026-07-09T18:16:50.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11359",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The pg_install_profilegrid AJAX handler checks neither a capability nor a valid nonce before installing and activating a plugin for a Subscriber-level caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4cce2842-bd8e-4a83-b83c-66aefe4df4b8?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ecommerce-user-profiles-by-profilegrid/tags/3.4/admin/class-profilegrid-woocommerce-admin.php#L303",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ecommerce-user-profiles-by-profilegrid/tags/3.4/includes/class-profilegrid-woocommerce.php#L166",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ecommerce-user-profiles-by-profilegrid/tags/3.4/admin/class-profilegrid-woocommerce-admin.php#L352",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3592677%40ecommerce-user-profiles-by-profilegrid&new=3592677%40ecommerce-user-profiles-by-profilegrid",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T12:01:56.518Z",
      "date_published": "2026-07-16T06:00:02.874Z",
      "date_updated": "2026-07-16T12:33:27.605Z",
      "publisher": "WPScan",
      "title": "BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "BetterDocs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05862
      },
      "nvd": {
        "published": "2026-07-16T07:16:46.480",
        "lastModified": "2026-07-16T13:43:05.487",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11371",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unauthenticated AI-summary path stores attacker-supplied markup without sanitizing it for later browser rendering.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/db41e3db-74c2-4b94-bbff-bd1493295241/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 369,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T12:53:14.413Z",
      "date_published": "2026-07-01T04:32:28.366Z",
      "date_updated": "2026-07-01T10:42:10.679Z",
      "publisher": "Wordfence",
      "title": "JetWidgets For Elementor <= 1.0.21 - Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting",
      "affected": {
        "vendors": [
          "jetmonsters"
        ],
        "products": [
          {
            "vendor": "jetmonsters",
            "product": "JetWidgets For Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04824
      },
      "nvd": {
        "published": "2026-07-01T05:16:16.457",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11380",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The JetWidgets For Elementor rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fffd6fc5-1578-414c-bb36-4f5dc0f27e19?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3583305/jetwidgets-for-elementor",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 511,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T12:59:34.906Z",
      "date_published": "2026-07-30T14:12:41.438Z",
      "date_updated": "2026-07-30T17:28:35.653Z",
      "publisher": "ibm",
      "title": "Cross-site Scripting in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Tivoli System Automation Application Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05844
      },
      "nvd": {
        "published": "2026-07-30T15:16:23.877",
        "lastModified": "2026-07-30T19:17:02.810",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11383",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The IBM administrative console renders attacker-controlled content as executable browser markup without the required context encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281073",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 156,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11386",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T15:11:57.169Z",
      "date_published": "2026-07-16T12:16:02.508Z",
      "date_updated": "2026-07-16T13:31:16.910Z",
      "publisher": "canonical",
      "title": "ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution",
      "affected": {
        "vendors": [
          "Canonical"
        ],
        "products": [
          {
            "vendor": "Canonical",
            "product": "ubuntu-pro-client (ubuntu-advantage-tools)"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 26.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 24.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 22.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 20.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 18.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 16.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 14.04 LTS"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@ubuntu.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00342,
        "percentile": 0.2683
      },
      "nvd": {
        "published": "2026-07-16T13:16:24.770",
        "lastModified": "2026-07-16T14:16:48.040",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11386",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Newlines in contract-server suites or aptURL values cross into root-owned APT source syntax, and additionalPackages can then make the root client install an attacker-selected package.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://ubuntu.com/security/CVE-2026-11386",
          "host": "ubuntu.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1312,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-11387",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T15:14:38.745Z",
      "date_published": "2026-07-01T07:53:37.874Z",
      "date_updated": "2026-07-01T10:32:03.955Z",
      "publisher": "Wordfence",
      "title": "SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset",
      "affected": {
        "vendors": [
          "cozyvision1"
        ],
        "products": [
          {
            "vendor": "cozyvision1",
            "product": "SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00515,
        "percentile": 0.41017
      },
      "nvd": {
        "published": "2026-07-01T08:16:20.587",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11387",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The password-reset flow updates an account email or password without binding the OTP-verified identity to that account.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c31906da-f2fd-40ac-86e0-3f1ed0409d0c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.5/handler/forms/class-ultimatemember.php#L288",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.5/handler/forms/class-wpresetpassword.php#L116",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.5/handler/forms/class-wpresetpassword.php#L68",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.5/handler/forms/class-ultimatemember.php#L88",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.5/handler/forms/class-wpresetpassword.php#L130",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.5/handler/smsalert_form_handler.php#L91",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3587983%40sms-alert&new=3587983%40sms-alert&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 801,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T15:45:10.434Z",
      "date_published": "2026-07-14T01:30:01.231Z",
      "date_updated": "2026-07-14T12:31:30.976Z",
      "publisher": "Wordfence",
      "title": "News Kit Addons For Elementor <= 1.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets",
      "affected": {
        "vendors": [
          "blazethemes"
        ],
        "products": [
          {
            "vendor": "blazethemes",
            "product": "News Kit Addons For Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16656
      },
      "nvd": {
        "published": "2026-07-14T02:16:52.280",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11390",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The widgets accept an attacker-supplied HTML tag name outside the client-side selector and emit it without server-side sanitization or output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/95b727ee-b410-471b-98f2-7cebd7f64a58?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/news-kit-elementor-addons/tags/1.4.2/includes/widgets/site-logo-title/site-logo-title.php#L50",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/news-kit-elementor-addons/tags/1.4.2/includes/widgets/site-logo-title/site-logo-title.php#L58",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/news-kit-elementor-addons/tags/1.4.2/includes/widgets/single/single-author-box.php#L831",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/news-kit-elementor-addons/tags/1.4.2/includes/widgets/site-logo-title/site-logo-title.php#L49",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/news-kit-elementor-addons/tags/1.4.7/includes/widgets/site-logo-title/site-logo-title.php#L50",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/news-kit-elementor-addons/tags/1.4.7/includes/widgets/site-logo-title/site-logo-title.php#L58",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/news-kit-elementor-addons/tags/1.4.7/includes/widgets/single/single-author-box.php#L831",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&new=3586039%40news-kit-elementor-addons%2Ftrunk&old=3580563%40news-kit-elementor-addons%2Ftrunk",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 644,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T16:03:56.942Z",
      "date_published": "2026-07-28T18:58:06.313Z",
      "date_updated": "2026-07-28T19:36:27.465Z",
      "publisher": "Tanium",
      "title": "Tanium addressed a SQL injection vulnerability in Patch.",
      "affected": {
        "vendors": [
          "Tanium"
        ],
        "products": [
          {
            "vendor": "Tanium",
            "product": "Patch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:3938794e-25f5-4123-a1ba-5cbd7f104512",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08436
      },
      "nvd": {
        "published": "2026-07-28T20:17:22.573",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11391",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.tanium.com/TAN-2026-019",
          "host": "security.tanium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 56,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-11392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T16:12:08.787Z",
      "date_published": "2026-07-10T03:31:13.504Z",
      "date_updated": "2026-07-14T01:30:15.288Z",
      "publisher": "Wordfence",
      "title": "WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters",
      "affected": {
        "vendors": [
          "thimpress"
        ],
        "products": [
          {
            "vendor": "thimpress",
            "product": "WP Hotel Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18818
      },
      "nvd": {
        "published": "2026-07-10T04:17:35.223",
        "lastModified": "2026-07-14T02:16:52.460",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11392",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8b56ca04-c6eb-401f-aa8a-b933c0527e51?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/templates/search/loop.php#L92",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/templates/search/v2/loop-v2.php#L40",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/includes/elementor/widgets/archive-room/list-results-room.php#L214",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/includes/wphb-functions.php#L748",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/includes/class-wphb-helpers.php#L29",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.2/templates/search/loop.php#L92",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.2/templates/search/v2/loop-v2.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.2/includes/elementor/widgets/archive-room/list-results-room.php#L215",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 448,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T16:28:07.222Z",
      "date_published": "2026-07-03T04:30:18.659Z",
      "date_updated": "2026-07-06T12:32:56.882Z",
      "publisher": "Wordfence",
      "title": "WP Import Export Lite <= 3.9.30 - Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' Parameter",
      "affected": {
        "vendors": [
          "vjinfotech"
        ],
        "products": [
          {
            "vendor": "vjinfotech",
            "product": "WP Import Export Lite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.1363
      },
      "nvd": {
        "published": "2026-07-03T06:16:20.653",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11397",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "When wp_safe_remote_get blocks an internal destination, the downloader retries the same untrusted URL through Guzzle without SSRF filtering.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/94384812-fa6e-48db-a84a-b1769e62ca58?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-import-export-lite/tags/3.9.30/includes/classes/import/downloader/download.php#L97",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-import-export-lite/tags/3.9.30/includes/classes/import/downloader/download.php#L31",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-import-export-lite/tags/3.9.30/includes/classes/import/extensions/url-upload/wpie_url_upload.php#L44",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-import-export-lite/tags/3.9.30/includes/classes/import/extensions/url-upload/class-wpie-url-upload.php#L29",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-import-export-lite/trunk/includes/classes/import/downloader/download.php?rev=3587811",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 864,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T16:30:18.829Z",
      "date_published": "2026-07-03T07:53:10.377Z",
      "date_updated": "2026-07-06T12:35:45.413Z",
      "publisher": "Wordfence",
      "title": "LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step",
      "affected": {
        "vendors": [
          "latepoint"
        ],
        "products": [
          {
            "vendor": "latepoint",
            "product": "LatePoint – Calendar Booking Plugin for Appointments and Events"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24793
      },
      "nvd": {
        "published": "2026-07-03T09:16:36.073",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11398",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The guest booking path selects an existing customer by email and updates that record without binding it to an authorized caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e4dcedcc-2878-47b2-99f0-ecba2cc33b69?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.1/lib/helpers/steps_helper.php#L1980",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.1/lib/helpers/steps_helper.php#L1953",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.1/lib/helpers/steps_helper.php#L1892",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.1/lib/controllers/steps_controller.php#L22",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/helpers/steps_helper.php#L1980",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/helpers/steps_helper.php#L1953",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/helpers/steps_helper.php#L1892",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/controllers/steps_controller.php#L22",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3572632%40latepoint&new=3572632%40latepoint&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 803,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T16:41:24.284Z",
      "date_published": "2026-07-14T15:28:23.509Z",
      "date_updated": "2026-07-14T15:59:18.173Z",
      "publisher": "Sonatype",
      "title": "Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation",
      "affected": {
        "vendors": [
          "Sonatype"
        ],
        "products": [
          {
            "vendor": "Sonatype",
            "product": "Nexus Repository Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-331",
          "name": "Insufficient Entropy",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:103e4ec9-0a87-450b-af77-479448ddef11",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00349,
        "percentile": 0.27614
      },
      "nvd": {
        "published": "2026-07-14T16:16:44.217",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11403",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Format-specific API keys are generated with insufficient unpredictability, allowing an attacker to derive a targeted user's active key when the related realm is enabled.",
        "basis": [
          "CNA",
          "CWE-331"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://help.sonatype.com/en/sonatype-nexus-repository-3-93-0-release-notes.html",
          "host": "help.sonatype.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://support.sonatype.com/hc/en-us/articles/52347011450515/",
          "host": "support.sonatype.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 388,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T17:46:47.767Z",
      "date_published": "2026-07-09T15:13:40.148Z",
      "date_updated": "2026-07-28T01:48:21.014Z",
      "publisher": "VulnCheck",
      "title": "Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID Parsing",
      "affected": {
        "vendors": [
          "Cesanta"
        ],
        "products": [
          {
            "vendor": "Cesanta",
            "product": "Mongoose"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27354
      },
      "nvd": {
        "published": "2026-07-09T16:16:34.640",
        "lastModified": "2026-07-28T03:16:43.060",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11404",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mg_tls_server_recv_hello uses the attacker-controlled ClientHello session_id_len as an index without checking it against the received buffer length.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cesanta/mongoose/releases/tag/7.22",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/cesanta/mongoose",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 486,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11405",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T18:12:15.445Z",
      "date_published": "2026-07-06T19:17:07.891Z",
      "date_updated": "2026-07-08T13:40:24.471Z",
      "publisher": "certcc",
      "title": "Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface",
      "affected": {
        "vendors": [
          "Tenda"
        ],
        "products": [
          {
            "vendor": "Tenda",
            "product": "firmware"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-912",
          "name": "Hidden Functionality",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01616,
        "percentile": 0.73634
      },
      "nvd": {
        "published": "2026-07-06T20:16:29.450",
        "lastModified": "2026-07-08T14:16:54.773",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11405",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The shipped web-server binary contains a hidden plaintext password path that grants an administrator session after normal authentication fails.",
        "basis": [
          "CNA",
          "CWE-912"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cwe.mitre.org/data/definitions/912.html",
          "host": "cwe.mitre.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://kb.cert.org/vuls/id/213560",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/213560",
          "host": "www.kb.cert.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 693,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-11426",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T20:39:33.140Z",
      "date_published": "2026-07-11T01:29:19.028Z",
      "date_updated": "2026-07-13T17:43:52.129Z",
      "publisher": "Wordfence",
      "title": "UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter",
      "affected": {
        "vendors": [
          "WebFactory"
        ],
        "products": [
          {
            "vendor": "WebFactory",
            "product": "Under Construction Page (Pro)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22182
      },
      "nvd": {
        "published": "2026-07-11T02:16:17.287",
        "lastModified": "2026-07-13T18:16:26.500",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11426",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The template_thumbnail parameter accepts an arbitrary local path and copies that file into a public uploads location.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/29dff562-e9b0-4cc9-b974-9239fbf0310f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://underconstructionpage.com/changelog/",
          "host": "underconstructionpage.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 470,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T02:21:39.261Z",
      "date_published": "2026-07-30T19:02:33.490Z",
      "date_updated": "2026-07-31T03:56:20.116Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server is affected by a remote code execution vulnerability",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26256
      },
      "nvd": {
        "published": "2026-07-30T20:16:52.140",
        "lastModified": "2026-07-31T04:16:45.530",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11536",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "In WebSphere Application Server, attacker-controlled serialized data is deserialized into live objects during security-sensitive processing.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7277544",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 125,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-11562",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T07:53:35.591Z",
      "date_published": "2026-07-01T06:00:01.845Z",
      "date_updated": "2026-07-01T10:20:02.352Z",
      "publisher": "WPScan",
      "title": "WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WS Form LITE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05883
      },
      "nvd": {
        "published": "2026-07-01T07:16:21.993",
        "lastModified": "2026-07-01T18:17:52.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11562",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "WS Form LITE fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e0283d75-0622-490c-9442-cf1aa0a1d167/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11563",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T07:57:39.644Z",
      "date_published": "2026-07-14T06:00:02.086Z",
      "date_updated": "2026-07-14T13:04:45.925Z",
      "publisher": "WPScan",
      "title": "Word Count and Social Shares <= 1.0 - Subscriber+ Arbitrary File Deletion via Path Traversal",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Word Count and Social Shares"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06089
      },
      "nvd": {
        "published": "2026-07-14T06:16:48.873",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11563",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The deletion operation accepts a subscriber-supplied path without confining it to the plugin's intended files.",
        "basis": [
          "CNA",
          "CWE-73",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/7f4b5f16-6c31-4dcc-94a4-120cb45631bb/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11564",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T08:22:50.089Z",
      "date_published": "2026-07-03T06:12:35.251Z",
      "date_updated": "2026-07-06T17:10:33.352Z",
      "publisher": "curl",
      "title": "Native CA trust persist",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00363,
        "percentile": 0.29059
      },
      "nvd": {
        "published": "2026-07-03T07:16:23.790",
        "lastModified": "2026-07-07T18:00:35.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-11564",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libcurl can reuse a pooled connection validated with native CA trust after the same easy handle has been changed to require custom CA material.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-11564.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11564.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3788984",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-11567",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T08:28:35.208Z",
      "date_published": "2026-07-14T06:00:02.299Z",
      "date_updated": "2026-07-14T12:29:42.659Z",
      "publisher": "WPScan",
      "title": "SureForms < 2.11.1 - Unauthenticated Payment Amount Bypass",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "SureForms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.0791
      },
      "nvd": {
        "published": "2026-07-14T06:16:54.410",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11567",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The payment handler accepts a client-controlled dynamic amount without binding it to the product or subscription amount configured by the site.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/bd738da7-f950-4da9-bcc1-c1fe845d7faa/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 307,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11568",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T09:06:54.676Z",
      "date_published": "2026-07-01T06:00:02.020Z",
      "date_updated": "2026-07-01T10:19:26.363Z",
      "publisher": "WPScan",
      "title": "Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_data",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Product Configurator for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20605
      },
      "nvd": {
        "published": "2026-07-01T07:16:22.083",
        "lastModified": "2026-07-01T18:17:52.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11568",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public pc_get_data action returns a requested product without checking caller authorization or the product publication status.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e208fee5-dad5-4aeb-b9b5-fbd72a5633e4/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 445,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11570",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T09:20:15.246Z",
      "date_published": "2026-07-01T06:00:02.195Z",
      "date_updated": "2026-07-01T10:18:43.807Z",
      "publisher": "WPScan",
      "title": "User Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "User Submitted Posts"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03519
      },
      "nvd": {
        "published": "2026-07-01T07:16:22.173",
        "lastModified": "2026-07-01T18:17:52.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11570",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User Submitted Posts emits a submitted value through an administrator-selected display template without HTML escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/35c33c56-5b12-4be5-9d45-68f47cd854ec/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11571",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T09:36:35.155Z",
      "date_published": "2026-07-09T06:00:02.118Z",
      "date_updated": "2026-07-09T14:39:49.930Z",
      "publisher": "WPScan",
      "title": "Everest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Residual CSV Artifacts",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Everest Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17147
      },
      "nvd": {
        "published": "2026-07-09T07:16:22.847",
        "lastModified": "2026-07-09T16:34:18.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11571",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Temporary CSV notification files are not reliably deleted and remain publicly retrievable under predictable upload paths.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/4bd381e9-2f4e-4e61-99af-88f50aed71f5/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11575",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T11:16:29.712Z",
      "date_published": "2026-07-17T06:00:01.861Z",
      "date_updated": "2026-07-17T13:03:16.958Z",
      "publisher": "WPScan",
      "title": "PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "PhonePe Payment Solutions"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13623
      },
      "nvd": {
        "published": "2026-07-17T07:16:37.753",
        "lastModified": "2026-07-17T15:44:29.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11575",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An empty callback secret reduces payment verification to an attacker-computable unkeyed hash.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e35eb029-87c3-4837-87c1-4ad7f6f5817f/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 495,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11578",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T11:40:12.713Z",
      "date_published": "2026-07-02T06:00:02.573Z",
      "date_updated": "2026-07-02T12:54:19.224Z",
      "publisher": "WPScan",
      "title": "Fluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Fluent Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06481
      },
      "nvd": {
        "published": "2026-07-02T06:16:12.910",
        "lastModified": "2026-07-02T15:12:53.577",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11578",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/3937e20f-dd46-4c2e-b170-d5e5c254b8d2/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11579",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T11:45:18.284Z",
      "date_published": "2026-07-15T06:00:02.091Z",
      "date_updated": "2026-07-15T10:33:48.659Z",
      "publisher": "WPScan",
      "title": "Kali Forms < 2.4.17 - Unauthenticated Media Upload",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Kali Forms — Contact Form & Drag-and-Drop Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.1486
      },
      "nvd": {
        "published": "2026-07-15T06:16:40.433",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11579",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload endpoint accepts files even when no configured form contains an upload field, placing only WordPress-default MIME types in the Media Library without enabling code execution.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/fae38fd0-8183-4864-8dae-0cd33a220bec/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11580",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T11:58:09.466Z",
      "date_published": "2026-07-15T06:00:02.266Z",
      "date_updated": "2026-07-15T10:31:39.200Z",
      "publisher": "WPScan",
      "title": "Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Kali Forms — Contact Form & Drag-and-Drop Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08782
      },
      "nvd": {
        "published": "2026-07-15T06:16:43.663",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11580",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/d73500e1-a8bc-4d31-ad9b-d1f71212bcc7/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 471,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11586",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T12:17:42.037Z",
      "date_published": "2026-07-03T06:13:04.448Z",
      "date_updated": "2026-07-06T15:16:27.052Z",
      "publisher": "curl",
      "title": "WS Auto-PONG memory exhaustion",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00491,
        "percentile": 0.3957
      },
      "nvd": {
        "published": "2026-07-03T07:16:23.883",
        "lastModified": "2026-07-07T17:59:46.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-11586",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "curl automatically acknowledges WebSocket PING frames while retaining unacknowledged frame allocations without an upper bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-11586.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11586.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3788931",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-11591",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T13:46:43.638Z",
      "date_published": "2026-07-11T05:35:47.927Z",
      "date_updated": "2026-07-13T16:12:30.040Z",
      "publisher": "Wordfence",
      "title": "Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters",
      "affected": {
        "vendors": [
          "trustindex"
        ],
        "products": [
          {
            "vendor": "trustindex",
            "product": "Widgets for Google Reviews"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16609
      },
      "nvd": {
        "published": "2026-07-11T07:16:45.073",
        "lastModified": "2026-07-13T17:16:39.930",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11591",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Multisite review-widget settings are stored without sufficient sanitization or output escaping and later execute as browser script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4d16e945-1576-4d9b-8e1b-995ec457215b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-reviews-plugin-for-google/tags/13.2.9/trustindex-plugin.class.php#L6551",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-reviews-plugin-for-google/tags/13.2.9/trustindex-plugin.class.php#L649",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-reviews-plugin-for-google/tags/13.2.9/tabs/free-widget-configurator.php#L400",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-reviews-plugin-for-google/tags/13.2.9/tabs/free-widget-configurator.php#L406",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-reviews-plugin-for-google/trunk/trustindex-plugin.class.php#L6551",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-reviews-plugin-for-google/trunk/trustindex-plugin.class.php#L649",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-reviews-plugin-for-google/trunk/tabs/free-widget-configurator.php#L400",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-reviews-plugin-for-google/trunk/tabs/free-widget-configurator.php#L406",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3584904%40wp-reviews-plugin-for-google&new=3584904%40wp-reviews-plugin-for-google",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11592",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T13:53:29.969Z",
      "date_published": "2026-07-02T05:35:13.163Z",
      "date_updated": "2026-07-02T12:37:28.997Z",
      "publisher": "Wordfence",
      "title": "Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action",
      "affected": {
        "vendors": [
          "icegram"
        ],
        "products": [
          {
            "vendor": "icegram",
            "product": "Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19364
      },
      "nvd": {
        "published": "2026-07-02T06:16:13.013",
        "lastModified": "2026-07-02T13:58:56.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11592",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A contributor can reach mail, list, or broadcast operations outside the intended role, but the exact authorization predicate is not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a2e70691-4de9-4b12-babf-bebe267a780b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.24/lite/admin/class-ig-es-onboarding.php#L171",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.24/lite/admin/class-email-subscribers-admin.php#L216",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.24/lite/includes/classes/class-es-newsletters.php#L717",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.24/lite/includes/workflows/admin/class-es-workflow-admin-edit.php#L74",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.24/lite/includes/class-email-subscribers-activator.php#L66",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.21/lite/admin/class-ig-es-onboarding.php#L171",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.21/lite/admin/class-email-subscribers-admin.php#L216",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.21/lite/includes/classes/class-es-newsletters.php#L717",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.21/lite/includes/workflows/admin/class-es-workflow-admin-edit.php#L74",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.21/lite/includes/class-email-subscribers-activator.php#L66",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3584584%40email-subscribers&new=3584584%40email-subscribers&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 680,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11598",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T14:34:48.857Z",
      "date_published": "2026-07-28T09:30:17.303Z",
      "date_updated": "2026-07-28T13:44:11.173Z",
      "publisher": "Wordfence",
      "title": "Shortcodify <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Shortcode Attribute",
      "affected": {
        "vendors": [
          "lrnz"
        ],
        "products": [
          {
            "vendor": "lrnz",
            "product": "Shortcodify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11356
      },
      "nvd": {
        "published": "2026-07-28T10:16:47.733",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11598",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The name shortcode attribute reaches stored page output without the required HTML sanitization and escaping.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/55ba8d6a-df38-4e24-afa4-6f82cb318c6b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/shortcodify/tags/1.4.3/shortcodify.php#L411",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/shortcodify/tags/1.4.3/shortcodify.php#L276",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 411,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11600",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T14:54:04.597Z",
      "date_published": "2026-07-02T05:35:01.383Z",
      "date_updated": "2026-07-02T15:54:20.863Z",
      "publisher": "Wordfence",
      "title": "Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting",
      "affected": {
        "vendors": [
          "envothemes"
        ],
        "products": [
          {
            "vendor": "envothemes",
            "product": "Envo's Templates & Widgets for Elementor and WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14644
      },
      "nvd": {
        "published": "2026-07-02T06:16:13.160",
        "lastModified": "2026-07-02T16:16:29.603",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11600",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Tabs widget passes a caller-controlled template identifier to Elementor rendering without checking that the caller may read that template.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/26100f1f-3224-486c-b4f9-7086d405a883?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/envo-elementor-for-woocommerce/tags/1.4.26/modules/tabs/widgets/tabs.php#L1268",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/envo-elementor-for-woocommerce/tags/1.4.26/modules/tabs/widgets/tabs.php#L103",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/envo-elementor-for-woocommerce/tags/1.4.26/modules/off-canvas/widgets/off-canvas.php#L631",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/envo-elementor-for-woocommerce/tags/1.4.25/modules/tabs/widgets/tabs.php#L1268",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/envo-elementor-for-woocommerce/tags/1.4.25/modules/tabs/widgets/tabs.php#L103",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/envo-elementor-for-woocommerce/tags/1.4.25/modules/off-canvas/widgets/off-canvas.php#L631",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3578489%40envo-elementor-for-woocommerce&new=3578489%40envo-elementor-for-woocommerce&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 902,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11605",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T15:26:55.139Z",
      "date_published": "2026-07-22T14:11:37.812Z",
      "date_updated": "2026-07-22T18:53:55.674Z",
      "publisher": "isc",
      "title": "Unnecessary validation of DNSSEC signed records",
      "affected": {
        "vendors": [
          "ISC"
        ],
        "products": [
          {
            "vendor": "ISC",
            "product": "BIND 9"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-408",
          "name": "Incorrect Behavior Order: Early Amplification",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-officer@isc.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00524,
        "percentile": 0.41548
      },
      "nvd": {
        "published": "2026-07-22T15:16:51.573",
        "lastModified": "2026-07-22T20:33:11.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11605",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BIND performs validation work for every superfluous but valid RRSIG in a response without an effective work bound.",
        "basis": [
          "CNA",
          "CWE-408"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.isc.org/docs/cve-2026-11605",
          "host": "kb.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.20.26",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.21.24",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 444,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-11610",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T16:13:02.502Z",
      "date_published": "2026-07-07T09:17:36.519Z",
      "date_updated": "2026-07-08T21:02:28.863Z",
      "publisher": "redhat",
      "title": "389-ds-base: 389-ds-base: heap buffer overflow in sasl_io_recv() via padded sasl unbind",
      "affected": {
        "vendors": [
          "389ds",
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "389ds",
            "product": "389-ds-base"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 11.5 E4S for RHEL 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 11.7 E4S for RHEL 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 11.9 for RHEL 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 12.2 E4S for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 12.4 E4S for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10.0 Extended Update Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9.6 Extended Update Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 13.2"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 12"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 13"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          }
        ],
        "affectedBlockCount": 24,
        "versionEntryCount": 21,
        "versionRangeCount": 21,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00627,
        "percentile": 0.46603
      },
      "nvd": {
        "published": "2026-07-07T10:16:39.690",
        "lastModified": "2026-07-08T21:16:46.137",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11610",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In 389-ds-base, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36195",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36196",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36197",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36198",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36200",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36201",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36202",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36204",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36205",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36206",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36208",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36209",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36585",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36641",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36660",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36670",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:36671",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11610",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484414",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 907,
        "referenceCount": 19,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 24,
        "affectedVersionEntryCount": 21
      }
    },
    {
      "cve_id": "CVE-2026-11622",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T20:17:01.626Z",
      "date_published": "2026-07-22T14:12:19.564Z",
      "date_updated": "2026-07-22T18:53:14.635Z",
      "publisher": "isc",
      "title": "Potential memory usage beyond configured limits",
      "affected": {
        "vendors": [
          "ISC"
        ],
        "products": [
          {
            "vendor": "ISC",
            "product": "BIND 9"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-officer@isc.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00509,
        "percentile": 0.40633
      },
      "nvd": {
        "published": "2026-07-22T15:16:51.703",
        "lastModified": "2026-07-22T20:33:11.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11622",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected protocol path allocates or retains attacker-driven state without an effective upper bound.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.isc.org/docs/cve-2026-11622",
          "host": "kb.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.20.26",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.21.24",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 518,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-11707",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T23:43:19.847Z",
      "date_published": "2026-07-30T14:15:25.319Z",
      "date_updated": "2026-07-30T18:10:59.992Z",
      "publisher": "ibm",
      "title": "Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Tivoli System Automation Application Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12204
      },
      "nvd": {
        "published": "2026-07-30T15:16:24.010",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11707",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The administrative console login page incorporates attacker-controlled content into browser-interpreted output without the required contextual neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281073",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11721",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T01:19:47.697Z",
      "date_published": "2026-07-22T14:13:08.748Z",
      "date_updated": "2026-07-22T18:52:46.888Z",
      "publisher": "isc",
      "title": "Cache poisoning possible with label count discrepancy, RRSIG, and wildcards",
      "affected": {
        "vendors": [
          "ISC"
        ],
        "products": [
          {
            "vendor": "ISC",
            "product": "BIND 9"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-officer@isc.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.31236
      },
      "nvd": {
        "published": "2026-07-22T15:16:51.837",
        "lastModified": "2026-07-22T20:33:11.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11721",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The BIND 9 DNSSEC path accepts an RRSIG label count that is inconsistent with its zone and synthesizes a wildcard name outside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.isc.org/docs/cve-2026-11721",
          "host": "kb.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.20.26",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.21.24",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-11756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:11:51.888Z",
      "date_published": "2026-07-28T07:35:17.764Z",
      "date_updated": "2026-07-28T12:53:11.927Z",
      "publisher": "3DS",
      "title": "Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x",
      "affected": {
        "vendors": [
          "Dassault Systèmes"
        ],
        "products": [
          {
            "vendor": "Dassault Systèmes",
            "product": "Station Launcher App in 3DEXPERIENCE platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:3DS.Information-Security@3ds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00452,
        "percentile": 0.37024
      },
      "nvd": {
        "published": "2026-07-28T08:17:14.007",
        "lastModified": "2026-07-30T19:11:32.053",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11756",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application deserializes an untrusted object representation that can instantiate attacker-selected behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.3ds.com/trust-center/security/security-advisories/cve-2026-11756",
          "host": "www.3ds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-11763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:40:39.402Z",
      "date_published": "2026-07-17T15:56:52.030Z",
      "date_updated": "2026-07-17T16:39:42.440Z",
      "publisher": "TR-CERT",
      "title": "IDOR in GIS Informatics' GisLab Laboratory Management System",
      "affected": {
        "vendors": [
          "Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc."
        ],
        "products": [
          {
            "vendor": "Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.",
            "product": "GisLab Laboratory Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18006
      },
      "nvd": {
        "published": "2026-07-17T17:17:13.047",
        "lastModified": "2026-07-17T17:54:18.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11763",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The GisLab Laboratory Management System request path accepts an attacker-selected object identifier without binding that object to the caller's tenant, owner, or permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0573",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 313,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11766",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T09:51:17.031Z",
      "date_published": "2026-07-06T06:00:01.483Z",
      "date_updated": "2026-07-06T12:02:30.806Z",
      "publisher": "WPScan",
      "title": "Ultimate Member < 2.12.0 - Subscriber+ Stored XSS via Custom Textarea Profile Fields",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Ultimate Member"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13385
      },
      "nvd": {
        "published": "2026-07-06T08:16:35.083",
        "lastModified": "2026-07-06T18:37:01.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11766",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ultimate Member stores custom textarea profile values and renders them without sufficient sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/96adb2d3-af34-4455-97d4-90af58049e78/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T09:52:45.351Z",
      "date_published": "2026-07-21T06:00:01.191Z",
      "date_updated": "2026-07-21T15:05:36.150Z",
      "publisher": "WPScan",
      "title": "CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Free Theme Builder for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19791
      },
      "nvd": {
        "published": "2026-07-21T07:16:33.567",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11767",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute when a logged-in administrator views the form submissions.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e06a6497-e44f-43b9-b6ba-407aea171387/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 334,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T11:25:26.667Z",
      "date_published": "2026-07-31T09:18:58.342Z",
      "date_updated": "2026-07-31T23:24:38.899Z",
      "publisher": "redhat",
      "title": "389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 11"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 12"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 13"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-90",
          "name": "Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00506,
        "percentile": 0.40427
      },
      "nvd": {
        "published": "2026-07-31T10:16:44.720",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11770",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled value reaches an LDAP filter without LDAP grammar separation.",
        "basis": [
          "CNA",
          "CWE-90"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-11770",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484802",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/389ds/389-ds-base/blob/main/ldap/servers/plugins/replication/repl_extop.c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-11771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T11:44:10.570Z",
      "date_published": "2026-07-30T16:36:41.087Z",
      "date_updated": "2026-07-30T18:04:42.335Z",
      "publisher": "OpenVPN",
      "title": "OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server",
      "affected": {
        "vendors": [
          "OpenVPN"
        ],
        "products": [
          {
            "vendor": "OpenVPN",
            "product": "OpenVPN"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-193",
          "name": "Off-by-one Error",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"
        },
        {
          "source": "NVD:security@openvpn.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00342,
        "percentile": 0.26846
      },
      "nvd": {
        "published": "2026-07-30T17:16:27.610",
        "lastModified": "2026-07-30T19:17:03.247",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11771",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The NTLM proxy-authentication path writes one byte beyond its response buffer when processing a crafted proxy reply.",
        "basis": [
          "CNA",
          "CWE-121",
          "CWE-193",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.openvpn.net/Security%20Announcements/CVE-2026-11771",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://community.openvpn.net/ReleaseHistory#openvpn-275-released-1-july-2026",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://community.openvpn.net/ReleaseHistory#openvpn-2621-released-1-july-2026",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-11778",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T12:15:26.855Z",
      "date_published": "2026-07-03T07:53:08.623Z",
      "date_updated": "2026-07-06T16:35:24.768Z",
      "publisher": "Wordfence",
      "title": "CURCY <= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange' Parameter",
      "affected": {
        "vendors": [
          "villatheme"
        ],
        "products": [
          {
            "vendor": "villatheme",
            "product": "CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16363
      },
      "nvd": {
        "published": "2026-07-03T09:16:36.497",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11778",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated WordPress request can pass attacker-controlled shortcode text to do_shortcode(), crossing directly into the shortcode interpreter without an authorization boundary.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5a30e5dc-1f15-40ce-9703-1e1add1df6da?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-multi-currency/trunk/frontend/cache.php#L108",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-multi-currency/trunk/frontend/cache.php#L99",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-multi-currency/trunk/frontend/cache.php#L18",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11781",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T12:32:58.447Z",
      "date_published": "2026-07-02T06:00:02.747Z",
      "date_updated": "2026-07-02T12:34:37.068Z",
      "publisher": "WPScan",
      "title": "Adminify < 4.2.10 - Contributor+ Sensitive Information Disclosure via Global Search AJAX",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Adminify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08744
      },
      "nvd": {
        "published": "2026-07-02T06:16:13.287",
        "lastModified": "2026-07-02T15:12:53.577",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11781",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The administration search returns non-public records without applying WordPress's per-user read-capability check to each result.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/0aa18fe0-2d64-45dc-9eab-9587d63853be/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 460,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11782",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T12:33:00.570Z",
      "date_published": "2026-07-30T06:00:09.749Z",
      "date_updated": "2026-07-30T15:09:45.485Z",
      "publisher": "WPScan",
      "title": "Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User Wallet & Points Manipulation via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Points and Rewards for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12684
      },
      "nvd": {
        "published": "2026-07-30T06:24:58.037",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11782",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated wallet update accepts a target account identifier without checking either authorization or ownership, allowing another user's balance and points to be changed.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/a1089e94-ecc7-458e-97f6-48bd809192ef/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 598,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11794",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T13:05:09.059Z",
      "date_published": "2026-07-01T06:00:02.367Z",
      "date_updated": "2026-07-01T10:14:46.721Z",
      "publisher": "WPScan",
      "title": "Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Advanced Form Integration — Connect Forms to 200+ Apps"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14719
      },
      "nvd": {
        "published": "2026-07-01T07:16:22.260",
        "lastModified": "2026-07-01T18:17:52.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11794",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Public form input can select the WordPress role assigned to a newly created user, including the administrator role.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/614b9517-d6d5-499f-8172-280280a312b2/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 471,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11798",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T13:39:24.046Z",
      "date_published": "2026-07-08T05:34:07.784Z",
      "date_updated": "2026-07-08T15:06:40.488Z",
      "publisher": "Wordfence",
      "title": "Social Share, Social Login and Social Comments Plugin <= 7.14.5 - Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter",
      "affected": {
        "vendors": [
          "the_champ"
        ],
        "products": [
          {
            "vendor": "the_champ",
            "product": "Social Share, Social Login and Social Comments Plugin – Super Socializer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10545
      },
      "nvd": {
        "published": "2026-07-08T06:16:21.707",
        "lastModified": "2026-07-08T16:16:26.770",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11798",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The plugin reflects the heateor_mastodon_share parameter into a web page without sufficient sanitization and output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/37d9171d-4722-4ebc-a773-9fd497bc12cf?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/super-socializer/tags/7.14.5/helper.php#L1246",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/super-socializer/tags/7.14.5/helper.php#L1243",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T14:53:04.712Z",
      "date_published": "2026-07-14T01:30:00.701Z",
      "date_updated": "2026-07-15T13:39:53.630Z",
      "publisher": "Wordfence",
      "title": "FoodBook Lite <= 1.5.6 - Missing Authorization to Unauthenticated User Registration via 'registration_action' AJAX Action",
      "affected": {
        "vendors": [
          "themelooks"
        ],
        "products": [
          {
            "vendor": "themelooks",
            "product": "FoodBook Lite – Online Food Ordering System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23468
      },
      "nvd": {
        "published": "2026-07-14T02:16:52.577",
        "lastModified": "2026-07-15T14:17:17.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11802",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public registration AJAX handler calls wp_insert_user without a nonce, capability check, or enforcement of the users_can_register setting.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8b67557c-785f-433b-8e5b-fcc0bda14892?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.6/inc/class-components-ajax.php#L86",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.6/inc/class-components-ajax.php#L68",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.6/inc/class-components-ajax.php#L21",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.6/inc/class-components-ajax.php#L18",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.7/inc/class-components-ajax.php#L67-L73",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.7/inc/class-components-ajax.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/foodbook-light-online-food-ordering-system/tags/1.5.7/inc/helper-functions.php#L724-L725",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 608,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T15:04:29.906Z",
      "date_published": "2026-07-23T15:07:42.043Z",
      "date_updated": "2026-07-23T18:16:05.366Z",
      "publisher": "Honeywell",
      "title": "Program Module Vulnerability",
      "affected": {
        "vendors": [
          "Tridium"
        ],
        "products": [
          {
            "vendor": "Tridium",
            "product": "Niagara Framework"
          },
          {
            "vendor": "Tridium",
            "product": "Niagara Enterprise Security"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-280",
          "name": "Improper Handling of Insufficient Permissions or Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:psirt@honeywell.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.0471
      },
      "nvd": {
        "published": "2026-07-23T16:17:13.273",
        "lastModified": "2026-07-23T19:16:51.933",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11804",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Niagara Framework operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-280"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.honeywell.com/us/en/product-security",
          "host": "www.honeywell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.tridium.com/us/en/product-security",
          "host": "www.tridium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-11818",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:11:02.337Z",
      "date_published": "2026-07-10T03:31:13.896Z",
      "date_updated": "2026-07-10T14:25:01.305Z",
      "publisher": "Wordfence",
      "title": "WPCafe <= 3.0.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via REST API",
      "affected": {
        "vendors": [
          "arraytics"
        ],
        "products": [
          {
            "vendor": "arraytics",
            "product": "WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15647
      },
      "nvd": {
        "published": "2026-07-10T04:17:47.277",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11818",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "WPCafe treats a nonce available to every signed-in user as sufficient authority for administrator-only workflow changes.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9cf2d3bd-359c-4334-ad28-b6b9722edd1c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L66",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L82",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L110",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L102",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L74",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L121",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.15/core/email-automation/Service/email-notification.php#L78",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.15/core/email-automation/Service/email-notification.php#L88",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.15/core/email-automation/Service/email-notification.php#L119",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 645,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11823",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T18:11:40.111Z",
      "date_published": "2026-07-01T05:35:29.663Z",
      "date_updated": "2026-07-01T10:42:10.506Z",
      "publisher": "Wordfence",
      "title": "BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter",
      "affected": {
        "vendors": [
          "Repute Infosystems"
        ],
        "products": [
          {
            "vendor": "Repute Infosystems",
            "product": "BookingPress Appointment Booking Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20715
      },
      "nvd": {
        "published": "2026-07-01T07:16:22.353",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11823",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The booking handler interpolates attacker-controlled store_service_date data into a SQL LIKE clause after removing slashes and without parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1663be8e-a6b8-4e0d-97d0-af7db2a2875c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bookingpress-appointment-booking-pro/trunk/core/classes/class.bookingpress_pro_staff_members.php#L3353",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 602,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11826",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T19:53:45.722Z",
      "date_published": "2026-07-18T13:35:35.639Z",
      "date_updated": "2026-07-28T01:48:21.734Z",
      "publisher": "VulnCheck",
      "title": "OpenPLC_v3 Heap-Based Buffer Overflow in Modbus Master getData()",
      "affected": {
        "vendors": [
          "openplcproject"
        ],
        "products": [
          {
            "vendor": "openplcproject",
            "product": "OpenPLC_v3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00421,
        "percentile": 0.34683
      },
      "nvd": {
        "published": "2026-07-18T14:17:11.480",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11826",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenPLC_v3 copies, writes, or indexes attacker-influenced data without enforcing the destination buffer or object bounds required by the operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/Shukhrat-03/5cf1825b72e485ef98a32958dfbc611a#security-vulnerability-report",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/thiagoralves/OpenPLC_v3/commit/b4702061dc14d1024856f71b4543298d77007b88",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/thiagoralves/OpenPLC_v3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openplc-v3-heap-based-buffer-overflow-in-modbus-master-getdata",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1069,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11827",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:03:57.026Z",
      "date_published": "2026-07-08T20:46:23.863Z",
      "date_updated": "2026-07-09T14:15:01.193Z",
      "publisher": "GitLab",
      "title": "Insufficiently Protected Credentials in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17085
      },
      "nvd": {
        "published": "2026-07-08T21:16:46.397",
        "lastModified": "2026-07-09T20:15:29.420",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-11827",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A maintainer-authorized request is not bound to the owner of the stored credential, allowing one user to obtain another user's credential.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/602478",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3720483",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-11841",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T06:53:18.277Z",
      "date_published": "2026-07-28T09:25:36.738Z",
      "date_updated": "2026-07-28T19:15:14.851Z",
      "publisher": "SICK AG",
      "title": "CVE-2026-11841",
      "affected": {
        "vendors": [
          "SICK AG"
        ],
        "products": [
          {
            "vendor": "SICK AG",
            "product": "InspectorP61x"
          },
          {
            "vendor": "SICK AG",
            "product": "InspectorP62x"
          },
          {
            "vendor": "SICK AG",
            "product": "InspectorP65x"
          },
          {
            "vendor": "SICK AG",
            "product": "InspectorP63x"
          },
          {
            "vendor": "SICK AG",
            "product": "InspectorP64x"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-552",
          "name": "Files or Directories Accessible to External Parties",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:psirt@sick.de",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00458,
        "percentile": 0.3745
      },
      "nvd": {
        "published": "2026-07-28T10:16:47.867",
        "lastModified": "2026-07-28T20:17:22.727",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11841",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "InspectorP61x exposes a filesystem location through an external interface without restricting it to the intended directory or callers.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-552"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.sick.com/psirt",
          "host": "www.sick.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_SICK PSIRT Security Advisories"
          ]
        },
        {
          "url": "https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf",
          "host": "www.sick.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_SICK Operating Guidelines"
          ]
        },
        {
          "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_ICS-CERT recommended practices on Industrial Security"
          ]
        },
        {
          "url": "https://www.first.org/cvss/calculator/3.1",
          "host": "www.first.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_CVSS v3.1 Calculator"
          ]
        },
        {
          "url": "https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.json",
          "host": "www.sick.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_The canonical URL."
          ]
        },
        {
          "url": "https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.pdf",
          "host": "www.sick.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 598,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-11851",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T08:22:42.915Z",
      "date_published": "2026-07-15T02:00:26.440Z",
      "date_updated": "2026-07-15T12:35:35.495Z",
      "publisher": "ASUS",
      "title": "Improper Neutralization of Special Elements used in an SQL Command (\"SQL Injection\") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted requ...",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "Router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00368,
        "percentile": 0.2953
      },
      "nvd": {
        "published": "2026-07-15T02:18:04.743",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11851",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted authenticated management request bypasses input validation and places attacker-controlled elements into a router SQL command.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory/",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-11855",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T08:56:17.436Z",
      "date_published": "2026-07-06T06:00:01.657Z",
      "date_updated": "2026-07-06T12:01:41.739Z",
      "publisher": "WPScan",
      "title": "Simple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API Version",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Simple Membership"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19791
      },
      "nvd": {
        "published": "2026-07-06T08:16:35.180",
        "lastModified": "2026-07-06T18:37:01.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11855",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "When no Stripe signing secret is configured, the plugin accepts an unauthenticated webhook value and later emits it unescaped in an administrator notice.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/217cb606-a0f2-4427-9262-cfe1cc90474e/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 358,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11856",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T08:59:16.646Z",
      "date_published": "2026-07-03T06:13:31.661Z",
      "date_updated": "2026-07-06T18:23:52.111Z",
      "publisher": "curl",
      "title": "cross-origin Digest auth state leak",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 172,
        "versionRangeCount": 172,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00604,
        "percentile": 0.45543
      },
      "nvd": {
        "published": "2026-07-03T07:16:23.973",
        "lastModified": "2026-07-07T19:43:55.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-11856",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "libcurl reuses a Digest Authorization header after the transfer origin changes, binding hostA credentials to a request for hostB.",
        "basis": [
          "CNA",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-11856.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-11856.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3793260",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 312,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 172
      }
    },
    {
      "cve_id": "CVE-2026-11866",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T12:15:27.794Z",
      "date_published": "2026-07-16T06:00:03.056Z",
      "date_updated": "2026-07-16T15:33:52.148Z",
      "publisher": "WPScan",
      "title": "LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Appointment Booking Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00095,
        "percentile": 0.00788
      },
      "nvd": {
        "published": "2026-07-16T07:16:46.593",
        "lastModified": "2026-07-16T16:18:59.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11866",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The central dispatcher accepts privileged state-changing actions without validating a CSRF nonce tied to the administrator session.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/84e936b8-1978-4dc3-aa40-5ce49bfdc445/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11867",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T12:15:30.132Z",
      "date_published": "2026-07-30T06:00:10.034Z",
      "date_updated": "2026-07-30T16:02:33.029Z",
      "publisher": "WPScan",
      "title": "Frontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Frontend Admin by DynamiApps"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11615
      },
      "nvd": {
        "published": "2026-07-30T06:24:58.203",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11867",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/63c90b08-fcff-4bd0-8953-b5cc5c796dbe/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11868",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T12:15:31.947Z",
      "date_published": "2026-07-20T06:00:02.635Z",
      "date_updated": "2026-07-20T13:15:28.613Z",
      "publisher": "WPScan",
      "title": "WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Travel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.07957
      },
      "nvd": {
        "published": "2026-07-20T07:16:34.650",
        "lastModified": "2026-07-20T20:39:31.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11868",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/a82da13b-ee86-495b-a684-324c1541d7ab/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11869",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T12:15:34.139Z",
      "date_published": "2026-07-09T06:00:02.322Z",
      "date_updated": "2026-07-09T14:40:56.289Z",
      "publisher": "WPScan",
      "title": "WP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclosure via Subject Access Request",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP DSGVO Tools (GDPR)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09224
      },
      "nvd": {
        "published": "2026-07-09T07:16:22.997",
        "lastModified": "2026-07-09T16:34:18.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11869",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/49170650-0006-4f3b-90f4-f8bb176beb7b/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 408,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11870",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T12:15:36.157Z",
      "date_published": "2026-07-30T06:00:10.207Z",
      "date_updated": "2026-07-30T18:21:02.622Z",
      "publisher": "WPScan",
      "title": "Hide My WP Ghost < 7.0.05 - IP Address Spoofing via Trusted Proxy Headers Leading to Protection Mechanism Bypass",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Ghost (Hide My WP Ghost)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08635
      },
      "nvd": {
        "published": "2026-07-30T06:24:58.323",
        "lastModified": "2026-07-30T19:17:03.550",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11870",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The service trusts attacker-controlled identity or network-origin data without authenticating its asserted source.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/d3bf6487-88a9-4fc7-87b6-5e739519aa64/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11875",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T12:38:40.449Z",
      "date_published": "2026-07-09T06:00:02.497Z",
      "date_updated": "2026-07-09T14:44:24.978Z",
      "publisher": "WPScan",
      "title": "WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Support Ticket Access via Session Cookie Forgery",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Support Plus Responsive Ticket System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09224
      },
      "nvd": {
        "published": "2026-07-09T07:16:23.107",
        "lastModified": "2026-07-09T16:34:18.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11875",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The plugin neither signs nor verifies its guest-session cookie, allowing a forged email identity to impersonate a ticket owner.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/1c69692e-5d0c-42cf-9b3d-b722f2ba4231/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11876",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T13:13:28.285Z",
      "date_published": "2026-07-21T14:11:19.753Z",
      "date_updated": "2026-07-22T18:27:58.532Z",
      "publisher": "@huntr_ai",
      "title": "Missing Authorization in get_deployed_stack Endpoint in zenml-io/zenml",
      "affected": {
        "vendors": [
          "zenml-io"
        ],
        "products": [
          {
            "vendor": "zenml-io",
            "product": "zenml-io/zenml"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@huntr.dev",
          "type": "Secondary",
          "version": "3.0",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08154
      },
      "nvd": {
        "published": "2026-07-21T15:16:30.480",
        "lastModified": "2026-07-23T18:24:39.053",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11876",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The stack-deployment endpoint omits tenant RBAC and uses a server-side client that bypasses the enforcement layer to enumerate every tenant's stacks.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://huntr.com/bounties/3b434e02-0ee9-4b5e-a44b-0988b6f074c7",
          "host": "huntr.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/zenml-io/zenml/commit/9ad2c65f24ded22a5a98d289d63a7f629b434b61",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 808,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11880",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T13:23:48.881Z",
      "date_published": "2026-07-01T06:00:02.543Z",
      "date_updated": "2026-07-01T10:17:33.638Z",
      "publisher": "WPScan",
      "title": "Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Fluent Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03715
      },
      "nvd": {
        "published": "2026-07-01T07:16:22.487",
        "lastModified": "2026-07-01T18:17:52.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11880",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A subscription identifier is accepted without binding the requested subscription to its owner.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/5de7c9e9-3a47-4bc6-a1b2-33eb8d3e3ec0/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11881",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T13:25:36.909Z",
      "date_published": "2026-07-30T06:00:10.415Z",
      "date_updated": "2026-07-30T12:36:35.949Z",
      "publisher": "WPScan",
      "title": "Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Fluent Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07884
      },
      "nvd": {
        "published": "2026-07-30T06:24:58.440",
        "lastModified": "2026-07-30T14:16:31.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11881",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A form-field setting is inserted into an inline script without the escaping required for JavaScript context.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/3ccc3b34-44ed-4489-86e5-4c0ae800ef73/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 524,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11883",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T13:48:22.029Z",
      "date_published": "2026-07-01T06:00:02.723Z",
      "date_updated": "2026-07-01T10:16:55.102Z",
      "publisher": "WPScan",
      "title": "WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WebAuthn Provider for Two Factor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00365,
        "percentile": 0.29173
      },
      "nvd": {
        "published": "2026-07-01T07:16:22.577",
        "lastModified": "2026-07-01T18:17:52.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11883",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The second-factor handler accepts a malformed WebAuthn response instead of requiring a valid assertion for the password-authenticated user.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/f718390c-1d7c-4048-bce6-a3170998e828/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 281,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11885",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T14:14:43.892Z",
      "date_published": "2026-07-30T16:38:25.814Z",
      "date_updated": "2026-07-30T17:35:20.927Z",
      "publisher": "ibm",
      "title": "Power System update in Buffer Copy",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "PowerVM Hypervisor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00101,
        "percentile": 0.01049
      },
      "nvd": {
        "published": "2026-07-30T17:16:27.760",
        "lastModified": "2026-07-30T19:17:03.763",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11885",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A crafted hypervisor call reaches a buffer-boundary failure, but the public record does not identify the buffer or missing size check.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280628",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-11887",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T14:21:57.118Z",
      "date_published": "2026-07-01T06:00:02.900Z",
      "date_updated": "2026-07-01T10:16:01.889Z",
      "publisher": "WPScan",
      "title": "Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Salon Booking System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07498
      },
      "nvd": {
        "published": "2026-07-01T07:16:22.667",
        "lastModified": "2026-07-01T18:22:46.440",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11887",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The AJAX action lets any logged-in user change the booking-approval setting without checking the capability required to alter that administrative policy.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/ed203765-0482-4d55-b36f-cdab11ed3cf0/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11889",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T14:40:08.574Z",
      "date_published": "2026-07-16T20:38:46.479Z",
      "date_updated": "2026-07-17T13:21:12.776Z",
      "publisher": "icscert",
      "title": "SALTO ProAccess Space Authorization Bypass Through User-Controlled Key",
      "affected": {
        "vendors": [
          "SALTO"
        ],
        "products": [
          {
            "vendor": "SALTO",
            "product": "ProAccess Space"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00192,
        "percentile": 0.09069
      },
      "nvd": {
        "published": "2026-07-16T21:17:19.050",
        "lastModified": "2026-07-17T18:31:44.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11889",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The request accepts an object or tenant identifier without binding that identifier to the authenticated caller's authorized scope.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-07",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-07.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-11896",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T15:39:57.936Z",
      "date_published": "2026-07-02T08:33:06.892Z",
      "date_updated": "2026-07-02T19:42:08.293Z",
      "publisher": "Wordfence",
      "title": "My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter",
      "affected": {
        "vendors": [
          "joedolson"
        ],
        "products": [
          {
            "vendor": "joedolson",
            "product": "My Calendar – Accessible Event Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23706
      },
      "nvd": {
        "published": "2026-07-02T10:16:27.280",
        "lastModified": "2026-07-02T20:17:00.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11896",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The vcal handler accepts an enumerable occurrence ID without checking event visibility, returning calendar exports for non-public events.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a72639df-fa05-414c-b30c-eb285f59d945?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/my-calendar/tags/3.7.14/my-calendar-api.php#L212",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/my-calendar/tags/3.7.14/my-calendar.php#L209",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/my-calendar/tags/3.7.14/my-calendar-api.php#L246",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/my-calendar/tags/3.7.14/my-calendar-events.php#L748",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/my-calendar/tags/3.7.14/includes/ical.php#L26",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/my-calendar/tags/3.7.14/includes/date-utilities.php#L417",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/my-calendar/trunk/my-calendar-api.php#L212",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/my-calendar/trunk/my-calendar.php#L209",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/my-calendar/trunk/my-calendar-api.php#L246",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/my-calendar/trunk/my-calendar-events.php#L748",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/my-calendar/trunk/includes/ical.php#L26",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/my-calendar/trunk/includes/date-utilities.php#L417",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3572191%40my-calendar&new=3572191%40my-calendar&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 14,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11897",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T15:40:44.241Z",
      "date_published": "2026-07-30T14:18:04.805Z",
      "date_updated": "2026-07-30T17:37:03.035Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability with HTTP/2",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22155
      },
      "nvd": {
        "published": "2026-07-30T15:16:24.143",
        "lastModified": "2026-08-04T15:26:57.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-11897",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WebSphere Application Server - Liberty path allocates attacker-driven resources without an effective bound or throttle.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280695",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11898",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T15:40:44.494Z",
      "date_published": "2026-07-11T05:35:45.854Z",
      "date_updated": "2026-07-15T13:36:07.923Z",
      "publisher": "Wordfence",
      "title": "White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings",
      "affected": {
        "vendors": [
          "videousermanuals"
        ],
        "products": [
          {
            "vendor": "videousermanuals",
            "product": "White Label CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15978
      },
      "nvd": {
        "published": "2026-07-11T07:16:45.213",
        "lastModified": "2026-07-15T14:17:17.320",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11898",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content is stored and later inserted into a page without the required HTML-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1f12cdb6-df2d-419d-a29c-1ff7f9d098f4?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.12/includes/classes/Admin_Dashboard.php#L430",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.12/includes/classes/Admin_Dashboard.php#L465",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.12/includes/classes/Settings.php#L228",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.12/includes/classes/Settings.php#L124",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.9/includes/classes/Admin_Dashboard.php#L430",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.9/includes/classes/Admin_Dashboard.php#L465",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.9/includes/classes/Settings.php#L228",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.9/includes/classes/Settings.php#L124",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3600959%40white-label-cms&new=3600959%40white-label-cms",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 513,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T15:43:26.797Z",
      "date_published": "2026-07-03T07:53:08.023Z",
      "date_updated": "2026-07-07T17:01:17.535Z",
      "publisher": "Wordfence",
      "title": "Ad Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute",
      "affected": {
        "vendors": [
          "spacetime"
        ],
        "products": [
          {
            "vendor": "spacetime",
            "product": "Ad Inserter – Ad Manager & AdSense Ads"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18659
      },
      "nvd": {
        "published": "2026-07-03T09:16:36.613",
        "lastModified": "2026-07-07T18:16:34.043",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11900",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Ad Inserter – Ad Manager & AdSense Ads request path accepts an attacker-selected object identifier without binding that object to the caller's tenant, owner, or permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/20f0e9ae-786b-4ba8-a6d5-92bf31ebc2c7?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.16/ad-inserter.php#L13083",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.16/ad-inserter.php#L10569",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.16/ad-inserter.php#L10818",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.16/ad-inserter.php#L2101",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.13/ad-inserter.php#L13083",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.13/ad-inserter.php#L10569",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.13/ad-inserter.php#L10818",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ad-inserter/tags/2.8.13/ad-inserter.php#L2101",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3591792%40ad-inserter&new=3591792%40ad-inserter&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 812,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11901",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T15:44:24.822Z",
      "date_published": "2026-07-11T05:35:44.057Z",
      "date_updated": "2026-07-14T14:26:01.248Z",
      "publisher": "Wordfence",
      "title": "WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler",
      "affected": {
        "vendors": [
          "thimpress"
        ],
        "products": [
          {
            "vendor": "thimpress",
            "product": "WP Hotel Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.0751
      },
      "nvd": {
        "published": "2026-07-11T07:16:45.347",
        "lastModified": "2026-07-14T15:16:56.343",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11901",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The PayPal IPN handler accepts an attacker-selected validation endpoint and omits merchant, currency, and transaction-uniqueness checks before completing an order.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/191ec7ea-6ca7-4943-8709-f372ae5a81c7?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.0/includes/gateways/paypal/class-wphb-payment-gateway-paypal.php#L173",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.0/includes/gateways/paypal/class-wphb-payment-gateway-paypal.php#L194",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.0/includes/gateways/paypal/class-wphb-payment-gateway-paypal.php#L186",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.0/includes/gateways/paypal/class-wphb-payment-gateway-paypal.php#L253",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/includes/gateways/paypal/class-wphb-payment-gateway-paypal.php#L173",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/includes/gateways/paypal/class-wphb-payment-gateway-paypal.php#L194",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/includes/gateways/paypal/class-wphb-payment-gateway-paypal.php#L186",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/includes/gateways/paypal/class-wphb-payment-gateway-paypal.php#L253",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3582839%40wp-hotel-booking&new=3582839%40wp-hotel-booking",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1066,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11903",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T15:50:46.983Z",
      "date_published": "2026-07-08T14:19:16.759Z",
      "date_updated": "2026-07-09T03:55:41.919Z",
      "publisher": "ProgressSoftware",
      "title": "Stored XSS in MOVEit Transfer Ad Hoc module",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "MOVEit Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20339
      },
      "nvd": {
        "published": "2026-07-08T15:16:25.470",
        "lastModified": "2026-07-10T14:01:59.527",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-11903",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says attacker-controlled input reaches executable syntax in MOVEit Transfer, while the input field and interpreter sink are not public.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.progress.com/s/article/MOVEit-Transfer-Critical-Security-Bulletin-June-2026",
          "host": "community.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-11904",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T15:51:27.374Z",
      "date_published": "2026-07-30T16:54:04.290Z",
      "date_updated": "2026-07-30T17:59:27.636Z",
      "publisher": "ibm",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Verify Identity Access"
          },
          {
            "vendor": "IBM",
            "product": "Security Verify Access"
          },
          {
            "vendor": "IBM",
            "product": "Verify Identity Access Container"
          },
          {
            "vendor": "IBM",
            "product": "Security Verify Access Container"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21505
      },
      "nvd": {
        "published": "2026-07-30T19:17:04.113",
        "lastModified": "2026-07-30T19:31:02.643",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11904",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Detailed error responses expose internal information to a remote requester.",
        "basis": [
          "CNA",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279510",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-11908",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T16:26:54.582Z",
      "date_published": "2026-07-10T21:43:03.734Z",
      "date_updated": "2026-07-14T14:34:40.621Z",
      "publisher": "drupal",
      "title": "Tagify - Moderately critical - Cross-site scripting (XSS) - SA-CONTRIB-2026-043",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Tagify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05826
      },
      "nvd": {
        "published": "2026-07-10T22:16:38.873",
        "lastModified": "2026-07-14T15:16:56.477",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11908",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-043",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11909",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T16:26:55.928Z",
      "date_published": "2026-07-10T21:43:38.232Z",
      "date_updated": "2026-07-13T18:09:37.596Z",
      "publisher": "drupal",
      "title": "Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Examples for Developers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05707
      },
      "nvd": {
        "published": "2026-07-10T22:16:38.973",
        "lastModified": "2026-07-13T19:16:36.507",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11909",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-044",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11913",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T16:43:04.126Z",
      "date_published": "2026-07-10T22:00:08.662Z",
      "date_updated": "2026-07-13T18:51:40.699Z",
      "publisher": "drupal",
      "title": "Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Mother May I"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24454
      },
      "nvd": {
        "published": "2026-07-10T23:16:46.490",
        "lastModified": "2026-07-13T19:16:37.200",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11913",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Drupal confirms an unfixed security issue in the unsupported module but does not disclose the vulnerable feature, input, check, or execution path.",
        "basis": [
          "CNA",
          "CWE-79",
          "https://www.drupal.org/sa-contrib-2026-045"
        ],
        "deepDive": true,
        "notes": "Drupal's advisory says only that the project is unsupported because of a known unfixed issue and instructs users to uninstall it; it does not substantiate the CNA's XSS label or any other cause."
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-045",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 92,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11914",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T16:43:05.303Z",
      "date_published": "2026-07-10T21:59:28.008Z",
      "date_updated": "2026-07-13T19:05:09.292Z",
      "publisher": "drupal",
      "title": "Composer - Critical - Unsupported - SA-CONTRIB-2026-046",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Composer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12176
      },
      "nvd": {
        "published": "2026-07-10T23:16:46.843",
        "lastModified": "2026-07-13T20:16:41.033",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11914",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record contains no vulnerability mechanism or impact statement beyond a generic input-validation label.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-046",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 84,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11915",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T16:43:06.497Z",
      "date_published": "2026-07-10T21:58:18.624Z",
      "date_updated": "2026-07-13T19:06:23.066Z",
      "publisher": "drupal",
      "title": "Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Brute force attack protection"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00192,
        "percentile": 0.09141
      },
      "nvd": {
        "published": "2026-07-10T23:16:46.933",
        "lastModified": "2026-07-13T20:16:41.707",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11915",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The authentication flow lacks an effective attempt limit for repeated credential guesses.",
        "basis": [
          "CNA",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-047",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11917",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T16:54:28.573Z",
      "date_published": "2026-07-14T15:07:41.808Z",
      "date_updated": "2026-07-14T15:54:01.677Z",
      "publisher": "Rockwell",
      "title": "ThinManager® - Path Traversal via API",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "FactoryTalk ThinManager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24905
      },
      "nvd": {
        "published": "2026-07-14T16:16:44.780",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11917",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ThinManager API does not confine a caller-supplied save path to the intended directory, allowing writes into restricted system locations.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1782.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11922",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T17:41:21.911Z",
      "date_published": "2026-07-24T03:27:39.188Z",
      "date_updated": "2026-07-24T12:24:23.509Z",
      "publisher": "@huntr_ai",
      "title": "Rate-limit Bypass in zenml-io/zenml",
      "affected": {
        "vendors": [
          "zenml-io"
        ],
        "products": [
          {
            "vendor": "zenml-io",
            "product": "zenml-io/zenml"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@huntr.dev",
          "type": "Secondary",
          "version": "3.0",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07661
      },
      "nvd": {
        "published": "2026-07-24T04:16:51.193",
        "lastModified": "2026-07-24T13:17:23.790",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11922",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The login rate limiter trusts a caller-controlled X-Forwarded-For value as the client address when all forwarding proxies are trusted, so the caller can rotate its rate-limit key.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://huntr.com/bounties/3cb8bf6a-ae55-4b38-8da3-601c666a210e",
          "host": "huntr.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/zenml-io/zenml/commit/8a2214bdd63eb8200ce4719d82c6f0d935e922d1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 621,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11925",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T17:57:47.060Z",
      "date_published": "2026-07-21T20:25:02.468Z",
      "date_updated": "2026-07-22T19:40:54.065Z",
      "publisher": "Tanium",
      "title": "Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.",
      "affected": {
        "vendors": [
          "Tanium"
        ],
        "products": [
          {
            "vendor": "Tanium",
            "product": "Tanium Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:3938794e-25f5-4123-a1ba-5cbd7f104512",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07503
      },
      "nvd": {
        "published": "2026-07-21T21:16:48.793",
        "lastModified": "2026-07-22T20:35:40.827",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11925",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports security impact in Tanium Server but does not identify the failing check, parser rule, state transition, or lifetime error.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.tanium.com/TAN-2026-017",
          "host": "security.tanium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-11944",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T21:25:07.392Z",
      "date_published": "2026-07-14T15:23:47.689Z",
      "date_updated": "2026-07-14T15:58:38.983Z",
      "publisher": "Fluid Attacks",
      "title": "openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download",
      "affected": {
        "vendors": [
          "OS4ED"
        ],
        "products": [
          {
            "vendor": "OS4ED",
            "product": "openSIS-Classic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:help@fluidattacks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30415
      },
      "nvd": {
        "published": "2026-07-14T16:16:44.917",
        "lastModified": "2026-07-14T20:28:57.843",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-11944",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted traversal segments in the sent-mail attachment path select files outside the messaging attachment directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fluidattacks.com/es/advisories/toto",
          "host": "fluidattacks.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/OS4ED/openSIS-Classic",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11946",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T21:38:14.592Z",
      "date_published": "2026-07-02T10:54:17.782Z",
      "date_updated": "2026-07-02T12:15:49.245Z",
      "publisher": "ENISA",
      "title": "GetEndpoints Memory Exhaustion in open62541",
      "affected": {
        "vendors": [
          "open62541 project / o6 Automation GmbH"
        ],
        "products": [
          {
            "vendor": "open62541 project / o6 Automation GmbH",
            "product": "open62541"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00381,
        "percentile": 0.30815
      },
      "nvd": {
        "published": "2026-07-02T12:16:54.740",
        "lastModified": "2026-07-02T17:39:07.620",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11946",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The discovery service buffers an attacker-declared multi-gigabyte endpointUrl across unfinished chunks without an effective length or completion bound.",
        "basis": [
          "CNA",
          "CWE-770",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open62541/open62541/pull/8142",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/open62541/open62541",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 607,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-11961",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T07:56:03.810Z",
      "date_published": "2026-07-17T06:00:02.044Z",
      "date_updated": "2026-07-17T14:12:22.220Z",
      "publisher": "WPScan",
      "title": "User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "User Registration & Membership"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16077
      },
      "nvd": {
        "published": "2026-07-17T07:16:37.850",
        "lastModified": "2026-07-17T15:44:29.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11961",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "User Registration & Membership fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/2ffab574-8626-472e-b6e4-09bcbaa62349/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11962",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T08:10:42.468Z",
      "date_published": "2026-07-06T06:00:01.869Z",
      "date_updated": "2026-07-06T12:14:33.831Z",
      "publisher": "WPScan",
      "title": "FileOrganizer < 1.2.0 - Authenticated Arbitrary File Upload via elFinder File Operations",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "FileOrganizer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00435,
        "percentile": 0.35834
      },
      "nvd": {
        "published": "2026-07-06T08:16:35.270",
        "lastModified": "2026-07-06T18:37:01.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11962",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Several elFinder operations accept executable PHP uploads without applying the file-type validation added only to the ordinary upload path.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/88390679-80c5-439f-89d1-2f46aff8cfdb/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11963",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T08:11:19.820Z",
      "date_published": "2026-07-13T06:00:01.343Z",
      "date_updated": "2026-07-13T15:53:39.115Z",
      "publisher": "WPScan",
      "title": "User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Membership Tier Modification via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "User Registration & Membership"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10138
      },
      "nvd": {
        "published": "2026-07-13T07:16:27.307",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11963",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User Registration & Membership accepts a caller-supplied object identifier without binding the selected object to the caller's ownership or authorized scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/a34a916a-983e-48a5-8f10-99214ee3b613/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11964",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T08:46:05.907Z",
      "date_published": "2026-07-13T06:00:01.573Z",
      "date_updated": "2026-07-13T15:52:54.768Z",
      "publisher": "WPScan",
      "title": "User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verification Bypass Leading to Membership Activation",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "User Registration & Membership"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19718
      },
      "nvd": {
        "published": "2026-07-13T07:16:27.420",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11964",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The membership plugin acts on PayPal webhook events without verifying their authenticity, so a forged approval event activates a paid membership.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/faf55649-8f76-4abf-a6b9-0d0774e22d29/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11965",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T08:47:33.210Z",
      "date_published": "2026-07-02T06:00:02.969Z",
      "date_updated": "2026-07-02T12:33:14.153Z",
      "publisher": "WPScan",
      "title": "User Registration & Membership < 5.2.0 - Unauthenticated Paid Membership Bypass",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "User Registration & Membership"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06074
      },
      "nvd": {
        "published": "2026-07-02T06:16:13.390",
        "lastModified": "2026-07-02T15:12:53.577",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11965",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The registration workflow activates a paid membership before establishing that payment completed.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/49f4c59e-5931-405d-8518-244531bbc889/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 348,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11966",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T08:55:41.528Z",
      "date_published": "2026-07-17T06:00:02.217Z",
      "date_updated": "2026-07-17T13:00:19.507Z",
      "publisher": "WPScan",
      "title": "User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe Subscription Handler",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "User Registration & Membership"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09867
      },
      "nvd": {
        "published": "2026-07-17T07:16:37.947",
        "lastModified": "2026-07-17T15:44:29.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11966",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A membership payment action accepts an unauthenticated caller-supplied user identifier and deletes the selected account without a capability or ownership check.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/8e3be064-b3b7-4d68-960b-8c850c3e6f77/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 314,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11973",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T11:35:31.358Z",
      "date_published": "2026-07-29T07:48:03.678Z",
      "date_updated": "2026-07-29T15:22:44.354Z",
      "publisher": "Wordfence",
      "title": "WP-Lister Lite for eBay <= 3.8.8 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "affected": {
        "vendors": [
          "wp-lab"
        ],
        "products": [
          {
            "vendor": "wp-lab",
            "product": "WP-Lister Lite for eBay"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21697
      },
      "nvd": {
        "published": "2026-07-29T09:16:29.040",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11973",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cec0d64e-7b31-4484-8237-2ab4d730ab86?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-lister-for-ebay/trunk/classes/model/ProfilesModel.php#L304",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-lister-for-ebay/trunk/classes/model/ProfilesModel.php#L278",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-lister-for-ebay/trunk/classes/table/StocksLogTable.php#L316",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-lister-for-ebay/trunk/classes/table/StocksLogTable.php#L277",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-lister-for-ebay/trunk/classes/model/EbayOrdersModel.php#L1354",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-lister-for-ebay/trunk/classes/model/EbayOrdersModel.php#L1291",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11974",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T11:50:00.532Z",
      "date_published": "2026-07-29T06:00:02.103Z",
      "date_updated": "2026-07-29T12:50:37.360Z",
      "publisher": "WPScan",
      "title": "Media folder Addon <= 4.1.6 - Unauthenticated Arbitrary File Download",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "wp-media-folder-addon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00489,
        "percentile": 0.39418
      },
      "nvd": {
        "published": "2026-07-29T07:16:41.143",
        "lastModified": "2026-07-30T14:16:31.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11974",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/7b6aea5d-2e2e-4920-9776-b15841ba1f26/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 473,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11980",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T13:21:02.331Z",
      "date_published": "2026-07-30T14:16:31.507Z",
      "date_updated": "2026-07-31T16:10:13.782Z",
      "publisher": "ibm",
      "title": "Code execution in IBM Desktop App",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Aspera Desktop App"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-242",
          "name": "Use of Inherently Dangerous Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06657
      },
      "nvd": {
        "published": "2026-07-30T15:16:24.277",
        "lastModified": "2026-07-31T16:16:57.403",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11980",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The desktop application searches for and loads startup DLLs from a location an attacker can influence.",
        "basis": [
          "CNA",
          "CWE-242"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280939",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T13:38:17.450Z",
      "date_published": "2026-07-01T04:32:26.862Z",
      "date_updated": "2026-07-01T10:42:11.276Z",
      "publisher": "Wordfence",
      "title": "GiveWP <= 4.15.3 - Cross-Site Request Forgery",
      "affected": {
        "vendors": [
          "stellarwp"
        ],
        "products": [
          {
            "vendor": "stellarwp",
            "product": "GiveWP – Donation Plugin and Fundraising Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05083
      },
      "nvd": {
        "published": "2026-07-01T05:16:16.607",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11981",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "give_set_notification_status_handler() changes the donation-email notification state without validating a WordPress nonce, allowing a forged administrator request to disable notifications.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/49954c72-df0d-46ec-a252-8af84dea41bf?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.15.3/includes/admin/emails/ajax-handler.php#L25",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.15.3/includes/admin/emails/ajax-handler.php#L24",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.15.3/includes/admin/emails/ajax-handler.php#L32",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/3.19.4/includes/admin/emails/ajax-handler.php#L25",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/3.19.4/includes/admin/emails/ajax-handler.php#L24",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/3.19.4/includes/admin/emails/ajax-handler.php#L32",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3573301/give/trunk/includes/admin/emails/ajax-handler.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fgive/tags/4.15.3&new_path=%2Fgive/tags/4.15.4",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11988",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T14:28:25.105Z",
      "date_published": "2026-07-01T04:32:27.231Z",
      "date_updated": "2026-07-01T10:42:11.133Z",
      "publisher": "Wordfence",
      "title": "LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter",
      "affected": {
        "vendors": [
          "thimpress"
        ],
        "products": [
          {
            "vendor": "thimpress",
            "product": "LearnPress – WordPress LMS Plugin for Create and Sell Online Courses"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.187
      },
      "nvd": {
        "published": "2026-07-01T05:16:16.750",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11988",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6b5e8cfd-989e-4a64-abb0-9daa22df46a4?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.3.9.1/inc/rest-api/v1/frontend/class-lp-rest-lazy-load-controller.php#L137",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.3.9.1/inc/rest-api/v1/frontend/class-lp-rest-lazy-load-controller.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.3.9.1/inc/user/abstract-lp-user.php#L680",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.7.5/inc/rest-api/v1/frontend/class-lp-rest-lazy-load-controller.php#L137",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.7.5/inc/rest-api/v1/frontend/class-lp-rest-lazy-load-controller.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.7.5/inc/user/abstract-lp-user.php#L680",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Flearnpress/tags/4.3.9.1&new_path=%2Flearnpress/tags/4.4.0",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 715,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11990",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T14:38:19.971Z",
      "date_published": "2026-07-10T09:32:45.502Z",
      "date_updated": "2026-07-10T18:16:36.454Z",
      "publisher": "Wordfence",
      "title": "KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint",
      "affected": {
        "vendors": [
          "iqonicdesign"
        ],
        "products": [
          {
            "vendor": "iqonicdesign",
            "product": "KiviCare – Clinic & Patient Management System (EHR)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00342,
        "percentile": 0.26801
      },
      "nvd": {
        "published": "2026-07-10T10:16:21.323",
        "lastModified": "2026-07-10T19:17:19.873",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11990",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated appointment action accepts a caller-selected appointment and payment identifier without verifying authority or completed payment.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/efe4223a-5c1a-401e-a46b-0278e96d2d71?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.4.0/app/controllers/api/AppointmentsController.php#L3931",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.4.0/app/controllers/api/AppointmentsController.php#L465",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.4.0/app/paymentGateways/KCPayLater.php#L109",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.4.0/app/services/KCAppointmentPaymentService.php#L32",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.4.0/app/baseClasses/KCPaymentGatewayFactory.php#L131",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.3.0/app/controllers/api/AppointmentsController.php#L3931",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.3.0/app/controllers/api/AppointmentsController.php#L465",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.3.0/app/paymentGateways/KCPayLater.php#L109",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.3.0/app/services/KCAppointmentPaymentService.php#L32",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.3.0/app/baseClasses/KCPaymentGatewayFactory.php#L131",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3599918%40kivicare-clinic-management-system&new=3599918%40kivicare-clinic-management-system",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 732,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-11992",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T14:53:51.026Z",
      "date_published": "2026-07-10T07:48:45.416Z",
      "date_updated": "2026-07-10T14:05:27.652Z",
      "publisher": "Wordfence",
      "title": "Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation",
      "affected": {
        "vendors": [
          "easyappointments"
        ],
        "products": [
          {
            "vendor": "easyappointments",
            "product": "Easy Appointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20244
      },
      "nvd": {
        "published": "2026-07-10T09:16:52.280",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-11992",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An appointment-cancellation action relies on a nonce exposed to authors and never checks their authority to cancel site-wide appointments.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/eea33d0b-2547-4c51-8c4c-d178d6c8502d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.25/src/ajax.php#L563",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.25/src/ajax.php#L619",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.25/src/ajax.php#L180",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.25/src/templates/appointments.tpl.php#L302",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.24.1/src/ajax.php#L563",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.24.1/src/ajax.php#L619",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.24.1/src/ajax.php#L180",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.24.1/src/templates/appointments.tpl.php#L302",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 671,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12001",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T16:23:35.413Z",
      "date_published": "2026-07-27T20:08:50.230Z",
      "date_updated": "2026-07-28T20:49:43.134Z",
      "publisher": "TPLink",
      "title": "Hardcoded Credential Vulnerability in Multiple TP-Link Router Models",
      "affected": {
        "vendors": [
          "TP Link Systems Inc.",
          "TP-Link Systems Inc."
        ],
        "products": [
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "TL-WR850N v3"
          },
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "Archer C20 v6"
          },
          {
            "vendor": "TP Link Systems Inc.",
            "product": "TL-WR845N v4"
          },
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "Archer MR200 v5"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f23511db-6c3e-4e32-a477-6aa17d310630",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15746
      },
      "nvd": {
        "published": "2026-07-27T21:16:47.457",
        "lastModified": "2026-07-28T16:20:10.853",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12001",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Firmware stores a reusable credential in a hard-coded password file.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tp-link.com/en/support/download/archer-mr200/v5/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/in/support/download/archer-mr200/v5/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/en/support/download/archer-c20/v6/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/download/archer-c20/v6/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/in/support/download/archer-c20/v6/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/en/support/download/tl-wr845n/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/in/support/download/tl-wr845n/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/in/support/download/tl-wr850n/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/faq/5210/",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-12002",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T16:59:38.484Z",
      "date_published": "2026-07-08T12:33:16.785Z",
      "date_updated": "2026-07-08T13:03:04.692Z",
      "publisher": "Wordfence",
      "title": "Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter",
      "affected": {
        "vendors": [
          "smub"
        ],
        "products": [
          {
            "vendor": "smub",
            "product": "Smash Balloon Social Photo Feed – Easy Social Feeds Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00102,
        "percentile": 0.01109
      },
      "nvd": {
        "published": "2026-07-08T13:16:28.380",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12002",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "maybe_connection_data accepts a cross-site request without a valid nonce, allowing an administrator's browser to overwrite stored access tokens.",
        "basis": [
          "CNA record",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/abe6366a-3729-474f-8920-b5ed2eeab906?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3575933/instagram-feed/trunk/admin/SBI_oEmbeds.php?old=3289310&old_path=instagram-feed%2Ftrunk%2Fadmin%2FSBI_oEmbeds.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 505,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12041",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T19:41:41.142Z",
      "date_published": "2026-07-08T05:34:08.842Z",
      "date_updated": "2026-07-08T13:59:24.726Z",
      "publisher": "Wordfence",
      "title": "Chatra Live Chat + ChatBot + Cart Saver <= 1.0.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'chatra-code' Setting",
      "affected": {
        "vendors": [
          "chatra"
        ],
        "products": [
          {
            "vendor": "chatra",
            "product": "Chatra Live Chat + ChatBot + Cart Saver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09194
      },
      "nvd": {
        "published": "2026-07-08T06:16:21.853",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12041",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chatra Live Chat + ChatBot + Cart Saver renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/75da660b-04c7-4f15-b49d-2aa320ef5b4b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatra-live-chat/tags/1.0.12/chatra.php#L61",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatra-live-chat/tags/1.0.12/chatra.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12064",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T07:23:29.455Z",
      "date_published": "2026-07-03T06:13:55.302Z",
      "date_updated": "2026-07-06T18:21:00.665Z",
      "publisher": "curl",
      "title": "proto-default skips SSH verification",
      "affected": {
        "vendors": [
          "curl"
        ],
        "products": [
          {
            "vendor": "curl",
            "product": "curl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 41,
        "versionRangeCount": 41,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-297",
          "name": "Improper Validation of Certificate with Host Mismatch",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26473
      },
      "nvd": {
        "published": "2026-07-03T07:16:24.217",
        "lastModified": "2026-07-07T19:43:11.187",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-12064",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "For a schemeless URL forced to SFTP, curl skips the SSH host-key configuration and connects without verifying the server key.",
        "basis": [
          "CNA",
          "CWE-295",
          "CWE-297"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://curl.se/docs/CVE-2026-12064.json",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://curl.se/docs/CVE-2026-12064.html",
          "host": "curl.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3797526",
          "host": "hackerone.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 683,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 41
      }
    },
    {
      "cve_id": "CVE-2026-12080",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T12:44:56.002Z",
      "date_published": "2026-07-20T12:40:45.399Z",
      "date_updated": "2026-07-20T19:08:22.324Z",
      "publisher": "redhat",
      "title": "Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux for NVIDIA 26"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-61",
          "name": "UNIX Symbolic Link (Symlink) Following",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.0372
      },
      "nvd": {
        "published": "2026-07-20T13:16:55.543",
        "lastModified": "2026-07-21T18:31:51.680",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12080",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The guest-ssh-add-authorized-keys handler follows attacker-controlled directory or file symlinks across its check and use steps, allowing a root-owned target to be replaced or taken over.",
        "basis": [
          "CNA",
          "CWE-61"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12080",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499603",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.com/qemu-project/qemu/-/work_items/3929",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-12081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T12:57:19.880Z",
      "date_published": "2026-07-13T06:00:01.807Z",
      "date_updated": "2026-07-13T15:50:21.485Z",
      "publisher": "WPScan",
      "title": "Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object Injection via Entry File Field",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Database for Contact Form 7, WPforms, Elementor forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.0372
      },
      "nvd": {
        "published": "2026-07-13T07:16:27.520",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12081",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled serialized data is passed to a native object deserializer that can instantiate executable object graphs.",
        "basis": [
          "CNA record",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/91d0baf4-1052-4666-a28b-34689e06cbab/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 473,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T12:57:22.525Z",
      "date_published": "2026-07-23T06:00:02.421Z",
      "date_updated": "2026-07-23T14:12:30.060Z",
      "publisher": "WPScan",
      "title": "Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Praison AI SEO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.1514
      },
      "nvd": {
        "published": "2026-07-23T07:16:31.423",
        "lastModified": "2026-07-23T15:16:33.560",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12082",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Several Praison AI SEO REST routes perform post-permalink writes and configuration reads without authenticating or authorizing the caller.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/d23cb7bd-b40c-4f87-a134-7c3b62043f18/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 275,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12083",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T13:04:18.229Z",
      "date_published": "2026-07-06T06:00:02.042Z",
      "date_updated": "2026-07-06T12:00:32.159Z",
      "publisher": "WPScan",
      "title": "Admin and Site Enhancements < 8.8.4 - Unauthenticated Administrator-Role Restoration via reset-for Parameter",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Admin and Site Enhancements (ASE)"
          },
          {
            "vendor": "Unknown",
            "product": "admin-site-enhancements-pro"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21756
      },
      "nvd": {
        "published": "2026-07-06T08:16:35.360",
        "lastModified": "2026-07-06T18:37:01.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12083",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The role-restoration handler checks neither authentication, authorization, nor a nonce before restoring a demoted account to administrator.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/a0c94f7f-6314-4ff2-bb92-ec02146975ff/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 502,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-12090",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T14:02:31.132Z",
      "date_published": "2026-07-01T03:43:37.605Z",
      "date_updated": "2026-07-01T10:32:05.420Z",
      "publisher": "Wordfence",
      "title": "Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'wppm_proj_filter' Parameter",
      "affected": {
        "vendors": [
          "taskbuilder"
        ],
        "products": [
          {
            "vendor": "taskbuilder",
            "product": "Taskbuilder – Project Management & Task Management Tool With Kanban Board"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23398
      },
      "nvd": {
        "published": "2026-07-01T05:16:16.900",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12090",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The wppm_proj_filter parameter is incorporated into an SQL statement without separating its data from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d1a78208-0909-4134-bc78-19e395fe7e24?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/trunk/includes/admin/projects/open_project/wppm_view_project_tasks.php#L21",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/trunk/includes/admin/projects/open_project/wppm_view_project_tasks.php#L181",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/trunk/includes/class-wppm-admin.php#L506",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.6/includes/admin/projects/open_project/wppm_view_project_tasks.php#L181",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.6/includes/admin/projects/open_project/wppm_view_project_tasks.php#L21",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.6/includes/class-wppm-admin.php#L506",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Ftaskbuilder/tags/5.0.8&new_path=%2Ftaskbuilder/tags/5.0.9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3576941/taskbuilder/trunk/includes/admin/projects/open_project/wppm_view_project_tasks.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 785,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12097",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T14:14:04.136Z",
      "date_published": "2026-07-08T05:34:08.154Z",
      "date_updated": "2026-07-08T13:12:59.152Z",
      "publisher": "Wordfence",
      "title": "User Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Settings Modification",
      "affected": {
        "vendors": [
          "saadiqbal"
        ],
        "products": [
          {
            "vendor": "saadiqbal",
            "product": "User Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17074
      },
      "nvd": {
        "published": "2026-07-08T06:16:22.000",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12097",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The User Management operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4f1d0a07-254c-4df9-90a4-966dff014df0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/user-management/tags/1.2/includes/model.php#L853",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/user-management/tags/1.2/includes/model.php#L729",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/user-management/tags/1.2/includes/model.php#L21",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/user-management/tags/1.2/users-imp-exp-wpexperts.php#L22",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T14:28:14.643Z",
      "date_published": "2026-07-11T05:35:49.340Z",
      "date_updated": "2026-07-13T14:29:56.736Z",
      "publisher": "Wordfence",
      "title": "Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action",
      "affected": {
        "vendors": [
          "subratamal"
        ],
        "products": [
          {
            "vendor": "subratamal",
            "product": "Wallet for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20927
      },
      "nvd": {
        "published": "2026-07-11T07:16:45.490",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12103",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A subscriber can reuse a frontend-exposed nonce to query the AJAX user search without authorization to enumerate every account.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/98b38844-c6fe-4655-8bbe-7600203b567e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-wallet/tags/1.6.3/includes/class-woo-wallet-ajax.php#L166",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-wallet/tags/1.6.3/includes/helper/woo-wallet-util.php#L1462",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-wallet/tags/1.6.3/includes/class-woo-wallet-frontend.php#L199",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-wallet/tags/1.6.3/includes/class-woo-wallet-ajax.php#L56",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-wallet/tags/1.6.0/includes/class-woo-wallet-ajax.php#L166",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-wallet/tags/1.6.0/includes/helper/woo-wallet-util.php#L1462",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-wallet/tags/1.6.0/includes/class-woo-wallet-frontend.php#L199",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-wallet/tags/1.6.0/includes/class-woo-wallet-ajax.php#L56",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3585829%40woo-wallet&new=3585829%40woo-wallet",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 703,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12108",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T14:32:13.190Z",
      "date_published": "2026-07-10T07:48:40.621Z",
      "date_updated": "2026-07-10T18:15:41.887Z",
      "publisher": "Wordfence",
      "title": "Highlighting Code Block <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'font_family' Setting",
      "affected": {
        "vendors": [
          "looswebstudio"
        ],
        "products": [
          {
            "vendor": "looswebstudio",
            "product": "Highlighting Code Block"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11023
      },
      "nvd": {
        "published": "2026-07-10T09:16:52.417",
        "lastModified": "2026-07-10T19:17:20.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12108",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/166e1d3a-3fd9-4ab0-ba0d-707c6d59e0cd?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/highlighting-code-block/tags/2.2.0/class/loos_hcb.php#L158",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/highlighting-code-block/tags/2.2.0/class/loos_hcb_menu.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/highlighting-code-block/tags/2.2.0/class/loos_hcb_scripts.php#L69",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/highlighting-code-block/tags/2.1.3/class/loos_hcb.php#L158",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/highlighting-code-block/tags/2.1.3/class/loos_hcb_menu.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/highlighting-code-block/tags/2.1.3/class/loos_hcb_scripts.php#L69",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3592103%40highlighting-code-block&new=3592103%40highlighting-code-block",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 520,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12110",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T14:38:07.858Z",
      "date_published": "2026-07-01T03:43:36.119Z",
      "date_updated": "2026-07-01T10:32:06.198Z",
      "publisher": "Wordfence",
      "title": "Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'task_search' Parameter",
      "affected": {
        "vendors": [
          "taskbuilder"
        ],
        "products": [
          {
            "vendor": "taskbuilder",
            "product": "Taskbuilder – Project Management & Task Management Tool With Kanban Board"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24275
      },
      "nvd": {
        "published": "2026-07-01T05:16:17.037",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12110",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The task_search parameter is concatenated into a SQL query without escaping and parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/78ab6263-7762-4fd2-af42-2224efa9509e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/trunk/includes/admin/tasks/wppm_tasks_list.php#L215",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/trunk/includes/admin/tasks/wppm_tasks_list.php#L9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/trunk/includes/class-wppm-admin.php#L516",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/trunk/includes/class-wppm-admin.php#L40",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.7/includes/admin/tasks/wppm_tasks_list.php#L215",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.7/includes/admin/tasks/wppm_tasks_list.php#L9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.7/includes/class-wppm-admin.php#L516",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.7/includes/class-wppm-admin.php#L40",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Ftaskbuilder/tags/5.0.8&new_path=%2Ftaskbuilder/tags/5.0.9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3576941/taskbuilder/trunk/includes/admin/tasks/wppm_tasks_list.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 751,
        "referenceCount": 11,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12113",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T14:41:49.325Z",
      "date_published": "2026-07-01T04:32:26.135Z",
      "date_updated": "2026-07-01T10:42:11.567Z",
      "publisher": "Wordfence",
      "title": "Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure",
      "affected": {
        "vendors": [
          "codepeople"
        ],
        "products": [
          {
            "vendor": "codepeople",
            "product": "Appointment Booking Calendar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13615
      },
      "nvd": {
        "published": "2026-07-01T05:16:17.173",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12113",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3838bb64-fd85-43a4-97a2-7ca7930697ad?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/appointment-booking-calendar/trunk/inc/cpabc_apps_on.inc.php#L328",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/appointment-booking-calendar/tags/1.3.99/inc/cpabc_apps_on.inc.php#L328",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/appointment-booking-calendar/trunk/inc/cpabc_apps_on.inc.php#L255",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/appointment-booking-calendar/tags/1.3.99/inc/cpabc_apps_on.inc.php#L255",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/appointment-booking-calendar/trunk/cpabc_appointments.php#L187",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/appointment-booking-calendar/tags/1.3.99/cpabc_appointments.php#L187",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3581633%40appointment-booking-calendar&new=3581633%40appointment-booking-calendar&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12116",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T14:47:35.871Z",
      "date_published": "2026-07-09T12:37:31.679Z",
      "date_updated": "2026-07-09T15:15:34.035Z",
      "publisher": "certcc",
      "title": "CVE-2026-12116",
      "affected": {
        "vendors": [
          "Xerte"
        ],
        "products": [
          {
            "vendor": "Xerte",
            "product": "Xerte Online Tools"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00566,
        "percentile": 0.43776
      },
      "nvd": {
        "published": "2026-07-09T14:16:26.467",
        "lastModified": "2026-07-09T19:49:55.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12116",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Xerte permits an uploaded PHP file to be selected as the configured antivirus executable, so the later scan step executes that file as server-side code.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thexerteproject/xerteonlinetoolkits/commit/8ef20628f80bd88bd1fe3e5844a9116a910086b7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/thexerteproject/xerteonlinetoolkits/issues/1543",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.xerte.org.uk/index.php/en/news/blog/80-news/364-xerte-3-14-and-3-15-important-security-update",
          "host": "www.xerte.org.uk",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 231,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-12118",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T14:59:49.826Z",
      "date_published": "2026-07-30T17:00:50.262Z",
      "date_updated": "2026-07-30T17:41:17.032Z",
      "publisher": "ibm",
      "title": "IBM webMethods Integration could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "webMethods Integration (on prem)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00499,
        "percentile": 0.40014
      },
      "nvd": {
        "published": "2026-07-30T19:17:04.483",
        "lastModified": "2026-07-30T19:31:02.643",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12118",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application deserializes attacker-controlled bytes with object semantics that can invoke executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278857",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 182,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12122",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T15:07:09.908Z",
      "date_published": "2026-07-02T08:33:06.133Z",
      "date_updated": "2026-07-02T12:20:45.477Z",
      "publisher": "Wordfence",
      "title": "Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action",
      "affected": {
        "vendors": [
          "themeum"
        ],
        "products": [
          {
            "vendor": "themeum",
            "product": "Kirki – Freeform Page Builder, Website Builder & Customizer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20722
      },
      "nvd": {
        "published": "2026-07-02T10:16:27.410",
        "lastModified": "2026-07-02T13:58:56.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12122",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The unauthenticated get_single_symbol action accepts a sequential post ID without checking publication state or read permission for the requested symbol.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8b5db7fa-2e72-4719-b85e-cc31778c2274?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.9/includes/Ajax/Symbol.php#L245",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.9/includes/Ajax/Symbol.php#L145",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.9/includes/Ajax.php#L73",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.5/includes/Ajax/Symbol.php#L245",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.5/includes/Ajax/Symbol.php#L145",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.5/includes/Ajax.php#L73",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3584702%40kirki&new=3584702%40kirki&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12123",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T15:11:28.352Z",
      "date_published": "2026-07-10T05:34:04.429Z",
      "date_updated": "2026-07-10T14:35:37.311Z",
      "publisher": "Wordfence",
      "title": "All-in-One Video Gallery <= 4.8.5 - Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter",
      "affected": {
        "vendors": [
          "plugins360"
        ],
        "products": [
          {
            "vendor": "plugins360",
            "product": "All-in-One Video Gallery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14981
      },
      "nvd": {
        "published": "2026-07-10T07:16:27.430",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12123",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The video download path fetches a subscriber-supplied URL without excluding loopback or internal destinations and returns the fetched body.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a3bb454c-ac0e-4915-8c6e-070596f7595a?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/all-in-one-video-gallery/tags/4.8.5/public/video.php#L904",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/all-in-one-video-gallery/tags/4.8.5/public/video.php#L724",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/all-in-one-video-gallery/tags/4.8.5/public/video.php#L758",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/all-in-one-video-gallery/tags/4.8.5/public/video.php#L681",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/all-in-one-video-gallery/tags/4.8.5/includes/roles.php#L70",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/all-in-one-video-gallery/tags/4.7.5/public/video.php#L904",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/all-in-one-video-gallery/tags/4.7.5/public/video.php#L724",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/all-in-one-video-gallery/tags/4.7.5/public/video.php#L758",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/all-in-one-video-gallery/tags/4.7.5/public/video.php#L681",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/all-in-one-video-gallery/tags/4.7.5/includes/roles.php#L70",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3582575",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 716,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12124",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T15:13:30.625Z",
      "date_published": "2026-07-28T05:39:41.443Z",
      "date_updated": "2026-07-28T13:29:30.785Z",
      "publisher": "Wordfence",
      "title": "PDFDraft <= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Disclosure via 'slug' Parameter",
      "affected": {
        "vendors": [
          "wpeverest"
        ],
        "products": [
          {
            "vendor": "wpeverest",
            "product": "PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11252
      },
      "nvd": {
        "published": "2026-07-28T07:16:40.787",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12124",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The PDF-serving AJAX and REST handlers expose template PDFs without a capability check and explicitly register the REST route as public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3cb869dd-c8cf-4849-a13f-6c8cf1c196b6?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pdfdraft/trunk/src/EmbedPdf.php#L448",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pdfdraft/trunk/src/EmbedPdf.php#L418",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pdfdraft/trunk/src/EmbedPdf.php#L60",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pdfdraft/trunk/src/EmbedPdf.php#L44",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3621033%40pdfdraft&new=3621033%40pdfdraft",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 769,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12126",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T15:16:02.267Z",
      "date_published": "2026-07-11T05:35:48.980Z",
      "date_updated": "2026-07-13T14:39:38.143Z",
      "publisher": "Wordfence",
      "title": "WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title'",
      "affected": {
        "vendors": [
          "wclovers"
        ],
        "products": [
          {
            "vendor": "wclovers",
            "product": "WCFM Marketplace – Multivendor Marketplace for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10565
      },
      "nvd": {
        "published": "2026-07-11T07:16:45.633",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12126",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attachment title stored through the REST API is returned in DataTables data and inserted as innerHTML without output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/881ec131-a716-4929-a44e-84bac161d81c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.7.2/controllers/media/wcfmmp-controller-media.php#L120",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.7.3/controllers/media/wcfmmp-controller-media.php#L120",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.7.3/core/class-wcfmmp-media.php#L163",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.7.3/controllers/media/wcfmmp-controller-media.php#L58",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.7.2/core/class-wcfmmp-media.php#L163",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.7.2/controllers/media/wcfmmp-controller-media.php#L58",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3588629%40wc-multivendor-marketplace&new=3588629%40wc-multivendor-marketplace",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 783,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12127",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T15:16:37.220Z",
      "date_published": "2026-07-01T04:32:27.607Z",
      "date_updated": "2026-07-01T10:42:10.985Z",
      "publisher": "Wordfence",
      "title": "WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name",
      "affected": {
        "vendors": [
          "smub"
        ],
        "products": [
          {
            "vendor": "smub",
            "product": "WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26912
      },
      "nvd": {
        "published": "2026-07-01T05:16:17.323",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12127",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A textarea-derived display name preserves CRLF bytes and is concatenated into the raw Reply-To mail header without removing header delimiters.",
        "basis": [
          "CNA",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d5a51c22-c4ca-4897-ad7e-c5df00b07fe0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.1.1/src/Emails/Mailer.php#L368",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.1.1/src/Emails/Notifications.php#L1098",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.1.1/src/Emails/Notifications.php#L1138",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.1.1/includes/fields/class-textarea.php#L326",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.0.2/src/Emails/Mailer.php#L368",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.0.2/src/Emails/Notifications.php#L1098",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.0.2/src/Emails/Notifications.php#L1138",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.0.2/includes/fields/class-textarea.php#L326",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3586095/wpforms-lite/trunk/src/Emails/Mailer.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fwpforms-lite/tags/1.10.2&new_path=%2Fwpforms-lite/tags/1.10.2.1",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1030,
        "referenceCount": 11,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12133",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T15:32:16.073Z",
      "date_published": "2026-07-01T03:43:33.374Z",
      "date_updated": "2026-07-01T10:42:12.169Z",
      "publisher": "Wordfence",
      "title": "JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action",
      "affected": {
        "vendors": [
          "beardev"
        ],
        "products": [
          {
            "vendor": "beardev",
            "product": "JoomSport – for Sports: Team & League, Football, Hockey & more"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16431
      },
      "nvd": {
        "published": "2026-07-01T05:16:17.490",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12133",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The group-deletion handler verifies a nonce but never checks whether the caller has the capability to delete groups.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/03122c29-4ca5-426a-8240-74ce96dd21f2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/trunk/includes/posts/joomsport-post-season.php#L296",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/posts/joomsport-post-season.php#L296",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/trunk/includes/posts/joomsport-post-season.php#L294",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/posts/joomsport-post-season.php#L294",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/trunk/includes/posts/joomsport-post-season.php#L25",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/posts/joomsport-post-season.php#L25",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/trunk/includes/joomsport-shortcodes.php#L473",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/joomsport-shortcodes.php#L473",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3581673%40joomsport-sports-league-results-management&new=3581673%40joomsport-sports-league-results-management&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12134",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T15:33:51.321Z",
      "date_published": "2026-07-02T08:33:06.525Z",
      "date_updated": "2026-07-02T14:57:35.251Z",
      "publisher": "Wordfence",
      "title": "JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action",
      "affected": {
        "vendors": [
          "beardev"
        ],
        "products": [
          {
            "vendor": "beardev",
            "product": "JoomSport – for Sports: Team & League, Football, Hockey & more"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14174
      },
      "nvd": {
        "published": "2026-07-02T10:16:27.530",
        "lastModified": "2026-07-02T15:16:56.820",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12134",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that JoomSport – for Sports: Team & League, Football, Hockey & more permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a00997d4-f242-4d49-8542-0738efa66222?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/posts/joomsport-post-season.php#L230",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/trunk/includes/posts/joomsport-post-season.php#L230",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/trunk/includes/posts/joomsport-post-season.php#L22",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/posts/joomsport-post-season.php#L22",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/trunk/includes/joomsport-shortcodes.php#L473",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/joomsport-shortcodes.php#L473",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3581673%40joomsport-sports-league-results-management&new=3581673%40joomsport-sports-league-results-management&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12135",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T15:59:43.436Z",
      "date_published": "2026-07-01T03:43:37.980Z",
      "date_updated": "2026-07-01T10:32:05.245Z",
      "publisher": "Wordfence",
      "title": "FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode",
      "affected": {
        "vendors": [
          "foliovision"
        ],
        "products": [
          {
            "vendor": "foliovision",
            "product": "FV Flowplayer Video Player"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09943
      },
      "nvd": {
        "published": "2026-07-01T05:16:17.630",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12135",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FV Flowplayer Video Player places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d5a3a560-08e6-43b7-b953-4e704eafc49b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fv-wordpress-flowplayer/trunk/controller/shortcodes.php#L227",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fv-wordpress-flowplayer/tags/7.5.49.7212/controller/shortcodes.php#L293",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fv-wordpress-flowplayer/trunk/controller/shortcodes.php#L293",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fv-wordpress-flowplayer/tags/7.5.49.7212/controller/shortcodes.php#L227",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3586305%40fv-wordpress-flowplayer%2Ftrunk&old=3557974%40fv-wordpress-flowplayer%2Ftrunk&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 480,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12139",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T17:05:55.702Z",
      "date_published": "2026-07-21T20:25:14.577Z",
      "date_updated": "2026-07-22T19:40:47.897Z",
      "publisher": "Tanium",
      "title": "Tanium addressed an information disclosure vulnerability in Connect.",
      "affected": {
        "vendors": [
          "Tanium"
        ],
        "products": [
          {
            "vendor": "Tanium",
            "product": "Connect"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-214",
          "name": "Invocation of Process Using Visible Sensitive Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:3938794e-25f5-4123-a1ba-5cbd7f104512",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01806
      },
      "nvd": {
        "published": "2026-07-21T21:16:48.937",
        "lastModified": "2026-07-22T20:35:40.827",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12139",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The affected Connect path places sensitive information in process invocation data that is visible beyond its intended observer, although Tanium does not publish the field.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-214"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.tanium.com/TAN-2026-018",
          "host": "security.tanium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 68,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-12141",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T17:13:30.104Z",
      "date_published": "2026-07-11T03:44:24.452Z",
      "date_updated": "2026-07-14T14:19:50.405Z",
      "publisher": "Wordfence",
      "title": "Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter",
      "affected": {
        "vendors": [
          "leap13"
        ],
        "products": [
          {
            "vendor": "leap13",
            "product": "Premium Addons for Elementor – Powerful Elementor Templates & Widgets"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09198
      },
      "nvd": {
        "published": "2026-07-11T05:16:32.000",
        "lastModified": "2026-07-14T15:16:56.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12141",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Premium Addons for Elementor – Powerful Elementor Templates & Widgets stores attacker-controlled content and later renders it without sufficient output escaping, allowing script execution in a visitor's browser.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/867a0742-4fa9-4473-8d51-9abb6ec353a8?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.82/addons/tooltips.php#L984",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.82/addons/tooltips.php#L251",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.82/addons/tooltips.php#L68",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3597629%40premium-addons-for-elementor&new=3597629%40premium-addons-for-elementor",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 793,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12142",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T17:32:40.310Z",
      "date_published": "2026-07-01T09:32:28.519Z",
      "date_updated": "2026-07-01T12:19:42.554Z",
      "publisher": "Wordfence",
      "title": "NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter",
      "affected": {
        "vendors": [
          "webaways"
        ],
        "products": [
          {
            "vendor": "webaways",
            "product": "NEX-Forms – Ultimate Forms Plugin for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.2271
      },
      "nvd": {
        "published": "2026-07-01T11:16:24.043",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12142",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NEX-Forms accepts script-capable tags and event handlers in its wp_kses allow-list, so stored _name array content remains executable HTML.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/da235dea-4884-4e6a-a8b8-65d34f050684?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php#L2903",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php#L2720",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php#L2660",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/includes/classes/class.db.php#L2660",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/includes/classes/class.db.php#L2809",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/includes/classes/class.functions.php#L2343",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/main.php#L2903",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/main.php#L2720",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/main.php#L2660",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/includes/classes/class.db.php#L2660",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/includes/classes/class.db.php#L2809",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/includes/classes/class.functions.php#L2343",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fnex-forms-express-wp-form-builder/tags/9.2.2&new_path=%2Fnex-forms-express-wp-form-builder/tags/9.2.3",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 638,
        "referenceCount": 14,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T17:37:43.374Z",
      "date_published": "2026-07-29T01:29:41.564Z",
      "date_updated": "2026-07-29T13:02:20.552Z",
      "publisher": "Wordfence",
      "title": "Wholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escalation via 'user_role_set' Parameter",
      "affected": {
        "vendors": [
          "saadiqbal"
        ],
        "products": [
          {
            "vendor": "saadiqbal",
            "product": "Wholesale for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00368,
        "percentile": 0.29537
      },
      "nvd": {
        "published": "2026-07-29T02:16:41.840",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12144",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "save_requests_meta passes a caller-selected role to WP_User::add_role without a role allowlist or privilege check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/327a155c-7a7d-494d-94d1-f7e7ee8927f0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-wholesale-pricing/tags/2.0.5/inc/class-wwp-wholesale-requests.php#L369",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-wholesale-pricing/tags/2.0.5/inc/class-wwp-wholesale-requests.php#L397",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-wholesale-pricing/tags/2.0.5/inc/class-wwp-wholesale-requests.php#L274",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3621257%40woo-wholesale-pricing&new=3621257%40woo-wholesale-pricing",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1089,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12153",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T18:22:34.569Z",
      "date_published": "2026-07-08T05:34:09.230Z",
      "date_updated": "2026-07-08T17:10:10.951Z",
      "publisher": "Wordfence",
      "title": "WP Learn Manager <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation and Activation via jslearnmanager_ajax AJAX Action",
      "affected": {
        "vendors": [
          "rabilal"
        ],
        "products": [
          {
            "vendor": "rabilal",
            "product": "WP Learn Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.31281
      },
      "nvd": {
        "published": "2026-07-08T06:16:22.157",
        "lastModified": "2026-07-08T18:16:30.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12153",
        "family": "AUTHORITY_BINDING",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "The public AJAX dispatcher permits unauthenticated module and task selection, and installPluginFromAjax and activatePluginFromAjax invoke WordPress plugin installation and activation without a capability check.",
        "basis": [
          "CNA",
          "CWE-862",
          "WordPress plugin source 1.1.8"
        ],
        "deepDive": true,
        "notes": "Inspected https://plugins.svn.wordpress.org/learn-manager/tags/1.1.8/includes/ajax.php and https://plugins.svn.wordpress.org/learn-manager/tags/1.1.8/modules/jslearnmanager/model.php; the source establishes the missing authorization checks, and no runtime reproduction was performed."
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8cbf5121-2511-4e21-a346-67fa1e34fc02?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learn-manager/tags/1.1.8/modules/jslearnmanager/model.php#L879",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learn-manager/tags/1.1.8/modules/jslearnmanager/model.php#L920",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learn-manager/tags/1.1.8/includes/ajax.php#L15",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learn-manager/tags/1.1.8/includes/ajax.php#L8",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 374,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12154",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T18:25:48.496Z",
      "date_published": "2026-07-06T17:31:48.426Z",
      "date_updated": "2026-07-07T14:07:04.454Z",
      "publisher": "Wordfence",
      "title": "Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_id' Shortcode Attribute",
      "affected": {
        "vendors": [
          "widgetpack"
        ],
        "products": [
          {
            "vendor": "widgetpack",
            "product": "Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08616
      },
      "nvd": {
        "published": "2026-07-06T18:16:36.670",
        "lastModified": "2026-07-07T15:16:42.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12154",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev() method, which passes the raw shortcode attribute through Feed_Old::get_feed() into the View::render() method, where it is echoed directly into the data-id HTML attribute without esc_attr().",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/86fbc499-dca3-41da-a6ef-8e97d7e46d0e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fb-reviews-widget/tags/2.7.3/includes/class-view.php#L36",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fb-reviews-widget/tags/2.7.3/includes/class-feed-shortcode.php#L57",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fb-reviews-widget/tags/2.7.3/includes/class-feed-old.php#L55",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3593292%40fb-reviews-widget&old=3451654%40fb-reviews-widget&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 701,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T18:38:08.245Z",
      "date_published": "2026-07-01T07:53:38.637Z",
      "date_updated": "2026-07-01T10:32:03.593Z",
      "publisher": "Wordfence",
      "title": "RegistrationMagic <= 6.0.9.1 - Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter",
      "affected": {
        "vendors": [
          "metagauss"
        ],
        "products": [
          {
            "vendor": "metagauss",
            "product": "RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00205,
        "percentile": 0.1062
      },
      "nvd": {
        "published": "2026-07-01T08:16:20.710",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12158",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.9.1.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ef7aff85-e1ca-47ce-86e9-a0fe356993a1?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/custom-registration-form-builder-with-submission-manager/tags/6.0.8.9/plus/chronos/services/service.php#L43",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/custom-registration-form-builder-with-submission-manager/tags/6.0.8.9/plus/chronos/controllers/task_controller.php#L63",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/custom-registration-form-builder-with-submission-manager/tags/6.0.8.9/plus/chronos/libs/rm_chronos.php#L277",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/custom-registration-form-builder-with-submission-manager/tags/6.0.8.9/plus/chronos/libs/task.php#L176",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3579552%40custom-registration-form-builder-with-submission-manager&new=3579552%40custom-registration-form-builder-with-submission-manager&sfp_email=&sfph_mail=#file8",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12166",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T19:40:24.620Z",
      "date_published": "2026-07-02T14:36:04.413Z",
      "date_updated": "2026-07-02T17:35:36.546Z",
      "publisher": "certcc",
      "title": "CVE-2026-12166",
      "affected": {
        "vendors": [
          "Little Orbit"
        ],
        "products": [
          {
            "vendor": "Little Orbit",
            "product": "GameFirst Anti-Cheat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11139
      },
      "nvd": {
        "published": "2026-07-02T15:16:56.927",
        "lastModified": "2026-07-02T18:16:48.197",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12166",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path dereferences a NULL pointer because the required validity check is missing or applied to the wrong value.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.littleorbit.com/",
          "host": "www.littleorbit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://kb.cert.org/vuls/id/639124",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/FzRsLLaSheR/CVE-2026-12166_CVE-2026-12167_CVE-2026-12168",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12167",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T19:40:33.666Z",
      "date_published": "2026-07-02T14:35:47.922Z",
      "date_updated": "2026-07-02T17:34:47.803Z",
      "publisher": "certcc",
      "title": "CVE-2026-12167",
      "affected": {
        "vendors": [
          "Little Orbit"
        ],
        "products": [
          {
            "vendor": "Little Orbit",
            "product": "GameFirst Anti-Cheat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.0669
      },
      "nvd": {
        "published": "2026-07-02T15:16:57.030",
        "lastModified": "2026-07-02T18:16:48.333",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12167",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The driver's minifilter communication port exposes privileged operations to local callers without an access restriction on the communication interface.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.littleorbit.com/",
          "host": "www.littleorbit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://kb.cert.org/vuls/id/639124",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/FzRsLLaSheR/CVE-2026-12166_CVE-2026-12167_CVE-2026-12168",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 224,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12168",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T19:40:44.862Z",
      "date_published": "2026-07-02T14:36:27.552Z",
      "date_updated": "2026-07-02T17:36:23.423Z",
      "publisher": "certcc",
      "title": "CVE-2026-12168",
      "affected": {
        "vendors": [
          "Little Orbit"
        ],
        "products": [
          {
            "vendor": "Little Orbit",
            "product": "GameFirst Anti-Cheat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-123",
          "name": "Write-what-where Condition",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05938
      },
      "nvd": {
        "published": "2026-07-02T15:16:57.123",
        "lastModified": "2026-07-02T18:16:48.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12168",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation fails to preserve a valid bound, initialization state, type, ownership rule, or object lifetime before memory access.",
        "basis": [
          "CNA",
          "CWE-123"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.littleorbit.com/",
          "host": "www.littleorbit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://kb.cert.org/vuls/id/639124",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/FzRsLLaSheR/CVE-2026-12166_CVE-2026-12167_CVE-2026-12168",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12170",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T20:24:56.022Z",
      "date_published": "2026-07-09T06:52:45.396Z",
      "date_updated": "2026-07-09T14:32:39.494Z",
      "publisher": "Wordfence",
      "title": "AcyMailing <= 10.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alignment' Attribute",
      "affected": {
        "vendors": [
          "acyba"
        ],
        "products": [
          {
            "vendor": "acyba",
            "product": "AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16201
      },
      "nvd": {
        "published": "2026-07-09T08:16:45.640",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12170",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4fd76fbc-22df-4071-a2ae-9c9ac9cdbc57?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/Core/wordpress/form.php#L292",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/Core/wordpress/form.php#L322",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/WpInit/Gutenberg.php#L202",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/WpInit/Gutenberg.php#L124",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3597432%40acymailing&new=3597432%40acymailing",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 491,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12194",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-14T07:01:15.150Z",
      "date_published": "2026-07-04T06:54:21.815Z",
      "date_updated": "2026-07-06T18:32:12.392Z",
      "publisher": "PRJBLK",
      "title": "PHPIPAM Authenticated LFI",
      "affected": {
        "vendors": [
          "phpipam"
        ],
        "products": [
          {
            "vendor": "phpipam",
            "product": "phpipam"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16426
      },
      "nvd": {
        "published": "2026-07-04T08:16:20.643",
        "lastModified": "2026-07-06T19:43:54.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12194",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An API caller can select an arbitrary local PHP file for inclusion outside the intended application file set.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/phpipam/phpipam/pull/4625",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "mitigation"
          ]
        },
        {
          "url": "https://projectblack.io/blog/local-ai-for-cyber-security/#the-benchmark-vulnerabilityphpipam-authenticated-lfi",
          "host": "projectblack.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12195",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-14T07:01:17.476Z",
      "date_published": "2026-07-04T11:33:27.032Z",
      "date_updated": "2026-07-06T18:31:10.303Z",
      "publisher": "PRJBLK",
      "title": "myVesta is affected by an authenticated remote code execution vulnerability.",
      "affected": {
        "vendors": [
          "myvesta"
        ],
        "products": [
          {
            "vendor": "myvesta",
            "product": "vesta"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00424,
        "percentile": 0.34912
      },
      "nvd": {
        "published": "2026-07-04T12:16:53.300",
        "lastModified": "2026-07-06T19:43:54.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12195",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The v_ftp_user value reaches a shell command without neutralizing command syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/myvesta/vesta/commit/95d7e43bf286d6881ca753dac93cb42d98cc7422",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://projectblack.io/blog/local-ai-for-cyber-security/#myvesta-authenticated-rce",
          "host": "projectblack.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12196",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-14T07:01:19.115Z",
      "date_published": "2026-07-04T12:05:19.775Z",
      "date_updated": "2026-07-06T13:57:21.795Z",
      "publisher": "PRJBLK",
      "title": "HestiaCP Admin Takeover",
      "affected": {
        "vendors": [
          "hestiacp"
        ],
        "products": [
          {
            "vendor": "hestiacp",
            "product": "hestiacp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17149
      },
      "nvd": {
        "published": "2026-07-04T12:16:53.600",
        "lastModified": "2026-07-06T19:43:54.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12196",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A low-privilege panel user can modify a cron job that invokes passwordless-sudo management scripts with administrator authority.",
        "basis": [
          "CNA record",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hestiacp/hestiacp/pull/5440",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://projectblack.io/blog/hestiacp-admin-takeover-rce/",
          "host": "projectblack.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 310,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12224",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-14T14:48:41.497Z",
      "date_published": "2026-07-01T06:51:06.963Z",
      "date_updated": "2026-07-01T10:32:04.874Z",
      "publisher": "Wordfence",
      "title": "Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint",
      "affected": {
        "vendors": [
          "wedevs"
        ],
        "products": [
          {
            "vendor": "wedevs",
            "product": "Dokan Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15011
      },
      "nvd": {
        "published": "2026-07-01T08:16:20.827",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12224",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The REST handler accepts arbitrary capability strings from a vendor and passes them to add_cap without an administrative capability allowlist.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6ff9c202-b3e8-4660-8763-a9fee468203e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://dokan.co/",
          "host": "dokan.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 696,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12228",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-14T20:13:15.214Z",
      "date_published": "2026-07-18T20:36:36.906Z",
      "date_updated": "2026-07-20T15:12:16.917Z",
      "publisher": "@huntr_ai",
      "title": "Stored XSS in Direct Messages via Prompt Sharing in parisneo/lollms",
      "affected": {
        "vendors": [
          "parisneo"
        ],
        "products": [
          {
            "vendor": "parisneo",
            "product": "parisneo/lollms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security@huntr.dev",
          "type": "Secondary",
          "version": "3.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17712
      },
      "nvd": {
        "published": "2026-07-18T21:17:03.040",
        "lastModified": "2026-07-23T18:24:39.053",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12228",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The prompt-sharing view renders stored prompt_content through v-html after a sanitizer that does not neutralize all executable markup.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://huntr.com/bounties/25623635-5ceb-4062-8289-02089e6d97c1",
          "host": "huntr.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 886,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12250",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T08:02:29.252Z",
      "date_published": "2026-07-05T14:27:28.637Z",
      "date_updated": "2026-07-06T13:25:48.493Z",
      "publisher": "TR-CERT",
      "title": "Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner",
      "affected": {
        "vendors": [
          "TUBITAK BILGEM Software Technologies Research Institute"
        ],
        "products": [
          {
            "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
            "product": "Pardus Domain Joiner"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-214",
          "name": "Invocation of Process Using Visible Sensitive Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01288
      },
      "nvd": {
        "published": "2026-07-05T15:16:56.247",
        "lastModified": "2026-07-06T18:16:45.163",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12250",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pardus Domain Joiner passes sensitive values in process invocation arguments that other local observers can inspect.",
        "basis": [
          "CNA",
          "CWE-214"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0498",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T08:27:12.663Z",
      "date_published": "2026-07-31T06:00:10.354Z",
      "date_updated": "2026-07-31T16:55:03.841Z",
      "publisher": "WPScan",
      "title": "Ultimate Member < 2.12.1 - Unauthenticated Privilege Escalation via Role Selection Field",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Ultimate Member"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13435
      },
      "nvd": {
        "published": "2026-07-31T07:16:23.240",
        "lastModified": "2026-07-31T18:17:09.777",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12251",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The registration form can assign a site-defined role carrying administrator capabilities because administrator-level capabilities are not filtered and the post-registration safeguard is disabled by default.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/dd394110-cf3c-4158-8b50-7abb8a23a2be/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 484,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T08:33:00.274Z",
      "date_published": "2026-07-04T00:58:58.930Z",
      "date_updated": "2026-07-06T18:33:11.411Z",
      "publisher": "@huntr_ai",
      "title": "Untrusted JAR Code Execution in Multiple Stanford Interface Classes in nltk/nltk",
      "affected": {
        "vendors": [
          "nltk"
        ],
        "products": [
          {
            "vendor": "nltk",
            "product": "nltk/nltk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@huntr.dev",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09388
      },
      "nvd": {
        "published": "2026-07-04T02:16:23.603",
        "lastModified": "2026-07-08T15:01:20.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-12252",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Five Stanford interface classes execute caller-selected JAR paths through java() without verifying artifact integrity or provenance.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://huntr.com/bounties/f5c93982-0cc9-4e2e-bb85-1b6ab29a2efb",
          "host": "huntr.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 665,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12255",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T08:48:55.176Z",
      "date_published": "2026-07-27T06:00:01.619Z",
      "date_updated": "2026-07-27T15:50:54.586Z",
      "publisher": "WPScan",
      "title": "MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "MainWP Child"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19655
      },
      "nvd": {
        "published": "2026-07-27T07:16:24.283",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12255",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MainWP Child registration handler accepts a named login without verifying the requester when password authentication is disabled, issuing a session for that account.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/6ecd37bf-f48a-4f7f-8a93-e7f0475371af/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 379,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12257",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T09:03:20.490Z",
      "date_published": "2026-07-13T11:29:59.542Z",
      "date_updated": "2026-07-13T13:06:34.313Z",
      "publisher": "INCIBE",
      "title": "Remote code execution in Mura Software’s CMS",
      "affected": {
        "vendors": [
          "Mura Software"
        ],
        "products": [
          {
            "vendor": "Mura Software",
            "product": "CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00411,
        "percentile": 0.33784
      },
      "nvd": {
        "published": "2026-07-13T12:16:29.150",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12257",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A request method parameter reaches CFML or Java object invocation and permits attacker-selected code behavior.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/remote-code-execution-mura-softwares-cms",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12270",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T11:00:01.358Z",
      "date_published": "2026-07-09T06:00:02.670Z",
      "date_updated": "2026-07-09T14:45:23.443Z",
      "publisher": "WPScan",
      "title": "Everest Forms < 3.5.0 - Unauthenticated Missing Authorization via Site Assistant REST Endpoints",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Everest Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07604
      },
      "nvd": {
        "published": "2026-07-09T07:16:23.210",
        "lastModified": "2026-07-09T16:34:18.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12270",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Everest Forms operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/30813664-2af7-45da-b37c-3d573bc80bd9/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12271",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T11:01:00.374Z",
      "date_published": "2026-07-13T06:00:01.994Z",
      "date_updated": "2026-07-13T15:49:18.088Z",
      "publisher": "WPScan",
      "title": "Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Tutor LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06616
      },
      "nvd": {
        "published": "2026-07-13T07:16:27.620",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12271",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tutor LMS writes to a quiz attempt selected by the caller without verifying that the attempt belongs to that caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/ca99ea35-4bf8-4dc8-a817-79fb9fa1c5bd/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12273",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T11:20:18.693Z",
      "date_published": "2026-07-13T06:00:02.180Z",
      "date_updated": "2026-07-13T15:51:16.393Z",
      "publisher": "WPScan",
      "title": "Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Tutor LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06654
      },
      "nvd": {
        "published": "2026-07-13T07:16:27.733",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12273",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and above to post auto-approved comments containing arbitrary HTML and links on any content across the site, bypassing the comment moderation queue.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/93031a51-fd53-48a0-a420-0024bbdaf45b/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 400,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12274",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T11:20:21.197Z",
      "date_published": "2026-07-13T06:00:02.352Z",
      "date_updated": "2026-07-13T15:48:20.554Z",
      "publisher": "WPScan",
      "title": "Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Tutor LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08261
      },
      "nvd": {
        "published": "2026-07-13T07:16:27.830",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12274",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A Tutor LMS save handler authorizes an unrelated identifier instead of checking whether the instructor may edit the target post.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/c3d98ead-a4f4-48fd-bf9c-4fa91c5681d7/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 404,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12275",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T11:20:23.214Z",
      "date_published": "2026-07-13T06:00:02.528Z",
      "date_updated": "2026-07-13T15:46:49.109Z",
      "publisher": "WPScan",
      "title": "Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Tutor LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06742
      },
      "nvd": {
        "published": "2026-07-13T07:16:27.923",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12275",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Droip and Kirki integrations omit the enrollment, purchase, and private-course checks used by the core course handler.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/fcd43a87-8721-4455-b014-ac81d53fc671/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 460,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12276",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T11:20:40.470Z",
      "date_published": "2026-07-10T06:00:01.974Z",
      "date_updated": "2026-07-10T11:35:01.651Z",
      "publisher": "WPScan",
      "title": "LA-Studio Element Kit for Elementor < 1.6.1 - Unauthenticated Open Registration",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "LA-Studio Element Kit for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.07958
      },
      "nvd": {
        "published": "2026-07-10T07:16:28.203",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12276",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The registration AJAX action creates a WordPress account even when site registration is disabled, bypassing the policy that should gate account creation.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/0c77a001-2773-4727-a873-848f5670fb96/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12277",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T11:46:11.509Z",
      "date_published": "2026-07-07T06:00:01.546Z",
      "date_updated": "2026-07-07T15:31:55.354Z",
      "publisher": "WPScan",
      "title": "Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletion via Saved File Metadata Path Traversal",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Frontend File Manager Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20952
      },
      "nvd": {
        "published": "2026-07-07T06:16:21.893",
        "lastModified": "2026-07-07T16:16:37.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12277",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled path or reference can select a file outside the intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/30f208f6-9d7b-4aaf-8689-496521d1a1dc/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12281",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T12:45:00.391Z",
      "date_published": "2026-07-15T06:00:02.460Z",
      "date_updated": "2026-07-15T10:30:29.732Z",
      "publisher": "WPScan",
      "title": "Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Shibboleth"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14039
      },
      "nvd": {
        "published": "2026-07-15T06:16:43.840",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12281",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "When header-identity mode has no anti-spoofing key, Shibboleth trusts client-supplied identity headers as an authenticated session instead of failing closed.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/8474eda4-6385-447a-9139-f57c049d1713/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 747,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12283",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T13:56:10.694Z",
      "date_published": "2026-07-17T19:05:04.209Z",
      "date_updated": "2026-07-17T19:43:21.238Z",
      "publisher": "AMZN",
      "title": "SQL injection in Amazon Athena Synapse connector",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "aws-athena-query-federation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35585
      },
      "nvd": {
        "published": "2026-07-17T20:17:14.007",
        "lastModified": "2026-07-20T17:14:58.043",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12283",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Synapse connector places a crafted table name into an SQL query without safe identifier handling.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/awslabs/aws-athena-query-federation/releases/tag/v2026.21.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-059-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/awslabs/aws-athena-query-federation/security/advisories/GHSA-43cr-4635-mfjp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12341",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T16:30:50.611Z",
      "date_published": "2026-07-20T18:22:36.997Z",
      "date_updated": "2026-07-21T12:32:33.109Z",
      "publisher": "SailPoint",
      "title": "SailPoint IdentityIQ Improper Bearer Token Validation Vulnerability",
      "affected": {
        "vendors": [
          "SailPoint Technologies"
        ],
        "products": [
          {
            "vendor": "SailPoint Technologies",
            "product": "IdentityIQ"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@sailpoint.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12159
      },
      "nvd": {
        "published": "2026-07-20T19:17:18.027",
        "lastModified": "2026-07-30T16:40:45.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-12341",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "IdentityIQ accepts an OAuth bearer token that has not passed the required validation, but the vendor does not disclose which token property or verification step fails.",
        "basis": [
          "CNA",
          "CWE-287",
          "SailPoint advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.sailpoint.com/security-advisories/sailpoint-identityiq-improper-bearer-token-validation-vulnerability-cve-2026-12341; the advisory confirms bearer-token validation failure and affected releases but does not disclose the rejected token property or a public patch."
      },
      "references": [
        {
          "url": "https://www.sailpoint.com/security-advisories/",
          "host": "www.sailpoint.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-12352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T21:08:54.168Z",
      "date_published": "2026-07-07T14:31:08.550Z",
      "date_updated": "2026-07-13T16:21:10.700Z",
      "publisher": "Digi",
      "title": "Incorrect Authorization",
      "affected": {
        "vendors": [
          "Digi International"
        ],
        "products": [
          {
            "vendor": "Digi International",
            "product": "PortServer TS 1/2/4"
          },
          {
            "vendor": "Digi International",
            "product": "Digi One SP / SP IA / IA"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:e8a6bb0b-e373-42b1-a5de-93e314325576",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17522
      },
      "nvd": {
        "published": "2026-07-07T15:16:42.283",
        "lastModified": "2026-07-13T17:16:46.307",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12352",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A remote unauthenticated caller can reach restricted device resources, but the public record does not identify the missing or incorrect authorization decision.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.digi.com/resources/security",
          "host": "www.digi.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "mitigation",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-12353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T21:27:58.344Z",
      "date_published": "2026-07-23T19:10:58.757Z",
      "date_updated": "2026-07-24T22:05:19.900Z",
      "publisher": "redhat",
      "title": "Rhcs: memory leak during https connection leads to denial of service",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Certificate System 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-772",
          "name": "Missing Release of Resource after Effective Lifetime",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17392
      },
      "nvd": {
        "published": "2026-07-23T20:17:07.077",
        "lastModified": "2026-07-24T23:16:49.730",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12353",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Red Hat Certificate System 9 error path does not release a resource after use, so repeated requests exhaust the available pool.",
        "basis": [
          "CNA",
          "CWE-772"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12353",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489056",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-12357",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:03:12.917Z",
      "date_published": "2026-07-29T19:04:58.457Z",
      "date_updated": "2026-07-29T19:35:52.202Z",
      "publisher": "zdi",
      "title": "Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Heimdall Data"
        ],
        "products": [
          {
            "vendor": "Heimdall Data",
            "product": "Database Proxy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01089,
        "percentile": 0.62087
      },
      "nvd": {
        "published": "2026-07-29T20:17:00.270",
        "lastModified": "2026-07-30T14:19:24.857",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12357",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "generateFileContent accepts carriage-return and line-feed sequences that alter a generated control file and lead to command execution.",
        "basis": [
          "CNA",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-447/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12374",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T07:28:42.180Z",
      "date_published": "2026-07-01T14:07:28.896Z",
      "date_updated": "2026-07-01T15:07:24.153Z",
      "publisher": "Cato",
      "title": "Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool",
      "affected": {
        "vendors": [
          "Cato Networks"
        ],
        "products": [
          {
            "vendor": "Cato Networks",
            "product": "SDP Client"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/AU:Y/R:U/V:C/RE:L/U:Amber"
        },
        {
          "source": "NVD:2505284f-8ffb-486c-bf60-e19c1097a90b",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:Amber"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00055,
        "percentile": 0.00005
      },
      "nvd": {
        "published": "2026-07-01T15:16:27.100",
        "lastModified": "2026-07-02T17:44:12.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12374",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The XPC service accepts a self-signed caller certificate as trusted before a later symlink swap redirects its privileged package operation.",
        "basis": [
          "CNA",
          "CWE-295",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.catonetworks.com/hc/en-us/articles/37284626576413-Security-Vulnerability-CVE-2026-12374-that-Impacts-macOS-Client-Versions-Lower-than-5-13-1",
          "host": "support.catonetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 356,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12375",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T07:48:21.773Z",
      "date_published": "2026-07-07T06:00:01.724Z",
      "date_updated": "2026-07-07T13:15:21.512Z",
      "publisher": "WPScan",
      "title": "Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "uncanny-automator-pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-912",
          "name": "Hidden Functionality",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22642
      },
      "nvd": {
        "published": "2026-07-07T06:16:22.003",
        "lastModified": "2026-07-07T14:16:28.297",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12375",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "uncanny-automator-pro trusted a compromised vendor distribution channel and installed malicious update content without an independent integrity boundary that rejected it.",
        "basis": [
          "CNA",
          "CWE-912"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/ddc83705-3df6-427c-957b-935135330f73/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12376",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T08:32:05.603Z",
      "date_published": "2026-07-31T06:00:11.328Z",
      "date_updated": "2026-07-31T17:43:31.961Z",
      "publisher": "WPScan",
      "title": "Academy LMS <= 3.8.2 - Subscriber+ Sensitive Information Disclosure via quiz_attempts REST Endpoint",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Academy LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05823
      },
      "nvd": {
        "published": "2026-07-31T07:16:23.633",
        "lastModified": "2026-07-31T18:17:09.967",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12376",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The quiz-attempt endpoint checks that the caller is enrolled somewhere but does not bind the requested attempt record to its owner.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/8cdd6ab6-d523-4406-a0ef-d9b3b27e10c8/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T08:51:08.047Z",
      "date_published": "2026-07-08T06:00:01.683Z",
      "date_updated": "2026-07-08T10:04:03.242Z",
      "publisher": "WPScan",
      "title": "BookingPress <= 1.1.28 - Unauthenticated PHP Object Injection",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Appointment Booking Calendar Plugin and Scheduling Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31661
      },
      "nvd": {
        "published": "2026-07-08T07:16:46.550",
        "lastModified": "2026-07-08T14:56:35.950",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12378",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Appointment Booking Calendar Plugin and Scheduling Plugin deserializes attacker-controlled data without restricting the object types or state that the serialized stream may construct.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/eb3abb88-43c3-42a8-a8a8-2ad67d37e020/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12379",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T09:08:08.138Z",
      "date_published": "2026-07-16T15:32:44.883Z",
      "date_updated": "2026-07-16T15:58:57.361Z",
      "publisher": "TQtC",
      "title": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Dashboard OAuth/OIDC implementation of Axivion",
      "affected": {
        "vendors": [
          "Qt"
        ],
        "products": [
          {
            "vendor": "Qt",
            "product": "Axivion"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/RE:M"
        },
        {
          "source": "NVD:a59d8014-47c4-4630-ab43-e1b13cbe58e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04008
      },
      "nvd": {
        "published": "2026-07-16T16:18:59.320",
        "lastModified": "2026-07-16T17:47:59.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12379",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OAuth completion flow accepts a post-authentication redirect outside the Dashboard origin and sends an authenticated user to an attacker-selected site.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wiki.qt.io/List_of_known_vulnerabilities_in_Qt_products#CVE-2026-12379",
          "host": "wiki.qt.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 639,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-12382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T10:07:17.206Z",
      "date_published": "2026-07-15T17:21:28.516Z",
      "date_updated": "2026-07-21T04:16:26.499Z",
      "publisher": "redhat",
      "title": "Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2.6 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2.6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2.7"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29303
      },
      "nvd": {
        "published": "2026-07-15T18:16:44.307",
        "lastModified": "2026-07-21T05:16:33.730",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12382",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The non-mTLS proxy route preserves a client-supplied Subject header and trusts it as the certificate identity.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13508",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:13545",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42142",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12382",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489126",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 444,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-12383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T10:07:26.251Z",
      "date_published": "2026-07-27T19:12:29.271Z",
      "date_updated": "2026-07-27T19:32:02.421Z",
      "publisher": "redhat",
      "title": "Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02828
      },
      "nvd": {
        "published": "2026-07-27T19:17:14.820",
        "lastModified": "2026-07-27T20:37:16.927",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12383",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The EDA external-event endpoint allows anonymous requests and trusts a caller-supplied Subject header as identity without requiring a trusted proxy to set it.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12383",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489127",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 604,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-12385",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T10:47:44.466Z",
      "date_published": "2026-07-13T19:33:56.776Z",
      "date_updated": "2026-07-14T14:31:24.365Z",
      "publisher": "Wordfence",
      "title": "Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter",
      "affected": {
        "vendors": [
          "nextendweb"
        ],
        "products": [
          {
            "vendor": "nextendweb",
            "product": "Smart Slider 3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15493
      },
      "nvd": {
        "published": "2026-07-13T20:16:42.387",
        "lastModified": "2026-07-14T15:16:56.723",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12385",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A contributor-accessible nonce authorizes a keyword query that is not constrained to posts the caller may view, exposing private and draft content.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a782d975-74ce-4265-9312-435b3585a5c6?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/smart-slider-3/tags/3.5.1.37/Nextend/Framework/Content/WordPress/WordPressContent.php#L45",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/smart-slider-3/tags/3.5.1.37/Nextend/Framework/Content/WordPress/WordPressContent.php#L20",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/smart-slider-3/tags/3.5.1.37/Nextend/Framework/Content/ControllerAjaxContent.php#L22",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/smart-slider-3/tags/3.5.1.37/Nextend/Framework/Content/ControllerAjaxContent.php#L15",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/smart-slider-3/tags/3.5.1.37/Nextend/Framework/Form/WordPress/PlatformForm.php#L22",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3599123/smart-slider-3",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 631,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12386",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T11:12:47.226Z",
      "date_published": "2026-07-05T14:31:47.467Z",
      "date_updated": "2026-07-06T13:25:28.190Z",
      "publisher": "TR-CERT",
      "title": "Buffer Overflow in TUBITAK BILGEM's Pardus Pen",
      "affected": {
        "vendors": [
          "TUBITAK BILGEM Software Technologies Research Institute"
        ],
        "products": [
          {
            "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
            "product": "Pardus Pen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-170",
          "name": "Improper Null Termination",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00096,
        "percentile": 0.0083
      },
      "nvd": {
        "published": "2026-07-05T15:16:56.373",
        "lastModified": "2026-07-06T18:16:45.163",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12386",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Overflow Buffers.",
        "basis": [
          "CNA",
          "CWE-170"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0499",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T12:15:12.153Z",
      "date_published": "2026-07-16T12:17:01.094Z",
      "date_updated": "2026-07-16T13:28:19.156Z",
      "publisher": "canonical",
      "title": "ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs",
      "affected": {
        "vendors": [
          "Canonical"
        ],
        "products": [
          {
            "vendor": "Canonical",
            "product": "ubuntu-pro-client (ubuntu-advantage-tools)"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 26.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 24.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 22.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 20.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 18.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 16.04 LTS"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@ubuntu.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05512
      },
      "nvd": {
        "published": "2026-07-16T13:16:24.930",
        "lastModified": "2026-07-16T14:16:48.203",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12391",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The root-run log collector follows a user-planted symlink at a predictable path and copies the root-readable target into an archive readable by that user.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://ubuntu.com/security/CVE-2026-12391",
          "host": "ubuntu.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1007,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-12393",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T12:26:37.800Z",
      "date_published": "2026-07-17T06:00:02.421Z",
      "date_updated": "2026-07-17T12:59:17.081Z",
      "publisher": "WPScan",
      "title": "WPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order Cancellation via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WPS Bookings for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06618
      },
      "nvd": {
        "published": "2026-07-17T07:16:38.023",
        "lastModified": "2026-07-17T15:44:29.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12393",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e2088a99-cde1-4c67-91c7-ddb60da11985/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T12:41:46.553Z",
      "date_published": "2026-07-27T06:00:01.817Z",
      "date_updated": "2026-07-27T15:50:40.270Z",
      "publisher": "WPScan",
      "title": "MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "MemberGlut"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19909
      },
      "nvd": {
        "published": "2026-07-27T07:16:24.383",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12394",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Front-end registration accepts a caller-selected WordPress role without restricting it to roles that anonymous registrants may receive.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/6b126a3e-30d5-4bed-ba47-33e589ec2852/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T13:12:32.338Z",
      "date_published": "2026-07-16T06:00:03.242Z",
      "date_updated": "2026-07-16T15:33:42.799Z",
      "publisher": "WPScan",
      "title": "WP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Parameter",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Job Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12552
      },
      "nvd": {
        "published": "2026-07-16T07:16:46.690",
        "lastModified": "2026-07-16T16:18:59.480",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12395",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The applied-resumes ta parameter reaches an SQL query without the required sanitization and escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/0183c669-cb09-4d53-852f-a0a877691d1e/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T13:13:43.958Z",
      "date_published": "2026-07-13T06:00:02.757Z",
      "date_updated": "2026-07-13T15:11:37.263Z",
      "publisher": "WPScan",
      "title": "WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rejection",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Job Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06617
      },
      "nvd": {
        "published": "2026-07-13T07:16:28.017",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12396",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Moderation actions omit the required capability and object-ownership checks.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/13d574ea-84fe-421b-b1e4-23f94e2000d7/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T13:17:20.552Z",
      "date_published": "2026-07-13T06:00:02.978Z",
      "date_updated": "2026-07-13T15:06:41.839Z",
      "publisher": "WPScan",
      "title": "WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Job Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05822
      },
      "nvd": {
        "published": "2026-07-13T07:16:28.113",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12397",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The email lookup accepts a caller-controlled job identifier without binding the associated employer record to the caller.",
        "basis": [
          "CNA record",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/8e797251-2351-4979-a6c1-c05c78622327/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T13:34:11.451Z",
      "date_published": "2026-07-10T07:48:43.100Z",
      "date_updated": "2026-07-14T01:35:43.795Z",
      "publisher": "Wordfence",
      "title": "FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints",
      "affected": {
        "vendors": [
          "priyanshuchaudhary"
        ],
        "products": [
          {
            "vendor": "priyanshuchaudhary",
            "product": "FlowForms – Conversational Form Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18793
      },
      "nvd": {
        "published": "2026-07-10T09:16:52.553",
        "lastModified": "2026-07-14T02:16:52.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12400",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FlowForms – Conversational Form Builder trusts an attacker-supplied object identifier without checking that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7f4e6133-f833-4da2-af4a-e7e7fcedfe3c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/flowforms/tags/1.1.1/includes/class-rest-api.php#L493",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/flowforms/tags/1.1.1/includes/class-rest-api.php#L48",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/flowforms/tags/1.1.1/includes/class-rest-api.php#L562",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/flowforms/tags/1.1.1/includes/class-rest-api.php#L603",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/flowforms/tags/1.1.1/includes/class-rest-api.php#L654",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/flowforms/tags/1.1.1/includes/class-rest-api.php#L694",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3577870%40flowforms&new=3577870%40flowforms",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 517,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12406",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:01:20.960Z",
      "date_published": "2026-07-09T07:55:11.676Z",
      "date_updated": "2026-07-09T14:08:28.882Z",
      "publisher": "Wordfence",
      "title": "User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter",
      "affected": {
        "vendors": [
          "wedevs"
        ],
        "products": [
          {
            "vendor": "wedevs",
            "product": "User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24793
      },
      "nvd": {
        "published": "2026-07-09T08:16:45.850",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12406",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The guest-media deletion action relies on a publicly available nonce and never requires an authenticated user authorized for the media object.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0049583a-0ad3-45e4-a29e-4b8c33d09857?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.7/includes/Ajax/Upload_Ajax.php#L271",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.7/includes/Ajax/Upload_Ajax.php#L257",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.7/includes/Ajax.php#L27",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.7/includes/Frontend.php#L88",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.2/includes/Ajax/Upload_Ajax.php#L271",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.2/includes/Ajax/Upload_Ajax.php#L257",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.2/includes/Ajax.php#L27",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.2/includes/Frontend.php#L88",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3578622%40wp-user-frontend&new=3578622%40wp-user-frontend",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 791,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12408",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:37:03.010Z",
      "date_published": "2026-07-01T07:53:37.500Z",
      "date_updated": "2026-07-01T10:32:04.144Z",
      "publisher": "Wordfence",
      "title": "Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter",
      "affected": {
        "vendors": [
          "rilwis"
        ],
        "products": [
          {
            "vendor": "rilwis",
            "product": "Slim SEO – A Fast & Automated SEO Plugin For WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.1729
      },
      "nvd": {
        "published": "2026-07-01T08:16:20.943",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12408",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The meta-tags endpoint checks only edit_posts and does not bind object.ID to a post the caller may read before returning protected post content.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6e6603a0-8f35-49fb-a517-ba6344538c4d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/slim-seo/tags/4.9.8/src/MetaTags/AI.php#L55",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/slim-seo/tags/4.9.8/src/MetaTags/AI.php#L21",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/slim-seo/tags/4.9.8/src/MetaTags/Data.php#L117",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/slim-seo/tags/4.9.5/src/MetaTags/AI.php#L55",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/slim-seo/tags/4.9.5/src/MetaTags/AI.php#L21",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/slim-seo/tags/4.9.5/src/MetaTags/Data.php#L117",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3576523%40slim-seo&new=3576523%40slim-seo&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1028,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:43:41.329Z",
      "date_published": "2026-07-16T02:30:56.243Z",
      "date_updated": "2026-07-17T12:37:27.474Z",
      "publisher": "Wordfence",
      "title": "Landing Page Builder <= 1.5.3.6 - Cross-Site Request Forgery to ulpb_admin_data AJAX Action",
      "affected": {
        "vendors": [
          "umarbajwa"
        ],
        "products": [
          {
            "vendor": "umarbajwa",
            "product": "Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.0295
      },
      "nvd": {
        "published": "2026-07-16T04:17:14.213",
        "lastModified": "2026-07-17T13:17:55.333",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12409",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ulpb_admin_ajax handler omits nonce validation, so a forged cross-site request inherits an editor or administrator session and mutates arbitrary posts.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a2b2dd36-eca8-4d80-80f5-783f9402dd3c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/page-builder-add/tags/1.5.3.6/admin/classes/ajax-requests-class.php#L111",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/page-builder-add/tags/1.5.3.6/admin/classes/ajax-requests-class.php#L19",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/page-builder-add/tags/1.5.3.5/admin/classes/ajax-requests-class.php#L111",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/page-builder-add/tags/1.5.3.5/admin/classes/ajax-requests-class.php#L19",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3444409%40page-builder-add&new=3444409%40page-builder-add",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 823,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12413",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:52:12.674Z",
      "date_published": "2026-07-02T21:19:22.177Z",
      "date_updated": "2026-07-07T17:02:12.976Z",
      "publisher": "libreswan",
      "title": "IKEv2 Denial of Service via malformed fragmentation",
      "affected": {
        "vendors": [
          "The Libreswan Project"
        ],
        "products": [
          {
            "vendor": "The Libreswan Project",
            "product": "libreswan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-193",
          "name": "Off-by-one Error",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:d42dc95b-23f1-4e06-9076-20753a0fb0df",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00598,
        "percentile": 0.45266
      },
      "nvd": {
        "published": "2026-07-02T22:16:42.517",
        "lastModified": "2026-07-08T18:52:42.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-12413",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "reassemble_v2_incoming_fragments stores unknown outer payloads and uses an off-by-one assertion boundary, allowing malformed fragmentation to reach a fatal assertion.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-193",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://libreswan.org/security/CVE-2026-12413/CVE-2026-12413.txt",
          "host": "libreswan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://libreswan.org/security/CVE-2026-12413/",
          "host": "libreswan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-12418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:03:46.619Z",
      "date_published": "2026-07-09T07:55:13.665Z",
      "date_updated": "2026-07-09T14:39:37.233Z",
      "publisher": "Wordfence",
      "title": "User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' Parameter",
      "affected": {
        "vendors": [
          "wedevs"
        ],
        "products": [
          {
            "vendor": "wedevs",
            "product": "User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15609
      },
      "nvd": {
        "published": "2026-07-09T08:16:46.000",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12418",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration handler trusts a caller-controlled object identifier without binding it to the caller's permitted objects.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8f66e25f-b67e-4227-95fe-69b40551af61?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.6/includes/Traits/FieldableTrait.php#L478",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.6/includes/Ajax/Frontend_Form_Ajax.php#L35",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.6/includes/Traits/FieldableTrait.php#L468",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.1/includes/Traits/FieldableTrait.php#L478",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.1/includes/Ajax/Frontend_Form_Ajax.php#L35",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-frontend/tags/4.3.1/includes/Traits/FieldableTrait.php#L468",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3578622%40wp-user-frontend&new=3578622%40wp-user-frontend",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 739,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12421",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:51:47.324Z",
      "date_published": "2026-07-23T06:52:33.047Z",
      "date_updated": "2026-07-23T13:51:55.403Z",
      "publisher": "Wordfence",
      "title": "ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password' Field Values",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "ARforms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08899
      },
      "nvd": {
        "published": "2026-07-23T08:16:23.683",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12421",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A password-field value is persisted and later rendered as executable browser markup without contextual encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/19e48549-8a28-4626-b0b5-b781cd01fa5b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/arforms/trunk/core/helpers/arrecordhelper.php#L704",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 364,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12426",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T17:04:21.226Z",
      "date_published": "2026-07-11T02:31:18.186Z",
      "date_updated": "2026-07-14T14:18:17.164Z",
      "publisher": "Wordfence",
      "title": "Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel",
      "affected": {
        "vendors": [
          "supercleanse"
        ],
        "products": [
          {
            "vendor": "supercleanse",
            "product": "Members – Membership & User Role Editor Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19524
      },
      "nvd": {
        "published": "2026-07-11T04:17:16.503",
        "lastModified": "2026-07-14T15:16:56.847",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12426",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "members_filter_protected_posts_for_rest exposes restricted-post counts and pagination differences that act as a boolean oracle for hidden keywords and content.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9c3557a6-aa72-496c-8515-2f6055de6b22?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/members/tags/3.2.22/inc/functions-content-permissions.php#L337",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/members/tags/3.2.22/inc/functions-private-site.php#L42",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/members/tags/3.2.19/inc/functions-content-permissions.php#L337",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/members/tags/3.2.19/inc/functions-private-site.php#L42",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3594293%40members%2Ftrunk&old=3552545%40members%2Ftrunk&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 471,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T17:09:56.538Z",
      "date_published": "2026-07-09T09:31:23.347Z",
      "date_updated": "2026-07-09T14:39:22.498Z",
      "publisher": "Wordfence",
      "title": "Blocks for ACF Fields <= 1.6.2 - Missing Authorization to Authenticated (Author+) Arbitrary ACF Field Value Disclosure via 'id' Parameter",
      "affected": {
        "vendors": [
          "gamaup"
        ],
        "products": [
          {
            "vendor": "gamaup",
            "product": "Blocks for ACF Fields — Display Custom Fields in the Block Editor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19887
      },
      "nvd": {
        "published": "2026-07-09T11:16:24.550",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12428",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The REST permission callback checks only publish_posts and never verifies that the requested ACF object's values are readable by the caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fc48f75d-a2e8-49ea-9bfa-a27a61ff8a84?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/acf-field-blocks/tags/1.6.0/inc/class-rest.php#L302",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/acf-field-blocks/tags/1.6.0/inc/class-rest.php#L100",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/acf-field-blocks/tags/1.6.0/inc/class-rest.php#L296",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/acf-field-blocks/tags/1.5.0/inc/class-rest.php#L302",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/acf-field-blocks/tags/1.5.0/inc/class-rest.php#L100",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/acf-field-blocks/tags/1.5.0/inc/class-rest.php#L296",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3587876%40acf-field-blocks&new=3587876%40acf-field-blocks",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 759,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T18:20:28.369Z",
      "date_published": "2026-07-09T08:31:35.571Z",
      "date_updated": "2026-07-09T14:37:17.193Z",
      "publisher": "Wordfence",
      "title": "Hydra Booking <= 1.2.1 - Authenticated (Custom+) Insecure Direct Object Reference to Sensitive Information Exposure via 'booking_id' Parameter",
      "affected": {
        "vendors": [
          "themefic"
        ],
        "products": [
          {
            "vendor": "themefic",
            "product": "Hydra Booking — Appointment Scheduling & Booking Calendar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17801
      },
      "nvd": {
        "published": "2026-07-09T10:16:23.807",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12433",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This is due to the getBookingDetails() callback only enforcing the tfhb_manage_options capability via tfhb_manage_options_permission(), without verifying that the requested booking belongs to the currently authenticated host (the lookup in getBookingDetailsData() filters solely on the booking id supplied in the URL).",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/aa00fe53-dc65-4200-80bb-9167b4230194?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hydra-booking/tags/1.1.44/admin/Controller/BookingController.php#L1418",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hydra-booking/tags/1.1.44/admin/Controller/BookingController.php#L100",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hydra-booking/tags/1.1.44/admin/Controller/RouteController.php#L55",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hydra-booking/tags/1.1.44/includes/hooks/ActivationHooks.php#L38",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hydra-booking/tags/1.1.41/admin/Controller/BookingController.php#L1418",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hydra-booking/tags/1.1.41/admin/Controller/BookingController.php#L100",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hydra-booking/tags/1.1.41/admin/Controller/RouteController.php#L55",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hydra-booking/tags/1.1.41/includes/hooks/ActivationHooks.php#L38",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3600170%40hydra-booking&new=3600170%40hydra-booking",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 947,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T18:24:03.282Z",
      "date_published": "2026-07-16T02:30:55.579Z",
      "date_updated": "2026-07-16T13:39:32.157Z",
      "publisher": "Wordfence",
      "title": "List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute",
      "affected": {
        "vendors": [
          "fernandobt"
        ],
        "products": [
          {
            "vendor": "fernandobt",
            "product": "List category posts"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15016
      },
      "nvd": {
        "published": "2026-07-16T04:17:15.847",
        "lastModified": "2026-07-16T14:16:48.360",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12434",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The catlist shortcode accepts a post_status value that exposes other users pending, scheduled, and trashed posts to a contributor.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3477baf1-71ef-44f3-938f-3e7d710e9df6?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/list-category-posts/tags/0.95.0/include/lcp-catlist.php#L623",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/list-category-posts/tags/0.95.0/include/lcp-catlist.php#L94",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/list-category-posts/tags/0.95.0/include/lcp-parameters.php#L208",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/list-category-posts/tags/0.95.0/list-category-posts.php#L184",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3598587%40list-category-posts&new=3598587%40list-category-posts",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T18:34:03.436Z",
      "date_published": "2026-07-01T07:53:36.717Z",
      "date_updated": "2026-07-01T10:32:04.521Z",
      "publisher": "Wordfence",
      "title": "Motors <= 1.4.111 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter",
      "affected": {
        "vendors": [
          "stylemix"
        ],
        "products": [
          {
            "vendor": "stylemix",
            "product": "Motors – Car Dealership & Classified Listings Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14174
      },
      "nvd": {
        "published": "2026-07-01T08:16:21.060",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12435",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A nonce harvested from the attacker's own listing is accepted for another listing because the action never verifies ownership of the supplied post ID.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5238c344-d685-4eab-822c-d3c1050cc982?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.110/includes/vehicle_functions.php#L2402",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.110/includes/vehicle_functions.php#L2400",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.110/templates/listing-cars/listing-list-owner-actions.php#L74",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.108/includes/vehicle_functions.php#L2402",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.108/includes/vehicle_functions.php#L2400",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.108/templates/listing-cars/listing-list-owner-actions.php#L74",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3577332%40motors-car-dealership-classified-listings&new=3577332%40motors-car-dealership-classified-listings&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 913,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T19:08:45.458Z",
      "date_published": "2026-07-29T19:00:36.048Z",
      "date_updated": "2026-07-31T16:10:56.005Z",
      "publisher": "GitLab",
      "title": "Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23324
      },
      "nvd": {
        "published": "2026-07-29T20:17:00.417",
        "lastModified": "2026-08-03T13:42:46.800",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-12436",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GitLab accepts user-controlled pipeline-schedule attributes that mass-assign another user's CI configuration instead of restricting updates to the schedule owner and permitted fields.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/603223",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3800511",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 361,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-12472",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T20:16:45.315Z",
      "date_published": "2026-07-02T08:33:07.265Z",
      "date_updated": "2026-07-02T14:52:43.310Z",
      "publisher": "Wordfence",
      "title": "Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters",
      "affected": {
        "vendors": [
          "themeum"
        ],
        "products": [
          {
            "vendor": "themeum",
            "product": "Kirki – Freeform Page Builder, Website Builder & Customizer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20572
      },
      "nvd": {
        "published": "2026-07-02T10:16:27.653",
        "lastModified": "2026-07-02T15:16:57.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12472",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated mail action can generate attacker-authored HTML messages containing a real reset link because the route lacks the required capability and nonce checks.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/af01964f-018d-4d19-8627-8889877db105?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.9/ComponentLibrary/controller/CompLibFormHandler.php#L342",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.9/ComponentLibrary/controller/CompLibFormHandler.php#L441",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.9/ComponentLibrary/controller/CompLibFormHandler.php#L49",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.9/ComponentLibrary/controller/ElementGenerator.php#L219",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3584702%40kirki&new=3584702%40kirki&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 853,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T20:25:13.528Z",
      "date_published": "2026-07-29T02:31:38.774Z",
      "date_updated": "2026-07-29T12:22:13.311Z",
      "publisher": "Wordfence",
      "title": "Easy Digital Downloads <= 3.6.9 - Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parameter",
      "affected": {
        "vendors": [
          "smub"
        ],
        "products": [
          {
            "vendor": "smub",
            "product": "Easy Digital Downloads – eCommerce Payments and Subscriptions made easy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00629,
        "percentile": 0.46705
      },
      "nvd": {
        "published": "2026-07-29T04:17:06.887",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12476",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The import handler trusts the upload Content-Type header and uses move_uploaded_file without validating the actual type or original extension before writing to a web-accessible directory.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5b0c8edd-b392-4d23-bde3-0521eeedc5a0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-digital-downloads/tags/3.6.8/includes/admin/import/import-functions.php#L92",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-digital-downloads/tags/3.6.8/includes/admin/import/import-functions.php#L68",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-digital-downloads/tags/3.6.8/includes/admin/import/import-functions.php#L87",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-digital-downloads/tags/3.6.7/includes/admin/import/import-functions.php#L92",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-digital-downloads/tags/3.6.7/includes/admin/import/import-functions.php#L68",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-digital-downloads/tags/3.6.7/includes/admin/import/import-functions.php#L87",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3625073/easy-digital-downloads/trunk/includes/admin/import/import-functions.php?old=3577787&old_path=easy-digital-downloads%2Ftrunk%2Fincludes%2Fadmin%2Fimport%2Fimport-functions.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 760,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12478",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:25:02.817Z",
      "date_published": "2026-07-14T09:26:19.184Z",
      "date_updated": "2026-07-15T14:42:55.698Z",
      "publisher": "redhat",
      "title": "Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16277
      },
      "nvd": {
        "published": "2026-07-14T10:16:30.957",
        "lastModified": "2026-07-15T15:16:27.070",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12478",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The overflow guard covers masked WebSocket frames only, so an extreme length on an unmasked frame drives an out-of-bounds read.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12478",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/cve-2026-0716",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489655",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/518",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 369,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-12480",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:57:28.799Z",
      "date_published": "2026-07-01T16:53:32.326Z",
      "date_updated": "2026-07-01T17:46:31.093Z",
      "publisher": "@huntr_ai",
      "title": "Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras",
      "affected": {
        "vendors": [
          "keras-team"
        ],
        "products": [
          {
            "vendor": "keras-team",
            "product": "keras-team/keras"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@huntr.dev",
          "type": "Secondary",
          "version": "3.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02778
      },
      "nvd": {
        "published": "2026-07-01T17:16:19.330",
        "lastModified": "2026-07-02T17:55:37.087",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12480",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Keras fails to reject virtual HDF5 datasets, so a model archive can select an external local HDF5 file that is read during loading.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://huntr.com/bounties/1875d257-5b03-4a69-ac70-e98653fa12c7",
          "host": "huntr.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/keras-team/keras/commit/d5a88bdb137c0d3039b8f4bbbe8c7099925cc10c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 706,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T01:06:48.759Z",
      "date_published": "2026-07-03T20:36:05.003Z",
      "date_updated": "2026-07-06T15:15:46.244Z",
      "publisher": "@huntr_ai",
      "title": "Deserialization of Untrusted Data in keras-team/keras",
      "affected": {
        "vendors": [
          "keras-team"
        ],
        "products": [
          {
            "vendor": "keras-team",
            "product": "keras-team/keras"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@huntr.dev",
          "type": "Secondary",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00467,
        "percentile": 0.38055
      },
      "nvd": {
        "published": "2026-07-03T21:16:54.737",
        "lastModified": "2026-07-08T15:01:47.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-12481",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Lambda deserialization treats an unset safe_mode value as equivalent to explicit disablement and consequently unmarshals attacker-controlled bytecode.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://huntr.com/bounties/59ceaed1-c8a3-4135-8f94-169ade02823d",
          "host": "huntr.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 897,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T01:32:32.655Z",
      "date_published": "2026-07-14T05:13:07.252Z",
      "date_updated": "2026-07-14T12:43:09.817Z",
      "publisher": "@huntr_ai",
      "title": "Path Traversal via Symlink Name Validation Bypass in keras-team/keras",
      "affected": {
        "vendors": [
          "keras-team"
        ],
        "products": [
          {
            "vendor": "keras-team",
            "product": "keras-team/keras"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@huntr.dev",
          "type": "Secondary",
          "version": "3.0",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22427
      },
      "nvd": {
        "published": "2026-07-14T06:16:59.527",
        "lastModified": "2026-07-15T20:56:32.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12482",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The tar filter validates regular members but lets a symlink name escape the intended extraction directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://huntr.com/bounties/5d3638e8-a9f6-4964-a865-ddb9fe4d4b6e",
          "host": "huntr.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 692,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12484",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T02:52:42.641Z",
      "date_published": "2026-07-19T19:47:27.743Z",
      "date_updated": "2026-07-20T13:45:55.809Z",
      "publisher": "@huntr_ai",
      "title": "Unsafe Deserialization in keras.layers.TorchModuleWrapper.from_config",
      "affected": {
        "vendors": [
          "keras-team"
        ],
        "products": [
          {
            "vendor": "keras-team",
            "product": "keras-team/keras"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@huntr.dev",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10563
      },
      "nvd": {
        "published": "2026-07-19T20:16:28.800",
        "lastModified": "2026-07-23T18:24:39.053",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12484",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TorchModuleWrapper.from_config loads attacker-controlled PyTorch pickle data with unsafe deserialization enabled by default.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://huntr.com/bounties/ab14df49-13b5-4442-b754-3189430bfa28",
          "host": "huntr.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 735,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T08:25:07.733Z",
      "date_published": "2026-07-16T06:00:03.419Z",
      "date_updated": "2026-07-16T15:33:35.211Z",
      "publisher": "WPScan",
      "title": "Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_user",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Happy Coders OTP Login for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.2218
      },
      "nvd": {
        "published": "2026-07-16T07:16:46.787",
        "lastModified": "2026-07-16T16:18:59.617",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12492",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/56fdcba6-c7b1-443d-9f9d-b738ecaadabc/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 323,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12493",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T08:29:49.750Z",
      "date_published": "2026-07-27T06:00:02.019Z",
      "date_updated": "2026-07-27T16:24:35.457Z",
      "publisher": "WPScan",
      "title": "Clover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated Payment Bypass via check_order",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Clover Payment Gateway by Zaytech for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11099
      },
      "nvd": {
        "published": "2026-07-27T07:16:24.480",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12493",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Clover Payment Gateway by Zaytech for WooCommerce fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/b9f3f6d8-b56f-4d0e-9102-c69e6756ab74/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 432,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12495",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T08:53:55.157Z",
      "date_published": "2026-07-27T10:32:19.167Z",
      "date_updated": "2026-07-28T06:49:36.326Z",
      "publisher": "INCIBE",
      "title": "Stack-Based Buffer Overflow in the Mercusys MB115-4G",
      "affected": {
        "vendors": [
          "Mercusys"
        ],
        "products": [
          {
            "vendor": "Mercusys",
            "product": "MB115-4G"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05897
      },
      "nvd": {
        "published": "2026-07-27T12:16:41.027",
        "lastModified": "2026-07-28T08:17:14.187",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12495",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted unauthenticated login request exceeds a stack buffer in http_gdpr_decrypt and corrupts the httpd process.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/stack-based-buffer-overflow-mercusys-mb115-4g",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T08:57:07.049Z",
      "date_published": "2026-07-24T13:57:24.818Z",
      "date_updated": "2026-07-24T15:01:17.030Z",
      "publisher": "NCSC.ch",
      "title": "Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server",
      "affected": {
        "vendors": [
          "Loytec"
        ],
        "products": [
          {
            "vendor": "Loytec",
            "product": "LIP-ME20xC"
          },
          {
            "vendor": "Loytec",
            "product": "L-INX"
          },
          {
            "vendor": "Loytec",
            "product": "L-GATE"
          },
          {
            "vendor": "Loytec",
            "product": "L-ROC"
          },
          {
            "vendor": "Loytec",
            "product": "L-IOB"
          },
          {
            "vendor": "Loytec",
            "product": "L-DALI"
          },
          {
            "vendor": "Loytec",
            "product": "L-VIS"
          },
          {
            "vendor": "Loytec",
            "product": "L-PAD"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00358,
        "percentile": 0.28474
      },
      "nvd": {
        "published": "2026-07-24T15:17:08.663",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12496",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LIP-ME20xC stores attacker-controlled content and later renders it without sufficient output escaping, allowing script execution in a visitor's browser.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.loytec.com/support/product-security/advisories/8522-dibt-cve-20260526-0004-unauthenticated-stored-xxs-in-opc-xml-da-server-statistics-high",
          "host": "www.loytec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-12497",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T08:57:49.902Z",
      "date_published": "2026-07-24T06:00:02.334Z",
      "date_updated": "2026-07-24T19:42:25.406Z",
      "publisher": "WPScan",
      "title": "ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14169
      },
      "nvd": {
        "published": "2026-07-24T07:16:32.350",
        "lastModified": "2026-07-24T20:48:39.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12497",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Different parsers define offered and accepted registration roles, causing the handler to fall back to accepting any non-administrator role.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/bfb14acb-051c-4bcb-adfc-10a27a00dfe7/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 754,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12500",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T09:09:55.183Z",
      "date_published": "2026-07-30T06:00:10.590Z",
      "date_updated": "2026-07-30T17:02:51.881Z",
      "publisher": "WPScan",
      "title": "WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Travel Engine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16837
      },
      "nvd": {
        "published": "2026-07-30T06:24:58.553",
        "lastModified": "2026-07-30T19:17:04.677",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12500",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An AJAX option-update action accepts a public nonce but performs no capability check before changing a site-wide setting.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/10b52de8-c1a8-4b58-9445-737d43033704/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 361,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12502",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T09:48:08.859Z",
      "date_published": "2026-07-24T13:57:44.001Z",
      "date_updated": "2026-07-24T14:58:22.991Z",
      "publisher": "NCSC.ch",
      "title": "Loytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudo",
      "affected": {
        "vendors": [
          "Loytec"
        ],
        "products": [
          {
            "vendor": "Loytec",
            "product": "LIP-ME20xC"
          },
          {
            "vendor": "Loytec",
            "product": "L-INX"
          },
          {
            "vendor": "Loytec",
            "product": "L-GATE"
          },
          {
            "vendor": "Loytec",
            "product": "L-ROC"
          },
          {
            "vendor": "Loytec",
            "product": "L-IOB"
          },
          {
            "vendor": "Loytec",
            "product": "L-DALI"
          },
          {
            "vendor": "Loytec",
            "product": "L-VIS"
          },
          {
            "vendor": "Loytec",
            "product": "L-PAD"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01268
      },
      "nvd": {
        "published": "2026-07-24T15:17:10.860",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12502",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ltsudo allows a lower administrative role to invoke a password-reset operation for accounts outside that role's intended authority.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.loytec.com/support/product-security/advisories/8519-dibt-cve-20260526-0001-unrestricted-service-account-password-reset-high",
          "host": "www.loytec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 313,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-12503",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T09:48:11.206Z",
      "date_published": "2026-07-24T13:57:56.691Z",
      "date_updated": "2026-07-24T14:57:47.202Z",
      "publisher": "NCSC.ch",
      "title": "Loytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter",
      "affected": {
        "vendors": [
          "Loytec"
        ],
        "products": [
          {
            "vendor": "Loytec",
            "product": "LIP-ME20xC"
          },
          {
            "vendor": "Loytec",
            "product": "L-INX"
          },
          {
            "vendor": "Loytec",
            "product": "L-GATE"
          },
          {
            "vendor": "Loytec",
            "product": "L-ROC"
          },
          {
            "vendor": "Loytec",
            "product": "L-IOB"
          },
          {
            "vendor": "Loytec",
            "product": "L-DALI"
          },
          {
            "vendor": "Loytec",
            "product": "L-VIS"
          },
          {
            "vendor": "Loytec",
            "product": "L-PAD"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03451
      },
      "nvd": {
        "published": "2026-07-24T15:17:10.997",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12503",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on `/etc/lighttpd/ssl/server.pem`.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.loytec.com/support/product-security/advisories/8520-dibt-cve-20260526-0002-symlink-following-in-chown-chmod-critical",
          "host": "www.loytec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-12504",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T09:48:17.638Z",
      "date_published": "2026-07-24T13:58:16.232Z",
      "date_updated": "2026-07-24T14:57:20.563Z",
      "publisher": "NCSC.ch",
      "title": "Loytec LINX firmware: Improper Authentication in PAM configuration",
      "affected": {
        "vendors": [
          "Loytec"
        ],
        "products": [
          {
            "vendor": "Loytec",
            "product": "LIP-ME20xC"
          },
          {
            "vendor": "Loytec",
            "product": "L-INX"
          },
          {
            "vendor": "Loytec",
            "product": "L-GATE"
          },
          {
            "vendor": "Loytec",
            "product": "L-ROC"
          },
          {
            "vendor": "Loytec",
            "product": "L-IOB"
          },
          {
            "vendor": "Loytec",
            "product": "L-DALI"
          },
          {
            "vendor": "Loytec",
            "product": "L-VIS"
          },
          {
            "vendor": "Loytec",
            "product": "L-PAD"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-521",
          "name": "Weak Password Requirements",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02924
      },
      "nvd": {
        "published": "2026-07-24T15:17:11.157",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12504",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PAM configuration accepts a UID-zero account whose password field is empty.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-521"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.loytec.com/support/product-security/advisories/8521-dibt-cve-20260526-0003-pam-passwordless-uid-0-authentication-high",
          "host": "www.loytec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-12510",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T11:39:09.525Z",
      "date_published": "2026-07-16T06:00:03.590Z",
      "date_updated": "2026-07-16T15:33:27.561Z",
      "publisher": "WPScan",
      "title": "AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "AI Engine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04262
      },
      "nvd": {
        "published": "2026-07-16T07:16:46.877",
        "lastModified": "2026-07-16T16:18:59.750",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12510",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/b7825c8a-1817-4a17-b641-076e48ac7c2e/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12511",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T11:39:11.317Z",
      "date_published": "2026-07-14T06:00:02.489Z",
      "date_updated": "2026-07-14T12:59:54.068Z",
      "publisher": "WPScan",
      "title": "AI Engine < 3.5.5 - Editor+ Arbitrary File Write via Path Traversal",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "AI Engine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22715
      },
      "nvd": {
        "published": "2026-07-14T06:17:05.787",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12511",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled path or object-name data is resolved without proving that the final target remains inside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/cf3cf59e-da36-429b-8794-5a46587e8462/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12512",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T11:59:13.454Z",
      "date_published": "2026-07-15T06:00:02.636Z",
      "date_updated": "2026-07-15T10:29:07.096Z",
      "publisher": "WPScan",
      "title": "Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Quotes llama"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.1876
      },
      "nvd": {
        "published": "2026-07-15T06:16:44.757",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12512",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/39d038f6-f009-4274-a8a7-9d7c2597ec85/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T12:41:37.963Z",
      "date_published": "2026-07-09T06:00:02.880Z",
      "date_updated": "2026-07-09T14:46:12.813Z",
      "publisher": "WPScan",
      "title": "Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Media Proxy",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Fediverse Embeds"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08549
      },
      "nvd": {
        "published": "2026-07-09T07:16:23.303",
        "lastModified": "2026-07-09T16:34:18.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12516",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fediverse Embeds follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/2ac80164-03b7-4966-b022-833b4194de80/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12517",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T12:47:07.188Z",
      "date_published": "2026-07-09T06:00:03.058Z",
      "date_updated": "2026-07-09T12:51:27.261Z",
      "publisher": "WPScan",
      "title": "Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Fediverse Embeds"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08549
      },
      "nvd": {
        "published": "2026-07-09T07:16:23.410",
        "lastModified": "2026-07-09T16:34:18.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12517",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unauthenticated site-info endpoint follows a caller-selected URL without excluding internal destinations and returns parsed metadata.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/460a996f-e27d-47e8-9d68-9e6be93100c0/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12523",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T13:35:37.498Z",
      "date_published": "2026-07-14T15:51:28.886Z",
      "date_updated": "2026-07-15T17:47:52.441Z",
      "publisher": "cloudflare",
      "title": "Resource exhaustion in quiche HTTP/3 and QPACK layers",
      "affected": {
        "vendors": [
          "Cloudflare"
        ],
        "products": [
          {
            "vendor": "Cloudflare",
            "product": "quiche"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@cloudflare.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21444
      },
      "nvd": {
        "published": "2026-07-14T16:16:45.050",
        "lastModified": "2026-07-15T18:16:44.430",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12523",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Attacker-controlled frame lengths trigger large preallocation while QPACK processing lacks effective memory limits.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cloudflare/quiche/security/advisories/GHSA-4fgf-9xrr-88gf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1042,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12525",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T13:40:16.637Z",
      "date_published": "2026-07-16T06:00:03.760Z",
      "date_updated": "2026-07-16T17:04:00.624Z",
      "publisher": "WPScan",
      "title": "Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Redux Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14776
      },
      "nvd": {
        "published": "2026-07-16T07:16:46.987",
        "lastModified": "2026-07-16T18:16:41.633",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12525",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The profile update path lets a subscriber write unrestricted user-meta keys, including the key that determines the administrator role.",
        "basis": [
          "CNA record",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/11d5d4c2-7ba9-4389-9050-28c90920e34b/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 417,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:59:45.420Z",
      "date_published": "2026-07-10T21:43:40.681Z",
      "date_updated": "2026-07-13T18:12:44.956Z",
      "publisher": "drupal",
      "title": "Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Formatter Field"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31395
      },
      "nvd": {
        "published": "2026-07-10T22:16:39.077",
        "lastModified": "2026-07-13T19:16:37.887",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12535",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Formatter Field lets attacker-controlled field names modify dynamically selected object attributes.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-048",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T15:04:47.036Z",
      "date_published": "2026-07-13T19:33:56.237Z",
      "date_updated": "2026-07-14T13:17:51.032Z",
      "publisher": "Wordfence",
      "title": "Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Module Title",
      "affected": {
        "vendors": [
          "themefusion"
        ],
        "products": [
          {
            "vendor": "themefusion",
            "product": "Avada (Fusion) Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06494
      },
      "nvd": {
        "published": "2026-07-13T20:16:42.520",
        "lastModified": "2026-07-14T14:16:32.480",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12536",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The page builder emits attacker-controlled content into HTML without the context-appropriate neutralization required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6199b852-3270-4456-934b-68c3ef11b9e5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://themeforest.net/item/avada-responsive-multipurpose-theme/2833226",
          "host": "themeforest.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12547",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T18:09:30.319Z",
      "date_published": "2026-07-21T18:35:53.214Z",
      "date_updated": "2026-07-21T19:14:49.960Z",
      "publisher": "redhat",
      "title": "Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13608
      },
      "nvd": {
        "published": "2026-07-21T19:17:09.303",
        "lastModified": "2026-07-21T20:16:58.620",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12547",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SoupAuthManager caches proxy credentials without binding them to the proxy host and port, then forwards the prior proxy's credentials after a proxy change.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12547",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489994",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libsoup/-/work_items/506",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-12548",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T18:25:16.477Z",
      "date_published": "2026-07-21T18:40:52.174Z",
      "date_updated": "2026-07-23T14:19:47.210Z",
      "publisher": "redhat",
      "title": "Libsoup: heap out-of-bounds read in libsoup due to integer truncation",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14569
      },
      "nvd": {
        "published": "2026-07-21T19:17:09.440",
        "lastModified": "2026-07-23T15:16:34.480",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12548",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the end of an allocated buffer because the available length is not enforced.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12548",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489996",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libsoup/-/work_items/512",
          "host": "gitlab.gnome.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-12557",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T20:03:34.649Z",
      "date_published": "2026-07-03T04:30:16.018Z",
      "date_updated": "2026-07-06T16:32:44.790Z",
      "publisher": "Wordfence",
      "title": "Ninja Forms - File Uploads <= 3.3.29 - Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST Endpoints",
      "affected": {
        "vendors": [
          "SaturdayDrive"
        ],
        "products": [
          {
            "vendor": "SaturdayDrive",
            "product": "Ninja Forms - File Uploads"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.12997
      },
      "nvd": {
        "published": "2026-07-03T06:16:21.207",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12557",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The debug-log REST endpoints expose read and delete operations without verifying that the caller is authorized.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1a54f8cc-cadb-4496-bcc4-ef8387b72300?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms-uploads/trunk/includes/Common/Routes/DebugLog.php#L88",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 401,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12562",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T20:31:31.583Z",
      "date_published": "2026-07-30T21:29:35.378Z",
      "date_updated": "2026-07-31T15:39:49.359Z",
      "publisher": "icscert",
      "title": "Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical Function",
      "affected": {
        "vendors": [
          "Toptech Systems"
        ],
        "products": [
          {
            "vendor": "Toptech Systems",
            "product": "RCU II+"
          },
          {
            "vendor": "Toptech Systems",
            "product": "Multiload II+"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20057
      },
      "nvd": {
        "published": "2026-07-30T22:16:53.343",
        "lastModified": "2026-07-31T16:16:57.663",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12562",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The RCU II+ path exposes a privileged operation without first authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip",
          "host": "s3.amazonaws.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz",
          "host": "s3.amazonaws.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/",
          "host": "s3.amazonaws.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf",
          "host": "s3.amazonaws.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-03.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 594,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-12575",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T05:22:51.481Z",
      "date_published": "2026-07-01T06:55:18.417Z",
      "date_updated": "2026-07-01T12:22:28.713Z",
      "publisher": "Deltaww",
      "title": "DVP80ES3 Improper Resource Shutdown or Release Vulnerability",
      "affected": {
        "vendors": [
          "deltaww"
        ],
        "products": [
          {
            "vendor": "deltaww",
            "product": "DVP80ES3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:759f5e80-c8e1-4224-bead-956d7b33c98b",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19995
      },
      "nvd": {
        "published": "2026-07-01T08:16:21.177",
        "lastModified": "2026-07-01T15:28:59.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12575",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The product can leave a finite resource unreleased, but the public record does not identify the resource or release path.",
        "basis": [
          "CNA",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00009_DVP80ES3%20Multiple%20Vulnerabilities_v1%20(CVE-2026-12575,%2012576,%2012577).pdf",
          "host": "filecenter.deltaww.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 67,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12576",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T05:22:53.986Z",
      "date_published": "2026-07-01T07:01:17.903Z",
      "date_updated": "2026-07-01T12:21:28.074Z",
      "publisher": "Deltaww",
      "title": "DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability",
      "affected": {
        "vendors": [
          "deltaww"
        ],
        "products": [
          {
            "vendor": "deltaww",
            "product": "DVP80ES3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-924",
          "name": "Improper Enforcement of Message Integrity During Transmission in a Communication Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:759f5e80-c8e1-4224-bead-956d7b33c98b",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.05023
      },
      "nvd": {
        "published": "2026-07-01T08:16:21.277",
        "lastModified": "2026-07-01T15:28:59.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12576",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The DVP80ES3 communication path accepts messages without enforcing the integrity protection required for the channel.",
        "basis": [
          "CNA",
          "CWE-924"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00009_DVP80ES3%20Multiple%20Vulnerabilities_v1%20(CVE-2026-12575,%2012576,%2012577).pdf",
          "host": "filecenter.deltaww.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12577",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T05:22:55.191Z",
      "date_published": "2026-07-01T07:05:25.146Z",
      "date_updated": "2026-07-01T12:35:02.947Z",
      "publisher": "Deltaww",
      "title": "DVP80ES3 Improperly Implemented Security Check for Standard vulnerability",
      "affected": {
        "vendors": [
          "deltaww"
        ],
        "products": [
          {
            "vendor": "deltaww",
            "product": "DVP80ES3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-358",
          "name": "Improperly Implemented Security Check for Standard",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:759f5e80-c8e1-4224-bead-956d7b33c98b",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16741
      },
      "nvd": {
        "published": "2026-07-01T08:16:21.380",
        "lastModified": "2026-07-01T15:28:59.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12577",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record names an improperly implemented standards check but does not disclose the standard, input, comparison, or resulting state transition.",
        "basis": [
          "CNA",
          "CWE-358"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00009_DVP80ES3%20Multiple%20Vulnerabilities_v1%20(CVE-2026-12575,%2012576,%2012577).pdf",
          "host": "filecenter.deltaww.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 79,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12579",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T05:22:59.674Z",
      "date_published": "2026-07-01T05:22:38.951Z",
      "date_updated": "2026-07-01T12:29:19.895Z",
      "publisher": "Deltaww",
      "title": "AS228T - Authentication Bypass Vulnerability",
      "affected": {
        "vendors": [
          "deltaww"
        ],
        "products": [
          {
            "vendor": "deltaww",
            "product": "AS228T"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:759f5e80-c8e1-4224-bead-956d7b33c98b",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19456
      },
      "nvd": {
        "published": "2026-07-01T07:16:22.753",
        "lastModified": "2026-07-01T15:28:59.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12579",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record names an authentication bypass in AS228T without identifying the alternate path, credential, session, or validation check that accepts the caller.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00012_AS228T%20Authentication%20Bypass%20Vulnerability%20(CVE-2026-12579).pdf",
          "host": "filecenter.deltaww.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 47,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12582",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T07:03:51.299Z",
      "date_published": "2026-07-13T06:00:03.229Z",
      "date_updated": "2026-07-13T14:51:37.360Z",
      "publisher": "WPScan",
      "title": "Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Library Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17919
      },
      "nvd": {
        "published": "2026-07-13T07:16:28.203",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12582",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database, including user password hashes.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/762dd8c3-8972-46ef-90c2-9f3f5dce4370/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12583",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T07:06:08.362Z",
      "date_published": "2026-07-14T06:00:02.660Z",
      "date_updated": "2026-07-14T12:28:44.066Z",
      "publisher": "WPScan",
      "title": "Newsletters < 4.15 - Unauthenticated PHP Object Injection via Subscriber Custom Field",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Newsletters"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25084
      },
      "nvd": {
        "published": "2026-07-14T06:17:05.900",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12583",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A public form stores attacker-controlled serialized PHP data that is later instantiated with a bundled file-writing gadget chain.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e4c44105-f43d-4dff-8487-7d8ae2691c4e/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12585",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T07:06:18.053Z",
      "date_published": "2026-07-16T06:00:03.930Z",
      "date_updated": "2026-07-16T16:57:01.246Z",
      "publisher": "WPScan",
      "title": "Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Abandoned Cart Lite for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13435
      },
      "nvd": {
        "published": "2026-07-16T07:16:47.100",
        "lastModified": "2026-07-16T18:16:41.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12585",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cart-recovery login tokens are forgeable or insufficiently bound to the selected account, allowing a crafted token to authenticate as another customer.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/c94475c8-d129-4735-b599-5094efb20cb8/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12588",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T08:34:21.001Z",
      "date_published": "2026-07-14T12:45:10.526Z",
      "date_updated": "2026-07-14T13:26:51.155Z",
      "publisher": "trellix",
      "title": "An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resour...",
      "affected": {
        "vendors": [
          "Trellix"
        ],
        "products": [
          {
            "vendor": "Trellix",
            "product": "Trellix HX Console"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:trellixpsirt@trellix.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11047
      },
      "nvd": {
        "published": "2026-07-14T13:18:14.087",
        "lastModified": "2026-07-15T21:00:31.273",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12588",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Decompression enforces no effective expansion-size limit before consuming memory, CPU, or storage.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.trellix.com/s/article/000015595",
          "host": "support.trellix.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 275,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12590",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T08:44:10.977Z",
      "date_published": "2026-07-09T10:21:10.447Z",
      "date_updated": "2026-07-09T12:06:01.554Z",
      "publisher": "openjs",
      "title": "body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement",
      "affected": {
        "vendors": [
          "body-parser"
        ],
        "products": [
          {
            "vendor": "body-parser",
            "product": "body-parser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.0027,
        "percentile": 0.19054
      },
      "nvd": {
        "published": "2026-07-09T11:16:24.670",
        "lastModified": "2026-07-10T02:45:02.800",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-12590",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An invalid body-size limit parses to null and silently disables request-size enforcement instead of rejecting the configuration.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 915,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-12592",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T09:19:56.429Z",
      "date_published": "2026-07-20T06:00:03.104Z",
      "date_updated": "2026-07-20T13:14:45.585Z",
      "publisher": "WPScan",
      "title": "SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "SlimStat Analytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10597
      },
      "nvd": {
        "published": "2026-07-20T07:16:34.757",
        "lastModified": "2026-07-20T20:39:31.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12592",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A visitor-controlled geolocation header is stored and rendered in an administrator report without HTML output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/3658cae6-f6ae-4ecc-8d74-bb402e61f5d5/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12593",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T09:26:17.599Z",
      "date_published": "2026-07-09T12:29:47.260Z",
      "date_updated": "2026-07-09T14:20:19.757Z",
      "publisher": "TQtC",
      "title": "Privilege escalation via forged API token creation in Axivion Dashboard OIDC/OAuth2/SSO subsystem",
      "affected": {
        "vendors": [
          "Qt"
        ],
        "products": [
          {
            "vendor": "Qt",
            "product": "Axivion"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:a59d8014-47c4-4630-ab43-e1b13cbe58e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20323
      },
      "nvd": {
        "published": "2026-07-09T14:16:26.713",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12593",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Dashboard token-creation endpoint authenticates the request but does not verify that the caller may create a token for the named other user.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wiki.qt.io/List_of_known_vulnerabilities_in_Qt_products#CVE-2026-12593",
          "host": "wiki.qt.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1050,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-12595",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T10:15:01.785Z",
      "date_published": "2026-07-09T23:30:09.414Z",
      "date_updated": "2026-07-10T14:13:16.007Z",
      "publisher": "Wordfence",
      "title": "LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via Discord OAuth Callback",
      "affected": {
        "vendors": [
          "LoginPress"
        ],
        "products": [
          {
            "vendor": "LoginPress",
            "product": "LoginPress Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27325
      },
      "nvd": {
        "published": "2026-07-10T00:16:32.120",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12595",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Discord OAuth callback maps an unverified provider email directly to a local account and issues a session without checking the provider's verified flag.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5949980f-2506-49be-9105-40ec2d2a4f77?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://loginpress.pro/",
          "host": "loginpress.pro",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 867,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12597",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T10:21:22.717Z",
      "date_published": "2026-07-09T23:30:08.882Z",
      "date_updated": "2026-07-10T15:27:43.854Z",
      "publisher": "Wordfence",
      "title": "LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via GitHub OAuth Callback",
      "affected": {
        "vendors": [
          "LoginPress"
        ],
        "products": [
          {
            "vendor": "LoginPress",
            "product": "LoginPress Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00422,
        "percentile": 0.34774
      },
      "nvd": {
        "published": "2026-07-10T00:16:32.603",
        "lastModified": "2026-07-10T16:16:25.080",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12597",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The GitHub OAuth callback binds a local account to the first returned email without requiring GitHub to mark that email as verified.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4f3ee9f6-6465-4caf-9aef-72dd37c61a2c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://loginpress.pro/",
          "host": "loginpress.pro",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1157,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12598",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T10:27:55.243Z",
      "date_published": "2026-07-09T23:30:09.783Z",
      "date_updated": "2026-07-10T18:04:50.339Z",
      "publisher": "Wordfence",
      "title": "LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email in Spotify OAuth Callback",
      "affected": {
        "vendors": [
          "LoginPress"
        ],
        "products": [
          {
            "vendor": "LoginPress",
            "product": "LoginPress Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27325
      },
      "nvd": {
        "published": "2026-07-10T00:16:32.727",
        "lastModified": "2026-07-10T19:17:20.113",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12598",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Spotify login flow binds a WordPress account to an unverified profile email without proving ownership of that email.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bef61f05-a2dc-4f61-a5da-7161a9912196?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://loginpress.pro/",
          "host": "loginpress.pro",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 861,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12606",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T11:27:18.643Z",
      "date_published": "2026-07-14T08:28:17.257Z",
      "date_updated": "2026-07-27T11:37:48.096Z",
      "publisher": "eclipse",
      "title": "Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling. Grizzly 5.0.1 supports system properties that enable the be...",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse GlassFish"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08653
      },
      "nvd": {
        "published": "2026-07-14T09:16:39.920",
        "lastModified": "2026-07-27T13:16:51.833",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-12606",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HTTP parser in Eclipse GlassFish interprets a malformed request boundary differently from another participant in the request chain.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/129",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 444,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-12617",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T13:52:43.335Z",
      "date_published": "2026-07-22T14:14:46.397Z",
      "date_updated": "2026-07-22T18:48:15.278Z",
      "publisher": "isc",
      "title": "Record ordering based unexpected exit with CNAME or DNAME",
      "affected": {
        "vendors": [
          "ISC"
        ],
        "products": [
          {
            "vendor": "ISC",
            "product": "BIND 9"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-officer@isc.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00488,
        "percentile": 0.39385
      },
      "nvd": {
        "published": "2026-07-22T15:16:51.963",
        "lastModified": "2026-07-22T20:33:11.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12617",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The resolver processes a particular ordering of CNAME or DNAME and address records through an invalid state transition that reaches a terminating assertion.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.isc.org/docs/cve-2026-12617",
          "host": "kb.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.20.26",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 796,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-12654",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T18:47:59.973Z",
      "date_published": "2026-07-24T06:52:00.542Z",
      "date_updated": "2026-07-24T19:55:36.258Z",
      "publisher": "Wordfence",
      "title": "Payment Plugins for Stripe WooCommerce <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret",
      "affected": {
        "vendors": [
          "paymentplugins"
        ],
        "products": [
          {
            "vendor": "paymentplugins",
            "product": "Payment Plugins for Stripe WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27842
      },
      "nvd": {
        "published": "2026-07-24T08:16:25.623",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12654",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A default-empty webhook secret disables signature verification, so a forged Stripe event can drive an order into the paid state.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/45185f25-9a1f-411d-9d2a-295b5ceb5629?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.105/includes/controllers/class-wc-stripe-controller-webhook.php#L60",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.108/includes/controllers/class-wc-stripe-controller-webhook.php#L60",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.108/includes/controllers/class-wc-stripe-controller-webhook.php#L54",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.108/includes/controllers/class-wc-stripe-controller-webhook.php#L24",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.108/includes/wc-stripe-webhook-functions.php#L427",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.108/includes/abstract/abstract-wc-stripe-payment.php#L104",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.105/includes/controllers/class-wc-stripe-controller-webhook.php#L54",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.105/includes/controllers/class-wc-stripe-controller-webhook.php#L24",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.105/includes/wc-stripe-webhook-functions.php#L427",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.105/includes/abstract/abstract-wc-stripe-payment.php#L104",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3611878%40woo-stripe-payment&new=3611878%40woo-stripe-payment",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 914,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12657",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T18:49:07.840Z",
      "date_published": "2026-07-02T08:33:04.988Z",
      "date_updated": "2026-07-02T12:37:48.368Z",
      "publisher": "Wordfence",
      "title": "LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter",
      "affected": {
        "vendors": [
          "latepoint"
        ],
        "products": [
          {
            "vendor": "latepoint",
            "product": "LatePoint – Calendar Booking Plugin for Appointments and Events"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00381,
        "percentile": 0.30865
      },
      "nvd": {
        "published": "2026-07-02T10:16:27.773",
        "lastModified": "2026-07-02T13:58:56.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12657",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LatePoint – Calendar Booking Plugin for Appointments and Events accepts a caller-supplied object identifier without binding the selected object to the caller's ownership or authorized scope.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/09588c2a-1631-4924-8277-d47f096493c5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/helpers/steps_helper.php#L1202",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/controllers/steps_controller.php#L341",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/controllers/steps_controller.php#L244",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/helpers/steps_helper.php#L1710",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/helpers/steps_helper.php#L1618",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/helpers/steps_helper.php#L1202",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/controllers/steps_controller.php#L341",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/controllers/steps_controller.php#L244",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/helpers/steps_helper.php#L1710",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.3.2/lib/helpers/steps_helper.php#L1618",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3584059%40latepoint&new=3584059%40latepoint&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 728,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12659",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T18:54:20.493Z",
      "date_published": "2026-07-14T15:14:14.363Z",
      "date_updated": "2026-07-14T15:57:22.367Z",
      "publisher": "Rockwell",
      "title": "Rockwell Automation Flex 5000® Adapter - Denial of Service",
      "affected": {
        "vendors": [
          "Rockwell Automation"
        ],
        "products": [
          {
            "vendor": "Rockwell Automation",
            "product": "The FLEX 5000® EtherNet/IP Adapter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:PSIRT@rockwellautomation.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24456
      },
      "nvd": {
        "published": "2026-07-14T16:16:45.170",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12659",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted CIP packet handling can free the same allocation twice, leaving the adapter unrecoverable until it is power-cycled.",
        "basis": [
          "CNA",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1789.html",
          "host": "www.rockwellautomation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 266,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T07:49:11.659Z",
      "date_published": "2026-07-16T06:00:04.102Z",
      "date_updated": "2026-07-16T17:57:31.091Z",
      "publisher": "WPScan",
      "title": "Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Customer Reviews for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16284
      },
      "nvd": {
        "published": "2026-07-16T07:16:47.210",
        "lastModified": "2026-07-16T19:16:44.267",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12684",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A media-upload AJAX action is callable without authentication, capability, or nonce checks even though it creates Media Library objects.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/169d3455-dd98-4b0b-b6c1-6c9c28aa9707/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 429,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T08:15:52.985Z",
      "date_published": "2026-07-10T06:00:02.207Z",
      "date_updated": "2026-07-10T15:04:42.106Z",
      "publisher": "WPScan",
      "title": "EscortWP <= 3.6.2 - Content Deletion via Vendor-Authored Backdoor",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "escortwp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-912",
          "name": "Hidden Functionality",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12919
      },
      "nvd": {
        "published": "2026-07-10T07:16:28.313",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12685",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The distributed theme contains vendor-authored obfuscated code that recognizes a hard-coded per-build key and exposes an unauthenticated backdoor.",
        "basis": [
          "CNA",
          "CWE-912"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/0e5f5730-167d-4853-a764-bb9e3d62fdc4/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 348,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12686",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T08:38:05.732Z",
      "date_published": "2026-07-06T08:48:54.613Z",
      "date_updated": "2026-07-06T12:50:57.194Z",
      "publisher": "INCIBE",
      "title": "Incorrect authorisation in Adiss’s Biloop",
      "affected": {
        "vendors": [
          "Adiss"
        ],
        "products": [
          {
            "vendor": "Adiss",
            "product": "Biloop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00309,
        "percentile": 0.23254
      },
      "nvd": {
        "published": "2026-07-06T11:16:26.797",
        "lastModified": "2026-07-06T18:41:46.210",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12686",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application does not adequately verify whether the requested company ID belongs to the authenticated user’s session, resulting in a cross-tenant authorisation bypass.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/incorrect-authorisation-adisss-biloop",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 562,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T08:40:27.925Z",
      "date_published": "2026-07-30T06:00:07.916Z",
      "date_updated": "2026-07-30T14:01:53.854Z",
      "publisher": "WPScan",
      "title": "ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group ID",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "ProfileGrid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21878
      },
      "nvd": {
        "published": "2026-07-30T06:24:58.677",
        "lastModified": "2026-07-30T14:19:00.067",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12687",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e754ef68-40ae-4420-a0b8-6c23a83bc450/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 353,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T08:40:29.702Z",
      "date_published": "2026-07-24T06:00:02.508Z",
      "date_updated": "2026-07-24T19:43:21.142Z",
      "publisher": "WPScan",
      "title": "ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "ProfileGrid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06075
      },
      "nvd": {
        "published": "2026-07-24T07:16:32.473",
        "lastModified": "2026-07-24T20:48:39.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12688",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The membership workflow trusts an unverified PayPal IPN message as proof of payment before granting the requested group membership.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/b62a2c10-78da-4a7d-a6e1-f50ebf0763db/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 275,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12689",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T08:40:31.614Z",
      "date_published": "2026-07-24T06:00:02.676Z",
      "date_updated": "2026-07-24T19:44:18.824Z",
      "publisher": "WPScan",
      "title": "ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "ProfileGrid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03607
      },
      "nvd": {
        "published": "2026-07-24T07:16:32.580",
        "lastModified": "2026-07-24T20:48:39.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12689",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/7368fe32-9415-47c3-b94b-b85ca1a0d101/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T08:40:34.360Z",
      "date_published": "2026-07-24T06:00:02.850Z",
      "date_updated": "2026-07-24T19:45:24.352Z",
      "publisher": "WPScan",
      "title": "ProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Authorization",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "ProfileGrid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04924
      },
      "nvd": {
        "published": "2026-07-24T07:16:32.680",
        "lastModified": "2026-07-24T20:48:39.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12690",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/7a1fc208-851b-4eb6-a332-fbef57181755/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 300,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12691",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T09:01:03.871Z",
      "date_published": "2026-07-17T16:32:36.141Z",
      "date_updated": "2026-07-17T16:50:39.340Z",
      "publisher": "TR-CERT",
      "title": "Authentication Bypass in Vimesoft's Enterprise Video Platform",
      "affected": {
        "vendors": [
          "Vimesoft Inc."
        ],
        "products": [
          {
            "vendor": "Vimesoft Inc.",
            "product": "Enterprise Video Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22212
      },
      "nvd": {
        "published": "2026-07-17T17:17:13.177",
        "lastModified": "2026-07-17T17:54:18.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12691",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Enterprise Video Platform exposes a critical operation without completing the authentication check required for that operation.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0574",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12692",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T09:01:24.669Z",
      "date_published": "2026-07-17T16:39:19.059Z",
      "date_updated": "2026-07-17T16:51:32.290Z",
      "publisher": "TR-CERT",
      "title": "Improper Authentication in Vimesoft's Enterprise Video Platform",
      "affected": {
        "vendors": [
          "Vimesoft Inc."
        ],
        "products": [
          {
            "vendor": "Vimesoft Inc.",
            "product": "Enterprise Video Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-620",
          "name": "Unverified Password Change",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27241
      },
      "nvd": {
        "published": "2026-07-17T17:17:13.303",
        "lastModified": "2026-07-17T17:54:18.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12692",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The password-change workflow accepts a new password without verifying the requester through the required existing credential or reset proof.",
        "basis": [
          "CNA",
          "CWE-620"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0574",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12693",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T09:01:27.281Z",
      "date_published": "2026-07-17T16:50:54.125Z",
      "date_updated": "2026-07-17T17:55:25.716Z",
      "publisher": "TR-CERT",
      "title": "IDOR in Vimesoft's Enterprise Video Platform",
      "affected": {
        "vendors": [
          "Vimesoft Inc."
        ],
        "products": [
          {
            "vendor": "Vimesoft Inc.",
            "product": "Enterprise Video Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18118
      },
      "nvd": {
        "published": "2026-07-17T17:17:13.430",
        "lastModified": "2026-07-17T18:17:13.847",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12693",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled key bypasses the access-control decision for the selected object.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0574",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12694",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T09:01:28.607Z",
      "date_published": "2026-07-17T16:59:09.138Z",
      "date_updated": "2026-07-17T17:54:58.489Z",
      "publisher": "TR-CERT",
      "title": "Missing Authorization in Vimesoft's Enterprise Video Platform",
      "affected": {
        "vendors": [
          "Vimesoft Inc."
        ],
        "products": [
          {
            "vendor": "Vimesoft Inc.",
            "product": "Enterprise Video Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15563
      },
      "nvd": {
        "published": "2026-07-17T17:17:13.547",
        "lastModified": "2026-07-17T18:17:14.037",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12694",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Enterprise Video Platform exposes functionality outside its intended ACL, but neither public record identifies the operation or missing authorization check.",
        "basis": [
          "CNA record",
          "CWE-862",
          "TR-CERT advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0574 and its public JSON endpoint; the advisory lists the CVE and upgrade to 3.25.0 but adds no causal implementation detail."
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0574",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T09:24:27.183Z",
      "date_published": "2026-07-31T06:00:11.504Z",
      "date_updated": "2026-07-31T17:42:33.859Z",
      "publisher": "WPScan",
      "title": "miniOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "miniOrange 2FA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21428
      },
      "nvd": {
        "published": "2026-07-31T07:16:23.747",
        "lastModified": "2026-07-31T18:17:10.150",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12695",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The two-factor handler verifies the submitted one-time password against an attacker-supplied secret instead of the targeted user's stored secret.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/1994ce51-3534-4cb3-b424-d2f9014e8bb3/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 369,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T09:25:21.565Z",
      "date_published": "2026-07-31T06:00:11.681Z",
      "date_updated": "2026-07-31T16:47:17.952Z",
      "publisher": "WPScan",
      "title": "wpForo Forum < 3.1.2 - Subscriber+ Cross-User AI Chat Message Deletion via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "wpForo Forum"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06618
      },
      "nvd": {
        "published": "2026-07-31T07:16:23.850",
        "lastModified": "2026-07-31T17:16:30.897",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12697",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The conversation-deletion handler accepts an object identifier without verifying that the current wpForo user owns that conversation.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/845362bb-a733-432e-86ac-7bf079d91e0f/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 275,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12701",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T09:53:04.810Z",
      "date_published": "2026-07-20T14:18:18.318Z",
      "date_updated": "2026-07-22T18:13:49.559Z",
      "publisher": "redhat",
      "title": "Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2.6 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.16 for RHEL 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.16 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.17 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.18 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6.19 for RHEL 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2.6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2.7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Update Infrastructure 4 for Cloud Providers"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Update Infrastructure 5"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 15,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00759,
        "percentile": 0.51682
      },
      "nvd": {
        "published": "2026-07-20T15:16:34.333",
        "lastModified": "2026-07-22T19:16:54.333",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12701",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "relative_path_validator rejects only leading slashes and permits embedded ../ segments, allowing FilesystemExport to write an attacker-controlled artifact outside the export directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42078",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42079",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42082",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42132",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42142",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42150",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42151",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42240",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-12701",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490703",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 682,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 15
      }
    },
    {
      "cve_id": "CVE-2026-12702",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T10:14:04.133Z",
      "date_published": "2026-07-24T08:29:31.719Z",
      "date_updated": "2026-07-24T12:36:31.660Z",
      "publisher": "Octopus",
      "title": "In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.",
      "affected": {
        "vendors": [
          "Octopus Deploy"
        ],
        "products": [
          {
            "vendor": "Octopus Deploy",
            "product": "Octopus Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@octopus.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13801
      },
      "nvd": {
        "published": "2026-07-24T09:16:22.900",
        "lastModified": "2026-07-28T16:25:15.680",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12702",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows an authentication or authorization boundary can be crossed but does not identify the exact caller-object predicate that fails.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://advisories.octopus.com/post/2026/sa2026-06",
          "host": "advisories.octopus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-12703",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T10:17:46.376Z",
      "date_published": "2026-07-29T14:13:19.692Z",
      "date_updated": "2026-07-29T15:07:08.712Z",
      "publisher": "TV",
      "title": "Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOS",
      "affected": {
        "vendors": [
          "TeamViewer"
        ],
        "products": [
          {
            "vendor": "TeamViewer",
            "product": "Remote"
          },
          {
            "vendor": "TeamViewer",
            "product": "Tensor"
          },
          {
            "vendor": "TeamViewer",
            "product": "ONE"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@teamviewer.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14447
      },
      "nvd": {
        "published": "2026-07-29T15:16:20.183",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12703",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unattended-access path establishes a remote connection without enforcing the configured two-factor connection-approval flow.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1007/",
          "host": "www.teamviewer.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-12705",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T10:24:46.696Z",
      "date_published": "2026-07-17T14:30:48.974Z",
      "date_updated": "2026-07-17T15:25:38.129Z",
      "publisher": "ABB",
      "title": "Integrity mechanism of KNX-device FW-files can be bypassed in ABB Update Tool",
      "affected": {
        "vendors": [
          "ABB"
        ],
        "products": [
          {
            "vendor": "ABB",
            "product": "KNX Update Tool (ABB)"
          },
          {
            "vendor": "ABB",
            "product": "KNX Update Tool (BJE)"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-353",
          "name": "Missing Support for Integrity Check",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cybersecurity@ch.abb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cybersecurity@ch.abb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00098,
        "percentile": 0.00928
      },
      "nvd": {
        "published": "2026-07-17T15:16:45.890",
        "lastModified": "2026-07-17T18:10:29.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12705",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The KNX Update Tool (ABB) update path lacks a required integrity check before accepting update content.",
        "basis": [
          "CNA",
          "CWE-353"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9270&LanguageCode=en&DocumentPartId=pdf&Action=Launch",
          "host": "search.abb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-12707",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T10:27:48.087Z",
      "date_published": "2026-07-14T15:18:24.104Z",
      "date_updated": "2026-07-14T15:57:47.140Z",
      "publisher": "cloudflare",
      "title": "Unbounded path event queue growth in quiche via peer-driven source connection ID rotation",
      "affected": {
        "vendors": [
          "Cloudflare"
        ],
        "products": [
          {
            "vendor": "Cloudflare",
            "product": "quiche"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@cloudflare.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20813
      },
      "nvd": {
        "published": "2026-07-14T16:16:45.297",
        "lastModified": "2026-07-14T16:45:02.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12707",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Path events enter an unbounded queue faster than the consumer can drain them, allowing memory growth without an effective cap.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cloudflare/quiche/security/advisories/GHSA-4q5x-gp38-rfp4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12715",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T11:04:06.795Z",
      "date_published": "2026-07-17T15:09:49.401Z",
      "date_updated": "2026-07-17T15:28:50.317Z",
      "publisher": "GoogleCloud",
      "title": "Missing Authorization in Firebase Studio allows Cross-Tenant Source Code Theft",
      "affected": {
        "vendors": [
          "Google Cloud"
        ],
        "products": [
          {
            "vendor": "Google Cloud",
            "product": "Firebase Studio"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/U:Clear"
        },
        {
          "source": "NVD:f45cbf4e-4146-4068-b7e1-655ffc2c548c",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10934
      },
      "nvd": {
        "published": "2026-07-17T16:17:13.047",
        "lastModified": "2026-07-17T18:08:08.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12715",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Firebase Studio operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.cloud.google.com/support/bulletins#gcp-2026-043",
          "host": "docs.cloud.google.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12720",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:02:01.867Z",
      "date_published": "2026-07-31T06:00:10.525Z",
      "date_updated": "2026-07-31T16:53:55.130Z",
      "publisher": "WPScan",
      "title": "Kirki < 6.0.13 - Unauthenticated PHP Object Injection",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Kirki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22783
      },
      "nvd": {
        "published": "2026-07-31T07:16:23.957",
        "lastModified": "2026-07-31T18:17:10.337",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12720",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kirki deserializes data stored by unauthenticated users without restricting the PHP classes that may be instantiated.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/22f5af1c-972e-4e31-9afa-bf50ac278c66/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 496,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12721",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:02:53.567Z",
      "date_published": "2026-07-31T06:00:10.742Z",
      "date_updated": "2026-07-31T16:52:19.507Z",
      "publisher": "WPScan",
      "title": "Kirki < 6.0.13 - Unauthenticated SQL Injection",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Kirki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17918
      },
      "nvd": {
        "published": "2026-07-31T07:16:24.057",
        "lastModified": "2026-07-31T17:16:31.993",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12721",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/4cba3900-9f29-4928-811c-163827358052/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12722",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:26:23.968Z",
      "date_published": "2026-07-30T13:16:14.667Z",
      "date_updated": "2026-08-03T08:36:45.734Z",
      "publisher": "TR-CERT",
      "title": "Authentication Bypass in FTC Software's E-Commerce Management Panel",
      "affected": {
        "vendors": [
          "FTC Software IT Services"
        ],
        "products": [
          {
            "vendor": "FTC Software IT Services",
            "product": "FTC E-Commerce Management Panel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17013
      },
      "nvd": {
        "published": "2026-07-30T14:16:45.740",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12722",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The e-commerce management panel exposes a critical operation without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0701",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:26:29.635Z",
      "date_published": "2026-07-20T06:00:03.332Z",
      "date_updated": "2026-07-20T15:05:08.888Z",
      "publisher": "WPScan",
      "title": "Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderation Bypass via Component Library",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Kirki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10442
      },
      "nvd": {
        "published": "2026-07-20T07:16:34.877",
        "lastModified": "2026-07-20T20:39:31.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12723",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/76df2c61-4ba7-4987-9e61-5d02142b3db5/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12724",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:26:32.263Z",
      "date_published": "2026-07-20T06:00:03.572Z",
      "date_updated": "2026-07-20T15:05:55.528Z",
      "publisher": "WPScan",
      "title": "Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Kirki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00101,
        "percentile": 0.01072
      },
      "nvd": {
        "published": "2026-07-20T07:16:34.980",
        "lastModified": "2026-07-20T20:39:31.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12724",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kirki places caller-supplied password-reset subject and body values into an HTML email without sanitizing or escaping them for that markup context.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/6c2d4489-de82-472d-a5f7-dc01b305fdd0/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T15:59:01.807Z",
      "date_published": "2026-07-03T01:28:19.653Z",
      "date_updated": "2026-07-06T16:36:20.191Z",
      "publisher": "Wordfence",
      "title": "weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX Action",
      "affected": {
        "vendors": [
          "wedevs"
        ],
        "products": [
          {
            "vendor": "wedevs",
            "product": "weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11677
      },
      "nvd": {
        "published": "2026-07-03T02:16:22.740",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12729",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/228d63a5-5053-4692-9801-4860325da153?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wedocs/tags/2.3.0/includes/Admin/Migrate.php#L206",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wedocs/tags/2.3.0/includes/Ajax.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wedocs/tags/2.3.0/includes/Admin/Migrate.php#L183",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wedocs/tags/2.3.0/includes/Admin/Migrate.php#L56",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3589430%40wedocs&new=3589430%40wedocs&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 807,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T15:59:53.395Z",
      "date_published": "2026-07-03T01:28:21.006Z",
      "date_updated": "2026-07-07T17:01:35.501Z",
      "publisher": "Wordfence",
      "title": "weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes",
      "affected": {
        "vendors": [
          "wedevs"
        ],
        "products": [
          {
            "vendor": "wedevs",
            "product": "weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.10043
      },
      "nvd": {
        "published": "2026-07-03T02:16:23.100",
        "lastModified": "2026-07-07T18:16:34.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12731",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cda6d5d5-b49a-40f4-9c83-c1c569891339?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wedocs/tags/2.3.0/assets/build/blocks/Sidebar/render.php#L540",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wedocs/tags/2.3.0/assets/build/blocks/Sidebar/render.php#L634",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wedocs/tags/2.3.0/assets/build/blocks/Sidebar/render.php#L154",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3589430%40wedocs&new=3589430%40wedocs&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 503,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12732",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T16:03:58.190Z",
      "date_published": "2026-07-01T07:53:36.180Z",
      "date_updated": "2026-07-01T10:32:04.704Z",
      "publisher": "Wordfence",
      "title": "LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute",
      "affected": {
        "vendors": [
          "thimpress"
        ],
        "products": [
          {
            "vendor": "thimpress",
            "product": "LearnPress – WordPress LMS Plugin for Create and Sell Online Courses"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08611
      },
      "nvd": {
        "published": "2026-07-01T08:16:21.487",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12732",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A shortcode attribute is interpolated into an HTML class attribute without attribute-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/09c8db69-60fa-4087-9096-5d34ce44f616?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.0/inc/TemplateHooks/Course/FilterCourseTemplate.php#L98",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.0/inc/Shortcodes/Course/FilterCourseShortcode.php#L29",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3587186%40learnpress&new=3587186%40learnpress&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 860,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12733",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T16:05:01.990Z",
      "date_published": "2026-07-30T17:57:02.684Z",
      "date_updated": "2026-07-31T15:59:20.632Z",
      "publisher": "ibm",
      "title": "IBM DataPower Gateway affected by denial of service",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "DataPower Gateway 10.6CD"
          },
          {
            "vendor": "IBM",
            "product": "DataPower Gateway 10.6.0"
          },
          {
            "vendor": "IBM",
            "product": "DataPower Gateway 11.0.0"
          },
          {
            "vendor": "IBM",
            "product": "DataPower Gateway 10.5.0"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23731
      },
      "nvd": {
        "published": "2026-07-30T19:17:04.867",
        "lastModified": "2026-07-31T16:16:57.827",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12733",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DataPower Gateway permits a remote request to consume an unspecified finite resource without an effective limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278746",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 118,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-12734",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T16:06:32.290Z",
      "date_published": "2026-07-03T01:28:19.126Z",
      "date_updated": "2026-07-06T16:23:38.805Z",
      "publisher": "Wordfence",
      "title": "weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block Attribute",
      "affected": {
        "vendors": [
          "wedevs"
        ],
        "products": [
          {
            "vendor": "wedevs",
            "product": "weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.10043
      },
      "nvd": {
        "published": "2026-07-03T02:16:23.223",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12734",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The connectorWidth block attribute reaches rendered page markup without sufficient sanitization or context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/11d68c98-3d7e-42af-be61-6bb5428b73b6?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wedocs/tags/2.3.0/assets/build/blocks/Sidebar/render.php#L138",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wedocs/tags/2.3.0/assets/build/blocks/Sidebar/render.php#L161",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3589430%40wedocs&new=3589430%40wedocs&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 479,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12736",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T16:24:48.590Z",
      "date_published": "2026-07-24T02:32:00.363Z",
      "date_updated": "2026-07-24T11:08:09.327Z",
      "publisher": "Wordfence",
      "title": "WPify Woo <= 5.4.16 - Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST Endpoint",
      "affected": {
        "vendors": [
          "wpify"
        ],
        "products": [
          {
            "vendor": "wpify",
            "product": "WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26325
      },
      "nvd": {
        "published": "2026-07-24T04:16:51.357",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12736",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The REST route lets a shop manager pass any WordPress option name to update_option without an option allowlist.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a9b8f2d5-a2c5-4f90-ab1d-4e17f7a7996e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpify-woo/tags/5.4.9/src/Api/SettingsApi.php#L67",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpify-woo/tags/5.4.10/src/Api/SettingsApi.php#L67",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpify-woo/tags/5.4.10/src/Api/SettingsApi.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpify-woo/tags/5.4.10/src/Managers/ApiManager.php#L18",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpify-woo/tags/5.4.9/src/Api/SettingsApi.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpify-woo/tags/5.4.9/src/Managers/ApiManager.php#L18",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3614762%40wpify-woo&new=3614762%40wpify-woo",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 744,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T16:37:04.989Z",
      "date_published": "2026-07-11T05:35:46.200Z",
      "date_updated": "2026-07-13T17:36:08.815Z",
      "publisher": "Wordfence",
      "title": "WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action",
      "affected": {
        "vendors": [
          "saadiqbal"
        ],
        "products": [
          {
            "vendor": "saadiqbal",
            "product": "WP Easy Pay – Payment and Donation form Builder for Square"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11748
      },
      "nvd": {
        "published": "2026-07-11T07:16:45.770",
        "lastModified": "2026-07-13T18:16:26.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12738",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A subscriber can invoke a handler that changes arbitrary post status without a capability check for that action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2121d9fa-bab4-489d-89bc-07a8660bc3d1?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-easy-pay/tags/4.5.0/wpep-setup.php#L1703",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-easy-pay/tags/4.5.0/wpep-setup.php#L1698",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-easy-pay/tags/4.5.0/wpep-setup.php#L31",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3593500%40wp-easy-pay&new=3593500%40wp-easy-pay",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 463,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12740",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T16:43:08.971Z",
      "date_published": "2026-07-04T17:58:31.298Z",
      "date_updated": "2026-07-06T13:54:14.245Z",
      "publisher": "CPANSec",
      "title": "Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter",
      "affected": {
        "vendors": [
          "CORNELIUS"
        ],
        "products": [
          {
            "vendor": "CORNELIUS",
            "product": "Plack::Middleware::OAuth"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06825
      },
      "nvd": {
        "published": "2026-07-04T18:16:28.133",
        "lastModified": "2026-07-06T18:16:45.163",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12740",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OAuth callback is accepted into a session without a state value binding it to the authorization request that the same session initiated.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://rt.cpan.org/Ticket/Display.html?id=179874",
          "host": "rt.cpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/c9s/Plack-Middleware-OAuth/pull/13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://security.metacpan.org/patches/P/Plack-Middleware-OAuth/0.10/CVE-2026-12740-r1.patch",
          "host": "security.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://datatracker.ietf.org/doc/html/rfc6749#section-10.12",
          "host": "datatracker.ietf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/04/10",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1014,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12741",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T16:46:14.784Z",
      "date_published": "2026-07-28T07:47:38.342Z",
      "date_updated": "2026-07-28T13:42:58.469Z",
      "publisher": "Wordfence",
      "title": "WP Fast Total Search <= 1.80.280 - Unauthenticated SQL Injection",
      "affected": {
        "vendors": [
          "epsiloncool"
        ],
        "products": [
          {
            "vendor": "epsiloncool",
            "product": "WP Fast Total Search – The Power of Indexed Search"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22754
      },
      "nvd": {
        "published": "2026-07-28T08:17:14.360",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12741",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WP Fast Total Search – The Power of Indexed Search incorporates attacker-controlled values or identifiers into a SQL statement without preserving the boundary between query syntax and data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e9b6fe22-330a-4c24-9fdf-16f35516fb2a?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fulltext-search/tags/1.80.280/includes/wpfts_search.php#L825",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fulltext-search/tags/1.80.280/fulltext-search.php#L453",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fulltext-search/tags/1.79.274/includes/wpfts_search.php#L825",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fulltext-search/tags/1.79.274/fulltext-search.php#L453",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12746",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T17:42:35.807Z",
      "date_published": "2026-07-04T17:52:41.494Z",
      "date_updated": "2026-07-06T14:56:03.698Z",
      "publisher": "CPANSec",
      "title": "Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter",
      "affected": {
        "vendors": [
          "BIAFRA"
        ],
        "products": [
          {
            "vendor": "BIAFRA",
            "product": "Dancer2::Plugin::Auth::OAuth::Provider"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08444
      },
      "nvd": {
        "published": "2026-07-04T18:16:28.247",
        "lastModified": "2026-07-06T18:16:45.163",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12746",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OAuth flow neither issues nor verifies state, so a callback is not bound to the browser session that initiated authorization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/BIAFRA/Dancer2-Plugin-Auth-OAuth-0.23/diff/BIAFRA/Dancer2-Plugin-Auth-OAuth-0.22",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/biafra/perl-Dancer2-Plugin-Auth-OAuth/commit/806420fc2abbe13bede4461475f2f3dcd7daf5f2.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://datatracker.ietf.org/doc/html/rfc6749#section-10.12",
          "host": "datatracker.ietf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/04/9",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1025,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12753",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T19:26:06.651Z",
      "date_published": "2026-07-16T02:30:55.919Z",
      "date_updated": "2026-07-18T02:40:22.936Z",
      "publisher": "Wordfence",
      "title": "Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection via 's' and 'match' Parameter",
      "affected": {
        "vendors": [
          "themehunk"
        ],
        "products": [
          {
            "vendor": "themehunk",
            "product": "Advance Product Search- Voice & Ajax Search for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22756
      },
      "nvd": {
        "published": "2026-07-16T04:17:16.073",
        "lastModified": "2026-07-18T03:16:34.577",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12753",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Advance Product Search- Voice & Ajax Search for WooCommerce incorporates attacker-controlled input into an SQL statement without parameterization, allowing input syntax to alter the database query.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4aa8342f-1f36-4eb5-8b69-ab90fd85e5cb?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/th-advance-product-search/tags/1.4.4/inc/thaps-function.php#L125",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/th-advance-product-search/tags/1.4.4/inc/thaps-function.php#L86",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/th-advance-product-search/tags/1.4.4/inc/thaps-function.php#L34",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3582785%40th-advance-product-search&new=3582785%40th-advance-product-search",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T19:29:52.724Z",
      "date_published": "2026-07-01T08:30:05.314Z",
      "date_updated": "2026-07-01T10:32:03.194Z",
      "publisher": "Wordfence",
      "title": "VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Scripting via 'layoutstyle' Parameter",
      "affected": {
        "vendors": [
          "e4jvikwp"
        ],
        "products": [
          {
            "vendor": "e4jvikwp",
            "product": "VikBooking Hotel Booking Engine & PMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12011
      },
      "nvd": {
        "published": "2026-07-01T10:16:26.790",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12754",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The rooms-list view renders the layoutstyle request parameter without sufficient HTML-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6d126213-e342-4271-aca0-5cc47214ae8b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/site/views/roomslist/tmpl/default.php#L46",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/site/views/roomslist/tmpl/default.php#L26",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/libraries/adapter/input/filter.php#L385",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.13/site/views/roomslist/tmpl/default.php#L46",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 621,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:26:20.327Z",
      "date_published": "2026-07-10T20:31:38.134Z",
      "date_updated": "2026-07-13T14:02:35.784Z",
      "publisher": "Wordfence",
      "title": "miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP Flow",
      "affected": {
        "vendors": [
          "cyberlord92"
        ],
        "products": [
          {
            "vendor": "cyberlord92",
            "product": "miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00463,
        "percentile": 0.37766
      },
      "nvd": {
        "published": "2026-07-10T21:16:53.160",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12761",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The profile-completion flow does not bind the submitted email address to the OAuth identity before logging in the corresponding account.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a56b59ce-29c2-4172-b703-a06d7bb28da0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-login-openid/tags/7.7.0/class-mo-openid-login-widget.php#L1502",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-login-openid/tags/7.7.0/view/profile_completion/mo_openid_prof_comp_funct.php#L41",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-login-openid/tags/7.7.0/view/profile_completion/mo_openid_prof_comp_funct.php#L191",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-login-openid/tags/7.7.0/mo-openid-social-login-functions.php#L34",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3592642/",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 997,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T19:53:36.643Z",
      "date_published": "2026-07-28T08:34:36.797Z",
      "date_updated": "2026-07-28T13:57:37.625Z",
      "publisher": "Wordfence",
      "title": "Premium Packages <= 6.2.0 - Unauthenticated SQL Injection",
      "affected": {
        "vendors": [
          "codename065"
        ],
        "products": [
          {
            "vendor": "codename065",
            "product": "Premium Packages – Sell Digital Products Securely"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22754
      },
      "nvd": {
        "published": "2026-07-28T09:16:40.667",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12800",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The cart coupon REST endpoint incorporates the code parameter into an SQL query without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b288386c-709c-49a6-9b46-28bf46c3c303?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/6.2.0/includes/libs/CouponCodes.php#L26",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/6.2.0/includes/libs/MiniCartAPI.php#L398",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/6.2.0/includes/libs/CouponCodes.php#L82",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3595291/wpdm-premium-packages",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 625,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12869",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T08:30:36.821Z",
      "date_published": "2026-07-16T06:00:04.278Z",
      "date_updated": "2026-07-16T12:34:58.653Z",
      "publisher": "WPScan",
      "title": "Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Template Import",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Header Footer Builder for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.0458
      },
      "nvd": {
        "published": "2026-07-16T07:16:47.300",
        "lastModified": "2026-07-16T13:43:05.487",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12869",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The template-import action accepts contributors with edit_posts and lets them publish a site-wide HTML widget without the required administrative capability.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/3c6562d9-f55e-4d82-be95-60e82a6feecf/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T09:25:11.907Z",
      "date_published": "2026-07-24T06:00:03.037Z",
      "date_updated": "2026-07-24T19:46:23.319Z",
      "publisher": "WPScan",
      "title": "Software Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Parameter",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Project Management, Bug and Issue Tracking Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14923
      },
      "nvd": {
        "published": "2026-07-24T07:16:32.777",
        "lastModified": "2026-07-24T20:48:39.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12877",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated search parameter is inserted into an SQL query without sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e9d0ea92-1046-457b-9619-38b61848e36a/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 392,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12879",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T09:35:44.962Z",
      "date_published": "2026-07-09T12:56:51.855Z",
      "date_updated": "2026-07-09T13:42:48.913Z",
      "publisher": "GoogleCloud",
      "title": "Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy",
      "affected": {
        "vendors": [
          "Google Cloud"
        ],
        "products": [
          {
            "vendor": "Google Cloud",
            "product": "Apigee"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-610",
          "name": "Externally Controlled Reference to a Resource in Another Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/U:Clear"
        },
        {
          "source": "NVD:f45cbf4e-4146-4068-b7e1-655ffc2c548c",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08656
      },
      "nvd": {
        "published": "2026-07-09T14:16:27.840",
        "lastModified": "2026-07-09T16:39:17.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12879",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The BigQuery data-access path acts with service authority without binding the requested data to the caller's Apigee tenant.",
        "basis": [
          "CNA",
          "CWE-441",
          "CWE-610"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cloud.google.com/apigee/docs/release-notes#July_08_2026",
          "host": "cloud.google.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 307,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12895",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:58:30.777Z",
      "date_published": "2026-07-29T10:58:50.322Z",
      "date_updated": "2026-07-29T12:07:55.509Z",
      "publisher": "INCIBE",
      "title": "SQL Injection in Frappe's ERPNext",
      "affected": {
        "vendors": [
          "Frappe"
        ],
        "products": [
          {
            "vendor": "Frappe",
            "product": "ERPNext"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12092
      },
      "nvd": {
        "published": "2026-07-29T11:16:47.227",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12895",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A supplier document name is interpolated with str.format() into SQL instead of being passed as a bound parameter.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/sql-injection-frappes-erpnext",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 715,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-12898",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:40:42.315Z",
      "date_published": "2026-07-20T06:00:03.782Z",
      "date_updated": "2026-07-20T15:04:20.034Z",
      "publisher": "WPScan",
      "title": "All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path Traversal",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "All-in-One WP Migration and Backup"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00308,
        "percentile": 0.23179
      },
      "nvd": {
        "published": "2026-07-20T07:16:35.087",
        "lastModified": "2026-07-20T20:39:31.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12898",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled path or reference can select a file outside the intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/c90553e4-8e1a-4c99-a28f-a0de8d635caa/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:52:57.092Z",
      "date_published": "2026-07-20T21:29:56.373Z",
      "date_updated": "2026-07-22T13:50:55.500Z",
      "publisher": "Wordfence",
      "title": "Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block",
      "affected": {
        "vendors": [
          "brainstormforce"
        ],
        "products": [
          {
            "vendor": "brainstormforce",
            "product": "Spectra Legacy – Gutenberg Blocks"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08524
      },
      "nvd": {
        "published": "2026-07-20T22:17:13.257",
        "lastModified": "2026-07-22T14:17:12.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12900",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Spectra Legacy – Gutenberg Blocks page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0e9dc5e3-9d72-4c04-8ba9-56428a6fdddd?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-addons-for-gutenberg/tags/2.19.28/blocks-config/image/class-uagb-image.php#L59",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-addons-for-gutenberg/tags/2.19.28/includes/blocks/image/block.php#L10",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 461,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12902",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T14:18:49.277Z",
      "date_published": "2026-07-01T03:43:36.478Z",
      "date_updated": "2026-07-01T10:32:05.956Z",
      "publisher": "Wordfence",
      "title": "Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions",
      "affected": {
        "vendors": [
          "stellarwp"
        ],
        "products": [
          {
            "vendor": "stellarwp",
            "product": "Kadence Blocks — Page Builder Toolkit for Gutenberg Editor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19364
      },
      "nvd": {
        "published": "2026-07-01T05:16:17.757",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12902",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Image-import AJAX actions allow contributors to create media attachments without enforcing the upload_files capability.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7de2cb7a-dc3d-41f2-8faa-9e87f78531b5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/class-kadence-blocks-prebuilt-library.php#L1078",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/class-kadence-blocks-prebuilt-library.php#L817",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/class-kadence-blocks-prebuilt-library.php#L916",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/class-kadence-blocks-prebuilt-library.php#L1223",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/class-kadence-blocks-prebuilt-library.php#L1078",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/class-kadence-blocks-prebuilt-library.php#L817",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/class-kadence-blocks-prebuilt-library.php#L916",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/class-kadence-blocks-prebuilt-library.php#L1223",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3590217%40kadence-blocks&new=3590217%40kadence-blocks&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 560,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12904",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T14:33:57.344Z",
      "date_published": "2026-07-01T03:43:34.639Z",
      "date_updated": "2026-07-01T10:42:11.715Z",
      "publisher": "Wordfence",
      "title": "Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter",
      "affected": {
        "vendors": [
          "stellarwp"
        ],
        "products": [
          {
            "vendor": "stellarwp",
            "product": "Kadence Blocks — Page Builder Toolkit for Gutenberg Editor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.2153
      },
      "nvd": {
        "published": "2026-07-01T05:16:17.897",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12904",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The request authorizes post_id but accesses a separately supplied post_path hash that is not bound to that decision.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/24cdd50f-742c-457c-85f7-9cccaf366e87?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L232",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L458",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L197",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L420",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L153",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L383",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L339",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/resources/Optimizer/Store/Table_Store.php#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.6/includes/resources/Optimizer/Path/Path.php#L60",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L232",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L458",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L197",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L420",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L153",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L383",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/resources/Optimizer/Rest/Optimize_Rest_Controller.php#L339",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/resources/Optimizer/Store/Table_Store.php#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.6.7/includes/resources/Optimizer/Path/Path.php#L60",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3590217%40kadence-blocks&new=3590217%40kadence-blocks&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 984,
        "referenceCount": 20,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12906",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T14:41:41.058Z",
      "date_published": "2026-07-16T06:00:04.463Z",
      "date_updated": "2026-07-16T16:53:35.525Z",
      "publisher": "WPScan",
      "title": "RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "RTMKit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07647
      },
      "nvd": {
        "published": "2026-07-16T07:16:47.400",
        "lastModified": "2026-07-16T18:16:41.917",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12906",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The AJAX action resolves a caller-supplied post identifier without checking that the caller may view that private post.",
        "basis": [
          "CNA record",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/594c3769-b953-4966-836d-a0dc4585fe87/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 300,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12907",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T14:41:44.233Z",
      "date_published": "2026-07-16T06:00:04.681Z",
      "date_updated": "2026-07-16T15:09:03.083Z",
      "publisher": "WPScan",
      "title": "RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Template Creation and Activation",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "RTMKit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.0648
      },
      "nvd": {
        "published": "2026-07-16T07:16:47.490",
        "lastModified": "2026-07-16T16:18:59.887",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12907",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An Author can invoke the builder AJAX action without the administrator capability required to activate a site-wide template.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/61588303-d356-4cec-9cdc-15dc8cb0b29f/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 340,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12918",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:30:56.786Z",
      "date_published": "2026-07-10T09:32:44.736Z",
      "date_updated": "2026-07-14T01:39:25.278Z",
      "publisher": "Wordfence",
      "title": "Mail Mint <= 1.24.1 - Authenticated (Administrator+) SQL Injection via 'recipients' Parameter",
      "affected": {
        "vendors": [
          "getwpfunnels"
        ],
        "products": [
          {
            "vendor": "getwpfunnels",
            "product": "Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24357
      },
      "nvd": {
        "published": "2026-07-10T10:16:22.893",
        "lastModified": "2026-07-14T02:16:52.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12918",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mail Mint stores recipient data and later concatenates it into a query, allowing stored input to become second-order SQL syntax.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bf7c500e-311f-4db5-8a54-de7b02fb11dd?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.24.1/app/Database/models/ContactGroupPivotModel.php#L130",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.24.1/app/MrmCommon.php#L1197",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.24.1/app/API/Controllers/Admin/CampaignController.php#L304",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.24.1/app/API/Controllers/Admin/CampaignController.php#L1088",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3592458%40mail-mint&new=3592458%40mail-mint",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1008,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12920",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:33:22.278Z",
      "date_published": "2026-07-03T01:28:20.021Z",
      "date_updated": "2026-07-06T15:33:17.935Z",
      "publisher": "Wordfence",
      "title": "Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Administrator+) SQL Injection via 's' Parameter",
      "affected": {
        "vendors": [
          "wplegalpages"
        ],
        "products": [
          {
            "vendor": "wplegalpages",
            "product": "Cookie Banner for GDPR / CCPA – WPLP Cookie Consent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21443
      },
      "nvd": {
        "published": "2026-07-03T02:16:23.343",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12920",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Cookie Banner for GDPR / CCPA – WPLP Cookie Consent, attacker-controlled input reaches an SQL statement without the required parameter binding or SQL-context escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/572bfa82-92f5-4801-8710-0626ca563a6c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/admin/data-req/class-wpl-data-req-table.php#L492",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/admin/data-req/class-wpl-data-req-table.php#L322",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/admin/data-req/class-wpl-data-req-table.php#L377",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/admin/data-req/class-wpl-data-req-table.php#L513",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3593450%40gdpr-cookie-consent&new=3593450%40gdpr-cookie-consent&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12923",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:48:46.550Z",
      "date_published": "2026-07-01T03:43:37.232Z",
      "date_updated": "2026-07-01T10:32:05.596Z",
      "publisher": "Wordfence",
      "title": "Video Gallery <= 4.0.3 - Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter",
      "affected": {
        "vendors": [
          "emarket-design"
        ],
        "products": [
          {
            "vendor": "emarket-design",
            "product": "Video Gallery – YouTube Gallery, Playlist & Video Grid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23345
      },
      "nvd": {
        "published": "2026-07-01T05:16:18.040",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12923",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The AJAX handler transforms a caller-controlled path value and invokes the result as a PHP function name without an allowlist.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/be4743d5-e4ca-4579-84e2-5eb3ef0e274d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/youtube-showcase/tags/4.0.3/includes/common-functions.php#L1070",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/youtube-showcase/tags/4.0.3/includes/common-functions.php#L1067",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/youtube-showcase/tags/4.0.3/includes/class-install-deactivate.php#L53",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3588198%40youtube-showcase&new=3588198%40youtube-showcase&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 975,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12924",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T17:02:31.023Z",
      "date_published": "2026-07-10T07:48:41.434Z",
      "date_updated": "2026-07-10T14:41:37.142Z",
      "publisher": "Wordfence",
      "title": "Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter",
      "affected": {
        "vendors": [
          "arraytics"
        ],
        "products": [
          {
            "vendor": "arraytics",
            "product": "Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.10001
      },
      "nvd": {
        "published": "2026-07-10T09:16:52.820",
        "lastModified": "2026-07-10T16:16:25.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12924",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The etn_faq_content value is stored and later emitted into browser-interpreted markup without sufficient sanitization and output escaping.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/343ed594-482a-4a27-9682-92bb643ee82a?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/templates/event/parts/event-details-parts.php#L359",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/templates/event/parts/styles/event-faq/style-1.php#L27",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/templates/event/parts/styles/event-faq/style-2.php#L26",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/core/event/Api/EventController.php#L2027",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/utils/functions.php#L44",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/core/event/Api/EventController.php#L801",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3600977%40wp-event-solution&new=3600977%40wp-event-solution",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 482,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12927",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T17:23:06.940Z",
      "date_published": "2026-07-29T12:37:47.199Z",
      "date_updated": "2026-07-29T14:19:12.306Z",
      "publisher": "schneider",
      "title": "CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition.",
      "affected": {
        "vendors": [
          "Schneider Electric"
        ],
        "products": [
          {
            "vendor": "Schneider Electric",
            "product": "IGSS Definition (Def.exe)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cybersecurity@se.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.1015
      },
      "nvd": {
        "published": "2026-07-29T13:17:36.300",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12927",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The IGSS Definition (Def.exe) path writes attacker-influenced data beyond the capacity of its destination buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://download.se.com/files?p_Doc_Ref=SEVD-2026-195-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-195-01.pdf",
          "host": "download.se.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12932",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T18:02:22.701Z",
      "date_published": "2026-07-30T16:42:03.164Z",
      "date_updated": "2026-07-30T18:05:58.903Z",
      "publisher": "OpenVPN",
      "title": "A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.",
      "affected": {
        "vendors": [
          "OpenVPN"
        ],
        "products": [
          {
            "vendor": "OpenVPN",
            "product": "OpenVPN"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@openvpn.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.27958
      },
      "nvd": {
        "published": "2026-07-30T17:16:27.920",
        "lastModified": "2026-07-30T19:17:05.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12932",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A TLS cryptographic-key allocation is not released on the affected path, so repeated use leaks memory.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.openvpn.net/Security%20Announcements/CVE-2026-12932",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://community.openvpn.net/ReleaseHistory#openvpn-275-released-1-july-2026",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://community.openvpn.net/ReleaseHistory#openvpn-2621-released-1-july-2026",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-12935",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T18:48:17.939Z",
      "date_published": "2026-07-29T18:20:06.417Z",
      "date_updated": "2026-07-30T03:55:40.565Z",
      "publisher": "TPLink",
      "title": "Unauthenticated Remote Code Execution in TP-Link TL-WR940N RTSP Conntrack Feature",
      "affected": {
        "vendors": [
          "TP-Link Systems Inc."
        ],
        "products": [
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "TL-WR940N v6"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f23511db-6c3e-4e32-a477-6aa17d310630",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00807,
        "percentile": 0.53291
      },
      "nvd": {
        "published": "2026-07-29T19:16:44.113",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12935",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The TL-WR940N v6 parser or handler can copy attacker-controlled data beyond the bounds of a stack allocation.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tp-link.com/us/support/download/tl-wr940n/v6/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/en/support/download/tl-wr940n/v6/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/jp/support/download/tl-wr940n/v6/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/faq/5213/",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 648,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-12936",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T18:51:28.989Z",
      "date_published": "2026-07-08T11:30:32.777Z",
      "date_updated": "2026-07-08T13:27:42.982Z",
      "publisher": "Wordfence",
      "title": "Recurio <= 1.1.3 - Authenticated (Shop Manager+) SQL Injection via 'data' Parameter",
      "affected": {
        "vendors": [
          "devitemsllc"
        ],
        "products": [
          {
            "vendor": "devitemsllc",
            "product": "Recurio – Ultimate Subscription for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18628
      },
      "nvd": {
        "published": "2026-07-08T12:17:19.923",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12936",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Recurio incorporates the data parameter into an SQL query without sufficient escaping or query parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4b34ad23-246e-42ba-89de-5985043848be?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/recurio/tags/1.1.2/includes/core/class-subscription-engine.php#L1095",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/recurio/tags/1.1.2/includes/core/class-subscription-engine.php#L301",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3593971%40recurio&new=3593971%40recurio",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12938",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:35:32.772Z",
      "date_published": "2026-07-29T01:29:40.753Z",
      "date_updated": "2026-07-29T12:30:07.422Z",
      "publisher": "Wordfence",
      "title": "Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute",
      "affected": {
        "vendors": [
          "contrid"
        ],
        "products": [
          {
            "vendor": "contrid",
            "product": "Newsletters"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11632
      },
      "nvd": {
        "published": "2026-07-29T02:16:42.883",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12938",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This is due to insufficient input sanitization and output escaping in the posts_single() function which propagates the attacker-controlled 'target' attribute into the global $wpml_target, and in the shortcode_posts() 'post_thumbnail' handler which concatenates $wpml_target into a target=\"...\" HTML attribute without esc_attr().",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/293abae5-a7fb-401f-af09-324a81ce8709?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/newsletters-lite/tags/4.15/helpers/shortcode.php#L845",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/newsletters-lite/tags/4.15/helpers/shortcode.php#L851",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/newsletters-lite/tags/4.15/helpers/shortcode.php#L492",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/newsletters-lite/tags/4.15/helpers/shortcode.php#L464",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/newsletters-lite/tags/4.15/includes/checkinit.php#L172",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3621582%40newsletters-lite&new=3621582%40newsletters-lite",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 711,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12939",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:37:29.147Z",
      "date_published": "2026-07-29T01:29:41.142Z",
      "date_updated": "2026-07-29T15:06:29.543Z",
      "publisher": "Wordfence",
      "title": "Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute",
      "affected": {
        "vendors": [
          "contrid"
        ],
        "products": [
          {
            "vendor": "contrid",
            "product": "Newsletters"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11632
      },
      "nvd": {
        "published": "2026-07-29T02:16:43.037",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12939",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This is due to insufficient input sanitization and output escaping in the post_thumbnail() method in helpers/shortcode.php, which concatenates the user-controlled $link shortcode attribute directly into an href attribute without esc_url() or esc_attr().",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2ca8ab94-45b8-4705-b23b-dbc743572121?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/newsletters-lite/tags/4.15/helpers/shortcode.php#L337",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/newsletters-lite/tags/4.15/helpers/shortcode.php#L327",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/newsletters-lite/tags/4.15/helpers/shortcode.php#L782",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/newsletters-lite/tags/4.15/includes/checkinit.php#L182",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3621582%40newsletters-lite&new=3621582%40newsletters-lite",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 664,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12940",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:44:45.455Z",
      "date_published": "2026-07-30T16:41:54.216Z",
      "date_updated": "2026-07-31T03:56:16.617Z",
      "publisher": "ibm",
      "title": "Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00478,
        "percentile": 0.38754
      },
      "nvd": {
        "published": "2026-07-30T17:16:28.040",
        "lastModified": "2026-07-31T04:16:45.870",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12940",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MCP stdio launcher filters environment variables with a blocklist that omits SHELLOPTS, BASHOPTS, and PS4, allowing shell behavior to be injected before launch.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279995",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 352,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12941",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:47:28.383Z",
      "date_published": "2026-07-16T02:30:56.944Z",
      "date_updated": "2026-07-16T12:46:18.344Z",
      "publisher": "Wordfence",
      "title": "MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter",
      "affected": {
        "vendors": [
          "wcmp"
        ],
        "products": [
          {
            "vendor": "wcmp",
            "product": "MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16873
      },
      "nvd": {
        "published": "2026-07-16T04:17:16.247",
        "lastModified": "2026-07-16T14:16:48.467",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12941",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c55bf5f5-20d5-4157-94d3-1a330cdc82df?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dc-woocommerce-multi-vendor/tags/5.0.8/classes/Transaction/Transaction.php#L274",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dc-woocommerce-multi-vendor/tags/5.0.8/classes/RestAPI/Controllers/Transactions.php#L113",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dc-woocommerce-multi-vendor/tags/5.0.8/classes/RestAPI/Controllers/Transactions.php#L76",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3606843%40dc-woocommerce-multi-vendor&new=3606843%40dc-woocommerce-multi-vendor",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 958,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12942",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:52:54.670Z",
      "date_published": "2026-07-30T16:45:49.604Z",
      "date_updated": "2026-07-30T17:32:16.191Z",
      "publisher": "ibm",
      "title": "Langflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpoints",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00416,
        "percentile": 0.34216
      },
      "nvd": {
        "published": "2026-07-30T19:17:05.297",
        "lastModified": "2026-07-30T19:31:02.643",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12942",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled path or reference can select a file outside the intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279993",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12943",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:55:16.119Z",
      "date_published": "2026-07-30T17:57:46.718Z",
      "date_updated": "2026-07-31T03:56:18.697Z",
      "publisher": "ibm",
      "title": "This Power Hardware Management Console update is being released to address",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "HMC V10.3.1050.0"
          },
          {
            "vendor": "IBM",
            "product": "HMC V11.1.1110.0"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0092,
        "percentile": 0.56833
      },
      "nvd": {
        "published": "2026-07-30T19:17:05.453",
        "lastModified": "2026-07-31T04:16:46.070",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12943",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value reaches an elevated HMC operating-system command without sufficient command-syntax neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278667",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-12945",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T20:24:54.097Z",
      "date_published": "2026-07-30T16:44:39.380Z",
      "date_updated": "2026-07-31T22:59:08.271Z",
      "publisher": "ibm",
      "title": "Langflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11968
      },
      "nvd": {
        "published": "2026-07-30T17:16:28.173",
        "lastModified": "2026-07-31T23:17:23.197",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12945",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Build-job APIs identify jobs without checking that the requested job belongs to the authenticated user.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279994",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12946",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T20:29:38.766Z",
      "date_published": "2026-07-30T19:01:50.960Z",
      "date_updated": "2026-07-31T03:56:19.395Z",
      "publisher": "ibm",
      "title": "Remote Code Execution in CUGA Component CodeAgent",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26973
      },
      "nvd": {
        "published": "2026-07-30T20:16:52.293",
        "lastModified": "2026-07-31T04:16:46.237",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12946",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Langflow permits remote user-controlled text to enter a code-evaluation path without separating it from executable code.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7278928",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 155,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12947",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T20:31:54.377Z",
      "date_published": "2026-07-30T14:17:30.878Z",
      "date_updated": "2026-07-30T16:18:40.220Z",
      "publisher": "ibm",
      "title": "IBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Discovery Connector nodes",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "App Connect Enterprise"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00395,
        "percentile": 0.32271
      },
      "nvd": {
        "published": "2026-07-30T15:16:24.427",
        "lastModified": "2026-07-30T17:16:28.330",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12947",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Discovery Connector nodes write potentially sensitive values to log files that a local user can read.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280894",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-12948",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T20:33:02.985Z",
      "date_published": "2026-07-07T14:32:43.977Z",
      "date_updated": "2026-07-13T16:19:13.748Z",
      "publisher": "Digi",
      "title": "Stored Cross-Site Scripting (XSS)",
      "affected": {
        "vendors": [
          "Digi International"
        ],
        "products": [
          {
            "vendor": "Digi International",
            "product": "Digi PortServer TS"
          },
          {
            "vendor": "Digi International",
            "product": "Digi One SP"
          },
          {
            "vendor": "Digi International",
            "product": "Digi One SP IA"
          },
          {
            "vendor": "Digi International",
            "product": "Digi One IA"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:e8a6bb0b-e373-42b1-a5de-93e314325576",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18917
      },
      "nvd": {
        "published": "2026-07-07T15:16:42.413",
        "lastModified": "2026-07-13T17:16:47.640",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12948",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Digi PortServer TS page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.digi.com/resources/security",
          "host": "www.digi.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 354,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-12955",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T21:19:30.826Z",
      "date_published": "2026-07-10T07:48:44.506Z",
      "date_updated": "2026-07-10T17:01:24.647Z",
      "publisher": "Wordfence",
      "title": "Cookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action",
      "affected": {
        "vendors": [
          "wplegalpages"
        ],
        "products": [
          {
            "vendor": "wplegalpages",
            "product": "Cookie Banner for GDPR / CCPA – WPLP Cookie Consent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09541
      },
      "nvd": {
        "published": "2026-07-10T09:16:52.987",
        "lastModified": "2026-07-10T17:16:53.490",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12955",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The schedule-save AJAX action changes an administrative option without checking manage_options or a request nonce.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ddee10e0-093c-47a3-8aa9-946d6d21e1b2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/admin/class-gdpr-cookie-consent-admin.php#L8139",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/admin/class-gdpr-cookie-consent-admin.php#L8132",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/includes/class-gdpr-cookie-consent.php#L251",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3601475/gdpr-cookie-consent/tags/4.3.7/admin/class-gdpr-cookie-consent-admin.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 612,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12960",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T05:33:05.433Z",
      "date_published": "2026-07-03T02:00:14.942Z",
      "date_updated": "2026-07-06T15:42:50.120Z",
      "publisher": "ASUS",
      "title": "An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL.",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "Router app"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-926",
          "name": "Improper Export of Android Application Components",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02035
      },
      "nvd": {
        "published": "2026-07-03T03:16:23.490",
        "lastModified": "2026-07-06T18:56:27.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12960",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An exported Android component accepts an Intent from another installed app and opens the caller-supplied URL without restricting it to an approved endpoint.",
        "basis": [
          "CNA",
          "CWE-926"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory/",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12968",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T09:24:02.548Z",
      "date_published": "2026-07-22T06:00:02.525Z",
      "date_updated": "2026-07-22T13:00:54.333Z",
      "publisher": "WPScan",
      "title": "Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Product Addons and Product Options With Custom Fields"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21393
      },
      "nvd": {
        "published": "2026-07-22T07:16:34.710",
        "lastModified": "2026-07-22T16:30:26.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12968",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Product Addons and Product Options With Custom Fields places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/8ae2ff84-a4a0-4fb1-842b-b3193e673d27/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 378,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12970",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T09:44:40.334Z",
      "date_published": "2026-07-20T06:00:03.955Z",
      "date_updated": "2026-07-20T15:01:31.822Z",
      "publisher": "WPScan",
      "title": "LearnPress < 4.4.1 - Reflected XSS via c_search",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "LearnPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04344
      },
      "nvd": {
        "published": "2026-07-20T07:16:35.190",
        "lastModified": "2026-07-20T20:39:31.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12970",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The c_search value is reflected into an HTML attribute without attribute-context escaping.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/d0a2780f-ab13-4bb8-935d-2aeba1de12d2/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 283,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12972",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T09:47:52.530Z",
      "date_published": "2026-07-20T06:00:04.142Z",
      "date_updated": "2026-07-20T15:00:38.378Z",
      "publisher": "WPScan",
      "title": "PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "PayPlus Payment Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07364
      },
      "nvd": {
        "published": "2026-07-20T07:16:35.290",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12972",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated AJAX action updates payment metadata for a caller-selected WooCommerce order without checking authorization or binding the order to its owner.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/dcd091d3-f830-4675-a3d5-926f4aa5a7a5/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12973",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T09:47:54.880Z",
      "date_published": "2026-07-20T06:00:04.376Z",
      "date_updated": "2026-07-20T14:59:50.083Z",
      "publisher": "WPScan",
      "title": "PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Modification",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "PayPlus Payment Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05627
      },
      "nvd": {
        "published": "2026-07-20T07:16:35.387",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12973",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated AJAX action returns or changes a WooCommerce order without checking either caller authorization or order ownership.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/385bee73-f9e5-425e-aa4c-3ff9274f8e00/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 318,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12978",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T10:56:12.742Z",
      "date_published": "2026-07-16T06:00:04.896Z",
      "date_updated": "2026-07-16T12:42:59.445Z",
      "publisher": "WPScan",
      "title": "FunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "FunnelKit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.05993
      },
      "nvd": {
        "published": "2026-07-16T07:16:47.577",
        "lastModified": "2026-07-16T13:43:05.487",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12978",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A Divi builder AJAX action reflects a caller-controlled value into HTML without output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/1b22645b-28cb-44f3-a5b9-c81a40175e59/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 373,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12979",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T10:56:14.346Z",
      "date_published": "2026-07-16T06:00:05.068Z",
      "date_updated": "2026-07-16T12:40:57.577Z",
      "publisher": "WPScan",
      "title": "FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "FunnelKit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09828
      },
      "nvd": {
        "published": "2026-07-16T07:16:47.663",
        "lastModified": "2026-07-16T13:43:05.487",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12979",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A template-import deletion path accepts an administrator-supplied path without constraining it to the intended template directory.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/d81ca171-65eb-484d-917f-f41b0cd20351/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 370,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T11:34:58.155Z",
      "date_published": "2026-07-24T06:00:03.207Z",
      "date_updated": "2026-07-24T19:40:55.809Z",
      "publisher": "WPScan",
      "title": "CAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password Reset",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "CAFEHAUS API"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22809
      },
      "nvd": {
        "published": "2026-07-24T07:16:32.880",
        "lastModified": "2026-07-24T20:48:39.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12981",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/79fa8b91-f88e-4249-9f17-9e98e879f6fa/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T11:36:33.944Z",
      "date_published": "2026-07-27T06:00:02.192Z",
      "date_updated": "2026-07-27T14:12:50.667Z",
      "publisher": "WPScan",
      "title": "Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Document Gallery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.0586
      },
      "nvd": {
        "published": "2026-07-27T07:16:24.577",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12982",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/a3c279ce-5db1-4331-ad74-4eef49619737/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12987",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T11:46:08.263Z",
      "date_published": "2026-07-22T06:00:02.698Z",
      "date_updated": "2026-07-22T12:59:16.253Z",
      "publisher": "WPScan",
      "title": "Events Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking Registration",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Events Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18648
      },
      "nvd": {
        "published": "2026-07-22T07:16:35.203",
        "lastModified": "2026-07-22T16:30:26.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12987",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Booking metadata is deserialized with attacker-selectable PHP classes and reaches an unparameterized database query through an available gadget chain.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/dac83702-298d-4422-b795-b7684cc3fb2b/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12988",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T11:48:46.764Z",
      "date_published": "2026-07-14T06:00:02.858Z",
      "date_updated": "2026-07-14T12:24:36.125Z",
      "publisher": "WPScan",
      "title": "WP 2FA < 3.1.1.2 - Account Takeover via 2FA Setup Email Binding",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP 2FA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06536
      },
      "nvd": {
        "published": "2026-07-14T06:17:11.677",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12988",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The 2FA setup flow sends the verification code to a caller-supplied email address without proving that the address belongs to the account being configured.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/8aa6bf91-54ee-4326-a477-31f42284be22/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12989",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T12:14:08.725Z",
      "date_published": "2026-07-27T11:37:08.253Z",
      "date_updated": "2026-07-27T15:46:22.000Z",
      "publisher": "INCIBE",
      "title": "Multiple vulnerabilities in Ghost Robotics' Vision 60",
      "affected": {
        "vendors": [
          "Ghost Robotics"
        ],
        "products": [
          {
            "vendor": "Ghost Robotics",
            "product": "Vision 60"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09448
      },
      "nvd": {
        "published": "2026-07-27T13:16:51.993",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12989",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive endpoint performs its operation without requiring the caller to authenticate.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ghost-robotics-vision-60",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 605,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12990",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T12:14:09.708Z",
      "date_published": "2026-07-27T11:38:40.015Z",
      "date_updated": "2026-07-27T15:45:49.434Z",
      "publisher": "INCIBE",
      "title": "Multiple vulnerabilities in Ghost Robotics' Vision 60",
      "affected": {
        "vendors": [
          "Ghost Robotics"
        ],
        "products": [
          {
            "vendor": "Ghost Robotics",
            "product": "Vision 60"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03089
      },
      "nvd": {
        "published": "2026-07-27T13:16:52.130",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12990",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The robot accepts a second modified client during an active control session without validating that client or binding control to the legitimate session.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ghost-robotics-vision-60",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12991",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T12:14:10.688Z",
      "date_published": "2026-07-27T11:44:27.523Z",
      "date_updated": "2026-07-27T15:45:09.693Z",
      "publisher": "INCIBE",
      "title": "Multiple vulnerabilities in Ghost Robotics' Vision 60",
      "affected": {
        "vendors": [
          "Ghost Robotics"
        ],
        "products": [
          {
            "vendor": "Ghost Robotics",
            "product": "Vision 60"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-300",
          "name": "Channel Accessible by Non-Endpoint",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03993
      },
      "nvd": {
        "published": "2026-07-27T13:16:52.250",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12991",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The robot control channel lacks cryptographic integrity and peer authentication, allowing a local-network intermediary to replace control traffic.",
        "basis": [
          "CNA",
          "CWE-300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ghost-robotics-vision-60",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 638,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12994",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T13:13:29.081Z",
      "date_published": "2026-07-11T05:35:48.289Z",
      "date_updated": "2026-07-13T16:12:05.930Z",
      "publisher": "Wordfence",
      "title": "WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller",
      "affected": {
        "vendors": [
          "wclovers"
        ],
        "products": [
          {
            "vendor": "wclovers",
            "product": "WCFM – Frontend Manager for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28823
      },
      "nvd": {
        "published": "2026-07-11T07:16:45.900",
        "lastModified": "2026-07-13T17:16:48.280",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12994",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A public request branch performs the action without login or capability enforcement and relies only on a publicly obtainable nonce.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/676b4637-a2c7-4a95-b644-bb0401f91b40?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-enquiry.php#L321",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-enquiry.php#L48",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/controllers/enquiry/wcfm-controller-enquiry-manage.php#L278",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/controllers/enquiry/wcfm-controller-enquiry-manage.php#L290",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.27/core/class-wcfm-frontend.php#L1197",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-enquiry.php#L321",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-enquiry.php#L48",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/controllers/enquiry/wcfm-controller-enquiry-manage.php#L278",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/controllers/enquiry/wcfm-controller-enquiry-manage.php#L290",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.26/core/class-wcfm-frontend.php#L1197",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3588570%40wc-frontend-manager&new=3588570%40wc-frontend-manager",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 770,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-12996",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T13:16:10.234Z",
      "date_published": "2026-07-30T16:38:58.925Z",
      "date_updated": "2026-07-30T18:07:17.597Z",
      "publisher": "OpenVPN",
      "title": "A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry",
      "affected": {
        "vendors": [
          "OpenVPN"
        ],
        "products": [
          {
            "vendor": "OpenVPN",
            "product": "OpenVPN"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@openvpn.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00397,
        "percentile": 0.32478
      },
      "nvd": {
        "published": "2026-07-30T17:16:28.450",
        "lastModified": "2026-07-30T19:17:05.643",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12996",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TLS session promotion or expiry can leave packet handling using memory after it has been freed.",
        "basis": [
          "CNA record",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.openvpn.net/Security%20Announcements/CVE-2026-12996",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://community.openvpn.net/ReleaseHistory#openvpn-275-released-1-july-2026",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://community.openvpn.net/ReleaseHistory#openvpn-2621-released-1-july-2026",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/07/msg00013.html",
          "host": "lists.debian.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-12997",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T13:16:23.201Z",
      "date_published": "2026-07-15T18:34:13.250Z",
      "date_updated": "2026-07-15T19:06:20.091Z",
      "publisher": "Wordfence",
      "title": "Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter",
      "affected": {
        "vendors": [
          "Gravity Forms"
        ],
        "products": [
          {
            "vendor": "Gravity Forms",
            "product": "Gravity Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00619,
        "percentile": 0.46249
      },
      "nvd": {
        "published": "2026-07-15T19:16:56.890",
        "lastModified": "2026-07-15T19:50:25.310",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-12997",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Gravity Forms accepts an attacker-controlled path that can resolve outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5c03c07f-8f41-47c2-bc95-d92a623f5f7c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.gravityforms.com/",
          "host": "www.gravityforms.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 615,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13001",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T13:37:47.800Z",
      "date_published": "2026-07-14T19:33:12.003Z",
      "date_updated": "2026-07-14T20:51:48.163Z",
      "publisher": "Wordfence",
      "title": "Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter",
      "affected": {
        "vendors": [
          "eteubert"
        ],
        "products": [
          {
            "vendor": "eteubert",
            "product": "Podlove Podcast Publisher"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00828,
        "percentile": 0.53957
      },
      "nvd": {
        "published": "2026-07-14T20:16:56.610",
        "lastModified": "2026-07-14T21:16:40.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13001",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The podcast cache handler accepts an unauthenticated upload without validating its file type, allowing an attacker-selected file object into the cache namespace.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f81a3429-f378-4295-adbe-ad6f1df59701?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/podlove-podcasting-plugin-for-wordpress/tags/4.4.2/lib/model/image.php#L439",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/podlove/podlove-publisher/commit/5b32468601e903bae2bcacfaf36ff583d2bc9387",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3597461/podlove-podcasting-plugin-for-wordpress",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 372,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13005",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T13:59:37.428Z",
      "date_published": "2026-07-16T02:30:54.787Z",
      "date_updated": "2026-07-16T15:11:45.717Z",
      "publisher": "Wordfence",
      "title": "MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Setting",
      "affected": {
        "vendors": [
          "mxchat"
        ],
        "products": [
          {
            "vendor": "mxchat",
            "product": "MxChat – AI Chatbot & Content Generation for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10963
      },
      "nvd": {
        "published": "2026-07-16T04:17:16.390",
        "lastModified": "2026-07-16T16:19:00.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13005",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In MxChat – AI Chatbot & Content Generation for WordPress, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/120bc64f-05ec-41e7-9ed4-d88014f4a3ea?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mxchat-basic/tags/3.2.10/includes/class-mxchat-admin.php#L7811",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mxchat-basic/tags/3.2.10/admin/class-ajax-handler.php#L145",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mxchat-basic/tags/3.2.10/admin/class-ajax-handler.php#L522",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mxchat-basic/tags/3.2.10/admin/class-ajax-handler.php#L528",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3590075%40mxchat-basic&new=3590075%40mxchat-basic",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13009",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:14:39.239Z",
      "date_published": "2026-07-23T09:33:57.201Z",
      "date_updated": "2026-07-23T16:05:45.927Z",
      "publisher": "Wordfence",
      "title": "AI Copilot <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'order[0][dir]' Parameter",
      "affected": {
        "vendors": [
          "wupsales"
        ],
        "products": [
          {
            "vendor": "wupsales",
            "product": "AI Copilot – Content Generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18842
      },
      "nvd": {
        "published": "2026-07-23T10:16:48.240",
        "lastModified": "2026-07-23T16:17:13.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13009",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled query text is concatenated into an SQL statement without parameter binding or equivalent grammar separation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2a965a23-5594-4925-8104-6f387a60ab49?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.5.4/classes/model.php#L162",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.5.4/classes/table.php#L259",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.5.4/modules/workspace/models/tasks.php#L266",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.5.4/modules/workspace/controller.php#L17",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3612849%40ai-copilot-content-generator&new=3612849%40ai-copilot-content-generator",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 869,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13010",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:17:51.209Z",
      "date_published": "2026-07-10T09:32:43.364Z",
      "date_updated": "2026-07-10T14:42:40.737Z",
      "publisher": "Wordfence",
      "title": "JoomSport <= 5.7.9 - Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute",
      "affected": {
        "vendors": [
          "beardev"
        ],
        "products": [
          {
            "vendor": "beardev",
            "product": "JoomSport – for Sports: Team & League, Football, Hockey & more"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.15995
      },
      "nvd": {
        "published": "2026-07-10T10:16:23.020",
        "lastModified": "2026-07-10T16:16:25.467",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13010",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The event shortcode attribute is concatenated into an SQL query without sufficient escaping or parameter preparation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a3aa680f-4ce2-43b2-81fb-c664e398c868?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.9/sportleague/base/wordpress/classes/class-jsport-getplayers.php#L102",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.9/includes/joomsport-shortcodes.php#L299",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3594276%40joomsport-sports-league-results-management&new=3594276%40joomsport-sports-league-results-management",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 703,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13011",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:20:11.816Z",
      "date_published": "2026-07-09T07:55:12.543Z",
      "date_updated": "2026-07-09T12:25:35.500Z",
      "publisher": "Wordfence",
      "title": "ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support <= 1.17.5 - Authenticated (HR Manager+) SQL Injection via 'orderby' Parameter",
      "affected": {
        "vendors": [
          "wedevs"
        ],
        "products": [
          {
            "vendor": "wedevs",
            "product": "ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17736
      },
      "nvd": {
        "published": "2026-07-09T08:16:46.130",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13011",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/208c8f55-14e0-47c4-b310-dd7b7edbadd4?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/erp/tags/1.17.5/modules/hrm/includes/functions-leave.php#L1409",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/erp/tags/1.17.5/modules/hrm/includes/functions-leave.php#L1408",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/erp/tags/1.17.5/modules/hrm/includes/functions-leave.php#L1521",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/erp/tags/1.17.5/modules/hrm/includes/LeaveRequestsListTable.php#L384",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3598905%40erp&new=3598905%40erp",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 699,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:40:38.489Z",
      "date_published": "2026-07-13T09:42:45.431Z",
      "date_updated": "2026-07-13T14:07:27.982Z",
      "publisher": "THA-PSIRT",
      "title": "Remote Code Execution vulnerability in \"Suspicious\" application",
      "affected": {
        "vendors": [
          "Thales CERT"
        ],
        "products": [
          {
            "vendor": "Thales CERT",
            "product": "Suspicious"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:psirt@thalesgroup.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0047,
        "percentile": 0.3824
      },
      "nvd": {
        "published": "2026-07-13T10:16:24.913",
        "lastModified": "2026-07-13T19:51:18.237",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13014",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker can select an arbitrary writable path in the application namespace instead of a constrained storage target.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-73",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thalesgroup-cert/suspicious/security/advisories/GHSA-x85x-9mrm-wwvp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 607,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13015",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:52:03.770Z",
      "date_published": "2026-07-01T03:43:36.847Z",
      "date_updated": "2026-07-01T10:32:05.780Z",
      "publisher": "Wordfence",
      "title": "WP Google Review Slider <= 18.1 - Reflected Cross-Site Scripting via 'place' Parameter",
      "affected": {
        "vendors": [
          "jgwhite33"
        ],
        "products": [
          {
            "vendor": "jgwhite33",
            "product": "WP Google Review Slider"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11433
      },
      "nvd": {
        "published": "2026-07-01T05:16:18.180",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13015",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WP Google Review Slider rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/815054e2-c575-439a-9a66-fce251b4da80?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-google-places-review-slider/trunk/admin/partials/googlecrawl_dfs.php#L109",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-google-places-review-slider/trunk/admin/partials/googlecrawl_dfs.php#L22",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-google-places-review-slider/trunk/admin/partials/googlecrawl_dfs.php#L48",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3590253%40wp-google-places-review-slider&new=3590253%40wp-google-places-review-slider&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 717,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13019",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:51:42.540Z",
      "date_published": "2026-07-07T16:40:53.066Z",
      "date_updated": "2026-07-08T03:56:44.996Z",
      "publisher": "Esri",
      "title": "Missing Authentication",
      "affected": {
        "vendors": [
          "Esri"
        ],
        "products": [
          {
            "vendor": "Esri",
            "product": "Portal for ArcGIS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@esri.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00434,
        "percentile": 0.35672
      },
      "nvd": {
        "published": "2026-07-07T17:16:35.400",
        "lastModified": "2026-07-09T14:40:59.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13019",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Portal for ArcGIS exposes a critical API to remote callers without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/june-2026-arcgis-security-bulletin",
          "host": "www.esri.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13020",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:51:44.189Z",
      "date_published": "2026-07-07T16:39:16.329Z",
      "date_updated": "2026-07-08T03:56:45.810Z",
      "publisher": "Esri",
      "title": "Weak Password Recovery Mechanism in Portal for ArcGIS",
      "affected": {
        "vendors": [
          "Esri"
        ],
        "products": [
          {
            "vendor": "Esri",
            "product": "Portal for ArcGIS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@esri.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18349
      },
      "nvd": {
        "published": "2026-07-07T17:16:35.510",
        "lastModified": "2026-07-09T14:33:14.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13020",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Portal for ArcGIS lets an unauthenticated caller manipulate the built-in recovery-question workflow and assume another account, while the accepted field or comparison is not public.",
        "basis": [
          "CNA",
          "CWE-640",
          "Esri June 2026 security bulletin"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/june-2026-arcgis-security-bulletin. Esri confirms manipulation of the built-in recovery-question workflow and removes that workflow when email recovery is unavailable, but does not publish the manipulated field or comparison. The vendor bulletin scores CVSS 3.1 at 8.1, while this shard carries a 9.8 maximum from another scoring source; retain both attributions rather than merging them."
      },
      "references": [
        {
          "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/june-2026-arcgis-security-bulletin",
          "host": "www.esri.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 463,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13039",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T17:16:57.845Z",
      "date_published": "2026-07-10T20:31:37.672Z",
      "date_updated": "2026-07-13T14:40:09.826Z",
      "publisher": "Wordfence",
      "title": "Eventin 4.0.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST API",
      "affected": {
        "vendors": [
          "arraytics"
        ],
        "products": [
          {
            "vendor": "arraytics",
            "product": "Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17257
      },
      "nvd": {
        "published": "2026-07-10T21:16:53.283",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13039",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "payment_complete accepts a fabricated checkout identifier without checking that the caller may complete the corresponding unpaid order.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/84a5348a-a307-4db4-83b6-08682282a4b8?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3600977%40wp-event-solution&new=3600977%40wp-event-solution",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 990,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13040",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T17:17:56.022Z",
      "date_published": "2026-07-03T04:30:17.322Z",
      "date_updated": "2026-07-07T17:01:29.467Z",
      "publisher": "Wordfence",
      "title": "NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter",
      "affected": {
        "vendors": [
          "webaways"
        ],
        "products": [
          {
            "vendor": "webaways",
            "product": "NEX-Forms – Ultimate Forms Plugin for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.2271
      },
      "nvd": {
        "published": "2026-07-03T06:16:21.590",
        "lastModified": "2026-07-07T18:16:34.557",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13040",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/49dc267a-48cf-487f-bedc-fd892666e9a0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php#L467",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php#L4896",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php#L4870",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php#L5323",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/includes/classes/class.functions.php#L2461",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php#L2660",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.11/main.php#L467",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.11/main.php#L4896",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.11/main.php#L4870",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.11/main.php#L5323",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.11/includes/classes/class.functions.php#L2461",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.11/main.php#L2660",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3584399%40nex-forms-express-wp-form-builder&new=3584399%40nex-forms-express-wp-form-builder&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 588,
        "referenceCount": 14,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13042",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T17:22:04.111Z",
      "date_published": "2026-07-16T03:44:31.767Z",
      "date_updated": "2026-07-18T02:42:11.267Z",
      "publisher": "Wordfence",
      "title": "RPB Chessboard <= 8.1.2 - Unauthenticated Stored Cross-Site Scripting via Comment Content",
      "affected": {
        "vendors": [
          "yo35"
        ],
        "products": [
          {
            "vendor": "yo35",
            "product": "RPB Chessboard"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16005
      },
      "nvd": {
        "published": "2026-07-16T05:16:17.780",
        "lastModified": "2026-07-18T03:16:34.687",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13042",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/848b9c6d-e0db-43ad-ac6d-3674435339dd?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rpb-chessboard/tags/8.1.2/php/abstractcontroller.php#L220",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rpb-chessboard/tags/8.1.2/php/abstractcontroller.php#L171",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rpb-chessboard/tags/8.1.2/php/abstractcontroller.php#L190",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rpb-chessboard/tags/8.1.0/php/abstractcontroller.php#L220",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rpb-chessboard/tags/8.1.0/php/abstractcontroller.php#L171",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/rpb-chessboard/tags/8.1.0/php/abstractcontroller.php#L190",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3604068%40rpb-chessboard&new=3604068%40rpb-chessboard",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 677,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13050",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T17:37:35.867Z",
      "date_published": "2026-07-02T23:08:12.667Z",
      "date_updated": "2026-07-07T03:56:20.933Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox networkd Out of Bounds Write Vulnerability",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00533,
        "percentile": 0.4201
      },
      "nvd": {
        "published": "2026-07-03T00:16:49.333",
        "lastModified": "2026-07-07T05:16:48.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13050",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled input reaches a write whose destination boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00029",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 359,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13053",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T17:49:03.096Z",
      "date_published": "2026-07-02T23:08:27.642Z",
      "date_updated": "2026-07-07T03:56:17.670Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Command Handler",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00581,
        "percentile": 0.44483
      },
      "nvd": {
        "published": "2026-07-03T00:16:50.320",
        "lastModified": "2026-07-10T13:00:36.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13053",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fireware OS writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00030",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13054",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T17:55:06.157Z",
      "date_published": "2026-07-02T23:07:57.548Z",
      "date_updated": "2026-07-07T03:56:23.074Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00586,
        "percentile": 0.44694
      },
      "nvd": {
        "published": "2026-07-03T00:16:50.497",
        "lastModified": "2026-07-10T12:58:52.963",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13054",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The management interface accepts traversal segments in a privileged file-write path and can select a target outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00028",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13055",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T17:59:56.769Z",
      "date_published": "2026-07-22T19:22:54.189Z",
      "date_updated": "2026-07-23T14:17:59.153Z",
      "publisher": "mongodb",
      "title": "Server crash via aggregation pipeline expression with compound wildcard index specification",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/AU:Y/R:A"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21193
      },
      "nvd": {
        "published": "2026-07-22T20:16:43.220",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13055",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The aggregation expression accepts a compound wildcard index specification that reaches an internal consistency assertion and aborts mongod.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-123081",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13056",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T17:59:58.065Z",
      "date_published": "2026-07-22T19:22:27.869Z",
      "date_updated": "2026-07-23T14:25:45.170Z",
      "publisher": "mongodb",
      "title": "A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1325",
          "name": "Improperly Controlled Sequential Memory Allocation",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21168
      },
      "nvd": {
        "published": "2026-07-22T20:16:43.383",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13056",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Array-producing query expressions can create unbounded intermediate objects in server memory until the process exhausts its heap.",
        "basis": [
          "CNA",
          "CWE-1325"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-124355",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13057",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T17:59:59.476Z",
      "date_published": "2026-07-22T19:22:05.646Z",
      "date_updated": "2026-07-23T14:25:25.365Z",
      "publisher": "mongodb",
      "title": "Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_META",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17846
      },
      "nvd": {
        "published": "2026-07-22T20:16:43.523",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13057",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Atlas Search path accepts client-supplied internal routing fields and uses them without binding the referenced collection data to the caller.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-126247",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13058",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:00.866Z",
      "date_published": "2026-07-22T19:21:34.259Z",
      "date_updated": "2026-07-23T14:25:01.308Z",
      "publisher": "mongodb",
      "title": "Transaction Command Insufficient Input Validation Leading to Process Termination",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.1336
      },
      "nvd": {
        "published": "2026-07-22T20:16:43.660",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13058",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MongoDB validates related transaction fields inconsistently and reaches a fatal invariant with an incomplete command state.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-127661",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13059",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:01.964Z",
      "date_published": "2026-07-22T19:21:06.550Z",
      "date_updated": "2026-07-24T03:56:11.586Z",
      "publisher": "mongodb",
      "title": "Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-807",
          "name": "Reliance on Untrusted Inputs in a Security Decision",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19998
      },
      "nvd": {
        "published": "2026-07-22T20:16:43.793",
        "lastModified": "2026-07-24T05:16:36.810",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13059",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Role-based query controls trust client-supplied command parameters when deciding which find, update, delete, and aggregate operations the caller may perform.",
        "basis": [
          "CNA",
          "CWE-807"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-128433",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13060",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:03.128Z",
      "date_published": "2026-07-22T19:19:58.404Z",
      "date_updated": "2026-07-23T14:18:21.625Z",
      "publisher": "mongodb",
      "title": "$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16069
      },
      "nvd": {
        "published": "2026-07-22T20:16:43.970",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13060",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MongoDB Server fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-127357",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13061",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:04.213Z",
      "date_published": "2026-07-22T19:19:34.846Z",
      "date_updated": "2026-07-23T14:23:48.855Z",
      "publisher": "mongodb",
      "title": "Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation Stage",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00162,
        "percentile": 0.0582
      },
      "nvd": {
        "published": "2026-07-22T20:16:44.123",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13061",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The listSessions stage returns cluster-level session metadata without enforcing the cluster-administrator authority required for that object set.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-127689",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13062",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:05.239Z",
      "date_published": "2026-07-22T19:19:01.472Z",
      "date_updated": "2026-07-23T14:23:30.353Z",
      "publisher": "mongodb",
      "title": "MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01992
      },
      "nvd": {
        "published": "2026-07-22T20:16:44.263",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13062",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mongos accepts client-controlled encryption metadata flags that should be server-owned and forwards them into Queryable Encryption writes.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-441"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-127831",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 333,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13063",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:06.309Z",
      "date_published": "2026-07-22T19:18:26.580Z",
      "date_updated": "2026-07-23T19:09:15.842Z",
      "publisher": "mongodb",
      "title": "libmongocrypt Improper Input Validation Leading to Process Termination",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11624
      },
      "nvd": {
        "published": "2026-07-22T20:16:44.407",
        "lastModified": "2026-07-23T20:17:07.217",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13063",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libmongocrypt accepts payload values whose arithmetic produces an excessively large allocation and terminates mongod under memory pressure.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-127737",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13064",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:07.375Z",
      "date_published": "2026-07-22T19:17:54.134Z",
      "date_updated": "2026-07-23T19:09:41.843Z",
      "publisher": "mongodb",
      "title": "MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14472
      },
      "nvd": {
        "published": "2026-07-22T20:16:44.533",
        "lastModified": "2026-07-23T20:17:07.340",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13064",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Deeply nested jsonSchema constructs trigger disproportionate CPU work that normal administrative cancellation cannot stop.",
        "basis": [
          "CNA",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-125872",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 291,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13065",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:08.414Z",
      "date_published": "2026-07-22T19:17:29.347Z",
      "date_updated": "2026-07-23T15:02:01.333Z",
      "publisher": "mongodb",
      "title": "MongoDB $linearFill Window Function Improper Input Validation Leading to Process Termination",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22763
      },
      "nvd": {
        "published": "2026-07-22T20:16:44.670",
        "lastModified": "2026-07-23T16:17:13.517",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13065",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MongoDB accepts an incompatible sortBy expression for $linearFill and later dereferences absent state, terminating mongod.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-127280",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13066",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:09.471Z",
      "date_published": "2026-07-22T19:17:08.248Z",
      "date_updated": "2026-07-23T14:23:10.572Z",
      "publisher": "mongodb",
      "title": "Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14198
      },
      "nvd": {
        "published": "2026-07-22T20:16:44.813",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13066",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-127694",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 310,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13067",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:10.530Z",
      "date_published": "2026-07-22T19:16:38.192Z",
      "date_updated": "2026-07-24T03:56:10.776Z",
      "publisher": "mongodb",
      "title": "tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00067,
        "percentile": 0.00031
      },
      "nvd": {
        "published": "2026-07-22T20:16:44.967",
        "lastModified": "2026-07-24T05:16:37.480",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13067",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-128387",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13068",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:11.573Z",
      "date_published": "2026-07-22T19:16:13.320Z",
      "date_updated": "2026-07-23T14:22:24.271Z",
      "publisher": "mongodb",
      "title": "MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege Misuse",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04638
      },
      "nvd": {
        "published": "2026-07-22T20:16:45.127",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13068",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-128198",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 327,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13069",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:12.588Z",
      "date_published": "2026-07-22T19:15:38.360Z",
      "date_updated": "2026-07-23T14:21:57.230Z",
      "publisher": "mongodb",
      "title": "Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhaustion",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05277
      },
      "nvd": {
        "published": "2026-07-22T20:16:45.270",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13069",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A Queryable Encryption find payload supplies an unchecked loop-control field, allowing one authenticated request to drive excessive CPU work or memory allocation.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-127566",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13070",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:13.792Z",
      "date_published": "2026-07-22T19:15:15.612Z",
      "date_updated": "2026-07-23T14:21:38.437Z",
      "publisher": "mongodb",
      "title": "Improper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Termination",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00089,
        "percentile": 0.00494
      },
      "nvd": {
        "published": "2026-07-22T20:16:45.420",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13070",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted input reaches a path that dereferences a null pointer instead of rejecting the invalid state.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-128362",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13071",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:15.210Z",
      "date_published": "2026-07-22T19:14:51.157Z",
      "date_updated": "2026-07-23T14:21:17.900Z",
      "publisher": "mongodb",
      "title": "Server-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process Termination",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15833
      },
      "nvd": {
        "published": "2026-07-22T20:16:45.580",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13071",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The record maps the MongoDB aggregation-expression termination path to a use-after-free but does not identify the freed object or lifetime transition.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-128473",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13072",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:16.599Z",
      "date_published": "2026-07-22T19:14:15.681Z",
      "date_updated": "2026-07-24T03:56:09.965Z",
      "publisher": "mongodb",
      "title": "MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23888
      },
      "nvd": {
        "published": "2026-07-22T20:16:45.740",
        "lastModified": "2026-07-24T05:16:37.607",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13072",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Compute mode processes externally sourced BSON without sufficient structural validation and can corrupt process memory.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-128494",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 341,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13073",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:17.815Z",
      "date_published": "2026-07-22T19:13:55.339Z",
      "date_updated": "2026-07-23T14:20:26.110Z",
      "publisher": "mongodb",
      "title": "MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Termination",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11624
      },
      "nvd": {
        "published": "2026-07-22T20:16:45.900",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13073",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted aggregation reaches an assertion because engine selection and later processing disagree about the valid representation.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-128512",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13074",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:19.050Z",
      "date_published": "2026-07-22T19:13:33.148Z",
      "date_updated": "2026-07-23T14:20:01.397Z",
      "publisher": "mongodb",
      "title": "Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of Service",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17628
      },
      "nvd": {
        "published": "2026-07-22T20:16:46.057",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13074",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A parameter combination in awaitable hello exhaust mode enters an unthrottled response loop that consumes excessive CPU.",
        "basis": [
          "CNA record",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-128517",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13075",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:20.176Z",
      "date_published": "2026-07-22T19:13:04.440Z",
      "date_updated": "2026-07-23T14:19:39.485Z",
      "publisher": "mongodb",
      "title": "$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion Generation",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14516
      },
      "nvd": {
        "published": "2026-07-22T20:16:46.213",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13075",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MongoDB Server allocates or queues attacker-driven work without a per-request or per-connection limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-128316",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 280,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13076",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:21.245Z",
      "date_published": "2026-07-22T19:12:42.711Z",
      "date_updated": "2026-07-23T15:01:16.367Z",
      "publisher": "mongodb",
      "title": "Aggregation Framework Memory Exhaustion Leading to Process Termination",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14474
      },
      "nvd": {
        "published": "2026-07-22T20:16:46.367",
        "lastModified": "2026-07-23T16:17:13.630",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13076",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A conversion stage in an aggregation pipeline can allocate memory disproportionate to the input without an effective limit until the operating system kills the process.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-128584",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 385,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13077",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:22.313Z",
      "date_published": "2026-07-22T19:12:11.370Z",
      "date_updated": "2026-07-23T14:19:15.392Z",
      "publisher": "mongodb",
      "title": "Out-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn Data",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15374
      },
      "nvd": {
        "published": "2026-07-22T20:16:46.517",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13077",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MongoDB decompresses a malformed BSONColumn CodeWScope element and uses its unchecked size in pointer arithmetic, reading beyond the heap object.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-129103",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 504,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13078",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:00:23.432Z",
      "date_published": "2026-07-22T19:11:20.916Z",
      "date_updated": "2026-07-23T14:18:44.825Z",
      "publisher": "mongodb",
      "title": "Local File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.0021,
        "percentile": 0.1126
      },
      "nvd": {
        "published": "2026-07-22T20:16:46.650",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13078",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MongoDB registers a MozJS module loader that lets server-side scripts select and read arbitrary host files with mongod privileges.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jira.mongodb.org/browse/SERVER-128832",
          "host": "jira.mongodb.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13079",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:02:48.522Z",
      "date_published": "2026-07-02T23:07:30.489Z",
      "date_updated": "2026-07-07T03:56:26.251Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03637
      },
      "nvd": {
        "published": "2026-07-03T00:16:50.630",
        "lastModified": "2026-07-10T14:32:03.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13079",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Windows VPN client assigns excessive permissions to an undisclosed critical resource, enabling a local user to act with SYSTEM authority.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00027",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 312,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13080",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:08:34.576Z",
      "date_published": "2026-07-09T06:52:50.904Z",
      "date_updated": "2026-07-09T12:47:19.785Z",
      "publisher": "Wordfence",
      "title": "WPFunnels <= 3.12.7 - Authenticated (Administrator+) Local File Inclusion via 'logKey' Parameter",
      "affected": {
        "vendors": [
          "getwpfunnels"
        ],
        "products": [
          {
            "vendor": "getwpfunnels",
            "product": "WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0069,
        "percentile": 0.49248
      },
      "nvd": {
        "published": "2026-07-09T08:16:46.270",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13080",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell include path accepts an attacker-controlled filename that can select executable local content.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e48ce7d2-0c57-499a-81b6-2d9488de704c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.6/admin/modules/settings/class-wpfnl-settings.php#L709",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.6/admin/modules/settings/class-wpfnl-settings.php#L703",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.6/admin/modules/settings/class-wpfnl-settings.php#L181",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.6/vendor/philipnewcomer/wp-ajax-helper/src/components/Utility.php#L26",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.11.0/admin/modules/settings/class-wpfnl-settings.php#L709",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.11.0/admin/modules/settings/class-wpfnl-settings.php#L703",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.11.0/admin/modules/settings/class-wpfnl-settings.php#L181",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.11.0/vendor/philipnewcomer/wp-ajax-helper/src/components/Utility.php#L26",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3597260%40wpfunnels&new=3597260%40wpfunnels",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:17:08.243Z",
      "date_published": "2026-07-17T12:54:07.177Z",
      "date_updated": "2026-07-17T17:29:23.536Z",
      "publisher": "CPANSec",
      "title": "GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets",
      "affected": {
        "vendors": [
          "BURAK"
        ],
        "products": [
          {
            "vendor": "BURAK",
            "product": "GD::SecurityImage"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-804",
          "name": "Guessable CAPTCHA",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12118
      },
      "nvd": {
        "published": "2026-07-17T13:17:55.443",
        "lastModified": "2026-07-17T18:17:14.137",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13082",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CAPTCHA values are generated with Perl rand, whose predictable output is not suitable for an authentication challenge.",
        "basis": [
          "CNA",
          "CWE-338",
          "CWE-804"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-40916",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://security.metacpan.org/patches/G/GD-SecurityImage/1.75/CVE-2026-13082-r1.patch",
          "host": "security.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13084",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:23.985Z",
      "date_published": "2026-07-02T23:06:48.043Z",
      "date_updated": "2026-07-06T14:54:50.318Z",
      "publisher": "WatchGuard",
      "title": "Null Pointer Dereference in WatchGuard Fireware OS iked Process",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00495,
        "percentile": 0.39757
      },
      "nvd": {
        "published": "2026-07-03T00:16:50.767",
        "lastModified": "2026-07-06T18:41:14.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13084",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Fireware OS error path dereferences an object after allocation or lookup can return null.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00024",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13089",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:53:35.254Z",
      "date_published": "2026-07-22T20:31:23.693Z",
      "date_updated": "2026-07-27T17:33:19.516Z",
      "publisher": "CPANSec",
      "title": "OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify",
      "affected": {
        "vendors": [
          "RITOU"
        ],
        "products": [
          {
            "vendor": "RITOU",
            "product": "OIDC::Lite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15203
      },
      "nvd": {
        "published": "2026-07-22T21:17:12.743",
        "lastModified": "2026-07-27T18:16:51.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13089",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OIDC::Lite derives the accepted JWT algorithm from the untrusted token header, allowing unsigned or algorithm-confused ID tokens to pass signature verification.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://datatracker.ietf.org/doc/html/rfc8725#section-3.1",
          "host": "datatracker.ietf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/ritou/p5-oidc-lite/pull/31",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://security.metacpan.org/patches/O/OIDC-Lite/0.10/CVE-2026-13089-r1.patch",
          "host": "security.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/22/17",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1186,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T19:38:58.369Z",
      "date_published": "2026-07-16T16:49:00.662Z",
      "date_updated": "2026-07-16T17:45:15.555Z",
      "publisher": "lenovo",
      "title": "A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.",
      "affected": {
        "vendors": [
          "Lenovo"
        ],
        "products": [
          {
            "vendor": "Lenovo",
            "product": "App Store"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03204
      },
      "nvd": {
        "published": "2026-07-16T17:16:54.950",
        "lastModified": "2026-07-16T18:16:42.060",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13103",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says App Store accepts a filesystem or upload target outside its intended namespace, while the path field and selection check are not public.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://iknow.lenovo.com.cn/detail/441419",
          "host": "iknow.lenovo.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13104",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T19:38:58.998Z",
      "date_published": "2026-07-16T16:49:06.878Z",
      "date_updated": "2026-07-16T17:38:29.523Z",
      "publisher": "lenovo",
      "title": "A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges.",
      "affected": {
        "vendors": [
          "Lenovo"
        ],
        "products": [
          {
            "vendor": "Lenovo",
            "product": "App Store"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-250",
          "name": "Execution with Unnecessary Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01587
      },
      "nvd": {
        "published": "2026-07-16T17:16:55.090",
        "lastModified": "2026-07-16T18:16:42.170",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13104",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Lenovo reports a privileged-code path for a local authenticated user but does not publish the privileged component or failed check.",
        "basis": [
          "CNA",
          "CWE-250"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://iknow.lenovo.com.cn/detail/441419",
          "host": "iknow.lenovo.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13110",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T20:01:33.470Z",
      "date_published": "2026-07-28T11:32:50.046Z",
      "date_updated": "2026-07-28T14:53:31.614Z",
      "publisher": "Wordfence",
      "title": "StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action",
      "affected": {
        "vendors": [
          "wedevs"
        ],
        "products": [
          {
            "vendor": "wedevs",
            "product": "StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14485
      },
      "nvd": {
        "published": "2026-07-28T12:16:35.210",
        "lastModified": "2026-07-28T16:17:27.170",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13110",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The unauthenticated AJAX handler treats a nonce published on every front-end page as authorization and performs no capability check before changing BOGO settings.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b0d4c009-d969-49bb-a56b-a704e5f89a86?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/bogo/includes/Ajax.php#L223",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/bogo/includes/Ajax.php#L31",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/bogo/includes/EnqueueScript.php#L177",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3619581%40storegrowth-sales-booster&new=3619581%40storegrowth-sales-booster",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13113",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T20:33:43.206Z",
      "date_published": "2026-07-29T19:00:31.041Z",
      "date_updated": "2026-07-29T19:43:09.825Z",
      "publisher": "GitLab",
      "title": "Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.002,
        "percentile": 0.10094
      },
      "nvd": {
        "published": "2026-07-29T20:17:00.550",
        "lastModified": "2026-08-03T13:29:14.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13113",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Two concurrent approval paths can both observe an unapproved GitLab state and commit conflicting approval results without serializing the transition.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/597838",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 327,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13114",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T20:48:10.695Z",
      "date_published": "2026-07-11T02:31:19.945Z",
      "date_updated": "2026-07-13T14:26:22.984Z",
      "publisher": "Wordfence",
      "title": "Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment Content and User Biographical Info",
      "affected": {
        "vendors": [
          "stylemix"
        ],
        "products": [
          {
            "vendor": "stylemix",
            "product": "Motors – Car Dealership & Classified Listings Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16036
      },
      "nvd": {
        "published": "2026-07-11T04:17:16.650",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13114",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f4e25aa6-8028-4c85-98c4-6f47a1502427?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.112/assets/js/listing-manager/libs/tooltip.js#L59",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.112/assets/js/listing-manager/libs/tooltip.js#L73",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.112/includes/helpers.php#L278",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.108/assets/js/listing-manager/libs/tooltip.js#L59",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.108/assets/js/listing-manager/libs/tooltip.js#L73",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.108/includes/helpers.php#L278",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3594971/motors-car-dealership-classified-listings",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13116",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T20:49:36.674Z",
      "date_published": "2026-07-11T03:44:22.778Z",
      "date_updated": "2026-07-13T14:25:51.519Z",
      "publisher": "Wordfence",
      "title": "PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute",
      "affected": {
        "vendors": [
          "wpovernight"
        ],
        "products": [
          {
            "vendor": "wpovernight",
            "product": "PDF Invoices & Packing Slips for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14683
      },
      "nvd": {
        "published": "2026-07-11T05:16:32.123",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13116",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PDF Invoices & Packing Slips for WooCommerce resolves a caller-controlled object identifier without binding the selected object to the caller's authorized scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6525195e-5d90-4dd4-b9ee-612a8295c262?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-pdf-invoices-packing-slips/tags/5.14.0/includes/Frontend.php#L284",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-pdf-invoices-packing-slips/tags/5.14.0/includes/Frontend.php#L271",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-pdf-invoices-packing-slips/tags/5.14.0/includes/Endpoint.php#L111",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-pdf-invoices-packing-slips/tags/5.9.2/includes/Frontend.php#L284",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-pdf-invoices-packing-slips/tags/5.9.2/includes/Frontend.php#L271",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-pdf-invoices-packing-slips/tags/5.9.2/includes/Endpoint.php#L111",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3590578%40woocommerce-pdf-invoices-packing-slips&new=3590578%40woocommerce-pdf-invoices-packing-slips",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 961,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13117",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T21:02:48.228Z",
      "date_published": "2026-07-30T16:32:42.271Z",
      "date_updated": "2026-07-30T18:08:24.623Z",
      "publisher": "OpenVPN",
      "title": "An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage",
      "affected": {
        "vendors": [
          "OpenVPN"
        ],
        "products": [
          {
            "vendor": "OpenVPN",
            "product": "OpenVPN"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@openvpn.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29303
      },
      "nvd": {
        "published": "2026-07-30T17:16:28.580",
        "lastModified": "2026-07-30T19:17:05.793",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13117",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An incomplete guard during TLS session promotion permits a session object to be used after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.openvpn.net/Security%20Announcements/CVE-2026-13117",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://community.openvpn.net/ReleaseHistory#openvpn-275-released-1-july-2026",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://community.openvpn.net/ReleaseHistory#openvpn-2621-released-1-july-2026",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13119",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T21:20:39.885Z",
      "date_published": "2026-07-23T09:33:57.977Z",
      "date_updated": "2026-07-23T13:36:30.521Z",
      "publisher": "Wordfence",
      "title": "Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' Parameter",
      "affected": {
        "vendors": [
          "roundupwp"
        ],
        "products": [
          {
            "vendor": "roundupwp",
            "product": "Registrations for the Events Calendar – Event Registration Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16263
      },
      "nvd": {
        "published": "2026-07-23T10:16:49.527",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13119",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The plugin interpolates attacker-controlled JSON keys as SQL column identifiers even though its escaping routine does not neutralize identifier grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/630cc68e-102e-4e05-98ff-94de434a10ae?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/registrations-for-the-events-calendar/tags/3.2/includes/admin/class-rtec-db-admin.php#L84",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/registrations-for-the-events-calendar/tags/3.2/includes/admin/admin-functions.php#L724",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/registrations-for-the-events-calendar/tags/3.2/includes/admin/admin-functions.php#L774",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3599275%40registrations-for-the-events-calendar&new=3599275%40registrations-for-the-events-calendar",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1010,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13122",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T22:11:24.264Z",
      "date_published": "2026-07-06T14:32:29.371Z",
      "date_updated": "2026-07-06T15:51:50.731Z",
      "publisher": "OpenVPN",
      "title": "OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled",
      "affected": {
        "vendors": [
          "Openvpn"
        ],
        "products": [
          {
            "vendor": "Openvpn",
            "product": "OpenVPN"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@openvpn.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21638
      },
      "nvd": {
        "published": "2026-07-06T16:16:28.677",
        "lastModified": "2026-07-09T13:06:19.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13122",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Malformed external-auth tokens can reach a process-terminating assertion instead of being rejected as ordinary invalid input.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.openvpn.net/Security%20Announcements/CVE-2026-13122",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13125",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T00:32:34.362Z",
      "date_published": "2026-07-02T02:14:22.167Z",
      "date_updated": "2026-07-02T12:30:01.650Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14819
      },
      "nvd": {
        "published": "2026-07-02T04:17:09.790",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13125",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The local WebSocket server exposes screen-capture and other sensitive methods without authenticating the connecting client.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2370",
          "host": "www.talosintelligence.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 700,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13126",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:45.197Z",
      "date_published": "2026-07-08T07:36:37.927Z",
      "date_updated": "2026-07-08T12:13:27.791Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06065
      },
      "nvd": {
        "published": "2026-07-08T09:16:29.307",
        "lastModified": "2026-07-09T14:20:52.397",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13126",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Foxit writes through a pop-up annotation object after embedded JavaScript has invalidated it by deleting its page.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13127",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:48.781Z",
      "date_published": "2026-07-08T07:36:36.349Z",
      "date_updated": "2026-07-08T12:13:59.482Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01884
      },
      "nvd": {
        "published": "2026-07-08T09:16:29.440",
        "lastModified": "2026-07-09T13:14:33.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13127",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Foxit PDF Editor, code retains or reuses an object after the lifetime transition that frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13128",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:51.769Z",
      "date_published": "2026-07-08T07:36:34.775Z",
      "date_updated": "2026-07-08T12:14:25.870Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Doc Object Use-After-Free Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01884
      },
      "nvd": {
        "published": "2026-07-08T09:16:29.557",
        "lastModified": "2026-07-09T13:19:07.903",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13128",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Foxit PDF Editor retains or reuses an object after its storage has been freed, allowing later processing to access invalid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13129",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:54.524Z",
      "date_published": "2026-07-08T07:36:30.034Z",
      "date_updated": "2026-07-08T13:20:30.258Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01884
      },
      "nvd": {
        "published": "2026-07-08T09:16:29.673",
        "lastModified": "2026-07-09T13:19:45.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13129",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Traversal of a damaged PDF field tree leaves Foxit holding an invalid form object that is later dereferenced through the field property path.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13131",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:08.013Z",
      "date_published": "2026-07-02T02:14:52.655Z",
      "date_updated": "2026-07-02T12:30:29.606Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12675
      },
      "nvd": {
        "published": "2026-07-02T04:17:11.520",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13131",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoWebPlayer uses an attacker-controlled array index without confirming that it falls within the target array.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 785,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13132",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:09.196Z",
      "date_published": "2026-07-02T02:17:15.274Z",
      "date_updated": "2026-07-02T12:31:38.542Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12674
      },
      "nvd": {
        "published": "2026-07-02T04:17:11.643",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13132",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoWebPlayer uses an unchecked command index to address several arrays and can therefore read or operate outside their bounds.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 784,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13142",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T08:44:44.198Z",
      "date_published": "2026-07-20T06:00:04.577Z",
      "date_updated": "2026-07-21T12:29:23.688Z",
      "publisher": "WPScan",
      "title": "Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeover via Email OTP Brute Force",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Social Login, Passkeys, Magic Link & Email OTP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13435
      },
      "nvd": {
        "published": "2026-07-20T07:16:35.483",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13142",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The email OTP verifier has no effective rate limit or attempt lockout for its short numeric code space.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/a34d9be7-c121-4c95-9ebb-a14c763e16bb/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T09:11:33.920Z",
      "date_published": "2026-07-30T06:00:11.267Z",
      "date_updated": "2026-07-30T16:05:27.697Z",
      "publisher": "WPScan",
      "title": "WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Travel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12728
      },
      "nvd": {
        "published": "2026-07-30T06:24:58.817",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13143",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "WP Travel marks a booking paid without verifying the PayPal IPN through PayPal's post-back authenticity handshake.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/21bc82e3-4568-4e01-8704-88a242743402/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 324,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T09:11:38.724Z",
      "date_published": "2026-07-30T06:00:11.442Z",
      "date_updated": "2026-07-30T16:10:28.422Z",
      "publisher": "WPScan",
      "title": "WP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Travel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09644
      },
      "nvd": {
        "published": "2026-07-30T06:24:58.953",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13145",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/f70172b6-0a55-4b99-8b3c-8170224938bb/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T09:16:56.966Z",
      "date_published": "2026-07-20T06:00:04.766Z",
      "date_updated": "2026-07-20T13:13:37.074Z",
      "publisher": "WPScan",
      "title": "Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Kirki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16815
      },
      "nvd": {
        "published": "2026-07-20T07:16:35.580",
        "lastModified": "2026-07-20T20:39:31.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13147",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/f39c3e35-8673-4095-a829-a9ec2624f66c/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13151",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-24T10:43:58.146Z",
      "date_published": "2026-07-08T20:46:18.853Z",
      "date_rejected": "2026-08-03T19:20:53.868Z",
      "date_updated": "2026-08-03T19:20:53.868Z",
      "publisher": "GitLab",
      "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
      "rejected_reason": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority."
    },
    {
      "cve_id": "CVE-2026-13152",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T11:18:39.061Z",
      "date_published": "2026-07-27T06:00:02.376Z",
      "date_updated": "2026-07-27T16:10:30.612Z",
      "publisher": "WPScan",
      "title": "Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Custom Fields Account Registration For Woocommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13434
      },
      "nvd": {
        "published": "2026-07-27T07:16:24.697",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13152",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/36aaba38-3143-4e80-8386-748632ff6704/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 378,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13156",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:02:09.353Z",
      "date_published": "2026-07-20T06:00:04.943Z",
      "date_updated": "2026-07-20T13:12:25.616Z",
      "publisher": "WPScan",
      "title": "MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "MailerSend"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03013
      },
      "nvd": {
        "published": "2026-07-20T07:16:35.687",
        "lastModified": "2026-07-20T20:39:31.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13156",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MailerSend configuration-delete action checks manage_options but omits its nonce check, allowing a forged administrator request to erase SMTP settings and deactivate the plugin.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/595e653d-0904-43cf-8e61-d684599de11b/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 435,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13161",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:17:38.257Z",
      "date_published": "2026-07-28T08:34:36.428Z",
      "date_updated": "2026-07-28T16:09:40.557Z",
      "publisher": "Wordfence",
      "title": "TrueBooker <= 1.2.2 - Unauthenticated SQL Injection",
      "affected": {
        "vendors": [
          "themetechmount"
        ],
        "products": [
          {
            "vendor": "themetechmount",
            "product": "TrueBooker – Appointment Booking and Scheduler System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00454,
        "percentile": 0.37169
      },
      "nvd": {
        "published": "2026-07-28T09:16:41.220",
        "lastModified": "2026-07-28T16:17:27.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13161",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9b0e973b-f0bf-44d1-b964-e259f68291aa?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/truebooker-appointment-booking/tags/1.2.0/main/function_ajax.php#L14866",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/truebooker-appointment-booking/tags/1.2.2/main/function_ajax.php#L14866",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/truebooker-appointment-booking/tags/1.2.2/main/function_ajax.php#L14741",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/truebooker-appointment-booking/tags/1.2.2/main/function_ajax.php#L14756",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/truebooker-appointment-booking/tags/1.2.0/main/function_ajax.php#L14741",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/truebooker-appointment-booking/tags/1.2.0/main/function_ajax.php#L14756",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3591506%40truebooker-appointment-booking%2Ftrunk%2Fmain%2Ffunction_ajax.php&old=3581699%40truebooker-appointment-booking%2Ftrunk%2Fmain%2Ffunction_ajax.php&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 926,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13178",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:26:32.708Z",
      "date_published": "2026-07-30T06:00:11.616Z",
      "date_updated": "2026-07-30T17:09:31.310Z",
      "publisher": "WPScan",
      "title": "Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Eventin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16837
      },
      "nvd": {
        "published": "2026-07-30T06:24:59.060",
        "lastModified": "2026-07-30T19:17:05.937",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13178",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Eventin resolves a caller-controlled object identifier without binding the selected object to the caller's authorized scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/09d6135f-b38c-4cfe-8a9f-5d79552c720c/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13181",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:46:36.671Z",
      "date_published": "2026-07-22T13:33:18.348Z",
      "date_updated": "2026-07-24T03:55:59.737Z",
      "publisher": "ProgressSoftware",
      "title": "RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00452,
        "percentile": 0.3704
      },
      "nvd": {
        "published": "2026-07-22T14:17:13.553",
        "lastModified": "2026-07-24T05:16:37.733",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13181",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Forged upload metadata controls AsyncUploadTypeName resolution and permits an attacker-selected runtime type to be instantiated.",
        "basis": [
          "CNA",
          "CWE-470"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rau-asyncuploadtypename-deserialization-CVE-2026-13181",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13182",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:46:37.358Z",
      "date_published": "2026-07-22T13:34:57.272Z",
      "date_updated": "2026-07-22T19:14:47.505Z",
      "publisher": "ProgressSoftware",
      "title": "RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22119
      },
      "nvd": {
        "published": "2026-07-22T14:17:13.683",
        "lastModified": "2026-07-22T20:16:46.913",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13182",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Distinguishable decryption and invalid-JSON errors reveal a cryptographic validity oracle.",
        "basis": [
          "CNA",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rau-padding-oracle-cve-2026-13182",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:46:38.096Z",
      "date_published": "2026-07-22T13:36:08.274Z",
      "date_updated": "2026-07-22T19:15:06.321Z",
      "publisher": "ProgressSoftware",
      "title": "RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.2212
      },
      "nvd": {
        "published": "2026-07-22T14:17:13.807",
        "lastModified": "2026-07-22T20:16:47.030",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13183",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RadAsyncUpload metadata validation produces measurable timing differences that reveal cryptographic validity.",
        "basis": [
          "CNA record",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rau-timing-oracle-CVE-2026-13183",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:46:38.790Z",
      "date_published": "2026-07-22T13:37:11.804Z",
      "date_updated": "2026-07-22T19:14:27.027Z",
      "publisher": "ProgressSoftware",
      "title": "RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-321",
          "name": "Use of Hard-coded Cryptographic Key",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10278
      },
      "nvd": {
        "published": "2026-07-22T14:17:13.927",
        "lastModified": "2026-07-22T20:16:47.143",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13184",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Telerik UI for ASP.NET AJAX relies on a built-in cryptographic key that an attacker can know or predict.",
        "basis": [
          "CNA",
          "CWE-321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rau-unauth-deserialization-chain-cve-2026-13184",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13185",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:46:39.507Z",
      "date_published": "2026-07-22T13:38:17.195Z",
      "date_updated": "2026-07-24T03:56:00.738Z",
      "publisher": "ProgressSoftware",
      "title": "PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAX",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00452,
        "percentile": 0.37078
      },
      "nvd": {
        "published": "2026-07-22T14:17:14.057",
        "lastModified": "2026-07-24T05:16:37.867",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13185",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ASP.NET component deserializes attacker-controlled persistence-cookie data as executable object state.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-persistence-cookie-deserialization-CVE-2026-13185",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13186",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:46:40.240Z",
      "date_published": "2026-07-22T13:39:14.908Z",
      "date_updated": "2026-07-24T03:56:01.638Z",
      "publisher": "ProgressSoftware",
      "title": "AppDataStorageProvider Path Traversal Deserialization Vulnerability in Telerik UI for ASP.NET AJAX",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00495,
        "percentile": 0.39816
      },
      "nvd": {
        "published": "2026-07-22T14:17:14.180",
        "lastModified": "2026-07-24T05:16:37.993",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13186",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file-backed AppDataStorageProvider derives a persistence path from an attacker-controlled storage key without containment, selecting a serialized file outside the intended store.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-appdata-path-traversal-deserialization-CVE-2026-13186",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 282,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:46:41.002Z",
      "date_published": "2026-07-22T13:40:21.443Z",
      "date_updated": "2026-07-24T03:56:03.170Z",
      "publisher": "ProgressSoftware",
      "title": "DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAX",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24109
      },
      "nvd": {
        "published": "2026-07-22T14:17:14.300",
        "lastModified": "2026-07-24T05:16:38.127",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13187",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An externally controlled provider type selects a class or code path without an allowlist of permitted implementations.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-470"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-dialoghandler-provider-type-tampering-CVE-2026-13187",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:46:41.850Z",
      "date_published": "2026-07-22T13:41:29.942Z",
      "date_updated": "2026-07-22T19:12:15.521Z",
      "publisher": "ProgressSoftware",
      "title": "DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00111,
        "percentile": 0.0154
      },
      "nvd": {
        "published": "2026-07-22T14:17:14.417",
        "lastModified": "2026-07-22T20:16:47.617",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13188",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "DialogHandler accepts request parameters that are not bound to authenticated server-side dialog state, although the affected parameters and state transition are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-dialoghandler-parameters-tampering-CVE-2026-13188",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13189",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:46:42.510Z",
      "date_published": "2026-07-22T13:42:19.375Z",
      "date_updated": "2026-07-22T19:11:54.445Z",
      "publisher": "ProgressSoftware",
      "title": "SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-36",
          "name": "Absolute Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26109
      },
      "nvd": {
        "published": "2026-07-22T14:17:14.537",
        "lastModified": "2026-07-22T20:16:47.747",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13189",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Telerik UI for ASP.NET AJAX path accepts an attacker-controlled path that can escape the intended filesystem root.",
        "basis": [
          "CNA",
          "CWE-36"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-spellchecker-dictionarylanguage-path-traversal-CVE-2026-13189",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13190",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:46:43.300Z",
      "date_published": "2026-07-22T13:43:12.374Z",
      "date_updated": "2026-07-24T03:56:04.216Z",
      "publisher": "ProgressSoftware",
      "title": "PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00452,
        "percentile": 0.3704
      },
      "nvd": {
        "published": "2026-07-22T14:17:14.667",
        "lastModified": "2026-07-24T05:16:38.253",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13190",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted serialized type metadata can instantiate attacker-selected classes during decoding.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-persistence-framework-unsafe-type-resolution-CVE-2026-13190",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:46:44.046Z",
      "date_published": "2026-07-22T13:44:14.027Z",
      "date_updated": "2026-07-22T19:10:33.166Z",
      "publisher": "ProgressSoftware",
      "title": "RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15672
      },
      "nvd": {
        "published": "2026-07-22T14:17:14.777",
        "lastModified": "2026-07-22T20:16:47.983",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13192",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Telerik UI for ASP.NET AJAX request path accepts an attacker-controlled destination or redirect without constraining the resolved server-side network target.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-radeditor-pdf-export-ssrf-CVE-2026-13192",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13199",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:50:43.732Z",
      "date_published": "2026-07-07T08:36:57.330Z",
      "date_updated": "2026-07-07T13:22:19.318Z",
      "publisher": "Nozomi",
      "title": "Insufficient Entropy in Raspberry Pi 5 and Compute Module 5",
      "affected": {
        "vendors": [
          "Raspberry Pi"
        ],
        "products": [
          {
            "vendor": "Raspberry Pi",
            "product": "Raspberry Pi 5 and Compute Module 5"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-331",
          "name": "Insufficient Entropy",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01754
      },
      "nvd": {
        "published": "2026-07-07T09:16:29.857",
        "lastModified": "2026-07-07T14:16:28.447",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13199",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Raspberry Pi EEPROM firmware emits predictable KASLR and RNG seeds instead of collecting sufficient entropy.",
        "basis": [
          "CNA",
          "CWE-331"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/raspberrypi/rpi-eeprom/pull/841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-13199",
          "host": "www.nozominetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 400,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13204",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T14:12:52.934Z",
      "date_published": "2026-07-22T14:15:30.557Z",
      "date_updated": "2026-07-22T18:52:12.584Z",
      "publisher": "isc",
      "title": "Unexpected exit in certain situations with NSEC and NSEC3 both present",
      "affected": {
        "vendors": [
          "ISC"
        ],
        "products": [
          {
            "vendor": "ISC",
            "product": "BIND 9"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-officer@isc.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00509,
        "percentile": 0.40634
      },
      "nvd": {
        "published": "2026-07-22T15:16:52.080",
        "lastModified": "2026-07-22T20:33:11.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13204",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.isc.org/docs/cve-2026-13204",
          "host": "kb.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.20.26",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.21.24",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 392,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-13211",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T15:07:32.597Z",
      "date_published": "2026-07-01T15:46:25.174Z",
      "date_updated": "2026-07-01T17:47:08.068Z",
      "publisher": "sba-research",
      "title": "Genucenter Disclosure of SNMP Credentials",
      "affected": {
        "vendors": [
          "genua"
        ],
        "products": [
          {
            "vendor": "genua",
            "product": "genucenter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03712
      },
      "nvd": {
        "published": "2026-07-01T17:16:19.740",
        "lastModified": "2026-07-02T18:45:21.210",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13211",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The genucenter web interface includes SNMP authentication and encryption keys in HTTP responses sent to Service and Admin roles.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260424-01_Genucenter_Disclosure_of_SNMP_Credentials",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13221",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T15:38:41.010Z",
      "date_published": "2026-07-13T15:40:11.035Z",
      "date_updated": "2026-07-14T13:33:18.189Z",
      "publisher": "CPANSec",
      "title": "Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk",
      "affected": {
        "vendors": [
          "SHAY"
        ],
        "products": [
          {
            "vendor": "SHAY",
            "product": "perl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35574
      },
      "nvd": {
        "published": "2026-07-13T17:16:48.923",
        "lastModified": "2026-07-14T18:15:18.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13221",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Perl_study_chunk stores a trie branch delta in 16 bits, so more than 65,535 fixed alternatives truncate the match-decision table.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/Perl/perl5/issues/23388",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "issue-tracking"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/13/5",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 676,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13228",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T16:43:26.354Z",
      "date_published": "2026-07-01T09:32:28.123Z",
      "date_updated": "2026-07-01T15:33:25.338Z",
      "publisher": "Wordfence",
      "title": "LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter",
      "affected": {
        "vendors": [
          "latepoint"
        ],
        "products": [
          {
            "vendor": "latepoint",
            "product": "LatePoint – Calendar Booking Plugin for Appointments and Events"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22271
      },
      "nvd": {
        "published": "2026-07-01T11:16:25.377",
        "lastModified": "2026-07-01T17:16:19.873",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13228",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "LatePoint lets a caller change another user's email through an object identifier and then use the roleless login flow, because neither step binds the target account to the caller.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8f9db3b8-dd37-4d8b-b041-50b453858a39?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/controllers/orders_controller.php#L127",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/controllers/orders_controller.php#L137",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/helpers/auth_helper.php#L256",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/latepoint/tags/5.6.2/lib/controllers/orders_controller.php#L112",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3590914/latepoint/trunk/lib/controllers/orders_controller.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Flatepoint/tags/5.6.3&new_path=%2Flatepoint/tags/5.6.4",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 830,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13230",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T17:50:08.263Z",
      "date_published": "2026-07-15T00:21:16.177Z",
      "date_updated": "2026-07-15T12:37:09.376Z",
      "publisher": "TPLink",
      "title": "Information Disclosure Vulnerability in Local Discovery Response in TP-Link Kasa EC70 and EC71",
      "affected": {
        "vendors": [
          "TP-Link Systems Inc."
        ],
        "products": [
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "Kasa EC71 v4"
          },
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "Kasa EC70 v4"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f23511db-6c3e-4e32-a477-6aa17d310630",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.1767
      },
      "nvd": {
        "published": "2026-07-15T01:16:14.620",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13230",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Sensitive data is returned, stored, or left readable through an output path that lacks the required disclosure boundary.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tp-link.com/us/support/download/ec71/#Firmware-Release-Notes",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/en/support/download/ec71/#Firmware-Release-Notes",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/en/support/download/ec70/v4/#Firmware-Release-Notes",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/faq/5192/",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 429,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13231",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:04.919Z",
      "date_published": "2026-07-10T21:44:37.716Z",
      "date_updated": "2026-07-13T16:39:58.503Z",
      "publisher": "drupal",
      "title": "Advanced Content Feedback (aka admin_feedback) - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-051",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Advanced Content Feedback (aka admin_feedback)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07881
      },
      "nvd": {
        "published": "2026-07-10T22:16:39.187",
        "lastModified": "2026-07-13T17:16:49.043",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13231",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Advanced Content Feedback (aka admin_feedback) page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-051",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:05.703Z",
      "date_published": "2026-07-10T21:44:38.621Z",
      "date_updated": "2026-07-13T18:04:11.237Z",
      "publisher": "drupal",
      "title": "Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access bypass / Insecure Direct Object Reference (IDOR) - SA-CONTRIB-2026-052",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Advanced Content Feedback (aka admin_feedback)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.0584
      },
      "nvd": {
        "published": "2026-07-10T22:16:39.297",
        "lastModified": "2026-07-13T19:16:38.567",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13232",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The feedback module permits forceful browsing of an object without a sufficient authorization check, but the exact object binding is not public.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-052",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13233",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:06.786Z",
      "date_published": "2026-07-10T21:44:39.537Z",
      "date_updated": "2026-07-13T18:08:13.043Z",
      "publisher": "drupal",
      "title": "OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONTRIB-2026-053",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "OpenAI Provider"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10541
      },
      "nvd": {
        "published": "2026-07-10T22:16:39.397",
        "lastModified": "2026-07-13T19:16:39.387",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13233",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Drupal provider lets an attacker control an outbound request destination without enforcing the intended server-side destination policy.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-053",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13234",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:07.754Z",
      "date_published": "2026-07-10T21:44:40.400Z",
      "date_updated": "2026-07-13T16:35:59.372Z",
      "publisher": "drupal",
      "title": "AI (Artificial Intelligence) - Moderately critical - Information Disclosure / Cross-site Scripting - SA-CONTRIB-2026-054",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "AI (Artificial Intelligence)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07882
      },
      "nvd": {
        "published": "2026-07-10T22:16:39.500",
        "lastModified": "2026-07-13T17:16:51.200",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13234",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The Drupal AI module emits attacker-controlled content as executable browser markup, although the exact source and sink are not public.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-054",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13235",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:08.720Z",
      "date_published": "2026-07-10T21:44:41.284Z",
      "date_updated": "2026-07-13T18:06:50.932Z",
      "publisher": "drupal",
      "title": "AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "AI (Artificial Intelligence)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05708
      },
      "nvd": {
        "published": "2026-07-10T22:16:39.597",
        "lastModified": "2026-07-16T15:07:50.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13235",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The AI (Artificial Intelligence) operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-055",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13236",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:09.667Z",
      "date_published": "2026-07-10T21:44:42.158Z",
      "date_updated": "2026-07-13T18:05:21.307Z",
      "publisher": "drupal",
      "title": "AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "AI Agents"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04271
      },
      "nvd": {
        "published": "2026-07-10T22:16:39.700",
        "lastModified": "2026-07-16T19:33:30.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13236",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "AI Agents exposes functionality without the required authorization, but the public record does not name the endpoint or missing permission check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-056",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13237",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:10.666Z",
      "date_published": "2026-07-10T21:44:43.053Z",
      "date_updated": "2026-07-13T17:59:44.338Z",
      "publisher": "drupal",
      "title": "AI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "AI Agents"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06435
      },
      "nvd": {
        "published": "2026-07-10T22:16:39.797",
        "lastModified": "2026-07-16T19:33:07.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13237",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that AI Agents permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-057",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13238",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:11.427Z",
      "date_published": "2026-07-10T21:44:51.275Z",
      "date_updated": "2026-07-13T18:00:23.950Z",
      "publisher": "drupal",
      "title": "Commerce Realex / Global Payments - Moderately critical - Access Bypass - SA-CONTRIB-2026-058",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Commerce Realex / Global Payments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03625
      },
      "nvd": {
        "published": "2026-07-10T22:16:39.900",
        "lastModified": "2026-07-13T19:16:42.123",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13238",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Commerce Realex / Global Payments fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-058",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13239",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:12.360Z",
      "date_published": "2026-07-10T21:44:52.141Z",
      "date_updated": "2026-07-13T18:01:25.722Z",
      "publisher": "drupal",
      "title": "WissKI - Critical - Access bypass - SA-CONTRIB-2026-059",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "WissKI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05565
      },
      "nvd": {
        "published": "2026-07-10T22:16:40.010",
        "lastModified": "2026-07-13T19:16:42.790",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13239",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "WissKI administrative content is reachable by direct navigation without the authorization check required for the requested operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-059",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 135,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13240",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:13.250Z",
      "date_published": "2026-07-10T21:44:53.011Z",
      "date_updated": "2026-07-13T18:02:03.735Z",
      "publisher": "drupal",
      "title": "Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Paragraphs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05566
      },
      "nvd": {
        "published": "2026-07-10T22:16:40.113",
        "lastModified": "2026-07-21T14:21:55.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13240",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in Paragraphs, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-060",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 144,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13241",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:14.145Z",
      "date_published": "2026-07-10T21:44:53.879Z",
      "date_updated": "2026-07-13T18:02:48.642Z",
      "publisher": "drupal",
      "title": "Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Paragraphs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05565
      },
      "nvd": {
        "published": "2026-07-10T22:16:40.217",
        "lastModified": "2026-07-21T14:21:51.910",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13241",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "high",
        "mechanism": "Paragraphs permits forceful browsing to content without applying the required authorization check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-061",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 144,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13242",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:15.050Z",
      "date_published": "2026-07-10T21:44:54.721Z",
      "date_updated": "2026-07-13T16:05:20.863Z",
      "publisher": "drupal",
      "title": "Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Geolocation Field"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06179
      },
      "nvd": {
        "published": "2026-07-10T22:16:40.320",
        "lastModified": "2026-07-13T17:16:57.690",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13242",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Geolocation Field module allows attacker-controlled syntax to alter an SQL query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-062",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:16.032Z",
      "date_published": "2026-07-10T21:44:55.591Z",
      "date_updated": "2026-07-13T17:53:29.708Z",
      "publisher": "drupal",
      "title": "Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-063",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Salesforce Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0009,
        "percentile": 0.00539
      },
      "nvd": {
        "published": "2026-07-10T22:16:40.420",
        "lastModified": "2026-07-13T19:16:44.843",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13243",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Drupal Salesforce Suite accepts a cross-site request, but the record does not identify the state-changing action or missing request-verification check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-063",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13244",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:00:17.008Z",
      "date_published": "2026-07-10T21:46:14.260Z",
      "date_updated": "2026-07-13T17:55:31.975Z",
      "publisher": "drupal",
      "title": "Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026-064",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Tealium iQ Tag Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15541
      },
      "nvd": {
        "published": "2026-07-10T22:16:40.523",
        "lastModified": "2026-07-13T19:16:45.523",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13244",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled Drupal data can modify dynamically selected object attributes during deserialization, enabling PHP object injection.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-064",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:03:05.183Z",
      "date_published": "2026-07-01T03:43:33.891Z",
      "date_updated": "2026-07-01T10:42:12.021Z",
      "publisher": "Wordfence",
      "title": "GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute",
      "affected": {
        "vendors": [
          "stellarwp"
        ],
        "products": [
          {
            "vendor": "stellarwp",
            "product": "GiveWP – Donation Plugin and Fundraising Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.1609
      },
      "nvd": {
        "published": "2026-07-01T05:16:18.333",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13246",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This is due to insufficient input sanitization and output escaping on user supplied attributes in CampaignCommentsShortcode::parseAttributes() and BlockRenderController::render(), where the blockId value is interpolated directly into a single-quoted HTML attribute without esc_attr().",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/08f8f489-6b31-45d8-a122-bbaa283a2b10?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/trunk/src/Campaigns/Blocks/CampaignComments/Controller/BlockRenderController.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/trunk/src/Campaigns/Shortcodes/CampaignCommentsShortcode.php#L78",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/trunk/src/Campaigns/Shortcodes/CampaignCommentsShortcode.php#L17",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/trunk/src/Campaigns/Actions/RegisterCampaignShortcodes.php#L30",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/trunk/src/Campaigns/Blocks/CampaignComments/render.php#L20",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Campaigns/Blocks/CampaignComments/Controller/BlockRenderController.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Campaigns/Shortcodes/CampaignCommentsShortcode.php#L78",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Campaigns/Shortcodes/CampaignCommentsShortcode.php#L17",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Campaigns/Actions/RegisterCampaignShortcodes.php#L30",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Campaigns/Blocks/CampaignComments/render.php#L20",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3590193%40give&new=3590193%40give&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 732,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13247",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:04:09.293Z",
      "date_published": "2026-07-10T09:32:45.117Z",
      "date_updated": "2026-07-10T17:01:18.179Z",
      "publisher": "Wordfence",
      "title": "Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter",
      "affected": {
        "vendors": [
          "logichunt"
        ],
        "products": [
          {
            "vendor": "logichunt",
            "product": "Logo Slider WP – Responsive Logo Carousel, Logo Gallery & Logo Showcase"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08612
      },
      "nvd": {
        "published": "2026-07-10T10:16:23.137",
        "lastModified": "2026-07-10T17:16:53.610",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13247",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dd321fd7-1f3a-4d1c-b832-69423a35fad5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/logo-slider-wp/trunk/public/partials/template/view-default.php#L43",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/logo-slider-wp/trunk/public/partials/view-controller.php#L66",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/logo-slider-wp/trunk/admin/class-logo-slider-wp-admin.php#L996",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3601263%40logo-slider-wp&new=3601263%40logo-slider-wp",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 486,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13250",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:06:44.195Z",
      "date_published": "2026-07-11T03:44:24.117Z",
      "date_updated": "2026-07-13T14:39:47.367Z",
      "publisher": "Wordfence",
      "title": "Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Content Deletion via delete_previously_imported AJAX Action",
      "affected": {
        "vendors": [
          "solacewp"
        ],
        "products": [
          {
            "vendor": "solacewp",
            "product": "Solace Extra"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22145
      },
      "nvd": {
        "published": "2026-07-11T05:16:32.243",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13250",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A deletion handler is reachable without a valid authorization check, and its nonce is exposed broadly enough that the operation can delete imported site content.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/860747b9-46ab-4c97-af36-f2e104043be0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.5.3/admin/import.php#L1424",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.5.3/includes/class-solace-extra.php#L313",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.5.3/admin/class-solace-extra-admin.php#L287",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.5.1/admin/import.php#L1424",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.5.1/includes/class-solace-extra.php#L313",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.5.1/admin/class-solace-extra-admin.php#L287",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3593408%40solace-extra&new=3593408%40solace-extra",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 787,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:41:58.569Z",
      "date_published": "2026-07-02T09:32:02.214Z",
      "date_updated": "2026-07-02T15:54:09.652Z",
      "publisher": "Wordfence",
      "title": "Perfmatters <= 2.6.4 - Unauthenticated Arbitrary File Read via 's' Parameter",
      "affected": {
        "vendors": [
          "perfmatters"
        ],
        "products": [
          {
            "vendor": "perfmatters",
            "product": "Perfmatters"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00641,
        "percentile": 0.47207
      },
      "nvd": {
        "published": "2026-07-02T10:16:27.893",
        "lastModified": "2026-07-02T16:16:29.703",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13251",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled path or reference can select a file outside the intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2c0082ff-2a33-44e9-b0d0-8b9a404ab648?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/perfmatters/trunk/inc/classes/Fonts.php#L131",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://perfmatters.io/docs/changelog/",
          "host": "perfmatters.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T19:48:31.427Z",
      "date_published": "2026-07-02T08:33:07.655Z",
      "date_updated": "2026-07-02T19:42:21.582Z",
      "publisher": "Wordfence",
      "title": "RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute",
      "affected": {
        "vendors": [
          "themeisle"
        ],
        "products": [
          {
            "vendor": "themeisle",
            "product": "RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09452
      },
      "nvd": {
        "published": "2026-07-02T10:16:28.010",
        "lastModified": "2026-07-02T20:17:00.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13252",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d402b7d1-3c12-4bdd-8ff3-e58d5501f0c0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/feedzy-rss-feeds/tags/5.2.0/includes/abstract/feedzy-rss-feeds-admin-abstract.php#L1700",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/feedzy-rss-feeds/tags/5.2.0/includes/abstract/feedzy-rss-feeds-admin-abstract.php#L1453",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/feedzy-rss-feeds/tags/5.2.0/includes/abstract/feedzy-rss-feeds-admin-abstract.php#L624",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/feedzy-rss-feeds/tags/5.2.0/includes/abstract/feedzy-rss-feeds-admin-abstract.php#L423",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3586919%40feedzy-rss-feeds&new=3586919%40feedzy-rss-feeds&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 489,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13253",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T19:53:28.879Z",
      "date_published": "2026-07-09T06:52:44.934Z",
      "date_updated": "2026-07-09T17:33:21.736Z",
      "publisher": "Wordfence",
      "title": "Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute",
      "affected": {
        "vendors": [
          "wpxpo"
        ],
        "products": [
          {
            "vendor": "wpxpo",
            "product": "Post Grid Gutenberg Blocks – PostX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.10001
      },
      "nvd": {
        "published": "2026-07-09T08:16:46.403",
        "lastModified": "2026-07-09T18:16:50.123",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13253",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A block attribute is concatenated into an HTML data attribute without attribute-context escaping, allowing stored script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/070ccd70-22c3-47f1-9dce-a884bff9ea76?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-post/tags/5.0.27/blocks/Advanced_Search.php#L116",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-post/tags/5.0.28/blocks/Advanced_Search.php#L116",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-post/tags/5.0.28/blocks/Advanced_Search.php#L108",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-post/tags/5.0.28/classes/Blocks.php#L231",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-post/tags/5.0.27/blocks/Advanced_Search.php#L108",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-post/tags/5.0.27/classes/Blocks.php#L231",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3598669%40ultimate-post&new=3598669%40ultimate-post",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 791,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13262",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T21:01:11.400Z",
      "date_published": "2026-07-11T02:31:17.133Z",
      "date_updated": "2026-07-13T14:39:57.646Z",
      "publisher": "Wordfence",
      "title": "Majestic Support <= 1.1.9 - Authenticated (Subscriber+) SQL Injection via 'val' Parameter",
      "affected": {
        "vendors": [
          "ahmadmj"
        ],
        "products": [
          {
            "vendor": "ahmadmj",
            "product": "Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27897
      },
      "nvd": {
        "published": "2026-07-11T04:17:16.793",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13262",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The val parameter reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/502577dd-49e3-419d-8b37-591be69ad131?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/majestic-support/tags/1.1.8/includes/ajax.php#L19",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/majestic-support/tags/1.1.9/modules/smartreply/model.php#L184",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/majestic-support/tags/1.1.9/modules/smartreply/model.php#L183",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/majestic-support/tags/1.1.9/includes/ajax.php#L19",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/majestic-support/tags/1.1.9/modules/ticket/tpls/ticketdetail.php#L672",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/majestic-support/tags/1.1.8/modules/smartreply/model.php#L184",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/majestic-support/tags/1.1.8/modules/smartreply/model.php#L183",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/majestic-support/tags/1.1.8/modules/ticket/tpls/ticketdetail.php#L672",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/majestic-support/tags/1.2.0/modules/smartreply/model.php?rev=3599140#L212",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 763,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13268",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T21:22:42.496Z",
      "date_published": "2026-07-29T19:08:46.783Z",
      "date_updated": "2026-07-30T13:41:40.892Z",
      "publisher": "zdi",
      "title": "G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability",
      "affected": {
        "vendors": [
          "G DATA"
        ],
        "products": [
          {
            "vendor": "G DATA",
            "product": "Total Security"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00151,
        "percentile": 0.04802
      },
      "nvd": {
        "published": "2026-07-29T20:17:00.700",
        "lastModified": "2026-07-30T14:19:24.857",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13268",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The privileged backup service follows an attacker-created symbolic link when deleting a file.",
        "basis": [
          "CNA record",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-432/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 617,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13305",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T00:12:00.171Z",
      "date_published": "2026-07-29T20:14:17.395Z",
      "date_updated": "2026-07-30T17:39:10.526Z",
      "publisher": "zdi",
      "title": "Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger AC Elite Home"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02271
      },
      "nvd": {
        "published": "2026-07-29T21:17:46.093",
        "lastModified": "2026-07-30T19:17:06.113",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13305",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MaxiCharger AC Elite Home accepts signed data without correctly verifying the signature against the trusted key and message.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-433/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 624,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13306",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T00:12:02.885Z",
      "date_published": "2026-07-29T20:14:20.963Z",
      "date_updated": "2026-07-30T15:18:55.786Z",
      "publisher": "zdi",
      "title": "Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger AC Elite Home"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08055
      },
      "nvd": {
        "published": "2026-07-29T21:17:46.257",
        "lastModified": "2026-07-30T16:16:55.097",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13306",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The charger exposes its USB management interface without authenticating the connected client.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-434/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13307",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T00:12:06.213Z",
      "date_published": "2026-07-29T20:14:27.469Z",
      "date_updated": "2026-07-30T15:18:41.231Z",
      "publisher": "zdi",
      "title": "Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger AC Elite Home"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27034
      },
      "nvd": {
        "published": "2026-07-29T21:17:46.370",
        "lastModified": "2026-07-30T16:16:55.210",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13307",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In MaxiCharger AC Elite Home, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-436/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 644,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13308",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T00:12:09.134Z",
      "date_published": "2026-07-29T20:14:30.765Z",
      "date_updated": "2026-07-30T15:18:34.551Z",
      "publisher": "zdi",
      "title": "Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger AC Elite Home"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00567,
        "percentile": 0.43806
      },
      "nvd": {
        "published": "2026-07-29T21:17:46.490",
        "lastModified": "2026-07-30T16:16:55.313",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13308",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled length can underflow before buffer allocation, producing an invalid allocation or copy size.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-437/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 653,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T00:12:12.202Z",
      "date_published": "2026-07-29T20:14:24.235Z",
      "date_updated": "2026-07-30T15:18:49.098Z",
      "publisher": "zdi",
      "title": "Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Autel"
        ],
        "products": [
          {
            "vendor": "Autel",
            "product": "MaxiCharger AC Elite Home"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13597
      },
      "nvd": {
        "published": "2026-07-29T21:17:46.607",
        "lastModified": "2026-07-30T16:16:55.417",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13309",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted NFC card response exceeds a fixed-length stack buffer in the charger's response handler.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-435/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 602,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13320",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:13:57.255Z",
      "date_published": "2026-07-08T20:46:13.854Z",
      "date_updated": "2026-07-09T13:41:48.373Z",
      "publisher": "GitLab",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 1.8999999999999995,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25737
      },
      "nvd": {
        "published": "2026-07-08T21:16:46.630",
        "lastModified": "2026-07-09T20:35:14.233",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13320",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The GitLab rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/604063",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3816917",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13321",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:45:35.931Z",
      "date_published": "2026-07-22T14:16:10.450Z",
      "date_updated": "2026-07-22T18:51:47.414Z",
      "publisher": "isc",
      "title": "DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field",
      "affected": {
        "vendors": [
          "ISC"
        ],
        "products": [
          {
            "vendor": "ISC",
            "product": "BIND 9"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-officer@isc.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12242
      },
      "nvd": {
        "published": "2026-07-22T15:16:52.200",
        "lastModified": "2026-07-22T20:33:11.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13321",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "BIND accepts a signed NSEC Next name outside the signer zone instead of binding the proof to the authoritative DNS namespace.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.isc.org/docs/cve-2026-13321",
          "host": "kb.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.20.26",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://downloads.isc.org/isc/bind9/9.21.24",
          "host": "downloads.isc.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-13323",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T09:14:56.817Z",
      "date_published": "2026-07-01T11:28:20.888Z",
      "date_updated": "2026-07-01T12:19:20.920Z",
      "publisher": "eclipse",
      "title": "In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. An unauthenticated atta...",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Open VSX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 4.6,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11574
      },
      "nvd": {
        "published": "2026-07-01T12:16:38.117",
        "lastModified": "2026-07-06T20:33:10.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13323",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Eclipse Open VSX rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/485",
          "host": "gitlab.eclipse.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Vendor Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/eclipse-openvsx/openvsx/pull/1922",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 810,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13330",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T13:25:33.951Z",
      "date_published": "2026-07-30T06:00:11.821Z",
      "date_updated": "2026-07-30T12:35:26.383Z",
      "publisher": "WPScan",
      "title": "Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Animation Addons for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.0788
      },
      "nvd": {
        "published": "2026-07-30T06:24:59.177",
        "lastModified": "2026-07-30T14:16:31.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13330",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The plugin permits SVG uploads without sanitizing embedded script, so stored files execute as browser markup.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/d5286cc6-c6e4-40e0-bd08-0699fb0c9e82/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13332",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T13:35:35.434Z",
      "date_published": "2026-07-27T06:00:02.553Z",
      "date_updated": "2026-07-27T14:11:35.944Z",
      "publisher": "WPScan",
      "title": "Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Service)",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Masteriyo LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.1514
      },
      "nvd": {
        "published": "2026-07-27T07:16:24.820",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13332",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/f987c823-f215-48f6-86fe-8d898f2c2d94/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 285,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13334",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T13:43:26.781Z",
      "date_published": "2026-07-09T07:55:12.187Z",
      "date_updated": "2026-07-09T14:35:53.100Z",
      "publisher": "Wordfence",
      "title": "Mang Board WP <= 2.3.4 - Reflected Cross-Site Scripting via 'stag' Parameter",
      "affected": {
        "vendors": [
          "kitae-park"
        ],
        "products": [
          {
            "vendor": "kitae-park",
            "product": "Mang Board WP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11982
      },
      "nvd": {
        "published": "2026-07-09T08:16:46.537",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13334",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The stag parameter is reflected into HTML without input sanitization or context-appropriate output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0f42b2be-2a7d-470a-896d-6148e31e4cce?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mangboard/tags/2.3.4/skins/bbs_basic/_header.php#L26",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mangboard/tags/2.3.4/includes/functions/func.board.php#L297",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mangboard/tags/2.3.4/includes/class.store.php#L110",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mangboard/tags/2.3.4/includes/class.store.php#L122",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3598739%40mangboard&new=3598739%40mangboard",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 414,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13341",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T14:11:55.561Z",
      "date_published": "2026-07-03T10:19:10.646Z",
      "date_updated": "2026-07-06T17:29:24.789Z",
      "publisher": "Kong",
      "title": "Prompt Injection and Credential Exposure via Untrusted Analytics Data in Kong Konnect MCP",
      "affected": {
        "vendors": [
          "KongHQ"
        ],
        "products": [
          {
            "vendor": "KongHQ",
            "product": "mcp-konnect"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:02762ae7-200e-4b20-9b2b-a77d5b8fc4cb",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17447
      },
      "nvd": {
        "published": "2026-07-03T11:16:27.720",
        "lastModified": "2026-07-06T19:01:56.880",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13341",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Untrusted tool content can become model instructions that trigger unintended Konnect API calls, while the public advisory does not disclose the prompt boundary or confirmation rule.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://github.com/Kong/mcp-konnect/security/advisories/GHSA-7767-3m3w-2p44",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13344",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T14:13:28.095Z",
      "date_published": "2026-07-30T06:00:12.016Z",
      "date_updated": "2026-07-30T12:34:00.047Z",
      "publisher": "WPScan",
      "title": "Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Essential Addons for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06976
      },
      "nvd": {
        "published": "2026-07-30T06:24:59.293",
        "lastModified": "2026-07-30T14:16:31.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13344",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/d212286d-e152-4bfa-a9e4-a4940ec4adf9/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13345",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T14:13:30.190Z",
      "date_published": "2026-07-30T06:00:12.201Z",
      "date_updated": "2026-07-30T17:12:56.492Z",
      "publisher": "WPScan",
      "title": "Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Essential Addons for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15843
      },
      "nvd": {
        "published": "2026-07-30T06:24:59.403",
        "lastModified": "2026-07-30T19:17:06.260",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13345",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts a caller-supplied object identifier without verifying that the selected object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/45937bce-12db-4770-9f15-606c62469f6d/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 353,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13346",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T14:15:08.834Z",
      "date_published": "2026-07-29T18:33:50.820Z",
      "date_updated": "2026-07-29T20:21:34.281Z",
      "publisher": "PSF",
      "title": "pip absolute path traversal during download from malicious package indexes",
      "affected": {
        "vendors": [
          "Python Packaging Authority"
        ],
        "products": [
          {
            "vendor": "Python Packaging Authority",
            "product": "pip"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-36",
          "name": "Absolute Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cna@python.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27412
      },
      "nvd": {
        "published": "2026-07-29T19:16:44.267",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13346",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "pip decodes a package-index URL inconsistently and lets a doubly encoded absolute path select a destination outside the download directory.",
        "basis": [
          "CNA",
          "CWE-36"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pypa/pip/pull/14110",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/",
          "host": "mail.python.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/29/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 588,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13347",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T14:32:04.252Z",
      "date_published": "2026-07-10T06:51:43.734Z",
      "date_updated": "2026-07-10T17:01:37.230Z",
      "publisher": "Wordfence",
      "title": "Hide My WP Lite <= 1.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'he_wrapper_js' Parameter",
      "affected": {
        "vendors": [
          "templatic1"
        ],
        "products": [
          {
            "vendor": "templatic1",
            "product": "Hide My WP Lite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00601,
        "percentile": 0.45379
      },
      "nvd": {
        "published": "2026-07-10T08:16:20.857",
        "lastModified": "2026-07-10T17:16:53.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13347",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The plugin concatenates an unauthenticated query value to ABSPATH and reads the result without canonicalization or containment checks.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e044c51c-40e0-4d33-8921-616d59e0e0d8?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hide-wp-login/tags/1.3/includes/functions.php#L139",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/hide-wp-login/tags/1.3/includes/functions.php#L117",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 886,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T16:24:12.456Z",
      "date_published": "2026-07-17T03:43:41.800Z",
      "date_updated": "2026-07-17T14:54:08.409Z",
      "publisher": "Wordfence",
      "title": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion",
      "affected": {
        "vendors": [
          "properfraction"
        ],
        "products": [
          {
            "vendor": "properfraction",
            "product": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00575,
        "percentile": 0.44203
      },
      "nvd": {
        "published": "2026-07-17T05:16:36.730",
        "lastModified": "2026-07-17T16:17:13.187",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13352",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ProfilePress registers a global MIME filter that adds executable extensions to every WordPress upload context instead of limiting them to digital products.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9bb520df-e838-4335-bd4f-97026082a204?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.18/src/Membership/DigitalProducts/UploadHandler.php#L49",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.18/src/Membership/DigitalProducts/UploadHandler.php#L18",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.18/src/Membership/DigitalProducts/Init.php#L9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.14/src/Membership/DigitalProducts/UploadHandler.php#L49",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.14/src/Membership/DigitalProducts/UploadHandler.php#L18",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.14/src/Membership/DigitalProducts/Init.php#L9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3599012%40wp-user-avatar&new=3599012%40wp-user-avatar",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 883,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T16:35:02.101Z",
      "date_published": "2026-07-11T02:31:19.579Z",
      "date_updated": "2026-07-13T17:41:11.332Z",
      "publisher": "Wordfence",
      "title": "WP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter",
      "affected": {
        "vendors": [
          "smackcoders"
        ],
        "products": [
          {
            "vendor": "smackcoders",
            "product": "WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00623,
        "percentile": 0.46456
      },
      "nvd": {
        "published": "2026-07-11T04:17:16.937",
        "lastModified": "2026-07-13T18:16:26.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13353",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Subscriber-reachable AJAX handlers omit capability checks, allowing a low-privileged user to persist PHP expressions that a later import evaluates.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e89fc348-1146-4593-8bf5-127f783ab786?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-csv-importer/tags/8.0.1/wp-ultimate-csv-importer.php#L419",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-csv-importer/tags/8.0.1/InstallAddons.php#L66",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-csv-importer/tags/8.0.1/SaveMapping.php#L185",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-csv-importer/tags/8.0.1/SaveMapping.php#L1562",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3591135/wp-ultimate-csv-importer",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 763,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13356",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T17:23:02.121Z",
      "date_published": "2026-07-06T23:07:42.721Z",
      "date_updated": "2026-07-07T13:27:01.584Z",
      "publisher": "mozilla",
      "title": "Interrupted navigation could allow address bar origin spoofing in Firefox for iOS",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox for iOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03166
      },
      "nvd": {
        "published": "2026-07-07T00:16:34.063",
        "lastModified": "2026-07-08T14:52:38.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13356",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A synchronous JavaScript dialog can interrupt a pending navigation after the address bar changes, leaving attacker content under the destination origin display.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2047768",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-65/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13357",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T18:13:25.213Z",
      "date_published": "2026-07-02T05:35:07.352Z",
      "date_updated": "2026-07-02T19:41:40.276Z",
      "publisher": "Wordfence",
      "title": "Houzez Property Feed <= 2.5.46 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "affected": {
        "vendors": [
          "propertyhive"
        ],
        "products": [
          {
            "vendor": "propertyhive",
            "product": "Houzez Property Feed"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20179
      },
      "nvd": {
        "published": "2026-07-02T06:16:13.490",
        "lastModified": "2026-07-02T20:17:00.873",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13357",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The orderby value is concatenated into an SQL ORDER BY clause before prepare can parameterize it.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7669f1d3-450c-4c17-aa1e-44ddda194727?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/houzez-property-feed/tags/2.5.46/includes/class-houzez-property-feed-admin-logs-export-table.php#L219",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/houzez-property-feed/tags/2.5.46/includes/class-houzez-property-feed-admin-logs-export-table.php#L205",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/houzez-property-feed/tags/2.5.46/includes/class-houzez-property-feed-admin.php#L587",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/houzez-property-feed/tags/2.5.46/includes/class-houzez-property-feed-admin.php#L138",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3592406%40houzez-property-feed&new=3592406%40houzez-property-feed&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 961,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13368",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T19:00:06.688Z",
      "date_published": "2026-07-02T23:06:32.928Z",
      "date_updated": "2026-07-07T03:56:35.031Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0079,
        "percentile": 0.52729
      },
      "nvd": {
        "published": "2026-07-03T00:16:50.890",
        "lastModified": "2026-07-07T05:16:48.803",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13368",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Fireware OS, code retains or reuses an object after the lifetime transition that frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 534,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13369",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T19:04:37.969Z",
      "date_published": "2026-07-02T09:32:03.716Z",
      "date_updated": "2026-07-02T12:18:54.246Z",
      "publisher": "Wordfence",
      "title": "Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter",
      "affected": {
        "vendors": [
          "SaturdayDrive"
        ],
        "products": [
          {
            "vendor": "SaturdayDrive",
            "product": "Ninja Forms - File Uploads"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00408,
        "percentile": 0.33537
      },
      "nvd": {
        "published": "2026-07-02T10:16:28.130",
        "lastModified": "2026-07-02T13:58:56.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13369",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ninja Forms - File Uploads allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/87d4dd4a-b1e2-4d08-aef1-77e58aa7531d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms-uploads/trunk/includes/integrations/ninjaforms/attachments.php#L107",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms-uploads/trunk/includes/integrations/ninjaforms/attachments.php#L196",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms-uploads/trunk/includes/fields/upload.php#L71",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 673,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T19:43:53.207Z",
      "date_published": "2026-07-02T23:04:42.674Z",
      "date_updated": "2026-07-07T17:01:52.545Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox Management Web UI Denial of Service via Unsafe Deserialization",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23332
      },
      "nvd": {
        "published": "2026-07-03T00:16:51.013",
        "lastModified": "2026-07-07T18:16:34.670",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13371",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The put_data endpoint deserializes administrator-supplied data as a trusted object and lets malformed state abort the management service.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00014",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13373",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T20:30:45.709Z",
      "date_published": "2026-07-02T23:05:00.814Z",
      "date_updated": "2026-07-06T15:47:29.819Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05469
      },
      "nvd": {
        "published": "2026-07-03T00:16:51.137",
        "lastModified": "2026-07-09T20:20:04.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13373",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fireware OS stores attacker-controlled content and later renders it without sufficient output escaping, allowing script execution in a visitor's browser.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00015",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13374",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T20:31:06.991Z",
      "date_published": "2026-07-02T23:05:13.056Z",
      "date_updated": "2026-07-07T17:01:46.872Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05468
      },
      "nvd": {
        "published": "2026-07-03T00:16:51.257",
        "lastModified": "2026-07-09T20:17:08.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13374",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ConnectWise integration stores configuration content that is later emitted into a page without sufficient script neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00016",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 412,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13375",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T20:31:08.245Z",
      "date_published": "2026-07-02T23:05:20.273Z",
      "date_updated": "2026-07-07T17:01:41.235Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05468
      },
      "nvd": {
        "published": "2026-07-03T00:16:51.373",
        "lastModified": "2026-07-09T20:15:02.137",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13375",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Autotask integration stores input that is later parsed as active page markup without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00017",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13376",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T20:34:53.978Z",
      "date_published": "2026-07-02T23:05:26.669Z",
      "date_updated": "2026-07-06T15:03:24.964Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05468
      },
      "nvd": {
        "published": "2026-07-03T00:16:51.497",
        "lastModified": "2026-07-09T20:06:02.590",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13376",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WatchGuard Fireware stores spamBlocker input and later renders it as active browser markup without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00018",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 385,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T20:34:54.862Z",
      "date_published": "2026-07-02T23:05:32.445Z",
      "date_updated": "2026-07-06T15:02:58.909Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05469
      },
      "nvd": {
        "published": "2026-07-03T00:16:51.643",
        "lastModified": "2026-07-09T20:15:46.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13377",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00019",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 383,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T21:12:54.787Z",
      "date_published": "2026-07-11T04:32:58.802Z",
      "date_updated": "2026-07-13T16:12:47.968Z",
      "publisher": "Wordfence",
      "title": "Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact Form 7 Form Field",
      "affected": {
        "vendors": [
          "wpvibes"
        ],
        "products": [
          {
            "vendor": "wpvibes",
            "product": "Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17515
      },
      "nvd": {
        "published": "2026-07-11T06:16:08.930",
        "lastModified": "2026-07-13T17:16:59.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13378",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Contact Form 7 field values are stored and rendered by Form Vibes without sufficient sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c6716a5d-48ed-4735-b765-a7606ea401d0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/form-vibes/tags/1.5.2/assets/dist/js/submission.js#L1",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/form-vibes/tags/1.5.2/inc/integrations/cf7.php#L126",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/form-vibes/tags/1.5.2/inc/integrations/base.php#L141",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3599917%40form-vibes&new=3597349%40form-vibes",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13379",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T21:22:05.303Z",
      "date_published": "2026-07-30T16:28:19.012Z",
      "date_updated": "2026-07-30T18:09:24.328Z",
      "publisher": "OpenVPN",
      "title": "The Windows interactive service in OpenVPN 2.",
      "affected": {
        "vendors": [
          "OpenVPN"
        ],
        "products": [
          {
            "vendor": "OpenVPN",
            "product": "OpenVPN"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-142",
          "name": "Improper Neutralization of Value Delimiters",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:N/SA:H"
        },
        {
          "source": "NVD:security@openvpn.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20801
      },
      "nvd": {
        "published": "2026-07-30T17:16:28.707",
        "lastModified": "2026-07-30T19:17:06.517",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13379",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The disconnect path processes a crafted search domain without the required string bounds, permitting an invalid read and service crash.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-142"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.openvpn.net/Security%20Announcements/CVE-2026-13379",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://community.openvpn.net/ReleaseHistory#openvpn-275-released-1-july-2026",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T21:22:28.646Z",
      "date_published": "2026-07-20T20:11:46.703Z",
      "date_updated": "2026-07-21T17:16:05.916Z",
      "publisher": "SRA",
      "title": "VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses",
      "affected": {
        "vendors": [
          "VSee"
        ],
        "products": [
          {
            "vendor": "VSee",
            "product": "Clinic"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-312",
          "name": "Cleartext Storage of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:57dba5dd-1a03-47f6-8b36-e84e47d335d8",
          "type": "Secondary",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17838
      },
      "nvd": {
        "published": "2026-07-20T21:16:46.510",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13380",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Three unauthenticated HTTP endpoints return configured SFTP credentials in cleartext response bodies.",
        "basis": [
          "CNA",
          "CWE-201",
          "CWE-312"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://labs.sra.io/posts/vseeclinic",
          "host": "labs.sra.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vsee.com/clinic",
          "host": "vsee.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 511,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13381",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T21:22:30.503Z",
      "date_published": "2026-07-20T20:12:55.332Z",
      "date_updated": "2026-07-21T17:15:55.868Z",
      "publisher": "SRA",
      "title": "VSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and Deletion",
      "affected": {
        "vendors": [
          "VSee"
        ],
        "products": [
          {
            "vendor": "VSee",
            "product": "Clinic"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:57dba5dd-1a03-47f6-8b36-e84e47d335d8",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11997
      },
      "nvd": {
        "published": "2026-07-20T21:16:46.660",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13381",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://labs.sra.io/posts/vseeclinic",
          "host": "labs.sra.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vsee.com/clinic",
          "host": "vsee.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 297,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T22:44:09.033Z",
      "date_published": "2026-07-02T23:05:53.872Z",
      "date_updated": "2026-07-07T03:56:38.252Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox ikestubd Out of Bounds Write Vulnerability",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00557,
        "percentile": 0.43274
      },
      "nvd": {
        "published": "2026-07-03T00:16:51.773",
        "lastModified": "2026-07-09T19:55:25.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13383",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fireware OS writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00020",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13384",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T22:44:10.384Z",
      "date_published": "2026-07-02T23:05:59.971Z",
      "date_updated": "2026-07-07T03:56:37.194Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox wgagent Out of Bounds Write Vulnerability",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00557,
        "percentile": 0.43275
      },
      "nvd": {
        "published": "2026-07-03T00:16:51.893",
        "lastModified": "2026-07-09T19:50:14.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13384",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted management request can make the wgagent process write outside a valid buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00021",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13385",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T03:42:59.077Z",
      "date_published": "2026-07-15T02:01:46.495Z",
      "date_updated": "2026-07-29T19:26:45.155Z",
      "publisher": "ASUS",
      "title": "An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server.",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "Router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-354",
          "name": "Improper Validation of Integrity Check Value",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04018
      },
      "nvd": {
        "published": "2026-07-15T02:18:12.090",
        "lastModified": "2026-07-29T20:17:00.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13385",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The router accepts update-server content without validating the server certificate or update integrity.",
        "basis": [
          "CNA",
          "CWE-295",
          "CWE-354"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory/",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 358,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T07:17:55.469Z",
      "date_published": "2026-07-27T06:00:02.724Z",
      "date_updated": "2026-07-27T14:10:09.471Z",
      "publisher": "WPScan",
      "title": "The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "The Events Calendar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.07957
      },
      "nvd": {
        "published": "2026-07-27T07:16:24.930",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13390",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An Event Aggregator REST route updates import state without authorizing the caller and skips integrity validation for one status value.",
        "basis": [
          "CNA record",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/c7d3b1c5-3b3a-4359-aa41-0dfccb091fa4/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T07:33:48.034Z",
      "date_published": "2026-07-31T06:00:10.969Z",
      "date_updated": "2026-07-31T16:49:52.762Z",
      "publisher": "WPScan",
      "title": "ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite)",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "ElementsKit Elementor Addons"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29701
      },
      "nvd": {
        "published": "2026-07-31T07:16:24.163",
        "lastModified": "2026-07-31T17:16:32.190",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13392",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ElementsKit Elementor Addons lets attacker-controlled text cross into an executable code or template grammar.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/955cbef5-51c3-4d10-86d2-e2882bbb56a4/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13393",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T07:33:52.723Z",
      "date_published": "2026-07-31T06:00:11.152Z",
      "date_updated": "2026-07-31T17:45:29.200Z",
      "publisher": "WPScan",
      "title": "ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite)",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "ElementsKit Elementor Addons"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04003
      },
      "nvd": {
        "published": "2026-07-31T07:16:24.277",
        "lastModified": "2026-07-31T18:17:10.500",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13393",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ElementsKit stores settings supplied by a multisite administrator and later renders them without neutralizing executable HTML.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e1eddc5a-cc5a-4665-a5c8-fcdf121be241/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 551,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T08:07:05.201Z",
      "date_published": "2026-07-30T06:00:12.486Z",
      "date_updated": "2026-07-30T17:15:50.693Z",
      "publisher": "WPScan",
      "title": "Bookly < 27.8 - Unauthenticated SQL Injection via staff_id",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Online Scheduling and Appointment Booking System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26442
      },
      "nvd": {
        "published": "2026-07-30T06:24:59.510",
        "lastModified": "2026-07-30T19:17:06.657",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13395",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Online Scheduling and Appointment Booking System, attacker-controlled input reaches an SQL statement without the required parameter binding or SQL-context escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/87e75d83-0ffc-4dd1-8839-1d5a90f5ea73/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 365,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T08:25:15.552Z",
      "date_published": "2026-07-16T16:14:14.891Z",
      "date_updated": "2026-07-17T13:30:45.877Z",
      "publisher": "CPANSec",
      "title": "HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes",
      "affected": {
        "vendors": [
          "CODECHILD"
        ],
        "products": [
          {
            "vendor": "CODECHILD",
            "product": "HTML::Bare"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00393,
        "percentile": 0.32044
      },
      "nvd": {
        "published": "2026-07-16T17:16:55.213",
        "lastModified": "2026-07-17T14:17:19.863",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13397",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Malformed input can enter a loop whose exit condition is never reached, monopolizing the processing thread.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nanoscopic/perl-HTML-Bare/pull/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://security.metacpan.org/patches/H/HTML-Bare/0.02/CVE-2026-13397-r1.patch",
          "host": "security.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/16/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 461,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T08:35:42.471Z",
      "date_published": "2026-07-27T06:00:03.496Z",
      "date_updated": "2026-07-27T13:53:58.533Z",
      "publisher": "WPScan",
      "title": "Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Simply Schedule Appointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04576
      },
      "nvd": {
        "published": "2026-07-27T07:16:25.023",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13400",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Notification content is decoded back into live HTML after wp_kses_post has run, reactivating a double-encoded stored payload at render time.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/501b2929-3216-4587-8124-088fd51becf1/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 482,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13401",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T08:38:33.750Z",
      "date_published": "2026-07-16T16:14:50.176Z",
      "date_updated": "2026-07-17T12:51:52.550Z",
      "publisher": "CPANSec",
      "title": "XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes",
      "affected": {
        "vendors": [
          "CODECHILD"
        ],
        "products": [
          {
            "vendor": "CODECHILD",
            "product": "XML::Bare"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31573
      },
      "nvd": {
        "published": "2026-07-16T17:16:55.320",
        "lastModified": "2026-07-17T13:17:55.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13401",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The XML::Bare path lets attacker-controlled state drive a loop without a guaranteed terminating condition.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nanoscopic/perl-XML-Bare/pull/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://security.metacpan.org/patches/X/XML-Bare/0.53/CVE-2026-13401-r1.patch",
          "host": "security.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/16/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 343,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13402",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T08:45:52.657Z",
      "date_published": "2026-07-17T06:00:02.627Z",
      "date_updated": "2026-07-17T12:56:50.988Z",
      "publisher": "WPScan",
      "title": "Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Royal Addons for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13326
      },
      "nvd": {
        "published": "2026-07-17T07:16:38.120",
        "lastModified": "2026-07-17T15:44:29.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13402",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A REST endpoint returns private or draft content without checking that publication state against the caller's privilege.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/1a7a9159-0e85-43c4-b1ab-7ea37a4f2d95/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T10:06:50.040Z",
      "date_published": "2026-07-17T12:50:30.389Z",
      "date_updated": "2026-07-17T17:32:51.458Z",
      "publisher": "CPANSec",
      "title": "Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled",
      "affected": {
        "vendors": [
          "GARU"
        ],
        "products": [
          {
            "vendor": "GARU",
            "product": "Dancer::Plugin::Auth::Google"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15462
      },
      "nvd": {
        "published": "2026-07-17T13:17:56.663",
        "lastModified": "2026-07-17T18:17:14.283",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13410",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Dancer::Plugin::Auth::Google secure-channel path does not correctly validate the peer certificate before trusting the connection.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/garu/Dancer-Plugin-Auth-Google/pull/5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://security.metacpan.org/patches/D/Dancer-Plugin-Auth-Google/0.07/CVE-2026-13410-r1.patch",
          "host": "security.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/pod/Furl#HTTPS-requests-claims-warnings!",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/17/8",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 454,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T13:02:04.521Z",
      "date_published": "2026-07-29T06:00:02.283Z",
      "date_updated": "2026-07-29T12:51:48.602Z",
      "publisher": "WPScan",
      "title": "Streamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Function Call",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Streamit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00536,
        "percentile": 0.42164
      },
      "nvd": {
        "published": "2026-07-29T07:16:41.250",
        "lastModified": "2026-07-30T14:16:31.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13423",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unauthenticated AJAX route invokes a PHP function and argument array selected by the requester.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/f85c5da1-412f-4079-8c44-708bc78c2b9b/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 404,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T13:05:29.224Z",
      "date_published": "2026-07-29T07:48:01.501Z",
      "date_updated": "2026-07-29T13:20:52.312Z",
      "publisher": "Wordfence",
      "title": "Database for CF7 <= 1.2.6 - Unauthenticated Stored Cross-Site Scripting via Array Form Field Values",
      "affected": {
        "vendors": [
          "code4life"
        ],
        "products": [
          {
            "vendor": "code4life",
            "product": "Database for CF7"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16175
      },
      "nvd": {
        "published": "2026-07-29T09:16:29.183",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13425",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/07fda92e-a085-42c7-a16d-1eace1dee195?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/database-for-cf7/trunk/database-for-cf7.php#L236",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/database-for-cf7/trunk/database-for-cf7.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 781,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T14:26:06.794Z",
      "date_published": "2026-07-10T03:31:13.126Z",
      "date_updated": "2026-07-10T20:31:29.049Z",
      "publisher": "Wordfence",
      "title": "Post Export Import with Media <= 1.13.1 - Authenticated (Administrator+) Arbitrary File Upload via Trailing-Dot Filename Bypass in ZIP Media Import",
      "affected": {
        "vendors": [
          "wpazleen"
        ],
        "products": [
          {
            "vendor": "wpazleen",
            "product": "Post Export Import with Media"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00597,
        "percentile": 0.45218
      },
      "nvd": {
        "published": "2026-07-10T04:17:47.430",
        "lastModified": "2026-07-10T21:16:53.397",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13430",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A trailing dot makes pathinfo return an empty extension, skipping the archive allowlist before the extracted file is copied into WordPress uploads.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/42f94f80-6157-4778-ad69-184943134fd2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/post-export-import-with-media/tags/1.13.1/includes/class-media-handler.php#L364",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/post-export-import-with-media/tags/1.13.1/includes/class-media-handler.php#L789",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/post-export-import-with-media/tags/1.13.1/includes/class-media-handler.php#L389",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/post-export-import-with-media/tags/1.13.1/includes/class-media-handler.php#L444",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/post-export-import-with-media/tags/1.13.1/includes/class-media-handler.php#L268",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3600506%40post-export-import-with-media&new=3600506%40post-export-import-with-media",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 855,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13432",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T14:33:37.355Z",
      "date_published": "2026-07-20T06:00:05.118Z",
      "date_updated": "2026-07-20T13:11:34.355Z",
      "publisher": "WPScan",
      "title": "ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "ThumbPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06619
      },
      "nvd": {
        "published": "2026-07-20T07:16:35.783",
        "lastModified": "2026-07-20T20:39:31.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13432",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/a408e8f9-4de7-4449-8fca-51ea46e4f433/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 290,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T15:01:44.178Z",
      "date_published": "2026-07-30T16:48:36.764Z",
      "date_updated": "2026-07-31T03:56:17.304Z",
      "publisher": "ibm",
      "title": "Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21029
      },
      "nvd": {
        "published": "2026-07-30T19:17:06.840",
        "lastModified": "2026-07-31T04:16:46.393",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13435",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "IBM Langflow's PythonREPL sandbox accepts input that escapes its validation boundary, while the public bulletin does not identify the accepted construct or failing check.",
        "basis": [
          "CNA",
          "CWE-94",
          "IBM Security Bulletin 7279987"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.ibm.com/support/pages/security-bulletin-python-interpreter-sandbox-bypass-leading-sensitive-data-exposure-0 (official node 7279987). It confirms Langflow 1.0.0-1.10.1, PythonREPL sandbox validation, fix 1.10.2, and no workaround, but publishes no input field, parser branch, or failing check."
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279987",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13439",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T15:53:18.464Z",
      "date_published": "2026-07-21T05:35:29.420Z",
      "date_updated": "2026-07-21T14:55:36.114Z",
      "publisher": "Wordfence",
      "title": "Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint",
      "affected": {
        "vendors": [
          "hassantafreshi"
        ],
        "products": [
          {
            "vendor": "hassantafreshi",
            "product": "Easy Form Builder by WhiteStudio – Drag & Drop Form Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00401,
        "percentile": 0.3292
      },
      "nvd": {
        "published": "2026-07-21T06:16:28.060",
        "lastModified": "2026-07-21T16:54:45.743",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13439",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The reset flow treats a public form session identifier as its password-reset secret and exposes the supporting REST nonce to unauthenticated callers.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/df8326b6-a443-4f76-a755-49f89af74d7e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-form-builder/trunk/includes/class-Emsfb-public.php#L5060",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-form-builder/trunk/includes/class-Emsfb-public.php#L5024",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-form-builder/trunk/includes/class-Emsfb-public.php#L1587",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-form-builder/trunk/includes/class-Emsfb-public.php#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-form-builder/trunk/includes/class-Emsfb-public.php#L623",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3588226/easy-form-builder/trunk/includes/class-Emsfb-public.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Feasy-form-builder/tags/4.0.11&new_path=%2Feasy-form-builder/tags/4.0.12",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 897,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13440",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T16:21:22.531Z",
      "date_published": "2026-07-28T11:32:48.864Z",
      "date_updated": "2026-07-28T12:19:10.061Z",
      "publisher": "Wordfence",
      "title": "StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'message_popup' Parameter",
      "affected": {
        "vendors": [
          "wedevs"
        ],
        "products": [
          {
            "vendor": "wedevs",
            "product": "StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.1823
      },
      "nvd": {
        "published": "2026-07-28T12:16:35.340",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13440",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/79d4d776-411e-45ec-aff7-23453e686bf2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.0.5/modules/sales-pop/includes/Ajax.php#L47",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/sales-pop/includes/Ajax.php#L47",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/bogo/includes/EnqueueScript.php#L170",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/sales-pop/assets/js/popup-custom.js#L130",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.0.5/modules/bogo/includes/EnqueueScript.php#L170",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.0.5/modules/sales-pop/assets/js/popup-custom.js#L130",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3619581%40storegrowth-sales-booster&new=3619581%40storegrowth-sales-booster",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 721,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13441",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T16:24:58.866Z",
      "date_published": "2026-07-09T09:31:20.201Z",
      "date_updated": "2026-07-09T12:19:37.188Z",
      "publisher": "Wordfence",
      "title": "EventPrime <= 4.3.4.2 - Unauthenticated Stored Cross-Site Scripting via 'new_event_type_background_color' Parameter",
      "affected": {
        "vendors": [
          "metagauss"
        ],
        "products": [
          {
            "vendor": "metagauss",
            "product": "EventPrime – Events Calendar, Bookings and Tickets"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16006
      },
      "nvd": {
        "published": "2026-07-09T11:16:24.790",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13441",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An event color value from a guest submission is stored and rendered without the sanitization and output encoding needed for its HTML context.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2abd400b-c633-4b38-ad3e-c9ce602ff07f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/eventprime-event-calendar-management/tags/4.3.4.2/admin/class-eventprime-event-calendar-management-admin.php#L1973",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/eventprime-event-calendar-management/tags/4.3.4.2/includes/class-ep-ajax.php#L1200",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/eventprime-event-calendar-management/tags/4.3.4.2/includes/class-eventprime-functions.php#L9793",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/eventprime-event-calendar-management/trunk/admin/class-eventprime-event-calendar-management-admin.php#L1973",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/eventprime-event-calendar-management/trunk/includes/class-ep-ajax.php#L1200",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/eventprime-event-calendar-management/trunk/includes/class-eventprime-functions.php#L9793",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3595157%40eventprime-event-calendar-management&new=3595157%40eventprime-event-calendar-management",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 763,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13442",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T16:32:33.209Z",
      "date_published": "2026-07-28T20:55:24.930Z",
      "date_updated": "2026-07-29T14:11:30.129Z",
      "publisher": "ibm",
      "title": "Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-520",
          "name": ".NET Misconfiguration: Use of Impersonation",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07051
      },
      "nvd": {
        "published": "2026-07-28T21:17:25.387",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13442",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Langflow lets one user reuse another user's FAISS namespace, binding vector reads and writes to an attacker-selected owner namespace.",
        "basis": [
          "CNA",
          "CWE-520"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279988",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13443",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T16:35:32.693Z",
      "date_published": "2026-07-01T03:43:35.748Z",
      "date_updated": "2026-07-01T10:32:06.393Z",
      "publisher": "Wordfence",
      "title": "Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title",
      "affected": {
        "vendors": [
          "themeum"
        ],
        "products": [
          {
            "vendor": "themeum",
            "product": "Tutor LMS – eLearning and online course solution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.10001
      },
      "nvd": {
        "published": "2026-07-01T05:16:18.513",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13443",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A lesson attachment title is stored and rendered into page markup without sufficient sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7483762c-5356-4844-90a9-511d9ec48625?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.13/templates/global/attachments.php#L34",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.13/classes/Utils.php#L1720",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.13/classes/Utils.php#L1688",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.9/templates/global/attachments.php#L34",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.9/classes/Utils.php#L1720",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.9/classes/Utils.php#L1688",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3590029%40tutor&new=3590029%40tutor&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13444",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T16:38:07.032Z",
      "date_published": "2026-07-30T18:38:32.531Z",
      "date_updated": "2026-07-30T19:21:21.684Z",
      "publisher": "ibm",
      "title": "Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-520",
          "name": ".NET Misconfiguration: Use of Impersonation",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11597
      },
      "nvd": {
        "published": "2026-07-30T19:17:06.997",
        "lastModified": "2026-07-30T20:16:52.430",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13444",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chroma storage keys are treated as a global namespace, so matching persist_directory and collection_name values reach a different user vector collection without an ownership check.",
        "basis": [
          "CNA",
          "CWE-520"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279989",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 453,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T16:40:55.714Z",
      "date_published": "2026-07-17T20:44:38.924Z",
      "date_updated": "2026-07-23T03:56:14.982Z",
      "publisher": "ibm",
      "title": "Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10646
      },
      "nvd": {
        "published": "2026-07-17T21:17:05.473",
        "lastModified": "2026-07-23T05:16:27.737",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13445",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SaveToFile accepts an absolute path to another user's storage without binding the selected file to the caller's namespace.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279990",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13446",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T16:43:04.516Z",
      "date_published": "2026-07-17T20:43:49.355Z",
      "date_updated": "2026-07-23T03:56:14.257Z",
      "publisher": "ibm",
      "title": "Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13346
      },
      "nvd": {
        "published": "2026-07-17T21:17:05.960",
        "lastModified": "2026-07-23T05:16:29.343",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13446",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Langflow OSS uses the same embedded credential or cryptographic key across installations instead of a per-deployment secret.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279991",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T16:47:23.234Z",
      "date_published": "2026-07-17T20:03:30.430Z",
      "date_updated": "2026-07-23T03:56:13.520Z",
      "publisher": "ibm",
      "title": "Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00456,
        "percentile": 0.3737
      },
      "nvd": {
        "published": "2026-07-17T20:17:14.713",
        "lastModified": "2026-07-23T05:16:29.463",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13448",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Langflow's public flow-build endpoint uses an incomplete component denylist, so unauthenticated flows can select components whose behavior includes code execution and other restricted operations.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-184"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279997",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 426,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13450",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:47:07.730Z",
      "date_published": "2026-07-09T07:55:12.923Z",
      "date_updated": "2026-07-09T14:02:29.719Z",
      "publisher": "Wordfence",
      "title": "GamiPress <= 7.9.4 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'access' Parameter",
      "affected": {
        "vendors": [
          "rubengc"
        ],
        "products": [
          {
            "vendor": "rubengc",
            "product": "GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00408,
        "percentile": 0.33582
      },
      "nvd": {
        "published": "2026-07-09T08:16:46.667",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13450",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The activity-log endpoint accepts an attacker-selected object key without checking ownership, and its purported nonce is published to every visitor.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3006261b-a09e-4cff-b49f-49e992c6fe0b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.3/includes/ajax-functions.php#L51",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.3/includes/ajax-functions.php#L48",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.3/includes/shortcodes/gamipress_logs.php#L272",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.3/includes/shortcodes/gamipress_logs.php#L329",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.3/includes/ajax-functions.php#L73",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.3/includes/scripts.php#L51",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.8.6/includes/ajax-functions.php#L51",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.8.6/includes/ajax-functions.php#L48",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.8.6/includes/shortcodes/gamipress_logs.php#L272",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.8.6/includes/shortcodes/gamipress_logs.php#L329",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.8.6/includes/ajax-functions.php#L73",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.8.6/includes/scripts.php#L51",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3593749%40gamipress&new=3593749%40gamipress",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 794,
        "referenceCount": 14,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T18:29:15.543Z",
      "date_published": "2026-07-01T08:30:04.792Z",
      "date_updated": "2026-07-01T10:32:03.402Z",
      "publisher": "Wordfence",
      "title": "MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter",
      "affected": {
        "vendors": [
          "jetmonsters"
        ],
        "products": [
          {
            "vendor": "jetmonsters",
            "product": "MotoPress Appointment Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17736
      },
      "nvd": {
        "published": "2026-07-01T10:16:27.980",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13454",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MotoPress Appointment Booking incorporates s into an SQL statement without parameterization, allowing input syntax to alter the database query.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/64e4d51a-7b65-4fba-9742-bc7d23f46f8d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motopress-appointment-lite/tags/2.4.5/includes/admin-pages/manage/ManageBookingsPage.php#L310",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motopress-appointment-lite/tags/2.4.5/includes/admin-pages/manage/ManageBookingsPage.php#L247",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motopress-appointment-lite/tags/2.4.3/includes/admin-pages/manage/ManageBookingsPage.php#L310",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/motopress-appointment-lite/tags/2.4.3/includes/admin-pages/manage/ManageBookingsPage.php#L247",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3591693/motopress-appointment-lite/trunk/includes/admin-pages/manage/ManageBookingsPage.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 625,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T19:37:59.929Z",
      "date_published": "2026-07-02T08:33:05.757Z",
      "date_updated": "2026-07-02T15:01:30.738Z",
      "publisher": "Wordfence",
      "title": "JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter",
      "affected": {
        "vendors": [
          "jetmonsters"
        ],
        "products": [
          {
            "vendor": "jetmonsters",
            "product": "JetFormBuilder — Dynamic Blocks Form Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25891
      },
      "nvd": {
        "published": "2026-07-02T10:16:28.247",
        "lastModified": "2026-07-02T15:16:57.317",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13459",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The generator endpoint exposes arbitrary post-meta keys without checking that the unauthenticated caller may read the underlying values.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/26c19bd3-32ea-4e28-9cde-1a6653acf6f1?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jetformbuilder/tags/3.6.3/includes/generators/get-from-db.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jetformbuilder/tags/3.6.3/modules/option-field/rest-api/generator-update-endpoint.php#L52",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jetformbuilder/tags/3.6.3/modules/option-field/rest-api/generator-update-endpoint.php#L80",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jetformbuilder/tags/3.6.3/modules/option-field/rest-api/generator-update-endpoint.php#L140",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jetformbuilder/tags/3.6.3/includes/generators/get-from-db.php#L160",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jetformbuilder/tags/3.6.0/includes/generators/get-from-db.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jetformbuilder/tags/3.6.0/modules/option-field/rest-api/generator-update-endpoint.php#L52",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jetformbuilder/tags/3.6.0/modules/option-field/rest-api/generator-update-endpoint.php#L80",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jetformbuilder/tags/3.6.0/modules/option-field/rest-api/generator-update-endpoint.php#L140",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jetformbuilder/tags/3.6.0/includes/generators/get-from-db.php#L160",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3591404%40jetformbuilder&new=3591404%40jetformbuilder&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1025,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13461",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T20:08:29.251Z",
      "date_published": "2026-07-09T17:08:53.024Z",
      "date_updated": "2026-07-10T20:32:30.071Z",
      "publisher": "certcc",
      "title": "PayRange version 7.0.7 contains a JavaScript injection vulnerability",
      "affected": {
        "vendors": [
          "PayRange"
        ],
        "products": [
          {
            "vendor": "PayRange",
            "product": "PayRange"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00429,
        "percentile": 0.35323
      },
      "nvd": {
        "published": "2026-07-09T17:16:56.997",
        "lastModified": "2026-07-10T21:16:53.510",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13461",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The PayRange WebView accepts injected JavaScript expressions that can call privileged bridge functions when the separate TLS bypass is present.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cwe.mitre.org/data/definitions/94.html",
          "host": "cwe.mitre.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://kb.cert.org/vuls/id/152953",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 290,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13462",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T20:08:46.304Z",
      "date_published": "2026-07-09T17:10:44.429Z",
      "date_updated": "2026-07-09T19:45:55.644Z",
      "publisher": "certcc",
      "title": "PayRange for Android, version 7.0.7, contains an SSL bypass vulnerability",
      "affected": {
        "vendors": [
          "PayRange"
        ],
        "products": [
          {
            "vendor": "PayRange",
            "product": "PayRange"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20438
      },
      "nvd": {
        "published": "2026-07-09T17:16:57.090",
        "lastModified": "2026-07-09T20:16:28.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13462",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PayRange webviews accept invalid TLS certificates instead of validating the peer certificate chain and hostname.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cwe.mitre.org/data/definitions/295.html",
          "host": "cwe.mitre.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://kb.cert.org/vuls/id/152953",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13463",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T20:09:45.350Z",
      "date_published": "2026-07-28T20:53:36.452Z",
      "date_updated": "2026-07-29T13:56:49.921Z",
      "publisher": "ibm",
      "title": "Due to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulnerability []",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Cloud Pak System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13172
      },
      "nvd": {
        "published": "2026-07-28T21:17:25.533",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13463",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "IBM Storage Protect credentials are written into log files where a local user can recover them.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279434",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 141,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13464",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T20:12:35.429Z",
      "date_published": "2026-07-24T02:31:59.162Z",
      "date_updated": "2026-07-24T14:40:01.097Z",
      "publisher": "Wordfence",
      "title": "Kirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' Parameter",
      "affected": {
        "vendors": [
          "themeum"
        ],
        "products": [
          {
            "vendor": "themeum",
            "product": "Kirki – Freeform Page Builder, Website Builder & Customizer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26903
      },
      "nvd": {
        "published": "2026-07-24T04:16:51.513",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13464",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/84f65255-f710-44f9-9f77-61776a40abae?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/includes/API/Frontend/Controllers/CollectionController.php#L117",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/includes/API/Frontend/Controllers/FrontendRESTController.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/includes/API/Frontend/Controllers/CollectionController.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.1/includes/API/Frontend/Controllers/CollectionController.php#L117",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.1/includes/API/Frontend/Controllers/FrontendRESTController.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.1/includes/API/Frontend/Controllers/CollectionController.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3617070%40kirki&new=3617070%40kirki",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 600,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13468",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T20:45:25.868Z",
      "date_published": "2026-07-01T03:43:35.375Z",
      "date_updated": "2026-07-01T10:32:06.575Z",
      "publisher": "Wordfence",
      "title": "Visualizer <= 4.0.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via /visualizer/v1/action/{chart}/{type}/ REST Endpoint",
      "affected": {
        "vendors": [
          "themeisle"
        ],
        "products": [
          {
            "vendor": "themeisle",
            "product": "Visualizer – Tables & Charts Manager with Built-in AI Generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00367,
        "percentile": 0.29417
      },
      "nvd": {
        "published": "2026-07-01T05:16:18.663",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13468",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/45dbcc5e-2746-4a55-a1d1-a7c67fa2950e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/visualizer/tags/4.0.3/classes/Visualizer/Module/Frontend.php#L155",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/visualizer/tags/4.0.3/classes/Visualizer/Module.php#L182",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/visualizer/tags/4.0.3/classes/Visualizer/Module/Frontend.php#L219",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/visualizer/tags/4.0.1/classes/Visualizer/Module/Frontend.php#L155",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/visualizer/tags/4.0.1/classes/Visualizer/Module.php#L182",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/visualizer/tags/4.0.1/classes/Visualizer/Module/Frontend.php#L219",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3591310%40visualizer&new=3591310%40visualizer&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 849,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13473",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T21:18:23.722Z",
      "date_published": "2026-07-17T19:58:31.025Z",
      "date_updated": "2026-07-23T03:56:12.789Z",
      "publisher": "ibm",
      "title": "IBM Storage Protect Client is vulnerable to Heap-Based Buffer Overflow",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Storage Protect Client"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00456,
        "percentile": 0.37307
      },
      "nvd": {
        "published": "2026-07-17T20:17:14.827",
        "lastModified": "2026-07-23T05:16:29.590",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13473",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Storage Protect Client can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279728",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T16:40:24.809Z",
      "date_published": "2026-07-09T18:33:16.055Z",
      "date_updated": "2026-07-09T19:47:34.844Z",
      "publisher": "Wordfence",
      "title": "UsersWP <= 1.2.65 - Authenticated (Subscriber+) Arbitrary File Deletion via File Upload Field",
      "affected": {
        "vendors": [
          "stiofansisland"
        ],
        "products": [
          {
            "vendor": "stiofansisland",
            "product": "UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0051,
        "percentile": 0.40683
      },
      "nvd": {
        "published": "2026-07-09T19:17:03.883",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13492",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled path or reference can select a file outside the intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b6cf6390-480f-44e2-ae36-67e3398add33?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/userswp/tags/1.2.65/includes/class-forms.php#L2323",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/userswp/tags/1.2.65/includes/class-forms.php#L2320",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/userswp/tags/1.2.65/includes/class-validation.php#L190",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/userswp/tags/1.2.65/includes/class-forms.php#L1059",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/userswp/tags/1.2.65/includes/class-forms.php#L1973",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3590340/userswp",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/AyeCode/userswp/commit/ddb17ad30ff3384cda85c5f372db30b03bd45ac8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 795,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13577",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-28T20:59:07.978Z",
      "date_published": "2026-07-20T07:11:10.403Z",
      "date_updated": "2026-07-22T12:00:11.288Z",
      "publisher": "CPANSec",
      "title": "Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable",
      "affected": {
        "vendors": [
          "CROMEDOME"
        ],
        "products": [
          {
            "vendor": "CROMEDOME",
            "product": "Dancer2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-340",
          "name": "Generation of Predictable Numbers or Identifiers",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21185
      },
      "nvd": {
        "published": "2026-07-20T08:16:28.987",
        "lastModified": "2026-07-22T12:17:09.823",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13577",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dancer2 silently falls back to a 32-bit rand-derived session identifier when cryptographic random modules are unavailable.",
        "basis": [
          "CNA",
          "CWE-338",
          "CWE-340"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/PerlDancer/Dancer2/blob/v2.1.0/lib/Dancer2/Core/Role/SessionFactory.pm#L142",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-5080",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 891,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13584",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T00:29:37.578Z",
      "date_published": "2026-07-30T06:44:46.128Z",
      "date_updated": "2026-08-04T03:56:05.662Z",
      "publisher": "Mitsubishi",
      "title": "Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol",
      "affected": {
        "vendors": [
          "Mitsubishi Electric Corporation"
        ],
        "products": [
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "MELSEC MX Controller MX-R model MXR300-16"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "MELSEC MX Controller MX-R model MXR300-32"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "MELSEC MX Controller MX-R model MXR300-64"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "MELSEC MX Controller MX-R model MXR500-128"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "MELSEC MX Controller MX-R model MXR500-256"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "MELSEC MX Controller MX-F model MXF100-8-N32"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "MELSEC MX Controller MX-F model MXF100-8-P32"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "MELSEC MX Controller MX-F model MXF100-16-N32"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "MELSEC MX Controller MX-F model MXF100-16-P32"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Master/local module RJ71GN11-T2"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Master/local module RJ71GN11-SX"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Master/local module RJ71GN11-EIP"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Master/local module FX5-CCLGN-MS"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "CC-Link IE TSN interface board NZ81GN11-SX"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "CC-Link IE TSN interface board NZ81GN11-T2"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Motion module RD78G4"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Motion module RD78G8"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Motion module RD78G16"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Motion module RD78G64"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Motion module RD78GHV"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Motion module RD78GHW"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Motion module FX5-40SSC-G"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Motion module FX5-80SSC-G"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Motion Control Board MR-EM441G"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2S1-32D"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2S1-32T"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2S1-32TE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2S1-32DT"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2S1-32DTE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2B1-32D"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2B1-32T"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2B1-32TE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2B1-32DT"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2B1-32DTE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GNCF1-32D"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GNCF1-32T"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GNCE3-32D"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GNCE3-32DT"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN12A4-16D"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN12A4-16DE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN12A2-16T"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN12A2-16TE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN12A42-16DT"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN12A42-16DTE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2S1-16D"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2S1-16T"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2S1-16TE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2B1-16D"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2B1-16T"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module NZ2GN2B1-16TE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module with safety functions NZ2GNSS2-8D"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module with safety functions NZ2GNSS2-8D-K"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module with safety functions NZ2GNSS2-8TE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module with safety functions NZ2GNSS2-8TE-K"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module with safety functions NZ2GNSS2-16DTE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module with safety functions NZ2GNSS2-16DTE-K"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module with safety functions NZ2GNS12A2-14DT"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Block-type remote module with safety functions NZ2GNS12A2-16DTE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Analog-Digital converter module NZ2GN2S-60AD4"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Analog-Digital converter module NZ2GN2B-60AD4"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Digital-Analog converter module NZ2GN2S-60DA4"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Digital-Analog converter module NZ2GN2B-60DA4"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "CC-Link IE TSN compatible coupler NZ2FT-GN"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "FPGA module NZ2GN2S-D41P01"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "FPGA module NZ2GN2S-D41D01"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "FPGA module NZ2GN2S-D41PD02"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Tension meter LM7-1LG"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Tension meter LM7-2LG"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "AC Servo MELSERVO-J5 MR-J5-G"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "AC Servo MELSERVO-J5 MR-J5W-G"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "AC Servo MELSERVO-J5 MR-J5-G-HS"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "AC Servo MELSERVO-J5 MR-J5-G-RJ"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "AC Servo MELSERVO-J5 MR-J5-G-LL"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "AC Servo MELSERVO-J5 MR-J5D-G4"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "AC Servo MELSERVO-J5 MR-MD333G"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "AC Servo MELSERVO-JET MR-JET-G"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "AC Servo MELSERVO-JET MR-JET-G4-HS"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Inverter FR-A800/F800/E800 Series FR-A8NCG"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Inverter FR-A800/F800/E800 Series FR-A8NCG-S"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Inverter FR-A800/F800/E800 Series FR-A800-GN"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Inverter FR-A800/F800/E800 Series FR-E800-E"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Inverter FR-A800/F800/E800 Series FR-E800-SCE"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "CC-Link IE TSN expansion unit FCU8-EX569"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Industrial Computer MELIPC series MI2532-W"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Industrial Computer MELIPC series MI2332-W"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "GOT3000 Series GT3715-FHCBD"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "GOT3000 Series GT3712-WXCBD"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "GOT3000 Series GT3715-XRBA"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "GOT3000 Series GT3715-XRBD"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "GOT3000 Series GT3712-XRBA"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "GOT3000 Series GT3712-XRBD"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "GOT3000 Series GT3710-XRBA"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "GOT3000 Series GT3710-XRBD"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "GOT3000 Series GT3708-XRBA"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "GOT3000 Series GT3708-XRBD"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "CC-Link IE TSN Communication Unit GT25-J71GN13-T2"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Motion Control Software SWM-G"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Motion Control Software SWM-G-N1"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Master/Local module Designated communication LSI NZ2GACP610-60"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Remote Station Communication LSI with GbE-PHY NZ2GACP620-60"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Remote Station Communication LSI with GbE-PHY NZ2GACP620-300"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Remote Station Communication LSI with GbE-PHY NZ2GACP621-90"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Remote Station Communication LSI with GbE-PHY NZ2GACP621-720"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Remote station software development kit SW1DNC-GNSDK1S-M"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Remote station software development kit SW1DNC-GNSDK2S-M"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Liner Track System MTR-S series Linear track control module MTR-SCU00-4G"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Liner Track System MTR-S series Linear track control module MTR-SCU00-PG"
          },
          {
            "vendor": "Mitsubishi Electric Corporation",
            "product": "Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M"
          }
        ],
        "affectedBlockCount": 115,
        "versionEntryCount": 115,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-924",
          "name": "Improper Enforcement of Message Integrity During Transmission in a Communication Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02755
      },
      "nvd": {
        "published": "2026-07-30T07:16:56.327",
        "lastModified": "2026-08-04T05:16:37.030",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13584",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CC-Link IE TSN control messages lack enforced integrity protection, so a network peer can alter control values in transit.",
        "basis": [
          "CNA",
          "CWE-924"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf",
          "host": "www.mitsubishielectric.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://jvn.jp/vu/JVNVU98879231/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1718,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 115,
        "affectedVersionEntryCount": 115
      }
    },
    {
      "cve_id": "CVE-2026-13585",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T00:35:42.676Z",
      "date_published": "2026-07-15T02:01:10.343Z",
      "date_updated": "2026-07-21T07:48:30.492Z",
      "publisher": "ASUS",
      "title": "Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive ...",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "System Control Interface v3"
          },
          {
            "vendor": "ASUS",
            "product": "System Control Interface"
          },
          {
            "vendor": "ASUS",
            "product": "Business Manager"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-226",
          "name": "Sensitive Information in Resource Not Removed Before Reuse",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:H/SI:N/SA:H"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.2298
      },
      "nvd": {
        "published": "2026-07-15T02:18:12.213",
        "lastModified": "2026-07-21T09:16:52.490",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13585",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A crafted IOCTL can request an allocation without an effective bound, exhausting kernel resources.",
        "basis": [
          "CNA",
          "CWE-226",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory/",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://seclists.org/fulldisclosure/2026/Jul/26",
          "host": "seclists.org",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 482,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13597",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T07:36:53.053Z",
      "date_published": "2026-07-27T06:00:03.687Z",
      "date_updated": "2026-07-27T13:52:26.324Z",
      "publisher": "WPScan",
      "title": "QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "微信二维码登陆"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17707
      },
      "nvd": {
        "published": "2026-07-27T07:16:25.127",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13597",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The WeChat webhook signature check always succeeds, so a forged login event yields a redeemable login code for the named account.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/5e856219-ece5-4d79-8375-fc0cbdc37d6c/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 433,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13602",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T08:26:50.725Z",
      "date_published": "2026-07-01T13:45:30.615Z",
      "date_updated": "2026-07-01T15:27:00.431Z",
      "publisher": "rami.io",
      "title": "Session takeover vulnerability",
      "affected": {
        "vendors": [
          "pretix"
        ],
        "products": [
          {
            "vendor": "pretix",
            "product": "pretix"
          },
          {
            "vendor": "pretix",
            "product": "pretix-mollie"
          },
          {
            "vendor": "pretix",
            "product": "pretix-oppwa"
          },
          {
            "vendor": "pretix",
            "product": "pretix-bitpay"
          },
          {
            "vendor": "pretix",
            "product": "pretix-payone"
          },
          {
            "vendor": "pretix",
            "product": "pretix-secuconnect"
          },
          {
            "vendor": "pretix",
            "product": "pretix-sofort"
          },
          {
            "vendor": "pretix",
            "product": "pretix-saferpay"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 10,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-323",
          "name": "Reusing a Nonce, Key Pair in Encryption",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U"
        },
        {
          "source": "NVD:655498c3-6ec5-4f0b-aea6-853b334d05a6",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00271,
        "percentile": 0.19296
      },
      "nvd": {
        "published": "2026-07-01T15:16:29.597",
        "lastModified": "2026-07-02T18:43:45.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13602",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pretix reuses one signature key and salt across unrelated redirect and payment flows, allowing a signature for arbitrary content to authorize attacker-chosen session parameters and user impersonation.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-323"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://pretix.eu/about/en/blog/20260701-release-2026-5-3/",
          "host": "pretix.eu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2282,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-13603",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T08:26:51.607Z",
      "date_published": "2026-07-01T13:18:09.434Z",
      "date_updated": "2026-07-01T14:07:36.332Z",
      "publisher": "rami.io",
      "title": "SSRF with API key leak in pretix-oppwa",
      "affected": {
        "vendors": [
          "pretix"
        ],
        "products": [
          {
            "vendor": "pretix",
            "product": "pretix-oppwa"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:U"
        },
        {
          "source": "NVD:655498c3-6ec5-4f0b-aea6-853b334d05a6",
          "type": "Secondary",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21043
      },
      "nvd": {
        "published": "2026-07-01T14:16:31.910",
        "lastModified": "2026-07-02T18:43:45.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13603",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server follows an attacker-controlled outbound URL without constraining its destination to the intended remote service.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://pretix.eu/about/en/blog/20260701-release-2026-5-3/",
          "host": "pretix.eu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1230,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13605",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T08:32:22.616Z",
      "date_published": "2026-07-29T06:00:02.458Z",
      "date_updated": "2026-07-29T12:46:24.654Z",
      "publisher": "WPScan",
      "title": "Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "PhotoSwipe"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14612
      },
      "nvd": {
        "published": "2026-07-29T07:16:41.350",
        "lastModified": "2026-07-30T14:16:31.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13605",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The lightbox writes an author-controlled title attribute into the DOM as a caption without escaping it for the destination context.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/7ec73098-99eb-48cb-8ff6-a05110691117/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 474,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13609",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T09:06:42.784Z",
      "date_published": "2026-07-31T06:00:11.859Z",
      "date_updated": "2026-07-31T16:44:13.155Z",
      "publisher": "WPScan",
      "title": "Frontend Admin by DynamiApps < 3.29.9 - Unauthenticated Stored Cross-Site Scripting via Form Field",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Frontend Admin by DynamiApps"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.1593
      },
      "nvd": {
        "published": "2026-07-31T07:16:24.377",
        "lastModified": "2026-07-31T17:16:32.347",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13609",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Frontend Admin by DynamiApps rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/836bc6cd-42f0-4cd9-bb4c-ce5b0ff0d84b/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T11:08:13.255Z",
      "date_published": "2026-07-29T06:00:02.637Z",
      "date_updated": "2026-07-29T12:38:26.923Z",
      "publisher": "WPScan",
      "title": "UsersWP < 1.2.67 - Two-Factor Authentication Bypass",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "UsersWP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16876
      },
      "nvd": {
        "published": "2026-07-29T07:16:41.460",
        "lastModified": "2026-07-30T14:16:31.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13690",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The UsersWP access path accepts an identity or request signal that is insufficient to authenticate the actor for the requested operation.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/144202a9-e86f-4977-a97a-eca673859c81/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13692",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T11:08:17.699Z",
      "date_published": "2026-07-29T06:00:02.834Z",
      "date_updated": "2026-07-29T12:35:25.421Z",
      "publisher": "WPScan",
      "title": "PayU CommercePro <= 3.8.9 - Unauthenticated Order Tampering",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "PayU CommercePro Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.07958
      },
      "nvd": {
        "published": "2026-07-29T07:16:41.560",
        "lastModified": "2026-07-30T14:16:31.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13692",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The PayU handler changes WooCommerce orders without verifying the payment gateway's signature.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e2dc15c7-2210-4be8-b7f3-55a9477e488d/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13693",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T11:08:19.595Z",
      "date_published": "2026-07-21T06:00:01.381Z",
      "date_updated": "2026-07-21T15:10:14.383Z",
      "publisher": "WPScan",
      "title": "Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Bit Form"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20264
      },
      "nvd": {
        "published": "2026-07-21T07:16:33.827",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13693",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/3a01cd45-1d36-4e36-aca8-947353c474a7/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13694",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T11:08:35.090Z",
      "date_published": "2026-07-21T06:00:01.558Z",
      "date_updated": "2026-07-21T15:19:28.801Z",
      "publisher": "WPScan",
      "title": "Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Bit Form"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10393
      },
      "nvd": {
        "published": "2026-07-21T07:16:33.927",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13694",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A workflow token remains accepted after the state in which it should expire.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/3ed474fc-8363-4068-9a12-3d63be4a81bd/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13696",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T11:13:06.325Z",
      "date_published": "2026-07-07T11:15:55.926Z",
      "date_updated": "2026-07-07T13:23:40.439Z",
      "publisher": "TR-CERT",
      "title": "LDAP Injection in HAVELSAN's Liman MYS",
      "affected": {
        "vendors": [
          "HAVELSAN Inc."
        ],
        "products": [
          {
            "vendor": "HAVELSAN Inc.",
            "product": "Liman MYS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-90",
          "name": "Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00355,
        "percentile": 0.28227
      },
      "nvd": {
        "published": "2026-07-07T12:16:32.730",
        "lastModified": "2026-07-07T14:16:28.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13696",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component lets attacker-controlled text cross into an executable or interpreted grammar without the required separation.",
        "basis": [
          "CNA",
          "CWE-90"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0504",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T11:30:50.679Z",
      "date_published": "2026-07-29T16:32:39.519Z",
      "date_updated": "2026-07-29T17:53:57.335Z",
      "publisher": "openjs",
      "title": "undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives",
      "affected": {
        "vendors": [
          "undici"
        ],
        "products": [
          {
            "vendor": "undici",
            "product": "undici"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-525",
          "name": "Use of Web Browser Cache Containing Sensitive Information",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.00313,
        "percentile": 0.2367
      },
      "nvd": {
        "published": "2026-07-29T17:16:50.503",
        "lastModified": "2026-08-04T14:17:59.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13697",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Undici misparses a malformed Cache-Control private directive, causing a shared cache to store a private response and also exposing an uncaught parser exception path.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-248",
          "CWE-525"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 850,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T11:47:58.522Z",
      "date_published": "2026-07-06T14:13:49.479Z",
      "date_updated": "2026-07-06T15:28:16.081Z",
      "publisher": "OpenVPN",
      "title": "A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service",
      "affected": {
        "vendors": [
          "OpenVPN"
        ],
        "products": [
          {
            "vendor": "OpenVPN",
            "product": "OpenVPN"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@openvpn.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23761
      },
      "nvd": {
        "published": "2026-07-06T15:16:35.140",
        "lastModified": "2026-07-09T13:05:30.767",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13698",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-triggerable path allocates or retains memory without releasing it when the operation ends.",
        "basis": [
          "CNA",
          "CWE-401",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.openvpn.net/Security%20Announcements/CVE-2026-13698",
          "host": "community.openvpn.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13699",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T11:55:12.660Z",
      "date_published": "2026-07-14T07:38:23.271Z",
      "date_updated": "2026-07-14T12:32:37.446Z",
      "publisher": "eclipse",
      "title": "Databroker 0.6.1 PublishValue missing data_point panic",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse KUKSA - Databroker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14857
      },
      "nvd": {
        "published": "2026-07-14T09:16:40.050",
        "lastModified": "2026-07-14T20:55:09.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13699",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PublishValue dereferences an omitted optional data_point field with unwrap instead of rejecting the incomplete request, panicking the worker handling that call.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/148",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 663,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13704",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T13:16:34.616Z",
      "date_published": "2026-07-02T05:35:14.362Z",
      "date_updated": "2026-07-02T12:35:05.389Z",
      "publisher": "Wordfence",
      "title": "GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form",
      "affected": {
        "vendors": [
          "stellarwp"
        ],
        "products": [
          {
            "vendor": "stellarwp",
            "product": "GiveWP – Donation Plugin and Fundraising Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14235
      },
      "nvd": {
        "published": "2026-07-02T06:16:13.620",
        "lastModified": "2026-07-02T13:58:56.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13704",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A donation-form image value is stored and later inserted into a page without sufficient input sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ee18552b-2814-4598-9b7b-7c919d6d644e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.14.6/includes/admin/forms/class-metabox-form-data.php#L1180",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.14.6/includes/formatting.php#L758",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.14.6/src/Views/Form/Templates/Sequoia/Sequoia.php#L459",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.14.6/src/Views/Form/Templates/Sequoia/sections/introduction.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Views/Form/Templates/Sequoia/sections/introduction.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Views/Form/Templates/Sequoia/Sequoia.php#L459",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/includes/admin/forms/class-metabox-form-data.php#L1180",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/includes/formatting.php#L758",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13705",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T13:21:04.275Z",
      "date_published": "2026-07-06T12:03:38.513Z",
      "date_updated": "2026-07-06T19:24:38.327Z",
      "publisher": "CPANSec",
      "title": "Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle",
      "affected": {
        "vendors": [
          "TONYC"
        ],
        "products": [
          {
            "vendor": "TONYC",
            "product": "Imager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03469
      },
      "nvd": {
        "published": "2026-07-06T13:16:32.447",
        "lastModified": "2026-07-06T20:16:29.587",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13705",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SGI reader compares a 16-bit RLE pixel count with remaining bytes even though each pixel consumes two bytes, allowing a heap read past the buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tonycoz/imager/commit/f28de02770dfc26ffbdc32048970ed84babbf730.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/release/TONYC/Imager-1.032/source/Changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/06/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 724,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13706",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T13:21:21.798Z",
      "date_published": "2026-07-01T14:29:49.167Z",
      "date_updated": "2026-07-01T15:44:29.349Z",
      "publisher": "wikimedia-foundation",
      "title": "UrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWG",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "UrlShortener"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 8.8,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25359
      },
      "nvd": {
        "published": "2026-07-01T16:16:31.617",
        "lastModified": "2026-07-09T16:02:41.730",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13706",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "URL validation uses PHP parsing semantics that disagree with WHATWG URL interpretation, allowing a URL rejected under one trust model to be accepted under the other.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T418533",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 163,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13707",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T13:21:39.196Z",
      "date_published": "2026-07-01T14:32:26.598Z",
      "date_updated": "2026-07-01T15:46:18.205Z",
      "publisher": "wikimedia-foundation",
      "title": "Session fixation attacks on improperly configured OAuth 1.0a tools",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "OAuth"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-384",
          "name": "Session Fixation",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 7.6,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15128
      },
      "nvd": {
        "published": "2026-07-01T16:16:31.743",
        "lastModified": "2026-07-13T15:29:34.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13707",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The OAuth authentication flow preserves an attacker-chosen session identifier across login instead of rotating it.",
        "basis": [
          "CNA",
          "CWE-384"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T428324",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13708",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T13:22:53.937Z",
      "date_published": "2026-07-06T12:04:10.659Z",
      "date_updated": "2026-07-06T18:53:51.698Z",
      "publisher": "CPANSec",
      "title": "Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol",
      "affected": {
        "vendors": [
          "TONYC"
        ],
        "products": [
          {
            "vendor": "TONYC",
            "product": "Imager::File::JPEG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30217
      },
      "nvd": {
        "published": "2026-07-06T13:16:32.567",
        "lastModified": "2026-07-06T19:16:55.830",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13708",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Each APP13 marker allocation overwrites the prior pointer without freeing it, so repeated markers steadily consume heap memory.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tonycoz/imager/commit/9f1c485ca3ee15dc261549e11afb356866552c3a.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/release/TONYC/Imager-File-JPEG-1.003/source/Changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/06/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 759,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13710",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T13:40:16.801Z",
      "date_published": "2026-07-10T09:32:44.348Z",
      "date_updated": "2026-07-10T10:16:17.458Z",
      "publisher": "Wordfence",
      "title": "Jeg Kit for Elementor <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget",
      "affected": {
        "vendors": [
          "jegtheme"
        ],
        "products": [
          {
            "vendor": "jegtheme",
            "product": "Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.10002
      },
      "nvd": {
        "published": "2026-07-10T10:16:23.270",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13710",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In the affected component, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/be78b7d5-3f99-46de-b2b8-14254ee1ab71?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.6/class/elements/views/class-image-box-view.php#L72",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.6/class/elements/views/class-image-box-view.php#L58",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.6/class/elements/views/class-image-box-view.php#L27",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.1.1/class/elements/views/class-image-box-view.php#L72",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.1.1/class/elements/views/class-image-box-view.php#L58",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.1.1/class/elements/views/class-image-box-view.php#L27",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3596439%40jeg-elementor-kit&new=3596439%40jeg-elementor-kit",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 749,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T13:57:19.498Z",
      "date_published": "2026-07-16T21:35:31.477Z",
      "date_updated": "2026-07-17T13:18:02.930Z",
      "publisher": "CPANSec",
      "title": "YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack",
      "affected": {
        "vendors": [
          "TODDR"
        ],
        "products": [
          {
            "vendor": "TODDR",
            "product": "YAML::Syck"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03314
      },
      "nvd": {
        "published": "2026-07-16T22:16:59.640",
        "lastModified": "2026-07-17T15:07:41.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13713",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "YAML::Syck retains or reuses an object after its storage has been freed, allowing later processing to access invalid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-415",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/TODDR/YAML-Syck-1.47/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/17/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 809,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13714",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:01:16.303Z",
      "date_published": "2026-07-27T06:00:03.927Z",
      "date_updated": "2026-07-27T16:11:22.377Z",
      "publisher": "WPScan",
      "title": "Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Realtyna Organic IDX plugin + WPL Real Estate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37711
      },
      "nvd": {
        "published": "2026-07-27T07:16:25.227",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13714",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The default-enabled upload API uses credentials shared by every installation and accepts executable PHP files without a file-type restriction.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/69f9dcd8-ab3c-46ed-ac6b-2f1db35f8d1f/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13722",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:21:49.222Z",
      "date_published": "2026-07-02T23:06:12.339Z",
      "date_updated": "2026-07-07T03:56:36.130Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14119
      },
      "nvd": {
        "published": "2026-07-03T00:16:52.010",
        "lastModified": "2026-07-07T05:16:49.130",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13722",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The backup restore path accepts a firmware image without correctly verifying its cryptographic signature before installation.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00022",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 375,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-13723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:24:39.792Z",
      "date_published": "2026-07-29T17:25:22.185Z",
      "date_updated": "2026-07-29T18:21:44.159Z",
      "publisher": "certcc",
      "title": "Develar's electron-builder allows arbitrary file overwrite",
      "affected": {
        "vendors": [
          "Develar"
        ],
        "products": [
          {
            "vendor": "Develar",
            "product": "app-builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25248
      },
      "nvd": {
        "published": "2026-07-29T18:16:50.603",
        "lastModified": "2026-07-30T19:10:06.847",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13723",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ZIP extraction treats Unicode-equivalent APFS names as distinct and then follows a colliding symlink when writing the regular entry.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/develar/app-builder",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://kb.cert.org/vuls/id/293714",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/develar/app-builder/pull/163",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/293714",
          "host": "www.kb.cert.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 650,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13724",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:27:22.477Z",
      "date_published": "2026-07-20T14:32:09.075Z",
      "date_updated": "2026-07-21T14:56:53.418Z",
      "publisher": "TR-CERT",
      "title": "Business Logic Bypass in Gobito's Corporate Training Management System",
      "affected": {
        "vendors": [
          "Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co."
        ],
        "products": [
          {
            "vendor": "Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co.",
            "product": "Corporate Training Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10274
      },
      "nvd": {
        "published": "2026-07-20T16:16:55.190",
        "lastModified": "2026-07-21T16:17:05.243",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13724",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A security decision is enforced only in the client, leaving the server without an equivalent authoritative validation, while the exact server action is not public.",
        "basis": [
          "CNA",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0582",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 281,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13726",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:34:34.415Z",
      "date_published": "2026-07-27T06:00:04.110Z",
      "date_updated": "2026-07-27T16:11:59.357Z",
      "publisher": "WPScan",
      "title": "Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "MPG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.05994
      },
      "nvd": {
        "published": "2026-07-27T07:16:25.320",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13726",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/4f97b6c6-c05b-4ea5-987d-d289b89cdea8/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13728",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:36:27.889Z",
      "date_published": "2026-07-02T23:07:01.203Z",
      "date_updated": "2026-07-06T14:56:01.465Z",
      "publisher": "WatchGuard",
      "title": "WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential Database",
      "affected": {
        "vendors": [
          "WatchGuard"
        ],
        "products": [
          {
            "vendor": "WatchGuard",
            "product": "Fireware OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:5d1c2695-1a31-4499-88ae-e847036fd7e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03328
      },
      "nvd": {
        "published": "2026-07-03T00:16:52.147",
        "lastModified": "2026-07-09T19:45:20.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-13728",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00025",
          "host": "www.watchguard.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:40:54.452Z",
      "date_published": "2026-07-01T03:43:34.273Z",
      "date_updated": "2026-07-01T10:42:11.871Z",
      "publisher": "Wordfence",
      "title": "WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter",
      "affected": {
        "vendors": [
          "quantumcloud"
        ],
        "products": [
          {
            "vendor": "quantumcloud",
            "product": "WPBot – AI ChatBot for Live Support, Lead Generation, AI Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00657,
        "percentile": 0.4793
      },
      "nvd": {
        "published": "2026-07-01T05:16:18.800",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13731",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/124f2b72-d8da-46ba-844f-e9cc01441702?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/includes/chat-sessions/reports/view/partials/view-single-chat.php#L148",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/includes/chat-sessions/wpbot-chat-sessions.php#L509",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/includes/chat-sessions/wpbot-chat-sessions.php#L644",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/functions.php#L1811",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/qcld-wpwbot.php#L603",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3591600%40chatbot&new=3591600%40chatbot&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 656,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13733",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:43:51.291Z",
      "date_published": "2026-07-01T07:53:38.269Z",
      "date_updated": "2026-07-01T10:32:03.787Z",
      "publisher": "Wordfence",
      "title": "Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute",
      "affected": {
        "vendors": [
          "codename065"
        ],
        "products": [
          {
            "vendor": "codename065",
            "product": "Download Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.10002
      },
      "nvd": {
        "published": "2026-07-01T08:16:21.603",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13733",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A shortcode attribute survives the save-time filter and is reconstructed as active script at render time because output-context escaping is incomplete.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ebf96aa9-2ee7-4411-8f43-3e8d023197bd?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.59/src/Package/views/all-packages-shortcode.php#L396",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.60/src/Package/views/all-packages-shortcode.php#L396",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.60/src/Package/Shortcodes.php#L398",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.60/src/Package/Shortcodes.php#L37",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.59/src/Package/Shortcodes.php#L398",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.59/src/Package/Shortcodes.php#L37",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3590868%40download-manager&new=3590868%40download-manager&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 741,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13741",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:00:47.793Z",
      "date_published": "2026-07-16T08:26:49.183Z",
      "date_updated": "2026-07-16T13:41:56.447Z",
      "publisher": "Wordfence",
      "title": "Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter",
      "affected": {
        "vendors": [
          "UnitedOver"
        ],
        "products": [
          {
            "vendor": "UnitedOver",
            "product": "Digits: WordPress Mobile Number Signup and Login"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15894
      },
      "nvd": {
        "published": "2026-07-16T09:16:16.553",
        "lastModified": "2026-07-16T14:16:48.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13741",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/02a283b2-a369-4927-a54a-61f26bee6ace?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://digits.unitedover.com/changelog/",
          "host": "digits.unitedover.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13743",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:29:03.049Z",
      "date_published": "2026-07-02T18:35:26.637Z",
      "date_updated": "2026-07-02T19:07:38.419Z",
      "publisher": "icscert",
      "title": "Improper verification of cryptographic signature in CubeSpace CW0057 Reaction Wheel",
      "affected": {
        "vendors": [
          "CubeSpace"
        ],
        "products": [
          {
            "vendor": "CubeSpace",
            "product": "CW0057 Reaction Wheel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01882
      },
      "nvd": {
        "published": "2026-07-02T19:16:59.720",
        "lastModified": "2026-07-06T19:42:59.550",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13743",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CW0057 Reaction Wheel accepts signed material without completing the cryptographic signature verification required for authenticity.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-02",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13753",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:46:12.558Z",
      "date_published": "2026-07-06T18:00:06.663Z",
      "date_updated": "2026-07-08T17:00:16.985Z",
      "publisher": "certcc",
      "title": "CVE-2026-13753",
      "affected": {
        "vendors": [
          "HP Inc."
        ],
        "products": [
          {
            "vendor": "HP Inc.",
            "product": "HP 2800 Printer Series"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32339
      },
      "nvd": {
        "published": "2026-07-06T19:16:55.963",
        "lastModified": "2026-07-06T20:16:29.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13753",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Administrative printer APIs return protected configuration to unauthenticated network callers even though the web interface requires administrator credentials.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.cert.org/vuls/id/828543",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/828543",
          "host": "www.kb.cert.org",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:51:34.650Z",
      "date_published": "2026-07-16T07:51:03.355Z",
      "date_updated": "2026-07-18T02:42:46.187Z",
      "publisher": "Wordfence",
      "title": "Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter",
      "affected": {
        "vendors": [
          "tickera"
        ],
        "products": [
          {
            "vendor": "tickera",
            "product": "Tickera – Sell Tickets & Manage Events"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16262
      },
      "nvd": {
        "published": "2026-07-16T09:16:16.693",
        "lastModified": "2026-07-18T03:16:34.813",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13754",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The s parameter reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8113fd51-9e2b-45c4-a17b-b38072da0de9?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php#L502",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php#L485",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php#L50",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3605637%40tickera-event-ticketing-system&new=3605637%40tickera-event-ticketing-system",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:55:44.725Z",
      "date_published": "2026-07-16T07:51:06.236Z",
      "date_updated": "2026-07-16T12:37:26.767Z",
      "publisher": "Wordfence",
      "title": "Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute",
      "affected": {
        "vendors": [
          "tickera"
        ],
        "products": [
          {
            "vendor": "tickera",
            "product": "Tickera – Sell Tickets & Manage Events"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.1319
      },
      "nvd": {
        "published": "2026-07-16T09:16:16.827",
        "lastModified": "2026-07-16T13:38:53.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13755",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The price_wrapper shortcode attribute reaches stored page output without sufficient sanitization and escaping.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f266f9db-a25e-4f50-b3c8-3bea3a7e86ce?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/classes/class.shortcodes.php#L232",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/classes/class.shortcodes.php#L212",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/classes/class.shortcodes.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3605637%40tickera-event-ticketing-system&new=3605637%40tickera-event-ticketing-system",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 673,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:34:21.761Z",
      "date_published": "2026-07-11T01:29:19.566Z",
      "date_updated": "2026-07-13T16:14:52.757Z",
      "publisher": "Wordfence",
      "title": "WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter",
      "affected": {
        "vendors": [
          "WP Grid Builder"
        ],
        "products": [
          {
            "vendor": "WP Grid Builder",
            "product": "WP Grid Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22341
      },
      "nvd": {
        "published": "2026-07-11T02:16:17.457",
        "lastModified": "2026-07-13T17:17:00.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13756",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The metadata REST handler lacks both an authorization check and a protected-meta-key restriction, allowing a subscriber to write administrator privileges into their own record.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6a42e0e8-a8c7-4bc5-80ca-5ef69d1f0b6c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://docs.wpgridbuilder.com/changelog/",
          "host": "docs.wpgridbuilder.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 485,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T18:12:25.134Z",
      "date_published": "2026-07-01T19:05:18.671Z",
      "date_updated": "2026-07-01T19:23:39.104Z",
      "publisher": "AMZN",
      "title": "OS Command Injection in aws-cdk-lib Docker Bundling",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "AWS CDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.00626,
        "percentile": 0.46563
      },
      "nvd": {
        "published": "2026-07-01T19:16:36.157",
        "lastModified": "2026-07-01T20:17:01.490",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13760",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AWS CDK passes dependency-version text containing shell metacharacters into an operating-system command.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aws/aws-cdk/releases/tag/v2.260.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-050-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/aws/aws-cdk/security/advisories/GHSA-vcrf-j523-4mrf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T19:46:50.351Z",
      "date_published": "2026-07-17T03:43:42.953Z",
      "date_updated": "2026-07-17T18:05:38.965Z",
      "publisher": "Wordfence",
      "title": "LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints",
      "affected": {
        "vendors": [
          "thimpress"
        ],
        "products": [
          {
            "vendor": "thimpress",
            "product": "LearnPress – WordPress LMS Plugin for Create and Sell Online Courses"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31561
      },
      "nvd": {
        "published": "2026-07-17T05:16:37.837",
        "lastModified": "2026-07-17T19:17:12.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13765",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The quiz REST handlers return correct-answer markers and explanations without checking authentication, enrollment, or access to the target course.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ee3bbf20-43fd-4977-b0ba-b81e7a3810d0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.1/inc/rest-api/v1/frontend/class-lp-rest-users-controller.php#L434",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.1/inc/rest-api/v1/frontend/class-lp-rest-users-controller.php#L80",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.1/inc/rest-api/v1/frontend/class-lp-rest-users-controller.php#L54",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.1/inc/course/class-lp-course-no-required-enroll.php#L145",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.1/inc/rest-api/v1/frontend/class-lp-rest-users-controller.php#L181",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.1/inc/lp-template-functions.php#L1422",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.3.6/inc/rest-api/v1/frontend/class-lp-rest-users-controller.php#L434",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.3.6/inc/rest-api/v1/frontend/class-lp-rest-users-controller.php#L80",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.3.6/inc/rest-api/v1/frontend/class-lp-rest-users-controller.php#L54",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.3.6/inc/course/class-lp-course-no-required-enroll.php#L145",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.3.6/inc/rest-api/v1/frontend/class-lp-rest-users-controller.php#L181",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/learnpress/tags/4.3.6/inc/lp-template-functions.php#L1422",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3603546%40learnpress&new=3603546%40learnpress",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 14,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T20:06:54.265Z",
      "date_published": "2026-07-16T07:51:01.744Z",
      "date_updated": "2026-07-16T15:11:34.365Z",
      "publisher": "Wordfence",
      "title": "Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter",
      "affected": {
        "vendors": [
          "expresstech"
        ],
        "products": [
          {
            "vendor": "expresstech",
            "product": "Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16262
      },
      "nvd": {
        "published": "2026-07-16T09:16:16.943",
        "lastModified": "2026-07-16T16:19:00.120",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13767",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled query text is concatenated into an SQL statement without parameter binding or equivalent grammar separation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/63fec549-09e0-4d4e-ae41-128ce0669501?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.2.0/php/admin/options-page-questions-tab.php#L143",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.2.0/php/admin/options-page-questions-tab.php#L1085",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/quiz-master-next/tags/11.2.0/php/classes/class-qmn-plugin-helper.php#L601",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3608310%40quiz-master-next&new=3608310%40quiz-master-next",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 953,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-13768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T20:16:52.293Z",
      "date_published": "2026-07-02T23:40:32.780Z",
      "date_updated": "2026-07-06T14:51:30.732Z",
      "publisher": "icscert",
      "title": "Gardyn IoT Hub Use of Hard-coded Credentials",
      "affected": {
        "vendors": [
          "Gardyn"
        ],
        "products": [
          {
            "vendor": "Gardyn",
            "product": "Gardyn Home Firmware"
          },
          {
            "vendor": "Gardyn",
            "product": "Gardyn Studio Firmware"
          },
          {
            "vendor": "Gardyn",
            "product": "Gardyn Cloud API"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00582,
        "percentile": 0.44538
      },
      "nvd": {
        "published": "2026-07-03T00:16:52.270",
        "lastModified": "2026-07-06T19:42:32.890",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13768",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Gardyn devices contain the same privileged iothubowner key, allowing anyone who recovers it to authenticate to registry and device-control operations.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mygardyn.com/security/",
          "host": "mygardyn.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-03",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-03.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-13769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T20:24:05.617Z",
      "date_published": "2026-07-01T18:34:19.112Z",
      "date_updated": "2026-07-01T19:24:53.753Z",
      "publisher": "AMZN",
      "title": "Overly permissive File Permissions in AWS CLI",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "AWS CLI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01992
      },
      "nvd": {
        "published": "2026-07-01T19:16:36.300",
        "lastModified": "2026-07-01T20:17:02.330",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13769",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Affected AWS CLI subcommands write credentials with permissions inherited from a permissive umask, making the files readable to other local users.",
        "basis": [
          "CNA",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aws/aws-cli/releases/tag/1.44.78",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/aws/aws-cli/releases/tag/2.34.29",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-049-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/aws/aws-cli/security/advisories/GHSA-wfp6-f47h-hxc3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-13771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T20:59:14.917Z",
      "date_published": "2026-07-09T06:52:51.309Z",
      "date_updated": "2026-07-09T14:39:55.811Z",
      "publisher": "Wordfence",
      "title": "Customer Reviews for WooCommerce <= 5.113.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute",
      "affected": {
        "vendors": [
          "ivole"
        ],
        "products": [
          {
            "vendor": "ivole",
            "product": "Customer Reviews for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14411
      },
      "nvd": {
        "published": "2026-07-09T08:16:46.800",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-13771",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A shortcode color attribute is stored and rendered without HTML-context neutralization, allowing script-bearing markup.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f286e61a-1afc-4f51-8b53-f3456a20150a?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.113.0/templates/badge-small.php#L1",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.113.0/includes/trust-badge/class-cr-trust-badge.php#L334",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.113.0/includes/trust-badge/class-cr-trust-badge.php#L60",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.113.0/includes/trust-badge/class-cr-trust-badge.php#L30",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.108.0/templates/badge-small.php#L1",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.108.0/includes/trust-badge/class-cr-trust-badge.php#L334",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.108.0/includes/trust-badge/class-cr-trust-badge.php#L60",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.108.0/includes/trust-badge/class-cr-trust-badge.php#L30",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3597201%40customer-reviews-woocommerce&new=3597201%40customer-reviews-woocommerce",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 435,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14029",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T23:04:37.915Z",
      "date_published": "2026-07-02T08:33:08.431Z",
      "date_updated": "2026-07-02T14:53:11.664Z",
      "publisher": "Wordfence",
      "title": "Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Parameter",
      "affected": {
        "vendors": [
          "trainingbusinesspros"
        ],
        "products": [
          {
            "vendor": "trainingbusinesspros",
            "product": "Groundhogg — CRM, Newsletters, and Marketing Automation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24275
      },
      "nvd": {
        "published": "2026-07-02T10:16:28.367",
        "lastModified": "2026-07-02T15:16:58.613",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14029",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Groundhogg concatenates the select parameter into an SQL query without sufficient escaping or preparation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fb7fd98d-de1d-4b06-b769-92df40bc1873?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.7/db/query/query.php#L228",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.8/db/query/query.php#L228",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.8/db/query/query.php#L427",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.8/db/db.php#L1366",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.8/api/v4/base-object-api.php#L505",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.7/db/query/query.php#L427",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.7/db/db.php#L1366",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.7/api/v4/base-object-api.php#L505",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3591885%40groundhogg&new=3591885%40groundhogg&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 733,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T01:26:04.860Z",
      "date_published": "2026-07-08T04:30:49.869Z",
      "date_updated": "2026-07-08T12:45:11.101Z",
      "publisher": "Wordfence",
      "title": "Widget Logic Visual <= 1.52 - Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter",
      "affected": {
        "vendors": [
          "totalbounty"
        ],
        "products": [
          {
            "vendor": "totalbounty",
            "product": "Widget Logic Visual"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00501,
        "percentile": 0.4012
      },
      "nvd": {
        "published": "2026-07-08T05:16:26.463",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14158",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The widget-logic-update-conditional-tags AJAX action checks neither capability nor nonce before storing the nwlv[cod-tag] value, which is later evaluated as PHP code.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5d82e9e2-c572-4911-a6a5-1384844214b0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/widget-logic-visual/trunk/custom.php#L50",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/widget-logic-visual/trunk/ajax.php#L91",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/widget-logic-visual/trunk/ajax.php#L14",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14165",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T06:02:28.161Z",
      "date_published": "2026-07-13T07:13:53.120Z",
      "date_updated": "2026-07-13T14:47:37.703Z",
      "publisher": "3DS",
      "title": "Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5",
      "affected": {
        "vendors": [
          "Dassault Systèmes"
        ],
        "products": [
          {
            "vendor": "Dassault Systèmes",
            "product": "Tuleap Enterprise Edition"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:3DS.Information-Security@3ds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15966
      },
      "nvd": {
        "published": "2026-07-13T08:16:20.253",
        "lastModified": "2026-07-13T19:29:14.377",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14165",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tuleap accepts a caller-controlled record key without binding the selected data to its owner.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.3ds.com/trust-center/security/security-advisories/cve-2026-14165",
          "host": "www.3ds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14167",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T06:39:03.547Z",
      "date_published": "2026-07-28T09:06:01.009Z",
      "date_updated": "2026-07-28T13:29:55.370Z",
      "publisher": "CERTVDE",
      "title": "ads-tec Industrial IT: Privilege escalation during configuration import",
      "affected": {
        "vendors": [
          "ads-tec Industrial IT"
        ],
        "products": [
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF1401"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF1421"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3401"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3421"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3801"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3821"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19876
      },
      "nvd": {
        "published": "2026-07-28T09:16:41.363",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14167",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-076/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-14168",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T06:39:05.718Z",
      "date_published": "2026-07-28T09:07:26.723Z",
      "date_updated": "2026-07-28T12:46:30.943Z",
      "publisher": "CERTVDE",
      "title": "ads-tec Industrial IT: Vertical privilege escalation via configuration table write",
      "affected": {
        "vendors": [
          "ads-tec Industrial IT"
        ],
        "products": [
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF1401"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF1421"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3401"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3421"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3801"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3821"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19876
      },
      "nvd": {
        "published": "2026-07-28T09:16:41.517",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14168",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A low-privileged remote caller can insert rows through the configuration-table path because that state-changing path omits the administrator authorization check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-076/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 182,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-14169",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T06:39:07.206Z",
      "date_published": "2026-07-28T09:07:36.032Z",
      "date_updated": "2026-07-28T13:59:20.151Z",
      "publisher": "CERTVDE",
      "title": "ads-tec Industrial IT: Account lockout via non-atomic user creation",
      "affected": {
        "vendors": [
          "ads-tec Industrial IT"
        ],
        "products": [
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF1401"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF1421"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3401"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3421"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3801"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3821"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-696",
          "name": "Incorrect Behavior Order",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21003
      },
      "nvd": {
        "published": "2026-07-28T09:16:41.640",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14169",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Account-update steps run in the wrong order, allowing a low-privileged request to overwrite existing passwords and leave administrative accounts inconsistent.",
        "basis": [
          "CNA",
          "CWE-696"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-076/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-14171",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T06:39:09.811Z",
      "date_published": "2026-07-28T09:08:09.315Z",
      "date_updated": "2026-07-28T15:19:52.672Z",
      "publisher": "CERTVDE",
      "title": "ads-tec Industrial IT: Post-login open redirect in the web interface",
      "affected": {
        "vendors": [
          "ads-tec Industrial IT"
        ],
        "products": [
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF1401"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF1421"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3401"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3421"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3801"
          },
          {
            "vendor": "ads-tec Industrial IT",
            "product": "DVG-IRF3821"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08145
      },
      "nvd": {
        "published": "2026-07-28T09:16:41.840",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14171",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The web interface accepts a caller-controlled post-login redirect without restricting it to a trusted destination origin.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-076/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 212,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-14172",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T06:49:55.764Z",
      "date_published": "2026-07-24T05:51:14.326Z",
      "date_updated": "2026-07-25T03:55:23.459Z",
      "publisher": "rapid7",
      "title": "Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation",
      "affected": {
        "vendors": [
          "Rapid7"
        ],
        "products": [
          {
            "vendor": "Rapid7",
            "product": "InsightVM"
          },
          {
            "vendor": "Rapid7",
            "product": "Nexpose"
          },
          {
            "vendor": "Rapid7",
            "product": "Insight Agent"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-250",
          "name": "Execution with Unnecessary Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@rapid7.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01299
      },
      "nvd": {
        "published": "2026-07-24T07:16:32.977",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14172",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The assessment engine executes discovered files under a privileged scan identity without verifying that a trusted owner controls those executables.",
        "basis": [
          "CNA",
          "CWE-250"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.rapid7.com/insight/release-notes-2026-july/#vulnerability-management-insightvm",
          "host": "docs.rapid7.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.rapid7.com/insight/release-notes-2026-july/#rapid7-agent-insight-agent",
          "host": "docs.rapid7.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 352,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14181",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T08:01:38.033Z",
      "date_published": "2026-07-01T11:42:49.874Z",
      "date_updated": "2026-07-01T12:05:42.403Z",
      "publisher": "openjs",
      "title": "@fastify/middie standalone engine vulnerable to Denial of Service via malformed percent-encoded paths",
      "affected": {
        "vendors": [
          "@fastify/middie"
        ],
        "products": [
          {
            "vendor": "@fastify/middie",
            "product": "@fastify/middie"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21365
      },
      "nvd": {
        "published": "2026-07-01T12:16:38.343",
        "lastModified": "2026-07-02T13:50:58.743",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14181",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The standalone middie engine lets a URL-decoding exception from malformed percent encoding escape synchronously and terminate the Node.js process.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fastify/middie/security/advisories/GHSA-qcc9-jh8q-47vh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 873,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T08:11:18.256Z",
      "date_published": "2026-07-21T06:00:01.726Z",
      "date_updated": "2026-07-21T15:23:43.105Z",
      "publisher": "WPScan",
      "title": "Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Classified Listing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05821
      },
      "nvd": {
        "published": "2026-07-21T07:16:34.020",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14183",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The payment-receipt handler accepts an order identifier without verifying that the requested order belongs to the authenticated caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/5b720785-86a4-4610-83cb-8cc998d90ccf/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 277,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T08:11:21.762Z",
      "date_published": "2026-07-21T06:00:01.905Z",
      "date_updated": "2026-07-21T15:43:25.999Z",
      "publisher": "WPScan",
      "title": "Academy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modification via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Academy LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03608
      },
      "nvd": {
        "published": "2026-07-21T07:16:34.120",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14184",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation trusts a caller-supplied object identifier without binding the selected object to the caller-authorized scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/56a5b91b-1e1a-429d-b9e9-a1a107183124/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 300,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14185",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T08:11:28.886Z",
      "date_published": "2026-07-21T06:00:02.126Z",
      "date_updated": "2026-07-21T13:32:05.486Z",
      "publisher": "WPScan",
      "title": "WPBot AI ChatBot < 8.2.0 - Subscriber+ RAG Settings Update",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WPBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04886
      },
      "nvd": {
        "published": "2026-07-21T07:16:34.213",
        "lastModified": "2026-07-21T18:51:56.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14185",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A retrieval-augmented-generation settings handler changes plugin configuration without a capability or nonce check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/a6839476-95bf-4785-b128-1e3bc8603ddc/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 275,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T08:25:41.301Z",
      "date_published": "2026-07-30T06:00:05.206Z",
      "date_updated": "2026-07-30T14:12:58.069Z",
      "publisher": "WPScan",
      "title": "Easy Appointments <= 3.12.26 - Contributor+ Customer Data Disclosure",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Easy Appointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.152
      },
      "nvd": {
        "published": "2026-07-30T06:24:59.613",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14188",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A customer-listing handler returns every stored customer's data without a per-request capability or nonce check.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/46995079-58df-4c48-871b-eb2f7c8433ce/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14189",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T08:25:44.832Z",
      "date_published": "2026-07-27T06:00:04.296Z",
      "date_updated": "2026-07-27T16:13:06.651Z",
      "publisher": "WPScan",
      "title": "WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WPBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05462
      },
      "nvd": {
        "published": "2026-07-27T07:16:25.413",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14189",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WPBot incorporates attacker-controlled values or identifiers into a SQL statement without preserving the boundary between query syntax and data.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e25ea94a-f5a0-4cae-975b-9e0a45af6bc2/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14190",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T08:28:11.530Z",
      "date_published": "2026-07-27T06:00:04.474Z",
      "date_updated": "2026-07-27T16:13:42.383Z",
      "publisher": "WPScan",
      "title": "Sina Extension for Elementor < 3.10.2 - Reflected XSS",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Sina Extension for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05861
      },
      "nvd": {
        "published": "2026-07-27T07:16:25.510",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14190",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unauthenticated AJAX handler reflects a value reconstructed from request input into HTML without output escaping.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/9b855913-a55e-469d-b3cd-324c31b0d4d8/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 333,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T08:32:07.249Z",
      "date_published": "2026-07-01T02:41:39.316Z",
      "date_updated": "2026-07-09T04:47:54.319Z",
      "publisher": "securin",
      "title": "WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader",
      "affected": {
        "vendors": [
          "RARLAB"
        ],
        "products": [
          {
            "vendor": "RARLAB",
            "product": "WinRAR"
          },
          {
            "vendor": "RARLAB",
            "product": "RAR"
          },
          {
            "vendor": "RARLAB",
            "product": "UnRAR"
          },
          {
            "vendor": "RARLAB",
            "product": "UnRAR.dll"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00886,
        "percentile": 0.55748
      },
      "nvd": {
        "published": "2026-07-01T04:16:58.647",
        "lastModified": "2026-07-09T06:16:18.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14191",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A later RAR5 recovery volume supplies a RecNum that is checked against its own header but not against the already allocated RecItems vector.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-129",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rarlab.com/download.htm",
          "host": "www.rarlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40477",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://www.securin.io/zero-days/cve-2026-14191-winrar-unrar-rar5-recovery-volume-rev-out-of-bounds-heap-write-in-recvolumes5-readheader",
          "host": "www.securin.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1017,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-14193",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T08:45:55.964Z",
      "date_published": "2026-07-01T05:30:54.717Z",
      "date_updated": "2026-07-01T12:28:00.186Z",
      "publisher": "Deltaww",
      "title": "DVP80ES300T - Improper Validation of Array Index Vulnerability",
      "affected": {
        "vendors": [
          "deltaww"
        ],
        "products": [
          {
            "vendor": "deltaww",
            "product": "DVP80ES300T"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:759f5e80-c8e1-4224-bead-956d7b33c98b",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17961
      },
      "nvd": {
        "published": "2026-07-01T07:16:22.873",
        "lastModified": "2026-07-01T15:28:59.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14193",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DVP80ES300T uses an array index without validating that it falls within the target array.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00013_DVP80ES300T%20Improper%20Validation%20of%20Array%20Index%20Vulnerability%20(CVE-2026-14193).pdf",
          "host": "filecenter.deltaww.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 65,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14198",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T09:12:37.009Z",
      "date_published": "2026-07-01T11:29:20.435Z",
      "date_updated": "2026-07-01T12:10:29.571Z",
      "publisher": "openjs",
      "title": "@fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values",
      "affected": {
        "vendors": [
          "@fastify/middie"
        ],
        "products": [
          {
            "vendor": "@fastify/middie",
            "product": "@fastify/middie"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22162
      },
      "nvd": {
        "published": "2026-07-01T12:16:38.463",
        "lastModified": "2026-07-02T13:50:22.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14198",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The middleware and router canonicalize an encoded slash differently, so a protected middleware path can miss a route that still executes.",
        "basis": [
          "CNA",
          "CWE-436"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fastify/middie/security/advisories/GHSA-2v46-jxjm-7q3v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 909,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14203",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T09:22:42.751Z",
      "date_published": "2026-07-27T06:00:04.649Z",
      "date_updated": "2026-07-27T16:14:23.444Z",
      "publisher": "WPScan",
      "title": "Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Smart Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04002
      },
      "nvd": {
        "published": "2026-07-27T07:16:25.607",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14203",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Smart Manager places a contributor-controlled post field into an HTML attribute without attribute-context encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/efcaa453-80f3-4565-a4f8-eefa231d77b6/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14207",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T09:37:46.308Z",
      "date_published": "2026-07-30T06:00:08.107Z",
      "date_updated": "2026-07-30T12:48:23.464Z",
      "publisher": "WPScan",
      "title": "LifterLMS < 10.0.10 - Instructor+ Stored XSS via Featured Pricing Information",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "LifterLMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00192,
        "percentile": 0.0914
      },
      "nvd": {
        "published": "2026-07-30T06:24:59.710",
        "lastModified": "2026-07-30T14:19:00.067",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14207",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-editing role to inject JavaScript that executes in the session of an administrator who views the course.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/19085d43-63b2-4fee-b06b-c21ab96236fb/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 281,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14221",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T11:51:21.184Z",
      "date_published": "2026-07-30T06:00:05.430Z",
      "date_updated": "2026-07-30T14:22:10.147Z",
      "publisher": "WPScan",
      "title": "Easy Appointments <= 3.12.26 - Contributor+ Appointment Data Disclosure & Modification via Missing Authorization",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Easy Appointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09311
      },
      "nvd": {
        "published": "2026-07-30T06:24:59.813",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14221",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/0ab7d35e-4552-4da0-857e-7fb56e576494/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14222",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T11:51:23.181Z",
      "date_published": "2026-07-30T06:00:05.605Z",
      "date_updated": "2026-07-30T18:45:37.527Z",
      "publisher": "WPScan",
      "title": "Easy Appointments <= 3.12.26 - Contributor+ Connection Deletion via Missing Authorization",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Easy Appointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15416
      },
      "nvd": {
        "published": "2026-07-30T06:24:59.907",
        "lastModified": "2026-07-30T19:17:07.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14222",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/5b481b5f-c994-46b9-9315-008aae77f785/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14223",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T11:51:24.891Z",
      "date_published": "2026-07-30T06:00:05.797Z",
      "date_updated": "2026-07-30T18:47:42.140Z",
      "publisher": "WPScan",
      "title": "Easy Appointments <= 3.12.26 - Subscriber+ Customer PII Disclosure via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Easy Appointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10742
      },
      "nvd": {
        "published": "2026-07-30T06:25:00.010",
        "lastModified": "2026-07-30T19:17:07.317",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14223",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation accepts a caller-supplied object identifier without binding the selected object to the authenticated caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/28b71d3e-5034-42d9-8044-68c90731d38f/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14224",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T11:51:26.586Z",
      "date_published": "2026-07-29T06:00:03.059Z",
      "date_updated": "2026-07-29T12:34:09.008Z",
      "publisher": "WPScan",
      "title": "Easy Appointments <= 3.12.26 - Subscriber+ Cross-User Appointment Data Modification via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Easy Appointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04321
      },
      "nvd": {
        "published": "2026-07-29T07:16:41.657",
        "lastModified": "2026-07-30T14:16:31.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14224",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/c39226d5-1b6f-4f08-903c-7ecc67d17eb0/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 759,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T11:51:30.860Z",
      "date_published": "2026-07-30T06:00:06.270Z",
      "date_updated": "2026-07-30T18:57:04.017Z",
      "publisher": "WPScan",
      "title": "Easy Appointments <= 3.12.26 - Subscriber+ Sensitive Information Disclosure via REST Appointments Listing",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Easy Appointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13136
      },
      "nvd": {
        "published": "2026-07-30T06:25:00.117",
        "lastModified": "2026-07-30T20:16:52.613",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14226",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An appointment-listing REST endpoint requires only a capability held by every authenticated user and therefore returns all bookings to subscribers.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/fa201b6f-af45-4ce9-aa3b-3688ae556965/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14227",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T12:02:13.218Z",
      "date_published": "2026-07-30T17:39:59.616Z",
      "date_updated": "2026-07-30T19:15:52.381Z",
      "publisher": "icscert",
      "title": "Insufficient session expiration in MikroTik RouterOS",
      "affected": {
        "vendors": [
          "MikroTik"
        ],
        "products": [
          {
            "vendor": "MikroTik",
            "product": "RouterOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00222,
        "percentile": 0.1288
      },
      "nvd": {
        "published": "2026-07-30T19:17:07.493",
        "lastModified": "2026-07-30T20:16:52.840",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14227",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RouterOS leaves an existing API session's old permissions active after inactivity expiry or a user-group reduction.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14231",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T12:47:48.451Z",
      "date_published": "2026-07-30T06:00:08.294Z",
      "date_updated": "2026-07-30T14:24:19.119Z",
      "publisher": "WPScan",
      "title": "LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "LifterLMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13137
      },
      "nvd": {
        "published": "2026-07-30T06:25:00.217",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14231",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The handler checks only that the caller is signed in and omits the capability required to query the protected post type.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/2a353964-9f4c-4528-b187-42766f0cfaed/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14234",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T12:50:34.527Z",
      "date_published": "2026-07-29T06:00:03.238Z",
      "date_updated": "2026-07-30T15:20:18.427Z",
      "publisher": "WPScan",
      "title": "WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WOLF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00099,
        "percentile": 0.00977
      },
      "nvd": {
        "published": "2026-07-29T07:16:41.757",
        "lastModified": "2026-07-30T16:16:55.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14234",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An AJAX action accepts a cross-site request without a nonce or capability check and writes attacker-supplied script content into a post.",
        "basis": [
          "CNA record",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/ba3b8f4a-772f-42ad-9c67-5623406118c1/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14235",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T12:55:00.420Z",
      "date_published": "2026-07-27T06:00:04.830Z",
      "date_updated": "2026-07-27T13:51:14.401Z",
      "publisher": "WPScan",
      "title": "WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Download Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14168
      },
      "nvd": {
        "published": "2026-07-27T07:16:25.700",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14235",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A temporary download token is neither session-bound nor promptly expired, leaving a leaked token reusable as a portable bearer credential.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/9634b51c-59a1-45f6-8b09-421d6bfd0204/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14236",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T12:57:33.276Z",
      "date_published": "2026-07-27T06:00:05.067Z",
      "date_updated": "2026-07-27T17:29:31.136Z",
      "publisher": "WPScan",
      "title": "Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Contact Form 7"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06738
      },
      "nvd": {
        "published": "2026-07-27T07:16:25.797",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14236",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Stripe integration accepts a caller-controlled return host and redirects the browser without constraining it to an approved origin.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/b53cc13d-c59e-4c11-aa71-fa1c38c2a34d/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14239",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T13:13:58.782Z",
      "date_published": "2026-07-30T06:00:12.663Z",
      "date_updated": "2026-07-30T06:00:12.663Z",
      "publisher": "WPScan",
      "title": "Tourmaster < 5.4.8 - Stored XSS via CSRF",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "tourmaster"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "epss": {
        "score": 0.00125,
        "percentile": 0.02616
      },
      "nvd": {
        "published": "2026-07-30T06:25:00.337",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14239",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The settings request lacks a session-bound nonce and stores an attacker-controlled label that is later rendered without escaping in the administrator interface.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/1cd293c6-10c3-4a5c-914e-b3bdcd316d2b/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 388,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14244",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T13:48:04.159Z",
      "date_published": "2026-07-08T04:30:49.005Z",
      "date_updated": "2026-07-08T15:08:49.752Z",
      "publisher": "Wordfence",
      "title": "Jssor Slider by jssor.com <= 3.1.24 - Unauthenticated Arbitrary File Read via 'url' Parameter",
      "affected": {
        "vendors": [
          "jssor"
        ],
        "products": [
          {
            "vendor": "jssor",
            "product": "Jssor Slider by jssor.com"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00692,
        "percentile": 0.49317
      },
      "nvd": {
        "published": "2026-07-08T05:16:26.700",
        "lastModified": "2026-07-08T16:16:27.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14244",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled path is used without confinement to the intended directory, allowing file access outside that namespace.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0cd880c9-75fe-420b-ae41-558678adb57b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jssor-slider/tags/3.1.24/interface/api/class-jssor-slider-admin-controller.php#L414",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jssor-slider/tags/3.1.24/interface/api/class-jssor-slider-admin-controller.php#L506",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jssor-slider/tags/3.1.24/interface/api/class-jssor-slider-admin-controller.php#L307",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jssor-slider/tags/3.1.24/jssor-slider.php#L128",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jssor-slider/tags/3.1.24/jssor-slider-dispatcher.php#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/jssor-slider/tags/3.1.24/interface/api/class-jssor-slider-admin-controller.php#L43",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14245",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T13:50:30.634Z",
      "date_published": "2026-07-09T07:55:14.036Z",
      "date_updated": "2026-07-09T12:24:12.159Z",
      "publisher": "Wordfence",
      "title": "miniOrange OTP Login, Verification and SMS Notifications <= 5.5.1 - Authentication Bypass to Administrator Account Takeover via 'username_b' Parameter",
      "affected": {
        "vendors": [
          "cyberlord92"
        ],
        "products": [
          {
            "vendor": "cyberlord92",
            "product": "miniOrange OTP Login, Verification and SMS Notifications"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00586,
        "percentile": 0.44714
      },
      "nvd": {
        "published": "2026-07-09T08:16:46.933",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14245",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "um_reset_password_process_hook accepts an arbitrary username without binding it to a completed OTP session and returns a password-reset URL for that account.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d34f4e77-f384-4d84-be32-0d349962b614?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.1/handler/forms/class-moumpasswordreset.php#L372",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.1/handler/forms/class-moumpasswordreset.php#L367",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.1/handler/forms/class-moumpasswordreset.php#L181",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.1/handler/forms/class-moumpasswordreset.php#L98",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.0/handler/forms/class-moumpasswordreset.php#L372",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.0/handler/forms/class-moumpasswordreset.php#L367",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.0/handler/forms/class-moumpasswordreset.php#L181",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-otp-verification/tags/5.5.0/handler/forms/class-moumpasswordreset.php#L98",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3595061%40miniorange-otp-verification&new=3595061%40miniorange-otp-verification",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1094,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14249",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T14:10:36.813Z",
      "date_published": "2026-07-02T05:35:06.954Z",
      "date_updated": "2026-07-02T15:03:09.103Z",
      "publisher": "Wordfence",
      "title": "Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter",
      "affected": {
        "vendors": [
          "emarket-design"
        ],
        "products": [
          {
            "vendor": "emarket-design",
            "product": "Request a Quote – Quote Forms for Any WordPress Site"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25846
      },
      "nvd": {
        "published": "2026-07-02T06:16:13.760",
        "lastModified": "2026-07-02T15:16:58.907",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14249",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "emd_delete_file derives a PHP function name from the public path parameter and invokes it as a variable function after exposing the only nonce on the public form page.",
        "basis": [
          "CNA",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5a349c4f-d2e7-47af-9013-3cfa496b3b8c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/request-a-quote/tags/2.5.5/includes/common-functions.php#L1038",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/request-a-quote/tags/2.5.5/includes/class-install-deactivate.php#L60",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/request-a-quote/tags/2.5.5/includes/emd-form-builder-lite/emd-form-frontend.php#L1187",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/request-a-quote/tags/2.5.5/includes/common-functions.php#L1035",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3592676%40request-a-quote&new=3592676%40request-a-quote&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 779,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14250",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T14:19:53.767Z",
      "date_published": "2026-07-08T11:30:33.205Z",
      "date_updated": "2026-07-08T12:38:09.291Z",
      "publisher": "Wordfence",
      "title": "Themehunk Login Registration <= 1.0.2 - Unauthenticated Privilege Escalation via 'role' Parameter",
      "affected": {
        "vendors": [
          "themehunk"
        ],
        "products": [
          {
            "vendor": "themehunk",
            "product": "TH Login Registration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11194
      },
      "nvd": {
        "published": "2026-07-08T12:17:20.200",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14250",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Account creation validates a requested role against all editable roles, allowing the caller to assign the editor role.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8eee3809-133e-4fd9-ad49-cc6fe3822457?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themehunk-login-registration/tags/1.0.2/includes/class-thlogin-rest-api.php#L811",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themehunk-login-registration/tags/1.0.2/includes/class-thlogin-rest-api.php#L782",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themehunk-login-registration/tags/1.0.2/includes/class-thlogin-rest-api.php#L82",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themehunk-login-registration/tags/1.0.2/includes/class-thlogin-rest-api.php#L243",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3592690%40themehunk-login-registration&new=3592690%40themehunk-login-registration",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 593,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T14:20:10.616Z",
      "date_published": "2026-07-15T07:01:00.229Z",
      "date_updated": "2026-07-16T15:12:26.794Z",
      "publisher": "redhat",
      "title": "Gitops-operator: gitops-operator: missing allowednamespace check in reconcilerhook for clusterrole/role cases enables potential privilege escalation and dos",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift GitOps"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.12948
      },
      "nvd": {
        "published": "2026-07-15T08:16:22.383",
        "lastModified": "2026-07-16T16:19:00.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14251",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Red Hat OpenShift GitOps operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14251",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484710",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 333,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-14254",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T14:40:32.730Z",
      "date_published": "2026-07-16T14:12:56.347Z",
      "date_updated": "2026-07-16T14:54:33.736Z",
      "publisher": "Perforce",
      "title": "Improper Restriction of Excessive Authentication Attempts in Delphix Continuous Data",
      "affected": {
        "vendors": [
          "Perforce"
        ],
        "products": [
          {
            "vendor": "Perforce",
            "product": "Delphix Continuous Data"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@puppet.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25476
      },
      "nvd": {
        "published": "2026-07-16T15:16:30.617",
        "lastModified": "2026-07-16T17:47:18.287",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14254",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent login attempts are evaluated before the failed-login counter and lockout state are updated, allowing the threshold to be bypassed.",
        "basis": [
          "CNA",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://portal.perforce.com/s/cve/a91Qi0000036VKLIA2/improper-restriction-of-excessive-authentication-attempts-in-delphix-cd",
          "host": "portal.perforce.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14257",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T15:45:06.757Z",
      "date_published": "2026-07-23T12:54:23.124Z",
      "date_updated": "2026-07-23T14:44:41.856Z",
      "publisher": "seal",
      "title": "brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash",
      "affected": {
        "vendors": [
          "juliangruber"
        ],
        "products": [
          {
            "vendor": "juliangruber",
            "product": "brace-expansion"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:22e2d327-25fe-45d7-9f0c-dcd23b7108df",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26483
      },
      "nvd": {
        "published": "2026-07-23T14:17:00.250",
        "lastModified": "2026-07-23T15:48:25.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14257",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.npmjs.com/package/brace-expansion",
          "host": "www.npmjs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/juliangruber/brace-expansion",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 866,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14258",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T15:57:04.334Z",
      "date_published": "2026-07-01T09:24:51.479Z",
      "date_updated": "2026-07-01T12:20:42.349Z",
      "publisher": "redhat",
      "title": "Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17166
      },
      "nvd": {
        "published": "2026-07-01T11:16:25.980",
        "lastModified": "2026-07-01T18:31:17.080",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14258",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A specially crafted IPv6 Router Advertisement containing a zero-length Neighbor Discovery option can bypass validation during packet storage and later be reparsed without adequate validation, causing the parser to enter a non-advancing loop.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14258",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2462305",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/NetworkConfiguration/dhcpcd/commit/75289ca",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/NetworkConfiguration/dhcpcd/issues/415",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-14261",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T16:15:16.781Z",
      "date_published": "2026-07-09T12:37:43.523Z",
      "date_updated": "2026-07-09T15:21:38.397Z",
      "publisher": "certcc",
      "title": "CVE-2026-14261",
      "affected": {
        "vendors": [
          "Xerte"
        ],
        "products": [
          {
            "vendor": "Xerte",
            "product": "Xerte Online Tools"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00847,
        "percentile": 0.54533
      },
      "nvd": {
        "published": "2026-07-09T14:16:28.263",
        "lastModified": "2026-07-09T19:49:55.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14261",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The deployed /setup/ workflow remains reachable after installation and lets an unauthenticated caller reinstall Xerte against an attacker-controlled database.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thexerteproject/xerteonlinetoolkits/issues/1532",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/thexerteproject/xerteonlinetoolkits/commit/8fec6602e80c5d35903d65e65b65b794297d8e90",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.xerte.org.uk/index.php/en/news/blog/80-news/364-xerte-3-14-and-3-15-important-security-update",
          "host": "www.xerte.org.uk",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14262",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T17:21:39.776Z",
      "date_published": "2026-07-11T03:44:25.497Z",
      "date_updated": "2026-07-13T17:37:15.584Z",
      "publisher": "Wordfence",
      "title": "Simple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter",
      "affected": {
        "vendors": [
          "nicu_m"
        ],
        "products": [
          {
            "vendor": "nicu_m",
            "product": "Simple JWT Login – Allows you to use JWT on REST endpoints."
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30942
      },
      "nvd": {
        "published": "2026-07-11T05:16:32.367",
        "lastModified": "2026-07-13T18:16:26.897",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14262",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Simple JWT leaves attacker-supplied identity claims in a token before signing it, so the service authenticates the caller as the identity chosen in those claims.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cd97a7a4-9f57-4882-9e3e-0e9853416af9?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simple-jwt-login/tags/3.6.6/src/Services/AuthenticateService.php#L34",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simple-jwt-login/tags/3.6.6/src/Services/AuthenticateService.php#L163",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simple-jwt-login/tags/3.6.6/src/Services/LoginService.php#L62",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simple-jwt-login/tags/3.6.6/src/Services/BaseService.php#L269",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3597277%40simple-jwt-login&new=3597277%40simple-jwt-login",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 943,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14265",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:36:33.284Z",
      "date_published": "2026-07-01T19:34:02.095Z",
      "date_updated": "2026-07-02T15:54:59.751Z",
      "publisher": "AMZN",
      "title": "RCE via Deserialization in AWS Advanced JDBC Wrapper",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "AWS Advanced JDBC Wrapper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00416,
        "percentile": 0.34279
      },
      "nvd": {
        "published": "2026-07-01T20:17:08.087",
        "lastModified": "2026-07-09T18:05:27.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14265",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application deserializes attacker-controlled bytes with object semantics that can invoke executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aws/aws-advanced-jdbc-wrapper/releases/tag/4.0.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "patch"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-051-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Release Notes",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/aws/aws-advanced-jdbc-wrapper/security/advisories/GHSA-c5q4-97jw-jggh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 604,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14266",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:43:50.027Z",
      "date_published": "2026-07-29T17:17:13.649Z",
      "date_updated": "2026-07-30T03:55:31.679Z",
      "publisher": "zdi",
      "title": "7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "7-Zip"
        ],
        "products": [
          {
            "vendor": "7-Zip",
            "product": "7-Zip"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00919,
        "percentile": 0.5681
      },
      "nvd": {
        "published": "2026-07-29T18:16:50.720",
        "lastModified": "2026-07-30T14:19:24.857",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14266",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "7-Zip writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-444/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/17/12",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14270",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T19:23:48.664Z",
      "date_published": "2026-07-29T11:34:19.822Z",
      "date_updated": "2026-07-29T12:05:01.223Z",
      "publisher": "Wordfence",
      "title": "Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) <= 2.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload in eco_save_settings",
      "affected": {
        "vendors": [
          "ThemeComplete"
        ],
        "products": [
          {
            "vendor": "ThemeComplete",
            "product": "Extra Checkout Options - addon for Extra Product Options plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00548,
        "percentile": 0.42799
      },
      "nvd": {
        "published": "2026-07-29T12:16:35.697",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14270",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Subscriber-accessible handlers lack capability checks, allowing a low-privilege user to expand the upload allowlist and then upload executable PHP.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a929efaf-80a1-45c1-9426-6c5b45a66530?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://codecanyon.net/item/extra-checkout-options-addon-for-extra-product-options/20439659",
          "host": "codecanyon.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 777,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14282",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T01:28:08.476Z",
      "date_published": "2026-07-23T08:34:41.914Z",
      "date_updated": "2026-07-23T13:41:10.555Z",
      "publisher": "Wordfence",
      "title": "GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field",
      "affected": {
        "vendors": [
          "rtcamp"
        ],
        "products": [
          {
            "vendor": "rtcamp",
            "product": "GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00671,
        "percentile": 0.48489
      },
      "nvd": {
        "published": "2026-07-23T10:16:49.657",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14282",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload handler trusts a multipart Content-Type and moves the original filename into a web-served directory without WordPress MIME and extension validation.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ce3ae202-1227-4247-9133-5c7284392c9f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/godam/tags/1.11.2/inc/classes/wpforms/class-wpforms-field-godam-video.php#L38",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/godam/tags/1.11.2/inc/classes/wpforms/class-wpforms-field-godam-video.php#L403",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/godam/tags/1.12.2/inc/classes/wpforms/class-wpforms-field-godam-video.php#L403",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/godam/tags/1.12.2/inc/classes/wpforms/class-wpforms-field-godam-video.php#L377",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/godam/tags/1.12.2/inc/classes/wpforms/class-wpforms-field-godam-video.php#L38",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/godam/tags/1.11.2/inc/classes/wpforms/class-wpforms-field-godam-video.php#L377",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3607513%40godam&new=3607513%40godam",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 773,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14289",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T08:06:07.667Z",
      "date_published": "2026-07-27T06:00:05.244Z",
      "date_updated": "2026-07-27T17:33:53.457Z",
      "publisher": "WPScan",
      "title": "WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "FacturaONE para WooCommerce con VeriFactu"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32407
      },
      "nvd": {
        "published": "2026-07-27T07:16:25.890",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14289",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated file-writing handler relies on a cryptographic key that is empty in the default state, making its sole request authenticator forgeable.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/f08365f6-57d2-475a-82c8-c4d27286569e/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14291",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T08:48:39.322Z",
      "date_published": "2026-07-23T06:00:02.596Z",
      "date_updated": "2026-07-23T14:10:42.101Z",
      "publisher": "WPScan",
      "title": "Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "security-ninja-premium"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.2517
      },
      "nvd": {
        "published": "2026-07-23T07:16:32.397",
        "lastModified": "2026-07-23T15:16:53.917",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14291",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "One login path completes password authentication without requiring the configured one-time second factor.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/e62cfba9-4956-43ba-8554-6cdb0eb8815b/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 428,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14300",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T10:48:09.848Z",
      "date_published": "2026-07-29T06:00:03.431Z",
      "date_updated": "2026-07-30T15:20:09.656Z",
      "publisher": "WPScan",
      "title": "miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15077
      },
      "nvd": {
        "published": "2026-07-29T07:16:41.857",
        "lastModified": "2026-07-30T16:16:55.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14300",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The email-verification code is not bound to the account for which it was issued and can be replayed against another email address.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/7ecf657b-b059-4420-8c36-f38d58960d2b/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14305",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T11:10:18.024Z",
      "date_published": "2026-07-30T06:00:12.882Z",
      "date_updated": "2026-07-30T13:08:09.507Z",
      "publisher": "WPScan",
      "title": "WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Delicious"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14013
      },
      "nvd": {
        "published": "2026-07-30T06:25:00.450",
        "lastModified": "2026-07-30T14:19:00.067",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14305",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated AJAX action accepts an arbitrary post identifier and changes that post's metadata without authorizing the target object.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/6a2aecc7-3fbb-4d63-b1ac-4f8243ca872b/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14310",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T11:33:46.076Z",
      "date_published": "2026-07-30T06:00:13.058Z",
      "date_updated": "2026-07-30T13:04:36.033Z",
      "publisher": "WPScan",
      "title": "Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Tutor LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07236
      },
      "nvd": {
        "published": "2026-07-30T06:25:00.567",
        "lastModified": "2026-07-30T14:19:00.067",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14310",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tutor LMS fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/8fa51eaf-5205-492c-bcf7-81136dbf12d4/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14317",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T11:48:45.089Z",
      "date_published": "2026-07-31T06:00:05.746Z",
      "date_updated": "2026-07-31T13:35:13.963Z",
      "publisher": "WPScan",
      "title": "GiveWP < 4.16.3 - Unauthenticated Payment Gateway Restriction Bypass",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "GiveWP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12728
      },
      "nvd": {
        "published": "2026-07-31T07:16:24.490",
        "lastModified": "2026-07-31T14:16:45.777",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14317",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GiveWP derives the usable gateway from request input instead of binding payment execution to the administrator-enabled gateway set.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/fa6f5470-b30d-4052-aacd-a0571d4678ac/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14318",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T11:48:47.274Z",
      "date_published": "2026-07-30T06:00:08.464Z",
      "date_updated": "2026-07-30T14:29:11.348Z",
      "publisher": "WPScan",
      "title": "GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "GiveWP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24079
      },
      "nvd": {
        "published": "2026-07-30T06:25:00.680",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14318",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GiveWP renders attacker-controlled content without the required HTML sanitization or output escaping, allowing cross-site scripting.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/2957014f-542d-43fc-ad65-de236446eeeb/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 283,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14319",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T11:48:49.247Z",
      "date_published": "2026-07-31T06:00:05.924Z",
      "date_updated": "2026-07-31T19:34:02.938Z",
      "publisher": "WPScan",
      "title": "GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "GiveWP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.23987
      },
      "nvd": {
        "published": "2026-07-31T07:16:24.593",
        "lastModified": "2026-07-31T20:16:46.290",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14319",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A recurring-donation REST endpoint returns donor records to unauthenticated callers without enforcing the endpoint's intended access restriction.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/f90c88a8-e5a5-4bcf-8fa1-59cdfef015a4/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14322",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T12:10:19.719Z",
      "date_published": "2026-07-22T06:00:02.905Z",
      "date_updated": "2026-07-22T15:01:17.495Z",
      "publisher": "WPScan",
      "title": "Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_method",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Timetics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.07958
      },
      "nvd": {
        "published": "2026-07-22T07:16:35.307",
        "lastModified": "2026-07-22T16:30:26.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14322",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The booking workflow treats an unrecognized payment method as sufficient to create an approved booking before payment.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/0fb14dca-d4aa-4c24-bf15-37099edb7614/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 291,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14324",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T12:14:59.165Z",
      "date_published": "2026-07-01T14:09:20.582Z",
      "date_updated": "2026-07-22T13:56:24.714Z",
      "publisher": "redhat",
      "title": "Pipewire: raop rtsp null deref",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07208
      },
      "nvd": {
        "published": "2026-07-01T15:17:06.540",
        "lastModified": "2026-07-01T18:31:17.080",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14324",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The RAOP module accepts an unbounded Content-Length and continues after a failed pw_array_add allocation, leaving memory use and failure handling uncontrolled.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14324",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2495903",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-14327",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T12:16:13.432Z",
      "date_published": "2026-07-03T01:28:21.367Z",
      "date_updated": "2026-07-06T14:46:37.194Z",
      "publisher": "Wordfence",
      "title": "AR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' Parameter",
      "affected": {
        "vendors": [
          "webandprint"
        ],
        "products": [
          {
            "vendor": "webandprint",
            "product": "AR for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00459,
        "percentile": 0.3756
      },
      "nvd": {
        "published": "2026-07-03T02:16:23.470",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14327",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cfa375a8-ab07-45da-bc77-1e7edc996e05?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ar-for-wordpress/tags/8.40/includes/ar-secure-download.php#L64",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ar-for-wordpress/tags/8.40/includes/ar-secure-download.php#L98",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ar-for-wordpress/tags/8.40/ar-wordpress.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ar-for-wordpress/tags/8.40/ar-wordpress.php#L130",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3593272%40ar-for-wordpress&new=3593272%40ar-for-wordpress&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 669,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T12:29:08.320Z",
      "date_published": "2026-07-28T09:30:16.345Z",
      "date_updated": "2026-07-28T14:00:19.271Z",
      "publisher": "Wordfence",
      "title": "Eazy Plugin Manager <= 4.4.1 - Authenticated (Subscriber+) Privilege Escalation via pos_get_option AJAX Action and admin/login REST Endpoint",
      "affected": {
        "vendors": [
          "eazyplugins"
        ],
        "products": [
          {
            "vendor": "eazyplugins",
            "product": "Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30267
      },
      "nvd": {
        "published": "2026-07-28T10:16:48.020",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14328",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A subscriber can use a nonce-only AJAX handler to read connection secrets, then supply their derived hash to a public REST endpoint that issues administrator cookies.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/23a73680-ed13-4250-95e8-2933403f54e6?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/plugins-on-steroids/tags/4.4.1/libs/class.rest_api.php#L263",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/plugins-on-steroids/tags/4.4.1/plugins-on-steroids.php#L1153",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/plugins-on-steroids/tags/4.4.1/plugins-on-steroids.php#L1221",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/plugins-on-steroids/tags/4.4.1/plugins-on-steroids.php#L446",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/plugins-on-steroids/tags/4.4.1/libs/class.rest_api.php#L46",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/plugins-on-steroids/tags/4.4.1/libs/class.rest_api.php#L1478",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1297,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14330",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T12:29:58.653Z",
      "date_published": "2026-07-01T14:09:25.189Z",
      "date_updated": "2026-07-22T13:56:24.692Z",
      "publisher": "redhat",
      "title": "Pipewire: pulse server alloca stack overflow",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.01007
      },
      "nvd": {
        "published": "2026-07-01T15:17:06.663",
        "lastModified": "2026-07-01T18:31:17.080",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14330",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PulseAudio protocol server places attacker-influenced data in multiple unbounded stack allocations, allowing a request to exhaust the thread stack.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14330",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2495907",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 68,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-14333",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T12:45:23.891Z",
      "date_published": "2026-07-31T06:00:06.098Z",
      "date_updated": "2026-07-31T13:34:20.830Z",
      "publisher": "WPScan",
      "title": "Demi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup Directory",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Demi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21878
      },
      "nvd": {
        "published": "2026-07-31T07:16:24.703",
        "lastModified": "2026-07-31T14:16:45.960",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14333",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The plugin writes full-site backups to a predictable web-accessible directory without access protection.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/df673b6f-2957-460a-b6fe-6e656d9193e0/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T12:59:37.189Z",
      "date_published": "2026-07-02T08:29:16.010Z",
      "date_updated": "2026-07-02T12:26:16.287Z",
      "publisher": "eclipse",
      "title": "PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse CSI - PIA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13614
      },
      "nvd": {
        "published": "2026-07-02T10:16:28.487",
        "lastModified": "2026-07-02T17:44:12.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14336",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PIA uses a bare string-prefix issuer allowlist, so an attacker-controlled lookalike URL can supply both OIDC discovery data and signing keys.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/154",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 719,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14340",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T13:42:35.041Z",
      "date_published": "2026-07-01T21:03:00.726Z",
      "date_updated": "2026-07-02T15:54:43.817Z",
      "publisher": "GitHub_P",
      "title": "An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories",
      "affected": {
        "vendors": [
          "GitHub"
        ],
        "products": [
          {
            "vendor": "GitHub",
            "product": "Enterprise Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:product-cna@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17629
      },
      "nvd": {
        "published": "2026-07-01T21:16:43.743",
        "lastModified": "2026-07-06T17:17:56.263",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14340",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The authorization check verifies only repository readability and fails to bind a user-to-server token's installation to the target repository.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.20",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.17",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.11",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.8",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.4",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.2",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1067,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-14341",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T13:45:49.828Z",
      "date_published": "2026-07-29T19:00:21.052Z",
      "date_updated": "2026-07-29T19:45:32.122Z",
      "publisher": "GitLab",
      "title": "Missing Authorization in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25113
      },
      "nvd": {
        "published": "2026-07-29T20:17:01.063",
        "lastModified": "2026-08-03T13:28:24.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14341",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A maintainer can alter protected-branch configuration outside the intended role boundary, but the exact authorization check is not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/604665",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3807593",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14342",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T14:22:37.127Z",
      "date_published": "2026-07-09T07:55:14.853Z",
      "date_updated": "2026-07-09T12:46:41.326Z",
      "publisher": "Wordfence",
      "title": "Mail Mint <= 1.24.2 - Authenticated (Administrator+) SQL Injection via 'contact_ids' Parameter",
      "affected": {
        "vendors": [
          "getwpfunnels"
        ],
        "products": [
          {
            "vendor": "getwpfunnels",
            "product": "Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18626
      },
      "nvd": {
        "published": "2026-07-09T08:16:47.073",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14342",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The contact_ids parameter is appended to an SQL query without sufficient escaping or parameterization.",
        "basis": [
          "CNA record",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fd75e795-54b8-4b9a-9417-9f707215ebfa?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mail-mint/trunk/app/Database/Models/ContactModel.php#L1159",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mail-mint/trunk/app/API/Controllers/Admin/ContactController.php#L1049",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mail-mint/trunk/app/API/Routes/Admin/ContactRoute.php#L475",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3597255%40mail-mint&new=3597255%40mail-mint",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14343",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T14:26:42.757Z",
      "date_published": "2026-07-09T06:52:45.773Z",
      "date_updated": "2026-07-09T17:31:10.016Z",
      "publisher": "Wordfence",
      "title": "Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes",
      "affected": {
        "vendors": [
          "codename065"
        ],
        "products": [
          {
            "vendor": "codename065",
            "product": "Download Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09454
      },
      "nvd": {
        "published": "2026-07-09T08:16:47.207",
        "lastModified": "2026-07-09T18:16:50.297",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14343",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Download Manager renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/74cd34be-008c-4ff3-ae3c-417cfd2fee9b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.61/src/User/views/reg-form.php#L69",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.61/src/User/views/reg-form.php#L78",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.61/src/User/Register.php#L123",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.61/src/User/Register.php#L32",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3594267%40download-manager&new=3594267%40download-manager",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 762,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14345",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T15:32:02.804Z",
      "date_published": "2026-07-07T05:34:19.628Z",
      "date_updated": "2026-07-08T17:11:20.954Z",
      "publisher": "Wordfence",
      "title": "WPFunnels <= 3.12.7 - Unauthenticated Remote Code Execution via 'postData' Parameter",
      "affected": {
        "vendors": [
          "getwpfunnels"
        ],
        "products": [
          {
            "vendor": "getwpfunnels",
            "product": "WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00745,
        "percentile": 0.51247
      },
      "nvd": {
        "published": "2026-07-07T06:16:22.113",
        "lastModified": "2026-07-08T18:16:32.003",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14345",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The plugin writes unauthenticated postData into a log that an administrator later includes as PHP, turning stored content into server-side code.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5d84d749-0ab5-49dd-8e4f-45681f197742?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/admin/modules/settings/class-wpfnl-settings.php#L709",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/public/class-wpfnl-public.php#L1185",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/includes/core/classes/class-wpfnl-ajax-handler.php#L523",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/includes/core/classes/class-wpfnl-ajax-handler.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/admin/modules/settings/class-wpfnl-settings.php#L709",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/public/class-wpfnl-public.php#L1185",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/includes/core/classes/class-wpfnl-ajax-handler.php#L523",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/includes/core/classes/class-wpfnl-ajax-handler.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3597260/wpfunnels/trunk/admin/modules/settings/class-wpfnl-settings.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fwpfunnels/tags/3.12.7&new_path=%2Fwpfunnels/tags/3.12.8",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 825,
        "referenceCount": 11,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T16:38:30.877Z",
      "date_published": "2026-07-29T19:00:16.040Z",
      "date_updated": "2026-07-29T19:33:59.070Z",
      "publisher": "GitLab",
      "title": "Exposure of Sensitive Information Through Metadata in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1230",
          "name": "Exposure of Sensitive Information Through Metadata",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16468
      },
      "nvd": {
        "published": "2026-07-29T20:17:01.197",
        "lastModified": "2026-08-03T13:27:26.207",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14351",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A public merge request reveals the title of a linked confidential issue because the metadata serialization path omits that issue's visibility check.",
        "basis": [
          "CNA",
          "CWE-1230"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/604691",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3708242",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "exploit",
            "permissions-required",
            "technical-description"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 333,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T17:00:42.202Z",
      "date_published": "2026-07-03T04:30:16.557Z",
      "date_updated": "2026-07-06T16:24:08.921Z",
      "publisher": "Wordfence",
      "title": "AR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameter",
      "affected": {
        "vendors": [
          "webandprint"
        ],
        "products": [
          {
            "vendor": "webandprint",
            "product": "AR for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.3841
      },
      "nvd": {
        "published": "2026-07-03T06:16:21.787",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14352",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled path is used without confinement to the intended directory, allowing file access outside that namespace.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2049712a-6ff2-4e2a-98f8-93a493a5bfd3?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ar-for-woocommerce/tags/8.40/ar-woocommerce.php#L249",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ar-for-woocommerce/tags/8.40/includes/ar-secure-download.php#L64",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ar-for-woocommerce/tags/8.40/includes/ar-secure-download.php#L95",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ar-for-woocommerce/tags/8.40/ar-woocommerce.php#L143",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3593279/ar-for-woocommerce/trunk/includes/ar-secure-download.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Far-for-woocommerce/tags/8.40&new_path=%2Far-for-woocommerce/tags/8.41",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 791,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14354",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T17:31:38.767Z",
      "date_published": "2026-07-29T11:54:46.553Z",
      "date_updated": "2026-07-29T12:42:22.173Z",
      "publisher": "schneider",
      "title": "CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker lev...",
      "affected": {
        "vendors": [
          "Schneider Electric"
        ],
        "products": [
          {
            "vendor": "Schneider Electric",
            "product": "EcoStruxure™ Cybersecurity Admin Expert"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:cybersecurity@se.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01912
      },
      "nvd": {
        "published": "2026-07-29T13:17:42.723",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14354",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The application inadequately protects stored credentials, but the public record does not identify the storage format, access path, or modification check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://download.se.com/files?p_Doc_Ref=SEVD-2026-195-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-195-02.pdf",
          "host": "download.se.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14355",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T17:52:41.706Z",
      "date_published": "2026-07-03T20:57:31.958Z",
      "date_updated": "2026-07-06T13:57:58.387Z",
      "publisher": "php",
      "title": "ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD",
      "affected": {
        "vendors": [
          "php"
        ],
        "products": [
          {
            "vendor": "php",
            "product": "php"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security@php.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20139
      },
      "nvd": {
        "published": "2026-07-03T21:16:55.783",
        "lastModified": "2026-07-08T20:11:16.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14355",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The php path writes attacker-influenced data beyond the capacity of its destination buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/php/php-src/security/advisories/GHSA-7jrw-539f-x6vr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.debian.org/debian-lts-announce/2026/07/msg00010.html",
          "host": "lists.debian.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-14356",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:00:16.820Z",
      "date_published": "2026-07-30T04:03:13.320Z",
      "date_updated": "2026-07-30T13:38:31.314Z",
      "publisher": "Wordfence",
      "title": "FleekDash V2 <= 2.6.2.2 - Missing Authorization to Authenticated (Subscriber+) Administrator Account Takeover via /users/{id} REST Endpoint",
      "affected": {
        "vendors": [
          "fleekdash"
        ],
        "products": [
          {
            "vendor": "fleekdash",
            "product": "FleekDash V2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18923
      },
      "nvd": {
        "published": "2026-07-30T05:16:32.853",
        "lastModified": "2026-07-30T14:16:46.943",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14356",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The users/{id} operation accepts an attacker-selected user identifier without binding the target account to the caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0867f6a6-17f6-48d3-8ef2-bf89f5b28b05?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fleekdash/trunk/includes/Controllers/UserController.php#L413",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 757,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14358",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:31:17.357Z",
      "date_published": "2026-07-01T18:48:55.744Z",
      "date_updated": "2026-07-10T12:24:49.631Z",
      "publisher": "wikimedia-foundation",
      "title": "Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title",
      "affected": {
        "vendors": [
          "The Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "The Wikimedia Foundation",
            "product": "Mediawiki - Charts Extension"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07251
      },
      "nvd": {
        "published": "2026-07-01T19:16:50.073",
        "lastModified": "2026-07-09T18:44:46.393",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14358",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Mediawiki - Charts Extension rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T430548",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        },
        {
          "url": "https://gerrit.wikimedia.org/r/q/Ibdaa7c852ae83f562e84dddc9c96ad64e2152210",
          "host": "gerrit.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14361",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T19:00:00.428Z",
      "date_published": "2026-07-08T20:11:32.799Z",
      "date_updated": "2026-07-08T20:37:56.570Z",
      "publisher": "HashiCorp",
      "title": "Consul-template is vulnerable to path redirection in writeToFile through symlink attack",
      "affected": {
        "vendors": [
          "HashiCorp"
        ],
        "products": [
          {
            "vendor": "HashiCorp",
            "product": "Tooling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@hashicorp.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01233
      },
      "nvd": {
        "published": "2026-07-08T20:16:47.850",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14361",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "consul-template's writeToFile helper follows an attacker-influenced redirection beyond the intended output directory or file.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.hashicorp.com/t/hcsec-2026-20-consul-template-vulnerable-to-path-redirections-in-writetofile/77559",
          "host": "discuss.hashicorp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14362",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T19:07:40.964Z",
      "date_published": "2026-07-08T17:14:18.218Z",
      "date_updated": "2026-07-08T19:40:16.119Z",
      "publisher": "HashiCorp",
      "title": "Denial of service via crafted push/pull gossip message in memberlist",
      "affected": {
        "vendors": [
          "HashiCorp"
        ],
        "products": [
          {
            "vendor": "HashiCorp",
            "product": "Shared library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@hashicorp.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16583
      },
      "nvd": {
        "published": "2026-07-08T18:16:32.130",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14362",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Shared library can be driven into resource exhaustion or termination, while the unbounded operation and limit are not public.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.hashicorp.com/t/hcsec-2026-18-memberlist-vulnerable-to-denial-of-service-via-gossip-message/77556",
          "host": "discuss.hashicorp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14363",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T19:17:15.130Z",
      "date_published": "2026-07-01T19:22:33.373Z",
      "date_updated": "2026-07-02T13:10:36.142Z",
      "publisher": "wikimedia-foundation",
      "title": "Cargo Extension: SQLi in Special:Drilldown",
      "affected": {
        "vendors": [
          "The Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "The Wikimedia Foundation",
            "product": "Mediawiki - Cargo Extension"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 2.9000000000000004,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21627
      },
      "nvd": {
        "published": "2026-07-01T20:17:08.330",
        "lastModified": "2026-07-07T18:38:04.320",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14363",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Special:Drilldown passes attacker-controlled input into an SQL command without SQL grammar separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T422774",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1279498",
          "host": "gerrit.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        },
        {
          "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1269701",
          "host": "gerrit.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 261,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T19:52:49.119Z",
      "date_published": "2026-07-16T16:49:12.445Z",
      "date_updated": "2026-07-16T17:36:41.747Z",
      "publisher": "lenovo",
      "title": "The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.",
      "affected": {
        "vendors": [
          "Lenovo"
        ],
        "products": [
          {
            "vendor": "Lenovo",
            "product": "XClarity Integrator for Microsoft Windows Admin Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:psirt@lenovo.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00757,
        "percentile": 0.51623
      },
      "nvd": {
        "published": "2026-07-16T17:16:55.423",
        "lastModified": "2026-07-16T18:16:42.287",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14371",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler places caller-controlled data in an operating-system command without safe argument separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://pcsupport.lenovo.com/us/en/product_security/home",
          "host": "pcsupport.lenovo.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14372",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T19:57:09.003Z",
      "date_published": "2026-07-09T09:31:21.987Z",
      "date_updated": "2026-07-09T12:31:38.236Z",
      "publisher": "Wordfence",
      "title": "Bit Form <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion via '_old' Parameter",
      "affected": {
        "vendors": [
          "bitpressadmin"
        ],
        "products": [
          {
            "vendor": "bitpressadmin",
            "product": "Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00671,
        "percentile": 0.48482
      },
      "nvd": {
        "published": "2026-07-09T11:16:24.910",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14372",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled path or object-name data is resolved without proving that the final target remains inside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/943668eb-0185-4029-9459-f99141bf84cf?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bit-form/tags/3.1.1/includes/Core/Util/FileHandler.php#L129",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bit-form/tags/3.1.1/includes/Core/Form/FormManager.php#L1039",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bit-form/tags/3.1.1/includes/Core/Form/FormManager.php#L1044",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bit-form/tags/3.1.1/includes/Frontend/Ajax/FrontendAjax.php#L87",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bit-form/tags/3.1.1/includes/Admin/Form/Helpers.php#L302",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bit-form/trunk/includes/Core/Util/FileHandler.php#L129",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bit-form/trunk/includes/Core/Form/FormManager.php#L1039",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bit-form/trunk/includes/Core/Form/FormManager.php#L1044",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bit-form/trunk/includes/Frontend/Ajax/FrontendAjax.php#L87",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bit-form/trunk/includes/Admin/Form/Helpers.php#L302",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3598554/bit-form/trunk/includes/Core/Form/FormManager.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fbit-form/tags/3.1.1&new_path=%2Fbit-form/tags/3.1.2",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 13,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14373",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T20:10:53.797Z",
      "date_published": "2026-07-08T17:29:30.614Z",
      "date_updated": "2026-07-08T20:37:39.961Z",
      "publisher": "HashiCorp",
      "title": "Nomad Docker driver Linux host namespace bypass",
      "affected": {
        "vendors": [
          "HashiCorp"
        ],
        "products": [
          {
            "vendor": "HashiCorp",
            "product": "Nomad"
          },
          {
            "vendor": "HashiCorp",
            "product": "Nomad Enterprise"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@hashicorp.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16173
      },
      "nvd": {
        "published": "2026-07-08T20:16:48.080",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14373",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.hashicorp.com/t/hcsec-2026-19-nomad-docker-driver-vulnerable-to-host-namespace-bypass-on-linux/77557",
          "host": "discuss.hashicorp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:17:54.504Z",
      "date_published": "2026-07-07T22:04:49.078Z",
      "date_updated": "2026-07-09T14:41:58.100Z",
      "publisher": "CPANSec",
      "title": "DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile",
      "affected": {
        "vendors": [
          "HMBRAND"
        ],
        "products": [
          {
            "vendor": "HMBRAND",
            "product": "DBI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-95",
          "name": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00479,
        "percentile": 0.38854
      },
      "nvd": {
        "published": "2026-07-07T23:16:53.963",
        "lastModified": "2026-07-10T14:46:21.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14380",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DBI interpolates the caller-influenced Profile package field into a Perl string eval without validating the package grammar.",
        "basis": [
          "CNA",
          "CWE-95"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ch8w-hxc2-v557",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://metacpan.org/release/HMBRAND/DBI-1.650/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/07/16",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 946,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14381",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:23.169Z",
      "date_published": "2026-07-01T22:21:42.848Z",
      "date_updated": "2026-07-02T16:56:45.649Z",
      "publisher": "Chrome",
      "title": "Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11552
      },
      "nvd": {
        "published": "2026-07-01T23:16:46.153",
        "lastModified": "2026-07-02T18:09:43.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14381",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome presents WebApp installation security UI that a crafted page can spoof, while the exact origin-to-UI binding failure is not public.",
        "basis": [
          "CNA",
          "CWE-290",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/407283320",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:23.724Z",
      "date_published": "2026-07-01T22:21:44.011Z",
      "date_updated": "2026-07-03T03:55:34.570Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18248
      },
      "nvd": {
        "published": "2026-07-01T23:16:46.617",
        "lastModified": "2026-07-03T04:17:40.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14382",
        "family": "STATE_SEQUENCE",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "ANGLE stopped tracking transform-feedback buffers after pause and unbind, so later validation allowed those still-active buffers to be modified for another use.",
        "basis": [
          "CNA",
          "CWE-20",
          "Chrome release",
          "Chromium source commit"
        ],
        "deepDive": true,
        "notes": "Inspected https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html?m=1 and https://chromium.googlesource.com/experimental/angle/angle/+/ee21230bc87855404b87b97b738091cd04b0d3f3; the fix and tests identify transform-feedback buffer tracking, but no independent reproduction was performed."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/492218546",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:24.057Z",
      "date_published": "2026-07-01T22:21:40.462Z",
      "date_updated": "2026-07-03T03:55:47.904Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27514
      },
      "nvd": {
        "published": "2026-07-01T23:16:46.743",
        "lastModified": "2026-07-03T04:17:40.523",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14383",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record reports arbitrary code execution from an inappropriate V8 implementation but does not disclose whether the enabling defect is a memory, parser, or authority failure.",
        "basis": [
          "CNA",
          "NVD"
        ],
        "deepDive": false,
        "notes": "The listed CWE-94 and CWE-119 classes do not identify a defensible primary engineering cause."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/492410546",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14384",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:24.280Z",
      "date_published": "2026-07-01T22:21:50.812Z",
      "date_updated": "2026-07-02T16:43:45.514Z",
      "publisher": "Chrome",
      "title": "Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17982
      },
      "nvd": {
        "published": "2026-07-01T23:16:46.833",
        "lastModified": "2026-07-02T18:41:21.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14384",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome parser can read beyond the end of its input or allocated buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/497543485",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14385",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:24.631Z",
      "date_published": "2026-07-01T22:21:37.417Z",
      "date_updated": "2026-07-02T13:50:54.954Z",
      "publisher": "Chrome",
      "title": "Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25256
      },
      "nvd": {
        "published": "2026-07-01T23:16:46.937",
        "lastModified": "2026-07-02T18:09:21.333",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14385",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted page drives ANGLE to write beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/499006005",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14386",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:24.890Z",
      "date_published": "2026-07-01T22:21:52.250Z",
      "date_updated": "2026-07-02T00:34:42.907Z",
      "publisher": "Chrome",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17982
      },
      "nvd": {
        "published": "2026-07-01T23:16:47.033",
        "lastModified": "2026-07-02T18:11:48.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14386",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Chrome, an attacker-controlled index or length permits a read beyond the valid memory region.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/499047960",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14387",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:25.150Z",
      "date_published": "2026-07-01T22:21:48.111Z",
      "date_updated": "2026-07-03T03:55:31.687Z",
      "publisher": "Chrome",
      "title": "Integer overflow in Skia in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-472",
          "name": "External Control of Assumed-Immutable Web Parameter",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19818
      },
      "nvd": {
        "published": "2026-07-01T23:16:47.140",
        "lastModified": "2026-07-03T04:17:40.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14387",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Skia performs attacker-influenced size arithmetic without detecting integer overflow, allowing the resulting wrapped value to violate later memory bounds.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-472"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/500305404",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14388",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:25.380Z",
      "date_published": "2026-07-01T22:21:52.836Z",
      "date_updated": "2026-07-02T00:33:26.711Z",
      "publisher": "Chrome",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17983
      },
      "nvd": {
        "published": "2026-07-01T23:16:47.237",
        "lastModified": "2026-07-02T17:28:50.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14388",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ANGLE reads beyond a valid memory boundary while processing a crafted web page and can expose process bytes.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/500476886",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:25.665Z",
      "date_published": "2026-07-01T22:21:48.639Z",
      "date_updated": "2026-07-03T03:55:39.653Z",
      "publisher": "Chrome",
      "title": "Integer overflow in Skia in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-472",
          "name": "External Control of Assumed-Immutable Web Parameter",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14281
      },
      "nvd": {
        "published": "2026-07-01T23:16:47.340",
        "lastModified": "2026-07-03T04:17:40.877",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14389",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Skia processes crafted page data through an integer calculation that can overflow inside the compromised renderer and enable a sandbox escape.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-472"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/500505046",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:25.910Z",
      "date_published": "2026-07-01T22:22:02.404Z",
      "date_updated": "2026-07-03T03:55:17.408Z",
      "publisher": "Chrome",
      "title": "Use after free in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.145
      },
      "nvd": {
        "published": "2026-07-01T23:16:47.437",
        "lastModified": "2026-07-03T04:17:41.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14390",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ANGLE can retain and use an object after its lifetime has ended when processing attacker-controlled web content.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/503054174",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:26.245Z",
      "date_published": "2026-07-01T22:21:47.563Z",
      "date_updated": "2026-07-02T00:35:10.876Z",
      "publisher": "Chrome",
      "title": "Integer overflow in ANGLE in Google Chrome on Windows prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-472",
          "name": "External Control of Assumed-Immutable Web Parameter",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14358
      },
      "nvd": {
        "published": "2026-07-01T23:16:47.537",
        "lastModified": "2026-07-02T18:08:29.713",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14391",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ANGLE integer arithmetic can overflow and cause reads from unintended process memory.",
        "basis": [
          "CNA",
          "CWE-190",
          "CWE-472"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/506212452",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 269,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:26.470Z",
      "date_published": "2026-07-01T22:21:55.690Z",
      "date_updated": "2026-07-03T03:55:26.980Z",
      "publisher": "Chrome",
      "title": "Out of bounds write in Tint in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19818
      },
      "nvd": {
        "published": "2026-07-01T23:16:47.633",
        "lastModified": "2026-07-03T04:17:41.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14392",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tint writes beyond an allocated buffer while processing attacker-controlled web content.",
        "basis": [
          "CNA",
          "CWE-787",
          "Chrome 150 release note"
        ],
        "deepDive": true,
        "notes": "Inspected https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html; the official release confirms the Tint out-of-bounds write, while the linked Chromium issue remains access-restricted and no narrower bounds error is public."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/508265321",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14393",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:26.711Z",
      "date_published": "2026-07-01T22:22:05.837Z",
      "date_updated": "2026-07-03T03:55:54.797Z",
      "publisher": "Chrome",
      "title": "Use after free in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20369
      },
      "nvd": {
        "published": "2026-07-01T23:16:47.733",
        "lastModified": "2026-07-03T04:17:41.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14393",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511255112",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:26.963Z",
      "date_published": "2026-07-01T22:22:06.880Z",
      "date_updated": "2026-07-02T13:50:00.397Z",
      "publisher": "Chrome",
      "title": "Use after free in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.145
      },
      "nvd": {
        "published": "2026-07-01T23:16:47.830",
        "lastModified": "2026-07-02T18:03:34.023",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14394",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511263221",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 184,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:27.196Z",
      "date_published": "2026-07-01T22:21:56.246Z",
      "date_updated": "2026-07-03T03:55:50.989Z",
      "publisher": "Chrome",
      "title": "Out of bounds write in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18206
      },
      "nvd": {
        "published": "2026-07-01T23:16:47.930",
        "lastModified": "2026-07-03T04:17:41.593",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14395",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected parser writes beyond its destination buffer because attacker-controlled size or index data is not bounded.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511290389",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:27.503Z",
      "date_published": "2026-07-01T22:21:51.344Z",
      "date_updated": "2026-07-02T17:05:13.787Z",
      "publisher": "Chrome",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14877
      },
      "nvd": {
        "published": "2026-07-01T23:16:48.030",
        "lastModified": "2026-07-02T18:12:15.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14396",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome can read beyond the valid bounds of an input or object allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511737097",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:27.736Z",
      "date_published": "2026-07-01T22:21:54.590Z",
      "date_updated": "2026-07-03T03:55:28.076Z",
      "publisher": "Chrome",
      "title": "Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15536
      },
      "nvd": {
        "published": "2026-07-01T23:16:48.127",
        "lastModified": "2026-07-03T04:17:41.847",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14397",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled input reaches a write whose destination boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511772608",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:27.996Z",
      "date_published": "2026-07-01T22:22:01.799Z",
      "date_updated": "2026-07-03T03:55:36.047Z",
      "publisher": "Chrome",
      "title": "Use after free in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12001
      },
      "nvd": {
        "published": "2026-07-01T23:16:48.223",
        "lastModified": "2026-07-03T04:17:44.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14398",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/512995785",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:28.255Z",
      "date_published": "2026-07-01T22:22:00.708Z",
      "date_updated": "2026-07-02T00:31:01.602Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in Dawn in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13188
      },
      "nvd": {
        "published": "2026-07-01T23:16:48.323",
        "lastModified": "2026-07-02T17:43:14.847",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14399",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dawn uses uninitialized memory while processing attacker-influenced browser content and can disclose process bytes.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513006745",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:28.500Z",
      "date_published": "2026-07-01T22:21:55.158Z",
      "date_updated": "2026-07-03T03:55:38.587Z",
      "publisher": "Chrome",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12908
      },
      "nvd": {
        "published": "2026-07-01T23:16:48.420",
        "lastModified": "2026-07-03T04:17:44.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14400",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ANGLE can write beyond the bounds of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513010645",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14401",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:28.739Z",
      "date_published": "2026-07-01T22:21:43.441Z",
      "date_updated": "2026-07-03T03:55:44.026Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14846
      },
      "nvd": {
        "published": "2026-07-01T23:16:48.523",
        "lastModified": "2026-07-03T04:17:45.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14401",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record does not identify which ANGLE input validation failed or how the crafted page crosses the sandbox boundary.",
        "basis": [
          "CNA record",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513048822",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 269,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14402",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:28.949Z",
      "date_published": "2026-07-01T22:21:57.886Z",
      "date_updated": "2026-07-02T00:32:25.504Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13189
      },
      "nvd": {
        "published": "2026-07-01T23:16:48.620",
        "lastModified": "2026-07-02T18:05:41.273",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14402",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome uses an uninitialized value whose prior memory contents can influence or escape the operation.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513051340",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:29.175Z",
      "date_published": "2026-07-01T22:22:05.291Z",
      "date_updated": "2026-07-03T03:55:53.628Z",
      "publisher": "Chrome",
      "title": "Use after free in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17369
      },
      "nvd": {
        "published": "2026-07-01T23:16:48.723",
        "lastModified": "2026-07-03T04:17:45.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14403",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome retains and accesses an object after the object's lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513298483",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:29.470Z",
      "date_published": "2026-07-01T22:21:39.035Z",
      "date_updated": "2026-07-02T13:12:41.518Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in PDFium in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10281
      },
      "nvd": {
        "published": "2026-07-01T23:16:48.840",
        "lastModified": "2026-07-02T18:06:21.407",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14404",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's public record identifies PDF-driven UI spoofing but does not disclose which security indicator or rendering state is misrepresented.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513337989",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14405",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:29.708Z",
      "date_published": "2026-07-01T22:22:01.246Z",
      "date_updated": "2026-07-03T03:55:24.809Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23055
      },
      "nvd": {
        "published": "2026-07-01T23:16:48.947",
        "lastModified": "2026-07-03T04:17:45.577",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14405",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path consumes a variable or optional value before establishing that it was initialized.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513376037",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14406",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:29.917Z",
      "date_published": "2026-07-01T22:21:53.998Z",
      "date_updated": "2026-07-02T00:33:00.247Z",
      "publisher": "Chrome",
      "title": "Out of bounds read in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08841
      },
      "nvd": {
        "published": "2026-07-01T23:16:49.060",
        "lastModified": "2026-07-02T18:00:35.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14406",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The V8 extension-processing path reads beyond a valid memory boundary when handling a crafted Chrome extension.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513435594",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14407",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:30.137Z",
      "date_published": "2026-07-01T22:21:41.028Z",
      "date_updated": "2026-07-03T03:55:57.085Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24305
      },
      "nvd": {
        "published": "2026-07-01T23:16:49.167",
        "lastModified": "2026-07-03T04:17:46.237",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14407",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path allows attacker-controlled content to cross into an executable code context.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513586956",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14408",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:30.375Z",
      "date_published": "2026-07-01T22:22:00.125Z",
      "date_updated": "2026-07-02T00:34:09.115Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in Dawn in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13188
      },
      "nvd": {
        "published": "2026-07-01T23:16:49.260",
        "lastModified": "2026-07-02T16:09:08.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14408",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An uninitialized Dawn value is returned or copied, exposing bytes left in process memory.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513631768",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:30.582Z",
      "date_published": "2026-07-01T22:21:41.596Z",
      "date_updated": "2026-07-03T03:55:59.345Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18268
      },
      "nvd": {
        "published": "2026-07-01T23:16:49.367",
        "lastModified": "2026-07-03T04:17:46.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14409",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record names an inappropriate V8 implementation and sandboxed code execution but does not disclose the failing check, state transition, or memory operation.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513810921",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:30.822Z",
      "date_published": "2026-07-01T22:21:39.904Z",
      "date_updated": "2026-07-02T16:56:57.504Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Skia in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00191,
        "percentile": 0.08962
      },
      "nvd": {
        "published": "2026-07-01T23:16:49.463",
        "lastModified": "2026-07-02T18:41:02.020",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14410",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's Skia component can misrepresent security-relevant interface content, but the public record does not identify the incorrect visual state or rendering rule.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513836996",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14411",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:31.043Z",
      "date_published": "2026-07-01T22:21:44.570Z",
      "date_updated": "2026-07-03T03:55:33.186Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16758
      },
      "nvd": {
        "published": "2026-07-01T23:16:49.557",
        "lastModified": "2026-07-03T04:17:48.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14411",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Google identifies untrusted input in ANGLE leading to a sandbox escape, but the public release and access-restricted issue do not reveal whether the failing operation is a bounds check, object lifetime, or policy decision.",
        "basis": [
          "CNA",
          "CWE-20",
          "Chrome 150 stable release",
          "Chromium issue 513919827"
        ],
        "deepDive": true,
        "notes": "Inspected https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html and https://issues.chromium.org/issues/513919827. The release identifies ANGLE and the fixed Chrome build, while the linked issue exposes no public technical body to an unauthenticated reader; the failing operation remains undetermined."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513919827",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14412",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:31.255Z",
      "date_published": "2026-07-01T22:21:45.091Z",
      "date_updated": "2026-07-03T03:55:42.948Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14846
      },
      "nvd": {
        "published": "2026-07-01T23:16:49.663",
        "lastModified": "2026-07-03T04:17:48.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14412",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome accepts malformed ANGLE input that can cross the renderer sandbox, but the public record does not identify the parsed field or failed validation.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513920834",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14413",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:31.482Z",
      "date_published": "2026-07-01T22:21:59.017Z",
      "date_updated": "2026-07-03T03:55:37.520Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10322
      },
      "nvd": {
        "published": "2026-07-01T23:16:49.763",
        "lastModified": "2026-07-03T04:17:48.493",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14413",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The public record identifies a memory-safety failure but does not disclose the exact buffer, lifetime transition, or invalid access.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513922055",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14414",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:31.694Z",
      "date_published": "2026-07-01T22:21:46.219Z",
      "date_updated": "2026-07-02T00:35:41.684Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14501
      },
      "nvd": {
        "published": "2026-07-01T23:16:49.863",
        "lastModified": "2026-07-02T16:13:37.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14414",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's Skia path permits untrusted input to corrupt process memory, while the public release does not identify the malformed object, bound, or lifetime transition.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513948227",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 283,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14415",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:31.926Z",
      "date_published": "2026-07-01T22:21:42.193Z",
      "date_updated": "2026-07-02T16:56:51.702Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16757
      },
      "nvd": {
        "published": "2026-07-01T23:16:49.973",
        "lastModified": "2026-07-02T18:40:42.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14415",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is written beyond the boundary of a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/515086856",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14416",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:32.150Z",
      "date_published": "2026-07-01T22:21:53.436Z",
      "date_updated": "2026-07-03T03:55:29.159Z",
      "publisher": "Chrome",
      "title": "Out of bounds read in Dawn in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15537
      },
      "nvd": {
        "published": "2026-07-01T23:16:50.063",
        "lastModified": "2026-07-03T04:17:48.653",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14416",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome reads beyond a valid memory object because an input length or pointer is not validated against the available buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/515428315",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14417",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:32.392Z",
      "date_published": "2026-07-01T22:22:04.158Z",
      "date_updated": "2026-07-03T03:55:21.979Z",
      "publisher": "Chrome",
      "title": "Use after free in Dawn in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10872
      },
      "nvd": {
        "published": "2026-07-01T23:16:50.170",
        "lastModified": "2026-07-03T04:17:48.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14417",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dawn retains or dereferences an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516649133",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:32.635Z",
      "date_published": "2026-07-01T22:21:58.436Z",
      "date_updated": "2026-07-02T00:31:57.538Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08371
      },
      "nvd": {
        "published": "2026-07-01T23:16:50.273",
        "lastModified": "2026-07-02T16:12:25.883",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14418",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ANGLE uses uninitialized data while processing crafted graphics input, making stale memory observable across an origin boundary.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516865345",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14419",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:32.856Z",
      "date_published": "2026-07-01T22:22:04.747Z",
      "date_updated": "2026-07-03T03:55:23.391Z",
      "publisher": "Chrome",
      "title": "Use after free in Skia in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12001
      },
      "nvd": {
        "published": "2026-07-01T23:16:50.383",
        "lastModified": "2026-07-03T04:17:48.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14419",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Skia retains or accesses an object after its lifetime has ended, allowing crafted page activity to operate on freed memory.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516981393",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14420",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:33.095Z",
      "date_published": "2026-07-01T22:21:49.727Z",
      "date_updated": "2026-07-03T03:55:30.246Z",
      "publisher": "Chrome",
      "title": "Out of bounds read and write in Dawn in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16758
      },
      "nvd": {
        "published": "2026-07-01T23:16:50.487",
        "lastModified": "2026-07-03T04:17:49.127",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14420",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome parser can read beyond the end of its input or allocated buffer.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517031505",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14421",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:33.334Z",
      "date_published": "2026-07-01T22:21:59.566Z",
      "date_updated": "2026-07-02T00:31:27.782Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12022
      },
      "nvd": {
        "published": "2026-07-01T23:16:50.587",
        "lastModified": "2026-07-02T16:20:10.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14421",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dawn uses uninitialized memory that a crafted page can expose to the renderer.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517033235",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:33.552Z",
      "date_published": "2026-07-01T22:21:50.264Z",
      "date_updated": "2026-07-02T16:56:39.292Z",
      "publisher": "Chrome",
      "title": "Out of bounds read and write in Tint in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19319
      },
      "nvd": {
        "published": "2026-07-01T23:16:50.690",
        "lastModified": "2026-07-02T18:40:22.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14422",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tint uses attacker-controlled dimensions or offsets without preserving the valid image-buffer bound, permitting both out-of-bounds reads and writes.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517225032",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:33.802Z",
      "date_published": "2026-07-01T22:21:56.787Z",
      "date_updated": "2026-07-03T03:55:25.907Z",
      "publisher": "Chrome",
      "title": "Type Confusion in Tint in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12692
      },
      "nvd": {
        "published": "2026-07-01T23:16:50.787",
        "lastModified": "2026-07-03T04:17:49.760",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14423",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome treats attacker-influenced storage as an incompatible object type, allowing later field or method access to use the wrong memory layout.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517522769",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:34.040Z",
      "date_published": "2026-07-01T22:22:03.616Z",
      "date_updated": "2026-07-03T03:55:20.490Z",
      "publisher": "Chrome",
      "title": "Use after free in Dawn in Google Chrome on Mac prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12001
      },
      "nvd": {
        "published": "2026-07-01T23:16:50.897",
        "lastModified": "2026-07-03T04:17:50.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14424",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dawn retains and dereferences an object after its lifetime ends while processing crafted renderer input on macOS.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517692772",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:34.249Z",
      "date_published": "2026-07-01T22:22:03.047Z",
      "date_updated": "2026-07-03T03:55:18.925Z",
      "publisher": "Chrome",
      "title": "Use after free in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12391
      },
      "nvd": {
        "published": "2026-07-01T23:16:51.000",
        "lastModified": "2026-07-03T04:17:50.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14425",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome continues to access an object after its storage has been released, allowing invalid heap use and possible corruption.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517935753",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14426",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:34.460Z",
      "date_published": "2026-07-01T22:22:07.471Z",
      "date_updated": "2026-07-03T03:55:58.248Z",
      "publisher": "Chrome",
      "title": "Use after free in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12174
      },
      "nvd": {
        "published": "2026-07-01T23:16:51.100",
        "lastModified": "2026-07-03T04:17:50.543",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14426",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "V8 can access an object after it has been freed while handling a crafted page and specific user gestures.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517981277",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:34.705Z",
      "date_published": "2026-07-01T22:21:38.469Z",
      "date_updated": "2026-07-03T03:55:45.106Z",
      "publisher": "Chrome",
      "title": "Heap buffer overflow in Skia in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15852
      },
      "nvd": {
        "published": "2026-07-01T23:16:51.200",
        "lastModified": "2026-07-03T04:17:50.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14427",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Skia writes beyond a heap buffer while processing renderer-controlled page content.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520113415",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:34.935Z",
      "date_published": "2026-07-01T22:21:45.642Z",
      "date_updated": "2026-07-03T03:55:41.885Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16266
      },
      "nvd": {
        "published": "2026-07-01T23:16:51.297",
        "lastModified": "2026-07-03T04:17:50.907",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14428",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record says Dawn insufficiently validates untrusted input but does not identify the field, parser, check, or state transition that permits the sandbox escape.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520180257",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14429",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:35.174Z",
      "date_published": "2026-07-01T22:21:46.962Z",
      "date_updated": "2026-07-03T03:55:40.801Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13653
      },
      "nvd": {
        "published": "2026-07-01T23:16:51.400",
        "lastModified": "2026-07-03T04:17:51.043",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14429",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520571816",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:35.425Z",
      "date_published": "2026-07-01T22:21:49.181Z",
      "date_updated": "2026-07-03T03:55:49.325Z",
      "publisher": "Chrome",
      "title": "Integer overflow in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-472",
          "name": "External Control of Assumed-Immutable Web Parameter",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21318
      },
      "nvd": {
        "published": "2026-07-01T23:16:51.497",
        "lastModified": "2026-07-03T04:17:51.183",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14430",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-190",
          "CWE-472"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522126182",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14431",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:35.658Z",
      "date_published": "2026-07-01T22:21:57.301Z",
      "date_updated": "2026-07-03T03:55:52.469Z",
      "publisher": "Chrome",
      "title": "Type Confusion in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18185
      },
      "nvd": {
        "published": "2026-07-01T23:16:51.600",
        "lastModified": "2026-07-03T04:17:51.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14431",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected runtime uses an object through an incompatible type and therefore applies the wrong memory layout.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523884658",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14432",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:37:35.884Z",
      "date_published": "2026-07-01T22:22:06.356Z",
      "date_updated": "2026-07-03T03:55:55.928Z",
      "publisher": "Chrome",
      "title": "Use after free in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16085
      },
      "nvd": {
        "published": "2026-07-01T23:16:51.697",
        "lastModified": "2026-07-03T04:17:51.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14432",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/524290062",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14439",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T22:14:07.575Z",
      "date_published": "2026-07-01T23:05:30.529Z",
      "date_updated": "2026-07-20T22:36:45.281Z",
      "publisher": "Altium",
      "title": "Path Traversal in Altium Git Service Allows Remote Code Execution",
      "affected": {
        "vendors": [
          "Altium"
        ],
        "products": [
          {
            "vendor": "Altium",
            "product": "Altium Enterprise Server"
          },
          {
            "vendor": "Altium",
            "product": "Altium 365"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:4760f414-e1ae-4ff1-bdad-c7a9c3538b79",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00601,
        "percentile": 0.45402
      },
      "nvd": {
        "published": "2026-07-01T23:16:51.800",
        "lastModified": "2026-07-20T23:16:55.490",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14439",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled path or reference can select a file outside the intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.altium.com/platform/security-compliance/security-advisories",
          "host": "www.altium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 850,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14440",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T22:20:45.895Z",
      "date_published": "2026-07-01T22:35:10.353Z",
      "date_updated": "2026-07-02T19:22:18.404Z",
      "publisher": "cloudflare",
      "title": "Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA records",
      "affected": {
        "vendors": [
          "Cloudflare"
        ],
        "products": [
          {
            "vendor": "Cloudflare",
            "product": "Universal SSL"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:cna@cloudflare.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00195,
        "percentile": 0.0947
      },
      "nvd": {
        "published": "2026-07-01T23:16:52.007",
        "lastModified": "2026-07-02T20:17:01.137",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14440",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cloudflare serves its permissive auto-managed CAA RRset in place of stricter customer CAA parameters, so certificate authorities never receive the requested account or validation-method binding.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developers.cloudflare.com/ssl/edge-certificates/caa-records/",
          "host": "developers.cloudflare.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://developers.cloudflare.com/ssl/edge-certificates/universal-ssl/limitations/",
          "host": "developers.cloudflare.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc8657",
          "host": "www.rfc-editor.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc8659",
          "host": "www.rfc-editor.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://david-osipov.vision/en/blog/cybersecurity/cloudflare-ssl-mitm-flaw-2026/",
          "host": "david-osipov.vision",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://community.cloudflare.com/t/critical-security-gap-cloudflare-must-fully-support-rfc-8657-caa/799999/10",
          "host": "community.cloudflare.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://community.cloudflare.com/t/universal-ssl-exposes-domains-to-bgp-leaks-re-venezuela-analysis/879930",
          "host": "community.cloudflare.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://zenodo.org/records/18330221",
          "host": "zenodo.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2141,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14446",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T03:46:49.452Z",
      "date_published": "2026-07-28T20:52:17.237Z",
      "date_updated": "2026-07-30T03:55:19.397Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server is affected by a privilege escalation",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21436
      },
      "nvd": {
        "published": "2026-07-28T21:17:25.660",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14446",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WebSphere administrative console exposes a privileged function without the authentication required for that function.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281631",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T07:14:32.098Z",
      "date_published": "2026-07-20T11:40:50.055Z",
      "date_updated": "2026-07-20T13:52:32.818Z",
      "publisher": "CERTVDE",
      "title": "Authenticated RCE in system_certificates view",
      "affected": {
        "vendors": [
          "Helmholz",
          "MB connect line"
        ],
        "products": [
          {
            "vendor": "MB connect line",
            "product": "mbCONNECT24"
          },
          {
            "vendor": "MB connect line",
            "product": "mymbCONNECT24"
          },
          {
            "vendor": "Helmholz",
            "product": "myREX24V2"
          },
          {
            "vendor": "Helmholz",
            "product": "myREX24V2.virtual"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00765,
        "percentile": 0.51891
      },
      "nvd": {
        "published": "2026-07-20T12:17:54.707",
        "lastModified": "2026-07-22T20:54:47.023",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14448",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an operating-system command without neutralizing command syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-044/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-058/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-14449",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T07:19:55.068Z",
      "date_published": "2026-07-02T11:47:53.387Z",
      "date_updated": "2026-07-02T13:14:25.969Z",
      "publisher": "NCSC.ch",
      "title": "POST-based reflected XSS via the thanks parameter in form components",
      "affected": {
        "vendors": [
          "u5CMS"
        ],
        "products": [
          {
            "vendor": "u5CMS",
            "product": "u5CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18901
      },
      "nvd": {
        "published": "2026-07-02T12:16:55.580",
        "lastModified": "2026-07-02T17:42:23.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14449",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The thanks form parameter is reflected into an HTML response without the required context-specific escaping.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/u5cms/u5cms/releases/tag/v12.8.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14453",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T08:14:59.645Z",
      "date_published": "2026-07-13T08:19:13.094Z",
      "date_updated": "2026-07-13T13:54:29.853Z",
      "publisher": "Centreon",
      "title": "A user with low privileges can inject SSTI templates that can lead to RCE in open-tickets",
      "affected": {
        "vendors": [
          "Centreon"
        ],
        "products": [
          {
            "vendor": "Centreon",
            "product": "Infra Monitoring"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H"
        },
        {
          "source": "NVD:bd4443e6-1eef-43f3-9886-25fc9ceeaae7",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00505,
        "percentile": 0.40415
      },
      "nvd": {
        "published": "2026-07-13T09:16:23.893",
        "lastModified": "2026-07-13T19:58:29.933",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14453",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Infra Monitoring lets attacker-controlled text cross into an executable code or template grammar.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/centreon/centreon/releases",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 476,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T08:18:50.542Z",
      "date_published": "2026-07-08T12:30:20.230Z",
      "date_updated": "2026-07-09T14:41:45.096Z",
      "publisher": "CPANSec",
      "title": "Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed",
      "affected": {
        "vendors": [
          "TONYC"
        ],
        "products": [
          {
            "vendor": "TONYC",
            "product": "Imager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-196",
          "name": "Unsigned to Signed Conversion Error",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00374,
        "percentile": 0.30161
      },
      "nvd": {
        "published": "2026-07-08T13:16:30.053",
        "lastModified": "2026-07-10T15:31:22.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14454",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A signed interpretation of an unsigned EXIF entry count becomes a near-address-space allocation request without an upper memory bound.",
        "basis": [
          "CNA",
          "CWE-196",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/TONYC/Imager-1.033/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/tonycoz/imager/commit/06f01a5d0fd591259aeba589370d6888384a6b6d.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/08/6",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 381,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T08:47:08.143Z",
      "date_published": "2026-07-03T14:09:38.691Z",
      "date_updated": "2026-07-06T15:56:06.301Z",
      "publisher": "TR-CERT",
      "title": "Argument Injection in TUBITAK BILGEM's pardus-software",
      "affected": {
        "vendors": [
          "TUBITAK BILGEM Software Technologies Research Institute"
        ],
        "products": [
          {
            "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
            "product": "pardus-software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09785
      },
      "nvd": {
        "published": "2026-07-03T15:16:32.253",
        "lastModified": "2026-07-06T18:16:45.163",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14459",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In pardus-software, attacker-controlled text is split into command arguments without neutralizing argument delimiters.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0497",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14460",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T08:47:10.200Z",
      "date_published": "2026-07-03T14:14:11.752Z",
      "date_updated": "2026-07-06T15:55:22.415Z",
      "publisher": "TR-CERT",
      "title": "Missing Authorization in TUBITAK BILGEM's pardus-software",
      "affected": {
        "vendors": [
          "TUBITAK BILGEM Software Technologies Research Institute"
        ],
        "products": [
          {
            "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
            "product": "pardus-software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05984
      },
      "nvd": {
        "published": "2026-07-03T15:16:32.367",
        "lastModified": "2026-07-06T18:16:45.163",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14460",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The record links pardus-software argument injection to missing authorization but does not disclose the operation, permitted caller, or missing check.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0497",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14461",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T08:57:32.810Z",
      "date_published": "2026-07-10T10:38:28.947Z",
      "date_updated": "2026-07-10T13:14:54.068Z",
      "publisher": "CERT-PL",
      "title": "Out-of-bound read in mtr",
      "affected": {
        "vendors": [
          "BitWizard"
        ],
        "products": [
          {
            "vendor": "BitWizard",
            "product": "mtr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22713
      },
      "nvd": {
        "published": "2026-07-10T11:16:32.823",
        "lastModified": "2026-07-10T19:22:17.323",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14461",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ipinfo_lookup gives dn_expand the DNS response length as its end boundary, allowing a crafted compression pointer in an oversized TXT response to read outside valid data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-14461",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/traviscross/mtr/commit/48e1794414d338ce47abc0f27c25ade8788af9c3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14468",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T14:02:23.960Z",
      "date_published": "2026-07-06T20:59:47.011Z",
      "date_updated": "2026-07-07T13:52:51.836Z",
      "publisher": "HashiCorp",
      "title": "Path traversal allows arbitrary file read in Terraform Enterprise container",
      "affected": {
        "vendors": [
          "HashiCorp"
        ],
        "products": [
          {
            "vendor": "HashiCorp",
            "product": "Terraform Enterprise"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@hashicorp.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21813
      },
      "nvd": {
        "published": "2026-07-06T21:16:53.000",
        "lastModified": "2026-07-07T15:16:42.847",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14468",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Terraform Enterprise path accepts an attacker-controlled path that can escape the intended filesystem root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.hashicorp.com/t/hcsec-2026-17-terraform-enterprise-vulnerable-to-arbitrary-file-read/77549",
          "host": "discuss.hashicorp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 491,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14471",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T14:25:46.661Z",
      "date_published": "2026-07-06T20:33:25.217Z",
      "date_updated": "2026-07-07T13:45:02.810Z",
      "publisher": "AMZN",
      "title": "Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "MCP Gateway & Registry"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00325,
        "percentile": 0.25
      },
      "nvd": {
        "published": "2026-07-06T21:16:53.123",
        "lastModified": "2026-07-07T14:16:28.837",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14471",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The table_name value is interpolated as an SQL identifier without constraining it to a valid identifier grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/agentic-community/mcp-gateway-registry/releases/tag/v1.0.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-052-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/agentic-community/mcp-gateway-registry/security/advisories/GHSA-79qc-vqfr-xx5q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14474",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T14:49:31.316Z",
      "date_published": "2026-07-07T09:12:33.200Z",
      "date_updated": "2026-08-04T04:02:54.542Z",
      "publisher": "redhat",
      "title": "Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalation",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10.0 Extended Update Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9.6 Extended Update Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 15,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00547,
        "percentile": 0.42755
      },
      "nvd": {
        "published": "2026-07-07T10:16:39.870",
        "lastModified": "2026-08-04T05:16:37.400",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14474",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The default Red Hat Enterprise Linux 10 configuration grants broader access or searches a broader authority scope than a secure deployment requires.",
        "basis": [
          "CNA",
          "CWE-1188"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41937",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42122",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46482",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46990",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49839",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49840",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49841",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49842",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49843",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49844",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14474",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496556",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 333,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 15
      }
    },
    {
      "cve_id": "CVE-2026-14475",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T14:55:53.182Z",
      "date_published": "2026-07-10T07:48:41.859Z",
      "date_updated": "2026-07-10T11:11:58.683Z",
      "publisher": "Wordfence",
      "title": "Cookie Banner for GDPR / CCPA <= 4.3.6 - Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter",
      "affected": {
        "vendors": [
          "wplegalpages"
        ],
        "products": [
          {
            "vendor": "wplegalpages",
            "product": "Cookie Banner for GDPR / CCPA – WPLP Cookie Consent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21697
      },
      "nvd": {
        "published": "2026-07-10T09:16:53.127",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14475",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The plugin incorporates scan_id into an SQL query without sufficient escaping or preparation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/376741ee-9b6b-4822-8bad-548e212cd563?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/modules/cookie-scanner/class-wpl-cookie-consent-cookie-scanner.php#L994",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/modules/cookie-scanner/class-wpl-cookie-consent-cookie-scanner.php#L1036",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/modules/cookie-scanner/classes/class-wpl-cookie-consent-cookie-scanner-ajax.php#L847",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/modules/cookie-scanner/classes/class-wpl-cookie-consent-cookie-scanner-ajax.php#L823",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/modules/cookie-scanner/classes/class-wpl-cookie-consent-cookie-scanner-ajax.php#L102",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3601475%40gdpr-cookie-consent&new=3601475%40gdpr-cookie-consent",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 536,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:18:56.861Z",
      "date_published": "2026-07-07T09:12:52.180Z",
      "date_updated": "2026-08-04T04:44:29.022Z",
      "publisher": "redhat",
      "title": "Sssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows kerberos authentication bypass",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10.0 Extended Update Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.8 Telecommunications Update Service"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9.6 Extended Update Support"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 15,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00644,
        "percentile": 0.47379
      },
      "nvd": {
        "published": "2026-07-07T10:16:39.993",
        "lastModified": "2026-08-04T06:16:29.573",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14476",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SSSD ad_gpo_extract_smb_components accepts parent-directory segments in the gPCFileSysPath LDAP attribute, allowing a GPO administrator to make the root process write outside its GPO cache and alter Kerberos configuration.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:41937",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42122",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46482",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46990",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49839",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49840",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49841",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49842",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49843",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:49844",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14476",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496581",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 418,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 15
      }
    },
    {
      "cve_id": "CVE-2026-14480",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:00:30.030Z",
      "date_published": "2026-07-10T22:17:49.406Z",
      "date_updated": "2026-07-13T15:41:57.195Z",
      "publisher": "icscert",
      "title": "OpenPLC v3 External Control of File Name or Path",
      "affected": {
        "vendors": [
          "OpenPLC"
        ],
        "products": [
          {
            "vendor": "OpenPLC",
            "product": "OpenPLC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 1.200000000000001,
      "epss": {
        "score": 0.0044,
        "percentile": 0.36205
      },
      "nvd": {
        "published": "2026-07-10T23:16:47.110",
        "lastModified": "2026-07-13T20:20:52.383",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14480",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenPLC stores prog_file as an upload destination without rejecting absolute paths that escape the intended directory.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-190-01.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 925,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:19:12.635Z",
      "date_published": "2026-07-23T08:34:41.164Z",
      "date_updated": "2026-07-23T13:48:25.187Z",
      "publisher": "Wordfence",
      "title": "Equalize Digital Accessibility Checker <= 1.46.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'html' Parameter",
      "affected": {
        "vendors": [
          "equalizedigital"
        ],
        "products": [
          {
            "vendor": "equalizedigital",
            "product": "Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.22996
      },
      "nvd": {
        "published": "2026-07-23T10:16:49.787",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14481",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c22f34f1-2df7-4ffc-b808-234ca9039404?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accessibility-checker/tags/1.44.1/admin/class-ajax.php#L529",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accessibility-checker/tags/1.45.0/admin/class-ajax.php#L529",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accessibility-checker/tags/1.45.0/includes/helper-functions.php#L759",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accessibility-checker/tags/1.45.0/includes/classes/class-rest-api.php#L520",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accessibility-checker/tags/1.45.0/admin/class-insert-rule-data.php#L68",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accessibility-checker/tags/1.44.1/includes/helper-functions.php#L759",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accessibility-checker/tags/1.44.1/includes/classes/class-rest-api.php#L520",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/accessibility-checker/tags/1.44.1/admin/class-insert-rule-data.php#L68",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3608913%40accessibility-checker&new=3608913%40accessibility-checker",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 674,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:25:33.538Z",
      "date_published": "2026-07-08T04:30:50.223Z",
      "date_updated": "2026-07-08T13:57:46.333Z",
      "publisher": "Wordfence",
      "title": "多说社会化评论框 <= 1.2 - Unauthenticated Privilege Escalation via api.php 'option'/'value' Parameters",
      "affected": {
        "vendors": [
          "shen2"
        ],
        "products": [
          {
            "vendor": "shen2",
            "product": "多说社会化评论框"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00318,
        "percentile": 0.2422
      },
      "nvd": {
        "published": "2026-07-08T05:16:26.840",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14482",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A WordPress endpoint accepts an empty HMAC and omits the capability checks required before changing arbitrary site options.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/732c7ccd-de50-4e27-8cb9-3bb0ed30f0b4?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/duoshuo/tags/1.2/LocalServer.php#L49",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/duoshuo/tags/1.2/LocalServer.php#L54",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/duoshuo/tags/1.2/api.php#L40",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 774,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14483",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:27:40.289Z",
      "date_published": "2026-07-31T05:35:22.781Z",
      "date_updated": "2026-07-31T19:26:05.373Z",
      "publisher": "Wordfence",
      "title": "Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command",
      "affected": {
        "vendors": [
          "realtyna"
        ],
        "products": [
          {
            "vendor": "realtyna",
            "product": "Realtyna Organic IDX plugin + WPL Real Estate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00611,
        "percentile": 0.45813
      },
      "nvd": {
        "published": "2026-07-31T07:16:24.803",
        "lastModified": "2026-07-31T20:16:46.443",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14483",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The public upload handler accepts executable file types, and installation-wide static API credentials make that unrestricted destination reachable without a WordPress capability check.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/23068a98-623d-4eb3-a7c5-6af410de4320?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/trunk/libraries/file.php#L217",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/trunk/libraries/io/mobile_application/set_property.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/trunk/libraries/services/io.php#L20",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/trunk/libraries/io/global.php#L142",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/trunk/assets/migrations/basic/1.0.0.sql#L1119",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 899,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14487",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T17:04:50.309Z",
      "date_published": "2026-07-08T04:30:50.925Z",
      "date_updated": "2026-07-08T13:12:21.710Z",
      "publisher": "Wordfence",
      "title": "Simple Coherent Form <= 2.4.13 - Unauthenticated Arbitrary File Deletion via 'id' Parameter",
      "affected": {
        "vendors": [
          "tombgtn"
        ],
        "products": [
          {
            "vendor": "tombgtn",
            "product": "Simple Coherent Form"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00742,
        "percentile": 0.51143
      },
      "nvd": {
        "published": "2026-07-08T05:16:26.980",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14487",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "removeUploadDir accepts an unauthenticated id-derived path without confining deletion to the plugin upload directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f4831e75-dc0e-4d6f-b2cb-8498d8629319?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simple-coherent-form/tags/2.4.13/includes/fields/file.php#L1387",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simple-coherent-form/tags/2.4.13/includes/fields/file.php#L1521",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simple-coherent-form/tags/2.4.13/includes/fields/file.php#L1544",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simple-coherent-form/tags/2.4.13/includes/fields/file.php#L1494",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simple-coherent-form/tags/2.4.13/includes/fields/file.php#L43",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 719,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T17:05:26.315Z",
      "date_published": "2026-07-29T09:31:15.974Z",
      "date_updated": "2026-07-29T14:31:01.547Z",
      "publisher": "Wordfence",
      "title": "Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'rwmb_frontend_field_object_id' Parameter",
      "affected": {
        "vendors": [
          "Meta Box"
        ],
        "products": [
          {
            "vendor": "Meta Box",
            "product": "Meta Box AIO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23048
      },
      "nvd": {
        "published": "2026-07-29T11:16:48.063",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14488",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The frontend dispatcher accepts a caller-supplied post ID and reaches deletion without a capability or ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e9506f84-3d33-48e0-8dce-d517e1a923e4?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metabox.io/plugins/meta-box-aio/changelog/",
          "host": "metabox.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 736,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T17:07:06.520Z",
      "date_published": "2026-07-08T05:34:09.943Z",
      "date_updated": "2026-07-08T12:52:21.650Z",
      "publisher": "Wordfence",
      "title": "WHMCS Bridge <= 6.9 - Unauthenticated Arbitrary File Upload via 'ccce' Parameter",
      "affected": {
        "vendors": [
          "globalprogramming"
        ],
        "products": [
          {
            "vendor": "globalprogramming",
            "product": "WHMCS Bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00545,
        "percentile": 0.42642
      },
      "nvd": {
        "published": "2026-07-08T06:16:22.307",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14489",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WHMCS Bridge connect function accepts an uploaded file without validating its type before placing it on the server.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c4fe6dcc-93c8-4956-85ae-a1125bc84509?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/whmcs-bridge/tags/6.9/includes/request.class.php#L309",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/whmcs-bridge/tags/6.9/includes/request.class.php#L296",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/whmcs-bridge/tags/6.9/bridge.init.php#L809",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/whmcs-bridge/tags/6.9/bridge.init.php#L852",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/whmcs-bridge/tags/6.9/bridge.init.php#L482",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 373,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T17:14:10.259Z",
      "date_published": "2026-07-28T05:39:42.809Z",
      "date_updated": "2026-07-28T13:31:20.768Z",
      "publisher": "Wordfence",
      "title": "Demi <= 0.0.6 - Unauthenticated Arbitrary Directory Deletion via demi_restore_step AJAX action",
      "affected": {
        "vendors": [
          "deveasel"
        ],
        "products": [
          {
            "vendor": "deveasel",
            "product": "Demi – One Click Demo Import, Backup & Site Migration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00509,
        "percentile": 0.40629
      },
      "nvd": {
        "published": "2026-07-28T07:16:40.963",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14490",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CleanDir accepts a caller-supplied absolute directory without allowlisting or canonical containment and recursively deletes that selected path.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/63922c28-0cb5-4abe-85ee-20b2cc6f015d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/classes/Backup/Tasks/CleanDir.php#L61",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/classes/Import/Manager.php#L767",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/classes/Import/Manager.php#L50",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/classes/Import/Manager.php#L287",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/classes/Backup/Tasks/CleanDir.php#L61",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/classes/Import/Manager.php#L767",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/classes/Import/Manager.php#L50",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/classes/Import/Manager.php#L287",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3616690%40demi-backup-migration&new=3616690%40demi-backup-migration",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 963,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14495",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T17:42:28.811Z",
      "date_published": "2026-07-08T05:34:07.285Z",
      "date_updated": "2026-07-08T12:44:30.272Z",
      "publisher": "Wordfence",
      "title": "DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insufficient Randomness via 'dologin' Parameter Weak PRNG Token",
      "affected": {
        "vendors": [
          "wpdo5ea"
        ],
        "products": [
          {
            "vendor": "wpdo5ea",
            "product": "DoLogin Security"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00434,
        "percentile": 0.35717
      },
      "nvd": {
        "published": "2026-07-08T06:16:22.443",
        "lastModified": "2026-07-08T14:55:07.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14495",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Passwordless-login tokens are generated from a roughly 20-bit Mersenne Twister seed, making an active token reconstructable by brute force.",
        "basis": [
          "CNA",
          "CWE-338"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/16bce371-b524-48eb-8537-3f9df802abd3?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dologin/tags/4.3/src/pswdless.cls.php#L86",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dologin/tags/4.3/src/s.cls.php#L240",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dologin/tags/4.3/src/pswdless.cls.php#L197",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dologin/tags/4.3/src/pswdless.cls.php#L27",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1486,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T17:55:22.464Z",
      "date_published": "2026-07-17T19:57:05.308Z",
      "date_updated": "2026-07-23T03:56:12.051Z",
      "publisher": "ibm",
      "title": "Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Langflow OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00448,
        "percentile": 0.36818
      },
      "nvd": {
        "published": "2026-07-17T20:17:14.950",
        "lastModified": "2026-07-23T05:16:29.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14499",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Python Interpreter component passes authenticated user input into command execution without neutralizing shell syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279996",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14500",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T17:59:31.850Z",
      "date_published": "2026-07-08T05:34:10.332Z",
      "date_updated": "2026-07-08T15:04:06.454Z",
      "publisher": "Wordfence",
      "title": "Bulk Order Update for WooCommerce <= 1.6 - Unauthenticated Arbitrary File Read via 'csv_url' Parameter",
      "affected": {
        "vendors": [
          "sayantandas20"
        ],
        "products": [
          {
            "vendor": "sayantandas20",
            "product": "Bulk Order Update for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25812
      },
      "nvd": {
        "published": "2026-07-08T06:16:22.583",
        "lastModified": "2026-07-08T16:16:27.123",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14500",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The AJAX handler passes an attacker-supplied absolute path to fopen after checks that reject traversal text but do not confine the selected file.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d3aa1f74-6372-4abe-894b-07ad3e81ea81?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bulk-order-update-for-woocommerce/tags/1.6/inc/plugin-html.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bulk-order-update-for-woocommerce/tags/1.6/inc/plugin-html.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bulk-order-update-for-woocommerce/tags/1.6/inc/plugin-html.php#L48",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 746,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T18:00:48.051Z",
      "date_published": "2026-07-17T19:55:50.177Z",
      "date_updated": "2026-07-20T18:02:26.778Z",
      "publisher": "ibm",
      "title": "Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Db2 Genius Hub"
          },
          {
            "vendor": "IBM",
            "product": "Agentics"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-676",
          "name": "Use of Potentially Dangerous Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15447
      },
      "nvd": {
        "published": "2026-07-17T20:17:15.073",
        "lastModified": "2026-07-20T19:17:18.263",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14501",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Db2 Genius Hub lets attacker-controlled schema, metadata, code text, or file content cross into a code-generation or execution interpreter without the quoting, allowlisting, or neutralization needed to keep it as data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-676"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279901",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14503",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T18:06:48.735Z",
      "date_published": "2026-07-17T03:43:41.024Z",
      "date_updated": "2026-07-17T10:24:31.926Z",
      "publisher": "Wordfence",
      "title": "pCloud WP Backup <= 2.0.3 -  Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read",
      "affected": {
        "vendors": [
          "ploudapp"
        ],
        "products": [
          {
            "vendor": "ploudapp",
            "product": "pCloud WP Backup"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.2095
      },
      "nvd": {
        "published": "2026-07-17T05:16:37.960",
        "lastModified": "2026-07-17T14:59:38.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14503",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The backup AJAX path lets a subscriber trigger a full-site archive without the required capability check, after which the predictable public path exposes it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0b301c6e-a3c5-4435-9bc9-fab18085fe2d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-wp-backup.php#L572",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-wp-backup.php#L210",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-wp-backup.php#L1635",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/Pcloud/Classes/class-wp2pcloudfilebackup.php#L111",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-wp-backup.php#L217",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3597399%40pcloud-wp-backup&new=3597399%40pcloud-wp-backup",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 668,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14504",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T18:20:34.196Z",
      "date_published": "2026-07-14T15:55:04.951Z",
      "date_updated": "2026-07-15T14:10:02.530Z",
      "publisher": "Sonatype",
      "title": "Nexus Repository 3 - Authorization Bypass in Component Upload API",
      "affected": {
        "vendors": [
          "Sonatype"
        ],
        "products": [
          {
            "vendor": "Sonatype",
            "product": "Nexus Repository 3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:103e4ec9-0a87-450b-af77-479448ddef11",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.1816
      },
      "nvd": {
        "published": "2026-07-14T16:16:45.423",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14504",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The component-upload API lets a user with only read or browse permission upload artifacts because it omits the repository write-permission check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://help.sonatype.com/en/sonatype-nexus-repository-3-94-0-release-notes.html",
          "host": "help.sonatype.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://support.sonatype.com/hc/en-us/articles/53137654741907",
          "host": "support.sonatype.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14512",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:17:20.304Z",
      "date_published": "2026-07-28T20:50:08.632Z",
      "date_updated": "2026-07-30T03:55:21.695Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00536,
        "percentile": 0.42204
      },
      "nvd": {
        "published": "2026-07-28T21:17:25.783",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14512",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebSphere deserializes pre-authentication attacker-controlled data into executable object behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281649",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14515",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:23:18.880Z",
      "date_published": "2026-07-28T20:50:33.785Z",
      "date_updated": "2026-07-29T12:39:03.143Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07489
      },
      "nvd": {
        "published": "2026-07-28T21:17:25.923",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14515",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebSphere returns attacker-controlled input as executable page markup without the required output separation.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281641",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 129,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:25:32.255Z",
      "date_published": "2026-07-28T08:34:35.444Z",
      "date_updated": "2026-07-28T14:53:47.676Z",
      "publisher": "Wordfence",
      "title": "Online Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQL Injection",
      "affected": {
        "vendors": [
          "ladela"
        ],
        "products": [
          {
            "vendor": "ladela",
            "product": "Online Scheduling and Appointment Booking System – Bookly"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0029,
        "percentile": 0.2122
      },
      "nvd": {
        "published": "2026-07-28T09:16:41.970",
        "lastModified": "2026-07-28T16:17:29.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14516",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Bookly incorporates the staff_ids parameter into an SQL query without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5c55abc7-b09d-4fea-bc2f-b903d3da119f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/27.5/lib/slots/Finder.php#L494",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/27.5/lib/ChainItem.php#L65",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/27.5/lib/ChainItem.php#L172",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bookly-responsive-appointment-booking-tool/tags/27.5/frontend/modules/booking/Ajax.php#L15",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 870,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14519",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:36:02.265Z",
      "date_published": "2026-07-30T14:05:31.735Z",
      "date_updated": "2026-07-30T17:26:57.088Z",
      "publisher": "ibm",
      "title": "IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settings",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "App Connect Enterprise"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00623,
        "percentile": 0.46442
      },
      "nvd": {
        "published": "2026-07-30T15:16:25.547",
        "lastModified": "2026-07-30T19:17:07.647",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14519",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281897",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14522",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:52:00.961Z",
      "date_published": "2026-07-30T14:06:56.265Z",
      "date_updated": "2026-07-31T03:56:01.243Z",
      "publisher": "ibm",
      "title": "IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settings",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "App Connect Enterprise"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.005,
        "percentile": 0.4008
      },
      "nvd": {
        "published": "2026-07-30T15:16:25.693",
        "lastModified": "2026-07-31T04:16:46.543",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14522",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281897",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14528",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T20:20:14.675Z",
      "date_published": "2026-07-28T20:37:32.976Z",
      "date_updated": "2026-07-30T03:55:23.956Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.1738
      },
      "nvd": {
        "published": "2026-07-28T21:17:26.060",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14528",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says WebSphere returns sensitive information but does not identify the value, response path, or missing redaction.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281649",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14529",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T20:25:40.691Z",
      "date_published": "2026-07-29T18:15:18.180Z",
      "date_updated": "2026-07-30T03:55:39.717Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          },
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25889
      },
      "nvd": {
        "published": "2026-07-29T19:16:44.720",
        "lastModified": "2026-08-04T14:14:17.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14529",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "When the SIP container is enabled, WebSphere accepts an attacker-controlled outbound request target without an effective server-side destination restriction.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281721",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 242,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14534",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T00:02:49.289Z",
      "date_published": "2026-07-04T13:25:55.283Z",
      "date_updated": "2026-07-06T14:59:37.264Z",
      "publisher": "BombadilSystems",
      "title": "Fickling check_safety() bypass via unlisted standard library modules (_posixsubprocess, site, atexit)",
      "affected": {
        "vendors": [
          "trailofbits"
        ],
        "products": [
          {
            "vendor": "trailofbits",
            "product": "fickling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:aa17e1a1-c329-4d6e-a1ed-8d0188aea082",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29347
      },
      "nvd": {
        "published": "2026-07-04T14:16:28.400",
        "lastModified": "2026-07-10T15:10:15.827",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14534",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pickle safety gate relies on an incomplete module denylist, so executable standard-library call targets are classified as safe and then deserialized.",
        "basis": [
          "CNA",
          "CWE-184",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/trailofbits/fickling/security/advisories/GHSA-m6fh-58r7-x697",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/trailofbits/fickling/pull/272",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch"
          ]
        },
        {
          "url": "https://github.com/trailofbits/fickling/commit/e8408615b63adf034f891f653692ab9b51f0f5af",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/trailofbits/fickling/releases/tag/v0.1.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1137,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T00:02:55.918Z",
      "date_published": "2026-07-04T13:31:14.937Z",
      "date_updated": "2026-07-06T14:58:34.718Z",
      "publisher": "BombadilSystems",
      "title": "Fickling MLAllowlist analysis pass rendered inoperative by shared mutable state in AnalysisContext.shorten_code()",
      "affected": {
        "vendors": [
          "trailofbits"
        ],
        "products": [
          {
            "vendor": "trailofbits",
            "product": "fickling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:aa17e1a1-c329-4d6e-a1ed-8d0188aea082",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25779
      },
      "nvd": {
        "published": "2026-07-04T14:16:29.063",
        "lastModified": "2026-07-10T15:00:43.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14535",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "UnsafeImportsML marks each shortened import as already reported in shared state, causing the later MLAllowlist pass to skip every allowlist decision.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/trailofbits/fickling/security/advisories/GHSA-cffv-grgg-g429",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/trailofbits/fickling/pull/278",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch"
          ]
        },
        {
          "url": "https://github.com/trailofbits/fickling/commit/41ce7cb01edd97072994039574a2301ebb3f463d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/trailofbits/fickling/releases/tag/v0.1.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1527,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T00:08:05.267Z",
      "date_published": "2026-07-06T19:23:21.459Z",
      "date_updated": "2026-07-09T15:01:21.700Z",
      "publisher": "DEVOLUTIONS",
      "title": "Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.5000000000000009,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14067
      },
      "nvd": {
        "published": "2026-07-06T20:16:29.883",
        "lastModified": "2026-07-09T16:16:36.927",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14536",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An invalid default MFA value causes the server to accept password credentials without enforcing the mandatory second factor.",
        "basis": [
          "CNA",
          "CWE-693",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0023/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T01:40:43.351Z",
      "date_published": "2026-07-31T01:38:18.978Z",
      "date_updated": "2026-07-31T16:08:17.628Z",
      "publisher": "Google",
      "title": "Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "mcp-toolbox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:cve-coordination@google.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10947
      },
      "nvd": {
        "published": "2026-07-31T02:16:27.687",
        "lastModified": "2026-07-31T16:16:57.950",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14537",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A legacy HTTP endpoint omits the scopeRequired authorization control used by the protected path.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/googleapis/mcp-toolbox/pull/3435",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T02:06:17.583Z",
      "date_published": "2026-07-31T01:42:29.707Z",
      "date_updated": "2026-07-31T16:09:31.250Z",
      "publisher": "Google",
      "title": "BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "mcp-toolbox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:cve-coordination@google.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10273
      },
      "nvd": {
        "published": "2026-07-31T02:16:28.757",
        "lastModified": "2026-07-31T16:16:58.073",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14538",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A fail-open dry-run result bypasses allowedDatasets validation before specialized BigQuery constructs access excluded datasets.",
        "basis": [
          "CNA record",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/googleapis/mcp-toolbox/pull/3452",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 632,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14539",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T02:17:44.796Z",
      "date_published": "2026-07-31T01:45:35.468Z",
      "date_updated": "2026-07-31T16:11:48.201Z",
      "publisher": "Google",
      "title": "Denial of Service via Unrestricted Payload Buffering in MCP Toolbox",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "mcp-toolbox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:cve-coordination@google.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11989
      },
      "nvd": {
        "published": "2026-07-31T02:16:28.920",
        "lastModified": "2026-07-31T16:16:58.180",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14539",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mcp-toolbox allocates or queues attacker-driven work without a per-request or per-connection limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/googleapis/mcp-toolbox/pull/3216",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 624,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14540",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T03:28:09.464Z",
      "date_published": "2026-07-31T01:46:54.942Z",
      "date_updated": "2026-07-31T16:12:49.663Z",
      "publisher": "Google",
      "title": "Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "mcp-toolbox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:cve-coordination@google.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10129
      },
      "nvd": {
        "published": "2026-07-31T02:16:29.060",
        "lastModified": "2026-07-31T16:16:58.303",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14540",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MCP HTTP client follows redirects without revalidating the destination address, allowing a public URL to redirect into an internal service.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/googleapis/mcp-toolbox/pull/3448",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 788,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14541",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T03:38:02.749Z",
      "date_published": "2026-07-31T01:48:39.019Z",
      "date_updated": "2026-07-31T16:14:54.005Z",
      "publisher": "Google",
      "title": "Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "mcp-toolbox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:cve-coordination@google.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18987
      },
      "nvd": {
        "published": "2026-07-31T03:16:24.170",
        "lastModified": "2026-07-31T17:16:32.513",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14541",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ValidateMCPAuth accepts Google access tokens without checking their audience when mcpEnabled is true and neither audience nor clientId is configured.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/googleapis/mcp-toolbox/pull/3450",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 547,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14544",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T07:06:13.196Z",
      "date_published": "2026-07-03T07:26:00.402Z",
      "date_updated": "2026-07-16T11:47:51.901Z",
      "publisher": "redhat",
      "title": "Hplip: incomplete fix for cve-2026-8631",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00864,
        "percentile": 0.55113
      },
      "nvd": {
        "published": "2026-07-03T08:16:24.433",
        "lastModified": "2026-07-16T12:17:02.597",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14544",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An arithmetic operation can wrap before the result is used for a memory size or offset, invalidating the later bounds assumption.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39976",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40831",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40894",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14544",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496772",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14545",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T08:09:23.811Z",
      "date_published": "2026-07-28T06:00:01.300Z",
      "date_updated": "2026-07-28T13:29:00.586Z",
      "publisher": "WPScan",
      "title": "TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "TrueBooker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.1991
      },
      "nvd": {
        "published": "2026-07-28T07:16:41.100",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14545",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A front-end password-reset handler changes the password for an attacker-selected account without validating ownership of that account.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/c97d9841-2bd7-438b-a719-7943d671c754/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14551",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T08:49:30.333Z",
      "date_published": "2026-07-22T09:42:34.205Z",
      "date_updated": "2026-07-22T12:41:00.539Z",
      "publisher": "NCSC.ch",
      "title": "Local Privilege Escalation in servereye client (sensorhub)",
      "affected": {
        "vendors": [
          "servereye GmbH"
        ],
        "products": [
          {
            "vendor": "servereye GmbH",
            "product": "servereye Windows Agent (Sensorhub)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-379",
          "name": "Creation of Temporary File in Directory with Insecure Permissions",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03178
      },
      "nvd": {
        "published": "2026-07-22T10:17:13.810",
        "lastModified": "2026-07-22T16:25:46.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14551",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The servereye Windows Agent (Sensorhub) privileged file operation accepts an attacker-controlled source or destination path.",
        "basis": [
          "CNA",
          "CWE-73",
          "CWE-269",
          "CWE-379"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.servereye.de/security-bulletins/2026-001/",
          "host": "www.servereye.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 928,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14554",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T09:12:56.237Z",
      "date_published": "2026-07-31T06:00:06.278Z",
      "date_updated": "2026-07-31T19:34:55.210Z",
      "publisher": "WPScan",
      "title": "Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s Parameters",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Check & Log Email"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13984
      },
      "nvd": {
        "published": "2026-07-31T07:16:24.987",
        "lastModified": "2026-07-31T20:16:46.553",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14554",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The d and s request values are incorporated into SQL syntax without parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/7b39bae3-41a2-4862-b7c3-1a386273d600/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14568",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T10:19:03.970Z",
      "date_published": "2026-07-27T06:00:05.425Z",
      "date_updated": "2026-07-27T17:35:40.456Z",
      "publisher": "WPScan",
      "title": "WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10393
      },
      "nvd": {
        "published": "2026-07-27T07:16:25.987",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14568",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration access path accepts an identity or request signal that is insufficient to authenticate the actor for the requested operation.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/dcbc2a0c-6fa6-4266-9292-0a1f3418da08/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14570",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T10:37:19.787Z",
      "date_published": "2026-07-05T01:30:12.849Z",
      "date_updated": "2026-07-06T13:42:11.715Z",
      "publisher": "CPANSec",
      "title": "Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery",
      "affected": {
        "vendors": [
          "TIMLEGGE"
        ],
        "products": [
          {
            "vendor": "TIMLEGGE",
            "product": "Crypt::DSA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-330",
          "name": "Use of Insufficiently Random Values",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23885
      },
      "nvd": {
        "published": "2026-07-05T02:17:40.190",
        "lastModified": "2026-07-06T18:16:45.163",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14570",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Crypt::DSA forces the high bit of generated signing nonces and private keys, introducing a bias that permits lattice-based private-key recovery.",
        "basis": [
          "CNA",
          "CWE-330"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/TIMLEGGE/Crypt-DSA-1.21/source/lib/Crypt/DSA/Util.pm#L56",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/TIMLEGGE/Crypt-DSA-1.22/diff/TIMLEGGE/Crypt-DSA-1.21#lib/Crypt/DSA/Util.pm",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/TIMLEGGE/Crypt-DSA-1.22/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 727,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14586",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T11:59:36.383Z",
      "date_published": "2026-07-22T13:03:53.107Z",
      "date_updated": "2026-07-22T14:33:23.363Z",
      "publisher": "NLnet Labs",
      "title": "Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.1878
      },
      "nvd": {
        "published": "2026-07-22T14:17:15.020",
        "lastModified": "2026-07-22T20:33:11.590",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14586",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-14586.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 706,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14592",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T12:17:40.452Z",
      "date_published": "2026-07-30T06:00:06.448Z",
      "date_updated": "2026-07-30T12:52:05.469Z",
      "publisher": "WPScan",
      "title": "WP Real IP-based Access Control <= 1.3.1 - Unauthenticated Stored XSS via acl_ctrl_addr",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Real IP-based Access Control"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11231
      },
      "nvd": {
        "published": "2026-07-30T06:25:00.807",
        "lastModified": "2026-07-30T14:19:00.067",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14592",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A low-privileged WordPress caller can store content for later HTML rendering because the write path lacks the required capability check.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/5f2fb7cd-5330-4721-ab1b-d8c247786c8f/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14602",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T12:56:33.886Z",
      "date_published": "2026-07-30T06:00:06.663Z",
      "date_updated": "2026-07-30T18:59:21.221Z",
      "publisher": "WPScan",
      "title": "Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Remote API"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00524,
        "percentile": 0.41544
      },
      "nvd": {
        "published": "2026-07-30T06:25:00.937",
        "lastModified": "2026-07-30T20:16:52.987",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14602",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected component deserializes attacker-controlled object data without restricting executable types or behavior.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/eb5a7d86-4762-48ad-83bf-81f048527147/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14603",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T12:59:52.015Z",
      "date_published": "2026-07-24T06:00:03.379Z",
      "date_updated": "2026-07-24T19:39:48.699Z",
      "publisher": "WPScan",
      "title": "WowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row Injection",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WowOptin: Next-Gen Popup Maker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15141
      },
      "nvd": {
        "published": "2026-07-24T07:16:33.120",
        "lastModified": "2026-07-24T20:48:39.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14603",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "WowOptin's REST endpoint lets an unauthenticated caller disable all opt-in forms or insert new template rows without the required authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/3a06d27a-9405-4cf2-9087-554018d31884/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14604",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T13:44:08.821Z",
      "date_published": "2026-07-03T18:30:08.783Z",
      "date_updated": "2026-07-06T16:31:22.971Z",
      "publisher": "VulDB",
      "title": "Open Asset Import Library Assimp PLY Model PlyLoader.cpp ExportToBlob double free",
      "affected": {
        "vendors": [
          "Open Asset Import Library"
        ],
        "products": [
          {
            "vendor": "Open Asset Import Library",
            "product": "Assimp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14315
      },
      "nvd": {
        "published": "2026-07-03T19:16:36.010",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14604",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The same allocation can be released twice along the affected object-lifetime path.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376112",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376112/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14604",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844567",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/assimp/assimp/issues/6620",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/user-attachments/files/27232640/poc.zip",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-14605",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T13:51:34.526Z",
      "date_published": "2026-07-03T19:15:07.914Z",
      "date_updated": "2026-07-06T15:25:54.648Z",
      "publisher": "VulDB",
      "title": "RT-Thread ls1c CAN ls1c_can.h recvmsg stack-based overflow",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "RT-Thread"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.8,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.8,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 1.7000000000000002,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03865
      },
      "nvd": {
        "published": "2026-07-03T20:16:52.070",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14605",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RT-Thread writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376113",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376113/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14605",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844580",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/RT-Thread/rt-thread/issues/11424",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/RT-Thread/rt-thread/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14606",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T13:51:36.756Z",
      "date_published": "2026-07-03T19:30:08.022Z",
      "date_updated": "2026-07-06T19:43:36.168Z",
      "publisher": "VulDB",
      "title": "RT-Thread SWM341 CAN SWM341.h CAN_Receive stack-based overflow",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "RT-Thread"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.8,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.8,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 1.7000000000000002,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03865
      },
      "nvd": {
        "published": "2026-07-03T20:16:52.237",
        "lastModified": "2026-07-06T21:16:53.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14606",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CAN_Receive writes past a stack buffer while processing attacker-influenced local input.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376114",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376114/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14606",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844591",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/RT-Thread/rt-thread/issues/11425",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/RT-Thread/rt-thread/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14607",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T13:51:39.652Z",
      "date_published": "2026-07-03T19:45:17.840Z",
      "date_updated": "2026-07-06T16:29:02.293Z",
      "publisher": "VulDB",
      "title": "RT-Thread lwp_syscall.c sys_getaddrinfo memory corruption",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "RT-Thread"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.6,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.6,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02102
      },
      "nvd": {
        "published": "2026-07-03T20:16:52.400",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14607",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "RT-Thread's sys_getaddrinfo processes a caller-controlled ai_addr value in a way that corrupts memory, but the exact bounds or lifetime error is not public.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376115",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376115/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14607",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844622",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/RT-Thread/rt-thread/issues/11428",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/RT-Thread/rt-thread/pull/11454",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/RT-Thread/rt-thread/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14608",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T13:56:09.494Z",
      "date_published": "2026-07-03T20:00:09.634Z",
      "date_updated": "2026-07-07T02:17:32.981Z",
      "publisher": "VulDB",
      "title": "SourceCodester CET Automated Grading System with AI Predictive Analytics POST index.php view_student authorization",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "CET Automated Grading System with AI Predictive Analytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00223,
        "percentile": 0.12943
      },
      "nvd": {
        "published": "2026-07-03T20:16:52.563",
        "lastModified": "2026-07-07T04:17:21.267",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14608",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The view_student handler uses a caller-controlled student ID without binding the selected record to the authenticated user's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376116",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376116/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14608",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844625",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 408,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14609",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T13:58:44.213Z",
      "date_published": "2026-07-03T20:15:09.103Z",
      "date_updated": "2026-07-06T16:52:16.672Z",
      "publisher": "VulDB",
      "title": "SourceCodester CET Automated Grading System with AI Predictive Analytics session fixiation",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "CET Automated Grading System with AI Predictive Analytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-384",
          "name": "Session Fixation",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24576
      },
      "nvd": {
        "published": "2026-07-03T21:16:55.903",
        "lastModified": "2026-07-06T18:16:36.920",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14609",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The CET Automated Grading System with AI Predictive Analytics authentication flow preserves an attacker-chosen session identifier across login instead of rotating it.",
        "basis": [
          "CNA",
          "CWE-384"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376117",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376117/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14609",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844641",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 373,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14610",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T14:03:32.815Z",
      "date_published": "2026-07-03T20:45:10.258Z",
      "date_updated": "2026-07-06T16:28:43.146Z",
      "publisher": "VulDB",
      "title": "Open Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile heap-based overflow",
      "affected": {
        "vendors": [
          "Open Asset Import Library"
        ],
        "products": [
          {
            "vendor": "Open Asset Import Library",
            "product": "Assimp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02818
      },
      "nvd": {
        "published": "2026-07-03T21:16:56.077",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14610",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Assimp's CSM importer writes beyond a heap buffer while parsing a crafted CSM file.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376118",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376118/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14610",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844646",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/assimp/assimp/issues/6622",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/assimp/assimp/pull/6649",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/user-attachments/files/27235863/poc.zip",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/assimp/assimp/commit/eb84eec580d3f4ba2f0fd87409b7d0744620f11e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-14611",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T14:09:19.785Z",
      "date_published": "2026-07-03T21:00:10.362Z",
      "date_updated": "2026-07-06T15:06:01.675Z",
      "publisher": "VulDB",
      "title": "DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of resource",
      "affected": {
        "vendors": [
          "DeepMyst"
        ],
        "products": [
          {
            "vendor": "DeepMyst",
            "product": "Mysti"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-668",
          "name": "Exposure of Resource to Wrong Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16743
      },
      "nvd": {
        "published": "2026-07-03T21:16:56.270",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14611",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says a remote workspacePath manipulation exposes a resource, but it does not identify the storage object or failing boundary.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-668"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376119",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376119/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14611",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844651",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/DeepMyst/Mysti/issues/46",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/DeepMyst/Mysti/pull/49",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/DeepMyst/Mysti/commit/6d709229b5199f6769fb3cf763e5122dcc43c079",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/DeepMyst/Mysti/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 506,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-14612",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T14:36:01.997Z",
      "date_published": "2026-07-03T15:11:02.173Z",
      "date_updated": "2026-07-07T02:16:43.353Z",
      "publisher": "redhat",
      "title": "Freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorization",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04009
      },
      "nvd": {
        "published": "2026-07-03T16:16:54.470",
        "lastModified": "2026-07-07T04:17:23.253",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14612",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Red Hat Enterprise Linux 10 copies, writes, or indexes attacker-influenced data without enforcing the destination buffer or object bounds required by the operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14612",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496879",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 637,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-14613",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T14:48:35.343Z",
      "date_published": "2026-07-03T15:16:44.640Z",
      "date_updated": "2026-07-13T11:46:28.563Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permission",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06811
      },
      "nvd": {
        "published": "2026-07-03T16:16:55.527",
        "lastModified": "2026-07-07T18:16:35.023",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14613",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "FGAP v2 authorizes viewing a role and then returns every group assigned to it without separately checking permission to view each group.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14613",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496878",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 635,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-14614",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T15:13:06.650Z",
      "date_published": "2026-07-03T15:33:00.892Z",
      "date_updated": "2026-07-17T11:35:02.499Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: fgap v2 client scope assignment bypass via clientresource",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04375
      },
      "nvd": {
        "published": "2026-07-03T16:16:55.650",
        "lastModified": "2026-07-17T12:17:02.587",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14614",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Red Hat Build of Keycloak accepts a caller-supplied object identifier without binding the selected object to the caller's ownership or authorized scope.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14614",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496889",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-14615",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T15:30:28.048Z",
      "date_published": "2026-07-03T15:47:08.632Z",
      "date_updated": "2026-07-13T11:46:26.025Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child view permission filter",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1220",
          "name": "Insufficient Granularity of Access Control",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06811
      },
      "nvd": {
        "published": "2026-07-03T16:16:55.773",
        "lastModified": "2026-07-06T18:41:14.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14615",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The FGAP v2 parent-group endpoint omits the per-child view-permission filter and reveals child groups outside the delegated administrator's scope.",
        "basis": [
          "CNA",
          "CWE-1220"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14615",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496891",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 445,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-14617",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T16:31:16.337Z",
      "date_published": "2026-07-03T21:45:10.246Z",
      "date_updated": "2026-07-06T19:40:14.670Z",
      "publisher": "VulDB",
      "title": "NousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py GatewayStreamConsumer._filter_and_accumulate case sensitivity",
      "affected": {
        "vendors": [
          "NousResearch"
        ],
        "products": [
          {
            "vendor": "NousResearch",
            "product": "hermes-agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 31,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-178",
          "name": "Improper Handling of Case Sensitivity",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-697",
          "name": "Incorrect Comparison",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 2.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 2.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 1.8,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14797
      },
      "nvd": {
        "published": "2026-07-03T22:16:52.943",
        "lastModified": "2026-07-06T20:16:30.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14617",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "GatewayStreamConsumer handles reasoning-tag case variants inconsistently, allowing them to evade the intended streaming filter.",
        "basis": [
          "CNA",
          "CWE-178",
          "CWE-697"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376134",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376134/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14617",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844654",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/issues/27288",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/pull/28631#issuecomment-4622188016",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/2229e5505bcbb3e15a7ae8fba4c4be37",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 672,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 31
      }
    },
    {
      "cve_id": "CVE-2026-14618",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T16:36:17.574Z",
      "date_published": "2026-07-04T06:00:09.970Z",
      "date_updated": "2026-07-27T06:58:21.581Z",
      "publisher": "VulDB",
      "title": "Open5GS AMF nnrf-handler.c amf_nnrf_handle_nf_discover denial of service",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "Open5GS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24007
      },
      "nvd": {
        "published": "2026-07-04T07:16:24.503",
        "lastModified": "2026-07-06T18:16:37.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14618",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Open5GS AMF discovery path fails to release or terminate a resource correctly, but the public record does not identify the resource or failing cleanup branch.",
        "basis": [
          "CNA",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376135",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376135/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14618",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844824",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/open5gs/open5gs/issues/4517",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/open5gs/open5gs/issues/4517#issuecomment-4589606265",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/ferrancanellas/open5gs/commit/fb5f67703de0213fb9c6e6ef3b48b6c1707e9503",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/open5gs/open5gs/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 440,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-14619",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T16:46:53.251Z",
      "date_published": "2026-07-04T06:30:07.999Z",
      "date_updated": "2026-07-07T02:28:36.540Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System medicine.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10589
      },
      "nvd": {
        "published": "2026-07-04T08:16:21.647",
        "lastModified": "2026-07-07T04:17:23.473",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14619",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This manipulation of the argument editid causes sql injection.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376136",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376136/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14619",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844842",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/cve_submit/issues/22",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 307,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14620",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T16:50:55.559Z",
      "date_published": "2026-07-03T17:00:00.679Z",
      "date_updated": "2026-07-06T15:54:51.519Z",
      "publisher": "openjs",
      "title": "webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints",
      "affected": {
        "vendors": [
          "webpack-dev-server"
        ],
        "products": [
          {
            "vendor": "webpack-dev-server",
            "product": "webpack-dev-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-749",
          "name": "Exposed Dangerous Method or Function",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04558
      },
      "nvd": {
        "published": "2026-07-03T17:16:53.620",
        "lastModified": "2026-07-07T15:12:43.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14620",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page.",
        "basis": [
          "CNA",
          "CWE-352",
          "CWE-749"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-f5vj-f2hx-8m93",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 729,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14621",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T16:52:34.586Z",
      "date_published": "2026-07-04T08:15:08.912Z",
      "date_updated": "2026-07-06T16:51:38.896Z",
      "publisher": "VulDB",
      "title": "FederatedAI FATE OSX Broker QueuePushReqStreamObserver.java QueuePushReqStreamObserver.initEggroll wrong session",
      "affected": {
        "vendors": [
          "FederatedAI"
        ],
        "products": [
          {
            "vendor": "FederatedAI",
            "product": "FATE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-488",
          "name": "Exposure of Data Element to Wrong Session",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 2.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 2.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 1.8,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15243
      },
      "nvd": {
        "published": "2026-07-04T09:16:27.543",
        "lastModified": "2026-07-06T18:16:37.197",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14621",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-488"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376137",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376137/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14621",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844900",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/FederatedAI/FATE/issues/5791",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/FederatedAI/FATE/pull/5792",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/FederatedAI/FATE/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 647,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14622",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T16:55:27.784Z",
      "date_published": "2026-07-04T08:45:08.095Z",
      "date_updated": "2026-07-06T16:22:53.722Z",
      "publisher": "VulDB",
      "title": "jairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authentication",
      "affected": {
        "vendors": [
          "jairiidriss"
        ],
        "products": [
          {
            "vendor": "jairiidriss",
            "product": "restaurant-website-php-mysql"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00408,
        "percentile": 0.33558
      },
      "nvd": {
        "published": "2026-07-04T09:16:27.767",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14622",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive function can be invoked without enforcing the caller authentication required for that operation.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376138",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376138/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14622",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845099",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/jairiidriss/restaurant-website-php-mysql/issues/6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/jairiidriss/restaurant-website-php-mysql/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14623",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:01:00.787Z",
      "date_published": "2026-07-04T09:45:10.403Z",
      "date_updated": "2026-07-06T15:01:50.499Z",
      "publisher": "VulDB",
      "title": "omec-project amf NGAP Message RRCInactiveTransitionReport denial of service",
      "affected": {
        "vendors": [
          "omec-project"
        ],
        "products": [
          {
            "vendor": "omec-project",
            "product": "amf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00317,
        "percentile": 0.2406
      },
      "nvd": {
        "published": "2026-07-04T10:16:27.623",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14623",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A remotely supplied NGAP RRCInactiveTransitionReport reaches a denial-of-service path whose unreleased resource or termination condition is not described publicly.",
        "basis": [
          "CNA",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376139",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376139/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14623",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845348",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/omec-project/amf/issues/676",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/omec-project/amf/pull/666",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/omec-project/amf/commit/34bc6724acc97dba1f8691e586da95b042cb612d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/omec-project/amf/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 434,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14624",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:01:03.539Z",
      "date_published": "2026-07-04T10:15:10.107Z",
      "date_updated": "2026-07-06T19:38:41.857Z",
      "publisher": "VulDB",
      "title": "omec-project amf NGSetupRequest handler.go denial of service",
      "affected": {
        "vendors": [
          "omec-project"
        ],
        "products": [
          {
            "vendor": "omec-project",
            "product": "amf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00317,
        "percentile": 0.2406
      },
      "nvd": {
        "published": "2026-07-04T11:16:47.613",
        "lastModified": "2026-07-06T20:16:30.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14624",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A remote NGSetupRequest can exhaust or strand a resource in AMF, but the public record does not identify the resource or missing cleanup path.",
        "basis": [
          "CNA",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376140",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376140/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14624",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845349",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/omec-project/amf/issues/677",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/omec-project/amf/pull/666",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/omec-project/amf/commit/34bc6724acc97dba1f8691e586da95b042cb612d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/omec-project/amf/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 457,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-14625",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:07:45.760Z",
      "date_published": "2026-07-04T11:30:07.910Z",
      "date_updated": "2026-07-06T17:12:17.826Z",
      "publisher": "VulDB",
      "title": "NousResearch hermes-agent server.py shell.exec protection mechanism",
      "affected": {
        "vendors": [
          "NousResearch"
        ],
        "products": [
          {
            "vendor": "NousResearch",
            "product": "hermes-agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13171
      },
      "nvd": {
        "published": "2026-07-04T12:16:53.740",
        "lastModified": "2026-07-06T18:16:37.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14625",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record labels shell.exec as a protection-mechanism failure but does not identify the bypassed check or trusted boundary.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376141",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376141/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14625",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845595",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/3b11589740dcf16b152b0929e1b3d024",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14626",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:07:48.069Z",
      "date_published": "2026-07-04T12:00:07.960Z",
      "date_updated": "2026-07-07T02:29:27.952Z",
      "publisher": "VulDB",
      "title": "NousResearch hermes-agent HTTP API run_agent.py AIAgent.run_conversation denial of service",
      "affected": {
        "vendors": [
          "NousResearch"
        ],
        "products": [
          {
            "vendor": "NousResearch",
            "product": "hermes-agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 31,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19893
      },
      "nvd": {
        "published": "2026-07-04T12:16:53.903",
        "lastModified": "2026-07-07T04:17:23.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14626",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Crafted todo data can exhaust or stall the service, but the public record does not identify the finite resource or missing termination condition.",
        "basis": [
          "CNA",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376142",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376142/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14626",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845596",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/b91a85f9448beadebe25d37a3f4fd760",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 460,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 31
      }
    },
    {
      "cve_id": "CVE-2026-14627",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:07:50.732Z",
      "date_published": "2026-07-04T12:45:06.333Z",
      "date_updated": "2026-07-06T16:51:32.667Z",
      "publisher": "VulDB",
      "title": "NousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authentication",
      "affected": {
        "vendors": [
          "NousResearch"
        ],
        "products": [
          {
            "vendor": "NousResearch",
            "product": "hermes-agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29547
      },
      "nvd": {
        "published": "2026-07-04T13:16:30.230",
        "lastModified": "2026-07-06T18:16:37.460",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14627",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "DiscordAdapter._is_allowed_user accepts an unauthenticated identity, but the public record does not disclose the failing identity comparison.",
        "basis": [
          "CNA record",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376143",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376143/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14627",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845598",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/d030c690b10a97319efb129ca2f5badb",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14628",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:07:53.319Z",
      "date_published": "2026-07-04T13:00:08.104Z",
      "date_updated": "2026-07-06T16:25:15.490Z",
      "publisher": "VulDB",
      "title": "NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal",
      "affected": {
        "vendors": [
          "NousResearch"
        ],
        "products": [
          {
            "vendor": "NousResearch",
            "product": "hermes-agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 17,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.00672,
        "percentile": 0.48517
      },
      "nvd": {
        "published": "2026-07-04T13:16:30.413",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14628",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "hermes-agent accepts an attacker-controlled path that can resolve outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376144",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376144/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14628",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845599",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/8af7eff27b50bec24b2d0f76dd1c4383",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 411,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-14629",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:10:08.620Z",
      "date_published": "2026-07-04T13:15:08.868Z",
      "date_updated": "2026-07-06T15:00:19.211Z",
      "publisher": "VulDB",
      "title": "RT-Thread Parameter lwp_syscall.c sys_ioctl divide by zero",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "RT-Thread"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-369",
          "name": "Divide By Zero",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00309,
        "percentile": 0.23241
      },
      "nvd": {
        "published": "2026-07-04T14:16:29.203",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14629",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RT-Thread accepts a zero divisor in read, write, or ioctl parameters and performs an unchecked division.",
        "basis": [
          "CNA",
          "CWE-369",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376145",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376145/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14629",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845610",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/RT-Thread/rt-thread/issues/11429",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/RT-Thread/rt-thread/pull/11453",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/RT-Thread/rt-thread/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14630",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:14:51.596Z",
      "date_published": "2026-07-04T14:00:10.026Z",
      "date_updated": "2026-07-06T19:05:32.208Z",
      "publisher": "VulDB",
      "title": "ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversation_history weak hash",
      "affected": {
        "vendors": [
          "ForceInjection"
        ],
        "products": [
          {
            "vendor": "ForceInjection",
            "product": "AI-fundermentals"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-327",
          "name": "Use of a Broken or Risky Cryptographic Algorithm",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-328",
          "name": "Use of Weak Hash",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 2.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 2.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 1.8,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05604
      },
      "nvd": {
        "published": "2026-07-04T15:16:30.740",
        "lastModified": "2026-07-06T20:16:30.310",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14630",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The conversation-history lookup derives session ownership with a weak hash that does not reliably bind recalled history to the verified user identity.",
        "basis": [
          "CNA",
          "CWE-327",
          "CWE-328"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376146",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376146/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14630",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845672",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ForceInjection/AI-fundamentals/issues/17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/ForceInjection/AI-fundamentals/pull/18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/ForceInjection/AI-fundamentals/commit/f57277fdd9ba373ace72d83c272023ec67f720d6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 915,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14631",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:15:55.995Z",
      "date_published": "2026-07-03T17:23:41.451Z",
      "date_updated": "2026-07-06T15:54:11.285Z",
      "publisher": "openjs",
      "title": "webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header",
      "affected": {
        "vendors": [
          "webpack-dev-server"
        ],
        "products": [
          {
            "vendor": "webpack-dev-server",
            "product": "webpack-dev-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33317
      },
      "nvd": {
        "published": "2026-07-03T18:16:24.687",
        "lastModified": "2026-07-07T15:08:59.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14631",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Malformed input raises an exception that escapes the request-handling boundary and terminates the affected process.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-m28w-2pqf-7qgj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 618,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14632",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:24:22.392Z",
      "date_published": "2026-07-04T15:15:08.431Z",
      "date_updated": "2026-07-06T17:12:57.257Z",
      "publisher": "VulDB",
      "title": "kirilkirkov Ecommerce-CodeIgniter-Bootstrap Trusted Backend MY_Controller.php setReferrer redirect",
      "affected": {
        "vendors": [
          "kirilkirkov"
        ],
        "products": [
          {
            "vendor": "kirilkirkov",
            "product": "Ecommerce-CodeIgniter-Bootstrap"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19399
      },
      "nvd": {
        "published": "2026-07-04T16:17:14.140",
        "lastModified": "2026-07-06T18:16:37.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14632",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "setReferrer trusts the attacker-controlled href argument as a redirect destination without confining it to an approved origin.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376147",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376147/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14632",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845900",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/security/advisories/GHSA-x9pg-hvpj-9q44",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/commit/213babdbaa949e94557246414db0130e01394517",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 680,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14633",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:24:24.761Z",
      "date_published": "2026-07-04T15:45:09.498Z",
      "date_updated": "2026-07-07T02:31:41.894Z",
      "publisher": "VulDB",
      "title": "kirilkirkov Ecommerce-CodeIgniter-Bootstrap Hidden REST API Endpoint set cross site scripting",
      "affected": {
        "vendors": [
          "kirilkirkov"
        ],
        "products": [
          {
            "vendor": "kirilkirkov",
            "product": "Ecommerce-CodeIgniter-Bootstrap"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00288,
        "percentile": 0.20994
      },
      "nvd": {
        "published": "2026-07-04T16:17:14.300",
        "lastModified": "2026-07-07T04:17:23.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14633",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Ecommerce-CodeIgniter-Bootstrap rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376148",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376148/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14633",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845903",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/security/advisories/GHSA-8q62-q8qx-j49g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/commit/d9785f995da77bdc62fb2d34bad5f7a162c9ad23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 700,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14634",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:24:28.104Z",
      "date_published": "2026-07-04T16:15:10.840Z",
      "date_updated": "2026-07-06T16:51:26.800Z",
      "publisher": "VulDB",
      "title": "kirilkirkov Ecommerce-CodeIgniter-Bootstrap Subscribed Emails Admin MY_Controller.php checkForPostRequests cross site scripting",
      "affected": {
        "vendors": [
          "kirilkirkov"
        ],
        "products": [
          {
            "vendor": "kirilkirkov",
            "product": "Ecommerce-CodeIgniter-Bootstrap"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00288,
        "percentile": 0.20994
      },
      "nvd": {
        "published": "2026-07-04T17:16:48.610",
        "lastModified": "2026-07-06T18:16:37.727",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14634",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled User-Agent value reaches a web page without output encoding and executes as browser markup.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376149",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376149/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14634",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845904",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/security/advisories/GHSA-v69c-5xg5-q7r8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/commit/23105f25dadf57b4314fc015a63a7c6e910c89df",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 733,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14635",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:24:31.004Z",
      "date_published": "2026-07-04T16:30:08.679Z",
      "date_updated": "2026-07-06T16:24:42.498Z",
      "publisher": "VulDB",
      "title": "kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Multi-Image Endpoint AddProduct.php path traversal",
      "affected": {
        "vendors": [
          "kirilkirkov"
        ],
        "products": [
          {
            "vendor": "kirilkirkov",
            "product": "Ecommerce-CodeIgniter-Bootstrap"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00439,
        "percentile": 0.36094
      },
      "nvd": {
        "published": "2026-07-04T17:16:48.780",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14635",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Vendor Multi-Image endpoint uses the attacker-controlled folder argument in AddProduct.php without constraining traversal outside the intended image directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376150",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376150/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14635",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845906",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/security/advisories/GHSA-6whv-r5hm-vcjr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/commit/2a9497ff11f36e573ad99e1c357ff0e6ded49745",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 756,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14636",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:24:34.759Z",
      "date_published": "2026-07-04T16:45:09.305Z",
      "date_updated": "2026-07-06T14:57:17.274Z",
      "publisher": "VulDB",
      "title": "kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Image Manager AddProduct.php do_upload_others_images path traversal",
      "affected": {
        "vendors": [
          "kirilkirkov"
        ],
        "products": [
          {
            "vendor": "kirilkirkov",
            "product": "Ecommerce-CodeIgniter-Bootstrap"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:P/E:ND/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24803
      },
      "nvd": {
        "published": "2026-07-04T17:16:48.937",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14636",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The vendor image upload handler uses the caller-controlled folder value without confining the resulting path to the upload directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376151",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376151/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14636",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845907",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/security/advisories/GHSA-q3g4-wpv3-v23v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/commit/de1c9e73ccf3bd032d9a0525c4752290d959dd8b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 688,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14637",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:24:37.659Z",
      "date_published": "2026-07-04T17:30:11.062Z",
      "date_updated": "2026-07-06T19:04:15.465Z",
      "publisher": "VulDB",
      "title": "kirilkirkov Ecommerce-CodeIgniter-Bootstrap ShoppingCart.php getCartItems deserialization",
      "affected": {
        "vendors": [
          "kirilkirkov"
        ],
        "products": [
          {
            "vendor": "kirilkirkov",
            "product": "Ecommerce-CodeIgniter-Bootstrap"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 8.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:C/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 8.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.0000000000000009,
      "epss": {
        "score": 0.0061,
        "percentile": 0.45806
      },
      "nvd": {
        "published": "2026-07-04T18:16:28.357",
        "lastModified": "2026-07-06T20:16:30.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14637",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The shopping_cart argument is deserialized directly from remote input, allowing crafted serialized data to cross the object-construction boundary.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376152",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376152/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14637",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845908",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/security/advisories/GHSA-9g5q-g6m3-v5cr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/commit/49b20f53de2b7ec34e920b11c863f1491d911a04",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 682,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14638",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:27:11.799Z",
      "date_published": "2026-07-04T17:45:08.122Z",
      "date_updated": "2026-07-06T17:13:53.825Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System patient.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10073
      },
      "nvd": {
        "published": "2026-07-04T18:16:28.550",
        "lastModified": "2026-07-06T18:16:37.887",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14638",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The patient.php editid parameter reaches an SQL statement as executable SQL syntax.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376154",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376154/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14638",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845933",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/submit/issues/23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 277,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14639",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:28:15.303Z",
      "date_published": "2026-07-04T18:00:08.125Z",
      "date_updated": "2026-07-07T02:32:28.163Z",
      "publisher": "VulDB",
      "title": "CodeAstro Ecommerce Website my_account.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Ecommerce Website"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10068
      },
      "nvd": {
        "published": "2026-07-04T18:16:28.700",
        "lastModified": "2026-07-07T04:17:27.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14639",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376155",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376155/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14639",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845974",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/Laichen-0/CVE/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14640",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:29:12.063Z",
      "date_published": "2026-07-04T18:15:08.221Z",
      "date_updated": "2026-07-06T16:51:20.774Z",
      "publisher": "VulDB",
      "title": "CodeAstro Apartment Visitor Management System Login index.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Apartment Visitor Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18014
      },
      "nvd": {
        "published": "2026-07-04T19:16:53.180",
        "lastModified": "2026-07-06T18:16:38.027",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14640",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376156",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376156/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14640",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846010",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/kk-333/cve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 334,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14641",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:44:12.476Z",
      "date_published": "2026-07-04T18:30:09.105Z",
      "date_updated": "2026-07-06T16:24:08.623Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_course.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18306
      },
      "nvd": {
        "published": "2026-07-04T19:16:53.333",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14641",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376157",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376157/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14641",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846143",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847955",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sunjingyuan123/ccvvee/issues/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14642",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:44:14.879Z",
      "date_published": "2026-07-04T18:45:08.326Z",
      "date_updated": "2026-07-06T13:51:26.736Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_class2.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18841
      },
      "nvd": {
        "published": "2026-07-04T19:16:53.483",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14642",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a Class and Exam Timetabling System database query without safe parameter binding, allowing SQL syntax injection.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376158",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376158/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14642",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846144",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sunjingyuan123/ccvvee/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 334,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14643",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:49:29.469Z",
      "date_published": "2026-07-29T21:08:33.311Z",
      "date_updated": "2026-07-30T15:18:09.760Z",
      "publisher": "openjs",
      "title": "undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives",
      "affected": {
        "vendors": [
          "undici"
        ],
        "products": [
          {
            "vendor": "undici",
            "product": "undici"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-524",
          "name": "Use of Cache Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13788
      },
      "nvd": {
        "published": "2026-07-29T22:16:52.337",
        "lastModified": "2026-08-04T15:53:30.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14643",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Whitespace around a qualified Cache-Control directive is parsed incorrectly, causing a private authenticated response to enter a shared cache.",
        "basis": [
          "CNA",
          "CWE-436",
          "CWE-524"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 968,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-14645",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T17:56:11.243Z",
      "date_published": "2026-07-14T16:33:47.721Z",
      "date_updated": "2026-07-15T15:13:09.292Z",
      "publisher": "Sonatype",
      "title": "Nexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global Capability",
      "affected": {
        "vendors": [
          "Sonatype"
        ],
        "products": [
          {
            "vendor": "Sonatype",
            "product": "Nexus Repository 3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:103e4ec9-0a87-450b-af77-479448ddef11",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00397,
        "percentile": 0.32474
      },
      "nvd": {
        "published": "2026-07-14T17:16:44.130",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14645",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The global webhook capability sends a server-side request to a configured URL without rejecting internal network destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://help.sonatype.com/en/sonatype-nexus-repository-3-94-0-release-notes.html",
          "host": "help.sonatype.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://support.sonatype.com/hc/en-us/articles/53158843564179/",
          "host": "support.sonatype.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14646",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:06:29.314Z",
      "date_published": "2026-07-14T16:49:46.416Z",
      "date_updated": "2026-07-15T15:13:01.396Z",
      "publisher": "Sonatype",
      "title": "Nexus Repository 3 - Server-Side Request Forgery (SSRF) via HTTP Redirect",
      "affected": {
        "vendors": [
          "Sonatype"
        ],
        "products": [
          {
            "vendor": "Sonatype",
            "product": "Nexus Repository 3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N"
        },
        {
          "source": "NVD:103e4ec9-0a87-450b-af77-479448ddef11",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18271
      },
      "nvd": {
        "published": "2026-07-14T17:16:44.410",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14646",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Nexus applies destination checks to the initial proxy URL but follows an upstream HTTP redirect without validating the redirect target against SSRF restrictions.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://help.sonatype.com/en/sonatype-nexus-repository-3-94-0-release-notes.html",
          "host": "help.sonatype.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://support.sonatype.com/hc/en-us/articles/53165019641363/",
          "host": "support.sonatype.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14647",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:29:28.371Z",
      "date_published": "2026-07-04T19:00:11.367Z",
      "date_updated": "2026-07-06T18:44:46.173Z",
      "publisher": "VulDB",
      "title": "onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "onnx"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 22,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16773
      },
      "nvd": {
        "published": "2026-07-04T19:16:53.640",
        "lastModified": "2026-07-06T19:16:56.340",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14647",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The onnx parser can read beyond the end of its input or allocated buffer.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376160",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376160/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14647",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846317",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/onnx/onnx/issues/8036",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/onnx/onnx/pull/8051",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/onnx/onnx/commit/a7bf3a0f1d18bb62575236ef6e4944980c40e045",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/onnx/onnx/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 467,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 22
      }
    },
    {
      "cve_id": "CVE-2026-14648",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:31:22.553Z",
      "date_published": "2026-07-04T19:15:08.145Z",
      "date_updated": "2026-07-06T17:14:42.579Z",
      "publisher": "VulDB",
      "title": "code-projects Online Voting System Login authentication.php test_input sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Online Voting System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27416
      },
      "nvd": {
        "published": "2026-07-04T20:16:54.780",
        "lastModified": "2026-07-06T18:16:38.143",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14648",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The login handler incorporates adminUserName and adminPassword into SQL without preserving the query grammar boundary.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376161",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376161/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14648",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846328",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/c4ttr4ck/ed954dc2e3da968eb460a18385146f4c",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 383,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14649",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:31:24.786Z",
      "date_published": "2026-07-04T19:45:08.192Z",
      "date_updated": "2026-07-07T03:01:15.414Z",
      "publisher": "VulDB",
      "title": "code-projects Online Voting System saveVote.php test_input sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Online Voting System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18836
      },
      "nvd": {
        "published": "2026-07-04T20:16:54.950",
        "lastModified": "2026-07-07T04:17:27.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14649",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Online Voting System, attacker-controlled values reach an SQL statement without the required escaping or parameter binding.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376162",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376162/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14649",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846330",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/c4ttr4ck/a29b2238099fa07b4f072c21123b55ef",
          "host": "gist.github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14650",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:40:38.396Z",
      "date_published": "2026-07-04T20:00:08.823Z",
      "date_updated": "2026-07-06T16:51:14.200Z",
      "publisher": "VulDB",
      "title": "connorskees grass UTF-8 Character raw_to_parse_error denial of service",
      "affected": {
        "vendors": [
          "connorskees"
        ],
        "products": [
          {
            "vendor": "connorskees",
            "product": "grass"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01887
      },
      "nvd": {
        "published": "2026-07-04T20:16:55.117",
        "lastModified": "2026-07-06T18:16:38.280",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14650",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "grass fails to release an acquired resource on the affected path, allowing repeated requests to exhaust the finite resource pool.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376163",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376163/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14650",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846665",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/connorskees/grass/issues/116",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/connorskees/grass/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 694,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-14651",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:40:42.488Z",
      "date_published": "2026-07-04T20:15:13.522Z",
      "date_updated": "2026-07-06T16:23:26.884Z",
      "publisher": "VulDB",
      "title": "connorskees grass visitor denial of service",
      "affected": {
        "vendors": [
          "connorskees"
        ],
        "products": [
          {
            "vendor": "connorskees",
            "product": "grass"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01817
      },
      "nvd": {
        "published": "2026-07-04T21:17:14.690",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14651",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "low",
        "mechanism": "Attacker-supplied Sass can drive the definitionally exponential extend algorithm into excessive work, while the record does not identify an enforceable missing bound.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376164",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376164/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14651",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846667",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/connorskees/grass/issues/117",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/connorskees/grass/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 655,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-14652",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:44:16.476Z",
      "date_published": "2026-07-04T20:30:09.887Z",
      "date_updated": "2026-07-06T13:51:02.190Z",
      "publisher": "VulDB",
      "title": "SourceCodester Simple and Nice Shopping Cart Script Admin Login login.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Simple and Nice Shopping Cart Script"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18834
      },
      "nvd": {
        "published": "2026-07-04T21:17:14.840",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14652",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Simple and Nice Shopping Cart Script incorporates Username into an SQL statement without parameterization, allowing input syntax to alter the database query.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376165",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376165/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14652",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846692",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/Yuesswor/cve/issues/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 334,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14653",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:44:18.752Z",
      "date_published": "2026-07-04T20:45:09.569Z",
      "date_updated": "2026-07-06T18:41:47.535Z",
      "publisher": "VulDB",
      "title": "SourceCodester Simple and Nice Shopping Cart Script mensproductdeletequery.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Simple and Nice Shopping Cart Script"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18834
      },
      "nvd": {
        "published": "2026-07-04T21:17:15.043",
        "lastModified": "2026-07-06T19:16:56.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14653",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mensproductdeletequery.php places the user_id argument into an SQL command without separating it as data.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376166",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376166/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14653",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846701",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/Yuesswor/cve/issues/3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14654",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:44:21.371Z",
      "date_published": "2026-07-04T21:00:09.344Z",
      "date_updated": "2026-07-06T17:29:58.088Z",
      "publisher": "VulDB",
      "title": "SourceCodester Simple and Nice Shopping Cart Script girlsproductdeletequery.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Simple and Nice Shopping Cart Script"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18835
      },
      "nvd": {
        "published": "2026-07-04T21:17:15.193",
        "lastModified": "2026-07-06T18:16:38.410",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14654",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "girlsproductdeletequery.php incorporates user_id into an SQL statement without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376167",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376167/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14654",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846702",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/Yuesswor/cve/issues/4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14655",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:50:24.033Z",
      "date_published": "2026-07-04T21:15:07.326Z",
      "date_updated": "2026-07-07T02:37:00.901Z",
      "publisher": "VulDB",
      "title": "code-projects Assessment Management view-users.php cross site scripting",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Assessment Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 3.3,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 3.3,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 2.9,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11906
      },
      "nvd": {
        "published": "2026-07-04T22:16:42.397",
        "lastModified": "2026-07-07T04:17:30.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14655",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Assessment Management renders attacker-controlled user data as active browser markup without the required output encoding.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376169",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376169/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14655",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846714",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zzzxc643/CVE1/blob/main/assessment/vul3.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14656",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:50:27.237Z",
      "date_published": "2026-07-04T21:30:08.426Z",
      "date_updated": "2026-07-06T16:51:07.971Z",
      "publisher": "VulDB",
      "title": "code-projects Assessment Management remove-user.php cross site scripting",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Assessment Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20072
      },
      "nvd": {
        "published": "2026-07-04T22:16:42.553",
        "lastModified": "2026-07-06T18:16:38.540",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14656",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The manipulation of the argument ID leads to cross site scripting.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376170",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376170/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14656",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846715",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zzzxc643/CVE1/blob/main/assessment/vul4.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 323,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14657",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:50:29.860Z",
      "date_published": "2026-07-04T21:45:07.870Z",
      "date_updated": "2026-07-06T16:19:01.343Z",
      "publisher": "VulDB",
      "title": "code-projects Assessment Management Database Query marking-scheme.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Assessment Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10589
      },
      "nvd": {
        "published": "2026-07-04T22:16:42.707",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14657",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The squestions[] request value reaches the marking-scheme.php database query without SQL grammar separation.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376172",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376172/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14657",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846716",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zzzxc643/CVE1/blob/main/assessment/vul5.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14658",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:50:32.861Z",
      "date_published": "2026-07-04T22:00:09.063Z",
      "date_updated": "2026-07-06T13:43:09.707Z",
      "publisher": "VulDB",
      "title": "code-projects Assessment Management marking-scheme.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Assessment Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10071
      },
      "nvd": {
        "published": "2026-07-04T23:16:54.607",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14658",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376171",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376171/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14658",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846717",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zzzxc643/CVE1/blob/main/assessment/vul6.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14659",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:52:05.127Z",
      "date_published": "2026-07-04T22:15:10.332Z",
      "date_updated": "2026-07-06T18:47:23.606Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System patientappointment.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10067
      },
      "nvd": {
        "published": "2026-07-04T23:16:55.280",
        "lastModified": "2026-07-06T19:16:56.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14659",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376173",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376173/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14659",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846728",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/vuln_submit/issues/21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 313,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14660",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T18:53:30.359Z",
      "date_published": "2026-07-04T22:30:09.316Z",
      "date_updated": "2026-07-06T17:41:03.762Z",
      "publisher": "VulDB",
      "title": "code-projects Online Job Portal login.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Online Job Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18015
      },
      "nvd": {
        "published": "2026-07-04T23:16:55.437",
        "lastModified": "2026-07-06T19:16:56.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14660",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376174",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376174/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14660",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846744",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/aiyuyuyu/cve/blob/main/job_portal_sql.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14683",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:39:55.742Z",
      "date_published": "2026-07-04T23:00:10.759Z",
      "date_updated": "2026-07-16T07:18:18.631Z",
      "publisher": "VulDB",
      "title": "HdrHistogram AbstractHistogram.java memory allocation",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "HdrHistogram"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01979
      },
      "nvd": {
        "published": "2026-07-04T23:16:55.590",
        "lastModified": "2026-07-16T08:16:16.500",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14683",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HdrHistogram allocates memory from an attacker-influenced size without enforcing a safe maximum.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376279",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376279/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14683",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846750",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846752",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/HdrHistogram/HdrHistogram/issues/219",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/HdrHistogram/HdrHistogram/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 610,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:39:58.430Z",
      "date_published": "2026-07-04T23:30:10.875Z",
      "date_updated": "2026-07-16T07:18:23.164Z",
      "publisher": "VulDB",
      "title": "HdrHistogram AbstractHistogram.java memory allocation",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "HdrHistogram"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02129
      },
      "nvd": {
        "published": "2026-07-05T00:17:35.457",
        "lastModified": "2026-07-16T08:16:17.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14684",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "low",
        "mechanism": "A caller-controlled significant-digits value can drive an unbounded memory allocation during histogram decoding.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376280",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376280/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14684",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846754",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/HdrHistogram/HdrHistogram/issues/220",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/HdrHistogram/HdrHistogram/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 593,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:40:13.250Z",
      "date_published": "2026-07-04T23:45:08.527Z",
      "date_updated": "2026-07-16T07:18:02.162Z",
      "publisher": "VulDB",
      "title": "HdrHistogram AbstractHistogram AbstractHistogram.java recordValueWithCount state issue",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "HdrHistogram"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-371",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01989
      },
      "nvd": {
        "published": "2026-07-05T00:17:35.610",
        "lastModified": "2026-07-16T08:16:17.687",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14685",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The disputed record names only a state issue and does not expose a defensible failing check, transition, or security boundary.",
        "basis": [
          "CNA",
          "CWE-371"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376281",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376281/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14685",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846761",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/HdrHistogram/HdrHistogram/issues/221",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/HdrHistogram/HdrHistogram/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 603,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14686",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:40:18.249Z",
      "date_published": "2026-07-05T00:00:10.233Z",
      "date_updated": "2026-07-16T07:18:14.216Z",
      "publisher": "VulDB",
      "title": "HdrHistogram Range Check DoubleHistogram.java org.HdrHistogram.DoubleHistogram.recordValue comparison",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "HdrHistogram"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-697",
          "name": "Incorrect Comparison",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15219
      },
      "nvd": {
        "published": "2026-07-05T01:21:57.560",
        "lastModified": "2026-07-16T08:16:17.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14686",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "low",
        "mechanism": "DoubleHistogram.recordValue uses an incorrect range comparison for a locally supplied value.",
        "basis": [
          "CNA record",
          "CWE-697"
        ],
        "deepDive": false,
        "notes": "The CNA record states that the security boundary and vulnerability status are disputed."
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376282",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376282/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14686",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846762",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/HdrHistogram/HdrHistogram/issues/222",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/HdrHistogram/HdrHistogram/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:42:15.722Z",
      "date_published": "2026-07-05T00:30:09.629Z",
      "date_updated": "2026-07-06T18:38:43.833Z",
      "publisher": "VulDB",
      "title": "666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison",
      "affected": {
        "vendors": [
          "666ghj"
        ],
        "products": [
          {
            "vendor": "666ghj",
            "product": "BettaFish"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-187",
          "name": "Partial String Comparison",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-697",
          "name": "Incorrect Comparison",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25729
      },
      "nvd": {
        "published": "2026-07-05T01:21:57.753",
        "lastModified": "2026-07-06T19:16:56.823",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14687",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BettaFish compares only part of a security-relevant string and treats that partial match as equivalent.",
        "basis": [
          "CNA",
          "CWE-187",
          "CWE-697"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376283",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376283/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14687",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846753",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/666ghj/BettaFish/issues/688",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/666ghj/BettaFish/pull/689",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/666ghj/BettaFish/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 420,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:48:31.734Z",
      "date_published": "2026-07-05T01:00:12.097Z",
      "date_updated": "2026-07-06T17:46:57.337Z",
      "publisher": "VulDB",
      "title": "itsourcecode Online Hotel Management System login.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Online Hotel Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20294
      },
      "nvd": {
        "published": "2026-07-05T01:21:57.917",
        "lastModified": "2026-07-06T19:16:56.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14688",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The hotel-management endpoint concatenates attacker-controlled input into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376284",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376284/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14688",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846809",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/geminipolo1991-vampire/CVE---Web/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 310,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14689",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:53:08.746Z",
      "date_published": "2026-07-05T01:15:21.240Z",
      "date_updated": "2026-07-07T02:39:17.733Z",
      "publisher": "VulDB",
      "title": "CodeAstro Apartment Visitor Management System add-apartment.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Apartment Visitor Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10076
      },
      "nvd": {
        "published": "2026-07-05T02:17:40.470",
        "lastModified": "2026-07-07T04:17:36.760",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14689",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Apartment Visitor Management System, attacker-controlled input reaches an SQL statement without the required parameter binding or SQL-context escaping.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376285",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376285/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14689",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846829",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/yihaofuweng/cve/issues/70",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 364,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:58:52.574Z",
      "date_published": "2026-07-05T01:30:09.372Z",
      "date_updated": "2026-07-06T16:50:53.507Z",
      "publisher": "VulDB",
      "title": "SourceCodester Multi-Vendor Online Grocery Management System Users.php save_users improper authorization",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Multi-Vendor Online Grocery Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21664
      },
      "nvd": {
        "published": "2026-07-05T02:17:40.743",
        "lastModified": "2026-07-06T18:16:39.157",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14690",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows an authentication or authorization boundary can be crossed but does not identify the exact caller-object predicate that fails.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376286",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376286/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14690",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846830",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lee945/cve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14691",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:58:54.895Z",
      "date_published": "2026-07-05T01:45:09.015Z",
      "date_updated": "2026-07-06T16:21:35.636Z",
      "publisher": "VulDB",
      "title": "SourceCodester Multi-Vendor Online Grocery Management System Setting SystemSettings.php update_settings_info code injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Multi-Vendor Online Grocery Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15404
      },
      "nvd": {
        "published": "2026-07-05T02:17:40.907",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14691",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "update_settings_info interprets attacker-controlled content array data as executable code rather than preserving it as data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376287",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376287/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14691",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846831",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lee945/cve/issues/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 394,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14692",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:58:57.286Z",
      "date_published": "2026-07-05T02:00:08.972Z",
      "date_updated": "2026-07-06T13:40:56.540Z",
      "publisher": "VulDB",
      "title": "SourceCodester Multi-Vendor Online Grocery Management System POST Parameter Master.php save_shop_type sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Multi-Vendor Online Grocery Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.1059
      },
      "nvd": {
        "published": "2026-07-05T03:16:18.470",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14692",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Multi-Vendor Online Grocery Management System data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376288",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376288/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14692",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846832",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lee945/cve/issues/3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14693",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:59:01.755Z",
      "date_published": "2026-07-05T02:15:09.034Z",
      "date_updated": "2026-07-06T18:37:23.456Z",
      "publisher": "VulDB",
      "title": "SourceCodester Multi-Vendor Online Grocery Management System Master.php cancel_order improper authorization",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Multi-Vendor Online Grocery Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14448
      },
      "nvd": {
        "published": "2026-07-05T03:16:19.773",
        "lastModified": "2026-07-06T19:16:57.063",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14693",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The cancel_order action lacks an effective authorization binding, but the public record does not identify the omitted capability or ownership check.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376289",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376289/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14693",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846833",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lee945/cve/issues/4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14694",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:59:04.405Z",
      "date_published": "2026-07-05T02:30:08.729Z",
      "date_updated": "2026-07-06T17:49:22.427Z",
      "publisher": "VulDB",
      "title": "SourceCodester Multi-Vendor Online Grocery Management System POST Parameter Master.php cancel_order sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Multi-Vendor Online Grocery Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10071
      },
      "nvd": {
        "published": "2026-07-05T03:16:19.967",
        "lastModified": "2026-07-06T19:16:57.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14694",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Multi-Vendor Online Grocery Management System data path incorporates attacker-controlled values into SQL grammar without parameterization or sufficient escaping.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376290",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376290/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14694",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846834",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lee945/cve/issues/5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 393,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:59:07.059Z",
      "date_published": "2026-07-05T02:45:07.836Z",
      "date_updated": "2026-07-07T02:40:17.701Z",
      "publisher": "VulDB",
      "title": "SourceCodester Multi-Vendor Online Grocery Management System Registration Users.php save_client sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Multi-Vendor Online Grocery Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18014
      },
      "nvd": {
        "published": "2026-07-05T03:16:20.137",
        "lastModified": "2026-07-07T04:17:36.970",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14695",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The registration handler incorporates the Name argument into an SQL statement without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376291",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376291/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14695",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846835",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lee945/cve/issues/6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T05:19:32.932Z",
      "date_published": "2026-07-05T03:00:08.621Z",
      "date_updated": "2026-07-06T16:50:47.714Z",
      "publisher": "VulDB",
      "title": "SourceCodester Syllabus-Aligned Learning Management and Examination System upload_files.php unrestricted upload",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Syllabus-Aligned Learning Management and Examination System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11812
      },
      "nvd": {
        "published": "2026-07-05T05:16:26.997",
        "lastModified": "2026-07-06T18:16:39.273",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14698",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SourceCodester upload_files.php accepts a remotely supplied file without restricting its type or executable placement, enabling an unrestricted upload.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376294",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376294/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14698",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846859",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://pastebin.com/PNJvBZwT",
          "host": "pastebin.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14699",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T05:22:43.104Z",
      "date_published": "2026-07-05T03:15:08.112Z",
      "date_updated": "2026-07-06T16:21:02.273Z",
      "publisher": "VulDB",
      "title": "zcaceres markdownify-mcp Markdownify.ts assertPathAllowed symlink",
      "affected": {
        "vendors": [
          "zcaceres"
        ],
        "products": [
          {
            "vendor": "zcaceres",
            "product": "markdownify-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-61",
          "name": "UNIX Symbolic Link (Symlink) Following",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03805
      },
      "nvd": {
        "published": "2026-07-05T05:16:27.977",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14699",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "assertPathAllowed accepts a symlink that resolves outside the intended filesystem namespace.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-61"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376295",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376295/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14699",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846864",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zcaceres/markdownify-mcp/issues/108",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zcaceres/markdownify-mcp/pull/109",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zcaceres/markdownify-mcp/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 309,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14700",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T05:24:35.276Z",
      "date_published": "2026-07-05T03:30:09.324Z",
      "date_updated": "2026-07-06T13:40:26.163Z",
      "publisher": "VulDB",
      "title": "code-projects Internship Management System Employer Login Endpoint login.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Internship Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18838
      },
      "nvd": {
        "published": "2026-07-05T05:16:28.140",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14700",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376296",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376296/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14700",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846889",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zzzxc643/CVE1/blob/main/assessment/vul7.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 386,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14701",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T05:24:37.642Z",
      "date_published": "2026-07-05T03:45:08.160Z",
      "date_updated": "2026-07-06T18:02:08.536Z",
      "publisher": "VulDB",
      "title": "code-projects Internship Management System Password Change Endpoint change_password.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Internship Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10074
      },
      "nvd": {
        "published": "2026-07-05T05:16:28.300",
        "lastModified": "2026-07-06T19:16:57.307",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14701",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376297",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376297/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14701",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846890",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zzzxc643/CVE1/blob/main/assessment/vul8.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 351,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14702",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T05:28:34.112Z",
      "date_published": "2026-07-05T04:00:08.361Z",
      "date_updated": "2026-07-06T17:49:57.657Z",
      "publisher": "VulDB",
      "title": "zcaceres markdownify-mcp webpage-to-markdown Markdownify.ts saveToTempFile random values",
      "affected": {
        "vendors": [
          "zcaceres"
        ],
        "products": [
          {
            "vendor": "zcaceres",
            "product": "markdownify-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-310",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-330",
          "name": "Use of Insufficiently Random Values",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1,
          "severity": "",
          "vector": "AV:L/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1,
          "severity": "",
          "vector": "AV:L/AC:H/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.5,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.0011,
        "percentile": 0.01485
      },
      "nvd": {
        "published": "2026-07-05T05:16:28.450",
        "lastModified": "2026-07-06T19:16:57.430",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14702",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "saveToTempFile generates a predictable temporary filename, so a local peer can guess the name used for security-sensitive temporary content.",
        "basis": [
          "CNA",
          "CWE-310",
          "CWE-330"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376298",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376298/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14702",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846942",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zcaceres/markdownify-mcp/issues/110",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zcaceres/markdownify-mcp/pull/111",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zcaceres/markdownify-mcp/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14703",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T05:32:24.749Z",
      "date_published": "2026-07-05T04:15:07.543Z",
      "date_updated": "2026-07-07T02:42:43.823Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System patientorder.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10586
      },
      "nvd": {
        "published": "2026-07-05T05:16:28.610",
        "lastModified": "2026-07-07T04:17:37.193",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14703",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a Hospital Management System database query without safe parameter binding, allowing SQL syntax injection.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376299",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376299/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14703",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846954",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/submit_vuln/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 309,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14704",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T05:46:21.381Z",
      "date_published": "2026-07-05T04:30:08.009Z",
      "date_updated": "2026-07-06T16:50:40.926Z",
      "publisher": "VulDB",
      "title": "stephen-kruger bluebox cross site scripting",
      "affected": {
        "vendors": [
          "stephen-kruger"
        ],
        "products": [
          {
            "vendor": "stephen-kruger",
            "product": "bluebox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 13,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00288,
        "percentile": 0.20994
      },
      "nvd": {
        "published": "2026-07-05T06:16:28.420",
        "lastModified": "2026-07-06T18:16:39.393",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14704",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The code argument reaches generated web content without the context separation needed to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376300",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376300/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14704",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847357",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/stephen-kruger/bluebox/issues/32",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/stephen-kruger/bluebox/issues/32#issuecomment-4632135192",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/stephen-kruger/bluebox/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 376,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-14705",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T05:55:10.492Z",
      "date_published": "2026-07-05T04:45:07.884Z",
      "date_updated": "2026-07-06T13:29:42.382Z",
      "publisher": "VulDB",
      "title": "code-projects Online Examination head.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Online Examination"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18831
      },
      "nvd": {
        "published": "2026-07-05T06:16:29.607",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14705",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The examination login path incorporates the uname and password parameters into SQL without preserving the query grammar boundary.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376301",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376301/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14705",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847384",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zzzxc643/CVE1/blob/main/project1/vul1.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14706",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T05:55:12.927Z",
      "date_published": "2026-07-05T05:00:08.778Z",
      "date_updated": "2026-07-06T13:39:58.701Z",
      "publisher": "VulDB",
      "title": "code-projects Online Examination Quiz Creation Feature update.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Online Examination"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10584
      },
      "nvd": {
        "published": "2026-07-05T06:16:30.043",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14706",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Quiz-creation parameters are incorporated into an update.php SQL statement without preserving the boundary between values and SQL syntax.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376302",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376302/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14706",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847386",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zzzxc643/CVE1/blob/main/project1/vul3.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 359,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T07:40:08.980Z",
      "date_published": "2026-07-05T05:15:07.440Z",
      "date_updated": "2026-07-06T17:53:16.705Z",
      "publisher": "VulDB",
      "title": "SourceCodester Pizzafy E-Commerce System ajax.php confirm_order sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Pizzafy E-Commerce System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18838
      },
      "nvd": {
        "published": "2026-07-05T06:16:30.480",
        "lastModified": "2026-07-06T19:16:57.550",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14713",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Pizzafy E-Commerce System query path incorporates attacker-controlled input into SQL without parameter separation.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376303",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376303/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14713",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846718",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/J4ng3ay/CVE/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 346,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14714",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T07:43:09.434Z",
      "date_published": "2026-07-05T05:30:09.514Z",
      "date_updated": "2026-07-06T18:20:42.707Z",
      "publisher": "VulDB",
      "title": "zhayujie chatgpt-on-wechat CowAgent wx Endpoint common.py verify_server missing authentication",
      "affected": {
        "vendors": [
          "zhayujie"
        ],
        "products": [
          {
            "vendor": "zhayujie",
            "product": "chatgpt-on-wechat CowAgent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00463,
        "percentile": 0.37798
      },
      "nvd": {
        "published": "2026-07-05T06:16:30.873",
        "lastModified": "2026-07-06T19:16:57.690",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14714",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "verify_server permits the WeChat endpoint to operate with an empty token, reducing its signature check to a predictable value.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376304",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376304/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14714",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847484",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/issues/2860",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/commit/3d7c68bac6ee74fad63f43cf99e45c62e202ed55",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/releases/tag/2.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 877,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14716",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T07:50:37.826Z",
      "date_published": "2026-07-05T05:45:07.965Z",
      "date_updated": "2026-07-07T02:43:44.690Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw WebSocket RPC router.go MethodRouter.Handle authorization",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15895
      },
      "nvd": {
        "published": "2026-07-05T06:16:31.240",
        "lastModified": "2026-07-07T04:17:37.643",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14716",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that GoClaw permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376305",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376305/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14716",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847501",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1188",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14717",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T07:52:12.611Z",
      "date_published": "2026-07-05T06:00:09.189Z",
      "date_updated": "2026-07-06T16:50:34.271Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System patientlogin.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.1059
      },
      "nvd": {
        "published": "2026-07-05T07:16:39.630",
        "lastModified": "2026-07-06T18:16:39.513",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14717",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Hospital Management System incorporates attacker-controlled values or identifiers into a SQL statement without preserving the boundary between query syntax and data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376306",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376306/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14717",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847503",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/submit_vuln/issues/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14719",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T07:55:32.396Z",
      "date_published": "2026-07-05T07:00:09.264Z",
      "date_updated": "2026-07-06T13:28:43.767Z",
      "publisher": "VulDB",
      "title": "SourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges management",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Onlne Examination & Learning Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21663
      },
      "nvd": {
        "published": "2026-07-05T08:16:25.803",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14719",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "register.php trusts the caller-supplied role value when assigning the new account's privileges.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-266",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376307",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376307/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14719",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847515",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://pastebin.com/Z4i5MGxk",
          "host": "pastebin.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14721",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T07:58:44.620Z",
      "date_published": "2026-07-05T07:15:06.452Z",
      "date_updated": "2026-07-06T13:39:30.030Z",
      "publisher": "VulDB",
      "title": "UTT HiPER 1250GW Web Endpoint ConfigWirelessBase_5g stack-based overflow",
      "affected": {
        "vendors": [
          "UTT"
        ],
        "products": [
          {
            "vendor": "UTT",
            "product": "HiPER 1250GW"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00447,
        "percentile": 0.36709
      },
      "nvd": {
        "published": "2026-07-05T08:16:26.647",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14721",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HiPER 1250GW copies attacker-controlled data past a fixed stack buffer because the input length is not bounded to the destination size.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376308",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376308/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14721",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847632",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/J-CLOWN-TAROT/UTT",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 372,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14722",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T08:01:16.620Z",
      "date_published": "2026-07-05T07:30:08.357Z",
      "date_updated": "2026-07-06T17:52:01.260Z",
      "publisher": "VulDB",
      "title": "tiddly-gittly TidGi-Desktop Git Repository Import loadWikiTiddlersWithSubWikis.ts code injection",
      "affected": {
        "vendors": [
          "tiddly-gittly"
        ],
        "products": [
          {
            "vendor": "tiddly-gittly",
            "product": "TidGi-Desktop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 13,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00322,
        "percentile": 0.2463
      },
      "nvd": {
        "published": "2026-07-05T08:16:26.807",
        "lastModified": "2026-07-06T19:16:57.833",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14722",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "TidGi-Desktop treats attacker-controlled Git repository import content as code in loadWikiTiddlersWithSubWikis.ts.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376309",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376309/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14722",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847648",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/tiddly-gittly/TidGi-Desktop/security/advisories/GHSA-9hc2-hjx8-q6pv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/tiddly-gittly/TidGi-Desktop/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 353,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-14723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T08:05:02.250Z",
      "date_published": "2026-07-05T07:45:08.075Z",
      "date_updated": "2026-07-06T17:51:18.363Z",
      "publisher": "VulDB",
      "title": "AD-Security AD_Miner Cache analyse_cache.py request_a deserialization",
      "affected": {
        "vendors": [
          "AD-Security"
        ],
        "products": [
          {
            "vendor": "AD-Security",
            "product": "AD_Miner"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02488
      },
      "nvd": {
        "published": "2026-07-05T08:16:26.957",
        "lastModified": "2026-07-06T19:16:57.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14723",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "analyse_cache.py deserializes data selected through a local command-line argument without establishing that it is trusted.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376310",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376310/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14723",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847672",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/AD-Security/AD_Miner/issues/238",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/AD-Security/AD_Miner/pull/239",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/AD-Security/AD_Miner/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847672?__cf_chl_f_tk=OMGtGTdlFc9MbAYE2yL37Va0.8fqbuwXCbUhJ7jVF8w-1783360226-1.0.1.1-06NIwDTuA.wmgvZmcy.dqKMaKSq8Jqm4cv6OH8kKfxw",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 339,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14725",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T08:06:32.108Z",
      "date_published": "2026-07-05T08:00:08.967Z",
      "date_updated": "2026-07-07T02:46:18.393Z",
      "publisher": "VulDB",
      "title": "SourceCodester Online Boat Reservation System session expiration",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Online Boat Reservation System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11812
      },
      "nvd": {
        "published": "2026-07-05T08:16:27.113",
        "lastModified": "2026-07-07T04:17:39.040",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14725",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The reservation system leaves a session valid beyond its intended expiration boundary, while the exact invalidation event is not public.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376311",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376311/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14725",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847674",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://medium.com/@hemantrajbhati5555/improper-session-invalidation-in-online-boat-reservation-system-using-php-acebd53a8ae7",
          "host": "medium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "exploit"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 290,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T08:48:15.419Z",
      "date_published": "2026-07-05T08:15:07.823Z",
      "date_updated": "2026-07-06T16:50:28.120Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System patientprofile.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10586
      },
      "nvd": {
        "published": "2026-07-05T09:16:27.243",
        "lastModified": "2026-07-06T18:16:39.643",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14730",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Performing a manipulation of the argument patientname results in sql injection.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376312",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376312/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14730",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847780",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/submit_vuln/issues/3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T08:48:17.809Z",
      "date_published": "2026-07-05T08:30:07.932Z",
      "date_updated": "2026-07-06T13:27:55.568Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System patientreport.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10585
      },
      "nvd": {
        "published": "2026-07-05T09:16:28.133",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14731",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The editid request value reaches patientreport.php as SQL syntax instead of a bound value.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376313",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376313/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14731",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847781",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/submit_vuln/issues/4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14732",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T08:53:05.466Z",
      "date_published": "2026-07-05T08:45:08.618Z",
      "date_updated": "2026-07-06T13:34:44.814Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_exam.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00284,
        "percentile": 0.2063
      },
      "nvd": {
        "published": "2026-07-05T09:16:28.290",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14732",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376314",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376314/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14732",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847956",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/cyberdrinclj/pcve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14733",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T08:54:01.809Z",
      "date_published": "2026-07-05T09:00:09.692Z",
      "date_updated": "2026-07-06T17:54:51.029Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_coursea.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20628
      },
      "nvd": {
        "published": "2026-07-05T09:16:28.443",
        "lastModified": "2026-07-06T19:16:58.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14733",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376315",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376315/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14733",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847983",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/cyberdrinclk/scve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14734",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T08:54:17.031Z",
      "date_published": "2026-07-05T09:15:08.326Z",
      "date_updated": "2026-07-06T18:15:15.740Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_product.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20629
      },
      "nvd": {
        "published": "2026-07-05T10:16:28.783",
        "lastModified": "2026-07-06T19:16:58.240",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14734",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376316",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376316/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14734",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/848001",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/cyberdrinclc-bot/cves/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14735",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T08:56:35.237Z",
      "date_published": "2026-07-05T09:30:07.998Z",
      "date_updated": "2026-07-07T02:48:25.755Z",
      "publisher": "VulDB",
      "title": "code-projects Smart Parking System parkings.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Smart Parking System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18832
      },
      "nvd": {
        "published": "2026-07-05T10:16:29.960",
        "lastModified": "2026-07-07T04:17:43.970",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14735",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a Smart Parking System database query without safe parameter binding, allowing query syntax injection.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376317",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376317/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14735",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/848002",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://medium.com/@avdzav10/sql-injection-leading-to-arbitrary-file-read-in-smart-parking-system-php-2cd5b084f9e1",
          "host": "medium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14736",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T09:00:10.944Z",
      "date_published": "2026-07-05T09:45:33.000Z",
      "date_updated": "2026-07-06T16:50:21.484Z",
      "publisher": "VulDB",
      "title": "Ruijie RG-UAC user_auth_commit.php unrestricted upload",
      "affected": {
        "vendors": [
          "Ruijie"
        ],
        "products": [
          {
            "vendor": "Ruijie",
            "product": "RG-UAC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20635
      },
      "nvd": {
        "published": "2026-07-05T10:16:30.117",
        "lastModified": "2026-07-06T18:16:39.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14736",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload_image handler accepts a remotely supplied file without restricting its dangerous type or destination.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376318",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376318/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14736",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/848624",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/wiki/OiAKwH3hRi3oVpkQyeycjjPrnL8?fromScene=spaceOverview",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T09:02:56.109Z",
      "date_published": "2026-07-05T10:00:36.457Z",
      "date_updated": "2026-07-06T13:07:09.368Z",
      "publisher": "VulDB",
      "title": "Hanwang e-Face General Management Platform querySysAuthStr.do sql injection",
      "affected": {
        "vendors": [
          "Hanwang"
        ],
        "products": [
          {
            "vendor": "Hanwang",
            "product": "e-Face General Management Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00259,
        "percentile": 0.1754
      },
      "nvd": {
        "published": "2026-07-05T11:16:26.553",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14737",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376320",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376320/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14737",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/848640",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/docx/RWItdiw5Go02UsxHxgNcMWBqnJc?from=from_copylink",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T09:06:11.045Z",
      "date_published": "2026-07-05T10:15:09.187Z",
      "date_updated": "2026-07-06T13:33:34.713Z",
      "publisher": "VulDB",
      "title": "exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash",
      "affected": {
        "vendors": [
          "exo-explore"
        ],
        "products": [
          {
            "vendor": "exo-explore",
            "product": "exo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 72,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-327",
          "name": "Use of a Broken or Risky Cryptographic Algorithm",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-328",
          "name": "Use of Weak Hash",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 2.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 2.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 3.6999999999999997,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12093
      },
      "nvd": {
        "published": "2026-07-05T11:16:27.197",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14738",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The vision feature cache key uses a weak hash, allowing distinct attacker-controlled inputs to collide in the cache namespace.",
        "basis": [
          "CNA record",
          "CWE-328"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376321",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376321/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14738",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/848737",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/exo-explore/exo/issues/2151",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/exo-explore/exo/pull/2152",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/exo-explore/exo/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 517,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 72
      }
    },
    {
      "cve_id": "CVE-2026-14739",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T09:24:31.098Z",
      "date_published": "2026-07-07T22:05:18.457Z",
      "date_updated": "2026-07-08T13:56:43.597Z",
      "publisher": "CPANSec",
      "title": "DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders",
      "affected": {
        "vendors": [
          "HMBRAND"
        ],
        "products": [
          {
            "vendor": "HMBRAND",
            "product": "DBI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00391,
        "percentile": 0.31876
      },
      "nvd": {
        "published": "2026-07-07T23:16:54.090",
        "lastModified": "2026-07-10T14:41:16.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14739",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DBI lets attacker-controlled input reach an out-of-bounds write.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-10879",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Not Applicable",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://metacpan.org/release/HMBRAND/DBI-1.650/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 296,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14740",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T09:43:56.576Z",
      "date_published": "2026-07-07T22:05:45.077Z",
      "date_updated": "2026-07-08T13:59:33.009Z",
      "publisher": "CPANSec",
      "title": "DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment",
      "affected": {
        "vendors": [
          "HMBRAND"
        ],
        "products": [
          {
            "vendor": "HMBRAND",
            "product": "DBI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.31435
      },
      "nvd": {
        "published": "2026-07-07T23:16:54.193",
        "lastModified": "2026-07-10T14:40:21.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14740",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DBI removes an initial SQL comment and then reads one byte beyond the shortened preparse buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/perl5-dbi/dbi/security/advisories/GHSA-35f4-f8m9-w8xg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://metacpan.org/release/HMBRAND/DBI-1.650/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/07/17",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 405,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14741",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T11:57:33.964Z",
      "date_published": "2026-07-17T15:20:07.201Z",
      "date_updated": "2026-07-21T14:17:09.873Z",
      "publisher": "CPANSec",
      "title": "HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date",
      "affected": {
        "vendors": [
          "OALDERS"
        ],
        "products": [
          {
            "vendor": "OALDERS",
            "product": "HTTP::Date"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28011
      },
      "nvd": {
        "published": "2026-07-17T16:17:13.443",
        "lastModified": "2026-07-21T15:16:30.610",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14741",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A user-controlled regular expression or match string drives unbounded backtracking in HTTP::Date.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/libwww-perl/HTTP-Date/commit/78c20952cdfbf11e03cf1199ad70f13298a84c5c.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/libwww-perl/HTTP-Date/pull/33",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://metacpan.org/release/OALDERS/HTTP-Date-6.08/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/17/10",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 914,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14742",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:46:38.803Z",
      "date_published": "2026-07-05T10:45:09.243Z",
      "date_updated": "2026-07-06T17:59:43.776Z",
      "publisher": "VulDB",
      "title": "langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash",
      "affected": {
        "vendors": [
          "langchain-ai"
        ],
        "products": [
          {
            "vendor": "langchain-ai",
            "product": "langgraph"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-327",
          "name": "Use of a Broken or Risky Cryptographic Algorithm",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-328",
          "name": "Use of Weak Hash",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 2.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 2.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 1.8,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05604
      },
      "nvd": {
        "published": "2026-07-05T11:16:27.390",
        "lastModified": "2026-07-06T19:16:58.397",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14742",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Task cache keys rely on a weak hash whose collisions can make distinct inputs share a cache identity.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-328"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376328",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376328/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14742",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849217",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/langchain-ai/langgraph/issues/8009",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/langchain-ai/langgraph/pull/8069",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/langchain-ai/langgraph/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 540,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-14743",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:56:41.679Z",
      "date_published": "2026-07-05T11:00:09.185Z",
      "date_updated": "2026-07-06T18:43:28.717Z",
      "publisher": "VulDB",
      "title": "code-projects Real State Services normalHomeSale.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Real State Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18009
      },
      "nvd": {
        "published": "2026-07-05T12:17:12.037",
        "lastModified": "2026-07-06T19:16:58.560",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14743",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "normalHomeSale.php incorporates the remote loc parameter into an SQL statement without preserving the SQL data boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376329",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376329/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14743",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849252",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/6Justdododo6/CVE/issues/22",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14744",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:56:44.337Z",
      "date_published": "2026-07-05T11:15:07.075Z",
      "date_updated": "2026-07-07T02:49:25.223Z",
      "publisher": "VulDB",
      "title": "code-projects Real State Services normalHomeRent.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Real State Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18009
      },
      "nvd": {
        "published": "2026-07-05T12:17:12.853",
        "lastModified": "2026-07-07T04:17:44.433",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14744",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Real State Services data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376330",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376330/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14744",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849260",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/6Justdododo6/CVE/issues/23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14745",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:56:46.918Z",
      "date_published": "2026-07-05T11:30:08.061Z",
      "date_updated": "2026-07-06T16:50:13.685Z",
      "publisher": "VulDB",
      "title": "code-projects Real State Services single-list_rent.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Real State Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18014
      },
      "nvd": {
        "published": "2026-07-05T12:17:13.007",
        "lastModified": "2026-07-06T18:16:39.883",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14745",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled ID is concatenated into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376331",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376331/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14745",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849265",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/6Justdododo6/CVE/issues/24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14746",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:57:07.957Z",
      "date_published": "2026-07-05T11:45:08.263Z",
      "date_updated": "2026-07-06T13:26:48.896Z",
      "publisher": "VulDB",
      "title": "code-projects Real State Services addprojectrent.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Real State Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18831
      },
      "nvd": {
        "published": "2026-07-05T12:17:13.160",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14746",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Real State Services data path incorporates attacker-controlled values into SQL grammar without parameterization or sufficient escaping.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376332",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376332/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14746",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849284",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/6Justdododo6/CVE/issues/25",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:57:11.133Z",
      "date_published": "2026-07-05T12:00:08.185Z",
      "date_updated": "2026-07-06T13:28:55.517Z",
      "publisher": "VulDB",
      "title": "code-projects Real State Services addprojectsale.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Real State Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18835
      },
      "nvd": {
        "published": "2026-07-05T13:16:55.653",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14747",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "addprojectsale.php incorporates the amen argument into an SQL statement without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376333",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376333/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14747",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849291",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/6Justdododo6/CVE/issues/26",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14748",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T13:05:15.145Z",
      "date_published": "2026-07-05T12:15:08.047Z",
      "date_updated": "2026-07-06T19:02:36.717Z",
      "publisher": "VulDB",
      "title": "AIAnytime Awesome-MCP-Server mcp-wiki/wiki-summary server.py server-side request forgery",
      "affected": {
        "vendors": [
          "AIAnytime"
        ],
        "products": [
          {
            "vendor": "AIAnytime",
            "product": "Awesome-MCP-Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14079
      },
      "nvd": {
        "published": "2026-07-05T13:16:55.810",
        "lastModified": "2026-07-06T19:16:58.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14748",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The url argument is used as an outbound request target without destination validation, allowing the caller to make the server request unintended hosts.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376334",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376334/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14748",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849289",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849300",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/AIAnytime/Awesome-MCP-Server/issues/34",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/AIAnytime/Awesome-MCP-Server/issues/35",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/AIAnytime/Awesome-MCP-Server/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 661,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14749",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T15:41:16.167Z",
      "date_published": "2026-07-05T12:45:07.950Z",
      "date_updated": "2026-07-06T18:44:00.629Z",
      "publisher": "VulDB",
      "title": "mjperpinosa stumasy calculate.php eval code injection",
      "affected": {
        "vendors": [
          "mjperpinosa"
        ],
        "products": [
          {
            "vendor": "mjperpinosa",
            "product": "stumasy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00322,
        "percentile": 0.2463
      },
      "nvd": {
        "published": "2026-07-05T13:16:55.963",
        "lastModified": "2026-07-06T19:16:58.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14749",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "calculate.php passes the mathematical_sentence parameter to eval as executable code.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376338",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376338/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14749",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849414",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mjperpinosa/stumasy/issues/5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mjperpinosa/stumasy/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 634,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14750",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T15:50:19.755Z",
      "date_published": "2026-07-05T13:00:10.692Z",
      "date_updated": "2026-07-07T02:50:24.885Z",
      "publisher": "VulDB",
      "title": "mjperpinosa stumasy accessing_dictionary_authorization.php accessing_dictionary_authorization sql injection",
      "affected": {
        "vendors": [
          "mjperpinosa"
        ],
        "products": [
          {
            "vendor": "mjperpinosa",
            "product": "stumasy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18833
      },
      "nvd": {
        "published": "2026-07-05T14:16:54.673",
        "lastModified": "2026-07-07T04:17:44.590",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14750",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376339",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376339/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14750",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849483",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mjperpinosa/stumasy/issues/6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mjperpinosa/stumasy/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 713,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14751",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T15:50:22.120Z",
      "date_published": "2026-07-05T13:15:08.543Z",
      "date_updated": "2026-07-06T16:50:05.587Z",
      "publisher": "VulDB",
      "title": "mjperpinosa stumasy search_scratch_data.php search_scratch_data sql injection",
      "affected": {
        "vendors": [
          "mjperpinosa"
        ],
        "products": [
          {
            "vendor": "mjperpinosa",
            "product": "stumasy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10586
      },
      "nvd": {
        "published": "2026-07-05T14:16:54.833",
        "lastModified": "2026-07-06T18:16:40.000",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14751",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376340",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376340/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14751",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849494",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mjperpinosa/stumasy/issues/7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mjperpinosa/stumasy/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 687,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14752",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T15:50:24.498Z",
      "date_published": "2026-07-05T13:30:08.679Z",
      "date_updated": "2026-07-06T13:08:48.416Z",
      "publisher": "VulDB",
      "title": "mjperpinosa stumasy add_into_dictionary.php add_definition cross site scripting",
      "affected": {
        "vendors": [
          "mjperpinosa"
        ],
        "products": [
          {
            "vendor": "mjperpinosa",
            "product": "stumasy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10407
      },
      "nvd": {
        "published": "2026-07-05T14:16:54.990",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14752",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376341",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376341/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14752",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849495",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mjperpinosa/stumasy/issues/8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mjperpinosa/stumasy/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 660,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14753",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T15:50:27.016Z",
      "date_published": "2026-07-05T13:45:08.177Z",
      "date_updated": "2026-07-06T13:26:44.191Z",
      "publisher": "VulDB",
      "title": "mjperpinosa stumasy Note Handler/Assignment notes authorization",
      "affected": {
        "vendors": [
          "mjperpinosa"
        ],
        "products": [
          {
            "vendor": "mjperpinosa",
            "product": "stumasy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00309,
        "percentile": 0.23217
      },
      "nvd": {
        "published": "2026-07-05T14:16:55.180",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14753",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "stumasy resolves a caller-controlled object identifier without binding the selected object to the caller's authorized scope.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376342",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376342/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14753",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849496",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mjperpinosa/stumasy/issues/9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mjperpinosa/stumasy/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 630,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T15:56:13.427Z",
      "date_published": "2026-07-05T14:00:08.727Z",
      "date_updated": "2026-07-06T17:43:45.755Z",
      "publisher": "VulDB",
      "title": "code-projects Hotel and Tourism Reservation add_room.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Hotel and Tourism Reservation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18839
      },
      "nvd": {
        "published": "2026-07-05T14:16:55.387",
        "lastModified": "2026-07-06T19:16:58.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14754",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Multiple add_room.php parameters are incorporated into an SQL statement without parameter binding.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376343",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376343/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14754",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850344",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://medium.com/@avdzav10/sql-injection-in-hotel-and-tourism-reservation-system-php-1-0-admin-add-room-php-25149909c16a",
          "host": "medium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T15:56:15.739Z",
      "date_published": "2026-07-05T14:15:07.494Z",
      "date_updated": "2026-07-06T18:45:39.501Z",
      "publisher": "VulDB",
      "title": "code-projects Hotel and Tourism Reservation Reservations Management reservations.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Hotel and Tourism Reservation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18832
      },
      "nvd": {
        "published": "2026-07-05T15:16:56.500",
        "lastModified": "2026-07-06T19:16:59.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14755",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The reservations page incorporates the delete parameter into SQL without preserving the query grammar boundary.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376344",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376344/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14755",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850365",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/anubhavv106/Security-Advisories/refs/heads/main/Hotel-Tourism-Reservation-add_event.php-SQLi.md",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 388,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T15:56:18.347Z",
      "date_published": "2026-07-05T14:30:08.074Z",
      "date_updated": "2026-07-07T02:51:19.151Z",
      "publisher": "VulDB",
      "title": "code-projects Hotel and Tourism Reservation Tour Management add_tour.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Hotel and Tourism Reservation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18832
      },
      "nvd": {
        "published": "2026-07-05T15:16:56.657",
        "lastModified": "2026-07-07T04:17:44.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14756",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The delete_image parameter is incorporated into an add_tour.php database query without safe parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376345",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376345/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14756",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850366",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/anubhavv106/Security-Advisories/refs/heads/main/Hotel-Tourism-Reservation-add_tour.php-SQLi.md",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14757",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T16:19:28.961Z",
      "date_published": "2026-07-05T14:45:07.662Z",
      "date_updated": "2026-07-06T16:49:53.452Z",
      "publisher": "VulDB",
      "title": "radareorg radare2 cmd_anal.inc core_anal_bytes integer overflow",
      "affected": {
        "vendors": [
          "radareorg"
        ],
        "products": [
          {
            "vendor": "radareorg",
            "product": "radare2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-189",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 5.9,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07206
      },
      "nvd": {
        "published": "2026-07-05T15:16:56.810",
        "lastModified": "2026-07-07T22:46:20.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14757",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unchecked integer calculation in radare2 can wrap and produce an invalid memory size or position.",
        "basis": [
          "CNA",
          "CWE-189",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376346",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376346/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "VDB Entry",
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14757",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850381",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/issues/26041",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 8,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-14758",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T16:19:31.432Z",
      "date_published": "2026-07-05T15:00:09.747Z",
      "date_updated": "2026-07-06T13:08:17.966Z",
      "publisher": "VulDB",
      "title": "radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow",
      "affected": {
        "vendors": [
          "radareorg"
        ],
        "products": [
          {
            "vendor": "radareorg",
            "product": "radare2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-189",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05886
      },
      "nvd": {
        "published": "2026-07-05T15:16:56.987",
        "lastModified": "2026-07-09T15:47:17.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14758",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "radare2 arithmetic in the hexpairs parser can wrap an integer used by cmd_anal_opcode.",
        "basis": [
          "CNA",
          "CWE-189",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376347",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376347/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "VDB Entry",
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14758",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850382",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/issues/26042",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/commit/84e773986e7e5bb30453a9384f498ec0ccc9d0a9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 8,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-14759",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T16:19:34.090Z",
      "date_published": "2026-07-05T15:15:08.985Z",
      "date_updated": "2026-07-06T13:20:53.970Z",
      "publisher": "VulDB",
      "title": "radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes_attr_calc_size heap-based overflow",
      "affected": {
        "vendors": [
          "radareorg"
        ],
        "products": [
          {
            "vendor": "radareorg",
            "product": "radare2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 6.1,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08871
      },
      "nvd": {
        "published": "2026-07-05T16:19:44.583",
        "lastModified": "2026-07-09T15:47:27.510",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14759",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In radare2, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376348",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376348/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "VDB Entry",
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14759",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850383",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/issues/26043",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/commit/cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 8,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-14760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T16:19:36.825Z",
      "date_published": "2026-07-05T15:30:08.954Z",
      "date_updated": "2026-07-06T15:40:58.650Z",
      "publisher": "VulDB",
      "title": "radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free",
      "affected": {
        "vendors": [
          "radareorg"
        ],
        "products": [
          {
            "vendor": "radareorg",
            "product": "radare2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 6.1,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06264
      },
      "nvd": {
        "published": "2026-07-05T16:19:44.740",
        "lastModified": "2026-07-09T15:47:37.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14760",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "radare2 retains or reuses an object after its storage has been freed, allowing later processing to access invalid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-119",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376349",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376349/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "VDB Entry",
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14760",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850384",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/issues/26044",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/commit/8b25c773785d85cb0103410a0905089d286921c2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 470,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 8,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-14761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T16:19:39.488Z",
      "date_published": "2026-07-05T15:45:08.421Z",
      "date_updated": "2026-07-06T18:46:20.994Z",
      "publisher": "VulDB",
      "title": "radareorg radare2 str.c r_str_append integer overflow",
      "affected": {
        "vendors": [
          "radareorg"
        ],
        "products": [
          {
            "vendor": "radareorg",
            "product": "radare2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-189",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05887
      },
      "nvd": {
        "published": "2026-07-05T16:19:44.893",
        "lastModified": "2026-07-06T20:03:52.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14761",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer arithmetic in r_str_ndup or r_str_append can wrap and produce an invalid size for subsequent string memory operations.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-189",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376350",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376350/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "VDB Entry",
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14761",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850385",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/issues/26045",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/commit/a20a56917ae85d732e683f8d9078bdcfee92446c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 8,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-14762",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T16:28:12.308Z",
      "date_published": "2026-07-05T16:00:07.947Z",
      "date_updated": "2026-07-07T02:52:16.860Z",
      "publisher": "VulDB",
      "title": "code-projects Hotel and Tourism Reservation Room Management rooms.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Hotel and Tourism Reservation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00325,
        "percentile": 0.24943
      },
      "nvd": {
        "published": "2026-07-05T16:19:45.043",
        "lastModified": "2026-07-07T04:17:44.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14762",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Hotel and Tourism Reservation incorporates delete into an SQL statement without parameterization, allowing input syntax to alter the database query.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376351",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376351/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14762",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850580",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/anubhavv106/Security-Advisories/refs/heads/main/Hotel-Tourism-Reservation-rooms.php-SQLi.md",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T16:28:14.567Z",
      "date_published": "2026-07-05T16:15:06.752Z",
      "date_updated": "2026-07-06T16:49:44.819Z",
      "publisher": "VulDB",
      "title": "code-projects Hotel and Tourism Reservation Tour Reservations tour_reserves.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Hotel and Tourism Reservation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18832
      },
      "nvd": {
        "published": "2026-07-05T17:17:27.463",
        "lastModified": "2026-07-06T18:16:40.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14763",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "tour_reserves.php incorporates the tour argument into an SQL statement without required SQL-context neutralization.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376352",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376352/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14763",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850581",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/anubhavv106/Security-Advisories/refs/heads/main/Hotel-Tourism-Reservation-tour_reserves.php-SQLi.md",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T16:28:17.401Z",
      "date_published": "2026-07-05T16:30:07.987Z",
      "date_updated": "2026-07-06T13:07:44.659Z",
      "publisher": "VulDB",
      "title": "code-projects Hotel and Tourism Reservation Event Management add_event.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Hotel and Tourism Reservation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18838
      },
      "nvd": {
        "published": "2026-07-05T17:17:27.667",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14764",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "add_event.php incorporates fdetails into an SQL statement without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376353",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376353/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14764",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850582",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/anubhavv106/Security-Advisories/refs/heads/main/Hotel-Tourism-Reservation-add_event.php_SQLi.md",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 354,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14766",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T03:56:36.631Z",
      "date_published": "2026-07-05T18:30:07.923Z",
      "date_updated": "2026-07-06T13:16:35.754Z",
      "publisher": "VulDB",
      "title": "CodeAstro Apartment Visitor Management System POST Parameter search-result.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Apartment Visitor Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10584
      },
      "nvd": {
        "published": "2026-07-05T19:16:28.563",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14766",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The visitor search page incorporates attacker-controlled input into an SQL statement without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376356",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376356/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14766",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850616",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/menelausx/29aef0a0ab6f289c0f45b379f6d759d7",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 395,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T03:57:33.939Z",
      "date_published": "2026-07-05T19:45:07.150Z",
      "date_updated": "2026-07-06T15:19:18.224Z",
      "publisher": "VulDB",
      "title": "CodeAstro Ecommerce Website POST Parameter confirm.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Ecommerce Website"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10584
      },
      "nvd": {
        "published": "2026-07-05T20:16:31.293",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14767",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The manipulation of the argument invoice_no results in sql injection.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376357",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376357/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14767",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850623",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/menelausx/2222914494e28e7d70f9a35af8fae824",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T03:59:17.519Z",
      "date_published": "2026-07-05T20:00:17.874Z",
      "date_updated": "2026-07-06T15:15:10.478Z",
      "publisher": "VulDB",
      "title": "code-projects Real State Services builderHome.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Real State Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18833
      },
      "nvd": {
        "published": "2026-07-05T20:16:31.457",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14768",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The loc request value reaches builderHome.php as SQL syntax instead of a bound value.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376358",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376358/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14768",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849302",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/6Justdododo6/CVE/issues/27",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 334,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T03:59:20.312Z",
      "date_published": "2026-07-05T20:15:07.816Z",
      "date_updated": "2026-07-07T02:52:58.407Z",
      "publisher": "VulDB",
      "title": "code-projects Real State Services pay.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Real State Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18837
      },
      "nvd": {
        "published": "2026-07-05T21:16:54.153",
        "lastModified": "2026-07-07T04:17:45.107",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14769",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376359",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376359/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14769",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849374",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/6Justdododo6/CVE/issues/28",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 314,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T04:01:30.413Z",
      "date_published": "2026-07-05T21:00:09.712Z",
      "date_updated": "2026-07-06T16:49:36.018Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_room.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20629
      },
      "nvd": {
        "published": "2026-07-05T21:16:54.310",
        "lastModified": "2026-07-06T18:16:40.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14770",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376360",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376360/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14770",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849106",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/orionyan520/cve_report/issues/3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 307,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T04:01:33.090Z",
      "date_published": "2026-07-05T21:30:09.068Z",
      "date_updated": "2026-07-06T13:03:35.795Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_exam1.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20629
      },
      "nvd": {
        "published": "2026-07-05T22:16:52.897",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14771",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376361",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376361/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14771",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849107",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/orionyan520/cve_report/issues/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14772",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T04:01:35.626Z",
      "date_published": "2026-07-05T22:00:09.168Z",
      "date_updated": "2026-07-06T13:16:00.262Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_course1.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20628
      },
      "nvd": {
        "published": "2026-07-05T22:16:53.063",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14772",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a Class and Exam Timetabling System database query without safe parameter binding, allowing query syntax injection.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376362",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376362/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14772",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849108",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/orionyan520/cve_report/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14773",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T04:03:50.118Z",
      "date_published": "2026-07-05T22:15:10.143Z",
      "date_updated": "2026-07-06T15:16:07.186Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System payment.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10588
      },
      "nvd": {
        "published": "2026-07-05T23:16:52.990",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14773",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The payment.php patientid parameter is incorporated into an SQL statement without separating data from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376363",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376363/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14773",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850644",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/submit_vuln/issues/5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 290,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14774",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T04:03:52.635Z",
      "date_published": "2026-07-05T22:30:09.884Z",
      "date_updated": "2026-07-06T15:14:15.468Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System paymentdischarge.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10586
      },
      "nvd": {
        "published": "2026-07-05T23:16:53.140",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14774",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376364",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376364/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14774",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850645",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/submit_vuln/issues/6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14775",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T04:08:13.179Z",
      "date_published": "2026-07-05T22:45:09.190Z",
      "date_updated": "2026-07-07T02:54:51.798Z",
      "publisher": "VulDB",
      "title": "SourceCodester Onlne Examination & Learning Management System process_lesson.php unrestricted upload",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Onlne Examination & Learning Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11813
      },
      "nvd": {
        "published": "2026-07-05T23:16:53.290",
        "lastModified": "2026-07-07T04:17:45.370",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14775",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "process_lesson.php accepts an uploaded file without restricting it to a safe file type.",
        "basis": [
          "CNA record",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376365",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376365/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14775",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850677",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nuiifornet/A033/blob/main/OE-LMS-RCE-1-process_lesson.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14776",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T04:08:15.541Z",
      "date_published": "2026-07-05T23:00:11.544Z",
      "date_updated": "2026-07-06T16:49:27.412Z",
      "publisher": "VulDB",
      "title": "SourceCodester Onlne Examination & Learning Management System Filename Extension upload_files.php pathinfo unrestricted upload",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Onlne Examination & Learning Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11811
      },
      "nvd": {
        "published": "2026-07-05T23:16:53.440",
        "lastModified": "2026-07-06T18:16:40.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14776",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Onlne Examination & Learning Management System stores an uploaded dangerous file without restricting its type and executable destination.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376366",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376366/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14776",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850678",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nuiifornet/A033/blob/main/OE-LMS-RCE-2-upload_files.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 469,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14777",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T04:08:18.319Z",
      "date_published": "2026-07-05T23:15:11.813Z",
      "date_updated": "2026-07-06T13:06:24.795Z",
      "publisher": "VulDB",
      "title": "SourceCodester Onlne Examination & Learning Management System announcements.php unrestricted upload",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Onlne Examination & Learning Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11814
      },
      "nvd": {
        "published": "2026-07-06T00:16:54.713",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14777",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The announcements handler accepts an unrestricted file upload into a web-reachable location.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376367",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376367/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14777",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850679",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nuiifornet/A033/blob/main/OE-LMS-RCE-3-announcements.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14778",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T04:08:21.195Z",
      "date_published": "2026-07-05T23:30:09.071Z",
      "date_updated": "2026-07-06T13:15:27.861Z",
      "publisher": "VulDB",
      "title": "SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Onlne Examination & Learning Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21662
      },
      "nvd": {
        "published": "2026-07-06T00:16:54.880",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14778",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The enrollment handler accepts attacker-selected student, schedule, and action values outside the caller's authority, while the record does not identify the missing role or ownership check.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376368",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376368/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14778",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850695",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nuiifornet/A033/blob/main/OE-LMS-IDOR-ajax_enroll.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 477,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14781",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T06:32:45.726Z",
      "date_published": "2026-07-05T06:55:30.225Z",
      "date_updated": "2026-07-06T14:12:11.151Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: oidc email_verified claim incorrectly applied to userinfo email",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1288",
          "name": "Improper Validation of Consistency within Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08674
      },
      "nvd": {
        "published": "2026-07-05T07:16:39.820",
        "lastModified": "2026-07-06T18:41:14.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14781",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The broker combines an email address from one OIDC response with a verification claim for a different address without checking their consistency.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-1288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14781",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497118",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1166,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-14782",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T09:47:30.034Z",
      "date_published": "2026-07-16T21:30:29.207Z",
      "date_updated": "2026-07-17T13:58:09.144Z",
      "publisher": "Wordfence",
      "title": "Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import",
      "affected": {
        "vendors": [
          "melograno"
        ],
        "products": [
          {
            "vendor": "melograno",
            "product": "Booking for Appointments and Events Calendar – Amelia"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15143
      },
      "nvd": {
        "published": "2026-07-16T22:16:59.753",
        "lastModified": "2026-07-17T14:59:38.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14782",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Customer-import data reaches an SQL query without sufficient escaping or parameter preparation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b3a58e68-d1f1-4d4f-ac64-bc6cb7dbdbfc?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ameliabooking/tags/2.4.3/src/Infrastructure/Repository/User/UserRepository.php#L476",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14783",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T14:00:38.992Z",
      "date_published": "2026-07-05T23:45:10.833Z",
      "date_updated": "2026-07-06T17:39:58.056Z",
      "publisher": "VulDB",
      "title": "NousResearch hermes-agent skills_tool.py skill_view path traversal",
      "affected": {
        "vendors": [
          "NousResearch"
        ],
        "products": [
          {
            "vendor": "NousResearch",
            "product": "hermes-agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25878
      },
      "nvd": {
        "published": "2026-07-06T00:16:55.037",
        "lastModified": "2026-07-06T19:16:59.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14783",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The hermes-agent path accepts an attacker-controlled path that can escape the intended filesystem root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376373",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376373/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14783",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847502",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/issues/38643",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/pull/40566",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/commit/56f833efa427ccb444c0f9ad1759af1012f2124d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14784",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T14:50:20.884Z",
      "date_published": "2026-07-06T00:00:11.832Z",
      "date_updated": "2026-07-06T13:29:33.137Z",
      "publisher": "VulDB",
      "title": "vxcontrol PentAGI Docker API client.go sandbox",
      "affected": {
        "vendors": [
          "vxcontrol"
        ],
        "products": [
          {
            "vendor": "vxcontrol",
            "product": "PentAGI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-264",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-265",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00228,
        "percentile": 0.1371
      },
      "nvd": {
        "published": "2026-07-06T01:16:54.757",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14784",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says only that a sandbox issue exists and does not reveal the bypassed boundary or causal check.",
        "basis": [
          "CNA",
          "CWE-264",
          "CWE-265"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376374",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376374/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14784",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849298",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/vxcontrol/pentagi/issues/337",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/vxcontrol/pentagi/pull/355",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/vxcontrol/pentagi/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 300,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14785",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T15:07:35.899Z",
      "date_published": "2026-07-28T09:30:17.667Z",
      "date_updated": "2026-07-28T19:16:29.280Z",
      "publisher": "Wordfence",
      "title": "Web Directory Free <= 1.7.13 - Unauthenticated SQL Injection",
      "affected": {
        "vendors": [
          "mihail-chepovskiy"
        ],
        "products": [
          {
            "vendor": "mihail-chepovskiy",
            "product": "Web Directory Free"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22755
      },
      "nvd": {
        "published": "2026-07-28T10:16:48.153",
        "lastModified": "2026-07-28T20:17:22.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14785",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Web Directory Free data path incorporates attacker-controlled values into SQL grammar without parameterization or sufficient escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7320421b-6b88-452d-a363-a71cdf7953a6?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/web-directory-free/tags/1.7.13/classes/frontend_controller.php#L307",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/web-directory-free/tags/1.7.13/classes/ajax_controller.php#L38",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/web-directory-free/tags/1.7.13/classes/frontend_controller.php#L51",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 461,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14786",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T16:03:14.292Z",
      "date_published": "2026-07-06T01:00:10.542Z",
      "date_updated": "2026-07-07T02:55:39.743Z",
      "publisher": "VulDB",
      "title": "radareorg radare2 str.c r_str_word_get0set integer overflow",
      "affected": {
        "vendors": [
          "radareorg"
        ],
        "products": [
          {
            "vendor": "radareorg",
            "product": "radare2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-189",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05581
      },
      "nvd": {
        "published": "2026-07-06T01:16:54.913",
        "lastModified": "2026-07-07T04:17:45.510",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14786",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "r_str_word_get0set performs integer arithmetic that can overflow before the resulting value is used.",
        "basis": [
          "CNA",
          "CWE-189",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376375",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376375/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "VDB Entry",
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14786",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850386",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/issues/26047",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/commit/11ac224c0eb8d57830fccc99e1c1cd8e5d958813",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 8,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-14787",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T16:03:16.568Z",
      "date_published": "2026-07-06T01:30:09.280Z",
      "date_updated": "2026-07-06T16:49:15.165Z",
      "publisher": "VulDB",
      "title": "radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow",
      "affected": {
        "vendors": [
          "radareorg"
        ],
        "products": [
          {
            "vendor": "radareorg",
            "product": "radare2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-189",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 6.1,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06384
      },
      "nvd": {
        "published": "2026-07-06T02:16:21.360",
        "lastModified": "2026-07-09T15:25:14.967",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14787",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in radare2, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-189",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376376",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376376/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "VDB Entry",
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14787",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850387",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/issues/26048",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/phix33/radare2/commit/2b6265476c75567006b0fcbb749f4ae7b189c5df",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 454,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 8,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-14788",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T16:03:19.139Z",
      "date_published": "2026-07-06T01:45:08.467Z",
      "date_updated": "2026-07-06T13:05:50.219Z",
      "publisher": "VulDB",
      "title": "radareorg radare2 cfile.c r_core_bin_load use after free",
      "affected": {
        "vendors": [
          "radareorg"
        ],
        "products": [
          {
            "vendor": "radareorg",
            "product": "radare2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 6.1,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06264
      },
      "nvd": {
        "published": "2026-07-06T02:16:21.527",
        "lastModified": "2026-07-09T15:18:53.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14788",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "radare2 r_core_bin_load retains and accesses an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376377",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376377/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "VDB Entry",
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14788",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850388",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/issues/26049",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/oldzhu/radare2/commit/635ab1eeb30340c26076722a90cb91fb2272130b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 8,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-14789",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T16:03:21.582Z",
      "date_published": "2026-07-06T02:00:10.294Z",
      "date_updated": "2026-07-06T12:59:10.100Z",
      "publisher": "VulDB",
      "title": "radareorg radare2 Memory64ListStream mdmp.c stack-based overflow",
      "affected": {
        "vendors": [
          "radareorg"
        ],
        "products": [
          {
            "vendor": "radareorg",
            "product": "radare2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 6.1,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08871
      },
      "nvd": {
        "published": "2026-07-06T03:16:29.220",
        "lastModified": "2026-07-09T15:09:39.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14789",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler copies attacker-controlled data beyond a fixed-size stack buffer.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376378",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376378/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "VDB Entry",
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14789",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850389",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/issues/26051",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mengzhisuoliu/radare2/commit/175d4addb68981331c85b10681c2161c38fb5762",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/radareorg/radare2/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 465,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 8,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-14790",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T16:07:15.466Z",
      "date_published": "2026-07-06T02:15:09.433Z",
      "date_updated": "2026-07-06T15:20:48.022Z",
      "publisher": "VulDB",
      "title": "GPAC Media File write_nhml.c nhmldump_send_frame null pointer dereference",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "GPAC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01788
      },
      "nvd": {
        "published": "2026-07-06T03:16:29.427",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14790",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GPAC dereferences a null pointer on an attacker-reachable processing path.",
        "basis": [
          "CNA",
          "CWE-404",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376379",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376379/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14790",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850391",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/issues/3596",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14791",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T18:16:17.170Z",
      "date_published": "2026-07-06T02:30:11.384Z",
      "date_updated": "2026-07-06T13:28:29.426Z",
      "publisher": "VulDB",
      "title": "crater-invoice-inc crater Invoice Note InvoicesRequest.php getFormattedString cross site scripting",
      "affected": {
        "vendors": [
          "crater-invoice-inc"
        ],
        "products": [
          {
            "vendor": "crater-invoice-inc",
            "product": "crater"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10407
      },
      "nvd": {
        "published": "2026-07-06T03:16:29.613",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14791",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376385",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376385/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14791",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850787",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/crater-invoice-inc/crater/issues/1327",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/crater-invoice-inc/crater/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 502,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-14792",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T18:21:20.337Z",
      "date_published": "2026-07-06T03:00:11.234Z",
      "date_updated": "2026-07-07T02:59:38.314Z",
      "publisher": "VulDB",
      "title": "Formbricks Survey actions.ts access control",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "Formbricks"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P/E:ND/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29324
      },
      "nvd": {
        "published": "2026-07-06T05:16:34.283",
        "lastModified": "2026-07-07T04:17:47.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14792",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Formbricks lets a lower-privileged caller exercise a higher-privileged operation because privilege assignment or enforcement is incomplete.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376386",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376386/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14792",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850791",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/formbricks/formbricks/pull/8094",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/formbricks/formbricks/commit/af6023b5ac3b030ffcea24fac799f76f3e3512c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/formbricks/formbricks/releases/tag/5.1.0-rc.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/formbricks/formbricks/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T18:26:20.325Z",
      "date_published": "2026-07-06T03:30:10.238Z",
      "date_updated": "2026-07-06T16:49:07.984Z",
      "publisher": "VulDB",
      "title": "Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets authorization",
      "affected": {
        "vendors": [
          "Craft"
        ],
        "products": [
          {
            "vendor": "Craft",
            "product": "CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13126
      },
      "nvd": {
        "published": "2026-07-06T05:16:34.603",
        "lastModified": "2026-07-06T18:16:40.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14793",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The reorder-sets action accepts an object operation without correctly binding it to the caller's authorized scope.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376387",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376387/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14793",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850792",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/commit/9bd05c91e6a7e6da5e949ec41a31c220c059aa04",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/releases/tag/4.18.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 448,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14794",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T18:29:29.737Z",
      "date_published": "2026-07-06T03:45:09.182Z",
      "date_updated": "2026-07-06T13:05:23.079Z",
      "publisher": "VulDB",
      "title": "Craft CMS Charts Endpoint ChartsController.php actionGetNewUsersData improper authorization",
      "affected": {
        "vendors": [
          "Craft"
        ],
        "products": [
          {
            "vendor": "Craft",
            "product": "CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12842
      },
      "nvd": {
        "published": "2026-07-06T05:16:34.817",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14794",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The chart endpoint accepts a userGroupId whose data scope is not constrained to groups the caller is authorized to inspect.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376388",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376388/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14794",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850793",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/commit/9ee53efc1314e6aba32771c66a13e072a246f4ce",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/releases/tag/4.18.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 485,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14795",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T18:32:27.304Z",
      "date_published": "2026-07-06T04:00:08.777Z",
      "date_updated": "2026-07-06T12:58:35.898Z",
      "publisher": "VulDB",
      "title": "CodeAstro Apartment Visitor Management System action-visitor.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Apartment Visitor Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10068
      },
      "nvd": {
        "published": "2026-07-06T05:16:35.010",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14795",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The remark parameter is incorporated into an action-visitor.php SQL statement without safe parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376389",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376389/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14795",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850848",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lilukun337/cve/issues/6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 356,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14796",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T18:32:29.507Z",
      "date_published": "2026-07-06T04:15:07.585Z",
      "date_updated": "2026-07-06T15:22:08.769Z",
      "publisher": "VulDB",
      "title": "CodeAstro Apartment Visitor Management System report.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Apartment Visitor Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10587
      },
      "nvd": {
        "published": "2026-07-06T05:16:35.223",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14796",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Apartment Visitor Management System query path incorporates attacker-controlled input into SQL without parameter separation.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376390",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376390/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14796",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850849",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lilukun337/cve/issues/7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14797",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T18:32:32.130Z",
      "date_published": "2026-07-06T04:45:08.230Z",
      "date_updated": "2026-07-06T10:46:24.850Z",
      "publisher": "VulDB",
      "title": "CodeAstro Apartment Visitor Management System edit-apartment.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Apartment Visitor Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10063
      },
      "nvd": {
        "published": "2026-07-06T06:16:27.153",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14797",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The editid parameter in edit-apartment.php is incorporated into SQL without parameterization.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376391",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376391/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14797",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850851",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lilukun337/cve/issues/9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14798",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T18:32:34.724Z",
      "date_published": "2026-07-06T05:00:08.606Z",
      "date_updated": "2026-07-07T13:59:14.860Z",
      "publisher": "VulDB",
      "title": "CodeAstro Apartment Visitor Management System visitor-entry.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Apartment Visitor Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10069
      },
      "nvd": {
        "published": "2026-07-06T06:16:27.513",
        "lastModified": "2026-07-07T15:16:43.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14798",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Apartment Visitor Management System, attacker-controlled values reach an SQL statement without the required escaping or parameter binding.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376392",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376392/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14798",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850852",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lilukun337/cve/issues/10",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 333,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T18:35:18.514Z",
      "date_published": "2026-07-06T05:45:06.048Z",
      "date_updated": "2026-07-06T16:48:57.418Z",
      "publisher": "VulDB",
      "title": "CodeAstro Ecommerce Website my_account.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Ecommerce Website"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10588
      },
      "nvd": {
        "published": "2026-07-06T06:16:27.710",
        "lastModified": "2026-07-06T18:16:41.000",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14799",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ecommerce Website incorporates attacker-controlled values or identifiers into a SQL statement without preserving the boundary between query syntax and data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376393",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376393/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14799",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850850",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lilukun337/cve/issues/8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T18:36:52.340Z",
      "date_published": "2026-07-06T06:00:08.783Z",
      "date_updated": "2026-07-06T13:04:16.385Z",
      "publisher": "VulDB",
      "title": "imhamzaazam ecommerceFlask cross-site request forgery",
      "affected": {
        "vendors": [
          "imhamzaazam"
        ],
        "products": [
          {
            "vendor": "imhamzaazam",
            "product": "ecommerceFlask"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05487
      },
      "nvd": {
        "published": "2026-07-06T08:16:35.460",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14800",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ecommerceFlask accepts an undisclosed cross-site state-changing request, while the affected action and missing request-binding check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-352",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376394",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376394/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14800",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850853",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/imhamzaazam/ecommerceFlask/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/imhamzaazam/ecommerceFlask/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 588,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T19:08:37.569Z",
      "date_published": "2026-07-06T06:15:07.752Z",
      "date_updated": "2026-07-06T12:52:53.879Z",
      "publisher": "VulDB",
      "title": "GPAC TeXML File load_text.c txtin_probe_duration divide by zero",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "GPAC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-369",
          "name": "Divide By Zero",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01609
      },
      "nvd": {
        "published": "2026-07-06T08:16:35.733",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14801",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GPAC fails to release a resource on an error or termination path, allowing repeated requests to exhaust it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-369",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376395",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376395/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14801",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850854",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/issues/3610",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T19:11:13.568Z",
      "date_published": "2026-07-06T06:30:08.952Z",
      "date_updated": "2026-07-06T15:17:49.174Z",
      "publisher": "VulDB",
      "title": "react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection",
      "affected": {
        "vendors": [
          "react"
        ],
        "products": [
          {
            "vendor": "react",
            "product": "create-react-app"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.01324,
        "percentile": 0.68116
      },
      "nvd": {
        "published": "2026-07-06T08:16:35.913",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14802",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "startBrowserProcess builds an operating-system command from attacker-influenced browser configuration without neutralizing shell syntax.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376396",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376396/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-14802",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850857",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/react/create-react-app/issues/17269",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/react/create-react-app/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 429,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14803",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:23:29.979Z",
      "date_published": "2026-07-06T01:34:43.872Z",
      "date_updated": "2026-07-06T18:51:14.358Z",
      "publisher": "CPANSec",
      "title": "Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder",
      "affected": {
        "vendors": [
          "SRI"
        ],
        "products": [
          {
            "vendor": "SRI",
            "product": "Mojo::JSON"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25618
      },
      "nvd": {
        "published": "2026-07-06T02:16:21.683",
        "lastModified": "2026-07-06T19:16:59.597",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14803",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The pure-Perl JSON decoder recursively descends nested arrays and objects without a depth limit.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mojolicious/mojo/commit/cc38b0554275c4d84f6b8b49bcbbc1bec2068fe1.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/release/SRI/Mojolicious-9.47/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/06/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 626,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T06:26:56.497Z",
      "date_published": "2026-07-06T07:09:51.844Z",
      "date_updated": "2026-07-06T15:53:24.029Z",
      "publisher": "twcert",
      "title": "PROG MIS｜ERP App - Use of Hard-coded Credentials",
      "affected": {
        "vendors": [
          "PROG MIS"
        ],
        "products": [
          {
            "vendor": "PROG MIS",
            "product": "ERP App"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35523
      },
      "nvd": {
        "published": "2026-07-06T08:16:36.070",
        "lastModified": "2026-07-06T18:41:46.210",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14807",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ERP App ships hard-coded login credentials that expose application source and database account details to anyone who knows the embedded values.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.twcert.org.tw/tw/cp-132-11023-3abe8-1.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.twcert.org.tw/en/cp-139-11024-c5c1a-2.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14808",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T06:26:57.980Z",
      "date_published": "2026-07-06T07:18:21.206Z",
      "date_updated": "2026-07-06T18:47:01.794Z",
      "publisher": "twcert",
      "title": "PROG MIS｜Prog Management System - Exposure of Sensitive Information",
      "affected": {
        "vendors": [
          "PROG MIS"
        ],
        "products": [
          {
            "vendor": "PROG MIS",
            "product": "Prog Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00472,
        "percentile": 0.38379
      },
      "nvd": {
        "published": "2026-07-06T08:16:36.213",
        "lastModified": "2026-07-06T19:16:59.770",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14808",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated page returns the database account and password, while the public advisory does not identify the page or code path that exposes them.",
        "basis": [
          "CNA",
          "CWE-497",
          "TWCERT TVN-202607002"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.twcert.org.tw/en/cp-139-11026-3df18-2.html; the official note confirms an unauthenticated page exposes database credentials and provides no endpoint, patch, or failing check."
      },
      "references": [
        {
          "url": "https://www.twcert.org.tw/tw/cp-132-11025-fa1d9-1.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.twcert.org.tw/en/cp-139-11026-3df18-2.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14809",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T06:26:59.384Z",
      "date_published": "2026-07-06T07:21:46.559Z",
      "date_updated": "2026-07-06T18:47:22.515Z",
      "publisher": "twcert",
      "title": "PROG MIS｜Prog Management System - SQL Injection",
      "affected": {
        "vendors": [
          "PROG MIS"
        ],
        "products": [
          {
            "vendor": "PROG MIS",
            "product": "Prog Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34488
      },
      "nvd": {
        "published": "2026-07-06T09:16:34.167",
        "lastModified": "2026-07-06T19:16:59.900",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14809",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.twcert.org.tw/tw/cp-132-11025-fa1d9-1.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.twcert.org.tw/en/cp-139-11026-3df18-2.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14819",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T08:27:13.045Z",
      "date_published": "2026-07-28T06:00:01.507Z",
      "date_updated": "2026-07-28T13:25:36.853Z",
      "publisher": "WPScan",
      "title": "Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Event Tickets and Registration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04004
      },
      "nvd": {
        "published": "2026-07-28T07:16:41.207",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14819",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/678a362f-b71d-4308-8fc3-f3bf3e6c3ca9/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14820",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T08:27:15.311Z",
      "date_published": "2026-07-27T06:00:05.866Z",
      "date_updated": "2026-07-27T17:37:40.405Z",
      "publisher": "WPScan",
      "title": "Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Quiz and Survey Master (QSM)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.131
      },
      "nvd": {
        "published": "2026-07-27T07:16:26.083",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14820",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The credential-check response distinguishes valid accounts and has no effective rate limit or failed-login audit, enabling enumeration and repeated password guesses.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/22af8c73-8147-4205-8285-a35881f2d041/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T08:27:18.113Z",
      "date_published": "2026-07-28T06:00:01.689Z",
      "date_updated": "2026-07-28T13:22:10.693Z",
      "publisher": "WPScan",
      "title": "Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Quiz and Survey Master (QSM)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.0648
      },
      "nvd": {
        "published": "2026-07-28T07:16:41.310",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14821",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/a53df549-5af1-4a0b-9f0f-a8c7893c82b6/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14827",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T08:51:22.216Z",
      "date_published": "2026-07-27T06:00:06.038Z",
      "date_updated": "2026-07-27T17:39:03.012Z",
      "publisher": "WPScan",
      "title": "Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Calendar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14612
      },
      "nvd": {
        "published": "2026-07-27T07:16:26.180",
        "lastModified": "2026-07-27T20:33:01.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14827",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Calendar page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/b2981b41-b712-43d9-a327-3a376346cec5/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 300,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14830",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T09:17:17.784Z",
      "date_published": "2026-07-31T06:00:06.450Z",
      "date_updated": "2026-07-31T13:33:11.686Z",
      "publisher": "WPScan",
      "title": "FlxWoo < 3.1.1 - Unauthenticated Payment Bypass",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "FlxWoo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11099
      },
      "nvd": {
        "published": "2026-07-31T07:16:25.097",
        "lastModified": "2026-07-31T14:16:46.133",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14830",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The checkout workflow marks an order paid before obtaining confirmation from the payment processor that the session was paid.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/b866258c-b49b-40db-a0ff-6c0921b5c89f/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14833",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T09:51:49.570Z",
      "date_published": "2026-07-31T06:00:06.879Z",
      "date_updated": "2026-07-31T13:29:02.531Z",
      "publisher": "WPScan",
      "title": "Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption Attribute",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Lightbox with PhotoSwipe"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14613
      },
      "nvd": {
        "published": "2026-07-31T07:16:25.207",
        "lastModified": "2026-07-31T14:16:46.297",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14833",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Stored input is rendered without the browser-context separation required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/aae59cb8-b259-464e-a86b-164d89f61342/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 350,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14834",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T09:51:50.855Z",
      "date_published": "2026-07-31T06:00:07.054Z",
      "date_updated": "2026-07-31T19:36:12.035Z",
      "publisher": "WPScan",
      "title": "Mailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Mailgun for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06075
      },
      "nvd": {
        "published": "2026-07-31T07:16:25.310",
        "lastModified": "2026-07-31T20:16:46.710",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14834",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated AJAX action invokes the owner's stored Mailgun credentials to add arbitrary addresses without a nonce or capability check.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/84135fff-e602-4773-8e79-a831284de0d2/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14837",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T09:59:37.390Z",
      "date_published": "2026-07-27T07:03:27.889Z",
      "date_updated": "2026-07-27T14:01:50.573Z",
      "publisher": "CERTVDE",
      "title": "SSH Enablement Signature Verification Bypass",
      "affected": {
        "vendors": [
          "Lenze"
        ],
        "products": [
          {
            "vendor": "Lenze",
            "product": "c430"
          },
          {
            "vendor": "Lenze",
            "product": "c520"
          },
          {
            "vendor": "Lenze",
            "product": "c550"
          },
          {
            "vendor": "Lenze",
            "product": "i950 GenA"
          },
          {
            "vendor": "Lenze",
            "product": "i950 GenB"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00082,
        "percentile": 0.00275
      },
      "nvd": {
        "published": "2026-07-27T08:16:17.463",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14837",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "c430 accepts signed data without correctly verifying the signature against the trusted key and message.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-077/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 352,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-14843",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T11:24:37.981Z",
      "date_published": "2026-07-31T06:00:07.231Z",
      "date_updated": "2026-07-31T13:27:45.469Z",
      "publisher": "WPScan",
      "title": "Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Events Made Easy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.07958
      },
      "nvd": {
        "published": "2026-07-31T07:16:25.420",
        "lastModified": "2026-07-31T14:16:46.470",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14843",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The endpoint accepts a public nonce and a caller-selected person identifier without checking ownership, allowing any record to be overwritten.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/0b445129-19e2-4240-a79a-d3190161d369/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14845",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T11:34:05.550Z",
      "date_published": "2026-07-31T06:00:07.409Z",
      "date_updated": "2026-07-31T19:38:14.518Z",
      "publisher": "WPScan",
      "title": "NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "NewStatPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05861
      },
      "nvd": {
        "published": "2026-07-31T07:16:25.530",
        "lastModified": "2026-07-31T20:16:46.860",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14845",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In NewStatPress, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/da5936d2-a96f-4ff8-8562-1248734f577f/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14846",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T11:34:32.061Z",
      "date_published": "2026-07-13T09:31:42.573Z",
      "date_updated": "2026-07-13T14:12:40.463Z",
      "publisher": "INCIBE",
      "title": "Incorrect neutralisation in the PrestaShop firmware",
      "affected": {
        "vendors": [
          "PrestaShop"
        ],
        "products": [
          {
            "vendor": "PrestaShop",
            "product": "The firmware"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1236",
          "name": "Improper Neutralization of Formula Elements in a CSV File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:H"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16505
      },
      "nvd": {
        "published": "2026-07-13T10:16:26.383",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14846",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An exported CSV cell retains attacker-controlled formula syntax, so a spreadsheet interprets the value as an expression.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-1236"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/incorrect-neutralisation-prestashop-firmware",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 467,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14847",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T11:38:57.439Z",
      "date_published": "2026-07-31T06:00:07.585Z",
      "date_updated": "2026-07-31T13:26:50.377Z",
      "publisher": "WPScan",
      "title": "Paid Member Subscriptions < 3.0.7 - Subscriber+ Payment Data Disclosure via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Paid Membership Subscriptions"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05825
      },
      "nvd": {
        "published": "2026-07-31T07:16:25.640",
        "lastModified": "2026-07-31T14:16:46.643",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14847",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A payment AJAX action accepts an enumerable payment identifier without a capability, nonce, or ownership check and returns another member's payment details.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/5cd6d414-8d7d-4627-9649-af092a1afb75/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14849",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T11:39:00.960Z",
      "date_published": "2026-07-31T06:00:07.762Z",
      "date_updated": "2026-07-31T13:25:56.328Z",
      "publisher": "WPScan",
      "title": "Paid Member Subscriptions < 3.0.7 - Unauthenticated Sensitive Information Exposure via Residual Export Files",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Paid Membership Subscriptions"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-552",
          "name": "Files or Directories Accessible to External Parties",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07517
      },
      "nvd": {
        "published": "2026-07-31T07:16:25.750",
        "lastModified": "2026-07-31T14:16:46.820",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14849",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Paid Membership Subscriptions export path writes sensitive data to a predictable web-accessible location without access enforcement.",
        "basis": [
          "CNA",
          "CWE-552"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/306a498d-0740-479b-b182-71fc3d7452bb/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 312,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14852",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T11:50:44.392Z",
      "date_published": "2026-07-14T09:26:28.525Z",
      "date_updated": "2026-07-29T19:26:45.645Z",
      "publisher": "Checkmk",
      "title": "mk_sap_hana: Privilege escalation via crafted sapstartsrv process name",
      "affected": {
        "vendors": [
          "Checkmk GmbH"
        ],
        "products": [
          {
            "vendor": "Checkmk GmbH",
            "product": "Checkmk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@checkmk.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12805
      },
      "nvd": {
        "published": "2026-07-14T10:16:31.117",
        "lastModified": "2026-07-29T20:17:01.563",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14852",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled process name is incorporated into a command that executes with elevated authority.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://checkmk.com/werk/20104",
          "host": "checkmk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 505,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-14856",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T12:26:14.050Z",
      "date_published": "2026-07-27T10:15:20.251Z",
      "date_updated": "2026-07-27T14:53:46.484Z",
      "publisher": "INCIBE",
      "title": "Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager",
      "affected": {
        "vendors": [
          "Media Manager"
        ],
        "products": [
          {
            "vendor": "Media Manager",
            "product": "TastyIgniter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13933
      },
      "nvd": {
        "published": "2026-07-27T12:16:42.880",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14856",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The TastyIgniter rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xss-tastyigniter-media-manager",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 642,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14862",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T12:39:48.616Z",
      "date_published": "2026-07-31T06:00:12.039Z",
      "date_updated": "2026-07-31T16:41:08.252Z",
      "publisher": "WPScan",
      "title": "Support Genix Lite < 1.4.48 - Unauthenticated Ticket Attachment Download via Missing Authorization",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Support Genix"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06285
      },
      "nvd": {
        "published": "2026-07-31T07:16:25.853",
        "lastModified": "2026-07-31T17:16:32.670",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14862",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The attachment download path accepts a stored filename without verifying that the requester may read the associated support ticket.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/ef1c6fd5-e62c-4951-a0ba-0e61edb1e795/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14865",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T13:11:08.309Z",
      "date_published": "2026-07-22T13:45:21.227Z",
      "date_updated": "2026-07-22T19:10:08.695Z",
      "publisher": "ProgressSoftware",
      "title": "XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-776",
          "name": "Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14861
      },
      "nvd": {
        "published": "2026-07-22T14:17:15.163",
        "lastModified": "2026-07-22T20:16:48.103",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14865",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.",
        "basis": [
          "CNA",
          "CWE-776"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rlb-xxe-injection-client-state-cve-2026-14865",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14867",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T13:45:31.176Z",
      "date_published": "2026-07-07T09:25:57.741Z",
      "date_updated": "2026-07-07T12:09:29.277Z",
      "publisher": "arcinfo",
      "title": "Insecure password storage in User directory",
      "affected": {
        "vendors": [
          "arcinfo"
        ],
        "products": [
          {
            "vendor": "arcinfo",
            "product": "PcVue"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-256",
          "name": "Plaintext Storage of a Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:Y/R:U/RE:M/U:Amber"
        },
        {
          "source": "NVD:87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00092,
        "percentile": 0.00626
      },
      "nvd": {
        "published": "2026-07-07T10:16:40.120",
        "lastModified": "2026-07-09T18:32:08.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14867",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PcVue stores built-in user credentials in the project User directory without the required confidentiality protection.",
        "basis": [
          "CNA",
          "CWE-256"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.pcvue.com/security/#SB2026-5",
          "host": "www.pcvue.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 242,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14868",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T13:45:32.651Z",
      "date_published": "2026-07-07T09:26:55.347Z",
      "date_updated": "2026-07-07T12:07:31.124Z",
      "publisher": "arcinfo",
      "title": "Weak encryption mechanism for User directory",
      "affected": {
        "vendors": [
          "arcinfo"
        ],
        "products": [
          {
            "vendor": "arcinfo",
            "product": "PcVue"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-326",
          "name": "Inadequate Encryption Strength",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/AU:Y/R:U/RE:M/U:Amber"
        },
        {
          "source": "NVD:87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 2.9000000000000004,
      "epss": {
        "score": 0.0005,
        "percentile": 0.00001
      },
      "nvd": {
        "published": "2026-07-07T10:16:40.273",
        "lastModified": "2026-07-09T18:32:08.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14868",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PcVue protects built-in-directory account configuration with encryption too weak to prevent a local attacker from altering privileged account state.",
        "basis": [
          "CNA",
          "CWE-326"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.pcvue.com/security/#SB2026-5",
          "host": "www.pcvue.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14869",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T14:03:28.716Z",
      "date_published": "2026-07-28T17:53:58.707Z",
      "date_updated": "2026-07-28T19:19:31.237Z",
      "publisher": "HashiCorp",
      "title": "terraform-mcp-server vulnerable to server side request forgery leading to token exposure",
      "affected": {
        "vendors": [
          "HashiCorp"
        ],
        "products": [
          {
            "vendor": "HashiCorp",
            "product": "Tooling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@hashicorp.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21522
      },
      "nvd": {
        "published": "2026-07-28T19:17:31.423",
        "lastModified": "2026-07-30T14:08:23.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14869",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server fetches a caller-controlled URL without restricting the scheme, host or resolved destination to approved targets.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.hashicorp.com/t/hcsec-2026-23-multiple-vulnerabilities-impacting-hashicorp-terraform-mcp-server/77606",
          "host": "discuss.hashicorp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 381,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14870",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T14:11:37.540Z",
      "date_published": "2026-07-28T06:00:02.324Z",
      "date_updated": "2026-07-28T13:19:17.540Z",
      "publisher": "WPScan",
      "title": "Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Database for Contact Form 7, WPforms, Elementor forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04346
      },
      "nvd": {
        "published": "2026-07-28T07:16:41.407",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14870",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/d574b78c-df04-4dab-bd33-e3a22ff51918/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14871",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T14:11:41.135Z",
      "date_published": "2026-07-17T14:55:32.945Z",
      "date_updated": "2026-07-17T15:28:21.159Z",
      "publisher": "Fluid Attacks",
      "title": "osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure",
      "affected": {
        "vendors": [
          "osTicket"
        ],
        "products": [
          {
            "vendor": "osTicket",
            "product": "osTicket"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:help@fluidattacks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23628
      },
      "nvd": {
        "published": "2026-07-17T16:17:13.580",
        "lastModified": "2026-07-17T18:10:00.977",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14871",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "osTicket permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fluidattacks.com/advisories/kyokai",
          "host": "fluidattacks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://medium.com/p/1abb8be847e6",
          "host": "medium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/osTicket/osTicket/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/osTicket/osTicket/releases/tag/v1.18.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/osTicket/osTicket/releases/tag/v1.17.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14881",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T16:26:01.113Z",
      "date_published": "2026-07-22T19:23:17.455Z",
      "date_updated": "2026-07-24T03:56:12.395Z",
      "publisher": "mongodb",
      "title": "Compass connection import allows to override OIDC browser open command (usually set through settings), allowing for arbitrary shell commands execution when connecting to cluster using OIDC auth flow",
      "affected": {
        "vendors": [
          "MongoDB"
        ],
        "products": [
          {
            "vendor": "MongoDB",
            "product": "MongoDB Compass"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@mongodb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00152,
        "percentile": 0.0485
      },
      "nvd": {
        "published": "2026-07-22T20:16:48.247",
        "lastModified": "2026-07-24T05:16:38.380",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14881",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An imported Compass connection can supply the command used to open an OIDC browser and thereby inject shell commands.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mongodb-js/compass/releases/tag/v1.49.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 297,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14890",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T17:51:01.634Z",
      "date_published": "2026-07-16T14:43:44.087Z",
      "date_updated": "2026-07-16T18:23:35.561Z",
      "publisher": "certcc",
      "title": "CVE-2026-14890",
      "affected": {
        "vendors": [
          "SGLang"
        ],
        "products": [
          {
            "vendor": "SGLang",
            "product": "SGLang"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00909,
        "percentile": 0.56489
      },
      "nvd": {
        "published": "2026-07-16T16:19:00.413",
        "lastModified": "2026-07-16T19:16:44.403",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14890",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A routable unauthenticated ZeroMQ socket passes attacker-supplied pickle bytes to an unsafe deserializer.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sgl-project/sglang/blob/main/python/sglang/srt/elastic_ep/expert_backup_manager.py",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://vince.cert.org/vuls/id/326070",
          "host": "vince.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/326070",
          "host": "www.kb.cert.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14891",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T18:05:48.932Z",
      "date_published": "2026-07-08T20:09:05.752Z",
      "date_updated": "2026-07-09T03:55:54.984Z",
      "publisher": "HashiCorp",
      "title": "Nomad vulnerable to sandbox escape in Docker task driver",
      "affected": {
        "vendors": [
          "HashiCorp"
        ],
        "products": [
          {
            "vendor": "HashiCorp",
            "product": "Nomad"
          },
          {
            "vendor": "HashiCorp",
            "product": "Nomad Enterprise"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security@hashicorp.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24079
      },
      "nvd": {
        "published": "2026-07-08T20:16:48.300",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14891",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Docker task driver lets a job submitter select a host path for a container bind mount even when bind mounts are disabled.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.hashicorp.com/t/hcsec-2026-21-nomad-vulnerable-to-sandbox-escape-in-docker-task-driver/77561",
          "host": "discuss.hashicorp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14893",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T18:19:15.930Z",
      "date_published": "2026-07-28T20:36:57.507Z",
      "date_updated": "2026-07-29T14:10:41.839Z",
      "publisher": "ibm",
      "title": "IBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent container image",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Observability with Instana (Agent)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00334,
        "percentile": 0.25988
      },
      "nvd": {
        "published": "2026-07-28T21:17:26.193",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14893",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Observability with Instana (Agent) normalization path lets input overwrite object prototype properties shared by later objects.",
        "basis": [
          "CNA",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281349",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14894",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T18:28:42.679Z",
      "date_published": "2026-07-10T02:30:40.490Z",
      "date_updated": "2026-07-10T14:10:37.476Z",
      "publisher": "Wordfence",
      "title": "Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)",
      "affected": {
        "vendors": [
          "WebRehab"
        ],
        "products": [
          {
            "vendor": "WebRehab",
            "product": "Super Forms – Drag & Drop Form Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00738,
        "percentile": 0.51012
      },
      "nvd": {
        "published": "2026-07-10T04:17:47.587",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14894",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unauthenticated form handler accepts executable file types after issuing any visitor a usable session nonce.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e9c7fb16-efbb-41e9-be13-98e96c1e9100?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/RensTillmann/super-forms/commit/c5838f5877c72b738c54ed970935c77ae6830c3a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 815,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14895",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T18:31:10.251Z",
      "date_published": "2026-07-07T22:12:22.460Z",
      "date_updated": "2026-07-08T14:05:18.813Z",
      "publisher": "CPANSec",
      "title": "String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service",
      "affected": {
        "vendors": [
          "BAKERSCOT"
        ],
        "products": [
          {
            "vendor": "BAKERSCOT",
            "product": "String::Util"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.31498
      },
      "nvd": {
        "published": "2026-07-07T23:16:54.293",
        "lastModified": "2026-07-08T15:56:29.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14895",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The trailing-whitespace regular expression retries a greedy match at every offset, making a long whitespace run consume quadratic CPU time.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/scottchiefbaker/String-Util/commit/f8150867aaeb8f57c59601aefb2193f2caed8745.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/release/BAKERSCOT/String-Util-1.36/diff/BAKERSCOT/String-Util-1.35#lib/String/Util.pm",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/scottchiefbaker/String-Util/releases",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/07/18",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 566,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14896",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T18:35:49.618Z",
      "date_published": "2026-07-08T20:21:16.463Z",
      "date_updated": "2026-07-09T13:40:15.017Z",
      "publisher": "HashiCorp",
      "title": "Nomad vulnerable to cross-namespace host volume claim deletion",
      "affected": {
        "vendors": [
          "HashiCorp"
        ],
        "products": [
          {
            "vendor": "HashiCorp",
            "product": "Nomad"
          },
          {
            "vendor": "HashiCorp",
            "product": "Nomad Enterprise"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security@hashicorp.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05679
      },
      "nvd": {
        "published": "2026-07-08T21:16:47.030",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14896",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Nomad fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.hashicorp.com/t/hcsec-2026-22-nomad-vulnerable-to-cross-namespace-host-volume-claim-deletion/77562",
          "host": "discuss.hashicorp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14898",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T19:35:48.882Z",
      "date_published": "2026-07-06T19:41:36.632Z",
      "date_updated": "2026-07-07T15:35:14.109Z",
      "publisher": "OAI",
      "title": "The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses.",
      "affected": {
        "vendors": [
          "OpenAI"
        ],
        "products": [
          {
            "vendor": "OpenAI",
            "product": "Codex desktop app for macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.2485
      },
      "nvd": {
        "published": "2026-07-06T20:16:30.580",
        "lastModified": "2026-07-07T16:16:37.877",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14898",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Codex renderer automatically fetched attacker-directed remote image URLs, allowing data embedded in the URL to leave the trusted session without a click.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://openai.com/codex/",
          "host": "openai.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 768,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14899",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T19:53:12.713Z",
      "date_published": "2026-07-22T19:19:42.305Z",
      "date_updated": "2026-07-27T17:12:52.731Z",
      "publisher": "mozilla",
      "title": "Off-by-one out of bounds read in MIME header parser for forwarding",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-193",
          "name": "Off-by-one Error",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.1758
      },
      "nvd": {
        "published": "2026-07-22T20:16:48.383",
        "lastModified": "2026-07-27T18:16:52.067",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14899",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Thunderbird advances one element past a buffer boundary because its terminal index is off by one.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-193"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2046137",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T19:54:26.333Z",
      "date_published": "2026-07-29T09:31:13.766Z",
      "date_updated": "2026-07-29T13:42:11.473Z",
      "publisher": "Wordfence",
      "title": "Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDetails' Parameter",
      "affected": {
        "vendors": [
          "StylemixThemes"
        ],
        "products": [
          {
            "vendor": "StylemixThemes",
            "product": "Cost Calculator Builder PRO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0069,
        "percentile": 0.49261
      },
      "nvd": {
        "published": "2026-07-29T11:16:48.200",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14900",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "js_to_php interpolates orderDetails originalValue into a formula passed to PHP eval while its allow-list leaves executable punctuation intact.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4c8f2872-06ff-41a2-b601-77a47470de0c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://stylemixthemes.com/cost-calculator-plugin/",
          "host": "stylemixthemes.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 825,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14902",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T21:20:44.490Z",
      "date_published": "2026-07-14T14:23:14.584Z",
      "date_updated": "2026-07-14T14:49:48.989Z",
      "publisher": "ivanti",
      "title": "An open redirect in Ivanti Xtraction before version 2026.",
      "affected": {
        "vendors": [
          "ivanti"
        ],
        "products": [
          {
            "vendor": "ivanti",
            "product": "Xtraction"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
          "type": "Secondary",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00542,
        "percentile": 0.42497
      },
      "nvd": {
        "published": "2026-07-14T15:16:56.977",
        "lastModified": "2026-07-15T16:23:03.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14902",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Xtraction accepts an external redirect destination without restricting it to a trusted origin.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Xtraction-CVE-2026-14902-CVE-2026-14903?language=en_US",
          "host": "hub.ivanti.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14903",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T21:20:45.037Z",
      "date_published": "2026-07-14T14:26:09.246Z",
      "date_updated": "2026-07-14T14:45:41.619Z",
      "publisher": "ivanti",
      "title": "Path traversal in Ivanti Xtraction before version 2026.",
      "affected": {
        "vendors": [
          "ivanti"
        ],
        "products": [
          {
            "vendor": "ivanti",
            "product": "Xtraction"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01019,
        "percentile": 0.5999
      },
      "nvd": {
        "published": "2026-07-14T15:16:57.113",
        "lastModified": "2026-07-15T16:23:03.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14903",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ivanti Xtraction accepts traversal segments in a requested path and resolves the selection outside the web root.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Xtraction-CVE-2026-14902-CVE-2026-14903?language=en_US",
          "host": "hub.ivanti.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 144,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14904",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T21:21:23.566Z",
      "date_published": "2026-07-07T16:37:58.362Z",
      "date_updated": "2026-07-07T17:24:40.824Z",
      "publisher": "AMZN",
      "title": "RES Auth.GetUserPrivateKey Arbitrary File Read",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "res"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00381,
        "percentile": 0.30877
      },
      "nvd": {
        "published": "2026-07-07T17:16:35.627",
        "lastModified": "2026-07-08T15:36:14.057",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14904",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The private-key API follows a user-replaceable ~/.ssh/id_rsa symlink as root, allowing the target file to escape the user key location.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aws/res/releases/tag/2026.06",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-053-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 704,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14906",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T21:26:25.464Z",
      "date_published": "2026-07-13T18:27:03.771Z",
      "date_updated": "2026-07-13T19:32:16.220Z",
      "publisher": "mozilla",
      "title": "Malicious webpage titles could allow overwriting of bundled PDF resources when saving webpages as PDFs in Firefox for iOS",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox for iOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07396
      },
      "nvd": {
        "published": "2026-07-13T19:16:46.200",
        "lastModified": "2026-07-14T18:31:45.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14906",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2045842",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-66/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14919",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T07:56:11.961Z",
      "date_published": "2026-07-31T06:00:12.218Z",
      "date_updated": "2026-07-31T16:38:27.612Z",
      "publisher": "WPScan",
      "title": "ShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via Password-Reset Email Reroute",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "ShopMonitor.io"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.1991
      },
      "nvd": {
        "published": "2026-07-31T07:16:25.963",
        "lastModified": "2026-07-31T17:16:32.863",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14919",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The password-reset mail test trusts client-supplied source headers, allowing an unauthenticated caller to redirect administrator reset mail.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/6d929535-9757-44ae-8c58-682f1eb89785/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14921",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T08:03:28.990Z",
      "date_published": "2026-07-31T06:00:07.939Z",
      "date_updated": "2026-07-31T19:40:51.550Z",
      "publisher": "WPScan",
      "title": "Ultimate Addons for WPBakery Page Builder < 3.21.5 - Contributor+ Stored XSS via ult_buttons Shortcode",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Ultimate Addons for WPBakery Page Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04578
      },
      "nvd": {
        "published": "2026-07-31T07:16:26.067",
        "lastModified": "2026-07-31T20:16:47.020",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14921",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/4bebd9ff-87b6-45ca-9b3e-9e6048693ca6/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14922",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T08:03:53.590Z",
      "date_published": "2026-07-31T06:00:08.117Z",
      "date_updated": "2026-07-31T19:41:45.293Z",
      "publisher": "WPScan",
      "title": "WP Photo Album Plus < 9.2.04.003 - Subscriber+ Stored XSS via Photo Comment",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Photo Album Plus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04578
      },
      "nvd": {
        "published": "2026-07-31T07:16:26.177",
        "lastModified": "2026-07-31T20:16:47.173",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14922",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/ca9f99eb-221a-417e-b18f-0a8b8b513f2e/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14923",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T08:59:07.515Z",
      "date_published": "2026-07-30T06:00:06.911Z",
      "date_updated": "2026-07-30T14:02:56.530Z",
      "publisher": "WPScan",
      "title": "Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modification",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Sync Post With Other Site"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17488
      },
      "nvd": {
        "published": "2026-07-30T06:25:01.067",
        "lastModified": "2026-07-30T15:16:25.827",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14923",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An operator-precedence error makes the REST capability predicate accept contributors who may edit posts but may not create or overwrite pages.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/cc635e60-f80e-4399-a016-9fde9228c58c/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 433,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14924",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:00:38.166Z",
      "date_published": "2026-07-28T06:00:02.497Z",
      "date_updated": "2026-07-28T13:16:39.290Z",
      "publisher": "WPScan",
      "title": "Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Tablesome Table"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16775
      },
      "nvd": {
        "published": "2026-07-28T07:16:41.507",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14924",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An AJAX action performs post creation and overwrite operations without authentication, capability, or nonce checks.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/6cbb9796-5f9b-44b4-b814-176ed225b184/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14926",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:14:07.886Z",
      "date_published": "2026-07-28T06:00:02.676Z",
      "date_updated": "2026-07-28T13:11:31.641Z",
      "publisher": "WPScan",
      "title": "FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "FluentCart A New Era of eCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04128
      },
      "nvd": {
        "published": "2026-07-28T07:16:41.617",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14926",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The subscription operation accepts an object identifier without checking that the caller owns that subscription.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/2f0f147e-0990-4ded-b2cd-ac2a32975782/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 375,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14927",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:14:16.181Z",
      "date_published": "2026-07-31T06:00:08.298Z",
      "date_updated": "2026-07-31T13:25:07.132Z",
      "publisher": "WPScan",
      "title": "FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "FluentCart A New Era of eCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05866
      },
      "nvd": {
        "published": "2026-07-31T07:16:26.280",
        "lastModified": "2026-07-31T14:16:46.993",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14927",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Order print routes resolve a sequential order identifier without checking authentication, ownership, or authorization.",
        "basis": [
          "CNA record",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/8e0d0e5d-b515-482f-aede-f7ed2046e4e3/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14928",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:18:59.814Z",
      "date_published": "2026-07-31T06:00:08.494Z",
      "date_updated": "2026-07-31T19:42:49.082Z",
      "publisher": "WPScan",
      "title": "JS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubject",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "JS Help Desk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00219,
        "percentile": 0.12433
      },
      "nvd": {
        "published": "2026-07-31T07:16:26.390",
        "lastModified": "2026-07-31T20:16:47.323",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14928",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The nonce-gated ticket search returns another user's ticket without checking ticket ownership or a support-management capability.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/c876774c-3cee-4a8a-a448-9d92fd8a4171/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 307,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14929",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:19:02.656Z",
      "date_published": "2026-07-31T06:00:08.669Z",
      "date_updated": "2026-07-31T13:24:23.485Z",
      "publisher": "WPScan",
      "title": "JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "JS Help Desk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04889
      },
      "nvd": {
        "published": "2026-07-31T07:16:26.500",
        "lastModified": "2026-07-31T14:16:47.173",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14929",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The help-desk reply update uses a caller-supplied reply identifier without verifying that the caller owns or may modify that reply.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/2d786e43-6dbc-4d63-844e-2ca1384cdfd3/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14930",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:19:06.069Z",
      "date_published": "2026-07-31T06:00:08.845Z",
      "date_updated": "2026-07-31T19:46:54.676Z",
      "publisher": "WPScan",
      "title": "JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "JS Help Desk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.1514
      },
      "nvd": {
        "published": "2026-07-31T07:16:26.610",
        "lastModified": "2026-07-31T20:16:47.480",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14930",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The front-end dispatcher accepts unauthenticated uploads and attaches them to arbitrary users' support tickets without a nonce, authorization, or ticket-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/075ca843-e787-43cc-8de4-54d8ddc63d4a/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14931",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:19:10.202Z",
      "date_published": "2026-07-31T06:00:09.023Z",
      "date_updated": "2026-07-31T19:47:50.635Z",
      "publisher": "WPScan",
      "title": "JS Help Desk < 3.1.4 - Contributor+ User Email Disclosure",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "JS Help Desk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00219,
        "percentile": 0.12432
      },
      "nvd": {
        "published": "2026-07-31T07:16:26.720",
        "lastModified": "2026-07-31T20:16:47.637",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14931",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The plugin grants a support-agent capability to Contributors and exposes a user-listing handler without a capability check.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/852375ba-b8f5-4fef-8a37-d889d97227f0/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14932",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T10:26:06.376Z",
      "date_published": "2026-07-22T13:46:45.714Z",
      "date_updated": "2026-07-22T19:09:34.640Z",
      "publisher": "ProgressSoftware",
      "title": "Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "Telerik UI for ASP.NET AJAX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-321",
          "name": "Use of Hard-coded Cryptographic Key",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11148
      },
      "nvd": {
        "published": "2026-07-22T14:17:15.283",
        "lastModified": "2026-07-22T20:16:48.487",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14932",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RadChart uses a hard-coded encryption key to protect ChartImage.axd parameters, allowing forged parameters to select image-extension files for read or deletion.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-radchart-hardcoded-key-file-read-cve-2026-14932",
          "host": "www.telerik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14934",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T11:05:22.340Z",
      "date_published": "2026-07-13T10:20:19.121Z",
      "date_updated": "2026-07-13T13:12:16.784Z",
      "publisher": "GoogleCloud",
      "title": "Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dataform and Colab Enterprise",
      "affected": {
        "vendors": [
          "Google Cloud"
        ],
        "products": [
          {
            "vendor": "Google Cloud",
            "product": "BigQuery"
          },
          {
            "vendor": "Google Cloud",
            "product": "Dataform"
          },
          {
            "vendor": "Google Cloud",
            "product": "Colab Enterprise"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear"
        },
        {
          "source": "NVD:f45cbf4e-4146-4068-b7e1-655ffc2c548c",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13422
      },
      "nvd": {
        "published": "2026-07-13T11:16:26.470",
        "lastModified": "2026-07-13T19:49:49.190",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14934",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Google Cloud repository creation can bind an authenticated caller to cross-tenant repository authority, but the public bulletin does not identify the missing object or tenant check.",
        "basis": [
          "CNA",
          "CWE-862",
          "Google Cloud support bulletin"
        ],
        "deepDive": true,
        "notes": "Inspected Google Cloud support bulletin https://docs.cloud.google.com/support/bulletins#gcp-2026-047. Google confirms that repository creation in BigQuery, Dataform, and Colab Enterprise allowed an authenticated cross-tenant takeover and says the service-side repair was applied on 2026-05-10 with no customer action, but the bulletin does not publish the request field, object-binding lookup, or missing authorization decision."
      },
      "references": [
        {
          "url": "https://docs.cloud.google.com/support/bulletins#gcp-2026-047",
          "host": "docs.cloud.google.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14935",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T11:25:35.489Z",
      "date_published": "2026-07-07T15:37:58.898Z",
      "date_updated": "2026-07-07T16:13:27.854Z",
      "publisher": "redhat",
      "title": "Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-670",
          "name": "Always-Incorrect Control Flow Implementation",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04731
      },
      "nvd": {
        "published": "2026-07-07T16:16:38.010",
        "lastModified": "2026-07-08T15:24:06.060",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14935",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An inverted SDP-fingerprint presence check accepts a session that lacks the certificate binding it is supposed to require.",
        "basis": [
          "CNA",
          "CWE-670"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14935",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497679",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/98",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5171",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 523,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-14940",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T12:01:04.779Z",
      "date_published": "2026-07-07T13:54:20.688Z",
      "date_updated": "2026-07-07T15:35:45.502Z",
      "publisher": "redhat",
      "title": "389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 11"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 12"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 13"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21661
      },
      "nvd": {
        "published": "2026-07-07T15:16:43.193",
        "lastModified": "2026-07-09T20:20:52.007",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14940",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Red Hat Directory Server 11 parser or handler can write attacker-controlled data beyond the bounds of a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14940",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497697",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-14955",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T13:32:03.687Z",
      "date_published": "2026-07-25T05:34:55.666Z",
      "date_updated": "2026-07-27T13:58:42.946Z",
      "publisher": "Wordfence",
      "title": "Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter",
      "affected": {
        "vendors": [
          "Themehigh"
        ],
        "products": [
          {
            "vendor": "Themehigh",
            "product": "Checkout Field Editor for WooCommerce (Pro)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00526,
        "percentile": 0.41646
      },
      "nvd": {
        "published": "2026-07-25T07:17:09.753",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14955",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The thwcfe_legacy_file parameter selects a path outside the intended checkout-file directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a9576cee-2375-437e-9dc8-713209a96a73?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.themehigh.com/product/woocommerce-checkout-field-editor-pro/",
          "host": "www.themehigh.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14956",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T13:38:12.463Z",
      "date_published": "2026-07-17T01:30:52.281Z",
      "date_updated": "2026-07-21T01:25:01.456Z",
      "publisher": "Wordfence",
      "title": "Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter",
      "affected": {
        "vendors": [
          "Bricksforge"
        ],
        "products": [
          {
            "vendor": "Bricksforge",
            "product": "Bricksforge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27838
      },
      "nvd": {
        "published": "2026-07-17T02:18:03.870",
        "lastModified": "2026-07-21T02:16:23.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14956",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to the trusted form-field whitelist.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d0538778-5ba4-4bec-a89d-ef90a9ba8375?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://bricksforge.io/version-changelog/",
          "host": "bricksforge.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 637,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14958",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T14:06:56.053Z",
      "date_published": "2026-07-28T20:36:05.337Z",
      "date_updated": "2026-07-30T03:55:26.302Z",
      "publisher": "ibm",
      "title": "OS command injection in IBM Aspera Faspex",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Aspera Faspex 5"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0052,
        "percentile": 0.4132
      },
      "nvd": {
        "published": "2026-07-28T21:17:26.317",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14958",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Aspera Faspex places attacker-controlled text into a shell command without quoting it as one argument.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280530",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14959",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T14:21:25.182Z",
      "date_published": "2026-07-28T20:33:51.198Z",
      "date_updated": "2026-07-30T03:55:27.073Z",
      "publisher": "ibm",
      "title": "OS Command Injection in IBM Aspera Faspex",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Aspera Faspex 5"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01038,
        "percentile": 0.606
      },
      "nvd": {
        "published": "2026-07-28T21:17:26.443",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14959",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler places caller-controlled data in an operating-system command without safe argument separation.",
        "basis": [
          "CNA",
          "CWE-78",
          "https://www.ibm.com/support/pages/node/7280530"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.ibm.com/support/pages/node/7280530. IBM confirms an authenticated shell-command injection and the 5.0.16 repair boundary, but publishes no parameter, command builder, or patch."
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280530",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 144,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14960",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T14:25:40.813Z",
      "date_published": "2026-07-15T17:08:47.481Z",
      "date_updated": "2026-07-16T15:33:59.441Z",
      "publisher": "certcc",
      "title": "CVE-2026-14960",
      "affected": {
        "vendors": [
          "Pegatron Corp."
        ],
        "products": [
          {
            "vendor": "Pegatron Corp.",
            "product": "Tdelo64.sys"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-668",
          "name": "Exposure of Resource to Wrong Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00478,
        "percentile": 0.38752
      },
      "nvd": {
        "published": "2026-07-15T18:16:44.540",
        "lastModified": "2026-07-16T16:19:00.507",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14960",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A Pegatron kernel driver exposes privileged port-I/O operations through an IOCTL interface without restricting which local callers may issue them.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-668"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.cert.org/vuls/id/529388",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 521,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14961",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T14:26:02.918Z",
      "date_published": "2026-07-15T17:09:52.285Z",
      "date_updated": "2026-07-15T19:31:32.591Z",
      "publisher": "certcc",
      "title": "CVE-2026-14961",
      "affected": {
        "vendors": [
          "Pegatron Corp."
        ],
        "products": [
          {
            "vendor": "Pegatron Corp.",
            "product": "Tdelo64.sys"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04615
      },
      "nvd": {
        "published": "2026-07-15T18:16:44.640",
        "lastModified": "2026-07-15T20:16:56.040",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14961",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The TdeIo driver interface performs privileged kernel-memory IOCTL operations without validating the caller's privilege or the supplied kernel address.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.cert.org/vuls/id/529388",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 1,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14966",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:14:09.717Z",
      "date_published": "2026-07-08T15:03:47.591Z",
      "date_updated": "2026-07-08T15:57:12.247Z",
      "publisher": "BLSOPS",
      "title": "Symlink guard bypass in unarchive module allows planting symlinks during extraction",
      "affected": {
        "vendors": [
          "Black Lantern Security"
        ],
        "products": [
          {
            "vendor": "Black Lantern Security",
            "product": "BBOT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cves@blacklanternsecurity.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21364
      },
      "nvd": {
        "published": "2026-07-08T16:16:27.237",
        "lastModified": "2026-07-09T17:05:26.503",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14966",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The archive guard misparses legacy p7zip listings with a DOS-attribute prefix and therefore permits a symlink entry to be extracted.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/blacklanternsecurity/bbot/commit/a3f1a2292e2b0a553827c6175b761abe28807735",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 620,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14967",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:14:11.304Z",
      "date_published": "2026-07-08T15:03:50.730Z",
      "date_updated": "2026-07-08T15:55:55.659Z",
      "publisher": "BLSOPS",
      "title": "Path traversal in github_workflows allows writing artifacts outside output directory",
      "affected": {
        "vendors": [
          "Black Lantern Security"
        ],
        "products": [
          {
            "vendor": "Black Lantern Security",
            "product": "BBOT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cves@blacklanternsecurity.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09849
      },
      "nvd": {
        "published": "2026-07-08T16:16:27.373",
        "lastModified": "2026-07-09T17:05:26.503",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14967",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The artifact path-containment check compares an unresolved path, allowing dot segments in a repository URL to select a destination outside the output directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/blacklanternsecurity/bbot/commit/c1c6ec05ff998e2fba55a14d1026f12563ccd82f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14969",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:32:40.440Z",
      "date_published": "2026-07-07T15:48:04.478Z",
      "date_updated": "2026-07-07T16:11:40.145Z",
      "publisher": "redhat",
      "title": "389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 11"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 12"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 13"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-329",
          "name": "Generation of Predictable IV with CBC Mode",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00077,
        "percentile": 0.00145
      },
      "nvd": {
        "published": "2026-07-07T16:16:38.310",
        "lastModified": "2026-07-09T20:16:29.207",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14969",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The directory server reuses a hard-coded initialization vector for CBC encryption, so equal plaintext blocks produce recognizable equal ciphertext blocks.",
        "basis": [
          "CNA",
          "CWE-329"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-14969",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497735",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 299,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-14971",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:36:57.998Z",
      "date_published": "2026-07-17T19:49:41.211Z",
      "date_updated": "2026-07-20T13:50:43.330Z",
      "publisher": "ibm",
      "title": "This PowerVM Novalink update is being released to address",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "PowerVM Novalink"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-16",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00097,
        "percentile": 0.0088
      },
      "nvd": {
        "published": "2026-07-17T20:17:15.190",
        "lastModified": "2026-07-20T17:15:53.673",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14971",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A non-default NovaLink API configuration grants a broader operation surface than intended, but the public record does not name the setting or permission change.",
        "basis": [
          "CNA",
          "CWE-16"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280225",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14973",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:44:30.497Z",
      "date_published": "2026-07-28T20:31:29.940Z",
      "date_updated": "2026-07-31T03:56:13.015Z",
      "publisher": "ibm",
      "title": "Path Traversal in IBM Desktop App",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Aspera Desktop App"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00452,
        "percentile": 0.37032
      },
      "nvd": {
        "published": "2026-07-28T21:17:26.570",
        "lastModified": "2026-07-31T04:16:46.710",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14973",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Aspera Desktop App file operation accepts an attacker-controlled path that escapes the intended directory or storage target.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280939",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14974",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:45:50.888Z",
      "date_published": "2026-07-28T20:29:47.119Z",
      "date_updated": "2026-07-30T03:55:27.825Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29345
      },
      "nvd": {
        "published": "2026-07-28T21:17:26.700",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14974",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebSphere deserializes attacker-controlled objects without restricting the classes or behavior reconstructed.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281641",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 165,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-14976",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:49:25.315Z",
      "date_published": "2026-07-28T20:29:09.349Z",
      "date_updated": "2026-07-30T14:10:54.485Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.0895
      },
      "nvd": {
        "published": "2026-07-28T21:17:26.830",
        "lastModified": "2026-07-30T15:16:25.987",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14976",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The public record shows that WebSphere Application Server - Liberty permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281633",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 156,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14979",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:58:17.358Z",
      "date_published": "2026-07-17T19:49:10.380Z",
      "date_updated": "2026-07-28T20:25:25.340Z",
      "publisher": "ibm",
      "title": "IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Engineering Lifecycle Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-776",
          "name": "Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00357,
        "percentile": 0.28384
      },
      "nvd": {
        "published": "2026-07-17T20:17:15.313",
        "lastModified": "2026-07-28T21:17:26.953",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14979",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Engineering Lifecycle Management expands attacker-controlled XML structures without a safe expansion bound, allowing a small document to drive excessive work or memory use.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-776"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279963",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14980",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T17:07:31.185Z",
      "date_published": "2026-07-30T14:09:23.375Z",
      "date_updated": "2026-07-31T03:56:03.632Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server Liberty is affected by a cross-site request forgery",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12746
      },
      "nvd": {
        "published": "2026-07-30T15:16:26.120",
        "lastModified": "2026-08-04T15:23:30.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-14980",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A cross-site request can make an authenticated Liberty controller issue a server-side request with the victim's elevated authority.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281651",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T17:15:07.142Z",
      "date_published": "2026-07-28T20:22:37.986Z",
      "date_updated": "2026-07-29T15:24:31.823Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          },
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17996
      },
      "nvd": {
        "published": "2026-07-28T21:17:27.090",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14981",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The WebSphere HTTP channel allocates request-driven resources without an effective limit, allowing repeated traffic to exhaust the server.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281625",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-14985",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:00:27.130Z",
      "date_published": "2026-07-22T14:32:31.868Z",
      "date_updated": "2026-07-27T16:58:13.543Z",
      "publisher": "certcc",
      "title": "CVE-2026-14985",
      "affected": {
        "vendors": [
          "Analog Way"
        ],
        "products": [
          {
            "vendor": "Analog Way",
            "product": "Picturall Quad Compact Mark II"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-250",
          "name": "Execution with Unnecessary Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07044
      },
      "nvd": {
        "published": "2026-07-22T15:16:52.420",
        "lastModified": "2026-07-27T18:16:52.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14985",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A privileged maintenance script accepts a path outside its intended namespace and runs with authority unnecessary for the caller.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-250"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.kb.cert.org/vuls/id/360868",
          "host": "www.kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14987",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:40:05.272Z",
      "date_published": "2026-07-16T02:30:56.586Z",
      "date_updated": "2026-07-16T12:45:22.534Z",
      "publisher": "Wordfence",
      "title": "GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting",
      "affected": {
        "vendors": [
          "stellarwp"
        ],
        "products": [
          {
            "vendor": "stellarwp",
            "product": "GiveWP – Donation Plugin and Fundraising Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10766
      },
      "nvd": {
        "published": "2026-07-16T04:17:19.400",
        "lastModified": "2026-07-16T14:16:48.670",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14987",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GiveWP places twitter_message inside a JavaScript template literal without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bdd0ba4b-56f1-4f4b-95f7-28c911c8de09?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.15.5/src/Views/Form/Templates/Sequoia/views/social-sharing.php#L41",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.15.5/includes/admin/forms/class-metabox-form-data.php#L1180",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.15.5/includes/formatting.php#L768",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.14.5/src/Views/Form/Templates/Sequoia/views/social-sharing.php#L41",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.14.5/includes/admin/forms/class-metabox-form-data.php#L1180",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/give/tags/4.14.5/includes/formatting.php#L768",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3607718%40give&new=3607718%40give",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 704,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-14996",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:59:33.610Z",
      "date_published": "2026-07-28T20:21:18.798Z",
      "date_updated": "2026-07-29T14:10:07.644Z",
      "publisher": "ibm",
      "title": "Multiple vulnerabilities in IBM Aspera Faspex",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Aspera Faspex 5"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13237
      },
      "nvd": {
        "published": "2026-07-28T21:17:27.240",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-14996",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "IBM states only that a session-management vulnerability was addressed and does not disclose the affected session state or failing transition.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280530",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15000",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T19:30:14.180Z",
      "date_published": "2026-07-09T06:52:48.758Z",
      "date_updated": "2026-07-09T14:33:50.288Z",
      "publisher": "Wordfence",
      "title": "Connect Contact Form 7 and Mailchimp <= 0.9.78.06 - Unauthenticated Stored Cross-Site Scripting via Mailchimp Merge Field Values",
      "affected": {
        "vendors": [
          "rnzo"
        ],
        "products": [
          {
            "vendor": "rnzo",
            "product": "Connect Contact Form 7 and Mailchimp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26597
      },
      "nvd": {
        "published": "2026-07-09T08:16:47.340",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15000",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all versions up to, and including, 0.9.78.06 due to insufficient input sanitization and output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/be2579e3-8e40-4603-9ec1-38f43dc1aa29?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-7-mailchimp-extension/tags/0.9.78.05/assets/js/chimpmatic-lite.js#L1706",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-7-mailchimp-extension/tags/0.9.78.05/includes/services/submission/class-cmatic-merge-vars-builder.php#L30",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-7-mailchimp-extension/tags/0.9.78.05/includes/api/class-cmatic-contact-lookup.php#L237",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-7-mailchimp-extension/tags/0.9.78.05/assets/js/chimpmatic-lite.js#L2036",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-7-mailchimp-extension/trunk/assets/js/chimpmatic-lite.js#L1706",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-7-mailchimp-extension/trunk/includes/services/submission/class-cmatic-merge-vars-builder.php#L30",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-7-mailchimp-extension/trunk/includes/api/class-cmatic-contact-lookup.php#L237",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-7-mailchimp-extension/trunk/assets/js/chimpmatic-lite.js#L2036",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3599649%40contact-form-7-mailchimp-extension&new=3599649%40contact-form-7-mailchimp-extension",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 644,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15003",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T20:18:49.308Z",
      "date_published": "2026-07-27T13:22:21.523Z",
      "date_updated": "2026-07-28T16:41:41.720Z",
      "publisher": "redhat",
      "title": "Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of service",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 23,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01281
      },
      "nvd": {
        "published": "2026-07-27T14:16:51.473",
        "lastModified": "2026-07-28T17:16:37.047",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15003",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47171",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15003",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497805",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=34053",
          "host": "sourceware.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15005",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T20:30:34.194Z",
      "date_published": "2026-07-16T08:26:49.721Z",
      "date_updated": "2026-07-16T12:26:31.212Z",
      "publisher": "Wordfence",
      "title": "Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter",
      "affected": {
        "vendors": [
          "timwhitlock"
        ],
        "products": [
          {
            "vendor": "timwhitlock",
            "product": "Loco Translate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11499
      },
      "nvd": {
        "published": "2026-07-16T09:16:17.060",
        "lastModified": "2026-07-16T13:38:53.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15005",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A forged cross-site request reaches execTemplate(), where a caller-controlled php://filter URI passes path validation and is included as PHP.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/241d7a82-5fa5-40e3-9336-823644ca17f0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.5/src/mvc/View.php#L274",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.5/src/mvc/View.php#L273",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.5/src/mvc/AdminController.php#L38",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.5/src/mvc/AdminRouter.php#L128",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.3/src/mvc/View.php#L274",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.3/src/mvc/View.php#L273",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.3/src/mvc/AdminController.php#L38",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/loco-translate/tags/2.8.3/src/mvc/AdminRouter.php#L128",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3603894%40loco-translate&new=3603894%40loco-translate",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 595,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15007",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T21:23:32.045Z",
      "date_published": "2026-07-17T15:16:02.252Z",
      "date_updated": "2026-07-17T16:39:17.312Z",
      "publisher": "GitHub_P",
      "title": "Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration",
      "affected": {
        "vendors": [
          "GitHub"
        ],
        "products": [
          {
            "vendor": "GitHub",
            "product": "Enterprise Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U"
        },
        {
          "source": "NVD:product-cna@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29287
      },
      "nvd": {
        "published": "2026-07-17T16:17:13.743",
        "lastModified": "2026-07-17T18:11:59.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15007",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Release-note generation parses attacker-controlled YAML without a nesting-depth limit, so deeply nested input can exhaust instance resources.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.18",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.12",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.9",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.5",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.3",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 635,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-15008",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T21:26:57.330Z",
      "date_published": "2026-07-16T07:51:04.143Z",
      "date_updated": "2026-07-17T12:43:19.033Z",
      "publisher": "Wordfence",
      "title": "Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token",
      "affected": {
        "vendors": [
          "uncannyowl"
        ],
        "products": [
          {
            "vendor": "uncannyowl",
            "product": "Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00594,
        "percentile": 0.45046
      },
      "nvd": {
        "published": "2026-07-16T09:16:17.200",
        "lastModified": "2026-07-17T13:17:57.280",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15008",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application deserializes attacker-controlled bytes with object semantics that can invoke executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9f2774e8-8b55-4c25-93c3-e0806208b1f3?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/forminator/tokens/fr-tokens.php#L136",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/forminator/triggers/anon-fr-submitform.php#L114",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/core/lib/utilities/db/class-automator-db-handler-triggers.php#L300",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/core/lib/recipe-parts/actions/trait-action-helpers-email.php#L481",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/core/services/email/attachment/handler.php#L201",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3607776%40uncanny-automator&new=3607776%40uncanny-automator",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 796,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15010",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T21:52:36.970Z",
      "date_published": "2026-07-11T06:50:33.433Z",
      "date_updated": "2026-07-13T16:11:39.208Z",
      "publisher": "Wordfence",
      "title": "bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields",
      "affected": {
        "vendors": [
          "robin-w"
        ],
        "products": [
          {
            "vendor": "robin-w",
            "product": "bbp style pack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10401
      },
      "nvd": {
        "published": "2026-07-11T07:16:46.033",
        "lastModified": "2026-07-13T17:17:01.803",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15010",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches bbp style pack page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f898ab34-2d63-458d-b19b-4e2b6f4a0f3b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.5/includes/functions_topic_fields.php#L146",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bbp-style-pack/tags/6.4.5/includes/functions_topic_fields.php#L235",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3601461%40bbp-style-pack&new=3601461%40bbp-style-pack",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 829,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15011",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T21:56:30.104Z",
      "date_published": "2026-07-23T08:34:42.275Z",
      "date_updated": "2026-07-23T13:58:56.220Z",
      "publisher": "Wordfence",
      "title": "Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter",
      "affected": {
        "vendors": [
          "emarket-design"
        ],
        "products": [
          {
            "vendor": "emarket-design",
            "product": "Customer Support Ticket System & Helpdesk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00494,
        "percentile": 0.39741
      },
      "nvd": {
        "published": "2026-07-23T10:16:49.917",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15011",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unauthenticated path value is used as a dynamic PHP function name, allowing attacker-selected functions to be invoked.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f9e2ad4b-716a-4a2d-87c0-2f351bd13884?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-ticket/tags/6.0.5/includes/common-functions.php#L1043",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-ticket/tags/6.0.5/includes/common-functions.php#L1040",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-ticket/tags/6.0.5/includes/class-install-deactivate.php#L59",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-ticket/tags/6.0.5/includes/emd-form-builder-lite/emd-form-frontend.php#L1187",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3617122%40wp-ticket&new=3617122%40wp-ticket",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 707,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15012",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T22:00:21.670Z",
      "date_published": "2026-07-28T05:39:42.395Z",
      "date_updated": "2026-07-28T13:41:15.476Z",
      "publisher": "Wordfence",
      "title": "Demi <= 0.0.8 - Unauthenticated Information Exposure to Arbitrary Directory Copy",
      "affected": {
        "vendors": [
          "deveasel"
        ],
        "products": [
          {
            "vendor": "deveasel",
            "product": "Demi – One Click Demo Import, Backup & Site Migration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24129
      },
      "nvd": {
        "published": "2026-07-28T07:16:41.720",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15012",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A restore key is stored in publicly accessible state and reused as the proof for accepting signed restore data.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/61ee1857-aa85-4d37-a347-a1f59c95cbff?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/classes/Import/Manager.php#L50",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/classes/Import/Manager.php#L460",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/classes/Import/Manager.php#L287",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/classes/Import/Tasks/RestoreFiles.php#L168",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/trunk/includes/helper-functions.php#L55",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/classes/Import/Manager.php#L460",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/classes/Import/Manager.php#L287",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/classes/Import/Manager.php#L50",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/classes/Import/Tasks/RestoreFiles.php#L168",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/demi-backup-migration/tags/0.0.6/includes/helper-functions.php#L55",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3616690%40demi-backup-migration&new=3616690%40demi-backup-migration",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 828,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15013",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T22:25:26.987Z",
      "date_published": "2026-07-16T03:44:32.129Z",
      "date_updated": "2026-07-16T12:45:15.688Z",
      "publisher": "Wordfence",
      "title": "SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion",
      "affected": {
        "vendors": [
          "cyberlord92"
        ],
        "products": [
          {
            "vendor": "cyberlord92",
            "product": "SAML Single Sign On – SSO Login"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00438,
        "percentile": 0.36036
      },
      "nvd": {
        "published": "2026-07-16T05:16:18.043",
        "lastModified": "2026-07-16T13:38:53.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15013",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mo_saml_cast_key trusts the assertion's SignatureMethod and recasts an RSA public key as an HMAC secret for forged-signature validation.",
        "basis": [
          "CNA record",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ee95092d-6351-4612-872d-284165bc1201?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-saml-20-single-sign-on/tags/5.4.3/class-mo-saml-utilities.php#L444",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-saml-20-single-sign-on/tags/5.4.3/class-mo-saml-utilities.php#L416",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-saml-20-single-sign-on/tags/5.4.3/class-mo-saml-utilities.php#L561",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-saml-20-single-sign-on/tags/5.4.3/class-mo-saml-login-validate.php#L119",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-saml-20-single-sign-on/tags/5.4.3/includes/lib/SAML2Core/class-mo-saml-xml-security-key.php#L722",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3601345%40miniorange-saml-20-single-sign-on&new=3601345%40miniorange-saml-20-single-sign-on",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 791,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T22:31:56.486Z",
      "date_published": "2026-07-28T06:54:34.753Z",
      "date_updated": "2026-07-28T13:56:55.300Z",
      "publisher": "Wordfence",
      "title": "SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter",
      "affected": {
        "vendors": [
          "cozyvision1"
        ],
        "products": [
          {
            "vendor": "cozyvision1",
            "product": "SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00459,
        "percentile": 0.37561
      },
      "nvd": {
        "published": "2026-07-28T08:17:14.580",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15014",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery accepts an alternate authentication path whose verified state is not bound to the account being logged in.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/661d4ea9-572d-4544-b5cf-39fd69c104a6?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/woocommerce/wc-registration.php#L691",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/woocommerce/wc-registration.php#L680",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/woocommerce/wc-registration.php#L252",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/woocommerce/wc-registration.php#L602",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.6/handler/forms/FormInterface.php#L56",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3623914%40sms-alert&new=3623914%40sms-alert",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 967,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15015",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T22:34:19.224Z",
      "date_published": "2026-07-23T09:33:59.123Z",
      "date_updated": "2026-07-23T13:45:33.763Z",
      "publisher": "Wordfence",
      "title": "MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege Escalation via OAuth Authorization Endpoint",
      "affected": {
        "vendors": [
          "cascadiawebservices"
        ],
        "products": [
          {
            "vendor": "cascadiawebservices",
            "product": "MountDev AI MCP Connector for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00381,
        "percentile": 0.30807
      },
      "nvd": {
        "published": "2026-07-23T10:16:50.047",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15015",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OAuth flow lets an unauthenticated caller register a redirect and obtain an administrator bearer token without binding issuance to administrator approval.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ce8ec66f-5efc-4354-8871-8e35ab4e51fc?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mountdev-ai-mcp-connector/tags/1.6.0/includes/class-oauth-controller.php#L571",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mountdev-ai-mcp-connector/tags/1.6.0/includes/class-oauth-controller.php#L474",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mountdev-ai-mcp-connector/tags/1.6.0/includes/class-oauth-controller.php#L188",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mountdev-ai-mcp-connector/tags/1.6.0/includes/class-oauth-controller.php#L370",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3601448%40mountdev-ai-mcp-connector&new=3601448%40mountdev-ai-mcp-connector",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 838,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15016",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T22:56:49.669Z",
      "date_published": "2026-07-28T12:36:30.012Z",
      "date_updated": "2026-07-28T13:37:29.646Z",
      "publisher": "Wordfence",
      "title": "Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions <= 3.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting",
      "affected": {
        "vendors": [
          "strangerstudios"
        ],
        "products": [
          {
            "vendor": "strangerstudios",
            "product": "Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05248
      },
      "nvd": {
        "published": "2026-07-28T13:17:34.150",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15016",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In the affected component, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/02e3f64c-1076-4247-9ee5-c1105edcfb39?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.paidmembershipspro.com/category/release-notes/",
          "host": "www.paidmembershipspro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 517,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15017",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T23:18:19.998Z",
      "date_published": "2026-07-23T09:33:56.808Z",
      "date_updated": "2026-07-23T14:00:37.667Z",
      "publisher": "Wordfence",
      "title": "MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' Handlers",
      "affected": {
        "vendors": [
          "mdjm"
        ],
        "products": [
          {
            "vendor": "mdjm",
            "product": "MDJM Event Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28915
      },
      "nvd": {
        "published": "2026-07-23T10:16:50.173",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15017",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Public role-management handlers omit authentication, nonce, capability, and role-allowlist checks before assigning WordPress roles.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2a691f92-9eff-4777-8198-b7cc5d9e73c0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.4/includes/employee-functions.php#L789",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.4/includes/admin/users/class-mdjm-employee-manager.php#L406",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.4/includes/admin/roles/class-mdjm-permissions.php#L24",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.4/includes/admin/roles/class-mdjm-permissions.php#L36",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mobile-dj-manager/tags/1.7.8.4/mobile-dj-manager.php#L107",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 947,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15021",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T00:57:49.863Z",
      "date_published": "2026-07-16T08:26:50.097Z",
      "date_updated": "2026-07-16T13:40:50.799Z",
      "publisher": "Wordfence",
      "title": "wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field",
      "affected": {
        "vendors": [
          "tomdever"
        ],
        "products": [
          {
            "vendor": "tomdever",
            "product": "wpForo Forum"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10765
      },
      "nvd": {
        "published": "2026-07-16T09:16:17.323",
        "lastModified": "2026-07-16T14:16:48.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15021",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A profile location value can break out of an href attribute because sanitize_text_field does not encode quotes and the output lacks attribute-context escaping.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2cd364c5-c053-4c50-8232-bb47ab8e834b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforo/tags/3.1.1/classes/Forms.php#L1035",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforo/tags/3.1.1/classes/Members.php#L1031",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforo/tags/3.1.1/classes/Forms.php#L1074",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforo/tags/3.0.5/classes/Forms.php#L1035",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforo/tags/3.0.5/classes/Members.php#L1031",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforo/tags/3.0.5/classes/Forms.php#L1074",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3603849%40wpforo&new=3603849%40wpforo",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 612,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15022",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T01:06:09.509Z",
      "date_published": "2026-07-16T07:51:03.751Z",
      "date_updated": "2026-07-18T02:43:25.272Z",
      "publisher": "Wordfence",
      "title": "Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array",
      "affected": {
        "vendors": [
          "themeum"
        ],
        "products": [
          {
            "vendor": "themeum",
            "product": "Tutor LMS – eLearning and online course solution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00341,
        "percentile": 0.26709
      },
      "nvd": {
        "published": "2026-07-16T09:16:17.440",
        "lastModified": "2026-07-18T03:16:34.913",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15022",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Tutor LMS – eLearning and online course solution data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8cd603aa-c4d4-488c-b134-6983240c3a18?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.13/restapi/REST_Quiz.php#L415",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.13/restapi/REST_Quiz.php#L384",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.13/restapi/REST_Quiz.php#L286",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.13/classes/Quiz.php#L626",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.13/classes/Quiz.php#L442",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.13/helpers/QueryHelper.php#L951",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.9/restapi/REST_Quiz.php#L415",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.9/restapi/REST_Quiz.php#L384",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.9/restapi/REST_Quiz.php#L286",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.9/classes/Quiz.php#L626",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.9/classes/Quiz.php#L442",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/3.9.9/helpers/QueryHelper.php#L951",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 821,
        "referenceCount": 13,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15025",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T01:19:36.329Z",
      "date_published": "2026-07-28T11:32:46.907Z",
      "date_updated": "2026-07-28T13:27:18.525Z",
      "publisher": "Wordfence",
      "title": "Uncanny Automator <= 7.3.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints",
      "affected": {
        "vendors": [
          "uncannyowl"
        ],
        "products": [
          {
            "vendor": "uncannyowl",
            "product": "Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00514,
        "percentile": 0.40959
      },
      "nvd": {
        "published": "2026-07-28T12:16:35.490",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15025",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Subscriber-accessible AJAX endpoints return integration metadata without a capability check or request nonce.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1bfa1538-7722-458d-a6a5-adde03e21e1a?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/google-contacts/helpers/google-contacts-helper.php#L113",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/google-contacts/google-contacts-integration.php#L70",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/mautic/helpers/mautic-app-helpers.php#L199",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/mautic/helpers/mautic-app-helpers.php#L250",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/mautic/helpers/mautic-app-helpers.php#L302",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.3.1.4/src/integrations/mautic/mautic-integration.php#L60",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/google-contacts/helpers/google-contacts-helper.php#L113",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/google-contacts/google-contacts-integration.php#L70",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/mautic/helpers/mautic-app-helpers.php#L199",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/mautic/helpers/mautic-app-helpers.php#L250",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/mautic/helpers/mautic-app-helpers.php#L302",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/uncanny-automator/tags/7.2.1/src/integrations/mautic/mautic-integration.php#L60",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3607785%40uncanny-automator&new=3607785%40uncanny-automator",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 827,
        "referenceCount": 14,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15026",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T01:25:12.489Z",
      "date_published": "2026-07-10T08:30:39.714Z",
      "date_updated": "2026-07-10T14:04:54.607Z",
      "publisher": "Wordfence",
      "title": "Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action",
      "affected": {
        "vendors": [
          "carazo"
        ],
        "products": [
          {
            "vendor": "carazo",
            "product": "Import and export users and customers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.12997
      },
      "nvd": {
        "published": "2026-07-10T09:16:53.277",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15026",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Import and export users and customers operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/85b61e0f-3bb2-4688-b513-14f4d2da6c30?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.3.9/classes/email-templates.php#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.3.9/classes/email-templates.php#L9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.3.9/classes/email-options.php#L357",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.10/classes/email-templates.php#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.10/classes/email-templates.php#L9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.10/classes/email-options.php#L357",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3601455%40import-users-from-csv-with-meta&new=3601455%40import-users-from-csv-with-meta",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 755,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15028",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T07:04:37.243Z",
      "date_published": "2026-07-10T09:55:49.895Z",
      "date_updated": "2026-07-15T09:15:19.559Z",
      "publisher": "redhat",
      "title": "Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10445
      },
      "nvd": {
        "published": "2026-07-10T10:16:23.417",
        "lastModified": "2026-07-15T10:16:45.283",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15028",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libarchive parses a malformed SUN.holesdata PAX sparse-file attribute into writes beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38279",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15028",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497970",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/libarchive/libarchive/issues/3251",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/libarchive/libarchive/pull/3253",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 464,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15029",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T07:18:44.846Z",
      "date_published": "2026-07-15T02:01:33.203Z",
      "date_updated": "2026-07-15T14:23:38.260Z",
      "publisher": "ASUS",
      "title": "Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL req...",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "System Control Interface v3"
          },
          {
            "vendor": "ASUS",
            "product": "System Control Interface"
          },
          {
            "vendor": "ASUS",
            "product": "Business Manager"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-822",
          "name": "Untrusted Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03368
      },
      "nvd": {
        "published": "2026-07-15T02:18:13.033",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15029",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections.",
        "basis": [
          "CNA",
          "CWE-822"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 428,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15030",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T07:18:46.459Z",
      "date_published": "2026-07-15T02:01:24.038Z",
      "date_updated": "2026-07-15T14:24:06.901Z",
      "publisher": "ASUS",
      "title": "Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL reque...",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "System Control Interface v3"
          },
          {
            "vendor": "ASUS",
            "product": "System Control Interface"
          },
          {
            "vendor": "ASUS",
            "product": "Business Manager"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01569
      },
      "nvd": {
        "published": "2026-07-15T02:18:13.173",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15030",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ASUS interface reads beyond the intended firmware buffer after a crafted IOCTL bypasses its boundary validation.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15033",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T07:36:46.092Z",
      "date_published": "2026-07-08T13:15:07.664Z",
      "date_updated": "2026-07-08T17:08:58.946Z",
      "publisher": "VulDB",
      "title": "christopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec os command injection",
      "affected": {
        "vendors": [
          "christopherthielen"
        ],
        "products": [
          {
            "vendor": "christopherthielen",
            "product": "check-peer-dependencies"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.01067,
        "percentile": 0.6148
      },
      "nvd": {
        "published": "2026-07-08T14:16:56.273",
        "lastModified": "2026-07-08T18:16:32.257",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15033",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler places caller-controlled data in an operating-system command without safe argument separation.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376784",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376784/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15033",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850875",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/christopherthielen/check-peer-dependencies/issues/74",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/christopherthielen/check-peer-dependencies/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-15034",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T07:38:11.295Z",
      "date_published": "2026-07-08T13:30:08.187Z",
      "date_updated": "2026-07-08T14:21:20.699Z",
      "publisher": "VulDB",
      "title": "flask-dashboard Flask-MonitoringDashboard cross-site request forgery",
      "affected": {
        "vendors": [
          "flask-dashboard"
        ],
        "products": [
          {
            "vendor": "flask-dashboard",
            "product": "Flask-MonitoringDashboard"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12846
      },
      "nvd": {
        "published": "2026-07-08T14:16:56.460",
        "lastModified": "2026-07-08T15:16:25.730",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15034",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The record identifies a cross-site request forgery in Flask-MonitoringDashboard, but does not publish the state-changing action or missing request check.",
        "basis": [
          "CNA",
          "CWE-352",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376785",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376785/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15034",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850877",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850878",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850879",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850880",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/flask-dashboard/Flask-MonitoringDashboard/issues/557",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/flask-dashboard/Flask-MonitoringDashboard/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 393,
        "referenceCount": 9,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15035",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T07:41:07.309Z",
      "date_published": "2026-07-08T14:00:09.786Z",
      "date_updated": "2026-07-08T14:20:35.536Z",
      "publisher": "VulDB",
      "title": "bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection",
      "affected": {
        "vendors": [
          "bentoml"
        ],
        "products": [
          {
            "vendor": "bentoml",
            "product": "OpenLLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 5.9,
      "epss": {
        "score": 0.01545,
        "percentile": 0.72528
      },
      "nvd": {
        "published": "2026-07-08T14:16:56.643",
        "lastModified": "2026-07-09T15:54:06.390",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15035",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application places attacker-controlled data into an operating-system command without separating the data from command syntax.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376786",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376786/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15035",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850895",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/bentoml/OpenLLM/issues/1229",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Third Party Advisory",
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/bentoml/OpenLLM/pull/1235",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/bentoml/OpenLLM/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 7,
        "cweCount": 3,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 8,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15036",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T07:46:03.631Z",
      "date_published": "2026-07-08T14:30:07.802Z",
      "date_updated": "2026-07-08T15:38:36.035Z",
      "publisher": "VulDB",
      "title": "Harness gitspaces Endpoint list_all.go getAuthorizedSpaces authorization",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "Harness"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14953
      },
      "nvd": {
        "published": "2026-07-08T15:16:25.970",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15036",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Harness resolves a caller-controlled object identifier without binding the selected object to the caller's authorized scope.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376787",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376787/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15036",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851013",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/harness/harness/issues/3689",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/harness/harness/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 458,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15037",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T08:35:17.940Z",
      "date_published": "2026-07-23T12:33:11.068Z",
      "date_updated": "2026-07-23T14:45:39.734Z",
      "publisher": "TQtC",
      "title": "XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization",
      "affected": {
        "vendors": [
          "Qt"
        ],
        "products": [
          {
            "vendor": "Qt",
            "product": "Qt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-91",
          "name": "XML Injection (aka Blind XPath Injection)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "NVD:a59d8014-47c4-4630-ab43-e1b13cbe58e3",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17871
      },
      "nvd": {
        "published": "2026-07-23T13:16:25.730",
        "lastModified": "2026-07-23T15:25:49.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15037",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "QDom serializes comment, CDATA, and processing-instruction text without neutralizing node terminators, so text can become XML markup.",
        "basis": [
          "CNA",
          "CWE-91"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://codereview.qt-project.org/c/qt/qtbase/+/748323",
          "host": "codereview.qt-project.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15041",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T10:00:02.126Z",
      "date_published": "2026-07-08T10:15:30.480Z",
      "date_updated": "2026-07-08T13:44:19.153Z",
      "publisher": "redhat",
      "title": "389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 11"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 12"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 13"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22283
      },
      "nvd": {
        "published": "2026-07-08T11:16:26.260",
        "lastModified": "2026-07-09T19:36:15.370",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15041",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Password verification compares PBKDF2 hashes with timing-variable memcmp rather than a constant-time comparison.",
        "basis": [
          "CNA",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15041",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498022",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15043",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T11:48:00.718Z",
      "date_published": "2026-07-14T09:44:25.733Z",
      "date_updated": "2026-07-14T15:32:33.329Z",
      "publisher": "CPANSec",
      "title": "DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text",
      "affected": {
        "vendors": [
          "HMBRAND"
        ],
        "products": [
          {
            "vendor": "HMBRAND",
            "product": "DBI::SQL::Nano"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-480",
          "name": "Use of Incorrect Operator",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.31435
      },
      "nvd": {
        "published": "2026-07-14T10:16:31.253",
        "lastModified": "2026-07-14T16:44:28.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15043",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DBI::SQL::Nano implements text less-than-or-equal with ge and greater-than-or-equal with le, reversing the result of those predicates.",
        "basis": [
          "CNA",
          "CWE-480"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mv45-ff6j-x9jp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://metacpan.org/release/HMBRAND/DBI-1.651/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/perl5-dbi/dbi/commit/e9742ef85a75867cbd696860e3bf3e32b681f98d.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/14/9",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 802,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15044",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T12:13:56.870Z",
      "date_published": "2026-07-08T14:37:22.054Z",
      "date_updated": "2026-07-14T13:36:08.063Z",
      "publisher": "redhat",
      "title": "Trustyai-service-operator: trustyai service operator: unauthenticated access to ai guardrails and orchestrator apis",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift AI (RHOAI)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06622
      },
      "nvd": {
        "published": "2026-07-08T15:16:26.120",
        "lastModified": "2026-07-14T14:16:32.897",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15044",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "When the documented security setting is disabled, deployed guardrail and orchestrator services expose cluster communication channels without authentication.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15044",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498039",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 518,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15048",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T12:48:56.997Z",
      "date_published": "2026-07-31T06:00:09.466Z",
      "date_updated": "2026-07-31T19:48:41.603Z",
      "publisher": "WPScan",
      "title": "GeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat History",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Geeky Bot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17147
      },
      "nvd": {
        "published": "2026-07-31T07:16:26.827",
        "lastModified": "2026-07-31T20:16:47.790",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15048",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An AJAX action returns chat-session metadata without checking whether the requester is authorized to see it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/881d1548-e6c3-4093-ab8c-dc3a9fcccc34/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 242,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15053",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:33:20.588Z",
      "date_published": "2026-07-08T13:46:40.902Z",
      "date_updated": "2026-07-08T14:27:37.033Z",
      "publisher": "Tanium",
      "title": "Tanium addressed a denial of service vulnerability in Tanium Server.",
      "affected": {
        "vendors": [
          "Tanium"
        ],
        "products": [
          {
            "vendor": "Tanium",
            "product": "Tanium Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:3938794e-25f5-4123-a1ba-5cbd7f104512",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33103
      },
      "nvd": {
        "published": "2026-07-08T14:16:56.930",
        "lastModified": "2026-07-10T19:00:47.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15053",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The record attributes denial of service to an excessive allocation condition but does not identify the attacker-controlled size or allocation site.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.tanium.com/TAN-2026-016",
          "host": "security.tanium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 68,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15054",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:35:44.530Z",
      "date_published": "2026-07-30T06:00:07.103Z",
      "date_updated": "2026-07-30T18:30:31.329Z",
      "publisher": "WPScan",
      "title": "Bit Form < 3.1.2 - Unauthenticated Inactive Form Submission",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Bit Form"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10161
      },
      "nvd": {
        "published": "2026-07-30T06:25:01.193",
        "lastModified": "2026-07-30T19:17:07.953",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15054",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Bit Form fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/ca7f4309-d546-4f6b-a973-cf47a455fc8f/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15057",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:47:02.097Z",
      "date_published": "2026-07-28T20:11:58.843Z",
      "date_updated": "2026-07-29T13:58:41.586Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17997
      },
      "nvd": {
        "published": "2026-07-28T21:17:27.367",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15057",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Liberty service permits attacker-influenced heap allocation without an effective bound until memory exhaustion denies service.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280126",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15058",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:55:05.553Z",
      "date_published": "2026-07-14T18:11:10.858Z",
      "date_updated": "2026-07-15T14:46:13.929Z",
      "publisher": "DEVOLUTIONS",
      "title": "Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05867
      },
      "nvd": {
        "published": "2026-07-14T19:16:50.817",
        "lastModified": "2026-07-30T14:57:33.110",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15058",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Server accepts a caller-supplied object identifier without binding the selected object to the caller's ownership or authorized scope.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0024/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15062",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T14:26:38.459Z",
      "date_published": "2026-07-08T14:32:12.165Z",
      "date_updated": "2026-07-08T15:18:02.740Z",
      "publisher": "SNOWFLAKE",
      "title": "SQL Injection in Snowflake Snowpark Python SDK",
      "affected": {
        "vendors": [
          "Snowflake"
        ],
        "products": [
          {
            "vendor": "Snowflake",
            "product": "Snowpark Python SDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:412d305a-227d-44f9-a262-a31ba44f2aea",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.2072
      },
      "nvd": {
        "published": "2026-07-08T15:16:26.320",
        "lastModified": "2026-07-09T16:39:17.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15062",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Snowpark composes SQL from database column names, COPY locations, or export paths without correctly separating those values from SQL syntax.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/snowflakedb/snowpark-python/blob/main/CHANGELOG.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 815,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15063",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T14:31:24.772Z",
      "date_published": "2026-07-08T14:58:12.105Z",
      "date_updated": "2026-07-08T15:56:34.556Z",
      "publisher": "redhat",
      "title": "Trustyai-service-operator: trustyai service operator: gorch port bypass when auth is enabled",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift AI (RHOAI)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08263
      },
      "nvd": {
        "published": "2026-07-08T16:16:27.723",
        "lastModified": "2026-07-09T16:39:17.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15063",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The gorch service template exposes metrics ports directly instead of placing them behind the configured authentication proxy.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15063",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498058",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15064",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T14:31:56.928Z",
      "date_published": "2026-07-28T20:10:16.529Z",
      "date_updated": "2026-07-30T03:55:29.367Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          },
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12582
      },
      "nvd": {
        "published": "2026-07-28T21:17:27.493",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15064",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebSphere accepts non-standard HTTP version tokens in a way that lets intermediaries disagree about the response boundary.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281625",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15067",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T14:39:47.802Z",
      "date_published": "2026-07-08T14:43:32.006Z",
      "date_updated": "2026-07-08T15:19:35.970Z",
      "publisher": "SNOWFLAKE",
      "title": "Multiple Security Vulnerabilities in Terraform Provider for Snowflake Could Allow Privilege Escalation and Unauthorized Snowflake Account Takeover",
      "affected": {
        "vendors": [
          "Snowflake"
        ],
        "products": [
          {
            "vendor": "Snowflake",
            "product": "Terraform Provider for Snowflake"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:412d305a-227d-44f9-a262-a31ba44f2aea",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29791
      },
      "nvd": {
        "published": "2026-07-08T15:16:26.433",
        "lastModified": "2026-07-09T16:39:17.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15067",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper neutralization of identifier content in user resource inputs could allow DDL injection into user management statements, potentially causing accounts to be created with attacker-controlled credentials and without the security controls configured by the operator.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/snowflakedb/terraform-provider-snowflake/releases",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 847,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15069",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T14:46:51.365Z",
      "date_published": "2026-07-17T19:40:48.285Z",
      "date_updated": "2026-07-20T13:52:29.108Z",
      "publisher": "ibm",
      "title": "Multiple Vulnerabilities in IBM Engineering AI hub.",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Engineering AI Hub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07489
      },
      "nvd": {
        "published": "2026-07-17T20:17:15.450",
        "lastModified": "2026-07-24T16:24:12.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15069",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input during web page generation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279964",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 177,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15070",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:04:03.967Z",
      "date_published": "2026-07-10T03:31:12.552Z",
      "date_updated": "2026-07-10T15:24:41.007Z",
      "publisher": "Wordfence",
      "title": "Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter",
      "affected": {
        "vendors": [
          "wordpresschef"
        ],
        "products": [
          {
            "vendor": "wordpresschef",
            "product": "Salon Booking System – Free Version"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17473
      },
      "nvd": {
        "published": "2026-07-10T04:17:47.727",
        "lastModified": "2026-07-10T16:16:25.573",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15070",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A forged cross-site request reaches setCustomText(), which interpolates insufficiently sanitized input into a web-accessible PHP file.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/301ad19a-f99c-45c8-83a7-d74e1a260556?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/salon-booking-system/tags/10.30.32/src/SLN/Settings.php#L335",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/salon-booking-system/tags/10.30.32/src/SLN/Action/Ajax/SetCustomText.php#L17",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/salon-booking-system/tags/10.30.32/src/SLN/Plugin.php#L407",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/salon-booking-system/tags/10.30.32/src/SLN/Action/Init.php#L628",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3600791%40salon-booking-system&new=3600791%40salon-booking-system",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 859,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15072",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:10:15.367Z",
      "date_published": "2026-07-11T02:31:18.884Z",
      "date_updated": "2026-07-13T16:14:20.964Z",
      "publisher": "Wordfence",
      "title": "KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder",
      "affected": {
        "vendors": [
          "iqonicdesign"
        ],
        "products": [
          {
            "vendor": "iqonicdesign",
            "product": "KiviCare – Clinic & Patient Management System (EHR)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19497
      },
      "nvd": {
        "published": "2026-07-11T04:17:19.953",
        "lastModified": "2026-07-13T17:17:02.500",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15072",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e2857fd0-2401-4e38-aa8a-3f0a89e14b78?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/controllers/api/DoctorSessionController.php#L1282",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/baseClasses/KCQueryBuilder.php#L470",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/controllers/api/DoctorSessionController.php#L1208",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/baseClasses/KCQueryBuilder.php#L245",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/baseClasses/KCQueryBuilder.php#L1283",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/controllers/api/DoctorSessionController.php#L87",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3602561%40kivicare-clinic-management-system&new=3602561%40kivicare-clinic-management-system",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 697,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15073",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:11:08.472Z",
      "date_published": "2026-07-11T02:31:16.800Z",
      "date_updated": "2026-07-15T13:50:23.082Z",
      "publisher": "Wordfence",
      "title": "KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in DoctorSessionController",
      "affected": {
        "vendors": [
          "iqonicdesign"
        ],
        "products": [
          {
            "vendor": "iqonicdesign",
            "product": "KiviCare – Clinic & Patient Management System (EHR)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15417
      },
      "nvd": {
        "published": "2026-07-11T04:17:21.943",
        "lastModified": "2026-07-15T14:17:17.597",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15073",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4f5ff7bc-9443-4b34-abd3-dac800f162a1?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/controllers/api/DoctorSessionController.php#L660",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/controllers/api/DoctorSessionController.php#L648",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kivicare-clinic-management-system/tags/4.5.0/app/baseClasses/KCQueryBuilder.php#L470",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3602561%40kivicare-clinic-management-system&new=3602561%40kivicare-clinic-management-system",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 719,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15074",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:21:49.362Z",
      "date_published": "2026-07-23T03:01:47.887Z",
      "date_updated": "2026-07-23T14:14:46.933Z",
      "publisher": "openjs",
      "title": "@fastify/static vulnerable to route guard bypass via path traversal",
      "affected": {
        "vendors": [
          "@fastify/static"
        ],
        "products": [
          {
            "vendor": "@fastify/static",
            "product": "@fastify/static"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00448,
        "percentile": 0.36792
      },
      "nvd": {
        "published": "2026-07-23T04:16:31.980",
        "lastModified": "2026-07-28T17:02:14.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15074",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "@fastify/static lets dot segments reach normalization after route middleware, allowing a request to bypass a guarded URL prefix while remaining inside the configured static root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fastify/fastify-static/security/advisories/GHSA-83w8-p2f5-377r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 659,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15075",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:22:44.892Z",
      "date_published": "2026-07-14T08:15:53.650Z",
      "date_updated": "2026-07-14T12:18:54.815Z",
      "publisher": "eclipse",
      "title": "In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only Content-Length is stripped; ...",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Vert.x"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00144,
        "percentile": 0.0416
      },
      "nvd": {
        "published": "2026-07-14T09:16:40.180",
        "lastModified": "2026-07-14T20:53:50.973",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15075",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The redirect handler copies credentials and custom headers to a cross-origin redirect target without comparing scheme, host, and port.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/161",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 883,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15076",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:26:03.652Z",
      "date_published": "2026-07-14T08:09:12.951Z",
      "date_updated": "2026-07-14T12:20:29.616Z",
      "publisher": "eclipse",
      "title": "In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that the Domain attribute of a Set-Cookie response header matches the originating s...",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Vert.x"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05329
      },
      "nvd": {
        "published": "2026-07-14T09:16:40.313",
        "lastModified": "2026-07-14T20:53:32.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15076",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cookie handling accepts a Set-Cookie Domain that is not constrained to the response origin, enabling cross-domain cookie injection.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/162",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1008,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15077",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:36:58.778Z",
      "date_published": "2026-07-29T19:00:11.047Z",
      "date_updated": "2026-07-29T19:33:20.717Z",
      "publisher": "GitLab",
      "title": "Improper Neutralization of Input Used for LLM Prompting in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-1427",
          "name": "Improper Neutralization of Input Used for LLM Prompting",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16472
      },
      "nvd": {
        "published": "2026-07-29T20:17:01.690",
        "lastModified": "2026-08-03T13:26:04.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15077",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The AI-assisted review path processes untrusted project content as LLM instructions, allowing it to retrieve data from unauthorized projects.",
        "basis": [
          "CNA record",
          "CWE-1427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/601482",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 341,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15079",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:44:53.333Z",
      "date_published": "2026-07-10T21:46:19.486Z",
      "date_updated": "2026-07-13T17:50:54.026Z",
      "publisher": "drupal",
      "title": "Login Disable - Moderately critical - Access bypass - SA-CONTRIB-2026-070",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Login Disable"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11184
      },
      "nvd": {
        "published": "2026-07-10T22:16:40.627",
        "lastModified": "2026-07-13T18:16:27.023",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15079",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Login Disable allows authentication attempts without an effective retry or throttling limit.",
        "basis": [
          "CNA",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-070",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15080",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:44:54.212Z",
      "date_published": "2026-07-10T21:46:20.380Z",
      "date_updated": "2026-07-13T17:52:19.827Z",
      "publisher": "drupal",
      "title": "Ray Enterprise Translation - Moderately critical - Cross site request forgery - SA-CONTRIB-2026-071",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Ray Enterprise Translation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01985
      },
      "nvd": {
        "published": "2026-07-10T22:16:40.730",
        "lastModified": "2026-07-13T19:16:46.310",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15080",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The translation action accepts a state-changing cross-site request under the victim's authenticated browser session.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-071",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:44:55.221Z",
      "date_published": "2026-07-10T21:46:21.263Z",
      "date_updated": "2026-07-13T18:16:23.908Z",
      "publisher": "drupal",
      "title": "Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Location Selector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.1728
      },
      "nvd": {
        "published": "2026-07-10T22:16:40.827",
        "lastModified": "2026-07-13T19:16:47.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15081",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Location Selector, attacker-controlled input reaches an SQL statement without the required parameter binding or SQL-context escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-072",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:44:56.251Z",
      "date_published": "2026-07-10T21:46:22.143Z",
      "date_updated": "2026-07-13T18:15:30.655Z",
      "publisher": "drupal",
      "title": "Siteimprove Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-073",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Siteimprove Analytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05783
      },
      "nvd": {
        "published": "2026-07-10T22:16:40.923",
        "lastModified": "2026-07-13T19:16:47.817",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15082",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-073",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15083",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:44:57.178Z",
      "date_published": "2026-07-10T21:46:33.886Z",
      "date_updated": "2026-07-13T18:18:06.766Z",
      "publisher": "drupal",
      "title": "ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "ECA: Event - Condition - Action"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07267
      },
      "nvd": {
        "published": "2026-07-10T22:16:41.030",
        "lastModified": "2026-07-13T19:16:48.497",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15083",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ECA permits attacker-controlled modification of dynamically selected object attributes, allowing unintended object state to be injected.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-074",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 285,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15084",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:44:58.126Z",
      "date_published": "2026-07-10T21:46:34.771Z",
      "date_updated": "2026-07-13T18:14:56.574Z",
      "publisher": "drupal",
      "title": "UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-075",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "UI Patterns (SDC in Drupal UI)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05784
      },
      "nvd": {
        "published": "2026-07-10T22:16:41.127",
        "lastModified": "2026-07-13T19:16:49.187",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15084",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The UI Patterns (SDC in Drupal UI) rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-075",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:44:59.219Z",
      "date_published": "2026-07-10T21:46:35.632Z",
      "date_updated": "2026-07-13T18:25:09.171Z",
      "publisher": "drupal",
      "title": "AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-076",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "AI SEO/GEO Analyzer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05783
      },
      "nvd": {
        "published": "2026-07-10T22:16:41.230",
        "lastModified": "2026-07-13T19:16:49.860",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15085",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Stored attacker input is emitted into a page without the context-specific escaping needed to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-076",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15086",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:45:00.086Z",
      "date_published": "2026-07-10T21:57:19.321Z",
      "date_updated": "2026-07-13T19:09:51.778Z",
      "publisher": "drupal",
      "title": "Raw Formatter [Meta Tag Formatter] - Critical - Unsupported - SA-CONTRIB-2026-077",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Raw Formatter [Meta Tag Formatter]"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19841
      },
      "nvd": {
        "published": "2026-07-10T23:16:47.330",
        "lastModified": "2026-07-13T20:16:43.430",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15086",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Drupal record supplies no technical description, structured weakness, or affected operation from which an engineering cause can be assigned.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-077",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 1,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15087",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:45:01.154Z",
      "date_published": "2026-07-10T21:57:28.467Z",
      "date_updated": "2026-07-13T19:07:49.334Z",
      "publisher": "drupal",
      "title": "Clean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Clean RESTful"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15669
      },
      "nvd": {
        "published": "2026-07-10T23:16:47.430",
        "lastModified": "2026-07-13T20:16:44.107",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15087",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Clean RESTful record identifies an authentication failure but does not disclose the protected route, credential decision, or failing check.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-078",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15089",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:45:03.255Z",
      "date_published": "2026-07-10T21:54:42.802Z",
      "date_updated": "2026-07-13T18:52:33.757Z",
      "publisher": "drupal",
      "title": "Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Commerce guest registration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22055
      },
      "nvd": {
        "published": "2026-07-10T23:16:47.533",
        "lastModified": "2026-07-13T19:16:50.537",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15089",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Drupal confirms a known security issue in every Commerce guest registration release, but neither the malformed CVE text nor the unsupported-project advisory identifies the failing authentication step.",
        "basis": [
          "CNA",
          "CWE-287",
          "Drupal SA-CONTRIB-2026-079"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.drupal.org/sa-contrib-2026-079. Drupal marks the entire Commerce guest registration project unsupported because of a known unfixed security issue and directs users to uninstall it, but publishes no authentication path or exploit mechanism."
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-079",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15091",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T16:07:31.099Z",
      "date_published": "2026-07-17T19:38:58.436Z",
      "date_updated": "2026-07-20T15:16:23.830Z",
      "publisher": "ibm",
      "title": "Multiple Vulnerabilities in IBM Engineering AI hub.",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Engineering AI Hub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24497
      },
      "nvd": {
        "published": "2026-07-17T20:17:15.567",
        "lastModified": "2026-07-24T16:41:43.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15091",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Engineering AI Hub renders attacker-controlled input as active browser script without HTML-context neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279964",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 173,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15093",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T16:10:36.076Z",
      "date_published": "2026-07-17T19:37:57.768Z",
      "date_updated": "2026-07-17T23:15:12.887Z",
      "publisher": "ibm",
      "title": "Multiple Vulnerabilities in IBM Engineering AI hub.",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Engineering AI Hub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11941
      },
      "nvd": {
        "published": "2026-07-17T20:17:15.680",
        "lastModified": "2026-07-24T16:41:48.647",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15093",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279964",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 166,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15094",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T16:26:57.732Z",
      "date_published": "2026-07-17T05:35:59.119Z",
      "date_updated": "2026-07-17T18:05:35.202Z",
      "publisher": "Wordfence",
      "title": "WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter",
      "affected": {
        "vendors": [
          "thimpress"
        ],
        "products": [
          {
            "vendor": "thimpress",
            "product": "WP Hotel Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00511,
        "percentile": 0.40775
      },
      "nvd": {
        "published": "2026-07-17T06:16:36.367",
        "lastModified": "2026-07-17T19:17:12.747",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15094",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8139f512-7bc9-45ae-83d7-bf496e1ad56d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.2/includes/TemplateHooks/ArchiveRoomTemplate.php#L262",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.2/includes/TemplateHooks/ArchiveRoomTemplate.php#L54",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.2/includes/wphb-functions.php#L733",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.2/includes/class-wphb-helpers.php#L29",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3609563%40wp-hotel-booking&new=3609563%40wp-hotel-booking",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 426,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15096",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T16:35:12.903Z",
      "date_published": "2026-07-11T03:44:23.435Z",
      "date_updated": "2026-07-13T16:13:09.307Z",
      "publisher": "Wordfence",
      "title": "Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field",
      "affected": {
        "vendors": [
          "themifyme"
        ],
        "products": [
          {
            "vendor": "themifyme",
            "product": "Themify Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08635
      },
      "nvd": {
        "published": "2026-07-11T05:16:32.670",
        "lastModified": "2026-07-13T17:17:03.153",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15096",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/72131ba4-976b-4f89-9a69-2469f22eb5fd?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.6/templates/template-map.php#L143",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.6/classes/class-themify-builder-active.php#L559",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.6/classes/class-builder-data-manager.php#L154",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3601964%40themify-builder&new=3601964%40themify-builder",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15097",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T16:36:53.355Z",
      "date_published": "2026-07-11T03:44:20.706Z",
      "date_updated": "2026-07-15T13:47:50.221Z",
      "publisher": "Wordfence",
      "title": "Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field",
      "affected": {
        "vendors": [
          "themifyme"
        ],
        "products": [
          {
            "vendor": "themifyme",
            "product": "Themify Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09474
      },
      "nvd": {
        "published": "2026-07-11T05:16:32.793",
        "lastModified": "2026-07-15T14:17:17.713",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15097",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Themify Builder page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/03721b29-7b26-4166-bba1-81614b412a09?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.6/templates/template-slider.php#L107",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.6/classes/class-themify-builder-active.php#L559",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.6/classes/class-builder-data-manager.php#L154",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.6/classes/class-builder-data-manager.php#L402",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3601964%40themify-builder&new=3601964%40themify-builder",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15099",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T16:46:19.078Z",
      "date_published": "2026-07-16T07:51:00.702Z",
      "date_updated": "2026-07-16T12:36:15.407Z",
      "publisher": "Wordfence",
      "title": "WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'steps' Block Attribute",
      "affected": {
        "vendors": [
          "wpdelicious"
        ],
        "products": [
          {
            "vendor": "wpdelicious",
            "product": "WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09239
      },
      "nvd": {
        "published": "2026-07-16T09:16:17.557",
        "lastModified": "2026-07-16T13:38:53.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15099",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A nested block href is interpolated into an anchor without URL validation or escaping, permitting a javascript scheme.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4a89c812-a643-47c0-bd33-cfb2389a7646?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/delicious-recipes/tags/1.10.2/src/blocks/dynamic-blocks/class-delicious-dynamic-recipe-card.php#L1627",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/delicious-recipes/tags/1.10.2/src/blocks/dynamic-blocks/class-delicious-dynamic-recipe-card.php#L363",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/delicious-recipes/tags/1.10.2/src/blocks/dynamic-blocks/class-delicious-dynamic-recipe-card.php#L1288",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3605415/delicious-recipes",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 785,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15100",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T16:48:20.982Z",
      "date_published": "2026-07-24T02:31:58.268Z",
      "date_updated": "2026-07-24T14:23:09.985Z",
      "publisher": "Wordfence",
      "title": "Post Grid Gutenberg Blocks <= 5.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'searchnoresult' Block Attribute",
      "affected": {
        "vendors": [
          "wpxpo"
        ],
        "products": [
          {
            "vendor": "wpxpo",
            "product": "Post Grid Gutenberg Blocks – PostX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09239
      },
      "nvd": {
        "published": "2026-07-24T04:16:51.680",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15100",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PostX block renders the searchnoresult attribute without sufficient input sanitization and output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1f645d0c-d641-4fff-a4f4-33c037de30e9?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-post/tags/5.0.32/blocks/Advanced_Search.php#L116",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-post/tags/5.0.32/blocks/Advanced_Search.php#L107",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-post/tags/5.0.32/classes/Blocks.php#L231",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3613430%40ultimate-post&new=3613430%40ultimate-post",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 715,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T16:58:02.760Z",
      "date_published": "2026-07-16T08:26:50.831Z",
      "date_updated": "2026-07-16T15:11:22.220Z",
      "publisher": "Wordfence",
      "title": "WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter",
      "affected": {
        "vendors": [
          "getwpfunnels"
        ],
        "products": [
          {
            "vendor": "getwpfunnels",
            "product": "WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23348
      },
      "nvd": {
        "published": "2026-07-16T09:16:17.677",
        "lastModified": "2026-07-16T16:19:00.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15103",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The settings route accepts any group_id as an option name and writes it without restricting the caller to safe plugin options, allowing wp_user_roles to be replaced.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/76ad6d21-f277-496f-aa6b-f9d5cb8a3801?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.8/includes/core/rest-api/Controllers/class-settings-controller.php#L462",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.8/includes/core/rest-api/Controllers/class-settings-controller.php#L66",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.8/includes/core/rest-api/Controllers/class-settings-controller.php#L40",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.8/includes/utils/class-wpfnl-functions.php#L1216",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3607181%40wpfunnels&new=3607181%40wpfunnels",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1050,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15104",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:03:33.248Z",
      "date_published": "2026-07-10T07:48:40.039Z",
      "date_updated": "2026-07-10T17:59:24.023Z",
      "publisher": "Wordfence",
      "title": "BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' Parameter",
      "affected": {
        "vendors": [
          "wpdevteam"
        ],
        "products": [
          {
            "vendor": "wpdevteam",
            "product": "BetterDocs –  AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15384
      },
      "nvd": {
        "published": "2026-07-10T09:16:53.407",
        "lastModified": "2026-07-10T19:17:20.210",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15104",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The BetterDocs –  AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot query path incorporates attacker-controlled input into SQL without parameter separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/05dbb5f4-b73b-46b4-9177-ba1d36fe0ee7?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/betterdocs/tags/4.6.0/includes/Core/PostType.php#L819",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/betterdocs/tags/4.6.0/includes/Utils/Helper.php#L344",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/betterdocs/tags/4.6.0/includes/Core/PostType.php#L767",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3601408%40betterdocs&new=3601408%40betterdocs",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 761,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15105",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:19.722Z",
      "date_published": "2026-07-08T22:15:12.176Z",
      "date_updated": "2026-08-01T14:56:11.532Z",
      "publisher": "VulDB",
      "title": "davenardella snap7 ReadVar Request s7_server.cpp PerformFunctionRead out-of-bounds write",
      "affected": {
        "vendors": [
          "davenardella"
        ],
        "products": [
          {
            "vendor": "davenardella",
            "product": "snap7"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:A/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:A/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 4.199999999999999,
      "epss": {
        "score": 0.00265,
        "percentile": 0.1826
      },
      "nvd": {
        "published": "2026-07-08T23:16:51.600",
        "lastModified": "2026-08-01T15:16:33.887",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15105",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The snap7 ReadVar handler writes past the destination buffer while processing a crafted request.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376946",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376946/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15105",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851026",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/davenardella/snap7/issues/16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/user-attachments/files/28681740/poc.zip",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/davenardella/snap7/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-15106",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:24.977Z",
      "date_published": "2026-07-16T07:51:05.397Z",
      "date_updated": "2026-07-16T12:38:20.321Z",
      "publisher": "Wordfence",
      "title": "WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter",
      "affected": {
        "vendors": [
          "quantumcloud"
        ],
        "products": [
          {
            "vendor": "quantumcloud",
            "product": "WPBot – AI ChatBot for Live Support, Lead Generation, AI Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19431
      },
      "nvd": {
        "published": "2026-07-16T09:16:17.800",
        "lastModified": "2026-07-16T13:38:53.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15106",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dc36ee53-81a9-416e-8e74-31d9c8802d6c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.0/includes/chat-sessions/wpbot-chat-sessions.php#L393",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.0/includes/chat-sessions/wpbot-chat-sessions.php#L372",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.0/includes/chat-sessions/wpbot-chat-sessions.php#L391",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/includes/chat-sessions/wpbot-chat-sessions.php#L393",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/includes/chat-sessions/wpbot-chat-sessions.php#L372",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/includes/chat-sessions/wpbot-chat-sessions.php#L391",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3608558%40chatbot&new=3608558%40chatbot",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 498,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15107",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:38.102Z",
      "date_published": "2026-07-08T22:36:06.218Z",
      "date_updated": "2026-07-10T03:55:24.687Z",
      "publisher": "Chrome",
      "title": "Use after free in IndexedDB in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.1548
      },
      "nvd": {
        "published": "2026-07-08T23:16:51.783",
        "lastModified": "2026-07-10T05:16:28.177",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15107",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome retains or reuses an object after its storage has been freed, allowing later processing to access invalid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/503553615",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15108",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:38.340Z",
      "date_published": "2026-07-08T22:35:59.196Z",
      "date_updated": "2026-07-09T10:36:37.839Z",
      "publisher": "Chrome",
      "title": "Integer overflow in Extensions API in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02575
      },
      "nvd": {
        "published": "2026-07-08T23:16:51.897",
        "lastModified": "2026-07-09T17:15:59.343",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15108",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer arithmetic in the Extensions API can overflow before a crafted extension indexes memory, producing an out-of-bounds read.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/515443146",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15109",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:38.723Z",
      "date_published": "2026-07-08T22:35:59.565Z",
      "date_updated": "2026-07-09T13:42:46.557Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12041
      },
      "nvd": {
        "published": "2026-07-08T23:16:52.000",
        "lastModified": "2026-07-09T17:15:46.783",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15109",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome reads memory before initializing it, allowing stale process data or an invalid value to influence execution.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516899138",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15110",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:39.115Z",
      "date_published": "2026-07-08T22:35:59.895Z",
      "date_updated": "2026-07-09T10:37:34.437Z",
      "publisher": "Chrome",
      "title": "Use after free in Extensions in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05108
      },
      "nvd": {
        "published": "2026-07-08T23:16:52.103",
        "lastModified": "2026-07-09T17:15:35.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15110",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Extensions can use an object after it has been freed while processing a crafted installed extension.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516948486",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15111",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:39.516Z",
      "date_published": "2026-07-08T22:36:00.240Z",
      "date_updated": "2026-07-10T03:55:32.285Z",
      "publisher": "Chrome",
      "title": "Use after free in Views in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08129
      },
      "nvd": {
        "published": "2026-07-08T23:16:52.203",
        "lastModified": "2026-07-10T05:16:28.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15111",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Views can retain and use a heap object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517508651",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15112",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:39.782Z",
      "date_published": "2026-07-08T22:35:57.558Z",
      "date_updated": "2026-07-10T03:55:28.527Z",
      "publisher": "Chrome",
      "title": "Use after free in Ozone in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.2514
      },
      "nvd": {
        "published": "2026-07-08T23:16:52.310",
        "lastModified": "2026-07-10T05:16:28.503",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15112",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Ozone uses an object after its storage has been freed while processing attacker-controlled content.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518006275",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15113",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:40.096Z",
      "date_published": "2026-07-08T22:36:00.578Z",
      "date_updated": "2026-07-10T03:55:35.365Z",
      "publisher": "Chrome",
      "title": "Use after free in Autofill in Google Chrome on Android prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10355
      },
      "nvd": {
        "published": "2026-07-08T23:16:52.413",
        "lastModified": "2026-07-10T05:16:28.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15113",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520540744",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15114",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:40.449Z",
      "date_published": "2026-07-08T22:36:00.919Z",
      "date_updated": "2026-07-10T03:55:31.517Z",
      "publisher": "Chrome",
      "title": "Out of bounds read and write in Codecs in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08515
      },
      "nvd": {
        "published": "2026-07-08T23:16:52.533",
        "lastModified": "2026-07-10T05:16:28.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15114",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520565945",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15115",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:40.716Z",
      "date_published": "2026-07-08T22:36:01.233Z",
      "date_updated": "2026-07-09T10:32:24.506Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00089,
        "percentile": 0.00498
      },
      "nvd": {
        "published": "2026-07-08T23:16:52.627",
        "lastModified": "2026-07-09T17:20:40.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15115",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520576676",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15116",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:40.968Z",
      "date_published": "2026-07-08T22:36:01.576Z",
      "date_updated": "2026-07-10T03:55:27.047Z",
      "publisher": "Chrome",
      "title": "Use after free in Actor in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15482
      },
      "nvd": {
        "published": "2026-07-08T23:16:52.730",
        "lastModified": "2026-07-10T05:16:28.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15116",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522092013",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15117",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:41.231Z",
      "date_published": "2026-07-08T22:36:01.902Z",
      "date_updated": "2026-07-10T03:55:30.754Z",
      "publisher": "Chrome",
      "title": "Use after free in Payments in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08128
      },
      "nvd": {
        "published": "2026-07-08T23:16:52.833",
        "lastModified": "2026-07-10T05:16:29.073",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15117",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A reachable path retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522568496",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 247,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15118",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:41.473Z",
      "date_published": "2026-07-08T22:36:02.238Z",
      "date_updated": "2026-07-10T03:55:41.438Z",
      "publisher": "Chrome",
      "title": "Use after free in Input in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15481
      },
      "nvd": {
        "published": "2026-07-08T23:16:52.940",
        "lastModified": "2026-07-10T05:16:29.213",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15118",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523238265",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15119",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:41.743Z",
      "date_published": "2026-07-08T22:36:02.589Z",
      "date_updated": "2026-07-10T03:55:34.573Z",
      "publisher": "Chrome",
      "title": "Race in GetUserMedia in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00151,
        "percentile": 0.04788
      },
      "nvd": {
        "published": "2026-07-08T23:16:53.050",
        "lastModified": "2026-07-10T05:16:29.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15119",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A race in GetUserMedia can violate the renderer-to-browser isolation sequence, but the contested state and ordering are not public.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523505418",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15120",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:41.990Z",
      "date_published": "2026-07-08T22:36:02.905Z",
      "date_updated": "2026-07-10T03:55:33.786Z",
      "publisher": "Chrome",
      "title": "Use after free in Core in Google Chrome on Windows prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08129
      },
      "nvd": {
        "published": "2026-07-08T23:16:53.143",
        "lastModified": "2026-07-10T05:16:29.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15120",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523609602",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15121",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:42.270Z",
      "date_published": "2026-07-08T22:36:03.216Z",
      "date_updated": "2026-07-10T03:55:36.126Z",
      "publisher": "Chrome",
      "title": "Use after free in WebRTC in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.22969
      },
      "nvd": {
        "published": "2026-07-08T23:16:53.247",
        "lastModified": "2026-07-10T05:16:29.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15121",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted WebRTC page triggers use of an object after its lifetime has ended.",
        "basis": [
          "CNA record",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523712556",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15122",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:42.495Z",
      "date_published": "2026-07-08T22:36:03.553Z",
      "date_updated": "2026-07-10T03:55:33.046Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09485
      },
      "nvd": {
        "published": "2026-07-08T23:16:53.347",
        "lastModified": "2026-07-10T05:16:29.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15122",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Chrome Codecs record reports generic input validation leading from a compromised renderer to sandbox escape but does not disclose the input, validation rule, or privileged transition.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523717219",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15123",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:42.747Z",
      "date_published": "2026-07-08T22:36:03.907Z",
      "date_updated": "2026-07-10T03:55:29.995Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in DOM in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10354
      },
      "nvd": {
        "published": "2026-07-08T23:16:53.450",
        "lastModified": "2026-07-10T05:16:29.973",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15123",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A DOM operation writes beyond a heap allocation when processing crafted page content.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523729553",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15124",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:42.988Z",
      "date_published": "2026-07-08T22:36:04.239Z",
      "date_updated": "2026-07-09T10:33:06.056Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Passwords in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06503
      },
      "nvd": {
        "published": "2026-07-08T23:16:53.547",
        "lastModified": "2026-07-09T17:50:17.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15124",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's Passwords component permits a crafted page to cross a same-origin boundary, while the public record does not disclose the policy decision that fails.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523735038",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15125",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:43.236Z",
      "date_published": "2026-07-08T22:36:04.563Z",
      "date_updated": "2026-07-10T03:55:26.297Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Forms in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14316
      },
      "nvd": {
        "published": "2026-07-08T23:16:53.637",
        "lastModified": "2026-07-10T05:16:30.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15125",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports sandboxed code execution through Chrome Forms but does not identify the implementation error that enables it.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523737685",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15126",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:43.483Z",
      "date_published": "2026-07-08T22:36:04.900Z",
      "date_updated": "2026-07-10T03:55:25.522Z",
      "publisher": "Chrome",
      "title": "Use after free in Forms in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15481
      },
      "nvd": {
        "published": "2026-07-08T23:16:53.733",
        "lastModified": "2026-07-10T05:16:30.253",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15126",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome Forms component can access an object after its lifetime has ended while processing a crafted page.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523748081",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15127",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:43.731Z",
      "date_published": "2026-07-08T22:36:05.220Z",
      "date_updated": "2026-07-09T10:15:03.155Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in WebGL in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03734
      },
      "nvd": {
        "published": "2026-07-08T23:16:53.830",
        "lastModified": "2026-07-09T17:49:59.053",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15127",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523752265",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15128",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:43.967Z",
      "date_published": "2026-07-08T22:36:05.560Z",
      "date_updated": "2026-07-09T10:14:29.053Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Forms in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03734
      },
      "nvd": {
        "published": "2026-07-08T23:16:53.930",
        "lastModified": "2026-07-09T17:49:51.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15128",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Forms component permits attacker-controlled content to cross into a privileged page context and execute script there.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523756329",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15129",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:44.223Z",
      "date_published": "2026-07-08T22:35:58.083Z",
      "date_updated": "2026-07-10T03:55:29.260Z",
      "publisher": "Chrome",
      "title": "Use after free in Views in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22073
      },
      "nvd": {
        "published": "2026-07-08T23:16:54.020",
        "lastModified": "2026-07-10T05:16:30.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15129",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path retains or dereferences an object after the object's storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/524045160",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15130",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:44.491Z",
      "date_published": "2026-07-08T22:36:05.902Z",
      "date_updated": "2026-07-09T10:34:12.946Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Navigation in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.0683
      },
      "nvd": {
        "published": "2026-07-08T23:16:54.127",
        "lastModified": "2026-07-09T17:49:42.217",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15130",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Navigation permits a crafted page to cross a site-isolation boundary, but the public record does not identify the policy comparison that fails.",
        "basis": [
          "CNA",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/526541544",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15131",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:44.744Z",
      "date_published": "2026-07-08T22:36:06.523Z",
      "date_updated": "2026-07-09T10:34:51.156Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Navigation in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.0683
      },
      "nvd": {
        "published": "2026-07-08T23:16:54.220",
        "lastModified": "2026-07-09T17:49:38.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15131",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome navigation processing permits a crafted page to cross the site-isolation boundary, while the public record omits the request state and validation rule involved.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/526542464",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15132",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:45.050Z",
      "date_published": "2026-07-08T22:35:58.469Z",
      "date_updated": "2026-07-10T03:55:27.796Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.1897
      },
      "nvd": {
        "published": "2026-07-08T23:16:54.317",
        "lastModified": "2026-07-10T05:16:30.537",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15132",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome V8 consumes a value before initializing the memory that defines it.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/527385397",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15133",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:45.300Z",
      "date_published": "2026-07-08T22:35:58.807Z",
      "date_updated": "2026-07-10T03:55:23.631Z",
      "publisher": "Chrome",
      "title": "Use after free in InterestGroups in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16084
      },
      "nvd": {
        "published": "2026-07-08T23:16:54.413",
        "lastModified": "2026-07-10T05:16:30.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15133",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path continues using an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/527406824",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15134",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:09:47.148Z",
      "date_published": "2026-07-08T23:00:10.115Z",
      "date_updated": "2026-07-09T14:32:00.430Z",
      "publisher": "VulDB",
      "title": "CodeAstro Simple Online Leave Management System index.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Simple Online Leave Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18015
      },
      "nvd": {
        "published": "2026-07-09T00:17:03.900",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15134",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376949",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376949/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15134",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851046",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/yihaofuweng/cve/issues/71",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15135",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:11:33.840Z",
      "date_published": "2026-07-08T23:30:09.990Z",
      "date_updated": "2026-07-09T14:40:03.876Z",
      "publisher": "VulDB",
      "title": "code-projects Online Food Order System edit_food_items.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Online Food Order System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18835
      },
      "nvd": {
        "published": "2026-07-09T00:17:04.063",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15135",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376951",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376951/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15135",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851065",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/susususua-AI/CVE/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15136",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:11:44.064Z",
      "date_published": "2026-07-28T05:39:43.634Z",
      "date_updated": "2026-07-28T13:55:24.005Z",
      "publisher": "Wordfence",
      "title": "Cookie Banner for GDPR / CCPA – WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries",
      "affected": {
        "vendors": [
          "wplegalpages"
        ],
        "products": [
          {
            "vendor": "wplegalpages",
            "product": "WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.0295
      },
      "nvd": {
        "published": "2026-07-28T07:16:41.853",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15136",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "process_bulk_action accepts forged state-changing requests because its nonce validation is missing or incorrect.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7a54b803-7e30-4964-88f0-d79276e67218?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/data-req/class-wpl-data-req-table.php#L287",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/data-req/class-wpl-data-req-table.php#L270",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/data-req/class-wpl-data-req-table.php#L444",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/class-gdpr-cookie-consent-admin.php#L1657",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3618614%40gdpr-cookie-consent&new=3618614%40gdpr-cookie-consent",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15137",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:13:28.509Z",
      "date_published": "2026-07-09T00:00:11.730Z",
      "date_updated": "2026-07-09T14:15:17.438Z",
      "publisher": "VulDB",
      "title": "code-projects Interview Management System View.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Interview Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18014
      },
      "nvd": {
        "published": "2026-07-09T00:17:04.217",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15137",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "View.php incorporates the attacker-controlled ID into an SQL command without parameter binding.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376952",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376952/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15137",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851066",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/susususua-AI/CVE/issues/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 333,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15138",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:16:38.505Z",
      "date_published": "2026-07-09T00:15:08.654Z",
      "date_updated": "2026-07-09T12:52:58.970Z",
      "publisher": "VulDB",
      "title": "tumf mcp-text-editor text_editor.py _validate_file_path path traversal",
      "affected": {
        "vendors": [
          "tumf"
        ],
        "products": [
          {
            "vendor": "tumf",
            "product": "mcp-text-editor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 5.4,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27318
      },
      "nvd": {
        "published": "2026-07-09T01:19:06.637",
        "lastModified": "2026-07-09T16:20:12.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15138",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file-path validator permits traversal sequences that select files outside the editor's intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/376953",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/376953/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15138",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851188",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/tumf/mcp-text-editor/issues/22",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/tumf/mcp-text-editor/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:24:00.555Z",
      "date_published": "2026-07-10T15:25:09.017Z",
      "date_updated": "2026-07-10T15:46:37.212Z",
      "publisher": "redhat",
      "title": "Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift AI (RHOAI)"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.1697
      },
      "nvd": {
        "published": "2026-07-10T16:16:25.680",
        "lastModified": "2026-07-10T17:49:57.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15143",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file_type detector resolves an attacker-supplied XML schema without restricting external URL or local-file references.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15143",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498165",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:27:38.479Z",
      "date_published": "2026-07-29T16:10:24.560Z",
      "date_updated": "2026-07-29T17:56:31.392Z",
      "publisher": "openjs",
      "title": "@fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotation",
      "affected": {
        "vendors": [
          "@fastify/rate-limit"
        ],
        "products": [
          {
            "vendor": "@fastify/rate-limit",
            "product": "@fastify/rate-limit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16621
      },
      "nvd": {
        "published": "2026-07-29T17:16:50.637",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15144",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The limiter keys IPv6 clients by a noncanonical address string and no subnet boundary, so address or spelling rotation creates fresh buckets.",
        "basis": [
          "CNA",
          "CWE-307",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fastify/fastify-rate-limit/security/advisories/GHSA-grpc-p53c-r64v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 914,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:29:21.751Z",
      "date_published": "2026-07-21T07:51:21.180Z",
      "date_updated": "2026-07-23T14:30:37.508Z",
      "publisher": "Wordfence",
      "title": "Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget",
      "affected": {
        "vendors": [
          "wpdevteam"
        ],
        "products": [
          {
            "vendor": "wpdevteam",
            "product": "Essential Addons for Elementor – Popular Elementor Templates & Widgets"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15325
      },
      "nvd": {
        "published": "2026-07-21T09:16:53.530",
        "lastModified": "2026-07-23T15:16:57.480",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15145",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fancy Text widget values reach rendered page markup without sufficient sanitization or context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2100d720-bfb4-451d-9907-e0b77ef507a5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.5/assets/front-end/js/lib-view/morphext/morphext.js#L27",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.10/assets/front-end/js/lib-view/morphext/morphext.js#L37",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.10/assets/front-end/js/view/fancy-text.js#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.10/assets/front-end/js/lib-view/morphext/morphext.js#L27",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.5/assets/front-end/js/lib-view/morphext/morphext.js#L37",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.5/assets/front-end/js/view/fancy-text.js#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/wpdevelopers/essential-addons-for-elementor-lite/commit/d88e08257",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3610135/essential-addons-for-elementor-lite/trunk/assets/front-end/js/lib-view/morphext/morphext.js",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fessential-addons-for-elementor-lite/tags/6.6.11&new_path=%2Fessential-addons-for-elementor-lite/tags/6.7.0",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 462,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15146",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T19:10:56.213Z",
      "date_published": "2026-07-10T18:20:58.269Z",
      "date_updated": "2026-07-15T18:46:29.362Z",
      "publisher": "certcc",
      "title": "CVE-2026-15146",
      "affected": {
        "vendors": [
          "GNU wget"
        ],
        "products": [
          {
            "vendor": "GNU wget",
            "product": "Wget"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06067
      },
      "nvd": {
        "published": "2026-07-10T19:17:20.307",
        "lastModified": "2026-07-15T19:16:57.323",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15146",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Wget trusts the host and port named by an FTP PASV reply instead of binding the data connection to the intended FTP peer.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://kb.cert.org/vuls/id/564823",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/564823",
          "host": "www.kb.cert.org",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 445,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15153",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T19:34:14.281Z",
      "date_published": "2026-07-30T06:00:07.520Z",
      "date_updated": "2026-07-30T18:28:25.241Z",
      "publisher": "WPScan",
      "title": "WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Hotel Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00297,
        "percentile": 0.22035
      },
      "nvd": {
        "published": "2026-07-30T06:25:01.330",
        "lastModified": "2026-07-30T19:17:08.117",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15153",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WP Hotel Booking incorporates attacker-controlled values or identifiers into a SQL statement without preserving the boundary between query syntax and data.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/0f678ab4-ec62-48a9-88c8-def3228ff725/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15154",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T19:44:43.020Z",
      "date_published": "2026-07-08T19:50:51.563Z",
      "date_updated": "2026-07-08T20:38:46.315Z",
      "publisher": "redhat",
      "title": "Guardrails-detectors: guardrails-detectors: unauthenticated regular-expression denial of service (redos) via detector_params.regex",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift AI (RHOAI)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10519
      },
      "nvd": {
        "published": "2026-07-08T20:16:48.430",
        "lastModified": "2026-07-10T15:24:29.933",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15154",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The public detector API compiles attacker-supplied regular expressions whose catastrophic backtracking can occupy a worker indefinitely.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15154",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498188",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 446,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15155",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T19:50:24.698Z",
      "date_published": "2026-07-11T05:35:49.683Z",
      "date_updated": "2026-07-15T13:46:28.209Z",
      "publisher": "Wordfence",
      "title": "Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection",
      "affected": {
        "vendors": [
          "wpdevteam"
        ],
        "products": [
          {
            "vendor": "wpdevteam",
            "product": "Essential Addons for Elementor – Popular Elementor Templates & Widgets"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00356,
        "percentile": 0.28351
      },
      "nvd": {
        "published": "2026-07-11T07:16:46.170",
        "lastModified": "2026-07-15T14:17:17.853",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15155",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A stored widget setting preserves CR/LF bytes into outgoing mail headers, allowing an attacker to add a Bcc recipient to an administrator password-reset message.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cbe8cf6c-b1fa-4f71-bb63-c8b181e54882?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.10/includes/Traits/Login_Registration.php#L1271",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.10/includes/Traits/Login_Registration.php#L1622",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.10/includes/Elements/Login_Register.php#L3333",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.5/includes/Traits/Login_Registration.php#L1271",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.5/includes/Traits/Login_Registration.php#L1622",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.5/includes/Elements/Login_Register.php#L3333",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3601504/essential-addons-for-elementor-lite/trunk/includes/Traits/Login_Registration.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fessential-addons-for-elementor-lite/tags/6.6.10&new_path=%2Fessential-addons-for-elementor-lite/tags/6.6.11",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 905,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15156",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T19:52:16.601Z",
      "date_published": "2026-07-21T04:33:03.564Z",
      "date_updated": "2026-07-22T14:19:38.985Z",
      "publisher": "Wordfence",
      "title": "Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings",
      "affected": {
        "vendors": [
          "wpdevteam"
        ],
        "products": [
          {
            "vendor": "wpdevteam",
            "product": "Essential Addons for Elementor – Popular Elementor Templates & Widgets"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10167
      },
      "nvd": {
        "published": "2026-07-21T05:16:34.110",
        "lastModified": "2026-07-22T15:16:52.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15156",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Reading Progress color settings supplied by a contributor are stored and rendered without sufficient HTML-context sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dde0cf3a-778b-4b5f-ac0e-600505d918ae?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.10/includes/Traits/Elements.php#L496",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.10/includes/Traits/Core.php#L185",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/6.6.10/includes/Classes/Bootstrap.php#L145",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3610135/essential-addons-for-elementor-lite/trunk/includes/Traits/Elements.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fessential-addons-for-elementor-lite/tags/6.6.11&new_path=%2Fessential-addons-for-elementor-lite/tags/6.7.0",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 483,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15157",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:03:17.332Z",
      "date_published": "2026-07-29T21:17:44.740Z",
      "date_updated": "2026-07-30T15:18:02.970Z",
      "publisher": "openjs",
      "title": "undici vulnerable to CRLF Injection via blob-like body 'type' property",
      "affected": {
        "vendors": [
          "undici"
        ],
        "products": [
          {
            "vendor": "undici",
            "product": "undici"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04961
      },
      "nvd": {
        "published": "2026-07-29T22:16:52.463",
        "lastModified": "2026-08-04T15:41:50.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15157",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Undici copies an unvalidated blob-like type value into an HTTP header, allowing CRLF to create new headers or a second request.",
        "basis": [
          "CNA",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 944,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-15158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:08:13.444Z",
      "date_published": "2026-07-09T08:31:35.105Z",
      "date_updated": "2026-07-09T13:52:43.210Z",
      "publisher": "Wordfence",
      "title": "Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter",
      "affected": {
        "vendors": [
          "creativethemeshq"
        ],
        "products": [
          {
            "vendor": "creativethemeshq",
            "product": "Blocksy Companion"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00611,
        "percentile": 0.45855
      },
      "nvd": {
        "published": "2026-07-09T10:16:25.370",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15158",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Blocksy Companion validates an uploaded attachment type with a substring-style check that permits an executable file to be stored.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2df449b4-3f3b-4afc-b391-8d8d11710c07?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.46/framework/premium/extensions/woocommerce-extra/features/advanced-reviews/feature.php#L811",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.46/framework/premium/extensions/custom-fonts/extension.php#L137",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 969,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15159",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:16:32.126Z",
      "date_published": "2026-07-17T02:31:31.480Z",
      "date_updated": "2026-07-17T10:24:54.455Z",
      "publisher": "Wordfence",
      "title": "Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter",
      "affected": {
        "vendors": [
          "SaturdayDrive"
        ],
        "products": [
          {
            "vendor": "SaturdayDrive",
            "product": "Ninja Forms - Excel Export"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07506
      },
      "nvd": {
        "published": "2026-07-17T04:16:50.540",
        "lastModified": "2026-07-17T14:59:38.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15159",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/783ccf21-db16-4aac-9a3c-992b3aac5526?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms-excel-export/trunk/ninja-forms-excel-export.php#L187",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15160",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:20:17.675Z",
      "date_published": "2026-07-17T02:31:31.093Z",
      "date_updated": "2026-07-17T12:01:06.040Z",
      "publisher": "Wordfence",
      "title": "Ninja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal",
      "affected": {
        "vendors": [
          "SaturdayDrive"
        ],
        "products": [
          {
            "vendor": "SaturdayDrive",
            "product": "Ninja Forms - Excel Export"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00459,
        "percentile": 0.3755
      },
      "nvd": {
        "published": "2026-07-17T04:16:50.700",
        "lastModified": "2026-07-17T14:59:38.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15160",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ninja Forms Excel Export accepts spreadsheet_export_tmp_name without path containment, allowing a subscriber to write spreadsheet files to arbitrary server locations.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/24fb24cc-c29f-4d2d-87ba-5d211386e7dd?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms-excel-export/trunk/includes/Handlers/ExportFile.php#L485",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms-excel-export/trunk/includes/Admin/ExtractPostData.php#L125",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms-excel-export/trunk/ninja-forms-excel-export.php#L95",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 381,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15161",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:24:07.379Z",
      "date_published": "2026-07-17T03:43:42.577Z",
      "date_updated": "2026-07-17T12:00:30.287Z",
      "publisher": "Wordfence",
      "title": "Ninja Forms - Excel Export <= 3.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'filter' Parameter",
      "affected": {
        "vendors": [
          "SaturdayDrive"
        ],
        "products": [
          {
            "vendor": "SaturdayDrive",
            "product": "Ninja Forms - Excel Export"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05248
      },
      "nvd": {
        "published": "2026-07-17T05:16:38.087",
        "lastModified": "2026-07-17T14:59:38.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15161",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e9ab836b-2798-43bd-b43b-8b7c7e81d42f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms-excel-export/trunk/includes/Admin/Menus/ExcelExport.php#L236",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 727,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15163",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:45:13.994Z",
      "date_published": "2026-07-08T20:50:40.278Z",
      "date_updated": "2026-07-09T13:49:25.283Z",
      "publisher": "GitLab",
      "title": "Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark",
      "affected": {
        "vendors": [
          "Wireshark Foundation"
        ],
        "products": [
          {
            "vendor": "Wireshark Foundation",
            "product": "Wireshark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08252
      },
      "nvd": {
        "published": "2026-07-08T21:16:47.227",
        "lastModified": "2026-07-09T19:56:30.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15163",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input can leave a processing loop without a reachable exit condition, consuming CPU until the operation is terminated.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wireshark.org/security/wnpa-sec-2026-61.html",
          "host": "www.wireshark.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21275",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21277",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21330",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21383",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15164",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:45:18.867Z",
      "date_published": "2026-07-08T20:50:35.393Z",
      "date_updated": "2026-07-09T13:50:08.985Z",
      "publisher": "GitLab",
      "title": "Heap-based Buffer Overflow in ciscodump",
      "affected": {
        "vendors": [
          "Wireshark Foundation"
        ],
        "products": [
          {
            "vendor": "Wireshark Foundation",
            "product": "ciscodump"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02295
      },
      "nvd": {
        "published": "2026-07-08T21:16:47.343",
        "lastModified": "2026-07-10T13:50:59.683",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15164",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data is written beyond the boundary of a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wireshark.org/security/wnpa-sec-2026-63.html",
          "host": "www.wireshark.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21375",
          "host": "gitlab.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 78,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15165",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:45:23.874Z",
      "date_published": "2026-07-08T20:50:45.283Z",
      "date_updated": "2026-07-09T13:47:02.064Z",
      "publisher": "GitLab",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "affected": {
        "vendors": [
          "Wireshark Foundation"
        ],
        "products": [
          {
            "vendor": "Wireshark Foundation",
            "product": "Wireshark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05318
      },
      "nvd": {
        "published": "2026-07-08T21:16:47.450",
        "lastModified": "2026-07-10T13:51:09.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15165",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The record maps a crafted TLS ECH decryptor crash to a heap buffer overflow but does not disclose the faulty length or copy operation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wireshark.org/security/wnpa-sec-2026-56.html",
          "host": "www.wireshark.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21390",
          "host": "gitlab.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 76,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15166",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:45:28.864Z",
      "date_published": "2026-07-08T20:55:55.070Z",
      "date_updated": "2026-07-09T13:13:51.109Z",
      "publisher": "GitLab",
      "title": "Stack-based Buffer Overflow in Wireshark",
      "affected": {
        "vendors": [
          "Wireshark Foundation"
        ],
        "products": [
          {
            "vendor": "Wireshark Foundation",
            "product": "Wireshark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05318
      },
      "nvd": {
        "published": "2026-07-08T21:16:47.560",
        "lastModified": "2026-07-09T19:59:14.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15166",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The IEEE 802.11 dissector can overflow a stack buffer while decoding a crafted packet.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wireshark.org/security/wnpa-sec-2026-57.html",
          "host": "www.wireshark.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21391",
          "host": "gitlab.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15167",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:45:33.866Z",
      "date_published": "2026-07-08T20:51:00.295Z",
      "date_updated": "2026-07-09T13:45:58.260Z",
      "publisher": "GitLab",
      "title": "Stack-based Buffer Overflow in Wireshark",
      "affected": {
        "vendors": [
          "Wireshark Foundation"
        ],
        "products": [
          {
            "vendor": "Wireshark Foundation",
            "product": "Wireshark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06717
      },
      "nvd": {
        "published": "2026-07-08T21:16:47.667",
        "lastModified": "2026-07-09T20:01:49.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15167",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can overflow a stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wireshark.org/security/wnpa-sec-2026-62.html",
          "host": "www.wireshark.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21352",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15168",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:45:38.879Z",
      "date_published": "2026-07-08T21:47:19.856Z",
      "date_updated": "2026-07-09T13:54:17.773Z",
      "publisher": "GitLab",
      "title": "Use of Uninitialized Variable in Wireshark",
      "affected": {
        "vendors": [
          "Wireshark Foundation"
        ],
        "products": [
          {
            "vendor": "Wireshark Foundation",
            "product": "Wireshark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02879
      },
      "nvd": {
        "published": "2026-07-08T22:17:13.717",
        "lastModified": "2026-07-09T19:20:39.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15168",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The BLF parser consumes an uninitialized variable and can expose residual process data.",
        "basis": [
          "CNA record",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wireshark.org/security/wnpa-sec-2026-60.html",
          "host": "www.wireshark.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21361",
          "host": "gitlab.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15169",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:45:43.874Z",
      "date_published": "2026-07-08T20:51:05.273Z",
      "date_updated": "2026-07-09T13:45:27.007Z",
      "publisher": "GitLab",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "affected": {
        "vendors": [
          "Wireshark Foundation"
        ],
        "products": [
          {
            "vendor": "Wireshark Foundation",
            "product": "Wireshark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13197
      },
      "nvd": {
        "published": "2026-07-08T21:16:47.777",
        "lastModified": "2026-07-09T20:02:39.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15169",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Wireshark writes attacker-controlled data beyond a heap buffer boundary.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wireshark.org/security/wnpa-sec-2026-59.html",
          "host": "www.wireshark.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21398",
          "host": "gitlab.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15170",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:45:48.875Z",
      "date_published": "2026-07-08T20:50:50.275Z",
      "date_updated": "2026-07-09T13:46:30.782Z",
      "publisher": "GitLab",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "affected": {
        "vendors": [
          "Wireshark Foundation"
        ],
        "products": [
          {
            "vendor": "Wireshark Foundation",
            "product": "Wireshark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05318
      },
      "nvd": {
        "published": "2026-07-08T21:16:47.880",
        "lastModified": "2026-07-09T19:26:00.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15170",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Z39.50 dissector writes past a heap buffer while parsing a crafted packet.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wireshark.org/security/wnpa-sec-2026-58.html",
          "host": "www.wireshark.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21397",
          "host": "gitlab.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15171",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:45:53.857Z",
      "date_published": "2026-07-08T20:51:10.283Z",
      "date_updated": "2026-07-09T13:44:55.663Z",
      "publisher": "GitLab",
      "title": "NULL Pointer Dereference in Wireshark",
      "affected": {
        "vendors": [
          "Wireshark Foundation"
        ],
        "products": [
          {
            "vendor": "Wireshark Foundation",
            "product": "Wireshark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02295
      },
      "nvd": {
        "published": "2026-07-08T21:16:47.990",
        "lastModified": "2026-07-09T19:24:29.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15171",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Wireshark, an error or lifecycle path dereferences a pointer that can still be null.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wireshark.org/security/wnpa-sec-2026-55.html",
          "host": "www.wireshark.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21378",
          "host": "gitlab.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15172",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:45:58.875Z",
      "date_published": "2026-07-08T20:51:20.287Z",
      "date_updated": "2026-07-09T13:42:52.886Z",
      "publisher": "GitLab",
      "title": "Unchecked Input for Loop Condition in Wireshark",
      "affected": {
        "vendors": [
          "Wireshark Foundation"
        ],
        "products": [
          {
            "vendor": "Wireshark Foundation",
            "product": "Wireshark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-606",
          "name": "Unchecked Input for Loop Condition",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02359
      },
      "nvd": {
        "published": "2026-07-08T21:16:48.097",
        "lastModified": "2026-07-09T19:23:17.337",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15172",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A protocol-controlled value governs loop progress without a safe iteration bound, allowing crafted input to keep the dissector running until it fails.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-606"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wireshark.org/security/wnpa-sec-2026-54.html",
          "host": "www.wireshark.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21347",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15173",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:46:03.869Z",
      "date_published": "2026-07-08T20:51:15.275Z",
      "date_updated": "2026-07-09T13:44:23.196Z",
      "publisher": "GitLab",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "affected": {
        "vendors": [
          "Wireshark Foundation"
        ],
        "products": [
          {
            "vendor": "Wireshark Foundation",
            "product": "Wireshark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00089,
        "percentile": 0.0053
      },
      "nvd": {
        "published": "2026-07-08T21:16:48.203",
        "lastModified": "2026-07-09T19:22:28.693",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15173",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pcapng parser writes beyond a heap allocation while parsing a crafted capture file.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wireshark.org/security/wnpa-sec-2026-53.html",
          "host": "www.wireshark.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21285",
          "host": "gitlab.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 77,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15174",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T20:46:08.884Z",
      "date_published": "2026-07-08T20:51:25.274Z",
      "date_updated": "2026-07-09T13:14:37.906Z",
      "publisher": "GitLab",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "affected": {
        "vendors": [
          "Wireshark Foundation"
        ],
        "products": [
          {
            "vendor": "Wireshark Foundation",
            "product": "Wireshark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00092,
        "percentile": 0.00623
      },
      "nvd": {
        "published": "2026-07-08T21:16:48.310",
        "lastModified": "2026-07-09T19:21:52.893",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15174",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Wireshark path writes attacker-influenced data beyond the capacity of its destination buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wireshark.org/security/wnpa-sec-2026-52.html",
          "host": "www.wireshark.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gitlab.com/wireshark/wireshark/-/work_items/21270",
          "host": "gitlab.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15182",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T04:56:52.789Z",
      "date_published": "2026-07-09T11:30:10.697Z",
      "date_updated": "2026-07-09T17:45:20.402Z",
      "publisher": "VulDB",
      "title": "GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "LibreDWG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03279
      },
      "nvd": {
        "published": "2026-07-09T12:16:25.407",
        "lastModified": "2026-07-09T18:16:50.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15182",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A length or bounds error permits a write beyond an allocated heap buffer.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377109",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377109/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15182",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851191",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/LibreDWG/libredwg/issues/1252",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/HackC0der/CVE-Repos/blob/main/libredwg/libredwg_0b57303_heap_overflow_decode_R13_R2000.dwg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/LibreDWG/libredwg/commit/18fd542bb4d5ccedf9de12052bf50068b2b26f06",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/LibreDWG/libredwg/releases/tag/0.14",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/LibreDWG/libredwg/issues/1249",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.gnu.org/",
          "host": "www.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 10,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-15183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T04:58:47.384Z",
      "date_published": "2026-07-14T08:42:38.507Z",
      "date_updated": "2026-07-14T12:21:40.309Z",
      "publisher": "SNOWFLAKE",
      "title": "Input Validation Vulnerabilities in Snowflake Spark Connector",
      "affected": {
        "vendors": [
          "Snowflake"
        ],
        "products": [
          {
            "vendor": "Snowflake",
            "product": "Snowflake Spark Connector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:412d305a-227d-44f9-a262-a31ba44f2aea",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11029
      },
      "nvd": {
        "published": "2026-07-14T09:16:40.443",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15183",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A single CVE bundles independent failures to freeze trusted catalog options, redact secrets, escape generated SQL, and constrain OAuth request destinations.",
        "basis": [
          "CNA",
          "CWE-89",
          "CWE-441",
          "CWE-918",
          "Snowflake release notes"
        ],
        "deepDive": true,
        "notes": "Read Snowflake release notes https://docs.snowflake.com/en/release-notes/clients-drivers/spark-connector-2026; version 3.2.1 lists four independent fixes (immutable fallback configuration, log redaction, SQL escaping, and OAuth URL validation), so no single lower-level mechanism covers the bundled record."
      },
      "references": [
        {
          "url": "https://docs.snowflake.com/en/release-notes/clients-drivers/spark-connector-2026",
          "host": "docs.snowflake.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 860,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:00:12.112Z",
      "date_published": "2026-07-09T12:00:17.369Z",
      "date_updated": "2026-07-09T12:55:55.857Z",
      "publisher": "VulDB",
      "title": "GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "LibreDWG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01986
      },
      "nvd": {
        "published": "2026-07-09T13:16:51.067",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15184",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "dwg_next_entity dereferences a null next_obj pointer while handling a crafted DWG object chain.",
        "basis": [
          "CNA",
          "CWE-404",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377110",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377110/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15184",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851192",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/LibreDWG/libredwg/issues/1253",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/HackC0der/CVE-Repos/blob/main/libredwg/libredwg_0b57303_dwggrep_segv_null_read_dwg_next_entity_dwg.c_1231.dwg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/LibreDWG/libredwg/commit/dde45dac3c4d902e4d8fed150a8017b9732019c9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/LibreDWG/libredwg/releases/tag/0.14",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.gnu.org/",
          "host": "www.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 560,
        "referenceCount": 9,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-15185",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:03:19.664Z",
      "date_published": "2026-07-09T12:30:08.948Z",
      "date_updated": "2026-07-09T14:41:36.729Z",
      "publisher": "VulDB",
      "title": "GPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "GPAC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01609
      },
      "nvd": {
        "published": "2026-07-09T14:16:29.537",
        "lastModified": "2026-07-09T16:19:45.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15185",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The num_langs argument is used without a sufficient bounds check and can drive an out-of-bounds read.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377111",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377111/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15185",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851214",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/issues/3611",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/commit/aa0fb77b82e51b159a2024c440cdf6b571b14d81",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/commit/532097084729a936bcdf6a27c41003f3bd7dc3ff",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15186",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:06:59.607Z",
      "date_published": "2026-07-09T13:15:08.296Z",
      "date_updated": "2026-07-09T14:39:10.538Z",
      "publisher": "VulDB",
      "title": "macrozheng mall Portal Endpoint create resource injection",
      "affected": {
        "vendors": [
          "macrozheng"
        ],
        "products": [
          {
            "vendor": "macrozheng",
            "product": "mall"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-99",
          "name": "Improper Control of Resource Identifiers ('Resource Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00237,
        "percentile": 0.1477
      },
      "nvd": {
        "published": "2026-07-09T14:16:29.733",
        "lastModified": "2026-07-09T16:16:38.047",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15186",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The application accepts an order identifier without binding the selected order to the requesting user.",
        "basis": [
          "CNA",
          "CWE-99"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377112",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377112/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15186",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851347",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/macrozheng/mall/issues/977",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/macrozheng/mall/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 428,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-15187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:14:13.888Z",
      "date_published": "2026-07-09T14:30:09.080Z",
      "date_updated": "2026-07-09T16:07:24.338Z",
      "publisher": "VulDB",
      "title": "enquirer Public Package API Enquirer.set prototype pollution",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "enquirer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16187
      },
      "nvd": {
        "published": "2026-07-09T16:16:38.190",
        "lastModified": "2026-07-09T17:16:57.187",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15187",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component lets attacker-controlled text cross into an executable or interpreted grammar without the required separation.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377113",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377113/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15187",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851357",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/enquirer/enquirer/issues/487",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/enquirer/enquirer/issues/487#issuecomment-4648521328",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/enquirer/enquirer/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:18:48.629Z",
      "date_published": "2026-07-09T15:15:08.172Z",
      "date_updated": "2026-07-09T16:15:01.284Z",
      "publisher": "VulDB",
      "title": "manjurulhoque django-job-portal Employee Dashboard Endpoint views.py EditEmployeeProfileAPIView access control",
      "affected": {
        "vendors": [
          "manjurulhoque"
        ],
        "products": [
          {
            "vendor": "manjurulhoque",
            "product": "django-job-portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11249
      },
      "nvd": {
        "published": "2026-07-09T16:16:38.350",
        "lastModified": "2026-07-09T17:16:57.310",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15188",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The component assigns or permits a privilege beyond the authority granted to the invoking user.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377114",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377114/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15188",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851436",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/manjurulhoque/django-job-portal/issues/91",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/manjurulhoque/django-job-portal/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 721,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15189",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:21:19.957Z",
      "date_published": "2026-07-09T15:30:09.679Z",
      "date_updated": "2026-07-09T17:43:31.453Z",
      "publisher": "VulDB",
      "title": "aerostackdev aerostack-mcp mcp-whatsapp upload_media server-side request forgery",
      "affected": {
        "vendors": [
          "aerostackdev"
        ],
        "products": [
          {
            "vendor": "aerostackdev",
            "product": "aerostack-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11242
      },
      "nvd": {
        "published": "2026-07-09T16:16:38.520",
        "lastModified": "2026-07-09T18:16:50.550",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15189",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server accepts an attacker-controlled destination without constraining the resolved request target to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377115",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377115/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15189",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851437",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/aerostackdev/aerostack-mcp/issues/3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/aerostackdev/aerostack-mcp/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15190",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:22:21.460Z",
      "date_published": "2026-07-09T15:45:09.130Z",
      "date_updated": "2026-07-09T17:14:09.187Z",
      "publisher": "VulDB",
      "title": "SourceCodester Simple and Nice Shopping Cart Script login.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Simple and Nice Shopping Cart Script"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25353
      },
      "nvd": {
        "published": "2026-07-09T17:16:57.437",
        "lastModified": "2026-07-09T19:03:47.433",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15190",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a Simple and Nice Shopping Cart Script database query without safe parameter binding, allowing SQL syntax injection.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377116",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377116/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15190",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851483",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zainaakinyi45-boop/cve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:33:07.527Z",
      "date_published": "2026-07-09T16:00:08.591Z",
      "date_updated": "2026-07-14T00:59:15.934Z",
      "publisher": "VulDB",
      "title": "mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authorization",
      "affected": {
        "vendors": [
          "mettle"
        ],
        "products": [
          {
            "vendor": "mettle",
            "product": "sendportal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12578
      },
      "nvd": {
        "published": "2026-07-09T17:16:57.620",
        "lastModified": "2026-07-14T02:16:52.933",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15191",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The campaign-creation endpoint accepts an object operation without correctly binding it to the caller's authorized tenant or resource.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377117",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377117/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15191",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851622",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mettle/sendportal/issues/339",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mettle/sendportal/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 466,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:36:19.016Z",
      "date_published": "2026-07-09T16:30:09.358Z",
      "date_updated": "2026-07-09T18:08:24.940Z",
      "publisher": "VulDB",
      "title": "mettle sendportal APIv1 Webhooks mailjet missing authentication",
      "affected": {
        "vendors": [
          "mettle"
        ],
        "products": [
          {
            "vendor": "mettle",
            "product": "sendportal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00572,
        "percentile": 0.44048
      },
      "nvd": {
        "published": "2026-07-09T17:16:57.783",
        "lastModified": "2026-07-09T19:17:04.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15192",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The APIv1 webhook functions accept remote calls without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377118",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377118/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15192",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851624",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mettle/sendportal/issues/340",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mettle/sendportal/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 422,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15193",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:42:57.622Z",
      "date_published": "2026-07-09T16:45:08.144Z",
      "date_updated": "2026-07-09T17:51:39.844Z",
      "publisher": "VulDB",
      "title": "AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection",
      "affected": {
        "vendors": [
          "AidanPark"
        ],
        "products": [
          {
            "vendor": "AidanPark",
            "product": "openclaw-android"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00683,
        "percentile": 0.48981
      },
      "nvd": {
        "published": "2026-07-09T17:16:57.947",
        "lastModified": "2026-07-09T19:03:47.433",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15193",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Android WebView bridge lets attacker-controlled data reach an operating-system command context without neutralizing shell syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377120",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377120/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15193",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851623",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/AidanPark/openclaw-android/issues/136",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/AidanPark/openclaw-android/pull/137",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/AidanPark/openclaw-android/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 432,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-15194",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:54:06.487Z",
      "date_published": "2026-07-09T17:00:07.483Z",
      "date_updated": "2026-07-09T17:31:40.158Z",
      "publisher": "VulDB",
      "title": "Open5GS AMF context.c amf_context_final use after free",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "Open5GS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02259
      },
      "nvd": {
        "published": "2026-07-09T17:16:58.097",
        "lastModified": "2026-07-09T19:03:47.433",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15194",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Open5GS path can dereference an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377122",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377122/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15194",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851630",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/open5gs/open5gs/security/advisories/GHSA-88pq-hpwv-2vjw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/open5gs/open5gs/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15195",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T06:00:53.324Z",
      "date_published": "2026-07-09T17:15:08.989Z",
      "date_updated": "2026-07-09T18:23:06.195Z",
      "publisher": "VulDB",
      "title": "apidevtools json-schema-ref-parser pointer.ts Pointer.set prototype pollution",
      "affected": {
        "vendors": [
          "apidevtools"
        ],
        "products": [
          {
            "vendor": "apidevtools",
            "product": "json-schema-ref-parser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17843
      },
      "nvd": {
        "published": "2026-07-09T18:16:51.313",
        "lastModified": "2026-07-09T19:17:04.207",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15195",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pointer setter follows attacker-controlled property paths into special prototype keys and modifies Object.prototype.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377123",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377123/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15195",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851809",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/APIDevTools/json-schema-ref-parser/issues/421",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/APIDevTools/json-schema-ref-parser/commit/a786bc6afc3674f650496472ee93d5cf74c4bd84",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/APIDevTools/json-schema-ref-parser/releases/tag/v15.3.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/APIDevTools/json-schema-ref-parser/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 464,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-15202",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T06:40:35.859Z",
      "date_published": "2026-07-09T17:30:07.209Z",
      "date_updated": "2026-07-09T18:27:56.467Z",
      "publisher": "VulDB",
      "title": "YzmCMS Header yzmphp.php get_url cross site scripting",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "YzmCMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18061
      },
      "nvd": {
        "published": "2026-07-09T18:16:51.480",
        "lastModified": "2026-07-09T19:17:04.357",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15202",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In YzmCMS, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377124",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377124/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15202",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851931",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/188452/72d03d030ee3cbfee2642badfa9dce33",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 414,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-15204",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T06:54:25.124Z",
      "date_published": "2026-07-09T17:45:10.075Z",
      "date_updated": "2026-07-14T01:07:22.744Z",
      "publisher": "VulDB",
      "title": "TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal",
      "affected": {
        "vendors": [
          "TOTOLINK"
        ],
        "products": [
          {
            "vendor": "TOTOLINK",
            "product": "X5000R"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:N/AC:M/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:N/AC:M/Au:N/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 2.6000000000000005,
      "epss": {
        "score": 0.00488,
        "percentile": 0.39385
      },
      "nvd": {
        "published": "2026-07-09T18:16:51.647",
        "lastModified": "2026-07-14T02:16:53.063",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15204",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "X5000R allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377125",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377125/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15204",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852073",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/meishigana/CVE/tree/main/totolink_x5000r_exportovpn_file_disclosure_2026-06-09",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related"
          ]
        },
        {
          "url": "https://www.totolink.net/",
          "host": "www.totolink.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15209",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T07:30:46.484Z",
      "date_published": "2026-07-31T06:00:09.640Z",
      "date_updated": "2026-07-31T19:45:10.724Z",
      "publisher": "WPScan",
      "title": "JS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "JS Help Desk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10142
      },
      "nvd": {
        "published": "2026-07-31T07:16:26.937",
        "lastModified": "2026-07-31T20:16:47.940",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15209",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ticket loader accepts another user's ticket ID without verifying that the requesting user owns the ticket.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/3665b8dd-2b02-4c3b-b024-f1e07f934fab/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 270,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15212",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T07:43:41.039Z",
      "date_published": "2026-07-23T19:45:52.225Z",
      "date_updated": "2026-07-24T14:27:08.898Z",
      "publisher": "Wordfence",
      "title": "WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 43.2 - Cross-Site Request Forgery to Privilege Escalation via Plugin Settings Update",
      "affected": {
        "vendors": [
          "wpo365"
        ],
        "products": [
          {
            "vendor": "wpo365",
            "product": "WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05354
      },
      "nvd": {
        "published": "2026-07-23T20:17:07.460",
        "lastModified": "2026-07-24T20:46:13.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15212",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The AJAX helper skips nonce verification when an absent option defaults false, letting a cross-origin request overwrite unrestricted plugin settings.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/51d0ba58-614e-4284-ae0b-b0b76fc5c46d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpo365-login/tags/43.2/Services/Ajax_Service.php#L805",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3610759/wpo365-login",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1061,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T10:14:23.078Z",
      "date_published": "2026-07-21T14:02:04.071Z",
      "date_updated": "2026-07-22T18:28:11.440Z",
      "publisher": "canonical",
      "title": "snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates",
      "affected": {
        "vendors": [
          "Canonical"
        ],
        "products": [
          {
            "vendor": "Canonical",
            "product": "Ubuntu 26.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 24.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 22.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 20.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 18.04 LTS"
          },
          {
            "vendor": "Canonical",
            "product": "Ubuntu 16.04 LTS"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-250",
          "name": "Execution with Unnecessary Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security@ubuntu.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02626
      },
      "nvd": {
        "published": "2026-07-21T15:16:31.030",
        "lastModified": "2026-07-22T19:16:54.937",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15226",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "snap-confine's default seccomp template omits restrictions on creating or applying set-user-ID executables inside a strict snap.",
        "basis": [
          "CNA",
          "CWE-250"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://ubuntu.com/security/CVE-2026-15226",
          "host": "ubuntu.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 989,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-15227",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T10:46:55.072Z",
      "date_published": "2026-07-31T12:21:58.292Z",
      "date_updated": "2026-07-31T19:50:52.858Z",
      "publisher": "Checkmk",
      "title": "Missing Authorization Allows Editing of Foreign Reports",
      "affected": {
        "vendors": [
          "Checkmk GmbH"
        ],
        "products": [
          {
            "vendor": "Checkmk GmbH",
            "product": "Checkmk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@checkmk.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10933
      },
      "nvd": {
        "published": "2026-07-31T13:17:19.593",
        "lastModified": "2026-07-31T20:16:48.100",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15227",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Checkmk permits a user without the Edit foreign Reports permission to modify a report owned by another user.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://checkmk.com/werk/20003",
          "host": "checkmk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-15228",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T10:50:51.533Z",
      "date_published": "2026-07-29T15:28:30.362Z",
      "date_updated": "2026-07-29T15:53:22.898Z",
      "publisher": "Kong",
      "title": "Kong Kubernetes Ingress Controller cluster-wide ingress configuration DoS via CA-certificate ID collision",
      "affected": {
        "vendors": [],
        "products": [],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:02762ae7-200e-4b20-9b2b-a77d5b8fc4cb",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03823
      },
      "nvd": {
        "published": "2026-07-29T16:17:49.723",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15228",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kong KIC collects CA secrets beyond the creator's namespace and lets a namespace-scoped user introduce duplicate identifiers that invalidate cluster-wide configuration.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Kong/kubernetes-ingress-controller/security/advisories/GHSA-g9h6-h2xj-mf78",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 0,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15235",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T11:38:13.310Z",
      "date_published": "2026-07-30T06:00:07.700Z",
      "date_updated": "2026-07-30T18:25:44.439Z",
      "publisher": "WPScan",
      "title": "Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "MotoPress Hotel Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13136
      },
      "nvd": {
        "published": "2026-07-30T06:25:01.467",
        "lastModified": "2026-07-30T19:17:08.273",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15235",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The booking-details AJAX action returns any booking to a subscriber without checking that the caller has permission to view that booking.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/c441d996-e21f-4a16-8dcc-0b0ed61aec76/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15240",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T11:50:04.632Z",
      "date_published": "2026-07-30T06:00:08.638Z",
      "date_updated": "2026-07-30T14:35:58.587Z",
      "publisher": "WPScan",
      "title": "Customer Switching for WooCommerce < 2.1.3 - Customer+ Privilege Escalation to Administrator via Insecure Operator Resolution",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Customer Switching"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10579
      },
      "nvd": {
        "published": "2026-07-30T06:25:01.600",
        "lastModified": "2026-07-30T15:16:26.250",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15240",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any permitted account, including an administrator, resulting in full account takeover.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/4e5b9e2a-c8e0-41db-a989-1b44bc76c9d8/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T11:56:55.414Z",
      "date_published": "2026-07-24T11:29:26.067Z",
      "date_updated": "2026-07-24T12:33:58.681Z",
      "publisher": "CERT-PL",
      "title": "Improper Validation of Certificate in CAS Client",
      "affected": {
        "vendors": [
          "Apereo"
        ],
        "products": [
          {
            "vendor": "Apereo",
            "product": "Java Apereo CAS Client"
          },
          {
            "vendor": "Apereo",
            "product": "Jasig CAS Client"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-297",
          "name": "Improper Validation of Certificate with Host Mismatch",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06615
      },
      "nvd": {
        "published": "2026-07-24T12:16:46.973",
        "lastModified": "2026-07-30T19:09:13.930",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15243",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CAS client checks CA trust and an allowlisted URL but omits certificate hostname verification for the peer it reaches.",
        "basis": [
          "CNA",
          "CWE-297"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-15243",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.apereo.org/programs/software/cas",
          "host": "www.apereo.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 705,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15250",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T12:23:13.558Z",
      "date_published": "2026-07-30T06:00:08.816Z",
      "date_updated": "2026-07-30T14:41:40.163Z",
      "publisher": "WPScan",
      "title": "LatePoint < 5.6.8 - Unauthenticated Booking Object Mass Assignment via Public Booking Funnel",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Appointment Booking Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11588
      },
      "nvd": {
        "published": "2026-07-30T06:25:01.800",
        "lastModified": "2026-07-30T15:16:26.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15250",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public booking flow lets an unauthenticated caller set approval-state fields that should be assigned only by the site's approval workflow.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/2609e202-9be3-42b0-a1fb-ace310b93bd0/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T12:38:54.313Z",
      "date_published": "2026-07-30T06:00:09.016Z",
      "date_updated": "2026-07-30T14:50:24.510Z",
      "publisher": "WPScan",
      "title": "Search Atlas SEO < 2.6.12 - Subscriber+ Google Indexing API Access",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Search Atlas SEO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07458
      },
      "nvd": {
        "published": "2026-07-30T06:25:01.940",
        "lastModified": "2026-07-30T15:16:26.587",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15252",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/a347a7a8-36d6-4806-8781-a9ae8eb94788/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15255",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T12:56:11.326Z",
      "date_published": "2026-07-30T06:00:09.191Z",
      "date_updated": "2026-07-30T15:02:30.668Z",
      "publisher": "WPScan",
      "title": "RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "RegistrationMagic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10264
      },
      "nvd": {
        "published": "2026-07-30T06:25:02.070",
        "lastModified": "2026-07-30T16:16:56.153",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15255",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RegistrationMagic accepts an OTP cookie without binding that token to the identity whose form submissions are requested.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/21fa84b9-afa6-49f7-abb1-c1edabda3cd8/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 323,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15257",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T13:03:43.047Z",
      "date_published": "2026-07-30T06:00:09.359Z",
      "date_updated": "2026-07-30T15:00:10.130Z",
      "publisher": "WPScan",
      "title": "RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modification",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "RegistrationMagic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08847
      },
      "nvd": {
        "published": "2026-07-30T06:25:02.203",
        "lastModified": "2026-07-30T16:16:56.300",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15257",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The submission-editing action fails to bind the requested submission and associated profile to the caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/fe6d0f6a-c2b4-4cd1-a7d2-e3afec76ebca/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15258",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T13:06:34.857Z",
      "date_published": "2026-07-31T06:00:09.816Z",
      "date_updated": "2026-07-31T19:44:02.517Z",
      "publisher": "WPScan",
      "title": "Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Product Feed Manager For WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.1276
      },
      "nvd": {
        "published": "2026-07-31T07:16:27.033",
        "lastModified": "2026-07-31T20:16:48.207",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15258",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/9e20442b-047b-46fe-be72-89c637deb6bc/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 261,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15265",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:11:48.773Z",
      "date_published": "2026-07-14T15:02:37.223Z",
      "date_updated": "2026-07-14T15:27:23.145Z",
      "publisher": "tenable",
      "title": "Tenable Agent Path Traversal Leading to Remote Code Execution",
      "affected": {
        "vendors": [
          "tenable"
        ],
        "products": [
          {
            "vendor": "tenable",
            "product": "tenable_agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:F/RL:U/RC:C"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37737
      },
      "nvd": {
        "published": "2026-07-14T15:16:57.457",
        "lastModified": "2026-07-15T21:00:31.273",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15265",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A privileged agent operation accepts a traversal path that writes outside the intended plugin directory.",
        "basis": [
          "CNA record",
          "CWE-22",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tenable.com/security/tns-2026-18",
          "host": "www.tenable.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15267",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:17:51.747Z",
      "date_published": "2026-07-28T08:34:36.049Z",
      "date_updated": "2026-07-28T12:44:57.772Z",
      "publisher": "Wordfence",
      "title": "Taskbuilder <= 5.0.9 - Authenticated (Subscriber+) SQL Injection",
      "affected": {
        "vendors": [
          "taskbuilder"
        ],
        "products": [
          {
            "vendor": "taskbuilder",
            "product": "Taskbuilder – Project Management & Task Management Tool With Kanban Board"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.1777
      },
      "nvd": {
        "published": "2026-07-28T09:16:42.107",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15267",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Taskbuilder – Project Management & Task Management Tool With Kanban Board builds an SQL statement from attacker-controlled text without parameterization or SQL-context separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/746eec41-e8d2-4c51-b63e-726eeadbb2ab?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.9/includes/admin/projects/open_project/wppm_view_project_tasks.php#L181",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.9/includes/admin/projects/open_project/wppm_view_project_tasks.php#L144",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/taskbuilder/tags/5.0.9/includes/class-wppm-admin.php#L545",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3576941/taskbuilder/trunk/includes/admin/projects/open_project/wppm_view_project_tasks.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 940,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15270",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:48:56.967Z",
      "date_published": "2026-07-09T19:45:08.076Z",
      "date_updated": "2026-07-10T20:32:20.066Z",
      "publisher": "VulDB",
      "title": "D-link DIR-823G Web boa.conf least privilege violation",
      "affected": {
        "vendors": [
          "D-link"
        ],
        "products": [
          {
            "vendor": "D-link",
            "product": "DIR-823G"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-272",
          "name": "Least Privilege Violation",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00443,
        "percentile": 0.36398
      },
      "nvd": {
        "published": "2026-07-09T20:16:28.887",
        "lastModified": "2026-07-13T13:09:00.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15270",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The web-server configuration assigns more privilege than intended, but the public record does not identify the directive or subject receiving it.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-272"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377213",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377213/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required",
            "VDB Entry",
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15270",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852314",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://app.notion.com/p/DIR823G-V1-0-2B05_20181207-37a1f5ba989080f2a043c60d2cfc7499?source=copy_link",
          "host": "app.notion.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://www.dlink.com/",
          "host": "www.dlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 461,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15271",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:50:16.412Z",
      "date_published": "2026-07-09T21:30:10.629Z",
      "date_updated": "2026-07-10T13:37:52.501Z",
      "publisher": "VulDB",
      "title": "TOTOLINK EX200 Web boa.conf least privilege violation",
      "affected": {
        "vendors": [
          "TOTOLINK"
        ],
        "products": [
          {
            "vendor": "TOTOLINK",
            "product": "A3000RU"
          },
          {
            "vendor": "TOTOLINK",
            "product": "A3100R"
          },
          {
            "vendor": "TOTOLINK",
            "product": "A950RG"
          },
          {
            "vendor": "TOTOLINK",
            "product": "AC1200T10"
          },
          {
            "vendor": "TOTOLINK",
            "product": "CP450"
          },
          {
            "vendor": "TOTOLINK",
            "product": "CS185R_T10"
          },
          {
            "vendor": "TOTOLINK",
            "product": "EX200"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-272",
          "name": "Least Privilege Violation",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:C/I:C/A:C/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00407,
        "percentile": 0.33482
      },
      "nvd": {
        "published": "2026-07-09T22:17:02.210",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15271",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The TOTOLINK web configuration grants remote processing more privilege than intended, while the public record does not identify the account, operation, or permission assignment involved.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-272"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377214",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377214/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15271",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852316",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852317",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852318",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852319",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852320",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852321",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852323",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://app.notion.com/p/A3000RU-V5-9c-5185-37a1f5ba989080d38bb6ca58b2a98c64?source=copy_link",
          "host": "app.notion.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://www.totolink.net/",
          "host": "www.totolink.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 12,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-15274",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:57:57.065Z",
      "date_published": "2026-07-09T21:45:09.762Z",
      "date_updated": "2026-07-10T14:38:26.819Z",
      "publisher": "VulDB",
      "title": "lo48576 fbxcel Node Header parser.rs denial of service",
      "affected": {
        "vendors": [
          "lo48576"
        ],
        "products": [
          {
            "vendor": "lo48576",
            "product": "fbxcel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02192
      },
      "nvd": {
        "published": "2026-07-09T22:17:03.270",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15274",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports denial of service in the fbxcel node-header parser but does not identify the failing operation or resource invariant.",
        "basis": [
          "CNA record",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377215",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377215/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15274",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852441",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lo48576/fbxcel/issues/14",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/lo48576/fbxcel/pull/15",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/lo48576/fbxcel/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-15276",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:02:29.634Z",
      "date_published": "2026-07-09T22:00:12.390Z",
      "date_updated": "2026-07-10T18:24:06.793Z",
      "publisher": "VulDB",
      "title": "pdeljanov Symphonia Metadata denial of service",
      "affected": {
        "vendors": [
          "pdeljanov"
        ],
        "products": [
          {
            "vendor": "pdeljanov",
            "product": "Symphonia"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02192
      },
      "nvd": {
        "published": "2026-07-09T22:17:03.450",
        "lastModified": "2026-07-10T19:17:20.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15276",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The metadata handler fails to release a finite resource on an undisclosed path, allowing local input to exhaust the process, but the resource is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377216",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377216/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15276",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852458",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/pdeljanov/Symphonia/issues/508",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/pdeljanov/Symphonia/pull/514",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/pdeljanov/Symphonia/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-15280",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:35:23.531Z",
      "date_published": "2026-07-28T20:09:11.584Z",
      "date_updated": "2026-07-29T12:38:22.606Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26109
      },
      "nvd": {
        "published": "2026-07-28T21:17:27.640",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15280",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WebSphere Application Server - Liberty path accepts an attacker-controlled path that can escape the intended filesystem root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281633",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 184,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15282",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:48:27.727Z",
      "date_published": "2026-07-10T04:31:20.078Z",
      "date_updated": "2026-07-14T01:30:57.647Z",
      "publisher": "Wordfence",
      "title": "Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload",
      "affected": {
        "vendors": [
          "tenteeglobal"
        ],
        "products": [
          {
            "vendor": "tenteeglobal",
            "product": "Instant Appointment"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01018,
        "percentile": 0.59972
      },
      "nvd": {
        "published": "2026-07-10T05:16:30.820",
        "lastModified": "2026-07-14T02:16:53.297",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15282",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path accepts a dangerous file type without validating the extension or content against an allowed set.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/097b1530-64fa-45b2-85f3-c6a2311405b5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/instant-appointment/trunk/includes/ajax/ajax_services.php#L3",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/instant-appointment/trunk/includes/front-end/ajax/login_ajax.php#L584",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/instant-appointment/trunk/includes/front-end/ajax/login_ajax.php#L598",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15283",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:49:03.889Z",
      "date_published": "2026-07-10T04:31:20.585Z",
      "date_updated": "2026-07-10T14:17:41.882Z",
      "publisher": "Wordfence",
      "title": "WPvivid Backup for MainWP <= 0.9.33 - Authenticated (Admin+) Stored Cross-Site Scripting",
      "affected": {
        "vendors": [
          "wpvividplugins"
        ],
        "products": [
          {
            "vendor": "wpvividplugins",
            "product": "WPvivid Backup for MainWP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.0852
      },
      "nvd": {
        "published": "2026-07-10T05:16:30.943",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15283",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WPvivid Backup for MainWP rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2083fdf7-e251-4162-b38f-8dab4395a8a7?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3047890%40wpvivid-backup-mainwp&new=3047890%40wpvivid-backup-mainwp&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 523,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15284",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:49:20.495Z",
      "date_published": "2026-07-10T04:31:21.383Z",
      "date_updated": "2026-07-10T20:31:09.070Z",
      "publisher": "Wordfence",
      "title": "King Addons for Elementor <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter",
      "affected": {
        "vendors": [
          "kingaddons"
        ],
        "products": [
          {
            "vendor": "kingaddons",
            "product": "King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22083
      },
      "nvd": {
        "published": "2026-07-10T05:16:31.067",
        "lastModified": "2026-07-10T21:16:53.823",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15284",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "King Addons stores form_page_id and concatenates it into an HTML href attribute without URL escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/349ba9de-69b3-42fb-aeba-c3a24280547f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.62/includes/widgets/Form_Builder/helpers/View_Submissions_Pro.php#L305",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.62/includes/widgets/Form_Builder/helpers/Create_Submission.php#L68",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.62/includes/widgets/Form_Builder/helpers/Upload_Email_File.php#L261",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.61/includes/widgets/Form_Builder/helpers/View_Submissions_Pro.php#L305",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.61/includes/widgets/Form_Builder/helpers/Create_Submission.php#L68",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.61/includes/widgets/Form_Builder/helpers/Upload_Email_File.php#L261",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fking-addons/tags/51.1.62&new_path=%2Fking-addons/tags/51.1.63",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3537725/king-addons/tags/51.1.63/includes/widgets/Form_Builder/helpers/Create_Submission.php?old=3515422&old_path=king-addons%2Ftags%2F51.1.62%2Fincludes%2Fwidgets%2FForm_Builder%2Fhelpers%2FCreate_Submission.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3537725/king-addons/tags/51.1.63/includes/widgets/Form_Builder/helpers/View_Submissions_Pro.php?old=3515422&old_path=king-addons%2Ftags%2F51.1.62%2Fincludes%2Fwidgets%2FForm_Builder%2Fhelpers%2FView_Submissions_Pro.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 791,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15285",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:49:35.073Z",
      "date_published": "2026-07-10T04:31:21.781Z",
      "date_updated": "2026-07-10T14:02:54.137Z",
      "publisher": "Wordfence",
      "title": "The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes",
      "affected": {
        "vendors": [
          "posimyththemes"
        ],
        "products": [
          {
            "vendor": "posimyththemes",
            "product": "The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17731
      },
      "nvd": {
        "published": "2026-07-10T05:16:31.210",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15285",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's `custom_attributes` setting in versions up to and including 6.4.11.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3c3217f9-67e5-488d-b80a-49a61678fb98?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/6.4.10/modules/widgets/tp_button.php#L1549",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/6.4.11/modules/widgets/tp_button.php#L1881",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/6.4.10/modules/helper-function.php#L65",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/6.4.12/modules/widgets/tp_button.php#L1680",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 417,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15286",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:49:52.117Z",
      "date_published": "2026-07-10T04:31:22.171Z",
      "date_updated": "2026-07-10T15:24:11.323Z",
      "publisher": "Wordfence",
      "title": "Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication",
      "affected": {
        "vendors": [
          "stellarwp"
        ],
        "products": [
          {
            "vendor": "stellarwp",
            "product": "Kadence Blocks — Page Builder Toolkit for Gutenberg Editor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18772
      },
      "nvd": {
        "published": "2026-07-10T05:16:31.343",
        "lastModified": "2026-07-10T16:16:25.810",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15286",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The process_pattern REST permission callback grants contributors a capability that lets them publish posts directly.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6e739eb4-6b8b-4bc7-a1e6-790180668c93?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/trunk/includes/class-kadence-blocks-prebuilt-library-rest-api.php#L590",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/trunk/includes/class-kadence-blocks-prebuilt-library-rest-api.php#L925",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3445125/",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 606,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15287",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:50:15.758Z",
      "date_published": "2026-07-10T04:31:22.580Z",
      "date_updated": "2026-07-10T18:03:36.230Z",
      "publisher": "Wordfence",
      "title": "rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Subscriber+) SQL Injection",
      "affected": {
        "vendors": [
          "rtcamp"
        ],
        "products": [
          {
            "vendor": "rtcamp",
            "product": "rtMedia for WordPress, BuddyPress and bbPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20446
      },
      "nvd": {
        "published": "2026-07-10T05:16:31.657",
        "lastModified": "2026-07-10T19:17:20.527",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15287",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7a2420ca-e079-429b-b1f1-47bf1d0a9f71?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3071359%40buddypress-media%2Ftrunk&old=3022114%40buddypress-media%2Ftrunk&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 525,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15288",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:50:42.634Z",
      "date_published": "2026-07-10T04:31:22.991Z",
      "date_updated": "2026-07-14T01:33:55.399Z",
      "publisher": "Wordfence",
      "title": "SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation",
      "affected": {
        "vendors": [
          "brainstormforce"
        ],
        "products": [
          {
            "vendor": "brainstormforce",
            "product": "SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26646
      },
      "nvd": {
        "published": "2026-07-10T05:16:31.923",
        "lastModified": "2026-07-14T02:16:53.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15288",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The payment workflow trusts a caller-supplied amount instead of recomputing it from the server-side order state before completing the transaction.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8b0e0f22-de42-4da9-a0c1-ae41ba57be03?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3427656/sureforms/tags/2.2.2/inc/payments/payment-helper.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3427656/sureforms/tags/2.2.2/inc/payments/front-end.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 614,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15289",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:51:10.591Z",
      "date_published": "2026-07-10T04:31:23.417Z",
      "date_updated": "2026-07-10T14:27:52.610Z",
      "publisher": "Wordfence",
      "title": "Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id'",
      "affected": {
        "vendors": [
          "wpdevart"
        ],
        "products": [
          {
            "vendor": "wpdevart",
            "product": "Booking calendar, Appointment Booking System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27274
      },
      "nvd": {
        "published": "2026-07-10T05:16:32.133",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15289",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8c052622-ac99-4069-b7df-41aea303ed9d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-calendar/trunk/includes/main_class.php#L64",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-calendar/trunk/includes/main_class.php#L90",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-calendar/trunk/includes/main_class.php#L91",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 647,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15290",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:51:26.056Z",
      "date_published": "2026-07-10T04:31:23.897Z",
      "date_updated": "2026-07-10T17:01:50.139Z",
      "publisher": "Wordfence",
      "title": "Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection",
      "affected": {
        "vendors": [
          "ultimatemember"
        ],
        "products": [
          {
            "vendor": "ultimatemember",
            "product": "Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00393,
        "percentile": 0.31995
      },
      "nvd": {
        "published": "2026-07-10T05:16:32.287",
        "lastModified": "2026-07-10T17:16:53.920",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15290",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The search parameter is concatenated into an existing Ultimate Member query without sufficient escaping or prepared binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8f539e25-5483-417d-a3c5-e7034c03c673?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.10.1/includes/core/class-member-directory.php#L1866",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.10.1/includes/core/class-member-directory.php#L1710",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3222364/ultimate-member/trunk/includes/core/class-member-directory.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3265901/",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 649,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15291",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:51:39.452Z",
      "date_published": "2026-07-10T04:31:24.297Z",
      "date_updated": "2026-07-10T13:16:42.262Z",
      "publisher": "Wordfence",
      "title": "Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure",
      "affected": {
        "vendors": [
          "themeatelier"
        ],
        "products": [
          {
            "vendor": "themeatelier",
            "product": "ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0047,
        "percentile": 0.38232
      },
      "nvd": {
        "published": "2026-07-10T05:16:32.430",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15291",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The leads REST endpoints return customer and account records without any authentication or authorization check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/91654765-6631-4eb4-9971-32b7db7933e1?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chat-help/tags/3.1.1/src/Admin/Leads.php#L149",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chat-help/tags/3.1.1/src/Admin/Leads.php#L157",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chat-help/tags/3.1.1/src/Admin/Leads.php#L234",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chat-help/tags/3.1.1/src/Admin/Leads.php#L207",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3394141%40chat-help%2Ftrunk&old=3390862%40chat-help%2Ftrunk&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 743,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15292",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:51:51.235Z",
      "date_published": "2026-07-10T04:31:24.681Z",
      "date_updated": "2026-07-10T15:20:55.122Z",
      "publisher": "Wordfence",
      "title": "Sudoku Shortcode <= 1.0.0 - Authenticated (Contributor+) Cross-Site Scripting via 'background' Shortcode Attribute",
      "affected": {
        "vendors": [
          "tibouille"
        ],
        "products": [
          {
            "vendor": "tibouille",
            "product": "Sudoku Shortcode"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15546
      },
      "nvd": {
        "published": "2026-07-10T05:16:32.563",
        "lastModified": "2026-07-10T16:16:25.917",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15292",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Sudoku shortcode renders its background parameter into a page without sufficient sanitization and output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/99e4b38c-f81d-4578-a623-ea62495e934d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sudoku-shortcode/trunk/sudoku-shortcode.php#L63",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sudoku-shortcode/tags/1.0.0/sudoku-shortcode.php#L63",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sudoku-shortcode/trunk/sudoku-shortcode.php#L73",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sudoku-shortcode/tags/1.0.0/sudoku-shortcode.php#L73",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 445,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15293",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:52:05.067Z",
      "date_published": "2026-07-10T04:31:25.059Z",
      "date_updated": "2026-07-10T18:01:18.569Z",
      "publisher": "Wordfence",
      "title": "WP Business Intelligence Lite <= 3.2.0 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary SQL Modification",
      "affected": {
        "vendors": [
          "joeyoungblood"
        ],
        "products": [
          {
            "vendor": "joeyoungblood",
            "product": "WP Business Intelligence Lite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27426
      },
      "nvd": {
        "published": "2026-07-10T05:16:32.700",
        "lastModified": "2026-07-10T19:17:20.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15293",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Subscriber-level users can modify stored SQL definitions because the update action omits the capability check required for query administration.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a7e35f18-7659-4b97-b99f-b57ac941cb22?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-business-intelligence-lite/tags/3.2.0/Admin/Menu/Query.php#L122",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-business-intelligence-lite/tags/3.2.0/Loader.php#L81",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15295",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:52:34.650Z",
      "date_published": "2026-07-10T19:44:07.987Z",
      "date_updated": "2026-07-14T13:49:18.883Z",
      "publisher": "Wordfence",
      "title": "Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting",
      "affected": {
        "vendors": [
          "dcooney"
        ],
        "products": [
          {
            "vendor": "dcooney",
            "product": "Ajax Load More – Infinite Scroll, Load More, & Lazy Load"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-692",
          "name": "Incomplete Denylist to Cross-Site Scripting",
          "abstraction": "Compound",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08903
      },
      "nvd": {
        "published": "2026-07-10T20:16:45.733",
        "lastModified": "2026-07-14T15:16:57.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15295",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Administrative settings are stored without sufficient sanitization and later rendered without output escaping when multisite or disabled unfiltered_html removes the normal WordPress filter.",
        "basis": [
          "CNA",
          "CWE-692"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a9bbcb41-d604-45ec-a36a-4b41e8f7a508?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3033302%40ajax-load-more%2Ftrunk&old=3025859%40ajax-load-more%2Ftrunk&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15296",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:52:45.126Z",
      "date_published": "2026-07-10T04:31:26.047Z",
      "date_updated": "2026-07-14T01:34:22.813Z",
      "publisher": "Wordfence",
      "title": "affiliate-toolkit – WP Affiliate Plugin with Amazon <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting",
      "affected": {
        "vendors": [
          "cservit"
        ],
        "products": [
          {
            "vendor": "cservit",
            "product": "affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17032
      },
      "nvd": {
        "published": "2026-07-10T05:16:32.837",
        "lastModified": "2026-07-14T02:16:53.510",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15296",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Shortcode attributes reach generated HTML without sufficient sanitization and output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b5e64a33-6165-4257-b324-0bbab4129e54?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/affiliate-toolkit-starter/trunk/includes/atkp_output.php#L299",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3227483/",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 526,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15297",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:53:39.402Z",
      "date_published": "2026-07-10T04:31:26.420Z",
      "date_updated": "2026-07-10T14:28:51.724Z",
      "publisher": "Wordfence",
      "title": "Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 - Reflected Cross-Site Scripting",
      "affected": {
        "vendors": [
          "neeraj_slit"
        ],
        "products": [
          {
            "vendor": "neeraj_slit",
            "product": "Brevo – Email, SMS, Web Push, Chat, and more."
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17225
      },
      "nvd": {
        "published": "2026-07-10T05:16:32.977",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15297",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Brevo – Email, SMS, Web Push, Chat, and more., attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bf4cb79e-e62b-4991-8ee5-493dafe38b80?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mailin/trunk/inc/table-forms.php#L102",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3055756%40mailin%2Ftrunk&old=3032712%40mailin%2Ftrunk&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 483,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15298",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:53:59.287Z",
      "date_published": "2026-07-10T04:31:26.785Z",
      "date_updated": "2026-07-10T17:01:43.683Z",
      "publisher": "Wordfence",
      "title": "TelSender <= 1.14.14 - Unauthenticated Stored Cross-Site Scripting via Telegram Chat Title",
      "affected": {
        "vendors": [
          "pechenki"
        ],
        "products": [
          {
            "vendor": "pechenki",
            "product": "TelSender – Сontact form 7, Events, Wpforms, ninja forms  and woocommerce to telegram bot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23789
      },
      "nvd": {
        "published": "2026-07-10T05:16:33.117",
        "lastModified": "2026-07-10T17:16:54.023",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15298",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cb02878a-2c85-4dcb-bdc0-e65addf9fb9c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/telsender/trunk/js/ajax.js#L139",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/telsender/tags/1.14.14/js/ajax.js#L139",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/telsender/trunk/js/ajax.js#L119",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/telsender/tags/1.14.14/js/ajax.js#L119",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/telsender/trunk/template/view.php#L111",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/telsender/tags/1.14.14/template/view.php#L111",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3449367%40telsender&new=3449367%40telsender&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 466,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15299",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:54:12.688Z",
      "date_published": "2026-07-10T04:31:27.184Z",
      "date_updated": "2026-07-10T13:16:15.917Z",
      "publisher": "Wordfence",
      "title": "Animation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget",
      "affected": {
        "vendors": [
          "wealcoder"
        ],
        "products": [
          {
            "vendor": "wealcoder",
            "product": "Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09244
      },
      "nvd": {
        "published": "2026-07-10T05:16:33.257",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15299",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Weather widget stores unchecked selector values and inserts them into an HTML class attribute without esc_attr.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e2e755c7-7d1e-45f7-9d0b-2df1ef0bdd02?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/animation-addons-for-elementor/tags/2.6.3/widgets/weather.php#L1246",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/animation-addons-for-elementor/tags/2.6.4/widgets/weather.php#L1246",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=/animation-addons-for-elementor/tags/2.6.3&new_path=/animation-addons-for-elementor/tags/2.6.4",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 938,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15300",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:54:32.605Z",
      "date_published": "2026-07-10T04:31:27.623Z",
      "date_updated": "2026-07-10T15:19:46.580Z",
      "publisher": "Wordfence",
      "title": "GEO my WP <= 4.5.4 - Unauthenticated SQL Injection via 'distance' / 'lat' / 'lng' Parameters",
      "affected": {
        "vendors": [
          "ninjew"
        ],
        "products": [
          {
            "vendor": "ninjew",
            "product": "GEO my WP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00349,
        "percentile": 0.2758
      },
      "nvd": {
        "published": "2026-07-10T05:16:33.393",
        "lastModified": "2026-07-10T16:16:26.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15300",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GEO my WP interpolates unquoted distance and coordinate values into SQL after esc_sql(), which does not make numeric query positions safe.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ecbc7f05-fc4f-4276-968e-04222a64e55a?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.4/plugins/posts-locator/includes/class-gmw-wp-query.php#L299",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.4/plugins/posts-locator/includes/class-gmw-wp-query.php#L300",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.4/plugins/posts-locator/includes/class-gmw-wp-query.php#L301",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5/plugins/posts-locator/includes/class-gmw-wp-query.php#L286",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5/plugins/posts-locator/includes/class-gmw-wp-query.php#L305",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 912,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15301",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:54:45.457Z",
      "date_published": "2026-07-10T04:31:28.002Z",
      "date_updated": "2026-07-10T18:14:23.338Z",
      "publisher": "Wordfence",
      "title": "BuddyHolis TableSearch <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting",
      "affected": {
        "vendors": [
          "digiblogger"
        ],
        "products": [
          {
            "vendor": "digiblogger",
            "product": "BuddyHolis TableSearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05249
      },
      "nvd": {
        "published": "2026-07-10T05:16:33.537",
        "lastModified": "2026-07-10T19:17:20.713",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15301",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The TableSearch placeholder value is stored and rendered without sufficient HTML-context sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/eea79152-76ef-4331-8999-e13f92cd08f4?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tablesearch/tags/1.1.0/tablesearch.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15302",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:55:24.951Z",
      "date_published": "2026-07-10T04:31:20.993Z",
      "date_updated": "2026-07-14T01:33:22.500Z",
      "publisher": "Wordfence",
      "title": "ARMember <= 4.0.27 - Directory Traversal via X-FILENAME",
      "affected": {
        "vendors": [
          "reputeinfosystems"
        ],
        "products": [
          {
            "vendor": "reputeinfosystems",
            "product": "ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-36",
          "name": "Absolute Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00533,
        "percentile": 0.42012
      },
      "nvd": {
        "published": "2026-07-10T05:16:33.677",
        "lastModified": "2026-07-14T02:16:53.617",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15302",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The X-FILENAME header can select an upload destination outside the ARMember upload directory.",
        "basis": [
          "CNA",
          "CWE-36"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2c8734f5-4d23-454d-bf00-6e9d36982098?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3062692/armember-membership/trunk/core/classes/class.arm_members_activity.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15304",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T16:13:51.370Z",
      "date_published": "2026-07-28T18:35:51.726Z",
      "date_updated": "2026-07-28T18:55:08.501Z",
      "publisher": "Wordfence",
      "title": "Plugin Organizer <= 10.2.4 - Authenticated (Subscriber+) SQL Injection",
      "affected": {
        "vendors": [
          "foomagoo"
        ],
        "products": [
          {
            "vendor": "foomagoo",
            "product": "Plugin Organizer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16261
      },
      "nvd": {
        "published": "2026-07-28T19:17:31.570",
        "lastModified": "2026-07-28T20:34:39.437",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15304",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Plugin Organizer incorporates PO_plugin_path into SQL without correctly escaping the value or using a parameterized query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c3ca06c0-6a7d-43ee-ac59-698e0f525e23?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/plugin-organizer/tags/10.2.4/lib/PO_Ajax.class.php#L985",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/plugin-organizer/tags/10.2.4/lib/PO_Ajax.class.php#L969",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/plugin-organizer/tags/10.2.4/lib/PluginOrganizer.class.php#L126",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3603359%40plugin-organizer%2Ftags%2F10.2.5%2Flib%2FPO_Ajax.class.php&old=%20%20%203405892%40plugin-organizer%2Ftags%2F10.2.4%2Flib%2FPO_Ajax.class.php&sfp_email=&sfph_mail=",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15305",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T16:25:43.306Z",
      "date_published": "2026-07-14T12:45:10.996Z",
      "date_updated": "2026-07-15T12:26:56.912Z",
      "publisher": "TYPO3",
      "title": "TYPO3 CMS - Unrestricted File Upload in Form Framework",
      "affected": {
        "vendors": [
          "TYPO3"
        ],
        "products": [
          {
            "vendor": "TYPO3",
            "product": "TYPO3 CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-351",
          "name": "Insufficient Type Distinction",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f4fb688c-4412-4426-b4b8-421ecf27b14a",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07038
      },
      "nvd": {
        "published": "2026-07-14T13:18:16.270",
        "lastModified": "2026-07-15T21:00:44.900",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15305",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MIME validator is registered before the concrete form properties are applied, so the configured allowedMimeTypes rule never enters the server-side processing pipeline.",
        "basis": [
          "CNA",
          "CWE-351"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://typo3.org/security/advisory/typo3-core-sa-2026-020",
          "host": "typo3.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/TYPO3/typo3/commit/817ad41cc9dd28aac0fc4d0fe16fc25d46dd554a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/TYPO3/typo3/commit/cfda21050398eb145211a4fa6f9988f10e43e10b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 435,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15306",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T16:25:49.739Z",
      "date_published": "2026-07-16T03:44:30.926Z",
      "date_updated": "2026-07-16T15:11:40.098Z",
      "publisher": "Wordfence",
      "title": "Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scripting via 's' Search Parameter",
      "affected": {
        "vendors": [
          "rextheme"
        ],
        "products": [
          {
            "vendor": "rextheme",
            "product": "Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11982
      },
      "nvd": {
        "published": "2026-07-16T05:16:18.170",
        "lastModified": "2026-07-16T16:19:00.747",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15306",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The search parameter is reflected into Product Feed Manager output without sufficient sanitization and output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/10207866-6615-486b-a60a-a522ed8a0285?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/best-woocommerce-feed/tags/7.6.0/admin/class-rex-product-feed-actions.php#L767",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/best-woocommerce-feed/tags/7.6.0/admin/class-rex-product-feed-actions.php#L841",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/best-woocommerce-feed/tags/7.6.0/admin/class-rex-product-feed-actions.php#L740",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/best-woocommerce-feed/tags/7.6.0/includes/class-rex-product-feed.php#L241",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3607243%40best-woocommerce-feed&new=3607243%40best-woocommerce-feed",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15308",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T17:04:11.926Z",
      "date_published": "2026-07-09T17:10:57.317Z",
      "date_updated": "2026-07-23T18:46:29.182Z",
      "publisher": "PSF",
      "title": "Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations",
      "affected": {
        "vendors": [
          "Python Software Foundation"
        ],
        "products": [
          {
            "vendor": "Python Software Foundation",
            "product": "CPython"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cna@python.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00551,
        "percentile": 0.42999
      },
      "nvd": {
        "published": "2026-07-09T17:16:58.260",
        "lastModified": "2026-07-23T19:16:53.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15308",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Repeated unterminated markup declarations make incremental HTML parsing perform unbounded CPU work.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/",
          "host": "mail.python.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/python/cpython/pull/153031",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/python/cpython/issues/153030",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/09/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15311",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T17:49:30.256Z",
      "date_published": "2026-07-09T23:45:10.318Z",
      "date_updated": "2026-07-10T14:12:45.061Z",
      "publisher": "VulDB",
      "title": "NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting",
      "affected": {
        "vendors": [
          "NousResearch"
        ],
        "products": [
          {
            "vendor": "NousResearch",
            "product": "hermes-agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10459
      },
      "nvd": {
        "published": "2026-07-10T00:16:32.853",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15311",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377247",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377247/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15311",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852843",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/issues/42667",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/pull/42759",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15317",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:07:32.588Z",
      "date_published": "2026-07-10T00:00:13.247Z",
      "date_updated": "2026-07-14T01:26:30.531Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw Guarded Web Fetch Flow web.go WebFetchTool.Execute server-side request forgery",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 5.4,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16026
      },
      "nvd": {
        "published": "2026-07-10T00:16:33.027",
        "lastModified": "2026-07-14T02:16:53.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15317",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server accepts an attacker-controlled destination without constraining the resolved request target to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377257",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377257/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15317",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852877",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3078",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 454,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-15318",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:07:35.019Z",
      "date_published": "2026-07-10T01:30:09.422Z",
      "date_updated": "2026-07-10T20:31:39.059Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw MQTT Channel mqtt.go authorization",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11813
      },
      "nvd": {
        "published": "2026-07-10T02:16:25.457",
        "lastModified": "2026-07-10T21:16:53.933",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15318",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The MQTT handler makes an authorization decision involving client_id, but the public record does not identify the protected object or failed comparison.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377258",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377258/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15318",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852879",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3068",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 470,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-15319",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:07:37.685Z",
      "date_published": "2026-07-10T01:45:08.961Z",
      "date_updated": "2026-07-10T14:24:20.728Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw Launcher access_control.go IPAllowlist access control",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24753
      },
      "nvd": {
        "published": "2026-07-10T03:16:20.433",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15319",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The launcher IP allowlist accepts a remote caller outside the intended access set, but the bypass input and comparison are not disclosed.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377259",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377259/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15319",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852884",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3069",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/pull/3126",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-15320",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:07:40.636Z",
      "date_published": "2026-07-10T02:00:08.478Z",
      "date_updated": "2026-07-10T15:26:27.879Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw pico.go rt.ReloadConfig authorization",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14448
      },
      "nvd": {
        "published": "2026-07-10T03:16:20.723",
        "lastModified": "2026-07-10T16:16:26.120",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15320",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A configuration-reload action lacks the required authorization, but the public record does not identify the missing subject, object, or predicate.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377260",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377260/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15320",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852942",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3071",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 405,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-15321",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:12:04.329Z",
      "date_published": "2026-07-10T02:45:09.559Z",
      "date_updated": "2026-07-10T18:25:35.946Z",
      "publisher": "VulDB",
      "title": "MyEMS Admin Backend svg.py on_post cross site scripting",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "MyEMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 3.3,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 3.3,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 2.9,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12562
      },
      "nvd": {
        "published": "2026-07-10T04:17:47.873",
        "lastModified": "2026-07-10T19:17:20.810",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15321",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "svg.py stores attacker-controlled SVG data that later reaches a browser as executable markup.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377263",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377263/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15321",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/853060",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/MyEMS/myems/issues/412",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/MyEMS/myems/commit/4a97edfbd786c779d0322054833b21ddf54d5b06",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/MyEMS/myems/releases/tag/v6.5.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/MyEMS/myems/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 587,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-15322",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:13:22.722Z",
      "date_published": "2026-07-17T19:35:19.725Z",
      "date_updated": "2026-07-21T02:08:29.327Z",
      "publisher": "ibm",
      "title": "Multiple Vulnerabilities in IBM Engineering AI hub.",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Engineering AI Hub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-598",
          "name": "Use of HTTP Request With Sensitive Query String",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.2269
      },
      "nvd": {
        "published": "2026-07-17T20:17:15.800",
        "lastModified": "2026-07-24T16:15:17.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15322",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Engineering AI Hub places a session secret in a URL where intermediaries and history can retain it.",
        "basis": [
          "CNA",
          "CWE-598"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7279964",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 155,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15324",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:15:48.011Z",
      "date_published": "2026-07-16T08:26:51.208Z",
      "date_updated": "2026-07-17T14:07:57.987Z",
      "publisher": "Wordfence",
      "title": "SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameter",
      "affected": {
        "vendors": [
          "phppoet"
        ],
        "products": [
          {
            "vendor": "phppoet",
            "product": "SysBasics Customize My Account for WooCommerce – Live My Account Customizer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11023
      },
      "nvd": {
        "published": "2026-07-16T09:16:17.920",
        "lastModified": "2026-07-17T14:17:20.417",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15324",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The account customizer stores or reflects attacker-controlled values into HTML without the required output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b2371b84-bb56-4e5d-afce-cd33f2ee9316?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customize-my-account-for-woocommerce/tags/4.4.14/templates/myaccount/navigation/02.php#L187",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customize-my-account-for-woocommerce/tags/4.4.14/include/admin/endpoint_form_response.php#L9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customize-my-account-for-woocommerce/tags/4.4.14/include/admin/admin_settings.php#L144",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customize-my-account-for-woocommerce/trunk/templates/myaccount/navigation/02.php#L187",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customize-my-account-for-woocommerce/trunk/include/admin/endpoint_form_response.php#L9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/customize-my-account-for-woocommerce/trunk/include/admin/admin_settings.php#L144",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3606867%40customize-my-account-for-woocommerce&new=3606867%40customize-my-account-for-woocommerce",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 475,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15325",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:18:09.780Z",
      "date_published": "2026-07-28T20:07:37.401Z",
      "date_updated": "2026-07-30T03:55:30.155Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          },
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.1106
      },
      "nvd": {
        "published": "2026-07-28T21:17:27.770",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15325",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebSphere interprets TRACE requests inconsistently across HTTP participants, allowing a request boundary to be smuggled through the chain.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281625",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15326",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:20:45.794Z",
      "date_published": "2026-07-10T03:15:08.830Z",
      "date_updated": "2026-07-10T14:04:36.292Z",
      "publisher": "VulDB",
      "title": "halo-dev halo Theme Installation ThemeUtils.java ThemeUtils.unzipThemeTo path traversal",
      "affected": {
        "vendors": [
          "halo-dev"
        ],
        "products": [
          {
            "vendor": "halo-dev",
            "product": "halo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.7,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:N/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.7,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00364,
        "percentile": 0.29156
      },
      "nvd": {
        "published": "2026-07-10T04:17:48.090",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15326",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled path is used without confinement to the intended directory, allowing file access outside that namespace.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377265",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377265/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15326",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/853064",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/halo-dev/halo/issues/10062",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/halo-dev/halo/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 438,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:20:49.634Z",
      "date_published": "2026-07-28T20:04:41.632Z",
      "date_updated": "2026-07-30T03:55:30.946Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent Interpretation of HTTP Requests",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          },
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11059
      },
      "nvd": {
        "published": "2026-07-28T21:17:27.920",
        "lastModified": "2026-07-30T14:08:40.373",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15328",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebSphere components interpret the same HTTP request boundaries inconsistently, allowing one request stream to be parsed as different requests downstream.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281625",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 159,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15329",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:37:41.980Z",
      "date_published": "2026-07-10T03:30:08.320Z",
      "date_updated": "2026-07-14T01:28:47.883Z",
      "publisher": "VulDB",
      "title": "zhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate information disclosure",
      "affected": {
        "vendors": [
          "zhayujie"
        ],
        "products": [
          {
            "vendor": "zhayujie",
            "product": "CowAgent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15364
      },
      "nvd": {
        "published": "2026-07-10T04:17:50.590",
        "lastModified": "2026-07-14T02:16:53.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15329",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record names BrowserTool._do_navigate and remote information disclosure but does not identify the supplied value, disclosed data, destination, or failing operation.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377272",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377272/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15329",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/853098",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/issues/2871",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/issues/2871#issuecomment-4922534422",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15330",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:37:44.563Z",
      "date_published": "2026-07-10T04:00:10.896Z",
      "date_updated": "2026-07-10T20:31:19.060Z",
      "publisher": "VulDB",
      "title": "zhayujie CowAgent Vision Tool vision.py _download_to_data_url server-side request forgery",
      "affected": {
        "vendors": [
          "zhayujie"
        ],
        "products": [
          {
            "vendor": "zhayujie",
            "product": "CowAgent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27886
      },
      "nvd": {
        "published": "2026-07-10T05:16:33.820",
        "lastModified": "2026-07-10T21:16:54.053",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15330",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An image argument controls a server-side fetch destination without restricting it to approved hosts or address ranges.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377273",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377273/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15330",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/853103",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/issues/2872",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/pull/2886",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/commit/e85290cddcbb5ffc9c235927f4c92e5b4c3ec264",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/releases/tag/2.1.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 562,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15331",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:37:47.214Z",
      "date_published": "2026-07-10T04:15:10.104Z",
      "date_updated": "2026-07-10T14:26:46.944Z",
      "publisher": "VulDB",
      "title": "zhayujie CowAgent Skill Installation service.py _add_package path traversal",
      "affected": {
        "vendors": [
          "zhayujie"
        ],
        "products": [
          {
            "vendor": "zhayujie",
            "product": "CowAgent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:P/E:ND/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00378,
        "percentile": 0.30493
      },
      "nvd": {
        "published": "2026-07-10T05:16:34.010",
        "lastModified": "2026-07-10T15:43:30.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15331",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "_add_url and _add_package use the attacker-controlled Name value in skill-installation paths without confining resolution to the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377274",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377274/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15331",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/853104",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/issues/2873",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/pull/2886",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/commit/e85290cddcbb5ffc9c235927f4c92e5b4c3ec264",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/releases/tag/2.1.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 489,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15332",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:37:50.069Z",
      "date_published": "2026-07-10T04:45:08.053Z",
      "date_updated": "2026-07-10T15:17:55.107Z",
      "publisher": "VulDB",
      "title": "zhayujie CowAgent Message Endpoint channel.py authorization",
      "affected": {
        "vendors": [
          "zhayujie"
        ],
        "products": [
          {
            "vendor": "zhayujie",
            "product": "CowAgent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11243
      },
      "nvd": {
        "published": "2026-07-10T05:16:34.200",
        "lastModified": "2026-07-10T16:16:26.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15332",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "CowAgent's message endpoint omits an authorization decision, but the record does not identify the protected action or caller-to-object binding.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377275",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377275/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15332",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/853105",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/issues/2874",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15333",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T18:40:02.166Z",
      "date_published": "2026-07-24T06:51:58.906Z",
      "date_updated": "2026-07-24T11:01:57.309Z",
      "publisher": "Wordfence",
      "title": "Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute",
      "affected": {
        "vendors": [
          "cozythemes"
        ],
        "products": [
          {
            "vendor": "cozythemes",
            "product": "Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16464
      },
      "nvd": {
        "published": "2026-07-24T08:16:25.777",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15333",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0cc9cad8-0e2f-4ecf-9ca7-15ca060879c1?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php#L2258",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php#L2170",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php#L2160",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php#L2183",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php#L2251",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php#L2254",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/functions.php#L2374",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/includes/functions.php#L2258",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/includes/functions.php#L2170",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/includes/functions.php#L2160",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/includes/functions.php#L2183",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/includes/functions.php#L2251",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/includes/functions.php#L2254",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/includes/functions.php#L2374",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3619461%40cozy-addons&new=3619461%40cozy-addons",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 502,
        "referenceCount": 16,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15334",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T19:00:09.445Z",
      "date_published": "2026-07-24T06:51:59.674Z",
      "date_updated": "2026-07-24T14:49:08.119Z",
      "publisher": "Wordfence",
      "title": "Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon.view' Block Attribute",
      "affected": {
        "vendors": [
          "cozythemes"
        ],
        "products": [
          {
            "vendor": "cozythemes",
            "product": "Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16464
      },
      "nvd": {
        "published": "2026-07-24T08:16:25.910",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15334",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The icon.view block attribute is stored and rendered without sufficient sanitization and HTML-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2daddb7a-0ea7-4d11-8699-1982e336120f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/advanced-categories/render.php#L425",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/advanced-categories/render.php#L413",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/advanced-categories/render.php#L414",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/advanced-categories/render.php#L426",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/advanced-categories/render.php#L427",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/advanced-categories/block.json#L354",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/blocks/advanced-categories/render.php#L425",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/blocks/advanced-categories/render.php#L413",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/blocks/advanced-categories/render.php#L414",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/blocks/advanced-categories/render.php#L426",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/blocks/advanced-categories/render.php#L427",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.9/blocks/advanced-categories/block.json#L354",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3619461%40cozy-addons&new=3619461%40cozy-addons",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 14,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15335",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T19:26:57.609Z",
      "date_published": "2026-07-11T03:44:24.811Z",
      "date_updated": "2026-07-14T14:24:49.343Z",
      "publisher": "Wordfence",
      "title": "Booking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form Parameter",
      "affected": {
        "vendors": [
          "masaakitanaka"
        ],
        "products": [
          {
            "vendor": "masaakitanaka",
            "product": "Booking Package"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00482,
        "percentile": 0.38983
      },
      "nvd": {
        "published": "2026-07-11T05:16:32.923",
        "lastModified": "2026-07-14T15:16:57.703",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15335",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8bc86a29-cb1f-4711-925c-51dbbf682477?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-package/tags/1.7.18/lib/Schedule.php#L9365",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-package/tags/1.7.20/lib/Schedule.php#L9365",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-package/tags/1.7.20/lib/Schedule.php#L12793",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-package/tags/1.7.20/index.php#L4381",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-package/tags/1.7.20/index.php#L243",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-package/tags/1.7.18/lib/Schedule.php#L12793",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-package/tags/1.7.18/index.php#L4381",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/booking-package/tags/1.7.18/index.php#L243",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3602166%40booking-package&new=3602166%40booking-package",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 850,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T19:28:35.242Z",
      "date_published": "2026-07-16T02:30:55.251Z",
      "date_updated": "2026-07-17T12:37:02.694Z",
      "publisher": "Wordfence",
      "title": "Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter",
      "affected": {
        "vendors": [
          "catchplugins"
        ],
        "products": [
          {
            "vendor": "catchplugins",
            "product": "Catch Themes Demo Import"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16431
      },
      "nvd": {
        "published": "2026-07-16T04:17:22.073",
        "lastModified": "2026-07-17T13:17:57.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15336",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A WordPress plugin performs installation through a request path before enforcing the capability required to install code.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/12c7661c-0700-4370-9272-d8a19b17006e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.2/inc/demo-importer.php#L233",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.3/inc/demo-importer.php#L233",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.3/inc/demo-importer.php#L135",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.3/inc/demo-importer.php#L136",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.3/inc/demo-importer.php#L235",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.2/inc/demo-importer.php#L135",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.2/inc/demo-importer.php#L136",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/catch-themes-demo-import/tags/3.2/inc/demo-importer.php#L235",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3604098%40catch-themes-demo-import&new=3604098%40catch-themes-demo-import",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 605,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15338",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T19:30:47.385Z",
      "date_published": "2026-07-11T02:31:18.532Z",
      "date_updated": "2026-07-14T14:19:00.588Z",
      "publisher": "Wordfence",
      "title": "LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting",
      "affected": {
        "vendors": [
          "choijun"
        ],
        "products": [
          {
            "vendor": "choijun",
            "product": "LA-Studio Element Kit for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00549,
        "percentile": 0.42869
      },
      "nvd": {
        "published": "2026-07-11T04:17:22.537",
        "lastModified": "2026-07-14T15:16:57.813",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15338",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "get_type_template normalizes separators but neither resolves nor rejects traversal segments before selecting the PHP include target.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c4c3f136-fa26-4813-9e69-f94eba9e4df7?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/tags/1.6.1/includes/addons/progress-bar.php#L869",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/tags/1.6.1/lastudio-element-kit.php#L430",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/tags/1.6.1/includes/addons/progress-bar.php#L866",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/tags/1.6.1/templates/progress-bar/global/index.php#L6",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/tags/1.6.1/templates/progress-bar/global/index.php#L20",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3602507%40lastudio-element-kit&new=3602507%40lastudio-element-kit",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 817,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15342",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T20:03:50.205Z",
      "date_published": "2026-07-21T16:42:52.478Z",
      "date_updated": "2026-07-22T19:01:12.727Z",
      "publisher": "certcc",
      "title": "CVE-2026-15342",
      "affected": {
        "vendors": [
          "Plane"
        ],
        "products": [
          {
            "vendor": "Plane",
            "product": "Plane"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-552",
          "name": "Files or Directories Accessible to External Parties",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.1333
      },
      "nvd": {
        "published": "2026-07-21T17:17:04.450",
        "lastModified": "2026-07-23T15:29:23.713",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15342",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Plane asset endpoints accept a workspace slug and asset ID without confirming that the caller belongs to the targeted workspace.",
        "basis": [
          "CNA",
          "CWE-552",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/makeplane/plane",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://kb.cert.org/vuls/id/762226",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/762226",
          "host": "www.kb.cert.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15343",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T20:11:46.081Z",
      "date_published": "2026-07-17T15:18:46.037Z",
      "date_updated": "2026-07-17T16:33:04.480Z",
      "publisher": "GitHub_P",
      "title": "Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths",
      "affected": {
        "vendors": [
          "GitHub"
        ],
        "products": [
          {
            "vendor": "GitHub",
            "product": "Enterprise Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:product-cna@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00446,
        "percentile": 0.36617
      },
      "nvd": {
        "published": "2026-07-17T16:17:13.917",
        "lastModified": "2026-07-17T18:11:59.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15343",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dependabot validates a nominal dependency path but not the symlink-resolved effective path used to write into the repository.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.18",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.12",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.9",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.5",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.3",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 744,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-15344",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T20:23:15.993Z",
      "date_published": "2026-07-29T02:31:39.343Z",
      "date_updated": "2026-07-29T15:05:33.069Z",
      "publisher": "Wordfence",
      "title": "WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Injection via 'table' Parameter",
      "affected": {
        "vendors": [
          "opajaap"
        ],
        "products": [
          {
            "vendor": "opajaap",
            "product": "WP Photo Album Plus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00355,
        "percentile": 0.28261
      },
      "nvd": {
        "published": "2026-07-29T04:17:13.313",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15344",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The export path inserts the table parameter into SQL without sufficient escaping or a prepared identifier boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/db14e2b8-3217-4f81-a44e-e50734ef304c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.02.003/wppa-ajax.php#L4448",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.03.001/wppa-admin-functions.php#L887",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.03.001/wppa-admin-functions.php#L899",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.03.001/wppa-ajax.php#L4448",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.03.001/wppa-input.php#L399",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.02.003/wppa-admin-functions.php#L887",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.02.003/wppa-admin-functions.php#L899",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.02.003/wppa-input.php#L399",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3602555%40wp-photo-album-plus&new=3602555%40wp-photo-album-plus",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 687,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15346",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T20:28:43.169Z",
      "date_published": "2026-07-24T07:53:37.201Z",
      "date_updated": "2026-07-24T14:48:41.120Z",
      "publisher": "Wordfence",
      "title": "VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Reflected Cross-Site Scripting via 'category_id' Parameter",
      "affected": {
        "vendors": [
          "e4jvikwp"
        ],
        "products": [
          {
            "vendor": "e4jvikwp",
            "product": "VikBooking Hotel Booking Engine & PMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.1773
      },
      "nvd": {
        "published": "2026-07-24T09:16:23.953",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15346",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The category_id request value is reflected into a hidden HTML element without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e456b8c8-ba4a-4199-b006-c6be381b6ef8?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/site/views/search/tmpl/default.php#L409",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.13/site/views/search/tmpl/default.php#L409",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.13/site/views/search/tmpl/default.php#L43",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.13/libraries/adapter/input/filter.php#L233",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.13/site/views/search/tmpl/default.php#L385",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/site/views/search/tmpl/default.php#L43",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/libraries/adapter/input/filter.php#L233",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/site/views/search/tmpl/default.php#L385",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3610507%40vikbooking&new=3610507%40vikbooking",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 540,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T20:39:47.692Z",
      "date_published": "2026-07-23T09:33:56.289Z",
      "date_updated": "2026-07-23T13:54:38.400Z",
      "publisher": "Wordfence",
      "title": "Premium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' Parameter",
      "affected": {
        "vendors": [
          "codename065"
        ],
        "products": [
          {
            "vendor": "codename065",
            "product": "Premium Packages – Sell Digital Products Securely"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24406
      },
      "nvd": {
        "published": "2026-07-23T10:16:50.303",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15348",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The download path trusts unsigned base64-encoded account data and issues an authentication cookie from attacker-controlled values.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0183866d-1eab-4982-b62e-77751c7e738c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.0/wpdm-premium-packages.php#L637",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.3/wpdm-premium-packages.php#L637",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.3/wpdm-premium-packages.php#L585",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.3/includes/libs/functions.php#L1811",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.3/wpdm-premium-packages.php#L632",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.3/wpdm-premium-packages.php#L119",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.0/wpdm-premium-packages.php#L585",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.0/includes/libs/functions.php#L1811",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.0/wpdm-premium-packages.php#L632",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.0/wpdm-premium-packages.php#L119",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3611573%40wpdm-premium-packages&new=3611573%40wpdm-premium-packages",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 879,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T20:40:51.432Z",
      "date_published": "2026-07-17T03:43:41.410Z",
      "date_updated": "2026-07-17T13:59:46.504Z",
      "publisher": "Wordfence",
      "title": "ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX Handler",
      "affected": {
        "vendors": [
          "wedevs"
        ],
        "products": [
          {
            "vendor": "wedevs",
            "product": "ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19363
      },
      "nvd": {
        "published": "2026-07-17T05:16:38.197",
        "lastModified": "2026-07-17T14:59:38.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15349",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An ERP action lets subscribers create company locations without checking an administrative capability.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0c943b6b-9b54-4569-a027-11571f152b6c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/erp/tags/1.17.5/includes/Admin/Ajax.php#L516",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/erp/tags/1.17.6/includes/Admin/Ajax.php#L516",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/erp/tags/1.17.6/includes/Admin/Ajax.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/erp/tags/1.17.6/includes/Admin/AdminPage.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/erp/tags/1.17.6/includes/Admin/views/address.php#L72",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/erp/tags/1.17.5/includes/Admin/Ajax.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/erp/tags/1.17.5/includes/Admin/AdminPage.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/erp/tags/1.17.5/includes/Admin/views/address.php#L72",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3609754%40erp&new=3609754%40erp",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15350",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T20:41:30.861Z",
      "date_published": "2026-07-16T07:51:01.300Z",
      "date_updated": "2026-07-16T13:44:37.970Z",
      "publisher": "Wordfence",
      "title": "The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Log Deletion via 'the_log_purge' Parameter",
      "affected": {
        "vendors": [
          "kevp75"
        ],
        "products": [
          {
            "vendor": "kevp75",
            "product": "The Cache Purger"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12813
      },
      "nvd": {
        "published": "2026-07-16T09:16:18.047",
        "lastModified": "2026-07-16T14:16:48.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15350",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that The Cache Purger permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5a9943b5-0f6d-4fbd-97eb-df61acd0c297?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-cache-purger/tags/2.3.03/work/inc/kp-cache-purge-common.php#L242",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-cache-purger/tags/2.3.03/work/inc/kp-cache-purge-common.php#L223",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-cache-purger/tags/2.3.03/work/inc/kp-cache-purge-common.php#L99",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-cache-purger/tags/2.3.03/work/inc/kp-cache-purge-admin.php#L132",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3603867%40the-cache-purger&new=3603867%40the-cache-purger",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 663,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T22:03:49.631Z",
      "date_published": "2026-07-16T19:48:43.886Z",
      "date_updated": "2026-07-17T13:26:28.783Z",
      "publisher": "icscert",
      "title": "NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference",
      "affected": {
        "vendors": [
          "NASA"
        ],
        "products": [
          {
            "vendor": "NASA",
            "product": "Core Flight System (cFS) Health & Safety (HS) Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00429,
        "percentile": 0.35332
      },
      "nvd": {
        "published": "2026-07-16T20:16:44.040",
        "lastModified": "2026-07-17T18:31:44.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15352",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Core Flight System (cFS) Health & Safety (HS) Application continues through a path where a required object pointer is null and dereferences that pointer instead of rejecting the input or state.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nasa/HS/releases/tag/v7.0.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-03",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-03.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15370",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T08:14:26.583Z",
      "date_published": "2026-07-21T09:07:34.608Z",
      "date_updated": "2026-07-30T08:29:07.609Z",
      "publisher": "redhat",
      "title": "Libssh: libssh: stack buffer overflow in sftp server longname construction",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00157,
        "percentile": 0.0536
      },
      "nvd": {
        "published": "2026-07-21T09:16:53.683",
        "lastModified": "2026-07-30T13:13:37.153",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15370",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SFTP server concatenates attacker-controlled filenames into a fixed-size stack buffer while building longname values.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47768",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15370",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499049",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15373",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T08:47:07.750Z",
      "date_published": "2026-07-10T14:45:07.443Z",
      "date_updated": "2026-07-13T13:51:54.305Z",
      "publisher": "VulDB",
      "title": "Eleveo Call Recording Software userAddAction.do improper authorization",
      "affected": {
        "vendors": [
          "Eleveo"
        ],
        "products": [
          {
            "vendor": "Eleveo",
            "product": "Call Recording Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17234
      },
      "nvd": {
        "published": "2026-07-10T16:16:26.357",
        "lastModified": "2026-07-13T15:16:53.823",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15373",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Call Recording Software permits a caller or role to perform an operation outside the authority assigned to that identity.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377440",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377440/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15373",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/797457",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/omarelshopky/cves/tree/main/eleveo/call-recording-software/CVE-2026-15373",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15374",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T08:47:10.996Z",
      "date_published": "2026-07-10T15:00:09.778Z",
      "date_updated": "2026-07-13T14:34:14.669Z",
      "publisher": "VulDB",
      "title": "Eleveo Call Recording Software Group roleAddAction.do improper authorization",
      "affected": {
        "vendors": [
          "Eleveo"
        ],
        "products": [
          {
            "vendor": "Eleveo",
            "product": "Call Recording Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17234
      },
      "nvd": {
        "published": "2026-07-10T16:16:26.517",
        "lastModified": "2026-07-13T16:16:33.867",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15374",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The group role-add endpoint lets a caller assign privileges beyond those authorized for that caller.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377441",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377441/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15374",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/797458",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/omarelshopky/cves/tree/main/eleveo/call-recording-software/CVE-2026-15374",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 407,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15375",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T08:47:14.350Z",
      "date_published": "2026-07-10T15:15:07.109Z",
      "date_updated": "2026-07-14T01:52:31.281Z",
      "publisher": "VulDB",
      "title": "Eleveo Call Recording Software LDAP User users_ldap.jsp improper authorization",
      "affected": {
        "vendors": [
          "Eleveo"
        ],
        "products": [
          {
            "vendor": "Eleveo",
            "product": "Call Recording Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12842
      },
      "nvd": {
        "published": "2026-07-10T16:16:26.667",
        "lastModified": "2026-07-14T02:16:53.997",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15375",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The LDAP user interface permits a remote action without the required privilege, but the public record does not identify the missing object or operation check.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377442",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377442/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15375",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/797459",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/omarelshopky/cves/blob/main/eleveo/call-recording-software/CVE-2026-15375",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/omarelshopky/cves/tree/main/eleveo/call-recording-software/CVE-2026-15375",
          "host": "github.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15376",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T08:47:17.326Z",
      "date_published": "2026-07-10T15:45:06.117Z",
      "date_updated": "2026-07-13T17:21:17.573Z",
      "publisher": "VulDB",
      "title": "Eleveo Call Recording Software statisticReportAction.do improper authorization",
      "affected": {
        "vendors": [
          "Eleveo"
        ],
        "products": [
          {
            "vendor": "Eleveo",
            "product": "Call Recording Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17234
      },
      "nvd": {
        "published": "2026-07-10T17:16:54.267",
        "lastModified": "2026-07-13T18:16:27.387",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15376",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A Call Recording Software report endpoint performs an action without enforcing the required authorization, while the missing role or object check is not public.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377443",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377443/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15376",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/797461",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/omarelshopky/cves/tree/main/eleveo/call-recording-software/CVE-2026-15376",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T08:47:20.246Z",
      "date_published": "2026-07-10T16:15:07.716Z",
      "date_updated": "2026-07-13T17:24:35.682Z",
      "publisher": "VulDB",
      "title": "Eleveo Call Recording Software sendlogfile improper authorization",
      "affected": {
        "vendors": [
          "Eleveo"
        ],
        "products": [
          {
            "vendor": "Eleveo",
            "product": "Call Recording Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00255,
        "percentile": 0.1707
      },
      "nvd": {
        "published": "2026-07-10T17:16:54.430",
        "lastModified": "2026-07-13T18:16:27.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15377",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The sendlogfile endpoint performs an operation without a sufficient authorization decision, while the public record does not identify the missing role or object check.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377444",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377444/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15377",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/797462",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/omarelshopky/cves/tree/main/eleveo/call-recording-software/CVE-2026-15377",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T08:57:01.261Z",
      "date_published": "2026-07-10T09:29:55.593Z",
      "date_updated": "2026-07-14T01:37:07.099Z",
      "publisher": "redhat",
      "title": "Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift AI (RHOAI)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.2394
      },
      "nvd": {
        "published": "2026-07-10T10:16:23.553",
        "lastModified": "2026-07-14T02:16:54.120",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15378",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15378",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498941",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 517,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15379",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T09:09:15.879Z",
      "date_published": "2026-07-17T06:47:42.858Z",
      "date_updated": "2026-07-21T14:15:20.358Z",
      "publisher": "symantec",
      "title": "Arbitrary File Read as SYSTEM in Symantec ITMS",
      "affected": {
        "vendors": [
          "Broadcom"
        ],
        "products": [
          {
            "vendor": "Broadcom",
            "product": "Symantec IT Management Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:Y/R:A/V:C/RE:M/U:Red"
        },
        {
          "source": "NVD:secure@symantec.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:C/RE:M/U:Red"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00102,
        "percentile": 0.01103
      },
      "nvd": {
        "published": "2026-07-17T08:16:57.773",
        "lastModified": "2026-07-21T15:16:31.170",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15379",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The WMI provider services a standard user's read in LocalSystem context instead of re-impersonating the caller before opening the file.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37995",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T09:09:18.592Z",
      "date_published": "2026-07-17T06:57:17.699Z",
      "date_updated": "2026-07-21T14:12:38.302Z",
      "publisher": "symantec",
      "title": "Local privilege escalation in Symantec ITMS",
      "affected": {
        "vendors": [
          "Broadcom"
        ],
        "products": [
          {
            "vendor": "Broadcom",
            "product": "Symantec Management Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/S:N/AU:Y/R:A/V:C/RE:M/U:Red"
        },
        {
          "source": "NVD:secure@symantec.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:C/RE:M/U:Red"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01931
      },
      "nvd": {
        "published": "2026-07-17T08:16:58.913",
        "lastModified": "2026-07-21T15:16:31.553",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15380",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A non-administrator can traverse a DCOM and scheduled-task permission chain that launches attacker-controlled work as SYSTEM.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37995",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15381",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T09:17:04.966Z",
      "date_published": "2026-07-31T06:00:09.998Z",
      "date_updated": "2026-07-31T17:47:20.807Z",
      "publisher": "WPScan",
      "title": "WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filter",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "WP Go Maps"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07564
      },
      "nvd": {
        "published": "2026-07-31T07:16:27.143",
        "lastModified": "2026-07-31T18:17:10.670",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15381",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/9676af2f-8871-4715-b420-082b1afeb7b4/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T09:19:33.064Z",
      "date_published": "2026-07-30T06:00:09.547Z",
      "date_updated": "2026-07-30T15:07:15.237Z",
      "publisher": "WPScan",
      "title": "Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Deletion via delete-bsf-fonts",
      "affected": {
        "vendors": [
          "Unknown"
        ],
        "products": [
          {
            "vendor": "Unknown",
            "product": "Ultimate Addons for WPBakery Page Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13401
      },
      "nvd": {
        "published": "2026-07-30T06:25:02.330",
        "lastModified": "2026-07-30T16:16:56.453",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15382",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The icon-pack deletion endpoint performs neither a capability check nor a nonce check before deleting the site custom icon fonts.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/54e94f13-758d-4e05-9993-c72ea270e216/",
          "host": "wpscan.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T11:40:35.281Z",
      "date_published": "2026-07-14T10:10:29.514Z",
      "date_updated": "2026-07-14T12:08:21.909Z",
      "publisher": "INCIBE",
      "title": "Inadequate access control in Sesame Time session management",
      "affected": {
        "vendors": [
          "Sesame Time"
        ],
        "products": [
          {
            "vendor": "Sesame Time",
            "product": "Sesame Time"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19695
      },
      "nvd": {
        "published": "2026-07-14T11:16:48.053",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15389",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The API treats possession of any USID as sufficient without verifying that the identifier belongs to the requesting user.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/inadequate-access-control-sesame-time-session-management",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 777,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T12:52:40.335Z",
      "date_published": "2026-07-14T15:34:01.547Z",
      "date_updated": "2026-07-15T14:01:34.760Z",
      "publisher": "CPANSec",
      "title": "DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location",
      "affected": {
        "vendors": [
          "HMBRAND"
        ],
        "products": [
          {
            "vendor": "HMBRAND",
            "product": "DBD::File"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05918
      },
      "nvd": {
        "published": "2026-07-14T16:16:45.827",
        "lastModified": "2026-07-15T14:17:17.997",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15392",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file operation follows a symlink from f_dir beyond the intended filesystem namespace.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mh3j-xwf4-jrqw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://metacpan.org/release/HMBRAND/DBI-1.651/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/perl5-dbi/dbi/commit/96d62dfe4528bf56fe13f413ed323d4252531728.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/14/15",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 453,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15393",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T13:02:10.347Z",
      "date_published": "2026-07-28T12:36:32.251Z",
      "date_updated": "2026-07-28T13:26:49.122Z",
      "publisher": "Wordfence",
      "title": "Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute",
      "affected": {
        "vendors": [
          "cozythemes"
        ],
        "products": [
          {
            "vendor": "cozythemes",
            "product": "Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16465
      },
      "nvd": {
        "published": "2026-07-28T13:17:34.697",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15393",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The postMeta.font.size block attribute reaches stored HTML output without sufficient sanitization or escaping.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e93de7ae-c3a8-4536-9c07-e64d7746e05f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/includes/Helpers/class-block-render.php#L512",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/Helpers/class-block-render.php#L512",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/Helpers/class-block-render.php#L513",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/Helpers/class-block-render.php#L531",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/Helpers/class-block-render.php#L532",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/Helpers/class-block-render.php#L550",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/includes/Helpers/class-block-render.php#L551",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/categorized-post-tabs/render.php#L1",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/includes/Helpers/class-block-render.php#L513",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/includes/Helpers/class-block-render.php#L531",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/includes/Helpers/class-block-render.php#L532",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/includes/Helpers/class-block-render.php#L550",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/includes/Helpers/class-block-render.php#L551",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.10/blocks/categorized-post-tabs/render.php#L1",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3619461%40cozy-addons&new=3619461%40cozy-addons",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 506,
        "referenceCount": 16,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T13:06:59.654Z",
      "date_published": "2026-07-23T09:33:58.720Z",
      "date_updated": "2026-07-23T14:54:29.917Z",
      "publisher": "Wordfence",
      "title": "Header Footer Script Adder <= 2.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'asm_code' Snippet Meta",
      "affected": {
        "vendors": [
          "mahethekiller"
        ],
        "products": [
          {
            "vendor": "mahethekiller",
            "product": "Header Footer Script Adder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.0924
      },
      "nvd": {
        "published": "2026-07-23T10:16:50.433",
        "lastModified": "2026-07-23T16:17:13.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15394",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Header Footer Script Adder renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c394c9bc-21f6-45ea-8eda-8ee22a9b87ba?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/header-and-footer-script-adder/tags/2.1/pro/class-pro-admin.php#L400",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/header-and-footer-script-adder/tags/2.1/pro/class-pro-public.php#L145",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/header-and-footer-script-adder/tags/2.1/pro/class-pro-public.php#L253",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3611085%40header-and-footer-script-adder&new=3611085%40header-and-footer-script-adder",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T13:11:19.947Z",
      "date_published": "2026-07-17T02:31:32.279Z",
      "date_updated": "2026-07-17T14:02:05.279Z",
      "publisher": "Wordfence",
      "title": "Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value",
      "affected": {
        "vendors": [
          "wpchill"
        ],
        "products": [
          {
            "vendor": "wpchill",
            "product": "Kali Forms — Contact Form & Drag-and-Drop Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16006
      },
      "nvd": {
        "published": "2026-07-17T04:16:50.840",
        "lastModified": "2026-07-17T14:59:38.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15395",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A public form path stores attacker-controlled markup that later executes when another user views the submission.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/90e39398-19d7-435d-b23f-e93b8cdbcae4?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.17/Inc/Frontend/class-submission-shortcode.php#L198",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.18/Inc/Frontend/class-submission-shortcode.php#L198",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.18/Inc/Frontend/class-form-processor.php#L88",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.18/Inc/Frontend/class-form-processor.php#L997",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.17/Inc/Frontend/class-form-processor.php#L88",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.17/Inc/Frontend/class-form-processor.php#L997",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3609303%40kali-forms&new=3609303%40kali-forms",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 631,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T13:23:25.836Z",
      "date_published": "2026-07-30T11:03:24.802Z",
      "date_updated": "2026-07-30T13:57:54.797Z",
      "publisher": "Wordfence",
      "title": "Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation via wps_sfw_install_plugin_configuration AJAX Action",
      "affected": {
        "vendors": [
          "wpswings"
        ],
        "products": [
          {
            "vendor": "wpswings",
            "product": "Subscriptions for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23755
      },
      "nvd": {
        "published": "2026-07-30T12:17:26.927",
        "lastModified": "2026-07-30T14:16:47.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15397",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The plugin-install AJAX handler permits a shop manager to install and activate arbitrary plugins without checking the administrative capability required for that action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7e898e40-2cc3-4b5a-833b-899e9c9f26d3?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/subscriptions-for-woocommerce/tags/2.0.0/includes/class-subscriptions-for-woocommerce.php#L394",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/subscriptions-for-woocommerce/tags/2.0.0/admin/class-subscriptions-for-woocommerce-admin.php#L1271",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/subscriptions-for-woocommerce/tags/2.0.0/admin/class-subscriptions-for-woocommerce-admin.php#L1248",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://plugins.trac.wordpress.org/changeset?reponame=&old=3624543%40subscriptions-for-woocommerce&new=3624543%40subscriptions-for-woocommerce",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 444,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15401",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T13:37:43.258Z",
      "date_published": "2026-07-24T09:31:45.522Z",
      "date_updated": "2026-07-24T19:52:04.538Z",
      "publisher": "Wordfence",
      "title": "VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter",
      "affected": {
        "vendors": [
          "e4jvikwp"
        ],
        "products": [
          {
            "vendor": "e4jvikwp",
            "product": "VikBooking Hotel Booking Engine & PMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00342,
        "percentile": 0.26846
      },
      "nvd": {
        "published": "2026-07-24T10:16:31.410",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15401",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0714273b-014e-4bed-b394-138f46a77eaa?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/admin/views/editorder/tmpl/default.php#L1405",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.13/admin/views/editorder/tmpl/default.php#L1405",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.13/admin/views/editorder/tmpl/default.php#L1420",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.13/site/controller.php#L304",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.13/site/controller.php#L919",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.13/site/controller.php#L1083",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.13/site/helpers/lib.vikbooking.php#L5415",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/admin/views/editorder/tmpl/default.php#L1420",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/site/controller.php#L304",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/site/controller.php#L919",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/site/controller.php#L1083",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.12/site/helpers/lib.vikbooking.php#L5415",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3610507%40vikbooking&new=3610507%40vikbooking",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 602,
        "referenceCount": 14,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T13:46:46.096Z",
      "date_published": "2026-07-23T08:34:38.958Z",
      "date_updated": "2026-07-23T13:55:19.140Z",
      "publisher": "Wordfence",
      "title": "Bulk Page Generator <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title",
      "affected": {
        "vendors": [
          "niklaslindemann"
        ],
        "products": [
          {
            "vendor": "niklaslindemann",
            "product": "Bulk Page Generator – LPagery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15547
      },
      "nvd": {
        "published": "2026-07-23T10:16:50.560",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15404",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "lpagery_add_filter_text_template_post echoes a raw post title into a JavaScript single-quoted string without JavaScript-context encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6720e68e-16fc-48c2-ad56-1f44a3e78bb2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lpagery/tags/2.5.7/lpagery.php#L513",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lpagery/tags/2.5.7/lpagery.php#L502",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/lpagery/tags/2.5.7/lpagery.php#L504",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3611156%40lpagery&new=3611156%40lpagery",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 812,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15407",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T13:54:17.109Z",
      "date_published": "2026-07-16T07:51:04.964Z",
      "date_updated": "2026-07-18T02:44:35.429Z",
      "publisher": "Wordfence",
      "title": "Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action",
      "affected": {
        "vendors": [
          "themifyme"
        ],
        "products": [
          {
            "vendor": "themifyme",
            "product": "Themify Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21003
      },
      "nvd": {
        "published": "2026-07-16T09:16:18.163",
        "lastModified": "2026-07-18T03:16:35.023",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15407",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Themify Builder path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b59e2773-31f0-4c19-b066-30982761bc44?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.5/classes/class-themify-builder-stylesheet.php#L160",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.7/classes/class-themify-builder-stylesheet.php#L160",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.7/classes/class-themify-builder-stylesheet.php#L17",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.7/classes/class-themify-builder-stylesheet.php#L313",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.7/classes/class-themify-builder-stylesheet.php#L69",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.5/classes/class-themify-builder-stylesheet.php#L17",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.5/classes/class-themify-builder-stylesheet.php#L313",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.5/classes/class-themify-builder-stylesheet.php#L69",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3607906%40themify-builder&new=3607906%40themify-builder",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 667,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T14:12:14.377Z",
      "date_published": "2026-07-14T19:39:34.808Z",
      "date_updated": "2026-08-04T03:56:14.089Z",
      "publisher": "sonicwall",
      "title": "A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.",
      "affected": {
        "vendors": [
          "SonicWall"
        ],
        "products": [
          {
            "vendor": "SonicWall",
            "product": "SMA1000"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.7844,
        "percentile": 0.99541
      },
      "official_kev": {
        "cveID": "CVE-2026-15409",
        "vendorProject": "SonicWall",
        "product": "SMA1000 Appliances",
        "vulnerabilityName": "SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
        "dateAdded": "2026-07-14",
        "shortDescription": "SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-07-17",
        "knownRansomwareCampaignUse": "Known",
        "notes": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-15409",
        "cwes": [
          "CWE-918"
        ]
      },
      "nvd": {
        "published": "2026-07-14T20:16:56.783",
        "lastModified": "2026-07-16T05:16:18.293",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15409",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SMA1000 Work Place interface accepts an attacker-controlled destination and makes a server-side request to that unintended location.",
        "basis": [
          "CNA",
          "CWE-918",
          "https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ",
          "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
        ],
        "deepDive": true,
        "notes": "SonicWall confirms active exploitation, fixed hotfix floors, and suspicious /wsproxy requests with attacker-controlled host parameters; neither the notice nor CISA KEV publishes the internal request-building check."
      },
      "references": [
        {
          "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008",
          "host": "psirt.global.sonicwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T14:12:17.270Z",
      "date_published": "2026-07-14T19:43:03.226Z",
      "date_updated": "2026-08-04T03:56:15.680Z",
      "publisher": "sonicwall",
      "title": "Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticate...",
      "affected": {
        "vendors": [
          "SonicWall"
        ],
        "products": [
          {
            "vendor": "SonicWall",
            "product": "SMA1000"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.76347,
        "percentile": 0.99487
      },
      "official_kev": {
        "cveID": "CVE-2026-15410",
        "vendorProject": "SonicWall",
        "product": "SMA1000 Appliances",
        "vulnerabilityName": "SonicWall SMA1000 Appliances Code Injection Vulnerability",
        "dateAdded": "2026-07-14",
        "shortDescription": "SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-07-17",
        "knownRansomwareCampaignUse": "Known",
        "notes": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-15410",
        "cwes": [
          "CWE-94"
        ]
      },
      "nvd": {
        "published": "2026-07-14T20:16:56.903",
        "lastModified": "2026-07-16T05:16:18.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15410",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SMA1000 code-generation path permits attacker-controlled directives to enter executable code without the required grammar separation.",
        "basis": [
          "CNA",
          "CWE-94",
          "SonicWall PSIRT",
          "CISA KEV JSON"
        ],
        "deepDive": true,
        "notes": "Read SonicWall PSIRT https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 and its official JSON endpoint https://psirtapi.global.sonicwall.com/api/v1/vulndetail/?advisory_id=SNWLID-2026-0008 plus CISA KEV JSON https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; the public material confirms administrator-level post-authentication code injection and active exploitation but does not publish the injected field or command-construction path."
      },
      "references": [
        {
          "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008",
          "host": "psirt.global.sonicwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 298,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15411",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T14:13:24.840Z",
      "date_published": "2026-07-28T11:32:49.652Z",
      "date_updated": "2026-07-28T13:39:31.480Z",
      "publisher": "Wordfence",
      "title": "StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action",
      "affected": {
        "vendors": [
          "wedevs"
        ],
        "products": [
          {
            "vendor": "wedevs",
            "product": "StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17694
      },
      "nvd": {
        "published": "2026-07-28T12:16:35.630",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15411",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated visitor obtains the sole nonce from frontend JavaScript and uses it to overwrite the spsg_popup_products option.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a1e07c9c-7d35-41b4-aaa1-f37c4f10f7ac?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/sales-pop/includes/Ajax.php#L52",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/sales-pop/includes/Ajax.php#L49",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/sales-pop/includes/Ajax.php#L34",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/bogo/includes/EnqueueScript.php#L170",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3619581%40storegrowth-sales-booster&new=3619581%40storegrowth-sales-booster",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 662,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15415",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T14:44:01.436Z",
      "date_published": "2026-07-17T19:36:13.885Z",
      "date_updated": "2026-07-20T15:05:18.931Z",
      "publisher": "AMZN",
      "title": "Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "aws-healthomics-mcp-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16042
      },
      "nvd": {
        "published": "2026-07-17T20:17:15.923",
        "lastModified": "2026-07-20T17:14:58.043",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15415",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper limitation of a pathname to a restricted directory in the linting tools of the AWS HealthOmics MCP Server (aws-healthomics-mcp-server) before version 0.0.36 might allow an actor who can influence the MCP agent to write an actor-controlled content to arbitrary locations outside the intended workflow bundle directory, via directory traversal sequences in the workflow_files input.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://pypi.org/project/awslabs.aws-healthomics-mcp-server/0.0.36/",
          "host": "pypi.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-060-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/awslabs/mcp/security/advisories/GHSA-6x7f-488g-75wm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 708,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15416",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T14:49:39.682Z",
      "date_published": "2026-07-14T08:56:29.942Z",
      "date_updated": "2026-07-15T14:39:52.411Z",
      "publisher": "redhat",
      "title": "Argo-cd: argo cd unauthenticated remote code execution in repo-server via generatemanifest grpc endpoint",
      "affected": {
        "vendors": [
          "Red Hat",
          "argoproj"
        ],
        "products": [
          {
            "vendor": "argoproj",
            "product": "argo-helm"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Openshift Data Foundation 4"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift GitOps"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20303
      },
      "nvd": {
        "published": "2026-07-14T09:16:40.590",
        "lastModified": "2026-07-15T15:16:28.067",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15416",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Argo CD repo-server exposes the generatemanifest gRPC endpoint without authentication, allowing attacker-controlled generation work to execute.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15416",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496732",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-helm/commit/0f245ab",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/argoproj/argo-helm/security/advisories/GHSA-47m3-95c7-g2g8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://thehackernews.com/2026/07/unpatched-argo-cd-repo-server-flaw.html",
          "host": "thehackernews.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql",
          "host": "www.synacktiv.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15420",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T15:00:42.141Z",
      "date_published": "2026-07-24T02:31:59.549Z",
      "date_updated": "2026-07-24T22:10:12.300Z",
      "publisher": "Wordfence",
      "title": "Nexter Blocks <= 5.0.0 - Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' Parameter",
      "affected": {
        "vendors": [
          "posimyththemes"
        ],
        "products": [
          {
            "vendor": "posimyththemes",
            "product": "Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00586,
        "percentile": 0.44713
      },
      "nvd": {
        "published": "2026-07-24T04:16:51.857",
        "lastModified": "2026-07-24T23:16:49.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15420",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/85550779-fd46-4130-92f1-b291d4e86b21?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.14/classes/tp-registered-blocks.php#L2985",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.17/classes/tp-registered-blocks.php#L2985",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.17/classes/tp-registered-blocks.php#L2862",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.17/classes/tp-registered-blocks.php#L3521",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.17/classes/tp-registered-blocks.php#L2710",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.14/classes/tp-registered-blocks.php#L2862",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.14/classes/tp-registered-blocks.php#L3521",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.14/classes/tp-registered-blocks.php#L2710",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3614203%40the-plus-addons-for-block-editor&new=3614203%40the-plus-addons-for-block-editor",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 432,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T15:20:03.858Z",
      "date_published": "2026-07-16T19:29:13.931Z",
      "date_updated": "2026-07-17T13:47:55.303Z",
      "publisher": "illumos",
      "title": "SCTP needs to better-check INIT ACK chunk parameters",
      "affected": {
        "vendors": [
          "OmniOS",
          "Triton Data Center",
          "illumos"
        ],
        "products": [
          {
            "vendor": "illumos",
            "product": "illumos-gate"
          },
          {
            "vendor": "OmniOS",
            "product": "OmniOS"
          },
          {
            "vendor": "Triton Data Center",
            "product": "SmartOS"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/S:P/AU:Y/R:U/V:C/RE:H/U:Red"
        },
        {
          "source": "NVD:0ca53633-f0b5-4853-ba72-e0a2e62000d0",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:H/U:Red"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00508,
        "percentile": 0.40545
      },
      "nvd": {
        "published": "2026-07-16T20:16:44.190",
        "lastModified": "2026-07-17T18:45:53.333",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15422",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "illumos parses malformed SCTP address parameters before integrity validation and writes past a heap allocation when the encoded address data exceeds its expected bound.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://illumos.topicbox.com/groups/developer/Ta1a8e2e1f7f928df/18117-sctp-needs-to-better-check-init-ack-chunk-parameters",
          "host": "illumos.topicbox.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "mailing-list"
          ]
        },
        {
          "url": "https://illumos.org/issues/18117",
          "host": "illumos.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/illumos/illumos-gate/commit/53a3efdeff8e6745bbfb69c5360f94962fb79e75",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 619,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-15425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T16:20:53.214Z",
      "date_published": "2026-07-25T06:50:05.480Z",
      "date_updated": "2026-07-27T14:36:44.294Z",
      "publisher": "Wordfence",
      "title": "Yoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name)",
      "affected": {
        "vendors": [
          "yoast"
        ],
        "products": [
          {
            "vendor": "yoast",
            "product": "Yoast SEO – Advanced SEO with real-time guidance and built-in AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10166
      },
      "nvd": {
        "published": "2026-07-25T07:17:09.897",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15425",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4b2fa1b7-a5af-4ea6-9bee-19a6cdfd7701?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wordpress-seo/tags/28.0/admin/class-bulk-editor-list-table.php#L900",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wordpress-seo/tags/28.0/admin/class-bulk-editor-list-table.php#L898",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wordpress-seo/tags/27.6/admin/class-bulk-editor-list-table.php#L900",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wordpress-seo/tags/27.6/admin/class-bulk-editor-list-table.php#L898",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3598937/wordpress-seo/trunk/admin/class-bulk-editor-list-table.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fwordpress-seo/tags/28.0&new_path=%2Fwordpress-seo/tags/28.1",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 617,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T16:59:14.788Z",
      "date_published": "2026-07-14T17:02:50.086Z",
      "date_updated": "2026-07-15T03:59:48.164Z",
      "publisher": "TPLink",
      "title": "OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v",
      "affected": {
        "vendors": [
          "TP-Link Systems Inc."
        ],
        "products": [
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "Archer VX1800v v1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f23511db-6c3e-4e32-a477-6aa17d310630",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.005,
        "percentile": 0.40073
      },
      "nvd": {
        "published": "2026-07-14T17:16:44.653",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15427",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value reaches operating-system command construction in Archer VX1800v v1 without separating it from command or argument syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tp-link.com/en/support/download/archer-vx1800v/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/faq/5189/",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 534,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T16:59:16.057Z",
      "date_published": "2026-07-14T17:03:33.853Z",
      "date_updated": "2026-07-15T03:59:51.416Z",
      "publisher": "TPLink",
      "title": "OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v",
      "affected": {
        "vendors": [
          "TP-Link Systems Inc."
        ],
        "products": [
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "Archer VX1800v v1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f23511db-6c3e-4e32-a477-6aa17d310630",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00885,
        "percentile": 0.5573
      },
      "nvd": {
        "published": "2026-07-14T17:16:44.790",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15428",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The TR-069 interface passes a domain value containing shell metacharacters to an operating-system command without shell-safe separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tp-link.com/en/support/download/archer-vx1800v/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/faq/5189/",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 418,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15429",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T16:59:17.389Z",
      "date_published": "2026-07-14T17:04:06.888Z",
      "date_updated": "2026-07-15T03:59:52.199Z",
      "publisher": "TPLink",
      "title": "Privilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800v",
      "affected": {
        "vendors": [
          "TP-Link Systems Inc."
        ],
        "products": [
          {
            "vendor": "TP-Link Systems Inc.",
            "product": "Archer VX1800v v1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f23511db-6c3e-4e32-a477-6aa17d310630",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00394,
        "percentile": 0.32145
      },
      "nvd": {
        "published": "2026-07-14T17:16:44.907",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15429",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HTTP authentication component allows newline characters in user input to create additional records in internally generated configuration data.",
        "basis": [
          "CNA",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tp-link.com/en/support/download/archer-vx1800v/#Firmware",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tp-link.com/us/support/faq/5189/",
          "host": "www.tp-link.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15432",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T17:38:15.752Z",
      "date_published": "2026-07-21T16:42:12.113Z",
      "date_updated": "2026-07-22T18:27:24.251Z",
      "publisher": "Google",
      "title": "Observable Timing Discrepancy in Tink-Java and Tink-Android ChunkedMacVerification",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Tink-Java"
          },
          {
            "vendor": "Google",
            "product": "Tink-Android"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-coordination@google.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00185,
        "percentile": 0.08332
      },
      "nvd": {
        "published": "2026-07-21T17:17:04.563",
        "lastModified": "2026-07-22T19:16:55.097",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15432",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ChunkedMacVerification compares MAC tags with a variable-time operation that reveals how many leading tag bytes match.",
        "basis": [
          "CNA",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tink-crypto/tink-java/issues/75",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T18:07:18.710Z",
      "date_published": "2026-07-30T14:08:36.535Z",
      "date_updated": "2026-07-31T16:10:24.469Z",
      "publisher": "ibm",
      "title": "IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "App Connect Enterprise"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00734,
        "percentile": 0.50862
      },
      "nvd": {
        "published": "2026-07-30T15:16:26.757",
        "lastModified": "2026-07-31T16:16:58.413",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15435",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The App Connect Enterprise file operation accepts an attacker-controlled path that escapes the intended directory or storage target.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281896",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15444",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T19:12:53.146Z",
      "date_published": "2026-07-28T11:32:49.252Z",
      "date_updated": "2026-07-28T14:02:13.340Z",
      "publisher": "Wordfence",
      "title": "Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter",
      "affected": {
        "vendors": [
          "themeum"
        ],
        "products": [
          {
            "vendor": "themeum",
            "product": "Tutor LMS – eLearning and online course solution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21017
      },
      "nvd": {
        "published": "2026-07-28T12:16:35.767",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15444",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The coupon_code value is appended to an SQL statement without sufficient escaping or query preparation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9d637d7b-7a47-40db-a931-ec7ca723dfab?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/4.0.1/helpers/QueryHelper.php#L207",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/4.0.1/ecommerce/CouponController.php#L193",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/4.0.1/models/CouponModel.php#L362",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tutor/tags/4.0.1/classes/Input.php#L335",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3618540%40tutor&new=3618540%40tutor",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T19:14:08.824Z",
      "date_published": "2026-07-16T03:44:31.406Z",
      "date_updated": "2026-07-16T12:43:50.670Z",
      "publisher": "Wordfence",
      "title": "SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "affected": {
        "vendors": [
          "cleverplugins"
        ],
        "products": [
          {
            "vendor": "cleverplugins",
            "product": "SEO Booster"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19354
      },
      "nvd": {
        "published": "2026-07-16T05:16:18.633",
        "lastModified": "2026-07-16T13:38:53.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15445",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In SEO Booster, attacker-controlled values reach an SQL statement without the required escaping or parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/59f622ee-eccf-4b5b-8fa0-93a4405eb1e9?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/seo-booster/trunk/inc/SB_GSC_List_Table.php#L579",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/seo-booster/trunk/inc/SB_GSC_List_Table.php#L559",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/seo-booster/trunk/seo-booster-gsc.php#L27",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3606177%40seo-booster&new=3606177%40seo-booster",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 710,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T19:20:56.047Z",
      "date_published": "2026-07-23T09:33:58.352Z",
      "date_updated": "2026-07-23T16:04:18.628Z",
      "publisher": "Wordfence",
      "title": "Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_order_status_filter' Parameter",
      "affected": {
        "vendors": [
          "tickera"
        ],
        "products": [
          {
            "vendor": "tickera",
            "product": "Tickera – Sell Tickets & Manage Events"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16263
      },
      "nvd": {
        "published": "2026-07-23T10:16:50.687",
        "lastModified": "2026-07-23T16:17:13.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15448",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tickera – Sell Tickets & Manage Events incorporates attacker-controlled values or identifiers into a SQL statement without preserving the boundary between query syntax and data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8972b507-4aae-40cc-a79e-2603dbdc70c0?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php#L260",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php#L252",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php#L238",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3618136%40tickera-event-ticketing-system&new=3618136%40tickera-event-ticketing-system",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15449",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T19:23:40.195Z",
      "date_published": "2026-07-16T19:27:16.036Z",
      "date_updated": "2026-07-17T12:42:57.781Z",
      "publisher": "illumos",
      "title": "TOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruption",
      "affected": {
        "vendors": [
          "OmniOS",
          "Triton Data Center",
          "illumos"
        ],
        "products": [
          {
            "vendor": "illumos",
            "product": "illumos-gate"
          },
          {
            "vendor": "OmniOS",
            "product": "OmniOS"
          },
          {
            "vendor": "Triton Data Center",
            "product": "SmartOS"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:0ca53633-f0b5-4853-ba72-e0a2e62000d0",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00084,
        "percentile": 0.00355
      },
      "nvd": {
        "published": "2026-07-16T20:16:44.373",
        "lastModified": "2026-07-17T18:45:53.333",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15449",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ioctl path sizes a kernel allocation from one copy of pr_valsize and then trusts a second copy that another thread can enlarge before use.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://illumos.topicbox.com/groups/developer/T923147fae854a738-M03c29e1be33dac2a5e3d9535/18020-double-copyin-of-dldioc-consumers",
          "host": "illumos.topicbox.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "mailing-list"
          ]
        },
        {
          "url": "https://illumos.org/issues/18020",
          "host": "illumos.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/illumos/illumos-gate/commit/6959feb5b430411a4809b06c53dcdb42fb525eac",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 875,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-15457",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T20:01:36.121Z",
      "date_published": "2026-07-17T03:43:40.514Z",
      "date_updated": "2026-07-21T01:27:08.585Z",
      "publisher": "Wordfence",
      "title": "Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter",
      "affected": {
        "vendors": [
          "themeum"
        ],
        "products": [
          {
            "vendor": "themeum",
            "product": "Kirki – Freeform Page Builder, Website Builder & Customizer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00766,
        "percentile": 0.51966
      },
      "nvd": {
        "published": "2026-07-17T05:16:38.323",
        "lastModified": "2026-07-21T03:16:40.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15457",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kirki – Freeform Page Builder, Website Builder & Customizer resolves attacker-controlled path components without confirming that the final path remains beneath the intended root.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/01a52285-2d0c-4b29-8dab-18a3e3640e5c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.13/app/Services/FontService.php#L157",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.13/app/Http/Controllers/Api/GlobalDataController.php#L105",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.13/routes/api.php#L74",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.13/includes/Ajax/Media.php#L996",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/app/Services/FontService.php#L157",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/app/Http/Controllers/Api/GlobalDataController.php#L105",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/routes/api.php#L74",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/includes/Ajax/Media.php#L996",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3608888%40kirki&new=3608888%40kirki",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T20:03:08.372Z",
      "date_published": "2026-07-16T03:44:32.477Z",
      "date_updated": "2026-07-17T14:08:47.143Z",
      "publisher": "Wordfence",
      "title": "SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'sort_field' Parameter",
      "affected": {
        "vendors": [
          "cleverplugins"
        ],
        "products": [
          {
            "vendor": "cleverplugins",
            "product": "SEO Booster"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19354
      },
      "nvd": {
        "published": "2026-07-16T05:16:18.747",
        "lastModified": "2026-07-17T15:16:46.043",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15458",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SEO Booster inserts sort_field into a query without sufficient escaping or parameter preparation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ffcf8071-89be-484c-9b6a-8b08e12cf100?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/seo-booster/tags/7.3.1/seo-booster.php#L404",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/seo-booster/tags/7.3.1/seo-booster.php#L389",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/seo-booster/tags/7.3.1/seo-booster.php#L406",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3606177%40seo-booster&new=3606177%40seo-booster",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 499,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15464",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:01:50.015Z",
      "date_published": "2026-07-24T06:52:01.916Z",
      "date_updated": "2026-07-24T14:27:56.299Z",
      "publisher": "Wordfence",
      "title": "WP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute",
      "affected": {
        "vendors": [
          "thimpress"
        ],
        "products": [
          {
            "vendor": "thimpress",
            "product": "WP Hotel Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09243
      },
      "nvd": {
        "published": "2026-07-24T08:16:26.033",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15464",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The widget_search shortcode attribute is stored and emitted into HTML without sufficient sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9f3a4258-2f45-4617-a5ca-9b28835ef405?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.2/templates/search/search-form.php#L103",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.2/includes/shortcodes/class-wphb-shortcode-hotel-booking.php#L44",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3609563%40wp-hotel-booking&new=3609563%40wp-hotel-booking",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 540,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15470",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T09:33:16.238Z",
      "date_published": "2026-07-11T23:45:09.686Z",
      "date_updated": "2026-07-13T18:22:03.741Z",
      "publisher": "VulDB",
      "title": "Eleveo Call Recording Software group.jsp improper authorization",
      "affected": {
        "vendors": [
          "Eleveo"
        ],
        "products": [
          {
            "vendor": "Eleveo",
            "product": "Call Recording Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10974
      },
      "nvd": {
        "published": "2026-07-12T00:16:17.480",
        "lastModified": "2026-07-13T19:16:51.223",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15470",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A Call Recording Software group endpoint exposes functionality outside the caller's privileges, while the exact authorization check is not public.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377775",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377775/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15470",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/797463",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/omarelshopky/cves/tree/main/eleveo/call-recording-software/CVE-2026-15470",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15471",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T09:33:19.930Z",
      "date_published": "2026-07-12T01:00:08.434Z",
      "date_updated": "2026-07-13T19:19:11.777Z",
      "publisher": "VulDB",
      "title": "Eleveo Call Recording Software pci_dss_status.jsp improper authorization",
      "affected": {
        "vendors": [
          "Eleveo"
        ],
        "products": [
          {
            "vendor": "Eleveo",
            "product": "Call Recording Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10975
      },
      "nvd": {
        "published": "2026-07-12T02:16:14.703",
        "lastModified": "2026-07-13T20:16:44.807",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15471",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The pci_dss_status.jsp endpoint performs an operation without a sufficient authorization decision, while the public record does not identify the missing role or object check.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377776",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377776/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15471",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/797464",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/omarelshopky/cves/tree/main/eleveo/call-recording-software/CVE-2026-15471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 381,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15472",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T09:33:22.603Z",
      "date_published": "2026-07-12T01:15:09.958Z",
      "date_updated": "2026-07-13T18:22:36.516Z",
      "publisher": "VulDB",
      "title": "Eleveo Call Recording Software composeEmailAction.do improper authorization",
      "affected": {
        "vendors": [
          "Eleveo"
        ],
        "products": [
          {
            "vendor": "Eleveo",
            "product": "Call Recording Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10974
      },
      "nvd": {
        "published": "2026-07-12T02:16:16.380",
        "lastModified": "2026-07-13T19:16:52.023",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15472",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Executing a manipulation can lead to improper authorization.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377777",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377777/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15472",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/797465",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/omarelshopky/cves/tree/main/eleveo/call-recording-software/CVE-2026-15472",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15473",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T09:33:25.486Z",
      "date_published": "2026-07-12T01:30:08.975Z",
      "date_updated": "2026-07-14T14:34:01.039Z",
      "publisher": "VulDB",
      "title": "Eleveo Call Recording Software Recorded Calls restoreCallAction.do improper authorization",
      "affected": {
        "vendors": [
          "Eleveo"
        ],
        "products": [
          {
            "vendor": "Eleveo",
            "product": "Call Recording Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10229
      },
      "nvd": {
        "published": "2026-07-12T03:16:09.530",
        "lastModified": "2026-07-14T15:16:58.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15473",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377778",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377778/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15473",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/797466",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/omarelshopky/cves/tree/main/eleveo/call-recording-software/CVE-2026-15473",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 433,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15474",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T09:33:28.296Z",
      "date_published": "2026-07-12T02:00:08.857Z",
      "date_updated": "2026-07-16T12:12:37.942Z",
      "publisher": "VulDB",
      "title": "Eleveo Call Recording Software audio.jsp improper authorization",
      "affected": {
        "vendors": [
          "Eleveo"
        ],
        "products": [
          {
            "vendor": "Eleveo",
            "product": "Call Recording Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10973
      },
      "nvd": {
        "published": "2026-07-12T03:16:10.700",
        "lastModified": "2026-07-16T13:16:28.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15474",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The component assigns or permits a privilege beyond the authority granted to the invoking user.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377779",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377779/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15474",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/797469",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/omarelshopky/cves/tree/main/eleveo/call-recording-software/CVE-2026-15474",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 454,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15475",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T09:40:55.072Z",
      "date_published": "2026-07-12T02:15:07.520Z",
      "date_updated": "2026-07-13T14:38:31.090Z",
      "publisher": "VulDB",
      "title": "MiniTool Partition Wizard Signed Kernel Driver pwdrvio.sys access control",
      "affected": {
        "vendors": [
          "MiniTool"
        ],
        "products": [
          {
            "vendor": "MiniTool",
            "product": "Partition Wizard"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01244
      },
      "nvd": {
        "published": "2026-07-12T03:16:10.860",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15475",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The signed kernel driver exposes operations to a local caller without adequate access control, while the public record does not identify the affected operation or check.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377780",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377780/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15475",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/833842",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://winslow1984.com/books/cve-collection/page/minitool-partition-wizard-kernel-driver-pwdrviosys-local-privilege-escalation",
          "host": "winslow1984.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.minitool.com/partition-manager/upgrade-history.html",
          "host": "www.minitool.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 510,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-15476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T09:44:33.072Z",
      "date_published": "2026-07-12T03:30:08.128Z",
      "date_updated": "2026-07-13T16:08:06.824Z",
      "publisher": "VulDB",
      "title": "QILING Disk Master Kernel Driver diskbckp.sys access control",
      "affected": {
        "vendors": [
          "QILING"
        ],
        "products": [
          {
            "vendor": "QILING",
            "product": "Disk Master"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01261
      },
      "nvd": {
        "published": "2026-07-12T04:16:20.087",
        "lastModified": "2026-07-13T17:17:05.260",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15476",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Disk Master kernel driver permits a local caller to cross an access-control boundary, but the protected operation and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377781",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377781/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15476",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/835610",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://winslow1984.com/books/cve-collection/page/qiling-disk-master-kernel-driver-diskbckpsys-6-0-0-0-local-privilege-escalation",
          "host": "winslow1984.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.idiskhome.com/download/beta/multi_DiskMaster_Pro_Trial.exe",
          "host": "www.idiskhome.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15477",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T09:49:25.934Z",
      "date_published": "2026-07-12T03:45:09.037Z",
      "date_updated": "2026-07-13T19:11:58.891Z",
      "publisher": "VulDB",
      "title": "Bahmni bahmnicore Search Endpoint sql additionalParams sql injection",
      "affected": {
        "vendors": [
          "Bahmni"
        ],
        "products": [
          {
            "vendor": "Bahmni",
            "product": "bahmnicore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 99,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10617
      },
      "nvd": {
        "published": "2026-07-12T05:16:08.447",
        "lastModified": "2026-07-13T20:16:45.500",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15477",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Bahmni search endpoint incorporates additionalParams input into SQL without separating data from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377782",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377782/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15477",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/836079",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/Bahmni/bahmni-core/security/advisories/GHSA-cg9w-r5g6-cxq5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://bahmni.atlassian.net/wiki/spaces/BAH/pages/5519474693/Bahmni+Security+Patch+July+02+2026+Release+Notes",
          "host": "bahmni.atlassian.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 476,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 99
      }
    },
    {
      "cve_id": "CVE-2026-15478",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T09:53:07.882Z",
      "date_published": "2026-07-12T04:30:07.683Z",
      "date_updated": "2026-07-13T16:33:59.335Z",
      "publisher": "VulDB",
      "title": "IceHRM UserReport Endpoint EmployeeAttendanceReport.php sql injection",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "IceHRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09591
      },
      "nvd": {
        "published": "2026-07-12T05:16:08.747",
        "lastModified": "2026-07-13T17:17:05.937",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15478",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377783",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377783/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15478",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/836330",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/gamonoid/icehrm/issues/376",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 450,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15479",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T09:56:44.847Z",
      "date_published": "2026-07-12T05:00:10.927Z",
      "date_updated": "2026-07-14T14:39:21.478Z",
      "publisher": "VulDB",
      "title": "H3C NX15 Administrator Password Modification Endpoint modify change_passwd password recovery",
      "affected": {
        "vendors": [
          "H3C"
        ],
        "products": [
          {
            "vendor": "H3C",
            "product": "NX15"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20632
      },
      "nvd": {
        "published": "2026-07-12T06:16:41.350",
        "lastModified": "2026-07-14T15:16:58.190",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15479",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The password-change endpoint implements a weak recovery flow that lets a remote caller replace the administrator password.",
        "basis": [
          "CNA record",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377785",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377785/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15479",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/837069",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/pre_auth_pwd_change",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 420,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15480",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T10:02:29.486Z",
      "date_published": "2026-07-12T05:30:08.401Z",
      "date_updated": "2026-07-13T18:12:41.393Z",
      "publisher": "VulDB",
      "title": "Trendnet TEW-635BRM Web Service rc start_httpd stack-based overflow",
      "affected": {
        "vendors": [
          "Trendnet"
        ],
        "products": [
          {
            "vendor": "Trendnet",
            "product": "TEW-635BRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00472,
        "percentile": 0.38383
      },
      "nvd": {
        "published": "2026-07-12T06:16:42.650",
        "lastModified": "2026-07-13T19:16:53.467",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15480",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TEW-635BRM writes attacker-controlled data beyond a stack buffer boundary.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377787",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377787/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15480",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/838236",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/glkfc/IoT-Vulnerability/blob/main/TRENDnet/TRENDnet_TEW635BRM_device_name_BOF_EN.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 638,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T10:02:32.426Z",
      "date_published": "2026-07-12T05:45:07.483Z",
      "date_updated": "2026-07-13T14:39:42.474Z",
      "publisher": "VulDB",
      "title": "Trendnet TEW-635BRM IPoA WAN Connection Setup rc ipoa_test command injection",
      "affected": {
        "vendors": [
          "Trendnet"
        ],
        "products": [
          {
            "vendor": "Trendnet",
            "product": "TEW-635BRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.01563,
        "percentile": 0.72826
      },
      "nvd": {
        "published": "2026-07-12T06:16:42.863",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15481",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ipoa_test path appends the ipoa_ipaddr value to a shell command without separating data from command syntax.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377788",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377788/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15481",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/838237",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/glkfc/IoT-Vulnerability/blob/main/TRENDnet/TRENDnet_TEW635BRM_ipoa_cmdinj_EN.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 703,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T10:05:08.167Z",
      "date_published": "2026-07-12T06:00:08.869Z",
      "date_updated": "2026-07-13T15:46:00.864Z",
      "publisher": "VulDB",
      "title": "Aster Telecom Azcall HTTP sis.php sql injection",
      "affected": {
        "vendors": [
          "Aster Telecom"
        ],
        "products": [
          {
            "vendor": "Aster Telecom",
            "product": "Azcall"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19569
      },
      "nvd": {
        "published": "2026-07-12T07:16:24.737",
        "lastModified": "2026-07-13T17:17:06.613",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15482",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Azcall, attacker-controlled input reaches an SQL statement without the required parameter binding or SQL-context escaping.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377789",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377789/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15482",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/841457",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 485,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15483",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T10:12:16.280Z",
      "date_published": "2026-07-12T06:15:05.879Z",
      "date_updated": "2026-07-15T16:22:52.567Z",
      "publisher": "VulDB",
      "title": "TRENDnet TEW-821DAP ssi tools_nslookup sub_41EC14 buffer overflow",
      "affected": {
        "vendors": [
          "TRENDnet"
        ],
        "products": [
          {
            "vendor": "TRENDnet",
            "product": "TEW-821DAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00472,
        "percentile": 0.38383
      },
      "nvd": {
        "published": "2026-07-12T07:16:24.927",
        "lastModified": "2026-07-15T17:16:45.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15483",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A copy into a fixed memory region proceeds without a sufficient input-size check, allowing the destination bounds to be exceeded.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377790",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377790/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15483",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/842380",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_BO2.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 524,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15484",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T10:12:18.573Z",
      "date_published": "2026-07-12T06:30:06.606Z",
      "date_updated": "2026-07-13T16:30:10.949Z",
      "publisher": "VulDB",
      "title": "TRENDnet TEW-821DAP ssi tools_nslookup sub_41EC14 buffer overflow",
      "affected": {
        "vendors": [
          "TRENDnet"
        ],
        "products": [
          {
            "vendor": "TRENDnet",
            "product": "TEW-821DAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00472,
        "percentile": 0.38384
      },
      "nvd": {
        "published": "2026-07-12T07:16:25.107",
        "lastModified": "2026-07-13T17:17:07.277",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15484",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The tools_nslookup handler copies attacker-controlled input beyond a destination buffer in sub_41EC14.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-119",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377791",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377791/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15484",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/842381",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_BO3.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 490,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15485",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T10:12:21.398Z",
      "date_published": "2026-07-12T07:00:17.966Z",
      "date_updated": "2026-07-14T14:40:25.911Z",
      "publisher": "VulDB",
      "title": "TRENDnet TEW-821DAP DNS Lookup tools_nslookup sub_43F2C4 os command injection",
      "affected": {
        "vendors": [
          "TRENDnet"
        ],
        "products": [
          {
            "vendor": "TRENDnet",
            "product": "TEW-821DAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.01072,
        "percentile": 0.61619
      },
      "nvd": {
        "published": "2026-07-12T08:16:10.940",
        "lastModified": "2026-07-14T15:16:58.317",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15485",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The TEW-821DAP path inserts attacker-controlled text into an operating-system command without preserving the command grammar.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377792",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377792/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15485",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/842382",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_CI3.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15486",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T10:12:24.075Z",
      "date_published": "2026-07-12T08:15:07.110Z",
      "date_updated": "2026-07-13T18:12:38.015Z",
      "publisher": "VulDB",
      "title": "TRENDnet TEW-821DAP Firmware Update tools_ddns sub_42026C os command injection",
      "affected": {
        "vendors": [
          "TRENDnet"
        ],
        "products": [
          {
            "vendor": "TRENDnet",
            "product": "TEW-821DAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.01072,
        "percentile": 0.61618
      },
      "nvd": {
        "published": "2026-07-12T09:16:38.560",
        "lastModified": "2026-07-13T19:16:54.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15486",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A router input is inserted into an operating-system command without shell-grammar neutralization.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377793",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377793/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15486",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/842383",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_CI4.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15487",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T10:12:26.832Z",
      "date_published": "2026-07-12T08:30:08.630Z",
      "date_updated": "2026-07-13T15:17:08.354Z",
      "publisher": "VulDB",
      "title": "TRENDnet TEW-821DAP Firmware Update system_ntp sub_41FBD0 os command injection",
      "affected": {
        "vendors": [
          "TRENDnet"
        ],
        "products": [
          {
            "vendor": "TRENDnet",
            "product": "TEW-821DAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.01072,
        "percentile": 0.61619
      },
      "nvd": {
        "published": "2026-07-12T09:16:39.577",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15487",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The TEW-821DAP command path concatenates attacker-controlled data into an operating-system command without preserving the shell grammar boundary.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377794",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377794/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15487",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/842385",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_CI5.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 523,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T10:18:41.821Z",
      "date_published": "2026-07-12T08:45:09.195Z",
      "date_updated": "2026-07-13T15:44:29.737Z",
      "publisher": "VulDB",
      "title": "hcr707305003 shiroiAdmin FileController.php upload unrestricted upload",
      "affected": {
        "vendors": [
          "hcr707305003"
        ],
        "products": [
          {
            "vendor": "hcr707305003",
            "product": "shiroiAdmin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23789
      },
      "nvd": {
        "published": "2026-07-12T09:16:39.740",
        "lastModified": "2026-07-13T17:17:07.953",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15488",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FileController::upload accepts a caller-supplied file without restricting dangerous uploaded file types.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377795",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377795/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15488",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/843890",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/hcr707305003/shiroiAdmin/releases/tag/v1.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/hcr707305003/shiroiAdmin/commit/3ecde28ea8a20a3840dbfefd6d6863ee79a83e70",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/hcr707305003/shiroiAdmin/",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T11:55:01.885Z",
      "date_published": "2026-07-12T09:00:07.002Z",
      "date_updated": "2026-07-15T16:08:12.063Z",
      "publisher": "VulDB",
      "title": "RafyMrX TOKO-ONLINE-ROTI login.php sql injection",
      "affected": {
        "vendors": [
          "RafyMrX"
        ],
        "products": [
          {
            "vendor": "RafyMrX",
            "product": "TOKO-ONLINE-ROTI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19568
      },
      "nvd": {
        "published": "2026-07-12T09:16:39.913",
        "lastModified": "2026-07-15T17:16:45.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15489",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Username argument reaches a SQL statement without parameter separation, allowing its value to change the query grammar.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377796",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377796/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15489",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844101",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T11:58:39.924Z",
      "date_published": "2026-07-12T09:30:07.534Z",
      "date_updated": "2026-07-13T16:27:09.290Z",
      "publisher": "VulDB",
      "title": "RafyMrX TOKO-ONLINE-ROTI add.php sql injection",
      "affected": {
        "vendors": [
          "RafyMrX"
        ],
        "products": [
          {
            "vendor": "RafyMrX",
            "product": "TOKO-ONLINE-ROTI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18823
      },
      "nvd": {
        "published": "2026-07-12T10:16:16.577",
        "lastModified": "2026-07-13T17:17:08.660",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15490",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The add.php kode_produk and kd_cs parameters reach an SQL query without SQL grammar separation.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377797",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377797/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15490",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844136",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 609,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15491",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T11:58:42.133Z",
      "date_published": "2026-07-12T09:45:06.760Z",
      "date_updated": "2026-07-14T14:41:07.744Z",
      "publisher": "VulDB",
      "title": "RafyMrX TOKO-ONLINE-ROTI missing authentication",
      "affected": {
        "vendors": [
          "RafyMrX"
        ],
        "products": [
          {
            "vendor": "RafyMrX",
            "product": "TOKO-ONLINE-ROTI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00383,
        "percentile": 0.31072
      },
      "nvd": {
        "published": "2026-07-12T10:16:18.257",
        "lastModified": "2026-07-14T15:16:58.467",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15491",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377798",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377798/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15491",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844137",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 482,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T12:01:28.373Z",
      "date_published": "2026-07-12T10:00:08.854Z",
      "date_updated": "2026-07-13T18:12:32.364Z",
      "publisher": "VulDB",
      "title": "igweze wizgrade studentConductManager.php cross site scripting",
      "affected": {
        "vendors": [
          "igweze"
        ],
        "products": [
          {
            "vendor": "igweze",
            "product": "wizgrade"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18057
      },
      "nvd": {
        "published": "2026-07-12T11:16:45.117",
        "lastModified": "2026-07-13T19:16:54.803",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15492",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377799",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377799/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15492",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844165",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844300",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15493",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T12:12:17.476Z",
      "date_published": "2026-07-12T10:15:06.512Z",
      "date_updated": "2026-07-13T15:18:11.248Z",
      "publisher": "VulDB",
      "title": "Akpali9 Attendance-Management-System absent.php cross site scripting",
      "affected": {
        "vendors": [
          "Akpali9"
        ],
        "products": [
          {
            "vendor": "Akpali9",
            "product": "Attendance-Management-System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00191,
        "percentile": 0.08992
      },
      "nvd": {
        "published": "2026-07-12T11:16:46.133",
        "lastModified": "2026-07-13T16:59:13.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15493",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377800",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377800/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15493",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844298",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 554,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15494",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T12:16:37.358Z",
      "date_published": "2026-07-12T10:30:07.667Z",
      "date_updated": "2026-07-13T15:42:11.439Z",
      "publisher": "VulDB",
      "title": "AMTT Hotel Broadband Operation System switch_status.php sql injection",
      "affected": {
        "vendors": [
          "AMTT"
        ],
        "products": [
          {
            "vendor": "AMTT",
            "product": "Hotel Broadband Operation System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10276
      },
      "nvd": {
        "published": "2026-07-12T11:16:46.380",
        "lastModified": "2026-07-13T17:17:09.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15494",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a Hotel Broadband Operation System database query without safe parameter binding, allowing SQL syntax injection.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377801",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377801/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15494",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844454",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/MichaelZhuang521/cve/issues/4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15495",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T12:23:54.881Z",
      "date_published": "2026-07-12T10:45:07.442Z",
      "date_updated": "2026-07-15T16:13:17.023Z",
      "publisher": "VulDB",
      "title": "SonicCloudOrg sonic-agent Android WebSocket Server AndroidWSServer.java os command injection",
      "affected": {
        "vendors": [
          "SonicCloudOrg"
        ],
        "products": [
          {
            "vendor": "SonicCloudOrg",
            "product": "sonic-agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.01543,
        "percentile": 0.72492
      },
      "nvd": {
        "published": "2026-07-12T11:16:46.537",
        "lastModified": "2026-07-15T17:16:46.100",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15495",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AndroidWSServer uses the remote path argument in an operating-system command without neutralizing command syntax.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377802",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377802/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15495",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844484",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/xpp3901/CVE_APPLY/tree/main/V-S003_SonicAgent_pullFile_CmdInjection_RCE",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related"
          ]
        },
        {
          "url": "https://github.com/xpp3901/CVE_APPLY/blob/main/V-S003_SonicAgent_pullFile_CmdInjection_RCE/poc_pullfile_rce.py",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T12:23:57.456Z",
      "date_published": "2026-07-12T11:00:07.400Z",
      "date_updated": "2026-07-13T16:25:13.265Z",
      "publisher": "VulDB",
      "title": "SonicCloudOrg sonic-agent Groovy Script GroovyScriptImpl.java evalIsFailed os command injection",
      "affected": {
        "vendors": [
          "SonicCloudOrg"
        ],
        "products": [
          {
            "vendor": "SonicCloudOrg",
            "product": "sonic-agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.01158,
        "percentile": 0.6397
      },
      "nvd": {
        "published": "2026-07-12T11:16:46.713",
        "lastModified": "2026-07-13T17:17:10.070",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15496",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Groovy script handler evaluates attacker-controlled content in a path that permits operating-system command execution.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377803",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377803/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15496",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844485",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/xpp3901/CVE_APPLY/tree/main/V-S002_SonicCloudPlatform_Groovy_Unsandboxed_RCE",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15497",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T12:24:01.571Z",
      "date_published": "2026-07-12T11:15:07.681Z",
      "date_updated": "2026-07-14T14:42:14.757Z",
      "publisher": "VulDB",
      "title": "SonicCloudOrg sonic-agent JWT Authentication Filter ExchangeController.java code injection",
      "affected": {
        "vendors": [
          "SonicCloudOrg"
        ],
        "products": [
          {
            "vendor": "SonicCloudOrg",
            "product": "sonic-agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00394,
        "percentile": 0.32116
      },
      "nvd": {
        "published": "2026-07-12T12:16:42.897",
        "lastModified": "2026-07-14T15:16:58.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15497",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Remote input reaching ExchangeController is treated as executable code without a public account of the exact input field or evaluation sink.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377804",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377804/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15497",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844486",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/xpp3901/CVE_APPLY/blob/main/V-S001_SonicCloudPlatform_Unauth_ExchangeSend",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 575,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15498",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T12:36:09.558Z",
      "date_published": "2026-07-12T11:30:07.445Z",
      "date_updated": "2026-07-13T18:12:23.382Z",
      "publisher": "VulDB",
      "title": "sergomanov SmartHomeAdatum Login users.php sql injection",
      "affected": {
        "vendors": [
          "sergomanov"
        ],
        "products": [
          {
            "vendor": "sergomanov",
            "product": "SmartHomeAdatum"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16898
      },
      "nvd": {
        "published": "2026-07-12T12:16:44.053",
        "lastModified": "2026-07-13T19:16:55.480",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15498",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SmartHomeAdatum query path incorporates attacker-controlled input into SQL without parameter separation.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377805",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377805/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15498",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844491",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T12:41:55.318Z",
      "date_published": "2026-07-12T11:45:08.034Z",
      "date_updated": "2026-07-13T15:18:55.453Z",
      "publisher": "VulDB",
      "title": "AstrBotDevs AstrBot Scheduled Task cron_tools.py FutureTaskTool.call improper authorization",
      "affected": {
        "vendors": [
          "AstrBotDevs"
        ],
        "products": [
          {
            "vendor": "AstrBotDevs",
            "product": "AstrBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10227
      },
      "nvd": {
        "published": "2026-07-12T12:16:44.257",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15499",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The scheduled-task handler accepts an unauthorized note payload, but the public record does not identify the missing subject or action check.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377806",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377806/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15499",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844656",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/2bab96d5bedef784f90c97009fff8a19",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15500",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T12:41:58.125Z",
      "date_published": "2026-07-12T12:00:07.716Z",
      "date_updated": "2026-07-13T15:41:38.976Z",
      "publisher": "VulDB",
      "title": "AstrBotDevs AstrBot market_list Endpoint plugin.py get_online_plugins server-side request forgery",
      "affected": {
        "vendors": [
          "AstrBotDevs"
        ],
        "products": [
          {
            "vendor": "AstrBotDevs",
            "product": "AstrBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11244
      },
      "nvd": {
        "published": "2026-07-12T12:16:44.413",
        "lastModified": "2026-07-13T17:17:10.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15500",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The URL validation in AstrBot permits an attacker-selected destination to reach private, loopback, metadata, or otherwise restricted services.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377807",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377807/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15500",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844659",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847481",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/cd162554554c273a3a7c0330aa02f3f0",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 520,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T12:42:07.168Z",
      "date_published": "2026-07-12T12:30:07.184Z",
      "date_updated": "2026-07-15T16:05:35.347Z",
      "publisher": "VulDB",
      "title": "AstrBotDevs AstrBot MCP Test Endpoint tools.py ToolsRoute.test_mcp_connection server-side request forgery",
      "affected": {
        "vendors": [
          "AstrBotDevs"
        ],
        "products": [
          {
            "vendor": "AstrBotDevs",
            "product": "AstrBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10746
      },
      "nvd": {
        "published": "2026-07-12T13:16:36.633",
        "lastModified": "2026-07-15T17:16:46.233",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15501",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AstrBot accepts an attacker-controlled destination without reapplying the network allowlist after URL parsing, redirects, or address resolution, allowing server-side requests to a prohibited target.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377808",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377808/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15501",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844665",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/b68732c140fb11d844b214cf2db50a5a",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 517,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15502",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-11T12:49:06.454Z",
      "date_published": "2026-07-12T12:45:07.222Z",
      "date_updated": "2026-07-13T15:59:38.587Z",
      "publisher": "VulDB",
      "title": "AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection",
      "affected": {
        "vendors": [
          "AojiaoZero"
        ],
        "products": [
          {
            "vendor": "AojiaoZero",
            "product": "Antaris"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09592
      },
      "nvd": {
        "published": "2026-07-12T13:16:37.643",
        "lastModified": "2026-07-13T17:17:11.520",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15502",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PayPal IPN handler incorporates item_number into an SQL statement without preserving the SQL data boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377809",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377809/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15502",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844725",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15505",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T05:36:17.390Z",
      "date_published": "2026-07-12T19:15:07.533Z",
      "date_updated": "2026-07-14T14:47:12.550Z",
      "publisher": "VulDB",
      "title": "vnotex vnote YAML Frontmatter markdownit.js cross site scripting",
      "affected": {
        "vendors": [
          "vnotex"
        ],
        "products": [
          {
            "vendor": "vnotex",
            "product": "vnote"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09428
      },
      "nvd": {
        "published": "2026-07-12T20:16:17.450",
        "lastModified": "2026-07-14T15:16:58.730",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15505",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "vnote renders attacker-controlled content without the required HTML sanitization or output escaping, allowing cross-site scripting.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377834",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377834/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15505",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844847",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 373,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15506",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T05:44:41.811Z",
      "date_published": "2026-07-12T21:30:12.054Z",
      "date_updated": "2026-07-14T16:35:28.887Z",
      "publisher": "VulDB",
      "title": "SecureAge CatchPulse Driver saappctl.sys heap-based overflow",
      "affected": {
        "vendors": [
          "SecureAge"
        ],
        "products": [
          {
            "vendor": "SecureAge",
            "product": "CatchPulse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.8,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.8,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 1.7000000000000002,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03905
      },
      "nvd": {
        "published": "2026-07-12T22:16:34.873",
        "lastModified": "2026-07-14T17:16:45.030",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15506",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A local request to saappctl.sys can copy data beyond a heap allocation because the driver does not enforce the destination bound.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377835",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377835/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15506",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845584",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://jordanhiggins.blog/catchpulse-antivirus-exploits/",
          "host": "jordanhiggins.blog",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/Kalagious/SecureAgeExploit",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://youtu.be/xZqRVWlrah8",
          "host": "youtu.be",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "media-coverage"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-15507",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T05:49:07.720Z",
      "date_published": "2026-07-12T22:00:11.042Z",
      "date_updated": "2026-07-13T15:20:01.822Z",
      "publisher": "VulDB",
      "title": "coollabsio Coolify Policy Policies authorization",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "Coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10748
      },
      "nvd": {
        "published": "2026-07-12T22:16:35.917",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15507",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Coolify policy handlers allow a remote operation without its required authorization, but the exact policy and resource binding are not public.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377836",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377836/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15507",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845670",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lakshayyverma/CVE-Discovery/blob/main/coolify-resource-policy-stubs.zip",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15508",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T05:52:24.844Z",
      "date_published": "2026-07-12T22:15:11.407Z",
      "date_updated": "2026-07-13T15:38:59.130Z",
      "publisher": "VulDB",
      "title": "Helicone ai-gateway AWS Metadata Service service.rs build_target_url server-side request forgery",
      "affected": {
        "vendors": [
          "Helicone"
        ],
        "products": [
          {
            "vendor": "Helicone",
            "product": "ai-gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 31,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00206,
        "percentile": 0.1075
      },
      "nvd": {
        "published": "2026-07-12T23:16:36.780",
        "lastModified": "2026-07-13T17:17:12.197",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15508",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Helicone ai-gateway permits an attacker-controlled target URL to reach the AWS metadata service.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377837",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377837/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15508",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/845671",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/oscar2744/CVE-Submit/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 473,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 31
      }
    },
    {
      "cve_id": "CVE-2026-15509",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T05:58:31.153Z",
      "date_published": "2026-07-12T22:30:09.041Z",
      "date_updated": "2026-07-15T15:36:02.287Z",
      "publisher": "VulDB",
      "title": "Leantime JSON-RPC Endpoint addUser improper authorization",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "Leantime"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10746
      },
      "nvd": {
        "published": "2026-07-12T23:16:37.817",
        "lastModified": "2026-07-15T16:16:43.350",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15509",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The manipulation of the argument role leads to improper authorization.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377838",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377838/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15509",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846167",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://bytium.com/insights/leantime-priv-escalation-vulnerability-low-priv-to-owner",
          "host": "bytium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-15510",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T05:58:33.430Z",
      "date_published": "2026-07-12T22:45:10.120Z",
      "date_updated": "2026-07-13T15:56:43.276Z",
      "publisher": "VulDB",
      "title": "Leantime API saveSetting improper authorization",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "Leantime"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10749
      },
      "nvd": {
        "published": "2026-07-12T23:16:37.977",
        "lastModified": "2026-07-13T17:17:12.920",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15510",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The manipulation results in improper authorization.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377839",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377839/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15510",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846171",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://bytium.com/insights/leantime-3-8-0-broken-access-control",
          "host": "bytium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 348,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-15511",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T06:00:12.846Z",
      "date_published": "2026-07-12T23:00:09.820Z",
      "date_updated": "2026-07-14T14:48:19.645Z",
      "publisher": "VulDB",
      "title": "Comfast CF-WR631AX V3 FastCGI Backend webmgnt system_wl_upload_pic_file os command injection",
      "affected": {
        "vendors": [
          "Comfast"
        ],
        "products": [
          {
            "vendor": "Comfast",
            "product": "CF-WR631AX V3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 10,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 10,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.02624,
        "percentile": 0.83969
      },
      "nvd": {
        "published": "2026-07-12T23:16:38.137",
        "lastModified": "2026-07-14T15:16:58.863",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15511",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler places caller-controlled data in an operating-system command without safe argument separation.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377840",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377840/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15511",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/846719",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/luminarydawn/cve/tree/main/Command%20Injection%20in%20Comfast%20CF-WR631AX%20V3%20%E2%80%94%20WiFi%20Portal%20Image%20Upload%20(CWE-78)",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-15512",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T06:22:45.472Z",
      "date_published": "2026-07-12T23:15:08.066Z",
      "date_updated": "2026-07-13T18:12:15.612Z",
      "publisher": "VulDB",
      "title": "pig-mesh Pig pig-codegen GeneratorServiceImpl.java code injection",
      "affected": {
        "vendors": [
          "pig-mesh"
        ],
        "products": [
          {
            "vendor": "pig-mesh",
            "product": "Pig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13608
      },
      "nvd": {
        "published": "2026-07-13T00:16:47.077",
        "lastModified": "2026-07-13T19:16:57.023",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15512",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches a dynamic code-generation or evaluation path without an effective allowlist, allowing it to run as code.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377841",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377841/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15512",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847500",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sombra0316/CVE-2026/blob/main/pig-mesh/SSIT.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 495,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15513",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T06:26:27.054Z",
      "date_published": "2026-07-12T23:30:15.048Z",
      "date_updated": "2026-07-13T15:24:17.623Z",
      "publisher": "VulDB",
      "title": "Wavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injection",
      "affected": {
        "vendors": [
          "Wavlink"
        ],
        "products": [
          {
            "vendor": "Wavlink",
            "product": "WL-NU516U1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.01067,
        "percentile": 0.6148
      },
      "nvd": {
        "published": "2026-07-13T00:16:47.233",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15513",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application places attacker-controlled data into a shell command without separating the data from command syntax.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377842",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377842/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15513",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/847517",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/0xcc12138/wavlink-nu516u1-csrf-command-injection-",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-06-22-5ccde97-mt7628-squashfs-sysupgrade.bin",
          "host": "dl.wavlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 511,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15514",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T06:33:05.734Z",
      "date_published": "2026-07-12T23:45:35.426Z",
      "date_updated": "2026-07-13T15:54:58.755Z",
      "publisher": "VulDB",
      "title": "Metasoft 美特软件 MetaCRM PHPRPC Remote Call rpc.jsp RPCService.query sql injection",
      "affected": {
        "vendors": [
          "Metasoft 美特软件"
        ],
        "products": [
          {
            "vendor": "Metasoft 美特软件",
            "product": "MetaCRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16884
      },
      "nvd": {
        "published": "2026-07-13T00:16:47.390",
        "lastModified": "2026-07-13T17:17:13.613",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15514",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a MetaCRM database query without safe parameter binding, allowing query syntax injection.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377843",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377843/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15514",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/848598",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/docx/SX91dyomSoAeHJxnfygckPQNnLL?from=from_copylink",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 499,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15515",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T11:02:05.805Z",
      "date_published": "2026-07-13T00:00:10.627Z",
      "date_updated": "2026-07-15T15:34:37.479Z",
      "publisher": "VulDB",
      "title": "Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path",
      "affected": {
        "vendors": [
          "Tencent"
        ],
        "products": [
          {
            "vendor": "Tencent",
            "product": "PC Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-426",
          "name": "Untrusted Search Path",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6,
          "severity": "",
          "vector": "AV:L/AC:H/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6,
          "severity": "",
          "vector": "AV:L/AC:H/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01901
      },
      "nvd": {
        "published": "2026-07-13T01:17:04.580",
        "lastModified": "2026-07-15T16:16:43.497",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15515",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The privileged QMUDisk driver resolves a dependency through an attacker-influenceable search path.",
        "basis": [
          "CNA",
          "CWE-426",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377844",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377844/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15515",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/848643",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/subsubsub1231/qmukiller",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 514,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T11:05:41.518Z",
      "date_published": "2026-07-13T00:15:08.047Z",
      "date_updated": "2026-07-13T15:22:08.631Z",
      "publisher": "VulDB",
      "title": "MacCMS Pro Installation Index.php step5 authorization",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "MacCMS Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19595
      },
      "nvd": {
        "published": "2026-07-13T01:17:04.753",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15516",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The installer step-five path permits an authentication bypass, but the public record does not reveal the accepted key or failed check.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377845",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377845/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15516",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/848741",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/trustbigcat/CVE/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/magicblack/maccms10/releases?page=3#release-v2022.1000.3025",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15517",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T11:08:34.732Z",
      "date_published": "2026-07-13T00:30:08.923Z",
      "date_updated": "2026-07-14T14:50:27.124Z",
      "publisher": "VulDB",
      "title": "Jinher OA PlanGiveOut.aspx sql injection",
      "affected": {
        "vendors": [
          "Jinher"
        ],
        "products": [
          {
            "vendor": "Jinher",
            "product": "OA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16899
      },
      "nvd": {
        "published": "2026-07-13T01:17:04.917",
        "lastModified": "2026-07-14T15:16:59.000",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15517",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The httpOID parameter is incorporated into an SQL command without separating data from SQL syntax.",
        "basis": [
          "CNA record",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377846",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377846/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15517",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849470",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/weini587/CVE/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 386,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15518",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T11:11:09.587Z",
      "date_published": "2026-07-13T00:45:08.507Z",
      "date_updated": "2026-07-13T18:12:11.633Z",
      "publisher": "VulDB",
      "title": "AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile unrestricted upload",
      "affected": {
        "vendors": [
          "AREA 17"
        ],
        "products": [
          {
            "vendor": "AREA 17",
            "product": "Twill CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16179
      },
      "nvd": {
        "published": "2026-07-13T01:17:05.073",
        "lastModified": "2026-07-13T19:16:57.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15518",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Twill CMS stores an uploaded dangerous file without restricting its type and executable destination.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377847",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377847/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15518",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/849572",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://bytium.com/insights/authenticated-arbitrary-file-upload-to-rce-in-twill-cms",
          "host": "bytium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 502,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-15519",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T11:16:58.125Z",
      "date_published": "2026-07-13T01:00:09.661Z",
      "date_updated": "2026-07-13T15:25:15.599Z",
      "publisher": "VulDB",
      "title": "usestrix PyPI system_prompt.jinja inclusion of functionality from untrusted control sphere",
      "affected": {
        "vendors": [
          "usestrix"
        ],
        "products": [
          {
            "vendor": "usestrix",
            "product": "strix"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14957
      },
      "nvd": {
        "published": "2026-07-13T02:16:09.513",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15519",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PyPI handler incorporates functionality from an untrusted system_prompt.jinja source into the package's trusted behavior.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377848",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377848/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15519",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/850802",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ez-lbz/strix-vul-report",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 524,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15520",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T11:27:17.703Z",
      "date_published": "2026-07-13T01:15:16.694Z",
      "date_updated": "2026-07-13T15:53:27.409Z",
      "publisher": "VulDB",
      "title": "GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "LibreDWG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03509
      },
      "nvd": {
        "published": "2026-07-13T02:16:10.543",
        "lastModified": "2026-07-13T17:17:14.273",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15520",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In LibreDWG, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377849",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377849/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15520",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/851190",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/LibreDWG/libredwg/issues/1251",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/advisories/GHSA-qg2f-8389-w95j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/HackC0der/CVE-Repos/blob/main/libredwg/libredwg_0b57303_heap_overflow_decompress_R2004_section.dwg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/LibreDWG/libredwg/commit/3d0f9fc2eddbd6579c99af3111c37c98f03475d0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/LibreDWG/libredwg/releases/tag/0.14.8396",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.gnu.org/",
          "host": "www.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 10,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15521",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T11:35:04.112Z",
      "date_published": "2026-07-13T01:30:09.205Z",
      "date_updated": "2026-07-15T15:37:34.957Z",
      "publisher": "VulDB",
      "title": "makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal",
      "affected": {
        "vendors": [
          "makafeli"
        ],
        "products": [
          {
            "vendor": "makafeli",
            "product": "n8n-workflow-builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 11,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03558
      },
      "nvd": {
        "published": "2026-07-13T02:16:10.717",
        "lastModified": "2026-07-15T16:16:43.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15521",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled path is used without confinement to the intended directory, allowing file access outside that namespace.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377850",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377850/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15521",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854522",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/makafeli/n8n-workflow-builder/issues/28",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/makafeli/n8n-workflow-builder/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 435,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-15522",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T11:36:50.421Z",
      "date_published": "2026-07-13T01:45:11.320Z",
      "date_updated": "2026-07-13T15:19:28.662Z",
      "publisher": "VulDB",
      "title": "tugcantopaloglu godot-mcp run_project index.js validatePath path traversal",
      "affected": {
        "vendors": [
          "tugcantopaloglu"
        ],
        "products": [
          {
            "vendor": "tugcantopaloglu",
            "product": "godot-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00137,
        "percentile": 0.0356
      },
      "nvd": {
        "published": "2026-07-13T03:16:16.197",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15522",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "validatePath accepts traversal segments in projectPath, allowing run_project to select a project outside its intended directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377851",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377851/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15522",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854523",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/tugcantopaloglu/godot-mcp/issues/9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/tugcantopaloglu/godot-mcp/commit/eb63add552aa4bd9205395cf91b40654654a3cf2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/tugcantopaloglu/godot-mcp/releases/tag/v3.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/tugcantopaloglu/godot-mcp/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15523",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T11:38:00.048Z",
      "date_published": "2026-07-13T02:00:07.786Z",
      "date_updated": "2026-07-14T14:51:19.345Z",
      "publisher": "VulDB",
      "title": "CodeAstro Simple Online Leave Management System dashboard.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Simple Online Leave Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10072
      },
      "nvd": {
        "published": "2026-07-13T03:16:16.360",
        "lastModified": "2026-07-14T15:16:59.137",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15523",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Simple Online Leave Management System data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377852",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377852/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15523",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854524",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/wsx138/cve/issues/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15524",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T12:04:44.931Z",
      "date_published": "2026-07-13T02:15:08.132Z",
      "date_updated": "2026-07-13T18:12:06.893Z",
      "publisher": "VulDB",
      "title": "alioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal",
      "affected": {
        "vendors": [
          "alioshr"
        ],
        "products": [
          {
            "vendor": "alioshr",
            "product": "memory-bank-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03559
      },
      "nvd": {
        "published": "2026-07-13T03:16:16.513",
        "lastModified": "2026-07-13T19:16:58.377",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15524",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A crafted projectName containing traversal segments resolves outside the intended project directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377853",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377853/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15524",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854526",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/alioshr/memory-bank-mcp/issues/36",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/alioshr/memory-bank-mcp/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 444,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-15525",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T12:06:16.224Z",
      "date_published": "2026-07-13T02:30:09.775Z",
      "date_updated": "2026-07-13T15:26:18.701Z",
      "publisher": "VulDB",
      "title": "kLOsk adloop write.py _validate_urls server-side request forgery",
      "affected": {
        "vendors": [
          "kLOsk"
        ],
        "products": [
          {
            "vendor": "kLOsk",
            "product": "adloop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11908
      },
      "nvd": {
        "published": "2026-07-13T03:16:16.670",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15525",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The adloop request path accepts an attacker-controlled destination or redirect without constraining the resolved server-side network target.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377854",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377854/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15525",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854528",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/kLOsk/adloop/issues/41",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/kLOsk/adloop/commit/217399723e3a2fb39389e5355d49ed80aaf9ea7c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/kLOsk/adloop/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/kLOsk/adloop/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-15526",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T12:07:55.086Z",
      "date_published": "2026-07-13T02:45:08.736Z",
      "date_updated": "2026-07-13T15:52:24.189Z",
      "publisher": "VulDB",
      "title": "augmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProjectDeps path traversal",
      "affected": {
        "vendors": [
          "augmnt"
        ],
        "products": [
          {
            "vendor": "augmnt",
            "product": "augments-mcp-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03559
      },
      "nvd": {
        "published": "2026-07-13T04:16:27.650",
        "lastModified": "2026-07-13T17:17:14.983",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15526",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "scanProjectDeps uses packageJsonPath without confining file selection to the intended project directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377855",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377855/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15526",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854529",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/augmnt/augments-mcp-server/issues/8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/augmnt/augments-mcp-server/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 459,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T12:51:37.994Z",
      "date_published": "2026-07-13T03:00:08.811Z",
      "date_updated": "2026-07-13T19:26:34.337Z",
      "publisher": "VulDB",
      "title": "better-auth better-icons scan_project_icons/sync_icon path traversal",
      "affected": {
        "vendors": [
          "better-auth"
        ],
        "products": [
          {
            "vendor": "better-auth",
            "product": "better-icons"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03806
      },
      "nvd": {
        "published": "2026-07-13T04:16:28.163",
        "lastModified": "2026-07-13T20:16:46.403",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15527",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The icons_file argument is accepted without confining traversal segments to the intended directory, allowing selection of a path outside that namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377865",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377865/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15527",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854530",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-icons/issues/18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-icons/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 427,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-15528",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T12:53:22.698Z",
      "date_published": "2026-07-13T03:15:09.151Z",
      "date_updated": "2026-07-13T15:16:42.484Z",
      "publisher": "VulDB",
      "title": "lamaalrajih kicad-mcp path_validator.py protection mechanism",
      "affected": {
        "vendors": [
          "lamaalrajih"
        ],
        "products": [
          {
            "vendor": "lamaalrajih",
            "product": "kicad-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01649
      },
      "nvd": {
        "published": "2026-07-13T04:16:28.360",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15528",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says project_path and schematic_path defeat path_validator.py but does not disclose the containment rule that fails.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377866",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377866/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15528",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854531",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/lamaalrajih/kicad-mcp/issues/57",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/lamaalrajih/kicad-mcp/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15529",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T15:47:24.318Z",
      "date_published": "2026-07-13T03:45:08.697Z",
      "date_updated": "2026-07-20T06:19:33.417Z",
      "publisher": "VulDB",
      "title": "yzhao062 pyod persistence.py pyod.utils.persistence.load deserialization",
      "affected": {
        "vendors": [
          "yzhao062"
        ],
        "products": [
          {
            "vendor": "yzhao062",
            "product": "pyod"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17367
      },
      "nvd": {
        "published": "2026-07-13T04:16:28.577",
        "lastModified": "2026-07-20T07:16:35.887",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15529",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component deserializes attacker-controlled object data without restricting executable types or behavior.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377872",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377872/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15529",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854559",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/yzhao062/pyod/issues/697",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/yzhao062/pyod/pull/698",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://pypi.org/project/pyod/3.6.2/",
          "host": "pypi.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/yzhao062/pyod/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 439,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-15530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T15:50:34.631Z",
      "date_published": "2026-07-13T04:00:08.752Z",
      "date_updated": "2026-07-13T18:11:59.931Z",
      "publisher": "VulDB",
      "title": "WuzhiCMS Attachment API index.php listimage information disclosure",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "WuzhiCMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23522
      },
      "nvd": {
        "published": "2026-07-13T06:16:26.810",
        "lastModified": "2026-07-13T19:16:59.043",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15530",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WuzhiCMS returns attachment metadata or content to a caller without publishing the exact authorization check or object scope that should restrict it.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377873",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377873/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15530",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854588",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/wuzhicms/wuzhicms/issues/217",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/wuzhicms/wuzhicms/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 439,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15531",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T15:56:12.103Z",
      "date_published": "2026-07-13T04:15:09.036Z",
      "date_updated": "2026-07-13T15:27:17.248Z",
      "publisher": "VulDB",
      "title": "yashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deserialization",
      "affected": {
        "vendors": [
          "yashbhalgat"
        ],
        "products": [
          {
            "vendor": "yashbhalgat",
            "product": "HashNeRF-pytorch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02243
      },
      "nvd": {
        "published": "2026-07-13T06:16:27.217",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15531",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application deserializes attacker-controlled bytes with object semantics that can invoke executable behavior.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377874",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377874/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15531",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854906",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/yashbhalgat/HashNeRF-pytorch/issues/49",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/yashbhalgat/HashNeRF-pytorch/pull/50",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/yashbhalgat/HashNeRF-pytorch/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 617,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15532",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T16:00:14.084Z",
      "date_published": "2026-07-13T04:30:08.174Z",
      "date_updated": "2026-07-13T15:51:56.052Z",
      "publisher": "VulDB",
      "title": "SourceCodester Online Book Store System User Management cross site scripting",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Online Book Store System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 3.3,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 3.3,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 2.9,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11324
      },
      "nvd": {
        "published": "2026-07-13T06:16:27.413",
        "lastModified": "2026-07-13T17:17:15.660",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15532",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Online Book Store System page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377877",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377877/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15532",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854983",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://medium.com/@gauravkumar67482/authenticated-stored-cross-site-scripting-xss-in-user-management-module-2c2ba72b2cdf",
          "host": "medium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "exploit"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15533",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T16:07:42.717Z",
      "date_published": "2026-07-13T04:45:06.261Z",
      "date_updated": "2026-07-13T19:22:17.467Z",
      "publisher": "VulDB",
      "title": "DedeCMS Column Management search.php code injection",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "DedeCMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16191
      },
      "nvd": {
        "published": "2026-07-13T06:16:27.603",
        "lastModified": "2026-07-13T20:16:47.070",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15533",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The column-name input reaches generated code in search.php without the separation required to keep input as data.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377878",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377878/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15533",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854988",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854989",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/DunkBoyZz/cve/blob/cb7d6aa088d5ae4b603399af0a3279c18b084f11/DedeCMS%20V5.7.118%20Column%20Name%20Cache%20File%20Writing%20RCE%20Vulnerability.docx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T17:56:16.350Z",
      "date_published": "2026-07-13T05:00:09.553Z",
      "date_updated": "2026-07-13T14:59:55.663Z",
      "publisher": "VulDB",
      "title": "AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserialization",
      "affected": {
        "vendors": [
          "AkariAsai"
        ],
        "products": [
          {
            "vendor": "AkariAsai",
            "product": "self-rag"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16001
      },
      "nvd": {
        "published": "2026-07-13T06:16:27.780",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15535",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The index deserializer accepts an attacker-controlled FAISS metadata object as trusted serialized data.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377885",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377885/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15535",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/854999",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/AkariAsai/self-rag/issues/105",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/AkariAsai/self-rag/pull/106",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/AkariAsai/self-rag/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 679,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T17:59:23.159Z",
      "date_published": "2026-07-13T05:30:09.461Z",
      "date_updated": "2026-07-15T13:49:32.177Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System patviewprescription.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10065
      },
      "nvd": {
        "published": "2026-07-13T07:16:28.463",
        "lastModified": "2026-07-15T14:17:18.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15536",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The delid parameter is incorporated into a patviewprescription.php database query without safe parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377886",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377886/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15536",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855008",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/submit_vuln/issues/7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T18:00:30.574Z",
      "date_published": "2026-07-13T05:45:09.011Z",
      "date_updated": "2026-07-13T18:11:53.767Z",
      "publisher": "VulDB",
      "title": "SourceCodester Online Book Store System login.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Online Book Store System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18012
      },
      "nvd": {
        "published": "2026-07-13T07:16:28.647",
        "lastModified": "2026-07-13T19:16:59.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15537",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Online Book Store System query path incorporates attacker-controlled input into SQL without parameter separation.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377887",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377887/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15537",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855010",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://medium.com/@gauravkumar67482/sql-injection-leading-to-authentication-bypass-43b773da1967",
          "host": "medium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "exploit"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T18:03:07.553Z",
      "date_published": "2026-07-13T06:00:11.115Z",
      "date_updated": "2026-07-13T15:22:07.104Z",
      "publisher": "VulDB",
      "title": "primefaces primereact API ObjectUtils.mutateFieldData prototype pollution",
      "affected": {
        "vendors": [
          "primefaces"
        ],
        "products": [
          {
            "vendor": "primefaces",
            "product": "primereact"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17123
      },
      "nvd": {
        "published": "2026-07-13T07:16:28.813",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15538",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mutateFieldData follows an attacker-controlled field path into prototype properties and changes shared object behavior.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377888",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377888/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15538",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855024",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/primefaces/primereact/issues/8553",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/Mantle-UI/mantle-ui/issues/50",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/primefaces/primereact/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 502,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-15539",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T18:04:47.797Z",
      "date_published": "2026-07-13T06:15:07.726Z",
      "date_updated": "2026-07-13T14:48:07.777Z",
      "publisher": "VulDB",
      "title": "SourceCodester Online Book Store System Book Image Upload Feature index.php books unrestricted upload",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Online Book Store System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13499
      },
      "nvd": {
        "published": "2026-07-13T07:16:29.020",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15539",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path in Online Book Store System accepts an attacker-selected file type or destination outside the intended executable-file policy.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377889",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377889/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15539",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855046",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://medium.com/@hemantrajbhati5555/critical-authenticated-remote-code-execution-rce-via-unrestricted-file-upload-5a4a313ea1f1",
          "host": "medium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "exploit"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 352,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15540",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T18:07:43.505Z",
      "date_published": "2026-07-13T06:30:08.672Z",
      "date_updated": "2026-07-13T18:39:28.827Z",
      "publisher": "VulDB",
      "title": "SourceCodester Online Book Store System Administrative index.php php file inclusion",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Online Book Store System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15425
      },
      "nvd": {
        "published": "2026-07-13T08:16:20.403",
        "lastModified": "2026-07-13T19:17:00.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15540",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Online Book Store System allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-73",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377890",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377890/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15540",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855048",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://medium.com/@hemantrajbhati5555/local-file-inclusion-lfi-via-page-parameter-leading-to-source-code-disclosure-ce722de0c407",
          "host": "medium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "broken-link",
            "exploit"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15541",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T18:12:28.084Z",
      "date_published": "2026-07-13T06:45:10.052Z",
      "date_updated": "2026-07-13T14:28:26.935Z",
      "publisher": "VulDB",
      "title": "will-moss Isaiah Master Websocket server.go Server.Handle authorization",
      "affected": {
        "vendors": [
          "will-moss"
        ],
        "products": [
          {
            "vendor": "will-moss",
            "product": "Isaiah"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24016
      },
      "nvd": {
        "published": "2026-07-13T08:16:20.600",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15541",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Master WebSocket handler accepts an Agent selection without verifying that the caller is authorized to control that agent.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377891",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377891/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15541",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855074",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/will-moss/isaiah/issues/34",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/will-moss/isaiah/pull/35",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/will-moss/isaiah/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-15542",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T18:13:53.748Z",
      "date_published": "2026-07-13T07:00:09.998Z",
      "date_updated": "2026-07-15T14:10:48.207Z",
      "publisher": "VulDB",
      "title": "will-moss Isaiah Websocket Connection Authentication main.go improper authentication",
      "affected": {
        "vendors": [
          "will-moss"
        ],
        "products": [
          {
            "vendor": "will-moss",
            "product": "Isaiah"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33097
      },
      "nvd": {
        "published": "2026-07-13T08:16:20.783",
        "lastModified": "2026-07-15T15:16:28.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15542",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in Isaiah, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377892",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377892/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15542",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855075",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/will-moss/isaiah/issues/33",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/will-moss/isaiah/pull/36",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/will-moss/isaiah/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 318,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-15543",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T18:14:49.133Z",
      "date_published": "2026-07-13T07:15:09.242Z",
      "date_updated": "2026-07-13T18:11:49.862Z",
      "publisher": "VulDB",
      "title": "Tenda CH22 CertListInfo formCertListInfo buffer overflow",
      "affected": {
        "vendors": [
          "Tenda"
        ],
        "products": [
          {
            "vendor": "Tenda",
            "product": "CH22"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00476,
        "percentile": 0.38657
      },
      "nvd": {
        "published": "2026-07-13T08:16:20.967",
        "lastModified": "2026-07-13T19:17:01.067",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15543",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "formCertListInfo copies the remote Name argument into a fixed buffer without an effective length check.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377893",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377893/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15543",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855077",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://candle-throne-f75.notion.site/Tenda-CH22-formCertListInfo-377df0aa11858088aabaeb0f5e1909c9",
          "host": "candle-throne-f75.notion.site",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.tenda.com.cn/",
          "host": "www.tenda.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 280,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15544",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T21:00:57.952Z",
      "date_published": "2026-07-13T07:30:14.239Z",
      "date_updated": "2026-07-13T15:23:20.254Z",
      "publisher": "VulDB",
      "title": "Shibby Tomato apcupsd tomatodata.cgi getupsvar stack-based overflow",
      "affected": {
        "vendors": [
          "Shibby"
        ],
        "products": [
          {
            "vendor": "Shibby",
            "product": "Tomato"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 29,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00438,
        "percentile": 0.36023
      },
      "nvd": {
        "published": "2026-07-13T08:16:21.150",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15544",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "getupsvar copies the remote Field value beyond a stack buffer in tomatodata.cgi.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377894",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377894/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15544",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855110",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gitee.com/Fengyi-Wang/CVE/issues/IJTQ5M",
          "host": "gitee.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 382,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 29
      }
    },
    {
      "cve_id": "CVE-2026-15545",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T21:01:00.552Z",
      "date_published": "2026-07-13T08:00:14.476Z",
      "date_updated": "2026-07-13T14:44:19.548Z",
      "publisher": "VulDB",
      "title": "Shibby Tomato apcupsd tomatodata.cgi main out-of-bounds write",
      "affected": {
        "vendors": [
          "Shibby"
        ],
        "products": [
          {
            "vendor": "Shibby",
            "product": "Tomato"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 29,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32422
      },
      "nvd": {
        "published": "2026-07-13T09:16:24.043",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15545",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Shibby Tomato's apcupsd CGI main function writes beyond a buffer while processing a crafted request.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377895",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377895/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15545",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855114",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gitee.com/Fengyi-Wang/CVE/issues/IJTQ5N",
          "host": "gitee.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 29
      }
    },
    {
      "cve_id": "CVE-2026-15546",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T21:01:03.730Z",
      "date_published": "2026-07-13T08:15:12.769Z",
      "date_updated": "2026-07-13T18:37:30.207Z",
      "publisher": "VulDB",
      "title": "Shibby Tomato start_jffs2 sub_2D568 os command injection",
      "affected": {
        "vendors": [
          "Shibby"
        ],
        "products": [
          {
            "vendor": "Shibby",
            "product": "Tomato"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 29,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.0105,
        "percentile": 0.60936
      },
      "nvd": {
        "published": "2026-07-13T09:16:24.213",
        "lastModified": "2026-07-13T19:17:01.950",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15546",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Performing a manipulation of the argument jffs2_exec results in os command injection.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377896",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377896/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15546",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855115",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gitee.com/Fengyi-Wang/CVE/issues/IJTQ5O",
          "host": "gitee.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 29
      }
    },
    {
      "cve_id": "CVE-2026-15547",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T21:01:06.356Z",
      "date_published": "2026-07-13T08:30:16.900Z",
      "date_updated": "2026-07-13T14:27:43.603Z",
      "publisher": "VulDB",
      "title": "Shibby Tomato CIFS Mount sub_2D048 os command injection",
      "affected": {
        "vendors": [
          "Shibby"
        ],
        "products": [
          {
            "vendor": "Shibby",
            "product": "Tomato"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 29,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.0105,
        "percentile": 0.60936
      },
      "nvd": {
        "published": "2026-07-13T09:16:24.387",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15547",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The cifs1 and cifs2 values reach the CIFS mount shell command without operating-system command separation.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377897",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377897/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15547",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855117",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gitee.com/Fengyi-Wang/CVE/issues/IJTQ5P",
          "host": "gitee.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 385,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 29
      }
    },
    {
      "cve_id": "CVE-2026-15548",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T21:01:09.003Z",
      "date_published": "2026-07-13T08:45:12.464Z",
      "date_updated": "2026-07-15T14:13:38.229Z",
      "publisher": "VulDB",
      "title": "Shibby Tomato DNS List Rendering httpd sub_407220 stack-based overflow",
      "affected": {
        "vendors": [
          "Shibby"
        ],
        "products": [
          {
            "vendor": "Shibby",
            "product": "Tomato"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 29,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00558,
        "percentile": 0.43315
      },
      "nvd": {
        "published": "2026-07-13T10:16:26.537",
        "lastModified": "2026-07-15T15:16:28.357",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15548",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler copies attacker-controlled data beyond a fixed-size stack buffer.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377898",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377898/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15548",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855121",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gitee.com/Fengyi-Wang/CVE/issues/IJTQ5R",
          "host": "gitee.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 341,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 29
      }
    },
    {
      "cve_id": "CVE-2026-15551",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T23:55:26.743Z",
      "date_published": "2026-07-13T00:11:59.190Z",
      "date_updated": "2026-07-13T15:46:29.647Z",
      "publisher": "samsung.tv_appliance",
      "title": "Samsung rlottie: Numeric truncation in gray_hline() leads to heap-based buffer overflow when rendering a crafted Lottie animation at native canvas size",
      "affected": {
        "vendors": [
          "Samsung Open Source"
        ],
        "products": [
          {
            "vendor": "Samsung Open Source",
            "product": "rlottie"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:PSIRT@samsung.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00081,
        "percentile": 0.00254
      },
      "nvd": {
        "published": "2026-07-13T01:17:05.233",
        "lastModified": "2026-07-13T19:28:17.967",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15551",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "rlottie performs security-relevant size arithmetic without rejecting an integer overflow or wraparound.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Samsung/rlottie/pull/595",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15552",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T01:32:19.856Z",
      "date_published": "2026-07-13T02:45:09.949Z",
      "date_updated": "2026-07-14T14:33:35.498Z",
      "publisher": "twcert",
      "title": "Ragic｜Enterprise Cloud Database - Stored Cross-Site Scripting",
      "affected": {
        "vendors": [
          "Ragic"
        ],
        "products": [
          {
            "vendor": "Ragic",
            "product": "Enterprise Cloud Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10649
      },
      "nvd": {
        "published": "2026-07-13T04:16:28.800",
        "lastModified": "2026-07-14T15:16:59.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15552",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.twcert.org.tw/tw/cp-132-11031-eccb2-1.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.twcert.org.tw/en/cp-139-11032-460c2-2.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15553",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T01:32:22.505Z",
      "date_published": "2026-07-13T03:10:37.912Z",
      "date_updated": "2026-07-14T14:33:25.148Z",
      "publisher": "twcert",
      "title": "Ragic｜Enterprise Cloud Database - Arbitrary File Upload",
      "affected": {
        "vendors": [
          "Ragic"
        ],
        "products": [
          {
            "vendor": "Ragic",
            "product": "Enterprise Cloud Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16488
      },
      "nvd": {
        "published": "2026-07-13T04:16:28.977",
        "lastModified": "2026-07-14T15:16:59.527",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15553",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Enterprise Cloud Database accepts an uploaded file without enforcing the file type and destination restrictions required for that content.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.twcert.org.tw/tw/cp-132-11031-eccb2-1.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.twcert.org.tw/en/cp-139-11032-460c2-2.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15557",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T05:03:01.385Z",
      "date_published": "2026-07-13T09:30:09.319Z",
      "date_updated": "2026-07-13T18:11:46.126Z",
      "publisher": "VulDB",
      "title": "waooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight improper authentication",
      "affected": {
        "vendors": [
          "waooAI"
        ],
        "products": [
          {
            "vendor": "waooAI",
            "product": "waoowaoo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00397,
        "percentile": 0.32485
      },
      "nvd": {
        "published": "2026-07-13T10:16:26.737",
        "lastModified": "2026-07-13T19:17:02.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15557",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Authentication helpers trust a caller-supplied x-internal-user-id header as an authenticated identity.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377906",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377906/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15557",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855187",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/waooAI/waoowaoo/issues/200",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/waooAI/waoowaoo/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 606,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15558",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T05:05:45.068Z",
      "date_published": "2026-07-13T11:30:08.876Z",
      "date_updated": "2026-07-13T13:44:38.097Z",
      "publisher": "VulDB",
      "title": "CodeAstro Simple Online Leave Management System deletemp.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Simple Online Leave Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10069
      },
      "nvd": {
        "published": "2026-07-13T12:16:30.590",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15558",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377907",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377907/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15558",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855188",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sl1der-fr0g/Findings/issues/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15559",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T05:05:47.193Z",
      "date_published": "2026-07-13T12:00:08.787Z",
      "date_updated": "2026-07-13T13:03:35.884Z",
      "publisher": "VulDB",
      "title": "CodeAstro Simple Online Leave Management System POST accept.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Simple Online Leave Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10067
      },
      "nvd": {
        "published": "2026-07-13T13:16:30.410",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15559",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The appid parameter is incorporated into an SQL command without separating data from SQL syntax.",
        "basis": [
          "CNA record",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/377908",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/377908/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15559",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855189",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sl1der-fr0g/Findings/issues/3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15574",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T07:52:38.428Z",
      "date_published": "2026-07-13T08:01:26.253Z",
      "date_updated": "2026-07-13T14:41:57.000Z",
      "publisher": "redhat",
      "title": "Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug default",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift AI (RHOAI)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-538",
          "name": "Insertion of Sensitive Information into Externally-Accessible File or Directory",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17489
      },
      "nvd": {
        "published": "2026-07-13T09:16:24.550",
        "lastModified": "2026-07-13T17:01:11.600",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15574",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Red Hat OpenShift AI (RHOAI) writes sensitive values to a file or log readable outside the request's confidentiality boundary.",
        "basis": [
          "CNA",
          "CWE-538"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15574",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499594",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15583",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T11:27:32.132Z",
      "date_published": "2026-07-15T07:29:48.038Z",
      "date_updated": "2026-07-29T14:00:19.522Z",
      "publisher": "GRAFANA",
      "title": "SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header",
      "affected": {
        "vendors": [
          "Grafana"
        ],
        "products": [
          {
            "vendor": "Grafana",
            "product": "Grafana MCP Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-610",
          "name": "Externally Controlled Reference to a Resource in Another Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@grafana.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00492,
        "percentile": 0.39576
      },
      "nvd": {
        "published": "2026-07-15T08:16:22.977",
        "lastModified": "2026-07-15T20:56:32.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15583",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Grafana MCP Server trusts the caller-supplied X-Grafana-URL as its upstream and sends the service-account token to that destination.",
        "basis": [
          "CNA",
          "CWE-610"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://grafana.com/security/security-advisories/cve-2026-15583",
          "host": "grafana.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15584",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T11:47:02.045Z",
      "date_published": "2026-07-13T12:01:06.562Z",
      "date_updated": "2026-07-14T14:32:25.141Z",
      "publisher": "redhat",
      "title": "Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot debug pods created in shared default namespace enable privilege escalation to node root",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Pen Drive Powered by Red Hat Lightspeed"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-250",
          "name": "Execution with Unnecessary Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15881
      },
      "nvd": {
        "published": "2026-07-13T13:16:30.560",
        "lastModified": "2026-07-14T15:16:59.637",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15584",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "incluster-checks creates privileged host-chroot debug pods in the shared default namespace, where ordinary edit-role users can enter them and reach node-root authority.",
        "basis": [
          "CNA",
          "CWE-250"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15584",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499647",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15588",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T13:21:08.322Z",
      "date_published": "2026-07-20T12:12:06.844Z",
      "date_updated": "2026-07-21T11:06:15.018Z",
      "publisher": "redhat",
      "title": "Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 12,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00192,
        "percentile": 0.09061
      },
      "nvd": {
        "published": "2026-07-20T12:17:55.220",
        "lastModified": "2026-07-21T18:31:51.680",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15588",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected protocol path allocates or retains attacker-driven state without an effective upper bound.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:39985",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40485",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42329",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15588",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499675",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3985",
          "host": "gitlab.gnome.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 475,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15594",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T14:01:13.127Z",
      "date_published": "2026-07-13T20:15:10.868Z",
      "date_updated": "2026-07-15T15:45:06.732Z",
      "publisher": "VulDB",
      "title": "waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authorization",
      "affected": {
        "vendors": [
          "waooAI"
        ],
        "products": [
          {
            "vendor": "waooAI",
            "product": "waoowaoo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 2.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 2.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 3.6999999999999997,
      "epss": {
        "score": 0.00298,
        "percentile": 0.2209
      },
      "nvd": {
        "published": "2026-07-13T21:16:39.103",
        "lastModified": "2026-07-15T16:16:43.750",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15594",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "stablePublicIdFromStorageKey derives or assigns media authority from an attacker-controlled storageKey without enforcing the required privilege boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378109",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378109/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15594",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855264",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/waooAI/waoowaoo/issues/201",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/waooAI/waoowaoo/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 541,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15595",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T14:02:36.735Z",
      "date_published": "2026-07-13T20:30:08.129Z",
      "date_updated": "2026-07-14T13:03:58.599Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System forsubject.php cross site scripting",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20072
      },
      "nvd": {
        "published": "2026-07-13T21:16:40.127",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15595",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Class and Exam Timetabling System rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378110",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378110/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15595",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855268",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/AlbaDove/cve/issues/6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 340,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15596",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T14:02:39.572Z",
      "date_published": "2026-07-13T21:30:08.683Z",
      "date_updated": "2026-07-15T14:23:52.386Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System subject.php cross site scripting",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27375
      },
      "nvd": {
        "published": "2026-07-13T22:16:44.907",
        "lastModified": "2026-07-15T15:16:28.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15596",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled subject value is rendered into HTML without contextual escaping.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378111",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378111/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15596",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855269",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/AlbaDove/cve/issues/5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15597",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T14:04:19.950Z",
      "date_published": "2026-07-13T21:45:09.410Z",
      "date_updated": "2026-07-14T14:30:40.312Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_exam2.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25352
      },
      "nvd": {
        "published": "2026-07-13T22:16:45.070",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15597",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Class and Exam Timetabling System data path incorporates attacker-controlled values into SQL grammar without parameterization or sufficient escaping.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378112",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378112/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15597",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855298",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/asdasddqwdq29-a11y/new-cve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15598",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T14:08:46.995Z",
      "date_published": "2026-07-13T22:00:11.338Z",
      "date_updated": "2026-07-14T13:01:23.090Z",
      "publisher": "VulDB",
      "title": "antv layout object.js setNestedValue prototype pollution",
      "affected": {
        "vendors": [
          "antv"
        ],
        "products": [
          {
            "vendor": "antv",
            "product": "layout"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23713
      },
      "nvd": {
        "published": "2026-07-13T22:16:45.227",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15598",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "setNestedValue accepts a crafted property path that modifies object prototype attributes.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378113",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378113/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15598",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855637",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/antvis/layout/issues/292",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15605",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T15:38:12.267Z",
      "date_published": "2026-07-13T22:45:09.813Z",
      "date_updated": "2026-07-14T12:42:47.147Z",
      "publisher": "VulDB",
      "title": "wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "wandb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-327",
          "name": "Use of a Broken or Risky Cryptographic Algorithm",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-328",
          "name": "Use of Weak Hash",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 2.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:N/A:N/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 2.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00151,
        "percentile": 0.0475
      },
      "nvd": {
        "published": "2026-07-13T23:16:45.383",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15605",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "wandb ArtifactManifestEntry.download relies on a weak digest in its artifact-integrity check, allowing a colliding artifact to satisfy the download validation boundary.",
        "basis": [
          "CNA",
          "CWE-327",
          "CWE-328"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378114",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378114/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15605",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855675",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/wandb/wandb/issues/12030",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/wandb/wandb/pull/12031",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/wandb/wandb/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15607",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T15:40:19.194Z",
      "date_published": "2026-07-13T23:00:15.192Z",
      "date_updated": "2026-07-15T15:49:45.254Z",
      "publisher": "VulDB",
      "title": "tanstack db Alias Path select.ts select prototype pollution",
      "affected": {
        "vendors": [
          "tanstack"
        ],
        "products": [
          {
            "vendor": "tanstack",
            "product": "db"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16861
      },
      "nvd": {
        "published": "2026-07-13T23:16:46.450",
        "lastModified": "2026-07-15T16:16:43.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15607",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The select alias-path handler assigns a __proto__-style key as an object property and mutates the returned object prototype.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378115",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378115/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15607",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855677",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/TanStack/db/issues/1584",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/TanStack/db/pull/1595",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/TanStack/db/commit/ac09b1177a100eafa85cba3cd09dd1f53f933ded",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/TanStack/db/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 483,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-15610",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:07:03.275Z",
      "date_published": "2026-07-16T07:51:05.820Z",
      "date_updated": "2026-07-16T12:36:49.218Z",
      "publisher": "Wordfence",
      "title": "WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function",
      "affected": {
        "vendors": [
          "quantumcloud"
        ],
        "products": [
          {
            "vendor": "quantumcloud",
            "product": "WPBot – AI ChatBot for Live Support, Lead Generation, AI Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14173
      },
      "nvd": {
        "published": "2026-07-16T09:16:18.280",
        "lastModified": "2026-07-16T13:38:53.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15610",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e905d146-66bf-4d6d-b2f5-fd3f862101af?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/includes/class-qcld-bot-rag.php#L791",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.5/includes/class-qcld-bot-rag.php#L791",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.5/includes/class-qcld-bot-rag.php#L27",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.5/qcld-wpwbot.php#L608",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/includes/class-qcld-bot-rag.php#L27",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/qcld-wpwbot.php#L608",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3608558%40chatbot&new=3608558%40chatbot",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15611",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:09:08.015Z",
      "date_published": "2026-07-23T15:45:48.250Z",
      "date_updated": "2026-07-27T16:32:47.244Z",
      "publisher": "certcc",
      "title": "Unverified email-based SSO account linking",
      "affected": {
        "vendors": [
          "Logto"
        ],
        "products": [
          {
            "vendor": "Logto",
            "product": "Logto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19607
      },
      "nvd": {
        "published": "2026-07-23T16:17:13.947",
        "lastModified": "2026-07-27T17:16:34.800",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15611",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Logto links an SSO identity to an existing account by matching an email address that the identity provider has not verified.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/packages/core/src/libraries/verification-helpers/single-sign-on.ts#L274",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/packages/core/src/routes/experience/classes/verifications/enterprise-sso-verification.ts#L284-L297",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15612",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:12:30.539Z",
      "date_published": "2026-07-23T15:45:27.100Z",
      "date_updated": "2026-07-27T16:37:08.498Z",
      "publisher": "certcc",
      "title": "LOIDC nonce validation bypass",
      "affected": {
        "vendors": [
          "Logto"
        ],
        "products": [
          {
            "vendor": "Logto",
            "product": "Logto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.08
      },
      "nvd": {
        "published": "2026-07-23T16:17:14.047",
        "lastModified": "2026-07-27T17:16:34.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15612",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OIDC validator accepts an ID token with no nonce claim instead of requiring the nonce that binds the token to the initiating browser session.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/packages/core/src/sso/OidcConnector/utils.ts#L175-L182",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 158,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15614",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:13:59.834Z",
      "date_published": "2026-07-23T15:44:11.159Z",
      "date_updated": "2026-07-27T15:35:54.176Z",
      "publisher": "certcc",
      "title": "IdP-initiated SAML sessions not reliably invalidated (replay)",
      "affected": {
        "vendors": [
          "Logto"
        ],
        "products": [
          {
            "vendor": "Logto",
            "product": "Logto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13856
      },
      "nvd": {
        "published": "2026-07-23T16:17:14.143",
        "lastModified": "2026-07-27T16:17:02.580",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15614",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Logto can silently leave an IdP-initiated SAML session valid after deletion is requested, allowing reuse during the original validity window.",
        "basis": [
          "CNA",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/packages/core/src/libraries/verification-helpers/single-sign-on.ts#L81-L99",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15615",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:14:15.128Z",
      "date_published": "2026-07-23T15:43:42.802Z",
      "date_updated": "2026-07-27T15:23:36.546Z",
      "publisher": "certcc",
      "title": "SAML <Conditions> element not validated",
      "affected": {
        "vendors": [
          "Logto"
        ],
        "products": [
          {
            "vendor": "Logto",
            "product": "Logto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.08049
      },
      "nvd": {
        "published": "2026-07-23T16:17:14.237",
        "lastModified": "2026-07-27T16:17:02.743",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15615",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Logto accepts a SAML assertion without enforcing its Conditions time and audience restrictions, so a stripped assertion can be replayed.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/packages/core/src/sso/SamlConnector/utils.ts#L175-L205",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/packages/connectors/connector-saml/src/utils.ts#L46-L110",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 151,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15616",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:14:31.396Z",
      "date_published": "2026-07-23T15:43:03.647Z",
      "date_updated": "2026-07-27T15:28:21.318Z",
      "publisher": "certcc",
      "title": "Local MFA not enforced during SSO sign-in",
      "affected": {
        "vendors": [
          "Logto"
        ],
        "products": [
          {
            "vendor": "Logto",
            "product": "Logto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-308",
          "name": "Use of Single-factor Authentication",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25363
      },
      "nvd": {
        "published": "2026-07-23T16:17:14.330",
        "lastModified": "2026-07-27T16:17:02.897",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15616",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Logto completes an SSO login without applying the locally required second factor to that authentication path.",
        "basis": [
          "CNA",
          "CWE-308"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/packages/core/src/routes/experience/classes/experience-interaction.ts#L538-L540",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 156,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15617",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:14:46.769Z",
      "date_published": "2026-07-23T15:41:29.123Z",
      "date_updated": "2026-07-27T15:33:20.686Z",
      "publisher": "certcc",
      "title": "Principal/domain lookup without case normalization",
      "affected": {
        "vendors": [
          "Logto"
        ],
        "products": [
          {
            "vendor": "Logto",
            "product": "Logto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-178",
          "name": "Improper Handling of Case Sensitivity",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20107
      },
      "nvd": {
        "published": "2026-07-23T16:17:14.423",
        "lastModified": "2026-07-27T16:17:03.047",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15617",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Principal lookup compares email or identifier strings without consistent case and Unicode normalization, allowing two textual identities to collide with one account.",
        "basis": [
          "CNA",
          "CWE-178"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/packages/core/src/libraries/verification-helpers/single-sign-on-guard.ts#L23-L33",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15618",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:57:32.960Z",
      "date_published": "2026-07-13T23:45:09.804Z",
      "date_updated": "2026-07-14T12:47:41.268Z",
      "publisher": "VulDB",
      "title": "mosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection mechanism",
      "affected": {
        "vendors": [
          "mosaxiv"
        ],
        "products": [
          {
            "vendor": "mosaxiv",
            "product": "clawlet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 11,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 5.4,
      "epss": {
        "score": 0.0024,
        "percentile": 0.1512
      },
      "nvd": {
        "published": "2026-07-14T00:16:18.647",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15618",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record names a command safety-guard failure but does not disclose the input form or guard condition that is bypassed.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378121",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378121/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15618",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855792",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mosaxiv/clawlet/issues/12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mosaxiv/clawlet/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 433,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-15619",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:57:35.760Z",
      "date_published": "2026-07-14T00:00:12.931Z",
      "date_updated": "2026-07-15T14:29:41.559Z",
      "publisher": "VulDB",
      "title": "mosaxiv clawlet IPv4 tool_web_fetch.go web_fetch server-side request forgery",
      "affected": {
        "vendors": [
          "mosaxiv"
        ],
        "products": [
          {
            "vendor": "mosaxiv",
            "product": "clawlet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 11,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 5.4,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16656
      },
      "nvd": {
        "published": "2026-07-14T00:16:18.823",
        "lastModified": "2026-07-15T15:16:28.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15619",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "web_fetch allows an attacker-controlled URL to make the server request a target outside the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378122",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378122/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15619",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855793",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mosaxiv/clawlet/issues/13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mosaxiv/clawlet/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-15620",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:57:38.543Z",
      "date_published": "2026-07-14T00:15:08.152Z",
      "date_updated": "2026-07-14T14:30:34.324Z",
      "publisher": "VulDB",
      "title": "mosaxiv clawlet tool_web_fetch.go tools.webFetch server-side request forgery",
      "affected": {
        "vendors": [
          "mosaxiv"
        ],
        "products": [
          {
            "vendor": "mosaxiv",
            "product": "clawlet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 11,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00228,
        "percentile": 0.1364
      },
      "nvd": {
        "published": "2026-07-14T01:16:16.867",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15620",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "clawlet accepts an attacker-controlled destination without reapplying the network allowlist after URL parsing, redirects, or address resolution, allowing server-side requests to a prohibited target.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378123",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378123/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15620",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855795",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mosaxiv/clawlet/issues/14",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mosaxiv/clawlet/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 370,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-15621",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:57:41.446Z",
      "date_published": "2026-07-14T00:45:11.699Z",
      "date_updated": "2026-07-14T12:41:02.564Z",
      "publisher": "VulDB",
      "title": "mosaxiv clawlet File Tools fs_ops.go edit_file link following",
      "affected": {
        "vendors": [
          "mosaxiv"
        ],
        "products": [
          {
            "vendor": "mosaxiv",
            "product": "clawlet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 11,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03806
      },
      "nvd": {
        "published": "2026-07-14T01:16:17.033",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15621",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file tools follow attacker-created links without constraining the resolved object to the intended workspace.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378124",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378124/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15621",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855796",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mosaxiv/clawlet/issues/15",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mosaxiv/clawlet/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-15622",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T17:01:54.313Z",
      "date_published": "2026-07-14T01:15:13.193Z",
      "date_updated": "2026-07-14T12:36:09.742Z",
      "publisher": "VulDB",
      "title": "poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization",
      "affected": {
        "vendors": [
          "poco-ai"
        ],
        "products": [
          {
            "vendor": "poco-ai",
            "product": "poco-claw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.00353,
        "percentile": 0.27957
      },
      "nvd": {
        "published": "2026-07-14T02:16:54.223",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15622",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "poco-claw accepts a caller-supplied object identifier without binding the selected object to the caller's ownership or authorized scope.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-285",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378125",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378125/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15622",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855797",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/poco-ai/poco-claw/issues/133",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/poco-ai/poco-claw/pull/135",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/poco-ai/poco-claw/commit/67fcc88505c57f77d3fcf04eb5b89425b10cbf48",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "patch"
          ]
        },
        {
          "url": "https://github.com/poco-ai/poco-claw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 464,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-15624",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T17:23:38.145Z",
      "date_published": "2026-07-14T01:30:09.483Z",
      "date_updated": "2026-07-15T14:53:36.990Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw invoke Endpoint create_video_byteplus.go bytePlusDownloadVideo server-side request forgery",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11245
      },
      "nvd": {
        "published": "2026-07-14T02:16:54.393",
        "lastModified": "2026-07-15T16:16:44.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15624",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "bytePlusDownloadVideo fetches the attacker-controlled output.video_url without restricting the destination to permitted network targets.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378126",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378126/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15624",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855798",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1199",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15625",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T17:23:41.371Z",
      "date_published": "2026-07-14T02:00:09.555Z",
      "date_updated": "2026-07-14T12:45:41.732Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete blacklist",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-183",
          "name": "Permissive List of Allowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20195
      },
      "nvd": {
        "published": "2026-07-14T02:16:54.550",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15625",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ExecApprovalManager authorizes commands with an incomplete denylist, so disallowed command forms can pass the approval check.",
        "basis": [
          "CNA",
          "CWE-183",
          "CWE-184"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378127",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378127/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15625",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855804",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855806",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855807",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855845",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855846",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855848",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1200",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1200#issuecomment-4760771866",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 12,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15626",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T17:23:45.857Z",
      "date_published": "2026-07-14T02:15:09.506Z",
      "date_updated": "2026-07-15T14:35:47.686Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw ACP ToolBridge Workspace tool_bridge.go writeFile path traversal",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21688
      },
      "nvd": {
        "published": "2026-07-14T04:17:04.430",
        "lastModified": "2026-07-15T15:16:28.897",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15626",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GoClaw ToolBridge writeFile accepts traversal segments and writes outside the provider's intended file namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378128",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378128/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15626",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855805",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1201",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1201#issuecomment-4760748680",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15627",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T17:24:16.907Z",
      "date_published": "2026-07-14T02:45:10.103Z",
      "date_updated": "2026-07-14T14:30:28.535Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw tool.go handleNavigate information disclosure",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15968
      },
      "nvd": {
        "published": "2026-07-14T04:17:15.857",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15627",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A caller-controlled targetUrl reaches handleNavigate and produces an information disclosure, while the public record omits the exposed data and failing check.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378129",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378129/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15627",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855847",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1207",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1207#issuecomment-4760370546",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-15628",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T17:28:11.050Z",
      "date_published": "2026-07-14T03:00:11.144Z",
      "date_updated": "2026-07-14T12:42:17.436Z",
      "publisher": "VulDB",
      "title": "zhayujie chatgpt-on-wechat CowAgent Vision Tool vision.py Vision._download_to_data_url server-side request forgery",
      "affected": {
        "vendors": [
          "zhayujie"
        ],
        "products": [
          {
            "vendor": "zhayujie",
            "product": "chatgpt-on-wechat CowAgent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00219,
        "percentile": 0.12443
      },
      "nvd": {
        "published": "2026-07-14T04:17:16.077",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15628",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Vision._download_to_data_url accepts an attacker-controlled image URL and makes the corresponding server-side request.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378130",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378130/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15628",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855849",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/issues/2878",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/pull/2886",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/commit/e85290cddcbb5ffc9c235927f4c92e5b4c3ec264",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/releases/tag/2.1.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 596,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15629",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T17:29:56.866Z",
      "date_published": "2026-07-14T03:30:09.462Z",
      "date_updated": "2026-07-14T12:30:25.981Z",
      "publisher": "VulDB",
      "title": "louisho5 picobot Workspace filesystem.go GetSkill link following",
      "affected": {
        "vendors": [
          "louisho5"
        ],
        "products": [
          {
            "vendor": "louisho5",
            "product": "picobot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21073
      },
      "nvd": {
        "published": "2026-07-14T05:16:17.723",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15629",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378131",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378131/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15629",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855854",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/louisho5/picobot/issues/40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/louisho5/picobot/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 469,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15630",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T17:35:29.688Z",
      "date_published": "2026-07-23T19:57:48.908Z",
      "date_updated": "2026-07-27T16:30:10.478Z",
      "publisher": "certcc",
      "title": "CVE-2026-15630",
      "affected": {
        "vendors": [
          "Casdoor"
        ],
        "products": [
          {
            "vendor": "Casdoor",
            "product": "Casdoor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15945
      },
      "nvd": {
        "published": "2026-07-23T21:17:02.760",
        "lastModified": "2026-07-30T19:10:06.847",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15630",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-639",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vokecyber.com/research/cve-2026-15630-casdoor-cross-tenant-authz",
          "host": "vokecyber.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15631",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T17:46:07.876Z",
      "date_published": "2026-07-18T12:46:37.291Z",
      "date_updated": "2026-07-20T15:15:21.351Z",
      "publisher": "openjs",
      "title": "@fastify/http-proxy vulnerable to prefix escape via WebSocket path traversal",
      "affected": {
        "vendors": [
          "@fastify/http-proxy"
        ],
        "products": [
          {
            "vendor": "@fastify/http-proxy",
            "product": "@fastify/http-proxy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25147
      },
      "nvd": {
        "published": "2026-07-18T13:17:05.323",
        "lastModified": "2026-07-28T15:42:54.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15631",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "@fastify/http-proxy accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fastify/fastify-http-proxy/security/advisories/GHSA-7hrw-592w-9wh2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 935,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15637",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T18:17:50.907Z",
      "date_published": "2026-07-14T18:05:34.963Z",
      "date_updated": "2026-07-15T14:40:46.594Z",
      "publisher": "DEVOLUTIONS",
      "title": "Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00192,
        "percentile": 0.09107
      },
      "nvd": {
        "published": "2026-07-14T19:16:51.013",
        "lastModified": "2026-07-30T14:57:54.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15637",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PAM credential endpoints use a caller-supplied identifier without checking that the caller may retrieve that credential's private key.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0024/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 300,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15641",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T18:21:03.185Z",
      "date_published": "2026-07-14T18:09:00.784Z",
      "date_updated": "2026-07-15T14:41:44.756Z",
      "publisher": "DEVOLUTIONS",
      "title": "Improper authorization in the access request status endpoint in Devolutions Server 2026.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11706
      },
      "nvd": {
        "published": "2026-07-14T19:16:51.110",
        "lastModified": "2026-07-30T14:57:43.467",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15641",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The workflow lets the requester approve the same request instead of requiring an independent approver.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0024/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 281,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15642",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T18:21:40.280Z",
      "date_published": "2026-07-14T18:09:46.308Z",
      "date_updated": "2026-07-15T14:43:07.544Z",
      "publisher": "DEVOLUTIONS",
      "title": "Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01799
      },
      "nvd": {
        "published": "2026-07-14T19:16:51.210",
        "lastModified": "2026-07-15T18:09:54.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15642",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Recovery Kit generation embeds the Azure Key Vault client secret in cleartext even when sensitive-data exclusion is selected.",
        "basis": [
          "CNA record",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0024/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15643",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T18:48:24.351Z",
      "date_published": "2026-07-14T20:03:58.729Z",
      "date_updated": "2026-07-15T14:22:10.360Z",
      "publisher": "AMZN",
      "title": "AWS HealthLake MCP Server SSRF via Pagination URL",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "awslabs.healthlake-mcp-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.8999999999999995,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12596
      },
      "nvd": {
        "published": "2026-07-14T21:16:41.293",
        "lastModified": "2026-07-15T16:17:47.050",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15643",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "awslabs.healthlake-mcp-server accepts an attacker-controlled server request target without constraining it to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://pypi.org/project/awslabs.healthlake-mcp-server/0.0.14/",
          "host": "pypi.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-054-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 690,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15646",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:10:06.115Z",
      "date_published": "2026-07-23T08:34:40.434Z",
      "date_updated": "2026-07-23T14:54:38.888Z",
      "publisher": "Wordfence",
      "title": "Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute",
      "affected": {
        "vendors": [
          "berocket"
        ],
        "products": [
          {
            "vendor": "berocket",
            "product": "Brands for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15545
      },
      "nvd": {
        "published": "2026-07-23T10:16:50.817",
        "lastModified": "2026-07-23T16:17:14.517",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15646",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WooCommerce brands component renders attacker-controlled content without neutralizing executable markup.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8fa3bcb9-df3e-4042-a28b-3d09bfebeebc?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/trunk/templates/catalog.php#L34",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/trunk/includes/shortcodes.php#L11",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/trunk/berocket/includes/functions.php#L516",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3608899%40brands-for-woocommerce&new=3608899%40brands-for-woocommerce",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15647",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:11:10.896Z",
      "date_published": "2026-07-23T08:34:40.072Z",
      "date_updated": "2026-07-23T16:04:37.162Z",
      "publisher": "Wordfence",
      "title": "Brands for WooCommerce <= 3.8.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field",
      "affected": {
        "vendors": [
          "berocket"
        ],
        "products": [
          {
            "vendor": "berocket",
            "product": "Brands for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09455
      },
      "nvd": {
        "published": "2026-07-23T10:16:50.943",
        "lastModified": "2026-07-23T16:17:14.617",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15647",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Brands for WooCommerce, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/89f6fa65-ef71-491e-8959-591b58d1444c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/tags/3.8.8/main.php#L718",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/tags/3.8.8/main.php#L774",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3608899%40brands-for-woocommerce&new=3608899%40brands-for-woocommerce",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 670,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15648",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:11:58.753Z",
      "date_published": "2026-07-24T06:52:00.092Z",
      "date_updated": "2026-07-24T22:10:51.283Z",
      "publisher": "Wordfence",
      "title": "Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'width' Shortcode Attribute",
      "affected": {
        "vendors": [
          "berocket"
        ],
        "products": [
          {
            "vendor": "berocket",
            "product": "Brands for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09245
      },
      "nvd": {
        "published": "2026-07-24T08:16:26.160",
        "lastModified": "2026-07-24T23:16:49.970",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15648",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3efb5f5c-64d2-4819-82bf-45574df94209?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/tags/3.8.8/addons/divi_shortcode/divi-builder.php#L127",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/tags/3.8.8/addons/divi_shortcode/divi-builder.php#L16",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/tags/3.8.8/addons/divi_shortcode/divi-builder.php#L7",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3608899%40brands-for-woocommerce&new=3608899%40brands-for-woocommerce",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15651",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:18:18.869Z",
      "date_published": "2026-07-16T07:51:04.530Z",
      "date_updated": "2026-07-16T15:11:28.732Z",
      "publisher": "Wordfence",
      "title": "WP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Injection via 'filtersource' Parameter",
      "affected": {
        "vendors": [
          "jgwhite33"
        ],
        "products": [
          {
            "vendor": "jgwhite33",
            "product": "WP TripAdvisor Review Slider"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21018
      },
      "nvd": {
        "published": "2026-07-16T09:16:18.393",
        "lastModified": "2026-07-16T16:19:00.867",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15651",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The filtersource value is inserted into SQL without sufficient escaping or parameter preparation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a0d38788-5f90-4ab1-8df1-1c67c1052e6d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.6/public/partials/wp-tripadvisor-review-slider-public-display.php#L106",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.6/public/partials/wp-tripadvisor-review-slider-public-display.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.6/public/partials/wp-tripadvisor-review-slider-public-display-widget.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.6/admin/class-wp-tripadvisor-review-slider-admin.php#L3310",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3607754/wp-tripadvisor-review-slider",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 517,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15652",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:39:08.971Z",
      "date_published": "2026-07-16T02:30:57.294Z",
      "date_updated": "2026-07-16T13:45:34.049Z",
      "publisher": "Wordfence",
      "title": "Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute",
      "affected": {
        "vendors": [
          "shapedplugin"
        ],
        "products": [
          {
            "vendor": "shapedplugin",
            "product": "Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09706
      },
      "nvd": {
        "published": "2026-07-16T04:17:25.463",
        "lastModified": "2026-07-16T14:16:48.987",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15652",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/eb0fb0a7-b9f7-42db-b826-fc09090bd817?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-accordion-free/tags/3.1.5/Blocks/Includes/ShortcodeBlock.php#L153",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-accordion-free/tags/3.1.5/Blocks/Includes/ShortcodeBlock.php#L150",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/easy-accordion-free/tags/3.1.5/Blocks/Includes/ShortcodeBlock.php#L127",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3607006%40easy-accordion-free&new=3607006%40easy-accordion-free",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 460,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15653",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:40:20.977Z",
      "date_published": "2026-07-24T06:52:01.471Z",
      "date_updated": "2026-07-24T12:29:03.502Z",
      "publisher": "Wordfence",
      "title": "Visualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' Parameter",
      "affected": {
        "vendors": [
          "themeisle"
        ],
        "products": [
          {
            "vendor": "themeisle",
            "product": "Visualizer – Tables & Charts Manager with Built-in AI Generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09237
      },
      "nvd": {
        "published": "2026-07-24T08:16:26.280",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15653",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted input reaches an interpreter without the grammar separation required by that execution context.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/914554fd-1525-4925-bce4-2df4a8df5dbf?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/visualizer/tags/4.0.5/classes/Visualizer/Render/Page/Data.php#L96",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/visualizer/tags/4.0.5/classes/Visualizer/Module/Chart.php#L826",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/visualizer/tags/4.0.5/classes/Visualizer/Module/Chart.php#L553",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3619025%40visualizer&new=3619025%40visualizer",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 466,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15657",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:52:18.155Z",
      "date_published": "2026-07-30T15:22:40.443Z",
      "date_updated": "2026-07-31T19:31:10.005Z",
      "publisher": "certcc",
      "title": "foreUP customer REST API allows authenticated users to read cleartext payment-processor merchant credentials",
      "affected": {
        "vendors": [
          "foreUP"
        ],
        "products": [
          {
            "vendor": "foreUP",
            "product": "foreUP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10141
      },
      "nvd": {
        "published": "2026-07-30T16:16:56.600",
        "lastModified": "2026-07-31T20:16:48.370",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15657",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The foreUP customer API returns cleartext payment-processor merchant credentials to any authenticated user instead of limiting their disclosure.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.cert.org/vuls/id/790363",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 156,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15658",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:52:45.444Z",
      "date_published": "2026-07-30T15:18:31.011Z",
      "date_updated": "2026-07-31T19:33:37.040Z",
      "publisher": "certcc",
      "title": "foreUP customer REST API allows unauthenticated endpoint access",
      "affected": {
        "vendors": [
          "foreUP"
        ],
        "products": [
          {
            "vendor": "foreUP",
            "product": "foreUP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10141
      },
      "nvd": {
        "published": "2026-07-30T16:16:56.700",
        "lastModified": "2026-07-31T20:16:48.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15658",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The foreUP API returns a record selected by the caller without checking that the authenticated customer owns it.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.cert.org/vuls/id/790363",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15663",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T20:24:33.708Z",
      "date_published": "2026-07-24T09:31:46.051Z",
      "date_updated": "2026-07-24T10:53:25.104Z",
      "publisher": "Wordfence",
      "title": "Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key",
      "affected": {
        "vendors": [
          "kstover"
        ],
        "products": [
          {
            "vendor": "kstover",
            "product": "Ninja Forms – The Contact Form Builder That Grows With You"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22535
      },
      "nvd": {
        "published": "2026-07-24T10:16:31.567",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15663",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2fda47d8-8e8c-4103-aabb-c70935e13450?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.9/includes/Abstracts/Model.php#L714",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.9/includes/Admin/Processes/ImportForm.php#L357",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.9/includes/Admin/Menus/ImportExport.php#L63",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.9/includes/AJAX/REST/BatchProcess.php#L41",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3614986%40ninja-forms&new=3614986%40ninja-forms",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 998,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15665",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T20:46:44.256Z",
      "date_published": "2026-07-24T06:51:58.346Z",
      "date_updated": "2026-07-24T20:26:51.110Z",
      "publisher": "Wordfence",
      "title": "Fluent Support <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute",
      "affected": {
        "vendors": [
          "wpmanageninja"
        ],
        "products": [
          {
            "vendor": "wpmanageninja",
            "product": "Fluent Support – Helpdesk & Customer Support Ticket System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09774
      },
      "nvd": {
        "published": "2026-07-24T08:16:26.410",
        "lastModified": "2026-07-24T21:16:42.460",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15665",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The redirect-to shortcode attribute is stored and rendered without sufficient sanitization and HTML-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0c963224-e680-4ca6-85ae-07cd0ee6c1d4?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluent-support/tags/2.3.0/app/Hooks/Handlers/AuthHandler.php#L149",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluent-support/tags/2.3.0/app/Hooks/Handlers/AuthHandler.php#L201",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluent-support/tags/2.3.0/app/Hooks/Handlers/AuthHandler.php#L500",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluent-support/tags/2.3.0/app/Hooks/Handlers/AuthHandler.php#L111",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3609122%40fluent-support&new=3609122%40fluent-support",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 609,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15668",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:12:07.140Z",
      "date_published": "2026-07-14T04:00:11.940Z",
      "date_updated": "2026-07-15T14:47:51.228Z",
      "publisher": "VulDB",
      "title": "louisho5 picobot web Tool web.go WebTool.Execute server-side request forgery",
      "affected": {
        "vendors": [
          "louisho5"
        ],
        "products": [
          {
            "vendor": "louisho5",
            "product": "picobot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13639
      },
      "nvd": {
        "published": "2026-07-14T05:16:18.030",
        "lastModified": "2026-07-15T15:16:29.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15668",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378162",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378162/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15668",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855866",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/louisho5/picobot/issues/41",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/louisho5/picobot/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 458,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15669",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:12:09.590Z",
      "date_published": "2026-07-14T05:15:08.751Z",
      "date_updated": "2026-07-14T12:40:52.008Z",
      "publisher": "VulDB",
      "title": "louisho5 picobot exec Tool exec.go ExecTool.Execute os command injection",
      "affected": {
        "vendors": [
          "louisho5"
        ],
        "products": [
          {
            "vendor": "louisho5",
            "product": "picobot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00622,
        "percentile": 0.46384
      },
      "nvd": {
        "published": "2026-07-14T06:17:19.803",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15669",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled command data reaches a command interpreter without safe argument separation or complete command-language neutralization.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378163",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378163/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15669",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855869",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855870",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/louisho5/picobot/issues/42",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/louisho5/picobot/issues/43",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/louisho5/picobot/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15670",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:12:46.906Z",
      "date_published": "2026-07-28T06:54:35.749Z",
      "date_updated": "2026-07-28T16:10:05.206Z",
      "publisher": "Wordfence",
      "title": "SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "affected": {
        "vendors": [
          "cozyvision1"
        ],
        "products": [
          {
            "vendor": "cozyvision1",
            "product": "SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18628
      },
      "nvd": {
        "published": "2026-07-28T08:17:14.750",
        "lastModified": "2026-07-28T16:17:29.950",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15670",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bcae549f-6a10-4b0d-a8d1-5dcc83e1f2e5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/helper/class-backinstock.php#L822",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/helper/class-backinstock.php#L813",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/helper/class-backinstock.php#L1105",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3623914%40sms-alert&new=3623914%40sms-alert",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15671",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:13:19.212Z",
      "date_published": "2026-07-28T06:54:35.333Z",
      "date_updated": "2026-07-28T14:53:54.940Z",
      "publisher": "Wordfence",
      "title": "SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' Parameter",
      "affected": {
        "vendors": [
          "cozyvision1"
        ],
        "products": [
          {
            "vendor": "cozyvision1",
            "product": "SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21017
      },
      "nvd": {
        "published": "2026-07-28T08:17:14.917",
        "lastModified": "2026-07-28T16:17:30.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15671",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery database query without safe parameter binding, allowing SQL syntax injection.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b8440c1d-2a02-42b4-8fc5-42e5a107c0af?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/template/sms_campaign.php#L56",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/helper/class-abandonedcart.php#L1716",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/SMSAlert-wc-order-sms.php#L106",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/SMSAlert-wc-order-sms.php#L196",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3623914%40sms-alert&new=3623914%40sms-alert",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 564,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15672",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:13:40.229Z",
      "date_published": "2026-07-14T05:30:08.657Z",
      "date_updated": "2026-07-15T14:36:41.762Z",
      "publisher": "VulDB",
      "title": "itsourcecode Electronic Judging System add_judges.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Electronic Judging System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10062
      },
      "nvd": {
        "published": "2026-07-14T06:17:25.633",
        "lastModified": "2026-07-15T15:16:29.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15672",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "add_judges.php inserts the fname parameter into an SQL command without parameter binding.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378164",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378164/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15672",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855930",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sjmycz/cve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 313,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15673",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:14:34.831Z",
      "date_published": "2026-07-28T06:54:36.163Z",
      "date_updated": "2026-07-28T12:57:02.647Z",
      "publisher": "Wordfence",
      "title": "SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checkout_payment_plans' and 'order_status' Settings",
      "affected": {
        "vendors": [
          "cozyvision1"
        ],
        "products": [
          {
            "vendor": "cozyvision1",
            "product": "SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25285
      },
      "nvd": {
        "published": "2026-07-28T08:17:15.077",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15673",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Stored plugin settings are later interpolated into a cron-time SQL query without parameterization, creating second-order SQL injection.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c2ad4325-be1f-48c1-b21f-adf9ce3fa2cb?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/handler/forms/woocommerce/wc-checkout.php#L2543",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/handler/forms/woocommerce/wc-checkout.php#L2523",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/handler/forms/woocommerce/wc-checkout.php#L2525",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/classes/setting-options.php#L408",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/classes/setting-options.php#L505",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/SMSAlert-wc-order-sms.php#L116",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/sms-alert/tags/3.9.7/SMSAlert-wc-order-sms.php#L177",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3623914%40sms-alert&new=3623914%40sms-alert",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 870,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15675",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:19:09.499Z",
      "date_published": "2026-07-14T05:45:07.884Z",
      "date_updated": "2026-07-14T14:30:22.483Z",
      "publisher": "VulDB",
      "title": "code-projects Online Job Portal EditUser.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Online Job Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18019
      },
      "nvd": {
        "published": "2026-07-14T06:17:30.483",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15675",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The UserId parameter is incorporated into an EditUser.php SQL statement without safe parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378165",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378165/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15675",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855969",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/shihuizhang-dazhi/MY-CVE/issues/3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15676",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:19:12.182Z",
      "date_published": "2026-07-14T06:00:08.240Z",
      "date_updated": "2026-07-14T12:47:06.364Z",
      "publisher": "VulDB",
      "title": "code-projects Online Job Portal DeleteUser.php sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Online Job Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.1802
      },
      "nvd": {
        "published": "2026-07-14T06:17:35.467",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15676",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Online Job Portal query path incorporates attacker-controlled input into SQL without parameter separation.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378166",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378166/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15676",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855976",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/shihuizhang-dazhi/MY-CVE/issues/4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15677",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:19:21.648Z",
      "date_published": "2026-07-14T06:15:07.720Z",
      "date_updated": "2026-07-14T12:23:21.410Z",
      "publisher": "VulDB",
      "title": "code-projects Online Job Portal JobSeekerInsert.php unrestricted upload",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Online Job Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21054
      },
      "nvd": {
        "published": "2026-07-14T07:16:19.417",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15677",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "JobSeekerInsert.php accepts an uploaded file without restricting it to safe file types or destinations.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378167",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378167/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15677",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855977",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/shihuizhang-dazhi/MY-CVE/issues/6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15678",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:19:29.452Z",
      "date_published": "2026-07-14T06:30:08.294Z",
      "date_updated": "2026-07-15T14:58:11.907Z",
      "publisher": "VulDB",
      "title": "code-projects Online Job Portal DetailJob.php cross site scripting",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Online Job Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09874
      },
      "nvd": {
        "published": "2026-07-14T07:16:20.630",
        "lastModified": "2026-07-15T16:16:44.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15678",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Online Job Portal, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378168",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378168/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15678",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855978",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/shihuizhang-dazhi/MY-CVE/issues/7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15680",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:28:47.326Z",
      "date_published": "2026-07-13T21:32:15.740Z",
      "date_updated": "2026-07-14T12:47:53.179Z",
      "publisher": "zdi",
      "title": "Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Lorex"
        ],
        "products": [
          {
            "vendor": "Lorex",
            "product": "2K Indoor Wi-Fi Security Camera"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-134",
          "name": "Use of Externally-Controlled Format String",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17622
      },
      "nvd": {
        "published": "2026-07-13T22:16:45.387",
        "lastModified": "2026-07-14T16:45:45.980",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15680",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "2K Indoor Wi-Fi Security Camera passes attacker-controlled text as a format string instead of data, allowing format directives to drive reads, writes, or control flow.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-134"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-398/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 618,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15681",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:29:16.312Z",
      "date_published": "2026-07-13T21:31:49.881Z",
      "date_updated": "2026-07-14T12:48:29.853Z",
      "publisher": "zdi",
      "title": "AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability",
      "affected": {
        "vendors": [
          "AnyDesk"
        ],
        "products": [
          {
            "vendor": "AnyDesk",
            "product": "AnyDesk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00104,
        "percentile": 0.01211
      },
      "nvd": {
        "published": "2026-07-13T22:16:45.510",
        "lastModified": "2026-07-14T21:00:36.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15681",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The privileged screen-recording service follows a local junction and creates a file at the junction-selected target.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-400/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 602,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15682",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:29:24.642Z",
      "date_published": "2026-07-13T21:31:11.029Z",
      "date_updated": "2026-07-14T12:51:30.078Z",
      "publisher": "zdi",
      "title": "AnyDesk Support Information Link Following Denial-of-Service Vulnerability",
      "affected": {
        "vendors": [
          "AnyDesk"
        ],
        "products": [
          {
            "vendor": "AnyDesk",
            "product": "AnyDesk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03113
      },
      "nvd": {
        "published": "2026-07-13T22:16:45.630",
        "lastModified": "2026-07-14T20:59:52.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15682",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AnyDesk follows an attacker-controlled link or junction before a privileged file operation, redirecting access to a different filesystem object.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-401/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 603,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15683",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:29:35.821Z",
      "date_published": "2026-07-13T21:30:56.601Z",
      "date_updated": "2026-07-14T12:52:06.747Z",
      "publisher": "zdi",
      "title": "Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability",
      "affected": {
        "vendors": [
          "Lorex"
        ],
        "products": [
          {
            "vendor": "Lorex",
            "product": "2K Indoor Wi-Fi Security Camera"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00096,
        "percentile": 0.00845
      },
      "nvd": {
        "published": "2026-07-13T22:16:45.793",
        "lastModified": "2026-07-14T16:45:45.980",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15683",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The camera management client accepts a server certificate without performing the required certificate validation.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-399/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 619,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:29:44.054Z",
      "date_published": "2026-07-13T21:30:42.534Z",
      "date_updated": "2026-07-14T13:00:33.375Z",
      "publisher": "zdi",
      "title": "Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability",
      "affected": {
        "vendors": [
          "Glarysoft"
        ],
        "products": [
          {
            "vendor": "Glarysoft",
            "product": "Glary Utilities"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03959
      },
      "nvd": {
        "published": "2026-07-13T22:16:45.993",
        "lastModified": "2026-07-14T16:45:45.980",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15684",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The privileged Disk Clean service follows an attacker-created junction when deleting files.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-402/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 624,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:29:52.777Z",
      "date_published": "2026-07-13T21:30:09.180Z",
      "date_updated": "2026-07-14T13:05:28.063Z",
      "publisher": "zdi",
      "title": "Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability",
      "affected": {
        "vendors": [
          "Ollama"
        ],
        "products": [
          {
            "vendor": "Ollama",
            "product": "Ollama"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00391,
        "percentile": 0.31834
      },
      "nvd": {
        "published": "2026-07-13T22:16:46.123",
        "lastModified": "2026-07-14T20:59:10.293",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15685",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ollama downloadBlob uses an attacker-controlled array index without validating it against the available elements.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-403/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 595,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T23:31:31.228Z",
      "date_published": "2026-07-23T18:43:25.357Z",
      "date_updated": "2026-07-23T19:03:12.469Z",
      "publisher": "kubernetes",
      "title": "Path traversal via non-tar copyDirectoryFromPod",
      "affected": {
        "vendors": [
          "Kubernetes"
        ],
        "products": [
          {
            "vendor": "Kubernetes",
            "product": "kubernetes-client/java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:jordan@liggitt.net",
          "type": "Secondary",
          "version": "3.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0.30000000000000027,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14487
      },
      "nvd": {
        "published": "2026-07-23T19:16:53.390",
        "lastModified": "2026-07-23T20:17:07.627",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15687",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kubernetes-client/java/issues/4861",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-15690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T04:55:16.031Z",
      "date_published": "2026-07-14T11:45:07.861Z",
      "date_updated": "2026-07-14T12:56:38.149Z",
      "publisher": "VulDB",
      "title": "open62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereference",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "open62541"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 2.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 2.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 1.8,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18849
      },
      "nvd": {
        "published": "2026-07-14T12:16:55.947",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15690",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "responseReadNamespacesArray dereferences a null Server_NamespaceArray received by the shared client.",
        "basis": [
          "CNA",
          "CWE-404",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378237",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378237/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15690",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855996",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/open62541/open62541/issues/8104",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/open62541/open62541/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 593,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-15691",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T04:58:09.621Z",
      "date_published": "2026-07-14T12:15:11.454Z",
      "date_updated": "2026-07-15T14:44:12.835Z",
      "publisher": "VulDB",
      "title": "Tenda BE12 Pro SafeClientFilter fromSafeClientFilter stack-based overflow",
      "affected": {
        "vendors": [
          "Tenda"
        ],
        "products": [
          {
            "vendor": "Tenda",
            "product": "BE12 Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00466,
        "percentile": 0.38005
      },
      "nvd": {
        "published": "2026-07-14T13:18:19.967",
        "lastModified": "2026-07-15T15:16:30.033",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15691",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler copies attacker-controlled data beyond a fixed-size stack buffer.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378238",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378238/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15691",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855999",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/cve-a/dexingzhiqing/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.tenda.com.cn/",
          "host": "www.tenda.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15692",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T04:58:11.929Z",
      "date_published": "2026-07-14T12:30:10.831Z",
      "date_updated": "2026-07-14T14:30:05.251Z",
      "publisher": "VulDB",
      "title": "Tenda BE12 Pro SafeUrlFilter fromSafeUrlFilter stack-based overflow",
      "affected": {
        "vendors": [
          "Tenda"
        ],
        "products": [
          {
            "vendor": "Tenda",
            "product": "BE12 Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00466,
        "percentile": 0.38005
      },
      "nvd": {
        "published": "2026-07-14T13:18:20.133",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15692",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BE12 Pro can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378239",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378239/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15692",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856010",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/cve-a/dexingzhiqing/issues/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.tenda.com.cn/",
          "host": "www.tenda.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15693",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T04:58:14.402Z",
      "date_published": "2026-07-14T13:15:10.740Z",
      "date_updated": "2026-07-14T13:55:46.773Z",
      "publisher": "VulDB",
      "title": "Tenda BE12 Pro SafeMacFilter fromSafeMacFilter stack-based overflow",
      "affected": {
        "vendors": [
          "Tenda"
        ],
        "products": [
          {
            "vendor": "Tenda",
            "product": "BE12 Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00466,
        "percentile": 0.38007
      },
      "nvd": {
        "published": "2026-07-14T14:16:33.130",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15693",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is copied beyond the boundary of a stack buffer.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378240",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378240/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15693",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856011",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/cve-a/dexingzhiqing/issues/3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.tenda.com.cn/",
          "host": "www.tenda.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 339,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15694",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T04:58:16.916Z",
      "date_published": "2026-07-14T14:15:09.735Z",
      "date_updated": "2026-07-14T14:35:17.481Z",
      "publisher": "VulDB",
      "title": "Tenda BE12 Pro SetIpBind fromSetIpBind stack-based overflow",
      "affected": {
        "vendors": [
          "Tenda"
        ],
        "products": [
          {
            "vendor": "Tenda",
            "product": "BE12 Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00466,
        "percentile": 0.38007
      },
      "nvd": {
        "published": "2026-07-14T15:17:00.583",
        "lastModified": "2026-07-14T15:26:24.850",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15694",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BE12 Pro writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378241",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378241/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15694",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856015",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/cve-a/dexingzhiqing/issues/4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.tenda.com.cn/",
          "host": "www.tenda.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 296,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T04:58:19.512Z",
      "date_published": "2026-07-14T14:30:09.879Z",
      "date_updated": "2026-07-15T16:11:22.565Z",
      "publisher": "VulDB",
      "title": "Tenda BE12 Pro DhcpListClient fromDhcpListClient stack-based overflow",
      "affected": {
        "vendors": [
          "Tenda"
        ],
        "products": [
          {
            "vendor": "Tenda",
            "product": "BE12 Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00476,
        "percentile": 0.38656
      },
      "nvd": {
        "published": "2026-07-14T15:17:00.753",
        "lastModified": "2026-07-15T17:16:46.363",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15695",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The fromDhcpListClient handler copies a caller-controlled page value beyond a stack buffer.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378242",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378242/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15695",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856017",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/cve-a/dexingzhiqing/issues/5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.tenda.com.cn/",
          "host": "www.tenda.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15696",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T04:58:22.099Z",
      "date_published": "2026-07-14T14:45:11.818Z",
      "date_updated": "2026-07-14T15:15:11.959Z",
      "publisher": "VulDB",
      "title": "Tenda BE12 Pro VirtualSer fromVirtualSer stack-based overflow",
      "affected": {
        "vendors": [
          "Tenda"
        ],
        "products": [
          {
            "vendor": "Tenda",
            "product": "BE12 Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00466,
        "percentile": 0.38007
      },
      "nvd": {
        "published": "2026-07-14T15:17:00.913",
        "lastModified": "2026-07-14T16:16:46.017",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15696",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can overflow a stack buffer.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378243",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378243/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15696",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856019",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/cve-a/dexingzhiqing/issues/6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.tenda.com.cn/",
          "host": "www.tenda.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T05:01:41.727Z",
      "date_published": "2026-07-14T15:15:09.763Z",
      "date_updated": "2026-07-15T14:47:52.297Z",
      "publisher": "VulDB",
      "title": "svgdotjs svg.js npm Package API EventTarget.on prototype pollution",
      "affected": {
        "vendors": [
          "svgdotjs"
        ],
        "products": [
          {
            "vendor": "svgdotjs",
            "product": "svg.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25527
      },
      "nvd": {
        "published": "2026-07-14T16:16:46.143",
        "lastModified": "2026-07-15T15:16:30.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15697",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "EventTarget.on permits attacker-controlled keys to modify object prototype attributes.",
        "basis": [
          "CNA record",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378244",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378244/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15697",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856013",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/svgdotjs/svg.js/issues/1343",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/svgdotjs/svg.js/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-15698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T05:08:37.762Z",
      "date_published": "2026-07-14T15:30:10.077Z",
      "date_updated": "2026-07-14T16:26:47.699Z",
      "publisher": "VulDB",
      "title": "kofrasa mingo Update API updateMany prototype pollution",
      "affected": {
        "vendors": [
          "kofrasa"
        ],
        "products": [
          {
            "vendor": "kofrasa",
            "product": "mingo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17843
      },
      "nvd": {
        "published": "2026-07-14T16:16:46.310",
        "lastModified": "2026-07-14T17:16:45.177",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15698",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The update API accepts special property paths that modify JavaScript object prototypes instead of treating those keys as ordinary untrusted data.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378245",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378245/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15698",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856014",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/kofrasa/mingo/issues/606",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/kofrasa/mingo/commit/fadc398251792c2ba441cbc539f359fc7943c0c2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/kofrasa/mingo/releases/tag/7.2.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/kofrasa/mingo/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15699",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T05:12:43.606Z",
      "date_published": "2026-07-14T15:45:08.286Z",
      "date_updated": "2026-07-14T17:52:49.267Z",
      "publisher": "VulDB",
      "title": "spencermountain compromise Public Root API extend.js nlp.extend prototype pollution",
      "affected": {
        "vendors": [
          "spencermountain"
        ],
        "products": [
          {
            "vendor": "spencermountain",
            "product": "compromise"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17123
      },
      "nvd": {
        "published": "2026-07-14T16:16:46.477",
        "lastModified": "2026-07-14T18:17:12.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15699",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The nlp.extend API lets a supplied plugin modify Object prototype properties outside the plugin's intended object scope.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378246",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378246/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15699",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856016",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/spencermountain/compromise/issues/1208",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/spencermountain/compromise/commit/b4644ab7179700df0607521f61c1ee9b5f78d89d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/spencermountain/compromise/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 660,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15700",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T05:22:57.571Z",
      "date_published": "2026-07-14T16:15:07.253Z",
      "date_updated": "2026-07-15T13:51:26.112Z",
      "publisher": "VulDB",
      "title": "DedeCMS Album Publishing Feature zip.class.php ExtractFile path traversal",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "DedeCMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00363,
        "percentile": 0.29039
      },
      "nvd": {
        "published": "2026-07-14T17:16:45.310",
        "lastModified": "2026-07-15T14:17:18.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15700",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file operation in DedeCMS uses an attacker-controlled path without confining the resolved object to the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378247",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378247/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15700",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856135",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/DunkBoyZz/dedecms/tree/379d9ec42cbe5d5b177578218070d69b6dada83f/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 370,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15701",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T05:27:02.636Z",
      "date_published": "2026-07-14T16:30:10.560Z",
      "date_updated": "2026-07-15T14:50:35.949Z",
      "publisher": "VulDB",
      "title": "Totolink NR1800X lighttpd formLogout.htm Form_Logout stack-based overflow",
      "affected": {
        "vendors": [
          "Totolink"
        ],
        "products": [
          {
            "vendor": "Totolink",
            "product": "NR1800X"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 10,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 10,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00785,
        "percentile": 0.52547
      },
      "nvd": {
        "published": "2026-07-14T17:16:45.477",
        "lastModified": "2026-07-15T16:16:44.257",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15701",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input exceeds a stack buffer because the copy or write is not bounded to that allocation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378248",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378248/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15701",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856136",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/fu9-dotom/cve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.totolink.net/",
          "host": "www.totolink.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 386,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15702",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T05:29:15.935Z",
      "date_published": "2026-07-14T16:45:09.501Z",
      "date_updated": "2026-07-15T13:17:16.052Z",
      "publisher": "VulDB",
      "title": "tamagui config.ts updateConfig prototype pollution",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "tamagui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26327
      },
      "nvd": {
        "published": "2026-07-14T17:16:45.640",
        "lastModified": "2026-07-15T14:17:18.893",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15702",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "updateConfig accepts prototype-sensitive keys and modifies shared object prototype attributes.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378249",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378249/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15702",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856138",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/tamagui/tamagui/issues/4029",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/tamagui/tamagui/commit/e46af9879b7627934ea4d6d6e46e65cea53abb3d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/tamagui/tamagui/releases/tag/v2.3.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/tamagui/tamagui/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 450,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-15703",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T05:39:51.433Z",
      "date_published": "2026-07-14T17:00:08.729Z",
      "date_updated": "2026-07-15T15:45:27.209Z",
      "publisher": "VulDB",
      "title": "SourceCodester Simple and Nice Shopping Cart Script userproductdeletequery.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Simple and Nice Shopping Cart Script"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25353
      },
      "nvd": {
        "published": "2026-07-14T17:16:45.803",
        "lastModified": "2026-07-15T16:16:44.377",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15703",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Simple and Nice Shopping Cart Script data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378250",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378250/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15703",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856152",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/Wut-sys/cve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15704",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T07:09:49.542Z",
      "date_published": "2026-07-24T07:41:42.653Z",
      "date_updated": "2026-07-24T12:30:35.564Z",
      "publisher": "eclipse",
      "title": "CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse BaSyx Go Components"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-180",
          "name": "Incorrect Behavior Order: Validate Before Canonicalize",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.27998
      },
      "nvd": {
        "published": "2026-07-24T09:16:24.113",
        "lastModified": "2026-07-30T19:12:22.607",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15704",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ABAC decision is made before trailing-slash canonicalization, so a different normalized path is used after authorization.",
        "basis": [
          "CNA",
          "CWE-180",
          "CWE-284",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/580",
          "host": "gitlab.eclipse.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/eclipse-basyx/basyx-go-components/pull/442",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/eclipse-basyx/basyx-go-components/releases/tag/v1.0.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/164",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1409,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15709",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T09:32:47.038Z",
      "date_published": "2026-07-14T19:41:37.331Z",
      "date_updated": "2026-07-15T12:58:18.795Z",
      "publisher": "redhat",
      "title": "Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00548,
        "percentile": 0.42844
      },
      "nvd": {
        "published": "2026-07-14T20:16:57.027",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15709",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Red Hat Enterprise Linux 10 decompression path expands attacker-controlled compressed data before enforcing an effective output-size limit.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15709",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499922",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libsoup/-/issues/511",
          "host": "gitlab.gnome.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 807,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15711",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T09:45:31.488Z",
      "date_published": "2026-07-14T19:45:47.784Z",
      "date_updated": "2026-07-15T14:11:08.927Z",
      "publisher": "redhat",
      "title": "Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00431,
        "percentile": 0.35428
      },
      "nvd": {
        "published": "2026-07-14T20:16:57.177",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15711",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "libsoup fails to reject WebSocket control frames larger than 125 bytes and crashes while processing the invalid frame.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15711",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499924",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libsoup/-/issues/515",
          "host": "gitlab.gnome.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 628,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15712",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T09:55:11.765Z",
      "date_published": "2026-07-14T18:11:33.603Z",
      "date_updated": "2026-07-14T19:15:43.984Z",
      "publisher": "redhat",
      "title": "Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00498,
        "percentile": 0.39973
      },
      "nvd": {
        "published": "2026-07-14T19:16:51.313",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15712",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Because the parser lacks strict length-boundary verification before reading this data, a remote, unauthenticated attacker can intentionally send a malformed GOAWAY frame missing the appropriate null delimiter.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15712",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499939",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libsoup/-/work_items/540",
          "host": "gitlab.gnome.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 719,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:14:16.964Z",
      "date_published": "2026-07-14T19:45:56.489Z",
      "date_updated": "2026-07-15T15:12:09.397Z",
      "publisher": "redhat",
      "title": "Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-772",
          "name": "Missing Release of Resource after Effective Lifetime",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00349,
        "percentile": 0.2755
      },
      "nvd": {
        "published": "2026-07-14T20:16:57.430",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15713",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets.",
        "basis": [
          "CNA",
          "CWE-772"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15713",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499941",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libsoup/-/work_items/541",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 658,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15714",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:23:23.535Z",
      "date_published": "2026-07-14T19:50:53.332Z",
      "date_updated": "2026-07-15T14:09:52.512Z",
      "publisher": "redhat",
      "title": "Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0039,
        "percentile": 0.31787
      },
      "nvd": {
        "published": "2026-07-14T20:16:57.560",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15714",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libsoup accepts an oversized or malformed multipart boundary and reads beyond the internal header buffer in soup_multipart_input_stream_read_headers().",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15714",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499942",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/libsoup/-/work_items/542",
          "host": "gitlab.gnome.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 646,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15715",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:40:56.375Z",
      "date_published": "2026-07-14T17:45:08.923Z",
      "date_updated": "2026-07-14T19:51:21.035Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System exam.php cross site scripting",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00359,
        "percentile": 0.28626
      },
      "nvd": {
        "published": "2026-07-14T18:17:12.423",
        "lastModified": "2026-07-14T20:21:36.510",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15715",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378291",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378291/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15715",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856170",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856171",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/AlbaDove/cve/issues/7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15718",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T12:15:45.500Z",
      "date_published": "2026-07-14T12:15:46.176Z",
      "date_updated": "2026-07-22T19:19:21.078Z",
      "publisher": "mozilla",
      "title": "Invalid pointer in the JavaScript: WebAssembly component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-763",
          "name": "Release of Invalid Pointer or Reference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00381,
        "percentile": 0.30838
      },
      "nvd": {
        "published": "2026-07-14T13:18:20.310",
        "lastModified": "2026-07-22T20:16:48.770",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15718",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The structured record indicates release of an invalid pointer, but Mozilla's public text omits the pointer, release path, and later memory access.",
        "basis": [
          "CNA",
          "CWE-763"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2045443",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-67/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15719",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T12:15:46.894Z",
      "date_published": "2026-07-14T12:15:47.592Z",
      "date_updated": "2026-07-22T19:19:22.168Z",
      "publisher": "mozilla",
      "title": "Site isolation issue in the DOM: Navigation component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.2645
      },
      "nvd": {
        "published": "2026-07-14T13:18:20.407",
        "lastModified": "2026-07-22T20:16:48.927",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15719",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The vendor identifies a DOM Navigation site-isolation issue but does not publish the violated isolation rule or state transition.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2043820",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-67/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-15720",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T12:29:33.633Z",
      "date_published": "2026-07-14T18:20:22.732Z",
      "date_updated": "2026-07-15T14:02:22.116Z",
      "publisher": "redhat-cnalr",
      "title": "Pre-auth heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler",
      "affected": {
        "vendors": [
          "open5gs"
        ],
        "products": [
          {
            "vendor": "open5gs",
            "product": "open5gs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:74b3a70d-cca6-4d34-9789-e83b222ae3be",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29854
      },
      "nvd": {
        "published": "2026-07-14T19:16:51.470",
        "lastModified": "2026-07-15T20:58:48.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15720",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pre-authentication mobile-identity handler reads beyond a heap allocation while parsing a crafted identity.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open5gs/open5gs/security/advisories/GHSA-f4mx-3x6p-cfwp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15722",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T12:55:19.649Z",
      "date_published": "2026-07-31T09:18:50.308Z",
      "date_updated": "2026-07-31T10:44:58.315Z",
      "publisher": "redhat",
      "title": "389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 11"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 12"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 13"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0051,
        "percentile": 0.40714
      },
      "nvd": {
        "published": "2026-07-31T10:16:44.863",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15722",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The RUV decoder copies an attacker-controlled run of digits into a fixed 16-byte stack buffer without a length bound.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15722",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499961",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15724",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T13:13:06.485Z",
      "date_published": "2026-07-21T16:55:34.486Z",
      "date_updated": "2026-07-24T03:55:48.821Z",
      "publisher": "ProgressSoftware",
      "title": "Path traversal in Progress ShareFile Storage Zones Controller (SZC)",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "ShareFile Storage Zones Controller"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26623
      },
      "nvd": {
        "published": "2026-07-21T17:17:04.703",
        "lastModified": "2026-07-24T05:16:38.557",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15724",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An administrative request can supply traversal segments that select files and write destinations outside the ShareFile controller's intended directory.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.sharefile.com/s/article/ShareFile-Storage-Zone-Controller-SZC-Service-Disruption-Guidance-Login-Issues-and-Access-Information",
          "host": "support.sharefile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 309,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15727",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T13:32:01.946Z",
      "date_published": "2026-07-16T08:26:50.455Z",
      "date_updated": "2026-07-16T12:24:07.859Z",
      "publisher": "Wordfence",
      "title": "WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter",
      "affected": {
        "vendors": [
          "xylus"
        ],
        "products": [
          {
            "vendor": "xylus",
            "product": "WP Bulk Delete"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00355,
        "percentile": 0.28261
      },
      "nvd": {
        "published": "2026-07-16T09:16:18.510",
        "lastModified": "2026-07-16T13:38:53.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15727",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WP Bulk Delete query path incorporates attacker-controlled input into SQL without parameter separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/39d325d4-073c-47b6-8ea4-30637417f0d7?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-bulk-delete/tags/1.4.1/includes/class-delete-api.php#L1071",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-bulk-delete/tags/1.4.2/includes/class-delete-api.php#L1113",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-bulk-delete/tags/1.4.2/includes/class-delete-api.php#L1071",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-bulk-delete/tags/1.4.2/includes/ajax-delete-handler.php#L36",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-bulk-delete/tags/1.4.2/includes/ajax-delete-handler.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-bulk-delete/tags/1.4.1/includes/class-delete-api.php#L1113",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-bulk-delete/tags/1.4.1/includes/ajax-delete-handler.php#L36",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-bulk-delete/tags/1.4.1/includes/ajax-delete-handler.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3608270/wp-bulk-delete/trunk/includes/class-delete-api.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 719,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T13:36:55.591Z",
      "date_published": "2026-07-28T06:54:36.591Z",
      "date_updated": "2026-07-28T13:30:26.477Z",
      "publisher": "Wordfence",
      "title": "GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute",
      "affected": {
        "vendors": [
          "rubengc"
        ],
        "products": [
          {
            "vendor": "rubengc",
            "product": "GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12075
      },
      "nvd": {
        "published": "2026-07-28T08:17:15.230",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15730",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The shortcode handler synthesizes HTML from heading_size after save-time filtering, so attacker markup reaches the browser at render time.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dedd24e6-ac0c-48cd-a76a-8fb61d2c3c0f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.8/includes/filters.php#L263",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.8/includes/filters.php#L390",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.8/includes/filters.php#L542",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.8/includes/filters.php#L1885",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.8/includes/shortcodes/gamipress_points_types.php#L212",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3619577%40gamipress&new=3619577%40gamipress",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 762,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15735",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T13:56:10.612Z",
      "date_published": "2026-07-29T01:29:40.216Z",
      "date_updated": "2026-07-29T14:22:10.309Z",
      "publisher": "Wordfence",
      "title": "Contact Form to Any API <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta",
      "affected": {
        "vendors": [
          "itpathsolutions"
        ],
        "products": [
          {
            "vendor": "itpathsolutions",
            "product": "Contact Form to Any API"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09238
      },
      "nvd": {
        "published": "2026-07-29T02:16:43.183",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15735",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Contact Form to Any API, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1f5390b1-c85b-4bf6-ab38-6ae0efe72ffa?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-to-any-api/tags/3.0.6/admin/class-cf7-to-any-api-admin.php#L519",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-to-any-api/tags/3.0.6/admin/class-cf7-to-any-api-admin.php#L334",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/contact-form-to-any-api/tags/3.0.6/admin/class-cf7-to-any-api-admin.php#L604",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3624000%40contact-form-to-any-api&new=3624000%40contact-form-to-any-api",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 429,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15736",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:01:42.714Z",
      "date_published": "2026-07-14T14:11:31.279Z",
      "date_updated": "2026-07-14T15:14:26.264Z",
      "publisher": "SNOWFLAKE",
      "title": "Multiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowflake-sqlalchemy",
      "affected": {
        "vendors": [
          "Snowflake"
        ],
        "products": [
          {
            "vendor": "Snowflake",
            "product": "Snowflake SQLAlchemy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:412d305a-227d-44f9-a262-a31ba44f2aea",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18723
      },
      "nvd": {
        "published": "2026-07-14T15:17:01.073",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15736",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Snowflake SQLAlchemy incorporates attacker-controlled values or identifiers into a SQL statement without preserving the boundary between query syntax and data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-73",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/snowflakedb/snowflake-sqlalchemy/releases",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1360,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:02:14.644Z",
      "date_published": "2026-07-16T17:03:15.160Z",
      "date_updated": "2026-07-16T17:58:56.977Z",
      "publisher": "AMZN",
      "title": "Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "bedrock-agentcore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12073
      },
      "nvd": {
        "published": "2026-07-16T18:16:42.537",
        "lastModified": "2026-07-17T18:08:44.860",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15737",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SDK records complete prompts and responses as unmasked OpenTelemetry span attributes readable by CloudWatch log principals.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://pypi.org/project/bedrock-agentcore/1.5.1/",
          "host": "pypi.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-058-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/aws/bedrock-agentcore-sdk-python/security/advisories/GHSA-hqf8-7w95-9r33",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 925,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:02:30.277Z",
      "date_published": "2026-07-14T20:19:23.721Z",
      "date_updated": "2026-07-15T13:01:51.239Z",
      "publisher": "AMZN",
      "title": "Cross-namespace traffic interception via incorrect route precedence ordering in AWS Load Balancer Controller",
      "affected": {
        "vendors": [
          "Amazon"
        ],
        "products": [
          {
            "vendor": "Amazon",
            "product": "aws-load-balancer-controller"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-653",
          "name": "Improper Isolation or Compartmentalization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 2.7,
      "epss": {
        "score": 0.00373,
        "percentile": 0.30026
      },
      "nvd": {
        "published": "2026-07-14T21:16:41.440",
        "lastModified": "2026-07-15T16:17:47.050",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15738",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gateway listener rules use an incorrect precedence order, allowing a route from one namespace to capture another namespace's gRPC traffic.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-653"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kubernetes-sigs/aws-load-balancer-controller/releases/tag/v3.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-055-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 343,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15739",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:22:59.359Z",
      "date_published": "2026-07-24T07:53:36.691Z",
      "date_updated": "2026-07-24T14:24:07.142Z",
      "publisher": "Wordfence",
      "title": "Rich Showcase for Google Reviews <= 6.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute",
      "affected": {
        "vendors": [
          "widgetpack"
        ],
        "products": [
          {
            "vendor": "widgetpack",
            "product": "Rich Showcase for Google Reviews"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15326
      },
      "nvd": {
        "published": "2026-07-24T09:16:24.257",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15739",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pagination shortcode attribute is stored and rendered without sufficient HTML-context sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c3851607-73e7-44ae-8d5b-e8b7460851ea?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.7/includes/class-view.php#L336",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.8/includes/class-view.php#L336",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.8/includes/class-view.php#L172",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.8/includes/class-feed-old.php#L45",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.8/includes/class-feed-shortcode.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.7/includes/class-view.php#L172",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.7/includes/class-feed-old.php#L45",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.7/includes/class-feed-shortcode.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&new=3610853%40widget-google-reviews%2Ftrunk&old=3606801%40widget-google-reviews%2Ftrunk",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 438,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15746",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:55:13.322Z",
      "date_published": "2026-07-15T18:35:47.382Z",
      "date_updated": "2026-07-15T18:54:31.562Z",
      "publisher": "AMZN",
      "title": "Credential disclosure in Strands Agents Tools elasticsearch_memory tool",
      "affected": {
        "vendors": [
          "Amazon"
        ],
        "products": [
          {
            "vendor": "Amazon",
            "product": "strands-agents-tools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15649
      },
      "nvd": {
        "published": "2026-07-15T19:16:57.773",
        "lastModified": "2026-07-15T19:50:36.327",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15746",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Elasticsearch memory tool sends an environment API key to a model-selected server when the caller omits an explicit key.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://pypi.org/project/strands-agents-tools/0.7.0/",
          "host": "pypi.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-056-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/strands-agents/tools/security/advisories/GHSA-ppcf-fpr3-x46v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1047,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T15:03:43.632Z",
      "date_published": "2026-07-14T17:07:32.593Z",
      "date_updated": "2026-07-15T16:32:58.629Z",
      "publisher": "CPANSec",
      "title": "Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle",
      "affected": {
        "vendors": [
          "SRI"
        ],
        "products": [
          {
            "vendor": "SRI",
            "product": "Mojolicious"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-204",
          "name": "Observable Response Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17023
      },
      "nvd": {
        "published": "2026-07-14T18:17:12.587",
        "lastModified": "2026-07-15T20:08:42.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15747",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Mojolicious caches one CSRF token for the session, giving a compression oracle a stable secret representation across responses.",
        "basis": [
          "CNA",
          "CWE-204",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mojolicious/mojo/commit/01921fbbbbeca2d1397e082d4a647f9b84c24e27.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/release/SRI/Mojolicious-9.48/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/14/16",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 564,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15749",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T15:39:43.344Z",
      "date_published": "2026-07-14T21:00:10.293Z",
      "date_updated": "2026-07-15T14:28:46.069Z",
      "publisher": "VulDB",
      "title": "mastergo-design mastergo-magic-mcp mcp__C2d get-c2d.ts execute path traversal",
      "affected": {
        "vendors": [
          "mastergo-design"
        ],
        "products": [
          {
            "vendor": "mastergo-design",
            "product": "mastergo-magic-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03769
      },
      "nvd": {
        "published": "2026-07-14T21:16:41.563",
        "lastModified": "2026-07-15T15:16:30.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15749",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Performing a manipulation of the argument filePath results in path traversal.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378328",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378328/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15749",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856632",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mastergo-design/mastergo-magic-mcp/issues/88",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mastergo-design/mastergo-magic-mcp/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15750",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T15:39:47.644Z",
      "date_published": "2026-07-14T21:30:08.566Z",
      "date_updated": "2026-07-15T12:44:54.296Z",
      "publisher": "VulDB",
      "title": "mastergo-design mastergo-magic-mcp mcp__getComponentLink get-component-link.ts z.string server-side request forgery",
      "affected": {
        "vendors": [
          "mastergo-design"
        ],
        "products": [
          {
            "vendor": "mastergo-design",
            "product": "mastergo-magic-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 5.4,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13506
      },
      "nvd": {
        "published": "2026-07-14T22:16:52.330",
        "lastModified": "2026-07-15T13:17:03.300",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15750",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The mcp__getComponentLink tool accepts an attacker-controlled URL and makes the corresponding server-side request.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378329",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378329/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15750",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856633",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mastergo-design/mastergo-magic-mcp/issues/89",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mastergo-design/mastergo-magic-mcp/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 504,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15751",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T15:39:51.050Z",
      "date_published": "2026-07-14T22:00:10.375Z",
      "date_updated": "2026-07-15T14:55:35.799Z",
      "publisher": "VulDB",
      "title": "mastergo-design mastergo-magic-mcp mcp__getComponentGenerator component-workflow.md execute path traversal",
      "affected": {
        "vendors": [
          "mastergo-design"
        ],
        "products": [
          {
            "vendor": "mastergo-design",
            "product": "mastergo-magic-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03805
      },
      "nvd": {
        "published": "2026-07-14T23:17:29.227",
        "lastModified": "2026-07-15T16:16:44.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15751",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378330",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378330/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15751",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856634",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mastergo-design/mastergo-magic-mcp/issues/90",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mastergo-design/mastergo-magic-mcp/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15752",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T15:51:25.852Z",
      "date_published": "2026-07-14T22:15:12.207Z",
      "date_updated": "2026-07-15T12:40:30.487Z",
      "publisher": "VulDB",
      "title": "zhinianboke xianyu-auto-reply Backend User Endpoint users authorization",
      "affected": {
        "vendors": [
          "zhinianboke"
        ],
        "products": [
          {
            "vendor": "zhinianboke",
            "product": "xianyu-auto-reply"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00297,
        "percentile": 0.21971
      },
      "nvd": {
        "published": "2026-07-14T23:17:29.390",
        "lastModified": "2026-07-15T13:17:03.500",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15752",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378334",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378334/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15752",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856716",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zhinianboke/xianyu-auto-reply/issues/192",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zhinianboke/xianyu-auto-reply/commit/19fc3282a1bb78a05c34945c088525d20e081cbd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhinianboke/xianyu-auto-reply/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 644,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15753",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T15:51:28.328Z",
      "date_published": "2026-07-14T22:30:09.981Z",
      "date_updated": "2026-07-15T18:14:14.492Z",
      "publisher": "VulDB",
      "title": "zhinianboke xianyu-auto-reply review approve trusting http permission methods on the server side",
      "affected": {
        "vendors": [
          "zhinianboke"
        ],
        "products": [
          {
            "vendor": "zhinianboke",
            "product": "xianyu-auto-reply"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-650",
          "name": "Trusting HTTP Permission Methods on the Server Side",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00261,
        "percentile": 0.1781
      },
      "nvd": {
        "published": "2026-07-14T23:17:29.560",
        "lastModified": "2026-07-15T19:16:58.273",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15753",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-650"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/378335",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/378335/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15753",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856719",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zhinianboke/xianyu-auto-reply/issues/192",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zhinianboke/xianyu-auto-reply/commit/19fc3282a1bb78a05c34945c088525d20e081cbd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhinianboke/xianyu-auto-reply/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 504,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T16:14:55.906Z",
      "date_published": "2026-07-24T06:51:59.294Z",
      "date_updated": "2026-07-24T10:59:33.620Z",
      "publisher": "Wordfence",
      "title": "Open User Map <= 1.4.45 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "affected": {
        "vendors": [
          "100plugins"
        ],
        "products": [
          {
            "vendor": "100plugins",
            "product": "Open User Map – Interactive Leaflet Maps"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15326
      },
      "nvd": {
        "published": "2026-07-24T08:16:26.533",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15755",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Open User Map – Interactive Leaflet Maps page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2bcc2783-1c47-47e4-ba63-822012aba0a6?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/open-user-map/tags/1.4.45/templates/partial-map-render.php#L450",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/open-user-map/tags/1.4.45/templates/partial-map-init.php#L682",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/open-user-map/tags/1.4.45/inc/Pages/Frontend.php#L120",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/open-user-map/tags/1.4.45/inc/Base/BaseController.php#L1026",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/open-user-map/tags/1.4.40/templates/partial-map-render.php#L450",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/open-user-map/tags/1.4.40/templates/partial-map-init.php#L682",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/open-user-map/tags/1.4.40/inc/Pages/Frontend.php#L120",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/open-user-map/tags/1.4.40/inc/Base/BaseController.php#L1026",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3618639%40open-user-map&new=3618639%40open-user-map",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 627,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15757",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T16:28:54.296Z",
      "date_published": "2026-07-14T17:46:15.979Z",
      "date_updated": "2026-07-15T16:50:16.246Z",
      "publisher": "NETGEAR",
      "title": "Insufficient input validation vulnerability in NETGEAR DGND3700v1 modem router",
      "affected": {
        "vendors": [
          "NETGEAR"
        ],
        "products": [
          {
            "vendor": "NETGEAR",
            "product": "DGND3700v1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/V:D/RE:L/U:Amber"
        },
        {
          "source": "NVD:a2826606-91e7-4eb6-899e-8484bd4575d5",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10477
      },
      "nvd": {
        "published": "2026-07-14T18:17:12.707",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15757",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says local Wi-Fi input can cause unauthorized commands but does not reveal the parser, command boundary, or missing authorization check.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.netgear.com/support/product/dgnd3700v1",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory",
          "host": "kb.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15759",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T16:38:37.414Z",
      "date_published": "2026-07-17T03:43:42.185Z",
      "date_updated": "2026-07-17T14:53:44.373Z",
      "publisher": "Wordfence",
      "title": "ChatHelp <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes",
      "affected": {
        "vendors": [
          "themeatelier"
        ],
        "products": [
          {
            "vendor": "themeatelier",
            "product": "ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10168
      },
      "nvd": {
        "published": "2026-07-17T05:16:38.447",
        "lastModified": "2026-07-17T16:17:14.060",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15759",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Stored input is rendered without the browser-context separation required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c3ec4978-0d51-4ca1-b0cf-81aaa4d43f7b?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chat-help/tags/3.5.1/src/Frontend/Shortcode/CustomButtonsTemplates.php#L76",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chat-help/tags/3.5.1/src/Frontend/Shortcode/CustomButtonsTemplates.php#L66",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chat-help/tags/3.5.1/src/Frontend/Shortcode/CustomButtonsTemplates.php#L138",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chat-help/tags/3.5.1/src/Frontend/Shortcode/CustomShortcode.php#L38",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chat-help/tags/3.5.1/src/Includes/ChatHelp.php#L192",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3609732%40chat-help&new=3609732%40chat-help",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 494,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T17:40:45.437Z",
      "date_published": "2026-07-23T08:34:39.715Z",
      "date_updated": "2026-07-23T13:41:41.369Z",
      "publisher": "Wordfence",
      "title": "Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filter' Parameter",
      "affected": {
        "vendors": [
          "tickera"
        ],
        "products": [
          {
            "vendor": "tickera",
            "product": "Tickera – Sell Tickets & Manage Events"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18842
      },
      "nvd": {
        "published": "2026-07-23T10:16:51.067",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15761",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The tc_event_filter parameter reaches an SQL query without sufficient escaping or parameterization.",
        "basis": [
          "CNA record",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/786ef53a-0fcd-4226-b469-52b72cd6890c?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php#L219",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php#L223",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php#L215",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php#L193",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3618129%40tickera-event-ticketing-system&new=3618129%40tickera-event-ticketing-system",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 816,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:14.070Z",
      "date_published": "2026-07-14T20:09:50.258Z",
      "date_updated": "2026-07-15T04:01:01.061Z",
      "publisher": "Chrome",
      "title": "Use after free in Ozone in Google Chrome on Linux prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00483,
        "percentile": 0.3904
      },
      "nvd": {
        "published": "2026-07-14T21:16:41.713",
        "lastModified": "2026-07-15T17:52:02.543",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15764",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517100492",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:14.551Z",
      "date_published": "2026-07-14T20:09:50.731Z",
      "date_updated": "2026-07-15T04:01:02.696Z",
      "publisher": "Chrome",
      "title": "Use after free in Ozone in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00483,
        "percentile": 0.39039
      },
      "nvd": {
        "published": "2026-07-14T21:16:41.887",
        "lastModified": "2026-07-15T17:51:43.053",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15765",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome accesses an object after it has been freed while processing crafted content.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518007484",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15766",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:14.791Z",
      "date_published": "2026-07-14T20:09:51.248Z",
      "date_updated": "2026-07-14T20:49:32.012Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22595
      },
      "nvd": {
        "published": "2026-07-14T21:16:42.040",
        "lastModified": "2026-07-15T17:51:11.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15766",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Skia exposes bytes from an uninitialized value or buffer to a crafted page before the storage has been initialized.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514010477",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:15.057Z",
      "date_published": "2026-07-14T20:09:51.633Z",
      "date_updated": "2026-07-15T04:01:05.101Z",
      "publisher": "Chrome",
      "title": "Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27203
      },
      "nvd": {
        "published": "2026-07-14T21:16:42.187",
        "lastModified": "2026-07-15T17:49:36.437",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15767",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input exceeds a heap allocation because the write is not bounded to the allocated size.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514748734",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 212,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:15.317Z",
      "date_published": "2026-07-14T20:09:52.029Z",
      "date_updated": "2026-07-15T15:22:09.181Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12727
      },
      "nvd": {
        "published": "2026-07-14T21:16:42.333",
        "lastModified": "2026-07-15T17:49:24.167",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15768",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "HTML-in-Canvas fails to enforce an origin policy, but the public record does not identify the compared origin or missing enforcement branch.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517931625",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:15.640Z",
      "date_published": "2026-07-14T20:09:52.489Z",
      "date_updated": "2026-07-14T20:44:10.471Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.1429
      },
      "nvd": {
        "published": "2026-07-14T21:16:42.420",
        "lastModified": "2026-07-15T17:49:08.717",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15769",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record says Linux Toolkit Theming accepts untrusted renderer input before a sandbox escape but does not disclose the parsed object, invalid value, or dangerous operation.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519731111",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:15.993Z",
      "date_published": "2026-07-14T20:09:52.915Z",
      "date_updated": "2026-07-14T20:44:42.572Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22594
      },
      "nvd": {
        "published": "2026-07-14T21:16:42.563",
        "lastModified": "2026-07-15T17:48:57.103",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15770",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An uninitialized value in V8 is consumed in a way that can expose or corrupt memory state.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/524792614",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:16.324Z",
      "date_published": "2026-07-14T20:09:53.363Z",
      "date_updated": "2026-07-14T20:45:08.231Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20472
      },
      "nvd": {
        "published": "2026-07-14T21:16:42.710",
        "lastModified": "2026-07-15T17:43:58.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15771",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record reports that renderer-compromised input can disclose process memory but does not identify the parser, bounds error, initialization failure, or causal operation.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/525177160",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15772",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:16.575Z",
      "date_published": "2026-07-14T20:09:53.756Z",
      "date_updated": "2026-07-14T20:45:30.822Z",
      "publisher": "Chrome",
      "title": "Use after free in GPU in Google Chrome on Android prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12397
      },
      "nvd": {
        "published": "2026-07-14T21:16:42.860",
        "lastModified": "2026-07-15T17:43:18.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15772",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome's GPU component accesses an object after its lifetime has ended when handling crafted web content.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/525317502",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15773",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:16.814Z",
      "date_published": "2026-07-14T20:09:54.113Z",
      "date_updated": "2026-07-14T20:49:02.843Z",
      "publisher": "Chrome",
      "title": "Use after free in Core in Google Chrome on Windows prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21768
      },
      "nvd": {
        "published": "2026-07-14T21:16:43.007",
        "lastModified": "2026-07-15T17:42:57.213",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15773",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome identifies a use-after-free in Core that can cross the Windows sandbox boundary, while the restricted issue does not expose the freed object or lifetime transition.",
        "basis": [
          "CNA",
          "CWE-416",
          "Chrome 150 stable release"
        ],
        "deepDive": true,
        "notes": "Inspected https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html and attempted the linked https://issues.chromium.org/issues/527676561. Google confirms a use-after-free in Core, Chrome severity High, and the fixed 150.0.7871.124/.125 rollout, but the issue body remains unavailable and no object or lifetime transition is public. The shard maximum is an ADP CVSS 9.6; retain that attribution separately from Chrome severity."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/527676561",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15774",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:17.104Z",
      "date_published": "2026-07-14T20:09:54.494Z",
      "date_updated": "2026-07-14T20:48:32.738Z",
      "publisher": "Chrome",
      "title": "Use after free in Skia in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12396
      },
      "nvd": {
        "published": "2026-07-14T21:16:43.160",
        "lastModified": "2026-07-15T17:42:24.073",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15774",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Skia accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/530646115",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15775",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:17.351Z",
      "date_published": "2026-07-14T20:09:54.816Z",
      "date_updated": "2026-07-15T15:44:12.137Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12726
      },
      "nvd": {
        "published": "2026-07-14T21:16:43.307",
        "lastModified": "2026-07-15T17:40:22.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15775",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "V8 violates the same-origin boundary for crafted page content, but the public record does not identify the origin state or implementation check.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/531319201",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15776",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:17.797Z",
      "date_published": "2026-07-14T20:09:55.194Z",
      "date_updated": "2026-07-15T04:01:05.942Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27685
      },
      "nvd": {
        "published": "2026-07-14T21:16:43.393",
        "lastModified": "2026-07-15T17:39:16.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15776",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome accesses an object through an incompatible type, invalidating the layout or lifetime assumptions used by the access.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/532595489",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15777",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:18.056Z",
      "date_published": "2026-07-14T20:09:55.560Z",
      "date_updated": "2026-07-29T19:26:45.491Z",
      "publisher": "Chrome",
      "title": "Use after free in UI in Google Chrome on Linux prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17262
      },
      "nvd": {
        "published": "2026-07-14T21:16:43.537",
        "lastModified": "2026-07-29T20:17:01.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15777",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A reachable path retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/532929679",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15778",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:31:18.338Z",
      "date_published": "2026-07-14T20:09:55.948Z",
      "date_updated": "2026-07-15T15:20:03.789Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16744
      },
      "nvd": {
        "published": "2026-07-14T21:16:43.677",
        "lastModified": "2026-07-15T17:35:55.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15778",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome accepts untrusted Navigation input that bypasses a navigation restriction, but the public record does not identify the policy check or field involved.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513795122",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 260,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15779",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:33:36.712Z",
      "date_published": "2026-07-15T12:33:04.688Z",
      "date_updated": "2026-07-15T13:04:49.311Z",
      "publisher": "redhat",
      "title": "Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validation",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00104,
        "percentile": 0.01208
      },
      "nvd": {
        "published": "2026-07-15T13:17:03.650",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15779",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "pam_winbind applies chown to an account's configured home path without rejecting critical filesystem targets such as the root directory.",
        "basis": [
          "CNA",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15779",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499991",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.com/samba-team/samba/-/blob/samba-4.19.4/nsswitch/pam_winbind.c",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.com/samba-team/samba/-/blob/samba-4.23.5/nsswitch/pam_winbind.c#L1622",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.com/samba-team/samba/-/blob/samba-4.24.3/nsswitch/pam_winbind.c#L1590",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 723,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15782",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T18:56:43.945Z",
      "date_published": "2026-07-21T05:35:28.946Z",
      "date_updated": "2026-07-21T13:27:49.495Z",
      "publisher": "Wordfence",
      "title": "WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content",
      "affected": {
        "vendors": [
          "smub"
        ],
        "products": [
          {
            "vendor": "smub",
            "product": "WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.0802
      },
      "nvd": {
        "published": "2026-07-21T06:16:28.210",
        "lastModified": "2026-07-21T16:54:45.743",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15782",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WPForms places attacker-controlled OptinMonster integration data into a browser execution context without sufficient escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6d5264a1-dabf-4630-9871-ab6e14817768?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.2.1/assets/js/frontend/wpforms.min.js#L5",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.0.4/assets/js/frontend/wpforms.min.js#L5",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3610719/wpforms-lite/trunk/assets/js/frontend/wpforms.min.js?old=3586095&old_path=wpforms-lite%2Ftrunk%2Fassets%2Fjs%2Ffrontend%2Fwpforms.min.js",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 789,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15783",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T19:06:07.523Z",
      "date_published": "2026-07-17T15:20:23.081Z",
      "date_updated": "2026-07-17T16:55:53.667Z",
      "publisher": "GitHub_P",
      "title": "Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites",
      "affected": {
        "vendors": [
          "GitHub"
        ],
        "products": [
          {
            "vendor": "GitHub",
            "product": "Enterprise Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:product-cna@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.1946
      },
      "nvd": {
        "published": "2026-07-17T16:17:14.183",
        "lastModified": "2026-07-17T18:11:59.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15783",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The delegated-bypass endpoint resolves a sequential rule-suite identifier without verifying that the caller can read the repository that owns it.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.18",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.12",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.9",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.5",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.3",
          "host": "docs.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 848,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-15786",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T19:18:05.209Z",
      "date_published": "2026-07-23T09:33:57.567Z",
      "date_updated": "2026-07-24T22:39:47.800Z",
      "publisher": "Wordfence",
      "title": "WP Encryption <= 7.8.6.6 - Authenticated (Administrator+) Arbitrary File Write via 'imploded' Parameter",
      "affected": {
        "vendors": [
          "gowebsmarty"
        ],
        "products": [
          {
            "vendor": "gowebsmarty",
            "product": "WP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Primary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33681
      },
      "nvd": {
        "published": "2026-07-23T10:16:51.207",
        "lastModified": "2026-07-24T23:16:50.087",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15786",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected product file operation accepts an attacker-controlled path that escapes the intended directory or storage target.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3ee86d33-5a1e-4dc5-b2f6-0beffd8a6b2e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-letsencrypt-ssl/tags/7.8.6.6/admin/le_admin.php#L2138",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-letsencrypt-ssl/tags/7.8.6.6/admin/le_admin.php#L2120",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wp-letsencrypt-ssl/tags/7.8.6.6/admin/le_admin.php#L150",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3617401%40wp-letsencrypt-ssl&new=3617401%40wp-letsencrypt-ssl",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 766,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15787",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T19:24:21.378Z",
      "date_published": "2026-07-22T08:33:30.358Z",
      "date_updated": "2026-07-22T18:48:34.168Z",
      "publisher": "Wordfence",
      "title": "Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes",
      "affected": {
        "vendors": [
          "brainstormforce"
        ],
        "products": [
          {
            "vendor": "brainstormforce",
            "product": "Ultimate Addons for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15325
      },
      "nvd": {
        "published": "2026-07-22T09:16:27.847",
        "lastModified": "2026-07-22T19:16:55.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15787",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Entity-encoded data attributes survive save-time filtering and are later decoded and inserted as HTML by jQuery.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/39f26d35-a702-49fc-aed1-0a329ac32553?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.8.8/inc/js/frontend.js#L682",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.8.8/inc/js/frontend.js#L701",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.9.1/inc/js/frontend.js#L684",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.9.1/inc/js/frontend.js#L703",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.9.1/inc/js/frontend.js#L682",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.9.1/inc/js/frontend.js#L701",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.8.8/inc/js/frontend.js#L684",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/2.8.8/inc/js/frontend.js#L703",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3614409/header-footer-elementor/trunk/inc/js/frontend.js",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fheader-footer-elementor/tags/2.9.1&new_path=%2Fheader-footer-elementor/tags/2.9.2",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 735,
        "referenceCount": 11,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15788",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T19:25:38.521Z",
      "date_published": "2026-07-20T19:12:56.386Z",
      "date_updated": "2026-07-21T12:40:56.055Z",
      "publisher": "Docker",
      "title": "WCOW cache mount source selector resolves NTFS junctions outside of cache root",
      "affected": {
        "vendors": [
          "moby"
        ],
        "products": [
          {
            "vendor": "moby",
            "product": "BuildKit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@docker.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04264
      },
      "nvd": {
        "published": "2026-07-20T20:16:43.223",
        "lastModified": "2026-07-21T13:17:02.663",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15788",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows cache selector follows an NTFS junction inside the cache root to host files outside that root.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/moby/buildkit/security/advisories/GHSA-388v-wmr2-g2v2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15789",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T19:27:01.532Z",
      "date_published": "2026-07-21T16:10:20.421Z",
      "date_updated": "2026-07-21T17:13:36.248Z",
      "publisher": "Docker",
      "title": "Malicious client can bypass destination directory validation on local sources upload",
      "affected": {
        "vendors": [
          "moby"
        ],
        "products": [
          {
            "vendor": "moby",
            "product": "BuildKit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@docker.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23805
      },
      "nvd": {
        "published": "2026-07-21T17:17:04.843",
        "lastModified": "2026-07-30T16:04:30.107",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15789",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BuildKit allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/moby/buildkit/security/advisories/GHSA-g2h8-426c-7976",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 270,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15791",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T19:30:08.561Z",
      "date_published": "2026-07-21T16:10:20.881Z",
      "date_updated": "2026-07-21T17:08:54.555Z",
      "publisher": "Docker",
      "title": "LLB file operation can be tricked to remove /tmp directory contents",
      "affected": {
        "vendors": [
          "moby"
        ],
        "products": [
          {
            "vendor": "moby",
            "product": "BuildKit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@docker.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.8,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 5.7,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16242
      },
      "nvd": {
        "published": "2026-07-21T17:17:04.963",
        "lastModified": "2026-07-30T15:59:22.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15791",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BuildKit accepts traversal-bearing low-level build paths and applies a container-root deletion operation to the host temporary directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/moby/buildkit/security/advisories/GHSA-32pv-7hq5-qhwq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15792",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T19:31:00.046Z",
      "date_published": "2026-07-21T16:10:21.395Z",
      "date_updated": "2026-07-21T17:01:55.840Z",
      "publisher": "Docker",
      "title": "Possible panic when incorrect parameters sent from frontend",
      "affected": {
        "vendors": [
          "moby"
        ],
        "products": [
          {
            "vendor": "moby",
            "product": "BuildKit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@docker.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15504
      },
      "nvd": {
        "published": "2026-07-21T17:17:05.093",
        "lastModified": "2026-07-30T15:52:15.977",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15792",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record says malformed frontend parameters can panic BuildKit but does not identify the parser, invalid state, or unchecked value that causes the panic.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/moby/buildkit/security/advisories/GHSA-qx3x-mv6r-52p6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T19:31:45.116Z",
      "date_published": "2026-07-21T16:10:21.790Z",
      "date_updated": "2026-07-21T16:58:40.200Z",
      "publisher": "Docker",
      "title": "Git source checkout from a bundle file could lead to command injection",
      "affected": {
        "vendors": [
          "moby"
        ],
        "products": [
          {
            "vendor": "moby",
            "product": "BuildKit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@docker.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10319
      },
      "nvd": {
        "published": "2026-07-21T17:17:05.220",
        "lastModified": "2026-07-30T15:33:48.303",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15793",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BuildKit places values derived from a malicious Git bundle into a host command invocation without preserving argument boundaries.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/moby/buildkit/security/advisories/GHSA-hw3h-2gp9-cxpv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15794",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T19:36:34.008Z",
      "date_published": "2026-07-23T08:34:41.556Z",
      "date_updated": "2026-07-23T13:47:16.110Z",
      "publisher": "Wordfence",
      "title": "Grid/List View for WooCommerce <= 3.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'position' Shortcode Attribute",
      "affected": {
        "vendors": [
          "berocket"
        ],
        "products": [
          {
            "vendor": "berocket",
            "product": "Grid/List View for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09237
      },
      "nvd": {
        "published": "2026-07-23T10:16:51.333",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15794",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The position shortcode attribute is stored and emitted into page markup without sufficient sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c4498d0a-32f2-4747-88bd-0f85312b4653?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gridlist-view-for-woocommerce/trunk/templates/list-grid.php#L14",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gridlist-view-for-woocommerce/trunk/includes/widget.php#L22",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gridlist-view-for-woocommerce/trunk/main.php#L171",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3611837%40gridlist-view-for-woocommerce&new=3611837%40gridlist-view-for-woocommerce",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T06:42:29.600Z",
      "date_published": "2026-07-22T03:44:59.368Z",
      "date_updated": "2026-07-22T13:02:39.261Z",
      "publisher": "Wordfence",
      "title": "WP Foodbakery <= 4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX Action",
      "affected": {
        "vendors": [
          "Chimpstudio"
        ],
        "products": [
          {
            "vendor": "Chimpstudio",
            "product": "WP Foodbakery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00516,
        "percentile": 0.41093
      },
      "nvd": {
        "published": "2026-07-22T05:17:08.820",
        "lastModified": "2026-07-22T16:30:26.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15802",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WP Foodbakery accepts an unconstrained backup-file path and deletes the selected filesystem object outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/45c8d883-1f97-4c9d-b406-c61e33a0959e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://themeforest.net/item/food-bakery-restaurant-bakery-responsive-wordpress-theme/18970331",
          "host": "themeforest.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T07:14:34.932Z",
      "date_published": "2026-07-15T07:31:32.752Z",
      "date_updated": "2026-07-15T12:33:12.244Z",
      "publisher": "twcert",
      "title": "MetaGuru｜HCM - SQL Injection",
      "affected": {
        "vendors": [
          "MetaGuru"
        ],
        "products": [
          {
            "vendor": "MetaGuru",
            "product": "HCM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00308,
        "percentile": 0.23163
      },
      "nvd": {
        "published": "2026-07-15T08:16:23.100",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15804",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HCM developed by MetaGuru has a SQL Injection vulnerability.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.twcert.org.tw/tw/cp-132-11035-5c640-1.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.twcert.org.tw/en/cp-139-11036-986ec-2.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15809",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T09:57:48.452Z",
      "date_published": "2026-07-15T12:32:42.587Z",
      "date_updated": "2026-07-17T08:50:58.115Z",
      "publisher": "redhat",
      "title": "Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Confidential Compute Attestation"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-134",
          "name": "Use of Externally-Controlled Format String",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.0269
      },
      "nvd": {
        "published": "2026-07-15T13:17:03.933",
        "lastModified": "2026-07-16T07:16:47.750",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15809",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CRI-O accepts a newline in the container HOME value and writes the resulting attacker-controlled line into /etc/passwd.",
        "basis": [
          "CNA",
          "CWE-116",
          "CWE-134"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15809",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500846",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/cri-o/cri-o/pull/6450",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cri-o/cri-o/pull/6524",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 376,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15810",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T10:03:09.218Z",
      "date_published": "2026-07-24T11:04:59.022Z",
      "date_updated": "2026-07-24T12:35:11.062Z",
      "publisher": "GoogleCloud",
      "title": "Cross-Site Scripting (XSS) in Looker allows Admin Account Takeover",
      "affected": {
        "vendors": [
          "Google Cloud"
        ],
        "products": [
          {
            "vendor": "Google Cloud",
            "product": "Looker"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Amber"
        },
        {
          "source": "NVD:f45cbf4e-4146-4068-b7e1-655ffc2c548c",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.1875
      },
      "nvd": {
        "published": "2026-07-24T12:16:47.543",
        "lastModified": "2026-07-27T20:37:16.927",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15810",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.cloud.google.com/support/bulletins#gcp-2026-049",
          "host": "docs.cloud.google.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://docs.cloud.google.com/looker/docs/release-notes#July_22_2026",
          "host": "docs.cloud.google.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 637,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-15811",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T10:18:11.691Z",
      "date_published": "2026-07-21T05:09:48.840Z",
      "date_updated": "2026-07-23T14:31:34.210Z",
      "publisher": "redhat",
      "title": "Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-212",
          "name": "Improper Removal of Sensitive Information Before Storage or Transfer",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00062,
        "percentile": 0.00015
      },
      "nvd": {
        "published": "2026-07-21T06:16:28.343",
        "lastModified": "2026-07-23T15:16:58.347",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15811",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kronosnet frees cryptographic configuration structures without wiping the raw encryption keys they contain.",
        "basis": [
          "CNA",
          "CWE-212"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15811",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500849",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 606,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T10:39:01.541Z",
      "date_published": "2026-07-21T05:09:48.164Z",
      "date_updated": "2026-07-22T14:20:07.617Z",
      "publisher": "redhat",
      "title": "Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dynamic links",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06137
      },
      "nvd": {
        "published": "2026-07-21T06:16:28.480",
        "lastModified": "2026-07-22T15:16:52.630",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15812",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The service trusts attacker-controlled identity or network-origin data without authenticating its asserted source.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15812",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500851",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 689,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15813",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T10:53:01.091Z",
      "date_published": "2026-07-20T10:36:03.641Z",
      "date_updated": "2026-07-20T12:08:19.314Z",
      "publisher": "redhat",
      "title": "Kronosnet: kronosnet: memory corruption and out-of-bounds access via malformed network packet defragmentation",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18865
      },
      "nvd": {
        "published": "2026-07-20T12:17:55.377",
        "lastModified": "2026-07-21T18:31:51.680",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15813",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "kronosnet accepts fragment sequence values that drive reassembly outside its internal bounds and can corrupt the heap.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15813",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500854",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 619,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T13:16:32.513Z",
      "date_published": "2026-07-24T07:53:35.538Z",
      "date_updated": "2026-07-25T00:51:25.016Z",
      "publisher": "Wordfence",
      "title": "SureDash <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "affected": {
        "vendors": [
          "brainstormforce"
        ],
        "products": [
          {
            "vendor": "brainstormforce",
            "product": "SureDash – Community, Courses & Member Dashboard"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10169
      },
      "nvd": {
        "published": "2026-07-24T09:16:24.387",
        "lastModified": "2026-07-25T01:16:25.903",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15821",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Shortcode attributes are rendered without sufficient sanitization or output escaping and later execute as browser script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/260c8ee3-dac5-4ad7-ba77-2312160e9348?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/suredash/tags/1.10.0/core/shortcodes/user-profile.php#L111",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/suredash/tags/1.10.0/core/shortcodes/user-profile.php#L85",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/suredash/tags/1.10.0/core/shortcodes/user-profile.php#L64",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/suredash/tags/1.10.0/core/blocks/interactivity/build/Profile/view.php#L23",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3614211%40suredash&new=3614211%40suredash",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15827",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T14:14:31.883Z",
      "date_published": "2026-07-23T08:34:39.337Z",
      "date_updated": "2026-07-23T13:53:00.860Z",
      "publisher": "Wordfence",
      "title": "GutenKit <= 2.4.12 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Mailchimp REST Endpoints",
      "affected": {
        "vendors": [
          "ataurr"
        ],
        "products": [
          {
            "vendor": "ataurr",
            "product": "GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23417
      },
      "nvd": {
        "published": "2026-07-23T10:16:51.467",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15827",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A REST permission callback always permits the request and the route enforces no login, nonce, or capability.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7430594c-3a71-4b24-875b-014e03be868f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.11/includes/Routes/MailChimp.php#L141",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.11/includes/Routes/MailChimp.php#L62",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.11/includes/Routes/MailChimp.php#L17",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.11/includes/Routes/MailChimp.php#L43",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.6/includes/Routes/MailChimp.php#L141",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.6/includes/Routes/MailChimp.php#L62",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.6/includes/Routes/MailChimp.php#L17",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.6/includes/Routes/MailChimp.php#L43",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3618270%40gutenkit-blocks-addon&new=3618270%40gutenkit-blocks-addon",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 814,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15829",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:00:56.723Z",
      "date_published": "2026-07-21T16:39:54.968Z",
      "date_updated": "2026-07-22T18:49:05.965Z",
      "publisher": "Google",
      "title": "SQL Injection and Security Boundary Bypass in googleapis/mcp-toolbox",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "MCP Toolbox for Databases (googleapis/mcp-toolbox)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-coordination@google.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07231
      },
      "nvd": {
        "published": "2026-07-21T17:17:05.350",
        "lastModified": "2026-07-22T19:16:55.480",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15829",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Forecast column parameters are interpolated into generated BigQuery SQL and the assembled query is executed without revalidation.",
        "basis": [
          "CNA record",
          "CWE-89",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/googleapis/mcp-toolbox/pull/3324",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 859,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15831",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:06:56.139Z",
      "date_published": "2026-07-29T19:00:01.048Z",
      "date_updated": "2026-07-29T19:32:52.354Z",
      "publisher": "GitLab",
      "title": "Generation of Incorrect Security Tokens in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1270",
          "name": "Generation of Incorrect Security Tokens",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12772
      },
      "nvd": {
        "published": "2026-07-29T20:17:01.983",
        "lastModified": "2026-08-03T12:59:58.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15831",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GitLab generates a security token without enforcing the authorization policy that token is expected to carry.",
        "basis": [
          "CNA",
          "CWE-1270"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/605484",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15895",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T17:56:36.976Z",
      "date_published": "2026-07-15T19:05:30.204Z",
      "date_updated": "2026-07-15T19:21:30.087Z",
      "publisher": "AMZN",
      "title": "OS command injection in jsii-diff in AWS jsii",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "jsii"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.0063,
        "percentile": 0.46734
      },
      "nvd": {
        "published": "2026-07-15T19:16:58.693",
        "lastModified": "2026-07-15T20:16:56.200",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15895",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "jsii-diff places crafted npm specifier text into a shell command without neutralizing command metacharacters.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aws/jsii/releases/tag/v1.131.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-057-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15899",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:40:19.018Z",
      "date_published": "2026-07-20T22:31:22.008Z",
      "date_updated": "2026-07-22T15:48:00.079Z",
      "publisher": "Chrome",
      "title": "Use after free in CameraCapture in Google Chrome on Mac prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14726
      },
      "nvd": {
        "published": "2026-07-20T23:16:55.637",
        "lastModified": "2026-07-27T12:58:16.657",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15899",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Chrome, a path retains or reuses an object after the lifetime transition that frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516987782",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:40:19.378Z",
      "date_published": "2026-07-20T22:31:22.573Z",
      "date_updated": "2026-07-22T15:47:50.433Z",
      "publisher": "Chrome",
      "title": "Use after free in GPU in Google Chrome on Android prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14725
      },
      "nvd": {
        "published": "2026-07-20T23:16:55.763",
        "lastModified": "2026-07-24T15:08:37.260",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15900",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path can retain or dereference an object after its storage has been released, leaving a dangling reference.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523750584",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15901",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:40:19.619Z",
      "date_published": "2026-07-20T22:31:23.245Z",
      "date_updated": "2026-07-22T15:47:39.718Z",
      "publisher": "Chrome",
      "title": "Use after free in Network in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17936
      },
      "nvd": {
        "published": "2026-07-20T23:16:55.877",
        "lastModified": "2026-07-24T15:08:22.467",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15901",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome Network component accesses a freed heap object while processing a crafted page.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/533446300",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15902",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:40:19.917Z",
      "date_published": "2026-07-20T22:31:23.663Z",
      "date_updated": "2026-07-24T12:48:09.182Z",
      "publisher": "Chrome",
      "title": "Use after free in Cast in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20555
      },
      "nvd": {
        "published": "2026-07-20T23:16:55.983",
        "lastModified": "2026-07-24T14:37:29.047",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15902",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path retains or dereferences an object after its storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522436154",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15903",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:40:20.217Z",
      "date_published": "2026-07-20T22:31:24.197Z",
      "date_updated": "2026-07-24T12:34:43.757Z",
      "publisher": "Chrome",
      "title": "Out of bounds read and write in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23833
      },
      "nvd": {
        "published": "2026-07-20T23:16:56.093",
        "lastModified": "2026-07-24T14:37:00.617",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15903",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A V8 bounds error permits reads and writes outside the intended memory region.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/531503216",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15904",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:40:20.475Z",
      "date_published": "2026-07-20T22:31:24.651Z",
      "date_updated": "2026-07-22T15:47:15.083Z",
      "publisher": "Chrome",
      "title": "Use after free in Ozone in Google Chrome on Linux prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14726
      },
      "nvd": {
        "published": "2026-07-20T23:16:56.190",
        "lastModified": "2026-07-24T15:07:48.997",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15904",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path retains or dereferences an object after the object's storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/532925350",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15905",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:40:20.911Z",
      "date_published": "2026-07-20T22:31:25.566Z",
      "date_updated": "2026-07-21T13:03:00.211Z",
      "publisher": "Chrome",
      "title": "Use after free in Aura in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00109,
        "percentile": 0.0143
      },
      "nvd": {
        "published": "2026-07-20T23:16:56.300",
        "lastModified": "2026-07-24T15:08:48.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15905",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome's Aura component accesses an object after its lifetime has ended while processing a malicious file.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/532970574",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 184,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15906",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:47:23.077Z",
      "date_published": "2026-07-23T08:34:40.801Z",
      "date_updated": "2026-07-23T13:54:59.218Z",
      "publisher": "Wordfence",
      "title": "Premium Packages <= 7.0.4 - Authenticated (Admin+) SQL Injection via 'orderby' Parameter",
      "affected": {
        "vendors": [
          "codename065"
        ],
        "products": [
          {
            "vendor": "codename065",
            "product": "Premium Packages – Sell Digital Products Securely"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20368
      },
      "nvd": {
        "published": "2026-07-23T10:16:51.597",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15906",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9bc6d516-7636-45b2-ade1-c8f2297f0ea1?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.0/src/Admin/Order/views/list-order-renews.php#L53",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.3/src/Admin/Order/views/list-order-renews.php#L53",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.3/src/Admin/Order/views/list-order-renews.php#L51",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.3/src/Order/OrderService.php#L314",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.0/src/Admin/Order/views/list-order-renews.php#L51",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/tags/7.0.0/src/Order/OrderService.php#L314",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3611573%40wpdm-premium-packages&new=3611573%40wpdm-premium-packages",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 526,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15907",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T19:18:37.918Z",
      "date_published": "2026-07-15T23:45:33.344Z",
      "date_updated": "2026-07-16T15:11:57.389Z",
      "publisher": "VulDB",
      "title": "H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection",
      "affected": {
        "vendors": [
          "H3C"
        ],
        "products": [
          {
            "vendor": "H3C",
            "product": "SecPath F1000-C8300"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16886
      },
      "nvd": {
        "published": "2026-07-16T00:16:19.170",
        "lastModified": "2026-07-16T16:19:00.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15907",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The subject parameter reaches an H3C log query as SQL syntax instead of a bound value.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379367",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379367/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15907",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/835656",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/docx/WCbgdWyJKoibcZxdsuMcUGKSnpf?from=from_copylink",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15909",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T19:22:26.317Z",
      "date_published": "2026-07-16T00:15:07.201Z",
      "date_updated": "2026-07-16T12:50:50.392Z",
      "publisher": "VulDB",
      "title": "RafyMrX TOKO-ONLINE-ROTI add.php authorization",
      "affected": {
        "vendors": [
          "RafyMrX"
        ],
        "products": [
          {
            "vendor": "RafyMrX",
            "product": "TOKO-ONLINE-ROTI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11514
      },
      "nvd": {
        "published": "2026-07-16T01:16:29.883",
        "lastModified": "2026-07-16T14:16:49.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15909",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379368",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379368/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-15909",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/844299",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15921",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T20:49:26.387Z",
      "date_published": "2026-07-15T21:16:46.936Z",
      "date_updated": "2026-07-16T12:53:35.897Z",
      "publisher": "harborist",
      "title": "nvm path traversal via a malicious mirror's LTS codename writes outside the alias directory",
      "affected": {
        "vendors": [
          "nvm-sh"
        ],
        "products": [
          {
            "vendor": "nvm-sh",
            "product": "nvm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:7ffcee3d-2c14-4c3e-b844-86c6a321a158",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:7ffcee3d-2c14-4c3e-b844-86c6a321a158",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13218
      },
      "nvd": {
        "published": "2026-07-15T22:16:45.717",
        "lastModified": "2026-07-16T14:16:49.230",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15921",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled path data is compared or normalized in a form that does not prove the final filesystem target remains inside the permitted namespace.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nvm-sh/nvm/security/advisories/GHSA-4ghp-wxpw-rhpg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/nvm-sh/nvm/commit/9275c5badda1d9d0cdad6f34598a111033eadb42",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1158,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15925",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T05:18:59.070Z",
      "date_published": "2026-07-16T05:31:35.515Z",
      "date_updated": "2026-07-16T12:43:16.112Z",
      "publisher": "SNOWFLAKE",
      "title": "Improper TLS Hostname Verification in Snowflake Connector for Python",
      "affected": {
        "vendors": [
          "Snowflake"
        ],
        "products": [
          {
            "vendor": "Snowflake",
            "product": "Snowflake Connector for Python"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-297",
          "name": "Improper Validation of Certificate with Host Mismatch",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:412d305a-227d-44f9-a262-a31ba44f2aea",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.0743
      },
      "nvd": {
        "published": "2026-07-16T07:16:47.957",
        "lastModified": "2026-07-16T13:47:43.027",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15925",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HTTPS client validates that a certificate chains to a trusted CA but does not require its hostname to match the requested Snowflake endpoint.",
        "basis": [
          "CNA",
          "CWE-297"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/snowflakedb/snowflake-connector-python/releases/tag/v3.18.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/snowflakedb/snowflake-connector-python/releases/tag/v4.7.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1102,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15927",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T06:31:41.405Z",
      "date_published": "2026-07-21T04:45:27.751Z",
      "date_updated": "2026-07-21T14:55:42.159Z",
      "publisher": "redhat",
      "title": "Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "mirror registry for Red Hat OpenShift 2"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Quay 3"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14009
      },
      "nvd": {
        "published": "2026-07-21T06:16:28.603",
        "lastModified": "2026-07-21T18:31:51.680",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15927",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Repository-level mirror handlers accept external_reference without the destination validation used by organization-level handlers, allowing worker requests to internal addresses.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15927",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501256",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 541,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15928",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T07:05:00.749Z",
      "date_published": "2026-07-27T02:23:23.674Z",
      "date_updated": "2026-07-27T14:53:06.306Z",
      "publisher": "TML",
      "title": "XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.",
      "affected": {
        "vendors": [
          "XMLRPC-C"
        ],
        "products": [
          {
            "vendor": "XMLRPC-C",
            "product": "XMLRPC-C"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:vdp@themissinglink.com.au",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.1875
      },
      "nvd": {
        "published": "2026-07-27T03:16:18.830",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15928",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The XMLRPC-C error page reflects attacker-controlled error data into HTML without the required output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xmlrpc-c.sourceforge.io/",
          "host": "xmlrpc-c.sourceforge.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.themissinglink.com.au/security-advisories/cve-2026-15928",
          "host": "www.themissinglink.com.au",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15929",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T07:14:00.895Z",
      "date_published": "2026-07-30T01:50:16.571Z",
      "date_updated": "2026-07-30T13:13:34.051Z",
      "publisher": "LGE",
      "title": "Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection.",
      "affected": {
        "vendors": [
          "LG Electronics"
        ],
        "products": [
          {
            "vendor": "LG Electronics",
            "product": "SmartShare"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:product.security@lge.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07142
      },
      "nvd": {
        "published": "2026-07-30T02:16:45.360",
        "lastModified": "2026-07-30T19:15:36.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15929",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SmartShare incorporates attacker-controlled input into an SQL command without neutralizing SQL syntax.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lgsecurity.lge.com/bulletins/pc#updateDetails",
          "host": "lgsecurity.lge.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 269,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15943",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T09:20:43.530Z",
      "date_published": "2026-07-17T11:49:49.874Z",
      "date_updated": "2026-07-17T14:53:16.118Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after token url change",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1288",
          "name": "Improper Validation of Consistency within Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10982
      },
      "nvd": {
        "published": "2026-07-17T12:17:03.313",
        "lastModified": "2026-07-17T18:08:08.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15943",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An identity-provider update reuses the stored client secret when the request contains the masked sentinel even after the token URL has changed to an attacker-controlled destination.",
        "basis": [
          "CNA",
          "CWE-1288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15943",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501270",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 438,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15945",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:26:48.913Z",
      "date_published": "2026-07-16T17:36:24.856Z",
      "date_updated": "2026-07-17T14:00:09.161Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09199
      },
      "nvd": {
        "published": "2026-07-16T18:16:42.693",
        "lastModified": "2026-07-17T18:08:08.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15945",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A role-member search checks access to the child group but returns details for a parent group the delegated administrator cannot view.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-15945",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501302",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 485,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-15957",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T13:52:17.532Z",
      "date_published": "2026-07-21T19:33:55.409Z",
      "date_updated": "2026-07-22T18:25:58.751Z",
      "publisher": "AMZN",
      "title": "Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "aws-sdk-rust"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34372
      },
      "nvd": {
        "published": "2026-07-21T20:16:58.780",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15957",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Generated deserializers recurse through attacker-controlled nesting without a depth limit and can exhaust the process stack.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/awslabs/aws-sdk-rust/releases/tag/release-2026-06-02",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-061-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/smithy-lang/smithy-rs/security/advisories/GHSA-4f2p-7j38-4xrg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 729,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15962",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T14:46:28.788Z",
      "date_published": "2026-07-26T01:28:39.517Z",
      "date_updated": "2026-07-27T20:23:52.496Z",
      "publisher": "Wordfence",
      "title": "Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field",
      "affected": {
        "vendors": [
          "techjewel"
        ],
        "products": [
          {
            "vendor": "techjewel",
            "product": "Fluent Forms Pro Add On Pack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30914
      },
      "nvd": {
        "published": "2026-07-26T02:16:28.790",
        "lastModified": "2026-07-27T21:16:48.080",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15962",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Fluent Forms Pro Add On Pack, attacker-controlled serialized data is deserialized into live objects during security-sensitive processing.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b95ec70c-ac76-48fa-9d9d-01cf1983e504?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://fluentforms.com",
          "host": "fluentforms.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 526,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15966",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T15:14:59.993Z",
      "date_published": "2026-07-23T19:58:01.659Z",
      "date_updated": "2026-07-25T03:55:21.850Z",
      "publisher": "ProgressSoftware",
      "title": "Improper CORS handling in MOVEit Transfer",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "MOVEit Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-942",
          "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 2.3000000000000007,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10548
      },
      "nvd": {
        "published": "2026-07-23T21:17:02.860",
        "lastModified": "2026-07-30T15:50:24.437",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15966",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MOVEit Transfer accepts untrusted origins in its cross-origin policy, allowing a hostile site to issue or read requests with browser-carried authority.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-942"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.0.3.html",
          "host": "docs.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15967",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T15:15:01.159Z",
      "date_published": "2026-07-23T19:59:33.949Z",
      "date_updated": "2026-07-25T03:55:22.642Z",
      "publisher": "ProgressSoftware",
      "title": "MOVEit Transfer refresh-token processing does not enforce updated account restrictions",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "MOVEit Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 2.3000000000000007,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10548
      },
      "nvd": {
        "published": "2026-07-23T21:17:02.977",
        "lastModified": "2026-07-30T15:50:12.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15967",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MOVEit accepts a refresh token without reapplying the account's current restrictions, preserving authority that should have expired after the account changed.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-613",
          "Vendor release note"
        ],
        "deepDive": true,
        "notes": "Inspected the official MOVEit Transfer 2026.0.3 release note at https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.0.3.html; row 105187 confirms that the repair re-enforces current account access policies during token refresh, while implementation source is not public."
      },
      "references": [
        {
          "url": "https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.0.3.html",
          "host": "docs.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 159,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15968",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T15:15:02.130Z",
      "date_published": "2026-07-23T20:01:13.408Z",
      "date_updated": "2026-07-24T13:32:48.089Z",
      "publisher": "ProgressSoftware",
      "title": "Stored XSS vulnerability in MOVEit Transfer",
      "affected": {
        "vendors": [
          "Progress"
        ],
        "products": [
          {
            "vendor": "Progress",
            "product": "MOVEit Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07892
      },
      "nvd": {
        "published": "2026-07-23T21:17:03.090",
        "lastModified": "2026-07-30T15:49:28.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15968",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MOVEit Transfer renders attacker-controlled content without the required HTML sanitization or output escaping, allowing cross-site scripting.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.0.3.html",
          "host": "docs.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 212,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-15969",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T15:25:47.694Z",
      "date_published": "2026-07-30T18:09:21.005Z",
      "date_updated": "2026-07-31T17:37:45.471Z",
      "publisher": "certcc",
      "title": "CVE-2026-15969",
      "affected": {
        "vendors": [
          "SGLang"
        ],
        "products": [
          {
            "vendor": "SGLang",
            "product": "SGLang"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00981,
        "percentile": 0.58821
      },
      "nvd": {
        "published": "2026-07-30T19:17:08.450",
        "lastModified": "2026-07-31T18:17:10.827",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15969",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SafeUnpickler relies on an incomplete deny-list and therefore deserializes a crafted pickle payload that invokes arbitrary commands.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sgl-project/sglang/security/advisories/GHSA-2wvm-gjg7-5jfm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://thoughts.apoorvdayal.com/posts/sglang-disclosures/",
          "host": "thoughts.apoorvdayal.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15971",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T15:32:19.244Z",
      "date_published": "2026-07-30T18:07:24.451Z",
      "date_updated": "2026-07-31T19:28:45.016Z",
      "publisher": "certcc",
      "title": "CVE-2026-15971",
      "affected": {
        "vendors": [
          "SGLang"
        ],
        "products": [
          {
            "vendor": "SGLang",
            "product": "SGLang"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-95",
          "name": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33164
      },
      "nvd": {
        "published": "2026-07-30T19:17:08.590",
        "lastModified": "2026-07-31T20:16:48.690",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15971",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The optional dumper accepts a remotely configured filter expression that its evaluation path passes to Python eval during inference.",
        "basis": [
          "CNA",
          "CWE-95",
          "SGLang source"
        ],
        "deepDive": true,
        "notes": "Read https://raw.githubusercontent.com/sgl-project/sglang/main/python/sglang/srt/debug_utils/dumper.py; the linked GHSA was unavailable, so no historical fix diff or runtime reproduction was verified."
      },
      "references": [
        {
          "url": "https://github.com/sgl-project/sglang/security/advisories/GHSA-h6rf-77vv-9mvj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://thoughts.apoorvdayal.com/posts/sglang-disclosures/",
          "host": "thoughts.apoorvdayal.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15974",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T15:35:55.270Z",
      "date_published": "2026-07-30T18:07:35.029Z",
      "date_updated": "2026-07-31T19:25:43.419Z",
      "publisher": "certcc",
      "title": "CVE-2026-15974",
      "affected": {
        "vendors": [
          "SGLang"
        ],
        "products": [
          {
            "vendor": "SGLang",
            "product": "SGLang"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.1113
      },
      "nvd": {
        "published": "2026-07-30T19:17:08.697",
        "lastModified": "2026-07-31T20:16:48.847",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15974",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SGLang fetches an unsanitized image_url, allowing the multimodal endpoint to request internal or local resources.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sgl-project/sglang/security/advisories/GHSA-x7w5-h7rp-gfp9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://thoughts.apoorvdayal.com/posts/sglang-disclosures/",
          "host": "thoughts.apoorvdayal.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15975",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T15:37:27.210Z",
      "date_published": "2026-07-29T18:59:56.043Z",
      "date_updated": "2026-07-29T19:32:20.549Z",
      "publisher": "GitLab",
      "title": "Allocation of Resources Without Limits or Throttling in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00394,
        "percentile": 0.32193
      },
      "nvd": {
        "published": "2026-07-29T20:17:02.117",
        "lastModified": "2026-08-03T14:28:00.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-15975",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/601420",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-15976",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T15:38:40.919Z",
      "date_published": "2026-07-30T18:07:44.256Z",
      "date_updated": "2026-07-31T19:11:57.388Z",
      "publisher": "certcc",
      "title": "CVE-2026-15976",
      "affected": {
        "vendors": [
          "SGLang"
        ],
        "products": [
          {
            "vendor": "SGLang",
            "product": "SGLang"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25767
      },
      "nvd": {
        "published": "2026-07-30T19:17:08.793",
        "lastModified": "2026-07-31T20:16:49.003",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15976",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sgl-project/sglang/security/advisories/GHSA-wf98-gv64-5wrf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://thoughts.apoorvdayal.com/posts/sglang-disclosures/",
          "host": "thoughts.apoorvdayal.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15977",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T15:40:45.979Z",
      "date_published": "2026-07-30T18:07:54.911Z",
      "date_updated": "2026-07-31T19:08:46.654Z",
      "publisher": "certcc",
      "title": "CVE-2026-15977",
      "affected": {
        "vendors": [
          "SGLang"
        ],
        "products": [
          {
            "vendor": "SGLang",
            "product": "SGLang"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15345
      },
      "nvd": {
        "published": "2026-07-30T19:17:08.893",
        "lastModified": "2026-07-31T20:16:49.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15977",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The server_info endpoint returns API keys and SSL key-file details when only the administrative API key is configured.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sgl-project/sglang/security/advisories/GHSA-jx7q-p32r-7wx8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://thoughts.apoorvdayal.com/posts/sglang-disclosures/",
          "host": "thoughts.apoorvdayal.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15978",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T15:41:50.504Z",
      "date_published": "2026-07-30T18:08:29.228Z",
      "date_updated": "2026-07-31T18:10:22.232Z",
      "publisher": "certcc",
      "title": "CVE-2026-15978",
      "affected": {
        "vendors": [
          "SGLang"
        ],
        "products": [
          {
            "vendor": "SGLang",
            "product": "SGLang"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21629
      },
      "nvd": {
        "published": "2026-07-30T19:17:08.993",
        "lastModified": "2026-07-31T19:17:03.897",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15978",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "With no API key configured, exposed weight-broadcast and transfer endpoints let a remote caller trigger export of model weights.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sgl-project/sglang/security/advisories/GHSA-cpqq-22v3-2wfm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://thoughts.apoorvdayal.com/posts/sglang-disclosures/",
          "host": "thoughts.apoorvdayal.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T16:55:30.527Z",
      "date_published": "2026-07-23T20:33:51.362Z",
      "date_updated": "2026-07-24T22:06:10.389Z",
      "publisher": "Wordfence",
      "title": "SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter",
      "affected": {
        "vendors": [
          "cyberlord92"
        ],
        "products": [
          {
            "vendor": "cyberlord92",
            "product": "SAML Single Sign On – SSO Login"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00547,
        "percentile": 0.42769
      },
      "nvd": {
        "published": "2026-07-23T21:17:03.220",
        "lastModified": "2026-07-24T23:16:50.257",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15981",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The signature validator treats OpenSSL's error return of -1 as truthy, so a malformed SAML signature is accepted as valid.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b412f60f-61ea-47b1-a3ef-17275f7951df?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-saml-20-single-sign-on/tags/5.4.4/class-mo-saml-login-validate.php#L118",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-saml-20-single-sign-on/tags/5.4.4/class-mo-saml-utilities.php#L403",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-saml-20-single-sign-on/tags/5.4.4/includes/lib/SAML2Core/class-mo-saml-xml-security-dsig.php#L938",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-saml-20-single-sign-on/tags/5.4.4/includes/lib/SAML2Core/class-mo-saml-xml-security-key.php#L621",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/miniorange-saml-20-single-sign-on/tags/5.4.4/class-mo-saml-login-validate.php#L541",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3611421/miniorange-saml-20-single-sign-on",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 816,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T17:05:25.189Z",
      "date_published": "2026-07-17T05:35:58.570Z",
      "date_updated": "2026-07-17T10:11:03.243Z",
      "publisher": "Wordfence",
      "title": "Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'",
      "affected": {
        "vendors": [
          "CodeRevolution"
        ],
        "products": [
          {
            "vendor": "CodeRevolution",
            "product": "Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26536
      },
      "nvd": {
        "published": "2026-07-17T06:16:36.560",
        "lastModified": "2026-07-17T14:59:38.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15982",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "aiomatic_call_google_ai_function lacks a capability check, allowing an anonymous caller to clear the function blacklist and invoke privileged PHP functions.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/53cc91fa-51fd-4d16-b740-a48f8d446b5d?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://coderevolution.ro/knowledge-base/faq/full-changelog-aiomatic-automatic-ai-content-writer-editor-gpt-3-gpt-4-chatgpt-chatbot-ai-toolkit/",
          "host": "coderevolution.ro",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15992",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T20:12:58.744Z",
      "date_published": "2026-07-28T18:35:51.190Z",
      "date_updated": "2026-07-29T14:01:03.473Z",
      "publisher": "Wordfence",
      "title": "WP Password Policy <= 3.7.1 - Authenticated (Subscriber+) Privilege Escalation",
      "affected": {
        "vendors": [
          "teydeastudio"
        ],
        "products": [
          {
            "vendor": "teydeastudio",
            "product": "WP Password Policy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.1957
      },
      "nvd": {
        "published": "2026-07-28T19:17:31.727",
        "lastModified": "2026-07-29T15:16:21.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15992",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The password-hint path applies an attacker-supplied role to a selected account without checking the caller's role-assignment capability.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4ad5ca1c-b8c3-42c0-8170-821ada826cbb?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/password-requirements/tags/3.7.1/src/modules/password-hint/class-module-password-hint.php#L39",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/password-requirements/tags/3.7.1/src/modules/password-hint/class-module-password-hint.php#L54",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 980,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15995",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T21:12:15.436Z",
      "date_published": "2026-07-17T19:34:52.644Z",
      "date_updated": "2026-07-20T13:28:31.747Z",
      "publisher": "ibm",
      "title": "IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant that may cause incorrect report summaries or report-processing errors under concurrent use",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Cognos Analytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02776
      },
      "nvd": {
        "published": "2026-07-17T20:17:16.047",
        "lastModified": "2026-07-20T17:15:53.673",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15995",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent requests share report-summary state and can mix one request's data into another response.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280311",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 351,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-15997",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T21:47:28.715Z",
      "date_published": "2026-07-16T22:17:16.525Z",
      "date_updated": "2026-07-17T13:12:39.282Z",
      "publisher": "bcorg",
      "title": "Native ARM SHA3 / SHAKE `restoreFullState`  fails to detect size_t underflow in a crafted encoded state",
      "affected": {
        "vendors": [
          "Legion of the Bouncy Castle Inc."
        ],
        "products": [
          {
            "vendor": "Legion of the Bouncy Castle Inc.",
            "product": "BC-LTS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 1.7,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/S:P/AU:N/R:A/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:91579145-5d7b-4cc5-b925-a0262ff19630",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.7,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:A/V:D/RE:M/U:Amber"
        }
      ],
      "max_cvss_observed_across_sources": 1.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.00984
      },
      "nvd": {
        "published": "2026-07-16T23:16:15.727",
        "lastModified": "2026-07-17T18:10:36.757",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-15997",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted serialized SHA3 or SHAKE state underflows a size_t calculation and drives an out-of-bounds write in the ARM native implementation.",
        "basis": [
          "CNA record",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bcgit/bc-lts-java/wiki/CVE-2026-15997",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 511,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16002",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T00:29:22.437Z",
      "date_published": "2026-07-23T20:57:11.463Z",
      "date_updated": "2026-07-24T13:36:36.942Z",
      "publisher": "icscert",
      "title": "Out-of-bounds Read in MZ Automation lib60870",
      "affected": {
        "vendors": [
          "MZ Automation"
        ],
        "products": [
          {
            "vendor": "MZ Automation",
            "product": "lib60870"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17338
      },
      "nvd": {
        "published": "2026-07-23T21:17:03.363",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16002",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "lib60870 reads beyond an allocated buffer because the input length or boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16008",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T05:15:27.899Z",
      "date_published": "2026-07-17T10:30:10.843Z",
      "date_updated": "2026-07-17T11:59:04.607Z",
      "publisher": "VulDB",
      "title": "sagold json-schema-library propertyDependencies.ts parsePropertyDependencies prototype pollution",
      "affected": {
        "vendors": [
          "sagold"
        ],
        "products": [
          {
            "vendor": "sagold",
            "product": "json-schema-library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17842
      },
      "nvd": {
        "published": "2026-07-17T11:17:13.080",
        "lastModified": "2026-07-17T14:59:38.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16008",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "parsePropertyDependencies applies attacker-controlled property names to shared object prototypes, enabling prototype pollution.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379752",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379752/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16008",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856721",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sagold/json-schema-library/issues/111",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sagold/json-schema-library/commit/432287ee6f68a02ce6f015354618486ec427a32d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/sagold/json-schema-library/releases/tag/v11.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/sagold/json-schema-library/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16009",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T05:16:37.710Z",
      "date_published": "2026-07-17T11:15:08.344Z",
      "date_updated": "2026-07-17T13:51:51.537Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System prescriptionorderdetail.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10076
      },
      "nvd": {
        "published": "2026-07-17T12:17:03.440",
        "lastModified": "2026-07-17T14:59:38.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16009",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Hospital Management System, attacker-controlled input reaches an SQL statement without the required parameter binding or SQL-context escaping.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379753",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379753/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16009",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856775",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/submit_vuln/issues/8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16013",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T05:34:00.739Z",
      "date_published": "2026-07-17T11:45:10.226Z",
      "date_updated": "2026-07-17T12:59:02.883Z",
      "publisher": "VulDB",
      "title": "liftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds",
      "affected": {
        "vendors": [
          "liftoff-sr"
        ],
        "products": [
          {
            "vendor": "liftoff-sr",
            "product": "CIPster"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.00428,
        "percentile": 0.35248
      },
      "nvd": {
        "published": "2026-07-17T12:17:03.620",
        "lastModified": "2026-07-17T14:59:38.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16013",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the end of an allocated buffer because the available length is not enforced.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379755",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379755/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16013",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856794",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/liftoff-sr/CIPster/issues/53",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/user-attachments/files/28926450/POC.zip",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/liftoff-sr/CIPster/commit/886a4d090e1c5b0475f0b1c2fe0606a8f0d6a519",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/liftoff-sr/CIPster/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 640,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T05:35:18.867Z",
      "date_published": "2026-07-17T12:45:14.471Z",
      "date_updated": "2026-07-21T01:36:31.542Z",
      "publisher": "VulDB",
      "title": "code-projects Hospital Bed Management System Login Form sql injection",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Hospital Bed Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18018
      },
      "nvd": {
        "published": "2026-07-17T13:17:57.983",
        "lastModified": "2026-07-21T03:16:40.587",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16014",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The login form incorporates the remote Username parameter into SQL without preserving the data-and-query boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379756",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379756/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16014",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856808",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gitee.com/Ajkss/cve/issues/IJU5GU",
          "host": "gitee.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 312,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16015",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T05:44:00.706Z",
      "date_published": "2026-07-17T13:15:12.605Z",
      "date_updated": "2026-07-17T18:05:31.368Z",
      "publisher": "VulDB",
      "title": "poco-ai poco-claw executor_manager API tasks.py create_task missing authentication",
      "affected": {
        "vendors": [
          "poco-ai"
        ],
        "products": [
          {
            "vendor": "poco-ai",
            "product": "poco-claw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:A/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:A/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 4.199999999999999,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31194
      },
      "nvd": {
        "published": "2026-07-17T14:17:21.517",
        "lastModified": "2026-07-17T19:17:12.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16015",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The poco-claw path exposes a privileged operation without first authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379757",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379757/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16015",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856812",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856813",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856815",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856816",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/poco-ai/poco-claw/issues/136",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/poco-ai/poco-claw/pull/135",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/poco-ai/poco-claw/issues/137",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/poco-ai/poco-claw/commit/67fcc88505c57f77d3fcf04eb5b89425b10cbf48",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "patch"
          ]
        },
        {
          "url": "https://github.com/poco-ai/poco-claw/releases/tag/0.5.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "patch"
          ]
        },
        {
          "url": "https://github.com/poco-ai/poco-claw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 13,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-16016",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T05:44:08.705Z",
      "date_published": "2026-07-17T13:30:10.299Z",
      "date_updated": "2026-07-17T14:51:53.546Z",
      "publisher": "VulDB",
      "title": "poco-ai poco-claw task.py run_task server-side request forgery",
      "affected": {
        "vendors": [
          "poco-ai"
        ],
        "products": [
          {
            "vendor": "poco-ai",
            "product": "poco-claw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21055
      },
      "nvd": {
        "published": "2026-07-17T14:17:21.697",
        "lastModified": "2026-07-17T16:17:14.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16016",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A server-side request destination is attacker-controlled and is not constrained to trusted network locations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379758",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379758/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16016",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856814",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/poco-ai/poco-claw/issues/138",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/poco-ai/poco-claw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 404,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16017",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T05:47:46.367Z",
      "date_published": "2026-07-17T14:15:07.811Z",
      "date_updated": "2026-07-17T17:27:24.361Z",
      "publisher": "VulDB",
      "title": "mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization",
      "affected": {
        "vendors": [
          "mosaxiv"
        ],
        "products": [
          {
            "vendor": "mosaxiv",
            "product": "clawlet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 11,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11244
      },
      "nvd": {
        "published": "2026-07-17T15:16:46.157",
        "lastModified": "2026-07-17T18:17:14.737",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16017",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The clawlet operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379759",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379759/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16017",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856824",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mosaxiv/clawlet/issues/17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mosaxiv/clawlet/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 401,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-16072",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:26:09.324Z",
      "date_published": "2026-07-17T13:40:01.921Z",
      "date_updated": "2026-07-21T16:52:16.803Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: organization invitation link exposure allows unauthorized member creation",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.1316
      },
      "nvd": {
        "published": "2026-07-17T14:17:21.860",
        "lastModified": "2026-07-21T17:17:05.480",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16072",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A delegated organization administrator can retrieve an invitation secret for a nonexistent email and create members without user-management permission.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16072",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501721",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16073",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:39:17.348Z",
      "date_published": "2026-07-17T18:15:07.652Z",
      "date_updated": "2026-07-22T15:38:08.117Z",
      "publisher": "VulDB",
      "title": "AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scripting",
      "affected": {
        "vendors": [
          "AstrBotDevs"
        ],
        "products": [
          {
            "vendor": "AstrBotDevs",
            "product": "AstrBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00191,
        "percentile": 0.08991
      },
      "nvd": {
        "published": "2026-07-17T19:17:13.103",
        "lastModified": "2026-07-22T16:17:11.100",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16073",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AstrBot Star.text_to_image and NetworkRenderStrategy.render place attacker-controlled T2I content into browser-executable markup without neutralizing script syntax.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379788",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379788/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16073",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852825",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/2abcecece4369c46cc8405e597c0528b",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 475,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16074",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:39:22.213Z",
      "date_published": "2026-07-17T20:15:09.598Z",
      "date_updated": "2026-07-20T17:57:32.069Z",
      "publisher": "VulDB",
      "title": "AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery",
      "affected": {
        "vendors": [
          "AstrBotDevs"
        ],
        "products": [
          {
            "vendor": "AstrBotDevs",
            "product": "AstrBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10229
      },
      "nvd": {
        "published": "2026-07-17T21:17:06.087",
        "lastModified": "2026-07-20T19:17:18.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16074",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AstrBot plugin update handlers fetch attacker-selected download_url, download_urls, or proxy destinations from the server.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379789",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379789/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16074",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852842",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/f84070f78d9c9c9407b0c396189cd716",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 486,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16075",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:39:26.049Z",
      "date_published": "2026-07-18T04:00:08.494Z",
      "date_updated": "2026-07-21T02:27:02.076Z",
      "publisher": "VulDB",
      "title": "AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization",
      "affected": {
        "vendors": [
          "AstrBotDevs"
        ],
        "products": [
          {
            "vendor": "AstrBotDevs",
            "product": "AstrBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12337
      },
      "nvd": {
        "published": "2026-07-18T05:16:52.490",
        "lastModified": "2026-07-21T04:16:49.437",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16075",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "get_chat_sessions trusts a caller-supplied Username when listing sessions instead of binding the requested account to the authenticated caller.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379790",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379790/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16075",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852863",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/5fee3adfd95333b0f4eff8165af61f81",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 474,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-16076",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:39:29.721Z",
      "date_published": "2026-07-18T05:30:08.451Z",
      "date_updated": "2026-07-20T19:10:52.910Z",
      "publisher": "VulDB",
      "title": "AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing",
      "affected": {
        "vendors": [
          "AstrBotDevs"
        ],
        "products": [
          {
            "vendor": "AstrBotDevs",
            "product": "AstrBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21374
      },
      "nvd": {
        "published": "2026-07-18T06:16:35.203",
        "lastModified": "2026-07-20T19:17:18.500",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16076",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "AstrBot accepts a caller-controlled username as proof of identity, allowing a remote caller to impersonate another account without validating an authentic credential.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379791",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379791/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16076",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852864",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/080ba55a71588dbbba3f27afed4c072c",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 473,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-16077",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:39:33.904Z",
      "date_published": "2026-07-18T06:45:07.835Z",
      "date_updated": "2026-07-20T15:17:34.665Z",
      "publisher": "VulDB",
      "title": "AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following",
      "affected": {
        "vendors": [
          "AstrBotDevs"
        ],
        "products": [
          {
            "vendor": "AstrBotDevs",
            "product": "AstrBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06402
      },
      "nvd": {
        "published": "2026-07-18T07:16:39.290",
        "lastModified": "2026-07-20T16:16:55.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16077",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The filesystem operation follows an attacker-controlled link instead of constraining the final object to the intended namespace.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379792",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379792/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16077",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852865",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gist.github.com/YLChen-007/d2581be79bb3caf9a032b0614dfc7728",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-16078",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:43:40.729Z",
      "date_published": "2026-07-23T08:34:38.449Z",
      "date_updated": "2026-07-23T14:54:49.593Z",
      "publisher": "Wordfence",
      "title": "WCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' Parameter",
      "affected": {
        "vendors": [
          "kilbot"
        ],
        "products": [
          {
            "vendor": "kilbot",
            "product": "WCPOS – Point of Sale (POS) plugin for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00613,
        "percentile": 0.45936
      },
      "nvd": {
        "published": "2026-07-23T10:16:51.727",
        "lastModified": "2026-07-23T16:17:14.723",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16078",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WCPOS – Point of Sale (POS) plugin for WooCommerce accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0148c70f-38e4-43d9-994e-f2b01dd168a1?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-pos/tags/1.9.7/includes/API/Templates_Controller.php#L446",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-pos/tags/1.9.7/includes/Templates.php#L481",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-pos/tags/1.9.7/includes/Templates.php#L445",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woocommerce-pos/tags/1.9.7/includes/API/Templates_Controller.php#L1497",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3612715%40woocommerce-pos&new=3612715%40woocommerce-pos",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 594,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:49:54.669Z",
      "date_published": "2026-07-18T07:45:09.658Z",
      "date_updated": "2026-07-20T13:43:04.743Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw auth.go cross-site request forgery",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06232
      },
      "nvd": {
        "published": "2026-07-18T08:16:35.130",
        "lastModified": "2026-07-20T15:16:35.003",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16081",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The auth.go handler accepts a state-changing browser request without a reliable cross-site request token or origin binding.",
        "basis": [
          "CNA",
          "CWE-352",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379793",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379793/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16081",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852943",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3072",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/pull/3160",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/commit/4b0229351678f479429b8d8b19207757266f246b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 420,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-16082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:49:58.787Z",
      "date_published": "2026-07-18T08:15:07.934Z",
      "date_updated": "2026-07-22T15:49:47.762Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw pipeline_execute.go ExecTool.executeRun toctou",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00091,
        "percentile": 0.00582
      },
      "nvd": {
        "published": "2026-07-18T09:17:07.783",
        "lastModified": "2026-07-22T16:17:11.257",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16082",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ExecTool validates an attacker-influenced target and later uses it after a window in which the selected object can change.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379794",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379794/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16082",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852944",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3081",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 418,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-16083",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:50:03.053Z",
      "date_published": "2026-07-18T08:30:09.134Z",
      "date_updated": "2026-07-20T17:36:15.416Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.0043,
        "percentile": 0.35406
      },
      "nvd": {
        "published": "2026-07-18T09:17:07.953",
        "lastModified": "2026-07-20T18:16:50.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16083",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The LINE webhook accepts a previously captured authenticated request again because it does not enforce freshness or one-time use.",
        "basis": [
          "CNA",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379795",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379795/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16083",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852945",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3073",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-16084",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:50:07.157Z",
      "date_published": "2026-07-18T09:00:10.981Z",
      "date_updated": "2026-07-21T02:28:05.666Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw web.go web_fetch server-side request forgery",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00401,
        "percentile": 0.32894
      },
      "nvd": {
        "published": "2026-07-18T09:17:08.113",
        "lastModified": "2026-07-21T04:16:49.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16084",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PicoClaw request path lets a caller choose a server-side destination outside the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379796",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379796/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16084",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852946",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3074",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/pull/3143",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/commit/c15aac21fe05ee103a470e1104bc891754e83392",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 432,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-16085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:50:10.945Z",
      "date_published": "2026-07-18T09:15:09.590Z",
      "date_updated": "2026-07-20T19:10:46.153Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw context.go NewContextBuilder inclusion of functionality from untrusted control sphere",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01632
      },
      "nvd": {
        "published": "2026-07-18T10:17:25.627",
        "lastModified": "2026-07-20T19:17:18.643",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16085",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NewContextBuilder includes functionality selected from an untrusted local control sphere without establishing trusted provenance.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379797",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379797/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16085",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852947",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3075",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-16088",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T13:54:58.288Z",
      "date_published": "2026-07-18T09:45:08.762Z",
      "date_updated": "2026-07-20T15:30:25.980Z",
      "publisher": "VulDB",
      "title": "halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversal",
      "affected": {
        "vendors": [
          "halo-dev"
        ],
        "products": [
          {
            "vendor": "halo-dev",
            "product": "halo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25489
      },
      "nvd": {
        "published": "2026-07-18T10:17:25.950",
        "lastModified": "2026-07-20T16:16:55.917",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16088",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file operation in halo uses an attacker-controlled path without confining the resolved object to the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379798",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379798/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16088",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/853097",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/halo-dev/halo/issues/10064",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/halo-dev/halo/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16089",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T14:00:35.799Z",
      "date_published": "2026-07-17T14:15:43.476Z",
      "date_updated": "2026-07-22T18:20:30.767Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: authorization codes can be retargeted to another client session",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-384",
          "name": "Session Fixation",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03933
      },
      "nvd": {
        "published": "2026-07-17T15:16:46.317",
        "lastModified": "2026-07-22T19:16:55.753",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16089",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Keycloak issues authorization codes without binding each code to the client that initiated the flow, allowing a valid code to be retargeted to another client.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-384"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16089",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501724",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 382,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16092",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T14:08:32.137Z",
      "date_published": "2026-07-30T03:03:21.282Z",
      "date_updated": "2026-07-30T13:58:36.670Z",
      "publisher": "Wordfence",
      "title": "Improved Save Button <= 1.2.1 - Authenticated (Author+) Second-Order SQL Injection via 'meta_key' Parameter",
      "affected": {
        "vendors": [
          "labelblanc"
        ],
        "products": [
          {
            "vendor": "labelblanc",
            "product": "Improved Save Button"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16262
      },
      "nvd": {
        "published": "2026-07-30T03:16:23.630",
        "lastModified": "2026-07-30T14:16:47.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16092",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improved Save Button incorporates meta_key into an SQL statement without parameterization, allowing input syntax to alter the database query.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a1dbc2ca-eb3f-4c0f-a5c0-28579f694237?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/improved-save-button/tags/1.2.1/actions/class-lb-save-and-then-action-duplicate.php#L179",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/improved-save-button/tags/1.2.1/actions/class-lb-save-and-then-action-duplicate.php#L173",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/improved-save-button/tags/1.2.1/lib/class-lb-save-and-then-post-save.php#L86",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16093",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T14:08:34.722Z",
      "date_published": "2026-07-17T16:42:52.407Z",
      "date_updated": "2026-07-21T01:45:52.870Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-807",
          "name": "Reliance on Untrusted Inputs in a Security Decision",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09229
      },
      "nvd": {
        "published": "2026-07-17T17:17:14.133",
        "lastModified": "2026-07-21T03:16:40.720",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16093",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Keycloak treats an attacker-supplied unsigned assertion header as satisfying a policy that requires a signed JWT assertion.",
        "basis": [
          "CNA",
          "CWE-807"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16093",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501729",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16095",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T14:13:59.281Z",
      "date_published": "2026-07-18T10:15:09.244Z",
      "date_updated": "2026-07-20T13:42:34.472Z",
      "publisher": "VulDB",
      "title": "Shibby Tomato rc setup_conntrack out-of-bounds write",
      "affected": {
        "vendors": [
          "Shibby"
        ],
        "products": [
          {
            "vendor": "Shibby",
            "product": "Tomato"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34513
      },
      "nvd": {
        "published": "2026-07-18T11:16:43.833",
        "lastModified": "2026-07-20T15:16:35.153",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16095",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "setup_conntrack uses the remote ct_tcp_timeout value in a way that writes beyond the destination bounds.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379799",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379799/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16095",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855123",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gitee.com/Fengyi-Wang/CVE/issues/IJTQ5S",
          "host": "gitee.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 318,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16096",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T14:14:03.492Z",
      "date_published": "2026-07-18T11:15:12.641Z",
      "date_updated": "2026-07-22T15:59:47.032Z",
      "publisher": "VulDB",
      "title": "Shibby Tomato webmon_recent_domains sub_40BB50 stack-based overflow",
      "affected": {
        "vendors": [
          "Shibby"
        ],
        "products": [
          {
            "vendor": "Shibby",
            "product": "Tomato"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00438,
        "percentile": 0.36023
      },
      "nvd": {
        "published": "2026-07-18T12:17:11.223",
        "lastModified": "2026-07-22T16:17:11.417",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16096",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Shibby Tomato copies crafted web-monitor data beyond a stack buffer in sub_40BB50.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379800",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379800/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16096",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855124",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gitee.com/Fengyi-Wang/CVE/issues/IJTQ5T",
          "host": "gitee.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16097",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T14:14:07.361Z",
      "date_published": "2026-07-18T12:00:15.023Z",
      "date_updated": "2026-07-20T17:34:01.861Z",
      "publisher": "VulDB",
      "title": "Shibby Tomato Scheduler Name sub_42537C stack-based overflow",
      "affected": {
        "vendors": [
          "Shibby"
        ],
        "products": [
          {
            "vendor": "Shibby",
            "product": "Tomato"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00463,
        "percentile": 0.37779
      },
      "nvd": {
        "published": "2026-07-18T12:17:11.393",
        "lastModified": "2026-07-20T18:16:50.603",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16097",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The manipulation of the argument a1 results in stack-based buffer overflow.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379801",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379801/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16097",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/855125",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://gitee.com/Fengyi-Wang/CVE/issues/IJTQ5U",
          "host": "gitee.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T14:46:55.658Z",
      "date_published": "2026-07-17T16:43:50.887Z",
      "date_updated": "2026-07-21T14:23:58.674Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypass at token redemption",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-841",
          "name": "Improper Enforcement of Behavioral Workflow",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.1092
      },
      "nvd": {
        "published": "2026-07-17T17:17:14.263",
        "lastModified": "2026-07-21T15:16:31.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16103",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler.",
        "basis": [
          "CNA",
          "CWE-841"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16103",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501736",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 558,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16104",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T14:48:32.086Z",
      "date_published": "2026-07-17T16:43:54.168Z",
      "date_updated": "2026-07-17T17:24:34.155Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10564
      },
      "nvd": {
        "published": "2026-07-17T17:17:14.393",
        "lastModified": "2026-07-17T18:17:14.863",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16104",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The authenticator-configuration response returns raw reCAPTCHA secrets to view-only administrators instead of masking secret-valued fields.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16104",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501737",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 490,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16105",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T14:50:31.309Z",
      "date_published": "2026-07-31T07:03:36.107Z",
      "date_updated": "2026-07-31T14:58:18.577Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10128
      },
      "nvd": {
        "published": "2026-07-31T08:16:25.940",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16105",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16105",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501738",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 411,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16106",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T14:53:02.339Z",
      "date_published": "2026-07-17T16:43:16.461Z",
      "date_updated": "2026-07-19T09:12:28.180Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Primary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10129
      },
      "nvd": {
        "published": "2026-07-17T17:17:14.510",
        "lastModified": "2026-07-17T18:08:08.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16106",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16106",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501739",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 417,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16107",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T14:53:58.481Z",
      "date_published": "2026-07-28T19:59:59.220Z",
      "date_updated": "2026-07-29T13:56:30.108Z",
      "publisher": "ibm",
      "title": "TS4500 CLI tool addresses security vulnerability",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "TS4500 CLI tool"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05502
      },
      "nvd": {
        "published": "2026-07-28T20:17:23.200",
        "lastModified": "2026-07-29T15:16:21.393",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16107",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TS4500 CLI tool accepts a certificate or revocation result without validating the identity and current trust state required for the connection.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7280583",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16108",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T14:54:36.323Z",
      "date_published": "2026-07-17T16:43:14.900Z",
      "date_updated": "2026-07-21T16:53:07.924Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08123
      },
      "nvd": {
        "published": "2026-07-17T17:17:14.653",
        "lastModified": "2026-07-21T17:17:05.607",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16108",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Realm-view permission is incorrectly treated as authority to view hidden default groups that require separate group permissions.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16108",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501740",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16117",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T15:40:14.822Z",
      "date_published": "2026-07-18T13:08:40.489Z",
      "date_updated": "2026-07-20T15:14:49.004Z",
      "publisher": "openjs",
      "title": "@fastify/http-proxy vulnerable to prefix escape via URL-encoded characters",
      "affected": {
        "vendors": [
          "@fastify/http-proxy"
        ],
        "products": [
          {
            "vendor": "@fastify/http-proxy",
            "product": "@fastify/http-proxy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18889
      },
      "nvd": {
        "published": "2026-07-18T14:17:11.620",
        "lastModified": "2026-07-28T15:39:01.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16117",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Routing matches a decoded path while prefix rewriting uses the raw encoded path, exposing an unintended upstream route.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fastify/fastify-http-proxy/security/advisories/GHSA-mx7v-qhg9-2mvv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 781,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16118",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T15:50:21.345Z",
      "date_published": "2026-07-17T19:44:40.562Z",
      "date_updated": "2026-07-29T16:55:45.562Z",
      "publisher": "redhat",
      "title": "Xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c",
      "affected": {
        "vendors": [
          "Red Hat",
          "xdg"
        ],
        "products": [
          {
            "vendor": "xdg",
            "product": "xdgmime"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.0334
      },
      "nvd": {
        "published": "2026-07-17T20:17:16.167",
        "lastModified": "2026-07-29T17:16:50.753",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16118",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Incorrect pointer arithmetic during byte swapping writes two bytes beyond a heap allocation while parsing a MIME magic file.",
        "basis": [
          "CNA record",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16118",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501732",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 558,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16119",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T15:56:44.538Z",
      "date_published": "2026-07-18T13:00:10.391Z",
      "date_updated": "2026-07-21T02:35:00.721Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw WebSocket Approval Endpoint exec_approval.go RequestApproval authorization",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20458
      },
      "nvd": {
        "published": "2026-07-18T14:17:11.740",
        "lastModified": "2026-07-21T04:16:49.820",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16119",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that GoClaw permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379828",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379828/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16119",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856825",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1212",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1212#issuecomment-4760281066",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16120",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T15:56:49.001Z",
      "date_published": "2026-07-18T13:30:10.481Z",
      "date_updated": "2026-07-20T19:10:38.406Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw exec_approval.go extractBin name resolution",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-706",
          "name": "Use of Incorrectly-Resolved Name or Reference",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00228,
        "percentile": 0.1371
      },
      "nvd": {
        "published": "2026-07-18T14:17:11.907",
        "lastModified": "2026-07-20T19:17:18.773",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16120",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The execution allowlist compares an incorrectly resolved binary name in matchesAllowlist and extractBin, so approval can bind to the wrong executable.",
        "basis": [
          "CNA",
          "CWE-706"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379829",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379829/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16120",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856826",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1213",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1213#issuecomment-4760246569",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 343,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16121",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T15:56:53.703Z",
      "date_published": "2026-07-18T14:15:09.776Z",
      "date_updated": "2026-07-20T15:07:57.237Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw exec_approval.go isSafeBin improper authorization",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11245
      },
      "nvd": {
        "published": "2026-07-18T15:17:32.987",
        "lastModified": "2026-07-20T16:16:56.167",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16121",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "GoClaw's isSafeBin decision permits a binary outside the caller's intended execution authority, while the public record does not identify the whitelist or permission rule that fails.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379830",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379830/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16121",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856827",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1214",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1206",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16122",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T15:56:57.968Z",
      "date_published": "2026-07-18T14:30:09.020Z",
      "date_updated": "2026-07-20T13:37:14.400Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw exec_approval.go matchesAllowlist authorization",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.7,
          "severity": "",
          "vector": "AV:A/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.7,
          "severity": "",
          "vector": "AV:A/AC:L/Au:M/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 2.9,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09604
      },
      "nvd": {
        "published": "2026-07-18T15:17:33.743",
        "lastModified": "2026-07-20T14:16:54.230",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16122",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The GoClaw allowlist path can authorize a disallowed execution request, but the record does not disclose the input or comparison that makes matchesAllowlist return the wrong decision.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379831",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379831/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16122",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856856",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1216",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1216#issuecomment-4760050291",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16123",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T15:57:02.258Z",
      "date_published": "2026-07-18T14:45:08.338Z",
      "date_updated": "2026-07-22T15:33:42.676Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw Invoke Endpoint tools_invoke.go ToolsInvokeHandler.ServeHTTP authorization",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11244
      },
      "nvd": {
        "published": "2026-07-18T15:17:33.900",
        "lastModified": "2026-07-22T16:17:11.563",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16123",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ToolsInvokeHandler.ServeHTTP exposes the invoke endpoint without enforcing the authorization required to call a tool.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379832",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379832/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16123",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856857",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1217",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1217#issuecomment-4759982122",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 382,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16124",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T15:57:06.671Z",
      "date_published": "2026-07-18T15:00:11.635Z",
      "date_updated": "2026-07-20T16:55:09.350Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw web_fetch web_shared.go isPrivateIP server-side request forgery",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 34,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25495
      },
      "nvd": {
        "published": "2026-07-18T16:17:12.657",
        "lastModified": "2026-07-20T17:17:04.473",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16124",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The GoClaw server fetches an attacker-selected network destination without enforcing the intended destination policy.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379833",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379833/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16124",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856858",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1218",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/pull/1269",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/commit/12a0168271827650ddb0026d6277fbadf3dcf3ea",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/releases/tag/v3.15.0-beta.33",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 34
      }
    },
    {
      "cve_id": "CVE-2026-16125",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T16:08:22.751Z",
      "date_published": "2026-07-18T15:15:08.064Z",
      "date_updated": "2026-07-21T02:45:29.691Z",
      "publisher": "VulDB",
      "title": "zevorn rt-claw http_request net.c claw_net_post server-side request forgery",
      "affected": {
        "vendors": [
          "zevorn"
        ],
        "products": [
          {
            "vendor": "zevorn",
            "product": "rt-claw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21056
      },
      "nvd": {
        "published": "2026-07-18T16:17:12.873",
        "lastModified": "2026-07-21T04:16:49.987",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16125",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation trusts attacker-controlled channel metadata without enforcing the intended origin or destination boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379837",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379837/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16125",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856869",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/issues/134",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16126",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T16:08:26.573Z",
      "date_published": "2026-07-18T15:45:08.996Z",
      "date_updated": "2026-07-20T19:10:31.732Z",
      "publisher": "VulDB",
      "title": "zevorn rt-claw Swarm RPC Receiver swarm.c handle_rpc_request authorization",
      "affected": {
        "vendors": [
          "zevorn"
        ],
        "products": [
          {
            "vendor": "zevorn",
            "product": "rt-claw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22056
      },
      "nvd": {
        "published": "2026-07-18T16:17:13.043",
        "lastModified": "2026-07-20T19:17:18.900",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16126",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The rt-claw operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379838",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379838/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16126",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856870",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856871",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/issues/135",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/issues/137",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 453,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16127",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T16:08:33.195Z",
      "date_published": "2026-07-18T16:00:08.864Z",
      "date_updated": "2026-07-20T15:08:39.313Z",
      "publisher": "VulDB",
      "title": "zevorn rt-claw http_request tool_net.c claw_net_post server-side request forgery",
      "affected": {
        "vendors": [
          "zevorn"
        ],
        "products": [
          {
            "vendor": "zevorn",
            "product": "rt-claw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21055
      },
      "nvd": {
        "published": "2026-07-18T16:17:13.217",
        "lastModified": "2026-07-20T16:16:56.313",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16127",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "claw_net_get and claw_net_post accept a caller-controlled URL without restricting server-side destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379839",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379839/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16127",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856872",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/issues/139",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 446,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16128",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T16:08:54.648Z",
      "date_published": "2026-07-18T16:30:08.241Z",
      "date_updated": "2026-07-20T13:27:50.378Z",
      "publisher": "VulDB",
      "title": "zevorn rt-claw http_request swarm.c receiver_thread server-side request forgery",
      "affected": {
        "vendors": [
          "zevorn"
        ],
        "products": [
          {
            "vendor": "zevorn",
            "product": "rt-claw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21054
      },
      "nvd": {
        "published": "2026-07-18T17:16:38.273",
        "lastModified": "2026-07-20T14:16:54.360",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16128",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says rt-claw accepts a request across an unintended network or origin boundary, while the request field and validation step are not public.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379840",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379840/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16128",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856873",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/issues/140",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 463,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16129",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T16:13:27.659Z",
      "date_published": "2026-07-18T17:00:09.200Z",
      "date_updated": "2026-07-22T15:47:31.469Z",
      "publisher": "VulDB",
      "title": "princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklist",
      "affected": {
        "vendors": [
          "princezuda"
        ],
        "products": [
          {
            "vendor": "princezuda",
            "product": "SafestClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-183",
          "name": "Permissive List of Allowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13827
      },
      "nvd": {
        "published": "2026-07-18T17:16:39.030",
        "lastModified": "2026-07-22T16:17:11.703",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16129",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "low",
        "mechanism": "ShellAction._validate_command relies on an incomplete command blacklist, leaving shell syntax that the validator does not reject.",
        "basis": [
          "CNA",
          "CWE-183",
          "CWE-184"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379845",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379845/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16129",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856882",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/princezuda/safestclaw/issues/59",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/princezuda/safestclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 732,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16130",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T16:16:09.661Z",
      "date_published": "2026-07-18T17:15:10.968Z",
      "date_updated": "2026-07-20T16:54:15.398Z",
      "publisher": "VulDB",
      "title": "nearai ironclaw write_file path_utils.rs validate_path link following",
      "affected": {
        "vendors": [
          "nearai"
        ],
        "products": [
          {
            "vendor": "nearai",
            "product": "ironclaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 3.2,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 3.2,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 2.9,
      "epss": {
        "score": 0.00138,
        "percentile": 0.0359
      },
      "nvd": {
        "published": "2026-07-18T18:16:37.430",
        "lastModified": "2026-07-20T17:17:04.633",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16130",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "validate_path() follows a local symlink during write_file, allowing the resolved write target to leave the permitted directory.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379848",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379848/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16130",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856883",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nearai/ironclaw/issues/4797",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nearai/ironclaw/pull/4869",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/nearai/ironclaw/commit/369ff3d240cf3c0787b50e1e9f182e1a06c71255",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/nearai/ironclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 459,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16131",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T16:17:22.895Z",
      "date_published": "2026-07-18T18:15:08.418Z",
      "date_updated": "2026-07-21T02:46:22.484Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System prescriptionrecord.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10075
      },
      "nvd": {
        "published": "2026-07-18T19:17:05.527",
        "lastModified": "2026-07-21T04:16:50.137",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16131",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379850",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379850/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16131",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856926",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/submit_vuln/issues/9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 339,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16133",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T16:19:30.219Z",
      "date_published": "2026-07-18T19:00:12.613Z",
      "date_updated": "2026-07-20T19:10:24.859Z",
      "publisher": "VulDB",
      "title": "LiuMengxuan04 MiniCode mcp.ts child_process.spawn command injection",
      "affected": {
        "vendors": [
          "LiuMengxuan04"
        ],
        "products": [
          {
            "vendor": "LiuMengxuan04",
            "product": "MiniCode"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00827,
        "percentile": 0.53913
      },
      "nvd": {
        "published": "2026-07-18T19:17:05.687",
        "lastModified": "2026-07-20T19:17:19.037",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16133",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The application places attacker-controlled data into an operating-system command without separating the data from command syntax.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379853",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379853/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16133",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856976",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/LiuMengxuan04/MiniCode/issues/35",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/LiuMengxuan04/MiniCode/pull/37",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://gist.github.com/menelausx/b42381d2788a334cba8cda43f52e2a28",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/LiuMengxuan04/MiniCode/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 426,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16150",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T19:01:44.871Z",
      "date_published": "2026-07-18T19:15:08.501Z",
      "date_updated": "2026-07-20T15:10:01.298Z",
      "publisher": "VulDB",
      "title": "RobinHerbots Inputmask Internal Deep Merge Helper extend.js extendAliases prototype pollution",
      "affected": {
        "vendors": [
          "RobinHerbots"
        ],
        "products": [
          {
            "vendor": "RobinHerbots",
            "product": "Inputmask"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17123
      },
      "nvd": {
        "published": "2026-07-18T20:17:29.947",
        "lastModified": "2026-07-20T16:16:56.430",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16150",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Inputmask deep-merge helpers accept attacker-controlled property names that can modify shared object-prototype attributes.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379909",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379909/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16150",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/856979",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/RobinHerbots/Inputmask/issues/2885",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/RobinHerbots/Inputmask/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-16151",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T19:30:24.070Z",
      "date_published": "2026-07-18T19:45:08.449Z",
      "date_updated": "2026-07-20T13:26:33.188Z",
      "publisher": "VulDB",
      "title": "CartoDB carto-api-client filters.ts addFilter prototype pollution",
      "affected": {
        "vendors": [
          "CartoDB"
        ],
        "products": [
          {
            "vendor": "CartoDB",
            "product": "carto-api-client"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24459
      },
      "nvd": {
        "published": "2026-07-18T20:17:30.107",
        "lastModified": "2026-07-20T14:16:54.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16151",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "addFilter accepts a column key that can modify properties on the shared JavaScript object prototype.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379917",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379917/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16151",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857043",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/CartoDB/carto-api-client/issues/299",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/CartoDB/carto-api-client/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 381,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16152",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T19:34:00.954Z",
      "date_published": "2026-07-18T20:00:10.046Z",
      "date_updated": "2026-07-22T14:56:48.533Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_rooma.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20628
      },
      "nvd": {
        "published": "2026-07-18T21:17:03.180",
        "lastModified": "2026-07-22T16:17:11.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16152",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The room-edit endpoint incorporates the ID parameter into SQL without preserving the query grammar boundary.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379918",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379918/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16152",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857078",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/justconter/cve/issues/6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16154",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T19:34:05.314Z",
      "date_published": "2026-07-18T20:15:10.589Z",
      "date_updated": "2026-07-20T16:51:54.520Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_room1.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20034
      },
      "nvd": {
        "published": "2026-07-18T21:17:03.343",
        "lastModified": "2026-07-20T17:17:04.760",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16154",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ID parameter is incorporated into an edit_room1.php SQL statement without safe parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379919",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379919/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16154",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857079",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/justconter/cve/issues/5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 354,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16155",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T19:34:09.553Z",
      "date_published": "2026-07-18T20:45:09.905Z",
      "date_updated": "2026-07-21T13:58:10.431Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System schoolyr.php cross site scripting",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09876
      },
      "nvd": {
        "published": "2026-07-18T21:17:03.507",
        "lastModified": "2026-07-21T15:16:32.350",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16155",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Class and Exam Timetabling System page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379920",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379920/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16155",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857080",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/justconter/cve/issues/4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16156",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T19:34:13.229Z",
      "date_published": "2026-07-18T21:00:10.097Z",
      "date_updated": "2026-07-21T14:58:44.621Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System forexam.php cross site scripting",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09876
      },
      "nvd": {
        "published": "2026-07-18T22:16:43.667",
        "lastModified": "2026-07-21T16:17:05.800",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16156",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The day parameter reaches page output without the escaping required to keep it from becoming browser script.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/379921",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/379921/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16156",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857081",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/justconter/cve/issues/3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16157",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T19:45:55.953Z",
      "date_published": "2026-07-22T17:29:25.278Z",
      "date_updated": "2026-07-27T17:03:37.752Z",
      "publisher": "certcc",
      "title": "Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability",
      "affected": {
        "vendors": [
          "Duplicati"
        ],
        "products": [
          {
            "vendor": "Duplicati",
            "product": "Duplicati"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.0203
      },
      "nvd": {
        "published": "2026-07-22T18:16:55.410",
        "lastModified": "2026-07-27T18:16:52.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16157",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Duplicati installs or creates a security-sensitive object with permissions that grant lower-privileged users write or read access.",
        "basis": [
          "CNA",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.cert.org/vuls/id/847406",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/847406",
          "host": "www.kb.cert.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T21:22:28.153Z",
      "date_published": "2026-07-18T12:28:17.262Z",
      "date_updated": "2026-07-20T15:15:50.016Z",
      "publisher": "openjs",
      "title": "@fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collision",
      "affected": {
        "vendors": [
          "@fastify/reply-from"
        ],
        "products": [
          {
            "vendor": "@fastify/reply-from",
            "product": "@fastify/reply-from"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13839
      },
      "nvd": {
        "published": "2026-07-18T13:17:06.030",
        "lastModified": "2026-07-21T18:31:51.680",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16158",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "@fastify/reply-from constructs a URL cache key by concatenating destination and source path without a delimiter, allowing different upstream routes to collide and reuse the wrong routing decision.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-441"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-v574-6498-x57v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 702,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T00:53:31.768Z",
      "date_published": "2026-07-28T19:50:07.232Z",
      "date_updated": "2026-07-29T12:38:48.001Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server is affected by an authentication bypass",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 2.8000000000000007,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24699
      },
      "nvd": {
        "published": "2026-07-28T20:17:23.330",
        "lastModified": "2026-08-03T14:55:49.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16184",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in WebSphere Application Server, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Read https://www.ibm.com/support/pages/node/7281628; IBM names a crafted unauthenticated request and APAR DT496677 but does not disclose the failed check, and its current bulletin reports CVSS 7.0 rather than the embedded aggregate's 9.8."
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281628",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T01:57:27.285Z",
      "date_published": "2026-07-28T19:47:03.010Z",
      "date_updated": "2026-07-29T12:40:27.634Z",
      "publisher": "ibm",
      "title": "IBM WebSphere Application Server Liberty is affected by a denial of service",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "WebSphere Application Server - Liberty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18007
      },
      "nvd": {
        "published": "2026-07-28T20:17:23.460",
        "lastModified": "2026-08-03T14:52:00.207",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16192",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "With restConnector-2.0 enabled, WebSphere Liberty permits uncontrolled recursion, but the public record does not identify the recursive input or call path.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281648",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 164,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16194",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T02:37:49.144Z",
      "date_published": "2026-07-18T21:15:10.826Z",
      "date_updated": "2026-07-20T13:54:55.381Z",
      "publisher": "VulDB",
      "title": "zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgery",
      "affected": {
        "vendors": [
          "zhayujie"
        ],
        "products": [
          {
            "vendor": "zhayujie",
            "product": "CowAgent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25494
      },
      "nvd": {
        "published": "2026-07-18T22:16:43.830",
        "lastModified": "2026-07-20T15:16:35.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16194",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebFetch.execute allows a remote caller to choose a server-side request destination without enforcing the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380009",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380009/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16194",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857620",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/issues/2889",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/pull/2900",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/commit/ea47f3097eed4f8295c4cb3d76ecb97e0f43d632",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/releases/tag/2.1.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/zhayujie/CowAgent/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 652,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16195",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T07:22:29.086Z",
      "date_published": "2026-07-18T22:30:10.281Z",
      "date_updated": "2026-07-20T13:25:11.446Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw Group Message wecom.go dispatchIncoming authorization",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11242
      },
      "nvd": {
        "published": "2026-07-18T23:17:00.847",
        "lastModified": "2026-07-20T14:16:54.627",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16195",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PicoClaw dispatches a group message without enforcing the required caller or channel authorization, while the missing comparison is not public.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380011",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380011/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16195",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852962",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3076",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 438,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-16196",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T07:22:33.012Z",
      "date_published": "2026-07-18T22:45:13.066Z",
      "date_updated": "2026-07-22T15:01:58.974Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw web_fetch web.go isPrivateOrRestrictedIP server-side request forgery",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21134
      },
      "nvd": {
        "published": "2026-07-18T23:17:01.010",
        "lastModified": "2026-07-22T16:17:11.993",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16196",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This manipulation causes server-side request forgery.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380012",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380012/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16196",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852963",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3077",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/pull/3085",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/commit/2efbe5d560e7ed9bc5209c203dc4aa6ecdbc7405",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 463,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-16197",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T07:22:36.968Z",
      "date_published": "2026-07-18T23:00:12.202Z",
      "date_updated": "2026-07-20T19:11:06.535Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw Group Message feishu_64.go handleMessageReceive authorization",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11248
      },
      "nvd": {
        "published": "2026-07-18T23:17:01.187",
        "lastModified": "2026-07-20T19:17:19.177",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16197",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Such manipulation leads to missing authorization.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380013",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380013/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16197",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852964",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3082",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-16198",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T07:22:40.821Z",
      "date_published": "2026-07-18T23:30:18.741Z",
      "date_updated": "2026-07-21T14:32:20.618Z",
      "publisher": "VulDB",
      "title": "Sipeed PicoClaw First Run Setup access_control.go authentication bypass",
      "affected": {
        "vendors": [
          "Sipeed"
        ],
        "products": [
          {
            "vendor": "Sipeed",
            "product": "PicoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00393,
        "percentile": 0.32021
      },
      "nvd": {
        "published": "2026-07-19T00:16:40.650",
        "lastModified": "2026-07-21T15:16:32.743",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16198",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380014",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380014/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16198",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/852965",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/issues/3080",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/pull/3083",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/commit/017601354be38cb027ff3ffb01aed79bd5d12610",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/sipeed/picoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 596,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-16199",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T07:24:32.110Z",
      "date_published": "2026-07-19T00:00:12.753Z",
      "date_updated": "2026-07-20T19:10:18.336Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw credentialed_exec.go ExecTool.Execute improper authorization",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11245
      },
      "nvd": {
        "published": "2026-07-19T00:16:40.830",
        "lastModified": "2026-07-20T19:17:19.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16199",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The component assigns or permits a privilege beyond the authority granted to the invoking user.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380015",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380015/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16199",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857621",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1215",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1215#issuecomment-4760153807",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 314,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16200",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T07:29:32.332Z",
      "date_published": "2026-07-19T00:15:10.494Z",
      "date_updated": "2026-07-20T13:55:35.771Z",
      "publisher": "VulDB",
      "title": "zevorn rt-claw RPC swarm.c claw_tool_invoke authorization",
      "affected": {
        "vendors": [
          "zevorn"
        ],
        "products": [
          {
            "vendor": "zevorn",
            "product": "rt-claw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21055
      },
      "nvd": {
        "published": "2026-07-19T01:17:01.900",
        "lastModified": "2026-07-20T15:16:35.440",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16200",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380016",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380016/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16200",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857622",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/issues/133",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16201",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T07:29:36.255Z",
      "date_published": "2026-07-19T00:45:10.166Z",
      "date_updated": "2026-07-20T13:24:33.583Z",
      "publisher": "VulDB",
      "title": "zevorn rt-claw http_request net.c claw_net_post information disclosure",
      "affected": {
        "vendors": [
          "zevorn"
        ],
        "products": [
          {
            "vendor": "zevorn",
            "product": "rt-claw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23521
      },
      "nvd": {
        "published": "2026-07-19T01:17:02.087",
        "lastModified": "2026-07-20T14:16:54.760",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16201",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The network helper discloses information to a remote caller, but the public record identifies neither the returned data nor the guard that should protect it.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380017",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380017/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16201",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857623",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/issues/136",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16202",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T07:32:40.789Z",
      "date_published": "2026-07-19T01:15:10.997Z",
      "date_updated": "2026-07-22T15:03:13.955Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System CYS.php cross site scripting",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09875
      },
      "nvd": {
        "published": "2026-07-19T02:16:43.350",
        "lastModified": "2026-07-22T16:17:12.153",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16202",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CYS.php course parameter is rendered into a web page without separating data from HTML or script grammar.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380018",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380018/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16202",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857765",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/AlbaDove/cve/issues/9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 350,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16203",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T07:32:44.673Z",
      "date_published": "2026-07-19T01:30:09.695Z",
      "date_updated": "2026-07-20T13:43:59.386Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System forCYS.php cross site scripting",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09875
      },
      "nvd": {
        "published": "2026-07-19T02:16:44.727",
        "lastModified": "2026-07-20T15:16:35.577",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16203",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content is rendered without the browser-context separation required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380019",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380019/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16203",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857766",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/AlbaDove/cve/issues/8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16204",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T07:34:33.333Z",
      "date_published": "2026-07-19T01:45:11.609Z",
      "date_updated": "2026-07-21T14:34:14.892Z",
      "publisher": "VulDB",
      "title": "zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_execute code injection",
      "affected": {
        "vendors": [
          "zevorn"
        ],
        "products": [
          {
            "vendor": "zevorn",
            "product": "rt-claw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 5.4,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23726
      },
      "nvd": {
        "published": "2026-07-19T03:16:42.087",
        "lastModified": "2026-07-21T15:16:33.177",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16204",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Telegram-supplied data reaches tool_run_script_execute as executable code without the required syntax separation.",
        "basis": [
          "CNA record",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380020",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380020/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16204",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857784",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/issues/138",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zevorn/rt-claw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16205",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T07:37:53.771Z",
      "date_published": "2026-07-19T02:00:09.299Z",
      "date_updated": "2026-07-20T19:10:11.563Z",
      "publisher": "VulDB",
      "title": "Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting",
      "affected": {
        "vendors": [
          "Pluck"
        ],
        "products": [
          {
            "vendor": "Pluck",
            "product": "CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 22,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 3.3,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 3.3,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 2.9,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10293
      },
      "nvd": {
        "published": "2026-07-19T03:16:42.250",
        "lastModified": "2026-07-20T19:17:19.430",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16205",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CMS renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380021",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380021/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16205",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857798",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/pluck-cms/pluck/issues/145",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 506,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 22
      }
    },
    {
      "cve_id": "CVE-2026-16206",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T08:23:11.906Z",
      "date_published": "2026-07-19T02:15:08.796Z",
      "date_updated": "2026-07-20T13:58:32.053Z",
      "publisher": "VulDB",
      "title": "django-oauth django-oauth-toolkit oauth2_validators.py _load_id_token session expiration",
      "affected": {
        "vendors": [
          "django-oauth"
        ],
        "products": [
          {
            "vendor": "django-oauth",
            "product": "django-oauth-toolkit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11243
      },
      "nvd": {
        "published": "2026-07-19T03:16:42.413",
        "lastModified": "2026-07-20T15:16:35.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16206",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record names _load_id_token and session expiration but does not disclose a security-relevant failing check or state transition.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380022",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380022/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16206",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857897",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857923",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/django-oauth/django-oauth-toolkit/issues/1715",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/django-oauth/django-oauth-toolkit/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 364,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16207",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T08:27:05.220Z",
      "date_published": "2026-07-19T02:30:08.210Z",
      "date_updated": "2026-07-20T13:24:00.321Z",
      "publisher": "VulDB",
      "title": "django-tastypie authentication.py ApiKeyAuthentication get request method with sensitive query strings",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "django-tastypie"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-598",
          "name": "Use of HTTP Request With Sensitive Query String",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 2.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:N/A:N/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 2.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 3.6999999999999997,
      "epss": {
        "score": 0.00399,
        "percentile": 0.32622
      },
      "nvd": {
        "published": "2026-07-19T04:16:44.460",
        "lastModified": "2026-07-20T14:16:54.890",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16207",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ApiKeyAuthentication places API credentials in a GET query string, exposing them to URL logs, history, referrers, and intermediaries.",
        "basis": [
          "CNA",
          "CWE-598"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380023",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380023/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16207",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857924",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/django-tastypie/django-tastypie/issues/1700",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/django-tastypie/django-tastypie/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 458,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16208",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T08:27:09.808Z",
      "date_published": "2026-07-19T02:45:09.240Z",
      "date_updated": "2026-07-22T14:58:26.978Z",
      "publisher": "VulDB",
      "title": "django-tastypie throttle.py CacheDBThrottle race condition",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "django-tastypie"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 2.7,
      "epss": {
        "score": 0.00167,
        "percentile": 0.06366
      },
      "nvd": {
        "published": "2026-07-19T04:17:03.523",
        "lastModified": "2026-07-22T16:17:12.287",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16208",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The record identifies a remotely triggerable race in CacheThrottle and CacheDBThrottle but does not disclose the shared state or interleaving.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380024",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380024/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16208",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857925",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/django-tastypie/django-tastypie/issues/1700",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/django-tastypie/django-tastypie/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16209",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T08:29:13.523Z",
      "date_published": "2026-07-19T03:00:11.685Z",
      "date_updated": "2026-07-20T12:14:14.468Z",
      "publisher": "VulDB",
      "title": "Gerapy Project Upload Endpoint views.py missing authentication",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "Gerapy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 14,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33744
      },
      "nvd": {
        "published": "2026-07-19T04:17:03.983",
        "lastModified": "2026-07-20T13:30:32.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16209",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The project-upload endpoint in views.py is reachable without authentication.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380025",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380025/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16209",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857926",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/Gerapy/Gerapy/issues/317",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/Gerapy/Gerapy/pull/319",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/Gerapy/Gerapy/commit/bd4891c60315f17611a3b7a651ffe0fba7cfe71e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Gerapy/Gerapy/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 448,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-16210",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T08:32:01.295Z",
      "date_published": "2026-07-19T03:15:08.240Z",
      "date_updated": "2026-07-21T14:38:35.474Z",
      "publisher": "VulDB",
      "title": "newpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing authentication",
      "affected": {
        "vendors": [
          "newpanjing"
        ],
        "products": [
          {
            "vendor": "newpanjing",
            "product": "simpleui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00397,
        "percentile": 0.32486
      },
      "nvd": {
        "published": "2026-07-19T04:17:04.343",
        "lastModified": "2026-07-21T16:17:05.920",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16210",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The simpleui path exposes a privileged operation without first authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380026",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380026/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16210",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857929",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/newpanjing/simpleui/issues/537",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/newpanjing/simpleui/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16211",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T08:40:44.904Z",
      "date_published": "2026-07-19T03:30:10.916Z",
      "date_updated": "2026-07-20T19:10:02.437Z",
      "publisher": "VulDB",
      "title": "allegro Hostname Allocation assets.py AssetLastHostname.increment_hostname race condition",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "allegro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.4,
          "severity": "",
          "vector": "AV:A/AC:H/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.4,
          "severity": "",
          "vector": "AV:A/AC:H/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.6,
      "cvss_source_score_spread": 1.4000000000000001,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05354
      },
      "nvd": {
        "published": "2026-07-19T04:17:05.010",
        "lastModified": "2026-07-20T19:17:19.567",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16211",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Concurrent hostname allocation can race so two operations act on an inconsistent allocation state.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380027",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380027/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16211",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857935",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/allegro/ralph/issues/3950",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 566,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16212",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T08:48:39.756Z",
      "date_published": "2026-07-19T03:45:08.520Z",
      "date_updated": "2026-07-20T13:57:53.934Z",
      "publisher": "VulDB",
      "title": "awesto django-shop Purchase Stock inventory.py race condition",
      "affected": {
        "vendors": [
          "awesto"
        ],
        "products": [
          {
            "vendor": "awesto",
            "product": "django-shop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 3.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 3.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 2.9000000000000004,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08154
      },
      "nvd": {
        "published": "2026-07-19T05:16:37.357",
        "lastModified": "2026-07-20T15:16:35.853",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16212",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Concurrent purchase-stock updates in shop/models/inventory.py race without preserving the checked inventory state.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380028",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380028/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16212",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857939",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/awesto/django-shop/issues/888",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/awesto/django-shop/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16213",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T08:52:44.014Z",
      "date_published": "2026-07-19T04:00:09.228Z",
      "date_updated": "2026-07-20T13:22:26.672Z",
      "publisher": "VulDB",
      "title": "Fantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cleartext storage",
      "affected": {
        "vendors": [
          "Fantomas42"
        ],
        "products": [
          {
            "vendor": "Fantomas42",
            "product": "django-blog-zinnia"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 20,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-310",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-312",
          "name": "Cleartext Storage of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00081,
        "percentile": 0.00253
      },
      "nvd": {
        "published": "2026-07-19T05:16:38.277",
        "lastModified": "2026-07-20T14:16:55.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16213",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "django-blog-zinnia stores protected-entry password information in cleartext in the entry protection handler.",
        "basis": [
          "CNA",
          "CWE-310",
          "CWE-312"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380029",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380029/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16213",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857944",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/Fantomas42/django-blog-zinnia/issues/595",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/Fantomas42/django-blog-zinnia/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 454,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-16214",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T09:51:40.418Z",
      "date_published": "2026-07-19T04:15:09.590Z",
      "date_updated": "2026-07-22T14:59:38.479Z",
      "publisher": "VulDB",
      "title": "geex-arts django-jet Dashboard views.py authorization",
      "affected": {
        "vendors": [
          "geex-arts"
        ],
        "products": [
          {
            "vendor": "geex-arts",
            "product": "django-jet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12578
      },
      "nvd": {
        "published": "2026-07-19T05:16:38.440",
        "lastModified": "2026-07-22T16:17:12.420",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16214",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "django-jet dashboard views permit a remote caller to bypass authorization, while the public record does not identify the view action, selected object, or failing ownership check.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380037",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380037/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16214",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857945",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/geex-arts/django-jet/issues/528",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/geex-arts/django-jet/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-16215",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T09:51:48.373Z",
      "date_published": "2026-07-19T04:30:09.330Z",
      "date_updated": "2026-07-20T10:33:32.993Z",
      "publisher": "VulDB",
      "title": "geex-arts django-jet OAuth Credential Revoke authorization",
      "affected": {
        "vendors": [
          "geex-arts"
        ],
        "products": [
          {
            "vendor": "geex-arts",
            "product": "django-jet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24265
      },
      "nvd": {
        "published": "2026-07-19T05:16:38.603",
        "lastModified": "2026-07-20T13:30:32.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16215",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OAuth credential-revocation handler performs a protected revoke operation without the required authorization check.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380038",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380038/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16215",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857946",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/geex-arts/django-jet/issues/528",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/geex-arts/django-jet/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-16216",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T09:51:52.151Z",
      "date_published": "2026-07-19T05:00:10.797Z",
      "date_updated": "2026-07-21T14:41:20.488Z",
      "publisher": "VulDB",
      "title": "geex-arts django-jet OAuth cross-site request forgery",
      "affected": {
        "vendors": [
          "geex-arts"
        ],
        "products": [
          {
            "vendor": "geex-arts",
            "product": "django-jet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05487
      },
      "nvd": {
        "published": "2026-07-19T06:17:09.510",
        "lastModified": "2026-07-21T16:17:06.067",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16216",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-352",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380039",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380039/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16216",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857947",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/geex-arts/django-jet/issues/528",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/geex-arts/django-jet/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-16217",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T09:53:24.724Z",
      "date_published": "2026-07-19T05:30:10.201Z",
      "date_updated": "2026-07-20T19:08:51.475Z",
      "publisher": "VulDB",
      "title": "guohongze adminset Delivery Deployment Endpoint deli.py authorization",
      "affected": {
        "vendors": [
          "guohongze"
        ],
        "products": [
          {
            "vendor": "guohongze",
            "product": "adminset"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 61,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12578
      },
      "nvd": {
        "published": "2026-07-19T06:17:09.863",
        "lastModified": "2026-07-20T19:17:19.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16217",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation accepts a caller-supplied object identifier without binding the selected object to the authenticated caller.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380040",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380040/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16217",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857950",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/guohongze/adminset/issues/161",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/guohongze/adminset/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 61
      }
    },
    {
      "cve_id": "CVE-2026-16218",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T09:55:57.419Z",
      "date_published": "2026-07-19T05:45:08.349Z",
      "date_updated": "2026-07-20T13:57:18.074Z",
      "publisher": "VulDB",
      "title": "hunvreus devpush Storage Reset Failure storage.py reset_storage improper check or handling of exceptional conditions",
      "affected": {
        "vendors": [
          "hunvreus"
        ],
        "products": [
          {
            "vendor": "hunvreus",
            "product": "devpush"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-703",
          "name": "Improper Check or Handling of Exceptional Conditions",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.4,
          "severity": "",
          "vector": "AV:A/AC:H/Au:S/C:N/I:P/A:N/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.4,
          "severity": "",
          "vector": "AV:A/AC:H/Au:S/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.6,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.002,
        "percentile": 0.10044
      },
      "nvd": {
        "published": "2026-07-19T06:17:10.067",
        "lastModified": "2026-07-20T15:16:36.003",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16218",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public record identifies a concrete input or state validation failure outside the main cause families, as described in the cited record.",
        "basis": [
          "CNA",
          "CWE-703"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380041",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380041/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16218",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857951",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/hunvreus/devpush/issues/69",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/hunvreus/devpush/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-16219",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T10:04:13.458Z",
      "date_published": "2026-07-19T06:00:11.583Z",
      "date_updated": "2026-07-20T13:21:27.780Z",
      "publisher": "VulDB",
      "title": "Croogo CMS Admin File Manager FileManager.php isEditable path traversal",
      "affected": {
        "vendors": [
          "Croogo"
        ],
        "products": [
          {
            "vendor": "Croogo",
            "product": "CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26938
      },
      "nvd": {
        "published": "2026-07-19T07:16:48.540",
        "lastModified": "2026-07-20T14:16:55.160",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16219",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CMS accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380042",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380042/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16219",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857986",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/croogo/croogo/issues/1008",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/fa1c4/security-advisories/tree/main/Croogo",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 411,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-16220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T10:07:54.805Z",
      "date_published": "2026-07-19T06:15:08.945Z",
      "date_updated": "2026-07-22T14:35:45.169Z",
      "publisher": "VulDB",
      "title": "code-projects Online Examination System account.php cross site scripting",
      "affected": {
        "vendors": [
          "code-projects"
        ],
        "products": [
          {
            "vendor": "code-projects",
            "product": "Online Examination System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19438
      },
      "nvd": {
        "published": "2026-07-19T07:16:49.687",
        "lastModified": "2026-07-22T15:16:52.750",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16220",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Quiz parameters reach generated HTML without the context-aware neutralization needed to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380043",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380043/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16220",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/857999",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zzzxc643/CVE1/blob/main/project1/vul5.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://code-projects.org/",
          "host": "code-projects.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 323,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16221",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T11:37:36.004Z",
      "date_published": "2026-07-19T14:08:32.993Z",
      "date_updated": "2026-07-20T13:53:42.583Z",
      "publisher": "openjs",
      "title": "fast-uri vulnerable to host confusion via literal backslash authority delimiter",
      "affected": {
        "vendors": [
          "fast-uri"
        ],
        "products": [
          {
            "vendor": "fast-uri",
            "product": "fast-uri"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12781
      },
      "nvd": {
        "published": "2026-07-19T15:16:49.027",
        "lastModified": "2026-07-21T18:31:51.680",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16221",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "fast-uri treats a backslash differently from Node's URL consumers, so a policy check and the eventual request resolve the same string to different hosts.",
        "basis": [
          "CNA",
          "CWE-436"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 890,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-16222",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:11:08.681Z",
      "date_published": "2026-07-19T06:45:09.639Z",
      "date_updated": "2026-07-20T10:26:14.132Z",
      "publisher": "VulDB",
      "title": "1Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side request forgery",
      "affected": {
        "vendors": [
          "1Panel-dev"
        ],
        "products": [
          {
            "vendor": "1Panel-dev",
            "product": "CordysCRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11909
      },
      "nvd": {
        "published": "2026-07-19T08:16:42.620",
        "lastModified": "2026-07-20T13:30:32.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16222",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TokenService accepts the mkAddress value as a server-side request destination without restricting it to trusted hosts or address ranges.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380044",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380044/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16222",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858043",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858044",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/1Panel-dev/CordysCRM/issues/2685",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/1Panel-dev/CordysCRM/issues/2686",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/1Panel-dev/CordysCRM/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16223",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:11:12.780Z",
      "date_published": "2026-07-19T07:15:09.159Z",
      "date_updated": "2026-07-21T14:48:42.529Z",
      "publisher": "VulDB",
      "title": "1Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgery",
      "affected": {
        "vendors": [
          "1Panel-dev"
        ],
        "products": [
          {
            "vendor": "1Panel-dev",
            "product": "CordysCRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11909
      },
      "nvd": {
        "published": "2026-07-19T08:16:43.647",
        "lastModified": "2026-07-21T16:17:06.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16223",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CordysCRM request path lets a caller choose a server-side destination outside the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380045",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380045/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16223",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858045",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858046",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/1Panel-dev/CordysCRM/issues/2687",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/1Panel-dev/CordysCRM/issues/2688",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/1Panel-dev/CordysCRM/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16224",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:24:56.183Z",
      "date_published": "2026-07-19T07:45:09.252Z",
      "date_updated": "2026-07-20T19:08:44.216Z",
      "publisher": "VulDB",
      "title": "jxxghp MoviePilot Application API improper authorization",
      "affected": {
        "vendors": [
          "jxxghp"
        ],
        "products": [
          {
            "vendor": "jxxghp",
            "product": "MoviePilot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12843
      },
      "nvd": {
        "published": "2026-07-19T09:17:01.250",
        "lastModified": "2026-07-20T19:17:19.847",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16224",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A MoviePilot API operation lacks adequate authorization, but the public record does not identify the protected object or failing permission check.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380046",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380046/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16224",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858227",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/jxxghp/MoviePilot/issues/5916",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/jxxghp/MoviePilot/commit/dc2b6910a423b3bfadeffaa303e1ba75cfb33900",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/jxxghp/MoviePilot/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-16225",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:29:33.863Z",
      "date_published": "2026-07-19T08:00:09.002Z",
      "date_updated": "2026-07-20T13:56:09.501Z",
      "publisher": "VulDB",
      "title": "davenardella snap7 s7_peer.cpp NegotiatePDULength out-of-bounds write",
      "affected": {
        "vendors": [
          "davenardella"
        ],
        "products": [
          {
            "vendor": "davenardella",
            "product": "snap7"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13711
      },
      "nvd": {
        "published": "2026-07-19T09:17:01.423",
        "lastModified": "2026-07-20T15:16:36.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16225",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In snap7, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380047",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380047/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16225",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858228",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/davenardella/snap7/issues/17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/davenardella/snap7/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:31:42.400Z",
      "date_published": "2026-07-19T08:15:08.198Z",
      "date_updated": "2026-07-20T13:20:54.419Z",
      "publisher": "VulDB",
      "title": "SourceCodester Pizzafy Ecommerce System admin_class_novo.php save_settings unrestricted upload",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Pizzafy Ecommerce System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.8,
          "severity": "",
          "vector": "AV:N/AC:L/Au:M/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12348
      },
      "nvd": {
        "published": "2026-07-19T09:17:01.593",
        "lastModified": "2026-07-20T14:16:55.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16226",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pizzafy Ecommerce System accepts an uploaded file without enforcing the type, destination, or execution restrictions required for that upload boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380048",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380048/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16226",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858229",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16227",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:33:24.082Z",
      "date_published": "2026-07-19T09:15:08.545Z",
      "date_updated": "2026-07-22T14:39:03.250Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_subject.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18018
      },
      "nvd": {
        "published": "2026-07-19T10:16:31.380",
        "lastModified": "2026-07-22T15:16:52.900",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16227",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ID parameter in edit_subject.php is incorporated into SQL without preserving the query grammar boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380049",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380049/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16227",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858246",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/fichterclapsaddle879-rgb/MyCve/issues/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16228",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:33:27.923Z",
      "date_published": "2026-07-19T09:30:08.971Z",
      "date_updated": "2026-07-20T10:25:41.258Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.1802
      },
      "nvd": {
        "published": "2026-07-19T10:16:32.677",
        "lastModified": "2026-07-20T13:30:32.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16228",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Class and Exam Timetabling System incorporates ID into an SQL statement without parameterization, allowing input syntax to alter the database query.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380050",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380050/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16228",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858247",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/fichterclapsaddle879-rgb/MyCve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16229",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:34:47.018Z",
      "date_published": "2026-07-19T09:45:08.064Z",
      "date_updated": "2026-07-21T14:52:29.755Z",
      "publisher": "VulDB",
      "title": "itsourcecode Courier Management System index.php cross site scripting",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Courier Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19437
      },
      "nvd": {
        "published": "2026-07-19T10:16:32.830",
        "lastModified": "2026-07-21T16:17:06.350",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16229",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Courier Management System renders the page argument from index.php as HTML without neutralizing script syntax.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380051",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380051/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16229",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858250",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/saintpierrezgnk4950-pixel/CVE-project/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T12:14:17.233Z",
      "date_published": "2026-07-22T13:53:09.830Z",
      "date_updated": "2026-08-02T07:06:06.363Z",
      "publisher": "checkpoint",
      "title": "Authentication Bypass in the SmartConsole Login Process Using an Application Token",
      "affected": {
        "vendors": [
          "checkpoint"
        ],
        "products": [
          {
            "vendor": "checkpoint",
            "product": "Quantum Security Management"
          },
          {
            "vendor": "checkpoint",
            "product": "Multi-Domain Security Management"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:cve@checkpoint.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.71391,
        "percentile": 0.99353
      },
      "official_kev": {
        "cveID": "CVE-2026-16232",
        "vendorProject": "Check Point",
        "product": "SmartConsole",
        "vulnerabilityName": "Check Point SmartConsole Improper Authentication Vulnerability",
        "dateAdded": "2026-07-22",
        "shortDescription": "Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-07-25",
        "knownRansomwareCampaignUse": "Unknown",
        "notes": "https://support.checkpoint.com/results/sk/sk185169/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-16232",
        "cwes": [
          "CWE-287"
        ]
      },
      "nvd": {
        "published": "2026-07-22T14:17:15.513",
        "lastModified": "2026-08-03T12:15:13.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16232",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "high",
        "mechanism": "SmartConsole accepts an application login token that grants unauthenticated administrative access, but the public advisory does not identify the failing token check.",
        "basis": [
          "CNA",
          "CWE-287",
          "Check Point advisory"
        ],
        "deepDive": true,
        "notes": "Read https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/amp/; Check Point confirms active exploitation and the application-token login boundary but does not publish the exact failing validation check."
      },
      "references": [
        {
          "url": "https://support.checkpoint.com/results/sk/sk185169",
          "host": "support.checkpoint.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-16235",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:48:13.976Z",
      "date_published": "2026-07-20T07:02:11.216Z",
      "date_updated": "2026-07-20T18:38:12.633Z",
      "publisher": "CPANSec",
      "title": "Crypt::Password versions through 0.28 for Perl generate insecure random values for salts",
      "affected": {
        "vendors": [
          "DRSTEVE"
        ],
        "products": [
          {
            "vendor": "DRSTEVE",
            "product": "Crypt::Password"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00357,
        "percentile": 0.28418
      },
      "nvd": {
        "published": "2026-07-20T07:16:37.320",
        "lastModified": "2026-07-20T19:17:19.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16235",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crypt::Password generates salts with the predictable non-cryptographic rand function.",
        "basis": [
          "CNA",
          "CWE-338"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/DRSTEVE/Crypt-Password-0.28/source/lib/Crypt/Password.pm#L306-309",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16236",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T19:56:51.970Z",
      "date_published": "2026-07-31T05:35:23.287Z",
      "date_updated": "2026-07-31T15:58:37.707Z",
      "publisher": "Wordfence",
      "title": "Realtyna Organic IDX plugin + WPL Real Estate <= 5.3.0 - Authenticated (Subscriber+) Arbitrary File Upload",
      "affected": {
        "vendors": [
          "realtyna"
        ],
        "products": [
          {
            "vendor": "realtyna",
            "product": "Realtyna Organic IDX plugin + WPL Real Estate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00629,
        "percentile": 0.46697
      },
      "nvd": {
        "published": "2026-07-31T07:16:27.257",
        "lastModified": "2026-07-31T16:16:58.663",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16236",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4a64f840-8570-4f98-8b72-27bee1607fc2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/tags/5.3.0/libraries/idx/idx_property_mapper.php#L392",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/tags/5.3.0/views/backend/addon_idx/wpl_ajax.php#L238",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/tags/5.3.0/api/init.php#L8",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/tags/5.3.0/libraries/idx/addon_idxn.php#L562",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 563,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16242",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T05:06:35.638Z",
      "date_published": "2026-07-20T07:33:16.712Z",
      "date_updated": "2026-08-04T12:09:27.081Z",
      "publisher": "redhat",
      "title": "Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1"
          },
          {
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.11.0"
          },
          {
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.17"
          },
          {
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.6"
          },
          {
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.8"
          },
          {
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4.22"
          },
          {
            "vendor": "Red Hat",
            "product": "Logging Subsystem for Red Hat OpenShift"
          },
          {
            "vendor": "Red Hat",
            "product": "Multicluster Engine for Kubernetes"
          },
          {
            "vendor": "Red Hat",
            "product": "OpenShift API for Data Protection"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 36,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00609,
        "percentile": 0.45754
      },
      "nvd": {
        "published": "2026-07-20T08:16:29.833",
        "lastModified": "2026-08-04T13:17:36.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16242",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47388",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47949",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47953",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47974",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48284",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48693",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16242",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502690",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/openshift/hypershift/pull/9031",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 456,
        "referenceCount": 11,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 12,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-16243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T06:42:55.700Z",
      "date_published": "2026-07-21T17:46:25.674Z",
      "date_updated": "2026-07-22T19:02:01.222Z",
      "publisher": "eclipse",
      "title": "Eclipse OMR : arraycmp SIMD implementation does not check if the number of bytes to compare is zero",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse OMR"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22479
      },
      "nvd": {
        "published": "2026-07-21T18:16:56.727",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16243",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SIMD array comparison path handles a zero-byte comparison without the required early boundary check.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/eclipse-omr/omr/pull/8349",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/eclipse-omr/omr/pull/8348",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/195",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16244",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T06:58:31.899Z",
      "date_published": "2026-07-20T12:15:09.006Z",
      "date_updated": "2026-07-20T19:08:29.087Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System prescriptionorderreport.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10075
      },
      "nvd": {
        "published": "2026-07-20T13:16:55.897",
        "lastModified": "2026-07-20T19:17:20.123",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16244",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380535",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380535/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16244",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858260",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ltranquility/submit_vuln/issues/10",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T06:59:08.963Z",
      "date_published": "2026-07-20T11:51:40.416Z",
      "date_updated": "2026-07-20T13:02:48.220Z",
      "publisher": "bizerba",
      "title": "Insecure permission assignment due to execution of LogPathConfig.exe during setup",
      "affected": {
        "vendors": [
          "Bizerba SE & Co. KG"
        ],
        "products": [
          {
            "vendor": "Bizerba SE & Co. KG",
            "product": "BRAIN2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:0beee27a-7d8c-424f-8e46-ac453fa147e6",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01678
      },
      "nvd": {
        "published": "2026-07-20T12:17:56.087",
        "lastModified": "2026-07-21T20:25:45.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16246",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Installation or startup assigns a broader default permission than the product's intended private scope.",
        "basis": [
          "CNA",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.bizerba.com/downloads/global/information-security/2026/bizerba-sa-2026-0003.pdf",
          "host": "www.bizerba.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16247",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T07:04:24.445Z",
      "date_published": "2026-07-20T11:54:37.566Z",
      "date_updated": "2026-07-20T12:55:40.988Z",
      "publisher": "bizerba",
      "title": "Insecure permission overwrite due to execution of LogPathConfig.exe while installing _connect.BRAIN",
      "affected": {
        "vendors": [
          "Bizerba SE & Co. KG"
        ],
        "products": [
          {
            "vendor": "Bizerba SE & Co. KG",
            "product": "_connect.BRAIN"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:0beee27a-7d8c-424f-8e46-ac453fa147e6",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00103,
        "percentile": 0.01168
      },
      "nvd": {
        "published": "2026-07-20T12:17:56.230",
        "lastModified": "2026-07-21T20:25:45.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16247",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The installer replaces ProgramData permissions with an Everyone full-control grant instead of limiting that grant to the application directories.",
        "basis": [
          "CNA",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.bizerba.com/downloads/global/information-security/2026/bizerba-sa-2026-0003.pdf",
          "host": "www.bizerba.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16248",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T07:14:01.898Z",
      "date_published": "2026-07-20T12:45:10.966Z",
      "date_updated": "2026-07-20T13:50:32.452Z",
      "publisher": "VulDB",
      "title": "Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow",
      "affected": {
        "vendors": [
          "Tenda"
        ],
        "products": [
          {
            "vendor": "Tenda",
            "product": "AC10"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 9,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00466,
        "percentile": 0.38005
      },
      "nvd": {
        "published": "2026-07-20T13:16:56.190",
        "lastModified": "2026-07-20T15:16:36.400",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16248",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The fromAdvSetLanip handler copies caller-controlled values beyond a stack buffer.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380539",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380539/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16248",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858411",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/teiwiet/tenda-ac10-vulnerabilities/blob/main/advisory-fromAdvSetLanip.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.tenda.com.cn/",
          "host": "www.tenda.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T07:28:11.371Z",
      "date_published": "2026-07-20T14:00:41.298Z",
      "date_updated": "2026-07-20T14:58:42.633Z",
      "publisher": "VulDB",
      "title": "Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection",
      "affected": {
        "vendors": [
          "Beijing Shenzhou Shihan Technology"
        ],
        "products": [
          {
            "vendor": "Beijing Shenzhou Shihan Technology",
            "product": "Multimedia Integrated Business Display System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18018
      },
      "nvd": {
        "published": "2026-07-20T15:16:36.540",
        "lastModified": "2026-07-20T17:14:14.557",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16252",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380551",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380551/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16252",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858453",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/docx/XSuvdAP8foTOKzxEnZaclsZznMb?from=from_copylink",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-vvp7-h4fj-m28w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 451,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16254",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T08:01:11.264Z",
      "date_published": "2026-07-20T10:42:02.327Z",
      "date_updated": "2026-07-20T13:03:28.164Z",
      "publisher": "redhat",
      "title": "Claircore: claircore: denial of service via out-of-bounds slice in claircore's apk installed-database parser",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Security 4"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Quay 3"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19332
      },
      "nvd": {
        "published": "2026-07-20T12:17:56.373",
        "lastModified": "2026-07-21T18:31:51.680",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16254",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Malformed apk database data drives an out-of-bounds slice access that panics the package scanner.",
        "basis": [
          "CNA record",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16254",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502701",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16266",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T08:55:21.686Z",
      "date_published": "2026-07-21T05:00:00.647Z",
      "date_updated": "2026-07-21T14:52:06.858Z",
      "publisher": "snyk",
      "title": "Versions of the package mongo-object before 3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "mongo-object"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:report@snyk.io",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:report@snyk.io",
          "type": "Secondary",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16049
      },
      "nvd": {
        "published": "2026-07-21T06:16:28.737",
        "lastModified": "2026-07-23T15:48:25.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16266",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mongo-object allows special property names to modify the shared JavaScript object prototype.",
        "basis": [
          "CNA",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.snyk.io/vuln/SNYK-JS-MONGOOBJECT-13816714",
          "host": "security.snyk.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/longshotlabs/mongo-object/issues/27",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/longshotlabs/mongo-object/blob/4f7a570f2a2fcfa9417b7870d5f859e9574ec73c/src/util.ts%23L251",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/longshotlabs/mongo-object/commit/638314107d8b397e5453c28e41729522b3e8d67c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16270",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T09:17:36.606Z",
      "date_published": "2026-07-22T12:37:13.205Z",
      "date_updated": "2026-07-22T18:55:41.693Z",
      "publisher": "CERT-PL",
      "title": "ReDoS in Open Mercato",
      "affected": {
        "vendors": [
          "Open Mercato"
        ],
        "products": [
          {
            "vendor": "Open Mercato",
            "product": "Open Mercato"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20011
      },
      "nvd": {
        "published": "2026-07-22T13:16:36.990",
        "lastModified": "2026-07-22T20:54:47.023",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16270",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application applies an attacker-controlled string to a backtracking regular expression whose worst-case work is not bounded.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-16270",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.openmercato.com/",
          "host": "www.openmercato.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/open-mercato/open-mercato/pull/1996",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16277",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T10:05:24.721Z",
      "date_published": "2026-07-20T14:09:38.333Z",
      "date_updated": "2026-07-21T15:30:21.219Z",
      "publisher": "redhat",
      "title": "Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20052
      },
      "nvd": {
        "published": "2026-07-20T15:16:36.720",
        "lastModified": "2026-07-21T18:31:51.680",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16277",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Red Hat Enterprise Linux 10, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16277",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2462085",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://git.linux-nfs.org/?p=steved/rpcbind.git;a=commitdiff;h=bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d",
          "host": "git.linux-nfs.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.linuxfromscratch.org/blfs/advisories/consolidated.html",
          "host": "www.linuxfromscratch.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16280",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T10:54:34.067Z",
      "date_published": "2026-07-24T22:02:38.245Z",
      "date_updated": "2026-07-27T16:02:36.595Z",
      "publisher": "imaginationtech",
      "title": "GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset",
      "affected": {
        "vendors": [
          "Imagination Technologies"
        ],
        "products": [
          {
            "vendor": "Imagination Technologies",
            "product": "Graphics DDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21768
      },
      "nvd": {
        "published": "2026-07-24T23:16:50.393",
        "lastModified": "2026-07-28T16:17:58.820",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16280",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An arithmetic operation can wrap before the result is used for a memory size or offset, invalidating the later bounds assumption.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
          "host": "www.imaginationtech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 339,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-16287",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T12:08:18.724Z",
      "date_published": "2026-07-23T07:44:03.591Z",
      "date_updated": "2026-07-23T14:00:45.291Z",
      "publisher": "TR-CERT",
      "title": "Root Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-update",
      "affected": {
        "vendors": [
          "TUBITAK BILGEM Software Technologies Research Institute"
        ],
        "products": [
          {
            "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
            "product": "pardus-update"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38492
      },
      "nvd": {
        "published": "2026-07-23T09:16:26.570",
        "lastModified": "2026-07-23T15:01:24.377",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16287",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The offline-update path incorporates attacker-controlled values into a root OS command without shell-safe separation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0609",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 266,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16308",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T14:31:00.798Z",
      "date_published": "2026-07-30T14:04:42.806Z",
      "date_updated": "2026-07-30T16:20:01.475Z",
      "publisher": "ibm",
      "title": "IBM Enterprise Build of Quarkus is affected by a DoS vulnerability",
      "affected": {
        "vendors": [
          "IBM"
        ],
        "products": [
          {
            "vendor": "IBM",
            "product": "Enterprise Build of Quarkus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@us.ibm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00549,
        "percentile": 0.42859
      },
      "nvd": {
        "published": "2026-07-30T15:16:26.910",
        "lastModified": "2026-07-30T17:16:28.837",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16308",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Enterprise Build of Quarkus path allocates attacker-driven resources without an effective bound or throttle.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7281904",
          "host": "www.ibm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16313",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T15:35:41.936Z",
      "date_published": "2026-07-28T16:47:06.471Z",
      "date_updated": "2026-07-28T19:34:45.732Z",
      "publisher": "redhat",
      "title": "Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15674
      },
      "nvd": {
        "published": "2026-07-28T17:16:37.807",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16313",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A newline in a SCSI device name creates additional udev properties because the value is not separated from the property grammar.",
        "basis": [
          "CNA",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16313",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502845",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/doug-gilbert/sg3_utils/pull/83",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 453,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16317",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T16:40:27.027Z",
      "date_published": "2026-07-21T20:12:48.047Z",
      "date_updated": "2026-07-22T19:41:19.156Z",
      "publisher": "AMZN",
      "title": "Silent Drop of TLS 1.3 Encrypted Records in s2n-tls",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "s2n-tls"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-354",
          "name": "Improper Validation of Integrity Check Value",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 1.8000000000000007,
      "epss": {
        "score": 0.00186,
        "percentile": 0.0842
      },
      "nvd": {
        "published": "2026-07-21T21:16:49.060",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16317",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The s2n-tls TLS record path omits the received outer content type from authenticated validation, allowing records to be silently discarded.",
        "basis": [
          "CNA",
          "CWE-354"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aws/s2n-tls/releases/tag/v1.7.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-062-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/aws/s2n-tls/security/advisories/GHSA-684c-v35q-fvx7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1190,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16318",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T16:42:03.595Z",
      "date_published": "2026-07-21T20:14:02.363Z",
      "date_updated": "2026-07-22T19:41:13.270Z",
      "publisher": "AMZN",
      "title": "QUIC Transport Parameters Memory Leak During HelloRetryRequest in s2n-tls",
      "affected": {
        "vendors": [
          "Amazon"
        ],
        "products": [
          {
            "vendor": "Amazon",
            "product": "s2n-tls"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31552
      },
      "nvd": {
        "published": "2026-07-21T21:16:49.220",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16318",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "s2n allocates a replacement ClientHello buffer during HelloRetryRequest without releasing the first allocation.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aws/s2n-tls/releases/tag/v1.7.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://staging.prod.website.marketing.aws.dev/security/security-bulletins/2026-062-aws/",
          "host": "staging.prod.website.marketing.aws.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/aws/s2n-tls/security/advisories/GHSA-cr7x-863j-xrc7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 985,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16324",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:42:36.229Z",
      "date_published": "2026-07-20T21:45:34.859Z",
      "date_updated": "2026-07-22T14:37:07.817Z",
      "publisher": "VulDB",
      "title": "Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload",
      "affected": {
        "vendors": [
          "Metasoft 美特软件"
        ],
        "products": [
          {
            "vendor": "Metasoft 美特软件",
            "product": "MetaCRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20037
      },
      "nvd": {
        "published": "2026-07-20T22:17:13.417",
        "lastModified": "2026-07-22T15:16:53.037",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16324",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MetaCRM /business/qnaire/upload.jsp accepts the caller-controlled File argument without restricting the uploaded object, enabling an unrestricted upload.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380685",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380685/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16324",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858454",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/docx/RTF0d4zxooIMA1xF9bGcnQNpnfg?from=from_copylink",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 404,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16326",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:50:16.465Z",
      "date_published": "2026-07-29T18:40:08.796Z",
      "date_updated": "2026-07-29T19:10:11.027Z",
      "publisher": "HashiCorp",
      "title": "consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode",
      "affected": {
        "vendors": [
          "HashiCorp"
        ],
        "products": [
          {
            "vendor": "HashiCorp",
            "product": "Tooling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-488",
          "name": "Exposure of Data Element to Wrong Session",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security@hashicorp.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22195
      },
      "nvd": {
        "published": "2026-07-29T19:16:44.900",
        "lastModified": "2026-07-30T14:08:23.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16326",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Stateless streamable-HTTP mode retains one client session token and reuses it for later clients.",
        "basis": [
          "CNA",
          "CWE-488"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.hashicorp.com/t/hcsec-2026-24-multiple-vulnerabilities-impacting-hashicorp-consul-mcp-server/77612",
          "host": "discuss.hashicorp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 291,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16327",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:50:18.490Z",
      "date_published": "2026-07-20T23:45:36.843Z",
      "date_updated": "2026-07-21T13:07:14.068Z",
      "publisher": "VulDB",
      "title": "D-Link DNS-320 upload.php unrestricted upload",
      "affected": {
        "vendors": [
          "D-Link"
        ],
        "products": [
          {
            "vendor": "D-Link",
            "product": "DNS-320"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00728,
        "percentile": 0.50637
      },
      "nvd": {
        "published": "2026-07-21T00:16:53.570",
        "lastModified": "2026-07-21T17:07:04.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16327",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path accepts attacker-controlled file content or names without enforcing the intended storage and executable-content boundary.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380693",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380693/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16327",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858455",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.dlink.com/",
          "host": "www.dlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 313,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:50:23.169Z",
      "date_published": "2026-07-29T18:32:39.870Z",
      "date_updated": "2026-07-29T19:11:05.959Z",
      "publisher": "HashiCorp",
      "title": "consul-mcp-server vulnerable to server side request forgery leading to token exposure",
      "affected": {
        "vendors": [
          "HashiCorp"
        ],
        "products": [
          {
            "vendor": "HashiCorp",
            "product": "Tooling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@hashicorp.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.1417
      },
      "nvd": {
        "published": "2026-07-29T19:16:45.060",
        "lastModified": "2026-07-30T14:08:23.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16328",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A Consul MCP request header can replace the configured backend URL, causing the server to send authenticated requests to an attacker-selected destination.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.hashicorp.com/t/hcsec-2026-24-multiple-vulnerabilities-impacting-hashicorp-consul-mcp-server/77612",
          "host": "discuss.hashicorp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 466,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16329",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:50:23.369Z",
      "date_published": "2026-07-21T00:15:34.274Z",
      "date_updated": "2026-07-22T13:58:41.989Z",
      "publisher": "VulDB",
      "title": "D-Link DNS-320 uploadify.php unrestricted upload",
      "affected": {
        "vendors": [
          "D-Link"
        ],
        "products": [
          {
            "vendor": "D-Link",
            "product": "DNS-320"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.0054,
        "percentile": 0.424
      },
      "nvd": {
        "published": "2026-07-21T01:16:29.117",
        "lastModified": "2026-07-22T14:17:15.653",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16329",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path accepts a file type that can become executable content at the selected storage destination.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380694",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380694/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16329",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858462",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/docx/MBHDdPBz4oUXa9xCdujchmPZneg?from=from_copylink",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.dlink.com/",
          "host": "www.dlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16330",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:50:27.949Z",
      "date_published": "2026-07-21T00:30:36.811Z",
      "date_updated": "2026-07-21T14:55:48.546Z",
      "publisher": "VulDB",
      "title": "D-Link DNS-320 uploadify.php unrestricted upload",
      "affected": {
        "vendors": [
          "D-Link"
        ],
        "products": [
          {
            "vendor": "D-Link",
            "product": "DNS-320"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00728,
        "percentile": 0.50638
      },
      "nvd": {
        "published": "2026-07-21T01:16:29.280",
        "lastModified": "2026-07-21T17:07:04.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16330",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DNS-320 accepts an uploaded file without enforcing the file type and destination restrictions required for executable content.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380696",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380696/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16330",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858463",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/docx/EkMxdLlavojfsXxzKXec5yUknEg?from=from_copylink",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.dlink.com/",
          "host": "www.dlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16331",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:50:32.688Z",
      "date_published": "2026-07-21T00:45:35.644Z",
      "date_updated": "2026-07-22T14:15:55.059Z",
      "publisher": "VulDB",
      "title": "D-Link DNS-320 save_ajax.php unrestricted upload",
      "affected": {
        "vendors": [
          "D-Link"
        ],
        "products": [
          {
            "vendor": "D-Link",
            "product": "DNS-320"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00728,
        "percentile": 0.50638
      },
      "nvd": {
        "published": "2026-07-21T01:16:29.450",
        "lastModified": "2026-07-22T15:16:53.167",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16331",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "save_ajax.php accepts an uploaded object without restricting its type and destination to the intended upload policy.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380697",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380697/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16331",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858464",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/docx/UZ6id3F1Joqlpxxn3NFcL8r7nHb?from=from_copylink",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.dlink.com/",
          "host": "www.dlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16332",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:50:37.304Z",
      "date_published": "2026-07-21T01:30:37.580Z",
      "date_updated": "2026-07-23T14:32:43.985Z",
      "publisher": "VulDB",
      "title": "D-Link DNS-320 multi_uploadify.php unrestricted upload",
      "affected": {
        "vendors": [
          "D-Link"
        ],
        "products": [
          {
            "vendor": "D-Link",
            "product": "DNS-320"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.0054,
        "percentile": 0.42399
      },
      "nvd": {
        "published": "2026-07-21T03:16:40.833",
        "lastModified": "2026-07-23T15:16:59.197",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16332",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The D-Link upload endpoint accepts Filedata content without enforcing the intended file-type or storage-object restriction.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380698",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380698/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16332",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858465",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/docx/EbAkdl1v8oC3Q3xAEJLcZFcZnMY?from=from_copylink",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.dlink.com/",
          "host": "www.dlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 307,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16334",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:00:34.243Z",
      "date_published": "2026-07-21T02:00:09.340Z",
      "date_updated": "2026-07-22T15:32:24.475Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System prescriptionorder.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10075
      },
      "nvd": {
        "published": "2026-07-21T03:16:41.007",
        "lastModified": "2026-07-22T16:17:12.560",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16334",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The editid parameter is incorporated into a prescriptionorder.php SQL statement without safe parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380703",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380703/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16334",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858648",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/LiamJim/cve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 309,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:06:42.878Z",
      "date_published": "2026-07-21T02:30:09.393Z",
      "date_updated": "2026-07-21T13:23:59.700Z",
      "publisher": "VulDB",
      "title": "trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect",
      "affected": {
        "vendors": [
          "trinodb"
        ],
        "products": [
          {
            "vendor": "trinodb",
            "product": "trino"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17446
      },
      "nvd": {
        "published": "2026-07-21T04:16:50.310",
        "lastModified": "2026-07-21T17:07:04.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16336",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The trino redirect path accepts an external destination without restricting it to a trusted origin.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380710",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380710/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16336",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858687",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/trinodb/trino/issues/29754",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/trinodb/trino/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 414,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16337",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:45.781Z",
      "date_published": "2026-07-20T19:15:11.190Z",
      "date_updated": "2026-07-21T12:45:11.144Z",
      "publisher": "dotCMS",
      "title": "Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.",
      "affected": {
        "vendors": [
          "dotCMS"
        ],
        "products": [
          {
            "vendor": "dotCMS",
            "product": "dotCMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@dotcms.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.004,
        "percentile": 0.32814
      },
      "nvd": {
        "published": "2026-07-20T20:16:43.387",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16337",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Low-privileged backend users can use ToolGroupResource and RoleAjax to grant themselves the administrator layout and role.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dotCMS/core/pull/36344",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16347",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T20:41:22.596Z",
      "date_published": "2026-07-28T19:59:29.927Z",
      "date_updated": "2026-07-29T13:57:56.713Z",
      "publisher": "icscert",
      "title": "Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router",
      "affected": {
        "vendors": [
          "MikroTik"
        ],
        "products": [
          {
            "vendor": "MikroTik",
            "product": "RouterOS"
          },
          {
            "vendor": "MikroTik",
            "product": "Cloud Hosted Router"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14322
      },
      "nvd": {
        "published": "2026-07-28T20:17:23.713",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16347",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The authentication service permits repeated guesses without a rate, account, or source bound that survives concurrent connections.",
        "basis": [
          "CNA",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 627,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:55:46.392Z",
      "date_published": "2026-07-21T12:37:31.917Z",
      "date_updated": "2026-07-22T19:18:14.229Z",
      "publisher": "mozilla",
      "title": "Same-origin policy bypass in the DOM: Navigation component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12029
      },
      "nvd": {
        "published": "2026-07-21T13:17:03.370",
        "lastModified": "2026-07-24T15:43:33.153",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16349",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The DOM Navigation component fails to preserve the same-origin boundary for an unspecified navigation case, permitting data or authority to cross between origins.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-346",
          "Mozilla advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Mozilla MFSA 2026-68 at https://www.mozilla.org/security/advisories/mfsa2026-68/; it confirms a same-origin-policy bypass in DOM Navigation and the fixed releases, while the linked bug is access-restricted and the exact origin comparison or navigation state is not public."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2034682",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16350",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:55:48.638Z",
      "date_published": "2026-07-21T12:37:32.759Z",
      "date_updated": "2026-07-22T19:18:15.333Z",
      "publisher": "mozilla",
      "title": "Incorrect boundary conditions in the Audio/Video: cubeb component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33308
      },
      "nvd": {
        "published": "2026-07-21T13:17:03.470",
        "lastModified": "2026-07-24T15:44:00.047",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16350",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The cubeb component applies incorrect memory boundary conditions, although Mozilla does not publish the affected buffer, arithmetic, or operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-119",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Mozilla advisory MFSA-2026-68 at https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/; it confirms the cubeb component and Firefox 153 repair, while https://bugzilla.mozilla.org/show_bug.cgi?id=2042033 is permission-restricted and the exact boundary error remains non-public."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2042033",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:55:50.743Z",
      "date_published": "2026-07-21T12:37:34.438Z",
      "date_updated": "2026-07-22T19:18:17.433Z",
      "publisher": "mozilla",
      "title": "Sandbox escape due to use-after-free in the DOM: Navigation component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00394,
        "percentile": 0.32141
      },
      "nvd": {
        "published": "2026-07-21T13:17:03.577",
        "lastModified": "2026-07-24T15:45:51.413",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16351",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Firefox continues to access an object after its storage has been released, allowing invalid heap use and possible corruption.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2045468",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:55:52.955Z",
      "date_published": "2026-07-21T12:37:35.292Z",
      "date_updated": "2026-07-22T19:18:18.625Z",
      "publisher": "mozilla",
      "title": "Sandbox escape due to use-after-free in the Disability Access APIs component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00394,
        "percentile": 0.3214
      },
      "nvd": {
        "published": "2026-07-21T13:17:03.693",
        "lastModified": "2026-07-24T15:47:35.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16352",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Disability Access APIs component can use an object after it has been freed, enabling a sandbox escape.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2046416",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:55:55.027Z",
      "date_published": "2026-07-21T12:37:39.485Z",
      "date_updated": "2026-07-22T19:18:24.106Z",
      "publisher": "mozilla",
      "title": "Invalid pointer in the DOM: Bindings (WebIDL) component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-824",
          "name": "Access of Uninitialized Pointer",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33308
      },
      "nvd": {
        "published": "2026-07-21T13:17:03.793",
        "lastModified": "2026-07-24T15:50:44.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16353",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The DOM WebIDL binding component handles an invalid pointer, but public records do not distinguish a use-after-free, null dereference, or uninitialized-pointer access.",
        "basis": [
          "CNA",
          "CWE-416",
          "CWE-476",
          "CWE-824",
          "Mozilla advisory"
        ],
        "deepDive": true,
        "notes": "Read https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/; the advisory identifies an invalid pointer in DOM WebIDL bindings, while the linked bug details were not publicly retrievable and the pointer-lifetime subtype remains unresolved."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2049523",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 182,
        "referenceCount": 6,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16354",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:55:56.965Z",
      "date_published": "2026-07-21T12:37:40.337Z",
      "date_updated": "2026-07-22T19:18:25.205Z",
      "publisher": "mozilla",
      "title": "Information disclosure in the Graphics: ImageLib component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00341,
        "percentile": 0.26717
      },
      "nvd": {
        "published": "2026-07-21T13:17:03.893",
        "lastModified": "2026-07-24T15:51:49.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16354",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Mozilla reports information disclosure in ImageLib but does not disclose the exposed bytes, object lifetime, boundary check, or output path.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2050626",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16355",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:55:59.129Z",
      "date_published": "2026-07-21T12:37:43.741Z",
      "date_updated": "2026-07-22T19:18:29.451Z",
      "publisher": "mozilla",
      "title": "JIT miscompilation in the JavaScript Engine: JIT component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33308
      },
      "nvd": {
        "published": "2026-07-21T13:17:04.000",
        "lastModified": "2026-07-24T15:27:33.097",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16355",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Firefox miscompiles JavaScript JIT code in a way classified as type confusion, while the public advisory and restricted bug omit the faulty optimization and value transition.",
        "basis": [
          "CNA",
          "CWE-843",
          "Mozilla MFSA 2026-68"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/ and attempted the linked Bugzilla record 2052207, which is access-restricted; the public source does not disclose the faulty JIT optimization."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2052207",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16356",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:01.537Z",
      "date_published": "2026-07-21T12:37:44.585Z",
      "date_updated": "2026-07-22T19:18:30.529Z",
      "publisher": "mozilla",
      "title": "Sandbox escape due to use-after-free in the Disability Access APIs component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00394,
        "percentile": 0.3214
      },
      "nvd": {
        "published": "2026-07-21T13:17:04.100",
        "lastModified": "2026-07-24T15:28:09.227",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16356",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Sandbox escape due to use-after-free in the Disability Access APIs component.",
        "basis": [
          "CNA",
          "CWE-416",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2052562",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16357",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:03.705Z",
      "date_published": "2026-07-21T12:37:45.425Z",
      "date_updated": "2026-07-22T19:18:31.600Z",
      "publisher": "mozilla",
      "title": "Incorrect boundary conditions in the Graphics component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33308
      },
      "nvd": {
        "published": "2026-07-21T13:17:04.207",
        "lastModified": "2026-07-24T15:28:40.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16357",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A Graphics boundary calculation is incorrect, but Mozilla's public advisory does not identify the buffer, index, or failed comparison.",
        "basis": [
          "CNA",
          "CWE-119",
          "https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/. Mozilla's advisory identifies the Graphics component and links Bug 2053326, but the public advisory does not expose the boundary calculation or patch."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2053326",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 182,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16358",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:05.445Z",
      "date_published": "2026-07-21T12:37:54.669Z",
      "date_updated": "2026-07-22T19:18:42.429Z",
      "publisher": "mozilla",
      "title": "Site isolation issue in the Graphics: WebRender component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12103
      },
      "nvd": {
        "published": "2026-07-21T13:17:04.310",
        "lastModified": "2026-07-24T15:29:32.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16358",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Mozilla identifies a WebRender site-isolation boundary failure, while the public advisory does not disclose the origin comparison or rendering transition that fails.",
        "basis": [
          "CNA",
          "CWE-346",
          "Mozilla MFSA 2026-68"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/, which links Bug 2040119; Mozilla publishes the affected component, fixed release, reporter and bug ID, but the reviewed public material supplies no causal detail or patch for the site-isolation failure."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2040119",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 184,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:07.912Z",
      "date_published": "2026-07-21T12:38:07.338Z",
      "date_updated": "2026-07-22T19:18:58.528Z",
      "publisher": "mozilla",
      "title": "Incorrect boundary conditions in the Audio/Video: GMP component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18044
      },
      "nvd": {
        "published": "2026-07-21T13:17:04.413",
        "lastModified": "2026-07-24T15:32:32.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16359",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The GMP audio/video component applies an incorrect memory boundary, but Mozilla's public advisory and restricted bug do not disclose the failing buffer operation.",
        "basis": [
          "CNA",
          "CWE-119",
          "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "https://bugzilla.mozilla.org/show_bug.cgi?id=2045424"
        ],
        "deepDive": true,
        "notes": "Mozilla's advisory identifies the GMP component and incorrect boundary conditions; the linked Bugzilla record was not publicly readable during review, so the exact buffer operation remains unknown."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2045424",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16360",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:09.806Z",
      "date_published": "2026-07-21T12:38:24.293Z",
      "date_updated": "2026-07-24T03:55:35.214Z",
      "publisher": "mozilla",
      "title": "Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25131
      },
      "nvd": {
        "published": "2026-07-21T13:17:04.517",
        "lastModified": "2026-07-24T15:07:50.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16360",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Mozilla groups multiple memory-safety bugs with evidence of corruption under this CVE without publishing one common bounds, ownership, or lifetime failure.",
        "basis": [
          "CNA",
          "CWE-119",
          "Mozilla security advisories"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/, https://www.mozilla.org/en-US/security/advisories/mfsa2026-69/, https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/, and https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/; Mozilla confirms an aggregate of memory-safety bugs with corruption evidence, but the CVE does not expose one common causal bound or lifetime error."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022635%2C2028004%2C2035756%2C2045184%2C2045185%2C2045198%2C2045392%2C2045395%2C2045396%2C2045397%2C2045405%2C2045414%2C2045415%2C2045451%2C2045454%2C2045508%2C2045510%2C2045513%2C2045515%2C2045518%2C2045604%2C2045607%2C2045612%2C2045617%2C2045619%2C2045624%2C2045625%2C2045729%2C2045737%2C2045741%2C2045742%2C2045763%2C2045767%2C2045770%2C2045772%2C2045773%2C2045783%2C2045833%2C2045848%2C2045865%2C2045875%2C2045957%2C2047723%2C2047729%2C2048795%2C2048799%2C2048801%2C2049392%2C2049397%2C2049398%2C2049399%2C2049404%2C2049405%2C2049407%2C2049812%2C2050657%2C2050668%2C2050990%2C2053166%2C2053273%2C2053576%2C2053583%2C2053587",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2043739%2C2045281%2C2045614%2C2045744%2C2045775%2C2047719%2C2049805%2C2051666",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 369,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16361",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:10.203Z",
      "date_published": "2026-07-21T12:38:27.370Z",
      "date_updated": "2026-07-24T03:55:36.035Z",
      "publisher": "mozilla",
      "title": "Memory safety bugs fixed in Thunderbird ESR 140.13",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00309,
        "percentile": 0.23243
      },
      "nvd": {
        "published": "2026-07-21T13:17:04.637",
        "lastModified": "2026-07-24T15:52:54.023",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16361",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected Mozilla releases contain memory-safety defects that can corrupt memory, while the public advisory does not expose each lifetime or bounds error.",
        "basis": [
          "CNA",
          "CWE-119",
          "Mozilla MFSA 2026-70",
          "Mozilla MFSA 2026-72",
          "Mozilla Bugzilla response"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/, https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/, and the linked https://bugzilla.mozilla.org/buglist.cgi?bug_id=2029734%2C2036518 on 2026-08-05; both MFSAs remain aggregate memory-safety descriptions and Bugzilla returned a client-challenge page, so no individual bounds or lifetime transition could be source-traced."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2029734%2C2036518",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-69/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 307,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16362",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:10.605Z",
      "date_published": "2026-07-21T12:37:33.621Z",
      "date_updated": "2026-07-22T19:18:16.408Z",
      "publisher": "mozilla",
      "title": "Use-after-free in the WebRTC: Audio/Video component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21446
      },
      "nvd": {
        "published": "2026-07-21T13:17:04.733",
        "lastModified": "2026-07-24T15:31:47.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16362",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2043188",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 158,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16363",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:13.042Z",
      "date_published": "2026-07-21T12:37:36.171Z",
      "date_updated": "2026-07-22T19:18:19.673Z",
      "publisher": "mozilla",
      "title": "JIT miscompilation in the JavaScript: WebAssembly component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-682",
          "name": "Incorrect Calculation",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00436,
        "percentile": 0.35876
      },
      "nvd": {
        "published": "2026-07-21T13:17:04.840",
        "lastModified": "2026-07-24T15:19:35.233",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16363",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The JavaScript and WebAssembly JIT miscompiles a value so execution accesses the underlying resource through an incompatible type.",
        "basis": [
          "CNA record",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2047689",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 166,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16364",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:15.028Z",
      "date_published": "2026-07-21T12:37:36.963Z",
      "date_updated": "2026-07-23T14:55:16.635Z",
      "publisher": "mozilla",
      "title": "Incorrect boundary conditions in the Audio/Video: Playback component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00306,
        "percentile": 0.22944
      },
      "nvd": {
        "published": "2026-07-21T13:17:04.940",
        "lastModified": "2026-07-24T16:33:16.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16364",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Firefox copies attacker-controlled data without enforcing the destination buffer size.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2047802",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16365",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:17.096Z",
      "date_published": "2026-07-21T12:37:37.777Z",
      "date_updated": "2026-07-24T20:16:53.217Z",
      "publisher": "mozilla",
      "title": "Privilege escalation in the DOM: Workers component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18852
      },
      "nvd": {
        "published": "2026-07-21T13:17:05.037",
        "lastModified": "2026-07-24T21:16:43.503",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16365",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The DOM Workers component permits privilege escalation, but Mozilla's public record does not identify the incorrect subject, object, or permission check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2049149",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16366",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:19.542Z",
      "date_published": "2026-07-21T12:37:38.652Z",
      "date_updated": "2026-07-24T20:16:38.167Z",
      "publisher": "mozilla",
      "title": "Privilege escalation in the DOM: Navigation component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18852
      },
      "nvd": {
        "published": "2026-07-21T13:17:05.140",
        "lastModified": "2026-07-24T21:16:43.670",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16366",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Firefox's DOM Navigation component permits privilege escalation, but the public advisory does not disclose the protected action or missing authority check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2049181",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16367",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:21.516Z",
      "date_published": "2026-07-21T12:37:41.177Z",
      "date_updated": "2026-07-22T19:18:26.247Z",
      "publisher": "mozilla",
      "title": "Sandbox escape due to invalid pointer in the Disability Access APIs component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30274
      },
      "nvd": {
        "published": "2026-07-21T13:17:05.240",
        "lastModified": "2026-07-24T16:35:00.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16367",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Mozilla identifies an invalid pointer in the Disability Access APIs component but does not publish the lifetime transition that makes the pointer invalid.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-416",
          "Mozilla advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Mozilla advisory https://www.mozilla.org/security/advisories/mfsa2026-68/; it confirms an invalid pointer in Disability Access APIs and the fixed releases, but the linked Bugzilla issue requires permission and no lifetime transition or patch is public."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2050627",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 143,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16368",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:23.990Z",
      "date_published": "2026-07-21T12:37:41.992Z",
      "date_updated": "2026-07-22T19:18:27.328Z",
      "publisher": "mozilla",
      "title": "Incorrect boundary conditions in the JavaScript: WebAssembly component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31564
      },
      "nvd": {
        "published": "2026-07-21T13:17:05.360",
        "lastModified": "2026-07-24T15:09:35.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16368",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Firefox WebAssembly component applies an incorrect memory boundary condition, but the public advisory does not identify the operation, object, or comparison.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-119",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Mozilla advisory MFSA-2026-68 at https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/; it confirms the JavaScript: WebAssembly component, high impact, and Firefox 153 repair, while the linked Bugzilla record https://bugzilla.mozilla.org/show_bug.cgi?id=2051015 did not yield public implementation detail, so the operation and boundary check remain unknown."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2051015",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 177,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16369",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:26.427Z",
      "date_published": "2026-07-21T12:37:42.865Z",
      "date_updated": "2026-07-22T19:18:28.400Z",
      "publisher": "mozilla",
      "title": "Integer overflow in the JavaScript: WebAssembly component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00436,
        "percentile": 0.35876
      },
      "nvd": {
        "published": "2026-07-21T13:17:06.707",
        "lastModified": "2026-07-24T15:19:30.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16369",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Firefox path performs attacker-influenced integer arithmetic that can overflow and invalidate a later memory bound.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2051854",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 164,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16370",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:28.223Z",
      "date_published": "2026-07-21T12:37:46.291Z",
      "date_updated": "2026-07-22T19:18:32.701Z",
      "publisher": "mozilla",
      "title": "Mitigation bypass in the DOM: Networking component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00309,
        "percentile": 0.23206
      },
      "nvd": {
        "published": "2026-07-21T13:17:06.860",
        "lastModified": "2026-07-24T16:35:27.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16370",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Mozilla identifies a DOM Networking mitigation bypass but does not publish the mitigated condition, bypass input, or failed check.",
        "basis": [
          "CNA",
          "CWE-693",
          "https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/",
          "https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/"
        ],
        "deepDive": true,
        "notes": "Firefox and Thunderbird advisories classify this as a moderate DOM Networking mitigation bypass and link only Bug 1996495; no public description or patch identifies the bypassed condition. The embedded 9.1 score materially conflicts with Mozilla severity."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1996495",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:30.229Z",
      "date_published": "2026-07-21T12:37:47.142Z",
      "date_updated": "2026-07-24T20:16:17.696Z",
      "publisher": "mozilla",
      "title": "Privilege escalation in the DOM: Navigation component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.2
      },
      "nvd": {
        "published": "2026-07-21T13:17:12.270",
        "lastModified": "2026-07-24T21:16:43.827",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16371",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Mozilla record names privilege escalation in DOM Navigation but does not disclose the check or state transition that permits it.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2008369",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16372",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:32.371Z",
      "date_published": "2026-07-21T12:37:47.981Z",
      "date_updated": "2026-07-24T20:15:21.451Z",
      "publisher": "mozilla",
      "title": "Privilege escalation in the DOM: Content Processes component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19335
      },
      "nvd": {
        "published": "2026-07-21T13:17:12.377",
        "lastModified": "2026-07-24T21:16:43.980",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16372",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Mozilla's content process permits a privilege increase, but the public record does not identify the privileged operation or missing boundary check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2013800",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16373",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:35.174Z",
      "date_published": "2026-07-21T12:37:48.818Z",
      "date_updated": "2026-07-22T15:44:39.551Z",
      "publisher": "mozilla",
      "title": "Information disclosure in the Privacy component in Firefox for Android",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.1932
      },
      "nvd": {
        "published": "2026-07-21T13:17:12.473",
        "lastModified": "2026-07-24T16:27:12.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16373",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Mozilla reports an information disclosure in Firefox for Android Privacy without identifying the exposed data, observer, or operation that releases it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2021964",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16374",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:36.642Z",
      "date_published": "2026-07-21T12:37:49.664Z",
      "date_updated": "2026-07-22T19:18:35.967Z",
      "publisher": "mozilla",
      "title": "Information disclosure in the Framework component in DevTools",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24651
      },
      "nvd": {
        "published": "2026-07-21T13:17:12.573",
        "lastModified": "2026-07-24T15:19:25.657",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16374",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Mozilla reports information disclosure in the DevTools Framework component but does not identify the data source, observer, or output path.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2027519",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 168,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16375",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:38.613Z",
      "date_published": "2026-07-21T12:37:50.458Z",
      "date_updated": "2026-07-22T19:18:37.021Z",
      "publisher": "mozilla",
      "title": "Site isolation issue in the Networking: HTTP component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11219
      },
      "nvd": {
        "published": "2026-07-21T13:17:12.677",
        "lastModified": "2026-07-24T15:15:12.170",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16375",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Firefox's HTTP component applies site isolation incorrectly, but the public advisory does not identify the trusted origin state or failing comparison.",
        "basis": [
          "CNA",
          "CWE-346",
          "https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/. Mozilla identifies Networking: HTTP and Bug 2032140 as a site-isolation issue; the public advisory does not expose the trusted origin state or failing check."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2032140",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 161,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16376",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:40.610Z",
      "date_published": "2026-07-21T12:37:51.295Z",
      "date_updated": "2026-07-22T19:18:38.107Z",
      "publisher": "mozilla",
      "title": "Denial-of-service in the Graphics: WebGPU component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28881
      },
      "nvd": {
        "published": "2026-07-21T13:17:12.760",
        "lastModified": "2026-07-24T16:38:54.823",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16376",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Mozilla identifies attacker-controlled WebGPU work that can exhaust resources, while the public advisory does not expose the command, allocation, or missing limit.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2035733",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:42.653Z",
      "date_published": "2026-07-21T12:37:52.135Z",
      "date_updated": "2026-07-22T19:18:39.146Z",
      "publisher": "mozilla",
      "title": "Mitigation bypass in the PDF Viewer component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.3144
      },
      "nvd": {
        "published": "2026-07-21T13:17:12.870",
        "lastModified": "2026-07-24T15:19:21.707",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16377",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Mozilla identifies a PDF Viewer mitigation bypass but does not name the mitigation, trigger, security state, or bypassed comparison.",
        "basis": [
          "CNA",
          "CWE-693",
          "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "https://bugzilla.mozilla.org/show_bug.cgi?id=2037770"
        ],
        "deepDive": true,
        "notes": "MFSA 2026-68 identifies only a PDF Viewer mitigation bypass and the linked Bugzilla issue was not publicly readable during review, leaving the mitigation and trigger undisclosed."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2037770",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 152,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:44.836Z",
      "date_published": "2026-07-21T12:37:52.990Z",
      "date_updated": "2026-07-22T19:18:40.219Z",
      "publisher": "mozilla",
      "title": "Other issue in the DOM: Copy & Paste and Drag & Drop component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00306,
        "percentile": 0.22943
      },
      "nvd": {
        "published": "2026-07-21T13:17:12.967",
        "lastModified": "2026-07-24T16:39:21.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16378",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The vendor identifies only an unspecified DOM copy, paste, and drag-and-drop issue, leaving the engineering cause undisclosed.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2038868",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16379",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:46.680Z",
      "date_published": "2026-07-21T12:37:53.832Z",
      "date_updated": "2026-07-24T20:16:00.567Z",
      "publisher": "mozilla",
      "title": "Privilege escalation in the DOM: Content Processes component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20001
      },
      "nvd": {
        "published": "2026-07-21T13:17:13.067",
        "lastModified": "2026-07-24T21:16:44.130",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16379",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "The DOM content-process boundary permits privilege escalation, but the public record does not identify the failing privilege check or state transition.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2039452",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 167,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:49.052Z",
      "date_published": "2026-07-21T12:37:55.544Z",
      "date_updated": "2026-07-22T19:18:43.465Z",
      "publisher": "mozilla",
      "title": "Mitigation bypass in the Networking component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00309,
        "percentile": 0.23206
      },
      "nvd": {
        "published": "2026-07-21T13:17:13.163",
        "lastModified": "2026-07-24T16:39:45.420",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16380",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Mozilla identifies a networking mitigation bypass but does not disclose the input, state transition, policy, or check that failed.",
        "basis": [
          "CNA",
          "CWE-693",
          "Mozilla advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.mozilla.org/security/advisories/mfsa2026-68/; it identifies a Networking mitigation bypass and Bug 2040386, but the public advisory and restricted bug do not disclose the causal check or patch."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2040386",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 111,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16381",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:51.463Z",
      "date_published": "2026-07-21T12:37:56.371Z",
      "date_updated": "2026-07-22T19:18:44.571Z",
      "publisher": "mozilla",
      "title": "Same-origin policy bypass in the Networking: DNS component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00173,
        "percentile": 0.07015
      },
      "nvd": {
        "published": "2026-07-21T13:17:13.260",
        "lastModified": "2026-07-24T15:19:11.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16381",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The DNS networking component can accept an origin relationship that violates the same-origin policy, but the failing DNS condition is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-346",
          "Mozilla MFSA 2026-68"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.mozilla.org/security/advisories/mfsa2026-68/; it names the DNS component and same-origin bypass but provides no causal check, and its moderate impact label conflicts with the embedded 9.1 secondary score."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2041001",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 165,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:53.743Z",
      "date_published": "2026-07-21T12:37:57.200Z",
      "date_updated": "2026-07-22T19:18:45.620Z",
      "publisher": "mozilla",
      "title": "Mitigation bypass in the DOM: Service Workers component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00378,
        "percentile": 0.30549
      },
      "nvd": {
        "published": "2026-07-21T13:17:13.363",
        "lastModified": "2026-07-24T16:40:10.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16382",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Mozilla material says Service Worker processing bypasses a mitigation but does not disclose the mitigation or failing condition.",
        "basis": [
          "CNA",
          "CWE-693",
          "Mozilla MFSA 2026-68",
          "Mozilla MFSA 2026-71",
          "Mozilla Bugzilla 2041864 access boundary"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/, https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/, and https://bugzilla.mozilla.org/show_bug.cgi?id=2041864. The advisories repeat only the mitigation-bypass label in Service Workers, and the linked bug is access-restricted, so no failing mitigation or patch can be stated."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2041864",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:56.113Z",
      "date_published": "2026-07-21T12:37:58.017Z",
      "date_updated": "2026-07-22T19:18:46.699Z",
      "publisher": "mozilla",
      "title": "Mitigation bypass in the DOM: Networking component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.3144
      },
      "nvd": {
        "published": "2026-07-21T13:17:13.460",
        "lastModified": "2026-07-24T15:19:09.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16383",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Mozilla identifies a DOM Networking mitigation bypass but does not publicly state which mitigation check or state transition failed.",
        "basis": [
          "CNA",
          "CWE-693",
          "Mozilla MFSA 2026-68, 2026-70, 2026-71, and 2026-72"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/, https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/, https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/, and https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/; they identify a DOM Networking mitigation bypass, while the linked Bugzilla detail was not publicly readable, so the failing mitigation check remains unknown."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2041902",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 157,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16384",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:56:57.902Z",
      "date_published": "2026-07-21T12:37:58.866Z",
      "date_updated": "2026-07-22T19:18:47.737Z",
      "publisher": "mozilla",
      "title": "Information disclosure due to uninitialized memory in the Graphics: WebGPU component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23533
      },
      "nvd": {
        "published": "2026-07-21T13:17:13.560",
        "lastModified": "2026-07-27T13:49:27.663",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16384",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Firefox, data is exposed or consumed before the allocated storage has been initialized.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2041911",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 150,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16385",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:00.454Z",
      "date_published": "2026-07-21T12:37:59.744Z",
      "date_updated": "2026-07-22T19:18:48.799Z",
      "publisher": "mozilla",
      "title": "Information disclosure due to uninitialized memory in the Graphics: WebGPU component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23533
      },
      "nvd": {
        "published": "2026-07-21T13:17:13.660",
        "lastModified": "2026-07-27T13:49:09.987",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16385",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Firefox exposes or consumes memory before the relevant bytes have been initialized, allowing prior memory contents to affect output.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2041912",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 150,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16386",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:02.260Z",
      "date_published": "2026-07-21T12:38:00.613Z",
      "date_updated": "2026-07-22T19:18:49.862Z",
      "publisher": "mozilla",
      "title": "Information disclosure due to uninitialized memory in the Graphics: WebGPU component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23533
      },
      "nvd": {
        "published": "2026-07-21T13:17:13.763",
        "lastModified": "2026-07-27T13:47:54.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16386",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebGPU exposes bytes from an uninitialized resource rather than initializing the memory before it becomes observable.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2041916",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 150,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16387",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:05.138Z",
      "date_published": "2026-07-21T12:38:01.478Z",
      "date_updated": "2026-07-22T19:18:50.988Z",
      "publisher": "mozilla",
      "title": "Site isolation issue in the Networking component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10574
      },
      "nvd": {
        "published": "2026-07-21T13:17:13.863",
        "lastModified": "2026-07-24T15:19:03.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16387",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a host, origin, proxy, or request-channel trust failure in Firefox, but does not disclose the exact validation rule.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-200",
          "CWE-284",
          "CWE-346",
          "Vendor advisory",
          "Vendor issue tracker"
        ],
        "deepDive": true,
        "notes": "Read https://www.mozilla.org/security/advisories/mfsa2026-68/ and attempted https://bugzilla.mozilla.org/show_bug.cgi?id=2043200; the advisory only names a Networking site-isolation issue and the linked bug did not expose public technical detail."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2043200",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 155,
        "referenceCount": 5,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16388",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:06.919Z",
      "date_published": "2026-07-21T12:38:02.352Z",
      "date_updated": "2026-07-22T19:18:52.074Z",
      "publisher": "mozilla",
      "title": "Sandbox escape in the DOM: Networking component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30273
      },
      "nvd": {
        "published": "2026-07-21T13:17:13.960",
        "lastModified": "2026-07-24T16:41:11.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16388",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Mozilla identifies a sandbox escape in DOM Networking but does not publicly identify the failing check, state transition, or memory condition.",
        "basis": [
          "CNA",
          "CWE-693",
          "https://www.mozilla.org/security/advisories/mfsa2026-68/"
        ],
        "deepDive": true,
        "notes": "Primary source inspected: https://www.mozilla.org/security/advisories/mfsa2026-68/. Mozilla labels the DOM networking sandbox escape Moderate and links restricted Bugzilla 2043845; no causal check is public, and that severity conflicts with the embedded maximum CVSS 9.8."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2043845",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:08.939Z",
      "date_published": "2026-07-21T12:38:03.170Z",
      "date_updated": "2026-07-22T19:18:53.146Z",
      "publisher": "mozilla",
      "title": "Incorrect boundary conditions, integer overflow in the Libraries component in NSS",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00422,
        "percentile": 0.34763
      },
      "nvd": {
        "published": "2026-07-21T13:17:14.063",
        "lastModified": "2026-07-24T16:41:41.413",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16389",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Incorrect NSS boundary arithmetic permits an integer overflow during library processing.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2043887",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:10.273Z",
      "date_published": "2026-07-21T12:38:04.009Z",
      "date_updated": "2026-07-22T19:18:54.209Z",
      "publisher": "mozilla",
      "title": "Mitigation bypass in the Enterprise Policies component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.23947
      },
      "nvd": {
        "published": "2026-07-21T13:17:14.160",
        "lastModified": "2026-07-24T15:18:50.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16390",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Mozilla identifies an Enterprise Policies mitigation bypass but does not disclose the policy check, state, or data path that permits it.",
        "basis": [
          "CNA",
          "CWE-693",
          "Mozilla MFSA 2026-68"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.mozilla.org/security/advisories/mfsa2026-68/ and its linked https://bugzilla.mozilla.org/show_bug.cgi?id=2044527; the advisory repeats the mitigation-bypass label and the public bug does not expose a causal check."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2044527",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 161,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:12.625Z",
      "date_published": "2026-07-21T12:38:04.805Z",
      "date_updated": "2026-07-22T19:18:55.258Z",
      "publisher": "mozilla",
      "title": "Information disclosure in the Storage: IndexedDB component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24651
      },
      "nvd": {
        "published": "2026-07-21T13:17:14.290",
        "lastModified": "2026-07-24T15:18:29.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16391",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Firefox returns protected data to an unintended caller; the exposed field and output path are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2044536",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 165,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:14.800Z",
      "date_published": "2026-07-21T12:38:05.665Z",
      "date_updated": "2026-07-28T14:56:37.367Z",
      "publisher": "mozilla",
      "title": "JIT miscompilation in the JavaScript Engine: JIT component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-670",
          "name": "Always-Incorrect Control Flow Implementation",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.31316
      },
      "nvd": {
        "published": "2026-07-21T13:17:14.400",
        "lastModified": "2026-07-28T16:17:31.333",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16392",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public Mozilla record identifies a JavaScript JIT miscompilation and unsafe type use but withholds the operation that is miscompiled.",
        "basis": [
          "CNA",
          "CWE-670",
          "CWE-843",
          "Mozilla Bugzilla access boundary"
        ],
        "deepDive": true,
        "notes": "https://bugzilla.mozilla.org/show_bug.cgi?id=2044606 was inspected; the official bug is access-restricted, so the public record still does not identify the miscompiled operation."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2044606",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16393",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:17.403Z",
      "date_published": "2026-07-21T12:38:06.513Z",
      "date_updated": "2026-07-22T19:18:57.465Z",
      "publisher": "mozilla",
      "title": "Incorrect boundary conditions in the Graphics: WebGPU component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22183
      },
      "nvd": {
        "published": "2026-07-21T13:17:14.500",
        "lastModified": "2026-07-24T16:42:08.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16393",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A WebGPU boundary calculation is incorrect, but Mozilla's public advisory does not identify the buffer, index, or failed comparison.",
        "basis": [
          "CNA",
          "CWE-119",
          "https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/. Mozilla's advisory identifies Graphics: WebGPU and links Bug 2045410, but the public advisory does not expose the boundary calculation or patch."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2045410",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 129,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:19.701Z",
      "date_published": "2026-07-21T12:38:08.172Z",
      "date_updated": "2026-07-22T19:18:59.557Z",
      "publisher": "mozilla",
      "title": "Mitigation bypass in the DOM: Security component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16492
      },
      "nvd": {
        "published": "2026-07-21T13:17:14.620",
        "lastModified": "2026-07-22T20:16:57.700",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16394",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Mozilla identifies a DOM Security mitigation bypass, while the public advisory does not identify the mitigation or the check that can be bypassed.",
        "basis": [
          "CNA",
          "CWE-693",
          "Mozilla MFSA 2026-68"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/, which links Bug 2046748; Mozilla names a DOM Security mitigation bypass and fixed release, but the reviewed public material does not identify the mitigation, trigger or failing check."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2046748",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:21.672Z",
      "date_published": "2026-07-21T12:38:09.008Z",
      "date_updated": "2026-07-23T14:55:43.191Z",
      "publisher": "mozilla",
      "title": "Integer overflow in the Audio/Video component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00336,
        "percentile": 0.26179
      },
      "nvd": {
        "published": "2026-07-21T13:17:14.733",
        "lastModified": "2026-07-22T20:16:57.870",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16395",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled arithmetic can overflow before its result is used by the affected memory or parser operation.",
        "basis": [
          "CNA",
          "CWE-190",
          "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "https://bugzilla.mozilla.org/show_bug.cgi?id=2047221"
        ],
        "deepDive": true,
        "notes": "Mozilla's advisory confirms a moderate-severity integer overflow in the Audio/Video component and names the restricted Bugzilla issue, but does not disclose the overflowing operation, operand, or downstream memory use."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2047221",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 111,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:23.712Z",
      "date_published": "2026-07-21T12:38:09.831Z",
      "date_updated": "2026-07-24T20:13:53.093Z",
      "publisher": "mozilla",
      "title": "Privilege escalation in WebExtensions",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15265
      },
      "nvd": {
        "published": "2026-07-21T13:17:14.853",
        "lastModified": "2026-07-24T21:16:44.300",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16396",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebExtensions permits a privilege escalation, but Mozilla does not disclose the privileged operation or enforcement rule that fails.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2047240",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 144,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:25.987Z",
      "date_published": "2026-07-21T12:38:10.683Z",
      "date_updated": "2026-07-21T19:29:51.336Z",
      "publisher": "mozilla",
      "title": "Clickjacking issue in the WebExtensions component in Firefox for Android",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1021",
          "name": "Improper Restriction of Rendered UI Layers or Frames",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07062
      },
      "nvd": {
        "published": "2026-07-21T13:17:14.977",
        "lastModified": "2026-07-22T18:29:21.307",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16397",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Android WebExtensions surface can be framed by an untrusted page without the required anti-clickjacking boundary.",
        "basis": [
          "CNA",
          "CWE-1021"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2047608",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 118,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:27.505Z",
      "date_published": "2026-07-21T12:38:11.535Z",
      "date_updated": "2026-07-23T14:55:45.893Z",
      "publisher": "mozilla",
      "title": "Site isolation issue in the Graphics component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04596
      },
      "nvd": {
        "published": "2026-07-21T13:17:15.137",
        "lastModified": "2026-07-24T16:42:35.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16398",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A site-isolation failure crosses an origin boundary, but the public record does not identify the failed origin comparison or request path.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2048345",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:29.336Z",
      "date_published": "2026-07-21T12:38:12.355Z",
      "date_updated": "2026-07-22T19:19:04.320Z",
      "publisher": "mozilla",
      "title": "Site isolation issue in the DOM: Navigation component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04596
      },
      "nvd": {
        "published": "2026-07-21T13:17:15.247",
        "lastModified": "2026-07-24T16:43:06.053",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16399",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The navigation component fails to preserve a site-isolation origin boundary, but the exact validation or state rule is not public.",
        "basis": [
          "CNA record",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2049981",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:31.408Z",
      "date_published": "2026-07-21T12:38:13.177Z",
      "date_updated": "2026-07-22T19:19:05.514Z",
      "publisher": "mozilla",
      "title": "Information disclosure in the DOM: Security component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16107
      },
      "nvd": {
        "published": "2026-07-21T13:17:15.367",
        "lastModified": "2026-07-24T16:43:29.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16400",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Mozilla identifies information disclosure in DOM Security but does not disclose the exposed data, output path, stale state, or failing access rule.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2050430",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16401",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:33.473Z",
      "date_published": "2026-07-21T12:38:14.044Z",
      "date_updated": "2026-07-24T20:13:26.310Z",
      "publisher": "mozilla",
      "title": "Privilege escalation in the Data Loss Prevention component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11845
      },
      "nvd": {
        "published": "2026-07-21T13:17:15.470",
        "lastModified": "2026-07-24T21:16:44.460",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16401",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The data-loss-prevention component permits privilege escalation, but Mozilla's public record does not identify the incorrect privilege transition.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2052565",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16402",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:35.982Z",
      "date_published": "2026-07-21T12:38:14.897Z",
      "date_updated": "2026-07-22T19:19:07.716Z",
      "publisher": "mozilla",
      "title": "Integer overflow in the Graphics: ImageLib component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00336,
        "percentile": 0.26179
      },
      "nvd": {
        "published": "2026-07-21T13:17:15.580",
        "lastModified": "2026-07-24T16:44:21.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16402",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Firefox, unchecked integer arithmetic wraps before its result controls a memory size, offset, or copy.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2052703",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 118,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:37.813Z",
      "date_published": "2026-07-21T12:38:15.745Z",
      "date_updated": "2026-07-22T19:19:08.765Z",
      "publisher": "mozilla",
      "title": "Spoofing issue in the Address Bar component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09809
      },
      "nvd": {
        "published": "2026-07-21T13:17:15.693",
        "lastModified": "2026-07-24T16:44:54.933",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16403",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The address bar can present security-relevant location information that does not correspond to the active browsing context, while the exact display-state error is not public.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1972244",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:40.223Z",
      "date_published": "2026-07-21T12:38:16.612Z",
      "date_updated": "2026-07-22T17:27:29.188Z",
      "publisher": "mozilla",
      "title": "Spoofing issue in Firefox for Android",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05649
      },
      "nvd": {
        "published": "2026-07-21T13:17:15.803",
        "lastModified": "2026-07-24T16:24:30.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16404",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Firefox for Android accepts a spoofed identity or security representation, but the public record does not disclose the trusted object or failing check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2020253",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16405",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:42.043Z",
      "date_published": "2026-07-21T12:38:17.436Z",
      "date_updated": "2026-07-22T19:19:10.922Z",
      "publisher": "mozilla",
      "title": "Information disclosure in the Networking: WebSockets component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17161
      },
      "nvd": {
        "published": "2026-07-21T13:17:15.910",
        "lastModified": "2026-07-22T20:16:59.350",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16405",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Mozilla reports information disclosure in WebSockets without identifying the exposed data, observer, request, or operation that releases it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2036591",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16406",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:43.911Z",
      "date_published": "2026-07-21T12:38:18.255Z",
      "date_updated": "2026-07-22T19:19:12.014Z",
      "publisher": "mozilla",
      "title": "Mitigation bypass in the Networking component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15842
      },
      "nvd": {
        "published": "2026-07-21T13:17:16.013",
        "lastModified": "2026-07-22T20:16:59.507",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16406",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Mozilla identifies a Networking mitigation bypass but does not publish the mitigated condition, bypass input, or failed check.",
        "basis": [
          "CNA",
          "CWE-693",
          "https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/",
          "https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/"
        ],
        "deepDive": true,
        "notes": "Firefox and Thunderbird advisories classify this as a low Networking mitigation bypass and link only Bug 2040382; no public description or patch identifies the bypassed condition. The embedded 9.1 score materially conflicts with Mozilla severity."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2040382",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 111,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16407",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:45.957Z",
      "date_published": "2026-07-21T12:38:19.096Z",
      "date_updated": "2026-07-22T19:19:13.083Z",
      "publisher": "mozilla",
      "title": "Mitigation bypass in the DOM: Service Workers component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20112
      },
      "nvd": {
        "published": "2026-07-21T13:17:16.113",
        "lastModified": "2026-07-24T16:45:25.727",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16407",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Mozilla identifies a Service Workers mitigation bypass, while the linked bug is restricted and the public advisory does not disclose the failing control.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-693",
          "Mozilla MFSA",
          "Mozilla Bugzilla access boundary"
        ],
        "deepDive": true,
        "notes": "Read Mozilla advisory https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/ and attempted linked bug https://bugzilla.mozilla.org/show_bug.cgi?id=2044063, which is access-restricted; the advisory calls the issue a low-impact Service Workers mitigation bypass and does not disclose a causal check, conflicting with the shard CVSS 9.8."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2044063",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16408",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:48.225Z",
      "date_published": "2026-07-21T12:38:19.930Z",
      "date_updated": "2026-07-22T19:19:14.444Z",
      "publisher": "mozilla",
      "title": "Integer overflow in the Audio/Video: Playback component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00336,
        "percentile": 0.26179
      },
      "nvd": {
        "published": "2026-07-21T13:17:16.220",
        "lastModified": "2026-07-22T20:16:59.847",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16408",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Firefox and Thunderbird playback perform integer arithmetic that can overflow before memory is addressed or sized.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2050477",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:50.095Z",
      "date_published": "2026-07-21T12:38:20.799Z",
      "date_updated": "2026-07-23T14:55:53.803Z",
      "publisher": "mozilla",
      "title": "Invalid pointer in the Security: PSM component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-824",
          "name": "Access of Uninitialized Pointer",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21049
      },
      "nvd": {
        "published": "2026-07-21T13:17:16.330",
        "lastModified": "2026-07-24T16:45:54.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16409",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Firefox, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-824"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2052134",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:51.809Z",
      "date_published": "2026-07-21T12:38:21.622Z",
      "date_updated": "2026-07-22T19:19:16.700Z",
      "publisher": "mozilla",
      "title": "JIT miscompilation in the JavaScript Engine: JIT component",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22846
      },
      "nvd": {
        "published": "2026-07-21T13:17:16.433",
        "lastModified": "2026-07-24T16:46:15.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16410",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Mozilla identifies a JavaScript JIT miscompilation that uses an incompatible type but does not publish the operation that is miscompiled.",
        "basis": [
          "CNA",
          "CWE-843",
          "Mozilla MFSA 2026-68 and 2026-71",
          "Mozilla Bugzilla access boundary"
        ],
        "deepDive": true,
        "notes": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/ and https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/ were inspected, and https://bugzilla.mozilla.org/rest/bug/2053680 returned 401; the public source identifies only a JavaScript JIT miscompilation and withholds the miscompiled operation."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2053680",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16411",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:54.086Z",
      "date_published": "2026-07-21T12:38:22.476Z",
      "date_updated": "2026-07-24T03:55:33.614Z",
      "publisher": "mozilla",
      "title": "Memory safety bugs fixed in Firefox 153",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23937
      },
      "nvd": {
        "published": "2026-07-21T13:17:16.530",
        "lastModified": "2026-07-24T05:16:40.620",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16411",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Mozilla's umbrella record confirms memory corruption across multiple Firefox defects but does not identify one shared buffer, bounds check, or lifetime transition.",
        "basis": [
          "CNA",
          "CWE-119",
          "https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/. Mozilla confirms an aggregate set of memory-safety bugs with evidence of corruption, but the umbrella CVE does not state one shared buffer or lifetime error."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1420800%2C1598946%2C1767921%2C2013993%2C2025417%2C2027325%2C2027364%2C2029433%2C2029807%2C2029901%2C2029922%2C2030102%2C2030563%2C2032110%2C2037801%2C2042756%2C2044625%2C2045609%2C2047920%2C2048491%2C2048492%2C2048800%2C2050534%2C2050662%2C2050871",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2006467%2C2027346%2C2027349%2C2027353%2C2027362%2C2027371%2C2027373%2C2028954%2C2029694%2C2036906%2C2038964%2C2039460%2C2040522%2C2040834%2C2043275%2C2045394%2C2045606%2C2052060",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2048936%2C2049804",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16412",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T21:57:54.488Z",
      "date_published": "2026-07-21T12:38:23.323Z",
      "date_updated": "2026-07-24T03:55:34.396Z",
      "publisher": "mozilla",
      "title": "Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Firefox"
          },
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25872
      },
      "nvd": {
        "published": "2026-07-21T13:17:16.630",
        "lastModified": "2026-07-24T05:16:40.790",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16412",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Mozilla groups multiple memory-safety defects under one CVE and does not publish a single bounds, type, or lifetime transition that explains all of them.",
        "basis": [
          "CNA",
          "CWE-119",
          "Mozilla MFSA 2026-68"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/. It confirms an aggregate of memory-safety defects fixed in Firefox ESR 140.13 and Firefox 153; linked bug groups do not establish one shared bounds or lifetime cause."
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2005113%2C2025369%2C2026301%2C2028663%2C2029761%2C2042242%2C2043271%2C2043300%2C2044612%2C2045378%2C2045406%2C2045407%2C2045616%2C2045626%2C2045730%2C2045732%2C2045769%2C2045771%2C2047957%2C2048934%2C2049818%2C2049822%2C2050151%2C2050368%2C2051653%2C2051658",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2043035%2C2045057%2C2045187%2C2045402%2C2045417%2C2045482%2C2045611%2C2045618%2C2045756%2C2046917%2C2047718",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045413%2C2053635%2C2053637",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-68/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-70/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-71/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-72/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16413",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T22:23:04.847Z",
      "date_published": "2026-07-21T22:04:07.376Z",
      "date_updated": "2026-07-24T12:46:27.440Z",
      "publisher": "Chrome",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10499
      },
      "nvd": {
        "published": "2026-07-21T23:16:58.017",
        "lastModified": "2026-07-24T15:56:20.553",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16413",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled input reaches a write whose destination boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517359779",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16414",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T22:23:05.151Z",
      "date_published": "2026-07-21T22:04:08.301Z",
      "date_updated": "2026-07-30T18:06:22.876Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 1.5000000000000009,
      "epss": {
        "score": 0.00088,
        "percentile": 0.00473
      },
      "nvd": {
        "published": "2026-07-21T23:16:58.943",
        "lastModified": "2026-07-30T19:17:09.090",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16414",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports a security impact in Chrome but does not identify the failing check, parser, state transition, or lifetime rule.",
        "basis": [
          "CNA",
          "CWE-20",
          "Chrome release advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html and the linked restricted issue https://issues.chromium.org/issues/517651910; Google discloses only insufficient validation in Chromecast, so the causal field and check remain non-public."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517651910",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16415",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T22:23:05.416Z",
      "date_published": "2026-07-21T22:04:08.624Z",
      "date_updated": "2026-07-24T12:49:58.291Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05492
      },
      "nvd": {
        "published": "2026-07-21T23:16:59.053",
        "lastModified": "2026-07-24T15:55:40.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16415",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Extension-controlled content can spoof the omnibox because Chrome insufficiently binds displayed URL state to the trusted navigation origin.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519244446",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16416",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T22:23:05.641Z",
      "date_published": "2026-07-21T22:04:09.007Z",
      "date_updated": "2026-07-30T18:05:28.047Z",
      "publisher": "Chrome",
      "title": "Integer overflow in Chromecast in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00093,
        "percentile": 0.00654
      },
      "nvd": {
        "published": "2026-07-21T23:16:59.170",
        "lastModified": "2026-07-30T19:17:09.260",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16416",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chromecast performs integer arithmetic that can overflow before a graphics or network value is used across the sandbox boundary.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520172356",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16417",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T22:23:05.836Z",
      "date_published": "2026-07-21T22:04:09.379Z",
      "date_updated": "2026-07-24T12:51:18.027Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05949
      },
      "nvd": {
        "published": "2026-07-21T23:16:59.287",
        "lastModified": "2026-07-24T15:55:19.233",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16417",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Skia uses an uninitialized value while processing crafted page content, allowing bytes not initialized for that operation to influence or escape the renderer.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521491024",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T22:23:06.041Z",
      "date_published": "2026-07-21T22:04:09.753Z",
      "date_updated": "2026-07-24T12:51:52.103Z",
      "publisher": "Chrome",
      "title": "Stack buffer overflow in V8 in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00271,
        "percentile": 0.19289
      },
      "nvd": {
        "published": "2026-07-21T23:16:59.400",
        "lastModified": "2026-07-24T15:41:46.123",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16418",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path copies attacker-influenced data beyond a fixed-size stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522125255",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16419",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T22:23:06.287Z",
      "date_published": "2026-07-21T22:04:10.114Z",
      "date_updated": "2026-07-24T12:45:46.928Z",
      "publisher": "Chrome",
      "title": "Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10356
      },
      "nvd": {
        "published": "2026-07-21T23:16:59.503",
        "lastModified": "2026-07-24T15:41:33.510",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16419",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted page causes ANGLE to read and write outside an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523435970",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16420",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T22:23:06.498Z",
      "date_published": "2026-07-21T22:04:06.444Z",
      "date_updated": "2026-07-24T12:47:35.962Z",
      "publisher": "Chrome",
      "title": "Type Confusion in WebAudio in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29877
      },
      "nvd": {
        "published": "2026-07-21T23:16:59.607",
        "lastModified": "2026-07-24T15:41:20.473",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16420",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The memory-handling path in Chrome permits an invalid bound, size, type, initialization state, or object lifetime.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/527930356",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16421",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T22:23:06.725Z",
      "date_published": "2026-07-21T22:04:06.937Z",
      "date_updated": "2026-07-24T12:47:16.267Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in WebAudio in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00341,
        "percentile": 0.26688
      },
      "nvd": {
        "published": "2026-07-21T23:16:59.710",
        "lastModified": "2026-07-24T15:40:30.657",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16421",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-16421 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/528276487",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T22:23:06.954Z",
      "date_published": "2026-07-21T22:04:10.481Z",
      "date_updated": "2026-07-22T13:45:19.084Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.0271
      },
      "nvd": {
        "published": "2026-07-21T23:16:59.817",
        "lastModified": "2026-07-24T14:54:15.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16422",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Chrome's certificate handling accepts network input that can make a domain appear authenticated under the wrong identity, while the exact validation field is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/533515002",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T22:23:07.179Z",
      "date_published": "2026-07-21T22:04:10.827Z",
      "date_updated": "2026-07-22T13:43:16.032Z",
      "publisher": "Chrome",
      "title": "Use after free in UI in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10355
      },
      "nvd": {
        "published": "2026-07-21T23:16:59.923",
        "lastModified": "2026-07-24T15:07:36.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16423",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome continues to access an object after its storage has been released, allowing invalid heap use and possible corruption.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/534582496",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T22:23:07.394Z",
      "date_published": "2026-07-21T22:04:11.197Z",
      "date_updated": "2026-07-22T13:38:52.783Z",
      "publisher": "Chrome",
      "title": "Use after free in GPU in Google Chrome on Android prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13215
      },
      "nvd": {
        "published": "2026-07-21T23:17:00.030",
        "lastModified": "2026-07-24T15:07:41.797",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16424",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Android GPU component can use an object after it has been freed after a renderer compromise.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/534858939",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16439",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T06:37:15.485Z",
      "date_published": "2026-07-21T17:28:44.409Z",
      "date_updated": "2026-07-22T18:27:00.671Z",
      "publisher": "eclipse",
      "title": "Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "OpenJ9"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-124",
          "name": "Buffer Underwrite ('Buffer Underflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10598
      },
      "nvd": {
        "published": "2026-07-21T18:16:56.883",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16439",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenJ9 Xtrace argument tracing can access memory before the start of its intended buffer.",
        "basis": [
          "CNA",
          "CWE-124"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/eclipse-openj9/openj9/pull/24394",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/192",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16441",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T06:43:35.115Z",
      "date_published": "2026-07-21T18:07:02.798Z",
      "date_updated": "2026-07-22T19:07:14.315Z",
      "publisher": "eclipse",
      "title": "Eclipse OpenJ9 : Method resolution default method precedence failure",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "OpenJ9"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-758",
          "name": "Reliance on Undefined, Unspecified, or Implementation-Defined Behavior",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00297,
        "percentile": 0.21942
      },
      "nvd": {
        "published": "2026-07-21T19:17:09.990",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16441",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenJ9 dispatches a call to an interface default method after a formerly concrete superclass method is recompiled as abstract, violating the expected method-resolution rule.",
        "basis": [
          "CNA",
          "CWE-758"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/eclipse-openj9/openj9/security/advisories/GHSA-hcfc-9hjx-2q7f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/eclipse-openj9/openj9/pull/24396",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/194",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T08:23:53.560Z",
      "date_published": "2026-07-21T12:51:08.650Z",
      "date_updated": "2026-07-22T18:00:32.326Z",
      "publisher": "redhat",
      "title": "Dracut: dracut: root code execution via dhcp options command injection in networkmanager initrd module",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00989,
        "percentile": 0.59081
      },
      "nvd": {
        "published": "2026-07-21T13:17:16.730",
        "lastModified": "2026-07-22T19:16:57.380",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16445",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:26534",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40700",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16445",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459963",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503147",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/dracutdevs/dracut/commit/e509c638e6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 509,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16447",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T08:49:19.967Z",
      "date_published": "2026-07-21T13:30:36.026Z",
      "date_updated": "2026-07-22T14:06:33.061Z",
      "publisher": "VulDB",
      "title": "D-Link DNS-320 multi_uploadify.php unrestricted upload",
      "affected": {
        "vendors": [
          "D-Link"
        ],
        "products": [
          {
            "vendor": "D-Link",
            "product": "DNS-320"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00728,
        "percentile": 0.50638
      },
      "nvd": {
        "published": "2026-07-21T14:16:33.650",
        "lastModified": "2026-07-22T15:16:53.293",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16447",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "multi_uploadify.php accepts Filedata[] without restricting the uploaded file type or destination.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380826",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380826/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16447",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858466",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/docx/KttYdnLfzotGUSxx7p3cbaornPd?from=from_copylink",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.dlink.com/",
          "host": "www.dlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 324,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T08:49:25.085Z",
      "date_published": "2026-07-21T14:15:37.230Z",
      "date_updated": "2026-07-21T14:55:10.371Z",
      "publisher": "VulDB",
      "title": "D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection",
      "affected": {
        "vendors": [
          "D-Link"
        ],
        "products": [
          {
            "vendor": "D-Link",
            "product": "DNS-120"
          },
          {
            "vendor": "D-Link",
            "product": "DNR-202L"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-315L"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-320"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-320L"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-320LW"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-321"
          },
          {
            "vendor": "D-Link",
            "product": "DNR-322L"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-323"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-325"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-326"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-327L"
          },
          {
            "vendor": "D-Link",
            "product": "DNR-326"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-340L"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-343"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-345"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-726-4"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-1100-4"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-1200-05"
          },
          {
            "vendor": "D-Link",
            "product": "DNS-1550-04"
          }
        ],
        "affectedBlockCount": 20,
        "versionEntryCount": 20,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.01055,
        "percentile": 0.61101
      },
      "nvd": {
        "published": "2026-07-21T15:16:33.587",
        "lastModified": "2026-07-21T17:07:04.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16448",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected handler places caller-controlled data in an operating-system command without safe argument separation.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380827",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380827/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16448",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858469",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://ucn9h68n9289.feishu.cn/docx/OfhNdwzvXoBlJBxDIW7clVmjnuh?from=from_copylink",
          "host": "ucn9h68n9289.feishu.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.dlink.com/",
          "host": "www.dlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 505,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 20,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-16449",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T08:55:32.165Z",
      "date_published": "2026-07-21T14:45:08.691Z",
      "date_updated": "2026-07-22T14:32:56.002Z",
      "publisher": "VulDB",
      "title": "zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection",
      "affected": {
        "vendors": [
          "zsadmin2025"
        ],
        "products": [
          {
            "vendor": "zsadmin2025",
            "product": "ZS-Admin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00192,
        "percentile": 0.09145
      },
      "nvd": {
        "published": "2026-07-21T16:17:07.313",
        "lastModified": "2026-07-22T15:16:53.430",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16449",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380828",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380828/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16449",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858790",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zsadmin2025/zs-admin-java/issues/4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 706,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16450",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T08:55:36.975Z",
      "date_published": "2026-07-21T15:30:08.890Z",
      "date_updated": "2026-07-23T14:26:15.736Z",
      "publisher": "VulDB",
      "title": "zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization",
      "affected": {
        "vendors": [
          "zsadmin2025"
        ],
        "products": [
          {
            "vendor": "zsadmin2025",
            "product": "ZS-Admin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00274,
        "percentile": 0.1958
      },
      "nvd": {
        "published": "2026-07-21T16:17:07.493",
        "lastModified": "2026-07-23T15:17:00.313",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16450",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380829",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380829/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16450",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858791",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zsadmin2025/zs-admin-java/issues/5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 647,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16451",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T08:55:41.634Z",
      "date_published": "2026-07-21T16:45:07.676Z",
      "date_updated": "2026-07-22T14:40:22.129Z",
      "publisher": "VulDB",
      "title": "zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload",
      "affected": {
        "vendors": [
          "zsadmin2025"
        ],
        "products": [
          {
            "vendor": "zsadmin2025",
            "product": "ZS-Admin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10225
      },
      "nvd": {
        "published": "2026-07-21T17:17:05.730",
        "lastModified": "2026-07-22T16:25:46.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16451",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ZS-Admin accepts an uploaded file without enforcing the file type and destination restrictions required for that content.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380830",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380830/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16451",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/858792",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/zsadmin2025/zs-admin-java/issues/6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 683,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T10:01:44.585Z",
      "date_published": "2026-07-21T16:38:27.723Z",
      "date_updated": "2026-07-22T18:58:48.011Z",
      "publisher": "eclipse",
      "title": "Privilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware Exfiltration",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "eclipse-hawkbit/hawkbit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14422
      },
      "nvd": {
        "published": "2026-07-21T17:17:05.887",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16454",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The firmware download controller authenticates a device to the tenant but does not bind the requested artifact to that device's assigned update.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/eclipse-hawkbit/hawkbit/security/advisories/GHSA-92r3-p8c2-3fpx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/196",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1108,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16461",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T11:33:40.142Z",
      "date_published": "2026-07-21T11:42:03.630Z",
      "date_updated": "2026-07-22T14:29:59.439Z",
      "publisher": "redhat",
      "title": "Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13587
      },
      "nvd": {
        "published": "2026-07-21T12:17:21.030",
        "lastModified": "2026-07-22T15:16:53.693",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16461",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Version formatting writes more bytes than a fixed-size stack buffer can hold.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16461",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502719",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16462",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T11:56:03.095Z",
      "date_published": "2026-07-28T09:27:22.755Z",
      "date_updated": "2026-07-28T19:15:38.784Z",
      "publisher": "CERTVDE",
      "title": "SQL injection via unauthenticated GetGridData endpoint",
      "affected": {
        "vendors": [
          "Weidmueller Interface"
        ],
        "products": [
          {
            "vendor": "Weidmueller Interface",
            "product": "PROCON-WEB SCADA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34532
      },
      "nvd": {
        "published": "2026-07-28T10:16:48.293",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16462",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unauthenticated GetGridData endpoint incorporates attacker input into SQL without the required grammar separation.",
        "basis": [
          "CNA record",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-085/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 154,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16463",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T13:10:56.170Z",
      "date_published": "2026-07-29T15:22:16.305Z",
      "date_updated": "2026-07-30T03:55:24.705Z",
      "publisher": "autodesk",
      "title": "DXF File Parsing Heap-Based Overflow in Autodesk AutoCAD",
      "affected": {
        "vendors": [
          "Autodesk"
        ],
        "products": [
          {
            "vendor": "Autodesk",
            "product": "AutoCAD"
          },
          {
            "vendor": "Autodesk",
            "product": "AutoCAD LT"
          },
          {
            "vendor": "Autodesk",
            "product": "DWG TrueView"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@autodesk.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.0529
      },
      "nvd": {
        "published": "2026-07-29T16:17:50.377",
        "lastModified": "2026-07-30T16:27:52.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16463",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AutoCAD writes attacker-controlled data beyond a heap buffer boundary.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0009",
          "host": "www.autodesk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.autodesk.com/products/autodesk-access/overview",
          "host": "www.autodesk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.autodesk.com/products/dwg-trueview/overview",
          "host": "www.autodesk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 270,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16465",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T13:11:00.568Z",
      "date_published": "2026-07-29T15:22:42.203Z",
      "date_updated": "2026-07-29T15:55:18.403Z",
      "publisher": "autodesk",
      "title": "DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD",
      "affected": {
        "vendors": [
          "Autodesk"
        ],
        "products": [
          {
            "vendor": "Autodesk",
            "product": "AutoCAD"
          },
          {
            "vendor": "Autodesk",
            "product": "AutoCAD LT"
          },
          {
            "vendor": "Autodesk",
            "product": "DWG TrueView"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:psirt@autodesk.com",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04162
      },
      "nvd": {
        "published": "2026-07-29T16:17:50.530",
        "lastModified": "2026-07-30T16:27:52.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16465",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An Autodesk file parser reads beyond the end of an allocated input buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0009",
          "host": "www.autodesk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.autodesk.com/products/autodesk-access/overview",
          "host": "www.autodesk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.autodesk.com/products/dwg-trueview/overview",
          "host": "www.autodesk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16473",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T14:03:06.762Z",
      "date_published": "2026-07-22T10:07:12.419Z",
      "date_updated": "2026-07-30T14:01:24.071Z",
      "publisher": "redhat",
      "title": "Sbc: sbc: heap out-of-bounds read via crafted sbc audio frame",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15759
      },
      "nvd": {
        "published": "2026-07-22T11:16:50.097",
        "lastModified": "2026-07-30T14:16:47.573",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16473",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Red Hat Enterprise Linux 10, an attacker-controlled index or length permits a read beyond the valid memory region.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16473",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503650",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://git.kernel.org/pub/scm/bluetooth/sbc.git",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://lore.kernel.org/linux-bluetooth/1660735014.5089519.1785359719739@mail.yahoo.com/",
          "host": "lore.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T14:56:59.820Z",
      "date_published": "2026-07-27T19:13:29.324Z",
      "date_updated": "2026-07-27T19:35:53.065Z",
      "publisher": "Google",
      "title": "Server-Side Request Forgery (SSRF) and Credential Exfiltration in googleapis/mcp-toolbox cloud-healthcare-fhir-fetch-page Tool",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "MCP Toolbox for Databases (googleapis/mcp-toolbox)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:cve-coordination@google.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16242
      },
      "nvd": {
        "published": "2026-07-27T19:17:14.970",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16481",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server follows an attacker-controlled outbound URL without constraining its destination to the intended remote service.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/googleapis/mcp-toolbox/pull/3453",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 941,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16484",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:39:13.592Z",
      "date_published": "2026-07-21T21:30:08.537Z",
      "date_updated": "2026-07-22T15:33:24.820Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00412,
        "percentile": 0.33947
      },
      "nvd": {
        "published": "2026-07-21T22:17:00.437",
        "lastModified": "2026-07-22T16:25:46.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16484",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "edit_subjecta.php incorporates the remote ID parameter into an SQL statement without preserving the SQL data boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380942",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380942/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16484",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/859905",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/austincooke723-tech/web-re-cve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 314,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16485",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:39:21.032Z",
      "date_published": "2026-07-21T22:00:11.939Z",
      "date_updated": "2026-07-22T15:18:33.775Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System class.php cross site scripting",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19439
      },
      "nvd": {
        "published": "2026-07-21T23:17:00.153",
        "lastModified": "2026-07-22T16:25:46.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16485",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Class and Exam Timetabling System rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380943",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380943/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16485",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/859906",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ashfaqsharif47-arch/Web-RCE/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16486",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:39:25.172Z",
      "date_published": "2026-07-21T22:45:09.010Z",
      "date_updated": "2026-07-22T18:48:39.788Z",
      "publisher": "VulDB",
      "title": "SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting",
      "affected": {
        "vendors": [
          "SourceCodester"
        ],
        "products": [
          {
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19439
      },
      "nvd": {
        "published": "2026-07-21T23:17:00.403",
        "lastModified": "2026-07-22T19:16:57.627",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16486",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted content is interpreted in an executable grammar without the required contextual neutralization.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380944",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380944/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16486",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/859907",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/kurshidheba852-hub/My-cve-repository/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.sourcecodester.com/",
          "host": "www.sourcecodester.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:49:25.967Z",
      "date_published": "2026-07-21T23:15:10.236Z",
      "date_updated": "2026-07-22T13:00:15.551Z",
      "publisher": "VulDB",
      "title": "QUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injection",
      "affected": {
        "vendors": [
          "QUSETIONS"
        ],
        "products": [
          {
            "vendor": "QUSETIONS",
            "product": "MiniCode-Python"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.1,
          "severity": "",
          "vector": "AV:N/AC:H/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.01003,
        "percentile": 0.59564
      },
      "nvd": {
        "published": "2026-07-22T00:17:30.693",
        "lastModified": "2026-07-22T16:25:46.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16488",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MiniCode-Python command path concatenates attacker-controlled data into an operating-system command without preserving the shell grammar boundary.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380945",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380945/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16488",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/860017",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/QUSETIONS/MiniCode-Python/issues/13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/QUSETIONS/MiniCode-Python/issues/13#issuecomment-4764889606",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://gist.github.com/menelausx/2e6275222cb2e8aa412a145ba7abec66",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/QUSETIONS/MiniCode-Python/commit/9d868dc2550f426c6ddf8ee98f30ffe450ca5e32",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/QUSETIONS/MiniCode-Python/releases/tag/v0.1.0-rc1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/QUSETIONS/MiniCode-Python/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 10,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:53:55.187Z",
      "date_published": "2026-07-21T23:30:09.680Z",
      "date_updated": "2026-07-23T13:54:26.365Z",
      "publisher": "VulDB",
      "title": "jsforce SFDX Connection Registry sfdx.js _execCommand os command injection",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "jsforce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 17,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00624,
        "percentile": 0.46482
      },
      "nvd": {
        "published": "2026-07-22T00:17:30.887",
        "lastModified": "2026-07-23T14:17:06.247",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16489",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "jsforce places attacker-controlled SFDX arguments into a local operating-system command without preserving the shell grammar boundary.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380946",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380946/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16489",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/860031",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/jsforce/jsforce/issues/1805",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/jsforce/jsforce/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-16490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:57:23.069Z",
      "date_published": "2026-07-22T00:15:08.275Z",
      "date_updated": "2026-07-22T14:32:53.022Z",
      "publisher": "VulDB",
      "title": "itsourcecode Hospital Management System prescription.php sql injection",
      "affected": {
        "vendors": [
          "itsourcecode"
        ],
        "products": [
          {
            "vendor": "itsourcecode",
            "product": "Hospital Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.002,
        "percentile": 0.10066
      },
      "nvd": {
        "published": "2026-07-22T01:16:25.197",
        "lastModified": "2026-07-22T16:25:46.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16490",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The editid argument reaches a SQL statement without parameter separation, allowing its value to change the query grammar.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380947",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380947/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16490",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/860032",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/shohatmedhat535-dotcom/cve-records/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://itsourcecode.com/",
          "host": "itsourcecode.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T16:04:58.786Z",
      "date_published": "2026-07-22T00:45:11.924Z",
      "date_updated": "2026-07-22T13:02:16.404Z",
      "publisher": "VulDB",
      "title": "umijs umi GIT File Helper getFileGitIno.ts git.getFileCreateInfo os command injection",
      "affected": {
        "vendors": [
          "umijs"
        ],
        "products": [
          {
            "vendor": "umijs",
            "product": "umi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 65,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5.2,
          "severity": "",
          "vector": "AV:A/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5.2,
          "severity": "",
          "vector": "AV:A/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 3.5,
      "epss": {
        "score": 0.01664,
        "percentile": 0.74404
      },
      "nvd": {
        "published": "2026-07-22T01:16:26.257",
        "lastModified": "2026-07-22T16:25:46.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16492",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "git.getFileCreateInfo inserts attacker-controlled file information into an operating-system command without shell grammar separation.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/380948",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/380948/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16492",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/860128",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/umijs/umi/issues/13345",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/umijs/umi/pull/13347",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/umijs/umi/commit/b6da12c17b024a43badb1fa565720c38cf42e647",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/umijs/umi/releases/tag/v4.6.64",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/umijs/umi/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 486,
        "referenceCount": 9,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 65
      }
    },
    {
      "cve_id": "CVE-2026-16493",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T16:32:33.912Z",
      "date_published": "2026-07-21T17:26:14.394Z",
      "date_updated": "2026-07-22T14:21:51.764Z",
      "publisher": "redhat",
      "title": "Ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for cve-2026-11332)",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24
      },
      "nvd": {
        "published": "2026-07-21T18:16:57.030",
        "lastModified": "2026-07-22T15:16:53.960",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16493",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The collection installer places an attacker-supplied Git URL before no end-of-options separator, so Git parses the URL as command-line options.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16493",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503724",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 627,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T16:53:07.388Z",
      "date_published": "2026-07-28T17:57:36.795Z",
      "date_updated": "2026-07-28T18:43:58.385Z",
      "publisher": "HashiCorp",
      "title": "terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user",
      "affected": {
        "vendors": [
          "HashiCorp"
        ],
        "products": [
          {
            "vendor": "HashiCorp",
            "product": "Tooling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-384",
          "name": "Session Fixation",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security@hashicorp.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19404
      },
      "nvd": {
        "published": "2026-07-28T19:17:31.983",
        "lastModified": "2026-07-30T14:08:23.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16496",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An MCP session identifier selects credentials from another user's long-lived session because the identifier is not bound to the authenticated caller.",
        "basis": [
          "CNA",
          "CWE-384"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.hashicorp.com/t/hcsec-2026-23-multiple-vulnerabilities-impacting-hashicorp-terraform-mcp-server/77606",
          "host": "discuss.hashicorp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 348,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16498",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T17:19:22.057Z",
      "date_published": "2026-07-28T17:57:45.748Z",
      "date_updated": "2026-07-28T18:39:15.712Z",
      "publisher": "HashiCorp",
      "title": "terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode",
      "affected": {
        "vendors": [
          "HashiCorp"
        ],
        "products": [
          {
            "vendor": "HashiCorp",
            "product": "Tooling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-488",
          "name": "Exposure of Data Element to Wrong Session",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security@hashicorp.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25537
      },
      "nvd": {
        "published": "2026-07-28T19:17:32.117",
        "lastModified": "2026-07-30T14:08:23.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16498",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Stateless streamable-HTTP handling can retain one tenant's Terraform token and use it to execute a later tenant's tool call.",
        "basis": [
          "CNA",
          "CWE-488"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.hashicorp.com/t/hcsec-2026-23-multiple-vulnerabilities-impacting-hashicorp-terraform-mcp-server/77606",
          "host": "discuss.hashicorp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16503",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T19:08:29.074Z",
      "date_published": "2026-07-31T15:18:33.052Z",
      "date_updated": "2026-08-03T17:13:26.182Z",
      "publisher": "certcc",
      "title": "VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities",
      "affected": {
        "vendors": [
          "VPS.org"
        ],
        "products": [
          {
            "vendor": "VPS.org",
            "product": "Supabase template"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1327",
          "name": "Binding to an Unrestricted IP Address",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1393",
          "name": "Use of Default Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15966
      },
      "nvd": {
        "published": "2026-07-31T16:16:58.773",
        "lastModified": "2026-08-03T18:16:37.420",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16503",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The deployment template binds PostgreSQL to 0.0.0.0 with the default postgres password while Docker networking bypasses the expected host UFW boundary.",
        "basis": [
          "CNA",
          "CWE-1188",
          "CWE-1327",
          "CWE-1393"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.cert.org/vuls/id/243636",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16504",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T19:08:55.664Z",
      "date_published": "2026-07-31T15:19:42.435Z",
      "date_updated": "2026-08-03T17:18:24.554Z",
      "publisher": "certcc",
      "title": "VPS.org one-click Zulip template deployment instance contains multiple vulnerabilities",
      "affected": {
        "vendors": [
          "VPS.org"
        ],
        "products": [
          {
            "vendor": "VPS.org",
            "product": "Zulip template"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-321",
          "name": "Use of Hard-coded Cryptographic Key",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1393",
          "name": "Use of Default Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18803
      },
      "nvd": {
        "published": "2026-07-31T16:16:58.873",
        "lastModified": "2026-08-03T18:16:37.580",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16504",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The deployment template ships a fixed signing key, a default database password, and HTTPS disabled across independent installations.",
        "basis": [
          "CNA",
          "CWE-321",
          "CWE-1188",
          "CWE-1393"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.cert.org/vuls/id/243636",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 158,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16517",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T22:31:53.865Z",
      "date_published": "2026-07-21T22:41:38.128Z",
      "date_updated": "2026-07-22T18:17:30.578Z",
      "publisher": "redhat",
      "title": "Libarchive: libarchive: signed integer overflow in archive_write_zip_header",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00078,
        "percentile": 0.00169
      },
      "nvd": {
        "published": "2026-07-21T23:17:00.587",
        "lastModified": "2026-07-22T19:16:57.760",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16517",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ZIP writer adds encryption overhead to a near-INT64_MAX size in signed arithmetic, causing overflow and invalid downstream size decisions.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:43818",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16517",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2505492",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 428,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16519",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T00:55:03.834Z",
      "date_published": "2026-07-24T07:05:02.046Z",
      "date_updated": "2026-07-24T12:29:41.082Z",
      "publisher": "GV",
      "title": "GeoVision GV-IP Device Utility DLL Search Order Hijacking Vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GV-IP Device Utility"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01973
      },
      "nvd": {
        "published": "2026-07-24T08:16:26.663",
        "lastModified": "2026-07-30T19:15:36.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16519",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The desktop application searches an unsafe directory order for DLLs and can load an attacker-planted library before the legitimate one.",
        "basis": [
          "CNA",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16524",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T06:52:16.739Z",
      "date_published": "2026-07-30T05:15:15.277Z",
      "date_updated": "2026-07-30T15:17:34.115Z",
      "publisher": "redhat",
      "title": "Pcp: pcp linux_sockets pmda: arbitrary command execution via command injection",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01077,
        "percentile": 0.61752
      },
      "nvd": {
        "published": "2026-07-30T06:25:02.460",
        "lastModified": "2026-07-30T16:16:56.807",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16524",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Red Hat Enterprise Linux 10 command path passes attacker-controlled text into command syntax without argument or shell separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16524",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506023",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16526",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T07:26:46.736Z",
      "date_published": "2026-07-30T05:20:07.504Z",
      "date_updated": "2026-07-30T13:55:19.017Z",
      "publisher": "redhat",
      "title": "Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-403",
          "name": "Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00759,
        "percentile": 0.51722
      },
      "nvd": {
        "published": "2026-07-30T06:25:02.663",
        "lastModified": "2026-07-30T14:16:47.700",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16526",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PCP module exposes an internal privileged connection handle to a process that should not control it.",
        "basis": [
          "CNA",
          "CWE-403"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16526",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506026",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T07:36:03.699Z",
      "date_published": "2026-07-30T05:30:16.930Z",
      "date_updated": "2026-07-31T22:41:42.714Z",
      "publisher": "redhat",
      "title": "Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access rules",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00395,
        "percentile": 0.32326
      },
      "nvd": {
        "published": "2026-07-30T06:25:02.813",
        "lastModified": "2026-07-31T23:17:23.303",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16527",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The pmproxy store endpoint accepts unauthenticated metric writes without enforcing the PMCD access rules for the requested operation.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16527",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506031",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16529",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T07:49:33.456Z",
      "date_published": "2026-07-30T05:30:18.630Z",
      "date_updated": "2026-07-30T13:58:48.865Z",
      "publisher": "redhat",
      "title": "Pcp: pcp: denial of service due to signed integer overflow",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21322
      },
      "nvd": {
        "published": "2026-07-30T06:25:02.953",
        "lastModified": "2026-07-30T14:16:47.830",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16529",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Red Hat Enterprise Linux 10 performs attacker-influenced size arithmetic without detecting integer overflow, allowing a wrapped value to violate later memory bounds.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16529",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506032",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T07:57:32.480Z",
      "date_published": "2026-07-30T05:30:59.912Z",
      "date_updated": "2026-07-30T13:37:45.509Z",
      "publisher": "redhat",
      "title": "Pcp: pcp: remote denial of service and information leakage",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22203
      },
      "nvd": {
        "published": "2026-07-30T06:25:03.113",
        "lastModified": "2026-07-30T14:16:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16530",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "pmLogLoadInDom bypasses a bounds check and reads beyond its valid buffer in response to a crafted pmproxy request.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16530",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506033",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 412,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16531",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:02:56.004Z",
      "date_published": "2026-07-30T05:41:07.583Z",
      "date_updated": "2026-07-30T15:17:27.782Z",
      "publisher": "redhat",
      "title": "Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00357,
        "percentile": 0.28418
      },
      "nvd": {
        "published": "2026-07-30T06:25:03.277",
        "lastModified": "2026-07-30T16:16:56.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16531",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Red Hat Enterprise Linux 10 resolves attacker-controlled path components without confirming that the final path remains beneath the intended root.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16531",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506037",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16543",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T09:53:31.062Z",
      "date_published": "2026-07-29T15:29:03.485Z",
      "date_updated": "2026-07-29T17:57:21.328Z",
      "publisher": "Kong",
      "title": "Kong Operator cluster-wide ingress configuration DoS via embedded KIC CA-certificate ID collision",
      "affected": {
        "vendors": [],
        "products": [],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:02762ae7-200e-4b20-9b2b-a77d5b8fc4cb",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03823
      },
      "nvd": {
        "published": "2026-07-29T16:17:50.660",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16543",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The embedded KIC selects CA-certificate Secrets across namespaces without ingress-class or namespace scoping, letting a namespace user inject a cluster-wide ID collision.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Kong/kong-operator/security/advisories/GHSA-h4fh-j7xg-vwcx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 0,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16544",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T09:58:35.294Z",
      "date_published": "2026-07-22T11:15:53.882Z",
      "date_updated": "2026-07-22T17:47:45.889Z",
      "publisher": "redhat",
      "title": "Awx: websocket eventconsumer missing authorization for inventory_update_events, project_update_events, and system_job_events allows cross-organization stdout disclosure",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27359
      },
      "nvd": {
        "published": "2026-07-22T12:17:10.480",
        "lastModified": "2026-07-22T18:16:59.987",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16544",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "AWX omits three websocket event groups from consumer_access, so their organization authorization check is skipped.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16544",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506053",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 616,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16551",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:57:39.812Z",
      "date_published": "2026-07-22T11:22:41.874Z",
      "date_updated": "2026-07-22T12:21:05.130Z",
      "publisher": "ThinkstAppliedResearch",
      "title": "Denial-of-Service in OpenCanary's MongoDB module",
      "affected": {
        "vendors": [
          "Thinkst Applied Research"
        ],
        "products": [
          {
            "vendor": "Thinkst Applied Research",
            "product": "OpenCanary"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/S:N"
        },
        {
          "source": "NVD:0f2be0ad-3469-4e56-b38f-4eb96719b425",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16737
      },
      "nvd": {
        "published": "2026-07-22T12:17:10.620",
        "lastModified": "2026-07-23T15:23:12.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16551",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenCanary's MongoDB module permits attacker-controlled processing to allocate excessively without an effective termination or size bound.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thinkst/opencanary/security/advisories/GHSA-vg37-pc42-q265",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16552",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-07-22T11:11:01.973Z",
      "date_published": "2026-07-22T15:55:58.222Z",
      "date_rejected": "2026-07-23T10:24:24.056Z",
      "date_updated": "2026-07-23T10:24:24.056Z",
      "publisher": "redhat",
      "title": "Rejected reason: The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of the threat model of the affected component.",
      "rejected_reason": "The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of the threat model of the affected component."
    },
    {
      "cve_id": "CVE-2026-16553",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T11:33:42.887Z",
      "date_published": "2026-07-29T18:59:46.164Z",
      "date_updated": "2026-07-29T19:31:40.245Z",
      "publisher": "GitLab",
      "title": "Insufficiently Protected Credentials in GitLab",
      "affected": {
        "vendors": [
          "GitLab"
        ],
        "products": [
          {
            "vendor": "GitLab",
            "product": "GitLab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16874
      },
      "nvd": {
        "published": "2026-07-29T20:17:02.460",
        "lastModified": "2026-08-03T14:14:35.333",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16553",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Virtual-registry upstream request handling can send protected credentials or data to an unintended host.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/603269",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/",
          "host": "docs.gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16554",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T11:49:39.961Z",
      "date_published": "2026-07-27T08:40:17.183Z",
      "date_updated": "2026-07-31T13:34:05.448Z",
      "publisher": "CERT-PL",
      "title": "Integer Overflow Leading to Heap Buffer Overflow in cJSON",
      "affected": {
        "vendors": [
          "DaveGamble"
        ],
        "products": [
          {
            "vendor": "DaveGamble",
            "product": "cJSON"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21744
      },
      "nvd": {
        "published": "2026-07-27T09:16:37.383",
        "lastModified": "2026-07-31T14:16:47.337",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16554",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-16554",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/DaveGamble/cJSON",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/26",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/31/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 849,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16560",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T12:11:52.389Z",
      "date_published": "2026-07-22T12:51:43.263Z",
      "date_updated": "2026-07-22T18:01:52.422Z",
      "publisher": "redhat",
      "title": "389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 11"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 12"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 13"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1220",
          "name": "Insufficient Granularity of Access Control",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15707
      },
      "nvd": {
        "published": "2026-07-22T14:17:18.043",
        "lastModified": "2026-07-22T19:16:57.877",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16560",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A legacy-quoted multivalued RDN leaves heap ownership inconsistent so a later call reuses the same pointer and can overwrite the allocation.",
        "basis": [
          "CNA",
          "CWE-1220"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16560",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506102",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 283,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16581",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T13:40:37.456Z",
      "date_published": "2026-07-28T20:05:35.105Z",
      "date_updated": "2026-07-29T13:59:18.399Z",
      "publisher": "icscert",
      "title": "Inclusion of sensitive information in source code in igloohome Smart Lock Mobile Application",
      "affected": {
        "vendors": [
          "igloohome"
        ],
        "products": [
          {
            "vendor": "igloohome",
            "product": "Smart Lock Mobile Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-540",
          "name": "Inclusion of Sensitive Information in Source Code",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13281
      },
      "nvd": {
        "published": "2026-07-28T21:17:28.070",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16581",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Sensitive backend material embedded in the mobile application source can be recovered and used against functions that lack sufficient authentication.",
        "basis": [
          "CNA",
          "CWE-540"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 266,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16584",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T13:43:35.240Z",
      "date_published": "2026-07-23T15:34:11.317Z",
      "date_updated": "2026-07-23T18:16:50.894Z",
      "publisher": "AMZN",
      "title": "AWS API MCP Server Security Policy Bypass via Startup Failure",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "aws-api-mcp-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-455",
          "name": "Non-exit on Failed Initialization",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03034
      },
      "nvd": {
        "published": "2026-07-23T16:17:15.787",
        "lastModified": "2026-07-23T19:16:53.537",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16584",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-policy initialization failure leaves the process running and skips policy checks for the rest of that process lifetime.",
        "basis": [
          "CNA",
          "CWE-455"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://pypi.org/project/awslabs.aws-api-mcp-server/1.3.47/",
          "host": "pypi.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-063-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/awslabs/mcp/security/advisories/GHSA-29w2-fq35-v728",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16585",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T13:45:18.223Z",
      "date_published": "2026-07-28T05:39:44.828Z",
      "date_updated": "2026-07-28T16:05:04.482Z",
      "publisher": "Wordfence",
      "title": "Better Messages <= 2.15.19 - Authenticated (Administrator+) Arbitrary File Deletion via Path Traversal via 'file' Parameter",
      "affected": {
        "vendors": [
          "wordplus"
        ],
        "products": [
          {
            "vendor": "wordplus",
            "product": "Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00734,
        "percentile": 0.50857
      },
      "nvd": {
        "published": "2026-07-28T07:16:41.993",
        "lastModified": "2026-07-28T16:17:32.097",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16585",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e9274957-7584-4df6-bb2a-d745510f5033?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bp-better-messages/tags/2.15.19/addons/stickers/rest.php#L285",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bp-better-messages/tags/2.15.19/addons/stickers/rest.php#L287",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bp-better-messages/tags/2.15.19/addons/stickers/pack-manager.php#L764",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/bp-better-messages/tags/2.15.19/addons/stickers/rest.php#L153",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3623636/bp-better-messages/trunk/addons/stickers/rest.php?old=3527109&old_path=bp-better-messages%2Ftrunk%2Faddons%2Fstickers%2Frest.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 881,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16587",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T13:47:06.150Z",
      "date_published": "2026-07-28T05:39:44.028Z",
      "date_updated": "2026-07-28T14:54:01.926Z",
      "publisher": "Wordfence",
      "title": "Advanced Form Integration <= 2.6.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary MailUp OAuth Token Overwrite via auth_redirect() Function",
      "affected": {
        "vendors": [
          "nasirahmed"
        ],
        "products": [
          {
            "vendor": "nasirahmed",
            "product": "Advanced Form Integration — Connect Forms to 200+ Apps"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12813
      },
      "nvd": {
        "published": "2026-07-28T07:16:42.130",
        "lastModified": "2026-07-28T16:17:32.807",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16587",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OAuth redirect handler lets any signed-in subscriber overwrite site-wide MailUp tokens without an administrative capability check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/af913bb1-eff6-47cd-9471-f74bafda1e52?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.6.0/platforms/mailup/mailup.php#L98",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.6.0/platforms/mailup/mailup.php#L51",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.6.0/platforms/mailup/mailup.php#L375",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.6.0/platforms/mailup/mailup.php#L411",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3621411%40advanced-form-integration&new=3621411%40advanced-form-integration",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 751,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16597",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T13:53:12.572Z",
      "date_published": "2026-07-29T09:31:12.876Z",
      "date_updated": "2026-07-29T15:22:35.098Z",
      "publisher": "Wordfence",
      "title": "GTM4WP <= 1.22.3 - Unauthenticated Stored Cross-Site Scripting via WooCommerce Billing Fields",
      "affected": {
        "vendors": [
          "duracelltomi"
        ],
        "products": [
          {
            "vendor": "duracelltomi",
            "product": "GTM4WP – A Google Tag Manager (GTM) plugin for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15311
      },
      "nvd": {
        "published": "2026-07-29T11:16:48.330",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16597",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Stored billing fields are rendered without sufficient browser-context escaping and execute as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/03542812-b6e5-421d-9ba6-43f1c779940f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/duracelltomi-google-tag-manager/tags/1.22.3/public/frontend.php#L1148",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/duracelltomi-google-tag-manager/tags/1.22.3/integration/woocommerce.php#L265",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/duracelltomi-google-tag-manager/tags/1.22.3/integration/woocommerce.php#L664",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/duracelltomi-google-tag-manager/tags/1.22.3/integration/woocommerce.php#L942",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3618063/duracelltomi-google-tag-manager/trunk/public/frontend.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fduracelltomi-google-tag-manager/tags/1.22.3&new_path=%2Fduracelltomi-google-tag-manager/tags/1.22.4",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 677,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16606",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T14:31:08.591Z",
      "date_published": "2026-07-22T15:14:12.557Z",
      "date_updated": "2026-07-22T18:50:25.615Z",
      "publisher": "FTI",
      "title": "Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris",
      "affected": {
        "vendors": [
          "Fujitsu"
        ],
        "products": [
          {
            "vendor": "Fujitsu",
            "product": "Linux openFT"
          },
          {
            "vendor": "Fujitsu",
            "product": "Oracle Solaris openFT"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:763b0cbd-1a52-41de-b280-f255286be201",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:763b0cbd-1a52-41de-b280-f255286be201",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00651,
        "percentile": 0.47692
      },
      "nvd": {
        "published": "2026-07-22T16:17:16.800",
        "lastModified": "2026-07-22T20:52:35.747",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16606",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A network-reachable openFT path permits unauthenticated input to become executable code, although the affected parser or command path is not public.",
        "basis": [
          "CNA record",
          "CWE-94",
          "Fujitsu security notice"
        ],
        "deepDive": true,
        "notes": "Inspected https://security.eu.fsastech.com/IndexDownload.asp?SoftwareGuid=20873292-0006-4a1c-a188-3940762a0075 and retrieved https://security.ts.fujitsu.com/ProductSecurity/content/FsasTech-PSIRT-FTI-FG-2026-042411-Security-Notice.pdf; the public notice identifies openFT, the critical rating, and fixed release but does not expose the vulnerable component or input-to-code path."
      },
      "references": [
        {
          "url": "https://security.eu.fsastech.com/IndexDownload.asp?SoftwareGuid=20873292-0006-4a1c-a188-3940762a0075",
          "host": "security.eu.fsastech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://security.ts.fujitsu.com/ProductSecurity/content/FsasTech-PSIRT-FTI-FG-2026-042411-Security-Notice.pdf",
          "host": "security.ts.fujitsu.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://global.fujitsu/de-de/capabilities/mainframe-solutions/bs2000-integration",
          "host": "global.fujitsu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "mitigation"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16607",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T14:31:14.251Z",
      "date_published": "2026-07-22T15:07:35.516Z",
      "date_updated": "2026-07-22T18:51:08.134Z",
      "publisher": "FTI",
      "title": "Authenticated local root privilege escalation vulnerability in openFT for Linux and Oracle Solaris",
      "affected": {
        "vendors": [
          "Fujitsu"
        ],
        "products": [
          {
            "vendor": "Fujitsu",
            "product": "Linux openFT"
          },
          {
            "vendor": "Fujitsu",
            "product": "Oracle Solaris openFT"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:763b0cbd-1a52-41de-b280-f255286be201",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:763b0cbd-1a52-41de-b280-f255286be201",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.001,
        "percentile": 0.01035
      },
      "nvd": {
        "published": "2026-07-22T16:17:16.963",
        "lastModified": "2026-07-22T20:52:35.747",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16607",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Linux openFT permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.eu.fsastech.com/IndexDownload.asp?SoftwareGuid=20873292-0006-4a1c-a188-3940762a0075",
          "host": "security.eu.fsastech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://security.ts.fujitsu.com/ProductSecurity/content/FsasTech-PSIRT-FTI-FG-2026-042411-Security-Notice.pdf",
          "host": "security.ts.fujitsu.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://global.fujitsu/de-de/capabilities/mainframe-solutions/bs2000-integration",
          "host": "global.fujitsu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "mitigation"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 378,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16610",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T14:35:11.380Z",
      "date_published": "2026-07-30T04:03:13.843Z",
      "date_updated": "2026-07-30T15:17:43.117Z",
      "publisher": "Wordfence",
      "title": "Admin and Site Enhancements (ASE) Pro <= 8.9.0 - Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key",
      "affected": {
        "vendors": [
          "ASE"
        ],
        "products": [
          {
            "vendor": "ASE",
            "product": "Admin and Site Enhancements (ASE) Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00578,
        "percentile": 0.44328
      },
      "nvd": {
        "published": "2026-07-30T05:16:34.520",
        "lastModified": "2026-07-30T16:16:57.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16610",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public form stores attacker-controlled repeater keys and later splices them into eval without validating them as identifiers.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2ef21a44-6d03-4197-b49c-d881f9831f46?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.wpase.com/",
          "host": "www.wpase.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 842,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16615",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T14:38:37.901Z",
      "date_published": "2026-07-22T16:12:03.536Z",
      "date_updated": "2026-07-31T13:58:32.910Z",
      "publisher": "redhat",
      "title": "Librest: weak random number generation in pkce implementation",
      "affected": {
        "vendors": [
          "GNOME",
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "GNOME",
            "product": "librest"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16943
      },
      "nvd": {
        "published": "2026-07-22T17:16:55.863",
        "lastModified": "2026-07-31T14:16:47.483",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16615",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PKCE implementation generates code verifiers with GLib GRand, whose predictable output lacks the cryptographic entropy required to bind an OAuth exchange.",
        "basis": [
          "CNA",
          "CWE-338"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47085",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16615",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2504432",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/librest/-/issues/25",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 525,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16624",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T15:02:38.700Z",
      "date_published": "2026-07-22T18:31:20.732Z",
      "date_updated": "2026-07-27T17:10:37.711Z",
      "publisher": "certcc",
      "title": "CVE-2026-16624",
      "affected": {
        "vendors": [
          "Cal.com"
        ],
        "products": [
          {
            "vendor": "Cal.com",
            "product": "Cal.diy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20343
      },
      "nvd": {
        "published": "2026-07-22T19:16:58.273",
        "lastModified": "2026-07-27T18:16:52.807",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16624",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The request accepts an object or tenant identifier without binding that identifier to the authenticated caller's authorized scope.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/calcom/cal.diy/security/advisories/GHSA-4fwh-xxpv-xfm6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://vokecyber.com/research/calcom-cross-tenant-webhook-plant",
          "host": "vokecyber.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16628",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T15:53:15.527Z",
      "date_published": "2026-07-22T21:00:12.521Z",
      "date_updated": "2026-07-23T13:47:28.526Z",
      "publisher": "VulDB",
      "title": "oclif JIT Plugin Entry child_process.exec os command injection",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "oclif"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 17,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00622,
        "percentile": 0.46384
      },
      "nvd": {
        "published": "2026-07-22T22:16:28.000",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16628",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The JIT plugin entry passes attacker-controlled jitPlugins text to child_process.exec without neutralizing shell syntax.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/382372",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/382372/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16628",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/860149",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/oclif/oclif/issues/2051",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/oclif/oclif/pull/2052",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/oclif/oclif/commit/939b045725e065baebc4587b8bccfd56731eed3d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/oclif/oclif/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 454,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-16629",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T16:02:19.846Z",
      "date_published": "2026-07-22T21:15:10.595Z",
      "date_updated": "2026-07-28T14:56:05.436Z",
      "publisher": "VulDB",
      "title": "danger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injection",
      "affected": {
        "vendors": [
          "danger"
        ],
        "products": [
          {
            "vendor": "danger",
            "product": "danger-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00622,
        "percentile": 0.46385
      },
      "nvd": {
        "published": "2026-07-22T22:16:29.073",
        "lastModified": "2026-07-28T16:17:33.610",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16629",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The danger-js path inserts attacker-controlled text into an operating-system command without preserving the command grammar.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/382377",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/382377/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16629",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/860211",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/danger/danger-js/pull/1513",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/danger/danger-js/commit/087a7290264cc6fb7154ea8c2552a7b2cb8b33a3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/danger/danger-js/releases/tag/13.0.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/danger/danger-js/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 484,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-16630",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T16:04:48.407Z",
      "date_published": "2026-07-22T22:15:12.312Z",
      "date_updated": "2026-07-23T14:17:09.169Z",
      "publisher": "VulDB",
      "title": "syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection",
      "affected": {
        "vendors": [
          "syncfusion"
        ],
        "products": [
          {
            "vendor": "syncfusion",
            "product": "ej2-javascript-ui-controls"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00635,
        "percentile": 0.4696
      },
      "nvd": {
        "published": "2026-07-22T23:16:34.890",
        "lastModified": "2026-07-23T15:25:49.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16630",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input crosses into an executable interpreter context without safe grammar separation.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/382380",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/382380/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16630",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/860232",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/syncfusion/ej2-javascript-ui-controls/issues/215",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/syncfusion/ej2-javascript-ui-controls/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 313,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16631",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T16:08:22.735Z",
      "date_published": "2026-07-22T23:30:14.981Z",
      "date_updated": "2026-07-23T13:44:17.592Z",
      "publisher": "VulDB",
      "title": "publint package-manager pack.js child_process.exec os command injection",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "publint"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00635,
        "percentile": 0.46954
      },
      "nvd": {
        "published": "2026-07-23T00:16:26.927",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16631",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The publint command path concatenates attacker-controlled data into an operating-system command without preserving the shell grammar boundary.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/382381",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/382381/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16631",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/860239",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/publint/publint/issues/236",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/publint/publint/pull/238",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/publint/publint/commit/adf2d9a09945fc98c85a2520a89f441d78b2dbd8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/publint/publint/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16632",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T16:13:01.618Z",
      "date_published": "2026-07-22T23:45:10.246Z",
      "date_updated": "2026-07-23T15:36:53.311Z",
      "publisher": "VulDB",
      "title": "boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validation",
      "affected": {
        "vendors": [
          "boazsegev"
        ],
        "products": [
          {
            "vendor": "boazsegev",
            "product": "facil.io"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23412
      },
      "nvd": {
        "published": "2026-07-23T00:16:28.020",
        "lastModified": "2026-07-23T16:17:15.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16632",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "websocket_on_protocol_error accepts an invalid on_message condition without the required validation, but the record does not publish the exact malformed frame state.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/382382",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/382382/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16632",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/860585",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/boazsegev/facil.io/issues/169",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/boazsegev/facil.io/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 469,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16634",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T16:37:55.533Z",
      "date_published": "2026-07-24T09:14:58.986Z",
      "date_updated": "2026-07-27T17:15:54.188Z",
      "publisher": "CPANSec",
      "title": "TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99",
      "affected": {
        "vendors": [
          "FELIPE"
        ],
        "products": [
          {
            "vendor": "FELIPE",
            "product": "TOML::XS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1104",
          "name": "Use of Unmaintained Third Party Components",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1395",
          "name": "Dependency on Vulnerable Third-Party Component",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00768,
        "percentile": 0.52025
      },
      "nvd": {
        "published": "2026-07-24T10:16:31.693",
        "lastModified": "2026-07-27T18:16:52.970",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16634",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TOML::XS bundles the abandoned tomlc99 parser, whose recursive handling of deeply nested TOML can overflow the caller stack.",
        "basis": [
          "CNA",
          "CWE-1104",
          "CWE-1395"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/FELIPE/TOML-XS-0.06/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/cktan/tomlc99/29076dfd095bbbbd50a3c1b2760d29f4b83e74ac/README.md",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cktan/tomlc99/issues/97",
          "host": "github.com",
          "sources": [
            "adp:1",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/cktan/tomlc17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://toml.io/en/v1.0.0",
          "host": "toml.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16653",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T18:20:31.073Z",
      "date_published": "2026-07-23T01:15:11.052Z",
      "date_updated": "2026-07-23T16:06:10.749Z",
      "publisher": "VulDB",
      "title": "boazsegev facil.io Public Folder http.c http_sendfile2 path traversal",
      "affected": {
        "vendors": [
          "boazsegev"
        ],
        "products": [
          {
            "vendor": "boazsegev",
            "product": "facil.io"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 59,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.0048,
        "percentile": 0.38911
      },
      "nvd": {
        "published": "2026-07-23T02:16:27.720",
        "lastModified": "2026-07-23T16:17:16.053",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16653",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "facil.io http_sendfile2 accepts a path that traverses beyond the configured public folder.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/382396",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/382396/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16653",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/860587",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/boazsegev/facil.io/issues/170",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/boazsegev/facil.io/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 456,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 59
      }
    },
    {
      "cve_id": "CVE-2026-16655",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T19:21:47.424Z",
      "date_published": "2026-07-29T09:31:14.503Z",
      "date_updated": "2026-07-29T12:24:03.916Z",
      "publisher": "Wordfence",
      "title": "Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member",
      "affected": {
        "vendors": [
          "wpmanageninja"
        ],
        "products": [
          {
            "vendor": "wpmanageninja",
            "product": "Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.2271
      },
      "nvd": {
        "published": "2026-07-29T11:16:48.480",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16655",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/635e19ba-da98-459c-ab91-ff969b0812fd?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.7/boot/globals.php#L110",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.7/app/Hooks/Ajax.php#L17",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.7/app/Modules/SubmissionHandler/SubmissionHandler.php#L20",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.7/app/Services/Form/SubmissionHandlerService.php#L123",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.7/app/Modules/Form/FormDataParser.php#L317",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.7/app/Services/Integrations/GlobalNotificationService.php#L59",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.6/boot/globals.php#L110",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.6/app/Hooks/Ajax.php#L17",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.6/app/Modules/SubmissionHandler/SubmissionHandler.php#L20",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.6/app/Services/Form/SubmissionHandlerService.php#L123",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.6/app/Modules/Form/FormDataParser.php#L317",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.6/app/Services/Integrations/GlobalNotificationService.php#L59",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3619584/fluentform/trunk/boot/globals.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Ffluentform/tags/6.2.7&new_path=%2Ffluentform/tags/6.2.8",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 15,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T02:40:02.606Z",
      "date_published": "2026-07-23T08:26:24.453Z",
      "date_updated": "2026-07-23T13:54:13.031Z",
      "publisher": "alibaba",
      "title": "Remote Code Execution in fastjson 1.2.68–1.2.83",
      "affected": {
        "vendors": [
          "Alibaba"
        ],
        "products": [
          {
            "vendor": "Alibaba",
            "product": "Fastjson"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:alibaba-cna@list.alibaba-inc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00413,
        "percentile": 0.34036
      },
      "nvd": {
        "published": "2026-07-23T09:16:26.700",
        "lastModified": "2026-07-23T15:01:24.377",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16723",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fastjson 1.x type resolution can treat attacker-directed resource and annotation signals as trust under default AutoType-off settings, allowing an @type value to reach class loading in a Spring Boot executable fat jar.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-502",
          "https://github.com/alibaba/fastjson2/wiki/Security-Advisory%3A-Remote-Code-Execution-in-fastjson-1.2.68%E2%80%931.2.83"
        ],
        "deepDive": true,
        "notes": "Alibaba's advisory confirms the affected parse entry points, default AutoType-off and SafeMode-off configuration, Spring Boot executable-fat-jar prerequisite, resource probing, annotation trust bypass, and class-loading consequence; source or patch lines were not published there."
      },
      "references": [
        {
          "url": "https://github.com/alibaba/fastjson2/wiki/Security-Advisory:-Remote-Code-Execution-in-fastjson-1.2.68%E2%80%931.2.83",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "mitigation",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16727",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T03:32:02.585Z",
      "date_published": "2026-07-30T02:00:07.781Z",
      "date_updated": "2026-07-31T03:55:49.349Z",
      "publisher": "ASUS",
      "title": "Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement.",
      "affected": {
        "vendors": [
          "ASUS"
        ],
        "products": [
          {
            "vendor": "ASUS",
            "product": "Armoury Crate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00087,
        "percentile": 0.00428
      },
      "nvd": {
        "published": "2026-07-30T02:16:45.537",
        "lastModified": "2026-07-31T04:16:48.200",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16727",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Armoury Crate has a file-replacement race that lets a local user substitute a crafted file before the elevated consumer uses it.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asus.com/security-advisory",
          "host": "www.asus.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16728",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T04:21:23.161Z",
      "date_published": "2026-07-29T20:59:02.314Z",
      "date_updated": "2026-07-30T15:18:18.440Z",
      "publisher": "openjs",
      "title": "undici vulnerable to downstream response desynchronization via retry interceptor",
      "affected": {
        "vendors": [
          "undici"
        ],
        "products": [
          {
            "vendor": "undici",
            "product": "undici"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.7000000000000002,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07343
      },
      "nvd": {
        "published": "2026-07-29T21:17:46.833",
        "lastModified": "2026-08-04T14:06:21.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16728",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The retry interceptor assembles a new response body while preserving the old Content-Length, so downstream peers receive inconsistent message boundaries.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1038,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-16729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T05:44:24.720Z",
      "date_published": "2026-07-29T16:45:57.001Z",
      "date_updated": "2026-07-29T18:08:16.149Z",
      "publisher": "openjs",
      "title": "undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields",
      "affected": {
        "vendors": [
          "undici"
        ],
        "products": [
          {
            "vendor": "undici",
            "product": "undici"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.0737
      },
      "nvd": {
        "published": "2026-07-29T17:16:51.123",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16729",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "undici accepts semicolons and unsanitized entries inside cookie attributes, allowing user input to inject additional Set-Cookie grammar.",
        "basis": [
          "CNA",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 863,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-16730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T05:56:48.689Z",
      "date_published": "2026-07-24T11:26:18.978Z",
      "date_updated": "2026-07-24T14:48:10.753Z",
      "publisher": "redhat",
      "title": "Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-755",
          "name": "Improper Handling of Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01325
      },
      "nvd": {
        "published": "2026-07-24T12:16:47.717",
        "lastModified": "2026-07-24T20:49:03.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16730",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "File-descriptor exhaustion makes SO_PEERPIDFD setup return EMFILE or ENFILE, and the broker treats that recoverable resource failure as fatal and exits.",
        "basis": [
          "CNA",
          "CWE-755"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16730",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506348",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/bus1/dbus-broker/issues/435",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16733",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T07:36:57.392Z",
      "date_published": "2026-07-23T13:30:09.258Z",
      "date_updated": "2026-07-23T15:38:22.184Z",
      "publisher": "VulDB",
      "title": "bahmutov find-cypress-specs Branch index.js shell.exec os command injection",
      "affected": {
        "vendors": [
          "bahmutov"
        ],
        "products": [
          {
            "vendor": "bahmutov",
            "product": "find-cypress-specs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 13,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00612,
        "percentile": 0.45876
      },
      "nvd": {
        "published": "2026-07-23T14:17:08.660",
        "lastModified": "2026-07-23T16:17:16.200",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16733",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The find-cypress-specs command path passes attacker-controlled text into command syntax without argument or shell separation.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/382478",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/382478/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16733",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/861021",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/bahmutov/find-cypress-specs/issues/423",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/bahmutov/find-cypress-specs/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 477,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-16735",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T07:39:05.652Z",
      "date_published": "2026-07-23T13:45:09.720Z",
      "date_updated": "2026-07-27T20:24:08.893Z",
      "publisher": "VulDB",
      "title": "release-it conventional-changelog Changelog File index.js writeChangelog os command injection",
      "affected": {
        "vendors": [
          "release-it"
        ],
        "products": [
          {
            "vendor": "release-it",
            "product": "conventional-changelog"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00622,
        "percentile": 0.46384
      },
      "nvd": {
        "published": "2026-07-23T14:17:08.880",
        "lastModified": "2026-07-27T21:16:48.193",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16735",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "writeChangelog places the infile value into an operating-system command without neutralizing shell syntax.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/382479",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/382479/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16735",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/861024",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/release-it/conventional-changelog/issues/149",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/release-it/conventional-changelog/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 462,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-16743",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T10:03:08.205Z",
      "date_published": "2026-07-24T12:56:34.520Z",
      "date_updated": "2026-08-03T10:42:36.155Z",
      "publisher": "redhat",
      "title": "Accountsservice: accountsservice: arbitrary file read via seticonfile for systemd-homed users",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00099,
        "percentile": 0.00935
      },
      "nvd": {
        "published": "2026-07-24T13:17:27.173",
        "lastModified": "2026-07-24T20:49:03.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16743",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The systemd-homed SetIconFile path opens a caller-selected filename as root without the validation and privilege drop used by the classic handler.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16743",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506381",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.freedesktop.org/accountsservice/accountsservice/-/work_items/138",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16745",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T10:24:31.723Z",
      "date_published": "2026-07-23T10:41:30.121Z",
      "date_updated": "2026-07-23T13:53:36.543Z",
      "publisher": "redhat",
      "title": "Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without origin validation",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift AI (RHOAI)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.1511
      },
      "nvd": {
        "published": "2026-07-23T11:16:40.043",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16745",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The odh-dashboard backend listens on a cluster-reachable port and trusts X-Forwarded-Access-Token without confirming that the request traversed the trusted proxy, allowing an internal caller to assert proxy identity directly.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16745",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506350",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 428,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16751",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:58:51.242Z",
      "date_published": "2026-07-29T13:16:00.450Z",
      "date_updated": "2026-07-30T13:40:06.238Z",
      "publisher": "certcc",
      "title": "Ente Museum Server Authorization Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Ente"
        ],
        "products": [
          {
            "vendor": "Ente",
            "product": "Museum Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-778",
          "name": "Insufficient Logging",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21758
      },
      "nvd": {
        "published": "2026-07-29T14:16:28.683",
        "lastModified": "2026-07-30T19:11:24.687",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16751",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The emergency approval API accepts a recovery approval before the configured waiting-period transition has completed.",
        "basis": [
          "CNA",
          "CWE-778",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ente/ente/tree/v2.0.34",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://vokecyber.com/research/cve-2026-16751-ente-emergency-recovery-bypass",
          "host": "vokecyber.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://vokecyber.com/blog/cve-2026-16751-ente-emergency-recovery-bypass",
          "host": "vokecyber.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T13:10:13.818Z",
      "date_published": "2026-07-23T18:32:53.792Z",
      "date_updated": "2026-07-23T19:03:57.617Z",
      "publisher": "AMZN",
      "title": "Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "aws-smithy-http-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00417,
        "percentile": 0.3437
      },
      "nvd": {
        "published": "2026-07-23T19:16:53.657",
        "lastModified": "2026-07-23T20:17:07.740",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16756",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The default server path lacks header-read timeouts and a connection cap, so incomplete requests can retain sockets and tasks indefinitely.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://crates.io/crates/aws-smithy-http-server/0.66.5",
          "host": "crates.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-064-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/smithy-lang/smithy-rs/security/advisories/GHSA-jvxp-qmx7-gjpx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 420,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T14:06:33.140Z",
      "date_published": "2026-07-23T21:15:10.064Z",
      "date_updated": "2026-07-24T13:39:45.705Z",
      "publisher": "VulDB",
      "title": "localstack serverless-localstack Configuration index.js os command injection",
      "affected": {
        "vendors": [
          "localstack"
        ],
        "products": [
          {
            "vendor": "localstack",
            "product": "serverless-localstack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00703,
        "percentile": 0.49725
      },
      "nvd": {
        "published": "2026-07-23T22:16:51.910",
        "lastModified": "2026-07-24T20:47:10.293",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16763",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "serverless-localstack incorporates custom.localstack.docker.compose_file into an operating-system command without neutralizing shell syntax.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/382620",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/382620/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16763",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/861028",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/localstack/serverless-localstack/issues/303",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/localstack/serverless-localstack/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 480,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-16764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T14:12:06.687Z",
      "date_published": "2026-07-23T21:30:11.529Z",
      "date_updated": "2026-07-24T14:39:30.521Z",
      "publisher": "VulDB",
      "title": "OWASP DefectDojo API/Web serializers.py UserSerializer privileges management",
      "affected": {
        "vendors": [
          "OWASP"
        ],
        "products": [
          {
            "vendor": "OWASP",
            "product": "DefectDojo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14292
      },
      "nvd": {
        "published": "2026-07-23T22:16:52.077",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16764",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "UserSerializer accepts control of is_staff without restricting that privilege assignment to an authorized administrator.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/382629",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/382629/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16764",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/861317",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/DefectDojo/django-DefectDojo/security/advisories/GHSA-w2j3-x3j3-mm43",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/DefectDojo/django-DefectDojo/pull/14952",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/DefectDojo/django-DefectDojo/commit/68a272f299d096249fd3ba9c2676bf69012857bf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/DefectDojo/django-DefectDojo/releases/tag/3.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T14:15:30.761Z",
      "date_published": "2026-07-23T21:45:09.650Z",
      "date_updated": "2026-07-24T14:00:32.694Z",
      "publisher": "VulDB",
      "title": "CodeAstro Online Classroom loginlinkadmin.php sql injection",
      "affected": {
        "vendors": [
          "CodeAstro"
        ],
        "products": [
          {
            "vendor": "CodeAstro",
            "product": "Online Classroom"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 7.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18019
      },
      "nvd": {
        "published": "2026-07-23T22:16:52.250",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16765",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Online Classroom incorporates loginlinkadmin.php input into an SQL statement without separating data from SQL syntax.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/382637",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/382637/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16765",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862023",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/anglemsg2401-bot/cve/issues/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://codeastro.com/",
          "host": "codeastro.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16766",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T14:17:40.588Z",
      "date_published": "2026-07-25T08:12:42.260Z",
      "date_updated": "2026-07-27T15:58:01.733Z",
      "publisher": "CPANSec",
      "title": "Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options",
      "affected": {
        "vendors": [
          "RRWO"
        ],
        "products": [
          {
            "vendor": "RRWO",
            "product": "Catalyst::View::Wkhtmltopdf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01304,
        "percentile": 0.67711
      },
      "nvd": {
        "published": "2026-07-25T09:16:32.000",
        "lastModified": "2026-07-28T16:19:30.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16766",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Options are passed directly to the wkhtmltopdf command without sanitization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/robrwo/Catalyst-View-Wkhtmltopdf/security/advisories/GHSA-42w4-jj8w-6p98",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://metacpan.org/release/RRWO/Catalyst-View-Wkhtmltopdf-v0.6.1/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/mc7244/Catalyst-View-Wkhtmltopdf/issues/6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/25/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T14:25:29.169Z",
      "date_published": "2026-07-23T22:15:11.686Z",
      "date_updated": "2026-07-24T11:09:57.109Z",
      "publisher": "VulDB",
      "title": "Ne-Lexa php-zip ZIP ZipFile.php extractTo path traversal",
      "affected": {
        "vendors": [
          "Ne-Lexa"
        ],
        "products": [
          {
            "vendor": "Ne-Lexa",
            "product": "php-zip"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00479,
        "percentile": 0.38839
      },
      "nvd": {
        "published": "2026-07-23T23:16:48.400",
        "lastModified": "2026-07-24T20:45:45.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16767",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ZipFile::extractTo accepts an archive entryName that can traverse outside the extraction directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/382660",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/382660/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-16767",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862203",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/Ne-Lexa/php-zip/issues/100",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/Ne-Lexa/php-zip/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T14:25:29.368Z",
      "date_published": "2026-07-23T16:41:20.704Z",
      "date_updated": "2026-07-31T14:03:37.674Z",
      "publisher": "redhat",
      "title": "Gdk-pixbuf: out-of-bounds read in ico parser",
      "affected": {
        "vendors": [
          "GNOME",
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "GNOME",
            "product": "gdk-pixbuf"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14717
      },
      "nvd": {
        "published": "2026-07-23T17:16:28.037",
        "lastModified": "2026-07-31T14:16:47.617",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16768",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the valid input or buffer boundary because its size check is incomplete.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16768",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506437",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302",
          "host": "gitlab.gnome.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 453,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T16:36:49.550Z",
      "date_published": "2026-07-28T18:21:40.048Z",
      "date_updated": "2026-07-28T19:31:06.344Z",
      "publisher": "certcc",
      "title": "CVE-2026-16771",
      "affected": {
        "vendors": [
          "AT&T"
        ],
        "products": [
          {
            "vendor": "AT&T",
            "product": "Arris BGW210‑700"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16446
      },
      "nvd": {
        "published": "2026-07-28T19:17:32.247",
        "lastModified": "2026-07-30T19:10:06.847",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16771",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The gateway relies on CSS and JavaScript to hide management endpoints while the CGI handlers perform no server-side authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://kb.cert.org/vuls/id/141367",
          "host": "kb.cert.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.kb.cert.org/vuls/id/141367",
          "host": "www.kb.cert.org",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 473,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16773",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T17:08:39.007Z",
      "date_published": "2026-07-28T11:32:48.445Z",
      "date_updated": "2026-07-28T19:18:32.377Z",
      "publisher": "Wordfence",
      "title": "WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action",
      "affected": {
        "vendors": [
          "quantumcloud"
        ],
        "products": [
          {
            "vendor": "quantumcloud",
            "product": "WPBot – AI ChatBot for Live Support, Lead Generation, AI Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.1949
      },
      "nvd": {
        "published": "2026-07-28T12:16:35.900",
        "lastModified": "2026-07-28T20:17:24.137",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16773",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated AJAX action can send stored chat transcripts and user PII to an attacker-chosen email address.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5463548c-22bd-4645-a94d-ee8c6a236337?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.9/includes/chat-sessions/wpbot-chat-sessions.php#L746",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.9/includes/chat-sessions/wpbot-chat-sessions.php#L707",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.9/includes/chat-sessions/wpbot-chat-sessions.php#L690",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.9/includes/chat-sessions/wpbot-chat-sessions.php#L702",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3621386%40chatbot&new=3621386%40chatbot",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 489,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16774",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T17:09:30.160Z",
      "date_published": "2026-07-28T11:32:47.474Z",
      "date_updated": "2026-07-28T14:53:38.807Z",
      "publisher": "Wordfence",
      "title": "WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action",
      "affected": {
        "vendors": [
          "quantumcloud"
        ],
        "products": [
          {
            "vendor": "quantumcloud",
            "product": "WPBot – AI ChatBot for Live Support, Lead Generation, AI Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14486
      },
      "nvd": {
        "published": "2026-07-28T12:16:36.030",
        "lastModified": "2026-07-28T16:17:34.383",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16774",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "wpcs_send_email is exposed to anonymous callers without a nonce or capability check and forwards caller-selected mail fields to wp_mail.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3cc6aa06-ab2a-4d5c-bbbe-4c19722ccc53?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.9/includes/chat-sessions/wpbot-chat-sessions.php#L494",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.9/includes/chat-sessions/wpbot-chat-sessions.php#L483",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.9/includes/chat-sessions/wpbot-chat-sessions.php#L478",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3621386%40chatbot&new=3621386%40chatbot",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 645,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16796",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T18:37:41.297Z",
      "date_published": "2026-07-23T20:06:32.908Z",
      "date_updated": "2026-07-24T13:34:19.993Z",
      "publisher": "AMZN",
      "title": "Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "bedrock-agentcore 1.18.1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00327,
        "percentile": 0.2519
      },
      "nvd": {
        "published": "2026-07-23T21:17:03.510",
        "lastModified": "2026-07-24T20:47:41.790",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16796",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A package name reaches the interpreter command as an unneutralized argument and can introduce additional command delimiters.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://pypi.org/project/bedrock-agentcore/1.18.1/",
          "host": "pypi.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-065-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/aws/bedrock-agentcore-sdk-python/security/advisories/GHSA-j6g5-3hh3-pgw8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 350,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16797",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:09:23.352Z",
      "date_published": "2026-07-28T05:39:43.219Z",
      "date_updated": "2026-07-28T12:59:11.414Z",
      "publisher": "Wordfence",
      "title": "ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter",
      "affected": {
        "vendors": [
          "devitemsllc"
        ],
        "products": [
          {
            "vendor": "devitemsllc",
            "product": "ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12311
      },
      "nvd": {
        "published": "2026-07-28T07:16:42.260",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16797",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled optionSection key selects arbitrary option rows beyond the caller's intended authority.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/75d5c684-090e-4fff-9bf7-2b7c41ef95d3?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.4.5/woolentor-blocks/includes/classes/Api/Api.php#L476",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.4.5/woolentor-blocks/includes/helper-functions.php#L7",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.4.5/woolentor-blocks/includes/classes/Api/Api.php#L143",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.4.5/woolentor-blocks/includes/classes/Api/Api.php#L168",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3623166%40woolentor-addons&new=3623166%40woolentor-addons",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 628,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16798",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:24:47.342Z",
      "date_published": "2026-07-24T14:53:01.692Z",
      "date_updated": "2026-07-24T17:49:40.208Z",
      "publisher": "DEVOLUTIONS",
      "title": "Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "PowerShell Universal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13077
      },
      "nvd": {
        "published": "2026-07-24T15:17:12.750",
        "lastModified": "2026-07-29T20:32:34.230",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16798",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Automation-job read responses return another user's stored OAuth refresh token without stripping the sensitive field.",
        "basis": [
          "CNA record",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0025/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:24:53.307Z",
      "date_published": "2026-07-24T14:53:33.439Z",
      "date_updated": "2026-07-24T17:47:16.710Z",
      "publisher": "DEVOLUTIONS",
      "title": "Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "PowerShell Universal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.0489
      },
      "nvd": {
        "published": "2026-07-24T15:17:12.857",
        "lastModified": "2026-07-29T20:33:19.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16799",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The server omits role authorization on automation tests and workflow updates, allowing a Reader to execute or modify them.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0025/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:24:57.616Z",
      "date_published": "2026-07-24T14:54:56.746Z",
      "date_updated": "2026-07-24T17:43:24.583Z",
      "publisher": "DEVOLUTIONS",
      "title": "Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "PowerShell Universal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21698
      },
      "nvd": {
        "published": "2026-07-24T15:17:12.963",
        "lastModified": "2026-07-29T20:33:43.027",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16800",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PowerShell Universal concatenates crafted schedule parameter names into a PowerShell invocation as executable syntax.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0025/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 314,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:25:01.955Z",
      "date_published": "2026-07-24T14:55:22.997Z",
      "date_updated": "2026-07-24T17:40:50.106Z",
      "publisher": "DEVOLUTIONS",
      "title": "Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "PowerShell Universal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21697
      },
      "nvd": {
        "published": "2026-07-24T15:17:13.077",
        "lastModified": "2026-07-29T20:33:59.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16801",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The variables feature writes an unescaped attacker-controlled value into a PowerShell configuration file, turning variable data into executable PowerShell syntax.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0025/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:25:10.122Z",
      "date_published": "2026-07-24T14:55:56.419Z",
      "date_updated": "2026-07-24T17:39:03.467Z",
      "publisher": "DEVOLUTIONS",
      "title": "Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "PowerShell Universal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-312",
          "name": "Cleartext Storage of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00076,
        "percentile": 0.00119
      },
      "nvd": {
        "published": "2026-07-24T15:17:13.180",
        "lastModified": "2026-07-29T20:34:27.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16802",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected feature stores a secret in cleartext on disk, so filesystem readers can recover the original value.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-312"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0025/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:51:37.018Z",
      "date_published": "2026-07-23T21:36:44.505Z",
      "date_updated": "2026-07-24T12:43:26.296Z",
      "publisher": "Chrome",
      "title": "Use after free in Input in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16382
      },
      "nvd": {
        "published": "2026-07-23T22:16:52.427",
        "lastModified": "2026-07-27T12:46:03.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16804",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome Input component can use an object after it has been freed in a renderer-compromise path.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/524721670",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 231,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16805",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:51:37.349Z",
      "date_published": "2026-07-23T21:36:44.042Z",
      "date_updated": "2026-07-25T03:55:20.198Z",
      "publisher": "Chrome",
      "title": "Use after free in Blink in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23833
      },
      "nvd": {
        "published": "2026-07-23T22:16:52.533",
        "lastModified": "2026-07-27T12:45:44.210",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16805",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path retains or dereferences an object after its storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523292588",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:51:37.592Z",
      "date_published": "2026-07-23T21:36:43.664Z",
      "date_updated": "2026-07-25T03:55:16.640Z",
      "publisher": "Chrome",
      "title": "Use after free in WebMCP in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00398,
        "percentile": 0.3255
      },
      "nvd": {
        "published": "2026-07-23T22:16:52.640",
        "lastModified": "2026-07-27T12:45:30.967",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16806",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A memory-safety error permits access outside the valid bounds or lifetime of an object.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522064153",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:51:37.861Z",
      "date_published": "2026-07-23T21:36:43.154Z",
      "date_updated": "2026-07-24T12:45:05.477Z",
      "publisher": "Chrome",
      "title": "Out of bounds write in Codecs in Google Chrome prior to 150.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17936
      },
      "nvd": {
        "published": "2026-07-23T22:16:52.750",
        "lastModified": "2026-07-27T12:45:14.207",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16807",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path computes or trusts a write extent that can exceed the destination object's bounds.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518237034",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16811",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T21:31:57.953Z",
      "date_published": "2026-07-28T05:39:44.419Z",
      "date_updated": "2026-07-28T13:30:49.041Z",
      "publisher": "Wordfence",
      "title": "ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "affected": {
        "vendors": [
          "devitemsllc"
        ],
        "products": [
          {
            "vendor": "devitemsllc",
            "product": "ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18627
      },
      "nvd": {
        "published": "2026-07-28T07:16:42.390",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16811",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query path incorporates attacker-controlled input into SQL without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bed2ada9-af3d-479e-8ae4-11eaad0b3842?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.4.5/includes/modules/abandoned-cart/includes/classes/Database/DB_Handler.php#L82",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.4.5/includes/modules/abandoned-cart/includes/classes/Api/Cart_Data.php#L248",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/3.4.5/includes/modules/abandoned-cart/includes/classes/Database/DB_Handler.php#L426",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3623166%40woolentor-addons&new=3623166%40woolentor-addons",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T21:46:32.558Z",
      "date_published": "2026-07-27T16:11:00.968Z",
      "date_updated": "2026-07-28T03:56:40.567Z",
      "publisher": "Arista",
      "title": "VeloCloud Orchestrator OS Command Injection",
      "affected": {
        "vendors": [
          "Arista Networks"
        ],
        "products": [
          {
            "vendor": "Arista Networks",
            "product": "VeloCloud Orchestrator On-Prem"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P"
        },
        {
          "source": "NVD:psirt@arista.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:psirt@arista.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00884,
        "percentile": 0.55705
      },
      "official_kev": {
        "cveID": "CVE-2026-16812",
        "vendorProject": "Arista",
        "product": "VeloCloud Orchestrator",
        "vulnerabilityName": "Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability",
        "dateAdded": "2026-07-27",
        "shortDescription": "Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-07-30",
        "knownRansomwareCampaignUse": "Unknown",
        "notes": "https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-16812",
        "cwes": [
          "CWE-78"
        ]
      },
      "nvd": {
        "published": "2026-07-27T16:17:03.640",
        "lastModified": "2026-07-28T14:50:33.960",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-16812",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated request reaches VCO functionality intended only for internal use and crosses an undisclosed OS-command boundary on the orchestrator host.",
        "basis": [
          "CNA",
          "CWE-78",
          "Arista Security Advisory 0144",
          "CISA KEV"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144 and the linked CISA KEV status. Arista confirms CWE-78, unauthenticated web reachability, active exploitation, affected release floors, and fixed releases, but not the endpoint or command sink. Revision 1.1 dated 2026-08-03 adds VCO Hosted to affected platforms and says Hosted and Dedicated are being actively patched, which conflicts with the embedded record statement that both had already been patched in advance; treat the current Arista revision as the current deployment state."
      },
      "references": [
        {
          "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144",
          "host": "www.arista.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16812",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 612,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-16843",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T03:06:45.941Z",
      "date_published": "2026-07-31T09:31:30.862Z",
      "date_updated": "2026-08-03T05:56:30.541Z",
      "publisher": "hikvision",
      "title": "Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation.",
      "affected": {
        "vendors": [
          "Hikvision"
        ],
        "products": [
          {
            "vendor": "Hikvision",
            "product": "DS-3WAP521-SI"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-3WAP522-SI"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-3WAP621E-SI"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-3WAP622E-SI"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-3WAP623E-SI"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-3WAP622G-SI"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-3WG105G-SI"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-3WG105GP-SI"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-3WG210GP-SI"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-3WG507G-SI"
          }
        ],
        "affectedBlockCount": 10,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:hsrc@hikvision.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00891,
        "percentile": 0.55921
      },
      "nvd": {
        "published": "2026-07-31T11:17:05.567",
        "lastModified": "2026-08-03T07:16:42.357",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16843",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Hikvision packet fields reach an operating-system command boundary without sufficient command-context validation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.hikvision.com/en/support/cybersecurity/security-advisory/command-execution-vulnerability-in-some-wireless-ap-products/",
          "host": "www.hikvision.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 10,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-16870",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T04:22:39.270Z",
      "date_published": "2026-07-24T04:40:41.019Z",
      "date_updated": "2026-07-24T17:23:49.204Z",
      "publisher": "SNOWFLAKE",
      "title": "Multiple Security Vulnerabilities in Snowflake libsnowflakeclient",
      "affected": {
        "vendors": [
          "Snowflake"
        ],
        "products": [
          {
            "vendor": "Snowflake",
            "product": "Snowflake libsnowflakeclient"
          },
          {
            "vendor": "Snowflake",
            "product": "Snowflake PHP PDO Driver"
          },
          {
            "vendor": "Snowflake",
            "product": "Snowflake ODBC Driver"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:412d305a-227d-44f9-a262-a31ba44f2aea",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28938
      },
      "nvd": {
        "published": "2026-07-24T06:16:42.553",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16870",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted download metadata overflows two native buffers, while the same CVE separately permits attacker-influenced connection settings to redirect credential-bearing requests.",
        "basis": [
          "CNA",
          "CWE-121",
          "CWE-787",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": "The CNA record combines two memory-corruption paths and a separate connection-redirection path under one CVE; the selected family reflects the native-buffer failures that can lead to code execution."
      },
      "references": [
        {
          "url": "https://github.com/snowflakedb/libsnowflakeclient/releases/tag/v2.9.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1459,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-16910",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T06:26:22.299Z",
      "date_published": "2026-07-24T06:36:18.918Z",
      "date_updated": "2026-07-24T10:55:46.478Z",
      "publisher": "redhat",
      "title": "Quay: ssrf in red hat quay notification webhooks (slack/generic)",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Update Service"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Quay 3"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11746
      },
      "nvd": {
        "published": "2026-07-24T08:16:26.790",
        "lastModified": "2026-07-24T20:49:03.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16910",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A Quay webhook accepts an attacker-selected destination and performs the server-side request without constraining the resolved target.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-16910",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506685",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-16969",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T08:23:11.209Z",
      "date_published": "2026-07-30T09:40:14.024Z",
      "date_updated": "2026-07-30T13:03:36.904Z",
      "publisher": "sba-research",
      "title": "DFIR-IRIS Stored XSS in Assets",
      "affected": {
        "vendors": [
          "dfir-iris"
        ],
        "products": [
          {
            "vendor": "dfir-iris",
            "product": "iris-web"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08146
      },
      "nvd": {
        "published": "2026-07-30T10:16:35.860",
        "lastModified": "2026-07-30T16:45:56.833",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16969",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260126-01_DFIR-IRIS_Stored_XSS",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 137,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16970",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T08:24:41.455Z",
      "date_published": "2026-07-30T09:45:24.228Z",
      "date_updated": "2026-07-30T15:38:37.247Z",
      "publisher": "sba-research",
      "title": "DFIR-IRIS Insufficient Logout Implementation",
      "affected": {
        "vendors": [
          "dfir-iris"
        ],
        "products": [
          {
            "vendor": "dfir-iris",
            "product": "iris-web"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.08018
      },
      "nvd": {
        "published": "2026-07-30T10:16:36.100",
        "lastModified": "2026-07-30T16:45:56.833",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16970",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Logout leaves the existing IRIS session cookie valid, so a stolen session remains reusable until its separate expiration.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260128-04_DFIR-IRIS_Insufficient_Logout",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/12",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-16971",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T08:24:42.942Z",
      "date_published": "2026-07-30T09:43:51.944Z",
      "date_updated": "2026-07-30T12:51:36.381Z",
      "publisher": "sba-research",
      "title": "DFIR-IRIS Missing Brute Force Protection in OTP Validation",
      "affected": {
        "vendors": [
          "dfir-iris"
        ],
        "products": [
          {
            "vendor": "dfir-iris",
            "product": "iris-web"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00318,
        "percentile": 0.24209
      },
      "nvd": {
        "published": "2026-07-30T10:16:36.220",
        "lastModified": "2026-07-30T16:45:56.833",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-16971",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OTP validation path has no effective bound on repeated MFA guesses.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260128-02_DFIR-IRIS_Missing_Brute_Force_Protection",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 127,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17039",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T12:43:53.156Z",
      "date_published": "2026-07-24T15:12:57.863Z",
      "date_updated": "2026-07-25T00:53:43.085Z",
      "publisher": "redhat",
      "title": "Pki-core: dogtag-pki: redhat-pki: pki-core: ca renewal request processing omits realm authorization check performed by enrollment path",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Certificate System 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Certificate System 11"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Certificate System 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11411
      },
      "nvd": {
        "published": "2026-07-24T16:16:34.367",
        "lastModified": "2026-07-25T02:16:39.073",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17039",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The certificate renewal path omits the realm authorization check used by enrollment, so a user in one realm can renew another realm's certificate.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2021-20179",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-17039",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506720",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/dogtagpki/pki/blob/master/base/ca/database/ds/acl.ldif",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/dogtagpki/pki/blob/master/base/ca/src/main/java/com/netscape/cms/servlet/cert/EnrollmentProcessor.java",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/dogtagpki/pki/blob/master/base/ca/src/main/java/com/netscape/cms/servlet/cert/RenewalProcessor.java",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/dogtagpki/pki/blob/master/base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CertServlet.java",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/dogtagpki/pki/commit/e2de26769761af04b9c56071bd1a1926903c49b6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-17048",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T13:25:29.276Z",
      "date_published": "2026-07-24T13:41:09.091Z",
      "date_updated": "2026-07-24T19:54:56.056Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10982
      },
      "nvd": {
        "published": "2026-07-24T14:16:26.493",
        "lastModified": "2026-07-24T20:49:03.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17048",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Admin REST API resolves a vaulted client-secret placeholder and returns the real secret to a delegated administrator whose role is view-only.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-17048",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506743",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-17059",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T13:37:57.969Z",
      "date_published": "2026-07-24T14:06:21.223Z",
      "date_updated": "2026-07-24T14:52:40.876Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11131
      },
      "nvd": {
        "published": "2026-07-24T15:17:13.300",
        "lastModified": "2026-07-24T20:49:03.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17059",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation trusts a caller-supplied object identifier without binding the selected object to the caller-authorized scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-17059",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506746",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-17072",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T14:10:44.899Z",
      "date_published": "2026-07-28T10:25:34.204Z",
      "date_updated": "2026-07-28T14:01:40.558Z",
      "publisher": "redhat",
      "title": "Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_flac_stream_headers when parsing flac codec data in matroska containers",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01898
      },
      "nvd": {
        "published": "2026-07-28T11:17:02.433",
        "lastModified": "2026-07-28T16:22:01.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17072",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A FLAC header length check omits the full copy size and permits a four-byte read beyond the heap buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-17072",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506750",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/111",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-17107",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T15:28:38.469Z",
      "date_published": "2026-07-24T18:56:05.194Z",
      "date_updated": "2026-08-04T01:47:58.548Z",
      "publisher": "redhat",
      "title": "Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cluster-admin on every managed cluster",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1"
          },
          {
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.11.0"
          },
          {
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.17"
          },
          {
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.6"
          },
          {
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.8"
          },
          {
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.9"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27273
      },
      "nvd": {
        "published": "2026-07-24T19:16:55.907",
        "lastModified": "2026-08-04T03:16:25.380",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17107",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The proxy appends privileged impersonation headers without removing caller-supplied values, so a hub user can inject a cluster-admin group.",
        "basis": [
          "CNA",
          "CWE-441"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:46885",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47388",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47735",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47949",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47953",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47974",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:48284",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-17107",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506771",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 480,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-17161",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T17:54:46.665Z",
      "date_published": "2026-07-29T01:29:42.670Z",
      "date_updated": "2026-07-29T13:03:31.467Z",
      "publisher": "Wordfence",
      "title": "WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'filterMobileText' Block Attribute",
      "affected": {
        "vendors": [
          "wpxpo"
        ],
        "products": [
          {
            "vendor": "wpxpo",
            "product": "WowStore – Store Builder & Product Blocks for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09238
      },
      "nvd": {
        "published": "2026-07-29T02:16:43.337",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17161",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WowStore – Store Builder & Product Blocks for WooCommerce places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fae39bf9-8ceb-4cb1-afd1-522c885e6ef5?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/product-blocks/trunk/classes/Functions.php#L1632",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/product-blocks/trunk/blocks/template/filter.php#L10",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/product-blocks/trunk/blocks/Product_Grid_1.php#L107",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3625492%40product-blocks&new=3625492%40product-blocks",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 718,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17162",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T17:55:44.362Z",
      "date_published": "2026-07-29T01:29:42.312Z",
      "date_updated": "2026-07-29T15:23:46.659Z",
      "publisher": "Wordfence",
      "title": "WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'currentPostId' Block Attribute",
      "affected": {
        "vendors": [
          "wpxpo"
        ],
        "products": [
          {
            "vendor": "wpxpo",
            "product": "WowStore – Store Builder & Product Blocks for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09238
      },
      "nvd": {
        "published": "2026-07-29T02:16:43.480",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17162",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WowStore stores a crafted currentPostId block attribute and renders it without sufficient sanitization and output escaping.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c5c82d8d-88eb-4159-af94-3f8e257dded6?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/product-blocks/tags/4.4.24/blocks/Filter.php#L136",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/product-blocks/tags/4.4.24/blocks/Filter.php#L116",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/product-blocks/tags/4.4.24/blocks/Filter.php#L97",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3625492%40product-blocks&new=3625492%40product-blocks",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 463,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17166",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T18:02:01.608Z",
      "date_published": "2026-07-29T01:29:41.941Z",
      "date_updated": "2026-07-29T12:56:46.107Z",
      "publisher": "Wordfence",
      "title": "Event Booking Manager for WooCommerce <= 5.3.7 - Missing Authorization to Authenticated (Contributor+) Site-Wide Payment Settings Modification via mep_save_payment_settings_modal AJAX Action",
      "affected": {
        "vendors": [
          "magepeopleteam"
        ],
        "products": [
          {
            "vendor": "magepeopleteam",
            "product": "Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14173
      },
      "nvd": {
        "published": "2026-07-29T02:16:43.613",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17166",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The plugin lets a Contributor change site-wide booking and payment settings without verifying authorization for that administrative action.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5f43e35e-55cd-45f1-b8a5-e47398d97cc2?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mage-eventpress/tags/5.3.7/admin/settings/global/admin_setting_panel.php#L1120",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mage-eventpress/tags/5.3.7/admin/settings/global/admin_setting_panel.php#L1080",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mage-eventpress/tags/5.3.7/admin/settings/global/admin_setting_panel.php#L25",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mage-eventpress/trunk/admin/settings/global/admin_setting_panel.php#L1120",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mage-eventpress/trunk/admin/settings/global/admin_setting_panel.php#L1080",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mage-eventpress/trunk/admin/settings/global/admin_setting_panel.php#L25",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3625494%40mage-eventpress&new=3625494%40mage-eventpress",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 635,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T19:03:13.728Z",
      "date_published": "2026-07-27T16:41:17.436Z",
      "date_updated": "2026-07-27T17:29:45.538Z",
      "publisher": "Arista",
      "title": "VeloCloud Orchestrator Flow Metrics API SQL Injection",
      "affected": {
        "vendors": [
          "Arista Networks"
        ],
        "products": [
          {
            "vendor": "Arista Networks",
            "product": "VeloCloud Orchestrator On-Prem"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/S:P"
        },
        {
          "source": "NVD:psirt@arista.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:psirt@arista.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.02826,
        "percentile": 0.85203
      },
      "nvd": {
        "published": "2026-07-27T17:16:35.407",
        "lastModified": "2026-07-30T19:10:52.250",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17191",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Flow Metrics API lets an authenticated user alter backend SQL queries with crafted input.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24365-security-advisory-0145",
          "host": "www.arista.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 460,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-17192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T19:03:16.141Z",
      "date_published": "2026-07-27T16:36:32.879Z",
      "date_updated": "2026-07-27T17:28:36.203Z",
      "publisher": "Arista",
      "title": "VeloCloud Orchestrator Missing Input Validation SSRF",
      "affected": {
        "vendors": [
          "Arista Networks"
        ],
        "products": [
          {
            "vendor": "Arista Networks",
            "product": "VeloCloud Orchestrator On-Prem"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/S:P"
        },
        {
          "source": "NVD:psirt@arista.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:psirt@arista.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.02338,
        "percentile": 0.81924
      },
      "nvd": {
        "published": "2026-07-27T17:16:35.573",
        "lastModified": "2026-07-30T19:10:52.250",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17192",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "VeloCloud Orchestrator lets an authenticated tenant administrator choose server-side request destinations that include otherwise inaccessible internal services.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24365-security-advisory-0145",
          "host": "www.arista.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-17346",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T02:52:54.197Z",
      "date_published": "2026-07-31T15:59:13.136Z",
      "date_updated": "2026-08-01T03:56:11.625Z",
      "publisher": "PostgreSQL",
      "title": "pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)",
      "affected": {
        "vendors": [
          "pgadmin.org"
        ],
        "products": [
          {
            "vendor": "pgadmin.org",
            "product": "pgAdmin 4"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00433,
        "percentile": 0.3566
      },
      "nvd": {
        "published": "2026-07-31T16:16:58.970",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17346",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Several pgAdmin templates missed the qtLiteral hardening and interpolate attacker-influenced identifiers or comments into executable SQL.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/issues/10193",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/73b3218992cc37af6e10b7e54eaeed6ec293c6b2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/f75452bfd0f786d0c071638919d48fc1d76f987d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2119,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-17347",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T02:52:54.844Z",
      "date_published": "2026-07-31T15:59:16.588Z",
      "date_updated": "2026-08-01T03:56:12.755Z",
      "publisher": "PostgreSQL",
      "title": "pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution",
      "affected": {
        "vendors": [
          "pgadmin.org"
        ],
        "products": [
          {
            "vendor": "pgadmin.org",
            "product": "pgAdmin 4"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18708
      },
      "nvd": {
        "published": "2026-07-31T16:16:59.140",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17347",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "pgAdmin substitutes an externally sourced username into an administrator-configured shell command before execution with shell=True, allowing metacharacters in %u to inject commands.",
        "basis": [
          "CNA",
          "CWE-78",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/issues/10191",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/ea7e798aac27174d2bacee1d6e136bed76a95e23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/e7a85767314e7b0fe0b35fe80b9c1af38f48dff6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1520,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T02:52:55.455Z",
      "date_published": "2026-07-31T15:59:18.714Z",
      "date_updated": "2026-07-31T17:23:08.497Z",
      "publisher": "PostgreSQL",
      "title": "pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)",
      "affected": {
        "vendors": [
          "pgadmin.org"
        ],
        "products": [
          {
            "vendor": "pgadmin.org",
            "product": "pgAdmin 4"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16307
      },
      "nvd": {
        "published": "2026-07-31T16:16:59.287",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17348",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306).",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/issues/10194",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/24fdcf0f58591c87ada31366c01e1af180eceb05",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1477,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-17349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T02:52:56.082Z",
      "date_published": "2026-07-31T15:59:47.841Z",
      "date_updated": "2026-08-01T03:56:26.176Z",
      "publisher": "PostgreSQL",
      "title": "pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner",
      "affected": {
        "vendors": [
          "pgadmin.org"
        ],
        "products": [
          {
            "vendor": "pgadmin.org",
            "product": "pgAdmin 4"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0.29999999999999893,
      "epss": {
        "score": 0.003,
        "percentile": 0.22332
      },
      "nvd": {
        "published": "2026-07-31T16:16:59.480",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17349",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Server.clone() copies another tenant's owner and credential columns into an ad-hoc server row before rebinding the clone to the caller.",
        "basis": [
          "CNA",
          "CWE-522",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/issues/10200",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/a7e74a6ed685bc34e1f77a8b6a94d00fa3dff815",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/64a9cdbd6a240a962144f84418beaf9e66419779",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1598,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17350",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T02:52:56.800Z",
      "date_published": "2026-07-31T16:00:03.744Z",
      "date_updated": "2026-07-31T17:05:44.535Z",
      "publisher": "PostgreSQL",
      "title": "pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers",
      "affected": {
        "vendors": [
          "pgadmin.org"
        ],
        "products": [
          {
            "vendor": "pgadmin.org",
            "product": "pgAdmin 4"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14053
      },
      "nvd": {
        "published": "2026-07-31T16:16:59.617",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17350",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Per-tool permission checks guard only one front-door route, leaving the other HTTP and Socket.IO handlers available to any authenticated user.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/issues/10190",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/461c3afba92baad37c70a6fbd52d205d13a9de53",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/d36bd8dc96812c716664feac533d240544e70adc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/ba1984718ad703011740ad48cb9b82402b89cc2c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/64a9cdbd6a240a962144f84418beaf9e66419779",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 3556,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T02:52:57.350Z",
      "date_published": "2026-07-31T16:00:19.103Z",
      "date_updated": "2026-08-01T03:56:14.973Z",
      "publisher": "PostgreSQL",
      "title": "pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)",
      "affected": {
        "vendors": [
          "pgadmin.org"
        ],
        "products": [
          {
            "vendor": "pgadmin.org",
            "product": "pgAdmin 4"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-115",
          "name": "Misinterpretation of Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00447,
        "percentile": 0.36748
      },
      "nvd": {
        "published": "2026-07-31T16:16:59.807",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17351",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The read-only gate trusts sqlparse's string grammar even when PostgreSQL parses the same bytes as multiple statements, allowing a smuggled COMMIT to end the wrapper transaction.",
        "basis": [
          "CNA",
          "CWE-115",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/issues/10192",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/ef76102bcd1cdb544eb9b4ef18d3382f22b76752",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/bf4792444446f0e7ab721d23cbd6bfe6afaa7a8b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2358,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17432",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T10:42:39.965Z",
      "date_published": "2026-07-26T00:15:11.157Z",
      "date_updated": "2026-07-27T18:01:13.928Z",
      "publisher": "VulDB",
      "title": "NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control",
      "affected": {
        "vendors": [
          "NousResearch"
        ],
        "products": [
          {
            "vendor": "NousResearch",
            "product": "hermes-agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 3.7,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13946
      },
      "nvd": {
        "published": "2026-07-26T01:16:25.783",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17432",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The SimpleX gateway makes an access-control decision from contactId, but the record does not disclose the subject-object binding that fails.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383065",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383065/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17432",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862424",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/issues/44730",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/pull/41246",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/issues/44729",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/commit/490c486ff65b766d9de0fe0e6f26e1778aaa8fb3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/NousResearch/hermes-agent/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 614,
        "referenceCount": 9,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T11:08:20.291Z",
      "date_published": "2026-07-26T02:30:09.678Z",
      "date_updated": "2026-07-27T20:23:47.697Z",
      "publisher": "VulDB",
      "title": "nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization",
      "affected": {
        "vendors": [
          "nanocoai"
        ],
        "products": [
          {
            "vendor": "nanocoai",
            "product": "NanoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 65,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00103,
        "percentile": 0.01164
      },
      "nvd": {
        "published": "2026-07-26T03:16:32.490",
        "lastModified": "2026-07-27T21:16:48.453",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17433",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The MCP server approval setup permits an unauthorized local action, but the missing subject, object, or approval comparison is not public.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383074",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383074/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17433",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862450",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nanocoai/nanoclaw/issues/2761",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nanocoai/nanoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 65
      }
    },
    {
      "cve_id": "CVE-2026-17434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T11:08:25.395Z",
      "date_published": "2026-07-26T03:00:16.981Z",
      "date_updated": "2026-07-27T14:37:23.201Z",
      "publisher": "VulDB",
      "title": "nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization",
      "affected": {
        "vendors": [
          "nanocoai"
        ],
        "products": [
          {
            "vendor": "nanocoai",
            "product": "NanoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 65,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11909
      },
      "nvd": {
        "published": "2026-07-26T04:16:46.573",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17434",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The add_mcp_server operation can assign or activate server authority improperly, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383075",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383075/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17434",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862451",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nanocoai/nanoclaw/issues/2762",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nanocoai/nanoclaw/pull/2998",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/nanocoai/nanoclaw/commit/e5b928783d5c485637565eb07d2967922dfbf8d8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/nanocoai/nanoclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 65
      }
    },
    {
      "cve_id": "CVE-2026-17457",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T18:54:27.603Z",
      "date_published": "2026-07-26T09:30:11.264Z",
      "date_updated": "2026-07-27T13:18:59.011Z",
      "publisher": "VulDB",
      "title": "mf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosure",
      "affected": {
        "vendors": [
          "mf-yang"
        ],
        "products": [
          {
            "vendor": "mf-yang",
            "product": "openclaw-cn"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00315,
        "percentile": 0.2392
      },
      "nvd": {
        "published": "2026-07-26T10:16:25.163",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17457",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "The browser navigation guard permits a URL outside its intended scheme boundary, but the public record does not disclose the accepted scheme or resulting data path.",
        "basis": [
          "CNA record",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383319",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383319/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17457",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862452",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mf-yang/openclaw-cn/issues/561",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mf-yang/openclaw-cn/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 484,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-17458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T18:54:32.998Z",
      "date_published": "2026-07-26T09:45:09.775Z",
      "date_updated": "2026-07-27T13:49:45.592Z",
      "publisher": "VulDB",
      "title": "mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery",
      "affected": {
        "vendors": [
          "mf-yang"
        ],
        "products": [
          {
            "vendor": "mf-yang",
            "product": "openclaw-cn"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13639
      },
      "nvd": {
        "published": "2026-07-26T11:16:58.470",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17458",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "openclaw-cn accepts an attacker-controlled server request target without constraining it to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383320",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383320/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17458",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862453",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/mf-yang/openclaw-cn/issues/562",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mf-yang/openclaw-cn/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 456,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-17459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T19:07:45.086Z",
      "date_published": "2026-07-26T10:15:09.381Z",
      "date_updated": "2026-07-27T17:23:26.106Z",
      "publisher": "VulDB",
      "title": "perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink",
      "affected": {
        "vendors": [
          "perwendel"
        ],
        "products": [
          {
            "vendor": "perwendel",
            "product": "spark"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-61",
          "name": "UNIX Symbolic Link (Symlink) Following",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24301
      },
      "nvd": {
        "published": "2026-07-26T11:16:58.643",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17459",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Spark's externalLocation handler follows a symlink supplied within the selected static-file tree into another filesystem location.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-61"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383321",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383321/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17459",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862468",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/perwendel/spark/issues/1296",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/perwendel/spark/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-17496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-26T14:28:45.607Z",
      "date_published": "2026-07-26T14:33:02.602Z",
      "date_updated": "2026-07-27T14:44:46.464Z",
      "publisher": "JFROG",
      "title": "NoteGen chat preview XSS via unsanitized AI/skill HTML rendering",
      "affected": {
        "vendors": [
          "codexu"
        ],
        "products": [
          {
            "vendor": "codexu",
            "product": "NoteGen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22368
      },
      "nvd": {
        "published": "2026-07-26T15:16:27.710",
        "lastModified": "2026-07-27T20:37:16.927",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17496",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NoteGen renders model-produced HTML through dangerouslySetInnerHTML with html enabled and no sanitizer, allowing prompt-influenced markup to execute in the Tauri webview.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/codexu/note-gen/commit/ae3ba948c41d8a74b4a20f4c6f26fcdda2002298",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/codexu/note-gen/releases/tag/note-gen-v0.32.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/codexu/note-gen",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 644,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17497",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-26T14:37:51.448Z",
      "date_published": "2026-07-26T14:38:08.960Z",
      "date_updated": "2026-07-27T14:49:03.628Z",
      "publisher": "JFROG",
      "title": "NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python",
      "affected": {
        "vendors": [
          "codexu"
        ],
        "products": [
          {
            "vendor": "codexu",
            "product": "NoteGen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1249",
          "name": "Application-Level Admin Tool with Inconsistent View of Underlying Operating System",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00455,
        "percentile": 0.37257
      },
      "nvd": {
        "published": "2026-07-26T15:16:27.873",
        "lastModified": "2026-07-27T20:37:16.927",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17497",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NoteGen grants its webview default permission to execute bash and Python with arbitrary arguments, exposing host command execution to webview script.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/codexu/note-gen/commit/00064a4a8ec4177d51094ffb3e15bf0758009c1f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/codexu/note-gen/releases/tag/note-gen-v0.32.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/codexu/note-gen",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 502,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17500",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-26T17:33:41.700Z",
      "date_published": "2026-07-27T00:15:12.222Z",
      "date_updated": "2026-07-27T18:03:26.332Z",
      "publisher": "VulDB",
      "title": "ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereference",
      "affected": {
        "vendors": [
          "ggml-org"
        ],
        "products": [
          {
            "vendor": "ggml-org",
            "product": "llama.cpp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34465
      },
      "nvd": {
        "published": "2026-07-27T01:16:26.380",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17500",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "_visit_pattern dereferences a null pointer while processing attacker-influenced JSON-schema input.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-404",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383353",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383353/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17500",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/798503",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ggml-org/llama.cpp/issues/25284",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/ggml-org/llama.cpp/pull/25308",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/ggml-org/llama.cpp/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 300,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-17501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-26T17:33:47.225Z",
      "date_published": "2026-07-27T00:30:11.082Z",
      "date_updated": "2026-07-29T04:43:05.523Z",
      "publisher": "VulDB",
      "title": "ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform recursion",
      "affected": {
        "vendors": [
          "ggml-org"
        ],
        "products": [
          {
            "vendor": "ggml-org",
            "product": "llama.cpp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P/E:ND/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34466
      },
      "nvd": {
        "published": "2026-07-27T01:16:26.570",
        "lastModified": "2026-07-29T06:16:56.907",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17501",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The llama.cpp JSON-Schema-to-GBNF transform recursively expands attacker-controlled schema structure without a terminating depth bound.",
        "basis": [
          "CNA",
          "CWE-404",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383354",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383354/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17501",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/798504",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ggml-org/llama.cpp/issues/25283",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/ggml-org/llama.cpp/pull/25308",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/ggml-org/llama.cpp/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17512",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T07:09:40.586Z",
      "date_published": "2026-07-27T12:30:10.137Z",
      "date_updated": "2026-07-27T13:01:00.517Z",
      "publisher": "VulDB",
      "title": "ggml-org whisper.cpp log_mel_spectrogram out-of-bounds",
      "affected": {
        "vendors": [
          "ggml-org"
        ],
        "products": [
          {
            "vendor": "ggml-org",
            "product": "whisper.cpp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01649
      },
      "nvd": {
        "published": "2026-07-27T13:16:52.950",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17512",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An object is accessed outside its valid allocation bounds or lifetime.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383382",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383382/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17512",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/798905",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ggml-org/whisper.cpp/issues/3923",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/ggml-org/whisper.cpp/pull/3925",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/ggml-org/whisper.cpp/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 281,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17513",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T07:09:45.327Z",
      "date_published": "2026-07-27T12:45:10.017Z",
      "date_updated": "2026-07-27T16:20:39.097Z",
      "publisher": "VulDB",
      "title": "ggml-org whisper.cpp ggml.c ggml_ftype_to_ggml_type assertion",
      "affected": {
        "vendors": [
          "ggml-org"
        ],
        "products": [
          {
            "vendor": "ggml-org",
            "product": "whisper.cpp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 1.7,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:N/I:N/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01604
      },
      "nvd": {
        "published": "2026-07-27T14:16:52.073",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17513",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled model file can select an unsupported ftype value that reaches an assertion in ggml_ftype_to_ggml_type and aborts the process.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383383",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383383/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17513",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/799055",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ggml-org/whisper.cpp/issues/3924",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/ggml-org/whisper.cpp/",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 343,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17514",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T07:18:11.588Z",
      "date_published": "2026-07-27T13:15:09.434Z",
      "date_updated": "2026-07-27T13:48:24.935Z",
      "publisher": "VulDB",
      "title": "ZJONSSON node-unzipper extract.js Extract path traversal",
      "affected": {
        "vendors": [
          "ZJONSSON"
        ],
        "products": [
          {
            "vendor": "ZJONSSON",
            "product": "node-unzipper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.3,
          "severity": "",
          "vector": "AV:L/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03559
      },
      "nvd": {
        "published": "2026-07-27T14:16:52.277",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17514",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The archive extractor accepts member paths that escape the intended extraction directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383384",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383384/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17514",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862473",
          "host": "vuldb.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/ZJONSSON/node-unzipper/issues/357",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/ZJONSSON/node-unzipper/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 386,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-17523",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T08:19:11.242Z",
      "date_published": "2026-07-27T08:58:58.143Z",
      "date_updated": "2026-07-29T10:12:39.744Z",
      "publisher": "redhat",
      "title": "Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-825",
          "name": "Expired Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02079
      },
      "nvd": {
        "published": "2026-07-27T10:16:36.270",
        "lastModified": "2026-07-29T11:16:48.620",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17523",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The CWE record attributes the Linux kernel privilege path to an expired pointer dereference in net/can/bcm.c, while the public narrative publishes only the resulting kernel code execution.",
        "basis": [
          "CNA",
          "CWE-825"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-17523",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507407",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/torvalds/linux/commit/bf74aa86e111aa3b2fbb25db37e3a3fab71b5b68",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-17524",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T08:21:00.930Z",
      "date_published": "2026-07-28T05:00:00.713Z",
      "date_updated": "2026-07-28T16:06:25.209Z",
      "publisher": "snyk",
      "title": "Versions of the package zip-lib before 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "zip-lib"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:report@snyk.io",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:report@snyk.io",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00785,
        "percentile": 0.52542
      },
      "nvd": {
        "published": "2026-07-28T06:16:41.380",
        "lastModified": "2026-07-30T20:11:09.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17524",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "zip-lib caches a directory as safe before extraction creates a symlink, then reuses that stale path decision for later entries.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.snyk.io/vuln/SNYK-JS-ZIPLIB-13834403",
          "host": "security.snyk.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/fpsqdb/zip-lib/commit/0c29b1e17050f2611f4f37e6aaa92a60b3cb89d5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/fpsqdb/zip-lib/issues/14",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 408,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T08:42:15.783Z",
      "date_published": "2026-07-27T09:31:40.761Z",
      "date_updated": "2026-07-27T18:09:27.103Z",
      "publisher": "redhat",
      "title": "Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrole grants create on datavolumes/source, allowing unauthorized pvc clone",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Virtualization 4"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.3029
      },
      "nvd": {
        "published": "2026-07-27T10:16:37.617",
        "lastModified": "2026-07-27T20:37:16.927",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17527",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The read-only CDI view role grants create on datavolumes/source, which clone authorization accepts as authority to copy any named PVC across namespaces.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-17527",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507413",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 759,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-17528",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T08:44:16.847Z",
      "date_published": "2026-07-28T05:00:01.620Z",
      "date_updated": "2026-07-28T16:05:45.252Z",
      "publisher": "snyk",
      "title": "Versions of the package nice-select2 before 2.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "nice-select2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:report@snyk.io",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:report@snyk.io",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12287
      },
      "nvd": {
        "published": "2026-07-28T06:16:41.730",
        "lastModified": "2026-07-30T20:11:09.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17528",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.snyk.io/vuln/SNYK-JS-NICESELECT2-13638683",
          "host": "security.snyk.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/bluzky/nice-select2/commit/ea23ff404e186f6e2a64a25c530f93165fd2ad26",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/bluzky/nice-select2/issues/97",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 339,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17529",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T08:45:45.115Z",
      "date_published": "2026-07-27T15:15:11.108Z",
      "date_updated": "2026-07-27T16:21:50.548Z",
      "publisher": "VulDB",
      "title": "AstrBotDevs AstrBot astr_main_agent.py authorization",
      "affected": {
        "vendors": [
          "AstrBotDevs"
        ],
        "products": [
          {
            "vendor": "AstrBotDevs",
            "product": "AstrBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00358,
        "percentile": 0.28541
      },
      "nvd": {
        "published": "2026-07-27T16:17:04.310",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17529",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The agent dispatch path accepts a caller-controlled req.func_tool value without proving that the caller is authorized to invoke the selected tool.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383394",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383394/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17529",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862512",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/AstrBotDevs/AstrBot/issues/8780",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/AstrBotDevs/AstrBot/pull/8786",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/AstrBotDevs/AstrBot/commit/d23011262e8e75e1ec41b0f1f0091493a022327e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/AstrBotDevs/AstrBot/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-17530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T08:45:52.537Z",
      "date_published": "2026-07-27T15:45:10.355Z",
      "date_updated": "2026-07-27T18:19:50.134Z",
      "publisher": "VulDB",
      "title": "AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization",
      "affected": {
        "vendors": [
          "AstrBotDevs"
        ],
        "products": [
          {
            "vendor": "AstrBotDevs",
            "product": "AstrBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 6.5,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00358,
        "percentile": 0.28541
      },
      "nvd": {
        "published": "2026-07-27T16:17:04.490",
        "lastModified": "2026-07-27T20:25:13.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17530",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "AstrBot permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383395",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383395/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17530",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862536",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/AstrBotDevs/AstrBot/issues/8781",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/AstrBotDevs/AstrBot/pull/8786",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/AstrBotDevs/AstrBot/commit/d23011262e8e75e1ec41b0f1f0091493a022327e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/AstrBotDevs/AstrBot/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 509,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-17531",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T08:49:58.088Z",
      "date_published": "2026-07-27T16:15:09.448Z",
      "date_updated": "2026-07-28T14:54:30.069Z",
      "publisher": "VulDB",
      "title": "unitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization",
      "affected": {
        "vendors": [
          "unitedbyai"
        ],
        "products": [
          {
            "vendor": "unitedbyai",
            "product": "droidclaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4.6,
          "severity": "",
          "vector": "AV:N/AC:H/Au:S/C:P/I:P/A:P"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 3.7,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09971
      },
      "nvd": {
        "published": "2026-07-27T17:16:35.997",
        "lastModified": "2026-07-28T16:17:36.480",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17531",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The scheduled callback route accepts an unsigned callback without binding it to an authorized caller or goal.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383396",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383396/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-17531",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862537",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/unitedbyai/droidclaw/issues/18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/unitedbyai/droidclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-17534",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:17:58.055Z",
      "date_published": "2026-07-27T09:19:23.982Z",
      "date_updated": "2026-07-27T10:24:05.709Z",
      "publisher": "JFROG",
      "title": "Kimi Code FetchURL SSRF protection bypass via DNS-resolving hostnames and redirects",
      "affected": {
        "vendors": [
          "MoonshotAI"
        ],
        "products": [
          {
            "vendor": "MoonshotAI",
            "product": "Kimi Code"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02282
      },
      "nvd": {
        "published": "2026-07-27T10:16:37.747",
        "lastModified": "2026-07-27T20:37:16.927",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17534",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FetchURL blocks only literal hostnames and IPs and neither resolves DNS nor revalidates redirects before connecting to an internal destination.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MoonshotAI/kimi-code/commit/31449728b72df94e22bcb2de350a1e7624895e30",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/MoonshotAI/kimi-code/pull/1791",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/MoonshotAI/kimi-code/releases/tag/%40moonshot-ai%2Fkimi-code%400.27.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/MoonshotAI/kimi-code",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 662,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17543",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T10:12:16.392Z",
      "date_published": "2026-07-30T11:22:04.549Z",
      "date_updated": "2026-07-31T03:55:46.475Z",
      "publisher": "php",
      "title": "SQL injection in ext-pgsql via E'...' backslash breakout",
      "affected": {
        "vendors": [
          "PHP Group"
        ],
        "products": [
          {
            "vendor": "PHP Group",
            "product": "PHP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:Y/R:U"
        },
        {
          "source": "NVD:security@php.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31327
      },
      "nvd": {
        "published": "2026-07-30T12:17:27.120",
        "lastModified": "2026-07-31T04:16:48.350",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17543",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PostgreSQL extension escapes attacker-provided backslashes incorrectly, allowing an E-string value to break out of its quoted SQL data context.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-17544",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T10:14:42.318Z",
      "date_published": "2026-07-30T11:22:24.023Z",
      "date_updated": "2026-07-31T03:55:47.261Z",
      "publisher": "php",
      "title": "Out-of-bounds write in bccomp() via crafted operand and scale",
      "affected": {
        "vendors": [
          "PHP Group"
        ],
        "products": [
          {
            "vendor": "PHP Group",
            "product": "PHP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N"
        },
        {
          "source": "NVD:security@php.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00428,
        "percentile": 0.3522
      },
      "nvd": {
        "published": "2026-07-30T12:17:27.347",
        "lastModified": "2026-07-31T04:16:48.513",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17544",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PHP path can write beyond the end of its allocated buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/php/php-src/security/advisories/GHSA-x692-q9x7-8c3f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 174,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-17550",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T12:14:33.962Z",
      "date_published": "2026-07-29T15:23:16.031Z",
      "date_updated": "2026-07-29T17:57:17.958Z",
      "publisher": "autodesk",
      "title": "DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD",
      "affected": {
        "vendors": [
          "Autodesk"
        ],
        "products": [
          {
            "vendor": "Autodesk",
            "product": "AutoCAD"
          },
          {
            "vendor": "Autodesk",
            "product": "AutoCAD LT"
          },
          {
            "vendor": "Autodesk",
            "product": "DWG TrueView"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@autodesk.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04273
      },
      "nvd": {
        "published": "2026-07-29T16:17:51.180",
        "lastModified": "2026-07-30T16:27:52.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17550",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AutoCAD reads past the available data while parsing a crafted DWG or DXF file.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0009",
          "host": "www.autodesk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.autodesk.com/products/autodesk-access/overview",
          "host": "www.autodesk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.autodesk.com/products/dwg-trueview/overview",
          "host": "www.autodesk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-17552",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T12:38:52.992Z",
      "date_published": "2026-07-27T18:04:47.993Z",
      "date_updated": "2026-07-28T13:47:10.576Z",
      "publisher": "CPANSec",
      "title": "Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call",
      "affected": {
        "vendors": [
          "RRWO"
        ],
        "products": [
          {
            "vendor": "RRWO",
            "product": "Plack::App::Prerender"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00349,
        "percentile": 0.27576
      },
      "nvd": {
        "published": "2026-07-27T18:16:54.150",
        "lastModified": "2026-07-28T16:19:30.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17552",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Appending a request target that begins with @ to a URL base turns the intended host into userinfo and makes the attacker-selected host authoritative.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/robrwo/perl-Plack-App-Prerender/security/advisories/GHSA-6x4w-x68j-ppqq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://metacpan.org/release/RRWO/Plack-App-Prerender-v0.3.0/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/robrwo/perl-Plack-App-Prerender/commit/2d793dd69e2b6f4e469618ee742bd8402677202d.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 842,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17561",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T14:24:08.230Z",
      "date_published": "2026-07-31T12:49:56.946Z",
      "date_updated": "2026-07-31T19:54:37.744Z",
      "publisher": "TR-CERT",
      "title": "Unauthenticated RCE in Innotim Software's Logsign SIEM",
      "affected": {
        "vendors": [
          "Innotim Software, Telecommunications and Consulting Trade Ltd. Co."
        ],
        "products": [
          {
            "vendor": "Innotim Software, Telecommunications and Consulting Trade Ltd. Co.",
            "product": "Logsign SIEM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:iletisim@usom.gov.tr",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23758
      },
      "nvd": {
        "published": "2026-07-31T13:17:19.730",
        "lastModified": "2026-07-31T20:16:49.313",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17561",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Logsign SIEM permits unauthenticated network input to enter a code-generation or code-execution path without the neutralization required to keep that input as data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94",
          "Turkish Cyber Security Presidency advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0717 and its official JSON endpoint https://siberguvenlik.gov.tr/api/incident/index?page=1&slug=tr-26-0717; the advisory confirms CVE-2026-17561 and the 6.4.108 upgrade floor but adds no vulnerable function, input field, source, or patch detail beyond the CNA code-injection record."
      },
      "references": [
        {
          "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0717",
          "host": "siberguvenlik.gov.tr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17566",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T14:43:12.802Z",
      "date_published": "2026-07-31T16:00:22.738Z",
      "date_updated": "2026-08-01T03:56:13.838Z",
      "publisher": "PostgreSQL",
      "title": "pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)",
      "affected": {
        "vendors": [
          "pgadmin.org"
        ],
        "products": [
          {
            "vendor": "pgadmin.org",
            "product": "pgAdmin 4"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-115",
          "name": "Misinterpretation of Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00427,
        "percentile": 0.3511
      },
      "nvd": {
        "published": "2026-07-31T16:17:00.037",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17566",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "pgAdmin's parenthesis checker interprets backslash-quote differently from psql, letting accepted query text terminate the copy wrapper and introduce a TO PROGRAM command.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-78",
          "CWE-115"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/issues/10213",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/pgadmin-org/pgadmin4/commit/1496fabe28c9f825f6bac0f0d000d9d3276322c3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2289,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17567",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T14:45:05.088Z",
      "date_published": "2026-07-31T09:32:01.350Z",
      "date_updated": "2026-07-31T23:25:22.575Z",
      "publisher": "Wordfence",
      "title": "Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter",
      "affected": {
        "vendors": [
          "wpmanageninja"
        ],
        "products": [
          {
            "vendor": "wpmanageninja",
            "product": "Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.3042
      },
      "nvd": {
        "published": "2026-07-31T11:17:05.697",
        "lastModified": "2026-08-01T00:17:16.220",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17567",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The receipt endpoint accepts a guessable transaction token without binding it to an authenticated owner, exposing another customer's payment record.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/565980d7-8dc9-42a4-90c5-2f75af52fb8e?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.4/app/Modules/Payments/PaymentMethods/BaseProcessor.php#L959",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.8/app/Modules/Payments/PaymentMethods/BaseProcessor.php#L959",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.8/app/Modules/Payments/TransactionShortcodes.php#L107",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.8/app/Modules/Payments/PaymentHandler.php#L218",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.4/app/Modules/Payments/TransactionShortcodes.php#L107",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.4/app/Modules/Payments/PaymentHandler.php#L218",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Ffluentform/tags/6.2.8&new_path=%2Ffluentform/tags/6.2.9",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3625751/fluentform/trunk/app/Modules/Payments/PaymentMethods/BaseProcessor.php",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 856,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17568",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T15:01:44.756Z",
      "date_published": "2026-07-27T17:36:57.462Z",
      "date_updated": "2026-07-28T13:43:18.213Z",
      "publisher": "DEVOLUTIONS",
      "title": "Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via ...",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14147
      },
      "nvd": {
        "published": "2026-07-27T18:16:54.273",
        "lastModified": "2026-08-03T12:32:36.887",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17568",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The role-membership endpoint lets a non-administrator with group-membership permission add or obtain administrator authority.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0026/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 385,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-17569",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T15:01:45.583Z",
      "date_published": "2026-07-27T17:37:19.772Z",
      "date_updated": "2026-07-28T13:45:03.527Z",
      "publisher": "DEVOLUTIONS",
      "title": "Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05824
      },
      "nvd": {
        "published": "2026-07-27T18:16:54.393",
        "lastModified": "2026-08-03T12:31:57.233",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17569",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The partial connection endpoint returns a NetBox API token to a user whose permission is limited to viewing the entry.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0026/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-17570",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T15:01:46.235Z",
      "date_published": "2026-07-27T17:38:05.237Z",
      "date_updated": "2026-07-27T18:33:13.569Z",
      "publisher": "DEVOLUTIONS",
      "title": "Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests.",
      "affected": {
        "vendors": [
          "Devolutions"
        ],
        "products": [
          {
            "vendor": "Devolutions",
            "product": "Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05728
      },
      "nvd": {
        "published": "2026-07-27T18:16:54.520",
        "lastModified": "2026-08-03T12:31:14.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17570",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Devolutions Server lets a low-privileged caller query another account's password-history object and returns plaintext credential secrets.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0026/",
          "host": "devolutions.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-17572",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T15:07:05.659Z",
      "date_published": "2026-07-27T15:11:36.949Z",
      "date_updated": "2026-07-27T18:37:34.393Z",
      "publisher": "HDFG",
      "title": "HDF5 SOHM List Index Heap Buffer Overflow",
      "affected": {
        "vendors": [
          "The HDF Group"
        ],
        "products": [
          {
            "vendor": "The HDF Group",
            "product": "HDF5"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:L/SA:H/E:U"
        },
        {
          "source": "NVD:0253b833-3e77-4dfe-9d57-17db1a2f0a74",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02082
      },
      "nvd": {
        "published": "2026-07-27T16:17:04.660",
        "lastModified": "2026-07-30T20:11:59.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17572",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An HDF5 SOHM list declares num_messages greater than list_max, driving heap reads and writes beyond the deserialization buffer.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/HDFGroup/hdf5/issues/6501",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17573",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T15:07:06.180Z",
      "date_published": "2026-07-27T15:11:54.655Z",
      "date_updated": "2026-07-27T17:27:00.732Z",
      "publisher": "HDFG",
      "title": "Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field",
      "affected": {
        "vendors": [
          "The HDF Group"
        ],
        "products": [
          {
            "vendor": "The HDF Group",
            "product": "HDF5"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:0253b833-3e77-4dfe-9d57-17db1a2f0a74",
          "type": "Secondary",
          "version": "4.0",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01955
      },
      "nvd": {
        "published": "2026-07-27T16:17:04.807",
        "lastModified": "2026-07-30T20:11:59.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17573",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.",
        "basis": [
          "CNA",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/HDFGroup/hdf5/issues/6124",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17574",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T15:07:06.932Z",
      "date_published": "2026-07-27T15:12:18.767Z",
      "date_updated": "2026-07-27T18:36:55.399Z",
      "publisher": "HDFG",
      "title": "NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag",
      "affected": {
        "vendors": [
          "The HDF Group"
        ],
        "products": [
          {
            "vendor": "The HDF Group",
            "product": "HDF5"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "NVD:0253b833-3e77-4dfe-9d57-17db1a2f0a74",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01955
      },
      "nvd": {
        "published": "2026-07-27T16:17:04.943",
        "lastModified": "2026-07-30T20:11:59.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17574",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path dereferences a NULL pointer because the required validity check is missing or applied to the wrong value.",
        "basis": [
          "CNA",
          "CWE-476",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/HDFGroup/hdf5/commit/3fa6ed6e9dfeebbc784e21d8c48e31e35a8042bc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17612",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T18:45:08.664Z",
      "date_published": "2026-07-27T18:45:35.455Z",
      "date_updated": "2026-07-27T19:37:40.824Z",
      "publisher": "Honeywell",
      "title": "Audit Log Exposure through Unauthorized Access",
      "affected": {
        "vendors": [
          "Honeywell"
        ],
        "products": [
          {
            "vendor": "Honeywell",
            "product": "S35 Series 3M/5M/8M/PinHole Cameras"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:psirt@honeywell.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00308,
        "percentile": 0.23075
      },
      "nvd": {
        "published": "2026-07-27T19:17:15.770",
        "lastModified": "2026-07-27T20:16:39.497",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17612",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The camera's audit-log interface returns sensitive log entries without authenticating the requesting caller.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://myhoneywellbuildingsuniversity.com/training/asp_support_download_center",
          "host": "myhoneywellbuildingsuniversity.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17650",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:13.891Z",
      "date_published": "2026-07-30T00:18:42.053Z",
      "date_updated": "2026-07-31T03:56:24.980Z",
      "publisher": "Chrome",
      "title": "Use after free in Compositing in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31371
      },
      "nvd": {
        "published": "2026-07-30T01:16:26.850",
        "lastModified": "2026-07-31T04:16:48.650",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17650",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A reachable path retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/514442821",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17651",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:14.211Z",
      "date_published": "2026-07-30T00:18:42.425Z",
      "date_updated": "2026-07-31T03:56:24.309Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00397,
        "percentile": 0.32454
      },
      "nvd": {
        "published": "2026-07-30T01:16:26.967",
        "lastModified": "2026-08-03T12:13:26.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17651",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Google identifies insufficient validation in Dawn and sandbox-escape impact but does not disclose the input, parser, state, or failing check.",
        "basis": [
          "CNA",
          "CWE-20",
          "Chromium issue page"
        ],
        "deepDive": true,
        "notes": "Inspected the linked primary issue https://issues.chromium.org/issues/517307966; the anonymous page exposes no issue description or patch details, so the Dawn input and failing validation remain non-public."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517307966",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 231,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17652",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:14.497Z",
      "date_published": "2026-07-30T00:18:42.874Z",
      "date_updated": "2026-07-31T15:59:29.929Z",
      "publisher": "Chrome",
      "title": "Use after free in Views in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00416,
        "percentile": 0.34258
      },
      "nvd": {
        "published": "2026-07-30T01:16:27.080",
        "lastModified": "2026-07-31T16:17:00.230",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17652",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Views can retain and dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/519262990",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17653",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:14.751Z",
      "date_published": "2026-07-30T00:18:43.352Z",
      "date_updated": "2026-07-31T03:56:23.610Z",
      "publisher": "Chrome",
      "title": "Use after free in Skia in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31371
      },
      "nvd": {
        "published": "2026-07-30T01:16:27.190",
        "lastModified": "2026-07-31T04:16:49.070",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17653",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/520514458",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17654",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:14.979Z",
      "date_published": "2026-07-30T00:18:43.696Z",
      "date_updated": "2026-07-31T03:55:39.190Z",
      "publisher": "Chrome",
      "title": "Race in Updater in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01763
      },
      "nvd": {
        "published": "2026-07-30T01:16:27.303",
        "lastModified": "2026-07-31T04:16:49.883",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17654",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A race in the macOS updater lets a local malicious file win a privileged update-state transition.",
        "basis": [
          "CNA record",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/522314940",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17655",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:15.240Z",
      "date_published": "2026-07-30T00:18:44.004Z",
      "date_updated": "2026-07-31T03:56:22.937Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00416,
        "percentile": 0.34222
      },
      "nvd": {
        "published": "2026-07-30T01:16:27.420",
        "lastModified": "2026-07-31T04:16:50.073",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17655",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Chrome ANGLE record reports generic input validation leading to sandbox escape but does not disclose the input, validation rule, or privileged transition.",
        "basis": [
          "CNA",
          "CWE-20",
          "https://chromereleases.googleblog.com/2026/07/"
        ],
        "deepDive": true,
        "notes": "Google's Chrome 151 release page identifies ANGLE and a generic input-validation failure at https://chromereleases.googleblog.com/2026/07/; the linked Chromium issue https://issues.chromium.org/issues/522556145 did not expose public issue content, so the input, validation rule, and sandbox transition remain unknown."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/522556145",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17656",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:15.589Z",
      "date_published": "2026-07-30T00:18:44.383Z",
      "date_updated": "2026-07-31T03:56:22.231Z",
      "publisher": "Chrome",
      "title": "Use after free in Ozone in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00416,
        "percentile": 0.34222
      },
      "nvd": {
        "published": "2026-07-30T01:16:27.530",
        "lastModified": "2026-07-31T04:16:50.240",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17656",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome's Ozone component uses an object after it has been freed while handling crafted page content.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/523725277",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17657",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:15.801Z",
      "date_published": "2026-07-30T00:18:44.690Z",
      "date_updated": "2026-07-31T03:56:21.542Z",
      "publisher": "Chrome",
      "title": "Use after free in Navigation in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00359,
        "percentile": 0.28635
      },
      "nvd": {
        "published": "2026-07-30T01:16:27.640",
        "lastModified": "2026-07-31T04:16:50.410",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17657",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Chrome, a path retains or reuses an object after the lifetime transition that frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/502293787",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17658",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:16.033Z",
      "date_published": "2026-07-30T00:18:45.036Z",
      "date_updated": "2026-07-31T03:56:00.548Z",
      "publisher": "Chrome",
      "title": "Use after free in V8 in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00464,
        "percentile": 0.37872
      },
      "nvd": {
        "published": "2026-07-30T01:16:27.763",
        "lastModified": "2026-07-31T04:16:50.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17658",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path can retain or dereference an object after its storage has been released, leaving a dangling reference.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/523030583",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17659",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:16.283Z",
      "date_published": "2026-07-30T00:18:45.332Z",
      "date_updated": "2026-07-30T20:22:14.007Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.1786
      },
      "nvd": {
        "published": "2026-07-30T01:16:27.870",
        "lastModified": "2026-07-30T21:16:54.383",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17659",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record states only that an inappropriate SiteIsolation implementation permits a bypass and does not reveal a causal check, state transition, parser, or memory error.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/495463654",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17660",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:16.527Z",
      "date_published": "2026-07-30T00:18:45.603Z",
      "date_updated": "2026-07-31T03:56:20.809Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Network in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31106
      },
      "nvd": {
        "published": "2026-07-30T01:16:27.980",
        "lastModified": "2026-07-31T04:16:50.747",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17660",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record says Network accepts untrusted renderer input before a sandbox escape but does not disclose the message, validation rule, or dangerous operation.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/497428001",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 260,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17661",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:16.774Z",
      "date_published": "2026-07-30T00:18:45.964Z",
      "date_updated": "2026-07-31T03:55:59.670Z",
      "publisher": "Chrome",
      "title": "Use after free in Loader in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00464,
        "percentile": 0.37872
      },
      "nvd": {
        "published": "2026-07-30T01:16:28.090",
        "lastModified": "2026-07-31T04:16:50.920",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17661",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A memory object remains reachable after its valid lifetime and can be accessed through a stale reference.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/497451790",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17662",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:17.019Z",
      "date_published": "2026-07-30T00:18:46.237Z",
      "date_updated": "2026-07-30T20:51:54.082Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10707
      },
      "nvd": {
        "published": "2026-07-30T01:16:28.203",
        "lastModified": "2026-07-30T21:16:54.853",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17662",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Chrome path applies an origin decision that permits data or authority to cross the intended origin boundary.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/497491557",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17663",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:17.243Z",
      "date_published": "2026-07-30T00:18:46.548Z",
      "date_updated": "2026-07-31T03:56:25.700Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27347
      },
      "nvd": {
        "published": "2026-07-30T01:16:28.303",
        "lastModified": "2026-08-03T12:13:08.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17663",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Chrome reports insufficient GPU input validation but does not identify the field, parser rule, or invalid state that causes the impact.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/500225310",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17664",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:17.506Z",
      "date_published": "2026-07-30T00:18:46.808Z",
      "date_updated": "2026-07-31T15:59:26.938Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00367,
        "percentile": 0.29364
      },
      "nvd": {
        "published": "2026-07-30T01:16:28.413",
        "lastModified": "2026-07-31T16:17:00.417",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17664",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Loader processing allows a compromised renderer to receive data belonging to another origin, while the rejected input and origin comparison are not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/500554346",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17665",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:17.750Z",
      "date_published": "2026-07-30T00:18:47.074Z",
      "date_updated": "2026-07-31T03:55:58.954Z",
      "publisher": "Chrome",
      "title": "Use after free in V8 in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36369
      },
      "nvd": {
        "published": "2026-07-30T01:16:28.540",
        "lastModified": "2026-08-03T12:12:47.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17665",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome V8 accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511277457",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17666",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:17.976Z",
      "date_published": "2026-07-30T00:18:47.359Z",
      "date_updated": "2026-07-30T17:38:54.762Z",
      "publisher": "Chrome",
      "title": "Cryptographic Flaw in Enterprise in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-325",
          "name": "Missing Cryptographic Step",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08747
      },
      "nvd": {
        "published": "2026-07-30T01:16:28.680",
        "lastModified": "2026-08-03T12:12:28.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17666",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Enterprise omits an undisclosed cryptographic step before a network-supplied decision bypasses access control; the public issue exposes no narrower mechanism.",
        "basis": [
          "CNA",
          "CWE-325",
          "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html"
        ],
        "deepDive": true,
        "notes": "Reviewed https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html. Chrome's release names only a cryptographic flaw in Enterprise, and the linked Chromium issue exposed only a sign-in page, so the missing cryptographic step remains undisclosed."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511761758",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17667",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:18.199Z",
      "date_published": "2026-07-30T00:18:47.707Z",
      "date_updated": "2026-07-30T17:38:46.408Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00381,
        "percentile": 0.30855
      },
      "nvd": {
        "published": "2026-07-30T01:16:28.783",
        "lastModified": "2026-08-03T12:12:05.797",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17667",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome consumes memory or an object field before the value has been initialized for that path.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513043537",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17668",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:18.434Z",
      "date_published": "2026-07-30T00:18:47.986Z",
      "date_updated": "2026-07-30T17:38:39.128Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00381,
        "percentile": 0.30855
      },
      "nvd": {
        "published": "2026-07-30T01:16:28.900",
        "lastModified": "2026-08-03T12:11:40.940",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17668",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The component uses memory before initializing the value that controls the subsequent access.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513134019",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17669",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:18.675Z",
      "date_published": "2026-07-30T00:18:48.276Z",
      "date_updated": "2026-07-30T17:38:32.917Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29654
      },
      "nvd": {
        "published": "2026-07-30T01:16:29.010",
        "lastModified": "2026-08-03T12:11:19.593",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17669",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome release labels an inappropriate Chrome for iOS implementation and sandbox-escape impact but does not disclose the failing control.",
        "basis": [
          "CNA",
          "CWE-693",
          "Chrome release advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html and the linked restricted issue https://issues.chromium.org/issues/513142464; the release discloses only an inappropriate Chrome for iOS implementation and keeps the engineering cause restricted."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513142464",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17670",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:18.920Z",
      "date_published": "2026-07-30T00:18:48.566Z",
      "date_updated": "2026-07-30T17:38:26.744Z",
      "publisher": "Chrome",
      "title": "Use after free in Views in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29653
      },
      "nvd": {
        "published": "2026-07-30T01:16:29.110",
        "lastModified": "2026-08-03T12:10:47.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17670",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Views dereferences an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513228974",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17671",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:19.215Z",
      "date_published": "2026-07-30T00:18:48.870Z",
      "date_updated": "2026-07-30T17:38:20.916Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29652
      },
      "nvd": {
        "published": "2026-07-30T01:16:29.220",
        "lastModified": "2026-08-03T12:10:27.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17671",
        "family": "STATE_SEQUENCE",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "ANGLE allowed advanced blending while a nonzero draw buffer was enabled and its Vulkan backend skipped the corresponding validation for disabled attachments.",
        "basis": [
          "CNA",
          "CWE-20",
          "Chrome release",
          "Chromium source commit"
        ],
        "deepDive": true,
        "notes": "Inspected https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html and https://chromium.googlesource.com/experimental/angle/angle/+/1b18da44dff8704b82f36d15424c7ac0583ce0ac; the fix identifies advanced-blend validation and backend handling, but no independent reproduction was performed."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513257423",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17672",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:19.441Z",
      "date_published": "2026-07-30T00:18:49.141Z",
      "date_updated": "2026-07-30T17:38:14.192Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29654
      },
      "nvd": {
        "published": "2026-07-30T01:16:29.330",
        "lastModified": "2026-08-03T12:10:10.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17672",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record says untrusted Chromecast input can lead from a compromised renderer to sandbox escape but does not reveal the validation rule, parser, object, or state transition that fails.",
        "basis": [
          "CNA",
          "CWE-20",
          "Chromium issue 513375270"
        ],
        "deepDive": true,
        "notes": "Inspected https://issues.chromium.org/issues/513375270, whose public response exposed no issue details; https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html returned a CAPTCHA, so the cause remains undetermined."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513375270",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17673",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:19.690Z",
      "date_published": "2026-07-30T00:18:49.410Z",
      "date_updated": "2026-07-30T17:38:02.759Z",
      "publisher": "Chrome",
      "title": "Integer overflow in QUIC in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29656
      },
      "nvd": {
        "published": "2026-07-30T01:16:29.447",
        "lastModified": "2026-08-03T12:17:37.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17673",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unchecked integer calculation in Chrome can wrap and produce an invalid memory size or position.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513735177",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 231,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17674",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:19.930Z",
      "date_published": "2026-07-30T00:18:49.674Z",
      "date_updated": "2026-07-31T15:59:23.881Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in HTML in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00391,
        "percentile": 0.31808
      },
      "nvd": {
        "published": "2026-07-30T01:16:29.560",
        "lastModified": "2026-07-31T16:17:00.577",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17674",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome can be induced to bypass Content Security Policy, but the public record does not disclose the failed policy rule or implementation check.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/513791232",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17675",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:20.153Z",
      "date_published": "2026-07-30T00:18:49.940Z",
      "date_updated": "2026-07-30T17:37:55.497Z",
      "publisher": "Chrome",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24004
      },
      "nvd": {
        "published": "2026-07-30T01:16:29.670",
        "lastModified": "2026-08-03T12:17:16.540",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17675",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Chrome, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513920258",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17676",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:20.430Z",
      "date_published": "2026-07-30T00:18:50.225Z",
      "date_updated": "2026-07-30T14:46:51.907Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29652
      },
      "nvd": {
        "published": "2026-07-30T01:16:29.783",
        "lastModified": "2026-08-03T12:17:01.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17676",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record says only that ANGLE had an inappropriate implementation reachable from a compromised renderer, so it does not expose the failing validation, state, or memory rule needed to assign a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-693",
          "Chrome release advisory"
        ],
        "deepDive": true,
        "notes": "Inspected the Chrome release at https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html and opened https://issues.chromium.org/issues/513920298; the release supplies only \"inappropriate implementation in ANGLE,\" and the issue requires sign-in, leaving the enabling cause undetermined."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513920298",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17677",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:20.683Z",
      "date_published": "2026-07-30T00:18:50.499Z",
      "date_updated": "2026-07-30T17:37:48.946Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29653
      },
      "nvd": {
        "published": "2026-07-30T01:16:29.883",
        "lastModified": "2026-08-03T12:16:42.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17677",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record reports an inappropriate ANGLE implementation leading to sandbox escape but discloses no failing check, state, or memory operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513921488",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17678",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:20.937Z",
      "date_published": "2026-07-30T00:18:50.788Z",
      "date_updated": "2026-07-30T17:37:39.718Z",
      "publisher": "Chrome",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29651
      },
      "nvd": {
        "published": "2026-07-30T01:16:29.990",
        "lastModified": "2026-08-03T12:16:25.223",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17678",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome reads beyond the available buffer because an input length, offset, or parser boundary is not checked before access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/515452019",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17679",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:21.153Z",
      "date_published": "2026-07-30T00:18:51.065Z",
      "date_updated": "2026-07-30T17:37:31.865Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27623
      },
      "nvd": {
        "published": "2026-07-30T01:16:30.100",
        "lastModified": "2026-08-03T12:16:09.193",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17679",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says Print Preview insufficiently validates input before leaking cross-origin data but does not identify the failing validation rule.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516430649",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17680",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:21.387Z",
      "date_published": "2026-07-30T00:18:51.348Z",
      "date_updated": "2026-07-30T14:49:37.165Z",
      "publisher": "Chrome",
      "title": "Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00399,
        "percentile": 0.32751
      },
      "nvd": {
        "published": "2026-07-30T01:16:30.217",
        "lastModified": "2026-08-03T12:15:53.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17680",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ChromeOS Color processing writes beyond a heap buffer using renderer-controlled input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516486611",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17681",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:21.587Z",
      "date_published": "2026-07-30T00:18:51.624Z",
      "date_updated": "2026-07-30T14:51:31.769Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0042,
        "percentile": 0.34625
      },
      "nvd": {
        "published": "2026-07-30T01:16:30.330",
        "lastModified": "2026-08-03T12:15:37.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17681",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record says Web Authentication insufficiently validates untrusted input but does not identify the field, parser, or check that permits the sandbox escape.",
        "basis": [
          "CNA",
          "CWE-20",
          "Chrome 151 release note"
        ],
        "deepDive": true,
        "notes": "Inspected https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html; it repeats only 'insufficient validation of untrusted input in Web Authentication,' and https://issues.chromium.org/issues/516813184 is access-restricted."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516813184",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 282,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17682",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:21.813Z",
      "date_published": "2026-07-30T00:18:51.893Z",
      "date_updated": "2026-07-30T14:53:41.154Z",
      "publisher": "Chrome",
      "title": "Integer overflow in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29653
      },
      "nvd": {
        "published": "2026-07-30T01:16:30.443",
        "lastModified": "2026-08-03T17:59:49.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17682",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516837126",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17683",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:22.023Z",
      "date_published": "2026-07-30T00:18:52.191Z",
      "date_updated": "2026-07-30T15:03:19.595Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27623
      },
      "nvd": {
        "published": "2026-07-30T01:16:30.560",
        "lastModified": "2026-08-03T17:59:44.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17683",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public Chrome record says ANGLE can expose process memory but does not identify the read, buffer, or state error that releases it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516887576",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:22.227Z",
      "date_published": "2026-07-30T00:18:52.470Z",
      "date_updated": "2026-07-30T15:05:34.790Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29652
      },
      "nvd": {
        "published": "2026-07-30T01:16:30.660",
        "lastModified": "2026-08-03T12:15:20.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17684",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Chrome for iOS insufficiently validates renderer-controlled input at a sandbox boundary; the public issue does not identify the field or check.",
        "basis": [
          "CNA",
          "CWE-20",
          "https://issues.chromium.org/issues/516894682"
        ],
        "deepDive": true,
        "notes": "Reviewed https://issues.chromium.org/issues/516894682. The linked Chromium issue did not expose public technical content at review time, so the failing validation remains undisclosed."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516894682",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:22.438Z",
      "date_published": "2026-07-30T00:18:52.747Z",
      "date_updated": "2026-07-31T03:55:58.270Z",
      "publisher": "Chrome",
      "title": "Use after free in Autofill in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36368
      },
      "nvd": {
        "published": "2026-07-30T01:16:30.770",
        "lastModified": "2026-08-03T17:59:39.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17685",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516910278",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17686",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:22.688Z",
      "date_published": "2026-07-30T00:18:53.024Z",
      "date_updated": "2026-07-30T15:09:05.824Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.2793
      },
      "nvd": {
        "published": "2026-07-30T01:16:30.880",
        "lastModified": "2026-08-03T17:59:32.487",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17686",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports a Passwords-component validation failure that bypasses site isolation but does not disclose the input, validation rule, or state transition.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516917065",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 247,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:22.923Z",
      "date_published": "2026-07-30T00:18:53.310Z",
      "date_updated": "2026-07-30T15:10:52.211Z",
      "publisher": "Chrome",
      "title": "Type Confusion in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33069
      },
      "nvd": {
        "published": "2026-07-30T01:16:30.990",
        "lastModified": "2026-08-03T17:59:02.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17687",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome interprets a memory object through an incompatible type and then performs an invalid access.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516985726",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:23.140Z",
      "date_published": "2026-07-30T00:18:53.745Z",
      "date_updated": "2026-07-30T15:12:15.191Z",
      "publisher": "Chrome",
      "title": "Use after free in Input in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29655
      },
      "nvd": {
        "published": "2026-07-30T01:16:31.100",
        "lastModified": "2026-08-03T17:58:54.590",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17688",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Input can retain and dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517016413",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17689",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:23.370Z",
      "date_published": "2026-07-30T00:18:54.018Z",
      "date_updated": "2026-07-30T13:32:54.178Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23414
      },
      "nvd": {
        "published": "2026-07-30T01:16:31.220",
        "lastModified": "2026-07-31T15:27:35.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17689",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation uses memory before it has been initialized.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517045160",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:23.593Z",
      "date_published": "2026-07-30T00:18:54.298Z",
      "date_updated": "2026-07-30T15:13:36.772Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in PDF in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.1938
      },
      "nvd": {
        "published": "2026-07-30T01:16:31.333",
        "lastModified": "2026-08-03T12:15:04.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17690",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "The PDF component permits crafted content to cross an origin boundary, but the public record does not identify the failing input or origin check.",
        "basis": [
          "CNA record",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517129282",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17691",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:23.827Z",
      "date_published": "2026-07-30T00:18:54.565Z",
      "date_updated": "2026-07-30T15:34:29.080Z",
      "publisher": "Chrome",
      "title": "Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29652
      },
      "nvd": {
        "published": "2026-07-30T01:16:31.443",
        "lastModified": "2026-08-03T15:02:07.273",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17691",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome lets attacker-controlled input reach an out-of-bounds write.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517321292",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17692",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:24.090Z",
      "date_published": "2026-07-30T00:18:54.870Z",
      "date_updated": "2026-07-30T15:18:37.065Z",
      "publisher": "Chrome",
      "title": "Use after free in DataTransfer in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29651
      },
      "nvd": {
        "published": "2026-07-30T01:16:31.550",
        "lastModified": "2026-08-03T15:02:16.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17692",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome's DataTransfer component uses a freed object after a compromised renderer triggers the vulnerable path.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517350808",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17693",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:24.333Z",
      "date_published": "2026-07-30T00:18:55.159Z",
      "date_updated": "2026-07-30T13:21:53.776Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14912
      },
      "nvd": {
        "published": "2026-07-30T01:16:31.663",
        "lastModified": "2026-07-31T15:27:51.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17693",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's FileSystem component leaks cross-origin data because a policy boundary is not enforced, while the public record does not identify the specific origin check.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517448723",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17694",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:24.553Z",
      "date_published": "2026-07-30T00:18:55.433Z",
      "date_updated": "2026-07-31T03:55:57.544Z",
      "publisher": "Chrome",
      "title": "Use after free in DOM in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36369
      },
      "nvd": {
        "published": "2026-07-30T01:16:31.763",
        "lastModified": "2026-08-03T17:58:44.210",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17694",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path can retain or dereference an object after its storage has been released, leaving a dangling reference.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517511796",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:24.794Z",
      "date_published": "2026-07-30T00:18:55.713Z",
      "date_updated": "2026-07-30T15:27:28.667Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29655
      },
      "nvd": {
        "published": "2026-07-30T01:16:31.877",
        "lastModified": "2026-08-03T17:51:01.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17695",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record states only that an inappropriate ANGLE implementation may permit sandbox escape and does not reveal the causal operation or protection failure.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-693",
          "Official-link access check"
        ],
        "deepDive": true,
        "notes": "Inspected both linked Chromium primary URLs: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html returned HTTP 429 and https://issues.chromium.org/issues/517543052 was not publicly retrievable in this review environment; no external technical content was added, so the ANGLE cause remains undetermined."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517543052",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17696",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:25.014Z",
      "date_published": "2026-07-30T00:18:55.996Z",
      "date_updated": "2026-07-30T13:32:54.341Z",
      "publisher": "Chrome",
      "title": "Side-channel information leakage in Media in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20703
      },
      "nvd": {
        "published": "2026-07-30T01:16:31.973",
        "lastModified": "2026-07-31T15:28:02.007",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17696",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path exposes a measurable side channel that lets a remote page infer data belonging to another origin.",
        "basis": [
          "CNA",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517550034",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:25.240Z",
      "date_published": "2026-07-30T00:18:56.265Z",
      "date_updated": "2026-07-30T15:31:26.502Z",
      "publisher": "Chrome",
      "title": "Type Confusion in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33068
      },
      "nvd": {
        "published": "2026-07-30T01:16:32.087",
        "lastModified": "2026-08-03T17:50:55.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17697",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation treats an object as the wrong runtime type, permitting invalid memory access.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517575864",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:25.454Z",
      "date_published": "2026-07-30T00:18:56.545Z",
      "date_updated": "2026-07-30T15:33:05.575Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22461
      },
      "nvd": {
        "published": "2026-07-30T01:16:32.200",
        "lastModified": "2026-08-03T13:45:28.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17698",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for Android UI handling permits crafted HTML to cross the origin boundary and leak data, while the exact validation rule is not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517670731",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17699",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:25.668Z",
      "date_published": "2026-07-30T00:18:56.815Z",
      "date_updated": "2026-07-30T15:37:36.401Z",
      "publisher": "Chrome",
      "title": "Use after free in Views in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04582
      },
      "nvd": {
        "published": "2026-07-30T01:16:32.310",
        "lastModified": "2026-08-03T17:50:49.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17699",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome accesses an object after its lifetime has ended while processing attacker-controlled input.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517785292",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17700",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:25.920Z",
      "date_published": "2026-07-30T00:18:57.164Z",
      "date_updated": "2026-07-30T13:32:54.488Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20704
      },
      "nvd": {
        "published": "2026-07-30T01:16:32.413",
        "lastModified": "2026-07-31T15:28:16.303",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17700",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Actor processing allows a compromised renderer to receive data belonging to another origin, while the rejected input and origin comparison are not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517789833",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17701",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:26.171Z",
      "date_published": "2026-07-30T00:18:57.474Z",
      "date_updated": "2026-07-30T15:44:10.374Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.27991
      },
      "nvd": {
        "published": "2026-07-30T01:16:32.523",
        "lastModified": "2026-08-03T17:50:41.777",
        "vulnStatus": "Analyzed",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17701",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ANGLE fails to validate a bound before performing the out-of-bounds read identified by CWE-125.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517972648",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17702",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:26.397Z",
      "date_published": "2026-07-30T00:18:57.742Z",
      "date_updated": "2026-07-30T17:34:59.061Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Skia in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10743
      },
      "nvd": {
        "published": "2026-07-30T01:16:32.630",
        "lastModified": "2026-08-03T17:50:13.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17702",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Skia lets renderer-controlled content cross an origin boundary and disclose data, but the public record does not identify the trusted origin state or check.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517973093",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17703",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:26.625Z",
      "date_published": "2026-07-30T00:18:58.038Z",
      "date_updated": "2026-07-30T15:51:38.205Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00318,
        "percentile": 0.2424
      },
      "nvd": {
        "published": "2026-07-30T01:16:32.737",
        "lastModified": "2026-08-03T15:03:32.543",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17703",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chrome for iOS enforces a navigation restriction in client-side state that a crafted page can bypass, while the exact transition is not public.",
        "basis": [
          "CNA",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518051499",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17704",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:26.850Z",
      "date_published": "2026-07-30T00:18:58.321Z",
      "date_updated": "2026-07-30T15:54:30.213Z",
      "publisher": "Chrome",
      "title": "Use after free in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29655
      },
      "nvd": {
        "published": "2026-07-30T01:16:32.837",
        "lastModified": "2026-08-03T17:50:06.333",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17704",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A reachable path retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519259107",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17705",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:27.091Z",
      "date_published": "2026-07-30T00:18:58.602Z",
      "date_updated": "2026-07-31T03:55:56.836Z",
      "publisher": "Chrome",
      "title": "Integer overflow in libxml in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36369
      },
      "nvd": {
        "published": "2026-07-30T01:16:32.950",
        "lastModified": "2026-08-03T17:49:48.147",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17705",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome performs size or index arithmetic that can wrap or produce an allocation smaller than the subsequent memory operation requires.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519665978",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17706",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:27.307Z",
      "date_published": "2026-07-30T00:18:58.889Z",
      "date_updated": "2026-07-30T13:32:54.635Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22148
      },
      "nvd": {
        "published": "2026-07-30T01:16:33.063",
        "lastModified": "2026-07-30T14:57:04.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17706",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Media component can expose cross-origin data after renderer compromise, but the exact validation rule is not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/519693032",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17707",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:27.536Z",
      "date_published": "2026-07-30T00:18:59.182Z",
      "date_updated": "2026-07-30T15:37:21.942Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in Media in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00381,
        "percentile": 0.30855
      },
      "nvd": {
        "published": "2026-07-30T01:16:33.170",
        "lastModified": "2026-08-03T15:02:28.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17707",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Media component exposes uninitialized process memory while handling crafted renderer-controlled content.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519701233",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17708",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:27.764Z",
      "date_published": "2026-07-30T00:18:59.485Z",
      "date_updated": "2026-07-30T15:38:46.096Z",
      "publisher": "Chrome",
      "title": "Use after free in Audio in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29656
      },
      "nvd": {
        "published": "2026-07-30T01:16:33.283",
        "lastModified": "2026-08-03T17:49:37.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17708",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome's Audio component accesses an object after it has been freed, allowing crafted renderer activity to operate on stale memory.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519738647",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17709",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:27.997Z",
      "date_published": "2026-07-30T00:18:59.751Z",
      "date_updated": "2026-07-30T15:40:18.535Z",
      "publisher": "Chrome",
      "title": "Race in Downloads in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21747
      },
      "nvd": {
        "published": "2026-07-30T01:16:33.390",
        "lastModified": "2026-08-03T17:49:28.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17709",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent Chrome operations can observe or mutate shared state without the synchronization required to preserve the security invariant.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519981494",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 231,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17710",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:28.212Z",
      "date_published": "2026-07-30T00:19:00.038Z",
      "date_updated": "2026-07-30T15:42:19.488Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29656
      },
      "nvd": {
        "published": "2026-07-30T01:16:33.500",
        "lastModified": "2026-08-03T17:49:06.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17710",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Google identifies an MHTML implementation flaw that enables a renderer sandbox escape, but the public release and restricted issue do not expose the failing state or check.",
        "basis": [
          "CNA",
          "CWE-693",
          "Chrome Release"
        ],
        "deepDive": true,
        "notes": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html ; https://issues.chromium.org/issues/519991712 - the release repeats only 'Inappropriate implementation in MHTML,' and the official issue requires sign-in, so no failing state, check, or patch was publicly inspectable."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519991712",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17711",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:28.436Z",
      "date_published": "2026-07-30T00:19:00.305Z",
      "date_updated": "2026-07-30T15:44:17.262Z",
      "publisher": "Chrome",
      "title": "Race in Downloads in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21747
      },
      "nvd": {
        "published": "2026-07-30T01:16:33.607",
        "lastModified": "2026-08-03T17:48:45.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17711",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Downloads accesses shared state concurrently without the synchronization needed to keep the state transition atomic and consistent.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362",
          "Chrome release advisory"
        ],
        "deepDive": true,
        "notes": "Inspected the Chrome release at https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html and checked the linked issue https://issues.chromium.org/issues/519996040; the release provides only \"Race in Downloads,\" while the issue is permission-gated and no shared object, lock, or interleaving is public."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519996040",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 231,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17712",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:28.680Z",
      "date_published": "2026-07-30T00:19:00.587Z",
      "date_updated": "2026-07-31T03:55:56.076Z",
      "publisher": "Chrome",
      "title": "Race in Skia in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28022
      },
      "nvd": {
        "published": "2026-07-30T01:16:33.713",
        "lastModified": "2026-08-03T17:48:07.760",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17712",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Concurrent Skia activity violates a shared-state invariant and permits sandboxed code execution, although the raced object is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520535595",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:28.912Z",
      "date_published": "2026-07-30T00:19:00.899Z",
      "date_updated": "2026-07-30T15:48:51.751Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29654
      },
      "nvd": {
        "published": "2026-07-30T01:16:33.820",
        "lastModified": "2026-08-03T17:47:42.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17713",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record only says untrusted Accessibility input can escape the Android sandbox and does not identify the data structure or validation rule involved.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20",
          "Vendor release note",
          "Vendor issue tracker"
        ],
        "deepDive": true,
        "notes": "Inspected https://issues.chromium.org/issues/520572766 and https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html; the issue was not publicly readable and the release entry adds no failing validation rule."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520572766",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 277,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17714",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:29.131Z",
      "date_published": "2026-07-30T00:19:01.167Z",
      "date_updated": "2026-07-30T15:50:32.399Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00381,
        "percentile": 0.30856
      },
      "nvd": {
        "published": "2026-07-30T01:16:33.930",
        "lastModified": "2026-08-03T17:47:13.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17714",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ANGLE reads an uninitialized value and exposes bytes from process memory to crafted web content.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521293438",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17715",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:29.360Z",
      "date_published": "2026-07-30T00:19:01.471Z",
      "date_updated": "2026-07-30T17:35:43.259Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10743
      },
      "nvd": {
        "published": "2026-07-30T01:16:34.037",
        "lastModified": "2026-08-03T17:47:07.553",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17715",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Chrome Passwords fails to preserve the same-origin boundary during a user-mediated operation, allowing cross-origin data disclosure.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521491778",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17716",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:29.586Z",
      "date_published": "2026-07-30T00:19:01.759Z",
      "date_updated": "2026-07-31T03:55:38.491Z",
      "publisher": "Chrome",
      "title": "Use after free in Updater in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03493
      },
      "nvd": {
        "published": "2026-07-30T01:16:34.137",
        "lastModified": "2026-07-31T04:16:52.333",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17716",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Updater uses an object after its storage has been freed during attacker-influenced network processing.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/521866061",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17717",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:29.808Z",
      "date_published": "2026-07-30T00:19:02.026Z",
      "date_updated": "2026-07-30T19:00:22.233Z",
      "publisher": "Chrome",
      "title": "Integer overflow in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29654
      },
      "nvd": {
        "published": "2026-07-30T01:16:34.247",
        "lastModified": "2026-08-03T17:47:01.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17717",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522063116",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17718",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:30.031Z",
      "date_published": "2026-07-30T00:19:02.311Z",
      "date_updated": "2026-07-30T18:57:47.771Z",
      "publisher": "Chrome",
      "title": "Use after free in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24002
      },
      "nvd": {
        "published": "2026-07-30T01:16:34.353",
        "lastModified": "2026-08-03T17:46:39.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17718",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522079372",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17719",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:30.275Z",
      "date_published": "2026-07-30T00:19:02.569Z",
      "date_updated": "2026-07-31T03:55:55.248Z",
      "publisher": "Chrome",
      "title": "Use after free in Input in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30625
      },
      "nvd": {
        "published": "2026-07-30T01:16:34.463",
        "lastModified": "2026-08-03T17:46:29.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17719",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path continues using an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522304853",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17720",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:30.484Z",
      "date_published": "2026-07-30T00:19:02.874Z",
      "date_updated": "2026-07-30T17:36:25.660Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07324
      },
      "nvd": {
        "published": "2026-07-30T01:16:34.587",
        "lastModified": "2026-08-03T17:45:52.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17720",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The browser or server accepts an attacker-controlled origin, navigation or presentation boundary without the required trust validation.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522545249",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17721",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:30.725Z",
      "date_published": "2026-07-30T00:19:03.139Z",
      "date_updated": "2026-07-30T18:53:33.549Z",
      "publisher": "Chrome",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24002
      },
      "nvd": {
        "published": "2026-07-30T01:16:34.690",
        "lastModified": "2026-08-03T17:45:46.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17721",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled input reaches a write whose destination boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523495723",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17722",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:30.943Z",
      "date_published": "2026-07-30T00:19:03.410Z",
      "date_updated": "2026-07-31T03:56:26.401Z",
      "publisher": "Chrome",
      "title": "Object lifecycle issue in WebView in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.2005
      },
      "nvd": {
        "published": "2026-07-30T01:16:34.803",
        "lastModified": "2026-08-03T13:46:22.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17722",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523592755",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:31.200Z",
      "date_published": "2026-07-30T00:19:03.676Z",
      "date_updated": "2026-07-31T03:56:27.072Z",
      "publisher": "Chrome",
      "title": "Use after free in Media in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17588
      },
      "nvd": {
        "published": "2026-07-30T01:16:34.903",
        "lastModified": "2026-07-31T04:16:52.940",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17723",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Media on Windows can retain and dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/523718303",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17724",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:31.424Z",
      "date_published": "2026-07-30T00:19:03.936Z",
      "date_updated": "2026-07-30T20:57:21.898Z",
      "publisher": "Chrome",
      "title": "Race in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04935
      },
      "nvd": {
        "published": "2026-07-30T01:16:35.020",
        "lastModified": "2026-07-30T22:16:54.630",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17724",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A race in the browser state transition permits universal cross-site scripting.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/523720739",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17725",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:31.620Z",
      "date_published": "2026-07-30T00:19:04.191Z",
      "date_updated": "2026-07-31T03:55:54.490Z",
      "publisher": "Chrome",
      "title": "Type Confusion in V8 in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00413,
        "percentile": 0.3401
      },
      "nvd": {
        "published": "2026-07-30T01:16:35.137",
        "lastModified": "2026-08-03T17:45:36.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17725",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted JavaScript causes V8 to access a resource through an incompatible runtime type.",
        "basis": [
          "CNA record",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/528501127",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17726",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:31.860Z",
      "date_published": "2026-07-30T00:19:04.467Z",
      "date_updated": "2026-07-31T03:56:27.787Z",
      "publisher": "Chrome",
      "title": "Integer overflow in WebGL in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24004
      },
      "nvd": {
        "published": "2026-07-30T01:16:35.257",
        "lastModified": "2026-08-03T13:44:37.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17726",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome uses an unchecked integer result after arithmetic can overflow its representable range.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/529867799",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17727",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:32.108Z",
      "date_published": "2026-07-30T00:19:04.732Z",
      "date_updated": "2026-07-31T03:56:28.536Z",
      "publisher": "Chrome",
      "title": "Out of bounds write in WebGL in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24004
      },
      "nvd": {
        "published": "2026-07-30T01:16:35.370",
        "lastModified": "2026-08-03T13:44:34.393",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17727",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chrome's WebGL path writes beyond an allocated buffer while processing crafted page input.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/529932631",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17728",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:32.362Z",
      "date_published": "2026-07-30T00:19:05.006Z",
      "date_updated": "2026-07-30T20:17:37.815Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08188
      },
      "nvd": {
        "published": "2026-07-30T01:16:35.487",
        "lastModified": "2026-07-30T21:16:55.930",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17728",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Chrome, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/461167648",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:32.584Z",
      "date_published": "2026-07-30T00:19:05.802Z",
      "date_updated": "2026-08-03T16:11:22.831Z",
      "publisher": "Chrome",
      "title": "Use after free in V8 in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21756
      },
      "nvd": {
        "published": "2026-07-30T01:16:35.590",
        "lastModified": "2026-08-03T17:16:31.943",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17729",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path can retain or dereference an object after its storage has been released, leaving a dangling reference.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/520656237",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:32.798Z",
      "date_published": "2026-07-30T00:19:06.087Z",
      "date_updated": "2026-07-30T13:32:54.784Z",
      "publisher": "Chrome",
      "title": "Side-channel information leakage in Autofill in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15642
      },
      "nvd": {
        "published": "2026-07-30T01:16:35.707",
        "lastModified": "2026-07-31T15:28:27.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17730",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Autofill exposes cross-origin state through a side channel whose observable result varies with user UI gestures.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/40057032",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:33.040Z",
      "date_published": "2026-07-30T00:19:06.360Z",
      "date_updated": "2026-07-30T17:37:37.849Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Autofill in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10157
      },
      "nvd": {
        "published": "2026-07-30T01:16:35.820",
        "lastModified": "2026-08-03T13:47:01.033",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17731",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chrome Autofill accepts page-controlled origin state that can expose data belonging to another origin, although the exact source-validation predicate is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/463551850",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17732",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:33.253Z",
      "date_published": "2026-07-30T00:19:05.539Z",
      "date_updated": "2026-07-30T17:37:07.908Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in SVG in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07021
      },
      "nvd": {
        "published": "2026-07-30T01:16:35.930",
        "lastModified": "2026-08-03T17:45:30.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17732",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An SVG load crosses an origin boundary and leaks data, but the public record does not identify the missing origin check.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/476646486",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17733",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:33.464Z",
      "date_published": "2026-07-30T00:19:06.626Z",
      "date_updated": "2026-07-30T17:38:07.608Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in QUIC in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10158
      },
      "nvd": {
        "published": "2026-07-30T01:16:36.033",
        "lastModified": "2026-08-03T13:47:15.657",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17733",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Chrome path applies an origin decision that permits data or authority to cross the intended origin boundary.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/495793059",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17734",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:33.715Z",
      "date_published": "2026-07-30T00:19:06.919Z",
      "date_updated": "2026-07-30T20:15:18.218Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08188
      },
      "nvd": {
        "published": "2026-07-30T01:16:36.147",
        "lastModified": "2026-07-30T21:16:56.083",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17734",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Autofill allows crafted web content to cross the browser markup execution boundary and execute in another origin.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/496304083",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17735",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:33.939Z",
      "date_published": "2026-07-30T00:19:07.246Z",
      "date_updated": "2026-07-30T20:07:20.184Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in BFCache in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "epss": {
        "score": 0.00208,
        "percentile": 0.11016
      },
      "nvd": {
        "published": "2026-07-30T01:16:36.257",
        "lastModified": "2026-07-30T21:16:56.240",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17735",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Google reports that BFCache input can lead from a compromised renderer to sandbox escape, but the public record does not disclose the enabling check, state transition, or memory error.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/496569497",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17736",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:34.188Z",
      "date_published": "2026-07-30T00:19:07.519Z",
      "date_updated": "2026-07-30T18:43:09.620Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00192,
        "percentile": 0.0908
      },
      "nvd": {
        "published": "2026-07-30T01:16:36.377",
        "lastModified": "2026-08-03T13:47:19.083",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17736",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome WebView accepts malformed input that can cross the renderer sandbox, but the public record does not identify the parsed field or failed validation.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/496715442",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:34.399Z",
      "date_published": "2026-07-30T00:19:07.841Z",
      "date_updated": "2026-07-30T18:43:38.375Z",
      "publisher": "Chrome",
      "title": "Use after free in Bluetooth in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07714
      },
      "nvd": {
        "published": "2026-07-30T01:16:36.483",
        "lastModified": "2026-08-03T13:47:21.563",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17737",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path continues using an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/498000415",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 247,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:34.613Z",
      "date_published": "2026-07-30T00:19:08.136Z",
      "date_updated": "2026-08-03T16:11:19.458Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20207
      },
      "nvd": {
        "published": "2026-07-30T01:16:36.603",
        "lastModified": "2026-08-03T17:16:32.117",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17738",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's Payments component insufficiently validates untrusted input, while the official release and public record do not reveal the accepted object or sandbox-boundary check.",
        "basis": [
          "CNA",
          "CWE-20",
          "Chrome Stable Channel release 151.0.7922.71/.72"
        ],
        "deepDive": true,
        "notes": "Inspected https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html. The official release lists issue 498079379 as insufficient validation in Payments but keeps the bug details restricted and exposes no failing check."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/498079379",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17739",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:34.819Z",
      "date_published": "2026-07-30T00:19:08.390Z",
      "date_updated": "2026-07-30T18:44:08.760Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03885
      },
      "nvd": {
        "published": "2026-07-30T01:16:36.717",
        "lastModified": "2026-08-03T17:45:21.783",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17739",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/498353463",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17740",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:35.045Z",
      "date_published": "2026-07-30T00:19:08.657Z",
      "date_updated": "2026-07-30T14:38:37.234Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18321
      },
      "nvd": {
        "published": "2026-07-30T01:16:36.820",
        "lastModified": "2026-07-31T15:28:39.653",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17740",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome uses uninitialized storage, allowing stale process memory to influence or escape through the operation.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/498827800",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17741",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:35.268Z",
      "date_published": "2026-07-30T00:19:08.916Z",
      "date_updated": "2026-07-30T18:44:39.508Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10566
      },
      "nvd": {
        "published": "2026-07-30T01:16:36.937",
        "lastModified": "2026-08-03T13:47:24.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17741",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record names generic input validation and a possible sandbox escape but does not reveal the failing parser, check, or state rule.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/498877660",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17742",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:35.489Z",
      "date_published": "2026-07-30T00:19:09.193Z",
      "date_updated": "2026-07-30T14:39:06.590Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Payments in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10158
      },
      "nvd": {
        "published": "2026-07-30T01:16:37.050",
        "lastModified": "2026-07-31T15:28:51.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17742",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's Payments policy permits crafted content to cross an origin boundary, but the exact origin check and data path are not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/499003233",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17743",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:35.730Z",
      "date_published": "2026-07-30T00:19:09.455Z",
      "date_updated": "2026-08-03T16:11:16.144Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in ControlledFrame in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08373
      },
      "nvd": {
        "published": "2026-07-30T01:16:37.160",
        "lastModified": "2026-08-03T17:16:32.300",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17743",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ControlledFrame fails to enforce an origin policy for crafted page activity, but the public record does not identify the mismatched origin or request check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/499204022",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17744",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:35.946Z",
      "date_published": "2026-07-30T00:19:09.715Z",
      "date_updated": "2026-07-30T18:45:20.547Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09613
      },
      "nvd": {
        "published": "2026-07-30T01:16:37.263",
        "lastModified": "2026-08-03T17:45:16.180",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17744",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record reports a File Input sandbox escape but does not identify a failing privilege check, state transition, or parser rule.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/500137309",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17745",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:36.184Z",
      "date_published": "2026-07-30T00:19:09.988Z",
      "date_updated": "2026-07-30T18:45:45.347Z",
      "publisher": "Chrome",
      "title": "Out of bounds read in Skia in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07714
      },
      "nvd": {
        "published": "2026-07-30T01:16:37.370",
        "lastModified": "2026-08-03T17:45:06.170",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17745",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Skia reads beyond an allocated buffer while processing renderer-controlled page data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/500172224",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17746",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:36.406Z",
      "date_published": "2026-07-30T00:19:10.264Z",
      "date_updated": "2026-07-30T18:46:14.492Z",
      "publisher": "Chrome",
      "title": "Use after free in GPU in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07713
      },
      "nvd": {
        "published": "2026-07-30T01:16:37.480",
        "lastModified": "2026-08-03T17:58:37.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17746",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Chrome, code retains or reuses an object after the lifetime transition that frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/500390256",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:36.625Z",
      "date_published": "2026-07-30T00:19:10.525Z",
      "date_updated": "2026-07-30T19:00:45.644Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.1212
      },
      "nvd": {
        "published": "2026-07-30T01:16:37.590",
        "lastModified": "2026-08-03T13:46:25.953",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17747",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome accepts a specifically malformed value or unsupported operation without the validation required by that interface, driving the component into an unsafe condition outside the other mechanism families.",
        "basis": [
          "CNA",
          "NVD",
          "ADP",
          "CWE-20",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/500472958",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17748",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:36.859Z",
      "date_published": "2026-07-30T00:19:10.811Z",
      "date_updated": "2026-08-03T16:11:12.875Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08373
      },
      "nvd": {
        "published": "2026-07-30T01:16:37.693",
        "lastModified": "2026-08-03T17:16:32.470",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17748",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Extensions component accepts renderer-controlled context across a site-isolation boundary, although the exact origin comparison is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/500494349",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17749",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:37.090Z",
      "date_published": "2026-07-30T00:19:11.091Z",
      "date_updated": "2026-08-03T16:11:09.621Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11746
      },
      "nvd": {
        "published": "2026-07-30T01:16:37.803",
        "lastModified": "2026-08-03T17:16:32.643",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17749",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record only says a malicious extension can pass untrusted input through an Extensions boundary and does not identify the data structure or validation rule involved.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20",
          "Vendor release note",
          "Vendor issue tracker"
        ],
        "deepDive": true,
        "notes": "Inspected https://issues.chromium.org/issues/500526602 and https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html; the issue was not publicly readable and the release entry adds no failing validation rule."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/500526602",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17750",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:37.300Z",
      "date_published": "2026-07-30T00:19:11.362Z",
      "date_updated": "2026-07-30T19:07:47.820Z",
      "publisher": "Chrome",
      "title": "Use after free in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10566
      },
      "nvd": {
        "published": "2026-07-30T01:16:37.910",
        "lastModified": "2026-08-03T17:58:25.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17750",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ANGLE can access an object after it has been freed while processing a crafted page.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/500560234",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17751",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:37.530Z",
      "date_published": "2026-07-30T00:19:11.633Z",
      "date_updated": "2026-07-31T03:55:53.730Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in AdFilter in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00365,
        "percentile": 0.29183
      },
      "nvd": {
        "published": "2026-07-30T01:16:38.027",
        "lastModified": "2026-08-03T17:58:04.673",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17751",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome AdFilter permits attacker code to exercise an unintended in-sandbox privilege, but the public record does not disclose the failing enforcement rule.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/501591293",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17752",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:37.754Z",
      "date_published": "2026-07-30T00:19:11.901Z",
      "date_updated": "2026-07-31T03:56:12.341Z",
      "publisher": "Chrome",
      "title": "Use after free in Views in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24003
      },
      "nvd": {
        "published": "2026-07-30T01:16:38.130",
        "lastModified": "2026-08-03T17:57:01.153",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17752",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Views uses an object after its storage has been freed while processing attacker-controlled web content.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/501619207",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17753",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:37.991Z",
      "date_published": "2026-07-30T00:19:12.170Z",
      "date_updated": "2026-07-30T14:49:51.055Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10157
      },
      "nvd": {
        "published": "2026-07-30T01:16:38.240",
        "lastModified": "2026-07-31T15:29:00.807",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17753",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Autofill implementation permits a crafted page to cross an origin boundary and read data belonging to another origin.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/501628355",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:38.195Z",
      "date_published": "2026-07-30T00:19:12.452Z",
      "date_updated": "2026-08-03T16:11:06.121Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Blink in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08374
      },
      "nvd": {
        "published": "2026-07-30T01:16:38.343",
        "lastModified": "2026-08-04T14:40:53.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17754",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/501675996",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:38.428Z",
      "date_published": "2026-07-30T00:19:12.713Z",
      "date_updated": "2026-08-03T16:11:01.554Z",
      "publisher": "Chrome",
      "title": "Incorrect security UI in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05214
      },
      "nvd": {
        "published": "2026-07-30T01:16:38.443",
        "lastModified": "2026-08-04T14:40:44.693",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17755",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's extension UI can present attacker-controlled content as trusted interface, but the public record does not identify the incorrect indicator or state.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/501854535",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:38.633Z",
      "date_published": "2026-07-30T00:19:12.987Z",
      "date_updated": "2026-08-03T15:55:14.606Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Presentation in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.2045
      },
      "nvd": {
        "published": "2026-07-30T01:16:38.550",
        "lastModified": "2026-08-04T14:40:33.177",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17756",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a request or browser security-boundary failure but does not disclose the exact host, origin, redirect or protocol check that fails.",
        "basis": [
          "CNA",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/501980797",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17757",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:38.880Z",
      "date_published": "2026-07-30T00:19:13.250Z",
      "date_updated": "2026-07-30T16:08:21.796Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.1832
      },
      "nvd": {
        "published": "2026-07-30T01:16:38.650",
        "lastModified": "2026-07-31T15:29:47.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17757",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation fails to preserve a valid bound, initialization state, type, ownership rule, or object lifetime before memory access.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/502351526",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17758",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:39.088Z",
      "date_published": "2026-07-30T00:19:05.273Z",
      "date_updated": "2026-07-30T16:20:24.389Z",
      "publisher": "Chrome",
      "title": "Heap buffer overflow in Dawn in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00342,
        "percentile": 0.26834
      },
      "nvd": {
        "published": "2026-07-30T01:16:38.777",
        "lastModified": "2026-08-03T17:56:52.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17758",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/503801946",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17759",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:39.335Z",
      "date_published": "2026-07-30T00:19:13.517Z",
      "date_updated": "2026-07-30T15:19:39.632Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in Codecs in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25141
      },
      "nvd": {
        "published": "2026-07-30T01:16:38.910",
        "lastModified": "2026-08-03T17:56:21.153",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17759",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Codecs uses uninitialized memory and can disclose process bytes.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/504650654",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:39.538Z",
      "date_published": "2026-07-30T00:19:13.778Z",
      "date_updated": "2026-07-30T14:50:57.444Z",
      "publisher": "Chrome",
      "title": "Side-channel information leakage in NoStatePrefetch in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15642
      },
      "nvd": {
        "published": "2026-07-30T01:16:39.027",
        "lastModified": "2026-07-31T15:29:11.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17760",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NoStatePrefetch microarchitectural behavior forms a side channel that exposes cross-origin data.",
        "basis": [
          "CNA",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/506473189",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:39.780Z",
      "date_published": "2026-07-30T00:19:14.042Z",
      "date_updated": "2026-07-31T21:39:55.900Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06605
      },
      "nvd": {
        "published": "2026-07-30T01:16:39.147",
        "lastModified": "2026-08-04T14:40:17.560",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17761",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Malicious network traffic reaches Chrome for iOS as executable page markup, but the missing validation step is not public.",
        "basis": [
          "CNA record",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/508249524",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17762",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:39.998Z",
      "date_published": "2026-07-30T00:19:14.321Z",
      "date_updated": "2026-07-30T14:51:29.822Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04368
      },
      "nvd": {
        "published": "2026-07-30T01:16:39.253",
        "lastModified": "2026-08-04T14:40:08.963",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17762",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS can leak cross-origin data through an inappropriate implementation whose missing origin or document binding is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/508251844",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:40.207Z",
      "date_published": "2026-07-30T00:19:14.599Z",
      "date_updated": "2026-07-30T14:51:53.690Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in GPU in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10157
      },
      "nvd": {
        "published": "2026-07-30T01:16:39.367",
        "lastModified": "2026-07-31T15:29:24.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17763",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The GPU component permits a compromised renderer to cross the browser's origin boundary, but the incorrect origin check is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511738693",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:40.438Z",
      "date_published": "2026-07-30T00:19:14.883Z",
      "date_updated": "2026-07-31T21:39:52.634Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in FedCM in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.2045
      },
      "nvd": {
        "published": "2026-07-30T01:16:39.473",
        "lastModified": "2026-08-04T14:38:47.537",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17764",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's FedCM component permits a crafted page to cross the same-origin boundary, while the public record does not identify the failed state or policy check.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511754400",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:40.648Z",
      "date_published": "2026-07-30T00:19:15.152Z",
      "date_updated": "2026-07-30T14:52:22.219Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in WebProtect in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10156
      },
      "nvd": {
        "published": "2026-07-30T01:16:39.660",
        "lastModified": "2026-07-31T15:29:36.767",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17765",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The WebProtect path permits a compromised renderer to cross an origin boundary, but the exact origin comparison is not public.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511765328",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17766",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:40.884Z",
      "date_published": "2026-07-30T00:19:15.416Z",
      "date_updated": "2026-07-30T17:48:37.750Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Clipboard in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02138
      },
      "nvd": {
        "published": "2026-07-30T01:16:39.767",
        "lastModified": "2026-08-03T13:47:26.540",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17766",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record identifies untrusted Clipboard input and cross-origin leakage but does not disclose the rejected value, missing validation, or data path.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511799537",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:41.104Z",
      "date_published": "2026-07-30T00:19:15.675Z",
      "date_updated": "2026-07-30T14:52:43.153Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12051
      },
      "nvd": {
        "published": "2026-07-30T01:16:39.880",
        "lastModified": "2026-08-04T14:39:57.237",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17767",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record says WebView accepts untrusted renderer input before cross-origin disclosure but does not identify the input, validation rule, or data path.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511822402",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:41.321Z",
      "date_published": "2026-07-30T00:19:15.932Z",
      "date_updated": "2026-07-31T21:39:49.088Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20206
      },
      "nvd": {
        "published": "2026-07-30T01:16:39.990",
        "lastModified": "2026-08-04T14:39:48.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17768",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome material says WebSockets input validation can enable a sandbox escape but withholds the rejected field and validation rule.",
        "basis": [
          "CNA",
          "CWE-20",
          "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html"
        ],
        "deepDive": true,
        "notes": "The official Chrome release post calls this a Medium WebSockets input-validation issue and keeps the linked bug details restricted; the embedded 9.6 score therefore conflicts with publisher severity and the exact validation rule remains unavailable."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/512999037",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:41.536Z",
      "date_published": "2026-07-30T00:19:16.189Z",
      "date_updated": "2026-07-30T14:53:00.184Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12052
      },
      "nvd": {
        "published": "2026-07-30T01:16:40.103",
        "lastModified": "2026-08-04T14:32:00.777",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17769",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Cast handling permits crafted HTML to cross the origin boundary and leak data, while the exact validation rule is not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513022076",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:41.780Z",
      "date_published": "2026-07-30T00:19:16.459Z",
      "date_updated": "2026-07-31T17:48:26.446Z",
      "publisher": "Chrome",
      "title": "Out of bounds read in Media in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06386
      },
      "nvd": {
        "published": "2026-07-30T01:16:40.220",
        "lastModified": "2026-08-04T14:31:40.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17770",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome reads beyond the bounds of an allocated buffer while processing attacker-controlled content.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513103345",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:42.002Z",
      "date_published": "2026-07-30T00:19:16.714Z",
      "date_updated": "2026-07-30T14:53:25.099Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14569
      },
      "nvd": {
        "published": "2026-07-30T01:16:40.330",
        "lastModified": "2026-08-04T14:31:34.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17771",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Chrome, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513160525",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17772",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:42.261Z",
      "date_published": "2026-07-30T00:19:16.985Z",
      "date_updated": "2026-07-31T17:48:55.814Z",
      "publisher": "Chrome",
      "title": "Out of bounds read in WebGL in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12052
      },
      "nvd": {
        "published": "2026-07-30T01:16:40.443",
        "lastModified": "2026-08-04T14:31:28.523",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17772",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome WebGL reads beyond the bounds of a memory object while processing a crafted page.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513197846",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17773",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:42.487Z",
      "date_published": "2026-07-30T00:19:17.248Z",
      "date_updated": "2026-07-30T14:53:42.901Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12052
      },
      "nvd": {
        "published": "2026-07-30T01:16:40.557",
        "lastModified": "2026-08-04T14:31:22.407",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17773",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Cast accepts crafted input that crosses an origin boundary, but the public record does not identify the field, parser, or validation rule.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513232523",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17774",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:42.725Z",
      "date_published": "2026-07-30T00:19:17.542Z",
      "date_updated": "2026-07-31T03:55:37.731Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03861
      },
      "nvd": {
        "published": "2026-07-30T01:16:40.670",
        "lastModified": "2026-08-04T14:31:15.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17774",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's Variations component permits untrusted input to corrupt process memory, while the official release does not identify the malformed value or memory invariant.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513323066",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17775",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:42.972Z",
      "date_published": "2026-07-30T00:19:17.801Z",
      "date_updated": "2026-07-30T16:08:14.601Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in PresentationAPI in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04367
      },
      "nvd": {
        "published": "2026-07-30T01:16:40.777",
        "lastModified": "2026-08-04T14:31:10.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17775",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The component accepts content without proving that its origin is the security principal the policy expects.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513363822",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17776",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:43.184Z",
      "date_published": "2026-07-30T00:19:18.072Z",
      "date_updated": "2026-07-31T17:49:32.344Z",
      "publisher": "Chrome",
      "title": "Policy bypass in Receiver in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07526
      },
      "nvd": {
        "published": "2026-07-30T01:16:40.880",
        "lastModified": "2026-08-04T14:31:05.737",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17776",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Receiver permits a renderer-compromised caller to bypass a policy boundary, but the public record does not identify the missing enforcement decision.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513404032",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17777",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:43.405Z",
      "date_published": "2026-07-30T00:19:18.343Z",
      "date_updated": "2026-07-30T14:54:53.039Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04368
      },
      "nvd": {
        "published": "2026-07-30T01:16:40.980",
        "lastModified": "2026-08-04T14:31:00.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17777",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Autofill can expose cross-origin data because the browser does not preserve the intended origin boundary, while the exact check is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513462236",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17778",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:43.614Z",
      "date_published": "2026-07-30T00:19:18.600Z",
      "date_updated": "2026-07-31T03:55:52.975Z",
      "publisher": "Chrome",
      "title": "Use after free in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27632
      },
      "nvd": {
        "published": "2026-07-30T01:16:41.087",
        "lastModified": "2026-08-03T17:56:12.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17778",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Extensions component retains and dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513467993",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17779",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:43.848Z",
      "date_published": "2026-07-30T00:19:18.877Z",
      "date_updated": "2026-07-31T17:50:34.326Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Site Isolation in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13283
      },
      "nvd": {
        "published": "2026-07-30T01:16:41.200",
        "lastModified": "2026-08-04T14:30:52.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17779",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's Site Isolation implementation permits a crafted page to cross an intended site boundary, but the bypass condition is not public.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513478933",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17780",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:44.078Z",
      "date_published": "2026-07-30T00:19:19.133Z",
      "date_updated": "2026-07-31T17:51:39.026Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09447
      },
      "nvd": {
        "published": "2026-07-30T01:16:41.307",
        "lastModified": "2026-08-04T14:29:59.403",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17780",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Isolated Web Apps accept a navigation that should be outside their permitted destination boundary, although the exact validation rule is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513485951",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17781",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:44.307Z",
      "date_published": "2026-07-30T00:19:19.409Z",
      "date_updated": "2026-07-30T17:57:51.956Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07648
      },
      "nvd": {
        "published": "2026-07-30T01:16:41.407",
        "lastModified": "2026-08-03T17:56:04.337",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17781",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An installed extension can cross the browser's origin boundary, but the public record does not identify the incorrect extension permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513502990",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17782",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:44.522Z",
      "date_published": "2026-07-30T00:19:19.688Z",
      "date_updated": "2026-07-31T17:49:15.287Z",
      "publisher": "Chrome",
      "title": "Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10528
      },
      "nvd": {
        "published": "2026-07-30T01:16:41.510",
        "lastModified": "2026-08-04T14:29:33.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17782",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A crafted page in Chrome for iOS can display attacker-controlled content in the Omnibox because the browser fails to preserve the URL bar's trusted security-UI boundary.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513507830",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17783",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:44.809Z",
      "date_published": "2026-07-30T00:19:19.997Z",
      "date_updated": "2026-07-30T14:55:20.357Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Loader in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02093
      },
      "nvd": {
        "published": "2026-07-30T01:16:41.617",
        "lastModified": "2026-08-04T14:29:21.867",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17783",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome trusts an origin, proxy header, cache key, or cross-origin channel without validating that it represents the same security principal and destination used by the policy decision.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513532735",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17784",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:45.099Z",
      "date_published": "2026-07-30T00:19:20.269Z",
      "date_updated": "2026-07-31T21:39:45.693Z",
      "publisher": "Chrome",
      "title": "Use after free in Audio in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20207
      },
      "nvd": {
        "published": "2026-07-30T01:16:41.723",
        "lastModified": "2026-08-04T14:29:06.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17784",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Audio component retains and dereferences an object after it has been freed while handling compromised-renderer input.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513694032",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17785",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:45.343Z",
      "date_published": "2026-07-30T00:19:20.535Z",
      "date_updated": "2026-07-30T14:55:41.513Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14569
      },
      "nvd": {
        "published": "2026-07-30T01:16:41.840",
        "lastModified": "2026-08-04T14:28:54.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17785",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome reads memory before initializing it, allowing stale process data or an invalid value to influence execution.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513769898",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17786",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:45.567Z",
      "date_published": "2026-07-30T00:19:20.804Z",
      "date_updated": "2026-07-31T03:55:37.052Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11745
      },
      "nvd": {
        "published": "2026-07-30T01:16:41.950",
        "lastModified": "2026-08-04T14:28:44.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17786",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says DevTools insufficiently validates extension input before privilege escalation but does not identify the failing boundary or check.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513770449",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 269,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17787",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:45.773Z",
      "date_published": "2026-07-30T00:19:21.068Z",
      "date_updated": "2026-08-03T16:10:58.009Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08373
      },
      "nvd": {
        "published": "2026-07-30T01:16:42.057",
        "lastModified": "2026-08-04T14:28:29.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17787",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Chrome DevTools accepts a crafted page interaction that crosses the same-origin request boundary.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513783632",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17788",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:46.021Z",
      "date_published": "2026-07-30T00:19:21.332Z",
      "date_updated": "2026-07-30T14:56:15.671Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Blink in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04368
      },
      "nvd": {
        "published": "2026-07-30T01:16:42.160",
        "lastModified": "2026-08-04T14:28:20.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17788",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Blink allows data to cross an origin boundary, but the public record does not identify the origin comparison or response path that fails.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513824957",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17789",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:46.230Z",
      "date_published": "2026-07-30T00:19:21.595Z",
      "date_updated": "2026-07-31T21:39:42.020Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11993
      },
      "nvd": {
        "published": "2026-07-30T01:16:42.257",
        "lastModified": "2026-08-04T16:09:15.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17789",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS accepts malicious network input that bypasses its navigation restrictions, while the rejected field and comparison are not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513855922",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17790",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:46.447Z",
      "date_published": "2026-07-30T00:19:21.886Z",
      "date_updated": "2026-07-30T15:35:29.897Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.1832
      },
      "nvd": {
        "published": "2026-07-30T01:16:42.367",
        "lastModified": "2026-08-03T15:01:18.627",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17790",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513919931",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17791",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:46.658Z",
      "date_published": "2026-07-30T00:19:22.184Z",
      "date_updated": "2026-07-31T21:39:38.615Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14375
      },
      "nvd": {
        "published": "2026-07-30T01:16:42.477",
        "lastModified": "2026-08-04T16:09:08.143",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17791",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Payments component insufficiently validates renderer-controlled input used in security UI, but the public record does not identify the field or check.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514006959",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17792",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:46.901Z",
      "date_published": "2026-07-30T00:19:22.447Z",
      "date_updated": "2026-07-31T17:47:24.297Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Credential Management in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14375
      },
      "nvd": {
        "published": "2026-07-30T01:16:42.587",
        "lastModified": "2026-08-04T14:27:29.167",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17792",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The browser or server accepts an attacker-controlled origin, navigation or presentation boundary without the required trust validation.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514019823",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:47.126Z",
      "date_published": "2026-07-30T00:19:22.718Z",
      "date_updated": "2026-07-31T16:12:54.158Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Messages in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18186
      },
      "nvd": {
        "published": "2026-07-30T01:16:42.683",
        "lastModified": "2026-08-03T13:44:26.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17793",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's Android Messages component lets crafted page content present a misleading trusted UI, but the public record does not identify the origin or navigation state that is misrepresented.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514063859",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17794",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:47.364Z",
      "date_published": "2026-07-30T00:19:22.992Z",
      "date_updated": "2026-07-31T16:09:58.420Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13965
      },
      "nvd": {
        "published": "2026-07-30T01:16:42.783",
        "lastModified": "2026-08-03T13:44:12.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17794",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Google identifies insufficient validation in Android Mobile and Omnibox spoofing but does not disclose the validated field or UI state rule.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514067070",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17795",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:47.583Z",
      "date_published": "2026-07-30T00:19:23.272Z",
      "date_updated": "2026-07-30T14:57:28.686Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in GetUserMedia in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12051
      },
      "nvd": {
        "published": "2026-07-30T01:16:42.893",
        "lastModified": "2026-08-04T16:08:58.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17795",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A compromised renderer can cross the GetUserMedia origin boundary and read another origin's data, but the failed origin check is not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514242889",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17796",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:47.825Z",
      "date_published": "2026-07-30T00:19:23.529Z",
      "date_updated": "2026-07-30T15:35:15.205Z",
      "publisher": "Chrome",
      "title": "Side-channel information leakage in WebXR in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22205
      },
      "nvd": {
        "published": "2026-07-30T01:16:43.003",
        "lastModified": "2026-08-03T17:55:56.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17796",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebXR-observable microarchitectural state forms a side channel that exposes process memory.",
        "basis": [
          "CNA",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514427844",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17797",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:48.083Z",
      "date_published": "2026-07-30T00:19:23.799Z",
      "date_updated": "2026-07-31T14:08:24.624Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08188
      },
      "nvd": {
        "published": "2026-07-30T01:16:43.107",
        "lastModified": "2026-08-04T16:08:47.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17797",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted CSS path permits attacker-controlled script or HTML to execute across the browser's intended page boundary.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514441966",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17798",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:48.293Z",
      "date_published": "2026-07-30T00:19:24.086Z",
      "date_updated": "2026-07-30T14:57:54.010Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Cast in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04368
      },
      "nvd": {
        "published": "2026-07-30T01:16:43.210",
        "lastModified": "2026-08-04T16:08:39.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17798",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Cast can leak cross-origin data through an inappropriate implementation whose missing sender, origin, or receiver binding is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514460133",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:48.555Z",
      "date_published": "2026-07-30T00:19:24.360Z",
      "date_updated": "2026-07-31T14:07:45.670Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.0976
      },
      "nvd": {
        "published": "2026-07-30T01:16:43.307",
        "lastModified": "2026-08-03T17:55:43.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17799",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Safe Browsing accepts a malicious file that bypasses its discretionary access-control decision, but the missing validation rule is not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514461031",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:48.772Z",
      "date_published": "2026-07-30T00:19:25.040Z",
      "date_updated": "2026-07-30T15:36:03.889Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in MediaRecording in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22205
      },
      "nvd": {
        "published": "2026-07-30T01:16:43.417",
        "lastModified": "2026-08-03T17:55:36.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17800",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The MediaRecording record reports disclosure of process memory but its physical-side-channel CWE does not identify a defensible allocation, initialization, bound, or channel failure.",
        "basis": [
          "CNA",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514480948",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:48.990Z",
      "date_published": "2026-07-30T00:19:25.308Z",
      "date_updated": "2026-07-31T15:22:06.228Z",
      "publisher": "Chrome",
      "title": "Out of bounds read and write in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24003
      },
      "nvd": {
        "published": "2026-07-30T01:16:43.523",
        "lastModified": "2026-08-03T17:55:27.883",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17801",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the end of an allocated buffer because the available length is not enforced.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514482938",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:49.219Z",
      "date_published": "2026-07-30T00:19:25.581Z",
      "date_updated": "2026-07-30T14:58:23.357Z",
      "publisher": "Chrome",
      "title": "Side-channel information leakage in GPU in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07559
      },
      "nvd": {
        "published": "2026-07-30T01:16:43.633",
        "lastModified": "2026-08-04T16:08:26.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17802",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The GPU path exposes cross-origin information through a side-channel signal available to a crafted page.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514512198",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17803",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:49.432Z",
      "date_published": "2026-07-30T00:19:25.874Z",
      "date_updated": "2026-07-31T15:20:23.002Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21444
      },
      "nvd": {
        "published": "2026-07-30T01:16:43.737",
        "lastModified": "2026-08-03T17:55:04.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17803",
        "family": "AUTHORITY_BINDING",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "SaveToDriveFlow previously obtained the document title only after account choice and did not show it in that chooser; the fix captures and displays one title before consent and reuses it for the upload.",
        "basis": [
          "CNA",
          "CWE-20",
          "Chrome release",
          "Chromium source commit acfd83c6"
        ],
        "deepDive": true,
        "notes": "Inspected the linked Chrome release URL https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html, the access-restricted issue https://issues.chromium.org/issues/515438919, and Chromium source commit https://chromium.googlesource.com/chromium/src/+/acfd83c6a15d997d3f907028014eb5251169eefe. The public source fix captures the document title before account selection, displays it in the chooser, and reuses that stored title for upload, binding consent to one file identity; the issue body remains restricted and the release page returned HTTP 429 during review, so any additional exploit steps remain outside the public boundary."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/515438919",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:49.654Z",
      "date_published": "2026-07-30T00:19:26.159Z",
      "date_updated": "2026-07-31T14:00:20.249Z",
      "publisher": "Chrome",
      "title": "Use after free in Media in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24003
      },
      "nvd": {
        "published": "2026-07-30T01:16:43.847",
        "lastModified": "2026-08-03T17:54:54.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17804",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A memory-safety defect permits access beyond the bounds or lifetime of a valid object.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/515448947",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17805",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:49.874Z",
      "date_published": "2026-07-30T00:19:26.417Z",
      "date_updated": "2026-07-31T13:58:25.590Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Glic in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13294
      },
      "nvd": {
        "published": "2026-07-30T01:16:43.950",
        "lastModified": "2026-08-03T13:44:31.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17805",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for Android Glic navigation policy accepts a crafted transition that escapes navigation restrictions, while the exact check is not public.",
        "basis": [
          "CNA",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516420806",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 212,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:50.112Z",
      "date_published": "2026-07-30T00:19:26.666Z",
      "date_updated": "2026-07-31T14:05:41.875Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05465
      },
      "nvd": {
        "published": "2026-07-30T01:16:44.053",
        "lastModified": "2026-08-03T17:53:44.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17806",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Chrome reports insufficient Extensions input validation but does not identify the field, parser rule, or invalid state that causes the impact.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516433058",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:50.351Z",
      "date_published": "2026-07-30T00:19:26.925Z",
      "date_updated": "2026-07-31T03:55:52.251Z",
      "publisher": "Chrome",
      "title": "Use after free in V8 in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22586
      },
      "nvd": {
        "published": "2026-07-30T01:16:44.157",
        "lastModified": "2026-08-03T17:53:06.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17807",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Chrome, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516763884",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17808",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:50.581Z",
      "date_published": "2026-07-30T00:19:27.188Z",
      "date_updated": "2026-07-30T13:32:54.930Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in WebGL in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.1832
      },
      "nvd": {
        "published": "2026-07-30T01:16:44.273",
        "lastModified": "2026-08-03T17:52:57.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17808",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome WebGL exposes bytes from memory that was used before initialization.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516778390",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17809",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:50.800Z",
      "date_published": "2026-07-30T00:19:27.446Z",
      "date_updated": "2026-07-31T14:05:14.090Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05464
      },
      "nvd": {
        "published": "2026-07-30T01:16:44.380",
        "lastModified": "2026-08-03T17:52:38.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17809",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Chrome Extensions accepts renderer-controlled input at a sandbox boundary, but the public record does not reveal whether the enabling failure is parsing, authority, memory, or channel validation.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": "The public record does not expose enough implementation detail to classify the enabling cause."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516813317",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17810",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:51.036Z",
      "date_published": "2026-07-30T00:19:27.718Z",
      "date_updated": "2026-07-30T13:32:55.084Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in Dawn in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.1832
      },
      "nvd": {
        "published": "2026-07-30T01:16:44.493",
        "lastModified": "2026-08-03T17:52:32.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17810",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome consumes memory or an object field before the value has been initialized for that path.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516882109",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17811",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:54.735Z",
      "date_published": "2026-07-30T00:19:28.146Z",
      "date_updated": "2026-07-31T14:04:45.270Z",
      "publisher": "Chrome",
      "title": "Use after free in ANGLE in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06522
      },
      "nvd": {
        "published": "2026-07-30T01:16:44.603",
        "lastModified": "2026-08-03T15:00:48.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17811",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A reachable path retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516954622",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:55.164Z",
      "date_published": "2026-07-30T00:19:28.405Z",
      "date_updated": "2026-07-31T14:04:20.218Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in DigitalCredentials in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09817
      },
      "nvd": {
        "published": "2026-07-30T01:16:44.730",
        "lastModified": "2026-08-03T17:52:26.403",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17812",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome DigitalCredentials can present security-critical UI in a spoofable form, but the public record does not identify the misrepresented element or state.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517101596",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17813",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:55.485Z",
      "date_published": "2026-07-30T00:19:28.682Z",
      "date_updated": "2026-07-31T13:55:33.540Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13294
      },
      "nvd": {
        "published": "2026-07-30T01:16:44.833",
        "lastModified": "2026-08-03T17:52:20.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17813",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS permits a navigation outside the intended restriction, but the public record does not identify the failing URL or origin policy check.",
        "basis": [
          "CNA",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517184957",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17814",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:55.759Z",
      "date_published": "2026-07-30T00:19:28.956Z",
      "date_updated": "2026-07-31T13:56:48.384Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19398
      },
      "nvd": {
        "published": "2026-07-30T01:16:44.937",
        "lastModified": "2026-08-03T17:52:12.013",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17814",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS accepts crafted navigation input that escapes the intended destination restrictions, but the missing validation rule is not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517312048",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17815",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:56.035Z",
      "date_published": "2026-07-30T00:19:29.251Z",
      "date_updated": "2026-07-30T17:47:04.118Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in GuestView in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10156
      },
      "nvd": {
        "published": "2026-07-30T01:16:45.043",
        "lastModified": "2026-08-03T17:52:02.890",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17815",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "GuestView does not consistently enforce the intended origin policy and can expose data from another origin, although the failing rule is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517427352",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17816",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:56.290Z",
      "date_published": "2026-07-30T00:19:29.512Z",
      "date_updated": "2026-07-31T03:55:36.353Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18766
      },
      "nvd": {
        "published": "2026-07-30T01:16:45.153",
        "lastModified": "2026-08-03T17:42:14.293",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17816",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Speech component fails to enforce a privilege policy against a compromised renderer, but the exact checked operation is not public.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517429672",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17817",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:56.540Z",
      "date_published": "2026-07-30T00:19:29.781Z",
      "date_updated": "2026-07-30T17:47:51.916Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in ReportingAndNEL in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.0602
      },
      "nvd": {
        "published": "2026-07-30T01:16:45.257",
        "lastModified": "2026-08-03T17:42:01.053",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17817",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ReportingAndNEL can return cross-origin data to a crafted page, but the exact origin-validation failure is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517461759",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17818",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:56.770Z",
      "date_published": "2026-07-30T00:19:30.072Z",
      "date_updated": "2026-07-31T13:43:37.109Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Network in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.0679
      },
      "nvd": {
        "published": "2026-07-30T01:16:45.363",
        "lastModified": "2026-08-03T17:41:53.370",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17818",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Chrome, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517466133",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17819",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:57.004Z",
      "date_published": "2026-07-30T00:19:30.337Z",
      "date_updated": "2026-07-31T15:38:00.442Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in WebAppInstalls in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12389
      },
      "nvd": {
        "published": "2026-07-30T01:16:45.460",
        "lastModified": "2026-08-03T17:41:45.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17819",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome accepts a specifically malformed value or unsupported operation without the validation required by that interface, driving the component into an unsafe condition outside the other mechanism families.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517487028",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17820",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:57.213Z",
      "date_published": "2026-07-30T00:19:30.613Z",
      "date_updated": "2026-07-30T17:46:33.154Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Autofill in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10156
      },
      "nvd": {
        "published": "2026-07-30T01:16:45.567",
        "lastModified": "2026-08-03T17:41:30.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17820",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Autofill enforces cross-origin policy against an incomplete or wrong request context, while the exact comparison and data path are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517493101",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:57.433Z",
      "date_published": "2026-07-30T00:19:30.912Z",
      "date_updated": "2026-07-31T15:32:21.472Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06811
      },
      "nvd": {
        "published": "2026-07-30T01:16:45.663",
        "lastModified": "2026-08-03T17:41:21.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17821",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in Chrome, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517597914",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17822",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:57.648Z",
      "date_published": "2026-07-30T00:19:31.180Z",
      "date_updated": "2026-07-31T15:30:48.003Z",
      "publisher": "Chrome",
      "title": "Race in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07102
      },
      "nvd": {
        "published": "2026-07-30T01:16:45.767",
        "lastModified": "2026-08-03T17:41:14.037",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17822",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A race in Chrome for iOS lets page and browser UI state diverge long enough to present spoofed interface content.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517621178",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17823",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:57.904Z",
      "date_published": "2026-07-30T00:19:31.449Z",
      "date_updated": "2026-07-31T15:28:24.098Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in WebXR in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07524
      },
      "nvd": {
        "published": "2026-07-30T01:16:45.857",
        "lastModified": "2026-08-03T17:40:52.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17823",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Chrome WebXR fails to enforce the same-origin policy for a crafted page request.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517628043",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17824",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:58.150Z",
      "date_published": "2026-07-30T00:19:31.723Z",
      "date_updated": "2026-07-31T15:26:23.215Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.1475
      },
      "nvd": {
        "published": "2026-07-30T01:16:45.960",
        "lastModified": "2026-08-03T17:40:42.617",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17824",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ServiceWorker permits a same-origin-policy bypass, but the public record does not identify the URL, origin, or policy comparison that fails.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517655543",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17825",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:58.396Z",
      "date_published": "2026-07-30T00:19:31.993Z",
      "date_updated": "2026-07-31T15:24:25.836Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Passwords in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12184
      },
      "nvd": {
        "published": "2026-07-30T01:16:46.057",
        "lastModified": "2026-08-03T13:44:06.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17825",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Insufficient policy enforcement in Passwords in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517675979",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17826",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:58.650Z",
      "date_published": "2026-07-30T00:19:32.277Z",
      "date_updated": "2026-07-30T17:46:00.946Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.0702
      },
      "nvd": {
        "published": "2026-07-30T01:16:46.157",
        "lastModified": "2026-08-03T15:04:08.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17826",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517690521",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17827",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:58.880Z",
      "date_published": "2026-07-30T00:19:32.541Z",
      "date_updated": "2026-07-31T15:45:20.202Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06789
      },
      "nvd": {
        "published": "2026-07-30T01:16:46.267",
        "lastModified": "2026-08-03T17:40:36.533",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17827",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517693726",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17828",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:59.108Z",
      "date_published": "2026-07-30T00:19:32.811Z",
      "date_updated": "2026-07-31T16:08:31.595Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12389
      },
      "nvd": {
        "published": "2026-07-30T01:16:46.367",
        "lastModified": "2026-08-03T17:40:22.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17828",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The browser or server accepts an attacker-controlled origin, navigation or presentation boundary without the required trust validation.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517702279",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17829",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:59.338Z",
      "date_published": "2026-07-30T00:19:33.077Z",
      "date_updated": "2026-07-30T17:45:28.312Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10156
      },
      "nvd": {
        "published": "2026-07-30T01:16:46.470",
        "lastModified": "2026-08-03T17:40:13.123",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17829",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Passwords component applies an incomplete origin policy and can disclose cross-origin data, but the public record does not identify the missing origin binding.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517705103",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17830",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:59.538Z",
      "date_published": "2026-07-30T00:19:33.365Z",
      "date_updated": "2026-07-31T16:03:06.198Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17917
      },
      "nvd": {
        "published": "2026-07-30T01:16:46.567",
        "lastModified": "2026-08-03T17:39:50.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17830",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS permits a navigation restriction bypass, but the public record does not identify the policy decision or state involved.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517710397",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17831",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:59.740Z",
      "date_published": "2026-07-30T00:19:33.653Z",
      "date_updated": "2026-07-31T16:00:01.791Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18186
      },
      "nvd": {
        "published": "2026-07-30T01:16:46.667",
        "lastModified": "2026-08-03T19:06:45.913",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17831",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says Passwords input validation permits UI spoofing but does not identify the trusted display state or validation rule.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517714728",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 247,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17832",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:34:59.976Z",
      "date_published": "2026-07-30T00:19:33.921Z",
      "date_updated": "2026-07-31T15:57:47.774Z",
      "publisher": "Chrome",
      "title": "Use after free in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16717
      },
      "nvd": {
        "published": "2026-07-30T01:16:46.777",
        "lastModified": "2026-08-03T19:06:31.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17832",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517723319",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17833",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:00.214Z",
      "date_published": "2026-07-30T00:19:34.201Z",
      "date_updated": "2026-07-30T17:44:59.502Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06021
      },
      "nvd": {
        "published": "2026-07-30T01:16:46.887",
        "lastModified": "2026-08-03T17:39:39.193",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17833",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Password handling fails to preserve an origin boundary, but the public record does not identify the affected value or validation rule.",
        "basis": [
          "CNA record",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517779123",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17834",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:00.504Z",
      "date_published": "2026-07-30T00:19:34.468Z",
      "date_updated": "2026-07-31T15:55:23.565Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16717
      },
      "nvd": {
        "published": "2026-07-30T01:16:46.987",
        "lastModified": "2026-08-03T19:06:14.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17834",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Chrome Passwords record reports generic input validation leading from a compromised renderer to sandbox escape but does not disclose the input, check, or privileged transition.",
        "basis": [
          "CNA",
          "CWE-20",
          "https://chromereleases.googleblog.com/2026/07/"
        ],
        "deepDive": true,
        "notes": "Google's Chrome 151 release page labels this only as an inappropriate implementation in Passwords at https://chromereleases.googleblog.com/2026/07/; the linked Chromium issue https://issues.chromium.org/issues/517793801 did not expose public issue content, so the input, check, and sandbox transition remain unknown."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517793801",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 264,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17835",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:00.761Z",
      "date_published": "2026-07-30T00:19:34.734Z",
      "date_updated": "2026-07-31T15:46:18.064Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12389
      },
      "nvd": {
        "published": "2026-07-30T01:16:47.093",
        "lastModified": "2026-08-03T19:05:58.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17835",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS lets crafted content present spoofed browser UI, but the erroneous display-state rule is not public.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517801739",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17836",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:00.992Z",
      "date_published": "2026-07-30T00:19:35.003Z",
      "date_updated": "2026-07-31T03:55:51.512Z",
      "publisher": "Chrome",
      "title": "Use after free in V8 in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22586
      },
      "nvd": {
        "published": "2026-07-30T01:16:47.190",
        "lastModified": "2026-08-03T17:39:33.960",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17836",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Chrome, a path retains or reuses an object after the lifetime transition that frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517972812",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17837",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:01.212Z",
      "date_published": "2026-07-30T00:19:35.260Z",
      "date_updated": "2026-07-31T15:43:24.492Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16718
      },
      "nvd": {
        "published": "2026-07-30T01:16:47.310",
        "lastModified": "2026-08-03T19:05:41.753",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17837",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record reports a DevTools input-validation flaw leading to sandbox escape but does not identify the accepted input or failing validation rule.",
        "basis": [
          "CNA record",
          "NVD",
          "Chrome release note"
        ],
        "deepDive": true,
        "notes": "Inspected Google Chrome release note https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html and checked linked issue https://issues.chromium.org/issues/517978932; the release repeats only insufficient DevTools input validation and the issue requires sign-in, leaving the accepted input and failing validation rule undisclosed."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517978932",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17838",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:01.422Z",
      "date_published": "2026-07-30T00:19:35.522Z",
      "date_updated": "2026-07-31T15:39:20.185Z",
      "publisher": "Chrome",
      "title": "Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12389
      },
      "nvd": {
        "published": "2026-07-30T01:16:47.417",
        "lastModified": "2026-08-03T19:05:16.560",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17838",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS presents incorrect security UI that allows domain spoofing, but the public record does not identify the misrepresented element or state.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518075952",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17839",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:01.646Z",
      "date_published": "2026-07-30T00:19:35.791Z",
      "date_updated": "2026-07-31T15:44:19.293Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12388
      },
      "nvd": {
        "published": "2026-07-30T01:16:47.520",
        "lastModified": "2026-08-03T19:04:56.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17839",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS can present attacker-controlled page state as trusted browser UI, but the public record does not identify the misrepresented indicator or state transition.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518080978",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17840",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:01.862Z",
      "date_published": "2026-07-30T00:19:36.084Z",
      "date_updated": "2026-07-31T15:43:05.730Z",
      "publisher": "Chrome",
      "title": "Incorrect security UI in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14962
      },
      "nvd": {
        "published": "2026-07-30T01:16:47.617",
        "lastModified": "2026-08-03T19:04:34.273",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17840",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The password-security user interface displays incorrect trust information that can misrepresent the active domain.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518082162",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17841",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:02.077Z",
      "date_published": "2026-07-30T00:19:36.362Z",
      "date_updated": "2026-08-03T19:39:57.508Z",
      "publisher": "Chrome",
      "title": "Race in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07101
      },
      "nvd": {
        "published": "2026-07-30T01:16:47.723",
        "lastModified": "2026-08-03T20:17:14.040",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17841",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The public record identifies a race in Chrome for iOS that permits UI spoofing but does not disclose the competing state transitions.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518088219",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17842",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:02.280Z",
      "date_published": "2026-07-30T00:19:36.624Z",
      "date_updated": "2026-07-31T15:40:38.393Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09346
      },
      "nvd": {
        "published": "2026-07-30T01:16:47.837",
        "lastModified": "2026-08-03T19:02:53.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17842",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome on iOS permits a crafted page to bypass the same-origin boundary, but the public record does not identify the origin comparison that fails.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518089997",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17843",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:02.496Z",
      "date_published": "2026-07-30T00:19:36.890Z",
      "date_updated": "2026-07-30T17:44:25.324Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07073
      },
      "nvd": {
        "published": "2026-07-30T01:16:47.940",
        "lastModified": "2026-08-03T17:39:28.147",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17843",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Chrome accepts a request across an unintended network or origin boundary, while the request field and validation step are not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518103887",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17844",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:02.761Z",
      "date_published": "2026-07-30T00:19:37.165Z",
      "date_updated": "2026-07-30T17:59:32.781Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01919
      },
      "nvd": {
        "published": "2026-07-30T01:16:48.047",
        "lastModified": "2026-08-03T17:39:21.217",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17844",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chrome Cast trusts a network or cross-origin input that should not cross the channel boundary, but the accepted field is not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518111542",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17845",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:03.014Z",
      "date_published": "2026-07-30T00:19:37.438Z",
      "date_updated": "2026-07-31T15:39:32.552Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.0802
      },
      "nvd": {
        "published": "2026-07-30T01:16:48.150",
        "lastModified": "2026-08-03T19:41:15.257",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17845",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518112775",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17846",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:03.301Z",
      "date_published": "2026-07-30T00:19:37.695Z",
      "date_updated": "2026-07-31T18:10:49.494Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Media in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09347
      },
      "nvd": {
        "published": "2026-07-30T01:16:48.247",
        "lastModified": "2026-08-03T19:41:09.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17846",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome permits a crafted page to cross a same-origin boundary in Media, while the public record does not identify the origin comparison that fails.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518121320",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17847",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:03.527Z",
      "date_published": "2026-07-30T00:19:37.958Z",
      "date_updated": "2026-07-31T18:16:00.774Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19739
      },
      "nvd": {
        "published": "2026-07-30T01:16:48.350",
        "lastModified": "2026-08-03T19:41:00.987",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17847",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Chrome reports that ANGLE accepts untrusted input leading to sandbox escape but does not disclose the input, parser, bound, object, or failed validation rule.",
        "basis": [
          "CNA",
          "CWE-20",
          "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "https://issues.chromium.org/issues/518243653"
        ],
        "deepDive": true,
        "notes": "The official release endpoint returned a rate-limit response and the linked Chromium issue was not publicly readable during review; no failing ANGLE validation rule was exposed."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518243653",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17848",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:03.751Z",
      "date_published": "2026-07-30T00:19:38.235Z",
      "date_updated": "2026-07-31T18:17:22.301Z",
      "publisher": "Chrome",
      "title": "Integer overflow in Codecs in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16967
      },
      "nvd": {
        "published": "2026-07-30T01:16:48.453",
        "lastModified": "2026-08-03T19:40:56.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17848",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Codecs component performs integer arithmetic that can overflow while processing a crafted video, enabling an invalid memory state.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518284253",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17849",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:03.968Z",
      "date_published": "2026-07-30T00:19:38.520Z",
      "date_updated": "2026-07-31T18:19:25.977Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13386
      },
      "nvd": {
        "published": "2026-07-30T01:16:48.567",
        "lastModified": "2026-07-31T21:21:16.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17849",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS can display an omnibox identity inconsistent with network navigation state, while the exact binding failure is not public.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518812672",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17850",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:04.186Z",
      "date_published": "2026-07-30T00:19:38.800Z",
      "date_updated": "2026-07-31T18:21:03.053Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Permissions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14891
      },
      "nvd": {
        "published": "2026-07-30T01:16:48.667",
        "lastModified": "2026-08-03T19:40:48.533",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17850",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Permissions component enforces the same-origin policy against the wrong or incomplete request context, but the exact comparison is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519078527",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17851",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:04.391Z",
      "date_published": "2026-07-30T00:19:39.067Z",
      "date_updated": "2026-07-30T13:32:55.242Z",
      "publisher": "Chrome",
      "title": "Side-channel information leakage in Autofill in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17485
      },
      "nvd": {
        "published": "2026-07-30T01:16:48.770",
        "lastModified": "2026-08-03T17:39:13.853",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17851",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Autofill exposes cross-origin data through a side channel observable from a compromised renderer, although the observable signal is not public.",
        "basis": [
          "CNA",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519243927",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17852",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:04.591Z",
      "date_published": "2026-07-30T00:19:39.336Z",
      "date_updated": "2026-07-31T18:22:27.671Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Media Router in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14891
      },
      "nvd": {
        "published": "2026-07-30T01:16:48.873",
        "lastModified": "2026-08-03T19:40:43.853",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17852",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Media Router accepts a request or response across an origin boundary that the same-origin policy should reject.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519348818",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17853",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:04.819Z",
      "date_published": "2026-07-30T00:19:39.598Z",
      "date_updated": "2026-07-31T18:14:50.647Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07215
      },
      "nvd": {
        "published": "2026-07-30T01:16:48.980",
        "lastModified": "2026-08-03T19:40:38.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17853",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DevTools permits renderer-controlled content to become script or HTML in a privileged page.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519472272",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17854",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:05.016Z",
      "date_published": "2026-07-30T00:19:39.876Z",
      "date_updated": "2026-07-31T18:44:35.289Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in WebMCP in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09346
      },
      "nvd": {
        "published": "2026-07-30T01:16:49.110",
        "lastModified": "2026-08-03T19:40:34.777",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17854",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "WebMCP fails to enforce the browser's same-origin policy for a crafted page, allowing a foreign origin to cross the protected request boundary.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519500882",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17855",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:05.232Z",
      "date_published": "2026-07-30T00:19:40.161Z",
      "date_updated": "2026-07-31T18:43:11.860Z",
      "publisher": "Chrome",
      "title": "Race in DevTools in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.126
      },
      "nvd": {
        "published": "2026-07-30T01:16:49.230",
        "lastModified": "2026-08-03T19:40:29.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17855",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome DevTools accesses shared state concurrently without the synchronization needed to keep the state transition atomic and consistent.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362",
          "Chrome release advisory"
        ],
        "deepDive": true,
        "notes": "Inspected the Chrome release at https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html and checked the linked issue https://issues.chromium.org/issues/519982572; the release provides only \"Race in DevTools,\" while the issue is permission-gated and no shared object, lock, or interleaving is public."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519982572",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17856",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:05.454Z",
      "date_published": "2026-07-30T00:19:40.438Z",
      "date_updated": "2026-07-31T18:42:06.944Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Network in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.1974
      },
      "nvd": {
        "published": "2026-07-30T01:16:49.353",
        "lastModified": "2026-08-03T19:39:35.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17856",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record reports an inappropriate Network implementation leading to sandbox escape but discloses no causal check, state, parser, or memory operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-693",
          "Official-link access check"
        ],
        "deepDive": true,
        "notes": "Inspected both linked Chromium primary sources: the Chrome release page reached Google's traffic-verification challenge and https://issues.chromium.org/issues/519991751 requires sign-in, so no external technical content was available and the cause remains undetermined."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519991751",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17857",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:05.677Z",
      "date_published": "2026-07-30T00:19:40.706Z",
      "date_updated": "2026-07-30T14:58:58.208Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Network in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07072
      },
      "nvd": {
        "published": "2026-07-30T01:16:49.450",
        "lastModified": "2026-08-03T17:39:07.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17857",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chrome treats a request or response as same-origin without validating the authoritative origin identity.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520186620",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17858",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:05.877Z",
      "date_published": "2026-07-30T00:19:41.005Z",
      "date_updated": "2026-07-30T14:59:26.255Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in WebNN in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14297
      },
      "nvd": {
        "published": "2026-07-30T01:16:49.553",
        "lastModified": "2026-08-03T17:39:02.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17858",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebNN reads an uninitialized value and exposes cross-origin data to crafted web content.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520191468",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17859",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:06.081Z",
      "date_published": "2026-07-30T00:19:41.273Z",
      "date_updated": "2026-07-30T14:59:50.358Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Favicons in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17486
      },
      "nvd": {
        "published": "2026-07-30T01:16:49.663",
        "lastModified": "2026-08-03T17:38:54.873",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17859",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Chrome Favicons exposes a cross-origin observation channel that reveals data to a remote page.",
        "basis": [
          "CNA",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520196753",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17860",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:06.303Z",
      "date_published": "2026-07-30T00:19:41.560Z",
      "date_updated": "2026-07-31T18:39:23.754Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00094,
        "percentile": 0.0074
      },
      "nvd": {
        "published": "2026-07-30T01:16:49.777",
        "lastModified": "2026-08-03T13:44:49.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17860",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Mobile permits Omnibox content spoofing after insufficient validation, but the public record does not disclose the accepted value or UI state rule.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520407381",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17861",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:06.509Z",
      "date_published": "2026-07-30T00:19:41.813Z",
      "date_updated": "2026-07-31T03:55:35.632Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01258
      },
      "nvd": {
        "published": "2026-07-30T01:16:49.903",
        "lastModified": "2026-08-03T17:38:50.093",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17861",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Updater accepts a malicious local file and can elevate privileges, while the public record does not identify the file property or unsafe operation.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520417861",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17862",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:06.730Z",
      "date_published": "2026-07-30T00:19:42.072Z",
      "date_updated": "2026-07-31T03:55:34.828Z",
      "publisher": "Chrome",
      "title": "Use after free in Tracing in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01567
      },
      "nvd": {
        "published": "2026-07-30T01:16:50.057",
        "lastModified": "2026-08-03T17:38:43.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17862",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520426287",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17863",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:06.938Z",
      "date_published": "2026-07-30T00:19:42.342Z",
      "date_updated": "2026-07-31T03:55:34.154Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01346
      },
      "nvd": {
        "published": "2026-07-30T01:16:50.190",
        "lastModified": "2026-08-03T17:38:34.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17863",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome on Windows lets a malicious local file cross a browser privilege boundary, but the public record does not identify the missing authorization check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520468718",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17864",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:07.141Z",
      "date_published": "2026-07-30T00:19:42.598Z",
      "date_updated": "2026-07-31T03:55:33.446Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00102,
        "percentile": 0.01084
      },
      "nvd": {
        "published": "2026-07-30T01:16:50.293",
        "lastModified": "2026-08-03T17:38:25.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17864",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The component assigns or permits a privilege beyond the authority granted to the invoking user.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520494861",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17865",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:07.356Z",
      "date_published": "2026-07-30T00:19:42.871Z",
      "date_updated": "2026-07-31T18:40:31.383Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19738
      },
      "nvd": {
        "published": "2026-07-30T01:16:50.400",
        "lastModified": "2026-08-03T17:43:47.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17865",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says only that an inappropriate Crypto implementation can enable a macOS sandbox escape after renderer compromise; the failing control is not public.",
        "basis": [
          "CNA",
          "CWE-693",
          "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "https://issues.chromium.org/issues/520516655"
        ],
        "deepDive": true,
        "notes": "The official release endpoint returned a rate-limit response and the linked Chromium issue was not publicly readable during review; neither exposed the failing Crypto control."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520516655",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17866",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:07.599Z",
      "date_published": "2026-07-30T00:19:43.133Z",
      "date_updated": "2026-07-30T19:32:10.288Z",
      "publisher": "Chrome",
      "title": "Type Confusion in Tab in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06815
      },
      "nvd": {
        "published": "2026-07-30T01:16:50.500",
        "lastModified": "2026-08-03T13:46:34.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17866",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome interprets a memory object through an incompatible type and then performs an invalid access.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520525732",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17867",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:07.866Z",
      "date_published": "2026-07-30T00:19:43.397Z",
      "date_updated": "2026-07-30T19:26:15.112Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07663
      },
      "nvd": {
        "published": "2026-07-30T01:16:50.610",
        "lastModified": "2026-08-03T17:43:31.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17867",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says Dawn input validation permits a sandbox escape but gives only the consequence and no defensible enabling mechanism.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520527496",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17868",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:08.088Z",
      "date_published": "2026-07-30T00:19:43.661Z",
      "date_updated": "2026-07-31T03:55:32.691Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in USB in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25778
      },
      "nvd": {
        "published": "2026-07-30T01:16:50.713",
        "lastModified": "2026-08-03T17:43:23.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17868",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "USB policy enforcement permits a privilege boundary crossing, but the public record does not disclose the failed policy decision.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520743499",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17869",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:08.293Z",
      "date_published": "2026-07-30T00:19:43.944Z",
      "date_updated": "2026-07-31T18:33:21.711Z",
      "publisher": "Chrome",
      "title": "Out of bounds read in WebXR in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17761
      },
      "nvd": {
        "published": "2026-07-30T01:16:50.817",
        "lastModified": "2026-08-03T17:43:17.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17869",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted WebXR content drives a read beyond the bounds of an allocated memory object.",
        "basis": [
          "CNA record",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521759269",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17870",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:08.541Z",
      "date_published": "2026-07-30T00:19:44.211Z",
      "date_updated": "2026-07-30T17:59:15.297Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01919
      },
      "nvd": {
        "published": "2026-07-30T01:16:50.920",
        "lastModified": "2026-08-03T17:43:08.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17870",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Cast accepts malicious local-network traffic that can expose cross-origin data, but the missing peer or origin validation is not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521784856",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17871",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:08.750Z",
      "date_published": "2026-07-30T00:19:44.468Z",
      "date_updated": "2026-07-30T16:08:08.561Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07073
      },
      "nvd": {
        "published": "2026-07-30T01:16:51.030",
        "lastModified": "2026-08-03T17:43:01.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17871",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Passwords component releases cross-origin data after crafted UI gestures, but the incorrect origin transition is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521938924",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17872",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:08.977Z",
      "date_published": "2026-07-30T00:19:44.744Z",
      "date_updated": "2026-07-30T19:23:06.465Z",
      "publisher": "Chrome",
      "title": "Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00066,
        "percentile": 0.00029
      },
      "nvd": {
        "published": "2026-07-30T01:16:51.123",
        "lastModified": "2026-08-03T13:46:37.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17872",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's WebAppInstalls path accepts cryptographic evidence that should fail verification, while the public record does not identify the signed object or verification rule.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521963740",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17873",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:09.196Z",
      "date_published": "2026-07-30T00:19:45.033Z",
      "date_updated": "2026-07-31T18:32:12.469Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.1475
      },
      "nvd": {
        "published": "2026-07-30T01:16:51.223",
        "lastModified": "2026-08-03T17:42:55.153",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17873",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS fails to enforce an access-control policy for crafted content, but the public record does not identify the protected action or predicate.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522074033",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17874",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:09.409Z",
      "date_published": "2026-07-30T00:19:45.320Z",
      "date_updated": "2026-07-30T19:19:29.040Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11361
      },
      "nvd": {
        "published": "2026-07-30T01:16:51.330",
        "lastModified": "2026-08-03T19:06:06.763",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17874",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS misrepresents security-relevant UI state, but the exact display element and implementation error are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522074154",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17875",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:09.615Z",
      "date_published": "2026-07-30T00:19:45.587Z",
      "date_updated": "2026-07-31T03:55:50.762Z",
      "publisher": "Chrome",
      "title": "Use after free in PDFium in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22816
      },
      "nvd": {
        "published": "2026-07-30T01:16:51.423",
        "lastModified": "2026-08-03T18:26:21.707",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17875",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path retains or dereferences an object after its storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522299155",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17876",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:09.853Z",
      "date_published": "2026-07-30T00:19:45.880Z",
      "date_updated": "2026-07-30T16:08:01.103Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Payments in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07072
      },
      "nvd": {
        "published": "2026-07-30T01:16:51.540",
        "lastModified": "2026-08-03T18:26:14.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17876",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Payment data crosses an origin boundary, but the public record does not identify the origin or policy check that is missing.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522425471",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:10.065Z",
      "date_published": "2026-07-30T00:19:46.185Z",
      "date_updated": "2026-07-31T03:55:31.988Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00103,
        "percentile": 0.01149
      },
      "nvd": {
        "published": "2026-07-30T01:16:51.637",
        "lastModified": "2026-08-03T17:37:43.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17877",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record reports local privilege escalation in Chromoting but does not disclose which authorization, parser, memory, or state invariant fails.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522426086",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17878",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:10.282Z",
      "date_published": "2026-07-30T00:19:46.451Z",
      "date_updated": "2026-07-30T18:25:56.128Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07216
      },
      "nvd": {
        "published": "2026-07-30T01:16:51.743",
        "lastModified": "2026-08-03T17:37:34.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17878",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome CSS processing allows crafted web content to execute script across an origin boundary.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522781838",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17879",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:10.494Z",
      "date_published": "2026-07-30T00:19:46.715Z",
      "date_updated": "2026-07-30T15:03:03.033Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11742
      },
      "nvd": {
        "published": "2026-07-30T01:16:51.840",
        "lastModified": "2026-08-03T17:37:23.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17879",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Chrome accepts a request across an unintended network or origin boundary, while the request field and validation step are not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522878450",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17880",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:10.727Z",
      "date_published": "2026-07-30T00:19:46.992Z",
      "date_updated": "2026-07-30T16:08:11.441Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11742
      },
      "nvd": {
        "published": "2026-07-30T01:16:51.940",
        "lastModified": "2026-08-03T17:37:15.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17880",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Autofill releases cross-origin data, but the public record does not identify the origin decision or data path.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523229759",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17881",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:10.981Z",
      "date_published": "2026-07-30T00:19:47.253Z",
      "date_updated": "2026-07-31T03:55:50.034Z",
      "publisher": "Chrome",
      "title": "Integer overflow in WebXR in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34384
      },
      "nvd": {
        "published": "2026-07-30T01:16:52.043",
        "lastModified": "2026-08-03T17:37:06.617",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17881",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An integer calculation in WebXR can corrupt memory, while the supplied CWE labels the record as use-after-free and the public issue does not resolve that mismatch.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": "The description says integer overflow while the structured record says CWE-416 use-after-free; the family is stable, but the exact memory error is not."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523477987",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17882",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:11.185Z",
      "date_published": "2026-07-30T00:19:47.512Z",
      "date_updated": "2026-07-31T18:30:40.259Z",
      "publisher": "Chrome",
      "title": "Policy bypass in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08591
      },
      "nvd": {
        "published": "2026-07-30T01:16:52.140",
        "lastModified": "2026-08-03T17:36:58.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17882",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's Extensions implementation fails to enforce a security policy, while the public release does not identify the policy object, operation, or boundary.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523637452",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17883",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:11.394Z",
      "date_published": "2026-07-30T00:19:47.770Z",
      "date_updated": "2026-07-31T18:28:44.738Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Headless in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09347
      },
      "nvd": {
        "published": "2026-07-30T01:16:52.237",
        "lastModified": "2026-08-03T17:36:49.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17883",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The component accepts content without proving that its origin is the security principal the policy expects.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523639090",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17884",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:11.651Z",
      "date_published": "2026-07-30T00:19:48.039Z",
      "date_updated": "2026-07-31T03:56:11.642Z",
      "publisher": "Chrome",
      "title": "Object lifecycle issue in WebRTC in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.1974
      },
      "nvd": {
        "published": "2026-07-30T01:16:52.340",
        "lastModified": "2026-08-03T17:36:43.293",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17884",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523692228",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17885",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:11.933Z",
      "date_published": "2026-07-30T00:19:48.310Z",
      "date_updated": "2026-07-30T15:04:04.299Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Paint in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07073
      },
      "nvd": {
        "published": "2026-07-30T01:16:52.440",
        "lastModified": "2026-08-03T17:36:35.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17885",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Paint processing can expose cross-origin data, but the public record does not identify the origin-state check that fails.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523698038",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17886",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:12.207Z",
      "date_published": "2026-07-30T00:19:48.581Z",
      "date_updated": "2026-07-31T03:56:10.912Z",
      "publisher": "Chrome",
      "title": "Use after free in Enterprise in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.1974
      },
      "nvd": {
        "published": "2026-07-30T01:16:52.540",
        "lastModified": "2026-08-03T17:36:24.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17886",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Enterprise component retains and dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523715964",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17887",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:12.452Z",
      "date_published": "2026-07-30T00:19:48.873Z",
      "date_updated": "2026-07-31T16:09:57.111Z",
      "publisher": "Chrome",
      "title": "Use after free in TabStrip in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22715
      },
      "nvd": {
        "published": "2026-07-30T01:16:52.647",
        "lastModified": "2026-08-03T17:36:19.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17887",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TabStrip uses an object after it has been freed during crafted UI interaction, permitting access to stale heap storage.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523717010",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17888",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:12.671Z",
      "date_published": "2026-07-30T00:19:49.138Z",
      "date_updated": "2026-07-30T19:22:48.880Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.0529
      },
      "nvd": {
        "published": "2026-07-30T01:16:52.763",
        "lastModified": "2026-08-03T17:36:09.390",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17888",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record reports a WebUI sandbox escape after generic input validation failure but does not reveal the accepted data type or dangerous operation.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523720529",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17889",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:12.888Z",
      "date_published": "2026-07-30T00:19:49.403Z",
      "date_updated": "2026-07-30T15:04:32.806Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in WebXR in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14298
      },
      "nvd": {
        "published": "2026-07-30T01:16:52.877",
        "lastModified": "2026-08-03T17:36:05.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17889",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebXR exposes data derived from an uninitialized value to a crafted page.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523735357",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17890",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:13.090Z",
      "date_published": "2026-07-30T00:19:49.667Z",
      "date_updated": "2026-07-30T19:25:34.134Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06462
      },
      "nvd": {
        "published": "2026-07-30T01:16:52.990",
        "lastModified": "2026-08-03T17:36:01.007",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17890",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record says untrusted DevTools input can enable a sandbox escape, but it does not identify the parsed object, invalid value, or security transition.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/524029061",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17891",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:13.304Z",
      "date_published": "2026-07-30T00:19:49.929Z",
      "date_updated": "2026-07-30T19:24:58.689Z",
      "publisher": "Chrome",
      "title": "Use after free in ANGLE in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05396
      },
      "nvd": {
        "published": "2026-07-30T01:16:53.097",
        "lastModified": "2026-08-03T13:46:40.800",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17891",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome retains or reuses an object after its storage has been freed, allowing later processing to access invalid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/524639223",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17892",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:13.518Z",
      "date_published": "2026-07-30T00:19:50.190Z",
      "date_updated": "2026-07-30T15:36:32.326Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in WebXR in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.1795
      },
      "nvd": {
        "published": "2026-07-30T01:16:53.207",
        "lastModified": "2026-08-03T17:35:56.370",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17892",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebXR returns process-memory information to crafted content, although the public record does not identify the read or output boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/524822998",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17893",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:13.744Z",
      "date_published": "2026-07-30T00:19:50.531Z",
      "date_updated": "2026-07-30T18:23:38.906Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06462
      },
      "nvd": {
        "published": "2026-07-30T01:16:53.313",
        "lastModified": "2026-08-03T17:35:22.673",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17893",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record reports an Updater sandbox escape from insufficient input validation but does not identify the input, parser, or failing check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/524824730",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 269,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17894",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:13.962Z",
      "date_published": "2026-07-30T00:19:50.803Z",
      "date_updated": "2026-07-31T03:56:09.503Z",
      "publisher": "Chrome",
      "title": "Use after free in Views in Google Chrome on Linux prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15665
      },
      "nvd": {
        "published": "2026-07-30T01:16:53.423",
        "lastModified": "2026-08-04T15:37:54.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17894",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome Views can access an object after it has been freed while processing a crafted page.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/524825209",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17895",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:14.172Z",
      "date_published": "2026-07-30T00:19:51.081Z",
      "date_updated": "2026-07-30T15:05:00.085Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in DataTransfer in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07072
      },
      "nvd": {
        "published": "2026-07-30T01:16:53.533",
        "lastModified": "2026-08-03T17:35:13.413",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17895",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Chrome DataTransfer exposes cross-origin data during a user-mediated transfer gesture.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/524931675",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17896",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:14.385Z",
      "date_published": "2026-07-30T00:19:51.349Z",
      "date_updated": "2026-07-31T03:56:08.780Z",
      "publisher": "Chrome",
      "title": "Use after free in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28926
      },
      "nvd": {
        "published": "2026-07-30T01:16:53.633",
        "lastModified": "2026-08-03T17:35:01.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17896",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome DevTools uses an object after its storage has been freed while processing attacker-controlled content.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/525331547",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17897",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:14.592Z",
      "date_published": "2026-07-30T00:19:51.627Z",
      "date_updated": "2026-07-30T17:43:54.792Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in ORB in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07074
      },
      "nvd": {
        "published": "2026-07-30T01:16:53.743",
        "lastModified": "2026-08-03T17:34:56.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17897",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The ORB implementation permits a crafted page to receive data that should remain confined to another origin.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/527665262",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17898",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:14.821Z",
      "date_published": "2026-07-30T00:19:51.907Z",
      "date_updated": "2026-07-31T03:56:08.063Z",
      "publisher": "Chrome",
      "title": "Use after free in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.0938
      },
      "nvd": {
        "published": "2026-07-30T01:16:53.840",
        "lastModified": "2026-08-03T17:34:47.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17898",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/506193577",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17899",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:15.048Z",
      "date_published": "2026-07-30T00:19:52.178Z",
      "date_updated": "2026-07-31T03:55:31.315Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09183
      },
      "nvd": {
        "published": "2026-07-30T01:16:53.953",
        "lastModified": "2026-08-03T17:34:41.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17899",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "DevTools fails to enforce a security policy against a malicious extension, but the public record does not identify the policy or privileged operation.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/375959766",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:15.265Z",
      "date_published": "2026-07-30T00:19:52.459Z",
      "date_updated": "2026-07-30T17:43:12.766Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Enterprise in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00151,
        "percentile": 0.04804
      },
      "nvd": {
        "published": "2026-07-30T01:16:54.053",
        "lastModified": "2026-08-03T15:00:55.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17900",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The browser or server accepts an attacker-controlled origin, navigation or presentation boundary without the required trust validation.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/496195854",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17901",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:15.471Z",
      "date_published": "2026-07-30T00:19:52.743Z",
      "date_updated": "2026-07-31T18:26:53.529Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Sharing in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07895
      },
      "nvd": {
        "published": "2026-07-30T01:16:54.160",
        "lastModified": "2026-08-03T13:44:46.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17901",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Android Sharing component accepts network-controlled navigation input without enforcing an undisclosed navigation boundary.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/496271098",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17902",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:15.688Z",
      "date_published": "2026-07-30T00:19:53.040Z",
      "date_updated": "2026-07-30T13:58:49.582Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08949
      },
      "nvd": {
        "published": "2026-07-30T01:16:54.253",
        "lastModified": "2026-08-03T17:34:34.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17902",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Editing makes cross-origin data observable, but the public record does not identify the data flow or isolation guard.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/497251066",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17903",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:15.905Z",
      "date_published": "2026-07-30T00:19:53.333Z",
      "date_updated": "2026-07-30T18:24:45.017Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.0196
      },
      "nvd": {
        "published": "2026-07-30T01:16:54.353",
        "lastModified": "2026-08-03T17:34:29.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17903",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Malicious local-network content reaches a privileged Chromecast page as executable HTML or script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/497277880",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17904",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:35:16.128Z",
      "date_published": "2026-07-30T00:25:18.753Z",
      "date_updated": "2026-07-30T17:49:18.361Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in NFC in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06019
      },
      "nvd": {
        "published": "2026-07-30T01:16:54.450",
        "lastModified": "2026-08-03T13:47:30.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17904",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "NFC policy enforcement accepts data across an unintended origin boundary, but the exact origin rule is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/497337759",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17905",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:55.615Z",
      "date_published": "2026-07-30T00:25:21.389Z",
      "date_updated": "2026-07-30T17:56:16.673Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in SurfaceCapture in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.0602
      },
      "nvd": {
        "published": "2026-07-30T01:16:54.557",
        "lastModified": "2026-08-03T17:34:21.910",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17905",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "SurfaceCapture exposes cross-origin data because an origin boundary is implemented incorrectly, with the exact check not public.",
        "basis": [
          "CNA record",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/497366217",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17906",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:55.947Z",
      "date_published": "2026-07-30T00:25:21.859Z",
      "date_updated": "2026-07-30T18:25:18.921Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05464
      },
      "nvd": {
        "published": "2026-07-30T01:16:54.657",
        "lastModified": "2026-08-03T17:34:13.557",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17906",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Chrome Bluetooth record reports generic input validation leading from a compromised renderer to sandbox escape but does not disclose the input, check, or privileged transition.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/497654761",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 261,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17907",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:56.211Z",
      "date_published": "2026-07-30T00:25:22.311Z",
      "date_updated": "2026-07-30T13:32:55.406Z",
      "publisher": "Chrome",
      "title": "Side-channel information leakage in Network in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09262
      },
      "nvd": {
        "published": "2026-07-30T01:16:54.773",
        "lastModified": "2026-08-03T17:33:58.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17907",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network side channel lets crafted page activity infer data belonging to another origin.",
        "basis": [
          "CNA",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/497837927",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17908",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:56.471Z",
      "date_published": "2026-07-30T00:25:22.872Z",
      "date_updated": "2026-07-31T14:02:30.598Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05465
      },
      "nvd": {
        "published": "2026-07-30T01:16:54.890",
        "lastModified": "2026-08-03T15:00:44.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17908",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Printing record says untrusted input can lead from a compromised renderer to a sandbox escape but does not identify the parsed value, invalid state, or failing security boundary.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/499062890",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17909",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:56.688Z",
      "date_published": "2026-07-30T00:25:23.251Z",
      "date_updated": "2026-07-30T18:03:04.984Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11918
      },
      "nvd": {
        "published": "2026-07-30T01:16:55.017",
        "lastModified": "2026-08-03T17:33:49.493",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17909",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Isolated Web Apps path accepts malicious network input across an origin boundary, but the public record does not identify the validation rule that fails.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/501693236",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17910",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:58.489Z",
      "date_published": "2026-07-30T00:25:23.691Z",
      "date_updated": "2026-07-30T17:42:37.651Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in NFC in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06021
      },
      "nvd": {
        "published": "2026-07-30T01:16:55.130",
        "lastModified": "2026-08-03T13:47:32.953",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17910",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The NFC component fails to enforce an origin boundary, but the public record does not identify the compared origin or missing policy branch.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/501749600",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17911",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:58.693Z",
      "date_published": "2026-07-30T00:25:24.095Z",
      "date_updated": "2026-07-30T17:42:13.099Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in SVG in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06021
      },
      "nvd": {
        "published": "2026-07-30T01:16:55.240",
        "lastModified": "2026-08-03T17:33:11.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17911",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chrome SVG insufficiently enforces an origin policy and can expose cross-origin data, although the protected resource and policy predicate are not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/502505715",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17912",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:58.900Z",
      "date_published": "2026-07-30T00:25:24.527Z",
      "date_updated": "2026-07-31T18:25:42.367Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08755
      },
      "nvd": {
        "published": "2026-07-30T01:16:55.343",
        "lastModified": "2026-08-03T17:32:51.963",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17912",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Navigation accepts an untrusted redirect target without restricting it to the intended origin or scheme.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/504202939",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 212,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17913",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:59.109Z",
      "date_published": "2026-07-30T00:25:24.976Z",
      "date_updated": "2026-07-30T00:25:24.976Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "epss": {
        "score": 0.00208,
        "percentile": 0.11016
      },
      "nvd": {
        "published": "2026-07-30T01:16:55.450",
        "lastModified": "2026-07-30T20:28:27.243",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-17913",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome record reports UI spoofing in Chrome for iOS but does not disclose the implementation error that enables it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://issues.chromium.org/issues/504209246",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17914",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:59.309Z",
      "date_published": "2026-07-30T00:25:25.650Z",
      "date_updated": "2026-07-30T18:22:53.685Z",
      "publisher": "Chrome",
      "title": "Side-channel information leakage in Skia in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12555
      },
      "nvd": {
        "published": "2026-07-30T01:16:55.560",
        "lastModified": "2026-08-03T18:26:09.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17914",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A Skia side channel lets a crafted page infer potentially sensitive bytes from process memory.",
        "basis": [
          "CNA",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/506377118",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17915",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:59.520Z",
      "date_published": "2026-07-30T00:25:26.074Z",
      "date_updated": "2026-07-30T18:22:26.177Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in WebView in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09816
      },
      "nvd": {
        "published": "2026-07-30T01:16:55.670",
        "lastModified": "2026-08-03T13:47:35.510",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17915",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Chrome accepts a request across an unintended network or origin boundary, while the request field and validation step are not public.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/506390325",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17916",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:59.798Z",
      "date_published": "2026-07-30T00:25:26.476Z",
      "date_updated": "2026-07-31T03:55:30.423Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Settings in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00166,
        "percentile": 0.062
      },
      "nvd": {
        "published": "2026-07-30T01:16:55.780",
        "lastModified": "2026-08-03T18:26:02.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17916",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Settings fails to enforce a renderer privilege policy, but the public record does not identify the setting or policy decision.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/510808598",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17917",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:36:59.997Z",
      "date_published": "2026-07-30T00:25:26.911Z",
      "date_updated": "2026-07-30T19:09:25.518Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12185
      },
      "nvd": {
        "published": "2026-07-30T01:16:55.880",
        "lastModified": "2026-08-03T19:06:10.510",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17917",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS fails to enforce an undisclosed access-control policy against crafted page content.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/511816897",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17918",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:00.197Z",
      "date_published": "2026-07-30T00:25:27.306Z",
      "date_updated": "2026-07-31T03:56:07.373Z",
      "publisher": "Chrome",
      "title": "Use after free in Sync in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22586
      },
      "nvd": {
        "published": "2026-07-30T01:16:55.980",
        "lastModified": "2026-08-03T17:32:23.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17918",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513127137",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17919",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:00.406Z",
      "date_published": "2026-07-30T00:25:27.703Z",
      "date_updated": "2026-07-30T12:11:57.555Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02141
      },
      "nvd": {
        "published": "2026-07-30T01:16:56.090",
        "lastModified": "2026-08-03T17:32:13.150",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17919",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Chrome reports a physical-access Enterprise policy-enforcement failure but does not identify the policy, protected operation, or missing state check.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513291747",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17920",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:00.699Z",
      "date_published": "2026-07-30T00:25:28.110Z",
      "date_updated": "2026-07-31T03:56:06.671Z",
      "publisher": "Chrome",
      "title": "Use after free in V8 in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12881
      },
      "nvd": {
        "published": "2026-07-30T01:16:56.190",
        "lastModified": "2026-08-03T17:32:07.843",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17920",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513413942",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17921",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:00.896Z",
      "date_published": "2026-07-30T00:25:28.536Z",
      "date_updated": "2026-07-30T19:06:39.378Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13295
      },
      "nvd": {
        "published": "2026-07-30T01:16:56.297",
        "lastModified": "2026-08-03T17:32:02.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17921",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Navigation input can bypass a browser restriction after renderer compromise, but the exact policy predicate is not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513503197",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17922",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:01.090Z",
      "date_published": "2026-07-30T00:25:28.951Z",
      "date_updated": "2026-07-31T03:56:05.772Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Enterprise in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00399,
        "percentile": 0.3273
      },
      "nvd": {
        "published": "2026-07-30T01:16:56.407",
        "lastModified": "2026-08-03T17:31:55.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17922",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Enterprise component lets crafted page input reach a code-execution context without the required separation.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513611659",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17923",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:01.293Z",
      "date_published": "2026-07-30T00:25:29.369Z",
      "date_updated": "2026-07-30T19:02:28.503Z",
      "publisher": "Chrome",
      "title": "Policy bypass in Enterprise in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11029
      },
      "nvd": {
        "published": "2026-07-30T01:16:56.503",
        "lastModified": "2026-08-03T17:31:46.260",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17923",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Enterprise navigation policy accepts a crafted domain name as permitted when it should remain outside the allowed destination set, but the comparison rule is not public.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513612928",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17924",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:01.494Z",
      "date_published": "2026-07-30T00:25:29.777Z",
      "date_updated": "2026-07-30T19:00:30.001Z",
      "publisher": "Chrome",
      "title": "Use after free in DNS in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16718
      },
      "nvd": {
        "published": "2026-07-30T01:16:56.607",
        "lastModified": "2026-08-03T17:31:35.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17924",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path can dereference an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513714124",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17925",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:01.677Z",
      "date_published": "2026-07-30T00:25:30.209Z",
      "date_updated": "2026-07-31T18:24:00.642Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Cast in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.0517
      },
      "nvd": {
        "published": "2026-07-30T01:16:56.713",
        "lastModified": "2026-08-03T13:44:41.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17925",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Cast implementation accepts a crafted page across the same-origin boundary, but the failed origin comparison is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513719671",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17926",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:01.903Z",
      "date_published": "2026-07-30T00:25:30.663Z",
      "date_updated": "2026-07-31T15:50:55.977Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13293
      },
      "nvd": {
        "published": "2026-07-30T01:16:56.820",
        "lastModified": "2026-08-03T17:31:27.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17926",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DevTools accepts untrusted navigation input that bypasses a navigation restriction, while the exact validation rule is not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513735900",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17927",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:02.128Z",
      "date_published": "2026-07-30T00:25:31.106Z",
      "date_updated": "2026-07-30T15:38:19.206Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02598
      },
      "nvd": {
        "published": "2026-07-30T01:16:56.923",
        "lastModified": "2026-08-03T17:29:55.143",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17927",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome trusts an origin, proxy header, cache key, or cross-origin channel without validating that it represents the same security principal and destination used by the policy decision.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513754837",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17928",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:02.326Z",
      "date_published": "2026-07-30T00:25:31.530Z",
      "date_updated": "2026-07-30T17:41:11.498Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in DataTransfer in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10213
      },
      "nvd": {
        "published": "2026-07-30T01:16:57.030",
        "lastModified": "2026-08-03T17:29:44.963",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17928",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "DataTransfer permits crafted content to cross an origin boundary and receive data, although the failed origin rule is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513762372",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17929",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:02.534Z",
      "date_published": "2026-07-30T00:25:31.920Z",
      "date_updated": "2026-07-31T15:47:01.532Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11029
      },
      "nvd": {
        "published": "2026-07-30T01:16:57.123",
        "lastModified": "2026-08-03T17:29:37.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17929",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in Chrome, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513768645",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17930",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:02.720Z",
      "date_published": "2026-07-30T00:25:32.341Z",
      "date_updated": "2026-07-31T03:55:29.406Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14809
      },
      "nvd": {
        "published": "2026-07-30T01:16:57.237",
        "lastModified": "2026-08-03T17:29:27.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17930",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says Extensions insufficiently validates renderer input before privilege escalation but does not disclose the failing check.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513769158",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17931",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:02.928Z",
      "date_published": "2026-07-30T00:25:32.803Z",
      "date_updated": "2026-07-30T19:51:29.951Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13294
      },
      "nvd": {
        "published": "2026-07-30T01:16:57.340",
        "lastModified": "2026-08-03T17:29:19.303",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17931",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome DevTools permits a crafted page to bypass a navigation restriction, but the exact request-state check is not public.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513781245",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17932",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:03.096Z",
      "date_published": "2026-07-30T00:25:33.187Z",
      "date_updated": "2026-07-30T17:39:07.003Z",
      "publisher": "Chrome",
      "title": "Use after free in DataTransfer in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01298
      },
      "nvd": {
        "published": "2026-07-30T01:16:57.437",
        "lastModified": "2026-08-03T15:00:58.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17932",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome DataTransfer uses freed storage and can expose residual process memory to a local attacker.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513819157",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17933",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:03.310Z",
      "date_published": "2026-07-30T00:25:33.591Z",
      "date_updated": "2026-07-30T17:39:40.495Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in DOMStorage in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.0602
      },
      "nvd": {
        "published": "2026-07-30T01:16:57.547",
        "lastModified": "2026-08-03T17:29:06.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17933",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The DOMStorage implementation permits a crafted page to receive data that should remain confined to another origin.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513822044",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17934",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:03.547Z",
      "date_published": "2026-07-30T00:25:34.001Z",
      "date_updated": "2026-07-30T19:49:13.926Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14869
      },
      "nvd": {
        "published": "2026-07-30T01:16:57.640",
        "lastModified": "2026-08-03T17:28:57.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17934",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513838421",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17935",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:03.756Z",
      "date_published": "2026-07-30T00:25:34.375Z",
      "date_updated": "2026-07-31T03:56:05.073Z",
      "publisher": "Chrome",
      "title": "Heap buffer overflow in Codecs in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.2648
      },
      "nvd": {
        "published": "2026-07-30T01:16:57.753",
        "lastModified": "2026-08-03T17:28:42.337",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17935",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler writes attacker-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513863267",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17936",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:03.966Z",
      "date_published": "2026-07-30T00:25:34.792Z",
      "date_updated": "2026-07-30T18:58:33.925Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07523
      },
      "nvd": {
        "published": "2026-07-30T01:16:57.860",
        "lastModified": "2026-08-03T17:28:31.407",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17936",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A crafted page combined with specific user-interface gestures can bypass DevTools navigation restrictions, while the public record does not identify the underlying boundary check.",
        "basis": [
          "CNA",
          "CWE-352",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513864014",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17937",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:04.163Z",
      "date_published": "2026-07-30T00:25:35.236Z",
      "date_updated": "2026-07-30T18:54:51.611Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09576
      },
      "nvd": {
        "published": "2026-07-30T01:16:57.967",
        "lastModified": "2026-08-03T17:28:17.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17937",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The DevTools component accepts page-controlled navigation input without enforcing an undisclosed navigation boundary.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513866380",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17938",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:04.375Z",
      "date_published": "2026-07-30T00:25:35.653Z",
      "date_updated": "2026-07-30T18:53:13.218Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in FullScreen in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13965
      },
      "nvd": {
        "published": "2026-07-30T01:16:58.070",
        "lastModified": "2026-08-03T13:47:37.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17938",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome FullScreen can present spoofable security-critical UI, but the public record does not identify the misrepresented element or state.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/513989304",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17939",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:04.574Z",
      "date_published": "2026-07-30T00:25:36.047Z",
      "date_updated": "2026-07-30T18:51:21.479Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07297
      },
      "nvd": {
        "published": "2026-07-30T01:16:58.167",
        "lastModified": "2026-08-03T17:28:09.683",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17939",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says Passwords input validation permits UI spoofing but does not identify the trusted display state or validation rule.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514060089",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17940",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:04.771Z",
      "date_published": "2026-07-30T00:25:36.448Z",
      "date_updated": "2026-07-30T19:41:46.687Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16717
      },
      "nvd": {
        "published": "2026-07-30T01:16:58.273",
        "lastModified": "2026-08-03T13:46:45.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17940",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public material says Picture-in-Picture input validation permits a sandbox escape but does not identify the input, parser, check, or state transition.",
        "basis": [
          "CNA",
          "CWE-20",
          "Chrome Stable Channel release",
          "Chromium issue 514069440"
        ],
        "deepDive": true,
        "notes": "Inspected https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html and https://issues.chromium.org/issues/514069440 on 2026-08-05; the linked release material did not expose the triggering input or causal check, and the Chromium issue did not provide publicly readable technical detail, so the sandbox-escape cause remains undetermined."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514069440",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 281,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17941",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:04.978Z",
      "date_published": "2026-07-30T00:25:36.862Z",
      "date_updated": "2026-07-30T19:40:39.107Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13966
      },
      "nvd": {
        "published": "2026-07-30T01:16:58.383",
        "lastModified": "2026-08-03T19:06:13.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17941",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chrome for iOS renders attacker-controlled navigation state as trusted Omnibox content.",
        "basis": [
          "CNA record",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514147906",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17942",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:05.174Z",
      "date_published": "2026-07-30T00:25:37.323Z",
      "date_updated": "2026-07-30T17:55:31.823Z",
      "publisher": "Chrome",
      "title": "Side-channel information leakage in SVG in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10213
      },
      "nvd": {
        "published": "2026-07-30T01:16:58.483",
        "lastModified": "2026-08-03T17:24:34.903",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17942",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome exposes secret-dependent microarchitectural behavior through a measurable hardware side channel.",
        "basis": [
          "CNA",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514406198",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17943",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:05.393Z",
      "date_published": "2026-07-30T00:25:37.729Z",
      "date_updated": "2026-07-30T19:39:39.786Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Parser in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09577
      },
      "nvd": {
        "published": "2026-07-30T01:16:58.597",
        "lastModified": "2026-08-03T17:28:12.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17943",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's parser accepts crafted markup in a form that escapes content-security-policy enforcement, but the parser discrepancy is not public.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514424283",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17944",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:05.570Z",
      "date_published": "2026-07-30T00:25:38.110Z",
      "date_updated": "2026-07-30T19:37:57.317Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08755
      },
      "nvd": {
        "published": "2026-07-30T01:16:58.693",
        "lastModified": "2026-08-03T15:05:21.507",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17944",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS permits a crafted page to bypass a navigation restriction, while the public record does not identify the URL or transition check that fails.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514510853",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 212,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17945",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:05.758Z",
      "date_published": "2026-07-30T00:25:38.540Z",
      "date_updated": "2026-07-30T19:30:44.467Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08936
      },
      "nvd": {
        "published": "2026-07-30T01:16:58.793",
        "lastModified": "2026-08-03T17:28:36.887",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17945",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A compromised renderer can make the navigation UI represent an untrusted page as a different security context, while the exact state mismatch is not public.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/514519203",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17946",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:05.958Z",
      "date_published": "2026-07-30T00:25:38.922Z",
      "date_updated": "2026-07-30T15:55:20.484Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in Dawn in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18947
      },
      "nvd": {
        "published": "2026-07-30T01:16:58.897",
        "lastModified": "2026-08-03T17:26:15.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17946",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Dawn component uses uninitialized data and can return residual process memory to a compromised renderer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/515437522",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17947",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:06.149Z",
      "date_published": "2026-07-30T00:25:39.354Z",
      "date_updated": "2026-07-30T15:57:18.487Z",
      "publisher": "Chrome",
      "title": "Use after free in WebSockets in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16718
      },
      "nvd": {
        "published": "2026-07-30T01:16:59.003",
        "lastModified": "2026-08-03T17:25:11.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17947",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path retains or dereferences an object after its storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/515438256",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17948",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:06.345Z",
      "date_published": "2026-07-30T00:25:39.749Z",
      "date_updated": "2026-07-31T03:55:44.170Z",
      "publisher": "Chrome",
      "title": "Type Confusion in V8 in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09381
      },
      "nvd": {
        "published": "2026-07-30T01:16:59.120",
        "lastModified": "2026-08-03T17:31:34.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17948",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A memory-safety failure permits invalid access outside an object's bounds or lifetime.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/516849257",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17949",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:06.557Z",
      "date_published": "2026-07-30T00:25:40.180Z",
      "date_updated": "2026-07-30T13:32:55.705Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in GPU in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12531
      },
      "nvd": {
        "published": "2026-07-30T01:16:59.247",
        "lastModified": "2026-08-03T17:23:23.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17949",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path exposes or consumes memory before the relevant value has been initialized.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517000034",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 186,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17950",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:06.737Z",
      "date_published": "2026-07-30T00:25:40.546Z",
      "date_updated": "2026-07-31T03:55:45.790Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18878
      },
      "nvd": {
        "published": "2026-07-30T01:16:59.377",
        "lastModified": "2026-07-31T04:17:05.183",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17950",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Chrome reports an inappropriate Safe Browsing implementation leading to code execution but does not disclose the enabling check, parser, or state transition.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517063658",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17951",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:06.931Z",
      "date_published": "2026-07-30T00:25:40.949Z",
      "date_updated": "2026-07-30T15:52:20.088Z",
      "publisher": "Chrome",
      "title": "Heap buffer overflow in WebRTC in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20137
      },
      "nvd": {
        "published": "2026-07-30T01:16:59.490",
        "lastModified": "2026-08-03T17:23:51.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17951",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Chrome, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517180511",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17952",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:07.119Z",
      "date_published": "2026-07-30T00:25:41.353Z",
      "date_updated": "2026-07-31T03:55:44.851Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08573
      },
      "nvd": {
        "published": "2026-07-30T01:16:59.603",
        "lastModified": "2026-07-31T04:17:07.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17952",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome lets a malicious extension cross a V8 sandbox privilege boundary, but the public record does not disclose the faulty V8 operation.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517316174",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17953",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:07.321Z",
      "date_published": "2026-07-30T00:25:41.796Z",
      "date_updated": "2026-07-30T15:01:00.298Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13294
      },
      "nvd": {
        "published": "2026-07-30T01:16:59.703",
        "lastModified": "2026-08-03T19:25:43.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17953",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebView relies on client-side navigation restrictions that crafted page content can bypass; the exact navigation check is not public.",
        "basis": [
          "CNA",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517335150",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 212,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17954",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:07.514Z",
      "date_published": "2026-07-30T00:25:42.248Z",
      "date_updated": "2026-07-30T17:41:46.557Z",
      "publisher": "Chrome",
      "title": "Policy bypass in MHTML in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.0524
      },
      "nvd": {
        "published": "2026-07-30T01:16:59.807",
        "lastModified": "2026-08-03T17:21:47.883",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17954",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's MHTML handling crosses an origin boundary without the required origin validation, while the failing comparison is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517383492",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 174,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17955",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:07.722Z",
      "date_published": "2026-07-30T00:25:42.662Z",
      "date_updated": "2026-07-30T15:04:17.832Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08935
      },
      "nvd": {
        "published": "2026-07-30T01:16:59.910",
        "lastModified": "2026-08-03T17:21:04.743",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17955",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Payments component can present attacker-controlled UI as trusted browser content, while the public record omits the origin or navigation state that is misrepresented.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517385072",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17956",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:07.928Z",
      "date_published": "2026-07-30T00:25:43.073Z",
      "date_updated": "2026-07-31T03:55:42.049Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Scheduling in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21373
      },
      "nvd": {
        "published": "2026-07-30T01:17:00.040",
        "lastModified": "2026-07-31T04:17:08.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17956",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome lets a lower-privileged caller exercise a higher-privileged operation because privilege assignment or enforcement is incomplete.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517436171",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17957",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:08.107Z",
      "date_published": "2026-07-30T00:25:43.472Z",
      "date_updated": "2026-07-30T17:54:19.341Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in CORS in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04325
      },
      "nvd": {
        "published": "2026-07-30T01:17:00.150",
        "lastModified": "2026-08-03T17:27:51.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17957",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The CORS implementation can release cross-origin data after renderer compromise, while the exact origin check is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517476342",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17958",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:08.304Z",
      "date_published": "2026-07-30T00:25:43.939Z",
      "date_updated": "2026-07-30T19:36:43.854Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Views in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08936
      },
      "nvd": {
        "published": "2026-07-30T01:17:00.260",
        "lastModified": "2026-08-03T17:29:08.057",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17958",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Views component displays attacker-controlled UI as if it belonged to a trusted browser context, but the incorrect UI state is not public.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517538206",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17959",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:08.489Z",
      "date_published": "2026-07-30T00:25:44.364Z",
      "date_updated": "2026-07-30T17:53:38.457Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Network in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06019
      },
      "nvd": {
        "published": "2026-07-30T01:17:00.360",
        "lastModified": "2026-08-03T17:27:13.177",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17959",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's network component permits cross-origin data to reach a crafted page, but the public record does not disclose the origin or response-boundary mistake.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517607890",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17960",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:08.668Z",
      "date_published": "2026-07-30T00:25:44.775Z",
      "date_updated": "2026-07-30T19:35:20.653Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09576
      },
      "nvd": {
        "published": "2026-07-30T01:17:00.470",
        "lastModified": "2026-08-03T15:04:39.903",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17960",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chrome for iOS sends referrer information despite a no-referrer policy, exposing request metadata the page asked the browser to suppress.",
        "basis": [
          "CNA",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517631680",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17961",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:08.878Z",
      "date_published": "2026-07-30T00:25:45.192Z",
      "date_updated": "2026-07-30T19:33:51.814Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Session in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08755
      },
      "nvd": {
        "published": "2026-07-30T01:17:00.563",
        "lastModified": "2026-08-03T13:46:50.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17961",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Android Session implementation permits a crafted navigation outside its allowed channel, but the failed restriction is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517700791",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17962",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:09.071Z",
      "date_published": "2026-07-30T00:25:45.600Z",
      "date_updated": "2026-07-30T19:32:33.546Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Blink in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.0679
      },
      "nvd": {
        "published": "2026-07-30T01:17:00.673",
        "lastModified": "2026-08-03T17:30:31.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17962",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Chrome, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517757268",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17963",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:09.243Z",
      "date_published": "2026-07-30T00:25:46.027Z",
      "date_updated": "2026-07-30T17:53:05.922Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in SVG in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06021
      },
      "nvd": {
        "published": "2026-07-30T01:17:00.773",
        "lastModified": "2026-08-03T17:26:46.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17963",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome trusts an origin, proxy header, cache key, or cross-origin channel without validating that it represents the same security principal and destination used by the policy decision.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/517759257",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 186,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17964",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:09.436Z",
      "date_published": "2026-07-30T00:25:46.431Z",
      "date_updated": "2026-07-30T19:29:38.628Z",
      "publisher": "Chrome",
      "title": "Incorrect security UI in UI in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08935
      },
      "nvd": {
        "published": "2026-07-30T01:17:00.883",
        "lastModified": "2026-08-03T13:46:54.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17964",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's Android UI displays attacker-influenced origin information as trusted browser state, while the incorrect UI state is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518025103",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17965",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:09.609Z",
      "date_published": "2026-07-30T00:25:46.882Z",
      "date_updated": "2026-07-30T19:16:27.859Z",
      "publisher": "Chrome",
      "title": "Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08935
      },
      "nvd": {
        "published": "2026-07-30T01:17:00.990",
        "lastModified": "2026-08-03T19:06:33.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17965",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chrome omits or misrepresents trusted browser UI, allowing attacker content to impersonate a different origin.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518049812",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17966",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:09.789Z",
      "date_published": "2026-07-30T00:25:47.320Z",
      "date_updated": "2026-07-30T19:17:35.673Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Views in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00103,
        "percentile": 0.01164
      },
      "nvd": {
        "published": "2026-07-30T01:17:01.093",
        "lastModified": "2026-08-03T16:31:16.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17966",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports an inappropriate Views implementation that leaks process memory but gives no defensible engineering cause.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518058990",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17967",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:09.962Z",
      "date_published": "2026-07-30T00:25:47.744Z",
      "date_updated": "2026-07-30T15:47:43.183Z",
      "publisher": "Chrome",
      "title": "Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24004
      },
      "nvd": {
        "published": "2026-07-30T01:17:01.193",
        "lastModified": "2026-08-03T17:59:33.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17967",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome for iOS can access a heap object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518243858",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17968",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:10.143Z",
      "date_published": "2026-07-30T00:25:48.152Z",
      "date_updated": "2026-07-30T15:07:11.020Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in WebXR in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18946
      },
      "nvd": {
        "published": "2026-07-30T01:17:01.307",
        "lastModified": "2026-08-03T19:39:18.687",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17968",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome WebXR reads an uninitialized value and exposes bytes from process memory.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518337516",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17969",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:10.329Z",
      "date_published": "2026-07-30T00:25:48.543Z",
      "date_updated": "2026-07-31T03:55:41.358Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21373
      },
      "nvd": {
        "published": "2026-07-30T01:17:01.417",
        "lastModified": "2026-07-31T04:17:08.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17969",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports code execution inside the Chrome sandbox through Passwords, without disclosing the enabling engineering failure.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518812295",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17970",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:10.517Z",
      "date_published": "2026-07-30T00:25:49.005Z",
      "date_updated": "2026-07-30T15:11:28.346Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04271
      },
      "nvd": {
        "published": "2026-07-30T01:17:01.520",
        "lastModified": "2026-08-03T16:26:47.467",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17970",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public Chrome record identifies input-validation-dependent UI spoofing by a privileged network attacker but does not expose the accepted input or faulty trust decision.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518814464",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17971",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:10.707Z",
      "date_published": "2026-07-30T00:25:49.446Z",
      "date_updated": "2026-07-30T14:57:27.461Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Frame in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00271,
        "percentile": 0.19151
      },
      "nvd": {
        "published": "2026-07-30T01:17:01.637",
        "lastModified": "2026-08-03T16:23:51.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17971",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The public record identifies a memory-safety failure but does not disclose the exact buffer, lifetime transition, or invalid access.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/518815075",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17972",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:10.890Z",
      "date_published": "2026-07-30T00:25:49.842Z",
      "date_updated": "2026-07-30T19:27:31.310Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08934
      },
      "nvd": {
        "published": "2026-07-30T01:17:01.740",
        "lastModified": "2026-08-03T15:04:15.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17972",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The browser or server accepts an attacker-controlled origin, navigation or presentation boundary without the required trust validation.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519202895",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17973",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:11.063Z",
      "date_published": "2026-07-30T00:25:50.282Z",
      "date_updated": "2026-07-30T19:26:33.842Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Views in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00101,
        "percentile": 0.01044
      },
      "nvd": {
        "published": "2026-07-30T01:17:01.850",
        "lastModified": "2026-08-03T17:16:20.727",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17973",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The macOS Views component can return process-memory data to a local caller, but the public record does not disclose the data path or stale state involved.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519230894",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17974",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:11.255Z",
      "date_published": "2026-07-30T00:25:50.691Z",
      "date_updated": "2026-07-30T19:25:18.984Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06778
      },
      "nvd": {
        "published": "2026-07-30T01:17:01.950",
        "lastModified": "2026-08-03T17:16:40.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17974",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "DevTools permits a navigation restriction bypass, but the public record does not identify the policy rule or protected transition.",
        "basis": [
          "CNA",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519232592",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17975",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:11.457Z",
      "date_published": "2026-07-30T00:25:51.131Z",
      "date_updated": "2026-07-30T19:19:00.704Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in IME in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14848
      },
      "nvd": {
        "published": "2026-07-30T01:17:02.057",
        "lastModified": "2026-08-03T17:17:13.183",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17975",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The IME implementation exposes process-memory information to crafted web content, but the output path or oracle is not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519233776",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 231,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17976",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:11.648Z",
      "date_published": "2026-07-30T00:25:51.564Z",
      "date_updated": "2026-07-30T19:23:47.861Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03673
      },
      "nvd": {
        "published": "2026-07-30T01:17:02.157",
        "lastModified": "2026-08-03T17:18:05.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17976",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A crafted extension domain bypasses a discretionary-access boundary, but the public record does not disclose the domain comparison rule.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519455164",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17977",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:11.837Z",
      "date_published": "2026-07-30T00:25:51.941Z",
      "date_updated": "2026-07-30T17:52:24.445Z",
      "publisher": "Chrome",
      "title": "Policy bypass in CSS in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05887
      },
      "nvd": {
        "published": "2026-07-30T01:17:02.260",
        "lastModified": "2026-08-03T16:28:45.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17977",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A CSS policy bypass exposes cross-origin data, but the public record does not identify the policy decision or failing origin check.",
        "basis": [
          "CNA record",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519603552",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17978",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:12.011Z",
      "date_published": "2026-07-30T00:25:52.349Z",
      "date_updated": "2026-07-30T18:20:01.210Z",
      "publisher": "Chrome",
      "title": "Side-channel information leakage in WebCodecs in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11459
      },
      "nvd": {
        "published": "2026-07-30T01:17:02.370",
        "lastModified": "2026-08-03T17:07:56.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17978",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome exposes secret-dependent microarchitectural behavior through a measurable hardware side channel.",
        "basis": [
          "CNA",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519610845",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17979",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:12.186Z",
      "date_published": "2026-07-30T00:25:52.759Z",
      "date_updated": "2026-07-31T03:55:43.490Z",
      "publisher": "Chrome",
      "title": "Race in V8 in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.1045
      },
      "nvd": {
        "published": "2026-07-30T01:17:02.477",
        "lastModified": "2026-07-31T04:17:08.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17979",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A race in V8 exposes a transient object or state transition that permits code execution inside the renderer sandbox.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519664497",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17980",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:12.356Z",
      "date_published": "2026-07-30T00:25:53.168Z",
      "date_updated": "2026-07-30T18:00:31.812Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in UI in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.0682
      },
      "nvd": {
        "published": "2026-07-30T01:17:02.587",
        "lastModified": "2026-08-03T13:44:53.143",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17980",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for Android can expose cross-origin data after specific UI gestures, while the public record does not identify the gesture-state or origin decision that fails.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519710361",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:12.537Z",
      "date_published": "2026-07-30T00:25:53.576Z",
      "date_updated": "2026-07-30T17:51:53.982Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Blink in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05379
      },
      "nvd": {
        "published": "2026-07-30T01:17:02.687",
        "lastModified": "2026-08-03T16:23:06.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17981",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Blink can return cross-origin data to crafted content, but the public record does not identify the origin-binding error.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519719512",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:12.734Z",
      "date_published": "2026-07-30T00:25:53.992Z",
      "date_updated": "2026-07-30T19:22:26.045Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08698
      },
      "nvd": {
        "published": "2026-07-30T01:17:02.793",
        "lastModified": "2026-08-03T16:37:12.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17982",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Cast component accepts untrusted input that bypasses the same-origin policy, but the trusted field and missing validation are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519735808",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17983",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:12.914Z",
      "date_published": "2026-07-30T00:25:54.404Z",
      "date_updated": "2026-07-30T19:21:30.593Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Global Media Controls in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08086
      },
      "nvd": {
        "published": "2026-07-30T01:17:02.907",
        "lastModified": "2026-08-03T16:38:42.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17983",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Global Media Controls can present attacker-controlled state as trusted browser UI, but the public record does not identify the misrepresented indicator or state transition.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519744561",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17984",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:13.100Z",
      "date_published": "2026-07-30T00:25:54.836Z",
      "date_updated": "2026-07-30T17:51:14.217Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Browser in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00092,
        "percentile": 0.00617
      },
      "nvd": {
        "published": "2026-07-30T01:17:03.010",
        "lastModified": "2026-08-03T13:44:58.100",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17984",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The browser trusts a cross-domain channel it should isolate, but the public record does not disclose the failing origin rule.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519978460",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17985",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:13.289Z",
      "date_published": "2026-07-30T00:25:55.280Z",
      "date_updated": "2026-07-30T19:20:22.852Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Speech in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12126
      },
      "nvd": {
        "published": "2026-07-30T01:17:03.113",
        "lastModified": "2026-08-03T16:39:19.497",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17985",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Chrome Speech policy permits crafted HTML to cross the site-isolation boundary, while the exact policy check is not public.",
        "basis": [
          "CNA",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519981430",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17986",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:13.481Z",
      "date_published": "2026-07-30T00:25:55.672Z",
      "date_updated": "2026-07-30T18:38:27.983Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11076
      },
      "nvd": {
        "published": "2026-07-30T01:17:03.210",
        "lastModified": "2026-08-03T17:03:53.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17986",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Bluetooth permits a compromised renderer to cross the same-origin boundary, but the failing policy rule is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519981896",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17987",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:13.654Z",
      "date_published": "2026-07-30T00:25:57.252Z",
      "date_updated": "2026-07-30T19:12:54.143Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13113
      },
      "nvd": {
        "published": "2026-07-30T01:17:03.317",
        "lastModified": "2026-08-03T16:41:20.693",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17987",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Google reports that a crafted PDF processed through Notifications can escape a compromised renderer, but its public release and issue page expose no failing check or operation.",
        "basis": [
          "CNA",
          "CWE-20",
          "Chrome 151 stable release",
          "Chromium issue 519988071"
        ],
        "deepDive": true,
        "notes": "Inspected https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html and https://issues.chromium.org/issues/519988071. The release supplies only the Notifications input-validation label and the linked issue exposes no public technical body. Chrome labels the issue Low while the shard maximum is CISA-ADP CVSS 9.6; these are different scoring systems and attributions, and neither reveals the root cause."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/519988071",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 264,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17988",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:13.833Z",
      "date_published": "2026-07-30T00:25:57.649Z",
      "date_updated": "2026-07-30T18:48:54.649Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12126
      },
      "nvd": {
        "published": "2026-07-30T01:17:03.420",
        "lastModified": "2026-08-03T17:03:12.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17988",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Navigation accepts input that bypasses a navigation restriction, but the public record does not identify the trusted URL or state field.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520005624",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17989",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:14.022Z",
      "date_published": "2026-07-30T00:25:58.054Z",
      "date_updated": "2026-07-31T03:55:42.793Z",
      "publisher": "Chrome",
      "title": "Type Confusion in V8 in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24081
      },
      "nvd": {
        "published": "2026-07-30T01:17:03.533",
        "lastModified": "2026-07-31T04:17:11.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17989",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected runtime uses an object through an incompatible type and therefore applies the wrong memory layout.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520017306",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17990",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:14.210Z",
      "date_published": "2026-07-30T00:25:58.447Z",
      "date_updated": "2026-07-30T17:48:29.975Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13113
      },
      "nvd": {
        "published": "2026-07-30T01:17:03.647",
        "lastModified": "2026-08-03T16:57:11.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17990",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome's WebAuthn component insufficiently validates untrusted input, while the official release and public record do not reveal the accepted object or authentication check.",
        "basis": [
          "CNA",
          "CWE-20",
          "Chrome Stable Channel release 151.0.7922.71/.72"
        ],
        "deepDive": true,
        "notes": "Inspected https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html. The official release lists issue 520018012 as insufficient validation in WebAuthn but keeps the bug details restricted and exposes no failing check."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520018012",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17991",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:14.393Z",
      "date_published": "2026-07-30T00:25:58.868Z",
      "date_updated": "2026-07-30T17:50:00.525Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in AI in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15504
      },
      "nvd": {
        "published": "2026-07-30T01:17:03.757",
        "lastModified": "2026-08-03T16:34:06.107",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17991",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Chrome reports that the AI component accepts untrusted input leading to sandbox escape but does not disclose the input, parser, object, or failed validation rule.",
        "basis": [
          "CNA",
          "CWE-20",
          "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "https://issues.chromium.org/issues/520110535"
        ],
        "deepDive": true,
        "notes": "The official release endpoint returned a rate-limit response and the linked Chromium issue was not publicly readable during review; no failing AI-component validation rule was exposed."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520110535",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17992",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:14.582Z",
      "date_published": "2026-07-30T00:25:59.345Z",
      "date_updated": "2026-07-30T17:57:01.066Z",
      "publisher": "Chrome",
      "title": "Uninitialized Use in Skia in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17485
      },
      "nvd": {
        "published": "2026-07-30T01:17:03.863",
        "lastModified": "2026-08-03T13:49:18.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17992",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chrome uses uninitialized storage, allowing stale process memory to influence or escape through the operation.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520506316",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17993",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:14.787Z",
      "date_published": "2026-07-30T00:25:59.797Z",
      "date_updated": "2026-07-31T03:55:28.500Z",
      "publisher": "Chrome",
      "title": "Race in Updater in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0008,
        "percentile": 0.00218
      },
      "nvd": {
        "published": "2026-07-30T01:17:03.977",
        "lastModified": "2026-07-31T04:17:14.127",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17993",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A local file operation races with the Windows updater's privileged use of that file, allowing the attacker to win the update-time state transition.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520532191",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17994",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:14.972Z",
      "date_published": "2026-07-30T00:26:00.203Z",
      "date_updated": "2026-07-30T18:17:36.790Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Media in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07937
      },
      "nvd": {
        "published": "2026-07-30T01:17:04.080",
        "lastModified": "2026-08-03T13:45:01.827",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17994",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome on Android permits a crafted page to cross a navigation boundary that should restrict its destination, but the failed policy check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520663771",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17995",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:15.165Z",
      "date_published": "2026-07-30T00:26:00.616Z",
      "date_updated": "2026-07-30T18:25:39.390Z",
      "publisher": "Chrome",
      "title": "Out of bounds read in Dawn in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14678
      },
      "nvd": {
        "published": "2026-07-30T01:17:04.183",
        "lastModified": "2026-08-03T13:48:51.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17995",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dawn reads beyond the bounds of a memory object while processing crafted page-controlled graphics input.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/520972775",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17996",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:15.340Z",
      "date_published": "2026-07-30T00:26:01.016Z",
      "date_updated": "2026-07-30T18:30:30.049Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00085,
        "percentile": 0.00382
      },
      "nvd": {
        "published": "2026-07-30T01:17:04.293",
        "lastModified": "2026-08-03T13:48:34.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17996",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chrome on macOS accepts a navigation from a malicious local file that its navigation restrictions should reject.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521473427",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17997",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:15.528Z",
      "date_published": "2026-07-30T00:26:01.433Z",
      "date_updated": "2026-07-30T17:50:37.439Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02828
      },
      "nvd": {
        "published": "2026-07-30T01:17:04.387",
        "lastModified": "2026-08-03T13:48:15.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17997",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Passwords component can leak cross-origin data after renderer compromise, but the exact origin check is not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521476960",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17998",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:15.718Z",
      "date_published": "2026-07-30T00:26:01.839Z",
      "date_updated": "2026-07-30T18:46:48.993Z",
      "publisher": "Chrome",
      "title": "Incorrect security UI in Extensions in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01979
      },
      "nvd": {
        "published": "2026-07-30T01:17:04.487",
        "lastModified": "2026-08-03T13:47:56.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17998",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A malicious extension can present attacker-controlled content as trusted Chrome extension UI because the browser does not preserve the required UI-origin distinction.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521601450",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-17999",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:15.891Z",
      "date_published": "2026-07-30T00:26:02.271Z",
      "date_updated": "2026-07-30T18:40:38.846Z",
      "publisher": "Chrome",
      "title": "Race in PictureInPicture in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04342
      },
      "nvd": {
        "published": "2026-07-30T01:17:04.590",
        "lastModified": "2026-08-03T13:45:08.540",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-17999",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome accesses shared state concurrently without the synchronization needed to keep the state transition atomic and consistent.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521615681",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18000",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:16.065Z",
      "date_published": "2026-07-30T00:26:02.704Z",
      "date_updated": "2026-07-30T17:49:47.018Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04908
      },
      "nvd": {
        "published": "2026-07-30T01:17:04.690",
        "lastModified": "2026-08-03T13:45:21.843",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18000",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The USB component permits compromised-renderer input to cross an origin policy boundary, although the public record omits the failing check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521623907",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18001",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:16.256Z",
      "date_published": "2026-07-30T00:26:03.142Z",
      "date_updated": "2026-07-30T15:19:19.551Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in WebGL in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09744
      },
      "nvd": {
        "published": "2026-07-30T01:17:04.797",
        "lastModified": "2026-08-03T16:06:55.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18001",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Chrome discloses protected data, but does not identify the output, cache, or memory path that exposes it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521757779",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18002",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:16.427Z",
      "date_published": "2026-07-30T00:26:03.683Z",
      "date_updated": "2026-07-30T15:24:35.517Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10326
      },
      "nvd": {
        "published": "2026-07-30T01:17:04.893",
        "lastModified": "2026-08-03T15:59:21.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18002",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Chrome material says Google Lens insufficiently validates untrusted input before a sandbox escape but does not identify the failing validation rule.",
        "basis": [
          "CNA",
          "CWE-20",
          "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html"
        ],
        "deepDive": true,
        "notes": "Primary source inspected: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html. Chrome labels the Google Lens validation issue Low and keeps issue 521864362 restricted; no causal check is public, and that label conflicts with the embedded maximum CVSS 9.6."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521864362",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18003",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:16.615Z",
      "date_published": "2026-07-30T00:26:04.074Z",
      "date_updated": "2026-07-30T15:27:40.592Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08514
      },
      "nvd": {
        "published": "2026-07-30T01:17:05.013",
        "lastModified": "2026-08-03T18:00:55.023",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18003",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Chrome for iOS renders attacker-controlled interface state in a way that can misrepresent the trusted browser UI.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/521934304",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18004",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:16.779Z",
      "date_published": "2026-07-30T00:26:04.499Z",
      "date_updated": "2026-07-30T15:33:59.662Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Speech in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05354
      },
      "nvd": {
        "published": "2026-07-30T01:17:05.127",
        "lastModified": "2026-08-03T15:59:01.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18004",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Speech permits cross-origin data to leave the renderer boundary, but the public record does not identify the policy check that fails.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522280805",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18005",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:16.961Z",
      "date_published": "2026-07-30T00:26:04.909Z",
      "date_updated": "2026-07-30T15:37:12.626Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in WebXR in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09744
      },
      "nvd": {
        "published": "2026-07-30T01:17:05.240",
        "lastModified": "2026-08-03T16:08:24.870",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18005",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The WebXR implementation returns bytes from process memory to a crafted page, while the originating lifetime or initialization error is not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522300211",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18006",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:17.129Z",
      "date_published": "2026-07-30T00:26:05.299Z",
      "date_updated": "2026-07-30T15:40:26.185Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Google Lens in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05106
      },
      "nvd": {
        "published": "2026-07-30T01:17:05.350",
        "lastModified": "2026-08-03T16:07:46.010",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18006",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public Chrome record identifies a renderer-to-Google-Lens UI-spoofing path but does not disclose the principal or UI-state check that fails.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522396262",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18007",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:17.319Z",
      "date_published": "2026-07-30T00:26:05.721Z",
      "date_updated": "2026-07-30T15:41:23.389Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Input in Google Chrome on Android prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05105
      },
      "nvd": {
        "published": "2026-07-30T01:17:05.450",
        "lastModified": "2026-08-03T19:39:23.597",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18007",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for Android permits crafted page content to spoof trusted input UI, but the public record does not identify the incorrect indicator or state.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522404101",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18008",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:17.498Z",
      "date_published": "2026-07-30T00:26:06.170Z",
      "date_updated": "2026-07-30T16:06:32.076Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Settings in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04014
      },
      "nvd": {
        "published": "2026-07-30T01:17:05.557",
        "lastModified": "2026-08-03T16:07:23.193",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18008",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The browser or server accepts an attacker-controlled origin, navigation or presentation boundary without the required trust validation.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522412676",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18009",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:17.686Z",
      "date_published": "2026-07-30T00:26:06.587Z",
      "date_updated": "2026-07-30T16:07:06.296Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04014
      },
      "nvd": {
        "published": "2026-07-30T01:17:05.653",
        "lastModified": "2026-08-03T15:57:49.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18009",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Passwords component fails to validate network-controlled navigation context before presenting security-relevant UI.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522419718",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18010",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:17.867Z",
      "date_published": "2026-07-30T00:26:06.995Z",
      "date_updated": "2026-07-30T16:08:04.708Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04014
      },
      "nvd": {
        "published": "2026-07-30T01:17:05.770",
        "lastModified": "2026-08-03T15:56:37.057",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18010",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome Passwords can present spoofable security-critical UI, but the public record does not identify the misrepresented element or state.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522419819",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18011",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:18.047Z",
      "date_published": "2026-07-30T00:26:07.428Z",
      "date_updated": "2026-07-30T14:05:47.631Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00091,
        "percentile": 0.00594
      },
      "nvd": {
        "published": "2026-07-30T01:17:05.860",
        "lastModified": "2026-08-03T18:00:37.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18011",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS exposes process-memory information to a local physical attacker, but the output path or oracle is not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522479633",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18012",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:18.231Z",
      "date_published": "2026-07-30T00:26:07.847Z",
      "date_updated": "2026-07-31T03:55:40.650Z",
      "publisher": "Chrome",
      "title": "Use after free in PDFium in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.13051
      },
      "nvd": {
        "published": "2026-07-30T01:17:05.967",
        "lastModified": "2026-07-31T04:17:16.533",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18012",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/522938824",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18013",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:18.418Z",
      "date_published": "2026-07-30T00:26:08.283Z",
      "date_updated": "2026-07-30T14:24:48.747Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05105
      },
      "nvd": {
        "published": "2026-07-30T01:17:06.080",
        "lastModified": "2026-08-03T18:00:20.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18013",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chrome for iOS presents attacker-controlled page state as trusted browser interface state.",
        "basis": [
          "CNA record",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523245998",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:18.596Z",
      "date_published": "2026-07-30T00:26:08.748Z",
      "date_updated": "2026-07-30T14:21:06.683Z",
      "publisher": "Chrome",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06504
      },
      "nvd": {
        "published": "2026-07-30T01:17:06.180",
        "lastModified": "2026-08-03T15:55:58.897",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18014",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DevTools accepts a malicious local file as navigation input without enforcing the intended navigation restriction.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523248021",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18015",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:18.785Z",
      "date_published": "2026-07-30T00:26:09.128Z",
      "date_updated": "2026-07-30T14:12:46.841Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08454
      },
      "nvd": {
        "published": "2026-07-30T01:17:06.297",
        "lastModified": "2026-08-04T15:36:07.747",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18015",
        "family": "OTHER_SPECIFIC",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "Tint emitted unsigned division or modulo operations for Metal without the required polyfill, allowing crafted WebGPU shader behavior to reach the Mac GPU sandbox boundary.",
        "basis": [
          "CNA",
          "CWE-693",
          "Google Chrome CNA",
          "Dawn fixed commit ed24c432dcb80344927e36905a860285195d3e45"
        ],
        "deepDive": true,
        "notes": "Primary-source deep dive: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html and https://chromium.googlesource.com/experimental/external/gob/dawn/dawn/%2B/ed24c432dcb80344927e36905a860285195d3e45 ; the public source identifies the missing Metal u32 div/mod polyfill, while the restricted Chromium issue does not disclose the full exploit chain."
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523698428",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18016",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:18.959Z",
      "date_published": "2026-07-30T00:26:09.546Z",
      "date_updated": "2026-07-30T14:10:09.454Z",
      "publisher": "Chrome",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03167
      },
      "nvd": {
        "published": "2026-07-30T01:17:06.397",
        "lastModified": "2026-08-03T17:59:59.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18016",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Chrome for iOS permits UI spoofing, while the public record does not identify which trusted indicator or navigation state is misrepresented.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523708527",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18017",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:19.137Z",
      "date_published": "2026-07-30T00:26:09.934Z",
      "date_updated": "2026-07-31T03:55:39.868Z",
      "publisher": "Chrome",
      "title": "Use after free in Dawn in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15482
      },
      "nvd": {
        "published": "2026-07-30T01:17:06.500",
        "lastModified": "2026-07-31T04:17:19.150",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18017",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path can retain or dereference an object after its storage has been released, leaving a dangling reference.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/523731236",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18018",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:19.318Z",
      "date_published": "2026-07-30T00:26:10.308Z",
      "date_updated": "2026-07-30T14:09:09.950Z",
      "publisher": "Chrome",
      "title": "Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00069,
        "percentile": 0.00043
      },
      "nvd": {
        "published": "2026-07-30T01:17:06.610",
        "lastModified": "2026-08-04T15:30:57.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18018",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Windows updater displays attacker-controlled file state as trusted UI, but the public record does not identify the misrepresented field or transition.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/524467747",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18019",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T23:37:19.509Z",
      "date_published": "2026-07-30T00:26:10.716Z",
      "date_updated": "2026-07-30T14:21:25.452Z",
      "publisher": "Chrome",
      "title": "Side-channel information leakage in Media in Google Chrome prior to 151.",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Chrome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1300",
          "name": "Improper Protection of Physical Side Channels",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.0596
      },
      "nvd": {
        "published": "2026-07-30T01:17:06.713",
        "lastModified": "2026-08-03T15:55:28.150",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18019",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Chrome path exposes a measurable side channel that lets a remote page infer data belonging to another origin.",
        "basis": [
          "CNA",
          "CWE-1300"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
          "host": "chromereleases.googleblog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://issues.chromium.org/issues/525691898",
          "host": "issues.chromium.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18022",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T00:20:11.430Z",
      "date_published": "2026-07-29T18:55:54.658Z",
      "date_updated": "2026-07-31T03:56:13.731Z",
      "publisher": "PostgreSQL",
      "title": "pgvector buffer overflow via integer wraparound in IVFFlat index build on 32-bit systems",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "pgvector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26884
      },
      "nvd": {
        "published": "2026-07-29T20:17:02.593",
        "lastModified": "2026-07-31T04:17:19.543",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18022",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "IVFFlat size arithmetic wraps and produces an undersized region that is then accessed out of bounds.",
        "basis": [
          "CNA",
          "CWE-190",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pgvector/pgvector/issues/1006",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/pgvector/pgvector/commit/636a92a3395d2e036ffd40d07aeb400a708ae104",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18028",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T07:28:14.113Z",
      "date_published": "2026-07-28T10:39:48.208Z",
      "date_updated": "2026-07-28T12:38:22.341Z",
      "publisher": "rami.io",
      "title": "Missing authorization check in event quick setup view",
      "affected": {
        "vendors": [
          "pretix GmbH"
        ],
        "products": [
          {
            "vendor": "pretix GmbH",
            "product": "pretix"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:655498c3-6ec5-4f0b-aea6-853b334d05a6",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.1093
      },
      "nvd": {
        "published": "2026-07-28T11:17:03.530",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18028",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pretix request path accepts an attacker-selected object identifier without binding that object to the caller's tenant, owner, or permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://pretix.eu/about/en/blog/20260728-release-2026-6-1/",
          "host": "pretix.eu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 434,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-18029",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T07:28:43.937Z",
      "date_published": "2026-07-28T10:39:29.727Z",
      "date_updated": "2026-07-28T12:36:18.719Z",
      "publisher": "rami.io",
      "title": "Insufficient validation of payment status in pretix-girosolution",
      "affected": {
        "vendors": [
          "pretix GmbH"
        ],
        "products": [
          {
            "vendor": "pretix GmbH",
            "product": "pretix-girosolution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-841",
          "name": "Improper Enforcement of Behavioral Workflow",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:655498c3-6ec5-4f0b-aea6-853b334d05a6",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10983
      },
      "nvd": {
        "published": "2026-07-28T11:17:03.677",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18029",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GiroCheckout accepts a previously successful payment response for a different payment workflow without binding it to the current transaction.",
        "basis": [
          "CNA",
          "CWE-841"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://pretix.eu/about/en/blog/20260728-release-2026-6-1/",
          "host": "pretix.eu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 290,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18038",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T08:31:54.362Z",
      "date_published": "2026-07-28T12:45:11.475Z",
      "date_updated": "2026-07-28T19:24:43.169Z",
      "publisher": "VulDB",
      "title": "nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure",
      "affected": {
        "vendors": [
          "nextlevelbuilder"
        ],
        "products": [
          {
            "vendor": "nextlevelbuilder",
            "product": "GoClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "cna",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@vuldb.com",
          "type": "Secondary",
          "version": "2.0",
          "score": 4,
          "severity": "",
          "vector": "AV:N/AC:L/Au:S/C:P/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3.1999999999999997,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12843
      },
      "nvd": {
        "published": "2026-07-28T13:17:36.507",
        "lastModified": "2026-07-28T20:34:39.437",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18038",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record ties remote information disclosure to ExecTool.Execute in the jq handler but does not identify the input, output, or missing access boundary.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://vuldb.com/vuln/383813",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/383813/cti",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "permissions-required",
            "signature"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-18038",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/862538",
          "host": "vuldb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/issues/1226",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/pull/1230",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/nextlevelbuilder/goclaw/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 7,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-18047",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T10:15:23.892Z",
      "date_published": "2026-07-28T12:44:24.682Z",
      "date_updated": "2026-07-28T13:26:27.569Z",
      "publisher": "redhat",
      "title": "Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication bypass via trailing slash",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Certificate System 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Certificate System 11"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Certificate System 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20384
      },
      "nvd": {
        "published": "2026-07-28T13:17:36.693",
        "lastModified": "2026-07-28T16:22:01.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18047",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tomcat applies an exact admin URL constraint while RESTEasy also routes the trailing-slash form, leaving that form unauthenticated.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18047",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507956",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 429,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18064",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T14:10:13.503Z",
      "date_published": "2026-07-30T21:35:14.061Z",
      "date_updated": "2026-07-31T15:41:27.652Z",
      "publisher": "icscert",
      "title": "NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference",
      "affected": {
        "vendors": [
          "NASA"
        ],
        "products": [
          {
            "vendor": "NASA",
            "product": "Core Flight System (cFS) Health & Safety (HS) Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26487
      },
      "nvd": {
        "published": "2026-07-30T22:16:54.790",
        "lastModified": "2026-07-31T16:17:05.247",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18064",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path dereferences a NULL pointer because the required validity check is missing or applied to the wrong value.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nasa/HS",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-06.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 373,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18072",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T15:05:15.700Z",
      "date_published": "2026-07-29T03:31:08.913Z",
      "date_updated": "2026-07-29T13:04:22.634Z",
      "publisher": "Wordfence",
      "title": "Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter",
      "affected": {
        "vendors": [
          "nico23"
        ],
        "products": [
          {
            "vendor": "nico23",
            "product": "Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-506",
          "name": "Embedded Malicious Code",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00586,
        "percentile": 0.44709
      },
      "nvd": {
        "published": "2026-07-29T05:16:40.840",
        "lastModified": "2026-07-30T14:01:30.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18072",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A malicious WordPress plugin release embeds a universal _wplogin token and runs its early init hook before normal authentication, allowing the token holder to select an administrator account.",
        "basis": [
          "CNA",
          "CWE-506"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/70f64ea0-5375-479f-90ac-29bcdf817cef?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/advanced-responsive-video-embedder/tags/10.8.7/php/fn-update-check.php#L52",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/advanced-responsive-video-embedder/tags/10.8.7/php/fn-update-check.php#L24",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/advanced-responsive-video-embedder/tags/10.8.7/php/fn-update-check.php#L33",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/advanced-responsive-video-embedder/tags/10.8.7/advanced-responsive-video-embedder.php#L76",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1055,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18084",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T15:56:20.749Z",
      "date_published": "2026-07-28T16:22:26.727Z",
      "date_updated": "2026-07-31T14:04:09.230Z",
      "publisher": "blackberry",
      "title": "Cross-Site Scripting (XSS) in Management Console of BlackBerry UEM",
      "affected": {
        "vendors": [
          "BlackBerry"
        ],
        "products": [
          {
            "vendor": "BlackBerry",
            "product": "UEM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:secure@blackberry.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17373
      },
      "nvd": {
        "published": "2026-07-28T17:16:37.960",
        "lastModified": "2026-07-30T16:51:19.723",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18084",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.blackberry.com/pkb/s/article/141208",
          "host": "support.blackberry.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 212,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T15:56:24.271Z",
      "date_published": "2026-07-28T16:21:59.172Z",
      "date_updated": "2026-07-28T16:54:04.123Z",
      "publisher": "blackberry",
      "title": "Improper Input Validation Leads to Arbitrary File Download and Potential Denial of Service in BlackBerry UEM",
      "affected": {
        "vendors": [
          "BlackBerry"
        ],
        "products": [
          {
            "vendor": "BlackBerry",
            "product": "UEM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:L/SA:L"
        },
        {
          "source": "NVD:secure@blackberry.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10983
      },
      "nvd": {
        "published": "2026-07-28T17:16:38.150",
        "lastModified": "2026-07-30T16:51:19.723",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18085",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public advisory links input validation to arbitrary file download and denial of service but does not reveal which value selects a file or consumes a resource.",
        "basis": [
          "CNA",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.blackberry.com/pkb/s/article/141208",
          "host": "support.blackberry.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18107",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T17:53:06.770Z",
      "date_published": "2026-07-28T18:32:37.226Z",
      "date_updated": "2026-07-29T15:25:17.525Z",
      "publisher": "redhat",
      "title": "Criu: criu: container escape via rseq critical section hijack during checkpoint/restore",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01636
      },
      "nvd": {
        "published": "2026-07-28T19:17:32.420",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18107",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CRIU lets an rseq critical-section transition redirect parasite execution while checkpoint credentials are being captured.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18107",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508140",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/checkpoint-restore/criu/pull/3097",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1298,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18140",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T18:30:40.451Z",
      "date_published": "2026-07-30T18:34:04.099Z",
      "date_updated": "2026-07-30T19:12:50.560Z",
      "publisher": "AMZN",
      "title": "Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "aws-smithy-json"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00436,
        "percentile": 0.35893
      },
      "nvd": {
        "published": "2026-07-30T19:17:26.457",
        "lastModified": "2026-07-30T20:17:03.400",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18140",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The unknown-key JSON skip path recurses without a depth bound, allowing a small deeply nested request to exhaust the process stack.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://crates.io/crates/aws-smithy-json/0.62.7",
          "host": "crates.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-067-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/smithy-lang/smithy-rs/security/advisories/GHSA-8ffr-xgwf-xj56",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18141",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T18:47:42.043Z",
      "date_published": "2026-07-31T15:34:16.724Z",
      "date_updated": "2026-07-31T19:00:47.232Z",
      "publisher": "redhat",
      "title": "Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http header",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16556
      },
      "nvd": {
        "published": "2026-07-31T16:17:05.387",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18141",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The gateway trusts a forgeable HTTP Subject header as proof of the mTLS certificate subject instead of binding the identity to the validated peer certificate.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18141",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508155",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 555,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18157",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T20:03:33.510Z",
      "date_published": "2026-07-31T02:38:28.243Z",
      "date_updated": "2026-07-31T15:58:53.619Z",
      "publisher": "redhat",
      "title": "Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution via apt argument injection",
      "affected": {
        "vendors": [
          "Red Hat",
          "RedHatInsights"
        ],
        "products": [
          {
            "vendor": "RedHatInsights",
            "product": "yggdrasil-worker-package-manager"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.1528
      },
      "nvd": {
        "published": "2026-07-31T03:16:25.223",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18157",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A package name beginning with a hyphen is passed to apt-get as an option instead of being separated as data.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18157",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2465250",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/RedHatInsights/yggdrasil-worker-package-manager/commit/959745bb5917c17f0316af199aace6c71baa5ad7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/RedHatInsights/yggdrasil-worker-package-manager/releases/tag/0.1.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/RedHatInsights/yggdrasil-worker-package-manager/releases/tag/0.2.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-18174",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T21:45:18.437Z",
      "date_published": "2026-07-29T13:46:07.361Z",
      "date_updated": "2026-07-29T14:54:22.767Z",
      "publisher": "openjs",
      "title": "@fastify/forwarded vulnerable to improper input validation via unstripped tab characters in X-Forwarded-For",
      "affected": {
        "vendors": [
          "@fastify/forwarded"
        ],
        "products": [
          {
            "vendor": "@fastify/forwarded",
            "product": "@fastify/forwarded"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09205
      },
      "nvd": {
        "published": "2026-07-29T14:16:28.790",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18174",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The forwarded-address parser trims spaces but preserves horizontal tabs, producing a client address that evades exact-match policy keys.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-184"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fastify/forwarded/security/advisories/GHSA-2849-m2w7-xm8f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 844,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-18186",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T01:38:48.878Z",
      "date_published": "2026-07-30T02:44:33.625Z",
      "date_updated": "2026-08-04T07:29:21.773Z",
      "publisher": "ASUSTOR1",
      "title": "A stored format string vulnerability was found in the FTP Backup on the ADM",
      "affected": {
        "vendors": [
          "ASUSTOR Inc."
        ],
        "products": [
          {
            "vendor": "ASUSTOR Inc.",
            "product": "ADM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-134",
          "name": "Use of Externally-Controlled Format String",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@asustor.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00226,
        "percentile": 0.1336
      },
      "nvd": {
        "published": "2026-07-30T03:16:24.213",
        "lastModified": "2026-08-04T14:18:10.873",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18186",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled backup configuration is later reused as a printf-style format string when the task log is processed.",
        "basis": [
          "CNA",
          "CWE-134"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asustor.com/security/security_advisory_detail?id=67",
          "host": "www.asustor.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 509,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-18187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T01:38:52.259Z",
      "date_published": "2026-07-30T02:54:45.595Z",
      "date_updated": "2026-08-04T07:28:39.992Z",
      "publisher": "ASUSTOR1",
      "title": "A format string vulnerability was found in the Internal Backup on the ADM",
      "affected": {
        "vendors": [
          "ASUSTOR Inc."
        ],
        "products": [
          {
            "vendor": "ASUSTOR Inc.",
            "product": "ADM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-134",
          "name": "Use of Externally-Controlled Format String",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@asustor.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13361
      },
      "nvd": {
        "published": "2026-07-30T03:16:24.363",
        "lastModified": "2026-08-04T14:17:56.053",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18187",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ADM passes attacker-controlled text as a format string instead of data, allowing format directives to drive reads, writes, or control flow.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-134"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asustor.com/security/security_advisory_detail?id=67",
          "host": "www.asustor.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-18188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T01:38:53.717Z",
      "date_published": "2026-07-30T02:59:08.566Z",
      "date_updated": "2026-08-04T07:27:32.766Z",
      "publisher": "ASUSTOR1",
      "title": "A format string vulnerability was found in the Rsync Backup on the ADM",
      "affected": {
        "vendors": [
          "ASUSTOR Inc."
        ],
        "products": [
          {
            "vendor": "ASUSTOR Inc.",
            "product": "ADM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-134",
          "name": "Use of Externally-Controlled Format String",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@asustor.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13361
      },
      "nvd": {
        "published": "2026-07-30T03:16:24.503",
        "lastModified": "2026-08-04T14:16:14.717",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-18188",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Rsync backup configuration or log data is supplied as the format string itself instead of as data to a fixed format.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-134"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asustor.com/security/security_advisory_detail?id=67",
          "host": "www.asustor.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-18191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T03:17:15.828Z",
      "date_published": "2026-07-29T06:36:50.243Z",
      "date_updated": "2026-07-29T13:06:02.460Z",
      "publisher": "twcert",
      "title": "Vacron｜IP Camera - Hidden Functionality",
      "affected": {
        "vendors": [
          "Vacron"
        ],
        "products": [
          {
            "vendor": "Vacron",
            "product": "VIN-DS783E-E6"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-912",
          "name": "Hidden Functionality",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00383,
        "percentile": 0.31052
      },
      "nvd": {
        "published": "2026-07-29T08:16:30.223",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18191",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "VIN-DS783E-E6 contains an undocumented remotely reachable function that returns administrator credentials.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-912"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.twcert.org.tw/tw/cp-132-11048-c8ce2-1.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.twcert.org.tw/en/cp-139-11049-db9ae-2.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T03:17:19.870Z",
      "date_published": "2026-07-29T06:40:23.103Z",
      "date_updated": "2026-07-29T13:07:17.966Z",
      "publisher": "twcert",
      "title": "Vacron｜IP Camera - Arbitrary File Read",
      "affected": {
        "vendors": [
          "Vacron"
        ],
        "products": [
          {
            "vendor": "Vacron",
            "product": "VIN-DS783E-E6"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0038,
        "percentile": 0.3077
      },
      "nvd": {
        "published": "2026-07-29T08:16:30.383",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18192",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The camera uses an authenticated request's relative path outside the intended directory and returns the selected system file.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.twcert.org.tw/tw/cp-132-11048-c8ce2-1.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.twcert.org.tw/en/cp-139-11049-db9ae-2.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 186,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18197",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T06:39:52.677Z",
      "date_published": "2026-07-29T06:53:36.040Z",
      "date_updated": "2026-07-29T13:08:57.387Z",
      "publisher": "tenable",
      "title": "Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS).",
      "affected": {
        "vendors": [],
        "products": [
          {
            "vendor": "",
            "product": "Link Library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.1875
      },
      "nvd": {
        "published": "2026-07-29T08:16:30.520",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18197",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Link Library emits attacker-controlled input as active page markup without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wordpress.org/plugins/link-library/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://tenable.com/security/research/tra-2026-52",
          "host": "tenable.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18201",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T07:42:03.892Z",
      "date_published": "2026-07-29T08:34:47.979Z",
      "date_updated": "2026-07-29T13:52:00.409Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: generic identity-provider creation can bind brokers to organizations without manage-organizations",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22049
      },
      "nvd": {
        "published": "2026-07-29T10:16:40.620",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18201",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Keycloak accepts an identity-provider administrator's organization operation without checking the separate organization-management permission.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18201",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508290",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18203",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T07:49:19.596Z",
      "date_published": "2026-07-31T07:08:26.588Z",
      "date_updated": "2026-07-31T23:20:33.733Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10396
      },
      "nvd": {
        "published": "2026-07-31T08:16:27.010",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18203",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Keycloak tests child-group membership with a raw path-prefix comparison, so a sibling group whose name shares the prefix inherits the wrong policy.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18203",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508291",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 453,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18206",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T07:56:25.314Z",
      "date_published": "2026-07-31T07:08:29.626Z",
      "date_updated": "2026-07-31T10:59:36.218Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12093
      },
      "nvd": {
        "published": "2026-07-31T08:16:27.177",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18206",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Keycloak treats any reverse-DNS hostname ending in a configured wildcard suffix as a subdomain, even when no label boundary separates it from the allowed domain.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18206",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508292",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18207",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T08:05:27.596Z",
      "date_published": "2026-07-29T08:34:44.747Z",
      "date_updated": "2026-07-29T14:25:42.823Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: client policy source-group condition bypass via duplicate group name matching",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23608
      },
      "nvd": {
        "published": "2026-07-29T10:16:40.770",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18207",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The client-policy condition compares group names rather than stable group identifiers, so a same-named group elsewhere satisfies the policy.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18207",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18208",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T08:13:24.248Z",
      "date_published": "2026-07-31T07:08:20.512Z",
      "date_updated": "2026-07-31T19:32:57.561Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12767
      },
      "nvd": {
        "published": "2026-07-31T08:16:27.323",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18208",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Token introspection marks a token inactive for the requesting audience but still includes that token's full claims in the signed response.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18208",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508304",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 661,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18209",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T08:19:43.641Z",
      "date_published": "2026-07-31T07:08:31.373Z",
      "date_updated": "2026-07-31T15:58:30.079Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1288",
          "name": "Improper Validation of Consistency within Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09181
      },
      "nvd": {
        "published": "2026-07-31T08:16:27.467",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18209",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-1288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18209",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508305",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 646,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18211",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T08:24:18.687Z",
      "date_published": "2026-07-31T07:08:24.767Z",
      "date_updated": "2026-07-31T14:56:13.354Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08866
      },
      "nvd": {
        "published": "2026-07-31T08:16:27.610",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18211",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Keycloak validates a client URI by string prefix rather than parsing and bounding the host, so a lookalike domain passes the secure-client policy.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18211",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508306",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 555,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18214",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T08:40:32.702Z",
      "date_published": "2026-07-31T07:08:26.652Z",
      "date_updated": "2026-07-31T23:21:31.386Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09935
      },
      "nvd": {
        "published": "2026-07-31T08:16:27.753",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18214",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Google token exchange authenticates the Google account but omits the configured hosted-domain authorization check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18214",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508308",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 433,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18215",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T08:47:14.946Z",
      "date_published": "2026-07-31T06:48:14.687Z",
      "date_updated": "2026-07-31T11:00:46.327Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08618
      },
      "nvd": {
        "published": "2026-07-31T08:16:27.893",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18215",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Microsoft token exchange accepts an identity from a tenant other than the tenant configured by the application.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18215",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508309",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 432,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18217",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T08:54:37.734Z",
      "date_published": "2026-07-31T06:38:25.023Z",
      "date_updated": "2026-07-31T19:32:22.166Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09181
      },
      "nvd": {
        "published": "2026-07-31T08:16:28.037",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18217",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Keycloak preserves attacker query parameters across a SAML HTTP-Redirect flow and appends the legitimate response after them, enabling parameter pollution at the service provider.",
        "basis": [
          "CNA record",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18217",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508311",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 619,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18218",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T09:00:23.659Z",
      "date_published": "2026-07-31T06:38:18.291Z",
      "date_updated": "2026-07-31T15:58:33.955Z",
      "publisher": "redhat",
      "title": "Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Build of Keycloak"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Data Grid 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Single Sign-On 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.0313
      },
      "nvd": {
        "published": "2026-07-31T08:16:28.177",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18218",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Client token revocation is skipped when an older nonzero realm not-before value exists, leaving tokens issued before the client cutoff usable.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18218",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508313",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 579,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T09:38:32.878Z",
      "date_published": "2026-07-29T09:47:51.891Z",
      "date_updated": "2026-07-29T12:12:53.713Z",
      "publisher": "redhat",
      "title": "Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processing",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 23,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.0842
      },
      "nvd": {
        "published": "2026-07-29T11:16:49.097",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18220",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "dlx_rtype_to_howto indexes a non-contiguous relocation table with an unchecked attacker-controlled relocation type and writes out of bounds.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18220",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507670",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1368,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18236",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T13:03:32.303Z",
      "date_published": "2026-07-29T17:37:01.519Z",
      "date_updated": "2026-07-29T18:08:58.347Z",
      "publisher": "Google",
      "title": "Google-ADK Continuation Forgery",
      "affected": {
        "vendors": [
          "Google"
        ],
        "products": [
          {
            "vendor": "Google",
            "product": "Google-ADK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P"
        },
        {
          "source": "NVD:cve-coordination@google.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.1013
      },
      "nvd": {
        "published": "2026-07-29T18:16:52.140",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18236",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ADK accepts a forged tool-confirmation event without checking agent registration, confirmation requirements, or argument equality with the original tool call.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/google/adk-python/commit/c03f333769feaeaa9fe8910fbe95cb9f2d513f54",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18245",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T14:45:04.539Z",
      "date_published": "2026-07-30T18:13:07.047Z",
      "date_updated": "2026-07-30T19:15:12.776Z",
      "publisher": "AMZN",
      "title": "Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "Amplify Codegen UI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00522,
        "percentile": 0.41422
      },
      "nvd": {
        "published": "2026-07-30T19:17:26.610",
        "lastModified": "2026-07-30T20:17:03.733",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18245",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled values are incorporated into generated code without enforcing a safe code-data boundary.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aws-amplify/amplify-codegen-ui/releases/tag/v2.20.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-066-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-74xx-rjgf-m69j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18255",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T16:19:25.998Z",
      "date_published": "2026-07-29T16:34:44.442Z",
      "date_updated": "2026-07-29T18:05:53.353Z",
      "publisher": "redhat",
      "title": "Quay: quay: global read-only superuser can view robot account tokens",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Quay 3"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19362
      },
      "nvd": {
        "published": "2026-07-29T17:16:51.393",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18255",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GLOBAL_READONLY_SUPER_USERS can retrieve robot tokens without repository membership, binding read-only global authority to secrets outside the user's repository scope.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18255",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2508454",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18257",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T16:33:59.899Z",
      "date_published": "2026-07-29T16:34:09.688Z",
      "date_updated": "2026-07-29T18:04:53.132Z",
      "publisher": "GitLab",
      "title": "Improper Certificate Validation in S2OPC",
      "affected": {
        "vendors": [
          "Systerel"
        ],
        "products": [
          {
            "vendor": "Systerel",
            "product": "S2OPC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.00989
      },
      "nvd": {
        "published": "2026-07-29T17:16:51.540",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18257",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The S2OPC certificate-validation path accepts a certificate whose required validity condition has not been established.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/systerel/S2OPC/-/work_items/1804",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18266",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T17:01:32.386Z",
      "date_published": "2026-07-29T19:05:20.221Z",
      "date_updated": "2026-07-29T19:36:20.352Z",
      "publisher": "zdi",
      "title": "Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability",
      "affected": {
        "vendors": [
          "LangGenius"
        ],
        "products": [
          {
            "vendor": "LangGenius",
            "product": "Dify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:zdi-disclosures@trendmicro.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.1559
      },
      "nvd": {
        "published": "2026-07-29T20:17:02.730",
        "lastModified": "2026-07-30T14:19:24.857",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18266",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An OAuth flow accepts a redirect target that is not constrained to the registered callback destination.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-452/",
          "host": "www.zerodayinitiative.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_research-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 597,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18321",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T19:04:09.259Z",
      "date_published": "2026-07-31T18:04:06.697Z",
      "date_updated": "2026-07-31T18:54:10.546Z",
      "publisher": "GitLab",
      "title": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsec",
      "affected": {
        "vendors": [
          "NTPsec"
        ],
        "products": [
          {
            "vendor": "NTPsec",
            "product": "ntpsec"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@gitlab.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00084,
        "percentile": 0.00324
      },
      "nvd": {
        "published": "2026-07-31T19:17:08.183",
        "lastModified": "2026-07-31T19:17:08.183",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18321",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NTPsec copies attacker-controlled Zyfer data beyond a fixed-size buffer.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/NTPsec/ntpsec/-/work_items/890",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 78,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T07:10:40.527Z",
      "date_published": "2026-07-30T07:23:04.083Z",
      "date_updated": "2026-07-30T13:02:36.576Z",
      "publisher": "eclipse",
      "title": "Unauthenticated SSRF in PIA via OIDC issuer allowlist bypass",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse CSI - PIA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15115
      },
      "nvd": {
        "published": "2026-07-30T08:16:28.887",
        "lastModified": "2026-07-30T19:12:22.607",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18353",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PIA validates the unverified JWT iss value with urlparse, then requests OIDC metadata with parsers that interpret a backslash-containing authority differently, so an allowlisted-looking issuer can redirect discovery to an attacker-selected host.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/eclipse-csi/pia/security/advisories/GHSA-v249-9xjm-qhgf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 591,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18358",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T08:33:03.012Z",
      "date_published": "2026-07-31T12:20:23.371Z",
      "date_updated": "2026-07-31T19:53:58.071Z",
      "publisher": "redhat",
      "title": "Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of service",
      "affected": {
        "vendors": [
          "GNOME",
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "GNOME",
            "product": "gnome-remote-desktop"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00428,
        "percentile": 0.35216
      },
      "nvd": {
        "published": "2026-07-31T13:17:19.933",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18358",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18358",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2462876",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18360",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T08:40:36.639Z",
      "date_published": "2026-07-30T09:41:18.762Z",
      "date_updated": "2026-07-30T13:04:26.091Z",
      "publisher": "sba-research",
      "title": "DFIR-IRIS Stored XSS in Custom Attributes",
      "affected": {
        "vendors": [
          "dfir-iris"
        ],
        "products": [
          {
            "vendor": "dfir-iris",
            "product": "iris-web"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18753
      },
      "nvd": {
        "published": "2026-07-30T10:16:36.343",
        "lastModified": "2026-07-30T16:45:56.833",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18360",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260126-01_DFIR-IRIS_Stored_XSS",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18361",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T08:40:37.983Z",
      "date_published": "2026-07-30T09:42:25.721Z",
      "date_updated": "2026-07-30T13:05:18.145Z",
      "publisher": "sba-research",
      "title": "DFIR-IRIS Stored XSS in Datastore Upload",
      "affected": {
        "vendors": [
          "dfir-iris"
        ],
        "products": [
          {
            "vendor": "dfir-iris",
            "product": "iris-web"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18752
      },
      "nvd": {
        "published": "2026-07-30T10:16:36.460",
        "lastModified": "2026-07-30T16:45:56.833",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18361",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260126-01_DFIR-IRIS_Stored_XSS",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18362",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T08:40:38.927Z",
      "date_published": "2026-07-30T09:44:32.085Z",
      "date_updated": "2026-07-30T12:27:19.675Z",
      "publisher": "sba-research",
      "title": "DFIR-IRIS Missing Brute Force Protection in User Authentication",
      "affected": {
        "vendors": [
          "dfir-iris"
        ],
        "products": [
          {
            "vendor": "dfir-iris",
            "product": "iris-web"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00357,
        "percentile": 0.28452
      },
      "nvd": {
        "published": "2026-07-30T10:16:36.580",
        "lastModified": "2026-07-30T16:45:56.833",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18362",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The authentication endpoint imposes no effective attempt or rate bound, allowing a remote client to run password guesses continuously.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sbaresearch/advisories/tree/public/2026/SBA-ADV-20260128-02_DFIR-IRIS_Missing_Brute_Force_Protection",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18363",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T08:57:33.496Z",
      "date_published": "2026-07-30T10:35:26.170Z",
      "date_updated": "2026-07-30T12:20:40.629Z",
      "publisher": "INCIBE",
      "title": "Weak password recovery mechanism in osTicket by Enhancesoft LLC",
      "affected": {
        "vendors": [
          "Enhancesoft LLC"
        ],
        "products": [
          {
            "vendor": "Enhancesoft LLC",
            "product": "osTicket"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cve-coordination@incibe.es",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.2212
      },
      "nvd": {
        "published": "2026-07-30T11:16:26.220",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18363",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The password-reset routine performs the expiry test only when token timestamp lookup fails, so an existing token timestamp bypasses expiration enforcement.",
        "basis": [
          "CNA",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/weak-password-recovery-mechanism-osticket-enhancesoft-llc",
          "host": "www.incibe.es",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-18369",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T09:59:47.272Z",
      "date_published": "2026-07-30T10:32:23.364Z",
      "date_updated": "2026-07-30T13:43:57.707Z",
      "publisher": "redhat",
      "title": "Dogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip literal identifiers and unvalidated redirects",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Certificate System 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Certificate System 11"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Certificate System 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.0939
      },
      "nvd": {
        "published": "2026-07-30T11:16:26.973",
        "lastModified": "2026-07-30T14:16:57.177",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18369",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ACME validator accepts IP literals as DNS identifiers and follows redirects without rechecking that each destination is public.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18369",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509234",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T11:01:08.520Z",
      "date_published": "2026-07-30T12:00:27.382Z",
      "date_updated": "2026-07-31T22:49:03.326Z",
      "publisher": "redhat",
      "title": "Project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secret token exfiltration via user-controlled api_url (ssrf / confused deputy)",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Cost Management Metrics Operator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15029
      },
      "nvd": {
        "published": "2026-07-30T12:17:27.553",
        "lastModified": "2026-07-31T23:17:23.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18378",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A user-editable upload URL receives the cluster-wide bearer token because the operator does not bind that credential to the trusted Red Hat endpoint.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18378",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509249",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18381",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T11:37:06.496Z",
      "date_published": "2026-07-30T12:00:05.482Z",
      "date_updated": "2026-07-30T12:14:46.389Z",
      "publisher": "redhat",
      "title": "Project-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token exfiltration via user-controlled prometheus service_address",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Cost Management Metrics Operator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09615
      },
      "nvd": {
        "published": "2026-07-30T12:17:27.693",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18381",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operator sends its own service-account bearer token to an upload URL supplied through a user-editable custom resource.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18381",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509251",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T11:46:08.800Z",
      "date_published": "2026-07-30T12:00:29.961Z",
      "date_updated": "2026-07-30T13:05:36.789Z",
      "publisher": "redhat",
      "title": "Project-koku/koku-metrics-operator: koku-metrics-operator: service-account client credentials sent to user-controlled token_url",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Cost Management Metrics Operator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20269
      },
      "nvd": {
        "published": "2026-07-30T12:17:27.827",
        "lastModified": "2026-07-30T14:16:57.307",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18382",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operator sends its service-account client ID and secret to an OAuth token URL controlled by the custom-resource author.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-18382",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509253",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 383,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-18394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T14:47:05.047Z",
      "date_published": "2026-07-31T19:34:15.007Z",
      "date_updated": "2026-07-31T20:01:07.095Z",
      "publisher": "AMZN",
      "title": "Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "Strands Agents Tools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21669
      },
      "nvd": {
        "published": "2026-07-31T20:16:49.780",
        "lastModified": "2026-08-04T14:48:22.933",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18394",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The http_request tool can route credential-bearing traffic through an actor-controlled proxy without binding the token to an authorized destination.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/strands-agents/tools/releases/tag/v0.8.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-069-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/strands-agents/tools/security/advisories/GHSA-qhw6-2h72-m84v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T20:11:46.469Z",
      "date_published": "2026-07-31T08:30:15.838Z",
      "date_updated": "2026-07-31T10:53:34.281Z",
      "publisher": "Wordfence",
      "title": "MailerPress <= 1.5.0 - Missing Authorization to Unauthenticated Arbitrary Modification via REST API Endpoint",
      "affected": {
        "vendors": [
          "mailerpress"
        ],
        "products": [
          {
            "vendor": "mailerpress",
            "product": "MailerPress – Newsletter, email marketing & AI automation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13524
      },
      "nvd": {
        "published": "2026-07-31T10:16:45.020",
        "lastModified": "2026-07-31T11:17:07.307",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18436",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/793a7ef0-8938-47a6-80ed-83f69fbbb27f?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mailerpress/trunk/src/Api/CampaignRevisions.php#L156",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mailerpress/trunk/src/Api/CampaignRevisions.php#L155",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18437",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T20:21:38.396Z",
      "date_published": "2026-07-31T08:30:15.331Z",
      "date_updated": "2026-07-31T14:50:17.110Z",
      "publisher": "Wordfence",
      "title": "MailPress <= 1.5.0 - Missing Authorization to Unauthenticated Contact Updates",
      "affected": {
        "vendors": [
          "mailerpress"
        ],
        "products": [
          {
            "vendor": "mailerpress",
            "product": "MailerPress – Newsletter, email marketing & AI automation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@wordfence.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00297,
        "percentile": 0.21946
      },
      "nvd": {
        "published": "2026-07-31T10:16:45.157",
        "lastModified": "2026-07-31T16:17:05.980",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18437",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MailerPress – Newsletter, email marketing & AI automation fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/159d031b-0362-4625-9d98-3908401c8ee8?source=cve",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mailerpress/trunk/src/Api/Contacts.php#L847",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mailerpress/trunk/src/Api/Contacts.php#L801",
          "host": "plugins.trac.wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18446",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T22:28:08.097Z",
      "date_published": "2026-07-31T14:37:01.584Z",
      "date_updated": "2026-07-31T17:47:35.325Z",
      "publisher": "openjs",
      "title": "fast-uri vulnerable to host confusion via backslash authority introducer",
      "affected": {
        "vendors": [
          "fast-uri"
        ],
        "products": [
          {
            "vendor": "fast-uri",
            "product": "fast-uri"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:ce714d77-add3-4f53-aff5-83d477b104bb",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12781
      },
      "nvd": {
        "published": "2026-07-31T15:16:27.983",
        "lastModified": "2026-07-31T18:17:13.383",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18446",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "fast-uri and Node treat backslashes differently when locating a URL authority, so a policy check and the eventual request resolve the same string to different hosts.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-436"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://cna.openjsf.org/security-advisories.html",
          "host": "cna.openjsf.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 754,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-18452",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-31T05:43:34.083Z",
      "date_published": "2026-07-31T05:54:55.052Z",
      "date_updated": "2026-07-31T19:25:00.663Z",
      "publisher": "twcert",
      "title": "Rich Source｜DMS+ (Non-Mobile) - Use of Hard-coded Credentials",
      "affected": {
        "vendors": [
          "Rich Source"
        ],
        "products": [
          {
            "vendor": "Rich Source",
            "product": "DMS+ (Non-Mobile)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:twcert@cert.org.tw",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35523
      },
      "nvd": {
        "published": "2026-07-31T07:16:27.400",
        "lastModified": "2026-07-31T20:16:49.927",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18452",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DMS+ (Non-Mobile) uses one fixed credential across installations, allowing anyone who knows it to authenticate to every device.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.twcert.org.tw/tw/cp-132-11072-3a4d4-1.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.twcert.org.tw/en/cp-139-11073-de184-2.html",
          "host": "www.twcert.org.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-18481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-31T12:40:04.618Z",
      "date_published": "2026-07-31T18:12:23.067Z",
      "date_updated": "2026-07-31T19:52:59.881Z",
      "publisher": "AMZN",
      "title": "Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft",
      "affected": {
        "vendors": [
          "AWS"
        ],
        "products": [
          {
            "vendor": "AWS",
            "product": "AWS Ops Wheel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ff89ba41-3aa1-4d27-914a-91399e9639e5",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20417
      },
      "nvd": {
        "published": "2026-07-31T19:17:08.347",
        "lastModified": "2026-08-04T14:48:22.933",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-18481",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AWS Ops Wheel accepts a dangerous URI scheme in participant_url and later renders it as an executable browser navigation target.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://aws.amazon.com/security/security-bulletins/2026-068-aws/",
          "host": "aws.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/aws/aws-ops-wheel/pull/168",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/aws/aws-ops-wheel/security/advisories/GHSA-6rr8-cf9x-pj23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 395,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-20146",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.384Z",
      "date_published": "2026-07-15T16:17:30.420Z",
      "date_updated": "2026-07-15T17:58:15.091Z",
      "publisher": "cisco",
      "title": "Cisco Identity Services Engine Path Traversal Vulnerability",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco Identity Services Engine Software"
          },
          {
            "vendor": "Cisco",
            "product": "Cisco ISE Passive Identity Connector"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 47,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26646
      },
      "nvd": {
        "published": "2026-07-15T17:16:46.970",
        "lastModified": "2026-07-16T14:03:27.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20146",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 657,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 47
      }
    },
    {
      "cve_id": "CVE-2026-20150",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.385Z",
      "date_published": "2026-07-15T16:17:00.370Z",
      "date_updated": "2026-07-15T18:46:29.743Z",
      "publisher": "cisco",
      "title": "Cisco RoomOS Security Hardening Release - Access Control Vulnerabilities",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco RoomOS Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 68,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12926
      },
      "nvd": {
        "published": "2026-07-15T17:16:47.110",
        "lastModified": "2026-07-15T19:16:59.990",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20150",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Cisco groups several access-control defects under one record without publishing the individual caller, object, or permission checks that fail.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 456,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 68
      }
    },
    {
      "cve_id": "CVE-2026-20153",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.386Z",
      "date_published": "2026-07-15T16:18:14.073Z",
      "date_updated": "2026-07-15T18:06:37.684Z",
      "publisher": "cisco",
      "title": "Cisco RoomOS Security Hardening Release - Input Validation Vulnerabilities",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco RoomOS Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 68,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16641
      },
      "nvd": {
        "published": "2026-07-15T17:16:47.247",
        "lastModified": "2026-07-15T19:17:00.473",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20153",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Cisco groups several internal RoomOS input-validation fixes under one record without publishing the inputs, parsers, checks, or individual failure paths.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 68
      }
    },
    {
      "cve_id": "CVE-2026-20156",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.387Z",
      "date_published": "2026-07-15T16:17:52.307Z",
      "date_updated": "2026-07-15T18:05:46.644Z",
      "publisher": "cisco",
      "title": "Cisco RoomOS Security Hardening Release - Buffer Management Vulnerabilities",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco RoomOS Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 68,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13714
      },
      "nvd": {
        "published": "2026-07-15T17:16:47.380",
        "lastModified": "2026-07-15T19:17:00.933",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20156",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Cisco groups multiple buffer-boundary vulnerabilities under one CVE without identifying a common length, allocation, or access operation.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 499,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 68
      }
    },
    {
      "cve_id": "CVE-2026-20157",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.387Z",
      "date_published": "2026-07-15T16:18:04.406Z",
      "date_updated": "2026-07-15T18:06:16.748Z",
      "publisher": "cisco",
      "title": "Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco RoomOS Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 68,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-311",
          "name": "Missing Encryption of Sensitive Data",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00061,
        "percentile": 0.00012
      },
      "nvd": {
        "published": "2026-07-15T17:16:47.507",
        "lastModified": "2026-07-15T19:17:01.390",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20157",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "RoomOS leaves one or more security-relevant data paths unencrypted, but the affected channel and key lifecycle are not public.",
        "basis": [
          "CNA",
          "CWE-311"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 446,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 68
      }
    },
    {
      "cve_id": "CVE-2026-20158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.387Z",
      "date_published": "2026-07-15T16:18:27.994Z",
      "date_updated": "2026-07-15T18:07:02.708Z",
      "publisher": "cisco",
      "title": "Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulnerabilities",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco RoomOS Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 68,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-664",
          "name": "Improper Control of a Resource Through its Lifetime",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16641
      },
      "nvd": {
        "published": "2026-07-15T17:16:47.640",
        "lastModified": "2026-07-15T19:17:01.807",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20158",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Cisco record supplies only a generic resource-lifetime weakness and impact without a concrete object, release error, or bound.",
        "basis": [
          "CNA",
          "CWE-664"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 479,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 68
      }
    },
    {
      "cve_id": "CVE-2026-20187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.394Z",
      "date_published": "2026-07-15T16:18:37.525Z",
      "date_updated": "2026-07-15T18:05:01.949Z",
      "publisher": "cisco",
      "title": "Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vulnerabilities",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco RoomOS Software"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 67,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-703",
          "name": "Improper Check or Handling of Exceptional Conditions",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16642
      },
      "nvd": {
        "published": "2026-07-15T17:16:47.770",
        "lastModified": "2026-07-15T19:17:08.807",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20187",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record groups multiple exceptional-condition defects and does not identify any individual failing check, state transition, or resource rule.",
        "basis": [
          "CNA record",
          "CWE-703"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 471,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 67
      }
    },
    {
      "cve_id": "CVE-2026-20191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.395Z",
      "date_published": "2026-07-01T16:27:32.642Z",
      "date_updated": "2026-07-01T17:25:09.294Z",
      "publisher": "cisco",
      "title": "Cisco Catalyst Center Arbitrary File Read Vulnerability",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco Catalyst Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 17,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00919,
        "percentile": 0.56806
      },
      "nvd": {
        "published": "2026-07-01T17:16:29.330",
        "lastModified": "2026-07-01T18:16:30.850",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20191",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Cisco Catalyst Center accepts an attacker-controlled path that can resolve outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-file-read-wLH2vf8X",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 451,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-20213",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.398Z",
      "date_published": "2026-07-01T16:27:38.657Z",
      "date_updated": "2026-07-01T17:25:08.998Z",
      "publisher": "cisco",
      "title": "ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco Secure Endpoint"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 146,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00563,
        "percentile": 0.43618
      },
      "nvd": {
        "published": "2026-07-01T17:16:29.460",
        "lastModified": "2026-07-09T17:56:55.537",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20213",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ClamAV PE parser omits a content-boundary check and writes beyond its buffer while scanning a crafted file.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 667,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 146
      }
    },
    {
      "cve_id": "CVE-2026-20214",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.398Z",
      "date_published": "2026-07-01T16:27:33.622Z",
      "date_updated": "2026-07-01T17:25:09.148Z",
      "publisher": "cisco",
      "title": "ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco Secure Endpoint"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 146,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00563,
        "percentile": 0.4362
      },
      "nvd": {
        "published": "2026-07-01T17:16:29.637",
        "lastModified": "2026-07-09T17:57:33.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20214",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ClamAV FSG parser copies crafted compressed-file content without validating it against the destination bound, causing an out-of-bounds write.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 706,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 146
      }
    },
    {
      "cve_id": "CVE-2026-20215",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.398Z",
      "date_published": "2026-07-01T16:28:09.844Z",
      "date_updated": "2026-07-01T17:25:08.547Z",
      "publisher": "cisco",
      "title": "ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco Secure Endpoint"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 146,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.005,
        "percentile": 0.40079
      },
      "nvd": {
        "published": "2026-07-01T17:16:29.807",
        "lastModified": "2026-07-09T17:57:16.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20215",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A copy into a fixed memory region proceeds without a sufficient input-size check, allowing the destination bounds to be exceeded.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 672,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 146
      }
    },
    {
      "cve_id": "CVE-2026-20216",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.398Z",
      "date_published": "2026-07-01T16:27:51.314Z",
      "date_updated": "2026-07-01T17:25:08.850Z",
      "publisher": "cisco",
      "title": "ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco Secure Endpoint"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 146,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.005,
        "percentile": 0.40078
      },
      "nvd": {
        "published": "2026-07-01T17:16:29.973",
        "lastModified": "2026-07-09T18:09:19.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20216",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The InstallShield scanner does not bound or promptly release temporary resources created for a crafted file, allowing the scan to consume available system resources.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 146
      }
    },
    {
      "cve_id": "CVE-2026-20217",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.398Z",
      "date_published": "2026-07-01T16:28:03.720Z",
      "date_updated": "2026-07-01T17:25:08.697Z",
      "publisher": "cisco",
      "title": "ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco Secure Endpoint"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 146,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.005,
        "percentile": 0.40078
      },
      "nvd": {
        "published": "2026-07-01T17:16:30.130",
        "lastModified": "2026-07-09T18:07:46.497",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20217",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Cisco Secure Endpoint path writes attacker-influenced data beyond the capacity of its destination buffer.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 679,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 146
      }
    },
    {
      "cve_id": "CVE-2026-20243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.400Z",
      "date_published": "2026-07-01T16:30:20.848Z",
      "date_updated": "2026-07-01T17:25:08.088Z",
      "publisher": "cisco",
      "title": "ClamAV ALZ Archive Processing Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco Secure Endpoint"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 146,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.005,
        "percentile": 0.40079
      },
      "nvd": {
        "published": "2026-07-01T17:16:30.423",
        "lastModified": "2026-07-09T18:03:17.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20243",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Missing ALZ boundary checks allow a crafted input to write beyond the allocated buffer.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 670,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 146
      }
    },
    {
      "cve_id": "CVE-2026-20244",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.400Z",
      "date_published": "2026-07-01T16:28:27.613Z",
      "date_updated": "2026-07-01T17:25:08.394Z",
      "publisher": "cisco",
      "title": "ClamAV DMG File Processing Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco Secure Endpoint"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 146,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.005,
        "percentile": 0.40079
      },
      "nvd": {
        "published": "2026-07-01T17:16:30.593",
        "lastModified": "2026-07-09T18:00:43.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20244",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Cisco Secure Endpoint path processes attacker-controlled data without a sufficient memory-boundary check.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 685,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 146
      }
    },
    {
      "cve_id": "CVE-2026-20296",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.407Z",
      "date_published": "2026-07-15T17:18:23.696Z",
      "date_updated": "2026-07-16T03:55:54.695Z",
      "publisher": "cisco",
      "title": "SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise",
      "affected": {
        "vendors": [
          "Splunk"
        ],
        "products": [
          {
            "vendor": "Splunk",
            "product": "Splunk Enterprise"
          },
          {
            "vendor": "Splunk",
            "product": "Splunk Cloud Platform"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13825
      },
      "nvd": {
        "published": "2026-07-15T18:16:44.740",
        "lastModified": "2026-07-24T18:18:34.027",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20296",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A cross-site request can cause Splunk to perform a privileged role-management action using the victim's authenticated session.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://advisory.splunk.com/advisories/SVD-2026-0702",
          "host": "advisory.splunk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 700,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-20297",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.407Z",
      "date_published": "2026-07-15T17:18:13.390Z",
      "date_updated": "2026-07-16T03:55:53.915Z",
      "publisher": "cisco",
      "title": "Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise",
      "affected": {
        "vendors": [
          "Splunk"
        ],
        "products": [
          {
            "vendor": "Splunk",
            "product": "Splunk Enterprise"
          },
          {
            "vendor": "Splunk",
            "product": "Splunk Cloud Platform"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00481,
        "percentile": 0.38925
      },
      "nvd": {
        "published": "2026-07-15T18:16:44.880",
        "lastModified": "2026-07-24T18:17:00.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20297",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Splunk app installation fails to confine archive paths to the selected app directory, allowing a privileged app installer to write into $SPLUNK_HOME/etc and its subdirectories.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://advisory.splunk.com/advisories/SVD-2026-0703",
          "host": "advisory.splunk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 578,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-20298",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.407Z",
      "date_published": "2026-07-15T17:18:32.070Z",
      "date_updated": "2026-07-16T03:55:51.583Z",
      "publisher": "cisco",
      "title": "Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise",
      "affected": {
        "vendors": [
          "Splunk"
        ],
        "products": [
          {
            "vendor": "Splunk",
            "product": "Splunk Enterprise"
          },
          {
            "vendor": "Splunk",
            "product": "Splunk Cloud Platform"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14028
      },
      "nvd": {
        "published": "2026-07-15T18:16:44.993",
        "lastModified": "2026-07-24T18:11:49.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20298",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A low-privileged Splunk user can query credential hashes through a REST operation that lacks the required role restriction.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://advisory.splunk.com/advisories/SVD-2026-0704",
          "host": "advisory.splunk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 597,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-20316",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-10-08T11:59:15.410Z",
      "date_published": "2026-07-29T16:22:08.888Z",
      "date_updated": "2026-08-01T03:55:31.477Z",
      "publisher": "cisco",
      "title": "Cisco Secure Firewall Management Center Software Static Credential Vulnerability",
      "affected": {
        "vendors": [
          "Cisco"
        ],
        "products": [
          {
            "vendor": "Cisco",
            "product": "Cisco Secure Firewall Management Center (FMC)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 67,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-259",
          "name": "Use of Hard-coded Password",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@cisco.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00788,
        "percentile": 0.52668
      },
      "official_kev": {
        "cveID": "CVE-2026-20316",
        "vendorProject": "Cisco",
        "product": "Secure Firewall Management Center (FMC)",
        "vulnerabilityName": "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability",
        "dateAdded": "2026-07-29",
        "shortDescription": "Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-08-01",
        "knownRansomwareCampaignUse": "Unknown",
        "notes": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20316",
        "cwes": [
          "CWE-259"
        ]
      },
      "nvd": {
        "published": "2026-07-29T17:16:51.840",
        "lastModified": "2026-08-01T05:16:55.973",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20316",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FMC ships a reusable static password for a low-privilege web account, allowing an unauthenticated remote party to log in as that account.",
        "basis": [
          "CNA",
          "CWE-259",
          "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh"
        ],
        "deepDive": true,
        "notes": "Reviewed https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh. Cisco confirms a static low-privilege web credential, active exploitation, fixed hotfixes, and an IOC path; it does not publish the credential or its creation code."
      },
      "references": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh",
          "host": "sec.cloudapps.cisco.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1023,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 67
      }
    },
    {
      "cve_id": "CVE-2026-20457",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T01:30:59.014Z",
      "date_published": "2026-07-01T03:13:58.305Z",
      "date_updated": "2026-07-01T10:40:26.558Z",
      "publisher": "MediaTek",
      "title": "In Modem, there is a possible system crash due to improper input validation.",
      "affected": {
        "vendors": [
          "MediaTek, Inc."
        ],
        "products": [
          {
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 59,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.08039
      },
      "nvd": {
        "published": "2026-07-01T04:17:13.100",
        "lastModified": "2026-07-01T18:16:00.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20457",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The structured record maps the modem crash to a null-pointer dereference, while the public description does not identify the malformed field or dereference site.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://corp.mediatek.com/product-security-bulletin/July-2026",
          "host": "corp.mediatek.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 59
      }
    },
    {
      "cve_id": "CVE-2026-20458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T01:30:59.014Z",
      "date_published": "2026-07-01T03:13:59.663Z",
      "date_updated": "2026-07-02T03:55:19.970Z",
      "publisher": "MediaTek",
      "title": "In Modem, there is a possible memory corruption due to a missing bounds check.",
      "affected": {
        "vendors": [
          "MediaTek, Inc."
        ],
        "products": [
          {
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 64,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10593
      },
      "nvd": {
        "published": "2026-07-01T04:17:13.943",
        "lastModified": "2026-07-02T05:16:40.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20458",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled input reaches a write whose destination boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://corp.mediatek.com/product-security-bulletin/July-2026",
          "host": "corp.mediatek.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 64
      }
    },
    {
      "cve_id": "CVE-2026-20459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T01:30:59.014Z",
      "date_published": "2026-07-01T03:14:00.977Z",
      "date_updated": "2026-07-01T10:39:19.025Z",
      "publisher": "MediaTek",
      "title": "In Modem, there is a possible system crash due to improper input validation.",
      "affected": {
        "vendors": [
          "MediaTek, Inc."
        ],
        "products": [
          {
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 83,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06524
      },
      "nvd": {
        "published": "2026-07-01T04:17:14.247",
        "lastModified": "2026-07-01T18:16:00.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20459",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The modem bulletin reports a crash from invalid rogue-base-station input but does not disclose the malformed field, parser state, or resource failure.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://corp.mediatek.com/product-security-bulletin/July-2026",
          "host": "corp.mediatek.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 83
      }
    },
    {
      "cve_id": "CVE-2026-20460",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T01:30:59.014Z",
      "date_published": "2026-07-01T03:14:02.293Z",
      "date_updated": "2026-07-01T10:39:34.250Z",
      "publisher": "MediaTek",
      "title": "In Modem, there is a possible information disclosure due to improper input validation.",
      "affected": {
        "vendors": [
          "MediaTek, Inc."
        ],
        "products": [
          {
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 67,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07105
      },
      "nvd": {
        "published": "2026-07-01T04:17:15.017",
        "lastModified": "2026-07-01T18:16:00.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20460",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A rogue base station can reach an alternate modem path that discloses information, but the public bulletin does not identify the failing input or trust check.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://corp.mediatek.com/product-security-bulletin/July-2026",
          "host": "corp.mediatek.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 351,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 67
      }
    },
    {
      "cve_id": "CVE-2026-20461",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T01:30:59.014Z",
      "date_published": "2026-07-01T03:14:03.686Z",
      "date_updated": "2026-07-01T10:39:51.662Z",
      "publisher": "MediaTek",
      "title": "In Modem, there is a possible out of bounds write due to a missing bounds check.",
      "affected": {
        "vendors": [
          "MediaTek, Inc."
        ],
        "products": [
          {
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 33,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07826
      },
      "nvd": {
        "published": "2026-07-01T04:17:15.130",
        "lastModified": "2026-07-01T18:16:00.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20461",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The modem writes attacker-controlled data without a bounds check when processing traffic from a rogue base station.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://corp.mediatek.com/product-security-bulletin/July-2026",
          "host": "corp.mediatek.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 33
      }
    },
    {
      "cve_id": "CVE-2026-20462",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T01:30:59.014Z",
      "date_published": "2026-07-01T03:14:04.991Z",
      "date_updated": "2026-07-02T03:55:17.558Z",
      "publisher": "MediaTek",
      "title": "In Telephony, there is a possible memory corruption due to a heap buffer overflow.",
      "affected": {
        "vendors": [
          "MediaTek, Inc."
        ],
        "products": [
          {
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 22,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00111,
        "percentile": 0.01532
      },
      "nvd": {
        "published": "2026-07-01T04:17:15.253",
        "lastModified": "2026-07-02T05:16:40.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20462",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Telephony writes beyond a heap allocation while processing local privileged input, corrupting adjacent memory.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://corp.mediatek.com/product-security-bulletin/July-2026",
          "host": "corp.mediatek.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 22
      }
    },
    {
      "cve_id": "CVE-2026-20463",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-03T01:30:59.015Z",
      "date_published": "2026-07-01T03:14:06.372Z",
      "date_updated": "2026-07-02T03:55:18.676Z",
      "publisher": "MediaTek",
      "title": "In Modem, there is a possible escalation of privilege due to a permissions bypass.",
      "affected": {
        "vendors": [
          "MediaTek, Inc."
        ],
        "products": [
          {
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 83,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-280",
          "name": "Improper Handling of Insufficient Permissions or Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0011,
        "percentile": 0.01478
      },
      "nvd": {
        "published": "2026-07-01T04:17:15.553",
        "lastModified": "2026-07-02T05:16:40.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20463",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MediaTek chipset operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-280"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://corp.mediatek.com/product-security-bulletin/July-2026",
          "host": "corp.mediatek.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 83
      }
    },
    {
      "cve_id": "CVE-2026-20672",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-11-11T14:43:07.866Z",
      "date_published": "2026-07-27T20:14:55.414Z",
      "date_updated": "2026-07-28T14:18:55.216Z",
      "publisher": "apple",
      "title": "An information disclosure issue was addressed with improved privacy controls.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02279
      },
      "nvd": {
        "published": "2026-07-27T21:16:48.740",
        "lastModified": "2026-07-29T15:03:12.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-20672",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Apple states that an app can access sensitive user data but does not disclose the failing privacy control or data path.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-20706",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:59.955Z",
      "date_published": "2026-07-03T20:19:28.868Z",
      "date_updated": "2026-07-06T18:34:55.061Z",
      "publisher": "Gitea",
      "title": "Gitea repository archive downloads bypass token scope checks",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00493,
        "percentile": 0.39659
      },
      "nvd": {
        "published": "2026-07-03T21:16:56.433",
        "lastModified": "2026-07-06T19:17:00.120",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20706",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The web archive endpoint serves repository contents without applying the access-token scope required for that archive operation.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-cr4g-f395-h25h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/37735",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.2/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 143,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-20744",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-27T23:33:47.834Z",
      "date_published": "2026-07-10T22:07:23.971Z",
      "date_updated": "2026-07-14T14:34:32.306Z",
      "publisher": "icscert",
      "title": "Hydro-Québec Le Circuit Electrique charging station backend Improper Access Control",
      "affected": {
        "vendors": [
          "Hydro-Québec"
        ],
        "products": [
          {
            "vendor": "Hydro-Québec",
            "product": "Le Circuit Electrique charging station backend"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00562,
        "percentile": 0.43534
      },
      "nvd": {
        "published": "2026-07-10T23:16:47.683",
        "lastModified": "2026-07-14T15:17:01.300",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20744",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Le Circuit Electrique charging station backend fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.hydroquebec.com/nous-joindre/",
          "host": "www.hydroquebec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-01.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 133,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-20779",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:26:00.104Z",
      "date_published": "2026-07-03T20:19:29.239Z",
      "date_updated": "2026-07-07T17:00:54.312Z",
      "publisher": "Gitea",
      "title": "Gitea TOTP single-use enforcement defect allows OTP replay",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00398,
        "percentile": 0.32601
      },
      "nvd": {
        "published": "2026-07-03T21:16:56.543",
        "lastModified": "2026-07-07T18:16:35.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20779",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Gitea does not record and reject a TOTP value after its first successful use, allowing the same code to be replayed across authentication paths.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-gx3v-q759-g323",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38151",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-20896",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:59.988Z",
      "date_published": "2026-07-03T20:19:29.588Z",
      "date_updated": "2026-07-07T17:00:46.549Z",
      "publisher": "Gitea",
      "title": "Gitea Docker image trusts spoofable reverse-proxy headers by default",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.31809,
        "percentile": 0.98125
      },
      "nvd": {
        "published": "2026-07-03T21:16:56.660",
        "lastModified": "2026-07-07T18:16:35.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20896",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "The Gitea Docker template sets every source as a trusted reverse proxy, so a direct client can supply X-WEBAUTH-USER and be treated as that user.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284",
          "Vendor advisory",
          "Vulnerable source",
          "Fixed source"
        ],
        "deepDive": true,
        "notes": "Read https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4 plus vulnerable and fixed source at https://raw.githubusercontent.com/go-gitea/gitea/v1.26.2/docker/root/etc/templates/app.ini and https://raw.githubusercontent.com/go-gitea/gitea/v1.26.3/docker/root/etc/templates/app.ini; the fixed template removes the image-level trust-all proxy overrides."
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38151",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-20909",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-22T15:13:33.704Z",
      "date_published": "2026-07-03T20:19:29.943Z",
      "date_updated": "2026-07-07T17:00:40.149Z",
      "publisher": "Gitea",
      "title": "Gitea tracked-time list endpoint has insufficient permission checks",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20826
      },
      "nvd": {
        "published": "2026-07-03T21:16:56.777",
        "lastModified": "2026-07-07T18:16:35.477",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-20909",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gitea lists tracked-time entries without applying the permission check required for the requested issue or repository.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36662",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36744",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21039",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.808Z",
      "date_published": "2026-07-10T04:58:00.790Z",
      "date_updated": "2026-07-10T15:17:27.349Z",
      "publisher": "SamsungMobile",
      "title": "Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01238
      },
      "nvd": {
        "published": "2026-07-10T05:16:34.387",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21039",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Samsung Settings allows a local caller to change Theft Protection settings without the required authority, but the missing check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21040",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.815Z",
      "date_published": "2026-07-10T04:58:01.879Z",
      "date_updated": "2026-07-10T14:30:55.833Z",
      "publisher": "SamsungMobile",
      "title": "Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00099,
        "percentile": 0.00965
      },
      "nvd": {
        "published": "2026-07-10T05:16:34.530",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21040",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "IAFDService exposes privileged APIs to a local caller outside the intended authority, while the exact API and role check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21041",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.815Z",
      "date_published": "2026-07-10T04:58:03.043Z",
      "date_updated": "2026-07-10T14:31:30.930Z",
      "publisher": "SamsungMobile",
      "title": "Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01238
      },
      "nvd": {
        "published": "2026-07-10T05:16:34.663",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21041",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "SamsungSEAgentService permits a local caller outside the intended access boundary to read sensitive information.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21042",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.815Z",
      "date_published": "2026-07-10T04:58:04.139Z",
      "date_updated": "2026-07-11T03:55:21.047Z",
      "publisher": "SamsungMobile",
      "title": "Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01899
      },
      "nvd": {
        "published": "2026-07-10T05:16:34.797",
        "lastModified": "2026-07-11T05:16:33.163",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21042",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21043",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.816Z",
      "date_published": "2026-07-10T04:58:05.222Z",
      "date_updated": "2026-07-11T03:55:20.258Z",
      "publisher": "SamsungMobile",
      "title": "Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system server privilege.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-35",
          "name": "Path Traversal: '.../...//'",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02939
      },
      "nvd": {
        "published": "2026-07-10T05:16:34.930",
        "lastModified": "2026-07-11T05:16:33.267",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21043",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-35"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21044",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.816Z",
      "date_published": "2026-07-10T04:58:06.743Z",
      "date_updated": "2026-07-10T14:33:24.915Z",
      "publisher": "SamsungMobile",
      "title": "Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00096,
        "percentile": 0.0085
      },
      "nvd": {
        "published": "2026-07-10T05:16:35.063",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21044",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KnoxGuardManager permits a local caller to bypass the authorization protecting the application's persistence configuration.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 157,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21045",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.816Z",
      "date_published": "2026-07-10T04:58:07.917Z",
      "date_updated": "2026-07-10T14:34:52.799Z",
      "publisher": "SamsungMobile",
      "title": "Out-of-bounds write in parsing TIFF format in libimagecodec.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.09999999999999964,
      "epss": {
        "score": 0.00465,
        "percentile": 0.37912
      },
      "nvd": {
        "published": "2026-07-10T05:16:35.177",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21045",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled input reaches a write whose destination boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 161,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21046",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.816Z",
      "date_published": "2026-07-10T04:58:09.129Z",
      "date_updated": "2026-07-11T03:55:19.537Z",
      "publisher": "SamsungMobile",
      "title": "Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00096,
        "percentile": 0.00849
      },
      "nvd": {
        "published": "2026-07-10T05:16:35.290",
        "lastModified": "2026-07-11T05:16:33.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21046",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Samsung Mobile Devices validates a mutable object and later uses it after another actor can replace or modify it.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 161,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21047",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.817Z",
      "date_published": "2026-07-28T11:23:41.001Z",
      "date_updated": "2026-07-29T19:14:55.153Z",
      "publisher": "SamsungMobile",
      "title": "Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32404
      },
      "nvd": {
        "published": "2026-07-28T12:16:36.207",
        "lastModified": "2026-07-30T16:45:56.833",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21047",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted remote input can make Samsung ImsService write outside a valid buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21048",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.817Z",
      "date_published": "2026-07-10T04:58:10.507Z",
      "date_updated": "2026-07-10T15:05:58.428Z",
      "publisher": "SamsungMobile",
      "title": "Out-of-bounds write in parsing DNG format in libimagecodec.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.09999999999999964,
      "epss": {
        "score": 0.00387,
        "percentile": 0.31502
      },
      "nvd": {
        "published": "2026-07-10T05:16:35.410",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21048",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted DNG data can write beyond the bounds of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21049",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.817Z",
      "date_published": "2026-07-10T04:58:11.656Z",
      "date_updated": "2026-07-11T03:55:18.770Z",
      "publisher": "SamsungMobile",
      "title": "Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02758
      },
      "nvd": {
        "published": "2026-07-10T05:16:35.533",
        "lastModified": "2026-07-11T05:16:33.473",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21049",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A local input to libpadm.so writes beyond the bounds of a memory object.",
        "basis": [
          "CNA record",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21050",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.817Z",
      "date_published": "2026-07-10T04:58:12.835Z",
      "date_updated": "2026-07-10T13:15:56.114Z",
      "publisher": "SamsungMobile",
      "title": "Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01238
      },
      "nvd": {
        "published": "2026-07-10T05:16:35.650",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21050",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Samsung Mobile Devices permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 129,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21051",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.819Z",
      "date_published": "2026-07-10T04:58:13.915Z",
      "date_updated": "2026-07-10T11:45:14.827Z",
      "publisher": "SamsungMobile",
      "title": "Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWifiSecurity settings.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01238
      },
      "nvd": {
        "published": "2026-07-10T05:16:35.760",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21051",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WLAN security settings ship with permissions that let a local attacker modify TencentWifiSecurity configuration.",
        "basis": [
          "CNA",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 144,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21052",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.820Z",
      "date_published": "2026-07-10T04:58:15.141Z",
      "date_updated": "2026-07-14T14:31:24.887Z",
      "publisher": "SamsungMobile",
      "title": "Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03124
      },
      "nvd": {
        "published": "2026-07-10T05:16:35.877",
        "lastModified": "2026-07-14T15:17:01.420",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21052",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file operation in Samsung Mobile Devices uses an attacker-controlled path without confining the resolved object to the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21053",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.820Z",
      "date_published": "2026-07-10T04:58:16.247Z",
      "date_updated": "2026-07-10T11:41:13.002Z",
      "publisher": "SamsungMobile",
      "title": "Improper input validation in Samsung Email prior to version 6.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Email"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00111,
        "percentile": 0.01523
      },
      "nvd": {
        "published": "2026-07-10T05:16:35.987",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21053",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Samsung Email lets a local caller select file-creation targets inside the application sandbox, but the public record does not identify the filename field or confinement check.",
        "basis": [
          "CNA record",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21054",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.820Z",
      "date_published": "2026-07-10T04:58:17.352Z",
      "date_updated": "2026-07-10T11:40:14.374Z",
      "publisher": "SamsungMobile",
      "title": "Improper export of android application components in InputSharing prior to version 2.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "InputSharing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-926",
          "name": "Improper Export of Android Application Components",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01788
      },
      "nvd": {
        "published": "2026-07-10T05:16:36.100",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21054",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "InputSharing exports an Android component with permissions that allow local applications to access sharing data.",
        "basis": [
          "CNA",
          "CWE-926"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21055",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.820Z",
      "date_published": "2026-07-10T04:58:18.785Z",
      "date_updated": "2026-07-11T03:55:17.271Z",
      "publisher": "SamsungMobile",
      "title": "Improper export of android application components in Bixby prior to version 4.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Bixby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-926",
          "name": "Improper Export of Android Application Components",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06877
      },
      "nvd": {
        "published": "2026-07-10T05:16:36.217",
        "lastModified": "2026-07-11T05:16:33.677",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21055",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Bixby application exposes a privileged Android component to local callers outside its intended trust boundary.",
        "basis": [
          "CNA",
          "CWE-926"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 159,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21056",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.820Z",
      "date_published": "2026-07-10T04:58:19.968Z",
      "date_updated": "2026-07-10T13:15:21.288Z",
      "publisher": "SamsungMobile",
      "title": "Improper authorization in Samsung Health prior to version 7.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Health"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00099,
        "percentile": 0.00966
      },
      "nvd": {
        "published": "2026-07-10T05:16:36.330",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21056",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A connected-device information action is reachable without an effective authorization check, whose exact form is not public.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21057",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-11T01:33:35.821Z",
      "date_published": "2026-07-10T04:58:21.040Z",
      "date_updated": "2026-07-10T11:30:25.418Z",
      "publisher": "SamsungMobile",
      "title": "Improper input validation in Samsung Pass prior to version 5.",
      "affected": {
        "vendors": [
          "Samsung Mobile"
        ],
        "products": [
          {
            "vendor": "Samsung Mobile",
            "product": "Samsung Pass"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:mobile.security@samsung.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01866
      },
      "nvd": {
        "published": "2026-07-10T05:16:36.453",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21057",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Samsung Pass accepts malformed local input whose unchecked size or offset drives an out-of-bounds write.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=07",
          "host": "security.samsungmobile.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21368",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-17T04:35:45.742Z",
      "date_published": "2026-07-06T20:09:34.872Z",
      "date_updated": "2026-07-07T13:10:54.219Z",
      "publisher": "qualcomm",
      "title": "Out-of-bounds Write in Camera Driver",
      "affected": {
        "vendors": [
          "Qualcomm, Inc."
        ],
        "products": [
          {
            "vendor": "Qualcomm, Inc.",
            "product": "Snapdragon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 91,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:product-security@qualcomm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0006,
        "percentile": 0.0001
      },
      "nvd": {
        "published": "2026-07-06T21:16:53.407",
        "lastModified": "2026-07-07T16:50:09.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-21368",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "JPEG validation writes beyond the destination buffer when crafted dimensions or lengths exceed the allocated extent.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html",
          "host": "docs.qualcomm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 91
      }
    },
    {
      "cve_id": "CVE-2026-21369",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-17T04:35:45.742Z",
      "date_published": "2026-07-06T20:09:35.999Z",
      "date_updated": "2026-07-07T13:10:43.683Z",
      "publisher": "qualcomm",
      "title": "Out-of-bounds Write in Camera Driver",
      "affected": {
        "vendors": [
          "Qualcomm, Inc."
        ],
        "products": [
          {
            "vendor": "Qualcomm, Inc.",
            "product": "Snapdragon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 109,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:product-security@qualcomm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0006,
        "percentile": 0.0001
      },
      "nvd": {
        "published": "2026-07-06T21:16:53.553",
        "lastModified": "2026-07-07T16:49:34.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-21369",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html",
          "host": "docs.qualcomm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 109
      }
    },
    {
      "cve_id": "CVE-2026-21370",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-17T04:35:45.742Z",
      "date_published": "2026-07-06T20:09:37.081Z",
      "date_updated": "2026-07-07T13:10:34.707Z",
      "publisher": "qualcomm",
      "title": "Out-of-bounds Write in Camera Driver",
      "affected": {
        "vendors": [
          "Qualcomm, Inc."
        ],
        "products": [
          {
            "vendor": "Qualcomm, Inc.",
            "product": "Snapdragon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 91,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:product-security@qualcomm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0006,
        "percentile": 0.0001
      },
      "nvd": {
        "published": "2026-07-06T21:16:53.707",
        "lastModified": "2026-07-07T16:47:47.907",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-21370",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The camera driver accepts a batch size and plane count that exceed the destination buffer bounds.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html",
          "host": "docs.qualcomm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 91
      }
    },
    {
      "cve_id": "CVE-2026-21379",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-17T04:35:45.743Z",
      "date_published": "2026-07-06T20:09:38.160Z",
      "date_updated": "2026-07-07T03:56:18.731Z",
      "publisher": "qualcomm",
      "title": "Buffer Over-read in Windows Compute",
      "affected": {
        "vendors": [
          "Qualcomm, Inc."
        ],
        "products": [
          {
            "vendor": "Qualcomm, Inc.",
            "product": "Snapdragon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 47,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:product-security@qualcomm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0007,
        "percentile": 0.00048
      },
      "nvd": {
        "published": "2026-07-06T21:16:53.850",
        "lastModified": "2026-07-07T16:45:53.567",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-21379",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The public record identifies a memory-safety failure but does not disclose the exact buffer, lifetime transition, or invalid access.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html",
          "host": "docs.qualcomm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 90,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 47
      }
    },
    {
      "cve_id": "CVE-2026-21383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-17T04:35:45.743Z",
      "date_published": "2026-07-06T20:09:39.251Z",
      "date_updated": "2026-07-08T03:56:37.495Z",
      "publisher": "qualcomm",
      "title": "Reusing a Nonce, Key Pair in Encryption in HLOS",
      "affected": {
        "vendors": [
          "Qualcomm, Inc."
        ],
        "products": [
          {
            "vendor": "Qualcomm, Inc.",
            "product": "Snapdragon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 53,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-323",
          "name": "Reusing a Nonce, Key Pair in Encryption",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:product-security@qualcomm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00069,
        "percentile": 0.00042
      },
      "nvd": {
        "published": "2026-07-06T21:16:53.973",
        "lastModified": "2026-07-08T05:16:27.107",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-21383",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The device reuses a static AES-GCM nonce when wrapping keys, breaking the nonce-uniqueness requirement of the authenticated-encryption scheme.",
        "basis": [
          "CNA",
          "CWE-323"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html",
          "host": "docs.qualcomm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 151,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 53
      }
    },
    {
      "cve_id": "CVE-2026-21384",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2025-12-17T04:35:45.743Z",
      "date_published": "2026-07-06T20:09:40.351Z",
      "date_updated": "2026-07-07T13:10:27.761Z",
      "publisher": "qualcomm",
      "title": "Out-of-bounds Write in Camera Driver",
      "affected": {
        "vendors": [
          "Qualcomm, Inc."
        ],
        "products": [
          {
            "vendor": "Qualcomm, Inc.",
            "product": "Snapdragon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 79,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:product-security@qualcomm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00056,
        "percentile": 0.00006
      },
      "nvd": {
        "published": "2026-07-06T21:16:54.097",
        "lastModified": "2026-07-07T17:27:33.407",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-21384",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A userspace port index can exceed the supported read-client range before the prepared-command update accesses the corresponding memory.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html",
          "host": "docs.qualcomm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 79
      }
    },
    {
      "cve_id": "CVE-2026-21575",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-01T00:00:40.720Z",
      "date_published": "2026-07-21T17:00:00.501Z",
      "date_updated": "2026-07-24T03:55:49.714Z",
      "publisher": "atlassian",
      "title": "This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.",
      "affected": {
        "vendors": [
          "Atlassian"
        ],
        "products": [
          {
            "vendor": "Atlassian",
            "product": "Sourcetree for Mac"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@atlassian.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23462
      },
      "nvd": {
        "published": "2026-07-21T18:16:57.170",
        "lastModified": "2026-07-24T05:16:41.557",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21575",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Sourcetree for Mac places caller-influenced data into dynamically evaluated code without restricting executable syntax.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999345",
          "host": "confluence.atlassian.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jira.atlassian.com/browse/SRCTREE-8275",
          "host": "jira.atlassian.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1039,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-21577",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-01T00:00:40.721Z",
      "date_published": "2026-07-21T17:00:00.483Z",
      "date_updated": "2026-07-22T18:48:52.568Z",
      "publisher": "atlassian",
      "title": "This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.",
      "affected": {
        "vendors": [
          "Atlassian"
        ],
        "products": [
          {
            "vendor": "Atlassian",
            "product": "Confluence Data Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 11,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@atlassian.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14458
      },
      "nvd": {
        "published": "2026-07-21T18:16:57.327",
        "lastModified": "2026-07-22T19:16:59.073",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21577",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An authenticated request can make a Confluence resource unavailable, but the record does not identify the unbounded work or unreleased resource.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999345",
          "host": "confluence.atlassian.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jira.atlassian.com/browse/CONFSERVER-104334",
          "host": "jira.atlassian.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1117,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-21579",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-01T00:00:40.721Z",
      "date_published": "2026-07-21T17:00:00.404Z",
      "date_updated": "2026-07-22T18:48:58.801Z",
      "publisher": "atlassian",
      "title": "This High severity Information Disclosure vulnerability was introduced in versions 7.",
      "affected": {
        "vendors": [
          "Atlassian"
        ],
        "products": [
          {
            "vendor": "Atlassian",
            "product": "Confluence Data Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 11,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@atlassian.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19625
      },
      "nvd": {
        "published": "2026-07-21T18:16:57.487",
        "lastModified": "2026-07-22T19:16:59.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21579",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Confluence returns sensitive information to an unauthenticated requester, but Atlassian does not disclose the endpoint, object, or output condition.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999345",
          "host": "confluence.atlassian.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jira.atlassian.com/browse/CONFSERVER-104340",
          "host": "jira.atlassian.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1058,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-21653",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-02T13:23:28.168Z",
      "date_published": "2026-07-23T20:19:32.586Z",
      "date_updated": "2026-07-24T13:35:30.721Z",
      "publisher": "jci",
      "title": "CCure and Victor Application Server - Server Side Request Forgery",
      "affected": {
        "vendors": [
          "Johnson Controls"
        ],
        "products": [
          {
            "vendor": "Johnson Controls",
            "product": "CCure 9000 and victor application server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:productsecurity@jci.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13801
      },
      "nvd": {
        "published": "2026-07-23T21:17:03.653",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21653",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The application server accepts an attacker-influenced server-side request destination without the required destination trust restrictions, although the exact parameter is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories",
          "host": "www.johnsoncontrols.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21655",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-02T13:23:28.169Z",
      "date_published": "2026-07-23T20:13:05.447Z",
      "date_updated": "2026-07-24T13:34:45.585Z",
      "publisher": "jci",
      "title": "C-CURE 9000 and Victor application server - Deserialization of Untrusted Data",
      "affected": {
        "vendors": [
          "Johnson Control"
        ],
        "products": [
          {
            "vendor": "Johnson Control",
            "product": "victor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:productsecurity@jci.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06112
      },
      "nvd": {
        "published": "2026-07-23T21:17:03.810",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21655",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The victor parser reconstructs an attacker-controlled serialized object with executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories",
          "host": "www.johnsoncontrols.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 151,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21662",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-02T13:23:28.170Z",
      "date_published": "2026-07-31T17:30:41.561Z",
      "date_updated": "2026-07-31T18:24:41.723Z",
      "publisher": "jci",
      "title": "FMS Employee Allows Upload of Unrestricted Files",
      "affected": {
        "vendors": [
          "Johnson Controls"
        ],
        "products": [
          {
            "vendor": "Johnson Controls",
            "product": "FM Systems Employee"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:productsecurity@jci.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00409,
        "percentile": 0.33672
      },
      "nvd": {
        "published": "2026-07-31T18:17:13.650",
        "lastModified": "2026-07-31T19:17:08.527",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21662",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FM Systems Employee accepts a dangerous uploaded file type without enforcing a safe upload policy.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories",
          "host": "www.johnsoncontrols.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T09:26:06.214Z",
      "date_published": "2026-07-23T01:48:16.245Z",
      "date_updated": "2026-07-29T13:59:53.891Z",
      "publisher": "GRAFANA",
      "title": "CVE-2026-21723 Record",
      "affected": {
        "vendors": [
          "Grafana"
        ],
        "products": [
          {
            "vendor": "Grafana",
            "product": "Grafana OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@grafana.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09863
      },
      "nvd": {
        "published": "2026-07-23T03:16:30.000",
        "lastModified": "2026-07-23T17:55:03.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21723",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The template-test endpoint executes arbitrarily many memory-unbounded templates until the Grafana process exhausts memory.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://grafana.com/security/security-advisories/cve-2026-21723",
          "host": "grafana.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-21729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T09:26:06.215Z",
      "date_published": "2026-07-16T03:12:07.912Z",
      "date_updated": "2026-07-29T13:59:46.962Z",
      "publisher": "GRAFANA",
      "title": "Loki detected_fields query limits results in unbounded memory allocation",
      "affected": {
        "vendors": [
          "Grafana"
        ],
        "products": [
          {
            "vendor": "Grafana",
            "product": "Loki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@grafana.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.1796
      },
      "nvd": {
        "published": "2026-07-16T04:17:29.260",
        "lastModified": "2026-07-16T14:16:49.383",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21729",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Loki accepts an attacker-controlled size, count, recursion depth, or work request without the quota or upper bound needed to keep resource use finite.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://grafana.com/security/security-advisories/cve-2026-21729",
          "host": "grafana.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 153,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T16:07:55.983Z",
      "date_published": "2026-07-17T17:06:19.920Z",
      "date_updated": "2026-07-17T17:54:25.664Z",
      "publisher": "HCL",
      "title": "Unauthorized Access to Admin Functionality via Forced Browsing",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "DevOps Loop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-425",
          "name": "Direct Request ('Forced Browsing')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04528
      },
      "nvd": {
        "published": "2026-07-17T17:17:14.780",
        "lastModified": "2026-07-17T18:17:14.997",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21760",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Administrative DevOps Loop endpoints can be reached directly without enforcing the authorization required for their functions.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-425"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132296",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T16:07:58.366Z",
      "date_published": "2026-07-17T17:10:02.255Z",
      "date_updated": "2026-07-17T17:53:54.150Z",
      "publisher": "HCL",
      "title": "CORS Misconfiguration in DevOps Loop",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "DevOps Loop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-942",
          "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.0427
      },
      "nvd": {
        "published": "2026-07-17T17:17:14.893",
        "lastModified": "2026-07-17T18:17:15.107",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21761",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DevOps Loop permits browser origins outside the trusted set to make credentialed cross-origin requests.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-942"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132296",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21762",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T16:07:58.366Z",
      "date_published": "2026-07-17T17:10:33.243Z",
      "date_updated": "2026-07-17T17:53:24.498Z",
      "publisher": "HCL",
      "title": "Missing HTTP Security Headers in DevOps Loop",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "DevOps Loop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-644",
          "name": "Improper Neutralization of HTTP Headers for Scripting Syntax",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06745
      },
      "nvd": {
        "published": "2026-07-17T17:17:15.010",
        "lastModified": "2026-07-17T18:17:15.200",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21762",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "DevOps Loop responses omit browser security headers that should constrain framing, MIME interpretation, and script execution.",
        "basis": [
          "CNA",
          "CWE-644"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132296",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T16:07:58.367Z",
      "date_published": "2026-07-17T17:11:01.861Z",
      "date_updated": "2026-07-17T17:53:06.286Z",
      "publisher": "HCL",
      "title": "Insufficient Input Validation in DevOps Loop",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "DevOps Loop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.0495
      },
      "nvd": {
        "published": "2026-07-17T17:17:15.123",
        "lastModified": "2026-07-17T18:17:15.297",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21764",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record says special characters cause unintended DevOps Loop behavior but gives neither a security consequence nor a causal processing boundary.",
        "basis": [
          "CNA",
          "CWE-754"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132296",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T16:07:58.367Z",
      "date_published": "2026-07-17T04:42:54.608Z",
      "date_updated": "2026-07-17T13:04:14.448Z",
      "publisher": "HCL",
      "title": "HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "HCL Traveler for Microsoft Outlook (HTMO)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00111,
        "percentile": 0.01545
      },
      "nvd": {
        "published": "2026-07-17T05:16:38.567",
        "lastModified": "2026-07-17T18:11:59.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21770",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HCL Traveler loads a DLL through a search path that allows an attacker-controlled replacement to be selected.",
        "basis": [
          "CNA",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130919",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21824",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T16:08:22.254Z",
      "date_published": "2026-07-20T15:04:37.890Z",
      "date_updated": "2026-07-21T14:56:45.939Z",
      "publisher": "HCL",
      "title": "A privilege escalation vulnerability affects HCL Commerce",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Commerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14681
      },
      "nvd": {
        "published": "2026-07-20T16:16:56.777",
        "lastModified": "2026-07-21T17:09:21.500",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21824",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "HCL Commerce grants a caller administrative effects and personal data beyond the caller's privilege, while the missing authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130114",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21840",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T16:08:25.001Z",
      "date_published": "2026-07-14T21:36:52.776Z",
      "date_updated": "2026-07-15T12:46:19.073Z",
      "publisher": "HCL",
      "title": "HCL BigFix Platform is affected by a user enumeration vulnerability",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "HCL BigFix Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.0495
      },
      "nvd": {
        "published": "2026-07-14T22:16:52.527",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21840",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service.",
        "basis": [
          "CNA",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132093",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21901",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T17:32:48.709Z",
      "date_published": "2026-07-09T21:01:31.334Z",
      "date_updated": "2026-07-10T14:21:31.624Z",
      "publisher": "juniper",
      "title": "Junos OS and Junos OS Evolved: Configuration of a specific SSH option results in mgd crash",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          },
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS Evolved"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/AU:Y/R:A/V:D/RE:M/U:Green"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:D/RE:M/U:Green"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01988
      },
      "nvd": {
        "published": "2026-07-09T21:16:54.467",
        "lastModified": "2026-07-10T17:49:57.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21901",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path dereferences a NULL pointer because the required validity check is missing or applied to the wrong value.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/orangecertcc/security-research/security/advisories/GHSA-g4f7-w2rc-hpj6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://supportportal.juniper.net/JSA110072",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1093,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-21953",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T18:07:34.713Z",
      "date_published": "2026-07-21T21:31:26.871Z",
      "date_updated": "2026-07-23T15:20:21.725Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Retail Xstore Point of Service"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00099,
        "percentile": 0.00929
      },
      "nvd": {
        "published": "2026-07-21T22:17:00.620",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21953",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 644,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-21954",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T18:07:34.713Z",
      "date_published": "2026-07-21T21:32:03.802Z",
      "date_updated": "2026-07-23T15:20:14.432Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Retail Xstore Point of Service"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09643
      },
      "nvd": {
        "published": "2026-07-21T22:17:00.763",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-21954",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle Retail Xstore Point of Service but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 587,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22049",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-05T22:47:18.701Z",
      "date_published": "2026-07-22T18:52:14.069Z",
      "date_updated": "2026-07-25T03:55:53.307Z",
      "publisher": "netapp",
      "title": "ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentia...",
      "affected": {
        "vendors": [
          "NETAPP"
        ],
        "products": [
          {
            "vendor": "NETAPP",
            "product": "ONTAP 9"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-alert@netapp.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20885
      },
      "nvd": {
        "published": "2026-07-22T19:16:59.820",
        "lastModified": "2026-07-25T05:16:34.723",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22049",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ONTAP accepts a WebAuthn assertion under an incorrectly validated Relying Party ID, allowing valid credentials to bypass the required second factor.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.netapp.com/advisory/NTAP-20260722-0001/",
          "host": "security.netapp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22068",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-06T00:14:54.783Z",
      "date_published": "2026-07-29T07:19:04.701Z",
      "date_updated": "2026-07-29T13:14:03.128Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Regex mappings match with malicious domain names",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-777",
          "name": "Regular Expression without Anchors",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 1.299999999999999,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11143
      },
      "nvd": {
        "published": "2026-07-29T08:16:30.660",
        "lastModified": "2026-07-30T14:54:03.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22068",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unanchored mapping regular expressions accept malicious domain names that only partially match the intended host pattern.",
        "basis": [
          "CNA",
          "CWE-777"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-22093",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-06T11:08:58.181Z",
      "date_published": "2026-07-13T09:10:56.109Z",
      "date_updated": "2026-07-16T15:41:09.083Z",
      "publisher": "DIVD",
      "title": "Adversary-in-the-Middle (AitM) attack  vulnerability in EVbee Service app",
      "affected": {
        "vendors": [
          "EVbee"
        ],
        "products": [
          {
            "vendor": "EVbee",
            "product": "EVbee Service"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:csirt@divd.nl",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05682
      },
      "nvd": {
        "published": "2026-07-13T10:16:26.910",
        "lastModified": "2026-07-13T17:44:34.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22093",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The product does not validate the peer certificate and also relies on a fixed weak RC4 secret.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://csirt.divd.nl/DIVD-2026-00001/",
          "host": "csirt.divd.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22095",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-06T11:08:58.182Z",
      "date_published": "2026-07-13T09:10:56.609Z",
      "date_updated": "2026-07-16T15:41:03.440Z",
      "publisher": "DIVD",
      "title": "Command injection in diagnosis web endpoint",
      "affected": {
        "vendors": [
          "EVbee"
        ],
        "products": [
          {
            "vendor": "EVbee",
            "product": "DC-80"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:csirt@divd.nl",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00909,
        "percentile": 0.5652
      },
      "nvd": {
        "published": "2026-07-13T10:16:27.050",
        "lastModified": "2026-07-13T17:44:34.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22095",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The port 8090 diagnosis endpoint passes attacker-controlled input across an operating-system command boundary without neutralizing command syntax.",
        "basis": [
          "CNA record",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://csirt.divd.nl/DIVD-2026-00001/",
          "host": "csirt.divd.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22096",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-06T11:08:58.182Z",
      "date_published": "2026-07-13T09:10:57.619Z",
      "date_updated": "2026-07-16T15:41:01.874Z",
      "publisher": "DIVD",
      "title": "Missing authentication for webserver endpoints",
      "affected": {
        "vendors": [
          "EVbee"
        ],
        "products": [
          {
            "vendor": "EVbee",
            "product": "DC-80"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:csirt@divd.nl",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23612
      },
      "nvd": {
        "published": "2026-07-13T10:16:27.167",
        "lastModified": "2026-07-13T17:44:34.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22096",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DC-80 exposes a security-sensitive endpoint without requiring caller authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://csirt.divd.nl/DIVD-2026-00001/",
          "host": "csirt.divd.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22097",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-06T11:08:58.182Z",
      "date_published": "2026-07-13T09:10:59.154Z",
      "date_updated": "2026-07-16T15:41:10.486Z",
      "publisher": "DIVD",
      "title": "Missing firmware validation allows remote code execution",
      "affected": {
        "vendors": [
          "EVbee"
        ],
        "products": [
          {
            "vendor": "EVbee",
            "product": "DC-80"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:csirt@divd.nl",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.1106
      },
      "nvd": {
        "published": "2026-07-13T10:16:27.277",
        "lastModified": "2026-07-13T17:44:34.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22097",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The firmware updater accepts an image without verifying a cryptographic signature before installation.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://csirt.divd.nl/DIVD-2026-00001/",
          "host": "csirt.divd.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22098",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-06T11:08:58.183Z",
      "date_published": "2026-07-13T09:10:59.654Z",
      "date_updated": "2026-07-16T15:41:04.833Z",
      "publisher": "DIVD",
      "title": "Sensitive information is written to logs",
      "affected": {
        "vendors": [
          "EVbee"
        ],
        "products": [
          {
            "vendor": "EVbee",
            "product": "DC-80"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:csirt@divd.nl",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16738
      },
      "nvd": {
        "published": "2026-07-13T10:16:27.393",
        "lastModified": "2026-07-13T17:44:34.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22098",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected charging system writes passwords and charging-card identifiers into log files visible beyond their intended audience.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://csirt.divd.nl/DIVD-2026-00001/",
          "host": "csirt.divd.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22099",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-06T11:08:58.183Z",
      "date_published": "2026-07-13T09:10:58.667Z",
      "date_updated": "2026-07-16T15:41:07.703Z",
      "publisher": "DIVD",
      "title": "Missing authentication for Bluetooth communication",
      "affected": {
        "vendors": [
          "EVbee"
        ],
        "products": [
          {
            "vendor": "EVbee",
            "product": "DC-80"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:csirt@divd.nl",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08646
      },
      "nvd": {
        "published": "2026-07-13T10:16:27.523",
        "lastModified": "2026-07-13T17:44:34.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22099",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The charger accepts sensitive Bluetooth commands without authenticating the nearby sender.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://csirt.divd.nl/DIVD-2026-00001/",
          "host": "csirt.divd.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22100",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-06T11:08:58.183Z",
      "date_published": "2026-07-13T09:10:57.110Z",
      "date_updated": "2026-07-16T15:41:11.895Z",
      "publisher": "DIVD",
      "title": "Comnand injection in OCPP ReserveLogin message",
      "affected": {
        "vendors": [
          "EVbee"
        ],
        "products": [
          {
            "vendor": "EVbee",
            "product": "DC-80"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:csirt@divd.nl",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00809,
        "percentile": 0.53371
      },
      "nvd": {
        "published": "2026-07-13T10:16:27.670",
        "lastModified": "2026-07-13T17:44:34.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22100",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ReserveLogin DataTransfer handler incorporates attacker-controlled data into a root OS command without shell-safe separation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://csirt.divd.nl/DIVD-2026-00001/",
          "host": "csirt.divd.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 159,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22102",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-06T11:08:58.184Z",
      "date_published": "2026-07-13T09:10:58.172Z",
      "date_updated": "2026-07-16T15:41:06.284Z",
      "publisher": "DIVD",
      "title": "Arbitrary file overwrite through certificate update functionality",
      "affected": {
        "vendors": [
          "EVbee"
        ],
        "products": [
          {
            "vendor": "EVbee",
            "product": "DC-80"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:csirt@divd.nl",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23769
      },
      "nvd": {
        "published": "2026-07-13T10:16:27.783",
        "lastModified": "2026-07-13T17:44:34.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22102",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The web endpoint uses the unverified Content-Disposition filename to choose a filesystem destination, allowing writes outside the intended location.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://csirt.divd.nl/DIVD-2026-00001/",
          "host": "csirt.divd.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 385,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-06T11:08:58.184Z",
      "date_published": "2026-07-13T09:11:00.237Z",
      "date_updated": "2026-07-16T15:41:13.345Z",
      "publisher": "DIVD",
      "title": "Command injection in NPC start web endpoint",
      "affected": {
        "vendors": [
          "EVbee"
        ],
        "products": [
          {
            "vendor": "EVbee",
            "product": "DC-80"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:csirt@divd.nl",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00909,
        "percentile": 0.56519
      },
      "nvd": {
        "published": "2026-07-13T10:16:27.900",
        "lastModified": "2026-07-13T17:44:34.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22103",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An endpoint inserts attacker-controlled input into an operating-system command without shell-safe separation.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://csirt.divd.nl/DIVD-2026-00001/",
          "host": "csirt.divd.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 89,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22104",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-06T11:08:58.185Z",
      "date_published": "2026-07-17T09:30:36.710Z",
      "date_updated": "2026-07-21T09:51:24.336Z",
      "publisher": "DIVD",
      "title": "Improper access control in Hashtopolis server chunk activity component",
      "affected": {
        "vendors": [
          "hashtopolis"
        ],
        "products": [
          {
            "vendor": "hashtopolis",
            "product": "server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/R:I"
        },
        {
          "source": "NVD:csirt@divd.nl",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:I/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24885
      },
      "nvd": {
        "published": "2026-07-17T10:16:36.550",
        "lastModified": "2026-07-17T18:08:27.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22104",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server request path accepts an attacker-selected object identifier without binding that object to the caller's tenant, owner, or permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://csirt.divd.nl/CVE-2026-22104",
          "host": "csirt.divd.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://csirt.divd.nl/DIVD-2026-00010",
          "host": "csirt.divd.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/hashtopolis/server/releases/tag/v0.14.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22547",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-22T15:13:33.653Z",
      "date_published": "2026-07-03T20:19:30.291Z",
      "date_updated": "2026-07-07T17:00:34.400Z",
      "publisher": "Gitea",
      "title": "Gitea repository creation accepts invalid field values",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00373,
        "percentile": 0.29999
      },
      "nvd": {
        "published": "2026-07-03T21:16:56.890",
        "lastModified": "2026-07-07T18:16:35.610",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22547",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gitea accepts repository-creation fields without enforcing documented length, trust-model, and object-format constraints.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36671",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36757",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22555",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:28.700Z",
      "date_published": "2026-07-03T20:19:30.648Z",
      "date_updated": "2026-07-06T20:23:09.456Z",
      "publisher": "Gitea",
      "title": "Gitea organization forks can expose organization secrets without create permission",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22787
      },
      "nvd": {
        "published": "2026-07-03T21:16:57.023",
        "lastModified": "2026-07-06T21:16:54.240",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22555",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-fhx7-m96w-mv29",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36950",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.0/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22620",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-08T04:55:11.730Z",
      "date_published": "2026-07-30T10:11:37.419Z",
      "date_updated": "2026-07-31T09:55:01.109Z",
      "publisher": "Eaton",
      "title": "Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.",
      "affected": {
        "vendors": [
          "Eaton"
        ],
        "products": [
          {
            "vendor": "Eaton",
            "product": "PADM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:CybersecurityCOE@eaton.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28928
      },
      "nvd": {
        "published": "2026-07-30T11:16:27.130",
        "lastModified": "2026-07-31T11:17:08.000",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22620",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The authentication component accepts malformed input that bypasses login, but Eaton does not publish the accepted field or validation rule.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/eaton-va-2026-1005.pdf",
          "host": "www.eaton.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.eaton.com/content/dam/eaton/products/backup-power-ups-surge-it-power-distribution/eol/secure/eaton-tripp-lite-series-padm-20-eol-notice.pdf",
          "host": "www.eaton.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22621",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-08T04:55:11.730Z",
      "date_published": "2026-07-30T10:16:28.953Z",
      "date_updated": "2026-07-31T09:55:33.569Z",
      "publisher": "Eaton",
      "title": "Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.",
      "affected": {
        "vendors": [
          "Eaton"
        ],
        "products": [
          {
            "vendor": "Eaton",
            "product": "PADM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:CybersecurityCOE@eaton.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00584,
        "percentile": 0.44594
      },
      "nvd": {
        "published": "2026-07-30T11:16:27.280",
        "lastModified": "2026-07-31T11:17:08.703",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22621",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component lets attacker-controlled text cross into an executable or interpreted grammar without the required separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/eaton-va-2026-1005.pdf",
          "host": "www.eaton.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.eaton.com/content/dam/eaton/products/backup-power-ups-surge-it-power-distribution/eol/secure/eaton-tripp-lite-series-padm-20-eol-notice.pdf",
          "host": "www.eaton.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22622",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-08T04:55:11.731Z",
      "date_published": "2026-07-30T10:21:17.647Z",
      "date_updated": "2026-07-31T09:56:07.330Z",
      "publisher": "Eaton",
      "title": "Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.",
      "affected": {
        "vendors": [
          "Eaton"
        ],
        "products": [
          {
            "vendor": "Eaton",
            "product": "PADM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:CybersecurityCOE@eaton.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22844
      },
      "nvd": {
        "published": "2026-07-30T11:16:27.397",
        "lastModified": "2026-07-31T11:17:09.397",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22622",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Eaton identifies improper validation in a session-management interface that lets an authenticated user gain unrestricted access, but does not publish the field or privilege transition.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/eaton-va-2026-1005.pdf",
          "host": "www.eaton.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.eaton.com/content/dam/eaton/products/backup-power-ups-surge-it-power-distribution/eol/secure/eaton-tripp-lite-series-padm-20-eol-notice.pdf",
          "host": "www.eaton.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22659",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-08T19:04:26.364Z",
      "date_published": "2026-07-10T13:31:02.784Z",
      "date_updated": "2026-07-14T15:53:21.144Z",
      "publisher": "VulnCheck",
      "title": "FlaskBB Authorization Bypass via Topic ID Manipulation",
      "affected": {
        "vendors": [
          "flaskbb"
        ],
        "products": [
          {
            "vendor": "flaskbb",
            "product": "flaskbb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00284,
        "percentile": 0.2065
      },
      "nvd": {
        "published": "2026-07-10T14:16:52.547",
        "lastModified": "2026-07-14T16:16:49.897",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22659",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Batch topic actions authorize only the first returned topic, allowing a permitted low-ID topic to lend its moderator decision to unauthorized topic IDs in the same request.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/flaskbb/flaskbb/security/advisories/GHSA-9rjj-9p2h-6c55",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/flaskbb/flaskbb/commit/acc88cfedd011124395e0101cb27432a47f712be",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/flaskbb-authorization-bypass-via-topic-id-manipulation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 498,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-22660",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-08T19:04:26.364Z",
      "date_published": "2026-07-10T13:26:31.423Z",
      "date_updated": "2026-07-14T15:53:21.858Z",
      "publisher": "VulnCheck",
      "title": "FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint",
      "affected": {
        "vendors": [
          "flaskbb"
        ],
        "products": [
          {
            "vendor": "flaskbb",
            "product": "flaskbb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-697",
          "name": "Incorrect Comparison",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25321
      },
      "nvd": {
        "published": "2026-07-10T14:16:52.687",
        "lastModified": "2026-07-14T16:16:50.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22660",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The bulk-delete guard compares integer group IDs from JSON with string literals, so built-in authorization groups are never recognized as protected.",
        "basis": [
          "CNA",
          "CWE-697"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/flaskbb/flaskbb/security/advisories/GHSA-r9cf-jxr6-5h3r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/flaskbb/flaskbb/commit/a5da9a529adddc65fe31e275192b642a4e32de64",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/flaskbb-logic-flaw-authorization-group-deletion-via-bulk-ajax-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 526,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-22752",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-09T06:55:03.990Z",
      "date_published": "2026-07-16T08:40:23.009Z",
      "date_updated": "2026-07-21T14:09:17.046Z",
      "publisher": "vmware",
      "title": "Spring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadata",
      "affected": {
        "vendors": [
          "Spring Security"
        ],
        "products": [
          {
            "vendor": "Spring Security",
            "product": "Spring Authorization Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00445,
        "percentile": 0.36595
      },
      "nvd": {
        "published": "2026-07-16T10:16:24.767",
        "lastModified": "2026-07-21T15:16:33.793",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22752",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Dynamic client registration accepts crafted client metadata fields without the validation required before those fields drive privileged behavior.",
        "basis": [
          "CNA",
          "CWE-287",
          "Spring vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://spring.io/security/cve-2026-22752/; the vendor confirms crafted dynamic-client metadata but does not name the individual fields or publish a source patch, and no reproduction was performed."
      },
      "references": [
        {
          "url": "https://spring.io/security/cve-2026-22752",
          "host": "spring.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-22874",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:59.971Z",
      "date_published": "2026-07-03T20:19:31.006Z",
      "date_updated": "2026-07-07T17:00:28.552Z",
      "publisher": "Gitea",
      "title": "Gitea webhook and migration allow-list filtering permits SSRF",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00554,
        "percentile": 0.43123
      },
      "nvd": {
        "published": "2026-07-03T21:16:57.157",
        "lastModified": "2026-07-07T18:16:35.747",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-22874",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "Gitea equates non-private global-unicast addresses with safe external destinations, leaving metadata, CGNAT, NAT64, Teredo, and 6to4 ranges reachable.",
        "basis": [
          "CNA",
          "CWE-918",
          "Gitea advisory",
          "Gitea fix"
        ],
        "deepDive": true,
        "notes": "Inspected https://github.com/go-gitea/gitea/security/advisories/GHSA-2r5c-gw76-rh3w and https://github.com/go-gitea/gitea/pull/38173; they trace the default external filter to net.IP.IsPrivate and add reserved-range handling, but no independent reproduction was performed."
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-2r5c-gw76-rh3w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38173",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38059",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-22927",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-13T15:24:15.286Z",
      "date_published": "2026-07-08T13:37:24.925Z",
      "date_updated": "2026-07-09T03:55:41.166Z",
      "publisher": "Omnissa",
      "title": "Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.",
      "affected": {
        "vendors": [
          "Omnissa"
        ],
        "products": [
          {
            "vendor": "Omnissa",
            "product": "Omnissa Workspace ONE® Tunnel for Windows"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:de5a6978-88fe-4c27-a7df-d0d5b52d5b52",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06676
      },
      "nvd": {
        "published": "2026-07-08T14:16:57.060",
        "lastModified": "2026-07-10T15:27:32.590",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-22927",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A local caller can influence a filesystem path outside the Tunnel application's intended namespace, but the affected path operation is not public.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": "The narrative states only privilege escalation; the path-traversal cause comes from the structured CWE."
      },
      "references": [
        {
          "url": "https://www.omnissa.com/omsa-2026-0002",
          "host": "www.omnissa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.omnissa.com/omnissa-security-response/",
          "host": "www.omnissa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-23537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-13T19:53:18.502Z",
      "date_published": "2026-07-01T13:49:27.306Z",
      "date_updated": "2026-07-15T01:18:20.267Z",
      "publisher": "redhat",
      "title": "Feast: unauthenticated arbitrary file write",
      "affected": {
        "vendors": [
          "Feast",
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Feast",
            "product": "Feast Feature Server"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift AI (RHOAI)"
          }
        ],
        "affectedBlockCount": 15,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00646,
        "percentile": 0.47464
      },
      "nvd": {
        "published": "2026-07-01T15:17:06.790",
        "lastModified": "2026-07-15T02:18:43.183",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-23537",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The save-document endpoint can write attacker-named JSON files outside its intended location, but the exact containment bypass is not public.",
        "basis": [
          "CNA",
          "CWE-862",
          "red-hat-data-services/feast PR 192"
        ],
        "deepDive": true,
        "notes": "Inspected https://github.com/red-hat-data-services/feast/pull/192; the official repository history confirms the read/save document feature but the public PR view does not expose a corrective containment check, so the exact path-restriction bypass remains unknown."
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-23537",
          "host": "access.redhat.com",
          "sources": [
            "adp:1",
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429304",
          "host": "bugzilla.redhat.com",
          "sources": [
            "adp:1",
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/red-hat-data-services/feast/pull/192",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23537.json",
          "host": "security.access.redhat.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "x_sadp-csaf-vex"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 676,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-23538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-13T19:53:18.502Z",
      "date_published": "2026-07-16T00:10:50.170Z",
      "date_updated": "2026-07-16T13:58:04.495Z",
      "publisher": "redhat",
      "title": "Feast: resource exhaustion via websocket endpoint",
      "affected": {
        "vendors": [
          "Feast",
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Feast",
            "product": "Feast Feature Server"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift AI (RHOAI)"
          }
        ],
        "affectedBlockCount": 15,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00748,
        "percentile": 0.51341
      },
      "nvd": {
        "published": "2026-07-16T01:16:30.530",
        "lastModified": "2026-07-16T14:16:49.493",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-23538",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unauthenticated clients can keep an unbounded number of WebSocket connections open until memory, CPU, or file descriptors are exhausted.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-23538",
          "host": "access.redhat.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429311",
          "host": "bugzilla.redhat.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/red-hat-data-services/feast/pull/192",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23538.json",
          "host": "security.access.redhat.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "x_sadp-csaf-vex"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 383,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-23556",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-14T13:07:36.961Z",
      "date_published": "2026-07-09T14:48:56.630Z",
      "date_updated": "2026-07-09T15:37:46.026Z",
      "publisher": "XEN",
      "title": "oxenstored keeps quota related use counts across domain destruction",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "oxenstored"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-281",
          "name": "Improper Preservation of Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@xen.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03533
      },
      "nvd": {
        "published": "2026-07-09T16:16:38.690",
        "lastModified": "2026-07-09T17:16:58.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-23556",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "oxenstored destroys a domain's nodes without clearing its quota usage counts, so a reused domain ID inherits stale consumption state.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-281"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xen.org/xsa/advisory-483.html",
          "host": "xenbits.xen.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/04/28/10",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://xenbits.xen.org/xsa/advisory-483.html",
          "host": "xenbits.xen.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-23559",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-14T13:07:36.961Z",
      "date_published": "2026-07-09T15:09:51.762Z",
      "date_updated": "2026-07-09T16:02:32.186Z",
      "publisher": "XEN",
      "title": "Multiple RBAC issues in XAPI",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "XAPI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-250",
          "name": "Execution with Unnecessary Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@xen.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03322
      },
      "nvd": {
        "published": "2026-07-09T16:16:38.807",
        "lastModified": "2026-07-09T17:16:58.487",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-23559",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "XAPI lets a vm-admin set VBD.other_config:backend-local, exposing arbitrary dom0 files as virtual disks to a controlled VM.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-250"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xen.org/xsa/advisory-489.html",
          "host": "xenbits.xen.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1847,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-23560",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-14T13:07:36.961Z",
      "date_published": "2026-07-09T15:12:00.013Z",
      "date_updated": "2026-07-09T16:08:13.898Z",
      "publisher": "XEN",
      "title": "Multiple RBAC issues in XAPI",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "XAPI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-250",
          "name": "Execution with Unnecessary Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@xen.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03804
      },
      "nvd": {
        "published": "2026-07-09T16:16:38.943",
        "lastModified": "2026-07-09T17:16:58.610",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-23560",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "XAPI lets a vm-admin set VM.other-config:is_system_domain even though that system-domain state requires stronger administrative authority.",
        "basis": [
          "CNA",
          "CWE-250"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xen.org/xsa/advisory-489.html",
          "host": "xenbits.xen.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1843,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-23561",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-14T13:07:36.961Z",
      "date_published": "2026-07-09T15:13:22.160Z",
      "date_updated": "2026-07-10T03:55:44.455Z",
      "publisher": "XEN",
      "title": "Multiple RBAC issues in XAPI",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "XAPI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-250",
          "name": "Execution with Unnecessary Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@xen.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03804
      },
      "nvd": {
        "published": "2026-07-09T16:16:39.100",
        "lastModified": "2026-07-10T05:16:36.587",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-23561",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "XAPI lets a vm-admin assign a virtual machine as a host storage domain even though that configuration requires a higher role.",
        "basis": [
          "CNA",
          "CWE-250"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xen.org/xsa/advisory-489.html",
          "host": "xenbits.xen.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1843,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-23562",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-14T13:07:36.961Z",
      "date_published": "2026-07-09T15:15:24.093Z",
      "date_updated": "2026-07-10T03:55:42.936Z",
      "publisher": "XEN",
      "title": "Multiple RBAC issues in XAPI",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "XAPI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-250",
          "name": "Execution with Unnecessary Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@xen.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03323
      },
      "nvd": {
        "published": "2026-07-09T16:16:39.233",
        "lastModified": "2026-07-10T05:16:36.723",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-23562",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A XenServer PCI-passthrough API omits the pool-admin check and lets a vm-admin access unintended host hardware.",
        "basis": [
          "CNA",
          "CWE-250"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xen.org/xsa/advisory-489.html",
          "host": "xenbits.xen.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1843,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-23573",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-14T14:46:20.539Z",
      "date_published": "2026-07-14T15:19:47.183Z",
      "date_updated": "2026-07-14T16:02:17.037Z",
      "publisher": "fortinet",
      "title": "An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.",
      "affected": {
        "vendors": [
          "Fortinet"
        ],
        "products": [
          {
            "vendor": "Fortinet",
            "product": "FortiOS"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiProxy"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiPAM"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 17,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:psirt@fortinet.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21326
      },
      "nvd": {
        "published": "2026-07-14T16:16:51.823",
        "lastModified": "2026-07-14T20:23:16.903",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-23573",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fortinet's SIP Proxy page places authenticated request data into generated HTML without the required context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-150",
          "host": "fortiguard.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-23697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-14T22:02:15.209Z",
      "date_published": "2026-07-07T16:17:02.850Z",
      "date_updated": "2026-07-14T15:53:34.953Z",
      "publisher": "VulnCheck",
      "title": "Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module",
      "affected": {
        "vendors": [
          "Vtiger"
        ],
        "products": [
          {
            "vendor": "Vtiger",
            "product": "Vtiger CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.01073,
        "percentile": 0.61637
      },
      "nvd": {
        "published": "2026-07-07T17:16:35.977",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-23697",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jivasecurity.com/writeups/vtiger-rce-phar-upload-cve-2026-23697",
          "host": "jivasecurity.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vtiger.com/",
          "host": "www.vtiger.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/vtiger-crm-authenticated-file-upload-rce-via-documents-module",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 603,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-23698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-14T22:02:15.209Z",
      "date_published": "2026-07-07T16:10:24.356Z",
      "date_updated": "2026-07-14T15:53:35.641Z",
      "publisher": "VulnCheck",
      "title": "Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload",
      "affected": {
        "vendors": [
          "Vtiger"
        ],
        "products": [
          {
            "vendor": "Vtiger",
            "product": "Vtiger CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00867,
        "percentile": 0.55204
      },
      "nvd": {
        "published": "2026-07-07T17:16:36.123",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-23698",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path accepts attacker-controlled file content or names without enforcing the intended storage and executable-content boundary.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jivasecurity.com/writeups/vtiger-rce-module-import-cve-2026-23698",
          "host": "jivasecurity.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vtiger.com/",
          "host": "www.vtiger.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/vtiger-crm-authenticated-rce-via-module-import-file-upload",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 783,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-23904",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-19T03:40:46.158Z",
      "date_published": "2026-07-29T09:07:18.168Z",
      "date_updated": "2026-07-29T14:00:38.959Z",
      "publisher": "apache",
      "title": "Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Kyuubi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-923",
          "name": "Improper Restriction of Communication Channel to Intended Endpoints",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00309,
        "percentile": 0.23228
      },
      "nvd": {
        "published": "2026-07-29T10:16:40.913",
        "lastModified": "2026-07-30T14:49:41.840",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-23904",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Engine UI proxy accepts a destination host and port from the request path without restricting the target to approved engine endpoints.",
        "basis": [
          "CNA",
          "CWE-923"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/kyuubi/pull/7483",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/ps79fcfx49ox9kwgztc5t5bw0tyhck9m",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/29/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 609,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-23981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-19T16:29:33.890Z",
      "date_published": "2026-07-30T16:08:26.989Z",
      "date_updated": "2026-07-30T19:35:52.546Z",
      "publisher": "apache",
      "title": "Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Superset"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.1788
      },
      "nvd": {
        "published": "2026-07-30T16:17:10.447",
        "lastModified": "2026-07-30T20:17:04.400",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-23981",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "UpdateChartCommand associates a chart with request-supplied dashboards without checking the caller's write permission on those dashboards.",
        "basis": [
          "CNA record",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/k7q9z27t901xvqnkwgyns1l7w1dj3csf",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/6",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-23985",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-19T17:23:00.841Z",
      "date_published": "2026-07-30T16:09:24.026Z",
      "date_updated": "2026-07-30T19:16:46.521Z",
      "publisher": "apache",
      "title": "Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Superset"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17326
      },
      "nvd": {
        "published": "2026-07-30T16:17:10.577",
        "lastModified": "2026-07-30T20:17:04.537",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-23985",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache Superset evaluates attacker-controlled input with a regular expression that can take excessive backtracking work.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/fdy7tx7glv90ypd7qnm1g1pt7nn336qx",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1066,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24012",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-20T02:30:29.932Z",
      "date_published": "2026-07-06T08:38:25.308Z",
      "date_updated": "2026-07-06T20:37:56.860Z",
      "publisher": "apache",
      "title": "Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache IoTDB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00678,
        "percentile": 0.48782
      },
      "nvd": {
        "published": "2026-07-06T09:16:35.037",
        "lastModified": "2026-07-07T17:53:36.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24012",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The query interface accepts an extreme time range and minimal aggregation interval, forcing an unbounded in-memory result set.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/0g5th1t2vj6j8hm5t9w3xh9n6f6ht9z8",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/06/10",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24013",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-20T02:32:08.414Z",
      "date_published": "2026-07-06T08:38:54.778Z",
      "date_updated": "2026-07-06T20:37:57.934Z",
      "publisher": "apache",
      "title": "Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache IoTDB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00521,
        "percentile": 0.41364
      },
      "nvd": {
        "published": "2026-07-06T09:16:35.163",
        "lastModified": "2026-07-07T17:50:26.877",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24013",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "IoTDB query handlers accept a forged sessionId without requiring openSession authentication or validating that the identifier belongs to an authenticated session.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/6pwkgnqhbm56mvn309f87snm84s0b75y",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/06/11",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 504,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-20T03:04:59.061Z",
      "date_published": "2026-07-06T08:34:26.447Z",
      "date_updated": "2026-07-06T20:37:58.998Z",
      "publisher": "apache",
      "title": "Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache IoTDB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00583,
        "percentile": 0.44586
      },
      "nvd": {
        "published": "2026-07-06T09:16:35.270",
        "lastModified": "2026-07-07T17:49:04.433",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24014",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "IoTDB constructs a Trigger JAR destination from a caller-controlled name without rejecting traversal sequences, allowing writes outside the Trigger directory.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/38298f803gb5j9nlhf0l9zkf34o90h3m",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/06/12",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 578,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24033",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-20T18:39:10.877Z",
      "date_published": "2026-07-29T07:22:42.043Z",
      "date_updated": "2026-07-29T13:12:49.617Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Request smuggling via chunked extension quoted-string parsing",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06457
      },
      "nvd": {
        "published": "2026-07-29T08:16:30.817",
        "lastModified": "2026-07-30T14:54:03.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24033",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Traffic Server and another HTTP participant parse quoted strings in chunk extensions differently, creating divergent request boundaries.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-24220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:35.635Z",
      "date_published": "2026-07-14T20:05:36.549Z",
      "date_updated": "2026-07-15T14:19:44.134Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT-LLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.1258
      },
      "nvd": {
        "published": "2026-07-14T21:16:43.773",
        "lastModified": "2026-07-15T16:23:03.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24220",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted input becomes executable or interpreted syntax without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24220",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24220",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:36.965Z",
      "date_published": "2026-07-14T20:07:04.904Z",
      "date_updated": "2026-07-15T14:19:20.598Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT-LLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02087
      },
      "nvd": {
        "published": "2026-07-14T21:16:43.880",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24226",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The TensorRT-LLM path allows attacker-controlled bytes to cross into an executable or interpreted grammar without the required separation.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24226",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24226",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24227",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:36.965Z",
      "date_published": "2026-07-14T20:14:39.134Z",
      "date_updated": "2026-07-15T13:16:22.288Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 4.500000000000001,
      "epss": {
        "score": 0.00696,
        "percentile": 0.49484
      },
      "nvd": {
        "published": "2026-07-14T21:16:43.983",
        "lastModified": "2026-07-17T03:31:06.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24227",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TensorRT reconstructs objects from attacker-controlled serialized data without constraining the deserialization behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24227",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24227",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5855",
          "host": "nvidia.custhelp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24229",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:36.965Z",
      "date_published": "2026-07-14T20:04:13.058Z",
      "date_updated": "2026-07-15T14:20:09.363Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT-LLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02268
      },
      "nvd": {
        "published": "2026-07-14T21:16:44.087",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24229",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24229",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24229",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:37.972Z",
      "date_published": "2026-07-21T16:07:25.130Z",
      "date_updated": "2026-07-21T17:19:03.845Z",
      "publisher": "nvidia",
      "title": "NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Tranformers4Rec"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03857
      },
      "nvd": {
        "published": "2026-07-21T17:17:06.453",
        "lastModified": "2026-07-21T18:31:51.680",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24232",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24232",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24232",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5869",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24233",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:37.972Z",
      "date_published": "2026-07-14T20:00:37.279Z",
      "date_updated": "2026-07-15T14:15:19.646Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT-LLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17985
      },
      "nvd": {
        "published": "2026-07-14T21:16:44.187",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24233",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component deserializes attacker-controlled object data without restricting executable types or behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24233",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24233",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 351,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24234",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:37.973Z",
      "date_published": "2026-07-14T20:04:56.494Z",
      "date_updated": "2026-07-15T14:45:03.236Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT-LLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01655
      },
      "nvd": {
        "published": "2026-07-14T21:16:44.293",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24234",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An NVIDIA multimodal input causes the server to fetch a caller-controlled URL without restricting its scheme, host, or resolved destination.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24234",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24234",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 278,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24238",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:37.973Z",
      "date_published": "2026-07-14T20:15:13.283Z",
      "date_updated": "2026-07-15T13:15:54.160Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00151,
        "percentile": 0.04779
      },
      "nvd": {
        "published": "2026-07-14T21:16:44.397",
        "lastModified": "2026-07-17T03:30:48.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24238",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-influenced array index is used without checking it against the destination array's bounds.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24238",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24238",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5855",
          "host": "nvidia.custhelp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 186,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24240",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:37.973Z",
      "date_published": "2026-07-01T14:43:24.661Z",
      "date_updated": "2026-07-01T16:02:40.142Z",
      "publisher": "nvidia",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Megatron-Bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.0618
      },
      "nvd": {
        "published": "2026-07-01T16:16:44.383",
        "lastModified": "2026-07-02T14:55:39.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24240",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Megatron-Bridge deserializes attacker-controlled data into object behavior that can execute in the receiving process.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24240",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24240",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24242",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:47.374Z",
      "date_published": "2026-07-01T14:48:44.441Z",
      "date_updated": "2026-07-01T16:02:13.255Z",
      "publisher": "nvidia",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Megatron-Bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04523
      },
      "nvd": {
        "published": "2026-07-01T16:16:44.510",
        "lastModified": "2026-07-02T14:56:20.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24242",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Megatron Bridge accepts an attacker-influenced server fetch destination without enforcing the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24242",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24242",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:47.375Z",
      "date_published": "2026-07-01T14:49:30.711Z",
      "date_updated": "2026-07-01T16:01:43.479Z",
      "publisher": "nvidia",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Megatron-Bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07258
      },
      "nvd": {
        "published": "2026-07-01T16:16:44.620",
        "lastModified": "2026-07-02T14:55:49.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24243",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Megatron Bridge passes attacker-controlled serialized data to a deserializer that can instantiate executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24243",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24243",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24244",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:47.375Z",
      "date_published": "2026-07-01T14:53:08.726Z",
      "date_updated": "2026-07-01T16:01:05.581Z",
      "publisher": "nvidia",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Megatron-Bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05079
      },
      "nvd": {
        "published": "2026-07-01T16:16:44.727",
        "lastModified": "2026-07-02T14:56:22.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24244",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Megatron Bridge deserializes attacker-influenced data into executable object state without a safe type or code boundary.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24244",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24244",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24245",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:47.375Z",
      "date_published": "2026-07-01T14:55:42.442Z",
      "date_updated": "2026-07-01T15:56:36.525Z",
      "publisher": "nvidia",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Megatron-Bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05079
      },
      "nvd": {
        "published": "2026-07-01T16:16:44.857",
        "lastModified": "2026-07-02T14:55:52.260",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24245",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Megatron-Bridge parser reconstructs an attacker-controlled serialized object with executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24245",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24245",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:47.375Z",
      "date_published": "2026-07-01T14:56:10.358Z",
      "date_updated": "2026-07-01T15:59:51.577Z",
      "publisher": "nvidia",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Megatron-Bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06533
      },
      "nvd": {
        "published": "2026-07-01T16:16:45.010",
        "lastModified": "2026-07-02T14:56:25.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24246",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Megatron Bridge lets externally controlled input select dynamically managed code that executes in the process.",
        "basis": [
          "CNA",
          "CWE-470"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24246",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24246",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 286,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24247",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:47.375Z",
      "date_published": "2026-07-01T14:56:43.115Z",
      "date_updated": "2026-07-01T15:59:10.202Z",
      "publisher": "nvidia",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Megatron-Bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06534
      },
      "nvd": {
        "published": "2026-07-01T16:16:45.133",
        "lastModified": "2026-07-02T14:55:56.227",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24247",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Megatron-Bridge, attacker-controlled serialized data is deserialized into live objects during security-sensitive processing.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24247",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24247",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24248",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:47.375Z",
      "date_published": "2026-07-01T14:57:15.559Z",
      "date_updated": "2026-07-01T15:58:34.670Z",
      "publisher": "nvidia",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Megatron-Bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.0721
      },
      "nvd": {
        "published": "2026-07-01T16:16:45.250",
        "lastModified": "2026-07-02T14:56:29.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24248",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Megatron-Bridge lets attacker-controlled schema, metadata, code text, or file content cross into a code-generation or execution interpreter without the quoting, allowlisting, or neutralization needed to keep it as data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24248",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24248",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24249",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:47.375Z",
      "date_published": "2026-07-01T14:57:40.156Z",
      "date_updated": "2026-07-01T15:57:54.343Z",
      "publisher": "nvidia",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Megatron-Bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06064
      },
      "nvd": {
        "published": "2026-07-01T16:16:45.357",
        "lastModified": "2026-07-02T14:56:03.253",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24249",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Megatron Bridge deserializes attacker-controlled data into executable object behavior.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24249",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24249",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24250",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:47.375Z",
      "date_published": "2026-07-01T14:58:22.971Z",
      "date_updated": "2026-07-01T15:54:21.738Z",
      "publisher": "nvidia",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Megatron-Bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05201
      },
      "nvd": {
        "published": "2026-07-01T16:16:45.467",
        "lastModified": "2026-07-02T14:56:32.730",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24250",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record associates Megatron-Bridge with unsafe interpreted input, but does not disclose the parser, grammar boundary, or execution sink.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24250",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24250",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 269,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:48.283Z",
      "date_published": "2026-07-01T14:58:48.711Z",
      "date_updated": "2026-07-01T15:54:49.582Z",
      "publisher": "nvidia",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Megatron-Bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05201
      },
      "nvd": {
        "published": "2026-07-01T16:16:45.573",
        "lastModified": "2026-07-02T14:56:17.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24251",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Megatron Bridge deserializes attacker-controlled data into dynamically managed code behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24251",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24251",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 286,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:48.283Z",
      "date_published": "2026-07-27T16:41:26.603Z",
      "date_updated": "2026-07-28T03:56:42.035Z",
      "publisher": "nvidia",
      "title": "NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "NeMo Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00686,
        "percentile": 0.49121
      },
      "nvd": {
        "published": "2026-07-27T17:16:36.167",
        "lastModified": "2026-07-28T05:17:04.577",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24252",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NVIDIA NeMo allows attacker-controlled text to alter an operating-system command.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24252",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24252",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5839",
          "host": "nvidia.custhelp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24259",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:48.284Z",
      "date_published": "2026-07-14T20:06:25.894Z",
      "date_updated": "2026-07-15T14:17:54.815Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT-LLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03666
      },
      "nvd": {
        "published": "2026-07-14T21:16:44.510",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24259",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TensorRT-LLM exposes a critical function without requiring caller authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24259",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24259",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24260",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:48.284Z",
      "date_published": "2026-07-01T14:34:54.537Z",
      "date_updated": "2026-07-02T03:57:33.130Z",
      "publisher": "nvidia",
      "title": "NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Container Toolkit"
          },
          {
            "vendor": "NVIDIA",
            "product": "GPU Operator"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24039
      },
      "nvd": {
        "published": "2026-07-01T16:16:45.683",
        "lastModified": "2026-07-02T05:16:40.560",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24260",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24260",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24260",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5850",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-24264",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:49.054Z",
      "date_published": "2026-07-01T15:11:08.653Z",
      "date_updated": "2026-07-01T15:55:16.556Z",
      "publisher": "nvidia",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Triton Inference Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00481,
        "percentile": 0.38974
      },
      "nvd": {
        "published": "2026-07-01T16:16:45.793",
        "lastModified": "2026-07-06T13:39:07.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24264",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24264",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24264",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5848",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24266",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:49.054Z",
      "date_published": "2026-07-01T15:11:30.422Z",
      "date_updated": "2026-07-01T15:55:42.553Z",
      "publisher": "nvidia",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Triton Inference Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00446,
        "percentile": 0.3665
      },
      "nvd": {
        "published": "2026-07-01T16:16:45.900",
        "lastModified": "2026-07-06T13:28:12.193",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24266",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path continues using an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24266",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24266",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5848",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24268",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:49.054Z",
      "date_published": "2026-07-14T20:15:48.589Z",
      "date_updated": "2026-07-15T13:15:25.934Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00167,
        "percentile": 0.06307
      },
      "nvd": {
        "published": "2026-07-14T21:16:44.610",
        "lastModified": "2026-07-17T03:30:25.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24268",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TensorRT can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24268",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24268",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5855",
          "host": "nvidia.custhelp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 173,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24270",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:49.054Z",
      "date_published": "2026-07-01T15:12:00.415Z",
      "date_updated": "2026-07-01T15:56:06.586Z",
      "publisher": "nvidia",
      "title": "NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "AIStore framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00513,
        "percentile": 0.40861
      },
      "nvd": {
        "published": "2026-07-01T16:16:46.017",
        "lastModified": "2026-07-01T18:32:29.917",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24270",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "AIStore permits an authentication bypass, but NVIDIA's bulletin does not disclose the spoofed identity, credential, endpoint, or failing comparison.",
        "basis": [
          "CNA",
          "CWE-290",
          "https://github.com/NVIDIA/product-security/blob/main/2026/5849/5849.md"
        ],
        "deepDive": true,
        "notes": "NVIDIA bulletin 5849 confirms versions 0 through 4.4, fixed in 4.5, and authentication bypass impact, but contains no technical mechanism."
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24270",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24270",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5849",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 242,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24271",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:51.101Z",
      "date_published": "2026-07-14T20:09:12.995Z",
      "date_updated": "2026-07-15T14:18:16.858Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resources without limits or throttling.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT-LLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02153
      },
      "nvd": {
        "published": "2026-07-14T21:16:44.717",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24271",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TensorRT-LLM accepts attacker-driven work or allocation without an effective size, rate, release, or termination bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24271",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24271",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24272",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-21T19:09:51.102Z",
      "date_published": "2026-07-14T20:16:16.922Z",
      "date_updated": "2026-07-15T13:13:37.983Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00151,
        "percentile": 0.04779
      },
      "nvd": {
        "published": "2026-07-14T21:16:44.817",
        "lastModified": "2026-07-17T03:28:54.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24272",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TensorRT can write beyond a heap allocation while processing attacker-influenced input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24272",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-24272",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5855",
          "host": "nvidia.custhelp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24451",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:26:00.298Z",
      "date_published": "2026-07-03T20:19:31.362Z",
      "date_updated": "2026-07-07T17:00:21.477Z",
      "publisher": "Gitea",
      "title": "Gitea fork synchronization can expose private parent repository data",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28056
      },
      "nvd": {
        "published": "2026-07-03T21:16:57.280",
        "lastModified": "2026-07-07T18:16:35.970",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24451",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Fork synchronization remains authorized after the parent repository transitions from public to private.",
        "basis": [
          "CNA record",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-wrf9-r3h7-7x5v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38151",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-23T12:31:40.820Z",
      "date_published": "2026-07-23T11:17:47.280Z",
      "date_updated": "2026-07-23T13:35:15.992Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Accessibility Helper (WAH) plugin <= 0.6.6 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "Alex Volkov"
        ],
        "products": [
          {
            "vendor": "Alex Volkov",
            "product": "WP Accessibility Helper (WAH)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01337
      },
      "nvd": {
        "published": "2026-07-23T12:17:12.527",
        "lastModified": "2026-07-23T14:17:09.527",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24537",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record ties WP Accessibility Helper (WAH) to a cross-origin or request-channel failure but does not identify the origin, peer, or channel binding that is missing.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-accessibility-helper/vulnerability/wordpress-wp-accessibility-helper-wah-plugin-0-6-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24552",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-23T12:31:51.715Z",
      "date_published": "2026-07-23T11:17:47.929Z",
      "date_updated": "2026-07-23T13:33:57.559Z",
      "publisher": "Patchstack",
      "title": "WordPress Create by Mediavine plugin <= 2.5.3 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "mischiefmarmot"
        ],
        "products": [
          {
            "vendor": "mischiefmarmot",
            "product": "Create by Mediavine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11466
      },
      "nvd": {
        "published": "2026-07-23T12:17:12.660",
        "lastModified": "2026-07-23T14:17:10.043",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24552",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The plugin concatenates a contributor-controlled value into an SQL query without parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mediavine-create/vulnerability/wordpress-create-by-mediavine-plugin-2-5-3-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 67,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24628",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-23T12:32:28.687Z",
      "date_published": "2026-07-23T11:17:48.587Z",
      "date_updated": "2026-07-23T15:12:34.828Z",
      "publisher": "Patchstack",
      "title": "WordPress Photo Gallery by Supsystic plugin <= 1.16.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Supsystic"
        ],
        "products": [
          {
            "vendor": "Supsystic",
            "product": "Photo Gallery by Supsystic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06852
      },
      "nvd": {
        "published": "2026-07-23T12:17:12.780",
        "lastModified": "2026-07-23T16:17:16.557",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24628",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Photo Gallery by Supsystic, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/gallery-by-supsystic/vulnerability/wordpress-photo-gallery-by-supsystic-plugin-1-16-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 90,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24639",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-23T12:32:36.811Z",
      "date_published": "2026-07-23T11:17:49.227Z",
      "date_updated": "2026-07-23T14:16:46.391Z",
      "publisher": "Patchstack",
      "title": "WordPress Photo Block plugin <= 1.7.1 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "Ronald Huereca"
        ],
        "products": [
          {
            "vendor": "Ronald Huereca",
            "product": "Photo Block"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05707
      },
      "nvd": {
        "published": "2026-07-23T12:17:12.907",
        "lastModified": "2026-07-23T15:17:03.120",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24639",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server follows an attacker-controlled outbound URL without constraining its destination to the intended remote service.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/photo-block/vulnerability/wordpress-photo-block-plugin-1-7-1-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-22T15:13:33.685Z",
      "date_published": "2026-07-03T20:19:31.693Z",
      "date_updated": "2026-07-07T17:00:15.503Z",
      "publisher": "Gitea",
      "title": "Gitea pull-request branch updates use insufficient permission checks",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24621
      },
      "nvd": {
        "published": "2026-07-03T21:16:57.397",
        "lastModified": "2026-07-07T18:16:36.117",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24690",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Gitea permits pull-request branch update or rebase actions without sufficient permission checks, but the subject-object check is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36465",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36838",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-23T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-08T15:47:34.791Z",
      "publisher": "mitre",
      "title": "An OS command injection vulnerability exists in the start_bonjour() function of the \"rc\" binary in Cisco RV130/RV130W with firmware 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00957,
        "percentile": 0.58026
      },
      "nvd": {
        "published": "2026-07-08T15:16:26.697",
        "lastModified": "2026-07-10T17:54:30.890",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24697",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The n/a path inserts attacker-controlled text into an operating-system command without preserving the command grammar.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/glkfc/IoT-Vulnerability/blob/main/cisco/RV130/2/wp-en.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-23T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-08T15:45:48.489Z",
      "publisher": "mitre",
      "title": "An OS command injection vulnerability exists in the save_syslog_to_file() function of the \"httpd\" binary in Cisco RV130/RV130W with firmware 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00957,
        "percentile": 0.58026
      },
      "nvd": {
        "published": "2026-07-08T15:16:26.827",
        "lastModified": "2026-07-10T17:51:09.083",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24698",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled value is evaluated in an interpreter context without separating data from grammar.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/glkfc/IoT-Vulnerability/blob/main/cisco/RV130/3/wp-en.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 373,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24699",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-23T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-08T15:45:27.072Z",
      "publisher": "mitre",
      "title": "An OS command injection vulnerability exists in the sub_34984() function of the \"rc\" binary in Cisco RV130/RV130W with firmware 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00957,
        "percentile": 0.58025
      },
      "nvd": {
        "published": "2026-07-08T15:16:26.943",
        "lastModified": "2026-07-10T17:50:43.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24699",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The n/a command path concatenates attacker-controlled data into an operating-system command without preserving the shell grammar boundary.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/glkfc/IoT-Vulnerability/blob/main/cisco/RV130/4/wp-en.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 368,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24700",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-23T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-08T15:49:09.772Z",
      "publisher": "mitre",
      "title": "An OS command injection vulnerability exists in the start_lltd() function of the \"rc\" binary in Cisco RV130/RV130W with firmware 1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01522,
        "percentile": 0.72116
      },
      "nvd": {
        "published": "2026-07-08T15:16:27.047",
        "lastModified": "2026-07-10T17:49:52.123",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-24700",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A Cisco handler places machine_name into an operating-system command without the required shell separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/glkfc/IoT-Vulnerability/blob/main/cisco/RV130/1/wp-en.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-24727",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-26T07:42:53.159Z",
      "date_published": "2026-07-24T08:29:06.889Z",
      "date_updated": "2026-07-24T12:33:09.459Z",
      "publisher": "ZUSO ART",
      "title": "SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type",
      "affected": {
        "vendors": [
          "SUNNET Technology Co., Ltd."
        ],
        "products": [
          {
            "vendor": "SUNNET Technology Co., Ltd.",
            "product": "Corporate Training Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H"
        },
        {
          "source": "NVD:ART@zuso.ai",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0067,
        "percentile": 0.4846
      },
      "nvd": {
        "published": "2026-07-24T09:16:24.520",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-24727",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://zuso.ai/advisory",
          "host": "zuso.ai",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25038",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:26:00.351Z",
      "date_published": "2026-07-03T20:19:32.042Z",
      "date_updated": "2026-07-07T17:00:09.768Z",
      "publisher": "Gitea",
      "title": "Gitea private organization labels are visible to unauthorized users",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00424,
        "percentile": 0.34904
      },
      "nvd": {
        "published": "2026-07-03T21:16:57.503",
        "lastModified": "2026-07-07T18:16:36.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25038",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-v73x-hx65-6pf4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38151",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 81,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25039",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-01-28T14:50:47.885Z",
      "date_published": "2026-07-20T14:53:13.505Z",
      "date_updated": "2026-07-20T16:29:08.661Z",
      "publisher": "GitHub_M",
      "title": "The application evaluate UNC path in workspace name",
      "affected": {
        "vendors": [
          "Scille"
        ],
        "products": [
          {
            "vendor": "Scille",
            "product": "parsec-cloud"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-40",
          "name": "Path Traversal: '\\\\UNC\\share\\name\\' (Windows UNC Share)",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.2708
      },
      "nvd": {
        "published": "2026-07-20T16:16:56.913",
        "lastModified": "2026-07-23T17:58:34.990",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25039",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Parsec accepts a UNC path in a workspace name and resolves it outside the intended local workspace namespace.",
        "basis": [
          "CNA",
          "CWE-40"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Scille/parsec-cloud/security/advisories/GHSA-qx56-wxpm-j4m6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 689,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25268",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-02T04:19:00.940Z",
      "date_published": "2026-07-06T20:09:41.411Z",
      "date_updated": "2026-07-07T03:56:16.611Z",
      "publisher": "qualcomm",
      "title": "Stack-based Buffer Overflow in WLAN Host",
      "affected": {
        "vendors": [
          "Qualcomm, Inc."
        ],
        "products": [
          {
            "vendor": "Qualcomm, Inc.",
            "product": "Snapdragon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 128,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:product-security@qualcomm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00072,
        "percentile": 0.00068
      },
      "nvd": {
        "published": "2026-07-06T21:16:54.730",
        "lastModified": "2026-07-07T16:37:11.267",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-25268",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data is copied beyond the boundary of a stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html",
          "host": "docs.qualcomm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 128
      }
    },
    {
      "cve_id": "CVE-2026-25271",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-02T04:19:00.940Z",
      "date_published": "2026-07-06T20:09:42.512Z",
      "date_updated": "2026-07-07T03:56:19.834Z",
      "publisher": "qualcomm",
      "title": "Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service",
      "affected": {
        "vendors": [
          "Qualcomm, Inc."
        ],
        "products": [
          {
            "vendor": "Qualcomm, Inc.",
            "product": "Snapdragon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 21,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:product-security@qualcomm.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00052,
        "percentile": 0.00002
      },
      "nvd": {
        "published": "2026-07-06T21:16:54.903",
        "lastModified": "2026-07-07T16:35:38.123",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-25271",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Asynchronous DSP processing validates a value and later consumes the same mutable input after it can be changed, creating a check-to-use race.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html",
          "host": "docs.qualcomm.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 21
      }
    },
    {
      "cve_id": "CVE-2026-25405",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-02T12:53:19.001Z",
      "date_published": "2026-07-23T11:17:49.885Z",
      "date_updated": "2026-07-23T16:03:57.753Z",
      "publisher": "Patchstack",
      "title": "WordPress eRoom plugin <= 1.7.1 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "DigitalME"
        ],
        "products": [
          {
            "vendor": "DigitalME",
            "product": "eRoom"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11466
      },
      "nvd": {
        "published": "2026-07-23T12:17:13.803",
        "lastModified": "2026-07-23T16:17:16.653",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25405",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A contributor-controlled eRoom value reaches an SQL command without the required SQL-data separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/eroom-zoom-meetings-webinar/vulnerability/wordpress-eroom-plugin-1-7-1-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 53,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-02T12:53:34.261Z",
      "date_published": "2026-07-23T11:17:50.517Z",
      "date_updated": "2026-07-23T14:54:12.497Z",
      "publisher": "Patchstack",
      "title": "WordPress Mediavine Control Panel plugin <= 2.10.10 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "mediavine"
        ],
        "products": [
          {
            "vendor": "mediavine",
            "product": "Mediavine Control Panel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00185,
        "percentile": 0.08321
      },
      "nvd": {
        "published": "2026-07-23T12:17:13.927",
        "lastModified": "2026-07-23T16:17:16.753",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25424",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Mediavine Control Panel lets a contributor perform an operation outside that role's intended authority, but the object and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mediavine-control-panel/vulnerability/wordpress-mediavine-control-panel-plugin-2-10-10-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 81,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-02T12:53:34.262Z",
      "date_published": "2026-07-23T11:17:51.168Z",
      "date_updated": "2026-07-23T13:34:28.653Z",
      "publisher": "Patchstack",
      "title": "WordPress eRoom plugin <= 1.7.1 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "DigitalME"
        ],
        "products": [
          {
            "vendor": "DigitalME",
            "product": "eRoom"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.1967
      },
      "nvd": {
        "published": "2026-07-23T12:17:14.050",
        "lastModified": "2026-07-23T14:17:10.497",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25427",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A subscriber can perform an operation outside that role's intended authority, but the public record does not identify the endpoint, object, or missing check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/eroom-zoom-meetings-webinar/vulnerability/wordpress-eroom-plugin-1-7-1-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 60,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25466",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-02T12:53:59.642Z",
      "date_published": "2026-07-23T11:17:51.814Z",
      "date_updated": "2026-07-23T13:34:26.978Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Go Maps plugin <= 10.1.04 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "WPGMaps"
        ],
        "products": [
          {
            "vendor": "WPGMaps",
            "product": "WP Go Maps"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13615
      },
      "nvd": {
        "published": "2026-07-23T12:17:14.173",
        "lastModified": "2026-07-23T14:17:10.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25466",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The WP Go Maps operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-google-maps/vulnerability/wordpress-wp-go-maps-plugin-10-1-04-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 72,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25552",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-02T20:12:33.395Z",
      "date_published": "2026-07-31T18:12:40.072Z",
      "date_updated": "2026-07-31T19:00:37.919Z",
      "publisher": "VulnCheck",
      "title": "Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header",
      "affected": {
        "vendors": [
          "TryGhost"
        ],
        "products": [
          {
            "vendor": "TryGhost",
            "product": "Ghost-CLI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-348",
          "name": "Use of Less Trusted Source",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06949
      },
      "nvd": {
        "published": "2026-07-31T19:17:08.663",
        "lastModified": "2026-07-31T19:17:08.663",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25552",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The default proxy chain trusts an attacker-appended X-Forwarded-For value as the client address used for rate limiting.",
        "basis": [
          "CNA",
          "CWE-348"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/TryGhost/Ghost-CLI/security/advisories/GHSA-wjx2-9fpq-8997",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.vulncheck.com/advisories/ghost-cli-ip-spoofing-via-x-forwarded-for-header",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 451,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25712",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:28.672Z",
      "date_published": "2026-07-03T20:19:32.421Z",
      "date_updated": "2026-07-07T16:59:58.397Z",
      "publisher": "Gitea",
      "title": "Gitea organization permission APIs expose private visibility information",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28008
      },
      "nvd": {
        "published": "2026-07-03T21:16:57.607",
        "lastModified": "2026-07-07T18:16:36.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25712",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Organization permission APIs return hidden-member or private-organization visibility data without applying the corresponding visibility rule.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36798",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25714",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:50.209Z",
      "date_published": "2026-07-03T20:19:32.756Z",
      "date_updated": "2026-07-07T16:59:52.655Z",
      "publisher": "Gitea",
      "title": "Gitea user organization API bypasses public-only token filtering",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25723
      },
      "nvd": {
        "published": "2026-07-03T21:16:57.707",
        "lastModified": "2026-07-07T18:16:36.550",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25714",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gitea Open Source Git Server fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-8629-vc8r-5p58",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/37118",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.2/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25718",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-22T15:13:33.721Z",
      "date_published": "2026-07-03T20:19:33.104Z",
      "date_updated": "2026-07-07T16:59:46.910Z",
      "publisher": "Gitea",
      "title": "Gitea template repository generation mishandles symlinked paths",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00428,
        "percentile": 0.35227
      },
      "nvd": {
        "published": "2026-07-03T21:16:57.823",
        "lastModified": "2026-07-07T18:16:36.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25718",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Template generation follows symlinked or non-regular paths and reads or writes through them outside the intended repository object set.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36734",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36746",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25779",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-22T15:13:33.665Z",
      "date_published": "2026-07-03T20:19:33.452Z",
      "date_updated": "2026-07-07T16:59:40.949Z",
      "publisher": "Gitea",
      "title": "Gitea redirect handling permits open redirects through backslash paths",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16112
      },
      "nvd": {
        "published": "2026-07-03T21:16:57.923",
        "lastModified": "2026-07-07T18:16:36.797",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25779",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Gitea's redirect validation fails to reject raw or encoded backslashes, allowing a redirect target to escape the intended local path form.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-j5r2-4c8j-xc3m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36660",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36716",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25782",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-22T15:13:33.711Z",
      "date_published": "2026-07-03T20:19:33.790Z",
      "date_updated": "2026-07-07T16:59:35.214Z",
      "publisher": "Gitea",
      "title": "Gitea tracked-time deletion can target entries from another issue",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20827
      },
      "nvd": {
        "published": "2026-07-03T21:16:58.030",
        "lastModified": "2026-07-07T18:16:36.937",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25782",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Gitea looks up a tracked-time entry by its ID without binding that entry to the issue named in the deletion URL.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36664",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36689",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-25800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-05T19:58:01.641Z",
      "date_published": "2026-07-23T19:09:19.159Z",
      "date_updated": "2026-07-23T19:37:11.300Z",
      "publisher": "GitHub_M",
      "title": "quinn-proto has remote memory exhaustion from unbounded out-of-order stream reassembly",
      "affected": {
        "vendors": [
          "quinn-rs"
        ],
        "products": [
          {
            "vendor": "quinn-rs",
            "product": "quinn"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26484
      },
      "nvd": {
        "published": "2026-07-23T20:17:07.860",
        "lastModified": "2026-07-30T19:59:01.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-25800",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Quinn buffers arbitrarily many noncontiguous out-of-order stream fragments without an effective overhead bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/quinn-rs/quinn/security/advisories/GHSA-4w2j-m93h-cj5j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/quinn-rs/quinn/pull/2694",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0185.html",
          "host": "rustsec.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 709,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26032",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-09T22:55:23.574Z",
      "date_published": "2026-07-15T18:49:43.153Z",
      "date_updated": "2026-07-15T19:31:07.994Z",
      "publisher": "apache",
      "title": "Apache Ivy: PackagerResolver path traversal vulnerability",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Ivy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00507,
        "percentile": 0.40526
      },
      "nvd": {
        "published": "2026-07-15T19:17:10.447",
        "lastModified": "2026-07-16T02:57:40.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-26032",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Apache Ivy builds its work directory from unnormalized module coordinates, so ../ segments in repository metadata escape buildRoot and overwrite other files.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/4d9dzrlnoplvywnyj9x6w84kxg7n3jyq",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/15/5",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 834,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26053",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-01T23:45:09.665Z",
      "date_published": "2026-07-07T03:48:47.708Z",
      "date_updated": "2026-07-07T13:37:52.035Z",
      "publisher": "Gallagher",
      "title": "An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform.",
      "affected": {
        "vendors": [
          "Gallagher"
        ],
        "products": [
          {
            "vendor": "Gallagher",
            "product": "Command Centre Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosures@gallagher.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04932
      },
      "nvd": {
        "published": "2026-07-07T05:16:50.117",
        "lastModified": "2026-07-07T14:16:29.567",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-26053",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform.",
        "basis": [
          "CNA",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-26053",
          "host": "security.gallagher.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-26080",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-11T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-20T18:16:43.967Z",
      "publisher": "mitre",
      "title": "HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.",
      "affected": {
        "vendors": [
          "HAProxy"
        ],
        "products": [
          {
            "vendor": "HAProxy",
            "product": "HAProxy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-252",
          "name": "Unchecked Return Value",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00416,
        "percentile": 0.3425
      },
      "nvd": {
        "published": "2026-07-20T16:16:57.057",
        "lastModified": "2026-07-21T19:49:44.020",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-26080",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The varint parser can enter a non-terminating or crashing state because malformed encodings are not rejected consistently.",
        "basis": [
          "CNA",
          "CWE-252"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.haproxy.org",
          "host": "www.haproxy.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.haproxy.org/?p=haproxy-3.2.git;a=commit;h=5bb098ce8a656ec5711b4de3e4c87f12b216e7a1",
          "host": "git.haproxy.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 162,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-26081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-11T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-20T18:18:45.876Z",
      "publisher": "mitre",
      "title": "HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.",
      "affected": {
        "vendors": [
          "HAProxy"
        ],
        "products": [
          {
            "vendor": "HAProxy",
            "product": "HAProxy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-130",
          "name": "Improper Handling of Length Parameter Inconsistency",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00363,
        "percentile": 0.28973
      },
      "nvd": {
        "published": "2026-07-20T16:16:57.203",
        "lastModified": "2026-07-21T19:49:44.020",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-26081",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The NEW_TOKEN parser accepts an inconsistent length value without first confirming that the declared token length fits the available input.",
        "basis": [
          "CNA",
          "CWE-130"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.haproxy.org",
          "host": "www.haproxy.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.haproxy.org/?p=haproxy-3.2.git;a=commit;h=4765277f4f915baac2d57db63538ff0a59966deb",
          "host": "git.haproxy.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-26145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-11T16:24:51.134Z",
      "date_published": "2026-07-02T22:18:56.842Z",
      "date_updated": "2026-08-03T22:52:40.297Z",
      "publisher": "microsoft",
      "title": "Microsoft Azure Synapse Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure Synapse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 5.000000000000001,
      "epss": {
        "score": 0.00359,
        "percentile": 0.28569
      },
      "nvd": {
        "published": "2026-07-02T23:16:49.813",
        "lastModified": "2026-07-07T14:27:00.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-26145",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Azure Synapse grants an already authorized network caller additional privilege through an undisclosed access-control failure.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26145"
        ],
        "deepDive": true,
        "notes": "The linked MSRC detail surface was inspected but did not expose more technical detail than the CNA record during review; the failing Azure Synapse access check remains undisclosed."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26145",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26197",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-11T19:56:24.813Z",
      "date_published": "2026-07-20T14:55:50.636Z",
      "date_updated": "2026-07-20T15:34:11.301Z",
      "publisher": "GitHub_M",
      "title": "Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c",
      "affected": {
        "vendors": [
          "HDFGroup"
        ],
        "products": [
          {
            "vendor": "HDFGroup",
            "product": "hdf5"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18671
      },
      "nvd": {
        "published": "2026-07-20T16:16:57.400",
        "lastModified": "2026-07-29T15:42:12.557",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-26197",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "hdf5 reads beyond a valid memory object because an input length or pointer is not validated against the available buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/HDFGroup/hdf5/security/advisories/GHSA-gh44-7wpq-622f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1016,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26199",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-11T19:56:24.813Z",
      "date_published": "2026-07-20T14:59:35.038Z",
      "date_updated": "2026-07-20T18:56:52.113Z",
      "publisher": "GitHub_M",
      "title": "Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero",
      "affected": {
        "vendors": [
          "HDFGroup"
        ],
        "products": [
          {
            "vendor": "HDFGroup",
            "product": "hdf5"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-124",
          "name": "Buffer Underwrite ('Buffer Underflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17137
      },
      "nvd": {
        "published": "2026-07-20T16:16:57.550",
        "lastModified": "2026-07-29T15:38:17.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-26199",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "H5Iget_name subtracts for a terminator when size is zero and writes before the start of the supplied buffer.",
        "basis": [
          "CNA",
          "CWE-124"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/HDFGroup/hdf5/security/advisories/GHSA-5c6x-jmgf-f5vc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/HDFGroup/hdf5/blob/develop/src/H5Gname.c#L474",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 392,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26231",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:59.965Z",
      "date_published": "2026-07-03T20:19:34.133Z",
      "date_updated": "2026-07-07T16:59:29.212Z",
      "publisher": "Gitea",
      "title": "Gitea maintainer-edit permissions allow unauthorized commits to readable repositories",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21384
      },
      "nvd": {
        "published": "2026-07-03T21:16:58.200",
        "lastModified": "2026-07-07T18:16:37.077",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-26231",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The maintainer edit path treats repository readability as sufficient authority to modify the repository.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-mm7c-rhg6-qr4r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/37479",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/37484",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.2/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:28.619Z",
      "date_published": "2026-07-03T20:19:34.473Z",
      "date_updated": "2026-07-07T16:59:23.495Z",
      "publisher": "Gitea",
      "title": "Gitea OAuth2 authorization codes lack expiry and reuse enforcement",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30628
      },
      "nvd": {
        "published": "2026-07-03T21:16:58.313",
        "lastModified": "2026-07-07T18:16:37.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-26232",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OAuth authorization codes remain exchangeable after expiry and after a prior successful use.",
        "basis": [
          "CNA record",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36797",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36851",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26247",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:28.654Z",
      "date_published": "2026-07-03T20:19:34.820Z",
      "date_updated": "2026-07-07T16:59:17.604Z",
      "publisher": "Gitea",
      "title": "Gitea OAuth2 PKCE S256 challenges are not enforced during token exchange",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30628
      },
      "nvd": {
        "published": "2026-07-03T21:16:58.417",
        "lastModified": "2026-07-07T18:16:37.327",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-26247",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gitea fails to persist the PKCE S256 challenge method and consequently exchanges the authorization code without enforcing the verifier.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36462",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36477",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 174,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26292",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-22T15:13:33.694Z",
      "date_published": "2026-07-03T20:19:35.166Z",
      "date_updated": "2026-07-07T16:59:11.597Z",
      "publisher": "Gitea",
      "title": "Gitea LFS mirror synchronization bypasses migration HTTP transport restrictions",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00482,
        "percentile": 0.39031
      },
      "nvd": {
        "published": "2026-07-03T21:16:58.517",
        "lastModified": "2026-07-07T18:16:37.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-26292",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "LFS push and mirror synchronization bypass the configured protected migration transport and send their requests through a different HTTP path.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36665",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36691",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26307",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:28.646Z",
      "date_published": "2026-07-03T20:19:35.520Z",
      "date_updated": "2026-07-09T14:43:25.768Z",
      "publisher": "Gitea",
      "title": "Gitea git grep search lacks a timeout",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00466,
        "percentile": 0.3798
      },
      "nvd": {
        "published": "2026-07-03T21:16:58.620",
        "lastModified": "2026-07-09T16:16:39.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-26307",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gitea runs attacker-influenced git grep searches without a timeout, allowing one search to retain CPU and server work indefinitely.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36809",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36835",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26355",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-13T18:05:27.825Z",
      "date_published": "2026-07-03T12:41:34.555Z",
      "date_updated": "2026-07-07T03:56:14.341Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01052,
        "percentile": 0.61023
      },
      "nvd": {
        "published": "2026-07-03T13:17:02.320",
        "lastModified": "2026-07-08T19:34:55.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-26355",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text reaches an operating-system command boundary without shell-safe argument separation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 451,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-26396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-16T00:00:00.000Z",
      "date_published": "2026-07-13T00:00:00.000Z",
      "date_updated": "2026-07-13T19:45:59.471Z",
      "publisher": "mitre",
      "title": "OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/application/routers/workspace.py. The input parameter “filename” is user-controllable and is concatenated into the file path t...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00746,
        "percentile": 0.51264
      },
      "nvd": {
        "published": "2026-07-13T19:17:03.320",
        "lastModified": "2026-07-13T20:37:48.157",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-26396",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file() route concatenates the user-controlled filename into a read path without confining the resolved path to the workspace.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/jack2223333/f79f233b67d6506b9dd184399525cbf4",
          "host": "gist.github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 373,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26483",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-16T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-20T18:17:59.743Z",
      "publisher": "mitre",
      "title": "Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input in the content parameter of the /temp...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05979
      },
      "nvd": {
        "published": "2026-07-20T18:16:50.733",
        "lastModified": "2026-07-23T18:28:20.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-26483",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The n/a rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mettle/sendportal",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/WinBlah12/8dbc1eae788945c6ea6ab1a2cdfd7cb1",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26718",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-16T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-16T18:28:28.231Z",
      "publisher": "mitre",
      "title": "A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13104
      },
      "nvd": {
        "published": "2026-07-15T22:16:45.980",
        "lastModified": "2026-07-16T19:16:44.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-26718",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A state-changing operation accepts requests without a CSRF token or method constraint that binds the action to the initiating site.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xxl-job-admin.com",
          "host": "xxl-job-admin.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/Ibrahim-Sartawi/CVE-2026-26718",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-26719",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-16T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-16T18:47:37.768Z",
      "publisher": "mitre",
      "title": "Cross Site Scripting vulnerability in xxl-job-admin v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00356,
        "percentile": 0.28325
      },
      "nvd": {
        "published": "2026-07-15T22:16:46.100",
        "lastModified": "2026-07-16T19:16:44.937",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-26719",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The n/a rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Ibrahim-Sartawi/CVE-2026-26719",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27060",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-17T13:23:42.766Z",
      "date_published": "2026-07-02T11:14:50.700Z",
      "date_updated": "2026-08-03T09:55:06.664Z",
      "publisher": "Patchstack",
      "title": "WordPress ARMember Premium plugin < 7.6 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "Repute Infosystems"
        ],
        "products": [
          {
            "vendor": "Repute Infosystems",
            "product": "ARMember Premium"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.2017
      },
      "nvd": {
        "published": "2026-07-02T12:16:58.940",
        "lastModified": "2026-08-03T10:16:28.473",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27060",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ARMember deserializes attacker-controlled PHP objects without restricting the classes or gadget behavior that may be invoked.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/armember/vulnerability/wordpress-armember-premium-plugin-7-0-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27064",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-17T13:23:42.767Z",
      "date_published": "2026-07-23T11:17:52.448Z",
      "date_updated": "2026-07-23T15:02:08.355Z",
      "publisher": "Patchstack",
      "title": "WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability",
      "affected": {
        "vendors": [
          "EverPress"
        ],
        "products": [
          {
            "vendor": "EverPress",
            "product": "Mailster"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19972
      },
      "nvd": {
        "published": "2026-07-23T12:17:16.810",
        "lastModified": "2026-07-23T16:17:16.853",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27064",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Mailster permits an editor to upload an arbitrary file type, while Patchstack does not publish the request handler, destination, or file-validation rule.",
        "basis": [
          "CNA",
          "CWE-434",
          "Patchstack PSID 159961276703"
        ],
        "deepDive": true,
        "notes": "Inspected https://patchstack.com/database/wordpress/plugin/mailster/vulnerability/wordpress-mailster-plugin-4-1-17-arbitrary-file-upload-vulnerability. Patchstack confirms editor privilege, affected versions through 4.1.17, fixed version 4.1.18, and arbitrary file upload, but publishes no handler, destination, or validation rule. Its Medium priority label coexists with CVSS 9.1 and is a separate Patchstack prioritization field rather than a second CVSS severity."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mailster/vulnerability/wordpress-mailster-plugin-4-1-17-arbitrary-file-upload-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 60,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27355",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:51:41.703Z",
      "date_published": "2026-07-23T11:17:53.078Z",
      "date_updated": "2026-07-23T14:18:16.707Z",
      "publisher": "Patchstack",
      "title": "WordPress Ditty plugin <= 3.1.66 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "metaphorcreations"
        ],
        "products": [
          {
            "vendor": "metaphorcreations",
            "product": "Ditty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19966
      },
      "nvd": {
        "published": "2026-07-23T12:17:17.770",
        "lastModified": "2026-07-23T15:17:03.983",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27355",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Patchstack record reports an unauthenticated protected operation but does not name the action, object, or missing capability check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ditty-news-ticker/vulnerability/wordpress-ditty-plugin-3-1-66-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 66,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27372",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:51:54.220Z",
      "date_published": "2026-07-23T11:17:53.712Z",
      "date_updated": "2026-07-23T16:03:06.902Z",
      "publisher": "Patchstack",
      "title": "WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Pepro Dev. Group"
        ],
        "products": [
          {
            "vendor": "Pepro Dev. Group",
            "product": "PeproDev Ultimate Invoice"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18745
      },
      "nvd": {
        "published": "2026-07-23T12:17:17.890",
        "lastModified": "2026-07-23T16:17:16.953",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27372",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/pepro-ultimate-invoice/vulnerability/wordpress-peprodev-ultimate-invoice-plugin-2-2-6-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 87,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:51:58.586Z",
      "date_published": "2026-07-23T11:17:54.366Z",
      "date_updated": "2026-07-23T14:54:03.075Z",
      "publisher": "Patchstack",
      "title": "WordPress QuickCal - Appointment Booking Calendar for WordPress plugin <= 1.0.16 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "axiomthemes"
        ],
        "products": [
          {
            "vendor": "axiomthemes",
            "product": "QuickCal - Appointment Booking Calendar for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18941
      },
      "nvd": {
        "published": "2026-07-23T12:17:18.020",
        "lastModified": "2026-07-23T16:17:17.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27377",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "QuickCal exposes a protected operation without publishing the exact permission or ownership check that is missing.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/quickcal/vulnerability/wordpress-quickcal-appointment-booking-calendar-for-wordpress-plugin-1-0-16-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:03.312Z",
      "date_published": "2026-07-23T11:17:55.023Z",
      "date_updated": "2026-07-23T13:34:05.961Z",
      "publisher": "Patchstack",
      "title": "WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Stylemix"
        ],
        "products": [
          {
            "vendor": "Stylemix",
            "product": "uListing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19669
      },
      "nvd": {
        "published": "2026-07-23T12:17:18.153",
        "lastModified": "2026-07-23T14:17:11.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27391",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ulisting/vulnerability/wordpress-ulisting-plugin-2-2-0-broken-access-control-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 63,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:03.313Z",
      "date_published": "2026-07-23T11:17:55.685Z",
      "date_updated": "2026-07-23T13:34:50.359Z",
      "publisher": "Patchstack",
      "title": "WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Stylemix"
        ],
        "products": [
          {
            "vendor": "Stylemix",
            "product": "uListing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00185,
        "percentile": 0.08326
      },
      "nvd": {
        "published": "2026-07-23T12:17:18.277",
        "lastModified": "2026-07-23T14:17:11.890",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27392",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "uListing exposes a protected action without checking the caller's required permission.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ulisting/vulnerability/wordpress-ulisting-plugin-2-2-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 64,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:08.214Z",
      "date_published": "2026-07-23T11:17:56.328Z",
      "date_updated": "2026-07-23T15:03:01.131Z",
      "publisher": "Patchstack",
      "title": "WordPress MarketKing plugin <= 2.1.40 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "WebWizards"
        ],
        "products": [
          {
            "vendor": "WebWizards",
            "product": "MarketKing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11857
      },
      "nvd": {
        "published": "2026-07-23T12:17:18.400",
        "lastModified": "2026-07-23T16:17:17.160",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27399",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated caller can perform a MarketKing operation without a required authorization check, but the affected object and action are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/marketking-multivendor-marketplace-for-woocommerce/vulnerability/wordpress-marketking-plugin-2-1-40-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 71,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27402",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:08.215Z",
      "date_published": "2026-07-02T11:14:51.643Z",
      "date_updated": "2026-07-02T12:48:15.305Z",
      "publisher": "Patchstack",
      "title": "WordPress Kids Life | Children School WordPress theme <= 5.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Designthemes"
        ],
        "products": [
          {
            "vendor": "Designthemes",
            "product": "Kids Life | Children School WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07167
      },
      "nvd": {
        "published": "2026-07-02T12:16:59.817",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27402",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The theme places unauthenticated attacker-controlled content into a browser-interpreted page without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/kidslife/vulnerability/wordpress-kids-life-children-school-wordpress-theme-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:08.215Z",
      "date_published": "2026-07-23T11:17:56.966Z",
      "date_updated": "2026-07-23T19:32:40.652Z",
      "publisher": "Patchstack",
      "title": "WordPress Hubbub Lite plugin <= 1.36.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "NerdPress"
        ],
        "products": [
          {
            "vendor": "NerdPress",
            "product": "Hubbub Lite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05713
      },
      "nvd": {
        "published": "2026-07-23T12:17:18.520",
        "lastModified": "2026-07-23T20:17:08.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27403",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The plugin stores attacker-controlled content and later renders it as executable browser markup without sufficient output neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/social-pug/vulnerability/wordpress-hubbub-lite-plugin-1-36-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:08.215Z",
      "date_published": "2026-07-02T11:14:52.554Z",
      "date_updated": "2026-07-02T14:51:33.339Z",
      "publisher": "Patchstack",
      "title": "WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Designthemes"
        ],
        "products": [
          {
            "vendor": "Designthemes",
            "product": "LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07166
      },
      "nvd": {
        "published": "2026-07-02T12:16:59.940",
        "lastModified": "2026-07-02T15:16:59.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27404",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The LMS page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/lms/vulnerability/wordpress-lms-theme-9-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 66,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27408",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:22.262Z",
      "date_published": "2026-07-02T11:14:53.444Z",
      "date_updated": "2026-07-02T14:55:17.399Z",
      "publisher": "Patchstack",
      "title": "WordPress NativeChurch theme <= 4.8.8.2 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "imithemes"
        ],
        "products": [
          {
            "vendor": "imithemes",
            "product": "NativeChurch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07164
      },
      "nvd": {
        "published": "2026-07-02T12:17:00.060",
        "lastModified": "2026-07-02T15:16:59.543",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27408",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NativeChurch permits unauthenticated input to reach page output as executable browser markup.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/nativechurch/vulnerability/wordpress-nativechurch-theme-4-8-8-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 79,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:22.262Z",
      "date_published": "2026-07-01T16:07:56.891Z",
      "date_updated": "2026-07-01T17:34:50.305Z",
      "publisher": "Patchstack",
      "title": "WordPress Webba Booking plugin <= 6.4.13 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Webba Plugins"
        ],
        "products": [
          {
            "vendor": "Webba Plugins",
            "product": "Webba Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09345
      },
      "nvd": {
        "published": "2026-07-01T17:16:32.220",
        "lastModified": "2026-07-01T18:22:18.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27409",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Webba Booking permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/webba-booking-lite/vulnerability/wordpress-webba-booking-plugin-6-4-13-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27412",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:22.262Z",
      "date_published": "2026-07-02T11:14:54.552Z",
      "date_updated": "2026-07-02T19:43:01.771Z",
      "publisher": "Patchstack",
      "title": "WordPress Pearl - Corporate Business theme <= 3.4.10 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "StylemixThemes"
        ],
        "products": [
          {
            "vendor": "StylemixThemes",
            "product": "Pearl - Corporate Business"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19576
      },
      "nvd": {
        "published": "2026-07-02T12:17:00.183",
        "lastModified": "2026-07-02T20:17:02.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27412",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pearl - Corporate Business allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/pearl/vulnerability/wordpress-pearl-corporate-business-theme-3-4-10-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 86,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27414",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:22.262Z",
      "date_published": "2026-07-02T11:14:55.517Z",
      "date_updated": "2026-07-02T15:53:44.804Z",
      "publisher": "Patchstack",
      "title": "WordPress Werkstatt theme <= 4.8.3 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "Fuelthemes"
        ],
        "products": [
          {
            "vendor": "Fuelthemes",
            "product": "Werkstatt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.2017
      },
      "nvd": {
        "published": "2026-07-02T12:17:00.313",
        "lastModified": "2026-07-02T16:16:30.227",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27414",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Werkstatt accepts contributor-controlled serialized PHP data that can instantiate attacker-selected object behavior.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/werkstatt/vulnerability/wordpress-werkstatt-theme-4-8-3-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 64,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:28.127Z",
      "date_published": "2026-07-23T11:17:57.727Z",
      "date_updated": "2026-07-23T16:02:24.492Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Fast Total Search plugin <= 1.81.282 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Epsiloncool"
        ],
        "products": [
          {
            "vendor": "Epsiloncool",
            "product": "WP Fast Total Search"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11855
      },
      "nvd": {
        "published": "2026-07-23T12:17:18.643",
        "lastModified": "2026-07-23T16:17:17.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27418",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in WP Fast Total Search, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/fulltext-search/vulnerability/wordpress-wp-fast-total-search-plugin-1-81-282-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27419",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:28.127Z",
      "date_published": "2026-07-02T11:14:56.371Z",
      "date_updated": "2026-07-02T12:12:11.625Z",
      "publisher": "Patchstack",
      "title": "WordPress Zegen theme <= 1.1.9 - Arbitrary File Upload vulnerability",
      "affected": {
        "vendors": [
          "Zozothemes"
        ],
        "products": [
          {
            "vendor": "Zozothemes",
            "product": "Zegen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27864
      },
      "nvd": {
        "published": "2026-07-02T12:17:00.437",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27419",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Zegen theme permits a subscriber to store an uploaded file of a dangerous type without enforcing the intended upload restrictions.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/zegen/vulnerability/wordpress-zegen-theme-1-1-9-arbitrary-file-upload-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 60,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:28.127Z",
      "date_published": "2026-07-23T11:17:58.367Z",
      "date_updated": "2026-07-23T14:53:53.072Z",
      "publisher": "Patchstack",
      "title": "WordPress YT Player plugin <= 2.0.9 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "bPlugins"
        ],
        "products": [
          {
            "vendor": "bPlugins",
            "product": "YT Player"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11853
      },
      "nvd": {
        "published": "2026-07-23T12:17:18.767",
        "lastModified": "2026-07-23T16:17:17.360",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27422",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "YT Player exposes an operation without authentication, but the public record does not identify the object or action whose authorization is missing.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/yt-player/vulnerability/wordpress-yt-player-plugin-2-0-9-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 69,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:28.127Z",
      "date_published": "2026-07-23T11:17:59.004Z",
      "date_updated": "2026-07-23T13:33:41.163Z",
      "publisher": "Patchstack",
      "title": "WordPress Participants Database plugin <= 2.7.8.4 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Roland Barker"
        ],
        "products": [
          {
            "vendor": "Roland Barker",
            "product": "Participants Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15605
      },
      "nvd": {
        "published": "2026-07-23T12:17:18.893",
        "lastModified": "2026-07-23T14:17:12.323",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27423",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Participants Database grants a subscriber an operation outside that role's intended authority, while the affected action and check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/participants-database/vulnerability/wordpress-participants-database-plugin-2-7-8-4-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 78,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:28.127Z",
      "date_published": "2026-07-02T11:14:57.235Z",
      "date_updated": "2026-07-02T12:47:35.285Z",
      "publisher": "Patchstack",
      "title": "WordPress Automotive Listings plugin <= 18.6 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Themesuite"
        ],
        "products": [
          {
            "vendor": "Themesuite",
            "product": "Automotive Listings"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07195
      },
      "nvd": {
        "published": "2026-07-02T12:17:00.570",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27425",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/automotive/vulnerability/wordpress-automotive-listings-plugin-18-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27426",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:32.856Z",
      "date_published": "2026-07-02T11:14:58.150Z",
      "date_updated": "2026-07-02T14:46:13.248Z",
      "publisher": "Patchstack",
      "title": "WordPress Automotive Car Dealership Business theme <= 13.3.3 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Themesuite"
        ],
        "products": [
          {
            "vendor": "Themesuite",
            "product": "Automotive Car Dealership Business"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08394
      },
      "nvd": {
        "published": "2026-07-02T12:17:00.700",
        "lastModified": "2026-07-02T15:16:59.627",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27426",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/automotive/vulnerability/wordpress-automotive-car-dealership-business-theme-13-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:32.856Z",
      "date_published": "2026-07-02T11:14:59.114Z",
      "date_updated": "2026-07-02T14:55:50.891Z",
      "publisher": "Patchstack",
      "title": "WordPress TheFox theme <= 3.9.76 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "tranmautritam"
        ],
        "products": [
          {
            "vendor": "tranmautritam",
            "product": "TheFox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08389
      },
      "nvd": {
        "published": "2026-07-02T12:17:00.823",
        "lastModified": "2026-07-02T15:16:59.723",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27430",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/thefox/vulnerability/wordpress-thefox-theme-3-9-76-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 72,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:32.857Z",
      "date_published": "2026-07-02T11:14:59.997Z",
      "date_updated": "2026-07-02T19:43:15.377Z",
      "publisher": "Patchstack",
      "title": "WordPress Motors theme <= 5.6.80 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "StylemixThemes"
        ],
        "products": [
          {
            "vendor": "StylemixThemes",
            "product": "Motors"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15835
      },
      "nvd": {
        "published": "2026-07-02T12:17:00.950",
        "lastModified": "2026-07-02T20:17:02.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27433",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/motors/vulnerability/wordpress-motors-theme-5-6-80-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 67,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:32.857Z",
      "date_published": "2026-07-01T08:50:05.943Z",
      "date_updated": "2026-07-01T10:22:34.470Z",
      "publisher": "Patchstack",
      "title": "WordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "WofficeIO"
        ],
        "products": [
          {
            "vendor": "WofficeIO",
            "product": "Woffice"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06731
      },
      "nvd": {
        "published": "2026-07-01T10:16:28.120",
        "lastModified": "2026-07-01T13:56:17.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27435",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/woffice/vulnerability/wordpress-woffice-theme-5-4-31-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 182,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-19T09:52:39.681Z",
      "date_published": "2026-07-02T11:15:00.887Z",
      "date_updated": "2026-07-02T15:53:38.941Z",
      "publisher": "Patchstack",
      "title": "WordPress Five Star Business Profile and Schema plugin <= 2.3.19 - Arbitrary Code Execution vulnerability",
      "affected": {
        "vendors": [
          "Rustaurius"
        ],
        "products": [
          {
            "vendor": "Rustaurius",
            "product": "Five Star Business Profile and Schema"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.31287
      },
      "nvd": {
        "published": "2026-07-02T12:17:01.073",
        "lastModified": "2026-07-02T16:16:30.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27436",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "Version 2.3.19 lets persisted contact-card order values replace callable names and accepts arbitrary existing schema callback functions, while 2.3.20 keeps callback names in code and enforces an allowlist.",
        "basis": [
          "CNA",
          "CWE-94",
          "Patchstack disclosure",
          "WordPress.org plugin changelog",
          "WordPress official 2.3.19 and 2.3.20 source archives"
        ],
        "deepDive": true,
        "notes": "Inspected https://patchstack.com/database/wordpress/plugin/business-profile/vulnerability/wordpress-five-star-business-profile-and-schema-plugin-2-3-19-arbitrary-code-execution-vulnerability?_s_id=cve, https://wordpress.org/plugins/business-profile/, https://downloads.wordpress.org/plugin/business-profile.2.3.19.zip, and https://downloads.wordpress.org/plugin/business-profile.2.3.20.zip. The source diff shows persisted contact-card values replacing callback names and unrestricted existing schema functions in 2.3.19; 2.3.20 keeps callback values in a fixed registry and allowlists schema functions. No code was executed and no exploit reproduction was performed."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/business-profile/vulnerability/wordpress-five-star-business-profile-and-schema-plugin-2-3-19-arbitrary-code-execution-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 92,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27657",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-22T15:13:33.716Z",
      "date_published": "2026-07-03T20:19:35.873Z",
      "date_updated": "2026-07-07T16:59:05.668Z",
      "publisher": "Gitea",
      "title": "Gitea email settings allow changing another user's primary email address",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27168
      },
      "nvd": {
        "published": "2026-07-03T21:16:58.720",
        "lastModified": "2026-07-07T18:16:37.613",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27657",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The email settings action accepts a target user identifier without binding it to the authenticated account.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36586",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36607",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 89,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27660",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-22T15:13:33.679Z",
      "date_published": "2026-07-03T20:19:36.226Z",
      "date_updated": "2026-07-07T16:58:57.804Z",
      "publisher": "Gitea",
      "title": "Gitea draft releases use insufficient permission checks",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27168
      },
      "nvd": {
        "published": "2026-07-03T21:16:58.830",
        "lastModified": "2026-07-07T18:16:37.750",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27660",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A caller without repository write permission can read draft-release data and attachments.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36659",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36715",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-23T17:50:17.028Z",
      "date_published": "2026-07-14T00:17:55.003Z",
      "date_updated": "2026-07-14T12:46:07.535Z",
      "publisher": "sap",
      "title": "HTTP Request Smuggling in SAP Approuter",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP Approuter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00687,
        "percentile": 0.49136
      },
      "nvd": {
        "published": "2026-07-14T01:16:17.193",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27690",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SAP Approuter and its downstream peer interpret a crafted HTTP request boundary inconsistently, causing request-response desynchronization.",
        "basis": [
          "CNA record",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3720138",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:26:00.375Z",
      "date_published": "2026-07-03T20:19:36.576Z",
      "date_updated": "2026-07-07T16:58:51.949Z",
      "publisher": "Gitea",
      "title": "Gitea repository feeds bypass API token scope enforcement",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00365,
        "percentile": 0.29209
      },
      "nvd": {
        "published": "2026-07-03T21:16:58.937",
        "lastModified": "2026-07-07T18:16:37.887",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27761",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Repository feed endpoints accept an API token without enforcing the repository scope required to read private commit data.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-3pww-vcvm-3gmj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38147",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:50.291Z",
      "date_published": "2026-07-03T20:19:36.924Z",
      "date_updated": "2026-07-07T16:58:45.839Z",
      "publisher": "Gitea",
      "title": "Gitea Composer package source links use insufficient permission checks",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.43068,
        "percentile": 0.98593
      },
      "nvd": {
        "published": "2026-07-03T21:16:59.043",
        "lastModified": "2026-07-07T18:16:37.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27771",
        "family": "AUTHORITY_BINDING",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "Composer metadata attached a linked repository's source URL without checking whether the requesting user could access that repository.",
        "basis": [
          "CNA",
          "CWE-862",
          "Gitea advisory GHSA-8qw8-rq86-9pc2",
          "Gitea PR #37610 diff"
        ],
        "deepDive": true,
        "notes": "Primary-source deep dive: https://github.com/go-gitea/gitea/security/advisories/GHSA-8qw8-rq86-9pc2 and https://github.com/go-gitea/gitea/pull/37610/files ; the fix adds GetDoerRepoPermission and only emits Composer source metadata when HasAnyUnitAccessOrPublicAccess succeeds."
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-8qw8-rq86-9pc2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/37610",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.2/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 177,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27775",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:59.996Z",
      "date_published": "2026-07-03T20:19:37.275Z",
      "date_updated": "2026-07-06T15:25:15.796Z",
      "publisher": "Gitea",
      "title": "Gitea pre-receive hook permission cache allows full repository write access",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00567,
        "percentile": 0.43841
      },
      "nvd": {
        "published": "2026-07-03T21:16:59.157",
        "lastModified": "2026-07-06T18:17:26.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27775",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gitea caches one branch-specific write decision across multiple refs in the same pre-receive session, allowing the grant to remain valid for unrelated refs.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-649p-mmhf-85c7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38151",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27779",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:28.660Z",
      "date_published": "2026-07-03T20:19:37.622Z",
      "date_updated": "2026-07-06T15:21:00.874Z",
      "publisher": "Gitea",
      "title": "Gitea forwarded-proto handling allows public URL spoofing",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00431,
        "percentile": 0.35463
      },
      "nvd": {
        "published": "2026-07-03T21:16:59.257",
        "lastModified": "2026-07-06T18:17:26.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27779",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gitea accepts malformed or injected forwarded-proto values when deriving its public URL, allowing a proxy header to spoof canonical links.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36810",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36836",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 151,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27780",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:28.724Z",
      "date_published": "2026-07-03T20:19:37.968Z",
      "date_updated": "2026-07-06T15:20:06.013Z",
      "publisher": "Gitea",
      "title": "Gitea pre-receive hook can miss branch-protection checks after scanner errors",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00472,
        "percentile": 0.38343
      },
      "nvd": {
        "published": "2026-07-03T21:16:59.347",
        "lastModified": "2026-07-06T18:17:26.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27780",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The pre-receive hook continues after bufio.Scanner errors, allowing oversized input to skip branch-protection authorization checks instead of failing closed.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36963",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.0/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 173,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27783",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:50.353Z",
      "date_published": "2026-07-03T20:19:38.321Z",
      "date_updated": "2026-07-06T15:19:12.048Z",
      "publisher": "Gitea",
      "title": "Gitea issue-template APIs bypass repository unit authorization",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20606
      },
      "nvd": {
        "published": "2026-07-03T21:16:59.450",
        "lastModified": "2026-07-06T18:17:26.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27783",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Gitea Open Source Git Server path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-3fwp-p5rj-2pxf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/37769",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/37781",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.2/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-27790",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-01T23:45:09.724Z",
      "date_published": "2026-07-07T03:49:10.293Z",
      "date_updated": "2026-07-07T13:37:26.913Z",
      "publisher": "Gallagher",
      "title": "Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service.",
      "affected": {
        "vendors": [
          "Gallagher"
        ],
        "products": [
          {
            "vendor": "Gallagher",
            "product": "T-20 Readers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosures@gallagher.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13542
      },
      "nvd": {
        "published": "2026-07-07T05:16:50.500",
        "lastModified": "2026-07-07T14:16:29.667",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27790",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A malformed input raises an uncaught exception that restarts the reader process.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-27790",
          "host": "security.gallagher.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 536,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-27823",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-24T02:32:39.799Z",
      "date_published": "2026-07-20T15:24:51.684Z",
      "date_updated": "2026-07-21T15:47:35.591Z",
      "publisher": "GitHub_M",
      "title": "Remote Code Execution Vulnerability in EGroupware",
      "affected": {
        "vendors": [
          "EGroupware"
        ],
        "products": [
          {
            "vendor": "EGroupware",
            "product": "egroupware"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01028,
        "percentile": 0.60281
      },
      "nvd": {
        "published": "2026-07-20T16:16:57.680",
        "lastModified": "2026-07-22T20:52:35.747",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27823",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The egroupware operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/EGroupware/egroupware/security/advisories/GHSA-h9qx-v5xp-ph8p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-27844",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-01T23:45:09.678Z",
      "date_published": "2026-07-07T03:49:34.370Z",
      "date_updated": "2026-07-07T13:36:54.335Z",
      "publisher": "Gallagher",
      "title": "Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denia...",
      "affected": {
        "vendors": [
          "Gallagher"
        ],
        "products": [
          {
            "vendor": "Gallagher",
            "product": "Controller 7000 and 6000"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosures@gallagher.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13543
      },
      "nvd": {
        "published": "2026-07-07T05:16:50.617",
        "lastModified": "2026-07-07T14:16:29.760",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-27844",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted controller request reaches an exception path that is not caught and restarts the controller.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-27844",
          "host": "security.gallagher.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 597,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-28144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-25T12:14:24.000Z",
      "date_published": "2026-07-31T13:41:33.450Z",
      "date_updated": "2026-07-31T14:00:46.523Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Maps plugin <= 4.9.6 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Flipper Code"
        ],
        "products": [
          {
            "vendor": "Flipper Code",
            "product": "WP Maps"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.0735
      },
      "nvd": {
        "published": "2026-07-31T14:16:49.800",
        "lastModified": "2026-07-31T14:16:49.800",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28144",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says WP Maps exposes protected data to an unintended observer, while the field and output path are not public.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-google-map-plugin/vulnerability/wordpress-wp-maps-plugin-4-9-6-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-25T12:14:24.000Z",
      "date_published": "2026-07-31T13:19:39.683Z",
      "date_updated": "2026-07-31T14:01:07.485Z",
      "publisher": "Patchstack",
      "title": "WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "StylemixThemes"
        ],
        "products": [
          {
            "vendor": "StylemixThemes",
            "product": "MasterStudy LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00111,
        "percentile": 0.01522
      },
      "nvd": {
        "published": "2026-07-31T14:16:49.967",
        "lastModified": "2026-07-31T14:16:49.967",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28145",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The MasterStudy LMS record says unverified data can change user state but does not identify the state field or authenticity check.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/masterstudy-lms-learning-management-system/vulnerability/wordpress-masterstudy-lms-plugin-3-7-39-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-25T15:28:40.650Z",
      "date_published": "2026-07-20T15:26:13.036Z",
      "date_updated": "2026-07-20T17:30:46.933Z",
      "publisher": "GitHub_M",
      "title": "Wazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master node",
      "affected": {
        "vendors": [
          "wazuh"
        ],
        "products": [
          {
            "vendor": "wazuh",
            "product": "wazuh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00396,
        "percentile": 0.3236
      },
      "nvd": {
        "published": "2026-07-20T16:16:57.820",
        "lastModified": "2026-07-29T15:37:36.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28220",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Wazuh resolves attacker-selected wazuh or api callables during JSON deserialization and then applies caller-supplied RBAC permissions as global execution context.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-w2jj-pfq9-mh9p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1267,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28302",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:15:09.403Z",
      "date_published": "2026-07-21T15:31:30.297Z",
      "date_updated": "2026-07-24T03:55:36.930Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00558,
        "percentile": 0.43323
      },
      "nvd": {
        "published": "2026-07-21T16:17:07.903",
        "lastModified": "2026-07-24T17:31:48.033",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28302",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SolarWinds Serv-U authorizes a group administrator by group role but fails to bind the selected administrative object to that group, allowing operations with root-level consequence.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28302",
          "host": "www.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28304",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:15:09.403Z",
      "date_published": "2026-07-21T15:32:04.741Z",
      "date_updated": "2026-07-24T03:55:37.779Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00546,
        "percentile": 0.42738
      },
      "nvd": {
        "published": "2026-07-21T16:17:08.050",
        "lastModified": "2026-07-24T17:33:31.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28304",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "SolarWinds confirms remote root code execution in Serv-U but publishes no input, endpoint, interpreter boundary, memory error, or authorization decision that enables it.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm"
        ],
        "deepDive": true,
        "notes": "SolarWinds' Serv-U 2026.3 release notes confirm remote code execution as root and the fixed release, but disclose no technical finding or causal path."
      },
      "references": [
        {
          "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28304",
          "host": "www.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28305",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:15:09.403Z",
      "date_published": "2026-07-21T15:33:55.983Z",
      "date_updated": "2026-07-24T03:55:38.634Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00546,
        "percentile": 0.42738
      },
      "nvd": {
        "published": "2026-07-21T16:17:08.180",
        "lastModified": "2026-07-24T17:41:20.133",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28305",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Serv-U resolves a caller-controlled object identifier without binding the selected object to the caller's authorized scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28305",
          "host": "www.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 281,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28306",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:15:09.403Z",
      "date_published": "2026-07-21T15:34:09.400Z",
      "date_updated": "2026-07-24T03:55:39.494Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Privilege Escalation Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00344,
        "percentile": 0.2702
      },
      "nvd": {
        "published": "2026-07-21T16:17:08.317",
        "lastModified": "2026-07-24T17:59:24.390",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28306",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Serv-U lets a domain administrator obtain the system-administrator role, but the vendor does not publish the failing role check.",
        "basis": [
          "CNA",
          "CWE-284",
          "SolarWinds release notes"
        ],
        "deepDive": true,
        "notes": "Inspected https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm; the vendor confirms the role escalation but does not publish the failing check, and no reproduction was performed."
      },
      "references": [
        {
          "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28306",
          "host": "www.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28307",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:28:17.157Z",
      "date_published": "2026-07-21T15:34:26.779Z",
      "date_updated": "2026-07-24T03:55:40.379Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Privilege Escalation Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00344,
        "percentile": 0.2702
      },
      "nvd": {
        "published": "2026-07-21T16:17:08.443",
        "lastModified": "2026-07-24T17:58:27.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28307",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Serv-U permits a domain user group to be elevated into an administrator group without enforcing the intended group-management privilege, but the endpoint is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "SolarWinds release notes"
        ],
        "deepDive": true,
        "notes": "Inspected https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm; the vendor confirms domain-user-group to administrator-group escalation but does not disclose the endpoint, authorization predicate, or patch diff."
      },
      "references": [
        {
          "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28307",
          "host": "www.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28308",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:28:17.157Z",
      "date_published": "2026-07-21T15:34:40.127Z",
      "date_updated": "2026-07-24T03:55:41.194Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00546,
        "percentile": 0.42739
      },
      "nvd": {
        "published": "2026-07-21T16:17:08.577",
        "lastModified": "2026-07-24T18:45:04.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28308",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A domain administrator can select a Serv-U object by identifier without the required per-object authorization, and the resulting operation can reach code execution.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28308",
          "host": "www.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:28:17.157Z",
      "date_published": "2026-07-21T15:34:52.384Z",
      "date_updated": "2026-07-24T03:55:41.996Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Broken Access Control Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27052
      },
      "nvd": {
        "published": "2026-07-21T16:17:08.743",
        "lastModified": "2026-07-24T18:44:45.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28309",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Serv-U permits a domain administrator to create a system-administrator account without requiring system-level authority.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28309",
          "host": "https",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28310",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:28:17.157Z",
      "date_published": "2026-07-21T15:35:07.899Z",
      "date_updated": "2026-07-24T03:55:42.875Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Privilege Escalation Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27051
      },
      "nvd": {
        "published": "2026-07-21T16:17:08.877",
        "lastModified": "2026-07-24T18:44:22.560",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28310",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A domain administrator can change its user type to system administrator, but SolarWinds does not disclose the missing role-transition check.",
        "basis": [
          "CNA",
          "CWE-862",
          "SolarWinds Serv-U 2026.3 release notes"
        ],
        "deepDive": true,
        "notes": "Inspected https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm; SolarWinds confirms domain-administrator to system-administrator escalation and the fixed release but does not publish the failed role-transition check."
      },
      "references": [
        {
          "url": "https://https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28310",
          "host": "https",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28312",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:28:17.157Z",
      "date_published": "2026-07-21T15:37:45.518Z",
      "date_updated": "2026-07-24T03:55:43.714Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Privilege Escalation Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00401,
        "percentile": 0.32865
      },
      "nvd": {
        "published": "2026-07-21T16:17:09.000",
        "lastModified": "2026-07-24T18:44:00.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28312",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Serv-U lets a group's authority become system-administrator authority, but SolarWinds does not publish the permission-binding error that permits the transition.",
        "basis": [
          "CNA",
          "CWE-285",
          "SolarWinds Release Notes"
        ],
        "deepDive": true,
        "notes": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm - the official release notes repeat the group-to-system-administrator impact but do not expose the permission-binding check or a source patch."
      },
      "references": [
        {
          "url": "https://https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28312",
          "host": "https",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28313",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:28:17.158Z",
      "date_published": "2026-07-21T15:38:22.855Z",
      "date_updated": "2026-07-24T03:55:44.594Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27051
      },
      "nvd": {
        "published": "2026-07-21T16:17:09.147",
        "lastModified": "2026-07-24T18:43:36.110",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28313",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Serv-U fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28313",
          "host": "https",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28314",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:28:17.158Z",
      "date_published": "2026-07-21T15:38:39.779Z",
      "date_updated": "2026-07-24T03:55:45.575Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00445,
        "percentile": 0.36591
      },
      "nvd": {
        "published": "2026-07-21T16:17:09.283",
        "lastModified": "2026-07-24T18:42:10.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28314",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Serv-U accepts an authenticated user's object reference without the ownership check needed to prevent account takeover, while the object and endpoint are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639",
          "Vendor release note"
        ],
        "deepDive": true,
        "notes": "Inspected the official Serv-U 2026.3 release notes at https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm; they confirm authenticated IDOR to account takeover and the 2026.3 repair but do not name the object or endpoint."
      },
      "references": [
        {
          "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28314",
          "host": "www.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28315",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:28:17.158Z",
      "date_published": "2026-07-21T15:39:04.982Z",
      "date_updated": "2026-07-21T17:44:05.421Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20559
      },
      "nvd": {
        "published": "2026-07-21T16:17:09.417",
        "lastModified": "2026-07-24T18:41:35.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28315",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Serv-U stores attacker-controlled content and later renders it without sufficient output escaping, allowing script execution in a visitor's browser.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28315",
          "host": "www.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28316",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:28:17.158Z",
      "date_published": "2026-07-21T15:39:17.464Z",
      "date_updated": "2026-07-24T03:55:46.373Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.0128,
        "percentile": 0.67186
      },
      "nvd": {
        "published": "2026-07-21T16:17:09.943",
        "lastModified": "2026-07-24T18:40:25.263",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28316",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Serv-U authorizes an operation by an attacker-controlled object reference without verifying that the domain administrator may act on that object.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28316",
          "host": "www.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28317",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:46:41.520Z",
      "date_published": "2026-07-21T15:39:30.473Z",
      "date_updated": "2026-07-24T03:55:47.253Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00344,
        "percentile": 0.2702
      },
      "nvd": {
        "published": "2026-07-21T16:17:10.157",
        "lastModified": "2026-07-24T18:38:44.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28317",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Serv-U authorizes a domain administrator operation using a caller-controlled object identifier without binding it to the permitted object.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28317",
          "host": "www.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28321",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:46:41.520Z",
      "date_published": "2026-07-21T15:39:46.561Z",
      "date_updated": "2026-07-24T03:55:48.019Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Serv-U Broken Access Control Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Serv-U"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4.3999999999999995,
      "epss": {
        "score": 0.00409,
        "percentile": 0.33651
      },
      "nvd": {
        "published": "2026-07-21T16:17:10.293",
        "lastModified": "2026-07-24T18:35:46.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28321",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Serv-U fails an access-control decision and permits a domain administrator to read or write arbitrary files, while the public advisory does not identify the missing object or path check.",
        "basis": [
          "CNA",
          "CWE-284",
          "SolarWinds advisory",
          "Serv-U 2026.3 release notes"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28321 and https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm; both confirm broken access control and the domain-administrator prerequisite without publishing the causal check."
      },
      "references": [
        {
          "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28321",
          "host": "www.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory",
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 283,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28323",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-26T14:46:41.520Z",
      "date_published": "2026-07-30T15:55:29.626Z",
      "date_updated": "2026-07-31T03:56:15.917Z",
      "publisher": "SolarWinds",
      "title": "SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability",
      "affected": {
        "vendors": [
          "SolarWinds"
        ],
        "products": [
          {
            "vendor": "SolarWinds",
            "product": "Web Help Desk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@solarwinds.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00638,
        "percentile": 0.47084
      },
      "nvd": {
        "published": "2026-07-30T16:17:10.710",
        "lastModified": "2026-07-31T04:17:19.927",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28323",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Web Help Desk accepts an unauthenticated SAML login when SAML 2.0 is enabled, while SolarWinds does not publish the assertion-validation step that fails.",
        "basis": [
          "CNA",
          "CWE-287",
          "SolarWinds CVE-2026-28323 advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28323; it confirms the SAML-enabled condition and fixed release 2026.2.1 without disclosing the assertion-validation flaw."
      },
      "references": [
        {
          "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28323",
          "host": "www.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-2-1_release_notes.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://documentation.solarwinds.com/en/success_center/whd/content/helpdesksecureconfiguration.htm",
          "host": "documentation.solarwinds.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_secure-configuration-guide"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 159,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-02-27T07:16:12.218Z",
      "date_published": "2026-07-07T21:08:04.579Z",
      "date_updated": "2026-07-29T14:00:16.160Z",
      "publisher": "GRAFANA",
      "title": "Cross-Organization Public Dashboard Deletion via Missing Org Isolation",
      "affected": {
        "vendors": [
          "Grafana"
        ],
        "products": [
          {
            "vendor": "Grafana",
            "product": "Grafana Enterprise"
          },
          {
            "vendor": "Grafana",
            "product": "Grafana OSS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@grafana.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0.3999999999999999,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03474
      },
      "nvd": {
        "published": "2026-07-07T22:16:50.607",
        "lastModified": "2026-07-10T16:05:56.213",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28378",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://grafana.com/security/security-advisories/cve-2026-28378",
          "host": "grafana.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-28564",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-02T02:27:12.754Z",
      "date_published": "2026-07-10T07:08:12.481Z",
      "date_updated": "2026-07-10T15:02:54.356Z",
      "publisher": "apache",
      "title": "Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache IoTDB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36313
      },
      "nvd": {
        "published": "2026-07-10T08:16:21.897",
        "lastModified": "2026-07-10T16:16:28.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28564",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The REST authentication cache continues accepting captured Basic credentials after their session should have expired.",
        "basis": [
          "CNA",
          "CWE-294",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/l38wpy7flvvfwv4rkps87l5z8gprnfy0",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/10/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 299,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T17:14:43.847Z",
      "date_published": "2026-07-23T22:04:49.903Z",
      "date_updated": "2026-07-24T12:38:10.521Z",
      "publisher": "icscert",
      "title": "Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs",
      "affected": {
        "vendors": [
          "Pronetiqs"
        ],
        "products": [
          {
            "vendor": "Pronetiqs",
            "product": "Panduit Intravue"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17491
      },
      "nvd": {
        "published": "2026-07-23T23:16:48.590",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28698",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "IntraVUE exposes the underlying host or share filesystem to an unauthenticated network caller, while the advisory does not publish the responsible endpoint or path check.",
        "basis": [
          "CNA",
          "CWE-497",
          "CISA CSAF ICSA-26-204-04"
        ],
        "deepDive": true,
        "notes": "Inspected https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-204-04.json; CISA adds the affected range, upgrade to 3.2.1a16 or later and network mitigations, but does not disclose the endpoint or filesystem selection logic."
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28699",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:50.232Z",
      "date_published": "2026-07-03T20:19:38.663Z",
      "date_updated": "2026-07-06T15:18:39.782Z",
      "publisher": "Gitea",
      "title": "Gitea Basic Auth bypasses OAuth2 access token scopes",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00567,
        "percentile": 0.4382
      },
      "nvd": {
        "published": "2026-07-03T21:16:59.567",
        "lastModified": "2026-07-06T18:17:26.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28699",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gitea's HTTP Basic authentication path fails to carry and enforce the OAuth2 access-token scopes applied by the token path.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-9r5x-wg6m-x2rc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/37503",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.2/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 135,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28705",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:28.526Z",
      "date_published": "2026-07-03T20:19:39.011Z",
      "date_updated": "2026-07-07T16:58:39.576Z",
      "publisher": "Gitea",
      "title": "Gitea repository dumps write release assets using unsafe path names",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29544
      },
      "nvd": {
        "published": "2026-07-03T21:16:59.683",
        "lastModified": "2026-07-07T18:16:38.090",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28705",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Gitea Open Source Git Server accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/pull/36799",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/36839",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.25.5/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:50.217Z",
      "date_published": "2026-07-03T20:19:39.358Z",
      "date_updated": "2026-07-07T16:58:33.235Z",
      "publisher": "Gitea",
      "title": "Gitea 3D file viewer allows stored XSS through glTF extensionsRequired",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26225
      },
      "nvd": {
        "published": "2026-07-03T21:16:59.787",
        "lastModified": "2026-07-07T18:16:38.223",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28737",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The 3D viewer renders an attacker-controlled glTF extensionsRequired value as executable browser content.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-9cpj-qc93-vw8v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/37233",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.0/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 157,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28740",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:59.982Z",
      "date_published": "2026-07-03T20:19:39.687Z",
      "date_updated": "2026-07-07T16:58:26.934Z",
      "publisher": "Gitea",
      "title": "Gitea LFS object reuse bypasses Code-unit authorization",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18633
      },
      "nvd": {
        "published": "2026-07-03T21:16:59.890",
        "lastModified": "2026-07-07T18:16:38.327",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28740",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LFS source-object access is authorized only against repository access and is not bound to the requested Code unit.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-2m9v-5q2g-58vq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38050",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 168,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28744",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T03:25:50.255Z",
      "date_published": "2026-07-03T20:19:40.031Z",
      "date_updated": "2026-07-06T15:17:58.355Z",
      "publisher": "Gitea",
      "title": "Gitea Git smart HTTP bypasses repository token scopes for bearer tokens",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26896
      },
      "nvd": {
        "published": "2026-07-03T21:17:00.003",
        "lastModified": "2026-07-06T18:17:26.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28744",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Git smart HTTP accepts a bearer token without enforcing that token's repository scopes.",
        "basis": [
          "CNA record",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-cc8w-r4qh-3v65",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/37583",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.2/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 145,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28811",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T15:00:35.684Z",
      "date_published": "2026-07-30T15:51:27.131Z",
      "date_updated": "2026-07-31T17:54:14.250Z",
      "publisher": "apache",
      "title": "Apache JSPWiki: Error Handling - Reveals Error Details",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache JSPWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1295",
          "name": "Debug Messages Revealing Unnecessary Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23345
      },
      "nvd": {
        "published": "2026-07-30T16:17:10.850",
        "lastModified": "2026-07-31T18:17:13.810",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28811",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache JSPWiki emits debugging details that reveal unnecessary internal information.",
        "basis": [
          "CNA",
          "CWE-1295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/2dm414zzjo3pvhjz6mvqy3b5yhvnkcg5",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2026-28811",
          "host": "jspwiki-wiki.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/14",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 156,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T15:01:12.543Z",
      "date_published": "2026-07-30T15:52:34.172Z",
      "date_updated": "2026-07-31T15:28:08.984Z",
      "publisher": "apache",
      "title": "Apache JSPWiki: UserManager does not sanity-check user database at startup",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache JSPWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23606
      },
      "nvd": {
        "published": "2026-07-30T16:17:10.967",
        "lastModified": "2026-07-31T16:17:06.240",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28812",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "UserManager performs an impersonation transition without the checks needed to bind the target identity to an authorized caller.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/n3m666d6t6871dldvz3ct49ooqkbgw2p",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/15",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 212,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28813",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T15:01:42.672Z",
      "date_published": "2026-07-30T15:54:19.667Z",
      "date_updated": "2026-07-31T11:34:33.218Z",
      "publisher": "apache",
      "title": "Apache JSPWiki: JSPWiki vulnerable to JSON hijacking",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache JSPWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04515
      },
      "nvd": {
        "published": "2026-07-30T16:17:11.070",
        "lastModified": "2026-07-31T12:16:48.910",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28813",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "JSPWiki returns JSON in a form that a cross-site page can consume without a request-to-session CSRF binding.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/56440mymwkxt1hf3j8hjpo41yco7gotv",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/16",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28814",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T15:02:10.764Z",
      "date_published": "2026-07-30T15:55:28.034Z",
      "date_updated": "2026-07-31T17:55:59.734Z",
      "publisher": "apache",
      "title": "Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache JSPWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25343
      },
      "nvd": {
        "published": "2026-07-30T16:17:11.183",
        "lastModified": "2026-07-31T18:17:13.973",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-28814",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable security-sensitive operation is exposed without the authentication step required before invoking it.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/8vv0311bvrrqxsyn913pcwf7pctyk52w",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/17",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 247,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-28849",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.970Z",
      "date_published": "2026-07-27T20:14:24.920Z",
      "date_updated": "2026-07-28T15:51:08.672Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.0129
      },
      "nvd": {
        "published": "2026-07-27T21:16:48.873",
        "lastModified": "2026-07-29T15:47:07.143",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28849",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Apple record says a crafted ZIP archive bypasses Gatekeeper checks but does not disclose the archive property, validation rule, or state transition.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-290",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-28896",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.983Z",
      "date_published": "2026-07-27T20:13:40.347Z",
      "date_updated": "2026-07-28T15:57:19.941Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02724
      },
      "nvd": {
        "published": "2026-07-27T21:16:48.980",
        "lastModified": "2026-07-29T15:47:13.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28896",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A macOS path mishandles memory and can terminate the system or expose kernel memory, while Apple does not publish the allocation, bounds, or lifetime operation.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-28900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.983Z",
      "date_published": "2026-07-27T20:14:34.090Z",
      "date_updated": "2026-07-28T15:20:26.865Z",
      "publisher": "apple",
      "title": "A file quarantine bypass was addressed with additional checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.0129
      },
      "nvd": {
        "published": "2026-07-27T21:16:49.080",
        "lastModified": "2026-07-29T15:47:18.417",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28900",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record reports a Gatekeeper quarantine bypass for ZIP content but does not reveal the metadata or validation rule that fails.",
        "basis": [
          "CNA",
          "CWE-290",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-28911",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.984Z",
      "date_published": "2026-07-27T20:14:11.645Z",
      "date_updated": "2026-07-28T15:52:28.469Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21228
      },
      "nvd": {
        "published": "2026-07-27T21:16:49.177",
        "lastModified": "2026-07-29T15:48:36.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28911",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A malicious application can corrupt memory in the Metal system-process path, but Apple does not disclose the invalid access or lifetime transition.",
        "basis": [
          "CNA",
          "CWE-119",
          "Apple macOS 26.6 and 14.8.8 security notes"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.apple.com/en-us/128067 and https://support.apple.com/en-us/128072; Apple confirms the Metal component, affected releases, system-process memory corruption, and improved memory handling, but publishes no invalid access, allocation, or lifetime transition."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-28912",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.984Z",
      "date_published": "2026-07-27T20:12:47.751Z",
      "date_updated": "2026-07-29T03:55:28.358Z",
      "publisher": "apple",
      "title": "A logic issue was addressed with improved restrictions.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03745
      },
      "nvd": {
        "published": "2026-07-27T21:16:49.273",
        "lastModified": "2026-07-29T15:45:01.307",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28912",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A macOS restriction permits a local user to elevate privileges, while Apple does not identify the protected operation or missing authorization state.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-28926",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.987Z",
      "date_published": "2026-07-27T20:13:46.302Z",
      "date_updated": "2026-07-29T03:55:32.295Z",
      "publisher": "apple",
      "title": "A race condition was addressed with improved state handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00088,
        "percentile": 0.00469
      },
      "nvd": {
        "published": "2026-07-27T21:16:49.550",
        "lastModified": "2026-07-29T16:42:48.107",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28926",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple reports a privilege-changing race in macOS but does not identify the two operations or shared state.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 168,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-28928",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.987Z",
      "date_published": "2026-07-27T20:12:57.012Z",
      "date_updated": "2026-07-28T14:34:15.156Z",
      "publisher": "apple",
      "title": "A use after free issue was addressed with improved memory management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34478
      },
      "nvd": {
        "published": "2026-07-27T21:16:49.650",
        "lastModified": "2026-07-28T19:31:06.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28928",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path continues using an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-28931",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.987Z",
      "date_published": "2026-07-27T20:14:05.946Z",
      "date_updated": "2026-07-29T03:55:42.970Z",
      "publisher": "apple",
      "title": "A buffer overflow was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20401
      },
      "nvd": {
        "published": "2026-07-27T21:16:49.750",
        "lastModified": "2026-07-29T05:16:43.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28931",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "iOS and iPadOS can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-28932",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.988Z",
      "date_published": "2026-07-27T20:13:06.008Z",
      "date_updated": "2026-07-28T17:55:38.021Z",
      "publisher": "apple",
      "title": "A logic issue existed resulting in memory corruption.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02818
      },
      "nvd": {
        "published": "2026-07-27T21:16:49.850",
        "lastModified": "2026-07-29T17:01:42.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28932",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple attributes the memory corruption to state management but does not disclose the object, invalid transition, or concurrent operation.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-28945",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.989Z",
      "date_published": "2026-07-27T20:12:51.856Z",
      "date_updated": "2026-07-28T14:40:14.723Z",
      "publisher": "apple",
      "title": "A permissions issue was addressed with additional sandbox restrictions.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02567
      },
      "nvd": {
        "published": "2026-07-27T21:16:50.120",
        "lastModified": "2026-07-28T17:54:14.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28945",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "macOS permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-28973",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.992Z",
      "date_published": "2026-07-27T20:13:08.442Z",
      "date_updated": "2026-07-28T14:32:17.475Z",
      "publisher": "apple",
      "title": "An integer overflow was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03257
      },
      "nvd": {
        "published": "2026-07-27T21:16:50.380",
        "lastModified": "2026-07-28T19:31:24.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28973",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unchecked integer arithmetic can wrap while processing app input and invalidate a sandbox-enforcing memory boundary.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-28981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.993Z",
      "date_published": "2026-07-27T20:12:24.059Z",
      "date_updated": "2026-07-29T03:55:27.560Z",
      "publisher": "apple",
      "title": "A buffer overflow was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.0504
      },
      "nvd": {
        "published": "2026-07-27T21:16:50.650",
        "lastModified": "2026-07-29T05:16:44.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28981",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An image parser copies or indexes crafted image data beyond a buffer boundary before the improved bounds check.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-28982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:36:03.993Z",
      "date_published": "2026-07-27T20:14:28.251Z",
      "date_updated": "2026-07-28T15:43:55.453Z",
      "publisher": "apple",
      "title": "A race condition was addressed with improved locking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24598
      },
      "nvd": {
        "published": "2026-07-27T21:16:50.743",
        "lastModified": "2026-07-28T19:53:28.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-28982",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent remote operations access shared kernel state without sufficient locking, allowing termination or memory corruption during the race window.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-29007",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:42:01.012Z",
      "date_published": "2026-07-08T16:11:25.888Z",
      "date_updated": "2026-07-14T18:39:49.120Z",
      "publisher": "VulnCheck",
      "title": "U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c",
      "affected": {
        "vendors": [
          "u-boot"
        ],
        "products": [
          {
            "vendor": "u-boot",
            "product": "u-boot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00548,
        "percentile": 0.42838
      },
      "nvd": {
        "published": "2026-07-08T17:17:20.907",
        "lastModified": "2026-07-22T18:31:40.713",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-29007",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The TCP option parser trusts a header offset larger than the segment and reads beyond the packet boundary.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/",
          "host": "y637f9qq2x.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://lists.denx.de/pipermail/u-boot/2026-May/617853.html",
          "host": "lists.denx.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory",
            "issue-tracking"
          ]
        },
        {
          "url": "https://u-boot.org/",
          "host": "u-boot.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/u-boot-rc3-out-of-bounds-read-in-tcp-rx-state-machine-via-tcp-c",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 617,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-29008",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:42:01.012Z",
      "date_published": "2026-07-08T16:14:41.613Z",
      "date_updated": "2026-07-14T18:39:49.802Z",
      "publisher": "VulnCheck",
      "title": "U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()",
      "affected": {
        "vendors": [
          "u-boot"
        ],
        "products": [
          {
            "vendor": "u-boot",
            "product": "u-boot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00552,
        "percentile": 0.4303
      },
      "nvd": {
        "published": "2026-07-08T17:17:21.047",
        "lastModified": "2026-07-22T18:32:12.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-29008",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A negative TCP payload length is converted to a large unsigned copy length and passed to memcpy.",
        "basis": [
          "CNA",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/",
          "host": "y637f9qq2x.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://lists.denx.de/pipermail/u-boot/2026-May/617853.html",
          "host": "lists.denx.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory",
            "issue-tracking"
          ]
        },
        {
          "url": "https://u-boot.org/",
          "host": "u-boot.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/u-boot-rc3-integer-underflow-dos-via-tcp-rx-state-machine",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 657,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-29009",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-03T16:42:01.012Z",
      "date_published": "2026-07-08T16:16:04.460Z",
      "date_updated": "2026-07-24T17:32:41.013Z",
      "publisher": "VulnCheck",
      "title": "U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK",
      "affected": {
        "vendors": [
          "u-boot"
        ],
        "products": [
          {
            "vendor": "u-boot",
            "product": "u-boot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.6000000000000014,
      "epss": {
        "score": 0.00557,
        "percentile": 0.43305
      },
      "nvd": {
        "published": "2026-07-08T17:17:21.173",
        "lastModified": "2026-07-24T18:16:52.967",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-29009",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "nfs_readlink_reply appends multiple relative symlink targets to a fixed 2048-byte buffer without validating their cumulative length.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/",
          "host": "y637f9qq2x.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://lists.denx.de/pipermail/u-boot/2026-May/617853.html",
          "host": "lists.denx.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory",
            "issue-tracking"
          ]
        },
        {
          "url": "https://git.u-boot-project.org/u-boot/u-boot/-/releases/v2026.07-rc2",
          "host": "git.u-boot-project.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://git.u-boot-project.org/u-boot/u-boot/-/commit/d6694018eaddefac6aae974f9cec72fd6e58f1bc",
          "host": "git.u-boot-project.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://u-boot.org/",
          "host": "u-boot.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/u-boot-rc3-buffer-overflow-in-nfs-readlink-reply-via-nfs-readlink",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 680,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-29519",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-04T15:39:26.872Z",
      "date_published": "2026-07-10T14:09:24.237Z",
      "date_updated": "2026-07-14T18:39:56.709Z",
      "publisher": "VulnCheck",
      "title": "Lucee CFML Server Reflected XSS via URL Path Parsing",
      "affected": {
        "vendors": [
          "lucee"
        ],
        "products": [
          {
            "vendor": "lucee",
            "product": "Lucee"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 1.9999999999999991,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31378
      },
      "nvd": {
        "published": "2026-07-10T15:16:39.007",
        "lastModified": "2026-07-14T19:16:56.453",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-29519",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Lucee places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/L4V4D0/CVE-2026-29519-Lucee-Reflected-XSS",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/lucee-cfml-server-reflected-xss-via-url-path-parsing",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-30618",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-04T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-16T13:24:00.406Z",
      "publisher": "mitre",
      "title": "xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO serv...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01671,
        "percentile": 0.74515
      },
      "nvd": {
        "published": "2026-07-15T22:16:46.210",
        "lastModified": "2026-07-16T14:16:49.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-30618",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The publicly exposed MCP management interface lets an unauthenticated caller register an STDIO server whose attacker-controlled command is then executed.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/",
          "host": "www.ox.security",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/xszyou/Fay",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-30623",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-04T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-16T13:19:39.318Z",
      "publisher": "mitre",
      "title": "LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM execu...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.05952,
        "percentile": 0.92544
      },
      "nvd": {
        "published": "2026-07-15T22:16:46.317",
        "lastModified": "2026-07-16T14:16:50.013",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-30623",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "LiteLLM executes caller-supplied MCP command and argument fields as host operating-system commands.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/BerriAI/litellm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/",
          "host": "www.ox.security",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://docs.litellm.ai/blog/mcp-stdio-command-injection-april-2026",
          "host": "docs.litellm.ai",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-30631",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-04T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T17:38:54.733Z",
      "publisher": "mitre",
      "title": "An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00497,
        "percentile": 0.39922
      },
      "nvd": {
        "published": "2026-07-21T21:16:49.370",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-30631",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "computer_write_file embeds the attacker-controlled destination path inside shell commands passed to exec, so shell substitutions in the path are interpreted as commands.",
        "basis": [
          "CNA",
          "CWE-78",
          "bytebot source at commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313"
        ],
        "deepDive": true,
        "notes": "Inspected commit-pinned source at https://github.com/bytebot-ai/bytebot/blob/3d37894ce07ef8d8b40adc7fd309ad96c2a71313/packages/bytebotd/src/computer-use/computer-use.service.ts; writeFile interpolates targetPath into sudo cp, chown, and chmod command strings, and no runtime reproduction was performed."
      },
      "references": [
        {
          "url": "https://gist.github.com/spdc-elm/1a56d53591a929446a54e50e64de9fc0",
          "host": "gist.github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/bytebot-ai/bytebot/commit/3d37894ce07ef8d8b40adc7fd309ad96c2a71313",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-30632",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-04T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T18:00:46.494Z",
      "publisher": "mitre",
      "title": "Directory traversal vulnerability in knowns-dev/knowns 0.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00659,
        "percentile": 0.48011
      },
      "nvd": {
        "published": "2026-07-21T20:17:00.470",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-30632",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/spdc-elm/b059904a9e351afc1f5d38351f8b9ea5",
          "host": "gist.github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/knowns-dev/knowns/commit/62fb0daaa0b9e66fce1d42c02b5bb519367cf669",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-30633",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-04T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T18:07:33.457Z",
      "publisher": "mitre",
      "title": "Directory traversal vulnerability in knowns-dev/knowns 0.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00659,
        "percentile": 0.48011
      },
      "nvd": {
        "published": "2026-07-21T21:16:49.493",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-30633",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/knowns-dev/knowns/commit/62fb0daaa0b9e66fce1d42c02b5bb519367cf669",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/spdc-elm/5e19d66402307bdfc8b25ab27469172f",
          "host": "gist.github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-31267",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-09T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T15:31:02.333Z",
      "publisher": "mitre",
      "title": "Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. A stack buffer overflow vulnerability in the administrative web interface allows an authenticated attacker with admin...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10443
      },
      "nvd": {
        "published": "2026-07-09T21:16:54.667",
        "lastModified": "2026-07-10T18:50:20.507",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-31267",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The router's administrative web interface copies request data into a fixed stack buffer without an effective length check.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://barry-dev.xyz/about",
          "host": "barry-dev.xyz",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/BarrYPL/13dcd071673866cbbfaaa05085b98cf3",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-31309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-09T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-16T12:21:40.263Z",
      "publisher": "mitre",
      "title": "Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0044,
        "percentile": 0.36189
      },
      "nvd": {
        "published": "2026-07-08T22:17:13.840",
        "lastModified": "2026-07-16T13:16:30.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-31309",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mysteriumnetwork/node/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/mysteriumnetwork/node/commit/bc099fcaff59fee9c8a8f8e07ffff5b3c5df2bb9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/sch8ill/CVE-2026-31309",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-31981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-10T16:14:03.265Z",
      "date_published": "2026-07-09T07:22:21.271Z",
      "date_updated": "2026-07-09T12:43:26.857Z",
      "publisher": "Nozomi",
      "title": "HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0",
      "affected": {
        "vendors": [
          "Nozomi Networks"
        ],
        "products": [
          {
            "vendor": "Nozomi Networks",
            "product": "Guardian"
          },
          {
            "vendor": "Nozomi Networks",
            "product": "CMC"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04003
      },
      "nvd": {
        "published": "2026-07-09T08:16:47.483",
        "lastModified": "2026-07-10T13:15:29.023",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-31981",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A shared validator permits administrator-supplied HTML tags in configuration data that the Diagram and Graph views render as markup.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.nozominetworks.com/NN-2026:8-01",
          "host": "security.nozominetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 624,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-31982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-10T16:14:03.266Z",
      "date_published": "2026-07-09T07:22:35.960Z",
      "date_updated": "2026-07-09T12:42:40.823Z",
      "publisher": "Nozomi",
      "title": "Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0",
      "affected": {
        "vendors": [
          "Nozomi Networks"
        ],
        "products": [
          {
            "vendor": "Nozomi Networks",
            "product": "Guardian"
          },
          {
            "vendor": "Nozomi Networks",
            "product": "CMC"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.7999999999999998,
      "epss": {
        "score": 0.00167,
        "percentile": 0.06306
      },
      "nvd": {
        "published": "2026-07-09T08:16:47.650",
        "lastModified": "2026-07-10T13:14:14.407",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-31982",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SAML sign-in endpoint accepts an attacker-controlled redirect target and caches it for later users without constraining the destination to an approved origin.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.nozominetworks.com/NN-2026:9-01",
          "host": "security.nozominetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 454,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-31983",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-10T16:14:03.266Z",
      "date_published": "2026-07-09T07:22:44.704Z",
      "date_updated": "2026-07-09T12:41:20.941Z",
      "publisher": "Nozomi",
      "title": "Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0",
      "affected": {
        "vendors": [
          "Nozomi Networks"
        ],
        "products": [
          {
            "vendor": "Nozomi Networks",
            "product": "Guardian"
          },
          {
            "vendor": "Nozomi Networks",
            "product": "CMC"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14461
      },
      "nvd": {
        "published": "2026-07-09T08:16:47.800",
        "lastModified": "2026-07-10T13:13:26.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-31983",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable security-sensitive operation is exposed without the authentication step required before invoking it.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.nozominetworks.com/NN-2026:10-01",
          "host": "security.nozominetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-31984",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-10T16:14:03.266Z",
      "date_published": "2026-07-09T07:22:53.172Z",
      "date_updated": "2026-07-09T12:40:47.448Z",
      "publisher": "Nozomi",
      "title": "DoS through oversized audit log entries in Guardian/CMC before 26.2.0",
      "affected": {
        "vendors": [
          "Nozomi Networks"
        ],
        "products": [
          {
            "vendor": "Nozomi Networks",
            "product": "Guardian"
          },
          {
            "vendor": "Nozomi Networks",
            "product": "CMC"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00274,
        "percentile": 0.1961
      },
      "nvd": {
        "published": "2026-07-09T08:16:47.940",
        "lastModified": "2026-07-10T13:12:51.087",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-31984",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Audit logging accepts an entry of unbounded size and writes it to disk, allowing repeated unauthenticated requests to exhaust storage.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.nozominetworks.com/NN-2026:11-01",
          "host": "security.nozominetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 392,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-31985",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-10T16:14:03.266Z",
      "date_published": "2026-07-09T07:23:06.045Z",
      "date_updated": "2026-07-09T12:30:59.025Z",
      "publisher": "Nozomi",
      "title": "Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2.0",
      "affected": {
        "vendors": [
          "Nozomi Networks"
        ],
        "products": [
          {
            "vendor": "Nozomi Networks",
            "product": "Remote Collector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-671",
          "name": "Lack of Administrator Control over Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02272
      },
      "nvd": {
        "published": "2026-07-09T08:16:48.083",
        "lastModified": "2026-07-09T16:39:17.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-31985",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Remote Collector configuration generated by n2os-tui disables TLS certificate verification for the upstream Guardian or CMC and offers no option to restore verification.",
        "basis": [
          "CNA",
          "CWE-671"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.nozominetworks.com/NN-2026:12-01",
          "host": "security.nozominetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 604,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-32665",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T10:07:51.860Z",
      "date_published": "2026-07-22T13:04:18.594Z",
      "date_updated": "2026-07-22T14:32:02.752Z",
      "publisher": "NLnet Labs",
      "title": "Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20715
      },
      "nvd": {
        "published": "2026-07-22T14:17:18.193",
        "lastModified": "2026-07-24T13:57:17.377",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-32665",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unbound exempts QUIC streams 0 and 4 from the quic-size gate and then allocates buffers from their declared 16-bit lengths while the streams remain open.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-32665.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 980,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-32718",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-13T14:33:42.825Z",
      "date_published": "2026-07-06T21:04:59.845Z",
      "date_updated": "2026-07-07T14:01:24.753Z",
      "publisher": "GitHub_M",
      "title": "Coolify read-scoped API tokens can perform state-changing validation operations",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11734
      },
      "nvd": {
        "published": "2026-07-06T22:16:47.927",
        "lastModified": "2026-07-07T15:16:43.513",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-32718",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Coolify protects mutating validation endpoints with a read-level ability instead of the permission required to change the target resource.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-f47p-xrgc-977v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/8893",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/c15bcd56347fc8c535755791e92e4f6c2af17e3a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 348,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-32806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T17:35:36.695Z",
      "date_published": "2026-07-20T16:10:17.575Z",
      "date_updated": "2026-07-20T18:07:36.104Z",
      "publisher": "GitHub_M",
      "title": "dataCycle Authorization Bypass Via /remote_render",
      "affected": {
        "vendors": [
          "datacycle-engine"
        ],
        "products": [
          {
            "vendor": "datacycle-engine",
            "product": "dataCycle-CORE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20915
      },
      "nvd": {
        "published": "2026-07-20T17:17:05.260",
        "lastModified": "2026-07-21T19:35:17.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-32806",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The endpoint does not restrict which partial can be rendered and does not apply controller-specific authorization before rendering the selected view.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-xc6g-2v4c-456c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 796,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-32807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T17:35:36.695Z",
      "date_published": "2026-07-20T15:31:30.999Z",
      "date_updated": "2026-07-20T16:14:09.733Z",
      "publisher": "GitHub_M",
      "title": "dataCycle Public DataLink Text File Download Ignores Validity And Authorization",
      "affected": {
        "vendors": [
          "datacycle-engine"
        ],
        "products": [
          {
            "vendor": "datacycle-engine",
            "product": "dataCycle-CORE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20913
      },
      "nvd": {
        "published": "2026-07-20T16:16:57.963",
        "lastModified": "2026-07-21T19:35:17.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-32807",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public text-file route accepts a DataLink UUID without checking authentication, link expiration, or the normal download authorization.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-gj99-3h7x-v4rv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-32819",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T17:35:36.697Z",
      "date_published": "2026-07-20T16:07:43.343Z",
      "date_updated": "2026-07-20T19:07:44.932Z",
      "publisher": "GitHub_M",
      "title": "dataCycle User Directory Enumeration Via /users/search",
      "affected": {
        "vendors": [
          "datacycle-engine"
        ],
        "products": [
          {
            "vendor": "datacycle-engine",
            "product": "dataCycle-CORE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09646
      },
      "nvd": {
        "published": "2026-07-20T17:17:05.493",
        "lastModified": "2026-07-21T19:35:17.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-32819",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "/users/search exposes other users' names and email addresses to a Standard user even though direct profile authorization denies the same records.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-c4wj-q23r-mq2q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-32820",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T17:35:36.697Z",
      "date_published": "2026-07-20T16:09:05.638Z",
      "date_updated": "2026-07-21T15:51:18.705Z",
      "publisher": "GitHub_M",
      "title": "dataCycle Public Markdown Path Traversal Via /docs/*path",
      "affected": {
        "vendors": [
          "datacycle-engine"
        ],
        "products": [
          {
            "vendor": "datacycle-engine",
            "product": "dataCycle-CORE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00603,
        "percentile": 0.45491
      },
      "nvd": {
        "published": "2026-07-20T17:17:05.623",
        "lastModified": "2026-07-21T19:35:17.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-32820",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled path or object-name data is resolved without proving that the final target remains inside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-gc37-6w59-hj36",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 626,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-32821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T17:35:36.697Z",
      "date_published": "2026-07-20T16:11:29.030Z",
      "date_updated": "2026-07-20T17:32:26.659Z",
      "publisher": "GitHub_M",
      "title": "API Collection Impersonation Via user_email And Missing Object- Level Authorization",
      "affected": {
        "vendors": [
          "datacycle-engine"
        ],
        "products": [
          {
            "vendor": "datacycle-engine",
            "product": "dataCycle-CORE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10137
      },
      "nvd": {
        "published": "2026-07-20T17:17:05.750",
        "lastModified": "2026-07-21T19:35:17.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-32821",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The collection API evaluates permissions as a caller-supplied user_email and exposes mutation routes that omit object-level authorization for the selected collection.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-vjjr-9q8g-mgx7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 707,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-32822",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T17:35:36.697Z",
      "date_published": "2026-07-20T15:34:14.116Z",
      "date_updated": "2026-07-20T17:40:15.245Z",
      "publisher": "GitHub_M",
      "title": "dataCycle Unauthenticated Reflected DOM XSS Via flash[...] On Public Pages",
      "affected": {
        "vendors": [
          "datacycle-engine"
        ],
        "products": [
          {
            "vendor": "datacycle-engine",
            "product": "dataCycle-CORE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-80",
          "name": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11529
      },
      "nvd": {
        "published": "2026-07-20T16:16:58.110",
        "lastModified": "2026-07-21T19:35:17.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-32822",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches dataCycle-CORE page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-80"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-q6x5-wcg6-v4gw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 686,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-32823",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T17:35:36.697Z",
      "date_published": "2026-07-20T16:12:33.395Z",
      "date_updated": "2026-07-20T19:05:22.754Z",
      "publisher": "GitHub_M",
      "title": "dataCycle State-Changing GET Endpoints Enable CSRF",
      "affected": {
        "vendors": [
          "datacycle-engine"
        ],
        "products": [
          {
            "vendor": "datacycle-engine",
            "product": "dataCycle-CORE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01333
      },
      "nvd": {
        "published": "2026-07-20T17:17:05.877",
        "lastModified": "2026-07-21T19:35:17.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-32823",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The application exposes state-changing operations through GET routes that browsers can invoke with an authenticated victim's cookies and no CSRF token.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-55wx-jh6w-jc57",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 947,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-32824",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T17:35:36.697Z",
      "date_published": "2026-07-20T16:14:02.808Z",
      "date_updated": "2026-07-20T17:44:43.760Z",
      "publisher": "GitHub_M",
      "title": "dataCycle User API Password Reset And Confirmation Flows Trust Attacker- Controlled Redirect Targets",
      "affected": {
        "vendors": [
          "datacycle-engine"
        ],
        "products": [
          {
            "vendor": "datacycle-engine",
            "product": "dataCycle-CORE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21833
      },
      "nvd": {
        "published": "2026-07-20T17:17:06.003",
        "lastModified": "2026-07-21T19:35:17.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-32824",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The password workflow embeds unallowlisted forward and redirect URLs into trusted email and browser flows, allowing tokens or users to be sent to an attacker host.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-8jfx-wpjg-hf38",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 935,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-32825",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-16T17:35:36.697Z",
      "date_published": "2026-07-20T16:15:37.377Z",
      "date_updated": "2026-07-20T18:06:24.323Z",
      "publisher": "GitHub_M",
      "title": "dataCycle No Brute-Force Protection On Web And API Login Endpoints",
      "affected": {
        "vendors": [
          "datacycle-engine"
        ],
        "products": [
          {
            "vendor": "datacycle-engine",
            "product": "dataCycle-CORE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21833
      },
      "nvd": {
        "published": "2026-07-20T17:17:06.140",
        "lastModified": "2026-07-21T19:35:17.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-32825",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Both login endpoints accept unlimited authentication attempts because account locking and request throttling are disabled or absent.",
        "basis": [
          "CNA",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-736f-cqq3-ccgf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1009,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33213",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-17T23:23:58.313Z",
      "date_published": "2026-07-15T14:36:19.522Z",
      "date_updated": "2026-07-15T17:49:38.917Z",
      "publisher": "GitHub_M",
      "title": "Redash: Open redirect vulnerability in post-login redirect handling",
      "affected": {
        "vendors": [
          "getredash"
        ],
        "products": [
          {
            "vendor": "getredash",
            "product": "redash"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07539
      },
      "nvd": {
        "published": "2026-07-15T15:16:31.530",
        "lastModified": "2026-07-15T20:52:04.320",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-33213",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The redash redirect path accepts an external destination without restricting it to a trusted origin.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getredash/redash/security/advisories/GHSA-rfgc-hc86-pxrv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getredash/redash/commit/9e66f81673c482d9ae6c425afe009644114605d0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33264",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-18T10:53:38.405Z",
      "date_published": "2026-07-07T09:20:18.518Z",
      "date_updated": "2026-07-08T03:56:40.205Z",
      "publisher": "apache",
      "title": "Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00992,
        "percentile": 0.59177
      },
      "nvd": {
        "published": "2026-07-07T10:16:40.443",
        "lastModified": "2026-07-08T19:37:10.507",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33264",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Airflow deserialization imports an attacker-supplied class path when privileged scheduler or API processes load a DAG.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/airflow/pull/66002",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/apache/airflow/pull/68528",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/otvdw8qt2y7xy2n5nq9xby9ky4rf5ltj",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/07/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 630,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33267",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-18T15:36:26.858Z",
      "date_published": "2026-07-29T07:21:52.256Z",
      "date_updated": "2026-07-30T03:55:17.126Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15776
      },
      "nvd": {
        "published": "2026-07-29T08:16:30.983",
        "lastModified": "2026-07-30T14:54:03.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-33267",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Apache Traffic Server accepts attacker-supplied @ headers as internal metadata instead of separating external header data from trusted proxy state.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-33327",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-18T21:23:36.678Z",
      "date_published": "2026-07-20T16:21:16.663Z",
      "date_updated": "2026-07-20T19:07:38.256Z",
      "publisher": "GitHub_M",
      "title": "Possible integer overflow leading to potential heap-based buffer overflow",
      "affected": {
        "vendors": [
          "libvips"
        ],
        "products": [
          {
            "vendor": "libvips",
            "product": "libvips"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03173
      },
      "nvd": {
        "published": "2026-07-20T17:17:06.283",
        "lastModified": "2026-07-23T15:57:13.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-33327",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libvips performs attacker-influenced size arithmetic without detecting integer overflow, allowing a wrapped value to violate later memory bounds.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/libvips/libvips/security/advisories/GHSA-2fcj-gj27-279x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/libvips/libvips/pull/4934",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-18T21:23:36.678Z",
      "date_published": "2026-07-20T16:22:22.378Z",
      "date_updated": "2026-07-21T15:58:57.209Z",
      "publisher": "GitHub_M",
      "title": "Possible integer overflow on 32-bit systems when reading GIF images",
      "affected": {
        "vendors": [
          "libvips"
        ],
        "products": [
          {
            "vendor": "libvips",
            "product": "libvips"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02115
      },
      "nvd": {
        "published": "2026-07-20T17:17:06.430",
        "lastModified": "2026-07-23T15:57:13.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-33328",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "On 32-bit systems, gifload dimension arithmetic can overflow and produce invalid bounds or allocation sizes.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/libvips/libvips/security/advisories/GHSA-r98w-4fp7-m9c7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/libvips/libvips/pull/4935",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/libvips/libvips/commit/9b633e45abfcf1fc4c84847007c81805193c0969",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 260,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-19T07:55:06.978Z",
      "date_published": "2026-07-10T14:58:23.329Z",
      "date_updated": "2026-07-29T14:00:26.954Z",
      "publisher": "GRAFANA",
      "title": "Denial of service via unbounded request body size",
      "affected": {
        "vendors": [
          "Grafana"
        ],
        "products": [
          {
            "vendor": "Grafana",
            "product": "Grafana OSS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@grafana.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31562
      },
      "nvd": {
        "published": "2026-07-10T16:16:29.130",
        "lastModified": "2026-07-13T20:51:35.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33382",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Several Grafana endpoints process request bodies without a size limit, allowing one large body to force excessive memory allocation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://grafana.com/security/security-advisories/cve-2026-33382",
          "host": "grafana.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-33385",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-19T10:45:47.736Z",
      "date_published": "2026-07-29T12:42:07.228Z",
      "date_updated": "2026-07-29T13:59:52.307Z",
      "publisher": "CERT-PL",
      "title": "Blind SQL Injection in Quick.CMS",
      "affected": {
        "vendors": [
          "OpenSolution"
        ],
        "products": [
          {
            "vendor": "OpenSolution",
            "product": "Quick.CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.1523
      },
      "nvd": {
        "published": "2026-07-29T13:18:08.400",
        "lastModified": "2026-07-30T19:09:20.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-33385",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Quick.CMS concatenates high-privilege administration fields into SQL without preserving the SQL data boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-33385/",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://opensolution.org/home.html",
          "host": "opensolution.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 701,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-19T11:28:43.172Z",
      "date_published": "2026-07-09T07:23:30.236Z",
      "date_updated": "2026-07-09T12:29:18.009Z",
      "publisher": "Nozomi",
      "title": "Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0",
      "affected": {
        "vendors": [
          "Nozomi Networks"
        ],
        "products": [
          {
            "vendor": "Nozomi Networks",
            "product": "Guardian"
          },
          {
            "vendor": "Nozomi Networks",
            "product": "CMC"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:prodsec@nozominetworks.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11334
      },
      "nvd": {
        "published": "2026-07-09T08:16:48.233",
        "lastModified": "2026-07-10T13:12:09.523",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33390",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Arc sensors receive administrative CLI permissions that exceed the authenticated user's intended role.",
        "basis": [
          "CNA",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.nozominetworks.com/NN-2026:13-01",
          "host": "security.nozominetworks.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-33434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-19T18:45:22.436Z",
      "date_published": "2026-07-16T23:36:33.929Z",
      "date_updated": "2026-07-18T03:22:04.345Z",
      "publisher": "GitHub_M",
      "title": "Wazuh: Rate Limit Bypass via /events Endpoint",
      "affected": {
        "vendors": [
          "wazuh"
        ],
        "products": [
          {
            "vendor": "wazuh",
            "product": "wazuh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-799",
          "name": "Improper Control of Interaction Frequency",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 2.8,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18325
      },
      "nvd": {
        "published": "2026-07-17T00:16:24.573",
        "lastModified": "2026-07-20T02:21:08.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33434",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CheckRateLimitsMiddleware overwrites an earlier exceeded-limit result, allowing requests that should be throttled to continue.",
        "basis": [
          "CNA",
          "CWE-799"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-37qc-8242-6crg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33443",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-19T23:04:05.695Z",
      "date_published": "2026-07-15T20:06:30.711Z",
      "date_updated": "2026-07-16T13:11:10.328Z",
      "publisher": "Absolute",
      "title": "Memory management error in Secure Access servers prior to 14.55",
      "affected": {
        "vendors": [
          "Absolute Security"
        ],
        "products": [
          {
            "vendor": "Absolute Security",
            "product": "Secure Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:SecurityResponse@netmotionsoftware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11738
      },
      "nvd": {
        "published": "2026-07-15T20:16:56.780",
        "lastModified": "2026-07-16T14:16:50.170",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33443",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A tunnel-protocol input reaches an undisclosed memory-management error that can leave Secure Access servers in persistent denial of service.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-33443",
          "host": "www.absolute.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33444",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-19T23:04:05.695Z",
      "date_published": "2026-07-15T20:10:20.421Z",
      "date_updated": "2026-07-16T13:10:18.013Z",
      "publisher": "Absolute",
      "title": "Memory management vulnerability in Secure Access servers",
      "affected": {
        "vendors": [
          "Absolute Secutity"
        ],
        "products": [
          {
            "vendor": "Absolute Secutity",
            "product": "Secure Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:SecurityResponse@netmotionsoftware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 3.2,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17385
      },
      "nvd": {
        "published": "2026-07-15T21:16:36.113",
        "lastModified": "2026-07-16T16:28:29.230",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33444",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The vendor describes a tunnel-protocol-triggered memory-management denial of service but does not identify the allocation, lifetime, or release error.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-33444",
          "host": "www.absolute.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 224,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-19T23:04:05.695Z",
      "date_published": "2026-07-15T20:13:55.272Z",
      "date_updated": "2026-07-16T13:09:35.944Z",
      "publisher": "Absolute",
      "title": "Memory management vulnerability in Secure Access servers",
      "affected": {
        "vendors": [
          "Absolute Security"
        ],
        "products": [
          {
            "vendor": "Absolute Security",
            "product": "Secure Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:SecurityResponse@netmotionsoftware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 2.799999999999999,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14696
      },
      "nvd": {
        "published": "2026-07-15T21:16:36.227",
        "lastModified": "2026-07-16T16:28:04.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33445",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The tunnel protocol permits an attacker-controlled workload that retains server memory or processing indefinitely; the public record gives no narrower resource primitive.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-33445",
          "host": "www.absolute.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33592",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T12:53:47.475Z",
      "date_published": "2026-07-02T07:12:24.250Z",
      "date_updated": "2026-07-02T12:30:18.800Z",
      "publisher": "ENISA",
      "title": "FindServers Memory Exhaustion in open62541",
      "affected": {
        "vendors": [
          "open62541 project / o6 Automation GmbH"
        ],
        "products": [
          {
            "vendor": "open62541 project / o6 Automation GmbH",
            "product": "open62541"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30956
      },
      "nvd": {
        "published": "2026-07-02T08:16:39.230",
        "lastModified": "2026-07-02T17:39:07.620",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-33592",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FindServers accepts unbounded declared array and string sizes and retains incomplete chunks until timeout, allowing a pre-session peer to consume gigabytes of memory.",
        "basis": [
          "CNA",
          "CWE-770",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open62541/open62541/pull/8142",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8142/changes/d253818d6c5e870e1db0e360b18138c8bdc809ae",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/open62541/open62541",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-33655",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T15:23:42.218Z",
      "date_published": "2026-07-09T22:28:46.992Z",
      "date_updated": "2026-07-10T14:16:49.910Z",
      "publisher": "GitHub_M",
      "title": "New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs",
      "affected": {
        "vendors": [
          "QuantumNous"
        ],
        "products": [
          {
            "vendor": "QuantumNous",
            "product": "new-api"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18292
      },
      "nvd": {
        "published": "2026-07-09T23:17:04.763",
        "lastModified": "2026-07-16T16:36:20.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33655",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server accepts an attacker-controlled destination without constraining the resolved request target to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/QuantumNous/new-api/security/advisories/GHSA-6qcr-qxgr-m7fv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/QuantumNous/new-api/commit/20399d3c8fcb4e3649d53163eb11940fd6763743",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/QuantumNous/new-api/releases/tag/v0.12.0-alpha.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 560,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T16:34:59.931Z",
      "date_published": "2026-07-15T20:47:45.146Z",
      "date_updated": "2026-07-16T12:54:14.283Z",
      "publisher": "GitHub_M",
      "title": "AVideo's Privilege AVideo: Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions",
      "affected": {
        "vendors": [
          "WWBN"
        ],
        "products": [
          {
            "vendor": "WWBN",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11067
      },
      "nvd": {
        "published": "2026-07-15T21:16:36.323",
        "lastModified": "2026-07-16T14:16:50.530",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-33684",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The signup API applies user-supplied verification and capability flags without requiring the API secret authorized to grant them.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-8j8m-p79x-g4jm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 909,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33692",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T16:34:59.932Z",
      "date_published": "2026-07-16T20:27:04.594Z",
      "date_updated": "2026-07-17T13:22:54.547Z",
      "publisher": "GitHub_M",
      "title": "AVideo Has Unauthenticated .env File Exposure via Official Docker Compose Configuration",
      "affected": {
        "vendors": [
          "WWBN"
        ],
        "products": [
          {
            "vendor": "WWBN",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18384
      },
      "nvd": {
        "published": "2026-07-16T21:17:20.183",
        "lastModified": "2026-07-17T18:36:41.143",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-33692",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Docker configuration exposes the project root as the document root without blocking dotfiles.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-wf69-r4mx-43rr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/WWBN/AVideo/commit/7f418de1a95ab87bb8c8c3eb3702d71c351e098d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 656,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T17:34:57.560Z",
      "date_published": "2026-07-16T20:46:53.407Z",
      "date_updated": "2026-07-17T11:12:04.938Z",
      "publisher": "GitHub_M",
      "title": "AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data",
      "affected": {
        "vendors": [
          "WWBN"
        ],
        "products": [
          {
            "vendor": "WWBN",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04117
      },
      "nvd": {
        "published": "2026-07-16T21:17:20.317",
        "lastModified": "2026-07-17T18:36:41.143",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-33731",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OR-based webhook signature logic accepts a legitimate transaction identifier while trusting attacker-controlled payment fields and omitting approval validation.",
        "basis": [
          "CNA record",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-95jh-7r58-xmxw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/WWBN/AVideo/commit/033e83ae904cacb99495dbea7cbcfb3738cf42e4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1080,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33734",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T17:34:57.560Z",
      "date_published": "2026-07-06T20:56:26.539Z",
      "date_updated": "2026-07-07T14:04:19.170Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12313
      },
      "nvd": {
        "published": "2026-07-06T21:16:55.227",
        "lastModified": "2026-07-07T15:16:43.627",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-33734",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FOSSBilling builds an SQL statement from attacker-controlled text without parameterization or SQL-context separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-jf7m-j359-2899",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T18:30:14.125Z",
      "date_published": "2026-07-16T23:40:59.817Z",
      "date_updated": "2026-07-17T12:16:14.684Z",
      "publisher": "GitHub_M",
      "title": "Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)",
      "affected": {
        "vendors": [
          "wazuh"
        ],
        "products": [
          {
            "vendor": "wazuh",
            "product": "wazuh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00485,
        "percentile": 0.39171
      },
      "nvd": {
        "published": "2026-07-17T00:16:25.383",
        "lastModified": "2026-07-20T13:31:37.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33754",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The unauthenticated cluster parser trusts a declared payload length and allocates that amount of memory before authentication or decryption.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-476v-28pp-5wg9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-33794",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T19:46:13.673Z",
      "date_published": "2026-07-09T21:02:05.330Z",
      "date_updated": "2026-07-10T14:22:17.928Z",
      "publisher": "juniper",
      "title": "Junos OS Evolved: PTX Series: Receipt of repeated ECMP routing updates results in PFE crash",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS Evolved"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:U/V:C/RE:M/U:Green"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Green"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.00236,
        "percentile": 0.1473
      },
      "nvd": {
        "published": "2026-07-09T21:16:54.790",
        "lastModified": "2026-07-13T12:57:12.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33794",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Repeated unilist ECMP updates corrupt evo-aftmand's internal route state until the forwarding process crashes and requires manual recovery.",
        "basis": [
          "CNA",
          "CWE-754"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110073",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1210,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-33799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T19:46:13.673Z",
      "date_published": "2026-07-09T21:02:31.614Z",
      "date_updated": "2026-07-10T13:31:54.447Z",
      "publisher": "juniper",
      "title": "Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results in memory leak and eventual snmpd crash",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          },
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS Evolved"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y/R:A/V:C/RE:M/U:Green"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:C/RE:M/U:Green"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13853
      },
      "nvd": {
        "published": "2026-07-09T21:16:54.963",
        "lastModified": "2026-07-13T12:55:46.097",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33799",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Repeated valid SNMPv3 queries leak snmpd memory because the request path does not release the associated allocation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110074",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1135,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-33800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T19:46:13.673Z",
      "date_published": "2026-07-09T21:03:00.614Z",
      "date_updated": "2026-07-20T13:05:07.325Z",
      "publisher": "juniper",
      "title": "Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps will cause an FPC crash",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-606",
          "name": "Unchecked Input for Loop Condition",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06105
      },
      "nvd": {
        "published": "2026-07-09T21:16:55.163",
        "lastModified": "2026-07-20T14:16:55.823",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-33800",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Repeated micro-BFD flaps keep appending expensive PFEMAN events faster than they complete, preventing loop termination until the watchdog restarts the FPC.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-606"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110075",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1086,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-33801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T19:46:13.673Z",
      "date_published": "2026-07-09T21:03:24.796Z",
      "date_updated": "2026-07-10T13:31:03.248Z",
      "publisher": "juniper",
      "title": "Junos OS and Junos OS Evolved: When a specifically malformed BGP route update is received RPD crashes",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          },
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS Evolved"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00172,
        "percentile": 0.0687
      },
      "nvd": {
        "published": "2026-07-09T21:16:55.330",
        "lastModified": "2026-07-13T20:36:12.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33801",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A malformed non-inet/inet6 BGP update crashes and restarts RPD, but the advisory does not identify the exceptional condition or operation that fails.",
        "basis": [
          "CNA",
          "CWE-754"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110076",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 824,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-33802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T19:46:13.673Z",
      "date_published": "2026-07-09T21:03:48.353Z",
      "date_updated": "2026-07-10T13:28:31.126Z",
      "publisher": "juniper",
      "title": "Junos OS: EX Series: Unauthorized users can execute service-impacting CLI command",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00092,
        "percentile": 0.0062
      },
      "nvd": {
        "published": "2026-07-09T22:17:03.633",
        "lastModified": "2026-07-14T16:59:28.487",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33802",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A user with no corresponding permission can invoke a privileged request through the command-line interface.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110077",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 767,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-33803",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-23T19:46:13.674Z",
      "date_published": "2026-07-09T21:04:14.997Z",
      "date_updated": "2026-07-10T13:30:26.315Z",
      "publisher": "juniper",
      "title": "Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS Evolved"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-923",
          "name": "Improper Restriction of Communication Channel to Intended Endpoints",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y/R:U/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17345
      },
      "nvd": {
        "published": "2026-07-09T22:17:03.807",
        "lastModified": "2026-07-13T20:59:26.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33803",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A wrongly initialized Junos OS Evolved process listens on a network port even though it should be reachable only inside the device.",
        "basis": [
          "CNA",
          "CWE-923"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110078",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 810,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-33842",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-24T00:52:01.354Z",
      "date_published": "2026-07-14T17:05:40.094Z",
      "date_updated": "2026-08-03T22:54:03.503Z",
      "publisher": "microsoft",
      "title": "Windows File Explorer Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28063
      },
      "nvd": {
        "published": "2026-07-14T17:16:46.037",
        "lastModified": "2026-07-22T16:17:17.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33842",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows Explorer exposes information to a local authorized attacker, but the returned data path and missing protection are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33842",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-33930",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-24T18:30:58.396Z",
      "date_published": "2026-07-29T07:23:54.658Z",
      "date_updated": "2026-07-29T13:11:14.140Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Buffer overflow via Host field that has a long string value",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24778
      },
      "nvd": {
        "published": "2026-07-29T08:16:31.127",
        "lastModified": "2026-08-03T13:42:43.303",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-33930",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-34034",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T15:29:04.743Z",
      "date_published": "2026-07-07T03:06:31.815Z",
      "date_updated": "2026-07-07T12:51:01.534Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Host RCE via Sentinel token injection",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33087
      },
      "nvd": {
        "published": "2026-07-07T04:17:47.603",
        "lastModified": "2026-07-07T13:22:13.557",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34034",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 4.0.0-beta.466, the sentinel_token setting is used in shell commands without sufficient validation, allowing an authenticated user with access to server Sentinel settings to inject shell syntax and execute commands on the host when Sentinel is restarted.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-rpr8-p7jc-x844",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/096d4369e59b3db7ace2db3ca42588c41b9b6019",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.466",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34035",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T15:29:04.744Z",
      "date_published": "2026-07-07T02:56:44.328Z",
      "date_updated": "2026-07-07T13:41:35.267Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Host RCE via Log Drain secret/env command injection",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26655
      },
      "nvd": {
        "published": "2026-07-07T04:17:47.873",
        "lastModified": "2026-07-07T14:16:29.983",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34035",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler places caller-controlled data in an operating-system command without safe argument separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-3xm2-hqg8-4m2p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/fcd574e1eb1c2f504c48e5be4a5cb6d69f8f1f55",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.466",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 350,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34037",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T15:29:04.744Z",
      "date_published": "2026-07-07T03:21:52.088Z",
      "date_updated": "2026-07-07T14:02:21.731Z",
      "publisher": "GitHub_M",
      "title": "Cross-Tenant Resource Cloning via Broken Object-Level Authorization in cloneTo()",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00297,
        "percentile": 0.21974
      },
      "nvd": {
        "published": "2026-07-07T04:17:48.020",
        "lastModified": "2026-07-07T15:16:43.730",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34037",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Coolify's cloneTo action loads the destination by an unscoped Eloquent identifier, allowing one tenant to clone into another tenant's resource.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-ggrr-wrvr-x83v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/1759a1631cd63271ebf6caa250c6d93440eaa333",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.464",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34038",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T15:29:04.744Z",
      "date_published": "2026-07-06T20:48:23.396Z",
      "date_updated": "2026-07-07T12:42:59.446Z",
      "publisher": "GitHub_M",
      "title": "Coolify authenticated remote command injection leading to RCE and secret exfiltration",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0175,
        "percentile": 0.75638
      },
      "nvd": {
        "published": "2026-07-06T21:16:55.370",
        "lastModified": "2026-07-07T13:22:13.557",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34038",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application places attacker-controlled data into an operating-system command without separating the data from command syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-qqrq-r9h4-x6wp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9007",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/23f9156c7306b221101f1ebbe4d3c6b5e2522acd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.469",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34044",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T15:29:04.745Z",
      "date_published": "2026-07-07T03:12:30.401Z",
      "date_updated": "2026-07-09T14:42:53.428Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Cross-team IDOR in logs component (resource lookup not team-scoped)",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.1565
      },
      "nvd": {
        "published": "2026-07-07T04:17:48.153",
        "lastModified": "2026-07-09T16:16:39.660",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34044",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Coolify looks up a log resource solely by UUID instead of scoping the lookup to the current team.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-565g-9j4m-wqmr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/6fbb5e626a82c576ae7a1a08b4e1d16aee2e82ed",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.466",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 395,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34047",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T15:29:04.745Z",
      "date_published": "2026-07-07T02:54:59.968Z",
      "date_updated": "2026-07-07T14:29:58.274Z",
      "publisher": "GitHub_M",
      "title": "Coolify: WebSocket Endpoint Access Control Flaw Leading to Remote Code Execution",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00448,
        "percentile": 0.36802
      },
      "nvd": {
        "published": "2026-07-07T04:17:48.287",
        "lastModified": "2026-07-07T15:16:43.837",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34047",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Terminal WebSocket bootstrap routes omit the expected authorization middleware and accept resources outside the caller's allowed scope.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-652w-qv22-2r7c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9169",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/bc91b41f92f1bbb53886a5d7a60335cbf1621cd5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34048",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T15:29:04.745Z",
      "date_published": "2026-07-07T03:19:42.772Z",
      "date_updated": "2026-07-07T13:56:10.936Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Missing authorization on terminal websocket bootstrap routes allows low-privileged members to execute commands on team servers",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00576,
        "percentile": 0.44224
      },
      "nvd": {
        "published": "2026-07-07T04:17:48.417",
        "lastModified": "2026-07-07T15:16:43.953",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34048",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Coolify's terminal WebSocket bootstrap verifies login but never verifies that the team member may open a terminal on the selected server.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-mw6q-2hmg-mhxv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/847166a3f89b7c80972fa0d2e5c754976f95b6ad",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 382,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34049",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T15:29:04.745Z",
      "date_published": "2026-07-06T21:22:46.878Z",
      "date_updated": "2026-07-07T12:46:10.583Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Command Injection via unsanitized MongoDB collection names in database backup",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09456
      },
      "nvd": {
        "published": "2026-07-06T22:16:48.117",
        "lastModified": "2026-07-07T13:22:13.557",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34049",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A MongoDB collection name containing shell metacharacters is inserted into a backup command without shell-safe argument separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-4mpw-wcj4-v9pp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9168",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/b1de75a7c67ce6aee977bd788b41e61837dbe0b9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 379,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34050",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T15:29:04.746Z",
      "date_published": "2026-07-06T21:08:08.611Z",
      "date_updated": "2026-07-07T13:51:02.738Z",
      "publisher": "GitHub_M",
      "title": "Coolify Settings/Updates Livewire component missing instance administrator authorization",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11736
      },
      "nvd": {
        "published": "2026-07-06T22:16:48.250",
        "lastModified": "2026-07-07T15:16:44.300",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34050",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Updates component omits the isInstanceAdmin check before exposing update settings and actions to ordinary users.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-c339-w3cq-2rjr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9206",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/0fed553207383f384b93cba24d28122065fa67d5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 394,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34057",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T15:29:04.747Z",
      "date_published": "2026-07-07T03:17:37.605Z",
      "date_updated": "2026-07-07T13:11:31.594Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Authenticated Remote Code Execution via Command Injection in Database Import Container Name",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27405
      },
      "nvd": {
        "published": "2026-07-07T04:17:48.647",
        "lastModified": "2026-07-07T14:16:30.080",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34057",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A client-controlled database import container name reaches a shell command without locking or validation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-6r3g-w7x8-54fj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/d486bf09ab2da8ad78fa721a079f066c76ce08d2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 457,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34058",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T15:29:04.747Z",
      "date_published": "2026-07-07T02:58:57.633Z",
      "date_updated": "2026-07-07T13:40:48.893Z",
      "publisher": "GitHub_M",
      "title": "Coolify: OS Command Injection via Unmanaged Container Operations - Remote Code Execution",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27859
      },
      "nvd": {
        "published": "2026-07-07T04:17:49.193",
        "lastModified": "2026-07-07T14:16:30.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34058",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In coolify, attacker-controlled input reaches an operating-system command without shell-context neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-rh5x-qx77-fq9v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9172",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/944a038349216f00b390e905c121355adc8b23c1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34096",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.825Z",
      "date_published": "2026-07-01T15:53:40.936Z",
      "date_updated": "2026-07-14T18:40:12.697Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System XSS via name Parameter in designer.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04403
      },
      "nvd": {
        "published": "2026-07-01T17:16:32.447",
        "lastModified": "2026-07-14T19:16:59.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34096",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "language-system places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-xss-via-designer-php-name-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34097",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.826Z",
      "date_published": "2026-07-01T16:02:34.601Z",
      "date_updated": "2026-07-14T18:40:13.413Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System XSS via id Parameter in text_file.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04403
      },
      "nvd": {
        "published": "2026-07-01T17:16:32.580",
        "lastModified": "2026-07-14T19:16:59.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34097",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "text_file.php inserts the id parameter into HTML form action attributes without attribute-context escaping.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-xss-via-text-file-php-id-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34098",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.826Z",
      "date_published": "2026-07-01T16:04:04.525Z",
      "date_updated": "2026-07-14T18:40:14.100Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System XSS via id Parameter in media.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04404
      },
      "nvd": {
        "published": "2026-07-01T17:16:32.700",
        "lastModified": "2026-07-14T19:16:59.257",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34098",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "language-system renders attacker-controlled content without the required HTML sanitization or output escaping, allowing cross-site scripting.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-xss-via-id-parameter-in-media-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34099",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.826Z",
      "date_published": "2026-07-01T16:08:08.295Z",
      "date_updated": "2026-07-14T18:40:14.777Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00459,
        "percentile": 0.37551
      },
      "nvd": {
        "published": "2026-07-01T17:16:32.820",
        "lastModified": "2026-07-14T19:16:59.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34099",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "job_info.php concatenates the unauthenticated id parameter directly into its SELECT statement.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-sql-injection-via-id-parameter-in-job-info-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34100",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.826Z",
      "date_published": "2026-07-01T16:10:07.054Z",
      "date_updated": "2026-07-14T18:40:15.459Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated SQL Injection via id Parameter in media.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00373,
        "percentile": 0.29997
      },
      "nvd": {
        "published": "2026-07-01T17:16:32.940",
        "lastModified": "2026-07-14T19:16:59.477",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34100",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "media.php concatenates the id parameter directly into an SQL query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-sql-injection-via-id-parameter-in-media-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34101",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.826Z",
      "date_published": "2026-07-01T16:11:00.426Z",
      "date_updated": "2026-07-14T18:40:16.147Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated SQL Injection via id Parameter in text_file.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00373,
        "percentile": 0.29997
      },
      "nvd": {
        "published": "2026-07-01T17:16:33.067",
        "lastModified": "2026-07-14T19:16:59.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34101",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "text_file.php concatenates the id GET parameter directly into a SELECT statement.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-sql-injection-via-id-parameter-in-text-file-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34102",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.826Z",
      "date_published": "2026-07-01T16:11:48.044Z",
      "date_updated": "2026-07-14T18:40:16.821Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info_get.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00373,
        "percentile": 0.29998
      },
      "nvd": {
        "published": "2026-07-01T17:16:33.180",
        "lastModified": "2026-07-14T19:16:59.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34102",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\\\".$_GET['id'].\\\"'.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-sql-injection-via-id-parameter-in-job-info-get-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.826Z",
      "date_published": "2026-07-01T16:12:26.812Z",
      "date_updated": "2026-07-14T18:40:17.457Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated SQL Injection via id Parameter in subtitles.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00373,
        "percentile": 0.29999
      },
      "nvd": {
        "published": "2026-07-01T17:16:33.303",
        "lastModified": "2026-07-14T19:16:59.827",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34103",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where id = '\\\".$_GET['id'].\\\"'.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-sql-injection-via-id-parameter-in-subtitles-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34104",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.826Z",
      "date_published": "2026-07-01T16:13:26.310Z",
      "date_updated": "2026-07-14T18:40:18.147Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated SQL Injection via name Parameter in designer.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00373,
        "percentile": 0.29998
      },
      "nvd": {
        "published": "2026-07-01T17:16:33.420",
        "lastModified": "2026-07-14T19:16:59.937",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34104",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "designer.php concatenates the name query parameter directly into a quoted SQL statement.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-sql-injection-via-name-parameter-in-designer-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34105",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.827Z",
      "date_published": "2026-07-01T16:15:01.201Z",
      "date_updated": "2026-07-14T18:40:18.827Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated SQL Injection via id Parameter in translate_text.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00373,
        "percentile": 0.29998
      },
      "nvd": {
        "published": "2026-07-01T17:16:33.537",
        "lastModified": "2026-07-14T19:17:00.053",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34105",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "translate_text.php concatenates the id query parameter directly into a SELECT statement instead of binding it as data.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-sql-injection-via-id-parameter-in-translate-text-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 298,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34106",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.827Z",
      "date_published": "2026-07-01T16:16:04.347Z",
      "date_updated": "2026-07-14T18:40:19.503Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in subtitles.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.0068,
        "percentile": 0.48851
      },
      "nvd": {
        "published": "2026-07-01T17:16:33.657",
        "lastModified": "2026-07-14T19:17:00.163",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34106",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application places attacker-controlled data into a shell command without separating the data from command syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-os-command-injection-via-id-parameter-in-subtitles-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 385,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34107",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.827Z",
      "date_published": "2026-07-01T16:16:50.769Z",
      "date_updated": "2026-07-14T18:40:20.208Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.0068,
        "percentile": 0.4885
      },
      "nvd": {
        "published": "2026-07-01T17:16:33.837",
        "lastModified": "2026-07-14T19:17:00.280",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34107",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value reaches operating-system command construction in language-system without separation from command or argument syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-os-command-injection-via-id-parameter-in-translate-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 356,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34108",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.827Z",
      "date_published": "2026-07-01T16:17:37.107Z",
      "date_updated": "2026-07-14T18:40:20.918Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00549,
        "percentile": 0.4285
      },
      "nvd": {
        "published": "2026-07-01T17:16:33.970",
        "lastModified": "2026-07-14T19:17:00.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34108",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The text.php id parameter is concatenated directly into a PHP exec command without neutralizing shell metacharacters.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-os-command-injection-via-id-parameter-in-text-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 346,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34109",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.827Z",
      "date_published": "2026-07-01T16:18:27.045Z",
      "date_updated": "2026-07-14T18:40:21.626Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speech.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00537,
        "percentile": 0.42248
      },
      "nvd": {
        "published": "2026-07-01T17:16:34.107",
        "lastModified": "2026-07-14T19:17:00.503",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34109",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The id value is concatenated into an exec command without neutralizing shell syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-os-command-injection-via-id-parameter-in-speech-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 356,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34110",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.827Z",
      "date_published": "2026-07-01T16:19:15.307Z",
      "date_updated": "2026-07-14T18:40:22.336Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in complex_start.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00549,
        "percentile": 0.4285
      },
      "nvd": {
        "published": "2026-07-01T17:16:34.263",
        "lastModified": "2026-07-14T19:17:00.610",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34110",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "complex_start.php concatenates the unauthenticated id parameter into exec without neutralizing shell metacharacters.",
        "basis": [
          "CNA record",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-os-command-injection-via-id-parameter-in-complex-start-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 358,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34111",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.827Z",
      "date_published": "2026-07-01T16:20:09.396Z",
      "date_updated": "2026-07-14T18:40:23.048Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac_text.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00549,
        "percentile": 0.42849
      },
      "nvd": {
        "published": "2026-07-01T17:16:34.397",
        "lastModified": "2026-07-14T19:17:00.727",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34111",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "language-system places attacker-controlled data into an operating-system command without separating it from command syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-os-command-injection-via-id-parameter-in-speechmac-text-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 373,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34112",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.827Z",
      "date_published": "2026-07-01T16:20:46.838Z",
      "date_updated": "2026-07-14T18:40:23.725Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00537,
        "percentile": 0.42248
      },
      "nvd": {
        "published": "2026-07-01T17:16:34.517",
        "lastModified": "2026-07-14T19:17:00.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34112",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "speechmac.php concatenates the unauthenticated id parameter directly into a PHP exec command.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-os-command-injection-via-id-parameter-in-speechmac-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34113",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.827Z",
      "date_published": "2026-07-01T16:21:21.167Z",
      "date_updated": "2026-07-14T18:40:24.406Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speech_text.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00537,
        "percentile": 0.42247
      },
      "nvd": {
        "published": "2026-07-01T17:16:34.650",
        "lastModified": "2026-07-14T19:17:00.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34113",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In language-system, attacker-controlled input reaches an operating-system command without shell-context neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-os-command-injection-via-id-parameter-in-speech-text-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34114",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.828Z",
      "date_published": "2026-07-01T16:21:59.251Z",
      "date_updated": "2026-07-14T18:40:25.099Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate_text.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00537,
        "percentile": 0.42247
      },
      "nvd": {
        "published": "2026-07-01T17:16:34.780",
        "lastModified": "2026-07-14T19:17:01.070",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34114",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text reaches an operating-system command boundary without shell-safe argument separation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-os-command-injection-via-id-parameter-in-translate-text-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34115",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.828Z",
      "date_published": "2026-07-01T16:22:45.160Z",
      "date_updated": "2026-07-14T18:40:25.800Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe_amazon.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00537,
        "percentile": 0.42247
      },
      "nvd": {
        "published": "2026-07-01T17:16:34.907",
        "lastModified": "2026-07-14T19:17:01.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34115",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "transcribe_amazon.php concatenates the unauthenticated id parameter directly into a PHP exec command, allowing shell metacharacters to change the command.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-os-command-injection-via-id-parameter-in-transcribe-amazon-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 372,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34116",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.828Z",
      "date_published": "2026-07-01T16:23:24.760Z",
      "date_updated": "2026-07-14T18:40:26.490Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00549,
        "percentile": 0.4285
      },
      "nvd": {
        "published": "2026-07-01T17:16:35.033",
        "lastModified": "2026-07-14T19:17:01.293",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34116",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The language-system path inserts attacker-controlled text into an operating-system command without preserving the command grammar.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-os-command-injection-via-id-parameter-in-transcribe-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 358,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34117",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T18:43:09.828Z",
      "date_published": "2026-07-01T16:24:06.805Z",
      "date_updated": "2026-07-14T18:40:27.231Z",
      "publisher": "VulnCheck",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text_to_subtitles.php",
      "affected": {
        "vendors": [
          "guardian"
        ],
        "products": [
          {
            "vendor": "guardian",
            "product": "language-system"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00537,
        "percentile": 0.42248
      },
      "nvd": {
        "published": "2026-07-01T17:16:35.160",
        "lastModified": "2026-07-14T19:17:01.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34117",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker input is incorporated into interpreter syntax without parameterization or context-specific escaping.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/cyberinforepo/d5b2771d82e1b31b8fc1c33052e08dad",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/guardian-language-system-unauthenticated-os-command-injection-via-id-parameter-in-text-to-subtitles-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 372,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34149",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T20:12:04.196Z",
      "date_published": "2026-07-07T03:09:33.827Z",
      "date_updated": "2026-07-07T14:07:09.741Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Authenticated Host-Level RCE via Unescaped Database Credentials in Backup Jobs",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12757
      },
      "nvd": {
        "published": "2026-07-07T04:17:49.800",
        "lastModified": "2026-07-07T15:16:44.403",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34149",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The coolify command path concatenates attacker-controlled data into an operating-system command without preserving the shell grammar boundary.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-4vff-6j8j-qhcg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/952f3247970d261ff93f85c79066192f58f9557e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/99043600ee881fd8581185e7590604d9882382cd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 440,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34150",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T20:12:04.196Z",
      "date_published": "2026-07-16T23:44:42.433Z",
      "date_updated": "2026-07-17T10:48:02.655Z",
      "publisher": "GitHub_M",
      "title": "Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing",
      "affected": {
        "vendors": [
          "wazuh"
        ],
        "products": [
          {
            "vendor": "wazuh",
            "product": "wazuh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17075
      },
      "nvd": {
        "published": "2026-07-17T00:16:25.520",
        "lastModified": "2026-07-20T13:36:42.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-34150",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Wazuh writes beyond a heap allocation while processing attacker-controlled input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-rvr9-89q8-w883",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 903,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34152",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T20:12:04.196Z",
      "date_published": "2026-07-07T03:11:14.111Z",
      "date_updated": "2026-07-09T14:42:58.988Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Command Injection via Newline in Pre/Post Deployment Commands (Heredoc Transport)",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29918
      },
      "nvd": {
        "published": "2026-07-07T04:17:50.043",
        "lastModified": "2026-07-09T16:16:39.760",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34152",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Coolify escapes deployment commands for single quotes but transports them in an SSH heredoc that preserves newlines, allowing an authenticated user to append shell statements on the remote server.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-5qp8-9gg7-4c86",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9173",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/ad95d65aca064f49b38f73f88d61f842737d5463",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34153",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T20:12:04.196Z",
      "date_published": "2026-07-06T21:12:46.488Z",
      "date_updated": "2026-07-07T14:51:37.912Z",
      "publisher": "GitHub_M",
      "title": "Coolify LocalFileVolume fs_path command injection enables RCE",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33087
      },
      "nvd": {
        "published": "2026-07-06T22:16:48.370",
        "lastModified": "2026-07-07T16:16:38.680",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34153",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LocalFileVolume::saveStorageOnServer inserts unescaped fs_path and parent_dir values into shell commands before validating the file-mount path.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-46hp-7m8g-7622",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9176",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/3fdce06b654fa3b7b4be59c0faaab6b4546c78de",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T20:12:04.196Z",
      "date_published": "2026-07-07T03:28:33.647Z",
      "date_updated": "2026-07-07T13:38:48.452Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Command injection via single-quote breakout in Docker Compose custom commands",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28133
      },
      "nvd": {
        "published": "2026-07-07T05:16:50.730",
        "lastModified": "2026-07-07T14:16:30.277",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34158",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler places caller-controlled data in an operating-system command without safe argument separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-j6j2-frv3-g6f7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 604,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34167",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T20:12:04.197Z",
      "date_published": "2026-07-06T21:28:24.046Z",
      "date_updated": "2026-07-08T19:43:19.741Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Cross-tenant activity log disclosure via unlocked Livewire property in ActivityMonitor",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09966
      },
      "nvd": {
        "published": "2026-07-06T22:16:48.497",
        "lastModified": "2026-07-08T20:16:48.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34167",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Coolify loads an Activity record by a global identifier without constraining it to the authenticated tenant.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-962v-gxmw-56hc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9189",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/2729dffb3e30167c1ffd642357b7e0bb99b7d180",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 637,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34168",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T20:12:04.198Z",
      "date_published": "2026-07-07T03:05:18.855Z",
      "date_updated": "2026-07-07T14:31:57.058Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Command injection via unsanitized persistent storage name in docker volume commands",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33087
      },
      "nvd": {
        "published": "2026-07-07T04:17:50.180",
        "lastModified": "2026-07-07T15:16:44.500",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34168",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application places attacker-controlled data into an operating-system command without separating the data from command syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-mh8x-fppq-cp77",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/d2064dd4998694cda2eabd00149f7c4d1e94c699",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34170",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T20:12:04.198Z",
      "date_published": "2026-07-07T03:23:40.061Z",
      "date_updated": "2026-07-07T13:55:10.465Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Server-Side Request Forgery via attacker-controlled GitHub App API URL",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06743
      },
      "nvd": {
        "published": "2026-07-07T04:17:50.357",
        "lastModified": "2026-07-07T15:16:44.607",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34170",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "coolify follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-3g6r-cxv5-3c7h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34171",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-25T20:12:04.198Z",
      "date_published": "2026-07-07T03:07:50.372Z",
      "date_updated": "2026-07-07T12:56:28.312Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Account takeover via CSRF-able GET endpoint that resets password to attacker-known value",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04341
      },
      "nvd": {
        "published": "2026-07-07T04:17:50.513",
        "lastModified": "2026-07-07T13:22:13.557",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34171",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A state-changing GET invitation route resets the visited account's password from an attacker-known invitation identifier without explicit victim confirmation.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-389w-cc6x-wr2m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/25d424c743d5134d4a005a6d8f754bb3235b632c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 434,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34196",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-26T13:47:30.669Z",
      "date_published": "2026-07-10T20:42:17.526Z",
      "date_updated": "2026-07-13T18:55:28.947Z",
      "publisher": "imaginationtech",
      "title": "GPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMem",
      "affected": {
        "vendors": [
          "Imagination Technologies"
        ],
        "products": [
          {
            "vendor": "Imagination Technologies",
            "product": "Graphics DDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.0202
      },
      "nvd": {
        "published": "2026-07-10T21:16:54.297",
        "lastModified": "2026-07-13T19:24:52.303",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34196",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An integer overflow lets two GPU virtual mappings reference one physical page, and freeing one mapping leaves the other reading and writing freed memory.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
          "host": "www.imaginationtech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-34198",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-26T15:57:52.323Z",
      "date_published": "2026-07-07T03:01:19.285Z",
      "date_updated": "2026-07-07T13:36:25.549Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Password reset link poisoning via X-Forwarded-Host header spoofing",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03733
      },
      "nvd": {
        "published": "2026-07-07T04:17:50.847",
        "lastModified": "2026-07-07T14:16:30.377",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34198",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Coolify trusts X-Forwarded-Host from any source and uses that value to construct a password-reset link, sending the token toward an attacker-controlled host.",
        "basis": [
          "CNA",
          "CWE-346",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-cgj8-7m5q-x5gv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9193",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/98569e4edbfc316877c9e0d27ea89fab3c49e3bd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 768,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34239",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-26T16:22:29.034Z",
      "date_published": "2026-07-20T17:11:01.502Z",
      "date_updated": "2026-07-20T18:24:41.863Z",
      "publisher": "GitHub_M",
      "title": "Chamilo Authenticated Remote Code Execution",
      "affected": {
        "vendors": [
          "chamilo"
        ],
        "products": [
          {
            "vendor": "chamilo",
            "product": "chamilo-lms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21391
      },
      "nvd": {
        "published": "2026-07-20T18:16:51.360",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34239",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The language AJAX endpoint treats any course-enrolled user as sufficiently authorized for an operation that can execute server-side code.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-4hwq-pv7c-3928",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34316",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-26T19:48:45.681Z",
      "date_published": "2026-07-21T21:32:45.710Z",
      "date_updated": "2026-07-23T15:20:01.440Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Service Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06801
      },
      "nvd": {
        "published": "2026-07-21T22:17:00.887",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34316",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthorized data access in Commerce Service Center but does not identify the object, role, or action check that fails.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 913,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-26T21:02:16.445Z",
      "date_published": "2026-07-14T17:05:40.673Z",
      "date_updated": "2026-08-03T22:54:04.124Z",
      "publisher": "microsoft",
      "title": "Windows Audio Service Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28062
      },
      "nvd": {
        "published": "2026-07-14T17:16:46.220",
        "lastModified": "2026-07-22T16:17:17.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-34328",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows Audio Service exposes protected local information to an authorized attacker, while Microsoft's public record does not identify the output or data-selection error.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34328",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-34346",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-26T21:02:16.446Z",
      "date_published": "2026-07-14T17:04:19.569Z",
      "date_updated": "2026-08-03T22:52:48.311Z",
      "publisher": "microsoft",
      "title": "Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 20,
        "versionEntryCount": 20,
        "versionRangeCount": 20,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-319",
          "name": "Cleartext Transmission of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10357
      },
      "nvd": {
        "published": "2026-07-14T17:16:46.373",
        "lastModified": "2026-07-22T16:17:17.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-34346",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 transmits sensitive data without a confidentiality-protecting channel, allowing an observer on the path to recover it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-319"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34346",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 159,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 20,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-34348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-26T21:02:16.447Z",
      "date_published": "2026-07-14T17:05:43.042Z",
      "date_updated": "2026-08-03T22:54:06.500Z",
      "publisher": "microsoft",
      "title": "Windows Event Logging Service Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00715,
        "percentile": 0.50178
      },
      "nvd": {
        "published": "2026-07-14T17:16:46.560",
        "lastModified": "2026-07-22T16:17:17.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-34348",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Microsoft record reports an Event Logging protection failure and disclosure but does not identify the protected data, output path, or failed mechanism.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34348",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-34349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-26T21:02:16.447Z",
      "date_published": "2026-07-14T17:04:19.019Z",
      "date_updated": "2026-08-03T22:52:47.831Z",
      "publisher": "microsoft",
      "title": "Windows Media Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28111
      },
      "nvd": {
        "published": "2026-07-14T17:16:46.730",
        "lastModified": "2026-07-22T16:17:18.153",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-34349",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Windows 10 Version 1809 discloses protected data, but does not identify the output, cache, or memory path that exposes it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34349",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-34490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-30T08:25:11.763Z",
      "date_published": "2026-07-31T17:17:33.651Z",
      "date_updated": "2026-07-31T17:38:49.752Z",
      "publisher": "jci",
      "title": "XAAP Android Data Stored in Unencrypted Database",
      "affected": {
        "vendors": [
          "Johnson Controls"
        ],
        "products": [
          {
            "vendor": "Johnson Controls",
            "product": "XAAP Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-312",
          "name": "Cleartext Storage of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:productsecurity@jci.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00101,
        "percentile": 0.01076
      },
      "nvd": {
        "published": "2026-07-31T18:17:14.150",
        "lastModified": "2026-07-31T18:17:14.150",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34490",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Android application stores sensitive XAAP data in a cleartext local database readable from a compromised device.",
        "basis": [
          "CNA",
          "CWE-312"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories",
          "host": "www.johnsoncontrols.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34495",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-30T08:25:11.763Z",
      "date_published": "2026-07-31T17:30:52.669Z",
      "date_updated": "2026-07-31T18:11:09.338Z",
      "publisher": "jci",
      "title": "FMS Employee vulnerable to XSS",
      "affected": {
        "vendors": [
          "Johnson Controls"
        ],
        "products": [
          {
            "vendor": "Johnson Controls",
            "product": "FM Systems Employee"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:productsecurity@jci.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34373
      },
      "nvd": {
        "published": "2026-07-31T18:17:14.310",
        "lastModified": "2026-07-31T19:17:08.850",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34495",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FM Systems Employee stores attacker input that is later parsed as executable page markup without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories",
          "host": "www.johnsoncontrols.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-30T08:25:11.763Z",
      "date_published": "2026-07-23T20:26:31.808Z",
      "date_updated": "2026-07-24T13:36:00.484Z",
      "publisher": "jci",
      "title": "victor Web - Priviledge Escalation",
      "affected": {
        "vendors": [
          "Johnson Controls"
        ],
        "products": [
          {
            "vendor": "Johnson Controls",
            "product": "victor Web"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L"
        },
        {
          "source": "NVD:productsecurity@jci.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10618
      },
      "nvd": {
        "published": "2026-07-23T21:17:03.947",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34496",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "victor Web permits a privilege-management action outside the caller's assigned role, while the public record does not identify the endpoint or missing check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories",
          "host": "www.johnsoncontrols.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 125,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34497",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-30T08:25:11.763Z",
      "date_published": "2026-07-31T17:31:05.487Z",
      "date_updated": "2026-07-31T18:10:50.071Z",
      "publisher": "jci",
      "title": "FMS Employee Vulnerable to HTML Injection",
      "affected": {
        "vendors": [
          "Johnson Controls"
        ],
        "products": [
          {
            "vendor": "Johnson Controls",
            "product": "FM Systems Employee"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-80",
          "name": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:productsecurity@jci.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34374
      },
      "nvd": {
        "published": "2026-07-31T18:17:14.457",
        "lastModified": "2026-07-31T19:17:08.983",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34497",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS).",
        "basis": [
          "CNA",
          "CWE-80"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories",
          "host": "www.johnsoncontrols.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 224,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34599",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-30T17:15:52.499Z",
      "date_published": "2026-07-06T21:20:56.608Z",
      "date_updated": "2026-07-07T14:23:47.614Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Authenticated Remote Code Execution in GetLogs Livewire Component",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01351,
        "percentile": 0.6879
      },
      "nvd": {
        "published": "2026-07-06T22:16:48.623",
        "lastModified": "2026-07-07T15:16:44.700",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34599",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the GetLogs Livewire component which allows users with team membership (lowest privilege member role) to execute arbitrary commands as root on managed servers.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-q9j6-xcvx-px63",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9229",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/f267a28cb2badc7e712c4592af4d79d090fe5063",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-34641",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-30T17:30:36.492Z",
      "date_published": "2026-07-31T23:08:58.446Z",
      "date_updated": "2026-08-04T03:56:22.645Z",
      "publisher": "adobe",
      "title": "Premiere Pro | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Premiere"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03702
      },
      "nvd": {
        "published": "2026-07-31T23:17:23.563",
        "lastModified": "2026-08-04T14:48:22.933",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-34641",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected parser writes beyond its destination buffer because attacker-controlled size or index data is not bounded.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/premiere_pro/apsb26-76.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-35048",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-03-31T21:06:06.429Z",
      "date_published": "2026-07-20T16:27:09.513Z",
      "date_updated": "2026-07-20T17:11:17.973Z",
      "publisher": "GitHub_M",
      "title": "Piwigo RCE via PHP Code Injection into Config File in Installer",
      "affected": {
        "vendors": [
          "Piwigo"
        ],
        "products": [
          {
            "vendor": "Piwigo",
            "product": "Piwigo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24617
      },
      "nvd": {
        "published": "2026-07-20T17:17:06.840",
        "lastModified": "2026-07-21T20:27:18.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-35048",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The installer interpolates unsanitized database parameters into a PHP configuration file after a removed PHP function disables its intended escaping branch.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Piwigo/Piwigo/security/advisories/GHSA-gphq-34pv-gvf3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 611,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35140",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T16:31:58.809Z",
      "date_published": "2026-07-16T12:48:11.395Z",
      "date_updated": "2026-07-16T14:16:26.309Z",
      "publisher": "HCL",
      "title": "HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "DFXAnalytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 4.2,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05783
      },
      "nvd": {
        "published": "2026-07-16T14:16:50.633",
        "lastModified": "2026-07-17T17:00:19.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35140",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DFXAnalytics omits the Secure attribute from authentication cookies, allowing them to traverse an unencrypted HTTP channel.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 383,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35141",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T16:31:58.809Z",
      "date_published": "2026-07-16T12:59:07.792Z",
      "date_updated": "2026-07-16T14:16:08.107Z",
      "publisher": "HCL",
      "title": "HCL DFXAnalytics is affected by a Login Replay Attack vulnerability",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "DFXAnalytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 2.6999999999999997,
      "epss": {
        "score": 0.00192,
        "percentile": 0.09089
      },
      "nvd": {
        "published": "2026-07-16T14:16:50.747",
        "lastModified": "2026-07-17T16:44:13.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35141",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The login flow accepts replayed authentication data without binding it to a fresh timestamp or nonce.",
        "basis": [
          "CNA",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 433,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35142",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T16:32:01.021Z",
      "date_published": "2026-07-16T13:02:45.684Z",
      "date_updated": "2026-07-16T14:14:51.156Z",
      "publisher": "HCL",
      "title": "HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "DFXAnalytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 5.6,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08136
      },
      "nvd": {
        "published": "2026-07-16T14:16:50.863",
        "lastModified": "2026-07-17T16:27:03.640",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35142",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Generated responses include internal IP addresses that should remain private.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 333,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T16:32:01.021Z",
      "date_published": "2026-07-16T13:04:04.877Z",
      "date_updated": "2026-07-16T13:45:27.006Z",
      "publisher": "HCL",
      "title": "HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "DFXAnalytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 3.5,
      "epss": {
        "score": 0.00108,
        "percentile": 0.01409
      },
      "nvd": {
        "published": "2026-07-16T14:16:50.973",
        "lastModified": "2026-07-17T16:22:20.560",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35143",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Authentication cookies omit SameSite and may therefore accompany a cross-site request when no independent CSRF control blocks it.",
        "basis": [
          "CNA record",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T16:32:01.021Z",
      "date_published": "2026-07-16T13:05:30.953Z",
      "date_updated": "2026-07-16T13:45:02.414Z",
      "publisher": "HCL",
      "title": "HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "DFXAnalytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06937
      },
      "nvd": {
        "published": "2026-07-16T14:16:51.123",
        "lastModified": "2026-07-17T19:03:57.607",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35145",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Responses omit HSTS, allowing a network intermediary to downgrade a browser from the intended HTTPS channel to HTTP.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35146",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T16:32:01.021Z",
      "date_published": "2026-07-16T11:01:08.740Z",
      "date_updated": "2026-07-16T12:14:36.987Z",
      "publisher": "HCL",
      "title": "HCL DFXServer is affected by an Unencrypted Communication vulnerability.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "DFXServer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-326",
          "name": "Inadequate Encryption Strength",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01896
      },
      "nvd": {
        "published": "2026-07-16T12:17:35.493",
        "lastModified": "2026-07-21T20:10:44.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35146",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DFXServer permits sensitive sessions over plaintext HTTP without transport encryption.",
        "basis": [
          "CNA",
          "CWE-326"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131782",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T16:32:01.021Z",
      "date_published": "2026-07-16T11:04:00.743Z",
      "date_updated": "2026-07-16T11:56:23.129Z",
      "publisher": "HCL",
      "title": "HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "DFXServer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18729
      },
      "nvd": {
        "published": "2026-07-16T12:17:35.617",
        "lastModified": "2026-07-21T20:16:32.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35147",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Selected DFXServer API endpoints execute protected actions without verifying that the caller has an authenticated session.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131782",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35148",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T16:32:01.022Z",
      "date_published": "2026-07-16T11:02:19.807Z",
      "date_updated": "2026-07-16T12:07:24.658Z",
      "publisher": "HCL",
      "title": "HCL DFXServer is affected by a Missing Access Control vulnerability",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "DFXServer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00167,
        "percentile": 0.06358
      },
      "nvd": {
        "published": "2026-07-16T12:17:35.733",
        "lastModified": "2026-07-21T20:16:38.743",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35148",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DFXServer exposes application API endpoints without authentication, allowing network callers to invoke them as trusted users.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131782",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 334,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35149",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T16:32:01.022Z",
      "date_published": "2026-07-16T11:03:06.446Z",
      "date_updated": "2026-07-16T12:06:39.721Z",
      "publisher": "HCL",
      "title": "HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "DFXServer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16055
      },
      "nvd": {
        "published": "2026-07-16T12:17:35.870",
        "lastModified": "2026-07-21T20:16:44.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35149",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The client treats an attacker-modified authentication response as proof of successful login instead of binding access to server-verified credentials.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131782",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35152",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T16:47:55.529Z",
      "date_published": "2026-07-15T09:19:54.983Z",
      "date_updated": "2026-07-15T14:33:38.726Z",
      "publisher": "apache",
      "title": "Apache Fineract: SQL injection in runreports endpoint",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Fineract"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0228,
        "percentile": 0.81424
      },
      "nvd": {
        "published": "2026-07-15T10:16:46.850",
        "lastModified": "2026-07-15T20:16:32.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35152",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Apache Fineract data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/fineract/pull/5980",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/d3bzcwsbywz7wg9zxvtlkvgmffqjyfn0",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/658yddn0bpxqw2hpxnyk3vqd05bkchg9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/15/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35159",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T17:04:27.475Z",
      "date_published": "2026-07-03T08:08:31.672Z",
      "date_updated": "2026-07-07T02:13:16.372Z",
      "publisher": "dell",
      "title": "Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "Inspiron 15 3520"
          },
          {
            "vendor": "Dell",
            "product": "G15 5530"
          },
          {
            "vendor": "Dell",
            "product": "Alienware 16 Area-51 AA16250"
          },
          {
            "vendor": "Dell",
            "product": "Alienware 16 Aurora AC16250"
          },
          {
            "vendor": "Dell",
            "product": "Alienware 16X Aurora AC16251"
          },
          {
            "vendor": "Dell",
            "product": "Alienware 18 Area-51 AA18250"
          },
          {
            "vendor": "Dell",
            "product": "Alienware Area-51 AAT2250"
          },
          {
            "vendor": "Dell",
            "product": "Alienware Aurora ACT1250"
          },
          {
            "vendor": "Dell",
            "product": "Alienware m15 R6"
          },
          {
            "vendor": "Dell",
            "product": "Alienware m15 R7"
          },
          {
            "vendor": "Dell",
            "product": "Alienware m16 R1"
          },
          {
            "vendor": "Dell",
            "product": "Alienware m16 R2"
          },
          {
            "vendor": "Dell",
            "product": "Alienware m18 R1"
          },
          {
            "vendor": "Dell",
            "product": "Alienware M18 R2"
          },
          {
            "vendor": "Dell",
            "product": "Alienware x14 R2"
          },
          {
            "vendor": "Dell",
            "product": "Alienware x16 R1"
          },
          {
            "vendor": "Dell",
            "product": "Alienware X16 R2"
          },
          {
            "vendor": "Dell",
            "product": "ChengMing 3900"
          },
          {
            "vendor": "Dell",
            "product": "ChengMing 3910/3911"
          },
          {
            "vendor": "Dell",
            "product": "Dell 14 DC14250"
          },
          {
            "vendor": "Dell",
            "product": "14 Plus 2-in-1 DB04250"
          },
          {
            "vendor": "Dell",
            "product": "14 Plus DB14250"
          },
          {
            "vendor": "Dell",
            "product": "15 DC15250"
          },
          {
            "vendor": "Dell",
            "product": "16 Plus 2-in-1 DB06250"
          },
          {
            "vendor": "Dell",
            "product": "16 Plus DB16250"
          },
          {
            "vendor": "Dell",
            "product": "24 All-in-One EC24250"
          },
          {
            "vendor": "Dell",
            "product": "27 All-in-One EC27250"
          },
          {
            "vendor": "Dell",
            "product": "G15 5510"
          },
          {
            "vendor": "Dell",
            "product": "G15 5511"
          },
          {
            "vendor": "Dell",
            "product": "G15 5520"
          },
          {
            "vendor": "Dell",
            "product": "G16 7620"
          },
          {
            "vendor": "Dell",
            "product": "G16 7630"
          },
          {
            "vendor": "Dell",
            "product": "Pro 13 Plus PB13250"
          },
          {
            "vendor": "Dell",
            "product": "Pro 13 Plus PB13255"
          },
          {
            "vendor": "Dell",
            "product": "Pro 13 Premium PA13250"
          },
          {
            "vendor": "Dell",
            "product": "Pro 14 Essential PV14250"
          },
          {
            "vendor": "Dell",
            "product": "Pro 14 PC14250"
          },
          {
            "vendor": "Dell",
            "product": "Pro 14 Plus PB14250"
          },
          {
            "vendor": "Dell",
            "product": "Pro 14 Plus PB14255"
          },
          {
            "vendor": "Dell",
            "product": "Pro 14 Premium PA14250"
          },
          {
            "vendor": "Dell",
            "product": "Pro 16 PC16250"
          },
          {
            "vendor": "Dell",
            "product": "Pro 16 Plus PB16250"
          },
          {
            "vendor": "Dell",
            "product": "Pro 16 Plus PB16255"
          },
          {
            "vendor": "Dell",
            "product": "Pro 24 All-In-One Plus QB24250 / Pro 24 All-In-One QC24250 / Pro 24 All-In-One QC24251"
          },
          {
            "vendor": "Dell",
            "product": "Pro Laptop PC14250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Laptop PC16250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Max 14 MC14250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Max 14 MC14255"
          },
          {
            "vendor": "Dell",
            "product": "Pro Max 16 MC16250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Max 16 MC16255"
          },
          {
            "vendor": "Dell",
            "product": "Pro Max Micro FCM2250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Max Slim FCS1250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Max Tower T2 FCT2250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Micro / QCM1255"
          },
          {
            "vendor": "Dell",
            "product": "Pro Micro Plus QBM1250 / Pro Micro QCM1250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Micro/Micro Plus QCM1250/QBM1250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Precision 7 T1"
          },
          {
            "vendor": "Dell",
            "product": "Pro Rugged 10 Tablets"
          },
          {
            "vendor": "Dell",
            "product": "Pro Rugged 12 Tablet"
          },
          {
            "vendor": "Dell",
            "product": "Pro Rugged 13 RA13250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Rugged 14 RB14250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Slim / QCS1255"
          },
          {
            "vendor": "Dell",
            "product": "Pro Slim Essential QVS1260"
          },
          {
            "vendor": "Dell",
            "product": "Pro Slim Plus QBS1250 / Pro Slim QCS1250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Slim Plus QBS1250/Pro Slim QCS1250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Tower / QCT1255"
          },
          {
            "vendor": "Dell",
            "product": "Pro Tower Essential QVT1260"
          },
          {
            "vendor": "Dell",
            "product": "Pro Tower Plus QBT1250 / Pro Tower QCT1250"
          },
          {
            "vendor": "Dell",
            "product": "Pro Tower Plus QBT1250/Pro Tower QCT1250"
          },
          {
            "vendor": "Dell",
            "product": "Slim ECS1250"
          },
          {
            "vendor": "Dell",
            "product": "Tower ECT1250"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 13 5330"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 14 5420"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 14 5430"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 14 5440"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 14 7430 2-in-1"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 14 7440 2-in-1"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 14 Plus 7420"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 14 Plus 7430"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 14 Plus 7440"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 15 3511"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 15 3530"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 16 5620"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 16 5630"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 16 5640"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 16 7630 2-in-1"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 16 7640 2-in-1"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 16 Plus 7620"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 16 Plus 7630"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 16 Plus 7640"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 24 5420 All-in-One"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 24 5430 All-in-One"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 27 7720 All-in-One"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 27 7730 All-in-One"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 3020 Desktop"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 3020 S"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 3030"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 3030S"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 5410 All-in-One"
          },
          {
            "vendor": "Dell",
            "product": "Inspiron 7710 All-in-One"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 3320"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 3340"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5320"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5330"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5340"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5350"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5421"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5430"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5430 Rugged Laptop"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5431"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5440"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5450"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5520"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5521"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5530"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5531"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5540"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 5550"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7030 Rugged Extreme"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7230 Rugged Extreme"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7320"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7320 Detachable"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7330"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7330 Rugged Laptop"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7340"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7350"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7420"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7430"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7440"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7450"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7520"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7530"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7640"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 7650"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 9330"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 9420"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 9430"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 9440 2-in-1"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 9450"
          },
          {
            "vendor": "Dell",
            "product": "Latitude 9520"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 3000 Micro / OptiPlex 3000 Small Form Factor / OptiPlex 3000 Tower"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 3000 Thin Client"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 3090 Ultra"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 5000 Micro / OptiPlex 5000 Small Form Factor / OptiPlex 5000 Tower"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 5090 Micro / OptiPlex 5090 Small Form Factor / OptiPlex 5090 Tower"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 5400 All-In-One"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 5490 AIO"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 7000 Micro / OptiPlex 7000 Small Form Factor / OptiPlex 7000 Tower / OptiPlex 7000 XE Micro"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 7000 OEM MT+"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 7090 Tower"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 7090 Ultra"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 7400 All-In-One"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex 7490 AIO"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex AIO 7420"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex All-in-One 7410"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex Micro 7010 / OptiPlex Micro Plus 7010"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex Micro 7020"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex SFF 7020"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex Small Form Factor 7010 / OptiPlex Small Form Factor Plus 7010"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex Tower 7010 / OptiPlex Tower Plus 7010"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex Tower 7020"
          },
          {
            "vendor": "Dell",
            "product": "OptiPlex XE4 SFF"
          },
          {
            "vendor": "Dell",
            "product": "PC14255"
          },
          {
            "vendor": "Dell",
            "product": "PC16255"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3260 XE Compact / Precision 3260 Compact"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3280 CFF"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3450"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3460 XE Small Form Factor / Precision 3460 Small Form Factor"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3470"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3480"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3490"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3560"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3561"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3570"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3571"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3580"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3581"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3590"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3591"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3650 MT"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3660"
          },
          {
            "vendor": "Dell",
            "product": "Precision 3680 Tower"
          },
          {
            "vendor": "Dell",
            "product": "Precision 5470"
          },
          {
            "vendor": "Dell",
            "product": "Precision 5480"
          },
          {
            "vendor": "Dell",
            "product": "Precision 5490"
          },
          {
            "vendor": "Dell",
            "product": "Precision 5560"
          },
          {
            "vendor": "Dell",
            "product": "Precision 5570"
          },
          {
            "vendor": "Dell",
            "product": "Precision 5680"
          },
          {
            "vendor": "Dell",
            "product": "Precision 5690"
          },
          {
            "vendor": "Dell",
            "product": "Precision 5770"
          },
          {
            "vendor": "Dell",
            "product": "Precision 5860 Tower"
          },
          {
            "vendor": "Dell",
            "product": "Precision 7560"
          },
          {
            "vendor": "Dell",
            "product": "Precision 7670"
          },
          {
            "vendor": "Dell",
            "product": "Precision 7680"
          },
          {
            "vendor": "Dell",
            "product": "Precision 7760"
          },
          {
            "vendor": "Dell",
            "product": "Precision 7770"
          },
          {
            "vendor": "Dell",
            "product": "Precision 7780"
          },
          {
            "vendor": "Dell",
            "product": "Precision 7875 Tower"
          },
          {
            "vendor": "Dell",
            "product": "Precision 7960 Tower"
          },
          {
            "vendor": "Dell",
            "product": "Precision Tower 7865"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 14 3420"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 14 3430"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 14 3440"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 15 3510"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 15 3520"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 15 3530"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 16 5630"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 16 5640"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 3020 Small Desktop"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 3020 Tower Desktop"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 3030"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 3030S"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 3910"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 5620"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 5890"
          },
          {
            "vendor": "Dell",
            "product": "Vostro 7620"
          },
          {
            "vendor": "Dell",
            "product": "XPS 13 9315"
          },
          {
            "vendor": "Dell",
            "product": "XPS 13 9340"
          },
          {
            "vendor": "Dell",
            "product": "XPS 13 9350"
          },
          {
            "vendor": "Dell",
            "product": "XPS 13 Plus 9320"
          },
          {
            "vendor": "Dell",
            "product": "XPS 14 (14 Premium) DA14250"
          },
          {
            "vendor": "Dell",
            "product": "XPS 14 9440"
          },
          {
            "vendor": "Dell",
            "product": "XPS 15 9510"
          },
          {
            "vendor": "Dell",
            "product": "XPS 15 9520"
          },
          {
            "vendor": "Dell",
            "product": "XPS 15 9530"
          },
          {
            "vendor": "Dell",
            "product": "XPS 16 (16 Premium) DA16250"
          },
          {
            "vendor": "Dell",
            "product": "XPS 16 9640"
          },
          {
            "vendor": "Dell",
            "product": "XPS 17 9720"
          },
          {
            "vendor": "Dell",
            "product": "XPS 17 9730"
          },
          {
            "vendor": "Dell",
            "product": "XPS 9320"
          }
        ],
        "affectedBlockCount": 230,
        "versionEntryCount": 230,
        "versionRangeCount": 230,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-305",
          "name": "Authentication Bypass by Primary Weakness",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.085
      },
      "nvd": {
        "published": "2026-07-03T09:16:36.937",
        "lastModified": "2026-07-07T02:16:29.577",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-35159",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The BIOS flow permits a protected operation without completing the authentication step required for that state.",
        "basis": [
          "CNA",
          "CWE-305"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000452197/dsa-2026-195",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 224,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 230,
        "affectedVersionEntryCount": 230
      }
    },
    {
      "cve_id": "CVE-2026-35198",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T18:48:58.937Z",
      "date_published": "2026-07-20T15:47:21.255Z",
      "date_updated": "2026-07-20T19:02:26.984Z",
      "publisher": "GitHub_M",
      "title": "HeyForm vulnerable to stored XSS via form field titles",
      "affected": {
        "vendors": [
          "heyform"
        ],
        "products": [
          {
            "vendor": "heyform",
            "product": "heyform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14366
      },
      "nvd": {
        "published": "2026-07-20T16:16:58.440",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-35198",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The heyform rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/heyform/heyform/security/advisories/GHSA-chmm-jqpm-3pwx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/heyform/heyform/commit/cc97d27a57ae400fec23abf5dcf6f9533c3b5db3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35210",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T18:48:58.937Z",
      "date_published": "2026-07-08T21:06:02.349Z",
      "date_updated": "2026-07-09T13:45:43.275Z",
      "publisher": "GitHub_M",
      "title": "OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection",
      "affected": {
        "vendors": [
          "OpenCTI-Platform"
        ],
        "products": [
          {
            "vendor": "OpenCTI-Platform",
            "product": "opencti"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17294
      },
      "nvd": {
        "published": "2026-07-08T21:16:48.487",
        "lastModified": "2026-07-13T14:46:34.827",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35210",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenCTI resolves an object selected by the caller without enforcing the object's permission and confidence restrictions.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-36fr-4m54-94mj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/OpenCTI-Platform/opencti/pull/14243",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/OpenCTI-Platform/opencti/commit/134531ddf5ecf741006b7f0870b7c36711b96540",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/OpenCTI-Platform/opencti/releases/tag/7.260326.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 610,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35211",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T18:48:58.937Z",
      "date_published": "2026-07-08T21:08:27.097Z",
      "date_updated": "2026-07-10T14:46:23.078Z",
      "publisher": "GitHub_M",
      "title": "OpenCTI: Elasticsearch Painless Script Injection via GraphQL `script` filter operator allows authenticated user to exfiltrate data and cause DoS",
      "affected": {
        "vendors": [
          "OpenCTI-Platform"
        ],
        "products": [
          {
            "vendor": "OpenCTI-Platform",
            "product": "opencti"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29738
      },
      "nvd": {
        "published": "2026-07-08T21:16:48.630",
        "lastModified": "2026-07-13T14:48:33.590",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35211",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "OpenCTI inserts attacker-controlled filter input into an Elasticsearch Painless script, allowing the filter to become executable script logic.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-qpp6-p693-rmm4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/OpenCTI-Platform/opencti/pull/15284",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/OpenCTI-Platform/opencti/commit/b134ccedf9e68386723cb42197f8e1d60c3bdbd9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/OpenCTI-Platform/opencti/releases/tag/7.260401.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35217",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T18:48:58.938Z",
      "date_published": "2026-07-20T16:39:49.102Z",
      "date_updated": "2026-07-20T17:53:52.495Z",
      "publisher": "GitHub_M",
      "title": "NanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an ASAN-Detectable Out-of-Bounds Read",
      "affected": {
        "vendors": [
          "nanomq"
        ],
        "products": [
          {
            "vendor": "nanomq",
            "product": "nanomq"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.0931
      },
      "nvd": {
        "published": "2026-07-20T17:17:06.980",
        "lastModified": "2026-07-23T15:52:06.097",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-35217",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NanoMQ reads the missing subscription-options byte from beyond a malformed MQTT SUBSCRIBE allocation before accepting the entry.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nanomq/nanomq/security/advisories/GHSA-w4xh-p384-w556",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1193,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T19:54:21.499Z",
      "date_published": "2026-07-29T07:05:57.508Z",
      "date_updated": "2026-07-29T14:27:45.179Z",
      "publisher": "CERTVDE",
      "title": "Out-of-bounds Write in CODESYS PROFINET Controller",
      "affected": {
        "vendors": [
          "CODESYS"
        ],
        "products": [
          {
            "vendor": "CODESYS",
            "product": "CODESYS PROFINET"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06848
      },
      "nvd": {
        "published": "2026-07-29T08:16:31.267",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-35226",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected parser writes beyond its destination buffer because attacker-controlled size or index data is not bounded.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-041/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35287",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T20:03:40.836Z",
      "date_published": "2026-07-21T21:32:46.042Z",
      "date_updated": "2026-07-23T15:19:50.586Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Application Testing Suite.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Testing Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23029
      },
      "nvd": {
        "published": "2026-07-21T22:17:01.020",
        "lastModified": "2026-07-24T18:48:33.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35287",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Testing Suite has an access-control failure in a named component, while the public CPU does not disclose the caller, object, or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35290",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-01T20:03:40.836Z",
      "date_published": "2026-07-21T21:32:46.594Z",
      "date_updated": "2026-07-23T15:19:37.663Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Application Testing Suite.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Testing Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38454
      },
      "nvd": {
        "published": "2026-07-21T22:17:01.140",
        "lastModified": "2026-07-24T18:48:59.123",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-35290",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Application Testing Suite exposes a takeover path to an unauthenticated TCP peer, but Oracle does not publish the endpoint, credential path, or omitted authentication decision.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html",
          "https://www.oracle.com/security-alerts/cpujul2026verbose.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July CPU confirms Application Testing Suite 13.3.0.1, unauthenticated TCP reachability, and takeover impact, while its published matrix omits the endpoint and failing authentication check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-02T19:21:11.804Z",
      "date_published": "2026-07-24T00:01:10.745Z",
      "date_updated": "2026-08-03T22:59:13.620Z",
      "publisher": "microsoft",
      "title": "Azure API Management (APIM) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure API Management (APIM)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00483,
        "percentile": 0.3906
      },
      "nvd": {
        "published": "2026-07-24T01:16:36.970",
        "lastModified": "2026-07-29T19:16:45.720",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-35425",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Azure API Management (APIM) permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35425",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35552",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-03T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-09T15:02:03.300Z",
      "publisher": "mitre",
      "title": "In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, ...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19838
      },
      "nvd": {
        "published": "2026-07-08T22:17:13.980",
        "lastModified": "2026-07-09T17:02:37.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-35552",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An authenticated ordinary user can call the license-deactivation API because the endpoint omits its privileged-user authorization check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://caxperts.com",
          "host": "caxperts.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/caxperts/security-advisories/blob/main/2026/CAXSEC-2026-001_portal.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35590",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-03T20:09:02.828Z",
      "date_published": "2026-07-20T16:23:33.905Z",
      "date_updated": "2026-07-20T19:03:42.733Z",
      "publisher": "GitHub_M",
      "title": "Possible out-of-bounds read leading to crash when decoding well-crafted EXIF metadata",
      "affected": {
        "vendors": [
          "libvips"
        ],
        "products": [
          {
            "vendor": "libvips",
            "product": "libvips"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02115
      },
      "nvd": {
        "published": "2026-07-20T17:17:07.133",
        "lastModified": "2026-07-23T15:57:13.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-35590",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The EXIF decoder passes an unchecked tag-group range to libexif, which can then dereference invalid state and crash.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": "The description names a range-check failure and possible null dereference, while the structured CWE-122 says heap buffer overflow."
      },
      "references": [
        {
          "url": "https://github.com/libvips/libvips/security/advisories/GHSA-jmwm-wc68-mhwm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/libvips/libvips/pull/4972",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/libvips/libvips/commit/91ebd4d35341a8353ea490392d556d582e4b846f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 312,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35591",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-03T21:25:12.161Z",
      "date_published": "2026-07-20T16:24:50.831Z",
      "date_updated": "2026-07-20T17:44:01.158Z",
      "publisher": "GitHub_M",
      "title": "Possible heap-based buffer overflow when decoding TIFF image containing well-crafted tile",
      "affected": {
        "vendors": [
          "libvips"
        ],
        "products": [
          {
            "vendor": "libvips",
            "product": "libvips"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03173
      },
      "nvd": {
        "published": "2026-07-20T17:17:07.277",
        "lastModified": "2026-07-23T15:57:13.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-35591",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The libvips path writes attacker-influenced data beyond an allocated heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/libvips/libvips/security/advisories/GHSA-523x-vhfw-6r76",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/libvips/libvips/pull/4973",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-35847",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T17:34:56.183Z",
      "publisher": "mitre",
      "title": "An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00367,
        "percentile": 0.29428
      },
      "nvd": {
        "published": "2026-07-30T21:17:15.057",
        "lastModified": "2026-07-31T18:17:14.613",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-35847",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "In the affected component, attacker-controlled input reaches an operating-system command without shell-context neutralization.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/freedom2132/CVE/tree/main",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36027",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-08T20:24:22.583Z",
      "publisher": "mitre",
      "title": "An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via the USB debugging (ADB) and Android Debug Bridge components",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1313",
          "name": "Hardware Allows Activation of Test or Debug Logic at Runtime",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25672
      },
      "nvd": {
        "published": "2026-07-08T20:16:48.817",
        "lastModified": "2026-07-10T18:48:55.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-36027",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component in CVE-2026-36027 exposes a security-sensitive hardware, debug, boot, or encrypted-data boundary to a physically proximate caller without the required physical-presence or device-state restriction.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-1313"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.com",
          "host": "code.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://code27.com",
          "host": "code27.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/redr0nin/Code-27-Companion-Hub-Exploits",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36028",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-09T14:53:24.816Z",
      "publisher": "mitre",
      "title": "A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.1475
      },
      "nvd": {
        "published": "2026-07-08T20:16:48.937",
        "lastModified": "2026-07-09T17:02:37.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-36028",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A factory-reset path is available from the physical interface without enforcing the kiosk authentication restrictions applied to normal paths.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.com",
          "host": "code.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/redr0nin/Code-27-Companion-Hub-Exploits",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://companion.com",
          "host": "companion.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 159,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36035",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-15T14:12:29.134Z",
      "publisher": "mitre",
      "title": "Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.2158
      },
      "nvd": {
        "published": "2026-07-14T23:17:29.730",
        "lastModified": "2026-07-15T20:58:48.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-36035",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The license-deactivation endpoint lets a low-privileged authenticated caller remove the server license without the required administrative authorization.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://caxperts.com",
          "host": "caxperts.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://universalplantviewer.com",
          "host": "universalplantviewer.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://medium.com/@hacker.dan/hello-world-first-post-first-cve-6671b82e2b71",
          "host": "medium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36162",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-07T00:00:00.000Z",
      "date_updated": "2026-07-08T13:36:22.536Z",
      "publisher": "mitre",
      "title": "An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03897
      },
      "nvd": {
        "published": "2026-07-07T23:16:54.410",
        "lastModified": "2026-07-09T17:02:37.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-36162",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LiquidFiles stores the Upload File Shares Name value and renders it without sufficient HTML escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.liquidfiles.com/release_notes/version_4-2-x.html",
          "host": "docs.liquidfiles.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://securing.pl/en/bypassing-csp-to-exploit-stored-xss-in-liquidfiles/",
          "host": "securing.pl",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36163",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-07T00:00:00.000Z",
      "date_updated": "2026-07-09T14:43:18.365Z",
      "publisher": "mitre",
      "title": "An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03898
      },
      "nvd": {
        "published": "2026-07-07T23:16:54.543",
        "lastModified": "2026-07-09T17:02:37.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-36163",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LiquidFiles serves an uploaded HTML file in an execution context where its script runs in the application origin.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.liquidfiles.com/release_notes/version_4-2-x.html",
          "host": "docs.liquidfiles.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://securing.pl/en/bypassing-csp-to-exploit-stored-xss-in-liquidfiles/",
          "host": "securing.pl",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36214",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-15T14:40:25.525Z",
      "publisher": "mitre",
      "title": "osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaS...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25499
      },
      "nvd": {
        "published": "2026-07-14T17:16:46.870",
        "lastModified": "2026-07-15T20:58:48.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-36214",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "osTicket stores tooltip content that survives insufficient sanitization and is interpreted as executable HTML in a Bootstrap tooltip.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://osticket.com/",
          "host": "osticket.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://enhancesoft.com/",
          "host": "enhancesoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/WesWrench/CVE-2026-36214",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/osTicket/osTicket/commit/5afdf5450ff5c7d218447014b7abbb5f1e6dd42f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/osTicket/osTicket/releases/tag/v1.18.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/osTicket/osTicket/releases/tag/v1.17.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 270,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-17T13:32:35.354Z",
      "publisher": "mitre",
      "title": "An issue in OPSWAT AppRemover Driver (ardrv.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00422,
        "percentile": 0.34778
      },
      "nvd": {
        "published": "2026-07-16T21:17:20.450",
        "lastModified": "2026-07-17T18:47:13.683",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-36425",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Any local user can open the device and send process termination requests without privilege validation.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.virustotal.com/gui/file/2248347b2ec49f07268a44816ebb6265677093ec277f825de1a76700ab25e3bc",
          "host": "www.virustotal.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.virustotal.com/gui/file/07c5209bf83065fe760f4fee4ed2308b0c523671f68ca73a3854c2c8c28c0541",
          "host": "www.virustotal.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.opswat.com/products/oesis-framework/application-removal",
          "host": "www.opswat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/redteamfortress/CVE-2026-36425",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36590",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-16T19:00:21.614Z",
      "publisher": "mitre",
      "title": "An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-772",
          "name": "Missing Release of Resource after Effective Lifetime",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00401,
        "percentile": 0.32872
      },
      "nvd": {
        "published": "2026-07-15T22:16:46.947",
        "lastModified": "2026-07-16T19:58:33.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-36590",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The NanoMQ record attributes the nni_qos_db_set denial of service to unreleased memory but does not identify the allocation or missing release path.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-772"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MoXie25/NanoMQ-Memory-Leak-Research.git",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://github.com/MoXie25/NanoMQ-Memory-Leak-Research/blob/main/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 143,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36669",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-20T18:09:37.039Z",
      "publisher": "mitre",
      "title": "An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00563,
        "percentile": 0.43638
      },
      "nvd": {
        "published": "2026-07-17T20:17:16.293",
        "lastModified": "2026-07-23T18:28:20.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-36669",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path accepts attacker-controlled file content or names without enforcing the intended storage and executable-content boundary.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.fengoffice.com/",
          "host": "www.fengoffice.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/firstlax6t/CVE-2026-36669-FengOffice",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36909",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-01T00:00:00.000Z",
      "date_updated": "2026-07-02T14:17:35.976Z",
      "publisher": "mitre",
      "title": "A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02153
      },
      "nvd": {
        "published": "2026-07-01T22:16:48.113",
        "lastModified": "2026-07-02T17:42:23.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-36909",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted input reaches a path that dereferences a null pointer instead of rejecting the invalid state.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Aleksoid1978/MPC-BE/issues/1062",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/axiomatic-systems/Bento4/issues/965",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36910",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-01T00:00:00.000Z",
      "date_updated": "2026-07-02T14:38:37.567Z",
      "publisher": "mitre",
      "title": "An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01654
      },
      "nvd": {
        "published": "2026-07-01T22:16:48.597",
        "lastModified": "2026-07-02T17:42:23.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-36910",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A crafted MP4 reaches an invalid memory access in BaseSplitterFile::Read, but the record does not disclose whether the cause is a bound, pointer, or lifetime error.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/axiomatic-systems/Bento4/issues/873",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/Aleksoid1978/MPC-BE/issues/1062",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36911",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-01T00:00:00.000Z",
      "date_updated": "2026-07-02T14:40:28.915Z",
      "publisher": "mitre",
      "title": "A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-369",
          "name": "Divide By Zero",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00111,
        "percentile": 0.01521
      },
      "nvd": {
        "published": "2026-07-01T22:16:48.703",
        "lastModified": "2026-07-02T17:42:23.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-36911",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted MP4 drives a zero divisor in CStreamSwitcherOutputPin::DecideBufferSize.",
        "basis": [
          "CNA",
          "CWE-369"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Aleksoid1978/MPC-BE/issues/1062",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 212,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-36912",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-01T00:00:00.000Z",
      "date_updated": "2026-07-02T13:02:22.870Z",
      "publisher": "mitre",
      "title": "A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26969
      },
      "nvd": {
        "published": "2026-07-01T22:16:48.827",
        "lastModified": "2026-07-02T17:42:23.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-36912",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can cause a null pointer to be dereferenced.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/axiomatic-systems/Bento4/issues/511",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/Aleksoid1978/MPC-BE/issues/1062",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-37270",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-07T00:00:00.000Z",
      "date_updated": "2026-07-09T14:37:59.925Z",
      "publisher": "mitre",
      "title": "Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00374,
        "percentile": 0.30179
      },
      "nvd": {
        "published": "2026-07-07T23:16:54.657",
        "lastModified": "2026-07-10T18:48:55.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-37270",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The firmware combines improper password validation with credentials hard-coded into the product.",
        "basis": [
          "CNA record",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/EmbdCDACHyd/CVE/blob/main/CVE-2026-37270/CVE-2026-37270.pdf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/EmbdCDACHyd/CVE/tree/main/CVE-2026-37270",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-37271",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-07T00:00:00.000Z",
      "date_updated": "2026-07-09T14:43:11.606Z",
      "publisher": "mitre",
      "title": "Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00373,
        "percentile": 0.30024
      },
      "nvd": {
        "published": "2026-07-07T23:16:54.773",
        "lastModified": "2026-07-10T18:48:55.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-37271",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The smartwatch accepts replayed BLE GATT write packets without binding them to a fresh authenticated session.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/EmbdCDACHyd/CVE/blob/main/CVE-2026-37271/CVE-2026-37271.pdf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/EmbdCDACHyd/CVE/tree/main/CVE-2026-37271",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38057",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T08:25:37.731Z",
      "date_published": "2026-07-10T14:11:15.829Z",
      "date_updated": "2026-07-10T17:00:34.681Z",
      "publisher": "icscert",
      "title": "ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery",
      "affected": {
        "vendors": [
          "ST Engineering iDirect"
        ],
        "products": [
          {
            "vendor": "ST Engineering iDirect",
            "product": "Evolution iQ‑Series terminals"
          },
          {
            "vendor": "ST Engineering iDirect",
            "product": "3315-Series"
          },
          {
            "vendor": "ST Engineering iDirect",
            "product": "9-Series Terminals"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13336
      },
      "nvd": {
        "published": "2026-07-10T15:16:39.397",
        "lastModified": "2026-07-10T17:16:56.873",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38057",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The reboot API relies only on a session cookie without SameSite protection and accepts a cross-site POST without a CSRF token.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://support.idirect.net/s/login",
          "host": "support.idirect.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-01.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 494,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-38059",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T08:25:37.731Z",
      "date_published": "2026-07-10T14:11:42.152Z",
      "date_updated": "2026-07-10T17:00:27.518Z",
      "publisher": "icscert",
      "title": "ST Engineering iDirect iQ-Series Terminals Missing authentication for critical function",
      "affected": {
        "vendors": [
          "ST Engineering iDirect"
        ],
        "products": [
          {
            "vendor": "ST Engineering iDirect",
            "product": "Evolution iQ‑Series terminals"
          },
          {
            "vendor": "ST Engineering iDirect",
            "product": "3315-Series"
          },
          {
            "vendor": "ST Engineering iDirect",
            "product": "9-Series Terminals"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00431,
        "percentile": 0.35464
      },
      "nvd": {
        "published": "2026-07-10T15:16:39.563",
        "lastModified": "2026-07-10T17:16:57.000",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38059",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The iQ200 exposes identity endpoints without authentication, returning device and satellite-authentication identifiers to any reachable client.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://support.idirect.net/s/login",
          "host": "support.idirect.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-01.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 471,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-38076",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T18:14:33.083Z",
      "publisher": "mitre",
      "title": "An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35518
      },
      "nvd": {
        "published": "2026-07-09T22:17:03.983",
        "lastModified": "2026-07-10T19:17:23.080",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38076",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An arithmetic operation can wrap before the result is used for a memory size or offset, invalidating the later bounds assumption.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "http://artifex.com",
          "host": "artifex.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/ArtifexSoftware/jbig2dec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/dkjsone/c237b83ffa9ebd7028b5db7f410fcf78",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38142",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-01T00:00:00.000Z",
      "date_updated": "2026-07-01T18:48:02.280Z",
      "publisher": "mitre",
      "title": "An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00685,
        "percentile": 0.49058
      },
      "nvd": {
        "published": "2026-07-01T19:16:51.757",
        "lastModified": "2026-07-02T18:42:02.063",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38142",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The fast_setting_internet_set endpoint incorporates the mac parameter into a system command without neutralizing command syntax.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/longqx223/Tenda-ac-18-V15.03.05.05-/blob/main/Tenda%20AC18%20Unauthenticated%20Second-Order%20OS%20Command%20Injection%20in%20goformfast_setting_internet_set.pdf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-17T13:35:47.954Z",
      "publisher": "mitre",
      "title": "A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27392
      },
      "nvd": {
        "published": "2026-07-16T21:17:20.567",
        "lastModified": "2026-07-17T18:47:17.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38158",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The n/a data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/youseries/ureport",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/musesix/cve/blob/main/ureport_sqli/ureport.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 182,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38450",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-15T14:25:45.034Z",
      "publisher": "mitre",
      "title": "An issue in Aetopia Digital Asset Management DAM v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00785,
        "percentile": 0.52537
      },
      "nvd": {
        "published": "2026-07-14T22:16:52.810",
        "lastModified": "2026-07-15T20:58:48.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38450",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Add/Update Project function treats attacker-controlled name and description values as executable code.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://eslam3kl.gitbook.io",
          "host": "eslam3kl.gitbook.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.aetopia.com/solutions/industry/enterprise-dam",
          "host": "www.aetopia.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://eslam3kl.gitbook.io/blog/web-application-findings/cve-2026-38450-aetopia-dam-server-side-template-injection",
          "host": "eslam3kl.gitbook.io",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38708",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-08-03T19:28:13.940Z",
      "publisher": "mitre",
      "title": "TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.setclock interfa...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02619,
        "percentile": 0.83936
      },
      "nvd": {
        "published": "2026-07-31T21:17:30.713",
        "lastModified": "2026-08-03T20:17:23.190",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38708",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.setclock interface.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cudy.com/pages/security-advisory/cudy-sa-26-7-aihgtk",
          "host": "www.cudy.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38709",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T11:41:41.617Z",
      "publisher": "mitre",
      "title": "TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. ...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0267,
        "percentile": 0.84277
      },
      "nvd": {
        "published": "2026-07-30T22:16:54.970",
        "lastModified": "2026-07-31T12:16:49.683",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38709",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The net.set_wan interface inserts crafted input into a root shell command without command-context separation.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cudy.com/pages/security-advisory/cudy-sa-26-7-jezzy-4",
          "host": "www.cudy.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38710",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-08-03T13:38:13.181Z",
      "publisher": "mitre",
      "title": "TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setclock interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02546,
        "percentile": 0.83441
      },
      "nvd": {
        "published": "2026-07-31T21:17:30.830",
        "lastModified": "2026-08-03T15:16:19.550",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38710",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected handler places caller-controlled data in an operating-system command without safe argument separation.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cudy.com/pages/security-advisory/cudy-sa-26-7-vufm-1-e",
          "host": "www.cudy.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38711",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-08-03T19:25:49.252Z",
      "publisher": "mitre",
      "title": "TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.upgrade_check in...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02619,
        "percentile": 0.83936
      },
      "nvd": {
        "published": "2026-07-31T20:16:50.190",
        "lastModified": "2026-08-03T20:17:23.350",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38711",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The router places the system.upgrade_check value in a shell command without complete command-language separation.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cudy.com/pages/security-advisory/cudy-sa-26-7-7-kjw-1-b",
          "host": "www.cudy.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 340,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-08-03T19:28:56.352Z",
      "publisher": "mitre",
      "title": "TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the ipsec_conn interface. T...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02619,
        "percentile": 0.83935
      },
      "nvd": {
        "published": "2026-07-31T21:17:30.937",
        "lastModified": "2026-08-03T20:17:23.520",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38713",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ipsec_conn interface places crafted remote input into a root shell command without separating data from command syntax.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cudy.com/pages/security-advisory/cudy-sa-26-7-ehixbe",
          "host": "www.cudy.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38752",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-20T15:12:38.662Z",
      "publisher": "mitre",
      "title": "A stack overflow in the evaluate() function (editors/awk.",
      "affected": {
        "vendors": [
          "BusyBox"
        ],
        "products": [
          {
            "vendor": "BusyBox",
            "product": "BusyBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 4.6,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10926
      },
      "nvd": {
        "published": "2026-07-15T22:16:47.130",
        "lastModified": "2026-07-20T16:16:58.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-38752",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BusyBox awk evaluate recursively processes a crafted script without an effective recursion limit, exhausting the process stack.",
        "basis": [
          "CNA",
          "CWE-121",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://busybox.net/",
          "host": "busybox.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://lists.busybox.net/pipermail/busybox/2026-June/092351.html",
          "host": "lists.busybox.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 172,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38753",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-20T15:33:13.060Z",
      "publisher": "mitre",
      "title": "A use-after-free in the awk_sub() function (editors/awk.",
      "affected": {
        "vendors": [
          "BusyBox"
        ],
        "products": [
          {
            "vendor": "BusyBox",
            "product": "BusyBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04287
      },
      "nvd": {
        "published": "2026-07-15T21:16:36.677",
        "lastModified": "2026-07-20T16:16:58.763",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-38753",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "awk_sub retains or dereferences storage after it has been freed while processing a crafted AWK program.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://busybox.net",
          "host": "busybox.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://lists.busybox.net/pipermail/busybox/2026-June/092352.html",
          "host": "lists.busybox.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 165,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-22T14:42:57.143Z",
      "publisher": "mitre",
      "title": "A heap overflow in the ifsbreakup() function (shell/ash.",
      "affected": {
        "vendors": [
          "BusyBox"
        ],
        "products": [
          {
            "vendor": "BusyBox",
            "product": "BusyBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.4000000000000004,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14577
      },
      "nvd": {
        "published": "2026-07-15T22:16:47.233",
        "lastModified": "2026-07-22T15:16:54.520",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-38754",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BusyBox ifsbreakup processes crafted shell input beyond a heap buffer boundary.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://busybox.net",
          "host": "busybox.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://lists.busybox.net/pipermail/busybox/2026-June/092353.html",
          "host": "lists.busybox.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://lists.busybox.net/pipermail/busybox/2026-June/092360.html",
          "host": "lists.busybox.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-20T15:30:59.964Z",
      "publisher": "mitre",
      "title": "A heap overflow in the evalcommand() function (shell/ash.",
      "affected": {
        "vendors": [
          "BusyBox"
        ],
        "products": [
          {
            "vendor": "BusyBox",
            "product": "BusyBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 4.6,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10926
      },
      "nvd": {
        "published": "2026-07-15T22:16:47.340",
        "lastModified": "2026-07-20T16:16:59.113",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-38755",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "BusyBox evalcommand processes crafted shell input in a way that overruns a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": "CWE-674 is also listed, but the embedded narrative does not establish an uncontrolled-recursion path."
      },
      "references": [
        {
          "url": "https://busybox.net",
          "host": "busybox.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://lists.busybox.net/pipermail/busybox/2026-June/092354.html",
          "host": "lists.busybox.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 161,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-22T00:00:00.000Z",
      "date_updated": "2026-07-24T19:54:02.771Z",
      "publisher": "mitre",
      "title": "An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-703",
          "name": "Improper Check or Handling of Exceptional Conditions",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07334
      },
      "nvd": {
        "published": "2026-07-22T23:16:35.143",
        "lastModified": "2026-07-24T20:17:04.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38763",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component path lets attacker-controlled work, memory, recursion, or retained resources grow without an effective bound or release condition.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-404",
          "CWE-703"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/D7EAD",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://dreadsec.co/p/protogent-kernel-anti-virus-multiple-vulnerabilities.html",
          "host": "dreadsec.co",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-23T00:00:00.000Z",
      "date_updated": "2026-07-24T19:33:59.255Z",
      "publisher": "mitre",
      "title": "An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-782",
          "name": "Exposed IOCTL with Insufficient Access Control",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00185,
        "percentile": 0.08348
      },
      "nvd": {
        "published": "2026-07-23T21:17:04.077",
        "lastModified": "2026-07-30T19:32:25.133",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38764",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pgsecdl.sys driver exposes privileged I/O control functionality to a local caller without sufficient access control.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-782"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/D7EAD",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://dreadsec.co/p/protogent-kernel-anti-virus-multiple-vulnerabilities.html",
          "host": "dreadsec.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://dreadsec.co/p/protogent-kernel-anti-virus-multiple-vulnerabilities.html#targets",
          "host": "dreadsec.co",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 140,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-22T00:00:00.000Z",
      "date_updated": "2026-07-24T19:47:24.642Z",
      "publisher": "mitre",
      "title": "An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-782",
          "name": "Exposed IOCTL with Insufficient Access Control",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06773
      },
      "nvd": {
        "published": "2026-07-22T23:16:35.390",
        "lastModified": "2026-07-24T20:17:04.950",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38765",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that the affected component permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-782"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/D7EAD",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://dreadsec.co/p/protogent-kernel-anti-virus-multiple-vulnerabilities.html",
          "host": "dreadsec.co",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 140,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38766",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-22T00:00:00.000Z",
      "date_updated": "2026-07-24T19:51:55.060Z",
      "publisher": "mitre",
      "title": "An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-782",
          "name": "Exposed IOCTL with Insufficient Access Control",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06772
      },
      "nvd": {
        "published": "2026-07-22T23:16:35.537",
        "lastModified": "2026-07-24T20:17:05.120",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38766",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component in CVE-2026-38766 fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-269",
          "CWE-782"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/D7EAD",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://dreadsec.co/p/protogent-kernel-anti-virus-multiple-vulnerabilities.html",
          "host": "dreadsec.co",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 133,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38891",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-01T00:00:00.000Z",
      "date_updated": "2026-07-02T13:03:26.870Z",
      "publisher": "mitre",
      "title": "An improper input validation in the gazebo_ros_diff_drive.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26969
      },
      "nvd": {
        "published": "2026-07-01T22:16:48.950",
        "lastModified": "2026-07-02T17:42:23.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38891",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says a crafted Twist message is insufficiently validated before denial of service but gives no parser, state, resource, or memory cause.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/REYu6/ROS-vul/blob/main/Gazebo%20CVE/gazebo_ros_diff_drive.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/REYu6/ROS-vul/blob/main/Gazebo%20CVE/260328211736.mp4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38968",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-02T00:00:00.000Z",
      "date_updated": "2026-07-06T17:16:49.092Z",
      "publisher": "mitre",
      "title": "ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh aut...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-341",
          "name": "Predictable from Observable State",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30665
      },
      "nvd": {
        "published": "2026-07-02T21:16:55.170",
        "lastModified": "2026-07-08T18:39:19.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-38968",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ntopng seeds session identifiers with observable time and weak pseudorandomness, making new cookies predictable or colliding under controlled timing.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-341"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ntop/ntopng/commit/179a346ceb6239fd36128ccca3efa8f9ea61eeb5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/ntop/ntopng/commit/14e22497233dc7d31d19dccb74b13bb073d16c2c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 343,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38969",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-02T00:00:00.000Z",
      "date_rejected": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-14T16:58:35.765Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-38970",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-02T00:00:00.000Z",
      "date_updated": "2026-07-06T14:44:12.877Z",
      "publisher": "mitre",
      "title": "pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go. The parser descends recursively through nested PDF objects, including arrays, via ParseObjectContext() and parseArray() witho...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00451,
        "percentile": 0.36983
      },
      "nvd": {
        "published": "2026-07-02T21:16:56.150",
        "lastModified": "2026-07-06T19:47:25.753",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38970",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The PDF parser recursively descends nested arrays and objects without a maximum nesting depth.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pdfcpu/pdfcpu/blob/a181c19acb322d6b93a1bbda9385a864a9ad6efe/pkg/pdfcpu/model/parse.go#L325-L366",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/pdfcpu/pdfcpu/blob/a181c19acb322d6b93a1bbda9385a864a9ad6efe/pkg/pdfcpu/model/parse.go#L942-L970",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/pdfcpu/pdfcpu",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38971",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-02T00:00:00.000Z",
      "date_updated": "2026-07-09T14:06:35.563Z",
      "publisher": "mitre",
      "title": "ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control().",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0051,
        "percentile": 0.4065
      },
      "nvd": {
        "published": "2026-07-02T21:16:56.253",
        "lastModified": "2026-07-09T15:16:33.110",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-38971",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GCS_MAVLINK handle_serial_control reads beyond its input buffer while handling serial-control data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ArduPilot/ardupilot",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://github.com/ArduPilot/ardupilot/pull/32587",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch"
          ]
        },
        {
          "url": "https://github.com/ArduPilot/ardupilot/issues/32524",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit"
          ]
        },
        {
          "url": "https://gist.github.com/quart27219/6bfcc615f89fb493d02aad480704593b",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 167,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38972",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-02T00:00:00.000Z",
      "date_updated": "2026-07-06T14:42:52.329Z",
      "publisher": "mitre",
      "title": "Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Notepad3.c. The application calls LoadLibrary(L\"MSFTEDIT.DLL\") with a bare DLL name, which allows a local attacker to pl...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07851
      },
      "nvd": {
        "published": "2026-07-02T21:16:56.353",
        "lastModified": "2026-07-08T18:49:50.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-38972",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Notepad3 calls LoadLibrary with the bare name MSFTEDIT.DLL, allowing Windows search-order resolution to select an attacker-controlled DLL.",
        "basis": [
          "CNA",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rizonesoft/Notepad3/pull/5606",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch"
          ]
        },
        {
          "url": "https://github.com/rizonesoft/Notepad3/issues/5605",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/rizonesoft/Notepad3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 432,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38973",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-06T00:00:00.000Z",
      "date_updated": "2026-07-09T14:57:12.423Z",
      "publisher": "mitre",
      "title": "mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find_method().",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05419
      },
      "nvd": {
        "published": "2026-07-06T22:16:48.767",
        "lastModified": "2026-07-09T16:16:40.723",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38973",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find_method().",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mrubyc/mrubyc/issues/279%2C",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/mrubyc/mrubyc/commit/f83a8b67ca1c7c62ac0dd548a363d79f767c4e30",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/mrubyc/mrubyc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38974",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-16T18:26:43.162Z",
      "publisher": "mitre",
      "title": "Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.0939
      },
      "nvd": {
        "published": "2026-07-15T22:16:47.443",
        "lastModified": "2026-07-16T19:16:45.283",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38974",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jelmer/dulwich/pull/2123",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/jelmer/dulwich",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38976",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-06T00:00:00.000Z",
      "date_updated": "2026-07-07T16:14:19.295Z",
      "publisher": "mitre",
      "title": "mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level super.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00446,
        "percentile": 0.36637
      },
      "nvd": {
        "published": "2026-07-06T22:16:48.900",
        "lastModified": "2026-07-07T17:16:36.247",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38976",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path dereferences a NULL pointer because the required validity check is missing or applied to the wrong value.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mrubyc/mrubyc/issues/276",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/hayat01sh1da/mrubyc/commit/c4aa2a06bfdd13a0f1ae5165c5760a2530314a42",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/mrubyc/mrubyc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 157,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-38979",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-06T00:00:00.000Z",
      "date_updated": "2026-07-09T15:00:53.847Z",
      "publisher": "mitre",
      "title": "ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTTP response path initializes an empty header list, forwards handler-added headers verbatim, and f...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1021",
          "name": "Improper Restriction of Rendered UI Layers or Frames",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.09978
      },
      "nvd": {
        "published": "2026-07-06T22:16:49.010",
        "lastModified": "2026-07-09T16:16:40.873",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-38979",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ajenti response paths omit frame-ancestor protections, allowing the login and administration interface to be embedded in an attacker-controlled page.",
        "basis": [
          "CNA",
          "CWE-1021"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ajenti/ajenti/commit/e54e83888fc7cb10061a18b04c1a7e3100d77f03",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/ajenti/ajenti",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 407,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39042",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-13T00:00:00.000Z",
      "date_updated": "2026-07-14T16:27:12.476Z",
      "publisher": "mitre",
      "title": "An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00409,
        "percentile": 0.33674
      },
      "nvd": {
        "published": "2026-07-13T22:16:46.247",
        "lastModified": "2026-07-15T20:27:37.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-39042",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled arithmetic can overflow before its result is used by the affected memory or parser operation.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mikrotik.com/supportsec",
          "host": "mikrotik.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://zakpatrik.cz/blog/finding-an-integer-overflow-in-mikrotik-routeros-core-ipc-library",
          "host": "zakpatrik.cz",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39155",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-23T00:00:00.000Z",
      "date_updated": "2026-07-24T19:35:57.930Z",
      "publisher": "mitre",
      "title": "Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream valid...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04678
      },
      "nvd": {
        "published": "2026-07-23T21:17:04.210",
        "lastModified": "2026-07-30T19:32:25.133",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-39155",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mod-onlinesign computes the next NSEC owner incorrectly and publishes an authenticated denial interval that covers legitimate names.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.knot-dns.cz/2026-04-01-version-3410.html",
          "host": "www.knot-dns.cz",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.knot-dns.cz/2026-04-02-version-354.html",
          "host": "www.knot-dns.cz",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 383,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39178",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-09T14:28:33.479Z",
      "publisher": "mitre",
      "title": "A SQL injection vulnerability in SOGo before 5.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05344
      },
      "nvd": {
        "published": "2026-07-08T22:17:14.103",
        "lastModified": "2026-07-09T17:02:37.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-39178",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Alinto/sogo/commit/1f7e5d2b2c2047c44a6a9e05f73c36491cb96d21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.sogo.nu/news/2026/sogo-v5127-released.html",
          "host": "www.sogo.nu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 173,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39179",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-09T14:26:08.890Z",
      "publisher": "mitre",
      "title": "A SQL injection vulnerability in SOGo before 5.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05343
      },
      "nvd": {
        "published": "2026-07-08T22:17:14.230",
        "lastModified": "2026-07-09T17:02:37.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-39179",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The newPassword value reaches an SQL statement without separating attacker data from SQL syntax.",
        "basis": [
          "CNA record",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Alinto/sogo/commit/1f7e5d2b2c2047c44a6a9e05f73c36491cb96d21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.sogo.nu/news/2026/sogo-v5127-released.html",
          "host": "www.sogo.nu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 182,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T15:25:09.237Z",
      "publisher": "mitre",
      "title": "decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === 'link'), the x.linkname field from the archive is passed ...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25374
      },
      "nvd": {
        "published": "2026-07-09T22:17:04.113",
        "lastModified": "2026-07-13T12:57:34.913",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-39243",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CVE-2026-39243 follows an attacker-influenced symbolic link into a filesystem object outside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kevva/decompress",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://www.npmjs.com/package/decompress",
          "host": "www.npmjs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://github.com/kevva/decompress/issues/113",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 679,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39244",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-10T00:00:00.000Z",
      "date_updated": "2026-07-10T18:10:22.926Z",
      "publisher": "mitre",
      "title": "adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntry.js line 103, Buffer.alloc(_centralHeader.size) allocates memory based on the declared uncompre...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00426,
        "percentile": 0.35079
      },
      "nvd": {
        "published": "2026-07-10T17:16:57.123",
        "lastModified": "2026-07-10T19:17:23.250",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-39244",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "adm-zip allocates the central-directory declared uncompressed size before checking it against actual data or an upper bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cthackers/adm-zip",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.npmjs.com/package/adm-zip",
          "host": "www.npmjs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cthackers/adm-zip/issues/568",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 985,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39245",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T15:27:09.755Z",
      "publisher": "mitre",
      "title": "decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDir function (index.js line 29) and the extraction path validation (index.js line 106) use String....",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26632
      },
      "nvd": {
        "published": "2026-07-09T22:17:04.247",
        "lastModified": "2026-07-13T12:56:55.153",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-39245",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "decompress checks path containment with a string prefix that lacks a separator boundary, so a sibling directory and an attacker-created symlink can escape the extraction root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kevva/decompress",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://www.npmjs.com/package/decompress",
          "host": "www.npmjs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-12265",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "US Government Resource"
          ]
        },
        {
          "url": "https://github.com/kevva/decompress/issues/115",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 889,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T17:27:46.481Z",
      "publisher": "mitre",
      "title": "decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.linkname field from the archive is passed directly to fs.symlink() without validation (index...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00556,
        "percentile": 0.43243
      },
      "nvd": {
        "published": "2026-07-09T22:17:04.370",
        "lastModified": "2026-07-13T12:44:41.167",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-39246",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Archive extraction creates an attacker-supplied symbolic link without constraining its target to the extraction namespace.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kevva/decompress",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://www.npmjs.com/package/decompress",
          "host": "www.npmjs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://github.com/kevva/decompress/issues/114",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T21:29:17.349Z",
      "date_published": "2026-07-16T23:55:18.974Z",
      "date_updated": "2026-07-17T13:53:52.826Z",
      "publisher": "GitHub_M",
      "title": "Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name",
      "affected": {
        "vendors": [
          "wazuh"
        ],
        "products": [
          {
            "vendor": "wazuh",
            "product": "wazuh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21159
      },
      "nvd": {
        "published": "2026-07-17T00:16:25.663",
        "lastModified": "2026-07-20T13:42:42.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-39359",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "authd accepts traversal-bearing group names during enrollment, and remoted later joins the stored name into synchronization paths that expose files outside the group directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-6q95-fcwc-4h44",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 989,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-39385",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-06T22:06:40.515Z",
      "date_published": "2026-07-20T16:55:08.593Z",
      "date_updated": "2026-07-20T19:07:17.376Z",
      "publisher": "GitHub_M",
      "title": "Frappe LMS enrollment bypass in paid courses via unrelated batch",
      "affected": {
        "vendors": [
          "frappe"
        ],
        "products": [
          {
            "vendor": "frappe",
            "product": "lms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12554
      },
      "nvd": {
        "published": "2026-07-20T17:17:07.417",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-39385",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The lms authentication flow exposes an alternate path that reaches protected functionality without the normal identity check.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frappe/lms/security/advisories/GHSA-c4xh-2rcm-6mgc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-07T08:24:32.861Z",
      "date_published": "2026-07-02T11:15:01.778Z",
      "date_updated": "2026-07-02T12:11:44.427Z",
      "publisher": "Patchstack",
      "title": "WordPress NOWPayments for WooCommerce plugin <= 1.4.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "CoderPress"
        ],
        "products": [
          {
            "vendor": "CoderPress",
            "product": "NOWPayments for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17146
      },
      "nvd": {
        "published": "2026-07-02T12:17:11.797",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-39448",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected action lacks an effective access-control decision, but the public record does not identify the subject or object binding.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/nowpayments-for-woocommerce/vulnerability/wordpress-nowpayments-for-woocommerce-plugin-1-4-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 87,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39822",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-07T18:13:03.527Z",
      "date_published": "2026-07-08T15:46:27.199Z",
      "date_updated": "2026-07-08T19:39:17.341Z",
      "publisher": "Go",
      "title": "Root escape via symlink plus trailing slash in os",
      "affected": {
        "vendors": [
          "Go standard library"
        ],
        "products": [
          {
            "vendor": "Go standard library",
            "product": "os"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-61",
          "name": "UNIX Symbolic Link (Symlink) Following",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14202
      },
      "nvd": {
        "published": "2026-07-08T17:17:21.310",
        "lastModified": "2026-07-13T14:54:26.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-39822",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The os file operation follows an attacker-influenced symlink or predictable temporary path outside the intended file object.",
        "basis": [
          "CNA",
          "CWE-61"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://go.dev/issue/79005",
          "host": "go.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch"
          ]
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc",
          "host": "groups.google.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://go.dev/cl/797880",
          "host": "go.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-4970",
          "host": "pkg.go.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-39873",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-07T19:58:20.173Z",
      "date_published": "2026-07-27T20:14:58.544Z",
      "date_updated": "2026-07-28T15:22:19.388Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25227
      },
      "nvd": {
        "published": "2026-07-27T21:16:51.340",
        "lastModified": "2026-07-28T19:53:04.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-39873",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A malicious SMB server can trigger an invalid memory operation in the macOS SMB client, but Apple does not disclose the access or lifetime error.",
        "basis": [
          "CNA",
          "CWE-119",
          "Apple macOS 26.6 and 14.8.8 security notes"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.apple.com/en-us/128067 and https://support.apple.com/en-us/128072; Apple confirms the SMB component and malicious-server trigger but publishes only improved memory handling, with no invalid access, allocation, or lifetime transition."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-39874",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-07T19:58:20.173Z",
      "date_published": "2026-07-27T20:13:52.763Z",
      "date_updated": "2026-07-28T03:57:13.809Z",
      "publisher": "apple",
      "title": "A permissions issue was addressed with additional restrictions.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0011,
        "percentile": 0.01509
      },
      "nvd": {
        "published": "2026-07-27T21:16:51.433",
        "lastModified": "2026-07-29T15:47:01.370",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-39874",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A macOS permission boundary permits a malicious app to gain root privileges, while Apple does not identify the entitlement, object, or operation left unrestricted.",
        "basis": [
          "CNA",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-39875",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-07T19:58:20.173Z",
      "date_published": "2026-07-27T20:14:01.161Z",
      "date_updated": "2026-07-28T03:57:08.569Z",
      "publisher": "apple",
      "title": "A permissions issue was addressed with additional restrictions.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06567
      },
      "nvd": {
        "published": "2026-07-27T21:16:51.533",
        "lastModified": "2026-07-29T15:46:54.523",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-39875",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple reports overly permissive macOS permissions that can yield root privileges but does not identify the file, service, or default permission.",
        "basis": [
          "CNA",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-39877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-07T19:58:20.174Z",
      "date_published": "2026-07-27T20:13:18.932Z",
      "date_updated": "2026-07-28T14:21:08.655Z",
      "publisher": "apple",
      "title": "A memory corruption issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03118
      },
      "nvd": {
        "published": "2026-07-27T21:16:51.640",
        "lastModified": "2026-07-29T17:02:33.107",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-39877",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure but does not disclose the exact buffer, lifetime transition, or invalid access.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 182,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-39878",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-07T20:32:03.010Z",
      "date_published": "2026-07-20T17:08:21.230Z",
      "date_updated": "2026-07-20T18:54:20.667Z",
      "publisher": "GitHub_M",
      "title": "Chamilo stored XSS via user registration leads to admin account takeover",
      "affected": {
        "vendors": [
          "chamilo"
        ],
        "products": [
          {
            "vendor": "chamilo",
            "product": "chamilo-lms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14685
      },
      "nvd": {
        "published": "2026-07-20T18:16:51.713",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-39878",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Chamilo stores registration data without HTML-context neutralization and later renders it to an administrator, allowing script execution in the administrator's session.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39879",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-07T20:32:03.010Z",
      "date_published": "2026-07-20T16:57:32.019Z",
      "date_updated": "2026-07-21T16:11:18.899Z",
      "publisher": "GitHub_M",
      "title": "SQL injection in syslog-ng SQL destionation driver",
      "affected": {
        "vendors": [
          "syslog-ng"
        ],
        "products": [
          {
            "vendor": "syslog-ng",
            "product": "syslog-ng"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-150",
          "name": "Improper Neutralization of Escape, Meta, or Control Sequences",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.068
      },
      "nvd": {
        "published": "2026-07-20T17:17:07.550",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-39879",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "afsql_dd_run_query omits the sanitization call before inserting data from an untrusted source into the configured SQL driver query.",
        "basis": [
          "CNA",
          "CWE-150"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/syslog-ng/syslog-ng/security/advisories/GHSA-qwf9-6222-m24m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 435,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-39903",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-07T20:57:06.209Z",
      "date_published": "2026-07-10T16:03:20.983Z",
      "date_updated": "2026-07-28T01:48:45.607Z",
      "publisher": "VulnCheck",
      "title": "Simple Machines Forum Authorization Bypass via AttachmentApprove.php",
      "affected": {
        "vendors": [
          "SimpleMachines"
        ],
        "products": [
          {
            "vendor": "SimpleMachines",
            "product": "SMF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25889
      },
      "nvd": {
        "published": "2026-07-10T17:16:57.230",
        "lastModified": "2026-07-14T21:16:46.467",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-39903",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A single-character operator error makes the AttachmentApprove permission predicate pass for users who lack approve_posts.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/SimpleMachines/SMF/pull/9182",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/SimpleMachines/SMF/pull/9181",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/SimpleMachines/SMF/commit/7d048f8d66aab9af51cd6ee110fbad103cf673e8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/SimpleMachines/SMF/commit/a7875e876a647572dd4c45da881b875092caac3d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/simple-machines-forum-authorization-bypass-via-attachmentapprove-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 551,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-40000",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T07:51:26.674Z",
      "date_published": "2026-07-27T09:35:01.526Z",
      "date_updated": "2026-07-28T11:04:11.498Z",
      "publisher": "zte",
      "title": "Path Traversal Vulnerability in ZTE Blade A75 5G",
      "affected": {
        "vendors": [
          "ZTE"
        ],
        "products": [
          {
            "vendor": "ZTE",
            "product": "Blade A75 5G"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 1.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@zte.com.cn",
          "type": "Secondary",
          "version": "3.1",
          "score": 1.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 1.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21893
      },
      "nvd": {
        "published": "2026-07-27T10:16:37.907",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-40000",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An exported preview Activity accepts an arbitrary content path and reads it with the File Manager's broader filesystem privileges.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/7341653040963675660",
          "host": "support.zte.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 562,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40005",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T08:40:49.866Z",
      "date_published": "2026-07-10T07:09:49.770Z",
      "date_updated": "2026-07-10T15:02:01.778Z",
      "publisher": "apache",
      "title": "Apache IoTDB: Path Traversal in Pipe File Transfer Receiver",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache IoTDB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00411,
        "percentile": 0.33854
      },
      "nvd": {
        "published": "2026-07-10T08:16:22.043",
        "lastModified": "2026-07-10T16:16:29.703",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-40005",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unsafe IoTDB API accepts a path that escapes the intended directory and writes wherever the process has filesystem permission.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/zw2vkbmy5xkf5y8g237v81hrs4c6b5lq",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/10/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 350,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40006",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T08:41:59.817Z",
      "date_published": "2026-07-10T07:10:54.826Z",
      "date_updated": "2026-07-10T14:59:16.628Z",
      "publisher": "apache",
      "title": "Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache IoTDB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34471
      },
      "nvd": {
        "published": "2026-07-10T08:16:22.163",
        "lastModified": "2026-07-10T16:16:29.893",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-40006",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unauthenticated AirGap receiver passes a network-supplied signed length directly to a byte-array allocation without an upper bound.",
        "basis": [
          "CNA",
          "CWE-770",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/rfpt7m9fvdrw37r3ow5omp2n914z6zqk",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/10/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 805,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40007",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T08:42:31.995Z",
      "date_published": "2026-07-10T07:12:29.926Z",
      "date_updated": "2026-07-10T14:54:55.434Z",
      "publisher": "apache",
      "title": "Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache IoTDB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00329,
        "percentile": 0.25412
      },
      "nvd": {
        "published": "2026-07-10T08:16:22.280",
        "lastModified": "2026-07-10T16:16:30.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-40007",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Apache IoTDB parser recurses once per attacker-controlled prefix or nesting level without a depth limit.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/tr23kh6kp8drrsv8ypv1mqm4v5kyy23m",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/10/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 617,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40008",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T08:42:56.547Z",
      "date_published": "2026-07-10T07:13:27.770Z",
      "date_updated": "2026-07-10T14:54:56.744Z",
      "publisher": "apache",
      "title": "Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache IoTDB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00423,
        "percentile": 0.34875
      },
      "nvd": {
        "published": "2026-07-10T08:16:22.397",
        "lastModified": "2026-07-10T16:16:30.343",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-40008",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pipe processor passes an attacker-supplied Java class name to Class.forName and instantiates it without an allowlist.",
        "basis": [
          "CNA",
          "CWE-470"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/fm8cpvzbox2qqy99ztglm8wkk1nrg9ng",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/10/5",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 405,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40009",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T09:06:05.914Z",
      "date_published": "2026-07-10T07:15:07.119Z",
      "date_updated": "2026-07-10T17:56:44.976Z",
      "publisher": "apache",
      "title": "Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache IoTDB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18319
      },
      "nvd": {
        "published": "2026-07-10T08:16:22.510",
        "lastModified": "2026-07-10T19:17:23.400",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-40009",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "IoTDB grants the reserved internal-auditor authority when an ordinary authenticated user renames their account to that reserved identity.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/65hh7dh28rcxlzdzwdpt630321tr8b61",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/10/6",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40047",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-08T16:19:46.829Z",
      "date_published": "2026-07-06T07:46:57.694Z",
      "date_updated": "2026-07-06T18:49:25.326Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0178,
        "percentile": 0.76071
      },
      "nvd": {
        "published": "2026-07-06T09:16:35.377",
        "lastModified": "2026-07-08T15:06:53.087",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40047",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache Camel passes attacker-controlled argument or command text into an operating-system command boundary without neutralizing the command grammar.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-40047.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2515,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40106",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-09T01:41:38.536Z",
      "date_published": "2026-07-16T23:57:16.037Z",
      "date_updated": "2026-07-17T14:31:32.183Z",
      "publisher": "GitHub_M",
      "title": "Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS)",
      "affected": {
        "vendors": [
          "wazuh"
        ],
        "products": [
          {
            "vendor": "wazuh",
            "product": "wazuh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02812
      },
      "nvd": {
        "published": "2026-07-17T02:18:05.780",
        "lastModified": "2026-07-20T02:29:49.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40106",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Registry wildcard expansion concatenates a maximum-length key into a fixed 256-byte heap buffer and writes beyond the allocation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-qvrc-pcfc-jhqc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 783,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40138",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-09T18:36:13.133Z",
      "date_published": "2026-07-06T16:12:42.627Z",
      "date_updated": "2026-07-07T14:59:19.946Z",
      "publisher": "BT",
      "title": "Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access",
      "affected": {
        "vendors": [
          "BeyondTrust"
        ],
        "products": [
          {
            "vendor": "BeyondTrust",
            "product": "Remote Support"
          },
          {
            "vendor": "BeyondTrust",
            "product": "Privileged Remote Access"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:13061848-ea10-403d-bd75-c83a022c2891",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36299
      },
      "nvd": {
        "published": "2026-07-06T17:16:30.793",
        "lastModified": "2026-07-07T16:16:38.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40138",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in Remote Support, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-287",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Read https://www.beyondtrust.com/trust-center/security-advisories/bt26-03; the vendor confirms authentication-data validation under a specific configuration but does not publish the data format or failed check."
      },
      "references": [
        {
          "url": "https://www.beyondtrust.com/trust-center/security-advisories/bt26-03",
          "host": "www.beyondtrust.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-40139",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-09T18:36:13.133Z",
      "date_published": "2026-07-06T16:13:02.413Z",
      "date_updated": "2026-07-07T15:00:13.079Z",
      "publisher": "BT",
      "title": "Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access",
      "affected": {
        "vendors": [
          "BeyondTrust"
        ],
        "products": [
          {
            "vendor": "BeyondTrust",
            "product": "Remote Support"
          },
          {
            "vendor": "BeyondTrust",
            "product": "Privileged Remote Access"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:13061848-ea10-403d-bd75-c83a022c2891",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.00674,
        "percentile": 0.48622
      },
      "nvd": {
        "published": "2026-07-06T17:16:30.920",
        "lastModified": "2026-07-07T18:39:48.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40139",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Remote Support improperly processes a pre-authentication request and grants appliance access, but the exact authentication check is not public.",
        "basis": [
          "CNA",
          "CWE-287",
          "https://www.beyondtrust.com/trust-center/security-advisories/bt26-03"
        ],
        "deepDive": true,
        "notes": "Primary source inspected: https://www.beyondtrust.com/trust-center/security-advisories/bt26-03. BeyondTrust identifies a pre-authentication authorization-subsystem issue and scores it CVSS v4.0 9.2, but it does not publish the failing check; the embedded maximum CVSS is 9.8."
      },
      "references": [
        {
          "url": "https://www.beyondtrust.com/trust-center/security-advisories/bt26-03",
          "host": "www.beyondtrust.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 400,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-40140",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-09T18:36:13.133Z",
      "date_published": "2026-07-06T16:13:22.126Z",
      "date_updated": "2026-07-07T15:01:24.511Z",
      "publisher": "BT",
      "title": "High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access",
      "affected": {
        "vendors": [
          "BeyondTrust"
        ],
        "products": [
          {
            "vendor": "BeyondTrust",
            "product": "Remote Support"
          },
          {
            "vendor": "BeyondTrust",
            "product": "Privileged Remote Access"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:13061848-ea10-403d-bd75-c83a022c2891",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00575,
        "percentile": 0.44207
      },
      "nvd": {
        "published": "2026-07-06T17:16:31.030",
        "lastModified": "2026-07-07T18:40:15.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40140",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The appliance network subsystem accepts client input that exhausts availability, but the public record does not identify the unbounded resource or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.beyondtrust.com/trust-center/security-advisories/bt26-03",
          "host": "www.beyondtrust.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-40141",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-09T18:36:13.133Z",
      "date_published": "2026-07-06T16:13:42.284Z",
      "date_updated": "2026-07-07T14:56:42.895Z",
      "publisher": "BT",
      "title": "High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access",
      "affected": {
        "vendors": [
          "BeyondTrust"
        ],
        "products": [
          {
            "vendor": "BeyondTrust",
            "product": "Remote Support"
          },
          {
            "vendor": "BeyondTrust",
            "product": "Privilege Remote Access"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-943",
          "name": "Improper Neutralization of Special Elements in Data Query Logic",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:13061848-ea10-403d-bd75-c83a022c2891",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00494,
        "percentile": 0.39752
      },
      "nvd": {
        "published": "2026-07-06T17:16:31.143",
        "lastModified": "2026-07-07T18:43:46.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40141",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A BeyondTrust web component fails to neutralize special elements in input used by query logic, while the public advisory does not disclose the parameter, query language, or sink.",
        "basis": [
          "CNA",
          "CWE-943",
          "BeyondTrust BT26-03"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.beyondtrust.com/trust-center/security-advisories/bt26-03; it confirms insufficient processing of certain input parameters and unintended resource access, but publishes no query grammar, parameter, or code path."
      },
      "references": [
        {
          "url": "https://www.beyondtrust.com/trust-center/security-advisories/bt26-03",
          "host": "www.beyondtrust.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 427,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-40187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-09T20:59:17.620Z",
      "date_published": "2026-07-20T17:00:38.515Z",
      "date_updated": "2026-07-20T17:34:06.076Z",
      "publisher": "GitHub_M",
      "title": "Authenticated RCE via Malicious eTemplate Upload in EGroupware",
      "affected": {
        "vendors": [
          "EGroupware"
        ],
        "products": [
          {
            "vendor": "EGroupware",
            "product": "egroupware"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-95",
          "name": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00933,
        "percentile": 0.57261
      },
      "nvd": {
        "published": "2026-07-20T17:17:07.690",
        "lastModified": "2026-07-23T18:04:31.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-40187",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component lets attacker-controlled text cross into an executable or interpreted grammar without the required separation.",
        "basis": [
          "CNA",
          "CWE-78",
          "CWE-95"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/EGroupware/egroupware/security/advisories/GHSA-8737-2x9g-xjj7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 598,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40257",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-10T17:31:45.787Z",
      "date_published": "2026-07-06T16:26:20.379Z",
      "date_updated": "2026-07-06T18:57:42.472Z",
      "publisher": "GitHub_M",
      "title": "OP-TEE has SHA-3 accelerated finalize heap overflow",
      "affected": {
        "vendors": [
          "OP-TEE"
        ],
        "products": [
          {
            "vendor": "OP-TEE",
            "product": "optee_os"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00109,
        "percentile": 0.01434
      },
      "nvd": {
        "published": "2026-07-06T17:16:31.253",
        "lastModified": "2026-07-07T18:56:50.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40257",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An off-by-one loop in the accelerated SHA-3 implementation writes past the hash-state allocation into subsequent TEE kernel memory.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OP-TEE/optee_os/security/advisories/GHSA-75x4-j8p9-55qv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 616,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40272",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-10T17:41:10.441Z",
      "date_published": "2026-07-29T17:58:27.761Z",
      "date_updated": "2026-07-29T18:08:13.992Z",
      "publisher": "blackberry",
      "title": "Vulnerability in the QNX libtraceparser Impacts QNX Software Development Platform",
      "affected": {
        "vendors": [
          "BlackBerry Ltd"
        ],
        "products": [
          {
            "vendor": "BlackBerry Ltd",
            "product": "QNX Software Development Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secure@blackberry.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01634
      },
      "nvd": {
        "published": "2026-07-29T18:16:53.347",
        "lastModified": "2026-07-30T16:51:19.723",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-40272",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The traceparser decode function accepts a specified quantity from a corrupted kernel event log without validating it before use.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.blackberry.com/pkb/s/article/141229",
          "host": "support.blackberry.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-40378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-11T23:06:15.615Z",
      "date_published": "2026-07-14T17:05:44.149Z",
      "date_updated": "2026-08-03T22:54:07.620Z",
      "publisher": "microsoft",
      "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 20,
        "versionEntryCount": 20,
        "versionRangeCount": 20,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00816,
        "percentile": 0.53582
      },
      "nvd": {
        "published": "2026-07-14T17:16:47.257",
        "lastModified": "2026-07-22T16:17:18.673",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40378",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 allocates memory from an attacker-influenced size without enforcing a safe maximum.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40378",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 20,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-40400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-13T00:27:50.798Z",
      "date_published": "2026-07-14T17:05:42.396Z",
      "date_updated": "2026-08-03T22:54:05.874Z",
      "publisher": "microsoft",
      "title": "Windows PowerShell Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00701,
        "percentile": 0.49669
      },
      "nvd": {
        "published": "2026-07-14T17:16:47.447",
        "lastModified": "2026-07-22T16:17:18.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40400",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerShell resolves an attacker-influenced relative path outside the intended location and executes the selected code.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40400",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-40422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-13T00:27:50.799Z",
      "date_published": "2026-07-14T17:05:41.226Z",
      "date_updated": "2026-08-03T22:54:04.756Z",
      "publisher": "microsoft",
      "title": "Windows File Explorer Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22143
      },
      "nvd": {
        "published": "2026-07-14T17:16:47.620",
        "lastModified": "2026-07-22T16:17:19.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40422",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation uses a resource before it has been initialized.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40422",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-40430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T17:14:43.830Z",
      "date_published": "2026-07-23T21:58:33.469Z",
      "date_updated": "2026-07-24T12:37:33.801Z",
      "publisher": "icscert",
      "title": "Plaintext Storage of a Password in Panduit IntraVUE by Pronetiqs",
      "affected": {
        "vendors": [
          "Pronetiqs"
        ],
        "products": [
          {
            "vendor": "Pronetiqs",
            "product": "Panduit Intravue"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-256",
          "name": "Plaintext Storage of a Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14168
      },
      "nvd": {
        "published": "2026-07-23T23:16:48.743",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-40430",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "IntraVUE stores a password in plaintext and exposes the cleartext credential through its API.",
        "basis": [
          "CNA record",
          "CWE-256"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 156,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40452",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-13T07:33:02.319Z",
      "date_published": "2026-07-10T07:16:05.992Z",
      "date_updated": "2026-07-10T17:55:35.036Z",
      "publisher": "apache",
      "title": "Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache IoTDB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20925
      },
      "nvd": {
        "published": "2026-07-10T08:16:22.627",
        "lastModified": "2026-07-10T19:17:23.540",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-40452",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The fastLastQuery REST route returns last-value data to an authenticated user without the authorization required for that data.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/04j2l6dosyboor4o2gvrzbrcrpllmh95",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/10/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-40454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-13T09:02:17.905Z",
      "date_published": "2026-07-10T07:19:01.868Z",
      "date_updated": "2026-07-10T14:55:00.635Z",
      "publisher": "apache",
      "title": "Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache IoTDB C++ client"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00329,
        "percentile": 0.25412
      },
      "nvd": {
        "published": "2026-07-10T08:16:22.750",
        "lastModified": "2026-07-10T16:16:30.770",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-40454",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The IoTDB TsBlock deserializer reads beyond its input buffer when a server returns malformed serialized data.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/9wml325g6bpovw0jf5ymtc3xl7fwlkrn",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/10/8",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 368,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-40467",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-13T14:44:55.647Z",
      "date_published": "2026-07-13T12:07:52.006Z",
      "date_updated": "2026-07-13T13:02:22.646Z",
      "publisher": "CERT-PL",
      "title": "Use after free in gawk",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "gawk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.4000000000000004,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11746
      },
      "nvd": {
        "published": "2026-07-13T13:16:36.770",
        "lastModified": "2026-07-14T01:13:59.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40467",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In gawk, a path retains or reuses an object after the lifetime transition that frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40468",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-13T14:44:55.647Z",
      "date_published": "2026-07-13T12:07:54.910Z",
      "date_updated": "2026-07-13T13:01:29.711Z",
      "publisher": "CERT-PL",
      "title": "Heap buffer overflow in gawk",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "gawk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 7,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10154
      },
      "nvd": {
        "published": "2026-07-13T13:16:36.907",
        "lastModified": "2026-07-14T01:12:11.343",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40468",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An arithmetic operation can wrap before the result is used for a memory size or offset, invalidating the later bounds assumption.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40469",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-13T14:44:55.647Z",
      "date_published": "2026-07-13T12:07:55.692Z",
      "date_updated": "2026-07-13T13:01:07.290Z",
      "publisher": "CERT-PL",
      "title": "Heap buffer overflow in gawk",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "gawk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11746
      },
      "nvd": {
        "published": "2026-07-13T13:16:37.033",
        "lastModified": "2026-07-14T01:11:18.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40469",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer arithmetic in gawk do_sub wraps on 32-bit builds and produces an invalid heap operation that can overwrite heap metadata and objects.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=ae1b2d508f46913269a9e62aceda3636afe8147b",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-13T20:29:02.808Z",
      "date_published": "2026-07-15T17:41:01.459Z",
      "date_updated": "2026-07-28T01:48:46.978Z",
      "publisher": "VulnCheck",
      "title": "Cherry Studio RCE via SearchService nodeIntegration Misconfiguration",
      "affected": {
        "vendors": [
          "CherryHQ"
        ],
        "products": [
          {
            "vendor": "CherryHQ",
            "product": "cherry-studio"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00438,
        "percentile": 0.35994
      },
      "nvd": {
        "published": "2026-07-15T18:16:45.230",
        "lastModified": "2026-07-15T21:02:41.590",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-40501",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The cherry-studio execution path loads code or content from an untrusted source into a privileged runtime.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/Mundi-Xu/99af1b08275fd437cfb79bfe481e68b7",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/CherryHQ/cherry-studio/commit/151853035e8e417a51559ebfc243eda98361a882",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cherry-studio-rce-via-searchservice-nodeintegration-misconfiguration",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 656,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-40553",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-14T09:44:32.553Z",
      "date_published": "2026-07-13T12:07:56.611Z",
      "date_updated": "2026-07-13T13:00:45.449Z",
      "publisher": "CERT-PL",
      "title": "Stack-based buffer overflow in gawk",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "gawk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.4000000000000004,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21284
      },
      "nvd": {
        "published": "2026-07-13T13:16:37.147",
        "lastModified": "2026-07-14T01:10:20.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40553",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An invalid memory access is possible because an object is used beyond its bounds or valid lifetime.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-40467",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40633",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-14T16:10:47.674Z",
      "date_published": "2026-07-15T10:07:27.568Z",
      "date_updated": "2026-07-15T15:11:44.976Z",
      "publisher": "dell",
      "title": "Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit...",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerScale OneFS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00109,
        "percentile": 0.01448
      },
      "nvd": {
        "published": "2026-07-15T11:16:25.463",
        "lastModified": "2026-07-15T19:39:48.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40633",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PowerScale OneFS logging path writes sensitive values into logs accessible to a lower-trust observer.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000483600/dsa-2026-261-security-update-for-dell-powerscale-onefs-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-40691",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T10:11:10.532Z",
      "date_published": "2026-07-22T13:04:35.410Z",
      "date_updated": "2026-07-22T14:31:26.565Z",
      "publisher": "NLnet Labs",
      "title": "Packet of death for DNSCrypt over TCP",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21555
      },
      "nvd": {
        "published": "2026-07-22T14:17:18.437",
        "lastModified": "2026-07-24T13:57:32.377",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40691",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unbound copies a DNSCrypt reply using an attacker-controlled length without bounding the write to the TCP reply buffer.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-40691.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 708,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40712",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-15T05:04:31.837Z",
      "date_published": "2026-07-22T15:28:15.113Z",
      "date_updated": "2026-07-24T03:56:06.739Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Manager, versions prior to 20.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 1.8999999999999995,
      "epss": {
        "score": 0.00349,
        "percentile": 0.27609
      },
      "nvd": {
        "published": "2026-07-22T16:17:19.247",
        "lastModified": "2026-07-29T17:40:59.493",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40712",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Dell identifies malformed REST API input followed by privilege elevation, but its proprietary-code advisory does not disclose the field, parser, or authorization transition that fails.",
        "basis": [
          "CNA",
          "CWE-20",
          "Dell DSA-2026-287"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.dell.com/support/kbdoc/en-us/000488847/dsa-2026-287-security-update-dell-powerprotect-data-manager-for-multiple-security-vulnerabilities. Dell repeats REST API improper input validation, high required privilege, and version 20.2.0.0 remediation without publishing the field, handler, or privilege transition."
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000488847/dsa-2026-287-security-update-dell-powerprotect-data-manager-for-multiple-security-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40714",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-15T05:04:31.837Z",
      "date_published": "2026-07-22T15:20:35.358Z",
      "date_updated": "2026-07-24T03:56:05.881Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Manager, versions prior to 20.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19972
      },
      "nvd": {
        "published": "2026-07-22T16:17:19.423",
        "lastModified": "2026-07-29T17:40:30.153",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40714",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Dell reports that malformed input can elevate an already privileged remote user but does not identify the input or authorization boundary.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000488847/dsa-2026-287-security-update-dell-powerprotect-data-manager-for-multiple-security-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 242,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40859",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-15T12:20:24.037Z",
      "date_published": "2026-07-06T07:54:29.981Z",
      "date_updated": "2026-07-06T18:48:16.623Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00879,
        "percentile": 0.55571
      },
      "nvd": {
        "published": "2026-07-06T09:16:35.520",
        "lastModified": "2026-07-07T17:40:09.207",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40859",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component deserializes attacker-controlled object data without restricting executable types or behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-40859.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2294,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-40952",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T00:19:03.573Z",
      "date_published": "2026-07-15T19:32:58.728Z",
      "date_updated": "2026-07-16T13:06:21.115Z",
      "publisher": "Absolute",
      "title": "Privilge misconfiguration in Secure Access installers",
      "affected": {
        "vendors": [
          "Absolute Security"
        ],
        "products": [
          {
            "vendor": "Absolute Security",
            "product": "Secure Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:SecurityResponse@netmotionsoftware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00094,
        "percentile": 0.00705
      },
      "nvd": {
        "published": "2026-07-15T20:16:57.907",
        "lastModified": "2026-07-16T14:16:51.250",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40952",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An installer assigns unsafe permissions when a nondefault installation path is selected, allowing a less-privileged user to modify privileged application content.",
        "basis": [
          "CNA",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-40952",
          "host": "www.absolute.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 296,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40953",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T00:19:03.573Z",
      "date_published": "2026-07-15T19:40:50.435Z",
      "date_updated": "2026-07-16T13:15:46.358Z",
      "publisher": "Absolute",
      "title": "Heap overflow in Secure Access clients",
      "affected": {
        "vendors": [
          "Absolute Security"
        ],
        "products": [
          {
            "vendor": "Absolute Security",
            "product": "Secure Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:SecurityResponse@netmotionsoftware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00073,
        "percentile": 0.00079
      },
      "nvd": {
        "published": "2026-07-15T20:16:58.077",
        "lastModified": "2026-07-16T14:16:51.390",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40953",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled input reaches a write whose destination boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-40953",
          "host": "www.absolute.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40954",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T00:19:03.573Z",
      "date_published": "2026-07-15T19:44:47.223Z",
      "date_updated": "2026-07-16T13:15:09.379Z",
      "publisher": "Absolute",
      "title": "Integer underflow in Secure Access clients prior to 14.55",
      "affected": {
        "vendors": [
          "Absolute Security"
        ],
        "products": [
          {
            "vendor": "Absolute Security",
            "product": "Secure Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:SecurityResponse@netmotionsoftware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 1.6,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10162
      },
      "nvd": {
        "published": "2026-07-15T20:16:58.273",
        "lastModified": "2026-07-16T14:16:51.547",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40954",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Secure Access traffic parsing can underflow an integer derived from tunnel-protocol data and enter an invalid processing state that terminates the client.",
        "basis": [
          "CNA",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-40954",
          "host": "www.absolute.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40955",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T00:19:03.573Z",
      "date_published": "2026-07-15T19:50:55.979Z",
      "date_updated": "2026-07-16T13:13:12.587Z",
      "publisher": "Absolute",
      "title": "Integer underflow vulnerability in Secure Access clients",
      "affected": {
        "vendors": [
          "Absolute Security"
        ],
        "products": [
          {
            "vendor": "Absolute Security",
            "product": "Secure Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:SecurityResponse@netmotionsoftware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 1.6,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10162
      },
      "nvd": {
        "published": "2026-07-15T20:16:59.893",
        "lastModified": "2026-07-16T14:16:51.683",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40955",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tunnel-protocol length arithmetic underflows in the client traffic parser and drives an invalid memory-processing path.",
        "basis": [
          "CNA",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-40955",
          "host": "www.absolute.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40956",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T00:19:03.574Z",
      "date_published": "2026-07-15T19:55:05.678Z",
      "date_updated": "2026-07-16T13:12:35.493Z",
      "publisher": "Absolute",
      "title": "Memory disclosure in Secure Access Clients",
      "affected": {
        "vendors": [
          "Absolute Security"
        ],
        "products": [
          {
            "vendor": "Absolute Security",
            "product": "Secure Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:SecurityResponse@netmotionsoftware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 1.6,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06744
      },
      "nvd": {
        "published": "2026-07-15T20:17:00.053",
        "lastModified": "2026-07-16T14:16:51.810",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40956",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Secure Access tunnel protocol can return a small amount of process memory to a peer, but the public advisory does not identify the read boundary or buffer.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-40956",
          "host": "www.absolute.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 231,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40957",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T00:19:03.574Z",
      "date_published": "2026-07-15T19:59:05.438Z",
      "date_updated": "2026-07-16T13:16:38.543Z",
      "publisher": "Absolute",
      "title": "Frameable content vulnerability in the Secure Access server login page",
      "affected": {
        "vendors": [
          "Absolute Security"
        ],
        "products": [
          {
            "vendor": "Absolute Security",
            "product": "Secure Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1021",
          "name": "Improper Restriction of Rendered UI Layers or Frames",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N"
        },
        {
          "source": "NVD:SecurityResponse@netmotionsoftware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23677
      },
      "nvd": {
        "published": "2026-07-15T20:17:00.210",
        "lastModified": "2026-07-16T14:16:51.930",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40957",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The login page permits hostile cross-origin framing, allowing another site to overlay or steer administrator interaction with the trusted page.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1021"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-40957",
          "host": "www.absolute.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-40958",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T00:19:03.574Z",
      "date_published": "2026-07-15T20:02:59.125Z",
      "date_updated": "2026-07-16T13:11:50.471Z",
      "publisher": "Absolute",
      "title": "Input validation error in Secure Access clients prior to 14.55",
      "affected": {
        "vendors": [
          "Absolute Security"
        ],
        "products": [
          {
            "vendor": "Absolute Security",
            "product": "Secure Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:SecurityResponse@netmotionsoftware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00223,
        "percentile": 0.13019
      },
      "nvd": {
        "published": "2026-07-15T20:17:00.503",
        "lastModified": "2026-07-16T14:16:52.060",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-40958",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The vendor reports malformed tunnel input causing denial of service but does not disclose the parser, exceptional condition, or exhausted resource.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-40958",
          "host": "www.absolute.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41041",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T08:43:37.693Z",
      "date_published": "2026-07-13T09:08:51.055Z",
      "date_updated": "2026-07-13T17:04:02.546Z",
      "publisher": "apache",
      "title": "Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Gravitino"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-177",
          "name": "Improper Handling of URL Encoding (Hex Encoding)",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00475,
        "percentile": 0.38583
      },
      "nvd": {
        "published": "2026-07-13T10:16:28.803",
        "lastModified": "2026-07-13T22:24:21.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41041",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Gravitino inserts an unencoded user identifier into a URL path, allowing reserved path syntax to alter the downstream request.",
        "basis": [
          "CNA",
          "CWE-177"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/4dnwg1qzb2yns1fkfmq0z45vmwyzytgz",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/13/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 231,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41042",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T11:19:50.383Z",
      "date_published": "2026-07-08T11:38:55.311Z",
      "date_updated": "2026-07-08T17:31:28.887Z",
      "publisher": "apache",
      "title": "Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Gravitino"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20756
      },
      "nvd": {
        "published": "2026-07-08T12:17:20.550",
        "lastModified": "2026-07-08T20:16:49.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41042",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The unauthenticated testConnection API passes an attacker-controlled H2 JDBC URL to the H2 interpreter, including an INIT clause that executes Java code.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/vdh88wc6j5b38v65ncb111wbbnkf6bvm",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/08/5",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 514,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41087",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T19:12:36.194Z",
      "date_published": "2026-07-14T17:05:41.770Z",
      "date_updated": "2026-08-03T22:54:05.393Z",
      "publisher": "microsoft",
      "title": "Windows File Explorer Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28062
      },
      "nvd": {
        "published": "2026-07-14T17:16:47.773",
        "lastModified": "2026-07-22T16:17:19.577",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41087",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows 10 Version 1607 returns, logs, or renders sensitive state to a caller that has not passed the authorization or redaction boundary for that data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41087",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-41106",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-16T19:12:36.196Z",
      "date_published": "2026-07-02T22:18:57.629Z",
      "date_updated": "2026-08-03T22:52:42.710Z",
      "publisher": "microsoft",
      "title": "Microsoft 365 Copilot Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Copilot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00531,
        "percentile": 0.41897
      },
      "nvd": {
        "published": "2026-07-02T23:16:50.867",
        "lastModified": "2026-07-07T14:24:12.110",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41106",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Copilot accepts an untrusted redirect destination and sends the browser to that attacker-selected site.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41106",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 137,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41121",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-17T05:04:42.886Z",
      "date_published": "2026-07-01T18:48:15.797Z",
      "date_updated": "2026-07-01T19:22:36.989Z",
      "publisher": "dell",
      "title": "Dell Device Management Agent, versions prior to DDMA 26.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "Device Management Agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00123,
        "percentile": 0.0248
      },
      "nvd": {
        "published": "2026-07-01T19:16:51.953",
        "lastModified": "2026-07-06T20:37:24.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41121",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Device Management Agent follows an attacker-controlled link or junction before a privileged file operation, redirecting access to a different filesystem object.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000473690/dsa-2026-258",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41122",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-17T05:04:42.886Z",
      "date_published": "2026-07-08T13:26:09.809Z",
      "date_updated": "2026-07-08T14:25:18.019Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12797
      },
      "nvd": {
        "published": "2026-07-08T14:16:58.197",
        "lastModified": "2026-07-08T20:09:50.337",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41122",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerProtect Data Domain stores unauthenticated input and later renders it without sufficient HTML-context neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 454,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-41123",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-17T05:04:42.886Z",
      "date_published": "2026-07-03T12:25:47.932Z",
      "date_updated": "2026-07-06T16:27:44.306Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04883
      },
      "nvd": {
        "published": "2026-07-03T13:17:10.720",
        "lastModified": "2026-07-08T19:34:50.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41123",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PowerProtect RBAC permits a low-privileged remote user to modify protected information, but the missing role-to-action binding is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-41124",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-17T05:04:42.886Z",
      "date_published": "2026-07-03T12:19:59.524Z",
      "date_updated": "2026-07-06T16:34:41.734Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 2.1000000000000005,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02734
      },
      "nvd": {
        "published": "2026-07-03T13:17:10.837",
        "lastModified": "2026-07-08T19:34:04.767",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41124",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerProtect Data Domain accepts traversal elements in a pathname and resolves a file outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-41154",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-17T16:26:03.730Z",
      "date_published": "2026-07-10T20:46:06.747Z",
      "date_updated": "2026-07-13T18:55:25.696Z",
      "publisher": "imaginationtech",
      "title": "GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse",
      "affected": {
        "vendors": [
          "Imagination Technologies"
        ],
        "products": [
          {
            "vendor": "Imagination Technologies",
            "product": "Graphics DDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03126
      },
      "nvd": {
        "published": "2026-07-10T21:16:54.410",
        "lastModified": "2026-07-13T19:24:52.303",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41154",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
          "host": "www.imaginationtech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-41186",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-17T17:41:35.905Z",
      "date_published": "2026-07-30T14:45:04.418Z",
      "date_updated": "2026-07-30T16:10:53.298Z",
      "publisher": "Tigera",
      "title": "Unauthenticated Go pprof exposure in Calico debug server",
      "affected": {
        "vendors": [
          "Tigera"
        ],
        "products": [
          {
            "vendor": "Tigera",
            "product": "Calico"
          },
          {
            "vendor": "Tigera",
            "product": "Calico Enterprise"
          },
          {
            "vendor": "Tigera",
            "product": "Calico Cloud"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-489",
          "name": "Active Debug Code",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:psirt@tigera.io",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14435
      },
      "nvd": {
        "published": "2026-07-30T15:16:31.677",
        "lastModified": "2026-07-30T17:16:31.463",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41186",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-489"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/projectcalico/calico/pull/12491",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/projectcalico/calico/pull/12634",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/projectcalico/calico/pull/12633",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tigera.io/security-bulletins/tta-2026-004/",
          "host": "www.tigera.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 567,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-41187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-17T17:41:35.905Z",
      "date_published": "2026-07-30T14:45:04.247Z",
      "date_updated": "2026-07-30T16:11:27.341Z",
      "publisher": "Tigera",
      "title": "Calico Tier Authorization Bypass via DeleteCollection",
      "affected": {
        "vendors": [
          "Tigera"
        ],
        "products": [
          {
            "vendor": "Tigera",
            "product": "Calico"
          },
          {
            "vendor": "Tigera",
            "product": "Calico Enterprise"
          },
          {
            "vendor": "Tigera",
            "product": "Calico Cloud"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:L/SA:H"
        },
        {
          "source": "NVD:psirt@tigera.io",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.1937
      },
      "nvd": {
        "published": "2026-07-30T15:16:31.860",
        "lastModified": "2026-07-30T17:16:31.583",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41187",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/projectcalico/calico/pull/12731",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/projectcalico/calico/pull/12735",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/projectcalico/calico/pull/12736",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/projectcalico/calico/pull/12737",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.tigera.io/security-bulletins/tta-2026-006/",
          "host": "www.tigera.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-41252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-18T03:47:03.136Z",
      "date_published": "2026-07-20T16:29:53.496Z",
      "date_updated": "2026-07-23T03:56:20.804Z",
      "publisher": "GitHub_M",
      "title": "xrdp: lib_palette_update Heap Buffer Overflow & RCE",
      "affected": {
        "vendors": [
          "neutrinolabs"
        ],
        "products": [
          {
            "vendor": "neutrinolabs",
            "product": "xrdp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00609,
        "percentile": 0.45742
      },
      "nvd": {
        "published": "2026-07-20T17:17:08.310",
        "lastModified": "2026-07-23T05:16:30.397",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41252",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The VNC color-map handler uses unvalidated incoming color indices for heap writes, allowing an out-of-range index to overwrite the allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-w5vg-6qmv-j63j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 652,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T15:32:33.815Z",
      "date_published": "2026-07-06T17:24:40.881Z",
      "date_updated": "2026-07-07T15:06:13.052Z",
      "publisher": "GitHub_M",
      "title": "OP-TEE has unbounded recursion in  sanitize_client_object()",
      "affected": {
        "vendors": [
          "OP-TEE"
        ],
        "products": [
          {
            "vendor": "OP-TEE",
            "product": "optee_os"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01254
      },
      "nvd": {
        "published": "2026-07-06T18:16:43.923",
        "lastModified": "2026-07-07T18:53:03.177",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41434",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The PKCS#11 client-object sanitizer recursively processes attacker-controlled nesting without a depth or termination bound.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OP-TEE/optee_os/security/advisories/GHSA-wh38-23ff-grff",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T16:14:19.006Z",
      "date_published": "2026-07-10T21:20:36.507Z",
      "date_updated": "2026-07-13T17:58:54.127Z",
      "publisher": "GitHub_M",
      "title": "Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generator",
      "affected": {
        "vendors": [
          "frappe"
        ],
        "products": [
          {
            "vendor": "frappe",
            "product": "frappe"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26378
      },
      "nvd": {
        "published": "2026-07-10T22:16:41.337",
        "lastModified": "2026-07-13T19:17:07.760",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41482",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "frappe accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frappe/frappe/security/advisories/GHSA-234v-jfr8-v2f8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/38643",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/39396",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/11066591ed7aa91a7b742f3f689277a90e620ce0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/46841f7fde3954e1d3b3a7e248a6d6022343e657",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/releases/tag/v16.18.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41514",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T18:18:50.681Z",
      "date_published": "2026-07-06T19:06:36.943Z",
      "date_updated": "2026-07-07T16:57:46.440Z",
      "publisher": "GitHub_M",
      "title": "OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery",
      "affected": {
        "vendors": [
          "OP-TEE"
        ],
        "products": [
          {
            "vendor": "OP-TEE",
            "product": "optee_os"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00095,
        "percentile": 0.008
      },
      "nvd": {
        "published": "2026-07-06T20:16:31.917",
        "lastModified": "2026-07-07T18:50:58.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41514",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RSA-OAEP label verification uses non-constant-time comparison and distinguishable errors, creating an adaptive plaintext-recovery oracle.",
        "basis": [
          "CNA",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OP-TEE/optee_os/security/advisories/GHSA-qw4r-9wj9-q23r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 768,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41515",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T18:18:50.681Z",
      "date_published": "2026-07-06T19:25:10.934Z",
      "date_updated": "2026-07-07T14:09:30.230Z",
      "publisher": "GitHub_M",
      "title": "OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery",
      "affected": {
        "vendors": [
          "OP-TEE"
        ],
        "products": [
          {
            "vendor": "OP-TEE",
            "product": "optee_os"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00094,
        "percentile": 0.00702
      },
      "nvd": {
        "published": "2026-07-06T20:16:32.060",
        "lastModified": "2026-07-07T18:54:35.227",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41515",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RSA-OAEP validation uses a non-constant-time comparison and distinguishable errors, creating an adaptive decryption oracle.",
        "basis": [
          "CNA",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OP-TEE/optee_os/security/advisories/GHSA-5q45-58r5-cq4g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 666,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T18:18:50.681Z",
      "date_published": "2026-07-06T19:27:32.040Z",
      "date_updated": "2026-07-06T19:47:57.871Z",
      "publisher": "GitHub_M",
      "title": "OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle",
      "affected": {
        "vendors": [
          "OP-TEE"
        ],
        "products": [
          {
            "vendor": "OP-TEE",
            "product": "optee_os"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03254
      },
      "nvd": {
        "published": "2026-07-06T20:16:32.197",
        "lastModified": "2026-07-07T18:56:37.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41516",
        "family": "HARDWARE_PHYSICAL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Non-constant-time label-hash comparison and distinguishable RSA decryption errors create a PKCS#1 v1.5 padding oracle.",
        "basis": [
          "CNA record",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OP-TEE/optee_os/security/advisories/GHSA-wxp6-8wwr-h4gf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 635,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41521",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-20T18:18:50.682Z",
      "date_published": "2026-07-20T16:41:43.935Z",
      "date_updated": "2026-07-20T18:57:19.781Z",
      "publisher": "GitHub_M",
      "title": "xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass",
      "affected": {
        "vendors": [
          "neutrinolabs"
        ],
        "products": [
          {
            "vendor": "neutrinolabs",
            "product": "xrdp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00392,
        "percentile": 0.31892
      },
      "nvd": {
        "published": "2026-07-20T17:17:08.460",
        "lastModified": "2026-07-22T20:07:10.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41521",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "xrdp uses an unchecked integer result after arithmetic can overflow its representable range.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-v8w6-pf78-9458",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 688,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41579",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T14:15:21.958Z",
      "date_published": "2026-07-01T00:02:08.639Z",
      "date_updated": "2026-07-01T13:35:41.354Z",
      "publisher": "GitHub_M",
      "title": "runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations",
      "affected": {
        "vendors": [
          "opencontainers"
        ],
        "products": [
          {
            "vendor": "opencontainers",
            "product": "runc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-61",
          "name": "UNIX Symbolic Link (Symlink) Following",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08445
      },
      "nvd": {
        "published": "2026-07-01T02:17:00.193",
        "lastModified": "2026-07-02T19:36:49.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41579",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "runc joins operations beneath an image-controlled /dev symlink, allowing removal or symlink creation in a host directory.",
        "basis": [
          "CNA",
          "CWE-61"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/opencontainers/runc/security/advisories/GHSA-xjvp-4fhw-gc47",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/opencontainers/runc/commit/864db8042dbb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 884,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-41580",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T14:15:21.958Z",
      "date_published": "2026-07-15T14:56:36.902Z",
      "date_updated": "2026-07-15T15:33:13.431Z",
      "publisher": "GitHub_M",
      "title": "Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Author)",
      "affected": {
        "vendors": [
          "Stirling-Tools"
        ],
        "products": [
          {
            "vendor": "Stirling-Tools",
            "product": "Stirling-PDF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13643
      },
      "nvd": {
        "published": "2026-07-15T16:16:45.223",
        "lastModified": "2026-07-30T14:30:52.563",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41580",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Stirling-PDF, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Stirling-Tools/Stirling-PDF/security/advisories/GHSA-rjjx-43g5-mp76",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Stirling-Tools/Stirling-PDF/releases/tag/v2.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 405,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41608",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-21T22:14:00.745Z",
      "date_published": "2026-07-27T10:53:43.865Z",
      "date_updated": "2026-07-28T14:54:47.811Z",
      "publisher": "apache",
      "title": "Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01097,
        "percentile": 0.62373
      },
      "nvd": {
        "published": "2026-07-27T12:16:44.277",
        "lastModified": "2026-07-28T16:17:45.907",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41608",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected decompression path limits compressed input without imposing a corresponding limit on expanded output.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/vwsbcwqdpwdtp8qkjo11ol6rodbfm21f",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/32",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41637",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T10:11:10.518Z",
      "date_published": "2026-07-22T13:04:52.605Z",
      "date_updated": "2026-07-22T14:29:25.088Z",
      "publisher": "NLnet Labs",
      "title": "Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-772",
          "name": "Missing Release of Resource after Effective Lifetime",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18284
      },
      "nvd": {
        "published": "2026-07-22T14:17:18.560",
        "lastModified": "2026-07-24T13:57:04.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41637",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Client-terminated DoQ queries retain waiting-reply accounting for in-flight resolutions, allowing repeated resets to fill the wait limit and exclude new clients.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-772"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-41637.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41703",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T06:21:22.982Z",
      "date_published": "2026-07-30T12:39:02.552Z",
      "date_updated": "2026-07-30T15:09:25.467Z",
      "publisher": "vmware",
      "title": "Out-of-bounds read vulnerability",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Cloud Foundation"
          },
          {
            "vendor": "VMware",
            "product": "vSphere Foundation"
          },
          {
            "vendor": "VMware",
            "product": "ESX"
          },
          {
            "vendor": "VMware",
            "product": "Workstation"
          },
          {
            "vendor": "VMware",
            "product": "Fusion"
          },
          {
            "vendor": "VMware",
            "product": "Telco Cloud Platform"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 12,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00556,
        "percentile": 0.43211
      },
      "nvd": {
        "published": "2026-07-30T13:16:49.300",
        "lastModified": "2026-07-30T16:17:11.403",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41703",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Cloud Foundation path reads beyond the validated extent of an attacker-influenced buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-41709",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T06:21:34.490Z",
      "date_published": "2026-07-30T12:45:02.292Z",
      "date_updated": "2026-07-30T15:10:15.160Z",
      "publisher": "vmware",
      "title": "ESX insufficient logging vulnerability",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Cloud Foundation"
          },
          {
            "vendor": "VMware",
            "product": "vSphere Foundation"
          },
          {
            "vendor": "VMware",
            "product": "ESX"
          },
          {
            "vendor": "VMware",
            "product": "Telco Cloud Platform"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 10,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-778",
          "name": "Insufficient Logging",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30895
      },
      "nvd": {
        "published": "2026-07-30T14:16:57.420",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41709",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Security-relevant events are not recorded with sufficient detail for the required audit trail.",
        "basis": [
          "CNA",
          "CWE-778"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 166,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-41857",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T06:22:10.081Z",
      "date_published": "2026-07-09T04:31:33.568Z",
      "date_updated": "2026-07-09T14:12:24.049Z",
      "publisher": "vmware",
      "title": "BOSH CLI Shell Injection",
      "affected": {
        "vendors": [
          "CloudFoundry BOSH"
        ],
        "products": [
          {
            "vendor": "CloudFoundry BOSH",
            "product": "BOSH CLI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04491
      },
      "nvd": {
        "published": "2026-07-09T06:16:20.287",
        "lastModified": "2026-07-13T13:37:39.707",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41857",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The BOSH CLI command path concatenates attacker-controlled data into an operating-system command without preserving the shell grammar boundary.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cloudfoundry.org/blog/cve-2026-41857-bosh-cli-shell-injection/",
          "host": "www.cloudfoundry.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41874",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T10:35:11.713Z",
      "date_published": "2026-07-28T12:02:45.628Z",
      "date_updated": "2026-07-28T19:19:36.287Z",
      "publisher": "CERT-PL",
      "title": "Hard-coded admin credentials in Quick.Cart",
      "affected": {
        "vendors": [
          "OpenSolution"
        ],
        "products": [
          {
            "vendor": "OpenSolution",
            "product": "Quick.Cart"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-256",
          "name": "Plaintext Storage of a Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03215
      },
      "nvd": {
        "published": "2026-07-28T13:18:23.180",
        "lastModified": "2026-07-30T16:29:42.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41874",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The device stores a fixed administrator credential in plaintext rather than protecting or provisioning it per installation.",
        "basis": [
          "CNA",
          "CWE-256"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-41874/",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://opensolution.org/shopping-cart-quick-cart.html",
          "host": "opensolution.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41876",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T11:32:15.204Z",
      "date_published": "2026-07-10T09:05:07.027Z",
      "date_updated": "2026-07-10T10:57:21.972Z",
      "publisher": "CERT-PL",
      "title": "OS Command Injection in R-SOFT DMS",
      "affected": {
        "vendors": [
          "R-SOFT SERWIS"
        ],
        "products": [
          {
            "vendor": "R-SOFT SERWIS",
            "product": "DMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00828,
        "percentile": 0.53965
      },
      "nvd": {
        "published": "2026-07-10T10:16:23.687",
        "lastModified": "2026-07-10T15:46:07.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41876",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The document converter executes shell commands using unsanitized file paths and format parameters.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-41876",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-41877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T11:32:15.204Z",
      "date_published": "2026-07-10T09:05:07.927Z",
      "date_updated": "2026-07-10T10:56:50.110Z",
      "publisher": "CERT-PL",
      "title": "Stored XSS in R-SOFT DMS",
      "affected": {
        "vendors": [
          "R-SOFT SERWIS"
        ],
        "products": [
          {
            "vendor": "R-SOFT SERWIS",
            "product": "DMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16585
      },
      "nvd": {
        "published": "2026-07-10T10:16:23.847",
        "lastModified": "2026-07-10T15:46:07.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41877",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file-upload name is stored and later rendered as active HTML and JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-41876",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-41878",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T11:32:15.204Z",
      "date_published": "2026-07-10T09:05:31.988Z",
      "date_updated": "2026-07-10T10:23:43.264Z",
      "publisher": "CERT-PL",
      "title": "Insecure Direct Object Reference in R-SOFT DMS",
      "affected": {
        "vendors": [
          "R-SOFT SERWIS"
        ],
        "products": [
          {
            "vendor": "R-SOFT SERWIS",
            "product": "DMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21573
      },
      "nvd": {
        "published": "2026-07-10T10:16:23.957",
        "lastModified": "2026-07-10T15:46:07.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41878",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-41876",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 351,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-41879",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T11:32:15.204Z",
      "date_published": "2026-07-10T09:05:47.551Z",
      "date_updated": "2026-07-10T10:19:29.636Z",
      "publisher": "CERT-PL",
      "title": "Weak password hashing in R-SOFT DMS",
      "affected": {
        "vendors": [
          "R-SOFT SERWIS"
        ],
        "products": [
          {
            "vendor": "R-SOFT SERWIS",
            "product": "DMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-328",
          "name": "Use of Weak Hash",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09902
      },
      "nvd": {
        "published": "2026-07-10T10:16:24.077",
        "lastModified": "2026-07-10T15:46:07.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41879",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application derives a super-administrator password with nested unsalted MD5, making offline recovery practical after the verifier is obtained.",
        "basis": [
          "CNA",
          "CWE-328"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-41876",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41880",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T11:32:15.204Z",
      "date_published": "2026-07-10T09:05:10.683Z",
      "date_updated": "2026-07-10T10:55:59.746Z",
      "publisher": "CERT-PL",
      "title": "OS Command Injection in R-SOFT DMS",
      "affected": {
        "vendors": [
          "R-SOFT SERWIS"
        ],
        "products": [
          {
            "vendor": "R-SOFT SERWIS",
            "product": "DMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01011,
        "percentile": 0.59768
      },
      "nvd": {
        "published": "2026-07-10T10:16:24.193",
        "lastModified": "2026-07-10T15:46:07.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41880",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OCR module passes user-controllable file paths to shell commands over SSH without shell-safe argument separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-41876",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 567,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-41899",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T15:11:54.672Z",
      "date_published": "2026-07-06T21:10:40.097Z",
      "date_updated": "2026-07-07T14:00:31.814Z",
      "publisher": "GitHub_M",
      "title": "Coolify unauthenticated feedback endpoint allows Discord webhook abuse",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22255
      },
      "nvd": {
        "published": "2026-07-06T22:16:49.130",
        "lastModified": "2026-07-07T15:16:45.423",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41899",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The feedback endpoint is unauthenticated and unthrottled while forwarding caller-controlled content to the configured Discord webhook.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-v64c-v633-58xp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9653",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/371e883c75a87d82c398bf89ee8ad6387348520d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 386,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41920",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T18:29:52.070Z",
      "date_published": "2026-07-29T07:18:01.534Z",
      "date_updated": "2026-07-29T13:14:49.109Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: SNI to Host header matching policy is not properly enforced",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 2.3000000000000007,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21903
      },
      "nvd": {
        "published": "2026-07-29T08:16:31.420",
        "lastModified": "2026-08-03T13:42:36.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-41920",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Traffic Server compares SNI with Host using only the Host length, so an SNI value with Host as a prefix passes the equality policy.",
        "basis": [
          "CNA",
          "CWE-284",
          "Apache vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d through the official Apache archive API; the advisory identifies a one-sided comparison length and says 9.0.0-9.2.14 is affected with 9.2.15 fixed, whereas the embedded record says through 9.1.14 with 9.1.15 fixed; no patch was inspected and no reproduction was performed."
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 247,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-41939",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-22T18:50:43.621Z",
      "date_published": "2026-07-29T17:39:08.767Z",
      "date_updated": "2026-07-30T13:58:58.433Z",
      "publisher": "VulnCheck",
      "title": "Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly",
      "affected": {
        "vendors": [
          "Care Everywhere LLC"
        ],
        "products": [
          {
            "vendor": "Care Everywhere LLC",
            "product": "Care Everywhere Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1392",
          "name": "Use of Default Credentials",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00801,
        "percentile": 0.53088
      },
      "nvd": {
        "published": "2026-07-29T18:16:53.477",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41939",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The bundled WildFly management interface is exposed with identical default credentials across installations, granting administrative deployment access.",
        "basis": [
          "CNA",
          "CWE-1392"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/VAMorales/95874f23e27e17362b87133013834c0a",
          "host": "gist.github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.intuvie.com/products-overview",
          "host": "www.intuvie.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/care-everywhere-gateway-hard-coded-credentials-rce-via-wildfly",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 622,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-41993",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-23T09:55:13.822Z",
      "date_published": "2026-07-17T03:50:13.217Z",
      "date_updated": "2026-07-27T14:07:43.598Z",
      "publisher": "TXOne",
      "title": "Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a local attacker with administrator privileges to bypass the file lockdown mechanism, resulting in unauthorized file trans...",
      "affected": {
        "vendors": [
          "TXOne Networks"
        ],
        "products": [
          {
            "vendor": "TXOne Networks",
            "product": "SafePortAgent"
          },
          {
            "vendor": "TXOne Networks",
            "product": "StellarProtect"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:3ad20294-822c-4ebc-9301-f9a7cf62d46e",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:3ad20294-822c-4ebc-9301-f9a7cf62d46e",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00102,
        "percentile": 0.01106
      },
      "nvd": {
        "published": "2026-07-17T05:16:39.007",
        "lastModified": "2026-07-27T14:16:52.513",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-41993",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A local administrator can move an unauthorized file through removable-media validation despite the lockdown policy, but the bypassed decision is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.txone.com/psirt/cve-2026-41993/",
          "host": "www.txone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-42016",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-23T13:41:13.754Z",
      "date_published": "2026-07-27T19:20:56.352Z",
      "date_updated": "2026-07-27T20:17:53.907Z",
      "publisher": "JFROG",
      "title": "Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.7000000000000011,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13864
      },
      "nvd": {
        "published": "2026-07-27T20:16:39.613",
        "lastModified": "2026-07-30T14:42:56.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-42016",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Artifactory validates the token signature and issuer but does not enforce the token scope required for the requested action.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42017",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-23T13:41:13.754Z",
      "date_published": "2026-07-27T19:26:23.746Z",
      "date_updated": "2026-07-27T20:18:32.504Z",
      "publisher": "JFROG",
      "title": "Privilege escalation via JFrog Worker event token exposure",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21119
      },
      "nvd": {
        "published": "2026-07-27T20:16:39.750",
        "lastModified": "2026-07-30T14:41:34.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-42017",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Artifactory event path exposes privileged authorization material to a lower-privileged user, but the exact event and output sink are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-42049",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-23T16:05:01.709Z",
      "date_published": "2026-07-14T21:44:25.018Z",
      "date_updated": "2026-07-15T13:26:06.033Z",
      "publisher": "GitHub_M",
      "title": "jadx: RCE Via Groovy Code Injection in Gradle Export",
      "affected": {
        "vendors": [
          "skylot"
        ],
        "products": [
          {
            "vendor": "skylot",
            "product": "jadx"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00151,
        "percentile": 0.04802
      },
      "nvd": {
        "published": "2026-07-14T22:16:52.940",
        "lastModified": "2026-07-15T20:23:47.313",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42049",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An Android manifest version string is inserted into a generated Groovy build file without escaping the surrounding string grammar.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/skylot/jadx/security/advisories/GHSA-w6f5-h4x4-rfpj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/skylot/jadx/commit/5a6e660b4663d998d52c7dc4511299f3368ef611",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/skylot/jadx/releases/tag/v1.5.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-24T17:15:21.834Z",
      "date_published": "2026-07-07T03:15:04.280Z",
      "date_updated": "2026-07-07T14:41:30.787Z",
      "publisher": "GitHub_M",
      "title": "Coolify: OS Command Injection via Persistent Volume Names - Root RCE on Managed Servers",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00435,
        "percentile": 0.3578
      },
      "nvd": {
        "published": "2026-07-07T04:17:51.200",
        "lastModified": "2026-07-07T15:16:46.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42143",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "coolify passes attacker-controlled argument or command text into an operating-system command boundary without neutralizing the command grammar.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-6pmw-6m96-4v4m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/d2064dd4998694cda2eabd00149f7c4d1e94c699",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 450,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-24T17:15:21.834Z",
      "date_published": "2026-07-07T03:03:58.895Z",
      "date_updated": "2026-07-09T14:43:05.636Z",
      "publisher": "GitHub_M",
      "title": "Coolify: File Upload Without Type or Size Validation in Database Backup Restore",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.1638
      },
      "nvd": {
        "published": "2026-07-07T04:17:51.353",
        "lastModified": "2026-07-09T16:16:41.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42145",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The backup-restore upload endpoint accepts files without a size limit, allowing an authenticated user to consume storage or processing capacity.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-434",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-66gv-g2w9-6wxp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9667",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/e6a6446daeace2999fb77888a611a3271812911f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 433,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-24T17:15:21.834Z",
      "date_published": "2026-07-07T03:13:50.436Z",
      "date_updated": "2026-07-07T14:33:48.769Z",
      "publisher": "GitHub_M",
      "title": "Coolify: SSRF via S3 Storage Endpoint in testConnection()",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17054
      },
      "nvd": {
        "published": "2026-07-07T04:17:51.760",
        "lastModified": "2026-07-07T15:16:46.573",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42147",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "coolify lets a caller choose a server-side destination without excluding internal or otherwise untrusted targets.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-pwm4-w33c-wjf3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/297e9c41e19958f6237919794c28c3fb1d4cda32",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 428,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42148",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-24T17:15:21.834Z",
      "date_published": "2026-07-06T21:14:31.801Z",
      "date_updated": "2026-07-07T12:43:59.967Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Command Injection via Unescaped Version String in Docker Build",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02201
      },
      "nvd": {
        "published": "2026-07-06T22:16:49.257",
        "lastModified": "2026-07-07T13:22:13.557",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42148",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "buildHelperImage places dev_helper_version into a Docker shell command without escaping it.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-x9qh-w4c4-54f9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9670",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/dc9322b11f5f4ab96e56af0df7d4f877e96e5e4c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42153",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-24T17:15:21.835Z",
      "date_published": "2026-07-06T21:30:44.813Z",
      "date_updated": "2026-07-07T13:46:55.120Z",
      "publisher": "GitHub_M",
      "title": "Coolify: PostgreSQL Healthcheck Command Injection Allows Root Code Execution in Container",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00359,
        "percentile": 0.28603
      },
      "nvd": {
        "published": "2026-07-06T22:16:49.383",
        "lastModified": "2026-07-07T14:16:30.477",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42153",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Coolify interpolates PostgreSQL user and database settings into a shell-form healthcheck command.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-gvc4-f276-r88p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9674",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/b74f54302b1a857c22c55fe1210d700859b0b3df",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42168",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-24T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-20T18:06:34.329Z",
      "publisher": "mitre",
      "title": "django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system() in pyas2/utils.py without sanitization, allowing an authentica...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01232,
        "percentile": 0.66011
      },
      "nvd": {
        "published": "2026-07-17T20:17:16.410",
        "lastModified": "2026-07-23T18:28:20.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42168",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "django-pyas2 passes Partner cmd_receive and cmd_send values directly to os.system.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/abhishek-ram/django-pyas2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/abhishek-ram/django-pyas2/releases/tag/v1.2.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/m4ty-m/vulnerability-research/tree/main/CVE-2026-42168",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42172",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-25T01:53:21.581Z",
      "date_published": "2026-07-07T02:52:58.684Z",
      "date_updated": "2026-07-07T13:57:00.744Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Sanctum API Tokens Have No Expiration — Leaked Tokens Grant Permanent Access",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08653
      },
      "nvd": {
        "published": "2026-07-07T04:17:52.133",
        "lastModified": "2026-07-07T15:16:46.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42172",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Coolify issues API tokens without an expiration time, so a leaked token remains valid until an operator explicitly revokes it.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-c83f-5ph7-x8xv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9677",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/b1a78df58efe3ac38679d18c888b5817c7f01216",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42200",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-25T05:04:37.027Z",
      "date_published": "2026-07-07T02:48:04.402Z",
      "date_updated": "2026-07-07T12:49:05.094Z",
      "publisher": "GitHub_M",
      "title": "Coolify: PostgreSQL Init Script Path Traversal Leads to Arbitrary File Write and Root RCE",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00542,
        "percentile": 0.42509
      },
      "nvd": {
        "published": "2026-07-07T04:17:52.923",
        "lastModified": "2026-07-07T13:22:13.557",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42200",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 4.0.0-beta.474, PostgreSQL initialization script (generate_init_scripts() method in app/Actions/Database/StartPostgresql.php) filename handling did not sufficiently restrict paths, allowing an authenticated user to write files outside the intended directory and achieve command execution through database initialization.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-mv4c-9x67-rrmv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9681",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/1cf6c7d0aef8e0edb800ae43f44ded102397cb13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 476,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42201",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-25T05:04:37.027Z",
      "date_published": "2026-07-07T03:29:13.739Z",
      "date_updated": "2026-07-07T13:58:15.968Z",
      "publisher": "GitHub_M",
      "title": "Coolify: OS Command Injection via Database Credential Fields in Docker Compose Service Commands",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09456
      },
      "nvd": {
        "published": "2026-07-07T05:16:51.237",
        "lastModified": "2026-07-07T15:16:46.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42201",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler places caller-controlled data in an operating-system command without safe argument separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-f35h-g2c2-q36v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9676",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/bff6d853708f3d7c861279586f107739036e67da",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42204",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-25T05:04:37.027Z",
      "date_published": "2026-07-06T21:17:16.800Z",
      "date_updated": "2026-07-07T14:47:36.729Z",
      "publisher": "GitHub_M",
      "title": "Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00359,
        "percentile": 0.28603
      },
      "nvd": {
        "published": "2026-07-06T22:16:49.510",
        "lastModified": "2026-07-07T15:16:46.867",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42204",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A shell-command validation regression permits ampersands in deployment command fields that are later evaluated by the host shell.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-chg4-63hm-xv9x",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9684",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/e1aac50b745cf499e710b7e35cd2a9d6a1538dd9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 420,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42210",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-25T05:04:37.028Z",
      "date_published": "2026-07-20T17:03:09.650Z",
      "date_updated": "2026-07-20T17:41:48.414Z",
      "publisher": "GitHub_M",
      "title": "Webmin 2FA requirement bypass",
      "affected": {
        "vendors": [
          "webmin"
        ],
        "products": [
          {
            "vendor": "webmin",
            "product": "webmin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34414
      },
      "nvd": {
        "published": "2026-07-20T17:17:08.597",
        "lastModified": "2026-07-23T18:04:31.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42210",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/webmin/webmin/security/advisories/GHSA-qpww-fff2-6fgv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/webmin/webmin/commit/da18a16c84ae5c0b78cad79609cb0efb174000ec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 463,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42218",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-25T05:04:37.028Z",
      "date_published": "2026-07-20T16:44:26.317Z",
      "date_updated": "2026-07-20T17:52:34.118Z",
      "publisher": "GitHub_M",
      "title": "XRDP is vulnerable to a server timing attack, leading to user enumeration",
      "affected": {
        "vendors": [
          "neutrinolabs"
        ],
        "products": [
          {
            "vendor": "neutrinolabs",
            "product": "xrdp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-204",
          "name": "Observable Response Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16424
      },
      "nvd": {
        "published": "2026-07-20T17:17:08.733",
        "lastModified": "2026-07-22T20:07:40.953",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-42218",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "xrdp login responses take measurably different time for existing and nonexistent usernames, creating a remote enumeration oracle.",
        "basis": [
          "CNA",
          "CWE-204"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-3wr5-fwmh-qh34",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 370,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42219",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-25T05:04:37.029Z",
      "date_published": "2026-07-10T21:26:30.005Z",
      "date_updated": "2026-07-13T14:15:58.161Z",
      "publisher": "GitHub_M",
      "title": "Frappe: Path Traversal via /backups Route",
      "affected": {
        "vendors": [
          "frappe"
        ],
        "products": [
          {
            "vendor": "frappe",
            "product": "frappe"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00457,
        "percentile": 0.37414
      },
      "nvd": {
        "published": "2026-07-10T22:16:41.550",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42219",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The backups download route does not confine a caller-selected path to the backup directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frappe/frappe/security/advisories/GHSA-w4p4-fp9m-47gj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/38740",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/39402",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/39403",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/4358f5bd449710027724a1679950d4ea65da6dcc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/a470a1189132984635e2ec148f87de5232f5535d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/a562ef2a5a3885895b9f9cf14d5a53e32e52d326",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/releases/tag/v15.109.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/releases/tag/v16.19.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-42331",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-26T13:26:14.513Z",
      "date_published": "2026-07-06T21:00:07.164Z",
      "date_updated": "2026-07-07T13:51:59.385Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling missing authorization in guest Invoice API endpoints",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16064
      },
      "nvd": {
        "published": "2026-07-06T21:16:55.617",
        "lastModified": "2026-07-07T15:16:46.967",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42331",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A guest invoice endpoint returns protected invoices without authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-8755-w77f-3g7j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 869,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42341",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-26T13:26:14.514Z",
      "date_published": "2026-07-06T20:53:21.391Z",
      "date_updated": "2026-07-07T15:15:36.538Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling has an unauthenticated payment bypass via IPN callback forgery",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08191
      },
      "nvd": {
        "published": "2026-07-06T21:16:55.740",
        "lastModified": "2026-07-07T16:16:39.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42341",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Custom payment IPN callback accepts a payment-state transition without authenticating the callback source.",
        "basis": [
          "CNA record",
          "CWE-306",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-5493-9m76-2qrr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 692,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T08:22:05.096Z",
      "date_published": "2026-07-02T11:15:02.678Z",
      "date_updated": "2026-07-02T12:39:29.644Z",
      "publisher": "Patchstack",
      "title": "WordPress Audrey theme <= 1.5 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "Elated-Themes"
        ],
        "products": [
          {
            "vendor": "Elated-Themes",
            "product": "Audrey"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21676
      },
      "nvd": {
        "published": "2026-07-02T12:17:17.027",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42382",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Audrey lets attacker-controlled include data select executable content outside the intended template namespace.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/audrey/vulnerability/wordpress-audrey-theme-1-5-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 63,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T10:14:34.318Z",
      "date_published": "2026-07-21T19:40:29.205Z",
      "date_updated": "2026-07-22T18:25:52.607Z",
      "publisher": "elastic",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21193
      },
      "nvd": {
        "published": "2026-07-21T20:17:00.593",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42397",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kibana's Entity Analytics endpoints accept an oversized input that drives excessive allocation without an effective request bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-9-3-7-9-4-4-security-update-esa-2026-55/388554/1",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 359,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-42447",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T13:55:58.693Z",
      "date_published": "2026-07-14T21:45:33.878Z",
      "date_updated": "2026-07-15T17:39:26.549Z",
      "publisher": "GitHub_M",
      "title": "jadx: HTML Injection in Summary panel",
      "affected": {
        "vendors": [
          "skylot"
        ],
        "products": [
          {
            "vendor": "skylot",
            "product": "jadx"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 1.4,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09893
      },
      "nvd": {
        "published": "2026-07-14T22:16:53.087",
        "lastModified": "2026-07-30T14:31:31.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-42447",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In jadx, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/skylot/jadx/security/advisories/GHSA-jwv3-q635-w9m4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/skylot/jadx/commit/7713655feeb8e1c4b80797e8fc0e8eb1550b65ef",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/skylot/jadx/releases/tag/v1.5.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 519,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42486",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T14:20:24.138Z",
      "date_published": "2026-07-09T15:16:34.880Z",
      "date_updated": "2026-07-10T03:55:43.730Z",
      "publisher": "XEN",
      "title": "Multiple RBAC issues in XAPI",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "XAPI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-250",
          "name": "Execution with Unnecessary Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@xen.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03323
      },
      "nvd": {
        "published": "2026-07-09T16:16:41.443",
        "lastModified": "2026-07-10T05:16:36.863",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42486",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A lower-privilege role can set a parameter reserved for a more privileged role, so the operation runs with authority the caller should not control.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-250"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xen.org/xsa/advisory-489.html",
          "host": "xenbits.xen.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1843,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T14:20:24.139Z",
      "date_published": "2026-07-28T12:31:28.304Z",
      "date_updated": "2026-07-28T16:33:22.683Z",
      "publisher": "XEN",
      "title": "vIRQ event channel binding may break Xenstore",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-459",
          "name": "Incomplete Cleanup",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00477,
        "percentile": 0.38728
      },
      "nvd": {
        "published": "2026-07-28T13:18:32.123",
        "lastModified": "2026-07-28T17:16:38.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42492",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Xen failure path leaves partially released state reachable by a later operation.",
        "basis": [
          "CNA",
          "CWE-459"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-496.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://xenbits.xen.org/xsa/advisory-496.html",
          "host": "xenbits.xen.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/13",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42493",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T14:20:24.139Z",
      "date_published": "2026-07-28T12:31:11.950Z",
      "date_updated": "2026-07-28T16:33:23.792Z",
      "publisher": "XEN",
      "title": "x86 shadow paging is deprecated",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00474,
        "percentile": 0.38499
      },
      "nvd": {
        "published": "2026-07-28T13:18:32.247",
        "lastModified": "2026-07-28T17:16:39.063",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42493",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Shadow-paging work can run for an excessive duration without an effective work limit or termination rule.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-495.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://xenbits.xen.org/xsa/advisory-495.html",
          "host": "xenbits.xen.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/12",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 411,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42494",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T14:20:24.139Z",
      "date_published": "2026-07-28T12:31:41.682Z",
      "date_updated": "2026-07-28T15:04:48.405Z",
      "publisher": "XEN",
      "title": "buffer overruns in libfsimage iso9660 handling",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01795
      },
      "nvd": {
        "published": "2026-07-28T13:18:32.370",
        "lastModified": "2026-07-28T16:17:48.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42494",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Xen path trusts a length or offset that can read beyond the initialized input buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-497.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 767,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42495",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-27T14:20:24.139Z",
      "date_published": "2026-07-28T12:31:41.743Z",
      "date_updated": "2026-07-28T15:01:03.756Z",
      "publisher": "XEN",
      "title": "buffer overruns in libfsimage iso9660 handling",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10686
      },
      "nvd": {
        "published": "2026-07-28T13:18:32.493",
        "lastModified": "2026-07-28T16:17:49.067",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42495",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libfsimage subtracts attacker-controlled ISO9660 fields when calculating the System Use area and allows the length to underflow.",
        "basis": [
          "CNA",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-497.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 767,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42505",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-28T00:21:12.792Z",
      "date_published": "2026-07-08T15:46:33.407Z",
      "date_updated": "2026-07-08T19:38:17.603Z",
      "publisher": "Go",
      "title": "Invoking Encrypted Client Hello privacy leak in crypto/tls",
      "affected": {
        "vendors": [
          "Go standard library"
        ],
        "products": [
          {
            "vendor": "Go standard library",
            "product": "crypto/tls"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16906
      },
      "nvd": {
        "published": "2026-07-08T17:17:21.497",
        "lastModified": "2026-07-13T17:05:36.303",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-42505",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Go TLS client places ECH PSK identities in the unencrypted ClientHello when it offers ECH, revealing an identity value that the encrypted handshake is intended to hide.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://go.dev/cl/775960",
          "host": "go.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://go.dev/issue/79282",
          "host": "go.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch"
          ]
        },
        {
          "url": "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc",
          "host": "groups.google.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5856",
          "host": "pkg.go.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-42527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-28T11:50:34.288Z",
      "date_published": "2026-07-06T07:55:06.159Z",
      "date_updated": "2026-07-06T18:47:30.650Z",
      "publisher": "apache",
      "title": "Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00625,
        "percentile": 0.46527
      },
      "nvd": {
        "published": "2026-07-06T09:16:35.657",
        "lastModified": "2026-07-07T23:42:40.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-42527",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Camel default deserialization filters admit java.net classes whose deserialization performs attacker-observable DNS lookups.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-42527.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2331,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-42533",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T21:19:09.517Z",
      "date_published": "2026-07-15T14:33:45.810Z",
      "date_updated": "2026-07-29T03:55:24.843Z",
      "publisher": "f5",
      "title": "NGINX Map directive and Regex matching vulnerability",
      "affected": {
        "vendors": [
          "F5"
        ],
        "products": [
          {
            "vendor": "F5",
            "product": "NGINX Plus"
          },
          {
            "vendor": "F5",
            "product": "NGINX Open Source"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.03596,
        "percentile": 0.88301
      },
      "nvd": {
        "published": "2026-07-15T15:16:33.480",
        "lastModified": "2026-07-29T05:16:44.720",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42533",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NGINX preserves regex capture variables across a map evaluation order that can invalidate their backing storage, causing a heap buffer overflow when later referenced.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://my.f5.com/manage/s/article/K000162097",
          "host": "my.f5.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1033,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-42546",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-28T16:56:50.191Z",
      "date_published": "2026-07-06T19:31:56.172Z",
      "date_updated": "2026-07-06T20:51:23.274Z",
      "publisher": "GitHub_M",
      "title": "OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj references",
      "affected": {
        "vendors": [
          "OP-TEE"
        ],
        "products": [
          {
            "vendor": "OP-TEE",
            "product": "optee_os"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01249
      },
      "nvd": {
        "published": "2026-07-06T20:16:33.257",
        "lastModified": "2026-07-07T18:56:18.507",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-42546",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OP-TEE skips mobj_put() when an attribute bitmask takes one branch, retaining an object reference and its memory across repeated calls.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OP-TEE/optee_os/security/advisories/GHSA-c7j8-fgqw-rcgp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1119,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42566",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-28T17:26:12.084Z",
      "date_published": "2026-07-19T23:16:04.835Z",
      "date_updated": "2026-07-21T14:53:42.856Z",
      "publisher": "GitHub_M",
      "title": "Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure",
      "affected": {
        "vendors": [
          "meshtastic"
        ],
        "products": [
          {
            "vendor": "meshtastic",
            "product": "firmware"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20119
      },
      "nvd": {
        "published": "2026-07-20T00:16:58.050",
        "lastModified": "2026-07-22T20:53:07.980",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42566",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Firmware truncation can split a multibyte UTF-8 sequence, and the malformed stored name propagates until the iOS client enters a decode fail-and-retry loop.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/meshtastic/firmware/security/advisories/GHSA-7ph5-2mjv-69h8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/meshtastic/firmware/commit/2cc13a1132d94b66a9505e7f07ee2d3e83bd0c95",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1640,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42792",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-29T18:06:33.251Z",
      "date_published": "2026-07-27T14:58:24.426Z",
      "date_updated": "2026-07-28T09:55:23.932Z",
      "publisher": "EEF",
      "title": "epmd permanent DoS via EMFILE on accept(2) in erts",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-755",
          "name": "Improper Handling of Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.31482
      },
      "nvd": {
        "published": "2026-07-27T16:17:06.257",
        "lastModified": "2026-07-30T17:01:07.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42792",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "epmd has no per-source connection cap and exits on file-descriptor exhaustion instead of treating EMFILE or ENFILE as recoverable.",
        "basis": [
          "CNA",
          "CWE-755",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-h6f3-hx58-xhj6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-42792.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-42792",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/865d203e4a6a8f44179eced9e1428f9259e4a3bb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1176,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-42900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T22:35:54.967Z",
      "date_published": "2026-07-14T17:04:20.414Z",
      "date_updated": "2026-08-03T22:52:48.865Z",
      "publisher": "microsoft",
      "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.3169
      },
      "nvd": {
        "published": "2026-07-14T17:16:47.993",
        "lastModified": "2026-07-23T05:16:30.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-42900",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Concurrent App Store operations can free shared state while another operation still uses it, enabling a use-after-free privilege path.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42900",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 182,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-42933",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T17:14:43.836Z",
      "date_published": "2026-07-23T21:59:50.055Z",
      "date_updated": "2026-07-24T12:39:42.841Z",
      "publisher": "icscert",
      "title": "Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs",
      "affected": {
        "vendors": [
          "Pronetiqs"
        ],
        "products": [
          {
            "vendor": "Pronetiqs",
            "product": "Panduit Intravue"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20712
      },
      "nvd": {
        "published": "2026-07-23T23:16:48.887",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42933",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "IntraVUE exposes an active proxy that forwards attacker traffic across the intended OT segmentation boundary.",
        "basis": [
          "CNA",
          "CWE-441"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42936",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T01:12:30.231Z",
      "date_published": "2026-07-15T05:12:08.548Z",
      "date_updated": "2026-07-15T13:55:25.402Z",
      "publisher": "jpcert",
      "title": "The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries.",
      "affected": {
        "vendors": [
          "SBI SECURITIES Co.,Ltd."
        ],
        "products": [
          {
            "vendor": "SBI SECURITIES Co.,Ltd.",
            "product": "HYPER SBI 2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03951
      },
      "nvd": {
        "published": "2026-07-15T06:16:45.003",
        "lastModified": "2026-07-15T20:27:37.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42936",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The installer searches its working directory for a DLL before a trusted system location and loads an attacker-planted library.",
        "basis": [
          "CNA",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://jvn.jp/en/jp/JVN59875262/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42952",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T16:55:26.126Z",
      "date_published": "2026-07-10T22:09:16.884Z",
      "date_updated": "2026-07-14T14:34:24.114Z",
      "publisher": "icscert",
      "title": "Hydro-Québec Le Circuit Electrique charging station backend Improper Restriction of Excessive Authentication Attempts",
      "affected": {
        "vendors": [
          "Hydro-Québec"
        ],
        "products": [
          {
            "vendor": "Hydro-Québec",
            "product": "Le Circuit Electrique charging station backend"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33139
      },
      "nvd": {
        "published": "2026-07-10T23:16:48.203",
        "lastModified": "2026-07-14T15:17:01.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42952",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The authentication path in Le Circuit Electrique charging station backend accepts repeated guesses without an effective rate, account, or source bound.",
        "basis": [
          "CNA",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.hydroquebec.com/nous-joindre/",
          "host": "www.hydroquebec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-01.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42953",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T15:40:50.751Z",
      "date_published": "2026-07-07T21:39:04.839Z",
      "date_updated": "2026-07-08T13:03:58.052Z",
      "publisher": "icscert",
      "title": "Out-of-bounds write in Labcenter Proteus",
      "affected": {
        "vendors": [
          "Labcenter"
        ],
        "products": [
          {
            "vendor": "Labcenter",
            "product": "Proteus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03855
      },
      "nvd": {
        "published": "2026-07-07T22:16:51.897",
        "lastModified": "2026-07-09T19:48:15.277",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42953",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Proteus copies, writes, or indexes attacker-influenced data without enforcing the destination buffer or object bounds required by the operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-06",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42955",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T10:11:10.510Z",
      "date_published": "2026-07-22T13:05:53.695Z",
      "date_updated": "2026-07-22T14:26:48.806Z",
      "publisher": "NLnet Labs",
      "title": "Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-672",
          "name": "Operation on a Resource after Expiration or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10448
      },
      "nvd": {
        "published": "2026-07-22T14:17:18.680",
        "lastModified": "2026-07-24T13:56:42.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-42955",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unbound lets a client query replace expired parent-side glue and extend that delegation's lifetime by another configured cache TTL.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-672"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42955.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 856,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42958",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T15:40:50.731Z",
      "date_published": "2026-07-07T21:52:25.406Z",
      "date_updated": "2026-07-08T13:05:45.177Z",
      "publisher": "icscert",
      "title": "Use After Free in Labcenter Proteus",
      "affected": {
        "vendors": [
          "Labcenter"
        ],
        "products": [
          {
            "vendor": "Labcenter",
            "product": "Proteus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02886
      },
      "nvd": {
        "published": "2026-07-07T22:16:52.060",
        "lastModified": "2026-07-09T19:48:15.277",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-42958",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Proteus continues to access an object after its storage has been released, allowing invalid heap use and possible corruption.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-06",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-42975",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T23:43:50.745Z",
      "date_published": "2026-07-14T17:04:21.605Z",
      "date_updated": "2026-08-03T22:52:49.980Z",
      "publisher": "microsoft",
      "title": "Windows Bluetooth Port Driver Remote Code Execution",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26441
      },
      "nvd": {
        "published": "2026-07-14T17:16:48.157",
        "lastModified": "2026-07-23T05:16:30.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-42975",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows Bluetooth Port Driver writes beyond a heap allocation while processing adjacent-network input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42975",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 133,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-42982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T23:43:50.745Z",
      "date_published": "2026-07-14T17:04:14.496Z",
      "date_updated": "2026-08-03T22:52:38.759Z",
      "publisher": "microsoft",
      "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1288",
          "name": "Improper Validation of Consistency within Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18932
      },
      "nvd": {
        "published": "2026-07-14T17:16:48.330",
        "lastModified": "2026-07-22T16:17:22.043",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-42982",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows Secure Kernel Mode accepts internally inconsistent input, but the public record does not identify the fields or invariant whose mismatch enables elevation.",
        "basis": [
          "CNA",
          "CWE-1288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42982",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-42990",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-04-30T23:43:50.746Z",
      "date_published": "2026-07-14T17:04:24.048Z",
      "date_updated": "2026-08-03T22:52:52.255Z",
      "publisher": "microsoft",
      "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 20,
        "versionEntryCount": 20,
        "versionRangeCount": 20,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00673,
        "percentile": 0.48558
      },
      "nvd": {
        "published": "2026-07-14T17:16:48.490",
        "lastModified": "2026-07-22T16:17:22.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-42990",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42990",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 20,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-43637",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T18:22:45.642Z",
      "date_published": "2026-07-15T13:54:38.892Z",
      "date_updated": "2026-07-15T14:41:32.022Z",
      "publisher": "VulnCheck",
      "title": "Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py",
      "affected": {
        "vendors": [
          "PreferredAI"
        ],
        "products": [
          {
            "vendor": "PreferredAI",
            "product": "cornac"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.29999999999999893,
      "epss": {
        "score": 0.00425,
        "percentile": 0.34991
      },
      "nvd": {
        "published": "2026-07-15T14:18:10.793",
        "lastModified": "2026-07-15T21:02:41.590",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43637",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Cornac passes archive members to extractall() without rejecting traversal, absolute-path, symlink, or hardlink targets outside the cache directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/PreferredAI/cornac/releases/tag/v2.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/PreferredAI/cornac/pull/709",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/PreferredAI/cornac/commit/8a50be72c11569b6747c6b96d6e31a0a1962f1a8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cornac-path-traversal-via-extract-archive-in-download-py",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43665",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.640Z",
      "date_published": "2026-07-27T20:14:38.088Z",
      "date_updated": "2026-07-28T15:05:24.738Z",
      "publisher": "apple",
      "title": "This issue was addressed with additional entitlement checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00098,
        "percentile": 0.00912
      },
      "nvd": {
        "published": "2026-07-27T21:16:52.457",
        "lastModified": "2026-07-29T17:02:48.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43665",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-43672",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.640Z",
      "date_published": "2026-07-27T20:14:31.558Z",
      "date_updated": "2026-07-28T15:22:49.290Z",
      "publisher": "apple",
      "title": "An authorization issue was addressed with improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01878
      },
      "nvd": {
        "published": "2026-07-27T21:16:52.553",
        "lastModified": "2026-07-29T15:46:50.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43672",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A macOS application can bypass Privacy preferences through an authorization-state error, but Apple does not disclose the state transition or entitlement check.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43673",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.640Z",
      "date_published": "2026-07-27T20:14:40.472Z",
      "date_updated": "2026-07-28T14:58:10.814Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.0253
      },
      "nvd": {
        "published": "2026-07-27T21:16:52.657",
        "lastModified": "2026-07-28T19:31:29.167",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43673",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Processing a crafted audio file corrupts process memory, but the public record does not identify the bounds or lifetime failure.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43681",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.641Z",
      "date_published": "2026-07-27T20:13:55.298Z",
      "date_updated": "2026-07-28T13:52:54.221Z",
      "publisher": "apple",
      "title": "A buffer overflow was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02682
      },
      "nvd": {
        "published": "2026-07-27T21:16:52.920",
        "lastModified": "2026-07-29T15:46:38.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43681",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can overflow a memory buffer.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43682",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.641Z",
      "date_published": "2026-07-27T20:13:22.085Z",
      "date_updated": "2026-07-28T19:04:18.239Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00513,
        "percentile": 0.40895
      },
      "nvd": {
        "published": "2026-07-27T21:16:53.040",
        "lastModified": "2026-07-29T17:03:19.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43682",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Remote HFS input can corrupt kernel memory, but Apple does not disclose the failing bound, allocation, type, or lifetime transition.",
        "basis": [
          "CNA record",
          "CWE-119",
          "Apple security advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.apple.com/en-us/128067; Apple identifies the HFS component and repeats that improved memory handling fixed the issue, without publishing a more specific memory error."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43693",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.642Z",
      "date_published": "2026-07-27T20:12:01.094Z",
      "date_updated": "2026-07-28T03:57:07.853Z",
      "publisher": "apple",
      "title": "A race condition was addressed with improved state handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00097,
        "percentile": 0.00857
      },
      "nvd": {
        "published": "2026-07-27T21:16:53.163",
        "lastModified": "2026-07-29T15:46:42.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43693",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A local macOS privilege transition uses shared state without sufficient synchronization, opening a race that can end with root privileges.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43694",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.642Z",
      "date_published": "2026-07-27T20:13:19.717Z",
      "date_updated": "2026-07-28T14:19:55.911Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34298
      },
      "nvd": {
        "published": "2026-07-27T21:16:53.273",
        "lastModified": "2026-07-29T15:46:12.623",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43694",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The macOS quarantine component permits memory corruption, but Apple's advisory does not identify the object, lifetime transition, or missing bound.",
        "basis": [
          "CNA",
          "CWE-119",
          "Apple security advisory 128067"
        ],
        "deepDive": true,
        "notes": "Primary-source deep dive: https://support.apple.com/en-us/128067 ; Apple identifies the quarantine component and memory handling only, without a public object, bound, or lifetime transition."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.643Z",
      "date_published": "2026-07-27T20:13:31.267Z",
      "date_updated": "2026-07-29T18:31:39.152Z",
      "publisher": "apple",
      "title": "An injection issue was addressed with improved validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04722
      },
      "nvd": {
        "published": "2026-07-27T21:16:53.370",
        "lastModified": "2026-07-29T19:16:45.967",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43698",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In macOS, attacker-controlled text is split into command arguments without neutralizing argument delimiters.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 168,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-43710",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.644Z",
      "date_published": "2026-07-27T20:14:04.775Z",
      "date_updated": "2026-07-28T13:45:11.204Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25226
      },
      "nvd": {
        "published": "2026-07-27T21:16:55.020",
        "lastModified": "2026-07-29T15:45:59.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43710",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple identifies a memory-handling flaw in HFS that can corrupt kernel memory, but it does not publish the invalid operation or lifetime transition.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-119",
          "Apple security content"
        ],
        "deepDive": true,
        "notes": "Inspected Apple security content https://support.apple.com/en-us/128067; it identifies HFS, kernel-memory corruption impact, and improved memory handling, but it does not disclose the invalid operation, source, or patch."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43711",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.644Z",
      "date_published": "2026-07-27T20:13:49.532Z",
      "date_updated": "2026-07-28T14:05:54.426Z",
      "publisher": "apple",
      "title": "A memory corruption issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.0253
      },
      "nvd": {
        "published": "2026-07-27T21:16:55.113",
        "lastModified": "2026-07-28T19:31:36.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43711",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A media component corrupts memory while processing a crafted video, but the public record does not identify the buffer, arithmetic, or lifetime error.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43714",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.644Z",
      "date_published": "2026-07-27T20:12:35.520Z",
      "date_updated": "2026-07-28T14:46:19.018Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved input sanitization.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02941
      },
      "nvd": {
        "published": "2026-07-27T21:16:55.523",
        "lastModified": "2026-07-28T19:31:39.390",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43714",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Apple reports that sanitized input still allowed an app to access protected user data, but does not identify the input, protected object, parser, or permission decision.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-43723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.645Z",
      "date_published": "2026-07-27T20:12:10.516Z",
      "date_updated": "2026-07-28T03:57:06.341Z",
      "publisher": "apple",
      "title": "A path handling issue was addressed with improved validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04604
      },
      "nvd": {
        "published": "2026-07-27T21:16:56.653",
        "lastModified": "2026-07-28T19:31:46.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43723",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Improper path handling lets attacker-controlled input resolve to a filesystem object outside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43728",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.645Z",
      "date_published": "2026-07-27T20:13:22.894Z",
      "date_updated": "2026-07-28T19:06:05.653Z",
      "publisher": "apple",
      "title": "This issue was addressed through improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09424
      },
      "nvd": {
        "published": "2026-07-27T21:16:57.393",
        "lastModified": "2026-07-29T17:03:39.427",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43728",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The macOS Keychain state-management path permits attacker-driven state modification, while the public record does not disclose the conflicting operations.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 161,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.645Z",
      "date_published": "2026-07-27T20:12:59.451Z",
      "date_updated": "2026-07-28T18:39:43.589Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03257
      },
      "nvd": {
        "published": "2026-07-27T21:16:57.487",
        "lastModified": "2026-07-29T20:25:07.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43729",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Processing a crafted image corrupts process memory, but Apple does not disclose the invalid access, size, or lifetime transition.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-43730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.646Z",
      "date_published": "2026-07-27T20:14:12.408Z",
      "date_updated": "2026-07-28T13:36:54.880Z",
      "publisher": "apple",
      "title": "A permissions issue was addressed with additional restrictions.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26401
      },
      "nvd": {
        "published": "2026-07-27T21:16:57.587",
        "lastModified": "2026-07-28T19:31:51.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43730",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The AuthKit permission boundary lets an app derive a user fingerprint, while Apple does not identify the identifier or missing restriction.",
        "basis": [
          "CNA",
          "CWE-200",
          "Apple iOS 26.6 security content"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.apple.com/en-us/128066 and the parallel Apple 26.6 platform notices. Apple locates the issue in AuthKit and says additional permission restrictions prevent app-driven fingerprinting, but does not name the identifier, entitlement, or code path."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-43733",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.646Z",
      "date_published": "2026-07-27T20:12:50.284Z",
      "date_updated": "2026-07-28T14:45:29.520Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03358
      },
      "nvd": {
        "published": "2026-07-27T21:16:58.000",
        "lastModified": "2026-07-28T19:31:56.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43733",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple reports image-triggered memory corruption but does not disclose the affected object, bound, or lifetime error.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.646Z",
      "date_published": "2026-07-27T20:12:39.600Z",
      "date_updated": "2026-07-28T14:56:55.407Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03039
      },
      "nvd": {
        "published": "2026-07-27T21:16:58.420",
        "lastModified": "2026-07-28T19:32:04.280",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43738",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The public record identifies a memory-safety failure but does not disclose the exact buffer, lifetime transition, or invalid access.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-43739",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.646Z",
      "date_published": "2026-07-27T20:12:00.295Z",
      "date_updated": "2026-07-28T16:31:48.011Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02707
      },
      "nvd": {
        "published": "2026-07-27T21:16:58.520",
        "lastModified": "2026-07-29T20:27:20.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43739",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "iOS and iPadOS can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-43744",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.647Z",
      "date_published": "2026-07-27T20:13:07.664Z",
      "date_updated": "2026-07-28T17:55:25.541Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02707
      },
      "nvd": {
        "published": "2026-07-27T21:16:59.093",
        "lastModified": "2026-07-29T20:28:03.027",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43744",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled input reaches a write whose destination boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 313,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.647Z",
      "date_published": "2026-07-27T20:14:06.746Z",
      "date_updated": "2026-07-28T13:40:38.554Z",
      "publisher": "apple",
      "title": "An out-of-bounds read was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02313
      },
      "nvd": {
        "published": "2026-07-27T21:16:59.450",
        "lastModified": "2026-07-28T19:52:50.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43747",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "macOS reads beyond a valid memory object because an input length or pointer is not validated against the available buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43748",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.647Z",
      "date_published": "2026-07-27T20:12:55.333Z",
      "date_updated": "2026-07-28T14:36:11.723Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00358,
        "percentile": 0.28464
      },
      "nvd": {
        "published": "2026-07-27T21:16:59.550",
        "lastModified": "2026-07-28T19:32:10.027",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43748",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An app-controlled operation writes beyond the bounds of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-43749",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.647Z",
      "date_published": "2026-07-27T20:13:26.376Z",
      "date_updated": "2026-07-28T03:57:07.090Z",
      "publisher": "apple",
      "title": "A parsing issue in the handling of directory paths was addressed with improved path validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04694
      },
      "nvd": {
        "published": "2026-07-27T21:16:59.643",
        "lastModified": "2026-07-28T19:52:21.577",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43749",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "macOS accepts a crafted directory path that escapes the intended filesystem scope before the improved path validation.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43750",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:21.647Z",
      "date_published": "2026-07-27T20:13:47.889Z",
      "date_updated": "2026-07-29T19:15:11.198Z",
      "publisher": "apple",
      "title": "A buffer overflow was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00437,
        "percentile": 0.35978
      },
      "nvd": {
        "published": "2026-07-27T21:16:59.747",
        "lastModified": "2026-07-29T20:17:03.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43750",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The macOS path copies input without enforcing the destination buffer size.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 247,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43752",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.815Z",
      "date_published": "2026-07-09T17:19:10.748Z",
      "date_updated": "2026-07-09T18:58:10.863Z",
      "publisher": "apple",
      "title": "An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console.",
      "affected": {
        "vendors": [
          "Claris"
        ],
        "products": [
          {
            "vendor": "Claris",
            "product": "FileMaker Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21128
      },
      "nvd": {
        "published": "2026-07-09T18:16:52.160",
        "lastModified": "2026-07-10T14:34:22.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43752",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The administrative LLM setup accepts a malicious installer upload and executes content selected from that file.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.claris.com/en/s/article/Arbitrary-Code-Execution-Vulnerability-Addressed-in-FileMaker-Server-via-Miniforge-Installer-Upload",
          "host": "community.claris.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43753",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.815Z",
      "date_published": "2026-07-27T20:13:12.387Z",
      "date_updated": "2026-07-28T14:28:20.421Z",
      "publisher": "apple",
      "title": "An out-of-bounds read was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.0673
      },
      "nvd": {
        "published": "2026-07-27T21:16:59.857",
        "lastModified": "2026-07-28T19:32:15.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43753",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In iOS and iPadOS, an attacker-controlled index or length permits a read beyond the valid memory region.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-43754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.815Z",
      "date_published": "2026-07-27T20:12:08.007Z",
      "date_updated": "2026-07-28T16:31:17.193Z",
      "publisher": "apple",
      "title": "This issue was addressed with improved redaction of sensitive information.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.0304
      },
      "nvd": {
        "published": "2026-07-27T21:16:59.957",
        "lastModified": "2026-07-29T17:04:01.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43754",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "macOS returns, logs, or renders sensitive state to a caller that has not passed the authorization or redaction boundary for that data.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.816Z",
      "date_published": "2026-07-27T20:12:32.976Z",
      "date_updated": "2026-07-28T03:57:15.393Z",
      "publisher": "apple",
      "title": "A race condition was addressed with improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00087,
        "percentile": 0.00453
      },
      "nvd": {
        "published": "2026-07-27T21:17:00.060",
        "lastModified": "2026-07-28T19:57:37.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43755",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A macOS race permits an application to reach a root-privileged transition, although Apple does not disclose the shared state or ordering rule.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 168,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-43756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.816Z",
      "date_published": "2026-07-27T20:14:18.280Z",
      "date_updated": "2026-07-28T15:59:39.162Z",
      "publisher": "apple",
      "title": "A logic issue was addressed with improved validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01811
      },
      "nvd": {
        "published": "2026-07-27T21:17:00.157",
        "lastModified": "2026-07-28T19:57:23.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43756",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in macOS, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-200",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43757",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.816Z",
      "date_published": "2026-07-27T20:15:03.194Z",
      "date_updated": "2026-07-28T13:57:04.490Z",
      "publisher": "apple",
      "title": "An out-of-bounds read was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25227
      },
      "nvd": {
        "published": "2026-07-27T21:17:00.257",
        "lastModified": "2026-07-28T19:56:56.693",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43757",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "macOS reads beyond an allocation because the affected component does not enforce the required bounds.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": "Editor attention: Apple describes only unexpected termination, while the embedded record carries a maximum CVSS of 9.8; confirm the scoring provenance before publication."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43758",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.816Z",
      "date_published": "2026-07-27T20:12:18.469Z",
      "date_updated": "2026-07-28T18:40:04.637Z",
      "publisher": "apple",
      "title": "An authorization issue was addressed with improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02941
      },
      "nvd": {
        "published": "2026-07-27T21:17:00.357",
        "lastModified": "2026-07-29T19:34:12.707",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43758",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple CoreMedia uses stale or incorrect authorization state when deciding whether an app may access user data, but the exact state transition is not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-43759",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.816Z",
      "date_published": "2026-07-27T20:12:22.409Z",
      "date_updated": "2026-07-28T14:11:00.388Z",
      "publisher": "apple",
      "title": "An authorization issue was addressed with improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02866
      },
      "nvd": {
        "published": "2026-07-27T21:17:00.457",
        "lastModified": "2026-07-28T19:56:30.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43759",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Apple platform state-management path authorizes an app to access sensitive user data, while the public record does not identify the subject, object, or stale state involved.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 173,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-43760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.816Z",
      "date_published": "2026-07-27T20:14:30.701Z",
      "date_updated": "2026-07-30T16:50:50.738Z",
      "publisher": "apple",
      "title": "An access issue was addressed with improved access restrictions.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15222
      },
      "nvd": {
        "published": "2026-07-27T21:17:00.557",
        "lastModified": "2026-07-30T19:17:30.313",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43760",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An application can cross the intended macOS access restriction and read user-sensitive data, while Apple does not identify the missing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://reverse.put.as/2026/07/29/its-a-pre-auth-stupid/",
          "host": "reverse.put.as",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-43763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.817Z",
      "date_published": "2026-07-27T20:12:27.300Z",
      "date_updated": "2026-07-28T14:24:56.390Z",
      "publisher": "apple",
      "title": "A permissions issue was addressed by removing the vulnerable code.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02494
      },
      "nvd": {
        "published": "2026-07-27T21:17:00.663",
        "lastModified": "2026-07-28T19:55:46.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43763",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public Apple record identifies a sandbox permission failure that lets an app read outside its sandbox but does not disclose the failed check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.817Z",
      "date_published": "2026-07-27T20:12:52.629Z",
      "date_updated": "2026-07-28T14:39:03.078Z",
      "publisher": "apple",
      "title": "An integer overflow was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34297
      },
      "nvd": {
        "published": "2026-07-27T21:17:00.770",
        "lastModified": "2026-07-28T19:55:27.950",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43764",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unchecked integer calculation wraps before the result is used for a memory or bounds decision.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.817Z",
      "date_published": "2026-07-27T20:13:29.604Z",
      "date_updated": "2026-07-28T16:01:32.887Z",
      "publisher": "apple",
      "title": "This issue was addressed with improved handling of symlinks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04131
      },
      "nvd": {
        "published": "2026-07-27T21:17:00.873",
        "lastModified": "2026-07-28T19:55:10.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43765",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A filesystem operation follows an attacker-influenced symbolic link without validating the final target or its ownership.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43766",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.817Z",
      "date_published": "2026-07-27T20:13:41.215Z",
      "date_updated": "2026-07-28T15:54:54.090Z",
      "publisher": "apple",
      "title": "An authorization issue was addressed with improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05663
      },
      "nvd": {
        "published": "2026-07-27T21:17:00.977",
        "lastModified": "2026-07-28T19:54:56.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43766",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A locked-device state permits physical access to protected user information, but Apple does not disclose the missing state-bound authorization check.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.817Z",
      "date_published": "2026-07-27T20:14:13.973Z",
      "date_updated": "2026-07-28T17:36:41.893Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01998
      },
      "nvd": {
        "published": "2026-07-27T21:17:01.080",
        "lastModified": "2026-07-30T14:35:41.590",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43767",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple reports a memory-handling error capable of termination but does not identify whether the failing operation reads or writes out of bounds.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-125",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.817Z",
      "date_published": "2026-07-27T20:13:02.690Z",
      "date_updated": "2026-07-28T17:55:43.809Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02818
      },
      "nvd": {
        "published": "2026-07-27T21:17:01.173",
        "lastModified": "2026-07-29T19:33:13.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43768",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An application can exhaust or mishandle memory until macOS terminates, but the finite resource and missing bound are not public.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.818Z",
      "date_published": "2026-07-27T20:13:16.584Z",
      "date_updated": "2026-07-28T14:25:19.673Z",
      "publisher": "apple",
      "title": "An integer overflow was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38476
      },
      "nvd": {
        "published": "2026-07-27T21:17:01.273",
        "lastModified": "2026-07-29T14:14:39.693",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43769",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer arithmetic can overflow and produce an invalid memory size or offset.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.818Z",
      "date_published": "2026-07-27T20:13:45.419Z",
      "date_updated": "2026-07-28T15:57:35.609Z",
      "publisher": "apple",
      "title": "A race condition was addressed with additional validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00094,
        "percentile": 0.00718
      },
      "nvd": {
        "published": "2026-07-27T21:17:01.377",
        "lastModified": "2026-07-29T14:14:55.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43770",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A race condition lets an application observe sensitive user data during an invalid state transition.",
        "basis": [
          "CNA record",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-43771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.818Z",
      "date_published": "2026-07-27T20:14:08.406Z",
      "date_updated": "2026-07-28T13:39:39.433Z",
      "publisher": "apple",
      "title": "A stack overflow was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04202
      },
      "nvd": {
        "published": "2026-07-27T21:17:01.477",
        "lastModified": "2026-07-28T18:07:16.727",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43771",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "macOS writes attacker-controlled data beyond a stack buffer boundary.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43772",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.818Z",
      "date_published": "2026-07-27T20:12:45.218Z",
      "date_updated": "2026-07-28T15:13:17.492Z",
      "publisher": "apple",
      "title": "A path traversal issue was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04695
      },
      "nvd": {
        "published": "2026-07-27T21:17:01.573",
        "lastModified": "2026-07-28T18:07:07.193",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43772",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A macOS path traversal accepts a path outside the sandbox's intended filesystem namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43773",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.818Z",
      "date_published": "2026-07-27T20:13:35.376Z",
      "date_updated": "2026-07-28T14:11:14.799Z",
      "publisher": "apple",
      "title": "An out-of-bounds read was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34297
      },
      "nvd": {
        "published": "2026-07-27T21:17:01.680",
        "lastModified": "2026-07-28T18:06:56.097",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43773",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In macOS, an attacker-controlled index or length permits a read beyond the valid memory region.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43774",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.818Z",
      "date_published": "2026-07-27T20:12:09.631Z",
      "date_updated": "2026-07-28T16:31:07.588Z",
      "publisher": "apple",
      "title": "An out-of-bounds read was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.0304
      },
      "nvd": {
        "published": "2026-07-27T21:17:01.777",
        "lastModified": "2026-07-29T19:32:51.167",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43774",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected Apple component reads beyond a valid boundary, while the structured record incorrectly labels the flaw as an out-of-bounds write.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43775",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.818Z",
      "date_published": "2026-07-27T20:12:31.398Z",
      "date_updated": "2026-07-28T14:36:58.146Z",
      "publisher": "apple",
      "title": "An authorization issue was addressed with improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.0228
      },
      "nvd": {
        "published": "2026-07-27T21:17:01.880",
        "lastModified": "2026-07-28T20:05:36.170",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43775",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An application can cross an authorization boundary because of incorrect state management, but the protected data, application, and state rule are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-43776",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.818Z",
      "date_published": "2026-07-27T20:14:34.942Z",
      "date_updated": "2026-07-28T03:57:19.188Z",
      "publisher": "apple",
      "title": "A buffer overflow was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05039
      },
      "nvd": {
        "published": "2026-07-27T21:17:01.977",
        "lastModified": "2026-07-28T19:44:17.417",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43776",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The iOS and iPadOS path writes attacker-influenced data beyond the capacity of its destination buffer.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43777",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.819Z",
      "date_published": "2026-07-27T20:14:36.533Z",
      "date_updated": "2026-07-28T14:52:30.889Z",
      "publisher": "apple",
      "title": "This issue was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00511,
        "percentile": 0.40739
      },
      "nvd": {
        "published": "2026-07-27T21:17:02.077",
        "lastModified": "2026-07-28T17:59:08.170",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43777",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Apple reports improved input validation for a remote denial of service but does not disclose the rejected field or causal parser rule.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43778",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.819Z",
      "date_published": "2026-07-27T20:11:57.145Z",
      "date_updated": "2026-07-28T16:32:11.679Z",
      "publisher": "apple",
      "title": "A use after free issue was addressed with improved memory management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0046,
        "percentile": 0.37593
      },
      "nvd": {
        "published": "2026-07-27T21:17:02.203",
        "lastModified": "2026-07-29T20:28:38.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43778",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The iOS and iPadOS path retains or dereferences an object after the object's storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43779",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.819Z",
      "date_published": "2026-07-27T20:12:43.545Z",
      "date_updated": "2026-07-28T15:07:46.063Z",
      "publisher": "apple",
      "title": "A logic issue was addressed with improved restrictions.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.31301
      },
      "nvd": {
        "published": "2026-07-27T21:17:02.307",
        "lastModified": "2026-07-28T17:58:56.950",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43779",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A macOS application can intercept network connections assigned to another process, but Apple does not disclose the ownership or routing check that fails.",
        "basis": [
          "CNA",
          "CWE-284",
          "Apple macOS 26.6 and 14.8.8 security notes"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.apple.com/en-us/128067 and https://support.apple.com/en-us/128072; Apple confirms cross-process network interception and improved restrictions but does not expose the ownership, routing, or entitlement check."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43780",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.819Z",
      "date_published": "2026-07-27T20:12:37.183Z",
      "date_updated": "2026-07-28T14:50:36.126Z",
      "publisher": "apple",
      "title": "An integer overflow was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03256
      },
      "nvd": {
        "published": "2026-07-27T21:17:02.403",
        "lastModified": "2026-07-28T19:44:50.557",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43780",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in iOS and iPadOS, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 296,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43781",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.819Z",
      "date_published": "2026-07-27T20:12:03.627Z",
      "date_updated": "2026-07-28T16:31:29.504Z",
      "publisher": "apple",
      "title": "A race condition was addressed with improved state handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00095,
        "percentile": 0.00774
      },
      "nvd": {
        "published": "2026-07-27T21:17:02.503",
        "lastModified": "2026-07-30T14:35:32.877",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43781",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple reports a race that exposes sensitive user data but does not identify the two operations or shared state.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43782",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.819Z",
      "date_published": "2026-07-27T20:15:00.118Z",
      "date_updated": "2026-07-28T14:26:54.028Z",
      "publisher": "apple",
      "title": "This issue was addressed with improved checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.0228
      },
      "nvd": {
        "published": "2026-07-27T21:17:02.600",
        "lastModified": "2026-07-28T19:47:47.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43782",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43792",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.820Z",
      "date_published": "2026-07-27T20:13:57.724Z",
      "date_updated": "2026-07-28T18:51:57.213Z",
      "publisher": "apple",
      "title": "An authorization issue was addressed with improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "Safari"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16251
      },
      "nvd": {
        "published": "2026-07-27T21:17:02.700",
        "lastModified": "2026-07-29T20:28:58.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43792",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128073",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 172,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-43793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.820Z",
      "date_published": "2026-07-27T20:13:56.959Z",
      "date_updated": "2026-07-28T13:50:37.339Z",
      "publisher": "apple",
      "title": "An issue existed in the handling of environment variables.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34297
      },
      "nvd": {
        "published": "2026-07-27T21:17:02.793",
        "lastModified": "2026-07-28T19:47:57.223",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43793",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Apple identifies DriverKit environment-variable handling and unexpected termination but does not disclose the variable, consumer, invalid state, or failed validation rule.",
        "basis": [
          "CNA",
          "CWE-20",
          "https://support.apple.com/en-us/128067",
          "https://support.apple.com/en-us/128071",
          "https://support.apple.com/en-us/128072"
        ],
        "deepDive": true,
        "notes": "Apple's three macOS advisories consistently identify DriverKit environment-variable handling and a validation fix, but provide no variable name, consumer, crash path, or invalid state."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43796",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.820Z",
      "date_published": "2026-07-27T20:12:42.751Z",
      "date_updated": "2026-07-28T15:05:28.102Z",
      "publisher": "apple",
      "title": "This issue was addressed with improved data protection.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.0294
      },
      "nvd": {
        "published": "2026-07-27T21:17:02.893",
        "lastModified": "2026-07-28T19:48:37.083",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43796",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "iOS and iPadOS makes protected data observable to a caller that should not receive it, while the exact output or storage guard is not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43797",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.820Z",
      "date_published": "2026-07-27T20:11:56.377Z",
      "date_updated": "2026-07-28T16:32:16.843Z",
      "publisher": "apple",
      "title": "This issue was addressed with improved checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02866
      },
      "nvd": {
        "published": "2026-07-27T21:17:03.000",
        "lastModified": "2026-07-29T20:38:54.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43797",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "An app can obtain contact information, but the public record does not identify the missing access or disclosure check.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-43799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.820Z",
      "date_published": "2026-07-27T20:14:35.761Z",
      "date_updated": "2026-07-28T15:17:21.099Z",
      "publisher": "apple",
      "title": "A use after free issue was addressed with improved memory management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0046,
        "percentile": 0.37593
      },
      "nvd": {
        "published": "2026-07-27T21:17:03.100",
        "lastModified": "2026-07-28T18:59:25.940",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43799",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An Apple system component accesses an object after it has been freed because its lifetime was not managed correctly.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 278,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.820Z",
      "date_published": "2026-07-27T20:13:01.912Z",
      "date_updated": "2026-07-28T17:55:49.959Z",
      "publisher": "apple",
      "title": "An information disclosure issue was addressed by removing the vulnerable code.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.0311
      },
      "nvd": {
        "published": "2026-07-27T21:17:03.210",
        "lastModified": "2026-07-29T20:38:25.437",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43800",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "An application can obtain sensitive user data, but the public record does not identify the storage, output, authorization, or memory condition that permits access.",
        "basis": [
          "CNA",
          "NVD"
        ],
        "deepDive": false,
        "notes": "CWE-200 states the consequence and does not establish an engineering cause."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-43801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.820Z",
      "date_published": "2026-07-27T20:13:18.155Z",
      "date_updated": "2026-07-28T14:22:10.106Z",
      "publisher": "apple",
      "title": "This issue was addressed with improved checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.0294
      },
      "nvd": {
        "published": "2026-07-27T21:17:03.337",
        "lastModified": "2026-07-28T18:58:29.487",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43801",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports sensitive-data access and improved checks but does not identify the protected object or failing check.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.820Z",
      "date_published": "2026-07-27T20:13:51.104Z",
      "date_updated": "2026-07-28T14:03:05.282Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34299
      },
      "nvd": {
        "published": "2026-07-27T21:17:03.450",
        "lastModified": "2026-07-28T17:58:49.233",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43802",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CoreVideo writes beyond a buffer because the vulnerable path does not enforce the destination bounds.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43803",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.821Z",
      "date_published": "2026-07-27T20:14:02.024Z",
      "date_updated": "2026-07-28T13:48:30.500Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0057,
        "percentile": 0.43973
      },
      "nvd": {
        "published": "2026-07-27T21:17:03.547",
        "lastModified": "2026-07-28T18:58:03.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43803",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In iOS and iPadOS, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.821Z",
      "date_published": "2026-07-27T20:14:22.292Z",
      "date_updated": "2026-07-28T16:00:41.528Z",
      "publisher": "apple",
      "title": "This issue was addressed through improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "Safari"
          },
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22757
      },
      "nvd": {
        "published": "2026-07-27T21:17:03.650",
        "lastModified": "2026-07-28T18:57:36.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43804",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Safari's website-processing state can enter an inconsistent condition that is not recovered or bounded, allowing a page to leave the app unavailable.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128073",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-43805",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.821Z",
      "date_published": "2026-07-27T20:14:59.348Z",
      "date_updated": "2026-07-28T14:35:20.451Z",
      "publisher": "apple",
      "title": "A race condition was addressed with improved state handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18965
      },
      "nvd": {
        "published": "2026-07-27T21:17:03.747",
        "lastModified": "2026-07-28T18:57:06.837",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43805",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An IOKit race violates kernel state ordering and can permit kernel-memory writes, while Apple does not publish the raced object or transition.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Apple's iOS 26.6 and macOS Tahoe 26.6 security pages at https://support.apple.com/en-us/128066 and https://support.apple.com/en-us/128067; they identify IOKit, a race condition, and improved state handling but do not publish the raced object or patch."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 266,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-43806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.821Z",
      "date_published": "2026-07-27T20:12:02.748Z",
      "date_updated": "2026-07-28T16:31:35.587Z",
      "publisher": "apple",
      "title": "A denial of service issue was addressed by removing the vulnerable code.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00108,
        "percentile": 0.0138
      },
      "nvd": {
        "published": "2026-07-27T21:17:03.850",
        "lastModified": "2026-07-30T14:35:23.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43806",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record reports attacker-triggered denial of service in macOS, but does not identify the unbounded work or unreleased resource.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 172,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.821Z",
      "date_published": "2026-07-27T20:12:38.834Z",
      "date_updated": "2026-07-28T14:53:39.239Z",
      "publisher": "apple",
      "title": "A buffer overflow was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00523,
        "percentile": 0.41445
      },
      "nvd": {
        "published": "2026-07-27T21:17:03.950",
        "lastModified": "2026-07-28T18:56:41.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43807",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected Apple component permits a buffer overflow because input length is not sufficiently bounded, but the exact buffer and copy operation are not public.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": "Editor attention: Apple describes only unexpected termination, while the embedded record carries a maximum CVSS of 9.8; confirm the scoring provenance before publication."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/127594",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/127595",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43809",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.821Z",
      "date_published": "2026-07-27T20:14:38.896Z",
      "date_updated": "2026-07-28T15:03:31.388Z",
      "publisher": "apple",
      "title": "An out-of-bounds read was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34299
      },
      "nvd": {
        "published": "2026-07-27T21:17:04.043",
        "lastModified": "2026-07-28T17:58:42.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43809",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A macOS component reads beyond a buffer because it does not enforce the required bounds.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43810",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.821Z",
      "date_published": "2026-07-27T20:11:59.520Z",
      "date_updated": "2026-07-28T16:31:53.676Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0057,
        "percentile": 0.43972
      },
      "nvd": {
        "published": "2026-07-27T21:17:04.140",
        "lastModified": "2026-07-29T20:37:53.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43810",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Apple kernel path mishandles memory and permits remote kernel memory corruption, while the public advisories do not disclose the lifetime or bounds error.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-416",
          "CWE-787",
          "Apple security content 128066"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.apple.com/en-us/128066; Apple identifies the Kernel component and says improved memory handling fixed remote termination or kernel-memory corruption, but it does not expose a source path or memory transition."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 7,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43811",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.821Z",
      "date_published": "2026-07-27T20:12:41.186Z",
      "date_updated": "2026-07-28T15:00:29.185Z",
      "publisher": "apple",
      "title": "A race condition was addressed with improved checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0008,
        "percentile": 0.00229
      },
      "nvd": {
        "published": "2026-07-27T21:17:04.237",
        "lastModified": "2026-07-28T18:56:16.037",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43811",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A race in the protected-filesystem update path lets an application modify protected content before the relevant state check completes.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 166,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.821Z",
      "date_published": "2026-07-27T20:14:24.050Z",
      "date_updated": "2026-07-28T15:40:50.526Z",
      "publisher": "apple",
      "title": "A use after free issue was addressed with improved memory management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34477
      },
      "nvd": {
        "published": "2026-07-27T21:17:04.330",
        "lastModified": "2026-07-28T20:05:06.560",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43812",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A use after free issue was addressed with improved memory management.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-43813",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.821Z",
      "date_published": "2026-07-27T20:14:56.977Z",
      "date_updated": "2026-07-28T14:25:47.377Z",
      "publisher": "apple",
      "title": "A validation issue was addressed with improved input sanitization.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02896
      },
      "nvd": {
        "published": "2026-07-27T21:17:04.430",
        "lastModified": "2026-07-28T20:04:46.760",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43813",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Apple reports that malformed app input could bypass code-signing enforcement, but the public record does not identify the parser, trust decision, or failing check.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": "The public record does not expose enough implementation detail to classify the enabling cause."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 247,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-43814",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.821Z",
      "date_published": "2026-07-27T20:13:53.540Z",
      "date_updated": "2026-07-28T14:01:14.548Z",
      "publisher": "apple",
      "title": "A use after free issue was addressed with improved memory management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34478
      },
      "nvd": {
        "published": "2026-07-27T21:17:04.527",
        "lastModified": "2026-07-28T20:04:06.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43814",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "iOS and iPadOS can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-43816",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.822Z",
      "date_published": "2026-07-27T20:13:00.236Z",
      "date_updated": "2026-07-28T17:55:55.633Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02706
      },
      "nvd": {
        "published": "2026-07-27T21:17:04.623",
        "lastModified": "2026-07-29T20:37:15.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43816",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled input reaches a write whose destination boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-43817",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.822Z",
      "date_published": "2026-07-27T20:13:21.313Z",
      "date_updated": "2026-07-28T17:55:13.418Z",
      "publisher": "apple",
      "title": "An out-of-bounds read was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02708
      },
      "nvd": {
        "published": "2026-07-27T21:17:04.720",
        "lastModified": "2026-07-29T20:36:38.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43817",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "iOS and iPadOS reads beyond a valid memory object because an input length or pointer is not validated against the available buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-43818",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.822Z",
      "date_published": "2026-07-27T20:13:44.522Z",
      "date_updated": "2026-07-29T03:55:31.511Z",
      "publisher": "apple",
      "title": "An integer overflow was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31547
      },
      "nvd": {
        "published": "2026-07-27T21:17:04.817",
        "lastModified": "2026-07-29T05:16:45.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43818",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Image parsing permits integer arithmetic to wrap and produce an invalid memory size or offset.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-43819",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.822Z",
      "date_published": "2026-07-27T20:14:09.183Z",
      "date_updated": "2026-07-28T15:54:04.911Z",
      "publisher": "apple",
      "title": "An access issue was addressed with additional sandbox restrictions.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02465
      },
      "nvd": {
        "published": "2026-07-27T21:17:04.913",
        "lastModified": "2026-07-28T20:02:29.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43819",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A sandboxed process gains access beyond its intended boundary, but the public record does not identify the protected object or missing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 158,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43820",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.822Z",
      "date_published": "2026-07-23T14:33:20.551Z",
      "date_updated": "2026-07-24T20:09:49.866Z",
      "publisher": "apple",
      "title": "NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer...",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "swift-nio-ssl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00078,
        "percentile": 0.00171
      },
      "nvd": {
        "published": "2026-07-23T15:17:05.503",
        "lastModified": "2026-07-24T21:16:44.627",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43820",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NIOSSLCertificate treats every SAN as ASN1_STRING-backed and reads a raw buffer out of bounds for SAN types with a different representation.",
        "basis": [
          "CNA record",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apple/swift-nio-ssl/security/advisories/GHSA-xfxg-9975-pc2j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 359,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.822Z",
      "date_published": "2026-07-27T20:13:27.950Z",
      "date_updated": "2026-07-28T19:12:45.961Z",
      "publisher": "apple",
      "title": "An access issue was addressed with improved access restrictions.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "Safari"
          },
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23411
      },
      "nvd": {
        "published": "2026-07-27T21:17:05.010",
        "lastModified": "2026-07-29T19:56:58.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43821",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Safari permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128073",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-43822",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.822Z",
      "date_published": "2026-07-27T20:13:39.570Z",
      "date_updated": "2026-07-28T15:59:51.652Z",
      "publisher": "apple",
      "title": "A use after free issue was addressed with improved memory management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0046,
        "percentile": 0.37593
      },
      "nvd": {
        "published": "2026-07-27T21:17:05.110",
        "lastModified": "2026-07-28T20:01:26.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43822",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An Apple component accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 278,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-43823",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-01T22:46:27.822Z",
      "date_published": "2026-07-23T14:33:20.924Z",
      "date_updated": "2026-07-23T18:12:10.258Z",
      "publisher": "apple",
      "title": "When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "swift-crypto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17091
      },
      "nvd": {
        "published": "2026-07-23T15:17:05.613",
        "lastModified": "2026-07-23T19:16:54.017",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43823",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In swift-crypto, one error or cleanup path releases the same allocation twice.",
        "basis": [
          "CNA",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apple/swift-crypto/security/advisories/GHSA-8q93-f6xh-4f6f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 365,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43825",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-02T08:57:20.984Z",
      "date_published": "2026-07-06T15:42:04.928Z",
      "date_updated": "2026-07-06T20:38:00.073Z",
      "publisher": "apache",
      "title": "Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache OpenNLP :: Core :: ML :: LibSVM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.08796,
        "percentile": 0.94654
      },
      "nvd": {
        "published": "2026-07-06T17:16:31.570",
        "lastModified": "2026-07-08T19:46:24.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43825",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled serialized data is passed to a native object deserializer that can instantiate executable object graphs.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/c7kom0pgk9cbpfnbooh5m3g85ndf50hn",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/06/9",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1573,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43829",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T03:13:26.241Z",
      "date_published": "2026-07-31T02:48:23.886Z",
      "date_updated": "2026-07-31T19:48:20.994Z",
      "publisher": "CSA",
      "title": "tbc",
      "affected": {
        "vendors": [
          "tbc"
        ],
        "products": [
          {
            "vendor": "tbc",
            "product": "tbc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15775
      },
      "nvd": {
        "published": "2026-07-31T04:17:20.193",
        "lastModified": "2026-07-31T20:16:50.317",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43829",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record assigns a stack-buffer-overflow weakness while withholding all technical details, so the affected buffer and copy path are unknown.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-xxx",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43830",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T03:13:26.241Z",
      "date_published": "2026-07-31T02:53:27.625Z",
      "date_updated": "2026-07-31T19:52:41.957Z",
      "publisher": "CSA",
      "title": "tbc",
      "affected": {
        "vendors": [
          "tbc"
        ],
        "products": [
          {
            "vendor": "tbc",
            "product": "tbc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23757
      },
      "nvd": {
        "published": "2026-07-31T04:17:21.760",
        "lastModified": "2026-07-31T20:16:50.463",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43830",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record withholds the product and all technical details, so the appended command-injection label does not reveal a public input, interpreter sink, or failing neutralization step.",
        "basis": [
          "CNA",
          "CWE-77",
          "CSA alerts index"
        ],
        "deepDive": true,
        "notes": "Inspected the supplied CSA URL https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-xxx and the current CSA alerts index https://www.csa.gov.sg/alerts-and-advisories/alerts/. The supplied route is a placeholder and no matching public alert disclosed a product, input, command sink, or mitigation; the record itself says details remain restricted, so the CWE-77 label alone cannot establish a public mechanism."
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-xxx",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43831",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T03:13:26.241Z",
      "date_published": "2026-07-31T02:57:11.653Z",
      "date_updated": "2026-07-31T19:57:05.874Z",
      "publisher": "CSA",
      "title": "tbc",
      "affected": {
        "vendors": [
          "tbc"
        ],
        "products": [
          {
            "vendor": "tbc",
            "product": "tbc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15778
      },
      "nvd": {
        "published": "2026-07-31T04:17:21.963",
        "lastModified": "2026-07-31T20:16:50.620",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43831",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "The restricted record identifies a stack overflow but publishes no input, size calculation, or overwritten object.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-xxx",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43832",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T03:13:26.242Z",
      "date_published": "2026-07-31T03:00:49.264Z",
      "date_updated": "2026-07-31T20:02:04.158Z",
      "publisher": "CSA",
      "title": "tbc",
      "affected": {
        "vendors": [
          "tbc"
        ],
        "products": [
          {
            "vendor": "tbc",
            "product": "tbc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15776
      },
      "nvd": {
        "published": "2026-07-31T04:17:22.187",
        "lastModified": "2026-07-31T20:16:50.777",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43832",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The tbc parser or handler can copy attacker-controlled data beyond the bounds of a stack allocation.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-xxx",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43833",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T03:13:26.242Z",
      "date_published": "2026-07-31T03:04:02.005Z",
      "date_updated": "2026-08-03T17:10:15.535Z",
      "publisher": "CSA",
      "title": "tbc",
      "affected": {
        "vendors": [
          "tbc"
        ],
        "products": [
          {
            "vendor": "tbc",
            "product": "tbc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09727
      },
      "nvd": {
        "published": "2026-07-31T04:17:22.380",
        "lastModified": "2026-08-03T18:16:39.053",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43833",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record withholds technical details and therefore exposes no defensible enabling cause.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-xxx",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43865",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T11:38:52.245Z",
      "date_published": "2026-07-06T07:55:26.650Z",
      "date_updated": "2026-07-06T18:46:19.640Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00972,
        "percentile": 0.5852
      },
      "nvd": {
        "published": "2026-07-06T09:16:35.787",
        "lastModified": "2026-07-07T23:38:55.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43865",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Camel-created Hazelcast instances omit a Java deserialization filter, so a cluster participant can make Hazelcast ObjectInputStream deserialize a crafted object before Camel processes it.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-43865.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/5",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2325,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-43866",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T11:44:06.700Z",
      "date_published": "2026-07-06T08:35:04.935Z",
      "date_updated": "2026-07-06T19:10:00.576Z",
      "publisher": "apache",
      "title": "Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00617,
        "percentile": 0.46149
      },
      "nvd": {
        "published": "2026-07-06T09:16:35.913",
        "lastModified": "2026-07-07T23:35:44.433",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43866",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Camel JMS deserializes an attacker-controlled Java object without restricting it to safe message types.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-43866.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 3110,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-43867",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T11:46:36.123Z",
      "date_published": "2026-07-06T08:24:10.108Z",
      "date_updated": "2026-07-06T19:27:29.706Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00893,
        "percentile": 0.55962
      },
      "nvd": {
        "published": "2026-07-06T09:16:36.057",
        "lastModified": "2026-07-07T23:33:09.727",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43867",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AwsSecretsManagerKeyLifecycleManager passes attacker-writable metadata to raw ObjectInputStream.readObject() before checking that the result is KeyMetadata.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": "The CNA explicitly states that this is the same underlying code path and fix as CVE-2026-46590 and an incomplete-remediation follow-on to CVE-2026-40048; corpus-level deduplication is required."
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-43867.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1883,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-43871",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T14:27:51.562Z",
      "date_published": "2026-07-27T10:56:15.279Z",
      "date_updated": "2026-07-27T13:01:39.993Z",
      "publisher": "apache",
      "title": "Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.01074,
        "percentile": 0.61682
      },
      "nvd": {
        "published": "2026-07-27T12:16:44.413",
        "lastModified": "2026-07-27T19:51:36.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-43871",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input can leave a processing loop without a reachable exit condition, consuming CPU until the operation is terminated.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/33",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-43910",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T16:11:33.086Z",
      "date_published": "2026-07-28T15:38:24.102Z",
      "date_updated": "2026-07-28T17:07:24.613Z",
      "publisher": "GitHub_M",
      "title": "Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor",
      "affected": {
        "vendors": [
          "appium"
        ],
        "products": [
          {
            "vendor": "appium",
            "product": "java-client"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14597
      },
      "nvd": {
        "published": "2026-07-28T16:18:12.440",
        "lastModified": "2026-07-30T19:17:21.870",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43910",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server accepts an attacker-controlled destination without constraining the resolved request target to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-441",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/appium/java-client/security/advisories/GHSA-28f5-38xr-jh2w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/appium/java-client/pull/2408",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/appium/java-client/commit/2b9cd442b9dbf56ccc6f1e83aeeb411c0ec230c9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/appium/java-client/releases/tag/v10.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 775,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43918",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T16:11:33.086Z",
      "date_published": "2026-07-06T21:18:31.172Z",
      "date_updated": "2026-07-08T19:41:57.803Z",
      "publisher": "GitHub_M",
      "title": "Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14545
      },
      "nvd": {
        "published": "2026-07-06T22:16:49.707",
        "lastModified": "2026-07-08T20:16:49.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43918",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Session identity loaders check only whether the account record exists and do not revoke sessions when the backing account becomes suspended or inactive.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-qv6c-v49w-8g2j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/releases/tag/0.8.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 595,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43921",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T16:11:33.086Z",
      "date_published": "2026-07-06T21:38:49.078Z",
      "date_updated": "2026-07-07T14:25:36.796Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serialization",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19544
      },
      "nvd": {
        "published": "2026-07-06T22:16:49.837",
        "lastModified": "2026-07-07T15:16:47.073",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43921",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Config serialization writes an unescaped single quote into executable config.php, which is then included as PHP code on each request.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-v4j9-w6pj-38w5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 761,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43925",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T16:59:09.089Z",
      "date_published": "2026-07-06T21:41:00.174Z",
      "date_updated": "2026-07-07T13:59:47.123Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22103
      },
      "nvd": {
        "published": "2026-07-06T22:16:49.963",
        "lastModified": "2026-07-07T15:16:47.183",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43925",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The self-registration endpoint mass-assigns a caller-supplied client group, allowing a new user to claim group-restricted discounts.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-q4rq-9844-r9w2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 609,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43927",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T16:59:09.089Z",
      "date_published": "2026-07-06T21:49:26.181Z",
      "date_updated": "2026-07-07T12:47:00.755Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling has race condition in cart checkout that bypasses promo code usage limits",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12621
      },
      "nvd": {
        "published": "2026-07-06T22:16:50.083",
        "lastModified": "2026-07-07T13:22:13.557",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43927",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Concurrent checkout requests all validate a promo code before any request commits the usage increment, allowing its maximum-use invariant to be exceeded.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-w898-cx35-25gh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 651,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43928",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T16:59:09.089Z",
      "date_published": "2026-07-06T21:53:31.172Z",
      "date_updated": "2026-07-07T13:39:52.513Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.1953
      },
      "nvd": {
        "published": "2026-07-06T22:16:50.210",
        "lastModified": "2026-07-07T14:16:30.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43928",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PayPal adapter credits the callback-supplied amount without matching it to the invoice total, and a floating-point tolerance marks a short payment as complete.",
        "basis": [
          "CNA",
          "CWE-754",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-xjc6-g382-h942",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 761,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43945",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T16:59:09.090Z",
      "date_published": "2026-07-21T21:24:59.259Z",
      "date_updated": "2026-07-22T18:24:33.883Z",
      "publisher": "GitHub_M",
      "title": "FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection",
      "affected": {
        "vendors": [
          "frangoteam"
        ],
        "products": [
          {
            "vendor": "frangoteam",
            "product": "FUXA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00862,
        "percentile": 0.55025
      },
      "nvd": {
        "published": "2026-07-21T22:17:01.250",
        "lastModified": "2026-07-23T15:49:31.790",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43945",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FUXA exposes an alternate unauthenticated path that bypasses its configured secure-mode and Node-RED authentication controls.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-284",
          "CWE-288",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frangoteam/FUXA/security/advisories/GHSA-p69w-mmfv-xrfj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/frangoteam/FUXA/releases/tag/v1.3.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 365,
        "referenceCount": 2,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43946",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T16:59:09.090Z",
      "date_published": "2026-07-21T21:27:29.248Z",
      "date_updated": "2026-07-22T15:02:58.663Z",
      "publisher": "GitHub_M",
      "title": "FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue",
      "affected": {
        "vendors": [
          "frangoteam"
        ],
        "products": [
          {
            "vendor": "frangoteam",
            "product": "FUXA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00542,
        "percentile": 0.42532
      },
      "nvd": {
        "published": "2026-07-21T22:17:01.410",
        "lastModified": "2026-07-23T15:49:31.790",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43946",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frangoteam/FUXA/security/advisories/GHSA-fwcm-rqvw-j3p7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/frangoteam/FUXA/pull/2260",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frangoteam/FUXA/commit/78534da61a91613712b44bb63c8d7da8c5df5ca4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frangoteam/FUXA/releases/tag/v1.3.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43947",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T16:59:09.090Z",
      "date_published": "2026-07-21T21:33:09.631Z",
      "date_updated": "2026-07-23T13:57:18.426Z",
      "publisher": "GitHub_M",
      "title": "FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass",
      "affected": {
        "vendors": [
          "frangoteam"
        ],
        "products": [
          {
            "vendor": "frangoteam",
            "product": "FUXA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00666,
        "percentile": 0.48268
      },
      "nvd": {
        "published": "2026-07-21T22:17:01.560",
        "lastModified": "2026-07-23T15:49:31.790",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43947",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "FUXA fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frangoteam/FUXA/security/advisories/GHSA-rg3m-cfq7-g6h6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/frangoteam/FUXA/pull/2260",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frangoteam/FUXA/commit/78534da61a91613712b44bb63c8d7da8c5df5ca4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frangoteam/FUXA/releases/tag/v1.3.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 865,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43977",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T20:24:31.916Z",
      "date_published": "2026-07-16T22:13:12.238Z",
      "date_updated": "2026-07-17T13:14:37.507Z",
      "publisher": "GitHub_M",
      "title": "wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API",
      "affected": {
        "vendors": [
          "wger-project"
        ],
        "products": [
          {
            "vendor": "wger-project",
            "product": "wger"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14169
      },
      "nvd": {
        "published": "2026-07-16T23:16:16.167",
        "lastModified": "2026-07-17T18:42:17.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43977",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RoutinePermission treats every template routine as readable and the logs and stats actions then return the owner's private data instead of the caller's.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wger-project/wger/security/advisories/GHSA-cj9g-27ph-4cgv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 894,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-43978",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T20:24:31.916Z",
      "date_published": "2026-07-16T22:11:57.629Z",
      "date_updated": "2026-07-17T10:49:37.286Z",
      "publisher": "GitHub_M",
      "title": "wger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managers",
      "affected": {
        "vendors": [
          "wger-project"
        ],
        "products": [
          {
            "vendor": "wger-project",
            "product": "wger"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11693
      },
      "nvd": {
        "published": "2026-07-16T23:16:16.310",
        "lastModified": "2026-07-17T18:42:17.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-43978",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "After one legitimate trainer switch, wger treats the trainer.identity session flag alone as permission for later switches into higher-privileged accounts.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wger-project/wger/security/advisories/GHSA-9qpr-vc49-hqg2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 683,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44019",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T21:24:36.506Z",
      "date_published": "2026-07-16T20:50:08.807Z",
      "date_updated": "2026-07-17T17:50:50.083Z",
      "publisher": "GitHub_M",
      "title": "Docling Core has insufficient validation of image reference URIs",
      "affected": {
        "vendors": [
          "docling-project"
        ],
        "products": [
          {
            "vendor": "docling-project",
            "product": "docling-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14594
      },
      "nvd": {
        "published": "2026-07-16T21:17:20.917",
        "lastModified": "2026-07-17T18:36:41.143",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44019",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Docling accepts file URI image references outside the document namespace and also decodes inline data without a size bound.",
        "basis": [
          "CNA",
          "CWE-73",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/docling-project/docling-core/security/advisories/GHSA-j5xp-7m2f-49jv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/docling-project/docling-core/releases/tag/v2.74.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 485,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44023",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T21:24:36.506Z",
      "date_published": "2026-07-16T21:00:49.617Z",
      "date_updated": "2026-07-17T18:06:33.532Z",
      "publisher": "GitHub_M",
      "title": "Docling Core has unsafe remote filename resolution",
      "affected": {
        "vendors": [
          "docling-project"
        ],
        "products": [
          {
            "vendor": "docling-project",
            "product": "docling-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20829
      },
      "nvd": {
        "published": "2026-07-16T21:17:21.123",
        "lastModified": "2026-07-30T14:27:27.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44023",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Docling resolves a remote Content-Disposition filename to a local path without confining it to the configured cache directory.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/docling-project/docling-core/security/advisories/GHSA-jmmv-h3mp-59v8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/docling-project/docling-core/releases/tag/v2.74.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 498,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44024",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T21:24:36.506Z",
      "date_published": "2026-07-08T21:20:29.598Z",
      "date_updated": "2026-07-10T03:55:45.194Z",
      "publisher": "GitHub_M",
      "title": "Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder",
      "affected": {
        "vendors": [
          "fluent"
        ],
        "products": [
          {
            "vendor": "fluent",
            "product": "fluentd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01092,
        "percentile": 0.62154
      },
      "nvd": {
        "published": "2026-07-08T22:17:14.337",
        "lastModified": "2026-07-13T18:48:53.893",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44024",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fluentd constructs an output path from attacker-influenced event data without constraining the resolved file to the configured output directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fluent/fluentd/security/advisories/GHSA-44hj-4m45-frj3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/fluent/fluentd/pull/5391",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/fluent/fluentd/commit/45c87a81f3ac0b72b3f9dcfe8cfb5f9038f81437",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/fluent/fluentd/releases/tag/v1.19.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 529,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44025",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-04T21:24:36.506Z",
      "date_published": "2026-07-08T21:23:16.920Z",
      "date_updated": "2026-07-09T13:47:17.414Z",
      "publisher": "GitHub_M",
      "title": "Fluentd: Exposure of Sensitive Information via Monitor Agent API",
      "affected": {
        "vendors": [
          "fluent"
        ],
        "products": [
          {
            "vendor": "fluent",
            "product": "fluentd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00414,
        "percentile": 0.34065
      },
      "nvd": {
        "published": "2026-07-08T22:17:14.473",
        "lastModified": "2026-07-16T14:31:07.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44025",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fluentd exposes the monitor-agent API without the required access boundary and serializes internal instance variables that can contain credentials.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fluent/fluentd/security/advisories/GHSA-pr7j-96cj-549h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/fluent/fluentd/pull/5392",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/fluent/fluentd/commit/990921518971699b9a97441970674d1800e29177",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/fluent/fluentd/releases/tag/v1.19.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 467,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44040",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T03:40:37.003Z",
      "date_published": "2026-07-01T03:33:20.355Z",
      "date_updated": "2026-07-09T04:36:05.643Z",
      "publisher": "securin",
      "title": "UltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authentication challenge bytes",
      "affected": {
        "vendors": [
          "uvnc"
        ],
        "products": [
          {
            "vendor": "uvnc",
            "product": "UltraVNC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.7000000000000002,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20526
      },
      "nvd": {
        "published": "2026-07-01T05:16:20.897",
        "lastModified": "2026-07-09T06:16:20.777",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44040",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "UltraVNC through 1.8.2.2 uses a cryptographically weak pseudo-random number generator to produce VNC authentication challenge bytes.",
        "basis": [
          "CNA",
          "CWE-338"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://uvnc.com/",
          "host": "uvnc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/ultravnc/UltraVNC",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.securin.io/zero-days/cve-2026-44040-libc-rand-weak-rng-vnc-auth-challenge-ultravnc",
          "host": "www.securin.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 827,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44041",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T03:40:37.003Z",
      "date_published": "2026-07-01T03:33:19.127Z",
      "date_updated": "2026-07-09T04:36:09.188Z",
      "publisher": "securin",
      "title": "UltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminated",
      "affected": {
        "vendors": [
          "uvnc"
        ],
        "products": [
          {
            "vendor": "uvnc",
            "product": "UltraVNC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24012
      },
      "nvd": {
        "published": "2026-07-01T05:16:21.033",
        "lastModified": "2026-07-09T06:16:21.010",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44041",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "vncWc2Mb calls wcslen() on a caller-supplied wide string before proving that the buffer contains a terminating NUL.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://uvnc.com/",
          "host": "uvnc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/ultravnc/UltraVNC",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.securin.io/zero-days/cve-2026-44041-vncwc2mb-wcslen-before-bounds-check-ultravnc",
          "host": "www.securin.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 659,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44042",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T03:40:37.003Z",
      "date_published": "2026-07-01T03:33:07.511Z",
      "date_updated": "2026-07-09T04:36:12.685Z",
      "publisher": "securin",
      "title": "UltraVNC repeater wi_uudecode off-by-one in base64 decode boundary check",
      "affected": {
        "vendors": [
          "uvnc"
        ],
        "products": [
          {
            "vendor": "uvnc",
            "product": "UltraVNC"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-193",
          "name": "Off-by-one Error",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:33c584b5-0579-4c06-b2a0-8d8329fcab9c",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31564
      },
      "nvd": {
        "published": "2026-07-01T05:16:21.153",
        "lastModified": "2026-07-09T06:16:21.157",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44042",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Base64 helper uses a strict greater-than length check where equality must also be rejected, leaving a one-byte boundary write.",
        "basis": [
          "CNA",
          "CWE-193"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://uvnc.com/",
          "host": "uvnc.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/ultravnc/UltraVNC",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.securin.io/zero-days/cve-2026-44042-wi-uudecode-off-by-one-bounded-ultravnc-repeater",
          "host": "www.securin.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 829,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44090",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.225Z",
      "date_published": "2026-07-30T06:47:04.767Z",
      "date_updated": "2026-07-30T12:34:08.064Z",
      "publisher": "CERTVDE",
      "title": "Missing authentication for MQTT Broker",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00401,
        "percentile": 0.32911
      },
      "nvd": {
        "published": "2026-07-30T07:16:56.810",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44090",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive endpoint performs its operation without requiring the caller to authenticate.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44091",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.225Z",
      "date_published": "2026-07-30T06:47:37.456Z",
      "date_updated": "2026-07-31T22:44:06.392Z",
      "publisher": "CERTVDE",
      "title": "Creation of a new configuration by posting a malicious ID to MQTT",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-501",
          "name": "Trust Boundary Violation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.29999999999999893,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25252
      },
      "nvd": {
        "published": "2026-07-30T07:16:56.963",
        "lastModified": "2026-07-31T23:17:23.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44091",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MQTT broker accepts an unauthenticated caller-supplied identifier that creates a new system configuration entry.",
        "basis": [
          "CNA",
          "CWE-501"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44092",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:47:57.320Z",
      "date_updated": "2026-07-30T15:17:18.110Z",
      "publisher": "CERTVDE",
      "title": "Missing input validation / stripping of CRLF characters in SystemConfigManager",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.29999999999999893,
      "epss": {
        "score": 0.0038,
        "percentile": 0.30716
      },
      "nvd": {
        "published": "2026-07-30T07:16:57.110",
        "lastModified": "2026-07-30T16:17:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44092",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ModbusServer accepts MQTT text containing CRLF control characters without stripping them before interpreting the resulting record boundaries.",
        "basis": [
          "CNA",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44093",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:48:19.608Z",
      "date_updated": "2026-07-30T12:55:41.446Z",
      "publisher": "CERTVDE",
      "title": "Local Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start script",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14106
      },
      "nvd": {
        "published": "2026-07-30T07:16:57.260",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44093",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An initialization script incorporates attacker-controlled input into a shell command without neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44094",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:48:37.951Z",
      "date_updated": "2026-07-30T14:04:15.872Z",
      "publisher": "CERTVDE",
      "title": "Fallback to second RAUC slot with default credentials",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-636",
          "name": "Not Failing Securely ('Failing Open')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.29999999999999893,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17443
      },
      "nvd": {
        "published": "2026-07-30T07:16:57.403",
        "lastModified": "2026-07-30T15:16:33.033",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44094",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A remote action can force boot into a fallback firmware slot that retains default SSH credentials.",
        "basis": [
          "CNA record",
          "CWE-636"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 286,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44095",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:48:55.750Z",
      "date_updated": "2026-07-30T12:32:56.327Z",
      "publisher": "CERTVDE",
      "title": "Local Privilege Escalation via Network scripts",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14105
      },
      "nvd": {
        "published": "2026-07-30T07:16:57.540",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44095",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CHARX SEC-3150 places attacker-controlled data into an operating-system command without separating it from command syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44096",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:49:16.576Z",
      "date_updated": "2026-07-31T22:45:06.024Z",
      "publisher": "CERTVDE",
      "title": "udhcpc Privilege Escalation",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14105
      },
      "nvd": {
        "published": "2026-07-30T07:16:57.677",
        "lastModified": "2026-07-31T23:17:23.847",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44096",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The udhcpc invocation lets the charx-web user place command syntax into a root-executed operation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 154,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44097",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:49:34.687Z",
      "date_updated": "2026-07-30T15:17:09.218Z",
      "publisher": "CERTVDE",
      "title": "File Upload vulnerability",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.7999999999999998,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15666
      },
      "nvd": {
        "published": "2026-07-30T07:16:57.813",
        "lastModified": "2026-07-30T16:17:11.743",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44097",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path in CHARX SEC-3150 accepts an attacker-selected file type or destination outside the intended file policy.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44098",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:49:53.260Z",
      "date_updated": "2026-07-30T12:56:14.535Z",
      "publisher": "CERTVDE",
      "title": "OS Command Injection in OCPP Agent via charge_box_id",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.01367,
        "percentile": 0.6915
      },
      "nvd": {
        "published": "2026-07-30T07:16:57.950",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44098",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text reaches an operating-system command boundary without shell-safe argument separation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44099",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:50:08.946Z",
      "date_updated": "2026-07-30T14:09:31.734Z",
      "publisher": "CERTVDE",
      "title": "Local Privilege Escalation via pppd password injection",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14106
      },
      "nvd": {
        "published": "2026-07-30T07:16:58.083",
        "lastModified": "2026-07-30T15:16:33.177",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44099",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A low-privileged user can inject shell syntax through a pppd password value that an elevated system-configuration path interprets as a root command.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44100",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:50:41.583Z",
      "date_updated": "2026-07-30T12:29:40.648Z",
      "publisher": "CERTVDE",
      "title": "JupiCore charging point reconfiguration without auth",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19943
      },
      "nvd": {
        "published": "2026-07-30T07:16:58.220",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44100",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CHARX SEC-3150 path exposes a privileged operation without first authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44101",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:51:09.276Z",
      "date_updated": "2026-07-31T22:46:01.757Z",
      "publisher": "CERTVDE",
      "title": "OCPP reconfiguration vulnerability",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00401,
        "percentile": 0.32911
      },
      "nvd": {
        "published": "2026-07-30T07:16:58.357",
        "lastModified": "2026-07-31T23:17:23.970",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44101",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An OCPP configuration operation is exposed without authenticating the remote caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44102",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:51:42.011Z",
      "date_updated": "2026-07-30T15:16:59.628Z",
      "publisher": "CERTVDE",
      "title": "OCPP Firmware download is not properly locked",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11199
      },
      "nvd": {
        "published": "2026-07-30T07:16:58.487",
        "lastModified": "2026-07-30T16:17:11.877",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44102",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The OCPP cleanup path deletes an invalid firmware file without locking it against concurrent reads, leaving the file briefly accessible.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:52:07.531Z",
      "date_updated": "2026-07-30T12:56:38.642Z",
      "publisher": "CERTVDE",
      "title": "JupiCore does not perform validation of firmware",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14702
      },
      "nvd": {
        "published": "2026-07-30T07:16:58.620",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44103",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The charging module accepts firmware without verifying its integrity or trusted update provenance.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 346,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44104",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.226Z",
      "date_published": "2026-07-30T06:52:31.346Z",
      "date_updated": "2026-07-30T14:05:46.344Z",
      "publisher": "CERTVDE",
      "title": "ControllerAgent does not perform validation of firmware",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15322
      },
      "nvd": {
        "published": "2026-07-30T07:16:58.760",
        "lastModified": "2026-07-30T15:16:33.297",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44104",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 269,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44105",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.227Z",
      "date_published": "2026-07-30T06:53:13.068Z",
      "date_updated": "2026-07-30T12:28:47.946Z",
      "publisher": "CERTVDE",
      "title": "Cleartext password in logs",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00094,
        "percentile": 0.00722
      },
      "nvd": {
        "published": "2026-07-30T07:16:58.897",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44105",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The credentials for the local user \"user-app\" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user \"user-app\".",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44106",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.227Z",
      "date_published": "2026-07-30T06:52:58.069Z",
      "date_updated": "2026-07-31T22:47:27.002Z",
      "publisher": "CERTVDE",
      "title": "Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website file",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14105
      },
      "nvd": {
        "published": "2026-07-30T07:16:59.027",
        "lastModified": "2026-07-31T23:17:24.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44106",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component lets attacker-controlled text cross into an executable or interpreted grammar without the required separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44107",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.227Z",
      "date_published": "2026-07-30T06:53:28.559Z",
      "date_updated": "2026-07-30T15:16:52.455Z",
      "publisher": "CERTVDE",
      "title": "Exposed Reboot via Modbus",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-749",
          "name": "Exposed Dangerous Method or Function",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00309,
        "percentile": 0.23277
      },
      "nvd": {
        "published": "2026-07-30T07:16:59.157",
        "lastModified": "2026-07-30T16:17:12.010",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44107",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A Modbus management function that reboots the device is exposed to the network without authentication.",
        "basis": [
          "CNA",
          "CWE-749"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44108",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T10:48:08.227Z",
      "date_published": "2026-07-30T06:53:42.718Z",
      "date_updated": "2026-07-30T12:59:30.573Z",
      "publisher": "CERTVDE",
      "title": "Firewall bypass during shutdown",
      "affected": {
        "vendors": [
          "Phoenix Contact"
        ],
        "products": [
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3150"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3100"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3050"
          },
          {
            "vendor": "Phoenix Contact",
            "product": "CHARX SEC-3000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-696",
          "name": "Incorrect Behavior Order",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:info@cert.vde.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37711
      },
      "nvd": {
        "published": "2026-07-30T07:16:59.307",
        "lastModified": "2026-07-30T14:31:21.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44108",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Shutdown stops the firewall before internal services have become unreachable, creating a temporary externally reachable service state.",
        "basis": [
          "CNA",
          "CWE-696"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.certvde.com/en/advisories/VDE-2026-008/",
          "host": "www.certvde.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 343,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44160",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T14:39:34.922Z",
      "date_published": "2026-07-08T21:24:28.346Z",
      "date_updated": "2026-07-09T19:34:55.352Z",
      "publisher": "GitHub_M",
      "title": "Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`",
      "affected": {
        "vendors": [
          "fluent"
        ],
        "products": [
          {
            "vendor": "fluent",
            "product": "fluentd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28689
      },
      "nvd": {
        "published": "2026-07-08T22:17:14.600",
        "lastModified": "2026-07-13T18:48:13.083",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44160",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fluentd limits only the compressed request size and decompresses gzip content in memory without an expanded-size bound.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fluent/fluentd/security/advisories/GHSA-j9cw-hwqf-85w7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/fluent/fluentd/pull/5393",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/fluent/fluentd/commit/f5f2b7cddf8aab3932e6dec9fa367a5f3eb27e10",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/fluent/fluentd/releases/tag/v1.19.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44161",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T14:39:34.922Z",
      "date_published": "2026-07-08T21:25:43.892Z",
      "date_updated": "2026-07-09T14:40:31.700Z",
      "publisher": "GitHub_M",
      "title": "Fluentd: Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`",
      "affected": {
        "vendors": [
          "fluent"
        ],
        "products": [
          {
            "vendor": "fluent",
            "product": "fluentd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00306,
        "percentile": 0.22931
      },
      "nvd": {
        "published": "2026-07-08T22:17:14.737",
        "lastModified": "2026-07-13T18:36:21.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44161",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An untrusted placeholder can replace the hostname in Fluentd's HTTP output endpoint and direct server requests to internal services.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/fluent/fluentd/security/advisories/GHSA-72f5-rr8c-r6gr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/fluent/fluentd/pull/5394",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/fluent/fluentd/commit/c6a01ea2e0ea01977f8d615f7c6dbfae4cba88c9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/fluent/fluentd/releases/tag/v1.19.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 471,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44174",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T14:39:34.923Z",
      "date_published": "2026-07-16T21:13:43.133Z",
      "date_updated": "2026-07-18T03:17:09.100Z",
      "publisher": "GitHub_M",
      "title": "Kirby: Arbitrary Method Call via REST API search and collection query endpoints",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20247
      },
      "nvd": {
        "published": "2026-07-16T22:17:01.650",
        "lastModified": "2026-07-18T05:16:53.543",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44174",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kirby treats attacker-selected model attribute names as callable methods, exposing sensitive getters and invoking methods with side effects.",
        "basis": [
          "CNA",
          "CWE-470"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-86rh-h242-j8xp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/4.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 681,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-44175",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T14:39:34.923Z",
      "date_published": "2026-07-16T21:36:06.390Z",
      "date_updated": "2026-07-17T13:11:28.792Z",
      "publisher": "GitHub_M",
      "title": "Kirby: Cross-site scripting (XSS) from list field content in the site frontend",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16866
      },
      "nvd": {
        "published": "2026-07-16T22:17:01.833",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44175",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kirby enforces list-field HTML sanitization only in the client and stores API-supplied markup server-side for later execution in visitors' browsers.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-5fhx-9q32-q257",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 859,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-44176",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T14:39:34.923Z",
      "date_published": "2026-07-16T21:24:04.415Z",
      "date_updated": "2026-07-17T11:11:07.047Z",
      "publisher": "GitHub_M",
      "title": "Kirby: `pages.access` permission is not checked during rendering of page drafts",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12
      },
      "nvd": {
        "published": "2026-07-16T22:17:01.967",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44176",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The draft resolver accepts any authenticated user and omits the pages.access check for the specific draft model.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-2xw4-v2wx-hqq9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1583,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-44177",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T14:39:34.924Z",
      "date_published": "2026-07-16T21:19:16.783Z",
      "date_updated": "2026-07-17T13:43:43.332Z",
      "publisher": "GitHub_M",
      "title": "Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00454,
        "percentile": 0.37224
      },
      "nvd": {
        "published": "2026-07-16T22:17:02.103",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44177",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kirby uses a request-provided user ID as an account-directory path without preventing traversal outside site/accounts.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-9hx7-c53c-v6x8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1128,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44178",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T14:39:34.924Z",
      "date_published": "2026-07-20T16:54:30.590Z",
      "date_updated": "2026-07-23T03:56:21.519Z",
      "publisher": "GitHub_M",
      "title": "xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow",
      "affected": {
        "vendors": [
          "neutrinolabs"
        ],
        "products": [
          {
            "vendor": "neutrinolabs",
            "product": "xrdp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00512,
        "percentile": 0.40781
      },
      "nvd": {
        "published": "2026-07-20T17:17:09.060",
        "lastModified": "2026-07-23T05:16:31.087",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44178",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In xrdp, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-hh7r-2rmq-q4g4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 679,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44180",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T14:39:34.924Z",
      "date_published": "2026-07-16T21:59:37.875Z",
      "date_updated": "2026-07-17T14:23:37.372Z",
      "publisher": "GitHub_M",
      "title": "Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed",
      "affected": {
        "vendors": [
          "jupyter-server"
        ],
        "products": [
          {
            "vendor": "jupyter-server",
            "product": "enterprise_gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00463,
        "percentile": 0.37815
      },
      "nvd": {
        "published": "2026-07-16T22:17:02.237",
        "lastModified": "2026-07-17T18:35:23.877",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44180",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Jupyter Enterprise Gateway's prohibited-ID enforcement accepts a crafted UID or GID representation that bypasses the comparison used to block disallowed execution identities.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jupyter-server/enterprise_gateway/security/advisories/GHSA-chq7-94j8-cj28",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/jupyter-server/enterprise_gateway/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1035,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44181",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T14:39:34.924Z",
      "date_published": "2026-07-16T22:03:13.493Z",
      "date_updated": "2026-07-17T14:05:01.860Z",
      "publisher": "GitHub_M",
      "title": "Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution",
      "affected": {
        "vendors": [
          "jupyter-server"
        ],
        "products": [
          {
            "vendor": "jupyter-server",
            "product": "enterprise_gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00461,
        "percentile": 0.37658
      },
      "nvd": {
        "published": "2026-07-16T23:16:16.453",
        "lastModified": "2026-07-17T18:35:23.877",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44181",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Enterprise Gateway renders attacker-controlled KERNEL environment values as Jinja2 templates that can execute Python and operating-system commands.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jupyter-server/enterprise_gateway/security/advisories/GHSA-f49j-v924-fx9w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/jupyter-server/enterprise_gateway/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 741,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44182",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T14:39:34.924Z",
      "date_published": "2026-07-16T22:05:09.576Z",
      "date_updated": "2026-07-17T15:04:51.068Z",
      "publisher": "GitHub_M",
      "title": "Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering",
      "affected": {
        "vendors": [
          "jupyter-server"
        ],
        "products": [
          {
            "vendor": "jupyter-server",
            "product": "enterprise_gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27455
      },
      "nvd": {
        "published": "2026-07-16T23:16:16.590",
        "lastModified": "2026-07-17T18:35:23.877",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44182",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Jupyter Enterprise Gateway inserts untrusted environment values into Kubernetes YAML without YAML-aware escaping, allowing extra fields or resources to be created.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jupyter-server/enterprise_gateway/security/advisories/GHSA-cfw7-6c5v-2wjq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/jupyter-server/enterprise_gateway/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 878,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T15:02:54.443Z",
      "date_published": "2026-07-22T12:06:50.258Z",
      "date_updated": "2026-07-22T16:02:42.074Z",
      "publisher": "redhat",
      "title": "Ansible-lightspeed: ansible lightspeed extension for visual studio code: information disclosure of google gemini api key",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-256",
          "name": "Plaintext Storage of a Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00089,
        "percentile": 0.00525
      },
      "nvd": {
        "published": "2026-07-22T12:17:59.690",
        "lastModified": "2026-07-22T17:16:56.240",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44187",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Ansible Lightspeed extension stores the Gemini API key in a plaintext configuration file and writes it to logs.",
        "basis": [
          "CNA",
          "CWE-256"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44187",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466765",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 494,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-44189",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T15:02:54.443Z",
      "date_published": "2026-07-22T12:06:36.571Z",
      "date_updated": "2026-07-22T12:19:09.393Z",
      "publisher": "redhat",
      "title": "Ansible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execution via malicious playbook filename",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00536,
        "percentile": 0.42198
      },
      "nvd": {
        "published": "2026-07-22T12:17:59.817",
        "lastModified": "2026-07-22T16:23:35.893",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44189",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The VS Code extension places a malicious playbook filename into a command without neutralizing argument delimiters.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44189",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466763",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-44190",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T15:02:54.443Z",
      "date_published": "2026-07-22T12:06:42.591Z",
      "date_updated": "2026-07-23T13:50:44.922Z",
      "publisher": "redhat",
      "title": "Ansible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script setting",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35532
      },
      "nvd": {
        "published": "2026-07-22T12:17:59.940",
        "lastModified": "2026-07-23T14:17:14.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44190",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Ansible Lightspeed extension treats an attacker-influenced activation-script setting as a command or executable path without preserving the command boundary.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44190",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466762",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-44191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T15:02:54.444Z",
      "date_published": "2026-07-22T12:11:29.899Z",
      "date_updated": "2026-07-22T18:48:19.980Z",
      "publisher": "redhat",
      "title": "Ansible-lightspeed: visual studio code ansible lightspeed extension: remote code execution via command injection in configuration settings",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38418
      },
      "nvd": {
        "published": "2026-07-22T13:16:37.367",
        "lastModified": "2026-07-22T19:17:03.743",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44191",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44191",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466761",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 611,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-44192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T15:02:54.444Z",
      "date_published": "2026-07-22T12:06:48.859Z",
      "date_updated": "2026-07-22T13:05:03.058Z",
      "publisher": "redhat",
      "title": "Ansible-lightspeed: ansible lightspeed mcp server: remote code execution and data exfiltration via path traversal",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04594
      },
      "nvd": {
        "published": "2026-07-22T12:18:00.063",
        "lastModified": "2026-07-22T16:23:35.893",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44192",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-44192",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466760",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 480,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-44210",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T15:13:47.571Z",
      "date_published": "2026-07-23T17:32:23.927Z",
      "date_updated": "2026-07-24T22:03:05.694Z",
      "publisher": "GitHub_M",
      "title": "Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations",
      "affected": {
        "vendors": [
          "kata-containers"
        ],
        "products": [
          {
            "vendor": "kata-containers",
            "product": "kata-containers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:P"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24402
      },
      "nvd": {
        "published": "2026-07-23T18:16:51.053",
        "lastModified": "2026-07-24T23:16:50.527",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44210",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Default-enabled pod annotations let a workload add virtiofsd arguments that replace the shared directory with the host root filesystem.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kata-containers/kata-containers/security/advisories/GHSA-rr59-xxvx-96qr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/kata-containers/kata-containers/commit/ffa59ce3aa7877d067c9a372df0c329a23a01744",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 857,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44227",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T15:42:40.518Z",
      "date_published": "2026-07-20T17:32:48.794Z",
      "date_updated": "2026-07-20T19:06:52.288Z",
      "publisher": "GitHub_M",
      "title": "RT: Reflected Cross-Site Scripting via URL parameters",
      "affected": {
        "vendors": [
          "bestpractical"
        ],
        "products": [
          {
            "vendor": "bestpractical",
            "product": "rt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05134
      },
      "nvd": {
        "published": "2026-07-20T18:16:52.183",
        "lastModified": "2026-07-23T15:57:13.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44227",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bestpractical/rt/security/advisories/GHSA-7742-fhq7-ggv9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bestpractical/rt/releases/tag/rt-6.0.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44228",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T15:42:40.518Z",
      "date_published": "2026-07-20T17:34:28.662Z",
      "date_updated": "2026-07-21T16:12:29.541Z",
      "publisher": "GitHub_M",
      "title": "RT: Stored Cross-Site Scripting via insufficient template escaping",
      "affected": {
        "vendors": [
          "bestpractical"
        ],
        "products": [
          {
            "vendor": "bestpractical",
            "product": "rt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04425
      },
      "nvd": {
        "published": "2026-07-20T18:16:52.323",
        "lastModified": "2026-07-23T15:57:13.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44228",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bestpractical/rt/security/advisories/GHSA-pfgp-5j8g-phgc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bestpractical/rt/releases/tag/rt-6.0.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44229",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T15:42:40.518Z",
      "date_published": "2026-07-20T19:18:25.818Z",
      "date_updated": "2026-07-21T16:20:15.243Z",
      "publisher": "GitHub_M",
      "title": "RT: Cross-Site Scripting via inline-served uploaded content",
      "affected": {
        "vendors": [
          "bestpractical"
        ],
        "products": [
          {
            "vendor": "bestpractical",
            "product": "rt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03656
      },
      "nvd": {
        "published": "2026-07-20T20:16:43.527",
        "lastModified": "2026-07-23T15:57:13.590",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44229",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches rt page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bestpractical/rt/security/advisories/GHSA-x576-pvwp-c2qv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bestpractical/rt/releases/tag/rt-6.0.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-44230",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T15:42:40.518Z",
      "date_published": "2026-07-20T19:25:16.161Z",
      "date_updated": "2026-07-20T21:43:46.877Z",
      "publisher": "GitHub_M",
      "title": "RT: Reflected Cross-Site Scripting in search results chart",
      "affected": {
        "vendors": [
          "bestpractical"
        ],
        "products": [
          {
            "vendor": "bestpractical",
            "product": "rt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05152
      },
      "nvd": {
        "published": "2026-07-20T20:16:43.660",
        "lastModified": "2026-07-23T15:57:13.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44230",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted search-chart URL is reflected into the RT page without the required browser-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bestpractical/rt/security/advisories/GHSA-p724-v26h-32g9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bestpractical/rt/releases/tag/rt-6.0.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 426,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-44231",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T15:42:40.518Z",
      "date_published": "2026-07-20T19:20:43.950Z",
      "date_updated": "2026-07-21T12:46:48.161Z",
      "publisher": "GitHub_M",
      "title": "RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint",
      "affected": {
        "vendors": [
          "bestpractical"
        ],
        "products": [
          {
            "vendor": "bestpractical",
            "product": "rt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16255
      },
      "nvd": {
        "published": "2026-07-20T20:16:43.797",
        "lastModified": "2026-07-23T15:57:13.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44231",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The REST user collection allows a caller to expose or rotate another user's credentials without the required per-user authorization.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-269",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bestpractical/rt/security/advisories/GHSA-7rx2-x357-wv74",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bestpractical/rt/releases/tag/rt-6.0.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 644,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-44251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T16:33:55.844Z",
      "date_published": "2026-07-17T00:01:41.131Z",
      "date_updated": "2026-07-17T18:06:15.671Z",
      "publisher": "GitHub_M",
      "title": "Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent message",
      "affected": {
        "vendors": [
          "wazuh"
        ],
        "products": [
          {
            "vendor": "wazuh",
            "product": "wazuh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28782
      },
      "nvd": {
        "published": "2026-07-17T02:18:05.973",
        "lastModified": "2026-07-20T02:22:10.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44251",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A size_t underflow in ReadSecMSG corrupts length arithmetic and can drive heap memory beyond its allocation.",
        "basis": [
          "CNA record",
          "CWE-191",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-jv5r-5p7c-g9fq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 463,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44268",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T17:04:45.713Z",
      "date_published": "2026-07-03T12:15:22.397Z",
      "date_updated": "2026-07-06T14:22:01.012Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00104,
        "percentile": 0.01209
      },
      "nvd": {
        "published": "2026-07-03T13:17:15.750",
        "lastModified": "2026-07-08T19:33:14.110",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44268",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record labels a permission assignment in PowerProtect Data Domain as unsafe but does not identify the resource or effective permission that crosses the boundary.",
        "basis": [
          "CNA",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44269",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T17:04:45.713Z",
      "date_published": "2026-07-03T12:09:06.006Z",
      "date_updated": "2026-07-07T17:01:11.663Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03253
      },
      "nvd": {
        "published": "2026-07-03T13:17:15.870",
        "lastModified": "2026-07-08T19:33:08.057",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44269",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerProtect resolves and follows a local attacker-controlled link before enforcing the intended file target.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44276",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T17:04:45.714Z",
      "date_published": "2026-07-22T15:13:07.215Z",
      "date_updated": "2026-07-22T15:55:09.983Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Manager, versions prior to 20.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00108,
        "percentile": 0.01384
      },
      "nvd": {
        "published": "2026-07-22T16:17:22.593",
        "lastModified": "2026-07-29T17:40:07.540",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44276",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PowerProtect Data Manager exposes protected REST API information to a local high-privileged caller, while Dell does not identify the returned object or data-selection error.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000488847/dsa-2026-287-security-update-dell-powerprotect-data-manager-for-multiple-security-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44332",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T19:52:59.146Z",
      "date_published": "2026-07-08T19:32:15.113Z",
      "date_updated": "2026-07-09T14:33:29.004Z",
      "publisher": "GitHub_M",
      "title": "Fiber: Username Enumeration via Timing Oracle in BasicAuth Default Authorizer",
      "affected": {
        "vendors": [
          "gofiber"
        ],
        "products": [
          {
            "vendor": "gofiber",
            "product": "fiber"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-203",
          "name": "Observable Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00411,
        "percentile": 0.33774
      },
      "nvd": {
        "published": "2026-07-08T20:16:49.773",
        "lastModified": "2026-07-15T20:52:13.877",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44332",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Authentication or protocol handling produces an observable response difference that reveals otherwise protected state.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-203"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gofiber/fiber/security/advisories/GHSA-g5vh-55hw-rxm8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gofiber/fiber/pull/4245",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gofiber/fiber/commit/c7ac00edd19f9669b1aebbec6e229658baaa059e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gofiber/fiber/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 382,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44342",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T19:52:59.147Z",
      "date_published": "2026-07-09T22:33:06.518Z",
      "date_updated": "2026-07-10T14:44:38.863Z",
      "publisher": "GitHub_M",
      "title": "New API CSRF in email and WeChat account binding endpoints",
      "affected": {
        "vendors": [
          "QuantumNous"
        ],
        "products": [
          {
            "vendor": "QuantumNous",
            "product": "new-api"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05544
      },
      "nvd": {
        "published": "2026-07-09T23:17:05.217",
        "lastModified": "2026-07-16T16:37:07.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44342",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "State-changing email and WeChat binding endpoints use GET and accept cross-site cookie-authenticated navigation without a CSRF-bound request token.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/QuantumNous/new-api/security/advisories/GHSA-26v7-h57m-gh9m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/QuantumNous/new-api/commit/e099117c61391abdf888fb75e382a582e550bd0e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/QuantumNous/new-api/releases/tag/v0.12.0-alpha.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T20:15:20.630Z",
      "date_published": "2026-07-19T23:06:32.005Z",
      "date_updated": "2026-07-24T03:56:28.416Z",
      "publisher": "GitHub_M",
      "title": "Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow",
      "affected": {
        "vendors": [
          "meshtastic"
        ],
        "products": [
          {
            "vendor": "meshtastic",
            "product": "firmware"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01003,
        "percentile": 0.59556
      },
      "nvd": {
        "published": "2026-07-20T00:16:58.210",
        "lastModified": "2026-07-24T05:16:44.400",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44359",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pull_request_target workflow checks out and executes an external contributor's fork in secret-bearing jobs without an approval gate, granting untrusted code the workflow's repository authority.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/meshtastic/firmware/security/advisories/GHSA-mjx5-98jq-q736",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/meshtastic/firmware/security/advisories/GHSA-6mwm-v2vv-pp96",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/meshtastic/firmware/commit/5716aeba3bc1e1d34fba9567ff88917ede4a78a5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://drive.google.com/file/d/1GdHT2s5hMYCiHt4zrWt1q58mvL7WQC0M/view?usp=sharing",
          "host": "drive.google.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1045,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44362",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-05T20:15:20.630Z",
      "date_published": "2026-07-06T19:33:48.666Z",
      "date_updated": "2026-07-06T20:51:51.914Z",
      "publisher": "GitHub_M",
      "title": "OP-TEE's subkey rollback protection can be bypassed with older subkey versions",
      "affected": {
        "vendors": [
          "OP-TEE"
        ],
        "products": [
          {
            "vendor": "OP-TEE",
            "product": "optee_os"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02356
      },
      "nvd": {
        "published": "2026-07-06T20:16:33.950",
        "lastModified": "2026-07-07T18:55:08.020",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44362",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A subkey version is not propagated, so rollback leaves the database version at zero and accepts the wrong key state.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OP-TEE/optee_os/security/advisories/GHSA-fhcg-pp56-8v75",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1247,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T16:55:26.145Z",
      "date_published": "2026-07-10T22:11:16.866Z",
      "date_updated": "2026-07-13T15:34:23.220Z",
      "publisher": "icscert",
      "title": "Hydro-Québec Le Circuit Electrique charging station backend Insufficient Session Expiration",
      "affected": {
        "vendors": [
          "Hydro-Québec"
        ],
        "products": [
          {
            "vendor": "Hydro-Québec",
            "product": "Le Circuit Electrique charging station backend"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00448,
        "percentile": 0.36776
      },
      "nvd": {
        "published": "2026-07-10T23:16:48.343",
        "lastModified": "2026-07-13T20:20:52.383",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44383",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Le Circuit Electrique charging station backend session lifecycle permits a credential or session identity to remain concurrently reusable beyond the intended connection state.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.hydroquebec.com/nous-joindre/",
          "host": "www.hydroquebec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-01.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44387",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T01:43:56.796Z",
      "date_published": "2026-07-28T08:40:21.004Z",
      "date_updated": "2026-07-28T16:09:18.061Z",
      "publisher": "jpcert",
      "title": "ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI.",
      "affected": {
        "vendors": [
          "ELECOM CO.,LTD."
        ],
        "products": [
          {
            "vendor": "ELECOM CO.,LTD.",
            "product": "WAB-M1775-PS"
          },
          {
            "vendor": "ELECOM CO.,LTD.",
            "product": "WAB-S1775"
          },
          {
            "vendor": "ELECOM CO.,LTD.",
            "product": "WAB-M2133"
          },
          {
            "vendor": "ELECOM CO.,LTD.",
            "product": "WAB-I1750-PS"
          },
          {
            "vendor": "ELECOM CO.,LTD.",
            "product": "WAB-S1167-PS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "3.0",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.2,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04656
      },
      "nvd": {
        "published": "2026-07-28T09:16:42.247",
        "lastModified": "2026-07-28T16:18:12.597",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44387",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected page renders attacker-controlled input as executable browser markup without the required context encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.elecom.co.jp/news/security/20260728-01/",
          "host": "www.elecom.co.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jvn.jp/en/jp/JVN56870912/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-44433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T14:40:00.954Z",
      "date_published": "2026-07-16T22:23:17.247Z",
      "date_updated": "2026-07-17T18:06:23.088Z",
      "publisher": "GitHub_M",
      "title": "Quicly is vulnerable to memory exhaustion",
      "affected": {
        "vendors": [
          "h2o"
        ],
        "products": [
          {
            "vendor": "h2o",
            "product": "quicly"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16019
      },
      "nvd": {
        "published": "2026-07-16T23:16:16.727",
        "lastModified": "2026-07-17T19:17:13.800",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44433",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A QUIC peer can send one byte at the largest permitted stream offset and make Quicly-backed applications allocate the sparse receive range, consuming large amounts of memory with few packets.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/h2o/quicly/security/advisories/GHSA-f7qr-4p37-9gx9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/h2o/quicly/commit/8b178e692c51a3b1031612ef89f03a53aac63c15",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 991,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T14:40:00.954Z",
      "date_published": "2026-07-16T22:34:09.386Z",
      "date_updated": "2026-07-18T03:21:24.526Z",
      "publisher": "GitHub_M",
      "title": "Quicly is vulnerable to stateless reset injection",
      "affected": {
        "vendors": [
          "h2o"
        ],
        "products": [
          {
            "vendor": "h2o",
            "product": "quicly"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-665",
          "name": "Improper Initialization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04446
      },
      "nvd": {
        "published": "2026-07-16T23:16:16.870",
        "lastModified": "2026-07-18T05:16:53.657",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44434",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The stateless-reset path accepts an all-zero secret slot as valid because initialization state is not checked.",
        "basis": [
          "CNA",
          "CWE-345",
          "CWE-665"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/h2o/quicly/security/advisories/GHSA-899f-49jq-pfh8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/h2o/quicly/commit/dccf5d4579c7ae9dd6e8f90c36d52e311bb60710",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 895,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T14:40:00.954Z",
      "date_published": "2026-07-16T22:39:50.873Z",
      "date_updated": "2026-07-17T13:02:55.330Z",
      "publisher": "GitHub_M",
      "title": "Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KB",
      "affected": {
        "vendors": [
          "h2o"
        ],
        "products": [
          {
            "vendor": "h2o",
            "product": "quicly"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20083
      },
      "nvd": {
        "published": "2026-07-16T23:16:17.010",
        "lastModified": "2026-07-17T18:34:36.267",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44435",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation lets attacker-controlled work or allocation grow without an effective per-request bound or termination condition.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/h2o/quicly/security/advisories/GHSA-2cw9-5673-73gv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/h2o/quicly/commit/937d0e9e7c669fc2bee4920632ab6aaac60e4d81",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T14:40:00.954Z",
      "date_published": "2026-07-16T22:44:34.254Z",
      "date_updated": "2026-07-17T10:48:33.974Z",
      "publisher": "GitHub_M",
      "title": "Quicly is vulnerable to connection state corruption",
      "affected": {
        "vendors": [
          "h2o"
        ],
        "products": [
          {
            "vendor": "h2o",
            "product": "quicly"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20086
      },
      "nvd": {
        "published": "2026-07-16T23:16:17.143",
        "lastModified": "2026-07-21T19:25:26.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44436",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "quicly can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-120",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/h2o/quicly/security/advisories/GHSA-v55w-59qx-2v78",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/h2o/quicly/commit/8b178e692c51a3b1031612ef89f03a53aac63c15",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1108,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44452",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T15:49:25.192Z",
      "date_published": "2026-07-16T22:54:42.914Z",
      "date_updated": "2026-07-17T14:03:52.757Z",
      "publisher": "GitHub_M",
      "title": "h2o is vulnerable to heap overrun",
      "affected": {
        "vendors": [
          "h2o"
        ],
        "products": [
          {
            "vendor": "h2o",
            "product": "h2o"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-170",
          "name": "Improper Null Termination",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16429
      },
      "nvd": {
        "published": "2026-07-16T23:16:17.280",
        "lastModified": "2026-07-17T18:37:25.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44452",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A length, offset, or termination error makes the program read beyond the end of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-170"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/h2o/h2o/security/advisories/GHSA-w68q-rqwx-7wvq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/h2o/h2o/commit/8dc37cb1e6171f7f772667618ea440696fed82c3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44453",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T15:49:25.192Z",
      "date_published": "2026-07-16T23:04:41.756Z",
      "date_updated": "2026-07-17T14:29:15.447Z",
      "publisher": "GitHub_M",
      "title": "h2o is vulnerable to musl libc stack overflow",
      "affected": {
        "vendors": [
          "h2o"
        ],
        "products": [
          {
            "vendor": "h2o",
            "product": "h2o"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20119
      },
      "nvd": {
        "published": "2026-07-16T23:16:17.423",
        "lastModified": "2026-07-17T18:37:25.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44453",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "h2o places an attacker-influenced static-file path in an alloca allocation that can exceed musl's worker-thread stack size.",
        "basis": [
          "CNA",
          "CWE-770",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/h2o/h2o/security/advisories/GHSA-rf9v-m59p-mq84",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/h2o/h2o/commit/6b5370d9d09fcf83aa7620ddf77de1954a192181",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 622,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T15:49:25.192Z",
      "date_published": "2026-07-07T20:16:39.161Z",
      "date_updated": "2026-07-08T13:48:00.841Z",
      "publisher": "GitHub_M",
      "title": "Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.7000000000000011,
      "epss": {
        "score": 0.01354,
        "percentile": 0.68853
      },
      "nvd": {
        "published": "2026-07-07T21:17:25.180",
        "lastModified": "2026-07-08T19:47:37.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44454",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The dotfiles module inserts a URL value into eval or sh -c, allowing shell syntax to run during automatic workspace provisioning.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-m3cr-vc2j-pm27",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/22011",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/registry/pull/703",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/commit/60e3ab7632f42415d283b9fd5622ee53a4639ceb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/registry/commit/8e68c96633f65a1babd76a93b6923e3deead4a82",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.30.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 961,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-44507",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-05-06T18:28:20.886Z",
      "date_published": "2026-07-20T20:29:26.577Z",
      "date_rejected": "2026-07-21T15:09:28.320Z",
      "date_updated": "2026-07-21T15:09:28.320Z",
      "publisher": "GitHub_M",
      "title": "Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER.",
      "rejected_reason": "** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43617. Reason: This candidate is a duplicate of CVE-2026-43617. Notes: All CVE users should reference CVE-2026-43617 instead of this candidate."
    },
    {
      "cve_id": "CVE-2026-44508",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-05-06T18:28:20.886Z",
      "date_published": "2026-07-20T20:30:14.341Z",
      "date_rejected": "2026-07-21T15:10:02.961Z",
      "date_updated": "2026-07-21T15:10:02.961Z",
      "publisher": "GitHub_M",
      "title": "Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER.",
      "rejected_reason": "** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate."
    },
    {
      "cve_id": "CVE-2026-44509",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-05-06T18:28:20.887Z",
      "date_published": "2026-07-20T20:27:21.420Z",
      "date_rejected": "2026-07-21T15:11:05.589Z",
      "date_updated": "2026-07-21T15:11:05.589Z",
      "publisher": "GitHub_M",
      "title": "Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER.",
      "rejected_reason": "** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate."
    },
    {
      "cve_id": "CVE-2026-44510",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-05-06T18:28:20.887Z",
      "date_published": "2026-07-20T21:03:17.056Z",
      "date_rejected": "2026-07-21T15:11:32.982Z",
      "date_updated": "2026-07-21T15:11:32.982Z",
      "publisher": "GitHub_M",
      "title": "Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER.",
      "rejected_reason": "** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate."
    },
    {
      "cve_id": "CVE-2026-44512",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T18:28:20.887Z",
      "date_published": "2026-07-08T19:32:04.886Z",
      "date_updated": "2026-07-09T13:36:58.289Z",
      "publisher": "GitHub_M",
      "title": "ONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)",
      "affected": {
        "vendors": [
          "onnx"
        ],
        "products": [
          {
            "vendor": "onnx",
            "product": "onnx"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08153
      },
      "nvd": {
        "published": "2026-07-08T20:16:49.913",
        "lastModified": "2026-07-13T17:02:01.533",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44512",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ONNX Upsample version adapter dereferences a null input pointer when a crafted node declares zero inputs.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/onnx/onnx/security/advisories/GHSA-hwpq-hmq9-wj77",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/onnx/onnx/pull/7813",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/onnx/onnx/commit/cd310408165ad47c3cd7eb2b86cb5b80aa2e4fdf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/onnx/onnx/releases/tag/v1.22.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44583",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T21:49:12.425Z",
      "date_published": "2026-07-20T20:01:58.914Z",
      "date_updated": "2026-07-21T16:23:05.330Z",
      "publisher": "GitHub_M",
      "title": "Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module",
      "affected": {
        "vendors": [
          "Paymenter"
        ],
        "products": [
          {
            "vendor": "Paymenter",
            "product": "Paymenter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25059
      },
      "nvd": {
        "published": "2026-07-20T21:16:47.380",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44583",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PayPal webhook uses the PAYPAL-CERT-URL header directly as a server-side HTTP destination without host, scheme, or signature validation.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Paymenter/Paymenter/security/advisories/GHSA-7wwh-xcc3-9fcg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1178,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44584",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T21:49:12.425Z",
      "date_published": "2026-07-20T19:58:49.126Z",
      "date_updated": "2026-07-20T21:44:18.192Z",
      "publisher": "GitHub_M",
      "title": "Paymenter doesn't reset email verification status after email change",
      "affected": {
        "vendors": [
          "Paymenter"
        ],
        "products": [
          {
            "vendor": "Paymenter",
            "product": "Paymenter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00115,
        "percentile": 0.0178
      },
      "nvd": {
        "published": "2026-07-20T21:16:47.520",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44584",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Changing an email address leaves the prior verified flag set instead of returning the account to an unverified state.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Paymenter/Paymenter/security/advisories/GHSA-rv89-wch8-c574",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 905,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44585",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T21:49:12.425Z",
      "date_published": "2026-07-20T20:04:57.110Z",
      "date_updated": "2026-07-21T12:48:33.373Z",
      "publisher": "GitHub_M",
      "title": "Paymenter: Broken object level authorization via service reference manipulation on ticket creation",
      "affected": {
        "vendors": [
          "Paymenter"
        ],
        "products": [
          {
            "vendor": "Paymenter",
            "product": "Paymenter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07548
      },
      "nvd": {
        "published": "2026-07-20T21:16:47.640",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44585",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ticket endpoint accepts a service ID without verifying that the referenced service belongs to the authenticated customer.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Paymenter/Paymenter/security/advisories/GHSA-x93q-x9pc-w5hw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1198,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44595",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T21:49:12.426Z",
      "date_published": "2026-07-16T16:02:46.293Z",
      "date_updated": "2026-07-18T02:57:18.980Z",
      "publisher": "GitHub_M",
      "title": "Yamcs: Unauthorized user enumeration via IAM API endpoints",
      "affected": {
        "vendors": [
          "yamcs"
        ],
        "products": [
          {
            "vendor": "yamcs",
            "product": "yamcs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00984,
        "percentile": 0.58914
      },
      "nvd": {
        "published": "2026-07-16T17:16:55.740",
        "lastModified": "2026-07-18T03:16:35.680",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44595",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "IAM list and get endpoints omit SystemPrivilege.ControlAccess before returning users, groups, and membership data.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yamcs/yamcs/security/advisories/GHSA-p2rj-mrmc-9w29",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/commit/0e12b518f103f24681299318a30a460fe4327b88",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/commit/e90099fba98e96214217c195b6a5b87b5f46e51c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 490,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44596",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-06T21:49:12.426Z",
      "date_published": "2026-07-16T16:04:11.794Z",
      "date_updated": "2026-07-17T14:05:15.049Z",
      "publisher": "GitHub_M",
      "title": "Yamcs: No Rate Limiting on Authentication Endpoint",
      "affected": {
        "vendors": [
          "yamcs"
        ],
        "products": [
          {
            "vendor": "yamcs",
            "product": "yamcs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 3.3000000000000007,
      "epss": {
        "score": 0.01729,
        "percentile": 0.75333
      },
      "nvd": {
        "published": "2026-07-16T17:16:55.880",
        "lastModified": "2026-07-17T18:44:26.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44596",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "yamcs accepts repeated authentication attempts without a rate, delay, or lockout bound, allowing untrusted work to be amplified.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/commit/309218c651680f79df11a8d0f8628f7033f98a83",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/commit/64392df531fbcbc65f19ee5724c4c23d289f49fc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 496,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44613",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T07:44:23.248Z",
      "date_published": "2026-07-30T15:19:40.786Z",
      "date_updated": "2026-07-31T17:50:45.810Z",
      "publisher": "apache",
      "title": "Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Zeppelin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06751
      },
      "nvd": {
        "published": "2026-07-30T16:17:12.130",
        "lastModified": "2026-07-31T18:17:14.853",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44613",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Zeppelin's default CORS policy accepts cross-origin state changes and text/plain bodies without a session-bound anti-CSRF requirement.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/zeppelin/pull/5229",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/94trzcny14c1csgotsnkyrfsflt30b2c",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 494,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44615",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T07:46:56.880Z",
      "date_published": "2026-07-31T11:05:07.878Z",
      "date_updated": "2026-07-31T16:20:12.350Z",
      "publisher": "apache",
      "title": "Path traversal in NotebookRepo note and folder path composition",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Zeppelin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00501,
        "percentile": 0.40159
      },
      "nvd": {
        "published": "2026-07-31T11:17:10.087",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44615",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache Zeppelin resolves attacker-controlled path components without confirming that the final path remains beneath the intended root.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/zeppelin/pull/5227",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/apache/zeppelin/pull/5248",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/ps1f0symnyxzq8c2dc3244v051jcwp40",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 710,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44616",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T07:49:20.694Z",
      "date_published": "2026-07-30T15:21:21.609Z",
      "date_updated": "2026-07-31T17:51:37.685Z",
      "publisher": "apache",
      "title": "Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Zeppelin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-90",
          "name": "Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27035
      },
      "nvd": {
        "published": "2026-07-30T16:17:12.257",
        "lastModified": "2026-07-31T18:17:15.070",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44616",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ActiveDirectoryGroupRealm builds LDAP filters from user-controlled search input without escaping LDAP filter syntax.",
        "basis": [
          "CNA",
          "CWE-90"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/zeppelin/pull/5226",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/p6llqpvcszpg1wc8kx5ncfkdbms3g0rn",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44617",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T07:50:20.046Z",
      "date_published": "2026-07-30T15:22:39.054Z",
      "date_updated": "2026-07-31T17:53:01.753Z",
      "publisher": "apache",
      "title": "Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Zeppelin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-90",
          "name": "Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28725
      },
      "nvd": {
        "published": "2026-07-30T16:17:12.373",
        "lastModified": "2026-07-31T18:17:15.263",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44617",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Zeppelin escapes an LDAP filter with distinguished-name rules instead of the LDAP filter grammar.",
        "basis": [
          "CNA",
          "CWE-90"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/zeppelin/pull/5226",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-31867",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://lists.apache.org/thread/s65t6n3s1v4j5b1w7zvv5w73ko69m1zv",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 451,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44621",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T10:11:10.524Z",
      "date_published": "2026-07-22T13:06:28.947Z",
      "date_updated": "2026-07-22T14:21:22.388Z",
      "publisher": "NLnet Labs",
      "title": "Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16139
      },
      "nvd": {
        "published": "2026-07-22T14:17:18.913",
        "lastModified": "2026-07-24T13:56:30.607",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44621",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "libunbound omits a required function from an allowlist, so reaching unwanted-reply-threshold handling terminates the embedding application.",
        "basis": [
          "CNA",
          "CWE-754"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44621.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 921,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44632",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T15:30:10.874Z",
      "date_published": "2026-07-16T16:05:28.554Z",
      "date_updated": "2026-07-16T16:46:26.159Z",
      "publisher": "GitHub_M",
      "title": "Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`",
      "affected": {
        "vendors": [
          "yamcs"
        ],
        "products": [
          {
            "vendor": "yamcs",
            "product": "yamcs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0117,
        "percentile": 0.64323
      },
      "nvd": {
        "published": "2026-07-16T17:16:56.023",
        "lastModified": "2026-07-17T18:38:47.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44632",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Yamcs passes mission-database algorithm text controlled by a ChangeMissionDatabase user to the Janino compiler without a sandbox.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yamcs/yamcs/security/advisories/GHSA-524g-x36v-9wm6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/commit/3c550348f866af4675d2ba4a51d8d12b7c7c6011",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/commit/4ff8fda642ea8c3309a4d3f379aa77b763148992",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 710,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:35:21.340Z",
      "date_published": "2026-07-22T13:06:42.751Z",
      "date_updated": "2026-07-22T14:19:53.266Z",
      "publisher": "NLnet Labs",
      "title": "Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-193",
          "name": "Off-by-one Error",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12303
      },
      "nvd": {
        "published": "2026-07-22T14:17:19.040",
        "lastModified": "2026-07-24T13:56:10.167",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44687",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "This is caused by an off-by-one error in 'harden-below-nxdomain' logic; enabled by default.",
        "basis": [
          "CNA",
          "CWE-193"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44687.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1204,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:35:21.352Z",
      "date_published": "2026-07-22T13:06:56.684Z",
      "date_updated": "2026-07-22T18:56:16.014Z",
      "publisher": "NLnet Labs",
      "title": "Cross-zone wildcard cache poisoning via RRSIG.labels manipulation",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04292
      },
      "nvd": {
        "published": "2026-07-22T14:17:19.153",
        "lastModified": "2026-07-24T13:57:55.313",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44690",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unbound writes cache state before fully validating RRSIG.Labels, allowing a sibling zone to introduce fraudulent wildcard delegation data.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44690.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 873,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44722",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:04:17.308Z",
      "date_published": "2026-07-17T16:42:01.472Z",
      "date_updated": "2026-07-17T17:25:08.270Z",
      "publisher": "GitHub_M",
      "title": "pyzipper: Encryption bypass for small files encrypted with pyzipper",
      "affected": {
        "vendors": [
          "danifus"
        ],
        "products": [
          {
            "vendor": "danifus",
            "product": "pyzipper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-480",
          "name": "Use of Incorrect Operator",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00087,
        "percentile": 0.00452
      },
      "nvd": {
        "published": "2026-07-17T17:17:15.240",
        "lastModified": "2026-07-17T18:45:20.713",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44722",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An operator-precedence error prevents automatic selection of AE-2, leaving a plaintext CRC32 in AE-1 archives that can confirm low-entropy plaintext guesses.",
        "basis": [
          "CNA",
          "CWE-480"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/danifus/pyzipper/security/advisories/GHSA-crqm-m339-7m2p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/danifus/pyzipper/commit/93ce88e7dfd1635443197dab3fb8d477cff579ae",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/danifus/pyzipper/releases/tag/v0.4.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 607,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44739",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:04:17.310Z",
      "date_published": "2026-07-17T19:10:10.107Z",
      "date_updated": "2026-07-17T23:15:23.395Z",
      "publisher": "GitHub_M",
      "title": "Pimcore: SQL Injection in Custom Reports Column Configuration",
      "affected": {
        "vendors": [
          "pimcore"
        ],
        "products": [
          {
            "vendor": "pimcore",
            "product": "pimcore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20773
      },
      "nvd": {
        "published": "2026-07-17T20:17:16.597",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44739",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-3234-gxc3-pq6f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/pull/19098",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/commit/3fd7733464f464e58ffa49ed91550c1a3f9535f2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/releases/tag/v12.3.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 648,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-44745",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:16:34.195Z",
      "date_published": "2026-07-14T00:18:16.089Z",
      "date_updated": "2026-07-14T12:39:36.122Z",
      "publisher": "sap",
      "title": "Open Redirect vulnerability in SAP Approuter",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP Approuter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25677
      },
      "nvd": {
        "published": "2026-07-14T01:16:17.320",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44745",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "SAP Approuter trusts an invalid OAuth2 login header or redirect transition, but the public record does not identify the header or validation rule.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3741519",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:16:34.195Z",
      "date_published": "2026-07-14T00:19:33.450Z",
      "date_updated": "2026-07-29T04:52:11.801Z",
      "publisher": "sap",
      "title": "Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP NetWeaver Application Server ABAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 12,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00533,
        "percentile": 0.42022
      },
      "nvd": {
        "published": "2026-07-14T01:16:17.437",
        "lastModified": "2026-07-29T06:16:59.680",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44747",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ABAP application-server memory management can corrupt memory, but the public material does not identify the specific bounds, ownership, or lifetime error.",
        "basis": [
          "CNA",
          "CWE-787",
          "SAP Note 3747367 landing page",
          "SAP Security Notes and News"
        ],
        "deepDive": true,
        "notes": "Inspected https://me.sap.com/notes/3747367 and https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 on 2026-08-05; SAP Note 3747367 redirected to authenticated SAP for Me and the public patch-day page did not expose the note body, leaving the exact memory-management error unavailable."
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3747367",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-44752",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:16:34.195Z",
      "date_published": "2026-07-14T00:19:45.308Z",
      "date_updated": "2026-07-14T12:38:59.318Z",
      "publisher": "sap",
      "title": "Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard)",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP NetWeaver Application Server Java(Configuration Wizard)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18094
      },
      "nvd": {
        "published": "2026-07-14T01:16:17.567",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44752",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content is rendered without the browser-context separation required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3748227",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44753",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:31:04.066Z",
      "date_published": "2026-07-14T00:19:58.321Z",
      "date_updated": "2026-07-14T12:38:29.089Z",
      "publisher": "sap",
      "title": "Information Disclosure vulnerability in SAP HANA Extended Application Services classic model (User Self Service)",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP HANA Extended Application Services classic model (User Self Service)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-204",
          "name": "Observable Response Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12553
      },
      "nvd": {
        "published": "2026-07-14T01:16:17.683",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44753",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-enumeration requests produce distinguishable responses for valid and invalid accounts.",
        "basis": [
          "CNA record",
          "CWE-204"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3732522",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44759",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:31:04.067Z",
      "date_published": "2026-07-14T00:20:09.899Z",
      "date_updated": "2026-07-14T12:38:05.143Z",
      "publisher": "sap",
      "title": "Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP NetWeaver Enterprise Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06835
      },
      "nvd": {
        "published": "2026-07-14T01:16:17.797",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44759",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SAP NetWeaver Enterprise Portal renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3746678",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 435,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:31:04.067Z",
      "date_published": "2026-07-14T00:20:19.533Z",
      "date_updated": "2026-07-14T12:37:36.535Z",
      "publisher": "sap",
      "title": "Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 18,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03988
      },
      "nvd": {
        "published": "2026-07-14T01:16:17.910",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44760",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Business Server Pages framework reflects unsanitized request input into HTML where the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3754659",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 562,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-44761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:31:04.067Z",
      "date_published": "2026-07-14T00:20:29.454Z",
      "date_updated": "2026-07-15T03:58:51.555Z",
      "publisher": "sap",
      "title": "Insecure Sample Credentials in SAP Commerce Cloud",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP Commerce Cloud"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1392",
          "name": "Use of Default Credentials",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00465,
        "percentile": 0.37942
      },
      "nvd": {
        "published": "2026-07-14T01:16:18.023",
        "lastModified": "2026-07-15T05:16:39.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44761",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A documented sample OAuth client can remain enabled with public sample credentials, allowing an unauthenticated caller to obtain an access token.",
        "basis": [
          "CNA",
          "CWE-1392"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3753495",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 458,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-44767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:39:44.147Z",
      "date_published": "2026-07-14T00:22:05.306Z",
      "date_updated": "2026-07-14T12:50:32.398Z",
      "publisher": "sap",
      "title": "Allowlist Bypass in setThemeRoot() Enables Cross-Origin CSS Injection",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "@ui5/webcomponents-base"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07887
      },
      "nvd": {
        "published": "2026-07-14T01:16:18.140",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44767",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "setThemeRoot accepts a cross-origin stylesheet URL without enforcing the configured theme-origin allowlist.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/UI5/webcomponents/security/advisories/GHSA-p8gx-753q-v89p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 759,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:39:44.147Z",
      "date_published": "2026-07-14T00:20:48.083Z",
      "date_updated": "2026-07-14T12:48:49.816Z",
      "publisher": "sap",
      "title": "Security misconfiguration in SAP CRM (WebClient UI)",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP CRM (WebClient UI)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-15",
          "name": "External Control of System or Configuration Setting",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06083
      },
      "nvd": {
        "published": "2026-07-14T01:16:18.253",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44768",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CRM WebClient omits restrictive Content-Security-Policy directives, allowing injected script to execute in the application origin.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-15"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3155685",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 341,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-44769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:39:44.147Z",
      "date_published": "2026-07-14T00:21:07.573Z",
      "date_updated": "2026-07-14T12:49:58.327Z",
      "publisher": "sap",
      "title": "SQL Injection vulnerability in SAP S/4HANA Project Management (PPM-PRO)",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP S/4HANA Project Management (PPM-PRO)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 19,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09727
      },
      "nvd": {
        "published": "2026-07-14T01:16:18.370",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44769",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SAP S/4HANA Project Management (PPM-PRO) data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3537373",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 19
      }
    },
    {
      "cve_id": "CVE-2026-44770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:39:44.147Z",
      "date_published": "2026-07-14T00:21:18.319Z",
      "date_updated": "2026-07-14T12:53:18.747Z",
      "publisher": "sap",
      "title": "Missing Authorization check in SAP S/4 HANA (Create Single Payment)",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP S/4 HANA (Create Single Payment)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06448
      },
      "nvd": {
        "published": "2026-07-14T01:16:18.480",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44770",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A restricted SAP user can retrieve entity keys because that operation omits the required authorization decision.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3713902",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-44771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T18:39:44.147Z",
      "date_published": "2026-07-14T00:21:28.231Z",
      "date_updated": "2026-07-14T12:52:09.720Z",
      "publisher": "sap",
      "title": "Missing Authorization check in SAP S/4HANA (Draft operation)",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP S/4HANA (Draft operation)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06794
      },
      "nvd": {
        "published": "2026-07-14T01:16:18.597",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44771",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The SAP S/4HANA (Draft operation) operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3515598",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 314,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44787",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T19:20:44.691Z",
      "date_published": "2026-07-09T22:03:41.409Z",
      "date_updated": "2026-07-10T20:59:36.502Z",
      "publisher": "GitHub_M",
      "title": "Discourse: Signup-time primary_group_id assignment grants whisperer access",
      "affected": {
        "vendors": [
          "discourse"
        ],
        "products": [
          {
            "vendor": "discourse",
            "product": "discourse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18674
      },
      "nvd": {
        "published": "2026-07-09T22:17:04.607",
        "lastModified": "2026-07-14T20:44:55.057",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44787",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Discourse signup accepts a caller-selected primary_group_id and assigns group authority that the new account is not entitled to receive.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/discourse/discourse/security/advisories/GHSA-vmwq-jvxx-jwfx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/012796ac28c85b30aa233c5ef042fc66efff8126",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/0f50a07a6ef4b33f3f826ce6d7bf6d7bd16912d8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/5418e3027dba109e27a4796463686d61e190ac29",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/6fc7e6cf04422fc3f9d1c99134803071e983ff0a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 372,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-44795",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T19:20:44.693Z",
      "date_published": "2026-07-10T21:49:27.287Z",
      "date_updated": "2026-07-15T03:59:56.097Z",
      "publisher": "GitHub_M",
      "title": "Spinnaker: Non-safe yaml deserialization allowing RCE when using specific types",
      "affected": {
        "vendors": [
          "spinnaker"
        ],
        "products": [
          {
            "vendor": "spinnaker",
            "product": "spinnaker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00543,
        "percentile": 0.42537
      },
      "nvd": {
        "published": "2026-07-10T22:16:41.717",
        "lastModified": "2026-07-21T14:01:22.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44795",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking.",
        "basis": [
          "CNA",
          "CWE-470",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/spinnaker/spinnaker/security/advisories/GHSA-c8q4-9h32-2ww8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/commit/4cbe1d5fea9df573aadfd8b093fb4b594b354ee5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/commit/e57c0db4584b398473a7bbb19402ce6c1e89b627",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/commit/f69d7b534d068ed74d0d3a1fbf17e2c945d36e5e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-44800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T20:07:18.270Z",
      "date_published": "2026-07-14T17:05:45.114Z",
      "date_updated": "2026-08-03T22:54:08.569Z",
      "publisher": "microsoft",
      "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04943
      },
      "nvd": {
        "published": "2026-07-14T17:16:48.667",
        "lastModified": "2026-07-22T16:17:22.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44800",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft reports a shared-resource race in Windows Push Notifications but does not publish the participating operations or object lifetime.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44800",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 182,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-44806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T20:07:18.271Z",
      "date_published": "2026-07-14T17:05:43.524Z",
      "date_updated": "2026-08-03T22:54:07.063Z",
      "publisher": "microsoft",
      "title": "Windows Secure Channel Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00816,
        "percentile": 0.53582
      },
      "nvd": {
        "published": "2026-07-14T17:16:48.797",
        "lastModified": "2026-07-22T16:17:22.893",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44806",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation lets attacker-controlled work or allocation grow without an effective per-request bound or termination condition.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44806",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-44840",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T21:21:48.352Z",
      "date_published": "2026-07-08T13:27:44.178Z",
      "date_updated": "2026-07-09T13:29:15.314Z",
      "publisher": "GitHub_M",
      "title": "Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query",
      "affected": {
        "vendors": [
          "dgraph-io"
        ],
        "products": [
          {
            "vendor": "dgraph-io",
            "product": "dgraph"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-943",
          "name": "Improper Neutralization of Special Elements in Data Query Logic",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00368,
        "percentile": 0.29529
      },
      "nvd": {
        "published": "2026-07-08T14:16:59.493",
        "lastModified": "2026-07-09T15:16:35.207",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44840",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Dgraph formats attacker-controlled values into a DQL query without using a parameterized query boundary.",
        "basis": [
          "CNA",
          "CWE-943"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dgraph-io/dgraph/security/advisories/GHSA-q2m9-6jp9-c6mc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dgraph-io/dgraph/commit/cee702c93f141eeb0c96a81f70830ec9e459efac",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dgraph-io/dgraph/releases/tag/v25.3.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 511,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T21:29:22.243Z",
      "date_published": "2026-07-07T19:03:35.253Z",
      "date_updated": "2026-07-07T20:31:53.068Z",
      "publisher": "hpe",
      "title": "Unauthenticated Remote Disclosure of Cryptographic Secrets",
      "affected": {
        "vendors": [
          "Hewlett Packard Enterprise (HPE)"
        ],
        "products": [
          {
            "vendor": "Hewlett Packard Enterprise (HPE)",
            "product": "HPE Networking Instant On"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-alert@hpe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19881
      },
      "nvd": {
        "published": "2026-07-07T20:16:28.693",
        "lastModified": "2026-07-09T16:39:17.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44877",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The switch exposes cryptographic secrets to an unauthenticated remote requester, but the public record does not identify the response, file, log, or diagnostic channel.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05038en_us&docLocale=en_US",
          "host": "support.hpe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44878",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T21:29:22.243Z",
      "date_published": "2026-07-21T20:42:17.908Z",
      "date_updated": "2026-07-23T13:29:55.282Z",
      "publisher": "hpe",
      "title": "Authenticated Path Traversal allows Unauthorized Access in Web Interface",
      "affected": {
        "vendors": [
          "Hewlett Packard Enterprise (HPE)"
        ],
        "products": [
          {
            "vendor": "Hewlett Packard Enterprise (HPE)",
            "product": "EdgeConnect SD-WAN Gateway (ECOS)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-377",
          "name": "Insecure Temporary File",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-alert@hpe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00412,
        "percentile": 0.33953
      },
      "nvd": {
        "published": "2026-07-21T21:16:49.640",
        "lastModified": "2026-07-23T15:51:22.823",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44878",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ECOS management interface permits an authenticated path to select files outside the intended management namespace, although the exact path field is not public.",
        "basis": [
          "CNA",
          "CWE-377",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05013en_us&docLocale=en_US",
          "host": "support.hpe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-44879",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T21:29:22.243Z",
      "date_published": "2026-07-21T20:42:48.014Z",
      "date_updated": "2026-07-23T13:31:22.744Z",
      "publisher": "hpe",
      "title": "Authenticated Command Injection allows arbitrary command execution in CLI Interface",
      "affected": {
        "vendors": [
          "Hewlett Packard Enterprise (HPE)"
        ],
        "products": [
          {
            "vendor": "Hewlett Packard Enterprise (HPE)",
            "product": "EdgeConnect SD-WAN Gateway (ECOS)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-alert@hpe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01651,
        "percentile": 0.74209
      },
      "nvd": {
        "published": "2026-07-21T21:16:49.750",
        "lastModified": "2026-07-23T15:51:22.823",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44879",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Privileged CLI input reaches an operating-system command without command-context neutralization.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05013en_us&docLocale=en_US",
          "host": "support.hpe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-44880",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T21:29:22.244Z",
      "date_published": "2026-07-21T18:01:52.885Z",
      "date_updated": "2026-07-24T03:55:50.739Z",
      "publisher": "hpe",
      "title": "Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX",
      "affected": {
        "vendors": [
          "Hewlett Packard Enterprise (HPE)"
        ],
        "products": [
          {
            "vendor": "Hewlett Packard Enterprise (HPE)",
            "product": "AOS-CX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-alert@hpe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00515,
        "percentile": 0.41034
      },
      "nvd": {
        "published": "2026-07-21T18:16:58.320",
        "lastModified": "2026-07-24T05:16:44.520",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44880",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The AOS-CX command-line interface copies remote low-privilege input beyond a buffer boundary in a privileged process.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05081en_us&docLocale=en_US",
          "host": "support.hpe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44891",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-07T21:50:33.545Z",
      "date_published": "2026-07-17T20:16:24.486Z",
      "date_updated": "2026-07-20T14:00:09.257Z",
      "publisher": "GitHub_M",
      "title": "Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00423,
        "percentile": 0.34869
      },
      "nvd": {
        "published": "2026-07-17T21:17:06.250",
        "lastModified": "2026-07-23T13:35:01.493",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44891",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "StompSubframeDecoder limits each header line but places no bound on the number or cumulative size of headers accumulated for one frame.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-vhch-2wf3-m8rp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/pull/17063",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/pull/17065",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 651,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-44907",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T02:33:35.449Z",
      "date_published": "2026-07-21T16:03:32.256Z",
      "date_updated": "2026-07-21T17:22:34.411Z",
      "publisher": "Meta",
      "title": "A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-serve...",
      "affected": {
        "vendors": [
          "Meta"
        ],
        "products": [
          {
            "vendor": "Meta",
            "product": "react-server-dom-turbopack"
          },
          {
            "vendor": "Meta",
            "product": "react-server-dom-parcel"
          },
          {
            "vendor": "Meta",
            "product": "react-server-dom-webpack"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve-assign@fb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00329,
        "percentile": 0.25441
      },
      "nvd": {
        "published": "2026-07-21T17:17:08.227",
        "lastModified": "2026-07-21T20:25:45.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44907",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server deserializes attacker-controlled React Server Component data along a path whose work is not effectively bounded.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/react/react/security/advisories/GHSA-wx67-qw84-cm4g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 361,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-44909",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T02:33:35.450Z",
      "date_published": "2026-07-23T16:27:01.658Z",
      "date_updated": "2026-07-23T19:07:28.874Z",
      "publisher": "Meta",
      "title": "Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer.",
      "affected": {
        "vendors": [
          "Facebook"
        ],
        "products": [
          {
            "vendor": "Facebook",
            "product": "proxygen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:cve-assign@fb.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00515,
        "percentile": 0.41003
      },
      "nvd": {
        "published": "2026-07-23T17:16:28.170",
        "lastModified": "2026-07-23T20:17:08.230",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44909",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Proxygen buffers complete responses for stalled HTTP/2 streams without a slow-consumer limit or release condition.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/facebook/proxygen/commit/f28742f21f7022c261b7620d4e6b20d82b6cff72",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 650,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44918",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T00:00:00.000Z",
      "date_published": "2026-07-10T00:00:00.000Z",
      "date_updated": "2026-07-10T14:31:59.215Z",
      "publisher": "mitre",
      "title": "OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.",
      "affected": {
        "vendors": [
          "OpenStack"
        ],
        "products": [
          {
            "vendor": "OpenStack",
            "product": "Ironic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00329,
        "percentile": 0.2539
      },
      "nvd": {
        "published": "2026-07-10T04:17:51.530",
        "lastModified": "2026-07-10T18:50:20.507",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44918",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation authorizes the caller generally but does not bind the requested object to that caller's tenant or ownership scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugs.launchpad.net/ironic/+bug/2150450",
          "host": "bugs.launchpad.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://security.openstack.org/ossa/OSSA-2026-026.html",
          "host": "security.openstack.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://lists.openstack.org/archives/list/openstack-announce@lists.openstack.org/thread/PAJKDWS23MKSSNX22JEVDA7RWN3BHJYC/",
          "host": "lists.openstack.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/08/4",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/08/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44934",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T12:29:48.967Z",
      "date_published": "2026-07-06T08:45:26.864Z",
      "date_updated": "2026-07-06T18:53:22.226Z",
      "publisher": "suse",
      "title": "Exposed tokens in SUSE Rancher AI Agent logs",
      "affected": {
        "vendors": [
          "SUSE"
        ],
        "products": [
          {
            "vendor": "SUSE",
            "product": "Rancher"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-215",
          "name": "Insertion of Sensitive Information Into Debugging Code",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01756
      },
      "nvd": {
        "published": "2026-07-06T09:16:36.170",
        "lastModified": "2026-07-06T19:46:02.023",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44934",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Rancher includes security-relevant internal data in an error, debug log, or diagnostic output that a lower-trust caller or local user can read.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-215"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rancher/rancher-ai-agent/security/advisories/GHSA-5r2r-h824-fr5v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44935",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T12:29:48.967Z",
      "date_published": "2026-07-02T16:00:06.751Z",
      "date_updated": "2026-07-03T03:56:15.397Z",
      "publisher": "suse",
      "title": "Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer",
      "affected": {
        "vendors": [
          "SUSE"
        ],
        "products": [
          {
            "vendor": "SUSE",
            "product": "Rancher"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1287",
          "name": "Improper Validation of Specified Type of Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00412,
        "percentile": 0.33925
      },
      "nvd": {
        "published": "2026-07-02T17:16:59.667",
        "lastModified": "2026-07-06T12:44:21.767",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44935",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Fleet resolves a tenant-supplied valuesFrom reference without checking that the named secret belongs to the same namespace or tenant.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rancher/fleet/security/advisories/GHSA-xr65-5cpm-g36x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44936",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T12:29:48.967Z",
      "date_published": "2026-07-06T09:30:20.688Z",
      "date_updated": "2026-07-06T12:47:45.102Z",
      "publisher": "suse",
      "title": "Rancher Fleet SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml",
      "affected": {
        "vendors": [
          "SUSE"
        ],
        "products": [
          {
            "vendor": "SUSE",
            "product": "Rancher"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25547
      },
      "nvd": {
        "published": "2026-07-06T11:16:27.610",
        "lastModified": "2026-07-09T20:34:30.743",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44936",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Rancher lets a caller choose a server-side destination without excluding internal or otherwise untrusted targets.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/advisories/GHSA-hx4v-cxpf-vh8m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Third Party Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44937",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T12:29:48.967Z",
      "date_published": "2026-07-06T09:52:18.659Z",
      "date_updated": "2026-07-06T12:46:59.551Z",
      "publisher": "suse",
      "title": "SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components",
      "affected": {
        "vendors": [
          "SUSE"
        ],
        "products": [
          {
            "vendor": "SUSE",
            "product": "Rancher"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30959
      },
      "nvd": {
        "published": "2026-07-06T11:16:27.727",
        "lastModified": "2026-07-09T20:24:49.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44937",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Fleet incorporates repository URL components into a regular expression without neutralizing regex syntax, allowing one repository's webhook to match another.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rancher/fleet/security/advisories/GHSA-jmf4-m7j9-g72r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44938",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T12:29:48.967Z",
      "date_published": "2026-07-07T13:05:03.344Z",
      "date_updated": "2026-07-08T03:56:44.251Z",
      "publisher": "suse",
      "title": "Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent",
      "affected": {
        "vendors": [
          "SUSE"
        ],
        "products": [
          {
            "vendor": "SUSE",
            "product": "Rancher"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00358,
        "percentile": 0.28503
      },
      "nvd": {
        "published": "2026-07-07T14:16:30.690",
        "lastModified": "2026-07-08T05:16:27.530",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44938",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Fleet copies repository-controlled namespace labels without filtering Pod Security Standards enforcement keys.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44938",
          "host": "bugzilla.suse.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/advisories/GHSA-864g-863m-vcvq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 518,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-44941",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T12:29:48.968Z",
      "date_published": "2026-07-02T15:19:05.302Z",
      "date_updated": "2026-07-07T13:14:20.403Z",
      "publisher": "suse",
      "title": "libzypp path traversal via \"keyhint\" in repomd.xml",
      "affected": {
        "vendors": [
          "SUSE"
        ],
        "products": [
          {
            "vendor": "SUSE",
            "product": "libzypp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.0052,
        "percentile": 0.41282
      },
      "nvd": {
        "published": "2026-07-02T16:16:30.550",
        "lastModified": "2026-07-07T17:27:50.640",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44941",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libzypp accepts traversal in the repository keyhint and writes the selected key outside the repository's intended key location.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=1267426",
          "host": "bugzilla.suse.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/openSUSE/libzypp/commit/294b1bad442d089ca671c5c03adc8031e3b29e04",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44943",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T12:29:48.968Z",
      "date_published": "2026-07-29T12:58:49.817Z",
      "date_updated": "2026-07-29T14:00:28.582Z",
      "publisher": "suse",
      "title": "remote limited file-write as root via discovery in open-iscsi",
      "affected": {
        "vendors": [
          "open-iscsi"
        ],
        "products": [
          {
            "vendor": "open-iscsi",
            "product": "open-iscsi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25549
      },
      "nvd": {
        "published": "2026-07-29T13:18:45.967",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44943",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44943",
          "host": "bugzilla.suse.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open-iscsi/open-iscsi/commit/668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 313,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44944",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T12:29:48.968Z",
      "date_published": "2026-07-29T13:04:50.575Z",
      "date_updated": "2026-07-29T14:00:52.512Z",
      "publisher": "suse",
      "title": "iscsiuio control-socket authentication bypass in open-iscsi",
      "affected": {
        "vendors": [
          "open-iscsi"
        ],
        "products": [
          {
            "vendor": "open-iscsi",
            "product": "open-iscsi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00093,
        "percentile": 0.00653
      },
      "nvd": {
        "published": "2026-07-29T13:18:46.113",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44944",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44944",
          "host": "bugzilla.suse.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open-iscsi/open-iscsi/commit/668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44955",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T17:14:43.840Z",
      "date_published": "2026-07-23T22:01:23.107Z",
      "date_updated": "2026-07-24T12:39:14.526Z",
      "publisher": "icscert",
      "title": "Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs",
      "affected": {
        "vendors": [
          "Pronetiqs"
        ],
        "products": [
          {
            "vendor": "Pronetiqs",
            "product": "Panduit Intravue"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00206,
        "percentile": 0.1084
      },
      "nvd": {
        "published": "2026-07-23T23:16:49.030",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44955",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44968",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T16:23:33.263Z",
      "date_published": "2026-07-16T17:48:29.604Z",
      "date_updated": "2026-07-17T18:10:05.040Z",
      "publisher": "GitHub_M",
      "title": "dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters",
      "affected": {
        "vendors": [
          "dbt-labs"
        ],
        "products": [
          {
            "vendor": "dbt-labs",
            "product": "dbt-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06846
      },
      "nvd": {
        "published": "2026-07-16T18:16:43.100",
        "lastModified": "2026-07-21T13:32:38.207",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44968",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted MCP values are appended as subprocess arguments without an option boundary, allowing them to become dbt global flags even though no shell is used.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dbt-labs/dbt-mcp/security/advisories/GHSA-xpww-f6pm-cfhq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dbt-labs/dbt-mcp/pull/752",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dbt-labs/dbt-mcp/commit/6534507b5e7a729758d5baece155602cad0bb22f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dbt-labs/dbt-mcp/releases/tag/v1.17.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 461,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44969",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T16:23:33.263Z",
      "date_published": "2026-07-16T17:49:50.663Z",
      "date_updated": "2026-07-17T18:06:51.913Z",
      "publisher": "GitHub_M",
      "title": "dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plaintext Without Redaction When File Logging Is Enabled",
      "affected": {
        "vendors": [
          "dbt-labs"
        ],
        "products": [
          {
            "vendor": "dbt-labs",
            "product": "dbt-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04517
      },
      "nvd": {
        "published": "2026-07-16T18:16:43.247",
        "lastModified": "2026-07-21T16:05:03.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44969",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "File logging records raw MCP tool arguments, including SQL and credentials, without redaction, rotation, or automatic deletion.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dbt-labs/dbt-mcp/security/advisories/GHSA-7xgw-6qf3-7w59",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dbt-labs/dbt-mcp/pull/752",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dbt-labs/dbt-mcp/commit/6534507b5e7a729758d5baece155602cad0bb22f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dbt-labs/dbt-mcp/releases/tag/v1.17.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 498,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44970",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T16:23:33.263Z",
      "date_published": "2026-07-16T17:49:19.310Z",
      "date_updated": "2026-07-18T03:02:18.972Z",
      "publisher": "GitHub_M",
      "title": "dbt-mcp: All MCP Tool Arguments Including Raw SQL and --vars Credentials Transmitted to dbt Labs Telemetry by Default Without Redaction",
      "affected": {
        "vendors": [
          "dbt-labs"
        ],
        "products": [
          {
            "vendor": "dbt-labs",
            "product": "dbt-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 1.1999999999999997,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14685
      },
      "nvd": {
        "published": "2026-07-16T18:16:43.377",
        "lastModified": "2026-07-21T16:04:44.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44970",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "dbt-mcp telemetry serializes complete tool arguments without redaction and sends values such as SQL, vars, and selections to the tracking service.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dbt-labs/dbt-mcp/security/advisories/GHSA-jj54-r8gm-2fcf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dbt-labs/dbt-mcp/pull/752",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dbt-labs/dbt-mcp/commit/6534507b5e7a729758d5baece155602cad0bb22f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dbt-labs/dbt-mcp/releases/tag/v1.17.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 581,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44974",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T16:23:33.263Z",
      "date_published": "2026-07-17T20:11:44.250Z",
      "date_updated": "2026-07-21T02:16:04.352Z",
      "publisher": "GitHub_M",
      "title": "Parameter smuggling in @hapi/content header parser allows upload-filter bypass via duplicate parameters",
      "affected": {
        "vendors": [
          "hapijs"
        ],
        "products": [
          {
            "vendor": "hapijs",
            "product": "content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.26997
      },
      "nvd": {
        "published": "2026-07-17T20:17:16.727",
        "lastModified": "2026-07-23T16:10:54.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44974",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Two header parsers choose different duplicate parameter occurrences, letting one component approve a filename that another component treats as executable.",
        "basis": [
          "CNA",
          "CWE-436"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hapijs/content/security/advisories/GHSA-36hh-x5p5-jgc8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hapijs/content/commit/3850079550c191d25e3643dc82a6d61144db8c2f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44978",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T16:23:33.264Z",
      "date_published": "2026-07-20T16:56:03.216Z",
      "date_updated": "2026-07-21T16:04:45.918Z",
      "publisher": "GitHub_M",
      "title": "xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verification",
      "affected": {
        "vendors": [
          "neutrinolabs"
        ],
        "products": [
          {
            "vendor": "neutrinolabs",
            "product": "xrdp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23825
      },
      "nvd": {
        "published": "2026-07-20T17:17:09.370",
        "lastModified": "2026-07-22T20:08:31.313",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-44978",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FIPS padding arithmetic can underflow and cause a read beyond the valid buffer.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9cg5-f7m7-ppvj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 979,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44979",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T16:23:33.264Z",
      "date_published": "2026-07-17T21:01:01.165Z",
      "date_updated": "2026-07-20T14:35:45.343Z",
      "publisher": "GitHub_M",
      "title": "@hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-hostname redirects",
      "affected": {
        "vendors": [
          "hapijs"
        ],
        "products": [
          {
            "vendor": "hapijs",
            "product": "wreck"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17676
      },
      "nvd": {
        "published": "2026-07-17T22:17:12.710",
        "lastModified": "2026-07-23T16:10:54.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44979",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cross-host redirects strip Authorization and Cookie but forward Proxy-Authorization to the new hostname.",
        "basis": [
          "CNA record",
          "CWE-200",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hapijs/wreck/security/advisories/GHSA-vhjm-w67q-g75c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hapijs/wreck/pull/312",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapijs/wreck/commit/a5b6fac9c684621c1d5733d10a0257697cfea373",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapijs/wreck/releases/tag/v18.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 502,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T16:23:33.264Z",
      "date_published": "2026-07-16T19:47:30.747Z",
      "date_updated": "2026-07-17T13:50:30.497Z",
      "publisher": "GitHub_M",
      "title": "CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression",
      "affected": {
        "vendors": [
          "crowdsecurity"
        ],
        "products": [
          {
            "vendor": "crowdsecurity",
            "product": "crowdsec"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21409
      },
      "nvd": {
        "published": "2026-07-16T20:16:44.900",
        "lastModified": "2026-07-17T18:44:13.257",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44981",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "crowdsec expands attacker-controlled archive content without a bound on resulting resource use.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/crowdsecurity/crowdsec/security/advisories/GHSA-273h-gvwr-c3qj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/crowdsecurity/crowdsec/commit/54a0dfe6c16b7687b0da6634e0b19ef0f5d9bb30",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/crowdsecurity/crowdsec/commit/56d0d6915f7f25941dc5b4f484028646f6601a37",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 471,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T16:23:33.264Z",
      "date_published": "2026-07-16T19:50:26.067Z",
      "date_updated": "2026-07-17T15:01:59.005Z",
      "publisher": "GitHub_M",
      "title": "CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests",
      "affected": {
        "vendors": [
          "crowdsecurity"
        ],
        "products": [
          {
            "vendor": "crowdsecurity",
            "product": "crowdsec"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12244
      },
      "nvd": {
        "published": "2026-07-16T20:16:45.033",
        "lastModified": "2026-07-17T18:44:13.257",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44982",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CrowdSec treats chunked or headerless HTTP bodies as empty because it sizes the WAF buffer only from Content-Length, so body rules never inspect them.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/crowdsecurity/crowdsec/security/advisories/GHSA-rw47-hm26-6wr7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/crowdsecurity/crowdsec/pull/4355",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/crowdsecurity/crowdsec/commit/3d5c4d9b127091e9063b9b5eb785372a599a4435",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/crowdsecurity/crowdsec/commit/57a793548671e6bbd2cde5562fe87b856ec9c642",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/crowdsecurity/crowdsec/releases/tag/v1.7.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 460,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-44986",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T16:23:33.265Z",
      "date_published": "2026-07-15T15:08:37.367Z",
      "date_updated": "2026-07-15T15:40:07.943Z",
      "publisher": "GitHub_M",
      "title": "Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile",
      "affected": {
        "vendors": [
          "penpot"
        ],
        "products": [
          {
            "vendor": "penpot",
            "product": "penpot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20575
      },
      "nvd": {
        "published": "2026-07-15T16:16:45.513",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-44986",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Penpot exposes invitation tokens and issues a session for an invitation email match without verifying the existing profile's password.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/penpot/penpot/security/advisories/GHSA-4937-35vc-hqjj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/penpot/penpot/pull/9380",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/penpot/penpot/commit/9e681260ccc4feb6c564ff0773fb9594b462c574",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/penpot/penpot/releases/tag/2.14.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 464,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45045",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:07:27.341Z",
      "date_published": "2026-07-08T19:26:26.580Z",
      "date_updated": "2026-07-09T13:20:08.367Z",
      "publisher": "GitHub_M",
      "title": "Fiber: X-Real-IP Spoofing via Header.Add() in BalancerForward",
      "affected": {
        "vendors": [
          "gofiber"
        ],
        "products": [
          {
            "vendor": "gofiber",
            "product": "fiber"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00363,
        "percentile": 0.29038
      },
      "nvd": {
        "published": "2026-07-08T20:16:50.060",
        "lastModified": "2026-07-15T20:50:55.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45045",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The receiver accepts an attacker-controlled identity signal without verifying the channel evidence that should authenticate its sender.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gofiber/fiber/security/advisories/GHSA-gcfq-8gqf-4876",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gofiber/fiber/pull/4260",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gofiber/fiber/pull/4495",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gofiber/fiber/commit/1403cc8292da3220e9316960b4030cc722a0f396",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gofiber/fiber/commit/33c9501288ab47a429c8b5e701493f0c3c0af37d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gofiber/fiber/releases/tag/v2.52.14",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gofiber/fiber/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 401,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-45063",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.095Z",
      "date_published": "2026-07-14T18:28:22.074Z",
      "date_updated": "2026-07-14T19:46:44.743Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25476
      },
      "nvd": {
        "published": "2026-07-14T19:17:05.620",
        "lastModified": "2026-07-15T15:01:08.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45063",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "X509Authenticator uses an unanchored emailAddress regex over the whole certificate DN, so text embedded in another RDN can be selected as the user identity.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-ph86-p8f6-f9r2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/59ef484029601a7af06f5e06c6ed921fdcea5a0d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 524,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-45064",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.095Z",
      "date_published": "2026-07-14T18:35:53.530Z",
      "date_updated": "2026-07-21T19:09:27.830Z",
      "publisher": "GitHub_M",
      "title": "Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "html-sanitizer"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1007",
          "name": "Insufficient Visual Distinction of Homoglyphs Presented to User",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21579
      },
      "nvd": {
        "published": "2026-07-14T19:17:05.763",
        "lastModified": "2026-07-21T20:17:00.933",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45064",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The symfony URL parser preserves visual-direction controls that make the displayed destination differ from its logical value.",
        "basis": [
          "CNA",
          "CWE-451",
          "CWE-1007"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-h5vq-qfcg-4m6p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/743a435e948b897ef2b5564ac438d4beb95d2526",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 491,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-45065",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.096Z",
      "date_published": "2026-07-14T17:43:45.644Z",
      "date_updated": "2026-07-14T19:51:44.841Z",
      "publisher": "GitHub_M",
      "title": "Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-185",
          "name": "Incorrect Regular Expression",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17713
      },
      "nvd": {
        "published": "2026-07-14T18:17:16.550",
        "lastModified": "2026-07-15T14:14:18.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45065",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A flawed alternation in URL validation accepts a protocol-relative //evil destination as a trusted redirect.",
        "basis": [
          "CNA",
          "CWE-185",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-72xp-p242-47p9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-45066",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.096Z",
      "date_published": "2026-07-14T17:53:49.836Z",
      "date_updated": "2026-07-16T14:29:30.033Z",
      "publisher": "GitHub_M",
      "title": "Symfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "html-sanitizer"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22058
      },
      "nvd": {
        "published": "2026-07-14T18:17:16.703",
        "lastModified": "2026-07-16T15:16:31.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45066",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Two symfony request-processing stages interpret the same attacker-controlled route or URL syntax differently and cross the intended routing boundary.",
        "basis": [
          "CNA",
          "CWE-184",
          "CWE-436"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-qc95-4862-92fh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/d506b556d3d3906f3e8660ad82257ce87edbaac4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-45067",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.096Z",
      "date_published": "2026-07-14T17:41:53.874Z",
      "date_updated": "2026-07-14T18:15:43.658Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\\Component\\Mime\\Address",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00619,
        "percentile": 0.46212
      },
      "nvd": {
        "published": "2026-07-14T18:17:16.847",
        "lastModified": "2026-07-14T20:25:54.190",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45067",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Symfony Address permits newline characters in an address value that is later emitted into an email header.",
        "basis": [
          "CNA",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-qpmx-3rfj-7rhv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/a1c42cbe517bc146a54da7505a107ded317478fe",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1062,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-45068",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.096Z",
      "date_published": "2026-07-14T19:02:10.265Z",
      "date_updated": "2026-07-15T13:24:09.154Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "mailer"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00407,
        "percentile": 0.33481
      },
      "nvd": {
        "published": "2026-07-14T20:17:00.107",
        "lastModified": "2026-07-15T14:18:10.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45068",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line without a -- end-of-options separator, allowing an address beginning with - to be interpreted as a sendmail command-line option instead of an address.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-xx3c-qf5g-hc39",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/c45144862dc289d03952f41f6078174089a3afc6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 448,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-45069",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.096Z",
      "date_published": "2026-07-14T18:46:54.011Z",
      "date_updated": "2026-07-14T19:46:35.158Z",
      "publisher": "GitHub_M",
      "title": "Symfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "security-http"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1287",
          "name": "Improper Validation of Specified Type of Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.29999999999999893,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14767
      },
      "nvd": {
        "published": "2026-07-14T19:17:06.017",
        "lastModified": "2026-07-15T15:02:19.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45069",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OIDC token validation omits mandatory claim checks before accepting the token.",
        "basis": [
          "CNA",
          "CWE-345",
          "CWE-1287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-29fc-p6c4-24cg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 445,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-45070",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.096Z",
      "date_published": "2026-07-14T18:25:46.647Z",
      "date_updated": "2026-07-16T14:31:20.673Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Email Header Injection via Non-Token Characters in Mime Parameter Names",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "mime"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21496
      },
      "nvd": {
        "published": "2026-07-14T19:17:06.147",
        "lastModified": "2026-07-16T15:16:31.487",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45070",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ParameterizedHeader validates mail-header parameter values but emits attacker-controlled parameter names verbatim, allowing CRLF to create additional headers.",
        "basis": [
          "CNA",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-vqc8-7275-q272",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/e62ea217f8b4ca8ae922ad0f949e0c4dc1f9b613",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-45071",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.096Z",
      "date_published": "2026-07-14T18:58:15.162Z",
      "date_updated": "2026-07-15T14:21:08.891Z",
      "publisher": "GitHub_M",
      "title": "Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "dom-crawler"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37694
      },
      "nvd": {
        "published": "2026-07-14T20:17:00.370",
        "lastModified": "2026-07-15T15:16:33.777",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45071",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Symfony's validateOnParse option can re-enable external-entity resolution after the caller selected a safe XML parsing posture.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-x6g4-fwcc-jj8w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/eea5fd7488cbdc241da4ce242344b7d9a3ecdf3d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-45072",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.096Z",
      "date_published": "2026-07-14T18:11:07.748Z",
      "date_updated": "2026-07-15T13:26:50.587Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "twig-bridge"
          },
          {
            "vendor": "symfony",
            "product": "web-profiler-bundle"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 3.4000000000000004,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14118
      },
      "nvd": {
        "published": "2026-07-14T19:17:06.277",
        "lastModified": "2026-07-16T03:12:44.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45072",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-hmr5-2xcr-v8pp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/863aa81c61166f1aa74b7732df316f76113acbdb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-45073",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.096Z",
      "date_published": "2026-07-14T18:23:41.235Z",
      "date_updated": "2026-07-14T19:14:47.342Z",
      "publisher": "GitHub_M",
      "title": "Symfony: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix",
      "affected": {
        "vendors": [
          "cache",
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "cache",
            "product": "symfony"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33711
      },
      "nvd": {
        "published": "2026-07-14T19:17:06.413",
        "lastModified": "2026-07-15T14:51:54.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45073",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PdoAdapter::doClear interpolates caller-supplied prefix data into a SQL LIKE literal without binding or escaping it.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-6qh9-h6wf-jgqc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/ec50b799d79ebe24561f29351c1efcb6da95c9b1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 471,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-45074",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.096Z",
      "date_published": "2026-07-14T17:49:24.895Z",
      "date_updated": "2026-07-14T18:24:34.062Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "security-http"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00413,
        "percentile": 0.33981
      },
      "nvd": {
        "published": "2026-07-14T18:17:16.990",
        "lastModified": "2026-07-15T15:35:14.170",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45074",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Cas2Handler derives the CAS service URL from an untrusted Host header, allowing a ticket issued for another registered service to be replayed.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-j8gj-9rm5-4xhx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/5ba145dba702404801bdf9e7e8d6df170060d541",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 536,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-45075",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.096Z",
      "date_published": "2026-07-14T18:40:37.287Z",
      "date_updated": "2026-07-16T14:38:19.284Z",
      "publisher": "GitHub_M",
      "title": "Symfony: HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "http-kernel"
          },
          {
            "vendor": "symfony",
            "product": "security-http"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30943
      },
      "nvd": {
        "published": "2026-07-14T19:17:06.650",
        "lastModified": "2026-07-16T15:16:31.607",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45075",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Symfony routes HEAD to a GET controller but skips method-scoped authorization, signature, and CSRF attributes configured only for GET.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-6439-2f28-8p8q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 466,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-45077",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T18:45:10.097Z",
      "date_published": "2026-07-14T17:46:33.837Z",
      "date_updated": "2026-07-14T18:24:19.069Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "monolog-bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-668",
          "name": "Exposure of Resource to Wrong Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.29999999999999893,
      "epss": {
        "score": 0.00447,
        "percentile": 0.36753
      },
      "nvd": {
        "published": "2026-07-14T18:17:17.130",
        "lastModified": "2026-07-15T15:35:50.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45077",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unauthenticated server:log listener base64-decodes network frames and passes them to PHP unserialize without an allowed-class boundary or integrity check.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-m7v2-7gxm-vc2v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/0891b2f293896c488e26943dc034334364b77fc4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 623,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-45086",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T19:27:26.697Z",
      "date_published": "2026-07-31T21:44:11.803Z",
      "date_updated": "2026-08-03T17:16:23.640Z",
      "publisher": "GitHub_M",
      "title": "Decidim: Forms admin question editor lacks authorization",
      "affected": {
        "vendors": [
          "decidim"
        ],
        "products": [
          {
            "vendor": "decidim",
            "product": "decidim"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06785
      },
      "nvd": {
        "published": "2026-07-31T22:17:02.157",
        "lastModified": "2026-08-03T18:16:39.203",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45086",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The /admin/demographics/questions route renders the live questionnaire editor to an ordinary participant without checking administrator status.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decidim/decidim/security/advisories/GHSA-vq6j-hj8w-7v39",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decidim/decidim/commit/fa52fb631a0788b30895d1312728a888607d81b5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decidim/decidim/commit/fc89301c6697c6101a7aed3fced3fa8311048cb9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 662,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-45112",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T20:04:35.618Z",
      "date_published": "2026-07-27T10:57:34.326Z",
      "date_updated": "2026-07-27T13:02:07.682Z",
      "publisher": "apache",
      "title": "Apache Thrift: Unbounded Read Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0194,
        "percentile": 0.78129
      },
      "nvd": {
        "published": "2026-07-27T12:16:44.560",
        "lastModified": "2026-07-27T19:51:07.873",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45112",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Java bindings allocate work or memory from attacker-controlled Thrift input without an effective upper bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/hl9kmf1z2o3lxvspoj3g9ykl8lj9mdxc",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/34",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45133",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T20:08:17.209Z",
      "date_published": "2026-07-14T18:45:03.458Z",
      "date_updated": "2026-07-15T13:25:32.835Z",
      "publisher": "GitHub_M",
      "title": "Symfony: [Yaml] Harden the parser when handling untrusted input",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-776",
          "name": "Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.0074,
        "percentile": 0.51084
      },
      "nvd": {
        "published": "2026-07-14T19:17:06.913",
        "lastModified": "2026-07-15T14:54:50.237",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45133",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The parser in symfony follows attacker-controlled nesting without a depth bound and exhausts the call stack.",
        "basis": [
          "CNA",
          "CWE-674",
          "CWE-776",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-c2p3-7m5p-cv8x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 523,
        "referenceCount": 5,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-45138",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T20:44:38.962Z",
      "date_published": "2026-07-19T23:18:51.312Z",
      "date_updated": "2026-07-20T13:18:54.966Z",
      "publisher": "GitHub_M",
      "title": "CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule",
      "affected": {
        "vendors": [
          "ci4-cms-erp"
        ],
        "products": [
          {
            "vendor": "ci4-cms-erp",
            "product": "ci4ms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.0436
      },
      "nvd": {
        "published": "2026-07-20T00:16:58.363",
        "lastModified": "2026-07-21T20:27:18.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45138",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ci4ms places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-2m69-jmvh-6chr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ci4-cms-erp/ci4ms/releases/tag/0.31.9.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 618,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45139",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T20:44:38.963Z",
      "date_published": "2026-07-20T13:58:39.800Z",
      "date_updated": "2026-07-20T16:40:55.398Z",
      "publisher": "GitHub_M",
      "title": "CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations",
      "affected": {
        "vendors": [
          "ci4-cms-erp"
        ],
        "products": [
          {
            "vendor": "ci4-cms-erp",
            "product": "ci4ms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18655
      },
      "nvd": {
        "published": "2026-07-20T15:16:38.020",
        "lastModified": "2026-07-21T20:27:18.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45139",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The delete and rename endpoints accept source paths for extensions excluded from write operations and can select critical project files.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-245j-xjvr-xvm5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ci4-cms-erp/ci4ms/releases/tag/0.31.9.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 914,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45150",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T20:44:38.964Z",
      "date_published": "2026-07-15T15:35:17.010Z",
      "date_updated": "2026-07-15T17:44:16.341Z",
      "publisher": "GitHub_M",
      "title": "Zen Browser - Missing Fullscreen Security Notification Allows Origin Spoofing",
      "affected": {
        "vendors": [
          "zen-browser"
        ],
        "products": [
          {
            "vendor": "zen-browser",
            "product": "desktop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16737
      },
      "nvd": {
        "published": "2026-07-15T16:16:45.657",
        "lastModified": "2026-07-15T20:51:32.813",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45150",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Zen Browser enters fullscreen without a persistent origin warning, allowing page content to hide the real browser UI and impersonate another origin.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zen-browser/desktop/security/advisories/GHSA-vjfv-85qf-v25c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 432,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45162",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-08T20:44:38.965Z",
      "date_published": "2026-07-17T18:50:19.924Z",
      "date_updated": "2026-07-17T23:15:31.060Z",
      "publisher": "GitHub_M",
      "title": "Pimcore: Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction",
      "affected": {
        "vendors": [
          "pimcore"
        ],
        "products": [
          {
            "vendor": "pimcore",
            "product": "pimcore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00574,
        "percentile": 0.44146
      },
      "nvd": {
        "published": "2026-07-17T19:17:14.167",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45162",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pimcore calls PHP unserialize on database and filesystem data without restricting allowed classes.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-36fc-7wjg-mfvj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/pull/19119",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/commit/4788bf3a3a7f2f760a8fe61e522565941e154e1e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/releases/tag/v12.3.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-45196",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T10:58:04.162Z",
      "date_published": "2026-07-10T20:53:50.761Z",
      "date_updated": "2026-07-15T03:59:55.338Z",
      "publisher": "imaginationtech",
      "title": "GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel",
      "affected": {
        "vendors": [
          "Imagination Technologies"
        ],
        "products": [
          {
            "vendor": "Imagination Technologies",
            "product": "Graphics DDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-280",
          "name": "Improper Handling of Insufficient Permissions or Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01266
      },
      "nvd": {
        "published": "2026-07-10T21:16:54.657",
        "lastModified": "2026-07-15T05:16:39.470",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45196",
        "family": "HARDWARE_PHYSICAL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The GPU firmware accepts host-kernel commands containing unvalidated pointers and uses them to select privileged GPU registers.",
        "basis": [
          "CNA",
          "CWE-280"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
          "host": "www.imaginationtech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 174,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-45203",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T10:58:04.163Z",
      "date_published": "2026-07-10T20:57:19.733Z",
      "date_updated": "2026-07-13T18:55:12.679Z",
      "publisher": "imaginationtech",
      "title": "GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial check, TOCTOU",
      "affected": {
        "vendors": [
          "Imagination Technologies"
        ],
        "products": [
          {
            "vendor": "Imagination Technologies",
            "product": "Graphics DDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00092,
        "percentile": 0.00609
      },
      "nvd": {
        "published": "2026-07-10T21:16:54.760",
        "lastModified": "2026-07-13T19:24:52.303",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45203",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A GPU firmware command is validated against host memory in one state and used after that state can change, allowing a TOCTOU write outside the permitted host range.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
          "host": "www.imaginationtech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 307,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-45260",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T18:41:13.155Z",
      "date_published": "2026-07-17T19:08:38.869Z",
      "date_updated": "2026-07-21T02:01:19.740Z",
      "publisher": "GitHub_M",
      "title": "Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling",
      "affected": {
        "vendors": [
          "pimcore"
        ],
        "products": [
          {
            "vendor": "pimcore",
            "product": "pimcore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00427,
        "percentile": 0.35172
      },
      "nvd": {
        "published": "2026-07-17T20:17:16.857",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45260",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Pimcore executes WebDAV MOVE mutations before checking the current user and the required rename, delete, create, or publish permissions.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-wc7j-g8wx-m2qx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/pull/19120",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/commit/9d7c77fd9b19fa011ce470de95d4438e65007d99",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/releases/tag/v12.3.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-45270",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T18:41:13.156Z",
      "date_published": "2026-07-20T14:12:13.093Z",
      "date_updated": "2026-07-20T15:11:27.452Z",
      "publisher": "GitHub_M",
      "title": "CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule",
      "affected": {
        "vendors": [
          "ci4-cms-erp"
        ],
        "products": [
          {
            "vendor": "ci4-cms-erp",
            "product": "ci4ms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10928
      },
      "nvd": {
        "published": "2026-07-20T15:16:38.163",
        "lastModified": "2026-07-21T20:27:18.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45270",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The public renderer for pages (`Home::index()` → `app/Views/templates/default/pages.php`) emits `$pageInfo->content` without `esc()`, yielding stored XSS that fires for every public visitor of the affected page — including administrators.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-gqr2-7hcg-rchf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ci4-cms-erp/ci4ms/releases/tag/0.31.9.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 657,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45293",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T20:14:43.201Z",
      "date_published": "2026-07-28T15:34:45.092Z",
      "date_updated": "2026-07-29T13:47:28.857Z",
      "publisher": "GitHub_M",
      "title": "WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability",
      "affected": {
        "vendors": [
          "WordPress"
        ],
        "products": [
          {
            "vendor": "WordPress",
            "product": "WordPress-Coding-Standards"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-95",
          "name": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08257
      },
      "nvd": {
        "published": "2026-07-28T16:18:13.503",
        "lastModified": "2026-07-29T14:16:30.737",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45293",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WordPressCS sniff inserts an untrusted tag extension into a vimgrep command evaluated by Vim's command parser.",
        "basis": [
          "CNA",
          "CWE-95"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WordPress/WordPress-Coding-Standards/security/advisories/GHSA-3pwp-g2mj-5p3v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/WordPress/WordPress-Coding-Standards/pull/2771",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/WordPress/WordPress-Coding-Standards/commit/a29048d0bbef5cf25d42349c74e4072d3cbc8325",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/WordPress/WordPress-Coding-Standards/releases/tag/3.4.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 790,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45295",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T20:14:43.201Z",
      "date_published": "2026-07-20T17:21:49.659Z",
      "date_updated": "2026-07-20T21:42:07.963Z",
      "publisher": "GitHub_M",
      "title": "FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint",
      "affected": {
        "vendors": [
          "freescout-help-desk"
        ],
        "products": [
          {
            "vendor": "freescout-help-desk",
            "product": "freescout"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.10007
      },
      "nvd": {
        "published": "2026-07-20T18:16:52.580",
        "lastModified": "2026-07-21T19:25:11.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45295",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The tracking endpoint accepts caller-supplied conversation and thread identifiers without authentication or ownership checks before updating opened_at.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-qjr9-6v9q-3r72",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 376,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45304",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T20:14:43.202Z",
      "date_published": "2026-07-14T18:48:49.329Z",
      "date_updated": "2026-07-14T19:13:39.323Z",
      "publisher": "GitHub_M",
      "title": "Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion (\"Billion Laughs\")",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "yaml"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-776",
          "name": "Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00804,
        "percentile": 0.53217
      },
      "nvd": {
        "published": "2026-07-14T19:17:07.050",
        "lastModified": "2026-07-15T14:55:30.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45304",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Recursive YAML alias expansion has no effective expansion bound, allowing a small document to allocate an enormous object graph.",
        "basis": [
          "CNA",
          "CWE-776"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-4qpc-3hr4-r2p4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/e77391b2e4f18821198f010d573674c8ed4a970a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 386,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-45305",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T20:14:43.202Z",
      "date_published": "2026-07-14T18:50:14.830Z",
      "date_updated": "2026-07-15T14:03:58.116Z",
      "publisher": "GitHub_M",
      "title": "Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "yaml"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00804,
        "percentile": 0.53217
      },
      "nvd": {
        "published": "2026-07-14T19:17:07.187",
        "lastModified": "2026-07-15T14:57:02.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45305",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "symfony applies an algorithm with attacker-triggered worst-case complexity without a work bound, allowing CPU exhaustion.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-9frc-8383-795m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/9749cd43c5e09b3735093623670b21b9d8a056cb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-45309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T20:14:43.203Z",
      "date_published": "2026-07-17T18:40:02.428Z",
      "date_updated": "2026-07-21T01:55:16.704Z",
      "publisher": "GitHub_M",
      "title": "AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username",
      "affected": {
        "vendors": [
          "ronf"
        ],
        "products": [
          {
            "vendor": "ronf",
            "product": "asyncssh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.0044,
        "percentile": 0.36181
      },
      "nvd": {
        "published": "2026-07-17T19:17:14.333",
        "lastModified": "2026-07-30T14:36:48.647",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45309",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AuthorizedKeysFile expands a raw pre-authentication username into a path and can read an attacker-selected key file outside the configured directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ronf/asyncssh/security/advisories/GHSA-g794-3fmp-753h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ronf/asyncssh/commit/2af2382cce946c959a378a62f257af253dc4ab51",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ronf/asyncssh/commit/3d515ba9ba0cd9990d248bdf62bcf05d51261a88",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 698,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45313",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T20:50:30.538Z",
      "date_published": "2026-07-15T21:21:23.091Z",
      "date_updated": "2026-07-16T12:52:46.717Z",
      "publisher": "GitHub_M",
      "title": "Sandboxie-Plus: Sandboxie APC Injection Sandbox Escape",
      "affected": {
        "vendors": [
          "sandboxie-plus"
        ],
        "products": [
          {
            "vendor": "sandboxie-plus",
            "product": "Sandboxie"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00108,
        "percentile": 0.01398
      },
      "nvd": {
        "published": "2026-07-15T22:16:48.873",
        "lastModified": "2026-07-16T14:16:52.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45313",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GUI request handles and a function pointer are accepted without binding them to the sandboxed process that owns them.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sandboxie-plus/Sandboxie/security/advisories/GHSA-rmv3-fhg3-75xh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/sandboxie-plus/Sandboxie/releases/tag/v1.17.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 687,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45320",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T20:50:30.539Z",
      "date_published": "2026-07-15T19:40:28.311Z",
      "date_updated": "2026-07-17T19:06:13.550Z",
      "publisher": "GitHub_M",
      "title": "DataEase Data Dashboard SqlVariable transFilter Unfiltered SQL Injection",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18881
      },
      "nvd": {
        "published": "2026-07-15T20:17:03.387",
        "lastModified": "2026-07-17T20:17:16.993",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45320",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "transFilter returns raw values for some operators and SubstitutedSql splices them into dashboard SQL.",
        "basis": [
          "CNA record",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-8vp9-9hx4-6458",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/163d510c6935a4010727392f5a680a7dc15abb13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 476,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45325",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T20:50:30.539Z",
      "date_published": "2026-07-16T16:41:30.157Z",
      "date_updated": "2026-07-17T18:06:58.358Z",
      "publisher": "GitHub_M",
      "title": "Gestor de Oferta: Prototype pollution in @tmlmobilidade/utils setValueAtPath",
      "affected": {
        "vendors": [
          "tmlmobilidade"
        ],
        "products": [
          {
            "vendor": "tmlmobilidade",
            "product": "go"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18668
      },
      "nvd": {
        "published": "2026-07-16T17:16:56.160",
        "lastModified": "2026-07-17T19:17:14.473",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45325",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "go allows special property names to modify the shared JavaScript object prototype.",
        "basis": [
          "CNA",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tmlmobilidade/go/security/advisories/GHSA-cmxg-94mg-jq94",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/tmlmobilidade/go/commit/b10505baa7ba0701f830a05f3007c0a6bdd00eb7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45330",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T20:50:30.540Z",
      "date_published": "2026-07-31T22:05:21.773Z",
      "date_updated": "2026-08-03T20:35:20.109Z",
      "publisher": "GitHub_M",
      "title": "Decidim: Veriﬁcation admins can access supplied IDs from other organisations",
      "affected": {
        "vendors": [
          "decidim"
        ],
        "products": [
          {
            "vendor": "decidim",
            "product": "decidim"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20129
      },
      "nvd": {
        "published": "2026-07-31T23:17:24.233",
        "lastModified": "2026-08-03T21:16:39.197",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45330",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The verification controller loads an authorization by raw identifier without constraining it to the administrator's current organization.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decidim/decidim/security/advisories/GHSA-86fh-w43w-338c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decidim/decidim/releases/tag/v0.30.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decidim/decidim/releases/tag/v0.31.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decidim/decidim/releases/tag/v0.32.0.rc2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 457,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-45334",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T20:50:30.540Z",
      "date_published": "2026-07-16T21:42:51.081Z",
      "date_updated": "2026-07-17T18:06:29.822Z",
      "publisher": "GitHub_M",
      "title": "Kirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12031
      },
      "nvd": {
        "published": "2026-07-16T22:17:02.550",
        "lastModified": "2026-07-17T19:17:14.577",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45334",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kirby's content-lock payload returns a locking user's email and identifier without applying the requester's users.access or users.list restrictions.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-39vq-49qm-r2mc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1401,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-45336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T21:40:08.176Z",
      "date_published": "2026-07-16T17:03:00.629Z",
      "date_updated": "2026-07-17T18:06:55.113Z",
      "publisher": "GitHub_M",
      "title": "HireFlow: Use of Hard-coded Credentials",
      "affected": {
        "vendors": [
          "StratonWebDesigners"
        ],
        "products": [
          {
            "vendor": "StratonWebDesigners",
            "product": "HireFlow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00428,
        "percentile": 0.35238
      },
      "nvd": {
        "published": "2026-07-16T18:16:43.517",
        "lastModified": "2026-07-17T19:17:14.687",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45336",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application uses a hard-coded signing secret whose public value lets an attacker forge trusted credentials.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/StratonWebDesigners/HireFlow/security/advisories/GHSA-x53g-jr84-jrv5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/StratonWebDesigners/HireFlow/releases/tag/v1.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 418,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45337",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-11T21:40:08.176Z",
      "date_published": "2026-07-15T17:31:44.983Z",
      "date_updated": "2026-07-15T18:02:58.506Z",
      "publisher": "GitHub_M",
      "title": "Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending",
      "affected": {
        "vendors": [
          "better-auth"
        ],
        "products": [
          {
            "vendor": "better-auth",
            "product": "better-auth"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03846
      },
      "nvd": {
        "published": "2026-07-15T18:16:45.580",
        "lastModified": "2026-07-21T04:21:25.230",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45337",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The pending device-code row is not claimed by its initiating user, and approve or deny accepts any authenticated session while userId is unset.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-285",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-cq3f-vc6p-68fh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/pull/9573",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/commit/99a254a79b59d5a3f5ca2123260118cddb5beed7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/releases/tag/v1.6.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 514,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45363",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T00:51:29.085Z",
      "date_published": "2026-07-14T21:32:26.676Z",
      "date_updated": "2026-07-15T13:26:21.205Z",
      "publisher": "GitHub_M",
      "title": "`jwt` (Ruby gem) - empty-key HMAC bypass",
      "affected": {
        "vendors": [
          "jwt"
        ],
        "products": [
          {
            "vendor": "jwt",
            "product": "ruby-jwt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-326",
          "name": "Inadequate Encryption Strength",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1391",
          "name": "Use of Weak Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15426
      },
      "nvd": {
        "published": "2026-07-14T22:16:54.463",
        "lastModified": "2026-07-15T20:23:47.313",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45363",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ruby-jwt treats an empty HMAC key as a valid HS256 verification secret, allowing an attacker who knows that empty value to forge an accepted token.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-326",
          "CWE-1391"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jwt/ruby-jwt/security/advisories/GHSA-c32j-vqhx-rx3x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/jwt/ruby-jwt/commit/9820020869ad147b941e49d96ab8beba35532964",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jwt/ruby-jwt/commit/db560b769a07bd9724e77ff505011ac01872106f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jwt/ruby-jwt/releases/tag/v2.10.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jwt/ruby-jwt/releases/tag/v3.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 648,
        "referenceCount": 5,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-45367",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T00:51:29.085Z",
      "date_published": "2026-07-16T16:52:04.901Z",
      "date_updated": "2026-07-18T03:00:14.087Z",
      "publisher": "GitHub_M",
      "title": "HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint",
      "affected": {
        "vendors": [
          "hapifhir"
        ],
        "products": [
          {
            "vendor": "hapifhir",
            "product": "org.hl7.fhir.core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00489,
        "percentile": 0.39411
      },
      "nvd": {
        "published": "2026-07-16T17:16:56.293",
        "lastModified": "2026-07-18T03:16:35.910",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45367",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-selected regular expression can trigger unbounded backtracking and consume CPU without an effective work limit.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-3653-68v6-rq57",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/pull/2403",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/pull/2463",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/commit/275d015c680ce9f90cbe285596e50118e472bf24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/commit/e08982d2b6f6dcd6c670a762d9cf999179fbe4ed",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/releases/tag/6.9.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45368",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T00:51:29.085Z",
      "date_published": "2026-07-16T21:49:46.244Z",
      "date_updated": "2026-07-18T03:18:56.903Z",
      "publisher": "GitHub_M",
      "title": "Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00334,
        "percentile": 0.2596
      },
      "nvd": {
        "published": "2026-07-16T22:17:02.680",
        "lastModified": "2026-07-18T05:16:53.790",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45368",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The kirby rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-qvjf-922g-pj44",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1035,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-45376",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T00:51:29.086Z",
      "date_published": "2026-07-31T22:34:27.181Z",
      "date_updated": "2026-08-03T17:13:15.144Z",
      "publisher": "GitHub_M",
      "title": "Decidim: Admin user search allows SQL injection through similarity-based sorting",
      "affected": {
        "vendors": [
          "decidim"
        ],
        "products": [
          {
            "vendor": "decidim",
            "product": "decidim"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00341,
        "percentile": 0.26782
      },
      "nvd": {
        "published": "2026-07-31T23:17:24.373",
        "lastModified": "2026-08-03T18:16:39.320",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45376",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Decidim passes attacker-influenced ordering input through Arel.sql and into an SQL order expression without parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decidim/decidim/security/advisories/GHSA-jvqq-cvh4-xm37",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decidim/decidim/commit/27335957b363516e23919a9006812f1c458c88e0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decidim/decidim/commit/e4d21b41fb462d9436035a043962a4090f2cc240",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decidim/decidim/commit/f3817fac448a4e3facd6bcb346167048b3421124",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decidim/decidim/releases/tag/v0.30.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decidim/decidim/releases/tag/v0.31.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decidim/decidim/releases/tag/v0.32.0.rc2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 467,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-45377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T00:51:29.086Z",
      "date_published": "2026-07-31T22:58:22.730Z",
      "date_updated": "2026-07-31T23:37:39.654Z",
      "publisher": "GitHub_M",
      "title": "Decidim: Private exports can be downloaded through reusable links",
      "affected": {
        "vendors": [
          "decidim"
        ],
        "products": [
          {
            "vendor": "decidim",
            "product": "decidim"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19571
      },
      "nvd": {
        "published": "2026-07-31T23:17:24.520",
        "lastModified": "2026-08-01T00:17:16.600",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45377",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A signed Decidim blob URL remains replayable outside the owner-checked request that produced it, so possession of the URL bypasses the intended per-request ownership state.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decidim/decidim/security/advisories/GHSA-767h-63j4-5226",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decidim/decidim/pull/16680",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 596,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-45382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T00:51:29.087Z",
      "date_published": "2026-07-21T20:57:48.312Z",
      "date_updated": "2026-07-23T14:10:50.623Z",
      "publisher": "GitHub_M",
      "title": "libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometry",
      "affected": {
        "vendors": [
          "strukturag"
        ],
        "products": [
          {
            "vendor": "strukturag",
            "product": "libde265"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16769
      },
      "nvd": {
        "published": "2026-07-21T21:16:49.863",
        "lastModified": "2026-07-23T18:18:16.703",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45382",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` at line 966 where `ctbAddrRS = ctbY * ctbsWidth + ctbX` is computed from PPS-supplied `colBd[]`/`rowBd[]` arrays without validating the result against `CtbAddrRStoTS.size() == sps->PicSizeInCtbsY`.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/strukturag/libde265/security/advisories/GHSA-hwhx-x2mq-ccr9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 611,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T00:51:29.087Z",
      "date_published": "2026-07-21T21:00:30.875Z",
      "date_updated": "2026-07-22T15:36:32.304Z",
      "publisher": "GitHub_M",
      "title": "libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18",
      "affected": {
        "vendors": [
          "strukturag"
        ],
        "products": [
          {
            "vendor": "strukturag",
            "product": "libde265"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.1729
      },
      "nvd": {
        "published": "2026-07-21T21:16:50.000",
        "lastModified": "2026-07-23T18:18:08.310",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45383",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the valid input or buffer boundary because its size check is incomplete.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/strukturag/libde265/security/advisories/GHSA-wg9q-ppqw-6q38",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 652,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45417",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T01:48:40.453Z",
      "date_published": "2026-07-15T19:20:16.815Z",
      "date_updated": "2026-07-16T15:12:51.317Z",
      "publisher": "GitHub_M",
      "title": "DataEase: SQL injection vulnerability",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13556
      },
      "nvd": {
        "published": "2026-07-15T20:17:03.970",
        "lastModified": "2026-07-16T16:19:08.067",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45417",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-rg6c-r9mv-39fr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/f1c7204da1787ef812ee23cd3d51a1824126c1fb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 427,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45419",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T01:48:40.453Z",
      "date_published": "2026-07-15T19:21:46.596Z",
      "date_updated": "2026-07-18T01:24:30.454Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Arbitrary File Write Vulnerability",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23674
      },
      "nvd": {
        "published": "2026-07-15T20:17:04.107",
        "lastModified": "2026-07-18T02:17:08.430",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45419",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled path or reference can select a file outside the intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-83fh-fgh3-g9f9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/d34f413ef047bd275909d67310d200cbc8ae31ba",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 434,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T16:07:22.617Z",
      "date_published": "2026-07-03T20:35:18.605Z",
      "date_updated": "2026-08-03T22:52:38.056Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16324
      },
      "nvd": {
        "published": "2026-07-03T21:17:00.183",
        "lastModified": "2026-07-07T13:50:43.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45488",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Edge can misrepresent security-critical UI to a network attacker, but Microsoft does not identify the UI element or state that is rendered incorrectly.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45488",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 164,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T16:07:22.618Z",
      "date_published": "2026-07-03T20:35:36.906Z",
      "date_updated": "2026-08-03T22:52:49.406Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-749",
          "name": "Exposed Dangerous Method or Function",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00475,
        "percentile": 0.38592
      },
      "nvd": {
        "published": "2026-07-03T21:17:00.307",
        "lastModified": "2026-07-12T20:16:18.723",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45489",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "Edge can present spoofed trust information, but the public record does not identify the host, origin, or UI binding that fails.",
        "basis": [
          "CNA",
          "CWE-290",
          "CWE-749"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45489",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 54,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T16:07:22.618Z",
      "date_published": "2026-07-14T17:04:39.667Z",
      "date_updated": "2026-08-03T22:53:03.830Z",
      "publisher": "microsoft",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Visual Studio Code"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00357,
        "percentile": 0.2844
      },
      "nvd": {
        "published": "2026-07-14T17:16:49.080",
        "lastModified": "2026-07-16T17:30:48.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45496",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Visual Studio Code accepts a local path that traverses outside the directory protected by its security feature.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45496",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T16:07:22.619Z",
      "date_published": "2026-07-02T22:18:56.092Z",
      "date_updated": "2026-08-03T22:52:40.981Z",
      "publisher": "microsoft",
      "title": "Azure OpenAI Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure Open AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00608,
        "percentile": 0.45716
      },
      "nvd": {
        "published": "2026-07-02T23:16:51.003",
        "lastModified": "2026-07-07T14:04:54.607",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45499",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An authorized Azure OpenAI caller can supply a server-side request destination outside the service's intended trust boundary, although the exact input is not public.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45499",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 118,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45533",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T17:48:47.878Z",
      "date_published": "2026-07-15T19:39:08.658Z",
      "date_updated": "2026-07-17T12:26:00.488Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Path Traversal Vulnerability",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23673
      },
      "nvd": {
        "published": "2026-07-15T20:17:04.460",
        "lastModified": "2026-07-17T13:18:49.410",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45533",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The dataease file operation accepts an attacker-controlled path that escapes the intended directory or storage target.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-mwr5-hw6p-cqmg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/dba08037232cf4760fd9e9f36f4bef4e9330d041",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 394,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45534",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T17:48:47.878Z",
      "date_published": "2026-07-15T19:19:10.873Z",
      "date_updated": "2026-07-16T12:55:36.206Z",
      "publisher": "GitHub_M",
      "title": "DataEase: RCE Vulnerability",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32394
      },
      "nvd": {
        "published": "2026-07-15T20:17:04.593",
        "lastModified": "2026-07-16T14:16:52.293",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45534",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Redshift driver loads attacker-controlled temporary configuration that selects a reflective Spring class-instantiation chain.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-cv4c-8rpv-2x97",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/3e58149f1e014b1a7ae2c12134b37ae438f676ac",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 620,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T17:48:47.878Z",
      "date_published": "2026-07-15T19:39:47.951Z",
      "date_updated": "2026-07-16T13:05:15.225Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Stored SQL Injection Vulnerability",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16204
      },
      "nvd": {
        "published": "2026-07-15T20:17:04.723",
        "lastModified": "2026-07-16T14:16:52.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45535",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In dataease, attacker-controlled values reach an SQL statement without the required escaping or parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-pv23-p64m-4pxf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/22930a493d900fe3d8084b3dd4c0125abdb2a847",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45568",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T19:00:14.600Z",
      "date_published": "2026-07-16T16:45:00.305Z",
      "date_updated": "2026-07-17T14:02:59.013Z",
      "publisher": "GitHub_M",
      "title": "zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths",
      "affected": {
        "vendors": [
          "openziti"
        ],
        "products": [
          {
            "vendor": "openziti",
            "product": "zrok"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28758
      },
      "nvd": {
        "published": "2026-07-16T17:16:56.423",
        "lastModified": "2026-07-20T01:58:23.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45568",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "zrok ProxyShare passes an absolute attacker-controlled request path to urljoin, allowing that path to replace the configured upstream and turn the proxy into an SSRF channel.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openziti/zrok/security/advisories/GHSA-jh67-hwqw-m5r7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/openziti/zrok/commit/7c1dc3ecd1c89d8cd2e845a72c3878bd2d31b4fe",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openziti/zrok/releases/tag/v2.0.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45576",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T19:00:14.600Z",
      "date_published": "2026-07-16T16:45:52.766Z",
      "date_updated": "2026-07-16T17:13:51.105Z",
      "publisher": "GitHub_M",
      "title": "zrok copy writes attacker-controlled WebDAV paths outside the destination root",
      "affected": {
        "vendors": [
          "openziti"
        ],
        "products": [
          {
            "vendor": "openziti",
            "product": "zrok"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00341,
        "percentile": 0.26714
      },
      "nvd": {
        "published": "2026-07-16T17:16:56.567",
        "lastModified": "2026-07-20T01:54:51.960",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45576",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The copy inventory preserves traversal-bearing WebDAV paths and writes them after joining with the selected local destination root.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openziti/zrok/security/advisories/GHSA-c656-jcx2-7pqj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/openziti/zrok/commit/a5811e61589d2f804267c6de4a9056db1bdea457",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openziti/zrok/releases/tag/v2.0.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45612",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T20:31:43.448Z",
      "date_published": "2026-07-16T16:34:40.398Z",
      "date_updated": "2026-07-16T18:01:14.603Z",
      "publisher": "GitHub_M",
      "title": "rz-libdemangle: Out of bound read in rust demangler",
      "affected": {
        "vendors": [
          "rizinorg"
        ],
        "products": [
          {
            "vendor": "rizinorg",
            "product": "rz-libdemangle"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02311
      },
      "nvd": {
        "published": "2026-07-16T17:16:56.687",
        "lastModified": "2026-07-16T19:16:45.433",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45612",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "rz-libdemangle reads beyond the available buffer because an input length, offset, or parser boundary is not checked before access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rizinorg/rz-libdemangle/security/advisories/GHSA-4p92-mfjf-qvrc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rizinorg/rz-libdemangle/pull/83",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rizinorg/rz-libdemangle/commit/6bf56d32b32547ae4cb069ccfc2d2b6c7b63a4cb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 242,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45623",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T20:31:43.449Z",
      "date_published": "2026-07-27T17:23:13.326Z",
      "date_updated": "2026-07-27T17:44:31.606Z",
      "publisher": "GitHub_M",
      "title": "PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments",
      "affected": {
        "vendors": [
          "postcss"
        ],
        "products": [
          {
            "vendor": "postcss",
            "product": "postcss"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00503,
        "percentile": 0.40281
      },
      "nvd": {
        "published": "2026-07-27T18:16:55.130",
        "lastModified": "2026-07-30T19:57:52.717",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45623",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PostCSS dereferences an attacker-controlled sourceMappingURL as a local path without a scheme, allow-list, or traversal check.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/postcss/postcss/security/advisories/GHSA-6g55-p6wh-862q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1079,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45646",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-12T20:33:35.156Z",
      "date_published": "2026-07-14T17:05:47.249Z",
      "date_updated": "2026-08-03T22:54:10.859Z",
      "publisher": "microsoft",
      "title": "OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "AspNet.OData"
          },
          {
            "vendor": "Microsoft",
            "product": "AspNetCore.OData"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0078,
        "percentile": 0.52383
      },
      "nvd": {
        "published": "2026-07-14T17:16:49.253",
        "lastModified": "2026-07-16T17:26:26.673",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45646",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OData processing allocates or performs work for network input without an effective limit or throttle.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45646",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-45695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T04:38:01.164Z",
      "date_published": "2026-07-16T15:42:31.795Z",
      "date_updated": "2026-07-16T18:08:13.371Z",
      "publisher": "GitHub_M",
      "title": "Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used",
      "affected": {
        "vendors": [
          "kopia"
        ],
        "products": [
          {
            "vendor": "kopia",
            "product": "kopia"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27445
      },
      "nvd": {
        "published": "2026-07-16T16:19:08.307",
        "lastModified": "2026-07-16T19:16:45.527",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45695",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kopia includes attacker-controlled SSH repository arguments such as ProxyCommand in a command invocation without preserving the shell or process-argument boundary.",
        "basis": [
          "CNA",
          "CWE-78",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kopia/kopia/security/advisories/GHSA-2q4c-3mrw-63c3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/kopia/kopia/pull/5354",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kopia/kopia/commit/c26c6a1b9734c5089217986ffa5cd19f8a6b8900",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kopia/kopia/releases/tag/v0.23.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45703",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T04:38:01.165Z",
      "date_published": "2026-07-17T18:52:44.530Z",
      "date_updated": "2026-07-17T19:22:48.025Z",
      "publisher": "GitHub_M",
      "title": "Pimcore: WordExport Authorization Bypass for Unauthorized Document Export",
      "affected": {
        "vendors": [
          "pimcore"
        ],
        "products": [
          {
            "vendor": "pimcore",
            "product": "pimcore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08622
      },
      "nvd": {
        "published": "2026-07-17T19:17:14.790",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45703",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Pimcore WordExport checks the general feature permission and resolves a caller-selected object without enforcing view permission on that object.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-332x-r494-54fq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/releases/tag/v12.3.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 534,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-45704",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T04:38:01.165Z",
      "date_published": "2026-07-17T19:12:50.888Z",
      "date_updated": "2026-07-20T13:53:55.744Z",
      "publisher": "GitHub_M",
      "title": "Pimcore: CustomReports Share Bypass",
      "affected": {
        "vendors": [
          "pimcore"
        ],
        "products": [
          {
            "vendor": "pimcore",
            "product": "pimcore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23756
      },
      "nvd": {
        "published": "2026-07-17T20:17:18.267",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45704",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The CustomReports detail endpoint omits the sharing check used by the listing endpoint, so a low-privileged backend user can request an unshared report by name.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-jwcc-gv4m-93x6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/pull/19099",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/commit/1893ff1cd116e442b995ddf17e8c6e0aa372268e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/pimcore/releases/tag/v12.3.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 731,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-45709",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T04:38:01.166Z",
      "date_published": "2026-07-20T14:37:00.607Z",
      "date_updated": "2026-07-20T19:08:08.066Z",
      "publisher": "GitHub_M",
      "title": "Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer",
      "affected": {
        "vendors": [
          "axllent"
        ],
        "products": [
          {
            "vendor": "axllent",
            "product": "mailpit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18251
      },
      "nvd": {
        "published": "2026-07-20T16:17:00.190",
        "lastModified": "2026-07-28T15:31:54.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45709",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mailpit's HTML checker follows attacker-controlled URLs and redirects with a plain network dialer that does not reject private or loopback destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/axllent/mailpit/security/advisories/GHSA-j3fj-qppj-fmmc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/axllent/mailpit/releases/tag/v1.30.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1522,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45711",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T05:51:48.665Z",
      "date_published": "2026-07-20T14:39:06.690Z",
      "date_updated": "2026-07-21T15:42:56.143Z",
      "publisher": "GitHub_M",
      "title": "Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs",
      "affected": {
        "vendors": [
          "axllent"
        ],
        "products": [
          {
            "vendor": "axllent",
            "product": "mailpit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.00311,
        "percentile": 0.2352
      },
      "nvd": {
        "published": "2026-07-20T16:17:00.333",
        "lastModified": "2026-07-28T15:30:44.933",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45711",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mailpit joins a remote server's message ID to the output directory without containment validation, allowing normalized traversal paths to escape that directory.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/axllent/mailpit/security/advisories/GHSA-qx5x-85p8-vg4j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/axllent/mailpit/releases/tag/v1.30.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 674,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45712",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T05:51:48.665Z",
      "date_published": "2026-07-20T14:59:40.516Z",
      "date_updated": "2026-07-20T15:33:02.751Z",
      "publisher": "GitHub_M",
      "title": "Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)",
      "affected": {
        "vendors": [
          "axllent"
        ],
        "products": [
          {
            "vendor": "axllent",
            "product": "mailpit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16079
      },
      "nvd": {
        "published": "2026-07-20T16:17:00.470",
        "lastModified": "2026-07-28T15:27:36.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45712",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A package-level Go map is read without the mutex while cleanup and CSS rewriting can write the same map, causing an unrecoverable concurrent-map runtime failure.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/axllent/mailpit/security/advisories/GHSA-w4vj-r5pg-3722",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/axllent/mailpit/releases/tag/v1.30.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 692,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T05:51:48.665Z",
      "date_published": "2026-07-20T15:01:01.489Z",
      "date_updated": "2026-07-20T16:16:44.713Z",
      "publisher": "GitHub_M",
      "title": "Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes",
      "affected": {
        "vendors": [
          "axllent"
        ],
        "products": [
          {
            "vendor": "axllent",
            "product": "mailpit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31573
      },
      "nvd": {
        "published": "2026-07-20T16:17:00.610",
        "lastModified": "2026-07-28T15:24:57.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45713",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mailpit accepts attacker-driven work or allocation without an effective size, rate, release, or termination bound.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/axllent/mailpit/security/advisories/GHSA-fpxj-m5q8-fphw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/axllent/mailpit/releases/tag/v1.30.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 943,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T06:54:34.219Z",
      "date_published": "2026-07-15T20:00:46.998Z",
      "date_updated": "2026-07-16T19:14:44.711Z",
      "publisher": "GitHub_M",
      "title": "Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations",
      "affected": {
        "vendors": [
          "argoproj"
        ],
        "products": [
          {
            "vendor": "argoproj",
            "product": "argo-cd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-212",
          "name": "Improper Removal of Sensitive Information Before Storage or Transfer",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00359,
        "percentile": 0.28581
      },
      "nvd": {
        "published": "2026-07-15T20:17:04.907",
        "lastModified": "2026-07-20T02:09:23.913",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45737",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ServerSideDiff fails to sanitize Secret annotations and stringData before returning predicted target and live state in UI or CLI diffs.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-212"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-rg3g-4rw9-gqrp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/commit/7879e6322465080a82d152bf00f2b92e0f36c658",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/commit/87e9148320749693624d08e3d6fa2cc217c672a0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/commit/ac11bec9986807adc8886ef1181eced7347ef5c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/commit/bcb4298afc9fcff5f5d69f4e1db2d0a75983f42c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/releases/tag/v3.2.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/releases/tag/v3.3.10",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/releases/tag/v3.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 8,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-45738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T06:54:34.219Z",
      "date_published": "2026-07-15T19:54:51.634Z",
      "date_updated": "2026-07-16T15:12:45.158Z",
      "publisher": "GitHub_M",
      "title": "Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation",
      "affected": {
        "vendors": [
          "argoproj"
        ],
        "products": [
          {
            "vendor": "argoproj",
            "product": "argo-cd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00392,
        "percentile": 0.3197
      },
      "nvd": {
        "published": "2026-07-15T20:17:05.057",
        "lastModified": "2026-07-20T02:06:47.313",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45738",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled javascript URI is accepted as an href and executes in the browser.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-h98r-wv3h-fr38",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/commit/00f83c41dcfd879f34f8e0248c860d704b41cf0f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/commit/35ea43c537d6e8948e67f347317fc4f88b325122",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/commit/c8df5ff7acc403adcee1256da5d87081cd52f0a6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/releases/tag/v3.2.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/releases/tag/v3.3.10",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-cd/releases/tag/v3.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 558,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-45753",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T06:54:34.221Z",
      "date_published": "2026-07-14T18:21:13.644Z",
      "date_updated": "2026-07-14T18:39:28.564Z",
      "publisher": "GitHub_M",
      "title": "Symfony: HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — javascript: URI Survives Sanitization (XSS)",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "html-sanitizer"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 3.9999999999999996,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21579
      },
      "nvd": {
        "published": "2026-07-14T19:17:07.633",
        "lastModified": "2026-07-15T13:44:21.307",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45753",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The sanitizer omits URL-bearing attributes from its checks, allowing javascript URIs to survive in admitted HTML.",
        "basis": [
          "CNA record",
          "CWE-79",
          "CWE-184"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-hhg7-c65m-h7ff",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/487728e7e180a674a6d4c01bd0cb56161cc441b7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-45754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T06:54:34.221Z",
      "date_published": "2026-07-14T18:54:24.337Z",
      "date_updated": "2026-07-21T17:54:06.698Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "lox24-notifier"
          },
          {
            "vendor": "symfony",
            "product": "mailjet-mailer"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27435
      },
      "nvd": {
        "published": "2026-07-14T19:17:07.777",
        "lastModified": "2026-07-21T18:16:58.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45754",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "symfony exposes a security-sensitive endpoint without requiring caller authentication.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-64hg-93w9-fc35",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/3e52bf5ab733ee32e35eeeeb2631d859c941838e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/4aaa45dd054f73445f1ab254968b7e60b546cc77",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-45755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T06:54:34.221Z",
      "date_published": "2026-07-14T18:56:20.615Z",
      "date_updated": "2026-07-14T19:46:25.210Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection",
      "affected": {
        "vendors": [
          "/mailtrap-mailer",
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "/mailtrap-mailer",
            "product": "mailtrap-mailer"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14982
      },
      "nvd": {
        "published": "2026-07-14T19:17:07.907",
        "lastModified": "2026-07-15T13:42:26.507",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45755",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Mailtrap webhook parser receives a configured secret but never verifies the X-Mt-Signature HMAC before accepting events.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-59f3-vp2f-mp9w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/4e0467e4e182cf2e704a3d9e1bc1a6be65d52ab8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 404,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-45756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T06:54:34.221Z",
      "date_published": "2026-07-14T17:57:03.811Z",
      "date_updated": "2026-07-21T18:48:57.481Z",
      "publisher": "GitHub_M",
      "title": "Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "json-path"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00598,
        "percentile": 0.45273
      },
      "nvd": {
        "published": "2026-07-14T18:17:17.563",
        "lastModified": "2026-07-21T19:17:10.237",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45756",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Symfony JsonPath passes attacker-controlled match and search patterns directly to preg_match without a length or backtracking bound.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-8v8v-g73j-492j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/1ac2d47418ec23066112db1e6ca35be6fe123d14",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 469,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-45780",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T07:45:21.252Z",
      "date_published": "2026-07-09T22:08:52.125Z",
      "date_updated": "2026-07-14T01:20:07.878Z",
      "publisher": "GitHub_M",
      "title": "Discourse: Private event sample invitees are serialized to non-invited event viewers",
      "affected": {
        "vendors": [
          "discourse"
        ],
        "products": [
          {
            "vendor": "discourse",
            "product": "discourse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00364,
        "percentile": 0.29145
      },
      "nvd": {
        "published": "2026-07-09T22:17:04.770",
        "lastModified": "2026-07-14T20:43:40.657",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45780",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "EventSerializer emits private invitee fields without applying the event-specific entitlement required for otherwise topic-authorized viewers.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/discourse/discourse/security/advisories/GHSA-22v7-6wgj-g9f7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/37969503f20369eb1712b7b88daedcfb4f63f5f1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/4d46638041b5f3d1e1f7f6f6f19c1df3bd65a586",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/6457ab71f36a2d1440fe96af0a2593897844b023",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/7deb4b6963442569357b41e61febe37594e5e730",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-45784",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T07:45:21.252Z",
      "date_published": "2026-07-17T20:26:12.969Z",
      "date_updated": "2026-07-20T13:49:55.716Z",
      "publisher": "GitHub_M",
      "title": "rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers",
      "affected": {
        "vendors": [
          "rust-openssl"
        ],
        "products": [
          {
            "vendor": "rust-openssl",
            "product": "rust-openssl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-131",
          "name": "Incorrect Calculation of Buffer Size",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00134,
        "percentile": 0.0332
      },
      "nvd": {
        "published": "2026-07-17T21:17:06.503",
        "lastModified": "2026-07-29T15:43:54.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45784",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "cipher_update_inplace sizes its output buffer too small for padded AES key wrap, allowing OpenSSL to write up to seven bytes past the allocation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-131",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-phqj-4mhp-q6mq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rust-openssl/rust-openssl/pull/2638",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rust-openssl/rust-openssl/commit/19eceb26f2404aae187e5444e65c404ebc1348a7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rust-openssl/rust-openssl/releases/tag/openssl-v0.10.80",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45785",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T07:45:21.252Z",
      "date_published": "2026-07-17T20:37:23.428Z",
      "date_updated": "2026-07-21T02:20:18.829Z",
      "publisher": "GitHub_M",
      "title": "OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle",
      "affected": {
        "vendors": [
          "openmcdf"
        ],
        "products": [
          {
            "vendor": "openmcdf",
            "product": "openmcdf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02992
      },
      "nvd": {
        "published": "2026-07-17T21:17:06.650",
        "lastModified": "2026-07-23T18:12:34.153",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45785",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The openmcdf path lets attacker-controlled state drive a loop without a guaranteed terminating condition.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openmcdf/openmcdf/security/advisories/GHSA-5qwm-7pvp-w988",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/openmcdf/openmcdf/commit/c6f82db722bd85db7b0caed3ca1aa374f1e07bc7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openmcdf/openmcdf/releases/tag/v3.1.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 863,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45788",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T08:19:32.602Z",
      "date_published": "2026-07-09T21:59:27.495Z",
      "date_updated": "2026-07-10T14:39:14.267Z",
      "publisher": "GitHub_M",
      "title": "Discourse: Secure uploads exposed by hotlinked image copying",
      "affected": {
        "vendors": [
          "discourse"
        ],
        "products": [
          {
            "vendor": "discourse",
            "product": "discourse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00465,
        "percentile": 0.37921
      },
      "nvd": {
        "published": "2026-07-09T22:17:04.933",
        "lastModified": "2026-07-14T20:41:53.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45788",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The pull_hotlinked_images path republishes a protected upload at a location available to an unintended observer.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/discourse/discourse/security/advisories/GHSA-3876-w96v-8v38",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/5807c426880eadf248006e851604fc9284327ce5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/8b4a959b251a856a9c911fb9f2ac34fbc31a7471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/eff53af26367ae0dcb3a426954d233e8c7449f95",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/fa74e0dec7341a858ab83a1977fa52629bced1aa",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-45793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T08:19:32.603Z",
      "date_published": "2026-07-15T16:22:19.418Z",
      "date_updated": "2026-07-15T18:11:10.355Z",
      "publisher": "GitHub_M",
      "title": "Composer: Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs",
      "affected": {
        "vendors": [
          "composer"
        ],
        "products": [
          {
            "vendor": "composer",
            "product": "composer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00797,
        "percentile": 0.52956
      },
      "nvd": {
        "published": "2026-07-15T17:16:48.173",
        "lastModified": "2026-07-15T20:54:43.733",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45793",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "BaseIO::loadConfiguration embeds rejected GitHub OAuth tokens in an UnexpectedValueException, exposing hyphenated ghs_ tokens to standard error and CI logs.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/composer/composer/security/advisories/GHSA-f9f8-rm49-7jv2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/composer/composer/pull/12853",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/pull/12855",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/commit/3f5e7f9fbfa541137d6d1d5643ec3b718e9d5039",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/commit/65e6390c49f1a11cd8b660d81822086db51fe2d1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/commit/e66c8fdb7ff5409bd2f358c5f194038e49e93714",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/releases/tag/1.10.28",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/releases/tag/2.2.28",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/releases/tag/2.9.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-45795",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T08:19:32.603Z",
      "date_published": "2026-07-16T16:35:58.581Z",
      "date_updated": "2026-07-16T18:06:23.420Z",
      "publisher": "GitHub_M",
      "title": "Janssen Project: JWE Request Object Signature Verification Bypass in jans-auth-server",
      "affected": {
        "vendors": [
          "JanssenProject"
        ],
        "products": [
          {
            "vendor": "JanssenProject",
            "product": "jans"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05544
      },
      "nvd": {
        "published": "2026-07-16T17:16:56.820",
        "lastModified": "2026-07-16T19:16:45.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45795",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Jans accepts an unsigned inner JWT from an encrypted JWE without verifying the required inner signature.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/JanssenProject/jans/security/advisories/GHSA-r3gj-4pj2-9j3j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/JanssenProject/jans/pull/13438",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/JanssenProject/jans/commit/0cdd214870ee30eb2186261f21c85b9e9fc63b5c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/JanssenProject/jans/releases/tag/v2.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45796",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T08:19:32.603Z",
      "date_published": "2026-07-07T21:03:11.066Z",
      "date_updated": "2026-07-08T13:53:41.602Z",
      "publisher": "GitHub_M",
      "title": "Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26066
      },
      "nvd": {
        "published": "2026-07-07T22:16:52.317",
        "lastModified": "2026-07-08T19:47:08.010",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45796",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server does not return the target's response body, but error messages in the API response reveal whether the target is reachable and what type of failure occurred.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-686c-7vgv-v3fx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/25274",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/commit/57b11d405f17492aa789d4b9ff33366f961a37f8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.24.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.30.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.31.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 957,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-45797",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T08:19:32.603Z",
      "date_published": "2026-07-20T15:43:13.473Z",
      "date_updated": "2026-07-20T19:07:52.276Z",
      "publisher": "GitHub_M",
      "title": "HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload",
      "affected": {
        "vendors": [
          "heyform"
        ],
        "products": [
          {
            "vendor": "heyform",
            "product": "heyform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00404,
        "percentile": 0.33195
      },
      "nvd": {
        "published": "2026-07-20T16:17:00.743",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45797",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path accepts and serves an attacker-controlled SVG as active content instead of constraining the file type.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/heyform/heyform/security/advisories/GHSA-m94h-jxvc-hhch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/heyform/heyform/commit/144240e5545d10fd9e120d05ccb402a6d7064674",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 459,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T08:19:32.603Z",
      "date_published": "2026-07-17T19:49:30.331Z",
      "date_updated": "2026-07-20T13:51:25.748Z",
      "publisher": "GitHub_M",
      "title": "Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service",
      "affected": {
        "vendors": [
          "square"
        ],
        "products": [
          {
            "vendor": "square",
            "product": "wire"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0049,
        "percentile": 0.39476
      },
      "nvd": {
        "published": "2026-07-17T20:17:18.393",
        "lastModified": "2026-07-23T16:15:11.587",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45799",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Wire accepts a negative signed length decoded from a protobuf varint and moves the reader position before the beginning of the buffer.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/square/wire/security/advisories/GHSA-7xpr-hc2w-34m9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/square/wire/pull/3595",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/square/wire/pull/3597",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/square/wire/commit/47d5b0dba53935d5332cd41a80a353b3fc90e7b0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/square/wire/commit/e4e56fab38a547d9625f05c97f1d8f0bcc3a5773",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/square/wire/releases/tag/6.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/square/wire/releases/tag/7.0.0-alpha03",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 659,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-45804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T08:19:32.604Z",
      "date_published": "2026-07-15T16:05:35.217Z",
      "date_updated": "2026-07-15T17:27:31.546Z",
      "publisher": "GitHub_M",
      "title": "Diffusers: TOCTOU Trust Remote Code Bypass",
      "affected": {
        "vendors": [
          "huggingface"
        ],
        "products": [
          {
            "vendor": "huggingface",
            "product": "diffusers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18737
      },
      "nvd": {
        "published": "2026-07-15T17:16:48.310",
        "lastModified": "2026-07-15T20:52:04.320",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45804",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Diffusers checks trust before resolving the final cached project directory, allowing the selected code-bearing directory to change between validation and import.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/huggingface/diffusers/security/advisories/GHSA-7wx4-6vff-v64p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/huggingface/diffusers/issues/13446",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/huggingface/diffusers/pull/13448",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/huggingface/diffusers/commit/a37f6f8394ac2a7ee8360c3abea811efe54512b1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/huggingface/diffusers/releases/tag/v0.38.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45805",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T08:19:32.604Z",
      "date_published": "2026-07-15T15:11:22.168Z",
      "date_updated": "2026-07-15T15:44:45.199Z",
      "publisher": "GitHub_M",
      "title": "Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE",
      "affected": {
        "vendors": [
          "penpot"
        ],
        "products": [
          {
            "vendor": "penpot",
            "product": "penpot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-749",
          "name": "Exposed Dangerous Method or Function",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.1374
      },
      "nvd": {
        "published": "2026-07-15T16:16:45.787",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45805",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ReplServer listens on every interface and exposes /execute without authentication before forwarding supplied JavaScript to PluginBridge.",
        "basis": [
          "CNA",
          "CWE-749"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/penpot/penpot/security/advisories/GHSA-22qr-rp27-j9wm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/penpot/penpot/issues/9518",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/penpot/penpot/commit/798ee46b4a84ee6dfc756b001f33acbe0280d62f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/penpot/penpot/releases/tag/2.15.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T08:19:32.604Z",
      "date_published": "2026-07-15T15:05:35.962Z",
      "date_updated": "2026-07-20T14:53:29.305Z",
      "publisher": "GitHub_M",
      "title": "Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url",
      "affected": {
        "vendors": [
          "penpot"
        ],
        "products": [
          {
            "vendor": "penpot",
            "product": "penpot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25056
      },
      "nvd": {
        "published": "2026-07-15T16:16:45.927",
        "lastModified": "2026-07-20T16:17:00.887",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45806",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "penpot follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/penpot/penpot/security/advisories/GHSA-35g2-w7f6-8v9h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/penpot/penpot/releases/tag/2.15.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45811",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T08:48:46.370Z",
      "date_published": "2026-07-24T12:09:10.299Z",
      "date_updated": "2026-07-24T18:14:45.702Z",
      "publisher": "apache",
      "title": "Apache NimBLE: Buffer overflow in socket HCI transport",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache NimBLE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00342,
        "percentile": 0.26853
      },
      "nvd": {
        "published": "2026-07-24T13:18:23.847",
        "lastModified": "2026-07-27T14:41:24.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45811",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HCI socket transport copies a received event into a configured pool without checking that the event fits the destination buffer.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/mynewt-nimble/commit/dcc4e4f026109eecd507de9479bb5019306a4a41",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/5mkz68y1py0o6zmxtc3l1o8grtrb78m0",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/11",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T08:56:54.914Z",
      "date_published": "2026-07-24T12:09:38.958Z",
      "date_updated": "2026-07-24T18:16:48.556Z",
      "publisher": "apache",
      "title": "Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache NimBLE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-131",
          "name": "Incorrect Calculation of Buffer Size",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34528
      },
      "nvd": {
        "published": "2026-07-24T13:18:23.967",
        "lastModified": "2026-07-27T14:41:19.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45812",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NimBLE advances to the next bundled advertising report with a miscalculated offset, causing a read past the HCI event buffer.",
        "basis": [
          "CNA",
          "CWE-131"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/mynewt-nimble/commit/605c7585408bc3674818eeb7b6f478a8aefe9746",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/rll5m1ly2vg8jr76lp5ohrtspr5vlofy",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/12",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 667,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45813",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T09:02:11.689Z",
      "date_published": "2026-07-24T12:10:12.070Z",
      "date_updated": "2026-07-24T18:18:46.883Z",
      "publisher": "apache",
      "title": "Apache NimBLE: Incorrect data validation in BASS add/modify source operation",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache NimBLE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27809
      },
      "nvd": {
        "published": "2026-07-24T13:18:24.087",
        "lastModified": "2026-07-27T14:41:12.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45813",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BASS Add Source and Modify Source parsing permits integer underflow in length handling and consequently reads or writes beyond a stack buffer.",
        "basis": [
          "CNA",
          "CWE-191",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/mynewt-nimble/pull/2232",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/vc1ny73w243z5wr6t0y10gc6t2c9cytw",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/13",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45815",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T09:31:25.414Z",
      "date_published": "2026-07-24T12:10:38.456Z",
      "date_updated": "2026-07-24T18:20:48.428Z",
      "publisher": "apache",
      "title": "Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache NimBLE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00602,
        "percentile": 0.45436
      },
      "nvd": {
        "published": "2026-07-24T13:18:24.200",
        "lastModified": "2026-07-27T14:41:01.180",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45815",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted ATT response reaches a parser assertion that is treated as impossible and terminates the device process.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/mynewt-nimble/commit/fae6a4874309ba0175d2c444e20f8a6bde007425",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/3d09hgo5zmm7dnryst3tb9857hk1bbos",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/14",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45816",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T09:41:40.675Z",
      "date_published": "2026-07-24T12:11:09.434Z",
      "date_updated": "2026-07-24T18:22:34.523Z",
      "publisher": "apache",
      "title": "Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache NimBLE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00615,
        "percentile": 0.46034
      },
      "nvd": {
        "published": "2026-07-24T13:18:24.307",
        "lastModified": "2026-07-27T14:40:54.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-45816",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A bogus controller event reaches the Long Term Key handler with a null object that is dereferenced when assertions are disabled.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/mynewt-nimble/commit/9448c5f495eb55018121b24a9dab5305c9222ea1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/psppdk5j8jnq1m4jn96tnfofspgqvzvn",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/15",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-45820",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T12:03:13.544Z",
      "date_published": "2026-07-22T06:57:13.726Z",
      "date_updated": "2026-07-22T12:53:38.246Z",
      "publisher": "seal",
      "title": "fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra ...",
      "affected": {
        "vendors": [
          "101arrowz"
        ],
        "products": [
          {
            "vendor": "101arrowz",
            "product": "fflate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/S:N/AU:Y/R:U/V:D/RE:M/U:Amber"
        },
        {
          "source": "NVD:22e2d327-25fe-45d7-9f0c-dcd23b7108df",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:M/U:Amber"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17026
      },
      "nvd": {
        "published": "2026-07-22T08:16:23.280",
        "lastModified": "2026-07-23T15:48:25.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-45820",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A ZIP64 sentinel without its required extra field keeps the unzip parser's loop condition true after out-of-bounds reads return no progress.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/101arrowz/fflate/blob/f7873560ad229c22c4b23b06c6a3806ffde77569/src/index.ts#L2714",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.npmjs.com/package/fflate",
          "host": "www.npmjs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 401,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-46336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T18:37:30.989Z",
      "date_published": "2026-07-16T17:04:31.056Z",
      "date_updated": "2026-07-18T03:01:26.480Z",
      "publisher": "GitHub_M",
      "title": "Manyfold: Authenticated Path Traversal via File Rename",
      "affected": {
        "vendors": [
          "manyfold3d"
        ],
        "products": [
          {
            "vendor": "manyfold3d",
            "product": "manyfold"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25787
      },
      "nvd": {
        "published": "2026-07-16T18:16:43.773",
        "lastModified": "2026-07-18T03:16:36.010",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46336",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Manyfold joins a user-controlled rename value to the model path without sanitizing traversal segments or confining the resolved target.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/manyfold3d/manyfold/security/advisories/GHSA-j5f9-r7wf-hv37",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/manyfold3d/manyfold/pull/6122",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/manyfold3d/manyfold/commit/ed6a53e54926708594c07d222155ac3a22f93174",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/manyfold3d/manyfold/releases/tag/v0.140.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 490,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46338",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T18:37:30.990Z",
      "date_published": "2026-07-16T18:24:18.155Z",
      "date_updated": "2026-07-17T17:52:57.729Z",
      "publisher": "GitHub_M",
      "title": "PyMdown Extensions: Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path",
      "affected": {
        "vendors": [
          "facelessuser"
        ],
        "products": [
          {
            "vendor": "facelessuser",
            "product": "pymdown-extensions"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23345
      },
      "nvd": {
        "published": "2026-07-16T19:16:45.733",
        "lastModified": "2026-07-30T14:28:41.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46338",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The snippet restriction compares normalized paths with a raw string prefix, so a sibling directory sharing that prefix is accepted as inside the base path.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-62q4-447f-wv8h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/facelessuser/pymdown-extensions/commit/63b7835776d703d6c339cf2110d9888f676efc0c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/facelessuser/pymdown-extensions/releases/tag/10.21.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 486,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46339",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T18:37:30.990Z",
      "date_published": "2026-07-15T20:41:06.937Z",
      "date_updated": "2026-07-16T12:55:46.031Z",
      "publisher": "GitHub_M",
      "title": "9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02395,
        "percentile": 0.82358
      },
      "nvd": {
        "published": "2026-07-15T21:16:50.067",
        "lastModified": "2026-07-16T14:16:52.513",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46339",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The proxy middleware omits authentication for CLI-tool and MCP routes that register plugins and invoke their commands.",
        "basis": [
          "CNA",
          "CWE-78",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-fhh6-4qxv-rpqj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/commit/992f4db4a0d858bcc86b4786f2abab117a6ccdf8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46341",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T18:37:30.990Z",
      "date_published": "2026-07-16T16:54:01.843Z",
      "date_updated": "2026-07-17T14:01:46.108Z",
      "publisher": "GitHub_M",
      "title": "Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching",
      "affected": {
        "vendors": [
          "apify"
        ],
        "products": [
          {
            "vendor": "apify",
            "product": "apify-mcp-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-183",
          "name": "Permissive List of Allowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00191,
        "percentile": 0.09002
      },
      "nvd": {
        "published": "2026-07-16T18:16:43.913",
        "lastModified": "2026-07-17T18:44:13.257",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46341",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The documentation fetch allowlist uses string-prefix comparison instead of parsing and comparing the URL hostname.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-183"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apify/apify-mcp-server/security/advisories/GHSA-jwp7-wg77-3w9v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/apify/apify-mcp-server/pull/781",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/apify/apify-mcp-server/commit/e39bdee530da1db0b3b3d3713558b33c9608e629",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/apify/apify-mcp-server/releases/tag/v0.9.21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 587,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T18:37:30.991Z",
      "date_published": "2026-07-16T17:58:53.070Z",
      "date_updated": "2026-07-17T13:59:11.141Z",
      "publisher": "GitHub_M",
      "title": "BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate them",
      "affected": {
        "vendors": [
          "bigbluebutton"
        ],
        "products": [
          {
            "vendor": "bigbluebutton",
            "product": "bigbluebutton"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-330",
          "name": "Use of Insufficiently Random Values",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17443
      },
      "nvd": {
        "published": "2026-07-16T19:16:45.863",
        "lastModified": "2026-07-17T18:36:41.143",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46351",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "BigBlueButton generates conference sessionToken values with insufficient cryptographic randomness.",
        "basis": [
          "CNA",
          "CWE-330"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-7959-pf2v-xc4h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bigbluebutton/bigbluebutton/commit/8457886c248aeba5597ee8749267602d6d117e98",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 454,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T18:37:30.991Z",
      "date_published": "2026-07-16T18:06:54.645Z",
      "date_updated": "2026-07-16T18:41:31.957Z",
      "publisher": "GitHub_M",
      "title": "BigBlueButton API checksum bypass via presentationUploadExternalUrl",
      "affected": {
        "vendors": [
          "bigbluebutton"
        ],
        "products": [
          {
            "vendor": "bigbluebutton",
            "product": "bigbluebutton"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18387
      },
      "nvd": {
        "published": "2026-07-16T19:16:46.000",
        "lastModified": "2026-07-17T18:33:28.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46353",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Supplying presentationUploadExternalUrl causes checksum validation and request execution to resolve different request forms, allowing requests without a valid checksum.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-43hc-5g2m-cqff",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bigbluebutton/bigbluebutton/commit/36fd1b407488a0c56ce620b91184d5a8aea68b3d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46354",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T18:37:30.991Z",
      "date_published": "2026-07-07T21:10:01.899Z",
      "date_updated": "2026-07-08T13:01:25.192Z",
      "publisher": "GitHub_M",
      "title": "Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17634
      },
      "nvd": {
        "published": "2026-07-07T22:16:52.467",
        "lastModified": "2026-07-08T19:47:02.427",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46354",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "azureidentity.Validate verifies that a PKCS#7 certificate chains to an Azure CA but never verifies the signature over the supplied instance-identity content.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-6x44-w3xg-hqqf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/25286",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.24.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.30.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.31.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 900,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-46377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T19:53:47.921Z",
      "date_published": "2026-07-16T17:57:16.643Z",
      "date_updated": "2026-07-16T18:21:45.505Z",
      "publisher": "GitHub_M",
      "title": "Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string",
      "affected": {
        "vendors": [
          "TomWright"
        ],
        "products": [
          {
            "vendor": "TomWright",
            "product": "dasel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02823
      },
      "nvd": {
        "published": "2026-07-16T19:16:46.127",
        "lastModified": "2026-07-17T18:33:28.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46377",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The selector lexer advances past a trailing backslash in a quoted string and then indexes beyond the source buffer.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/TomWright/dasel/security/advisories/GHSA-m5j3-4634-c2vq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/TomWright/dasel/commit/5fc1172287df89860caf139b146007d7ed12178c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/TomWright/dasel/releases/tag/v3.10.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 461,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T19:53:47.921Z",
      "date_published": "2026-07-16T17:54:51.705Z",
      "date_updated": "2026-07-17T15:06:49.587Z",
      "publisher": "GitHub_M",
      "title": "Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal",
      "affected": {
        "vendors": [
          "TomWright"
        ],
        "products": [
          {
            "vendor": "TomWright",
            "product": "dasel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01614
      },
      "nvd": {
        "published": "2026-07-16T19:16:46.260",
        "lastModified": "2026-07-17T18:36:41.143",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46378",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The selector lexer fails to advance or terminate at end-of-input for an unterminated regex literal, leaving the parser in an infinite loop.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/TomWright/dasel/security/advisories/GHSA-m6xr-fvfg-5g64",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/TomWright/dasel/commit/95f8dd3af12958bf6ca2a737b3ec0267280f86ed",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 466,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46388",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T19:53:47.922Z",
      "date_published": "2026-07-10T14:44:52.865Z",
      "date_updated": "2026-07-10T19:03:08.593Z",
      "publisher": "GitHub_M",
      "title": "osquery: Unprivileged users can temporarily read file carve contents",
      "affected": {
        "vendors": [
          "osquery"
        ],
        "products": [
          {
            "vendor": "osquery",
            "product": "osquery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-279",
          "name": "Incorrect Execution-Assigned Permissions",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-378",
          "name": "Creation of Temporary File With Insecure Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-379",
          "name": "Creation of Temporary File in Directory with Insecure Permissions",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00094,
        "percentile": 0.00727
      },
      "nvd": {
        "published": "2026-07-10T16:16:31.400",
        "lastModified": "2026-07-10T20:16:45.867",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46388",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In-progress file-carve directories are created with permissions that let unprivileged local users read their temporary contents.",
        "basis": [
          "CNA",
          "CWE-279",
          "CWE-378",
          "CWE-379"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/osquery/osquery/security/advisories/GHSA-fg78-9q98-62hh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/osquery/osquery/pull/8961",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/osquery/osquery/commit/6dabe9ded33bf9c6fc0f3e37ec364a1cbbd25d68",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/osquery/osquery/releases/tag/5.23.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T21:04:10.932Z",
      "date_published": "2026-07-21T19:51:18.745Z",
      "date_updated": "2026-07-22T14:28:22.326Z",
      "publisher": "GitHub_M",
      "title": "Klever-Go KVM read-only execution can commit contract delete and upgrade side effects",
      "affected": {
        "vendors": [
          "klever-io"
        ],
        "products": [
          {
            "vendor": "klever-io",
            "product": "klever-go"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00342,
        "percentile": 0.26856
      },
      "nvd": {
        "published": "2026-07-21T20:17:01.067",
        "lastModified": "2026-07-23T15:52:43.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46403",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KVM marks execution read-only in runtime state but fails to enforce that state in indirect delete and upgrade hooks whose output later mutates accounts.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/klever-io/klever-go/security/advisories/GHSA-jc6w-wmfc-fh33",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/klever-io/klever-go/commit/333f6ec910906e227705fc5767dc897d8fbfc862",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/klever-io/klever-go/commit/68b94a40824fac2d848a4ded6eb7c91ada6ce9ef",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1423,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T21:04:10.932Z",
      "date_published": "2026-07-16T18:04:11.116Z",
      "date_updated": "2026-07-17T18:06:48.388Z",
      "publisher": "GitHub_M",
      "title": "BigBlueButton: Presentation URL Security Hardening",
      "affected": {
        "vendors": [
          "bigbluebutton"
        ],
        "products": [
          {
            "vendor": "bigbluebutton",
            "product": "bigbluebutton"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.172
      },
      "nvd": {
        "published": "2026-07-16T19:16:46.387",
        "lastModified": "2026-07-17T19:17:14.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46404",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Presentation fetching does not reliably exclude local and link-local destinations or pin a validated DNS result across redirects.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-xqm3-6q7q-4v5h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bigbluebutton/bigbluebutton/commit/7ccc60c965d744d9fb637715052352a1e59a2c27",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T21:04:10.933Z",
      "date_published": "2026-07-20T14:15:04.995Z",
      "date_updated": "2026-07-21T14:10:48.573Z",
      "publisher": "GitHub_M",
      "title": "FileBrowser Quantum: unauthenticated user share share info",
      "affected": {
        "vendors": [
          "gtsteffaniak"
        ],
        "products": [
          {
            "vendor": "gtsteffaniak",
            "product": "filebrowser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17946
      },
      "nvd": {
        "published": "2026-07-20T15:16:38.673",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46410",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A sharing operation reveals source or path data, but the public record does not identify the output condition or observer.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-3jmg-p96m-m328",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gtsteffaniak/filebrowser/commit/1802e1281135cba83eb4acd86b58293fe121e2a5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46412",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T21:04:10.933Z",
      "date_published": "2026-07-20T14:31:53.194Z",
      "date_updated": "2026-07-20T15:32:29.327Z",
      "publisher": "GitHub_M",
      "title": "Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm",
      "affected": {
        "vendors": [
          "BeProduct"
        ],
        "products": [
          {
            "vendor": "BeProduct",
            "product": "beproduct-org-nestjs-auth"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-506",
          "name": "Embedded Malicious Code",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00424,
        "percentile": 0.34929
      },
      "nvd": {
        "published": "2026-07-20T16:17:01.000",
        "lastModified": "2026-07-23T18:02:09.653",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46412",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A compromised npm publishing credential distributed postinstall malware that harvested local and cloud credentials during dependency installation.",
        "basis": [
          "CNA record",
          "CWE-506"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/BeProduct/beproduct-org-nestjs-auth/security/advisories/GHSA-6xwp-cp5h-q856",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://www.aikido.dev/blog/checklist-github-actions",
          "host": "www.aikido.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "host": "www.aikido.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1386,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46413",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T21:04:10.933Z",
      "date_published": "2026-07-09T21:55:45.096Z",
      "date_updated": "2026-07-10T14:32:39.498Z",
      "publisher": "GitHub_M",
      "title": "Discourse: Regular users can route multipart uploads into the admin backup store",
      "affected": {
        "vendors": [
          "discourse"
        ],
        "products": [
          {
            "vendor": "discourse",
            "product": "discourse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29333
      },
      "nvd": {
        "published": "2026-07-09T22:17:05.090",
        "lastModified": "2026-07-14T20:41:29.523",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46413",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ExternalUploadManager lets a regular user select the administrator backup store as the destination for a multipart upload.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/discourse/discourse/security/advisories/GHSA-3mvf-q9rg-w6m7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/1f1ded8dd361d81786bff17b35e1138d6ee299c0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/7ddde266617b452152c1bf5f903f6c07be38fc40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/a53df26dcf7e50ce2b20bfd5454a0c9d44b8fc7d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/abaa664c5df84026efb2ca264ba0f5586c3f2b01",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 290,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46415",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T21:04:10.933Z",
      "date_published": "2026-07-20T15:05:21.961Z",
      "date_updated": "2026-07-21T13:53:08.959Z",
      "publisher": "GitHub_M",
      "title": "Caddy Defender trusted proxy client IP bypass",
      "affected": {
        "vendors": [
          "JasonLovesDoggo"
        ],
        "products": [
          {
            "vendor": "JasonLovesDoggo",
            "product": "caddy-defender"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-348",
          "name": "Use of Less Trusted Source",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.0569
      },
      "nvd": {
        "published": "2026-07-20T16:17:01.163",
        "lastModified": "2026-07-23T18:14:47.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46415",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Caddy Defender evaluates the immediate proxy address instead of Caddy's policy-resolved client_ip when enforcing IP blocks.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-348"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/JasonLovesDoggo/caddy-defender/security/advisories/GHSA-3h23-rrpc-3p87",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/JasonLovesDoggo/caddy-defender/pull/139",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://caddyserver.com/docs/caddyfile/matchers#client-ip",
          "host": "caddyserver.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://caddyserver.com/docs/caddyfile/options#trusted-proxies",
          "host": "caddyserver.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1577,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46420",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T22:18:22.829Z",
      "date_published": "2026-07-17T19:51:10.253Z",
      "date_updated": "2026-07-20T18:15:56.324Z",
      "publisher": "GitHub_M",
      "title": "setup-php: Command Injection in Repository-Derived PHP Version Resolution",
      "affected": {
        "vendors": [
          "shivammathur"
        ],
        "products": [
          {
            "vendor": "shivammathur",
            "product": "setup-php"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01149,
        "percentile": 0.6374
      },
      "nvd": {
        "published": "2026-07-17T20:17:18.567",
        "lastModified": "2026-07-23T18:08:31.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46420",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "setup-php inserts repository-controlled PHP version strings into generated shell or PowerShell scripts without constraining them to version syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/shivammathur/setup-php/security/advisories/GHSA-pqwm-q9pv-ph8r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/shivammathur/setup-php/commit/eeef37e059fb5368a5bc8ed8ce45ff54bd39b80b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shivammathur/setup-php/releases/tag/2.37.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 657,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46421",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T22:18:22.829Z",
      "date_published": "2026-07-15T18:52:09.971Z",
      "date_updated": "2026-07-15T19:22:50.086Z",
      "publisher": "GitHub_M",
      "title": "Supply chain compromise via malicious package versions (@cap-js/sqlite,  @cap-js/postgres, @cap-js/db-service)",
      "affected": {
        "vendors": [
          "@cap-js/db-service",
          "cap-js"
        ],
        "products": [
          {
            "vendor": "cap-js",
            "product": "@cap-js/sqlite"
          },
          {
            "vendor": "cap-js",
            "product": "@cap-js/postgres"
          },
          {
            "vendor": "@cap-js/db-service",
            "product": "@cap-js/db-service"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-506",
          "name": "Embedded Malicious Code",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31162
      },
      "nvd": {
        "published": "2026-07-15T19:17:17.523",
        "lastModified": "2026-07-15T20:29:34.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46421",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Compromised releases of three CAP database packages contained credential-harvesting and self-propagating code in the dependency supply chain.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-506"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cap-js/cds-dbs/security/advisories/GHSA-pvw4-cvr4-97p8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://me.sap.com/notes/3747787",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://www.sap.com/documents/2026/05/8203a8b9-4d7f-0010-bca6-c68f7e60039b.html",
          "host": "www.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared",
          "host": "www.stepsecurity.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 803,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-13T22:18:22.830Z",
      "date_published": "2026-07-20T15:37:58.396Z",
      "date_updated": "2026-07-21T15:49:36.495Z",
      "publisher": "GitHub_M",
      "title": "lettre has TLS hostname verification disabled when using Boring TLS backend",
      "affected": {
        "vendors": [
          "lettre"
        ],
        "products": [
          {
            "vendor": "lettre",
            "product": "lettre"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00191,
        "percentile": 0.0902
      },
      "nvd": {
        "published": "2026-07-20T16:17:01.347",
        "lastModified": "2026-07-23T17:58:34.990",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46428",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An inverted boolean in the boring-tls integration disables TLS hostname verification under the default strict configuration.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lettre/lettre/security/advisories/GHSA-4pj9-g833-qx53",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lettre/lettre/commit/f5efffc88360dbdbfcef80f465e42d5bce68ca35",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lettre/lettre/releases/tag/v0.11.22",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0141.html",
          "host": "rustsec.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46452",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T07:13:57.754Z",
      "date_published": "2026-07-24T12:11:42.453Z",
      "date_updated": "2026-07-24T18:04:46.229Z",
      "publisher": "apache",
      "title": "Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache NimBLE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00561,
        "percentile": 0.43463
      },
      "nvd": {
        "published": "2026-07-24T13:18:25.097",
        "lastModified": "2026-07-27T14:40:45.187",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46452",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "NimBLE Mesh Proxy SAR reassembly forwards an invalid segment sequence to the application instead of rejecting it, creating memory pressure and parser instability.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/mynewt-nimble/commit/593f95227a4073efde840a9bb34614929dfa7ed1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/ym80ogxj3398khvxxogxroz4gvgw3ssg",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/16",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46453",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T08:17:55.698Z",
      "date_published": "2026-07-06T07:55:56.230Z",
      "date_updated": "2026-07-06T18:44:44.793Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00577,
        "percentile": 0.44304
      },
      "nvd": {
        "published": "2026-07-06T09:16:36.317",
        "lastModified": "2026-07-07T23:30:09.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46453",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unprefixed headers bypass the filter and let the caller override the intended Elasticsearch operation or query scope.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46453.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/6",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2644,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T08:45:22.737Z",
      "date_published": "2026-07-06T07:56:14.036Z",
      "date_updated": "2026-07-06T17:41:19.974Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00706,
        "percentile": 0.4985
      },
      "nvd": {
        "published": "2026-07-06T09:16:36.457",
        "lastModified": "2026-07-08T03:15:21.903",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46454",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "CometdBinding.populateExchangeFromMessage copies every client-supplied ext.CamelHeaders entry into the Exchange without filtering Camel control headers.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46454.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2110,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46455",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T08:55:41.867Z",
      "date_published": "2026-07-06T07:56:29.905Z",
      "date_updated": "2026-07-06T19:29:29.570Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00426,
        "percentile": 0.35056
      },
      "nvd": {
        "published": "2026-07-06T09:16:36.573",
        "lastModified": "2026-07-08T03:15:29.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46455",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Camel's Keycloak verifier omits the IS_ACTIVE check and accepts tokens before nbf or after exp.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46455.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/8",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1713,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46456",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T08:59:11.779Z",
      "date_published": "2026-07-06T07:56:51.598Z",
      "date_updated": "2026-07-06T19:28:37.870Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00641,
        "percentile": 0.47213
      },
      "nvd": {
        "published": "2026-07-06T09:16:36.683",
        "lastModified": "2026-07-08T03:15:11.683",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46456",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "AWS2-SQS copies sender-controlled message attributes into Camel headers without an inbound filter, allowing a queue sender to set internal control headers used by downstream producers.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46456.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/9",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2324,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46457",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T11:45:46.558Z",
      "date_published": "2026-07-06T07:57:13.104Z",
      "date_updated": "2026-07-06T19:27:26.948Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00423,
        "percentile": 0.34832
      },
      "nvd": {
        "published": "2026-07-06T09:16:36.807",
        "lastModified": "2026-07-08T03:14:59.887",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46457",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Camel trusts NATS message headers as control headers, allowing a lower-trust message to override route behavior.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46457.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/10",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2190,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T14:11:53.521Z",
      "date_published": "2026-07-15T12:51:00.988Z",
      "date_updated": "2026-07-15T13:02:49.266Z",
      "publisher": "CERT-PL",
      "title": "Credential exposure in ICU Scandinavia Boomerang",
      "affected": {
        "vendors": [
          "ICU Scandinavia"
        ],
        "products": [
          {
            "vendor": "ICU Scandinavia",
            "product": "Boomerang"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15407
      },
      "nvd": {
        "published": "2026-07-15T13:17:21.560",
        "lastModified": "2026-07-15T18:03:03.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46458",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-46458",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://icuscandinavia.se/boomerang-quality-assurance-lab/",
          "host": "icuscandinavia.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 340,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T14:11:53.521Z",
      "date_published": "2026-07-15T12:51:02.161Z",
      "date_updated": "2026-07-15T13:02:21.938Z",
      "publisher": "CERT-PL",
      "title": "Missing Authorization in ICU Scandinavia Boomerang",
      "affected": {
        "vendors": [
          "ICU Scandinavia"
        ],
        "products": [
          {
            "vendor": "ICU Scandinavia",
            "product": "Boomerang"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21052
      },
      "nvd": {
        "published": "2026-07-15T13:17:22.077",
        "lastModified": "2026-07-15T18:03:03.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46459",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Boomerang exposes device-receiver endpoints without authentication, allowing remote reads of facility configuration and writes to the sensor database.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-46458",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://icuscandinavia.se/boomerang-quality-assurance-lab/",
          "host": "icuscandinavia.se",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 290,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46463",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T17:05:39.858Z",
      "date_published": "2026-07-03T13:42:07.171Z",
      "date_updated": "2026-07-06T16:28:13.050Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15579
      },
      "nvd": {
        "published": "2026-07-03T14:16:29.660",
        "lastModified": "2026-07-08T19:32:28.133",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46463",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled arithmetic can wrap before its result is used by the affected memory operation.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 392,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-46464",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T17:05:39.859Z",
      "date_published": "2026-07-03T13:32:35.091Z",
      "date_updated": "2026-07-07T02:15:08.108Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00422,
        "percentile": 0.34798
      },
      "nvd": {
        "published": "2026-07-03T14:16:30.360",
        "lastModified": "2026-07-08T19:32:24.010",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46464",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerProtect Data Domain follows an attacker-influenced link or pre-planted path without verifying the final filesystem object.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 428,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-46465",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T17:05:39.859Z",
      "date_published": "2026-07-03T13:16:00.714Z",
      "date_updated": "2026-07-06T16:29:09.489Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-134",
          "name": "Use of Externally-Controlled Format String",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14906
      },
      "nvd": {
        "published": "2026-07-03T14:16:30.473",
        "lastModified": "2026-07-08T19:32:19.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46465",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An externally controlled string is used as a formatting program instead of as inert format data.",
        "basis": [
          "CNA",
          "CWE-134"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-46466",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T17:05:39.859Z",
      "date_published": "2026-07-03T13:10:01.883Z",
      "date_updated": "2026-07-06T14:18:49.663Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-348",
          "name": "Use of Less Trusted Source",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00109,
        "percentile": 0.0145
      },
      "nvd": {
        "published": "2026-07-03T14:16:30.593",
        "lastModified": "2026-07-08T19:32:15.503",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46466",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "PowerProtect uses security-relevant data from a less-trusted source, allowing a high-privileged remote user to tamper with information, although the source is not public.",
        "basis": [
          "CNA",
          "CWE-348"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-46467",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T17:05:39.859Z",
      "date_published": "2026-07-03T13:04:26.935Z",
      "date_updated": "2026-07-07T02:14:33.621Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00085,
        "percentile": 0.00381
      },
      "nvd": {
        "published": "2026-07-03T13:17:22.990",
        "lastModified": "2026-07-08T19:33:06.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46467",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerProtect writes sensitive information into logs readable by a low-privileged local user.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-46468",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T17:05:39.859Z",
      "date_published": "2026-07-03T12:58:46.278Z",
      "date_updated": "2026-07-06T16:33:11.018Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03253
      },
      "nvd": {
        "published": "2026-07-03T13:17:23.110",
        "lastModified": "2026-07-08T19:33:04.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46468",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PowerProtect Data Domain file operation follows an attacker-influenced link outside the intended file object.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-46485",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T18:06:06.811Z",
      "date_published": "2026-07-15T18:08:48.278Z",
      "date_updated": "2026-07-20T14:38:24.078Z",
      "publisher": "GitHub_M",
      "title": "Dash: Users can write to config despire permissions (OIDC tested)",
      "affected": {
        "vendors": [
          "lissy93"
        ],
        "products": [
          {
            "vendor": "lissy93",
            "product": "dashy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-15",
          "name": "External Control of System or Configuration Setting",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22737
      },
      "nvd": {
        "published": "2026-07-15T19:17:17.657",
        "lastModified": "2026-07-20T16:17:01.520",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46485",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OIDC config-saving path permits unauthenticated or non-admin callers to write config.yaml despite the configured administrative policy.",
        "basis": [
          "CNA",
          "CWE-15",
          "CWE-284",
          "CWE-287",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lissy93/dashy/security/advisories/GHSA-vjj9-fmvr-6h3p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lissy93/dashy/releases/tag/4.0.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 401,
        "referenceCount": 2,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46512",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T19:12:32.754Z",
      "date_published": "2026-07-16T18:15:52.181Z",
      "date_updated": "2026-07-18T03:05:10.646Z",
      "publisher": "GitHub_M",
      "title": "Frogman: Dialplan template parameters interpolated into extensions_custom.conf without escaping",
      "affected": {
        "vendors": [
          "mwtcmi"
        ],
        "products": [
          {
            "vendor": "mwtcmi",
            "product": "frogman"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27859
      },
      "nvd": {
        "published": "2026-07-16T19:16:46.510",
        "lastModified": "2026-07-18T03:16:36.113",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46512",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "frogman lets attacker-controlled schema, metadata, code text, or file content cross into a code-generation or execution interpreter without the quoting, allowlisting, or neutralization needed to keep it as data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mwtcmi/frogman/security/advisories/GHSA-pxfc-q72v-jh8m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/commit/36a05ffa2df1d256b6f6f7c3b66ef77ebe3e458a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/releases/tag/v1.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/releases/tag/v1.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 519,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46513",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T19:12:32.754Z",
      "date_published": "2026-07-16T18:14:05.454Z",
      "date_updated": "2026-07-17T13:58:34.353Z",
      "publisher": "GitHub_M",
      "title": "Frogman: API tokens stored in plaintext",
      "affected": {
        "vendors": [
          "mwtcmi"
        ],
        "products": [
          {
            "vendor": "mwtcmi",
            "product": "frogman"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-256",
          "name": "Plaintext Storage of a Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17745
      },
      "nvd": {
        "published": "2026-07-16T19:16:46.640",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46513",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Frogman stores reusable API bearer tokens in plaintext, so database read access recovers active credentials at their assigned privilege level.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-256"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mwtcmi/frogman/security/advisories/GHSA-9xf5-9ghq-p6cw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/commit/b10f314add08c8e7585ba4b27d071b07d026ab55",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/releases/tag/v1.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/releases/tag/v1.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46514",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T19:12:32.754Z",
      "date_published": "2026-07-16T18:11:11.738Z",
      "date_updated": "2026-07-16T18:40:59.789Z",
      "publisher": "GitHub_M",
      "title": "Frogman: Plaintext passwords and secrets persisted to audit log",
      "affected": {
        "vendors": [
          "mwtcmi"
        ],
        "products": [
          {
            "vendor": "mwtcmi",
            "product": "frogman"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17622
      },
      "nvd": {
        "published": "2026-07-16T19:16:46.767",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46514",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Frogman serializes tool responses containing plaintext passwords and extension secrets into an audit log readable by lower-privileged users.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mwtcmi/frogman/security/advisories/GHSA-3p65-2prr-cfvf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/commit/02203edb613774f265ad8a21d99c4f6cf7de0d4d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/releases/tag/v1.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/releases/tag/v1.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 477,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46515",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T19:12:32.754Z",
      "date_published": "2026-07-16T18:17:14.563Z",
      "date_updated": "2026-07-16T18:29:28.728Z",
      "publisher": "GitHub_M",
      "title": "Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution",
      "affected": {
        "vendors": [
          "mwtcmi"
        ],
        "products": [
          {
            "vendor": "mwtcmi",
            "product": "frogman"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24779
      },
      "nvd": {
        "published": "2026-07-16T19:16:46.907",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46515",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Frogman assigns read-tier users to tools that expose administrator secrets and execute privileged saved GraphQL queries.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mwtcmi/frogman/security/advisories/GHSA-q4c4-5cr4-8q47",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/issues/13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/issues/25",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/commit/55ea257d5c24bc01c814a607faa7e76e86b111ec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/commit/b8a8bfc12b564bcb77caef952873b9ffd4a98b00",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/releases/tag/v1.6.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T19:12:32.755Z",
      "date_published": "2026-07-20T14:23:23.073Z",
      "date_updated": "2026-07-20T19:08:14.950Z",
      "publisher": "GitHub_M",
      "title": "Frogman vulnerable to stored XSS in chat console formatter (escalation vector in multi-admin deployments)",
      "affected": {
        "vendors": [
          "mwtcmi"
        ],
        "products": [
          {
            "vendor": "mwtcmi",
            "product": "frogman"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17699
      },
      "nvd": {
        "published": "2026-07-20T15:16:38.833",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46516",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Frogman inserts chat formatter capture groups as raw HTML instead of separating reflected tool data from markup.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mwtcmi/frogman/security/advisories/GHSA-7qvv-vgw9-rcxg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/mwtcmi/frogman/commit/f0d2ba1785abb31b7d5debeae526f9e36962b55e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 778,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46555",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T20:42:31.369Z",
      "date_published": "2026-07-20T17:06:22.232Z",
      "date_updated": "2026-07-20T17:35:17.593Z",
      "publisher": "GitHub_M",
      "title": "WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration",
      "affected": {
        "vendors": [
          "verygoodplugins"
        ],
        "products": [
          {
            "vendor": "verygoodplugins",
            "product": "whatsapp-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08595
      },
      "nvd": {
        "published": "2026-07-20T17:17:09.820",
        "lastModified": "2026-07-23T18:04:42.997",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46555",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The loopback bridge lacks authentication and Host validation and accepts an unconstrained absolute media_path, allowing an untrusted local or DNS-rebinding caller to send messages and exfiltrate files.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-306",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/verygoodplugins/whatsapp-mcp/security/advisories/GHSA-7jj9-4qqq-4xc4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/verygoodplugins/whatsapp-mcp/blob/main/SECURITY.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/verygoodplugins/whatsapp-mcp/releases/tag/v0.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2109,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46556",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T20:42:31.369Z",
      "date_published": "2026-07-21T20:34:23.536Z",
      "date_updated": "2026-07-22T14:50:37.123Z",
      "publisher": "GitHub_M",
      "title": "FlaskBB: SSRF in get_image_info() via unrestricted avatar URL",
      "affected": {
        "vendors": [
          "flaskbb"
        ],
        "products": [
          {
            "vendor": "flaskbb",
            "product": "flaskbb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.1113
      },
      "nvd": {
        "published": "2026-07-21T21:16:50.133",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46556",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints, including cloud metadata services.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/flaskbb/flaskbb/security/advisories/GHSA-xq32-9g7q-7297",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/flaskbb/flaskbb/commit/e87e585f54bbe36694e91d52ee9b2d2e65dd4ab5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46562",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-14T20:42:31.370Z",
      "date_published": "2026-07-16T16:06:39.148Z",
      "date_updated": "2026-07-16T18:02:19.337Z",
      "publisher": "GitHub_M",
      "title": "Yamcs: Remote Code Execution via Mission Database algorithm override",
      "affected": {
        "vendors": [
          "yamcs"
        ],
        "products": [
          {
            "vendor": "yamcs",
            "product": "yamcs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-95",
          "name": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0078,
        "percentile": 0.52387
      },
      "nvd": {
        "published": "2026-07-16T17:16:56.953",
        "lastModified": "2026-07-20T01:53:17.737",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46562",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Yamcs evaluates editable JavaScript algorithms in Nashorn without a ClassFilter, exposing Java classes and operating-system command execution.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-95",
          "CWE-470"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yamcs/yamcs/security/advisories/GHSA-vmwp-vh32-rj75",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/commit/3c550348f866af4675d2ba4a51d8d12b7c7c6011",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/commit/4ff8fda642ea8c3309a4d3f379aa77b763148992",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 813,
        "referenceCount": 5,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46582",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T10:11:10.536Z",
      "date_published": "2026-07-22T13:07:40.588Z",
      "date_updated": "2026-07-22T18:56:40.376Z",
      "publisher": "NLnet Labs",
      "title": "A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-358",
          "name": "Improperly Implemented Security Check for Standard",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.0788
      },
      "nvd": {
        "published": "2026-07-22T14:17:19.397",
        "lastModified": "2026-07-24T13:55:34.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46582",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "One thread marks a replayed wildcard RRset secure before NSEC validation completes, allowing another serve-expired thread to cache and answer with that transient state.",
        "basis": [
          "CNA",
          "CWE-358"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-46582.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1474,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46584",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T07:52:46.176Z",
      "date_published": "2026-07-06T08:02:37.913Z",
      "date_updated": "2026-07-06T19:26:03.975Z",
      "publisher": "apache",
      "title": "Apache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parameters",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel Mail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00391,
        "percentile": 0.31866
      },
      "nvd": {
        "published": "2026-07-06T09:16:36.927",
        "lastModified": "2026-07-08T15:06:26.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46584",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The mail producer accepts untrusted mail.smtp and mail.smtps message headers as JavaMail session properties, allowing message input to override the configured upstream channel.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46584.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/11",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2417,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46585",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T07:54:48.302Z",
      "date_published": "2026-07-06T08:03:16.498Z",
      "date_updated": "2026-07-06T19:24:45.975Z",
      "publisher": "apache",
      "title": "Apache Camel Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel Lucene"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00399,
        "percentile": 0.32685
      },
      "nvd": {
        "published": "2026-07-06T09:16:37.030",
        "lastModified": "2026-07-08T15:06:03.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46585",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Camel HTTP filtering allows non-Camel QUERY headers through to the Lucene producer, where they replace the trusted route query.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46585.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/12",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2005,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46587",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T08:56:50.216Z",
      "date_published": "2026-07-06T09:35:31.928Z",
      "date_updated": "2026-07-06T21:31:56.383Z",
      "publisher": "apache",
      "title": "Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00524,
        "percentile": 0.41547
      },
      "nvd": {
        "published": "2026-07-06T11:16:28.677",
        "lastModified": "2026-07-08T14:38:17.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46587",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Untrusted non-Camel-prefixed exchange headers bypass the Couchbase header filter and override the operation selected by the application.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46587.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/06/15",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46588",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T08:57:46.627Z",
      "date_published": "2026-07-06T09:36:25.163Z",
      "date_updated": "2026-07-06T21:31:57.875Z",
      "publisher": "apache",
      "title": "Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00524,
        "percentile": 0.41547
      },
      "nvd": {
        "published": "2026-07-06T11:16:28.777",
        "lastModified": "2026-07-08T14:38:22.180",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46588",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Non-Camel-prefixed headers bypass the header filter and override the CouchDB operation selected by trusted code.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46588.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/06/16",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46590",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T13:23:22.009Z",
      "date_published": "2026-07-06T08:03:54.979Z",
      "date_updated": "2026-07-06T19:16:21.233Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00714,
        "percentile": 0.50133
      },
      "nvd": {
        "published": "2026-07-06T09:16:37.147",
        "lastModified": "2026-07-08T15:05:34.147",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46590",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Key lifecycle managers pass attacker-writable backend bytes to ObjectInputStream.readObject before any type check or class filter.",
        "basis": [
          "CNA record",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46590.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2110,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46591",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T13:27:34.353Z",
      "date_published": "2026-07-06T08:04:17.286Z",
      "date_updated": "2026-07-06T19:21:17.467Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-943",
          "name": "Improper Neutralization of Special Elements in Data Query Logic",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00329,
        "percentile": 0.25387
      },
      "nvd": {
        "published": "2026-07-06T09:16:37.263",
        "lastModified": "2026-07-08T15:05:01.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46591",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Neo4j producer parameterizes property values but concatenates attacker-controlled property names into the Cypher WHERE clause.",
        "basis": [
          "CNA",
          "CWE-943"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46591.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2001,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46592",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T13:32:13.841Z",
      "date_published": "2026-07-06T08:04:32.968Z",
      "date_updated": "2026-07-06T19:20:07.548Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32365
      },
      "nvd": {
        "published": "2026-07-06T09:16:37.380",
        "lastModified": "2026-07-08T14:54:24.890",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46592",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Camel lets inbound HTTP operationName headers cross its transport filter and select a different backend SOAP operation.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-441"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46592.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/15",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2084,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46593",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T13:52:51.435Z",
      "date_published": "2026-07-31T11:40:53.781Z",
      "date_updated": "2026-07-31T19:53:03.540Z",
      "publisher": "CERT-PL",
      "title": "Authenticated SQL Injection in PHP Poll Script",
      "affected": {
        "vendors": [
          "PHP Jabbers"
        ],
        "products": [
          {
            "vendor": "PHP Jabbers",
            "product": "PHP Poll Script"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00297,
        "percentile": 0.21935
      },
      "nvd": {
        "published": "2026-07-31T12:16:50.527",
        "lastModified": "2026-07-31T20:16:50.930",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46593",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In PHP Poll Script, attacker-controlled input reaches an SQL statement without the required parameter binding or SQL-context escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2025-67649/",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.phpjabbers.com/php-poll-script/",
          "host": "www.phpjabbers.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 281,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46594",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T13:52:51.436Z",
      "date_published": "2026-07-31T11:40:57.749Z",
      "date_updated": "2026-07-31T19:51:30.479Z",
      "publisher": "CERT-PL",
      "title": "Reflected XSS in PHP Poll Script",
      "affected": {
        "vendors": [
          "PHP Jabbers"
        ],
        "products": [
          {
            "vendor": "PHP Jabbers",
            "product": "PHP Poll Script"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.2745
      },
      "nvd": {
        "published": "2026-07-31T12:16:50.653",
        "lastModified": "2026-07-31T20:16:51.047",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46594",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2025-67649/",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.phpjabbers.com/php-poll-script/",
          "host": "www.phpjabbers.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46600",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T17:35:00.814Z",
      "date_published": "2026-07-21T19:18:59.755Z",
      "date_updated": "2026-07-23T15:00:35.473Z",
      "publisher": "Go",
      "title": "Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage",
      "affected": {
        "vendors": [
          "golang.org/x/net"
        ],
        "products": [
          {
            "vendor": "golang.org/x/net",
            "product": "golang.org/x/net/dns/dnsmessage"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26487
      },
      "nvd": {
        "published": "2026-07-21T20:17:01.213",
        "lastModified": "2026-07-23T18:27:48.877",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46600",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The DNS message parser permits an SVCB or HTTPS parameter length to exceed the remaining message buffer and panics while reading the invalid field.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://go.dev/cl/786345",
          "host": "go.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://go.dev/issue/79795",
          "host": "go.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5942",
          "host": "pkg.go.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 110,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46621",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T19:34:14.012Z",
      "date_published": "2026-07-16T16:07:38.699Z",
      "date_updated": "2026-07-16T18:00:50.323Z",
      "publisher": "GitHub_M",
      "title": "Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection",
      "affected": {
        "vendors": [
          "yamcs"
        ],
        "products": [
          {
            "vendor": "yamcs",
            "product": "yamcs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00998,
        "percentile": 0.59358
      },
      "nvd": {
        "published": "2026-07-16T17:16:57.090",
        "lastModified": "2026-07-20T01:46:21.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46621",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Jython compiles and runs a user-supplied algorithm without an isolation boundary around the generated code.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yamcs/yamcs/security/advisories/GHSA-2g95-6x5q-xjwj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/commit/3c550348f866af4675d2ba4a51d8d12b7c7c6011",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/commit/4ff8fda642ea8c3309a4d3f379aa77b763148992",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 660,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46627",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T19:34:14.013Z",
      "date_published": "2026-07-14T21:15:17.366Z",
      "date_updated": "2026-07-16T15:03:37.558Z",
      "publisher": "GitHub_M",
      "title": "Twig: Sandbox resource exhaustion via unbounded `for` / `range()`",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00385,
        "percentile": 0.3122
      },
      "nvd": {
        "published": "2026-07-14T22:16:54.700",
        "lastModified": "2026-07-16T16:19:08.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46627",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Twig sandbox enforces a symbol allow-list but imposes no CPU, memory, or wall-clock limit on an untrusted template.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-923g-j88x-j34q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/6bfa285e2f98651adb7aa480bf83a741d154f09f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46628",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T19:34:14.013Z",
      "date_published": "2026-07-14T21:19:54.501Z",
      "date_updated": "2026-07-15T12:49:21.254Z",
      "publisher": "GitHub_M",
      "title": "Twig: The `spaceless` filter implicitly marks its output as safe",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06588
      },
      "nvd": {
        "published": "2026-07-14T22:16:54.853",
        "lastModified": "2026-07-16T03:11:52.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46628",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Twig's spaceless processing marks transformed content as safe HTML and bypasses automatic output escaping.",
        "basis": [
          "CNA",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-4j38-f5cw-54h7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/3190b9ae12614dfd58cc5d8f394bac4708b17913",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46629",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T19:34:14.013Z",
      "date_published": "2026-07-14T21:22:15.595Z",
      "date_updated": "2026-07-15T12:53:13.636Z",
      "publisher": "GitHub_M",
      "title": "Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22516
      },
      "nvd": {
        "published": "2026-07-14T22:16:55.860",
        "lastModified": "2026-07-16T03:11:40.067",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46629",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Twig intl-extra memoizes ICU formatter objects under template-controlled locale, pattern, and attribute keys without eviction, pinning unbounded objects for the Twig environment lifetime.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-35wc-cvqg-78fp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/6add9066fc5c0455eb764c1f3af6e4e4e3562419",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46633",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T20:11:54.583Z",
      "date_published": "2026-07-14T21:14:24.916Z",
      "date_updated": "2026-07-16T03:55:36.587Z",
      "publisher": "GitHub_M",
      "title": "Twig: PHP code injection via `{% use %}` template name",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.1000000000000014,
      "epss": {
        "score": 0.00642,
        "percentile": 0.47261
      },
      "nvd": {
        "published": "2026-07-14T22:16:55.997",
        "lastModified": "2026-07-16T05:16:19.800",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46633",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-7p85-w9px-jpjp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/679447fa29083043665482ccf7d64372472621b8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/e9ff55f6910832428e48a35b2e0748189ad49ae3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46634",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T20:11:54.583Z",
      "date_published": "2026-07-14T21:19:17.804Z",
      "date_updated": "2026-07-29T18:26:17.523Z",
      "publisher": "GitHub_M",
      "title": "Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 2.1000000000000005,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34535
      },
      "nvd": {
        "published": "2026-07-14T22:16:56.130",
        "lastModified": "2026-07-29T19:16:46.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46634",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Twig assigns an inner string template a synthesized name outside the outer template's SourcePolicy sandbox decision, so the inner template renders without that policy.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-24x9-r6q4-q93w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/1cde8f2b62463f85d47995fc25f8241cb409d915",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 407,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46635",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T20:11:54.583Z",
      "date_published": "2026-07-14T21:12:56.046Z",
      "date_updated": "2026-07-15T13:26:27.106Z",
      "publisher": "GitHub_M",
      "title": "Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00297,
        "percentile": 0.21927
      },
      "nvd": {
        "published": "2026-07-14T22:16:56.270",
        "lastModified": "2026-07-15T20:19:05.940",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46635",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Twig's column filter sends object arrays through array_column(), bypassing the sandbox property-allowlist check in CoreExtension::getAttribute().",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-vcc8-phrv-43wj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/f05c5011c25caf17de37614b7e04662022532ac4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 412,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46637",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T20:11:54.584Z",
      "date_published": "2026-07-14T21:25:20.141Z",
      "date_updated": "2026-07-16T15:05:57.087Z",
      "publisher": "GitHub_M",
      "title": "Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`",
      "affected": {
        "vendors": [
          "twig",
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          },
          {
            "vendor": "twig",
            "product": "cssinliner-extra"
          },
          {
            "vendor": "twig",
            "product": "markdown-extra"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07225
      },
      "nvd": {
        "published": "2026-07-14T22:16:56.410",
        "lastModified": "2026-07-16T16:19:08.693",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46637",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-116",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-jv8m-2544-3pg3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/84982072c79a7417b0d158a401d91344f3658299",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/e36489d3521ecbfc08bdcc61294302557035f14a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 343,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46638",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T20:11:54.584Z",
      "date_published": "2026-07-14T21:23:50.961Z",
      "date_updated": "2026-07-15T12:48:08.554Z",
      "publisher": "GitHub_M",
      "title": "Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 2.0999999999999996,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18208
      },
      "nvd": {
        "published": "2026-07-14T22:16:56.553",
        "lastModified": "2026-07-16T03:11:19.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46638",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Twig reuses a template cached outside the sandbox without rerunning checkSecurity, so forbidden template constructs remain executable inside the sandbox include.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-7fxw-r6jv-74c8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/819c6a89fe0f261b8555c4f4d5e27d31984223ea",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 356,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46639",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T20:11:54.584Z",
      "date_published": "2026-07-14T21:13:42.321Z",
      "date_updated": "2026-07-15T12:54:34.864Z",
      "publisher": "GitHub_M",
      "title": "Twig: Sandbox property and method bypass via object-destructuring assignment",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27785
      },
      "nvd": {
        "published": "2026-07-14T22:16:56.697",
        "lastModified": "2026-07-16T03:11:02.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46639",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Object-destructuring compilation hardcodes the sandbox flag to false and skips property and method policy checks.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-mm6w-gr99-p3jj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 427,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46640",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T20:11:54.584Z",
      "date_published": "2026-07-14T21:22:57.332Z",
      "date_updated": "2026-07-16T03:55:34.985Z",
      "publisher": "GitHub_M",
      "title": "Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33261
      },
      "nvd": {
        "published": "2026-07-14T22:16:56.840",
        "lastModified": "2026-07-16T05:16:20.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46640",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Twig concatenates an attacker-controlled dynamic attribute into a macro reference without identifier validation and emits it as raw generated PHP.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-45vw-wh46-2vx8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/324fa60545694fa6abe85ded9befcb82e1066bc2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 375,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46644",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T20:11:54.584Z",
      "date_published": "2026-07-14T20:48:31.771Z",
      "date_updated": "2026-07-15T12:52:31.603Z",
      "publisher": "GitHub_M",
      "title": "symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "polyfill"
          },
          {
            "vendor": "symfony",
            "product": "polyfill-intl-idn"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1289",
          "name": "Improper Validation of Unsafe Equivalence in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00394,
        "percentile": 0.32232
      },
      "nvd": {
        "published": "2026-07-14T21:16:55.850",
        "lastModified": "2026-07-15T18:16:22.887",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46644",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The IDN polyfill accepts ACE labels whose Punycode decodes to ASCII-only text, allowing distinct hostnames to canonicalize as equivalent during trust checks.",
        "basis": [
          "CNA",
          "CWE-1289"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/polyfill/security/advisories/GHSA-2xf4-cg6j-vhgq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/polyfill/commit/1be936e2491ccebe152bd736dfc91eb1422c8bec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/polyfill/releases/tag/v1.38.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 654,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46671",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T21:46:51.547Z",
      "date_published": "2026-07-20T15:56:50.944Z",
      "date_updated": "2026-07-20T17:31:57.487Z",
      "publisher": "GitHub_M",
      "title": "Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory",
      "affected": {
        "vendors": [
          "msiemens"
        ],
        "products": [
          {
            "vendor": "msiemens",
            "product": "onenote.rs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04118
      },
      "nvd": {
        "published": "2026-07-20T16:17:01.630",
        "lastModified": "2026-07-23T18:04:42.997",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46671",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The onenote.rs file operation accepts an attacker-controlled path that escapes the intended directory or storage target.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/msiemens/onenote.rs/security/advisories/GHSA-4j5m-wc25-pvh7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/msiemens/onenote.rs/commit/c9267b2c96e2542be7e7b557d67318e81b733585",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/msiemens/onenote.rs/blob/master/CHANGELOG.md#111---2026-05-15",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/msiemens/onenote.rs/releases/tag/v1.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1424,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46672",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T21:46:51.547Z",
      "date_published": "2026-07-07T20:55:02.846Z",
      "date_updated": "2026-07-08T13:00:02.162Z",
      "publisher": "GitHub_M",
      "title": "Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escapeCsv` Helper",
      "affected": {
        "vendors": [
          "actualbudget"
        ],
        "products": [
          {
            "vendor": "actualbudget",
            "product": "actual"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1236",
          "name": "Improper Neutralization of Formula Elements in a CSV File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03171
      },
      "nvd": {
        "published": "2026-07-07T21:17:25.420",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46672",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CSV serializer emits attacker-controlled formula prefixes without neutralizing spreadsheet evaluation.",
        "basis": [
          "CNA",
          "CWE-1236"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/actualbudget/actual/security/advisories/GHSA-7gh7-258j-4mpq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/pull/7859",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/commit/068185751c03b42e726e3c60b718413d5f96c306",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/releases/tag/v26.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 787,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46678",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T21:46:51.547Z",
      "date_published": "2026-07-29T20:16:45.986Z",
      "date_updated": "2026-07-30T14:37:27.447Z",
      "publisher": "GitHub_M",
      "title": "Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)",
      "affected": {
        "vendors": [
          "pydantic"
        ],
        "products": [
          {
            "vendor": "pydantic",
            "product": "pydantic-ai"
          },
          {
            "vendor": "pydantic",
            "product": "pydantic-ai-slim"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36274
      },
      "nvd": {
        "published": "2026-07-29T21:17:47.040",
        "lastModified": "2026-08-04T13:52:14.037",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46678",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The URL validation in pydantic-ai permits an attacker-selected destination to reach private, loopback, metadata, or otherwise restricted services.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-cqp8-fcvh-x7r3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pydantic/pydantic-ai/releases/tag/v1.99.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1089,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46680",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T21:46:51.547Z",
      "date_published": "2026-07-01T17:40:25.499Z",
      "date_updated": "2026-07-03T03:56:06.341Z",
      "publisher": "GitHub_M",
      "title": "containerd user ID handling bypass allows runAsNonRoot evasion",
      "affected": {
        "vendors": [
          "containerd"
        ],
        "products": [
          {
            "vendor": "containerd",
            "product": "containerd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12743
      },
      "nvd": {
        "published": "2026-07-01T18:16:32.853",
        "lastModified": "2026-07-03T04:17:53.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46680",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "containerd fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/containerd/containerd/security/advisories/GHSA-fqw6-gf59-qr4w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-46681",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T21:46:51.547Z",
      "date_published": "2026-07-21T14:02:03.732Z",
      "date_updated": "2026-07-21T15:00:58.090Z",
      "publisher": "GitHub_M",
      "title": "@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty",
      "affected": {
        "vendors": [
          "nevware21"
        ],
        "products": [
          {
            "vendor": "nevware21",
            "product": "ts-utils"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20635
      },
      "nvd": {
        "published": "2026-07-21T15:16:35.177",
        "lastModified": "2026-07-23T18:14:47.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46681",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The copy helper iterates inherited properties and accepts __proto__, constructor, and prototype keys, allowing input to modify the shared object prototype.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nevware21/ts-utils/security/advisories/GHSA-x7j8-49r8-mr43",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nevware21/ts-utils/commit/5e887f4e2fbee7160c8f501634c45e6a229e83bb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T21:46:51.548Z",
      "date_published": "2026-07-15T19:41:15.036Z",
      "date_updated": "2026-07-17T18:18:37.875Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Unauthorized Command Execution Vulnerability",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09256
      },
      "nvd": {
        "published": "2026-07-15T20:17:05.317",
        "lastModified": "2026-07-17T19:17:15.033",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46684",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DataEase decodes enterprise JWTs and trusts chosen uid and oid claims without verifying the token signature.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-gp6v-f7mm-458v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/3efda9d29c0df4300d43bb7874638e03060c3e2d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46686",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T21:46:51.548Z",
      "date_published": "2026-07-16T16:59:17.567Z",
      "date_updated": "2026-07-16T17:52:58.817Z",
      "publisher": "GitHub_M",
      "title": "Emlog Reflected Cross-Site Scripting",
      "affected": {
        "vendors": [
          "emlog"
        ],
        "products": [
          {
            "vendor": "emlog",
            "product": "emlog"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24769
      },
      "nvd": {
        "published": "2026-07-16T18:16:44.063",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46686",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Emlog applies SQL-style addslashes to the search keyword but omits the HTML escaping required before placing it in a value attribute.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/emlog/emlog/security/advisories/GHSA-3h87-c3m2-jpj9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T21:46:51.548Z",
      "date_published": "2026-07-16T17:01:31.147Z",
      "date_updated": "2026-07-16T17:54:49.001Z",
      "publisher": "GitHub_M",
      "title": "Emlog Local File Inclusion (LFI)",
      "affected": {
        "vendors": [
          "emlog"
        ],
        "products": [
          {
            "vendor": "emlog",
            "product": "emlog"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-24",
          "name": "Path Traversal: '../filedir'",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21442
      },
      "nvd": {
        "published": "2026-07-16T18:16:44.203",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46687",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Emlog stores an author-controlled traversal path and later includes the selected local PHP file.",
        "basis": [
          "CNA",
          "CWE-24",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/emlog/emlog/security/advisories/GHSA-9h6g-q584-9vfg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46700",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T23:26:58.308Z",
      "date_published": "2026-07-07T20:56:39.203Z",
      "date_updated": "2026-07-08T14:43:18.586Z",
      "publisher": "GitHub_M",
      "title": "Actual: Missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets",
      "affected": {
        "vendors": [
          "actualbudget"
        ],
        "products": [
          {
            "vendor": "actualbudget",
            "product": "actual"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.09995
      },
      "nvd": {
        "published": "2026-07-07T21:17:25.560",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46700",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Actual's secret endpoint checks only for a valid session and does not require the administrative capability needed to read the named server secret.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/actualbudget/actual/security/advisories/GHSA-3f62-qv96-4p78",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/pull/7862",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/commit/3494f78c9459ed9c412e28b500b675ba5eb72d4e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/releases/tag/v26.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 607,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46701",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T23:26:58.308Z",
      "date_published": "2026-07-20T16:33:43.791Z",
      "date_updated": "2026-07-20T19:07:31.413Z",
      "publisher": "GitHub_M",
      "title": "Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret",
      "affected": {
        "vendors": [
          "Jovancoding"
        ],
        "products": [
          {
            "vendor": "Jovancoding",
            "product": "Network-AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06388
      },
      "nvd": {
        "published": "2026-07-20T17:17:09.990",
        "lastModified": "2026-07-21T19:49:44.020",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46701",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "An empty default MCP secret makes every request pass authorization, while wildcard CORS exposes the unauthenticated tools to a cross-origin browser caller.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-j3vx-cx2r-pvg8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/commit/dc5048112283f3f4eb6c06dd2bf5aa93ef9339be",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/releases/tag/v5.4.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 809,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46709",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T23:26:58.309Z",
      "date_published": "2026-07-15T14:59:18.601Z",
      "date_updated": "2026-07-16T03:55:43.215Z",
      "publisher": "GitHub_M",
      "title": "Tabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)",
      "affected": {
        "vendors": [
          "Eugeny"
        ],
        "products": [
          {
            "vendor": "Eugeny",
            "product": "tabby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13443
      },
      "nvd": {
        "published": "2026-07-15T16:16:46.053",
        "lastModified": "2026-07-30T14:30:37.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46709",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell without neutralizing command substitution metacharacters such as $(…) and `…`, so the incomplete CVE-2026-45038 fix for control characters still allows code execution when the victim presses Enter.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Eugeny/tabby/security/advisories/GHSA-mq9v-2pgm-fxgh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Eugeny/tabby/commit/e151472b951bbd472ddc0545ec8656e4c0f352da",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Eugeny/tabby/releases/tag/v1.0.234",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46715",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-15T23:26:58.309Z",
      "date_published": "2026-07-20T17:10:27.014Z",
      "date_updated": "2026-07-20T18:43:54.970Z",
      "publisher": "GitHub_M",
      "title": "Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance",
      "affected": {
        "vendors": [
          "pallets-eco"
        ],
        "products": [
          {
            "vendor": "pallets-eco",
            "product": "Flask-Security-Too"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20162
      },
      "nvd": {
        "published": "2026-07-20T18:16:52.937",
        "lastModified": "2026-07-23T18:08:24.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46715",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OAuth reauthentication marks a victim session fresh without verifying that the presented OAuth identity belongs to the session's user.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pallets-eco/flask-security/security/advisories/GHSA-97r5-pg8x-p63p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pallets-eco/flask-security/commit/8e69f3a94a463c0e8ddc46e31743717559fd8d48",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46726",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-16T16:46:21.884Z",
      "date_published": "2026-07-06T08:05:40.270Z",
      "date_updated": "2026-07-06T19:19:03.677Z",
      "publisher": "apache",
      "title": "Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel Vertx Websocket"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00783,
        "percentile": 0.52494
      },
      "nvd": {
        "published": "2026-07-06T09:16:37.503",
        "lastModified": "2026-07-08T14:54:13.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46726",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WebSocket consumer copies untrusted query and path parameters into Camel control headers, allowing CamelHttpUri to redirect a downstream server request.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-200",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-46726.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/16",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2428,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-17T17:04:27.065Z",
      "date_published": "2026-07-03T12:54:00.862Z",
      "date_updated": "2026-07-07T13:12:20.640Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01891
      },
      "nvd": {
        "published": "2026-07-03T13:17:23.390",
        "lastModified": "2026-07-08T19:32:43.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46730",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged local Data Domain caller can execute a command outside the authorized set, but Dell does not disclose the command boundary or failed check.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-46737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-17T17:04:27.066Z",
      "date_published": "2026-07-22T15:49:40.557Z",
      "date_updated": "2026-07-24T20:12:11.641Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Manager, versions prior to 20.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27487
      },
      "nvd": {
        "published": "2026-07-22T16:17:24.093",
        "lastModified": "2026-07-29T17:39:45.833",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46737",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The REST API record names improper input validation and remote execution but does not identify an interpreter, parser, memory, or authorization boundary.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000488847/dsa-2026-287-security-update-dell-powerprotect-data-manager-for-multiple-security-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-17T17:04:27.066Z",
      "date_published": "2026-07-22T15:34:12.800Z",
      "date_updated": "2026-07-24T03:56:07.554Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Manager, versions prior to 20.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 1.8999999999999995,
      "epss": {
        "score": 0.00349,
        "percentile": 0.2761
      },
      "nvd": {
        "published": "2026-07-22T16:17:24.223",
        "lastModified": "2026-07-29T17:39:21.237",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46738",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The REST API record names improper input validation and privilege escalation but does not reveal the input, parser, check, or authority transition.",
        "basis": [
          "CNA",
          "CWE-20",
          "Dell DSA-2026-287"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.dell.com/support/kbdoc/en-us/000488847/dsa-2026-287-security-update-dell-powerprotect-data-manager-for-multiple-security-vulnerabilities on 2026-08-05; Dell confirms a REST API input-validation issue, affected versions before 20.2.0.0, and privilege escalation, but does not disclose the field, parser, or authorization transition. The advisory lists CVSS 7.2 while the embedded CNA maximum is 9.1, so the score discrepancy also needs editorial attention."
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000488847/dsa-2026-287-security-update-dell-powerprotect-data-manager-for-multiple-security-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46876",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.308Z",
      "date_published": "2026-07-21T21:32:47.206Z",
      "date_updated": "2026-07-23T15:19:29.456Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Application Testing Suite.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Testing Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38452
      },
      "nvd": {
        "published": "2026-07-21T22:17:01.690",
        "lastModified": "2026-07-24T18:49:16.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46876",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Application Testing Suite Install component accepts unauthenticated Oracle Net access with takeover authority, but the failing access-control check is not public.",
        "basis": [
          "CNA record",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official matrix confirms the Install component, Oracle Net, no authentication, and affected version 13.3.0.1 but publishes no causal check or code path."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 495,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46917",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.311Z",
      "date_published": "2026-07-21T21:32:47.601Z",
      "date_updated": "2026-07-23T15:19:18.407Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM for JDK"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM Enterprise Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21162
      },
      "nvd": {
        "published": "2026-07-21T22:17:01.810",
        "lastModified": "2026-08-03T18:55:54.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46917",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle identifies a remotely reachable JSSE vulnerability and denial-of-service impact but does not disclose the TLS input, parser state, or failing validation rule.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1038,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-46923",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.311Z",
      "date_published": "2026-07-21T21:32:47.918Z",
      "date_updated": "2026-07-23T15:19:04.289Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Financials (International)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.1764
      },
      "nvd": {
        "published": "2026-07-21T22:17:01.930",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46923",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports an authorization flaw that permits product takeover, but it does not disclose the failing permission decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 755,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46924",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.311Z",
      "date_published": "2026-07-21T21:32:48.232Z",
      "date_updated": "2026-07-23T15:18:51.467Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Application Testing Suite.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Testing Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28163
      },
      "nvd": {
        "published": "2026-07-21T22:17:02.047",
        "lastModified": "2026-07-24T18:49:36.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46924",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated TCP takeover of Application Testing Suite, but the current CPU does not disclose the function, parser, or authorization check that fails.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html - Oracle's current risk matrix confirms the Application Testing Suite component, TCP reachability, no prior privileges, affected version, and takeover impact, but publishes no failing function, parser, or authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46936",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.312Z",
      "date_published": "2026-07-21T21:32:48.555Z",
      "date_updated": "2026-07-23T15:18:43.077Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16729
      },
      "nvd": {
        "published": "2026-07-21T22:17:02.160",
        "lastModified": "2026-07-27T14:54:30.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46936",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports a repeatable MySQL DDL denial of service but does not identify the statement shape, state transition, or exhausted resource.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 675,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-46941",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.312Z",
      "date_published": "2026-07-21T21:32:48.881Z",
      "date_updated": "2026-07-23T15:18:32.107Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Cost Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23502
      },
      "nvd": {
        "published": "2026-07-21T22:17:02.283",
        "lastModified": "2026-07-30T17:15:07.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46941",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can exceed its authority in Oracle Cost Maintenance, but the protected object, action, and failing check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46943",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.313Z",
      "date_published": "2026-07-21T21:32:49.201Z",
      "date_updated": "2026-07-23T15:18:20.124Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Retail EFTLink"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22436
      },
      "nvd": {
        "published": "2026-07-21T22:17:02.397",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46943",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Retail EFTLink path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 712,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46948",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.313Z",
      "date_published": "2026-07-21T21:32:49.519Z",
      "date_updated": "2026-07-23T15:18:09.593Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Utilities Network Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04528
      },
      "nvd": {
        "published": "2026-07-21T22:17:02.513",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46948",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected operation is reachable without the required authorization binding, whose exact subject and object check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 919,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-46954",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.313Z",
      "date_published": "2026-07-21T21:32:49.842Z",
      "date_updated": "2026-07-23T15:17:58.349Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Human Resources"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37138
      },
      "nvd": {
        "published": "2026-07-21T22:17:02.647",
        "lastModified": "2026-07-27T16:58:52.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46954",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Human Resources operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46968",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.314Z",
      "date_published": "2026-07-21T21:32:50.164Z",
      "date_updated": "2026-07-23T15:17:46.291Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Java SE (component: JSSE).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.2019
      },
      "nvd": {
        "published": "2026-07-21T22:17:02.760",
        "lastModified": "2026-07-31T15:27:29.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46968",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle identifies a JSSE integrity impact reachable through TLS data but does not disclose the protocol state, validation rule, or write path that permits it.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 870,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-46975",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.314Z",
      "date_published": "2026-07-21T21:32:50.483Z",
      "date_updated": "2026-07-23T15:17:36.027Z",
      "publisher": "oracle",
      "title": "Vulnerability in the RDBMS component of Oracle Database Server.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Database Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11857
      },
      "nvd": {
        "published": "2026-07-21T22:17:02.883",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46975",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Database Server permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 620,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-46980",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:50.818Z",
      "date_updated": "2026-07-23T15:17:26.188Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Utilities Network Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09644
      },
      "nvd": {
        "published": "2026-07-21T22:17:03.007",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46980",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthorized Mobile-component data reads by a low-privileged HTTP caller but does not publish the object or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 704,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-46981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:51.156Z",
      "date_updated": "2026-07-23T15:17:16.766Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Utilities Network Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09324
      },
      "nvd": {
        "published": "2026-07-21T22:17:03.123",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46981",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 990,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-46982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:51.477Z",
      "date_updated": "2026-07-23T15:17:03.483Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Retail Integration Bus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28164
      },
      "nvd": {
        "published": "2026-07-21T22:17:03.240",
        "lastModified": "2026-07-31T15:07:37.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46982",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Retail Integration Bus exposes an unauthenticated access-control failure in RIB Kernel, while the CPU does not disclose the endpoint or authorization rule.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle Critical Patch Update July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. The official CPU identifies Retail Integration Bus RIB Kernel over HTTP, unauthenticated access, score 9.8, and affected 14.1.3.2, but no endpoint or authorization rule."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46983",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:51.847Z",
      "date_updated": "2026-07-23T15:16:53.824Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Retail Integration Bus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38443
      },
      "nvd": {
        "published": "2026-07-21T22:17:03.347",
        "lastModified": "2026-07-31T15:18:35.987",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46983",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Retail Integration Bus exposes a takeover path to an unauthenticated HTTP caller, but Oracle does not publish the route or omitted authentication decision.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html",
          "https://www.oracle.com/security-alerts/cpujul2026verbose.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July CPU confirms the RIB Kernal component, HTTP protocol, affected release, unauthenticated reachability, and takeover impact but no route or authentication decision."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-46984",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:52.196Z",
      "date_updated": "2026-07-23T15:16:39.821Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00306,
        "percentile": 0.22913
      },
      "nvd": {
        "published": "2026-07-21T22:17:03.460",
        "lastModified": "2026-07-24T18:58:01.277",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46984",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Enterprise Manager Base Platform permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46985",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:52.536Z",
      "date_updated": "2026-07-23T15:16:30.726Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14792
      },
      "nvd": {
        "published": "2026-07-21T22:17:03.583",
        "lastModified": "2026-07-24T18:58:26.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46985",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "An unauthenticated HTTPS caller can read protected Enterprise Manager data, but Oracle does not publish the missing object or function check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46986",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:52.960Z",
      "date_updated": "2026-07-23T15:16:16.975Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00306,
        "percentile": 0.22913
      },
      "nvd": {
        "published": "2026-07-21T22:17:03.690",
        "lastModified": "2026-07-24T18:58:49.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46986",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports unauthenticated access to some Enterprise Manager data but does not disclose the request, object, check, or output path that enables it.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46987",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:53.309Z",
      "date_updated": "2026-07-23T15:16:06.586Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Service Level Mgmt).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17783
      },
      "nvd": {
        "published": "2026-07-21T22:17:03.810",
        "lastModified": "2026-07-24T18:59:14.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46987",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTPS user can read critical Enterprise Manager data outside that role's intended scope, but the object or permission check is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 780,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46988",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:53.666Z",
      "date_updated": "2026-07-23T15:15:55.211Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.265
      },
      "nvd": {
        "published": "2026-07-21T22:17:03.923",
        "lastModified": "2026-07-24T19:00:02.133",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46988",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Enterprise Manager Base Platform operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46989",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:54.002Z",
      "date_updated": "2026-07-23T13:32:19.875Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15568
      },
      "nvd": {
        "published": "2026-07-21T22:17:04.037",
        "lastModified": "2026-07-24T19:01:25.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46989",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged UI Framework user can exceed its assigned access, but Oracle does not disclose the failing authorization binding.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the Oracle risk matrix confirms the UI Framework component, HTTPS vector, low privileges, and changed scope but does not disclose the authorization mechanism."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1033,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46990",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:54.350Z",
      "date_updated": "2026-07-23T13:34:26.867Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13677
      },
      "nvd": {
        "published": "2026-07-21T22:17:04.173",
        "lastModified": "2026-07-24T19:01:58.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46990",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 885,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46991",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:54.688Z",
      "date_updated": "2026-07-23T13:37:03.370Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01284
      },
      "nvd": {
        "published": "2026-07-21T22:17:04.303",
        "lastModified": "2026-07-24T19:02:32.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46991",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-46991 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 810,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46992",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:55.065Z",
      "date_updated": "2026-07-27T14:07:43.896Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33019
      },
      "nvd": {
        "published": "2026-07-21T22:17:04.423",
        "lastModified": "2026-07-31T21:08:38.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46992",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A critical Enterprise Manager function is reachable by a low-privilege HTTPS caller without the authentication required for that function.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 597,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46993",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:55.444Z",
      "date_updated": "2026-07-23T13:44:09.900Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18942
      },
      "nvd": {
        "published": "2026-07-21T22:17:04.540",
        "lastModified": "2026-07-24T19:03:19.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46993",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle Enterprise Manager Base Platform in its Agent Next Gen component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 927,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46994",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:55.793Z",
      "date_updated": "2026-07-23T13:47:27.963Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28924
      },
      "nvd": {
        "published": "2026-07-21T22:17:04.663",
        "lastModified": "2026-07-24T19:03:42.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46994",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Agent Next Gen accepts an unauthenticated HTTPS path that permits platform takeover, but the exact missing or incorrect access check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Primary source inspected: https://www.oracle.com/security-alerts/cpujul2026.html. Oracle identifies Agent Next Gen, HTTPS, no authentication, and CVSS 9.8, but publishes no affected operation or causal check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46995",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:56.127Z",
      "date_updated": "2026-07-23T13:48:10.433Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33023
      },
      "nvd": {
        "published": "2026-07-21T22:17:04.780",
        "lastModified": "2026-07-24T19:04:40.420",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46995",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Enterprise Manager lets a low-privileged network user take over the platform, but the public record does not disclose the privilege-to-operation check that fails.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46996",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.315Z",
      "date_published": "2026-07-21T21:32:56.466Z",
      "date_updated": "2026-07-23T15:01:35.662Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10254
      },
      "nvd": {
        "published": "2026-07-21T22:17:04.897",
        "lastModified": "2026-07-24T19:05:09.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46996",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Enterprise Manager permits an operation outside the caller's intended authority, while the public record does not identify the missing subject, object, or action check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 762,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46997",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:32:56.822Z",
      "date_updated": "2026-07-27T14:07:44.044Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11615
      },
      "nvd": {
        "published": "2026-07-21T22:17:05.007",
        "lastModified": "2026-07-24T18:16:55.420",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46997",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Enterprise Manager Base Platform permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 634,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46998",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:32:57.180Z",
      "date_updated": "2026-07-23T14:00:22.441Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20764
      },
      "nvd": {
        "published": "2026-07-21T22:17:05.123",
        "lastModified": "2026-07-24T19:05:29.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-46998",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle maps the Metadata Plugin issue to an open redirect and a user-assisted takeover, but does not publish the redirect parameter or validation failure.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 669,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-46999",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:32:57.522Z",
      "date_updated": "2026-07-27T14:07:44.189Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12041
      },
      "nvd": {
        "published": "2026-07-21T22:17:05.237",
        "lastModified": "2026-07-24T18:16:55.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-46999",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that the Discovery Framework admits an unauthenticated HTTPS operation beyond its intended authority, but does not publish the failing check.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 902,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47000",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:32:57.887Z",
      "date_updated": "2026-07-23T14:04:41.198Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.0275
      },
      "nvd": {
        "published": "2026-07-21T22:17:05.353",
        "lastModified": "2026-07-24T19:00:52.093",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47000",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle's record supports a cross-site request boundary failure in Enterprise Manager Security Framework, but does not publish the state-changing endpoint or missing request check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 690,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47001",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:32:58.414Z",
      "date_updated": "2026-07-23T14:05:58.779Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Web Services Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12803
      },
      "nvd": {
        "published": "2026-07-21T22:17:05.470",
        "lastModified": "2026-07-24T19:05:51.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47001",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle Enterprise Manager Base Platform but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 746,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47002",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:32:58.776Z",
      "date_updated": "2026-07-23T14:14:25.274Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13979
      },
      "nvd": {
        "published": "2026-07-21T22:17:05.580",
        "lastModified": "2026-07-24T19:06:20.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47002",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle UI Framework record maps the issue to an open redirect but does not disclose the target field or origin validation rule.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 964,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47003",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:32:59.118Z",
      "date_updated": "2026-07-23T14:20:43.369Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.2409
      },
      "nvd": {
        "published": "2026-07-21T22:17:05.683",
        "lastModified": "2026-07-24T19:06:39.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47003",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTPS caller can read critical Enterprise Manager data, but the missing authorization decision or endpoint is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 624,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47004",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:32:59.797Z",
      "date_updated": "2026-07-23T14:28:06.405Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33031
      },
      "nvd": {
        "published": "2026-07-21T22:17:05.797",
        "lastModified": "2026-07-24T19:07:00.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47004",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A critical self-update operation is exposed without the authentication required for that function.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47005",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:33:00.144Z",
      "date_updated": "2026-07-23T14:39:42.475Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26499
      },
      "nvd": {
        "published": "2026-07-21T22:17:05.913",
        "lastModified": "2026-07-24T19:07:23.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47005",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privilege HTTPS user can acquire takeover authority in Self Update Framework, but the exact authorization failure is not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 591,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47006",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:33:00.485Z",
      "date_updated": "2026-07-23T14:51:42.109Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager Base Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26499
      },
      "nvd": {
        "published": "2026-07-21T22:17:06.027",
        "lastModified": "2026-07-24T19:07:37.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47006",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Enterprise Manager Base Platform permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 591,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47007",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:33:00.833Z",
      "date_updated": "2026-07-23T15:05:18.931Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Communications Pricing Design Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01818
      },
      "nvd": {
        "published": "2026-07-21T22:17:06.143",
        "lastModified": "2026-07-31T15:18:01.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47007",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The on-premise deployment grants a low-privileged local user access beyond the intended data scope, but the failing control is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1023,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47008",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:33:01.190Z",
      "date_updated": "2026-07-23T14:55:47.292Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24712
      },
      "nvd": {
        "published": "2026-07-21T22:17:06.260",
        "lastModified": "2026-07-27T14:54:01.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47008",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports repeatable InnoDB hangs or crashes under high-privileged network input, but the CPU does not identify the unbounded resource or termination failure.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 622,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47009",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:33:01.534Z",
      "date_updated": "2026-07-29T03:55:57.318Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile PLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29754
      },
      "nvd": {
        "published": "2026-07-21T22:17:06.373",
        "lastModified": "2026-07-31T15:10:57.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47009",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports user-assisted disclosure of Agile PLM data but does not identify the request, output field, or failing access check.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 639,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47010",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:33:01.890Z",
      "date_updated": "2026-07-23T14:58:56.335Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM for JDK"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM Enterprise Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15648
      },
      "nvd": {
        "published": "2026-07-21T22:17:06.497",
        "lastModified": "2026-07-31T15:13:21.283",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47010",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Unauthenticated ImageIO input can cross an Oracle Java sandbox access boundary, but the affected object and missing access-control check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1272,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-47011",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.316Z",
      "date_published": "2026-07-21T21:33:02.247Z",
      "date_updated": "2026-07-23T15:06:53.738Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Deployment"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-203",
          "name": "Observable Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.0607
      },
      "nvd": {
        "published": "2026-07-21T22:17:06.623",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47011",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Siebel CRM Deployment path produces an attacker-observable difference that reveals a protected state or value.",
        "basis": [
          "CNA",
          "CWE-203"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 625,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47012",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:02.596Z",
      "date_updated": "2026-07-23T15:08:09.894Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26959
      },
      "nvd": {
        "published": "2026-07-21T22:17:06.740",
        "lastModified": "2026-07-27T14:53:35.210",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47012",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled activity can exhaust a finite resource, but the public record does not identify the allocation or missing bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 681,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-47013",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:02.941Z",
      "date_updated": "2026-07-23T15:09:00.192Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Java SE (component: JavaFX).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22841
      },
      "nvd": {
        "published": "2026-07-21T22:17:06.857",
        "lastModified": "2026-07-31T14:52:14.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47013",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Oracle Java SE request path allocates work or memory from attacker-controlled input without an effective item or byte limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 924,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:03.289Z",
      "date_updated": "2026-07-23T15:10:33.054Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Workbench"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17819
      },
      "nvd": {
        "published": "2026-07-21T22:17:06.977",
        "lastModified": "2026-07-31T14:44:31.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47014",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Product Workbench permits a low-privileged HTTP caller to cross an access boundary, but the protected action and failing authorization check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 715,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47015",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:03.627Z",
      "date_updated": "2026-08-01T03:55:36.850Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise PeopleTools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07284
      },
      "nvd": {
        "published": "2026-07-21T22:17:07.097",
        "lastModified": "2026-08-01T05:16:56.147",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47015",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says PeopleSoft Enterprise PeopleTools accepts a request across an unintended network or origin boundary, while the request field and validation step are not public.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1051,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47016",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:03.982Z",
      "date_updated": "2026-07-23T15:17:22.755Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 1.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01935
      },
      "nvd": {
        "published": "2026-07-21T22:17:07.217",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47016",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports a physical path to Siebel event data but does not publish the exposed storage or output operation.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 637,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47017",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:04.339Z",
      "date_updated": "2026-07-23T15:19:45.097Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Process Scheduler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise PeopleTools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14058
      },
      "nvd": {
        "published": "2026-07-21T22:17:07.337",
        "lastModified": "2026-07-27T19:36:34.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47017",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 975,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47018",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:04.682Z",
      "date_updated": "2026-07-23T16:07:59.609Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Cloud Applications"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36252
      },
      "nvd": {
        "published": "2026-07-21T22:17:07.450",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47018",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled input can consume finite work or memory without an effective bound, release or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47019",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:05.039Z",
      "date_updated": "2026-08-01T03:55:40.441Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Hub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26313
      },
      "nvd": {
        "published": "2026-07-21T22:17:07.567",
        "lastModified": "2026-08-01T05:16:56.273",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47019",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can cross an undisclosed Item Catalog authorization boundary into critical Product Hub data operations.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 695,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47021",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:05.422Z",
      "date_updated": "2026-07-23T15:22:07.794Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM for JDK"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM Enterprise Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22842
      },
      "nvd": {
        "published": "2026-07-21T22:17:07.670",
        "lastModified": "2026-07-31T13:42:33.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47021",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Java SE accepts attacker-driven work or allocation without an effective size, rate, or termination bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1270,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-47022",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:05.770Z",
      "date_updated": "2026-07-23T15:25:25.897Z",
      "publisher": "oracle",
      "title": "Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "GoldenGate Stream Analytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03185
      },
      "nvd": {
        "published": "2026-07-21T22:17:07.793",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47022",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A local low-privilege user can partially exhaust GoldenGate Stream Analytics, but Oracle does not publish the unbounded resource or operation.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 609,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47023",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:06.123Z",
      "date_updated": "2026-07-23T15:27:02.974Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24713
      },
      "nvd": {
        "published": "2026-07-21T22:17:07.913",
        "lastModified": "2026-07-27T14:53:00.007",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47023",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged replication request can hang or repeatedly crash MySQL, but Oracle does not disclose the resource, loop, or termination condition involved.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 681,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-47024",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:06.459Z",
      "date_updated": "2026-07-23T15:27:41.064Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise PeopleTools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.0487
      },
      "nvd": {
        "published": "2026-07-21T22:17:08.020",
        "lastModified": "2026-07-27T19:36:05.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47024",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged PeopleTools user can read or modify data beyond the role's authority after another user interacts, but the failing access decision is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 919,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47026",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:06.803Z",
      "date_updated": "2026-08-01T03:55:38.595Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise PeopleTools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19329
      },
      "nvd": {
        "published": "2026-07-21T22:17:08.137",
        "lastModified": "2026-08-01T05:16:56.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47026",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PeopleSoft Enterprise PeopleTools redirect path accepts an external destination without restricting it to a trusted origin.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 824,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47027",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:07.144Z",
      "date_updated": "2026-07-23T17:07:46.826Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Java SE (component: Libraries).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21162
      },
      "nvd": {
        "published": "2026-07-21T22:17:08.250",
        "lastModified": "2026-08-03T18:55:05.263",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47027",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports a remotely triggerable Java denial of service but supplies no engineering cause beyond a broad access-control classification.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1070,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-47028",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.317Z",
      "date_published": "2026-07-21T21:33:07.484Z",
      "date_updated": "2026-07-23T17:07:40.129Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Document Management and Collaboration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25099
      },
      "nvd": {
        "published": "2026-07-21T22:17:08.360",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47028",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Document Management and Collaboration permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 798,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47030",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:07.826Z",
      "date_updated": "2026-07-23T17:07:31.945Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Java SE (component: JavaFX).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11325
      },
      "nvd": {
        "published": "2026-07-21T22:17:08.473",
        "lastModified": "2026-08-03T18:54:11.537",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47030",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-47030 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1018,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47031",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:08.200Z",
      "date_updated": "2026-07-23T17:07:26.141Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Bill Issues).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Bills of Material"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31656
      },
      "nvd": {
        "published": "2026-07-21T22:17:08.587",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47031",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Bills of Material grants a low-privilege HTTP caller operations beyond its role, while the protected object and failing check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47032",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:08.540Z",
      "date_updated": "2026-07-23T17:07:16.517Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM End User"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00219,
        "percentile": 0.1248
      },
      "nvd": {
        "published": "2026-07-21T22:17:08.710",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47032",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Siebel CRM End User in its Redwood UI component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 747,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47033",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:08.894Z",
      "date_updated": "2026-07-23T17:07:10.232Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Contracts Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.235
      },
      "nvd": {
        "published": "2026-07-21T22:17:08.823",
        "lastModified": "2026-07-27T17:44:32.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47033",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Contracts Integration grants a low-privilege HTTP caller operations beyond its authority, but Oracle does not disclose the failing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47034",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:09.226Z",
      "date_updated": "2026-07-23T17:06:59.696Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Java SE (component: JavaFX).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11325
      },
      "nvd": {
        "published": "2026-07-21T22:17:08.943",
        "lastModified": "2026-08-03T18:53:50.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47034",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A sandboxed JavaFX application can modify data beyond its granted authority, but Oracle does not disclose the failing sandbox control.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1018,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47035",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:09.574Z",
      "date_updated": "2026-07-23T17:06:50.911Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Java SE (component: JavaFX).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06909
      },
      "nvd": {
        "published": "2026-07-21T22:17:09.060",
        "lastModified": "2026-08-03T18:53:27.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47035",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle JavaFX permits an unauthenticated network caller to affect protected application state, while the public record does not identify the failing authorization boundary.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1018,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47036",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:09.940Z",
      "date_updated": "2026-07-25T03:55:44.686Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Development"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25614
      },
      "nvd": {
        "published": "2026-07-21T22:17:09.170",
        "lastModified": "2026-07-25T05:16:34.993",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47036",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Siebel Approval Manager exposes an HTTP path that can be reached without authentication, while Oracle does not publish the missing gate or handler.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the CPU confirms unauthenticated HTTP reachability and affected versions, while the failing approval-manager gate remains undisclosed."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47037",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:10.281Z",
      "date_updated": "2026-07-28T03:56:44.349Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22444
      },
      "nvd": {
        "published": "2026-07-21T22:17:09.283",
        "lastModified": "2026-07-28T05:17:06.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47037",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an authentication-engine takeover by a low-privileged user but does not publish the credential or session check that fails.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47038",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:10.615Z",
      "date_updated": "2026-07-24T17:44:40.092Z",
      "publisher": "oracle",
      "title": "Vulnerability in the RDBMS component of Oracle Database Server.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Database Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10644
      },
      "nvd": {
        "published": "2026-07-21T22:17:09.437",
        "lastModified": "2026-07-24T18:16:55.860",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47038",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-47039",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:10.947Z",
      "date_updated": "2026-07-23T15:36:03.902Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Java VM component of Oracle Database Server.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Database Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20157
      },
      "nvd": {
        "published": "2026-07-21T22:17:09.547",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47039",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-47040",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:11.302Z",
      "date_updated": "2026-07-23T15:37:04.597Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Net Services component of Oracle Database Server.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Net Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0045,
        "percentile": 0.3696
      },
      "nvd": {
        "published": "2026-07-21T22:17:09.667",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47040",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A security-sensitive endpoint performs its operation without requiring the caller to authenticate.",
        "basis": [
          "CNA",
          "CWE-306",
          "https://www.oracle.com/security-alerts/cpujul2026.html",
          "https://www.oracle.com/security-alerts/cpujul2026verbose.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July CPU confirms the Connection Manager component, unauthenticated Oracle Net reachability, affected releases, and confidentiality and availability impact, but publishes no endpoint, credential path, or omitted authentication check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 695,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-47041",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:11.627Z",
      "date_updated": "2026-07-23T16:07:28.928Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02706
      },
      "nvd": {
        "published": "2026-07-21T22:17:09.783",
        "lastModified": "2026-07-27T20:12:30.707",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47041",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged local VirtualBox caller can cause repeatable crashes, but Oracle does not disclose the finite resource or missing termination rule.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 711,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47043",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:11.976Z",
      "date_updated": "2026-07-23T15:39:07.145Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05812
      },
      "nvd": {
        "published": "2026-07-21T22:17:09.893",
        "lastModified": "2026-07-27T20:12:22.540",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47043",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "VirtualBox exposes a subset of accessible data to a privileged local caller, but the disclosure path is not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 685,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47044",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:12.333Z",
      "date_updated": "2026-07-23T15:40:04.203Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01865
      },
      "nvd": {
        "published": "2026-07-21T22:17:10.007",
        "lastModified": "2026-07-27T20:12:17.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47044",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "VirtualBox can be driven into complete denial of service, but the public record does not identify the exhausted resource or missing termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 588,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47045",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:12.761Z",
      "date_updated": "2026-07-23T15:40:49.299Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JDBC component of Oracle Database Server.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Database Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.16999
      },
      "nvd": {
        "published": "2026-07-21T22:17:10.113",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47045",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "JDBC permits a redirect to an untrusted URL that can move a user-mediated request outside the intended destination boundary.",
        "basis": [
          "CNA record",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-47046",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.318Z",
      "date_published": "2026-07-21T21:33:13.093Z",
      "date_updated": "2026-07-23T15:41:23.105Z",
      "publisher": "oracle",
      "title": "Vulnerability in the RDBMS component of Oracle Database Server.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Database Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20476
      },
      "nvd": {
        "published": "2026-07-21T22:17:10.233",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47046",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says attacker-driven input can exhaust or stop Oracle Database Server but does not identify the unbounded allocation, queue, loop, or unreleased resource.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 605,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47047",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:13.419Z",
      "date_updated": "2026-07-28T03:56:53.806Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02113
      },
      "nvd": {
        "published": "2026-07-21T22:17:10.343",
        "lastModified": "2026-07-28T05:17:06.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47047",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "VirtualBox permits a low-privileged local user to reach a higher-privilege takeover path, but Oracle does not disclose the transition.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 545,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47048",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:13.761Z",
      "date_updated": "2026-07-23T15:30:59.819Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise PeopleTools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04869
      },
      "nvd": {
        "published": "2026-07-21T22:17:10.457",
        "lastModified": "2026-07-27T19:34:58.507",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47048",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle maps the PeopleTools issue to open redirect, but the CPU does not identify the redirect parameter, allowlist, or destination validation rule.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 919,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47049",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:15.116Z",
      "date_updated": "2026-07-23T15:30:18.740Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise PeopleTools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30688
      },
      "nvd": {
        "published": "2026-07-21T22:17:10.570",
        "lastModified": "2026-07-27T19:34:23.627",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47049",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports that a high-privilege PeopleTools user can read protected data but does not identify the failing authorization predicate.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47050",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:15.461Z",
      "date_updated": "2026-07-23T15:29:41.622Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04267
      },
      "nvd": {
        "published": "2026-07-21T22:17:10.677",
        "lastModified": "2026-07-27T20:11:31.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47050",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged local VirtualBox user can modify critical data beyond its intended authority, but the public record does not identify the object or check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 931,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47051",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:15.823Z",
      "date_updated": "2026-07-23T15:28:59.836Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise PeopleTools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04869
      },
      "nvd": {
        "published": "2026-07-21T22:17:10.790",
        "lastModified": "2026-07-27T19:33:49.903",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47051",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The PeopleSoft Enterprise PeopleTools navigation flow accepts an attacker-selected external destination without restricting it to trusted origins.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 920,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47052",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:16.179Z",
      "date_updated": "2026-07-23T15:28:10.918Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00431,
        "percentile": 0.35442
      },
      "nvd": {
        "published": "2026-07-21T22:17:10.903",
        "lastModified": "2026-07-27T14:52:30.413",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47052",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A finite resource can be consumed without an effective cap or release condition, whose implementation is not disclosed.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 668,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-47053",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:16.614Z",
      "date_updated": "2026-07-23T15:27:33.121Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00101,
        "percentile": 0.01055
      },
      "nvd": {
        "published": "2026-07-21T22:17:11.020",
        "lastModified": "2026-07-27T20:11:23.757",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47053",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle VM VirtualBox operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 796,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47054",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:16.966Z",
      "date_updated": "2026-07-28T03:56:54.587Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02113
      },
      "nvd": {
        "published": "2026-07-21T22:17:11.133",
        "lastModified": "2026-07-28T05:17:06.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47054",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle VirtualBox permits a low-privileged local caller to gain broader control, but the privileged operation and failing check are not public.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 600,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47055",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:17.318Z",
      "date_updated": "2026-07-23T15:26:19.228Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01993
      },
      "nvd": {
        "published": "2026-07-21T22:17:11.253",
        "lastModified": "2026-07-27T20:11:03.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47055",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle VM VirtualBox permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 695,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47056",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:17.664Z",
      "date_updated": "2026-07-23T15:43:07.204Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Data Integrator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28167
      },
      "nvd": {
        "published": "2026-07-21T22:17:11.370",
        "lastModified": "2026-07-27T20:10:54.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47056",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle says Data Integrator REST Service accepts an unauthenticated HTTP path to takeover but does not publish the route or missing authentication check.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html was inspected; Oracle confirms the Data Integrator REST Service, HTTP reachability, versions, and CVSS conditions but publishes no REST route or missing authentication check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 666,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47057",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:18.014Z",
      "date_updated": "2026-07-23T16:06:51.646Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Java SE (component: Scripting).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00463,
        "percentile": 0.37812
      },
      "nvd": {
        "published": "2026-07-21T22:17:11.483",
        "lastModified": "2026-08-03T18:52:45.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47057",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation lets attacker-controlled work or allocation grow without an effective per-request bound or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 961,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-47058",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:18.357Z",
      "date_updated": "2026-08-01T03:56:47.473Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Java SE (component: Scripting).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.2989
      },
      "nvd": {
        "published": "2026-07-21T22:17:11.600",
        "lastModified": "2026-08-03T18:52:14.967",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47058",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a Scripting-component unsafe-deserialization class reachable through supplied API data, while the CPU does not publish the serialized type or behavior path.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1096,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-47059",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:18.688Z",
      "date_updated": "2026-07-23T17:06:42.111Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM for JDK"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM Enterprise Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00306,
        "percentile": 0.22893
      },
      "nvd": {
        "published": "2026-07-21T22:17:11.727",
        "lastModified": "2026-08-03T18:51:30.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47059",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle Java SE but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1285,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-47060",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:19.030Z",
      "date_updated": "2026-07-23T17:06:32.773Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JDBC component of Oracle Database Server.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Database Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12246
      },
      "nvd": {
        "published": "2026-07-21T22:17:11.850",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47060",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Database Server permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 617,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-47061",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:19.371Z",
      "date_updated": "2026-07-23T17:06:24.881Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JDBC component of Oracle Database Server.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Database Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04727
      },
      "nvd": {
        "published": "2026-07-21T22:17:11.960",
        "lastModified": "2026-07-23T18:30:55.460",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47061",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "An adjacent unauthenticated actor can obtain JDBC data after user interaction, but Oracle does not publish the failing authorization boundary.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 781,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-47062",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:19.737Z",
      "date_updated": "2026-07-23T17:06:15.364Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01297
      },
      "nvd": {
        "published": "2026-07-21T22:17:12.077",
        "lastModified": "2026-07-27T20:10:38.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47062",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports that a local low-privileged user can crash VirtualBox but does not disclose the input or engineering failure.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 588,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47063",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:20.088Z",
      "date_updated": "2026-07-23T17:06:07.880Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM for JDK"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM Enterprise Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17148
      },
      "nvd": {
        "published": "2026-07-21T22:17:12.190",
        "lastModified": "2026-08-03T18:50:40.373",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47063",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Java libraries permit unauthenticated network input to modify protected data, but Oracle does not publish the missing access-control decision.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1295,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-47064",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T15:55:10.319Z",
      "date_published": "2026-07-21T21:33:20.524Z",
      "date_updated": "2026-07-23T17:05:56.269Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18277
      },
      "nvd": {
        "published": "2026-07-21T22:17:12.383",
        "lastModified": "2026-07-27T14:52:01.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47064",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Oracle record reports an optimizer-triggered database denial of service but gives no failing bound, state rule, or memory condition.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 678,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-47078",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T17:28:10.319Z",
      "date_published": "2026-07-27T15:03:50.929Z",
      "date_updated": "2026-07-28T09:53:55.522Z",
      "publisher": "EEF",
      "title": "Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04831
      },
      "nvd": {
        "published": "2026-07-27T16:17:07.643",
        "lastModified": "2026-07-30T17:01:07.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47078",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ZIP depth check considers only the final path depth, so a path can escape the extraction root before later components raise the counter.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-rf72-wp7h-jg3x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-47078.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-47078",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/8a933c9c7835b06776d31d17b79b7336627d887a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 906,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-47081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-16T18:30:39.011Z",
      "publisher": "mitre",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.",
      "affected": {
        "vendors": [
          "cyrusimap"
        ],
        "products": [
          {
            "vendor": "cyrusimap",
            "product": "Cyrus IMAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05952
      },
      "nvd": {
        "published": "2026-07-16T19:16:48.573",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47081",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation authorizes the caller generally but does not bind the requested object to that caller's tenant or ownership scope.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cyrusimap.org/imap/download/release-notes/index.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-16T18:49:27.734Z",
      "publisher": "mitre",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.",
      "affected": {
        "vendors": [
          "cyrusimap"
        ],
        "products": [
          {
            "vendor": "cyrusimap",
            "product": "Cyrus IMAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09585
      },
      "nvd": {
        "published": "2026-07-16T19:16:48.713",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47082",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cyrus IMAP fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cyrusimap.org/imap/download/release-notes/index.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 383,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47083",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-16T18:51:53.806Z",
      "publisher": "mitre",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.",
      "affected": {
        "vendors": [
          "cyrusimap"
        ],
        "products": [
          {
            "vendor": "cyrusimap",
            "product": "Cyrus IMAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-204",
          "name": "Observable Response Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.0929
      },
      "nvd": {
        "published": "2026-07-16T19:16:48.850",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47083",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ESEARCH response varies with another account's folders and matching messages, exposing names and content predicates as a cross-user oracle.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-204"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cyrusimap.org/imap/download/release-notes/index.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47084",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-16T18:53:38.575Z",
      "publisher": "mitre",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.",
      "affected": {
        "vendors": [
          "cyrusimap"
        ],
        "products": [
          {
            "vendor": "cyrusimap",
            "product": "Cyrus IMAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11864
      },
      "nvd": {
        "published": "2026-07-16T19:16:48.987",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47084",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cyrus IMAP exposes the admin-only LOCALDELETE command to non-admin users without enforcing mailbox ACLs.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cyrusimap.org/imap/download/release-notes/index.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-16T18:54:53.528Z",
      "publisher": "mitre",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.",
      "affected": {
        "vendors": [
          "cyrusimap"
        ],
        "products": [
          {
            "vendor": "cyrusimap",
            "product": "Cyrus IMAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-340",
          "name": "Generation of Predictable Numbers or Identifiers",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09925
      },
      "nvd": {
        "published": "2026-07-16T19:16:49.120",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47085",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "When a mailbox lacks mboxkey, Cyrus IMAP derives URLAUTH HMAC tokens from a predictable key that an attacker can reproduce.",
        "basis": [
          "CNA",
          "CWE-340"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cyrusimap.org/imap/download/release-notes/index.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47086",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-16T18:47:07.040Z",
      "publisher": "mitre",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.",
      "affected": {
        "vendors": [
          "cyrusimap"
        ],
        "products": [
          {
            "vendor": "cyrusimap",
            "product": "Cyrus IMAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07657
      },
      "nvd": {
        "published": "2026-07-16T19:16:49.253",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47086",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GENURLAUTH issues a mailbox token without verifying that the authenticated caller has read access to that mailbox.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cyrusimap.org/imap/download/release-notes/index.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47087",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-16T19:00:30.184Z",
      "publisher": "mitre",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.",
      "affected": {
        "vendors": [
          "cyrusimap"
        ],
        "products": [
          {
            "vendor": "cyrusimap",
            "product": "Cyrus IMAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-672",
          "name": "Operation on a Resource after Expiration or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00192,
        "percentile": 0.09108
      },
      "nvd": {
        "published": "2026-07-16T19:16:49.383",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47087",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cyrus IMAP continues accepting a URLAUTH URL after the authorizer's underlying access has been revoked.",
        "basis": [
          "CNA",
          "CWE-672"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cyrusimap.org/imap/download/release-notes/index.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47088",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-16T19:01:31.618Z",
      "publisher": "mitre",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.",
      "affected": {
        "vendors": [
          "cyrusimap"
        ],
        "products": [
          {
            "vendor": "cyrusimap",
            "product": "Cyrus IMAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07519
      },
      "nvd": {
        "published": "2026-07-16T19:16:49.513",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47088",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A trailing backslash in a nested MIME comment advances Cyrus IMAP parsing beyond the message buffer and returns adjacent heap bytes to the authenticated user.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cyrusimap.org/imap/download/release-notes/index.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47089",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T00:00:00.000Z",
      "date_published": "2026-07-16T00:00:00.000Z",
      "date_updated": "2026-07-16T19:01:51.550Z",
      "publisher": "mitre",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.",
      "affected": {
        "vendors": [
          "cyrusimap"
        ],
        "products": [
          {
            "vendor": "cyrusimap",
            "product": "Cyrus IMAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07498
      },
      "nvd": {
        "published": "2026-07-16T19:16:49.647",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47089",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The IMAP LISTRIGHTS operation is available to any authenticated user instead of being limited to administrators of the named mailbox.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cyrusimap.org/imap/download/release-notes/index.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html",
          "host": "www.cyrusimap.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 348,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47121",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T19:50:18.694Z",
      "date_published": "2026-07-21T13:53:05.030Z",
      "date_updated": "2026-07-22T14:30:47.083Z",
      "publisher": "GitHub_M",
      "title": "Sparkle: Binary delta apply intermediate-symlink traversal in malicious .delta",
      "affected": {
        "vendors": [
          "sparkle-project"
        ],
        "products": [
          {
            "vendor": "sparkle-project",
            "product": "Sparkle"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13772
      },
      "nvd": {
        "published": "2026-07-21T14:16:34.387",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47121",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The delta extractor rejects only an immediate symlink parent, so an earlier archive symlink can redirect a later write outside the staging tree.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sparkle-project/Sparkle/security/advisories/GHSA-hg88-v3cw-3qrh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/sparkle-project/Sparkle/commit/fe7b718d0736f3e139e374e26fbca96f29e13bf0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1151,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47122",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T19:50:18.694Z",
      "date_published": "2026-07-21T13:57:59.824Z",
      "date_updated": "2026-07-21T14:55:16.991Z",
      "publisher": "GitHub_M",
      "title": "Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection",
      "affected": {
        "vendors": [
          "sparkle-project"
        ],
        "products": [
          {
            "vendor": "sparkle-project",
            "product": "Sparkle"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00078,
        "percentile": 0.00149
      },
      "nvd": {
        "published": "2026-07-21T15:16:35.327",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47122",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Sparkle stops validating new Mach-service clients after installation stage one, so later local connections are accepted without a team-ID or code-signing check.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-441"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sparkle-project/Sparkle/security/advisories/GHSA-g3hp-f6mg-559v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 484,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47128",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T19:50:18.695Z",
      "date_published": "2026-07-20T21:46:32.692Z",
      "date_updated": "2026-07-21T12:56:44.319Z",
      "publisher": "GitHub_M",
      "title": "nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`",
      "affected": {
        "vendors": [
          "always-further"
        ],
        "products": [
          {
            "vendor": "always-further",
            "product": "nono"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00089,
        "percentile": 0.00498
      },
      "nvd": {
        "published": "2026-07-20T22:17:14.847",
        "lastModified": "2026-07-23T18:14:09.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47128",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nolabs-ai/nono/security/advisories/GHSA-27vp-2mmc-vmh3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47129",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T19:50:18.695Z",
      "date_published": "2026-07-20T20:34:55.578Z",
      "date_updated": "2026-07-21T14:56:15.739Z",
      "publisher": "GitHub_M",
      "title": "NextCRM has Broken Access Control in Server Actions that allows any authenticated user to deactivate/activate arbitrary accounts",
      "affected": {
        "vendors": [
          "pdovhomilja"
        ],
        "products": [
          {
            "vendor": "pdovhomilja",
            "product": "nextcrm-app"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.12947
      },
      "nvd": {
        "published": "2026-07-20T21:16:47.777",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47129",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "activateUser and deactivateUser omit the required administrator-role check and accept any authenticated member.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pdovhomilja/nextcrm-app/security/advisories/GHSA-gm7p-f88p-vhfr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pdovhomilja/nextcrm-app/releases/tag/v0.12.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47130",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T19:50:18.695Z",
      "date_published": "2026-07-20T20:49:38.988Z",
      "date_updated": "2026-07-21T16:33:28.425Z",
      "publisher": "GitHub_M",
      "title": "NextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Tenant CRM Data Tampering",
      "affected": {
        "vendors": [
          "pdovhomilja"
        ],
        "products": [
          {
            "vendor": "pdovhomilja",
            "product": "nextcrm-app"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05824
      },
      "nvd": {
        "published": "2026-07-20T21:16:47.917",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47130",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Contact and target update endpoints do not verify that the requested resource belongs to the caller or tenant.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pdovhomilja/nextcrm-app/security/advisories/GHSA-mg5f-m89f-4gmc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47133",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T19:50:18.695Z",
      "date_published": "2026-07-20T21:12:26.245Z",
      "date_updated": "2026-07-21T14:09:08.557Z",
      "publisher": "GitHub_M",
      "title": "ClearanceKit's signed policy tables lack monotonic counter, allowing replay of older legitimately-signed snapshots",
      "affected": {
        "vendors": [
          "craigjbass"
        ],
        "products": [
          {
            "vendor": "craigjbass",
            "product": "clearancekit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01269
      },
      "nvd": {
        "published": "2026-07-20T22:17:14.997",
        "lastModified": "2026-07-23T18:14:32.283",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47133",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A signed policy snapshot lacks freshness or monotonic-state binding and can be replayed after policy has changed.",
        "basis": [
          "CNA",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craigjbass/clearancekit/security/advisories/GHSA-9hx3-5wp9-2qqg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 837,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47134",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T19:50:18.695Z",
      "date_published": "2026-07-20T21:17:22.539Z",
      "date_updated": "2026-07-21T14:56:09.708Z",
      "publisher": "GitHub_M",
      "title": "ClearanceKit: Policy signing key in System Keychain has permissive ACL allowing any local-root process to forge signed policy",
      "affected": {
        "vendors": [
          "craigjbass"
        ],
        "products": [
          {
            "vendor": "craigjbass",
            "product": "clearancekit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01269
      },
      "nvd": {
        "published": "2026-07-20T22:17:15.133",
        "lastModified": "2026-07-23T18:04:31.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47134",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ECDSA policy-signing key is persisted without the intended System Keychain ACL, so any root process can use it to forge policy signatures.",
        "basis": [
          "CNA record",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craigjbass/clearancekit/security/advisories/GHSA-w254-hxm5-3hgh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1119,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T19:50:18.696Z",
      "date_published": "2026-07-21T20:10:44.476Z",
      "date_updated": "2026-07-22T13:42:55.326Z",
      "publisher": "GitHub_M",
      "title": "Capstone has a NULL Pointer Dereference with 3DNow! opcodes",
      "affected": {
        "vendors": [
          "capstone-engine"
        ],
        "products": [
          {
            "vendor": "capstone-engine",
            "product": "capstone"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00398,
        "percentile": 0.32585
      },
      "nvd": {
        "published": "2026-07-21T21:16:50.270",
        "lastModified": "2026-07-30T15:16:57.420",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47143",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "capstone dereferences a null pointer instead of rejecting the invalid object state.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/capstone-engine/capstone/security/advisories/GHSA-289w-cm54-fgrm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/capstone-engine/capstone/pull/2924",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/capstone-engine/capstone/commit/a0201371719b5aaa91d318ab2898843718f92d1f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/capstone-engine/capstone/commit/fab595205fee206f5c21be6ed8ad2eaf9225f1c7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 462,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T19:50:18.696Z",
      "date_published": "2026-07-20T21:49:09.058Z",
      "date_updated": "2026-07-22T14:18:13.390Z",
      "publisher": "GitHub_M",
      "title": "Shamefile has an arbitrary file read via shamefile.yaml in shame next",
      "affected": {
        "vendors": [
          "BKDDFS"
        ],
        "products": [
          {
            "vendor": "BKDDFS",
            "product": "shamefile"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.0432
      },
      "nvd": {
        "published": "2026-07-20T22:17:15.263",
        "lastModified": "2026-07-23T15:54:18.643",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47144",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "shame next resolves a path from shamefile.yaml outside the repository and reads the selected file one line at a time.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/BKDDFS/shamefile/security/advisories/GHSA-x6p3-76f2-xxvh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/BKDDFS/shamefile/pull/80",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/BKDDFS/shamefile/commit/77b0aeea318503582818c708518c601fedc43557",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/BKDDFS/shamefile/releases/tag/v0.1.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pypa/advisory-database/tree/main/vulns/shamefile/PYSEC-2026-3065.yaml",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 553,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T21:25:34.496Z",
      "date_published": "2026-07-15T15:01:51.955Z",
      "date_updated": "2026-07-15T18:04:27.279Z",
      "publisher": "GitHub_M",
      "title": "Vaultwarden: CSRF in SSO Authorization Flow",
      "affected": {
        "vendors": [
          "dani-garcia"
        ],
        "products": [
          {
            "vendor": "dani-garcia",
            "product": "vaultwarden"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05648
      },
      "nvd": {
        "published": "2026-07-15T16:16:46.200",
        "lastModified": "2026-07-15T19:17:17.790",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47158",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Vaultwarden accepts OAuth state that is not bound to the initiating browser session, accepts attacker-controlled PKCE values, and retains failed SSO records for later token redemption.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-pfp2-jhgq-6hg5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dani-garcia/vaultwarden/pull/7163",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dani-garcia/vaultwarden/commit/d297e274a35dccd0f5d935e9d5934e0f7e9c0a87",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.36.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 484,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47159",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T21:25:34.496Z",
      "date_published": "2026-07-15T15:02:46.349Z",
      "date_updated": "2026-07-15T15:34:11.312Z",
      "publisher": "GitHub_M",
      "title": "Vaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token Exposure",
      "affected": {
        "vendors": [
          "dani-garcia"
        ],
        "products": [
          {
            "vendor": "dani-garcia",
            "product": "vaultwarden"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29739
      },
      "nvd": {
        "published": "2026-07-15T16:16:46.353",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47159",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SSO discovery returns organization identifiers for arbitrary emails and issues a pre-validation token using only the discovered identifier.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-hxqh-ff5p-wfr3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dani-garcia/vaultwarden/pull/7163",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dani-garcia/vaultwarden/commit/d297e274a35dccd0f5d935e9d5934e0f7e9c0a87",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.36.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 454,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47160",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T21:25:34.496Z",
      "date_published": "2026-07-15T15:04:15.990Z",
      "date_updated": "2026-07-15T15:41:42.401Z",
      "publisher": "GitHub_M",
      "title": "Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex/Octal IP Bypass",
      "affected": {
        "vendors": [
          "dani-garcia"
        ],
        "products": [
          {
            "vendor": "dani-garcia",
            "product": "vaultwarden"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1389",
          "name": "Incorrect Parsing of Numbers with Different Radices",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14089
      },
      "nvd": {
        "published": "2026-07-15T16:16:46.490",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47160",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Vaultwarden's icon fetcher parses decimal, hexadecimal, and octal IP forms without normalizing them before address blocking, allowing requests to internal destinations.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918",
          "CWE-1389"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-72vh-x5jq-m82g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dani-garcia/vaultwarden/pull/7162",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dani-garcia/vaultwarden/commit/a354e57659d26149fde0d91b76f83fce94e8f277",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.36.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47164",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T21:25:34.496Z",
      "date_published": "2026-07-15T15:03:22.800Z",
      "date_updated": "2026-07-15T15:41:17.392Z",
      "publisher": "GitHub_M",
      "title": "Vaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Attacker-Controlled IdP Identity",
      "affected": {
        "vendors": [
          "dani-garcia"
        ],
        "products": [
          {
            "vendor": "dani-garcia",
            "product": "vaultwarden"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.19019
      },
      "nvd": {
        "published": "2026-07-15T16:16:46.630",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47164",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The vaultwarden path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-6x5c-84vm-5j56",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dani-garcia/vaultwarden/pull/7163",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dani-garcia/vaultwarden/commit/d297e274a35dccd0f5d935e9d5934e0f7e9c0a87",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.36.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 428,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47178",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T21:25:34.498Z",
      "date_published": "2026-07-21T21:09:10.999Z",
      "date_updated": "2026-07-22T15:30:57.634Z",
      "publisher": "GitHub_M",
      "title": "libheif has Heap Out Of Bounds Write in unci subsystem",
      "affected": {
        "vendors": [
          "strukturag"
        ],
        "products": [
          {
            "vendor": "strukturag",
            "product": "libheif"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 1.7000000000000002,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09895
      },
      "nvd": {
        "published": "2026-07-21T22:17:12.503",
        "lastModified": "2026-07-27T15:22:40.207",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47178",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A crafted input permits a write beyond an allocated heap buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/strukturag/libheif/security/advisories/GHSA-5x55-x5pf-9c6g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47180",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T22:07:37.434Z",
      "date_published": "2026-07-17T18:21:25.199Z",
      "date_updated": "2026-07-17T19:21:29.700Z",
      "publisher": "GitHub_M",
      "title": "Zeroconf: Unbounded recursion in DNS compression-pointer decoder allows LAN-local denial of service",
      "affected": {
        "vendors": [
          "python-zeroconf"
        ],
        "products": [
          {
            "vendor": "python-zeroconf",
            "product": "python-zeroconf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13884
      },
      "nvd": {
        "published": "2026-07-17T19:17:15.153",
        "lastModified": "2026-07-23T16:13:02.287",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47180",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The python-zeroconf parser follows attacker-controlled recursion without an effective depth or cycle limit.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-9pgc-3ccv-5297",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/pull/1719",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/commit/f9e23592137f30fdf7ef710dba065da31c79b1cf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/releases/tag/0.149.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T22:07:37.434Z",
      "date_published": "2026-07-17T18:22:59.803Z",
      "date_updated": "2026-07-17T23:15:36.656Z",
      "publisher": "GitHub_M",
      "title": "Zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion",
      "affected": {
        "vendors": [
          "python-zeroconf"
        ],
        "products": [
          {
            "vendor": "python-zeroconf",
            "product": "python-zeroconf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15372
      },
      "nvd": {
        "published": "2026-07-17T19:17:15.303",
        "lastModified": "2026-07-23T16:13:02.287",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47183",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Zeroconf retains attacker-induced exception keys in an unbounded deduplication dictionary.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-phvx-9mgw-67r5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/issues/1714",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/pull/1717",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/commit/95561e28b24922358f1991e38e3a86d70d72dcec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/releases/tag/0.149.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T22:07:37.434Z",
      "date_published": "2026-07-17T18:25:07.387Z",
      "date_updated": "2026-07-21T01:50:36.488Z",
      "publisher": "GitHub_M",
      "title": "Zeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via multicast flood",
      "affected": {
        "vendors": [
          "python-zeroconf"
        ],
        "products": [
          {
            "vendor": "python-zeroconf",
            "product": "python-zeroconf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15372
      },
      "nvd": {
        "published": "2026-07-17T19:17:15.440",
        "lastModified": "2026-07-23T16:13:02.287",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47184",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 0.149.7, DNSCache._async_add inserted every response record into cache, _expirations, _expire_heap, and service_cache without a cap, allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to multicast valid mDNS responses with unique names and cause memory exhaustion, slower cache lookups, slower async_expire passes, and broken discovery, registration, and ServiceBrowser callbacks.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-rfg2-pjw2-56x2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/issues/1715",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/pull/1718",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/commit/0ad3f37b5b852b8f614d322283d148efb2cef6e4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/releases/tag/0.149.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47198",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T22:07:37.436Z",
      "date_published": "2026-07-20T20:18:21.275Z",
      "date_updated": "2026-07-22T14:18:44.682Z",
      "publisher": "GitHub_M",
      "title": "Paymenter: URL parameter injection bypasses paid plan limits at checkout",
      "affected": {
        "vendors": [
          "Paymenter"
        ],
        "products": [
          {
            "vendor": "Paymenter",
            "product": "Paymenter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20935
      },
      "nvd": {
        "published": "2026-07-20T21:16:48.043",
        "lastModified": "2026-07-23T15:54:18.643",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47198",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller can override URL-writable provisioning properties that control plan limits without the required authority.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Paymenter/Paymenter/security/advisories/GHSA-5q4q-834j-g8g4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1225,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47199",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T22:07:37.436Z",
      "date_published": "2026-07-10T21:14:12.195Z",
      "date_updated": "2026-07-13T15:59:34.730Z",
      "publisher": "GitHub_M",
      "title": "Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE",
      "affected": {
        "vendors": [
          "frappe"
        ],
        "products": [
          {
            "vendor": "frappe",
            "product": "frappe"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00401,
        "percentile": 0.32848
      },
      "nvd": {
        "published": "2026-07-10T22:16:41.870",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47199",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component lets attacker-controlled text cross into an executable or interpreted grammar without the required separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frappe/frappe/security/advisories/GHSA-wx8j-cw4r-vrhv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/39345",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/39346",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/628e103f7ffe307447d9fc9e2c572cbddedfa3b5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/91d3ded038d1c901b73f4a2293e134d691c1662d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/releases/tag/v15.108.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/releases/tag/v16.18.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47212",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T22:25:21.258Z",
      "date_published": "2026-07-14T19:00:30.703Z",
      "date_updated": "2026-07-15T14:04:41.492Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event Injection",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "twilio-notifier"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14981
      },
      "nvd": {
        "published": "2026-07-14T20:17:01.187",
        "lastModified": "2026-07-15T15:03:11.553",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47212",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Symfony accepts a Twilio webhook when signature verification is absent or ineffective, allowing an unauthenticated caller to invoke the trusted webhook path.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-55rj-x2vc-4whq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/8545fb2af6c07dfb5ef0fc8d9bccf86db2c94356",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 392,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-47219",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T22:25:21.258Z",
      "date_published": "2026-07-28T22:14:31.279Z",
      "date_updated": "2026-07-29T15:24:01.203Z",
      "publisher": "GitHub_M",
      "title": "find-my-way is Vulnerable to DDoS with HTTP2",
      "affected": {
        "vendors": [
          "delvedor"
        ],
        "products": [
          {
            "vendor": "delvedor",
            "product": "find-my-way"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00461,
        "percentile": 0.37644
      },
      "nvd": {
        "published": "2026-07-28T23:17:03.763",
        "lastModified": "2026-07-30T20:02:44.977",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47219",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "find-my-way indexes a normal JavaScript object with an HTTP/2 method and treats inherited properties such as constructor as router nodes, causing an uncaught exception.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/delvedor/find-my-way/security/advisories/GHSA-c96f-x56v-gq3h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 667,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47237",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T22:54:18.271Z",
      "date_published": "2026-07-21T20:49:18.293Z",
      "date_updated": "2026-07-22T15:08:36.303Z",
      "publisher": "GitHub_M",
      "title": "Kubeflow Community Distribution: Overly Permissive Istio Permissions Allows Kubeflow Authorization Token Stealing",
      "affected": {
        "vendors": [
          "kubeflow"
        ],
        "products": [
          {
            "vendor": "kubeflow",
            "product": "community-distribution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24298
      },
      "nvd": {
        "published": "2026-07-21T21:16:50.403",
        "lastModified": "2026-07-23T18:22:56.103",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47237",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "community-distribution lets a lower-privileged caller exercise a higher-privileged operation because privilege assignment or enforcement is incomplete.",
        "basis": [
          "CNA",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kubeflow/community-distribution/security/advisories/GHSA-v824-8gxh-pgjw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/kubeflow/community-distribution/pull/3043",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kubeflow/community-distribution/commit/31b2411dda319bfeae8686ecdf3a39436ec32ce2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 708,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47247",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T22:54:18.272Z",
      "date_published": "2026-07-21T21:16:59.853Z",
      "date_updated": "2026-07-22T14:29:24.487Z",
      "publisher": "GitHub_M",
      "title": "libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation",
      "affected": {
        "vendors": [
          "strukturag"
        ],
        "products": [
          {
            "vendor": "strukturag",
            "product": "libheif"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-226",
          "name": "Sensitive Information in Resource Not Removed Before Reuse",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-682",
          "name": "Incorrect Calculation",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00448,
        "percentile": 0.36759
      },
      "nvd": {
        "published": "2026-07-21T22:17:12.643",
        "lastModified": "2026-07-27T15:20:54.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47247",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Grid decoding leaves pixel-plane storage uninitialized and later emits those heap bytes as output pixels.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-226",
          "CWE-682",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/strukturag/libheif/security/advisories/GHSA-2vh6-whr3-cmq3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T22:54:18.273Z",
      "date_published": "2026-07-21T21:18:56.870Z",
      "date_updated": "2026-07-22T13:48:12.355Z",
      "publisher": "GitHub_M",
      "title": "libheif has an incomplete fix for CVE-2026-3949: integer overflow bypass in vvdec_push_data2",
      "affected": {
        "vendors": [
          "strukturag"
        ],
        "products": [
          {
            "vendor": "strukturag",
            "product": "libheif"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07718
      },
      "nvd": {
        "published": "2026-07-21T22:17:12.800",
        "lastModified": "2026-07-27T15:19:27.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47251",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An integer overflow in libheif's size check lets a crafted VVC track bypass the check and trigger the prior heap out-of-bounds read.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/strukturag/libheif/security/advisories/GHSA-p6q9-fhf2-vj9v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/strukturag/libheif/issues/1712",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "exploit",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47254",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T22:54:18.273Z",
      "date_published": "2026-07-21T21:21:41.491Z",
      "date_updated": "2026-07-22T18:24:43.175Z",
      "publisher": "GitHub_M",
      "title": "libheif Has Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OOB Chunk Vector Access",
      "affected": {
        "vendors": [
          "strukturag"
        ],
        "products": [
          {
            "vendor": "strukturag",
            "product": "libheif"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08705
      },
      "nvd": {
        "published": "2026-07-21T22:17:12.957",
        "lastModified": "2026-07-27T15:16:14.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47254",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A malformed stco and stsz relationship stores m_chunks.size as an index and later reads m_chunks at that out-of-range index.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/strukturag/libheif/security/advisories/GHSA-wqjg-4x9g-6cvg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47255",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:03:37.228Z",
      "date_published": "2026-07-20T21:56:40.252Z",
      "date_updated": "2026-07-21T14:06:27.159Z",
      "publisher": "GitHub_M",
      "title": "AgenticMail API/storage and outbound relay hardening",
      "affected": {
        "vendors": [
          "agenticmail"
        ],
        "products": [
          {
            "vendor": "agenticmail",
            "product": "@agenticmail/api"
          },
          {
            "vendor": "agenticmail",
            "product": "@agenticmail/core"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-319",
          "name": "Cleartext Transmission of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07549
      },
      "nvd": {
        "published": "2026-07-20T22:17:15.403",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47255",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The advisory aggregates unrelated ownership, SQL, mail-header, secret-handling, and TLS weaknesses without identifying one demonstrated primary path.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-89",
          "CWE-284",
          "CWE-319",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/agenticmail/agenticmail/security/advisories/GHSA-wjjv-3mj2-39hf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/agenticmail/agenticmail/commit/1408de543fa3577d8c2d4fdb289c75fe6faafac7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/agenticmail/agenticmail/commit/234b811e426a0743170f3b10bc43419d64330155",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/agenticmail/agenticmail/commit/6c70c8254c906f823392d7f5ccee88a5481e7731",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/agenticmail/agenticmail/commit/8cb053f2307dd77b7736ffa0d7df04b0ccc3272d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/agenticmail/agenticmail/blob/7b9b05d973676e9f3d097c08b8e649f59bfc15d0/CHANGELOG.md?plain=1#L1842",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/agenticmail/agenticmail/blob/7b9b05d973676e9f3d097c08b8e649f59bfc15d0/packages/core/src/mail/sender.ts#L33",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 720,
        "referenceCount": 7,
        "cweCount": 5,
        "cnaCweCount": 5,
        "adpCweCount": 0,
        "nvdCweCount": 5,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47262",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:03:37.229Z",
      "date_published": "2026-07-01T17:48:43.205Z",
      "date_updated": "2026-07-01T18:34:06.714Z",
      "publisher": "GitHub_M",
      "title": "containerd image-triggered runtime DoS via unbounded group parsing",
      "affected": {
        "vendors": [
          "containerd"
        ],
        "products": [
          {
            "vendor": "containerd",
            "product": "containerd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18244
      },
      "nvd": {
        "published": "2026-07-01T19:16:52.097",
        "lastModified": "2026-07-02T19:40:45.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47262",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A crafted container image causes unbounded memory consumption during container creation, but the responsible allocation path is not public.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-47275",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:03:37.230Z",
      "date_published": "2026-07-20T16:43:03.704Z",
      "date_updated": "2026-07-20T18:56:28.995Z",
      "publisher": "GitHub_M",
      "title": "nanomq NULL Pointer Dereference in MQTTv5 Client CONNECT Decoder Leading to Remote DoS",
      "affected": {
        "vendors": [
          "nanomq"
        ],
        "products": [
          {
            "vendor": "nanomq",
            "product": "nanomq"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06512
      },
      "nvd": {
        "published": "2026-07-20T17:17:10.120",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47275",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In nanomq, an error or lifecycle path dereferences a pointer that can still be null.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nanomq/nanomq/security/advisories/GHSA-52qr-3v49-wmx6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 948,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47276",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:03:37.230Z",
      "date_published": "2026-07-20T16:44:44.300Z",
      "date_updated": "2026-07-20T17:41:06.753Z",
      "publisher": "GitHub_M",
      "title": "NULL Pointer Dereference in REST API properties_parse via Malformed user_properties",
      "affected": {
        "vendors": [
          "nanomq"
        ],
        "products": [
          {
            "vendor": "nanomq",
            "product": "nanomq"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14473
      },
      "nvd": {
        "published": "2026-07-20T17:17:10.260",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47276",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "nanomq continues through a path where a required object pointer is null and dereferences that pointer instead of rejecting the input or state.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nanomq/nanomq/security/advisories/GHSA-qq2v-xvxg-3hvf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47282",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:53:33.896Z",
      "date_published": "2026-07-14T17:04:39.052Z",
      "date_updated": "2026-08-03T22:53:03.193Z",
      "publisher": "microsoft",
      "title": "GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Visual Studio Code"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00612,
        "percentile": 0.45905
      },
      "nvd": {
        "published": "2026-07-14T17:16:49.383",
        "lastModified": "2026-07-16T17:21:30.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47282",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "GitHub Copilot or Visual Studio Code exposes protected credentials to a network attacker, while Microsoft does not disclose the credential, storage, or return path.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47282",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47290",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:53:33.896Z",
      "date_published": "2026-07-14T17:08:28.167Z",
      "date_updated": "2026-08-03T22:56:47.700Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00404,
        "percentile": 0.33181
      },
      "nvd": {
        "published": "2026-07-14T18:17:17.760",
        "lastModified": "2026-07-16T15:11:11.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47290",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise continues to access an object after its storage has been released, allowing invalid heap use and possible corruption.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47290",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 91,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-47295",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:53:33.897Z",
      "date_published": "2026-07-14T17:08:01.082Z",
      "date_updated": "2026-08-03T22:56:20.740Z",
      "publisher": "microsoft",
      "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2016 Service Pack 3 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2019 (CU 32)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2019 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2022 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2022 for x64-based Systems (CU 25)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 (CU 6)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 for x64-based Systems (GDR)"
          }
        ],
        "affectedBlockCount": 10,
        "versionEntryCount": 10,
        "versionRangeCount": 10,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00922,
        "percentile": 0.56866
      },
      "nvd": {
        "published": "2026-07-14T18:17:17.883",
        "lastModified": "2026-07-22T16:50:46.420",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47295",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SQL Server incorporates authorized remote input into an SQL command without correctly neutralizing SQL syntax.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47295",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 166,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 10,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-47296",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:53:33.897Z",
      "date_published": "2026-07-14T17:04:15.041Z",
      "date_updated": "2026-08-03T22:52:39.702Z",
      "publisher": "microsoft",
      "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2016 Service Pack 3 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2019 (CU 32)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2019 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2022 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2022 for x64-based Systems (CU 25)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 (CU 6)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 for x64-based Systems (GDR)"
          }
        ],
        "affectedBlockCount": 10,
        "versionEntryCount": 10,
        "versionRangeCount": 10,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00497,
        "percentile": 0.39893
      },
      "nvd": {
        "published": "2026-07-14T17:16:49.507",
        "lastModified": "2026-08-04T00:16:43.190",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47296",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SQL Server permits authorized network input to alter the structure of an SQL command and cross a privilege boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47296",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 166,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 10,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-47300",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:53:33.897Z",
      "date_published": "2026-07-14T18:20:12.225Z",
      "date_updated": "2026-08-03T22:52:50.586Z",
      "publisher": "microsoft",
      "title": "ASP.NET Core Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-303",
          "name": "Incorrect Implementation of Authentication Algorithm",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00527,
        "percentile": 0.41683
      },
      "nvd": {
        "published": "2026-07-14T19:17:08.303",
        "lastModified": "2026-07-22T21:17:15.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47300",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ASP.NET Core implements an authentication algorithm incorrectly, but the public record does not identify the credential, comparison, or algorithm step that fails.",
        "basis": [
          "CNA",
          "CWE-303"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47300",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-47301",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:53:33.897Z",
      "date_published": "2026-07-14T18:45:32.167Z",
      "date_updated": "2026-08-03T22:53:51.760Z",
      "publisher": "microsoft",
      "title": "Configuration Manager Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Configuration Manager"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Configuration Manager 2509"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Configuration Manager 2603"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00537,
        "percentile": 0.42242
      },
      "nvd": {
        "published": "2026-07-14T19:17:08.420",
        "lastModified": "2026-07-30T19:17:31.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47301",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47301",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-47302",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:53:33.897Z",
      "date_published": "2026-07-14T18:45:32.796Z",
      "date_updated": "2026-08-03T22:52:51.150Z",
      "publisher": "microsoft",
      "title": ".NET Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 12,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01029,
        "percentile": 0.60319
      },
      "nvd": {
        "published": "2026-07-14T19:17:08.540",
        "lastModified": "2026-07-24T13:40:00.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47302",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47302",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 12,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-47303",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:53:33.898Z",
      "date_published": "2026-07-14T18:45:33.438Z",
      "date_updated": "2026-08-03T22:52:51.774Z",
      "publisher": "microsoft",
      "title": "ASP.NET Core Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-90",
          "name": "Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-302",
          "name": "Authentication Bypass by Assumed-Immutable Data",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00736,
        "percentile": 0.5092
      },
      "nvd": {
        "published": "2026-07-14T19:17:08.707",
        "lastModified": "2026-07-22T21:17:15.777",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47303",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ASP.NET Core trusts assumed-immutable authentication data during an authorized network request, but the public record does not identify the field or state transition.",
        "basis": [
          "CNA",
          "CWE-90",
          "CWE-302",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47303",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-47304",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:53:33.898Z",
      "date_published": "2026-07-14T18:45:33.914Z",
      "date_updated": "2026-08-03T22:54:08.088Z",
      "publisher": "microsoft",
      "title": ".NET Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.5"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12073
      },
      "nvd": {
        "published": "2026-07-14T19:17:08.830",
        "lastModified": "2026-07-24T13:39:57.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47304",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The trust path accepts data without correctly verifying the cryptographic signature that should authenticate it.",
        "basis": [
          "CNA",
          "CWE-345",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47304",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 133,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-47305",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-18T23:53:33.898Z",
      "date_published": "2026-07-14T18:45:34.402Z",
      "date_updated": "2026-08-03T22:58:57.349Z",
      "publisher": "microsoft",
      "title": "Visual Studio Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26113
      },
      "nvd": {
        "published": "2026-07-14T19:17:08.970",
        "lastModified": "2026-07-16T15:27:58.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47305",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports a local Visual Studio protection-mechanism failure and code execution but does not disclose the protection, input, or failing check.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47305",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-47390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:22:45.729Z",
      "date_published": "2026-07-21T14:47:53.059Z",
      "date_updated": "2026-07-22T14:10:08.532Z",
      "publisher": "GitHub_M",
      "title": "PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          },
          {
            "vendor": "MervinPraison",
            "product": "praisonaiagents"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06183
      },
      "nvd": {
        "published": "2026-07-21T16:17:11.760",
        "lastModified": "2026-07-22T15:17:17.097",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47390",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PraisonAI follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5c6w-wwfq-7qqm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1684",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/b0d8f777528f3253a0cfb0a3ef65455da6ae32f6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1085,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:22:45.729Z",
      "date_published": "2026-07-21T15:21:22.916Z",
      "date_updated": "2026-07-23T14:27:07.049Z",
      "publisher": "GitHub_M",
      "title": "PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-95",
          "name": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0078,
        "percentile": 0.52401
      },
      "nvd": {
        "published": "2026-07-21T16:17:11.920",
        "lastModified": "2026-07-23T15:17:11.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47391",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unauthenticated A2A message can cause an LLM to pass attacker-controlled expression text to Python eval.",
        "basis": [
          "CNA",
          "CWE-95",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-vg22-4gmj-prxw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1793",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/e0fb8e7dd1ee6759c18ed07f436c21dbd9c20747",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 940,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:22:45.729Z",
      "date_published": "2026-07-21T15:27:16.557Z",
      "date_updated": "2026-07-21T16:39:40.246Z",
      "publisher": "GitHub_M",
      "title": "PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          },
          {
            "vendor": "MervinPraison",
            "product": "< 1.6.40"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00602,
        "percentile": 0.45418
      },
      "nvd": {
        "published": "2026-07-21T16:17:12.087",
        "lastModified": "2026-07-21T18:59:43.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47392",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Access to print.__self__ exposes Python builtins and import functionality, bypassing the expression sandbox.",
        "basis": [
          "CNA",
          "CWE-184",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4mr5-g6f9-cfrh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1684",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/b0d8f777528f3253a0cfb0a3ef65455da6ae32f6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 755,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47393",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:22:45.729Z",
      "date_published": "2026-07-21T15:39:28.459Z",
      "date_updated": "2026-07-22T14:34:05.072Z",
      "publisher": "GitHub_M",
      "title": "PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33157
      },
      "nvd": {
        "published": "2026-07-21T16:17:12.270",
        "lastModified": "2026-07-22T15:17:17.247",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47393",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The API server generator defaults authentication to disabled while producing a network-exposed service.",
        "basis": [
          "CNA record",
          "CWE-1188",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8444-4fhq-fxpq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1685",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/advisories/GHSA-6rmh-7xcm-cpxj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 808,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:22:45.729Z",
      "date_published": "2026-07-21T15:44:36.292Z",
      "date_updated": "2026-07-21T18:01:03.736Z",
      "publisher": "GitHub_M",
      "title": "PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00427,
        "percentile": 0.35177
      },
      "nvd": {
        "published": "2026-07-21T16:17:12.440",
        "lastModified": "2026-07-21T18:59:43.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47394",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PraisonAI accepts an attacker-controlled path that can resolve outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-200",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-9cr9-25q5-8prj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1684",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/b0d8f777528f3253a0cfb0a3ef65455da6ae32f6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1133,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:22:45.729Z",
      "date_published": "2026-07-21T15:52:52.682Z",
      "date_updated": "2026-07-21T17:15:13.196Z",
      "publisher": "GitHub_M",
      "title": "PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          },
          {
            "vendor": "MervinPraison",
            "product": "praisonaiagents"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02939
      },
      "nvd": {
        "published": "2026-07-21T16:17:12.600",
        "lastModified": "2026-07-21T18:59:43.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47395",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The CLI automatically dereferences attacker-influenced @url targets without blocking loopback, private, or metadata addresses.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5cxw-77wg-jrf3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1684",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/b0d8f777528f3253a0cfb0a3ef65455da6ae32f6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 908,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:22:45.729Z",
      "date_published": "2026-07-21T15:55:22.599Z",
      "date_updated": "2026-07-22T14:13:42.099Z",
      "publisher": "GitHub_M",
      "title": "PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27233
      },
      "nvd": {
        "published": "2026-07-21T16:17:12.760",
        "lastModified": "2026-07-22T15:17:17.393",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47396",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PraisonAI's token verifier fails open when CALL_SERVER_TOKEN is unset, leaving the network-bound agent-control routes unauthenticated.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-86qc-r5v2-v6x6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 939,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:22:45.729Z",
      "date_published": "2026-07-21T15:57:25.695Z",
      "date_updated": "2026-07-23T14:25:50.782Z",
      "publisher": "GitHub_M",
      "title": "PraisonAI has an Arbitrary File Write in Python API",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00381,
        "percentile": 0.30864
      },
      "nvd": {
        "published": "2026-07-21T17:17:08.670",
        "lastModified": "2026-07-23T15:17:12.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47397",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled path is used without confinement to the intended directory, allowing file access outside that namespace.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hvhp-v2gc-268q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1684",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/b0d8f777528f3253a0cfb0a3ef65455da6ae32f6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:22:45.730Z",
      "date_published": "2026-07-21T16:01:22.037Z",
      "date_updated": "2026-07-21T16:33:53.371Z",
      "publisher": "GitHub_M",
      "title": "PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25542
      },
      "nvd": {
        "published": "2026-07-21T17:17:08.803",
        "lastModified": "2026-07-21T18:59:43.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47398",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "agents_generator.py loads and executes YAML-selected local modules without the local-tools gate, path validation, or integrity verification.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-78r8-wwqv-r299",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1685",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 558,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:22:45.730Z",
      "date_published": "2026-07-21T16:15:09.882Z",
      "date_updated": "2026-07-22T14:36:30.296Z",
      "publisher": "GitHub_M",
      "title": "PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21234
      },
      "nvd": {
        "published": "2026-07-21T17:17:08.950",
        "lastModified": "2026-07-22T15:17:17.527",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47399",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The praisonai-platform handler trusts a caller-controlled object identifier without binding it to the caller's permitted objects.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6h6v-6m7w-7vxx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1686",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/24385d64876577620f749957bd4814f162f4ca47",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1154,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47405",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.525Z",
      "date_published": "2026-07-21T16:18:27.991Z",
      "date_updated": "2026-07-21T17:59:03.862Z",
      "publisher": "GitHub_M",
      "title": "PraisonAI Platform missing role checks let any workspace member become owner and take over workspace membership",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21208
      },
      "nvd": {
        "published": "2026-07-21T17:17:09.083",
        "lastModified": "2026-07-21T18:59:43.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47405",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Administrative routes require only the member minimum role, granting privileged actions to callers below the intended role.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-h37g-4h4p-9x97",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1686",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/24385d64876577620f749957bd4814f162f4ca47",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 990,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47406",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.525Z",
      "date_published": "2026-07-21T16:37:12.672Z",
      "date_updated": "2026-07-21T17:22:05.161Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace ownership check, cross-workspace issue linking + read + delete IDOR",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14025
      },
      "nvd": {
        "published": "2026-07-21T17:17:09.220",
        "lastModified": "2026-07-21T18:59:43.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47406",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The praisonai-platform request path accepts an attacker-selected object identifier without binding that object to the caller's tenant, owner, or permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4x6r-9v57-3gqw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1685",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 805,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47407",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.525Z",
      "date_published": "2026-07-21T16:42:33.533Z",
      "date_updated": "2026-07-22T14:16:34.674Z",
      "publisher": "GitHub_M",
      "title": "PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.1495
      },
      "nvd": {
        "published": "2026-07-21T17:17:09.363",
        "lastModified": "2026-07-22T15:17:17.657",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47407",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PraisonAI validates membership only against the workspace in the URL and then loads an inner resource by global identifier without comparing its workspace.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-639",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-h8q5-cp56-rr65",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1686",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/24385d64876577620f749957bd4814f162f4ca47",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1596,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47408",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.525Z",
      "date_published": "2026-07-21T16:49:49.131Z",
      "date_updated": "2026-07-23T14:25:16.518Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14026
      },
      "nvd": {
        "published": "2026-07-21T17:17:09.500",
        "lastModified": "2026-07-23T15:17:12.770",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47408",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PraisonAI checks membership in workspace_id but loads activity solely by issue_id, allowing a member of any workspace to read another workspace issue activity log.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-27p4-pjqv-whgj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1685",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 614,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.525Z",
      "date_published": "2026-07-21T16:53:18.207Z",
      "date_updated": "2026-07-21T18:28:11.328Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id}",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20683
      },
      "nvd": {
        "published": "2026-07-21T17:17:09.640",
        "lastModified": "2026-07-21T19:17:10.370",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47409",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The workspace-member deletion endpoint checks only that the caller is a member and omits caller-role, target-role, and last-owner checks.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-w388-2392-px73",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1686",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/24385d64876577620f749957bd4814f162f4ca47",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 553,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.525Z",
      "date_published": "2026-07-21T16:55:31.021Z",
      "date_updated": "2026-07-22T14:43:35.648Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: JWT signing key defaults to hardcoded \"dev-secret-change-me\", allowing token forgery for any user when PLATFORM_ENV is unset",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-321",
          "name": "Use of Hard-coded Cryptographic Key",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28731
      },
      "nvd": {
        "published": "2026-07-21T17:17:09.773",
        "lastModified": "2026-07-22T15:17:17.800",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47410",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "When two environment variables are omitted, PraisonAI defaults to development mode and a public fixed JWT key that lets an attacker mint arbitrary identities.",
        "basis": [
          "CNA",
          "CWE-321",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-3qg8-5g3r-79v5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1685",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 718,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47411",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.525Z",
      "date_published": "2026-07-21T17:02:48.081Z",
      "date_updated": "2026-07-21T17:52:25.520Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09435
      },
      "nvd": {
        "published": "2026-07-21T18:16:59.663",
        "lastModified": "2026-07-21T18:59:43.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47411",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A workspace member can update security-sensitive workspace settings because the mutation does not enforce the administrator privilege required for those fields.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-rcmc-q9rj-4wmq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 654,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47412",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.525Z",
      "date_published": "2026-07-21T17:04:47.332Z",
      "date_updated": "2026-07-22T18:27:12.639Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20683
      },
      "nvd": {
        "published": "2026-07-21T18:16:59.980",
        "lastModified": "2026-07-22T19:17:05.297",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47412",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The workspace deletion route authorizes any member although the cascading destructive action requires an owner-level decision.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-g8rr-7rj2-f627",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1686",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/24385d64876577620f749957bd4814f162f4ca47",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 653,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47413",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.525Z",
      "date_published": "2026-07-21T17:07:21.546Z",
      "date_updated": "2026-07-22T14:19:41.300Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.1116
      },
      "nvd": {
        "published": "2026-07-21T18:17:00.133",
        "lastModified": "2026-07-22T15:17:17.920",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47413",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The workspace member endpoint requires only ordinary membership and passes caller-selected user_id and role values to MemberService.add without an owner-level check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8g2p-pqm3-fcfh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 701,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47414",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.526Z",
      "date_published": "2026-07-21T17:11:36.632Z",
      "date_updated": "2026-07-23T14:24:40.577Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: Label endpoints accept any label_id and any issue_id without workspace ownership check, cross-workspace label edit/delete and issue-label-link IDOR",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12036
      },
      "nvd": {
        "published": "2026-07-21T18:17:00.283",
        "lastModified": "2026-07-23T15:17:13.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47414",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Label endpoints check membership in the URL workspace but never verify that the supplied label and issue IDs belong to that workspace.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5jx9-w35f-vp65",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1685",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47415",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.526Z",
      "date_published": "2026-07-21T17:13:08.109Z",
      "date_updated": "2026-07-21T18:07:41.322Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20222
      },
      "nvd": {
        "published": "2026-07-21T18:17:00.423",
        "lastModified": "2026-07-21T19:17:10.480",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47415",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The issue endpoints check membership in the URL workspace but fetch issue_id globally without constraining it to that workspace.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-xwq8-frcg-77q8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 603,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47416",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.526Z",
      "date_published": "2026-07-21T17:19:11.996Z",
      "date_updated": "2026-07-22T14:49:10.462Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id}",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.1116
      },
      "nvd": {
        "published": "2026-07-21T18:17:00.563",
        "lastModified": "2026-07-22T16:17:25.417",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47416",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The workspace-member route permits any member to assign any role because it never requires owner or administrator authority for MemberService.update_role.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-c2m8-4gcg-v22g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 757,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47417",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.526Z",
      "date_published": "2026-07-21T17:24:40.741Z",
      "date_updated": "2026-07-21T17:56:44.597Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11159
      },
      "nvd": {
        "published": "2026-07-21T18:17:00.707",
        "lastModified": "2026-07-21T18:59:43.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47417",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Comment endpoints verify membership in the URL workspace but never verify that the issue identifier belongs to that workspace.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-cp4f-5m9r-5jc2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 674,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.526Z",
      "date_published": "2026-07-21T17:26:45.841Z",
      "date_updated": "2026-07-22T18:27:07.254Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21132
      },
      "nvd": {
        "published": "2026-07-21T18:17:00.853",
        "lastModified": "2026-07-22T19:17:05.527",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47418",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Project endpoints check membership in the URL workspace but fetch project_id globally without constraining it to that workspace.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-943m-6wx2-rc2j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/pull/1685",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 759,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47419",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.526Z",
      "date_published": "2026-07-21T17:31:58.909Z",
      "date_updated": "2026-07-22T14:23:46.691Z",
      "publisher": "GitHub_M",
      "title": "praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "praisonai-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21841
      },
      "nvd": {
        "published": "2026-07-21T18:17:00.990",
        "lastModified": "2026-07-22T15:17:18.030",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47419",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Agent endpoints authorize membership in the URL's workspace but look up agent_id globally without constraining it to that workspace.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7p8g-6c6g-h9w7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 695,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.526Z",
      "date_published": "2026-07-10T21:09:58.177Z",
      "date_updated": "2026-07-14T14:35:18.141Z",
      "publisher": "GitHub_M",
      "title": "Frappe: Unrestricted API access to save_report",
      "affected": {
        "vendors": [
          "frappe"
        ],
        "products": [
          {
            "vendor": "frappe",
            "product": "frappe"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19981
      },
      "nvd": {
        "published": "2026-07-10T22:16:42.007",
        "lastModified": "2026-07-14T15:17:01.953",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47422",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "frappe fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frappe/frappe/security/advisories/GHSA-w8g7-j846-j248",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.526Z",
      "date_published": "2026-07-14T19:56:02.057Z",
      "date_updated": "2026-07-16T14:47:21.564Z",
      "publisher": "GitHub_M",
      "title": "DOMPurify XSS via `selectedcontent` re-clone",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18967
      },
      "nvd": {
        "published": "2026-07-14T20:17:02.143",
        "lastModified": "2026-07-21T19:50:48.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47423",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DOMPurify permits selectedcontent and the browser later re-clones its unsanitized child markup into active page content.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-87xg-pxx2-7hvx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cure53/DOMPurify/commit/011b0c78f2a0f57ee54f5fcccb697a46ca6e63ea",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cure53/DOMPurify/releases/tag/3.4.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.526Z",
      "date_published": "2026-07-21T17:47:40.995Z",
      "date_updated": "2026-07-23T14:20:36.413Z",
      "publisher": "GitHub_M",
      "title": "Rattler vulnerable to entry-point path traversal in noarch:python install (arbitrary file write)",
      "affected": {
        "vendors": [
          "conda",
          "prefix-dev"
        ],
        "products": [
          {
            "vendor": "conda",
            "product": "rattler"
          },
          {
            "vendor": "conda",
            "product": "py-rattler"
          },
          {
            "vendor": "conda",
            "product": "rattler-build"
          },
          {
            "vendor": "prefix-dev",
            "product": "pixi"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00147,
        "percentile": 0.0444
      },
      "nvd": {
        "published": "2026-07-21T18:17:01.130",
        "lastModified": "2026-07-23T18:04:31.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47425",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Rattler joins an unvalidated package entry-point name to the install prefix, allowing traversal or absolute names to write executable files elsewhere.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/conda/rattler/security/advisories/GHSA-q53q-5r4j-5729",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/conda/rattler/commit/4f06eca89aa13209774d26dbac077c41b72bac7c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 872,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.527Z",
      "date_published": "2026-07-28T15:32:27.294Z",
      "date_updated": "2026-07-28T17:31:19.108Z",
      "publisher": "GitHub_M",
      "title": "GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler",
      "affected": {
        "vendors": [
          "github"
        ],
        "products": [
          {
            "vendor": "github",
            "product": "github-mcp-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00394,
        "percentile": 0.3223
      },
      "nvd": {
        "published": "2026-07-28T16:18:14.853",
        "lastModified": "2026-07-30T19:58:04.837",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47427",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CompletionsHandler dereferences params.Ref without checking for nil, so an unauthenticated request can panic the server.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/github/github-mcp-server/security/advisories/GHSA-w4q6-qw23-4rg7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/github/github-mcp-server/pull/2502",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/github/github-mcp-server/commit/c88d2ecdd3bb07f7bdd75296e3ee676febf14f58",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/github/github-mcp-server/releases/tag/v1.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.527Z",
      "date_published": "2026-07-14T19:30:19.670Z",
      "date_updated": "2026-07-15T13:20:14.275Z",
      "publisher": "GitHub_M",
      "title": "Vitest browser mode serves unsanitized otelCarrier query parameter as inline script",
      "affected": {
        "vendors": [
          "vitest-dev"
        ],
        "products": [
          {
            "vendor": "vitest-dev",
            "product": "vitest"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31535
      },
      "nvd": {
        "published": "2026-07-14T20:17:02.307",
        "lastModified": "2026-07-15T20:23:47.313",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47428",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Vitest inserts otelCarrier directly into an inline module script served from the browser-runner origin.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vitest-dev/vitest/security/advisories/GHSA-2h32-95rg-cppp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/pull/10283",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/pull/10285",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/commit/18af98cee1830604d57f6a02bf28f8067cdffc06",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/commit/3514f9fa135c90e1c35754fc4d27c9cf351faafa",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/releases/tag/v4.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/releases/tag/v5.0.0-beta.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47429",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:37:43.527Z",
      "date_published": "2026-07-14T19:28:08.688Z",
      "date_updated": "2026-07-21T15:02:17.187Z",
      "publisher": "GitHub_M",
      "title": "Vitest: Arbitrary file can be read and executed when Vitest UI server is listening",
      "affected": {
        "vendors": [
          "vitest-dev"
        ],
        "products": [
          {
            "vendor": "vitest-dev",
            "product": "vitest"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01011,
        "percentile": 0.59763
      },
      "nvd": {
        "published": "2026-07-14T20:17:02.460",
        "lastModified": "2026-07-21T16:17:12.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47429",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Vitest's Windows attachment route misclassifies device-style paths as servable and permits selection outside the intended attachment root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vitest-dev/vitest/security/advisories/GHSA-5xrq-8626-4rwp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/pull/10445",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/pull/9350",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/commit/20e00ef7808de6d330c5e2fda530f686e08f1c8d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/commit/af88b1f5d82844a4761ea9a977156c98e2b14ca8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/releases/tag/v3.2.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/releases/tag/v4.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 405,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47470",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:37.796Z",
      "date_published": "2026-07-14T20:07:51.321Z",
      "date_updated": "2026-07-15T14:18:56.930Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT-LLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02154
      },
      "nvd": {
        "published": "2026-07-14T21:16:56.123",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47470",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The TensorRT-LLM gRPC chat endpoint accepts a malformed local input and can be driven into denial of service, while the affected field and operation are not public.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47470",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47470",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47471",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:38.727Z",
      "date_published": "2026-07-14T20:02:10.300Z",
      "date_updated": "2026-07-15T14:20:37.643Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT-LLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12069
      },
      "nvd": {
        "published": "2026-07-14T21:16:56.230",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47471",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47471",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47471",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47472",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:38.727Z",
      "date_published": "2026-07-14T20:01:29.906Z",
      "date_updated": "2026-07-15T14:11:54.536Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT-LLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13366
      },
      "nvd": {
        "published": "2026-07-14T21:16:56.333",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47472",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component deserializes attacker-controlled object data without restricting executable types or behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47472",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47472",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 296,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47473",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:38.727Z",
      "date_published": "2026-07-14T20:03:08.209Z",
      "date_updated": "2026-07-15T14:20:56.026Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT-LLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-123",
          "name": "Write-what-where Condition",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02916
      },
      "nvd": {
        "published": "2026-07-14T21:16:56.440",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47473",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TensorRT-LLM can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-123"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47473",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47473",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 224,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47475",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:38.728Z",
      "date_published": "2026-07-14T20:08:43.131Z",
      "date_updated": "2026-07-15T14:18:36.942Z",
      "publisher": "nvidia",
      "title": "NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "TensorRT-LLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02153
      },
      "nvd": {
        "published": "2026-07-14T21:16:56.547",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47475",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A request to the OpenAI-compatible inference API can reach an assertion in the sampler thread and terminate service processing.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47475",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47475",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:38.728Z",
      "date_published": "2026-07-14T19:43:39.115Z",
      "date_updated": "2026-07-15T14:07:29.600Z",
      "publisher": "nvidia",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Triton Inference Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26968
      },
      "nvd": {
        "published": "2026-07-14T20:17:02.620",
        "lastModified": "2026-07-15T16:23:03.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47476",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Triton permits attacker-driven work or allocation without an effective bound, but NVIDIA does not disclose the request, resource, or termination rule.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47476",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47476",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47477",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:38.728Z",
      "date_published": "2026-07-14T19:45:05.705Z",
      "date_updated": "2026-07-15T14:08:01.204Z",
      "publisher": "nvidia",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Triton Inference Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23068
      },
      "nvd": {
        "published": "2026-07-14T20:17:02.770",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47477",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Triton Inference Server can write beyond a stack buffer while processing attacker-controlled input.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47477",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47477",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47478",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:38.728Z",
      "date_published": "2026-07-14T19:45:59.026Z",
      "date_updated": "2026-07-15T14:12:24.562Z",
      "publisher": "nvidia",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Triton Inference Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-910",
          "name": "Use of Expired File Descriptor",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22373
      },
      "nvd": {
        "published": "2026-07-14T20:17:02.890",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47478",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation operates on a file descriptor after its lifetime has expired.",
        "basis": [
          "CNA",
          "CWE-910"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47478",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47478",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47479",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:38.728Z",
      "date_published": "2026-07-14T19:46:57.144Z",
      "date_updated": "2026-07-15T14:36:59.344Z",
      "publisher": "nvidia",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Triton Inference Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20083
      },
      "nvd": {
        "published": "2026-07-14T20:17:03.003",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47479",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A Triton request can consume an unbounded resource, but the public record does not identify the resource, limit, or release path.",
        "basis": [
          "CNA record",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47479",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47479",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47480",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:38.728Z",
      "date_published": "2026-07-14T19:47:59.935Z",
      "date_updated": "2026-07-15T14:12:52.500Z",
      "publisher": "nvidia",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Triton Inference Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20081
      },
      "nvd": {
        "published": "2026-07-14T20:17:03.120",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47480",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Triton Inference Server allows attacker-controlled input to raise an uncaught exception that terminates request processing.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47480",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47480",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:39.687Z",
      "date_published": "2026-07-14T19:49:07.820Z",
      "date_updated": "2026-07-15T14:13:24.115Z",
      "publisher": "nvidia",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Triton Inference Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17393
      },
      "nvd": {
        "published": "2026-07-14T20:17:03.243",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47481",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Triton permits a request to bypass authentication through an alternate path or channel.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47481",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47481",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:39.687Z",
      "date_published": "2026-07-14T19:50:09.678Z",
      "date_updated": "2026-07-15T14:14:07.042Z",
      "publisher": "nvidia",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "Triton Inference Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.2008
      },
      "nvd": {
        "published": "2026-07-14T20:17:03.367",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47482",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Triton Inference Server leaves an allocation unreleased after its effective lifetime, allowing repeated requests to accumulate memory.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47482",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47482",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47483",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T19:55:39.687Z",
      "date_published": "2026-07-28T15:55:31.369Z",
      "date_updated": "2026-07-28T16:48:18.878Z",
      "publisher": "nvidia",
      "title": "NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests.",
      "affected": {
        "vendors": [
          "NVIDIA"
        ],
        "products": [
          {
            "vendor": "NVIDIA",
            "product": "DCGM"
          },
          {
            "vendor": "NVIDIA",
            "product": "DCGM Exporter"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:psirt@nvidia.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.22971
      },
      "nvd": {
        "published": "2026-07-28T16:18:15.003",
        "lastModified": "2026-07-28T17:16:45.823",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47483",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected protocol path allocates or retains attacker-driven state without an effective upper bound.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47483",
          "host": "nvd.nist.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47483",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/NVIDIA/product-security/tree/main/2026/5857",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47632",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T20:12:27.069Z",
      "date_published": "2026-07-14T17:05:45.655Z",
      "date_updated": "2026-08-03T22:54:09.041Z",
      "publisher": "microsoft",
      "title": "Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure Monitor Agent Metrics Extension"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.2368
      },
      "nvd": {
        "published": "2026-07-14T17:16:49.637",
        "lastModified": "2026-07-27T18:43:34.870",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47632",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Azure Monitor Agent accepts an adjacent endpoint without correctly validating its certificate, allowing that endpoint to gain elevated trust.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47632",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47642",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T20:12:27.070Z",
      "date_published": "2026-07-14T17:08:28.638Z",
      "date_updated": "2026-08-03T22:56:48.282Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00404,
        "percentile": 0.33182
      },
      "nvd": {
        "published": "2026-07-14T18:17:18.550",
        "lastModified": "2026-07-16T11:48:36.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47642",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Microsoft 365 Apps for Enterprise path retains or dereferences an object after its storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47642",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-47646",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T20:12:27.071Z",
      "date_published": "2026-07-08T23:24:43.015Z",
      "date_updated": "2026-07-28T22:20:28.497Z",
      "publisher": "microsoft",
      "title": "Dynamics 365 Customer Voice Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Dynamics 365 Customer Voice"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 3.200000000000001,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19539
      },
      "nvd": {
        "published": "2026-07-09T00:17:23.160",
        "lastModified": "2026-07-09T19:17:05.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47646",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted input is rendered as browser markup without the required contextual escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47646",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47657",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:10:38.796Z",
      "date_published": "2026-07-21T17:50:08.427Z",
      "date_updated": "2026-07-21T18:36:42.028Z",
      "publisher": "GitHub_M",
      "title": "HumHub Missing Authorization on Remove All Space Members Action",
      "affected": {
        "vendors": [
          "humhub"
        ],
        "products": [
          {
            "vendor": "humhub",
            "product": "humhub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11998
      },
      "nvd": {
        "published": "2026-07-21T18:17:01.277",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47657",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HumHub lets an authenticated caller invoke the member-removal operation without the role required to remove all members.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/humhub/humhub/security/advisories/GHSA-hj67-5q6h-j7c2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/humhub/humhub/pull/8163",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47667",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:10:38.797Z",
      "date_published": "2026-07-21T19:57:49.446Z",
      "date_updated": "2026-07-23T14:13:10.735Z",
      "publisher": "GitHub_M",
      "title": "CImg Library: Uncontrolled Memory Allocation and Memory Leak in `_load_analyze()` via Crafted NIfTI/Analyze Header",
      "affected": {
        "vendors": [
          "GreycLab"
        ],
        "products": [
          {
            "vendor": "GreycLab",
            "product": "CImg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00426,
        "percentile": 0.35078
      },
      "nvd": {
        "published": "2026-07-21T20:17:01.323",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47667",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from the first 4 bytes of an Analyze/NIfTI file and passed directly to `new unsigned char[header_size]` without being bounded against the actual file size.",
        "basis": [
          "CNA",
          "CWE-401",
          "CWE-789",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/GreycLab/CImg/security/advisories/GHSA-rmfc-grgj-qwhv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/GreycLab/CImg/issues/480",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/GreycLab/CImg/commit/6a69bf725ffd111a4c7dc61cc15e3661abd158ee",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 779,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47668",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:10:38.797Z",
      "date_published": "2026-07-23T17:34:52.399Z",
      "date_updated": "2026-07-24T03:56:27.625Z",
      "publisher": "GitHub_M",
      "title": "DbGate: Unauthenticated Remote Code Execution via JSON Script Runner",
      "affected": {
        "vendors": [
          "dbgate"
        ],
        "products": [
          {
            "vendor": "dbgate",
            "product": "dbgate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.04339,
        "percentile": 0.9025
      },
      "nvd": {
        "published": "2026-07-23T18:16:53.350",
        "lastModified": "2026-07-24T05:16:44.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47668",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DbGate concatenates the functionName field into generated JavaScript that a child Node.js process executes.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-94",
          "CWE-1188"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dbgate/dbgate/security/advisories/GHSA-8v3q-9vmx-36vc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dbgate/dbgate/releases/tag/v7.1.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/dbgate-unauth-rce.yaml",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 466,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47669",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:10:38.797Z",
      "date_published": "2026-07-23T19:13:15.469Z",
      "date_updated": "2026-07-24T20:09:54.441Z",
      "publisher": "GitHub_M",
      "title": "DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE",
      "affected": {
        "vendors": [
          "dbgate"
        ],
        "products": [
          {
            "vendor": "dbgate",
            "product": "dbgate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27066
      },
      "nvd": {
        "published": "2026-07-23T20:17:08.357",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47669",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "unzipDirectory() joins ../ archive members to the extraction root without proving the normalized destination remains inside that root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dbgate/dbgate/security/advisories/GHSA-h535-j5hr-mv56",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dbgate/dbgate/releases/tag/v7.1.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47670",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:10:38.797Z",
      "date_published": "2026-07-23T19:12:00.882Z",
      "date_updated": "2026-07-24T20:10:09.061Z",
      "publisher": "GitHub_M",
      "title": "DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection",
      "affected": {
        "vendors": [
          "dbgate"
        ],
        "products": [
          {
            "vendor": "dbgate",
            "product": "dbgate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01714,
        "percentile": 0.75153
      },
      "nvd": {
        "published": "2026-07-23T20:17:08.500",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47670",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application places attacker-controlled data into an operating-system command without separating the data from command syntax.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dbgate/dbgate/security/advisories/GHSA-wm5r-5qp3-5vxf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dbgate/dbgate/releases/tag/v7.1.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47671",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:10:38.797Z",
      "date_published": "2026-07-21T20:00:53.145Z",
      "date_updated": "2026-07-22T15:44:11.174Z",
      "publisher": "GitHub_M",
      "title": "Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets",
      "affected": {
        "vendors": [
          "nhost"
        ],
        "products": [
          {
            "vendor": "nhost",
            "product": "cli"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18632
      },
      "nvd": {
        "published": "2026-07-21T20:17:01.473",
        "lastModified": "2026-07-30T15:27:31.953",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47671",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The local configserver exposes secret-reading and secret-writing GraphQL operations with dummy authorization and permissive cross-origin access.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nhost/nhost/security/advisories/GHSA-64cj-qvx5-m4f3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nhost/nhost/pull/4302",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nhost/nhost/commit/e407511627d2c2c1137a70e9ca1ca31095d23479",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nhost/nhost/releases/tag/cli@1.46.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 822,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:18:20.402Z",
      "date_published": "2026-07-21T20:37:32.498Z",
      "date_updated": "2026-07-22T18:25:10.593Z",
      "publisher": "GitHub_M",
      "title": "FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host Management page",
      "affected": {
        "vendors": [
          "FOGProject"
        ],
        "products": [
          {
            "vendor": "FOGProject",
            "product": "fogproject"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09919
      },
      "nvd": {
        "published": "2026-07-21T21:16:50.543",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47685",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unauthenticated inventory endpoint stores client fields that the administrator page later inserts into HTML without encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOGProject/fogproject/security/advisories/GHSA-2r7m-6mqf-5cc4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 511,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:18:20.403Z",
      "date_published": "2026-07-21T20:39:01.101Z",
      "date_updated": "2026-07-22T14:31:39.609Z",
      "publisher": "GitHub_M",
      "title": "FOGProject has stored XSS via unescaped option label in selectForm() accessible from unauthenticated inventory endpoint",
      "affected": {
        "vendors": [
          "FOGProject"
        ],
        "products": [
          {
            "vendor": "FOGProject",
            "product": "fogproject"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12176
      },
      "nvd": {
        "published": "2026-07-21T21:16:50.680",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47687",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FOG stores attacker-controlled inventory data and later renders it as an unescaped option label in an administrator's page.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOGProject/fogproject/security/advisories/GHSA-hg23-3w27-2rf2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 628,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:18:20.403Z",
      "date_published": "2026-07-21T20:40:31.480Z",
      "date_updated": "2026-07-22T13:41:39.164Z",
      "publisher": "GitHub_M",
      "title": "FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of host encryption keys and power schedules",
      "affected": {
        "vendors": [
          "FOGProject"
        ],
        "products": [
          {
            "vendor": "FOGProject",
            "product": "fogproject"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05117
      },
      "nvd": {
        "published": "2026-07-21T21:16:50.810",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47688",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Public client-node routing exposes clearAES and clearPMTasks without login, session, or CSRF authorization before destructive state changes.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOGProject/fogproject/security/advisories/GHSA-95pr-mcrf-x2qg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47689",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:18:20.403Z",
      "date_published": "2026-07-21T20:42:19.896Z",
      "date_updated": "2026-07-22T18:25:04.533Z",
      "publisher": "GitHub_M",
      "title": "FOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group Inventory tab",
      "affected": {
        "vendors": [
          "FOGProject"
        ],
        "products": [
          {
            "vendor": "FOGProject",
            "product": "fogproject"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.05992
      },
      "nvd": {
        "published": "2026-07-21T21:16:50.937",
        "lastModified": "2026-07-23T15:33:09.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47689",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The fogproject page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOGProject/fogproject/security/advisories/GHSA-fqgf-j2gh-92cm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 673,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:18:20.403Z",
      "date_published": "2026-07-21T20:46:26.449Z",
      "date_updated": "2026-07-22T14:59:37.761Z",
      "publisher": "GitHub_M",
      "title": "MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflow",
      "affected": {
        "vendors": [
          "meltano"
        ],
        "products": [
          {
            "vendor": "meltano",
            "product": "hub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21629
      },
      "nvd": {
        "published": "2026-07-21T21:16:51.067",
        "lastModified": "2026-07-23T16:15:11.587",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47690",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A pull_request_target workflow runs attacker-influenced pull-request handling with a repository write token and access to base-repository secrets.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/meltano/hub/security/advisories/GHSA-wrpf-f35c-j28w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/meltano/hub/pull/2247",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/meltano/hub/pull/2249",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/meltano/hub/pull/2251",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/meltano/hub/commit/923820de8f64d753951fbbd54f7282a3d5f75173",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/myogahunter/meltano-hub-poc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 483,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:18:20.403Z",
      "date_published": "2026-07-21T20:51:07.866Z",
      "date_updated": "2026-07-23T14:05:43.090Z",
      "publisher": "GitHub_M",
      "title": "CC-Tweaked has an SSRF Protection Bypass with NAT64",
      "affected": {
        "vendors": [
          "cc-tweaked"
        ],
        "products": [
          {
            "vendor": "cc-tweaked",
            "product": "CC-Tweaked"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00342,
        "percentile": 0.2688
      },
      "nvd": {
        "published": "2026-07-21T21:16:51.210",
        "lastModified": "2026-07-23T18:28:20.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47695",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CC-Tweaked accepts an attacker-controlled destination without reapplying the network allowlist after URL parsing, redirects, or address resolution, allowing server-side requests to a prohibited target.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cc-tweaked/CC-Tweaked/security/advisories/GHSA-5jh9-2h63-pw4q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 796,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:18:20.403Z",
      "date_published": "2026-07-21T20:53:19.260Z",
      "date_updated": "2026-07-22T15:38:40.645Z",
      "publisher": "GitHub_M",
      "title": "Shelf has cross-organization IDOR: authenticated users could read/attach another workspace's assets, tags, custodians, bookings, QR codes and audit data",
      "affected": {
        "vendors": [
          "Shelf-nu"
        ],
        "products": [
          {
            "vendor": "Shelf-nu",
            "product": "shelf.nu"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07931
      },
      "nvd": {
        "published": "2026-07-21T21:16:51.340",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47697",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Shelf connects and reads request-supplied entity IDs without verifying that each entity belongs to the caller's organization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Shelf-nu/shelf.nu/security/advisories/GHSA-r46p-gfrp-xxgq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 629,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47703",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:18:20.404Z",
      "date_published": "2026-07-15T16:03:17.047Z",
      "date_updated": "2026-07-15T17:45:59.434Z",
      "publisher": "GitHub_M",
      "title": "AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle",
      "affected": {
        "vendors": [
          "AdguardTeam"
        ],
        "products": [
          {
            "vendor": "AdguardTeam",
            "product": "AdGuardHome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-330",
          "name": "Use of Insufficiently Random Values",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02383
      },
      "nvd": {
        "published": "2026-07-15T17:16:48.540",
        "lastModified": "2026-07-30T14:29:18.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47703",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The DoQ forwarding path collapses the DNS transaction ID to zero and exposes a source-port oracle, weakening response matching.",
        "basis": [
          "CNA",
          "CWE-330",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/AdguardTeam/AdGuardHome/security/advisories/GHSA-xgx4-4h9w-53pv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47708",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:29:25.481Z",
      "date_published": "2026-07-21T20:55:15.048Z",
      "date_updated": "2026-07-22T15:10:36.426Z",
      "publisher": "GitHub_M",
      "title": "MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper",
      "affected": {
        "vendors": [
          "SepineTam"
        ],
        "products": [
          {
            "vendor": "SepineTam",
            "product": "stata-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22571
      },
      "nvd": {
        "published": "2026-07-21T21:16:51.477",
        "lastModified": "2026-07-23T18:19:01.223",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47708",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "MCP-for-Stata interpolates log_file_name into a Stata command without neutralizing quotes, newlines, or command separators.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/SepineTam/mcp-for-stata/security/advisories/GHSA-4p62-hqp5-g644",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/SepineTam/mcp-for-stata/issues/74",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/SepineTam/mcp-for-stata/commit/e6f945941ae0c7cf5e74a428e0b3dc82b396382f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 579,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47709",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:29:25.481Z",
      "date_published": "2026-07-21T21:31:14.724Z",
      "date_updated": "2026-07-22T15:06:56.971Z",
      "publisher": "GitHub_M",
      "title": "libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling for malformed unci image missing ispe",
      "affected": {
        "vendors": [
          "strukturag"
        ],
        "products": [
          {
            "vendor": "strukturag",
            "product": "libheif"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00212,
        "percentile": 0.116
      },
      "nvd": {
        "published": "2026-07-21T22:17:13.097",
        "lastModified": "2026-07-27T15:17:57.187",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47709",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libheif's tiling API dereferences a missing property when a malformed uncompressed HEIF image omits required tiling state.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/strukturag/libheif/security/advisories/GHSA-4h72-vqgp-9376",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/strukturag/libheif/issues/1802",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/strukturag/libheif/pull/1806",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Patch",
            "Third Party Advisory",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47714",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:29:25.482Z",
      "date_published": "2026-07-21T21:04:06.167Z",
      "date_updated": "2026-07-22T13:37:10.052Z",
      "publisher": "GitHub_M",
      "title": "libheif has integer overflow in inline mask size calculation that causes undersized buffer allocation",
      "affected": {
        "vendors": [
          "strukturag"
        ],
        "products": [
          {
            "vendor": "strukturag",
            "product": "libheif"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01311
      },
      "nvd": {
        "published": "2026-07-21T21:16:51.617",
        "lastModified": "2026-07-30T15:07:07.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47714",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/strukturag/libheif/security/advisories/GHSA-h4wm-6wwf-qvhx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47722",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:29:25.482Z",
      "date_published": "2026-07-23T19:19:41.976Z",
      "date_updated": "2026-07-24T11:11:20.665Z",
      "publisher": "GitHub_M",
      "title": "nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml",
      "affected": {
        "vendors": [
          "juev"
        ],
        "products": [
          {
            "vendor": "juev",
            "product": "nebula-mesh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18879
      },
      "nvd": {
        "published": "2026-07-23T20:17:08.637",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47722",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Host override fields are interpolated unescaped into generated YAML, allowing configuration structure to be injected into agents.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-7hp6-g3pq-3pc3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/issues/126",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/commit/c1506f7344ab375a145a7449b193af3f19bb41ef",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 439,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:29:25.482Z",
      "date_published": "2026-07-23T20:17:26.478Z",
      "date_updated": "2026-07-24T13:54:01.417Z",
      "publisher": "GitHub_M",
      "title": "nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)",
      "affected": {
        "vendors": [
          "juev"
        ],
        "products": [
          {
            "vendor": "juev",
            "product": "nebula-mesh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1021",
          "name": "Improper Restriction of Rendered UI Layers or Frames",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22608
      },
      "nvd": {
        "published": "2026-07-23T21:17:04.340",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47723",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The browser-facing response omits an effective frame-ancestor restriction, allowing a sensitive interface to be embedded by another origin.",
        "basis": [
          "CNA",
          "CWE-1021"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-w7w5-5gcp-38rw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/commit/b45fda5476c41ffcff1ca23058aef0fb851359c1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47724",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:29:25.482Z",
      "date_published": "2026-07-23T20:20:59.494Z",
      "date_updated": "2026-07-28T14:55:31.612Z",
      "publisher": "GitHub_M",
      "title": "nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation",
      "affected": {
        "vendors": [
          "juev"
        ],
        "products": [
          {
            "vendor": "juev",
            "product": "nebula-mesh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27694
      },
      "nvd": {
        "published": "2026-07-23T21:17:04.477",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47724",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-598g-h2vc-h5vg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/commit/9d8bcd7667ecd0c2975cc71fb35a02fe131f76f2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 844,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47725",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:29:25.483Z",
      "date_published": "2026-07-28T17:56:29.651Z",
      "date_updated": "2026-07-28T19:36:36.348Z",
      "publisher": "GitHub_M",
      "title": "nebula-mesh: Web UI lacks CSRF tokens on /ui/* mutating endpoints",
      "affected": {
        "vendors": [
          "juev"
        ],
        "products": [
          {
            "vendor": "juev",
            "product": "nebula-mesh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05072
      },
      "nvd": {
        "published": "2026-07-28T19:17:34.237",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47725",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "nebula-mesh accepts a state-changing browser request without validating an unforgeable anti-CSRF token or equivalent origin proof.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-273q-qgh5-wrj6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 649,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47726",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:29:25.483Z",
      "date_published": "2026-07-28T17:58:27.219Z",
      "date_updated": "2026-07-28T18:43:23.969Z",
      "publisher": "GitHub_M",
      "title": "nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator",
      "affected": {
        "vendors": [
          "juev"
        ],
        "products": [
          {
            "vendor": "juev",
            "product": "nebula-mesh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14914
      },
      "nvd": {
        "published": "2026-07-28T19:17:34.393",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47726",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The audit-log route requires only any operator key and omits the administrator check needed for cross-tenant log access.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-qm33-p5p9-f8vg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/commit/8baaace54c2a23e7c351b3efab5a31ab07b125dc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 608,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:29:25.483Z",
      "date_published": "2026-07-16T16:13:19.767Z",
      "date_updated": "2026-07-17T18:07:10.084Z",
      "publisher": "GitHub_M",
      "title": "Squid: Memory disclosure in FTP gateway",
      "affected": {
        "vendors": [
          "squid-cache"
        ],
        "products": [
          {
            "vendor": "squid-cache",
            "product": "squid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1289",
          "name": "Improper Validation of Unsafe Equivalence in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01503,
        "percentile": 0.71801
      },
      "nvd": {
        "published": "2026-07-16T17:16:57.217",
        "lastModified": "2026-07-20T01:43:02.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47729",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An FTP listing without a filename makes the parser read beyond the valid input buffer.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-1289"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/squid-cache/squid/pull/2408",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/squid-cache/squid/pull/2409",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/squid-cache/squid/releases/tag/SQUID_7_6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:29:25.483Z",
      "date_published": "2026-07-14T21:21:10.185Z",
      "date_updated": "2026-07-21T14:45:11.407Z",
      "publisher": "GitHub_M",
      "title": "Twig: XSS in profiler HtmlDumper via unescaped template and profile names",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06588
      },
      "nvd": {
        "published": "2026-07-14T22:16:59.530",
        "lastModified": "2026-07-21T16:17:13.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47730",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Twig renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-2g2g-8p8h-fgwm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/a5f6e8793e603ef34fa86aed2a72f9fbe0b43745",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T21:29:25.483Z",
      "date_published": "2026-07-21T21:36:22.944Z",
      "date_updated": "2026-07-22T14:28:21.722Z",
      "publisher": "GitHub_M",
      "title": "NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)",
      "affected": {
        "vendors": [
          "NASA-AMMOS"
        ],
        "products": [
          {
            "vendor": "NASA-AMMOS",
            "product": "AIT-Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00804,
        "percentile": 0.53219
      },
      "nvd": {
        "published": "2026-07-21T22:17:13.230",
        "lastModified": "2026-07-23T18:14:47.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47731",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The unauthenticated BSC handler accepts an absolute or traversal filename and later writes uploaded bytes at that filesystem path.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/NASA-AMMOS/AIT-Core/security/advisories/GHSA-p462-prxw-mjx4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/NASA-AMMOS/AIT-Core/releases/tag/2.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/NASA-AMMOS/AIT-Core/releases/tag/3.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2083,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47732",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T22:16:39.503Z",
      "date_published": "2026-07-14T21:12:13.071Z",
      "date_updated": "2026-07-15T13:26:33.236Z",
      "publisher": "GitHub_M",
      "title": "Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28676
      },
      "nvd": {
        "published": "2026-07-14T22:16:59.667",
        "lastModified": "2026-07-16T03:06:57.963",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47732",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Twig performs unguarded string coercion in several sandbox constructs, invoking an object's __toString method without SecurityPolicy::checkMethodAllowed.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-pr2w-4gpj-cpq4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/447d0b2331e01b8fc6e08119ac984e1ef50caef9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.26.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 504,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47736",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T22:16:39.503Z",
      "date_published": "2026-07-14T19:54:26.229Z",
      "date_updated": "2026-07-15T14:28:29.155Z",
      "publisher": "GitHub_M",
      "title": "Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion",
      "affected": {
        "vendors": [
          "puma"
        ],
        "products": [
          {
            "vendor": "puma",
            "product": "puma"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00346,
        "percentile": 0.2723
      },
      "nvd": {
        "published": "2026-07-14T20:17:03.620",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47736",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Puma buffers an unterminated PROXY v1 line and repeatedly scans the growing buffer without a line-length limit.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/puma/puma/security/advisories/GHSA-qpgp-93vx-g8v8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/puma/puma/commit/439c6136d9c2275721b7864db3ee78af7c80889f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/puma/puma/commit/ebe9db3929ab8299d19c8f5b41e8ef4f4b22fa58",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/puma/puma/releases/tag/v7.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/puma/puma/releases/tag/v8.0.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T22:16:39.503Z",
      "date_published": "2026-07-14T19:45:16.648Z",
      "date_updated": "2026-07-15T14:10:20.444Z",
      "publisher": "GitHub_M",
      "title": "Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections",
      "affected": {
        "vendors": [
          "puma"
        ],
        "products": [
          {
            "vendor": "puma",
            "product": "puma"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07481
      },
      "nvd": {
        "published": "2026-07-14T20:17:03.767",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47737",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Puma re-parses a PROXY v1 header after every keep-alive request, allowing a second header on the same connection to replace the trusted remote address.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-290",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/puma/puma/security/advisories/GHSA-2vqw-3mp8-cgmx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/puma/puma/pull/3944",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/puma/puma/pull/3947",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/puma/puma/commit/439c6136d9c2275721b7864db3ee78af7c80889f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/puma/puma/commit/ebe9db3929ab8299d19c8f5b41e8ef4f4b22fa58",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/puma/puma/releases/tag/v7.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/puma/puma/releases/tag/v8.0.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 460,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47743",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T22:16:39.504Z",
      "date_published": "2026-07-23T17:20:25.550Z",
      "date_updated": "2026-07-23T18:19:03.439Z",
      "publisher": "GitHub_M",
      "title": "Shopper: Multiple data integrity and disclosure issues in admin Livewire components",
      "affected": {
        "vendors": [
          "shopperlabs"
        ],
        "products": [
          {
            "vendor": "shopperlabs",
            "product": "shopper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28001
      },
      "nvd": {
        "published": "2026-07-23T18:16:53.490",
        "lastModified": "2026-07-23T19:16:54.323",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47743",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Shopper leaves Livewire Eloquent identifiers mutable in the client snapshot, allowing an authenticated user to substitute another record ID; the grouped record also exposes a plaintext password snapshot and an unescaped barcode sink.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-200",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/shopperlabs/shopper/security/advisories/GHSA-hr9v-r8r2-hg7j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/shopperlabs/shopper/pull/511",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1606,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47751",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T22:16:39.505Z",
      "date_published": "2026-07-16T15:59:29.885Z",
      "date_updated": "2026-07-18T02:55:59.645Z",
      "publisher": "GitHub_M",
      "title": "Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration",
      "affected": {
        "vendors": [
          "anthropics"
        ],
        "products": [
          {
            "vendor": "anthropics",
            "product": "claude-code-action"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00561,
        "percentile": 0.43524
      },
      "nvd": {
        "published": "2026-07-16T17:16:57.357",
        "lastModified": "2026-07-18T03:16:36.220",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47751",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An automation action trusts a pull request's .mcp.json and enables project-supplied MCP servers in the privileged workflow.",
        "basis": [
          "CNA",
          "CWE-78",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/anthropics/claude-code-action/security/advisories/GHSA-8q5r-mmjf-575q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/anthropics/claude-code-action/pull/1066",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/anthropics/claude-code-action/commit/9ddce40de8c1ab71fb6303a125fdad0968dc1312",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/anthropics/claude-code-action/releases/tag/v1.0.74",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 811,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47752",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T22:16:39.505Z",
      "date_published": "2026-07-23T16:57:54.967Z",
      "date_updated": "2026-07-23T17:43:09.688Z",
      "publisher": "GitHub_M",
      "title": "Tugtainer has Server-Side Template Injection in notification templates that leads to Remote Code Execution",
      "affected": {
        "vendors": [
          "Quenary"
        ],
        "products": [
          {
            "vendor": "Quenary",
            "product": "tugtainer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00392,
        "percentile": 0.31895
      },
      "nvd": {
        "published": "2026-07-23T18:16:53.630",
        "lastModified": "2026-07-23T18:23:01.873",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47752",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The tugtainer path renders attacker-controlled template text in an unsandboxed template engine that exposes code execution primitives.",
        "basis": [
          "CNA",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Quenary/tugtainer/security/advisories/GHSA-g2cj-2x47-78vq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T22:16:39.505Z",
      "date_published": "2026-07-23T17:08:24.133Z",
      "date_updated": "2026-07-28T14:55:37.555Z",
      "publisher": "GitHub_M",
      "title": "ITFlow Vulnerable to Authenticated Cross-Tenant Credential Disclosure via Unprotected Credential Modal",
      "affected": {
        "vendors": [
          "itflow-org"
        ],
        "products": [
          {
            "vendor": "itflow-org",
            "product": "itflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19583
      },
      "nvd": {
        "published": "2026-07-23T18:16:53.780",
        "lastModified": "2026-07-28T16:18:15.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47755",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ITFlow loads secrets by caller-controlled identifiers without binding them to the caller's client tenant.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/itflow-org/itflow/security/advisories/GHSA-987x-g5f9-2rpq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/itflow-org/itflow/compare/v26.04...v26.05",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T22:36:16.882Z",
      "date_published": "2026-07-14T18:38:36.513Z",
      "date_updated": "2026-07-16T14:34:59.539Z",
      "publisher": "GitHub_M",
      "title": "Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "runtime"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00389,
        "percentile": 0.3165
      },
      "nvd": {
        "published": "2026-07-14T19:17:09.237",
        "lastModified": "2026-07-16T15:16:31.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47767",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Symfony decides that a request has no query parameters while the web SAPI still exposes the same bytes as argv, allowing HTTP input to set APP_ENV or APP_DEBUG as console flags.",
        "basis": [
          "CNA",
          "CWE-436"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-fqc7-9xjw-jrh3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Not Applicable",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/3228c3806ee511008bea19a95084d460b17e5d25",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 503,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-47768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T22:36:16.882Z",
      "date_published": "2026-07-28T18:19:39.559Z",
      "date_updated": "2026-07-28T18:47:53.458Z",
      "publisher": "GitHub_M",
      "title": "nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)",
      "affected": {
        "vendors": [
          "juev"
        ],
        "products": [
          {
            "vendor": "juev",
            "product": "nebula-mesh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-598",
          "name": "Use of HTTP Request With Sensitive Query String",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00108,
        "percentile": 0.01391
      },
      "nvd": {
        "published": "2026-07-28T19:17:34.567",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47768",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "nebula-mesh places a newly minted operator API key in a redirect URL that reaches history, Referer headers, and proxy logs.",
        "basis": [
          "CNA",
          "CWE-598"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-9pg3-25fq-p6cc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-19T22:36:16.882Z",
      "date_published": "2026-07-23T17:23:27.570Z",
      "date_updated": "2026-07-23T18:14:38.774Z",
      "publisher": "GitHub_M",
      "title": "APIFold Vulnerable to Unauthenticated Webhook Event Injection",
      "affected": {
        "vendors": [
          "Work90210"
        ],
        "products": [
          {
            "vendor": "Work90210",
            "product": "APIFold"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28807
      },
      "nvd": {
        "published": "2026-07-23T18:16:53.920",
        "lastModified": "2026-07-23T19:16:54.427",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47769",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Work90210/APIFold/security/advisories/GHSA-x82h-9r8v-m672",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Work90210/APIFold/pull/235",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Work90210/APIFold/commit/7f19b52280f414f57af2b79a95333d1c8fbeece5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 892,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47826",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:48.931Z",
      "date_published": "2026-07-09T05:45:33.512Z",
      "date_updated": "2026-07-09T14:10:24.256Z",
      "publisher": "vmware",
      "title": "blobs.yaml Path Traversal Allows File Writes",
      "affected": {
        "vendors": [
          "CloudFoundry Foundation"
        ],
        "products": [
          {
            "vendor": "CloudFoundry Foundation",
            "product": "BOSH CLI tool"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27003
      },
      "nvd": {
        "published": "2026-07-09T07:16:23.840",
        "lastModified": "2026-07-13T13:36:53.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47826",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BOSH CLI resolves a caller-controlled blobs.yml path outside the intended project, allowing reads or writes against arbitrary local paths.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cloudfoundry.org/blog/cve-2026-47826-blobs-yaml-path-traversal-allows-file-writes/",
          "host": "www.cloudfoundry.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47828",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:48.931Z",
      "date_published": "2026-07-09T06:07:10.251Z",
      "date_updated": "2026-07-09T12:50:23.498Z",
      "publisher": "vmware",
      "title": "Missing TLS Certificate Verification in BOSH CLI Allows Root Code Execution via Man-in-the-Middle Credential Replay",
      "affected": {
        "vendors": [
          "BOSH-Ecosystem / BOSH (bosh-cli)"
        ],
        "products": [
          {
            "vendor": "BOSH-Ecosystem / BOSH (bosh-cli)",
            "product": "bosh-cli"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 1.8000000000000007,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04478
      },
      "nvd": {
        "published": "2026-07-09T07:16:23.990",
        "lastModified": "2026-07-13T13:35:57.873",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47828",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The BOSH CLI sends bootstrap packages and templates to the new VM over HTTPS without validating the server certificate against the manifest CA.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cloudfoundry.org/blog/cve-2026-47828-missing-tls-certificate-verification-in-bosh-cli-allows-root-code-execution-via-man-in-the-middle-credential-replay/",
          "host": "www.cloudfoundry.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 607,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47829",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:48.931Z",
      "date_published": "2026-07-09T06:25:56.071Z",
      "date_updated": "2026-07-09T13:12:14.523Z",
      "publisher": "vmware",
      "title": "Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised Director",
      "affected": {
        "vendors": [
          "CloudFoundry Foundation"
        ],
        "products": [
          {
            "vendor": "CloudFoundry Foundation",
            "product": "bosh-cli"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13198
      },
      "nvd": {
        "published": "2026-07-09T07:16:24.150",
        "lastModified": "2026-07-13T13:33:49.180",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47829",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "bosh-cli passes Director-controlled values as OpenSSH arguments without separating them from option syntax, enabling local ssh option injection.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cloudfoundry.org/blog/cve-2026-47829-argument-injection-in-bosh-cli-allows-local-command-execution-on-operator-workstations-via-compromised-director/",
          "host": "www.cloudfoundry.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47830",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:48.931Z",
      "date_published": "2026-07-09T06:25:58.095Z",
      "date_updated": "2026-07-09T12:49:41.047Z",
      "publisher": "vmware",
      "title": "Incorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM via Executable Overwrite",
      "affected": {
        "vendors": [
          "Cloud Foundry Foundation"
        ],
        "products": [
          {
            "vendor": "Cloud Foundry Foundation",
            "product": "bosh-windows-stemcell-builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.001,
        "percentile": 0.01026
      },
      "nvd": {
        "published": "2026-07-09T07:16:24.280",
        "lastModified": "2026-07-09T16:39:17.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47830",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Low-privilege users can overwrite executables in C:\\bosh that a SYSTEM service runs after restart because the files have unsafe permissions.",
        "basis": [
          "CNA",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cloudfoundry.org/blog/cve-2026-47830-incorrect-permission-assignment-allows-local-privilege-escalation-to-system-via-executable-overwrite/",
          "host": "www.cloudfoundry.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47831",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:48.931Z",
      "date_published": "2026-07-09T06:26:00.127Z",
      "date_updated": "2026-07-09T12:50:39.057Z",
      "publisher": "vmware",
      "title": "Cryptographically Weak Password Generation in bosh-windows-stemcell-builder Allows Remote SSH Brute-Force Attacks",
      "affected": {
        "vendors": [
          "Cloud Foundry Foundation"
        ],
        "products": [
          {
            "vendor": "Cloud Foundry Foundation",
            "product": "bosh-windows-stemcell-builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00191,
        "percentile": 0.08954
      },
      "nvd": {
        "published": "2026-07-09T07:16:24.423",
        "lastModified": "2026-07-09T16:39:17.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47831",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GenerateRandomPassword uses a cryptographically weak random generator, making generated Windows stemcell SSH passwords brute-forceable.",
        "basis": [
          "CNA",
          "CWE-338"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cloudfoundry.org/blog/cve-2026-47831-cryptographically-weak-password-generation-in-bosh-windows-stemcell-builder-allows-remote-ssh-brute-force-attacks/",
          "host": "www.cloudfoundry.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 280,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47840",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:51.003Z",
      "date_published": "2026-07-09T06:26:02.169Z",
      "date_updated": "2026-07-09T12:49:24.260Z",
      "publisher": "vmware",
      "title": "LDAP StartTLS unconditionally disables hostname verification",
      "affected": {
        "vendors": [
          "CloudFoundry Foundation"
        ],
        "products": [
          {
            "vendor": "CloudFoundry Foundation",
            "product": "UAA"
          },
          {
            "vendor": "CloudFoundry Foundation",
            "product": "Cf-deployment"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-297",
          "name": "Improper Validation of Certificate with Host Mismatch",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 1.8000000000000007,
      "epss": {
        "score": 0.00132,
        "percentile": 0.0321
      },
      "nvd": {
        "published": "2026-07-09T07:16:24.553",
        "lastModified": "2026-07-09T16:39:17.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47840",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LDAP StartTLS disables hostname verification, so a certificate for any name from a trusted CA is accepted for the configured directory host.",
        "basis": [
          "CNA",
          "CWE-297"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cloudfoundry.org/blog/cve-2026-47840-ldap-starttls-unconditionally-disables-hostname-verification/",
          "host": "www.cloudfoundry.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47858",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:55.156Z",
      "date_published": "2026-07-30T05:15:31.292Z",
      "date_updated": "2026-08-01T03:56:10.532Z",
      "publisher": "vmware",
      "title": "live information startup mode is vulnerable for remote code execution",
      "affected": {
        "vendors": [
          "Spring"
        ],
        "products": [
          {
            "vendor": "Spring",
            "product": "Spring Tools for Eclipse"
          },
          {
            "vendor": "Spring",
            "product": "Spring Tools for VSCode / Cursor / Theia"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09682
      },
      "nvd": {
        "published": "2026-07-30T06:25:52.120",
        "lastModified": "2026-08-01T05:16:56.700",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47858",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Live-information mode exposes a JMX control path without the authentication needed to prevent remote code execution.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://spring.io/security/cve-2026-47858",
          "host": "spring.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-47865",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:57.076Z",
      "date_published": "2026-07-18T08:57:05.890Z",
      "date_updated": "2026-07-23T03:56:15.727Z",
      "publisher": "vmware",
      "title": "VMware Avi Load Balancer Authentication Bypass Vulnerability",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Avi Load Balancer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00874,
        "percentile": 0.5542
      },
      "nvd": {
        "published": "2026-07-18T09:17:08.287",
        "lastModified": "2026-07-23T05:16:31.203",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47865",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A network caller can bypass authentication to the Avi Control plane, but Broadcom does not publish the failed identity check.",
        "basis": [
          "CNA",
          "CWE-287",
          "Broadcom VMSA-2026-0005"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926; Broadcom confirms unauthenticated Avi Control plane access, affected and fixed versions, and no workaround but publishes no failed identity check."
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 341,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-47866",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:57.077Z",
      "date_published": "2026-07-18T08:57:08.170Z",
      "date_updated": "2026-07-23T03:56:16.450Z",
      "publisher": "vmware",
      "title": "VMware Avi Load Balancer Authorization Bypass Vulnerability",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Avi Load Balancer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18751
      },
      "nvd": {
        "published": "2026-07-18T09:17:08.413",
        "lastModified": "2026-07-23T05:16:31.373",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47866",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Avi Load Balancer permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47867",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:57.077Z",
      "date_published": "2026-07-18T08:57:11.729Z",
      "date_updated": "2026-07-23T03:56:17.181Z",
      "publisher": "vmware",
      "title": "VMware Avi Load Balancer Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Avi Load Balancer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36271
      },
      "nvd": {
        "published": "2026-07-18T09:17:08.527",
        "lastModified": "2026-07-23T05:16:31.483",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47867",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Avi Load Balancer lets attacker-controlled schema, metadata, code text, or file content cross into a code-generation or execution interpreter without the quoting, allowlisting, or neutralization needed to keep it as data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47868",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:57.077Z",
      "date_published": "2026-07-18T08:57:14.131Z",
      "date_updated": "2026-07-23T03:56:17.911Z",
      "publisher": "vmware",
      "title": "VMware Avi Load Balancer Local Privilege Escalation Vulnerability",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Avi Load Balancer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0011,
        "percentile": 0.01477
      },
      "nvd": {
        "published": "2026-07-18T09:17:08.627",
        "lastModified": "2026-07-23T05:16:31.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47868",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Avi Load Balancer permits a local user to gain root code-execution authority, while the public advisory does not identify the role, object, or missing check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 343,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47869",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:57.077Z",
      "date_published": "2026-07-18T08:57:16.678Z",
      "date_updated": "2026-07-23T03:56:18.600Z",
      "publisher": "vmware",
      "title": "VMware Avi Load Balancer Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Avi Load Balancer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00441,
        "percentile": 0.3627
      },
      "nvd": {
        "published": "2026-07-18T09:17:08.740",
        "lastModified": "2026-07-23T05:16:31.703",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47869",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Avi Load Balancer passes attacker-controlled text into a command, code, or downstream grammar without the required structural separation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47870",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:57.077Z",
      "date_published": "2026-07-18T08:57:18.882Z",
      "date_updated": "2026-07-24T20:17:47.315Z",
      "publisher": "vmware",
      "title": "VMware Avi Load Balancer Privilege Escalation Vulnerability",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Avi Load Balancer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16687
      },
      "nvd": {
        "published": "2026-07-18T09:17:08.847",
        "lastModified": "2026-07-24T21:16:45.157",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47870",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Avi Load Balancer lets an authenticated user obtain code-execution privileges, but the public record does not identify the misbound role, object, or operation.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 327,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47871",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:57.077Z",
      "date_published": "2026-07-18T08:57:21.563Z",
      "date_updated": "2026-07-23T03:56:20.090Z",
      "publisher": "vmware",
      "title": "VMware Avi Load Balancer Directory Traversal Vulnerability",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Avi Load Balancer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00651,
        "percentile": 0.47673
      },
      "nvd": {
        "published": "2026-07-18T09:17:08.960",
        "lastModified": "2026-07-23T05:16:31.913",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47871",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Avi Load Balancer validates authenticated file paths incompletely, allowing selection outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 354,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47873",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:57.077Z",
      "date_published": "2026-07-30T05:23:59.651Z",
      "date_updated": "2026-08-01T03:56:09.351Z",
      "publisher": "vmware",
      "title": "Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces",
      "affected": {
        "vendors": [
          "Spring"
        ],
        "products": [
          {
            "vendor": "Spring",
            "product": "Spring Tools for Eclipse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1327",
          "name": "Binding to an Unrestricted IP Address",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08239
      },
      "nvd": {
        "published": "2026-07-30T06:25:52.253",
        "lastModified": "2026-08-01T05:16:56.820",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47873",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Spring Tools publishes Docker control ports on 0.0.0.0 instead of restricting the management interface to loopback.",
        "basis": [
          "CNA",
          "CWE-1327"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://spring.io/security/cve-2026-47873",
          "host": "spring.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47876",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:58.694Z",
      "date_published": "2026-07-30T12:31:52.158Z",
      "date_updated": "2026-07-30T13:02:29.161Z",
      "publisher": "vmware",
      "title": "VMXNET3 out-of-bounds write vulnerability",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Cloud Foundation"
          },
          {
            "vendor": "VMware",
            "product": "vSphere Foundation"
          },
          {
            "vendor": "VMware",
            "product": "ESX"
          },
          {
            "vendor": "VMware",
            "product": "Telco Cloud Platform"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 10,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20362
      },
      "nvd": {
        "published": "2026-07-30T13:16:51.100",
        "lastModified": "2026-07-30T14:16:58.467",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47876",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-47882",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T10:00:58.694Z",
      "date_published": "2026-07-30T05:26:07.335Z",
      "date_updated": "2026-08-01T03:56:08.233Z",
      "publisher": "vmware",
      "title": "Spring Boot DevTools remote secret generated with a non-cryptographic PRNG",
      "affected": {
        "vendors": [
          "Spring"
        ],
        "products": [
          {
            "vendor": "Spring",
            "product": "Spring Tools for Eclipse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07063
      },
      "nvd": {
        "published": "2026-07-30T06:25:52.370",
        "lastModified": "2026-08-01T05:16:56.930",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-47882",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Spring Tools generates the remote DevTools shared secret with a non-cryptographic pseudo-random generator.",
        "basis": [
          "CNA",
          "CWE-338"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://spring.io/security/cve-2026-47882",
          "host": "spring.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47896",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T14:21:24.921Z",
      "date_published": "2026-07-03T07:48:35.289Z",
      "date_updated": "2026-07-06T17:30:50.057Z",
      "publisher": "apache",
      "title": "Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Lucene.Net"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/RE:L"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:L/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00722,
        "percentile": 0.50431
      },
      "nvd": {
        "published": "2026-07-03T09:16:37.397",
        "lastModified": "2026-07-08T15:04:21.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47896",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7y9gbt17p55fh1zltks4pnh719wq9sqt",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/03/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 327,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47897",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T14:24:00.557Z",
      "date_published": "2026-07-03T07:48:11.367Z",
      "date_updated": "2026-07-06T17:31:22.410Z",
      "publisher": "apache",
      "title": "Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator client",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Lucene.Net"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/RE:L"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:L/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00605,
        "percentile": 0.45552
      },
      "nvd": {
        "published": "2026-07-03T08:16:24.817",
        "lastModified": "2026-07-08T18:29:03.233",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47897",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled path or object-name data is resolved without proving that the final target remains inside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/on1j3zmvgtf8n9fw78z3lyf6dn94p5zc",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/03/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47898",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T14:30:51.549Z",
      "date_published": "2026-07-03T07:47:38.904Z",
      "date_updated": "2026-07-06T17:32:25.185Z",
      "publisher": "apache",
      "title": "Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Lucene.Net"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 5.800000000000001,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27478
      },
      "nvd": {
        "published": "2026-07-03T08:16:24.977",
        "lastModified": "2026-07-08T18:25:07.617",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47898",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The XML parser resolves external entities from attacker-controlled input instead of disabling external resource expansion.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7yn9k6sbbsk18yco5y2hszpcf8dst489",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/03/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-47967",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.364Z",
      "date_published": "2026-07-14T17:48:51.495Z",
      "date_updated": "2026-07-15T03:59:32.975Z",
      "publisher": "adobe",
      "title": "Audition | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Audition"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08759
      },
      "nvd": {
        "published": "2026-07-14T18:17:18.680",
        "lastModified": "2026-07-15T05:16:40.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47967",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Audition writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/audition/apsb26-71.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47968",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.365Z",
      "date_published": "2026-07-14T17:48:48.673Z",
      "date_updated": "2026-07-15T03:59:35.315Z",
      "publisher": "adobe",
      "title": "Audition | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Audition"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08759
      },
      "nvd": {
        "published": "2026-07-14T18:17:18.810",
        "lastModified": "2026-07-15T05:16:40.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47968",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Audition writes outside a valid buffer while processing a malicious file.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/audition/apsb26-71.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47969",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.365Z",
      "date_published": "2026-07-14T17:48:50.082Z",
      "date_updated": "2026-07-14T21:12:40.444Z",
      "publisher": "adobe",
      "title": "Audition | Out-of-bounds Read (CWE-125)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Audition"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09716
      },
      "nvd": {
        "published": "2026-07-14T18:17:18.930",
        "lastModified": "2026-07-15T13:52:16.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47969",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can cause a read beyond the bounds of a valid buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/audition/apsb26-71.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47971",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.365Z",
      "date_published": "2026-07-14T19:58:56.119Z",
      "date_updated": "2026-07-15T10:36:44.052Z",
      "publisher": "adobe",
      "title": "Media Encoder | Stack-based Buffer Overflow (CWE-121)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Media Encoder"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00297,
        "percentile": 0.2202
      },
      "nvd": {
        "published": "2026-07-14T21:16:56.980",
        "lastModified": "2026-07-17T03:27:15.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47971",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted media file causes Media Encoder to write past a stack buffer.",
        "basis": [
          "CNA record",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/media-encoder/apsb26-72.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47976",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.365Z",
      "date_published": "2026-07-14T19:58:54.743Z",
      "date_updated": "2026-07-15T10:36:30.397Z",
      "publisher": "adobe",
      "title": "Media Encoder | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Media Encoder"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14534
      },
      "nvd": {
        "published": "2026-07-14T21:16:57.120",
        "lastModified": "2026-07-17T03:26:40.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47976",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Adobe Media Encoder lets attacker-controlled input reach an out-of-bounds write.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/media-encoder/apsb26-72.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47979",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.366Z",
      "date_published": "2026-07-14T19:58:54.039Z",
      "date_updated": "2026-07-15T14:29:35.569Z",
      "publisher": "adobe",
      "title": "Media Encoder | Out-of-bounds Read (CWE-125)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Media Encoder"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15009
      },
      "nvd": {
        "published": "2026-07-14T21:16:57.240",
        "lastModified": "2026-07-17T03:25:25.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47979",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Media Encoder reads beyond the end of a buffer while parsing a malicious file.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/media-encoder/apsb26-72.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-47984",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.366Z",
      "date_published": "2026-07-14T19:44:20.595Z",
      "date_updated": "2026-07-15T15:12:14.755Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00525,
        "percentile": 0.41596
      },
      "nvd": {
        "published": "2026-07-14T20:17:04.223",
        "lastModified": "2026-07-15T16:16:46.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47984",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Adobe identifies an authorization failure that permits unauthenticated read and write access, but the bulletin does not disclose the protected object, action, or missing permission check.",
        "basis": [
          "CNA",
          "CWE-863",
          "Adobe APSB26-73"
        ],
        "deepDive": true,
        "notes": "https://helpx.adobe.com/security/products/magento/apsb26-73.html - Adobe lists incorrect authorization and security-feature bypass, but no protected action, object, or permission check; the bulletin lists CVSS 8.2 while the embedded shard maximum is 9.1."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 299,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-47988",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.367Z",
      "date_published": "2026-07-14T19:44:19.146Z",
      "date_updated": "2026-07-15T14:09:20.789Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00525,
        "percentile": 0.41596
      },
      "nvd": {
        "published": "2026-07-14T20:17:04.347",
        "lastModified": "2026-07-15T15:35:15.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47988",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Adobe confirms an authorization bypass in Commerce but does not publish the protected operation or the authorization predicate that fails.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-863",
          "Adobe security bulletin"
        ],
        "deepDive": true,
        "notes": "Inspected Adobe bulletin https://helpx.adobe.com/security/products/magento/apsb26-73.html; it confirms CWE-863, a security-feature bypass, affected branches, and fixed builds, but publishes no protected operation, authorization predicate, or patch."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 299,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-47992",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.367Z",
      "date_published": "2026-07-14T19:44:11.362Z",
      "date_updated": "2026-07-15T10:27:34.223Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.19924,
        "percentile": 0.97166
      },
      "nvd": {
        "published": "2026-07-14T20:17:04.470",
        "lastModified": "2026-07-15T15:33:23.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47992",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Adobe Commerce accepts high-privileged input as SQL syntax, although Adobe's current bulletin labels the issue as generic input validation and does not publish the query or parameter.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Adobe bulletin APSB26-73 at https://helpx.adobe.com/security/products/magento/apsb26-73.html; its current table maps CVE-2026-47992 to CWE-20 and privilege escalation with CVSS 7.2, while the embedded CVE record calls it SQL injection and maps CWE-89, and the bulletin publishes no query, parameter, or patch logic; Adobe also reports no known exploitation."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-47994",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.367Z",
      "date_published": "2026-07-14T19:44:12.075Z",
      "date_updated": "2026-07-16T14:45:34.163Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00622,
        "percentile": 0.46405
      },
      "nvd": {
        "published": "2026-07-14T20:17:04.597",
        "lastModified": "2026-07-29T19:17:24.027",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47994",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Adobe Commerce rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-47995",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.367Z",
      "date_published": "2026-07-14T19:44:14.936Z",
      "date_updated": "2026-07-15T14:27:20.329Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00397,
        "percentile": 0.32458
      },
      "nvd": {
        "published": "2026-07-14T20:17:04.727",
        "lastModified": "2026-07-29T19:17:20.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47995",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker input enters an executable interpreter context without grammar-safe encoding or parameterization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 411,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-47996",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.367Z",
      "date_published": "2026-07-14T19:44:12.787Z",
      "date_updated": "2026-07-15T12:56:51.887Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.20054,
        "percentile": 0.9718
      },
      "nvd": {
        "published": "2026-07-14T20:17:04.840",
        "lastModified": "2026-07-15T14:31:11.823",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47996",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Adobe Commerce operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-863",
          "Adobe APSB26-73"
        ],
        "deepDive": true,
        "notes": "Read Adobe APSB26-73 https://helpx.adobe.com/security/products/magento/apsb26-73.html; it confirms a high-privilege incorrect-authorization security-feature bypass but does not identify the protected action, object, or failed authorization predicate."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-47997",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.367Z",
      "date_published": "2026-07-14T19:44:19.854Z",
      "date_updated": "2026-07-15T15:12:20.602Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.08993,
        "percentile": 0.94746
      },
      "nvd": {
        "published": "2026-07-14T20:17:04.960",
        "lastModified": "2026-07-15T16:16:46.907",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47997",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Adobe Commerce contains an authorization bypass, but the public record does not identify the protected action, object, or failing permission check.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 350,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-47998",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.368Z",
      "date_published": "2026-07-14T19:44:16.347Z",
      "date_updated": "2026-07-15T14:08:52.584Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00633,
        "percentile": 0.46893
      },
      "nvd": {
        "published": "2026-07-14T20:17:05.080",
        "lastModified": "2026-07-15T15:16:35.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47998",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Adobe Commerce permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 350,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-47999",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.368Z",
      "date_published": "2026-07-14T19:44:18.454Z",
      "date_updated": "2026-07-15T17:39:53.384Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.07076,
        "percentile": 0.93573
      },
      "nvd": {
        "published": "2026-07-14T20:17:05.200",
        "lastModified": "2026-07-15T18:16:46.193",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-47999",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-48000",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.368Z",
      "date_published": "2026-07-14T19:44:15.654Z",
      "date_updated": "2026-07-16T14:46:10.054Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1.7999999999999998,
      "epss": {
        "score": 0.00353,
        "percentile": 0.27949
      },
      "nvd": {
        "published": "2026-07-14T20:17:05.320",
        "lastModified": "2026-07-16T16:19:09.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48000",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-48001",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T15:50:31.368Z",
      "date_published": "2026-07-14T19:44:14.208Z",
      "date_updated": "2026-07-15T14:26:32.819Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Information Exposure (CWE-200)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00564,
        "percentile": 0.43676
      },
      "nvd": {
        "published": "2026-07-14T20:17:05.443",
        "lastModified": "2026-07-15T15:16:36.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48001",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected interface returns, embeds or leaves protected information visible to an observer who is not entitled to receive it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-48008",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.586Z",
      "date_published": "2026-07-17T17:47:27.906Z",
      "date_updated": "2026-07-17T19:47:56.823Z",
      "publisher": "GitHub_M",
      "title": "Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass",
      "affected": {
        "vendors": [
          "shopware"
        ],
        "products": [
          {
            "vendor": "shopware",
            "product": "shopware"
          },
          {
            "vendor": "shopware",
            "product": "platform"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18159
      },
      "nvd": {
        "published": "2026-07-17T18:17:15.713",
        "lastModified": "2026-07-17T20:17:19.337",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48008",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Sync API can write the integration admin field without the WriteProtection enforced by the ordinary integration endpoint.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/shopware/shopware/security/advisories/GHSA-gv8p-48fr-4fxg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/1e047f6d7fd9129271e28c1c9f1c272983c6f48f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/db5adff33ec30b648979cd1938c87f164f7b3073",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.6.10.18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.7.10.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48009",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.586Z",
      "date_published": "2026-07-17T17:58:15.568Z",
      "date_updated": "2026-07-17T19:08:02.871Z",
      "publisher": "GitHub_M",
      "title": "Shopware: Admin Account Takeover via User Recovery Hash Exposure",
      "affected": {
        "vendors": [
          "shopware"
        ],
        "products": [
          {
            "vendor": "shopware",
            "product": "shopware"
          },
          {
            "vendor": "shopware",
            "product": "platform"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19384
      },
      "nvd": {
        "published": "2026-07-17T18:17:15.863",
        "lastModified": "2026-07-17T20:17:19.973",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48009",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Shopware exposes password-recovery hashes through the Admin API to a low-privilege read role without field-level read protection.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/shopware/shopware/security/advisories/GHSA-8v9p-g828-v98f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/06f8b9aa4fecb239a2ff33a6546192d7ce7ed0f8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/9ef4873f810e26fb38da051624f7f2720139279a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/d82c23d8d5b22dd722c8f76c4f66785d1a7a72d8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.6.10.18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.7.10.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 567,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48010",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.586Z",
      "date_published": "2026-07-17T17:55:25.722Z",
      "date_updated": "2026-07-17T23:15:41.762Z",
      "publisher": "GitHub_M",
      "title": "Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts",
      "affected": {
        "vendors": [
          "shopware"
        ],
        "products": [
          {
            "vendor": "shopware",
            "product": "shopware"
          },
          {
            "vendor": "shopware",
            "product": "platform"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18159
      },
      "nvd": {
        "published": "2026-07-17T18:17:16.023",
        "lastModified": "2026-07-18T00:16:48.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48010",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "UserController writes a caller-supplied admin flag in system scope without checking that the API caller is already an administrator.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/shopware/shopware/security/advisories/GHSA-v39m-97p8-gqg7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/7f1cef324ca4edfa6369264cc1c41287d032624d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/d8d9a34a9255abf69c2798015a17cd6a80b08c25",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.6.10.18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.7.10.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48012",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.586Z",
      "date_published": "2026-07-23T19:16:38.956Z",
      "date_updated": "2026-07-24T13:31:43.099Z",
      "publisher": "GitHub_M",
      "title": "Shopware SSO referer trust leading to an arbitrary redirect target",
      "affected": {
        "vendors": [
          "shopware"
        ],
        "products": [
          {
            "vendor": "shopware",
            "product": "shopware"
          },
          {
            "vendor": "shopware",
            "product": "platform"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05834
      },
      "nvd": {
        "published": "2026-07-23T20:17:08.777",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48012",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SSO entry point trusts an arbitrary Referer as a redirect target without same-origin, relative-path, or safe-scheme validation.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/shopware/shopware/security/advisories/GHSA-4x3x-869w-xx3m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.7.10.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1781,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48013",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.586Z",
      "date_published": "2026-07-23T19:14:32.579Z",
      "date_updated": "2026-07-23T19:27:54.530Z",
      "publisher": "GitHub_M",
      "title": "Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation",
      "affected": {
        "vendors": [
          "shopware"
        ],
        "products": [
          {
            "vendor": "shopware",
            "product": "shopware"
          },
          {
            "vendor": "shopware",
            "product": "platform"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11759
      },
      "nvd": {
        "published": "2026-07-23T20:17:08.920",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48013",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The external-link endpoint checks only the URL scheme and sends a server-side HEAD request without rejecting private, loopback, or metadata destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/shopware/shopware/security/advisories/GHSA-gq96-5pfx-f4vc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.6.10.18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.7.10.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.586Z",
      "date_published": "2026-07-17T17:56:43.236Z",
      "date_updated": "2026-07-21T01:48:04.992Z",
      "publisher": "GitHub_M",
      "title": "Shopware: Admin API ACL Bypass in Order State Transition Endpoints",
      "affected": {
        "vendors": [
          "shopware"
        ],
        "products": [
          {
            "vendor": "shopware",
            "product": "shopware"
          },
          {
            "vendor": "shopware",
            "product": "platform"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14312
      },
      "nvd": {
        "published": "2026-07-17T18:17:16.177",
        "lastModified": "2026-07-21T03:16:41.510",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48014",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Order transition routes omit both ACL metadata and an explicit privilege check before performing state-machine writes in system scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/shopware/shopware/security/advisories/GHSA-f8q6-3g5w-jjr6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/86dff24ba500e16325742e59d20357f57a79c2af",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/9f15faee704b61e8a96657024fa96c70b47ad082",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.6.10.18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.7.10.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 644,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48015",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.586Z",
      "date_published": "2026-07-17T17:53:01.695Z",
      "date_updated": "2026-07-17T18:11:57.809Z",
      "publisher": "GitHub_M",
      "title": "Shopware: Stored XSS via SVG file upload — no SVG sanitization",
      "affected": {
        "vendors": [
          "shopware"
        ],
        "products": [
          {
            "vendor": "shopware",
            "product": "shopware"
          },
          {
            "vendor": "shopware",
            "product": "platform"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20068
      },
      "nvd": {
        "published": "2026-07-17T18:17:16.323",
        "lastModified": "2026-07-17T19:17:15.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48015",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Shopware serves uploaded SVG content without sanitizing executable SVG elements and event handlers.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/shopware/shopware/security/advisories/GHSA-xvhc-gm7j-mhmc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/745a3ea3b77d4fe0f78c595ef527d8453a134497",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/fd6d39bdb62dfa06fe62c7c87b37607d84094cda",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.6.10.18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.7.10.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 541,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48016",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.586Z",
      "date_published": "2026-07-17T17:54:21.990Z",
      "date_updated": "2026-07-20T19:27:17.356Z",
      "publisher": "GitHub_M",
      "title": "Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment",
      "affected": {
        "vendors": [
          "shopware"
        ],
        "products": [
          {
            "vendor": "shopware",
            "product": "shopware"
          },
          {
            "vendor": "shopware",
            "product": "platform"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14957
      },
      "nvd": {
        "published": "2026-07-17T18:17:16.457",
        "lastModified": "2026-07-20T20:16:43.937",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48016",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The payment endpoint accepts an orderId without proving that the current customer or guest owns that order.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/shopware/shopware/security/advisories/GHSA-9v5m-39wh-5chq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/69dd5b6cb01d3c2aea49ac29dd4512a87836ac3f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/commit/df15f2e607dcf9ebc4a26ec622ffcf452dc25090",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.6.10.18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/shopware/shopware/releases/tag/v6.7.10.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48021",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.587Z",
      "date_published": "2026-07-24T18:26:57.751Z",
      "date_updated": "2026-07-25T00:57:07.063Z",
      "publisher": "GitHub_M",
      "title": "epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau",
      "affected": {
        "vendors": [
          "med-united"
        ],
        "products": [
          {
            "vendor": "med-united",
            "product": "epa4all"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02542
      },
      "nvd": {
        "published": "2026-07-24T19:16:58.033",
        "lastModified": "2026-07-30T19:19:45.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48021",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "epa4all establishes an encrypted connection without validating the peer certificate or host key, allowing an active network attacker to substitute its own endpoint.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-295",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/med-united/epa4all/security/advisories/GHSA-vvh7-x6c7-46gh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/med-united/epa4all/releases/tag/2026-05-20",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://www.machinespirits.com/advisory/aa49f0",
          "host": "www.machinespirits.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 524,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48022",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.587Z",
      "date_published": "2026-07-17T21:02:05.980Z",
      "date_updated": "2026-07-20T19:10:59.345Z",
      "publisher": "GitHub_M",
      "title": "@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects",
      "affected": {
        "vendors": [
          "hapijs"
        ],
        "products": [
          {
            "vendor": "hapijs",
            "product": "wreck"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-319",
          "name": "Cleartext Transmission of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02279
      },
      "nvd": {
        "published": "2026-07-17T22:17:14.413",
        "lastModified": "2026-07-23T16:10:54.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48022",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Wreck compares redirect hostnames without scheme or port, so it forwards credential headers across a cross-port or HTTPS-to-HTTP origin change.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-319",
          "CWE-346",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hapijs/wreck/security/advisories/GHSA-x426-x7cc-3fpc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hapijs/wreck/pull/313",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapijs/wreck/commit/b93323b63ad3adb14d2b4019d77219182211641e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapijs/wreck/releases/tag/v18.1.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 619,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48025",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.587Z",
      "date_published": "2026-07-28T17:40:37.329Z",
      "date_updated": "2026-07-29T13:55:01.392Z",
      "publisher": "GitHub_M",
      "title": "nebula-mesh: Decrypted CA private key persists in heap after signing",
      "affected": {
        "vendors": [
          "juev"
        ],
        "products": [
          {
            "vendor": "juev",
            "product": "nebula-mesh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-244",
          "name": "Improper Clearing of Heap Memory Before Release ('Heap Inspection')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21382
      },
      "nvd": {
        "published": "2026-07-28T18:17:20.583",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48025",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "nebula-mesh drops its last reference to a plaintext CA private key without zeroing the backing slice, leaving the key in heap memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-244"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-8h84-fhqq-q58v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/commit/bca1d5914fbaf3517d3b86145a802c00de4a8122",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 915,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48029",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.587Z",
      "date_published": "2026-07-22T14:13:27.879Z",
      "date_updated": "2026-07-22T15:20:39.509Z",
      "publisher": "GitHub_M",
      "title": "libheif: heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow",
      "affected": {
        "vendors": [
          "strukturag"
        ],
        "products": [
          {
            "vendor": "strukturag",
            "product": "libheif"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18697
      },
      "nvd": {
        "published": "2026-07-22T15:17:18.357",
        "lastModified": "2026-07-22T20:38:42.127",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48029",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An irot-induced tile-coordinate underflow makes ImageItem_Grid::decode_grid_tile read outside a heap allocation.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/strukturag/libheif/security/advisories/GHSA-6x5f-qchq-cxqv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/strukturag/libheif/commit/e523ec0bf379110b7c33d4c159f8b1202d332157",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48030",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T17:44:09.588Z",
      "date_published": "2026-07-27T17:53:34.438Z",
      "date_updated": "2026-07-27T18:53:42.856Z",
      "publisher": "GitHub_M",
      "title": "Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78)",
      "affected": {
        "vendors": [
          "pheditor"
        ],
        "products": [
          {
            "vendor": "pheditor",
            "product": "pheditor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01545,
        "percentile": 0.72532
      },
      "nvd": {
        "published": "2026-07-27T18:16:55.347",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48030",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pheditor places the dir parameter into a shell command without neutralizing shell metacharacters.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pheditor/pheditor/security/advisories/GHSA-jvc5-6g7q-c843",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pheditor/pheditor/releases/tag/2.0.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 474,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48032",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:15:53.577Z",
      "date_published": "2026-07-24T18:39:05.061Z",
      "date_updated": "2026-07-27T17:20:38.935Z",
      "publisher": "GitHub_M",
      "title": "Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers",
      "affected": {
        "vendors": [
          "kerberosmansour"
        ],
        "products": [
          {
            "vendor": "kerberosmansour",
            "product": "hulumi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-697",
          "name": "Incorrect Comparison",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00309,
        "percentile": 0.23278
      },
      "nvd": {
        "published": "2026-07-24T19:16:58.190",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48032",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Hulumi's IAM policy validation compares multi-OIDC-provider policy forms incorrectly and accepts a role policy outside the intended trust constraints.",
        "basis": [
          "CNA",
          "CWE-697"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-g759-4pxw-6692",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/pull/178",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48033",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:15:53.577Z",
      "date_published": "2026-07-24T18:39:18.532Z",
      "date_updated": "2026-07-24T19:16:19.349Z",
      "publisher": "GitHub_M",
      "title": "Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name",
      "affected": {
        "vendors": [
          "kerberosmansour"
        ],
        "products": [
          {
            "vendor": "kerberosmansour",
            "product": "hulumi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.1969
      },
      "nvd": {
        "published": "2026-07-24T19:16:58.340",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48033",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Hulumi compares an unnormalized Pulumi URN against a trusted prefix, then resolves the name differently when policy is enforced, allowing a forged logical name to evade policy packs.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-rhgj-6g2c-frmm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/pull/178",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48034",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:15:53.577Z",
      "date_published": "2026-07-24T18:38:53.735Z",
      "date_updated": "2026-07-24T20:15:32.345Z",
      "publisher": "GitHub_M",
      "title": "HULUMI-H5 bypass via decoy sibling resources targeting a different bucket",
      "affected": {
        "vendors": [
          "kerberosmansour"
        ],
        "products": [
          {
            "vendor": "kerberosmansour",
            "product": "hulumi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17424
      },
      "nvd": {
        "published": "2026-07-24T19:16:58.477",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48034",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The record identifies a cross-bucket policy bypass using a decoy sibling resource but does not disclose the exact resource-selection check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-9vc9-4jv3-rf86",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/pull/175",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/pull/178",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 264,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48035",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:15:53.577Z",
      "date_published": "2026-07-24T18:43:35.696Z",
      "date_updated": "2026-07-27T20:23:56.410Z",
      "publisher": "GitHub_M",
      "title": "Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened",
      "affected": {
        "vendors": [
          "kerberosmansour"
        ],
        "products": [
          {
            "vendor": "kerberosmansour",
            "product": "hulumi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1059",
          "name": "Insufficient Technical Documentation",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Prohibited",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17554
      },
      "nvd": {
        "published": "2026-07-24T19:16:58.617",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48035",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The infrastructure component creates an audit bucket whose deletion controls do not match the advertised tamper-resistant tier.",
        "basis": [
          "CNA",
          "CWE-1059"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-2mxr-p26x-mj73",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/pull/178",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48036",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:15:53.577Z",
      "date_published": "2026-07-24T18:44:05.631Z",
      "date_updated": "2026-07-25T00:58:23.970Z",
      "publisher": "GitHub_M",
      "title": "Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts",
      "affected": {
        "vendors": [
          "kerberosmansour"
        ],
        "products": [
          {
            "vendor": "kerberosmansour",
            "product": "hulumi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-755",
          "name": "Improper Handling of Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21629
      },
      "nvd": {
        "published": "2026-07-24T19:16:58.753",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48036",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The drift workflow caches transient adapter failures as a clean result and can promote ordinary provider churn to an incident, making the persisted verdict diverge from the underlying check.",
        "basis": [
          "CNA",
          "CWE-755"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-32g3-35g9-wc9g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/pull/178",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 523,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48037",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:15:53.577Z",
      "date_published": "2026-07-24T18:44:23.652Z",
      "date_updated": "2026-07-27T16:05:37.812Z",
      "publisher": "GitHub_M",
      "title": "Hulumi: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture",
      "affected": {
        "vendors": [
          "kerberosmansour"
        ],
        "products": [
          {
            "vendor": "kerberosmansour",
            "product": "hulumi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17555
      },
      "nvd": {
        "published": "2026-07-24T19:16:58.897",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48037",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "AccountFoundation's reuse path silently applies a weaker GuardDuty and Security Hub configuration than the secure default.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-cj8g-prcm-mfg5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/pull/178",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48038",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:15:53.577Z",
      "date_published": "2026-07-14T19:24:32.644Z",
      "date_updated": "2026-07-15T13:27:13.334Z",
      "publisher": "GitHub_M",
      "title": "joi: Uncaught RangeError on deeply nested input through recursive `link()` schemas",
      "affected": {
        "vendors": [
          "hapijs"
        ],
        "products": [
          {
            "vendor": "hapijs",
            "product": "joi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22468
      },
      "nvd": {
        "published": "2026-07-14T20:17:05.563",
        "lastModified": "2026-07-15T20:22:55.353",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48038",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Deeply nested input traverses recursive link schemas until validate raises an unhandled RangeError that can terminate the request process.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hapijs/joi/security/advisories/GHSA-q7cg-457f-vx79",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hapijs/joi/pull/3113",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapijs/joi/commit/97bd51de94d595a2d8949eb3bec0dbdd2f8a7a74",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapijs/joi/commit/fc146a628ab9cc250854407722d9f8738c9548e7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48045",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:15:53.578Z",
      "date_published": "2026-07-17T18:26:19.274Z",
      "date_updated": "2026-07-17T19:21:38.396Z",
      "publisher": "GitHub_M",
      "title": "Zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood",
      "affected": {
        "vendors": [
          "python-zeroconf"
        ],
        "products": [
          {
            "vendor": "python-zeroconf",
            "product": "python-zeroconf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13884
      },
      "nvd": {
        "published": "2026-07-17T19:17:15.820",
        "lastModified": "2026-07-23T16:13:02.287",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48045",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Deferred traffic-control queries create lists and timers without an effective bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-9663-mqmp-p9mm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/pull/1751",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/commit/b22c8ff19c66c68907d220a4823c0950f4fa93f7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/releases/tag/0.149.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48049",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:15:53.578Z",
      "date_published": "2026-07-17T21:03:16.577Z",
      "date_updated": "2026-07-21T02:26:04.404Z",
      "publisher": "GitHub_M",
      "title": "@hapi/inert: Static-file confinement bypass via sibling-prefix path",
      "affected": {
        "vendors": [
          "hapijs"
        ],
        "products": [
          {
            "vendor": "hapijs",
            "product": "inert"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00446,
        "percentile": 0.36666
      },
      "nvd": {
        "published": "2026-07-17T22:17:14.557",
        "lastModified": "2026-07-23T16:10:54.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48049",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A raw string-prefix confinement check treats a sibling directory sharing the configured prefix as inside the static-file root.",
        "basis": [
          "CNA record",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hapijs/inert/security/advisories/GHSA-rcvq-m9j9-6f4g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hapijs/inert/pull/176",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapijs/inert/commit/bcceb761a43b9d1178eb6bd553e4ad2bb70494d9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapijs/inert/releases/tag/v7.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 628,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48051",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:15:53.578Z",
      "date_published": "2026-07-27T17:59:39.206Z",
      "date_updated": "2026-07-28T14:54:23.072Z",
      "publisher": "GitHub_M",
      "title": "Papra: SSRF via HTTP redirect bypass in webhook delivery",
      "affected": {
        "vendors": [
          "papra-hq"
        ],
        "products": [
          {
            "vendor": "papra-hq",
            "product": "papra"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10957
      },
      "nvd": {
        "published": "2026-07-27T18:16:55.633",
        "lastModified": "2026-07-30T19:16:52.210",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48051",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "papra accepts an attacker-controlled server request target without constraining it to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/papra-hq/papra/security/advisories/GHSA-5g86-85rp-f9hx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 849,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48052",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:15:53.579Z",
      "date_published": "2026-07-27T18:00:27.990Z",
      "date_updated": "2026-07-27T18:23:54.469Z",
      "publisher": "GitHub_M",
      "title": "Papra: Cross-organization tag deletion and modification via authenticated cross-tenant request",
      "affected": {
        "vendors": [
          "papra-hq"
        ],
        "products": [
          {
            "vendor": "papra-hq",
            "product": "papra"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11518
      },
      "nvd": {
        "published": "2026-07-27T18:16:55.780",
        "lastModified": "2026-07-30T19:16:52.210",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48052",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The tag mutation verifies URL-organization membership but updates by tag ID alone, so the database write can target another organization.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/papra-hq/papra/security/advisories/GHSA-wrx4-3vff-jm94",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/papra-hq/papra/pull/1080",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/papra-hq/papra/commit/47d44e0681bf59da0638b140d1c5ef5b970f6b67",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 482,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48058",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:25:25.707Z",
      "date_published": "2026-07-28T18:47:57.916Z",
      "date_updated": "2026-07-28T19:16:39.082Z",
      "publisher": "GitHub_M",
      "title": "nebula-mesh: Session and OIDC state cookies lack the Secure attribute",
      "affected": {
        "vendors": [
          "juev"
        ],
        "products": [
          {
            "vendor": "juev",
            "product": "nebula-mesh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-614",
          "name": "Sensitive Cookie in HTTPS Session Without 'Secure' Attribute",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09256
      },
      "nvd": {
        "published": "2026-07-28T19:17:34.747",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48058",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "nebula-mesh omits the Secure attribute from session and OIDC cookies, allowing a plaintext request to send those credentials outside the intended HTTPS channel.",
        "basis": [
          "CNA",
          "CWE-614"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-rqfj-vv8r-xhqc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/commit/ffdd67dbf221d9a5855c39fbe11b49c245048d85",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48060",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:25:25.707Z",
      "date_published": "2026-07-28T19:02:40.207Z",
      "date_updated": "2026-07-28T19:39:13.421Z",
      "publisher": "GitHub_M",
      "title": "Litestar: HTML Injection Through CSRF Token",
      "affected": {
        "vendors": [
          "litestar-org"
        ],
        "products": [
          {
            "vendor": "litestar-org",
            "product": "litestar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20645
      },
      "nvd": {
        "published": "2026-07-28T20:17:25.760",
        "lastModified": "2026-07-30T20:02:12.943",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48060",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/litestar-org/litestar/security/advisories/GHSA-542p-wvx7-72m4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/litestar-org/litestar/releases/tag/v2.20.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 465,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48062",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:25:25.707Z",
      "date_published": "2026-07-17T20:36:29.676Z",
      "date_updated": "2026-07-20T13:47:15.742Z",
      "publisher": "GitHub_M",
      "title": "CodeIgniter: Uploaded file extension validation bypass in `ext_in` rule",
      "affected": {
        "vendors": [
          "codeigniter4"
        ],
        "products": [
          {
            "vendor": "codeigniter4",
            "product": "CodeIgniter4"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00438,
        "percentile": 0.36045
      },
      "nvd": {
        "published": "2026-07-17T21:17:06.787",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48062",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ext_in validates the MIME-derived guessed extension instead of the client filename extension, allowing executable filenames with benign-looking content to pass upload validation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-2gr4-ppc7-7mhx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/commit/29299349e7d232e9532767c7cefaed30957309be",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 937,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48068",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:25:25.708Z",
      "date_published": "2026-07-14T19:39:42.607Z",
      "date_updated": "2026-07-21T14:56:52.473Z",
      "publisher": "GitHub_M",
      "title": "@grpc/grps-js: A malformed request can cause a server crash",
      "affected": {
        "vendors": [
          "grpc"
        ],
        "products": [
          {
            "vendor": "grpc",
            "product": "grpc-node"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00617,
        "percentile": 0.46138
      },
      "nvd": {
        "published": "2026-07-14T20:17:05.710",
        "lastModified": "2026-07-21T16:17:13.210",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48068",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The grpc-node request path lets attacker-controlled input reach an uncaught exception that terminates service processing.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grpc/grpc-node/security/advisories/GHSA-5375-pq7m-f5r2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/commit/058665a6c6dae445e2ab0f3f6259164fac52ee17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/commit/1cf4bfa738b15e59cc3daf49ffa24c04f9b626f7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/commit/234f9172b2ff35e586ca7d4e788557aad5985668",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/commit/455efce8acb7fb249652a74c1618a6d7daf1faba",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/commit/b1b7268f7b81b92c6f03f5128dfd871c08aeb903",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/commit/e2c035aab2fe5e55d46d5fc427481497314a53a4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 13,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48069",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:25:25.708Z",
      "date_published": "2026-07-14T19:42:32.883Z",
      "date_updated": "2026-07-15T13:27:06.200Z",
      "publisher": "GitHub_M",
      "title": "@grpc/grps-js: An incoming malformed compressed message can cause a client or server crash",
      "affected": {
        "vendors": [
          "grpc"
        ],
        "products": [
          {
            "vendor": "grpc",
            "product": "grpc-node"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00617,
        "percentile": 0.46137
      },
      "nvd": {
        "published": "2026-07-14T20:17:05.867",
        "lastModified": "2026-07-15T20:23:47.313",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48069",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A malformed compressed message raises an uncaught exception that terminates the serving path.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grpc/grpc-node/security/advisories/GHSA-99f4-grh7-6pcq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/commit/2375eadcc52ca2b1ef55288bcd6355168b02706c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/commit/2fe55fd76a8bb59eaab5f39e3552b5f84985a163",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/commit/4091bd902105f8fb655741758aee71418c48b5d5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/commit/b3f16094473b5c8f38b0955eafa4a19507127346",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/commit/b61c4d65953db85c2ae55b4b3cd98a4259dc87cb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/commit/b6dcfc3cee9ef390e5869ebea5a8c5ae187720b9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 13,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48125",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:46:58.291Z",
      "date_published": "2026-07-14T20:54:56.374Z",
      "date_updated": "2026-07-15T12:55:20.077Z",
      "publisher": "GitHub_M",
      "title": "UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`",
      "affected": {
        "vendors": [
          "faisalman"
        ],
        "products": [
          {
            "vendor": "faisalman",
            "product": "ua-parser-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29901
      },
      "nvd": {
        "published": "2026-07-14T21:16:57.347",
        "lastModified": "2026-07-15T20:21:03.480",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48125",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ua-parser-js parser performs superlinear work on attacker-controlled input without an effective work bound.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/faisalman/ua-parser-js/security/advisories/GHSA-9h5v-pfqq-x599",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/faisalman/ua-parser-js/commit/90354d3458495628b1d3ba68a9d76673e6d14fc5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/faisalman/ua-parser-js/releases/tag/2.0.10",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 574,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48127",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T18:46:58.292Z",
      "date_published": "2026-07-10T21:23:37.101Z",
      "date_updated": "2026-07-14T14:13:11.460Z",
      "publisher": "GitHub_M",
      "title": "Frappe: Arbitrary Attachment Injection via add_attachments and upload_file",
      "affected": {
        "vendors": [
          "frappe"
        ],
        "products": [
          {
            "vendor": "frappe",
            "product": "frappe"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29597
      },
      "nvd": {
        "published": "2026-07-10T22:16:42.140",
        "lastModified": "2026-07-14T15:17:02.070",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48127",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Frappe allows a caller without write access to attach a file to an object selected by that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frappe/frappe/security/advisories/GHSA-fwrv-4rw4-97fw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/39407",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/39550",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/39553",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/4bf27db101c34bd542a760290fc0775efa5cd0e4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/b1c86042e6f85986f35365c80bb1d102ff1cd0e4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/fee1af6d89910f6b174fd094184060aeb641d07d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/releases/tag/v15.110.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/releases/tag/v16.20.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T22:31:12.384Z",
      "date_published": "2026-07-27T10:58:31.112Z",
      "date_updated": "2026-07-28T03:55:50.038Z",
      "publisher": "apache",
      "title": "Apache Thrift: c_glib TLS Client Missing Hostname Verification",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-297",
          "name": "Improper Validation of Certificate with Host Mismatch",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34393
      },
      "nvd": {
        "published": "2026-07-27T12:16:44.700",
        "lastModified": "2026-07-28T05:17:06.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48144",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.",
        "basis": [
          "CNA",
          "CWE-297"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/2xoltfxgzf5jyhcwq6y07spts5cn6ppj",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/35",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-20T22:45:26.457Z",
      "date_published": "2026-07-27T10:59:46.107Z",
      "date_updated": "2026-07-27T13:03:08.355Z",
      "publisher": "apache",
      "title": "Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-297",
          "name": "Improper Validation of Certificate with Host Mismatch",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00435,
        "percentile": 0.35829
      },
      "nvd": {
        "published": "2026-07-27T12:16:44.840",
        "lastModified": "2026-07-27T19:49:14.997",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48145",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Certificate hostname matching accepts a wildcard relationship that does not establish the requested host identity.",
        "basis": [
          "CNA",
          "CWE-297"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/2popgc4ks1l87jjho1w5fpk5k4x06b7h",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/36",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 224,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48203",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T08:58:37.029Z",
      "date_published": "2026-07-06T08:06:22.592Z",
      "date_updated": "2026-07-06T19:17:53.635Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29692
      },
      "nvd": {
        "published": "2026-07-06T09:16:37.633",
        "lastModified": "2026-07-08T03:14:47.170",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48203",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Camel's HTTP header filter passes SolrParam.* and SolrField.* across an untrusted ingress, letting clients control Solr request destinations and document fields.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-74",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "http://camel.apache.org/security/CVE-2026-48203.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/17",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2191,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-48204",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T09:00:09.248Z",
      "date_published": "2026-07-06T08:06:52.913Z",
      "date_updated": "2026-07-06T19:08:16.754Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00452,
        "percentile": 0.37024
      },
      "nvd": {
        "published": "2026-07-06T09:16:37.760",
        "lastModified": "2026-07-08T03:14:37.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48204",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Apache Camel lets untrusted HTTP headers select a privileged GridFS operation or object instead of separating transport metadata from the component's trusted control headers.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-48204.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/18",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2249,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-48205",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T09:01:03.728Z",
      "date_published": "2026-07-06T08:08:19.869Z",
      "date_updated": "2026-07-06T19:07:20.497Z",
      "publisher": "apache",
      "title": "Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel DNS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29693
      },
      "nvd": {
        "published": "2026-07-06T09:16:37.880",
        "lastModified": "2026-07-08T03:14:28.607",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48205",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Camel's HTTP header filter lets raw dns.server and lookup headers cross into the DNS producer, allowing the requester to select the resolver and internal lookup target.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-48205.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/19",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2107,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-48206",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T09:02:10.464Z",
      "date_published": "2026-07-06T08:09:09.027Z",
      "date_updated": "2026-07-06T19:06:19.319Z",
      "publisher": "apache",
      "title": "Apache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel JIRA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00349,
        "percentile": 0.276
      },
      "nvd": {
        "published": "2026-07-06T09:16:38.000",
        "lastModified": "2026-07-08T03:14:18.167",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48206",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Non-Camel-prefixed JIRA control headers cross the HTTP filter and override trusted route parameters while operations run with the configured service account.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-48206.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/20",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2361,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-48252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.130Z",
      "date_published": "2026-07-14T19:20:55.762Z",
      "date_updated": "2026-07-15T19:38:47.824Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Missing Authentication for Critical Function (CWE-306)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29836
      },
      "nvd": {
        "published": "2026-07-14T20:17:06.053",
        "lastModified": "2026-07-17T17:46:06.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48252",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A critical Experience Manager write function is reachable without the authentication required for that operation.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48253",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.130Z",
      "date_published": "2026-07-14T19:20:57.257Z",
      "date_updated": "2026-07-15T19:38:49.301Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06426
      },
      "nvd": {
        "published": "2026-07-14T20:17:06.197",
        "lastModified": "2026-07-17T17:46:02.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48253",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Experience Manager lets attacker-controlled DOM data enter a JavaScript-capable browser context without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48254",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.130Z",
      "date_published": "2026-07-14T19:20:53.631Z",
      "date_updated": "2026-07-15T19:38:46.763Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06426
      },
      "nvd": {
        "published": "2026-07-14T20:17:06.320",
        "lastModified": "2026-07-17T17:45:59.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48254",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled DOM data is interpreted as executable JavaScript in the Experience Manager origin, although the exact source and sink are not public.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48255",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.130Z",
      "date_published": "2026-07-14T19:20:55.054Z",
      "date_updated": "2026-07-15T19:38:48.918Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06427
      },
      "nvd": {
        "published": "2026-07-14T20:17:06.443",
        "lastModified": "2026-07-17T17:45:54.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48255",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Adobe Experience Manager as a Cloud Service page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48257",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.130Z",
      "date_published": "2026-07-14T19:20:54.339Z",
      "date_updated": "2026-07-16T14:41:42.407Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06426
      },
      "nvd": {
        "published": "2026-07-14T20:17:06.570",
        "lastModified": "2026-07-17T17:45:12.267",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48257",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled DOM data reaches browser execution as JavaScript in the Adobe Experience Manager origin.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48259",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.131Z",
      "date_published": "2026-07-14T19:21:01.631Z",
      "date_updated": "2026-07-15T19:38:48.192Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00682,
        "percentile": 0.48949
      },
      "nvd": {
        "published": "2026-07-14T20:17:06.697",
        "lastModified": "2026-07-17T17:45:51.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48259",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The URL validation in Adobe Experience Manager as a Cloud Service permits an attacker-selected destination to reach private, loopback, metadata, or otherwise restricted services.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48260",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.131Z",
      "date_published": "2026-07-14T19:20:59.376Z",
      "date_updated": "2026-07-15T19:38:47.109Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06426
      },
      "nvd": {
        "published": "2026-07-14T20:17:06.820",
        "lastModified": "2026-07-17T17:45:41.397",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48260",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Adobe Experience Manager as a Cloud Service places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48261",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.131Z",
      "date_published": "2026-07-14T19:20:57.976Z",
      "date_updated": "2026-07-15T19:38:50.038Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06425
      },
      "nvd": {
        "published": "2026-07-14T20:17:06.950",
        "lastModified": "2026-07-17T17:45:33.150",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48261",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled DOM input reaches an executable browser context in Experience Manager without the required DOM-context neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48262",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.131Z",
      "date_published": "2026-07-14T19:20:56.503Z",
      "date_updated": "2026-07-15T19:38:46.411Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06425
      },
      "nvd": {
        "published": "2026-07-14T20:17:07.073",
        "lastModified": "2026-07-17T17:45:30.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48262",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Client-side code in Adobe Experience Manager as a Cloud Service places attacker-controlled data into an executable DOM context without sufficient sanitization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48263",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.131Z",
      "date_published": "2026-07-14T19:21:00.097Z",
      "date_updated": "2026-07-15T19:38:45.696Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00167,
        "percentile": 0.06325
      },
      "nvd": {
        "published": "2026-07-14T20:17:07.213",
        "lastModified": "2026-07-17T17:45:27.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48263",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Experience Manager stores low-privilege form-field content and later renders it without sufficient HTML neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48267",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.131Z",
      "date_published": "2026-07-06T19:45:31.065Z",
      "date_updated": "2026-07-07T13:43:52.214Z",
      "publisher": "adobe",
      "title": "DNG SDK | NULL Pointer Dereference (CWE-476)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "DNG SDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03707
      },
      "nvd": {
        "published": "2026-07-06T21:16:56.223",
        "lastModified": "2026-07-08T19:42:40.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48267",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The DNG SDK dereferences a null pointer while processing a user-supplied file.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/dng-sdk/apsb26-67.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48269",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.132Z",
      "date_published": "2026-07-14T20:04:07.411Z",
      "date_updated": "2026-07-15T10:38:05.662Z",
      "publisher": "adobe",
      "title": "Premiere Pro | Heap-based Buffer Overflow (CWE-122)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Premiere"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00297,
        "percentile": 0.2202
      },
      "nvd": {
        "published": "2026-07-14T21:16:57.473",
        "lastModified": "2026-07-17T03:25:07.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48269",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Premiere Pro copies attacker-controlled media data beyond a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/premiere_pro/apsb26-76.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48270",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.132Z",
      "date_published": "2026-07-14T20:04:05.984Z",
      "date_updated": "2026-07-15T10:37:51.242Z",
      "publisher": "adobe",
      "title": "Premiere Pro | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Premiere"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09515
      },
      "nvd": {
        "published": "2026-07-14T21:16:57.580",
        "lastModified": "2026-07-17T03:24:48.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48270",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/premiere_pro/apsb26-76.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48272",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.132Z",
      "date_published": "2026-07-14T20:21:16.239Z",
      "date_updated": "2026-07-15T10:35:08.685Z",
      "publisher": "adobe",
      "title": "Creative Cloud Desktop | Uncontrolled Search Path Element (CWE-427)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Creative Cloud Desktop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03489
      },
      "nvd": {
        "published": "2026-07-14T21:16:57.710",
        "lastModified": "2026-07-17T03:24:18.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48272",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user.",
        "basis": [
          "CNA",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/creative-cloud/apsb26-77.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 310,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48274",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.133Z",
      "date_published": "2026-07-14T20:07:31.728Z",
      "date_updated": "2026-07-15T10:40:37.459Z",
      "publisher": "adobe",
      "title": "After Effects | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "After Effects"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04533
      },
      "nvd": {
        "published": "2026-07-14T21:16:57.910",
        "lastModified": "2026-07-17T03:23:51.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48274",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected parser writes beyond its destination buffer because attacker-controlled size or index data is not bounded.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/after_effects/apsb26-78.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48275",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.133Z",
      "date_published": "2026-07-14T21:16:06.604Z",
      "date_updated": "2026-07-15T10:41:31.837Z",
      "publisher": "adobe",
      "title": "Illustrator | Untrusted Search Path (CWE-426)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Illustrator Desktop 2026"
          },
          {
            "vendor": "Adobe",
            "product": "Illustrator Desktop 2025"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-426",
          "name": "Untrusted Search Path",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05788
      },
      "nvd": {
        "published": "2026-07-14T22:17:00.580",
        "lastModified": "2026-07-16T18:35:03.693",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48275",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Executable loading searches an attacker-influenced location before a trusted location, allowing an untrusted module to be selected.",
        "basis": [
          "CNA",
          "CWE-426"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/illustrator/apsb26-79.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48284",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.134Z",
      "date_published": "2026-07-14T21:04:08.134Z",
      "date_updated": "2026-07-15T10:34:09.877Z",
      "publisher": "adobe",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.28002,
        "percentile": 0.97911
      },
      "nvd": {
        "published": "2026-07-14T21:16:58.043",
        "lastModified": "2026-07-15T18:00:17.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48284",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Adobe identifies improper input validation leading to ColdFusion code execution but does not publish the input, parser, endpoint, or failed validation rule.",
        "basis": [
          "CNA",
          "CWE-20",
          "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html"
        ],
        "deepDive": true,
        "notes": "APSB26-82 confirms ColdFusion 2025 Update 11 and 2023 Update 22 as fixes and says Adobe knew of no in-the-wild exploitation, but gives only CWE-20 and impact."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48287",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.134Z",
      "date_published": "2026-07-14T21:32:58.807Z",
      "date_updated": "2026-07-14T23:39:12.202Z",
      "publisher": "adobe",
      "title": "CAI Content Credentials | Untrusted Search Path (CWE-426)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Content Credentials Rust SDK"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials Command-Line Tool"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials JS SDK"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-426",
          "name": "Untrusted Search Path",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03695
      },
      "nvd": {
        "published": "2026-07-14T22:17:00.713",
        "lastModified": "2026-07-16T19:05:19.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48287",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Content Credentials loads executable code through an untrusted search path that an attacker can influence during user interaction.",
        "basis": [
          "CNA",
          "CWE-426"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 386,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48290",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.134Z",
      "date_published": "2026-07-14T21:33:01.048Z",
      "date_updated": "2026-07-14T23:39:11.773Z",
      "publisher": "adobe",
      "title": "CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Content Credentials Rust SDK"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials Command-Line Tool"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials JS SDK"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07493
      },
      "nvd": {
        "published": "2026-07-14T22:17:00.840",
        "lastModified": "2026-07-16T19:03:27.127",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48290",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Content Credentials can be induced to issue a server-side request to an attacker-selected destination, although the stated downstream impact is internally inconsistent.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48295",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.135Z",
      "date_published": "2026-07-14T21:33:01.777Z",
      "date_updated": "2026-07-14T23:39:11.628Z",
      "publisher": "adobe",
      "title": "CAI Content Credentials | Insufficiently Protected Credentials (CWE-522)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Content Credentials Rust SDK"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials Command-Line Tool"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials JS SDK"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31633
      },
      "nvd": {
        "published": "2026-07-14T22:17:00.960",
        "lastModified": "2026-07-16T19:03:30.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48295",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Credentials are insufficiently protected, but the public record does not identify their storage path, comparison, or lifecycle failure.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48296",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.135Z",
      "date_published": "2026-07-14T21:32:59.536Z",
      "date_updated": "2026-07-14T23:39:12.060Z",
      "publisher": "adobe",
      "title": "CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Content Credentials Rust SDK"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials Command-Line Tool"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials JS SDK"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05057
      },
      "nvd": {
        "published": "2026-07-14T22:17:01.083",
        "lastModified": "2026-07-16T19:03:36.217",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48296",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled arithmetic wraps below zero and produces an invalid size used by the Content Credentials SDK.",
        "basis": [
          "CNA record",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 324,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48298",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.135Z",
      "date_published": "2026-07-14T21:32:54.977Z",
      "date_updated": "2026-07-14T23:39:12.913Z",
      "publisher": "adobe",
      "title": "CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Content Credentials Rust SDK"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials Command-Line Tool"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials JS SDK"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.05004
      },
      "nvd": {
        "published": "2026-07-14T22:17:01.207",
        "lastModified": "2026-07-16T19:03:45.133",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48298",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Content Credentials Rust SDK uses a size result after attacker-controlled arithmetic can underflow.",
        "basis": [
          "CNA",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 324,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48302",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.136Z",
      "date_published": "2026-07-14T21:32:56.574Z",
      "date_updated": "2026-07-14T23:39:12.634Z",
      "publisher": "adobe",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Content Credentials Rust SDK"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials Command-Line Tool"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials JS SDK"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05056
      },
      "nvd": {
        "published": "2026-07-14T22:17:01.333",
        "lastModified": "2026-07-16T19:03:50.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48302",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record says malformed input can crash Content Credentials but does not disclose the parser, state, or resource failure that causes the crash.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48308",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.136Z",
      "date_published": "2026-07-14T20:04:05.282Z",
      "date_updated": "2026-07-16T14:53:18.646Z",
      "publisher": "adobe",
      "title": "Premiere Pro | Improper Input Validation (CWE-20)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Premiere"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04335
      },
      "nvd": {
        "published": "2026-07-14T21:16:58.153",
        "lastModified": "2026-07-17T03:23:28.143",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48308",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Premiere Pro record reports a security-feature bypass and unauthorized write but does not identify the input, parser, destination, or validation rule that fails.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/premiere_pro/apsb26-76.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 369,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.136Z",
      "date_published": "2026-07-14T17:48:50.802Z",
      "date_updated": "2026-07-15T10:37:10.812Z",
      "publisher": "adobe",
      "title": "Audition | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Audition"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06222
      },
      "nvd": {
        "published": "2026-07-14T18:17:19.060",
        "lastModified": "2026-07-15T13:51:52.543",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48309",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser can write beyond the destination allocation because the computed length or boundary is not enforced.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/audition/apsb26-71.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48310",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.136Z",
      "date_published": "2026-07-14T19:21:02.330Z",
      "date_updated": "2026-07-16T14:44:17.004Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00506,
        "percentile": 0.40425
      },
      "nvd": {
        "published": "2026-07-14T20:17:07.450",
        "lastModified": "2026-07-17T17:45:04.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48310",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Experience Manager accepts traversal-bearing path input and resolves reads outside the intended filesystem directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48311",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.136Z",
      "date_published": "2026-07-14T20:35:15.591Z",
      "date_updated": "2026-07-15T10:32:49.236Z",
      "publisher": "adobe",
      "title": "Bridge | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04533
      },
      "nvd": {
        "published": "2026-07-14T21:16:58.383",
        "lastModified": "2026-07-16T19:08:01.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48311",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Adobe Bridge path writes attacker-influenced data beyond the capacity of its destination buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-81.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48312",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.136Z",
      "date_published": "2026-07-14T21:32:58.069Z",
      "date_updated": "2026-07-14T23:39:12.350Z",
      "publisher": "adobe",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Content Credentials Rust SDK"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials Command-Line Tool"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials JS SDK"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05488
      },
      "nvd": {
        "published": "2026-07-14T22:17:01.593",
        "lastModified": "2026-07-16T19:03:54.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48312",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record lists input validation, security bypass, and write impact without identifying the accepted input or violated invariant.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48316",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.137Z",
      "date_published": "2026-07-06T16:13:57.475Z",
      "date_updated": "2026-07-07T13:10:00.267Z",
      "publisher": "adobe",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01601,
        "percentile": 0.73412
      },
      "nvd": {
        "published": "2026-07-06T17:16:32.010",
        "lastModified": "2026-07-09T17:19:22.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48316",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Adobe states that unvalidated input reaches a ColdFusion code-execution path but does not identify the input, parser, or failing validation rule publicly.",
        "basis": [
          "CNA",
          "CWE-20",
          "Adobe APSB26-68"
        ],
        "deepDive": true,
        "notes": "Read Adobe APSB26-68 https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html; the bulletin confirms unauthenticated code execution from improper input validation but publishes no input, parser, endpoint, or failed validation rule."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48318",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.137Z",
      "date_published": "2026-07-14T21:04:13.183Z",
      "date_updated": "2026-07-15T10:34:39.970Z",
      "publisher": "adobe",
      "title": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.2346,
        "percentile": 0.97565
      },
      "nvd": {
        "published": "2026-07-14T21:16:58.493",
        "lastModified": "2026-07-15T17:59:53.417",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48318",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ColdFusion accepts a path that escapes the intended directory and reaches files outside the authorized filesystem scope.",
        "basis": [
          "CNA",
          "CWE-22",
          "Adobe APSB26-82"
        ],
        "deepDive": true,
        "notes": "Inspected https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html; Adobe confirms CWE-22, CVSS 9.9, and fixes in ColdFusion 2025 Update 11 and 2023 Update 22, but does not publish the vulnerable path parameter or filesystem sink."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 370,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48319",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.137Z",
      "date_published": "2026-07-14T21:04:10.288Z",
      "date_updated": "2026-07-21T21:19:01.997Z",
      "publisher": "adobe",
      "title": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.3229,
        "percentile": 0.98155
      },
      "nvd": {
        "published": "2026-07-14T21:16:58.600",
        "lastModified": "2026-07-29T19:16:47.933",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48319",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "ColdFusion allows a high-privileged caller to select a path outside the intended directory and reach code execution, while Adobe does not publish the affected path field or file operation.",
        "basis": [
          "CNA",
          "CWE-22",
          "Adobe APSB26-82"
        ],
        "deepDive": true,
        "notes": "Inspected https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html. Adobe confirms a high-privileged path traversal with code-execution impact, affected ColdFusion 2025 Update 10 and earlier and 2023 Update 21 and earlier, and fixes in Updates 11 and 22, while withholding the path parameter and file operation. Adobe states it was unaware of in-the-wild exploitation on 2026-07-14; EPSS 0.3229 is a predictive score and is not contrary exploitation evidence."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 376,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48320",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.137Z",
      "date_published": "2026-07-14T21:04:15.334Z",
      "date_updated": "2026-07-15T15:11:55.013Z",
      "publisher": "adobe",
      "title": "ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.13021,
        "percentile": 0.9594
      },
      "nvd": {
        "published": "2026-07-14T21:16:58.703",
        "lastModified": "2026-07-29T19:17:39.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48320",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ColdFusion reflects attacker-controlled browser input into HTML without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79",
          "Adobe APSB26-82"
        ],
        "deepDive": true,
        "notes": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html was inspected; Adobe confirms reflected XSS and privilege escalation but does not publish the reflected parameter or output context."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 370,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48321",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.137Z",
      "date_published": "2026-07-14T21:04:09.567Z",
      "date_updated": "2026-07-16T03:55:24.149Z",
      "publisher": "adobe",
      "title": "ColdFusion | Incorrect Authorization (CWE-863)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00771,
        "percentile": 0.52115
      },
      "nvd": {
        "published": "2026-07-14T21:16:58.813",
        "lastModified": "2026-07-29T19:17:35.093",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48321",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ColdFusion applies an incorrect authorization decision to an undisclosed read/write operation; the Adobe CNA does not identify the endpoint, object, or privilege check.",
        "basis": [
          "CNA",
          "CWE-863",
          "https://cveawg.mitre.org/api/cve/CVE-2026-48321"
        ],
        "deepDive": true,
        "notes": "Reviewed https://cveawg.mitre.org/api/cve/CVE-2026-48321. The live Adobe CNA record confirms incorrect authorization and the fixed product versions but still does not identify the endpoint, object, privilege, or failing check; Adobe's linked bulletin timed out during two retrieval methods."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48322",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.137Z",
      "date_published": "2026-07-14T21:04:08.871Z",
      "date_updated": "2026-07-15T10:34:24.993Z",
      "publisher": "adobe",
      "title": "ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00849,
        "percentile": 0.54565
      },
      "nvd": {
        "published": "2026-07-14T21:16:58.920",
        "lastModified": "2026-07-15T17:56:24.253",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48322",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Adobe ColdFusion permits attacker-controlled input to reach a code-injection path, while APSB26-82 does not publish the endpoint, input field, or evaluation sink.",
        "basis": [
          "CNA",
          "CWE-94",
          "Adobe APSB26-82"
        ],
        "deepDive": true,
        "notes": "Inspected https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html. It confirms code injection and fixes in ColdFusion 2025 Update 11 and 2023 Update 22, but gives no input or sink; the bulletin's CVSS 9.6 differs from the embedded 9.9 maximum."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48324",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.137Z",
      "date_published": "2026-07-14T21:04:14.618Z",
      "date_updated": "2026-07-21T21:20:48.788Z",
      "publisher": "adobe",
      "title": "ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01439,
        "percentile": 0.70558
      },
      "nvd": {
        "published": "2026-07-14T21:16:59.023",
        "lastModified": "2026-07-29T19:16:50.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48324",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 382,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48325",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.137Z",
      "date_published": "2026-07-14T21:04:06.722Z",
      "date_updated": "2026-07-15T10:33:56.694Z",
      "publisher": "adobe",
      "title": "ColdFusion | Missing Authentication for Critical Function (CWE-306)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00513,
        "percentile": 0.40858
      },
      "nvd": {
        "published": "2026-07-14T21:16:59.143",
        "lastModified": "2026-07-15T18:39:37.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48325",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ColdFusion 2025 exposes a security-sensitive operation without verifying that the network caller is authenticated.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48327",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.138Z",
      "date_published": "2026-07-14T21:04:12.455Z",
      "date_updated": "2026-07-15T10:33:15.972Z",
      "publisher": "adobe",
      "title": "ColdFusion | Incorrect Authorization (CWE-863)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29803
      },
      "nvd": {
        "published": "2026-07-14T21:16:59.257",
        "lastModified": "2026-07-15T18:39:30.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48327",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ColdFusion permits a low-privilege adjacent actor to reach code-executing behavior without sufficient authorization, but Adobe does not publish the failing check.",
        "basis": [
          "CNA",
          "CWE-863",
          "Adobe security bulletin"
        ],
        "deepDive": true,
        "notes": "Inspected https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html; Adobe publishes only the CWE, impact, and affected updates, not the failing authorization check, and no reproduction was performed."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.138Z",
      "date_published": "2026-07-14T21:04:07.429Z",
      "date_updated": "2026-07-15T15:12:02.100Z",
      "publisher": "adobe",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00529,
        "percentile": 0.41802
      },
      "nvd": {
        "published": "2026-07-14T21:16:59.363",
        "lastModified": "2026-07-15T18:39:23.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48328",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Adobe reports that malformed input bypasses a ColdFusion security feature and exposes data but does not disclose the input grammar or failed check.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48329",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.138Z",
      "date_published": "2026-07-14T21:04:10.998Z",
      "date_updated": "2026-07-15T14:36:31.234Z",
      "publisher": "adobe",
      "title": "ColdFusion | Insufficient Session Expiration (CWE-613)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21902
      },
      "nvd": {
        "published": "2026-07-14T21:16:59.470",
        "lastModified": "2026-07-15T18:39:00.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48329",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "ColdFusion leaves a privileged session valid beyond its intended lifetime, allowing a high-privileged actor to reuse stale authorization for a write operation.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 309,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48332",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T21:04:13.906Z",
      "date_updated": "2026-07-15T17:38:35.635Z",
      "publisher": "adobe",
      "title": "ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.10748,
        "percentile": 0.95379
      },
      "nvd": {
        "published": "2026-07-14T21:16:59.583",
        "lastModified": "2026-07-15T18:39:42.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48332",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ColdFusion lets a low-privileged caller induce a server-side request to a target outside the intended network trust boundary.",
        "basis": [
          "CNA",
          "CWE-918",
          "Adobe APSB26-82"
        ],
        "deepDive": true,
        "notes": "Inspected https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html. Adobe confirms CWE-918, affected updates, CVSS, and fixed updates, but publishes no endpoint, destination-validation rule, or source patch."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 327,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48334",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T21:16:07.327Z",
      "date_updated": "2026-07-21T21:35:12.679Z",
      "publisher": "adobe",
      "title": "Illustrator | Improper Input Validation (CWE-20)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Illustrator Desktop 2026"
          },
          {
            "vendor": "Adobe",
            "product": "Illustrator Desktop 2025"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.004,
        "percentile": 0.32795
      },
      "nvd": {
        "published": "2026-07-14T22:17:01.717",
        "lastModified": "2026-07-29T19:16:57.390",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48334",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Adobe identifies improper input validation leading to privilege escalation but does not disclose the parser, object, or failing validation rule.",
        "basis": [
          "CNA",
          "CWE-20",
          "Adobe APSB26-79"
        ],
        "deepDive": true,
        "notes": "Inspected https://helpx.adobe.com/security/products/illustrator/apsb26-79.html; Adobe confirms improper input validation, privilege escalation, affected versions, and fixes but does not identify the parser or validation rule."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/illustrator/apsb26-79.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 352,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48335",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T21:16:08.774Z",
      "date_updated": "2026-07-16T03:55:33.462Z",
      "publisher": "adobe",
      "title": "Illustrator | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Illustrator Desktop 2026"
          },
          {
            "vendor": "Adobe",
            "product": "Illustrator Desktop 2025"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03656
      },
      "nvd": {
        "published": "2026-07-14T22:17:01.840",
        "lastModified": "2026-07-16T18:35:10.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48335",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Illustrator Desktop 2026, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/illustrator/apsb26-79.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T21:16:09.490Z",
      "date_updated": "2026-07-15T10:40:51.767Z",
      "publisher": "adobe",
      "title": "Illustrator | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Illustrator Desktop 2026"
          },
          {
            "vendor": "Adobe",
            "product": "Illustrator Desktop 2025"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03655
      },
      "nvd": {
        "published": "2026-07-14T22:17:01.963",
        "lastModified": "2026-07-16T18:35:08.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48336",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Illustrator Desktop 2026 copies, writes, or indexes attacker-influenced data without enforcing the destination buffer or object bounds required by the operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/illustrator/apsb26-79.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48337",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T21:16:08.056Z",
      "date_updated": "2026-07-15T10:41:18.799Z",
      "publisher": "adobe",
      "title": "Illustrator | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Illustrator Desktop 2026"
          },
          {
            "vendor": "Adobe",
            "product": "Illustrator Desktop 2025"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03654
      },
      "nvd": {
        "published": "2026-07-14T22:17:02.090",
        "lastModified": "2026-07-16T18:35:06.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48337",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Illustrator writes malicious-file data beyond a valid buffer boundary while opening the file.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/illustrator/apsb26-79.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48338",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T21:04:11.745Z",
      "date_updated": "2026-07-16T15:01:16.864Z",
      "publisher": "adobe",
      "title": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2025"
          },
          {
            "vendor": "Adobe",
            "product": "ColdFusion 2023"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17423
      },
      "nvd": {
        "published": "2026-07-14T21:16:59.690",
        "lastModified": "2026-07-16T16:19:09.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48338",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ColdFusion 2025 resolves attacker-controlled path components without confirming that the final path remains beneath the intended root.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 370,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48339",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T20:35:16.341Z",
      "date_updated": "2026-07-15T10:32:08.611Z",
      "publisher": "adobe",
      "title": "Bridge | Heap-based Buffer Overflow (CWE-122)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.0859
      },
      "nvd": {
        "published": "2026-07-14T21:16:59.790",
        "lastModified": "2026-07-16T19:07:38.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48339",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Adobe Bridge copies malicious-file data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-81.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48340",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T20:35:17.792Z",
      "date_updated": "2026-07-15T10:31:53.182Z",
      "publisher": "adobe",
      "title": "Bridge | Untrusted Pointer Dereference (CWE-822)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-822",
          "name": "Untrusted Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06671
      },
      "nvd": {
        "published": "2026-07-14T21:16:59.897",
        "lastModified": "2026-07-16T19:07:35.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48340",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Adobe Bridge dereferences a pointer value derived from an untrusted file without establishing that it is valid.",
        "basis": [
          "CNA",
          "CWE-822"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-81.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48341",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T20:35:14.113Z",
      "date_updated": "2026-07-15T10:32:21.710Z",
      "publisher": "adobe",
      "title": "Bridge | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04595
      },
      "nvd": {
        "published": "2026-07-14T21:17:00.007",
        "lastModified": "2026-07-16T19:07:48.487",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48341",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Adobe Bridge writes attacker-controlled data beyond an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-81.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48342",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T20:35:14.863Z",
      "date_updated": "2026-07-15T10:31:39.053Z",
      "publisher": "adobe",
      "title": "Bridge | Integer Overflow or Wraparound (CWE-190)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06621
      },
      "nvd": {
        "published": "2026-07-14T21:17:00.113",
        "lastModified": "2026-07-16T19:07:53.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48342",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-81.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48343",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T20:35:17.066Z",
      "date_updated": "2026-07-15T10:32:35.055Z",
      "publisher": "adobe",
      "title": "Bridge | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04533
      },
      "nvd": {
        "published": "2026-07-14T21:17:00.217",
        "lastModified": "2026-07-16T19:07:57.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48343",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-81.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48344",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T20:21:15.537Z",
      "date_updated": "2026-07-15T10:34:54.284Z",
      "publisher": "adobe",
      "title": "GoCart | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Creative Cloud Desktop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00104,
        "percentile": 0.01187
      },
      "nvd": {
        "published": "2026-07-14T21:17:00.327",
        "lastModified": "2026-07-17T03:23:06.023",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48344",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected workflow fails to preserve its invariant across a state transition or concurrent operation.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/creative-cloud/apsb26-77.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48345",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.139Z",
      "date_published": "2026-07-14T19:53:34.525Z",
      "date_updated": "2026-07-15T10:39:40.057Z",
      "publisher": "adobe",
      "title": "Animate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Animate 2023"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Animate 2024"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00716,
        "percentile": 0.50209
      },
      "nvd": {
        "published": "2026-07-14T20:17:07.573",
        "lastModified": "2026-07-16T18:42:31.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48345",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled command data reaches a command interpreter without safe argument separation or complete command-language neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/animate/apsb26-83.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48346",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T19:53:35.227Z",
      "date_updated": "2026-07-15T10:39:13.282Z",
      "publisher": "adobe",
      "title": "Animate | Untrusted Search Path (CWE-426)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Animate 2023"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Animate 2024"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-426",
          "name": "Untrusted Search Path",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08481
      },
      "nvd": {
        "published": "2026-07-14T20:17:07.700",
        "lastModified": "2026-07-16T18:43:41.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48346",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The application resolves executable content through a search path that an attacker can influence.",
        "basis": [
          "CNA",
          "CWE-426"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/animate/apsb26-83.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48347",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T19:53:33.822Z",
      "date_updated": "2026-07-15T10:38:59.616Z",
      "publisher": "adobe",
      "title": "Animate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Animate 2023"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Animate 2024"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00545,
        "percentile": 0.42691
      },
      "nvd": {
        "published": "2026-07-14T20:17:07.820",
        "lastModified": "2026-07-16T18:43:47.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48347",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value reaches operating-system command construction in Adobe Animate 2023 without separation from command or argument syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/animate/apsb26-83.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T19:53:32.422Z",
      "date_updated": "2026-07-15T10:38:32.924Z",
      "publisher": "adobe",
      "title": "Animate | Incorrect Authorization (CWE-863)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Animate 2023"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Animate 2024"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06218
      },
      "nvd": {
        "published": "2026-07-14T20:17:07.940",
        "lastModified": "2026-07-16T18:43:51.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48348",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Animate performs a file-triggered operation under authority the input should not receive, but the checked subject, object, and action are not public.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/animate/apsb26-83.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T19:53:33.123Z",
      "date_updated": "2026-07-15T10:38:19.308Z",
      "publisher": "adobe",
      "title": "Animate | Incorrect Authorization (CWE-863)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Animate 2023"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Animate 2024"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00192,
        "percentile": 0.09098
      },
      "nvd": {
        "published": "2026-07-14T20:17:08.067",
        "lastModified": "2026-07-16T18:43:55.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48349",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Animate executes code under authority the input should not receive, but the public record does not identify the protected action or failed check.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/animate/apsb26-83.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 286,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48350",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T19:53:31.717Z",
      "date_updated": "2026-07-15T10:40:10.147Z",
      "publisher": "adobe",
      "title": "Animate | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Animate 2023"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Animate 2024"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09681
      },
      "nvd": {
        "published": "2026-07-14T20:17:08.180",
        "lastModified": "2026-07-16T18:43:59.617",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48350",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted Animate file supplies a path that escapes the directory restriction applied by the parser.",
        "basis": [
          "CNA record",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/animate/apsb26-83.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T21:32:57.308Z",
      "date_updated": "2026-07-14T23:39:12.490Z",
      "publisher": "adobe",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Content Credentials Rust SDK"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials Command-Line Tool"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials JS SDK"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00407,
        "percentile": 0.33495
      },
      "nvd": {
        "published": "2026-07-14T22:17:02.210",
        "lastModified": "2026-07-16T19:03:57.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48351",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The CAI Content Credentials record names improper input validation and application crash but does not disclose the input, parser, or rejected invariant.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T21:32:54.225Z",
      "date_updated": "2026-07-14T23:39:13.057Z",
      "publisher": "adobe",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Content Credentials Rust SDK"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials Command-Line Tool"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials JS SDK"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00407,
        "percentile": 0.33495
      },
      "nvd": {
        "published": "2026-07-14T22:17:02.357",
        "lastModified": "2026-07-16T19:04:00.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48352",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record says malformed input can crash Content Credentials but does not disclose the parser, state, or resource failure that causes the crash.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T21:32:53.498Z",
      "date_updated": "2026-07-14T23:39:13.190Z",
      "publisher": "adobe",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Content Credentials Rust SDK"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials Command-Line Tool"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials JS SDK"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05128
      },
      "nvd": {
        "published": "2026-07-14T22:17:02.503",
        "lastModified": "2026-07-16T19:04:04.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48353",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A malicious Content Credentials file can select files outside the intended scope, but Adobe does not disclose the path field or containment check that fails.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 348,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48354",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T21:32:55.707Z",
      "date_updated": "2026-07-14T23:39:12.774Z",
      "publisher": "adobe",
      "title": "CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Content Credentials Rust SDK"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials Command-Line Tool"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials JS SDK"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.05003
      },
      "nvd": {
        "published": "2026-07-14T22:17:02.643",
        "lastModified": "2026-07-16T19:04:07.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48354",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An arithmetic operation can wrap before the result is used for a memory size or offset, invalidating the later bounds assumption.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48355",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T19:20:58.668Z",
      "date_updated": "2026-07-15T19:38:49.677Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00167,
        "percentile": 0.06324
      },
      "nvd": {
        "published": "2026-07-14T20:17:08.300",
        "lastModified": "2026-07-17T17:45:23.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48355",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Experience Manager stores low-privileged form-field input and later emits it into browser-interpreted output without contextual neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48356",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T19:44:17.036Z",
      "date_updated": "2026-07-21T21:34:31.760Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.28225,
        "percentile": 0.97924
      },
      "nvd": {
        "published": "2026-07-14T20:17:08.437",
        "lastModified": "2026-07-29T19:17:00.407",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48356",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Adobe Commerce upload path accepts a file type that can become executable or security-sensitive after storage.",
        "basis": [
          "CNA",
          "CWE-434",
          "Adobe APSB26-73"
        ],
        "deepDive": true,
        "notes": "Inspected Adobe bulletin https://helpx.adobe.com/security/products/magento/apsb26-73.html. Adobe identifies an unauthenticated dangerous-file upload requiring victim interaction, lists the affected Commerce and Magento release trains, and provides July 2026 updates, but does not publish the upload handler, accepted extension, or storage/execution path. The bulletin reports CVSS 3.1 score 9.6 while the shard carries CNA score 9.3, and Adobe said on 2026-07-14 that it was unaware of in-the-wild exploitation; EPSS 0.28225 is predictive rather than exploitation evidence."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 427,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-48357",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T21:33:00.285Z",
      "date_updated": "2026-07-14T23:39:11.923Z",
      "publisher": "adobe",
      "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Content Credentials Rust SDK"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials Command-Line Tool"
          },
          {
            "vendor": "Adobe",
            "product": "Content Credentials JS SDK"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.05003
      },
      "nvd": {
        "published": "2026-07-14T22:17:02.770",
        "lastModified": "2026-07-16T19:04:11.763",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48357",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An attacker can exhaust a finite resource, but the public record does not identify the work unit, bound, or release path.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48358",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T19:44:17.756Z",
      "date_updated": "2026-07-21T21:21:53.252Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01486,
        "percentile": 0.7148
      },
      "nvd": {
        "published": "2026-07-14T20:17:08.653",
        "lastModified": "2026-07-29T19:16:54.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48358",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Adobe Commerce output path emits attacker-influenced data without the escaping required by the downstream interpreter context.",
        "basis": [
          "CNA",
          "CWE-116",
          "Adobe APSB26-73"
        ],
        "deepDive": true,
        "notes": "Read Adobe APSB26-73 https://helpx.adobe.com/security/products/magento/apsb26-73.html; it narrows the issue to webhooks and output escaping but does not disclose the output context or interpreter boundary."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 341,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-48359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.140Z",
      "date_published": "2026-07-14T19:21:00.902Z",
      "date_updated": "2026-07-15T19:38:48.564Z",
      "publisher": "adobe",
      "title": "Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5 LTS"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Experience Manager 6.5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01705,
        "percentile": 0.75026
      },
      "nvd": {
        "published": "2026-07-14T20:17:08.810",
        "lastModified": "2026-07-17T17:45:16.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48359",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Adobe Experience Manager permits an XML parser to resolve attacker-controlled external entities.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48363",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.141Z",
      "date_published": "2026-07-13T20:03:57.419Z",
      "date_updated": "2026-07-15T03:58:55.358Z",
      "publisher": "adobe",
      "title": "ColdFusion | Uncontrolled Search Path Element (CWE-427)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.0547
      },
      "nvd": {
        "published": "2026-07-13T21:16:47.857",
        "lastModified": "2026-07-15T05:16:44.607",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48363",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user.",
        "basis": [
          "CNA",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48364",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.141Z",
      "date_published": "2026-07-13T20:03:41.687Z",
      "date_updated": "2026-07-15T03:58:56.154Z",
      "publisher": "adobe",
      "title": "ColdFusion | Uncontrolled Search Path Element (CWE-427)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "ColdFusion"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.0547
      },
      "nvd": {
        "published": "2026-07-13T21:16:48.337",
        "lastModified": "2026-07-15T05:16:44.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48364",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user.",
        "basis": [
          "CNA",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48365",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.141Z",
      "date_published": "2026-07-14T17:48:49.377Z",
      "date_updated": "2026-07-15T10:36:57.211Z",
      "publisher": "adobe",
      "title": "Audition | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Audition"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07775
      },
      "nvd": {
        "published": "2026-07-14T18:17:19.197",
        "lastModified": "2026-07-15T13:51:34.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48365",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected parser writes beyond its destination buffer because attacker-controlled size or index data is not bounded.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/audition/apsb26-71.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48366",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.141Z",
      "date_published": "2026-07-14T19:58:55.425Z",
      "date_updated": "2026-07-15T10:36:03.752Z",
      "publisher": "adobe",
      "title": "Media Encoder | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Media Encoder"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04595
      },
      "nvd": {
        "published": "2026-07-14T21:17:00.553",
        "lastModified": "2026-07-17T03:22:42.133",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48366",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Adobe Media Encoder can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/media-encoder/apsb26-72.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48367",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.141Z",
      "date_published": "2026-07-14T20:07:32.432Z",
      "date_updated": "2026-07-15T10:40:23.783Z",
      "publisher": "adobe",
      "title": "After Effects | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "After Effects"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04596
      },
      "nvd": {
        "published": "2026-07-14T21:17:00.660",
        "lastModified": "2026-07-17T03:22:10.693",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48367",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled input reaches a write whose destination boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/after_effects/apsb26-78.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48368",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.141Z",
      "date_published": "2026-07-14T17:48:47.959Z",
      "date_updated": "2026-07-15T03:59:36.836Z",
      "publisher": "adobe",
      "title": "Audition | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Audition"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07775
      },
      "nvd": {
        "published": "2026-07-14T18:17:19.317",
        "lastModified": "2026-07-15T13:51:02.217",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48368",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Audition writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/audition/apsb26-71.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48369",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.141Z",
      "date_published": "2026-07-14T20:04:06.693Z",
      "date_updated": "2026-07-15T10:37:37.619Z",
      "publisher": "adobe",
      "title": "Premiere Pro | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Premiere"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04531
      },
      "nvd": {
        "published": "2026-07-14T21:17:00.893",
        "lastModified": "2026-07-17T03:21:48.717",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48369",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Premiere Pro writes beyond an allocated buffer while processing a malicious file.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/premiere_pro/apsb26-76.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48370",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.141Z",
      "date_published": "2026-07-14T19:58:53.324Z",
      "date_updated": "2026-07-15T10:36:17.340Z",
      "publisher": "adobe",
      "title": "Media Encoder | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Media Encoder"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04531
      },
      "nvd": {
        "published": "2026-07-14T21:17:01.000",
        "lastModified": "2026-07-17T03:20:28.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48370",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Media Encoder writes beyond a buffer boundary while processing a malicious file opened by the user.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/media-encoder/apsb26-72.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.141Z",
      "date_published": "2026-07-14T19:44:13.490Z",
      "date_updated": "2026-07-15T14:08:27.282Z",
      "publisher": "adobe",
      "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce B2B"
          },
          {
            "vendor": "Adobe",
            "product": "Magento Open Source"
          },
          {
            "vendor": "Adobe",
            "product": "Adobe Commerce Webhooks Plugin"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 8,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.08001
      },
      "nvd": {
        "published": "2026-07-14T20:17:09.200",
        "lastModified": "2026-07-15T15:16:36.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48371",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A low-privileged user can store script-bearing form content that Adobe Commerce later renders as executable browser markup.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-48372",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.141Z",
      "date_published": "2026-07-28T17:51:29.167Z",
      "date_updated": "2026-07-28T17:59:59.491Z",
      "publisher": "adobe",
      "title": "Format Plugins | Heap-based Buffer Overflow (CWE-122)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Format Plugins"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08467
      },
      "nvd": {
        "published": "2026-07-28T18:17:20.747",
        "lastModified": "2026-07-28T20:35:35.883",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48372",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Format Plugins path writes attacker-influenced data beyond an allocated heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/formatplugins/apsb26-87.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48373",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.141Z",
      "date_published": "2026-07-17T19:29:39.303Z",
      "date_updated": "2026-07-23T03:56:11.342Z",
      "publisher": "adobe",
      "title": "Acrobat Reader | Heap-based Buffer Overflow (CWE-122)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Acrobat Reader"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08468
      },
      "nvd": {
        "published": "2026-07-17T20:17:21.290",
        "lastModified": "2026-07-23T05:16:32.020",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48373",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Acrobat Reader writes beyond a heap allocation while processing a malicious file.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/acrobat/apsb26-63.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48374",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.142Z",
      "date_published": "2026-07-28T17:58:47.623Z",
      "date_updated": "2026-07-28T18:48:07.767Z",
      "publisher": "adobe",
      "title": "Bridge | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08863
      },
      "nvd": {
        "published": "2026-07-28T19:17:34.987",
        "lastModified": "2026-08-03T13:36:52.153",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48374",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file operation in Adobe Bridge uses an attacker-controlled path without confining the resolved object to the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-89.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48388",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.143Z",
      "date_published": "2026-07-28T17:46:26.236Z",
      "date_updated": "2026-07-28T19:35:18.940Z",
      "publisher": "adobe",
      "title": "Photoshop Installer | CWE-427: Uncontrolled Search Path Element",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Photoshop Installer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06926
      },
      "nvd": {
        "published": "2026-07-28T18:17:20.887",
        "lastModified": "2026-07-28T20:35:35.883",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48388",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Adobe Photoshop Installer searches an attacker-writable location for a loadable library before a trusted location, allowing dependency substitution during installation or startup.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cwe.mitre.org/data/definitions/427.html",
          "host": "cwe.mitre.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.143Z",
      "date_published": "2026-07-20T18:14:22.124Z",
      "date_updated": "2026-07-23T03:56:22.942Z",
      "publisher": "adobe",
      "title": "DNG SDK | Stack-based Buffer Overflow (CWE-121)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "DNG SDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08468
      },
      "nvd": {
        "published": "2026-07-20T19:17:23.807",
        "lastModified": "2026-07-23T05:16:32.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48389",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The DNG SDK copies malicious-file data beyond a fixed stack buffer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/dng-sdk/apsb26-67.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.143Z",
      "date_published": "2026-07-28T17:58:46.196Z",
      "date_updated": "2026-07-29T18:12:40.625Z",
      "publisher": "adobe",
      "title": "Bridge | Incorrect Authorization (CWE-863)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04157
      },
      "nvd": {
        "published": "2026-07-28T19:17:35.123",
        "lastModified": "2026-08-03T13:36:49.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48390",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in Adobe Bridge, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-89.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.143Z",
      "date_published": "2026-07-28T17:58:48.334Z",
      "date_updated": "2026-07-29T03:56:02.075Z",
      "publisher": "adobe",
      "title": "Bridge | Untrusted Search Path (CWE-426)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-426",
          "name": "Untrusted Search Path",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05174
      },
      "nvd": {
        "published": "2026-07-28T19:17:35.243",
        "lastModified": "2026-08-03T13:36:58.373",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48391",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Adobe Bridge resolves executable code through an attacker-influenced search path when a malicious file is opened.",
        "basis": [
          "CNA",
          "CWE-426"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-89.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.143Z",
      "date_published": "2026-07-28T17:58:46.917Z",
      "date_updated": "2026-07-29T03:56:04.059Z",
      "publisher": "adobe",
      "title": "Bridge | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04509
      },
      "nvd": {
        "published": "2026-07-28T19:17:35.377",
        "lastModified": "2026-08-03T13:36:54.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48392",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Adobe Bridge writes beyond a memory buffer while processing a user-supplied file.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-89.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48393",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.143Z",
      "date_published": "2026-07-28T17:58:44.694Z",
      "date_updated": "2026-07-29T03:56:04.851Z",
      "publisher": "adobe",
      "title": "Bridge | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.0451
      },
      "nvd": {
        "published": "2026-07-28T19:17:35.503",
        "lastModified": "2026-08-03T13:37:00.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48393",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Adobe Bridge writes attacker-controlled data beyond an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-89.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.143Z",
      "date_published": "2026-07-28T17:58:49.047Z",
      "date_updated": "2026-07-29T03:56:05.714Z",
      "publisher": "adobe",
      "title": "Bridge | Out-of-bounds Write (CWE-787)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.0451
      },
      "nvd": {
        "published": "2026-07-28T19:17:35.627",
        "lastModified": "2026-08-03T13:37:03.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48394",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-89.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.143Z",
      "date_published": "2026-07-28T17:58:45.455Z",
      "date_updated": "2026-07-29T18:12:28.635Z",
      "publisher": "adobe",
      "title": "Bridge | Untrusted Search Path (CWE-426)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-426",
          "name": "Untrusted Search Path",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06587
      },
      "nvd": {
        "published": "2026-07-28T19:17:35.753",
        "lastModified": "2026-08-03T13:36:47.150",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48395",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user.",
        "basis": [
          "CNA",
          "CWE-426"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-89.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.143Z",
      "date_published": "2026-07-28T17:58:43.967Z",
      "date_updated": "2026-07-29T03:56:07.353Z",
      "publisher": "adobe",
      "title": "Bridge | Incorrect Authorization (CWE-863)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Bridge"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05685
      },
      "nvd": {
        "published": "2026-07-28T19:17:35.870",
        "lastModified": "2026-08-03T13:37:05.503",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48396",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/bridge/apsb26-89.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.146Z",
      "date_published": "2026-07-30T02:48:59.525Z",
      "date_updated": "2026-08-03T18:23:42.280Z",
      "publisher": "adobe",
      "title": "Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Campaign Classic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.297
      },
      "nvd": {
        "published": "2026-07-30T03:16:24.810",
        "lastModified": "2026-08-03T19:16:47.187",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48448",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/campaign/apsb26-114.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48449",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:28:38.146Z",
      "date_published": "2026-07-30T02:49:00.205Z",
      "date_updated": "2026-08-03T18:23:41.904Z",
      "publisher": "adobe",
      "title": "Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)",
      "affected": {
        "vendors": [
          "Adobe"
        ],
        "products": [
          {
            "vendor": "Adobe",
            "product": "Adobe Campaign Classic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@adobe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00542,
        "percentile": 0.42489
      },
      "nvd": {
        "published": "2026-07-30T03:16:24.957",
        "lastModified": "2026-08-03T19:16:47.320",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48449",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Adobe Campaign Classic permits unauthenticated code execution through an undisclosed authorization failure in on-premise components.",
        "basis": [
          "CNA",
          "CWE-863",
          "https://helpx.adobe.com/security/products/campaign/apsb26-114.html"
        ],
        "deepDive": true,
        "notes": "APSB26-114 confines the customer action to on-premise and hybrid on-premise components and names build 9398 as fixed, but does not identify the authorization decision."
      },
      "references": [
        {
          "url": "https://helpx.adobe.com/security/products/campaign/apsb26-114.html",
          "host": "helpx.adobe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48487",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:33:08.291Z",
      "date_published": "2026-07-17T18:28:21.417Z",
      "date_updated": "2026-07-20T19:26:06.005Z",
      "publisher": "GitHub_M",
      "title": "Zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet",
      "affected": {
        "vendors": [
          "python-zeroconf"
        ],
        "products": [
          {
            "vendor": "python-zeroconf",
            "product": "python-zeroconf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-130",
          "name": "Improper Handling of Length Parameter Inconsistency",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10465
      },
      "nvd": {
        "published": "2026-07-17T19:17:15.963",
        "lastModified": "2026-07-23T16:13:02.287",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48487",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The parser advances its offset by an attacker-declared RDLENGTH without checking the remaining DNS message size and caches truncated attacker-shaped records.",
        "basis": [
          "CNA",
          "CWE-130"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-qc2x-6f54-m6h9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/issues/1752",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/pull/1756",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/commit/544449596e645fcaad3834fa0cb614a54f847a82",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-zeroconf/python-zeroconf/releases/tag/0.149.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 563,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:33:08.291Z",
      "date_published": "2026-07-14T19:14:12.233Z",
      "date_updated": "2026-07-16T14:40:10.013Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "security-http"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00475,
        "percentile": 0.38584
      },
      "nvd": {
        "published": "2026-07-14T20:17:09.330",
        "lastModified": "2026-07-16T15:16:31.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48489",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A request-supplied failure path dispatches an internal subrequest that bypasses firewall listeners protecting the target GET route.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-6h46-9jf5-q59x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/c48a4276309e11aedeeb0ce3a89dfbf0b4fe04ff",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.53",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.41",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 486,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-48492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:33:08.292Z",
      "date_published": "2026-07-08T21:11:19.698Z",
      "date_updated": "2026-07-09T14:17:32.841Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT's selectlist visibility is too permissive",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13518
      },
      "nvd": {
        "published": "2026-07-08T22:17:14.870",
        "lastModified": "2026-07-10T19:46:50.507",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48492",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The selectlist endpoint performs its protected action without enforcing authorization.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-f3c5-6cw8-fg57",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/4f943d4a7ab8e53f3d9e32770602d1118bab005f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:33:08.292Z",
      "date_published": "2026-07-30T17:10:28.347Z",
      "date_updated": "2026-07-30T18:07:34.332Z",
      "publisher": "GitHub_M",
      "title": "Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache",
      "affected": {
        "vendors": [
          "activepieces"
        ],
        "products": [
          {
            "vendor": "activepieces",
            "product": "activepieces"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-668",
          "name": "Exposure of Resource to Wrong Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14915
      },
      "nvd": {
        "published": "2026-07-30T19:17:32.747",
        "lastModified": "2026-07-30T20:07:01.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48499",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unsanitized sandbox path segment selects read-write cached flow and code files belonging to another tenant.",
        "basis": [
          "CNA record",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/activepieces/activepieces/security/advisories/GHSA-5h2x-g6m3-grmq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/activepieces/activepieces/commit/9d8d328424bd32d295c5727af7550e1b57f9074d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/activepieces/activepieces/releases/tag/0.84.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 3,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48504",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T15:33:08.293Z",
      "date_published": "2026-07-17T20:13:45.686Z",
      "date_updated": "2026-07-20T15:18:22.372Z",
      "publisher": "GitHub_M",
      "title": "OpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagation",
      "affected": {
        "vendors": [
          "open-telemetry"
        ],
        "products": [
          {
            "vendor": "open-telemetry",
            "product": "opentelemetry-rust"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22767
      },
      "nvd": {
        "published": "2026-07-17T20:17:21.413",
        "lastModified": "2026-07-23T17:59:19.940",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48504",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "opentelemetry-rust allocates or queues attacker-driven work without a per-request or per-connection limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-telemetry/opentelemetry-rust/security/advisories/GHSA-w9wp-h8wv-79jx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-rust/commit/a389ca6b3e416416bc8fc9b01cf6076b9182ed14",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 598,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:34:46.417Z",
      "date_published": "2026-07-23T15:23:16.097Z",
      "date_updated": "2026-07-28T01:49:25.383Z",
      "publisher": "VulnCheck",
      "title": "GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspx",
      "affected": {
        "vendors": [
          "GFI Software"
        ],
        "products": [
          {
            "vendor": "GFI Software",
            "product": "GFI Archiver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03645
      },
      "nvd": {
        "published": "2026-07-23T16:17:25.250",
        "lastModified": "2026-07-23T17:55:03.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48530",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The classification wizard stores rule-name and email-criteria values without encoding and later renders them as executable HTML.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gfi.ai/products-and-solutions/network-security-solutions/archiver/resources/documentation/product-releases",
          "host": "gfi.ai",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gfi-archiver-stored-xss-via-categorizationpolicywizard-aspx",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48531",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:34:46.417Z",
      "date_published": "2026-07-23T15:25:13.555Z",
      "date_updated": "2026-07-28T01:49:26.050Z",
      "publisher": "VulnCheck",
      "title": "GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspx",
      "affected": {
        "vendors": [
          "GFI Software"
        ],
        "products": [
          {
            "vendor": "GFI Software",
            "product": "GFI Archiver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03638
      },
      "nvd": {
        "published": "2026-07-23T16:17:25.403",
        "lastModified": "2026-07-23T17:55:03.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48531",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In GFI Archiver, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gfi.ai/products-and-solutions/network-security-solutions/archiver/resources/documentation/product-releases",
          "host": "gfi.ai",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gfi-archiver-stored-xss-via-retentionpolicywizard-aspx",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 467,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48532",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:34:46.417Z",
      "date_published": "2026-07-23T15:26:00.747Z",
      "date_updated": "2026-07-28T01:49:26.700Z",
      "publisher": "VulnCheck",
      "title": "GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspx",
      "affected": {
        "vendors": [
          "GFI Software"
        ],
        "products": [
          {
            "vendor": "GFI Software",
            "product": "GFI Archiver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03638
      },
      "nvd": {
        "published": "2026-07-23T16:17:25.547",
        "lastModified": "2026-07-23T17:55:03.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48532",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gfi.ai/products-and-solutions/network-security-solutions/archiver/resources/documentation/product-releases",
          "host": "gfi.ai",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gfi-archiver-stored-xss-via-faaretentionpolicywizard-aspx",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48533",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-05-21T18:34:46.417Z",
      "date_published": "2026-07-23T15:27:26.552Z",
      "date_rejected": "2026-07-23T15:34:46.558Z",
      "date_updated": "2026-07-23T15:34:46.558Z",
      "publisher": "VulnCheck",
      "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
      "rejected_reason": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority."
    },
    {
      "cve_id": "CVE-2026-48534",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:34:46.417Z",
      "date_published": "2026-07-23T15:28:12.332Z",
      "date_updated": "2026-07-28T01:49:27.361Z",
      "publisher": "VulnCheck",
      "title": "GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx",
      "affected": {
        "vendors": [
          "GFI Software"
        ],
        "products": [
          {
            "vendor": "GFI Software",
            "product": "GFI Archiver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03643
      },
      "nvd": {
        "published": "2026-07-23T16:17:25.760",
        "lastModified": "2026-07-23T17:55:03.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48534",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SaveAllConfigSettings stores the attacker-controlled IMAP server URL and the configuration page later renders it without output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gfi.ai/products-and-solutions/network-security-solutions/archiver/resources/documentation/product-releases",
          "host": "gfi.ai",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gfi-archiver-stored-xss-via-imapserverwizard-aspx",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:34:46.417Z",
      "date_published": "2026-07-23T15:29:17.535Z",
      "date_updated": "2026-07-28T01:49:27.999Z",
      "publisher": "VulnCheck",
      "title": "GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspx",
      "affected": {
        "vendors": [
          "GFI Software"
        ],
        "products": [
          {
            "vendor": "GFI Software",
            "product": "GFI Archiver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03642
      },
      "nvd": {
        "published": "2026-07-23T16:17:25.903",
        "lastModified": "2026-07-27T17:16:36.327",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48535",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The GFI Archiver rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gfi.ai/products-and-solutions/network-security-solutions/archiver/resources/documentation/product-releases",
          "host": "gfi.ai",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gfi-archiver-stored-xss-via-callhomesettingswizard-aspx",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:34:46.417Z",
      "date_published": "2026-07-23T15:30:24.962Z",
      "date_updated": "2026-07-28T01:49:28.668Z",
      "publisher": "VulnCheck",
      "title": "GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspx",
      "affected": {
        "vendors": [
          "GFI Software"
        ],
        "products": [
          {
            "vendor": "GFI Software",
            "product": "GFI Archiver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03643
      },
      "nvd": {
        "published": "2026-07-23T16:17:26.037",
        "lastModified": "2026-07-23T17:55:03.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48536",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted bytes are interpreted as executable syntax without the required grammar separation.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gfi.ai/products-and-solutions/network-security-solutions/archiver/resources/documentation/product-releases",
          "host": "gfi.ai",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gfi-archiver-stored-xss-via-generalsettingswizard-aspx",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 469,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:34:46.417Z",
      "date_published": "2026-07-23T15:31:11.236Z",
      "date_updated": "2026-07-28T01:49:29.387Z",
      "publisher": "VulnCheck",
      "title": "GFI Archiver < 15.13 Stored XSS via FileArchiveAssistantWizard.aspx",
      "affected": {
        "vendors": [
          "GFI Software"
        ],
        "products": [
          {
            "vendor": "GFI Software",
            "product": "GFI Archiver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03643
      },
      "nvd": {
        "published": "2026-07-23T16:17:26.177",
        "lastModified": "2026-07-23T17:55:03.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48537",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The GFI Archiver rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gfi.ai/products-and-solutions/network-security-solutions/archiver/resources/documentation/product-releases",
          "host": "gfi.ai",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gfi-archiver-stored-xss-via-filearchiveassistantwizard-aspx",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:34:46.417Z",
      "date_published": "2026-07-23T15:32:04.790Z",
      "date_updated": "2026-07-28T01:49:30.050Z",
      "publisher": "VulnCheck",
      "title": "GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashx",
      "affected": {
        "vendors": [
          "GFI Software"
        ],
        "products": [
          {
            "vendor": "GFI Software",
            "product": "GFI Archiver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03637
      },
      "nvd": {
        "published": "2026-07-23T16:17:26.320",
        "lastModified": "2026-07-23T17:55:03.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48538",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GFI stores attacker-controlled input and renders it later as executable browser markup without the required encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gfi.ai/products-and-solutions/network-security-solutions/archiver/resources/documentation/product-releases",
          "host": "gfi.ai",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gfi-archiver-stored-xss-via-importsettingswizard-ashx",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48539",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T18:34:46.417Z",
      "date_published": "2026-07-23T15:32:59.409Z",
      "date_updated": "2026-07-28T01:49:30.714Z",
      "publisher": "VulnCheck",
      "title": "GFI Archiver < 15.13 Stored XSS via MailInsights.aspx",
      "affected": {
        "vendors": [
          "GFI Software"
        ],
        "products": [
          {
            "vendor": "GFI Software",
            "product": "GFI Archiver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03644
      },
      "nvd": {
        "published": "2026-07-23T16:17:26.470",
        "lastModified": "2026-07-23T17:55:03.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48539",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The injected payload is stored by ReportScheduling.btnSaveReport_Click() without output encoding and is executed in the browser of the user who created the scheduled report when they subsequently view the MailInsights page.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gfi.ai/products-and-solutions/network-security-solutions/archiver/resources/documentation/product-releases",
          "host": "gfi.ai",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gfi-archiver-stored-xss-via-mailinsights-aspx",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 490,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48561",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T20:00:35.245Z",
      "date_published": "2026-07-14T17:04:12.678Z",
      "date_updated": "2026-08-03T22:52:37.321Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge Copilot Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge Copilot for Android"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge Copilot for IOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00764,
        "percentile": 0.5188
      },
      "nvd": {
        "published": "2026-07-14T17:16:49.753",
        "lastModified": "2026-07-26T18:17:38.233",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48561",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Copilot Chat passes network-supplied input to a command interpreter without neutralizing command syntax.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48561",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48564",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T20:00:35.245Z",
      "date_published": "2026-07-14T17:05:46.287Z",
      "date_updated": "2026-08-03T22:54:09.592Z",
      "publisher": "microsoft",
      "title": "DHCP Server Service Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00763,
        "percentile": 0.51854
      },
      "nvd": {
        "published": "2026-07-14T17:16:49.873",
        "lastModified": "2026-07-16T16:35:15.907",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48564",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler writes attacker-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48564",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 111,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-48571",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T20:00:35.245Z",
      "date_published": "2026-07-14T17:04:25.140Z",
      "date_updated": "2026-08-03T22:52:53.365Z",
      "publisher": "microsoft",
      "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.1177
      },
      "nvd": {
        "published": "2026-07-14T17:16:50.023",
        "lastModified": "2026-07-22T16:17:26.493",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48571",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 11 version 23H2 can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48571",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-48572",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T20:00:35.245Z",
      "date_published": "2026-07-14T17:04:24.666Z",
      "date_updated": "2026-08-03T22:52:52.815Z",
      "publisher": "microsoft",
      "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06011
      },
      "nvd": {
        "published": "2026-07-14T17:16:50.257",
        "lastModified": "2026-07-16T16:23:25.280",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48572",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent Windows App Installer operations use a shared resource without the synchronization required to keep its privilege-sensitive state valid.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48572",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 177,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-48580",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T20:00:35.246Z",
      "date_published": "2026-07-14T17:08:29.197Z",
      "date_updated": "2026-08-03T22:56:48.750Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-822",
          "name": "Untrusted Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00459,
        "percentile": 0.37553
      },
      "nvd": {
        "published": "2026-07-14T18:17:20.033",
        "lastModified": "2026-07-15T19:43:22.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48580",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Excel dereferences a pointer derived from untrusted input without first establishing that the pointed-to memory is valid.",
        "basis": [
          "CNA",
          "CWE-822"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48580",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-48581",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T20:00:35.246Z",
      "date_published": "2026-07-14T17:05:46.776Z",
      "date_updated": "2026-08-03T22:54:10.226Z",
      "publisher": "microsoft",
      "title": "Surface Broker SDMA Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Surface Go"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Surface Hub"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Surface Laptop Go"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Surface Laptop Go 3"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Surface Pro"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Surface Pro 8"
          },
          {
            "vendor": "Microsoft",
            "product": "Surface Laptop 4 with AMD Processor"
          },
          {
            "vendor": "Microsoft",
            "product": "Surface Laptop 4 with Intel Processor"
          },
          {
            "vendor": "Microsoft",
            "product": "Surface Windows Dev Kit"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1220",
          "name": "Insufficient Granularity of Access Control",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11883
      },
      "nvd": {
        "published": "2026-07-14T17:16:50.767",
        "lastModified": "2026-07-24T13:37:22.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48581",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Surface Broker applies an access-control decision at insufficient granularity and thereby grants a local caller more privilege than intended.",
        "basis": [
          "CNA",
          "CWE-1220"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48581",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-48586",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T20:38:07.261Z",
      "date_published": "2026-07-27T11:02:54.430Z",
      "date_updated": "2026-07-27T13:03:46.048Z",
      "publisher": "apache",
      "title": "Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.01074,
        "percentile": 0.61682
      },
      "nvd": {
        "published": "2026-07-27T12:16:44.970",
        "lastModified": "2026-07-27T19:49:42.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48586",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Thrift expands highly compressed input without an effective amplification bound, allowing a small payload to consume disproportionate resources.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/p008svsjf9p6bj47wyyf5dgglq5z7xoq",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/37",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 264,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48588",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-21T20:50:32.466Z",
      "date_published": "2026-07-07T14:09:32.687Z",
      "date_updated": "2026-07-07T14:59:53.337Z",
      "publisher": "DSF",
      "title": "Potential exposure of private data via cached Set-Cookie response",
      "affected": {
        "vendors": [
          "djangoproject"
        ],
        "products": [
          {
            "vendor": "djangoproject",
            "product": "Django"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-524",
          "name": "Use of Cache Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 3,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28806
      },
      "nvd": {
        "published": "2026-07-07T15:16:47.447",
        "lastModified": "2026-07-09T13:01:25.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48588",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Django caches a cookie-varying response despite unrelated request cookies and can serve that private response from a shared cache to another caller.",
        "basis": [
          "CNA",
          "CWE-524"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.djangoproject.com/en/dev/releases/security/",
          "host": "docs.djangoproject.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://groups.google.com/g/django-announce",
          "host": "groups.google.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "mailing-list"
          ]
        },
        {
          "url": "https://www.djangoproject.com/weblog/2026/jul/07/security-releases/",
          "host": "www.djangoproject.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 475,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48614",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T15:00:09.276Z",
      "date_published": "2026-07-06T16:46:05.644Z",
      "date_updated": "2026-07-06T17:39:05.008Z",
      "publisher": "hackerone",
      "title": "An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.",
      "affected": {
        "vendors": [
          "WebPros"
        ],
        "products": [
          {
            "vendor": "WebPros",
            "product": "Plesk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25522
      },
      "nvd": {
        "published": "2026-07-06T18:16:46.130",
        "lastModified": "2026-07-06T19:41:00.653",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48614",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The XML API accepts attacker-controlled configuration directives as executable configuration grammar and writes their effects as root.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.plesk.com/hc/en-us/articles/41171817973143-Vulnerability-in-Plesk-XML-API",
          "host": "support.plesk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48736",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T19:10:35.746Z",
      "date_published": "2026-07-14T19:09:30.260Z",
      "date_updated": "2026-07-15T13:23:06.394Z",
      "publisher": "GitHub_M",
      "title": "Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "http-client"
          },
          {
            "vendor": "symfony",
            "product": "http-foundation"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.0046,
        "percentile": 0.37631
      },
      "nvd": {
        "published": "2026-07-14T20:17:09.943",
        "lastModified": "2026-07-16T03:12:24.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48736",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The private-network filter omits IPv6 transition prefixes that can encode private IPv4 destinations in an allowed form.",
        "basis": [
          "CNA",
          "CWE-184",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-38cx-cq6f-5755",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/82765368cf74177c36613575182f168a2eb765b2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/85b831555be8ea1f43bf01078afe87bc4c92f65e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.53",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.41",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 477,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-48747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T19:10:35.747Z",
      "date_published": "2026-07-14T19:16:24.327Z",
      "date_updated": "2026-07-15T14:22:53.743Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "mailomat-mailer"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-757",
          "name": "Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09717
      },
      "nvd": {
        "published": "2026-07-14T20:17:10.080",
        "lastModified": "2026-07-15T15:16:37.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48747",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Webhook verification accepts the HMAC algorithm named by the request instead of requiring the provider's documented SHA-256 algorithm.",
        "basis": [
          "CNA",
          "CWE-347",
          "CWE-757"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-rrj9-5q2j-4gvr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/bdfe9fe0d94d33dfaca0bc2fe0b00b54767b0c88",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-48758",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T19:39:05.356Z",
      "date_published": "2026-07-14T20:36:28.641Z",
      "date_updated": "2026-07-15T12:54:55.445Z",
      "publisher": "GitHub_M",
      "title": "sigstore-js: DSSE payloadType type-binding failure",
      "affected": {
        "vendors": [
          "sigstore"
        ],
        "products": [
          {
            "vendor": "sigstore",
            "product": "sigstore-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09601
      },
      "nvd": {
        "published": "2026-07-14T21:17:01.113",
        "lastModified": "2026-07-15T20:23:47.313",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48758",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "sigstore-js verifies a signature without binding every security-relevant field and required authority to the signed representation, allowing a modified or under-threshold object to pass verification.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sigstore/sigstore-js/security/advisories/GHSA-jfc7-64v2-mr8c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-js/pull/1657",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-js/commit/b5aa4f1f8d2db0a9dfa6430fb114d9c2f1c304f7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-js/releases/tag/%40sigstore%2Fcore%403.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T19:39:05.356Z",
      "date_published": "2026-07-14T19:11:42.179Z",
      "date_updated": "2026-07-15T14:36:03.339Z",
      "publisher": "GitHub_M",
      "title": "Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "html-sanitizer"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1007",
          "name": "Insufficient Visual Distinction of Homoglyphs Presented to User",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17488
      },
      "nvd": {
        "published": "2026-07-14T20:17:10.220",
        "lastModified": "2026-07-15T15:16:37.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48760",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "UrlSanitizer rejects raw visual-control characters but retains percent-encoded bidirectional marks and Unicode whitespace that downstream display can decode.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-451",
          "CWE-1007"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-v3wm-qf9p-c549",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/b21a626fd90f5c12d2db432c629eed3e780ba2f8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.41",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T19:39:05.356Z",
      "date_published": "2026-07-14T19:21:26.582Z",
      "date_updated": "2026-07-21T18:02:30.352Z",
      "publisher": "GitHub_M",
      "title": "Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv=\"refresh\"> content",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "html-sanitizer"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1023",
          "name": "Incomplete Comparison with Missing Factors",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18738
      },
      "nvd": {
        "published": "2026-07-14T20:17:10.363",
        "lastModified": "2026-07-21T19:17:10.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48761",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Symfony's sanitizer omits several URL-bearing attributes and meta-refresh content, allowing javascript URLs to survive sanitization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79",
          "CWE-1023"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-x5qj-865h-mgvm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/069a70f9f26e61e9de3b7f9a864a86ed24b36bd0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.41",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v8.0.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 519,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-48784",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:18:20.365Z",
      "date_published": "2026-07-14T19:04:20.058Z",
      "date_updated": "2026-07-15T13:27:22.254Z",
      "publisher": "GitHub_M",
      "title": "Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "symfony"
          },
          {
            "vendor": "symfony",
            "product": "routing"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-172",
          "name": "Encoding Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18662
      },
      "nvd": {
        "published": "2026-07-14T20:17:10.517",
        "lastModified": "2026-07-15T14:44:46.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48784",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "UrlGenerator skips alternating chained dot segments during encoding, so normal URL resolution can collapse the generated URL onto a different path.",
        "basis": [
          "CNA",
          "CWE-172",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/symfony/security/advisories/GHSA-h5x3-xfc9-m39h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/commit/4b63c3a3f7af04ecd79c89a594b0b02a01990b1d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v5.4.53",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v6.4.41",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/symfony/releases/tag/v7.4.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 450,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-48795",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:18:20.366Z",
      "date_published": "2026-07-15T21:23:14.393Z",
      "date_updated": "2026-07-16T18:49:54.392Z",
      "publisher": "GitHub_M",
      "title": "Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser",
      "affected": {
        "vendors": [
          "adonisjs"
        ],
        "products": [
          {
            "vendor": "adonisjs",
            "product": "core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22314
      },
      "nvd": {
        "published": "2026-07-15T22:16:50.383",
        "lastModified": "2026-07-16T19:16:49.773",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48795",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Nested multipart keys drive lodash set through ordinary intermediate objects and modify Object.prototype.",
        "basis": [
          "CNA",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/adonisjs/core/security/advisories/GHSA-qcm7-3vpr-hj5h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/adonisjs/bodyparser/commit/8a85eb0c2061b0caca10faedbfc2cf24b56cf9f6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/adonisjs/bodyparser/commit/aa96908f7b3f64c19e15d2d2d916b69137bdf469",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/adonisjs/bodyparser/releases/tag/v10.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/adonisjs/bodyparser/releases/tag/v11.0.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:18:20.366Z",
      "date_published": "2026-07-15T16:11:24.967Z",
      "date_updated": "2026-07-15T18:01:49.289Z",
      "publisher": "GitHub_M",
      "title": "Postiz: Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook",
      "affected": {
        "vendors": [
          "gitroomhq"
        ],
        "products": [
          {
            "vendor": "gitroomhq",
            "product": "postiz-app"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.0603
      },
      "nvd": {
        "published": "2026-07-15T17:16:48.667",
        "lastModified": "2026-07-15T20:54:57.420",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48799",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Postiz accepts a Nowpayments callback without verifying its shared-secret authenticity and trusts a body-supplied organization identifier for the credited tenant.",
        "basis": [
          "CNA",
          "CWE-345",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-j7rp-5mgj-qgg9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gitroomhq/postiz-app/commit/23696d2973510ae1f3f48bfa41a6bfbbf9827b05",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://gadvisory.org/advisories/PSA-2026-Q3TCPK",
          "host": "gadvisory.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gitroomhq/postiz-app/releases/tag/v2.21.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 394,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:18:20.367Z",
      "date_published": "2026-07-14T20:03:56.430Z",
      "date_updated": "2026-07-15T12:56:15.250Z",
      "publisher": "GitHub_M",
      "title": "linkify-it: Quadratic algorithmic complexity in LinkifyIt#match scan loop",
      "affected": {
        "vendors": [
          "markdown-it"
        ],
        "products": [
          {
            "vendor": "markdown-it",
            "product": "linkify-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20958
      },
      "nvd": {
        "published": "2026-07-14T21:17:01.247",
        "lastModified": "2026-07-15T20:21:13.857",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48801",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/markdown-it/linkify-it/security/advisories/GHSA-22p9-wv53-3rq4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/markdown-it/linkify-it/commit/6be6d15e0641bf1daeaa977d500cabc743166159",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48805",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:57:10.975Z",
      "date_published": "2026-07-14T21:26:34.876Z",
      "date_updated": "2026-07-16T15:09:20.665Z",
      "publisher": "GitHub_M",
      "title": "Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.0027,
        "percentile": 0.19027
      },
      "nvd": {
        "published": "2026-07-14T22:17:04.773",
        "lastModified": "2026-07-17T03:18:15.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48805",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Deprecated Twig wrappers omit the current sandbox state when checking arrow callables, so legacy calls bypass sandbox callable restrictions.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-p42q-9prx-q5wq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/e235cae3a1d1e23edc24df4d675f18108c6b167b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.27.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 395,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:57:10.975Z",
      "date_published": "2026-07-14T21:28:08.781Z",
      "date_updated": "2026-07-15T12:47:14.623Z",
      "publisher": "GitHub_M",
      "title": "Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14384
      },
      "nvd": {
        "published": "2026-07-14T22:17:04.943",
        "lastModified": "2026-07-17T03:17:51.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48806",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Twig coerces dynamic mapping keys through __toString() without running the sandbox's ensureToStringAllowed() policy check.",
        "basis": [
          "CNA",
          "CWE-693",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-5v5v-ww74-355v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/9ff41014639ef0e8eb50ac7669191c309d863105",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.27.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 313,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:57:10.975Z",
      "date_published": "2026-07-14T21:29:15.934Z",
      "date_updated": "2026-07-15T12:50:42.588Z",
      "publisher": "GitHub_M",
      "title": "Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12013
      },
      "nvd": {
        "published": "2026-07-14T22:17:05.090",
        "lastModified": "2026-07-17T03:16:31.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48807",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Twig's sandbox omits policy checks when Traversable values are coerced through selected filters and operators, allowing contained Stringable objects to execute __toString().",
        "basis": [
          "CNA",
          "CWE-693",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-8x9c-rmqh-456c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.27.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 353,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48808",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:57:10.976Z",
      "date_published": "2026-07-14T21:27:21.812Z",
      "date_updated": "2026-07-15T14:31:58.897Z",
      "publisher": "GitHub_M",
      "title": "Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15035
      },
      "nvd": {
        "published": "2026-07-14T22:17:05.427",
        "lastModified": "2026-07-17T03:16:15.253",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48808",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Twig's column filter drops the current Source before the property-policy check, so the sandbox evaluates a weaker authorization context.",
        "basis": [
          "CNA",
          "CWE-693",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-h8vq-8gpg-mhcg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/09c6706407ed7b1cb2d7d1408004f811e47e0424",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.27.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:57:10.976Z",
      "date_published": "2026-07-20T17:32:46.125Z",
      "date_updated": "2026-07-20T18:25:47.624Z",
      "publisher": "GitHub_M",
      "title": "FreeScout Allows Unauthenticated Access to Legacy Attachment Files",
      "affected": {
        "vendors": [
          "freescout-help-desk"
        ],
        "products": [
          {
            "vendor": "freescout-help-desk",
            "product": "freescout"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00368,
        "percentile": 0.29531
      },
      "nvd": {
        "published": "2026-07-20T18:16:53.173",
        "lastModified": "2026-07-21T19:25:11.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48812",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The attachment route skips token authentication whenever token_type marks a deterministic legacy attachment.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-wg74-ww4w-2qpc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/freescout-help-desk/freescout/commit/215241ee2eb73eaa3b47e392599c7dc1b427dc7e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48815",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:57:10.976Z",
      "date_published": "2026-07-14T20:27:16.925Z",
      "date_updated": "2026-07-15T12:56:29.848Z",
      "publisher": "GitHub_M",
      "title": "sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforced",
      "affected": {
        "vendors": [
          "sigstore"
        ],
        "products": [
          {
            "vendor": "sigstore",
            "product": "sigstore-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04044
      },
      "nvd": {
        "published": "2026-07-14T21:17:01.370",
        "lastModified": "2026-07-15T20:23:47.313",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48815",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "sigstore-js drops configured certificate OID constraints before verification and can accept a signer outside the application's allowed certificate set.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sigstore/sigstore-js/security/advisories/GHSA-52v5-jr5w-gjxr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-js/pull/1658",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-js/commit/7845532f9d17f6f765363dbee82b01bd159fb52b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-js/releases/tag/sigstore%404.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 448,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48816",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:57:10.976Z",
      "date_published": "2026-07-14T20:39:05.532Z",
      "date_updated": "2026-07-15T14:26:01.060Z",
      "publisher": "GitHub_M",
      "title": "sigstore-js: Insufficient Verification of Data Authenticity",
      "affected": {
        "vendors": [
          "sigstore"
        ],
        "products": [
          {
            "vendor": "sigstore",
            "product": "sigstore-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02495
      },
      "nvd": {
        "published": "2026-07-14T21:17:01.497",
        "lastModified": "2026-07-15T20:23:47.313",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48816",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unbound integratedTime value controls certificate and timestamp validation instead of authenticated timing evidence.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sigstore/sigstore-js/security/advisories/GHSA-xgjw-pm74-86q4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-js/pull/1659",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-js/commit/f074710a91ea9260a9ac2142345634579843a3cd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-js/releases/tag/%40sigstore%2Fverify%403.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 489,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48819",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:57:10.976Z",
      "date_published": "2026-07-17T19:46:00.402Z",
      "date_updated": "2026-07-20T16:24:20.624Z",
      "publisher": "GitHub_M",
      "title": "Hey API: `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key",
      "affected": {
        "vendors": [
          "hey-api"
        ],
        "products": [
          {
            "vendor": "hey-api",
            "product": "openapi-ts"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12761
      },
      "nvd": {
        "published": "2026-07-17T20:17:21.553",
        "lastModified": "2026-07-23T18:02:00.793",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48819",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "buildClientParams writes an unknown slot key named __proto__ and changes the target object's prototype.",
        "basis": [
          "CNA record",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hey-api/hey-api/security/advisories/GHSA-hhx9-57xq-r5rw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hey-api/hey-api/commit/023909137a15eff9c0263d3bcd116140076b214f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hey-api/hey-api/commit/da321a1529eb3c90d2109da870f514b915a60169",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hey-api/hey-api/releases/tag/%40hey-api%2Fopenapi-ts%400.97.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 619,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48824",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-22T20:57:10.977Z",
      "date_published": "2026-07-20T15:02:52.107Z",
      "date_updated": "2026-07-20T19:07:58.952Z",
      "publisher": "GitHub_M",
      "title": "Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)",
      "affected": {
        "vendors": [
          "axllent"
        ],
        "products": [
          {
            "vendor": "axllent",
            "product": "mailpit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00421,
        "percentile": 0.34698
      },
      "nvd": {
        "published": "2026-07-20T16:17:03.080",
        "lastModified": "2026-07-28T15:24:17.230",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48824",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mailpit allocates or queues attacker-driven work without a per-request or per-connection limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/axllent/mailpit/security/advisories/GHSA-28pq-6qxg-wg5r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/axllent/mailpit/releases/tag/v1.30.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 973,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48828",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-23T13:48:30.828Z",
      "date_published": "2026-07-07T09:18:53.833Z",
      "date_updated": "2026-07-07T13:47:31.600Z",
      "publisher": "apache",
      "title": "Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33687
      },
      "nvd": {
        "published": "2026-07-07T10:16:41.260",
        "lastModified": "2026-07-08T19:26:11.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48828",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The bulk Variables API calls the redactor without the variable key, so key-based secret rules cannot hide JSON values.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/airflow/pull/67495",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/y9kf314t6dhnv994hr11wj3tbow847yc",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/07/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48863",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-25T20:59:30.305Z",
      "date_published": "2026-07-16T00:46:12.846Z",
      "date_updated": "2026-07-18T02:39:45.746Z",
      "publisher": "redhat",
      "title": "Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service",
      "affected": {
        "vendors": [
          "OpenSUSE",
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "OpenSUSE",
            "product": "libsolv"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Satellite 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Update Infrastructure 4 for Cloud Providers"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0047,
        "percentile": 0.38207
      },
      "nvd": {
        "published": "2026-07-16T01:16:30.830",
        "lastModified": "2026-07-18T03:16:36.330",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48863",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In libsolv, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-48863",
          "host": "access.redhat.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460975",
          "host": "bugzilla.redhat.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/openSUSE/libsolv/commit/44f8c085045b1f771641091bbb2b810d12cff9e8#diff-309f245ec9b669ec78b8159c39e6f50130b4d4a0448f742685f7833d04bc4caaR592",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48863.json",
          "host": "security.access.redhat.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "x_sadp-csaf-vex"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 412,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48891",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T01:31:02.693Z",
      "date_published": "2026-07-07T09:17:28.748Z",
      "date_updated": "2026-07-07T13:25:31.445Z",
      "publisher": "apache",
      "title": "Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00393,
        "percentile": 0.31999
      },
      "nvd": {
        "published": "2026-07-07T10:16:41.373",
        "lastModified": "2026-07-09T13:16:42.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48891",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Airflow filters top-level DAG keys but leaves unauthorized DAG identifiers in dependency source and target fields.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/airflow/pull/67627",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "patch"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-28563",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "related"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/wzc8nflg94rq6w8f5tvtlo0o3g4wjrfl",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 926,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48892",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T01:39:22.505Z",
      "date_published": "2026-07-07T09:16:26.466Z",
      "date_updated": "2026-07-07T13:23:08.572Z",
      "publisher": "apache",
      "title": "Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33687
      },
      "nvd": {
        "published": "2026-07-07T10:16:41.480",
        "lastModified": "2026-07-09T13:16:57.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48892",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Airflow's Config API represents per-key secrets-backend environment overrides as synthetic options omitted from sensitive_config_values, so the masker returns plaintext credentials.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/airflow/pull/67622",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/pq5yy40079h6tzh3fxvw28dd8dbk72hk",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/07/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 655,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48910",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T10:41:07.254Z",
      "date_published": "2026-07-30T15:56:33.613Z",
      "date_updated": "2026-07-30T16:37:15.693Z",
      "publisher": "apache",
      "title": "Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache JSPWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-80",
          "name": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16687
      },
      "nvd": {
        "published": "2026-07-30T16:17:12.637",
        "lastModified": "2026-07-30T19:33:40.490",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48910",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Apache JSPWiki rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-80"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/yvbdjnocw5qq3xkbjs9h77ghlg0bsw2c",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/18",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48947",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T16:47:13.550Z",
      "date_published": "2026-07-07T17:32:45.116Z",
      "date_updated": "2026-07-08T09:56:00.315Z",
      "publisher": "Joomla",
      "title": "Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints",
      "affected": {
        "vendors": [
          "Joomla! Project"
        ],
        "products": [
          {
            "vendor": "Joomla! Project",
            "product": "Joomla! CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09715
      },
      "nvd": {
        "published": "2026-07-07T19:16:52.607",
        "lastModified": "2026-07-09T14:26:48.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48947",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A privileged user can overwrite media files even when the caller lacks edit permission for those files.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developer.joomla.org/security-centre/1055-20260701-core-incorrect-access-control-in-com-media-webservice-endpoints.html",
          "host": "developer.joomla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48948",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T16:47:13.550Z",
      "date_published": "2026-07-07T17:29:47.142Z",
      "date_updated": "2026-07-08T09:52:52.045Z",
      "publisher": "Joomla",
      "title": "Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download",
      "affected": {
        "vendors": [
          "Joomla! Project"
        ],
        "products": [
          {
            "vendor": "Joomla! Project",
            "product": "Joomla! CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 2.4000000000000004,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15254
      },
      "nvd": {
        "published": "2026-07-07T19:16:52.800",
        "lastModified": "2026-07-09T14:20:16.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48948",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The com_contact vCard download checks access incompletely and returns contacts that the caller is not permitted to view.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developer.joomla.org/security-centre/1056-20260702-core-incorrect-access-control-in-com-contact-vcf-download.html",
          "host": "developer.joomla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48949",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T16:47:13.550Z",
      "date_published": "2026-07-07T17:29:33.872Z",
      "date_updated": "2026-07-08T09:52:37.880Z",
      "publisher": "Joomla",
      "title": "Joomla! Core - [20260703] - XSS in MFA method management",
      "affected": {
        "vendors": [
          "Joomla! Project"
        ],
        "products": [
          {
            "vendor": "Joomla! Project",
            "product": "Joomla! CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04431
      },
      "nvd": {
        "published": "2026-07-07T19:16:53.203",
        "lastModified": "2026-07-09T13:52:59.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48949",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MFA views render attacker-controlled input as executable browser markup without the required context encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developer.joomla.org/security-centre/1057-20260703-core-xss-in-mfa-method-management.html",
          "host": "developer.joomla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 77,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48950",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T16:47:13.550Z",
      "date_published": "2026-07-07T17:31:46.968Z",
      "date_updated": "2026-07-08T09:54:59.780Z",
      "publisher": "Joomla",
      "title": "Joomla! Core - [20260704] - XSS in com_templates",
      "affected": {
        "vendors": [
          "Joomla! Project"
        ],
        "products": [
          {
            "vendor": "Joomla! Project",
            "product": "Joomla! CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00147,
        "percentile": 0.0443
      },
      "nvd": {
        "published": "2026-07-07T19:16:53.543",
        "lastModified": "2026-07-09T13:48:02.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48950",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developer.joomla.org/security-centre/1058-20260704-core-xss-in-com-templates.html",
          "host": "developer.joomla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 92,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48951",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T16:47:13.550Z",
      "date_published": "2026-07-07T17:30:24.904Z",
      "date_updated": "2026-07-08T09:53:34.261Z",
      "publisher": "Joomla",
      "title": "Joomla! Core - [20260705] - XSS in various modalreturn layouts",
      "affected": {
        "vendors": [
          "Joomla! Project"
        ],
        "products": [
          {
            "vendor": "Joomla! Project",
            "product": "Joomla! CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04431
      },
      "nvd": {
        "published": "2026-07-07T19:16:53.680",
        "lastModified": "2026-07-09T13:44:41.940",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48951",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Joomla modalreturn layouts render attacker-controlled values without HTML-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developer.joomla.org/security-centre/1059-20260705-core-xss-in-various-modalreturn-layouts.html",
          "host": "developer.joomla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 91,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48952",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T16:47:13.550Z",
      "date_published": "2026-07-07T17:33:39.504Z",
      "date_updated": "2026-07-08T09:56:50.251Z",
      "publisher": "Joomla",
      "title": "Joomla! Core - [20260706] - XSS in com_installer",
      "affected": {
        "vendors": [
          "Joomla! Project"
        ],
        "products": [
          {
            "vendor": "Joomla! Project",
            "product": "Joomla! CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04431
      },
      "nvd": {
        "published": "2026-07-07T19:16:53.810",
        "lastModified": "2026-07-09T13:43:43.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48952",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developer.joomla.org/security-centre/1060-20260706-core-xss-in-com-installer.html",
          "host": "developer.joomla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 88,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48953",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T16:47:13.550Z",
      "date_published": "2026-07-07T17:30:00.427Z",
      "date_updated": "2026-07-08T09:53:08.632Z",
      "publisher": "Joomla",
      "title": "Joomla! Core - [20260707] - XSS in the generic image output layout",
      "affected": {
        "vendors": [
          "Joomla! Project"
        ],
        "products": [
          {
            "vendor": "Joomla! Project",
            "product": "Joomla! CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04431
      },
      "nvd": {
        "published": "2026-07-07T19:16:53.933",
        "lastModified": "2026-07-09T13:32:08.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48953",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developer.joomla.org/security-centre/1061-20260707-core-xss-in-the-generic-image-output-layout.html",
          "host": "developer.joomla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48954",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T16:47:13.550Z",
      "date_published": "2026-07-07T17:29:28.797Z",
      "date_updated": "2026-07-08T09:52:30.862Z",
      "publisher": "Joomla",
      "title": "Joomla! Core - [20260708] - XSS through language overrides",
      "affected": {
        "vendors": [
          "Joomla! Project"
        ],
        "products": [
          {
            "vendor": "Joomla! Project",
            "product": "Joomla! CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00147,
        "percentile": 0.0443
      },
      "nvd": {
        "published": "2026-07-07T19:16:54.060",
        "lastModified": "2026-07-09T14:44:43.660",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48954",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developer.joomla.org/security-centre/1062-20260708-core-xss-through-language-overrides.html",
          "host": "developer.joomla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48955",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T16:47:13.550Z",
      "date_published": "2026-07-07T17:31:35.096Z",
      "date_updated": "2026-07-08T09:54:46.961Z",
      "publisher": "Joomla",
      "title": "Joomla! Core - [20260709] - Incorrect Access Control in com_workflow",
      "affected": {
        "vendors": [
          "Joomla! Project"
        ],
        "products": [
          {
            "vendor": "Joomla! Project",
            "product": "Joomla! CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.09999999999999964,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11074
      },
      "nvd": {
        "published": "2026-07-07T19:16:54.193",
        "lastModified": "2026-07-09T17:00:04.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48955",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Joomla! CMS permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developer.joomla.org/security-centre/1063-20260709-core-incorrect-access-control-in-com-workflow.html",
          "host": "developer.joomla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-48956",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T16:47:13.550Z",
      "date_published": "2026-07-07T17:31:34.152Z",
      "date_updated": "2026-07-08T09:54:45.131Z",
      "publisher": "Joomla",
      "title": "Joomla! Core - [20260710] - Incorrect Access Control in com_modules",
      "affected": {
        "vendors": [
          "Joomla! Project"
        ],
        "products": [
          {
            "vendor": "Joomla! Project",
            "product": "Joomla! CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06402
      },
      "nvd": {
        "published": "2026-07-07T19:16:54.313",
        "lastModified": "2026-07-09T16:58:49.893",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48956",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "com_modules exposes the frontend module list to a user lacking the required access, but the exact permission predicate is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developer.joomla.org/security-centre/1064-20260710-core-incorrect-access-control-in-com-modules.html",
          "host": "developer.joomla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48957",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T16:47:13.550Z",
      "date_published": "2026-07-07T17:30:38.205Z",
      "date_updated": "2026-07-08T09:53:48.446Z",
      "publisher": "Joomla",
      "title": "Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints",
      "affected": {
        "vendors": [
          "Joomla! Project"
        ],
        "products": [
          {
            "vendor": "Joomla! Project",
            "product": "Joomla! CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 2.4000000000000004,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15254
      },
      "nvd": {
        "published": "2026-07-07T19:16:54.440",
        "lastModified": "2026-07-09T16:57:34.057",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48957",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Joomla's com_privacy service exposes privacy datasets without the required access check, although the exact endpoint check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developer.joomla.org/security-centre/1065-20260711-core-incorrect-access-control-in-com-privacy-webservice-endpoints.html",
          "host": "developer.joomla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48958",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T16:47:13.550Z",
      "date_published": "2026-07-07T17:32:35.922Z",
      "date_updated": "2026-07-08T09:55:50.241Z",
      "publisher": "Joomla",
      "title": "Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints",
      "affected": {
        "vendors": [
          "Joomla! Project"
        ],
        "products": [
          {
            "vendor": "Joomla! Project",
            "product": "Joomla! CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 2.4000000000000004,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17831
      },
      "nvd": {
        "published": "2026-07-07T19:16:54.567",
        "lastModified": "2026-07-09T16:55:31.333",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-48958",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The com_fields web-service endpoint lets an unauthorized user create custom fields, but the public record does not identify the missing route or capability check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developer.joomla.org/security-centre/1066-20260712-core-incorrect-access-control-in-com-fields-webservice-endpoints.html",
          "host": "developer.joomla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-48978",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-26T23:26:07.974Z",
      "date_published": "2026-07-17T19:34:53.690Z",
      "date_updated": "2026-07-21T02:06:49.654Z",
      "publisher": "GitHub_M",
      "title": "oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens",
      "affected": {
        "vendors": [
          "oras-project"
        ],
        "products": [
          {
            "vendor": "oras-project",
            "product": "oras-go"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-319",
          "name": "Cleartext Transmission of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11423
      },
      "nvd": {
        "published": "2026-07-17T20:17:21.693",
        "lastModified": "2026-07-23T18:08:07.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-48978",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The registry client follows an unvalidated bearer-token realm host and scheme, allowing requests and credentials to cross the registry trust boundary.",
        "basis": [
          "CNA",
          "CWE-319",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/oras-project/oras-go/security/advisories/GHSA-xf85-363p-868w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/oras-project/oras-go/commit/7a9f4b0b9558821b0422152ebe21ae56930fe764",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/oras-project/oras-go/releases/tag/v2.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 593,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49033",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T15:40:50.740Z",
      "date_published": "2026-07-07T21:53:38.630Z",
      "date_updated": "2026-07-08T13:08:40.658Z",
      "publisher": "icscert",
      "title": "Stack-Based Buffer Overflow in Labcenter Proteus",
      "affected": {
        "vendors": [
          "Labcenter"
        ],
        "products": [
          {
            "vendor": "Labcenter",
            "product": "Proteus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03055
      },
      "nvd": {
        "published": "2026-07-07T22:16:52.637",
        "lastModified": "2026-07-09T19:48:15.277",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49033",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Proteus copies attacker-controlled data beyond a stack buffer and can overwrite control data.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-06",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49035",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:01:29.554Z",
      "date_published": "2026-07-23T20:48:18.888Z",
      "date_updated": "2026-07-24T13:42:05.960Z",
      "publisher": "icscert",
      "title": "Stack-based Buffer Overflow in MZ Automation libIEC61850",
      "affected": {
        "vendors": [
          "MZ Automation"
        ],
        "products": [
          {
            "vendor": "MZ Automation",
            "product": "libIEC61850"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29663
      },
      "nvd": {
        "published": "2026-07-23T21:17:04.620",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49035",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In libIEC61850, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49042",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T07:43:27.847Z",
      "date_published": "2026-07-06T09:34:48.956Z",
      "date_updated": "2026-07-06T21:31:59.344Z",
      "publisher": "apache",
      "title": "Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00524,
        "percentile": 0.41548
      },
      "nvd": {
        "published": "2026-07-06T11:16:29.607",
        "lastModified": "2026-07-08T14:38:10.537",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49042",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Apache Camel langchain4j-tools forwards undeclared message headers as tool arguments instead of restricting the call to the parameters declared by the tool interface.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-49042.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/06/17",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49086",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T11:04:35.426Z",
      "date_published": "2026-07-06T08:10:06.768Z",
      "date_updated": "2026-07-06T19:04:56.921Z",
      "publisher": "apache",
      "title": "Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to influence internal behaviour",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel Dapr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00426,
        "percentile": 0.35075
      },
      "nvd": {
        "published": "2026-07-06T09:16:38.120",
        "lastModified": "2026-07-08T14:53:56.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49086",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Dapr consumer copies attacker-controlled source routing fields into producer-direction headers that override the route's configured destination.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20",
          "CWE-441"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-49086.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/21",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2025,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-49087",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T11:31:33.582Z",
      "date_published": "2026-07-01T16:35:19.567Z",
      "date_updated": "2026-07-01T17:25:07.782Z",
      "publisher": "elastic",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20401
      },
      "nvd": {
        "published": "2026-07-01T17:16:35.687",
        "lastModified": "2026-07-02T17:53:01.593",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49087",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kibana accepts attacker-controlled work or allocation without an effective size, count, rate, or timeout bound.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-8-19-15-9-3-4-security-update-esa-2026-49",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 298,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49088",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T11:31:33.582Z",
      "date_published": "2026-07-01T16:59:24.086Z",
      "date_updated": "2026-07-01T17:25:07.634Z",
      "publisher": "elastic",
      "title": "Insertion of Sensitive Information into Log File in Kibana Leading to Information Disclosure",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11529
      },
      "nvd": {
        "published": "2026-07-01T17:16:35.807",
        "lastModified": "2026-07-02T17:52:31.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49088",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kibana's optional APM instrumentation writes sensitive request-header values into application logs visible to log operators.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-8-18-9-8-19-6-9-0-8-9-1-6-security-update-esa-2026-50",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-49090",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T11:31:33.582Z",
      "date_published": "2026-07-01T17:15:54.359Z",
      "date_updated": "2026-07-01T17:56:42.069Z",
      "publisher": "elastic",
      "title": "Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Elasticsearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16493
      },
      "nvd": {
        "published": "2026-07-01T18:16:33.540",
        "lastModified": "2026-07-02T14:43:04.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49090",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A crafted Elasticsearch bulk request triggers sustained CPU work without an effective processing bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/elasticsearch-7-17-24-8-15-0-security-update-esa-2026-52",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49091",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T11:31:33.582Z",
      "date_published": "2026-07-01T17:21:28.544Z",
      "date_updated": "2026-07-02T03:57:31.736Z",
      "publisher": "elastic",
      "title": "Improper Output Neutralization for Logs in Kibana Leading to Log Injection",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10174
      },
      "nvd": {
        "published": "2026-07-01T18:16:34.040",
        "lastModified": "2026-07-02T18:15:39.927",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49091",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kibana records attacker-controlled terminal control sequences in logs without neutralizing them for the log viewer.",
        "basis": [
          "CNA",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-7-17-15-8-11-1-security-update-esa-2026-53",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49092",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T11:31:33.582Z",
      "date_published": "2026-07-21T19:28:36.675Z",
      "date_updated": "2026-07-22T18:26:06.728Z",
      "publisher": "elastic",
      "title": "Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information Exposure",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05843
      },
      "nvd": {
        "published": "2026-07-21T20:17:01.610",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49092",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Kibana processes a low-privileged caller's request with another user's authority and returns data outside the caller's ACL.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-54/388553",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 351,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49097",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T11:43:12.917Z",
      "date_published": "2026-07-06T08:10:26.965Z",
      "date_updated": "2026-07-06T19:02:56.155Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or users",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00561,
        "percentile": 0.43529
      },
      "nvd": {
        "published": "2026-07-06T09:16:38.240",
        "lastModified": "2026-07-08T03:12:14.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49097",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Camel IRC control headers use names that pass the HTTP header filter and let an inbound HTTP client override the trusted IRC destination.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-49097.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/22",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2128,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-49098",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T11:44:53.864Z",
      "date_published": "2026-07-06T08:10:43.227Z",
      "date_updated": "2026-07-07T12:27:08.483Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00532,
        "percentile": 0.4196
      },
      "nvd": {
        "published": "2026-07-06T09:16:38.357",
        "lastModified": "2026-07-08T03:11:33.087",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49098",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Raw kafka.* headers can cross an HTTP-to-Kafka route and override the configured topic because the upstream filter recognizes only Camel-prefixed control headers.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-49098.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/23",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2558,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-49099",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T11:46:24.688Z",
      "date_published": "2026-07-06T08:11:30.540Z",
      "date_updated": "2026-07-07T12:30:34.187Z",
      "publisher": "apache",
      "title": "Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel Salesforce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00341,
        "percentile": 0.26739
      },
      "nvd": {
        "published": "2026-07-06T09:16:38.487",
        "lastModified": "2026-07-08T03:10:36.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49099",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Raw HTTP headers can override trusted Salesforce producer parameters because their names evade Camel's inbound control-header filter.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-49099.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/24",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2837,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-49119",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T17:40:12.737Z",
      "date_published": "2026-07-01T18:30:38.749Z",
      "date_updated": "2026-07-14T21:33:12.523Z",
      "publisher": "VulnCheck",
      "title": "Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess()",
      "affected": {
        "vendors": [
          "gradio-app"
        ],
        "products": [
          {
            "vendor": "gradio-app",
            "product": "gradio"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.0069,
        "percentile": 0.49253
      },
      "nvd": {
        "published": "2026-07-01T19:16:52.463",
        "lastModified": "2026-07-14T22:17:06.273",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49119",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled path or reference can select a file outside the intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gradio-app/gradio/releases/tag/gradio%406.16.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/gradio-app/gradio/pull/13437",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/gradio-app/gradio/commit/97d541f3d5fd05b2587a69ecc94b68fe5d2d7004",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gradio-path-traversal-via-fileexplorer-preprocess",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Release Notes",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T17:50:04.538Z",
      "date_published": "2026-07-08T14:55:13.819Z",
      "date_updated": "2026-07-08T17:31:32.120Z",
      "publisher": "CPANSec",
      "title": "App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc",
      "affected": {
        "vendors": [
          "PETDANCE"
        ],
        "products": [
          {
            "vendor": "PETDANCE",
            "product": "App::Ack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-426",
          "name": "Untrusted Search Path",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00329,
        "percentile": 0.25451
      },
      "nvd": {
        "published": "2026-07-08T15:16:27.563",
        "lastModified": "2026-07-08T20:16:50.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49145",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ack loads options from an untrusted project .ackrc whose blocklist permits --files-from to select files outside the project.",
        "basis": [
          "CNA",
          "CWE-73",
          "CWE-426"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/PETDANCE/ack-v3.10.0/source/Changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/08/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 604,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49146",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T17:50:04.538Z",
      "date_published": "2026-07-08T14:55:37.207Z",
      "date_updated": "2026-07-08T17:31:33.218Z",
      "publisher": "CPANSec",
      "title": "App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc",
      "affected": {
        "vendors": [
          "PETDANCE"
        ],
        "products": [
          {
            "vendor": "PETDANCE",
            "product": "App::Ack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30217
      },
      "nvd": {
        "published": "2026-07-08T15:16:27.673",
        "lastModified": "2026-07-08T20:16:50.503",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49146",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted .ackrc context value drives an allocation without an effective size bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/beyondgrep/ack3/commit/45ff5fe77dbd96f7332f31943102291f878f30b8.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/release/PETDANCE/ack-v3.10.0/source/Changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/08/8",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 553,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T17:50:04.538Z",
      "date_published": "2026-07-08T14:55:50.232Z",
      "date_updated": "2026-07-08T17:31:34.336Z",
      "publisher": "CPANSec",
      "title": "App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes",
      "affected": {
        "vendors": [
          "PETDANCE"
        ],
        "products": [
          {
            "vendor": "PETDANCE",
            "product": "App::Ack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-150",
          "name": "Improper Neutralization of Escape, Meta, or Control Sequences",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00329,
        "percentile": 0.25451
      },
      "nvd": {
        "published": "2026-07-08T15:16:27.787",
        "lastModified": "2026-07-08T20:16:50.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49147",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ack prints raw filename control bytes to a terminal without neutralizing cursor, color, or other escape sequences.",
        "basis": [
          "CNA record",
          "CWE-150"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/PETDANCE/ack-v3.10.0/source/Changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/08/9",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 643,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:08:39.282Z",
      "date_published": "2026-07-27T11:05:07.157Z",
      "date_updated": "2026-07-27T13:04:21.271Z",
      "publisher": "apache",
      "title": "Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01097,
        "percentile": 0.62373
      },
      "nvd": {
        "published": "2026-07-27T12:16:45.113",
        "lastModified": "2026-07-27T19:50:09.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49158",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache Thrift expands attacker-controlled archive content without a bound on resulting resource use.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/fmjl8l415tj9zwlob8v2dr5hq1d0hts7",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/38",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49159",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.622Z",
      "date_published": "2026-07-24T00:01:11.315Z",
      "date_updated": "2026-08-03T22:59:14.246Z",
      "publisher": "microsoft",
      "title": "Microsoft Graph Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Graph"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00552,
        "percentile": 0.43043
      },
      "nvd": {
        "published": "2026-07-24T01:16:40.230",
        "lastModified": "2026-07-29T14:16:24.510",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49159",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft Graph returns sensitive information to an authorized network caller outside the caller's intended data scope, but the output path is not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49159",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49162",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.622Z",
      "date_published": "2026-07-14T17:04:25.616Z",
      "date_updated": "2026-08-03T22:52:53.835Z",
      "publisher": "microsoft",
      "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09921
      },
      "nvd": {
        "published": "2026-07-14T17:16:50.903",
        "lastModified": "2026-07-22T16:17:26.847",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49162",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 11 Version 24H2, a path retains or reuses an object after the lifetime transition that frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49162",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 110,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-49164",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.622Z",
      "date_published": "2026-07-14T17:04:26.168Z",
      "date_updated": "2026-08-03T22:52:54.317Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00649,
        "percentile": 0.47579
      },
      "nvd": {
        "published": "2026-07-14T17:16:51.033",
        "lastModified": "2026-07-22T16:17:26.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49164",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input exceeds a heap allocation because the write is not bounded to the allocated size.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49164",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49165",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.622Z",
      "date_published": "2026-07-14T17:04:26.651Z",
      "date_updated": "2026-08-03T22:52:54.920Z",
      "publisher": "microsoft",
      "title": "Microsoft Windows App Store Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15529
      },
      "nvd": {
        "published": "2026-07-14T17:16:51.210",
        "lastModified": "2026-07-29T20:17:03.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49165",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows App Store consumes an uninitialized resource and returns residual information to a local authorized caller.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49165",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-49166",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.622Z",
      "date_published": "2026-07-14T17:04:27.287Z",
      "date_updated": "2026-08-03T22:52:55.403Z",
      "publisher": "microsoft",
      "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15134
      },
      "nvd": {
        "published": "2026-07-14T17:16:51.370",
        "lastModified": "2026-07-22T16:17:27.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49166",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 11 Version 24H2 path retains or dereferences an object after its storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49166",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-49167",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.622Z",
      "date_published": "2026-07-14T17:04:27.881Z",
      "date_updated": "2026-08-03T22:52:56.009Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00252,
        "percentile": 0.1668
      },
      "nvd": {
        "published": "2026-07-14T17:16:51.493",
        "lastModified": "2026-07-22T16:17:27.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49167",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An object can be accessed outside its valid allocation bounds or lifetime.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49167",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-49168",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.622Z",
      "date_published": "2026-07-14T17:04:28.524Z",
      "date_updated": "2026-08-03T22:52:56.550Z",
      "publisher": "microsoft",
      "title": "Storage Spaces Direct Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22792
      },
      "nvd": {
        "published": "2026-07-14T17:16:51.633",
        "lastModified": "2026-07-22T16:17:27.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49168",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 path performs integer conversion or arithmetic that can wrap, truncate, or change sign before a memory operation.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49168",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 141,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-49169",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.623Z",
      "date_published": "2026-07-14T17:04:29.073Z",
      "date_updated": "2026-08-03T22:52:57.025Z",
      "publisher": "microsoft",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00509,
        "percentile": 0.40632
      },
      "nvd": {
        "published": "2026-07-14T17:16:51.813",
        "lastModified": "2026-07-16T16:13:38.843",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49169",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows DNS Server accesses an object after its lifetime has ended while processing network input.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49169",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 90,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49170",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.623Z",
      "date_published": "2026-07-14T17:04:29.615Z",
      "date_updated": "2026-08-03T22:52:57.564Z",
      "publisher": "microsoft",
      "title": "Windows StateRepository API Server file Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1220",
          "name": "Insufficient Granularity of Access Control",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02797,
        "percentile": 0.85038
      },
      "nvd": {
        "published": "2026-07-14T17:16:51.930",
        "lastModified": "2026-07-22T16:17:27.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49170",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Windows 10 Version 1809 permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-1220"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49170",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-49171",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.623Z",
      "date_published": "2026-07-14T17:04:30.096Z",
      "date_updated": "2026-08-03T22:52:58.110Z",
      "publisher": "microsoft",
      "title": "Windows Speech Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12102
      },
      "nvd": {
        "published": "2026-07-14T17:16:52.073",
        "lastModified": "2026-07-22T16:17:27.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49171",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Speech accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49171",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-49172",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.623Z",
      "date_published": "2026-07-14T17:04:31.579Z",
      "date_updated": "2026-08-03T22:52:59.922Z",
      "publisher": "microsoft",
      "title": "Windows FTP Service Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00673,
        "percentile": 0.48606
      },
      "nvd": {
        "published": "2026-07-14T17:16:52.233",
        "lastModified": "2026-07-23T05:16:32.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49172",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler writes attacker-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49172",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-49173",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.623Z",
      "date_published": "2026-07-14T17:04:32.213Z",
      "date_updated": "2026-08-03T22:53:00.473Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15178
      },
      "nvd": {
        "published": "2026-07-14T17:16:52.390",
        "lastModified": "2026-07-22T16:17:28.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49173",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 11 version 26H1 can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49173",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49174",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.623Z",
      "date_published": "2026-07-14T17:04:32.676Z",
      "date_updated": "2026-08-03T22:53:01.021Z",
      "publisher": "microsoft",
      "title": "DNS Client Tampering Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09814
      },
      "nvd": {
        "published": "2026-07-14T17:16:52.513",
        "lastModified": "2026-07-22T16:17:28.467",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49174",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows DNS exposes a critical local tampering operation through an authentication failure, but the record does not name the operation, identity, or missing check.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49174",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 129,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-49175",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.623Z",
      "date_published": "2026-07-14T17:04:31.111Z",
      "date_updated": "2026-08-03T22:52:59.282Z",
      "publisher": "microsoft",
      "title": "Windows DNS Client Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15134
      },
      "nvd": {
        "published": "2026-07-14T17:16:52.650",
        "lastModified": "2026-07-22T16:17:28.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49175",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 21H2 writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49175",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-49176",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.623Z",
      "date_published": "2026-07-14T17:04:30.644Z",
      "date_updated": "2026-08-03T22:52:58.714Z",
      "publisher": "microsoft",
      "title": "Windows WalletService Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00471,
        "percentile": 0.38298
      },
      "nvd": {
        "published": "2026-07-14T17:16:52.780",
        "lastModified": "2026-07-22T16:17:28.753",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49176",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "WalletService follows an attacker-influenced link or alias to a privileged object during a local operation.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49176",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-49177",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.623Z",
      "date_published": "2026-07-14T17:04:33.224Z",
      "date_updated": "2026-08-03T22:53:01.566Z",
      "publisher": "microsoft",
      "title": "Windows TCP/IP Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22143
      },
      "nvd": {
        "published": "2026-07-14T18:17:23.407",
        "lastModified": "2026-07-22T16:17:28.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49177",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows TCP/IP reads beyond a memory object's valid bounds and exposes the adjacent data to a local authorized user.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49177",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49178",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.623Z",
      "date_published": "2026-07-14T17:05:47.889Z",
      "date_updated": "2026-08-03T22:54:11.417Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00618,
        "percentile": 0.46181
      },
      "nvd": {
        "published": "2026-07-14T17:16:52.933",
        "lastModified": "2026-07-22T16:17:29.137",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49178",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Active Directory Domain Services writes beyond a heap allocation while processing attacker-controlled network input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49178",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49180",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.623Z",
      "date_published": "2026-07-14T17:05:48.392Z",
      "date_updated": "2026-08-03T22:54:12.044Z",
      "publisher": "microsoft",
      "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00325,
        "percentile": 0.2497
      },
      "nvd": {
        "published": "2026-07-14T17:16:53.100",
        "lastModified": "2026-07-22T16:17:29.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49180",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 file operation follows an attacker-influenced link outside the intended file object.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49180",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 163,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49181",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.623Z",
      "date_published": "2026-07-14T17:05:49.015Z",
      "date_updated": "2026-08-03T22:54:12.513Z",
      "publisher": "microsoft",
      "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 2.3000000000000007,
      "epss": {
        "score": 0.00794,
        "percentile": 0.5284
      },
      "nvd": {
        "published": "2026-07-14T17:16:53.277",
        "lastModified": "2026-07-29T20:17:03.800",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49181",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows DHCP Client arithmetic underflows and wraps a value used by a network-triggered privileged path.",
        "basis": [
          "CNA",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49181",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-49183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.624Z",
      "date_published": "2026-07-14T17:05:50.207Z",
      "date_updated": "2026-08-03T22:54:13.686Z",
      "publisher": "microsoft",
      "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04943
      },
      "nvd": {
        "published": "2026-07-14T17:16:53.437",
        "lastModified": "2026-07-22T16:17:29.607",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49183",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A protected object can change between the check and use steps in Windows 10 Version 1809, invalidating the state assumed by the later operation.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49183",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-49184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-27T23:44:09.624Z",
      "date_published": "2026-07-14T17:05:49.648Z",
      "date_updated": "2026-08-03T22:54:13.068Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18256
      },
      "nvd": {
        "published": "2026-07-14T17:16:53.580",
        "lastModified": "2026-07-22T16:17:29.760",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49184",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 copies, writes, or indexes attacker-influenced data without enforcing the destination buffer or object bounds required by the operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49184",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49208",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T03:42:34.340Z",
      "date_published": "2026-07-17T16:10:49.101Z",
      "date_updated": "2026-07-21T01:41:46.730Z",
      "publisher": "GitHub_M",
      "title": "Symfony UX: Format-less date LiveProps parsed with the permissive DateTime constructor",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "ux"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15222
      },
      "nvd": {
        "published": "2026-07-17T17:17:15.380",
        "lastModified": "2026-07-21T03:16:41.853",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49208",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A format-less DateTime LiveProp passes client text to the permissive DateTime interpreter, allowing relative expressions to change business dates.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/ux/security/advisories/GHSA-89g7-22c8-3j23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/commit/d24d78fda6df2d5964312255943ebf3a217b79a2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v2.36.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v3.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49209",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T03:42:34.340Z",
      "date_published": "2026-07-17T16:02:06.498Z",
      "date_updated": "2026-07-17T17:26:18.929Z",
      "publisher": "GitHub_M",
      "title": "Symfony UX: Denial of service in symfony/ux-live-component via unbounded batch action requests",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "ux"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23614
      },
      "nvd": {
        "published": "2026-07-17T17:17:15.517",
        "lastModified": "2026-07-20T16:56:45.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49209",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The live-component batch endpoint performs a full subrequest for every client-supplied action without limiting the array length.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/ux/security/advisories/GHSA-mm82-c99c-h2cf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/commit/95e878d5257f13d6d652ca95e3ef6bb0934d674f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v2.36.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v3.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 518,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49210",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T03:42:34.340Z",
      "date_published": "2026-07-17T16:09:17.850Z",
      "date_updated": "2026-07-17T16:52:59.836Z",
      "publisher": "GitHub_M",
      "title": "Symfony UX: XSS in symfony/ux-live-component via attacker-controlled child component tag",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "ux"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09301
      },
      "nvd": {
        "published": "2026-07-17T17:17:15.650",
        "lastModified": "2026-07-20T16:56:24.797",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49210",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ChildComponentPartialRenderer inserts the client-controlled child tag name directly into generated HTML without validation or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/ux/security/advisories/GHSA-38x5-rcv4-xf7x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/commit/fbc5e9a1bda7e4556be21bb1d970f382760ed9a9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v2.36.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v3.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49211",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T03:42:34.340Z",
      "date_published": "2026-07-17T16:14:29.271Z",
      "date_updated": "2026-07-17T16:41:33.402Z",
      "publisher": "GitHub_M",
      "title": "Symfony UX: Information exposure via unescaped LIKE wildcards in EntitySearchUtil",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "ux"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00305,
        "percentile": 0.2286
      },
      "nvd": {
        "published": "2026-07-17T17:17:15.790",
        "lastModified": "2026-07-20T16:56:08.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49211",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "EntitySearchUtil places unescaped SQL LIKE wildcard syntax into the autocomplete predicate, turning a narrow search into a broad matcher or oracle.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/ux/security/advisories/GHSA-946h-jp5c-8fvh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/commit/725ab3d40689c91ff19ad2d01940a30007769214",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v2.36.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v3.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 540,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49212",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T03:42:34.340Z",
      "date_published": "2026-07-17T16:03:27.784Z",
      "date_updated": "2026-07-17T17:48:49.503Z",
      "publisher": "GitHub_M",
      "title": "Symfony UX: LiveComponentHydrator HMAC checksum lacks component and slot binding",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "ux"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05768
      },
      "nvd": {
        "published": "2026-07-17T17:17:15.930",
        "lastModified": "2026-07-20T16:55:45.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49212",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Symfony UX signs only sorted property names and values, omitting the component, slot, and request context needed to prevent a valid MAC from being replayed in another location.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/ux/security/advisories/GHSA-34w5-c283-j9fg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/commit/a224b5af3e2e33ee14ac71356ae0e0877900a81c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v2.36.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v3.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49213",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T03:42:34.341Z",
      "date_published": "2026-07-10T21:33:43.090Z",
      "date_updated": "2026-07-13T16:16:39.911Z",
      "publisher": "GitHub_M",
      "title": "TypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP request execution",
      "affected": {
        "vendors": [
          "baptisteArno"
        ],
        "products": [
          {
            "vendor": "baptisteArno",
            "product": "typebot.io"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24355
      },
      "nvd": {
        "published": "2026-07-10T22:16:42.270",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49213",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHttpReqUrl.ts can be bypassed with the IPv6 unspecified address :: because validateIPAddress blocks local, metadata, and private ranges but does not block :: or its expanded form.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/baptisteArno/typebot.io/security/advisories/GHSA-qx46-p88f-xxm3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/baptisteArno/typebot.io/pull/2511",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/baptisteArno/typebot.io/commit/f56c3c3f771df13a8c11e88f500dfdd78981bed1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/baptisteArno/typebot.io/releases/tag/v3.17.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 625,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49215",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T03:42:34.341Z",
      "date_published": "2026-07-17T16:16:42.126Z",
      "date_updated": "2026-07-17T18:05:15.930Z",
      "publisher": "GitHub_M",
      "title": "Symfony UX: CSRF Protection Bypass in symfony/ux-live-component — Accept Header is CORS-Safelisted",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "ux"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 3.3000000000000003,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01964
      },
      "nvd": {
        "published": "2026-07-17T17:17:16.060",
        "lastModified": "2026-07-20T16:54:54.023",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49215",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Symfony treats a CORS-safelisted Accept value as proof of a Live Component request, so a cross-origin fetch can invoke a LiveAction when session cookies are sent.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/ux/security/advisories/GHSA-4m4j-hmqq-3gxm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/commit/aed7493db2b4b7bf1f9c79b33cda544f06904b27",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v2.36.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v3.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49216",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T03:42:34.341Z",
      "date_published": "2026-07-17T16:15:34.990Z",
      "date_updated": "2026-07-21T01:44:13.539Z",
      "publisher": "GitHub_M",
      "title": "Symfony UX: XSS in symfony/ux-autocomplete via unescaped AJAX response data",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "ux"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07335
      },
      "nvd": {
        "published": "2026-07-17T17:17:16.190",
        "lastModified": "2026-07-21T03:16:41.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49216",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/ux/security/advisories/GHSA-mwqm-4fw3-cjvr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/commit/842ae54bc74de389299f975f01aafae272cb0019",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v2.36.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v3.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49229",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T03:42:34.342Z",
      "date_published": "2026-07-07T20:59:34.173Z",
      "date_updated": "2026-07-09T13:56:02.796Z",
      "publisher": "GitHub_M",
      "title": "Actual: Disabled OpenID users keep access through existing session tokens",
      "affected": {
        "vendors": [
          "actualbudget"
        ],
        "products": [
          {
            "vendor": "actualbudget",
            "product": "actual"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16693
      },
      "nvd": {
        "published": "2026-07-07T22:16:52.780",
        "lastModified": "2026-07-09T15:16:35.530",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49229",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Session validation accepts an unexpired token without checking whether its associated OpenID user has since been disabled.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/actualbudget/actual/security/advisories/GHSA-cq9c-6w48-qmfg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/commit/c8cb8a223a4faf1c2e1dcb0795a79a93f7b19e80",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/releases/tag/v26.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 496,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49256",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T14:33:01.179Z",
      "date_published": "2026-07-09T21:56:40.444Z",
      "date_updated": "2026-07-10T13:39:27.829Z",
      "publisher": "GitHub_M",
      "title": "Discourse: Hidden tag names leaked via category serializers",
      "affected": {
        "vendors": [
          "discourse"
        ],
        "products": [
          {
            "vendor": "discourse",
            "product": "discourse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00373,
        "percentile": 0.29999
      },
      "nvd": {
        "published": "2026-07-09T22:17:05.260",
        "lastModified": "2026-07-14T20:40:56.590",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49256",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Sensitive data is returned, stored, or left readable through an output path that lacks the required disclosure boundary.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/discourse/discourse/security/advisories/GHSA-mwp7-572g-6qpx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-49258",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T14:33:01.179Z",
      "date_published": "2026-07-28T18:52:58.713Z",
      "date_updated": "2026-07-28T19:21:43.453Z",
      "publisher": "GitHub_M",
      "title": "Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)",
      "affected": {
        "vendors": [
          "juev"
        ],
        "products": [
          {
            "vendor": "juev",
            "product": "nebula-mesh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20507
      },
      "nvd": {
        "published": "2026-07-28T19:17:36.000",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49258",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "nebula-mesh resolves a caller-controlled object identifier without binding the selected object to the caller's authorized scope.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-c6v2-3ffm-vcmc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/forgekeep/nebula-mesh/pull/161",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 732,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49274",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T20:07:58.860Z",
      "date_published": "2026-07-09T18:38:32.436Z",
      "date_updated": "2026-07-14T01:10:30.223Z",
      "publisher": "GitHub_M",
      "title": "Kirby: `pages.access` permission is not checked in the pages picker for parent pages",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19682
      },
      "nvd": {
        "published": "2026-07-09T19:17:05.490",
        "lastModified": "2026-07-14T02:16:55.240",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49274",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The page picker fails to enforce pages.access on a caller-selected parent and reveals fields from inaccessible pages.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-23q2-54qv-rq5x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/1ae575da24e1b1cb8803a031d37eff14606d7c55",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/3bad37117adf2013548a784f820ddb2d8317333c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/3f4398cdcf9f50f84fdac52ad78a7a85fb31589f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/bffffce6c081f69c46163cc89b1fd18ccf2a18d1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/4.9.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49276",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T20:07:58.861Z",
      "date_published": "2026-07-09T18:48:50.543Z",
      "date_updated": "2026-07-10T14:11:49.896Z",
      "publisher": "GitHub_M",
      "title": "Kirby: Self cross-site scripting (self-XSS) in the writer field",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-83",
          "name": "Improper Neutralization of Script in Attributes in a Web Page",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21127
      },
      "nvd": {
        "published": "2026-07-09T19:17:05.670",
        "lastModified": "2026-07-10T15:49:19.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49276",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A scripting-capable link target is accepted without separating attacker data from executable browser grammar.",
        "basis": [
          "CNA",
          "CWE-83"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-rhj6-r49h-5932",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/4.9.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49279",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T20:07:58.861Z",
      "date_published": "2026-07-15T20:57:21.381Z",
      "date_updated": "2026-07-18T02:22:09.068Z",
      "publisher": "GitHub_M",
      "title": "WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)",
      "affected": {
        "vendors": [
          "WWBN"
        ],
        "products": [
          {
            "vendor": "WWBN",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25161
      },
      "nvd": {
        "published": "2026-07-15T22:16:52.163",
        "lastModified": "2026-07-18T03:16:36.547",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49279",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MessageSQLite sanitizes msg while a higher-priority json field reaches the WebSocket renderer with executable markup intact.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-2fhx-q92v-5fhv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/WWBN/AVideo/commit/3e0b3ce2bfa766183ff0ae227439394db57b1a23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 949,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49284",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T20:07:58.861Z",
      "date_published": "2026-07-17T19:17:23.897Z",
      "date_updated": "2026-07-20T19:22:12.247Z",
      "publisher": "GitHub_M",
      "title": "SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`",
      "affected": {
        "vendors": [
          "simplesamlphp"
        ],
        "products": [
          {
            "vendor": "simplesamlphp",
            "product": "simplesamlphp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04523
      },
      "nvd": {
        "published": "2026-07-17T20:17:21.830",
        "lastModified": "2026-07-30T13:39:25.117",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49284",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SAML ACS binds a response from one trusted IdP to login state created for another IdP when the response and assertion omit the expected InResponseTo binding.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-q8r6-xj3f-wrrm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/simplesamlphp/simplesamlphp/releases/tag/v2.4.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/simplesamlphp/simplesamlphp/releases/tag/v2.5.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 578,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49296",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T20:36:21.757Z",
      "date_published": "2026-07-07T09:18:12.369Z",
      "date_updated": "2026-07-07T13:28:17.894Z",
      "publisher": "apache",
      "title": "Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id}",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31105
      },
      "nvd": {
        "published": "2026-07-07T10:16:41.603",
        "lastModified": "2026-07-08T20:04:17.073",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49296",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The DAG source endpoint checks access to one DAG but returns the entire shared source file containing other unauthorized DAGs.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/airflow/pull/67662",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/qqv41t3oydkn9o14r2rfz1wkdrsp5jzn",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/07/5",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49297",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-28T20:42:43.353Z",
      "date_published": "2026-07-06T09:54:07.148Z",
      "date_updated": "2026-07-06T19:26:04.051Z",
      "publisher": "apache",
      "title": "Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow Google provider"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00697,
        "percentile": 0.49505
      },
      "nvd": {
        "published": "2026-07-06T11:16:30.207",
        "lastModified": "2026-07-08T14:53:39.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49297",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Airflow operators join untrusted GCS object names directly to local or SFTP destination paths without normalization or containment checks.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/airflow/pull/67667",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/cb5nvoxsj1q7rv878cyqgtg150w0zglq?users@airflow.apache.org",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/04/8",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 937,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49326",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T07:46:07.488Z",
      "date_published": "2026-07-24T14:56:22.664Z",
      "date_updated": "2026-07-24T17:57:56.951Z",
      "publisher": "apache",
      "title": "Apache HBase: Missing scanner instance owner check in thrift delegation service",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache HBase"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14339
      },
      "nvd": {
        "published": "2026-07-24T15:17:31.163",
        "lastModified": "2026-07-24T20:47:41.790",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49326",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HBase checks scanner ownership at open but omits it at fetch and close, allowing one user to read or close another user's server-side scanner.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/f4l4sjgwb9tb04cqnkpgl6gy3slgvcsj",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/23",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 740,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-49332",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T13:28:56.553Z",
      "date_published": "2026-07-28T12:18:26.112Z",
      "date_updated": "2026-07-28T13:03:08.605Z",
      "publisher": "redhat",
      "title": "Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreams",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Primary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09298
      },
      "nvd": {
        "published": "2026-07-28T13:18:46.067",
        "lastModified": "2026-07-28T16:22:01.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49332",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "openshift/oauth-proxy sets dash-form identity headers but leaves underscore aliases supplied by the client, allowing a downstream normalization step to trust the attacker value.",
        "basis": [
          "CNA",
          "CWE-436"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-49332",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2483253",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 451,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-49352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T14:35:45.903Z",
      "date_published": "2026-07-15T20:43:41.168Z",
      "date_updated": "2026-07-16T18:55:46.479Z",
      "publisher": "GitHub_M",
      "title": "9Router: Hardcoded Default fallback JWT Secret  Allows Authentication Bypass",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00437,
        "percentile": 0.35929
      },
      "nvd": {
        "published": "2026-07-15T21:16:53.743",
        "lastModified": "2026-07-16T19:16:49.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49352",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The service falls back to a hard-coded JWT secret that any party knowing the constant can use to forge tokens.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-jphh-m39h-6gwx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/commit/fe3ce25ae3cda48c0702c2d452e17f6ec214009d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/releases/tag/v0.4.44",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T14:35:45.903Z",
      "date_published": "2026-07-15T20:49:15.693Z",
      "date_updated": "2026-07-16T15:12:31.230Z",
      "publisher": "GitHub_M",
      "title": "9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14
      },
      "nvd": {
        "published": "2026-07-15T21:16:53.870",
        "lastModified": "2026-07-16T16:19:10.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49353",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "isLocalRequest trusts spoofable Host and Origin headers to guard local-only endpoints, exposing MCP child-process input paths behind proxies or tunnels.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-6g2f-w7g3-77vf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/commit/5e1c1261368e06dced1cbc650684561b2c8844db",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/commit/bb86808582067e4fc6f004508a919efb9970d1d5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/releases/tag/v0.4.46",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49365",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T16:50:08.917Z",
      "date_published": "2026-07-06T08:11:49.232Z",
      "date_updated": "2026-07-07T12:34:51.854Z",
      "publisher": "apache",
      "title": "Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00501,
        "percentile": 0.40165
      },
      "nvd": {
        "published": "2026-07-06T09:16:38.627",
        "lastModified": "2026-07-09T03:04:17.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49365",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Camel Netty returns internal route exception details because muteException is disabled by default.",
        "basis": [
          "CNA",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-49365.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/25",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2078,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-49394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-29T19:08:01.256Z",
      "date_published": "2026-07-10T21:24:47.624Z",
      "date_updated": "2026-07-13T16:17:40.190Z",
      "publisher": "GitHub_M",
      "title": "Frappe: Auth. bypass via update_page",
      "affected": {
        "vendors": [
          "frappe"
        ],
        "products": [
          {
            "vendor": "frappe",
            "product": "frappe"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.22995
      },
      "nvd": {
        "published": "2026-07-10T22:16:42.410",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49394",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frappe/frappe/security/advisories/GHSA-r24j-xrj8-273q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/39508",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/39526",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/2471d94c397dc23301b30ed3bb30353f53b33f2c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/6eba29d7ae80cdb4d0b2a245a477b1d2312736ca",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/releases/tag/v16.19.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-30T02:43:33.106Z",
      "date_published": "2026-07-15T19:11:55.303Z",
      "date_updated": "2026-07-16T15:12:56.970Z",
      "publisher": "GitHub_M",
      "title": "Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket access",
      "affected": {
        "vendors": [
          "cilium"
        ],
        "products": [
          {
            "vendor": "cilium",
            "product": "cilium"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0.3999999999999986,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02628
      },
      "nvd": {
        "published": "2026-07-15T20:17:10.453",
        "lastModified": "2026-07-17T17:50:17.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49445",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cilium installs Envoy's administrative Unix socket with permissions that make the privileged control interface reachable to untrusted local processes.",
        "basis": [
          "CNA",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cilium/cilium/security/advisories/GHSA-3fcv-jvfp-m4q9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/pull/44512",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/commit/7bfbdd5c1be83d6c9ba3e089b4c804b6603505b6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/releases/tag/v1.17.14",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/releases/tag/v1.18.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/releases/tag/v1.19.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-49447",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-30T02:43:33.106Z",
      "date_published": "2026-07-28T20:35:36.636Z",
      "date_updated": "2026-07-29T13:36:42.108Z",
      "publisher": "GitHub_M",
      "title": "Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens",
      "affected": {
        "vendors": [
          "azukaar"
        ],
        "products": [
          {
            "vendor": "azukaar",
            "product": "Cosmos-Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13147
      },
      "nvd": {
        "published": "2026-07-28T21:17:28.427",
        "lastModified": "2026-07-30T20:02:12.943",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49447",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public-devices route accepts any non-empty Authorization header because it strips Bearer but never validates or uses the resulting token.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/azukaar/Cosmos-Server/security/advisories/GHSA-5fqm-cc34-fcf5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/azukaar/Cosmos-Server/commit/59c561d686c8f9843b3e092b50f6346c481d8bbf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/azukaar/Cosmos-Server/releases/tag/v0.22.19",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 476,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-30T02:43:33.107Z",
      "date_published": "2026-07-14T19:58:50.397Z",
      "date_updated": "2026-07-15T13:03:02.384Z",
      "publisher": "GitHub_M",
      "title": "DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-501",
          "name": "Trust Boundary Violation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.311
      },
      "nvd": {
        "published": "2026-07-14T21:17:01.620",
        "lastModified": "2026-07-21T19:47:48.413",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49458",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DOMPurify uses parent-realm instanceof checks on foreign-realm nodes, skipping sanitization branches and leaving executable markup intact.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-501",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-hpcv-96wg-7vj8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cure53/DOMPurify/commit/bb7739e5bccec7e1ab3dae3f3e42d02db3acaaae",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cure53/DOMPurify/releases/tag/3.4.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 484,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-30T02:43:33.107Z",
      "date_published": "2026-07-14T20:01:44.857Z",
      "date_updated": "2026-07-15T14:17:27.943Z",
      "publisher": "GitHub_M",
      "title": "DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22699
      },
      "nvd": {
        "published": "2026-07-14T21:17:01.743",
        "lastModified": "2026-07-21T19:51:07.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49459",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A clobbered form descendant makes DOMPurify skip attribute sanitization on the parentless root and preserve an event-handler attribute.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-693",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-r47g-fvhr-h676",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cure53/DOMPurify/commit/bb7739e5bccec7e1ab3dae3f3e42d02db3acaaae",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cure53/DOMPurify/releases/tag/3.4.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49471",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-30T04:17:43.094Z",
      "date_published": "2026-07-07T20:50:50.545Z",
      "date_updated": "2026-07-09T13:55:44.505Z",
      "publisher": "GitHub_M",
      "title": "Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE",
      "affected": {
        "vendors": [
          "oraios"
        ],
        "products": [
          {
            "vendor": "oraios",
            "product": "serena"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21363
      },
      "nvd": {
        "published": "2026-07-07T21:17:25.833",
        "lastModified": "2026-07-20T14:54:40.713",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49471",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Serena exposes its local dashboard API without authentication, allowing a rebinding-origin browser request to write persistent agent memory.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/oraios/serena/security/advisories/GHSA-37h2-6p4f-mp3q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/oraios/serena/commit/016ccbe1c095a3eed7967737ac1d4df2754f5d96",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/oraios/serena/releases/tag/v1.5.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 712,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-30T04:17:43.095Z",
      "date_published": "2026-07-14T20:53:12.497Z",
      "date_updated": "2026-07-15T14:27:06.146Z",
      "publisher": "GitHub_M",
      "title": "Soup Sieve: Memory Exhaustion via Large Comma-Separated Selector Lists in soupsieve",
      "affected": {
        "vendors": [
          "facelessuser"
        ],
        "products": [
          {
            "vendor": "facelessuser",
            "product": "soupsieve"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00522,
        "percentile": 0.41392
      },
      "nvd": {
        "published": "2026-07-14T21:17:01.877",
        "lastModified": "2026-07-28T15:48:11.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49476",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The selector compiler places no cumulative bound on comma-separated selector branches and allocates memory in proportion to an attacker-supplied list.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/facelessuser/soupsieve/releases/tag/2.8.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49477",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-30T04:17:43.095Z",
      "date_published": "2026-07-14T20:51:29.369Z",
      "date_updated": "2026-07-21T14:49:40.914Z",
      "publisher": "GitHub_M",
      "title": "Soup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selector Parser",
      "affected": {
        "vendors": [
          "facelessuser"
        ],
        "products": [
          {
            "vendor": "facelessuser",
            "product": "soupsieve"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00522,
        "percentile": 0.41393
      },
      "nvd": {
        "published": "2026-07-14T21:17:02.007",
        "lastModified": "2026-07-28T15:48:00.760",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49477",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The soupsieve parser applies a backtracking regular expression to unbounded attacker input, allowing disproportionate CPU work.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/facelessuser/soupsieve/commit/eb4397618709186c109400448c6043b728217dc3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/facelessuser/soupsieve/releases/tag/2.8.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 521,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49485",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-30T04:17:43.095Z",
      "date_published": "2026-07-17T20:59:47.800Z",
      "date_updated": "2026-07-20T13:45:26.634Z",
      "publisher": "GitHub_M",
      "title": "HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint",
      "affected": {
        "vendors": [
          "hapifhir"
        ],
        "products": [
          {
            "vendor": "hapifhir",
            "product": "org.hl7.fhir.core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29867
      },
      "nvd": {
        "published": "2026-07-17T22:17:16.893",
        "lastModified": "2026-07-23T16:11:03.457",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49485",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FHIRPath regular-expression functions accept patterns that trigger catastrophic backtracking without an effective evaluation budget.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-7cmj-v6x8-frvv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/pull/2463",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/commit/109c88837c032ef399b2eb87ddde86692065cf41",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/commit/e08982d2b6f6dcd6c670a762d9cf999179fbe4ed",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/releases/tag/6.9.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/releases/tag/6.9.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 741,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49487",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-31T01:41:02.944Z",
      "date_published": "2026-07-07T09:19:36.710Z",
      "date_updated": "2026-07-07T13:41:45.272Z",
      "publisher": "apache",
      "title": "Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33687
      },
      "nvd": {
        "published": "2026-07-07T10:16:41.723",
        "lastModified": "2026-07-09T13:17:08.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49487",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Task-instance APIs return deferred trigger arguments without masking secrets embedded in those arguments.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/airflow/pull/67868",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/qlw6pozlzlfhkvmbgqsbjlq6vj4v0pc4",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/07/6",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 502,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-31T06:53:32.094Z",
      "date_published": "2026-07-14T12:21:05.929Z",
      "date_updated": "2026-07-15T15:13:20.235Z",
      "publisher": "apache",
      "title": "Apache OpenMeetings: Arbitrary File Read",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache OpenMeetings"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00531,
        "percentile": 0.41905
      },
      "nvd": {
        "published": "2026-07-14T13:18:57.313",
        "lastModified": "2026-07-15T16:16:47.663",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49488",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache OpenMeetings allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/74zf32shox9oy62b7t55mvcj874bxqnj",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/14/10",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-31T17:04:24.517Z",
      "date_published": "2026-07-22T15:39:48.244Z",
      "date_updated": "2026-07-24T03:56:08.365Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Manager, versions prior to 20.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1270",
          "name": "Generation of Incorrect Security Tokens",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20834
      },
      "nvd": {
        "published": "2026-07-22T16:17:29.943",
        "lastModified": "2026-07-29T17:37:24.533",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49499",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerProtect IAM generates a security token with incorrect authority, allowing a low-privilege remote caller to obtain elevated privileges.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1270"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000488847/dsa-2026-287-security-update-dell-powerprotect-data-manager-for-multiple-security-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-05-31T17:04:24.517Z",
      "date_published": "2026-07-15T10:01:11.925Z",
      "date_updated": "2026-07-16T03:55:21.048Z",
      "publisher": "dell",
      "title": "Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerab...",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerScale OneFS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01252
      },
      "nvd": {
        "published": "2026-07-15T10:16:47.357",
        "lastModified": "2026-07-16T05:16:21.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49501",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in PowerScale OneFS, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000483600/dsa-2026-261-security-update-for-dell-powerscale-onefs-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-49743",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T11:03:13.031Z",
      "date_published": "2026-07-24T08:42:51.369Z",
      "date_updated": "2026-07-24T17:27:53.720Z",
      "publisher": "imaginationtech",
      "title": "GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closed",
      "affected": {
        "vendors": [
          "Imagination Technologies"
        ],
        "products": [
          {
            "vendor": "Imagination Technologies",
            "product": "Graphics DDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0011,
        "percentile": 0.01485
      },
      "nvd": {
        "published": "2026-07-24T09:16:24.667",
        "lastModified": "2026-07-28T16:17:58.820",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49743",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The GPU driver fails to increment a synchronization primitive reference before exporting its fence, so closing the fence frees an object still in use.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
          "host": "www.imaginationtech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 513,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-49744",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T11:03:13.032Z",
      "date_published": "2026-07-24T08:51:16.698Z",
      "date_updated": "2026-07-24T17:25:55.652Z",
      "publisher": "imaginationtech",
      "title": "GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()",
      "affected": {
        "vendors": [
          "Imagination Technologies"
        ],
        "products": [
          {
            "vendor": "Imagination Technologies",
            "product": "Graphics DDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-823",
          "name": "Use of Out-of-range Pointer Offset",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0011,
        "percentile": 0.01485
      },
      "nvd": {
        "published": "2026-07-24T09:16:24.787",
        "lastModified": "2026-07-28T16:17:58.820",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49744",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Guest GPU commands can address and write data outside the guest's virtualized GPU-memory range.",
        "basis": [
          "CNA",
          "CWE-823"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
          "host": "www.imaginationtech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-49745",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T11:03:13.032Z",
      "date_published": "2026-07-24T08:55:40.309Z",
      "date_updated": "2026-07-24T17:22:56.733Z",
      "publisher": "imaginationtech",
      "title": "GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0",
      "affected": {
        "vendors": [
          "Imagination Technologies"
        ],
        "products": [
          {
            "vendor": "Imagination Technologies",
            "product": "Graphics DDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-823",
          "name": "Use of Out-of-range Pointer Offset",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0011,
        "percentile": 0.01486
      },
      "nvd": {
        "published": "2026-07-24T09:16:24.897",
        "lastModified": "2026-07-28T16:17:58.820",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49745",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.",
        "basis": [
          "CNA",
          "CWE-823"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
          "host": "www.imaginationtech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-49779",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T15:29:19.865Z",
      "date_published": "2026-07-02T11:15:03.479Z",
      "date_updated": "2026-07-28T14:20:33.630Z",
      "publisher": "Patchstack",
      "title": "WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerability",
      "affected": {
        "vendors": [
          "Addify"
        ],
        "products": [
          {
            "vendor": "Addify",
            "product": "Tax Exempt for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-35",
          "name": "Path Traversal: '.../...//'",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26932
      },
      "nvd": {
        "published": "2026-07-02T12:17:29.923",
        "lastModified": "2026-07-28T15:17:15.530",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49779",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal.",
        "basis": [
          "CNA",
          "CWE-35"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-tax-exempt-plugin/vulnerability/wordpress-tax-exempt-for-woocommerce-plugin-1-9-3-path-traversal-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 172,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49783",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.207Z",
      "date_published": "2026-07-14T17:05:50.741Z",
      "date_updated": "2026-08-03T22:54:14.316Z",
      "publisher": "microsoft",
      "title": "Secure Boot Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-358",
          "name": "Improperly Implemented Security Check for Standard",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17306
      },
      "nvd": {
        "published": "2026-07-14T17:16:53.747",
        "lastModified": "2026-07-22T16:17:30.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49783",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Secure Boot path applies the required standard verification check incorrectly, allowing a locally authorized caller to cross the boot-trust boundary.",
        "basis": [
          "CNA",
          "CWE-358"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49783",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 141,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-49784",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.207Z",
      "date_published": "2026-07-14T17:04:35.724Z",
      "date_updated": "2026-08-03T22:53:02.113Z",
      "publisher": "microsoft",
      "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04941
      },
      "nvd": {
        "published": "2026-07-14T17:16:53.900",
        "lastModified": "2026-07-23T05:16:32.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49784",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent Windows App Store operations use shared state without sufficient synchronization, opening a local privilege transition race.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49784",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-49787",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.207Z",
      "date_published": "2026-07-14T17:05:51.320Z",
      "date_updated": "2026-08-03T22:54:14.791Z",
      "publisher": "microsoft",
      "title": "HTTP.sys Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00816,
        "percentile": 0.53583
      },
      "nvd": {
        "published": "2026-07-14T17:16:54.053",
        "lastModified": "2026-07-22T16:17:30.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49787",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 accepts attacker-driven work or allocation without an effective size, rate, release, or termination bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49787",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-49788",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.207Z",
      "date_published": "2026-07-14T17:05:52.114Z",
      "date_updated": "2026-08-03T22:54:15.270Z",
      "publisher": "microsoft",
      "title": "HTTP/2 Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0078,
        "percentile": 0.52384
      },
      "nvd": {
        "published": "2026-07-14T17:16:54.207",
        "lastModified": "2026-07-22T16:17:30.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49788",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HTTP/2 processing allocates a finite server resource without an effective limit or throttle for an unauthenticated peer.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49788",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-49789",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.207Z",
      "date_published": "2026-07-14T17:05:52.611Z",
      "date_updated": "2026-08-03T22:54:15.824Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00277,
        "percentile": 0.1992
      },
      "nvd": {
        "published": "2026-07-14T17:16:54.360",
        "lastModified": "2026-07-22T16:17:31.807",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49789",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can overflow a stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49789",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49790",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.207Z",
      "date_published": "2026-07-14T17:05:53.193Z",
      "date_updated": "2026-08-03T22:54:16.447Z",
      "publisher": "microsoft",
      "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00258,
        "percentile": 0.1743
      },
      "nvd": {
        "published": "2026-07-14T17:16:54.543",
        "lastModified": "2026-07-20T11:37:37.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49790",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer underflow in UDFS produces heap-buffer bounds that permit an out-of-bounds write.",
        "basis": [
          "CNA record",
          "CWE-191",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49790",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 92,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49791",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.207Z",
      "date_published": "2026-07-14T17:05:53.797Z",
      "date_updated": "2026-08-03T22:54:17.071Z",
      "publisher": "microsoft",
      "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20036
      },
      "nvd": {
        "published": "2026-07-14T17:16:54.720",
        "lastModified": "2026-07-22T16:17:32.107",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49791",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 follows an attacker-influenced symbolic link into a filesystem object outside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49791",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49792",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.207Z",
      "date_published": "2026-07-14T17:05:54.370Z",
      "date_updated": "2026-08-03T22:54:17.704Z",
      "publisher": "microsoft",
      "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-197",
          "name": "Numeric Truncation Error",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17306
      },
      "nvd": {
        "published": "2026-07-14T17:16:54.893",
        "lastModified": "2026-07-22T16:17:32.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49792",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ReFS truncates a numeric value before using it in a memory-sensitive operation, enabling local code execution.",
        "basis": [
          "CNA",
          "CWE-197"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49792",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-49793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:05:55.171Z",
      "date_updated": "2026-08-03T22:54:18.336Z",
      "publisher": "microsoft",
      "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17307
      },
      "nvd": {
        "published": "2026-07-14T17:16:55.050",
        "lastModified": "2026-07-22T16:17:32.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49793",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 10 Version 1607, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49793",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-49794",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:05:55.671Z",
      "date_updated": "2026-08-03T22:54:18.807Z",
      "publisher": "microsoft",
      "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27247
      },
      "nvd": {
        "published": "2026-07-14T17:16:55.203",
        "lastModified": "2026-07-22T16:17:32.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49794",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the end of an allocated buffer because the available length is not enforced.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49794",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49795",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:05:56.971Z",
      "date_updated": "2026-08-03T22:54:19.923Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01897,
        "percentile": 0.77607
      },
      "nvd": {
        "published": "2026-07-14T17:16:55.377",
        "lastModified": "2026-07-22T16:17:32.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49795",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows kernel can access a freed object on a local authorized path, enabling privilege escalation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49795",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-49796",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:05:56.488Z",
      "date_updated": "2026-08-03T22:54:19.368Z",
      "publisher": "microsoft",
      "title": "Windows GDI+ Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31682
      },
      "nvd": {
        "published": "2026-07-14T17:16:55.523",
        "lastModified": "2026-07-22T16:17:32.960",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49796",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 path writes attacker-influenced data beyond the capacity of its destination buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49796",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49797",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:05:57.738Z",
      "date_updated": "2026-08-03T22:54:20.576Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28689
      },
      "nvd": {
        "published": "2026-07-14T17:16:55.693",
        "lastModified": "2026-07-22T16:17:33.283",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49797",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A memory object is accessed beyond its valid bounds or after its lifetime ends.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49797",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49798",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:05:58.466Z",
      "date_updated": "2026-08-03T22:54:21.129Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02287,
        "percentile": 0.81488
      },
      "nvd": {
        "published": "2026-07-14T17:16:55.857",
        "lastModified": "2026-07-22T16:17:33.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49798",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 path retains or dereferences an object after the object's storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49798",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 95,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:06:00.662Z",
      "date_updated": "2026-08-03T22:54:22.701Z",
      "publisher": "microsoft",
      "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00791,
        "percentile": 0.52745
      },
      "nvd": {
        "published": "2026-07-14T17:16:56.023",
        "lastModified": "2026-07-22T16:17:33.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49799",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Network input can exhaust LSASS resources, but the public record does not identify the unbounded allocation, work item, or release failure.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49799",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 157,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:05:59.791Z",
      "date_updated": "2026-08-03T22:54:22.233Z",
      "publisher": "microsoft",
      "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02112,
        "percentile": 0.79982
      },
      "nvd": {
        "published": "2026-07-14T17:16:56.193",
        "lastModified": "2026-07-22T16:17:34.020",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49800",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Windows 10 Version 1809, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49800",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 143,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-49801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:06:04.157Z",
      "date_updated": "2026-08-03T22:54:25.940Z",
      "publisher": "microsoft",
      "title": "Windows SMB Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22141
      },
      "nvd": {
        "published": "2026-07-14T17:16:56.347",
        "lastModified": "2026-07-22T16:17:34.230",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49801",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49801",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:06:04.650Z",
      "date_updated": "2026-08-03T22:54:26.569Z",
      "publisher": "microsoft",
      "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04944
      },
      "nvd": {
        "published": "2026-07-14T17:16:56.520",
        "lastModified": "2026-07-22T16:17:34.413",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49802",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected workflow fails to preserve its invariant across a state transition or concurrent operation.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49802",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-49803",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:06:06.259Z",
      "date_updated": "2026-08-03T22:54:28.318Z",
      "publisher": "microsoft",
      "title": "Windows AppX Deployment Extensions Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04943
      },
      "nvd": {
        "published": "2026-07-14T17:16:56.643",
        "lastModified": "2026-07-22T16:17:34.553",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49803",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft identifies a race in AppX Deployment Service that permits local privilege escalation, while the record does not disclose the shared object or conflicting transitions.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49803",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:06:02.437Z",
      "date_updated": "2026-08-03T22:54:24.362Z",
      "publisher": "microsoft",
      "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 17,
        "versionEntryCount": 17,
        "versionRangeCount": 17,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28697
      },
      "nvd": {
        "published": "2026-07-14T17:16:56.813",
        "lastModified": "2026-07-16T16:19:10.527",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49804",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data is written beyond the boundary of a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49804",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 17,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-49805",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:06:05.688Z",
      "date_updated": "2026-08-03T22:54:27.667Z",
      "publisher": "microsoft",
      "title": "Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.03303,
        "percentile": 0.87317
      },
      "nvd": {
        "published": "2026-07-14T17:16:56.990",
        "lastModified": "2026-07-22T16:17:34.870",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49805",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows 10 Version 1607 permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49805",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-49806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:06:05.184Z",
      "date_updated": "2026-08-03T22:54:27.117Z",
      "publisher": "microsoft",
      "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04944
      },
      "nvd": {
        "published": "2026-07-14T17:16:57.173",
        "lastModified": "2026-07-22T16:17:35.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49806",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent USB print-driver operations use shared object state without sufficient synchronization and can reach a freed object.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49806",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-49807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:06:08.316Z",
      "date_updated": "2026-08-03T22:54:30.579Z",
      "publisher": "microsoft",
      "title": "Windows DirectX Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00374,
        "percentile": 0.30113
      },
      "nvd": {
        "published": "2026-07-14T17:16:57.297",
        "lastModified": "2026-07-22T16:17:35.177",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49807",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows DirectX exposes sensitive local information to an unauthorized process, but the source buffer and output path are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49807",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-49808",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:02:37.208Z",
      "date_published": "2026-07-14T17:06:10.210Z",
      "date_updated": "2026-08-03T22:54:32.230Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04963
      },
      "nvd": {
        "published": "2026-07-14T17:16:57.443",
        "lastModified": "2026-07-22T16:17:35.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49808",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Concurrent Windows Kernel operations can release shared state while another operation still uses it, creating a use-after-free privilege path.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49808",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-49813",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:04:30.334Z",
      "date_published": "2026-07-03T14:18:11.239Z",
      "date_updated": "2026-07-07T13:12:36.741Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0046,
        "percentile": 0.37597
      },
      "nvd": {
        "published": "2026-07-03T15:16:32.487",
        "lastModified": "2026-07-08T19:32:10.657",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49813",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PowerProtect Data Domain command path passes attacker-controlled text into command syntax without argument or shell separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 460,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-49814",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:04:30.334Z",
      "date_published": "2026-07-03T14:13:36.579Z",
      "date_updated": "2026-07-07T03:56:08.854Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01216,
        "percentile": 0.65592
      },
      "nvd": {
        "published": "2026-07-03T15:16:32.610",
        "lastModified": "2026-07-08T19:32:07.010",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49814",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerProtect inserts a privileged remote user's input into an operating-system command without neutralizing shell syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 461,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-49815",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T17:04:30.334Z",
      "date_published": "2026-07-03T14:09:19.831Z",
      "date_updated": "2026-07-07T03:56:10.428Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01096,
        "percentile": 0.62328
      },
      "nvd": {
        "published": "2026-07-03T15:16:32.720",
        "lastModified": "2026-07-08T19:32:01.087",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49815",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In PowerProtect Data Domain, attacker-controlled input reaches an operating-system command without shell-context neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-49834",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T18:50:36.056Z",
      "date_published": "2026-07-17T19:20:06.140Z",
      "date_updated": "2026-07-17T19:42:17.005Z",
      "publisher": "GitHub_M",
      "title": "sigstore-go: Multi-log threshold bypass via single compromised log",
      "affected": {
        "vendors": [
          "sigstore"
        ],
        "products": [
          {
            "vendor": "sigstore",
            "product": "sigstore-go"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00113,
        "percentile": 0.0163
      },
      "nvd": {
        "published": "2026-07-17T20:17:21.963",
        "lastModified": "2026-07-30T13:18:22.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49834",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "sigstore-go verifies a signature without binding every security-relevant field and required authority to the signed representation, allowing a modified or under-threshold object to pass verification.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sigstore/sigstore-go/security/advisories/GHSA-9vcr-p3rj-q5q6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-go/pull/633",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-go/commit/dbb07e62623edd5b175fb9dd5a41dcb85a159207",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-go/releases/tag/v1.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49835",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T18:50:36.056Z",
      "date_published": "2026-07-17T18:16:41.764Z",
      "date_updated": "2026-07-17T19:45:44.026Z",
      "publisher": "GitHub_M",
      "title": "Sigstore Timestamp Authority: OOM due to unbounded metric label cardinality",
      "affected": {
        "vendors": [
          "sigstore"
        ],
        "products": [
          {
            "vendor": "sigstore",
            "product": "timestamp-authority"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00447,
        "percentile": 0.36699
      },
      "nvd": {
        "published": "2026-07-17T19:17:16.227",
        "lastModified": "2026-07-30T14:14:05.867",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49835",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The metrics middleware uses raw request paths and methods as persistent Prometheus labels, allowing unbounded time-series cardinality to exhaust memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sigstore/timestamp-authority/security/advisories/GHSA-9c54-x2g4-v92j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/sigstore/timestamp-authority/commit/506ec57b6ac2ea1e4739322e47453469425b69b5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sigstore/timestamp-authority/releases/tag/v2.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49844",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T20:15:42.977Z",
      "date_published": "2026-07-10T21:14:59.111Z",
      "date_updated": "2026-07-14T14:35:11.005Z",
      "publisher": "apache",
      "title": "Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Log4j API"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0.39999999999999947,
      "epss": {
        "score": 0.00574,
        "percentile": 0.44135
      },
      "nvd": {
        "published": "2026-07-10T22:16:42.540",
        "lastModified": "2026-07-14T20:03:09.910",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49844",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Log4j serializes NaN and infinity as bare tokens, allowing attacker-controlled values to produce invalid JSON for downstream log parsers.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message",
          "host": "logging.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "related"
          ]
        },
        {
          "url": "https://github.com/apache/logging-log4j2/pull/4163",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://logging.apache.org/cyclonedx/vdr.xml",
          "host": "logging.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://logging.apache.org/security.html#CVE-2026-49844",
          "host": "logging.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1317,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-49852",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T22:03:19.640Z",
      "date_published": "2026-07-17T19:14:58.019Z",
      "date_updated": "2026-07-20T14:58:41.701Z",
      "publisher": "GitHub_M",
      "title": "joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)",
      "affected": {
        "vendors": [
          "authlib"
        ],
        "products": [
          {
            "vendor": "authlib",
            "product": "joserfc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-326",
          "name": "Inadequate Encryption Strength",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1391",
          "name": "Use of Weak Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04062
      },
      "nvd": {
        "published": "2026-07-17T20:17:23.270",
        "lastModified": "2026-07-23T18:02:00.793",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49852",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "joserfc accepts an empty or nil HMAC verification key and consequently validates attacker-forged JWT signatures.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-326",
          "CWE-1391"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/authlib/joserfc/security/advisories/GHSA-gg9x-qcx2-xmrh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/authlib/joserfc/commit/86d00910b2b2d2d07503fee9b572906daefab7f1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/authlib/joserfc/releases/tag/1.6.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 611,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49853",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T22:03:19.640Z",
      "date_published": "2026-07-14T20:41:32.075Z",
      "date_updated": "2026-07-21T14:47:51.048Z",
      "publisher": "GitHub_M",
      "title": "Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient",
      "affected": {
        "vendors": [
          "tornadoweb"
        ],
        "products": [
          {
            "vendor": "tornadoweb",
            "product": "tornado"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00365,
        "percentile": 0.29185
      },
      "nvd": {
        "published": "2026-07-14T21:17:02.130",
        "lastModified": "2026-07-21T16:17:13.477",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49853",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Tornado preserves authorization credentials when following a redirect to a different scheme, host, or port.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/tornadoweb/tornado/pull/3626",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/tornadoweb/tornado/commit/aba2569f7ed7a6bdbef816658fb6b7182531b751",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/tornadoweb/tornado/releases/tag/v6.5.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49854",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T22:03:19.640Z",
      "date_published": "2026-07-14T20:43:03.977Z",
      "date_updated": "2026-07-15T13:26:39.749Z",
      "publisher": "GitHub_M",
      "title": "Tornado: Out-of-bounds memory access in C extension",
      "affected": {
        "vendors": [
          "tornadoweb"
        ],
        "products": [
          {
            "vendor": "tornadoweb",
            "product": "tornado"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26369
      },
      "nvd": {
        "published": "2026-07-14T21:17:02.300",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49854",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tornado's native websocket_mask reads past the provided mask or data buffer because it does not validate the supplied lengths.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-cx3h-4qpv-8hc9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/tornadoweb/tornado/pull/3626",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/tornadoweb/tornado/commit/96dc88c2a05705287856b2cd6b4b4034f9a6aaac",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/tornadoweb/tornado/releases/tag/v6.5.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49855",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T22:03:19.640Z",
      "date_published": "2026-07-14T20:45:02.982Z",
      "date_updated": "2026-07-16T14:56:38.904Z",
      "publisher": "GitHub_M",
      "title": "tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)",
      "affected": {
        "vendors": [
          "tornadoweb"
        ],
        "products": [
          {
            "vendor": "tornadoweb",
            "product": "tornado"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00572,
        "percentile": 0.44054
      },
      "nvd": {
        "published": "2026-07-14T21:17:02.437",
        "lastModified": "2026-07-16T16:19:10.690",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49855",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tornado limits each decompressed chunk without limiting the accumulated output, allowing a compressed response or request to expand until memory is exhausted.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/tornadoweb/tornado/pull/3626",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/tornadoweb/tornado/commit/ff808b33adc52d89a549376a5e3628e92abbc8ff",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49858",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T22:03:19.640Z",
      "date_published": "2026-07-01T19:24:58.170Z",
      "date_updated": "2026-07-02T12:20:09.370Z",
      "publisher": "GitHub_M",
      "title": "API Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate",
      "affected": {
        "vendors": [
          "api-platform"
        ],
        "products": [
          {
            "vendor": "api-platform",
            "product": "core"
          },
          {
            "vendor": "api-platform",
            "product": "api-platform/hal"
          },
          {
            "vendor": "api-platform",
            "product": "api-platform/json-api"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-524",
          "name": "Use of Cache Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11114
      },
      "nvd": {
        "published": "2026-07-01T20:17:10.153",
        "lastModified": "2026-07-02T18:41:35.990",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49858",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The JSON:API and HAL normalizers omit the isCacheKeySafe gate, allowing a component layout computed for one user to be reused for a user with different field permissions.",
        "basis": [
          "CNA",
          "CWE-524",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/api-platform/core/security/advisories/GHSA-pjhx-3c3w-9v23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 972,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-49866",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T22:03:19.641Z",
      "date_published": "2026-07-08T20:47:09.051Z",
      "date_updated": "2026-07-09T14:40:44.919Z",
      "publisher": "GitHub_M",
      "title": "libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays",
      "affected": {
        "vendors": [
          "libp2p"
        ],
        "products": [
          {
            "vendor": "libp2p",
            "product": "js-libp2p"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36231
      },
      "nvd": {
        "published": "2026-07-08T21:16:49.137",
        "lastModified": "2026-07-10T19:10:59.333",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49866",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Gossipsub decodes and iterates IHAVE and IWANT arrays with infinite item limits, allowing one frame to monopolize the Node.js event loop.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/libp2p/js-libp2p/security/advisories/GHSA-cwc9-cp4j-mcvv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/libp2p/js-libp2p/pull/3520",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/libp2p/js-libp2p/commit/773dd80ded24dbd6b19e675c89fd2f3b45f2d899",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/libp2p/js-libp2p/releases/tag/gossipsub-v16.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 422,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49867",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-01T22:03:19.641Z",
      "date_published": "2026-07-15T19:41:52.701Z",
      "date_updated": "2026-07-18T01:38:33.335Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Authenticated Stored XSS in DataEase Template Static Resources",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.1888
      },
      "nvd": {
        "published": "2026-07-15T20:17:12.943",
        "lastModified": "2026-07-18T02:17:09.423",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49867",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Authenticated users can publish unsanitized SVG bytes as same-origin static resources, allowing browser-executable markup to run when the resource is opened.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-jqxj-h53x-mpvf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/b00d9e3a73a9653bfc3ea0c41c0c3a5b0dd40bf8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 637,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49876",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T12:32:43.972Z",
      "date_published": "2026-07-13T08:45:35.082Z",
      "date_updated": "2026-07-13T14:27:15.256Z",
      "publisher": "apache",
      "title": "Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Gravitino"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.32993
      },
      "nvd": {
        "published": "2026-07-13T10:16:29.603",
        "lastModified": "2026-07-13T22:22:55.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49876",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server accepts an attacker-controlled destination without constraining the resolved request target to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/2ffkj771d6dp1okh2cdtody969hoo1zs",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/13/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49969",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T16:30:15.233Z",
      "date_published": "2026-07-13T18:09:31.010Z",
      "date_updated": "2026-07-15T14:17:07.833Z",
      "publisher": "VulnCheck",
      "title": "Laravel-Mediable < 7.0.0 SSRF via RemoteUrlAdapter URL Handling",
      "affected": {
        "vendors": [
          "plank"
        ],
        "products": [
          {
            "vendor": "plank",
            "product": "laravel-mediable"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 2.1000000000000005,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15263
      },
      "nvd": {
        "published": "2026-07-13T19:17:09.793",
        "lastModified": "2026-07-15T15:16:42.063",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49969",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "laravel-mediable follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/plank/laravel-mediable/releases/tag/7.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/plank/laravel-mediable/commit/7e9e3000fa05fe16e678f15bfb51a091e60c2cb8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/laravel-mediable-ssrf-via-remoteurladapter-url-handling",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49970",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T16:30:15.234Z",
      "date_published": "2026-07-13T18:11:36.832Z",
      "date_updated": "2026-07-14T21:33:32.071Z",
      "publisher": "VulnCheck",
      "title": "Laravel-Mediable < 7.0.0 Path Traversal via File::sanitizePath()",
      "affected": {
        "vendors": [
          "plank"
        ],
        "products": [
          {
            "vendor": "plank",
            "product": "laravel-mediable"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00771,
        "percentile": 0.52105
      },
      "nvd": {
        "published": "2026-07-13T19:17:09.943",
        "lastModified": "2026-07-14T22:17:12.587",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49970",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A permissive path regex and ineffective trailing trim allow an upload directory to traverse to arbitrary filesystem locations.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/plank/laravel-mediable/releases/tag/7.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/plank/laravel-mediable/commit/6d1e7fb39922fdfb3b2d120e13f4eb2e653ae082",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/laravel-mediable-path-traversal-via-file-sanitizepath",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 603,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49971",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T16:30:15.234Z",
      "date_published": "2026-07-13T18:13:29.473Z",
      "date_updated": "2026-07-14T21:33:32.767Z",
      "publisher": "VulnCheck",
      "title": "Laravel-Mediable < 7.0.0 Stored XSS via SVG File Upload",
      "affected": {
        "vendors": [
          "plank"
        ],
        "products": [
          {
            "vendor": "plank",
            "product": "laravel-mediable"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10462
      },
      "nvd": {
        "published": "2026-07-13T19:17:10.250",
        "lastModified": "2026-07-14T22:17:12.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49971",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An uploaded SVG is served in a context where embedded script can execute.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/plank/laravel-mediable/releases/tag/7.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/plank/laravel-mediable/commit/65046b2162fac23ec5d5e8fbdff01a9a0804003e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/laravel-mediable-stored-xss-via-svg-file-upload",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49972",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T16:30:15.234Z",
      "date_published": "2026-07-13T18:16:02.131Z",
      "date_updated": "2026-07-15T18:49:02.236Z",
      "publisher": "VulnCheck",
      "title": "Laravel-Mediable < 7.0.0 File Upload RCE via Extension Bypass",
      "affected": {
        "vendors": [
          "plank"
        ],
        "products": [
          {
            "vendor": "plank",
            "product": "laravel-mediable"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00777,
        "percentile": 0.52298
      },
      "nvd": {
        "published": "2026-07-13T19:17:10.447",
        "lastModified": "2026-07-15T19:17:24.827",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49972",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Double-extension validation accepts an inner PHP extension in the stored basename while trusting the outer image extension.",
        "basis": [
          "CNA record",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/plank/laravel-mediable/releases/tag/7.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/plank/laravel-mediable/commit/49e3583bed13423611b3391f89e6b002571eed73",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/laravel-mediable-file-upload-rce-via-extension-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49977",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T18:30:51.281Z",
      "date_published": "2026-07-17T20:21:21.476Z",
      "date_updated": "2026-07-20T19:11:28.659Z",
      "publisher": "GitHub_M",
      "title": "tarteaucitron.js: data-cookie attribute can be used to delete arbitrary cookies",
      "affected": {
        "vendors": [
          "AmauriC"
        ],
        "products": [
          {
            "vendor": "AmauriC",
            "product": "tarteaucitron.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.1006
      },
      "nvd": {
        "published": "2026-07-17T21:17:06.930",
        "lastModified": "2026-07-23T18:08:15.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49977",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The purge handler trusts any clicked element carrying purgeBtn and data-cookie attributes without checking that the cookie belongs to a managed service.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/AmauriC/tarteaucitron.js/security/advisories/GHSA-jxj7-g6gm-49j7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/AmauriC/tarteaucitron.js/commit/24b5464400ae2ff1ad96a092c629b9d632b9cc93",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/AmauriC/tarteaucitron.js/releases/tag/v1.33.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://www.drupal.org/sa-contrib-2026-040",
          "host": "www.drupal.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49978",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T18:30:51.281Z",
      "date_published": "2026-07-14T20:02:46.263Z",
      "date_updated": "2026-07-21T14:59:20.582Z",
      "publisher": "GitHub_M",
      "title": "DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00334,
        "percentile": 0.25925
      },
      "nvd": {
        "published": "2026-07-14T21:17:02.560",
        "lastModified": "2026-07-21T19:49:00.217",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49978",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "IN_PLACE sanitization skips shadow content inside template.content, leaving executable markup that later runs when the template is cloned.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-rp9w-3fw7-7cwq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cure53/DOMPurify/commit/ca30f070c360df162a3e3848e80e6fd3c9e74bff",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cure53/DOMPurify/releases/tag/3.4.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T18:30:51.282Z",
      "date_published": "2026-07-14T21:26:00.460Z",
      "date_updated": "2026-07-21T14:57:52.032Z",
      "publisher": "GitHub_M",
      "title": "Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`",
      "affected": {
        "vendors": [
          "twigphp"
        ],
        "products": [
          {
            "vendor": "twigphp",
            "product": "Twig"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.1999999999999993,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11612
      },
      "nvd": {
        "published": "2026-07-14T22:17:13.070",
        "lastModified": "2026-07-21T16:17:13.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-49981",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A cached Twig Template retains the allow-list verdict from an earlier sandbox state and reuses it when a later render applies a different policy.",
        "basis": [
          "CNA",
          "CWE-693",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/twigphp/Twig/security/advisories/GHSA-529h-vh3j-85hq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/commit/23eb6eb1267cb0d303b91eb5cff9b0c559c538a4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/twigphp/Twig/releases/tag/v3.27.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49987",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T18:30:51.282Z",
      "date_published": "2026-07-15T18:06:27.018Z",
      "date_updated": "2026-07-15T19:40:40.723Z",
      "publisher": "GitHub_M",
      "title": "Repomix: Command Injection (RCE) via `--remote-branch` Argument Injection",
      "affected": {
        "vendors": [
          "yamadashy"
        ],
        "products": [
          {
            "vendor": "yamadashy",
            "product": "repomix"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00495,
        "percentile": 0.39788
      },
      "nvd": {
        "published": "2026-07-15T19:17:25.483",
        "lastModified": "2026-07-15T20:17:13.083",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49987",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A user-controlled command argument is accepted as a Git option because the invocation omits strict option termination and validation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yamadashy/repomix/security/advisories/GHSA-9mm9-rqhj-j5mx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/yamadashy/repomix/commit/92bfa3193b5233a0d21beff929444153c088de82",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamadashy/repomix/releases/tag/v1.14.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49988",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T18:30:51.282Z",
      "date_published": "2026-07-15T18:05:10.789Z",
      "date_updated": "2026-07-18T01:16:12.325Z",
      "publisher": "GitHub_M",
      "title": "Repomix: attach_packed_output can bypass file-read secret scanning for supported local files",
      "affected": {
        "vendors": [
          "yamadashy"
        ],
        "products": [
          {
            "vendor": "yamadashy",
            "product": "repomix"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03725
      },
      "nvd": {
        "published": "2026-07-15T19:17:25.823",
        "lastModified": "2026-07-18T02:17:09.540",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49988",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "attach_packed_output registers arbitrary supported local files as packed output without the normal path validation or secret-scanning boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yamadashy/repomix/security/advisories/GHSA-hwpp-h97w-2h3j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/yamadashy/repomix/commit/e447f7dba6f51fdb26bcad0c280542fca291960e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamadashy/repomix/releases/tag/v1.14.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49997",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T18:30:51.283Z",
      "date_published": "2026-07-15T16:14:03.602Z",
      "date_updated": "2026-07-20T14:50:35.228Z",
      "publisher": "GitHub_M",
      "title": "SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16967
      },
      "nvd": {
        "published": "2026-07-15T17:16:49.103",
        "lastModified": "2026-07-20T16:17:04.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49997",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Document::purge_edges disables permissions while deleting connected edge records, bypassing the edge table's delete and select rules when a node is removed.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-whwg-vh4f-pmmf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/surrealdb/surrealdb/commit/500f4060349580b9cbb9c07b8112a487551c4616",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/surrealdb/surrealdb/releases/tag/v3.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-49998",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T18:30:51.283Z",
      "date_published": "2026-07-16T19:33:33.147Z",
      "date_updated": "2026-07-17T11:13:39.150Z",
      "publisher": "GitHub_M",
      "title": "Centrifugo: Dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass",
      "affected": {
        "vendors": [
          "centrifugal"
        ],
        "products": [
          {
            "vendor": "centrifugal",
            "product": "centrifugo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07438
      },
      "nvd": {
        "published": "2026-07-16T20:16:45.290",
        "lastModified": "2026-07-17T18:42:17.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-49998",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The JWKS cache keys entries only by kid, allowing a key from one issuer to satisfy validation for another issuer.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/centrifugal/centrifugo/security/advisories/GHSA-g6vg-wj8f-48cj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/centrifugal/centrifugo/pull/1142",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/centrifugal/centrifugo/commit/15d785015c6f318c1b68ea40b813699c9f8bd2c4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/centrifugal/centrifugo/releases/tag/v6.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 558,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50007",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T22:46:02.578Z",
      "date_published": "2026-07-07T20:53:21.457Z",
      "date_updated": "2026-07-08T14:02:20.277Z",
      "publisher": "GitHub_M",
      "title": "Actual: Shared users can perform owner-only file management actions",
      "affected": {
        "vendors": [
          "actualbudget"
        ],
        "products": [
          {
            "vendor": "actualbudget",
            "product": "actual"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.1591
      },
      "nvd": {
        "published": "2026-07-07T21:17:25.977",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50007",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The actual operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/actualbudget/actual/security/advisories/GHSA-23vm-ffgg-qvjr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/pull/7977",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/pull/8333",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/commit/18a8dc03c48eeb2e8252669a80673e6a9933b5fd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/commit/3b9e79ed5ee795a80bbae214d6ebb2755289d7f2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50012",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T22:46:02.579Z",
      "date_published": "2026-07-16T16:11:34.488Z",
      "date_updated": "2026-07-17T14:04:25.895Z",
      "publisher": "GitHub_M",
      "title": "Squid: Memory corruption in cache_digest reply handling",
      "affected": {
        "vendors": [
          "squid-cache"
        ],
        "products": [
          {
            "vendor": "squid-cache",
            "product": "squid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01364,
        "percentile": 0.69094
      },
      "nvd": {
        "published": "2026-07-16T17:16:57.493",
        "lastModified": "2026-07-20T01:35:45.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50012",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Squid trusts a digest size that differs from the received data length and writes beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/squid-cache/squid/security/advisories/GHSA-5vmx-9x64-9284",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/squid-cache/squid/pull/2423",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/squid-cache/squid/commit/19fcfe922717c8b255270c032dcde4071c003bcd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/squid-cache/squid/releases/tag/SQUID_7_6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 596,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50030",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-02T22:46:02.580Z",
      "date_published": "2026-07-15T19:24:51.531Z",
      "date_updated": "2026-07-18T01:30:34.129Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Arbitrary SQL execution in preview path (direct data disclosure)",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.1888
      },
      "nvd": {
        "published": "2026-07-15T20:17:13.233",
        "lastModified": "2026-07-18T02:17:09.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50030",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DataEase SQL preview accepts caller-supplied SQL and a datasource identifier, passes the decoded query to prepareStatement.executeQuery, and returns rows from arbitrary readable datasource tables.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-j4v5-5gcx-cvfc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/22930a493d900fe3d8084b3dd4c0125abdb2a847",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50032",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:01:29.573Z",
      "date_published": "2026-07-23T20:53:36.613Z",
      "date_updated": "2026-07-24T13:41:13.842Z",
      "publisher": "icscert",
      "title": "NULL Pointer Dereference in MZ Automation libIEC61850",
      "affected": {
        "vendors": [
          "MZ Automation"
        ],
        "products": [
          {
            "vendor": "MZ Automation",
            "product": "libIEC61850"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00263,
        "percentile": 0.1796
      },
      "nvd": {
        "published": "2026-07-23T21:17:04.773",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50032",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50039",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:01:29.564Z",
      "date_published": "2026-07-23T20:32:30.439Z",
      "date_updated": "2026-07-24T13:54:22.569Z",
      "publisher": "icscert",
      "title": "Stack-based Buffer Overflow in MZ Automation libIEC61850",
      "affected": {
        "vendors": [
          "MZ Automation"
        ],
        "products": [
          {
            "vendor": "MZ Automation",
            "product": "libIEC61850"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00267,
        "percentile": 0.1866
      },
      "nvd": {
        "published": "2026-07-23T21:17:04.910",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50039",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler copies attacker-controlled data beyond a fixed-size stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 145,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50043",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T06:52:54.348Z",
      "date_published": "2026-07-01T06:53:32.950Z",
      "date_updated": "2026-07-01T12:24:26.718Z",
      "publisher": "jpcert",
      "title": "Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110.",
      "affected": {
        "vendors": [
          "Seiko Solutions Inc."
        ],
        "products": [
          {
            "vendor": "Seiko Solutions Inc.",
            "product": "SkyBridge MB-A100/MB-A110"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.01367,
        "percentile": 0.69158
      },
      "nvd": {
        "published": "2026-07-01T08:16:21.727",
        "lastModified": "2026-07-01T18:17:31.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50043",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled command data reaches a command interpreter without safe argument separation or complete command-language neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.seiko-sol.co.jp/archives/94618/",
          "host": "www.seiko-sol.co.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jvn.jp/en/jp/JVN20721579/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50044",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T17:14:43.844Z",
      "date_published": "2026-07-23T22:03:25.523Z",
      "date_updated": "2026-07-24T12:38:40.611Z",
      "publisher": "icscert",
      "title": "Inadequate Encryption Strength in Panduit IntraVUE  by Pronetiqs",
      "affected": {
        "vendors": [
          "Pronetiqs"
        ],
        "products": [
          {
            "vendor": "Pronetiqs",
            "product": "Panduit Intravue"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-326",
          "name": "Inadequate Encryption Strength",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00084,
        "percentile": 0.00356
      },
      "nvd": {
        "published": "2026-07-23T23:16:49.170",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50044",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "IntraVUE protects administrator credentials with a hash weak enough for offline recovery or pass-the-hash reuse.",
        "basis": [
          "CNA",
          "CWE-326"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50045",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:27:22.806Z",
      "date_published": "2026-07-22T13:07:55.730Z",
      "date_updated": "2026-07-22T18:57:09.417Z",
      "publisher": "NLnet Labs",
      "title": "'max-global-quota' reset by DNSSEC validation restarts",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-406",
          "name": "Insufficient Control of Network Message Volume (Network Amplification)",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19994
      },
      "nvd": {
        "published": "2026-07-22T14:17:19.987",
        "lastModified": "2026-07-24T13:58:11.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50045",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DNSSEC validation restarts reset accounting so one client query can exceed the configured global upstream-packet quota.",
        "basis": [
          "CNA",
          "CWE-406"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50045.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50046",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:27:22.824Z",
      "date_published": "2026-07-22T13:08:08.710Z",
      "date_updated": "2026-07-22T18:57:33.147Z",
      "publisher": "NLnet Labs",
      "title": "Possible heap use-after-free in an error path when a DoT forwarded query is jostled out",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14837
      },
      "nvd": {
        "published": "2026-07-22T14:17:20.117",
        "lastModified": "2026-07-24T13:55:29.627",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50046",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "waiting_tcp keeps a pointer to a TLS server-name string after serviced_query frees that string during mesh jostling.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50046.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1232,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:01:29.578Z",
      "date_published": "2026-07-23T20:50:42.198Z",
      "date_updated": "2026-07-24T13:41:40.192Z",
      "publisher": "icscert",
      "title": "Improper Handling of  Syntactically Invalid Structure in MZ Automation libIEC61850",
      "affected": {
        "vendors": [
          "MZ Automation"
        ],
        "products": [
          {
            "vendor": "MZ Automation",
            "product": "libIEC61850"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-228",
          "name": "Improper Handling of Syntactically Invalid Structure",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06104
      },
      "nvd": {
        "published": "2026-07-23T21:17:05.057",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50103",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The shared GOOSE parser accepts a malformed TLV structure and dereferences a null pointer instead of rejecting the frame.",
        "basis": [
          "CNA",
          "CWE-228"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50124",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T18:49:32.274Z",
      "date_published": "2026-07-15T19:38:14.211Z",
      "date_updated": "2026-07-17T12:25:17.524Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Remote Code Execution (RCE) via Zip Protocol & File Dropper",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24697
      },
      "nvd": {
        "published": "2026-07-15T20:17:13.370",
        "lastModified": "2026-07-17T13:18:54.510",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50124",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload and datasource path accepts an attacker-supplied database artifact whose embedded Java aliases execute when queried.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-cjmg-jqmc-xj5v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/a7bffa795cb0ca041dce0effe68479cf3bf13db1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 460,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50130",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T18:49:32.275Z",
      "date_published": "2026-07-14T21:35:00.813Z",
      "date_updated": "2026-07-16T03:55:27.225Z",
      "publisher": "GitHub_M",
      "title": "Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`",
      "affected": {
        "vendors": [
          "pi-hole"
        ],
        "products": [
          {
            "vendor": "pi-hole",
            "product": "pi-hole"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-282",
          "name": "Improper Ownership Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16683
      },
      "nvd": {
        "published": "2026-07-14T22:17:13.203",
        "lastModified": "2026-07-30T14:31:09.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50130",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A user-replaceable logrotate file is re-owned by root and later interpreted by a root cron job, laundering attacker content across trust states.",
        "basis": [
          "CNA",
          "CWE-282"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pi-hole/pi-hole/security/advisories/GHSA-h8w9-qx2v-wrww",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pi-hole/pi-hole/commit/18002bf7c6bf382fe5861d01321f427019e1be89",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pi-hole/pi-hole/releases/tag/v6.4.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 459,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50133",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T18:49:32.275Z",
      "date_published": "2026-07-06T19:31:18.386Z",
      "date_updated": "2026-07-07T14:44:31.886Z",
      "publisher": "GitHub_M",
      "title": "Hugo: XSS via text/html content files",
      "affected": {
        "vendors": [
          "gohugoio"
        ],
        "products": [
          {
            "vendor": "gohugoio",
            "product": "hugo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00185,
        "percentile": 0.08296
      },
      "nvd": {
        "published": "2026-07-06T20:16:37.043",
        "lastModified": "2026-07-08T03:08:33.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50133",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In hugo, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gohugoio/hugo/security/advisories/GHSA-c54g-xjwj-8g82",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/commit/e41a06447daa3071a01f333fdcec0a5153c3c8d1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/releases/tag/v0.162.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 475,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50134",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T18:49:32.275Z",
      "date_published": "2026-07-06T19:42:49.280Z",
      "date_updated": "2026-07-07T16:57:36.713Z",
      "publisher": "GitHub_M",
      "title": "Hugo: security.http.urls allow-list bypass via HTTP redirects",
      "affected": {
        "vendors": [
          "gohugoio"
        ],
        "products": [
          {
            "vendor": "gohugoio",
            "product": "hugo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16346
      },
      "nvd": {
        "published": "2026-07-06T20:16:37.197",
        "lastModified": "2026-07-08T03:08:10.280",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50134",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "hugo accepts an attacker-controlled destination without reapplying the network allowlist after URL parsing, redirects, or address resolution, allowing server-side requests to a prohibited target.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gohugoio/hugo/security/advisories/GHSA-vxgm-5rmg-5w8g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/commit/86fbb0f7a8bbb93e2e916390de9e5a4f24bf9f50",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/releases/tag/v0.162.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50135",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T18:49:32.275Z",
      "date_published": "2026-07-06T19:52:04.561Z",
      "date_updated": "2026-07-07T16:57:29.874Z",
      "publisher": "GitHub_M",
      "title": "Hugo: Symlink confinement bypass in resources.Get",
      "affected": {
        "vendors": [
          "gohugoio"
        ],
        "products": [
          {
            "vendor": "gohugoio",
            "product": "hugo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00271,
        "percentile": 0.19146
      },
      "nvd": {
        "published": "2026-07-06T21:16:56.347",
        "lastModified": "2026-07-08T14:53:04.987",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50135",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RootMappingFs follows a direct symlink before applying mount confinement, allowing resources.Get to read the external target.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gohugoio/hugo/security/advisories/GHSA-fw87-fv5r-9fpw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/commit/f8b5fa09a64950c32b803821ede411ebfe772b7a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/releases/tag/v0.162.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 482,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T18:49:32.275Z",
      "date_published": "2026-07-15T20:04:07.099Z",
      "date_updated": "2026-07-17T12:27:10.432Z",
      "publisher": "GitHub_M",
      "title": "ncnn: Out-of-bounds heap write in ParamDict::load_param via unchecked negative parameter id",
      "affected": {
        "vendors": [
          "Tencent"
        ],
        "products": [
          {
            "vendor": "Tencent",
            "product": "ncnn"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00108,
        "percentile": 0.01394
      },
      "nvd": {
        "published": "2026-07-15T20:17:13.500",
        "lastModified": "2026-07-17T13:18:54.657",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50144",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ncnn rejects parameter IDs above the array limit but not negative IDs, allowing a model file to write before the params array.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20",
          "CWE-129",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Tencent/ncnn/security/advisories/GHSA-jxmc-3mv6-7pwr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Tencent/ncnn/commit/5a0288f255daa6c3294f77109f67718e434ec020",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-50147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T18:49:32.276Z",
      "date_published": "2026-07-15T15:21:23.107Z",
      "date_updated": "2026-07-15T16:04:03.343Z",
      "publisher": "GitHub_M",
      "title": "Metabase: Arbitrary File Read via MySQL Connection Property Injection",
      "affected": {
        "vendors": [
          "metabase"
        ],
        "products": [
          {
            "vendor": "metabase",
            "product": "metabase"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.09987
      },
      "nvd": {
        "published": "2026-07-15T16:16:47.830",
        "lastModified": "2026-07-30T14:30:23.497",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50147",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Metabase permits unsafe MySQL or MariaDB JDBC connection parameters that make the driver interpret a server-local path as a file source.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/metabase/metabase/security/advisories/GHSA-mfpj-crjq-xrcp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-50148",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T18:49:32.276Z",
      "date_published": "2026-07-15T15:18:04.142Z",
      "date_updated": "2026-07-20T14:55:07.812Z",
      "publisher": "GitHub_M",
      "title": "Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write",
      "affected": {
        "vendors": [
          "metabase"
        ],
        "products": [
          {
            "vendor": "metabase",
            "product": "metabase"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00427,
        "percentile": 0.3516
      },
      "nvd": {
        "published": "2026-07-15T16:16:47.963",
        "lastModified": "2026-07-30T14:29:58.737",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50148",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A model editor can direct the Snowflake JDBC driver to write attacker-controlled bytes over an arbitrary Metabase host file.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/metabase/metabase/security/advisories/GHSA-r6x2-rchx-q9g9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 671,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-50151",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T20:54:20.431Z",
      "date_published": "2026-07-17T19:41:11.648Z",
      "date_updated": "2026-07-20T13:52:07.476Z",
      "publisher": "GitHub_M",
      "title": "oras-go: credential forwarding via unvalidated Location header in blob upload",
      "affected": {
        "vendors": [
          "oras-project"
        ],
        "products": [
          {
            "vendor": "oras-project",
            "product": "oras-go"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00364,
        "percentile": 0.29169
      },
      "nvd": {
        "published": "2026-07-17T20:17:23.683",
        "lastModified": "2026-07-23T16:15:11.587",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50151",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "oras-go follows a registry-controlled redirect to another host while forwarding the original authorization credentials.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/oras-project/oras-go/pull/1152",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/oras-project/oras-go/commit/4683c46ef078091544f5f55fd25102f002806991",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/oras-project/oras-go/releases/tag/v2.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 486,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50160",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T20:54:20.432Z",
      "date_published": "2026-07-01T17:48:49.381Z",
      "date_updated": "2026-07-02T03:57:34.538Z",
      "publisher": "GitHub_M",
      "title": "Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite",
      "affected": {
        "vendors": [
          "hoppscotch"
        ],
        "products": [
          {
            "vendor": "hoppscotch",
            "product": "hoppscotch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.08603,
        "percentile": 0.94543
      },
      "nvd": {
        "published": "2026-07-01T19:16:53.173",
        "lastModified": "2026-07-02T19:45:47.390",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50160",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The onboarding endpoint accepts undeclared configuration keys because NestJS request whitelisting is disabled, allowing an unauthenticated caller to overwrite JWT_SECRET.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-j542-4rch-8hwf",
          "host": "github.com",
          "sources": [
            "adp:1",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hoppscotch/hoppscotch/pull/6171",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/06/23/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1002,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50162",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T20:54:20.432Z",
      "date_published": "2026-07-17T19:39:28.847Z",
      "date_updated": "2026-07-20T18:18:44.172Z",
      "publisher": "GitHub_M",
      "title": "oras-go: file store write outside workingDir via symlink traversal",
      "affected": {
        "vendors": [
          "oras-project"
        ],
        "products": [
          {
            "vendor": "oras-project",
            "product": "oras-go"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00365,
        "percentile": 0.29239
      },
      "nvd": {
        "published": "2026-07-17T20:17:23.817",
        "lastModified": "2026-07-23T18:08:07.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50162",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not account for symlink traversal, so when AllowPathTraversalOnWrite=false an attacker-controlled blob title through ocispec.AnnotationTitle such as out/pwn.txt can follow a workingDir symlink out -> /some/outside/dir and cause pushFile() to create /some/outside/dir/pwn.txt outside workingDir.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/oras-project/oras-go/security/advisories/GHSA-8xwf-rjm4-xvhv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/oras-project/oras-go/commit/cc323e564d90c6b5b4bdd71d3c8d2ee2713b37e5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/oras-project/oras-go/releases/tag/v2.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50163",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T20:54:20.432Z",
      "date_published": "2026-07-17T19:36:01.254Z",
      "date_updated": "2026-07-20T15:01:16.630Z",
      "publisher": "GitHub_M",
      "title": "oras-go: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution in `oras-go` tar extraction",
      "affected": {
        "vendors": [
          "oras-project"
        ],
        "products": [
          {
            "vendor": "oras-project",
            "product": "oras-go"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27132
      },
      "nvd": {
        "published": "2026-07-17T20:17:23.943",
        "lastModified": "2026-07-23T18:02:00.793",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50163",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The hardlink validator checks a target against the extraction root but returns an unresolved relative name that os.Link resolves against the process working directory.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/oras-project/oras-go/security/advisories/GHSA-fxhp-mv3v-67qp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/oras-project/oras-go/pull/1232",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/oras-project/oras-go/commit/c463c654ab3ef34422c1764cd619806cebf20451",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/oras-project/oras-go/releases/tag/v2.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 643,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50179",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T22:05:13.644Z",
      "date_published": "2026-07-07T20:58:16.074Z",
      "date_updated": "2026-07-09T14:42:17.117Z",
      "publisher": "GitHub_M",
      "title": "Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields",
      "affected": {
        "vendors": [
          "actualbudget"
        ],
        "products": [
          {
            "vendor": "actualbudget",
            "product": "actual"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1236",
          "name": "Improper Neutralization of Formula Elements in a CSV File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07087
      },
      "nvd": {
        "published": "2026-07-07T22:16:52.923",
        "lastModified": "2026-07-09T16:16:42.473",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50179",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CSV export writes formula-leading user fields verbatim, causing spreadsheet applications to interpret transaction data as formulas.",
        "basis": [
          "CNA",
          "CWE-1236"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/actualbudget/actual/security/advisories/GHSA-xqjm-27pc-rvwm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/commit/068185751c03b42e726e3c60b718413d5f96c306",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/actualbudget/actual/releases/tag/v26.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 680,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50180",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T22:05:13.644Z",
      "date_published": "2026-07-09T23:42:52.853Z",
      "date_updated": "2026-07-10T20:59:17.652Z",
      "publisher": "GitHub_M",
      "title": "Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read",
      "affected": {
        "vendors": [
          "langroid"
        ],
        "products": [
          {
            "vendor": "langroid",
            "product": "langroid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00568,
        "percentile": 0.43858
      },
      "nvd": {
        "published": "2026-07-10T00:16:33.197",
        "lastModified": "2026-07-10T21:16:54.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50180",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SQL safety gate uses a function-name blocklist that omits PostgreSQL file-reading functions, so dangerous SELECT statements reach the database engine.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/langroid/langroid/security/advisories/GHSA-pmch-g965-grmr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/langroid/langroid/commit/00b7dd7b79c5d03c94be284cf3459d98195ebfba",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1243,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50181",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T22:05:13.644Z",
      "date_published": "2026-07-09T23:44:46.559Z",
      "date_updated": "2026-07-14T01:25:33.853Z",
      "publisher": "GitHub_M",
      "title": "Langroid: Path traversal in the file tools allows read/write outside configured current directory",
      "affected": {
        "vendors": [
          "langroid"
        ],
        "products": [
          {
            "vendor": "langroid",
            "product": "langroid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14382
      },
      "nvd": {
        "published": "2026-07-10T00:16:33.340",
        "lastModified": "2026-07-14T02:16:55.357",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50181",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "langroid accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/langroid/langroid/security/advisories/GHSA-fg23-3346-88f5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/langroid/langroid/commit/56e2756ecab70a70a7e6edbee2f2187b8484683e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 920,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50182",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T22:05:13.644Z",
      "date_published": "2026-07-15T21:04:26.203Z",
      "date_updated": "2026-07-17T12:34:49.289Z",
      "publisher": "GitHub_M",
      "title": "AVideo Has Unauthenticated Reflected XSS via $_GET['search'] in YouTubeAPI Gallery Pagination",
      "affected": {
        "vendors": [
          "WWBN"
        ],
        "products": [
          {
            "vendor": "WWBN",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07534
      },
      "nvd": {
        "published": "2026-07-15T22:16:54.507",
        "lastModified": "2026-07-17T13:18:56.360",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50182",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The search parameter is concatenated into link attributes without encoding and later executes through the page's inline-script assembly.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-hgjh-6wj8-gcgf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/WWBN/AVideo/commit/f50fc033b7adb36f1ffd6640e7826468bdafdec3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1167,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T22:05:13.644Z",
      "date_published": "2026-07-15T21:13:06.995Z",
      "date_updated": "2026-07-16T12:50:47.083Z",
      "publisher": "GitHub_M",
      "title": "WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section",
      "affected": {
        "vendors": [
          "WWBN"
        ],
        "products": [
          {
            "vendor": "WWBN",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05848
      },
      "nvd": {
        "published": "2026-07-15T22:16:54.643",
        "lastModified": "2026-07-16T14:16:52.617",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50183",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A YouTube title is rendered without sufficient browser-context escaping and can execute as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-66q5-cj5g-wrfx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/WWBN/AVideo/commit/7292129eaee5f609beae103b5cb387d55f17b877",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1279,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50185",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T22:05:13.644Z",
      "date_published": "2026-07-17T18:35:02.078Z",
      "date_updated": "2026-07-20T19:24:54.587Z",
      "publisher": "GitHub_M",
      "title": "RustCrypto Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set",
      "affected": {
        "vendors": [
          "RustCrypto"
        ],
        "products": [
          {
            "vendor": "RustCrypto",
            "product": "utils"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-758",
          "name": "Reliance on Undefined, Unspecified, or Implementation-Defined Behavior",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.0157
      },
      "nvd": {
        "published": "2026-07-17T19:17:16.370",
        "lastModified": "2026-07-23T16:18:40.543",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50185",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The aarch64 conditional-move implementation assumes high register bits are zero-extended and computes incorrect results when they are set.",
        "basis": [
          "CNA record",
          "CWE-758"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/RustCrypto/utils/security/advisories/GHSA-3rjw-m598-pq24",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/RustCrypto/utils/commit/dba6c355c9f241e3726d5ec2a68f9f3b519f6063",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/RustCrypto/utils/releases/tag/cmov-v0.5.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T22:05:13.645Z",
      "date_published": "2026-07-09T18:44:56.901Z",
      "date_updated": "2026-07-09T19:20:56.407Z",
      "publisher": "GitHub_M",
      "title": "Kirby: Request header injection in `Http\\Remote`",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-113",
          "name": "Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21278
      },
      "nvd": {
        "published": "2026-07-09T19:17:05.827",
        "lastModified": "2026-07-10T15:49:19.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50188",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "kirby accepts CRLF bytes that terminate the intended field and inject an additional protocol field.",
        "basis": [
          "CNA",
          "CWE-93",
          "CWE-113"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-4v4h-m2qq-ppgw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/aa33414e1669e866cdd6f4decfae2a669e8bb828",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/fad9cbd22c73ed0fbd3aaf62310a8dcacfc007cd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/4.9.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 440,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-50195",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T22:05:13.645Z",
      "date_published": "2026-07-01T17:50:53.072Z",
      "date_updated": "2026-07-01T18:32:29.659Z",
      "publisher": "GitHub_M",
      "title": "containerd: CRI checkpoint import allows local image tag poisoning",
      "affected": {
        "vendors": [
          "containerd"
        ],
        "products": [
          {
            "vendor": "containerd",
            "product": "containerd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 4.300000000000001,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25812
      },
      "nvd": {
        "published": "2026-07-01T19:16:53.333",
        "lastModified": "2026-07-02T19:43:59.417",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50195",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Checkpoint import accepts unvalidated image references and assigns attacker-selected tags, poisoning the node's trusted local image cache.",
        "basis": [
          "CNA",
          "CWE-345",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/containerd/containerd/security/advisories/GHSA-cvxm-645q-p574",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 870,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-50197",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-03T22:05:13.645Z",
      "date_published": "2026-07-17T19:23:43.574Z",
      "date_updated": "2026-07-20T14:33:29.442Z",
      "publisher": "GitHub_M",
      "title": "Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding: chunked / HTTP/2 requests",
      "affected": {
        "vendors": [
          "zalando"
        ],
        "products": [
          {
            "vendor": "zalando",
            "product": "skipper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00429,
        "percentile": 0.35315
      },
      "nvd": {
        "published": "2026-07-17T20:17:24.087",
        "lastModified": "2026-07-23T18:02:00.793",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50197",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Skipper presents an empty body to OPA for chunked or HTTP/2 requests while forwarding the full body upstream, so policy and origin interpret different requests.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zalando/skipper/security/advisories/GHSA-659f-rgp5-w4wf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zalando/skipper/pull/4041",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zalando/skipper/commit/3152f3b0bb52ca89c3564be42434db0a2a1cea23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zalando/skipper/releases/tag/v0.26.10",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:27:22.796Z",
      "date_published": "2026-07-22T13:08:21.443Z",
      "date_updated": "2026-07-22T18:58:00.043Z",
      "publisher": "NLnet Labs",
      "title": "'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-348",
          "name": "Use of Less Trusted Source",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01347
      },
      "nvd": {
        "published": "2026-07-22T14:17:20.240",
        "lastModified": "2026-07-24T13:59:07.013",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50243",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A response-rewrite path treats a DNS answer with failed validation as usable input and replaces its security status with an insecure result.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-348"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50243.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 960,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50248",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T10:11:10.539Z",
      "date_published": "2026-07-22T13:08:32.488Z",
      "date_updated": "2026-07-22T18:58:20.160Z",
      "publisher": "NLnet Labs",
      "title": "BOGUS configured primary hostname accepted for XFR in auth/rpz zones",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02835
      },
      "nvd": {
        "published": "2026-07-22T14:17:20.370",
        "lastModified": "2026-07-24T13:59:37.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50248",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unbound accepts a primary hostname whose A or AAAA result is DNSSEC BOGUS as an XFR endpoint, allowing a spoofed address to replace the zone source.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50248.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:27:22.791Z",
      "date_published": "2026-07-22T13:08:43.577Z",
      "date_updated": "2026-07-22T14:34:49.620Z",
      "publisher": "NLnet Labs",
      "title": "Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16852
      },
      "nvd": {
        "published": "2026-07-22T14:17:20.503",
        "lastModified": "2026-07-24T14:05:26.497",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50251",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A zero-address glue record exits Unbound's unwanted-reply accounting path before incrementing the threshold counter, allowing repeated replies to trigger avoidable cache flushes.",
        "basis": [
          "CNA",
          "CWE-184"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50251.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1217,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:35:21.348Z",
      "date_published": "2026-07-22T13:08:54.981Z",
      "date_updated": "2026-07-22T14:18:36.928Z",
      "publisher": "NLnet Labs",
      "title": "Possible cache poisoning attack by mapping source port population per thread",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-349",
          "name": "Acceptance of Extraneous Untrusted Data With Trusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:H/E:P/U:Amber"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 3.6000000000000005,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03904
      },
      "nvd": {
        "published": "2026-07-22T14:17:20.627",
        "lastModified": "2026-07-24T14:05:44.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50252",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Per-thread source-port partitioning reduces the effective entropy of DNS query identifiers and makes responses easier to predict.",
        "basis": [
          "CNA",
          "CWE-349"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50252.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1709,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50271",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T16:26:05.984Z",
      "date_published": "2026-07-17T20:42:34.036Z",
      "date_updated": "2026-07-20T19:16:57.759Z",
      "publisher": "GitHub_M",
      "title": "dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS",
      "affected": {
        "vendors": [
          "DataDog"
        ],
        "products": [
          {
            "vendor": "DataDog",
            "product": "dd-trace-py"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36276
      },
      "nvd": {
        "published": "2026-07-17T21:17:07.070",
        "lastModified": "2026-07-23T18:06:16.760",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50271",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The dd-trace-py request path allocates work or memory from attacker-controlled input without an effective item or byte limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/DataDog/dd-trace-py/security/advisories/GHSA-mw54-j2v2-42hr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/DataDog/dd-trace-py/pull/17926",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/DataDog/dd-trace-py/commit/9c80faa3dcfe238d008c3b3cd0b8e5dfef0aa4cd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/DataDog/dd-trace-py/releases/tag/v4.8.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 629,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50272",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T16:26:05.984Z",
      "date_published": "2026-07-17T20:28:21.250Z",
      "date_updated": "2026-07-21T02:19:01.666Z",
      "publisher": "GitHub_M",
      "title": "dd-trace: Improper parsing of W3C baggage headers may lead to DoS",
      "affected": {
        "vendors": [
          "DataDog"
        ],
        "products": [
          {
            "vendor": "DataDog",
            "product": "dd-trace-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36276
      },
      "nvd": {
        "published": "2026-07-17T21:17:07.200",
        "lastModified": "2026-07-23T18:06:16.760",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50272",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "dd-trace accepts baggage headers without an effective bound on allocated parsing resources.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/DataDog/dd-trace-js/security/advisories/GHSA-wxqq-gcq8-c443",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/DataDog/dd-trace-js/pull/8255",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/DataDog/dd-trace-js/commit/a7d4c0da05f67cde05a99272b725a317c461d0e6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/DataDog/dd-trace-js/releases/tag/v5.100.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 676,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50273",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T16:26:05.984Z",
      "date_published": "2026-07-17T18:01:14.533Z",
      "date_updated": "2026-07-17T19:46:45.397Z",
      "publisher": "GitHub_M",
      "title": "Datadog .NET Tracer: Improper parsing of W3C baggage headers may lead to DoS",
      "affected": {
        "vendors": [
          "DataDog"
        ],
        "products": [
          {
            "vendor": "DataDog",
            "product": "dd-trace-dotnet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00482,
        "percentile": 0.39011
      },
      "nvd": {
        "published": "2026-07-17T18:17:16.840",
        "lastModified": "2026-07-17T20:17:24.220",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50273",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on extraction, allowing a remote unauthenticated attacker to send a baggage header with many comma-separated key-value pairs or one very large value and cause unbounded CPU and memory consumption in services with baggage propagation enabled.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/DataDog/dd-trace-dotnet/security/advisories/GHSA-38wr-vpc7-2mp4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/DataDog/dd-trace-dotnet/pull/8555",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/DataDog/dd-trace-dotnet/commit/38092e0d41a36decbe649e048e48ae1b1607292f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/DataDog/dd-trace-dotnet/releases/tag/v3.43.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50274",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T16:26:05.984Z",
      "date_published": "2026-07-17T20:41:27.675Z",
      "date_updated": "2026-07-20T15:04:14.809Z",
      "publisher": "GitHub_M",
      "title": "dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS",
      "affected": {
        "vendors": [
          "DataDog"
        ],
        "products": [
          {
            "vendor": "DataDog",
            "product": "dd-trace-go"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36276
      },
      "nvd": {
        "published": "2026-07-17T21:17:07.337",
        "lastModified": "2026-07-23T18:02:09.653",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50274",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 2.8.1, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES limits on the extract path.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/DataDog/dd-trace-go/security/advisories/GHSA-74j5-xf3v-crq8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/DataDog/dd-trace-go/pull/4720",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/DataDog/dd-trace-go/commit/192712ba0291b2e89166259111ebb5e90c8f52df",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/DataDog/dd-trace-go/releases/tag/v2.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 702,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50279",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T16:26:05.985Z",
      "date_published": "2026-07-01T23:31:31.101Z",
      "date_updated": "2026-07-02T12:27:42.242Z",
      "publisher": "GitHub_M",
      "title": "Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap",
      "affected": {
        "vendors": [
          "craftcms"
        ],
        "products": [
          {
            "vendor": "craftcms",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15848
      },
      "nvd": {
        "published": "2026-07-02T00:16:44.543",
        "lastModified": "2026-07-02T15:11:16.363",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50279",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Craft checks entry-edit authority before applying an attacker-selected author list and does not reauthorize the resulting authorship change.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craftcms/cms/security/advisories/GHSA-qq2c-2q8j-jh27",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/commit/9cc493be8b414d7116c7f2bc2a6d0926e73f1248",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 700,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50280",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T16:26:05.985Z",
      "date_published": "2026-07-01T23:43:49.095Z",
      "date_updated": "2026-07-02T15:39:22.626Z",
      "publisher": "GitHub_M",
      "title": "Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check",
      "affected": {
        "vendors": [
          "craftcms"
        ],
        "products": [
          {
            "vendor": "craftcms",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.194
      },
      "nvd": {
        "published": "2026-07-02T00:16:44.677",
        "lastModified": "2026-07-02T16:16:30.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50280",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Craft CMS checks only viewEntries on the destination section before actionMoveToSection() saves an entry there, omitting the required saveEntries permission.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craftcms/cms/security/advisories/GHSA-43cq-c2gq-pfpw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/commit/0a6b916f6367b0162b2eaf2366add67b45fa98ea",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 847,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50281",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T16:26:05.985Z",
      "date_published": "2026-07-02T16:02:14.029Z",
      "date_updated": "2026-07-02T19:44:23.581Z",
      "publisher": "GitHub_M",
      "title": "Craft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elements",
      "affected": {
        "vendors": [
          "craftcms"
        ],
        "products": [
          {
            "vendor": "craftcms",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16814
      },
      "nvd": {
        "published": "2026-07-02T17:17:00.000",
        "lastModified": "2026-07-02T20:17:03.500",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50281",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Bulk duplicate accepts id inside newAttributes after the top-level ID guard, allowing mass assignment to turn an intended insert into an update of another entry.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craftcms/cms/security/advisories/GHSA-x5m4-g2cq-52pq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/commit/8f6587c25050bbb6e080d59c71f6bb8932fc8600",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1288,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50282",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T16:26:05.985Z",
      "date_published": "2026-07-02T16:15:25.823Z",
      "date_updated": "2026-07-02T18:01:27.543Z",
      "publisher": "GitHub_M",
      "title": "Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves",
      "affected": {
        "vendors": [
          "craftcms"
        ],
        "products": [
          {
            "vendor": "craftcms",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10935
      },
      "nvd": {
        "published": "2026-07-02T17:17:01.070",
        "lastModified": "2026-07-02T19:16:59.887",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50282",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Craft CMS force-move can delete a conflicting destination folder without checking the caller's delete permission on that destination.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craftcms/cms/security/advisories/GHSA-3w32-23wj-rxg3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 614,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-50283",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T16:26:05.985Z",
      "date_published": "2026-07-01T22:20:01.949Z",
      "date_updated": "2026-07-02T14:47:28.384Z",
      "publisher": "GitHub_M",
      "title": "Craft CMS: Unauthorized Deletion of Source Assets During File Replacement",
      "affected": {
        "vendors": [
          "craftcms"
        ],
        "products": [
          {
            "vendor": "craftcms",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.1827
      },
      "nvd": {
        "published": "2026-07-01T23:16:52.207",
        "lastModified": "2026-07-02T15:17:02.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50283",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The replace-file action checks permissions on the target asset only and deletes the separate source asset without checking delete permission on its volume.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craftcms/cms/security/advisories/GHSA-qh45-9g5p-m2v4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/commit/2c2579c7f1030872423f268d0c8b48377101961d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1166,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-50284",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T16:26:05.985Z",
      "date_published": "2026-07-01T22:37:30.334Z",
      "date_updated": "2026-07-02T12:46:04.509Z",
      "publisher": "GitHub_M",
      "title": "Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets",
      "affected": {
        "vendors": [
          "craftcms"
        ],
        "products": [
          {
            "vendor": "craftcms",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16351
      },
      "nvd": {
        "published": "2026-07-01T23:16:52.350",
        "lastModified": "2026-07-02T15:11:16.363",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50284",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The folder-deletion endpoint checks deleteAssets but omits deletePeerAssets before recursively deleting other users' descendant assets.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craftcms/cms/security/advisories/GHSA-7h62-6v23-v8fm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/commit/b4e08977f0c9bdf002a77f9f6d1346cd55ac0598",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 765,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-50289",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T16:26:05.986Z",
      "date_published": "2026-07-17T19:42:41.417Z",
      "date_updated": "2026-07-20T16:22:33.661Z",
      "publisher": "GitHub_M",
      "title": "systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux",
      "affected": {
        "vendors": [
          "sebhildebrandt"
        ],
        "products": [
          {
            "vendor": "sebhildebrandt",
            "product": "systeminformation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.01873,
        "percentile": 0.77312
      },
      "nvd": {
        "published": "2026-07-17T20:17:24.857",
        "lastModified": "2026-07-29T15:46:42.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50289",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A path read from the interfaces source directive is interpolated unquoted into a shell command executed by networkInterfaces.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-5xpp-75jx-m839",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/sebhildebrandt/systeminformation/commit/bbfddde48672d0ee124fefdb3cb4442fd9dd4f03",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sebhildebrandt/systeminformation/releases/tag/v5.31.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 672,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50293",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.974Z",
      "date_published": "2026-07-14T17:06:10.859Z",
      "date_updated": "2026-08-03T22:54:32.777Z",
      "publisher": "microsoft",
      "title": "Windows Internal Task Bar Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17307
      },
      "nvd": {
        "published": "2026-07-14T17:16:57.570",
        "lastModified": "2026-07-23T05:16:32.833",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50293",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 21H2 path can dereference an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50293",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-50294",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.974Z",
      "date_published": "2026-07-14T17:06:02.916Z",
      "date_updated": "2026-08-03T22:54:24.920Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00374,
        "percentile": 0.30113
      },
      "nvd": {
        "published": "2026-07-14T17:16:57.697",
        "lastModified": "2026-07-22T16:17:35.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50294",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows kernel exposes sensitive system information to a local caller outside its authorized control sphere.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50294",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 157,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50295",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.974Z",
      "date_published": "2026-07-14T17:06:15.061Z",
      "date_updated": "2026-08-03T22:54:37.161Z",
      "publisher": "microsoft",
      "title": "Windows Zero Trust DNS Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12224
      },
      "nvd": {
        "published": "2026-07-14T17:16:57.870",
        "lastModified": "2026-07-22T16:17:35.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50295",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Windows 11 Version 24H2 permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50295",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50296",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.974Z",
      "date_published": "2026-07-14T17:06:12.511Z",
      "date_updated": "2026-08-03T22:54:34.272Z",
      "publisher": "microsoft",
      "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09922
      },
      "nvd": {
        "published": "2026-07-14T17:16:57.987",
        "lastModified": "2026-07-22T16:17:35.890",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50296",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 retains or reuses an object after its storage has been freed, allowing later processing to access invalid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50296",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50297",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.974Z",
      "date_published": "2026-07-14T17:06:12.980Z",
      "date_updated": "2026-08-03T22:54:34.919Z",
      "publisher": "microsoft",
      "title": "Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11753
      },
      "nvd": {
        "published": "2026-07-14T17:16:58.137",
        "lastModified": "2026-07-22T16:17:36.053",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50297",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Win32k grants a local authorized caller authority beyond its assigned privilege, while Microsoft does not publish the object or failing access check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50297",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50298",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.974Z",
      "date_published": "2026-07-14T17:06:09.636Z",
      "date_updated": "2026-08-03T22:54:31.601Z",
      "publisher": "microsoft",
      "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25191
      },
      "nvd": {
        "published": "2026-07-14T17:16:58.303",
        "lastModified": "2026-07-22T16:17:36.233",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50298",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 performs unchecked integer arithmetic that wraps and produces an invalid allocation size, offset, or length.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50298",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 133,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50299",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.974Z",
      "date_published": "2026-07-14T17:05:59.041Z",
      "date_updated": "2026-08-03T22:54:21.674Z",
      "publisher": "microsoft",
      "title": "Windows Storage Spaces Direct Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.2519
      },
      "nvd": {
        "published": "2026-07-14T17:16:58.477",
        "lastModified": "2026-07-22T16:17:36.420",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50299",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer wraparound in Storage Spaces Direct produces an incorrect heap size and permits memory corruption.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50299",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 135,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-50300",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.974Z",
      "date_published": "2026-07-14T17:06:16.865Z",
      "date_updated": "2026-08-03T22:54:38.807Z",
      "publisher": "microsoft",
      "title": "Windows DWM Core Library Information Disclosure  Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22142
      },
      "nvd": {
        "published": "2026-07-14T17:16:58.640",
        "lastModified": "2026-07-22T16:17:36.597",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50300",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows kernel integer arithmetic underflows and leads to an out-of-bounds read.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50300",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50301",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:08:29.665Z",
      "date_updated": "2026-08-03T22:56:49.320Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22631
      },
      "nvd": {
        "published": "2026-07-14T18:17:27.880",
        "lastModified": "2026-07-16T19:43:45.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50301",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Office copies attacker-controlled content beyond a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50301",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50302",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:06:18.717Z",
      "date_updated": "2026-08-03T22:54:40.425Z",
      "publisher": "microsoft",
      "title": "Windows Cryptographic Services Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14701
      },
      "nvd": {
        "published": "2026-07-14T18:17:28.010",
        "lastModified": "2026-07-22T16:17:36.827",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50302",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50302",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50303",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:06:17.490Z",
      "date_updated": "2026-08-03T22:54:39.273Z",
      "publisher": "microsoft",
      "title": "Windows Key Guard Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1240",
          "name": "Use of a Cryptographic Primitive with a Risky Implementation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10328
      },
      "nvd": {
        "published": "2026-07-14T17:16:58.790",
        "lastModified": "2026-07-22T16:17:36.963",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50303",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft identifies a risky cryptographic implementation in Key Guard but does not disclose the primitive or misuse.",
        "basis": [
          "CNA",
          "CWE-1240"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50303",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50304",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:06:22.847Z",
      "date_updated": "2026-08-03T22:54:44.366Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 19,
        "versionEntryCount": 19,
        "versionRangeCount": 19,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01074,
        "percentile": 0.61681
      },
      "nvd": {
        "published": "2026-07-14T18:17:28.220",
        "lastModified": "2026-07-22T16:17:37.117",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50304",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler copies attacker-controlled data beyond a fixed-size stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50304",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 19,
        "affectedVersionEntryCount": 19
      }
    },
    {
      "cve_id": "CVE-2026-50305",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:06:20.436Z",
      "date_updated": "2026-08-03T22:54:42.182Z",
      "publisher": "microsoft",
      "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08201
      },
      "nvd": {
        "published": "2026-07-14T18:17:28.377",
        "lastModified": "2026-07-22T16:17:37.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50305",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A race in the Brokering File System permits one path to free an object while another path still uses it during local privilege-sensitive work.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50305",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 110,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50306",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:06:24.052Z",
      "date_updated": "2026-08-03T22:54:45.520Z",
      "publisher": "microsoft",
      "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15135
      },
      "nvd": {
        "published": "2026-07-14T18:17:28.497",
        "lastModified": "2026-07-22T16:17:37.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50306",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows TCP/IP can release an object while a reachable path still retains and later dereferences it.",
        "basis": [
          "CNA",
          "CWE-190",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50306",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50307",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:06:29.696Z",
      "date_updated": "2026-08-03T22:54:51.185Z",
      "publisher": "microsoft",
      "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.002,
        "percentile": 0.10106
      },
      "nvd": {
        "published": "2026-07-14T18:17:28.690",
        "lastModified": "2026-07-22T16:17:37.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50307",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1809 accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50307",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50308",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:06:01.220Z",
      "date_updated": "2026-08-03T22:54:23.341Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28689
      },
      "nvd": {
        "published": "2026-07-14T17:16:58.927",
        "lastModified": "2026-07-22T16:17:37.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50308",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NTFS integer arithmetic can underflow and wrap into an invalid memory size or offset.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50308",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 111,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:06:27.958Z",
      "date_updated": "2026-08-03T22:54:49.572Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15135
      },
      "nvd": {
        "published": "2026-07-14T18:17:29.013",
        "lastModified": "2026-07-22T16:17:37.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50309",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can write beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50309",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50310",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:06:41.908Z",
      "date_updated": "2026-08-03T22:55:01.086Z",
      "publisher": "microsoft",
      "title": "Windows Human Interface Device Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22064
      },
      "nvd": {
        "published": "2026-07-14T18:17:29.190",
        "lastModified": "2026-07-22T16:17:38.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50310",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An integer calculation in Windows Human Interface Device handling wraps and produces an invalid memory extent.",
        "basis": [
          "CNA record",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50310",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50311",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:06:01.891Z",
      "date_updated": "2026-08-03T22:54:23.889Z",
      "publisher": "microsoft",
      "title": "Windows Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15444
      },
      "nvd": {
        "published": "2026-07-14T17:16:59.090",
        "lastModified": "2026-07-22T16:17:38.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50311",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Windows 10 Version 1607 permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50311",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50312",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:06:43.077Z",
      "date_updated": "2026-08-03T22:55:02.037Z",
      "publisher": "microsoft",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25175
      },
      "nvd": {
        "published": "2026-07-14T18:17:29.503",
        "lastModified": "2026-07-22T16:17:38.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50312",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WinSock ancillary driver accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50312",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50313",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:06:30.811Z",
      "date_updated": "2026-08-03T22:54:52.320Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00435,
        "percentile": 0.35778
      },
      "nvd": {
        "published": "2026-07-14T18:17:29.680",
        "lastModified": "2026-07-22T16:17:38.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50313",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 10 Version 1607, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50313",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50314",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.975Z",
      "date_published": "2026-07-14T17:08:30.148Z",
      "date_updated": "2026-08-03T22:56:49.789Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00437,
        "percentile": 0.35942
      },
      "nvd": {
        "published": "2026-07-14T18:17:29.863",
        "lastModified": "2026-07-16T19:48:31.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50314",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path can retain or dereference an object after its storage has been released, leaving a dangling reference.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50314",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 91,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50315",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.976Z",
      "date_published": "2026-07-14T17:06:39.139Z",
      "date_updated": "2026-08-03T22:54:58.853Z",
      "publisher": "microsoft",
      "title": "Windows Image Acquisition Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23439
      },
      "nvd": {
        "published": "2026-07-14T18:17:30.003",
        "lastModified": "2026-07-23T05:16:32.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50315",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Image Acquisition dereferences a null pointer on a local authorized path and exposes a privilege-escalation condition.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50315",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50316",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.976Z",
      "date_published": "2026-07-14T17:06:11.403Z",
      "date_updated": "2026-08-03T22:54:33.254Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28061
      },
      "nvd": {
        "published": "2026-07-14T17:16:59.260",
        "lastModified": "2026-07-22T16:17:39.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50316",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 21H2 execution path writes secrets into records or logs readable by users who are not entitled to those secret values.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50316",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 129,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50317",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.976Z",
      "date_published": "2026-07-14T17:06:49.775Z",
      "date_updated": "2026-08-03T22:55:08.972Z",
      "publisher": "microsoft",
      "title": "Windows Operating Systems Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00199,
        "percentile": 0.0994
      },
      "nvd": {
        "published": "2026-07-14T18:17:30.690",
        "lastModified": "2026-07-23T05:16:33.093",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50317",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A race permits one thread to free an object while another thread still uses it.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50317",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50318",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T17:30:16.976Z",
      "date_published": "2026-07-14T17:06:07.295Z",
      "date_updated": "2026-08-03T22:54:29.562Z",
      "publisher": "microsoft",
      "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17306
      },
      "nvd": {
        "published": "2026-07-14T17:16:59.410",
        "lastModified": "2026-07-16T14:38:26.033",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50318",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 parser or handler can copy attacker-controlled data beyond the bounds of a stack allocation.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50318",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50321",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.951Z",
      "date_published": "2026-07-14T17:06:37.931Z",
      "date_updated": "2026-08-03T22:54:57.729Z",
      "publisher": "microsoft",
      "title": "Windows USB Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05048
      },
      "nvd": {
        "published": "2026-07-14T18:17:30.903",
        "lastModified": "2026-07-22T16:17:39.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50321",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A USB teardown race frees an object while another execution path can still dereference it.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50321",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 174,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50322",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.951Z",
      "date_published": "2026-07-14T17:06:47.626Z",
      "date_updated": "2026-08-03T22:55:06.620Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08703
      },
      "nvd": {
        "published": "2026-07-14T18:17:31.090",
        "lastModified": "2026-07-22T16:17:39.663",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50322",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an unsafe state transition in Windows 11 Version 24H2, while the stale or reordered state and enforcing check are not public.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50322",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50323",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.951Z",
      "date_published": "2026-07-14T17:06:06.821Z",
      "date_updated": "2026-08-03T22:54:28.942Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11771
      },
      "nvd": {
        "published": "2026-07-14T17:16:59.573",
        "lastModified": "2026-07-22T16:17:39.797",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50323",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Runtime accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50323",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50324",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.951Z",
      "date_published": "2026-07-14T17:06:42.480Z",
      "date_updated": "2026-08-03T22:55:01.568Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 17,
        "versionEntryCount": 17,
        "versionRangeCount": 17,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00782,
        "percentile": 0.5245
      },
      "nvd": {
        "published": "2026-07-14T18:17:31.277",
        "lastModified": "2026-07-22T16:17:39.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50324",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation lets attacker-controlled work or allocation grow without an effective per-request bound or termination condition.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50324",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 166,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 17,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-50325",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.951Z",
      "date_published": "2026-07-14T17:06:13.450Z",
      "date_updated": "2026-08-03T22:54:35.413Z",
      "publisher": "microsoft",
      "title": "Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11753
      },
      "nvd": {
        "published": "2026-07-14T17:16:59.697",
        "lastModified": "2026-07-22T16:17:40.137",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50325",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft identifies an access-control failure in Win32K that permits local privilege escalation, while the public record does not disclose the protected object or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50325",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50326",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.951Z",
      "date_published": "2026-07-14T17:06:30.245Z",
      "date_updated": "2026-08-03T22:54:51.737Z",
      "publisher": "microsoft",
      "title": "Windows Unified Consent System Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23438
      },
      "nvd": {
        "published": "2026-07-14T18:17:31.527",
        "lastModified": "2026-07-23T05:16:33.213",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50326",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A reachable path retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50326",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-50327",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.951Z",
      "date_published": "2026-07-14T17:06:32.455Z",
      "date_updated": "2026-08-03T22:54:53.904Z",
      "publisher": "microsoft",
      "title": "Windows Media Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27369
      },
      "nvd": {
        "published": "2026-07-14T18:17:31.657",
        "lastModified": "2026-07-22T16:17:40.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50327",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 11 Version 24H2 writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50327",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.951Z",
      "date_published": "2026-07-14T17:06:23.499Z",
      "date_updated": "2026-08-03T22:54:44.937Z",
      "publisher": "microsoft",
      "title": "Windows Server Update Service (WSUS) Tampering Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0118,
        "percentile": 0.64602
      },
      "nvd": {
        "published": "2026-07-14T18:17:31.783",
        "lastModified": "2026-07-20T17:00:48.883",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50328",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "WSUS leaves an exceptional input path uncaught, allowing a network caller to reach a state-changing failure.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50328",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-50329",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.951Z",
      "date_published": "2026-07-14T17:06:21.145Z",
      "date_updated": "2026-08-03T22:54:42.733Z",
      "publisher": "microsoft",
      "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0195,
        "percentile": 0.78237
      },
      "nvd": {
        "published": "2026-07-14T18:17:31.940",
        "lastModified": "2026-07-22T16:17:40.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50329",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows kernel accesses an object after its lifetime has ended, allowing a local authorized user to corrupt privileged kernel state.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50329",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50330",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:06:43.833Z",
      "date_updated": "2026-08-03T22:55:02.593Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Client Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 2.3000000000000007,
      "epss": {
        "score": 0.01115,
        "percentile": 0.62845
      },
      "nvd": {
        "published": "2026-07-14T18:17:32.087",
        "lastModified": "2026-07-22T16:17:40.833",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50330",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Remote Desktop Client writes past a heap allocation while processing unauthenticated network input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50330",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50331",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:06:34.470Z",
      "date_updated": "2026-08-03T22:54:54.935Z",
      "publisher": "microsoft",
      "title": "Windows Application Model Core API Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15138
      },
      "nvd": {
        "published": "2026-07-14T18:17:32.263",
        "lastModified": "2026-07-22T16:17:41.027",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50331",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 path can dereference an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50331",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50332",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:06:19.318Z",
      "date_updated": "2026-08-03T22:54:41.059Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-197",
          "name": "Numeric Truncation Error",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27412
      },
      "nvd": {
        "published": "2026-07-14T18:17:32.420",
        "lastModified": "2026-07-22T16:17:41.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50332",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A numeric truncation contributes to a heap buffer overflow in a privileged Windows kernel path.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-197"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50332",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50333",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:06:03.597Z",
      "date_updated": "2026-08-03T22:54:25.395Z",
      "publisher": "microsoft",
      "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11883
      },
      "nvd": {
        "published": "2026-07-14T17:16:59.860",
        "lastModified": "2026-07-23T05:16:33.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50333",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Spaceport driver exposes a critical privileged function without authenticating or authorizing the caller that invokes it.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50333",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50334",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:07:08.567Z",
      "date_updated": "2026-08-03T22:55:26.769Z",
      "publisher": "microsoft",
      "title": "Windows Push Notification Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28063
      },
      "nvd": {
        "published": "2026-07-14T18:17:32.743",
        "lastModified": "2026-07-22T16:17:41.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50334",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows 10 Version 1607 returns, logs, or renders sensitive state to a caller that has not passed the authorization or redaction boundary for that data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50334",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 145,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50335",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:06:48.115Z",
      "date_updated": "2026-08-03T22:55:07.253Z",
      "publisher": "microsoft",
      "title": "Windows Operating Systems Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19998
      },
      "nvd": {
        "published": "2026-07-14T18:17:32.923",
        "lastModified": "2026-07-23T05:16:33.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50335",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows grants a local authorized caller authority beyond its assigned privilege, while Microsoft does not publish the operation or failing access check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50335",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:06:58.003Z",
      "date_updated": "2026-08-03T22:55:16.408Z",
      "publisher": "microsoft",
      "title": "Windows Media Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23438
      },
      "nvd": {
        "published": "2026-07-14T18:17:33.073",
        "lastModified": "2026-07-22T16:17:41.893",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50336",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 11 Version 24H2 writes attacker-controlled data beyond a heap allocation because the copy or allocation size is not validated.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50336",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-50337",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:06:26.134Z",
      "date_updated": "2026-08-03T22:54:47.893Z",
      "publisher": "microsoft",
      "title": "Windows Notification Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-704",
          "name": "Incorrect Type Conversion or Cast",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23439
      },
      "nvd": {
        "published": "2026-07-14T18:17:33.200",
        "lastModified": "2026-07-22T16:17:42.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50337",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Windows Notification uses an incorrect type conversion and subsequently accesses data through the wrong representation.",
        "basis": [
          "CNA",
          "CWE-704"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50337",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 118,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50338",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:05:02.743Z",
      "date_updated": "2026-08-03T22:53:23.339Z",
      "publisher": "microsoft",
      "title": "Azure Spring Apps Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure Spring Apps"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00468,
        "percentile": 0.38121
      },
      "nvd": {
        "published": "2026-07-14T17:17:00.020",
        "lastModified": "2026-07-24T13:35:51.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50338",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Azure Spring Apps authenticates an authorized network caller incorrectly and permits privilege elevation, but the exact identity check is not public.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50338",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50339",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:06:40.576Z",
      "date_updated": "2026-08-03T22:54:59.882Z",
      "publisher": "microsoft",
      "title": "Windows Push Notification Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28062
      },
      "nvd": {
        "published": "2026-07-14T18:17:33.470",
        "lastModified": "2026-07-22T16:17:42.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50339",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows Push Notifications exposes protected local information to an authorized caller, while the public record does not identify the data or output path.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50339",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 151,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50340",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:06:50.441Z",
      "date_updated": "2026-08-03T22:55:09.620Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00502,
        "percentile": 0.40186
      },
      "nvd": {
        "published": "2026-07-14T18:17:33.617",
        "lastModified": "2026-07-22T16:17:42.390",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50340",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50340",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50341",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:06:33.047Z",
      "date_updated": "2026-08-03T22:59:18.815Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22142
      },
      "nvd": {
        "published": "2026-07-14T18:17:33.740",
        "lastModified": "2026-07-20T17:04:01.933",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50341",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50341",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 95,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50342",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.952Z",
      "date_published": "2026-07-14T17:06:08.939Z",
      "date_updated": "2026-08-03T22:54:31.134Z",
      "publisher": "microsoft",
      "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11884
      },
      "nvd": {
        "published": "2026-07-14T17:17:00.140",
        "lastModified": "2026-07-23T05:16:33.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50342",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50342",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-50343",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.953Z",
      "date_published": "2026-07-14T17:06:35.076Z",
      "date_updated": "2026-08-03T22:54:55.485Z",
      "publisher": "microsoft",
      "title": "Microsoft Install Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.035,
        "percentile": 0.88007
      },
      "nvd": {
        "published": "2026-07-14T18:17:33.973",
        "lastModified": "2026-07-22T16:17:42.747",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50343",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The component assigns or permits a privilege beyond the authority granted to the invoking user.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50343",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50344",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.953Z",
      "date_published": "2026-07-14T17:07:09.669Z",
      "date_updated": "2026-08-03T22:55:27.792Z",
      "publisher": "microsoft",
      "title": "Windows OLE Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.2
      },
      "nvd": {
        "published": "2026-07-14T18:17:34.120",
        "lastModified": "2026-07-23T05:16:33.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50344",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50344",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50345",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.953Z",
      "date_published": "2026-07-14T17:06:47.065Z",
      "date_updated": "2026-08-03T22:55:06.062Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08702
      },
      "nvd": {
        "published": "2026-07-14T18:17:34.350",
        "lastModified": "2026-07-22T16:17:43.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50345",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 11 Version 24H2 accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50345",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50346",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:15:10.953Z",
      "date_published": "2026-07-14T17:07:05.323Z",
      "date_updated": "2026-08-03T22:55:23.587Z",
      "publisher": "microsoft",
      "title": "Netlogon RPC Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19999
      },
      "nvd": {
        "published": "2026-07-14T18:17:34.470",
        "lastModified": "2026-07-22T16:17:43.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50346",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "RPC Runtime grants a locally authorized caller an operation beyond its privilege, but the subject, object, and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50346",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50347",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.814Z",
      "date_published": "2026-07-14T17:06:37.155Z",
      "date_updated": "2026-08-03T22:54:57.185Z",
      "publisher": "microsoft",
      "title": "Windows Data.dll Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00435,
        "percentile": 0.35777
      },
      "nvd": {
        "published": "2026-07-14T18:17:34.627",
        "lastModified": "2026-07-22T16:17:43.390",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50347",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer arithmetic produces an invalid heap allocation size and permits a heap overflow.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50347",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.814Z",
      "date_published": "2026-07-14T17:06:46.504Z",
      "date_updated": "2026-08-03T22:55:05.508Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00336,
        "percentile": 0.26164
      },
      "nvd": {
        "published": "2026-07-14T18:17:34.783",
        "lastModified": "2026-07-22T16:17:43.577",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50348",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unsynchronized Windows Runtime operations race so one path can use an object after another path frees it.",
        "basis": [
          "CNA record",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50348",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50350",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.814Z",
      "date_published": "2026-07-14T17:06:15.706Z",
      "date_updated": "2026-08-03T22:54:37.708Z",
      "publisher": "microsoft",
      "title": "Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28064
      },
      "nvd": {
        "published": "2026-07-14T17:17:00.260",
        "lastModified": "2026-07-22T16:17:43.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50350",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Windows Trusted Runtime Interface Driver record states local information disclosure but does not disclose the data source, output path, or memory or authority failure.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50350",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 165,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-50351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.814Z",
      "date_published": "2026-07-14T17:06:07.758Z",
      "date_updated": "2026-08-03T22:54:30.108Z",
      "publisher": "microsoft",
      "title": "Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02797,
        "percentile": 0.85039
      },
      "nvd": {
        "published": "2026-07-14T17:17:00.390",
        "lastModified": "2026-07-23T05:16:34.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50351",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows ACM permits a local caller to cross a privilege boundary, but the failing access-control check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50351",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 127,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:07:10.185Z",
      "date_updated": "2026-08-03T22:55:28.341Z",
      "publisher": "microsoft",
      "title": "Windows Cryptographic Services Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00458,
        "percentile": 0.37497
      },
      "nvd": {
        "published": "2026-07-14T18:17:35.090",
        "lastModified": "2026-07-22T16:17:44.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50352",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows Cryptographic Services exposes protected local information, while Microsoft does not identify the output, buffer, or data-selection error.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50352",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 155,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:55.196Z",
      "date_updated": "2026-08-03T22:55:13.714Z",
      "publisher": "microsoft",
      "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23436
      },
      "nvd": {
        "published": "2026-07-14T18:17:35.267",
        "lastModified": "2026-07-22T16:17:44.237",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50353",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path can retain or dereference an object after its storage has been released, leaving a dangling reference.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50353",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50354",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:11.956Z",
      "date_updated": "2026-08-03T22:54:33.805Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15192
      },
      "nvd": {
        "published": "2026-07-14T17:17:00.563",
        "lastModified": "2026-07-22T16:17:44.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50354",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows kernel can access a freed object on a local authorized path, enabling privilege escalation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50354",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50355",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:53.291Z",
      "date_updated": "2026-08-03T22:55:12.153Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 19,
        "versionEntryCount": 19,
        "versionRangeCount": 19,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01074,
        "percentile": 0.61681
      },
      "nvd": {
        "published": "2026-07-14T18:17:35.490",
        "lastModified": "2026-07-24T14:16:19.867",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50355",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Microsoft .NET Framework 3.5 AND 4.7.2 path writes attacker-influenced data beyond the capacity of its destination buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50355",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 19,
        "affectedVersionEntryCount": 19
      }
    },
    {
      "cve_id": "CVE-2026-50356",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:14.020Z",
      "date_updated": "2026-08-03T22:54:36.045Z",
      "publisher": "microsoft",
      "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04941
      },
      "nvd": {
        "published": "2026-07-14T17:17:00.717",
        "lastModified": "2026-07-23T05:16:34.193",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50356",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent operations violate the required state ordering and allow access to stale or prematurely transitioned state.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50356",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50357",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:44.443Z",
      "date_updated": "2026-08-03T22:55:03.145Z",
      "publisher": "microsoft",
      "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-197",
          "name": "Numeric Truncation Error",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23441
      },
      "nvd": {
        "published": "2026-07-14T18:17:35.790",
        "lastModified": "2026-07-20T17:21:44.333",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50357",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 path performs integer conversion or arithmetic that can wrap, truncate, or change sign before a memory operation.",
        "basis": [
          "CNA",
          "CWE-197"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50357",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50358",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:52.659Z",
      "date_updated": "2026-08-03T22:55:11.520Z",
      "publisher": "microsoft",
      "title": "Windows Media Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17606
      },
      "nvd": {
        "published": "2026-07-14T18:17:35.963",
        "lastModified": "2026-07-22T16:17:45.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50358",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected Windows component accesses a freed object after its ownership lifetime ends.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50358",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 92,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:09:14.796Z",
      "date_updated": "2026-08-03T22:57:34.452Z",
      "publisher": "microsoft",
      "title": "Microsoft XML Core Services Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17606
      },
      "nvd": {
        "published": "2026-07-14T18:17:36.147",
        "lastModified": "2026-07-22T16:17:45.177",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50359",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Windows 10 Version 1607, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50359",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50360",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:24.527Z",
      "date_updated": "2026-08-03T22:54:46.146Z",
      "publisher": "microsoft",
      "title": "Windows SMB Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-303",
          "name": "Incorrect Implementation of Authentication Algorithm",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00526,
        "percentile": 0.41646
      },
      "nvd": {
        "published": "2026-07-14T18:17:36.323",
        "lastModified": "2026-07-23T05:16:34.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50360",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows SMB Server applies an authentication algorithm incorrectly before granting network privileges.",
        "basis": [
          "CNA",
          "CWE-303"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50360",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50361",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:49.209Z",
      "date_updated": "2026-08-03T22:55:08.426Z",
      "publisher": "microsoft",
      "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08201
      },
      "nvd": {
        "published": "2026-07-14T18:17:36.453",
        "lastModified": "2026-07-22T16:17:45.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50361",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path releases the same allocation twice.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50361",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50362",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:07:36.240Z",
      "date_updated": "2026-08-03T22:55:55.378Z",
      "publisher": "microsoft",
      "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26113
      },
      "nvd": {
        "published": "2026-07-14T18:17:36.580",
        "lastModified": "2026-07-20T15:10:59.107",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50362",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50362",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50363",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:21.798Z",
      "date_updated": "2026-08-03T22:54:43.239Z",
      "publisher": "microsoft",
      "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23439
      },
      "nvd": {
        "published": "2026-07-14T18:17:36.737",
        "lastModified": "2026-07-22T16:17:45.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50363",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data is written beyond the boundary of a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50363",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-50364",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:18.091Z",
      "date_updated": "2026-08-03T22:54:39.864Z",
      "publisher": "microsoft",
      "title": "Windows Backup Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26966
      },
      "nvd": {
        "published": "2026-07-14T17:17:00.897",
        "lastModified": "2026-07-22T16:17:45.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50364",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 21H2 follows an attacker-influenced link or pre-planted path without verifying the final filesystem object.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50364",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50365",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:07:14.479Z",
      "date_updated": "2026-08-03T22:55:33.853Z",
      "publisher": "microsoft",
      "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00459,
        "percentile": 0.37549
      },
      "nvd": {
        "published": "2026-07-14T18:17:37.010",
        "lastModified": "2026-07-23T05:16:34.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50365",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Windows RPC API accepts an adjacent network caller without proper authentication, but the exact RPC method and credential check are not public.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50365",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50366",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:51.549Z",
      "date_updated": "2026-08-03T22:55:10.894Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00755,
        "percentile": 0.51582
      },
      "nvd": {
        "published": "2026-07-14T18:17:37.187",
        "lastModified": "2026-07-22T16:17:46.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50366",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Active Directory Domain Services dereferences a null pointer while processing an authorized network request.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50366",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50367",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:07:19.156Z",
      "date_updated": "2026-08-03T22:55:40.734Z",
      "publisher": "microsoft",
      "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-118",
          "name": "Incorrect Access of Indexable Resource ('Range Error')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-822",
          "name": "Untrusted Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15133
      },
      "nvd": {
        "published": "2026-07-14T18:17:37.363",
        "lastModified": "2026-07-22T16:17:46.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50367",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Sensor Data Service dereferences an attacker-influenced pointer outside the trusted indexable object it is meant to address.",
        "basis": [
          "CNA",
          "CWE-822"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50367",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50368",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:29.120Z",
      "date_updated": "2026-08-03T22:54:50.619Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 19,
        "versionEntryCount": 19,
        "versionRangeCount": 19,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0078,
        "percentile": 0.52384
      },
      "nvd": {
        "published": "2026-07-14T18:17:37.523",
        "lastModified": "2026-07-24T14:14:03.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50368",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Microsoft .NET Framework 3.5 AND 4.7.2 path copies attacker-influenced data beyond a fixed-size stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50368",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 19,
        "affectedVersionEntryCount": 19
      }
    },
    {
      "cve_id": "CVE-2026-50369",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:07:12.902Z",
      "date_updated": "2026-08-03T22:55:31.251Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00682,
        "percentile": 0.48954
      },
      "nvd": {
        "published": "2026-07-14T18:17:37.673",
        "lastModified": "2026-07-22T16:17:46.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50369",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Remote Desktop Services accesses an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50369",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50370",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:36.491Z",
      "date_updated": "2026-08-03T22:54:56.559Z",
      "publisher": "microsoft",
      "title": "DHCP Server Service Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00494,
        "percentile": 0.39751
      },
      "nvd": {
        "published": "2026-07-14T18:17:37.850",
        "lastModified": "2026-07-20T14:52:20.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50370",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 10 Version 1607, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50370",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-50371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:57.505Z",
      "date_updated": "2026-08-03T22:55:15.865Z",
      "publisher": "microsoft",
      "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08702
      },
      "nvd": {
        "published": "2026-07-14T18:17:38.003",
        "lastModified": "2026-07-23T05:16:34.657",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50371",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 accesses shared state concurrently without the synchronization needed to keep the state transition atomic and consistent.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50371",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50372",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:48:26.815Z",
      "date_published": "2026-07-14T17:06:19.830Z",
      "date_updated": "2026-08-03T22:54:41.628Z",
      "publisher": "microsoft",
      "title": "Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15888
      },
      "nvd": {
        "published": "2026-07-14T18:17:38.180",
        "lastModified": "2026-07-22T16:17:47.103",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50372",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Redirected Drive Buffering reads beyond a heap buffer and exposes or uses bytes outside the valid allocation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50372",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50373",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.744Z",
      "date_published": "2026-07-14T17:06:54.567Z",
      "date_updated": "2026-08-03T22:55:13.166Z",
      "publisher": "microsoft",
      "title": "Windows Search Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19999
      },
      "nvd": {
        "published": "2026-07-14T18:17:38.360",
        "lastModified": "2026-07-22T16:17:47.297",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50373",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in Windows 10 Version 1809, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50373",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50374",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.744Z",
      "date_published": "2026-07-14T17:07:18.523Z",
      "date_updated": "2026-08-03T22:55:40.102Z",
      "publisher": "microsoft",
      "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24797
      },
      "nvd": {
        "published": "2026-07-14T18:17:38.507",
        "lastModified": "2026-07-20T14:41:16.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50374",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Cloud Files Mini Filter Driver accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50374",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50375",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.744Z",
      "date_published": "2026-07-14T17:06:48.670Z",
      "date_updated": "2026-08-03T22:55:07.803Z",
      "publisher": "microsoft",
      "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.01813,
        "percentile": 0.7653
      },
      "nvd": {
        "published": "2026-07-14T18:17:38.653",
        "lastModified": "2026-07-22T16:17:47.543",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50375",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The DirectX graphics kernel writes beyond a heap buffer during a local authorized operation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50375",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50376",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.744Z",
      "date_published": "2026-07-14T17:07:05.796Z",
      "date_updated": "2026-08-03T22:55:24.138Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00868,
        "percentile": 0.55232
      },
      "nvd": {
        "published": "2026-07-14T18:17:38.800",
        "lastModified": "2026-07-22T16:17:47.707",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50376",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows RDP returns or processes an uninitialized resource whose residual contents can be disclosed over the network.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50376",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.744Z",
      "date_published": "2026-07-14T17:06:44.918Z",
      "date_updated": "2026-08-03T22:55:03.783Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30894
      },
      "nvd": {
        "published": "2026-07-14T18:17:39.010",
        "lastModified": "2026-07-21T13:06:39.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50377",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50377",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.744Z",
      "date_published": "2026-07-14T17:07:04.215Z",
      "date_updated": "2026-08-03T22:55:22.533Z",
      "publisher": "microsoft",
      "title": "Windows Key Guard Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09939
      },
      "nvd": {
        "published": "2026-07-14T18:17:39.183",
        "lastModified": "2026-07-22T16:17:47.993",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50378",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50378",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 173,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50379",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.744Z",
      "date_published": "2026-07-14T17:06:59.740Z",
      "date_updated": "2026-08-03T22:55:17.828Z",
      "publisher": "microsoft",
      "title": "Windows Media Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00365,
        "percentile": 0.29204
      },
      "nvd": {
        "published": "2026-07-14T18:17:39.340",
        "lastModified": "2026-07-22T16:17:48.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50379",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected workflow fails to preserve its invariant across a state transition or concurrent operation.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50379",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-50380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.744Z",
      "date_published": "2026-07-14T17:06:31.826Z",
      "date_updated": "2026-08-03T22:54:53.278Z",
      "publisher": "microsoft",
      "title": "Windows GDI+ Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00625,
        "percentile": 0.46521
      },
      "nvd": {
        "published": "2026-07-14T18:17:39.483",
        "lastModified": "2026-07-22T16:17:48.280",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50380",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50380",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50381",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.744Z",
      "date_published": "2026-07-14T17:06:16.302Z",
      "date_updated": "2026-08-03T22:54:38.254Z",
      "publisher": "microsoft",
      "title": "Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20761
      },
      "nvd": {
        "published": "2026-07-14T17:17:01.027",
        "lastModified": "2026-07-22T16:17:48.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50381",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The program accesses a resource through an incompatible type and then applies invalid memory assumptions.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50381",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 162,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.744Z",
      "date_published": "2026-07-14T17:07:10.666Z",
      "date_updated": "2026-08-03T22:55:28.970Z",
      "publisher": "microsoft",
      "title": "DirectX Graphics Kernel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-822",
          "name": "Untrusted Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18903
      },
      "nvd": {
        "published": "2026-07-14T18:17:39.727",
        "lastModified": "2026-07-22T16:17:48.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50382",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1809 reads beyond a valid memory object because an input length or pointer is not validated against the available buffer.",
        "basis": [
          "CNA",
          "CWE-822"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50382",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.745Z",
      "date_published": "2026-07-14T17:07:19.716Z",
      "date_updated": "2026-08-03T22:55:41.283Z",
      "publisher": "microsoft",
      "title": "Windows Print Spooler Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22143
      },
      "nvd": {
        "published": "2026-07-14T18:17:39.870",
        "lastModified": "2026-07-22T16:17:48.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50383",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Print Spooler reads beyond the end of a buffer and exposes adjacent memory.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50383",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50384",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.745Z",
      "date_published": "2026-07-14T17:06:14.578Z",
      "date_updated": "2026-08-03T22:54:36.612Z",
      "publisher": "microsoft",
      "title": "Windows Clip Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04945
      },
      "nvd": {
        "published": "2026-07-14T17:17:01.160",
        "lastModified": "2026-07-22T16:17:48.903",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50384",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A race permits an object to be used after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50384",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50385",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.745Z",
      "date_published": "2026-07-14T17:07:15.657Z",
      "date_updated": "2026-08-03T22:55:37.147Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08202
      },
      "nvd": {
        "published": "2026-07-14T18:17:40.090",
        "lastModified": "2026-07-22T16:17:49.057",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50385",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unsynchronized Windows Runtime operations race so a local caller can reach a use-after-free privilege transition.",
        "basis": [
          "CNA record",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50385",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50386",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.745Z",
      "date_published": "2026-07-14T17:06:26.764Z",
      "date_updated": "2026-08-03T22:54:48.369Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26112
      },
      "nvd": {
        "published": "2026-07-14T18:17:40.213",
        "lastModified": "2026-07-22T16:17:49.180",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50386",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 writes attacker-controlled data beyond a heap buffer boundary.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50386",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50387",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.745Z",
      "date_published": "2026-07-14T17:07:08.099Z",
      "date_updated": "2026-08-03T22:55:26.281Z",
      "publisher": "microsoft",
      "title": "Windows GDI Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office for Android"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 22,
        "versionEntryCount": 22,
        "versionRangeCount": 22,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01921,
        "percentile": 0.779
      },
      "nvd": {
        "published": "2026-07-14T18:17:40.390",
        "lastModified": "2026-07-22T16:17:49.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50387",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows GDI writes beyond a stack buffer during a local operation.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50387",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 22,
        "affectedVersionEntryCount": 22
      }
    },
    {
      "cve_id": "CVE-2026-50388",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.745Z",
      "date_published": "2026-07-14T17:06:55.827Z",
      "date_updated": "2026-08-03T22:55:14.182Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00435,
        "percentile": 0.35778
      },
      "nvd": {
        "published": "2026-07-14T18:17:40.580",
        "lastModified": "2026-07-22T16:17:49.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50388",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 10 Version 1607, an attacker-controlled index or length permits a read beyond the valid memory region.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50388",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 91,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.745Z",
      "date_published": "2026-07-14T17:07:27.624Z",
      "date_updated": "2026-08-03T22:55:49.402Z",
      "publisher": "microsoft",
      "title": "Windows File Explorer Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00458,
        "percentile": 0.37497
      },
      "nvd": {
        "published": "2026-07-14T18:17:40.753",
        "lastModified": "2026-07-22T16:17:49.767",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50389",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Microsoft record reports local information disclosure in File Explorer but does not identify the exposed object or output path.",
        "basis": [
          "CNA record",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50389",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.745Z",
      "date_published": "2026-07-14T17:06:45.500Z",
      "date_updated": "2026-08-03T22:55:04.331Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21914
      },
      "nvd": {
        "published": "2026-07-14T18:17:40.913",
        "lastModified": "2026-07-22T16:17:49.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50390",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows kernel accesses a resource through an incompatible type, permitting a local authorized caller to corrupt privileged state.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50390",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 140,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.745Z",
      "date_published": "2026-07-14T17:07:02.440Z",
      "date_updated": "2026-08-03T22:55:20.813Z",
      "publisher": "microsoft",
      "title": "Windows Group Policy Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19999
      },
      "nvd": {
        "published": "2026-07-14T18:17:41.093",
        "lastModified": "2026-07-22T16:17:50.117",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50391",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows Group Policy mishandles privilege assignment and permits local elevation, but Microsoft does not publish the privileged object, role transition, or failing check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50391",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.745Z",
      "date_published": "2026-07-14T17:06:22.370Z",
      "date_updated": "2026-08-03T22:54:43.786Z",
      "publisher": "microsoft",
      "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.1253
      },
      "nvd": {
        "published": "2026-07-14T18:17:41.310",
        "lastModified": "2026-07-21T12:55:21.183",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50392",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A memory-safety error permits access outside the valid bounds or lifetime of an object.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50392",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50393",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.745Z",
      "date_published": "2026-07-14T17:06:25.096Z",
      "date_updated": "2026-08-03T22:54:46.740Z",
      "publisher": "microsoft",
      "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.002,
        "percentile": 0.10106
      },
      "nvd": {
        "published": "2026-07-14T18:17:41.440",
        "lastModified": "2026-07-22T16:17:50.370",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50393",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 11 Version 24H2 path retains or dereferences an object after the object's storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50393",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.745Z",
      "date_published": "2026-07-14T17:07:39.042Z",
      "date_updated": "2026-08-03T22:55:57.746Z",
      "publisher": "microsoft",
      "title": "Windows Media Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28111
      },
      "nvd": {
        "published": "2026-07-14T18:17:41.560",
        "lastModified": "2026-07-22T16:17:50.493",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50394",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows Media returns sensitive information to a local authorized attacker, but the data object and missing protection are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50394",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-50396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.746Z",
      "date_published": "2026-07-14T17:06:35.809Z",
      "date_updated": "2026-08-03T22:54:56.052Z",
      "publisher": "microsoft",
      "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.002,
        "percentile": 0.10106
      },
      "nvd": {
        "published": "2026-07-14T18:17:41.727",
        "lastModified": "2026-07-22T16:17:50.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50396",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Windows 11 Version 24H2, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50396",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.746Z",
      "date_published": "2026-07-14T17:07:06.288Z",
      "date_updated": "2026-08-03T22:55:24.778Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09949
      },
      "nvd": {
        "published": "2026-07-14T18:17:41.850",
        "lastModified": "2026-07-22T16:17:50.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50397",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows Kernel accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50397",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:55:14.746Z",
      "date_published": "2026-07-14T17:06:58.570Z",
      "date_updated": "2026-08-03T22:55:16.881Z",
      "publisher": "microsoft",
      "title": "Windows Media Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00393,
        "percentile": 0.32026
      },
      "nvd": {
        "published": "2026-07-14T18:17:42.020",
        "lastModified": "2026-07-22T16:17:50.973",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50398",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected workflow fails to preserve its invariant across a state transition or concurrent operation.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50398",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.258Z",
      "date_published": "2026-07-14T17:07:29.399Z",
      "date_updated": "2026-08-03T22:55:50.980Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15179
      },
      "nvd": {
        "published": "2026-07-14T18:17:42.147",
        "lastModified": "2026-07-22T16:17:51.103",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50399",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 21H2 can read beyond the valid bounds of an input or object allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50399",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.258Z",
      "date_published": "2026-07-14T17:06:27.407Z",
      "date_updated": "2026-08-03T22:54:48.992Z",
      "publisher": "microsoft",
      "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15139
      },
      "nvd": {
        "published": "2026-07-14T18:17:42.280",
        "lastModified": "2026-07-22T16:17:51.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50400",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50400",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50401",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.258Z",
      "date_published": "2026-07-14T17:07:04.774Z",
      "date_updated": "2026-08-03T22:55:23.021Z",
      "publisher": "microsoft",
      "title": "Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22141
      },
      "nvd": {
        "published": "2026-07-14T18:17:42.453",
        "lastModified": "2026-07-22T16:17:51.427",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50401",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Cloud Files mini-filter reads beyond the bounds of a local kernel buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50401",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50402",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.258Z",
      "date_published": "2026-07-14T17:07:22.151Z",
      "date_updated": "2026-08-03T22:55:43.689Z",
      "publisher": "microsoft",
      "title": "NTFS Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-681",
          "name": "Incorrect Conversion between Numeric Types",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27913
      },
      "nvd": {
        "published": "2026-07-14T18:17:42.600",
        "lastModified": "2026-07-22T16:17:51.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50402",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows NTFS converts a numeric value to an incompatible type, allowing truncation or reinterpretation that reaches an invalid memory read.",
        "basis": [
          "CNA",
          "CWE-126",
          "CWE-681"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50402",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.258Z",
      "date_published": "2026-07-14T17:07:01.395Z",
      "date_updated": "2026-08-03T22:55:19.638Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04942
      },
      "nvd": {
        "published": "2026-07-14T18:17:42.780",
        "lastModified": "2026-07-22T16:17:51.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50403",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Concurrent Windows Runtime operations can free shared state before all users finish with it, producing a use-after-free privilege path.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50403",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.258Z",
      "date_published": "2026-07-14T17:06:50.939Z",
      "date_updated": "2026-08-03T22:55:10.257Z",
      "publisher": "microsoft",
      "title": "Windows Media Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04946
      },
      "nvd": {
        "published": "2026-07-14T18:17:42.907",
        "lastModified": "2026-07-22T16:17:51.910",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50404",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent Windows 11 Version 24H2 operations can observe or mutate shared state without the synchronization required to preserve the security invariant.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50404",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-50405",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:06.849Z",
      "date_updated": "2026-08-03T22:55:25.329Z",
      "publisher": "microsoft",
      "title": "Windows Filtering Platform Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1220",
          "name": "Insufficient Granularity of Access Control",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11884
      },
      "nvd": {
        "published": "2026-07-14T18:17:43.033",
        "lastModified": "2026-07-22T16:17:52.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50405",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Filtering Platform grants a caller access at a coarser privilege level than the protected operation requires.",
        "basis": [
          "CNA",
          "CWE-1220"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50405",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50406",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:43.551Z",
      "date_updated": "2026-08-03T22:56:03.337Z",
      "publisher": "microsoft",
      "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17607
      },
      "nvd": {
        "published": "2026-07-14T18:17:43.210",
        "lastModified": "2026-07-23T05:16:34.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50406",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 10 Version 21H2, code retains or reuses an object after the lifetime transition that frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50406",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50407",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:06:33.790Z",
      "date_updated": "2026-08-03T22:54:54.376Z",
      "publisher": "microsoft",
      "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23439
      },
      "nvd": {
        "published": "2026-07-14T18:17:43.333",
        "lastModified": "2026-07-20T14:20:44.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50407",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 copies, writes, or indexes attacker-influenced data without enforcing the destination buffer or object bounds required by the operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50407",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 127,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50408",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:08:32.834Z",
      "date_updated": "2026-08-03T22:56:52.613Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27129
      },
      "nvd": {
        "published": "2026-07-14T18:17:43.490",
        "lastModified": "2026-07-16T15:16:32.187",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50408",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Excel reads beyond a valid memory buffer while processing attacker-controlled local content.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50408",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-50409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:23.191Z",
      "date_updated": "2026-08-03T22:55:44.884Z",
      "publisher": "microsoft",
      "title": "Windows Overlay Filter Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28063
      },
      "nvd": {
        "published": "2026-07-14T18:17:43.627",
        "lastModified": "2026-07-20T14:18:43.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50409",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Windows 10 Version 1607 discloses protected data, but does not identify the output, cache, or memory path that exposes it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50409",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:06:56.317Z",
      "date_updated": "2026-08-03T22:55:14.737Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09922
      },
      "nvd": {
        "published": "2026-07-14T18:17:43.790",
        "lastModified": "2026-07-22T16:17:52.607",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50410",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Runtime accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50410",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50411",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:37.996Z",
      "date_updated": "2026-08-03T22:55:56.572Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 24,
        "versionEntryCount": 24,
        "versionRangeCount": 24,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0078,
        "percentile": 0.52383
      },
      "nvd": {
        "published": "2026-07-14T18:17:43.937",
        "lastModified": "2026-07-24T14:11:35.523",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50411",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Active Directory Federation Services overflows a stack buffer while processing unauthenticated network input.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50411",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 24,
        "affectedVersionEntryCount": 24
      }
    },
    {
      "cve_id": "CVE-2026-50412",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:06:25.571Z",
      "date_updated": "2026-08-03T22:54:47.412Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.2344
      },
      "nvd": {
        "published": "2026-07-14T18:17:44.110",
        "lastModified": "2026-07-20T14:14:09.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50412",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows NTFS copies attacker-controlled data beyond a stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50412",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50413",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:16.218Z",
      "date_updated": "2026-08-03T22:55:37.953Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.0000000000000009,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15743
      },
      "nvd": {
        "published": "2026-07-14T18:17:44.287",
        "lastModified": "2026-07-22T16:17:53.100",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50413",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50413",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50414",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:06:59.109Z",
      "date_updated": "2026-08-03T22:55:17.350Z",
      "publisher": "microsoft",
      "title": "Windows Media Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.0053,
        "percentile": 0.4187
      },
      "nvd": {
        "published": "2026-07-14T18:17:44.413",
        "lastModified": "2026-07-22T16:17:53.237",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50414",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50414",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50415",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:39.607Z",
      "date_updated": "2026-08-03T22:55:58.371Z",
      "publisher": "microsoft",
      "title": "Windows Media Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00618,
        "percentile": 0.46196
      },
      "nvd": {
        "published": "2026-07-14T18:17:44.540",
        "lastModified": "2026-07-22T16:17:53.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50415",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50415",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50416",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:06:52.183Z",
      "date_updated": "2026-08-03T22:59:18.342Z",
      "publisher": "microsoft",
      "title": "Win32k Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00475,
        "percentile": 0.38581
      },
      "nvd": {
        "published": "2026-07-14T18:17:44.690",
        "lastModified": "2026-07-20T14:00:54.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50416",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected interface returns, embeds or leaves protected information visible to an observer who is not entitled to receive it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50416",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50417",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:31.528Z",
      "date_updated": "2026-08-03T22:55:53.284Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23435
      },
      "nvd": {
        "published": "2026-07-14T18:17:44.813",
        "lastModified": "2026-07-21T15:19:33.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50417",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows NTFS copies attacker-influenced data beyond a heap buffer boundary.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50417",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:03.025Z",
      "date_updated": "2026-08-03T22:55:21.438Z",
      "publisher": "microsoft",
      "title": "Windows System Secure Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09567
      },
      "nvd": {
        "published": "2026-07-14T18:17:44.990",
        "lastModified": "2026-07-22T16:17:53.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50418",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A local unauthenticated caller can bypass a Windows security feature, but Microsoft does not disclose the protected operation or access-control decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50418",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 111,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-50419",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:06:28.498Z",
      "date_updated": "2026-08-03T22:54:50.042Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26384
      },
      "nvd": {
        "published": "2026-07-14T18:17:45.113",
        "lastModified": "2026-07-22T16:17:53.847",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50419",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Windows kernel exposes sensitive information to a local caller, but the output path or oracle is not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50419",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50420",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:35.439Z",
      "date_updated": "2026-08-03T22:55:54.904Z",
      "publisher": "microsoft",
      "title": "HTTP.sys Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.0038,
        "percentile": 0.30753
      },
      "nvd": {
        "published": "2026-07-14T18:17:45.290",
        "lastModified": "2026-07-22T16:17:54.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50420",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can cause a read beyond the bounds of a valid buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50420",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50421",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:17.973Z",
      "date_updated": "2026-08-03T22:55:39.551Z",
      "publisher": "microsoft",
      "title": "Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23441
      },
      "nvd": {
        "published": "2026-07-14T18:17:45.410",
        "lastModified": "2026-07-23T05:16:34.963",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50421",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows telemetry accesses a resource through an incompatible runtime type.",
        "basis": [
          "CNA record",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50421",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 174,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:17.341Z",
      "date_updated": "2026-08-03T22:55:39.007Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23435
      },
      "nvd": {
        "published": "2026-07-14T18:17:45.567",
        "lastModified": "2026-07-20T17:33:53.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50422",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 reads beyond an allocated buffer because the input length or boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50422",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 95,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:03.665Z",
      "date_updated": "2026-08-03T22:55:22.065Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0263,
        "percentile": 0.84007
      },
      "nvd": {
        "published": "2026-07-14T18:17:45.737",
        "lastModified": "2026-07-22T16:17:54.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50423",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Windows kernel permits a local caller to elevate privilege, but the incorrect access-control decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50423",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:56:53.259Z",
      "date_published": "2026-07-14T17:07:42.997Z",
      "date_updated": "2026-08-03T22:56:02.692Z",
      "publisher": "microsoft",
      "title": "Windows Domain Controller Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-822",
          "name": "Untrusted Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00816,
        "percentile": 0.53583
      },
      "nvd": {
        "published": "2026-07-14T18:17:45.867",
        "lastModified": "2026-07-22T16:17:54.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50424",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Domain Controller dereferences a network-supplied pointer without establishing that it designates valid memory.",
        "basis": [
          "CNA",
          "CWE-822"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50424",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.375Z",
      "date_published": "2026-07-14T17:06:38.490Z",
      "date_updated": "2026-08-03T22:54:58.286Z",
      "publisher": "microsoft",
      "title": "Windows Internal System User Profile Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15138
      },
      "nvd": {
        "published": "2026-07-14T18:17:45.990",
        "lastModified": "2026-07-23T05:16:35.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50425",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path can retain or dereference an object after its storage has been released, leaving a dangling reference.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50425",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-50426",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.375Z",
      "date_published": "2026-07-14T17:07:15.031Z",
      "date_updated": "2026-08-03T22:55:35.604Z",
      "publisher": "microsoft",
      "title": "Windows DNS Server Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00359,
        "percentile": 0.28599
      },
      "nvd": {
        "published": "2026-07-14T18:17:46.123",
        "lastModified": "2026-07-29T19:16:46.647",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50426",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows DNS Server accepts a relative traversal path and selects content outside the intended directory during adjacent-network processing.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50426",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-50427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.375Z",
      "date_published": "2026-07-14T17:07:16.785Z",
      "date_updated": "2026-08-03T22:55:38.529Z",
      "publisher": "microsoft",
      "title": "Content Delivery Manager Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 10,
        "versionEntryCount": 10,
        "versionRangeCount": 10,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08201
      },
      "nvd": {
        "published": "2026-07-14T18:17:46.283",
        "lastModified": "2026-07-23T05:16:35.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50427",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1809 path retains or dereferences an object after its storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50427",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 10,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-50428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.375Z",
      "date_published": "2026-07-14T17:06:53.936Z",
      "date_updated": "2026-08-03T22:55:12.702Z",
      "publisher": "microsoft",
      "title": "Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22739
      },
      "nvd": {
        "published": "2026-07-14T18:17:46.447",
        "lastModified": "2026-07-22T16:17:55.127",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50428",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An object is read or written outside its valid allocation bounds.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50428",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 143,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50429",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.375Z",
      "date_published": "2026-07-14T17:07:41.894Z",
      "date_updated": "2026-08-03T22:56:00.690Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00768,
        "percentile": 0.52017
      },
      "nvd": {
        "published": "2026-07-14T18:17:46.573",
        "lastModified": "2026-07-22T16:17:55.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50429",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 path trusts a length or offset that can read beyond the initialized input buffer.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50429",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.375Z",
      "date_published": "2026-07-14T17:06:41.263Z",
      "date_updated": "2026-08-03T22:55:00.448Z",
      "publisher": "microsoft",
      "title": "Windows Push Notification Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28064
      },
      "nvd": {
        "published": "2026-07-14T18:17:46.737",
        "lastModified": "2026-07-22T16:17:55.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50430",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows Push Notifications returns sensitive information to a local authorized attacker, but the data object and missing protection are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50430",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 151,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50431",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.375Z",
      "date_published": "2026-07-14T17:07:30.491Z",
      "date_updated": "2026-08-03T22:55:52.177Z",
      "publisher": "microsoft",
      "title": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00458,
        "percentile": 0.37498
      },
      "nvd": {
        "published": "2026-07-14T18:17:46.897",
        "lastModified": "2026-07-22T16:17:55.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50431",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record names information disclosure in the Windows QoS Packet Scheduler without identifying the returned bytes, observer, or failing operation.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50431",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 86,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50432",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.375Z",
      "date_published": "2026-07-14T17:07:28.845Z",
      "date_updated": "2026-08-03T22:55:50.429Z",
      "publisher": "microsoft",
      "title": "Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00662,
        "percentile": 0.48143
      },
      "nvd": {
        "published": "2026-07-14T18:17:47.077",
        "lastModified": "2026-07-22T16:17:55.763",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50432",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Virtual Filtering Platform accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50432",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.375Z",
      "date_published": "2026-07-14T17:07:01.885Z",
      "date_updated": "2026-08-03T22:55:20.186Z",
      "publisher": "microsoft",
      "title": "Windows Media Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01921,
        "percentile": 0.779
      },
      "nvd": {
        "published": "2026-07-14T18:17:47.240",
        "lastModified": "2026-07-22T16:17:55.933",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50433",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path continues using an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50433",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 92,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.375Z",
      "date_published": "2026-07-14T17:06:40.070Z",
      "date_updated": "2026-08-03T22:54:59.330Z",
      "publisher": "microsoft",
      "title": "Windows Push Notification Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28064
      },
      "nvd": {
        "published": "2026-07-14T18:17:47.413",
        "lastModified": "2026-07-22T16:17:56.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50434",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected interface returns, embeds or leaves protected information visible to an observer who is not entitled to receive it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50434",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 151,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:07:22.625Z",
      "date_updated": "2026-08-03T22:55:44.256Z",
      "publisher": "microsoft",
      "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15134
      },
      "nvd": {
        "published": "2026-07-14T18:17:47.547",
        "lastModified": "2026-07-23T05:16:35.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50435",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows Overlay Filter performs a buffer read beyond the end of the allocated object.",
        "basis": [
          "CNA",
          "CWE-126",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50435",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-50436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:07:11.217Z",
      "date_updated": "2026-08-03T22:55:29.599Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0178,
        "percentile": 0.7606
      },
      "nvd": {
        "published": "2026-07-14T18:17:47.717",
        "lastModified": "2026-07-22T16:17:56.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50436",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 11 Version 24H2 accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50436",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50437",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:07:11.777Z",
      "date_updated": "2026-08-03T22:55:30.227Z",
      "publisher": "microsoft",
      "title": "Windows DWM Core Library Information Disclosure  Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22142
      },
      "nvd": {
        "published": "2026-07-14T18:17:47.840",
        "lastModified": "2026-07-22T16:17:56.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50437",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DWM Core reads beyond the bounds of a local memory object.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50437",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50438",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:07:34.847Z",
      "date_updated": "2026-08-03T22:55:54.415Z",
      "publisher": "microsoft",
      "title": "Microsoft PC Manager Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft PC Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.1992
      },
      "nvd": {
        "published": "2026-07-14T18:17:47.993",
        "lastModified": "2026-07-21T04:16:22.127",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50438",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft PC Manager follows an attacker-controlled link before privileged file access, selecting a target outside the intended object.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50438",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50439",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:07:24.920Z",
      "date_updated": "2026-08-03T22:55:46.555Z",
      "publisher": "microsoft",
      "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00535,
        "percentile": 0.42151
      },
      "nvd": {
        "published": "2026-07-14T18:17:48.123",
        "lastModified": "2026-07-22T16:17:56.817",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50439",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Message Queuing Queue Manager accesses an object after it has been freed while handling unauthenticated network activity.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50439",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50440",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:06:31.359Z",
      "date_updated": "2026-08-03T22:54:52.795Z",
      "publisher": "microsoft",
      "title": "Windows Audio Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05048
      },
      "nvd": {
        "published": "2026-07-14T18:17:48.300",
        "lastModified": "2026-07-23T05:16:35.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50440",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent Windows 11 Version 24H2 operations can observe or mutate shared state without the synchronization required to preserve the security invariant.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50440",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 177,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-50441",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:07:23.743Z",
      "date_updated": "2026-08-03T22:55:45.436Z",
      "publisher": "microsoft",
      "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-822",
          "name": "Untrusted Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15139
      },
      "nvd": {
        "published": "2026-07-14T18:17:48.423",
        "lastModified": "2026-07-22T16:17:57.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50441",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ReFS dereferences a pointer supplied from an untrusted context without validating that it addresses a safe object.",
        "basis": [
          "CNA",
          "CWE-822"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50441",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50442",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:07:27.065Z",
      "date_updated": "2026-08-03T22:55:48.857Z",
      "publisher": "microsoft",
      "title": "Windows File Explorer Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28062
      },
      "nvd": {
        "published": "2026-07-14T18:17:48.580",
        "lastModified": "2026-07-22T16:17:57.307",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50442",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows File Explorer exposes protected local information to an authorized attacker, while Microsoft's public record does not identify the object or output involved.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50442",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50444",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:07:38.548Z",
      "date_updated": "2026-08-03T22:55:57.198Z",
      "publisher": "microsoft",
      "title": "Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00604,
        "percentile": 0.45502
      },
      "nvd": {
        "published": "2026-07-14T18:17:48.737",
        "lastModified": "2026-07-21T15:23:36.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50444",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50444",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 145,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-50445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:07:09.141Z",
      "date_updated": "2026-08-03T22:55:27.324Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00651,
        "percentile": 0.47699
      },
      "nvd": {
        "published": "2026-07-14T18:17:48.890",
        "lastModified": "2026-07-22T16:17:57.577",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50445",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows RDP reads past a buffer boundary while handling attacker-controlled network data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50445",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50447",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:07:33.517Z",
      "date_updated": "2026-08-03T22:55:53.763Z",
      "publisher": "microsoft",
      "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00908,
        "percentile": 0.56472
      },
      "nvd": {
        "published": "2026-07-14T18:17:49.077",
        "lastModified": "2026-07-22T16:17:57.763",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50447",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 writes attacker-controlled data beyond a heap allocation because the copy or allocation size is not validated.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50447",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:07:07.472Z",
      "date_updated": "2026-08-03T22:55:25.808Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26112
      },
      "nvd": {
        "published": "2026-07-14T18:17:49.290",
        "lastModified": "2026-07-22T16:17:57.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50448",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows NTFS writes beyond a heap allocation while processing attacker-controlled local input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50448",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50449",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.376Z",
      "date_published": "2026-07-14T17:06:56.954Z",
      "date_updated": "2026-08-03T22:55:15.395Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09922
      },
      "nvd": {
        "published": "2026-07-14T18:17:49.477",
        "lastModified": "2026-07-22T16:17:58.133",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50449",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Runtime uses a local object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50449",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50450",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:57:47.377Z",
      "date_published": "2026-07-14T17:07:42.437Z",
      "date_updated": "2026-08-03T22:56:02.149Z",
      "publisher": "microsoft",
      "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04946
      },
      "nvd": {
        "published": "2026-07-14T18:17:49.633",
        "lastModified": "2026-07-22T16:17:58.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50450",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows Wireless Wide Area Network Service has a shared-resource race, but the public record does not identify the shared object, conflicting operations, or invalid transition.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50450",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50451",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.976Z",
      "date_published": "2026-07-14T17:07:20.330Z",
      "date_updated": "2026-08-03T22:55:41.952Z",
      "publisher": "microsoft",
      "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12736
      },
      "nvd": {
        "published": "2026-07-14T18:17:49.787",
        "lastModified": "2026-07-22T16:17:58.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50451",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50451",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 157,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50452",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.977Z",
      "date_published": "2026-07-14T17:06:45.989Z",
      "date_updated": "2026-08-03T22:55:04.961Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17458
      },
      "nvd": {
        "published": "2026-07-14T18:17:49.967",
        "lastModified": "2026-07-22T16:17:58.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50452",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50452",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50453",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.977Z",
      "date_published": "2026-07-14T17:07:31.043Z",
      "date_updated": "2026-08-03T22:55:52.734Z",
      "publisher": "microsoft",
      "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00364,
        "percentile": 0.29147
      },
      "nvd": {
        "published": "2026-07-14T18:17:50.120",
        "lastModified": "2026-07-22T16:17:58.800",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50453",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the valid input or buffer boundary because its size check is incomplete.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50453",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.977Z",
      "date_published": "2026-07-14T17:07:13.997Z",
      "date_updated": "2026-08-03T22:55:32.483Z",
      "publisher": "microsoft",
      "title": "Windows User Interface Core Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0044,
        "percentile": 0.36169
      },
      "nvd": {
        "published": "2026-07-14T18:17:50.290",
        "lastModified": "2026-07-29T20:17:04.100",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50454",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled path or object-name data is resolved without proving that the final target remains inside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50454",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50455",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.977Z",
      "date_published": "2026-07-14T17:07:20.899Z",
      "date_updated": "2026-08-03T22:55:42.511Z",
      "publisher": "microsoft",
      "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22141
      },
      "nvd": {
        "published": "2026-07-14T18:17:50.423",
        "lastModified": "2026-07-22T16:17:59.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50455",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The implementation fails to preserve a valid bound, initialization state, type, ownership rule, or object lifetime before memory access.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50455",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50456",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.977Z",
      "date_published": "2026-07-14T17:07:28.289Z",
      "date_updated": "2026-08-03T22:55:49.952Z",
      "publisher": "microsoft",
      "title": "Windows File Explorer Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28064
      },
      "nvd": {
        "published": "2026-07-14T18:17:50.597",
        "lastModified": "2026-07-22T16:17:59.307",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50456",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows File Explorer exposes protected local information to an authorized caller, but Microsoft does not disclose the data or missing output guard.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50456",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50457",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.977Z",
      "date_published": "2026-07-14T17:07:25.967Z",
      "date_updated": "2026-08-03T22:55:47.657Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 10,
        "versionEntryCount": 10,
        "versionRangeCount": 10,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08202
      },
      "nvd": {
        "published": "2026-07-14T18:17:50.773",
        "lastModified": "2026-07-22T16:17:59.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50457",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Runtime can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50457",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 10,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-50458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.977Z",
      "date_published": "2026-07-14T17:07:40.248Z",
      "date_updated": "2026-08-03T22:55:58.835Z",
      "publisher": "microsoft",
      "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.0862
      },
      "nvd": {
        "published": "2026-07-14T18:17:50.910",
        "lastModified": "2026-07-22T16:17:59.653",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50458",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50458",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 110,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.977Z",
      "date_published": "2026-07-14T17:07:44.661Z",
      "date_updated": "2026-08-03T22:56:04.287Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09679
      },
      "nvd": {
        "published": "2026-07-14T18:17:51.040",
        "lastModified": "2026-07-22T16:17:59.783",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50459",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows kernel dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA record",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50459",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 95,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50460",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.977Z",
      "date_published": "2026-07-14T17:07:00.843Z",
      "date_updated": "2026-08-03T22:55:19.091Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00506,
        "percentile": 0.40431
      },
      "nvd": {
        "published": "2026-07-14T18:17:51.167",
        "lastModified": "2026-07-22T16:17:59.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50460",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A race permits one thread to free an object while another thread can still use the same object.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50460",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50461",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.977Z",
      "date_published": "2026-07-14T17:07:29.945Z",
      "date_updated": "2026-08-03T22:55:51.616Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26113
      },
      "nvd": {
        "published": "2026-07-14T18:17:51.317",
        "lastModified": "2026-07-22T16:18:00.083",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50461",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NTFS writes beyond a heap allocation while processing attacker-controlled local input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50461",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50462",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.977Z",
      "date_published": "2026-07-14T17:07:25.474Z",
      "date_updated": "2026-08-03T22:55:47.103Z",
      "publisher": "microsoft",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00392,
        "percentile": 0.31975
      },
      "nvd": {
        "published": "2026-07-14T18:17:51.497",
        "lastModified": "2026-07-22T16:18:00.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50462",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file operation in Windows 10 Version 1607 uses an attacker-controlled path without confining the resolved object to the intended namespace.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50462",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50463",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.977Z",
      "date_published": "2026-07-14T17:07:00.301Z",
      "date_updated": "2026-08-03T22:55:18.455Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00738,
        "percentile": 0.50991
      },
      "nvd": {
        "published": "2026-07-14T18:17:51.707",
        "lastModified": "2026-07-22T16:18:00.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50463",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the end of an allocated buffer because the available length is not enforced.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50463",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50465",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.978Z",
      "date_published": "2026-07-14T17:07:24.361Z",
      "date_updated": "2026-08-03T22:55:45.988Z",
      "publisher": "microsoft",
      "title": "Windows DNS Client Tampering Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11903
      },
      "nvd": {
        "published": "2026-07-14T18:17:51.850",
        "lastModified": "2026-07-22T16:18:00.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50465",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A local authorized caller can tamper with Windows DNS state because of an undisclosed access-control failure.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50465",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50466",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.978Z",
      "date_published": "2026-07-14T17:07:21.513Z",
      "date_updated": "2026-08-03T22:55:43.068Z",
      "publisher": "microsoft",
      "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15137
      },
      "nvd": {
        "published": "2026-07-14T18:17:51.977",
        "lastModified": "2026-07-22T16:18:00.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50466",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 11 Version 24H2 path retains or dereferences an object after its storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50466",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50467",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.978Z",
      "date_published": "2026-07-14T17:08:30.777Z",
      "date_updated": "2026-08-03T22:56:50.415Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26667
      },
      "nvd": {
        "published": "2026-07-14T18:17:52.100",
        "lastModified": "2026-07-16T15:21:18.393",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50467",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A stale or invalid memory reference remains usable beyond the object's valid lifetime.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50467",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 91,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50468",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.978Z",
      "date_published": "2026-07-14T17:09:08.079Z",
      "date_updated": "2026-08-03T22:57:27.893Z",
      "publisher": "microsoft",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 (CU 6)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 for x64-based Systems (GDR)"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00716,
        "percentile": 0.50201
      },
      "nvd": {
        "published": "2026-07-14T18:17:52.237",
        "lastModified": "2026-07-22T17:30:04.960",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50468",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Microsoft SQL Server 2025 (CU 6) path trusts a length or offset that can read beyond the initialized input buffer.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50468",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-50469",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.978Z",
      "date_published": "2026-07-14T17:07:13.526Z",
      "date_updated": "2026-08-03T22:55:31.904Z",
      "publisher": "microsoft",
      "title": "Windows Projected File System Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00271,
        "percentile": 0.1912
      },
      "nvd": {
        "published": "2026-07-14T18:17:52.357",
        "lastModified": "2026-07-22T16:18:00.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50469",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Projected File System follows an attacker-controlled link before file access and reaches an unintended object.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50469",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 156,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50470",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.978Z",
      "date_published": "2026-07-14T17:07:44.100Z",
      "date_updated": "2026-08-03T22:56:03.808Z",
      "publisher": "microsoft",
      "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00738,
        "percentile": 0.5099
      },
      "nvd": {
        "published": "2026-07-14T18:17:52.500",
        "lastModified": "2026-07-22T16:18:01.133",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50470",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Windows 10 Version 1607, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50470",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50471",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.978Z",
      "date_published": "2026-07-14T17:07:12.417Z",
      "date_updated": "2026-08-03T22:55:30.704Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 20,
        "versionEntryCount": 20,
        "versionRangeCount": 20,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22626
      },
      "nvd": {
        "published": "2026-07-14T18:17:52.677",
        "lastModified": "2026-07-22T16:18:01.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50471",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows NTFS writes beyond the bounds of a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50471",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 20,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-50473",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.978Z",
      "date_published": "2026-07-14T17:07:26.516Z",
      "date_updated": "2026-08-03T22:55:48.299Z",
      "publisher": "microsoft",
      "title": "Windows File Explorer Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28061
      },
      "nvd": {
        "published": "2026-07-14T18:17:52.857",
        "lastModified": "2026-07-22T16:18:01.503",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50473",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50473",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50474",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.978Z",
      "date_published": "2026-07-14T17:07:37.434Z",
      "date_updated": "2026-08-03T22:55:55.936Z",
      "publisher": "microsoft",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00612,
        "percentile": 0.45889
      },
      "nvd": {
        "published": "2026-07-14T18:17:53.013",
        "lastModified": "2026-07-22T16:18:01.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50474",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50474",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50475",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.979Z",
      "date_published": "2026-07-14T17:07:40.791Z",
      "date_updated": "2026-08-03T22:55:59.394Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00536,
        "percentile": 0.42161
      },
      "nvd": {
        "published": "2026-07-14T18:17:53.190",
        "lastModified": "2026-07-22T16:18:01.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50475",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A length, offset, or termination error makes the program read beyond the end of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50475",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2443",
          "host": "www.talosintelligence.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:17.979Z",
      "date_published": "2026-07-14T17:07:41.420Z",
      "date_updated": "2026-08-03T22:56:00.049Z",
      "publisher": "microsoft",
      "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01633,
        "percentile": 0.73933
      },
      "nvd": {
        "published": "2026-07-14T18:17:53.360",
        "lastModified": "2026-07-22T16:18:02.053",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50476",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50476",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50477",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.336Z",
      "date_published": "2026-07-14T17:07:45.296Z",
      "date_updated": "2026-08-03T22:56:04.913Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.0000000000000009,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24159
      },
      "nvd": {
        "published": "2026-07-14T18:17:53.537",
        "lastModified": "2026-07-22T16:18:02.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50477",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows kernel writes beyond a heap allocation while handling local attacker-controlled input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50477",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50478",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.336Z",
      "date_published": "2026-07-14T17:07:45.935Z",
      "date_updated": "2026-08-03T22:56:05.548Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23479
      },
      "nvd": {
        "published": "2026-07-14T18:17:53.710",
        "lastModified": "2026-07-22T16:18:02.433",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50478",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows kernel accesses an object after its lifetime has ended, allowing a local authorized user to corrupt privileged kernel state.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50478",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50479",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.336Z",
      "date_published": "2026-07-14T17:07:46.500Z",
      "date_updated": "2026-08-03T22:56:06.184Z",
      "publisher": "microsoft",
      "title": "Windows USB Hub Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-822",
          "name": "Untrusted Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23434
      },
      "nvd": {
        "published": "2026-07-14T18:17:53.857",
        "lastModified": "2026-07-21T03:45:19.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50479",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The USB Hub Driver dereferences a pointer supplied or influenced outside the trusted object lifetime during a local operation.",
        "basis": [
          "CNA",
          "CWE-822"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50479",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50480",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.336Z",
      "date_published": "2026-07-14T17:07:46.980Z",
      "date_updated": "2026-08-03T22:56:06.805Z",
      "publisher": "microsoft",
      "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15137
      },
      "nvd": {
        "published": "2026-07-14T18:17:53.990",
        "lastModified": "2026-07-21T03:46:53.177",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50480",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 path writes attacker-influenced data beyond an allocated heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50480",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-50482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.336Z",
      "date_published": "2026-07-14T17:07:47.450Z",
      "date_updated": "2026-08-03T22:56:07.430Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00258,
        "percentile": 0.1743
      },
      "nvd": {
        "published": "2026-07-14T18:17:54.117",
        "lastModified": "2026-07-22T16:18:02.743",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50482",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NTFS writes beyond a heap allocation while processing attacker-controlled local input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50482",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50483",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.336Z",
      "date_published": "2026-07-14T17:07:48.547Z",
      "date_updated": "2026-08-03T22:56:09.223Z",
      "publisher": "microsoft",
      "title": "Windows Graphics Component Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26358
      },
      "nvd": {
        "published": "2026-07-14T18:17:54.290",
        "lastModified": "2026-07-22T16:18:02.927",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50483",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft Graphics exposes protected local information to an authorized attacker, while Microsoft's public record does not identify the object or output involved.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50483",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 153,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50484",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.336Z",
      "date_published": "2026-07-14T17:07:49.168Z",
      "date_updated": "2026-08-03T22:56:09.775Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23479
      },
      "nvd": {
        "published": "2026-07-14T18:17:54.420",
        "lastModified": "2026-07-22T16:18:03.053",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50484",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1809 copies, writes, or indexes attacker-influenced data without enforcing the destination buffer or object bounds required by the operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50484",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50485",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.336Z",
      "date_published": "2026-07-14T17:07:50.975Z",
      "date_updated": "2026-08-03T22:56:10.886Z",
      "publisher": "microsoft",
      "title": "Windows Hyper-V Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00426,
        "percentile": 0.35059
      },
      "nvd": {
        "published": "2026-07-14T18:17:54.560",
        "lastModified": "2026-07-21T18:22:37.117",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50485",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Hyper-V reads past a valid buffer while handling an adjacent authorized request and can terminate the service.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50485",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50486",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.336Z",
      "date_published": "2026-07-14T17:07:51.451Z",
      "date_updated": "2026-08-03T22:56:11.435Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15136
      },
      "nvd": {
        "published": "2026-07-14T18:17:54.740",
        "lastModified": "2026-07-22T16:18:03.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50486",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 21H2 continues to access an object after its storage has been released, allowing invalid heap use and possible corruption.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50486",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-50487",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.336Z",
      "date_published": "2026-07-14T17:07:51.922Z",
      "date_updated": "2026-08-03T22:56:11.901Z",
      "publisher": "microsoft",
      "title": "Windows DNS Client Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00738,
        "percentile": 0.50998
      },
      "nvd": {
        "published": "2026-07-14T18:17:54.870",
        "lastModified": "2026-07-22T16:18:03.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50487",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows DNS Client accesses an object after it has been freed while handling network input.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50487",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.336Z",
      "date_published": "2026-07-14T17:07:52.474Z",
      "date_updated": "2026-08-03T22:56:12.373Z",
      "publisher": "microsoft",
      "title": "Clipboard User Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14129
      },
      "nvd": {
        "published": "2026-07-14T18:17:54.993",
        "lastModified": "2026-07-21T18:20:28.267",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50488",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Clipboard User Service permits local input to alter the structure of a privileged command, while the public record does not identify the input or command-construction path.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50488",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-50489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:07:54.137Z",
      "date_updated": "2026-08-03T22:56:14.017Z",
      "publisher": "microsoft",
      "title": "Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.0000000000000009,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28767
      },
      "nvd": {
        "published": "2026-07-14T18:17:55.117",
        "lastModified": "2026-07-21T18:19:16.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50489",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Win32K copies attacker-controlled data beyond a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50489",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:07:55.309Z",
      "date_updated": "2026-08-03T22:56:15.056Z",
      "publisher": "microsoft",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17607
      },
      "nvd": {
        "published": "2026-07-14T18:17:55.290",
        "lastModified": "2026-07-22T16:18:03.763",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50490",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50490",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50491",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:07:57.078Z",
      "date_updated": "2026-08-03T22:56:16.791Z",
      "publisher": "microsoft",
      "title": "Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17605
      },
      "nvd": {
        "published": "2026-07-14T18:17:55.463",
        "lastModified": "2026-07-23T05:16:35.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50491",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50491",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 110,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:07:57.731Z",
      "date_updated": "2026-08-03T22:56:17.259Z",
      "publisher": "microsoft",
      "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00408,
        "percentile": 0.33583
      },
      "nvd": {
        "published": "2026-07-14T18:17:55.640",
        "lastModified": "2026-07-21T18:21:48.223",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50492",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler writes attacker-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50492",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50493",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:07:49.714Z",
      "date_updated": "2026-08-03T22:59:19.378Z",
      "publisher": "microsoft",
      "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23435
      },
      "nvd": {
        "published": "2026-07-14T18:17:55.800",
        "lastModified": "2026-07-22T16:18:04.183",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50493",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1809 can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50493",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50494",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:07:54.685Z",
      "date_updated": "2026-08-03T22:56:14.570Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.2344
      },
      "nvd": {
        "published": "2026-07-14T18:17:55.943",
        "lastModified": "2026-07-21T18:24:07.037",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50494",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data is written beyond the boundary of a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50494",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50495",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:07:47.990Z",
      "date_updated": "2026-08-03T22:56:08.674Z",
      "publisher": "microsoft",
      "title": "DNS Client Tampering Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20393
      },
      "nvd": {
        "published": "2026-07-14T18:17:56.117",
        "lastModified": "2026-07-22T16:18:04.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50495",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A local authorized caller can tamper with Windows DNS state, but Microsoft does not disclose the protected object or access-control decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50495",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:08:00.054Z",
      "date_updated": "2026-08-03T22:56:19.638Z",
      "publisher": "microsoft",
      "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01125,
        "percentile": 0.63101
      },
      "nvd": {
        "published": "2026-07-14T18:17:56.267",
        "lastModified": "2026-07-21T18:24:44.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50496",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Network Policy Server SNMP reads beyond a valid buffer and returns adjacent memory.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50496",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50497",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:07:59.488Z",
      "date_updated": "2026-08-03T22:56:19.089Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-193",
          "name": "Off-by-one Error",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00868,
        "percentile": 0.55231
      },
      "nvd": {
        "published": "2026-07-14T18:17:56.437",
        "lastModified": "2026-07-22T16:18:04.747",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50497",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An off-by-one condition exposes or uses memory that has not been initialized.",
        "basis": [
          "CNA",
          "CWE-193",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50497",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50498",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:07:55.965Z",
      "date_updated": "2026-08-03T22:56:15.605Z",
      "publisher": "microsoft",
      "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17737
      },
      "nvd": {
        "published": "2026-07-14T18:17:56.640",
        "lastModified": "2026-07-21T18:25:25.890",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50498",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer underflow in UDFS produces bounds that permit a read beyond an allocated buffer.",
        "basis": [
          "CNA record",
          "CWE-191",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50498",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 92,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:07:53.578Z",
      "date_updated": "2026-08-03T22:56:13.470Z",
      "publisher": "microsoft",
      "title": "Windows Print Spooler Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15138
      },
      "nvd": {
        "published": "2026-07-14T18:17:56.813",
        "lastModified": "2026-07-22T16:18:05.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50499",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1809 writes attacker-controlled data beyond a heap buffer boundary.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50499",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50500",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:07:52.945Z",
      "date_updated": "2026-08-03T22:56:12.999Z",
      "publisher": "microsoft",
      "title": "Windows Netlogon Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00692,
        "percentile": 0.49324
      },
      "nvd": {
        "published": "2026-07-14T18:17:56.960",
        "lastModified": "2026-07-21T18:25:55.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50500",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Netlogon uses an object after it has been freed during a network-reachable operation.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50500",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.337Z",
      "date_published": "2026-07-14T17:07:58.364Z",
      "date_updated": "2026-08-03T22:56:17.903Z",
      "publisher": "microsoft",
      "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26398
      },
      "nvd": {
        "published": "2026-07-14T18:17:57.137",
        "lastModified": "2026-07-22T14:14:47.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50501",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 11 Version 24H2, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50501",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50502",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T18:59:53.338Z",
      "date_published": "2026-07-14T17:07:50.353Z",
      "date_updated": "2026-08-03T22:56:10.325Z",
      "publisher": "microsoft",
      "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1220",
          "name": "Insufficient Granularity of Access Control",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.006,
        "percentile": 0.45332
      },
      "nvd": {
        "published": "2026-07-14T18:17:57.277",
        "lastModified": "2026-07-22T16:18:05.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50502",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The service grants a network operation at a coarser access-control level than the security-sensitive action requires.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-1220"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50502",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 137,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50503",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.292Z",
      "date_published": "2026-07-14T17:07:58.931Z",
      "date_updated": "2026-08-03T22:56:18.534Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08703
      },
      "nvd": {
        "published": "2026-07-14T18:17:57.470",
        "lastModified": "2026-07-22T16:18:05.590",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50503",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Windows Runtime concurrently uses a shared resource without sufficient synchronization, allowing a local race to elevate privileges.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50503",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50504",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.292Z",
      "date_published": "2026-07-14T17:08:00.531Z",
      "date_updated": "2026-08-03T22:56:20.191Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00622,
        "percentile": 0.46409
      },
      "nvd": {
        "published": "2026-07-14T18:17:57.617",
        "lastModified": "2026-07-22T16:18:05.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50504",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 path reads beyond the validated extent of an attacker-influenced buffer.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50504",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50505",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.292Z",
      "date_published": "2026-07-14T17:07:56.528Z",
      "date_updated": "2026-08-03T22:56:16.158Z",
      "publisher": "microsoft",
      "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00502,
        "percentile": 0.40185
      },
      "nvd": {
        "published": "2026-07-14T18:17:57.810",
        "lastModified": "2026-07-22T15:00:25.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50505",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Incorrect size, bounds, or ownership handling permits invalid memory access.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50505",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50506",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.292Z",
      "date_published": "2026-07-14T17:04:38.435Z",
      "date_updated": "2026-08-03T22:53:02.660Z",
      "publisher": "microsoft",
      "title": "OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "AspNet.OData"
          },
          {
            "vendor": "Microsoft",
            "product": "AspNetCore.OData"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0078,
        "percentile": 0.52383
      },
      "nvd": {
        "published": "2026-07-14T17:17:01.303",
        "lastModified": "2026-07-24T13:40:15.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50506",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The AspNet.OData request path allocates work or memory from attacker-controlled input without an effective item or byte limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50506",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-50509",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.292Z",
      "date_published": "2026-07-14T17:08:01.551Z",
      "date_updated": "2026-08-03T22:56:21.296Z",
      "publisher": "microsoft",
      "title": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.03172,
        "percentile": 0.8676
      },
      "nvd": {
        "published": "2026-07-14T18:17:58.057",
        "lastModified": "2026-07-22T15:05:27.757",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50509",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Wireless Wide Area Network Service reconstructs objects from untrusted serialized data.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50509",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 140,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-50510",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.292Z",
      "date_published": "2026-07-14T17:08:02.102Z",
      "date_updated": "2026-08-03T22:56:21.846Z",
      "publisher": "microsoft",
      "title": "GitHub Copilot Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "GitHub Copilot Plugin for JetBrains IDEs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-641",
          "name": "Improper Restriction of Names for Files and Other Resources",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14293
      },
      "nvd": {
        "published": "2026-07-14T18:17:58.233",
        "lastModified": "2026-07-22T16:24:29.957",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50510",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Copilot accepts deceptive resource names that select files or resources outside the user-intended object.",
        "basis": [
          "CNA",
          "CWE-641"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50510",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50517",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.292Z",
      "date_published": "2026-07-24T00:01:11.819Z",
      "date_updated": "2026-08-03T22:59:14.797Z",
      "publisher": "microsoft",
      "title": "Microsoft M365 Copilot Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Copilot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01254,
        "percentile": 0.66549
      },
      "nvd": {
        "published": "2026-07-24T01:17:02.257",
        "lastModified": "2026-07-29T14:19:20.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50517",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component deserializes attacker-controlled object data without restricting executable types or behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50517",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 111,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50518",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.292Z",
      "date_published": "2026-07-14T17:08:02.730Z",
      "date_updated": "2026-08-03T22:56:22.484Z",
      "publisher": "microsoft",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.11058,
        "percentile": 0.95474
      },
      "nvd": {
        "published": "2026-07-14T18:17:58.373",
        "lastModified": "2026-07-22T15:15:16.043",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50518",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Windows DHCP Server accepts malicious domain-name data without validating its incoming size before copying it into a heap buffer, allowing the request to corrupt adjacent heap memory.",
        "basis": [
          "CNA",
          "CWE-122",
          "Microsoft MSRC July 2026 CVRF"
        ],
        "deepDive": true,
        "notes": "Inspected https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jul. Microsoft's FAQ says crafted network requests carry malicious domain-name data and the DHCP Server function fails to validate incoming data size before memory corruption; it does not name the function or copy site."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50518",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-50520",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.292Z",
      "date_published": "2026-07-14T17:05:07.225Z",
      "date_updated": "2026-08-03T22:53:27.620Z",
      "publisher": "microsoft",
      "title": "Visual Studio Code Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Visual Studio Code"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16853
      },
      "nvd": {
        "published": "2026-07-14T17:17:01.420",
        "lastModified": "2026-07-16T15:02:15.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50520",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The application places attacker-controlled data into an operating-system command without separating the data from command syntax.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50520",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Product",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 162,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50521",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.293Z",
      "date_published": "2026-07-01T20:14:43.695Z",
      "date_updated": "2026-07-28T22:19:44.899Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00456,
        "percentile": 0.37377
      },
      "nvd": {
        "published": "2026-07-01T21:17:03.037",
        "lastModified": "2026-07-03T04:17:54.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50521",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge (Chromium-based) accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50521",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 111,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50522",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.293Z",
      "date_published": "2026-07-14T17:05:27.656Z",
      "date_updated": "2026-08-03T22:53:47.054Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.7576,
        "percentile": 0.99474
      },
      "official_kev": {
        "cveID": "CVE-2026-50522",
        "vendorProject": "Microsoft",
        "product": "SharePoint",
        "vulnerabilityName": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability ",
        "dateAdded": "2026-07-22",
        "shortDescription": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-07-25",
        "knownRansomwareCampaignUse": "Unknown",
        "notes": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-50522",
        "cwes": [
          "CWE-502"
        ]
      },
      "nvd": {
        "published": "2026-07-14T17:17:01.547",
        "lastModified": "2026-07-23T15:44:10.873",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50522",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SharePoint deserializes attacker-controlled data into executable object behavior without an adequate type or object-graph boundary.",
        "basis": [
          "CNA",
          "CWE-502",
          "MSRC CVRF",
          "CISA KEV"
        ],
        "deepDive": true,
        "notes": "Inspected Microsoft official CVRF https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jul and CISA official KEV JSON https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; CISA lists the CVE as known exploited and unauthenticated, while the CVRF threat field says Exploited:No and its FAQ says Site Owner is required despite the CNA description and CVSS saying unauthenticated; no reproduction was performed."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50522",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-50524",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.293Z",
      "date_published": "2026-07-14T19:29:53.872Z",
      "date_updated": "2026-08-03T22:53:24.918Z",
      "publisher": "microsoft",
      "title": ".NET Framework Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1287",
          "name": "Improper Validation of Specified Type of Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00634,
        "percentile": 0.46905
      },
      "nvd": {
        "published": "2026-07-14T20:17:37.000",
        "lastModified": "2026-07-22T21:17:40.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50524",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The .NET Framework accepts network input whose required type is not validated and terminates while processing the unexpected representation.",
        "basis": [
          "CNA",
          "CWE-1287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50524",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-50525",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.293Z",
      "date_published": "2026-07-14T19:29:54.357Z",
      "date_updated": "2026-08-03T22:56:23.034Z",
      "publisher": "microsoft",
      "title": ".NET Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00604,
        "percentile": 0.45521
      },
      "nvd": {
        "published": "2026-07-14T20:17:37.120",
        "lastModified": "2026-07-24T13:39:54.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50525",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A remote .NET operation can allocate resources without an effective size or rate bound until service is exhausted.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50525",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-50526",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.293Z",
      "date_published": "2026-07-14T19:29:54.992Z",
      "date_updated": "2026-08-03T22:56:23.587Z",
      "publisher": "microsoft",
      "title": ".NET Tampering Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14736
      },
      "nvd": {
        "published": "2026-07-14T20:17:37.240",
        "lastModified": "2026-07-22T21:17:40.993",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50526",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The .NET 10.0 file operation follows an attacker-influenced link outside the intended file object.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50526",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-50527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.293Z",
      "date_published": "2026-07-14T19:29:55.564Z",
      "date_updated": "2026-08-03T22:56:24.220Z",
      "publisher": "microsoft",
      "title": ".NET Framework Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 12,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0084,
        "percentile": 0.54318
      },
      "nvd": {
        "published": "2026-07-14T20:17:37.363",
        "lastModified": "2026-07-24T13:39:44.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50527",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The .NET Framework writes beyond a stack buffer in a remotely reachable path.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50527",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 12,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-50528",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T19:00:41.293Z",
      "date_published": "2026-07-14T19:29:56.224Z",
      "date_updated": "2026-08-03T22:56:24.684Z",
      "publisher": "microsoft",
      "title": ".NET Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-302",
          "name": "Authentication Bypass by Assumed-Immutable Data",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-636",
          "name": "Not Failing Securely ('Failing Open')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00551,
        "percentile": 0.42991
      },
      "nvd": {
        "published": "2026-07-14T20:17:37.533",
        "lastModified": "2026-07-22T21:17:41.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50528",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that .NET 10.0 permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-302",
          "CWE-636",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50528",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-50529",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T20:37:18.652Z",
      "date_published": "2026-07-07T20:39:23.727Z",
      "date_updated": "2026-07-08T13:14:13.484Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Link Token Leakage Prior to Share Password/Ticket Validation",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20755
      },
      "nvd": {
        "published": "2026-07-07T21:17:26.110",
        "lastModified": "2026-07-08T15:07:37.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50529",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DataEase returns X-DE-LINK-TOKEN before validating the share password or ticket, so the authorization artifact escapes before the gate that is meant to control it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-7287-qqj9-phr6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/c4e85a981e53c95b1ea73757db31e3025efdc410",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 429,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T20:37:18.652Z",
      "date_published": "2026-07-07T20:41:07.576Z",
      "date_updated": "2026-07-08T13:57:27.568Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshared Datasets",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14914
      },
      "nvd": {
        "published": "2026-07-07T21:17:26.240",
        "lastModified": "2026-07-08T15:07:37.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50530",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The share token is checked only against sceneId and is not bound to the table and field identifiers supplied in the chart-data request.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-qcf4-345v-6vg9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/c4e85a981e53c95b1ea73757db31e3025efdc410",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50558",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T21:34:34.426Z",
      "date_published": "2026-07-29T15:34:05.042Z",
      "date_updated": "2026-07-29T17:59:48.113Z",
      "publisher": "GitHub_M",
      "title": "Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive",
      "affected": {
        "vendors": [
          "brightio"
        ],
        "products": [
          {
            "vendor": "brightio",
            "product": "penelope"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16409
      },
      "nvd": {
        "published": "2026-07-29T16:17:52.900",
        "lastModified": "2026-07-29T18:16:53.640",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50558",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Penelope extracts a session-provided tar archive without validating member paths, allowing archive entries to write outside the download directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/brightio/penelope/security/advisories/GHSA-f42x-p2mx-hm8r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/brightio/penelope/commit/a040afb5db32c7e80b5e8a2f9b2164cf911cfa62",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/brightio/penelope/releases/tag/v0.20.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 467,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50562",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-04T21:34:34.426Z",
      "date_published": "2026-07-15T16:55:03.994Z",
      "date_updated": "2026-07-15T18:13:13.693Z",
      "publisher": "GitHub_M",
      "title": "FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows",
      "affected": {
        "vendors": [
          "labring"
        ],
        "products": [
          {
            "vendor": "labring",
            "product": "FastGPT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-494",
          "name": "Download of Code Without Integrity Check",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00151,
        "percentile": 0.04751
      },
      "nvd": {
        "published": "2026-07-15T18:16:47.160",
        "lastModified": "2026-07-15T20:10:53.803",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50562",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Privileged workflow_run jobs trust and deploy artifacts built from untrusted pull-request code.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-494",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/labring/FastGPT/security/advisories/GHSA-rvgc-2c29-g876",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50622",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T09:34:23.834Z",
      "date_published": "2026-07-29T09:10:12.149Z",
      "date_updated": "2026-07-30T03:55:13.207Z",
      "publisher": "apache",
      "title": "Apache Atlas: Missing Authorization on Admin Endpoints",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Atlas"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00349,
        "percentile": 0.2755
      },
      "nvd": {
        "published": "2026-07-29T10:16:41.047",
        "lastModified": "2026-07-30T14:54:03.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50622",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Apache Atlas admin endpoints require a login but do not require the administrative role for administrative operations.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/6r9vs7g5gkp983pwvky781hofdozhgzn",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/29/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 392,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50641",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T13:27:10.270Z",
      "date_published": "2026-07-29T12:37:58.532Z",
      "date_updated": "2026-07-29T14:18:45.698Z",
      "publisher": "CERT-PL",
      "title": "Plaintext password storage in Streamsoft Business Intelligence",
      "affected": {
        "vendors": [
          "Streamsoft"
        ],
        "products": [
          {
            "vendor": "Streamsoft",
            "product": "Business Intelligence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-256",
          "name": "Plaintext Storage of a Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05664
      },
      "nvd": {
        "published": "2026-07-29T13:18:53.053",
        "lastModified": "2026-07-30T19:11:24.687",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50641",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application stores account passwords as plaintext database values.",
        "basis": [
          "CNA",
          "CWE-256"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-50641",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.streamsoft.pl/business-intelligence/",
          "host": "www.streamsoft.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50642",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T13:27:10.270Z",
      "date_published": "2026-07-29T09:46:07.962Z",
      "date_updated": "2026-07-29T12:13:51.709Z",
      "publisher": "CERT-PL",
      "title": "Terminal Escape Injection in diff‑so‑fancy",
      "affected": {
        "vendors": [
          "so-fancy"
        ],
        "products": [
          {
            "vendor": "so-fancy",
            "product": "diff-so-fancy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22269
      },
      "nvd": {
        "published": "2026-07-29T11:16:49.617",
        "lastModified": "2026-07-30T19:11:24.687",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50642",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The terminal renderer strips only SGR sequences and emits other attacker-controlled control characters, including OSC, CSI, and carriage return sequences.",
        "basis": [
          "CNA",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-41874/",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/so-fancy/diff-so-fancy",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 805,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50644",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T13:27:10.270Z",
      "date_published": "2026-07-09T09:57:32.568Z",
      "date_updated": "2026-07-09T12:09:06.573Z",
      "publisher": "CERT-PL",
      "title": "SQL Injection in SOPlanning Audit Retention Configuration",
      "affected": {
        "vendors": [
          "SOPlanning"
        ],
        "products": [
          {
            "vendor": "SOPlanning",
            "product": "SOPlanning"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19891
      },
      "nvd": {
        "published": "2026-07-09T11:16:39.887",
        "lastModified": "2026-07-09T19:49:55.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50644",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-50644",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.soplanning.org/en/",
          "host": "www.soplanning.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50646",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.830Z",
      "date_published": "2026-07-14T19:29:56.821Z",
      "date_updated": "2026-08-03T22:56:25.236Z",
      "publisher": "microsoft",
      "title": ".NET Framework Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00949,
        "percentile": 0.5778
      },
      "nvd": {
        "published": "2026-07-14T20:17:37.670",
        "lastModified": "2026-07-24T13:40:03.973",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50646",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft maps the .NET protection failure to unsafe deserialization but does not disclose the serialized input, type, or rejected-object check.",
        "basis": [
          "CNA",
          "CWE-502",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50646",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50647",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.830Z",
      "date_published": "2026-07-14T17:08:06.278Z",
      "date_updated": "2026-08-03T22:56:25.875Z",
      "publisher": "microsoft",
      "title": "Active Directory Federation Server Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 24,
        "versionEntryCount": 24,
        "versionRangeCount": 24,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01074,
        "percentile": 0.61681
      },
      "nvd": {
        "published": "2026-07-14T18:17:58.743",
        "lastModified": "2026-07-24T13:15:36.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50647",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AD FS can enter a loop whose exit condition is unreachable when processing an unauthenticated network request.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50647",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 166,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 24,
        "affectedVersionEntryCount": 24
      }
    },
    {
      "cve_id": "CVE-2026-50648",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.830Z",
      "date_published": "2026-07-14T19:29:57.312Z",
      "date_updated": "2026-08-03T22:56:26.436Z",
      "publisher": "microsoft",
      "title": ".NET Framework Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 12,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0084,
        "percentile": 0.54318
      },
      "nvd": {
        "published": "2026-07-14T20:17:37.937",
        "lastModified": "2026-07-24T13:39:49.927",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50648",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input drives an allocation without an effective size bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50648",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 12,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-50649",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.830Z",
      "date_published": "2026-07-14T19:29:57.970Z",
      "date_updated": "2026-08-03T22:56:26.919Z",
      "publisher": "microsoft",
      "title": ".NET Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 10,
        "versionEntryCount": 10,
        "versionRangeCount": 10,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00918,
        "percentile": 0.56786
      },
      "nvd": {
        "published": "2026-07-14T20:17:38.103",
        "lastModified": "2026-07-24T13:40:09.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50649",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A local .NET path deserializes attacker-controlled data as runtime objects with executable behavior.",
        "basis": [
          "CNA record",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50649",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 10,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-50650",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.830Z",
      "date_published": "2026-07-14T19:29:58.620Z",
      "date_updated": "2026-08-03T22:56:27.691Z",
      "publisher": "microsoft",
      "title": ".NET Framework Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0029,
        "percentile": 0.2121
      },
      "nvd": {
        "published": "2026-07-14T20:17:38.230",
        "lastModified": "2026-07-24T13:40:12.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50650",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": ".NET 8.0 lets attacker-controlled text cross into an executable code or template grammar.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50650",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50651",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.830Z",
      "date_published": "2026-07-14T19:40:13.750Z",
      "date_updated": "2026-08-03T22:56:28.235Z",
      "publisher": "microsoft",
      "title": ".NET Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0084,
        "percentile": 0.54319
      },
      "nvd": {
        "published": "2026-07-14T20:17:38.387",
        "lastModified": "2026-07-22T21:17:42.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50651",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network request can make .NET allocate resources without a limit or throttle until the service becomes unavailable.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50651",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-50652",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.830Z",
      "date_published": "2026-07-14T17:05:38.899Z",
      "date_updated": "2026-08-03T22:53:56.089Z",
      "publisher": "microsoft",
      "title": "Azure Active Directory Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure Active Directory"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8.1"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01149,
        "percentile": 0.63729
      },
      "nvd": {
        "published": "2026-07-14T17:17:01.673",
        "lastModified": "2026-07-24T15:41:14.763",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50652",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Azure Active Directory, attacker-controlled serialized data is converted into live objects without restricting the permitted types or behaviors.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50652",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50653",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.831Z",
      "date_published": "2026-07-14T17:05:39.461Z",
      "date_updated": "2026-08-03T22:53:56.541Z",
      "publisher": "microsoft",
      "title": "Azure Active Directory Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure Active Directory"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8.1"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0078,
        "percentile": 0.52383
      },
      "nvd": {
        "published": "2026-07-14T17:17:01.790",
        "lastModified": "2026-07-24T15:15:06.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50653",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Malformed input can enter a loop whose exit condition is never reached, monopolizing the processing thread.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50653",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 144,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50655",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.831Z",
      "date_published": "2026-07-14T17:08:09.138Z",
      "date_updated": "2026-08-03T22:56:28.786Z",
      "publisher": "microsoft",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00505,
        "percentile": 0.40388
      },
      "nvd": {
        "published": "2026-07-14T18:17:59.123",
        "lastModified": "2026-07-22T15:16:24.853",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50655",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Media Foundation copies local attacker-controlled media data beyond a heap allocation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50655",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50657",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.831Z",
      "date_published": "2026-07-14T17:08:09.761Z",
      "date_updated": "2026-08-03T22:56:29.328Z",
      "publisher": "microsoft",
      "title": "Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Defender for Endpoint for Mac"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-359",
          "name": "Exposure of Private Personal Information to an Unauthorized Actor",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00437,
        "percentile": 0.3596
      },
      "nvd": {
        "published": "2026-07-14T18:17:59.303",
        "lastModified": "2026-07-22T16:40:39.537",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50657",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft Defender exposes private personal information to a local authorized caller, but the record does not identify the data, output surface, or missing disclosure check.",
        "basis": [
          "CNA",
          "CWE-359"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50657",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 150,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50658",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.831Z",
      "date_published": "2026-07-14T17:08:10.310Z",
      "date_updated": "2026-08-03T22:56:29.810Z",
      "publisher": "microsoft",
      "title": "Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Defender for Endpoint for Mac"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08703
      },
      "nvd": {
        "published": "2026-07-14T18:17:59.563",
        "lastModified": "2026-07-22T16:35:50.343",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50658",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A race between state-changing operations permits an otherwise forbidden result.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50658",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50659",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.831Z",
      "date_published": "2026-07-14T19:40:15.949Z",
      "date_updated": "2026-08-03T22:56:30.290Z",
      "publisher": "microsoft",
      "title": ".NET Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 3.5 AND 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft .NET Framework 4.8.1"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.12"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2022 version 17.14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Visual Studio 2026 version 18.7"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0055,
        "percentile": 0.42924
      },
      "nvd": {
        "published": "2026-07-14T20:17:38.917",
        "lastModified": "2026-07-24T13:39:30.693",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50659",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The .NET 10.0 output path emits attacker-influenced data without the escaping required by the downstream interpreter context.",
        "basis": [
          "CNA",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50659",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-50661",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.831Z",
      "date_published": "2026-07-14T17:08:11.402Z",
      "date_updated": "2026-08-03T22:56:30.759Z",
      "publisher": "microsoft",
      "title": "Windows BitLocker Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00723,
        "percentile": 0.50453
      },
      "nvd": {
        "published": "2026-07-14T18:17:59.720",
        "lastModified": "2026-07-22T15:21:26.967",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50661",
        "family": "HARDWARE_PHYSICAL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A physical interaction can bypass BitLocker protection, but the public record does not disclose the interface, measurement, or protection state that fails.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50663",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.831Z",
      "date_published": "2026-07-14T17:04:40.205Z",
      "date_updated": "2026-08-03T22:53:04.301Z",
      "publisher": "microsoft",
      "title": "Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Age of Empires II: Definitive Edition Game"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00679,
        "percentile": 0.48838
      },
      "nvd": {
        "published": "2026-07-14T17:17:01.930",
        "lastModified": "2026-07-24T19:06:29.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50663",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Age of Empires II: Definitive Edition Game accepts a filesystem or upload target outside its intended namespace, while the path field and selection check are not public.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50663",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 133,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50665",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.831Z",
      "date_published": "2026-07-14T17:09:22.137Z",
      "date_updated": "2026-08-03T22:57:42.267Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 4.5,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27665
      },
      "nvd": {
        "published": "2026-07-14T18:18:00.080",
        "lastModified": "2026-07-16T15:15:36.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50665",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Office reads beyond the bounds of a memory object.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50665",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50666",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.832Z",
      "date_published": "2026-07-14T17:08:12.029Z",
      "date_updated": "2026-08-03T22:56:31.337Z",
      "publisher": "microsoft",
      "title": "Windows Remote Access Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00618,
        "percentile": 0.46181
      },
      "nvd": {
        "published": "2026-07-14T18:18:00.240",
        "lastModified": "2026-07-23T05:16:36.230",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50666",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path continues using an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50666",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-50667",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.832Z",
      "date_published": "2026-07-14T17:08:12.500Z",
      "date_updated": "2026-08-03T22:56:31.886Z",
      "publisher": "microsoft",
      "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.02012,
        "percentile": 0.7895
      },
      "nvd": {
        "published": "2026-07-14T18:18:00.433",
        "lastModified": "2026-07-22T15:02:41.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50667",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Concurrent paths access shared state without the synchronization needed to preserve its lifetime and authorization invariants.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50667",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 168,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50668",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.832Z",
      "date_published": "2026-07-14T17:08:13.126Z",
      "date_updated": "2026-08-03T22:56:32.369Z",
      "publisher": "microsoft",
      "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22792
      },
      "nvd": {
        "published": "2026-07-14T18:18:00.623",
        "lastModified": "2026-07-22T15:03:36.870",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50668",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data is written beyond the boundary of a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50668",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50669",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.832Z",
      "date_published": "2026-07-14T17:08:13.683Z",
      "date_updated": "2026-08-03T22:56:32.992Z",
      "publisher": "microsoft",
      "title": "Windows Telephony Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04945
      },
      "nvd": {
        "published": "2026-07-14T18:18:00.810",
        "lastModified": "2026-07-22T15:26:44.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50669",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Windows Telephony Service has a shared-state race that permits a local authorized caller to cross the intended privilege boundary.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50669",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50670",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:33:50.832Z",
      "date_published": "2026-07-14T17:08:14.314Z",
      "date_updated": "2026-08-03T22:56:33.462Z",
      "publisher": "microsoft",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.0000000000000009,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15137
      },
      "nvd": {
        "published": "2026-07-14T18:18:01.063",
        "lastModified": "2026-07-16T20:01:27.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50670",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Win32k performs an out-of-bounds read in a heap-buffer processing path reachable by a local attacker.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-122",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50670",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50672",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.079Z",
      "date_published": "2026-07-14T17:08:14.947Z",
      "date_updated": "2026-08-03T22:56:34.047Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04944
      },
      "nvd": {
        "published": "2026-07-14T18:18:01.290",
        "lastModified": "2026-07-22T15:37:02.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50672",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A race in Windows NTFS leaves a kernel object reachable after it has been freed.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50672",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 91,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50673",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.079Z",
      "date_published": "2026-07-14T17:08:15.424Z",
      "date_updated": "2026-08-03T22:56:34.562Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09967
      },
      "nvd": {
        "published": "2026-07-14T18:18:01.457",
        "lastModified": "2026-07-16T19:59:23.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50673",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A local Windows Kernel path dereferences a null pointer instead of maintaining a valid object reference, although the elevation transition is not public.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": "CWE-367 is also listed, but the narrative does not disclose the time-of-check/time-of-use sequence."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50673",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50674",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.079Z",
      "date_published": "2026-07-14T17:08:15.982Z",
      "date_updated": "2026-08-03T22:56:35.131Z",
      "publisher": "microsoft",
      "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17607
      },
      "nvd": {
        "published": "2026-07-14T18:18:01.670",
        "lastModified": "2026-07-22T16:17:18.497",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50674",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 11 Version 24H2 path can dereference an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50674",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50675",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.079Z",
      "date_published": "2026-07-14T17:05:08.316Z",
      "date_updated": "2026-08-03T22:53:28.641Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00325,
        "percentile": 0.24995
      },
      "nvd": {
        "published": "2026-07-14T17:17:02.053",
        "lastModified": "2026-07-15T18:30:27.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50675",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Excel writes beyond a heap allocation while processing a malicious workbook.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50675",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-50676",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.079Z",
      "date_published": "2026-07-14T17:08:16.538Z",
      "date_updated": "2026-08-03T22:56:35.612Z",
      "publisher": "microsoft",
      "title": "Windows Media Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09939
      },
      "nvd": {
        "published": "2026-07-14T18:18:01.897",
        "lastModified": "2026-07-22T16:18:08.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50676",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A protected object can change between the check and use steps in Windows 11 Version 24H2, invalidating the state assumed by the later operation.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50676",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-50677",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.079Z",
      "date_published": "2026-07-14T17:08:17.092Z",
      "date_updated": "2026-08-03T22:56:36.155Z",
      "publisher": "microsoft",
      "title": "Windows Media Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14952
      },
      "nvd": {
        "published": "2026-07-14T18:18:02.063",
        "lastModified": "2026-07-22T16:18:46.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50677",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 11 Version 24H2 retains or reuses an object after its storage has been freed, allowing later processing to access invalid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50677",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 92,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-50678",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:05:08.873Z",
      "date_updated": "2026-08-03T22:53:29.275Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 3.3,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23838
      },
      "nvd": {
        "published": "2026-07-14T17:17:02.187",
        "lastModified": "2026-07-15T18:30:06.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50678",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Excel writes beyond a heap allocation while processing attacker-controlled local content.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50678",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-50679",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:08:18.786Z",
      "date_updated": "2026-08-03T22:56:37.744Z",
      "publisher": "microsoft",
      "title": "Windows Search Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23437
      },
      "nvd": {
        "published": "2026-07-14T18:18:02.310",
        "lastModified": "2026-07-22T16:20:10.023",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50679",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 11 Version 24H2 writes attacker-controlled data beyond a heap allocation because the copy or allocation size is not validated.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50679",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 125,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50680",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:08:19.888Z",
      "date_updated": "2026-08-03T22:56:38.964Z",
      "publisher": "microsoft",
      "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.39999999999999947,
      "epss": {
        "score": 0.00341,
        "percentile": 0.2675
      },
      "nvd": {
        "published": "2026-07-14T18:18:02.470",
        "lastModified": "2026-07-22T16:18:10.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50680",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Hyper-V writes beyond a heap allocation while processing a local authorized request.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50680",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50681",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:08:20.427Z",
      "date_updated": "2026-08-03T22:56:39.639Z",
      "publisher": "microsoft",
      "title": "Windows Secure Channel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00458,
        "percentile": 0.37497
      },
      "nvd": {
        "published": "2026-07-14T18:18:02.647",
        "lastModified": "2026-07-22T16:18:10.427",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50681",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows Cryptographic Services exposes sensitive local information to an authorized caller, but the public record does not disclose the output or isolation failure.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50681",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 155,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50682",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:08:21.386Z",
      "date_updated": "2026-08-03T22:56:40.897Z",
      "publisher": "microsoft",
      "title": "Active Directory Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00891,
        "percentile": 0.55897
      },
      "nvd": {
        "published": "2026-07-14T18:18:02.820",
        "lastModified": "2026-07-22T16:18:10.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50682",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Active Directory reads beyond an allocated buffer while processing network input.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50682",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-50683",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:08:22.574Z",
      "date_updated": "2026-08-03T22:56:42.012Z",
      "publisher": "microsoft",
      "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00488,
        "percentile": 0.39394
      },
      "nvd": {
        "published": "2026-07-14T18:18:02.967",
        "lastModified": "2026-07-21T19:55:26.823",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50683",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50683",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 127,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-50684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:08:18.301Z",
      "date_updated": "2026-08-03T22:56:37.276Z",
      "publisher": "microsoft",
      "title": "Active Directory Federation Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29976
      },
      "nvd": {
        "published": "2026-07-14T18:18:03.163",
        "lastModified": "2026-07-21T19:55:23.760",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50684",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50684",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-50685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:08:21.944Z",
      "date_updated": "2026-08-03T22:56:41.448Z",
      "publisher": "microsoft",
      "title": "Windows DHCP Server Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 12,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00619,
        "percentile": 0.46224
      },
      "nvd": {
        "published": "2026-07-14T18:18:03.603",
        "lastModified": "2026-07-21T19:55:20.847",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50685",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path releases the same allocation twice.",
        "basis": [
          "CNA",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50685",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 12,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-50686",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:08:23.680Z",
      "date_updated": "2026-08-03T22:56:43.142Z",
      "publisher": "microsoft",
      "title": "Windows OLE Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00659,
        "percentile": 0.48027
      },
      "nvd": {
        "published": "2026-07-14T18:18:03.900",
        "lastModified": "2026-07-23T05:16:36.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50686",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 accesses an object through an incompatible type, invalidating the layout or lifetime assumptions used by the access.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50686",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 140,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-50687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:08:23.121Z",
      "date_updated": "2026-08-03T22:56:42.568Z",
      "publisher": "microsoft",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.0000000000000009,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24116
      },
      "nvd": {
        "published": "2026-07-14T18:18:04.310",
        "lastModified": "2026-07-22T16:18:11.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50687",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A reachable path retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50687",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-50688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:08:19.404Z",
      "date_updated": "2026-08-03T22:56:38.386Z",
      "publisher": "microsoft",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01719,
        "percentile": 0.75213
      },
      "nvd": {
        "published": "2026-07-14T18:18:04.580",
        "lastModified": "2026-07-16T19:58:42.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50688",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50688",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50689",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:08:24.168Z",
      "date_updated": "2026-08-03T22:56:43.776Z",
      "publisher": "microsoft",
      "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14952
      },
      "nvd": {
        "published": "2026-07-14T18:18:05.017",
        "lastModified": "2026-07-22T16:18:11.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50689",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Clipboard Server can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50689",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.080Z",
      "date_published": "2026-07-14T17:08:25.350Z",
      "date_updated": "2026-08-03T22:56:44.998Z",
      "publisher": "microsoft",
      "title": "Windows SMB Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.31453
      },
      "nvd": {
        "published": "2026-07-14T18:18:05.263",
        "lastModified": "2026-07-22T16:18:11.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50690",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows SMB returns data derived from a resource that was used before initialization.",
        "basis": [
          "CNA record",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50690",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50692",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.081Z",
      "date_published": "2026-07-14T17:08:25.981Z",
      "date_updated": "2026-08-03T22:56:45.573Z",
      "publisher": "microsoft",
      "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24115
      },
      "nvd": {
        "published": "2026-07-14T18:18:05.440",
        "lastModified": "2026-07-22T16:18:12.100",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50692",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 writes attacker-controlled data beyond a heap buffer boundary.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50692",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-50694",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.081Z",
      "date_published": "2026-07-14T17:05:14.115Z",
      "date_updated": "2026-08-03T22:53:33.897Z",
      "publisher": "microsoft",
      "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00662,
        "percentile": 0.4815
      },
      "nvd": {
        "published": "2026-07-14T17:17:02.327",
        "lastModified": "2026-07-22T16:18:12.293",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50694",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows SSTP accesses an object after it has been freed on an unauthenticated network path.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50694",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 129,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.081Z",
      "date_published": "2026-07-14T17:04:41.303Z",
      "date_updated": "2026-08-03T22:53:05.568Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00796,
        "percentile": 0.52904
      },
      "nvd": {
        "published": "2026-07-14T17:17:02.493",
        "lastModified": "2026-07-22T16:18:12.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50695",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 10 Version 1607, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50695",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50696",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.081Z",
      "date_published": "2026-07-14T17:04:43.447Z",
      "date_updated": "2026-08-03T22:53:07.763Z",
      "publisher": "microsoft",
      "title": "Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00816,
        "percentile": 0.53583
      },
      "nvd": {
        "published": "2026-07-14T17:17:02.670",
        "lastModified": "2026-07-16T12:26:03.497",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50696",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input exceeds a heap allocation because the write is not bounded to the allocated size.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50696",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-50697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T14:35:07.081Z",
      "date_published": "2026-07-14T17:04:44.739Z",
      "date_updated": "2026-08-03T22:53:08.942Z",
      "publisher": "microsoft",
      "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20611
      },
      "nvd": {
        "published": "2026-07-14T17:17:02.813",
        "lastModified": "2026-07-22T16:18:12.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50697",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Common Log File System Driver exposes protected information on a local authorized path, but the data, observer, and output operation are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50697",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-50721",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T16:10:05.751Z",
      "date_published": "2026-07-02T21:44:09.423Z",
      "date_updated": "2026-07-07T17:01:58.011Z",
      "publisher": "libreswan",
      "title": "IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload",
      "affected": {
        "vendors": [
          "The Libreswan Project"
        ],
        "products": [
          {
            "vendor": "The Libreswan Project",
            "product": "libreswan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:d42dc95b-23f1-4e06-9076-20753a0fb0df",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 2.1999999999999993,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31405
      },
      "nvd": {
        "published": "2026-07-02T22:16:43.367",
        "lastModified": "2026-07-09T15:46:40.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50721",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RSA_authenticate_hash_signature_raw_rsa accepts a PKCS #1 v1.5 signature whose embedded authentication hash is shorter than required, enabling forgery with small public exponents and an assertion crash.",
        "basis": [
          "CNA",
          "CWE-347",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://libreswan.org/security/CVE-2026-50721/CVE-2026-50721.txt",
          "host": "libreswan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://libreswan.org/security/CVE-2026-50721/",
          "host": "libreswan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch"
          ]
        },
        {
          "url": "https://libreswan.org/security/CVE-2026-50722/CVE-2026-50722.txt",
          "host": "libreswan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "related"
          ]
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc2313",
          "host": "www.rfc-editor.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Technical Description",
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 765,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-50722",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T16:10:05.751Z",
      "date_published": "2026-07-02T21:34:41.413Z",
      "date_updated": "2026-07-07T17:02:06.722Z",
      "publisher": "libreswan",
      "title": "IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload",
      "affected": {
        "vendors": [
          "The Libreswan Project"
        ],
        "products": [
          {
            "vendor": "The Libreswan Project",
            "product": "libreswan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:d42dc95b-23f1-4e06-9076-20753a0fb0df",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 2.1999999999999993,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27292
      },
      "nvd": {
        "published": "2026-07-02T22:16:43.550",
        "lastModified": "2026-07-09T15:47:00.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50722",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DER signature validation accepts a malformed encoding instead of enforcing a unique valid representation.",
        "basis": [
          "CNA",
          "CWE-347",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://libreswan.org/security/CVE-2026-50722/CVE-2026-50722.txt",
          "host": "libreswan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://libreswan.org/security/CVE-2026-50722/",
          "host": "libreswan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch"
          ]
        },
        {
          "url": "https://libreswan.org/security/CVE-2026-50721/CVE-2026-50721.txt",
          "host": "libreswan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "related"
          ]
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc8017",
          "host": "www.rfc-editor.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Technical Description",
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 738,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-50735",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T19:13:51.103Z",
      "date_published": "2026-07-28T17:55:12.049Z",
      "date_updated": "2026-07-28T19:02:17.182Z",
      "publisher": "EDB",
      "title": "pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copying them, resulting in an out-of-bounds read.",
      "affected": {
        "vendors": [
          "EnterpriseDB"
        ],
        "products": [
          {
            "vendor": "EnterpriseDB",
            "product": "pglogical"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:20be33e2-bf35-4d13-8fad-18bd2f3e3659",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09358
      },
      "nvd": {
        "published": "2026-07-28T19:17:36.540",
        "lastModified": "2026-07-30T16:31:26.770",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50735",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pglogical path trusts a length or offset that can read beyond the initialized input buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.enterprisedb.com/docs/security/advisories/cve202650735/",
          "host": "www.enterprisedb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 822,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50736",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T19:13:51.103Z",
      "date_published": "2026-07-28T17:55:27.283Z",
      "date_updated": "2026-07-28T18:54:34.942Z",
      "publisher": "EDB",
      "title": "The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a ...",
      "affected": {
        "vendors": [
          "EnterpriseDB"
        ],
        "products": [
          {
            "vendor": "EnterpriseDB",
            "product": "pglogical"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:20be33e2-bf35-4d13-8fad-18bd2f3e3659",
          "type": "Secondary",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09357
      },
      "nvd": {
        "published": "2026-07-28T19:17:36.700",
        "lastModified": "2026-07-30T16:31:26.770",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50736",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "pglogical executes publisher-controlled queue payloads as SQL with the subscriber apply worker's superuser authority.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.enterprisedb.com/docs/security/advisories/cve202650736/",
          "host": "www.enterprisedb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 876,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T19:13:51.103Z",
      "date_published": "2026-07-28T17:55:43.126Z",
      "date_updated": "2026-07-28T18:52:19.292Z",
      "publisher": "EDB",
      "title": "When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber.",
      "affected": {
        "vendors": [
          "EnterpriseDB"
        ],
        "products": [
          {
            "vendor": "EnterpriseDB",
            "product": "pglogical"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-250",
          "name": "Execution with Unnecessary Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:20be33e2-bf35-4d13-8fad-18bd2f3e3659",
          "type": "Secondary",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09358
      },
      "nvd": {
        "published": "2026-07-28T19:17:36.827",
        "lastModified": "2026-07-30T16:31:26.770",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50737",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pglogical subscriber evaluates publisher-influenced default expressions inside a superuser-equivalent apply worker when replicated rows omit columns.",
        "basis": [
          "CNA",
          "CWE-250"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.enterprisedb.com/docs/security/advisories/cve202650737/",
          "host": "www.enterprisedb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 987,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-05T19:13:51.103Z",
      "date_published": "2026-07-28T17:55:58.209Z",
      "date_updated": "2026-07-28T18:46:25.423Z",
      "publisher": "EDB",
      "title": "A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has been freed or recycled during normal worker lifecycle events.",
      "affected": {
        "vendors": [
          "EnterpriseDB"
        ],
        "products": [
          {
            "vendor": "EnterpriseDB",
            "product": "pglogical"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:20be33e2-bf35-4d13-8fad-18bd2f3e3659",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.2239
      },
      "nvd": {
        "published": "2026-07-28T19:17:36.967",
        "lastModified": "2026-07-30T16:31:26.770",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50738",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A pglogical worker slot can be freed and recycled while another path still treats it as the original live worker.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.enterprisedb.com/docs/security/advisories/cve202650738/",
          "host": "www.enterprisedb.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 646,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50743",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-06T15:00:09.779Z",
      "date_published": "2026-07-20T16:53:12.618Z",
      "date_updated": "2026-07-20T18:23:49.327Z",
      "publisher": "hackerone",
      "title": "A CSRF vulnerability exists in the `zone-include.",
      "affected": {
        "vendors": [
          "Revive"
        ],
        "products": [
          {
            "vendor": "Revive",
            "product": "Adserver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15013
      },
      "nvd": {
        "published": "2026-07-20T17:17:57.500",
        "lastModified": "2026-07-23T18:27:26.193",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50743",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://hackerone.com/reports/3781691",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50746",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-06T15:00:09.780Z",
      "date_published": "2026-07-02T14:49:16.907Z",
      "date_updated": "2026-07-02T15:52:15.315Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Connect Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02505,
        "percentile": 0.83155
      },
      "nvd": {
        "published": "2026-07-02T15:17:02.723",
        "lastModified": "2026-07-29T19:16:06.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50746",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "UniFi Connect exposes an unauthenticated access-control failure that reaches command execution on the host, while the advisory does not reveal the endpoint or command sink.",
        "basis": [
          "CNA",
          "CWE-284",
          "Ubiquiti Security Advisory Bulletin 066"
        ],
        "deepDive": true,
        "notes": "Inspected https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc. It confirms unauthenticated network access, affected UniFi Connect Application through 3.24.16, fix 3.24.20, and command injection impact, but no endpoint, permission check, or sink."
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-06T15:00:09.780Z",
      "date_published": "2026-07-02T14:49:17.029Z",
      "date_updated": "2026-07-02T15:52:10.116Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Talk Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00488,
        "percentile": 0.39371
      },
      "nvd": {
        "published": "2026-07-02T15:17:02.877",
        "lastModified": "2026-07-09T13:21:57.180",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50747",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50748",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-06T15:00:09.780Z",
      "date_published": "2026-07-02T14:49:16.696Z",
      "date_updated": "2026-07-02T16:10:26.883Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Access Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01207,
        "percentile": 0.6534
      },
      "nvd": {
        "published": "2026-07-02T15:17:02.990",
        "lastModified": "2026-07-09T13:21:36.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-50748",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "UniFi Access accepts low-privilege network input that reaches a host command without command-syntax neutralization.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T17:58:49.988Z",
      "publisher": "mitre",
      "title": "An issue in DayuanJiang next-ai-draw-io 0.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00425,
        "percentile": 0.35028
      },
      "nvd": {
        "published": "2026-07-21T20:17:01.733",
        "lastModified": "2026-07-22T18:17:00.540",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50755",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "getUserIdFromRequest treats the first client-supplied X-Forwarded-For value as identity for quotas, telemetry, and usage accounting without trusted-proxy validation.",
        "basis": [
          "CNA",
          "CWE-290",
          "official project issue"
        ],
        "deepDive": true,
        "notes": "Inspected https://github.com/DayuanJiang/next-ai-draw-io/issues/750 in the official project repository; the issue shows the vulnerable source and downstream uses but no maintainer fix or linked patch, and no reproduction was performed."
      },
      "references": [
        {
          "url": "https://github.com/DayuanJiang/next-ai-draw-io/issues/750",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/August829/Yu/blob/main/CVE-2026-50755.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 140,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T17:57:13.872Z",
      "publisher": "mitre",
      "title": "An issue in DayuanJiang next-ai-draw-io 0.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1390",
          "name": "Weak Authentication",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.2959
      },
      "nvd": {
        "published": "2026-07-21T20:17:01.843",
        "lastModified": "2026-07-22T18:17:00.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50756",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says the x-ai-provider component exposes information but does not disclose a token, request, output, or validation failure.",
        "basis": [
          "CNA",
          "CWE-1390"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/DayuanJiang/next-ai-draw-io/issues/749",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/August829/Yu/blob/main/CVE-2026-50756.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 135,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50757",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T17:54:22.794Z",
      "publisher": "mitre",
      "title": "Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00464,
        "percentile": 0.37876
      },
      "nvd": {
        "published": "2026-07-21T20:17:01.947",
        "lastModified": "2026-07-22T18:17:00.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50757",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MCP server accepts traversal segments that select a file outside its intended directory and can place executable content there.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/DayuanJiang/next-ai-draw-io/issues/754",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/August829/Yu/blob/main/CVE-2026-50757.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 155,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50758",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T17:52:05.589Z",
      "publisher": "mitre",
      "title": "Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00506,
        "percentile": 0.40436
      },
      "nvd": {
        "published": "2026-07-21T20:17:02.053",
        "lastModified": "2026-07-22T18:17:01.043",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50758",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/DayuanJiang/next-ai-draw-io/issues/755",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/August829/Yu/blob/main/CVE-2026-50758.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/August829/CVEP/issues/17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 145,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50759",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T17:47:44.921Z",
      "publisher": "mitre",
      "title": "An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37747
      },
      "nvd": {
        "published": "2026-07-21T20:17:02.163",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50759",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The state and instance-deletion endpoints accept remote requests without authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/exo-explore/exo/issues/1833",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/August829/Yu/blob/main/CVE-2026-50759.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50782",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-30T17:39:24.075Z",
      "publisher": "mitre",
      "title": "Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00349,
        "percentile": 0.27577
      },
      "nvd": {
        "published": "2026-07-29T21:17:47.200",
        "lastModified": "2026-07-30T19:18:04.930",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50782",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The XML parser in the affected component resolves attacker-supplied external entities instead of keeping external resources outside the document grammar.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dihe123/CNVD-Jinher-OA-XXE/tree/main",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/dihe123/CNVD-Jinher-OA-XXE/blob/main/README.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50810",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-07T00:00:00.000Z",
      "date_updated": "2026-07-09T14:34:16.133Z",
      "publisher": "mitre",
      "title": "A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02241
      },
      "nvd": {
        "published": "2026-07-07T23:16:54.887",
        "lastModified": "2026-07-10T18:50:20.507",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50810",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component in CVE-2026-50810 continues through a path where a required object pointer is null and dereferences that pointer instead of rejecting the input or state.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gpac/gpac/issues/3507",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/gpac/gpac/commit/b35c61f104b85fbb16520ac2838d5d2ef70845b5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/junius-sec/0c67bf67a268ff8861100bfc132e801c",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50811",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-07T00:00:00.000Z",
      "date_updated": "2026-07-08T19:47:19.631Z",
      "publisher": "mitre",
      "title": "An out-of-bounds read vulnerability exists in FreeType 2.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20079
      },
      "nvd": {
        "published": "2026-07-07T23:16:55.017",
        "lastModified": "2026-07-09T17:02:37.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50811",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FT_Get_Var_Design_Coordinates can make TT_Get_Var_Design read beyond valid variation data in ttgxvar.c.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.freedesktop.org/freetype/freetype/-/issues/1436",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.freedesktop.org/freetype/freetype/-/commit/5a280ecde6f324de0d226261036e736e0cb49a71",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/freetype/freetype/commit/5a280ecde6f324de0d226261036e736e0cb49a71",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/junius-sec/6dd0fb25b643f89914083a38e5e57ace",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.freedesktop.org/freetype/freetype/-/work_items/1436",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-08T20:11:45.210Z",
      "publisher": "mitre",
      "title": "A NULL pointer dereference in the SQLite Session Extension in SQLite 3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01619
      },
      "nvd": {
        "published": "2026-07-08T18:16:32.400",
        "lastModified": "2026-07-09T19:48:15.277",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50812",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "the affected component passes a null value pointer into code that dereferences it while applying a malformed changeset.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sqlite.org/src/info/e807d4e3798efd53",
          "host": "sqlite.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/junius-sec/bb556f333957c5226dede314db0e9e91",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 369,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50813",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-08T20:12:52.184Z",
      "publisher": "mitre",
      "title": "An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AC:L/AV:L/A:H/C:L/I:N/PR:N/S:U/UI:R"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0011,
        "percentile": 0.01487
      },
      "nvd": {
        "published": "2026-07-08T18:16:32.560",
        "lastModified": "2026-07-09T19:48:15.277",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50813",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SQLite's Session Extension merge path reads beyond the valid changeset buffer.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sqlite.org/src/info/869a51ae84df",
          "host": "sqlite.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/sqlite/sqlite/commit/c597ed79d1bd03f57198d10d1f431adda293cf2e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/junius-sec/f8acb66bafb80134c8e1a1c8c7c9f4f4",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-50986",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-08-03T19:27:28.278Z",
      "publisher": "mitre",
      "title": "PrestaShop module, totadministrativemandate <1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03388
      },
      "nvd": {
        "published": "2026-07-31T21:17:31.610",
        "lastModified": "2026-08-03T20:17:24.537",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-50986",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The payment validation controller performs an order-confirmation request without a CSRF token binding it to the user's intent.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://addons.prestashop.com/fr/paiement-transfert-bancaire/6297-mandat-administratif.html",
          "host": "addons.prestashop.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://prestafence.com/en/2026/07/cve-2026-50986-csrf-administrative-mandate/",
          "host": "prestafence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 231,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51025",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-21T14:57:58.455Z",
      "publisher": "mitre",
      "title": "Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11878
      },
      "nvd": {
        "published": "2026-07-20T22:17:15.553",
        "lastModified": "2026-07-21T20:27:18.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51025",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Member Marketing System emits attacker-controlled ClientMessageController data as active browser markup without the required encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/W000i/vuln/issues/4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 167,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51026",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-20T18:19:50.537Z",
      "publisher": "mitre",
      "title": "Directory Traversal vulnerability in FileThingie v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:L/S:U/UI:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00848,
        "percentile": 0.54537
      },
      "nvd": {
        "published": "2026-07-20T16:17:04.777",
        "lastModified": "2026-07-21T20:27:18.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51026",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/leefish/filethingie",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/SpeWnz/Vulnerability-Research/tree/main/CVE-2026-51026",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51027",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-20T18:22:14.005Z",
      "publisher": "mitre",
      "title": "An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00342,
        "percentile": 0.26879
      },
      "nvd": {
        "published": "2026-07-20T16:17:04.897",
        "lastModified": "2026-07-21T20:27:18.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51027",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "FileThingie counts raw slash characters to authorize upward moves while the operating system normalizes repeated slashes, so an authenticated user can move a file outside the configured root.",
        "basis": [
          "CNA",
          "CWE-200",
          "upstream ft2.php source",
          "original disclosure"
        ],
        "deepDive": true,
        "notes": "The original disclosure and the upstream ft2.php source were inspected at https://github.com/SpeWnz/Vulnerability-Research/tree/main/CVE-2026-51027 and https://github.com/leefish/filethingie/blob/master/ft2.php; the CNA description and CWE do not match the source-traced path traversal."
      },
      "references": [
        {
          "url": "https://github.com/leefish/filethingie",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/SpeWnz/Vulnerability-Research/tree/main/CVE-2026-51027",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51031",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-21T14:57:51.916Z",
      "publisher": "mitre",
      "title": "FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker to obtain sensitive information",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.20993
      },
      "nvd": {
        "published": "2026-07-20T22:17:15.663",
        "lastModified": "2026-07-21T20:27:18.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51031",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://xinyi234.github.io/2026/04/13/FlareSolverr-Server-Side-Request-Forgery-SSRF-Vulnerability-Report/",
          "host": "xinyi234.github.io",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51077",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_updated": "2026-07-28T14:55:20.561Z",
      "publisher": "mitre",
      "title": "SQL injection vulnerability in Dede CMS v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23402
      },
      "nvd": {
        "published": "2026-07-27T22:17:30.570",
        "lastModified": "2026-07-28T16:23:19.783",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51077",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dedecms.com/",
          "host": "www.dedecms.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitee.com/etera1i2e/cve-2026-51077/blob/master/README.md",
          "host": "gitee.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 168,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51078",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_updated": "2026-07-28T14:55:14.812Z",
      "publisher": "mitre",
      "title": "An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00315,
        "percentile": 0.2392
      },
      "nvd": {
        "published": "2026-07-27T22:17:30.690",
        "lastModified": "2026-07-28T16:23:19.783",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51078",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Sensitive data is returned, stored, or left readable through an output path that lacks the required disclosure boundary.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dedecms.com/",
          "host": "www.dedecms.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitee.com/etera1i2e/cve-2026-51078/blob/master/README.md",
          "host": "gitee.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 150,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51080",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-17T16:55:36.699Z",
      "publisher": "mitre",
      "title": "libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22288
      },
      "nvd": {
        "published": "2026-07-17T14:17:24.270",
        "lastModified": "2026-07-17T18:47:13.683",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51080",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libpvestorage-perl parses attacker-controlled XML while allowing external entities to resolve outside the intended document boundary.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/post-849970",
          "host": "forum.proxmox.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 127,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-17T15:13:18.023Z",
      "publisher": "mitre",
      "title": "A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04571
      },
      "nvd": {
        "published": "2026-07-17T15:16:46.753",
        "lastModified": "2026-07-17T18:29:27.757",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51081",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input is rendered by Proxmox VE as executable HTML or browser script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/post-849973",
          "host": "forum.proxmox.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-17T16:44:44.740Z",
      "publisher": "mitre",
      "title": "A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12778
      },
      "nvd": {
        "published": "2026-07-17T15:16:46.867",
        "lastModified": "2026-07-17T18:28:39.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51082",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A race between vncproxy and vncwebsocket can attach one user to another user's virtual-machine session.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/post-849971",
          "host": "forum.proxmox.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 422,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51083",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-17T15:26:43.644Z",
      "publisher": "mitre",
      "title": "Incorrect access control in Proxmox Virtual Environment (PVE) 9.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.1014
      },
      "nvd": {
        "published": "2026-07-17T15:16:46.973",
        "lastModified": "2026-07-17T18:29:27.757",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51083",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The cloudinit dump API lets a limited PVE user retrieve password hashes without sufficient permission.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-2#post-84997",
          "host": "forum.proxmox.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51105",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-14T15:21:29.814Z",
      "publisher": "mitre",
      "title": "Buffer Overflow vulnerability in aMULE-Project aMule v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24272
      },
      "nvd": {
        "published": "2026-07-14T15:17:04.023",
        "lastModified": "2026-07-15T20:27:37.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51105",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CVE-2026-51105 writes attacker-controlled data beyond a stack buffer boundary.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/amule-project/amule/issues/445",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51119",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-10T00:00:00.000Z",
      "date_updated": "2026-07-10T18:03:27.940Z",
      "publisher": "mitre",
      "title": "An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30932
      },
      "nvd": {
        "published": "2026-07-10T17:16:57.587",
        "lastModified": "2026-07-10T19:17:23.787",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51119",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The CreateAppUser component permits privilege escalation, but no public vendor material identifies the missing role or permission check.",
        "basis": [
          "CNA",
          "CWE-269",
          "Invixium official product site"
        ],
        "deepDive": true,
        "notes": "Primary-source deep dive: https://www.invixium.com/ ; the linked vendor surface identifies IXM WEB but publishes no CVE advisory or failing CreateAppUser authorization rule."
      },
      "references": [
        {
          "url": "http://affected.com",
          "host": "affected.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://invixium.com",
          "host": "invixium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/A17-ba/CVE-2026-51119",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://invixium.com",
          "host": "invixium.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51235",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:33:57.338Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51244",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:02.161Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51251",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:06.040Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51252",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:06.835Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51254",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:08.051Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51259",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:10.638Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51260",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:11.541Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51261",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:12.351Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51263",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:13.557Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51266",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:15.237Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51267",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:15.952Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51268",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:16.737Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51269",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:17.463Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51270",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:18.237Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51271",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:18.961Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51272",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:19.755Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51273",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:20.551Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51274",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:21.337Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51275",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-28T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:22.056Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51290",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:28.746Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51291",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:29.537Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51292",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:30.252Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51293",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:31.037Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51294",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:31.751Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51295",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:32.536Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51296",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:33.252Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51297",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:34.058Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51298",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:34.844Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51300",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:35.949Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51302",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:37.145Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51303",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:38.009Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51304",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_rejected": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T14:34:39.044Z",
      "publisher": "mitre",
      "title": "Rejected reason: DO NOT USE THIS CVE RECORD.",
      "rejected_reason": "DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none."
    },
    {
      "cve_id": "CVE-2026-51380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-16T15:24:41.397Z",
      "publisher": "mitre",
      "title": "Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00411,
        "percentile": 0.33759
      },
      "nvd": {
        "published": "2026-07-15T21:16:54.437",
        "lastModified": "2026-07-16T16:19:12.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51380",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Tenda UploadCfg endpoint copies attacker-controlled configuration data beyond a fixed-size buffer.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tendacn.com/material/show/104968",
          "host": "www.tendacn.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/snyi001/CV/blob/main/11.zip",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/snyi001/Tenda-AC10-v3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51385",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-07T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-21T14:57:44.100Z",
      "publisher": "mitre",
      "title": "An issue in safishamsi Open-Source GRAPHIFY v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AC:H/AV:N/A:N/C:H/I:L/PR:N/S:C/UI:R"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00401,
        "percentile": 0.32907
      },
      "nvd": {
        "published": "2026-07-20T22:17:15.773",
        "lastModified": "2026-07-23T18:28:20.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51385",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The CVE record attributes remote code execution to a code-injection path across Graphify URL-fetch functions but does not identify the executable value or interpreter sink.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://graphify.com",
          "host": "graphify.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://lock.cmpxchg8b.com/rebinder.html",
          "host": "lock.cmpxchg8b.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/Arturo0x90/CVE-2026-51385/",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-09T15:07:19.133Z",
      "publisher": "mitre",
      "title": "In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processing loop.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20081
      },
      "nvd": {
        "published": "2026-07-08T22:17:15.000",
        "lastModified": "2026-07-09T17:02:37.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51535",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation lets attacker-controlled work or allocation grow without an effective per-request bound or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://github.com/EIPStackGroup/OpENer/issues/562",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://gist.github.com/MrAlaskan/bec306c51fec9f777b2599f5dea09dd1",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-13T00:00:00.000Z",
      "date_updated": "2026-07-14T13:39:38.351Z",
      "publisher": "mitre",
      "title": "In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream length calculated as an int is passed ...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00472,
        "percentile": 0.38372
      },
      "nvd": {
        "published": "2026-07-13T22:16:47.263",
        "lastModified": "2026-07-15T20:15:56.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51536",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpENer truncates an attacker-controlled length to EipInt16, turning a large value negative and bypassing the bounds check before a stack copy.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/EIPStackGroup/OpENer/issues/563",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://gist.github.com/MrAlaskan/e160c626a32e03e5d9eddaa732560672",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 680,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-13T00:00:00.000Z",
      "date_updated": "2026-07-14T13:16:42.741Z",
      "publisher": "mitre",
      "title": "EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid ENIP outer frame carrying a malforme...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00444,
        "percentile": 0.36457
      },
      "nvd": {
        "published": "2026-07-13T22:16:47.387",
        "lastModified": "2026-07-15T20:15:56.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51537",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A length, offset, or termination error makes the program read beyond the end of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/EIPStackGroup/OpENer/issues/564",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://gist.github.com/MrAlaskan/a5fb0fb7765c9df80d28220ed558f04e",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 458,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-13T00:00:00.000Z",
      "date_updated": "2026-07-14T13:13:59.608Z",
      "publisher": "mitre",
      "title": "EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, it verifies whether the provided ses...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.3142
      },
      "nvd": {
        "published": "2026-07-13T22:16:47.497",
        "lastModified": "2026-07-15T20:15:56.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51538",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpENer verifies that a session handle exists globally but does not bind that handle to the TCP connection issuing the command.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/EIPStackGroup/OpENer/issues/565",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://gist.github.com/MrAlaskan/8156ca3acd6754a9f66efede0a1351f2",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 597,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51539",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-13T00:00:00.000Z",
      "date_updated": "2026-07-14T13:08:40.977Z",
      "publisher": "mitre",
      "title": "A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.2697
      },
      "nvd": {
        "published": "2026-07-13T22:16:47.603",
        "lastModified": "2026-07-15T20:27:37.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51539",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Windows receive loop manages network-read timeouts incorrectly and can remain occupied indefinitely by a remote peer.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/stephane/libmodbus/issues/843",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/MrAlaskan/f22dcf01a5dd90da1b191fcee9043a32",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51540",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-13T00:00:00.000Z",
      "date_updated": "2026-07-14T16:27:06.729Z",
      "publisher": "mitre",
      "title": "OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData).",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30665
      },
      "nvd": {
        "published": "2026-07-13T22:16:47.703",
        "lastModified": "2026-07-15T20:15:56.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51540",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpENer underflows an integer while parsing a connected explicit SendUnitData message, leading to invalid memory sizing or indexing.",
        "basis": [
          "CNA",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/EIPStackGroup/OpENer/issues/568",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://gist.github.com/MrAlaskan/5e0c2af7f4a1d188814c7fa8f812c8da",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51541",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-13T00:00:00.000Z",
      "date_updated": "2026-07-14T13:06:54.526Z",
      "publisher": "mitre",
      "title": "OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker can send a valid ENIP SendRRData frame carrying a very short CIP payload...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30665
      },
      "nvd": {
        "published": "2026-07-13T22:16:47.807",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51541",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CIP parser trusts EPath path_size without comparing the claimed words with the remaining payload and reads beyond the receive buffer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/EIPStackGroup/OpENer/issues/582",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://gist.github.com/MrAlaskan/705c680856e48c535148265c0899ad4b",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 520,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51564",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_updated": "2026-07-28T16:03:30.459Z",
      "publisher": "mitre",
      "title": "An issue in the redirect parameter in Milk admin <=0.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00655,
        "percentile": 0.47827
      },
      "nvd": {
        "published": "2026-07-27T22:17:30.810",
        "lastModified": "2026-07-28T16:23:19.783",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51564",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component redirect path accepts an external destination without restricting it to a trusted origin.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/giuliopanda/milk-admin/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/giuliopanda/milk-admin/blob/6389386de2a9226c84ecb7e79cd16d7c027952ad/milkadmin/App/Route.php",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/giuliopanda/milk-admin/blob/6389386de2a9226c84ecb7e79cd16d7c027952ad/public_html/index.php",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/1337Skid/CVE-2026-51564",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51565",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-27T00:00:00.000Z",
      "date_updated": "2026-07-28T13:30:29.071Z",
      "publisher": "mitre",
      "title": "Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33062
      },
      "nvd": {
        "published": "2026-07-27T23:16:41.160",
        "lastModified": "2026-07-28T16:23:19.783",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51565",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Milk admin reflects the action parameter into a page without escaping it from HTML and script grammar.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/giuliopanda/milk-admin/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/giuliopanda/milk-admin/blob/6389386de2a9226c84ecb7e79cd16d7c027952ad/milkadmin/Modules/Docs/DocsController.php",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/1337Skid/CVE-2026-51565",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51597",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T17:28:17.973Z",
      "publisher": "mitre",
      "title": "MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response ...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29933
      },
      "nvd": {
        "published": "2026-07-09T17:16:59.333",
        "lastModified": "2026-07-10T18:51:16.090",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51597",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The RTSP Digest implementation accepts a previously captured nonce and response in a new connection because the nonce never expires.",
        "basis": [
          "CNA",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kkkk2222874/cve_ID_report/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_5th/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51598",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-09T17:40:57.516Z",
      "publisher": "mitre",
      "title": "An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07905
      },
      "nvd": {
        "published": "2026-07-09T17:16:59.457",
        "lastModified": "2026-07-10T18:50:20.507",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51598",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MIPC252W RTSP parser accepts a malformed DESCRIBE request URL without validating the request-line syntax, allowing the malformed value to crash the service.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kkkk2222874/cve_ID_report/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_6th/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 270,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51599",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T17:28:11.928Z",
      "publisher": "mitre",
      "title": "An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00433,
        "percentile": 0.35606
      },
      "nvd": {
        "published": "2026-07-09T17:16:59.577",
        "lastModified": "2026-07-10T18:53:55.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51599",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The RTSP parser accepts a Content-Length without a body, enters a body-wait state, and consumes subsequent connection data until timeout.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kkkk2222874/cve_ID_report/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_7th/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 545,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51600",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-09T17:43:42.929Z",
      "publisher": "mitre",
      "title": "Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a corresponding mess...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-703",
          "name": "Improper Check or Handling of Exceptional Conditions",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00404,
        "percentile": 0.33186
      },
      "nvd": {
        "published": "2026-07-09T17:16:59.693",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51600",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The RTSP parser trusts Content-Length and waits forever when the declared body is absent, leaking the connection resource.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-400",
          "CWE-703"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kkkk2222874/cve_ID_report/blob/main/Tenda_CP3_V3.0/Tenda_CP3_V3.0/Tenda_CP3_V3.0_1th/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 568,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51601",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T17:28:02.194Z",
      "publisher": "mitre",
      "title": "Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An unauthenticated remot...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33706
      },
      "nvd": {
        "published": "2026-07-09T17:16:59.810",
        "lastModified": "2026-07-10T18:16:22.480",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51601",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The RTSP PLAY handler copies an overlong Range clock value into a fixed stack buffer without checking its length.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kkkk2222874/cve_ID_report/blob/main/Tenda_CP3_V3.0/Tenda_CP3_V3.0_2th/README.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51602",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-09T17:46:25.580Z",
      "publisher": "mitre",
      "title": "A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33013
      },
      "nvd": {
        "published": "2026-07-09T17:16:59.930",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51602",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The RTSP second-stage URL parser copies an overlong SETUP URL into a stack buffer without validating its length.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kkkk2222874/cve_ID_report/blob/main/Tenda_CP3_V3.0/Tenda_CP3_V3.0_3th/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 639,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51603",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-09T17:47:44.452Z",
      "publisher": "mitre",
      "title": "A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00411,
        "percentile": 0.33796
      },
      "nvd": {
        "published": "2026-07-09T17:17:00.867",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51603",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tenda CP3's RTSP service copies a crafted request beyond a stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kkkk2222874/cve_ID_report/blob/main/Tenda_CP3_V3.0/Tenda_CP3_V3.0_4th/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 758,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51604",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-09T17:36:57.086Z",
      "publisher": "mitre",
      "title": "A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33706
      },
      "nvd": {
        "published": "2026-07-09T17:17:00.970",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51604",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kkkk2222874/cve_ID_report/blob/main/Tenda_CP3_V3.0/Tenda_CP3_V3.0_6th/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51605",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-09T17:39:01.874Z",
      "publisher": "mitre",
      "title": "A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33706
      },
      "nvd": {
        "published": "2026-07-09T17:17:01.070",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51605",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kkkk2222874/cve_ID_report/blob/main/Tenda_CP3_V3.0/Tenda_CP3_V3.0_7th/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51606",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-09T17:53:01.219Z",
      "publisher": "mitre",
      "title": "An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24866
      },
      "nvd": {
        "published": "2026-07-09T17:17:01.173",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51606",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The RTSP service does not reject oversized request-line and header fields with bounded parsing, and instead resets the connection.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kkkk2222874/cve_ID_report/blob/main/Tenda_CP3_V3.0/Tenda_CP3_V3.0_5th/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 407,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51785",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-08-03T17:07:17.616Z",
      "publisher": "mitre",
      "title": "An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01149,
        "percentile": 0.63745
      },
      "nvd": {
        "published": "2026-07-31T21:17:31.730",
        "lastModified": "2026-08-03T18:16:39.450",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51785",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches a dynamic code-generation or evaluation path without an effective allowlist, allowing it to run as code.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rfc-editor.org/rfc/rfc9112.html#section-6.3",
          "host": "www.rfc-editor.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc2616",
          "host": "www.rfc-editor.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.rfc-editor.org/rfc/rfc2616.html#section-4.4",
          "host": "www.rfc-editor.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://fenrisk.com/hiawatha-http-smuggling",
          "host": "fenrisk.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-17T15:02:40.362Z",
      "publisher": "mitre",
      "title": "Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29851
      },
      "nvd": {
        "published": "2026-07-14T23:17:29.843",
        "lastModified": "2026-07-17T16:17:15.513",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51807",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is copied beyond the boundary of a stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/osamu620/OpenHTJ2K/commit/0778b93",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/osamu620/OpenHTJ2K/blob/main/CHANGELOG",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/osamu620/OpenHTJ2K/releases",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/osamu620/OpenHTJ2K/compare/0778b93...v0.18.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 588,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51808",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-15T14:01:51.284Z",
      "publisher": "mitre",
      "title": "Buffer Overflow vulnerability in OpenHTJ2K v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0048,
        "percentile": 0.38879
      },
      "nvd": {
        "published": "2026-07-14T23:17:29.957",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51808",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenHTJ2K decoder functions copy input beyond a valid destination buffer because the input size is not bounded to that buffer.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/osamu620/OpenHTJ2K/blob/main/CHANGELOG",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/osamu620/OpenHTJ2K/pull/320",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/osamu620/OpenHTJ2K/releases/tag/v0.18.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-13T00:00:00.000Z",
      "date_updated": "2026-07-14T16:27:17.880Z",
      "publisher": "mitre",
      "title": "SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00527,
        "percentile": 0.41677
      },
      "nvd": {
        "published": "2026-07-13T22:16:47.910",
        "lastModified": "2026-07-15T20:27:37.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51821",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The getUserLogin endpoint incorporates attacker input into an SQL statement without separating data from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cnblogs.com/goww/p/19942271",
          "host": "www.cnblogs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/sign9981/CVE/issues/2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 163,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51833",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-20T18:02:55.948Z",
      "publisher": "mitre",
      "title": "Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose the original IP address of the server.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30394
      },
      "nvd": {
        "published": "2026-07-17T20:17:24.990",
        "lastModified": "2026-07-23T18:17:51.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51833",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A server-side request accepts an attacker-selected destination without enforcing the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenforo.com",
          "host": "xenforo.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/dennywise/CVE-2026-51833-Public-Disclosure/blob/main/CVE-2026-51833.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51923",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T15:32:15.156Z",
      "publisher": "mitre",
      "title": "An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30889
      },
      "nvd": {
        "published": "2026-07-09T21:16:55.480",
        "lastModified": "2026-07-10T18:51:16.090",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51923",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The user-settings component accepts a caller-controlled object identifier without binding the referenced account data to that caller.",
        "basis": [
          "CNA record",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://ZeroBreach.de",
          "host": "zerobreach.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://docuform.de",
          "host": "docuform.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/ZeroBreach-GmbH",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51924",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T15:32:57.854Z",
      "publisher": "mitre",
      "title": "An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25504
      },
      "nvd": {
        "published": "2026-07-09T21:16:55.590",
        "lastModified": "2026-07-10T18:51:16.090",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51924",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that CVE-2026-51924 permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docuform.de",
          "host": "docuform.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/ZeroBreach-GmbH",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 137,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51925",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T15:33:55.421Z",
      "publisher": "mitre",
      "title": "A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24642
      },
      "nvd": {
        "published": "2026-07-09T21:16:55.690",
        "lastModified": "2026-07-10T18:51:16.090",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51925",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The dfm-menu_report.php component accepts a local-file selection outside its intended include namespace.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docuform.de",
          "host": "docuform.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/ZeroBreach-GmbH",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 318,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51926",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-09T00:00:00.000Z",
      "date_updated": "2026-07-10T15:35:04.919Z",
      "publisher": "mitre",
      "title": "An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the l...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-203",
          "name": "Observable Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.2865
      },
      "nvd": {
        "published": "2026-07-09T21:16:55.790",
        "lastModified": "2026-07-10T18:53:55.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51926",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The login endpoint returns distinguishable responses for existing and nonexistent usernames, creating an account-existence oracle.",
        "basis": [
          "CNA",
          "CWE-203"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docuform.de",
          "host": "docuform.de",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/ZeroBreach-GmbH",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51937",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-07T00:00:00.000Z",
      "date_updated": "2026-07-08T14:17:11.579Z",
      "publisher": "mitre",
      "title": "An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the GetAccessTokenComponent.java component",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27645
      },
      "nvd": {
        "published": "2026-07-07T23:16:55.130",
        "lastModified": "2026-07-09T17:02:37.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51937",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record associates exposed OneBlog endpoints with missing authentication but does not identify the exact handler or missing gate.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://developers.weixin.qq.com/doc/offiaccount/Basic_Information/Get_access_token.html",
          "host": "developers.weixin.qq.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/zhangyd-c/OneBlog/issues/43",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://gist.github.com/Passwords404/2599df955cdb36b36b9551b5b7809114",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51946",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-01T00:00:00.000Z",
      "date_updated": "2026-07-01T18:07:49.066Z",
      "publisher": "mitre",
      "title": "SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00336,
        "percentile": 0.2622
      },
      "nvd": {
        "published": "2026-07-01T18:16:34.193",
        "lastModified": "2026-07-02T18:43:45.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51946",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GoAdmin inserts the __sort_type URL parameter into SQL for admin info endpoints without preserving the data-and-query boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/GoAdminGroup/go-admin/tree/main",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://blog.silentgrid.com/ai-assisted-penetration-testing-in-practice/",
          "host": "blog.silentgrid.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51947",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-01T00:00:00.000Z",
      "date_updated": "2026-07-02T16:57:04.583Z",
      "publisher": "mitre",
      "title": "An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Servic...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0113,
        "percentile": 0.63234
      },
      "nvd": {
        "published": "2026-07-01T19:16:53.663",
        "lastModified": "2026-07-02T17:47:43.557",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51947",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The n/a path permits an attacker-controlled serialized object graph to reach a code-capable deserializer.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.pivotal.aurea.com/article/129552-remediating-insecure-deserialization-cwe-502-in-pivotal-6-6-04-08-smart-client-pbs",
          "host": "support.pivotal.aurea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://timtimxs.github.io/CVE-2026-39253-Advisory/",
          "host": "timtimxs.github.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://timtimxs.github.io/CVE-2026-51947-Advisory/",
          "host": "timtimxs.github.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51953",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-08-03T17:00:23.580Z",
      "publisher": "mitre",
      "title": "An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication logic, logout handler components",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19849
      },
      "nvd": {
        "published": "2026-07-31T22:17:02.313",
        "lastModified": "2026-08-03T17:16:37.383",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51953",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A session or token remains valid past logout or expiration, but the public record does not identify the stale-token decision path.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/liufee/cms",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/altamish1994/CVE_Published/blob/main/FeehiCMS/CVE-2026-51953.MD",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 153,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-51992",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-29T00:00:00.000Z",
      "date_updated": "2026-07-29T18:11:13.784Z",
      "publisher": "mitre",
      "title": "SQL Injection vulnerability in ClickHouse Server Versions <= 26.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00515,
        "percentile": 0.41003
      },
      "nvd": {
        "published": "2026-07-29T17:16:52.040",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-51992",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The n/a data path incorporates attacker-controlled values into SQL grammar without parameterization or sufficient escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://clickhouse.com/docs/sql-reference/dictionaries#postgresql",
          "host": "clickhouse.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/TheLiimbo/CVE-2026-51992",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 158,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52100",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-15T14:38:12.184Z",
      "publisher": "mitre",
      "title": "Cross Site Request Forgery vulnerability in andreimarcu linux-server v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23725
      },
      "nvd": {
        "published": "2026-07-14T21:17:05.237",
        "lastModified": "2026-07-15T20:27:37.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52100",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A cross-site request can invoke linux-server's uploadPutHandler under the victim's session and write attacker-selected content.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/andreimarcu/linx-server",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/nk7667/-linx-server-vulnerability-report/blob/main/CVE-2026-52100.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52101",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-14T00:00:00.000Z",
      "date_updated": "2026-07-15T14:34:00.067Z",
      "publisher": "mitre",
      "title": "An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31707
      },
      "nvd": {
        "published": "2026-07-14T21:17:05.343",
        "lastModified": "2026-07-15T20:27:37.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52101",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "When remote uploads are enabled, uploadRemote passes the caller-supplied url directly to http.Get and saves the fetched response, allowing requests to internal or metadata addresses.",
        "basis": [
          "CNA",
          "CWE-200",
          "upstream linx-server upload.go",
          "linked researcher disclosure"
        ],
        "deepDive": true,
        "notes": "Inspected https://github.com/andreimarcu/linx-server/blob/master/upload.go and https://github.com/nk7667/-linx-server-vulnerability-report/blob/main/CVE-2026-52101.md. uploadRemote parses the url form value and passes it to http.Get without target filtering, then stores the response. This supports SSRF rather than the embedded CWE-200-only classification; the upstream repository is frozen and no vendor fix or advisory is public."
      },
      "references": [
        {
          "url": "https://github.com/andreimarcu/linx-server",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/nk7667/-linx-server-vulnerability-report/blob/main/CVE-2026-52101.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 167,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52134",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-08-03T16:57:17.922Z",
      "publisher": "mitre",
      "title": "An issue in the parseGoosePayload() function (/goose/goose_receiver.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.008,
        "percentile": 0.53038
      },
      "nvd": {
        "published": "2026-07-31T22:17:02.437",
        "lastModified": "2026-08-03T17:16:37.560",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52134",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The device accepts a captured authenticated GOOSE frame again, so freshness is not enforced against replay.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mz-automation/libiec61850",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/mz-automation/libiec61850/tree/v1.6/src/goose/goose_receiver.c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/if-forget/CVE-2026-52134-libiec61850",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52186",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-01T00:00:00.000Z",
      "date_updated": "2026-07-02T13:05:11.119Z",
      "publisher": "mitre",
      "title": "SQL Injection vulnerability in UTT nv518G nv518GV3v3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00527,
        "percentile": 0.41678
      },
      "nvd": {
        "published": "2026-07-01T22:16:49.070",
        "lastModified": "2026-07-02T17:42:23.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52186",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://utt.com.cn/downloadcenter.php?filetypeid=3&model=518G&lang=zhcn",
          "host": "utt.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/akuma-QAQ/CVEreport/blob/main/518G/FUN_00463bbc/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 157,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-02T00:00:00.000Z",
      "date_updated": "2026-07-06T17:54:10.604Z",
      "publisher": "mitre",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00452,
        "percentile": 0.37064
      },
      "nvd": {
        "published": "2026-07-02T20:17:03.603",
        "lastModified": "2026-07-06T19:48:39.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52187",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The UTT gohead/sub_483ba0 component copies remote input past a fixed buffer bound, allowing a crafted request to crash the device.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://utt.com.cn/downloadcenter.php?filetypeid=3&model=518G&lang=zhcn",
          "host": "utt.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/akuma-QAQ/CVEreport/blob/main/518G/FUN_00483ba0/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 162,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-02T00:00:00.000Z",
      "date_updated": "2026-07-06T14:31:02.072Z",
      "publisher": "mitre",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14823
      },
      "nvd": {
        "published": "2026-07-02T21:16:56.460",
        "lastModified": "2026-07-06T18:38:23.207",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52188",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The nv518G request handler processes remote data beyond the boundary of its destination buffer.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://utt.com.cn/downloadcenter.php?filetypeid=3&model=518G&lang=zhcn",
          "host": "utt.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/akuma-QAQ/CVEreport/tree/main/518G/FUN_00497498",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 163,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52189",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-02T00:00:00.000Z",
      "date_updated": "2026-07-06T14:49:36.028Z",
      "publisher": "mitre",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00452,
        "percentile": 0.37063
      },
      "nvd": {
        "published": "2026-07-02T21:16:56.557",
        "lastModified": "2026-07-06T18:38:23.207",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52189",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The nv518G gohead handler copies remote input into a fixed-size buffer without enforcing the destination size.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://utt.com.cn/downloadcenter.php?filetypeid=3&model=518G&lang=zhcn",
          "host": "utt.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/akuma-QAQ/CVEreport/blob/main/518G/FUN_00487330/README.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 162,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52190",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-01T00:00:00.000Z",
      "date_updated": "2026-07-02T12:38:55.333Z",
      "publisher": "mitre",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00452,
        "percentile": 0.37063
      },
      "nvd": {
        "published": "2026-07-01T22:16:49.187",
        "lastModified": "2026-07-02T17:42:23.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52190",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A remote request overflows a fixed stack buffer in the router's gohead processing component.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://utt.com.cn/downloadcenter.php?filetypeid=3&model=518G&lang=zhcn",
          "host": "utt.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/akuma-QAQ/CVEreport/tree/main/518G/FUN_00448384",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 162,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-02T00:00:00.000Z",
      "date_updated": "2026-07-06T14:48:36.449Z",
      "publisher": "mitre",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00452,
        "percentile": 0.37063
      },
      "nvd": {
        "published": "2026-07-02T21:16:56.650",
        "lastModified": "2026-07-06T18:38:23.207",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52191",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The gohead request path copies or writes crafted input beyond a fixed buffer, although the exact field and copy operation are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://utt.com.cn/downloadcenter.php?filetypeid=3&model=518G&lang=zhcn",
          "host": "utt.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/akuma-QAQ/CVEreport/tree/main/518G/FUN_00444c8c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 162,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-02T00:00:00.000Z",
      "date_updated": "2026-07-06T14:47:26.371Z",
      "publisher": "mitre",
      "title": "An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_445C5C component",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00409,
        "percentile": 0.33674
      },
      "nvd": {
        "published": "2026-07-02T21:16:56.747",
        "lastModified": "2026-07-06T18:38:23.207",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52192",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component path lets attacker-controlled work, memory, recursion, or retained resources grow without an effective bound or release condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://utt.com.cn/downloadcenter.php?filetypeid=3&model=518G&lang=zhcn",
          "host": "utt.com.cn",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/akuma-QAQ/CVEreport/tree/main/518G/FUN_00445c5c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 141,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52199",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-20T17:59:28.219Z",
      "publisher": "mitre",
      "title": "An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00599,
        "percentile": 0.45328
      },
      "nvd": {
        "published": "2026-07-17T20:17:25.100",
        "lastModified": "2026-07-23T18:28:20.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52199",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The router's adbd component accepts attacker-controlled content as executable code, although the exact injection route is not public.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lamaper/CVE-2026-52199",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52200",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-08T00:00:00.000Z",
      "date_updated": "2026-07-09T15:10:48.578Z",
      "publisher": "mitre",
      "title": "An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint in MifiService.apk",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0068,
        "percentile": 0.48851
      },
      "nvd": {
        "published": "2026-07-08T22:17:15.127",
        "lastModified": "2026-07-09T17:02:37.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52200",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MifiService /ajax servlet executes sensitive management operations without requiring a valid server-side session or token, allowing an adjacent unauthenticated caller to reach operations that can execute code.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-94",
          "Original researcher report"
        ],
        "deepDive": true,
        "notes": "Inspected the original researcher report at https://github.com/lamaper/CVE-2026-52200; it identifies MifiService.apk, com.mifiservice.server.AjaxSevlet, absent session enforcement, and absent CSRF/origin checks, which supports AUTHORITY_BINDING as the earliest cause rather than the embedded CWE-94 label, but no vendor source, official patch, or fixed firmware was available for inspection."
      },
      "references": [
        {
          "url": "https://github.com/lamaper/UZ801-MifiService-Broken-Access-Control",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/lamaper/CVE-2026-52200",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 167,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52203",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-20T17:53:09.054Z",
      "publisher": "mitre",
      "title": "An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.2269
      },
      "nvd": {
        "published": "2026-07-17T21:17:07.490",
        "lastModified": "2026-07-23T18:17:51.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52203",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record says the source parameter exposes MCMS information but does not identify the selected object, output path, or missing check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/this1slwl/1bfb6996ca7edf6f5d15b5ebc181f337",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-08-03T16:54:25.285Z",
      "publisher": "mitre",
      "title": "A reflected cross-site scripting (XSS) vulnerability in the /logo.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04575
      },
      "nvd": {
        "published": "2026-07-31T22:17:02.553",
        "lastModified": "2026-08-03T17:16:37.733",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52232",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "the affected component reflects request input into HTML without context-appropriate escaping, allowing script execution after a victim opens the crafted request.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/whitewhale-dmb/Vulnerability-Research/tree/main/CVE-2026-52232",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-20T17:51:15.964Z",
      "publisher": "mitre",
      "title": "cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17661
      },
      "nvd": {
        "published": "2026-07-17T21:17:07.610",
        "lastModified": "2026-07-23T18:17:51.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52348",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CrudOption.order builds SQL from attacker-controlled order input without preserving the SQL data boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cool-team-official/cool-admin-java/issues/19",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-21T14:58:39.018Z",
      "publisher": "mitre",
      "title": "Directory Traversal vulnerability in Menyoo 2.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16746
      },
      "nvd": {
        "published": "2026-07-20T15:16:39.827",
        "lastModified": "2026-07-23T18:28:20.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52349",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Menyoo file-management operations accept traversal paths that escape their intended save and rename directories.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/itsjustcurtis/MenyooSP/pull/550",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/itsjustcurtis/MenyooSP/commit/729aa48",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 350,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-08-03T16:51:24.587Z",
      "publisher": "mitre",
      "title": "A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13156
      },
      "nvd": {
        "published": "2026-07-31T22:17:02.673",
        "lastModified": "2026-08-03T17:16:37.907",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52371",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "xxl-job accepts an attacker-selected trigger destination and makes server-side requests to internal resources.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/RichardKabuto/xxl-job-ssrf-poc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52439",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-23T00:00:00.000Z",
      "date_updated": "2026-07-24T19:26:42.120Z",
      "publisher": "mitre",
      "title": "An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-917",
          "name": "Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00515,
        "percentile": 0.40992
      },
      "nvd": {
        "published": "2026-07-23T21:17:05.200",
        "lastModified": "2026-07-28T16:23:19.783",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52439",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism.",
        "basis": [
          "CNA",
          "CWE-917"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitee.com/xiandafu/beetl",
          "host": "gitee.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitee.com/xiandafu/beetl/issues/IJO1HM",
          "host": "gitee.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52469",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T17:30:59.134Z",
      "publisher": "mitre",
      "title": "SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00383,
        "percentile": 0.31009
      },
      "nvd": {
        "published": "2026-07-21T21:16:51.760",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52469",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Y4y17/CVE/blob/main/Crocus/SQL%20Injection-1.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52470",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T17:11:26.583Z",
      "publisher": "mitre",
      "title": "SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00383,
        "percentile": 0.31008
      },
      "nvd": {
        "published": "2026-07-21T21:16:51.873",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52470",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The orderfield value reaches RecordStateMapper.xml and is inserted with ${} directly into queryHistory and query SQL statements.",
        "basis": [
          "CNA",
          "CWE-89",
          "https://github.com/Y4y17/CVE/blob/main/Crocus/SQL%20Injection-2.md"
        ],
        "deepDive": true,
        "notes": "Reviewed https://github.com/Y4y17/CVE/blob/main/Crocus/SQL%20Injection-2.md. The discoverer's report identifies orderfield, RecordStateMapper.xml, and direct ${} concatenation, but no vendor patch or commit was available for independent source tracing."
      },
      "references": [
        {
          "url": "https://github.com/Y4y17/CVE/blob/main/Crocus/SQL%20Injection-2.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 129,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52472",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T16:41:22.387Z",
      "publisher": "mitre",
      "title": "SQL injection vulnerability in Wgcloud 3.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00383,
        "percentile": 0.31009
      },
      "nvd": {
        "published": "2026-07-21T21:16:51.983",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52472",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Y4y17/CVE/blob/main/Wgcloud/SQL-Injection-1.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52474",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T16:37:22.913Z",
      "publisher": "mitre",
      "title": "An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30222
      },
      "nvd": {
        "published": "2026-07-21T21:16:52.093",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52474",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "JobUtil.java exposes sensitive information to a remote caller, but the public record does not identify the data, endpoint, or missing output control.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Y4y17/CVE/blob/main/AiFlowy/Any%20SpringBean%20invocation.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52475",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T17:08:37.888Z",
      "publisher": "mitre",
      "title": "Cross Site Scripting vulnerability in aiflowy <= 2.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12097
      },
      "nvd": {
        "published": "2026-07-21T21:16:52.203",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52475",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "aiflowy emits caller-controlled UploadController content into a web page without the sanitization or escaping required for that context.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Y4y17/CVE/blob/main/AiFlowy/Any%20file%20upload%20vulnerability.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-21T00:00:00.000Z",
      "date_updated": "2026-07-22T16:17:48.178Z",
      "publisher": "mitre",
      "title": "SQL Injection vulnerability in aiflowy <= 2.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29561
      },
      "nvd": {
        "published": "2026-07-21T21:16:52.307",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52476",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DatacenterQuery.getPageData incorporates attacker input into an SQL statement without separating data from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Y4y17/CVE/blob/main/AiFlowy/SQL%20Injection.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 164,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52533",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-13T00:00:00.000Z",
      "date_updated": "2026-07-14T13:37:23.520Z",
      "publisher": "mitre",
      "title": "An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00414,
        "percentile": 0.3411
      },
      "nvd": {
        "published": "2026-07-13T22:16:48.020",
        "lastModified": "2026-07-15T20:27:37.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52533",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record says access to an etc/shadow component permits privilege escalation but does not identify the exposed operation, credentials, or failed authorization check.",
        "basis": [
          "CNA",
          "CWE-269",
          "D-Link Security Bulletin"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.dlink.com/en/security-bulletin/ on 2026-08-05; D-Link states that its public bulletins deliberately disclose only the minimum information and the page did not expose a CVE-2026-52533-specific advisory or causal check. The embedded statement about an etc/shadow component therefore cannot support a more specific cause."
      },
      "references": [
        {
          "url": "https://www.dlink.com/en/security-bulletin/",
          "host": "www.dlink.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://codeberg.org/zuhri/advisory#recent-poc",
          "host": "codeberg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://zuh.re/cve/2026-52533/",
          "host": "zuh.re",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 125,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52539",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-30T00:00:00.000Z",
      "date_updated": "2026-07-31T11:43:25.439Z",
      "publisher": "mitre",
      "title": "Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauth...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22668
      },
      "nvd": {
        "published": "2026-07-30T21:17:47.213",
        "lastModified": "2026-07-31T12:16:50.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52539",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "When configuration is absent, Outstatic signs JWTs with a public hard-coded secret that attackers can reuse to forge administrator sessions.",
        "basis": [
          "CNA record",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/avitorio/outstatic/blob/canary/packages/outstatic/src/utils/constants.ts",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/avitorio/outstatic",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52584",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-17T00:00:00.000Z",
      "date_updated": "2026-07-20T17:48:03.329Z",
      "publisher": "mitre",
      "title": "Buffer Overflow vulnerability in libjxl v.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01931
      },
      "nvd": {
        "published": "2026-07-17T21:17:07.723",
        "lastModified": "2026-07-23T18:28:35.280",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52584",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CVE-2026-52584 writes attacker-controlled data beyond a stack buffer boundary.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/libjxl/libjxl/issues/4803",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/libjxl/libjxl/pull/4804",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52656",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T00:00:00.000Z",
      "date_published": "2026-07-20T00:00:00.000Z",
      "date_updated": "2026-07-21T14:57:37.988Z",
      "publisher": "mitre",
      "title": "An issue in SJCAM AllWinner Tech products SJ4000-Air V1.",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0051,
        "percentile": 0.40678
      },
      "nvd": {
        "published": "2026-07-20T22:17:15.900",
        "lastModified": "2026-07-23T18:17:51.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52656",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The camera accepts a crafted FEX file on a code-execution path, but the public vendor site does not identify the parser or validation failure.",
        "basis": [
          "CNA",
          "CWE-94",
          "SJCAM official product site"
        ],
        "deepDive": true,
        "notes": "Primary-source deep dive: https://www.sjcam.com/ ; the linked vendor site contains no CVE-2026-52656 advisory, patch, parser detail, or validation rule, so the crafted-FEX cause remains broad."
      },
      "references": [
        {
          "url": "https://sjcam.com",
          "host": "sjcam.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://keowu.re/posts/Lelouch--Reverse-Engineering-of-an-SJCAM-Action-Camera-with-proprietary-Android--based-firmware-and-Rewriting-a-completely-OpenSource-CFW",
          "host": "keowu.re",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52680",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T06:19:53.298Z",
      "date_published": "2026-07-30T16:07:12.786Z",
      "date_updated": "2026-07-31T17:56:51.075Z",
      "publisher": "apache",
      "title": "Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Kyuubi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00548,
        "percentile": 0.42823
      },
      "nvd": {
        "published": "2026-07-30T16:17:14.040",
        "lastModified": "2026-07-31T18:17:15.800",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52680",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled path is used without confinement to the intended directory, allowing file access outside that namespace.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/b0qx2v8k5v4rrqsh53pb146t7so0lmrk",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/5",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T08:05:31.707Z",
      "date_published": "2026-07-23T07:49:04.336Z",
      "date_updated": "2026-07-23T14:00:17.742Z",
      "publisher": "OX",
      "title": "Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack",
      "affected": {
        "vendors": [
          "PowerDNS"
        ],
        "products": [
          {
            "vendor": "PowerDNS",
            "product": "Recursor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@open-xchange.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04057
      },
      "nvd": {
        "published": "2026-07-23T09:16:26.843",
        "lastModified": "2026-07-23T15:48:25.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52684",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A slow authorization response lets cached records expire between lookup and TTL capping, so nearly expired child data refreshes authoritative NS state without the intended cap.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/PowerDNS/pdns/pull/17748",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 1,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52686",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T08:05:31.707Z",
      "date_published": "2026-07-23T08:03:37.563Z",
      "date_updated": "2026-07-23T13:56:55.653Z",
      "publisher": "OX",
      "title": "Wildcard CNAME proof validation bypass",
      "affected": {
        "vendors": [
          "PowerDNS"
        ],
        "products": [
          {
            "vendor": "PowerDNS",
            "product": "Recursor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@open-xchange.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01649
      },
      "nvd": {
        "published": "2026-07-23T09:16:26.967",
        "lastModified": "2026-07-23T15:48:25.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52686",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Recursor verification path accepts signed or MAC-protected data without validating the required authentic bytes.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-powerdns-2026-10.html",
          "host": "docs.powerdns.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-52688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T08:05:31.708Z",
      "date_published": "2026-07-23T08:03:58.542Z",
      "date_updated": "2026-07-23T13:56:15.511Z",
      "publisher": "OX",
      "title": "RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation",
      "affected": {
        "vendors": [
          "PowerDNS"
        ],
        "products": [
          {
            "vendor": "PowerDNS",
            "product": "Recursor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security@open-xchange.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.0274
      },
      "nvd": {
        "published": "2026-07-23T09:16:27.080",
        "lastModified": "2026-07-23T15:48:25.133",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52688",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DNSSEC validation accepts an RRSIG state that does not satisfy the required signature verification rule.",
        "basis": [
          "CNA",
          "CWE-295",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-powerdns-2026-10.html",
          "host": "docs.powerdns.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-52746",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T14:00:43.573Z",
      "date_published": "2026-07-17T18:32:47.173Z",
      "date_updated": "2026-08-03T20:50:28.984Z",
      "publisher": "GitHub_M",
      "title": "JSONata: Malicious inputs to \"$toMillis\" function can cause resource exhaustion",
      "affected": {
        "vendors": [
          "jsonata-js"
        ],
        "products": [
          {
            "vendor": "jsonata-js",
            "product": "jsonata"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30605
      },
      "nvd": {
        "published": "2026-07-17T19:17:16.500",
        "lastModified": "2026-08-03T21:16:40.620",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-52746",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "JSONata $toMillis applies an ISO-8601 validation expression with superlinear backtracking to attacker-controlled nonmatching strings, consuming excessive CPU during query evaluation.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jsonata-js/jsonata/security/advisories/GHSA-86vw-mfpg-wwv9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/jsonata-js/jsonata/pull/782",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jsonata-js/jsonata/pull/793",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jsonata-js/jsonata/commit/80ba95d170f74e3f20f4f36b8b77d8c85cea7686",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jsonata-js/jsonata/commit/d6ffc17cb16a8e53c222205bd274624e919cce0b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jsonata-js/jsonata/releases/tag/v1.8.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jsonata-js/jsonata/releases/tag/v2.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-52747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T14:00:43.573Z",
      "date_published": "2026-07-10T21:42:11.503Z",
      "date_updated": "2026-07-13T17:48:27.282Z",
      "publisher": "GitHub_M",
      "title": "ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass",
      "affected": {
        "vendors": [
          "owasp-modsecurity"
        ],
        "products": [
          {
            "vendor": "owasp-modsecurity",
            "product": "ModSecurity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-180",
          "name": "Incorrect Behavior Order: Validate Before Canonicalize",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00519,
        "percentile": 0.41263
      },
      "nvd": {
        "published": "2026-07-10T22:16:42.697",
        "lastModified": "2026-07-14T20:00:08.103",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-52747",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WAF and backend normalize line breaks differently, allowing one request to be parsed into different grammars.",
        "basis": [
          "CNA",
          "CWE-180"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-rcw9-2f5r-7p88",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/owasp-modsecurity/ModSecurity/commit/875504c2758169c41be1ad2f0cc64d896b7815d7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 703,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T17:13:43.063Z",
      "date_published": "2026-07-10T21:40:23.961Z",
      "date_updated": "2026-07-13T14:08:57.437Z",
      "publisher": "GitHub_M",
      "title": "ModSecurity: Transformation utf8toUnicode produces wrong output on i386 architecture",
      "affected": {
        "vendors": [
          "owasp-modsecurity"
        ],
        "products": [
          {
            "vendor": "owasp-modsecurity",
            "product": "ModSecurity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-467",
          "name": "Use of sizeof() on a Pointer Type",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00414,
        "percentile": 0.34069
      },
      "nvd": {
        "published": "2026-07-10T22:16:42.833",
        "lastModified": "2026-07-14T19:46:34.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-52761",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ModSecurity passes a pointer size rather than the Unicode buffer length to snprintf(), truncating t:utf8toUnicode output on i386 and changing WAF rule decisions.",
        "basis": [
          "CNA",
          "CWE-467"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-qjgm-7gp4-f8qq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/owasp-modsecurity/ModSecurity/commit/edcd010814e234d46e2ec55a0f1078ff9d3032e4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52791",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T18:02:19.731Z",
      "date_published": "2026-07-29T16:14:46.724Z",
      "date_updated": "2026-07-29T17:56:43.388Z",
      "publisher": "GitHub_M",
      "title": "fuse-overlayfs release-1.x preserves SUID/SGID bits after truncate/open(O_TRUNC)",
      "affected": {
        "vendors": [
          "containers"
        ],
        "products": [
          {
            "vendor": "containers",
            "product": "fuse-overlayfs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00102,
        "percentile": 0.01116
      },
      "nvd": {
        "published": "2026-07-29T17:16:52.187",
        "lastModified": "2026-07-29T18:16:54.047",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52791",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A FUSE write or truncate path preserves SUID or SGID bits after content changes, allowing the modified file to retain privileges it should lose.",
        "basis": [
          "CNA",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/containers/fuse-overlayfs/security/advisories/GHSA-2cc4-p72c-v85h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/containers/fuse-overlayfs/commit/97e0d968a782fc259ebde112db1e9b9ff1ad724f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/containers/fuse-overlayfs/releases/tag/v1.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 346,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52830",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T18:11:06.662Z",
      "date_published": "2026-07-02T20:39:35.927Z",
      "date_updated": "2026-07-06T14:36:02.848Z",
      "publisher": "GitHub_M",
      "title": "fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection",
      "affected": {
        "vendors": [
          "leshchenko1979"
        ],
        "products": [
          {
            "vendor": "leshchenko1979",
            "product": "fast-mcp-telegram"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00545,
        "percentile": 0.42657
      },
      "nvd": {
        "published": "2026-07-02T21:16:56.847",
        "lastModified": "2026-07-06T19:41:00.653",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52830",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The bearer-token verifier joins an unnormalized token into a session-file path, so traversal selects the reserved legacy session despite the exact-name rejection.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://web.archive.org/web/20250926152207/https://github.com/leshchenko1979/fast-mcp-telegram",
          "host": "web.archive.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/advisories/GHSA-rxw2-pc8j-vxwm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 939,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52837",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T18:41:27.723Z",
      "date_published": "2026-07-14T14:48:26.692Z",
      "date_updated": "2026-07-29T16:28:13.175Z",
      "publisher": "GitHub_M",
      "title": "Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page",
      "affected": {
        "vendors": [
          "alextselegidis"
        ],
        "products": [
          {
            "vendor": "alextselegidis",
            "product": "easyappointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27941
      },
      "nvd": {
        "published": "2026-07-14T15:17:04.170",
        "lastModified": "2026-07-29T17:16:52.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52837",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unauthenticated reschedule view serializes the entire customer row for a supplied appointment hash instead of returning a field-minimized, caller-authorized record.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-xgr6-pqjv-3pf8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/alextselegidis/easyappointments/commit/40bb0b31b531540bc9006efce4220eb0a437ed2b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 644,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52838",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T18:41:27.724Z",
      "date_published": "2026-07-14T15:07:43.865Z",
      "date_updated": "2026-07-14T16:26:53.608Z",
      "publisher": "GitHub_M",
      "title": "Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS",
      "affected": {
        "vendors": [
          "alextselegidis"
        ],
        "products": [
          {
            "vendor": "alextselegidis",
            "product": "easyappointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08256
      },
      "nvd": {
        "published": "2026-07-14T16:17:00.410",
        "lastModified": "2026-07-14T17:17:03.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52838",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An administrator-supplied disabled-booking message is stored and rendered on the public page as raw HTML without sanitization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-996f-334j-67g7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/alextselegidis/easyappointments/commit/629a0415f54f75556c17f4f5d9c77fda1fdbdeae",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 592,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52839",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T18:41:27.724Z",
      "date_published": "2026-07-14T15:21:23.199Z",
      "date_updated": "2026-07-29T16:25:59.689Z",
      "publisher": "GitHub_M",
      "title": "Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass",
      "affected": {
        "vendors": [
          "alextselegidis"
        ],
        "products": [
          {
            "vendor": "alextselegidis",
            "product": "easyappointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04299
      },
      "nvd": {
        "published": "2026-07-14T16:17:00.540",
        "lastModified": "2026-07-29T17:16:52.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52839",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Appointment mutations accept id_users_provider without binding that provider to the authenticated session, even committing an unauthorized row before an error.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-w8xc-8g92-v77h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/alextselegidis/easyappointments/commit/725eafa647308846ce887657db12771a829e42ef",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 926,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52840",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T18:41:27.724Z",
      "date_published": "2026-07-14T15:23:59.992Z",
      "date_updated": "2026-07-15T13:53:09.948Z",
      "publisher": "GitHub_M",
      "title": "Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network",
      "affected": {
        "vendors": [
          "alextselegidis"
        ],
        "products": [
          {
            "vendor": "alextselegidis",
            "product": "easyappointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08423
      },
      "nvd": {
        "published": "2026-07-14T16:17:00.670",
        "lastModified": "2026-07-15T14:18:23.000",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52840",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CalDAV connection test sends a Guzzle request to a caller-supplied URL without scheme, host, or internal-address validation.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-pm5p-7w5h-jm5q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/alextselegidis/easyappointments/commit/6eb9336a91cfb276379506625e81f5bd9ed3a536",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52841",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T18:41:27.724Z",
      "date_published": "2026-07-14T15:27:50.367Z",
      "date_updated": "2026-07-14T15:45:45.967Z",
      "publisher": "GitHub_M",
      "title": "Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync",
      "affected": {
        "vendors": [
          "alextselegidis"
        ],
        "products": [
          {
            "vendor": "alextselegidis",
            "product": "easyappointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02931
      },
      "nvd": {
        "published": "2026-07-14T16:17:00.800",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52841",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OAuth callback writes a token to the URL-supplied provider row without checking that the logged-in user owns that provider.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-8hm4-r66f-29wr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/alextselegidis/easyappointments/commit/4b2d245d2cd2058dc76e05f6eb65b26699268471",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 610,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52842",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T18:41:27.724Z",
      "date_published": "2026-07-15T16:18:26.157Z",
      "date_updated": "2026-07-15T16:35:28.146Z",
      "publisher": "GitHub_M",
      "title": "Lightpanda:URL parser misidentifies page origin for URLs containing @ in the path - Same-Origin Policy bypass",
      "affected": {
        "vendors": [
          "lightpanda-io"
        ],
        "products": [
          {
            "vendor": "lightpanda-io",
            "product": "browser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05763
      },
      "nvd": {
        "published": "2026-07-15T17:16:50.317",
        "lastModified": "2026-07-15T20:49:41.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52842",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Lightpanda searches the whole URL for an at-sign and assigns an attacker host the origin of a victim hostname found in the path.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lightpanda-io/browser/security/advisories/GHSA-mq6p-m9cc-q432",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lightpanda-io/browser/pull/1998",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lightpanda-io/browser/commit/0588cc374d4af9687cf6f45a7d52f7af04bbacfb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lightpanda-io/browser/releases/tag/0.3.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 408,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52843",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T18:41:27.724Z",
      "date_published": "2026-07-15T16:16:07.762Z",
      "date_updated": "2026-07-15T17:37:26.880Z",
      "publisher": "GitHub_M",
      "title": "Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin requests regardless of credentials mode",
      "affected": {
        "vendors": [
          "lightpanda-io"
        ],
        "products": [
          {
            "vendor": "lightpanda-io",
            "product": "browser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07017
      },
      "nvd": {
        "published": "2026-07-15T17:16:50.467",
        "lastModified": "2026-07-15T20:50:57.257",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52843",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The browser attaches session cookies to cross-origin fetch and XHR requests even when the caller's credentials mode forbids them.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lightpanda-io/browser/security/advisories/GHSA-36mm-v3c2-24cc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lightpanda-io/browser/pull/2155",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lightpanda-io/browser/commit/2cdaac780bed65db98bbb6ed2ad5bc6011863c76",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lightpanda-io/browser/releases/tag/0.2.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 465,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52855",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T18:41:27.724Z",
      "date_published": "2026-07-31T16:16:42.470Z",
      "date_updated": "2026-07-31T19:55:37.770Z",
      "publisher": "GitHub_M",
      "title": "Wings exposes node configuration secrets through egg configuration-file templating",
      "affected": {
        "vendors": [
          "pterodactyl"
        ],
        "products": [
          {
            "vendor": "pterodactyl",
            "product": "wings"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19606
      },
      "nvd": {
        "published": "2026-07-31T17:16:33.313",
        "lastModified": "2026-07-31T20:16:51.173",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52855",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Wings expands low-privileged egg-template placeholders against node configuration secrets, exposing tokens and registry credentials through generated configuration files.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pterodactyl/wings/security/advisories/GHSA-pfvc-3p5h-x7h6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pterodactyl/wings/commit/eb65e27ae077a63e38518c490768486af1cd86a9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pterodactyl/wings/releases/tag/v1.12.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 361,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52856",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T18:41:27.724Z",
      "date_published": "2026-07-31T16:20:31.222Z",
      "date_updated": "2026-07-31T18:57:35.513Z",
      "publisher": "GitHub_M",
      "title": "Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service",
      "affected": {
        "vendors": [
          "pterodactyl"
        ],
        "products": [
          {
            "vendor": "pterodactyl",
            "product": "wings"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-755",
          "name": "Improper Handling of Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26031
      },
      "nvd": {
        "published": "2026-07-31T17:16:33.460",
        "lastModified": "2026-07-31T19:17:09.120",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52856",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A malformed SFTP handshake packet reaches an unchecked panic condition and terminates the Wings process.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-129",
          "CWE-248",
          "CWE-617",
          "CWE-755"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pterodactyl/wings/security/advisories/GHSA-ghrq-5wpp-hxx5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pterodactyl/wings/commit/8e49c7c0eda815d3ada171831876a1c14c493026",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pterodactyl/wings/releases/tag/v1.13.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 3,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52857",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T18:41:27.724Z",
      "date_published": "2026-07-31T16:09:42.791Z",
      "date_updated": "2026-07-31T16:16:47.071Z",
      "publisher": "GitHub_M",
      "title": "Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM",
      "affected": {
        "vendors": [
          "pterodactyl"
        ],
        "products": [
          {
            "vendor": "pterodactyl",
            "product": "wings"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.0165
      },
      "nvd": {
        "published": "2026-07-31T16:17:06.490",
        "lastModified": "2026-07-31T17:16:33.607",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52857",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Wings lets JSON, YAML, or XML parser input grow without a size bound, allowing a configuration file to exhaust process memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pterodactyl/wings/security/advisories/GHSA-q6hh-gp44-4hcm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pterodactyl/wings/commit/5f71f65711b6b9e6f913bec94a7b36d9a5eaae49",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pterodactyl/wings/releases/tag/v1.13.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52863",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:27:22.803Z",
      "date_published": "2026-07-22T13:09:06.454Z",
      "date_updated": "2026-07-22T14:17:58.654Z",
      "publisher": "NLnet Labs",
      "title": "Memory corruption could lead to crash and denial of service",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14837
      },
      "nvd": {
        "published": "2026-07-22T14:17:20.757",
        "lastModified": "2026-07-24T14:23:56.397",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-52863",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A subquery receives only a shallow view-name copy, so freeing the owning super-query leaves the subquery with a dangling pointer.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-52863.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 929,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52865",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T23:45:50.281Z",
      "date_published": "2026-07-15T14:33:45.155Z",
      "date_updated": "2026-07-15T15:36:57.172Z",
      "publisher": "f5",
      "title": "NGINX Ingress Controller vulnerability",
      "affected": {
        "vendors": [
          "F5"
        ],
        "products": [
          {
            "vendor": "F5",
            "product": "NGINX Ingress Controller"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20843
      },
      "nvd": {
        "published": "2026-07-15T15:16:44.587",
        "lastModified": "2026-07-16T14:02:35.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-52865",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NGINX Ingress Controller dereferences a null pointer while processing a malformed Ingress or TransportServer object.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://my.f5.com/manage/s/article/K000161834",
          "host": "my.f5.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 795,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-52869",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T21:44:27.363Z",
      "date_published": "2026-07-15T20:06:23.604Z",
      "date_updated": "2026-07-16T13:00:37.854Z",
      "publisher": "GitHub_M",
      "title": "MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal",
      "affected": {
        "vendors": [
          "modelcontextprotocol"
        ],
        "products": [
          {
            "vendor": "modelcontextprotocol",
            "product": "python-sdk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24359
      },
      "nvd": {
        "published": "2026-07-15T20:17:38.427",
        "lastModified": "2026-07-17T18:06:50.957",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-52869",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MCP HTTP transports treat possession of a session identifier as authority without binding that identifier to the authenticated principal.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-jpw9-pfvf-9f58",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/pull/2690",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/pull/2719",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/commit/1abcca2408a6b50e10ec601181f63f9978705c00",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/commit/ce267b6fc515dc4efc1dc70b6975b16ff0feef0a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.27.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 610,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52870",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T21:44:27.364Z",
      "date_published": "2026-07-15T20:07:53.500Z",
      "date_updated": "2026-07-16T13:01:40.089Z",
      "publisher": "GitHub_M",
      "title": "MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks",
      "affected": {
        "vendors": [
          "modelcontextprotocol"
        ],
        "products": [
          {
            "vendor": "modelcontextprotocol",
            "product": "python-sdk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.1472
      },
      "nvd": {
        "published": "2026-07-15T20:17:38.577",
        "lastModified": "2026-07-17T18:07:07.873",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-52870",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-hvrp-rf83-w775",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/pull/2720",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/commit/62137874ff26dd74d2fea80ff528a7fd9ca7a5e7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.27.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 495,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52887",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T21:44:27.365Z",
      "date_published": "2026-07-15T20:16:43.023Z",
      "date_updated": "2026-07-20T14:39:47.788Z",
      "publisher": "GitHub_M",
      "title": "NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE",
      "affected": {
        "vendors": [
          "nocobase"
        ],
        "products": [
          {
            "vendor": "nocobase",
            "product": "nocobase"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00593,
        "percentile": 0.44998
      },
      "nvd": {
        "published": "2026-07-15T21:16:54.543",
        "lastModified": "2026-07-20T16:17:05.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52887",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The latestMsgReceiveTimestamp filter is inserted into Sequelize.literal without escaping or parameter binding, allowing stacked PostgreSQL statements.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nocobase/nocobase/security/advisories/GHSA-p849-8hwh-84j9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nocobase/nocobase/commit/68d64e3fcfb8be2ae4f3bfc9e1ee3f85b87c89ce",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nocobase/nocobase/releases/tag/v2.0.61",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 547,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52888",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T21:44:27.365Z",
      "date_published": "2026-07-15T20:13:52.669Z",
      "date_updated": "2026-07-16T15:12:38.696Z",
      "publisher": "GitHub_M",
      "title": "NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass",
      "affected": {
        "vendors": [
          "nocobase"
        ],
        "products": [
          {
            "vendor": "nocobase",
            "product": "nocobase"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18916
      },
      "nvd": {
        "published": "2026-07-15T21:16:54.673",
        "lastModified": "2026-07-16T16:19:12.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52888",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SQL-collection blacklist omits PostgreSQL system catalogs, so an administrator can query password hashes and server metadata.",
        "basis": [
          "CNA",
          "CWE-184",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nocobase/nocobase/security/advisories/GHSA-v8vm-cqh8-q87q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nocobase/nocobase/commit/87c548969ce9258dd7f0d9571c9453ae10bc3fc4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nocobase/nocobase/releases/tag/v2.1.0-alpha.46",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52890",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T21:44:27.365Z",
      "date_published": "2026-07-15T21:07:16.921Z",
      "date_updated": "2026-07-16T12:59:24.289Z",
      "publisher": "GitHub_M",
      "title": "Wekan: Arbitrary file read and server DoS via attachment versions.original.path",
      "affected": {
        "vendors": [
          "wekan"
        ],
        "products": [
          {
            "vendor": "wekan",
            "product": "wekan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00325,
        "percentile": 0.24933
      },
      "nvd": {
        "published": "2026-07-15T22:17:16.310",
        "lastModified": "2026-07-16T14:16:53.827",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52890",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Wekan stores an attacker-controlled attachment path and later streams it without checking that the resolved file remains inside the storage root.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wekan/wekan/security/advisories/GHSA-g6vm-7757-pr88",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/commit/fc92b342ceedcf38dbd614a0f7b50d6dc2b22eb8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/releases/tag/v9.31",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 622,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52891",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T21:44:27.365Z",
      "date_published": "2026-07-15T21:08:02.223Z",
      "date_updated": "2026-07-17T18:23:51.039Z",
      "publisher": "GitHub_M",
      "title": "Wekan: Shell Injection via Avatar Upload",
      "affected": {
        "vendors": [
          "wekan"
        ],
        "products": [
          {
            "vendor": "wekan",
            "product": "wekan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33088
      },
      "nvd": {
        "published": "2026-07-15T22:17:16.450",
        "lastModified": "2026-07-17T19:17:16.647",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52891",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application places attacker-controlled data into a shell command without separating the data from command syntax.",
        "basis": [
          "CNA",
          "CWE-78",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wekan/wekan/security/advisories/GHSA-35j7-h385-2q9g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/commit/a4c74a5980e9f778eb444fd346f32aa3d16786a9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/releases/tag/v9.07",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 439,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52892",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T21:44:27.365Z",
      "date_published": "2026-07-15T21:08:42.926Z",
      "date_updated": "2026-07-16T15:12:17.687Z",
      "publisher": "GitHub_M",
      "title": "Wekan: Read-only board members can create/modify/delete Custom Fields (privilege escalation via read-level authz on write ops)",
      "affected": {
        "vendors": [
          "wekan"
        ],
        "products": [
          {
            "vendor": "wekan",
            "product": "wekan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17507
      },
      "nvd": {
        "published": "2026-07-15T22:17:16.580",
        "lastModified": "2026-07-16T16:19:12.480",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52892",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Mutating custom-field routes use a read-level board-access check instead of the required write-level check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wekan/wekan/security/advisories/GHSA-6733-4wgq-8xvr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/commit/70db04a93fedabe40331f21f86e6bdc91625914e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/releases/tag/v9.32",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-52893",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-08T21:44:27.366Z",
      "date_published": "2026-07-15T21:12:11.088Z",
      "date_updated": "2026-07-18T02:35:24.728Z",
      "publisher": "GitHub_M",
      "title": "Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hook",
      "affected": {
        "vendors": [
          "wekan"
        ],
        "products": [
          {
            "vendor": "wekan",
            "product": "wekan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22479
      },
      "nvd": {
        "published": "2026-07-15T22:17:16.710",
        "lastModified": "2026-07-18T03:16:36.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-52893",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OIDC account hook merges credentials into an existing account by matching email or username without verifying ownership or email_verified.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wekan/wekan/security/advisories/GHSA-mp7g-hj5q-gxhq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/commit/73204d4e0a7d77a1b186b3d76e8eaf2f3e7c9fd9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/releases/tag/v9.32",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 514,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53326",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.398Z",
      "date_published": "2026-07-01T13:32:12.924Z",
      "date_updated": "2026-07-04T11:51:04.894Z",
      "publisher": "Linux",
      "title": "debugobjects: Don't call fill_pool() in early boot hardirq context",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-667",
          "name": "Improper Locking",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00095,
        "percentile": 0.00752
      },
      "nvd": {
        "published": "2026-07-01T14:16:40.443",
        "lastModified": "2026-07-23T20:52:50.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53326",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An allocation performed in hard-interrupt context can wait on a lock that the interrupted path already holds.",
        "basis": [
          "CNA",
          "CWE-667"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3cc90ea0dd0fb1f8db577dcdc027fc46c06049f6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5d95f6b267f3d7fe54f42a3b224bb4a3d3990b41",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/27335c50014102e9077b784ebd314954286afcab",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/44b8b03a9fb5c575548fc72c674653d6baba142a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7bc71bdb1c1526c7f02a6adab324394ff1327b0a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0d046ae106255cba5eb83b23f78ee93f3620247d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 822,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-53327",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.398Z",
      "date_published": "2026-07-01T13:32:13.493Z",
      "date_updated": "2026-07-04T11:51:05.892Z",
      "publisher": "Linux",
      "title": "debugobjects: Do not fill_pool() if pi_blocked_on",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02986
      },
      "nvd": {
        "published": "2026-07-01T14:16:40.550",
        "lastModified": "2026-07-23T20:52:46.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53327",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "fill_pool attempts to block on another real-time lock while current::pi_blocked_on already records a pending lock, corrupting the priority-inheritance invariant.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8a680d54f1adf3e3aa815578684556716fda6f0c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a3383df76f0d7a597066df018409eb9e5e698064",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/3f6a3b24ab7b9d51f6f4778254bef0e5847beb55",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/3a408cae608d9c075dd3a9e5cfc03b3cb0726863",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/33bee10644f8fff3b1a0187ad5ad34513e5e8e72",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5f41161059fd0f1bbf18c90f3180e38cc45a14eb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 434,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-53328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.398Z",
      "date_published": "2026-07-01T13:32:14.030Z",
      "date_updated": "2026-07-01T13:32:14.030Z",
      "publisher": "Linux",
      "title": "sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02348
      },
      "nvd": {
        "published": "2026-07-01T14:16:40.650",
        "lastModified": "2026-07-23T20:52:41.010",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53328",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The sched_ext move path treats a legitimate NULL cgrp_moving_from state as an invariant violation and raises a kernel warning.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cdff2eb97be147d2ce52ac1327841068781f25dc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0ffcad63b19a1cadb475c9f405a93607fdcd0d7c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/bc75f5951fac4e49d175c4433fc08fb1ec01172f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/02e545c4297a26dbbc41df81b831e7f605bcd306",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1580,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-53329",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.398Z",
      "date_published": "2026-07-01T13:32:14.598Z",
      "date_updated": "2026-07-18T07:33:19.828Z",
      "publisher": "Linux",
      "title": "drm/amd/display: Use krealloc_array() in dal_vector_reserve()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03343
      },
      "nvd": {
        "published": "2026-07-01T14:16:40.760",
        "lastModified": "2026-07-23T21:34:08.263",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53329",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "dal_vector_reserve multiplies capacity by element size in 32-bit arithmetic, wraps the allocation small, and later appends beyond it.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9540b0a4d13e4ede64ae1197d66a176d2149daa9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/31180638a33acad12c863132704a76536fb66211",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b15825deac1acff72638bbc8f05b89ceef8dfb13",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/201151e120f0062bcda21cad5d007b82725ad23b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a914aa802669e073f014dae2e5708633b5cecd34",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e09689286385a66311ac6922af95339d7a3cef8d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/de988c7a31f0774f07894cfe4802996f318e2870",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/da48bc4461b8a5ebfb9264c9b191a701d8e99009",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53330",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.398Z",
      "date_published": "2026-07-01T13:32:15.160Z",
      "date_updated": "2026-07-10T11:53:48.960Z",
      "publisher": "Linux",
      "title": "drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.0251
      },
      "nvd": {
        "published": "2026-07-01T14:16:40.893",
        "lastModified": "2026-07-23T21:34:03.903",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53330",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "dp_get_eq_aux_rd_interval can index aux_rd_interval[7] when a sink reports eight repeaters even though the array has only indices 0 through 6.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/454d3b3d499c18373f8960d31aea48338a3ca9e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/dc1490927d79fe9621e29f4a4f5d7b5ccb6aea3e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e8b4d37eba05141ee01794fc6b7f2da808cee83b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 715,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53331",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.398Z",
      "date_published": "2026-07-01T13:32:15.733Z",
      "date_updated": "2026-07-01T13:32:15.733Z",
      "publisher": "Linux",
      "title": "slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02422
      },
      "nvd": {
        "published": "2026-07-01T14:16:40.997",
        "lastModified": "2026-07-23T21:33:58.167",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53331",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Slimbus shutdown path acquires tx_lock before ctrl->lock while other paths take them in the reverse order, creating an ABBA deadlock.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3d1561537237c6cc1db76155183d8bbdac2339f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/dc4d5c57e012c2c669793deb1515a57bbc6bf5dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d54a221b0f3cd9e1f03f18104be34e02a8258fae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/aad4337a21b9ad3ae8d668fa8678d05e26ecbaa8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/9f0d45d509b434c54da10e01f4ef8086e4583401",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/9708eb50fd7343145b422be852f890212155d845",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/55f2ea9ff83cc27a85526b14bc9b32f96a08d6ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1678,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-53332",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.398Z",
      "date_published": "2026-07-01T13:32:16.289Z",
      "date_updated": "2026-07-24T14:33:51.996Z",
      "publisher": "Linux",
      "title": "slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02423
      },
      "nvd": {
        "published": "2026-07-01T14:16:41.137",
        "lastModified": "2026-07-24T15:18:00.473",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53332",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The NGD driver enables interrupts and registers callbacks before the NGD work structures are initialized, allowing a concurrent callback to queue NULL work.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/946b97d632f0f58a705dafac644c1e9346e01f35",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2047eeb38db878a31f58db19d98f8aedf284342e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/afc631e246936a40558f494112a4188401382671",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/290014c7987636e6105bba89fa04cb4d59f775c1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fa3790c7ea98328ddc3f7d8bf40247556245a6fc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/24ec89123fc9d0d24ce719dcf7fd6c57e5b0d753",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/08564e15c47a5fb0af6643a43ee15521d49bcdea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2a9d50e9ea406e0c8735938484adc20515ef1b47",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1508,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53333",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.398Z",
      "date_published": "2026-07-01T13:32:16.852Z",
      "date_updated": "2026-07-01T13:32:16.852Z",
      "publisher": "Linux",
      "title": "mm/mincore: handle non-swap entries before !CONFIG_SWAP guard",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01607
      },
      "nvd": {
        "published": "2026-07-01T14:16:41.243",
        "lastModified": "2026-07-23T21:33:48.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53333",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mincore_swap applies a non-swap-entry test only inside the CONFIG_SWAP branch, so a build without swap can mis-handle migration or hwpoison entries.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a8f91ddf67f669f547bb9fb559738da6f8ee2cf3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/3481d4372ae34243f7025925314385b852c50f7e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0c25b8734367574e21aeb8468c2e522713134da7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 666,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53334",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.398Z",
      "date_published": "2026-07-01T13:32:17.419Z",
      "date_updated": "2026-07-01T13:32:17.419Z",
      "publisher": "Linux",
      "title": "mm/damon/reclaim: handle ctx allocation failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02087
      },
      "nvd": {
        "published": "2026-07-01T14:16:41.350",
        "lastModified": "2026-07-23T21:33:43.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53334",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A failed context allocation leaves a null pointer that the following path dereferences.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/66bc00ea37fa8ec14be5a3909d067a5967ef234b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/635b45ce61de53a9357e28ac97461428cdb650f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7e2ed8a29427af534bf2cb9b8bc51762b8b6e654",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 983,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53335",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:17.953Z",
      "date_updated": "2026-07-01T13:32:17.953Z",
      "publisher": "Linux",
      "title": "mm/damon/lru_sort: handle ctx allocation failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02097
      },
      "nvd": {
        "published": "2026-07-01T14:16:41.460",
        "lastModified": "2026-07-23T21:33:33.100",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53335",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Linux error path dereferences an object after allocation or lookup can return null.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6d48f15659395bf1381114f01be91bc68e0be46a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/daab1996431a71f43219dcac48ecc9ad2aad3f1c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ab04340b5ae5d52c1d46b750538febcde9d889e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 536,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:18.489Z",
      "date_updated": "2026-07-01T13:32:18.489Z",
      "publisher": "Linux",
      "title": "nvmem: layouts: onie-tlv: fix hang on unknown types",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01702
      },
      "nvd": {
        "published": "2026-07-01T14:16:41.560",
        "lastModified": "2026-07-23T21:33:30.033",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53336",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Linux ONIE TLV parser encounters an unknown type without advancing its cursor, causing the parsing loop to repeat indefinitely.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/033d498b0f473c6456be5f885be172024ad84972",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/fd47edeabadfaa75422009dc5894e92c4c697517",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/4a4d21f531ccf5bb333d99b620e0d66551f3652c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/4f27eb01619c36cc8e3ce9a2a9af97f145f5d1c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ea41020b9018e31c2ea7e9d89021e3e6d7470883",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-53337",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:19.046Z",
      "date_updated": "2026-07-01T13:32:19.046Z",
      "publisher": "Linux",
      "title": "net: bonding: fix NULL pointer dereference in bond_do_ioctl()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01752
      },
      "nvd": {
        "published": "2026-07-01T14:16:41.667",
        "lastModified": "2026-07-23T21:33:19.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53337",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "bond_do_ioctl calls slave_dbg before checking whether __dev_get_by_name returned NULL, and the macro dereferences slave_dev->name for a nonexistent interface.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1b7558c85493467b2ea20738866b822db6442034",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b02b2e3e876c18733b868a29064abd11cdbf8feb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/66693957bacd1c9dae6188a7312d6be69a221f2d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a629418d463fb50d132a1aa063b0105857311e5f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c2cfe290fdb1c32a4f4eb2b8ca3f363b305d21ba",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/bcb8fad90f27300add583a8371db504b766d95c7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b0878106ddc486375084145848ff255dedfff46a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a764b0e8317a863006e05732e1aefe821b9d8c2d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1085,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53338",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:21.147Z",
      "date_updated": "2026-07-01T13:32:21.147Z",
      "publisher": "Linux",
      "title": "net: airoha: Add NULL check for of_reserved_mem_lookup() in airoha_qdma_init_hfwd_queues()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01623
      },
      "nvd": {
        "published": "2026-07-01T14:16:41.807",
        "lastModified": "2026-07-23T21:33:12.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53338",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "airoha_qdma_init_hfwd_queues dereferences the result of of_reserved_mem_lookup without checking whether it is null.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/01f7d4b504580664d36faea5671cde5e3f0d8a5b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/cdb96c42db7b256348f9b57718debfaa4bca6b39",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f9f25118faa4dd2b6e3d14a03d123bbdbd59925d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 858,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53339",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:21.709Z",
      "date_updated": "2026-07-01T13:32:21.709Z",
      "publisher": "Linux",
      "title": "i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01748
      },
      "nvd": {
        "published": "2026-07-01T14:16:41.910",
        "lastModified": "2026-07-23T21:33:01.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53339",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "cci_remove() halts both controller masters even when only one completion object was initialized, dereferencing the uninitialized master's NULL completion state.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e8669d12da0ade52adfe0abe96cd99e708abc9bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/4d2b4a9cda6837e5ee1de1290f2e773a713b71e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a50b8adb9cdb9a495b0b45583956897b7411ed7a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7107627b8b35015027201e7a095a3f6e30b4a46f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/4cd206c1d57a9370d5219f7b1fc45169d7bdf951",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a162a260c8c4db7501c65220e76913e8e351f823",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8ce7ff721a5e9d06d53ef65d01c89fce6d26d6ff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/729ac5a4b966aac42e08a94dea966f4429008548",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1044,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53340",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:22.276Z",
      "date_updated": "2026-07-01T13:32:22.276Z",
      "publisher": "Linux",
      "title": "i2c: imx: fix clock and pinctrl state inconsistency in runtime PM",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01617
      },
      "nvd": {
        "published": "2026-07-01T14:16:42.040",
        "lastModified": "2026-07-23T21:32:49.007",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53340",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The I2C suspend sequence disables a clock before all users are quiescent and can leave the controller in an invalid state on resume.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9fa82cf393bafc7bd7ca15c1d5cbd5b57ab9de1d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c8f5269c1bf505847bc7dbb92054594790114de6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8783fb8031799f1230997c16df8c8dce9fcd1841",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 668,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53341",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:22.873Z",
      "date_updated": "2026-07-18T07:33:21.019Z",
      "publisher": "Linux",
      "title": "fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02136
      },
      "nvd": {
        "published": "2026-07-01T14:16:42.143",
        "lastModified": "2026-07-23T21:32:39.067",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53341",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "may_decode_fh reads mount::mnt_ns without RCU protection while concurrent unmount can free the namespace before the later user_ns dereference.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/15ea8dc42a02259d49dee38a658d40f60fcd75ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/32138633e51e6db59e474765cf93268c92b42888",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a8ed2c29fcfdac78db96c9da4e659c8a513f2a94",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/40ab6644b99685755f740b872c00ef40d9aa870e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1969,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-53342",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:23.449Z",
      "date_updated": "2026-07-01T13:32:23.449Z",
      "publisher": "Linux",
      "title": "arm64: mm: call pagetable dtor when freeing hot-removed page tables",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01607
      },
      "nvd": {
        "published": "2026-07-01T14:16:42.260",
        "lastModified": "2026-07-23T21:32:31.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53342",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ARM64 hot-remove frees page-table pages without the destructor paired with their constructor, leaving page type, counters, and lock allocations live.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/95f27fcda681021ed3906d3cae7e68b6a57a1d8e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/aaa688ac9f18207f7452c6472e647c1febaea6a3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c594b83457ccdee76d458416fb3bc9348a37592f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1574,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53343",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:23.979Z",
      "date_updated": "2026-07-01T13:32:23.979Z",
      "publisher": "Linux",
      "title": "ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 17,
        "versionRangeCount": 16,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01722
      },
      "nvd": {
        "published": "2026-07-01T14:16:42.363",
        "lastModified": "2026-07-23T21:32:28.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53343",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ARM reads byte-granular KASAN shadow with an unaligned word load, causing an alignment fault during task switching.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c0b8c148a7754826156993ed6442d31536ec86b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c2e3aadc8fef7da068490597fc5582f8f362aeb2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c74990828d3c486ee44aaa68240eb3abff289d1c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/517720913bd3c17a52cd55a740064f68455ab88e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2a4dc9a0ac3326e79fb58fdaae724b92127709a9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/77a1f6883dc6e837bb2cb30b9b02e2f94338e2c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 775,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-53344",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:24.546Z",
      "date_updated": "2026-07-01T13:32:24.546Z",
      "publisher": "Linux",
      "title": "pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.00998
      },
      "nvd": {
        "published": "2026-07-01T14:16:42.480",
        "lastModified": "2026-07-23T21:32:16.227",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53344",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pinctrl driver initializes regmap before setting the device and address fields that regmap's probe-time SPI read dereferences.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3a13bb9540dfd7014c5601608afcbbadbbcfd673",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8473c3a197b57ff01396f7a2ec6ddf65383820d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 414,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-53345",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:25.098Z",
      "date_updated": "2026-07-10T11:53:49.955Z",
      "publisher": "Linux",
      "title": "KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01698
      },
      "nvd": {
        "published": "2026-07-01T14:16:42.573",
        "lastModified": "2026-07-22T19:16:15.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53345",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A writable guest-page mapping can survive the last userspace exit when no later KVM_RUN occurs, leaving the allocation unreleased during vCPU destruction.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/033d39e41fc30f484f4e4f37fb4cd76b12cbb18e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/66a8e7ddd901023c89a2733494d827eca3f9c1b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/343e95c8ecc40e0738975ef4ee24c0c35e800e6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/99d7d43784ae3235026581e9bf892c036e04c8e6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8618004d3e897c0f1b71d9a9ab860461289bb89a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1854,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-53346",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:25.668Z",
      "date_updated": "2026-07-01T13:32:25.668Z",
      "publisher": "Linux",
      "title": "rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01901
      },
      "nvd": {
        "published": "2026-07-01T14:16:42.693",
        "lastModified": "2026-07-22T19:16:11.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53346",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A compiler flag fails to mark compiler-generated functions for unwinding, so kernel boot patching applies an invalid partial pointer-authentication sequence.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bde772ee239720af216fb0b14753971059e132dc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d0f25a1755f2c15b1746379c8d9d7dfde85f58f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7de13410f59e59b21d3c268a6e22d40f5d9d8a54",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ac35b5580ace12e5d0a0b5e61e36d2c4e1ffa29c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1426,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-53347",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:26.262Z",
      "date_updated": "2026-07-01T13:32:26.262Z",
      "publisher": "Linux",
      "title": "drm/virtio: Fix driver removal with disabled KMS",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01696
      },
      "nvd": {
        "published": "2026-07-01T14:16:42.800",
        "lastModified": "2026-07-22T19:15:45.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53347",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The virtio GPU removal path shuts down uninitialized atomic and modesetting state when KMS is disabled.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ed3e134700a2e07caa99b9bc0683ebbe0327c562",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/38a5f891cda6d121c149c94cda89c31ec7024ee3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/19a6a00ff50c284f3a9818882ad2be58b33b790a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/15e561869a8b4e4db69733be1d6f33770664f989",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f329e8325e054bd6d84d10904f8dd51137281b92",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-53348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:26.850Z",
      "date_updated": "2026-07-01T13:32:26.850Z",
      "publisher": "Linux",
      "title": "ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.00999
      },
      "nvd": {
        "published": "2026-07-01T14:16:42.907",
        "lastModified": "2026-07-22T19:15:37.717",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53348",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A failed probe leaves a registered serial port pointing to devm-freed driver data because its error path does not unregister the port.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9a4895059bb6a8505098a9f75de187fd15631fc8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e4c60a1d4b6ccc66aefb3789cd908d4f9482eefd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1748,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-53349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:27.412Z",
      "date_updated": "2026-07-01T13:32:27.412Z",
      "publisher": "Linux",
      "title": "netfilter: nf_conntrack: destroy stale expectfn expectations on unregister",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01738
      },
      "nvd": {
        "published": "2026-07-01T14:16:43.003",
        "lastModified": "2026-07-22T19:15:07.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53349",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "nf_conntrack unregisters an expectation callback without removing live expectations that retain a raw pointer to the module text, so a later expected connection can call into unloaded code.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fbfde85308b99938a6092c48753214d190ece48d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/29d8cc44bbdf7b83a1929912214afe6643c1b4f1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f92c90a2a3e6ff6f9f7fe88fde9004b4ca8f956d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/9d017671dcfcec23321fb7962dea624f9e71ddb1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/bf8c0b5dd203be94c2ad50e264cec19267c6bd39",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c3009418f9fa1dcb3eb86f4d8c92583537b5faa3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1969,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-53350",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:27.975Z",
      "date_updated": "2026-07-01T13:32:27.975Z",
      "publisher": "Linux",
      "title": "ASoC: wm_adsp: Fix NULL dereference when removing firmware controls",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01738
      },
      "nvd": {
        "published": "2026-07-01T14:16:43.137",
        "lastModified": "2026-07-22T19:15:04.307",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53350",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "wm_adsp_control_remove dereferences cs_ctl->priv even for control paths that never allocated private data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5ee9bbe2af2f373e08d3017f9aef2f2eaf29fbc3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/10def23b67b42679d5b1a356e1a6f3498bd188c3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2f1be283aa777d655525d000d16474b7e7d015ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/12e579b889624ec54a201d98fdff975de556c731",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/6effd6f7b0ba1f5d1df702b2ef7460bcc215e9b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7d3fb78b550301e43fdc60312aed733069694426",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 866,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-53351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.399Z",
      "date_published": "2026-07-01T13:32:28.548Z",
      "date_updated": "2026-07-01T13:32:28.548Z",
      "publisher": "Linux",
      "title": "riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFI",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.01005
      },
      "nvd": {
        "published": "2026-07-01T14:16:43.253",
        "lastModified": "2026-07-22T19:14:59.953",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53351",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The RISC-V core-dump regset uses the wrong note-type declaration, causing the ELF dumper's note-name invariant to fail and warn.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/08200bef0983ffed039ab399df0cba8d900ce5fc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e3573f739e3dadab57ec80488d07e05c8f6e82d3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 278,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-53352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-01T13:32:29.105Z",
      "date_updated": "2026-07-01T13:32:29.105Z",
      "publisher": "Linux",
      "title": "signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00086,
        "percentile": 0.0041
      },
      "nvd": {
        "published": "2026-07-01T14:16:43.347",
        "lastModified": "2026-07-22T19:14:54.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53352",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "execve aborts a group stop but leaves the caller's JOBCTL pending flags set, causing it to consume an already-zero group_stop_count.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2b32b2fb241435145ea199efac024540759d2495",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/391ebe74456a0f1d60b3ba4a8a64d9f44c1728fe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f8d720bc2e35d568c18be0644e92a468de428370",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f4aae11abb449dc536269705d0419ec69480faa9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/76aebd9ef20078719dfd6282d3b06c27e900a65a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8c046f36222c6ce1e0daef2c45c891c72602f8a1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/dfcd0ba14769d94d76ac9d9814b85e7fcacd4e29",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/90918794a4e2c3b440f8fcf3847765a8b1d81b25",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1911,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-01T13:32:29.699Z",
      "date_updated": "2026-07-01T13:32:29.699Z",
      "publisher": "Linux",
      "title": "hsr: Remove WARN_ONCE() in hsr_addr_is_self().",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01688
      },
      "nvd": {
        "published": "2026-07-01T14:16:43.490",
        "lastModified": "2026-07-22T19:14:48.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53353",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "An HSR device remains discoverable after self_node is cleared during deletion, violating the warning's assumed lifecycle state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/271355c2ef6171dbc815e7ae653eed63444bbd58",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0232b6fcb7615fb7fecfe0727a23065a53e228b8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/66a46e22396fd5d09606f37f73643eb20e99aa42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d71bb171661ec0225bf4babdd4d296d744982fb3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/afd0f17ca46258cec3a5cc48b8df9327fe772490",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 3758,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-53354",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-01T13:32:30.246Z",
      "date_updated": "2026-07-18T07:33:22.248Z",
      "publisher": "Linux",
      "title": "arm64: errata: Mitigate TLBI errata on various Arm CPUs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 19,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02381
      },
      "nvd": {
        "published": "2026-07-01T14:16:43.627",
        "lastModified": "2026-07-22T19:14:41.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53354",
        "family": "HARDWARE_PHYSICAL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Affected Arm CPUs can mishandle a broadcast TLBI and retain translation state that should have been invalidated.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/925058203229403008d77a52b1e63e2ae5f4a3cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8364384ae82fbffdf8968abaac3455ed854da18d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7c3ad9365079e716b57d2363d3081ee7680cc18e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e717a4d08779f1a28d6e0275e75040b12c33c753",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/4e7c80742e6dada9f8b9ad63f3a49c03af07ecb8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d4fd4282204044fdedd1e42abbe70a9206f74ec0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1b47b1e1d8675fdf5f6e11e7fa19c704d8c6f5cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1268c64e2bcb6e968152990e87bd10c440fcc9c0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/cfd391e74134db664feb499d43af286380b10ba8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1284,
        "referenceCount": 9,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-53355",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-01T13:32:30.831Z",
      "date_updated": "2026-07-18T07:33:23.522Z",
      "publisher": "Linux",
      "title": "net: rds: clear i_sends on setup unwind",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 26,
        "versionRangeCount": 21,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00399,
        "percentile": 0.32664
      },
      "nvd": {
        "published": "2026-07-01T14:16:43.790",
        "lastModified": "2026-07-22T19:14:36.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53355",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "When rds_ib_setup_qp() fails after allocating i_sends but before allocating i_recvs, the sends_out path frees i_sends without clearing the pointer.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/66cccec111421a10efdc2c74499d15b93e7acae5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2c5e5e4a5970c41f16e3ad801a78719ed5d5c71b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/29d940026dce39e3018dab6f67c9427249321270",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e7cf30aa5f1fc6c2a86df65df8b731df20e44d79",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f16ad421a4e3e7db2d14bdf3b16f583bc4f3b30a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1d4ec754ee3871f7e3670c67bb0298c9c5760926",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/27040bbca289a704eafcacca167d310c6ce2b1bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/20cf0fb715c41111469577e85e35d15f099473e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 713,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 26
      }
    },
    {
      "cve_id": "CVE-2026-53356",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-01T13:32:31.428Z",
      "date_updated": "2026-07-18T07:33:24.602Z",
      "publisher": "Linux",
      "title": "drm/i915/gem: Fix phys BO pread/pwrite with offset",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02173
      },
      "nvd": {
        "published": "2026-07-01T14:16:44.733",
        "lastModified": "2026-07-22T19:14:30.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53356",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "sg_page() returns struct page pointer not (void *) so the scaling of pread/pwrite is wrong for phys BO and wrong parts of BO would be accessed if non-zero offset is used.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/40f738991058eb3e3530c3006a5bd6fd5e29f035",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1ec8fc63e9cdb22da54e48e536c9204020416fc6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/14469860e2e39b7095dcd658d2bad38a11110a68",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/07c33be968d9e0cab6cba38c81850a09942fcb2e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/3bd168dd835b93a3862cd05b0d13c432b115f9d6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/32d4c5d328a3ff995420f4f85163e1e403f43628",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/dd51a2eeb93bc6faa892ff9083911dd23f82c187",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d21ad938398bca695a511307de38a65889e3b354",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 458,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53357",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-02T13:43:17.077Z",
      "date_updated": "2026-07-18T07:33:25.711Z",
      "publisher": "Linux",
      "title": "Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17368
      },
      "nvd": {
        "published": "2026-07-02T15:17:03.103",
        "lastModified": "2026-07-22T19:06:30.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53357",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A close-versus-disconnect race frees an L2CAP child socket while the listening-socket cleanup path still uses it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/751de6ec671fe75ad9cf65a0638d2a06b6a5984d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/407217734835d21d4e0105ebf347860dc1806f88",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7eebd4c2c86f573af87ff165d08a83432eb0b919",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5d86d2f1b4d9a508c441d3e45277ae1a73cfed57",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/87c543e2f78d0871f271df92dab98901bbd5b6f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/added1213395071470a900cc845a042fb51882a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a5ca86a6097a8b030ca3226cd300b17ed330f966",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ab1513597c6cf17cd1ad2a21e3b045421b48e022",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1966,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53358",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-02T13:43:17.630Z",
      "date_updated": "2026-07-18T07:33:26.927Z",
      "publisher": "Linux",
      "title": "Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-667",
          "name": "Improper Locking",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09495
      },
      "nvd": {
        "published": "2026-07-02T15:17:03.283",
        "lastModified": "2026-07-22T19:07:50.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53358",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Bluetooth cleanup closes a channel under a lock order that conflicts with the connection lock order instead of deferring closure to the correctly ordered timer path.",
        "basis": [
          "CNA",
          "CWE-667"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3634cbdc2eb414b69ffa752ddbe5e0458518e321",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e1c100e2d61bd8c718b7d91fe3e050780a9bf72d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/89dec92041717b027216e110599e4f6d6c921b79",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/50dfec218808b148ab4247b1858031b7a32015c5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/859d3ace791ed878ae9ba5522c7844d960da8f88",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7555fd885a0603f50e49a655850a1f2bd8a25398",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8c8e620467a7b51562dbcefbd1f09f288d7d710d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1028,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-04T11:51:49.052Z",
      "date_updated": "2026-07-29T18:22:55.066Z",
      "publisher": "Linux",
      "title": "KVM: x86: Fix shadow paging use-after-free due to unexpected role",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00908,
        "percentile": 0.56472
      },
      "nvd": {
        "published": "2026-07-04T12:17:01.760",
        "lastModified": "2026-07-29T19:16:47.180",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53359",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A reachable path retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b1337aae5e194324e4810d561764e7793f8b3864",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/9291654d69e08542de37755cebe4d5b02c3170d1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2ad3afa40ac6aa340dada122f9abfa46c0a6eb35",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5e470998a23e4c3d89ed24e8172cb22747e61efa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1ae7d5a6db6c190ce183e3098ca0e0846e14d462",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/81ccda30b4e83d8f5cc4fd50503c44e3a33abfeb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/06/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List"
          ]
        },
        {
          "url": "https://github.com/V4bel/Januscape/blob/main/assets/write-up.md",
          "host": "github.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1609,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-53360",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-04T11:53:58.657Z",
      "date_updated": "2026-07-18T07:33:29.230Z",
      "publisher": "Linux",
      "title": "KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08076
      },
      "nvd": {
        "published": "2026-07-04T12:17:01.880",
        "lastModified": "2026-07-22T19:07:37.640",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53360",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "snp_begin_psc bounds a guest-controlled entry index by a protocol maximum instead of the allocated scratch-buffer size, enabling heap reads and writes past that allocation.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bf9ba093fbb83c0c9a3dedd50efec29424eca2fc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c9b4198fbc6ed99a9da4bee9f74bb730f926c9ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b328ede59ac34e7998e1eee5e5f0cc26c2a91846",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/db3f2195d29344a3cf1e9dd9ab7f21ced7308cf7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 3077,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-53361",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-04T11:54:52.543Z",
      "date_updated": "2026-07-18T07:33:30.463Z",
      "publisher": "Linux",
      "title": "af_unix: Set gc_in_progress to true in unix_gc().",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 13,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02514
      },
      "nvd": {
        "published": "2026-07-04T12:17:02.010",
        "lastModified": "2026-07-22T19:07:32.853",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53361",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent garbage-collection scheduling can start unix_gc with gc_in_progress cleared, violating the state relied on by MSG_PEEK handling.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/82c17e13d404f686e164590483fd6c1abaa675d0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/591f1ac217428a6d2b32a8ac14aac0fab44f155a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0cfa78c050662784fc8e3ab26dbfd1dc632b2082",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d82ba05263c69fa2437fe93e4e561cc40f4c03af",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1227,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-53362",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-04T11:56:35.864Z",
      "date_updated": "2026-07-18T07:33:31.678Z",
      "publisher": "Linux",
      "title": "ipv6: account for fraggap on the paged allocation path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18261
      },
      "nvd": {
        "published": "2026-07-04T12:17:02.113",
        "lastModified": "2026-07-22T19:07:28.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53362",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The linear allocation omits fraggap space, allowing subsequent fragment handling to overwrite skb_shared_info.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1725,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-53363",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-10T11:55:31.820Z",
      "date_updated": "2026-07-18T07:33:32.898Z",
      "publisher": "Linux",
      "title": "xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21794
      },
      "nvd": {
        "published": "2026-07-10T12:17:22.983",
        "lastModified": "2026-07-22T19:07:24.213",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53363",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "iptfs_consume_frags moves page-backed fragments without preserving their shared-read-only ownership marker, allowing later in-place encryption on shared pages.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/dd66f7f6e360ee82cd905517726f8e9091265de5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c885d111ed9f5a0a1f3cc4e87a50db6518abaa6c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e9096a5a170e7ecd6467bc2e08668ec39897cda7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 631,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53364",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-13T17:33:52.302Z",
      "date_updated": "2026-08-03T09:32:35.820Z",
      "publisher": "Linux",
      "title": "Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 11,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01728
      },
      "nvd": {
        "published": "2026-07-13T18:16:28.297",
        "lastModified": "2026-08-03T10:16:30.547",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53364",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Linux loses an allocated object on an error path without releasing it.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/488e808e3fa53200f3ef3324c45fcba4ae9f4972",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e6b78019664dfe37c3dc707f50e7b453d6c7726d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a59d4f4217e6200ca9180643e5738a87d3fa8be0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/bfa9d28960ed677d556bdf097073bc3129686229",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 591,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-53365",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-13T17:33:52.863Z",
      "date_updated": "2026-07-24T14:33:53.406Z",
      "publisher": "Linux",
      "title": "vsock/virtio: fix zerocopy completion for multi-skb sends",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01726
      },
      "nvd": {
        "published": "2026-07-13T18:16:28.433",
        "lastModified": "2026-07-24T15:18:00.630",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53365",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The virtio-vsock send loop attaches zerocopy completion tracking only to the final fragment, leaving earlier pinned pages without release notification.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/293fe8f2d1b5ac464ca16a8eba09571bbbb34ba9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/76b995bc57bd90cb6e954e1966fbd8786da47f0d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b3155f2b78db21e99256bcf7eb902f24ff6d5338",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ae38d9179190a956e2a87a69ef1dd6f451b51c4d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1104,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-53366",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-16T05:13:40.893Z",
      "date_updated": "2026-07-24T14:33:54.829Z",
      "publisher": "Linux",
      "title": "ipv4: account for fraggap on the paged allocation path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06742
      },
      "nvd": {
        "published": "2026-07-16T06:16:27.333",
        "lastModified": "2026-07-24T15:18:00.757",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53366",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The paged __ip_append_data path omits fraggap from the linear allocation while copying those bytes there, leaving the destination undersized by fraggap.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5c6375bced6147ec2e460ee3b653f4860d5ecdc2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ce494707a9c07f27c219ca67f3e138061f53d9b3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a9c24eda24bd15f432e37824e6fc440977cb241c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/77798d7be6ef71e72fb6fc8a2901bf74ebc9706f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c04d9ece23deb9e26c19f9ca215e98b3295aa1bb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/eca856950f7cb1a221e02b99d758409f2c5cec42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 951,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-53367",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-19T09:10:28.879Z",
      "date_updated": "2026-07-19T09:10:28.879Z",
      "publisher": "Linux",
      "title": "selinux: fix avdcache auditing",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01651
      },
      "nvd": {
        "published": "2026-07-19T09:17:01.773",
        "lastModified": "2026-07-29T16:55:50.037",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53367",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SELinux reuses a cached audited-permission vector for a different permission request instead of recomputing the current audit decision.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e3e722ea88e051ae5361dc540c01ba18f87b5ffd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/bce6a32bc888dfebb6a7d4dee454228b71ed8369",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f92d542577db878acfd21cc18dab23d03023b217",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-53368",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.400Z",
      "date_published": "2026-07-19T09:10:29.573Z",
      "date_updated": "2026-07-20T13:39:40.917Z",
      "publisher": "Linux",
      "title": "f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01873
      },
      "nvd": {
        "published": "2026-07-19T09:17:01.903",
        "lastModified": "2026-07-29T16:55:46.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53368",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "f2fs_need_dentry_mark reads NAT flags without the checkpoint writer's lock, so it records an inode mark from a state that changes before __write_node_folio consumes it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bedb710b63ae1bd617e65d0a8cf6cea1200b3753",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b28a83ea4934215b5de906c3ee4fbfbc651573e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/019f9dda7f66e55eb94cd32e1d3fff5835f73fbc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1557,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53369",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T09:10:30.283Z",
      "date_updated": "2026-07-20T13:39:41.882Z",
      "publisher": "Linux",
      "title": "udf: reject descriptors with oversized CRC length",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03725
      },
      "nvd": {
        "published": "2026-07-19T09:17:02.017",
        "lastModified": "2026-07-29T16:55:36.617",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53369",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "udf_read_tagged skips descriptor CRC verification when the declared CRC span exceeds the descriptor, allowing a malformed descriptor to bypass its integrity check.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/832ab4a882dc9b3c0155490d9993642ef545fd22",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7d1b6adbf90df6c8941090d5646fbeca25ba9770",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/3dede76d525919bb966f9213e131af685de5ff99",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/50dfaf4a027742b4fcdc3e9305e7199ece9bc6a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/31605bbe94557bff721eaf041001169d44ac6f98",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1873eb81c65d3f849418d7386baa39c439c9fc38",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/fdb26e628d2a211a23815d375bd33bdf863344e2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/55d41b0a20128e86b9e960dd2e3f0a2d69a18df7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53370",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T09:10:30.990Z",
      "date_updated": "2026-07-19T09:10:30.990Z",
      "publisher": "Linux",
      "title": "perf/x86/intel: Improve validation and configuration of ACR masks",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02514
      },
      "nvd": {
        "published": "2026-07-19T09:17:02.153",
        "lastModified": "2026-07-29T16:55:32.737",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53370",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An early return skips group validation and leaves a stale mask uncleared for the next state transition.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/aab56b95bee3ff79176b13443cd9d7cfe9747df0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c05e01cef47d9b4969eae2dcf9467e2a555bcb4f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5ad732a56be46aabf158c16aa0c095291727aaef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1362,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T09:10:31.706Z",
      "date_updated": "2026-07-19T09:10:31.706Z",
      "publisher": "Linux",
      "title": "RDMA/ionic: bound node_desc sysfs read with %.64s",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.0164
      },
      "nvd": {
        "published": "2026-07-19T09:17:02.260",
        "lastModified": "2026-07-29T16:55:29.373",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53371",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "hca_type_show prints a user-controlled 64-byte node_desc with unbounded %s even though the array may lack a NUL terminator, reading into adjacent fields.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/61df14f306f153bffa2f3c74a94ff5a85c99fa39",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a3e9372203afde2c62576356bb9a17890bc7fd6c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/654a27f25530d052eeedf086e6c3e2d585c203bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 877,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53372",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T09:10:32.453Z",
      "date_updated": "2026-07-19T09:10:32.453Z",
      "publisher": "Linux",
      "title": "iommu/vt-d: Block PASID attachment to nested domain with dirty tracking",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01652
      },
      "nvd": {
        "published": "2026-07-19T09:17:02.367",
        "lastModified": "2026-07-29T16:55:25.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53372",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Linux permits nested dirty tracking to be enabled with an incompatible attached VT-d device configuration.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3ea9ce757bd3de955b56e7bc5672fc479e40b045",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/9009c1af5458322469fa9a4371081a4449c5947d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/cc5bd898ff70710ffc41cd8e5c2741cb64750047",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53373",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T10:01:57.632Z",
      "date_updated": "2026-07-20T13:39:42.904Z",
      "publisher": "Linux",
      "title": "mm/vma: do not try to unmap a VMA if mmap_prepare() invoked from mmap()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01601
      },
      "nvd": {
        "published": "2026-07-19T11:16:38.390",
        "lastModified": "2026-07-29T16:55:22.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53373",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The mmap_prepare error path tries to unmap a VMA that mmap supplied before it entered the maple tree, violating the cleanup rule for a still-detached VMA.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5394bcb746503f2ae4b206212416dccea78e3773",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/619eab23e1ce7c97e54bfc5a417306d94b3f6f13",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1324,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-53374",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T10:01:58.292Z",
      "date_updated": "2026-07-20T13:39:43.888Z",
      "publisher": "Linux",
      "title": "drm/amdgpu: zero-initialize GART table on allocation",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02171
      },
      "nvd": {
        "published": "2026-07-19T11:16:38.500",
        "lastModified": "2026-07-29T16:55:18.957",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53374",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Linux GART path uses page-table entries before initializing them.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/40df11255d71b02e20e70579f1b12b687e396e26",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/91fbb5e635c8fb1b49e15c19da06480089ef719f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8ae8b9e74bab94aab1d79f1688129bcc61c8b29a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b17175d0a375b3ed5e81597dac4983fdb46e478d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/791941be5da125d9a1b228582bfdc300c05d05b3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e6c2e6c2e1fa066968a16aca1cb66cd1bdde7741",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 828,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-53375",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T10:01:58.898Z",
      "date_updated": "2026-07-20T13:39:44.889Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/vce: Prevent partial address patches",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02172
      },
      "nvd": {
        "published": "2026-07-19T11:16:38.623",
        "lastModified": "2026-07-29T16:55:14.563",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53375",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The VCE patcher can accept only one valid half of a 64-bit address and write the resulting partial address into firmware state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2d66d1f5d8c0434e9a5ad21cc6eaf3a5e32141d5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/944db9cfa5373f67eb94621d4c2eee572c05fa3f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0ee17150763962671f43a62ddf8f6ea1feaff438",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b3d1a0a45c4aec484fa2a5b060b611e3d3064470",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ea2c554e700b86a04534b4c24ece5844e8c5f07e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/de2a02cc28d6d5d37db07d00a9a684c754a5fd74",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-53376",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T10:01:59.527Z",
      "date_updated": "2026-07-20T06:41:19.041Z",
      "publisher": "Linux",
      "title": "drm/amdkfd: Add upper bound check for num_of_nodes",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.0258
      },
      "nvd": {
        "published": "2026-07-19T11:16:38.740",
        "lastModified": "2026-07-29T16:55:09.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53376",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The amdkfd path validates only the lower bound of an attacker-influenced index and can access memory past the upper end of the array.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4a8093c7def141cc6e854fbe3f9693867982418f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/6ba6ec5fcbb0d03ca11ed1cc38d57a7deb6c6b20",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/44d5a450c04d3d734c13a03561c3131020d66edf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7b80137eb8aa9d1cbfe7ccf3eeb1faa94ae35d7e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/74b73fa56a395d46745e4f245225963e9f8be7f1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 281,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-53377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T10:02:00.168Z",
      "date_updated": "2026-07-20T06:41:20.243Z",
      "publisher": "Linux",
      "title": "drm/msm: always recover the gpu",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02485
      },
      "nvd": {
        "published": "2026-07-19T11:16:38.847",
        "lastModified": "2026-07-29T16:55:00.823",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53377",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The GPU recovery worker advances the hung ring fence and then exits when no work remains, leaving the GPU hung for the next submission.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/132b8d51f0ffbee6e4e1ebbe1a50330aaf2dbd5d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2f5c90478749dfd9a32386100b6078a364298b01",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/01a0d6cd7032e9993feea19fadb03ef9d5b488f2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 740,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-53378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T10:02:00.779Z",
      "date_updated": "2026-07-19T10:02:00.779Z",
      "publisher": "Linux",
      "title": "drm/colorop: Fix blob property reference tracking in state lifecycle",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.01034
      },
      "nvd": {
        "published": "2026-07-19T11:16:38.953",
        "lastModified": "2026-07-29T16:58:55.143",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53378",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Linux fails to release memory after the corresponding operation completes, allowing repeated use to exhaust memory.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/271059f1d9020e9ac967524e319fbbaa22d0475b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/235b333e2878d791cee09e1e72f44611a9400114",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-53379",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T10:02:01.410Z",
      "date_updated": "2026-07-19T10:02:01.410Z",
      "publisher": "Linux",
      "title": "media: i2c: ov8856: free control handler on error in ov8856_init_controls()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02193
      },
      "nvd": {
        "published": "2026-07-19T11:16:39.060",
        "lastModified": "2026-07-29T16:20:04.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53379",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ov8856_init_controls omits control-handler cleanup when adding a control fails, leaking the allocated handler state.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c13721040a566d832ee8a20ecf04b7ef288a1525",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d1b3811c6b0f67fb7f0acfe09bf8244aa8b12465",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/fd10fb4c33bdc9c25c9b9d5e7e39f635e34c44a3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ba9e9274c4ecfc039c45752dd6055137eaa5f08e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/791598484fd558bb426ef5e051effa5c227d5390",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f727e3251ceee91f3d6e6d87e323aaf070f0de8e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f75e160745663ce9b13362ae6e90bd439c58df69",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 278,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-53380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T10:02:02.030Z",
      "date_updated": "2026-07-20T13:39:45.884Z",
      "publisher": "Linux",
      "title": "media: rzv2h-ivc: Fix concurrent buffer list access",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01601
      },
      "nvd": {
        "published": "2026-07-19T11:16:39.173",
        "lastModified": "2026-07-29T16:19:52.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53380",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The buffer-transfer workqueue removes an entry from a shared list without holding the spinlock used by concurrent list modifiers.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c746522bd3264132ab2e2382e96e19cdb8a6c1ba",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/72773ff1cdfaebc593f53b1719b2c1773ecf8c43",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-53381",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T11:59:30.469Z",
      "date_updated": "2026-07-20T13:39:46.855Z",
      "publisher": "Linux",
      "title": "virtiofs: fix UAF on submount umount",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 27,
        "versionRangeCount": 25,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03705
      },
      "nvd": {
        "published": "2026-07-19T12:16:48.807",
        "lastModified": "2026-07-29T16:19:35.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53381",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A virtiofs submount can destroy its superblock while a release path still holds an inode reference that later accesses the freed superblock.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/607a1d4c42f649e6197567c0448fd9ebb316cd42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1cc0e3a0c6499aaaa2f21a4fcbba388486afb25e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0b809199ff87c44487e516a725dd4be2185712ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2181a09ba980f142650fb053666350ead4471cfe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/97c4691653d145dcc699eca5d3aba3219a520f1f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2abfd3ffbd9452f72535d96ff3982b3ab1f8f2f9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/39a2b95e008665c14f84e50ed411d898df7cd11b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e09412a714bcd49375198427bb4aa005037a9d6f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/06b41351779e9289e8785694ade9042ae85e41ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 27
      }
    },
    {
      "cve_id": "CVE-2026-53382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T11:59:31.045Z",
      "date_updated": "2026-07-19T11:59:31.045Z",
      "publisher": "Linux",
      "title": "media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 19,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03193
      },
      "nvd": {
        "published": "2026-07-19T12:16:48.970",
        "lastModified": "2026-07-29T19:31:54.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53382",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Linux path dereferences a NULL pointer after a required object is absent or allocation fails.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/455bc12e7b73ab5a2dfcb47822e91e772bc6c42e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f0f5a1d7056980a0d512456fdb370cfb72bba86a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/6df7e16d4f742c80add58995a6e69385b97aa9e6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/cd923dadefadb9671b5ac341b672ff424d429c39",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/353d9578951dd38bc9679308f5b618ceed1f20fa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f965cf22dda7f512f4922415894c3e528269a4ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b28b12be6e8910489e6800ed93ea4d41dfe19683",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/232e4b313ea342672edf8947e067c0de4328405b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7d8bf3d8f91073f4db347ed3aa6302b56107499c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1625,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-53383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T11:59:31.616Z",
      "date_updated": "2026-07-20T13:39:47.835Z",
      "publisher": "Linux",
      "title": "ksmbd: reject non-VALID session in compound request branch",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 22,
        "versionRangeCount": 20,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0069,
        "percentile": 0.49251
      },
      "nvd": {
        "published": "2026-07-19T12:16:49.117",
        "lastModified": "2026-07-29T19:31:47.073",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53383",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The compound-request shortcut reuses a session before confirming that authentication reached the VALID state.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/25ff12b82a376ff5c4583102a63d2456a6b9ebb9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/fc578523a72cb8b329d32070b95898e81613cc3f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d2bbbb6c55812220fee5d801c275cc267ea3cbeb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8f0302fb691537d33ec8f668565257ea9d340ffe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7cad3ceaf679c55bc9946685dacafce78ce6b51a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/06e1f05a1dbe8bbd054c0927b17fc0a61cc8bef7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5f983b864d3d473ac533b2f4f44a1bbe5dcbccf4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/609ca17d869d04ba249e32cdcbf13c0b1c66f43c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1636,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 22
      }
    },
    {
      "cve_id": "CVE-2026-53384",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T11:59:32.153Z",
      "date_updated": "2026-07-28T13:38:23.518Z",
      "publisher": "Linux",
      "title": "serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00488,
        "percentile": 0.39392
      },
      "nvd": {
        "published": "2026-07-19T12:16:49.263",
        "lastModified": "2026-07-29T19:31:22.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53384",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Linux, code retains or reuses an object after the lifetime transition that frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ccdf4510a3873b14e5e348cdb038717996f09fda",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/511d2b92f8d20de04acafab676150d26fb5c67f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/07ffe414a708ae60551401cec5d727ed156b8caf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/3d205fe80f2181f0109150ad1fa06ee5bc046935",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d72650a4f334581b23a1892b888a4cb1be142f76",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/778b9dda4b24005a27bcd9c35c110bf8d7f259ca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/10fc708b4de7f86002d2d735a2dbf3b5b7f65692",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 848,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-53385",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.401Z",
      "date_published": "2026-07-19T11:59:32.732Z",
      "date_updated": "2026-07-19T11:59:32.732Z",
      "publisher": "Linux",
      "title": "vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 31,
        "versionRangeCount": 26,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03194
      },
      "nvd": {
        "published": "2026-07-19T12:16:49.387",
        "lastModified": "2026-07-29T19:31:11.617",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53385",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "vcs_write drops the console lock while retaining a vc_data pointer and later calls vcs_scr_updated after revalidation returned NULL, allowing concurrent console deletion to reach a null dereference.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/43a6281790273c1b0a9ab76609ff0245b968f1e6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b6bbb85cf45bf0b070e741997fe0af3a772c5ad5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ff4806202749a51938236214adc0281481a57366",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8232fca738011ca2ec865b46ec721d1796dc0580",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/73049768ad57145acd337102c5aa3c788e6642c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7cc3dd79777f6ae4625ec37e84dd18a26dc88bde",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/74be188eb2dc1c99d63986167b9a67d415fe7326",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/09a43e81279b8da15526da09877134b8bcf618b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a287620312dc6dcb9a093417a0e589bf30fcf38a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 971,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 31
      }
    },
    {
      "cve_id": "CVE-2026-53386",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T11:59:33.318Z",
      "date_updated": "2026-07-20T13:39:49.826Z",
      "publisher": "Linux",
      "title": "iio: adc: ti-ads1298: add bounds check to pga_settings index",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02906
      },
      "nvd": {
        "published": "2026-07-19T12:16:49.540",
        "lastModified": "2026-07-29T19:31:02.180",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53386",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ADS1298 PGA bit mask can produce index seven for a seven-element array, and the driver used that index without a bounds check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d5793975fc3b1780ba576812158ef22e3104e60e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d08d82d83ed45fd8c001a9df66ad7ebb86c9d6c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/abe0854e356b1bb814393ca884cb42b3eb12ce10",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/abd776ded3e256889610595290f6ca46cb6e91ab",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/95e8a48d7a85d4226934020e57815a3316d3a14b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-53387",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T11:59:33.888Z",
      "date_updated": "2026-07-20T13:39:50.863Z",
      "publisher": "Linux",
      "title": "iio: light: veml6075: add bounds check to veml6075_it_ms index",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02609
      },
      "nvd": {
        "published": "2026-07-19T12:16:49.650",
        "lastModified": "2026-07-29T19:30:52.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53387",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Linux uses an attacker-controlled array index without confirming that it falls within the target array.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/df9127a1d2d748e426c49c8fcd9b6801e4eb743d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0a89002737ee34decc20fa232204dbe5fe83e0de",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f75beebcd5bc9bdc80e0722142e78a6f306214ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e545936e06f1c7173ab41a5f33a77ff43ced3a8d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/307dc4240bd41852d9e0912921e298160db1c109",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-53388",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T11:59:34.456Z",
      "date_updated": "2026-07-20T13:39:51.906Z",
      "publisher": "Linux",
      "title": "fuse: re-lock request before replacing page cache folio",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03213
      },
      "nvd": {
        "published": "2026-07-19T12:16:49.757",
        "lastModified": "2026-07-29T19:30:41.847",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53388",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "fuse_try_move_folio leaves the request unlocked on success, allowing abort handling to free fuse_io_args before later copy logic uses it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7c18691e0cfda29672f79bafde8abdb7710674f6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5927b43a4f8d89e86930f524bf63e9c7e66f61b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/030fe3e9d8abdee303dd7e9e42f45082d382a407",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/46473ddccdc5065033e397d6e62c280dbcd3d9c2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/af2892249d982a1c036ca456cc135374e68b6677",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0223f452532d9cd8a5e87c45de828fd93c99bd25",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e28db6ac4792d065ab32565fd9f0a2361c3d4666",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a078484921052d0badd827fcc2770b5cfc1d4120",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 815,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T12:01:54.386Z",
      "date_updated": "2026-07-20T13:39:52.858Z",
      "publisher": "Linux",
      "title": "net/tcp-ao: fix use-after-free of key in del_async path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02599
      },
      "nvd": {
        "published": "2026-07-19T12:16:49.890",
        "lastModified": "2026-07-29T19:30:30.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53389",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The asynchronous TCP-AO key deletion path frees a key without clearing current_key and rnext_key pointers that are later dereferenced.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6ce7ef41743740ce15c2061561b784148b565b3f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e77fbefd1269b5c123e7c651a1ebdce1b87d19a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7ddc29a094d96e9b3aa280433c6dc443df9eabf2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5ba9950bc9078e19b69cca1e56d1553b125c6857",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 858,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-53390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T12:01:54.951Z",
      "date_updated": "2026-07-24T14:33:56.623Z",
      "publisher": "Linux",
      "title": "ksmbd: fix out-of-bounds read in smb_check_perm_dacl()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 23,
        "versionRangeCount": 21,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0047,
        "percentile": 0.38216
      },
      "nvd": {
        "published": "2026-07-19T12:16:50.000",
        "lastModified": "2026-07-29T19:30:20.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53390",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ksmbd's DACL ACE walk advances through a variable-size ACE before proving that the full ACE lies inside the security descriptor.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c7488c85fd822959e9b5c22fbd9e7c8a21caf5e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/988c93d3bba066d8669143e6ec30bb2be9608d53",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/36599894fa8536fefdf1e296c0af71b8b7226859",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d5c81a095c86fe507c032d08f3a8cfc518444927",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7627ff8c4f9919f14de562b0160ab4ec9d80b1f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e36e35660adb9b8ef1435ac359151dda5f094c55",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1ef06004ed4bd6d3ed8c840d9d1a376b66d4935b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1893,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 23
      }
    },
    {
      "cve_id": "CVE-2026-53391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T12:01:55.521Z",
      "date_updated": "2026-07-20T13:39:54.843Z",
      "publisher": "Linux",
      "title": "NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00517,
        "percentile": 0.41118
      },
      "nvd": {
        "published": "2026-07-19T12:16:50.137",
        "lastModified": "2026-07-29T19:30:11.987",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53391",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The \"< 0\" check does not catch this, and the next line is strrchr(NULL, '.'), a kernel NULL pointer dereference reachable from any pNFS-flexfile client mounted against a malicious or compromised metadata server.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/76b94cbd32aacf36a641956385a852635c6802b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c8e4e0c701d0192a2efb6df059c0f9e19678c23d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/6c344fff2feff9d4d716d8e4ad40e9b5040ee5ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/427ab81a811dab4bca9d19f82eec5847ae42646e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/012d37a568bfbb2c9686f03ade75560bc7139956",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/30aae62e50b4e074a90a9a5e15246548fbdc1182",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/41fe0f7b84f0cb822ae10ab08592996a592b2a25",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1052,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-53392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T12:01:56.101Z",
      "date_updated": "2026-07-24T14:33:58.026Z",
      "publisher": "Linux",
      "title": "NFSv4/flexfiles: reject zero filehandle version count",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00501,
        "percentile": 0.40148
      },
      "nvd": {
        "published": "2026-07-19T12:16:50.260",
        "lastModified": "2026-07-29T20:33:57.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53392",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ff_layout_alloc_lseg accepts a zero filehandle-version count, stores ZERO_SIZE_PTR, and later flexfiles paths dereference it as a populated array.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9033591535c066726f5b505126ccb4068b98fa4f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/18cc6d57a14fa65ab2a2b52279f549041c4bc9cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/be7829715e341b42846437dd9e721005db59f0cc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/eeabb9020721db6bc132e68eeae380b8d4fb4b04",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7779c85028a0676fb190cde4f0c540f4f8e97761",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d8c90c7cc061265d5f2813a1f5c82ef2f4707e67",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2131ed64b767ffa8bcdb3677d90f3964e39aabc8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2c6bb3c40bc24f6aa8dfbe6fe98c3ad6389203f2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1091,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53393",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T12:01:56.684Z",
      "date_updated": "2026-07-24T14:33:59.642Z",
      "publisher": "Linux",
      "title": "nfsd: reset write verifier on deferred writeback errors",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 19,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03347
      },
      "nvd": {
        "published": "2026-07-19T12:16:50.367",
        "lastModified": "2026-07-29T20:33:29.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53393",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Deferred NFS writeback errors return without rotating the write verifier, causing clients to treat failed unstable writes as durable.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b8e5894e56cff70fa245628fe16f0ad6367f8090",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/bc2baca02ec56da7707a74ed5d340b0a1dff1841",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/43b65d2997963e80e8d8d86520bcb1e0751227de",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/666e837b247fcadf2d8d508b9b0e49d720393eb4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1dd664b39774a9c89b72de8e59bf9ef4b3aaff2e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/4367afc119c51e17a616f6908772b7e2c2c4013f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b027cca33c97354149fcc0ddeede4525c41093cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2090b05803faab8a9fa62fbff871007862cac1b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1010,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-53394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T12:01:57.261Z",
      "date_updated": "2026-07-20T13:39:56.755Z",
      "publisher": "Linux",
      "title": "nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00446,
        "percentile": 0.36658
      },
      "nvd": {
        "published": "2026-07-19T12:16:50.480",
        "lastModified": "2026-07-29T20:33:20.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53394",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An NFS retry path overwrites an already allocated open-owner pointer after a concurrent unconfirmed-owner insertion, leaking the prior allocation.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c9aefb2b5f11337c9202c5bd0c45d71198449718",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/017a6150106b054cc84d1b0582d97bd3a74d4281",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a10bf67fe06469a71a401f72f328237345d553c0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/57aee7a35bb12753057c5b65d72d1f46c0e95b07",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 959,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-53395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T12:01:57.816Z",
      "date_updated": "2026-07-20T13:39:57.731Z",
      "publisher": "Linux",
      "title": "nfsd: fix dead ACL conflict guard in nfsd4_create",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27008
      },
      "nvd": {
        "published": "2026-07-19T12:16:50.597",
        "lastModified": "2026-07-29T20:32:44.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53395",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ACL conflict guard checks source pointers after ownership transfer has nulled them, bypassing cleanup and leaking two ACL objects per crafted CREATE request.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8371cc5c0a2cc2a71b3dcfd47ff1f7fcfc526a5e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a60f25a800846ab8e5a13f8a9d05111f2aee55a7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 952,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-53396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T12:01:58.375Z",
      "date_updated": "2026-07-20T13:39:58.755Z",
      "publisher": "Linux",
      "title": "nfsd: fix posix_acl leak and ignored error in nfsd4_create_file",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18734
      },
      "nvd": {
        "published": "2026-07-19T12:16:50.693",
        "lastModified": "2026-07-29T20:32:39.597",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53396",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An early nfsd4_create_file failure jumps past nfsd_attrs_free, allowing repeated CREATE failures with ACL attributes to leak posix_acl allocations.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/18cf006a08babec0bbac2a3784f8f28e56e47490",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/24c975bbdd564d7d0ad90294bfa69729830345de",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1156,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-53397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T12:01:58.938Z",
      "date_updated": "2026-07-20T13:39:59.694Z",
      "publisher": "Linux",
      "title": "nfsd: fix posix_acl leak on SETACL decode failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00529,
        "percentile": 0.41792
      },
      "nvd": {
        "published": "2026-07-19T12:16:50.793",
        "lastModified": "2026-07-29T20:31:59.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53397",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A second SETACL decode failure leaves the first allocated ACL without a release path for the server lifetime.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b2eb1ffd511d1b3c3e21122f97cbbccea411e277",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b94c4be77682aab06d65ca7296149e3bcfb37353",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/887f92ceccf3eacd5f2402db21254d66372fae00",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1e96239fddcefacf6afe6c498357be68eacbcabc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/bd69a825485168ef74e815ecb286754b570fdcc7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/136b416593f1349cf6f72c8e3d18f0f204ee8545",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a5b42c1e4ff2befaa6b96f7cbf32174751eba083",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0853ac544c590880d797b04daa33fcb72b6be0e1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1700,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T12:01:59.507Z",
      "date_updated": "2026-07-20T13:40:00.661Z",
      "publisher": "Linux",
      "title": "NFSD: Fix SECINFO_NO_NAME decode error cleanup",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 19,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00514,
        "percentile": 0.40948
      },
      "nvd": {
        "published": "2026-07-19T12:16:50.933",
        "lastModified": "2026-07-29T20:31:45.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53398",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A truncated XDR decode leaves stale sin_exp state that a later exp_put releases incorrectly.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8836405abdc53ca3dd5fc68b2cf6f8f012fad011",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/49de5d31dd8fdebf78bdeaf196b0ca5cd5c75439",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5ec37edcb534f3fc92304be236d37f08e6545585",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1e04be34cafae119e82bcaccd6d28a20f72a3647",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/161d1aaeb04d620d3692639700512bb5038c1e10",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c8a24effd96d4779e2ad779654682304491c55a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/46eb17d45be69d28c7a23ea03283b207426a8232",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/9e18e83b8846a5c3fe13fc8a464b4865d33996c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 783,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-53399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.402Z",
      "date_published": "2026-07-19T12:02:00.055Z",
      "date_updated": "2026-07-24T14:34:01.063Z",
      "publisher": "Linux",
      "title": "nfsd: release layout stid on setlease failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00514,
        "percentile": 0.40952
      },
      "nvd": {
        "published": "2026-07-19T12:16:51.063",
        "lastModified": "2026-07-29T20:31:11.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53399",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The setlease failure path frees a published state ID without removing its IDR entry, leaving walkers to dereference freed slab memory.",
        "basis": [
          "CNA record",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": "The structured CWE names a NULL dereference, while the description establishes a dangling IDR pointer and use-after-free as the enabling lifetime error."
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d788ef40a7517d22c97ab01700e4ae4c611b6f2f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2e0a5d6d62600b8c614d1b55e50ef94035d6adf9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7bbb7ce74051c8be4b69ff44ce3db370600dae61",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/48a586e382e4db1dbf958d44b63e081df5f8ed04",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d369e5edfaaf83a448016e2f1da392b2174be801",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8dee7c278f1c2b5bb80e17a6281c3812fc8b0cdd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/83c2b7797742339bb768f83935f7ca33950db138",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/30d55c8aabb261bc3f427d6b9aae7ef6206063f9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1750,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.403Z",
      "date_published": "2026-07-19T12:02:00.632Z",
      "date_updated": "2026-07-24T14:34:02.226Z",
      "publisher": "Linux",
      "title": "i2c: core: fix adapter registration race",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00099,
        "percentile": 0.00975
      },
      "nvd": {
        "published": "2026-07-19T12:16:51.177",
        "lastModified": "2026-07-29T20:28:23.877",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53400",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The I2C adapter is published in the IDR before its embedded device is initialized, allowing a concurrent lookup to use uninitialized state.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2e57c788e71f1763445f812eba4e0b4a2fbd0646",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a4365bc41baaf67f3a5aa8556d23544e6ec7480a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1febb174815bcae56d73587e99e8f87e02f0784d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/da9d8d9711f78deebc202d0cffcf577e45ee8621",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/78793c75dc6d0ff2e4d50ad617349b328a99054e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/6a946038f2a5a8c29048c6af369d4e391448a5c5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a4c8094bbf4c6fa68b17e3b16f6a0a1b7a14f3e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ba14d7cf2fe7284610a29854bdff22b2537d3ce6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 628,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53401",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.403Z",
      "date_published": "2026-07-19T12:02:01.209Z",
      "date_updated": "2026-07-20T13:40:03.562Z",
      "publisher": "Linux",
      "title": "fbdev: omap2: fix use-after-free in omapfb_mmap",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02991
      },
      "nvd": {
        "published": "2026-07-19T12:16:51.287",
        "lastModified": "2026-07-29T20:37:13.657",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53401",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "omapfb_mmap reads address and length from a newly assigned region but increments the old region's map count, allowing the mapped region to be freed concurrently.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6eb6ebcc8590007ad59ddccc8b5f9201655b33f8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7958e67375aa111522086286bba13cfc0816ce8d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1208,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-53402",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.403Z",
      "date_published": "2026-07-19T12:02:01.795Z",
      "date_updated": "2026-07-24T14:34:03.280Z",
      "publisher": "Linux",
      "title": "fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 22,
        "versionRangeCount": 20,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02874
      },
      "nvd": {
        "published": "2026-07-19T12:16:51.387",
        "lastModified": "2026-07-30T17:42:07.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53402",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "fbcon's error rollback restores the font count but not hi_font state or the screen buffer, so later rendering indexes a reverted 256-character font with inflated values.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cb016bcb40c81e7b19c4ae6143babb366dae8e20",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ac562193c36696513ae196171892e9338475c4bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/3618a4c5b2591cfa83efe74f5b18c2d02b35c3f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a7a526fbc847f07ad3a503c7382189be5ab68574",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b5bb2c696e140c399cb874def2feedf61dee27d6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/076b1aa65f77a49bce5a48a4a55a397cfcafa2b8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/39815715cbcfabb16fc8c5f4a23deeda20f5df62",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8fdc8c2057eea08d40ce2c8eed41ff9e451c65c2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1287,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 22
      }
    },
    {
      "cve_id": "CVE-2026-53403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T07:44:35.403Z",
      "date_published": "2026-07-19T12:02:02.382Z",
      "date_updated": "2026-07-20T06:41:25.020Z",
      "publisher": "Linux",
      "title": "fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03007
      },
      "nvd": {
        "published": "2026-07-19T12:16:51.510",
        "lastModified": "2026-07-30T17:41:41.283",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53403",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Replacing the framebuffer modelist can remove the current mode, leaving later console takeover code with a stale null mode pointer.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1458a4d804550b7101e8bb02c1cb941088e4c0c7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8707f02ac9f5f632039b60df2c9f3dc914709f72",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0d8c7f21ad8529d5c181e61f86be35b887ae2e4d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7640b4f68acb54c2c4f6b4a8aee0e9849dacd929",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/4f1a7fe8ba845cb7d39580755f78c3b7b9a0b61e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/eea16b6f805c0b1fb2f72f0f771088ea45356956",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/88913059c77e171f44ba829282d42dde0d458811",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7f08fc10fa3d3366dc3af723970bd03d7d6d10e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1151,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-53405",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T09:39:17.153Z",
      "date_published": "2026-07-20T14:20:06.824Z",
      "date_updated": "2026-07-21T14:57:26.644Z",
      "publisher": "apache",
      "title": "Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Syncope"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-653",
          "name": "Improper Isolation or Compartmentalization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00445,
        "percentile": 0.36541
      },
      "nvd": {
        "published": "2026-07-20T15:16:42.987",
        "lastModified": "2026-07-27T15:00:33.227",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53405",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Syncope imports administrator-supplied BPMN Groovy scriptTask content and executes it directly on the server without a sandbox.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-653"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/vdq0tk6ylffz6trbgbllj9kb1ndzff7k",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/6",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 632,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-53409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T10:12:34.854Z",
      "date_published": "2026-07-16T21:08:12.379Z",
      "date_updated": "2026-07-17T13:20:11.431Z",
      "publisher": "Zoom",
      "title": "Improper Privilege Management in Zoom Rooms for Windows before version 7.",
      "affected": {
        "vendors": [
          "Zoom Communications"
        ],
        "products": [
          {
            "vendor": "Zoom Communications",
            "product": "Zoom Rooms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@zoom.us",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04909
      },
      "nvd": {
        "published": "2026-07-16T21:17:21.253",
        "lastModified": "2026-07-17T18:08:08.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53409",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Zoom Rooms for Windows permits a local authenticated user to gain additional privilege, but the advisory does not disclose the operation or permission transition that fails.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-26011",
          "host": "www.zoom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 164,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T10:12:34.854Z",
      "date_published": "2026-07-16T21:11:44.086Z",
      "date_updated": "2026-07-17T13:19:48.397Z",
      "publisher": "Zoom",
      "title": "Zoom Clients for Windows - Race Condition",
      "affected": {
        "vendors": [
          "Zoom Communications"
        ],
        "products": [
          {
            "vendor": "Zoom Communications",
            "product": "Zoom Clients"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@zoom.us",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00094,
        "percentile": 0.00707
      },
      "nvd": {
        "published": "2026-07-16T21:17:21.377",
        "lastModified": "2026-07-17T18:08:08.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53410",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Operations occur in an unsafe order and expose stale or partially transitioned state.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-26012",
          "host": "www.zoom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53411",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T10:18:05.660Z",
      "date_published": "2026-07-16T21:13:33.254Z",
      "date_updated": "2026-07-17T13:19:18.986Z",
      "publisher": "Zoom",
      "title": "Zoom Workplace VDI Plugin for Windows - Improper Input Validation",
      "affected": {
        "vendors": [
          "Zoom Communications"
        ],
        "products": [
          {
            "vendor": "Zoom Communications",
            "product": "Zoom Workplace VDI Plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@zoom.us",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04217
      },
      "nvd": {
        "published": "2026-07-16T22:17:31.267",
        "lastModified": "2026-07-17T18:08:08.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53411",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Windows install and uninstall workflow has a TOCTOU window in which an authenticated local user can change checked state before the privileged action.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-26013",
          "host": "www.zoom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53412",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T10:18:05.660Z",
      "date_published": "2026-07-16T21:15:25.664Z",
      "date_updated": "2026-07-17T13:18:46.094Z",
      "publisher": "Zoom",
      "title": "Zoom Workplace VDI Plugin for Windows - Improper Input Validation",
      "affected": {
        "vendors": [
          "Zoom Communications"
        ],
        "products": [
          {
            "vendor": "Zoom Communications",
            "product": "Zoom Workplace for Windows"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@zoom.us",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00647,
        "percentile": 0.47495
      },
      "nvd": {
        "published": "2026-07-16T22:17:31.380",
        "lastModified": "2026-07-17T18:08:08.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53412",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Zoom identifies improper Windows client input validation leading to account takeover but does not disclose the input, parser, trust decision, or state change.",
        "basis": [
          "CNA",
          "CWE-20",
          "Zoom ZSB-26014"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.zoom.com/en/trust/security-bulletin/zsb-26014/; Zoom confirms affected Windows clients, CVSS 9.8, unauthenticated network reachability, and account takeover, but publishes no input, parser, trust decision, or patch-level mechanism."
      },
      "references": [
        {
          "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-26014",
          "host": "www.zoom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53421",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T10:22:09.599Z",
      "date_published": "2026-07-20T14:21:10.071Z",
      "date_updated": "2026-07-21T14:57:20.891Z",
      "publisher": "apache",
      "title": "Apache Syncope: Remote Code Execution via Scripted Connector",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Syncope"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-653",
          "name": "Improper Isolation or Compartmentalization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00678,
        "percentile": 0.48786
      },
      "nvd": {
        "published": "2026-07-20T15:16:43.117",
        "lastModified": "2026-07-27T15:00:13.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53421",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Apache Syncope permits entitled administrators to run Groovy through scripted REST or SQL connectors without a sandbox strong enough to contain the script.",
        "basis": [
          "CNA",
          "CWE-653"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/nmzvz6gb2ldm30wvyk613r8dfrb6r8yx",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-53422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T11:01:47.529Z",
      "date_published": "2026-07-02T16:06:03.802Z",
      "date_updated": "2026-07-24T14:16:07.357Z",
      "publisher": "EEF",
      "title": "SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-204",
          "name": "Observable Response Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17876
      },
      "nvd": {
        "published": "2026-07-02T17:17:01.473",
        "lastModified": "2026-07-24T15:18:01.720",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53422",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SFTP REALPATH resolves attacker-selected paths beyond the intended namespace and exposes path-existence information.",
        "basis": [
          "CNA",
          "CWE-204"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-h9pw-h5w4-h976",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-53422.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-53422",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Third Party Advisory",
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/059e5785ef8c1d423820ca633fb7b37f47645172",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/86622cfaacf57a02c7645d1999f946846b504c94",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/c5a8f50ae68888ff243c5c741a06d2b3a4b48b7a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1643,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-53431",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T11:01:47.529Z",
      "date_published": "2026-07-30T14:17:27.909Z",
      "date_updated": "2026-07-31T04:20:43.209Z",
      "publisher": "EEF",
      "title": "Boruta accepts expired JWT client assertions due to missing exp claim validation",
      "affected": {
        "vendors": [
          "malach-it"
        ],
        "products": [
          {
            "vendor": "malach-it",
            "product": "boruta"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00413,
        "percentile": 0.34001
      },
      "nvd": {
        "published": "2026-07-30T15:16:33.567",
        "lastModified": "2026-07-30T17:16:32.863",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53431",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Boruta verifies that exp exists but never checks that it is still in the future, so a captured signed client assertion remains replayable indefinitely.",
        "basis": [
          "CNA",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/malach-it/boruta_auth/security/advisories/GHSA-xjv8-vmh5-xhf6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-53431.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-53431",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/malach-it/boruta_auth/commit/5204f88f9b2cdd9637a755337ed5f99185be5474",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/malach-it/boruta_auth/commit/69363432aa36760fc5438e4e17115d0f7c1b925a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1205,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-53444",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T16:31:21.493Z",
      "date_published": "2026-07-15T21:11:38.711Z",
      "date_updated": "2026-07-17T12:35:40.593Z",
      "publisher": "GitHub_M",
      "title": "Wekan: Missing authorization on OIDC Meteor methods allows privilege escalation to admin",
      "affected": {
        "vendors": [
          "wekan"
        ],
        "products": [
          {
            "vendor": "wekan",
            "product": "wekan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14915
      },
      "nvd": {
        "published": "2026-07-15T22:17:16.840",
        "lastModified": "2026-07-17T13:18:57.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53444",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Wekan exposes global OIDC configuration methods without enforcing the administrator role before changing authentication settings.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wekan/wekan/security/advisories/GHSA-cv95-8h7c-2ffq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/commit/305864f0c77456ad0f2c1e616266c8a06749c951",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/releases/tag/v9.32",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 626,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T16:31:21.494Z",
      "date_published": "2026-07-15T21:11:04.683Z",
      "date_updated": "2026-07-16T12:51:57.861Z",
      "publisher": "GitHub_M",
      "title": "Wekan: Authorization bypass in copyBoard DDP method allows any user to copy private boards",
      "affected": {
        "vendors": [
          "wekan"
        ],
        "products": [
          {
            "vendor": "wekan",
            "product": "wekan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14916
      },
      "nvd": {
        "published": "2026-07-15T22:17:16.973",
        "lastModified": "2026-07-16T14:16:53.950",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53445",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wekan/wekan/security/advisories/GHSA-7w2h-g83c-jqrp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/commit/8940a103970c5da3f02b3615eef09fabfff421e3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/releases/tag/v9.32",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53446",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T16:31:21.494Z",
      "date_published": "2026-07-15T21:10:11.930Z",
      "date_updated": "2026-07-16T12:49:40.489Z",
      "publisher": "GitHub_M",
      "title": "Wekan: Server-Side Request Forgery (SSRF) via webhook integration URLs",
      "affected": {
        "vendors": [
          "wekan"
        ],
        "products": [
          {
            "vendor": "wekan",
            "product": "wekan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20883
      },
      "nvd": {
        "published": "2026-07-15T22:17:17.103",
        "lastModified": "2026-07-16T14:16:54.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53446",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Wekan stores and fetches administrator-supplied webhook URLs without applying its existing private-network destination checks.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wekan/wekan/security/advisories/GHSA-hc3x-hq3m-663q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/commit/0e5fef6f31164fd3de4db353d04173ee0490cd65",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/releases/tag/v9.32",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53447",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T16:31:21.494Z",
      "date_published": "2026-07-15T21:12:59.647Z",
      "date_updated": "2026-07-16T18:48:01.813Z",
      "publisher": "GitHub_M",
      "title": "Wekan: `cloneBoard` Meteor method has no authorization check — any user can clone (read) any private board by ID",
      "affected": {
        "vendors": [
          "wekan"
        ],
        "products": [
          {
            "vendor": "wekan",
            "product": "wekan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13989
      },
      "nvd": {
        "published": "2026-07-15T22:17:17.240",
        "lastModified": "2026-07-16T19:16:49.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53447",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "cloneBoard exports a caller-supplied private board ID without checking source-board membership or export permission.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wekan/wekan/security/advisories/GHSA-qfqv-42qw-vvwh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/commit/357de728c03113b787065bac2c5832ad77f1a117",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/releases/tag/v9.35",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 479,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T16:31:21.494Z",
      "date_published": "2026-07-10T17:56:07.689Z",
      "date_updated": "2026-07-15T03:59:00.043Z",
      "publisher": "GitHub_M",
      "title": "Coturn: SQL Injection in HTTPS Admin Panel Delete Operations",
      "affected": {
        "vendors": [
          "coturn"
        ],
        "products": [
          {
            "vendor": "coturn",
            "product": "coturn"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00431,
        "percentile": 0.35429
      },
      "nvd": {
        "published": "2026-07-10T19:17:23.930",
        "lastModified": "2026-07-16T13:35:10.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53448",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The coturn admin panel interpolates query parameters into SQL and omits the secure-string filter used by the STUN path.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coturn/coturn/security/advisories/GHSA-v8hj-2xx7-xmp5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coturn/coturn/pull/1924",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coturn/coturn/commit/b84dbab1d1aa6e2bf0211a1cdbb250d6de2a0d09",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coturn/coturn/releases/tag/4.12.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 604,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53449",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T16:31:21.494Z",
      "date_published": "2026-07-10T17:59:11.161Z",
      "date_updated": "2026-07-13T18:23:43.228Z",
      "publisher": "GitHub_M",
      "title": "Coturn: Arbitrary File Write via CLI psd Command",
      "affected": {
        "vendors": [
          "coturn"
        ],
        "products": [
          {
            "vendor": "coturn",
            "product": "coturn"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15841
      },
      "nvd": {
        "published": "2026-07-10T19:17:24.073",
        "lastModified": "2026-07-16T13:30:39.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53449",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The authenticated psd CLI command passes its filename argument directly to fopen without path restriction, allowing overwrite of any file writable by coturn.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coturn/coturn/security/advisories/GHSA-jj76-vwjw-w34r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coturn/coturn/commit/e72930f571beba3bc7a9f97661af2614aae92a55",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coturn/coturn/releases/tag/4.13.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 507,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53450",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T16:31:21.494Z",
      "date_published": "2026-07-10T18:05:06.474Z",
      "date_updated": "2026-07-10T19:03:44.107Z",
      "publisher": "GitHub_M",
      "title": "Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection",
      "affected": {
        "vendors": [
          "coturn"
        ],
        "products": [
          {
            "vendor": "coturn",
            "product": "coturn"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06972
      },
      "nvd": {
        "published": "2026-07-10T19:17:24.193",
        "lastModified": "2026-07-16T19:29:44.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53450",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The loopback check tests the literal IPv6 form before normalizing IPv4-mapped IPv6, so ::ffff:127.0.0.1 bypasses relay restrictions.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coturn/coturn/security/advisories/GHSA-w4hf-cr3w-6h79",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coturn/coturn/commit/b057acbebe721c8f2f202ddad5e16289e295c754",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53466",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T16:31:21.495Z",
      "date_published": "2026-07-01T18:20:44.416Z",
      "date_updated": "2026-07-01T18:52:17.717Z",
      "publisher": "GitHub_M",
      "title": "ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-681",
          "name": "Incorrect Conversion between Numeric Types",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12661
      },
      "nvd": {
        "published": "2026-07-01T19:16:54.110",
        "lastModified": "2026-07-02T19:34:08.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53466",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An integer overflow in the XCF decoder produces an out-of-bounds read from a crafted image.",
        "basis": [
          "CNA",
          "CWE-190",
          "CWE-681"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pjxj-pchx-4c3m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-53467",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T16:31:21.495Z",
      "date_published": "2026-07-01T18:50:56.821Z",
      "date_updated": "2026-07-01T19:27:13.148Z",
      "publisher": "GitHub_M",
      "title": "ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09765
      },
      "nvd": {
        "published": "2026-07-01T19:16:54.253",
        "lastModified": "2026-07-02T19:34:05.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53467",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MNG decoder leaves destination pixels uninitialized and then exposes bytes already present in the heap allocation.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8g53-9m3c-69xg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 323,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-53478",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:04:35.249Z",
      "date_published": "2026-07-03T14:03:29.533Z",
      "date_updated": "2026-07-07T03:56:11.694Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01216,
        "percentile": 0.65591
      },
      "nvd": {
        "published": "2026-07-03T15:16:32.840",
        "lastModified": "2026-07-08T19:31:54.393",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53478",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerProtect Data Domain passes attacker-controlled argument or command text into an operating-system command boundary without neutralizing the command grammar.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 451,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-53479",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:04:35.250Z",
      "date_published": "2026-07-07T13:07:26.591Z",
      "date_updated": "2026-07-08T13:41:13.329Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01143,
        "percentile": 0.63559
      },
      "nvd": {
        "published": "2026-07-07T14:16:32.410",
        "lastModified": "2026-07-08T19:57:25.183",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53479",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerProtect Data Domain places high-privilege remote input into an operating-system command context without command-grammar neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-53480",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:04:35.250Z",
      "date_published": "2026-07-08T13:44:45.485Z",
      "date_updated": "2026-07-08T14:29:57.118Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17956
      },
      "nvd": {
        "published": "2026-07-08T14:17:03.880",
        "lastModified": "2026-07-08T20:09:53.847",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53480",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PowerProtect Data Domain accepts a path that escapes its restricted directory and modifies the selected file.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-53481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:04:35.250Z",
      "date_published": "2026-07-07T13:02:37.613Z",
      "date_updated": "2026-07-08T03:56:41.732Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00443,
        "percentile": 0.36438
      },
      "nvd": {
        "published": "2026-07-07T13:16:31.397",
        "lastModified": "2026-07-08T19:57:35.883",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53481",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PowerProtect Data Domain accepts a remote path that escapes its intended directory boundary.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 628,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-53482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:04:35.250Z",
      "date_published": "2026-07-08T13:39:30.283Z",
      "date_updated": "2026-07-09T13:31:31.768Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29917
      },
      "nvd": {
        "published": "2026-07-08T14:17:04.000",
        "lastModified": "2026-07-09T15:16:35.927",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53482",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerProtect Data Domain performs unchecked integer arithmetic that can wrap an allocation or bounds calculation.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 392,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-53483",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:04:35.250Z",
      "date_published": "2026-07-07T12:57:07.708Z",
      "date_updated": "2026-07-08T03:56:40.966Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29956
      },
      "nvd": {
        "published": "2026-07-07T13:16:31.590",
        "lastModified": "2026-07-08T19:57:04.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53483",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PowerProtect Data Domain accepts a remote unauthenticated caller as authorized, while Dell does not publish the credential or session check that fails.",
        "basis": [
          "CNA",
          "CWE-287",
          "Dell DSA-2026-278"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities; Dell repeats the improper-authentication result without publishing the request path or check."
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 551,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-53486",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:05:25.058Z",
      "date_published": "2026-07-14T20:07:14.190Z",
      "date_updated": "2026-07-15T13:26:56.864Z",
      "publisher": "GitHub_M",
      "title": "decompress: Archive extraction can create files and links outside the target directory",
      "affected": {
        "vendors": [
          "XhmikosR"
        ],
        "products": [
          {
            "vendor": "XhmikosR",
            "product": "decompress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00643,
        "percentile": 0.4729
      },
      "nvd": {
        "published": "2026-07-14T21:17:05.447",
        "lastModified": "2026-07-15T20:29:17.680",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53486",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/XhmikosR/decompress/security/advisories/GHSA-mp2f-45pm-3cg9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/XhmikosR/decompress/commit/281cefa00cd4275c10479bc5f1abba6b14dee8bd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/XhmikosR/decompress/commit/60b5299402e72b0b53ca2e55222e9a1ccb44afae",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/XhmikosR/decompress/commit/9fcda4b0a66ca22dc8d337f9b0e7c30293c5fb89",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/XhmikosR/decompress/commit/aca5aac415dc04a6fae5200e51368cff436a09dd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/XhmikosR/decompress/releases/tag/v10.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/XhmikosR/decompress/releases/tag/v11.1.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 7,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-53488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:05:25.059Z",
      "date_published": "2026-07-01T00:11:20.610Z",
      "date_updated": "2026-07-03T03:56:07.868Z",
      "publisher": "GitHub_M",
      "title": "containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull",
      "affected": {
        "vendors": [
          "containerd"
        ],
        "products": [
          {
            "vendor": "containerd",
            "product": "containerd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07352
      },
      "nvd": {
        "published": "2026-07-01T02:17:00.467",
        "lastModified": "2026-07-03T04:17:55.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53488",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Untrusted image LABEL values flow into a restart monitor's binary:// logger command without validation at the CRI boundary.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/containerd/containerd/security/advisories/GHSA-xhf5-7wjv-pqxp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 438,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-53489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:05:25.059Z",
      "date_published": "2026-07-01T18:10:41.802Z",
      "date_updated": "2026-07-02T14:34:50.018Z",
      "publisher": "GitHub_M",
      "title": "containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore",
      "affected": {
        "vendors": [
          "containerd"
        ],
        "products": [
          {
            "vendor": "containerd",
            "product": "containerd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-61",
          "name": "UNIX Symbolic Link (Symlink) Following",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08481
      },
      "nvd": {
        "published": "2026-07-01T19:16:54.383",
        "lastModified": "2026-07-02T19:33:12.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53489",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Containerd restores a checkpoint-supplied container.log symlink without validating its target, allowing log reads from arbitrary host files.",
        "basis": [
          "CNA",
          "CWE-61"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/containerd/containerd/security/advisories/GHSA-rgh6-rfwx-v388",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 346,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-53492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:05:25.059Z",
      "date_published": "2026-07-01T17:59:12.552Z",
      "date_updated": "2026-07-02T12:50:43.273Z",
      "publisher": "GitHub_M",
      "title": "containerd CRI checkpoint restore CDI annotation smuggling",
      "affected": {
        "vendors": [
          "containerd"
        ],
        "products": [
          {
            "vendor": "containerd",
            "product": "containerd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00347,
        "percentile": 0.2738
      },
      "nvd": {
        "published": "2026-07-01T19:16:54.510",
        "lastModified": "2026-07-02T19:33:00.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53492",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Checkpoint restore trusts CDI annotations from untrusted archive metadata instead of reauthorizing devices and mounts against the pod's create-time specification.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/containerd/containerd/security/advisories/GHSA-33vj-92qq-66hc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 965,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-53500",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:05:25.059Z",
      "date_published": "2026-07-31T18:35:54.234Z",
      "date_updated": "2026-07-31T23:30:44.046Z",
      "publisher": "GitHub_M",
      "title": "Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot",
      "affected": {
        "vendors": [
          "thumbor"
        ],
        "products": [
          {
            "vendor": "thumbor",
            "product": "thumbor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20936
      },
      "nvd": {
        "published": "2026-07-31T19:17:09.247",
        "lastModified": "2026-08-01T00:17:16.713",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53500",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "thumbor follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thumbor/thumbor/security/advisories/GHSA-6x26-6r6f-m537",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/thumbor/thumbor/commit/68876715350c6c8f49c324e5515e64908830aed7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/thumbor/thumbor/releases/tag/7.8.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:05:25.059Z",
      "date_published": "2026-07-31T18:42:42.360Z",
      "date_updated": "2026-07-31T19:58:01.891Z",
      "publisher": "GitHub_M",
      "title": "Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature",
      "affected": {
        "vendors": [
          "thumbor"
        ],
        "products": [
          {
            "vendor": "thumbor",
            "product": "thumbor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11069
      },
      "nvd": {
        "published": "2026-07-31T19:17:09.413",
        "lastModified": "2026-07-31T20:16:51.280",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53501",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Removing every occurrence of an HMAC substring makes the URL that is validated differ from the resource URL that is used.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thumbor/thumbor/security/advisories/GHSA-mw3h-qjxj-6xg9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/thumbor/thumbor/commit/e3ae3e2500537b4d735df4144129a649374bb70b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/thumbor/thumbor/releases/tag/7.8.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 581,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53502",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:05:25.059Z",
      "date_published": "2026-07-31T19:03:16.522Z",
      "date_updated": "2026-07-31T19:18:09.047Z",
      "publisher": "GitHub_M",
      "title": "Thumbor has path traversal via post-validation URL decoding bypass in file_loader",
      "affected": {
        "vendors": [
          "thumbor"
        ],
        "products": [
          {
            "vendor": "thumbor",
            "product": "thumbor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00357,
        "percentile": 0.28391
      },
      "nvd": {
        "published": "2026-07-31T19:17:09.577",
        "lastModified": "2026-07-31T20:16:51.397",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53502",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Path decoding occurs after the root check, allowing an encoded traversal to select a file outside the intended root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thumbor/thumbor/security/advisories/GHSA-cj54-hpcc-gj6h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/thumbor/thumbor/commit/3b986d13677b30fe6651c8c72ebb25957ac0a40d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/thumbor/thumbor/releases/tag/7.8.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 285,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53503",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:05:25.059Z",
      "date_published": "2026-07-31T18:54:20.747Z",
      "date_updated": "2026-07-31T21:39:35.108Z",
      "publisher": "GitHub_M",
      "title": "Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS",
      "affected": {
        "vendors": [
          "thumbor"
        ],
        "products": [
          {
            "vendor": "thumbor",
            "product": "thumbor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-369",
          "name": "Divide By Zero",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34371
      },
      "nvd": {
        "published": "2026-07-31T19:17:09.737",
        "lastModified": "2026-07-31T22:17:02.790",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53503",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The convolution extension uses the unvalidated columns value as a divisor and reaches division by zero.",
        "basis": [
          "CNA record",
          "CWE-369"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thumbor/thumbor/security/advisories/GHSA-cqjp-jf4r-h5q9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/thumbor/thumbor/commit/447e192e3fb92e64c12e5354a56a4a7133f69d73",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/thumbor/thumbor/releases/tag/7.8.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53504",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:05:25.059Z",
      "date_published": "2026-07-31T18:57:19.257Z",
      "date_updated": "2026-07-31T23:31:37.588Z",
      "publisher": "GitHub_M",
      "title": "Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter",
      "affected": {
        "vendors": [
          "thumbor"
        ],
        "products": [
          {
            "vendor": "thumbor",
            "product": "thumbor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26029
      },
      "nvd": {
        "published": "2026-07-31T19:17:09.920",
        "lastModified": "2026-08-01T00:17:16.823",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53504",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The convolution-filter regular expression performs exponential backtracking on repeated numeric input without a work bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thumbor/thumbor/security/advisories/GHSA-5vjc-7cxw-4w6j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/thumbor/thumbor/commit/3f38fe1610d20168e91f76d432212de30727eb2e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/thumbor/thumbor/releases/tag/7.8.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53505",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:05:25.059Z",
      "date_published": "2026-07-31T19:00:22.755Z",
      "date_updated": "2026-08-03T17:20:37.186Z",
      "publisher": "GitHub_M",
      "title": "Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS",
      "affected": {
        "vendors": [
          "thumbor"
        ],
        "products": [
          {
            "vendor": "thumbor",
            "product": "thumbor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26483
      },
      "nvd": {
        "published": "2026-07-31T19:17:10.123",
        "lastModified": "2026-08-03T18:16:39.617",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53505",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Thumbor accepts an unbounded proportion filter that requests extremely large post-transform resizes and exhausts CPU and memory.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thumbor/thumbor/security/advisories/GHSA-phj3-59pf-cp83",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/thumbor/thumbor/commit/2c716119de986cfc68c7071af52a98187e006023",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/thumbor/thumbor/releases/tag/7.8.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53510",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:05:25.060Z",
      "date_published": "2026-07-31T19:38:33.457Z",
      "date_updated": "2026-07-31T20:04:21.069Z",
      "publisher": "GitHub_M",
      "title": "Savon::Model evaluates WSDL operation names as Ruby source",
      "affected": {
        "vendors": [
          "savonrb"
        ],
        "products": [
          {
            "vendor": "savonrb",
            "product": "savon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32367
      },
      "nvd": {
        "published": "2026-07-31T20:16:51.530",
        "lastModified": "2026-07-31T20:16:51.530",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53510",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Savon interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/savonrb/savon/security/advisories/GHSA-mx5j-mp4f-g8jg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/savonrb/savon/commit/8f22eb543e7436f6247172c9be47e22792d375e9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/savonrb/savon/releases/tag/v2.17.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53511",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:30:33.455Z",
      "date_published": "2026-07-07T20:46:49.199Z",
      "date_updated": "2026-07-09T03:55:49.907Z",
      "publisher": "GitHub_M",
      "title": "calibre: Arbitrary Code Execution in Template Formatter via Book Metadata",
      "affected": {
        "vendors": [
          "kovidgoyal"
        ],
        "products": [
          {
            "vendor": "kovidgoyal",
            "product": "calibre"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04623
      },
      "nvd": {
        "published": "2026-07-07T21:17:26.380",
        "lastModified": "2026-07-10T18:59:59.160",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53511",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled values are incorporated into generated code without enforcing a safe code-data boundary.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kovidgoyal/calibre/security/advisories/GHSA-2j4m-2q7x-2c47",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/kovidgoyal/calibre/commit/712f4e1ff5c1e798c335bef3bacc4efdee052e9c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kovidgoyal/calibre/releases/tag/v9.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 388,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53512",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:30:33.455Z",
      "date_published": "2026-07-15T17:18:09.512Z",
      "date_updated": "2026-07-18T01:08:08.419Z",
      "publisher": "GitHub_M",
      "title": "Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins",
      "affected": {
        "vendors": [
          "better-auth"
        ],
        "products": [
          {
            "vendor": "better-auth",
            "product": "better-auth"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11649
      },
      "nvd": {
        "published": "2026-07-15T18:16:47.420",
        "lastModified": "2026-07-21T13:33:47.543",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53512",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The refresh-token grant verifies token possession and client_id but omits the confidential client's secret, allowing token replay at the OAuth endpoint.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-287",
          "CWE-306",
          "CWE-345",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-pw9m-5jxm-xr6h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/pull/9576",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/commit/1f2ff4215c4affff0b140b0c0a712c0dde35659c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/releases/tag/v1.6.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 4,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53513",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:30:33.455Z",
      "date_published": "2026-07-15T17:15:59.611Z",
      "date_updated": "2026-07-15T19:29:02.266Z",
      "publisher": "GitHub_M",
      "title": "Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration",
      "affected": {
        "vendors": [
          "@better-auth",
          "better-auth"
        ],
        "products": [
          {
            "vendor": "better-auth",
            "product": "better-auth"
          },
          {
            "vendor": "@better-auth",
            "product": "sso"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08752
      },
      "nvd": {
        "published": "2026-07-15T18:16:47.547",
        "lastModified": "2026-07-21T15:39:52.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53513",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The better-auth server fetches an attacker-selected network destination without enforcing the intended destination policy.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-345",
          "CWE-441",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-5rr4-8452-hf4v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/pull/9574",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/commit/37f60cb176cb53147da7dfd5ec15afa5b486e81e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/releases/tag/v1.6.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 564,
        "referenceCount": 4,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-53514",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:30:33.456Z",
      "date_published": "2026-07-15T17:30:46.069Z",
      "date_updated": "2026-07-18T01:13:02.175Z",
      "publisher": "GitHub_M",
      "title": "Better Auth: Unauthorized invitation acceptance via unverified email match in organization plugin",
      "affected": {
        "vendors": [
          "better-auth"
        ],
        "products": [
          {
            "vendor": "better-auth",
            "product": "better-auth"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03723
      },
      "nvd": {
        "published": "2026-07-15T18:16:47.683",
        "lastModified": "2026-07-21T13:41:03.313",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53514",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The invitation flow treats possession of an unverified email address as ownership of the invited identity.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-345",
          "CWE-441",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-fmh4-wcc4-5jm3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/pull/9577",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/commit/23094a628f007f801be6d26e5b15dc5fc6fc4eb8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/releases/tag/v1.6.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 808,
        "referenceCount": 4,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53515",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:30:33.456Z",
      "date_published": "2026-07-15T17:27:00.291Z",
      "date_updated": "2026-07-15T19:30:08.165Z",
      "publisher": "GitHub_M",
      "title": "Better Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/sso",
      "affected": {
        "vendors": [
          "@better-auth",
          "better-auth"
        ],
        "products": [
          {
            "vendor": "better-auth",
            "product": "better-auth"
          },
          {
            "vendor": "@better-auth",
            "product": "sso"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14983
      },
      "nvd": {
        "published": "2026-07-15T18:16:47.817",
        "lastModified": "2026-07-21T15:38:36.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53515",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The better-auth privilege path permits a lower-trust actor to acquire or exercise a role beyond the actor's assigned authority.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-285",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-gv74-j8m3-fg5f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/pull/9220",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/commit/86765f1597378f5c3deed1b80ca91faac0a6bf00",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/releases/tag/v1.6.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 494,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-53516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:30:33.456Z",
      "date_published": "2026-07-15T17:13:16.431Z",
      "date_updated": "2026-07-15T17:52:35.572Z",
      "publisher": "GitHub_M",
      "title": "Better Auth: Account takeover via OAuth auto-link to unverified pre-registered email",
      "affected": {
        "vendors": [
          "better-auth"
        ],
        "products": [
          {
            "vendor": "better-auth",
            "product": "better-auth"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04872
      },
      "nvd": {
        "published": "2026-07-15T18:16:47.967",
        "lastModified": "2026-07-21T14:14:22.307",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53516",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Better Auth trusts an identity provider's email_verified claim for account linking without restricting which providers may assert that identity.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-g38m-r43w-p2q7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/pull/9578",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/commit/da7e50beee849c59a2ed1ec6b3a38cc6ab9fb563",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/releases/tag/v1.6.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 640,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53517",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:30:33.456Z",
      "date_published": "2026-07-15T17:33:38.943Z",
      "date_updated": "2026-07-15T19:21:22.553Z",
      "publisher": "GitHub_M",
      "title": "Better Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Concurrent Replay and Token Family Forking",
      "affected": {
        "vendors": [
          "@better-auth",
          "better-auth"
        ],
        "products": [
          {
            "vendor": "better-auth",
            "product": "better-auth"
          },
          {
            "vendor": "@better-auth",
            "product": "oauth-provider"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15238
      },
      "nvd": {
        "published": "2026-07-15T18:16:48.107",
        "lastModified": "2026-07-21T16:00:22.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53517",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Better Auth performs refresh-token read, validation, revocation, and replacement as separate operations, allowing concurrent requests to validate one parent token and mint forked token families.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-392p-2q2v-4372",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/commit/c6918ecc9e3a75892169415d7f6c95b591b6a52d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/releases/tag/v1.6.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-53518",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:30:33.456Z",
      "date_published": "2026-07-15T17:17:06.410Z",
      "date_updated": "2026-07-15T18:07:49.190Z",
      "publisher": "GitHub_M",
      "title": "Better Auth OAuth Provider: Race Condition in Authorization Code Exchange Enables Multi-Use Code Redemption",
      "affected": {
        "vendors": [
          "better-auth"
        ],
        "products": [
          {
            "vendor": "better-auth",
            "product": "better-auth"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13819
      },
      "nvd": {
        "published": "2026-07-15T18:16:48.240",
        "lastModified": "2026-07-21T16:03:12.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53518",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Authorization-code redemption is not atomic, so concurrent requests can redeem the same code more than once.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-7w99-5wm4-3g79",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/commit/b4bc65a007784b2eb0efb459e5fa6fd8055d3ec9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/better-auth/better-auth/releases/tag/v1.6.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T17:30:33.457Z",
      "date_published": "2026-07-16T18:52:43.462Z",
      "date_updated": "2026-07-17T18:06:44.807Z",
      "publisher": "GitHub_M",
      "title": "Activepieces: Arbitrary file write in git-sync via path traversal and symlinks",
      "affected": {
        "vendors": [
          "activepieces"
        ],
        "products": [
          {
            "vendor": "activepieces",
            "product": "activepieces"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00574,
        "percentile": 0.44167
      },
      "nvd": {
        "published": "2026-07-16T19:16:50.097",
        "lastModified": "2026-07-17T19:17:16.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53535",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Git sync follows repository symlinks and accepts ../ in stored identifiers, so generated project state can overwrite host files outside the clone.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/activepieces/activepieces/security/advisories/GHSA-qqcr-rg2x-97mm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/activepieces/activepieces/pull/12711",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/activepieces/activepieces/commit/01bd4ef76fc1ad1bf7adc10c39ece4f624da6bf5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/activepieces/activepieces/releases/tag/0.82.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1167,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T18:13:07.262Z",
      "date_published": "2026-07-16T18:48:30.875Z",
      "date_updated": "2026-07-18T03:06:51.360Z",
      "publisher": "GitHub_M",
      "title": "Activepieces: Cross-tenant file download via missing JWT audience check on step-files signed URL",
      "affected": {
        "vendors": [
          "activepieces"
        ],
        "products": [
          {
            "vendor": "activepieces",
            "product": "activepieces"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08191
      },
      "nvd": {
        "published": "2026-07-16T19:16:50.240",
        "lastModified": "2026-07-18T03:16:36.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53536",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A JWT accepted without validating its audience can name a null fileId that falls through to a cross-tenant object lookup.",
        "basis": [
          "CNA",
          "CWE-345",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/activepieces/activepieces/security/advisories/GHSA-9723-fmff-mc24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/activepieces/activepieces/commit/2cb6148010a6c2a22900f4c8b08d75cc5c921d1c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/activepieces/activepieces/commit/afe852f60e39fcc6273d41e11f0765586b5a0e49",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/activepieces/activepieces/releases/tag/0.83.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 862,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53551",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T18:13:07.263Z",
      "date_published": "2026-07-31T20:12:57.932Z",
      "date_updated": "2026-08-03T16:26:59.863Z",
      "publisher": "GitHub_M",
      "title": "free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure",
      "affected": {
        "vendors": [
          "free5gc"
        ],
        "products": [
          {
            "vendor": "free5gc",
            "product": "free5gc"
          },
          {
            "vendor": "free5gc",
            "product": "ausf"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00429,
        "percentile": 0.35308
      },
      "nvd": {
        "published": "2026-07-31T20:16:51.697",
        "lastModified": "2026-08-03T17:16:38.093",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53551",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "JSON accepts control characters in supiOrSuci that are then copied unescaped into a URL path, where Go's URL parser rejects the second grammar and triggers the failure path.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/free5gc/free5gc/security/advisories/GHSA-qj55-47fp-p62j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/free5gc/free5gc/issues/1048",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/free5gc/ausf/pull/61",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/free5gc/ausf/commit/bfc4a10094dbacbd862baa4686829f3fcc06ce1e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/free5gc/ausf/releases/tag/v1.4.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/free5gc/free5gc/releases/tag/v4.2.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 642,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-53565",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T18:32:47.375Z",
      "date_published": "2026-07-14T12:49:17.998Z",
      "date_updated": "2026-07-15T04:00:59.472Z",
      "publisher": "Citrix",
      "title": "Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges",
      "affected": {
        "vendors": [
          "Citrix"
        ],
        "products": [
          {
            "vendor": "Citrix",
            "product": "Secure Access Client for Windows"
          },
          {
            "vendor": "Citrix",
            "product": "Citrix Endpoint Analysis Client for Windows"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:secure@citrix.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02619
      },
      "nvd": {
        "published": "2026-07-14T13:18:58.463",
        "lastModified": "2026-07-15T16:23:57.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53565",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege local user can become SYSTEM, but the Citrix record does not identify the privileged object or missing role check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696734",
          "host": "support.citrix.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-53566",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T18:32:47.375Z",
      "date_published": "2026-07-14T13:12:57.829Z",
      "date_updated": "2026-07-14T13:56:09.574Z",
      "publisher": "Citrix",
      "title": "Out-of-bounds memory read",
      "affected": {
        "vendors": [
          "Citrix"
        ],
        "products": [
          {
            "vendor": "Citrix",
            "product": "Citrix Secure Access Client for Windows"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:secure@citrix.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03187
      },
      "nvd": {
        "published": "2026-07-14T14:16:34.960",
        "lastModified": "2026-07-15T16:23:57.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53566",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Citrix Secure Access Client reads beyond the end of a valid memory buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696734",
          "host": "support.citrix.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 162,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53573",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T19:11:53.483Z",
      "date_published": "2026-07-31T22:16:25.110Z",
      "date_updated": "2026-08-03T16:26:56.688Z",
      "publisher": "GitHub_M",
      "title": "core-geonetwork has an Open Redirect Bypass",
      "affected": {
        "vendors": [
          "geonetwork"
        ],
        "products": [
          {
            "vendor": "geonetwork",
            "product": "core-geonetwork"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30436
      },
      "nvd": {
        "published": "2026-07-31T23:17:24.667",
        "lastModified": "2026-08-03T17:16:38.220",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53573",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OAuth login filters accept an external post-login redirect target without restricting it to a trusted destination.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-pjp7-q6wp-97qx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/geonetwork/core-geonetwork/pull/9307",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/geonetwork/core-geonetwork/pull/9309",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-53591",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T19:11:53.485Z",
      "date_published": "2026-07-20T19:47:18.338Z",
      "date_updated": "2026-07-20T20:15:26.874Z",
      "publisher": "GitHub_M",
      "title": "FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmails",
      "affected": {
        "vendors": [
          "freescout-help-desk"
        ],
        "products": [
          {
            "vendor": "freescout-help-desk",
            "product": "freescout"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12033
      },
      "nvd": {
        "published": "2026-07-20T20:16:44.613",
        "lastModified": "2026-07-21T19:25:11.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53591",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The inbound reply authenticator accepts a malformed HMAC length, allowing an unauthenticated email to be attached to an existing conversation.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-8vm3-wwq4-ggfx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53592",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T19:39:52.403Z",
      "date_published": "2026-07-20T19:49:06.270Z",
      "date_updated": "2026-07-21T14:42:22.367Z",
      "publisher": "GitHub_M",
      "title": "FreeScout vulnerable to prototype pollution in getQueryParam",
      "affected": {
        "vendors": [
          "freescout-help-desk"
        ],
        "products": [
          {
            "vendor": "freescout-help-desk",
            "product": "freescout"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02105
      },
      "nvd": {
        "published": "2026-07-20T20:16:44.747",
        "lastModified": "2026-07-21T19:25:11.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53592",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "getQueryParam blocks only top-level __proto__ keys and still follows nested attacker keys into Object.prototype.",
        "basis": [
          "CNA",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-w5fc-8pp3-f755",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53593",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T19:39:52.403Z",
      "date_published": "2026-07-20T19:52:33.060Z",
      "date_updated": "2026-07-21T14:56:31.717Z",
      "publisher": "GitHub_M",
      "title": "FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete upload extension denylist (.pht) — bypass of CVE-2025-48471",
      "affected": {
        "vendors": [
          "freescout-help-desk"
        ],
        "products": [
          {
            "vendor": "freescout-help-desk",
            "product": "freescout"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20511
      },
      "nvd": {
        "published": "2026-07-20T20:16:44.883",
        "lastModified": "2026-07-21T19:25:11.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53593",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload denylist omits the executable .pht extension while preserving original extensions in a web-accessible directory.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-27vp-fpg8-j8wv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 899,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53594",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T19:39:52.403Z",
      "date_published": "2026-07-20T20:12:54.720Z",
      "date_updated": "2026-07-21T13:55:06.155Z",
      "publisher": "GitHub_M",
      "title": "FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path",
      "affected": {
        "vendors": [
          "freescout-help-desk"
        ],
        "products": [
          {
            "vendor": "freescout-help-desk",
            "product": "freescout"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27823
      },
      "nvd": {
        "published": "2026-07-20T21:16:48.280",
        "lastModified": "2026-07-21T19:25:11.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53594",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "freescout allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-858x-8f77-9vc5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 674,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53595",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T19:39:52.403Z",
      "date_published": "2026-07-20T20:14:59.365Z",
      "date_updated": "2026-07-21T14:56:21.784Z",
      "publisher": "GitHub_M",
      "title": "FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL",
      "affected": {
        "vendors": [
          "freescout-help-desk"
        ],
        "products": [
          {
            "vendor": "freescout-help-desk",
            "product": "freescout"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-178",
          "name": "Improper Handling of Case Sensitivity",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00374,
        "percentile": 0.3012
      },
      "nvd": {
        "published": "2026-07-20T21:16:48.417",
        "lastModified": "2026-07-21T19:25:11.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53595",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public user-setup route selects an account by an empty invite hash and accepts a plaintext far-future timestamp after decryption failure, allowing the selected account to be reset.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-178",
          "CWE-287",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-jqj5-r72v-v29g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1156,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53596",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T19:39:52.403Z",
      "date_published": "2026-07-20T20:17:38.322Z",
      "date_updated": "2026-07-21T16:27:52.079Z",
      "publisher": "GitHub_M",
      "title": "FreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)",
      "affected": {
        "vendors": [
          "freescout-help-desk"
        ],
        "products": [
          {
            "vendor": "freescout-help-desk",
            "product": "freescout"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14863
      },
      "nvd": {
        "published": "2026-07-20T21:16:48.550",
        "lastModified": "2026-07-21T19:25:11.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53596",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FreeScout accepts unlimited upload requests without rate limiting, allowing repeated requests to overload storage and database work.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-ph4f-2jhx-q76w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53597",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T19:39:52.404Z",
      "date_published": "2026-07-16T14:54:55.075Z",
      "date_updated": "2026-07-18T02:51:03.900Z",
      "publisher": "GitHub_M",
      "title": "Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "prompty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00931,
        "percentile": 0.57198
      },
      "nvd": {
        "published": "2026-07-16T16:19:12.860",
        "lastModified": "2026-07-18T03:16:36.890",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53597",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Prompty loader leaves gray-matter's executable JavaScript frontmatter engines enabled for attacker-controlled prompt files.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/prompty/security/advisories/GHSA-c4gh-rv8h-q9vw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/prompty/commit/c27402da2487075be577f06aa79df627fb9d6853",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 446,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53598",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T19:39:52.404Z",
      "date_published": "2026-07-16T14:59:01.797Z",
      "date_updated": "2026-07-17T14:06:36.423Z",
      "publisher": "GitHub_M",
      "title": "Prompty: Arbitrary File Read via ${file:path} Reference Expansion",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "prompty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01057,
        "percentile": 0.61155
      },
      "nvd": {
        "published": "2026-07-16T16:19:12.990",
        "lastModified": "2026-07-17T14:17:24.793",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53598",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prompty expands file references without confining absolute, parent-relative, or symlink-resolved paths to an allowed root.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/prompty/security/advisories/GHSA-wxhm-2mq7-7697",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/prompty/commit/88ac9948d7d37995edbb2f6d36913436626c39e1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53599",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T19:39:52.404Z",
      "date_published": "2026-07-31T19:43:15.663Z",
      "date_updated": "2026-07-31T21:39:28.144Z",
      "publisher": "GitHub_M",
      "title": "Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers",
      "affected": {
        "vendors": [
          "redaxo"
        ],
        "products": [
          {
            "vendor": "redaxo",
            "product": "core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23802
      },
      "nvd": {
        "published": "2026-07-31T20:16:51.847",
        "lastModified": "2026-07-31T22:17:03.213",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53599",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "REDAXO validates a polyglot upload under an allowed extension while allowing executable content to be stored in the media namespace.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/redaxo/core/security/advisories/GHSA-98pp-vccm-qm25",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/redaxo/core/pull/6538",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/redaxo/core/commit/462e36896bb65d292ba22d711044c23c9cfb0340",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/redaxo/core/releases/tag/5.21.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 401,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53624",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:16:59.646Z",
      "date_published": "2026-07-08T19:32:08.191Z",
      "date_updated": "2026-07-10T14:57:28.656Z",
      "publisher": "GitHub_M",
      "title": "Fiber: HSTS header never set in helmet middleware due to incorrect protocol check",
      "affected": {
        "vendors": [
          "gofiber"
        ],
        "products": [
          {
            "vendor": "gofiber",
            "product": "fiber"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-319",
          "name": "Cleartext Transmission of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07579
      },
      "nvd": {
        "published": "2026-07-08T20:16:52.293",
        "lastModified": "2026-07-15T20:49:42.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53624",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fiber checks c.Protocol() instead of c.Scheme(), so configured HSTS policy is never placed on HTTPS responses.",
        "basis": [
          "CNA",
          "CWE-319"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gofiber/fiber/security/advisories/GHSA-gv83-gqw6-9j2c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gofiber/fiber/pull/4389",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gofiber/fiber/commit/04dd4e7754f61768fddccacc79057e416f13e6bf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gofiber/fiber/releases/tag/v3.4.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53633",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:16:59.647Z",
      "date_published": "2026-07-14T19:35:42.739Z",
      "date_updated": "2026-07-29T18:26:18.528Z",
      "publisher": "GitHub_M",
      "title": "Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE",
      "affected": {
        "vendors": [
          "vitest-dev"
        ],
        "products": [
          {
            "vendor": "vitest-dev",
            "product": "vitest"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-749",
          "name": "Exposed Dangerous Method or Function",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00578,
        "percentile": 0.44318
      },
      "nvd": {
        "published": "2026-07-14T20:17:42.173",
        "lastModified": "2026-07-29T19:16:47.370",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53633",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker-controlled Node.js code.",
        "basis": [
          "CNA",
          "CWE-749",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vitest-dev/vitest/security/advisories/GHSA-g8mr-85jm-7xhm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/pull/10444",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/pull/10450",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/pull/10456",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/commit/385a1aefd4c2bfa5e7d58bf7c6834c929969f2c7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/commit/63e3b2eee4d58da56786a6333f517b9b492528c7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/commit/e4067b3b150005fd42cf75f994300119245806b9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/releases/tag/v3.2.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/releases/tag/v4.1.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vitest-dev/vitest/releases/tag/v5.0.0-beta.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 10,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-53640",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:16:59.648Z",
      "date_published": "2026-07-06T22:30:48.314Z",
      "date_updated": "2026-07-07T14:12:19.961Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13424
      },
      "nvd": {
        "published": "2026-07-06T23:16:55.430",
        "lastModified": "2026-07-07T15:16:47.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53640",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-jqw4-3hj3-8m4f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 554,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53641",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:16:59.648Z",
      "date_published": "2026-07-06T22:36:38.105Z",
      "date_updated": "2026-07-08T19:41:51.333Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-838",
          "name": "Inappropriate Encoding for Output Context",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20824
      },
      "nvd": {
        "published": "2026-07-06T23:16:55.967",
        "lastModified": "2026-07-08T20:16:52.437",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53641",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-838"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-q6c8-6r72-35f7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 722,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53642",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:16:59.648Z",
      "date_published": "2026-07-06T22:45:51.137Z",
      "date_updated": "2026-07-07T14:27:05.224Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling: Unverified clients can access client-area pages when email confirmation is required",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13423
      },
      "nvd": {
        "published": "2026-07-06T23:16:56.097",
        "lastModified": "2026-07-07T15:16:47.823",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53642",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-7v47-rh46-w923",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 733,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53643",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:16:59.648Z",
      "date_published": "2026-07-06T22:49:50.500Z",
      "date_updated": "2026-07-07T13:59:08.434Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13424
      },
      "nvd": {
        "published": "2026-07-06T23:16:56.227",
        "lastModified": "2026-07-07T15:16:47.930",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53643",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FOSSBilling resolves a caller-controlled object identifier without binding the selected object to the caller's authorized scope.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-563q-g4r4-6f9m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 668,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53644",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:16:59.648Z",
      "date_published": "2026-07-06T22:51:39.028Z",
      "date_updated": "2026-07-07T13:46:20.051Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active orders",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16552
      },
      "nvd": {
        "published": "2026-07-06T23:16:56.360",
        "lastModified": "2026-07-07T14:16:32.743",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53644",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "API-key secrets remain readable and resettable after an order leaves the active lifecycle state because the endpoints omit an order-state check.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-qf6j-vq68-qmfh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 819,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53645",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:16:59.648Z",
      "date_published": "2026-07-06T22:55:56.528Z",
      "date_updated": "2026-07-07T13:42:46.451Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalation",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15201
      },
      "nvd": {
        "published": "2026-07-06T23:16:56.493",
        "lastModified": "2026-07-07T14:16:32.857",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53645",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A staff user can update their own permission fields without an administrator authorization check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-4hf7-xxxw-64rm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 754,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53646",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:16:59.648Z",
      "date_published": "2026-07-06T22:58:10.415Z",
      "date_updated": "2026-07-07T13:56:05.622Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling: Client password reset token reuse allows persistent account takeover",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11948
      },
      "nvd": {
        "published": "2026-07-06T23:16:56.683",
        "lastModified": "2026-07-07T15:16:48.033",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53646",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A new password-reset request reuses the existing token instead of rotating and invalidating the previously issued token.",
        "basis": [
          "CNA record",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-vp66-w6rc-x32p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 996,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53647",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:50:36.876Z",
      "date_published": "2026-07-06T23:10:29.692Z",
      "date_updated": "2026-07-07T14:28:02.693Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0042,
        "percentile": 0.34584
      },
      "nvd": {
        "published": "2026-07-07T00:16:34.263",
        "lastModified": "2026-07-07T15:16:48.137",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53647",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FOSSBilling exposes a security-sensitive endpoint without requiring caller authentication.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-306",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-737q-9gpr-6mpq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 817,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53648",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:50:36.876Z",
      "date_published": "2026-07-06T23:12:09.614Z",
      "date_updated": "2026-07-07T13:58:05.740Z",
      "publisher": "GitHub_M",
      "title": "FOSSBilling: Downloadable product files can be overwritten through filename collisions",
      "affected": {
        "vendors": [
          "FOSSBilling"
        ],
        "products": [
          {
            "vendor": "FOSSBilling",
            "product": "FOSSBilling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-668",
          "name": "Exposure of Resource to Wrong Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18161
      },
      "nvd": {
        "published": "2026-07-07T00:16:34.390",
        "lastModified": "2026-07-07T15:16:48.243",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53648",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FOSSBilling derives storage solely from the original filename hash, so equal names select one path and a later upload overwrites an earlier product.",
        "basis": [
          "CNA",
          "CWE-73",
          "CWE-668"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-x7p2-xhvc-cfp9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1037,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53653",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:50:36.876Z",
      "date_published": "2026-07-10T16:12:01.576Z",
      "date_updated": "2026-07-10T20:58:50.005Z",
      "publisher": "GitHub_M",
      "title": "Grav: Unauthenticated denial of service via unbounded image derivative dimensions",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22418
      },
      "nvd": {
        "published": "2026-07-10T17:16:57.857",
        "lastModified": "2026-07-10T21:16:54.963",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53653",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Grav accepts attacker-selected image derivative dimensions without a pixel, memory, or CPU ceiling.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-4x9g-vw65-vvf9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/commit/d9f9f0369a07ae5c96cde700c7949e1237b29cf6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/commit/f4c0f42eea755cedad6f626b342c88d4cba72174",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/releases/tag/1.7.53",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/releases/tag/2.0.0-rc.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-53657",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:50:36.876Z",
      "date_published": "2026-07-10T15:42:39.774Z",
      "date_updated": "2026-07-14T01:53:50.477Z",
      "publisher": "GitHub_M",
      "title": "Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket",
      "affected": {
        "vendors": [
          "lima-vm"
        ],
        "products": [
          {
            "vendor": "lima-vm",
            "product": "lima"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-668",
          "name": "Exposure of Resource to Wrong Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02989
      },
      "nvd": {
        "published": "2026-07-10T17:16:57.987",
        "lastModified": "2026-07-14T02:16:55.467",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53657",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The QEMU guest-agent socket is accessible to arbitrary guest users even though it can tunnel to privileged Unix sockets.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lima-vm/lima/security/advisories/GHSA-2j9v-p4xj-cjw2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lima-vm/lima/commit/8a45892378d22f40505c31a38f786a07701b6d50",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lima-vm/lima/commit/b08cae8a670cf916d5da11c48a6de76dabd89678",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lima-vm/lima/releases/tag/v2.1.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 510,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53666",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:50:36.877Z",
      "date_published": "2026-07-27T21:14:49.547Z",
      "date_updated": "2026-07-28T15:19:58.603Z",
      "publisher": "GitHub_M",
      "title": "React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration",
      "affected": {
        "vendors": [
          "remix-run"
        ],
        "products": [
          {
            "vendor": "remix-run",
            "product": "react-router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00415,
        "percentile": 0.34148
      },
      "nvd": {
        "published": "2026-07-27T22:17:30.937",
        "lastModified": "2026-08-03T14:04:25.027",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53666",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "deserializeErrors permits attacker-influenced SSR error fields to select and invoke an unexpected constructor during client hydration.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-470"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/remix-run/react-router/security/advisories/GHSA-337j-9hxr-rhxg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/pull/15175",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/commit/9d22943fd46c8ae4b08236425fa3549e10e9ad1a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 662,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53667",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:50:36.877Z",
      "date_published": "2026-07-27T21:21:16.084Z",
      "date_updated": "2026-07-28T13:51:15.333Z",
      "publisher": "GitHub_M",
      "title": "React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)",
      "affected": {
        "vendors": [
          "remix-run"
        ],
        "products": [
          {
            "vendor": "remix-run",
            "product": "react-router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27685
      },
      "nvd": {
        "published": "2026-07-27T22:17:31.093",
        "lastModified": "2026-08-03T13:58:50.023",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53667",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "React Router's RSCErrorHandler accepts an untrusted redirect target without restricting its URL scheme, allowing navigation to an attacker-selected protocol.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/remix-run/react-router/security/advisories/GHSA-h8fp-f39c-q6mh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/pull/15177",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/commit/ce596e823f0d7b883a433af1d5a839a8b9fe0242",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 340,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53668",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:50:36.877Z",
      "date_published": "2026-07-27T21:42:17.641Z",
      "date_updated": "2026-07-28T13:44:11.335Z",
      "publisher": "GitHub_M",
      "title": "React Router: Open redirect can lead to XSS",
      "affected": {
        "vendors": [
          "remix-run"
        ],
        "products": [
          {
            "vendor": "remix-run",
            "product": "react-router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26224
      },
      "nvd": {
        "published": "2026-07-27T22:17:31.237",
        "lastModified": "2026-08-03T14:13:34.623",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53668",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A navigation or callback path accepts an attacker-controlled redirect destination outside the intended origin.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/remix-run/react-router/security/advisories/GHSA-jjmj-jmhj-qwj2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/pull/14718",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/commit/3a5b5ad0e5cf9918c646509563f5c41a89226ff3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-53669",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-09T20:50:36.877Z",
      "date_published": "2026-07-27T22:11:39.056Z",
      "date_updated": "2026-07-28T16:04:33.480Z",
      "publisher": "GitHub_M",
      "title": "React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)",
      "affected": {
        "vendors": [
          "remix-run"
        ],
        "products": [
          {
            "vendor": "remix-run",
            "product": "react-router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23827
      },
      "nvd": {
        "published": "2026-07-27T22:17:31.377",
        "lastModified": "2026-08-03T13:56:59.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53669",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The react-router navigation path permits attacker-controlled URL syntax to select an external destination outside the intended host policy.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/remix-run/react-router/security/advisories/GHSA-wrjc-x8rr-h8h6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/pull/15176",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "http://github.com/remix-run/react-router/pull/15176",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53712",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T16:43:31.241Z",
      "date_published": "2026-07-17T18:19:11.896Z",
      "date_updated": "2026-07-17T19:09:07.924Z",
      "publisher": "GitHub_M",
      "title": "SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithms",
      "affected": {
        "vendors": [
          "ongres"
        ],
        "products": [
          {
            "vendor": "ongres",
            "product": "scram"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-636",
          "name": "Not Failing Securely ('Failing Open')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-757",
          "name": "Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00167,
        "percentile": 0.06334
      },
      "nvd": {
        "published": "2026-07-17T19:17:16.880",
        "lastModified": "2026-07-23T16:15:11.587",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53712",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SCRAM client treats missing TLS endpoint binding data as permission to downgrade from SCRAM-SHA-256-PLUS to unbound SCRAM-SHA-256.",
        "basis": [
          "CNA",
          "CWE-636",
          "CWE-757"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ongres/scram/security/advisories/GHSA-p9jg-fcr6-3mhf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ongres/scram/releases/tag/3.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 748,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53727",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T16:43:31.242Z",
      "date_published": "2026-07-17T20:30:37.291Z",
      "date_updated": "2026-07-20T13:48:30.250Z",
      "publisher": "GitHub_M",
      "title": "css_parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`",
      "affected": {
        "vendors": [
          "premailer"
        ],
        "products": [
          {
            "vendor": "premailer",
            "product": "css_parser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22537
      },
      "nvd": {
        "published": "2026-07-17T21:17:07.837",
        "lastModified": "2026-07-23T16:15:11.587",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53727",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "css_parser fetches attacker-influenced CSS URLs without scheme, host, or IP filtering and follows redirects through the same function, allowing requests to internal addresses and redirected file URLs.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/premailer/css_parser/security/advisories/GHSA-9pmc-p236-855h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/premailer/css_parser/commit/7d2ddf0189cd54b54f378f59daefa10cb036e476",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/premailer/css_parser/commit/e0a151458b2a801ae265ba420862ef8b1127b3ae",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/premailer/css_parser/releases/tag/v3.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 743,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T16:43:31.242Z",
      "date_published": "2026-07-07T20:23:08.560Z",
      "date_updated": "2026-07-08T14:49:59.141Z",
      "publisher": "GitHub_M",
      "title": "DataEase ExportCenter IDOR allows cross-user export task access",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00391,
        "percentile": 0.31847
      },
      "nvd": {
        "published": "2026-07-07T21:17:26.543",
        "lastModified": "2026-07-08T15:16:29.190",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53729",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ExportCenter accepts another user task ID for download, deletion, retry, or link generation, and its download route also omits authentication.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-9423-78gr-xjj5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/57e90bdcc21c3fa2ec57184671603ad88a5b941b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T16:43:31.242Z",
      "date_published": "2026-07-07T20:29:19.728Z",
      "date_updated": "2026-07-09T14:42:33.726Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Unauthorized Access to Engine Database via previewSql Endpoint",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14545
      },
      "nvd": {
        "published": "2026-07-07T21:17:26.700",
        "lastModified": "2026-07-09T16:16:43.120",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53730",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SQL preview endpoint omits its permission annotation and lets any authenticated user select the built-in engine database and execute arbitrary statements.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-2jmq-vffm-4qmj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/7b47af38b8fa017c9eecb00a4a49264663189e7b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53751",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T17:48:40.545Z",
      "date_published": "2026-07-07T20:31:12.180Z",
      "date_updated": "2026-07-08T13:49:16.880Z",
      "publisher": "GitHub_M",
      "title": "DataEase: H2 JDBC URL Filter Bypass Leads to Remote Code Execution (RCE)",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32422
      },
      "nvd": {
        "published": "2026-07-07T21:17:26.857",
        "lastModified": "2026-07-08T15:07:37.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53751",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "H2 JDBC applies Unicode validation and SQL parsing to different character interpretations, allowing input accepted by the validator to change query syntax in the parser.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-xjhm-r8p8-c2cg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/2204258118eac6160a6636ca20dbedb0d3f95747",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-10T17:48:40.547Z",
      "date_published": "2026-07-06T19:35:39.800Z",
      "date_updated": "2026-07-07T14:10:54.311Z",
      "publisher": "GitHub_M",
      "title": "OP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks authentication guarantee",
      "affected": {
        "vendors": [
          "OP-TEE"
        ],
        "products": [
          {
            "vendor": "OP-TEE",
            "product": "optee_os"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04629
      },
      "nvd": {
        "published": "2026-07-06T20:16:37.327",
        "lastModified": "2026-07-07T18:53:34.977",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53763",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "AES-GCM stores processed payload and AAD lengths in 32-bit counters, so inputs above 512 MiB wrap the bit length used to compute the authentication tag.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OP-TEE/optee_os/security/advisories/GHSA-fcm8-vjhf-6vqh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 519,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T01:11:27.545Z",
      "date_published": "2026-07-07T14:10:04.025Z",
      "date_updated": "2026-07-07T14:59:07.106Z",
      "publisher": "DSF",
      "title": "Heap buffer over-read in GDALRaster",
      "affected": {
        "vendors": [
          "djangoproject"
        ],
        "products": [
          {
            "vendor": "djangoproject",
            "product": "Django"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-805",
          "name": "Buffer Access with Incorrect Length Value",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20315
      },
      "nvd": {
        "published": "2026-07-07T15:16:48.453",
        "lastModified": "2026-07-09T12:59:39.403",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53877",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Django reads beyond a valid memory object because an input length or pointer is not validated against the available buffer.",
        "basis": [
          "CNA",
          "CWE-805"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.djangoproject.com/en/dev/releases/security/",
          "host": "docs.djangoproject.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://groups.google.com/g/django-announce",
          "host": "groups.google.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "mailing-list"
          ]
        },
        {
          "url": "https://www.djangoproject.com/weblog/2026/jul/07/security-releases/",
          "host": "www.djangoproject.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-53878",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T01:11:27.546Z",
      "date_published": "2026-07-07T14:10:29.935Z",
      "date_updated": "2026-07-07T14:58:18.415Z",
      "publisher": "DSF",
      "title": "Header injection possibility since DomainNameValidator accepted newlines in input",
      "affected": {
        "vendors": [
          "djangoproject"
        ],
        "products": [
          {
            "vendor": "djangoproject",
            "product": "Django"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-144",
          "name": "Improper Neutralization of Line Delimiters",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10837
      },
      "nvd": {
        "published": "2026-07-07T15:16:48.583",
        "lastModified": "2026-07-09T12:58:17.183",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53878",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DomainNameValidator accepts newline characters that an application can later reinterpret as additional HTTP header fields.",
        "basis": [
          "CNA",
          "CWE-144"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.djangoproject.com/en/dev/releases/security/",
          "host": "docs.djangoproject.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://groups.google.com/g/django-announce",
          "host": "groups.google.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "mailing-list"
          ]
        },
        {
          "url": "https://www.djangoproject.com/weblog/2026/jul/07/security-releases/",
          "host": "www.djangoproject.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 563,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-53902",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T07:44:52.179Z",
      "date_published": "2026-07-01T11:58:31.205Z",
      "date_updated": "2026-07-01T13:42:53.914Z",
      "publisher": "CERT-PL",
      "title": "Privilege Escalation in MCO",
      "affected": {
        "vendors": [
          "MyComplianceOffice"
        ],
        "products": [
          {
            "vendor": "MyComplianceOffice",
            "product": "MCO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11113
      },
      "nvd": {
        "published": "2026-07-01T13:17:45.237",
        "lastModified": "2026-07-06T17:39:04.233",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53902",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The group-membership endpoint accepts a group ID without verifying that the authenticated user may add themselves to that group.",
        "basis": [
          "CNA",
          "CWE-266",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53902",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://mco.mycomplianceoffice.com/",
          "host": "mco.mycomplianceoffice.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 700,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53903",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T07:44:52.179Z",
      "date_published": "2026-07-01T11:58:36.922Z",
      "date_updated": "2026-07-01T13:42:31.836Z",
      "publisher": "CERT-PL",
      "title": "Insecure Direct Object Reference in MCO",
      "affected": {
        "vendors": [
          "MyComplianceOffice"
        ],
        "products": [
          {
            "vendor": "MyComplianceOffice",
            "product": "MCO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 2.8,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15658
      },
      "nvd": {
        "published": "2026-07-01T13:17:45.373",
        "lastModified": "2026-07-06T17:33:20.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53903",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PDF statement endpoint retrieves a trading document by caller-supplied ID without verifying that the authenticated user owns or may read that document.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53902",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://mco.mycomplianceoffice.com/",
          "host": "mco.mycomplianceoffice.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 760,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53904",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T07:44:52.179Z",
      "date_published": "2026-07-01T11:58:42.805Z",
      "date_updated": "2026-07-01T13:41:19.482Z",
      "publisher": "CERT-PL",
      "title": "Account Denial of Service in MCO",
      "affected": {
        "vendors": [
          "MyComplianceOffice"
        ],
        "products": [
          {
            "vendor": "MyComplianceOffice",
            "product": "MCO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10516
      },
      "nvd": {
        "published": "2026-07-01T13:17:45.490",
        "lastModified": "2026-07-06T14:33:41.370",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53904",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Each unlimited password-reset request invalidates the current password and prior temporary passwords, so repeated resets keep the victim locked out.",
        "basis": [
          "CNA",
          "CWE-307",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53902",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://mco.mycomplianceoffice.com/",
          "host": "mco.mycomplianceoffice.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 752,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53905",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T07:44:52.179Z",
      "date_published": "2026-07-01T11:58:49.816Z",
      "date_updated": "2026-07-01T13:40:58.674Z",
      "publisher": "CERT-PL",
      "title": "Unauthorized Access to Administrator ACL View in MCO",
      "affected": {
        "vendors": [
          "MyComplianceOffice"
        ],
        "products": [
          {
            "vendor": "MyComplianceOffice",
            "product": "MCO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.7999999999999998,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09234
      },
      "nvd": {
        "published": "2026-07-01T13:17:45.607",
        "lastModified": "2026-07-06T14:28:47.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53905",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The admin-view-hierarchy endpoint returns administrator ACL structures to a low-privileged user without the required permission check.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53902",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://mco.mycomplianceoffice.com/",
          "host": "mco.mycomplianceoffice.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53906",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T07:44:52.179Z",
      "date_published": "2026-07-01T11:58:55.138Z",
      "date_updated": "2026-07-01T13:39:18.244Z",
      "publisher": "CERT-PL",
      "title": "Path Disclosure and Path Traversal in MCO",
      "affected": {
        "vendors": [
          "MyComplianceOffice"
        ],
        "products": [
          {
            "vendor": "MyComplianceOffice",
            "product": "MCO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 3.0999999999999996,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26604
      },
      "nvd": {
        "published": "2026-07-01T13:17:45.717",
        "lastModified": "2026-07-06T14:22:34.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53906",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload filename can escape the intended directory and select an arbitrary write location, while error responses also disclose absolute server paths.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53902",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://mco.mycomplianceoffice.com/",
          "host": "mco.mycomplianceoffice.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53907",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T07:44:52.179Z",
      "date_published": "2026-07-01T11:58:59.627Z",
      "date_updated": "2026-07-01T13:38:34.349Z",
      "publisher": "CERT-PL",
      "title": "Stored Cross‑Site Scripting in MCO",
      "affected": {
        "vendors": [
          "MyComplianceOffice"
        ],
        "products": [
          {
            "vendor": "MyComplianceOffice",
            "product": "MCO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03841
      },
      "nvd": {
        "published": "2026-07-01T13:17:45.830",
        "lastModified": "2026-07-06T14:07:41.883",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53907",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MCO places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53902",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://mco.mycomplianceoffice.com/",
          "host": "mco.mycomplianceoffice.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 432,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53908",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T07:44:52.179Z",
      "date_published": "2026-07-01T11:59:15.246Z",
      "date_updated": "2026-07-01T13:38:09.459Z",
      "publisher": "CERT-PL",
      "title": "User Enumeration in MCO",
      "affected": {
        "vendors": [
          "MyComplianceOffice"
        ],
        "products": [
          {
            "vendor": "MyComplianceOffice",
            "product": "MCO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-204",
          "name": "Observable Response Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 2.6000000000000005,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11452
      },
      "nvd": {
        "published": "2026-07-01T13:17:45.967",
        "lastModified": "2026-07-06T13:58:40.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53908",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Username-reminder and password-reset responses differ for existing and nonexistent identities, creating a user-enumeration oracle.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-204"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53902",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://mco.mycomplianceoffice.com/",
          "host": "mco.mycomplianceoffice.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 462,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53909",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T07:44:52.179Z",
      "date_published": "2026-07-01T11:59:26.104Z",
      "date_updated": "2026-07-01T13:37:13.787Z",
      "publisher": "CERT-PL",
      "title": "Arbitrary File Upload in MCO",
      "affected": {
        "vendors": [
          "MyComplianceOffice"
        ],
        "products": [
          {
            "vendor": "MyComplianceOffice",
            "product": "MCO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13518
      },
      "nvd": {
        "published": "2026-07-01T13:17:46.080",
        "lastModified": "2026-07-06T13:47:37.867",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53909",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MCO enforces upload type restrictions only in client-side code, so a direct request can store an arbitrary file type.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53902",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://mco.mycomplianceoffice.com/",
          "host": "mco.mycomplianceoffice.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 393,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53910",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T07:44:52.179Z",
      "date_published": "2026-07-22T13:42:50.539Z",
      "date_updated": "2026-07-27T10:58:52.287Z",
      "publisher": "CERT-PL",
      "title": "Heap-based Buffer Overflow in GNU diffutils",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "diffutils"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16709
      },
      "nvd": {
        "published": "2026-07-22T14:17:21.030",
        "lastModified": "2026-07-27T12:16:45.250",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53910",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Signed line-mapping arithmetic overflows in diff3, producing undersized allocations and out-of-bounds writes.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-53910",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/diffutils.git/",
          "host": "git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 987,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53913",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T10:24:16.144Z",
      "date_published": "2026-07-06T08:12:32.594Z",
      "date_updated": "2026-07-07T12:36:54.235Z",
      "publisher": "apache",
      "title": "Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is accepted",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel Keycloak"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-636",
          "name": "Not Failing Securely ('Failing Open')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00746,
        "percentile": 0.51273
      },
      "nvd": {
        "published": "2026-07-06T09:16:38.753",
        "lastModified": "2026-07-09T03:03:58.543",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53913",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KeycloakSecurityPolicy performs bearer-token cryptographic verification only inside optional role or permission checks that are skipped by default.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306",
          "CWE-636"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-53913.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2580,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-53935",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T15:46:12.317Z",
      "date_published": "2026-07-07T20:44:54.972Z",
      "date_updated": "2026-07-08T13:18:09.946Z",
      "publisher": "GitHub_M",
      "title": "CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation",
      "affected": {
        "vendors": [
          "cilium"
        ],
        "products": [
          {
            "vendor": "cilium",
            "product": "cilium"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11418
      },
      "nvd": {
        "published": "2026-07-07T21:17:27.000",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53935",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cilium lets a namespace-scoped LocalRedirectPolicy claim traffic for services outside that namespace's intended authority.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cilium/cilium/security/advisories/GHSA-q6h5-q3q6-f87x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/pull/45412",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/pull/45584",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/pull/45585",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/commit/81d446395673dc2c684c047c12715caffac1a351",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/commit/92ca32eda85aa0c7611c28221cc26fa08be17ebc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/commit/fe7eb53c7aac9fa7ec610b1975d73fbbb198c66d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-53951",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T15:50:01.281Z",
      "date_published": "2026-07-08T15:26:08.626Z",
      "date_updated": "2026-07-09T13:47:38.033Z",
      "publisher": "GitHub_M",
      "title": "Copier: trust-prefix bypass via path traversal runs tasks unprompted",
      "affected": {
        "vendors": [
          "copier-org"
        ],
        "products": [
          {
            "vendor": "copier-org",
            "product": "copier"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.0877
      },
      "nvd": {
        "published": "2026-07-08T16:16:30.623",
        "lastModified": "2026-07-10T19:06:45.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53951",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A template reference that textually starts with a trusted prefix but contains `..` is therefore granted trust yet resolves to a different, attacker-controlled template, whose `tasks` / `migrations` / `jinja_extensions` then run without the `--trust` prompt — arbitrary command execution.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/copier-org/copier/security/advisories/GHSA-9gmc-jqmh-3rvm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/copier-org/copier/releases/tag/v9.15.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 728,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53961",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T15:50:01.282Z",
      "date_published": "2026-07-09T21:48:11.449Z",
      "date_updated": "2026-07-10T13:44:30.447Z",
      "publisher": "GitHub_M",
      "title": "Discourse: Forged AWS SNS bounce notifications can disable a targeted user's email (missing TopicArn binding)",
      "affected": {
        "vendors": [
          "discourse"
        ],
        "products": [
          {
            "vendor": "discourse",
            "product": "discourse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14158
      },
      "nvd": {
        "published": "2026-07-09T22:17:05.440",
        "lastModified": "2026-07-14T20:37:07.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53961",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages were signed by Amazon but did not bind them to trusted TopicArn values, allowing any AWS account holder to publish validly signed forged Bounce notifications that revoke a targeted user email.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/discourse/discourse/security/advisories/GHSA-8f9m-v436-wr3x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/3a3d315a85ef3c6aabfc7e7bb38702059784f06b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/61f12e13aa1b760f81d5ff60f12e3a7e77434b94",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/958f0cd831d65a49ec75f05343ca2c167679f0ea",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/aea35190791261bab258ebab05da279e78cdd0e6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 446,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-53962",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T15:50:01.282Z",
      "date_published": "2026-07-09T22:02:27.430Z",
      "date_updated": "2026-07-10T20:31:50.782Z",
      "publisher": "GitHub_M",
      "title": "Discourse: Insufficient SVG sanitization logic",
      "affected": {
        "vendors": [
          "discourse"
        ],
        "products": [
          {
            "vendor": "discourse",
            "product": "discourse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22174
      },
      "nvd": {
        "published": "2026-07-09T22:17:05.600",
        "lastModified": "2026-07-14T01:35:33.597",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53962",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/discourse/discourse/security/advisories/GHSA-jmcf-3367-78vv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/3ee8343cd7f00d59d8513bee0a12e02d50bfc358",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/810c2715799fd08b06fd6ffc664d9562fe9ea6ff",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/92a699d89b84685b6fdd63cd0d0e371793c69dad",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/b8ceb49f4ba52257be30eb3c2ce51a5bf03be5fe",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 361,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-53963",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T15:50:01.282Z",
      "date_published": "2026-07-09T22:05:46.329Z",
      "date_updated": "2026-07-14T01:19:05.114Z",
      "publisher": "GitHub_M",
      "title": "Discourse: Stored-XSS in 2FA delete confirmation modal",
      "affected": {
        "vendors": [
          "discourse"
        ],
        "products": [
          {
            "vendor": "discourse",
            "product": "discourse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.7000000000000002,
      "epss": {
        "score": 0.00498,
        "percentile": 0.40004
      },
      "nvd": {
        "published": "2026-07-09T22:17:05.763",
        "lastModified": "2026-07-14T02:16:55.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53963",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/discourse/discourse/security/advisories/GHSA-wg5x-7f23-m3r5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/40de62cddadc65c328a1028ab999f3fa94adbfed",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/529e17d4d570a48972e7cf64720e5dd1fdf23ca8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/d92973e51a46cf6dd20c71e6068e6769b67eea5b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/daea5214d833eacbdd3b1a78d99eb14e9cabd915",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 379,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-53987",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T16:07:13.001Z",
      "date_published": "2026-07-09T15:44:04.474Z",
      "date_updated": "2026-07-20T17:45:50.981Z",
      "publisher": "VulnCheck",
      "title": "GLPI 11 before 2.14.4 Tag Plugin Stored Cross-Site Scripting in Kanban Badge Rendering",
      "affected": {
        "vendors": [
          "Tag plugin"
        ],
        "products": [
          {
            "vendor": "Tag plugin",
            "product": "GLPI 11"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00341,
        "percentile": 0.26736
      },
      "nvd": {
        "published": "2026-07-09T17:17:01.277",
        "lastModified": "2026-07-20T18:16:53.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-53987",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pluginsGLPI/tag/security/advisories/GHSA-6rpj-89c7-x2mh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/pluginsGLPI/tag/releases/tag/2.14.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/pluginsGLPI/tag",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/pluginsGLPI/tag/commit/49e6b6eb5f83bcd84139a5e5ec54c0ddd14acc90",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/glpi-tag-plugin-stored-cross-site-scripting-in-kanban-badge-rendering",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 474,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-53994",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T16:07:13.001Z",
      "date_published": "2026-07-18T19:30:32.740Z",
      "date_updated": "2026-07-28T01:49:40.378Z",
      "publisher": "VulnCheck",
      "title": "ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size Truncation",
      "affected": {
        "vendors": [
          "ProFTPD Project"
        ],
        "products": [
          {
            "vendor": "ProFTPD Project",
            "product": "ProFTPD"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00424,
        "percentile": 0.34925
      },
      "nvd": {
        "published": "2026-07-18T20:17:30.283",
        "lastModified": "2026-07-30T18:00:47.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-53994",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A zero SFTP packet length underflows an unsigned size, truncates a roughly 4 GB allocation request to a small block, and then streams attacker bytes beyond it.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/proftpd/proftpd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://github.com/proftpd/proftpd/commit/7342836fa98e36209660a4c5805c801476f63936",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/proftpd-mod-sftp-heap-buffer-overflow-via-unsigned-integer-underflow-and-size-truncation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1242,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54000",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T16:34:11.635Z",
      "date_published": "2026-07-10T14:51:35.142Z",
      "date_updated": "2026-07-14T03:55:44.196Z",
      "publisher": "GitHub_M",
      "title": "osquery: Heap buffer overflow in `getProcessCurrentDirectory()` via `processes` table (Windows)",
      "affected": {
        "vendors": [
          "osquery"
        ],
        "products": [
          {
            "vendor": "osquery",
            "product": "osquery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00108,
        "percentile": 0.01371
      },
      "nvd": {
        "published": "2026-07-10T16:16:32.340",
        "lastModified": "2026-07-14T05:16:18.207",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54000",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unchecked PEB string lengths make process-directory collection write beyond a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/osquery/osquery/security/advisories/GHSA-4r78-6hg6-33gg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/osquery/osquery/pull/8934",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/osquery/osquery/commit/3d457c412eb0c986b0c37d8903edae8bc9f9e246",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/osquery/osquery/releases/tag/5.23.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 523,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54001",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T16:34:11.635Z",
      "date_published": "2026-07-10T14:49:18.318Z",
      "date_updated": "2026-07-14T03:55:44.942Z",
      "publisher": "GitHub_M",
      "title": "osquery: Heap buffer overflow via `authenticode` table (Windows)",
      "affected": {
        "vendors": [
          "osquery"
        ],
        "products": [
          {
            "vendor": "osquery",
            "product": "osquery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00108,
        "percentile": 0.0137
      },
      "nvd": {
        "published": "2026-07-10T16:16:32.467",
        "lastModified": "2026-07-14T05:16:18.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54001",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can write beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/osquery/osquery/security/advisories/GHSA-hr28-jvpx-68cx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/osquery/osquery/pull/8923",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/osquery/osquery/commit/59a808cda96d5a089cf6ec147efe152459284d54",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/osquery/osquery/releases/tag/5.23.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54002",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T16:34:11.635Z",
      "date_published": "2026-07-09T18:34:29.041Z",
      "date_updated": "2026-07-09T19:26:59.702Z",
      "publisher": "GitHub_M",
      "title": "Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-87",
          "name": "Improper Neutralization of Alternate XSS Syntax",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00409,
        "percentile": 0.3367
      },
      "nvd": {
        "published": "2026-07-09T19:17:05.977",
        "lastModified": "2026-07-10T15:49:19.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54002",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dom::sanitize leaves executable child markup beneath unknown HTML or XML elements unsanitized.",
        "basis": [
          "CNA record",
          "CWE-79",
          "CWE-87"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-wr9h-4r83-f4v6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/0f0437b5128c910103cbc78fc34d94b2a3faef4c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/7ad76cf9c7387462828e6ebfc8404e31b37829e9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/9ec1873864441dbc06479ef7823da348ec7f2700",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/bb2562e16c754493a403b8df84c9883108871e4c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/4.9.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 545,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54003",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T16:34:11.635Z",
      "date_published": "2026-07-09T18:36:43.667Z",
      "date_updated": "2026-07-09T19:23:24.078Z",
      "publisher": "GitHub_M",
      "title": "Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-454",
          "name": "External Initialization of Trusted Variables or Data Stores",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00545,
        "percentile": 0.42661
      },
      "nvd": {
        "published": "2026-07-09T19:17:06.120",
        "lastModified": "2026-07-10T15:49:19.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54003",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "kirby initializes a trusted local-origin decision from attacker-controlled proxy headers.",
        "basis": [
          "CNA",
          "CWE-454"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-whxw-24jc-cwmv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/pull/8166",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/1c7fee90e49153cf9ca4a6ec17481d25fbedc48d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/3423f66c01dbc0455862e23ee699d2aa469f3234",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/66a3a14bf0892d320723ba766cd5f1d33a51d15b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/ab992dc149610b90e337c2955ab6ccb7f72ffb3a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/4.9.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54004",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T16:34:11.635Z",
      "date_published": "2026-07-09T18:42:00.680Z",
      "date_updated": "2026-07-09T19:48:01.785Z",
      "publisher": "GitHub_M",
      "title": "Kirby: Access to files of top-level drafts is not protected by permissions",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23616
      },
      "nvd": {
        "published": "2026-07-09T19:17:06.270",
        "lastModified": "2026-07-10T15:49:19.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54004",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The clean-file redirect exposes media from top-level draft pages without checking page access permission or a preview token.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-89cp-7p28-jffg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/5b9a0ed587575e39156d37fa42ca7f6c73e121f7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/bc721080cd8dd4dcb7fc20b3fd0460ee8d0603b0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/4.9.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54005",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T16:34:11.635Z",
      "date_published": "2026-07-09T18:47:02.487Z",
      "date_updated": "2026-07-14T01:14:10.573Z",
      "publisher": "GitHub_M",
      "title": "Kirby: `pages.access` permission is not checked in the `site/find` REST API route",
      "affected": {
        "vendors": [
          "getkirby"
        ],
        "products": [
          {
            "vendor": "getkirby",
            "product": "kirby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18849
      },
      "nvd": {
        "published": "2026-07-09T19:17:06.400",
        "lastModified": "2026-07-14T02:16:55.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54005",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kirby's site/find route returns arbitrary published-page content without applying the role's pages.access permission.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getkirby/kirby/security/advisories/GHSA-r3w8-2c5r-h9j9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/a16dbd4329293c2c4b9a375d2badcb27c6337004",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/commit/b22d0b64b6478ce6871dc7ec3368d7afaf078688",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/4.9.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getkirby/kirby/releases/tag/5.4.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54051",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:24:35.096Z",
      "date_published": "2026-07-20T16:24:20.791Z",
      "date_updated": "2026-07-21T16:03:01.029Z",
      "publisher": "GitHub_M",
      "title": "Network-AI has an an OS Command Injection issue",
      "affected": {
        "vendors": [
          "Jovancoding"
        ],
        "products": [
          {
            "vendor": "Jovancoding",
            "product": "Network-AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29762
      },
      "nvd": {
        "published": "2026-07-20T17:17:57.643",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54051",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text reaches an operating-system command boundary without shell-safe argument separation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-qw6v-5fcf-5666",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/commit/379f77656b578144e03415c5b134d8309a4b5792",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1142,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54052",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:24:35.096Z",
      "date_published": "2026-07-15T20:34:10.748Z",
      "date_updated": "2026-07-18T02:18:02.757Z",
      "publisher": "GitHub_M",
      "title": "n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments",
      "affected": {
        "vendors": [
          "czlonkowski"
        ],
        "products": [
          {
            "vendor": "czlonkowski",
            "product": "n8n-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13685
      },
      "nvd": {
        "published": "2026-07-15T21:16:54.797",
        "lastModified": "2026-07-18T03:16:37.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54052",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Workflow version backups share a tenant-independent namespace, allowing one authenticated tenant to read or delete another tenant's snapshots.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/czlonkowski/n8n-mcp/security/advisories/GHSA-j6r7-6fhx-77wx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/czlonkowski/n8n-mcp/releases/tag/v2.56.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 554,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54058",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:24:35.096Z",
      "date_published": "2026-07-14T16:27:38.050Z",
      "date_updated": "2026-07-14T17:54:25.654Z",
      "publisher": "GitHub_M",
      "title": "Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31163
      },
      "nvd": {
        "published": "2026-07-14T17:17:03.433",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54058",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Pillow path reads beyond the validated extent of an attacker-influenced buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9719",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90b3cfc1d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 435,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54059",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:24:35.096Z",
      "date_published": "2026-07-06T18:46:09.433Z",
      "date_updated": "2026-07-07T16:57:53.021Z",
      "publisher": "GitHub_M",
      "title": "Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33678
      },
      "nvd": {
        "published": "2026-07-06T19:17:08.127",
        "lastModified": "2026-07-07T18:58:26.730",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54059",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted PCF dimensions bypass the decompression-size check and force excessive allocation or work.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 343,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54060",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:24:35.096Z",
      "date_published": "2026-07-06T18:49:23.788Z",
      "date_updated": "2026-07-07T14:08:14.588Z",
      "publisher": "GitHub_M",
      "title": "Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34419
      },
      "nvd": {
        "published": "2026-07-06T19:17:08.270",
        "lastModified": "2026-07-07T18:58:45.827",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54060",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Pillow conversion path allocates memory from an attacker-controlled size without enforcing a safe upper bound.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 340,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54061",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:24:35.096Z",
      "date_published": "2026-07-08T13:23:56.884Z",
      "date_updated": "2026-07-08T14:26:13.341Z",
      "publisher": "GitHub_M",
      "title": "Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import",
      "affected": {
        "vendors": [
          "dgraph-io"
        ],
        "products": [
          {
            "vendor": "dgraph-io",
            "product": "dgraph"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31534
      },
      "nvd": {
        "published": "2026-07-08T14:17:06.520",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54061",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dgraph exposes external snapshot RPCs on the public gRPC port without authentication, and Prepare deletes the existing database before stream validation completes.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dgraph-io/dgraph/security/advisories/GHSA-rrwh-6jrq-wp5v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dgraph-io/dgraph/releases/tag/v25.3.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54063",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:24:35.097Z",
      "date_published": "2026-07-10T15:53:31.020Z",
      "date_updated": "2026-07-10T18:39:48.791Z",
      "publisher": "GitHub_M",
      "title": "Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)",
      "affected": {
        "vendors": [
          "qax-os"
        ],
        "products": [
          {
            "vendor": "qax-os",
            "product": "excelize"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31533
      },
      "nvd": {
        "published": "2026-07-10T17:16:58.440",
        "lastModified": "2026-07-16T14:11:27.260",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54063",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 2.11.0, the checkSheet() function in github.com/xuri/excelize/v2 uses an attacker-controlled <row r=\"N\"> XML attribute value directly as the length argument to make([]xlsxRow, row) without validating it against the Excel row limit (TotalRows = 1,048,576).",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/qax-os/excelize/security/advisories/GHSA-h69g-9hx6-f3v4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/qax-os/excelize/releases/tag/v2.11.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 740,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54074",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:44:47.759Z",
      "date_published": "2026-07-01T20:47:22.796Z",
      "date_updated": "2026-07-02T15:35:56.343Z",
      "publisher": "GitHub_M",
      "title": "@tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels",
      "affected": {
        "vendors": [
          "tinacms"
        ],
        "products": [
          {
            "vendor": "tinacms",
            "product": "tinacms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06684
      },
      "nvd": {
        "published": "2026-07-01T21:17:03.227",
        "lastModified": "2026-07-02T17:45:00.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54074",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tina unquotes an internal marker inside unsanitized YAML labels and emits the result as executable JavaScript in a generated template.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-4936-9hrh-qqpw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 774,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54078",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:44:47.760Z",
      "date_published": "2026-07-29T15:11:05.239Z",
      "date_updated": "2026-07-29T18:02:18.227Z",
      "publisher": "GitHub_M",
      "title": "veraPDF Validation XXE via Rich Text",
      "affected": {
        "vendors": [
          "veraPDF"
        ],
        "products": [
          {
            "vendor": "veraPDF",
            "product": "veraPDF-validation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24385
      },
      "nvd": {
        "published": "2026-07-29T16:17:53.053",
        "lastModified": "2026-07-30T19:23:14.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54078",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DictionaryKeysHelper parses attacker-controlled PDF rich-text entries with external entities enabled and returns resolved local-file content in validation output.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/veraPDF/veraPDF-validation/security/advisories/GHSA-3jh7-wm29-q568",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-validation/pull/730",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-validation/commit/cacd9436d0de40b0e58cc7d2dbb06451619e61ec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 550,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54079",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:44:47.760Z",
      "date_published": "2026-07-29T15:07:23.558Z",
      "date_updated": "2026-07-29T15:44:57.528Z",
      "publisher": "GitHub_M",
      "title": "veraPDF Validation XXE via XFA",
      "affected": {
        "vendors": [
          "veraPDF"
        ],
        "products": [
          {
            "vendor": "veraPDF",
            "product": "veraPDF-validation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24385
      },
      "nvd": {
        "published": "2026-07-29T16:17:53.203",
        "lastModified": "2026-07-30T19:23:14.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54079",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "veraPDF parses attacker-controlled XML with external-entity resolution enabled, allowing the document to read local or remote resources.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/veraPDF/veraPDF-validation/security/advisories/GHSA-36mm-w85j-3q2j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-validation/pull/730",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-validation/commit/cacd9436d0de40b0e58cc7d2dbb06451619e61ec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54080",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:44:47.760Z",
      "date_published": "2026-07-29T15:17:12.153Z",
      "date_updated": "2026-07-29T15:48:33.678Z",
      "publisher": "GitHub_M",
      "title": "veraPDF Parser DoS via PostScript CMap Streams",
      "affected": {
        "vendors": [
          "veraPDF"
        ],
        "products": [
          {
            "vendor": "veraPDF",
            "product": "veraPDF-parser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1325",
          "name": "Improperly Controlled Sequential Memory Allocation",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22468
      },
      "nvd": {
        "published": "2026-07-29T16:17:53.347",
        "lastModified": "2026-07-30T19:23:14.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54080",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted PDF CMap programs can request unbounded PostScript array allocation or enter a zero-increment loop during parsing.",
        "basis": [
          "CNA",
          "CWE-1325"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/veraPDF/veraPDF-parser/security/advisories/GHSA-jrmc-qg6p-94fp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-parser/pull/703",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-parser/commit/73d6ec002b98ce1f3f68640442f8e5d5613c80ce",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-parser/commit/cb3538607a549d63504299be1088c85ae48605f4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 519,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:44:47.760Z",
      "date_published": "2026-07-29T15:18:52.076Z",
      "date_updated": "2026-07-30T15:19:44.182Z",
      "publisher": "GitHub_M",
      "title": "veraPDF Parser DoS via PostScript Type 1 Font Programs",
      "affected": {
        "vendors": [
          "veraPDF"
        ],
        "products": [
          {
            "vendor": "veraPDF",
            "product": "veraPDF-parser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1325",
          "name": "Improperly Controlled Sequential Memory Allocation",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22469
      },
      "nvd": {
        "published": "2026-07-29T16:17:53.493",
        "lastModified": "2026-07-30T19:23:14.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54081",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Type 1 font interpreter permits unbounded PostScript allocation, zero-increment loops, and recursive dictionary execution.",
        "basis": [
          "CNA",
          "CWE-1325"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/veraPDF/veraPDF-parser/security/advisories/GHSA-7c26-995w-6f47",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-parser/pull/703",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-parser/commit/73d6ec002b98ce1f3f68640442f8e5d5613c80ce",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-parser/commit/cb3538607a549d63504299be1088c85ae48605f4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T18:44:47.760Z",
      "date_published": "2026-07-29T15:14:19.998Z",
      "date_updated": "2026-07-30T13:52:07.526Z",
      "publisher": "GitHub_M",
      "title": "veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs",
      "affected": {
        "vendors": [
          "veraPDF"
        ],
        "products": [
          {
            "vendor": "veraPDF",
            "product": "veraPDF-validation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13955
      },
      "nvd": {
        "published": "2026-07-29T16:17:53.630",
        "lastModified": "2026-07-30T19:23:14.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54082",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "veraPDF parses attacker-controlled PDF XML with the default DocumentBuilderFactory and permits external entity resolution.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/veraPDF/veraPDF-validation/security/advisories/GHSA-cg9x-g3gm-h5h6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-validation/pull/730",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/veraPDF/veraPDF-validation/commit/cacd9436d0de40b0e58cc7d2dbb06451619e61ec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 496,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54107",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.834Z",
      "date_published": "2026-07-14T17:04:47.582Z",
      "date_updated": "2026-08-03T22:53:11.794Z",
      "publisher": "microsoft",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.8000000000000007,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05047
      },
      "nvd": {
        "published": "2026-07-14T17:17:03.570",
        "lastModified": "2026-07-15T18:19:35.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54107",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Concurrent Win32K operations access a shared resource without sufficient synchronization, but Microsoft does not disclose the resource or interleaving.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54107",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-54108",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.835Z",
      "date_published": "2026-07-14T17:05:07.770Z",
      "date_updated": "2026-08-03T22:53:28.084Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00775,
        "percentile": 0.52237
      },
      "nvd": {
        "published": "2026-07-14T17:17:03.737",
        "lastModified": "2026-07-15T15:12:42.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54108",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An authenticated SharePoint caller controls a file name or path beyond the intended namespace, although the affected operation is not public.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54108",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54109",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.835Z",
      "date_published": "2026-07-14T17:04:51.569Z",
      "date_updated": "2026-08-03T22:53:15.634Z",
      "publisher": "microsoft",
      "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15135
      },
      "nvd": {
        "published": "2026-07-14T17:17:03.853",
        "lastModified": "2026-07-22T16:18:13.213",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54109",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 path writes attacker-influenced data beyond an allocated heap buffer.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54109",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 125,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-54111",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.835Z",
      "date_published": "2026-07-14T17:04:45.930Z",
      "date_updated": "2026-08-03T22:53:10.058Z",
      "publisher": "microsoft",
      "title": "Universal Print Management Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04945
      },
      "nvd": {
        "published": "2026-07-14T17:17:04.003",
        "lastModified": "2026-07-22T16:18:13.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54111",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The USB print driver uses shared state concurrently without synchronization, allowing a privilege-sensitive race.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54111",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-54112",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.835Z",
      "date_published": "2026-07-14T17:04:49.885Z",
      "date_updated": "2026-08-03T22:53:13.901Z",
      "publisher": "microsoft",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04945
      },
      "nvd": {
        "published": "2026-07-14T17:17:04.123",
        "lastModified": "2026-07-15T17:57:39.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54112",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A protected object can change between the check and use steps in Windows 10 Version 1809, invalidating the state assumed by the later operation.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54112",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-54114",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.835Z",
      "date_published": "2026-07-14T17:04:52.895Z",
      "date_updated": "2026-08-03T22:53:16.737Z",
      "publisher": "microsoft",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01921,
        "percentile": 0.77901
      },
      "nvd": {
        "published": "2026-07-14T17:17:04.267",
        "lastModified": "2026-07-22T16:18:13.593",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54114",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1809 retains or reuses an object after its storage has been freed, allowing later processing to access invalid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54114",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-54115",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.835Z",
      "date_published": "2026-07-14T17:08:17.726Z",
      "date_updated": "2026-08-03T22:56:36.722Z",
      "publisher": "microsoft",
      "title": "Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23435
      },
      "nvd": {
        "published": "2026-07-14T18:18:07.537",
        "lastModified": "2026-07-21T19:54:45.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54115",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer arithmetic in the affected Windows path can wrap and drive a heap operation with an invalid size.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54115",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-54116",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.835Z",
      "date_published": "2026-07-14T17:09:08.631Z",
      "date_updated": "2026-08-03T22:57:28.513Z",
      "publisher": "microsoft",
      "title": "Microsoft SQL Server Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 (CU 6)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 for x64-based Systems (GDR)"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00953,
        "percentile": 0.57905
      },
      "nvd": {
        "published": "2026-07-14T18:18:07.707",
        "lastModified": "2026-07-22T16:53:37.833",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54116",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft SQL Server 2025 (CU 6) accesses a resource through an incompatible type, allowing memory to be interpreted outside its valid representation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54116",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 145,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54117",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.835Z",
      "date_published": "2026-07-14T17:05:04.964Z",
      "date_updated": "2026-08-03T22:53:25.472Z",
      "publisher": "microsoft",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 (CU 6)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 for x64-based Systems (GDR)"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01288,
        "percentile": 0.67369
      },
      "nvd": {
        "published": "2026-07-14T17:17:04.407",
        "lastModified": "2026-07-22T16:51:31.820",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54117",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SQL Server deserializes network data supplied by an authorized attacker into executable object behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54117",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54118",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.835Z",
      "date_published": "2026-07-14T17:05:05.500Z",
      "date_updated": "2026-08-03T22:53:25.941Z",
      "publisher": "microsoft",
      "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2016 Service Pack 3 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2019 (CU 32)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2019 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2022 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2022 for x64-based Systems (CU 25)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 (CU 6)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 for x64-based Systems (GDR)"
          }
        ],
        "affectedBlockCount": 10,
        "versionEntryCount": 10,
        "versionRangeCount": 10,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01288,
        "percentile": 0.67369
      },
      "nvd": {
        "published": "2026-07-14T17:17:04.530",
        "lastModified": "2026-07-22T16:49:32.987",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54118",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SQL Server deserializes untrusted network data supplied by an authorized attacker.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54118",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 10,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-54119",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.836Z",
      "date_published": "2026-07-14T17:04:54.247Z",
      "date_updated": "2026-08-03T22:53:17.924Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00816,
        "percentile": 0.53583
      },
      "nvd": {
        "published": "2026-07-14T17:17:04.660",
        "lastModified": "2026-07-22T16:18:14.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54119",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Active Directory enters a loop whose exit condition is unreachable for a crafted network input.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54119",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-54120",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.836Z",
      "date_published": "2026-07-23T23:55:12.907Z",
      "date_updated": "2026-08-03T22:52:45.424Z",
      "publisher": "microsoft",
      "title": "Microsoft Surface Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Surface Management Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00708,
        "percentile": 0.49945
      },
      "nvd": {
        "published": "2026-07-24T01:17:25.340",
        "lastModified": "2026-07-25T05:16:35.207",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54120",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Microsoft Surface accepts an invalid network input and executes code, while MSRC does not publish the affected parser, field, or memory operation.",
        "basis": [
          "CNA",
          "CWE-20",
          "Microsoft MSRC CVE-2026-54120 page"
        ],
        "deepDive": true,
        "notes": "Inspected https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54120; the official public surface supplies no mechanism beyond improper input validation and network code execution."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54120",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54121",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.836Z",
      "date_published": "2026-07-14T17:08:20.916Z",
      "date_updated": "2026-08-03T22:56:40.255Z",
      "publisher": "microsoft",
      "title": "Active Directory Certificate Services Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01052,
        "percentile": 0.61009
      },
      "nvd": {
        "published": "2026-07-14T18:18:08.057",
        "lastModified": "2026-07-21T19:54:33.623",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54121",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft identifies improper authorization in AD CS but does not disclose the certificate operation, object, or permission check.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-54122",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.836Z",
      "date_published": "2026-07-14T17:04:57.330Z",
      "date_updated": "2026-08-03T22:53:20.575Z",
      "publisher": "microsoft",
      "title": "Windows GDI+ Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20579
      },
      "nvd": {
        "published": "2026-07-14T17:17:04.833",
        "lastModified": "2026-07-16T12:06:17.827",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54122",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected handler writes attacker-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54122",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-54124",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.836Z",
      "date_published": "2026-07-14T17:09:26.995Z",
      "date_updated": "2026-08-03T22:57:47.831Z",
      "publisher": "microsoft",
      "title": "Windows Terminal Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Terminal for Windows 10"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Terminal for Windows 11"
          }
        ],
        "affectedBlockCount": 10,
        "versionEntryCount": 10,
        "versionRangeCount": 10,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00435,
        "percentile": 0.35777
      },
      "nvd": {
        "published": "2026-07-14T18:18:08.373",
        "lastModified": "2026-07-22T16:18:14.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54124",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 21H2 can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54124",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 10,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-54125",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.836Z",
      "date_published": "2026-07-14T17:08:24.727Z",
      "date_updated": "2026-08-03T22:56:44.337Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08201
      },
      "nvd": {
        "published": "2026-07-14T18:18:08.513",
        "lastModified": "2026-07-21T19:56:17.333",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54125",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Windows Runtime performs concurrent operations on a shared resource without sufficient synchronization, creating a use-after-free window.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54125",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-54126",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.837Z",
      "date_published": "2026-07-14T17:08:26.997Z",
      "date_updated": "2026-08-03T22:56:46.593Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00651,
        "percentile": 0.47698
      },
      "nvd": {
        "published": "2026-07-14T18:18:08.657",
        "lastModified": "2026-07-22T16:18:14.687",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54126",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 reads beyond a valid memory object because an input length or pointer is not validated against the available buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54126",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-54127",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.837Z",
      "date_published": "2026-07-14T17:05:14.656Z",
      "date_updated": "2026-08-03T22:53:34.528Z",
      "publisher": "microsoft",
      "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15385
      },
      "nvd": {
        "published": "2026-07-14T17:17:04.993",
        "lastModified": "2026-07-22T16:18:14.873",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54127",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Hyper-V can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54127",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-54128",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.837Z",
      "date_published": "2026-07-14T17:08:26.522Z",
      "date_updated": "2026-08-03T22:56:46.043Z",
      "publisher": "microsoft",
      "title": "Windows DHCP Client Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22362
      },
      "nvd": {
        "published": "2026-07-14T18:18:08.873",
        "lastModified": "2026-07-22T16:18:15.007",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54128",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54128",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-54129",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.837Z",
      "date_published": "2026-07-14T17:04:41.862Z",
      "date_updated": "2026-08-03T22:53:06.193Z",
      "publisher": "microsoft",
      "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11737
      },
      "nvd": {
        "published": "2026-07-14T17:17:05.113",
        "lastModified": "2026-07-22T16:18:15.210",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54129",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Hyper-V dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA record",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54129",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-54131",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.837Z",
      "date_published": "2026-07-14T17:09:09.828Z",
      "date_updated": "2026-08-03T22:57:29.642Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22631
      },
      "nvd": {
        "published": "2026-07-14T18:18:09.123",
        "lastModified": "2026-07-15T19:41:00.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54131",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54131",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-54132",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T20:33:37.837Z",
      "date_published": "2026-07-14T17:04:47.087Z",
      "date_updated": "2026-08-03T22:53:11.311Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22824
      },
      "nvd": {
        "published": "2026-07-14T17:17:05.250",
        "lastModified": "2026-07-22T16:18:15.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54132",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows kernel writes beyond a heap allocation during a physically initiated operation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54132",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-54149",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T21:15:33.871Z",
      "date_published": "2026-07-10T15:05:32.613Z",
      "date_updated": "2026-07-10T16:01:08.445Z",
      "publisher": "GitHub_M",
      "title": "MaxKB MCP tool import validation bypass allows post-authentication remote code execution",
      "affected": {
        "vendors": [
          "1Panel-dev"
        ],
        "products": [
          {
            "vendor": "1Panel-dev",
            "product": "MaxKB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31165
      },
      "nvd": {
        "published": "2026-07-10T16:16:32.587",
        "lastModified": "2026-07-10T19:10:59.333",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54149",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MaxKB import and MCP reference paths permit stdio transport commands to reach MultiServerMCPClient without consistent transport validation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-4pr3-9xhm-98x5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/1Panel-dev/MaxKB/releases/tag/v2.10.0-lts",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 547,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54159",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T21:46:52.380Z",
      "date_published": "2026-07-17T20:39:25.838Z",
      "date_updated": "2026-07-20T13:56:07.400Z",
      "publisher": "GitHub_M",
      "title": "ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE",
      "affected": {
        "vendors": [
          "PrestaShop"
        ],
        "products": [
          {
            "vendor": "PrestaShop",
            "product": "ps_facetedsearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00406,
        "percentile": 0.33395
      },
      "nvd": {
        "published": "2026-07-17T21:17:07.963",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54159",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A URL-controlled filter value is serialized into cache data and later passed to raw PHP unserialize, allowing object-graph execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/PrestaShop/ps_facetedsearch/security/advisories/GHSA-m5f5-28qr-9g9r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/PrestaShop/ps_facetedsearch/commit/9ca839fac68a60641d8187a3ff9730ab09af33cb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PrestaShop/ps_facetedsearch/releases/tag/v4.0.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 770,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54163",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T21:46:52.380Z",
      "date_published": "2026-07-17T20:19:18.186Z",
      "date_updated": "2026-07-20T17:45:49.353Z",
      "publisher": "GitHub_M",
      "title": "secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input",
      "affected": {
        "vendors": [
          "github"
        ],
        "products": [
          {
            "vendor": "github",
            "product": "secure_headers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-113",
          "name": "Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07088
      },
      "nvd": {
        "published": "2026-07-17T21:17:08.107",
        "lastModified": "2026-07-23T18:04:31.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54163",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CSP builders interpolate caller-controlled sandbox, plugin_types, and report_to strings without removing semicolons or line breaks, allowing new directives or headers to be injected.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79",
          "CWE-113"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/github/secure_headers/security/advisories/GHSA-rqq5-2gf9-4w4q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/github/secure_headers/commit/286a79dea80c6a9be4ca93e0f284c923cf77e539",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/github/secure_headers/releases/tag/v7.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 727,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54164",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T21:46:52.380Z",
      "date_published": "2026-07-01T19:14:28.770Z",
      "date_updated": "2026-07-02T15:50:25.125Z",
      "publisher": "GitHub_M",
      "title": "API Platform Core: Missing IRI type check enables resource type confusion",
      "affected": {
        "vendors": [
          "api-platform"
        ],
        "products": [
          {
            "vendor": "api-platform",
            "product": "core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09481
      },
      "nvd": {
        "published": "2026-07-01T20:17:10.657",
        "lastModified": "2026-07-02T17:54:15.243",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54164",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "AbstractItemNormalizer resolves a relation IRI without passing the operation that activates the expected-class guard, allowing a resource of the wrong type to enter a declared relation.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/api-platform/core/security/advisories/GHSA-9rjg-x2p2-h68h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54171",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-11T21:46:52.381Z",
      "date_published": "2026-07-17T20:09:44.716Z",
      "date_updated": "2026-07-20T13:59:42.883Z",
      "publisher": "GitHub_M",
      "title": "Excon: redact additional sensitive/risky headers when following redirects",
      "affected": {
        "vendors": [
          "excon"
        ],
        "products": [
          {
            "vendor": "excon",
            "product": "excon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22713
      },
      "nvd": {
        "published": "2026-07-17T20:17:26.500",
        "lastModified": "2026-07-29T15:20:21.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54171",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A redirect forwards sensitive request headers to the new destination instead of removing credentials at the trust boundary.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/excon/excon/security/advisories/GHSA-48rx-c7pg-q66r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/excon/excon/pull/901",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 412,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54234",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T16:25:43.084Z",
      "date_published": "2026-07-06T19:49:20.481Z",
      "date_updated": "2026-07-07T14:13:34.348Z",
      "publisher": "GitHub_M",
      "title": "vLLM: Remote DoS in vLLM via Invalid Recovered Token Reinjection",
      "affected": {
        "vendors": [
          "vllm-project"
        ],
        "products": [
          {
            "vendor": "vllm-project",
            "product": "vllm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00363,
        "percentile": 0.28963
      },
      "nvd": {
        "published": "2026-07-06T21:16:56.477",
        "lastModified": "2026-07-07T19:04:17.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54234",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A recovered token equal to the vocabulary boundary is converted to minus one and reinjected into drafter input IDs, causing a later GPU assertion.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vllm-project/vllm/security/advisories/GHSA-8wr5-jm2h-8r4f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vllm-project/vllm/pull/44744",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vllm-project/vllm/commit/8a5cf1ccd65e8ac7635c402c1ec0b08988bc26ca",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 951,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54242",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T16:25:43.084Z",
      "date_published": "2026-07-17T20:23:42.129Z",
      "date_updated": "2026-07-20T15:31:25.686Z",
      "publisher": "GitHub_M",
      "title": "Statamic: Server-Side Request Forgery via Glide (DNS rebinding)",
      "affected": {
        "vendors": [
          "statamic"
        ],
        "products": [
          {
            "vendor": "statamic",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04419
      },
      "nvd": {
        "published": "2026-07-17T21:17:08.247",
        "lastModified": "2026-07-23T15:05:52.760",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54242",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Statamic validates a remote URL before connection but permits DNS rebinding to change the resolved destination to an internal address.",
        "basis": [
          "CNA",
          "CWE-367",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/statamic/cms/security/advisories/GHSA-v5c4-wcpj-x73m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/statamic/cms/pull/14761",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/statamic/cms/commit/d8f4575c425e2932f22ac030568e990be0dae2da",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/statamic/cms/releases/tag/v5.73.24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/statamic/cms/releases/tag/v6.20.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 706,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T16:25:43.085Z",
      "date_published": "2026-07-17T20:24:53.576Z",
      "date_updated": "2026-07-20T13:34:48.019Z",
      "publisher": "GitHub_M",
      "title": "Statamic: CSV formula injection in form submission exports",
      "affected": {
        "vendors": [
          "statamic"
        ],
        "products": [
          {
            "vendor": "statamic",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1236",
          "name": "Improper Neutralization of Formula Elements in a CSV File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00191,
        "percentile": 0.09002
      },
      "nvd": {
        "published": "2026-07-17T21:17:08.390",
        "lastModified": "2026-07-23T15:05:52.760",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54243",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Statamic writes form values beginning with spreadsheet formula trigger characters into CSV cells without neutralization, so an editor opening the export executes the cell as a formula.",
        "basis": [
          "CNA",
          "CWE-1236"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/statamic/cms/security/advisories/GHSA-h77m-qrj7-jxcw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/statamic/cms/pull/14760",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/statamic/cms/commit/f17c098e52a92597fc5f81bd287700b3d05f4add",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/statamic/cms/releases/tag/v5.73.24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/statamic/cms/releases/tag/v6.20.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 685,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54244",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T16:25:43.085Z",
      "date_published": "2026-07-17T20:22:35.728Z",
      "date_updated": "2026-07-20T19:11:22.297Z",
      "publisher": "GitHub_M",
      "title": "Statamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editors",
      "affected": {
        "vendors": [
          "statamic"
        ],
        "products": [
          {
            "vendor": "statamic",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07028
      },
      "nvd": {
        "published": "2026-07-17T21:17:08.523",
        "lastModified": "2026-07-23T15:05:52.760",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54244",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prior to 5.74.0 and 6.20.3, the Live Preview endpoint for existing entries and terms in src/Http/Controllers/CP/PreviewController.php only checked view authorization, but it accepts and renders caller-supplied field values.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/statamic/cms/security/advisories/GHSA-7mqq-4v55-88gh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/statamic/cms/pull/14791",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/statamic/cms/commit/87b9998f4d9e40de53346402ccf6eb3c17ba168f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/statamic/cms/releases/tag/v5.74.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/statamic/cms/releases/tag/v6.20.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54249",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T16:25:43.085Z",
      "date_published": "2026-07-29T20:28:07.154Z",
      "date_updated": "2026-07-30T13:08:12.954Z",
      "publisher": "GitHub_M",
      "title": "VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — S3/GCS confused deputy via provider metadata injection",
      "affected": {
        "vendors": [
          "pydantic"
        ],
        "products": [
          {
            "vendor": "pydantic",
            "product": "pydantic-ai"
          },
          {
            "vendor": "pydantic",
            "product": "pydantic-ai-slim"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.0966
      },
      "nvd": {
        "published": "2026-07-29T21:17:47.323",
        "lastModified": "2026-08-04T13:22:03.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54249",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "UploadedFile references are resolved with the server's cloud or provider identity without binding the referenced object to the submitting client.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-h7p7-w5gc-xj3w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1027,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-54259",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T17:13:32.278Z",
      "date_published": "2026-07-01T21:09:19.800Z",
      "date_updated": "2026-07-02T15:49:19.274Z",
      "publisher": "GitHub_M",
      "title": "Wagtail: Improper restriction handling on Documents and Images chosen endpoints",
      "affected": {
        "vendors": [
          "wagtail"
        ],
        "products": [
          {
            "vendor": "wagtail",
            "product": "wagtail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-280",
          "name": "Improper Handling of Insufficient Permissions or Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05819
      },
      "nvd": {
        "published": "2026-07-01T22:16:49.297",
        "lastModified": "2026-07-02T19:26:19.807",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54259",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Wagtail restores a permission or request context incorrectly after a chooser operation, allowing records outside the caller's permitted collection to be listed.",
        "basis": [
          "CNA",
          "CWE-280"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wagtail/wagtail/security/advisories/GHSA-h54r-xq46-qwqm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 540,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54260",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T17:13:32.278Z",
      "date_published": "2026-07-01T21:08:24.820Z",
      "date_updated": "2026-07-02T15:54:38.571Z",
      "publisher": "GitHub_M",
      "title": "Wagtail: Denial of service via unbounded filter specs in the image preview",
      "affected": {
        "vendors": [
          "wagtail"
        ],
        "products": [
          {
            "vendor": "wagtail",
            "product": "wagtail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12601
      },
      "nvd": {
        "published": "2026-07-01T22:16:49.523",
        "lastModified": "2026-07-02T19:25:51.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54260",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An authenticated administrator can submit crafted filter specifications whose rendition-processing cost has no effective per-operation bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wagtail/wagtail/security/advisories/GHSA-f2p5-j6fg-5cxf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 434,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54261",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T17:13:32.279Z",
      "date_published": "2026-07-01T21:10:22.800Z",
      "date_updated": "2026-07-02T14:42:46.778Z",
      "publisher": "GitHub_M",
      "title": "Wagtail: Improper permission handling in image preview",
      "affected": {
        "vendors": [
          "wagtail"
        ],
        "products": [
          {
            "vendor": "wagtail",
            "product": "wagtail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-280",
          "name": "Improper Handling of Insufficient Permissions or Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10141
      },
      "nvd": {
        "published": "2026-07-01T22:16:49.653",
        "lastModified": "2026-07-02T19:25:27.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54261",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "wagtail permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-280"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wagtail/wagtail/security/advisories/GHSA-r6p4-grq7-xm4m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 467,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54262",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T17:13:32.279Z",
      "date_published": "2026-07-01T21:11:27.671Z",
      "date_updated": "2026-07-02T12:42:13.452Z",
      "publisher": "GitHub_M",
      "title": "Wagtail: Pages translations can be created without page permissions when using simple_translation",
      "affected": {
        "vendors": [
          "wagtail"
        ],
        "products": [
          {
            "vendor": "wagtail",
            "product": "wagtail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-280",
          "name": "Improper Handling of Insufficient Permissions or Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05819
      },
      "nvd": {
        "published": "2026-07-01T22:16:49.787",
        "lastModified": "2026-07-02T19:29:35.960",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54262",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The translation workflow checks the submit-translation capability but not whether the user has permission on the source page being translated.",
        "basis": [
          "CNA",
          "CWE-280"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wagtail/wagtail/security/advisories/GHSA-8634-mr4j-r72c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54263",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T17:13:32.279Z",
      "date_published": "2026-07-01T21:12:30.719Z",
      "date_updated": "2026-07-06T14:41:12.073Z",
      "publisher": "GitHub_M",
      "title": "Wagtail: Reflected XSS in dynamic image URL generator view",
      "affected": {
        "vendors": [
          "wagtail"
        ],
        "products": [
          {
            "vendor": "wagtail",
            "product": "wagtail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10495
      },
      "nvd": {
        "published": "2026-07-01T22:16:49.917",
        "lastModified": "2026-07-06T16:16:34.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54263",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Wagtail dynamic image URL view reflects editor-controlled input into an administrator page without sufficient contextual escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wagtail/wagtail/security/advisories/GHSA-23m2-mghx-vqmf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 705,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54272",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T17:13:32.280Z",
      "date_published": "2026-07-27T17:13:09.244Z",
      "date_updated": "2026-07-27T17:42:10.446Z",
      "publisher": "GitHub_M",
      "title": "ip-address: Misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks",
      "affected": {
        "vendors": [
          "beaugunderson"
        ],
        "products": [
          {
            "vendor": "beaugunderson",
            "product": "ip-address"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16928
      },
      "nvd": {
        "published": "2026-07-27T18:16:56.410",
        "lastModified": "2026-07-27T18:16:56.410",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54272",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Address classification fails to normalize IPv4-mapped or NAT64 IPv6 addresses before private-range checks, so internal destinations can be mislabeled as global.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/beaugunderson/ip-address/security/advisories/GHSA-22jq-vg5j-6vgg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1247,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54291",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T17:46:37.293Z",
      "date_published": "2026-07-06T18:55:01.675Z",
      "date_updated": "2026-07-06T19:47:17.454Z",
      "publisher": "GitHub_M",
      "title": "Silent channel-binding authentication downgrade via unsupported certificate algorithms",
      "affected": {
        "vendors": [
          "pgjdbc"
        ],
        "products": [
          {
            "vendor": "pgjdbc",
            "product": "pgjdbc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-636",
          "name": "Not Failing Securely ('Failing Open')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-757",
          "name": "Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10402
      },
      "nvd": {
        "published": "2026-07-06T19:17:08.407",
        "lastModified": "2026-07-09T13:16:25.717",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54291",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unsupported certificate algorithm produces an empty channel binding that is accepted as plain SCRAM instead of failing a channelBinding=require connection.",
        "basis": [
          "CNA",
          "CWE-636",
          "CWE-757"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-j92g-9f8w-j867",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pgjdbc/pgjdbc/commit/77df98e4e66c12936ded3478a0954f6f580bad99",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ongres/scram/releases/tag/3.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Not Applicable",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 795,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54329",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T18:42:02.224Z",
      "date_published": "2026-07-10T18:26:44.378Z",
      "date_updated": "2026-07-10T20:58:22.265Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Cross-Tenant Accessory Injection in Snipe-IT API",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13319
      },
      "nvd": {
        "published": "2026-07-10T19:17:24.440",
        "lastModified": "2026-07-10T21:16:55.297",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54329",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The accessory create path mass-assigns company_id without binding the new record to the caller's company.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-pwpj-p52h-q484",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/6a0ec6945126a79fc25c0990c99abe632db370c3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/dc8cbf4786bb38b260b4ae1723ec9e7f81d82fe5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/e2bea57146eb3a3781b5eb21b69d7e04cc87c268",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54332",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T19:23:22.316Z",
      "date_published": "2026-07-28T16:17:48.796Z",
      "date_updated": "2026-07-28T17:28:21.158Z",
      "publisher": "GitHub_M",
      "title": "GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS",
      "affected": {
        "vendors": [
          "gopacket"
        ],
        "products": [
          {
            "vendor": "gopacket",
            "product": "gopacket"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00367,
        "percentile": 0.29416
      },
      "nvd": {
        "published": "2026-07-28T17:16:51.257",
        "lastModified": "2026-07-30T19:17:21.870",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54332",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The sFlow decoder multiplies attacker-controlled counts into a slice allocation without checking them against the datagram's remaining bytes.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gopacket/gopacket/security/advisories/GHSA-g6v3-7xmc-w563",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gopacket/gopacket/commit/76119086f5936aacd7088bdf97d565501bb6c4cc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gopacket/gopacket/releases/tag/v1.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 494,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54335",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T19:23:22.316Z",
      "date_published": "2026-07-17T20:56:51.857Z",
      "date_updated": "2026-07-20T17:38:02.512Z",
      "publisher": "GitHub_M",
      "title": "Feathersjs: Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__",
      "affected": {
        "vendors": [
          "feathersjs"
        ],
        "products": [
          {
            "vendor": "feathersjs",
            "product": "feathers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17462
      },
      "nvd": {
        "published": "2026-07-17T22:17:44.840",
        "lastModified": "2026-07-23T17:58:34.990",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54335",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "feathers follows attacker-controlled object keys through prototype-bearing properties, allowing input to modify inherited program state.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/feathersjs/feathers/security/advisories/GHSA-28xv-ph75-77wh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/feathersjs/feathers/pull/3690",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/feathersjs/feathers/commit/28b3c03c63bdbff53115fdaa46c56980e7942acc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/feathersjs/feathers/releases/tag/v5.0.45",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 677,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54340",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T19:23:22.316Z",
      "date_published": "2026-07-16T23:29:50.799Z",
      "date_updated": "2026-07-17T18:06:19.274Z",
      "publisher": "GitHub_M",
      "title": "h2o has HTTP/2 state amplification",
      "affected": {
        "vendors": [
          "h2o"
        ],
        "products": [
          {
            "vendor": "h2o",
            "product": "h2o"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.2012
      },
      "nvd": {
        "published": "2026-07-17T00:16:25.810",
        "lastModified": "2026-07-17T19:17:17.030",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54340",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Decoded HPACK header state remains allocated on stalled HTTP/2 streams without a sufficient combined state and stream bound.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/h2o/h2o/security/advisories/GHSA-qcrr-wrhc-pgq9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/h2o/h2o/commit/9265bdd9a996ed992681055e3996baf3e09d2063",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 457,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54342",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T19:23:22.317Z",
      "date_published": "2026-07-24T18:26:34.794Z",
      "date_updated": "2026-07-27T16:27:06.387Z",
      "publisher": "GitHub_M",
      "title": "TLS Certificate Verification Disabled on CXF Transport Clients in epa4all",
      "affected": {
        "vendors": [
          "med-united"
        ],
        "products": [
          {
            "vendor": "med-united",
            "product": "epa4all"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02627
      },
      "nvd": {
        "published": "2026-07-24T19:16:59.200",
        "lastModified": "2026-07-30T19:19:45.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54342",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "epa4all disables TLS certificate verification for backend clients, allowing any network-positioned certificate to authenticate the peer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/med-united/epa4all/security/advisories/GHSA-296w-v8f6-3rf7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/med-united/epa4all/security/advisories/GHSA-vvh7-x6c7-46gh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/med-united/epa4all/releases/tag/2026-05-20",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://www.machinespirits.com/advisory/b98b02",
          "host": "www.machinespirits.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54344",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T19:23:22.317Z",
      "date_published": "2026-07-08T15:08:19.691Z",
      "date_updated": "2026-07-08T16:19:26.299Z",
      "publisher": "GitHub_M",
      "title": "ToolJet GitHub Actions comment body shell injection exposes deployment secrets",
      "affected": {
        "vendors": [
          "ToolJet"
        ],
        "products": [
          {
            "vendor": "ToolJet",
            "product": "ToolJet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06708
      },
      "nvd": {
        "published": "2026-07-08T16:16:30.760",
        "lastModified": "2026-07-09T19:40:42.113",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54344",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A GitHub Actions workflow interpolates an untrusted pull-request comment directly into a Bash conditional.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ToolJet/ToolJet/security/advisories/GHSA-4pm2-w6g5-28mm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54345",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T19:23:22.317Z",
      "date_published": "2026-07-28T16:14:12.097Z",
      "date_updated": "2026-07-28T17:11:47.628Z",
      "publisher": "GitHub_M",
      "title": "GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)",
      "affected": {
        "vendors": [
          "gopacket"
        ],
        "products": [
          {
            "vendor": "gopacket",
            "product": "gopacket"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31574
      },
      "nvd": {
        "published": "2026-07-28T17:16:51.400",
        "lastModified": "2026-07-30T19:17:21.870",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54345",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Diameter decoder subtracts a 12-byte header from a smaller unsigned length, wrapping to a value that requests an approximately four-gigabyte allocation.",
        "basis": [
          "CNA",
          "CWE-191",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gopacket/gopacket/security/advisories/GHSA-6r28-9ppf-4hj5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gopacket/gopacket/commit/145859d0eaee1a6f5925ffb93851c976449c3311",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gopacket/gopacket/releases/tag/v1.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54363",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T20:20:02.947Z",
      "date_published": "2026-07-30T12:24:15.423Z",
      "date_updated": "2026-07-30T14:38:25.155Z",
      "publisher": "VulnCheck",
      "title": "CentreStack < 17.5 Hardcoded Key Token Forgery RCE",
      "affected": {
        "vendors": [
          "Gladinet"
        ],
        "products": [
          {
            "vendor": "Gladinet",
            "product": "CentreStack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-321",
          "name": "Use of Hard-coded Cryptographic Key",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00394,
        "percentile": 0.32132
      },
      "nvd": {
        "published": "2026-07-30T13:16:51.223",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54363",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CentreStack uses a static hard-coded SysNumber as a cryptographic key, allowing anyone who obtains the value to forge encrypted tokens.",
        "basis": [
          "CNA",
          "CWE-321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.centrestack.com/",
          "host": "www.centrestack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/centrestack-hardcoded-key-token-forgery-rce",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54364",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T20:20:02.947Z",
      "date_published": "2026-07-30T12:24:44.549Z",
      "date_updated": "2026-07-30T12:53:07.895Z",
      "publisher": "VulnCheck",
      "title": "CentreStack < 17.4 Session Injection via SelectProvider.aspx",
      "affected": {
        "vendors": [
          "Gladinet"
        ],
        "products": [
          {
            "vendor": "Gladinet",
            "product": "CentreStack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16643
      },
      "nvd": {
        "published": "2026-07-30T13:16:51.367",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54364",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Newline and tab characters in AccountName break the custom session serialization grammar and inject a resellerid variable that satisfies the management-session check.",
        "basis": [
          "CNA",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.centrestack.com/",
          "host": "www.centrestack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/centrestack-session-injection-via-selectprovider-aspx",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 513,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54365",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T20:20:02.947Z",
      "date_published": "2026-07-30T12:25:05.528Z",
      "date_updated": "2026-07-31T22:51:40.063Z",
      "publisher": "VulnCheck",
      "title": "CentreStack < 17.3 Unauthenticated User Creation via Deserialization in GSNamespace.dll",
      "affected": {
        "vendors": [
          "Gladinet"
        ],
        "products": [
          {
            "vendor": "Gladinet",
            "product": "CentreStack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12152
      },
      "nvd": {
        "published": "2026-07-30T13:16:51.503",
        "lastModified": "2026-07-31T23:17:24.820",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54365",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.centrestack.com/",
          "host": "www.centrestack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/centrestack-unauthenticated-user-creation-via-deserialization-in-gsnamespace-dll",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 604,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54366",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T20:20:02.948Z",
      "date_published": "2026-07-30T12:25:36.860Z",
      "date_updated": "2026-07-30T12:59:47.092Z",
      "publisher": "VulnCheck",
      "title": "CentreStack < 17.4 XXE via SharePoint Storage Configuration",
      "affected": {
        "vendors": [
          "Gladinet"
        ],
        "products": [
          {
            "vendor": "Gladinet",
            "product": "CentreStack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20898
      },
      "nvd": {
        "published": "2026-07-30T13:16:51.640",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54366",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unauthenticated storage handler parses attacker-hosted XML with external entities enabled, allowing the parser to read and exfiltrate local files.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.centrestack.com/",
          "host": "www.centrestack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/centrestack-xxe-via-sharepoint-storage-configuration",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54367",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T20:20:02.948Z",
      "date_published": "2026-07-30T12:26:11.653Z",
      "date_updated": "2026-07-30T15:16:38.944Z",
      "publisher": "VulnCheck",
      "title": "CentreStack < 17.2 Unauthenticated API Authorization Bypass",
      "affected": {
        "vendors": [
          "Gladinet"
        ],
        "products": [
          {
            "vendor": "Gladinet",
            "product": "CentreStack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08602
      },
      "nvd": {
        "published": "2026-07-30T13:16:51.770",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54367",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Exposed APIs omit authorization and accept account identifiers forged with a static shared encryption key, allowing settings for arbitrary users or the cluster account to be changed.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.centrestack.com/",
          "host": "www.centrestack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/centrestack-unauthenticated-api-authorization-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54368",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-12T20:20:02.948Z",
      "date_published": "2026-07-30T12:26:49.831Z",
      "date_updated": "2026-07-30T14:41:23.530Z",
      "publisher": "VulnCheck",
      "title": "CentreStack < 17.4 SQL Injection via x-glad-filter Header",
      "affected": {
        "vendors": [
          "Gladinet"
        ],
        "products": [
          {
            "vendor": "Gladinet",
            "product": "CentreStack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00392,
        "percentile": 0.31964
      },
      "nvd": {
        "published": "2026-07-30T13:16:51.910",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54368",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.centrestack.com/",
          "host": "www.centrestack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/centrestack-sql-injection-via-x-glad-filter-header",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 509,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-13T10:04:54.084Z",
      "date_published": "2026-07-01T17:02:21.778Z",
      "date_updated": "2026-07-01T17:36:47.358Z",
      "publisher": "apache",
      "title": "Apache HttpComponents Core: Unbounded HTTP Header/Line Length in Default Configuration",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache HttpComponents Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00565,
        "percentile": 0.43711
      },
      "nvd": {
        "published": "2026-07-01T17:16:36.357",
        "lastModified": "2026-07-24T20:04:03.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54399",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The HTTP/1.1 parser accepts an excessive count or length of headers without a memory bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-13T15:00:00.604Z",
      "date_published": "2026-07-02T14:49:16.753Z",
      "date_updated": "2026-07-02T16:11:02.050Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Access Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00519,
        "percentile": 0.41219
      },
      "nvd": {
        "published": "2026-07-02T15:17:03.623",
        "lastModified": "2026-07-09T13:21:25.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54400",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "UniFi Access permits a high-privileged network actor to gain host privileges, but the public advisory does not identify the misbound subject, object, or action.",
        "basis": [
          "CNA",
          "CWE-284",
          "Ubiquiti Security Advisory Bulletin 066"
        ],
        "deepDive": true,
        "notes": "Inspected https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc and its official public GraphQL release payload on 2026-08-05; Bulletin 066 confirms UniFi Access Application 4.2.28 and earlier, update to 4.2.29 or later, network plus high privileges, and improper access control, but it does not name the failed authorization check."
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54401",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-13T15:00:00.604Z",
      "date_published": "2026-07-02T14:49:17.032Z",
      "date_updated": "2026-07-02T15:51:58.264Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi OS Server"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Machines"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Fortress Gateway"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Wall"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Routers"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Express 7"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Keys"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Network Video Recorders"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Video Recorders"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Gateways"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Network Attached Storage"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Firewall Core"
          }
        ],
        "affectedBlockCount": 12,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00239,
        "percentile": 0.1504
      },
      "nvd": {
        "published": "2026-07-02T15:17:03.730",
        "lastModified": "2026-07-10T02:50:13.673",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54401",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A server-side request accepts an attacker-selected destination without enforcing the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 12,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-54402",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-13T15:00:00.604Z",
      "date_published": "2026-07-02T14:49:17.030Z",
      "date_updated": "2026-07-02T15:52:04.606Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi OS Server"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Machines"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Fortress Gateway"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Wall"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Routers"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Express 7"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Keys"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Network Video Recorders"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Video Recorders"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Gateways"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Network Attached Storage"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Firewall Core"
          }
        ],
        "affectedBlockCount": 12,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.01305,
        "percentile": 0.67725
      },
      "nvd": {
        "published": "2026-07-02T15:17:03.837",
        "lastModified": "2026-07-10T02:49:32.057",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54402",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A low-privilege UniFi OS input crosses into a host command without neutralizing command delimiters.",
        "basis": [
          "CNA record",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 12,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-54403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-13T15:00:00.604Z",
      "date_published": "2026-07-02T14:49:16.633Z",
      "date_updated": "2026-07-02T16:09:42.714Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi OS Server"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Machines"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Fortress Gateway"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Wall"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Routers"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Express 7"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Keys"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Network Video Recorders"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Video Recorders"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Gateways"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Network Attached Storage"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Firewall Core"
          }
        ],
        "affectedBlockCount": 12,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0062,
        "percentile": 0.46311
      },
      "nvd": {
        "published": "2026-07-02T15:17:03.947",
        "lastModified": "2026-07-10T02:46:57.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54403",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "UniFi OS Server accepts an attacker-controlled path that can resolve outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 12,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-54404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-13T15:00:00.605Z",
      "date_published": "2026-07-02T14:49:16.757Z",
      "date_updated": "2026-07-03T03:56:09.490Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi OS Server"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Machines"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Fortress Gateway"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Wall"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Routers"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Express 7"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Keys"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Network Video Recorders"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Video Recorders"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Gateways"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Network Attached Storage"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Firewall Core"
          }
        ],
        "affectedBlockCount": 12,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20224
      },
      "nvd": {
        "published": "2026-07-02T15:17:04.060",
        "lastModified": "2026-07-10T02:48:50.627",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54404",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "UniFi OS places authenticated request data into SQL statements without the required parameter separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 12,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-54405",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-13T15:00:00.605Z",
      "date_published": "2026-07-02T14:49:16.619Z",
      "date_updated": "2026-07-02T16:09:09.474Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack on the application.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Network Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26547
      },
      "nvd": {
        "published": "2026-07-02T15:17:04.193",
        "lastModified": "2026-07-02T17:50:24.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54405",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The UniFi record attributes denial of service to improper input validation but does not identify the input, parser, exception, work bound, or failing state transition.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54406",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-13T15:00:00.605Z",
      "date_published": "2026-07-02T14:49:16.718Z",
      "date_updated": "2026-07-02T16:10:43.419Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Network Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30413
      },
      "nvd": {
        "published": "2026-07-02T15:17:04.310",
        "lastModified": "2026-07-06T19:35:08.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54406",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The application permits a privileged network caller to select a host write target outside the intended path, but the vulnerable parameter is not public.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54407",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-13T15:00:00.605Z",
      "date_published": "2026-07-02T14:49:16.605Z",
      "date_updated": "2026-07-02T16:08:49.302Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Protect Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23392
      },
      "nvd": {
        "published": "2026-07-02T15:17:04.417",
        "lastModified": "2026-07-06T19:32:10.967",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54407",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Certain UniFi Protect API endpoints permit network callers to bypass authentication, but the endpoints and missing check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54408",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-13T15:00:00.605Z",
      "date_published": "2026-07-02T14:49:16.684Z",
      "date_updated": "2026-07-02T16:08:26.785Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Protect Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.200000000000001,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22761
      },
      "nvd": {
        "published": "2026-07-02T15:17:04.523",
        "lastModified": "2026-07-07T16:33:15.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54408",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "UniFi Protect permits an unauthenticated network caller to reach data streaming, but the vendor advisory does not disclose the stream endpoint or missing gate.",
        "basis": [
          "CNA",
          "CWE-284",
          "Ubiquiti SAB-066"
        ],
        "deepDive": true,
        "notes": "Inspected Ubiquiti Security Advisory Bulletin 066 at https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc. Ubiquiti confirms unauthenticated network access to UniFi Protect data streaming, affected versions through 7.1.77, and remediation in 7.1.83, but does not publish the streaming endpoint or missing gate. The vendor bulletin scores the issue 8.6 while this shard carries an NVD maximum of 9.8; retain the source attribution for that conflict."
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-13T15:00:00.605Z",
      "date_published": "2026-07-02T14:49:16.639Z",
      "date_updated": "2026-07-02T16:10:07.537Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Protect Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-665",
          "name": "Improper Initialization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19355
      },
      "nvd": {
        "published": "2026-07-02T15:17:04.627",
        "lastModified": "2026-07-07T16:34:31.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54409",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An initialization path can bypass authentication, but the public record does not identify the state flag or omitted check.",
        "basis": [
          "CNA",
          "CWE-665"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-14T03:57:25.577Z",
      "date_published": "2026-07-24T03:42:26.433Z",
      "date_updated": "2026-07-24T12:26:32.687Z",
      "publisher": "mitre",
      "title": "In OpenStack Ironic Python Agent through 11.",
      "affected": {
        "vendors": [
          "OpenStack"
        ],
        "products": [
          {
            "vendor": "OpenStack",
            "product": "Ironic Python Agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02519
      },
      "nvd": {
        "published": "2026-07-24T05:16:45.460",
        "lastModified": "2026-07-24T13:18:27.610",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54422",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Ironic Python Agent supplies image-download credentials to a bootc container that may itself be attacker-controlled, allowing the container to extract them.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugs.launchpad.net/ironic-python-agent/+bug/2155826",
          "host": "bugs.launchpad.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/23/4",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://security.openstack.org/ossa/OSSA-2026-028.html",
          "host": "security.openstack.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/23/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-14T04:04:35.484Z",
      "date_published": "2026-07-10T03:10:54.638Z",
      "date_updated": "2026-07-10T15:25:59.292Z",
      "publisher": "mitre",
      "title": "In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.",
      "affected": {
        "vendors": [
          "OpenStack"
        ],
        "products": [
          {
            "vendor": "OpenStack",
            "product": "Ironic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-424",
          "name": "Improper Protection of Alternate Path",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22568
      },
      "nvd": {
        "published": "2026-07-10T04:17:52.230",
        "lastModified": "2026-07-10T18:51:16.090",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54423",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Ironic's send_raw path permits arbitrary IPMI commands without applying the restrictions enforced by the normal command interface.",
        "basis": [
          "CNA",
          "CWE-424"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugs.launchpad.net/ironic/+bug/2150458",
          "host": "bugs.launchpad.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://security.openstack.org/ossa/OSSA-2026-025.html",
          "host": "security.openstack.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/08/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-54424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-14T04:15:58.932Z",
      "date_published": "2026-07-04T00:45:24.208Z",
      "date_updated": "2026-07-06T15:35:01.009Z",
      "publisher": "mitre",
      "title": "An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege.",
      "affected": {
        "vendors": [
          "Unity"
        ],
        "products": [
          {
            "vendor": "Unity",
            "product": "Parsec"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-648",
          "name": "Incorrect Use of Privileged APIs",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15768
      },
      "nvd": {
        "published": "2026-07-04T01:16:27.340",
        "lastModified": "2026-07-06T19:47:18.123",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54424",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A SYSTEM Parsec process inherits a user-controlled AppData environment value and therefore performs privileged work against a location selected by the user.",
        "basis": [
          "CNA",
          "CWE-648"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://parsec.app/",
          "host": "parsec.app",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://support.parsec.app/hc/en-us/articles/50612943726612-CVE-2026-54424",
          "host": "support.parsec.app",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.tomadimitrie.dev/blog/CVE-2026-54424",
          "host": "www.tomadimitrie.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/tomadimitrie/CVE-2026-54424",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 407,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-14T09:39:30.814Z",
      "date_published": "2026-07-01T17:03:53.938Z",
      "date_updated": "2026-07-01T18:15:56.634Z",
      "publisher": "apache",
      "title": "Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache HttpComponents Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00587,
        "percentile": 0.44749
      },
      "nvd": {
        "published": "2026-07-01T18:16:34.507",
        "lastModified": "2026-07-24T20:03:41.313",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54428",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HTTP/2 HPACK decoder accepts oversized compressed headers before the peer acknowledges the configured header-list limit.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 383,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54429",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T10:05:28.879Z",
      "date_published": "2026-07-14T09:19:17.249Z",
      "date_updated": "2026-07-14T12:15:38.712Z",
      "publisher": "siemens",
      "title": "A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions).",
      "affected": {
        "vendors": [
          "Siemens"
        ],
        "products": [
          {
            "vendor": "Siemens",
            "product": "SIMATIC S7-PLCSIM Advanced"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05931
      },
      "nvd": {
        "published": "2026-07-14T10:16:33.123",
        "lastModified": "2026-07-15T20:27:37.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54429",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation lets attacker-controlled work or allocation grow without an effective per-request bound or termination condition.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-828211.html",
          "host": "cert-portal.siemens.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 591,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T13:08:01.056Z",
      "date_published": "2026-07-02T10:30:33.766Z",
      "date_updated": "2026-07-02T12:17:21.724Z",
      "publisher": "CERT-PL",
      "title": "Server-Site Request Forgery in liboauth2",
      "affected": {
        "vendors": [
          "OpenIDC"
        ],
        "products": [
          {
            "vendor": "OpenIDC",
            "product": "liboauth2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02258
      },
      "nvd": {
        "published": "2026-07-02T11:16:16.423",
        "lastModified": "2026-07-02T17:43:14.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54430",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "liboauth2 incorporates an unverified JWT kid value into a server-side URL and fetches the selected destination without an allowlist.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-54430",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/OpenIDC/liboauth2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/OpenIDC/liboauth2/commit/347507ac5b51f48c2933bbe49b2ee07c2af4712b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 494,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54431",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T13:08:01.057Z",
      "date_published": "2026-07-02T10:30:57.655Z",
      "date_updated": "2026-07-02T12:16:41.569Z",
      "publisher": "CERT-PL",
      "title": "Improper Data Validation in liboauth2",
      "affected": {
        "vendors": [
          "OpenIDC"
        ],
        "products": [
          {
            "vendor": "OpenIDC",
            "product": "liboauth2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-358",
          "name": "Improperly Implemented Security Check for Standard",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02819
      },
      "nvd": {
        "published": "2026-07-02T11:16:17.123",
        "lastModified": "2026-07-02T17:43:14.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54431",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The DPoP verifier accepts a JWK header containing private EC key material even though the proof format requires rejection of private parameters.",
        "basis": [
          "CNA",
          "CWE-358"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-54430",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/OpenIDC/liboauth2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/OpenIDC/liboauth2/commit/c0b57152ed6a0af33aeb04a60bd7f5bff5ab8800",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54432",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T13:27:41.810Z",
      "date_published": "2026-07-14T16:21:55.409Z",
      "date_updated": "2026-07-15T15:13:14.654Z",
      "publisher": "mitre",
      "title": "Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.",
      "affected": {
        "vendors": [
          "Roundcube"
        ],
        "products": [
          {
            "vendor": "Roundcube",
            "product": "Webmail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12766
      },
      "nvd": {
        "published": "2026-07-14T17:17:05.387",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54432",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Webmail page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2",
          "host": "roundcube.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T13:29:12.505Z",
      "date_published": "2026-07-14T16:18:16.549Z",
      "date_updated": "2026-07-15T14:10:33.042Z",
      "publisher": "mitre",
      "title": "In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by...",
      "affected": {
        "vendors": [
          "Roundcube"
        ],
        "products": [
          {
            "vendor": "Roundcube",
            "product": "Webmail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 2.8,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23587
      },
      "nvd": {
        "published": "2026-07-14T17:17:05.530",
        "lastModified": "2026-07-17T19:24:24.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54433",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Roundcube renders crafted plain-text email content in a way that turns attacker input into script in the authenticated webmail origin.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2",
          "host": "roundcube.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 285,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54443",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T15:30:40.317Z",
      "date_published": "2026-07-15T18:19:31.219Z",
      "date_updated": "2026-07-15T19:17:57.724Z",
      "publisher": "GitHub_M",
      "title": "Dashy: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
      "affected": {
        "vendors": [
          "lissy93"
        ],
        "products": [
          {
            "vendor": "lissy93",
            "product": "dashy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-80",
          "name": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-84",
          "name": "Improper Neutralization of Encoded URI Schemes in a Web Page",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13739
      },
      "nvd": {
        "published": "2026-07-15T19:17:50.270",
        "lastModified": "2026-07-15T20:17:40.743",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54443",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dashy places an RSS-supplied javascript URI into an anchor href and executes it in the dashboard origin when clicked.",
        "basis": [
          "CNA",
          "CWE-80",
          "CWE-84"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lissy93/dashy/security/advisories/GHSA-2x3v-qmgm-r8hv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lissy93/dashy/releases/tag/3.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T15:30:40.318Z",
      "date_published": "2026-07-15T21:33:27.190Z",
      "date_updated": "2026-07-16T15:12:06.414Z",
      "publisher": "GitHub_M",
      "title": "AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin",
      "affected": {
        "vendors": [
          "WWBN"
        ],
        "products": [
          {
            "vendor": "WWBN",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22684
      },
      "nvd": {
        "published": "2026-07-15T22:17:19.160",
        "lastModified": "2026-07-16T16:19:13.120",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54458",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Anonymous WebSocket metadata is stored, broadcast, interpolated into an HTML template, and appended as live DOM without output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-8whc-2wmv-ww35",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/WWBN/AVideo/commit/8be71e53ccbe9b84b30870db386fb4d2b11e1c16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1591,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54463",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T15:30:40.319Z",
      "date_published": "2026-07-17T20:05:17.888Z",
      "date_updated": "2026-07-20T16:58:33.914Z",
      "publisher": "GitHub_M",
      "title": "websocket-driver: Memory exhaustion via abuse of protocol length headers",
      "affected": {
        "vendors": [
          "faye"
        ],
        "products": [
          {
            "vendor": "faye",
            "product": "websocket-driver-ruby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24891
      },
      "nvd": {
        "published": "2026-07-17T20:17:26.633",
        "lastModified": "2026-07-23T18:04:42.997",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54463",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The websocket-driver-ruby path lets attacker-controlled work, memory, recursion, or retained resources grow without an effective bound or release condition.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-ghhp-3qvg-889p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/faye/websocket-driver-ruby/commit/d0141f041f6e3677a951255d547a313e732ccbe0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54464",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T15:30:40.319Z",
      "date_published": "2026-07-17T20:03:36.326Z",
      "date_updated": "2026-07-21T02:13:20.815Z",
      "publisher": "GitHub_M",
      "title": "websocket-driver: Resource limit bypass via message compression",
      "affected": {
        "vendors": [
          "faye"
        ],
        "products": [
          {
            "vendor": "faye",
            "product": "websocket-driver-ruby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.2489
      },
      "nvd": {
        "published": "2026-07-17T20:17:26.770",
        "lastModified": "2026-07-23T18:14:09.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54464",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WebSocket limit measures compressed frame lengths and never enforces the maximum on the larger decompressed message.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-33ph-fccm-39pj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/faye/websocket-driver-ruby/commit/fa8641724f10bf3273585f1dcf9041f540bbd036",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 827,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54465",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T15:30:40.319Z",
      "date_published": "2026-07-17T20:06:06.980Z",
      "date_updated": "2026-07-20T13:49:17.424Z",
      "publisher": "GitHub_M",
      "title": "websocket-driver: Memory exhaustion in HTTP header parser",
      "affected": {
        "vendors": [
          "faye"
        ],
        "products": [
          {
            "vendor": "faye",
            "product": "websocket-driver-ruby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.2489
      },
      "nvd": {
        "published": "2026-07-17T20:17:26.897",
        "lastModified": "2026-07-23T16:19:47.997",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54465",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HTTP header parser accepts a never-ending header list on one connection without a memory or header-count limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/faye/websocket-driver-ruby/security/advisories/GHSA-8j3g-f24p-4mpw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/faye/websocket-driver-ruby/commit/17b569f232896e71d458404ccf4854f80e987710",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 489,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54466",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T15:30:40.319Z",
      "date_published": "2026-07-17T20:53:24.769Z",
      "date_updated": "2026-07-20T19:11:09.339Z",
      "publisher": "GitHub_M",
      "title": "websocket-driver: Message corruption via abuse of protocol length headers",
      "affected": {
        "vendors": [
          "faye"
        ],
        "products": [
          {
            "vendor": "faye",
            "product": "websocket-driver-node"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-130",
          "name": "Improper Handling of Length Parameter Inconsistency",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17979
      },
      "nvd": {
        "published": "2026-07-17T21:17:08.657",
        "lastModified": "2026-07-23T16:18:40.543",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54466",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "websocket-driver accepts an indefinitely long encoded frame-length header without bounding the number of continuation bytes, allowing attacker input to drive unbounded parsing and message-state corruption.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-130"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/faye/websocket-driver-node/security/advisories/GHSA-xv26-6w52-cph6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/faye/websocket-driver-node/commit/5b197ca874dab58e96cacad8a3c256797d804680",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 656,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54468",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T16:28:29.012Z",
      "date_published": "2026-07-10T12:09:05.546Z",
      "date_updated": "2026-07-10T18:53:01.001Z",
      "publisher": "dell",
      "title": "Dell Unisphere for PowerMax, version(s) 10.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "Unisphere for PowerMax"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22517
      },
      "nvd": {
        "published": "2026-07-10T12:17:23.290",
        "lastModified": "2026-07-16T16:41:15.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54468",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unisphere accepts traversal-bearing remote paths and reads the resolved file outside its intended directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54469",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T16:28:29.012Z",
      "date_published": "2026-07-10T12:14:48.803Z",
      "date_updated": "2026-07-14T03:55:41.008Z",
      "publisher": "dell",
      "title": "Dell Unisphere for PowerMax, version(s) 10.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "Unisphere for PowerMax"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00433,
        "percentile": 0.35609
      },
      "nvd": {
        "published": "2026-07-10T13:16:20.427",
        "lastModified": "2026-07-16T18:19:19.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54469",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unisphere for PowerMax deserializes attacker-controlled data without restricting the object types or state that the serialized stream may construct.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54470",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T16:28:29.012Z",
      "date_published": "2026-07-10T12:20:16.742Z",
      "date_updated": "2026-07-10T14:43:05.838Z",
      "publisher": "dell",
      "title": "Dell Unisphere for PowerMax, version(s) 10.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "Unisphere for PowerMax"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08945
      },
      "nvd": {
        "published": "2026-07-10T13:16:20.550",
        "lastModified": "2026-07-16T18:19:25.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54470",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unisphere permits an XML parser to resolve attacker-controlled external entity references.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000483543/dsa-2026-272-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtualappliance-dell-unisphere-360-dell-solutionsenabler-and-dell-solutionsenabler-virtualappliance-security-update-for-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 264,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54477",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T15:47:37.782Z",
      "date_published": "2026-07-02T23:52:49.505Z",
      "date_updated": "2026-07-06T15:43:39.779Z",
      "publisher": "icscert",
      "title": "Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax",
      "affected": {
        "vendors": [
          "Gardyn"
        ],
        "products": [
          {
            "vendor": "Gardyn",
            "product": "Gardyn Home Firmware"
          },
          {
            "vendor": "Gardyn",
            "product": "Gardyn Studio Firmware"
          },
          {
            "vendor": "Gardyn",
            "product": "Gardyn Cloud API"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-644",
          "name": "Improper Neutralization of HTTP Headers for Scripting Syntax",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00271,
        "percentile": 0.19094
      },
      "nvd": {
        "published": "2026-07-03T00:16:52.440",
        "lastModified": "2026-07-06T19:42:49.287",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54477",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The Gardyn admin panel omits security response headers needed to constrain framing and script execution.",
        "basis": [
          "CNA",
          "CWE-644"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mygardyn.com/security/",
          "host": "mygardyn.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-03",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-03.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54478",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:27:22.817Z",
      "date_published": "2026-07-22T13:09:18.323Z",
      "date_updated": "2026-07-22T14:14:47.347Z",
      "publisher": "NLnet Labs",
      "title": "DNS Cookie bypass when combined with proxy-protocol use",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07507
      },
      "nvd": {
        "published": "2026-07-22T14:17:21.177",
        "lastModified": "2026-07-24T14:24:03.907",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54478",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unbound computes its server cookie from the proxy connection address instead of the declared client address, binding the trust decision to the wrong network peer.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-54478.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 612,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54483",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T17:49:28.560Z",
      "date_published": "2026-07-03T12:34:43.239Z",
      "date_updated": "2026-07-07T13:12:01.597Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00451,
        "percentile": 0.36975
      },
      "nvd": {
        "published": "2026-07-03T13:17:29.507",
        "lastModified": "2026-07-08T19:32:39.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54483",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 450,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-54490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T18:01:15.510Z",
      "date_published": "2026-07-17T20:54:22.417Z",
      "date_updated": "2026-07-21T02:23:58.273Z",
      "publisher": "GitHub_M",
      "title": "websocket-driver: Resource limit bypass via message compression",
      "affected": {
        "vendors": [
          "faye"
        ],
        "products": [
          {
            "vendor": "faye",
            "product": "websocket-driver-node"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.1798
      },
      "nvd": {
        "published": "2026-07-17T21:17:08.780",
        "lastModified": "2026-07-23T18:14:09.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54490",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 0.7.5, if this library is used with the permessage-deflate extension, a WebSocket server or client can be made to accept messages that are larger than the configured maximum message size because the limit is checked against the message frames' length headers, which give the size of the compressed data, not the size after decompression in lib/websocket/driver/hybi.js.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/faye/websocket-driver-node/security/advisories/GHSA-mp7j-qc5w-4988",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/faye/websocket-driver-node/commit/c55679a5b18251dd0a55d18a0cc6a4fd8822b92f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 600,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T18:01:15.511Z",
      "date_published": "2026-07-17T16:59:06.809Z",
      "date_updated": "2026-07-17T17:23:50.731Z",
      "publisher": "GitHub_M",
      "title": "Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness",
      "affected": {
        "vendors": [
          "ZcashFoundation",
          "zcash"
        ],
        "products": [
          {
            "vendor": "ZcashFoundation",
            "product": "zebra"
          },
          {
            "vendor": "zcash",
            "product": "halo2_gadgets"
          },
          {
            "vendor": "zcash",
            "product": "orchard"
          },
          {
            "vendor": "zcash",
            "product": "librustzcash"
          },
          {
            "vendor": "zcash",
            "product": "zcash"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11352
      },
      "nvd": {
        "published": "2026-07-17T17:17:16.620",
        "lastModified": "2026-07-17T18:45:20.713",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54496",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The scalar-multiplication gadget assigns the base point without a copy constraint tying it to the Orchard action's actual base.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-ww9q-8r59-xv46",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ZcashFoundation/zebra/releases/tag/v5.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zcash/halo2/releases/tag/halo2_gadgets-0.5.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zcash/librustzcash/releases/tag/zcash_primitives-0.28.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zcash/orchard/releases/tag/0.14.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zcash/zcash/releases/tag/v6.20.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://zfnd.org/zebra-4-5-3-and-5-0-0-emergency-soft-fork-and-nu6-2-activation",
          "host": "zfnd.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 728,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-54497",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T18:01:15.511Z",
      "date_published": "2026-07-17T20:45:28.338Z",
      "date_updated": "2026-07-20T13:46:20.930Z",
      "publisher": "GitHub_M",
      "title": "view_component: Reused Component Instances Retain Stale Render Context",
      "affected": {
        "vendors": [
          "ViewComponent"
        ],
        "products": [
          {
            "vendor": "ViewComponent",
            "product": "view_component"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-488",
          "name": "Exposure of Data Element to Wrong Session",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-668",
          "name": "Exposure of Resource to Wrong Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16266
      },
      "nvd": {
        "published": "2026-07-17T21:17:08.907",
        "lastModified": "2026-07-29T15:43:39.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54497",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A reused component instance retains helpers, request and tenant context from an earlier render and can apply that stale authority to a later request.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-488",
          "CWE-668"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ViewComponent/view_component/security/advisories/GHSA-9h85-g7w3-rh49",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ViewComponent/view_component/commit/6796b2e89d0bd7b9d7d763a86275e5334731dd61",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ViewComponent/view_component/releases/tag/v4.12.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 739,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54498",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T18:01:15.511Z",
      "date_published": "2026-07-17T20:46:52.176Z",
      "date_updated": "2026-07-20T17:38:56.324Z",
      "publisher": "GitHub_M",
      "title": "view_component: around_render HTML-Safety Bypass",
      "affected": {
        "vendors": [
          "ViewComponent"
        ],
        "products": [
          {
            "vendor": "ViewComponent",
            "product": "view_component"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23626
      },
      "nvd": {
        "published": "2026-07-17T21:17:09.043",
        "lastModified": "2026-07-29T15:42:39.397",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54498",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ViewComponent/view_component/security/advisories/GHSA-97jw-64cj-jc58",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ViewComponent/view_component/commit/48e5fd2d602344c7d33019fbc5c8b087e315bb78",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ViewComponent/view_component/commit/6796b2e89d0bd7b9d7d763a86275e5334731dd61",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ViewComponent/view_component/releases/tag/v4.12.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 680,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T18:01:15.511Z",
      "date_published": "2026-07-08T22:23:02.664Z",
      "date_updated": "2026-07-09T13:13:28.368Z",
      "publisher": "GitHub_M",
      "title": "Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders",
      "affected": {
        "vendors": [
          "stanfordnlp"
        ],
        "products": [
          {
            "vendor": "stanfordnlp",
            "product": "stanza"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-676",
          "name": "Use of Potentially Dangerous Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27033
      },
      "nvd": {
        "published": "2026-07-08T23:16:54.690",
        "lastModified": "2026-07-13T14:57:10.527",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54499",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "stanza deserializes attacker-controlled data into object behavior that can execute in the receiving process.",
        "basis": [
          "CNA",
          "CWE-502",
          "CWE-676"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/stanfordnlp/stanza/security/advisories/GHSA-v5jw-96jm-7h2c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/stanfordnlp/stanza/pull/1587",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/stanfordnlp/stanza/commit/b745008c68c9e50ccb5acd537cb6f2453f8b7ad4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/stanfordnlp/stanza/releases/tag/v1.12.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54522",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T18:40:01.651Z",
      "date_published": "2026-07-30T16:33:06.080Z",
      "date_updated": "2026-07-30T17:39:15.020Z",
      "publisher": "GitHub_M",
      "title": "MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure",
      "affected": {
        "vendors": [
          "msgpack"
        ],
        "products": [
          {
            "vendor": "msgpack",
            "product": "msgpack-ruby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02108
      },
      "nvd": {
        "published": "2026-07-30T17:16:33.030",
        "lastModified": "2026-07-30T19:27:23.630",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54522",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Buffer#clear returns a page to a shared pool while retaining stale pointers that later alias another buffer's storage.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/msgpack/msgpack-ruby/security/advisories/GHSA-4mrv-5p47-p938",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/msgpack/msgpack-ruby/commit/5627d71606b565641d2dd501b82aae862f4abe90",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 446,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54526",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T18:40:01.651Z",
      "date_published": "2026-07-16T19:07:30.804Z",
      "date_updated": "2026-07-17T13:57:43.413Z",
      "publisher": "GitHub_M",
      "title": "Argo Workflows: Incomplete fix for CVE-2026-31892: ArtifactGC.PodSpecPatch bypass of Strict/Secure templateReferencing",
      "affected": {
        "vendors": [
          "argoproj"
        ],
        "products": [
          {
            "vendor": "argoproj",
            "product": "argo-workflows"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00363,
        "percentile": 0.28984
      },
      "nvd": {
        "published": "2026-07-16T19:16:50.373",
        "lastModified": "2026-07-30T14:28:18.717",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54526",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ArtifactGC is allowlisted as a whole, allowing a nested PodSpecPatch to create a privileged pod beyond the intended action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/argoproj/argo-workflows/security/advisories/GHSA-48p8-g2fx-3wwm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-workflows/commit/277e9cef0ad16d7eaaab253573d0695951a65dbd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-workflows/commit/358cc3968c8f06f1be0967e41df191088db0b662",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-workflows/releases/tag/v3.7.15",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/argoproj/argo-workflows/releases/tag/v4.0.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1123,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T18:40:01.651Z",
      "date_published": "2026-07-08T21:03:01.698Z",
      "date_updated": "2026-07-09T14:16:09.781Z",
      "publisher": "GitHub_M",
      "title": "JupyterLab Git: Stored XSS leading to RCE",
      "affected": {
        "vendors": [
          "jupyterlab"
        ],
        "products": [
          {
            "vendor": "jupyterlab",
            "product": "jupyterlab-git"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28806
      },
      "nvd": {
        "published": "2026-07-08T21:16:49.273",
        "lastModified": "2026-07-15T20:46:01.510",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54527",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PlainTextDiff.createHeader inserts a Git filename into innerHTML without escaping it for HTML context.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-f962-v9hr-pfg5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/jupyterlab/jupyterlab-git/commit/c6d37b88f36aa59aee317930b95e427fb9d6b09b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jupyterlab/jupyterlab-git/releases/tag/v0.54.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 361,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54528",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T18:40:01.651Z",
      "date_published": "2026-07-08T21:04:18.613Z",
      "date_updated": "2026-07-09T13:04:34.325Z",
      "publisher": "GitHub_M",
      "title": "jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories",
      "affected": {
        "vendors": [
          "jupyterlab"
        ],
        "products": [
          {
            "vendor": "jupyterlab",
            "product": "jupyterlab-git"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-178",
          "name": "Improper Handling of Case Sensitivity",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.2769
      },
      "nvd": {
        "published": "2026-07-08T21:16:49.407",
        "lastModified": "2026-07-15T20:42:15.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54528",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "jupyterlab-git compares a protected path with case-sensitive rules on a case-insensitive filesystem.",
        "basis": [
          "CNA",
          "CWE-178"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-436q-jwfr-rm2h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/jupyterlab/jupyterlab-git/commit/460035275b5963dc96e364e60ba6a73717fbd033",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jupyterlab/jupyterlab-git/releases/tag/v0.54.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T18:40:01.652Z",
      "date_published": "2026-07-20T16:57:32.738Z",
      "date_updated": "2026-07-20T18:48:02.307Z",
      "publisher": "GitHub_M",
      "title": "xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER",
      "affected": {
        "vendors": [
          "neutrinolabs"
        ],
        "products": [
          {
            "vendor": "neutrinolabs",
            "product": "xrdp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31159
      },
      "nvd": {
        "published": "2026-07-20T17:17:59.723",
        "lastModified": "2026-07-22T20:06:37.757",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54538",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "xrdp accepts a crafted totalLength that prevents its parser pointer from advancing and leaves a worker in an infinite CPU loop.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9j3q-9mvw-qv7j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 791,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54540",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:04:14.455Z",
      "date_published": "2026-07-27T17:53:53.891Z",
      "date_updated": "2026-07-27T18:36:26.962Z",
      "publisher": "GitHub_M",
      "title": "Authenticated terminal command whitelist bypass in Pheditor",
      "affected": {
        "vendors": [
          "pheditor"
        ],
        "products": [
          {
            "vendor": "pheditor",
            "product": "pheditor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00712,
        "percentile": 0.50049
      },
      "nvd": {
        "published": "2026-07-27T18:16:56.580",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54540",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pheditor accepts a command whose prefix is allowed and passes the rest to shell_exec, so shell substitution syntax executes commands outside the whitelist.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pheditor/pheditor/security/advisories/GHSA-9643-6xjp-vx57",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pheditor/pheditor/releases/tag/2.0.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 579,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54545",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:04:14.455Z",
      "date_published": "2026-07-28T14:43:45.808Z",
      "date_updated": "2026-07-28T16:09:23.417Z",
      "publisher": "GitHub_M",
      "title": "@wakaru/cli arbitrary file write during bundle unpack",
      "affected": {
        "vendors": [
          "pionxzh"
        ],
        "products": [
          {
            "vendor": "pionxzh",
            "product": "wakaru"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04623
      },
      "nvd": {
        "published": "2026-07-28T16:18:59.327",
        "lastModified": "2026-07-30T19:16:52.210",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54545",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled path is used without confinement to the intended directory, allowing file access outside that namespace.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pionxzh/wakaru/security/advisories/GHSA-7wpj-vvmv-pgm8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pionxzh/wakaru/commit/1d30383b20a6f768786b8ada2f1b0945de13c316",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pionxzh/wakaru/releases/tag/v1.4.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 621,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54560",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:04:14.457Z",
      "date_published": "2026-07-15T14:40:24.765Z",
      "date_updated": "2026-07-15T15:16:35.699Z",
      "publisher": "GitHub_M",
      "title": "Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim",
      "affected": {
        "vendors": [
          "cloudreve"
        ],
        "products": [
          {
            "vendor": "cloudreve",
            "product": "cloudreve"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16012
      },
      "nvd": {
        "published": "2026-07-15T15:16:44.840",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54560",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cloudreve omits client_id from access tokens, so the verifier does not load scopes and RequiredScopes treats a low-scope token as an unrestricted session.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/commit/ed20843dc3df20a25fcaf6b538647e11c4d68d87",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.16.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 519,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54562",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:04:14.457Z",
      "date_published": "2026-07-15T14:37:37.176Z",
      "date_updated": "2026-07-15T15:00:16.053Z",
      "publisher": "GitHub_M",
      "title": "Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses",
      "affected": {
        "vendors": [
          "cloudreve"
        ],
        "products": [
          {
            "vendor": "cloudreve",
            "product": "cloudreve"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.1565
      },
      "nvd": {
        "published": "2026-07-15T15:16:44.977",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54562",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The cloudreve server fetches an attacker-selected network destination without enforcing the intended destination policy.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-x756-g4x3-c64m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/commit/aaebf317a78f2413d74afd66c21a1f3143711312",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.16.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 504,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54563",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:04:14.457Z",
      "date_published": "2026-07-15T14:38:54.129Z",
      "date_updated": "2026-07-15T15:34:04.861Z",
      "publisher": "GitHub_M",
      "title": "Cloudreve: Path Traversal / Broken Access Control in Cloudreve WebDAV (`/dav`) — scoped DAV credential escapes its configured account root",
      "affected": {
        "vendors": [
          "cloudreve"
        ],
        "products": [
          {
            "vendor": "cloudreve",
            "product": "cloudreve"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08418
      },
      "nvd": {
        "published": "2026-07-15T15:16:45.100",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54563",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A decoded traversal pathname escapes the configured DAV root during filesystem resolution.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w5fv-7x5q-g8qp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 534,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54568",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:15:27.343Z",
      "date_published": "2026-07-16T15:32:06.556Z",
      "date_updated": "2026-07-16T18:03:30.788Z",
      "publisher": "GitHub_M",
      "title": "Microsoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE Client to Read Another Device's system_info",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "UFO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00536,
        "percentile": 0.42189
      },
      "nvd": {
        "published": "2026-07-16T16:19:13.220",
        "lastModified": "2026-07-16T19:16:50.500",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54568",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The UFO request path accepts an attacker-selected object identifier without binding that object to the caller's tenant, owner, or permitted scope.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/UFO/security/advisories/GHSA-hc27-j4p9-qm2x",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/UFO/commit/2558da4e7dd05096aa6b489eca64efed96126713",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/UFO/releases/tag/3.0.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 499,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54572",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:15:27.343Z",
      "date_published": "2026-07-14T21:37:41.882Z",
      "date_updated": "2026-07-15T12:43:01.494Z",
      "publisher": "GitHub_M",
      "title": "rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote",
      "affected": {
        "vendors": [
          "rclone"
        ],
        "products": [
          {
            "vendor": "rclone",
            "product": "rclone"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00309,
        "percentile": 0.2327
      },
      "nvd": {
        "published": "2026-07-14T22:17:16.533",
        "lastModified": "2026-07-17T03:13:56.627",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54572",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "rclone recreates archive symlinks without verifying that their targets remain inside the destination tree.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rclone/rclone/commit/1154afebee986180b489084d38e2a0c578751498",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rclone/rclone/releases/tag/v1.74.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 476,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54574",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:15:27.343Z",
      "date_published": "2026-07-29T16:32:15.576Z",
      "date_updated": "2026-07-29T19:24:47.953Z",
      "publisher": "GitHub_M",
      "title": "`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive",
      "affected": {
        "vendors": [
          "termux"
        ],
        "products": [
          {
            "vendor": "termux",
            "product": "proot-distro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-61",
          "name": "UNIX Symbolic Link (Symlink) Following",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04262
      },
      "nvd": {
        "published": "2026-07-29T17:16:52.743",
        "lastModified": "2026-07-30T20:07:01.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54574",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _apply_layer() in proot_distro/helpers/docker.py without validating archive-controlled symlink targets in member.linkname, allowing a malicious archive to plant an absolute host-path symlink and write files through it onto the host filesystem.",
        "basis": [
          "CNA",
          "CWE-61"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/termux/proot-distro/security/advisories/GHSA-9xq3-3fqg-4vg7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/termux/proot-distro/commit/a96d7a9667f38e45d812614852ee3915d1c0ae45",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/termux/proot-distro/releases/tag/v5.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54590",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:45:23.538Z",
      "date_published": "2026-07-08T20:36:45.258Z",
      "date_updated": "2026-07-10T15:00:21.849Z",
      "publisher": "GitHub_M",
      "title": "AsyncSSH AuthorizedKeysFile username substitution bypass through ~ and environment expansion",
      "affected": {
        "vendors": [
          "ronf"
        ],
        "products": [
          {
            "vendor": "ronf",
            "product": "asyncssh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.208
      },
      "nvd": {
        "published": "2026-07-08T21:16:49.523",
        "lastModified": "2026-07-10T19:22:24.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54590",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AsyncSSH checks an AuthorizedKeysFile template before expanding ~ or environment variables, allowing the later resolved path to escape the intended directory.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ronf/asyncssh/security/advisories/GHSA-qr67-gv47-xwwh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ronf/asyncssh/commit/3d515ba9ba0cd9990d248bdf62bcf05d51261a88",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ronf/asyncssh/releases/tag/v2.23.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 518,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54591",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:45:23.539Z",
      "date_published": "2026-07-08T20:33:57.420Z",
      "date_updated": "2026-07-09T14:40:52.505Z",
      "publisher": "GitHub_M",
      "title": "AsyncSSH: SCP Path Traversal to Arbitrary File Write",
      "affected": {
        "vendors": [
          "ronf"
        ],
        "products": [
          {
            "vendor": "ronf",
            "product": "asyncssh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23691
      },
      "nvd": {
        "published": "2026-07-08T21:16:49.657",
        "lastModified": "2026-07-10T19:10:59.333",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54591",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AsyncSSH's SCP receive path accepts traversal components and writes the received file outside the requested destination directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ronf/asyncssh/security/advisories/GHSA-2wxc-x7rj-hg8f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ronf/asyncssh/commit/d730803b8e4e94c20c7580d90f94d1e05f9f58de",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ronf/asyncssh/releases/tag/v2.23.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54593",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:45:23.539Z",
      "date_published": "2026-07-28T15:42:56.971Z",
      "date_updated": "2026-07-28T16:39:43.359Z",
      "publisher": "GitHub_M",
      "title": "Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions",
      "affected": {
        "vendors": [
          "pterodactyl"
        ],
        "products": [
          {
            "vendor": "pterodactyl",
            "product": "panel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1259",
          "name": "Improper Restriction of Security Token Assignment",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1270",
          "name": "Generation of Incorrect Security Tokens",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00357,
        "percentile": 0.28438
      },
      "nvd": {
        "published": "2026-07-28T16:19:00.097",
        "lastModified": "2026-07-30T19:29:19.027",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54593",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Wings verifies the JWT signature and common IDs but not the token's intended purpose, allowing a lower-privilege WebSocket or download token to authorize file upload.",
        "basis": [
          "CNA",
          "CWE-1259",
          "CWE-1270"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pterodactyl/panel/security/advisories/GHSA-8r6w-3qq5-4p4r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pterodactyl/panel/pull/5636",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pterodactyl/panel/commit/7ffcd636310bb72b54bac3280d2a15e727feded7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pterodactyl/wings/commit/d0ddc80844479302abdaf9654de3bacd511c0f5c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 790,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54601",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:45:23.539Z",
      "date_published": "2026-07-07T21:16:12.976Z",
      "date_updated": "2026-07-08T13:53:13.863Z",
      "publisher": "GitHub_M",
      "title": "FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusion",
      "affected": {
        "vendors": [
          "labring"
        ],
        "products": [
          {
            "vendor": "labring",
            "product": "FastGPT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15932
      },
      "nvd": {
        "published": "2026-07-07T22:16:53.060",
        "lastModified": "2026-07-08T15:07:37.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54601",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "reTrainingCollection lets a tenant persist another tenant's datasetId, leaving downstream authorization checks to resolve ownership from inconsistent object IDs.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/labring/FastGPT/security/advisories/GHSA-qxcq-48gr-93pj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/pull/7071",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/commit/54a53e7d4399f1dfa2913394442c3cf6de672fb3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/releases/tag/v4.15.0-beta4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54602",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:45:23.540Z",
      "date_published": "2026-07-07T21:24:20.359Z",
      "date_updated": "2026-07-08T13:47:36.790Z",
      "publisher": "GitHub_M",
      "title": "FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecord",
      "affected": {
        "vendors": [
          "labring"
        ],
        "products": [
          {
            "vendor": "labring",
            "product": "FastGPT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13581
      },
      "nvd": {
        "published": "2026-07-07T22:16:53.217",
        "lastModified": "2026-07-08T15:07:37.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54602",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "getRecord authenticates the caller but looks up traces by requestId without constraining the lookup to the caller's team.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/labring/FastGPT/security/advisories/GHSA-6vx6-f72r-74cg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/commit/60c62b7af8269c826885b541bb56e6e5c424c11a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 379,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54603",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:45:23.540Z",
      "date_published": "2026-07-28T16:29:03.566Z",
      "date_updated": "2026-07-29T13:52:49.325Z",
      "publisher": "GitHub_M",
      "title": "OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host",
      "affected": {
        "vendors": [
          "ruby-oauth"
        ],
        "products": [
          {
            "vendor": "ruby-oauth",
            "product": "oauth2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18768
      },
      "nvd": {
        "published": "2026-07-28T17:16:52.227",
        "lastModified": "2026-07-29T14:16:31.080",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54603",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OAuth2 follows a protocol-relative redirect to a new authority while retaining the bearer Authorization header for the redirected request.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ruby-oauth/oauth2/security/advisories/GHSA-pp92-crg2-gfv9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ruby-oauth/oauth2/commit/0f0a474f1b38453e119e660c2daca742d4378ce9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ruby-oauth/oauth2/releases/tag/v2.0.22",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 375,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54605",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:45:23.540Z",
      "date_published": "2026-07-28T16:26:27.705Z",
      "date_updated": "2026-07-28T17:37:21.560Z",
      "publisher": "GitHub_M",
      "title": "OAuth: Cross-origin token-request redirects can expose signed request metadata",
      "affected": {
        "vendors": [
          "ruby-oauth"
        ],
        "products": [
          {
            "vendor": "ruby-oauth",
            "product": "oauth"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03164
      },
      "nvd": {
        "published": "2026-07-28T17:16:52.367",
        "lastModified": "2026-07-28T18:17:22.090",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54605",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OAuth client follows a cross-origin token-response redirect while forwarding signed request metadata, including the Authorization header, to the new host.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ruby-oauth/oauth/security/advisories/GHSA-prq8-7wvh-44qh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ruby-oauth/oauth/commit/d069dc8c4c9631947451215f07460d6cdf0caf3f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ruby-oauth/oauth/releases/tag/v1.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54607",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:45:23.540Z",
      "date_published": "2026-07-07T21:20:43.617Z",
      "date_updated": "2026-07-08T13:48:51.954Z",
      "publisher": "GitHub_M",
      "title": "FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard)",
      "affected": {
        "vendors": [
          "labring"
        ],
        "products": [
          {
            "vendor": "labring",
            "product": "FastGPT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.1497
      },
      "nvd": {
        "published": "2026-07-07T22:16:53.357",
        "lastModified": "2026-07-08T15:07:37.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54607",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The FastGPT request path lets a caller choose a server-side destination outside the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/labring/FastGPT/security/advisories/GHSA-72hf-5382-2mq9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/pull/7073",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/commit/1d7b8768aecd53ae59372fd68b10af0e80722c79",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/releases/tag/v4.15.0-beta4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 445,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54609",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T19:45:23.540Z",
      "date_published": "2026-07-28T16:36:37.938Z",
      "date_updated": "2026-07-28T17:07:15.080Z",
      "publisher": "GitHub_M",
      "title": "QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding",
      "affected": {
        "vendors": [
          "Quiet-Terminal-Interactive"
        ],
        "products": [
          {
            "vendor": "Quiet-Terminal-Interactive",
            "product": "QTINeon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-406",
          "name": "Insufficient Control of Network Message Volume (Network Amplification)",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17959
      },
      "nvd": {
        "published": "2026-07-28T17:16:52.507",
        "lastModified": "2026-07-30T19:59:01.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54609",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The relay forwards unauthenticated reconnect packets to the host without a rate or amplification bound.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-406",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Quiet-Terminal-Interactive/QTINeon/security/advisories/GHSA-85rg-p3fr-xc2f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 365,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54619",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:07:02.184Z",
      "date_published": "2026-07-28T16:21:20.943Z",
      "date_updated": "2026-07-28T19:33:33.444Z",
      "publisher": "GitHub_M",
      "title": "sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity",
      "affected": {
        "vendors": [
          "sparklemotion"
        ],
        "products": [
          {
            "vendor": "sparklemotion",
            "product": "sqlite3-ruby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.013
      },
      "nvd": {
        "published": "2026-07-28T17:16:52.650",
        "lastModified": "2026-07-30T19:31:43.780",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54619",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In sqlite3-ruby, code retains or reuses an object after the lifetime transition that frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sparklemotion/sqlite3-ruby/security/advisories/GHSA-28hh-pr2h-2w89",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/sparklemotion/sqlite3-ruby/pull/710",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sparklemotion/sqlite3-ruby/commit/2bd436d17f77cdd4c31b00fe9d50b0d21cbaf033",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sparklemotion/sqlite3-ruby/releases/tag/v2.9.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54620",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:07:02.184Z",
      "date_published": "2026-07-28T16:23:38.389Z",
      "date_updated": "2026-07-28T17:27:04.382Z",
      "publisher": "GitHub_M",
      "title": "sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks",
      "affected": {
        "vendors": [
          "sparklemotion"
        ],
        "products": [
          {
            "vendor": "sparklemotion",
            "product": "sqlite3-ruby"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.013
      },
      "nvd": {
        "published": "2026-07-28T17:16:52.790",
        "lastModified": "2026-07-30T19:31:43.780",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54620",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "sqlite3-ruby retains or reuses an object after its storage has been freed, allowing later processing to access invalid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sparklemotion/sqlite3-ruby/security/advisories/GHSA-j7fr-3v8c-3qc3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/sparklemotion/sqlite3-ruby/pull/711",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sparklemotion/sqlite3-ruby/commit/b24e1e6076528b7f95f99acf7a81c70d0004c726",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sparklemotion/sqlite3-ruby/releases/tag/v2.9.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 261,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54621",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:07:02.184Z",
      "date_published": "2026-07-28T21:35:27.863Z",
      "date_updated": "2026-07-29T12:34:35.056Z",
      "publisher": "GitHub_M",
      "title": "`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03978
      },
      "nvd": {
        "published": "2026-07-28T22:17:39.930",
        "lastModified": "2026-07-30T20:02:12.943",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54621",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A carriage return in a GraphQL Union description terminates the generated Python comment and injects executable Python into the output model.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-j884-q54q-mmx3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/aec47bc414779f4a9992b3919c8f7663afd6c988",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.60.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54635",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:07:02.185Z",
      "date_published": "2026-07-28T17:09:08.372Z",
      "date_updated": "2026-07-28T17:31:13.617Z",
      "publisher": "GitHub_M",
      "title": "pytonapi has a Webhook Custom Path Authentication Bypass",
      "affected": {
        "vendors": [
          "nessshon"
        ],
        "products": [
          {
            "vendor": "nessshon",
            "product": "tonapi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0042,
        "percentile": 0.34602
      },
      "nvd": {
        "published": "2026-07-28T18:17:22.427",
        "lastModified": "2026-07-30T20:02:12.943",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54635",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The webhook dispatcher stores bearer tokens only for default paths, so a documented custom path resolves to no token and skips authentication.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nessshon/tonapi/security/advisories/GHSA-3fcr-jvgp-7f58",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nessshon/tonapi/commit/854222b7ee68d3fb7b4d6d899d200f388483bd86",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nessshon/tonapi/releases/tag/v2.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "host": "",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 640,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54638",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:07:02.186Z",
      "date_published": "2026-07-28T22:14:53.550Z",
      "date_updated": "2026-07-29T14:20:26.682Z",
      "publisher": "GitHub_M",
      "title": "td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode",
      "affected": {
        "vendors": [
          "gotd"
        ],
        "products": [
          {
            "vendor": "gotd",
            "product": "td"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27231
      },
      "nvd": {
        "published": "2026-07-28T23:17:08.617",
        "lastModified": "2026-07-29T15:16:24.990",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54638",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "proto.UnencryptedMessage.Decode allocates attacker-specified dataLen bytes before checking how much packet data remains.",
        "basis": [
          "CNA",
          "CWE-770",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gotd/td/security/advisories/GHSA-whmm-qj9r-wvr2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gotd/td/issues/1711",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gotd/td/commit/9d5d1f31ea5022d9798d84ccce15de2e91ba6baa",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gotd/td/releases/tag/v0.145.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54650",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.198Z",
      "date_published": "2026-07-28T22:20:36.566Z",
      "date_updated": "2026-07-29T14:21:36.367Z",
      "publisher": "GitHub_M",
      "title": "openhole-server vulnerable to path traversal via URL-decoded request path",
      "affected": {
        "vendors": [
          "bablilayoub"
        ],
        "products": [
          {
            "vendor": "bablilayoub",
            "product": "openhole"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28804
      },
      "nvd": {
        "published": "2026-07-28T23:17:08.763",
        "lastModified": "2026-07-29T15:16:25.093",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54650",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "openhole forwards a decoded URL path instead of the preserved request target, allowing encoded dot segments to cross the tunneled service's path boundary.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bablilayoub/openhole/security/advisories/GHSA-fh2f-xfxc-q9cc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bablilayoub/openhole/commit/a28c27adde2a7ed0c347b730c8707208c0f78ed3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bablilayoub/openhole/releases/tag/v0.1.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 393,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54652",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.199Z",
      "date_published": "2026-07-08T14:52:42.752Z",
      "date_updated": "2026-07-08T15:20:23.777Z",
      "publisher": "GitHub_M",
      "title": "Frigate viewer can read logs exposing admin and camera credentials",
      "affected": {
        "vendors": [
          "blakeblackshear"
        ],
        "products": [
          {
            "vendor": "blakeblackshear",
            "product": "frigate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-598",
          "name": "Use of HTTP Request With Sensitive Query String",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13988
      },
      "nvd": {
        "published": "2026-07-08T15:16:29.390",
        "lastModified": "2026-07-08T16:16:30.903",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54652",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Frigate allows the viewer role to download service logs that are intended for stronger roles and that can contain credentials or tokens.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-532",
          "CWE-598",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/blakeblackshear/frigate/security/advisories/GHSA-c4qf-xxq4-vf55",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/blakeblackshear/frigate/commit/68e8afd35c76f05f68de47ee9588d2c91796de4b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/blakeblackshear/frigate/commit/bd1fc1cc72cd4fa371464a087cbf3d7f3142edc6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 3,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54653",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.199Z",
      "date_published": "2026-07-28T21:48:04.619Z",
      "date_updated": "2026-07-29T13:27:46.750Z",
      "publisher": "GitHub_M",
      "title": "`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00349,
        "percentile": 0.2762
      },
      "nvd": {
        "published": "2026-07-28T22:17:40.077",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54653",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The generator emits an attacker-controlled default_factory schema value as executable Python in generated models, so importing the generated module evaluates the expression.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-386q-5hp3-95m9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/17fc235e234cbcfaaadef8c74cb72c9687db0d1d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.60.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://gist.github.com/thegr1ffyn/9648b0fe4fcf7d569ac8e61dd11eebaf",
          "host": "gist.github.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 578,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54654",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.199Z",
      "date_published": "2026-07-28T21:22:52.070Z",
      "date_updated": "2026-07-29T15:24:23.911Z",
      "publisher": "GitHub_M",
      "title": "`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03978
      },
      "nvd": {
        "published": "2026-07-28T22:17:40.217",
        "lastModified": "2026-07-30T20:02:44.977",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54654",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A carriage return in extra-template-data escapes a generated Python comment and injects executable code into the generated model.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-wjv6-jcfj-mf9r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/b73abb5cd703a50471b8950bbd3bd0b82ad71de7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.60.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 805,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54655",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.199Z",
      "date_published": "2026-07-28T21:33:45.438Z",
      "date_updated": "2026-07-29T12:47:08.130Z",
      "publisher": "GitHub_M",
      "title": "`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04261
      },
      "nvd": {
        "published": "2026-07-28T22:17:40.360",
        "lastModified": "2026-07-30T20:02:12.943",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54655",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The JSON-Schema x-python-type extension is inserted into generated Python annotations without restricting expressions that execute when the module is imported.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-m34r-v34r-rf9q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/2c93c9b712f43391dcfa975a1e4aa0b7c93ccbba",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.60.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54656",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.199Z",
      "date_published": "2026-07-28T21:43:56.286Z",
      "date_updated": "2026-07-29T14:12:17.588Z",
      "publisher": "GitHub_M",
      "title": "`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04658
      },
      "nvd": {
        "published": "2026-07-28T22:17:40.507",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54656",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches a dynamic code-generation or evaluation path without an effective allowlist, allowing it to run as code.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-8m8r-38jm-f355",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/a43d02906111a2fdcaf13ee5b62eb2da85376f19",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.60.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54658",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.199Z",
      "date_published": "2026-07-28T22:18:48.800Z",
      "date_updated": "2026-07-29T12:31:52.584Z",
      "publisher": "GitHub_M",
      "title": "@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution",
      "affected": {
        "vendors": [
          "hypequery"
        ],
        "products": [
          {
            "vendor": "hypequery",
            "product": "hypequery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32399
      },
      "nvd": {
        "published": "2026-07-28T23:17:08.913",
        "lastModified": "2026-07-30T20:02:12.943",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54658",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hypequery/hypequery/security/advisories/GHSA-6wcc-39rp-hh9p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hypequery/hypequery/commit/4dfa9d77d70a08b970e722268b75ca7d13db0bdf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hypequery/hypequery/blob/main/packages/clickhouse/CHANGELOG.md#202",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hypequery/hypequery/releases/tag/@hypequery/clickhouse@2.0.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 370,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54659",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.199Z",
      "date_published": "2026-07-28T22:25:35.231Z",
      "date_updated": "2026-07-29T13:06:59.870Z",
      "publisher": "GitHub_M",
      "title": "Pagy I18n locale option is not validated before being used in a file path",
      "affected": {
        "vendors": [
          "ddnexus"
        ],
        "products": [
          {
            "vendor": "ddnexus",
            "product": "pagy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00368,
        "percentile": 0.29518
      },
      "nvd": {
        "published": "2026-07-28T23:17:09.067",
        "lastModified": "2026-07-30T19:19:45.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54659",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "pagy accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ddnexus/pagy/security/advisories/GHSA-2xmw-f8j8-wfxc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ddnexus/pagy/pull/908",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ddnexus/pagy/commit/efcf09690e9fa7d7abdfb987b785a55f87e287df",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ddnexus/pagy/releases/tag/43.5.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54660",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.199Z",
      "date_published": "2026-07-29T14:21:34.295Z",
      "date_updated": "2026-07-30T13:43:08.019Z",
      "publisher": "GitHub_M",
      "title": "swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`",
      "affected": {
        "vendors": [
          "acacode"
        ],
        "products": [
          {
            "vendor": "acacode",
            "product": "swagger-typescript-api"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15614
      },
      "nvd": {
        "published": "2026-07-29T15:16:25.300",
        "lastModified": "2026-07-30T19:23:45.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54660",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Remote schema resolution forwards a developer or CI authorization token to every cross-origin $ref URL supplied by the specification.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-201",
          "CWE-522",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-h754-fxp7-88wx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/pull/1779",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9de",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 465,
        "referenceCount": 4,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54661",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.199Z",
      "date_published": "2026-07-29T14:30:29.903Z",
      "date_updated": "2026-07-29T15:00:20.087Z",
      "publisher": "GitHub_M",
      "title": "swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template",
      "affected": {
        "vendors": [
          "acacode"
        ],
        "products": [
          {
            "vendor": "acacode",
            "product": "swagger-typescript-api"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.1902
      },
      "nvd": {
        "published": "2026-07-29T15:16:25.440",
        "lastModified": "2026-07-30T19:23:14.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54661",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An OpenAPI server URL is inserted into EJS-generated code without separating data from executable grammar.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-94",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-38c3-wv3c-v3xj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/pull/1779",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9de",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 434,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54662",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.199Z",
      "date_published": "2026-07-29T14:26:15.992Z",
      "date_updated": "2026-07-29T15:16:06.092Z",
      "publisher": "GitHub_M",
      "title": "swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template",
      "affected": {
        "vendors": [
          "acacode"
        ],
        "products": [
          {
            "vendor": "acacode",
            "product": "swagger-typescript-api"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.1902
      },
      "nvd": {
        "published": "2026-07-29T15:16:25.577",
        "lastModified": "2026-07-30T19:23:14.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54662",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An OpenAPI server URL is interpolated into an EJS TypeScript template without escaping and becomes executable generated code.",
        "basis": [
          "CNA record",
          "CWE-1336",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-hqj5-cw9f-rx67",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/pull/1779",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9de",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54663",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.199Z",
      "date_published": "2026-07-29T14:28:33.360Z",
      "date_updated": "2026-07-29T14:58:32.750Z",
      "publisher": "GitHub_M",
      "title": "swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`",
      "affected": {
        "vendors": [
          "acacode"
        ],
        "products": [
          {
            "vendor": "acacode",
            "product": "swagger-typescript-api"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07877
      },
      "nvd": {
        "published": "2026-07-29T15:16:25.713",
        "lastModified": "2026-07-30T19:23:14.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54663",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "swagger-typescript-api accepts an attacker-controlled server request target without constraining it to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-441",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-x36r-4347-pm5x",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/pull/1779",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9de",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 503,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54664",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T20:16:46.199Z",
      "date_published": "2026-07-29T14:32:41.168Z",
      "date_updated": "2026-07-30T15:19:53.209Z",
      "publisher": "GitHub_M",
      "title": "swagger-typescript-api vulnerable to code injection via unescaped enum string values",
      "affected": {
        "vendors": [
          "acacode"
        ],
        "products": [
          {
            "vendor": "acacode",
            "product": "swagger-typescript-api"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.1902
      },
      "nvd": {
        "published": "2026-07-29T15:16:25.850",
        "lastModified": "2026-07-30T19:23:45.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54664",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The generator renders unescaped OpenAPI enum values into TypeScript declarations that execute when the generated module is imported.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-94",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-5f94-x226-ccpm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/pull/1779",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9de",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 496,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54666",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:53:58.560Z",
      "date_published": "2026-07-29T14:34:48.668Z",
      "date_updated": "2026-07-30T13:47:57.135Z",
      "publisher": "GitHub_M",
      "title": "swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies",
      "affected": {
        "vendors": [
          "acacode"
        ],
        "products": [
          {
            "vendor": "acacode",
            "product": "swagger-typescript-api"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20804
      },
      "nvd": {
        "published": "2026-07-29T15:16:25.990",
        "lastModified": "2026-07-30T19:23:45.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54666",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The generator inserts an OpenAPI path containing template-literal interpolation into generated JavaScript without escaping the code context.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-94",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-w284-33mx-6g9v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/pull/1779",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9de",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 479,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54680",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:53:58.561Z",
      "date_published": "2026-07-29T16:57:16.913Z",
      "date_updated": "2026-07-30T13:56:07.649Z",
      "publisher": "GitHub_M",
      "title": "Logging operator has Fluentd configuration injection that allows remote code execution",
      "affected": {
        "vendors": [
          "kube-logging"
        ],
        "products": [
          {
            "vendor": "kube-logging",
            "product": "logging-operator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00426,
        "percentile": 0.35067
      },
      "nvd": {
        "published": "2026-07-29T17:16:52.900",
        "lastModified": "2026-07-30T14:16:59.670",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54680",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Fluentd renderer inserts CRD strings into fluent.conf without escaping, allowing a Flow author to inject an exec output block.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kube-logging/logging-operator/security/advisories/GHSA-mjqf-28ph-426h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/kube-logging/logging-operator/commit/cf437d7f1e056c78740bf5716ac8bdebcf002425",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kube-logging/logging-operator/releases/tag/6.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:53:58.561Z",
      "date_published": "2026-07-14T21:46:29.373Z",
      "date_updated": "2026-07-15T14:31:05.749Z",
      "publisher": "GitHub_M",
      "title": "jadx: XAPK archive entries with absolute paths can plant drop-in plugins and achieve code execution on the next jadx run",
      "affected": {
        "vendors": [
          "skylot"
        ],
        "products": [
          {
            "vendor": "skylot",
            "product": "jadx"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03264
      },
      "nvd": {
        "published": "2026-07-14T22:17:16.680",
        "lastModified": "2026-07-15T20:23:47.313",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54684",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "XApkLoader resolves absolute archive entry names after a CWD-based check, allowing an entry to write outside the temporary directory and plant a loadable plugin.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/skylot/jadx/security/advisories/GHSA-gpvc-ccw7-744v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/skylot/jadx/commit/a74bb07d6eebaf4da5c2b2cbc4d3c0c3cb7517cb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/skylot/jadx/releases/tag/v1.5.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 621,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:53:58.561Z",
      "date_published": "2026-07-20T14:17:13.083Z",
      "date_updated": "2026-07-21T15:31:49.570Z",
      "publisher": "GitHub_M",
      "title": "FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel",
      "affected": {
        "vendors": [
          "gtsteffaniak"
        ],
        "products": [
          {
            "vendor": "gtsteffaniak",
            "product": "filebrowser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18963
      },
      "nvd": {
        "published": "2026-07-20T15:16:43.787",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54685",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The filebrowser path produces an attacker-observable difference that reveals a protected state or value.",
        "basis": [
          "CNA",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-7789-65hx-f26w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gtsteffaniak/filebrowser/commit/af08800667b874620edc6f44c3e2e64fec7abd85",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.3.2-beta",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 453,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:53:58.562Z",
      "date_published": "2026-07-28T21:42:06.802Z",
      "date_updated": "2026-07-29T15:24:16.907Z",
      "publisher": "GitHub_M",
      "title": "datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11222
      },
      "nvd": {
        "published": "2026-07-28T22:17:40.650",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54690",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A remote JSON Schema reference controls a server-side fetch without an allowlist for destination hosts or address ranges.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-954p-556p-r752",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/5fdba4a09f2d7a9996a504975b7ef7d63e3715bb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.61.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 566,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54691",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:58:06.562Z",
      "date_published": "2026-07-28T21:29:52.197Z",
      "date_updated": "2026-07-29T14:18:45.531Z",
      "publisher": "GitHub_M",
      "title": "datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11222
      },
      "nvd": {
        "published": "2026-07-28T22:17:40.800",
        "lastModified": "2026-07-30T20:02:44.977",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54691",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The datamodel-code-generator request path accepts an attacker-controlled destination or redirect without constraining the resolved server-side network target.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-rfr2-mq9m-x2qx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/5fdba4a09f2d7a9996a504975b7ef7d63e3715bb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.61.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54693",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:58:06.562Z",
      "date_published": "2026-07-29T16:50:39.957Z",
      "date_updated": "2026-07-29T17:54:41.535Z",
      "publisher": "GitHub_M",
      "title": "ZITADEL Users Can Self-Verify Email/Phone via API",
      "affected": {
        "vendors": [
          "zitadel"
        ],
        "products": [
          {
            "vendor": "zitadel",
            "product": "zitadel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26906
      },
      "nvd": {
        "published": "2026-07-29T17:16:53.067",
        "lastModified": "2026-07-30T20:07:01.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54693",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ZITADEL's self-management API authorizes an operation against the wrong subject or role boundary.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-jq8w-8q2f-ffm9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/90f310212d3a5075084a603bf61fed549c92956d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/a1748b2f0326ddf7be0de44b4f980ae2c07c0151",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/ed09b3df7f43e870423e4d8f2757e6894481604f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v3.4.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v4.15.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 579,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:58:06.562Z",
      "date_published": "2026-07-09T18:52:33.008Z",
      "date_updated": "2026-07-10T14:13:04.675Z",
      "publisher": "GitHub_M",
      "title": "Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID",
      "affected": {
        "vendors": [
          "pipecat-ai"
        ],
        "products": [
          {
            "vendor": "pipecat-ai",
            "product": "pipecat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29601
      },
      "nvd": {
        "published": "2026-07-09T19:17:06.540",
        "lastModified": "2026-07-13T14:20:47.763",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54695",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Prior to 1.4.0, the pipecat development runner registers a /ws WebSocket endpoint for telephony testing that accepts connections without authentication, reads an attacker-supplied callSid from a Twilio stream-start handshake in src/pipecat/runner/utils.py, and passes it to TwilioFrameSerializer so the server can issue an authenticated Twilio REST API hang-up request with the server operator's credentials; equivalent unauthenticated call-control sinks exist for Telnyx and Plivo.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pipecat-ai/pipecat/security/advisories/GHSA-j8cv-x86q-rj85",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pipecat-ai/pipecat/pull/4660",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pipecat-ai/pipecat/commit/3032da53434c5ef01d368654b3551cf21c50dec9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pipecat-ai/pipecat/commit/88440676996e5e548e1aecea5d565e1c48ccf6fa",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pipecat-ai/pipecat/releases/tag/v1.4.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 630,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:58:06.562Z",
      "date_published": "2026-07-07T21:29:23.595Z",
      "date_updated": "2026-07-08T13:02:17.049Z",
      "publisher": "GitHub_M",
      "title": "Hasura: Row-level authorization bypass on table computed fields",
      "affected": {
        "vendors": [
          "hasura"
        ],
        "products": [
          {
            "vendor": "hasura",
            "product": "graphql-engine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06652
      },
      "nvd": {
        "published": "2026-07-07T22:16:53.500",
        "lastModified": "2026-07-10T17:49:57.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54698",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table computed field (returning SETOF some_table) to infer row values that ought to be filtered for their role based on some_table's row-level permissions.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hasura/graphql-engine/security/advisories/GHSA-r27x-gc74-qmxh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 509,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54704",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:58:06.563Z",
      "date_published": "2026-07-01T21:15:37.903Z",
      "date_updated": "2026-07-02T12:23:50.336Z",
      "publisher": "GitHub_M",
      "title": "OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords",
      "affected": {
        "vendors": [
          "open-telemetry"
        ],
        "products": [
          {
            "vendor": "open-telemetry",
            "product": "opentelemetry-java-instrumentation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13078
      },
      "nvd": {
        "published": "2026-07-01T22:16:50.050",
        "lastModified": "2026-07-06T17:00:08.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54704",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The JDBC sanitizer misses double-quoted passwords in CONNECT statements and exports them as clear-text trace attributes.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java-instrumentation/security/advisories/GHSA-rwqx-fvqh-6wm4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54705",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:58:06.563Z",
      "date_published": "2026-07-29T17:21:20.414Z",
      "date_updated": "2026-07-29T17:54:49.618Z",
      "publisher": "GitHub_M",
      "title": "mathlive's Lack of Escaping of HTML allows for XSS",
      "affected": {
        "vendors": [
          "arnog"
        ],
        "products": [
          {
            "vendor": "arnog",
            "product": "mathlive"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11126
      },
      "nvd": {
        "published": "2026-07-29T18:16:54.857",
        "lastModified": "2026-07-30T20:07:01.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54705",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MathLive serializes attacker-controlled content into markup without the context-specific escaping required for the target attribute or element.",
        "basis": [
          "CNA",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/arnog/mathlive/security/advisories/GHSA-fm7p-gw32-828p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/arnog/mathlive/issues/3028",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/arnog/mathlive/commit/5fe1c46153883f9ec0249a5c8c34e64aaae9cfb8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54706",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:58:06.563Z",
      "date_published": "2026-07-31T16:30:58.062Z",
      "date_updated": "2026-07-31T19:00:44.128Z",
      "publisher": "GitHub_M",
      "title": "OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files",
      "affected": {
        "vendors": [
          "onionshare"
        ],
        "products": [
          {
            "vendor": "onionshare",
            "product": "onionshare"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15608
      },
      "nvd": {
        "published": "2026-07-31T17:16:33.723",
        "lastModified": "2026-07-31T19:17:10.430",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54706",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The filesystem operation follows an attacker-controlled link instead of constraining the final object to the intended namespace.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/onionshare/onionshare/commit/48f31cfac077fcc9c04c67c2a6dbf87d956f5eec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/onionshare/onionshare/releases/tag/v2.6.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 463,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54707",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:58:06.563Z",
      "date_published": "2026-07-31T16:28:06.628Z",
      "date_updated": "2026-07-31T23:28:15.094Z",
      "publisher": "GitHub_M",
      "title": "OnionShare Receive mode writes uploaded files even when file uploads are disabled",
      "affected": {
        "vendors": [
          "onionshare"
        ],
        "products": [
          {
            "vendor": "onionshare",
            "product": "onionshare"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13948
      },
      "nvd": {
        "published": "2026-07-31T17:16:33.870",
        "lastModified": "2026-08-01T00:17:16.933",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54707",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Receive mode writes multipart file data even when the disable_files policy says the endpoint is text-only.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/onionshare/onionshare/security/advisories/GHSA-v833-3823-cmhp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/onionshare/onionshare/commit/a090e97193efc91fbeac9dace7793ea568b83cf5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/onionshare/onionshare/releases/tag/v2.6.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 433,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54712",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:58:06.563Z",
      "date_published": "2026-07-01T21:17:44.160Z",
      "date_updated": "2026-07-02T15:41:16.104Z",
      "publisher": "GitHub_M",
      "title": "OpenTelemetry Javaagent RMI context propagation allows resource exhaustion",
      "affected": {
        "vendors": [
          "open-telemetry"
        ],
        "products": [
          {
            "vendor": "open-telemetry",
            "product": "opentelemetry-java-instrumentation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17999
      },
      "nvd": {
        "published": "2026-07-01T22:16:50.187",
        "lastModified": "2026-07-06T16:58:10.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54712",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The RMI propagation reader caps entry count but not aggregate string bytes, allowing one payload to allocate unbounded memory.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-telemetry/opentelemetry-java-instrumentation/security/advisories/GHSA-fq3f-m5qm-99f5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 695,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54714",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:58:06.564Z",
      "date_published": "2026-07-10T19:54:28.526Z",
      "date_updated": "2026-07-13T18:18:36.103Z",
      "publisher": "GitHub_M",
      "title": "Logto: XSS via unescaped RelayState in SAML auto-submit form",
      "affected": {
        "vendors": [
          "logto-io"
        ],
        "products": [
          {
            "vendor": "logto-io",
            "product": "logto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16771
      },
      "nvd": {
        "published": "2026-07-10T20:16:46.173",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54714",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Logto reflects SAML values into an auto-submit HTML form without HTML-attribute escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/logto-io/logto/security/advisories/GHSA-cpm5-w86q-w85f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/logto-io/logto/pull/9008",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/logto-io/logto/commit/209fa0a5cbe8522f9cf31873239dc6424099bb5e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/logto-io/logto/releases/tag/v1.41.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54715",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T22:58:06.564Z",
      "date_published": "2026-07-30T20:23:36.554Z",
      "date_updated": "2026-07-31T15:30:19.164Z",
      "publisher": "GitHub_M",
      "title": "GoAccess: Heap Out-of-Bounds Write in parse_browser()",
      "affected": {
        "vendors": [
          "allinurl"
        ],
        "products": [
          {
            "vendor": "allinurl",
            "product": "goaccess"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17945
      },
      "nvd": {
        "published": "2026-07-30T21:17:49.323",
        "lastModified": "2026-07-31T16:17:07.073",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54715",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "parse_browser moves a version substring past a heap allocation when a crafted token does not begin with the assumed Opera prefix.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/allinurl/goaccess/security/advisories/GHSA-qcx5-vh2x-35fr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/allinurl/goaccess/commit/81f90d9dafd6956c188dea9f944d24946d3d3351",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 469,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54719",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:07:33.231Z",
      "date_published": "2026-07-28T21:58:50.208Z",
      "date_updated": "2026-07-29T12:32:38.975Z",
      "publisher": "GitHub_M",
      "title": "goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of CVE-2026-40189)",
      "affected": {
        "vendors": [
          "goshs-labs"
        ],
        "products": [
          {
            "vendor": "goshs-labs",
            "product": "goshs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20571
      },
      "nvd": {
        "published": "2026-07-28T23:17:09.213",
        "lastModified": "2026-07-30T19:19:45.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54719",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The bulk ZIP download route omits the folder ACL and custom-auth checks used by protected file paths.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/goshs-labs/goshs/security/advisories/GHSA-rmxw-pq4x-3fvh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/goshs-labs/goshs/commit/7cf911a26ace737e1a55b7dc073e307a25f7fd1d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/goshs-labs/goshs/releases/tag/v2.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 426,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54720",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:07:33.231Z",
      "date_published": "2026-07-01T21:02:59.522Z",
      "date_updated": "2026-07-02T15:54:49.241Z",
      "publisher": "GitHub_M",
      "title": "Silverstripe Framework: Possible XSS attack through media embed",
      "affected": {
        "vendors": [
          "silverstripe"
        ],
        "products": [
          {
            "vendor": "silverstripe",
            "product": "silverstripe-framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05131
      },
      "nvd": {
        "published": "2026-07-01T21:17:03.417",
        "lastModified": "2026-07-02T17:54:15.243",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54720",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The media-from-web feature renders a crafted embed without keeping its content outside browser script grammar.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/silverstripe/silverstripe-framework/security/advisories/GHSA-gvrw-qqp5-jgc5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://www.silverstripe.org/download/security-releases/cve-2026-54720",
          "host": "www.silverstripe.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54722",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:07:33.232Z",
      "date_published": "2026-07-30T16:27:13.435Z",
      "date_updated": "2026-07-30T17:29:31.550Z",
      "publisher": "GitHub_M",
      "title": "dssrf: there a critical security bug with remove_at_symbol_in_string",
      "affected": {
        "vendors": [
          "HackingRepo"
        ],
        "products": [
          {
            "vendor": "HackingRepo",
            "product": "dssrf-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-76",
          "name": "Improper Neutralization of Equivalent Special Elements",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25345
      },
      "nvd": {
        "published": "2026-07-30T17:16:33.180",
        "lastModified": "2026-07-30T19:18:08.220",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54722",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The safety check rewrites away the URL's @ delimiter before parsing, so it validates a different host from the URL the client later requests.",
        "basis": [
          "CNA",
          "CWE-76"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/HackingRepo/dssrf-js/security/advisories/GHSA-cg4g-m8jx-vjv2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/HackingRepo/dssrf-js/issues/97",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/HackingRepo/dssrf-js/pull/98",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/HackingRepo/dssrf-js/commit/9211f91bf532433a1a1b27d946571546a63664b3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 420,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54725",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:07:33.232Z",
      "date_published": "2026-07-31T17:45:09.548Z",
      "date_updated": "2026-07-31T18:58:46.332Z",
      "publisher": "GitHub_M",
      "title": "vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API",
      "affected": {
        "vendors": [
          "bank-vaults"
        ],
        "products": [
          {
            "vendor": "bank-vaults",
            "product": "vault-secrets-webhook"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24474
      },
      "nvd": {
        "published": "2026-07-31T18:17:17.013",
        "lastModified": "2026-07-31T19:17:10.833",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54725",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "vault-secrets-webhook accepts an attacker-controlled destination without reapplying the network allowlist after URL parsing, redirects, or address resolution, allowing server-side requests to a prohibited target.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bank-vaults/vault-secrets-webhook/security/advisories/GHSA-r2v3-8gwf-7ghm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bank-vaults/vault-secrets-webhook/commit/76db45976fee0f54cafd94dffa425e6b542f65a0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bank-vaults/vault-secrets-webhook/releases/tag/v1.23.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54727",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:07:33.232Z",
      "date_published": "2026-07-29T16:41:46.521Z",
      "date_updated": "2026-07-29T18:07:46.535Z",
      "publisher": "GitHub_M",
      "title": "proot-distro has a Container Isolation Bypass via Crafted Restore Archive",
      "affected": {
        "vendors": [
          "termux"
        ],
        "products": [
          {
            "vendor": "termux",
            "product": "proot-distro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-668",
          "name": "Exposure of Resource to Wrong Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02237
      },
      "nvd": {
        "published": "2026-07-29T17:16:53.250",
        "lastModified": "2026-07-30T20:07:01.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54727",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The restore path accepts a hardlink whose source belongs to another installed container and copies that selected file across the container boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-668"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/termux/proot-distro/security/advisories/GHSA-7h3g-4w2f-fj2f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/termux/proot-distro/commit/98aff324b7d8500ff75a8ca9ac087ee636be4716",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/termux/proot-distro/releases/tag/v5.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 411,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54728",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:07:33.232Z",
      "date_published": "2026-07-16T19:18:17.637Z",
      "date_updated": "2026-07-17T13:47:18.414Z",
      "publisher": "GitHub_M",
      "title": "bunkerweb: Improper Input Validation and Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in BunkerWeb",
      "affected": {
        "vendors": [
          "bunkerity"
        ],
        "products": [
          {
            "vendor": "bunkerity",
            "product": "bunkerweb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14752
      },
      "nvd": {
        "published": "2026-07-16T20:16:45.427",
        "lastModified": "2026-07-17T18:44:13.257",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54728",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "BunkerWeb passes a low-privilege caller's Host header through a configuration-dependent UI or API path without the required validation and downstream encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bunkerity/bunkerweb/security/advisories/GHSA-254j-92cv-m443",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bunkerity/bunkerweb/commit/685ccbbe7d204132a843a7b7fd802d1bdb3f20a9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bunkerity/bunkerweb/releases/tag/v1.6.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 517,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:07:33.232Z",
      "date_published": "2026-07-31T16:58:56.571Z",
      "date_updated": "2026-07-31T17:31:00.320Z",
      "publisher": "GitHub_M",
      "title": "dssrf: any users using 1.1.1.1 DNS is impacted by SSRF",
      "affected": {
        "vendors": [
          "HackingRepo"
        ],
        "products": [
          {
            "vendor": "HackingRepo",
            "product": "dssrf-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21474
      },
      "nvd": {
        "published": "2026-07-31T18:17:17.173",
        "lastModified": "2026-07-31T18:17:17.173",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54729",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "is_url_safe treats an unresolved hostname as safe without a dns.lookup fallback, allowing a blocked local destination to pass the SSRF check.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/HackingRepo/dssrf-js/security/advisories/GHSA-5846-7qm3-r52j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/HackingRepo/dssrf-js/pull/102",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/HackingRepo/dssrf-js/commit/668c21792cd1252baf779a176aa652e2b4c0067d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54733",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:07:33.232Z",
      "date_published": "2026-07-16T14:52:03.389Z",
      "date_updated": "2026-07-16T15:35:02.951Z",
      "publisher": "GitHub_M",
      "title": "moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "o365-moodle"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00915,
        "percentile": 0.56687
      },
      "nvd": {
        "published": "2026-07-16T16:19:13.360",
        "lastModified": "2026-07-16T17:46:34.020",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54733",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Teams SSO endpoint trusts claims from a base64-decoded JWT without verifying its signature.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/o365-moodle/security/advisories/GHSA-hqjh-93qv-47v5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/o365-moodle/commit/01b2d4c2e13b06a66557527084cbf9bace655944",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/o365-moodle/commit/258872f6e2011f4efa8ebb77d2898142a9435e89",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/o365-moodle/commit/d5596655f0baaee0f11aec2e10d6f36b0bd29220",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/o365-moodle/releases/tag/v20260423_m405",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/o365-moodle/releases/tag/v20260423_m500",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/o365-moodle/releases/tag/v20260423_m501",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54735",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:07:33.233Z",
      "date_published": "2026-07-29T15:59:46.640Z",
      "date_updated": "2026-07-29T18:04:18.670Z",
      "publisher": "GitHub_M",
      "title": "prebid-server's request forgery vulnerability allows for possible host environment data extraction",
      "affected": {
        "vendors": [
          "prebid"
        ],
        "products": [
          {
            "vendor": "prebid",
            "product": "prebid-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27782
      },
      "nvd": {
        "published": "2026-07-29T16:17:54.317",
        "lastModified": "2026-07-30T20:06:04.573",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54735",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prebid bidder adapters interpolate user-supplied parameters into outbound URLs and allow server-side requests to attacker-selected or internal destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/prebid/prebid-server/security/advisories/GHSA-4p3g-4hcj-wpvx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/prebid/prebid-server/pull/4802",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/prebid/prebid-server/commit/494ac271cd4b5024df9123ef25ca3cff96390be3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/prebid/prebid-server/releases/tag/v4.4.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 496,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54736",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:07:33.233Z",
      "date_published": "2026-07-10T21:02:53.873Z",
      "date_updated": "2026-07-13T18:01:40.822Z",
      "publisher": "GitHub_M",
      "title": "Phalcon: Non-constant-time HMAC verification in `Encryption\\Crypt::decrypt` (timing side-channel)",
      "affected": {
        "vendors": [
          "phalcon"
        ],
        "products": [
          {
            "vendor": "phalcon",
            "product": "cphalcon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04448
      },
      "nvd": {
        "published": "2026-07-10T22:16:42.970",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54736",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Phalcon compares an attacker-supplied HMAC with an early-exit byte comparison, exposing a timing oracle that can recover a valid tag.",
        "basis": [
          "CNA",
          "CWE-208",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/phalcon/cphalcon/security/advisories/GHSA-8jqh-95g6-7jpj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/phalcon/cphalcon/issues/17090",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/phalcon/cphalcon/pull/17091",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/phalcon/cphalcon/commit/ad53ab1b2e7ec59b3af92b0b37b8aaa099011137",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/phalcon/cphalcon/releases/tag/v5.14.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:07:33.233Z",
      "date_published": "2026-07-31T17:48:42.670Z",
      "date_updated": "2026-07-31T19:00:41.074Z",
      "publisher": "GitHub_M",
      "title": "@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging",
      "affected": {
        "vendors": [
          "phun-ky"
        ],
        "products": [
          {
            "vendor": "phun-ky",
            "product": "defaults-deep"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17855
      },
      "nvd": {
        "published": "2026-07-31T18:17:17.330",
        "lastModified": "2026-07-31T19:17:10.957",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54737",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, allowing properties to be written to Object.prototype.",
        "basis": [
          "CNA",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/phun-ky/defaults-deep/security/advisories/GHSA-mj3g-7xcc-x4vh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/phun-ky/defaults-deep/pull/49",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/phun-ky/defaults-deep/commit/807dba930f8718f9126cad59d949b8fd3539b059",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/phun-ky/defaults-deep/releases/tag/2.0.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:12:41.965Z",
      "date_published": "2026-07-01T20:29:17.924Z",
      "date_updated": "2026-07-02T14:41:32.037Z",
      "publisher": "GitHub_M",
      "title": "Jodit Editor: Prototype pollution via Jodit.configure() / ConfigMerge",
      "affected": {
        "vendors": [
          "xdan"
        ],
        "products": [
          {
            "vendor": "xdan",
            "product": "jodit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19457
      },
      "nvd": {
        "published": "2026-07-01T21:17:03.553",
        "lastModified": "2026-07-02T15:17:04.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54756",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ConfigMerge recursively copies prototype-mutating keys from caller-supplied options into ordinary configuration objects.",
        "basis": [
          "CNA",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/xdan/jodit/security/advisories/GHSA-5957-5c94-3v7w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 648,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:12:41.966Z",
      "date_published": "2026-07-09T23:49:52.364Z",
      "date_updated": "2026-07-10T15:27:12.550Z",
      "publisher": "GitHub_M",
      "title": "Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls",
      "affected": {
        "vendors": [
          "langroid"
        ],
        "products": [
          {
            "vendor": "langroid",
            "product": "langroid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00558,
        "percentile": 0.43355
      },
      "nvd": {
        "published": "2026-07-10T00:16:33.477",
        "lastModified": "2026-07-10T16:16:33.063",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54760",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SQL guard compares raw text with a function-name regex, while PostgreSQL accepts quoted, commented, or schema-qualified spellings that evade the blocklist and still execute the function.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/langroid/langroid/security/advisories/GHSA-6xc5-4r68-67fc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 961,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:12:41.966Z",
      "date_published": "2026-07-06T20:33:36.059Z",
      "date_updated": "2026-07-08T19:42:06.759Z",
      "publisher": "GitHub_M",
      "title": "Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth",
      "affected": {
        "vendors": [
          "traefik"
        ],
        "products": [
          {
            "vendor": "traefik",
            "product": "traefik"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-178",
          "name": "Improper Handling of Case Sensitivity",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.002,
        "percentile": 0.09996
      },
      "nvd": {
        "published": "2026-07-06T21:16:56.787",
        "lastModified": "2026-07-08T20:16:52.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54763",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The service trusts attacker-controlled identity or network-origin data without authenticating its asserted source.",
        "basis": [
          "CNA",
          "CWE-178",
          "CWE-290",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/traefik/traefik/security/advisories/GHSA-x677-9fxg-v5c5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/traefik/traefik/pull/13262",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/traefik/traefik/commit/108a5264473a2cbc8f12d6d691a3c6553cdf2c1b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 720,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:12:41.966Z",
      "date_published": "2026-07-06T20:20:29.345Z",
      "date_updated": "2026-07-07T14:03:17.886Z",
      "publisher": "GitHub_M",
      "title": "ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false",
      "affected": {
        "vendors": [
          "traefik"
        ],
        "products": [
          {
            "vendor": "traefik",
            "product": "traefik"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14212
      },
      "nvd": {
        "published": "2026-07-06T21:16:56.930",
        "lastModified": "2026-07-08T03:01:46.417",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54764",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Traefik derives X-Forwarded-Port from unsanitized incoming forwarding metadata even when trustForwardHeader is false, allowing an HTTP client to present port 443 to ForwardAuth.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/traefik/traefik/security/advisories/GHSA-3q9r-p662-5j8m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/traefik/traefik/pull/13344",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/traefik/traefik/commit/7ae92d8c2c10ac04ef5a03df0ed5019ce0f44b2d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 639,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:12:41.966Z",
      "date_published": "2026-07-06T20:27:32.803Z",
      "date_updated": "2026-07-07T14:19:07.941Z",
      "publisher": "GitHub_M",
      "title": "Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port",
      "affected": {
        "vendors": [
          "traefik"
        ],
        "products": [
          {
            "vendor": "traefik",
            "product": "traefik"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11627
      },
      "nvd": {
        "published": "2026-07-06T21:16:57.067",
        "lastModified": "2026-07-08T03:01:20.093",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54765",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Routes sharing one Service and port are deduplicated without their filter identity, so one route's authorization context can be applied to another route.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/traefik/traefik/security/advisories/GHSA-6p8f-p8j2-rqmv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/traefik/traefik/pull/13367",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/traefik/traefik/commit/8aada7a7d52e4588a75386d8b86d270f6fe8d549",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/traefik/traefik/releases/tag/v3.7.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 823,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.713Z",
      "date_published": "2026-07-31T22:24:40.639Z",
      "date_updated": "2026-08-03T20:36:22.466Z",
      "publisher": "GitHub_M",
      "title": "WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)",
      "affected": {
        "vendors": [
          "wp-graphql"
        ],
        "products": [
          {
            "vendor": "wp-graphql",
            "product": "wp-graphql"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-204",
          "name": "Observable Response Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19979
      },
      "nvd": {
        "published": "2026-07-31T23:17:24.973",
        "lastModified": "2026-08-03T21:16:40.757",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54768",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Different password-reset responses reveal whether a supplied account exists.",
        "basis": [
          "CNA",
          "CWE-204"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-jhh7-832h-f8hv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql/v2.15.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.713Z",
      "date_published": "2026-07-09T23:51:10.855Z",
      "date_updated": "2026-07-10T14:12:23.422Z",
      "publisher": "GitHub_M",
      "title": "Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent",
      "affected": {
        "vendors": [
          "langroid"
        ],
        "products": [
          {
            "vendor": "langroid",
            "product": "langroid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00638,
        "percentile": 0.47115
      },
      "nvd": {
        "published": "2026-07-10T00:16:33.603",
        "lastModified": "2026-07-10T15:49:19.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54769",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TableChatAgent evaluates LLM output with built-ins still present in eval globals, allowing imported operating-system commands to execute.",
        "basis": [
          "CNA record",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/langroid/langroid/security/advisories/GHSA-q9p7-wqxg-mrhc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 969,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.713Z",
      "date_published": "2026-07-09T23:52:11.014Z",
      "date_updated": "2026-07-10T14:23:23.640Z",
      "publisher": "GitHub_M",
      "title": "Langroid: handle_message() executes user-supplied tool JSON without sender verification",
      "affected": {
        "vendors": [
          "langroid"
        ],
        "products": [
          {
            "vendor": "langroid",
            "product": "langroid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-75",
          "name": "Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19998
      },
      "nvd": {
        "published": "2026-07-10T00:16:33.737",
        "lastModified": "2026-07-10T15:49:19.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54771",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The chat handler interprets raw user JSON as a direct tool invocation even when the tool is registered with use disabled.",
        "basis": [
          "CNA",
          "CWE-75"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/langroid/langroid/security/advisories/GHSA-gjgq-w2m6-wr5q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54772",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.713Z",
      "date_published": "2026-07-08T22:06:08.914Z",
      "date_updated": "2026-07-09T14:19:17.666Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0047,
        "percentile": 0.38208
      },
      "nvd": {
        "published": "2026-07-08T23:16:54.830",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54772",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Premature EOF in the framing handshake leaves one thread-pool worker spinning at full CPU for each unauthenticated connection.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-p86g-xrr2-pf7c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/03ddbced349931a2da6c0efcdf745c0722eff77c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/7ddd966d6e58564a32ab30c825dd693b45a34a55",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/c4212988cd6fd472783d0413426eeac61044097a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 456,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54773",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.713Z",
      "date_published": "2026-07-08T22:09:32.584Z",
      "date_updated": "2026-07-10T14:05:22.358Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF: WS-Security signature substitution via document-wide Signature lookup",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14919
      },
      "nvd": {
        "published": "2026-07-08T23:16:54.960",
        "lastModified": "2026-07-10T15:16:41.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54773",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CoreWCF searches the entire SOAP document for a Signature and can verify an attacker-inserted header signature instead of the wsse:Security signature.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-jc6x-rj79-w4mx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/0589692d4b9a41d21b34ac48281e95f6df7f4ce5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/30aef805270976c42477e3f2a05f4e563d86e247",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/4618f24165ad018ad3ed2636bf8c3bc87d2a3be2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 480,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54774",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.713Z",
      "date_published": "2026-07-08T22:17:07.314Z",
      "date_updated": "2026-07-10T03:55:39.135Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.047
      },
      "nvd": {
        "published": "2026-07-08T23:16:55.090",
        "lastModified": "2026-07-10T05:16:37.267",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54774",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SAML path accepts a signed assertion without completing cryptographic verification of the SignatureValue for non-X.509 keys.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-rpj7-hr7h-w6p9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/65d09022749854ba943e376aefb958dec05b00d8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/b914495ce63c44924664643b60a262e7595081a4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/e7454132876ecc7e2cf80e541a44376eeb54979b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54775",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.713Z",
      "date_published": "2026-07-08T22:13:37.611Z",
      "date_updated": "2026-07-09T14:20:32.975Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-755",
          "name": "Improper Handling of Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00336,
        "percentile": 0.26181
      },
      "nvd": {
        "published": "2026-07-08T23:16:55.227",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54775",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "KafkaTransportPump does not handle a null-value tombstone as an exceptional record and permanently stops the consume loop.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-248",
          "CWE-754",
          "CWE-755"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-m744-jhq9-ppw6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/1a229d0d14a07766302f7d14c866889f04a3a624",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/6d7431ebc0ebe6521ea6d0dbea8982bac3d2bc98",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/8f95f3ac3c929409e830b5c5659683ef9f6ea6b0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 6,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54776",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.713Z",
      "date_published": "2026-07-08T22:04:39.200Z",
      "date_updated": "2026-07-09T12:56:16.584Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00109,
        "percentile": 0.01461
      },
      "nvd": {
        "published": "2026-07-08T23:16:55.360",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54776",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CoreWCF dispatches Unix-domain-socket messages even when the connection skips the application/unixposix stream upgrade that establishes PosixIdentity.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-wjpq-6766-7f5j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/994431268e3362c0cd126450fe2a135c202551f3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/9af16955e51a57348dafce0019e259a092ef7440",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/f2f1a05927a88b8a75fa0582fa8ed75eb891e463",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54777",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.714Z",
      "date_published": "2026-07-08T22:01:21.323Z",
      "date_updated": "2026-07-10T03:55:40.674Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-665",
          "name": "Improper Initialization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00088,
        "percentile": 0.00478
      },
      "nvd": {
        "published": "2026-07-08T22:17:15.240",
        "lastModified": "2026-07-10T05:16:37.393",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54777",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A named-pipe startup race lets another party claim or interact with the endpoint before the intended owner establishes it.",
        "basis": [
          "CNA",
          "CWE-367",
          "CWE-665"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-6jj2-4q5c-x8g6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/8ed9c780c7c6fb22fa215c5771dee0c1e49596b7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/e7d225394fd429900dcbc445dcdd53b94e964077",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54778",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.714Z",
      "date_published": "2026-07-08T22:11:55.490Z",
      "date_updated": "2026-07-09T13:23:29.922Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-825",
          "name": "Expired Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.00984
      },
      "nvd": {
        "published": "2026-07-08T23:16:55.493",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54778",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Concurrent CoreWCF connections share non-reentrant getpwuid and getgrgid storage, so one connection can receive another connection's POSIX peer identity.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-825"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-q6v9-43v5-jv9q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/a3d95ea4627b818995e92c7def4c016164cacfce",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/b0acb105589b455a095ea5ff49f5191e4eeff791",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/b4867547c94bb088568935d581a55dda18a621e1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54779",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.714Z",
      "date_published": "2026-07-08T22:07:46.453Z",
      "date_updated": "2026-07-09T14:17:57.224Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF: SAML token replay protection is inoperative",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18801
      },
      "nvd": {
        "published": "2026-07-08T23:16:55.630",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54779",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CoreWCF inserts replay identifiers into a cache but fails to reject a duplicate when TryAdd reports that the identifier already exists.",
        "basis": [
          "CNA",
          "CWE-294",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-9jr3-rj99-8jq3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/3800c4e2bb4c6fde00ddacefdc2221ef33d55621",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/7b0b5231cf21b4b5c1fc3caac9981f8bee43823f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/84f8cff5a786b5aaa73448cb379d366a7df98238",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 370,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54780",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.714Z",
      "date_published": "2026-07-08T22:15:06.161Z",
      "date_updated": "2026-07-09T19:21:36.312Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-327",
          "name": "Use of a Broken or Risky Cryptographic Algorithm",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-757",
          "name": "Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05344
      },
      "nvd": {
        "published": "2026-07-08T23:16:55.757",
        "lastModified": "2026-07-09T20:16:29.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54780",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validates ds:SignedInfo SignatureMethod against the configured SecurityAlgorithmSuite but does not validate each ds:Reference DigestMethod, allowing a sender to use a rejected digest algorithm such as SHA-1 while the message is still accepted.",
        "basis": [
          "CNA",
          "CWE-327",
          "CWE-757"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-4v55-cpmv-3vcm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/58742312117cc671e6e9c694c2f5f9f669c17136",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/9104e581cff3d047ace5e179bfae86807a44be1f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/fea67b2cd73a5a85115c325d504303ec7382e133",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 457,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54781",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.714Z",
      "date_published": "2026-07-08T22:19:40.784Z",
      "date_updated": "2026-07-09T14:40:11.234Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07576
      },
      "nvd": {
        "published": "2026-07-08T23:16:55.890",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54781",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SAML validation accepts a subject confirmation without enforcing the corresponding proof key.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-48pq-2xq3-c2m4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/6a99df3242f54acd6f89edfd6050430b72d0c685",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/86dd3232b6b8aaf32281be9e8d798afad6145d58",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/9eb9b46d1c2af06fb71f656a02f4d5b4649c1f03",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 450,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54782",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.714Z",
      "date_published": "2026-07-08T22:20:37.401Z",
      "date_updated": "2026-07-10T03:55:37.656Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15967
      },
      "nvd": {
        "published": "2026-07-08T23:16:56.030",
        "lastModified": "2026-07-10T05:16:37.520",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54782",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CoreWCF federated SAML validation can neither resolve the correct issuer key nor require a signature, so an unsigned or wrongly verified token can impersonate a trusted principal.",
        "basis": [
          "CNA",
          "CWE-290",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-xjr9-gg9q-jx3v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/0b8c8af851260e85e8402af53233d1b8f87dfb6f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/0e63c2cca55763d8be6b226a234579280a09e7b6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/e5cc9b6a4ecc102a50d782093bfc72e0790abe3d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54783",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.714Z",
      "date_published": "2026-07-08T22:16:08.533Z",
      "date_updated": "2026-07-10T03:55:39.889Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04052
      },
      "nvd": {
        "published": "2026-07-08T23:16:56.173",
        "lastModified": "2026-07-10T05:16:37.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54783",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CoreWCF verifies a signature that does not cover the security-relevant request target and also accepts replayed signed messages.",
        "basis": [
          "CNA",
          "CWE-294",
          "CWE-345",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-gqv6-pwcg-87r8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/0589692d4b9a41d21b34ac48281e95f6df7f4ce5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/30aef805270976c42477e3f2a05f4e563d86e247",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/4618f24165ad018ad3ed2636bf8c3bc87d2a3be2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 446,
        "referenceCount": 6,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54784",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.714Z",
      "date_published": "2026-07-08T22:18:13.846Z",
      "date_updated": "2026-07-10T03:55:38.395Z",
      "publisher": "GitHub_M",
      "title": "CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality",
      "affected": {
        "vendors": [
          "CoreWCF"
        ],
        "products": [
          {
            "vendor": "CoreWCF",
            "product": "CoreWCF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-311",
          "name": "Missing Encryption of Sensitive Data",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-523",
          "name": "Unprotected Transport of Credentials",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07157
      },
      "nvd": {
        "published": "2026-07-08T23:16:56.307",
        "lastModified": "2026-07-10T05:16:37.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54784",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SPNEGO session negotiation exposes the recovered proof key to an observer who can then impersonate the principal or forge WS-SecureConversation traffic.",
        "basis": [
          "CNA",
          "CWE-311",
          "CWE-523"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-2288-8h3r-cqgg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/2afae08b2fa5288428df89e8161116b816cf6b4b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/commit/f216aa6929d41dc99cee098b1e69c260ec4c41c7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 474,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54785",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.714Z",
      "date_published": "2026-07-31T22:31:04.190Z",
      "date_updated": "2026-08-03T16:26:53.194Z",
      "publisher": "GitHub_M",
      "title": "gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode",
      "affected": {
        "vendors": [
          "eLyiN"
        ],
        "products": [
          {
            "vendor": "eLyiN",
            "product": "gemini-bridge"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00151,
        "percentile": 0.04816
      },
      "nvd": {
        "published": "2026-07-31T23:17:25.133",
        "lastModified": "2026-08-03T17:16:38.353",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54785",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "consult_gemini_with_files accepts arbitrary local paths without confining reads to the working directory before forwarding file contents.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/eLyiN/gemini-bridge/security/advisories/GHSA-c5px-58j2-7fqp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/eLyiN/gemini-bridge/pull/9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/eLyiN/gemini-bridge/commit/8f3b85afd02b692c4bc974b5176e12fb277ea801",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/eLyiN/gemini-bridge/releases/tag/v1.3.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 519,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54786",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.714Z",
      "date_published": "2026-07-01T20:12:35.560Z",
      "date_updated": "2026-07-02T12:44:55.431Z",
      "publisher": "GitHub_M",
      "title": "Wasmtime: Leak in WASIp1 `fd_renumber` implementation",
      "affected": {
        "vendors": [
          "bytecodealliance"
        ],
        "products": [
          {
            "vendor": "bytecodealliance",
            "product": "wasmtime"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-772",
          "name": "Missing Release of Resource after Effective Lifetime",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 2.7,
      "epss": {
        "score": 0.00217,
        "percentile": 0.1222
      },
      "nvd": {
        "published": "2026-07-01T21:17:03.690",
        "lastModified": "2026-07-02T19:27:54.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54786",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WASIp1 fd_renumber updates the guest descriptor table without closing the corresponding host descriptor, so repeated calls exhaust host descriptors.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-772"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-3p27-qvp9-27qf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1221,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-54787",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-15T23:23:57.714Z",
      "date_published": "2026-07-31T21:58:14.156Z",
      "date_updated": "2026-07-31T23:36:13.441Z",
      "publisher": "GitHub_M",
      "title": "sigstore-go fails to check signature timestamps against a signing key's validity period",
      "affected": {
        "vendors": [
          "sigstore"
        ],
        "products": [
          {
            "vendor": "sigstore",
            "product": "sigstore-go"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-324",
          "name": "Use of a Key Past its Expiration Date",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0009,
        "percentile": 0.00556
      },
      "nvd": {
        "published": "2026-07-31T23:17:25.287",
        "lastModified": "2026-08-01T00:17:17.040",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54787",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "sigstore-go fails to compare a bundle signing time with an ExpiringKey validity window, so expired key material can still produce an accepted signature.",
        "basis": [
          "CNA",
          "CWE-324"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sigstore/sigstore-go/security/advisories/GHSA-wqqc-jjcq-vfxm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-go/pull/642",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-go/commit/4594ab4c779d08be1f4419803a8249188f35ed5f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-go/releases/tag/v1.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 373,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54798",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T07:47:12.273Z",
      "date_published": "2026-07-09T14:15:51.173Z",
      "date_updated": "2026-07-09T14:54:39.999Z",
      "publisher": "siemens",
      "title": "A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.",
      "affected": {
        "vendors": [
          "Siemens"
        ],
        "products": [
          {
            "vendor": "Siemens",
            "product": "CPCI85 Central Processing/Communication"
          },
          {
            "vendor": "Siemens",
            "product": "SICORE Base system"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-489",
          "name": "Active Debug Code",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15122
      },
      "nvd": {
        "published": "2026-07-09T15:16:36.443",
        "lastModified": "2026-07-09T17:00:41.453",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54798",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Production firmware exposes an active debugging interface through authenticated HTTP endpoints, allowing debug behavior to terminate the web process.",
        "basis": [
          "CNA",
          "CWE-489"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-229470.html",
          "host": "cert-portal.siemens.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 379,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T07:47:12.273Z",
      "date_published": "2026-07-09T14:15:52.247Z",
      "date_updated": "2026-07-09T14:46:38.615Z",
      "publisher": "siemens",
      "title": "A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.",
      "affected": {
        "vendors": [
          "Siemens"
        ],
        "products": [
          {
            "vendor": "Siemens",
            "product": "CPCI85 Central Processing/Communication"
          },
          {
            "vendor": "Siemens",
            "product": "SICORE Base system"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-489",
          "name": "Active Debug Code",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 1.7000000000000002,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02761
      },
      "nvd": {
        "published": "2026-07-09T15:16:36.580",
        "lastModified": "2026-07-09T17:00:41.453",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54799",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The firmware updater does not correctly validate the firmware signature before installation.",
        "basis": [
          "CNA",
          "CWE-489"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-229470.html",
          "host": "cert-portal.siemens.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T07:47:12.274Z",
      "date_published": "2026-07-09T14:15:53.306Z",
      "date_updated": "2026-07-09T14:45:11.451Z",
      "publisher": "siemens",
      "title": "A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.",
      "affected": {
        "vendors": [
          "Siemens"
        ],
        "products": [
          {
            "vendor": "Siemens",
            "product": "CPCI85 Central Processing/Communication"
          },
          {
            "vendor": "Siemens",
            "product": "SICORE Base system"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04321
      },
      "nvd": {
        "published": "2026-07-09T15:16:36.707",
        "lastModified": "2026-07-09T17:00:41.453",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54800",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The product ships with all OPC UA security mechanisms disabled in its default configuration.",
        "basis": [
          "CNA",
          "CWE-1188"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-229470.html",
          "host": "cert-portal.siemens.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 356,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T07:47:12.274Z",
      "date_published": "2026-07-09T14:15:54.353Z",
      "date_updated": "2026-07-09T17:37:43.135Z",
      "publisher": "siemens",
      "title": "A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.",
      "affected": {
        "vendors": [
          "Siemens"
        ],
        "products": [
          {
            "vendor": "Siemens",
            "product": "CPCI85 Central Processing/Communication"
          },
          {
            "vendor": "Siemens",
            "product": "SICORE Base system"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-620",
          "name": "Unverified Password Change",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26601
      },
      "nvd": {
        "published": "2026-07-09T15:16:36.830",
        "lastModified": "2026-07-09T18:16:54.307",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54801",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The administrative account-modification path accepts credentials that are not validated as carrying the elevated authority required for that action.",
        "basis": [
          "CNA",
          "CWE-620"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-229470.html",
          "host": "cert-portal.siemens.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54885",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T10:47:13.914Z",
      "date_published": "2026-07-30T14:16:43.631Z",
      "date_updated": "2026-07-31T04:20:03.434Z",
      "publisher": "EEF",
      "title": "Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching",
      "affected": {
        "vendors": [
          "malach-it"
        ],
        "products": [
          {
            "vendor": "malach-it",
            "product": "boruta"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29971
      },
      "nvd": {
        "published": "2026-07-30T15:16:34.050",
        "lastModified": "2026-07-30T17:16:33.337",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54885",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Boruta fetches request_uri and jwks_uri destinations without restricting scheme, resolved address, redirect target, or response size.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/malach-it/boruta_auth/security/advisories/GHSA-5q9h-vf5j-fr2g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-54885.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-54885",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/malach-it/boruta_auth/commit/001e3dc5c259e67c6f907e98867eda4141c96d0d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/malach-it/boruta_auth/commit/95fb10b78129355e475681f324c9a01ef0af2be5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1485,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54886",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T10:47:13.914Z",
      "date_published": "2026-07-02T16:06:20.502Z",
      "date_updated": "2026-07-24T14:14:32.812Z",
      "publisher": "EEF",
      "title": "SSH SFTP server denial of service via extended channel data infinite loop",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25617
      },
      "nvd": {
        "published": "2026-07-02T17:17:02.387",
        "lastModified": "2026-07-24T15:18:03.833",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54886",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SFTP handler tail-calls itself with unchanged arguments for extended channel data, creating an infinite loop and an unbounded message queue.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-7wp4-pc27-2vj9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-54886.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-54886",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Third Party Advisory",
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/eaf9550b8ad4738b81149d3f617102d980c6dd18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2205,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54887",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T10:47:13.915Z",
      "date_published": "2026-07-02T16:06:04.156Z",
      "date_updated": "2026-07-24T14:15:16.337Z",
      "publisher": "EEF",
      "title": "DTLS server cookie bypass during startup window due to empty initial cookie secret",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1394",
          "name": "Use of Default Cryptographic Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15584
      },
      "nvd": {
        "published": "2026-07-02T17:17:02.570",
        "lastModified": "2026-07-24T15:18:04.063",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54887",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The DTLS server initializes its prior cookie secret to an empty value, making startup-window cookies predictable to an observer.",
        "basis": [
          "CNA",
          "CWE-1394"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-p2m2-3c2w-8jp8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-54887.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-54887",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/888e3bcd72d5406016b9e0de741026bc2a6f114d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1372,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54890",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T10:47:13.915Z",
      "date_published": "2026-07-27T15:39:03.475Z",
      "date_updated": "2026-07-28T09:55:08.138Z",
      "publisher": "EEF",
      "title": "BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00318,
        "percentile": 0.24258
      },
      "nvd": {
        "published": "2026-07-27T16:17:41.437",
        "lastModified": "2026-07-30T17:01:07.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54890",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Erlang arithmetic underflows a requested size and turns it into an invalidly large allocation.",
        "basis": [
          "CNA",
          "CWE-191",
          "CWE-789",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-54pw-5645-jh86",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-54890.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-54890",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/dc1bf9344c0ce62717cf60866590cea0242780fd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1484,
        "referenceCount": 5,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-54891",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T10:47:13.915Z",
      "date_published": "2026-07-02T16:06:30.982Z",
      "date_updated": "2026-08-03T14:51:40.832Z",
      "publisher": "EEF",
      "title": "Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-924",
          "name": "Improper Enforcement of Message Integrity During Transmission in a Communication Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03408
      },
      "nvd": {
        "published": "2026-07-02T17:17:02.747",
        "lastModified": "2026-08-03T16:16:29.693",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54891",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The TLS client buffers unauthenticated APPLICATION_DATA received before handshake completion and later delivers it to the application as authenticated post-handshake data.",
        "basis": [
          "CNA",
          "CWE-924"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-gf6r-99xw-6qg6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-54891.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-54891",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/07d2d0e93f6aaf7652a81e8df075fc1728da5e96",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1521,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-54893",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T10:47:13.915Z",
      "date_published": "2026-07-06T14:04:16.486Z",
      "date_updated": "2026-07-07T04:32:26.465Z",
      "publisher": "EEF",
      "title": "Email-derived URL path injection in the Swoosh Microsoft Graph adapter",
      "affected": {
        "vendors": [
          "swoosh"
        ],
        "products": [
          {
            "vendor": "swoosh",
            "product": "swoosh"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04035
      },
      "nvd": {
        "published": "2026-07-06T15:16:39.683",
        "lastModified": "2026-07-06T19:37:48.003",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54893",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Swoosh.Adapters.MsGraph builds its Microsoft Graph API request URL by interpolating the sender's email address into the URL path (/users/{from}/sendMail) without percent-encoding or validation.",
        "basis": [
          "CNA",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/swoosh/swoosh/security/advisories/GHSA-754j-98wh-57rf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-54893.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-54893",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/swoosh/swoosh/commit/e38235453e81d1727bfc8d91e69ec4cb211ccf61",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 938,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-54908",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T13:49:33.556Z",
      "date_published": "2026-07-01T19:34:24.014Z",
      "date_updated": "2026-07-02T15:54:54.578Z",
      "publisher": "GitHub_M",
      "title": "Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message",
      "affected": {
        "vendors": [
          "pion"
        ],
        "products": [
          {
            "vendor": "pion",
            "product": "dtls"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24457
      },
      "nvd": {
        "published": "2026-07-01T20:17:10.797",
        "lastModified": "2026-07-02T18:43:54.070",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54908",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted ECDHE_PSK ServerKeyExchange reaches an unchecked parser path that panics instead of returning a protocol error.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pion/dtls/security/advisories/GHSA-wg4g-wm44-ch5j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pion/dtls/pull/839",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54909",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T13:49:33.556Z",
      "date_published": "2026-07-31T22:03:53.514Z",
      "date_updated": "2026-08-03T17:30:22.558Z",
      "publisher": "GitHub_M",
      "title": "Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute",
      "affected": {
        "vendors": [
          "pion"
        ],
        "products": [
          {
            "vendor": "pion",
            "product": "stun"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.2985
      },
      "nvd": {
        "published": "2026-07-31T23:17:25.433",
        "lastModified": "2026-08-03T18:16:39.733",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54909",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The STUN XOR-MAPPED-ADDRESS parser indexes a malformed short attribute and panics instead of rejecting it.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pion/stun/security/advisories/GHSA-34rh-wp3j-6cxc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pion/stun/pull/278",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pion/stun/commit/fa9f074a33a8059c76c960b1fbee39f308002423",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pion/stun/releases/tag/v3.1.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 275,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54910",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T13:49:33.556Z",
      "date_published": "2026-07-20T14:20:21.412Z",
      "date_updated": "2026-07-20T14:52:10.145Z",
      "publisher": "GitHub_M",
      "title": "FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files",
      "affected": {
        "vendors": [
          "gtsteffaniak"
        ],
        "products": [
          {
            "vendor": "gtsteffaniak",
            "product": "filebrowser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23014
      },
      "nvd": {
        "published": "2026-07-20T15:16:43.933",
        "lastModified": "2026-07-23T17:58:34.990",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-54910",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The subtitle endpoint passes unsanitized path and name values to filesystem resolution without confining them to the storage root.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-vvp7-h4fj-m28w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gtsteffaniak/filebrowser/commit/f3f4bbe80cb569d664174aea874d7bfa008c3b5a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1070,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54919",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T13:49:33.557Z",
      "date_published": "2026-07-10T16:06:12.848Z",
      "date_updated": "2026-07-14T03:55:43.419Z",
      "publisher": "GitHub_M",
      "title": "cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backends",
      "affected": {
        "vendors": [
          "yhirose"
        ],
        "products": [
          {
            "vendor": "yhirose",
            "product": "cpp-httplib"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06005
      },
      "nvd": {
        "published": "2026-07-10T17:16:58.700",
        "lastModified": "2026-07-14T05:16:18.563",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54919",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Certificate-chain validation is skipped when the peer is addressed by an IP literal.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-8ffh-4p95-g3p2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/yhirose/cpp-httplib/commit/fa981cedae004ea9d946f1392b9dec22fac6fee6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yhirose/cpp-httplib/releases/tag/v0.47.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 699,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.868Z",
      "date_published": "2026-07-14T17:04:52.034Z",
      "date_updated": "2026-08-03T22:53:16.270Z",
      "publisher": "microsoft",
      "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0038,
        "percentile": 0.3074
      },
      "nvd": {
        "published": "2026-07-14T17:17:05.663",
        "lastModified": "2026-07-20T13:37:42.593",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54982",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 uses a size result after attacker-controlled arithmetic can underflow.",
        "basis": [
          "CNA",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54982",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-54983",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.868Z",
      "date_published": "2026-07-14T17:04:40.759Z",
      "date_updated": "2026-08-03T22:53:05.095Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0078,
        "percentile": 0.52384
      },
      "nvd": {
        "published": "2026-07-14T17:17:05.833",
        "lastModified": "2026-07-20T14:54:04.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54983",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AD FS writes beyond a stack buffer when processing unauthenticated network input.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54983",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-54986",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.868Z",
      "date_published": "2026-07-14T17:04:48.157Z",
      "date_updated": "2026-08-03T22:53:12.255Z",
      "publisher": "microsoft",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01921,
        "percentile": 0.779
      },
      "nvd": {
        "published": "2026-07-14T17:17:06.003",
        "lastModified": "2026-07-20T14:56:32.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54986",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 10 Version 1607, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54986",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-54987",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.868Z",
      "date_published": "2026-07-14T17:04:42.898Z",
      "date_updated": "2026-08-03T22:53:07.300Z",
      "publisher": "microsoft",
      "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15139
      },
      "nvd": {
        "published": "2026-07-14T17:17:06.153",
        "lastModified": "2026-07-23T05:16:36.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54987",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input exceeds a heap allocation because the write is not bounded to the allocated size.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54987",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-54988",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.868Z",
      "date_published": "2026-07-14T17:05:09.425Z",
      "date_updated": "2026-08-03T22:53:29.734Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23023
      },
      "nvd": {
        "published": "2026-07-14T17:17:06.310",
        "lastModified": "2026-07-16T11:52:07.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54988",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Excel reads beyond a valid memory boundary while processing local attacker-controlled content.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54988",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-54989",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.868Z",
      "date_published": "2026-07-14T17:04:42.342Z",
      "date_updated": "2026-08-03T22:53:06.750Z",
      "publisher": "microsoft",
      "title": "Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.002,
        "percentile": 0.10105
      },
      "nvd": {
        "published": "2026-07-14T17:17:06.440",
        "lastModified": "2026-07-23T05:16:36.743",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54989",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 path retains or dereferences an object after its storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54989",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 133,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-54990",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.868Z",
      "date_published": "2026-07-14T17:04:44.100Z",
      "date_updated": "2026-08-03T22:53:08.390Z",
      "publisher": "microsoft",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00545,
        "percentile": 0.42639
      },
      "nvd": {
        "published": "2026-07-14T17:17:06.603",
        "lastModified": "2026-07-22T16:18:16.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54990",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A bounds or lifetime violation permits access outside valid memory.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54990",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-54991",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:04:46.582Z",
      "date_updated": "2026-08-03T22:53:10.693Z",
      "publisher": "microsoft",
      "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05048
      },
      "nvd": {
        "published": "2026-07-14T17:17:06.720",
        "lastModified": "2026-07-20T14:23:28.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54991",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows USB Print Driver uses a shared resource concurrently without synchronization, while the public record does not name that resource.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54991",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-54992",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:04:50.999Z",
      "date_updated": "2026-08-03T22:53:15.089Z",
      "publisher": "microsoft",
      "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00471,
        "percentile": 0.38262
      },
      "nvd": {
        "published": "2026-07-14T17:17:06.830",
        "lastModified": "2026-07-20T15:05:31.827",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54992",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser writes attacker-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54992",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-54993",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:04:48.639Z",
      "date_updated": "2026-08-03T22:53:12.727Z",
      "publisher": "microsoft",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26112
      },
      "nvd": {
        "published": "2026-07-14T17:17:07.000",
        "lastModified": "2026-07-20T15:05:57.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54993",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Windows 10 Version 1809, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54993",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-54995",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:04:56.665Z",
      "date_updated": "2026-08-03T22:53:20.104Z",
      "publisher": "microsoft",
      "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.0059,
        "percentile": 0.44909
      },
      "nvd": {
        "published": "2026-07-14T17:17:07.143",
        "lastModified": "2026-07-20T17:18:43.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54995",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Reliable Multicast Transport Driver accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54995",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-54996",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:04:53.546Z",
      "date_updated": "2026-08-03T22:53:17.295Z",
      "publisher": "microsoft",
      "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04942
      },
      "nvd": {
        "published": "2026-07-14T17:17:07.310",
        "lastModified": "2026-07-20T17:09:49.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54996",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected workflow fails to preserve its invariant across a state transition or concurrent operation.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54996",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-54997",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:04:55.070Z",
      "date_updated": "2026-08-03T22:53:18.452Z",
      "publisher": "microsoft",
      "title": "Windows SMB Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22141
      },
      "nvd": {
        "published": "2026-07-14T17:17:07.427",
        "lastModified": "2026-07-20T17:11:08.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54997",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SMB path uses an object before all of its fields and backing resources have been initialized.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54997",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-54998",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-02T22:18:58.222Z",
      "date_updated": "2026-08-03T22:52:42.245Z",
      "publisher": "microsoft",
      "title": "Microsoft Exchange Online Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Online"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00648,
        "percentile": 0.47547
      },
      "nvd": {
        "published": "2026-07-02T23:16:51.137",
        "lastModified": "2026-07-07T05:16:52.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54998",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54998",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-54999",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:04:55.622Z",
      "date_updated": "2026-08-03T22:53:19.000Z",
      "publisher": "microsoft",
      "title": "Windows TCP/IP Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21378
      },
      "nvd": {
        "published": "2026-07-14T17:17:07.657",
        "lastModified": "2026-07-24T19:20:37.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-54999",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 accesses shared state without the synchronization needed to keep concurrent lifecycle transitions consistent.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54999",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-55000",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:04:45.298Z",
      "date_updated": "2026-08-03T22:53:09.489Z",
      "publisher": "microsoft",
      "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16093
      },
      "nvd": {
        "published": "2026-07-14T17:17:07.827",
        "lastModified": "2026-07-24T19:16:47.047",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55000",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The USB print driver dereferences an object after it has been freed during a physical attack path.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55000",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-55001",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:04:49.220Z",
      "date_updated": "2026-08-03T22:53:13.358Z",
      "publisher": "microsoft",
      "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11883
      },
      "nvd": {
        "published": "2026-07-14T17:17:07.943",
        "lastModified": "2026-07-24T14:18:05.577",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55001",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Active Directory trusts a certificate without completing the required certificate validation.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55001",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55002",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:05:06.049Z",
      "date_updated": "2026-08-03T22:53:26.405Z",
      "publisher": "microsoft",
      "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2016 Service Pack 3 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2019 (CU 32)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2019 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2022 (GDR)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2022 for x64-based Systems (CU 25)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 (CU 6)"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 for x64-based Systems (GDR)"
          }
        ],
        "affectedBlockCount": 10,
        "versionEntryCount": 10,
        "versionRangeCount": 10,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00618,
        "percentile": 0.46181
      },
      "nvd": {
        "published": "2026-07-14T17:17:08.070",
        "lastModified": "2026-08-04T00:17:16.540",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55002",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An authenticated SQL Server user can control a file name or path beyond the operation's intended storage namespace, although the exact operation is not public.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55002",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 10,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-55003",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:04:56.181Z",
      "date_updated": "2026-08-03T22:53:19.644Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00651,
        "percentile": 0.47698
      },
      "nvd": {
        "published": "2026-07-14T17:17:08.200",
        "lastModified": "2026-07-24T19:18:49.073",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55003",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1607 path uses uninitialized storage and can return residual data to the caller.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55003",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-55004",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:04:50.522Z",
      "date_updated": "2026-08-03T22:53:14.524Z",
      "publisher": "microsoft",
      "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15137
      },
      "nvd": {
        "published": "2026-07-14T17:17:08.367",
        "lastModified": "2026-07-24T19:15:59.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55004",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Printer Drivers free the same allocation twice in a local privilege-sensitive path.",
        "basis": [
          "CNA",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55004",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-55005",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.869Z",
      "date_published": "2026-07-14T17:04:57.884Z",
      "date_updated": "2026-08-03T22:53:21.133Z",
      "publisher": "microsoft",
      "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2016 Cumulative Update 23"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2019 Cumulative Update 14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2019 Cumulative Update 15"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server Subscription Edition RTM"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00664,
        "percentile": 0.48197
      },
      "nvd": {
        "published": "2026-07-14T17:17:08.537",
        "lastModified": "2026-07-24T19:19:21.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55005",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Microsoft Exchange Server 2016 Cumulative Update 23, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55005",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55006",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:10:05.870Z",
      "date_published": "2026-07-14T17:04:58.430Z",
      "date_updated": "2026-08-03T22:53:21.603Z",
      "publisher": "microsoft",
      "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2016 Cumulative Update 23"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2019 Cumulative Update 14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2019 Cumulative Update 15"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server Subscription Edition RTM"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1220",
          "name": "Insufficient Granularity of Access Control",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11922
      },
      "nvd": {
        "published": "2026-07-14T17:17:08.650",
        "lastModified": "2026-07-24T19:19:25.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55006",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Exchange Server 2016 Cumulative Update 23 fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1220"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55006",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55008",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.283Z",
      "date_published": "2026-07-14T17:04:58.913Z",
      "date_updated": "2026-08-03T22:53:22.232Z",
      "publisher": "microsoft",
      "title": "Microsoft Exchange Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2016 Cumulative Update 23"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2019 Cumulative Update 14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2019 Cumulative Update 15"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server Subscription Edition RTM"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0085,
        "percentile": 0.54612
      },
      "nvd": {
        "published": "2026-07-14T17:17:08.763",
        "lastModified": "2026-07-24T19:19:30.413",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55008",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Exchange Server renders network input into a web page without correctly neutralizing browser script syntax.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55009",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.283Z",
      "date_published": "2026-07-14T17:05:02.147Z",
      "date_updated": "2026-08-03T22:53:22.801Z",
      "publisher": "microsoft",
      "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2016 Cumulative Update 23"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2019 Cumulative Update 14"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2019 Cumulative Update 15"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server Subscription Edition RTM"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01613,
        "percentile": 0.73597
      },
      "nvd": {
        "published": "2026-07-14T17:17:08.883",
        "lastModified": "2026-07-24T19:19:42.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55009",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Exchange Server 2016 Cumulative Update 23 deserializes attacker-controlled data without restricting the object types or state that the serialized stream may construct.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55009",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55010",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.283Z",
      "date_published": "2026-07-14T17:08:27.625Z",
      "date_updated": "2026-08-03T22:56:47.139Z",
      "publisher": "microsoft",
      "title": "Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Minecraft Bedrock Dedicated Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0074,
        "percentile": 0.51083
      },
      "nvd": {
        "published": "2026-07-14T18:18:11.723",
        "lastModified": "2026-07-22T16:47:25.417",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55010",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Minecraft Bedrock Dedicated Server writes beyond a heap allocation while processing unauthenticated network input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55010",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55011",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.283Z",
      "date_published": "2026-07-14T17:05:03.262Z",
      "date_updated": "2026-08-03T22:53:23.887Z",
      "publisher": "microsoft",
      "title": "Microsoft Defender Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Malware Protection Engine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00374,
        "percentile": 0.30145
      },
      "nvd": {
        "published": "2026-07-14T17:17:08.990",
        "lastModified": "2026-07-24T19:19:48.540",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55011",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Defender integer arithmetic underflows while processing local input and corrupts the subsequent memory operation.",
        "basis": [
          "CNA",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55011",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55012",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.283Z",
      "date_published": "2026-07-14T17:05:03.730Z",
      "date_updated": "2026-08-03T22:53:24.366Z",
      "publisher": "microsoft",
      "title": "Microsoft Defender Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Malware Protection Engine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00374,
        "percentile": 0.30145
      },
      "nvd": {
        "published": "2026-07-14T17:17:09.107",
        "lastModified": "2026-07-24T19:19:52.617",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55012",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Defender permits integer arithmetic to wrap and corrupt a subsequent memory-size or bounds calculation.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55012",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.284Z",
      "date_published": "2026-07-14T17:05:23.086Z",
      "date_updated": "2026-08-03T22:53:42.511Z",
      "publisher": "microsoft",
      "title": "Windows Remote Help Defense Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows Remote Help"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11882
      },
      "nvd": {
        "published": "2026-07-14T17:17:09.217",
        "lastModified": "2026-07-24T18:49:21.940",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55014",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55014",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55016",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.284Z",
      "date_published": "2026-07-14T17:08:31.730Z",
      "date_updated": "2026-08-03T22:56:51.589Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00412,
        "percentile": 0.33918
      },
      "nvd": {
        "published": "2026-07-14T18:18:12.040",
        "lastModified": "2026-07-15T15:13:00.180",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55016",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55016",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55017",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.284Z",
      "date_published": "2026-07-14T17:08:31.254Z",
      "date_updated": "2026-08-03T22:56:51.039Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.2263
      },
      "nvd": {
        "published": "2026-07-14T18:18:12.163",
        "lastModified": "2026-07-16T15:22:15.837",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55017",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected handler writes attacker-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55017",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-55018",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.284Z",
      "date_published": "2026-07-14T17:08:33.892Z",
      "date_updated": "2026-08-03T22:56:53.639Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26666
      },
      "nvd": {
        "published": "2026-07-14T18:18:12.287",
        "lastModified": "2026-07-16T15:22:31.510",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55018",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55018",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 91,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55019",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.284Z",
      "date_published": "2026-07-14T17:08:33.303Z",
      "date_updated": "2026-08-03T22:56:53.171Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00549,
        "percentile": 0.42858
      },
      "nvd": {
        "published": "2026-07-14T18:18:12.420",
        "lastModified": "2026-07-15T15:13:02.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55019",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55019",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55020",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.284Z",
      "date_published": "2026-07-14T17:08:35.027Z",
      "date_updated": "2026-08-03T22:56:54.832Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00412,
        "percentile": 0.33874
      },
      "nvd": {
        "published": "2026-07-14T18:18:12.540",
        "lastModified": "2026-07-16T15:16:32.693",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55020",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Microsoft SharePoint Enterprise Server 2016 page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55020",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55021",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.284Z",
      "date_published": "2026-07-14T17:08:35.528Z",
      "date_updated": "2026-08-03T22:56:55.310Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00651,
        "percentile": 0.47678
      },
      "nvd": {
        "published": "2026-07-14T18:18:12.663",
        "lastModified": "2026-07-15T15:13:09.663",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55021",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SharePoint renders attacker-controlled input into a web page without the required browser-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55021",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55022",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.284Z",
      "date_published": "2026-07-14T17:08:36.181Z",
      "date_updated": "2026-08-03T22:56:55.892Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.3041
      },
      "nvd": {
        "published": "2026-07-14T18:18:12.780",
        "lastModified": "2026-07-16T15:27:24.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55022",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input causes an object to be interpreted as an incompatible type.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55022",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55023",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.284Z",
      "date_published": "2026-07-14T17:08:36.677Z",
      "date_updated": "2026-08-03T22:56:56.517Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00546,
        "percentile": 0.42744
      },
      "nvd": {
        "published": "2026-07-14T18:18:12.913",
        "lastModified": "2026-07-16T16:18:39.230",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55023",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Office reads beyond the bounds of a memory object.",
        "basis": [
          "CNA record",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55023",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55024",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.284Z",
      "date_published": "2026-07-14T17:08:32.354Z",
      "date_updated": "2026-08-03T22:56:52.139Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00393,
        "percentile": 0.32017
      },
      "nvd": {
        "published": "2026-07-14T18:18:13.060",
        "lastModified": "2026-07-15T18:40:01.097",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55024",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise accesses a resource through an incompatible type and applies invalid memory assumptions.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55024",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 144,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55025",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.285Z",
      "date_published": "2026-07-14T17:08:37.352Z",
      "date_updated": "2026-08-03T22:56:56.989Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.2263
      },
      "nvd": {
        "published": "2026-07-14T18:18:13.190",
        "lastModified": "2026-07-15T18:39:28.117",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55025",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Excel treats a resource as an incompatible type and performs invalid memory operations while opening attacker input.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55025",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 144,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55026",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.285Z",
      "date_published": "2026-07-14T17:08:39.562Z",
      "date_updated": "2026-08-03T22:56:59.122Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00412,
        "percentile": 0.33921
      },
      "nvd": {
        "published": "2026-07-14T18:18:13.330",
        "lastModified": "2026-07-16T16:17:54.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55026",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Microsoft 365 Apps for Enterprise, unchecked integer arithmetic wraps before its result controls a memory size, offset, or copy.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55026",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55027",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.285Z",
      "date_published": "2026-07-14T17:08:41.141Z",
      "date_updated": "2026-08-03T22:57:00.803Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00546,
        "percentile": 0.42743
      },
      "nvd": {
        "published": "2026-07-14T18:18:13.473",
        "lastModified": "2026-07-16T16:14:56.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55027",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the end of an allocated buffer because the available length is not enforced.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55027",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55028",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.285Z",
      "date_published": "2026-07-14T17:08:42.241Z",
      "date_updated": "2026-08-03T22:57:01.980Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00421,
        "percentile": 0.34738
      },
      "nvd": {
        "published": "2026-07-14T18:18:13.613",
        "lastModified": "2026-07-16T16:14:28.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55028",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Office reads beyond a valid memory boundary while processing local attacker-controlled content.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55028",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55029",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.285Z",
      "date_published": "2026-07-14T17:08:41.617Z",
      "date_updated": "2026-08-03T22:57:01.432Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22631
      },
      "nvd": {
        "published": "2026-07-14T18:18:13.757",
        "lastModified": "2026-07-15T18:38:38.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55029",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Microsoft 365 Apps for Enterprise path writes attacker-influenced data beyond the capacity of its destination buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55029",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55030",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.285Z",
      "date_published": "2026-07-14T17:08:37.976Z",
      "date_updated": "2026-08-03T22:56:57.538Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00549,
        "percentile": 0.42858
      },
      "nvd": {
        "published": "2026-07-14T18:18:13.890",
        "lastModified": "2026-07-15T15:13:12.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55030",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is inserted into an executable grammar without context-specific neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55030",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55031",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.285Z",
      "date_published": "2026-07-14T17:08:38.995Z",
      "date_updated": "2026-08-03T22:56:58.564Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00393,
        "percentile": 0.32017
      },
      "nvd": {
        "published": "2026-07-14T18:18:14.013",
        "lastModified": "2026-07-15T18:37:24.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55031",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Microsoft 365 Apps for Enterprise path trusts a length or offset that can read beyond the initialized input buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55031",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55032",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:12:44.285Z",
      "date_published": "2026-07-14T17:08:45.598Z",
      "date_updated": "2026-08-03T22:57:05.448Z",
      "publisher": "microsoft",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Word 2016"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29964
      },
      "nvd": {
        "published": "2026-07-14T18:18:14.150",
        "lastModified": "2026-07-16T16:14:07.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55032",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component dereferences an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55032",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55033",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.835Z",
      "date_published": "2026-07-14T17:08:46.146Z",
      "date_updated": "2026-08-03T22:57:06.084Z",
      "publisher": "microsoft",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Word 2016"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00578,
        "percentile": 0.44345
      },
      "nvd": {
        "published": "2026-07-14T18:18:14.293",
        "lastModified": "2026-07-16T16:13:17.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55033",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Microsoft 365 Apps for Enterprise, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55033",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55034",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.835Z",
      "date_published": "2026-07-14T17:08:40.594Z",
      "date_updated": "2026-08-03T22:57:00.339Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00867,
        "percentile": 0.55208
      },
      "nvd": {
        "published": "2026-07-14T18:18:14.437",
        "lastModified": "2026-07-15T15:13:15.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55034",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SharePoint renders attacker-controlled input as active HTML or script without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55034",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55035",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.835Z",
      "date_published": "2026-07-14T17:08:50.812Z",
      "date_updated": "2026-08-03T22:57:10.611Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00527,
        "percentile": 0.41679
      },
      "nvd": {
        "published": "2026-07-14T18:18:14.557",
        "lastModified": "2026-07-16T16:08:18.227",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55035",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the valid input or buffer boundary because its size check is incomplete.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55035",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55036",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.835Z",
      "date_published": "2026-07-14T17:08:51.360Z",
      "date_updated": "2026-08-03T22:57:11.081Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22629
      },
      "nvd": {
        "published": "2026-07-14T18:18:14.700",
        "lastModified": "2026-07-16T14:18:49.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55036",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise reads beyond the end of an attacker-influenced buffer because the operation's length exceeds the available bytes.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55036",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55037",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.835Z",
      "date_published": "2026-07-14T17:08:53.550Z",
      "date_updated": "2026-08-03T22:57:13.208Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22627
      },
      "nvd": {
        "published": "2026-07-14T18:18:14.883",
        "lastModified": "2026-07-16T11:47:48.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55037",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data is written beyond the boundary of a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55037",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55038",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.835Z",
      "date_published": "2026-07-14T17:08:54.676Z",
      "date_updated": "2026-08-03T22:57:14.416Z",
      "publisher": "microsoft",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Word 2016"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00496,
        "percentile": 0.39833
      },
      "nvd": {
        "published": "2026-07-14T18:18:15.083",
        "lastModified": "2026-07-16T14:30:49.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55038",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55038",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55039",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.835Z",
      "date_published": "2026-07-14T17:08:43.268Z",
      "date_updated": "2026-08-03T22:57:03.242Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22628
      },
      "nvd": {
        "published": "2026-07-14T18:18:15.257",
        "lastModified": "2026-07-16T14:18:09.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55039",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Excel integer arithmetic underflows and drives a memory operation with an invalid size or offset.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55039",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55040",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.835Z",
      "date_published": "2026-07-14T17:09:00.641Z",
      "date_updated": "2026-08-03T22:57:20.406Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1390",
          "name": "Weak Authentication",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01626,
        "percentile": 0.73811
      },
      "nvd": {
        "published": "2026-07-14T18:18:15.413",
        "lastModified": "2026-07-15T20:01:41.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55040",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "SharePoint accepts an anonymous network connection as an impersonated user, but Microsoft does not disclose the credential condition or authentication check that accepts it.",
        "basis": [
          "CNA",
          "CWE-1390",
          "Microsoft CVRF"
        ],
        "deepDive": true,
        "notes": "Inspected https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jul and https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040; Microsoft confirms anonymous connection and impersonation but does not disclose the credential form, parsing rule, or failing authentication check."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 127,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55041",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.835Z",
      "date_published": "2026-07-14T17:08:46.781Z",
      "date_updated": "2026-08-03T22:57:06.709Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22628
      },
      "nvd": {
        "published": "2026-07-14T18:18:15.570",
        "lastModified": "2026-07-16T11:55:36.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55041",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Excel writes past a heap allocation while processing a crafted local document opened by the victim.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55041",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55042",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.835Z",
      "date_published": "2026-07-14T17:09:03.554Z",
      "date_updated": "2026-08-03T22:57:23.239Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30907
      },
      "nvd": {
        "published": "2026-07-14T18:18:15.730",
        "lastModified": "2026-07-16T14:30:21.133",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55042",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Microsoft 365 Apps for Enterprise path uses uninitialized storage and can return residual data to the caller.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55042",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55043",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.835Z",
      "date_published": "2026-07-14T17:09:04.616Z",
      "date_updated": "2026-08-03T22:57:24.485Z",
      "publisher": "microsoft",
      "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft PowerPoint 2016"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27423
      },
      "nvd": {
        "published": "2026-07-14T18:18:15.897",
        "lastModified": "2026-07-16T14:30:00.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55043",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerPoint integer arithmetic permits a write beyond a heap allocation while parsing a malicious file.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55043",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55044",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:51.908Z",
      "date_updated": "2026-08-03T22:57:11.552Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22627
      },
      "nvd": {
        "published": "2026-07-14T18:18:16.043",
        "lastModified": "2026-07-16T11:54:34.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55044",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Microsoft 365 Apps for Enterprise, an attacker-controlled index or length permits a read beyond the valid memory region.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55044",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55045",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:43.821Z",
      "date_updated": "2026-08-03T22:57:03.801Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28905
      },
      "nvd": {
        "published": "2026-07-14T18:18:16.193",
        "lastModified": "2026-07-16T14:29:37.020",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55045",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise uses an attacker-influenced length or index without proving it lies inside the backing object, allowing a read beyond valid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55045",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 95,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55046",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:34.516Z",
      "date_updated": "2026-08-03T22:56:54.197Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00459,
        "percentile": 0.37553
      },
      "nvd": {
        "published": "2026-07-14T18:18:16.353",
        "lastModified": "2026-07-16T11:46:12.100",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55046",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Excel reads beyond a valid memory buffer while processing attacker-controlled local content.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55046",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55047",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:42.792Z",
      "date_updated": "2026-08-03T22:57:02.602Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00537,
        "percentile": 0.42252
      },
      "nvd": {
        "published": "2026-07-14T18:18:16.503",
        "lastModified": "2026-07-16T14:28:37.870",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55047",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise reads beyond the available buffer because an input length, offset, or parser boundary is not checked before access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55047",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55048",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:40.040Z",
      "date_updated": "2026-08-03T22:56:59.693Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22627
      },
      "nvd": {
        "published": "2026-07-14T18:18:16.680",
        "lastModified": "2026-07-15T20:16:23.897",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55048",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer wraparound in Excel produces an incorrect heap size and permits memory corruption when a malicious document is opened.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55048",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55049",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:45.003Z",
      "date_updated": "2026-08-03T22:57:04.906Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26666
      },
      "nvd": {
        "published": "2026-07-14T18:18:16.860",
        "lastModified": "2026-07-16T14:28:12.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55049",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Office writes beyond a heap buffer while processing local attacker input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55049",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55050",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:44.445Z",
      "date_updated": "2026-08-03T22:57:04.353Z",
      "publisher": "microsoft",
      "title": "Microsoft Word Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Word 2016"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00421,
        "percentile": 0.34739
      },
      "nvd": {
        "published": "2026-07-14T18:18:17.010",
        "lastModified": "2026-07-16T15:16:32.960",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55050",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Word reads beyond an allocated buffer while processing attacker-controlled document data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55050",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55051",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:58.921Z",
      "date_updated": "2026-08-03T22:57:18.804Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00626,
        "percentile": 0.46553
      },
      "nvd": {
        "published": "2026-07-14T18:18:17.153",
        "lastModified": "2026-07-16T14:26:49.910",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55051",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55051",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 135,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55052",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:09:06.976Z",
      "date_updated": "2026-08-03T22:57:26.845Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00649,
        "percentile": 0.47572
      },
      "nvd": {
        "published": "2026-07-14T18:18:17.287",
        "lastModified": "2026-07-16T14:26:42.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55052",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55052",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55053",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:56.097Z",
      "date_updated": "2026-08-03T22:57:15.980Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22628
      },
      "nvd": {
        "published": "2026-07-14T18:18:17.410",
        "lastModified": "2026-07-15T20:13:43.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55053",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected handler writes attacker-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55053",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55054",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:52.994Z",
      "date_updated": "2026-08-03T22:57:12.742Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00623,
        "percentile": 0.46444
      },
      "nvd": {
        "published": "2026-07-14T18:18:17.547",
        "lastModified": "2026-07-15T13:49:30.437",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55054",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise can read beyond the valid bounds of an input or object allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55054",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55055",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:52.454Z",
      "date_updated": "2026-08-03T22:57:12.121Z",
      "publisher": "microsoft",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Word 2016"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29965
      },
      "nvd": {
        "published": "2026-07-14T18:18:17.683",
        "lastModified": "2026-07-16T14:26:35.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55055",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data is copied beyond the boundary of a stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55055",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55056",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:09:00.094Z",
      "date_updated": "2026-08-03T22:57:19.856Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26667
      },
      "nvd": {
        "published": "2026-07-14T18:18:17.827",
        "lastModified": "2026-07-16T14:42:49.627",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55056",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55056",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55057",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:57.273Z",
      "date_updated": "2026-08-03T22:57:17.097Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30907
      },
      "nvd": {
        "published": "2026-07-14T18:18:17.953",
        "lastModified": "2026-07-16T14:40:40.007",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55057",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Office integer arithmetic can overflow and produce an invalid memory size or offset that exposes information.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55057",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55058",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:13:49.836Z",
      "date_published": "2026-07-14T17:08:54.040Z",
      "date_updated": "2026-08-03T22:57:13.863Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22628
      },
      "nvd": {
        "published": "2026-07-14T18:18:18.087",
        "lastModified": "2026-07-15T20:05:42.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55058",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can cause a read beyond the bounds of a valid buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55058",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55075",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:33:35.710Z",
      "date_published": "2026-07-07T21:33:38.189Z",
      "date_updated": "2026-07-08T13:03:16.212Z",
      "publisher": "GitHub_M",
      "title": "Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-289",
          "name": "Authentication Bypass by Alternate Name",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20725
      },
      "nvd": {
        "published": "2026-07-07T22:16:53.650",
        "lastModified": "2026-07-08T19:46:56.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55075",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OIDC account linking falls back to an email alias without binding it to one provider subject and treats a missing or malformed email_verified claim as verified.",
        "basis": [
          "CNA record",
          "CWE-289"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-9r87-mvcw-x35f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/25712",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/25713",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 804,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55076",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:33:35.711Z",
      "date_published": "2026-07-07T22:23:26.179Z",
      "date_updated": "2026-07-08T14:03:39.329Z",
      "publisher": "GitHub_M",
      "title": "Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-704",
          "name": "Incorrect Type Conversion or Cast",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23071
      },
      "nvd": {
        "published": "2026-07-07T23:16:55.237",
        "lastModified": "2026-07-08T19:46:04.560",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55076",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A failed Go boolean assertion for email_verified is treated as verified and the email fallback then binds the login to an account.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-704"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-75vm-6w67-gwvp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/25712",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/25713",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 882,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55077",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:33:35.711Z",
      "date_published": "2026-07-07T22:44:28.621Z",
      "date_updated": "2026-07-09T14:41:52.486Z",
      "publisher": "GitHub_M",
      "title": "Coder: User-admin role can reset owner account password",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00336,
        "percentile": 0.26193
      },
      "nvd": {
        "published": "2026-07-07T23:16:55.377",
        "lastModified": "2026-07-09T16:16:44.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55077",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The password-reset endpoint authorizes ActionUpdatePersonal but fails to prevent a user-admin from resetting an owner account.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-29xf-69gq-m9jx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/25709",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 775,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55078",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:33:35.711Z",
      "date_published": "2026-07-07T22:47:07.079Z",
      "date_updated": "2026-07-08T13:55:16.017Z",
      "publisher": "GitHub_M",
      "title": "Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26367
      },
      "nvd": {
        "published": "2026-07-07T23:16:55.510",
        "lastModified": "2026-07-08T19:45:05.967",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55078",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Coder limits each ZIP entry but not their aggregate decompressed size, allowing CreateTarFromZip to grow one in-memory buffer without a total ceiling.",
        "basis": [
          "CNA",
          "CWE-409",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-2mg2-p7r7-g27f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/25877",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 847,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55079",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:33:35.711Z",
      "date_published": "2026-07-07T23:50:37.197Z",
      "date_updated": "2026-07-08T12:53:41.432Z",
      "publisher": "GitHub_M",
      "title": "Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00336,
        "percentile": 0.26145
      },
      "nvd": {
        "published": "2026-07-08T00:16:33.153",
        "lastModified": "2026-07-08T19:44:45.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55079",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A client-supplied size is used directly for allocation without first enforcing a safe maximum.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-f962-qm93-mj4c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/25710",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 698,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:33:35.711Z",
      "date_published": "2026-07-21T18:36:46.507Z",
      "date_updated": "2026-07-22T14:39:07.792Z",
      "publisher": "GitHub_M",
      "title": "DHIS2 Reflected XSS in OpenAPI HTML scope parameter",
      "affected": {
        "vendors": [
          "dhis2"
        ],
        "products": [
          {
            "vendor": "dhis2",
            "product": "dhis2-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18699
      },
      "nvd": {
        "published": "2026-07-21T19:17:10.950",
        "lastModified": "2026-07-22T15:17:19.207",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55081",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OpenAPI HTML endpoint reflects the scope query value into generated HTML without sufficient contextual sanitization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dhis2/dhis2-core/security/advisories/GHSA-6785-hj47-c27h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dhis2/dhis2-core/pull/24158",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dhis2/dhis2-core/pull/24159",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dhis2/dhis2-core/pull/24160",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dhis2/dhis2-core/pull/24161",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dhis2/dhis2-core/pull/24162",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 751,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:33:35.711Z",
      "date_published": "2026-07-21T18:43:42.535Z",
      "date_updated": "2026-07-22T18:26:12.396Z",
      "publisher": "GitHub_M",
      "title": "DHIS2 SQL injection in SQL View filter values",
      "affected": {
        "vendors": [
          "dhis2"
        ],
        "products": [
          {
            "vendor": "dhis2",
            "product": "dhis2-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00334,
        "percentile": 0.26
      },
      "nvd": {
        "published": "2026-07-21T19:17:11.093",
        "lastModified": "2026-07-22T19:17:06.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55082",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The dhis2-core data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dhis2/dhis2-core/security/advisories/GHSA-3288-cm98-664f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dhis2/dhis2-core/pull/22253",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dhis2/dhis2-core/pull/24172",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dhis2/dhis2-core/pull/24173",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dhis2/dhis2-core/pull/24174",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 849,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55084",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:41:54.577Z",
      "date_published": "2026-07-21T18:30:09.057Z",
      "date_updated": "2026-07-21T19:03:58.016Z",
      "publisher": "GitHub_M",
      "title": "SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read",
      "affected": {
        "vendors": [
          "dhis2"
        ],
        "products": [
          {
            "vendor": "dhis2",
            "product": "dhis2-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16806
      },
      "nvd": {
        "published": "2026-07-21T19:17:11.223",
        "lastModified": "2026-07-21T20:17:02.277",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55084",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted input reaches an interpreter as syntax rather than being kept as data.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dhis2/dhis2-core/security/advisories/GHSA-pwmg-mvjw-4m23",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dhis2/dhis2-core/pull/24162",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 994,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-55100",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T14:41:54.579Z",
      "date_published": "2026-07-31T17:03:41.858Z",
      "date_updated": "2026-07-31T19:57:01.760Z",
      "publisher": "GitHub_M",
      "title": "hashi-vault-js has a path traversal and query parameter injection",
      "affected": {
        "vendors": [
          "kyndryl-open-source"
        ],
        "products": [
          {
            "vendor": "kyndryl-open-source",
            "product": "hashi-vault-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30953
      },
      "nvd": {
        "published": "2026-07-31T18:17:17.480",
        "lastModified": "2026-07-31T20:16:51.993",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55100",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Vault.js concatenates unencoded name, username, group, role, and version values into request paths and query strings, allowing route traversal and parameter injection.",
        "basis": [
          "CNA",
          "CWE-23",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kyndryl-open-source/hashi-vault-js/security/advisories/GHSA-g956-2f74-rmv7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/kyndryl-open-source/hashi-vault-js/pull/66",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kyndryl-open-source/hashi-vault-js/commit/ea2f76052d366a08f35f62ef4c12b6a334c91ec2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/kyndryl-open-source/hashi-vault-js/releases/tag/v0.5.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55110",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:00:01.614Z",
      "date_published": "2026-07-02T14:49:16.794Z",
      "date_updated": "2026-07-02T15:52:20.711Z",
      "publisher": "hackerone",
      "title": "A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi OS Server"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Machines"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Fortress Gateway"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Wall"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Routers"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Express 7"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Keys"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Network Video Recorders"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Video Recorders"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Gateways"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Network Attached Storage"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Firewall Core"
          }
        ],
        "affectedBlockCount": 12,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-942",
          "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04495
      },
      "nvd": {
        "published": "2026-07-02T15:17:04.870",
        "lastModified": "2026-07-09T18:33:16.890",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55110",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "UniFi permits an untrusted origin to issue credentialed cross-origin requests using the victim's authenticated browser session.",
        "basis": [
          "CNA",
          "CWE-942"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 12,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-55111",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:00:01.614Z",
      "date_published": "2026-07-02T14:49:17.257Z",
      "date_updated": "2026-07-02T15:51:52.648Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the UniFi Protect Floodlight.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Protect Floodlight"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.2611
      },
      "nvd": {
        "published": "2026-07-02T15:17:04.987",
        "lastModified": "2026-07-09T13:20:47.137",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55111",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says UniFi Protect Floodlight accepts a filesystem or upload target outside its intended namespace, while the path field and selection check are not public.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55112",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:00:01.614Z",
      "date_published": "2026-07-02T14:50:48.656Z",
      "date_updated": "2026-07-02T15:51:35.516Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Machines"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Wall"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Routers"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Keys"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Network Video Recorders"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Video Recorders"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Gateways"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09827
      },
      "nvd": {
        "published": "2026-07-02T15:17:05.103",
        "lastModified": "2026-07-10T02:46:09.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55112",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "UniFi OS permits a low-privileged network user to gain host privileges, but the public record does not identify the protected operation or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-55113",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:00:01.614Z",
      "date_published": "2026-07-02T14:50:48.567Z",
      "date_updated": "2026-07-02T15:51:46.930Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API...",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Talk Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.13
      },
      "nvd": {
        "published": "2026-07-02T15:17:05.303",
        "lastModified": "2026-07-09T13:19:57.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55113",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55114",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:00:01.614Z",
      "date_published": "2026-07-02T14:50:49.035Z",
      "date_updated": "2026-07-02T15:51:04.788Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Network Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17672
      },
      "nvd": {
        "published": "2026-07-02T15:17:05.410",
        "lastModified": "2026-07-06T19:28:22.497",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55114",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "UniFi Network has an access-control failure in a named component, while the public advisory does not disclose the caller, object, or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55115",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:00:01.614Z",
      "date_published": "2026-07-02T14:50:48.762Z",
      "date_updated": "2026-07-02T15:51:23.659Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Protect Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00523,
        "percentile": 0.41448
      },
      "nvd": {
        "published": "2026-07-02T15:17:05.513",
        "lastModified": "2026-07-07T16:36:26.370",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55115",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server accepts an attacker-controlled destination without constraining the resolved request target to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 186,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55116",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:00:01.614Z",
      "date_published": "2026-07-02T14:50:48.820Z",
      "date_updated": "2026-07-02T15:51:11.890Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Machines"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Fortress Gateway"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Wall"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Dream Routers"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Express 7"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Cloud Gateways"
          },
          {
            "vendor": "Ubiquiti Inc",
            "product": "Enterprise Firewall Core"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00414,
        "percentile": 0.341
      },
      "nvd": {
        "published": "2026-07-02T15:17:05.633",
        "lastModified": "2026-07-09T18:14:16.047",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55116",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Under certain network configurations, UniFi OS accepts unauthorized device changes, but Ubiquiti does not identify the protected operation or failed authorization check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Ubiquiti security bulletin"
        ],
        "deepDive": true,
        "notes": "Inspected https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc; the bulletin gives affected UniFi OS devices, fixed versions, network conditions, and unauthorized-change impact but no protected operation or failed authorization check. The current official bulletin scores it 9.0, while this embedded shard records 9.8."
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-55117",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:00:01.614Z",
      "date_published": "2026-07-02T14:50:48.606Z",
      "date_updated": "2026-07-02T15:51:41.293Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Access Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30922
      },
      "nvd": {
        "published": "2026-07-02T15:17:05.740",
        "lastModified": "2026-07-09T13:19:42.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55117",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "UniFi Access accepts traversal segments in a remotely supplied path and selects host files outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 159,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55118",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:00:01.614Z",
      "date_published": "2026-07-02T14:50:48.734Z",
      "date_updated": "2026-07-02T15:51:29.494Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Network Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10523
      },
      "nvd": {
        "published": "2026-07-02T15:17:05.840",
        "lastModified": "2026-07-06T19:26:55.523",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55118",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged UniFi user can cross into a higher role under unspecified conditions because an access-control boundary is incomplete.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55119",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:00:01.614Z",
      "date_published": "2026-07-02T14:50:49.042Z",
      "date_updated": "2026-07-02T15:50:51.870Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Talk Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.1276
      },
      "nvd": {
        "published": "2026-07-02T15:17:05.957",
        "lastModified": "2026-07-09T13:19:26.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55119",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged network user can obtain higher UniFi Talk privileges, but the public record does not identify the role, action, or missing authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55120",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.680Z",
      "date_published": "2026-07-14T17:09:06.338Z",
      "date_updated": "2026-08-03T22:57:26.298Z",
      "publisher": "microsoft",
      "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft PowerPoint 2016"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27424
      },
      "nvd": {
        "published": "2026-07-14T18:18:18.220",
        "lastModified": "2026-07-15T20:08:16.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55120",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Microsoft 365 Apps for Enterprise path writes attacker-influenced data beyond an allocated heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55120",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55121",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.680Z",
      "date_published": "2026-07-14T17:10:17.586Z",
      "date_updated": "2026-08-03T22:59:05.341Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00363,
        "percentile": 0.29029
      },
      "nvd": {
        "published": "2026-07-14T18:18:18.347",
        "lastModified": "2026-07-15T20:09:38.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55121",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Office reads beyond the available buffer while processing local attacker-controlled content.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55121",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55122",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.680Z",
      "date_published": "2026-07-14T17:08:56.721Z",
      "date_updated": "2026-08-03T22:57:16.544Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.2606
      },
      "nvd": {
        "published": "2026-07-14T18:18:18.500",
        "lastModified": "2026-07-15T20:04:06.150",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55122",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Microsoft 365 Apps for Enterprise, an attacker-controlled index or length permits a read beyond the valid memory region.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55122",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55123",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.680Z",
      "date_published": "2026-07-14T17:09:05.762Z",
      "date_updated": "2026-08-03T22:57:25.663Z",
      "publisher": "microsoft",
      "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft PowerPoint 2016"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-681",
          "name": "Incorrect Conversion between Numeric Types",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27423
      },
      "nvd": {
        "published": "2026-07-14T18:18:18.633",
        "lastModified": "2026-07-16T14:32:20.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55123",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise copies, writes, or indexes attacker-influenced data without enforcing the destination buffer or object bounds required by the operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122",
          "CWE-681"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55123",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55124",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.680Z",
      "date_published": "2026-07-14T17:08:47.741Z",
      "date_updated": "2026-08-03T22:57:07.910Z",
      "publisher": "microsoft",
      "title": "Microsoft Word Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Word 2016"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1287",
          "name": "Improper Validation of Specified Type of Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00421,
        "percentile": 0.34738
      },
      "nvd": {
        "published": "2026-07-14T18:18:18.767",
        "lastModified": "2026-07-16T14:32:34.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55124",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Microsoft record says Word accepts an input of an invalid type before disclosure but does not identify the field, conversion, or read boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20",
          "CWE-1287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55124",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55125",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.680Z",
      "date_published": "2026-07-14T17:08:38.525Z",
      "date_updated": "2026-08-03T22:56:58.094Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29966
      },
      "nvd": {
        "published": "2026-07-14T18:18:18.920",
        "lastModified": "2026-07-16T14:39:36.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55125",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise writes attacker-controlled data beyond a heap allocation because the copy or allocation size is not validated.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55125",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55126",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.680Z",
      "date_published": "2026-07-14T17:08:58.373Z",
      "date_updated": "2026-08-03T22:57:18.183Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 1.8999999999999995,
      "epss": {
        "score": 0.00532,
        "percentile": 0.41966
      },
      "nvd": {
        "published": "2026-07-14T18:18:19.063",
        "lastModified": "2026-07-16T14:24:03.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55126",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SharePoint renders authorized attacker input into a web page without correctly neutralizing script syntax.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55126",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55127",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.681Z",
      "date_published": "2026-07-14T17:08:48.385Z",
      "date_updated": "2026-08-03T22:57:08.463Z",
      "publisher": "microsoft",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Word 2016"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34431
      },
      "nvd": {
        "published": "2026-07-14T18:18:19.180",
        "lastModified": "2026-07-16T14:39:16.763",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55127",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Word writes beyond a heap buffer while processing local attacker input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55127",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55128",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.681Z",
      "date_published": "2026-07-14T17:09:02.323Z",
      "date_updated": "2026-08-03T22:57:22.123Z",
      "publisher": "microsoft",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Word 2016"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29965
      },
      "nvd": {
        "published": "2026-07-14T18:18:19.320",
        "lastModified": "2026-07-16T14:32:46.910",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55128",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Word uses an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55128",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55129",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.681Z",
      "date_published": "2026-07-14T17:08:50.193Z",
      "date_updated": "2026-08-03T22:57:10.058Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26667
      },
      "nvd": {
        "published": "2026-07-14T18:18:19.463",
        "lastModified": "2026-07-16T14:33:05.180",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55129",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55129",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55130",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.681Z",
      "date_published": "2026-07-14T17:09:02.968Z",
      "date_updated": "2026-08-03T22:57:22.687Z",
      "publisher": "microsoft",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Word 2016"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29966
      },
      "nvd": {
        "published": "2026-07-14T18:18:19.587",
        "lastModified": "2026-07-15T20:12:41.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55130",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55130",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55131",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.681Z",
      "date_published": "2026-07-14T17:08:57.748Z",
      "date_updated": "2026-08-03T22:57:17.562Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22629
      },
      "nvd": {
        "published": "2026-07-14T18:18:19.717",
        "lastModified": "2026-07-15T20:01:54.230",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55131",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected handler writes attacker-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55131",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55132",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.681Z",
      "date_published": "2026-07-14T17:08:55.152Z",
      "date_updated": "2026-08-03T22:57:14.969Z",
      "publisher": "microsoft",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Word 2016"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00463,
        "percentile": 0.37806
      },
      "nvd": {
        "published": "2026-07-14T18:18:19.850",
        "lastModified": "2026-07-16T13:39:21.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55132",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise can release the same allocation twice along one error and teardown path.",
        "basis": [
          "CNA",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55132",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55133",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.681Z",
      "date_published": "2026-07-14T17:09:05.118Z",
      "date_updated": "2026-08-03T22:57:25.112Z",
      "publisher": "microsoft",
      "title": "Microsoft OneNote Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22626
      },
      "nvd": {
        "published": "2026-07-14T18:18:20.003",
        "lastModified": "2026-07-22T05:17:11.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55133",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data is written beyond the boundary of a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55133",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 111,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55134",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.681Z",
      "date_published": "2026-07-14T17:08:59.548Z",
      "date_updated": "2026-08-03T22:57:19.297Z",
      "publisher": "microsoft",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Word 2016"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29965
      },
      "nvd": {
        "published": "2026-07-14T18:18:20.163",
        "lastModified": "2026-07-16T13:40:01.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55134",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55134",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-55135",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.681Z",
      "date_published": "2026-07-14T17:09:07.524Z",
      "date_updated": "2026-08-03T22:57:27.334Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00412,
        "percentile": 0.33873
      },
      "nvd": {
        "published": "2026-07-14T18:18:20.307",
        "lastModified": "2026-07-16T15:16:33.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55135",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SharePoint renders attacker-controlled input into a web page without the required browser-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55135",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55136",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.681Z",
      "date_published": "2026-07-14T17:08:48.931Z",
      "date_updated": "2026-08-03T22:57:09.007Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-822",
          "name": "Untrusted Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22631
      },
      "nvd": {
        "published": "2026-07-14T18:18:20.437",
        "lastModified": "2026-07-15T17:16:53.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55136",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation dereferences an untrusted pointer as though it referenced valid memory.",
        "basis": [
          "CNA",
          "CWE-822"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55136",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55137",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.681Z",
      "date_published": "2026-07-14T17:08:55.624Z",
      "date_updated": "2026-08-03T22:57:15.508Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.2263
      },
      "nvd": {
        "published": "2026-07-14T18:18:20.583",
        "lastModified": "2026-07-15T17:16:13.527",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55137",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted Excel input writes beyond a heap buffer.",
        "basis": [
          "CNA record",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55137",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55138",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.682Z",
      "date_published": "2026-07-14T17:08:47.258Z",
      "date_updated": "2026-08-03T22:57:07.348Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-822",
          "name": "Untrusted Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27129
      },
      "nvd": {
        "published": "2026-07-14T18:18:20.720",
        "lastModified": "2026-07-15T17:15:34.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55138",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise dereferences an attacker-influenced pointer without establishing that it addresses a valid object.",
        "basis": [
          "CNA",
          "CWE-822"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55138",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55139",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.682Z",
      "date_published": "2026-07-14T17:09:04.127Z",
      "date_updated": "2026-08-03T22:57:23.862Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26635
      },
      "nvd": {
        "published": "2026-07-14T18:18:20.863",
        "lastModified": "2026-07-16T16:00:53.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55139",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Office reads beyond an input buffer while processing a local document.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55139",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55140",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.682Z",
      "date_published": "2026-07-14T17:09:01.852Z",
      "date_updated": "2026-08-03T22:57:21.575Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26668
      },
      "nvd": {
        "published": "2026-07-14T18:18:20.997",
        "lastModified": "2026-07-16T15:48:52.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55140",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Microsoft 365 Apps for Enterprise, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55140",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55141",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.682Z",
      "date_published": "2026-07-14T17:08:49.554Z",
      "date_updated": "2026-08-03T22:57:09.570Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22632
      },
      "nvd": {
        "published": "2026-07-14T18:18:21.123",
        "lastModified": "2026-07-15T17:14:37.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55141",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input exceeds a stack buffer because the copy or write is not bounded to that allocation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55141",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 110,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55142",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.682Z",
      "date_published": "2026-07-14T17:09:01.202Z",
      "date_updated": "2026-08-03T22:57:21.030Z",
      "publisher": "microsoft",
      "title": "Microsoft Word Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Word 2016"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-197",
          "name": "Numeric Truncation Error",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00421,
        "percentile": 0.34738
      },
      "nvd": {
        "published": "2026-07-14T18:18:21.273",
        "lastModified": "2026-07-16T13:40:07.760",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55142",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Word truncates a numeric value used by a local content-processing path, producing an invalid memory range that discloses data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-197"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55142",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.682Z",
      "date_published": "2026-07-14T17:05:06.598Z",
      "date_updated": "2026-08-03T22:53:27.029Z",
      "publisher": "microsoft",
      "title": "Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-325",
          "name": "Missing Cryptographic Step",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06069
      },
      "nvd": {
        "published": "2026-07-14T17:17:09.327",
        "lastModified": "2026-07-21T05:16:34.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55144",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 11 Version 24H2 cryptographic path omits a required integrity or authenticity operation.",
        "basis": [
          "CNA",
          "CWE-325"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55144",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-55145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:03:49.682Z",
      "date_published": "2026-07-14T17:09:09.269Z",
      "date_updated": "2026-08-03T22:57:29.068Z",
      "publisher": "microsoft",
      "title": "Outlook Copilot Tampering Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Copilot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29781
      },
      "nvd": {
        "published": "2026-07-14T18:18:21.520",
        "lastModified": "2026-07-22T16:26:41.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55145",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled value is concatenated into an operating-system command without shell-safe quoting.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55145",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55153",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:13:28.165Z",
      "date_published": "2026-07-01T20:02:47.254Z",
      "date_updated": "2026-07-06T14:02:08.977Z",
      "publisher": "GitHub_M",
      "title": "mchange-commons-java contains elements susceptible to abuse via JNDI injection and \"deserialization gadgets\"",
      "affected": {
        "vendors": [
          "swaldman"
        ],
        "products": [
          {
            "vendor": "swaldman",
            "product": "mchange-commons-java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25269
      },
      "nvd": {
        "published": "2026-07-01T21:17:03.823",
        "lastModified": "2026-07-06T15:16:39.837",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55153",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The mchange-commons-java path permits attacker-controlled serialized data or a dangerous object graph to reach a deserializer.",
        "basis": [
          "CNA",
          "CWE-470",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/swaldman/mchange-commons-java/security/advisories/GHSA-h84g-69h7-mw6v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 929,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55170",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:13:28.166Z",
      "date_published": "2026-07-09T21:04:28.713Z",
      "date_updated": "2026-07-10T14:26:15.294Z",
      "publisher": "GitHub_M",
      "title": "OpenFGA MySQL backend: case-insensitive collation on identifier columns causes incorrect authorization decisions",
      "affected": {
        "vendors": [
          "openfga"
        ],
        "products": [
          {
            "vendor": "openfga",
            "product": "openfga"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-178",
          "name": "Improper Handling of Case Sensitivity",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 3.3000000000000003,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16204
      },
      "nvd": {
        "published": "2026-07-09T22:17:05.937",
        "lastModified": "2026-07-14T01:22:35.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55170",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenFGA stores authorization identifiers in case-insensitive MySQL columns even though the authorization model treats those identifiers as case-sensitive.",
        "basis": [
          "CNA",
          "CWE-178"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openfga/openfga/security/advisories/GHSA-cf98-j28v-49v6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/openfga/helm-charts/commit/96d5517a2693ff5def451dee7d6b9d1baeb281f8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openfga/openfga/commit/a2e0dbefc3e01a95c785f81a3563bc6571b08b11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openfga/helm-charts/releases/tag/openfga-0.3.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openfga/openfga/releases/tag/v1.18.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 434,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55173",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:20:43.085Z",
      "date_published": "2026-07-16T20:41:26.345Z",
      "date_updated": "2026-07-17T13:44:36.168Z",
      "publisher": "GitHub_M",
      "title": "AVideo incomplete fix for CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink",
      "affected": {
        "vendors": [
          "WWBN"
        ],
        "products": [
          {
            "vendor": "WWBN",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02162,
        "percentile": 0.80429
      },
      "nvd": {
        "published": "2026-07-16T21:17:21.483",
        "lastModified": "2026-07-17T18:36:41.143",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55173",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete and still does not neutralize a single & ( the shell background operator).",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-wc3f-xc32-435f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/WWBN/AVideo/commit/c1cfa2bea8a351a1d07f5758f82887403e3abf1f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1259,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55175",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:20:43.085Z",
      "date_published": "2026-07-10T21:52:08.166Z",
      "date_updated": "2026-07-15T03:59:56.840Z",
      "publisher": "GitHub_M",
      "title": "Spinnaker: Improper yaml processing on kustomize bake operations",
      "affected": {
        "vendors": [
          "spinnaker"
        ],
        "products": [
          {
            "vendor": "spinnaker",
            "product": "spinnaker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00615,
        "percentile": 0.46075
      },
      "nvd": {
        "published": "2026-07-10T23:16:48.487",
        "lastModified": "2026-07-21T19:25:45.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55175",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Rosco Kustomize bake operations deserialize unsafe YAML tags from attacker-controlled manifests.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/spinnaker/spinnaker/security/advisories/GHSA-p68j-q7hf-3qcp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/commit/2d75818b85cc4c35144d5e5ed45e7340fcab5dfe",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/commit/bbc30c9b9034a056e95f012fa1b34e9fd703cae7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/commit/de5a7a05af35aee19eb71d289cd0b77f67509009",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/commit/df32d568e82519d9f3896fc9007baba0077c87fd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/commit/f5cec213f8cf207843ed5a6929395960a1ca094f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/releases/tag/rosco-2025.3.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/releases/tag/rosco-2025.4.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/releases/tag/rosco-2026.0.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/releases/tag/rosco-2026.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/spinnaker/spinnaker/releases/tag/rosco-2026.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 407,
        "referenceCount": 11,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:20:43.086Z",
      "date_published": "2026-07-10T21:43:59.548Z",
      "date_updated": "2026-07-13T15:55:15.065Z",
      "publisher": "GitHub_M",
      "title": "Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms (follow-up to CVE-2026-27808)",
      "affected": {
        "vendors": [
          "axllent"
        ],
        "products": [
          {
            "vendor": "axllent",
            "product": "mailpit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20426
      },
      "nvd": {
        "published": "2026-07-10T22:16:43.110",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55187",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mailpit blocks only a subset of internal-address encodings, so IPv6 transition and legacy prefixes reach internal destinations through link checking.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/axllent/mailpit/security/advisories/GHSA-w4mc-hhc6-xp28",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/axllent/mailpit/commit/a88dadbbe1df016a35a445089ef2a362a6c2de78",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/axllent/mailpit/releases/tag/v1.30.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 716,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55195",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T15:20:43.087Z",
      "date_published": "2026-07-08T20:30:58.654Z",
      "date_updated": "2026-07-09T14:06:02.499Z",
      "publisher": "GitHub_M",
      "title": "py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size",
      "affected": {
        "vendors": [
          "miurahr"
        ],
        "products": [
          {
            "vendor": "miurahr",
            "product": "py7zr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11296
      },
      "nvd": {
        "published": "2026-07-08T21:16:49.840",
        "lastModified": "2026-07-10T19:06:45.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55195",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "py7zr expands archive members without enforcing a total decompressed-size budget, allowing a small archive to exhaust disk or memory.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/miurahr/py7zr/security/advisories/GHSA-gjrg-mpp7-g774",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/miurahr/py7zr/commit/28faf107b64374fa5a02bfb93aa2024e281ca97b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/miurahr/py7zr/releases/tag/v1.1.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 404,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55206",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:16:32.627Z",
      "date_published": "2026-07-08T20:32:09.905Z",
      "date_updated": "2026-07-09T14:26:55.698Z",
      "publisher": "GitHub_M",
      "title": "py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()",
      "affected": {
        "vendors": [
          "miurahr"
        ],
        "products": [
          {
            "vendor": "miurahr",
            "product": "py7zr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11296
      },
      "nvd": {
        "published": "2026-07-08T21:16:49.987",
        "lastModified": "2026-07-10T19:07:46.400",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55206",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled collection size drives quadratic processing before the archive is accepted.",
        "basis": [
          "CNA",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/miurahr/py7zr/security/advisories/GHSA-h4gh-22qq-72r7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/miurahr/py7zr/commit/d7aa3a197d15c75a65b24f796d3a69f83806d3f8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/miurahr/py7zr/releases/tag/v1.1.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 432,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55207",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:16:32.627Z",
      "date_published": "2026-07-09T21:02:02.733Z",
      "date_updated": "2026-07-10T13:34:28.607Z",
      "publisher": "GitHub_M",
      "title": "Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass",
      "affected": {
        "vendors": [
          "pimcore"
        ],
        "products": [
          {
            "vendor": "pimcore",
            "product": "pimcore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27694
      },
      "nvd": {
        "published": "2026-07-09T21:16:55.890",
        "lastModified": "2026-07-10T15:52:52.497",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55207",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pimcore appends a valid reset token to a caller-controlled resetPasswordUrl, allowing the token to be delivered to an attacker-selected origin.",
        "basis": [
          "CNA",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-h854-c3m3-mh5v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pimcore/studio-backend-bundle/pull/1882",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/studio-backend-bundle/commit/ea9d329686f5e5aea2eec378d63ac2deb965bb27",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/studio-backend-bundle/releases/tag/v2025.4.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/studio-backend-bundle/releases/tag/v2026.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 670,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55208",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:16:32.627Z",
      "date_published": "2026-07-09T20:57:53.346Z",
      "date_updated": "2026-07-10T13:51:59.895Z",
      "publisher": "GitHub_M",
      "title": "Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes",
      "affected": {
        "vendors": [
          "pimcore"
        ],
        "products": [
          {
            "vendor": "pimcore",
            "product": "pimcore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16263
      },
      "nvd": {
        "published": "2026-07-09T21:16:56.020",
        "lastModified": "2026-07-10T15:52:52.497",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55208",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DateFilter wraps a caller-supplied column name in backticks without escaping embedded backticks, allowing the value to append SQL syntax.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-79cw-hfcc-7mw9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pimcore/studio-backend-bundle/pull/1883",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/studio-backend-bundle/commit/f532428cfbf4f5d6e299a13cedd5c29541802552",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/studio-backend-bundle/releases/tag/v2025.4.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/studio-backend-bundle/releases/tag/v2026.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 635,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55212",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:16:32.627Z",
      "date_published": "2026-07-09T20:53:36.900Z",
      "date_updated": "2026-07-10T20:32:10.057Z",
      "publisher": "GitHub_M",
      "title": "Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation",
      "affected": {
        "vendors": [
          "pimcore"
        ],
        "products": [
          {
            "vendor": "pimcore",
            "product": "pimcore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09967
      },
      "nvd": {
        "published": "2026-07-09T21:16:56.150",
        "lastModified": "2026-07-10T21:16:55.400",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55212",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Pimcore guards class-definition creation with the objects permission instead of the classes permission required for that action.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-f97c-ph8j-8vff",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pimcore/studio-backend-bundle/pull/1886",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/studio-backend-bundle/commit/d1a4788c0f159c360d550c34256c8abbbd633ae0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/studio-backend-bundle/releases/tag/v2025.4.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pimcore/studio-backend-bundle/releases/tag/v2026.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 661,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55213",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:16:32.627Z",
      "date_published": "2026-07-10T20:49:58.764Z",
      "date_updated": "2026-07-13T14:14:45.685Z",
      "publisher": "GitHub_M",
      "title": "h2o: musl libc stack overflow (QPACK)",
      "affected": {
        "vendors": [
          "h2o"
        ],
        "products": [
          {
            "vendor": "h2o",
            "product": "h2o"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27007
      },
      "nvd": {
        "published": "2026-07-10T21:16:55.497",
        "lastModified": "2026-07-13T19:24:52.303",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55213",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A peer-controlled QPACK instruction can drive an approximately 800-kilobyte alloca that exceeds the default musl thread stack.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/h2o/h2o/security/advisories/GHSA-432c-8xmj-frmq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/h2o/h2o/commit/edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55219",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:16:32.628Z",
      "date_published": "2026-07-20T20:20:44.944Z",
      "date_updated": "2026-07-20T21:45:00.984Z",
      "publisher": "GitHub_M",
      "title": "Paymenter: Race condition in payWithCredit() enables credit double-spend",
      "affected": {
        "vendors": [
          "Paymenter"
        ],
        "products": [
          {
            "vendor": "Paymenter",
            "product": "Paymenter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04183
      },
      "nvd": {
        "published": "2026-07-20T21:16:48.687",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55219",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The credit-balance row lock is issued outside a database transaction, so concurrent payments can spend the same balance twice.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Paymenter/Paymenter/security/advisories/GHSA-pgcq-8grm-5rx9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1185,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55229",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:16:32.628Z",
      "date_published": "2026-07-10T20:35:12.809Z",
      "date_updated": "2026-07-13T16:19:22.189Z",
      "publisher": "GitHub_M",
      "title": "Gotenberg: SSRF via LibreOffice document processing",
      "affected": {
        "vendors": [
          "gotenberg"
        ],
        "products": [
          {
            "vendor": "gotenberg",
            "product": "gotenberg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00355,
        "percentile": 0.28198
      },
      "nvd": {
        "published": "2026-07-10T21:16:55.630",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55229",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LibreOffice conversion follows document-linked HTTP and local-file resources without constraining them to an approved destination set.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gotenberg/gotenberg/security/advisories/GHSA-2mrg-35hw-x3x9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gotenberg/gotenberg/commit/98fc40347885ad510a311b990a73397c6d4143db",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gotenberg/gotenberg/releases/tag/v8.34.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 414,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55233",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:44:00.623Z",
      "date_published": "2026-07-10T19:59:59.530Z",
      "date_updated": "2026-07-13T18:10:43.893Z",
      "publisher": "GitHub_M",
      "title": "OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstream",
      "affected": {
        "vendors": [
          "openresty"
        ],
        "products": [
          {
            "vendor": "openresty",
            "product": "openresty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26968
      },
      "nvd": {
        "published": "2026-07-10T21:16:55.760",
        "lastModified": "2026-07-14T19:20:51.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55233",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "openresty copies, writes, or indexes attacker-influenced data without enforcing the destination buffer or object bounds required by the operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openresty/openresty/security/advisories/GHSA-wx83-v28q-68gx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/openresty/openresty/commit/5c56ad2958a2dad8b2cc99f4987b8642cbc647d1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 594,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55234",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:44:00.623Z",
      "date_published": "2026-07-15T21:13:35.600Z",
      "date_updated": "2026-07-16T15:12:11.967Z",
      "publisher": "GitHub_M",
      "title": "Wekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are not a member of (cross-board write via collection allow rule)",
      "affected": {
        "vendors": [
          "wekan"
        ],
        "products": [
          {
            "vendor": "wekan",
            "product": "wekan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15551
      },
      "nvd": {
        "published": "2026-07-15T22:17:25.880",
        "lastModified": "2026-07-16T16:19:13.690",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55234",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Wekan checks write authority against the stored source boardId and never validates the replacement boardId in the update modifier.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wekan/wekan/security/advisories/GHSA-gm7v-pc38-53jr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/commit/d369a3614a4737c29d48a6345a790edf2506ddae",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/releases/tag/v9.37",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55238",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:44:00.624Z",
      "date_published": "2026-07-20T17:05:01.470Z",
      "date_updated": "2026-07-20T19:07:08.673Z",
      "publisher": "GitHub_M",
      "title": "xrdp: Malformed Confirm Active capability sets cause out-of-bounds reads",
      "affected": {
        "vendors": [
          "neutrinolabs"
        ],
        "products": [
          {
            "vendor": "neutrinolabs",
            "product": "xrdp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22852
      },
      "nvd": {
        "published": "2026-07-20T17:18:07.277",
        "lastModified": "2026-07-22T20:06:18.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55238",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "xrdp reads beyond the available buffer because an input length, offset, or parser boundary is not checked before access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-mg8j-x9rw-9xv3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 796,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55242",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:44:00.624Z",
      "date_published": "2026-07-15T15:38:31.577Z",
      "date_updated": "2026-07-15T16:02:44.516Z",
      "publisher": "GitHub_M",
      "title": "ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix",
      "affected": {
        "vendors": [
          "frappe"
        ],
        "products": [
          {
            "vendor": "frappe",
            "product": "erpnext"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03514
      },
      "nvd": {
        "published": "2026-07-15T16:16:48.960",
        "lastModified": "2026-07-15T20:49:41.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55242",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ERPNext treats an operational user's autonaming configuration as a server-side template that can access data outside that user's permissions.",
        "basis": [
          "CNA",
          "CWE-863",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frappe/erpnext/security/advisories/GHSA-pxf3-4gvc-v45j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55254",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T16:44:00.625Z",
      "date_published": "2026-07-17T19:55:16.728Z",
      "date_updated": "2026-07-20T18:07:31.078Z",
      "publisher": "GitHub_M",
      "title": "NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation",
      "affected": {
        "vendors": [
          "ncalc"
        ],
        "products": [
          {
            "vendor": "ncalc",
            "product": "ncalc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08409
      },
      "nvd": {
        "published": "2026-07-17T20:17:27.023",
        "lastModified": "2026-07-23T16:13:02.287",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55254",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NCalc accepts an unbounded factorial operand whose arithmetic wrap leaves the computation consuming work without an effective termination bound.",
        "basis": [
          "CNA",
          "CWE-190",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ncalc/ncalc/security/advisories/GHSA-3w5p-95mh-gq75",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ncalc/ncalc/pull/575",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ncalc/ncalc/commit/eeb6155ee1899b1fdf2cda3da35a4f0ca93ffd6a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ncalc/ncalc/releases/tag/v6.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 439,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55370",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T18:57:40.181Z",
      "date_published": "2026-07-10T19:56:53.317Z",
      "date_updated": "2026-07-10T20:14:41.325Z",
      "publisher": "GitHub_M",
      "title": "Logto: TOTP code can be replayed within the RFC 6238 validity window (one-time use violation)",
      "affected": {
        "vendors": [
          "logto-io"
        ],
        "products": [
          {
            "vendor": "logto-io",
            "product": "logto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09912
      },
      "nvd": {
        "published": "2026-07-10T20:16:46.333",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55370",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 1.41.0, Logto's existing TOTP verification accepted a successfully used TOTP code again while the code remained inside the RFC 6238 acceptance window because the verifier used otplib's stateless check with window = 1 and did not persist or compare the accepted TOTP time-step counter.",
        "basis": [
          "CNA",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/logto-io/logto/security/advisories/GHSA-6wj7-c66m-6c82",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/logto-io/logto/pull/9109",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/logto-io/logto/commit/9118867f6cbadc7291cf913beb4fede91ed5d374",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/logto-io/logto/releases/tag/v1.41.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T18:57:40.181Z",
      "date_published": "2026-07-10T19:57:58.088Z",
      "date_updated": "2026-07-13T16:20:47.725Z",
      "publisher": "GitHub_M",
      "title": "Logto: Account Center MFA management step-up bypass via WebAuthn registration verification",
      "affected": {
        "vendors": [
          "logto-io"
        ],
        "products": [
          {
            "vendor": "logto-io",
            "product": "logto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17526
      },
      "nvd": {
        "published": "2026-07-10T20:16:46.460",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55377",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prior to 1.41.0, Logto's Account Center step-up check accepted any active verification record that belonged to the current user and had isVerified === true.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/logto-io/logto/security/advisories/GHSA-q4h3-38gc-4p4j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/logto-io/logto/pull/9110",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/logto-io/logto/commit/f56255a7edf3b22b0ec2fdb814814ce6b0123b74",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/logto-io/logto/releases/tag/v1.41.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 637,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55379",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T18:57:40.181Z",
      "date_published": "2026-07-06T18:52:11.633Z",
      "date_updated": "2026-07-06T19:17:03.941Z",
      "publisher": "GitHub_M",
      "title": "Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00421,
        "percentile": 0.34741
      },
      "nvd": {
        "published": "2026-07-06T19:17:08.577",
        "lastModified": "2026-07-07T18:59:01.817",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55379",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The BDF font loader passes attacker-controlled dimensions to Image.new() without Pillow's decompression-bomb size check.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 388,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T18:57:40.182Z",
      "date_published": "2026-07-06T18:50:14.789Z",
      "date_updated": "2026-07-06T19:23:30.046Z",
      "publisher": "GitHub_M",
      "title": "Pillow GdImageFile decompression bomb protection bypass",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.3442
      },
      "nvd": {
        "published": "2026-07-06T19:17:08.703",
        "lastModified": "2026-07-07T18:58:54.647",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55380",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The GD loader trusts header dimensions without the decompression-bomb size check, allowing a small file to request excessive C-heap allocation.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T18:57:40.183Z",
      "date_published": "2026-07-28T21:49:21.260Z",
      "date_updated": "2026-07-29T12:33:45.388Z",
      "publisher": "GitHub_M",
      "title": "datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-610",
          "name": "Externally Controlled Reference to a Resource in Another Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28918
      },
      "nvd": {
        "published": "2026-07-28T22:17:48.400",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55389",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled path or reference can select a file outside the intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-22",
          "CWE-610"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-8359-h9fx-j6v9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/2ff4a72b4550a2b2069754c5b075b1655067e5fb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.62.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T18:57:40.183Z",
      "date_published": "2026-07-28T21:25:32.208Z",
      "date_updated": "2026-07-29T14:16:03.510Z",
      "publisher": "GitHub_M",
      "title": "Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-610",
          "name": "Externally Controlled Reference to a Resource in Another Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28803
      },
      "nvd": {
        "published": "2026-07-28T22:17:48.557",
        "lastModified": "2026-07-30T20:02:44.977",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55390",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "datamodel-code-generator accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-200",
          "CWE-610"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-442q-2j6p-642g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/d2d5cecd9fd3a2a6dbf148bf0740b83a11fc6820",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.62.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T18:57:40.183Z",
      "date_published": "2026-07-28T21:45:39.058Z",
      "date_updated": "2026-07-29T13:30:14.117Z",
      "publisher": "GitHub_M",
      "title": "datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-350",
          "name": "Reliance on Reverse DNS Resolution for a Security-Critical Action",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09646
      },
      "nvd": {
        "published": "2026-07-28T22:17:48.697",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55391",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SSRF guard validates one DNS resolution but the HTTP client resolves again, allowing a rebinding host to reach a private address.",
        "basis": [
          "CNA",
          "CWE-350",
          "CWE-367",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-vx7x-vcc2-c44g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/25c8b7e497419eb20b230fa3318c04f9bebc5a6f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.63.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://gist.github.com/thegr1ffyn/c1d54dd6ff2a4c0d7d0dabe00c4985f4",
          "host": "gist.github.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:26:37.698Z",
      "date_published": "2026-07-15T20:17:00.166Z",
      "date_updated": "2026-07-16T13:08:45.489Z",
      "publisher": "Absolute",
      "title": "Memory management vulnerability in Secure Access clients",
      "affected": {
        "vendors": [
          "Absolute Security"
        ],
        "products": [
          {
            "vendor": "Absolute Security",
            "product": "Secure Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:SecurityResponse@netmotionsoftware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 3.2,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11202
      },
      "nvd": {
        "published": "2026-07-15T21:16:54.980",
        "lastModified": "2026-07-16T16:27:38.407",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55398",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Memory management can corrupt or exhaust process memory, but the public record does not identify the bounds, ownership, or lifetime failure.",
        "basis": [
          "CNA",
          "CWE-119",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-55398",
          "host": "www.absolute.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:26:37.698Z",
      "date_published": "2026-07-15T20:20:13.950Z",
      "date_updated": "2026-07-16T13:07:32.872Z",
      "publisher": "Absolute",
      "title": "Resource exhaustion vulnerability in the Secure Access publisher",
      "affected": {
        "vendors": [
          "Absolute Security"
        ],
        "products": [
          {
            "vendor": "Absolute Security",
            "product": "Secure Access"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:SecurityResponse@netmotionsoftware.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12195
      },
      "nvd": {
        "published": "2026-07-15T21:16:55.083",
        "lastModified": "2026-07-16T16:25:48.123",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55399",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A credentialed Secure Access tunnel client can exhaust a publisher resource, but the record does not identify the resource or missing limit.",
        "basis": [
          "CNA record",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-55399",
          "host": "www.absolute.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.124Z",
      "date_published": "2026-07-28T21:31:49.172Z",
      "date_updated": "2026-07-29T12:46:11.346Z",
      "publisher": "GitHub_M",
      "title": "datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11508
      },
      "nvd": {
        "published": "2026-07-28T22:17:48.840",
        "lastModified": "2026-07-30T20:02:12.943",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55403",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "datamodel-code-generator accepts an attacker-controlled redirect destination without restricting navigation to an approved host.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-r5vv-ff45-prp2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/a585c037c8307b7aae815de193b7fe1c4c44994b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.63.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.124Z",
      "date_published": "2026-07-08T19:36:48.792Z",
      "date_updated": "2026-07-09T14:41:17.681Z",
      "publisher": "GitHub_M",
      "title": "yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output",
      "affected": {
        "vendors": [
          "yt-dlp"
        ],
        "products": [
          {
            "vendor": "yt-dlp",
            "product": "yt-dlp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00412,
        "percentile": 0.33947
      },
      "nvd": {
        "published": "2026-07-08T20:16:52.987",
        "lastModified": "2026-07-13T17:01:13.303",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55404",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "yt-dlp writes attacker-controlled URL or metadata text into shortcut-file grammar without escaping file URIs or newlines.",
        "basis": [
          "CNA",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-6v4j-43gg-vj32",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/yt-dlp/yt-dlp/commit/b6590aaa1e3808155d69c9a79a797ae484163789",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yt-dlp/yt-dlp/releases/tag/2026.07.04",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 505,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55405",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.124Z",
      "date_published": "2026-07-10T20:33:40.804Z",
      "date_updated": "2026-07-13T14:07:50.892Z",
      "publisher": "GitHub_M",
      "title": "LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector",
      "affected": {
        "vendors": [
          "langchain4j"
        ],
        "products": [
          {
            "vendor": "langchain4j",
            "product": "langchain4j"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27481
      },
      "nvd": {
        "published": "2026-07-10T21:16:55.977",
        "lastModified": "2026-07-13T18:09:30.873",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55405",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In langchain4j, attacker-controlled input reaches an SQL statement without the required parameter binding or SQL-context escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/langchain4j/langchain4j/security/advisories/GHSA-2mfg-cc43-9pcj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/langchain4j/langchain4j/commit/13a0698bdfaf105d8aaf0367881df51358596219",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/langchain4j/langchain4j/commit/1bc1f60aa58ef5c3c1703caf73362482480351cf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/langchain4j/langchain4j/commit/8805d5d128694302f1b0a2650174186862f669e7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/langchain4j/langchain4j/commit/ce96291dfb243c7f6753b5d65c7a77914642314f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/langchain4j/langchain4j/commit/f14a10ce77e4ea1b8277f67d6a81f46abd7a5bc2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/langchain4j/langchain4j/releases/tag/1.16.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 806,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55406",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.124Z",
      "date_published": "2026-07-16T15:54:29.511Z",
      "date_updated": "2026-07-16T16:47:37.717Z",
      "publisher": "GitHub_M",
      "title": "Buffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref",
      "affected": {
        "vendors": [
          "anthropics"
        ],
        "products": [
          {
            "vendor": "anthropics",
            "product": "buffa"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02829
      },
      "nvd": {
        "published": "2026-07-16T17:16:57.623",
        "lastModified": "2026-07-16T17:36:10.603",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55406",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path can retain or dereference an object after its storage has been released, leaving a dangling reference.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/anthropics/buffa/security/advisories/GHSA-9pwq-gcrx-wghh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/anthropics/buffa/pull/154",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/anthropics/buffa/commit/7dcf50a1a40eca6ed8d6c6dd59f4310aa0d68b0e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/anthropics/buffa/releases/tag/v0.7.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 786,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55407",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.124Z",
      "date_published": "2026-07-16T15:57:31.704Z",
      "date_updated": "2026-07-16T18:04:39.764Z",
      "publisher": "GitHub_M",
      "title": "Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation",
      "affected": {
        "vendors": [
          "anthropics"
        ],
        "products": [
          {
            "vendor": "anthropics",
            "product": "buffa"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00423,
        "percentile": 0.34847
      },
      "nvd": {
        "published": "2026-07-16T17:16:57.770",
        "lastModified": "2026-07-16T19:16:50.603",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55407",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "decode_unknown_field allocates for nested and length-delimited unknown fields without an in-decode budget, allowing a small protobuf to amplify into excessive heap use.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400",
          "CWE-770",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/anthropics/buffa/security/advisories/GHSA-f9qc-qg88-7pq5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/anthropics/buffa/pull/184",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/anthropics/buffa/commit/278fa43fcff661d4ee6bd83b75955a153d4281fc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/anthropics/buffa/releases/tag/v0.8.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 890,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55408",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.124Z",
      "date_published": "2026-07-07T21:02:43.310Z",
      "date_updated": "2026-07-08T14:08:02.043Z",
      "publisher": "GitHub_M",
      "title": "Koodo Reader: Remote code execution via malicious epub file",
      "affected": {
        "vendors": [
          "koodo-reader"
        ],
        "products": [
          {
            "vendor": "koodo-reader",
            "product": "koodo-reader"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08608
      },
      "nvd": {
        "published": "2026-07-07T22:16:53.790",
        "lastModified": "2026-07-08T15:16:29.527",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55408",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Koodo Reader renders EPUB chapter HTML with Node integration enabled in subframes, allowing a hidden iframe in a book to invoke operating-system APIs.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koodo-reader/koodo-reader/security/advisories/GHSA-mjr7-w4jq-2rq9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.125Z",
      "date_published": "2026-07-15T20:19:54.632Z",
      "date_updated": "2026-07-18T01:52:49.269Z",
      "publisher": "GitHub_M",
      "title": "NocoBase backup restore schema name allows command injection",
      "affected": {
        "vendors": [
          "nocobase"
        ],
        "products": [
          {
            "vendor": "nocobase",
            "product": "nocobase"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29757
      },
      "nvd": {
        "published": "2026-07-15T21:16:55.183",
        "lastModified": "2026-07-18T02:17:10.037",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55410",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted bytes become executable interpreter syntax without the required grammar separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nocobase/nocobase/security/advisories/GHSA-p853-83gj-wjj3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nocobase/nocobase/commit/0e1aba1b7b112ffc841588963f7343c00edd9806",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nocobase/nocobase/releases/tag/v2.1.19",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 477,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55415",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.125Z",
      "date_published": "2026-07-28T21:37:55.642Z",
      "date_updated": "2026-07-29T14:06:25.028Z",
      "publisher": "GitHub_M",
      "title": "datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-95",
          "name": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19849
      },
      "nvd": {
        "published": "2026-07-28T22:17:48.983",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55415",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The datamodel-code-generator code-generation path permits attacker-controlled directives to enter executable code without the required grammar separation.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-95"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-5578-w22f-pfx9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/577d49569c2254c371a97e495020ae2238a73b84",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.64.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 650,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55417",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.125Z",
      "date_published": "2026-07-07T20:02:54.306Z",
      "date_updated": "2026-07-08T13:11:19.485Z",
      "publisher": "GitHub_M",
      "title": "Chevereto private profile setting leaks username on /json endpoint",
      "affected": {
        "vendors": [
          "chevereto"
        ],
        "products": [
          {
            "vendor": "chevereto",
            "product": "chevereto"
          },
          {
            "vendor": "chevereto",
            "product": "chevereto/chevereto"
          },
          {
            "vendor": "chevereto",
            "product": "rodber/chevereto-free"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16282
      },
      "nvd": {
        "published": "2026-07-07T21:17:27.160",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55417",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Chevereto hides a private listing in HTML but returns the same listing through a JSON endpoint without the required read authorization.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/chevereto/chevereto/security/advisories/GHSA-h4jp-mxfx-g8xp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://chevereto.com/community/threads/chevereto-v4-5-4-announcement.16398/post-80153",
          "host": "chevereto.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.125Z",
      "date_published": "2026-07-07T21:18:45.315Z",
      "date_updated": "2026-07-09T14:42:06.607Z",
      "publisher": "GitHub_M",
      "title": "FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)",
      "affected": {
        "vendors": [
          "labring"
        ],
        "products": [
          {
            "vendor": "labring",
            "product": "FastGPT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22152
      },
      "nvd": {
        "published": "2026-07-07T22:16:53.930",
        "lastModified": "2026-07-09T16:16:44.800",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55418",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unrelated resource and then sign or read an S3 object using a key taken directly from the request, without checking that the key belongs to the caller's team.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/labring/FastGPT/security/advisories/GHSA-6rxv-p43w-mmx5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/pull/7104",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/commit/decb6d2fb1417fb9e2bca145d2dcc9cbcf06396c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/releases/tag/v4.15.0-beta5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 560,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55420",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.125Z",
      "date_published": "2026-07-09T17:54:07.940Z",
      "date_updated": "2026-07-14T01:08:46.909Z",
      "publisher": "GitHub_M",
      "title": "Discourse: Remote code execution via pdf uploads",
      "affected": {
        "vendors": [
          "discourse"
        ],
        "products": [
          {
            "vendor": "discourse",
            "product": "discourse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27451
      },
      "nvd": {
        "published": "2026-07-09T18:16:54.440",
        "lastModified": "2026-07-14T02:16:56.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55420",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Discourse PDF processing reaches an operating-system command boundary under non-default configurations, but the public record does not disclose the command or input.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/discourse/discourse/security/advisories/GHSA-7wq5-jgww-5rw3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/ca5a7e06167561928556afa2f237d67e459c6914",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 286,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.126Z",
      "date_published": "2026-07-09T22:01:22.249Z",
      "date_updated": "2026-07-10T14:40:09.311Z",
      "publisher": "GitHub_M",
      "title": "Discourse: Topic featured link susceptible to stored XSS",
      "affected": {
        "vendors": [
          "discourse"
        ],
        "products": [
          {
            "vendor": "discourse",
            "product": "discourse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22174
      },
      "nvd": {
        "published": "2026-07-09T22:17:06.097",
        "lastModified": "2026-07-14T01:26:52.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55424",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/discourse/discourse/security/advisories/GHSA-695w-7fv8-mxg3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/1bce8881e4253d9bbab56f011a12ef899b926b59",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/6679d9a5083488bae10c2adbb345c481c583242c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/6828aee9b15c2655d63b515ac919830bd540ff83",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/c9b9405f5bd0bf0269e505e28e3aad388d7657c5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 427,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:48:43.126Z",
      "date_published": "2026-07-07T23:55:26.240Z",
      "date_updated": "2026-07-08T13:10:01.820Z",
      "publisher": "GitHub_M",
      "title": "Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18615
      },
      "nvd": {
        "published": "2026-07-08T00:16:33.323",
        "lastModified": "2026-07-08T19:44:24.297",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55427",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Coder places a caller-controlled value containing newlines into an SSH configuration file, allowing the value to inject additional directives.",
        "basis": [
          "CNA",
          "CWE-74",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-mcqq-fqgf-rxwm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/26154",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 906,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.016Z",
      "date_published": "2026-07-07T23:57:45.338Z",
      "date_updated": "2026-07-08T13:11:08.435Z",
      "publisher": "GitHub_M",
      "title": "Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15923
      },
      "nvd": {
        "published": "2026-07-08T00:16:33.463",
        "lastModified": "2026-07-08T19:44:06.553",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55428",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The tailnet coordinator binds Addresses to the authenticated agent UUID but forwards agent-supplied AllowedIPs without the same identity-to-prefix check.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-wrq8-fcv5-8hvp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/26144",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 674,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55429",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.017Z",
      "date_published": "2026-07-08T00:00:33.785Z",
      "date_updated": "2026-07-08T14:41:39.988Z",
      "publisher": "GitHub_M",
      "title": "Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20903
      },
      "nvd": {
        "published": "2026-07-08T00:16:33.597",
        "lastModified": "2026-07-08T19:43:31.533",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55429",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Workspace app upsert accepts a caller-controlled app ID and can rebind an existing cross-workspace row without verifying that it belongs to the workspace being built.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-9rjw-3gwp-f59v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/26103",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 833,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.017Z",
      "date_published": "2026-07-08T00:03:29.728Z",
      "date_updated": "2026-07-08T17:10:40.949Z",
      "publisher": "GitHub_M",
      "title": "Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03845
      },
      "nvd": {
        "published": "2026-07-08T01:16:27.270",
        "lastModified": "2026-07-08T19:43:14.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55430",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The workspace app proxy prefers an untrusted X-Forwarded-Host header when selecting a subdomain app and does not restrict that header to trusted proxies.",
        "basis": [
          "CNA",
          "CWE-345",
          "CWE-441"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-5g4w-3vw9-478w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/26204",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 951,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55431",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.017Z",
      "date_published": "2026-07-08T00:10:49.165Z",
      "date_updated": "2026-07-08T13:57:02.059Z",
      "publisher": "GitHub_M",
      "title": "Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08062
      },
      "nvd": {
        "published": "2026-07-08T01:16:27.480",
        "lastModified": "2026-07-08T19:42:45.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55431",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Coder CLI substitutes a real session token into an attacker-controlled external app URL before handing the URL to the operating system.",
        "basis": [
          "CNA",
          "CWE-522",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-v54h-cp2w-9x4g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/26146",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 862,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55432",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.017Z",
      "date_published": "2026-07-08T00:20:24.264Z",
      "date_updated": "2026-07-08T12:51:10.411Z",
      "publisher": "GitHub_M",
      "title": "Coder's sub-agent app registration bypasses template port-sharing policy enforcement",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07936
      },
      "nvd": {
        "published": "2026-07-08T01:16:27.620",
        "lastModified": "2026-07-08T19:40:36.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55432",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CreateSubAgent persists a requested app sharing level without checking it against the template administrator's MaxPortSharingLevel policy.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-x9qq-2qh5-8rxf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/26061",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 713,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.017Z",
      "date_published": "2026-07-08T00:22:36.304Z",
      "date_updated": "2026-07-08T13:01:44.431Z",
      "publisher": "GitHub_M",
      "title": "Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.131
      },
      "nvd": {
        "published": "2026-07-08T01:16:27.760",
        "lastModified": "2026-07-08T19:39:45.713",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55433",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The recreate endpoint checks only workspace read access and omits the update permission required before a destructive rebuild.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-jqj2-x4c5-jfxm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/25812",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 654,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.017Z",
      "date_published": "2026-07-07T20:14:00.531Z",
      "date_updated": "2026-07-08T14:15:15.446Z",
      "publisher": "GitHub_M",
      "title": "Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23015
      },
      "nvd": {
        "published": "2026-07-07T21:17:27.290",
        "lastModified": "2026-07-08T19:47:17.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55434",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AI Bridge reads the entire authenticated request body without a maximum size and can exhaust process memory.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-f5vp-w269-392g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/26164",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 560,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.017Z",
      "date_published": "2026-07-07T17:37:31.211Z",
      "date_updated": "2026-07-09T14:42:41.115Z",
      "publisher": "GitHub_M",
      "title": "Suspended Coder users retain access to AI Bridge LLM proxy endpoints",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09518
      },
      "nvd": {
        "published": "2026-07-07T19:16:54.873",
        "lastModified": "2026-07-09T16:16:44.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55435",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Account suspension leaves existing API keys valid on AI Bridge endpoints because their authorization path omits suspended-account state.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-wqxv-w64v-5wh6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/26164",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/26173",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/commit/0d2c9f904a8b75b888140fcc8fbf4633660cc787",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 741,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.017Z",
      "date_published": "2026-07-08T00:26:13.175Z",
      "date_updated": "2026-07-08T13:11:46.877Z",
      "publisher": "GitHub_M",
      "title": "Coder's AI Bridge Proxy skips TLS certificate verification in default configuration",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05664
      },
      "nvd": {
        "published": "2026-07-08T01:16:27.890",
        "lastModified": "2026-07-08T19:39:30.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55436",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "coder establishes an encrypted connection without validating the peer certificate or host key, allowing an active network attacker to substitute its own endpoint.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-84rm-42xw-mx52",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/26131",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 996,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55437",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.017Z",
      "date_published": "2026-07-08T00:29:18.268Z",
      "date_updated": "2026-07-08T14:00:43.204Z",
      "publisher": "GitHub_M",
      "title": "Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.0765
      },
      "nvd": {
        "published": "2026-07-08T01:16:28.020",
        "lastModified": "2026-07-08T19:38:48.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55437",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AgentLogLine inserts ansi-to-html output through dangerouslySetInnerHTML without enabling XML escaping.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-7qw2-f75v-62f7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/25808",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 691,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55438",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.017Z",
      "date_published": "2026-07-08T00:31:20.573Z",
      "date_updated": "2026-07-08T17:10:30.943Z",
      "publisher": "GitHub_M",
      "title": "Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing",
      "affected": {
        "vendors": [
          "coder"
        ],
        "products": [
          {
            "vendor": "coder",
            "product": "coder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04661
      },
      "nvd": {
        "published": "2026-07-08T01:16:28.150",
        "lastModified": "2026-07-08T19:38:38.473",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55438",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Coder resolves a UUID workspace by ID but trusts the username embedded in its subdomain for CORS without comparing it to the authoritative owner.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coder/coder/security/advisories/GHSA-5wg6-jmq2-53pw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/26085",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/pull/26086",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.29.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.32.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.33.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 868,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55440",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.017Z",
      "date_published": "2026-07-16T15:35:51.346Z",
      "date_updated": "2026-07-16T16:23:56.463Z",
      "publisher": "GitHub_M",
      "title": "Microsoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated session-squatting denial of service",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "UFO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0066,
        "percentile": 0.48079
      },
      "nvd": {
        "published": "2026-07-16T16:19:13.787",
        "lastModified": "2026-07-16T17:46:04.350",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55440",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "COMMAND_RESULTS creates attacker-chosen sessions without an owner_client_id, letting one authenticated client reserve another client's session identifier.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/UFO/security/advisories/GHSA-hxjv-fmjf-wmjf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/UFO/commit/cc653bde75337ab60c320e6b7cb61b86ba6ca948",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/UFO/releases/tag/3.0.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 507,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.018Z",
      "date_published": "2026-07-15T21:20:01.430Z",
      "date_updated": "2026-07-18T02:37:14.779Z",
      "publisher": "GitHub_M",
      "title": "Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication",
      "affected": {
        "vendors": [
          "whyour"
        ],
        "products": [
          {
            "vendor": "whyour",
            "product": "qinglong"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00404,
        "percentile": 0.332
      },
      "nvd": {
        "published": "2026-07-15T22:17:26.020",
        "lastModified": "2026-07-18T03:16:37.117",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55445",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Qinglong checks only the api init path before a later rewrite maps the unchecked open path to the privileged initialization handler.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/whyour/qinglong/security/advisories/GHSA-v667-gc2r-2xm7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/whyour/qinglong/pull/2941",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/whyour/qinglong/commit/6bec52dca158481258315ba0fc2f11206df7b719",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55452",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T21:59:57.018Z",
      "date_published": "2026-07-10T19:40:05.790Z",
      "date_updated": "2026-07-10T20:58:08.024Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: CSV formula injection in Activity Report export",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1236",
          "name": "Improper Neutralization of Formula Elements in a CSV File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 2.5,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14373
      },
      "nvd": {
        "published": "2026-07-10T20:16:46.590",
        "lastModified": "2026-07-14T12:29:03.427",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55452",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Snipe-IT writes an attacker-controlled User-Agent into CSV without neutralizing spreadsheet formula prefixes.",
        "basis": [
          "CNA",
          "CWE-1236"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-whrx-mmgr-gpcf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/7b7d2c87fbc965a7933b1bf9e3f2c331b8c8e19c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.5.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 445,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55460",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:10:37.608Z",
      "date_published": "2026-07-10T18:39:22.370Z",
      "date_updated": "2026-07-14T13:43:51.341Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Authorization bypass on bulk editing users",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20788
      },
      "nvd": {
        "published": "2026-07-10T19:17:24.667",
        "lastModified": "2026-07-14T14:16:35.080",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55460",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /users/bulksave with delete_user=1 because BulkUsersController::destroy() authorizes only update, allowing the user to soft-delete another non-admin user.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-vgx7-c78r-69w9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/374f426f0c6bb7a4f129f7b85051cc1da753a0f5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 368,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55461",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:10:37.608Z",
      "date_published": "2026-07-10T19:41:50.744Z",
      "date_updated": "2026-07-14T13:47:25.867Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Open Redirect After User Edit",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14144
      },
      "nvd": {
        "published": "2026-07-10T20:16:46.713",
        "lastModified": "2026-07-14T15:17:04.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55461",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer header into Laravel’s intended URL session value and later uses redirect()->intended(...) when redirect_option=back is submitted, allowing Snipe-IT to be used as a trusted redirector after a legitimate user edit action.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-wg2f-x2c2-c4rp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/f4cac9635868c020174361ad7a80b2545a4e7623",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 405,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55462",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:10:37.608Z",
      "date_published": "2026-07-10T19:35:05.107Z",
      "date_updated": "2026-07-13T15:01:17.917Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Authorization bypass on print inventory page",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20027
      },
      "nvd": {
        "published": "2026-07-10T20:16:46.837",
        "lastModified": "2026-07-14T12:21:23.217",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55462",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The inventory print path authorizes viewing the user but omits the separate permissions protecting assigned license and cost data.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-fc33-6w3q-538h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/374f426f0c6bb7a4f129f7b85051cc1da753a0f5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 417,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55464",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:10:37.608Z",
      "date_published": "2026-07-10T18:40:42.050Z",
      "date_updated": "2026-07-13T15:00:18.011Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Stored XSS via Markdown custom field",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06908
      },
      "nvd": {
        "published": "2026-07-10T19:17:24.800",
        "lastModified": "2026-07-13T16:16:37.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55464",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Markdown link rendering escapes raw HTML but leaves javascript: URIs active, so a clicked attacker-supplied link executes in the site's origin.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-r52f-r9v5-66xr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/006981cccffce1739e24d3b680b676f772f40e2d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55466",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:10:37.608Z",
      "date_published": "2026-07-10T19:37:54.362Z",
      "date_updated": "2026-07-13T18:22:07.780Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Stored XSS via inline-served attachment",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 2.499999999999999,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27311
      },
      "nvd": {
        "published": "2026-07-10T20:16:46.970",
        "lastModified": "2026-07-14T12:18:23.297",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55466",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-jhph-5q74-pmfx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/000cea0a622d586366cf60d2240c7c2a4b17c955",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55469",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:10:37.608Z",
      "date_published": "2026-07-10T19:42:36.798Z",
      "date_updated": "2026-07-10T20:16:14.160Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Path traversal vulnerability via CSV import `image` field",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00378,
        "percentile": 0.30519
      },
      "nvd": {
        "published": "2026-07-10T20:16:47.093",
        "lastModified": "2026-07-14T12:14:48.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55469",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "snipe-it accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-xr9m-gphc-9p63",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/abc4363e8393b29a5566b8c50144426af72bbc97",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55470",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:10:37.608Z",
      "date_published": "2026-07-08T21:27:34.034Z",
      "date_updated": "2026-07-09T12:59:00.576Z",
      "publisher": "GitHub_M",
      "title": "HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS",
      "affected": {
        "vendors": [
          "hapifhir"
        ],
        "products": [
          {
            "vendor": "hapifhir",
            "product": "org.hl7.fhir.core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00445,
        "percentile": 0.36551
      },
      "nvd": {
        "published": "2026-07-08T22:17:15.377",
        "lastModified": "2026-07-16T16:31:26.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55470",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DSTU2 FHIRPathEngine.matches runs attacker-supplied regular expressions without a timeout and permits catastrophic backtracking to consume the event loop.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-fxj4-p9xp-37v5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/commit/56376f7986222626af061ca7fc27ee1ab030e590",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/releases/tag/6.9.10",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 510,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55471",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:10:37.608Z",
      "date_published": "2026-07-08T21:28:45.390Z",
      "date_updated": "2026-07-09T13:26:16.545Z",
      "publisher": "GitHub_M",
      "title": "HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory",
      "affected": {
        "vendors": [
          "hapifhir"
        ],
        "products": [
          {
            "vendor": "hapifhir",
            "product": "org.hl7.fhir.core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00376,
        "percentile": 0.30374
      },
      "nvd": {
        "published": "2026-07-08T22:17:15.520",
        "lastModified": "2026-07-16T16:32:45.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55471",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TransformerFactory processes external XML entities without the hardening needed to keep the parser inside its intended data boundary.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-2f55-g35j-5jmf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/commit/01ca2ecdefec9b33204d2495fe78af8c0dc52298",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hapifhir/org.hl7.fhir.core/releases/tag/6.9.10",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 558,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55472",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:10:37.609Z",
      "date_published": "2026-07-10T18:36:58.923Z",
      "date_updated": "2026-07-13T18:22:44.183Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09661
      },
      "nvd": {
        "published": "2026-07-10T19:17:24.920",
        "lastModified": "2026-07-13T19:17:13.897",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55472",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The API detects a parent-child company mismatch but continues, creating a location beneath a parent owned by another tenant.",
        "basis": [
          "CNA record",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-8w8c-8mx9-52cw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/9a8cbd6e00613a726b639a97a1da71b3c54f9489",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55474",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:10:37.609Z",
      "date_published": "2026-07-10T18:29:56.511Z",
      "date_updated": "2026-07-10T19:12:30.256Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Directory traversal in displaySig",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00329,
        "percentile": 0.25452
      },
      "nvd": {
        "published": "2026-07-10T19:17:25.080",
        "lastModified": "2026-07-10T20:16:47.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55474",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "snipe-it accepts relative path segments that can escape the intended directory.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-c6f4-wj38-m3g3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/pull/18927",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/cd69a7ea53e030e6e05f08be18daac672c8c4121",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.5.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 378,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55475",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:10:37.609Z",
      "date_published": "2026-07-10T19:43:56.948Z",
      "date_updated": "2026-07-13T16:11:50.638Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Import created_by can be overwritten",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00192,
        "percentile": 0.0911
      },
      "nvd": {
        "published": "2026-07-10T20:16:47.333",
        "lastModified": "2026-07-14T12:14:09.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55475",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The import API accepts a caller-supplied created_by value without authorizing the caller to change import ownership.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-5wx7-xq8j-v4qm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/pull/19072",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/39fbe983132feca2ef15c1c0200fcc77c23a1434",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:10:37.609Z",
      "date_published": "2026-07-10T18:35:49.893Z",
      "date_updated": "2026-07-13T16:15:56.129Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.002,
        "percentile": 0.10036
      },
      "nvd": {
        "published": "2026-07-10T19:17:25.230",
        "lastModified": "2026-07-13T17:17:33.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55476",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The asset-request route trusts cancel_by_admin and a supplied user ID without checking that the caller may cancel the target user's request.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-53jc-27pc-x8r8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/3c1b18919afbba12d419a9795929493b0391c91a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/ac2162113d9e25e4c61b61916ce67fb2a1050553",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55478",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:28:27.061Z",
      "date_published": "2026-07-10T18:34:15.757Z",
      "date_updated": "2026-07-10T20:58:14.783Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Missing object-level authorization in Kits API",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.00175,
        "percentile": 0.0723
      },
      "nvd": {
        "published": "2026-07-10T19:17:25.580",
        "lastModified": "2026-07-10T21:16:56.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55478",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The request accepts an object or tenant identifier without binding that identifier to the authenticated caller's authorized scope.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-crv3-j83j-f3r6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/0d870d540d27107634f3134e0e7f106b3faa6992",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55479",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:28:27.061Z",
      "date_published": "2026-07-10T19:40:52.446Z",
      "date_updated": "2026-07-10T20:57:59.427Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Incorrect permission for legacy license checkin API",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08837
      },
      "nvd": {
        "published": "2026-07-10T20:16:47.463",
        "lastModified": "2026-07-14T12:41:29.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55479",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The legacy license check-in endpoint tests checkout permission instead of check-in permission, allowing a user to reclaim another assignee's seat.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-8frh-vhgh-64cf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/80c8aa41dc813b0815db00bb44eb0fff9f89a227",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 402,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:28:27.061Z",
      "date_published": "2026-07-10T19:45:14.984Z",
      "date_updated": "2026-07-14T13:51:35.022Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: CSS Injection via `header_color` Setting",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14632
      },
      "nvd": {
        "published": "2026-07-10T20:16:47.587",
        "lastModified": "2026-07-14T15:17:04.540",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55481",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The snipe-it rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-w7qw-5wfv-gwx9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/pull/19097",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/c31190a128ec96fb34000a2f27eae198b1a51d40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 411,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:28:27.062Z",
      "date_published": "2026-07-07T21:08:26.638Z",
      "date_updated": "2026-07-08T13:52:07.490Z",
      "publisher": "GitHub_M",
      "title": "OpenWrt: EAD Integer Underflow → Pre-Auth Denial of Service",
      "affected": {
        "vendors": [
          "openwrt"
        ],
        "products": [
          {
            "vendor": "openwrt",
            "product": "openwrt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00987,
        "percentile": 0.5901
      },
      "nvd": {
        "published": "2026-07-07T22:16:54.060",
        "lastModified": "2026-07-10T17:37:00.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55490",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Integer arithmetic underflows and produces an invalid size or offset used for memory access.",
        "basis": [
          "CNA",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openwrt/openwrt/security/advisories/GHSA-9558-77jp-g3fw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/openwrt/openwrt/commit/63c0767f3d02f7b10b0f0b5293366bd059a08ca5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openwrt/openwrt/releases/tag/v25.12.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 401,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55495",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:28:27.062Z",
      "date_published": "2026-07-31T02:58:14.080Z",
      "date_updated": "2026-07-31T19:27:00.216Z",
      "publisher": "GitHub_M",
      "title": "Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account",
      "affected": {
        "vendors": [
          "cloudreve"
        ],
        "products": [
          {
            "vendor": "cloudreve",
            "product": "cloudreve"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00376,
        "percentile": 0.30381
      },
      "nvd": {
        "published": "2026-07-31T04:17:22.597",
        "lastModified": "2026-07-31T20:16:52.113",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55495",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PUT_RELATIVE treats X-WOPI-SuggestedTarget as a path, so slash and dot-dot segments can escape the source file directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-49h3-cwhj-4737",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/commit/7968e50429efab40ffa8f57fecdfbd5a73d23630",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:28:27.062Z",
      "date_published": "2026-07-31T03:23:33.099Z",
      "date_updated": "2026-07-31T14:02:34.248Z",
      "publisher": "GitHub_M",
      "title": "Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate",
      "affected": {
        "vendors": [
          "cloudreve"
        ],
        "products": [
          {
            "vendor": "cloudreve",
            "product": "cloudreve"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-359",
          "name": "Exposure of Private Personal Information to an Unauthorized Actor",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28788
      },
      "nvd": {
        "published": "2026-07-31T04:17:22.877",
        "lastModified": "2026-07-31T14:16:50.340",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55496",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Cloudreve search omits the active-account predicate and returns email addresses for users who should not be discoverable.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-359"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-8r7f-r8hj-r3rv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/commit/7e1289d552794bdbeb551be78456115c87dcb3da",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 694,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55497",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:28:27.062Z",
      "date_published": "2026-07-31T03:28:59.171Z",
      "date_updated": "2026-07-31T15:58:48.793Z",
      "publisher": "GitHub_M",
      "title": "Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)",
      "affected": {
        "vendors": [
          "cloudreve"
        ],
        "products": [
          {
            "vendor": "cloudreve",
            "product": "cloudreve"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00531,
        "percentile": 0.41899
      },
      "nvd": {
        "published": "2026-07-31T04:17:23.137",
        "lastModified": "2026-07-31T16:17:07.187",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55497",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Cloudreve limits compressed image size but leaves decoded pixel dimensions unbounded, allowing a small image to force a fatal allocation during thumbnail or avatar decoding.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-409",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-g9j2-8w95-3vwv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/commit/3607f79bb44c35d0be4fa8b6e24c0502b51415a9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 417,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:28:27.062Z",
      "date_published": "2026-07-31T03:34:33.206Z",
      "date_updated": "2026-07-31T23:15:27.840Z",
      "publisher": "GitHub_M",
      "title": "Cloudreve: Broken access control in file event stream leaks activity events for unshared siblings to single-file share recipients",
      "affected": {
        "vendors": [
          "cloudreve"
        ],
        "products": [
          {
            "vendor": "cloudreve",
            "product": "cloudreve"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25638
      },
      "nvd": {
        "published": "2026-07-31T04:17:23.380",
        "lastModified": "2026-08-01T00:17:17.157",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55499",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A single-file share subscribes to the owner parent-folder event topic and consequently exposes events for unshared siblings.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w8x7-h2px-xmq8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/commit/0b00dd308f132d6e6e8476857ef79f4865600bbc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55500",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:28:27.062Z",
      "date_published": "2026-07-10T15:28:27.620Z",
      "date_updated": "2026-07-10T15:41:31.178Z",
      "publisher": "GitHub_M",
      "title": "9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database Takeover",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.31493
      },
      "nvd": {
        "published": "2026-07-10T16:16:33.357",
        "lastModified": "2026-07-10T17:25:46.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55500",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The database import/export endpoint allows a non-administrative JWT or CLI token to read or replace all credentials and settings because it lacks operation-level authorization.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-qvfm-67h2-2qfx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/commit/0c7c9de00ae3ab81d6580e3cc368483c4c03f6fd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/releases/tag/v0.4.80",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 395,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:28:27.063Z",
      "date_published": "2026-07-10T15:23:53.709Z",
      "date_updated": "2026-07-10T16:45:23.879Z",
      "publisher": "GitHub_M",
      "title": "9router: Login brute-force protection bypass via spoofed X-Forwarded-For header",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24419
      },
      "nvd": {
        "published": "2026-07-10T16:16:33.493",
        "lastModified": "2026-07-10T17:25:46.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55501",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The rate limiter trusts a caller-controlled X-Forwarded-For value as the client identity, allowing repeated attempts to rotate the key used for throttling.",
        "basis": [
          "CNA",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-7cfm-pqrj-xgq7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/commit/7648c3412b403a29f04967c4b4e9725e228791d4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/releases/tag/v0.4.80",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 593,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55502",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:28:27.063Z",
      "date_published": "2026-07-31T03:35:59.389Z",
      "date_updated": "2026-07-31T11:09:00.719Z",
      "publisher": "GitHub_M",
      "title": "Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials",
      "affected": {
        "vendors": [
          "cloudreve"
        ],
        "products": [
          {
            "vendor": "cloudreve",
            "product": "cloudreve"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26436
      },
      "nvd": {
        "published": "2026-07-31T04:17:23.563",
        "lastModified": "2026-07-31T11:17:10.207",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55502",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OneDrive OAuth sign-in route persists storage-policy credentials under Admin.Read and omits the Admin.Write guard used by sibling mutation routes.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-hq88-5x99-x3gf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 647,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55510",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:44:22.283Z",
      "date_published": "2026-07-01T18:53:58.567Z",
      "date_updated": "2026-07-01T19:21:37.355Z",
      "publisher": "GitHub_M",
      "title": "ImageMagick: Use-After-Free in crafted 8BIM when identifying an image",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00103,
        "percentile": 0.01155
      },
      "nvd": {
        "published": "2026-07-01T19:16:54.780",
        "lastModified": "2026-07-02T19:31:07.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55510",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-ff5c-8x9r-8qcw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55514",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:44:22.284Z",
      "date_published": "2026-07-06T20:07:40.405Z",
      "date_updated": "2026-07-06T20:46:52.405Z",
      "publisher": "GitHub_M",
      "title": "vLLM denial of service via prompt embeds on M-RoPE models",
      "affected": {
        "vendors": [
          "vllm-project"
        ],
        "products": [
          {
            "vendor": "vllm-project",
            "product": "vllm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29709
      },
      "nvd": {
        "published": "2026-07-06T21:16:57.207",
        "lastModified": "2026-07-07T19:02:37.753",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55514",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A pure prompt-embeds request on an M-RoPE model reaches an unchecked assertion that terminates the shared engine process.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vllm-project/vllm/security/advisories/GHSA-33cg-gxv8-3p8g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vllm-project/vllm/pull/45252",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vllm-project/vllm/commit/470229c37efaf69c86e8bc97482b0b1ff7551c65",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vllm-project/vllm/releases/tag/v0.24.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55515",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:44:22.284Z",
      "date_published": "2026-07-10T19:36:45.157Z",
      "date_updated": "2026-07-13T15:02:04.161Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.1883
      },
      "nvd": {
        "published": "2026-07-10T20:16:47.713",
        "lastModified": "2026-07-14T11:49:24.023",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55515",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The report deletion endpoint checks only reports.view and deletes a pending acceptance by global ID without constraining it to the caller's company or asset access.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-35cr-9hqq-p2mg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/802067f3987a4b65bfc2efe60e22e07c24e01e6a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:44:22.284Z",
      "date_published": "2026-07-10T18:31:57.507Z",
      "date_updated": "2026-07-14T13:42:33.155Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Cross-company asset maintenance re-parenting via API update",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.1229
      },
      "nvd": {
        "published": "2026-07-10T19:17:25.710",
        "lastModified": "2026-07-14T14:16:35.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55516",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The maintenance update authorizes the old asset but accepts a replacement asset_id without checking access to the newly selected asset's company.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-575r-357h-fhch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/905d498ecdb0ee5591231c97bf48435e92044368",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55518",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T22:44:22.284Z",
      "date_published": "2026-07-17T20:51:19.056Z",
      "date_updated": "2026-07-20T15:20:34.406Z",
      "publisher": "GitHub_M",
      "title": "Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation",
      "affected": {
        "vendors": [
          "avo-hq"
        ],
        "products": [
          {
            "vendor": "avo-hq",
            "product": "avo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25579
      },
      "nvd": {
        "published": "2026-07-17T21:17:09.173",
        "lastModified": "2026-07-23T17:58:34.990",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55518",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The association write endpoint omits the attach permission check enforced by the UI and GET path before changing the relationship.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/avo-hq/avo/security/advisories/GHSA-8fq9-273g-6mrg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/avo-hq/avo/pull/4568",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/avo-hq/avo/commit/995928e586fd1788dd496bd51c4dbe4a79cb2b9c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/avo-hq/avo/releases/tag/v3.32.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 785,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55542",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:01:04.074Z",
      "date_published": "2026-07-08T20:32:14.897Z",
      "date_updated": "2026-07-09T13:28:25.170Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 3,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06812
      },
      "nvd": {
        "published": "2026-07-08T21:16:50.117",
        "lastModified": "2026-07-10T19:48:18.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55542",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The S3 signature branch returns a signed object URL before running the authorization check used by local storage.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-6mmj-jhqj-6c6q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/ded6515cbc27a28f07395da318483c2e96263259",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55544",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:01:04.074Z",
      "date_published": "2026-07-20T20:57:19.722Z",
      "date_updated": "2026-07-22T13:50:12.699Z",
      "publisher": "GitHub_M",
      "title": "NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign Disclosure and Tampering",
      "affected": {
        "vendors": [
          "pdovhomilja"
        ],
        "products": [
          {
            "vendor": "pdovhomilja",
            "product": "nextcrm-app"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07834
      },
      "nvd": {
        "published": "2026-07-20T22:17:16.407",
        "lastModified": "2026-07-22T14:17:21.293",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55544",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Campaign handlers query and mutate records only by object ID and ignore the authenticated user's ownership scope.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pdovhomilja/nextcrm-app/security/advisories/GHSA-c9vg-c532-ppqx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 739,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55548",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:01:04.075Z",
      "date_published": "2026-07-16T16:09:35.505Z",
      "date_updated": "2026-07-16T18:14:19.081Z",
      "publisher": "GitHub_M",
      "title": "Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets",
      "affected": {
        "vendors": [
          "yamcs"
        ],
        "products": [
          {
            "vendor": "yamcs",
            "product": "yamcs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16091
      },
      "nvd": {
        "published": "2026-07-16T17:16:57.987",
        "lastModified": "2026-07-20T01:29:18.843",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55548",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "yamcs fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yamcs/yamcs/security/advisories/GHSA-8xjq-pr36-ccgf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/commit/b566beceba98cc35514b0e1519be126b8c5a0438",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/commit/c743cc3acf5b5c53ff5181b94eacc21340f70dd9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 834,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55550",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:01:04.075Z",
      "date_published": "2026-07-20T21:02:16.513Z",
      "date_updated": "2026-07-20T21:41:29.884Z",
      "publisher": "GitHub_M",
      "title": "NextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users to Modify the CRM Product Catalog",
      "affected": {
        "vendors": [
          "pdovhomilja"
        ],
        "products": [
          {
            "vendor": "pdovhomilja",
            "product": "nextcrm-app"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09393
      },
      "nvd": {
        "published": "2026-07-20T22:17:16.543",
        "lastModified": "2026-07-21T18:57:45.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55550",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MCP product tools accept low-privilege bearer tokens for catalog writes without enforcing the manager or administrator role required by normal actions.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269",
          "CWE-284",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pdovhomilja/nextcrm-app/security/advisories/GHSA-wv63-cq38-qg58",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 614,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55554",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:11:20.213Z",
      "date_published": "2026-07-28T19:28:43.838Z",
      "date_updated": "2026-07-29T15:24:54.517Z",
      "publisher": "GitHub_M",
      "title": "Dompdf: Chroot Validation Bypass",
      "affected": {
        "vendors": [
          "dompdf"
        ],
        "products": [
          {
            "vendor": "dompdf",
            "product": "dompdf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20014
      },
      "nvd": {
        "published": "2026-07-28T20:17:26.723",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55554",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Dompdf uses a separator-free string-prefix test for its chroot, so sibling directories whose names share the prefix pass containment validation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dompdf/dompdf/security/advisories/GHSA-wvh6-f5jh-8gw4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/releases/tag/v3.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 660,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55555",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:11:20.213Z",
      "date_published": "2026-07-28T19:23:45.525Z",
      "date_updated": "2026-07-28T19:43:31.156Z",
      "publisher": "GitHub_M",
      "title": "Dompdf: File existence oracle via font-face stylesheet declaration",
      "affected": {
        "vendors": [
          "dompdf"
        ],
        "products": [
          {
            "vendor": "dompdf",
            "product": "dompdf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-203",
          "name": "Observable Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00504,
        "percentile": 0.40306
      },
      "nvd": {
        "published": "2026-07-28T20:17:26.867",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55555",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dompdf's repeated file URI processing exhausts memory only for existing paths, exposing file existence through the observable response difference.",
        "basis": [
          "CNA",
          "CWE-203"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dompdf/dompdf/security/advisories/GHSA-7x2p-4jvh-6384",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/commit/75c39a083bf7298044fb27399b4cc183054438b4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/releases/tag/v3.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1036,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55574",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:11:20.214Z",
      "date_published": "2026-07-06T20:05:31.003Z",
      "date_updated": "2026-07-06T20:52:57.336Z",
      "publisher": "GitHub_M",
      "title": "vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends",
      "affected": {
        "vendors": [
          "vllm-project"
        ],
        "products": [
          {
            "vendor": "vllm-project",
            "product": "vllm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24918
      },
      "nvd": {
        "published": "2026-07-06T21:16:57.347",
        "lastModified": "2026-07-07T19:03:35.010",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55574",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "vLLM compiles attacker-supplied regular expressions without a timeout or effective complexity bound.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vllm-project/vllm/security/advisories/GHSA-rwxx-mrjm-wc2m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vllm-project/vllm/pull/45118",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vllm-project/vllm/commit/2b3006076c5e9bc4cda9e03e3641388de3c5c286",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 748,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55575",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:11:20.214Z",
      "date_published": "2026-07-08T19:32:01.216Z",
      "date_updated": "2026-07-09T14:00:04.585Z",
      "publisher": "GitHub_M",
      "title": "LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce",
      "affected": {
        "vendors": [
          "harttle"
        ],
        "products": [
          {
            "vendor": "harttle",
            "product": "liquidjs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31111
      },
      "nvd": {
        "published": "2026-07-08T20:16:53.137",
        "lastModified": "2026-07-10T19:06:45.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55575",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LiquidJS clones an entire input array before applying a configured memory limit, leaving the allocation outside the effective resource budget.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/harttle/liquidjs/security/advisories/GHSA-g357-x5c3-c72p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/harttle/liquidjs/pull/907",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/harttle/liquidjs/commit/8a0c74a7fcb1671aa1dcb71ec82ba0602dc90d04",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/harttle/liquidjs/releases/tag/v10.27.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 458,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55576",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:11:20.214Z",
      "date_published": "2026-07-15T21:02:14.524Z",
      "date_updated": "2026-07-18T02:28:48.423Z",
      "publisher": "GitHub_M",
      "title": "MaaAssistantArknights: PR-title expression injection in release-preparation.yml",
      "affected": {
        "vendors": [
          "MaaAssistantArknights"
        ],
        "products": [
          {
            "vendor": "MaaAssistantArknights",
            "product": "MaaAssistantArknights"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00297,
        "percentile": 0.22025
      },
      "nvd": {
        "published": "2026-07-15T22:17:26.157",
        "lastModified": "2026-07-18T03:16:37.230",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55576",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The release workflow interpolates a fork pull-request title into a shell run block, allowing shell metacharacters in a qualifying title to execute on the runner.",
        "basis": [
          "CNA",
          "CWE-78",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MaaAssistantArknights/MaaAssistantArknights/security/advisories/GHSA-pqx2-5g66-f5w8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/MaaAssistantArknights/MaaAssistantArknights/commit/cafc3946059e6337d2089d4fec8b6885ba17c332",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55577",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:11:20.215Z",
      "date_published": "2026-07-01T18:56:28.768Z",
      "date_updated": "2026-07-01T19:24:45.452Z",
      "publisher": "GitHub_M",
      "title": "ImageMagick: Heap Buffer Overflow in ImageMagick MVG decoder",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-755",
          "name": "Improper Handling of Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13403
      },
      "nvd": {
        "published": "2026-07-01T19:16:54.907",
        "lastModified": "2026-07-02T19:30:48.277",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55577",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ImageMagick MVG decoder writes past a heap buffer while processing a crafted image.",
        "basis": [
          "CNA",
          "CWE-754",
          "CWE-755",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wx47-rm3x-jx6p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 324,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55578",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:18:03.169Z",
      "date_published": "2026-07-27T17:54:29.407Z",
      "date_updated": "2026-07-28T14:03:57.628Z",
      "publisher": "GitHub_M",
      "title": "Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection",
      "affected": {
        "vendors": [
          "pheditor"
        ],
        "products": [
          {
            "vendor": "pheditor",
            "product": "pheditor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28875
      },
      "nvd": {
        "published": "2026-07-27T18:16:56.730",
        "lastModified": "2026-07-28T15:17:19.233",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55578",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pheditor's shell command blocklist leaves pipe, backtick, and newline syntax available to escape the configured command allowlist.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pheditor/pheditor/security/advisories/GHSA-wg4w-wr5q-6vjc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/advisories/GHSA-9643-6xjp-vx57",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pheditor/pheditor/releases/tag/2.0.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 661,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55579",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:18:03.169Z",
      "date_published": "2026-07-27T17:54:45.156Z",
      "date_updated": "2026-07-27T18:59:35.588Z",
      "publisher": "GitHub_M",
      "title": "Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise",
      "affected": {
        "vendors": [
          "pheditor"
        ],
        "products": [
          {
            "vendor": "pheditor",
            "product": "pheditor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00603,
        "percentile": 0.45461
      },
      "nvd": {
        "published": "2026-07-27T18:16:56.880",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55579",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pheditor ships a fixed admin password hash and does not require a first-login change, making every unchanged deployment share the same credential.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pheditor/pheditor/security/advisories/GHSA-p4h7-p9rj-2pq2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pheditor/pheditor/releases/tag/2.0.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 511,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55590",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:18:03.170Z",
      "date_published": "2026-07-09T18:55:30.241Z",
      "date_updated": "2026-07-09T19:18:12.885Z",
      "publisher": "GitHub_M",
      "title": "CakePHP: Open redirect weakness via backslash bypass",
      "affected": {
        "vendors": [
          "cakephp"
        ],
        "products": [
          {
            "vendor": "cakephp",
            "product": "authentication"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19816
      },
      "nvd": {
        "published": "2026-07-09T19:17:06.670",
        "lastModified": "2026-07-13T17:09:24.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55590",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application accepts an attacker-controlled redirect destination without binding navigation to an approved host.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cakephp/authentication/security/advisories/GHSA-hhpq-7wg4-36jm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cakephp/authentication/pull/795",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cakephp/authentication/pull/796",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cakephp/authentication/pull/799",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cakephp/authentication/commit/1c1e29c7e8129cfbcae74558316ecd3ea50a8273",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cakephp/authentication/commit/df28ea4e712f1e5bd0e42be4a3c5c750ca50764d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cakephp/authentication/commit/ee24bd48b9c3ef693dc9965de8f0cc8020a7052c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cakephp/authentication/releases/tag/2.11.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cakephp/authentication/releases/tag/3.3.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cakephp/authentication/releases/tag/4.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55592",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:18:03.170Z",
      "date_published": "2026-07-07T20:48:28.648Z",
      "date_updated": "2026-07-08T14:30:28.126Z",
      "publisher": "GitHub_M",
      "title": "Dashy: XSS in workspace url parameter",
      "affected": {
        "vendors": [
          "lissy93"
        ],
        "products": [
          {
            "vendor": "lissy93",
            "product": "dashy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.1701
      },
      "nvd": {
        "published": "2026-07-07T21:17:27.433",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55592",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches dashy page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lissy93/dashy/security/advisories/GHSA-58mp-4qr3-vmrc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lissy93/dashy/commit/4bc620e21cc8e3466f32b8bc40614b0d0eb5648b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lissy93/dashy/releases/tag/4.3.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55594",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:18:03.170Z",
      "date_published": "2026-07-01T18:58:46.046Z",
      "date_updated": "2026-07-02T14:38:08.174Z",
      "publisher": "GitHub_M",
      "title": "ImageMagick: Stack Overflow in MVG decoder due to missing depth check.",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15383
      },
      "nvd": {
        "published": "2026-07-01T19:16:55.037",
        "lastModified": "2026-07-02T19:30:34.957",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55594",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MVG decoder recurses through nested content without a depth check until it exhausts the process stack.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mx48-2qq3-23hf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55595",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:18:03.170Z",
      "date_published": "2026-07-01T19:00:31.074Z",
      "date_updated": "2026-07-02T12:46:43.676Z",
      "publisher": "GitHub_M",
      "title": "ImageMagick: Infinite Loop in connected-components when providing invalid arguments",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0009,
        "percentile": 0.00563
      },
      "nvd": {
        "published": "2026-07-01T19:16:55.160",
        "lastModified": "2026-07-02T19:30:27.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55595",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can enter a loop whose exit condition is never reached.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qhmf-7fc4-8q3h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55596",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:18:03.170Z",
      "date_published": "2026-07-08T20:27:58.987Z",
      "date_updated": "2026-07-09T13:41:00.054Z",
      "publisher": "GitHub_M",
      "title": "Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript",
      "affected": {
        "vendors": [
          "udecode"
        ],
        "products": [
          {
            "vendor": "udecode",
            "product": "plate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15364
      },
      "nvd": {
        "published": "2026-07-08T21:16:50.247",
        "lastModified": "2026-07-10T19:06:45.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55596",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Serialized provider metadata bypasses URL protocol validation and places a javascript URI directly into an iframe source.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/udecode/plate/security/advisories/GHSA-qj6x-xx2h-8hvv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/udecode/plate/pull/5014",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/udecode/plate/commit/6214914ca811adf22d0ad503154494216eed68ba",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/udecode/plate/releases/tag/v53.1.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55597",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:18:03.170Z",
      "date_published": "2026-07-01T19:03:29.911Z",
      "date_updated": "2026-07-01T19:21:38.493Z",
      "publisher": "GitHub_M",
      "title": "ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-682",
          "name": "Incorrect Calculation",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00103,
        "percentile": 0.0116
      },
      "nvd": {
        "published": "2026-07-01T19:16:55.363",
        "lastModified": "2026-07-02T19:30:14.533",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55597",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick lets attacker-controlled input reach an out-of-bounds write.",
        "basis": [
          "CNA",
          "CWE-682",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-c4v7-w88g-m6c4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55604",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:31:22.445Z",
      "date_published": "2026-07-09T21:13:15.713Z",
      "date_updated": "2026-07-10T14:42:09.579Z",
      "publisher": "GitHub_M",
      "title": "@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key",
      "affected": {
        "vendors": [
          "arikusi"
        ],
        "products": [
          {
            "vendor": "arikusi",
            "product": "deepseek-mcp-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13192
      },
      "nvd": {
        "published": "2026-07-09T22:17:06.247",
        "lastModified": "2026-07-10T19:20:32.893",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55604",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The process-global session store accepts caller-supplied session IDs without binding them to an authenticated principal or transport session.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/arikusi/deepseek-mcp-server/security/advisories/GHSA-fh3r-g96v-f578",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/arikusi/deepseek-mcp-server/releases/tag/v1.7.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 484,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55605",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:31:22.445Z",
      "date_published": "2026-07-09T21:10:53.882Z",
      "date_updated": "2026-07-10T13:35:30.010Z",
      "publisher": "GitHub_M",
      "title": "@arikusi/deepseek-mcp-server Missing Authentication on Self-Hosted HTTP MCP Endpoint",
      "affected": {
        "vendors": [
          "arikusi"
        ],
        "products": [
          {
            "vendor": "arikusi",
            "product": "deepseek-mcp-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00429,
        "percentile": 0.35331
      },
      "nvd": {
        "published": "2026-07-09T22:17:06.400",
        "lastModified": "2026-07-10T19:20:32.893",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55605",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The self-hosted HTTP MCP route has no authentication provider or guarding middleware, allowing any reachable client to initialize a session and invoke tools.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/arikusi/deepseek-mcp-server/security/advisories/GHSA-72f3-6w86-7rv3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/arikusi/deepseek-mcp-server/blob/main/CHANGELOG.md#180---2026-06-14",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/arikusi/deepseek-mcp-server/releases/tag/v1.8.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1138,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55608",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:31:22.445Z",
      "date_published": "2026-07-15T20:35:29.539Z",
      "date_updated": "2026-07-17T12:32:25.385Z",
      "publisher": "GitHub_M",
      "title": "n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode",
      "affected": {
        "vendors": [
          "czlonkowski"
        ],
        "products": [
          {
            "vendor": "czlonkowski",
            "product": "n8n-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06
      },
      "nvd": {
        "published": "2026-07-15T21:16:55.307",
        "lastModified": "2026-07-17T17:11:08.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55608",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Multi-tenant mode can resolve workflow-version backups in the default scope instead of the authenticated tenant scope.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/czlonkowski/n8n-mcp/security/advisories/GHSA-2cf7-hpwf-47h9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/czlonkowski/n8n-mcp/commit/1f42899749ed0c584fb6b4fd63d75233c3edee59",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/czlonkowski/n8n-mcp/releases/tag/v2.57.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 454,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55615",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:31:22.445Z",
      "date_published": "2026-07-09T23:40:44.576Z",
      "date_updated": "2026-07-10T13:43:08.734Z",
      "publisher": "GitHub_M",
      "title": "Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879",
      "affected": {
        "vendors": [
          "langroid"
        ],
        "products": [
          {
            "vendor": "langroid",
            "product": "langroid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00383,
        "percentile": 0.3105
      },
      "nvd": {
        "published": "2026-07-10T00:16:33.867",
        "lastModified": "2026-07-10T15:49:19.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55615",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Neo4jChatAgent sends prompt-influenced LLM output directly to the Cypher driver without validation, a statement allowlist, or an opt-out gate.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/langroid/langroid/security/advisories/GHSA-2pq5-3q89-j7cc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/langroid/langroid/commit/5a3097d9dd6378b08ced5480b0caf76cc58d00fa",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 800,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55626",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:31:22.446Z",
      "date_published": "2026-07-20T17:11:44.442Z",
      "date_updated": "2026-07-24T20:17:30.075Z",
      "publisher": "GitHub_M",
      "title": "xrdp: No authentication required with Xvnc backend on RHEL 9",
      "affected": {
        "vendors": [
          "neutrinolabs"
        ],
        "products": [
          {
            "vendor": "neutrinolabs",
            "product": "xrdp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02647
      },
      "nvd": {
        "published": "2026-07-20T18:16:54.150",
        "lastModified": "2026-07-28T15:05:57.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55626",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The xrdp path exposes a privileged operation without first authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-m3xx-cpc4-982r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55628",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.055Z",
      "date_published": "2026-07-01T18:16:23.076Z",
      "date_updated": "2026-07-29T20:30:01.982Z",
      "publisher": "GitHub_M",
      "title": "ImageMagick: Policy Bypass in concatenate operation due to missing checks",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00098,
        "percentile": 0.00899
      },
      "nvd": {
        "published": "2026-07-01T19:16:55.707",
        "lastModified": "2026-07-29T21:17:47.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55628",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A concatenate operation can read or write paths that the active filesystem policy is supposed to exclude.",
        "basis": [
          "CNA",
          "CWE-73",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-82mp-vp5c-9pf7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 323,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55629",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.056Z",
      "date_published": "2026-07-16T19:12:56.106Z",
      "date_updated": "2026-07-17T18:12:13.546Z",
      "publisher": "GitHub_M",
      "title": "Whistle: Path traversal",
      "affected": {
        "vendors": [
          "avwo"
        ],
        "products": [
          {
            "vendor": "avwo",
            "product": "whistle"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00456,
        "percentile": 0.37342
      },
      "nvd": {
        "published": "2026-07-16T20:16:45.577",
        "lastModified": "2026-07-17T19:17:17.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55629",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GET /cgi-bin/temp/get passes a filename that misses the temporary-file pattern directly to getFile, allowing reads of arbitrary paths.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/avwo/whistle/security/advisories/GHSA-3vfr-4gwf-qxfp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/avwo/whistle/commit/777bcf69bae2972aa7138a158c91619185653cf5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "http://github.com/avwo/whistle/releases/tag/v2.10.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55631",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.056Z",
      "date_published": "2026-07-07T20:24:56.074Z",
      "date_updated": "2026-07-08T12:55:40.744Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Path Traversal Leading to Arbitrary File Deletion via Font Management",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23673
      },
      "nvd": {
        "published": "2026-07-07T21:17:27.593",
        "lastModified": "2026-07-08T15:07:37.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55631",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DataEase concatenates fileTransName into a deletion path without confining the selected file to the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-r99p-w8fc-93g6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 504,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55633",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.056Z",
      "date_published": "2026-07-07T20:27:28.491Z",
      "date_updated": "2026-07-08T14:46:11.454Z",
      "publisher": "GitHub_M",
      "title": "DataEase H2 RCE via Zip Protocol & File Dropper Fix bypass",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00501,
        "percentile": 0.4016
      },
      "nvd": {
        "published": "2026-07-07T21:17:27.750",
        "lastModified": "2026-07-08T15:16:29.953",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55633",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DataEase FontManage.saveFile accepts a zip archive disguised as a .ttf file, allowing the archive to reach the H2 zip protocol path and execute code.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-8x36-774q-pwqg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/265b31179f1427c059f739841f2e39aaa6d1b937",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/releases/tag/v2.10.24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55635",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.056Z",
      "date_published": "2026-07-07T20:35:43.173Z",
      "date_updated": "2026-07-09T14:42:27.348Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Authenticated SQL Injection in Chart Quota Filters",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18308
      },
      "nvd": {
        "published": "2026-07-07T21:17:27.903",
        "lastModified": "2026-07-09T16:16:45.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55635",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Quota2SQLObj.getYWheres inserts chart quota and Y-axis filter values into SQL without literal escaping or parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-p758-rx6v-hc8g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/4463e21cb73d3d4bb8af89a0cb71ee403e4b808a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55638",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.057Z",
      "date_published": "2026-07-10T15:38:21.922Z",
      "date_updated": "2026-07-10T16:46:33.965Z",
      "publisher": "GitHub_M",
      "title": "9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29918
      },
      "nvd": {
        "published": "2026-07-10T17:16:59.183",
        "lastModified": "2026-07-10T17:35:11.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55638",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The route guard omits /codex before that path is rewritten to a protected provider API, allowing unauthenticated requests to spend operator credentials.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-8gmq-j984-vp4r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/commit/b282f0554972ea35281520738759d76abcd0b0b3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/releases/tag/v0.5.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 445,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55639",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.057Z",
      "date_published": "2026-07-20T17:14:50.233Z",
      "date_updated": "2026-07-20T19:06:59.250Z",
      "publisher": "GitHub_M",
      "title": "xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_sec_process_mcs_data_CS_SECURITY)",
      "affected": {
        "vendors": [
          "neutrinolabs"
        ],
        "products": [
          {
            "vendor": "neutrinolabs",
            "product": "xrdp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16855
      },
      "nvd": {
        "published": "2026-07-20T18:16:54.287",
        "lastModified": "2026-07-29T15:21:33.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55639",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "xrdp can read beyond the valid bounds of an input or object allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-6g36-mxcf-r3gc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 794,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55641",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.057Z",
      "date_published": "2026-07-10T15:36:05.964Z",
      "date_updated": "2026-07-10T19:06:14.379Z",
      "publisher": "GitHub_M",
      "title": "9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-348",
          "name": "Use of Less Trusted Source",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1327",
          "name": "Binding to an Unrestricted IP Address",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15979
      },
      "nvd": {
        "published": "2026-07-10T17:16:59.330",
        "lastModified": "2026-07-10T20:16:47.833",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55641",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The proxy trusts the client-controlled Host header to decide that a remote request is local, bypassing the API key and exposing an attacker-selected SSRF destination.",
        "basis": [
          "CNA",
          "CWE-1327",
          "CWE-290",
          "CWE-348",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-86m2-fcxq-5q7c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/commit/b282f0554972ea35281520738759d76abcd0b0b3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/releases/tag/v0.5.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 3,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55645",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.058Z",
      "date_published": "2026-07-20T16:51:59.140Z",
      "date_updated": "2026-07-21T15:24:45.532Z",
      "publisher": "GitHub_M",
      "title": "xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_data_control)",
      "affected": {
        "vendors": [
          "neutrinolabs"
        ],
        "products": [
          {
            "vendor": "neutrinolabs",
            "product": "xrdp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20547
      },
      "nvd": {
        "published": "2026-07-20T17:18:07.430",
        "lastModified": "2026-07-22T20:05:55.147",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55645",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "xrdp reads beyond a valid memory object because an input length or pointer is not validated against the available buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-3m4m-h22g-c7xx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 795,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55646",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.058Z",
      "date_published": "2026-07-06T19:41:11.330Z",
      "date_updated": "2026-07-06T19:49:44.773Z",
      "publisher": "GitHub_M",
      "title": "vLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limit",
      "affected": {
        "vendors": [
          "vllm-project"
        ],
        "products": [
          {
            "vendor": "vllm-project",
            "product": "vllm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21128
      },
      "nvd": {
        "published": "2026-07-06T20:16:37.663",
        "lastModified": "2026-07-07T19:04:45.057",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55646",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The speech endpoint reads the complete multipart upload into memory before enforcing the configured compressed-file size limit.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vllm-project/vllm/security/advisories/GHSA-v82g-2437-67m2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vllm-project/vllm/pull/45510",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vllm-project/vllm/commit/b997071ec493765abbed990c65843ed05e4708a8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 727,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55647",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.058Z",
      "date_published": "2026-07-07T20:37:54.884Z",
      "date_updated": "2026-07-08T13:50:59.742Z",
      "publisher": "GitHub_M",
      "title": "DataEase: authenticated stored XSS in the dashboard text components",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18881
      },
      "nvd": {
        "published": "2026-07-07T21:17:28.060",
        "lastModified": "2026-07-08T15:07:37.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55647",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DataEase renders stored dashboard text through Vue v-html without server-side HTML sanitization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-4v63-24fg-pfg7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/9565812980da781eda04c0a3632bf5dc8b0469f6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/adab5f1e8954ff91830a3b2f052a42a139d978e1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55651",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.059Z",
      "date_published": "2026-07-14T15:31:51.028Z",
      "date_updated": "2026-07-14T16:00:49.009Z",
      "publisher": "GitHub_M",
      "title": "Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure",
      "affected": {
        "vendors": [
          "alextselegidis"
        ],
        "products": [
          {
            "vendor": "alextselegidis",
            "product": "easyappointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00185,
        "percentile": 0.08306
      },
      "nvd": {
        "published": "2026-07-14T16:17:00.937",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55651",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The customer-search response exposes other users' appointment hashes, which function as bearer values for later appointment changes.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-4vmm-5qvc-w5p7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55652",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-16T23:52:12.059Z",
      "date_published": "2026-07-15T21:15:11.246Z",
      "date_updated": "2026-07-17T12:36:23.896Z",
      "publisher": "GitHub_M",
      "title": "Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin)",
      "affected": {
        "vendors": [
          "wekan"
        ],
        "products": [
          {
            "vendor": "wekan",
            "product": "wekan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00355,
        "percentile": 0.28222
      },
      "nvd": {
        "published": "2026-07-15T22:17:26.293",
        "lastModified": "2026-07-17T13:18:58.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55652",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Header login trusts a client-supplied X-Forwarded-For value ahead of the socket address and therefore accepts spoofed trusted-source requests.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wekan/wekan/security/advisories/GHSA-jggc-qvfc-jr6x",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/commit/b181889a565254bc9bf79379a34fc7f617ccda28",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/releases/tag/v9.46",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55659",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:05:03.777Z",
      "date_published": "2026-07-10T20:57:39.281Z",
      "date_updated": "2026-07-13T16:01:23.973Z",
      "publisher": "GitHub_M",
      "title": "Grist: XSS through unsafe value interpolation in server-rendered pages",
      "affected": {
        "vendors": [
          "gristlabs"
        ],
        "products": [
          {
            "vendor": "gristlabs",
            "product": "grist-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19681
      },
      "nvd": {
        "published": "2026-07-10T21:16:56.577",
        "lastModified": "2026-07-13T18:12:29.917",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55659",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Grist embeds document and OAuth values into HTML and inline script without complete context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gristlabs/grist-core/security/advisories/GHSA-6qrq-h2h6-cw54",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gristlabs/grist-core/commit/4ced8064b7ea0e1763d5a6a2588b22774ce7efbc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gristlabs/grist-core/releases/tag/v1.7.15",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 799,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55660",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:05:03.777Z",
      "date_published": "2026-07-01T21:00:27.321Z",
      "date_updated": "2026-07-02T12:43:47.881Z",
      "publisher": "GitHub_M",
      "title": "TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover",
      "affected": {
        "vendors": [
          "tinacms"
        ],
        "products": [
          {
            "vendor": "tinacms",
            "product": "tinacms"
          },
          {
            "vendor": "tinacms",
            "product": "@tinacms/app"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-940",
          "name": "Improper Verification of Source of a Communication Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09537
      },
      "nvd": {
        "published": "2026-07-01T21:17:03.960",
        "lastModified": "2026-07-02T17:45:00.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55660",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The editor trusts cross-origin postMessage data without checking its origin or source, allowing a foreign window to drive authenticated editor and OAuth flows.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-346",
          "CWE-601",
          "CWE-940"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-g5qx-h5f3-mp2f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/tinacms/tinacms/pull/7056",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 927,
        "referenceCount": 2,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55661",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:05:03.777Z",
      "date_published": "2026-07-01T20:44:50.116Z",
      "date_updated": "2026-07-06T14:39:33.214Z",
      "publisher": "GitHub_M",
      "title": "TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes",
      "affected": {
        "vendors": [
          "tinacms"
        ],
        "products": [
          {
            "vendor": "tinacms",
            "product": "tinacms"
          },
          {
            "vendor": "tinacms",
            "product": "@tinacms/mdx"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-87",
          "name": "Improper Neutralization of Alternate XSS Syntax",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15072
      },
      "nvd": {
        "published": "2026-07-01T21:17:04.090",
        "lastModified": "2026-07-06T16:16:34.977",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55661",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "tinacms places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79",
          "CWE-87"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-2vcc-5v34-9jc8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/tinacms/tinacms/pull/7056",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 667,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55664",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:05:03.777Z",
      "date_published": "2026-07-10T20:59:12.603Z",
      "date_updated": "2026-07-13T18:55:09.131Z",
      "publisher": "GitHub_M",
      "title": "Grist: Insufficient access control in the /forms endpoint exposes table metadata",
      "affected": {
        "vendors": [
          "gristlabs"
        ],
        "products": [
          {
            "vendor": "gristlabs",
            "product": "grist-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15503
      },
      "nvd": {
        "published": "2026-07-10T21:16:56.723",
        "lastModified": "2026-07-13T19:17:14.547",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55664",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The forms endpoint reads arbitrary widget metadata without applying document access rules or confirming that the requested section is a form.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gristlabs/grist-core/security/advisories/GHSA-w2hc-w6cg-xvh9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gristlabs/grist-core/commit/14694156fe99c438c5f7a452ad367e933bb194db",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gristlabs/grist-core/releases/tag/v1.7.15",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55665",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:05:03.777Z",
      "date_published": "2026-07-10T20:58:24.755Z",
      "date_updated": "2026-07-14T14:11:49.064Z",
      "publisher": "GitHub_M",
      "title": "DOM-based XSS in Grist via unsanitized links, enabling privilege escalation",
      "affected": {
        "vendors": [
          "gristlabs"
        ],
        "products": [
          {
            "vendor": "gristlabs",
            "product": "grist-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24656
      },
      "nvd": {
        "published": "2026-07-10T21:16:56.847",
        "lastModified": "2026-07-14T15:17:04.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55665",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Grist places attacker-controlled javascript URLs into clickable href values without scheme validation, executing them in the victim's authenticated origin.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gristlabs/grist-core/security/advisories/GHSA-7f6v-vghq-34xq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gristlabs/grist-core/commit/5d0a90a162b5125fce7e8a86fb137eee5199dbde",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gristlabs/grist-core/releases/tag/v1.7.15",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 936,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55668",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:05:03.777Z",
      "date_published": "2026-07-08T14:55:25.433Z",
      "date_updated": "2026-07-08T16:11:52.007Z",
      "publisher": "GitHub_M",
      "title": "File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope",
      "affected": {
        "vendors": [
          "filebrowser"
        ],
        "products": [
          {
            "vendor": "filebrowser",
            "product": "filebrowser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18857
      },
      "nvd": {
        "published": "2026-07-08T15:16:30.057",
        "lastModified": "2026-07-08T17:17:24.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55668",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ScopedFs validates a dangling symlink's existing ancestor and then follows the symlink during creation outside the user's scope.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-8wc8-hf36-mjh9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/filebrowser/filebrowser/commit/64511ce45e3be379e965f7f4fb0929a068d5bb81",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/filebrowser/filebrowser/releases/tag/v2.63.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 372,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55669",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:05:03.777Z",
      "date_published": "2026-07-10T16:58:46.140Z",
      "date_updated": "2026-07-10T18:16:52.558Z",
      "publisher": "GitHub_M",
      "title": "ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider",
      "affected": {
        "vendors": [
          "zitadel"
        ],
        "products": [
          {
            "vendor": "zitadel",
            "product": "zitadel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01605
      },
      "nvd": {
        "published": "2026-07-10T17:16:59.460",
        "lastModified": "2026-07-10T19:17:25.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55669",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ZITADEL accepts a signed external identity token without verifying that its audience names ZITADEL.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-g5h5-m4hm-xjrr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v3.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v4.15.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55670",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:05:03.777Z",
      "date_published": "2026-07-10T17:15:44.783Z",
      "date_updated": "2026-07-10T20:58:36.084Z",
      "publisher": "GitHub_M",
      "title": "ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers",
      "affected": {
        "vendors": [
          "zitadel"
        ],
        "products": [
          {
            "vendor": "zitadel",
            "product": "zitadel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20841
      },
      "nvd": {
        "published": "2026-07-10T18:16:23.360",
        "lastModified": "2026-07-10T21:16:56.973",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55670",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ZITADEL retains a deleted user's original resource owner and applies that stale owner when the identifier is later recreated.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-6x8v-2fq5-2229",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/pull/12261",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/a939b847d90c3370bd162064e57764b89c01be46",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v4.15.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 394,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55671",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:05:03.778Z",
      "date_published": "2026-07-10T17:17:50.095Z",
      "date_updated": "2026-07-14T02:04:22.076Z",
      "publisher": "GitHub_M",
      "title": "ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components",
      "affected": {
        "vendors": [
          "zitadel"
        ],
        "products": [
          {
            "vendor": "zitadel",
            "product": "zitadel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16598
      },
      "nvd": {
        "published": "2026-07-10T18:16:23.503",
        "lastModified": "2026-07-14T02:16:56.173",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55671",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ZITADEL fetches user-defined notification, logout, and metadata URLs without consistently rechecking protected destinations after DNS resolution, redirects, and protocol changes.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-29jh-8cfq-rr8x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/b6f78086913b8d916bce9ab2e049ab0d84f947fd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v4.15.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 453,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55672",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:05:03.778Z",
      "date_published": "2026-07-10T17:19:05.266Z",
      "date_updated": "2026-07-10T18:38:10.755Z",
      "publisher": "GitHub_M",
      "title": "ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)",
      "affected": {
        "vendors": [
          "zitadel"
        ],
        "products": [
          {
            "vendor": "zitadel",
            "product": "zitadel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19788
      },
      "nvd": {
        "published": "2026-07-10T18:16:23.637",
        "lastModified": "2026-07-10T19:17:25.983",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55672",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows fail to verify that the requesting client matches the client that initiated the authorization flow, allowing intercepted grants or refresh tokens to be exchanged under a different client.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-xqxv-4jc2-x56x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/562403079a98cf2059cdac11865a45e2f285be71",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/5b1708e0e650398f0ebc3341714f0798b0118917",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v3.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v4.15.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:13:10.650Z",
      "date_published": "2026-07-27T21:45:57.751Z",
      "date_updated": "2026-07-28T13:40:04.996Z",
      "publisher": "GitHub_M",
      "title": "React Router: Unauthenticated Denial of Service via Inefficient Route Matching",
      "affected": {
        "vendors": [
          "remix-run"
        ],
        "products": [
          {
            "vendor": "remix-run",
            "product": "react-router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00699,
        "percentile": 0.49591
      },
      "nvd": {
        "published": "2026-07-27T22:17:40.860",
        "lastModified": "2026-08-03T13:56:02.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55685",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation lets attacker-controlled work or allocation grow without an effective per-request bound or termination condition.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://github.com/remix-run/react-router/security/advisories/GHSA-chx6-hx7r-mcp5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/pull/15186",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/commit/09e6020d1950e54f361f7ad00938ecd4dde60929",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 456,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:13:10.650Z",
      "date_published": "2026-07-10T15:59:31.646Z",
      "date_updated": "2026-07-10T20:58:56.932Z",
      "publisher": "GitHub_M",
      "title": "ESF-IDF: Stack-Based Out-of-Bounds Write in JPEG Decoder DQT Marker Parsing",
      "affected": {
        "vendors": [
          "espressif"
        ],
        "products": [
          {
            "vendor": "espressif",
            "product": "esp-idf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.31224
      },
      "nvd": {
        "published": "2026-07-10T17:16:59.590",
        "lastModified": "2026-07-10T21:16:57.073",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55687",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The JPEG DQT parser uses an unchecked four-bit table selector to index a four-entry stack array.",
        "basis": [
          "CNA",
          "CWE-121",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/espressif/esp-idf/security/advisories/GHSA-v6r2-f6p2-88cj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/espressif/esp-idf/commit/303c01305acb8ae5c4eb24a1786300681b4822a4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/espressif/esp-idf/commit/6ffafe8e93142ef8ffe51a6311d4abfc0f10fe77",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/espressif/esp-idf/commit/7ccfc00f39faf1b7e5919f45b56fe44ba699d7c1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/espressif/esp-idf/commit/82c5c2dad45313786fb7e973059bc9094d95c3b2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/espressif/esp-idf/commit/f2df45bcedef11354e83c31a9718d680a68422c4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/espressif/esp-idf/releases/tag/v6.0.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 578,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-55688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:13:10.650Z",
      "date_published": "2026-07-01T19:40:12.004Z",
      "date_updated": "2026-07-02T14:39:00.419Z",
      "publisher": "GitHub_M",
      "title": "AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore",
      "affected": {
        "vendors": [
          "AsyncHttpClient"
        ],
        "products": [
          {
            "vendor": "AsyncHttpClient",
            "product": "async-http-client"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1275",
          "name": "Sensitive Cookie with Improper SameSite Attribute",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07691
      },
      "nvd": {
        "published": "2026-07-01T20:17:11.273",
        "lastModified": "2026-07-02T17:51:04.033",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55688",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The cookie store accepts a response's Domain attribute without verifying that the responding host may set cookies for that domain.",
        "basis": [
          "CNA",
          "CWE-1275"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2196",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 828,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55689",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T00:13:10.650Z",
      "date_published": "2026-07-09T21:06:22.543Z",
      "date_updated": "2026-07-10T13:45:39.194Z",
      "publisher": "GitHub_M",
      "title": "OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset",
      "affected": {
        "vendors": [
          "openfga"
        ],
        "products": [
          {
            "vendor": "openfga",
            "product": "openfga"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22409
      },
      "nvd": {
        "published": "2026-07-09T22:17:06.553",
        "lastModified": "2026-07-14T01:28:44.147",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55689",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenFGA skips JWT audience validation when no audience is configured, accepting a token minted for another service by the same issuer.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openfga/openfga/security/advisories/GHSA-hcxc-wf8j-23hv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/openfga/openfga/commit/44596773b2e62738720ef215bf7fa04352954271",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openfga/helm-ch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openfga/helm-charts/releases/tag/openfga-0.3.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openfga/openfga/releases/tag/v1.18.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55708",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:27:22.800Z",
      "date_published": "2026-07-22T13:09:30.500Z",
      "date_updated": "2026-07-22T14:10:36.937Z",
      "publisher": "NLnet Labs",
      "title": "Privacy/configuration issue when adding local data in views through 'unbound-control'",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04671
      },
      "nvd": {
        "published": "2026-07-22T14:17:21.403",
        "lastModified": "2026-07-24T14:24:10.027",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55708",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Creating a view's local-zone tree through unbound-control omits the default protected zones and sends their queries to public DNS.",
        "basis": [
          "CNA",
          "CWE-1188"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55708.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 656,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55717",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:27:22.813Z",
      "date_published": "2026-07-22T13:09:40.927Z",
      "date_updated": "2026-07-22T14:07:31.075Z",
      "publisher": "NLnet Labs",
      "title": "'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14837
      },
      "nvd": {
        "published": "2026-07-22T14:17:21.537",
        "lastModified": "2026-07-24T14:24:16.293",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55717",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A second processing pass resets alias_rrset but leaves partial_rep, creating an inconsistent state that reaches a null dereference.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55717.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 896,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T23:45:50.277Z",
      "date_published": "2026-07-15T14:33:44.806Z",
      "date_updated": "2026-07-16T03:55:31.898Z",
      "publisher": "f5",
      "title": "NGINX Ingress Controller vulnerability",
      "affected": {
        "vendors": [
          "F5"
        ],
        "products": [
          {
            "vendor": "F5",
            "product": "NGINX Ingress Controller"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-76",
          "name": "Improper Neutralization of Equivalent Special Elements",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0.3999999999999986,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21512
      },
      "nvd": {
        "published": "2026-07-15T15:16:45.327",
        "lastModified": "2026-07-16T14:02:51.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55723",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled CRD and annotation fields are written into generated NGINX configuration without neutralizing directive syntax.",
        "basis": [
          "CNA record",
          "CWE-76"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://my.f5.com/manage/s/article/K000161800",
          "host": "my.f5.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 880,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55726",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T15:47:37.778Z",
      "date_published": "2026-07-02T23:49:11.192Z",
      "date_updated": "2026-07-06T15:44:18.370Z",
      "publisher": "icscert",
      "title": "Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere",
      "affected": {
        "vendors": [
          "Gardyn"
        ],
        "products": [
          {
            "vendor": "Gardyn",
            "product": "Gardyn Home Firmware"
          },
          {
            "vendor": "Gardyn",
            "product": "Gardyn Studio Firmware"
          },
          {
            "vendor": "Gardyn",
            "product": "Gardyn Cloud API"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00394,
        "percentile": 0.32117
      },
      "nvd": {
        "published": "2026-07-03T00:16:52.607",
        "lastModified": "2026-07-06T19:42:59.550",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55726",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Azure Blob container holding device logs is configured for unauthenticated public listing and object reads.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mygardyn.com/security/",
          "host": "mygardyn.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-03",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-03.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55727",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-21T17:17:02.798Z",
      "date_published": "2026-07-06T20:00:01.041Z",
      "date_updated": "2026-07-06T20:52:18.246Z",
      "publisher": "Genetec",
      "title": "A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.",
      "affected": {
        "vendors": [
          "Genetec Inc."
        ],
        "products": [
          {
            "vendor": "Genetec Inc.",
            "product": "Genetec Security Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@genetec.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21344
      },
      "nvd": {
        "published": "2026-07-06T21:16:57.580",
        "lastModified": "2026-07-07T14:00:51.320",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55727",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The video-stream authentication mechanism allows unauthenticated retrieval, but the missing validation step is not public.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://resources.genetec.com/security-advisories/vulnerability-affecting-live-video-retrieval-in-security-center-5-14-0-0",
          "host": "resources.genetec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55728",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T09:48:05.267Z",
      "date_published": "2026-07-24T13:58:35.474Z",
      "date_updated": "2026-07-24T14:56:40.020Z",
      "publisher": "NCSC.ch",
      "title": "Loytec LINX firmware: Stack-based Buffer Overflow in cmd_ipaddr_conflict",
      "affected": {
        "vendors": [
          "Loytec"
        ],
        "products": [
          {
            "vendor": "Loytec",
            "product": "LIP-ME20xC"
          },
          {
            "vendor": "Loytec",
            "product": "L-INX"
          },
          {
            "vendor": "Loytec",
            "product": "L-GATE"
          },
          {
            "vendor": "Loytec",
            "product": "L-ROC"
          },
          {
            "vendor": "Loytec",
            "product": "L-IOB"
          },
          {
            "vendor": "Loytec",
            "product": "L-DALI"
          },
          {
            "vendor": "Loytec",
            "product": "L-VIS"
          },
          {
            "vendor": "Loytec",
            "product": "L-PAD"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "4.0",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01677
      },
      "nvd": {
        "published": "2026-07-24T15:18:30.950",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55728",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In LIP-ME20xC, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.loytec.com/support/product-security/advisories/8523-dibt-cve-20260526-0005-stack-buffer-overflow-in-cmd_ipaddr_conflict-low",
          "host": "www.loytec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T09:48:05.268Z",
      "date_published": "2026-07-24T13:59:43.912Z",
      "date_updated": "2026-07-24T14:55:29.967Z",
      "publisher": "NCSC.ch",
      "title": "Loytec LWEB802: Exposure of Sensitive Information in browser localStorage",
      "affected": {
        "vendors": [
          "Loytec"
        ],
        "products": [
          {
            "vendor": "Loytec",
            "product": "LWEB-802"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24601
      },
      "nvd": {
        "published": "2026-07-24T15:18:31.120",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55729",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "LWEB-802 stores management credentials in browser localStorage where a crafted-link flow can expose them to an unauthenticated remote actor.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.loytec.com/support/product-security/advisories/8526-dibt-cve-20260601-0001-exposure-of-credentials-stored-in-browser-local-storage-high",
          "host": "www.loytec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T09:48:05.268Z",
      "date_published": "2026-07-24T14:00:04.544Z",
      "date_updated": "2026-07-24T14:54:57.839Z",
      "publisher": "NCSC.ch",
      "title": "Loytec LWEB802: Reflected Cross-Site Scripting in LWEB802",
      "affected": {
        "vendors": [
          "Loytec"
        ],
        "products": [
          {
            "vendor": "Loytec",
            "product": "LWEB-802"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00358,
        "percentile": 0.28474
      },
      "nvd": {
        "published": "2026-07-24T15:18:31.257",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55730",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LWEB802 reflects the project or mspParams parameter into browser-interpreted output without contextual neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.loytec.com/support/product-security/advisories/8527-dibt-cve-20260601-0002-reflected-cross-site-scripting-xss-high",
          "host": "www.loytec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T09:48:05.268Z",
      "date_published": "2026-07-24T14:00:30.497Z",
      "date_updated": "2026-07-24T14:54:34.007Z",
      "publisher": "NCSC.ch",
      "title": "Loytec LINX firmware: Unchecked input for loop condition in the SNMP agent",
      "affected": {
        "vendors": [
          "Loytec"
        ],
        "products": [
          {
            "vendor": "Loytec",
            "product": "LIP-ME20xC"
          },
          {
            "vendor": "Loytec",
            "product": "L-INX"
          },
          {
            "vendor": "Loytec",
            "product": "L-GATE"
          },
          {
            "vendor": "Loytec",
            "product": "L-ROC"
          },
          {
            "vendor": "Loytec",
            "product": "L-IOB"
          },
          {
            "vendor": "Loytec",
            "product": "L-DALI"
          },
          {
            "vendor": "Loytec",
            "product": "L-VIS"
          },
          {
            "vendor": "Loytec",
            "product": "L-PAD"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-606",
          "name": "Unchecked Input for Loop Condition",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24601
      },
      "nvd": {
        "published": "2026-07-24T15:18:31.393",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55731",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The LIP-ME20xC path lets attacker-controlled state drive a loop without a guaranteed terminating condition.",
        "basis": [
          "CNA",
          "CWE-606"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.loytec.com/support/product-security/advisories/8531-dibt-cve-20260601-0003-unchecked-input-for-loop-condition-cwe-606-in-the-snmp-agent-medium",
          "host": "www.loytec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 324,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55732",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T09:48:05.268Z",
      "date_published": "2026-07-24T14:00:48.771Z",
      "date_updated": "2026-07-24T14:53:49.184Z",
      "publisher": "NCSC.ch",
      "title": "Loytec LINX firmware: Out-of-bounds Read in BACnet packet parsing (bacdt_datetime_to_tod)",
      "affected": {
        "vendors": [
          "Loytec"
        ],
        "products": [
          {
            "vendor": "Loytec",
            "product": "LIP-ME20xC"
          },
          {
            "vendor": "Loytec",
            "product": "L-INX"
          },
          {
            "vendor": "Loytec",
            "product": "L-GATE"
          },
          {
            "vendor": "Loytec",
            "product": "L-ROC"
          },
          {
            "vendor": "Loytec",
            "product": "L-IOB"
          },
          {
            "vendor": "Loytec",
            "product": "L-DALI"
          },
          {
            "vendor": "Loytec",
            "product": "L-VIS"
          },
          {
            "vendor": "Loytec",
            "product": "L-PAD"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vulnerability@ncsc.ch",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00322,
        "percentile": 0.246
      },
      "nvd": {
        "published": "2026-07-24T15:18:31.543",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55732",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Invalid bounds or object-lifetime handling permits an out-of-range memory access.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.loytec.com/support/product-security/advisories/8532-dibt-cve-20260608-0001-bacnet-crash-due-to-invalid-timesync-message-high",
          "host": "www.loytec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-55737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T10:44:34.365Z",
      "date_published": "2026-07-27T15:13:54.699Z",
      "date_updated": "2026-07-28T09:55:26.434Z",
      "publisher": "EEF",
      "title": "Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-195",
          "name": "Signed to Unsigned Conversion Error",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02711
      },
      "nvd": {
        "published": "2026-07-27T16:17:48.847",
        "lastModified": "2026-07-30T17:01:07.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55737",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OTP path computes or trusts a write extent that can exceed the destination object's bounds.",
        "basis": [
          "CNA",
          "CWE-195",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-446w-268v-9462",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-55737.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-55737",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1169,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:34:51.880Z",
      "date_published": "2026-07-08T19:31:22.919Z",
      "date_updated": "2026-07-09T14:37:41.666Z",
      "publisher": "GitHub_M",
      "title": "handlebars.java FileTemplateLoader Path Traversal",
      "affected": {
        "vendors": [
          "jknack"
        ],
        "products": [
          {
            "vendor": "jknack",
            "product": "handlebars.java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00415,
        "percentile": 0.34134
      },
      "nvd": {
        "published": "2026-07-08T20:16:53.287",
        "lastModified": "2026-07-10T19:13:03.283",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55760",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Handlebars loader resolves caller-controlled traversal segments outside the template root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jknack/handlebars.java/security/advisories/GHSA-r4gv-qr8j-p3pg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/jknack/handlebars.java/commit/d177cdee8b750385ca7a0d0f89f2d4be73e28f4e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jknack/handlebars.java/releases/tag/v4.5.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 427,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:34:51.880Z",
      "date_published": "2026-07-08T15:03:54.158Z",
      "date_updated": "2026-07-08T15:52:30.257Z",
      "publisher": "GitHub_M",
      "title": "Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances",
      "affected": {
        "vendors": [
          "portainer"
        ],
        "products": [
          {
            "vendor": "portainer",
            "product": "portainer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21305
      },
      "nvd": {
        "published": "2026-07-08T16:16:31.020",
        "lastModified": "2026-07-10T17:48:26.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55761",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoints (/api/restore and /api/users/admin/init) remain accessible during the five-minute setup window for uninitialized instances, allowing a network attacker to restore a crafted backup or create the first administrator account and gain full administrative access.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/portainer/portainer/security/advisories/GHSA-x626-fcwx-f5pc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/portainer/portainer/issues/2770",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/portainer/portainer/commit/49f19107cf9a3540cbe406c9eb7f24390e1af02b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/portainer/portainer/commit/d2b56efcb4e43c4168bb6688eee9f6bf22867312",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/portainer/portainer/releases/tag/2.39.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/portainer/portainer/releases/tag/2.43.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 612,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:34:51.881Z",
      "date_published": "2026-07-30T20:34:32.833Z",
      "date_updated": "2026-07-31T23:10:06.368Z",
      "publisher": "GitHub_M",
      "title": "GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame length causes a remote pre-authentication denial of service",
      "affected": {
        "vendors": [
          "allinurl"
        ],
        "products": [
          {
            "vendor": "allinurl",
            "product": "goaccess"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-681",
          "name": "Incorrect Conversion between Numeric Types",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.2011
      },
      "nvd": {
        "published": "2026-07-30T21:17:57.193",
        "lastModified": "2026-07-31T23:17:25.583",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55768",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before enforcing the maximum frame size, allowing an unauthenticated remote client to bypass the guard and force an approximately 18-exabyte allocation request that terminates the process.",
        "basis": [
          "CNA",
          "CWE-681",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/allinurl/goaccess/security/advisories/GHSA-5gm5-pvh2-wg46",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/allinurl/goaccess/commit/ea74b87254d0adc675c087ff49bddd2d60dc01d5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:34:51.881Z",
      "date_published": "2026-07-13T19:28:00.835Z",
      "date_updated": "2026-07-14T14:31:41.860Z",
      "publisher": "GitHub_M",
      "title": "CedarJava has policy injection, type confusion, and incorrect equality comparison vulnerabilities",
      "affected": {
        "vendors": [
          "cedar-policy"
        ],
        "products": [
          {
            "vendor": "cedar-policy",
            "product": "cedar-java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-697",
          "name": "Incorrect Comparison",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27145
      },
      "nvd": {
        "published": "2026-07-13T20:16:48.453",
        "lastModified": "2026-07-14T15:17:04.773",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55771",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "EntityIdentifier.equals() returns true for null and false for self-comparison because its two early equality branches are inverted.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-697",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": "The description says Cedar's Rust authorization decisions are unaffected; the supplied CWE-94 and high CVSS should not be presented as demonstrated policy-engine code execution."
      },
      "references": [
        {
          "url": "https://github.com/cedar-policy/cedar-java/security/advisories/GHSA-4r9r-4425-74p7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55772",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:34:51.881Z",
      "date_published": "2026-07-13T18:44:47.577Z",
      "date_updated": "2026-07-21T19:02:48.982Z",
      "publisher": "GitHub_M",
      "title": "CedarJava has a type confusion vulnerability",
      "affected": {
        "vendors": [
          "cedar-policy"
        ],
        "products": [
          {
            "vendor": "cedar-policy",
            "product": "cedar-java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.1937
      },
      "nvd": {
        "published": "2026-07-13T19:17:15.183",
        "lastModified": "2026-07-21T19:17:11.360",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55772",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CedarJava serializes caller-controlled reserved magic keys as ordinary map data, and the Rust evaluator reinterprets that shape as an entity reference during authorization.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cedar-policy/cedar-java/security/advisories/GHSA-93g4-m6xv-cmvr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55773",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:34:51.881Z",
      "date_published": "2026-07-13T19:17:03.552Z",
      "date_updated": "2026-07-15T14:18:27.118Z",
      "publisher": "GitHub_M",
      "title": "CedarJava has a policy injection vulnerability",
      "affected": {
        "vendors": [
          "cedar-policy"
        ],
        "products": [
          {
            "vendor": "cedar-policy",
            "product": "cedar-java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21689
      },
      "nvd": {
        "published": "2026-07-13T20:16:48.580",
        "lastModified": "2026-07-15T15:16:45.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55773",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "toCedarExpr inserts quotes and backslashes from a value into Cedar source without escaping, allowing the value to terminate its expression context and inject policy logic.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cedar-policy/cedar-java/security/advisories/GHSA-qmch-v2q9-wg4p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 951,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55777",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.379Z",
      "date_published": "2026-07-30T20:37:40.575Z",
      "date_updated": "2026-07-31T11:24:05.795Z",
      "publisher": "GitHub_M",
      "title": "GoAccess: Out-of-bounds heap read in parse_ios() via crafted User-Agent leads to remote crash/DoS",
      "affected": {
        "vendors": [
          "allinurl"
        ],
        "products": [
          {
            "vendor": "allinurl",
            "product": "goaccess"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17946
      },
      "nvd": {
        "published": "2026-07-30T21:17:57.360",
        "lastModified": "2026-07-31T12:16:51.520",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55777",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "goaccess reads beyond a valid memory object because an input length or pointer is not validated against the available buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/allinurl/goaccess/security/advisories/GHSA-5phr-qpgf-hgrg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/allinurl/goaccess/commit/ba813ed97d998dbdcb8d87e178799a4bb2da9e81",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 458,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55778",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.379Z",
      "date_published": "2026-07-08T20:50:52.531Z",
      "date_updated": "2026-07-09T13:39:44.881Z",
      "publisher": "GitHub_M",
      "title": "Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist",
      "affected": {
        "vendors": [
          "parse-community"
        ],
        "products": [
          {
            "vendor": "parse-community",
            "product": "parse-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00406,
        "percentile": 0.33387
      },
      "nvd": {
        "published": "2026-07-08T21:16:50.387",
        "lastModified": "2026-07-10T19:06:45.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55778",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload blocklist can be bypassed with a compound extension and active content type, allowing an executable web object to be stored and served.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/parse-community/parse-server/security/advisories/GHSA-v8x7-r927-cc93",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/pull/10505",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/pull/10506",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/commit/97c6a78d19f976ec756c1295f08a8fccab90799a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/commit/be12a60d65b6e140481882037fb896b1f951df50",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/releases/tag/8.6.81",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/releases/tag/9.9.1-alpha.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55780",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.379Z",
      "date_published": "2026-07-10T16:49:26.257Z",
      "date_updated": "2026-07-13T18:14:24.210Z",
      "publisher": "GitHub_M",
      "title": "NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size",
      "affected": {
        "vendors": [
          "M2Team"
        ],
        "products": [
          {
            "vendor": "M2Team",
            "product": "NanaZip"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01583
      },
      "nvd": {
        "published": "2026-07-10T17:16:59.733",
        "lastModified": "2026-07-13T19:17:15.323",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55780",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NanaZip trusts a bundle entry size for allocation and lets allocation exceptions escape the COM boundary and crash the process.",
        "basis": [
          "CNA",
          "CWE-248",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/M2Team/NanaZip/security/advisories/GHSA-ppm9-5267-rq72",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/M2Team/NanaZip/commit/ad62e3b4970b9f01e924c99094d6fed7a42f849a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/M2Team/NanaZip/releases/tag/6.5.1749.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55781",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.379Z",
      "date_published": "2026-07-10T16:50:24.371Z",
      "date_updated": "2026-07-10T20:58:43.057Z",
      "publisher": "GitHub_M",
      "title": "NanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalidated fs_bsize/fs_fsize superblock fields",
      "affected": {
        "vendors": [
          "M2Team"
        ],
        "products": [
          {
            "vendor": "M2Team",
            "product": "NanaZip"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01584
      },
      "nvd": {
        "published": "2026-07-10T17:16:59.883",
        "lastModified": "2026-07-10T21:16:57.170",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55781",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The UFS parser accepts attacker-controlled block and fragment sizes without upper bounds and uses them for multi-gigabyte buffer allocations.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/M2Team/NanaZip/security/advisories/GHSA-m34h-jf84-m74h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/M2Team/NanaZip/commit/6415b6bff70bc9c486b49cbbc1982724c67f8338",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/M2Team/NanaZip/releases/tag/6.5.1749.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55782",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.379Z",
      "date_published": "2026-07-10T16:46:38.842Z",
      "date_updated": "2026-07-14T02:00:57.604Z",
      "publisher": "GitHub_M",
      "title": "NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fields",
      "affected": {
        "vendors": [
          "M2Team"
        ],
        "products": [
          {
            "vendor": "M2Team",
            "product": "NanaZip"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01669
      },
      "nvd": {
        "published": "2026-07-10T17:17:00.017",
        "lastModified": "2026-07-14T02:16:56.287",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55782",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The NanaZip parser allocates memory from an attacker-controlled size without an effective upper bound.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/M2Team/NanaZip/security/advisories/GHSA-qxhc-2v6p-wm8m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/M2Team/NanaZip/commit/1ce90f2d14a984476d0407a835273705607facf2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/M2Team/NanaZip/commit/56aee89037947410dd5e66f3a087e0f290484bae",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/M2Team/NanaZip/commit/92b12a6e1eb0cf8e88fcc277aa7508ca1ff27db6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/M2Team/NanaZip/releases/tag/6.5.1749.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 587,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55783",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.379Z",
      "date_published": "2026-07-10T16:48:29.959Z",
      "date_updated": "2026-07-10T18:38:45.230Z",
      "publisher": "GitHub_M",
      "title": "NanaZip: NULL pointer dereference in Extract() of all seven NanaZip custom archive handlers when extracting/testing the whole archive",
      "affected": {
        "vendors": [
          "M2Team"
        ],
        "products": [
          {
            "vendor": "M2Team",
            "product": "NanaZip"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01584
      },
      "nvd": {
        "published": "2026-07-10T17:17:00.147",
        "lastModified": "2026-07-10T19:17:26.120",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55783",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Seven archive handlers dereference a null Indices pointer when the engine requests extraction of every item.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/M2Team/NanaZip/security/advisories/GHSA-q67r-9cfh-xc29",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/M2Team/NanaZip/commit/5d74d90b737ac7096e5d944a5a3070c5c6a8f894",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/M2Team/NanaZip/releases/tag/6.5.1749.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 600,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55789",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.380Z",
      "date_published": "2026-07-10T19:55:37.360Z",
      "date_updated": "2026-07-13T18:16:18.449Z",
      "publisher": "GitHub_M",
      "title": "Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers",
      "affected": {
        "vendors": [
          "logto-io"
        ],
        "products": [
          {
            "vendor": "logto-io",
            "product": "logto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-91",
          "name": "XML Injection (aka Blind XPath Injection)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1395",
          "name": "Dependency on Vulnerable Third-Party Component",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22087
      },
      "nvd": {
        "published": "2026-07-10T20:16:47.933",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55789",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SAML template inserts user-controlled profile text into XML without escaping, causing the IdP to sign attacker-created assertion elements.",
        "basis": [
          "CNA",
          "CWE-91",
          "CWE-1395"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/logto-io/logto/security/advisories/GHSA-vfpw-vq44-4p63",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/logto-io/logto/pull/9107",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/logto-io/logto/commit/9097054860f0d638d90778d3dcde2ba050b844b6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/logto-io/logto/releases/tag/v1.41.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 692,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55790",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.380Z",
      "date_published": "2026-07-01T22:57:53.934Z",
      "date_updated": "2026-07-02T19:41:26.967Z",
      "publisher": "GitHub_M",
      "title": "Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget",
      "affected": {
        "vendors": [
          "craftcms"
        ],
        "products": [
          {
            "vendor": "craftcms",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.2345
      },
      "nvd": {
        "published": "2026-07-01T23:16:52.483",
        "lastModified": "2026-07-02T20:17:03.723",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55790",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "cms places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craftcms/cms/security/advisories/GHSA-24x4-j6x9-rfw5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/commit/6bbb66038a268552180ca5c8eed9f46ea25a4417",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55791",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.380Z",
      "date_published": "2026-07-01T23:13:58.321Z",
      "date_updated": "2026-07-02T15:54:26.284Z",
      "publisher": "GitHub_M",
      "title": "Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs",
      "affected": {
        "vendors": [
          "craftcms"
        ],
        "products": [
          {
            "vendor": "craftcms",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-644",
          "name": "Improper Neutralization of HTTP Headers for Scripting Syntax",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25605
      },
      "nvd": {
        "published": "2026-07-02T00:16:44.803",
        "lastModified": "2026-07-02T16:16:33.677",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55791",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A permissive trusted-host setting lets Host headers redefine baseUrl, causing actionResourceJs to fetch and return attacker-selected JavaScript.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79",
          "CWE-644",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craftcms/cms/security/advisories/GHSA-c55v-343g-5xff",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/pull/18559",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 807,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55792",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.380Z",
      "date_published": "2026-07-01T23:20:28.993Z",
      "date_updated": "2026-07-02T14:49:11.273Z",
      "publisher": "GitHub_M",
      "title": "Craft CMS: Sensitive File Disclosure / Server-Side File Read",
      "affected": {
        "vendors": [
          "craftcms"
        ],
        "products": [
          {
            "vendor": "craftcms",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18733
      },
      "nvd": {
        "published": "2026-07-02T00:16:44.940",
        "lastModified": "2026-07-02T15:17:06.300",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55792",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Craft's template sandbox allowlists dataUrl(), letting a permitted template editor make the server read and embed sensitive local files.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craftcms/cms/security/advisories/GHSA-287w-mxq6-x2cp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/pull/18559",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 873,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.380Z",
      "date_published": "2026-07-01T21:57:58.440Z",
      "date_updated": "2026-07-02T15:54:31.536Z",
      "publisher": "GitHub_M",
      "title": "Craft CMS: Stored XSS via Structure entry title in table view",
      "affected": {
        "vendors": [
          "craftcms"
        ],
        "products": [
          {
            "vendor": "craftcms",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17301
      },
      "nvd": {
        "published": "2026-07-01T22:16:50.327",
        "lastModified": "2026-07-02T16:16:33.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55793",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Craft CMS decodes an escaped title and concatenates it into new table-view HTML without attribute escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craftcms/cms/security/advisories/GHSA-xrqc-p465-2xvg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/commit/162321e899cc97517fb6f5a02b5528f549d0c6cc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 864,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55794",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.380Z",
      "date_published": "2026-07-01T23:26:22.071Z",
      "date_updated": "2026-07-02T12:41:39.752Z",
      "publisher": "GitHub_M",
      "title": "Craft CMS: Potential authenticated Remote Code Execution via referrer redirect",
      "affected": {
        "vendors": [
          "craftcms"
        ],
        "products": [
          {
            "vendor": "craftcms",
            "product": "cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21583
      },
      "nvd": {
        "published": "2026-07-02T00:16:45.067",
        "lastModified": "2026-07-02T15:12:53.577",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55794",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Craft CMS compiles an attacker-controlled Referrer-derived redirect string as an unsandboxed Twig template.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/craftcms/cms/security/advisories/GHSA-f74w-488g-8x5r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/craftcms/cms/pull/18680",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 691,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55798",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:40:28.381Z",
      "date_published": "2026-07-06T18:44:38.441Z",
      "date_updated": "2026-07-07T15:19:40.072Z",
      "publisher": "GitHub_M",
      "title": "Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07482
      },
      "nvd": {
        "published": "2026-07-06T19:17:08.830",
        "lastModified": "2026-07-07T18:58:33.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55798",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pillow embeds an attacker-controlled Windows file path directly in a cmd.exe command string.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-4x4j-2g7c-83w6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/8404ea5fe5df40fc34aa1e51403dd6fce0778b8a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/88194166691b7b603529b8b036ab3ab9cedd2de4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/b0e06caa64c1405aa3da0bb1d2bd9a77ca22de7f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 368,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55803",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:59:52.673Z",
      "date_published": "2026-07-10T21:46:38.051Z",
      "date_updated": "2026-07-13T18:24:17.938Z",
      "publisher": "drupal",
      "title": "Drupal core - Critical - PHP object injection - SA-CORE-2026-005",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Drupal core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11981
      },
      "nvd": {
        "published": "2026-07-10T22:16:43.250",
        "lastModified": "2026-07-16T15:09:30.623",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55803",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-core-2026-005",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-55804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:59:52.673Z",
      "date_published": "2026-07-10T21:46:39.054Z",
      "date_updated": "2026-07-13T18:23:35.057Z",
      "publisher": "drupal",
      "title": "Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Drupal core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11982
      },
      "nvd": {
        "published": "2026-07-10T22:16:43.353",
        "lastModified": "2026-07-16T15:11:21.957",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55804",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-core-2026-006",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-55806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:59:52.673Z",
      "date_published": "2026-07-10T21:46:39.920Z",
      "date_updated": "2026-07-13T18:22:03.916Z",
      "publisher": "drupal",
      "title": "Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Drupal core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10779
      },
      "nvd": {
        "published": "2026-07-10T22:16:43.460",
        "lastModified": "2026-07-16T15:26:23.107",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55806",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-core-2026-007",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-55807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:59:52.673Z",
      "date_published": "2026-07-10T21:46:40.786Z",
      "date_updated": "2026-07-13T18:20:30.331Z",
      "publisher": "drupal",
      "title": "Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Drupal core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03849
      },
      "nvd": {
        "published": "2026-07-10T22:16:43.563",
        "lastModified": "2026-07-16T14:58:17.093",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55807",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server fetches a caller-controlled URL without restricting the scheme, host or resolved destination to approved targets.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-core-2026-008",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 286,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-55808",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:59:52.673Z",
      "date_published": "2026-07-10T21:46:43.600Z",
      "date_updated": "2026-07-13T18:18:56.714Z",
      "publisher": "drupal",
      "title": "Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Drupal core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05759
      },
      "nvd": {
        "published": "2026-07-10T22:16:43.667",
        "lastModified": "2026-07-16T15:02:57.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55808",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-core-2026-009",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-55809",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:59:52.673Z",
      "date_published": "2026-07-10T21:44:35.985Z",
      "date_updated": "2026-07-13T18:12:03.975Z",
      "publisher": "drupal",
      "title": "Flag attendance field - Critical - PHP object injection - SA-CONTRIB-2026-049",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Flag attendance field"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.2299
      },
      "nvd": {
        "published": "2026-07-10T22:16:43.763",
        "lastModified": "2026-07-14T19:38:04.640",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55809",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The module permits dynamically selected object attributes to be modified without restricting them to the intended attribute set.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-049",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55810",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T14:59:52.673Z",
      "date_published": "2026-07-10T21:44:36.859Z",
      "date_updated": "2026-07-13T18:10:48.820Z",
      "publisher": "drupal",
      "title": "Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Plotly.js Graphing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16201
      },
      "nvd": {
        "published": "2026-07-10T22:16:43.867",
        "lastModified": "2026-07-14T19:32:40.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55810",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Plotly.js Graphing lets input modify dynamically selected PHP object attributes and inject an unintended object into application processing.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-050",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55824",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:29:38.864Z",
      "date_published": "2026-07-31T19:04:00.322Z",
      "date_updated": "2026-07-31T19:58:42.933Z",
      "publisher": "GitHub_M",
      "title": "Contao crawler leaks auth credentials to external hosts",
      "affected": {
        "vendors": [
          "contao"
        ],
        "products": [
          {
            "vendor": "contao",
            "product": "contao"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05077
      },
      "nvd": {
        "published": "2026-07-31T19:17:11.090",
        "lastModified": "2026-07-31T20:16:52.233",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55824",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The crawler's external-host client removes nonexistent auth option names and forwards the real Basic or Bearer credentials to external origins.",
        "basis": [
          "CNA record",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/contao/contao/security/advisories/GHSA-3mr9-p497-58f6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1008,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55825",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:29:38.864Z",
      "date_published": "2026-07-31T19:07:40.609Z",
      "date_updated": "2026-07-31T23:33:16.171Z",
      "publisher": "GitHub_M",
      "title": "Contao: Possible path traversal in job download URIs",
      "affected": {
        "vendors": [
          "contao"
        ],
        "products": [
          {
            "vendor": "contao",
            "product": "contao"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11113
      },
      "nvd": {
        "published": "2026-07-31T20:16:52.343",
        "lastModified": "2026-08-01T00:17:17.263",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55825",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "contao accepts an attacker-controlled path that can resolve outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/contao/contao/security/advisories/GHSA-grm4-wm43-9jh5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 873,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55827",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:29:38.864Z",
      "date_published": "2026-07-10T19:47:03.498Z",
      "date_updated": "2026-07-15T03:58:59.199Z",
      "publisher": "GitHub_M",
      "title": "FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode",
      "affected": {
        "vendors": [
          "FreeRDP"
        ],
        "products": [
          {
            "vendor": "FreeRDP",
            "product": "FreeRDP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-131",
          "name": "Incorrect Calculation of Buffer Size",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00339,
        "percentile": 0.2651
      },
      "nvd": {
        "published": "2026-07-10T20:16:48.060",
        "lastModified": "2026-07-15T05:17:15.187",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55827",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RemoteFX decoding allocates for DstWidth and DstHeight but writes using the larger desktop stride and height.",
        "basis": [
          "CNA",
          "CWE-131",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c495-h83v-3prp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/pull/12899",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/commit/e58adf922ea4c0d5495e59a1fe488d70092e0e3e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/releases/tag/3.27.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 482,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55830",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:29:38.864Z",
      "date_published": "2026-07-08T21:16:36.200Z",
      "date_updated": "2026-07-09T13:46:21.968Z",
      "publisher": "GitHub_M",
      "title": "RestrictedPython guard hooks can be shadowed via positional-only arguments",
      "affected": {
        "vendors": [
          "zopefoundation"
        ],
        "products": [
          {
            "vendor": "zopefoundation",
            "product": "RestrictedPython"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13447
      },
      "nvd": {
        "published": "2026-07-08T22:17:15.653",
        "lastModified": "2026-07-10T19:06:45.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55830",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RestrictedPython omits positional-only parameters from protected guard-name checks, allowing local arguments to shadow security hooks.",
        "basis": [
          "CNA",
          "CWE-184"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-ffg3-p8fm-mjx2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zopefoundation/RestrictedPython/commit/3737596ec9f28c34a073cc845bd2f4c0a80cb671",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55831",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:29:38.864Z",
      "date_published": "2026-07-20T23:00:31.859Z",
      "date_updated": "2026-07-23T14:33:27.925Z",
      "publisher": "GitHub_M",
      "title": "Netty SPDY SETTINGS frame count materializes unbounded settings map",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00423,
        "percentile": 0.34878
      },
      "nvd": {
        "published": "2026-07-21T00:17:35.383",
        "lastModified": "2026-07-23T15:17:16.780",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55831",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected protocol path allocates or retains attacker-driven state without an effective upper bound.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55833",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:29:38.864Z",
      "date_published": "2026-07-20T23:18:07.893Z",
      "date_updated": "2026-07-21T13:03:47.690Z",
      "publisher": "GitHub_M",
      "title": "Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00423,
        "percentile": 0.34878
      },
      "nvd": {
        "published": "2026-07-21T00:17:35.537",
        "lastModified": "2026-07-23T13:34:45.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55833",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SPDY decoder keeps inflating compressed header bytes after maxHeaderSize has marked the raw frame truncated, allowing compressed input to drive unbounded CPU and allocation work.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 551,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55843",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:29:38.865Z",
      "date_published": "2026-07-10T18:33:09.250Z",
      "date_updated": "2026-07-13T14:54:19.491Z",
      "publisher": "GitHub_M",
      "title": "Snipe-IT: Improper Privilege Management",
      "affected": {
        "vendors": [
          "grokability"
        ],
        "products": [
          {
            "vendor": "grokability",
            "product": "snipe-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22132
      },
      "nvd": {
        "published": "2026-07-10T19:17:26.250",
        "lastModified": "2026-07-13T16:16:38.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55843",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "UsersController passes an omitted permission field through normalization and preservation actions that can replace the target user's permissions with a sparse set.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grokability/snipe-it/security/advisories/GHSA-j5g3-42wp-gqm3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/commit/1cff2d67aabd00ee51d864c1d7fb717494c1d6ad",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grokability/snipe-it/releases/tag/v8.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 519,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55849",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:44:40.994Z",
      "date_published": "2026-07-08T21:10:15.798Z",
      "date_updated": "2026-07-09T19:36:40.011Z",
      "publisher": "GitHub_M",
      "title": "@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized `--workspace` Argument",
      "affected": {
        "vendors": [
          "CycloneDX"
        ],
        "products": [
          {
            "vendor": "CycloneDX",
            "product": "cyclonedx-node-npm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05734
      },
      "nvd": {
        "published": "2026-07-08T22:17:15.783",
        "lastModified": "2026-07-10T19:15:21.853",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55849",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled value crosses into an executable syntax context without neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CycloneDX/cyclonedx-node-npm/security/advisories/GHSA-v75r-vx73-82pj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/CycloneDX/cyclonedx-node-npm/pull/1476",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CycloneDX/cyclonedx-node-npm/commit/9f646253f4263d8644dadb86e5597fad996f688f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/CycloneDX/cyclonedx-node-npm/releases/tag/v5.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55851",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:44:40.995Z",
      "date_published": "2026-07-21T21:22:34.879Z",
      "date_updated": "2026-07-23T14:04:47.858Z",
      "publisher": "GitHub_M",
      "title": "Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00612,
        "percentile": 0.45877
      },
      "nvd": {
        "published": "2026-07-21T22:17:14.340",
        "lastModified": "2026-07-30T14:48:31.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55851",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "HAProxyMessageDecoder sign-extends 0xFF to -1, confusing a version byte with its need-more-data sentinel and growing the cumulation buffer without bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-q6cq-mhr2-jmr5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 730,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55852",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:44:40.995Z",
      "date_published": "2026-07-10T21:28:29.445Z",
      "date_updated": "2026-07-13T14:11:14.738Z",
      "publisher": "GitHub_M",
      "title": "Frappe: TarSlip RCE in Package Import",
      "affected": {
        "vendors": [
          "frappe"
        ],
        "products": [
          {
            "vendor": "frappe",
            "product": "frappe"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00457,
        "percentile": 0.37414
      },
      "nvd": {
        "published": "2026-07-10T22:16:43.970",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55852",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Frappe extracts tar members without rejecting paths that escape the destination directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frappe/frappe/security/advisories/GHSA-58w2-4cjg-hvp6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/38716",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/40044",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/40045",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/3c75f13fd7d4441a880dd236450277dc37fcddfd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/4772e3e7f72db43d48137af74fa77e5fce903223",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/57e527d933aeffaec0cd735838701792c848e3e7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/releases/tag/v15.112.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/releases/tag/v16.23.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55865",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:44:40.996Z",
      "date_published": "2026-07-09T20:34:38.618Z",
      "date_updated": "2026-07-14T01:16:10.895Z",
      "publisher": "GitHub_M",
      "title": "Python Liquid: Infinite loop when parsing malformed `{% case %}` tags",
      "affected": {
        "vendors": [
          "jg-rp"
        ],
        "products": [
          {
            "vendor": "jg-rp",
            "product": "liquid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.176
      },
      "nvd": {
        "published": "2026-07-09T21:16:56.277",
        "lastModified": "2026-07-14T02:16:56.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55865",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 2.2.1, given a malformed {% case %} tag without an associated {% when %} or {% else %} block and no terminating {% endcase %} tag, Python Liquid hangs in an infinite loop at parse time because liquid.TokenStream.eof did not give the EOF token matching kind and value fields, allowing malicious template authors to craft templates for a denial of service attack.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jg-rp/liquid/security/advisories/GHSA-vq2f-vcc9-j8mv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/jg-rp/liquid/commit/26db8931cf35e8433c1ca506fc32c3bb62f743d4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jg-rp/liquid/releases/tag/v2.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 475,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55873",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.758Z",
      "date_published": "2026-07-08T14:48:37.000Z",
      "date_updated": "2026-07-08T15:33:34.018Z",
      "publisher": "GitHub_M",
      "title": "SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets",
      "affected": {
        "vendors": [
          "seaweedfs"
        ],
        "products": [
          {
            "vendor": "seaweedfs",
            "product": "seaweedfs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09966
      },
      "nvd": {
        "published": "2026-07-08T15:16:30.190",
        "lastModified": "2026-07-08T16:16:31.177",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55873",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "In versions 4.08 through 4.33, requests signed with SigV4 service s3tables are routed to the S3Tables management API where authorization collapses account-less S3 identities into the shared admin account and fails open, allowing an authenticated low-privileged S3 user to enumerate administrator-owned table bucket names and ARNs.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-hgpf-8634-g44c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/seaweedfs/seaweedfs/pull/9961",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/seaweedfs/seaweedfs/commit/b13463880c1fa62e255c058a9228b63cc95b4b36",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/seaweedfs/seaweedfs/releases/tag/4.34",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55874",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.759Z",
      "date_published": "2026-07-08T14:43:40.155Z",
      "date_updated": "2026-07-08T17:01:02.948Z",
      "publisher": "GitHub_M",
      "title": "SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read",
      "affected": {
        "vendors": [
          "seaweedfs"
        ],
        "products": [
          {
            "vendor": "seaweedfs",
            "product": "seaweedfs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25223
      },
      "nvd": {
        "published": "2026-07-08T15:16:30.320",
        "lastModified": "2026-07-08T18:16:33.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55874",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SeaweedFS authorizes X-Amz-Copy-Source before rejecting dot-dot segments, so a principal confined to one bucket can copy objects from another.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-56wq-x3wv-3ff4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/seaweedfs/seaweedfs/pull/9929",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/seaweedfs/seaweedfs/commit/b44cf51fe931bd75aa4d37ae766bea90d7f85ccd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/seaweedfs/seaweedfs/releases/tag/4.34",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 339,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.759Z",
      "date_published": "2026-07-08T21:32:37.407Z",
      "date_updated": "2026-07-09T14:40:25.026Z",
      "publisher": "GitHub_M",
      "title": "Symfony UX: XSS in symfony/ux-icons via unsanitized SVG content in local files and Iconify on-demand responses",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "ux"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00191,
        "percentile": 0.09002
      },
      "nvd": {
        "published": "2026-07-08T22:17:15.920",
        "lastModified": "2026-07-10T19:13:03.283",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55877",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/ux/security/advisories/GHSA-6v8j-33hc-mv84",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/commit/3a4964ec3700f0af4e13f7bfbf8bb3174c3e79d1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v2.36.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v3.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 448,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55878",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.759Z",
      "date_published": "2026-07-08T21:30:33.816Z",
      "date_updated": "2026-07-09T14:19:07.068Z",
      "publisher": "GitHub_M",
      "title": "Symfony: Path Traversal in symfony/ux-toolkit Allows Arbitrary File Write and Read via Crafted Recipe Manifest",
      "affected": {
        "vendors": [
          "symfony"
        ],
        "products": [
          {
            "vendor": "symfony",
            "product": "ux"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04372
      },
      "nvd": {
        "published": "2026-07-08T22:17:16.050",
        "lastModified": "2026-07-10T19:10:59.333",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55878",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled path or reference can select a file outside the intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/symfony/ux/security/advisories/GHSA-p9xj-fpr2-jf2q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/commit/7b4ddf3764bf269a1b5fde5bf03c4bce568694e4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v2.36.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/symfony/ux/releases/tag/v3.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 467,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55879",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.759Z",
      "date_published": "2026-07-10T20:39:44.493Z",
      "date_updated": "2026-07-13T16:18:55.275Z",
      "publisher": "GitHub_M",
      "title": "OpenReplay: Unauthenticated stored XSS leads to dashboard account takeover",
      "affected": {
        "vendors": [
          "openreplay"
        ],
        "products": [
          {
            "vendor": "openreplay",
            "product": "openreplay"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21225
      },
      "nvd": {
        "published": "2026-07-10T21:16:57.367",
        "lastModified": "2026-07-13T18:12:29.917",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55879",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenReplay stores visitor-controlled event names and URLs and renders them in the dashboard without output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openreplay/openreplay/security/advisories/GHSA-3mfc-7hf4-jfxh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/openreplay/openreplay/commit/ec41f4425a99c478a4418adbd2f094ab6a8b0daf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openreplay/openreplay/releases/tag/v1.25.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 562,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55880",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.759Z",
      "date_published": "2026-07-10T20:42:15.563Z",
      "date_updated": "2026-07-13T18:03:13.624Z",
      "publisher": "GitHub_M",
      "title": "OpenReplay: Cross-user IDOR in notes and dashboard widgets",
      "affected": {
        "vendors": [
          "openreplay"
        ],
        "products": [
          {
            "vendor": "openreplay",
            "product": "openreplay"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09393
      },
      "nvd": {
        "published": "2026-07-10T21:16:57.493",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55880",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Note and dashboard mutations omit the ownership predicate used by sibling operations and therefore act on another user's private objects by ID.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openreplay/openreplay/security/advisories/GHSA-9xfv-p2fx-vmx9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 518,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55881",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.759Z",
      "date_published": "2026-07-10T20:44:15.897Z",
      "date_updated": "2026-07-13T14:12:24.593Z",
      "publisher": "GitHub_M",
      "title": "OpenReplay: Cross-tenant session replay disclosure via missing session ownership check in first-mob endpoint",
      "affected": {
        "vendors": [
          "openreplay"
        ],
        "products": [
          {
            "vendor": "openreplay",
            "product": "openreplay"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.1591
      },
      "nvd": {
        "published": "2026-07-10T21:16:57.653",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55881",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenReplay validates the project tenant but never verifies that the requested session belongs to that project before issuing a recording URL.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openreplay/openreplay/security/advisories/GHSA-w2x5-m7w5-479h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/openreplay/openreplay/pull/4692",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openreplay/openreplay/commit/ddd09117f644a309c7b040cda0a11ff9433e9e49",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openreplay/openreplay/releases/tag/v1.27.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55882",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.759Z",
      "date_published": "2026-07-10T21:37:12.245Z",
      "date_updated": "2026-07-13T18:54:59.289Z",
      "publisher": "GitHub_M",
      "title": "Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server",
      "affected": {
        "vendors": [
          "tilt-dev"
        ],
        "products": [
          {
            "vendor": "tilt-dev",
            "product": "tilt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31162
      },
      "nvd": {
        "published": "2026-07-10T22:16:44.113",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55882",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Tilt mounts active pprof debug handlers on the HUD server without runtime access control when that listener is network exposed.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tilt-dev/tilt/security/advisories/GHSA-p749-9w62-w533",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/tilt-dev/tilt/pull/6776",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/tilt-dev/tilt/commit/47393fba7f6ef5e305d5e814551feef8e4acbc0a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/tilt-dev/tilt/releases/tag/v0.37.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 507,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55883",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.759Z",
      "date_published": "2026-07-10T21:38:18.081Z",
      "date_updated": "2026-07-14T14:14:47.863Z",
      "publisher": "GitHub_M",
      "title": "Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream",
      "affected": {
        "vendors": [
          "tilt-dev"
        ],
        "products": [
          {
            "vendor": "tilt-dev",
            "product": "tilt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12878
      },
      "nvd": {
        "published": "2026-07-10T22:16:44.287",
        "lastModified": "2026-07-14T15:17:04.873",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55883",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The WebSocket upgrader accepts a missing Origin header while an unauthenticated endpoint gives any caller the nominal CSRF token.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tilt-dev/tilt/security/advisories/GHSA-6m68-r693-78qx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/tilt-dev/tilt/pull/6776",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/tilt-dev/tilt/commit/47393fba7f6ef5e305d5e814551feef8e4acbc0a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/tilt-dev/tilt/releases/tag/v0.37.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55884",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.759Z",
      "date_published": "2026-07-10T21:36:18.861Z",
      "date_updated": "2026-07-29T19:26:45.343Z",
      "publisher": "GitHub_M",
      "title": "Tilt: Missing authentication on the network-exposed Tilt HUD server",
      "affected": {
        "vendors": [
          "tilt-dev"
        ],
        "products": [
          {
            "vendor": "tilt-dev",
            "product": "tilt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00398,
        "percentile": 0.32545
      },
      "nvd": {
        "published": "2026-07-10T22:16:44.423",
        "lastModified": "2026-07-29T20:17:04.337",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55884",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Tilt HUD registers security-sensitive handlers without authentication when the server is reachable off loopback.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tilt-dev/tilt/security/advisories/GHSA-c73q-8xxr-rgqm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/tilt-dev/tilt/pull/6776",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/tilt-dev/tilt/commit/47393fba7f6ef5e305d5e814551feef8e4acbc0a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/tilt-dev/tilt/releases/tag/v0.37.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55885",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.759Z",
      "date_published": "2026-07-10T16:13:48.649Z",
      "date_updated": "2026-07-14T01:58:03.984Z",
      "publisher": "GitHub_M",
      "title": "Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-312",
          "name": "Cleartext Storage of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07053
      },
      "nvd": {
        "published": "2026-07-10T17:17:00.273",
        "lastModified": "2026-07-14T02:16:56.520",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55885",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The downloadable administrative backup embeds password hashes and configuration secrets that are not separated from ordinary backup content.",
        "basis": [
          "CNA",
          "CWE-312",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-2f86-9cp8-6hcf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/releases/tag/1.7.53",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55886",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.760Z",
      "date_published": "2026-07-01T20:25:43.632Z",
      "date_updated": "2026-07-02T12:22:32.358Z",
      "publisher": "GitHub_M",
      "title": "Jodit Editor: Prototype Pollution in Jodit via Jodit.modules.Helpers.set()",
      "affected": {
        "vendors": [
          "xdan"
        ],
        "products": [
          {
            "vendor": "xdan",
            "product": "jodit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23917
      },
      "nvd": {
        "published": "2026-07-01T21:17:04.220",
        "lastModified": "2026-07-02T15:12:53.577",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55886",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "jodit follows attacker-controlled object keys through prototype-bearing properties, allowing input to modify inherited program state.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/xdan/jodit/security/advisories/GHSA-vpmm-x3fm-qr5c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 758,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55890",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T16:59:42.760Z",
      "date_published": "2026-07-10T16:17:14.238Z",
      "date_updated": "2026-07-10T18:39:18.467Z",
      "publisher": "GitHub_M",
      "title": "Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style()",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08602
      },
      "nvd": {
        "published": "2026-07-10T17:17:00.400",
        "lastModified": "2026-07-10T19:17:26.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55890",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Grav writes editor-controlled Markdown image style data directly into an HTML style attribute without sanitization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-pmf8-g7c8-7v54",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/commit/24fd6cbc438e12310b126d1176e7d7601203a6f2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/releases/tag/2.0.0-rc.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55898",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T17:36:34.621Z",
      "date_published": "2026-07-14T17:09:10.387Z",
      "date_updated": "2026-08-03T22:57:30.194Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22445
      },
      "nvd": {
        "published": "2026-07-14T18:18:21.640",
        "lastModified": "2026-07-15T17:12:17.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55898",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft 365 Apps for Enterprise reads beyond the available buffer because an input length, offset, or parser boundary is not checked before access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55898",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55899",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T17:36:34.621Z",
      "date_published": "2026-07-14T17:05:10.091Z",
      "date_updated": "2026-08-03T22:53:30.285Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.2263
      },
      "nvd": {
        "published": "2026-07-14T17:17:09.443",
        "lastModified": "2026-07-16T11:51:04.013",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55899",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Excel copies malicious-document data beyond a fixed stack buffer.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55899",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 110,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55944",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T17:37:17.983Z",
      "date_published": "2026-07-14T17:09:10.942Z",
      "date_updated": "2026-08-03T22:57:30.751Z",
      "publisher": "microsoft",
      "title": "Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Dynamics NAV 2018"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01281,
        "percentile": 0.67199
      },
      "nvd": {
        "published": "2026-07-14T18:18:21.850",
        "lastModified": "2026-07-22T16:42:03.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55944",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dynamics NAV deserializes untrusted data received from an unauthenticated network caller.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55944",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55945",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T17:37:17.983Z",
      "date_published": "2026-07-03T20:35:07.264Z",
      "date_updated": "2026-08-03T22:53:30.847Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04212
      },
      "nvd": {
        "published": "2026-07-03T21:17:00.550",
        "lastModified": "2026-07-07T13:31:43.910",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55945",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft Edge has a shared-resource race that discloses information, but the public record does not identify the shared object, conflicting operations, or invalid transition.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55945",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55947",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T17:37:17.983Z",
      "date_published": "2026-07-14T17:09:11.650Z",
      "date_updated": "2026-08-03T22:57:31.313Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22626
      },
      "nvd": {
        "published": "2026-07-14T18:18:22.050",
        "lastModified": "2026-07-15T16:23:03.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55947",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55947",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55948",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T17:37:17.983Z",
      "date_published": "2026-07-14T17:05:11.111Z",
      "date_updated": "2026-08-03T22:53:31.326Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22629
      },
      "nvd": {
        "published": "2026-07-14T17:17:09.637",
        "lastModified": "2026-07-16T11:50:22.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55948",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55948",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55949",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T17:37:17.983Z",
      "date_published": "2026-07-14T17:09:12.118Z",
      "date_updated": "2026-08-03T22:57:31.787Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22626
      },
      "nvd": {
        "published": "2026-07-14T18:18:22.320",
        "lastModified": "2026-07-15T16:22:11.707",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55949",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The public record identifies a memory-safety failure but does not disclose the exact buffer, lifetime transition, or invalid access.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55949",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55950",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T17:55:15.685Z",
      "date_published": "2026-07-02T16:06:24.783Z",
      "date_updated": "2026-07-24T14:14:42.082Z",
      "publisher": "EEF",
      "title": "DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 2.799999999999999,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30673
      },
      "nvd": {
        "published": "2026-07-02T17:17:02.910",
        "lastModified": "2026-07-24T15:18:32.220",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55950",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Rapid DTLS reconnects reuse a source tuple before the prior DOWN event is processed, causing a duplicate gb_trees insertion that crashes the shared demultiplexer.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-hwfc-5hf4-gvr3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-55950.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-55950",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/e44d2bf01c4473ef2ea7f09e3523cf96de6e4a04",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1458,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55952",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T17:55:15.686Z",
      "date_published": "2026-07-02T16:06:08.474Z",
      "date_updated": "2026-07-24T14:14:09.990Z",
      "publisher": "EEF",
      "title": "TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00481,
        "percentile": 0.38922
      },
      "nvd": {
        "published": "2026-07-02T17:17:03.067",
        "lastModified": "2026-07-24T15:18:32.410",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55952",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The TLS 1.3 server forwards unequal PSK identity and binder lists to the session-ticket handler without checking that their counts match.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-8c57-44c9-pc59",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-55952.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-55952",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Third Party Advisory",
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/e77823e6d980b2ec0b4fe4ea3f2d098ca239e3ce",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/2c3e599797644310e5d4aa39c7193420e59dadff",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/9b5437c72fa3403a75c1aba28e5c532bc191c662",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1077,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55953",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T17:55:15.686Z",
      "date_published": "2026-07-27T15:21:29.327Z",
      "date_updated": "2026-08-03T21:44:17.335Z",
      "publisher": "EEF",
      "title": "TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-757",
          "name": "Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15768
      },
      "nvd": {
        "published": "2026-07-27T16:17:49.500",
        "lastModified": "2026-08-03T22:16:50.353",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55953",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OTP mishandles the generation, validation, binding, or lifecycle of an authentication secret, token, credential, or signature.",
        "basis": [
          "CNA",
          "CWE-757"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-55953.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-55953",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/064e236414614f9085cbbbd6eacf0e43c02d1b4b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/0a82596d425abe43dc2e0b3d74aa1557ef74051c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/e6ff938116b2872bccc478af7fefb56627285b77",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1447,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-55954",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T17:55:15.686Z",
      "date_published": "2026-07-14T15:08:26.051Z",
      "date_updated": "2026-07-15T04:14:10.603Z",
      "publisher": "EEF",
      "title": "Missing ID token claim validation in ueberauth_apple allows account takeover",
      "affected": {
        "vendors": [
          "ueberauth"
        ],
        "products": [
          {
            "vendor": "ueberauth",
            "product": "ueberauth_apple"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00411,
        "percentile": 0.33778
      },
      "nvd": {
        "published": "2026-07-14T16:17:01.093",
        "lastModified": "2026-07-15T20:17:27.810",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55954",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Apple strategy verifies the JWT signature but accepts unvalidated issuer, audience, expiry, issued-at, and subject claims as login identity.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ueberauth/ueberauth_apple/security/advisories/GHSA-pxx8-68pc-p9mr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-55954.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-55954",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/ueberauth/ueberauth_apple/commit/01e2d9c9b3134e1b78633ad82d136d5ff4a61f28",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1028,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55968",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T23:09:21.035Z",
      "date_published": "2026-07-27T11:06:17.910Z",
      "date_updated": "2026-07-27T13:05:00.181Z",
      "publisher": "apache",
      "title": "Apache Thrift: Node.js quadratic-time DoS in server receive transports",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.01097,
        "percentile": 0.62373
      },
      "nvd": {
        "published": "2026-07-27T12:16:45.683",
        "lastModified": "2026-07-27T19:50:17.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55968",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The receive transport performs unbounded or quadratic work on attacker-controlled input.",
        "basis": [
          "CNA",
          "CWE-407",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/gxhhfyr6flr5vzr4qnxm13p6fc41qstp",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/39",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55969",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T23:13:54.948Z",
      "date_published": "2026-07-27T11:07:53.785Z",
      "date_updated": "2026-07-27T13:05:35.872Z",
      "publisher": "apache",
      "title": "Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.01097,
        "percentile": 0.62372
      },
      "nvd": {
        "published": "2026-07-27T12:16:45.823",
        "lastModified": "2026-07-27T19:50:33.893",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55969",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TProtocol::checkReadBytesAvailable performs length arithmetic that can overflow before enforcing the read boundary.",
        "basis": [
          "CNA record",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/xmkgd107k795hyrg5kf97mny30sgl5bo",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/40",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-55970",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T23:27:21.434Z",
      "date_published": "2026-07-27T11:09:41.544Z",
      "date_updated": "2026-07-27T13:07:21.939Z",
      "publisher": "apache",
      "title": "Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00825,
        "percentile": 0.53865
      },
      "nvd": {
        "published": "2026-07-27T12:16:45.977",
        "lastModified": "2026-07-27T19:50:45.897",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55970",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache Thrift reads past the end of a buffer and exposes adjacent memory.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/8pbnw4dyxxc9opp6qq725jhrzg25v8q7",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/41",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55971",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-17T23:28:34.852Z",
      "date_published": "2026-07-27T11:11:23.201Z",
      "date_updated": "2026-07-28T03:55:51.567Z",
      "publisher": "apache",
      "title": "Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.01042,
        "percentile": 0.60722
      },
      "nvd": {
        "published": "2026-07-27T12:16:46.110",
        "lastModified": "2026-07-28T05:17:06.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55971",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Apache Thrift C++ bindings write beyond a heap allocation while processing crafted serialized input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/xjs36m6kjxpmrmzwck636msg3nvoqnmx",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/42",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55973",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:27:22.820Z",
      "date_published": "2026-07-22T13:09:50.942Z",
      "date_updated": "2026-07-22T14:06:00.025Z",
      "publisher": "NLnet Labs",
      "title": "'dns-error-reporting: yes' leads to stack buffer overflow",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21371
      },
      "nvd": {
        "published": "2026-07-22T14:17:21.663",
        "lastModified": "2026-07-24T14:24:21.837",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55973",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unbound trusts an EDNS report-channel length past an embedded root and later interprets a garbage byte as a DNS label length, overwriting a stack buffer.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55973.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 975,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55977",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T04:11:38.685Z",
      "date_published": "2026-07-28T08:10:10.046Z",
      "date_updated": "2026-07-28T12:50:05.454Z",
      "publisher": "CSA",
      "title": "Bypass of application rate-limiting mechanism",
      "affected": {
        "vendors": [
          "EShare"
        ],
        "products": [
          {
            "vendor": "EShare",
            "product": "ESharePro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00093,
        "percentile": 0.00665
      },
      "nvd": {
        "published": "2026-07-28T08:17:16.630",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55977",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The authentication flow does not enforce an effective attempt limit, allowing repeated guesses against the protected secret or code.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-093/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55985",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T18:17:10.045Z",
      "date_published": "2026-07-24T21:37:29.863Z",
      "date_updated": "2026-07-27T14:31:42.000Z",
      "publisher": "icscert",
      "title": "Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information",
      "affected": {
        "vendors": [
          "Tycon Systems"
        ],
        "products": [
          {
            "vendor": "Tycon Systems",
            "product": "TPDIN-Monitor-WEB2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-312",
          "name": "Cleartext Storage of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04645
      },
      "nvd": {
        "published": "2026-07-24T22:16:50.807",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55985",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The management interface stores system credentials in plaintext and renders them directly on an authenticated configuration page.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-312"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tyconsystems.com/contact",
          "host": "www.tyconsystems.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-01.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55990",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T10:11:10.529Z",
      "date_published": "2026-07-22T13:10:01.635Z",
      "date_updated": "2026-07-22T14:04:28.690Z",
      "publisher": "NLnet Labs",
      "title": "Packet of death for a DNSCrypt misconfigured Unbound",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17253
      },
      "nvd": {
        "published": "2026-07-22T14:17:21.810",
        "lastModified": "2026-07-24T14:24:26.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55990",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Unbound path uses a value or pointer before assigning a valid initial state.",
        "basis": [
          "CNA",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55990.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 849,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55991",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T10:11:10.505Z",
      "date_published": "2026-07-22T13:10:13.235Z",
      "date_updated": "2026-07-22T14:03:20.789Z",
      "publisher": "NLnet Labs",
      "title": "Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-195",
          "name": "Signed to Unsigned Conversion Error",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14836
      },
      "nvd": {
        "published": "2026-07-22T14:17:21.957",
        "lastModified": "2026-07-24T14:25:18.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55991",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A signed value is converted to a large unsigned QUIC varint and reaches an invalid memory or assertion state.",
        "basis": [
          "CNA",
          "CWE-195"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55991.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1136,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55993",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T08:12:33.509Z",
      "date_published": "2026-07-06T08:13:24.909Z",
      "date_updated": "2026-07-07T12:39:32.830Z",
      "publisher": "apache",
      "title": "Apache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling influencing internal behaviour",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel Atmosphere Websocket"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00783,
        "percentile": 0.52494
      },
      "nvd": {
        "published": "2026-07-06T09:16:38.897",
        "lastModified": "2026-07-09T03:03:47.023",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55993",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Apache Camel Atmosphere Websocket request path accepts an attacker-controlled destination or redirect without constraining the resolved server-side network target.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-200",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-55993.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/27",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2571,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-55994",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T08:14:02.970Z",
      "date_published": "2026-07-06T08:13:59.420Z",
      "date_updated": "2026-07-06T21:13:45.038Z",
      "publisher": "apache",
      "title": "Apache Camel Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling control over internal behaviour",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel Iggy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00621,
        "percentile": 0.46362
      },
      "nvd": {
        "published": "2026-07-06T09:16:39.033",
        "lastModified": "2026-07-09T03:03:31.657",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55994",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Camel Iggy maps untrusted inbound headers onto Exchange routing headers, allowing the sender to select internal request destinations.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-200",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-55994.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/28",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2242,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-55995",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T09:26:55.987Z",
      "date_published": "2026-07-29T13:43:22.381Z",
      "date_updated": "2026-07-29T14:43:55.157Z",
      "publisher": "suse",
      "title": "Double-free in the iSNS attribute decoder in open-iscsi",
      "affected": {
        "vendors": [
          "open-iscsi"
        ],
        "products": [
          {
            "vendor": "open-iscsi",
            "product": "open-iscsi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16635
      },
      "nvd": {
        "published": "2026-07-29T14:16:31.423",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-55995",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in open-iscsi, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55995",
          "host": "bugzilla.suse.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open-iscsi/open-isns/commit/56718d4e9d1a4f51c30697b5c0534144bb41c9bb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-55999",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T09:26:55.988Z",
      "date_published": "2026-07-08T08:07:11.088Z",
      "date_updated": "2026-07-09T03:55:43.683Z",
      "publisher": "suse",
      "title": "xorg-server / xwayland glamor font atlas Heap Buffer Overflow",
      "affected": {
        "vendors": [
          "X.Org"
        ],
        "products": [
          {
            "vendor": "X.Org",
            "product": "xorg-server"
          },
          {
            "vendor": "X.Org",
            "product": "xwayland"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18894
      },
      "nvd": {
        "published": "2026-07-08T09:16:29.800",
        "lastModified": "2026-07-09T19:49:51.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-55999",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Xorg SetFont omits glyph-boundary checks and writes beyond the destination heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.freedesktop.org/xorg/xserver/-/commit/fbf7bac22e2c6bd627fb042742a23318263edae1",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/08/2",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Third Party Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56000",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T09:26:55.988Z",
      "date_published": "2026-07-08T07:36:15.357Z",
      "date_updated": "2026-07-08T12:42:16.061Z",
      "publisher": "suse",
      "title": "xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()",
      "affected": {
        "vendors": [
          "X.Org"
        ],
        "products": [
          {
            "vendor": "X.Org",
            "product": "xorg-x11-server"
          },
          {
            "vendor": "X.Org",
            "product": "xwayland"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12828
      },
      "nvd": {
        "published": "2026-07-08T09:16:29.923",
        "lastModified": "2026-07-09T19:47:29.210",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56000",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path continues using an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.freedesktop.org/xorg/xserver/-/commit/2779affbdb4354e894f490e56f962527d6125043",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/08/2",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Third Party Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56001",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T09:26:55.988Z",
      "date_published": "2026-07-08T08:49:24.706Z",
      "date_updated": "2026-07-09T03:55:45.984Z",
      "publisher": "suse",
      "title": "libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow",
      "affected": {
        "vendors": [
          "X.Org"
        ],
        "products": [
          {
            "vendor": "X.Org",
            "product": "libXfont2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00381,
        "percentile": 0.30803
      },
      "nvd": {
        "published": "2026-07-08T09:16:30.050",
        "lastModified": "2026-07-09T19:46:32.177",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56001",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libXfont2 can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/08/1",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Third Party Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56002",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T09:26:55.988Z",
      "date_published": "2026-07-08T09:12:51.480Z",
      "date_updated": "2026-07-09T03:55:46.745Z",
      "publisher": "suse",
      "title": "libXfont2 PCF Font Parsing Heap Buffer Overflow",
      "affected": {
        "vendors": [
          "X.Org"
        ],
        "products": [
          {
            "vendor": "X.Org",
            "product": "libXfont2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00428,
        "percentile": 0.35218
      },
      "nvd": {
        "published": "2026-07-08T10:16:23.327",
        "lastModified": "2026-07-13T13:57:14.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56002",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is written beyond the boundary of a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/b4389e0b1d84a690b819bb27b1439968811a3674",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/08/1",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Third Party Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56003",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T09:26:55.988Z",
      "date_published": "2026-07-08T09:25:41.723Z",
      "date_updated": "2026-07-09T03:55:47.539Z",
      "publisher": "suse",
      "title": "libXfont2 computeProps Property Buffer Heap Buffer Overflow",
      "affected": {
        "vendors": [
          "X.Org"
        ],
        "products": [
          {
            "vendor": "X.Org",
            "product": "libXfont2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00373,
        "percentile": 0.3006
      },
      "nvd": {
        "published": "2026-07-08T10:16:23.577",
        "lastModified": "2026-07-09T19:50:11.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56003",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libXfont2 writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/08/1",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Third Party Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/dff957a5158da038a282a59a31fe736702732939",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 260,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56004",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T09:26:55.988Z",
      "date_published": "2026-07-02T14:54:02.119Z",
      "date_updated": "2026-07-02T16:11:28.338Z",
      "publisher": "suse",
      "title": "obs-service-tar_scm: command injection via mercurial handler",
      "affected": {
        "vendors": [
          "openSUSE"
        ],
        "products": [
          {
            "vendor": "openSUSE",
            "product": "buildservice"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30227
      },
      "nvd": {
        "published": "2026-07-02T15:17:06.413",
        "lastModified": "2026-07-02T17:45:44.830",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56004",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Mercurial service handler places attacker-controlled _service data into a shell command without command-safe separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openSUSE/obs-service-tar_scm/pull/552/changes/bcf29d318c671c45fe87dd9f995a4a0c78ecedd7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56015",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T11:27:09.117Z",
      "date_published": "2026-07-03T12:56:04.288Z",
      "date_updated": "2026-07-06T18:36:22.103Z",
      "publisher": "CPANSec",
      "title": "Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length",
      "affected": {
        "vendors": [
          "TPODER"
        ],
        "products": [
          {
            "vendor": "TPODER",
            "product": "Net::IP::LPM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00537,
        "percentile": 0.42221
      },
      "nvd": {
        "published": "2026-07-03T13:17:30.130",
        "lastModified": "2026-07-06T19:17:08.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56015",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The trie builder walks an unbounded prefix length over a fixed 4-byte or 16-byte packed address and reads past it.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://rt.cpan.org/Ticket/Display.html?id=179856",
          "host": "rt.cpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://security.metacpan.org/patches/N/Net-IP-LPM/1.10/CVE-2026-56015-r2.patch",
          "host": "security.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/03/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1073,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56016",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T11:27:09.117Z",
      "date_published": "2026-07-01T06:46:23.589Z",
      "date_updated": "2026-07-01T17:36:49.480Z",
      "publisher": "CPANSec",
      "title": "CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources",
      "affected": {
        "vendors": [
          "MARKSTOS"
        ],
        "products": [
          {
            "vendor": "MARKSTOS",
            "product": "CGI::Session::ID::md5"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-340",
          "name": "Generation of Predictable Numbers or Identifiers",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28862
      },
      "nvd": {
        "published": "2026-07-01T08:16:21.883",
        "lastModified": "2026-07-02T17:39:57.427",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56016",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Session IDs are derived from predictable process ID, time, and non-cryptographic rand values, allowing an attacker to guess another session identifier.",
        "basis": [
          "CNA",
          "CWE-338",
          "CWE-340"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/MARKSTOS/CGI-Session-4.49/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://metacpan.org/release/MARKSTOS/CGI-Session-4.49/source/lib/CGI/Session/ID/md5.pm",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/01/6",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 597,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56037",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T14:37:40.347Z",
      "date_published": "2026-07-02T11:30:12.515Z",
      "date_updated": "2026-07-02T15:52:31.034Z",
      "publisher": "Patchstack",
      "title": "WordPress Themify Popup plugin <= 1.4.3 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "Themify"
        ],
        "products": [
          {
            "vendor": "Themify",
            "product": "Themify Popup"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22254
      },
      "nvd": {
        "published": "2026-07-02T12:17:34.210",
        "lastModified": "2026-07-02T16:16:33.973",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56037",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Themify Popup parser reconstructs an attacker-controlled serialized object with executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/themify-popup/vulnerability/wordpress-themify-popup-plugin-1-4-3-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 156,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T17:04:56.015Z",
      "date_published": "2026-07-03T12:46:42.895Z",
      "date_updated": "2026-07-06T15:29:01.032Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00095,
        "percentile": 0.0079
      },
      "nvd": {
        "published": "2026-07-03T13:17:30.240",
        "lastModified": "2026-07-08T19:32:34.597",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56085",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerProtect uses an uninitialized resource in a local path and can expose its residual contents.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-56086",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T17:04:56.016Z",
      "date_published": "2026-07-08T13:34:04.194Z",
      "date_updated": "2026-07-09T03:55:50.758Z",
      "publisher": "dell",
      "title": "Dell PowerProtect Data Domain, versions 7.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerProtect Data Domain"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23809
      },
      "nvd": {
        "published": "2026-07-08T14:17:14.980",
        "lastModified": "2026-07-09T04:17:46.973",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56086",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that PowerProtect Data Domain permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 385,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-56087",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-18T17:04:56.016Z",
      "date_published": "2026-07-15T17:28:03.944Z",
      "date_updated": "2026-07-15T19:30:38.769Z",
      "publisher": "dell",
      "title": "Dell ThinOS 10, versions prior to 2605_10.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "ThinOS 10"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04195
      },
      "nvd": {
        "published": "2026-07-15T18:16:48.370",
        "lastModified": "2026-07-15T20:17:48.740",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56087",
        "family": "HARDWARE_PHYSICAL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ThinOS 10 exposes a security-sensitive hardware, debug, boot, or encrypted-data boundary to a physically proximate caller without the required physical-presence or device-state restriction.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000489640/dsa-2026-300-security-update-for-dell-thinos-10-for-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56139",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T09:53:55.822Z",
      "date_published": "2026-07-06T08:15:08.493Z",
      "date_updated": "2026-07-06T20:55:43.126Z",
      "publisher": "apache",
      "title": "Apache Camel Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel Undertow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0053,
        "percentile": 0.41858
      },
      "nvd": {
        "published": "2026-07-06T09:16:39.157",
        "lastModified": "2026-07-09T03:03:18.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56139",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Undertow consumer returns complete exception stack traces because muteException defaults to false and Rest DSL ignores an explicit true setting.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-56139.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/05/29",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2307,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56140",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T09:56:29.381Z",
      "date_published": "2026-07-06T08:16:00.599Z",
      "date_updated": "2026-07-06T19:31:06.707Z",
      "publisher": "apache",
      "title": "Apache Camel AWS2 SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy to align it with sibling components",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Camel AWS2 SNS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00427,
        "percentile": 0.3513
      },
      "nvd": {
        "published": "2026-07-06T09:16:39.280",
        "lastModified": "2026-07-09T13:02:06.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56140",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The SNS header strategy lacks an inbound Camel-namespace filter, although the producer-only component exposes no known external path that can exercise it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://camel.apache.org/security/CVE-2026-56140.html",
          "host": "camel.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2076,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T11:01:02.535Z",
      "date_published": "2026-07-21T19:49:43.992Z",
      "date_updated": "2026-07-22T18:25:40.635Z",
      "publisher": "elastic",
      "title": "Incorrect Authorization in Elasticsearch Leading to Information Disclosure",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Elasticsearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11385
      },
      "nvd": {
        "published": "2026-07-21T20:17:02.377",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56144",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ingest simulation feature runs pipelines and returns mappings for indices outside the caller's limited index privileges.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/elasticsearch-8-19-18-9-3-7-9-4-4-security-update-esa-2026-56/388555",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 564,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T11:01:02.535Z",
      "date_published": "2026-07-21T20:04:47.033Z",
      "date_updated": "2026-07-22T18:25:22.708Z",
      "publisher": "elastic",
      "title": "Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Elasticsearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21194
      },
      "nvd": {
        "published": "2026-07-21T20:17:02.500",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56145",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An EQL sequence query can force Elasticsearch to consume enough memory to crash the node without an effective allocation bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/elasticsearch-8-19-18-9-3-7-9-4-4-security-update-esa-2026-57/388556",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56146",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T11:01:02.535Z",
      "date_published": "2026-07-21T20:09:18.544Z",
      "date_updated": "2026-07-22T18:25:16.770Z",
      "publisher": "elastic",
      "title": "Improper Access Control in Kibana Leading to Unauthorized Data Modification and Information Disclosure",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07032
      },
      "nvd": {
        "published": "2026-07-21T20:17:02.613",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56146",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kibana grants a read-only user a mutation path for Entity Analytics Watchlist configuration.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-58/388557",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T11:01:02.535Z",
      "date_published": "2026-07-21T20:14:59.750Z",
      "date_updated": "2026-07-22T19:41:07.488Z",
      "publisher": "elastic",
      "title": "Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Information Disclosure and Case Attachment Integrity Compromise",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17462
      },
      "nvd": {
        "published": "2026-07-21T21:16:52.433",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56147",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Because the access control check and the resource retrieval use different resolution mechanisms, an authenticated attacker with limited file management permissions can obtain the contents of, modify, or delete protected case attachments — such as those associated with Security Solution cases — without holding the privileges required to access those features.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-8-19-18-9-3-7-9-4-3-security-update-esa-2026-59/388558",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 768,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56148",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T11:01:02.535Z",
      "date_published": "2026-07-01T16:17:05.998Z",
      "date_updated": "2026-07-01T17:25:09.726Z",
      "publisher": "elastic",
      "title": "Uncontrolled Recursion in Elasticsearch Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Elasticsearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27383
      },
      "nvd": {
        "published": "2026-07-01T17:16:36.840",
        "lastModified": "2026-07-02T17:38:29.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56148",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/elasticsearch-8-19-17-9-3-6-9-4-3-security-update-esa-2026-42",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56149",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T11:01:02.535Z",
      "date_published": "2026-07-01T16:21:24.437Z",
      "date_updated": "2026-07-01T17:25:09.581Z",
      "publisher": "elastic",
      "title": "Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Elasticsearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24886
      },
      "nvd": {
        "published": "2026-07-01T17:16:36.957",
        "lastModified": "2026-07-02T17:35:59.397",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56149",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation lets attacker-controlled work or allocation grow without an effective per-request bound or termination condition.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/elasticsearch-8-19-17-9-3-6-9-4-3-security-update-esa-2026-43",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 327,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56150",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T11:01:02.535Z",
      "date_published": "2026-07-01T16:26:31.198Z",
      "date_updated": "2026-07-01T17:25:09.438Z",
      "publisher": "elastic",
      "title": "Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Fleet Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27699
      },
      "nvd": {
        "published": "2026-07-01T17:16:37.060",
        "lastModified": "2026-07-06T18:51:50.527",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56150",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled request can allocate or retain work or memory without an effective per-request bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/fleet-server-8-19-11-9-2-5-9-3-0-security-update-esa-2026-44",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56151",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T11:01:02.535Z",
      "date_published": "2026-07-01T16:29:25.165Z",
      "date_updated": "2026-07-01T17:25:08.241Z",
      "publisher": "elastic",
      "title": "Improper Input Validation in Kibana Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20402
      },
      "nvd": {
        "published": "2026-07-01T17:16:37.167",
        "lastModified": "2026-07-02T16:09:39.207",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56151",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kibana accepts a malformed Fleet policy input that invalidates agent, server, and policy management state instead of rejecting the policy.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-8-19-17-9-3-6-9-4-3-security-update-esa-2026-45",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 309,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56152",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T11:01:02.535Z",
      "date_published": "2026-07-01T16:32:21.830Z",
      "date_updated": "2026-07-01T17:25:07.934Z",
      "publisher": "elastic",
      "title": "Incorrect Authorization in Elastic Defend Leading to Information Disclosure",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Elastic Defend"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09975
      },
      "nvd": {
        "published": "2026-07-01T17:16:37.273",
        "lastModified": "2026-07-06T18:05:39.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56152",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Elastic Defend user can read response-action data outside the intended ACL, but the exact missing authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/elastic-defend-8-19-13-9-2-7-9-3-2-security-update-esa-2026-46",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56155",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.988Z",
      "date_published": "2026-07-14T17:05:11.702Z",
      "date_updated": "2026-08-03T22:53:31.888Z",
      "publisher": "microsoft",
      "title": "Active Directory Federation Services Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1220",
          "name": "Insufficient Granularity of Access Control",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.02333,
        "percentile": 0.81871
      },
      "official_kev": {
        "cveID": "CVE-2026-56155",
        "vendorProject": "Microsoft",
        "product": "Active Directory Federation Services",
        "vulnerabilityName": "Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability ",
        "dateAdded": "2026-07-14",
        "shortDescription": "Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-07-28",
        "knownRansomwareCampaignUse": "Unknown",
        "notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-56155; https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/decommission/adfs-decommission-guide",
        "cwes": [
          "CWE-1220"
        ]
      },
      "nvd": {
        "published": "2026-07-14T17:17:09.763",
        "lastModified": "2026-07-15T14:18:24.010",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56155",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AD FS uses an access-control decision that is too coarse and lets an already authorized local user acquire administrator privileges.",
        "basis": [
          "CNA",
          "CWE-1220",
          "Microsoft July 2026 CVRF",
          "CISA KEV"
        ],
        "deepDive": true,
        "notes": "Inspected https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jul and https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json on 2026-08-05; Microsoft confirms CWE-1220, administrator privilege gain, and exploitation detected, while CISA added it on 2026-07-14 with a 2026-07-28 due date, but neither source discloses the protected object or check."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56155",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 151,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-56156",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.988Z",
      "date_published": "2026-07-14T17:09:12.669Z",
      "date_updated": "2026-08-03T22:57:32.415Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26113
      },
      "nvd": {
        "published": "2026-07-14T18:18:22.537",
        "lastModified": "2026-07-15T16:20:17.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56156",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can write beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56156",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-56157",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.988Z",
      "date_published": "2026-07-14T17:09:13.214Z",
      "date_updated": "2026-08-03T22:57:32.884Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00356,
        "percentile": 0.28309
      },
      "nvd": {
        "published": "2026-07-14T18:18:22.673",
        "lastModified": "2026-07-15T15:13:19.563",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56157",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An authenticated SharePoint user can present spoofed content because access control is improper, but the public record identifies no object or failing check.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56157",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56159",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.988Z",
      "date_published": "2026-07-14T17:09:14.316Z",
      "date_updated": "2026-08-03T22:57:33.907Z",
      "publisher": "microsoft",
      "title": "DHCP Server Service Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00996,
        "percentile": 0.59289
      },
      "nvd": {
        "published": "2026-07-14T18:18:22.797",
        "lastModified": "2026-07-21T20:14:36.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56159",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 writes attacker-controlled data beyond a heap buffer boundary.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56159",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-56160",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.988Z",
      "date_published": "2026-07-23T23:55:13.691Z",
      "date_updated": "2026-08-03T22:52:46.048Z",
      "publisher": "microsoft",
      "title": "Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure Red Hat OpenShift (ARO)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00652,
        "percentile": 0.47716
      },
      "nvd": {
        "published": "2026-07-24T01:17:34.560",
        "lastModified": "2026-07-25T05:16:35.313",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56160",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Azure Red Hat OpenShift allows an authenticated network caller to elevate privilege, but MSRC publishes no failing authorization rule.",
        "basis": [
          "CNA",
          "CWE-285",
          "Microsoft MSRC CVE page"
        ],
        "deepDive": true,
        "notes": "Primary-source deep dive: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56160 ; the official page exposes no technical detail beyond the embedded improper-authorization record."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56160",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56163",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.988Z",
      "date_published": "2026-07-24T14:36:55.793Z",
      "date_updated": "2026-08-03T22:52:44.301Z",
      "publisher": "microsoft",
      "title": "Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure Kubernetes Service"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00901,
        "percentile": 0.5622
      },
      "nvd": {
        "published": "2026-07-24T15:18:33.030",
        "lastModified": "2026-07-29T14:57:34.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56163",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected AKS network function is reachable without the authentication gate required before granting elevated authority.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56163",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 152,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56164",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.988Z",
      "date_published": "2026-07-14T17:05:12.313Z",
      "date_updated": "2026-08-03T22:53:32.361Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 4.500000000000001,
      "epss": {
        "score": 0.22439,
        "percentile": 0.97459
      },
      "official_kev": {
        "cveID": "CVE-2026-56164",
        "vendorProject": "Microsoft",
        "product": "SharePoint Server",
        "vulnerabilityName": "Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability",
        "dateAdded": "2026-07-14",
        "shortDescription": "Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-07-17",
        "knownRansomwareCampaignUse": "Unknown",
        "notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56164 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-56164",
        "cwes": [
          "CWE-306"
        ]
      },
      "nvd": {
        "published": "2026-07-14T17:17:09.907",
        "lastModified": "2026-07-14T21:10:41.693",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56164",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable security-sensitive operation is exposed without the authentication step required before invoking it.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-306",
          "Microsoft CVRF",
          "CISA KEV"
        ],
        "deepDive": true,
        "notes": "Inspected Microsoft July 2026 CVRF https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jul and CISA KEV JSON https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; both confirm CWE-306 and exploitation, while Microsoft publishes fixes and AMSI mitigation but no vulnerable endpoint or source patch."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56164",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 145,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56165",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.989Z",
      "date_published": "2026-07-23T23:55:12.338Z",
      "date_updated": "2026-08-03T22:52:44.870Z",
      "publisher": "microsoft",
      "title": "Microsoft Account Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Account"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00721,
        "percentile": 0.50378
      },
      "nvd": {
        "published": "2026-07-24T01:17:34.750",
        "lastModified": "2026-07-30T15:46:42.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56165",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Account copies network-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56165",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 111,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56167",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.989Z",
      "date_published": "2026-07-23T23:55:11.014Z",
      "date_updated": "2026-08-03T22:52:43.765Z",
      "publisher": "microsoft",
      "title": "Azure AI Search Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure AI Search"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00406,
        "percentile": 0.3335
      },
      "nvd": {
        "published": "2026-07-24T01:17:34.877",
        "lastModified": "2026-07-29T14:36:54.927",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56167",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Azure AI Search server fetches an attacker-selected network destination without enforcing the intended destination policy.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56167",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56168",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.989Z",
      "date_published": "2026-07-14T17:09:15.345Z",
      "date_updated": "2026-08-03T22:57:34.992Z",
      "publisher": "microsoft",
      "title": "Windows SMB Server Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00791,
        "percentile": 0.52746
      },
      "nvd": {
        "published": "2026-07-14T18:18:23.020",
        "lastModified": "2026-07-22T16:18:24.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56168",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A memory object is accessed outside its valid bounds or lifetime.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56168",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-56169",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.989Z",
      "date_published": "2026-07-14T17:05:12.870Z",
      "date_updated": "2026-08-03T22:53:32.832Z",
      "publisher": "microsoft",
      "title": "Windows Admin Center Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows Admin Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.7000000000000011,
      "epss": {
        "score": 0.00505,
        "percentile": 0.40419
      },
      "nvd": {
        "published": "2026-07-14T17:17:10.027",
        "lastModified": "2026-07-21T18:15:45.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56169",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Windows Admin Center access path accepts an identity or request signal that is insufficient to authenticate the actor for the requested operation.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56169",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56170",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.989Z",
      "date_published": "2026-07-14T17:05:13.486Z",
      "date_updated": "2026-08-03T22:53:33.440Z",
      "publisher": "microsoft",
      "title": "ASP.NET Core Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01008,
        "percentile": 0.59667
      },
      "nvd": {
        "published": "2026-07-14T17:17:10.140",
        "lastModified": "2026-07-22T21:17:56.337",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56170",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ASP.NET accepts requests that trigger allocations without an effective memory limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56170",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56171",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.989Z",
      "date_published": "2026-07-17T21:34:17.768Z",
      "date_updated": "2026-08-03T22:59:13.069Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Remote Desktop Web Client"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Admin Center"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-359",
          "name": "Exposure of Private Personal Information to an Unauthorized Actor",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.0048,
        "percentile": 0.38885
      },
      "nvd": {
        "published": "2026-07-17T22:17:54.117",
        "lastModified": "2026-07-22T18:24:35.273",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56171",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Remote Desktop Web Client exposes protected data to an unintended observer, while the field and output path are not public.",
        "basis": [
          "CNA",
          "CWE-359"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56171",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 152,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56173",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.989Z",
      "date_published": "2026-07-14T17:09:15.974Z",
      "date_updated": "2026-08-03T22:57:35.618Z",
      "publisher": "microsoft",
      "title": "Windows WebView Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15888
      },
      "nvd": {
        "published": "2026-07-14T18:18:23.310",
        "lastModified": "2026-07-22T16:18:25.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56173",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows WebView accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56173",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-56175",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.989Z",
      "date_published": "2026-07-14T17:09:17.012Z",
      "date_updated": "2026-08-03T22:57:36.767Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23438
      },
      "nvd": {
        "published": "2026-07-14T18:18:23.460",
        "lastModified": "2026-07-22T11:49:21.103",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56175",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler writes attacker-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56175",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-56176",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.989Z",
      "date_published": "2026-07-14T17:09:16.454Z",
      "date_updated": "2026-08-03T22:57:36.171Z",
      "publisher": "microsoft",
      "title": "Windows Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15136
      },
      "nvd": {
        "published": "2026-07-14T18:18:23.630",
        "lastModified": "2026-07-22T17:36:39.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56176",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 can read beyond the valid bounds of an input or object allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56176",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-56178",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:53:31.990Z",
      "date_published": "2026-07-14T17:09:24.821Z",
      "date_updated": "2026-08-03T22:57:45.555Z",
      "publisher": "microsoft",
      "title": "Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Defender for Endpoint for Mac"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06395
      },
      "nvd": {
        "published": "2026-07-14T18:18:23.917",
        "lastModified": "2026-07-22T16:34:23.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56178",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Defender checks a local object and later uses it without preserving identity or exclusivity across the intervening race window.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56178",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 145,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56181",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.005Z",
      "date_published": "2026-07-14T17:10:17.039Z",
      "date_updated": "2026-08-03T22:59:04.787Z",
      "publisher": "microsoft",
      "title": "Windows Network Address Translation (NAT) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14808
      },
      "nvd": {
        "published": "2026-07-14T18:18:24.793",
        "lastModified": "2026-07-22T16:18:26.147",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56181",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Windows 11 Version 24H2 accepts data from a network origin without validating that the origin is authorized for the claimed action.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56181",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-56182",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.005Z",
      "date_published": "2026-07-14T17:09:17.646Z",
      "date_updated": "2026-08-03T22:57:37.326Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15135
      },
      "nvd": {
        "published": "2026-07-14T18:18:25.010",
        "lastModified": "2026-07-22T16:18:26.267",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56182",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NTFS integer arithmetic can wrap and drive a privileged local memory operation with an invalid size or offset.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56182",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-56183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.005Z",
      "date_published": "2026-07-14T17:09:18.124Z",
      "date_updated": "2026-08-03T22:57:37.908Z",
      "publisher": "microsoft",
      "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15888
      },
      "nvd": {
        "published": "2026-07-14T18:18:28.063",
        "lastModified": "2026-07-23T05:16:37.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56183",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows MIDI Service retains and uses an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56183",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.006Z",
      "date_published": "2026-07-14T17:09:19.214Z",
      "date_updated": "2026-08-03T22:57:39.155Z",
      "publisher": "microsoft",
      "title": "Win32k Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00458,
        "percentile": 0.37497
      },
      "nvd": {
        "published": "2026-07-14T18:18:28.213",
        "lastModified": "2026-07-22T11:43:09.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56184",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Win32K returns or exposes sensitive local information to an authorized user who should not receive it, but the output path is not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56184",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-56185",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.006Z",
      "date_published": "2026-07-14T17:05:15.865Z",
      "date_updated": "2026-08-03T22:53:35.547Z",
      "publisher": "microsoft",
      "title": "Windows Admin Center Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows Admin Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00604,
        "percentile": 0.45507
      },
      "nvd": {
        "published": "2026-07-14T17:17:10.257",
        "lastModified": "2026-07-21T18:15:15.177",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56185",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The record identifies an authentication failure in Windows Admin Center but does not disclose the credential, session, or endpoint check involved.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56185",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56186",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.006Z",
      "date_published": "2026-07-14T17:09:20.474Z",
      "date_updated": "2026-08-03T22:57:40.280Z",
      "publisher": "microsoft",
      "title": "Windows Secure Channel Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.01059,
        "percentile": 0.61219
      },
      "nvd": {
        "published": "2026-07-14T18:18:28.440",
        "lastModified": "2026-07-22T16:18:26.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56186",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Schannel reads beyond an allocated buffer in a network-reachable authenticated path.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56186",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-56187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.006Z",
      "date_published": "2026-07-14T17:09:19.845Z",
      "date_updated": "2026-08-03T22:57:39.776Z",
      "publisher": "microsoft",
      "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17606
      },
      "nvd": {
        "published": "2026-07-14T18:18:28.650",
        "lastModified": "2026-07-23T05:16:37.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56187",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 11 Version 24H2, code retains or reuses an object after the lifetime transition that frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56187",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.006Z",
      "date_published": "2026-07-14T17:09:21.098Z",
      "date_updated": "2026-08-03T22:57:40.932Z",
      "publisher": "microsoft",
      "title": "Windows Server Network driver Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00916,
        "percentile": 0.56725
      },
      "nvd": {
        "published": "2026-07-14T18:18:28.800",
        "lastModified": "2026-07-22T16:18:26.960",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56188",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Windows Server Network driver accesses shared connection state concurrently without the synchronization needed to keep that state consistent, allowing crafted network traffic to drive the race into code execution.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362",
          "Microsoft CVRF"
        ],
        "deepDive": true,
        "notes": "Inspected Microsoft's official July 2026 CVRF at https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jul and the advisory entry https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56188; the record confirms CWE-362 and crafted malicious traffic, but it does not publish the shared object, missing lock, or source diff."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56188",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 188,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-56189",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.006Z",
      "date_published": "2026-07-14T17:09:21.584Z",
      "date_updated": "2026-08-03T22:57:41.616Z",
      "publisher": "microsoft",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32382
      },
      "nvd": {
        "published": "2026-07-14T18:18:28.997",
        "lastModified": "2026-07-22T11:41:07.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56189",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Media Foundation writes beyond a heap allocation while processing attacker-controlled media data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56189",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-56190",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.006Z",
      "date_published": "2026-07-14T17:09:18.669Z",
      "date_updated": "2026-08-03T22:57:38.529Z",
      "publisher": "microsoft",
      "title": "Remote Desktop Protocol Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01088,
        "percentile": 0.62067
      },
      "nvd": {
        "published": "2026-07-14T18:18:29.240",
        "lastModified": "2026-07-22T16:18:27.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56190",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 uses a resource before its initialization path has established valid state.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56190",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-56191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.006Z",
      "date_published": "2026-07-24T00:01:12.361Z",
      "date_updated": "2026-08-03T22:59:15.267Z",
      "publisher": "microsoft",
      "title": "Microsoft Exchange Online Tampering Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Online"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00667,
        "percentile": 0.48302
      },
      "nvd": {
        "published": "2026-07-24T01:17:36.417",
        "lastModified": "2026-07-29T14:55:55.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56191",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Exchange Online accepted an unauthenticated network action that allowed tampering, but Microsoft does not disclose the failing authentication decision.",
        "basis": [
          "CNA",
          "CWE-287",
          "https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2026-56191"
        ],
        "deepDive": true,
        "notes": "Primary source inspected: https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2026-56191. MSRC says the issue is already fully mitigated and requires no customer action, but its public API provides only the generic CWE-287 description and no failing authentication check."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56191",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.006Z",
      "date_published": "2026-07-14T17:09:22.693Z",
      "date_updated": "2026-08-03T22:57:42.901Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00421,
        "percentile": 0.34738
      },
      "nvd": {
        "published": "2026-07-14T18:18:29.447",
        "lastModified": "2026-07-16T15:16:33.303",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56192",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Office reads beyond a memory buffer while processing local attacker input.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56192",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-56193",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.006Z",
      "date_published": "2026-07-14T17:05:15.283Z",
      "date_updated": "2026-08-03T22:53:34.997Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00365,
        "percentile": 0.29253
      },
      "nvd": {
        "published": "2026-07-14T17:17:10.377",
        "lastModified": "2026-07-16T15:12:47.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56193",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Office reads beyond an allocated buffer while processing attacker-controlled content.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56193",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-56194",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.006Z",
      "date_published": "2026-07-14T17:09:27.468Z",
      "date_updated": "2026-08-03T22:57:48.385Z",
      "publisher": "microsoft",
      "title": "Windows NFS Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00852,
        "percentile": 0.54672
      },
      "nvd": {
        "published": "2026-07-14T18:18:29.757",
        "lastModified": "2026-07-22T16:18:27.617",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56194",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56194",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 125,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-56195",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.006Z",
      "date_published": "2026-07-14T17:09:23.166Z",
      "date_updated": "2026-08-03T22:57:43.595Z",
      "publisher": "microsoft",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30907
      },
      "nvd": {
        "published": "2026-07-14T18:18:29.937",
        "lastModified": "2026-07-16T13:40:15.753",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56195",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56195",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-56196",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.007Z",
      "date_published": "2026-07-14T17:09:23.641Z",
      "date_updated": "2026-08-03T22:57:44.220Z",
      "publisher": "microsoft",
      "title": "Windows Admin Center (WAC) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows Admin Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00954,
        "percentile": 0.57953
      },
      "nvd": {
        "published": "2026-07-14T18:18:30.070",
        "lastModified": "2026-07-24T13:38:16.307",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56196",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56196",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56197",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T13:54:04.007Z",
      "date_published": "2026-07-14T17:09:24.187Z",
      "date_updated": "2026-08-03T22:57:44.912Z",
      "publisher": "microsoft",
      "title": "Windows Admin Center (WAC) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows Admin Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0092,
        "percentile": 0.56839
      },
      "nvd": {
        "published": "2026-07-14T18:18:30.200",
        "lastModified": "2026-07-24T13:38:01.297",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56197",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Attacker-controlled command data reaches a command interpreter without safe argument separation or complete command-language neutralization.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56197",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56217",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:43:24.737Z",
      "date_published": "2026-07-08T13:48:54.936Z",
      "date_updated": "2026-07-08T14:28:35.887Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Encrypted Bundle Policy Bypass via Direct PostgREST Update",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11978
      },
      "nvd": {
        "published": "2026-07-08T14:17:15.107",
        "lastModified": "2026-07-08T15:16:30.547",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56217",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-4qwf-mrgx-mvfx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-encrypted-bundle-policy-bypass-via-direct-postgrest-update",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:43:24.737Z",
      "date_published": "2026-07-08T13:48:55.633Z",
      "date_updated": "2026-07-08T17:08:48.937Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Unauthorized Manifest Insertion via Read-Only Org Member",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10396
      },
      "nvd": {
        "published": "2026-07-08T14:17:15.277",
        "lastModified": "2026-07-08T18:16:33.370",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56220",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public.manifest INSERT policy grants read-only organization members write authority to create OTA manifest rows.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-vmgg-crr8-887p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-unauthorized-manifest-insertion-via-read-only-org-member",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 414,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:46:58.630Z",
      "date_published": "2026-07-08T13:48:56.322Z",
      "date_updated": "2026-07-08T15:50:59.980Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Unauthenticated Organization Data Disclosure via get_orgs_v6 RPC",
      "affected": {
        "vendors": [
          "Cap-go"
        ],
        "products": [
          {
            "vendor": "Cap-go",
            "product": "capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00255,
        "percentile": 0.16972
      },
      "nvd": {
        "published": "2026-07-08T14:17:15.413",
        "lastModified": "2026-07-08T17:17:25.070",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56226",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An anonymous SECURITY DEFINER RPC accepts any user UUID without binding it to the requester and returns that user's organization data.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-m7mm-35v3-82f4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-unauthenticated-organization-data-disclosure-via-get-orgs-v6-rpc",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 547,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56238",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:50:06.625Z",
      "date_published": "2026-07-12T12:06:28.923Z",
      "date_updated": "2026-07-13T14:23:57.551Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00368,
        "percentile": 0.29467
      },
      "nvd": {
        "published": "2026-07-12T12:16:44.587",
        "lastModified": "2026-07-13T17:02:40.460",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56238",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The global_stats endpoint permits unauthenticated access using only a publicly available API key.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-73rv-fpp7-r3r4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-unauthenticated-information-disclosure-via-postgrest-global-stats-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56240",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:50:06.625Z",
      "date_published": "2026-07-11T13:00:56.415Z",
      "date_updated": "2026-07-13T18:54:55.666Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Billing Authorization Bypass via Exhausted Usage Credits",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00182,
        "percentile": 0.0804
      },
      "nvd": {
        "published": "2026-07-11T14:16:20.707",
        "lastModified": "2026-07-13T19:17:22.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56240",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A divergent plan_valid expression treats exhausted or expired grants as authorized even after the authoritative billing gate denies access.",
        "basis": [
          "CNA record",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-g9fc-82c2-p2r6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-billing-authorization-bypass-via-exhausted-usage-credits",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56241",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:50:06.625Z",
      "date_published": "2026-07-12T12:06:29.581Z",
      "date_updated": "2026-07-14T14:43:46.193Z",
      "publisher": "VulnCheck",
      "title": "Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11418
      },
      "nvd": {
        "published": "2026-07-12T12:16:44.730",
        "lastModified": "2026-07-14T15:17:04.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56241",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Deleting a super-admin role binding leaves the stale user_right value intact, so the demoted user retains organization-wide RPC access.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-rvvc-rvxv-qcrh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-rbac-demotion-privilege-retention-via-stale-org-users-user-right",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:53:16.001Z",
      "date_published": "2026-07-08T13:48:57.049Z",
      "date_updated": "2026-07-08T14:23:48.803Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Cross-Organization Authorization Bypass via Scoped API Key Privilege Inheritance",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00223,
        "percentile": 0.12948
      },
      "nvd": {
        "published": "2026-07-08T14:17:15.543",
        "lastModified": "2026-07-08T15:16:30.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56246",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Route authorization evaluates an API key owner's user privileges before enforcing the key's limited_to_orgs scope.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-ccm4-hf72-p28m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-cross-organization-authorization-bypass-via-scoped-api-key-privilege-inheritance",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 657,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56250",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:53:16.001Z",
      "date_published": "2026-07-08T13:48:57.743Z",
      "date_updated": "2026-07-08T14:23:22.128Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Arbitrary R2 Object Deletion via Mutable r2_path in app_versions",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00258,
        "percentile": 0.1735
      },
      "nvd": {
        "published": "2026-07-08T14:17:15.673",
        "lastModified": "2026-07-08T15:16:30.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56250",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Capgo lets an upload-scoped key retarget app_versions.r2_path to another tenant's object before cleanup deletes that object.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-pw8p-5jg6-cxj3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-arbitrary-r2-object-deletion-via-mutable-r2-path-in-app-versions",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 418,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:56:09.655Z",
      "date_published": "2026-07-12T12:06:30.257Z",
      "date_updated": "2026-07-13T16:15:27.298Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Scope Isolation Failure in Webhook Test Endpoint",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.00169,
        "percentile": 0.0655
      },
      "nvd": {
        "published": "2026-07-12T12:16:44.867",
        "lastModified": "2026-07-13T17:17:37.627",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56252",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Capgo's webhook test endpoint accepts an app-scoped API key for organization-scoped webhooks without enforcing limited_to_apps.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-qvr7-f6j6-64wp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-scope-isolation-failure-in-webhook-test-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56254",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:56:09.655Z",
      "date_published": "2026-07-10T13:57:52.184Z",
      "date_updated": "2026-07-10T15:17:16.881Z",
      "publisher": "VulnCheck",
      "title": "capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution",
      "affected": {
        "vendors": [
          "capacitor-updater"
        ],
        "products": [
          {
            "vendor": "capacitor-updater",
            "product": "capacitor-updater"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-320",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00151,
        "percentile": 0.04816
      },
      "nvd": {
        "published": "2026-07-10T15:16:41.810",
        "lastModified": "2026-07-10T16:16:33.713",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56254",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The update scheme distributes its signing private key to every device, allowing a server or on-path compromise to sign attacker-created update bundles.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-320"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-j2f4-4pfc-p8rx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capacitor-updater-end-to-end-encryption-bypass-via-private-key-distribution",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56259",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:56:09.656Z",
      "date_published": "2026-07-12T12:06:30.919Z",
      "date_updated": "2026-07-14T21:34:08.713Z",
      "publisher": "VulnCheck",
      "title": "Crawl4AI - LLM Credential Exfiltration via base_url and Environment Variable Resolution",
      "affected": {
        "vendors": [
          "Crawl4AI"
        ],
        "products": [
          {
            "vendor": "Crawl4AI",
            "product": "Crawl4AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.00308,
        "percentile": 0.2308
      },
      "nvd": {
        "published": "2026-07-12T12:16:45.013",
        "lastModified": "2026-07-14T18:29:21.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56259",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Crawl4AI Docker API accepts an attacker-selected base_url for LLM calls and sends environment-held API credentials to that destination.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/unclecode/crawl4ai/security/advisories/GHSA-f989-c77f-r2cq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/crawl4ai-llm-credential-exfiltration-via-base-url-and-environment-variable-resolution",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 483,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56260",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:56:09.656Z",
      "date_published": "2026-07-12T12:06:31.568Z",
      "date_updated": "2026-07-14T21:34:09.393Z",
      "publisher": "VulnCheck",
      "title": "Crawl4AI - Arbitrary File Write via output_path Parameter",
      "affected": {
        "vendors": [
          "Crawl4AI"
        ],
        "products": [
          {
            "vendor": "Crawl4AI",
            "product": "Crawl4AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.29999999999999893,
      "epss": {
        "score": 0.00421,
        "percentile": 0.34687
      },
      "nvd": {
        "published": "2026-07-12T12:16:45.153",
        "lastModified": "2026-07-14T18:25:42.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56260",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Docker API screenshot and PDF endpoints accept output_path without validation, allowing absolute or traversal paths to write outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/unclecode/crawl4ai/security/advisories/GHSA-365w-hqf6-vxfg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/unclecode/crawl4ai",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/crawl4ai-arbitrary-file-write-via-output-path-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56261",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-19T21:56:09.656Z",
      "date_published": "2026-07-10T13:57:52.897Z",
      "date_updated": "2026-07-14T21:34:10.071Z",
      "publisher": "VulnCheck",
      "title": "Crawl4AI - Server-Side Request Forgery via Webhook URLs",
      "affected": {
        "vendors": [
          "Crawl4AI"
        ],
        "products": [
          {
            "vendor": "Crawl4AI",
            "product": "Crawl4AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29889
      },
      "nvd": {
        "published": "2026-07-10T15:16:42.017",
        "lastModified": "2026-07-13T15:21:04.963",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56261",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crawl4AI accepts webhook URLs without destination validation and sends server-side requests to internal or metadata addresses.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/unclecode/crawl4ai/security/advisories/GHSA-365w-hqf6-vxfg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/unclecode/crawl4ai",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/crawl4ai-server-side-request-forgery-via-webhook-urls",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 445,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56271",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T01:47:54.000Z",
      "date_published": "2026-07-12T12:06:32.246Z",
      "date_updated": "2026-07-13T15:41:09.159Z",
      "publisher": "VulnCheck",
      "title": "Flowise - Weak Default JWT Secrets in Authentication Middleware",
      "affected": {
        "vendors": [
          "Flowise"
        ],
        "products": [
          {
            "vendor": "Flowise",
            "product": "Flowise"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-321",
          "name": "Use of Hard-coded Cryptographic Key",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00376,
        "percentile": 0.30324
      },
      "nvd": {
        "published": "2026-07-12T12:16:45.290",
        "lastModified": "2026-07-14T18:24:59.487",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56271",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts).",
        "basis": [
          "CNA",
          "CWE-321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-cc4f-hjpj-g9p8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/flowise-weak-default-jwt-secrets-in-authentication-middleware",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 642,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56273",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T01:47:54.000Z",
      "date_published": "2026-07-08T13:48:58.446Z",
      "date_updated": "2026-07-09T13:34:57.997Z",
      "publisher": "VulnCheck",
      "title": "Flowise - Path Traversal in Vector Store basePath Parameter",
      "affected": {
        "vendors": [
          "Flowise"
        ],
        "products": [
          {
            "vendor": "Flowise",
            "product": "Flowise"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.0033,
        "percentile": 0.2551
      },
      "nvd": {
        "published": "2026-07-08T14:17:15.800",
        "lastModified": "2026-07-09T15:16:37.727",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56273",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Flowise joins an authenticated user basePath into Faiss and SimpleStore paths without containing it under the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-w6v6-49gh-mc9w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/flowise-path-traversal-in-vector-store-basepath-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-56279",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T01:51:24.919Z",
      "date_published": "2026-07-10T13:57:53.609Z",
      "date_updated": "2026-07-10T14:44:47.363Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23684
      },
      "nvd": {
        "published": "2026-07-10T15:16:42.157",
        "lastModified": "2026-07-10T16:16:33.963",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56279",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-fch8-pp28-mw2x",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-information-disclosure-via-get-orgs-v7-rpc-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56281",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T01:51:24.919Z",
      "date_published": "2026-07-12T12:06:32.940Z",
      "date_updated": "2026-07-13T14:21:17.138Z",
      "publisher": "VulnCheck",
      "title": "Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09712
      },
      "nvd": {
        "published": "2026-07-12T12:16:45.433",
        "lastModified": "2026-07-13T17:02:40.460",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56281",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-6ffx-8hjj-jhhf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-sql-injection-via-unvalidated-limit-parameter-in-admin-stats-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56283",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T01:51:24.919Z",
      "date_published": "2026-07-08T13:48:59.142Z",
      "date_updated": "2026-07-08T14:27:40.018Z",
      "publisher": "VulnCheck",
      "title": "Capgo - HTML Injection Leading to Open Redirection in Organization Settings",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00138,
        "percentile": 0.0364
      },
      "nvd": {
        "published": "2026-07-08T14:17:15.970",
        "lastModified": "2026-07-08T15:16:30.887",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56283",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-vhvc-gxfh-m85g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-html-injection-leading-to-open-redirection-in-organization-settings",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56284",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T01:51:24.919Z",
      "date_published": "2026-07-08T13:48:59.885Z",
      "date_updated": "2026-07-08T17:08:38.955Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Unauthenticated Metrics Disclosure via get_total_metrics RPC",
      "affected": {
        "vendors": [
          "Cap-go"
        ],
        "products": [
          {
            "vendor": "Cap-go",
            "product": "capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00214,
        "percentile": 0.1188
      },
      "nvd": {
        "published": "2026-07-08T14:17:16.100",
        "lastModified": "2026-07-08T18:16:33.487",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56284",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The get_total_metrics RPC is callable by the anonymous role and returns organization usage data for a supplied organization UUID.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-h5jf-xgvh-hgjw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-unauthenticated-metrics-disclosure-via-get-total-metrics-rpc",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 466,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56287",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T06:45:41.509Z",
      "date_published": "2026-07-15T09:19:38.262Z",
      "date_updated": "2026-07-15T14:32:08.722Z",
      "publisher": "apache",
      "title": "Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Fineract"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00469,
        "percentile": 0.38141
      },
      "nvd": {
        "published": "2026-07-15T10:16:47.507",
        "lastModified": "2026-07-15T20:15:42.117",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56287",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The client search API concatenates orderBy and sortOrder into SQL without sufficient identifier validation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/l5klcj2v0dx63bssvb0gmw1nzzc47col",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/apache/fineract/pull/6020",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/15/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 625,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56288",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T10:58:09.261Z",
      "date_published": "2026-07-09T09:29:07.947Z",
      "date_updated": "2026-07-09T12:57:48.785Z",
      "publisher": "CERT-PL",
      "title": "NULL Pointer Dereference in GNU patch",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "patch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01798
      },
      "nvd": {
        "published": "2026-07-09T11:16:40.713",
        "lastModified": "2026-07-13T14:08:47.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56288",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Consecutive end-of-file newline markers corrupt GNU patch's hunk state and lead it to pass a null pointer to fwrite.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56288",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/patch.git/",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Product",
            "product"
          ]
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=e6d6a4e021660679d7fc9150f981d4920f722313",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 555,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56289",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T10:58:09.261Z",
      "date_published": "2026-07-09T09:29:22.467Z",
      "date_updated": "2026-07-09T12:21:39.125Z",
      "publisher": "CERT-PL",
      "title": "Loop with Unreachable Exit Condition in GNU patch",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "patch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01798
      },
      "nvd": {
        "published": "2026-07-09T11:16:40.840",
        "lastModified": "2026-07-13T14:10:56.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56289",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A unified-diff hunk can claim an extremely large line offset that keeps GNU patch searching in a loop with no reachable completion condition.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56288",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/patch.git/",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "product"
          ]
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=faba04ef4f2b410257f76c1b9dc85e350929c4b9",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 669,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56291",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T11:57:32.752Z",
      "date_published": "2026-07-09T09:53:57.886Z",
      "date_updated": "2026-07-23T14:55:16.620Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "balbooa.com Balbooa Forms extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.76066,
        "percentile": 0.99483
      },
      "official_kev": {
        "cveID": "CVE-2026-56291",
        "vendorProject": "Balbooa",
        "product": "Forms",
        "vulnerabilityName": "Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability",
        "dateAdded": "2026-07-10",
        "shortDescription": "Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-07-13",
        "knownRansomwareCampaignUse": "Unknown",
        "notes": "https://www.balbooa.com/joomla-forms ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-56291",
        "cwes": [
          "CWE-434"
        ]
      },
      "nvd": {
        "published": "2026-07-09T11:16:40.990",
        "lastModified": "2026-07-24T13:30:37.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56291",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Balbooa Forms upload path accepts executable files from an unauthenticated requester.",
        "basis": [
          "CNA",
          "CWE-434",
          "Balbooa product page",
          "CISA KEV embedded status"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.balbooa.com/joomla-forms. The page is product material without an advisory or patch diff; the linked CISA catalog endpoint did not return inspectable catalog content, so KEV status comes from the embedded CISA field, while the upload mechanism and version boundary remain supported by the CNA record."
      },
      "references": [
        {
          "url": "https://www.balbooa.com/joomla-forms",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56291",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56292",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T11:57:32.752Z",
      "date_published": "2026-07-09T13:49:39.916Z",
      "date_updated": "2026-07-23T14:59:47.603Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1",
      "affected": {
        "vendors": [
          "acymailing.com"
        ],
        "products": [
          {
            "vendor": "acymailing.com",
            "product": "acymailing.com AcyMailing extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23516
      },
      "nvd": {
        "published": "2026-07-09T15:16:37.937",
        "lastModified": "2026-07-23T16:17:26.990",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56292",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AcyMailing incorporates attacker-controlled data into an SQL query without parameter separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.acymailing.com/",
          "host": "www.acymailing.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/acymailing-sql-injection-disclosure/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 247,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56293",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:49:17.829Z",
      "date_published": "2026-07-08T13:49:00.600Z",
      "date_updated": "2026-07-08T15:48:18.809Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Stale Cross-Organization Authorization via Incomplete deploy_history Update in transfer_app()",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04075
      },
      "nvd": {
        "published": "2026-07-08T14:17:16.230",
        "lastModified": "2026-07-08T17:17:25.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56293",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Application transfer updates the owning organization but leaves deploy_history.owner_org stale, preserving access under the prior tenant state.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-854w-xj7g-prv3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-stale-cross-organization-authorization-via-incomplete-deploy-history-update-in-transfer-app",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 393,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56296",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:49:17.829Z",
      "date_published": "2026-07-11T13:00:57.100Z",
      "date_updated": "2026-07-13T15:19:17.614Z",
      "publisher": "VulnCheck",
      "title": "Cap-go - App Existence Oracle via Unauthenticated transfer_app RPC",
      "affected": {
        "vendors": [
          "Cap-go"
        ],
        "products": [
          {
            "vendor": "Cap-go",
            "product": "capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-203",
          "name": "Observable Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15068
      },
      "nvd": {
        "published": "2026-07-11T14:16:21.683",
        "lastModified": "2026-07-13T18:12:29.917",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56296",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "capgo returns distinguishable responses for existing and non-existing objects, allowing an unauthenticated caller to use the difference as an enumeration oracle.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-203"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-fmm3-3qcg-85j6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cap-go-app-existence-oracle-via-unauthenticated-transfer-app-rpc",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56297",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:49:17.829Z",
      "date_published": "2026-07-08T13:49:01.343Z",
      "date_updated": "2026-07-08T14:23:00.749Z",
      "publisher": "VulnCheck",
      "title": "FreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel Callback",
      "affected": {
        "vendors": [
          "FreeRDP"
        ],
        "products": [
          {
            "vendor": "FreeRDP",
            "product": "FreeRDP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28785
      },
      "nvd": {
        "published": "2026-07-08T14:17:16.360",
        "lastModified": "2026-07-10T14:36:57.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56297",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent DRDYNVC data and close handling accesses channel_callback after dvcman_channel_close has freed it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3mv2-5q57-2v8h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/freerdp-use-after-free-via-race-condition-in-drdynvc-channel-callback",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 411,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56298",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:49:17.830Z",
      "date_published": "2026-07-08T13:49:02.073Z",
      "date_updated": "2026-07-08T14:30:56.532Z",
      "publisher": "VulnCheck",
      "title": "Capgo - EXIF Metadata Exposure in App Information Image Upload",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08543
      },
      "nvd": {
        "published": "2026-07-08T14:17:16.493",
        "lastModified": "2026-07-08T15:16:31.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56298",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Capgo republishes uploaded images without removing EXIF metadata, leaving embedded location and device data available to later readers.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-62jm-xp28-x4xw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-exif-metadata-exposure-in-app-information-image-upload",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56303",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:53:19.893Z",
      "date_published": "2026-07-11T13:00:57.777Z",
      "date_updated": "2026-07-13T16:11:08.264Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22503
      },
      "nvd": {
        "published": "2026-07-11T14:16:21.820",
        "lastModified": "2026-07-13T17:17:38.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56303",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A SECURITY DEFINER database function containing API-key metadata is executable by the anonymous role through a public RPC endpoint.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-2xjq-h43m-592f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-unauthenticated-api-key-metadata-disclosure-via-security-definer-rpc-function",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 408,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56305",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:53:19.893Z",
      "date_published": "2026-07-10T13:57:54.294Z",
      "date_updated": "2026-07-14T01:44:08.466Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Authentication Bypass in Password Change via Missing Current Password Validation",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-620",
          "name": "Unverified Password Change",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0.3999999999999986,
      "epss": {
        "score": 0.00357,
        "percentile": 0.28382
      },
      "nvd": {
        "published": "2026-07-10T15:16:42.300",
        "lastModified": "2026-07-14T02:16:56.633",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56305",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Capgo changes an account password for a session holder without requiring proof of the current password.",
        "basis": [
          "CNA",
          "CWE-620"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-rjr5-qxqj-cx8g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-authentication-bypass-in-password-change-via-missing-current-password-validation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56308",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:53:19.893Z",
      "date_published": "2026-07-12T12:06:33.602Z",
      "date_updated": "2026-07-14T14:45:07.642Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Insufficient Authentication in Email Change Endpoint",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15696
      },
      "nvd": {
        "published": "2026-07-12T12:16:45.567",
        "lastModified": "2026-07-14T15:17:05.250",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56308",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Capgo lets a session holder replace the account email without proving the current password or control of the existing email address.",
        "basis": [
          "CNA",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-9px4-w25f-mvm4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-insufficient-authentication-in-email-change-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:53:19.893Z",
      "date_published": "2026-07-10T13:57:54.973Z",
      "date_updated": "2026-07-10T15:12:54.376Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17497
      },
      "nvd": {
        "published": "2026-07-10T15:16:42.440",
        "lastModified": "2026-07-10T16:16:34.070",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56309",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The attachment upload endpoint omits plan and quota checks, permitting upload-scoped keys to create persistent public objects outside normal bundle accounting.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-q52j-ggvx-cr4v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-plan-bypass-via-unrestricted-attachment-upload-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 373,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56312",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:53:19.893Z",
      "date_published": "2026-07-10T13:57:55.606Z",
      "date_updated": "2026-07-10T17:01:05.178Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19646
      },
      "nvd": {
        "published": "2026-07-10T15:16:42.587",
        "lastModified": "2026-07-10T17:17:00.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56312",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha validation is enforced.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-whc5-fvr7-g5v3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-account-creation-before-captcha-validation-in-accept-invitation-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56313",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T12:59:07.917Z",
      "date_published": "2026-07-12T12:06:34.266Z",
      "date_updated": "2026-07-13T16:01:22.299Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19833
      },
      "nvd": {
        "published": "2026-07-12T12:16:45.703",
        "lastModified": "2026-07-13T17:17:39.603",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56313",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SSO prelink operation applies a provider's email-domain match to users in other organizations without tenant scoping.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-x3vq-34gg-cwq7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-cross-organization-account-disruption-via-sso-prelink-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56329",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:06:29.994Z",
      "date_published": "2026-07-10T13:57:56.297Z",
      "date_updated": "2026-07-10T15:45:22.401Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore Decoding",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14788
      },
      "nvd": {
        "published": "2026-07-10T15:16:42.727",
        "lastModified": "2026-07-10T17:17:00.643",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56329",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Preview hostnames decode double underscores to dots non-bijectively, letting two distinct tenant application IDs resolve to the same preview namespace.",
        "basis": [
          "CNA",
          "CWE-436"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-76qq-gg2p-pwwj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-cross-tenant-preview-namespace-collision-via-non-bijective-underscore-decoding",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56335",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:13:56.012Z",
      "date_published": "2026-07-10T13:57:56.947Z",
      "date_updated": "2026-07-10T14:56:52.599Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Channel Configuration Mutation via Write-Scoped API Keys",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21796
      },
      "nvd": {
        "published": "2026-07-10T15:16:42.880",
        "lastModified": "2026-07-10T16:16:34.187",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56335",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-ph9c-vwjq-pqhj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-channel-configuration-mutation-via-write-scoped-api-keys",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:13:56.012Z",
      "date_published": "2026-07-12T12:06:34.915Z",
      "date_updated": "2026-07-14T14:33:45.176Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint",
      "affected": {
        "vendors": [
          "Capgo"
        ],
        "products": [
          {
            "vendor": "Capgo",
            "product": "Capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10682
      },
      "nvd": {
        "published": "2026-07-12T12:16:45.837",
        "lastModified": "2026-07-14T15:17:05.360",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56336",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The unauthenticated SSO domain-check endpoint returns internal organization and provider identifiers for an enumerable email domain.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-c5jf-5wxg-mgrq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-information-disclosure-via-unauthenticated-sso-check-domain-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56339",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T13:13:56.012Z",
      "date_published": "2026-07-15T11:25:27.297Z",
      "date_updated": "2026-07-15T18:38:40.103Z",
      "publisher": "VulnCheck",
      "title": "Capgo - Unauthenticated Organization Existence Enumeration via rescind_invitation RPC",
      "affected": {
        "vendors": [
          "Cap-go"
        ],
        "products": [
          {
            "vendor": "Cap-go",
            "product": "capgo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-203",
          "name": "Observable Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19832
      },
      "nvd": {
        "published": "2026-07-15T12:18:02.140",
        "lastModified": "2026-07-15T20:27:37.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56339",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The invitation RPC returns distinguishable NO_ORG and NO_RIGHTS errors that reveal whether a supplied organization identifier exists.",
        "basis": [
          "CNA",
          "CWE-203"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Cap-go/capgo/security/advisories/GHSA-8432-3cgm-vw5j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/capgo-unauthenticated-organization-existence-enumeration-via-rescind-invitation-rpc",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 495,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T18:13:07.363Z",
      "date_published": "2026-07-15T11:25:27.992Z",
      "date_updated": "2026-07-15T12:42:58.824Z",
      "publisher": "VulnCheck",
      "title": "n8n - Guardrail Node Bypass via Crafted Input",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.26997
      },
      "nvd": {
        "published": "2026-07-15T12:18:02.297",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56349",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Crafted input bypasses a guardrail around interpreted content, but the public record does not disclose the parser or failed grammar rule.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-fvfv-ppw4-7h2w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-guardrail-node-bypass-via-crafted-input",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T18:13:07.364Z",
      "date_published": "2026-07-15T11:25:28.663Z",
      "date_updated": "2026-07-15T13:49:30.931Z",
      "publisher": "VulnCheck",
      "title": "n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16235
      },
      "nvd": {
        "published": "2026-07-15T12:18:02.433",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56352",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The legacy ExecuteWorkflow localFile option reads a caller-supplied path without applying the configured file-access confinement.",
        "basis": [
          "CNA record",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-2vx9-7wpg-88jq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-arbitrary-file-read-and-execution-via-executeworkflow-localfile-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 629,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-56353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T18:13:07.364Z",
      "date_published": "2026-07-15T11:25:29.334Z",
      "date_updated": "2026-07-16T15:14:09.641Z",
      "publisher": "VulnCheck",
      "title": "n8n - Authentication Bypass in Chat Trigger Node",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00231,
        "percentile": 0.1406
      },
      "nvd": {
        "published": "2026-07-15T12:18:02.580",
        "lastModified": "2026-07-16T20:09:02.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56353",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that n8n permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-jh8h-6c9q-7gmw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-authentication-bypass-in-chat-trigger-node",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 375,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-56354",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T18:13:07.364Z",
      "date_published": "2026-07-10T13:57:57.614Z",
      "date_updated": "2026-07-10T16:42:43.575Z",
      "publisher": "VulnCheck",
      "title": "n8n - Cross-Site Scripting and Open Redirect in Form Node",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 10,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06527
      },
      "nvd": {
        "published": "2026-07-10T15:16:43.030",
        "lastModified": "2026-07-13T16:54:48.843",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56354",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Form Node stores unsanitized HTML descriptions under an iframe policy that permits the content to execute script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-w673-8fjw-457c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-cross-site-scripting-and-open-redirect-in-form-node",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 422,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-56359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T21:16:53.711Z",
      "date_published": "2026-07-08T13:49:02.746Z",
      "date_updated": "2026-07-09T13:37:23.855Z",
      "publisher": "VulnCheck",
      "title": "n8n - Cross-Site Scripting in Credential Management OAuth2 Authorization URL",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03919
      },
      "nvd": {
        "published": "2026-07-08T14:17:16.620",
        "lastModified": "2026-07-09T15:16:38.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56359",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In n8n, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-364x-8g5j-x2pr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-cross-site-scripting-in-credential-management-oauth2-authorization-url",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-56360",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T21:16:53.711Z",
      "date_published": "2026-07-08T13:49:03.453Z",
      "date_updated": "2026-07-08T14:26:33.242Z",
      "publisher": "VulnCheck",
      "title": "n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08376
      },
      "nvd": {
        "published": "2026-07-08T14:17:16.757",
        "lastModified": "2026-07-08T19:32:49.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56360",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ZendeskTrigger handler accepts webhook bodies without verifying the sender's HMAC-SHA256 signature.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-38c7-23hj-2wgq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-webhook-forgery-via-unsigned-post-requests-in-zendesktrigger",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-56362",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-20T21:16:53.711Z",
      "date_published": "2026-07-08T13:49:04.142Z",
      "date_updated": "2026-07-08T17:08:28.947Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick - Heap-buffer-overflow Read in GetPixelIndex via OpenPixelCache Metadata Desynchronization",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 2.1,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08718
      },
      "nvd": {
        "published": "2026-07-08T14:17:16.887",
        "lastModified": "2026-07-10T18:27:38.870",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56362",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenPixelCache updates channel metadata before allocating matching pixel-cache storage, leaving GetPixelIndex to read using metadata that no longer matches the heap buffer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gq5v-qf8q-fp77",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-heap-buffer-overflow-read-in-getpixelindex-via-openpixelcache-metadata-desynchronization",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-56366",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-21T02:05:21.919Z",
      "date_published": "2026-07-10T13:57:58.303Z",
      "date_updated": "2026-07-14T01:45:51.729Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick - Memory Leak in META Reader APP1JPEG Error Path",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 3.2,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06589
      },
      "nvd": {
        "published": "2026-07-10T15:16:43.217",
        "lastModified": "2026-07-14T02:16:56.757",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56366",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ImageMagick error or repeat path acquires memory without releasing it, allowing attacker-driven resource exhaustion.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9r56-3gjq-hqf7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-meta-reader-app1jpeg-error-path",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-56372",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-21T02:05:21.920Z",
      "date_published": "2026-07-11T13:00:58.423Z",
      "date_updated": "2026-07-13T14:34:41.530Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 5.8,
      "epss": {
        "score": 0.00198,
        "percentile": 0.0982
      },
      "nvd": {
        "published": "2026-07-11T14:16:21.953",
        "lastModified": "2026-07-13T22:18:43.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56372",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A memory-safety defect permits invalid access beyond an object's bounds or lifetime.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8vfj-q2cp-5m5j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-heap-buffer-overflow-read-via-unrecognized-magnify-method",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56373",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-21T02:05:21.920Z",
      "date_published": "2026-07-10T13:57:58.981Z",
      "date_updated": "2026-07-10T15:06:42.233Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick - Use-After-Free Write in PDB Decoder",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13996
      },
      "nvd": {
        "published": "2026-07-10T15:16:43.450",
        "lastModified": "2026-07-13T15:15:51.143",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56373",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ImageMagick path retains or dereferences an object after the object's storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3j4x-rwrx-xxj9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-use-after-free-write-in-pdb-decoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-56374",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-21T02:05:21.920Z",
      "date_published": "2026-07-08T13:49:04.868Z",
      "date_updated": "2026-07-08T15:46:51.394Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick - Heap Buffer Overflow in FTXT Encoder via format Parameter",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05371
      },
      "nvd": {
        "published": "2026-07-08T14:17:17.037",
        "lastModified": "2026-07-09T14:51:05.950",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56374",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick's FTXT decoder reads beyond an allocated buffer while processing crafted image data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-w54j-7wpm-crhj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-heap-buffer-overflow-in-ftxt-encoder-via-format-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56375",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-21T02:05:21.920Z",
      "date_published": "2026-07-15T11:25:30.028Z",
      "date_updated": "2026-07-15T12:21:07.011Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick - Memory Leak in ASHLAR Coder Action Failure",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00111,
        "percentile": 0.01533
      },
      "nvd": {
        "published": "2026-07-15T12:18:02.727",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56375",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6p22-q7w5-33pg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-ashlar-coder-action-failure",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-21T07:15:13.879Z",
      "date_published": "2026-07-29T09:39:52.243Z",
      "date_updated": "2026-07-29T12:21:04.442Z",
      "publisher": "CERT-PL",
      "title": "Arbitrary Command Execution in GNU Bison",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "Bison"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05072
      },
      "nvd": {
        "published": "2026-07-29T11:16:49.767",
        "lastModified": "2026-07-30T16:28:33.633",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56389",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A Bison grammar can replace the XSLT executable through tool.xsltproc, and bison passes that value directly to execvp.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56389",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/bison.git/",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=3169c1e7a2c6acc4c59dfcf8b089896d6881925b",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 812,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-21T07:15:13.879Z",
      "date_published": "2026-07-29T09:40:03.213Z",
      "date_updated": "2026-07-29T12:15:19.804Z",
      "publisher": "CERT-PL",
      "title": "Arbitrary Output Location Change in GNU Bison",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "Bison"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03227
      },
      "nvd": {
        "published": "2026-07-29T11:16:49.910",
        "lastModified": "2026-07-30T16:28:33.633",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56390",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56389",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/bison.git/",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=8d101c19d4d9aaedf83a448c925513742d4efcf0",
          "host": "cgit.git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 744,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-21T11:40:32.790Z",
      "date_published": "2026-07-24T07:44:45.581Z",
      "date_updated": "2026-07-24T12:31:34.245Z",
      "publisher": "CERT-PL",
      "title": "Out‑of‑bounds Read in GNU coreutils",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "coreutils"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.0336
      },
      "nvd": {
        "published": "2026-07-24T09:16:25.003",
        "lastModified": "2026-07-30T16:28:33.633",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56391",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "coreutils can read beyond the valid bounds of an input or object allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/",
          "host": "git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371",
          "host": "git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 706,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-21T11:40:32.790Z",
      "date_published": "2026-07-24T07:44:54.885Z",
      "date_updated": "2026-07-24T12:32:14.074Z",
      "publisher": "CERT-PL",
      "title": "Heap-based Buffer Overflow in GNU coreutils",
      "affected": {
        "vendors": [
          "GNU"
        ],
        "products": [
          {
            "vendor": "GNU",
            "product": "coreutils"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 1.8,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 1.8,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 1.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04559
      },
      "nvd": {
        "published": "2026-07-24T09:16:25.147",
        "lastModified": "2026-07-30T16:28:33.633",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56392",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is written beyond the boundary of a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-56391",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/",
          "host": "git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d",
          "host": "git.savannah.gnu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 679,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-21T12:37:58.435Z",
      "date_published": "2026-07-15T11:25:30.722Z",
      "date_updated": "2026-07-15T13:25:55.678Z",
      "publisher": "VulnCheck",
      "title": "Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.7000000000000002,
      "epss": {
        "score": 0.00416,
        "percentile": 0.34273
      },
      "nvd": {
        "published": "2026-07-15T12:18:02.870",
        "lastModified": "2026-07-16T20:03:37.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56398",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Open WebUI infers an OAuth profile image type from its URL extension, allowing active SVG content to be stored and served inline on the application origin.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-3wgj-c2hg-vm6q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/open-webui-stored-cross-site-scripting-via-oauth-picture-claim-svg-data-uri",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-21T12:37:58.435Z",
      "date_published": "2026-07-15T11:25:31.421Z",
      "date_updated": "2026-07-15T18:33:15.579Z",
      "publisher": "VulnCheck",
      "title": "open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 1.299999999999999,
      "epss": {
        "score": 0.00348,
        "percentile": 0.2744
      },
      "nvd": {
        "published": "2026-07-15T12:18:03.017",
        "lastModified": "2026-07-16T20:03:11.553",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56400",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The functions API permits credentialed requests from arbitrary origins, allowing a malicious site to invoke an administrator's code-execution capability.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-6xcp-7mpr-m7wm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/open-webui-remote-code-execution-via-cors-misconfiguration-and-session-validation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56401",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-06-21T12:37:58.435Z",
      "date_published": "2026-07-08T13:49:05.553Z",
      "date_rejected": "2026-07-15T11:42:41.971Z",
      "date_updated": "2026-07-15T11:42:41.971Z",
      "publisher": "VulnCheck",
      "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
      "rejected_reason": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority."
    },
    {
      "cve_id": "CVE-2026-56416",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:27:22.810Z",
      "date_published": "2026-07-22T13:10:24.023Z",
      "date_updated": "2026-07-22T14:00:45.744Z",
      "publisher": "NLnet Labs",
      "title": "Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-354",
          "name": "Improper Validation of Integrity Check Value",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01975
      },
      "nvd": {
        "published": "2026-07-22T14:17:22.090",
        "lastModified": "2026-07-24T14:25:29.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56416",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unbound accepts signed multi-name RDATA that omits its second domain name and then walks stale scratch-buffer bytes beyond the allocation.",
        "basis": [
          "CNA",
          "CWE-354"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-56416.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 954,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T10:55:30.996Z",
      "date_published": "2026-07-30T13:11:11.395Z",
      "date_updated": "2026-07-30T15:10:44.082Z",
      "publisher": "bosch",
      "title": "The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration.",
      "affected": {
        "vendors": [
          "Bosch"
        ],
        "products": [
          {
            "vendor": "Bosch",
            "product": "BSH ELP (Electronic Platform) Modules"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-286",
          "name": "Incorrect User Management",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@bosch.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20635
      },
      "nvd": {
        "published": "2026-07-30T14:16:59.780",
        "lastModified": "2026-07-30T16:45:56.833",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56428",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Firmware installs a fixed, non-revocable SSH public key in root's authorized_keys, so possession of the matching private key authenticates as root.",
        "basis": [
          "CNA",
          "CWE-286"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://psirt.bosch.com/security-advisories/BOSCH-SA-943700.html",
          "host": "psirt.bosch.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:49:43.050Z",
      "date_published": "2026-07-15T14:33:46.142Z",
      "date_updated": "2026-07-15T18:10:54.402Z",
      "publisher": "f5",
      "title": "NGINX ngx_http_ssi_module vulnerability",
      "affected": {
        "vendors": [
          "F5"
        ],
        "products": [
          {
            "vendor": "F5",
            "product": "NGINX Plus"
          },
          {
            "vendor": "F5",
            "product": "NGINX Open Source"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 1.8000000000000007,
      "epss": {
        "score": 0.0045,
        "percentile": 0.36954
      },
      "nvd": {
        "published": "2026-07-15T15:16:45.700",
        "lastModified": "2026-07-15T19:18:04.890",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56434",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The NGINX Plus path can dereference an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://my.f5.com/manage/s/article/K000162098",
          "host": "my.f5.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 822,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-56437",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-28T23:50:03.147Z",
      "date_published": "2026-07-08T04:38:08.120Z",
      "date_updated": "2026-07-08T13:00:01.648Z",
      "publisher": "jpcert",
      "title": "Uncontrolled search path element issue exists in Pupsman versions prior to 3.",
      "affected": {
        "vendors": [
          "Fuji Electric Co.,Ltd."
        ],
        "products": [
          {
            "vendor": "Fuji Electric Co.,Ltd.",
            "product": "Pupsman"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03333
      },
      "nvd": {
        "published": "2026-07-08T06:16:22.733",
        "lastModified": "2026-07-08T15:07:37.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56437",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Pupsman installer loads a same-directory DLL before a trusted library location and can run it as SYSTEM.",
        "basis": [
          "CNA",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.fujielectric.co.jp/products/power_supply/ups/product_detail/software_pupsman.html",
          "host": "www.fujielectric.co.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jvn.jp/en/jp/JVN62347140/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56444",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T12:35:21.345Z",
      "date_published": "2026-07-22T13:10:34.229Z",
      "date_updated": "2026-07-22T13:58:09.702Z",
      "publisher": "NLnet Labs",
      "title": "Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration",
      "affected": {
        "vendors": [
          "NLnet Labs"
        ],
        "products": [
          {
            "vendor": "NLnet Labs",
            "product": "Unbound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-772",
          "name": "Missing Release of Resource after Effective Lifetime",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:sep@nlnetlabs.nl",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14838
      },
      "nvd": {
        "published": "2026-07-22T14:17:22.203",
        "lastModified": "2026-07-24T13:43:15.783",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56444",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A serve-expired discard branch drops a reply without decrementing its reply-address counter, eventually blocking new duplicate-query clients.",
        "basis": [
          "CNA",
          "CWE-772"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-56444.txt",
          "host": "www.nlnetlabs.nl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 957,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56451",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:17:54.241Z",
      "date_published": "2026-07-14T09:19:18.322Z",
      "date_updated": "2026-07-14T14:30:15.376Z",
      "publisher": "siemens",
      "title": "A vulnerability has been identified in Opcenter X (All versions < V2604).",
      "affected": {
        "vendors": [
          "Siemens"
        ],
        "products": [
          {
            "vendor": "Siemens",
            "product": "Opcenter X"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:H/SA:H"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:productcert@siemens.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22848
      },
      "nvd": {
        "published": "2026-07-14T10:16:33.287",
        "lastModified": "2026-07-15T20:27:37.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56451",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Opcenter X trusts the JWT algorithm named by the untrusted token header instead of restricting verification to an approved algorithm, allowing an attacker to forge a token that passes authentication.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-096828.html",
          "host": "cert-portal.siemens.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56452",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:31:17.496Z",
      "date_published": "2026-07-20T20:26:28.301Z",
      "date_updated": "2026-07-21T17:15:49.562Z",
      "publisher": "apache",
      "title": "Apache MINA SSHD: Path traversal in SCP file reception",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache MINA SSHD"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00569,
        "percentile": 0.43898
      },
      "nvd": {
        "published": "2026-07-20T21:16:48.820",
        "lastModified": "2026-07-27T13:49:31.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56452",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SCP receiver accepts paths in C and D command filenames and writes the resolved files outside the selected receive directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/xgoqvmksmd94fsqnzqjdtfjxf35os9no",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/15",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 820,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56453",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:38:32.648Z",
      "date_published": "2026-07-16T13:06:49.509Z",
      "date_updated": "2026-07-16T13:44:39.518Z",
      "publisher": "HCL",
      "title": "HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "DFXAnalytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 4.300000000000001,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08517
      },
      "nvd": {
        "published": "2026-07-16T14:16:54.497",
        "lastModified": "2026-07-17T19:09:35.767",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56453",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a host, origin, proxy, or request-channel trust failure in DFXAnalytics, but does not disclose the exact validation rule.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-294",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787; the official support page exposed no additional technical content, leaving the response-manipulation wording as the evidence boundary."
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 365,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:38:32.649Z",
      "date_published": "2026-07-16T13:08:38.448Z",
      "date_updated": "2026-07-16T13:41:57.396Z",
      "publisher": "HCL",
      "title": "HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "DFXAnalytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-327",
          "name": "Use of a Broken or Risky Cryptographic Algorithm",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03564
      },
      "nvd": {
        "published": "2026-07-16T14:16:54.643",
        "lastModified": "2026-07-17T19:10:04.607",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56454",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DFXAnalytics enables TLS 1.0 and TLS 1.1, retaining deprecated cryptographic protocol behavior for protected connections.",
        "basis": [
          "CNA",
          "CWE-327"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56455",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:38:32.649Z",
      "date_published": "2026-07-16T13:13:21.294Z",
      "date_updated": "2026-07-16T13:35:40.644Z",
      "publisher": "HCL",
      "title": "HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS).",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "DFXAnalytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18661
      },
      "nvd": {
        "published": "2026-07-16T14:16:54.797",
        "lastModified": "2026-07-17T19:10:42.027",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56455",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DFXAnalytics copies excessive input into a fixed stack memory container without enforcing its size.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 439,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56456",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:38:32.649Z",
      "date_published": "2026-07-16T13:15:35.460Z",
      "date_updated": "2026-07-16T14:13:21.718Z",
      "publisher": "HCL",
      "title": "HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "DFXAnalytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15235
      },
      "nvd": {
        "published": "2026-07-16T14:16:54.943",
        "lastModified": "2026-07-17T19:11:30.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56456",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HCL DFXAnalytics includes internal filesystem paths in dashboard or diagnostic output visible to an unauthorized observer.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:38:32.649Z",
      "date_published": "2026-07-09T08:51:07.571Z",
      "date_updated": "2026-07-09T12:34:23.917Z",
      "publisher": "HCL",
      "title": "HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "HCL DevOps Deploy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-942",
          "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.0999999999999996,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04926
      },
      "nvd": {
        "published": "2026-07-09T10:16:26.967",
        "lastModified": "2026-07-10T16:00:03.797",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56458",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.",
        "basis": [
          "CNA",
          "CWE-942"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131695",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:38:32.650Z",
      "date_published": "2026-07-09T08:25:50.779Z",
      "date_updated": "2026-07-09T12:37:09.372Z",
      "publisher": "HCL",
      "title": "HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "HCL DevOps Deploy / HCL Launch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00103,
        "percentile": 0.01158
      },
      "nvd": {
        "published": "2026-07-09T10:16:27.093",
        "lastModified": "2026-07-10T15:55:49.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56459",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application stores potentially sensitive information in log files that could be read by a local user.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131696",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56460",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:38:32.650Z",
      "date_published": "2026-07-09T09:09:42.386Z",
      "date_updated": "2026-07-09T12:23:15.700Z",
      "publisher": "HCL",
      "title": "HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerability",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "HCL DevOps Deploy / HCL Launch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13078
      },
      "nvd": {
        "published": "2026-07-09T10:16:27.207",
        "lastModified": "2026-07-13T12:58:05.137",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56460",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131697",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:19.110Z",
      "date_published": "2026-07-27T11:51:58.049Z",
      "date_updated": "2026-07-27T15:44:23.507Z",
      "publisher": "HCL",
      "title": "HCL Connections is vulnerable to information disclosure",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Connections"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05242
      },
      "nvd": {
        "published": "2026-07-27T13:18:21.703",
        "lastModified": "2026-07-30T20:11:59.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56537",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "HCL reports that request handling exposes information to an unauthorized user, while the public record does not identify the response or error path that carries it.",
        "basis": [
          "CNA",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132507",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:19.110Z",
      "date_published": "2026-07-27T11:55:24.601Z",
      "date_updated": "2026-07-27T15:43:39.605Z",
      "publisher": "HCL",
      "title": "HCL Connections is vulnerable to information disclosure",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "Connections"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-213",
          "name": "Exposure of Sensitive Information Due to Incompatible Policies",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05242
      },
      "nvd": {
        "published": "2026-07-27T13:18:21.827",
        "lastModified": "2026-07-30T20:11:59.920",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56538",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Sensitive data is returned, stored, or left readable through an output path that lacks the required disclosure boundary.",
        "basis": [
          "CNA",
          "CWE-213"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132507",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 167,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56567",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:42.053Z",
      "date_published": "2026-07-31T14:52:27.681Z",
      "date_updated": "2026-07-31T17:46:04.546Z",
      "publisher": "HCL",
      "title": "HCL iControl is affected by multiple security vulnerabilities.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "HCL iControl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-15",
          "name": "External Control of System or Configuration Setting",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01593
      },
      "nvd": {
        "published": "2026-07-31T16:17:07.290",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56567",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The deployment exposes internal configuration files publicly because its web server or application hardening does not restrict those files.",
        "basis": [
          "CNA",
          "CWE-15"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132395",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56568",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:42.053Z",
      "date_published": "2026-07-31T14:54:05.175Z",
      "date_updated": "2026-07-31T17:43:15.680Z",
      "publisher": "HCL",
      "title": "HCL iControl is affected by multiple security vulnerabilities.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "HCL iControl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09432
      },
      "nvd": {
        "published": "2026-07-31T16:17:07.410",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56568",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HCL iControl returns raw API errors containing internal endpoints, parameters, codes, and authentication state to clients.",
        "basis": [
          "CNA",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132395",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56569",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:42.053Z",
      "date_published": "2026-07-31T14:57:47.176Z",
      "date_updated": "2026-07-31T17:42:54.616Z",
      "publisher": "HCL",
      "title": "HCL iControl is affected by multiple security vulnerabilities.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "HCL iControl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01611
      },
      "nvd": {
        "published": "2026-07-31T16:17:07.523",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56569",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A web-server hardening configuration leaves sensitive configuration files publicly accessible.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132395",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 186,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56570",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:42.054Z",
      "date_published": "2026-07-31T14:59:02.772Z",
      "date_updated": "2026-07-31T17:42:23.156Z",
      "publisher": "HCL",
      "title": "HCL iControl is affected by multiple security vulnerabilities.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "HCL iControl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07338
      },
      "nvd": {
        "published": "2026-07-31T16:17:07.637",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56570",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Browser autocomplete retains login identifiers in a shared environment where another user can enumerate the suggestions.",
        "basis": [
          "CNA record",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132395",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 307,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56571",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:42.054Z",
      "date_published": "2026-07-31T15:13:17.262Z",
      "date_updated": "2026-07-31T17:40:21.563Z",
      "publisher": "HCL",
      "title": "HCL iControl is affected by multiple security vulnerabilities.",
      "affected": {
        "vendors": [
          "HCL Software"
        ],
        "products": [
          {
            "vendor": "HCL Software",
            "product": "HCL iControl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06745
      },
      "nvd": {
        "published": "2026-07-31T16:17:07.753",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56571",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record associates HCL iControl with sensitive output exposure but does not identify the disclosed field, output path, or missing disclosure check.",
        "basis": [
          "CNA",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132395",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56577",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:47.964Z",
      "date_published": "2026-07-21T17:32:56.327Z",
      "date_updated": "2026-07-22T18:26:55.059Z",
      "publisher": "HCL",
      "title": "HCL MyCloud affected by Weak Password Policy",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "MyCloud"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-521",
          "name": "Weak Password Requirements",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06242
      },
      "nvd": {
        "published": "2026-07-21T18:17:01.547",
        "lastModified": "2026-08-03T14:50:12.433",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56577",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MyCloud accepts passwords under a policy too weak to resist practical brute-force or credential attacks.",
        "basis": [
          "CNA",
          "CWE-521"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132381",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56578",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:47.964Z",
      "date_published": "2026-07-21T17:34:33.553Z",
      "date_updated": "2026-07-22T18:26:48.215Z",
      "publisher": "HCL",
      "title": "HCL MyCloud was affected by Server Version Disclosure",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "MyCloud"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.0599
      },
      "nvd": {
        "published": "2026-07-21T18:17:01.667",
        "lastModified": "2026-08-03T14:40:24.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56578",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HCL MyCloud returns its server software version to clients that do not need that deployment detail.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132381",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 162,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56579",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:47.964Z",
      "date_published": "2026-07-21T17:35:39.475Z",
      "date_updated": "2026-07-22T18:26:40.945Z",
      "publisher": "HCL",
      "title": "HCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "MyCloud"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05269
      },
      "nvd": {
        "published": "2026-07-21T18:17:01.787",
        "lastModified": "2026-08-03T14:40:39.553",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56579",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MyCloud places the product license key in an HTTP response where a requester can receive it.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132381",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56580",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:47.964Z",
      "date_published": "2026-07-21T17:36:28.947Z",
      "date_updated": "2026-07-22T18:26:35.626Z",
      "publisher": "HCL",
      "title": "HCL MyCloud was affected by Using Components with Known Vulnerability",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "MyCloud"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1104",
          "name": "Use of Unmaintained Third Party Components",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07413
      },
      "nvd": {
        "published": "2026-07-21T18:17:01.903",
        "lastModified": "2026-08-03T14:52:33.277",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56580",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HCL MyCloud deploys an unsupported IIS component with known public vulnerabilities.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1104"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132381",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56581",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:47.964Z",
      "date_published": "2026-07-21T17:37:26.615Z",
      "date_updated": "2026-07-22T18:26:28.572Z",
      "publisher": "HCL",
      "title": "HCL MyCloud was affected with Cookie Attribute Path Not Set",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "MyCloud"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-614",
          "name": "Sensitive Cookie in HTTPS Session Without 'Secure' Attribute",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.00999
      },
      "nvd": {
        "published": "2026-07-21T18:17:02.047",
        "lastModified": "2026-08-03T14:40:32.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56581",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HCL MyCloud leaves a cookie Path attribute unset, widening the request paths to which the browser may attach the cookie; the supplied CWE instead describes a missing Secure attribute.",
        "basis": [
          "CNA",
          "CWE-614"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132381",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 150,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56582",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:47.965Z",
      "date_published": "2026-07-21T17:38:24.830Z",
      "date_updated": "2026-07-22T18:26:23.193Z",
      "publisher": "HCL",
      "title": "HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "MyCloud"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-327",
          "name": "Use of a Broken or Risky Cryptographic Algorithm",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00103,
        "percentile": 0.01133
      },
      "nvd": {
        "published": "2026-07-21T18:17:02.170",
        "lastModified": "2026-08-03T14:40:08.783",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56582",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "TLS-CBC padding handling leaks timing differences that reveal whether a guessed plaintext or padding state was valid.",
        "basis": [
          "CNA",
          "CWE-327"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132381",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56583",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:56.746Z",
      "date_published": "2026-07-21T17:39:19.129Z",
      "date_updated": "2026-07-22T18:26:17.683Z",
      "publisher": "HCL",
      "title": "HCL MyCloud was affected with Concurrent Login Vulnerability.",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "MyCloud"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03834
      },
      "nvd": {
        "published": "2026-07-21T18:17:02.287",
        "lastModified": "2026-08-03T14:52:57.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56583",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The MyCloud session lifecycle permits a credential or session identity to remain concurrently reusable beyond the intended connection state.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132381",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56584",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:56.746Z",
      "date_published": "2026-07-21T14:36:09.537Z",
      "date_updated": "2026-07-22T18:27:53.505Z",
      "publisher": "HCL",
      "title": "HCL IEM was affected with the Information disclosure nginx server",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "IntelliOps Event Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06844
      },
      "nvd": {
        "published": "2026-07-21T15:16:36.630",
        "lastModified": "2026-07-30T13:11:20.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56584",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "nginx reveals its version to an unauthorized observer, but the public record does not identify the response surface or configuration state responsible.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132378",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56585",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:56.746Z",
      "date_published": "2026-07-21T14:46:53.637Z",
      "date_updated": "2026-07-22T18:27:41.632Z",
      "publisher": "HCL",
      "title": "HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "IntelliOps Event Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 1.1999999999999997,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04209
      },
      "nvd": {
        "published": "2026-07-21T16:17:17.977",
        "lastModified": "2026-07-30T13:08:15.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56585",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "HCL IEM omits frame-embedding protection, allowing an attacker page to overlay the application and induce an authenticated user to trigger unintended actions.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132378",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56586",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:56.746Z",
      "date_published": "2026-07-21T14:48:41.192Z",
      "date_updated": "2026-07-22T18:27:35.911Z",
      "publisher": "HCL",
      "title": "HCL IEM was affected with X-Content-Type-Options Header Missing",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "IntelliOps Event Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-16",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 1.1,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02378
      },
      "nvd": {
        "published": "2026-07-21T16:17:18.107",
        "lastModified": "2026-07-30T13:04:56.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56586",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "The response omits X-Content-Type-Options, while the record does not establish the claimed SSL-stripping or man-in-the-middle path.",
        "basis": [
          "CNA",
          "CWE-16"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132378",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 172,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56587",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T13:39:56.746Z",
      "date_published": "2026-07-21T14:36:53.887Z",
      "date_updated": "2026-07-22T18:27:48.179Z",
      "publisher": "HCL",
      "title": "HCL IEM was affected with Strict transport security not enforced",
      "affected": {
        "vendors": [
          "HCLSoftware"
        ],
        "products": [
          {
            "vendor": "HCLSoftware",
            "product": "IntelliOps Event Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-523",
          "name": "Unprotected Transport of Credentials",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:psirt@hcl.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05182
      },
      "nvd": {
        "published": "2026-07-21T15:16:36.743",
        "lastModified": "2026-07-30T13:10:07.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56587",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-523"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132378",
          "host": "support.hcl-software.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56623",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T14:49:48.620Z",
      "date_published": "2026-07-20T20:29:08.249Z",
      "date_updated": "2026-07-21T17:15:28.287Z",
      "publisher": "apache",
      "title": "Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache MINA SSHD"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00593,
        "percentile": 0.45028
      },
      "nvd": {
        "published": "2026-07-20T21:16:48.947",
        "lastModified": "2026-07-27T13:50:42.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56623",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled path or object-name data is resolved without proving that the final target remains inside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/bhw26snzgvk0mtqqp5dcyjvczp4kcqky",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1036,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56624",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T15:05:27.038Z",
      "date_published": "2026-07-20T20:28:26.333Z",
      "date_updated": "2026-07-23T03:56:23.660Z",
      "publisher": "apache",
      "title": "Apache MINA SSHD: SSH certificate options lack validations",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache MINA SSHD"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07518
      },
      "nvd": {
        "published": "2026-07-20T21:16:49.070",
        "lastModified": "2026-07-27T13:49:18.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56624",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SSH certificate validator accepts unsupported force-command and verify-required critical options without implementing or rejecting their required semantics.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/o4c2jml522j3z80gbryqzc2f1253ltp6",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/17",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1037,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56642",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T15:17:38.795Z",
      "date_published": "2026-07-14T17:09:25.401Z",
      "date_updated": "2026-08-03T22:57:46.114Z",
      "publisher": "microsoft",
      "title": "Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Service Fabric"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00869,
        "percentile": 0.55274
      },
      "nvd": {
        "published": "2026-07-14T18:18:30.353",
        "lastModified": "2026-07-24T13:38:49.313",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56642",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Service Fabric writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56642",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56643",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T15:17:38.795Z",
      "date_published": "2026-07-14T17:09:25.951Z",
      "date_updated": "2026-08-03T22:57:46.661Z",
      "publisher": "microsoft",
      "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23437
      },
      "nvd": {
        "published": "2026-07-14T18:18:30.497",
        "lastModified": "2026-07-22T16:18:28.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56643",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The DirectX graphics kernel dereferences an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56643",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-56644",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T15:17:38.795Z",
      "date_published": "2026-07-14T17:09:26.513Z",
      "date_updated": "2026-08-03T22:57:47.208Z",
      "publisher": "microsoft",
      "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23437
      },
      "nvd": {
        "published": "2026-07-14T18:18:30.650",
        "lastModified": "2026-07-22T16:18:28.230",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56644",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows kernel accesses an object after its lifetime has ended, allowing a local authorized user to corrupt privileged state.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56644",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-56645",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T15:17:38.795Z",
      "date_published": "2026-07-03T20:35:08.069Z",
      "date_updated": "2026-08-03T22:53:47.520Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00556,
        "percentile": 0.43223
      },
      "nvd": {
        "published": "2026-07-03T21:17:00.670",
        "lastModified": "2026-07-07T13:45:19.933",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56645",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Edge writes beyond a heap allocation while processing attacker-controlled network content opened by the victim.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56645",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 125,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56646",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T15:17:38.796Z",
      "date_published": "2026-07-03T20:35:14.383Z",
      "date_updated": "2026-08-03T22:53:48.147Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00651,
        "percentile": 0.47698
      },
      "nvd": {
        "published": "2026-07-03T21:17:00.783",
        "lastModified": "2026-07-07T13:44:42.013",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56646",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record reports information exposure and spoofing in Edge but does not identify the exposed value or the engineering failure that releases it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56646",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 161,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56647",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T15:17:38.796Z",
      "date_published": "2026-07-14T17:09:28.026Z",
      "date_updated": "2026-08-03T22:57:48.933Z",
      "publisher": "microsoft",
      "title": "Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00852,
        "percentile": 0.54672
      },
      "nvd": {
        "published": "2026-07-14T18:18:30.930",
        "lastModified": "2026-07-23T05:16:37.590",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56647",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Remote Access Service integer arithmetic can wrap a value used in a network privilege-sensitive path.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56647",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-56648",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T15:17:38.796Z",
      "date_published": "2026-07-14T17:09:28.500Z",
      "date_updated": "2026-08-03T22:57:49.473Z",
      "publisher": "microsoft",
      "title": "Windows NFS Server Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00474,
        "percentile": 0.38517
      },
      "nvd": {
        "published": "2026-07-14T18:18:31.127",
        "lastModified": "2026-07-22T16:18:28.687",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56648",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A protected object can change between the check and use steps in Windows 10 Version 1607, invalidating the state assumed by the later operation.",
        "basis": [
          "CNA",
          "CWE-367",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56648",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-56649",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T15:17:38.796Z",
      "date_published": "2026-07-14T17:09:29.051Z",
      "date_updated": "2026-08-03T22:57:50.060Z",
      "publisher": "microsoft",
      "title": "Windows Network File System Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 2.1999999999999993,
      "epss": {
        "score": 0.00651,
        "percentile": 0.47697
      },
      "nvd": {
        "published": "2026-07-14T18:18:31.913",
        "lastModified": "2026-07-22T16:18:28.877",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56649",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 accesses shared state concurrently without the synchronization needed to keep the state transition atomic and consistent.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56649",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 186,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-56650",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T15:17:38.796Z",
      "date_published": "2026-07-14T17:09:30.788Z",
      "date_updated": "2026-08-03T22:57:51.865Z",
      "publisher": "microsoft",
      "title": "Windows Network File System Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-197",
          "name": "Numeric Truncation Error",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23437
      },
      "nvd": {
        "published": "2026-07-14T18:18:32.100",
        "lastModified": "2026-07-22T16:18:29.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56650",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Numeric truncation produces an incorrect size before Windows NFS writes beyond a heap allocation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122",
          "CWE-197"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56650",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 118,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-56664",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.043Z",
      "date_published": "2026-07-10T17:21:22.653Z",
      "date_updated": "2026-07-10T18:01:25.422Z",
      "publisher": "GitHub_M",
      "title": "ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider",
      "affected": {
        "vendors": [
          "zitadel"
        ],
        "products": [
          {
            "vendor": "zitadel",
            "product": "zitadel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10464
      },
      "nvd": {
        "published": "2026-07-10T18:16:23.890",
        "lastModified": "2026-07-10T19:17:26.543",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56664",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ZITADEL skips its maximum-token-age check when a trusted issuer's JWT omits iat, allowing arbitrarily old tokens to authenticate.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-wxg7-w2v3-w38g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/4925fab849d39a88674485d937b79e54318b48a8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/d1c3aa84af8fcb0f33910ada30b866f4afb551ac",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v3.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v4.15.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 393,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56665",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.043Z",
      "date_published": "2026-07-10T17:22:46.079Z",
      "date_updated": "2026-07-10T18:17:48.365Z",
      "publisher": "GitHub_M",
      "title": "ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider",
      "affected": {
        "vendors": [
          "zitadel"
        ],
        "products": [
          {
            "vendor": "zitadel",
            "product": "zitadel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00167,
        "percentile": 0.06354
      },
      "nvd": {
        "published": "2026-07-10T18:16:24.020",
        "lastModified": "2026-07-10T19:17:26.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56665",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ZITADEL accepts a trusted-issuer JWT with no exp claim and assigns it no automatic expiration window.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-v77h-2w3m-94hx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/4925fab849d39a88674485d937b79e54318b48a8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/d1c3aa84af8fcb0f33910ada30b866f4afb551ac",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v3.4.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v4.15.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56666",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.043Z",
      "date_published": "2026-07-10T17:37:37.137Z",
      "date_updated": "2026-07-13T18:09:47.186Z",
      "publisher": "GitHub_M",
      "title": "ZITADEL: Auto-linking by email: IdP-side email verification is not checked",
      "affected": {
        "vendors": [
          "zitadel"
        ],
        "products": [
          {
            "vendor": "zitadel",
            "product": "zitadel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08826
      },
      "nvd": {
        "published": "2026-07-10T18:16:24.150",
        "lastModified": "2026-07-13T19:17:23.487",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56666",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ZITADEL auto-links an external identity by email without requiring the external provider to attest ownership of that email.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-992q-9gwp-7r79",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/c97012f0c5dc2fe960ae6e940cbea23229f0557f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v4.15.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56667",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.043Z",
      "date_published": "2026-07-10T17:25:46.882Z",
      "date_updated": "2026-07-10T20:58:28.907Z",
      "publisher": "GitHub_M",
      "title": "ZITADEL: Stored XSS via Default URI Redirect in Login V2",
      "affected": {
        "vendors": [
          "zitadel"
        ],
        "products": [
          {
            "vendor": "zitadel",
            "product": "zitadel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13208
      },
      "nvd": {
        "published": "2026-07-10T18:16:24.283",
        "lastModified": "2026-07-10T21:16:57.810",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56667",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ZITADEL passes an administrator-configured defaultRedirectUri with a javascript or data scheme to browser navigation, allowing the URI to be interpreted as active content.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-5wcj-9wj4-j65h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/038265925a3b05ac1df8aad461ab071983e9eb85",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v4.15.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56668",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.043Z",
      "date_published": "2026-07-10T17:46:25.937Z",
      "date_updated": "2026-07-14T13:40:35.609Z",
      "publisher": "GitHub_M",
      "title": "ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange",
      "affected": {
        "vendors": [
          "zitadel"
        ],
        "products": [
          {
            "vendor": "zitadel",
            "product": "zitadel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13989
      },
      "nvd": {
        "published": "2026-07-10T18:16:24.413",
        "lastModified": "2026-07-14T14:16:35.310",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56668",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not verify that the subject token belongs to the requesting client or that requested scopes remain within the original token's scopes, allowing a low-privilege token to be exchanged for elevated permissions at another application.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-vrh8-c9cm-wh8v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/commit/e2886a61670ca8fd41c9434f87036546e5620bcc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zitadel/zitadel/releases/tag/v4.15.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 440,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56669",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.043Z",
      "date_published": "2026-07-08T20:25:18.200Z",
      "date_updated": "2026-07-10T15:02:07.512Z",
      "publisher": "GitHub_M",
      "title": "Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict",
      "affected": {
        "vendors": [
          "elysiajs"
        ],
        "products": [
          {
            "vendor": "elysiajs",
            "product": "elysia"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00358,
        "percentile": 0.28468
      },
      "nvd": {
        "published": "2026-07-08T21:16:50.690",
        "lastModified": "2026-07-10T19:10:59.333",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56669",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prior to 1.4.29, Elysia uses getAll in form data normalization for multipart/form-data endpoints, causing the amount of work to grow quadratically with the number of unique key-value pairs and allowing CPU exhaustion.",
        "basis": [
          "CNA",
          "CWE-407",
          "CWE-436"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/elysiajs/elysia/security/advisories/GHSA-9643-4qgh-g8mx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/elysiajs/elysia/commit/8358ff9efbcedf9534995f5977f26b9ceab59329",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://gist.github.com/jviide/ea040eabe7bac058326174e2cd42dfd9",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/elysiajs/elysia/releases/tag/1.4.29",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 385,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56670",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.043Z",
      "date_published": "2026-07-31T04:17:43.843Z",
      "date_updated": "2026-07-31T19:00:49.766Z",
      "publisher": "GitHub_M",
      "title": "ComfyUI: Stored XSS via SVG file upload on the /view endpoint",
      "affected": {
        "vendors": [
          "Comfy-Org"
        ],
        "products": [
          {
            "vendor": "Comfy-Org",
            "product": "ComfyUI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13117
      },
      "nvd": {
        "published": "2026-07-31T06:16:27.560",
        "lastModified": "2026-07-31T19:17:11.290",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56670",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The view endpoint serves uploaded SVG as active image/svg+xml content in the application origin instead of forcing inert delivery.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/security/advisories/GHSA-rj8c-c4p8-3c5h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/commit/96e0e3585b41e1417442eaa14ec57f7b4ffcb5e0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 361,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56671",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.043Z",
      "date_published": "2026-07-31T04:21:54.417Z",
      "date_updated": "2026-07-31T23:19:15.408Z",
      "publisher": "GitHub_M",
      "title": "ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read",
      "affected": {
        "vendors": [
          "Comfy-Org"
        ],
        "products": [
          {
            "vendor": "Comfy-Org",
            "product": "ComfyUI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00661,
        "percentile": 0.481
      },
      "nvd": {
        "published": "2026-07-31T06:16:29.860",
        "lastModified": "2026-08-01T00:17:17.373",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56671",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "get_model_preview joins an unrestricted route capture to the model directory without checking containment or bounding path_index.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/security/advisories/GHSA-pj59-g5vv-74q4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/pull/14734",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 953,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56672",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.043Z",
      "date_published": "2026-07-31T04:27:18.721Z",
      "date_updated": "2026-07-31T11:06:19.744Z",
      "publisher": "GitHub_M",
      "title": "ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization",
      "affected": {
        "vendors": [
          "Comfy-Org"
        ],
        "products": [
          {
            "vendor": "Comfy-Org",
            "product": "ComfyUI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14766
      },
      "nvd": {
        "published": "2026-07-31T06:16:30.170",
        "lastModified": "2026-07-31T11:17:10.903",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56672",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/security/advisories/GHSA-53g8-45wq-pcv8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/commit/96e0e3585b41e1417442eaa14ec57f7b4ffcb5e0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 782,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56673",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.043Z",
      "date_published": "2026-07-31T04:46:21.314Z",
      "date_updated": "2026-07-31T19:31:07.613Z",
      "publisher": "GitHub_M",
      "title": "ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence probing and image exfiltration",
      "affected": {
        "vendors": [
          "Comfy-Org"
        ],
        "products": [
          {
            "vendor": "Comfy-Org",
            "product": "ComfyUI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0043,
        "percentile": 0.35399
      },
      "nvd": {
        "published": "2026-07-31T06:16:30.520",
        "lastModified": "2026-07-31T20:16:52.487",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56673",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ComfyUI accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/security/advisories/GHSA-rvxv-29p8-pxgq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/pull/14734",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/releases/tag/v0.28.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 711,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56675",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.044Z",
      "date_published": "2026-07-10T15:39:23.282Z",
      "date_updated": "2026-07-10T16:55:03.329Z",
      "publisher": "GitHub_M",
      "title": "9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-441",
          "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23915
      },
      "nvd": {
        "published": "2026-07-10T17:17:01.070",
        "lastModified": "2026-07-10T17:35:11.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56675",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The backend treats a reverse proxy's loopback source as proof that an external request is local and skips API-key authentication.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-290",
          "CWE-306",
          "CWE-441"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-x5c9-v98j-722r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/commit/da667836cc7584bea0edd893de1d590c9ea279dc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/releases/tag/v0.5.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 3,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56676",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.044Z",
      "date_published": "2026-07-10T15:30:49.514Z",
      "date_updated": "2026-07-13T18:11:54.297Z",
      "publisher": "GitHub_M",
      "title": "9router: Image prefetch DNS rebinding allows SSRF to internal services",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05122
      },
      "nvd": {
        "published": "2026-07-10T16:16:34.923",
        "lastModified": "2026-07-13T19:17:24.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56676",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server validates one DNS result and later connects after rebinding can change the destination address.",
        "basis": [
          "CNA",
          "CWE-367",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-cmhj-wh2f-9cgx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/commit/c7d07448c58bec1200741de0b73305b860416b82",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/releases/tag/v0.5.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56678",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.044Z",
      "date_published": "2026-07-15T20:51:33.190Z",
      "date_updated": "2026-07-16T12:53:24.795Z",
      "publisher": "GitHub_M",
      "title": "9Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06785
      },
      "nvd": {
        "published": "2026-07-15T21:16:55.430",
        "lastModified": "2026-07-16T14:16:55.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56678",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled region changes the validation destination while the server forwards the submitted Kiro key in the Authorization header.",
        "basis": [
          "CNA record",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-6mwv-4mrm-5p3m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/commit/126aa244c5b51b74ab8c7594e3418fcf4437bf6f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/releases/tag/v0.5.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 470,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56679",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T16:39:01.044Z",
      "date_published": "2026-07-15T20:50:30.458Z",
      "date_updated": "2026-07-16T13:00:42.944Z",
      "publisher": "GitHub_M",
      "title": "9Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24882
      },
      "nvd": {
        "published": "2026-07-15T21:16:55.560",
        "lastModified": "2026-07-16T14:16:55.167",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56679",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "9router lets attacker-controlled field names modify dynamically selected object attributes.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-vmjq-hvgq-2wv4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 446,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T17:04:26.238Z",
      "date_published": "2026-07-15T17:33:07.011Z",
      "date_updated": "2026-07-16T03:55:52.361Z",
      "publisher": "dell",
      "title": "Dell ThinOS 10, versions prior to 2605_10.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "ThinOS 10"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-448",
          "name": "Obsolete Feature in UI",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00104,
        "percentile": 0.01214
      },
      "nvd": {
        "published": "2026-07-15T18:16:48.493",
        "lastModified": "2026-07-16T05:16:25.420",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56687",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "ThinOS leaves an obsolete UI feature available to a low-privileged local user, opening an unauthorized access path.",
        "basis": [
          "CNA",
          "CWE-448"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000489640/dsa-2026-300-security-update-for-dell-thinos-10-for-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T17:04:26.238Z",
      "date_published": "2026-07-10T11:57:41.752Z",
      "date_updated": "2026-07-10T17:01:12.022Z",
      "publisher": "dell",
      "title": "Dell PowerFlex Manager, Version prior to 5.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerFlex Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01199,
        "percentile": 0.6512
      },
      "nvd": {
        "published": "2026-07-10T12:17:23.453",
        "lastModified": "2026-07-16T16:46:37.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56688",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In PowerFlex Manager, attacker-controlled input reaches an operating-system command without shell-context neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000477538/dsa-2026-066-security-update-for-powerflex-software-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 439,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56689",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T17:04:26.238Z",
      "date_published": "2026-07-10T11:51:27.171Z",
      "date_updated": "2026-07-10T13:00:10.810Z",
      "publisher": "dell",
      "title": "Dell PowerFlex Manager, Version prior to 5.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerFlex Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.126
      },
      "nvd": {
        "published": "2026-07-10T12:17:23.577",
        "lastModified": "2026-07-16T16:47:25.023",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56689",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled query text is concatenated into an SQL statement without parameter binding or equivalent grammar separation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000477538/dsa-2026-066-security-update-for-powerflex-software-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T17:04:26.238Z",
      "date_published": "2026-07-10T11:43:44.004Z",
      "date_updated": "2026-07-10T13:14:31.666Z",
      "publisher": "dell",
      "title": "Dell PowerFlex Manager, Version prior to 5.",
      "affected": {
        "vendors": [
          "Dell"
        ],
        "products": [
          {
            "vendor": "Dell",
            "product": "PowerFlex Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security_alert@emc.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.1524
      },
      "nvd": {
        "published": "2026-07-10T12:17:23.700",
        "lastModified": "2026-07-16T16:48:00.263",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56690",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PowerFlex Manager incorporates low-privileged remote input into an SQL command without preserving the SQL data boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.dell.com/support/kbdoc/en-us/000477538/dsa-2026-066-security-update-for-powerflex-software-multiple-vulnerabilities",
          "host": "www.dell.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56699",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T17:09:16.556Z",
      "date_published": "2026-07-15T11:25:32.119Z",
      "date_updated": "2026-07-15T12:42:22.159Z",
      "publisher": "VulnCheck",
      "title": "Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index",
      "affected": {
        "vendors": [
          "wazuh"
        ],
        "products": [
          {
            "vendor": "wazuh",
            "product": "wazuh"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27832
      },
      "nvd": {
        "published": "2026-07-15T12:18:15.293",
        "lastModified": "2026-07-15T21:01:16.810",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56699",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Wazuh interpolates an enrolled agent's DataValue.index into OpenSearch NDJSON without escaping line boundaries, allowing the agent to append bulk operations.",
        "basis": [
          "CNA",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-ff9g-85jq-r3g3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/wazuh-manager-ndjson-injection-in-inventory-sync-via-agent-controlled-datavalue-index",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 393,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56722",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:17:28.958Z",
      "date_published": "2026-07-28T20:17:36.690Z",
      "date_updated": "2026-07-29T14:06:27.019Z",
      "publisher": "GitHub_M",
      "title": "Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI",
      "affected": {
        "vendors": [
          "dompdf"
        ],
        "products": [
          {
            "vendor": "dompdf",
            "product": "dompdf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00558,
        "percentile": 0.43349
      },
      "nvd": {
        "published": "2026-07-28T21:17:28.587",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56722",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A second pass over an SVG data URI resolves a file path without reapplying chroot or path validation.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dompdf/dompdf/security/advisories/GHSA-cx96-42px-69fm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/commit/6a58996865db05d8fede748507e50ac4b8c5bfd0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/commit/bf7b02f642e26007dedc5a22b3d6e15f9931120a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/releases/tag/v3.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 796,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56740",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:17:28.959Z",
      "date_published": "2026-07-17T21:17:03.239Z",
      "date_updated": "2026-07-20T13:58:00.902Z",
      "publisher": "GitHub_M",
      "title": "JLine: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables",
      "affected": {
        "vendors": [
          "jline"
        ],
        "products": [
          {
            "vendor": "jline",
            "product": "jline3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00504,
        "percentile": 0.40368
      },
      "nvd": {
        "published": "2026-07-17T22:17:57.153",
        "lastModified": "2026-07-23T17:57:11.017",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56740",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "JLine Telnet accepts an unbounded number or size of environment variables for a connection.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/pull/2001",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/jline-3.30.14",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 578,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56741",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:17:28.959Z",
      "date_published": "2026-07-17T21:15:14.732Z",
      "date_updated": "2026-07-20T15:21:23.382Z",
      "publisher": "GitHub_M",
      "title": "JLine: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry",
      "affected": {
        "vendors": [
          "jline"
        ],
        "products": [
          {
            "vendor": "jline",
            "product": "jline3"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00515,
        "percentile": 0.40983
      },
      "nvd": {
        "published": "2026-07-17T22:17:57.317",
        "lastModified": "2026-07-23T17:57:11.017",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56741",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/pull/2000",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/commit/733eb353dca7b0ea0252e724445b6defa29c393e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/commit/86b7ba7801988aadb1a67555629522a71d603bd3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.0.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/jline/jline3/releases/tag/4.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 639,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56742",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:17:28.959Z",
      "date_published": "2026-07-15T19:14:07.617Z",
      "date_updated": "2026-07-16T12:57:08.040Z",
      "publisher": "GitHub_M",
      "title": "Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces",
      "affected": {
        "vendors": [
          "cilium"
        ],
        "products": [
          {
            "vendor": "cilium",
            "product": "cilium"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 3,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06778
      },
      "nvd": {
        "published": "2026-07-15T20:17:51.850",
        "lastModified": "2026-07-17T17:48:48.260",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56742",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cilium/cilium/security/advisories/GHSA-w7c2-w76w-5hmj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/commit/7422068aff67ac77c7dcc57aa5b9240c91333deb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/commit/e0b1cef513ff910323f3743e9f3e3d86721e4857",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/commit/f23929cff682d6ed0dc158070812cb302fc0032b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/commit/fd47963ea394d5e8fa4a88c40a79063430c512ca",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/releases/tag/v1.17.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/releases/tag/v1.18.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/releases/tag/v1.19.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 427,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56743",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:17:28.959Z",
      "date_published": "2026-07-15T19:15:30.924Z",
      "date_updated": "2026-07-16T13:03:36.080Z",
      "publisher": "GitHub_M",
      "title": "Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match",
      "affected": {
        "vendors": [
          "cilium"
        ],
        "products": [
          {
            "vendor": "cilium",
            "product": "cilium"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05473
      },
      "nvd": {
        "published": "2026-07-15T20:17:51.987",
        "lastModified": "2026-07-17T17:29:02.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56743",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Cilium parser creates a wildcard namespace selector for a selectorless CIDR peer under a custom cluster name, widening the generated allow rule.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cilium/cilium/security/advisories/GHSA-fm8w-2m5w-9j7r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/pull/46305",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/pull/46456",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/commit/1c84ae3b58a7cd54f7ee355e6c524c82f620eae8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/commit/bacea640404c0805c23515353dc1681c5bf35171",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cilium/cilium/releases/tag/v1.19.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 553,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56745",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:17:28.959Z",
      "date_published": "2026-07-21T21:31:25.307Z",
      "date_updated": "2026-07-22T15:30:19.140Z",
      "publisher": "GitHub_M",
      "title": "Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00612,
        "percentile": 0.45877
      },
      "nvd": {
        "published": "2026-07-21T22:17:14.500",
        "lastModified": "2026-07-30T14:46:55.073",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56745",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Netty removes a ByteBuf from a collection without releasing its retained reference on one path, allowing repeated inputs to exhaust memory.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 688,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56746",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T19:17:28.959Z",
      "date_published": "2026-07-21T21:36:18.627Z",
      "date_updated": "2026-07-22T13:39:41.978Z",
      "publisher": "GitHub_M",
      "title": "Netty has a Security Control Bypass via CORS Short-Circuit Failure",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29575
      },
      "nvd": {
        "published": "2026-07-21T22:17:14.667",
        "lastModified": "2026-07-30T14:47:53.123",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56746",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CorsHandler's origin expression treats Origin: null as acceptable and forwards the request before the configured short-circuit rejection can run.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 827,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T20:02:07.173Z",
      "date_published": "2026-07-27T19:22:12.784Z",
      "date_updated": "2026-07-27T20:23:09.438Z",
      "publisher": "Cribl",
      "title": "Code Injection in JSON Pointer Processing Component in Cribl Stream",
      "affected": {
        "vendors": [
          "Cribl"
        ],
        "products": [
          {
            "vendor": "Cribl",
            "product": "Cribl Stream"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:af879a92-7297-456a-bb0e-905ac6c64bdc",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:af879a92-7297-456a-bb0e-905ac6c64bdc",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00364,
        "percentile": 0.29118
      },
      "nvd": {
        "published": "2026-07-27T20:16:39.873",
        "lastModified": "2026-07-30T19:12:22.607",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56747",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Cribl Stream places caller-influenced data into dynamically evaluated code without restricting executable syntax.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.cribl.io/stream/release-notes/release-v4182/#security-fixes",
          "host": "docs.cribl.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://trust.cribl.io/notifications",
          "host": "trust.cribl.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56748",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T20:02:07.174Z",
      "date_published": "2026-07-27T19:27:31.700Z",
      "date_updated": "2026-07-27T20:22:35.788Z",
      "publisher": "Cribl",
      "title": "Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import",
      "affected": {
        "vendors": [
          "Cribl"
        ],
        "products": [
          {
            "vendor": "Cribl",
            "product": "Cribl Stream"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-61",
          "name": "UNIX Symbolic Link (Symlink) Following",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:af879a92-7297-456a-bb0e-905ac6c64bdc",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:af879a92-7297-456a-bb0e-905ac6c64bdc",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00566,
        "percentile": 0.43772
      },
      "nvd": {
        "published": "2026-07-27T20:16:40.017",
        "lastModified": "2026-07-30T19:12:22.607",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56748",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Pack Git import follows a repository symlink into the functions directory and then loads code from the attacker-selected target.",
        "basis": [
          "CNA",
          "CWE-61"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.cribl.io/stream/release-notes/release-v4182/#security-fixes",
          "host": "docs.cribl.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://trust.cribl.io/notifications",
          "host": "trust.cribl.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56758",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T19:32:49.404Z",
      "date_published": "2026-07-30T22:29:20.516Z",
      "date_updated": "2026-07-31T15:52:20.133Z",
      "publisher": "icscert",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "affected": {
        "vendors": [
          "MZ Automation GmbH"
        ],
        "products": [
          {
            "vendor": "MZ Automation GmbH",
            "product": "libiec61850"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00181,
        "percentile": 0.0786
      },
      "nvd": {
        "published": "2026-07-30T23:16:51.517",
        "lastModified": "2026-07-31T16:17:07.867",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56758",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ACSE parser trusts a zero- or one-byte calling AP-title length and reads past the associated heap buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 269,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T21:55:17.942Z",
      "date_published": "2026-07-11T13:00:59.084Z",
      "date_updated": "2026-07-14T14:30:12.573Z",
      "publisher": "VulnCheck",
      "title": "Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option",
      "affected": {
        "vendors": [
          "Hono"
        ],
        "products": [
          {
            "vendor": "Hono",
            "product": "Hono"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07431
      },
      "nvd": {
        "published": "2026-07-11T14:16:22.080",
        "lastModified": "2026-07-14T15:17:05.593",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56763",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "parseBody with dot notation accepts the special __proto__ key and turns form field names into prototype-bearing object structure.",
        "basis": [
          "CNA",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/honojs/hono/security/advisories/GHSA-v8w9-8mx6-g223",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/hono-prototype-pollution-via-proto-key-in-parsebody-with-dot-option",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 346,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T21:55:17.942Z",
      "date_published": "2026-07-15T11:25:32.814Z",
      "date_updated": "2026-07-15T13:50:24.700Z",
      "publisher": "VulnCheck",
      "title": "Hono - Timing Attack in basicAuth and bearerAuth Middleware",
      "affected": {
        "vendors": [
          "Hono"
        ],
        "products": [
          {
            "vendor": "Hono",
            "product": "Hono"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13822
      },
      "nvd": {
        "published": "2026-07-15T12:18:15.440",
        "lastModified": "2026-07-15T21:02:13.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56764",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Hono secret comparison exits early and leaks credential information through response timing.",
        "basis": [
          "CNA",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/honojs/hono/security/advisories/GHSA-gq3j-xvxp-8hrf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/hono-timing-attack-in-basicauth-and-bearerauth-middleware",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-22T21:55:17.942Z",
      "date_published": "2026-07-10T13:57:59.648Z",
      "date_updated": "2026-07-10T17:00:55.985Z",
      "publisher": "VulnCheck",
      "title": "Vikunja - Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR",
      "affected": {
        "vendors": [
          "Vikunja"
        ],
        "products": [
          {
            "vendor": "Vikunja",
            "product": "Vikunja"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00358,
        "percentile": 0.28503
      },
      "nvd": {
        "published": "2026-07-10T15:16:43.727",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56765",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Vikunja exposes privileged share hashes and fetches attachments by global ID without checking project ownership.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-2pv8-4c52-mf8j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/vikunja-unauthenticated-instance-wide-data-breach-via-link-share-hash-disclosure-chained-with-cross-project-attachment-idor",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56775",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T01:22:22.571Z",
      "date_published": "2026-07-08T13:49:06.267Z",
      "date_updated": "2026-07-08T14:31:22.470Z",
      "publisher": "VulnCheck",
      "title": "n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07353
      },
      "nvd": {
        "published": "2026-07-08T14:17:17.420",
        "lastModified": "2026-07-08T19:31:35.683",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56775",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Three mutating evaluation endpoints authorize workflow:read instead of workflow:execute, allowing a viewer to start, cancel, or delete test runs.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-664h-gpgq-h6xx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-incorrect-oauth-scope-validation-in-evaluation-test-runs-endpoints",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-56776",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T01:22:22.571Z",
      "date_published": "2026-07-08T13:49:06.971Z",
      "date_updated": "2026-07-09T14:55:45.087Z",
      "publisher": "VulnCheck",
      "title": "n8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 2.1000000000000005,
      "epss": {
        "score": 0.00161,
        "percentile": 0.0575
      },
      "nvd": {
        "published": "2026-07-08T14:17:17.553",
        "lastModified": "2026-07-09T16:16:45.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56776",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "n8n fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-hv7x-3x78-gx53",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-incorrect-oauth-scope-validation-in-workflow-test-run-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-56778",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T01:22:22.572Z",
      "date_published": "2026-07-08T13:49:07.670Z",
      "date_updated": "2026-07-08T14:25:29.900Z",
      "publisher": "VulnCheck",
      "title": "n8n - Authorization Bypass in Public API Execution Retry Endpoint",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00174,
        "percentile": 0.071
      },
      "nvd": {
        "published": "2026-07-08T14:17:17.683",
        "lastModified": "2026-07-08T19:26:35.280",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56778",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The public retry endpoint checks workflow read scope instead of execute scope, so a read-only collaborator can rerun an execution.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-h3jj-5f3v-3685",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-authorization-bypass-in-public-api-execution-retry-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 491,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-56810",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T12:29:02.507Z",
      "date_published": "2026-07-06T09:17:17.429Z",
      "date_updated": "2026-07-07T04:32:36.390Z",
      "publisher": "EEF",
      "title": "mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5",
      "affected": {
        "vendors": [
          "elixir-mint"
        ],
        "products": [
          {
            "vendor": "elixir-mint",
            "product": "mint"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27007
      },
      "nvd": {
        "published": "2026-07-06T11:16:30.983",
        "lastModified": "2026-07-06T19:37:48.003",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56810",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mint buffers an entire declared HTTP chunk before emitting data and imposes no chunk-size limit, allowing a slow server to grow client memory without bound.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/elixir-mint/mint/security/advisories/GHSA-c59h-fq4p-r36r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-56810.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-56810",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/elixir-mint/mint/commit/193ce714907d16e8adc4ab3c40e4f0c2f045b2a6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1427,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56811",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T12:29:02.507Z",
      "date_published": "2026-07-07T15:09:57.581Z",
      "date_updated": "2026-07-07T16:14:39.702Z",
      "publisher": "EEF",
      "title": "Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service",
      "affected": {
        "vendors": [
          "phoenixframework"
        ],
        "products": [
          {
            "vendor": "phoenixframework",
            "product": "phoenix"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.0042,
        "percentile": 0.34591
      },
      "nvd": {
        "published": "2026-07-07T16:16:40.710",
        "lastModified": "2026-07-09T14:59:45.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56811",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Phoenix accepts an unbounded number of persistent channel joins on one transport and can exhaust the BEAM process table.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/phoenixframework/phoenix/security/advisories/GHSA-6983-jfq8-485w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-56811.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Third Party Advisory",
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-56811",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Third Party Advisory",
            "related"
          ]
        },
        {
          "url": "https://github.com/phoenixframework/phoenix/commit/c498ba8cf49f6accbbd0c643a5340b58db891218",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/phoenixframework/phoenix/commit/d19ca0a8d9f82c130b7ed339b9f033433e2dea5e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/phoenixframework/phoenix/commit/a612100cd8a4279091abc1a2ef8fb98a6d01c0a1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/phoenixframework/phoenix/commit/16e295d2fccab185d1292322e2bee5d46c725c8a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1644,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-56812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T12:29:02.507Z",
      "date_published": "2026-07-07T15:22:46.933Z",
      "date_updated": "2026-07-07T16:11:22.228Z",
      "publisher": "EEF",
      "title": "Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff",
      "affected": {
        "vendors": [
          "phoenixframework"
        ],
        "products": [
          {
            "vendor": "phoenixframework",
            "product": "phoenix"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00507,
        "percentile": 0.40506
      },
      "nvd": {
        "published": "2026-07-07T16:16:40.920",
        "lastModified": "2026-07-09T14:51:19.313",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56812",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Phoenix tests attacker-controlled presence keys through inherited object properties and then calls metas.map on a prototype member.",
        "basis": [
          "CNA",
          "CWE-754"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/phoenixframework/phoenix/security/advisories/GHSA-63mc-hw7g-86rr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory",
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-56812.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Third Party Advisory",
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-56812",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Third Party Advisory",
            "related"
          ]
        },
        {
          "url": "https://github.com/phoenixframework/phoenix/commit/7f7b971c1ea0994e3fbd1c11ddb05e780bd38ad8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/phoenixframework/phoenix/commit/89a1c4be161e436241e12b2378a719904b9bd96f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/phoenixframework/phoenix/commit/b90b22521465ece00eb5a19d5aa2b9465b209c85",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/phoenixframework/phoenix/commit/beffc4da1e787e572121f68902c63daf4fe7d9c2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1811,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-56813",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T12:29:02.507Z",
      "date_published": "2026-07-10T12:51:08.758Z",
      "date_updated": "2026-07-10T14:45:34.174Z",
      "publisher": "EEF",
      "title": "Cookie attribute injection in Plug.Conn.Cookies.encode/2",
      "affected": {
        "vendors": [
          "elixir-plug"
        ],
        "products": [
          {
            "vendor": "elixir-plug",
            "product": "plug"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-141",
          "name": "Improper Neutralization of Parameter/Argument Delimiters",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04324
      },
      "nvd": {
        "published": "2026-07-10T13:16:20.663",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56813",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Plug.Conn.Cookies encodes an attacker-controlled cookie value without neutralizing semicolon delimiters, allowing injected cookie attributes.",
        "basis": [
          "CNA",
          "CWE-141"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/elixir-plug/plug/security/advisories/GHSA-wpmj-jh88-rpgm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-56813.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-56813",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/elixir-plug/plug/commit/c6575800b2c4e15af1904df87522ca8a23da020c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1159,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-56814",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T12:29:02.507Z",
      "date_published": "2026-07-10T11:14:35.574Z",
      "date_updated": "2026-07-10T14:41:43.299Z",
      "publisher": "EEF",
      "title": "Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)",
      "affected": {
        "vendors": [
          "elixir-plug"
        ],
        "products": [
          {
            "vendor": "elixir-plug",
            "product": "plug"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00579,
        "percentile": 0.44369
      },
      "nvd": {
        "published": "2026-07-10T12:17:24.837",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56814",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enforce its :length budget against all consumed resources, allowing an unauthenticated remote attacker to cause denial of service.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/elixir-plug/plug/security/advisories/GHSA-95qv-c9g9-rm63",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-56814.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-56814",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/elixir-plug/plug/commit/981597d3a4271ede64373c7a731702a42c500dd6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/elixir-plug/plug/commit/56edca2ce35fe5589cd581644d8a4493fa5f484e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/elixir-plug/plug/commit/0ee8afcc61466dc5f7a8f048d0632c899165b81f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/elixir-plug/plug/commit/cae36053350e5215a4e0ca33cd130af9c5fc6364",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/elixir-plug/plug/commit/f7effaed811c00b5f5bf817936bfd9c5df27b7dc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/elixir-plug/plug/commit/df97d3f17f808a9916a7700a701fb85314559d56",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1477,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-56816",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T14:55:09.116Z",
      "date_published": "2026-07-21T21:56:36.194Z",
      "date_updated": "2026-07-22T18:24:28.067Z",
      "publisher": "GitHub_M",
      "title": "Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00522,
        "percentile": 0.41392
      },
      "nvd": {
        "published": "2026-07-21T22:17:14.803",
        "lastModified": "2026-07-30T14:48:10.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56816",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; `decodeFrame` trusts `payLoadLength`, allowing an attacker to open multiple QUIC streams and send reserved frames with very large payload lengths to cause memory exhaustion and denial of service.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-hpcc-26xq-25fv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 489,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56817",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T14:55:09.116Z",
      "date_published": "2026-07-21T22:06:56.481Z",
      "date_updated": "2026-07-22T15:42:09.445Z",
      "publisher": "GitHub_M",
      "title": "Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29866
      },
      "nvd": {
        "published": "2026-07-21T23:17:52.127",
        "lastModified": "2026-07-30T14:48:18.777",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56817",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "XmlDecoder creates an XML input factory without disabling DTD and external-entity processing before parsing channel bytes.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-4qhr-g3c6-fcfx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 574,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56819",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T14:55:09.116Z",
      "date_published": "2026-07-21T22:11:17.470Z",
      "date_updated": "2026-07-23T13:55:29.793Z",
      "publisher": "GitHub_M",
      "title": "Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00365,
        "percentile": 0.29246
      },
      "nvd": {
        "published": "2026-07-21T23:17:52.263",
        "lastModified": "2026-07-30T14:46:35.563",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56819",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Netty retains an HTTP/2 DATA ByteBuf before decompression and fails to release it when the decompressor is already closed, leaking direct memory per frame.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56820",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T14:55:09.116Z",
      "date_published": "2026-07-21T22:26:16.588Z",
      "date_updated": "2026-07-24T20:12:43.581Z",
      "publisher": "GitHub_M",
      "title": "Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.00182,
        "percentile": 0.07996
      },
      "nvd": {
        "published": "2026-07-21T23:17:52.403",
        "lastModified": "2026-07-30T14:48:49.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56820",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The certificate, signature, or revocation result is accepted without validating it against the exact credential and request being authenticated.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-272m-gcwp-mpwg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T14:55:09.116Z",
      "date_published": "2026-07-28T23:07:13.616Z",
      "date_updated": "2026-07-31T16:12:56.878Z",
      "publisher": "GitHub_M",
      "title": "Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-299",
          "name": "Improper Check for Certificate Revocation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03821
      },
      "nvd": {
        "published": "2026-07-29T00:16:38.573",
        "lastModified": "2026-07-31T16:17:07.983",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56821",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Netty reports an expired OCSP GOOD response as valid instead of stopping validation, allowing that stale response to be replayed after certificate revocation.",
        "basis": [
          "CNA",
          "CWE-299"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-g7hg-vrcf-mvmr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 658,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56822",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T14:55:09.116Z",
      "date_published": "2026-07-28T23:17:17.325Z",
      "date_updated": "2026-07-30T03:55:17.891Z",
      "publisher": "GitHub_M",
      "title": "Netty: TOCTOU in OcspServerCertificateValidator",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01606
      },
      "nvd": {
        "published": "2026-07-29T00:16:38.717",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56822",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OCSP validator signals handshake completion before asynchronous revocation validation finishes, allowing application data to flow to a revoked server.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-wc96-39fc-566f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1242,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-56841",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:00:03.631Z",
      "date_published": "2026-07-02T14:50:48.763Z",
      "date_updated": "2026-07-02T15:51:17.657Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Protect Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20224
      },
      "nvd": {
        "published": "2026-07-02T15:17:07.750",
        "lastModified": "2026-07-06T19:32:47.187",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56841",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56842",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:00:03.632Z",
      "date_published": "2026-07-02T14:50:49.035Z",
      "date_updated": "2026-07-02T15:50:57.619Z",
      "publisher": "hackerone",
      "title": "A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access ...",
      "affected": {
        "vendors": [
          "Ubiquiti Inc"
        ],
        "products": [
          {
            "vendor": "Ubiquiti Inc",
            "product": "UniFi Network Application"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11789
      },
      "nvd": {
        "published": "2026-07-02T15:17:07.870",
        "lastModified": "2026-07-06T19:27:30.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-56842",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "UniFi Network Application keeps a caller's privileges active after the access-removal state transition.",
        "basis": [
          "CNA record",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc",
          "host": "community.ui.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56843",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:00:03.632Z",
      "date_published": "2026-07-08T00:15:43.120Z",
      "date_updated": "2026-07-08T13:04:17.023Z",
      "publisher": "hackerone",
      "title": "Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.",
      "affected": {
        "vendors": [
          "Webpros"
        ],
        "products": [
          {
            "vendor": "Webpros",
            "product": "Plesk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00364,
        "percentile": 0.2912
      },
      "nvd": {
        "published": "2026-07-08T01:16:28.277",
        "lastModified": "2026-07-10T18:57:22.440",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56843",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Legacy XML-RPC schemas bypass the domain-ownership check applied to only some lookup filters, allowing cross-tenant domain queries.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.plesk.com/hc/en-us/articles/41178305151255-Vulnerability-in-Plesk-XML-API-Cleartext-FTP-Password-Exposure",
          "host": "support.plesk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56844",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:00:03.632Z",
      "date_published": "2026-07-22T00:44:32.798Z",
      "date_updated": "2026-07-22T13:02:38.298Z",
      "publisher": "hackerone",
      "title": "A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.",
      "affected": {
        "vendors": [
          "Veeam"
        ],
        "products": [
          {
            "vendor": "Veeam",
            "product": "Backup and Replication"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02939
      },
      "nvd": {
        "published": "2026-07-22T01:16:26.523",
        "lastModified": "2026-07-23T18:27:07.573",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56844",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Veeam Updater permits a local user to escape an intended path boundary, but the selected path and failing check are not public.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.veeam.com/kb4879",
          "host": "www.veeam.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56847",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:00:03.632Z",
      "date_published": "2026-07-30T06:02:50.099Z",
      "date_updated": "2026-07-30T12:35:31.331Z",
      "publisher": "hackerone",
      "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affecte...",
      "affected": {
        "vendors": [
          "nodejs"
        ],
        "products": [
          {
            "vendor": "nodejs",
            "product": "node"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1119",
          "name": "Excessive Use of Unconditional Branching",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Prohibited",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05462
      },
      "nvd": {
        "published": "2026-07-30T06:25:54.953",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56847",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Node.js trace events can write trace logs outside the paths granted by --allow-fs-write, bypassing the Permission Model's file-write decision.",
        "basis": [
          "CNA",
          "CWE-1119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nodejs.org/en/blog/vulnerability/july-2026-security-releases",
          "host": "nodejs.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56850",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:00:03.632Z",
      "date_published": "2026-07-30T06:02:50.074Z",
      "date_updated": "2026-07-30T12:37:10.100Z",
      "publisher": "hackerone",
      "title": "A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects...",
      "affected": {
        "vendors": [
          "nodejs"
        ],
        "products": [
          {
            "vendor": "nodejs",
            "product": "node"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00082,
        "percentile": 0.00283
      },
      "nvd": {
        "published": "2026-07-30T06:25:55.073",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56850",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The HTTPS agent's PFX object-array cache key can collide, causing a connection authenticated with one client certificate to be reused for another identity.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nodejs.org/en/blog/vulnerability/july-2026-security-releases",
          "host": "nodejs.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 282,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-56852",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:10:49.352Z",
      "date_published": "2026-07-21T19:18:59.951Z",
      "date_updated": "2026-07-23T13:26:20.232Z",
      "publisher": "Go",
      "title": "Infinite loop on invalid input in golang.org/x/text",
      "affected": {
        "vendors": [
          "golang.org/x/text"
        ],
        "products": [
          {
            "vendor": "golang.org/x/text",
            "product": "golang.org/x/text/unicode/norm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00446,
        "percentile": 0.36637
      },
      "nvd": {
        "published": "2026-07-21T20:17:02.867",
        "lastModified": "2026-07-23T18:27:48.877",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56852",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "norm.Iter fails to advance or terminate when invalid UTF-8 reaches a particular normalization state, producing an infinite loop.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://go.dev/issue/80142",
          "host": "go.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://go.dev/cl/794100",
          "host": "go.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://pkg.go.dev/vuln/GO-2026-5970",
          "host": "pkg.go.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 90,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-56877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T15:43:45.665Z",
      "date_published": "2026-07-13T21:51:43.515Z",
      "date_updated": "2026-07-16T06:49:11.082Z",
      "publisher": "mitre",
      "title": "The SCORM lab launch endpoint in Skillable (scorm.",
      "affected": {
        "vendors": [
          "Skillable"
        ],
        "products": [
          {
            "vendor": "Skillable",
            "product": "SCORM Lab Launch Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-472",
          "name": "External Control of Assumed-Immutable Web Parameter",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00391,
        "percentile": 0.31865
      },
      "nvd": {
        "published": "2026-07-13T22:16:48.133",
        "lastModified": "2026-07-16T07:16:48.090",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-56877",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SCORM Lab Launch Integration authorization path trusts a client-supplied identity value that should have remained server-controlled.",
        "basis": [
          "CNA",
          "CWE-472"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.skillable.com/security/",
          "host": "www.skillable.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/12/1",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/12/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/12/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://seclists.org/fulldisclosure/2026/Jul/20",
          "host": "seclists.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 460,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57019",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.248Z",
      "date_published": "2026-07-09T21:04:41.927Z",
      "date_updated": "2026-07-10T13:29:55.755Z",
      "publisher": "juniper",
      "title": "Junos OS: MX Series: Specific traffic causes an FPC to reset",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07441
      },
      "nvd": {
        "published": "2026-07-09T22:17:06.707",
        "lastModified": "2026-07-13T20:58:26.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57019",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Packet-size arithmetic trusts a crafted quantity and computes a buffer smaller than the subsequent access requires.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110079",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1369,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-57020",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.248Z",
      "date_published": "2026-07-09T21:05:07.368Z",
      "date_updated": "2026-07-10T13:29:08.357Z",
      "publisher": "juniper",
      "title": "Junos OS: QFX10000 Series: IPv6 multicast traffic received on non-IRB interfaces causes a multicast flood",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:U/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07441
      },
      "nvd": {
        "published": "2026-07-09T22:17:06.887",
        "lastModified": "2026-07-13T20:57:06.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57020",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "EVPN-VxLAN forwarding floods IPv6 multicast between spines and ESI leaves without terminating the cycle, forming an endless loop that saturates links.",
        "basis": [
          "CNA",
          "CWE-754"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110080",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 983,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57021",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.248Z",
      "date_published": "2026-07-09T21:05:45.214Z",
      "date_updated": "2026-07-10T14:28:45.161Z",
      "publisher": "juniper",
      "title": "Junos OS: SRX Series: If VPN compliance-check is configured an attacker can cause http-gk process crash",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y/R:A/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00336,
        "percentile": 0.26125
      },
      "nvd": {
        "published": "2026-07-09T22:17:07.057",
        "lastModified": "2026-07-13T20:33:08.187",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57021",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Junos http-gk writes beyond an allocated buffer while processing attacker-controlled network input.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110081",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 921,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-57022",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.248Z",
      "date_published": "2026-07-09T21:06:06.154Z",
      "date_updated": "2026-07-10T14:31:13.320Z",
      "publisher": "juniper",
      "title": "Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a TCP connection establishment by the affected device can crash the PFE",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/R:A/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:A/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21383
      },
      "nvd": {
        "published": "2026-07-09T22:17:07.233",
        "lastModified": "2026-07-14T16:54:04.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57022",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "A specific reply packet crashes and restarts the Junos PFE after the device initiates a TCP connection, while the public advisory does not reveal the exceptional condition that is mishandled.",
        "basis": [
          "CNA",
          "CWE-754"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110082",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 870,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-57023",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.248Z",
      "date_published": "2026-07-09T21:06:34.219Z",
      "date_updated": "2026-07-10T15:28:45.274Z",
      "publisher": "juniper",
      "title": "Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25648
      },
      "nvd": {
        "published": "2026-07-09T22:17:07.397",
        "lastModified": "2026-07-14T15:19:42.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57023",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The TCP proxy accepts a malformed TCP-header quantity that crashes flowd, although the exact header field is not public.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110083",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 823,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57024",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.248Z",
      "date_published": "2026-07-09T21:06:57.585Z",
      "date_updated": "2026-07-10T14:31:54.759Z",
      "publisher": "juniper",
      "title": "Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-694",
          "name": "Use of Multiple Resources with Duplicate Identifier",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/AU:Y/R:U/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15955
      },
      "nvd": {
        "published": "2026-07-09T22:17:07.553",
        "lastModified": "2026-07-14T15:16:42.397",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57024",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The IKE peer index wraps and reuses an identifier still assigned to another peer, driving repeated daemon crashes during later negotiations.",
        "basis": [
          "CNA",
          "CWE-694"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110084",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1284,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-57025",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.248Z",
      "date_published": "2026-07-09T21:07:20.486Z",
      "date_updated": "2026-07-16T08:26:17.852Z",
      "publisher": "juniper",
      "title": "Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning/ethernet-switching' command causes l2ald crash",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          },
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS Evolved"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-466",
          "name": "Return of Pointer Value Outside of Expected Range",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00098,
        "percentile": 0.00902
      },
      "nvd": {
        "published": "2026-07-09T22:17:07.747",
        "lastModified": "2026-07-16T09:16:18.650",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57025",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A function returns or consumes a pointer outside the storage region its caller expects, invalidating the subsequent memory access.",
        "basis": [
          "CNA",
          "CWE-466"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110085",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 888,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-57026",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.248Z",
      "date_published": "2026-07-09T21:07:44.855Z",
      "date_updated": "2026-07-10T14:33:07.076Z",
      "publisher": "juniper",
      "title": "Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1286",
          "name": "Improper Validation of Syntactic Correctness of Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25649
      },
      "nvd": {
        "published": "2026-07-09T22:17:07.923",
        "lastModified": "2026-07-14T15:03:23.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57026",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SIP ALG accepts a syntactically malformed INVITE instead of rejecting it, and the invalid form reaches a flowd crash-and-restart path.",
        "basis": [
          "CNA",
          "CWE-1286"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110086",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 776,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-57027",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.248Z",
      "date_published": "2026-07-09T21:08:07.684Z",
      "date_updated": "2026-07-10T14:33:33.977Z",
      "publisher": "juniper",
      "title": "Junos OS: EX4100 Series, EX4400: With sFlow configured in a VC scenario multicast traffic leads to an FPC crash",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06106
      },
      "nvd": {
        "published": "2026-07-09T22:17:08.093",
        "lastModified": "2026-07-13T20:26:30.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57027",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Cross-member multicast forwarding with sFlow retains packet buffers without releasing them, causing memory use to grow until the forwarding component restarts.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110087",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 830,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57028",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.248Z",
      "date_published": "2026-07-09T21:08:25.702Z",
      "date_updated": "2026-07-10T14:37:21.433Z",
      "publisher": "juniper",
      "title": "Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS Evolved"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-923",
          "name": "Improper Restriction of Communication Channel to Intended Endpoints",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/AU:Y/R:U/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.39999999999999947,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07516
      },
      "nvd": {
        "published": "2026-07-09T22:17:08.257",
        "lastModified": "2026-07-13T20:24:50.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57028",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Incorrect process initialization exposes an internal-only license-management port to unauthenticated network clients.",
        "basis": [
          "CNA",
          "CWE-923"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110088",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 499,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57029",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.249Z",
      "date_published": "2026-07-09T21:12:36.288Z",
      "date_updated": "2026-07-10T14:45:20.380Z",
      "publisher": "juniper",
      "title": "Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS Evolved"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-820",
          "name": "Missing Synchronization",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02194
      },
      "nvd": {
        "published": "2026-07-09T22:17:08.453",
        "lastModified": "2026-07-13T20:23:46.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57029",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A next-hop update can race the sFlow collector thread because both access the data without the required synchronization.",
        "basis": [
          "CNA",
          "CWE-820"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110089",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 801,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57030",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.249Z",
      "date_published": "2026-07-09T21:13:12.671Z",
      "date_updated": "2026-07-10T14:43:39.183Z",
      "publisher": "juniper",
      "title": "Junos OS: SRX Series: Flow sessions are not getting cleared leading to a DoS",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:U/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19551
      },
      "nvd": {
        "published": "2026-07-09T22:17:08.643",
        "lastModified": "2026-07-13T20:16:07.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57030",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A race while assigning a flow's removal timeout can replace the intended three-second value with an extremely large lifetime, causing invalid sessions to accumulate.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110090",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1664,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57031",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.249Z",
      "date_published": "2026-07-09T21:13:46.497Z",
      "date_updated": "2026-07-10T14:37:16.783Z",
      "publisher": "juniper",
      "title": "Junos OS: MX Series: For subscribers configured on static interfaces, input filters are not in effect",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/AU:Y/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00151,
        "percentile": 0.04794
      },
      "nvd": {
        "published": "2026-07-09T22:17:08.827",
        "lastModified": "2026-07-10T17:49:57.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57031",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The packet-forwarding path omits configured ingress filters for subscribers on the affected static interfaces.",
        "basis": [
          "CNA",
          "CWE-754"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110091",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 741,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-57032",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:27:00.249Z",
      "date_published": "2026-07-09T21:14:11.048Z",
      "date_updated": "2026-07-10T14:34:50.488Z",
      "publisher": "juniper",
      "title": "Junos OS: EX Series: Subscribing to an unsupported telemetry sensor path causes fxpc process crash",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-236",
          "name": "Improper Handling of Undefined Parameters",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15211
      },
      "nvd": {
        "published": "2026-07-09T22:17:09.007",
        "lastModified": "2026-07-13T20:07:12.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57032",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The packet-forwarding engine does not reject an unsupported telemetry sensor path before dereferencing undefined handling state.",
        "basis": [
          "CNA",
          "CWE-236"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110092",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 860,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57054",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T16:55:07.912Z",
      "date_published": "2026-07-09T21:14:33.905Z",
      "date_updated": "2026-07-10T14:34:09.815Z",
      "publisher": "juniper",
      "title": "Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs",
      "affected": {
        "vendors": [
          "Juniper Networks"
        ],
        "products": [
          {
            "vendor": "Juniper Networks",
            "product": "Junos OS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-706",
          "name": "Use of Incorrectly-Resolved Name or Reference",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/AU:Y/RE:M"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X"
        },
        {
          "source": "NVD:sirt@juniper.net",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14141
      },
      "nvd": {
        "published": "2026-07-09T22:17:09.180",
        "lastModified": "2026-07-13T20:03:52.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57054",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The URL filter resolves a specially formatted URL to the wrong reference and forwards a request that its configured policy should block.",
        "basis": [
          "CNA",
          "CWE-706"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://supportportal.juniper.net/JSA110093",
          "host": "supportportal.juniper.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 837,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-57073",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T17:59:40.467Z",
      "date_published": "2026-07-16T16:15:16.551Z",
      "date_updated": "2026-07-17T12:44:26.715Z",
      "publisher": "CPANSec",
      "title": "HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead",
      "affected": {
        "vendors": [
          "CODECHILD"
        ],
        "products": [
          {
            "vendor": "CODECHILD",
            "product": "HTML::Bare"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00422,
        "percentile": 0.34756
      },
      "nvd": {
        "published": "2026-07-16T17:16:58.117",
        "lastModified": "2026-07-17T13:18:58.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57073",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HTML::Bare uses an attacker-influenced length or index without proving it lies inside the backing object, allowing a read beyond valid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nanoscopic/perl-HTML-Bare/pull/2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://security.metacpan.org/patches/H/HTML-Bare/0.02/CVE-2026-57073-r1.patch",
          "host": "security.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://security.metacpan.org/patches/H/HTML-Bare/0.04/CVE-2026-57073-r2.patch",
          "host": "security.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/16/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57074",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T17:59:40.467Z",
      "date_published": "2026-07-16T16:15:34.033Z",
      "date_updated": "2026-07-17T18:07:06.943Z",
      "publisher": "CPANSec",
      "title": "XML::Bare versions through 0.53 for Perl have an unbounded character lookahead",
      "affected": {
        "vendors": [
          "CODECHILD"
        ],
        "products": [
          {
            "vendor": "CODECHILD",
            "product": "XML::Bare"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33062
      },
      "nvd": {
        "published": "2026-07-16T17:16:58.213",
        "lastModified": "2026-07-17T19:17:17.263",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57074",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "parserc_parse looks ahead for multicharacter XML tokens without checking that each offset remains inside the input buffer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nanoscopic/perl-XML-Bare/pull/1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://security.metacpan.org/patches/X/XML-Bare/0.53/CVE-2026-57074-r1.patch",
          "host": "security.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/16/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57075",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:02:32.994Z",
      "date_published": "2026-07-16T21:39:22.991Z",
      "date_updated": "2026-07-17T13:08:37.487Z",
      "publisher": "CPANSec",
      "title": "YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec",
      "affected": {
        "vendors": [
          "TODDR"
        ],
        "products": [
          {
            "vendor": "TODDR",
            "product": "YAML::Syck"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00374,
        "percentile": 0.3016
      },
      "nvd": {
        "published": "2026-07-16T22:17:43.447",
        "lastModified": "2026-07-17T15:07:41.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57075",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "YAML::Syck uses a signed byte as an index into its Base64 lookup table, so a high-bit input byte reads before the table.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/TODDR/YAML-Syck-1.47/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/17/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 671,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57076",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:02:32.995Z",
      "date_published": "2026-07-16T21:40:59.686Z",
      "date_updated": "2026-07-17T13:07:23.790Z",
      "publisher": "CPANSec",
      "title": "YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor",
      "affected": {
        "vendors": [
          "TODDR"
        ],
        "products": [
          {
            "vendor": "TODDR",
            "product": "YAML::Syck"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02569
      },
      "nvd": {
        "published": "2026-07-16T22:17:43.550",
        "lastModified": "2026-07-17T15:07:41.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57076",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A YAML anchor name is owned both by a node and the anchors table, so freeing the node leaves the table key dangling for a later comparison.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/TODDR/YAML-Syck-1.47/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/17/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 703,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57077",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:02:32.995Z",
      "date_published": "2026-07-16T21:41:52.038Z",
      "date_updated": "2026-07-17T13:05:34.286Z",
      "publisher": "CPANSec",
      "title": "YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len",
      "affected": {
        "vendors": [
          "TODDR"
        ],
        "products": [
          {
            "vendor": "TODDR",
            "product": "YAML::Syck"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00141,
        "percentile": 0.0392
      },
      "nvd": {
        "published": "2026-07-16T22:17:43.650",
        "lastModified": "2026-07-17T15:07:41.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57077",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "YAML Syck scans for a newline past the lexer buffer because it checks neither the terminator nor the following byte bound.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/TODDR/YAML-Syck-1.47/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-11683",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 600,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57083",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.052Z",
      "date_published": "2026-07-14T17:09:29.597Z",
      "date_updated": "2026-08-03T22:57:50.683Z",
      "publisher": "microsoft",
      "title": "Windows Media Photo Codec Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00495,
        "percentile": 0.39772
      },
      "nvd": {
        "published": "2026-07-14T18:18:32.323",
        "lastModified": "2026-07-22T16:18:29.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57083",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Codecs Library exposes residual data from an uninitialized resource.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57083",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-57084",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.053Z",
      "date_published": "2026-07-14T17:09:30.158Z",
      "date_updated": "2026-08-03T22:57:51.230Z",
      "publisher": "microsoft",
      "title": "Windows File Explorer Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00518,
        "percentile": 0.41189
      },
      "nvd": {
        "published": "2026-07-14T18:18:32.520",
        "lastModified": "2026-07-22T16:18:29.760",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57084",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57084",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 119,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-57085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.053Z",
      "date_published": "2026-07-14T17:09:34.116Z",
      "date_updated": "2026-08-03T22:58:02.395Z",
      "publisher": "microsoft",
      "title": "Windows Print Spooler Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19498
      },
      "nvd": {
        "published": "2026-07-14T18:18:32.713",
        "lastModified": "2026-07-22T16:18:29.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57085",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57085",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-57087",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.053Z",
      "date_published": "2026-07-14T17:09:35.418Z",
      "date_updated": "2026-08-03T22:58:04.075Z",
      "publisher": "microsoft",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.0000000000000009,
      "epss": {
        "score": 0.00802,
        "percentile": 0.53107
      },
      "nvd": {
        "published": "2026-07-14T18:18:32.903",
        "lastModified": "2026-07-22T16:18:30.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57087",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected handler writes attacker-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57087",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-57088",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.053Z",
      "date_published": "2026-07-14T17:09:35.940Z",
      "date_updated": "2026-08-03T22:58:04.617Z",
      "publisher": "microsoft",
      "title": "Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19999
      },
      "nvd": {
        "published": "2026-07-14T18:18:33.080",
        "lastModified": "2026-07-23T05:16:37.763",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57088",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57088",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-57089",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.053Z",
      "date_published": "2026-07-14T17:09:33.635Z",
      "date_updated": "2026-08-03T22:57:54.539Z",
      "publisher": "microsoft",
      "title": "Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 2.3000000000000007,
      "epss": {
        "score": 0.0061,
        "percentile": 0.45783
      },
      "nvd": {
        "published": "2026-07-14T18:18:33.237",
        "lastModified": "2026-07-23T05:16:37.897",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57089",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A reachable path retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416",
          "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57089"
        ],
        "deepDive": true,
        "notes": "The linked MSRC detail surface was inspected but did not expose the srvnet.sys object's allocation, release, or later use; the public record supports use-after-free in the SMB network path without a source-level lifetime trace."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57089",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-57090",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.053Z",
      "date_published": "2026-07-14T17:09:31.906Z",
      "date_updated": "2026-08-03T22:57:52.976Z",
      "publisher": "microsoft",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00812,
        "percentile": 0.53459
      },
      "nvd": {
        "published": "2026-07-14T18:18:33.430",
        "lastModified": "2026-07-22T16:18:30.560",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57090",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57090",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-57091",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.053Z",
      "date_published": "2026-07-14T17:09:33.077Z",
      "date_updated": "2026-08-03T22:57:53.992Z",
      "publisher": "microsoft",
      "title": "Windows File History Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28767
      },
      "nvd": {
        "published": "2026-07-14T18:18:33.620",
        "lastModified": "2026-07-22T16:18:30.730",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57091",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows File History Service copies attacker-influenced data beyond a stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57091",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-57092",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.053Z",
      "date_published": "2026-07-14T17:09:34.750Z",
      "date_updated": "2026-08-03T22:58:03.597Z",
      "publisher": "microsoft",
      "title": "Microsoft Windows VMSwitch Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01184,
        "percentile": 0.64728
      },
      "nvd": {
        "published": "2026-07-14T18:18:33.810",
        "lastModified": "2026-07-22T16:18:30.897",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57092",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57092",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-57093",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.053Z",
      "date_published": "2026-07-14T17:09:36.579Z",
      "date_updated": "2026-08-03T22:58:05.274Z",
      "publisher": "microsoft",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17607
      },
      "nvd": {
        "published": "2026-07-14T18:18:33.997",
        "lastModified": "2026-07-22T16:18:31.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57093",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows Ancillary Function Driver dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA record",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57093",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-57094",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.053Z",
      "date_published": "2026-07-14T17:09:32.451Z",
      "date_updated": "2026-08-03T22:57:53.523Z",
      "publisher": "microsoft",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00829,
        "percentile": 0.54002
      },
      "nvd": {
        "published": "2026-07-14T18:18:34.170",
        "lastModified": "2026-07-22T16:18:31.267",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57094",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 writes attacker-controlled data beyond a heap buffer boundary.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57094",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-57095",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.053Z",
      "date_published": "2026-07-14T17:09:31.359Z",
      "date_updated": "2026-08-03T22:57:52.426Z",
      "publisher": "microsoft",
      "title": "Win32k Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00456,
        "percentile": 0.37336
      },
      "nvd": {
        "published": "2026-07-14T18:18:34.347",
        "lastModified": "2026-07-22T16:18:31.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57095",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Win32K exposes sensitive information during a local operation, but Microsoft does not identify the value or output path.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57095",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-57096",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.053Z",
      "date_published": "2026-07-14T17:09:37.235Z",
      "date_updated": "2026-08-03T22:58:05.811Z",
      "publisher": "microsoft",
      "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23436
      },
      "nvd": {
        "published": "2026-07-14T18:18:34.520",
        "lastModified": "2026-07-22T16:18:31.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57096",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 10 Version 1607, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57096",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-57097",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.054Z",
      "date_published": "2026-07-14T17:05:16.417Z",
      "date_updated": "2026-08-03T22:53:36.103Z",
      "publisher": "microsoft",
      "title": "Microsoft XML Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-426",
          "name": "Untrusted Search Path",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0.39999999999999947,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24605
      },
      "nvd": {
        "published": "2026-07-14T17:17:10.630",
        "lastModified": "2026-07-22T16:18:31.817",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57097",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The loader searches an attacker-influenceable path for trusted code or data instead of resolving a fixed trusted location.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-426"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57097",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-57100",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.054Z",
      "date_published": "2026-07-02T22:18:55.289Z",
      "date_updated": "2026-08-03T22:52:41.658Z",
      "publisher": "microsoft",
      "title": "Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Entra Provisioning Service"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00653,
        "percentile": 0.47747
      },
      "nvd": {
        "published": "2026-07-02T23:16:51.267",
        "lastModified": "2026-07-08T18:34:25.597",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57100",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Entra SyncFabric follows an attacker-controlled server-side destination and can reach network resources outside the intended trust boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57100",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 155,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57101",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.054Z",
      "date_published": "2026-07-14T17:09:37.912Z",
      "date_updated": "2026-08-03T22:58:06.299Z",
      "publisher": "microsoft",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Visual Studio Code"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36332
      },
      "nvd": {
        "published": "2026-07-14T18:18:34.850",
        "lastModified": "2026-07-16T15:42:04.420",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57101",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Visual Studio Code rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57101",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Product",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57102",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.054Z",
      "date_published": "2026-07-14T17:09:38.545Z",
      "date_updated": "2026-08-03T22:58:06.859Z",
      "publisher": "microsoft",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Visual Studio Code"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00767,
        "percentile": 0.51995
      },
      "nvd": {
        "published": "2026-07-14T18:18:34.977",
        "lastModified": "2026-07-16T15:34:36.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57102",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application loads executable functionality from an untrusted control sphere without verifying its provenance.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57102",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Product",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 155,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57106",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.054Z",
      "date_published": "2026-07-24T14:36:53.082Z",
      "date_updated": "2026-08-03T22:59:15.735Z",
      "publisher": "microsoft",
      "title": "Data Quality Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Purview Data Governance"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00901,
        "percentile": 0.5622
      },
      "nvd": {
        "published": "2026-07-24T15:18:39.633",
        "lastModified": "2026-07-29T15:00:03.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57106",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Microsoft Purview Data Governance request path accepts an attacker-controlled destination or redirect without constraining the resolved server-side network target.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57106",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57107",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.054Z",
      "date_published": "2026-07-14T17:05:17.033Z",
      "date_updated": "2026-08-03T22:53:36.568Z",
      "publisher": "microsoft",
      "title": "Windows Admin Center Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows Admin Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11882
      },
      "nvd": {
        "published": "2026-07-14T17:17:10.860",
        "lastModified": "2026-07-21T18:15:45.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57107",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Windows Admin Center contains an authentication failure, but the public record does not identify the credential path or protected operation.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57107",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57108",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T18:29:51.054Z",
      "date_published": "2026-07-14T17:09:39.087Z",
      "date_updated": "2026-08-03T22:58:07.407Z",
      "publisher": "microsoft",
      "title": ".NET Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": ".NET 10.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 8.0"
          },
          {
            "vendor": "Microsoft",
            "product": ".NET 9.0"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01105,
        "percentile": 0.62582
      },
      "nvd": {
        "published": "2026-07-14T18:18:35.150",
        "lastModified": "2026-07-22T21:18:01.023",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57108",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in .NET 10.0, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57108",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 138,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-57111",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-23T21:53:48.681Z",
      "date_published": "2026-07-09T07:09:05.827Z",
      "date_updated": "2026-07-09T13:38:56.274Z",
      "publisher": "apache",
      "title": "Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Helix REST"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1385",
          "name": "Missing Origin Validation in WebSockets",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18914
      },
      "nvd": {
        "published": "2026-07-09T08:16:48.957",
        "lastModified": "2026-07-09T19:45:35.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57111",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A permissive CORS policy lets a cross-origin caller read responses that should remain origin-bound.",
        "basis": [
          "CNA",
          "CWE-1385"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/wy2yv90lvqzx46vkg35xrtfddffq9cfj",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/08/11",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 708,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57156",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T01:45:48.698Z",
      "date_published": "2026-07-10T19:52:25.553Z",
      "date_updated": "2026-07-15T03:59:00.856Z",
      "publisher": "GitHub_M",
      "title": "FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsing",
      "affected": {
        "vendors": [
          "FreeRDP"
        ],
        "products": [
          {
            "vendor": "FreeRDP",
            "product": "FreeRDP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.200000000000001,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34379
      },
      "nvd": {
        "published": "2026-07-10T20:16:48.257",
        "lastModified": "2026-07-15T05:17:19.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57156",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "update_read_delta_points() multiplies an attacker-controlled count in 32-bit size arithmetic, allocates the wrapped result, and initializes beyond that heap allocation.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v5wf-j8j4-77h7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/pull/12938",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/commit/487f35daccb36a6224e530dcd8fa60850825f823",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/releases/tag/3.28.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 429,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57157",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T01:45:48.698Z",
      "date_published": "2026-07-10T19:51:00.559Z",
      "date_updated": "2026-07-10T20:57:52.054Z",
      "publisher": "GitHub_M",
      "title": "Out-of-bounds read in the camera device enumerator server (rdpecam) via unterminated DeviceName / VirtualChannelName",
      "affected": {
        "vendors": [
          "FreeRDP"
        ],
        "products": [
          {
            "vendor": "FreeRDP",
            "product": "FreeRDP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00368,
        "percentile": 0.29471
      },
      "nvd": {
        "published": "2026-07-10T20:16:48.387",
        "lastModified": "2026-07-13T22:44:25.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57157",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FreeRDP can read beyond the valid bounds of an input or object allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-47fr-jw86-c3fj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/pull/12930",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/pull/12945",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/commit/02991e7b3cc0b9800b09030c0e9c80bab877d668",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/commit/bd789a31cb794750dbe5e7c0e205981074cb681a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/releases/tag/3.28.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 486,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T01:45:48.698Z",
      "date_published": "2026-07-10T19:49:03.646Z",
      "date_updated": "2026-07-14T13:54:51.055Z",
      "publisher": "GitHub_M",
      "title": "FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-23530",
      "affected": {
        "vendors": [
          "FreeRDP"
        ],
        "products": [
          {
            "vendor": "FreeRDP",
            "product": "FreeRDP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 4,
      "epss": {
        "score": 0.00459,
        "percentile": 0.3756
      },
      "nvd": {
        "published": "2026-07-10T20:16:48.523",
        "lastModified": "2026-07-14T15:17:05.717",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57158",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A length, offset, or termination error makes the program read beyond the end of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mp3f-59pg-c5pp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/pull/12952",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/commit/a7e797626fcb7f1d556ce63febb84f9f4a822731",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/releases/tag/3.28.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57167",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T01:47:55.285Z",
      "date_published": "2026-07-10T16:37:59.631Z",
      "date_updated": "2026-07-10T17:42:51.158Z",
      "publisher": "GitHub_M",
      "title": "PeerTube: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
      "affected": {
        "vendors": [
          "Chocobozzz"
        ],
        "products": [
          {
            "vendor": "Chocobozzz",
            "product": "PeerTube"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-80",
          "name": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18879
      },
      "nvd": {
        "published": "2026-07-10T17:17:01.430",
        "lastModified": "2026-07-10T18:56:43.823",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57167",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches PeerTube page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-80"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Chocobozzz/PeerTube/security/advisories/GHSA-jxwq-h9xv-hr28",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Chocobozzz/PeerTube/commit/45394d701b08e87d72b8f0c1866b881f2becbde3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Chocobozzz/PeerTube/releases/tag/v8.2.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57172",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T01:47:55.285Z",
      "date_published": "2026-07-07T20:33:26.555Z",
      "date_updated": "2026-07-08T13:37:38.831Z",
      "publisher": "GitHub_M",
      "title": "DataEase: Hardcoded JWT Signing Secret in ShareLink",
      "affected": {
        "vendors": [
          "dataease"
        ],
        "products": [
          {
            "vendor": "dataease",
            "product": "dataease"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-321",
          "name": "Use of Hard-coded Cryptographic Key",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21107
      },
      "nvd": {
        "published": "2026-07-07T21:17:28.223",
        "lastModified": "2026-07-08T15:07:37.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57172",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ShareSecretManage signs share-link JWTs with a public hardcoded default key that attackers can reuse after revocation.",
        "basis": [
          "CNA",
          "CWE-321",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dataease/dataease/security/advisories/GHSA-7cpg-f4cj-7pgm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dataease/dataease/commit/356e83b518603f5612104760ced80aae8fc5d675",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 465,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57205",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:00:46.801Z",
      "date_published": "2026-07-16T15:12:46.826Z",
      "date_updated": "2026-07-16T15:25:26.441Z",
      "publisher": "GitHub_M",
      "title": "SimpleChat: Authenticated users can access other users' profile metadata through user IDOR endpoints",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "simplechat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.005,
        "percentile": 0.40073
      },
      "nvd": {
        "published": "2026-07-16T16:19:14.050",
        "lastModified": "2026-07-16T17:13:54.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57205",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The profile endpoints accept a user_id and read that user's Cosmos DB document without checking object-level authorization.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/simplechat/security/advisories/GHSA-x2jq-2m5m-65m4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/simplechat/blob/main/docs/explanation/fixes/USER_PROFILE_IDOR_AUTHORIZATION_FIX.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/simplechat/releases/tag/v0.250.001",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57206",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:00:46.801Z",
      "date_published": "2026-07-16T15:17:05.558Z",
      "date_updated": "2026-07-16T18:53:39.456Z",
      "publisher": "GitHub_M",
      "title": "SimpleChat plugin validation endpoints missing authentication and authorization",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "simplechat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00891,
        "percentile": 0.55913
      },
      "nvd": {
        "published": "2026-07-16T16:19:14.217",
        "lastModified": "2026-07-16T19:16:50.820",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57206",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Plugin validation routes declare authentication only in Swagger metadata and omit runtime login, user, or administrator decorators before executing validation and repair actions.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/simplechat/security/advisories/GHSA-g6gr-xp46-hrmj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/simplechat/blob/main/docs/explanation/fixes/PLUGIN_VALIDATION_ROUTE_AUTH_FIX.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/simplechat/releases/tag/v0.250.001",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 722,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57211",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:00:46.802Z",
      "date_published": "2026-07-10T20:16:01.719Z",
      "date_updated": "2026-07-13T16:13:38.702Z",
      "publisher": "GitHub_M",
      "title": "RabbitMQ: UNC SSRF affecting the management UI on Windows",
      "affected": {
        "vendors": [
          "rabbitmq"
        ],
        "products": [
          {
            "vendor": "rabbitmq",
            "product": "rabbitmq-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-36",
          "name": "Absolute Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 3.5,
      "epss": {
        "score": 0.00429,
        "percentile": 0.35288
      },
      "nvd": {
        "published": "2026-07-10T21:16:58.007",
        "lastModified": "2026-07-13T22:40:24.073",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57211",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The static-file handler resolves URL-encoded backslashes as a Windows UNC path before validating that the path stays local.",
        "basis": [
          "CNA",
          "CWE-36",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-7v84-m3g5-vxq6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15803",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/39c3a8e9c71da0403d8dfc13f700e60c936e3682",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/6730797f6a34b4e8308cea60adf1243857e70204",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57212",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:21:33.809Z",
      "date_published": "2026-07-10T20:15:28.422Z",
      "date_updated": "2026-07-13T18:55:35.052Z",
      "publisher": "GitHub_M",
      "title": "RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size",
      "affected": {
        "vendors": [
          "rabbitmq"
        ],
        "products": [
          {
            "vendor": "rabbitmq",
            "product": "rabbitmq-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00433,
        "percentile": 0.3563
      },
      "nvd": {
        "published": "2026-07-10T21:16:58.150",
        "lastModified": "2026-07-13T22:37:54.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57212",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RabbitMQ checks accumulated body size before the last chunk but never checks the final combined JSON body size.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-5cmq-vp28-xqrj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15712",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15714",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/3976d148901bdfa82e1cd60b7a4534e073266ba5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/b8fc2ef7c50a2797d15e1ea7cf34f290032303bb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 378,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57213",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:21:33.810Z",
      "date_published": "2026-07-10T20:14:30.972Z",
      "date_updated": "2026-07-14T13:58:52.669Z",
      "publisher": "GitHub_M",
      "title": "RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering",
      "affected": {
        "vendors": [
          "rabbitmq"
        ],
        "products": [
          {
            "vendor": "rabbitmq",
            "product": "rabbitmq-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16611
      },
      "nvd": {
        "published": "2026-07-10T21:16:58.280",
        "lastModified": "2026-07-14T15:17:05.840",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57213",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In rabbitmq-server, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-qxrp-7cmp-p77h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15708",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15711",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/33dedfe4fd53ff009cc67ab36358d0624c6b2e53",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/c2d0d69edf01efbd6e87dfb250c373a32da957f8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57214",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:21:33.810Z",
      "date_published": "2026-07-10T20:18:15.810Z",
      "date_updated": "2026-07-13T15:04:23.857Z",
      "publisher": "GitHub_M",
      "title": "RabbitMQ: Stored XSS in RabbitMQ management UI",
      "affected": {
        "vendors": [
          "rabbitmq"
        ],
        "products": [
          {
            "vendor": "rabbitmq",
            "product": "rabbitmq-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12531
      },
      "nvd": {
        "published": "2026-07-10T21:16:58.423",
        "lastModified": "2026-07-13T21:27:48.487",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57214",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "rabbitmq-server places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6jfq-prw2-7rwp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15606",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15608",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/b0027b6c1ae5b869d876e211efe6189ffd92b5c2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/b267a290dd89e42c6e0256f46fc273a8adb7f3ec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57215",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:21:33.810Z",
      "date_published": "2026-07-10T20:23:26.132Z",
      "date_updated": "2026-07-13T18:08:05.307Z",
      "publisher": "GitHub_M",
      "title": "RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom",
      "affected": {
        "vendors": [
          "rabbitmq"
        ],
        "products": [
          {
            "vendor": "rabbitmq",
            "product": "rabbitmq-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.8000000000000007,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30996
      },
      "nvd": {
        "published": "2026-07-10T21:16:58.550",
        "lastModified": "2026-07-13T21:27:14.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57215",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "RabbitMQ accepts direct-reply-to bindings that its Khepri deletion path does not remove, leaving persistent routes after unbind.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-5cq3-v9jx-p3x3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15935",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15938",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/9055500d10ca7629dd2b051c6dc7a4b0bb8f6734",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/c84f3c880e0f22b49c01237cf8f86e176eeadc72",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 407,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57216",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:21:33.810Z",
      "date_published": "2026-07-10T20:20:33.269Z",
      "date_updated": "2026-07-13T14:01:23.697Z",
      "publisher": "GitHub_M",
      "title": "RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks",
      "affected": {
        "vendors": [
          "rabbitmq"
        ],
        "products": [
          {
            "vendor": "rabbitmq",
            "product": "rabbitmq-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 3.2,
      "epss": {
        "score": 0.00504,
        "percentile": 0.4031
      },
      "nvd": {
        "published": "2026-07-10T21:16:58.677",
        "lastModified": "2026-07-13T21:09:20.123",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57216",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "RabbitMQ applies the loopback restriction to the backend listener address instead of the PROXY-protocol client address, admitting remote guest sessions.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-36m6-588r-vqcw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15936",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15940",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/7273c9eb6920abcde17b892dbe97ccaf906ead47",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/9f8c39fcf0acbc43080ee7017a62a02832114112",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57217",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:21:33.810Z",
      "date_published": "2026-07-10T20:25:29.498Z",
      "date_updated": "2026-07-13T15:58:13.432Z",
      "publisher": "GitHub_M",
      "title": "RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass",
      "affected": {
        "vendors": [
          "rabbitmq"
        ],
        "products": [
          {
            "vendor": "rabbitmq",
            "product": "rabbitmq-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27867
      },
      "nvd": {
        "published": "2026-07-10T21:16:58.810",
        "lastModified": "2026-07-13T21:04:14.127",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57217",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A Khepri topic-permission lookup error collapses to undefined, which the internal authorization backend treats as allow.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-gpvw-75h5-3wvx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15941",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/15943",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/94f1d33a70fcfa09006649599e79fc92786a2d36",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/ce1f682aa6b398820c5e3ce1ff7435184027c82c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57218",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:21:33.810Z",
      "date_published": "2026-07-10T20:21:30.331Z",
      "date_updated": "2026-07-13T18:55:32.041Z",
      "publisher": "GitHub_M",
      "title": "RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure",
      "affected": {
        "vendors": [
          "rabbitmq"
        ],
        "products": [
          {
            "vendor": "rabbitmq",
            "product": "rabbitmq-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27867
      },
      "nvd": {
        "published": "2026-07-10T21:16:58.937",
        "lastModified": "2026-07-13T20:54:58.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57218",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "RabbitMQ leaves an existing consumer authorized after its OAuth token expires or is refreshed to narrower scopes.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-wmrr-4h5v-5ch7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/16092",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/16097",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/501ad947cd6bbcc9486fe96e0d073992bfe52cc4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/db20d6c0fcf3056030f244b5adab0d45c0db0c9e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 368,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57219",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:21:33.810Z",
      "date_published": "2026-07-10T20:22:26.516Z",
      "date_updated": "2026-07-29T19:26:44.962Z",
      "publisher": "GitHub_M",
      "title": "RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations",
      "affected": {
        "vendors": [
          "rabbitmq"
        ],
        "products": [
          {
            "vendor": "rabbitmq",
            "product": "rabbitmq-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00784,
        "percentile": 0.52517
      },
      "nvd": {
        "published": "2026-07-10T21:16:59.060",
        "lastModified": "2026-07-29T20:17:04.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57219",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "RabbitMQ exposes an obsolete OAuth configuration endpoint without the authorization needed to protect the client secret.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-pj24-8j6m-vq9q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/16083",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/16086",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/98b1daf740237c85941e8addcbea6e74f4a2743c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/aa387c4451e7b674df3e3ba89df86a99d697cc7f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:21:33.810Z",
      "date_published": "2026-07-10T20:19:23.162Z",
      "date_updated": "2026-07-13T16:20:19.134Z",
      "publisher": "GitHub_M",
      "title": "RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS",
      "affected": {
        "vendors": [
          "rabbitmq"
        ],
        "products": [
          {
            "vendor": "rabbitmq",
            "product": "rabbitmq-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00547,
        "percentile": 0.4279
      },
      "nvd": {
        "published": "2026-07-10T21:16:59.180",
        "lastModified": "2026-07-13T20:49:24.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57220",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths and consume broker memory in rabbit_stream_core.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-f364-87q5-j35q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/16171",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/16173",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/595ec28fa1621b1f2c28124e4e0466a8ad963547",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/773a49c4921e8be990262a2d609c35916825679e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 385,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57221",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:21:33.810Z",
      "date_published": "2026-07-10T20:24:27.921Z",
      "date_updated": "2026-07-13T18:05:48.847Z",
      "publisher": "GitHub_M",
      "title": "RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users",
      "affected": {
        "vendors": [
          "rabbitmq"
        ],
        "products": [
          {
            "vendor": "rabbitmq",
            "product": "rabbitmq-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33758
      },
      "nvd": {
        "published": "2026-07-10T21:16:59.327",
        "lastModified": "2026-07-13T20:44:52.037",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57221",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read queue message and consumer counts.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-9q2j-2hq8-22r2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/16085",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/pull/16090",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/709a14e49e06c138a8cd672c9809ca34a2767962",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/commit/dc3d1aa4f5c3331a425ee599b45be9423a2e83fc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 422,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57230",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:21:33.811Z",
      "date_published": "2026-07-10T20:47:31.404Z",
      "date_updated": "2026-07-13T16:02:46.498Z",
      "publisher": "GitHub_M",
      "title": "OpenReplay: Authenticated ClickHouse SQL injection via session search",
      "affected": {
        "vendors": [
          "openreplay"
        ],
        "products": [
          {
            "vendor": "openreplay",
            "product": "openreplay"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10868
      },
      "nvd": {
        "published": "2026-07-10T21:16:59.450",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57230",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The session-search API inserts authenticated user input into two ClickHouse query positions without escaping or parameters.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openreplay/openreplay/security/advisories/GHSA-vxf8-j7jx-p65x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/openreplay/openreplay/pull/4715",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openreplay/openreplay/commit/ae8de6893250dd41175c6b2d312545c515fa5a16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openreplay/openreplay/releases/tag/v1.27.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 525,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T02:21:33.811Z",
      "date_published": "2026-07-31T18:29:53.924Z",
      "date_updated": "2026-08-03T17:24:45.798Z",
      "publisher": "GitHub_M",
      "title": "Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module",
      "affected": {
        "vendors": [
          "contao"
        ],
        "products": [
          {
            "vendor": "contao",
            "product": "contao"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00182,
        "percentile": 0.07991
      },
      "nvd": {
        "published": "2026-07-31T19:17:11.423",
        "lastModified": "2026-08-03T18:16:39.847",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57232",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The feed reader passes backend-configured URLs directly to the HTTP client without restricting schemes, loopback, private, or metadata destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/contao/contao/security/advisories/GHSA-87mg-5grr-rhwh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/contao/contao/commit/27f6201809553bee767dcef15535bb8f0f4eac5f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/contao/contao/commit/53b939ff2c4718e3a1d7c54ddd8886e9370618e4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 961,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57237",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:15.648Z",
      "date_published": "2026-07-08T07:36:06.219Z",
      "date_updated": "2026-07-08T13:15:21.343Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01883
      },
      "nvd": {
        "published": "2026-07-08T09:16:31.577",
        "lastModified": "2026-07-09T14:20:34.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57237",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A reachable path retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-57238",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:15.648Z",
      "date_published": "2026-07-08T07:36:28.457Z",
      "date_updated": "2026-07-08T13:18:08.981Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01852
      },
      "nvd": {
        "published": "2026-07-08T09:16:31.693",
        "lastModified": "2026-07-09T14:22:01.103",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57238",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Foxit PDF Editor accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57239",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:15.648Z",
      "date_published": "2026-07-08T07:36:33.186Z",
      "date_updated": "2026-07-09T03:55:40.047Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Local Privilege Escalation",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-427",
          "name": "Uncontrolled Search Path Element",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.39999999999999947,
      "epss": {
        "score": 0.0017,
        "percentile": 0.0661
      },
      "nvd": {
        "published": "2026-07-08T09:16:31.817",
        "lastModified": "2026-07-09T14:31:41.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57239",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A privileged Foxit process locates and executes an executable file from a path controllable by a low-privileged user.",
        "basis": [
          "CNA",
          "CWE-427"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57240",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:15.648Z",
      "date_published": "2026-07-08T07:36:31.636Z",
      "date_updated": "2026-07-08T12:20:15.388Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Form Field Use-After-Free Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02885
      },
      "nvd": {
        "published": "2026-07-08T09:16:31.927",
        "lastModified": "2026-07-09T14:22:30.227",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57240",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fields are deleted while stale pointers to them remain available for later use.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57241",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:15.648Z",
      "date_published": "2026-07-08T07:36:26.902Z",
      "date_updated": "2026-07-08T13:17:27.611Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01301
      },
      "nvd": {
        "published": "2026-07-08T09:16:32.040",
        "lastModified": "2026-07-09T14:28:24.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57241",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Page objects lose synchronization while the renderer continues to trust a stale page count and reads beyond the valid page array.",
        "basis": [
          "CNA record",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57242",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:15.648Z",
      "date_published": "2026-07-08T07:36:25.247Z",
      "date_updated": "2026-07-08T13:16:35.128Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Page Use-After-Free Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01851
      },
      "nvd": {
        "published": "2026-07-08T09:16:32.153",
        "lastModified": "2026-07-09T14:21:18.657",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57242",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Foxit PDF Editor retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 286,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:15.648Z",
      "date_published": "2026-07-08T07:36:23.592Z",
      "date_updated": "2026-07-08T13:16:09.439Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01319
      },
      "nvd": {
        "published": "2026-07-08T09:16:32.267",
        "lastModified": "2026-07-09T14:23:13.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57243",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "JavaScript reentrancy changes document state while a page is formatted, leaving stale page metadata that is later dereferenced.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57244",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:15.649Z",
      "date_published": "2026-07-08T07:36:04.601Z",
      "date_updated": "2026-07-08T13:14:51.433Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Form Control Use-After-Free Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.0185
      },
      "nvd": {
        "published": "2026-07-08T09:16:32.387",
        "lastModified": "2026-07-09T13:22:48.437",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57244",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Form reset can reenter Foxit's synchronization traversal without verifying that the control object is still alive, leaving a stale pointer that is dereferenced.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 297,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-57245",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:15.649Z",
      "date_published": "2026-07-08T07:36:22.015Z",
      "date_updated": "2026-07-08T13:44:42.121Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Signature Hyperlink Use-After-Free Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01851
      },
      "nvd": {
        "published": "2026-07-08T09:16:32.503",
        "lastModified": "2026-07-09T13:14:08.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57245",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path can retain or dereference an object after its storage has been released, leaving a dangling reference.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 359,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:15.649Z",
      "date_published": "2026-07-08T07:36:20.437Z",
      "date_updated": "2026-07-08T12:37:10.445Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Signature Buffer Overflow Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04502
      },
      "nvd": {
        "published": "2026-07-08T09:16:32.620",
        "lastModified": "2026-07-09T13:01:38.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57246",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The signature plugin copies an abnormal string without validating its length, overflowing the destination buffer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57247",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:18.717Z",
      "date_published": "2026-07-08T07:36:03.024Z",
      "date_updated": "2026-07-08T13:14:30.233Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Field Use-After-Free Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01883
      },
      "nvd": {
        "published": "2026-07-08T09:16:32.737",
        "lastModified": "2026-07-09T12:58:46.753",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57247",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Foxit PDF Editor path retains or dereferences an object after its storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-57248",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:18.717Z",
      "date_published": "2026-07-08T07:36:18.835Z",
      "date_updated": "2026-07-08T12:38:26.513Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Annotation Improper Release Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-763",
          "name": "Release of Invalid Pointer or Reference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04462
      },
      "nvd": {
        "published": "2026-07-08T09:16:32.847",
        "lastModified": "2026-07-09T12:05:52.557",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57248",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A bounds, size, or lifetime error permits invalid memory access.",
        "basis": [
          "CNA",
          "CWE-763"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57249",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:18.717Z",
      "date_published": "2026-07-08T07:36:17.227Z",
      "date_updated": "2026-07-08T12:40:28.820Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01885
      },
      "nvd": {
        "published": "2026-07-08T09:16:32.960",
        "lastModified": "2026-07-09T12:04:47.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57249",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Foxit PDF Editor path retains or dereferences an object after the object's storage can be freed or reused.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57250",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:18.717Z",
      "date_published": "2026-07-08T07:36:01.416Z",
      "date_updated": "2026-07-08T13:13:58.987Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Form Field Use-After-Free Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01852
      },
      "nvd": {
        "published": "2026-07-08T09:16:33.070",
        "lastModified": "2026-07-09T13:10:49.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57250",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Reentrant PDF JavaScript invalidates a native object and a later call dereferences that freed object.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-57251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:18.717Z",
      "date_published": "2026-07-08T07:36:15.661Z",
      "date_updated": "2026-07-08T12:41:07.653Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Cloud Appearance Buffer Overflow Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01994
      },
      "nvd": {
        "published": "2026-07-08T09:16:33.180",
        "lastModified": "2026-07-09T13:00:26.617",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57251",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Foxit PDF Editor, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:18.717Z",
      "date_published": "2026-07-08T07:36:12.539Z",
      "date_updated": "2026-07-08T12:43:57.683Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.0185
      },
      "nvd": {
        "published": "2026-07-08T09:16:33.293",
        "lastModified": "2026-07-09T12:03:56.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57252",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachment panel to continue accessing invalid pointers, eventually leading to the application crashing.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57253",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:18.718Z",
      "date_published": "2026-07-08T07:36:14.101Z",
      "date_updated": "2026-07-08T12:43:06.097Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01319
      },
      "nvd": {
        "published": "2026-07-08T09:16:33.400",
        "lastModified": "2026-07-09T11:57:26.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57253",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the valid input or buffer boundary because its size check is incomplete.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57254",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:18.718Z",
      "date_published": "2026-07-08T07:36:10.974Z",
      "date_updated": "2026-07-08T12:46:02.325Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Annotation Type Confusion Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01852
      },
      "nvd": {
        "published": "2026-07-08T09:16:33.520",
        "lastModified": "2026-07-09T11:59:16.257",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57254",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Foxit PDF Editor accesses an object through an incompatible type, invalidating the layout or lifetime assumptions used by the access.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57255",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:18.718Z",
      "date_published": "2026-07-08T07:36:09.396Z",
      "date_updated": "2026-07-08T12:46:48.415Z",
      "publisher": "Foxit",
      "title": "Security vulnerability in Foxit PDF Editor/Reader — OOB Read via NaN-Bypass Clamp",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00109,
        "percentile": 0.01448
      },
      "nvd": {
        "published": "2026-07-08T09:16:33.647",
        "lastModified": "2026-07-09T11:53:28.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57255",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A length, offset, or termination error makes the program read beyond the end of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57256",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:18.718Z",
      "date_published": "2026-07-08T07:35:59.810Z",
      "date_updated": "2026-07-09T17:37:54.106Z",
      "publisher": "Foxit",
      "title": "Foxit Editor/Reader List Box Format Use-After-Free Vulnerability",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02705
      },
      "nvd": {
        "published": "2026-07-08T09:16:33.770",
        "lastModified": "2026-07-09T18:16:54.613",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57256",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Foxit PDF Editor accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2420",
          "host": "www.talosintelligence.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 473,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-57257",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:24.249Z",
      "date_published": "2026-07-08T07:35:58.222Z",
      "date_updated": "2026-07-08T12:39:33.187Z",
      "publisher": "Foxit",
      "title": "Security vulnerability in Foxit PDF Editor/Reader — PRC 3D BRep Renderer Heap OOB Read",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01318
      },
      "nvd": {
        "published": "2026-07-08T09:16:33.907",
        "lastModified": "2026-07-09T14:25:57.033",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57257",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PRC parser indexes an entity array without verifying that the entity index is within bounds.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-57258",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:24.249Z",
      "date_published": "2026-07-08T07:35:56.660Z",
      "date_updated": "2026-07-08T12:40:12.497Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader Crash via Malformed PRC 3D Stream",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01575
      },
      "nvd": {
        "published": "2026-07-08T09:16:34.030",
        "lastModified": "2026-07-09T14:30:06.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57258",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PRC parser assumes a constructed array contains elements and reads them without verifying the array bounds.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-57259",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:24.249Z",
      "date_published": "2026-07-08T07:36:07.818Z",
      "date_updated": "2026-07-08T13:15:43.861Z",
      "publisher": "Foxit",
      "title": "Foxit PDF Editor/Reader XDP XFA XXE arbitrary local file read",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12223
      },
      "nvd": {
        "published": "2026-07-08T09:16:34.157",
        "lastModified": "2026-07-09T14:28:47.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57259",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The XDP or XFA parser resolves attacker-defined XML external entities to local file paths and returns the referenced file content.",
        "basis": [
          "CNA",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 378,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57260",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T03:01:24.249Z",
      "date_published": "2026-07-08T07:35:55.012Z",
      "date_updated": "2026-07-08T12:47:34.866Z",
      "publisher": "Foxit",
      "title": "Security vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompression (Type Confusion / Invalid Pointer Dereference)",
      "affected": {
        "vendors": [
          "Foxit Software Inc."
        ],
        "products": [
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Editor"
          },
          {
            "vendor": "Foxit Software Inc.",
            "product": "Foxit PDF Reader"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:14984358-7092-470d-8f34-ade47a7658a2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06686
      },
      "nvd": {
        "published": "2026-07-08T09:16:34.283",
        "lastModified": "2026-07-09T11:32:15.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57260",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Foxit PDF Editor path can write beyond the end of its allocated buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "host": "www.foxit.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-57264",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:03.740Z",
      "date_published": "2026-07-02T02:18:12.568Z",
      "date_updated": "2026-07-02T12:32:25.505Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12675
      },
      "nvd": {
        "published": "2026-07-02T04:17:11.777",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57264",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoWebPlayer uses a caller-provided index to access command arrays without validating that the index is in range.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 781,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57265",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:03.740Z",
      "date_published": "2026-07-02T02:18:47.724Z",
      "date_updated": "2026-07-02T12:29:34.294Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12674
      },
      "nvd": {
        "published": "2026-07-02T04:17:11.897",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57265",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In GeoWebPlayer, an attacker-controlled index or length permits a read beyond the valid memory region.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 779,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57266",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:03.740Z",
      "date_published": "2026-07-02T02:19:10.412Z",
      "date_updated": "2026-07-02T12:36:07.280Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12675
      },
      "nvd": {
        "published": "2026-07-02T04:17:12.017",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57266",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoWebPlayer uses an attacker-influenced length or index without proving it lies inside the backing object, allowing a read beyond valid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 784,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57267",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:03.740Z",
      "date_published": "2026-07-02T02:19:40.534Z",
      "date_updated": "2026-07-02T12:35:41.331Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13296
      },
      "nvd": {
        "published": "2026-07-02T04:17:12.170",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57267",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoWebPlayer uses an unchecked command index to access command arrays beyond their valid range.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 783,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57268",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:03.740Z",
      "date_published": "2026-07-02T02:20:11.291Z",
      "date_updated": "2026-07-02T12:35:19.946Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21577
      },
      "nvd": {
        "published": "2026-07-02T04:17:12.467",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57268",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoWebPlayer uses an attacker-controlled array index without confirming that it falls within the target array.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1855,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57269",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:03.740Z",
      "date_published": "2026-07-02T02:20:43.396Z",
      "date_updated": "2026-07-02T12:40:45.176Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15879
      },
      "nvd": {
        "published": "2026-07-02T04:17:12.793",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57269",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoWebPlayer's disconnect command uses an unchecked index to access command arrays outside their bounds.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 785,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57270",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:03.740Z",
      "date_published": "2026-07-02T02:21:11.097Z",
      "date_updated": "2026-07-02T12:40:13.858Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13296
      },
      "nvd": {
        "published": "2026-07-02T04:17:13.103",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57270",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoWebPlayer uses an unchecked websocket command index to read outside several command arrays.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 779,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57271",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:03.740Z",
      "date_published": "2026-07-02T02:21:46.247Z",
      "date_updated": "2026-07-02T12:39:38.730Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15269
      },
      "nvd": {
        "published": "2026-07-02T04:17:13.273",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57271",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoWebPlayer uses an attacker-controlled pause-command index without validating it against the available command array.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 404,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57272",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:03.740Z",
      "date_published": "2026-07-02T02:22:36.287Z",
      "date_updated": "2026-07-02T12:38:48.618Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16791
      },
      "nvd": {
        "published": "2026-07-02T04:17:13.423",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57272",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoWebPlayer uses a caller-supplied index to access several WebSocket command arrays without validating that the index is in range.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 781,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57273",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:03.740Z",
      "date_published": "2026-07-02T02:23:43.611Z",
      "date_updated": "2026-07-02T12:37:31.537Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21596
      },
      "nvd": {
        "published": "2026-07-02T04:17:13.570",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57273",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The connectInfo handler copies attacker-controlled JSON strings into fixed-size stack buffers without length checks.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2375",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 901,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57274",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:05.704Z",
      "date_published": "2026-07-02T02:24:11.611Z",
      "date_updated": "2026-07-02T12:36:12.891Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21596
      },
      "nvd": {
        "published": "2026-07-02T04:17:14.430",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57274",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The connectionInfo handler copies attacker-controlled JSON strings into fixed-size stack buffers without length limits.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2375",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 901,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57275",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:05.704Z",
      "date_published": "2026-07-02T02:24:39.554Z",
      "date_updated": "2026-07-02T12:34:58.181Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21597
      },
      "nvd": {
        "published": "2026-07-02T04:17:14.587",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57275",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The localhost WebSocket command handler copies JSON strings byte by byte into fixed-size buffers without enforcing a maximum length.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2375",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 897,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57276",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:05.704Z",
      "date_published": "2026-07-02T02:25:09.701Z",
      "date_updated": "2026-07-02T12:32:50.311Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21596
      },
      "nvd": {
        "published": "2026-07-02T04:17:14.763",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57276",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation fails to preserve a valid bound, initialization state, type, ownership rule, or object lifetime before memory access.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2375",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 898,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57277",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:05.704Z",
      "date_published": "2026-07-02T02:25:34.916Z",
      "date_updated": "2026-07-02T12:34:29.480Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20978
      },
      "nvd": {
        "published": "2026-07-02T04:17:15.157",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57277",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoWebPlayer writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2375",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 878,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57278",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T05:48:05.704Z",
      "date_published": "2026-07-02T02:26:09.613Z",
      "date_updated": "2026-07-02T12:33:49.256Z",
      "publisher": "GV",
      "title": "GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability",
      "affected": {
        "vendors": [
          "GeoVision Inc."
        ],
        "products": [
          {
            "vendor": "GeoVision Inc.",
            "product": "GeoWebPlayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:0df08a0e-a200-4957-9bb0-084f562506f9",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20978
      },
      "nvd": {
        "published": "2026-07-02T04:17:15.380",
        "lastModified": "2026-07-02T16:51:29.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57278",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The connectionInfo handler copies attacker-controlled JSON strings into fixed-size stack buffers without length limits.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.geovision.com.tw/cyber_security.php",
          "host": "www.geovision.com.tw",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2375",
          "host": "talosintelligence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 877,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57308",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T09:58:14.969Z",
      "date_published": "2026-07-20T14:21:57.415Z",
      "date_updated": "2026-07-21T14:57:14.949Z",
      "publisher": "apache",
      "title": "Apache Syncope: SQL injection vulnerability in Audit Events search",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Syncope"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00496,
        "percentile": 0.39848
      },
      "nvd": {
        "published": "2026-07-20T15:16:44.197",
        "lastModified": "2026-07-27T15:00:04.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57308",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unsanitized audit-event sort parameters reach stacked SQL queries as executable SQL syntax.",
        "basis": [
          "CNA record",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/g0gpctj90pbczbjl5jr33t8gr1gltg8v",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/8",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 469,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-57309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:12:42.195Z",
      "date_published": "2026-07-20T12:52:37.113Z",
      "date_updated": "2026-07-20T15:41:44.857Z",
      "publisher": "CERT-PL",
      "title": "Blind SQL Injection in Windu CMS",
      "affected": {
        "vendors": [
          "JCD"
        ],
        "products": [
          {
            "vendor": "JCD",
            "product": "Windu CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23774
      },
      "nvd": {
        "published": "2026-07-20T13:16:56.367",
        "lastModified": "2026-07-22T20:53:19.510",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57309",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windu CMS builds an SQL statement from attacker-controlled text without parameterization or SQL-context separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-57309",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://windu.org",
          "host": "windu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 340,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57310",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:12:42.195Z",
      "date_published": "2026-07-20T12:52:56.365Z",
      "date_updated": "2026-07-20T15:40:24.711Z",
      "publisher": "CERT-PL",
      "title": "Weak password hashing in Windu CMS",
      "affected": {
        "vendors": [
          "JCD"
        ],
        "products": [
          {
            "vendor": "JCD",
            "product": "Windu CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-916",
          "name": "Use of Password Hash With Insufficient Computational Effort",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07081
      },
      "nvd": {
        "published": "2026-07-20T13:16:56.507",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57310",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windu stores passwords with MD5 and SHA-1 plus a static salt, making stolen hashes cheaply recoverable.",
        "basis": [
          "CNA",
          "CWE-916"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-57309",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://windu.org",
          "host": "windu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 318,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57311",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:12:42.195Z",
      "date_published": "2026-07-20T12:53:08.554Z",
      "date_updated": "2026-07-29T09:42:56.327Z",
      "publisher": "CERT-PL",
      "title": "Unrestricted Upload of File with Dangerous Type in Windu CMS",
      "affected": {
        "vendors": [
          "JCD"
        ],
        "products": [
          {
            "vendor": "JCD",
            "product": "Windu CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00374,
        "percentile": 0.30111
      },
      "nvd": {
        "published": "2026-07-20T13:16:56.633",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57311",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path in Windu CMS accepts an attacker-selected file type or destination outside the intended file policy.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-57309",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://windu.org",
          "host": "windu.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57342",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:24.971Z",
      "date_published": "2026-07-02T11:15:04.435Z",
      "date_updated": "2026-07-02T14:56:19.868Z",
      "publisher": "Patchstack",
      "title": "WordPress ShortPixel Adaptive Images plugin <= 3.11.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "ShortPixel"
        ],
        "products": [
          {
            "vendor": "ShortPixel",
            "product": "ShortPixel Adaptive Images"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12325
      },
      "nvd": {
        "published": "2026-07-02T12:17:34.350",
        "lastModified": "2026-07-02T15:17:07.983",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57342",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/shortpixel-adaptive-images/vulnerability/wordpress-shortpixel-adaptive-images-plugin-3-11-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 87,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57343",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:24.971Z",
      "date_published": "2026-07-02T11:15:05.510Z",
      "date_updated": "2026-07-02T19:43:28.706Z",
      "publisher": "Patchstack",
      "title": "WordPress Real Estate 7 theme <= 3.5.9 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Contempoinc"
        ],
        "products": [
          {
            "vendor": "Contempoinc",
            "product": "Real Estate 7"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08386
      },
      "nvd": {
        "published": "2026-07-02T12:17:34.487",
        "lastModified": "2026-07-02T20:17:03.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57343",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Real Estate 7 emits unauthenticated attacker-controlled content into browser-interpreted output without sufficient contextual neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/realestate-7/vulnerability/wordpress-real-estate-7-theme-3-5-9-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 78,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57344",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:24.971Z",
      "date_published": "2026-07-02T11:15:06.634Z",
      "date_updated": "2026-07-02T15:53:33.162Z",
      "publisher": "Patchstack",
      "title": "WordPress Classified Listing plugin <= 5.4.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "RadiusTheme"
        ],
        "products": [
          {
            "vendor": "RadiusTheme",
            "product": "Classified Listing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08386
      },
      "nvd": {
        "published": "2026-07-02T12:17:34.603",
        "lastModified": "2026-07-02T16:16:34.253",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57344",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Classified Listing rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/classified-listing/vulnerability/wordpress-classified-listing-plugin-5-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57345",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:24.971Z",
      "date_published": "2026-07-02T11:15:07.465Z",
      "date_updated": "2026-07-02T12:14:00.631Z",
      "publisher": "Patchstack",
      "title": "WordPress Internal Links Manager plugin <= 3.0.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Webraketen"
        ],
        "products": [
          {
            "vendor": "Webraketen",
            "product": "Internal Links Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08386
      },
      "nvd": {
        "published": "2026-07-02T12:17:34.730",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57345",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker input becomes executable interpreter syntax without the necessary context separation.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/seo-automated-link-building/vulnerability/wordpress-internal-links-manager-plugin-3-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 87,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57347",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:24.971Z",
      "date_published": "2026-07-02T11:15:08.324Z",
      "date_updated": "2026-07-02T12:43:26.221Z",
      "publisher": "Patchstack",
      "title": "WordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "jetmonsters"
        ],
        "products": [
          {
            "vendor": "jetmonsters",
            "product": "Hotel Booking Lite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29837
      },
      "nvd": {
        "published": "2026-07-02T12:17:34.847",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57347",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Hotel Booking Lite exposes subscriber-sensitive data, while the public record does not identify the endpoint, field, or retrieval path.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/motopress-hotel-booking-lite/vulnerability/wordpress-hotel-booking-lite-plugin-6-0-3-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:24.971Z",
      "date_published": "2026-07-02T11:15:09.176Z",
      "date_updated": "2026-07-02T14:08:50.836Z",
      "publisher": "Patchstack",
      "title": "WordPress Paid Member Subscriptions plugin <= 3.0.4 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "Cozmoslabs"
        ],
        "products": [
          {
            "vendor": "Cozmoslabs",
            "product": "Paid Member Subscriptions"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09632
      },
      "nvd": {
        "published": "2026-07-02T12:17:34.967",
        "lastModified": "2026-07-02T15:17:09.090",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57348",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WordPress plugin accepts a caller-selected URL and performs a server-side request without restricting the destination.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/paid-member-subscriptions/vulnerability/wordpress-paid-member-subscriptions-plugin-3-0-4-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:24.972Z",
      "date_published": "2026-07-02T11:15:09.990Z",
      "date_updated": "2026-07-02T14:57:14.205Z",
      "publisher": "Patchstack",
      "title": "WordPress WPeMatico RSS Feed Fetcher plugin <= 2.8.17 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "etruel"
        ],
        "products": [
          {
            "vendor": "etruel",
            "product": "WPeMatico RSS Feed Fetcher"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08386
      },
      "nvd": {
        "published": "2026-07-02T12:17:35.087",
        "lastModified": "2026-07-02T15:17:09.193",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57349",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says attacker-controlled input reaches executable syntax in WPeMatico RSS Feed Fetcher, while the input field and interpreter sink are not public.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wpematico/vulnerability/wordpress-wpematico-rss-feed-fetcher-plugin-2-8-17-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 92,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57350",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:24.972Z",
      "date_published": "2026-07-02T11:15:10.800Z",
      "date_updated": "2026-07-02T19:43:42.128Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Debugging plugin <= 2.12.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Andy Fragen"
        ],
        "products": [
          {
            "vendor": "Andy Fragen",
            "product": "WP Debugging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08387
      },
      "nvd": {
        "published": "2026-07-02T12:17:35.213",
        "lastModified": "2026-07-02T20:17:04.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57350",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WP Debugging renders unauthenticated input as active HTML or script without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-debugging/vulnerability/wordpress-wp-debugging-plugin-2-12-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 78,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:24.972Z",
      "date_published": "2026-07-02T11:15:11.655Z",
      "date_updated": "2026-07-02T15:53:27.892Z",
      "publisher": "Patchstack",
      "title": "WordPress HandL UTM Grabber plugin <= 2.9.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Haktan Suren"
        ],
        "products": [
          {
            "vendor": "Haktan Suren",
            "product": "HandL UTM Grabber"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08387
      },
      "nvd": {
        "published": "2026-07-02T12:17:35.347",
        "lastModified": "2026-07-02T16:16:34.350",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57351",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/handl-utm-grabber/vulnerability/wordpress-handl-utm-grabber-plugin-2-9-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:36.888Z",
      "date_published": "2026-07-02T11:15:12.503Z",
      "date_updated": "2026-07-02T12:11:14.988Z",
      "publisher": "Patchstack",
      "title": "WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.0 - Broken Authentication vulnerability",
      "affected": {
        "vendors": [
          "VillaTheme"
        ],
        "products": [
          {
            "vendor": "VillaTheme",
            "product": "ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1390",
          "name": "Weak Authentication",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10543
      },
      "nvd": {
        "published": "2026-07-02T12:17:35.480",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57352",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The authentication design relies on a credential or proof that does not provide the strength required to bind the caller to the claimed identity.",
        "basis": [
          "CNA",
          "CWE-1390"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/woo-alidropship/vulnerability/wordpress-ald-dropshipping-and-fulfillment-for-aliexpress-and-woocommerce-plugin-2-2-0-broken-authentication-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 125,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:36.888Z",
      "date_published": "2026-07-02T11:15:13.364Z",
      "date_updated": "2026-07-02T12:43:08.999Z",
      "publisher": "Patchstack",
      "title": "WordPress Link Whisper Premium plugin <= 2.9.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "LinkWhisper"
        ],
        "products": [
          {
            "vendor": "LinkWhisper",
            "product": "Link Whisper Premium"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22229
      },
      "nvd": {
        "published": "2026-07-02T12:17:35.610",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57353",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/link-whisper-premium/vulnerability/wordpress-link-whisper-premium-plugin-2-9-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57354",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:36.888Z",
      "date_published": "2026-07-02T11:15:14.184Z",
      "date_updated": "2026-07-02T14:35:43.161Z",
      "publisher": "Patchstack",
      "title": "WordPress JetReviews plugin <= 3.0.0.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Crocoblock. Jetimpex Inc."
        ],
        "products": [
          {
            "vendor": "Crocoblock. Jetimpex Inc.",
            "product": "JetReviews"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12324
      },
      "nvd": {
        "published": "2026-07-02T12:17:35.730",
        "lastModified": "2026-07-02T15:17:09.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57354",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches JetReviews page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/jet-reviews/vulnerability/wordpress-jetreviews-plugin-3-0-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 72,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57355",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:36.888Z",
      "date_published": "2026-07-02T11:15:15.123Z",
      "date_updated": "2026-07-02T14:58:13.199Z",
      "publisher": "Patchstack",
      "title": "WordPress Classified Listing plugin <= 5.4.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "RadiusTheme"
        ],
        "products": [
          {
            "vendor": "RadiusTheme",
            "product": "Classified Listing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22229
      },
      "nvd": {
        "published": "2026-07-02T12:17:35.847",
        "lastModified": "2026-07-02T15:17:09.397",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57355",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A subscriber can perform a Classified Listing operation outside the intended role, but the object and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/classified-listing/vulnerability/wordpress-classified-listing-plugin-5-4-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 73,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57356",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:36.889Z",
      "date_published": "2026-07-02T11:15:16.231Z",
      "date_updated": "2026-07-02T19:43:55.556Z",
      "publisher": "Patchstack",
      "title": "WordPress MC Woocommerce Wishlist plugin <= 1.9.19 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Moreconvert Team"
        ],
        "products": [
          {
            "vendor": "Moreconvert Team",
            "product": "MC Woocommerce Wishlist"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08387
      },
      "nvd": {
        "published": "2026-07-02T12:17:35.963",
        "lastModified": "2026-07-02T20:17:04.147",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57356",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The wishlist plugin places unauthenticated attacker-controlled content into a browser-interpreted page without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/smart-wishlist-for-more-convert/vulnerability/wordpress-mc-woocommerce-wishlist-plugin-1-9-19-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 89,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57357",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:36.889Z",
      "date_published": "2026-07-02T11:15:17.451Z",
      "date_updated": "2026-07-02T15:53:22.538Z",
      "publisher": "Patchstack",
      "title": "WordPress Search Atlas SEO plugin <= 2.6.6 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Search Atlas Group"
        ],
        "products": [
          {
            "vendor": "Search Atlas Group",
            "product": "Search Atlas SEO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08385
      },
      "nvd": {
        "published": "2026-07-02T12:17:36.080",
        "lastModified": "2026-07-02T16:16:34.443",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57357",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The plugin reflects unauthenticated request input as executable browser markup, although the affected parameter and output context are not public.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/metasync/vulnerability/wordpress-search-atlas-seo-plugin-2-6-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 81,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57358",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:36.889Z",
      "date_published": "2026-07-02T11:15:18.297Z",
      "date_updated": "2026-07-02T12:10:49.926Z",
      "publisher": "Patchstack",
      "title": "WordPress Customize My Account for WooCommerce plugin <= 4.3.9 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "SysBasics"
        ],
        "products": [
          {
            "vendor": "SysBasics",
            "product": "Customize My Account for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08388
      },
      "nvd": {
        "published": "2026-07-02T12:17:36.200",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57358",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Customize My Account for WooCommerce page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/customize-my-account-for-woocommerce/vulnerability/wordpress-customize-my-account-for-woocommerce-plugin-4-3-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:36.889Z",
      "date_published": "2026-07-02T11:15:19.229Z",
      "date_updated": "2026-07-02T12:42:52.044Z",
      "publisher": "Patchstack",
      "title": "WordPress ReviewX plugin <= 2.3.10 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "ReviewX"
        ],
        "products": [
          {
            "vendor": "ReviewX",
            "product": "ReviewX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08388
      },
      "nvd": {
        "published": "2026-07-02T12:17:36.330",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57359",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ReviewX permits unauthenticated input to reach generated page markup as executable browser content.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/reviewx/vulnerability/wordpress-reviewx-plugin-2-3-10-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 73,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57360",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:36.889Z",
      "date_published": "2026-07-02T11:15:20.147Z",
      "date_updated": "2026-07-02T14:32:52.699Z",
      "publisher": "Patchstack",
      "title": "WordPress eCommerce Product Catalog plugin <= 3.5.4 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "impleCode"
        ],
        "products": [
          {
            "vendor": "impleCode",
            "product": "eCommerce Product Catalog"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08393
      },
      "nvd": {
        "published": "2026-07-02T12:17:36.440",
        "lastModified": "2026-07-02T15:17:09.510",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57360",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In eCommerce Product Catalog, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ecommerce-product-catalog/vulnerability/wordpress-ecommerce-product-catalog-plugin-3-5-4-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 90,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57361",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:36.889Z",
      "date_published": "2026-07-02T11:15:21.096Z",
      "date_updated": "2026-07-02T19:45:39.467Z",
      "publisher": "Patchstack",
      "title": "WordPress Survey Maker plugin <= 5.2.2.5 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Ays Pro"
        ],
        "products": [
          {
            "vendor": "Ays Pro",
            "product": "Survey Maker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08394
      },
      "nvd": {
        "published": "2026-07-02T12:17:36.560",
        "lastModified": "2026-07-02T20:17:04.243",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57361",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Survey Maker places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/survey-maker/vulnerability/wordpress-survey-maker-plugin-5-2-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 79,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57362",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:46.645Z",
      "date_published": "2026-07-02T11:15:21.960Z",
      "date_updated": "2026-07-02T19:44:09.312Z",
      "publisher": "Patchstack",
      "title": "WordPress ChatBot plugin <= 8.3.2 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "QuantumCloud"
        ],
        "products": [
          {
            "vendor": "QuantumCloud",
            "product": "ChatBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08394
      },
      "nvd": {
        "published": "2026-07-02T12:17:36.673",
        "lastModified": "2026-07-02T20:17:04.343",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57362",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ChatBot reflects unauthenticated input into a browser-interpreted page without sufficient contextual neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/chatbot/vulnerability/wordpress-chatbot-plugin-8-3-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 72,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57363",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:46.645Z",
      "date_published": "2026-07-13T08:41:23.759Z",
      "date_updated": "2026-07-13T13:52:47.958Z",
      "publisher": "Patchstack",
      "title": "WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "QuantumCloud"
        ],
        "products": [
          {
            "vendor": "QuantumCloud",
            "product": "ChatBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07176
      },
      "nvd": {
        "published": "2026-07-13T10:16:29.720",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57363",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ChatBot stores attacker-controlled content and later renders it without sufficient output escaping, allowing script execution in a visitor's browser.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/chatbot/vulnerability/wordpress-chatbot-plugin-8-3-7-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57364",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:46.645Z",
      "date_published": "2026-07-13T08:41:23.764Z",
      "date_updated": "2026-07-13T13:48:17.465Z",
      "publisher": "Patchstack",
      "title": "WordPress Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More plugin <= 2.2.0 - Other Vulnerability Type vulnerability",
      "affected": {
        "vendors": [
          "WPDeveloper"
        ],
        "products": [
          {
            "vendor": "WPDeveloper",
            "product": "Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16145
      },
      "nvd": {
        "published": "2026-07-13T10:16:29.853",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57364",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "Better Payment exposes functionality outside its ACL boundary, but the public record does not identify the affected operation or the quantity check that fails.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/better-payment/vulnerability/wordpress-better-payment-instant-payments-donations-fundraising-with-subscriptions-more-plugin-2-2-0-other-vulnerability-type-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 381,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57365",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:46.645Z",
      "date_published": "2026-07-13T08:41:23.646Z",
      "date_updated": "2026-07-13T16:07:54.165Z",
      "publisher": "Patchstack",
      "title": "WordPress reCAPTCHA (v2 & v3) for Asgaros Forum plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Hitesh Chandwani"
        ],
        "products": [
          {
            "vendor": "Hitesh Chandwani",
            "product": "reCAPTCHA (v2 &amp; v3) for Asgaros Forum"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05261
      },
      "nvd": {
        "published": "2026-07-13T10:16:29.980",
        "lastModified": "2026-07-13T17:17:43.000",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57365",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The reCAPTCHA extension permits attacker-controlled DOM data to be interpreted as active page markup.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/recaptcha-for-asgaros-forum/vulnerability/wordpress-recaptcha-v2-v3-for-asgaros-forum-plugin-1-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 298,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57366",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:46.645Z",
      "date_published": "2026-07-02T11:15:22.825Z",
      "date_updated": "2026-07-02T15:53:17.236Z",
      "publisher": "Patchstack",
      "title": "WordPress WPAdverts plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Greg Winiarski"
        ],
        "products": [
          {
            "vendor": "Greg Winiarski",
            "product": "WPAdverts"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08388
      },
      "nvd": {
        "published": "2026-07-02T12:17:36.797",
        "lastModified": "2026-07-02T16:16:34.540",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57366",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WPAdverts renders unauthenticated attacker input as active browser markup without the required output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wpadverts/vulnerability/wordpress-wpadverts-plugin-2-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 74,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57367",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:46.645Z",
      "date_published": "2026-07-23T11:17:59.644Z",
      "date_updated": "2026-07-23T13:53:12.938Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Booking System plugin < 5.12.8.1 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "WP Booking System ."
        ],
        "products": [
          {
            "vendor": "WP Booking System .",
            "product": "WP Booking System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23936
      },
      "nvd": {
        "published": "2026-07-23T12:18:27.910",
        "lastModified": "2026-07-23T14:17:23.743",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57367",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-booking-system-premium/vulnerability/wordpress-wp-booking-system-plugin-5-12-8-1-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 74,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57368",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:46.646Z",
      "date_published": "2026-07-13T08:41:23.763Z",
      "date_updated": "2026-07-13T16:07:54.002Z",
      "publisher": "Patchstack",
      "title": "WordPress Jobmonster theme <= 4.8.5 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "NooTheme"
        ],
        "products": [
          {
            "vendor": "NooTheme",
            "product": "Jobmonster"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.0776
      },
      "nvd": {
        "published": "2026-07-13T10:16:30.100",
        "lastModified": "2026-07-13T17:17:43.677",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57368",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Jobmonster theme reflects attacker-controlled browser content without the neutralization required for its HTML context.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/noo-jobmonster/vulnerability/wordpress-jobmonster-theme-4-8-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57369",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:46.646Z",
      "date_published": "2026-07-13T08:41:23.644Z",
      "date_updated": "2026-07-13T13:58:15.685Z",
      "publisher": "Patchstack",
      "title": "WordPress Themify Builder plugin <= 7.7.4 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "themifyme"
        ],
        "products": [
          {
            "vendor": "themifyme",
            "product": "Themify Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07163
      },
      "nvd": {
        "published": "2026-07-13T10:16:30.217",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57369",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/themify-builder/vulnerability/wordpress-themify-builder-plugin-7-7-4-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57370",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:46.646Z",
      "date_published": "2026-07-23T11:18:00.301Z",
      "date_updated": "2026-07-23T15:06:43.803Z",
      "publisher": "Patchstack",
      "title": "WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.9.1 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "CODEPRESS IT Solutions LLC"
        ],
        "products": [
          {
            "vendor": "CODEPRESS IT Solutions LLC",
            "product": "Visitor Traffic Real Time Statistics Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07763
      },
      "nvd": {
        "published": "2026-07-23T12:18:28.057",
        "lastModified": "2026-07-23T16:17:27.120",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57370",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/visitors-traffic-real-time-statistics-pro/vulnerability/wordpress-visitor-traffic-real-time-statistics-pro-plugin-11-9-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:46.646Z",
      "date_published": "2026-07-13T08:41:23.759Z",
      "date_updated": "2026-07-13T14:39:27.857Z",
      "publisher": "Patchstack",
      "title": "WordPress WPJAM Basic plugin <= 7.0 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "denishua"
        ],
        "products": [
          {
            "vendor": "denishua",
            "product": "WPJAM Basic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27072
      },
      "nvd": {
        "published": "2026-07-13T10:16:30.330",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57371",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application deserializes attacker-controlled bytes with object semantics that can invoke executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/wpjam-basic/vulnerability/wordpress-wpjam-basic-plugin-7-0-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 164,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57372",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:54.515Z",
      "date_published": "2026-07-13T08:41:23.761Z",
      "date_updated": "2026-07-13T13:52:19.596Z",
      "publisher": "Patchstack",
      "title": "WordPress WPJAM Basic plugin <= 7.0 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "denishua"
        ],
        "products": [
          {
            "vendor": "denishua",
            "product": "WPJAM Basic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08675
      },
      "nvd": {
        "published": "2026-07-13T10:16:30.450",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57372",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WPJAM Basic follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/wpjam-basic/vulnerability/wordpress-wpjam-basic-plugin-7-0-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57373",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:54.515Z",
      "date_published": "2026-07-23T11:18:00.952Z",
      "date_updated": "2026-07-23T14:19:54.737Z",
      "publisher": "Patchstack",
      "title": "WordPress Funnel Kit Funnel Builder PRO plugin <= 3.15.0.4 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Wisetr INC."
        ],
        "products": [
          {
            "vendor": "Wisetr INC.",
            "product": "Funnel Kit Funnel Builder PRO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05262
      },
      "nvd": {
        "published": "2026-07-23T12:18:28.190",
        "lastModified": "2026-07-23T15:17:18.500",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57373",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Customer-controlled data is rendered into Funnel Builder pages without the required browser-context separation.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/funnel-builder-pro/vulnerability/wordpress-funnel-kit-funnel-builder-pro-plugin-3-15-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 90,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57374",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:54.515Z",
      "date_published": "2026-07-23T11:18:01.586Z",
      "date_updated": "2026-07-23T16:02:07.464Z",
      "publisher": "Patchstack",
      "title": "WordPress Funnel Kit Funnel Builder PRO plugin <= 3.15.0.7 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Wisetr INC."
        ],
        "products": [
          {
            "vendor": "Wisetr INC.",
            "product": "Funnel Kit Funnel Builder PRO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07183
      },
      "nvd": {
        "published": "2026-07-23T12:18:28.313",
        "lastModified": "2026-07-23T16:17:27.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57374",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content is rendered without the browser-context separation required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/funnel-builder-pro/vulnerability/wordpress-funnel-kit-funnel-builder-pro-plugin-3-15-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57375",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:54.515Z",
      "date_published": "2026-07-13T08:41:23.762Z",
      "date_updated": "2026-07-13T13:47:23.506Z",
      "publisher": "Patchstack",
      "title": "WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "FluxBuilder"
        ],
        "products": [
          {
            "vendor": "FluxBuilder",
            "product": "MStore API"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09322
      },
      "nvd": {
        "published": "2026-07-13T10:16:30.570",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57375",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "MStore API exposes an operation without the required authorization, but the record does not identify the route, object, or missing check.",
        "basis": [
          "CNA record",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/mstore-api/vulnerability/wordpress-mstore-api-plugin-4-18-4-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57376",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:54.515Z",
      "date_published": "2026-07-13T08:41:23.645Z",
      "date_updated": "2026-07-13T16:07:54.325Z",
      "publisher": "Patchstack",
      "title": "WordPress ElementInvader Addons for Elementor plugin <= 1.4.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Element Invader"
        ],
        "products": [
          {
            "vendor": "Element Invader",
            "product": "ElementInvader Addons for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07183
      },
      "nvd": {
        "published": "2026-07-13T10:16:30.687",
        "lastModified": "2026-07-13T17:17:44.320",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57376",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ElementInvader Addons for Elementor renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/elementinvader-addons-for-elementor/vulnerability/wordpress-elementinvader-addons-for-elementor-plugin-1-4-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:54.515Z",
      "date_published": "2026-07-13T08:41:23.643Z",
      "date_updated": "2026-07-13T16:07:54.478Z",
      "publisher": "Patchstack",
      "title": "WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "WPXPO"
        ],
        "products": [
          {
            "vendor": "WPXPO",
            "product": "WowAddons"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15432
      },
      "nvd": {
        "published": "2026-07-13T10:16:30.803",
        "lastModified": "2026-07-13T17:17:44.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57377",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WowAddons exposes an action without the required authorization, but the affected action and object scope are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/product-addons/vulnerability/wordpress-wowaddons-plugin-1-6-8-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 198,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:54.515Z",
      "date_published": "2026-07-13T08:41:23.794Z",
      "date_updated": "2026-07-13T13:54:42.973Z",
      "publisher": "Patchstack",
      "title": "WordPress Advanced Forms plugin <= 1.9.3.7 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Phil Kurth"
        ],
        "products": [
          {
            "vendor": "Phil Kurth",
            "product": "Advanced Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14977
      },
      "nvd": {
        "published": "2026-07-13T10:16:30.920",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57378",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Advanced Forms permits an operation outside the caller's assigned authority, while the Patchstack record does not identify the endpoint, object, or missing check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/advanced-forms/vulnerability/wordpress-advanced-forms-plugin-1-9-3-7-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57379",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:54.515Z",
      "date_published": "2026-07-13T08:41:23.800Z",
      "date_updated": "2026-07-13T14:39:24.727Z",
      "publisher": "Patchstack",
      "title": "WordPress FormyChat plugin <= 2.15.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WPPOOL"
        ],
        "products": [
          {
            "vendor": "WPPOOL",
            "product": "FormyChat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07183
      },
      "nvd": {
        "published": "2026-07-13T10:16:31.050",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57379",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/social-contact-form/vulnerability/wordpress-formychat-plugin-2-15-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:54.516Z",
      "date_published": "2026-07-13T08:41:23.798Z",
      "date_updated": "2026-07-13T13:44:19.714Z",
      "publisher": "Patchstack",
      "title": "WordPress Extensions for Leaflet Map plugin <= 5.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "hupe13"
        ],
        "products": [
          {
            "vendor": "hupe13",
            "product": "Extensions for Leaflet Map"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07182
      },
      "nvd": {
        "published": "2026-07-13T10:16:31.167",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57380",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Extensions for Leaflet Map moves attacker-controlled DOM data into an executable browser context without the required contextual neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/extensions-leaflet-map/vulnerability/wordpress-extensions-for-leaflet-map-plugin-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57381",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:45:54.516Z",
      "date_published": "2026-07-13T08:41:23.886Z",
      "date_updated": "2026-07-13T13:48:41.243Z",
      "publisher": "Patchstack",
      "title": "WordPress PropertyHive plugin <= 2.2.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Property Hive"
        ],
        "products": [
          {
            "vendor": "Property Hive",
            "product": "PropertyHive"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07182
      },
      "nvd": {
        "published": "2026-07-13T10:16:31.293",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57381",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PropertyHive rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/propertyhive/vulnerability/wordpress-propertyhive-plugin-2-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:01.632Z",
      "date_published": "2026-07-13T08:41:23.918Z",
      "date_updated": "2026-07-13T16:07:53.859Z",
      "publisher": "Patchstack",
      "title": "WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Mitchell Bennis"
        ],
        "products": [
          {
            "vendor": "Mitchell Bennis",
            "product": "Simple File List"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07178
      },
      "nvd": {
        "published": "2026-07-13T10:16:31.437",
        "lastModified": "2026-07-13T17:17:45.603",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57382",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted content reaches an interpreter without being constrained to data in the target grammar.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/simple-file-list/vulnerability/wordpress-simple-file-list-plugin-6-3-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:01.632Z",
      "date_published": "2026-07-13T08:41:23.918Z",
      "date_updated": "2026-07-13T16:07:53.704Z",
      "publisher": "Patchstack",
      "title": "WordPress JobSearch plugin <= 3.2.9 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "eyecix"
        ],
        "products": [
          {
            "vendor": "eyecix",
            "product": "JobSearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07178
      },
      "nvd": {
        "published": "2026-07-13T10:16:31.567",
        "lastModified": "2026-07-13T17:17:46.243",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57383",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The JobSearch rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/wp-jobsearch/vulnerability/wordpress-jobsearch-plugin-3-2-9-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57384",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:01.632Z",
      "date_published": "2026-07-23T11:18:02.227Z",
      "date_updated": "2026-07-23T14:53:41.475Z",
      "publisher": "Patchstack",
      "title": "WordPress WishList Member X plugin <= 3.32.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Membership Software"
        ],
        "products": [
          {
            "vendor": "Membership Software",
            "product": "WishList Member X"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10702
      },
      "nvd": {
        "published": "2026-07-23T12:18:28.440",
        "lastModified": "2026-07-23T16:17:27.310",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57384",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected page renders attacker-controlled input as executable browser markup without the required context encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wishlist-member/vulnerability/wordpress-wishlist-member-x-plugin-3-32-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 78,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57385",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:01.632Z",
      "date_published": "2026-07-13T08:41:23.918Z",
      "date_updated": "2026-07-13T13:52:49.955Z",
      "publisher": "Patchstack",
      "title": "WordPress Vitepos plugin <= 3.4.2 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "appsbd"
        ],
        "products": [
          {
            "vendor": "appsbd",
            "product": "Vitepos"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16734
      },
      "nvd": {
        "published": "2026-07-13T10:16:31.687",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57385",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says attacker-controlled input reaches executable syntax in Vitepos, while the input field and interpreter sink are not public.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/vitepos-lite/vulnerability/wordpress-vitepos-plugin-3-4-2-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57386",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:01.632Z",
      "date_published": "2026-07-13T08:41:23.914Z",
      "date_updated": "2026-07-13T14:39:21.418Z",
      "publisher": "Patchstack",
      "title": "WordPress aBlocks plugin < 2.9.1 - Privilege Escalation vulnerability",
      "affected": {
        "vendors": [
          "Kodezen LLC"
        ],
        "products": [
          {
            "vendor": "Kodezen LLC",
            "product": "aBlocks"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.1999
      },
      "nvd": {
        "published": "2026-07-13T10:16:31.803",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57386",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The aBlocks record reports an incorrect privilege assignment but does not name the assigned role, operation, or responsible code path.",
        "basis": [
          "CNA",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/ablocks/vulnerability/wordpress-ablocks-plugin-2-9-1-privilege-escalation-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 157,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57387",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:01.632Z",
      "date_published": "2026-07-13T08:41:23.922Z",
      "date_updated": "2026-07-13T13:42:56.072Z",
      "publisher": "Patchstack",
      "title": "WordPress picu plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "picu"
        ],
        "products": [
          {
            "vendor": "picu",
            "product": "picu"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07191
      },
      "nvd": {
        "published": "2026-07-13T10:16:31.923",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57387",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/picu/vulnerability/wordpress-picu-plugin-3-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 186,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57388",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:01.632Z",
      "date_published": "2026-07-13T08:41:23.926Z",
      "date_updated": "2026-07-13T13:48:59.240Z",
      "publisher": "Patchstack",
      "title": "WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Themefic"
        ],
        "products": [
          {
            "vendor": "Themefic",
            "product": "Hydra Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07192
      },
      "nvd": {
        "published": "2026-07-13T10:16:32.040",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57388",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/hydra-booking/vulnerability/wordpress-hydra-booking-plugin-1-1-44-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:01.633Z",
      "date_published": "2026-07-13T08:41:23.939Z",
      "date_updated": "2026-07-13T16:07:53.542Z",
      "publisher": "Patchstack",
      "title": "WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability",
      "affected": {
        "vendors": [
          "Adrian Tobey"
        ],
        "products": [
          {
            "vendor": "Adrian Tobey",
            "product": "Groundhogg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29872
      },
      "nvd": {
        "published": "2026-07-13T10:16:32.160",
        "lastModified": "2026-07-13T17:17:46.903",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57389",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled path or reference can select a file outside the intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/groundhogg/vulnerability/wordpress-groundhogg-plugin-4-4-1-arbitrary-file-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:01.633Z",
      "date_published": "2026-07-13T08:41:23.947Z",
      "date_updated": "2026-07-13T16:07:53.389Z",
      "publisher": "Patchstack",
      "title": "WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "EDGARROJAS"
        ],
        "products": [
          {
            "vendor": "EDGARROJAS",
            "product": "Extra Product Options Builder for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15433
      },
      "nvd": {
        "published": "2026-07-13T10:16:32.283",
        "lastModified": "2026-07-13T17:17:47.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57390",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Extra Product Options Builder for WooCommerce exposes a protected action without checking the caller's required permission.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/additional-product-fields-for-woocommerce/vulnerability/wordpress-extra-product-options-builder-for-woocommerce-plugin-1-2-167-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:01.633Z",
      "date_published": "2026-07-13T08:41:24.025Z",
      "date_updated": "2026-07-13T13:51:40.490Z",
      "publisher": "Patchstack",
      "title": "WordPress Loops & Logic plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Tangible"
        ],
        "products": [
          {
            "vendor": "Tangible",
            "product": "Loops & Logic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.05992
      },
      "nvd": {
        "published": "2026-07-13T10:16:32.417",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57391",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Loops and Logic stores attacker-controlled content and later emits it into HTML without the required output neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/tangible-loops-and-logic/vulnerability/wordpress-loops-logic-plugin-4-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:07.752Z",
      "date_published": "2026-07-13T08:41:24.035Z",
      "date_updated": "2026-07-13T14:39:17.897Z",
      "publisher": "Patchstack",
      "title": "WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Themefic"
        ],
        "products": [
          {
            "vendor": "Themefic",
            "product": "Tourfic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15433
      },
      "nvd": {
        "published": "2026-07-13T10:16:32.750",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57392",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Tourfic exposes an operation without the required authorization level, but the action, object, and failed check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/tourfic/vulnerability/wordpress-tourfic-plugin-2-22-5-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57393",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:07.752Z",
      "date_published": "2026-07-13T08:41:24.069Z",
      "date_updated": "2026-07-21T16:56:54.582Z",
      "publisher": "Patchstack",
      "title": "WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "EDGARROJAS"
        ],
        "products": [
          {
            "vendor": "EDGARROJAS",
            "product": "WooCommerce PDF Invoice Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.19014
      },
      "nvd": {
        "published": "2026-07-13T10:16:32.870",
        "lastModified": "2026-07-21T17:17:12.117",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57393",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The invoice builder returns embedded sensitive system data to an authenticated user outside the intended control sphere, although the data field is not public.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/woo-pdf-invoice-builder/vulnerability/wordpress-woocommerce-pdf-invoice-builder-plugin-2-0-8-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 277,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:07.752Z",
      "date_published": "2026-07-13T08:41:24.067Z",
      "date_updated": "2026-07-13T13:49:18.549Z",
      "publisher": "Patchstack",
      "title": "WordPress Newsletters plugin <= 4.14 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Tribulant Software"
        ],
        "products": [
          {
            "vendor": "Tribulant Software",
            "product": "Newsletters"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07188
      },
      "nvd": {
        "published": "2026-07-13T10:16:32.993",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57394",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Newsletters page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/newsletters-lite/vulnerability/wordpress-newsletters-plugin-4-14-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:07.752Z",
      "date_published": "2026-07-13T08:41:24.073Z",
      "date_updated": "2026-07-13T16:07:53.244Z",
      "publisher": "Patchstack",
      "title": "WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Themefic"
        ],
        "products": [
          {
            "vendor": "Themefic",
            "product": "Tourfic"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16128
      },
      "nvd": {
        "published": "2026-07-13T10:16:33.110",
        "lastModified": "2026-07-13T17:17:48.187",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57395",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Tourfic exposes an operation at an incorrect access-control level, but the public record does not identify the action or permission check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/tourfic/vulnerability/wordpress-tourfic-plugin-2-22-5-broken-access-control-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:07.752Z",
      "date_published": "2026-07-13T08:41:24.073Z",
      "date_updated": "2026-07-13T16:07:53.083Z",
      "publisher": "Patchstack",
      "title": "WordPress Free Gifts for WooCommerce plugin <= 13.1.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Flintop"
        ],
        "products": [
          {
            "vendor": "Flintop",
            "product": "Free Gifts for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07189
      },
      "nvd": {
        "published": "2026-07-13T10:16:33.223",
        "lastModified": "2026-07-13T17:17:48.833",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57396",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Free Gifts for WooCommerce, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/free-gifts-for-woocommerce/vulnerability/wordpress-free-gifts-for-woocommerce-plugin-13-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:07.752Z",
      "date_published": "2026-07-23T11:18:02.865Z",
      "date_updated": "2026-07-23T13:33:15.586Z",
      "publisher": "Patchstack",
      "title": "WordPress Coaching theme <= 3.9.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "ThimPress."
        ],
        "products": [
          {
            "vendor": "ThimPress.",
            "product": "Coaching"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07189
      },
      "nvd": {
        "published": "2026-07-23T12:18:28.560",
        "lastModified": "2026-07-23T14:17:24.170",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57397",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Coaching places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/coaching/vulnerability/wordpress-coaching-theme-3-9-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 73,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:07.752Z",
      "date_published": "2026-07-13T08:41:24.076Z",
      "date_updated": "2026-07-13T13:46:49.710Z",
      "publisher": "Patchstack",
      "title": "WordPress Real Estate Manager Pro plugin <= 12.8.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WebCodingPlace"
        ],
        "products": [
          {
            "vendor": "WebCodingPlace",
            "product": "Real Estate Manager Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07189
      },
      "nvd": {
        "published": "2026-07-13T10:16:33.340",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57398",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Real Estate Manager Pro reflects attacker-controlled input into HTML without the required contextual escaping.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/real-estate-manager-pro/vulnerability/wordpress-real-estate-manager-pro-plugin-12-8-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:07.752Z",
      "date_published": "2026-07-13T08:41:24.074Z",
      "date_updated": "2026-07-13T14:39:14.729Z",
      "publisher": "Patchstack",
      "title": "WordPress Proxy & VPN Blocker plugin <= 3.5.8 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Proxy &amp; VPN Blocker"
        ],
        "products": [
          {
            "vendor": "Proxy &amp; VPN Blocker",
            "product": "Proxy &amp; VPN Blocker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.0719
      },
      "nvd": {
        "published": "2026-07-13T10:16:33.453",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57399",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Proxy &amp; VPN Blocker stores attacker-controlled content and later renders it without sufficient output escaping, allowing script execution in a visitor's browser.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/proxy-vpn-blocker/vulnerability/wordpress-proxy-vpn-blocker-plugin-3-5-8-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:07.752Z",
      "date_published": "2026-07-13T08:41:24.089Z",
      "date_updated": "2026-07-13T13:42:38.175Z",
      "publisher": "Patchstack",
      "title": "WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "WP Swings"
        ],
        "products": [
          {
            "vendor": "WP Swings",
            "product": "Event Tickets Manager for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.1452
      },
      "nvd": {
        "published": "2026-07-13T10:16:33.567",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57400",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Event Tickets Manager exposes a protected operation without the required authorization check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/event-tickets-manager-for-woocommerce/vulnerability/wordpress-event-tickets-manager-for-woocommerce-plugin-1-5-5-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 281,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57401",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:07.752Z",
      "date_published": "2026-07-13T08:41:24.092Z",
      "date_updated": "2026-07-13T13:47:52.263Z",
      "publisher": "Patchstack",
      "title": "WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability",
      "affected": {
        "vendors": [
          "Brainstorm Force"
        ],
        "products": [
          {
            "vendor": "Brainstorm Force",
            "product": "SureDash"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29857
      },
      "nvd": {
        "published": "2026-07-13T10:16:33.683",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57401",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SureDash permits a caller-controlled traversal path to select a file outside the intended deletion directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/suredash/vulnerability/wordpress-suredash-plugin-1-8-0-arbitrary-file-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57402",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:27.804Z",
      "date_published": "2026-07-13T08:41:24.172Z",
      "date_updated": "2026-07-13T16:07:52.935Z",
      "publisher": "Patchstack",
      "title": "WordPress Flexible Refund and Return Order for WooCommerce plugin <= 1.0.51 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "wpdesk"
        ],
        "products": [
          {
            "vendor": "wpdesk",
            "product": "Flexible Refund and Return Order for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05264
      },
      "nvd": {
        "published": "2026-07-13T10:16:33.833",
        "lastModified": "2026-07-13T17:17:49.473",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57402",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Flexible Refund and Return Order stores attacker-controlled content and later emits it as executable browser markup without sufficient encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/flexible-refund-and-return-order-for-woocommerce/vulnerability/wordpress-flexible-refund-and-return-order-for-woocommerce-plugin-1-0-51-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:27.804Z",
      "date_published": "2026-07-13T08:41:24.184Z",
      "date_updated": "2026-07-13T16:07:52.788Z",
      "publisher": "Patchstack",
      "title": "WordPress GD Security Headers plugin <= 1.8 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Milan Petrovic"
        ],
        "products": [
          {
            "vendor": "Milan Petrovic",
            "product": "GD Security Headers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07193
      },
      "nvd": {
        "published": "2026-07-13T10:16:33.950",
        "lastModified": "2026-07-13T17:17:50.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57403",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Security Headers gd-security-headers allows Reflected XSS.This issue affects GD Security Headers: from n/a through <= 1.8.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/gd-security-headers/vulnerability/wordpress-gd-security-headers-plugin-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 242,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:27.804Z",
      "date_published": "2026-07-13T08:41:24.223Z",
      "date_updated": "2026-07-13T16:07:52.647Z",
      "publisher": "Patchstack",
      "title": "WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "magepeopleteam"
        ],
        "products": [
          {
            "vendor": "magepeopleteam",
            "product": "Booking and Rental Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15434
      },
      "nvd": {
        "published": "2026-07-13T10:16:34.070",
        "lastModified": "2026-07-13T17:17:50.790",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57404",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Patchstack record identifies a subscriber-reachable authorization failure but does not name the operation or missing capability check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/booking-and-rental-manager-for-woocommerce/vulnerability/wordpress-booking-and-rental-manager-plugin-2-6-9-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 269,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57405",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:27.804Z",
      "date_published": "2026-07-13T08:41:24.222Z",
      "date_updated": "2026-07-13T14:39:11.681Z",
      "publisher": "Patchstack",
      "title": "WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "themehunk"
        ],
        "products": [
          {
            "vendor": "themehunk",
            "product": "Open Shop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13371
      },
      "nvd": {
        "published": "2026-07-13T10:16:34.187",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57405",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/open-shop/vulnerability/wordpress-open-shop-theme-1-7-1-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57406",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:27.804Z",
      "date_published": "2026-07-13T08:41:24.225Z",
      "date_updated": "2026-07-13T13:41:42.672Z",
      "publisher": "Patchstack",
      "title": "WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Roxnor"
        ],
        "products": [
          {
            "vendor": "Roxnor",
            "product": "FundEngine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.1452
      },
      "nvd": {
        "published": "2026-07-13T10:16:34.300",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57406",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/wp-fundraising-donation/vulnerability/wordpress-fundengine-plugin-1-7-6-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57407",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:27.805Z",
      "date_published": "2026-07-13T08:41:24.224Z",
      "date_updated": "2026-07-13T13:59:35.290Z",
      "publisher": "Patchstack",
      "title": "WordPress PDF Generator for WordPress plugin <= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "WP Swings"
        ],
        "products": [
          {
            "vendor": "WP Swings",
            "product": "PDF Generator for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08676
      },
      "nvd": {
        "published": "2026-07-13T10:16:34.417",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57407",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server accepts an attacker-controlled destination without constraining the resolved request target to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/pdf-generator-for-wp/vulnerability/wordpress-pdf-generator-for-wordpress-plugin-1-6-2-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57408",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:27.805Z",
      "date_published": "2026-07-13T08:41:24.226Z",
      "date_updated": "2026-07-13T16:07:52.507Z",
      "publisher": "Patchstack",
      "title": "WordPress Peach Payments Gateway plugin <= 4.0.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "peachpayments"
        ],
        "products": [
          {
            "vendor": "peachpayments",
            "product": "Peach Payments Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15433
      },
      "nvd": {
        "published": "2026-07-13T10:16:34.533",
        "lastModified": "2026-07-13T17:17:51.427",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57408",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Peach Payments Gateway permits an unauthorized operation, but the public record does not identify the operation or missing permission check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/wc-peach-payments-gateway/vulnerability/wordpress-peach-payments-gateway-plugin-4-0-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:27.805Z",
      "date_published": "2026-07-13T08:41:24.229Z",
      "date_updated": "2026-07-13T16:07:52.367Z",
      "publisher": "Patchstack",
      "title": "WordPress Active Products Tables for WooCommerce plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "RealMag777"
        ],
        "products": [
          {
            "vendor": "RealMag777",
            "product": "Active Products Tables for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07194
      },
      "nvd": {
        "published": "2026-07-13T10:16:34.650",
        "lastModified": "2026-07-13T17:17:52.067",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57409",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Active Products Tables renders attacker-controlled DOM data without the required browser-context separation.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/profit-products-tables-for-woocommerce/vulnerability/wordpress-active-products-tables-for-woocommerce-plugin-1-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 297,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:27.805Z",
      "date_published": "2026-07-13T08:41:24.238Z",
      "date_updated": "2026-07-13T13:45:11.127Z",
      "publisher": "Patchstack",
      "title": "WordPress MailerPress plugin <= 2.0.2 - Privilege Escalation vulnerability",
      "affected": {
        "vendors": [
          "MailerPress Team"
        ],
        "products": [
          {
            "vendor": "MailerPress Team",
            "product": "MailerPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19989
      },
      "nvd": {
        "published": "2026-07-13T10:16:34.767",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57410",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The product assigns privilege incorrectly, but the public record does not disclose the role field, protected action, or failed check.",
        "basis": [
          "CNA",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/mailerpress/vulnerability/wordpress-mailerpress-plugin-2-0-2-privilege-escalation-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 175,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57411",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:27.805Z",
      "date_published": "2026-07-13T08:41:24.239Z",
      "date_updated": "2026-07-13T14:39:08.470Z",
      "publisher": "Patchstack",
      "title": "WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= 3.2.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Aman"
        ],
        "products": [
          {
            "vendor": "Aman",
            "product": "CF7 Views &#8211; Complete Entry Management for Contact Form 7"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07191
      },
      "nvd": {
        "published": "2026-07-13T10:16:34.877",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57411",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CF7 Views places attacker-controlled DOM content into a browser-executable context without sufficient neutralization.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/cf7-views/vulnerability/wordpress-cf7-views-complete-entry-management-for-contact-form-7-plugin-3-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 310,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57412",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:38.623Z",
      "date_published": "2026-07-13T08:41:24.318Z",
      "date_updated": "2026-07-13T13:39:42.998Z",
      "publisher": "Patchstack",
      "title": "WordPress Gift Vouchers plugin <= 4.6.9 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Codemenschen"
        ],
        "products": [
          {
            "vendor": "Codemenschen",
            "product": "Gift Vouchers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15433
      },
      "nvd": {
        "published": "2026-07-13T10:16:34.993",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57412",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Gift Vouchers permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/gift-voucher/vulnerability/wordpress-gift-vouchers-plugin-4-6-9-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57413",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:38.624Z",
      "date_published": "2026-07-13T08:41:24.334Z",
      "date_updated": "2026-07-13T13:49:41.734Z",
      "publisher": "Patchstack",
      "title": "WordPress Instant Image Generator plugin <= 2.1.4 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "bdthemes"
        ],
        "products": [
          {
            "vendor": "bdthemes",
            "product": "Instant Image Generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.0593
      },
      "nvd": {
        "published": "2026-07-13T10:16:35.113",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57413",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Instant Image Generator lets caller-controlled input choose a server-side request destination without enforcing the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/ai-image/vulnerability/wordpress-instant-image-generator-plugin-2-1-4-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57414",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:38.624Z",
      "date_published": "2026-07-13T08:41:24.371Z",
      "date_updated": "2026-07-13T16:07:52.220Z",
      "publisher": "Patchstack",
      "title": "WordPress ChatBot for eCommerce – WoowBot plugin <= 4.6.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "QuantumCloud"
        ],
        "products": [
          {
            "vendor": "QuantumCloud",
            "product": "ChatBot for eCommerce &#8211; WoowBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05262
      },
      "nvd": {
        "published": "2026-07-13T10:16:35.230",
        "lastModified": "2026-07-13T17:17:52.800",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57414",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In ChatBot for eCommerce – WoowBot, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/woowbot-woocommerce-chatbot/vulnerability/wordpress-chatbot-for-ecommerce-woowbot-plugin-4-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 283,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57415",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:38.624Z",
      "date_published": "2026-07-13T08:41:24.376Z",
      "date_updated": "2026-07-13T16:07:52.073Z",
      "publisher": "Patchstack",
      "title": "WordPress Gift Vouchers plugin <= 4.7.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Codemenschen"
        ],
        "products": [
          {
            "vendor": "Codemenschen",
            "product": "Gift Vouchers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07192
      },
      "nvd": {
        "published": "2026-07-13T10:16:35.350",
        "lastModified": "2026-07-13T17:17:53.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57415",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/gift-voucher/vulnerability/wordpress-gift-vouchers-plugin-4-7-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57416",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:38.624Z",
      "date_published": "2026-07-13T08:41:24.380Z",
      "date_updated": "2026-07-13T13:43:57.427Z",
      "publisher": "Patchstack",
      "title": "WordPress SiteGround Email Marketing plugin <= 1.7.5 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "SiteGround"
        ],
        "products": [
          {
            "vendor": "SiteGround",
            "product": "SiteGround Email Marketing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07192
      },
      "nvd": {
        "published": "2026-07-13T10:16:35.473",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57416",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SiteGround Email Marketing stores attacker-controlled content and later emits it into browser-interpreted output without sufficient contextual neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/siteground-email-marketing/vulnerability/wordpress-siteground-email-marketing-plugin-1-7-5-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57417",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:38.624Z",
      "date_published": "2026-07-13T08:41:24.382Z",
      "date_updated": "2026-07-13T14:39:03.953Z",
      "publisher": "Patchstack",
      "title": "WordPress Cart Lift plugin <= 3.1.57 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "RexTheme"
        ],
        "products": [
          {
            "vendor": "RexTheme",
            "product": "Cart Lift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07192
      },
      "nvd": {
        "published": "2026-07-13T10:16:35.600",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57417",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Cart Lift rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/cart-lift/vulnerability/wordpress-cart-lift-plugin-3-1-57-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:38.624Z",
      "date_published": "2026-07-13T08:41:24.384Z",
      "date_updated": "2026-07-13T13:34:37.297Z",
      "publisher": "Patchstack",
      "title": "WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "BoldGrid"
        ],
        "products": [
          {
            "vendor": "BoldGrid",
            "product": "Client Invoicing by Sprout Invoices"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16128
      },
      "nvd": {
        "published": "2026-07-13T10:16:35.720",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57418",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected operation lacks an effective authorization check, but the public record does not identify the missing binding.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/sprout-invoices/vulnerability/wordpress-client-invoicing-by-sprout-invoices-plugin-20-8-13-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57419",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:38.624Z",
      "date_published": "2026-07-13T08:41:24.381Z",
      "date_updated": "2026-07-13T13:50:37.405Z",
      "publisher": "Patchstack",
      "title": "WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Fahad Mahmood"
        ],
        "products": [
          {
            "vendor": "Fahad Mahmood",
            "product": "Stock Locations for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11615
      },
      "nvd": {
        "published": "2026-07-13T10:16:35.837",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57419",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Stock Locations for WooCommerce operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/stock-locations-for-woocommerce/vulnerability/wordpress-stock-locations-for-woocommerce-plugin-3-1-8-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57420",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:38.624Z",
      "date_published": "2026-07-13T08:41:24.389Z",
      "date_updated": "2026-07-13T16:07:51.929Z",
      "publisher": "Patchstack",
      "title": "WordPress Author Box WP Lens plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Netrr"
        ],
        "products": [
          {
            "vendor": "Netrr",
            "product": "Author Box WP Lens"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05261
      },
      "nvd": {
        "published": "2026-07-13T10:16:35.953",
        "lastModified": "2026-07-13T17:17:54.137",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57420",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected page renders attacker-controlled input as executable browser markup without the required context encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/author-box-for-divi/vulnerability/wordpress-author-box-wp-lens-plugin-2-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57421",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:38.624Z",
      "date_published": "2026-07-13T08:41:24.392Z",
      "date_updated": "2026-07-13T16:07:51.774Z",
      "publisher": "Patchstack",
      "title": "WordPress CRM Perks Forms plugin <= 1.1.7 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "CRM Perks"
        ],
        "products": [
          {
            "vendor": "CRM Perks",
            "product": "CRM Perks Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07758
      },
      "nvd": {
        "published": "2026-07-13T10:16:36.070",
        "lastModified": "2026-07-13T17:17:54.823",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57421",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says attacker-controlled input reaches executable syntax in CRM Perks Forms, while the input field and interpreter sink are not public.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/crm-perks-forms/vulnerability/wordpress-crm-perks-forms-plugin-1-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:44.604Z",
      "date_published": "2026-07-13T08:41:24.464Z",
      "date_updated": "2026-07-13T13:43:11.695Z",
      "publisher": "Patchstack",
      "title": "WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "VillaTheme"
        ],
        "products": [
          {
            "vendor": "VillaTheme",
            "product": "Bopo – WooCommerce Product Bundle Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07194
      },
      "nvd": {
        "published": "2026-07-13T10:16:36.200",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57422",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Bopo bundle builder reflects attacker-controlled input into HTML without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/bopo-woo-product-bundle-builder/vulnerability/wordpress-bopo-woocommerce-product-bundle-builder-plugin-1-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 296,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:44.604Z",
      "date_published": "2026-07-13T08:41:24.483Z",
      "date_updated": "2026-07-13T14:38:58.533Z",
      "publisher": "Patchstack",
      "title": "WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.8 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Kofi Mokome"
        ],
        "products": [
          {
            "vendor": "Kofi Mokome",
            "product": "Message Filter for Contact Form 7"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07191
      },
      "nvd": {
        "published": "2026-07-13T10:16:36.317",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57423",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/cf7-message-filter/vulnerability/wordpress-message-filter-for-contact-form-7-plugin-1-6-3-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 270,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:44.604Z",
      "date_published": "2026-07-13T08:41:24.518Z",
      "date_updated": "2026-07-13T13:32:13.317Z",
      "publisher": "Patchstack",
      "title": "WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.4 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "knitpay"
        ],
        "products": [
          {
            "vendor": "knitpay",
            "product": "Razorpay Payment Links for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15432
      },
      "nvd": {
        "published": "2026-07-13T10:16:36.433",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57424",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/rzp-woocommerce/vulnerability/wordpress-razorpay-payment-links-for-woocommerce-plugin-2-1-4-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:44.605Z",
      "date_published": "2026-07-23T11:18:03.490Z",
      "date_updated": "2026-07-23T13:52:54.256Z",
      "publisher": "Patchstack",
      "title": "WordPress Autopay dla WooCommerce plugin <= 2.2.27 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "wpdesk"
        ],
        "products": [
          {
            "vendor": "wpdesk",
            "product": "Autopay dla WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14521
      },
      "nvd": {
        "published": "2026-07-23T12:18:28.683",
        "lastModified": "2026-07-23T14:17:24.603",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57425",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/pay-wp/vulnerability/wordpress-autopay-dla-woocommerce-plugin-2-2-27-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 84,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57426",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:44.605Z",
      "date_published": "2026-07-02T11:15:23.860Z",
      "date_updated": "2026-07-02T12:10:28.862Z",
      "publisher": "Patchstack",
      "title": "WordPress Modula - PRO plugin <= 2.10.8 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Chill Media Labs S.R.L."
        ],
        "products": [
          {
            "vendor": "Chill Media Labs S.R.L.",
            "product": "Modula - PRO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08395
      },
      "nvd": {
        "published": "2026-07-02T12:17:36.913",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57426",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Modula - PRO page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/modula/vulnerability/wordpress-modula-pro-plugin-2-10-8-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 78,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:44.605Z",
      "date_published": "2026-07-23T11:18:04.135Z",
      "date_updated": "2026-07-23T15:05:13.737Z",
      "publisher": "Patchstack",
      "title": "WordPress Download Monitor - WPForms Lock plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Download Monitor"
        ],
        "products": [
          {
            "vendor": "Download Monitor",
            "product": "Download Monitor - WPForms Lock"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07184
      },
      "nvd": {
        "published": "2026-07-23T12:18:28.803",
        "lastModified": "2026-07-23T16:17:27.410",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57427",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The extension places unauthenticated input into generated web content without the encoding required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/dlm-wpforms-lock/vulnerability/wordpress-download-monitor-wpforms-lock-plugin-1-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T12:46:44.605Z",
      "date_published": "2026-07-23T11:18:04.778Z",
      "date_updated": "2026-07-23T14:21:10.792Z",
      "publisher": "Patchstack",
      "title": "WordPress Sprout Clients plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "BoldGrid"
        ],
        "products": [
          {
            "vendor": "BoldGrid",
            "product": "Sprout Clients"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07183
      },
      "nvd": {
        "published": "2026-07-23T12:18:28.930",
        "lastModified": "2026-07-23T15:17:19.343",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57428",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Sprout Clients places unauthenticated attacker-controlled content into a browser-interpreted page without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/sprout-clients/vulnerability/wordpress-sprout-clients-plugin-3-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 79,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57432",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:09:26.322Z",
      "date_published": "2026-07-13T15:38:20.728Z",
      "date_updated": "2026-07-14T13:34:42.360Z",
      "publisher": "CPANSec",
      "title": "Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack",
      "affected": {
        "vendors": [
          "SHAY"
        ],
        "products": [
          {
            "vendor": "SHAY",
            "product": "perl"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11402
      },
      "nvd": {
        "published": "2026-07-13T17:17:55.670",
        "lastModified": "2026-07-14T18:04:48.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57432",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The perl parser can read beyond the end of its input or allocated buffer.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/13/6",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 610,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:09:26.322Z",
      "date_published": "2026-07-13T15:37:04.517Z",
      "date_updated": "2026-07-14T13:36:37.394Z",
      "publisher": "CPANSec",
      "title": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record",
      "affected": {
        "vendors": [
          "HAARG"
        ],
        "products": [
          {
            "vendor": "HAARG",
            "product": "Storable"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00357,
        "percentile": 0.28418
      },
      "nvd": {
        "published": "2026-07-13T17:17:55.783",
        "lastModified": "2026-07-14T17:47:20.473",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57433",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A signed item count plus one overflows before av_extend receives the resulting negative deserialization size.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/13/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Patch",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 457,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57439",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:21:20.729Z",
      "date_published": "2026-07-08T14:58:38.693Z",
      "date_updated": "2026-07-08T16:12:28.118Z",
      "publisher": "GitHub_M",
      "title": "CyberChef: Prototype pollution in Series Chart operation",
      "affected": {
        "vendors": [
          "gchq"
        ],
        "products": [
          {
            "vendor": "gchq",
            "product": "CyberChef"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00094,
        "percentile": 0.00735
      },
      "nvd": {
        "published": "2026-07-08T16:16:31.280",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57439",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CSV parser accepts __proto__ as an ordinary key and mutates the shared object prototype used by later operations.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gchq/CyberChef/security/advisories/GHSA-fx6f-382r-j72c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gchq/CyberChef/issues/2568",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gchq/CyberChef/pull/2569",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gchq/CyberChef/commit/85db3be5d0096859b810f0e8d3e151d5dc9b948f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gchq/CyberChef/releases/tag/v11.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57474",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:52:00.373Z",
      "date_published": "2026-07-10T17:10:15.585Z",
      "date_updated": "2026-07-21T17:06:47.452Z",
      "publisher": "cisa-cg",
      "title": "Deloitte AI Assist for Customer information disclosure",
      "affected": {
        "vendors": [
          "Deloitte"
        ],
        "products": [
          {
            "vendor": "Deloitte",
            "product": "AI Assist for Customer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21462
      },
      "nvd": {
        "published": "2026-07-10T18:16:24.657",
        "lastModified": "2026-07-21T18:17:02.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57474",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "AI Assist for Customer returns, logs, or renders sensitive state to a caller that has not passed the authorization or redaction boundary for that data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://zerotolerance.me/advisories/deloitte-aiassist-ascend-2026-vu487875/",
          "host": "zerotolerance.me",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://zerotolerance.me/advisories/assets/VU487875-deloitte-ascend-advisory.pdf",
          "host": "zerotolerance.me",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-191-01.json",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-57474",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57475",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:52:07.929Z",
      "date_published": "2026-07-10T17:10:35.437Z",
      "date_updated": "2026-08-03T18:19:52.994Z",
      "publisher": "cisa-cg",
      "title": "Deloitte AI Assist for Customer unauthenticated configuration write",
      "affected": {
        "vendors": [
          "Deloitte"
        ],
        "products": [
          {
            "vendor": "Deloitte",
            "product": "AI Assist for Customer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26618
      },
      "nvd": {
        "published": "2026-07-10T18:16:24.813",
        "lastModified": "2026-08-03T19:16:47.610",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57475",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Public AI Assist API endpoints accepted configuration writes without authenticating the remote caller.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://zerotolerance.me/advisories/deloitte-aiassist-ascend-2026-vu487875/",
          "host": "zerotolerance.me",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://zerotolerance.me/advisories/assets/VU487875-deloitte-ascend-advisory.pdf",
          "host": "zerotolerance.me",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-57475",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-191-01.json",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Technical Description",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T13:52:15.600Z",
      "date_published": "2026-07-10T17:10:50.682Z",
      "date_updated": "2026-08-03T18:20:12.103Z",
      "publisher": "cisa-cg",
      "title": "Deloitte AI Assist for Customer unauthenticated RAG corpus read and write",
      "affected": {
        "vendors": [
          "Deloitte"
        ],
        "products": [
          {
            "vendor": "Deloitte",
            "product": "AI Assist for Customer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16117
      },
      "nvd": {
        "published": "2026-07-10T18:16:24.947",
        "lastModified": "2026-08-03T19:16:47.783",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57476",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AI Assist for Customer reaches a protected operation without completing the authentication state or credential validation required for that path.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://zerotolerance.me/advisories/deloitte-aiassist-ascend-2026-vu487875/",
          "host": "zerotolerance.me",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://zerotolerance.me/advisories/assets/VU487875-deloitte-ascend-advisory.pdf",
          "host": "zerotolerance.me",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-191-01.json",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Technical Description",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-57476",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57480",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T14:53:40.110Z",
      "date_published": "2026-07-08T20:53:21.307Z",
      "date_updated": "2026-07-09T13:43:23.509Z",
      "publisher": "GitHub_M",
      "title": "Parse Server: Denial of service via exponential-time processing of deeply nested query operators",
      "affected": {
        "vendors": [
          "parse-community"
        ],
        "products": [
          {
            "vendor": "parse-community",
            "product": "parse-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26097
      },
      "nvd": {
        "published": "2026-07-08T21:16:50.890",
        "lastModified": "2026-07-10T19:07:46.400",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57480",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Deeply nested logical query operators cause exponential traversal and block Parse Server's event loop.",
        "basis": [
          "CNA",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/parse-community/parse-server/security/advisories/GHSA-cgxm-vr2f-6fj8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/pull/10511",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/pull/10512",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/commit/0f5d2ad77b422dc904458254548be87397fc6e9b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/commit/1103c7a890e0455ba3dccd4bc5db17efe1789c9a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/releases/tag/8.6.82",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/releases/tag/9.9.1-alpha.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 417,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T14:53:40.110Z",
      "date_published": "2026-07-08T20:54:55.923Z",
      "date_updated": "2026-07-10T14:14:39.740Z",
      "publisher": "GitHub_M",
      "title": "Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change",
      "affected": {
        "vendors": [
          "parse-community"
        ],
        "products": [
          {
            "vendor": "parse-community",
            "product": "parse-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31392
      },
      "nvd": {
        "published": "2026-07-08T21:16:51.043",
        "lastModified": "2026-07-10T19:07:46.400",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57481",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Parse Server emits the wrong pre-change or post-change object state when a save simultaneously changes fields and revokes LiveQuery read access.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/parse-community/parse-server/security/advisories/GHSA-97pr-9hgg-3p8r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/pull/10515",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/pull/10516",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/commit/c9b24cecfee76d8563019adaacbcbd78471dc41e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/commit/e9c85dfe40a866a55ebae3b6ae56285ac0a22e64",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/releases/tag/8.6.83",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/parse-community/parse-server/releases/tag/9.9.1-alpha.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 438,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57494",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T14:53:40.111Z",
      "date_published": "2026-07-20T22:01:43.891Z",
      "date_updated": "2026-07-21T14:56:03.184Z",
      "publisher": "GitHub_M",
      "title": "AgenticMail: Cross-agent task authorization bypass in AgenticMail API",
      "affected": {
        "vendors": [
          "agenticmail"
        ],
        "products": [
          {
            "vendor": "agenticmail",
            "product": "@agenticmail/api"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12554
      },
      "nvd": {
        "published": "2026-07-20T22:17:16.970",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57494",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AgenticMail lets a low-privileged agent address another agent's object identifier without checking ownership.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/agenticmail/agenticmail/security/advisories/GHSA-hjwc-26pj-v3pm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 884,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57495",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T14:53:40.111Z",
      "date_published": "2026-07-20T22:09:54.001Z",
      "date_updated": "2026-07-22T13:53:49.201Z",
      "publisher": "GitHub_M",
      "title": "AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)",
      "affected": {
        "vendors": [
          "agenticmail"
        ],
        "products": [
          {
            "vendor": "agenticmail",
            "product": "@agenticmail/core"
          },
          {
            "vendor": "agenticmail",
            "product": "@agenticmail/claudecode"
          },
          {
            "vendor": "agenticmail",
            "product": "@agenticmail/codex"
          },
          {
            "vendor": "agenticmail",
            "product": "@agenticmail/openclaw"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20358
      },
      "nvd": {
        "published": "2026-07-20T22:17:17.107",
        "lastModified": "2026-07-23T15:54:18.643",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57495",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Inbound mail resumes a bypassPermissions agent session without checking that the sender is the operator, placing attacker-controlled mail text into a privileged prompt.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/agenticmail/agenticmail/security/advisories/GHSA-fq4x-789w-jg5h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1233,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T14:53:40.112Z",
      "date_published": "2026-07-09T22:27:34.962Z",
      "date_updated": "2026-07-10T20:59:23.914Z",
      "publisher": "GitHub_M",
      "title": "Zen: Context-menu \"Open link in glance\" / \"Split link in new tab\" loads a page-controlled link with the System principal, bypassing the web-content scheme restriction",
      "affected": {
        "vendors": [
          "zen-browser"
        ],
        "products": [
          {
            "vendor": "zen-browser",
            "product": "desktop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 0,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21201
      },
      "nvd": {
        "published": "2026-07-09T23:17:05.353",
        "lastModified": "2026-07-10T21:16:59.583",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57501",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load a page-controlled link URL with the System principal instead of the originating page's principal, allowing a malicious web page to place a link to a file URL that can load with System privileges when opened through either context-menu item and bypass the content-to-file security check that blocks an ordinary click.",
        "basis": [
          "CNA",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zen-browser/desktop/security/advisories/GHSA-vpvg-hp3v-rm5q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/zen-browser/desktop/commit/44f7616238208200547c7df500d945752d7b6379",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/zen-browser/desktop/releases/tag/1.21.5b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57510",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T15:58:58.536Z",
      "date_published": "2026-07-28T19:06:14.550Z",
      "date_updated": "2026-07-28T19:50:02.065Z",
      "publisher": "VulnCheck",
      "title": "SuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC",
      "affected": {
        "vendors": [
          "superplanehq"
        ],
        "products": [
          {
            "vendor": "superplanehq",
            "product": "superplane"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26407
      },
      "nvd": {
        "published": "2026-07-28T20:17:27.027",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57510",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CanvasService handlers accept canvas and queue UUIDs without binding them to the authenticated user's organization.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/superplanehq/superplane/releases/tag/v0.27.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/superplanehq/superplane/pull/5635",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/superplanehq/superplane/commit/3e45cf4f1b5f1be9fbbfd90c97960a73f00f897b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/superplane-broken-object-level-authorization-via-canvasservice-grpc",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57511",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T15:58:58.537Z",
      "date_published": "2026-07-28T19:09:47.930Z",
      "date_updated": "2026-07-29T15:25:00.652Z",
      "publisher": "VulnCheck",
      "title": "SuperPlane < 0.30.0 SMTP Header Injection via Webhook Event Title",
      "affected": {
        "vendors": [
          "superplanehq"
        ],
        "products": [
          {
            "vendor": "superplanehq",
            "product": "superplane"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14604
      },
      "nvd": {
        "published": "2026-07-28T20:17:27.197",
        "lastModified": "2026-07-30T20:16:05.187",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57511",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A webhook title containing CRLF is copied into SMTP DATA headers without neutralization, allowing additional mail headers to be injected.",
        "basis": [
          "CNA",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/superplanehq/superplane/releases/tag/v0.30.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/superplanehq/superplane/pull/6354",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/superplanehq/superplane/commit/428c559dd2fa0aef3ba825a434a1b05c9abc7df7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/superplane-smtp-header-injection-via-webhook-event-title",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 503,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T15:58:58.537Z",
      "date_published": "2026-07-01T16:36:55.765Z",
      "date_updated": "2026-07-14T21:34:31.049Z",
      "publisher": "VulnCheck",
      "title": "Ray < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader",
      "affected": {
        "vendors": [
          "Anyscale, Inc"
        ],
        "products": [
          {
            "vendor": "Anyscale, Inc",
            "product": "Ray"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00553,
        "percentile": 0.4307
      },
      "nvd": {
        "published": "2026-07-01T17:16:37.390",
        "lastModified": "2026-07-14T22:17:23.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57516",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application deserializes attacker-controlled bytes with object semantics that can invoke executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ray-project/ray/releases/tag/ray-2.56.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/ray-project/ray/security/advisories/GHSA-hhrp-gw25-jr43",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/ray-project/ray/pull/63469",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/ray-project/ray/pull/63470",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ray-unsafe-deserialization-rce-via-webdataset-reader",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57517",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T15:58:58.537Z",
      "date_published": "2026-07-01T15:11:35.317Z",
      "date_updated": "2026-07-02T19:30:48.040Z",
      "publisher": "VulnCheck",
      "title": "Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter",
      "affected": {
        "vendors": [
          "Control Web Panel"
        ],
        "products": [
          {
            "vendor": "Control Web Panel",
            "product": "Control Web Panel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.01151,
        "percentile": 0.63786
      },
      "nvd": {
        "published": "2026-07-01T16:16:49.070",
        "lastModified": "2026-07-02T20:17:04.450",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57517",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a Control Web Panel database query without safe parameter binding, allowing query syntax injection.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://karmainsecurity.com/KIS-2026-12",
          "host": "karmainsecurity.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://control-webpanel.com/changelog#1773753427572-9bf81bf4-f2d2",
          "host": "control-webpanel.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/control-web-panel-blind-sql-injection-via-userres-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "http://seclists.org/fulldisclosure/2026/Jul/9",
          "host": "seclists.org",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T15:58:58.538Z",
      "date_published": "2026-07-24T19:08:20.323Z",
      "date_updated": "2026-07-25T10:30:02.895Z",
      "publisher": "VulnCheck",
      "title": "Milkdown < 7.21.3 Stored XSS via javascript: URL in link href",
      "affected": {
        "vendors": [
          "Milkdown"
        ],
        "products": [
          {
            "vendor": "Milkdown",
            "product": "milkdown"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07525
      },
      "nvd": {
        "published": "2026-07-24T20:18:02.893",
        "lastModified": "2026-07-27T20:37:34.230",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57530",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Milkdown stores a javascript URL as an href and sanitizes it as plain text rather than enforcing an allowed URL scheme.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Milkdown/milkdown/releases/tag/v7.21.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/Milkdown/milkdown/pull/2410",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/Milkdown/milkdown/commit/db1ae721854a0ab2f188b83cf8695702966640f1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.npmjs.com/package/@milkdown/preset-commonmark",
          "host": "www.npmjs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.npmjs.com/package/@milkdown/components",
          "host": "www.npmjs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/milkdown-stored-xss-via-javascript-url-in-link-href",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 688,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57531",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T15:58:58.538Z",
      "date_published": "2026-07-24T19:10:05.984Z",
      "date_updated": "2026-07-25T10:30:03.580Z",
      "publisher": "VulnCheck",
      "title": "Milkdown < 7.21.3 DOM XSS via innerHTML Assignment",
      "affected": {
        "vendors": [
          "Milkdown"
        ],
        "products": [
          {
            "vendor": "Milkdown",
            "product": "milkdown"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16322
      },
      "nvd": {
        "published": "2026-07-24T20:18:03.530",
        "lastModified": "2026-07-27T20:37:34.230",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57531",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A sanitizer bypass reaches innerHTML and turns attacker-controlled markup into executable browser content.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Milkdown/milkdown/releases/tag/v7.21.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/Milkdown/milkdown/pull/2410",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/Milkdown/milkdown/commit/db1ae721854a0ab2f188b83cf8695702966640f1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.npmjs.com/package/@milkdown/plugin-emoji",
          "host": "www.npmjs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/milkdown-dom-xss-via-innerhtml-assignment",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 631,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57571",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:49:56.207Z",
      "date_published": "2026-07-06T20:09:52.251Z",
      "date_updated": "2026-07-07T14:53:40.859Z",
      "publisher": "GitHub_M",
      "title": "Crawl4AI arbitrary file write via download filename path traversal",
      "affected": {
        "vendors": [
          "unclecode"
        ],
        "products": [
          {
            "vendor": "unclecode",
            "product": "crawl4ai"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00596,
        "percentile": 0.45144
      },
      "nvd": {
        "published": "2026-07-06T21:16:57.907",
        "lastModified": "2026-07-07T19:07:22.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57571",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The download filename is joined to the destination without confinement, so absolute or traversal paths select an arbitrary write target.",
        "basis": [
          "CNA record",
          "CWE-22",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/unclecode/crawl4ai/security/advisories/GHSA-2jq4-q6vv-4cp3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/unclecode/crawl4ai/commit/60886d1a0c52682e4c83a7cef9dfac417fff6bd2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 669,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57572",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:49:56.207Z",
      "date_published": "2026-07-06T20:16:21.597Z",
      "date_updated": "2026-07-08T19:42:13.954Z",
      "publisher": "GitHub_M",
      "title": "Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args",
      "affected": {
        "vendors": [
          "unclecode"
        ],
        "products": [
          {
            "vendor": "unclecode",
            "product": "crawl4ai"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00534,
        "percentile": 0.42069
      },
      "nvd": {
        "published": "2026-07-06T21:16:58.047",
        "lastModified": "2026-07-08T20:16:53.567",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57572",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "crawl4ai lets attacker-controlled argument text alter the option grammar of an invoked command.",
        "basis": [
          "CNA",
          "CWE-88",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/unclecode/crawl4ai/security/advisories/GHSA-r253-r9jw-qg44",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/unclecode/crawl4ai/commit/60886d1a0c52682e4c83a7cef9dfac417fff6bd2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 553,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57573",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:49:56.207Z",
      "date_published": "2026-07-06T20:11:15.691Z",
      "date_updated": "2026-07-07T14:16:25.619Z",
      "publisher": "GitHub_M",
      "title": "Crawl4AI unauthenticated SSRF in Docker streaming crawl endpoint",
      "affected": {
        "vendors": [
          "unclecode"
        ],
        "products": [
          {
            "vendor": "unclecode",
            "product": "crawl4ai"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17912
      },
      "nvd": {
        "published": "2026-07-06T21:16:58.197",
        "lastModified": "2026-07-07T19:07:47.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57573",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The streaming crawl path sends seed URLs directly to the crawler without the private-address validation used by the non-streaming path.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/unclecode/crawl4ai/security/advisories/GHSA-wm69-2pc3-rmmf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/unclecode/crawl4ai/commit/60886d1a0c52682e4c83a7cef9dfac417fff6bd2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57574",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:49:56.208Z",
      "date_published": "2026-07-10T20:55:49.896Z",
      "date_updated": "2026-07-13T18:55:15.968Z",
      "publisher": "GitHub_M",
      "title": "Misskey: TOTP tokens can be reused",
      "affected": {
        "vendors": [
          "misskey-dev"
        ],
        "products": [
          {
            "vendor": "misskey-dev",
            "product": "misskey"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-294",
          "name": "Authentication Bypass by Capture-replay",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26658
      },
      "nvd": {
        "published": "2026-07-10T21:16:59.683",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57574",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Misskey accepts the same TOTP value more than once during its valid time step instead of recording and rejecting prior use.",
        "basis": [
          "CNA",
          "CWE-294"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/misskey-dev/misskey/security/advisories/GHSA-2m5x-5mp6-6vpq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/misskey-dev/misskey/commit/00c6210a591db2b0be438740d05b82070fa68ac6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/misskey-dev/misskey/commit/d323fe00d04ac46ab0b4e66fce9169effaa8dfb7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/misskey-dev/misskey/releases/tag/2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 504,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57575",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:49:56.208Z",
      "date_published": "2026-07-10T20:54:33.347Z",
      "date_updated": "2026-07-14T14:08:13.314Z",
      "publisher": "GitHub_M",
      "title": "Misskey: SSRF bypass in URL Preview",
      "affected": {
        "vendors": [
          "misskey-dev"
        ],
        "products": [
          {
            "vendor": "misskey-dev",
            "product": "misskey"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27416
      },
      "nvd": {
        "published": "2026-07-10T21:16:59.820",
        "lastModified": "2026-07-14T15:17:06.090",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57575",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server follows an attacker-controlled outbound URL without constraining its destination to the intended remote service.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/misskey-dev/misskey/security/advisories/GHSA-jvcx-f39m-5xrj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/misskey-dev/misskey/commit/1eac4ccf513a067b9f7b7d123057c09a389fccee",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/misskey-dev/misskey/releases/tag/2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57584",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-24T18:49:56.209Z",
      "date_published": "2026-07-10T21:04:26.946Z",
      "date_updated": "2026-07-13T18:04:51.160Z",
      "publisher": "GitHub_M",
      "title": "Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS",
      "affected": {
        "vendors": [
          "phalcon"
        ],
        "products": [
          {
            "vendor": "phalcon",
            "product": "cphalcon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34521
      },
      "nvd": {
        "published": "2026-07-10T22:16:44.560",
        "lastModified": "2026-07-13T19:21:55.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57584",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The default router's nested-quantifier PCRE scans crafted request paths with catastrophic backtracking and can exhaust a worker's CPU.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/phalcon/cphalcon/security/advisories/GHSA-x7rj-f32v-7jjg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/phalcon/cphalcon/commit/14ba22d389d5ca620bb9d5207205f836ef1224f2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/phalcon/cphalcon/commit/fa798e919cb2c487062bb9899ad6fc2b673b3a67",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/phalcon/cphalcon/releases/tag/v5.15.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 634,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57599",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T02:07:05.126Z",
      "date_published": "2026-07-22T11:00:49.219Z",
      "date_updated": "2026-07-22T12:44:49.458Z",
      "publisher": "hikvision",
      "title": "There is a privilege escalation vulnerability in some Hikvision cameras.",
      "affected": {
        "vendors": [
          "Hikvision"
        ],
        "products": [
          {
            "vendor": "Hikvision",
            "product": "DS-2CD Series"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:hsrc@hikvision.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11417
      },
      "nvd": {
        "published": "2026-07-22T12:18:16.757",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57599",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Hikvision camera firmware assigns excessive privilege to an unspecified operation, but the public record does not identify the principal, object, or permission check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabilities-in-some-hikvision-cameras/",
          "host": "www.hikvision.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57600",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T02:07:05.126Z",
      "date_published": "2026-07-22T11:01:36.269Z",
      "date_updated": "2026-07-22T12:35:10.527Z",
      "publisher": "hikvision",
      "title": "Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.",
      "affected": {
        "vendors": [
          "Hikvision"
        ],
        "products": [
          {
            "vendor": "Hikvision",
            "product": "DS-2CD Series"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-2DE Series"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-2DP Series"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-2TD Series"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:hsrc@hikvision.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16221
      },
      "nvd": {
        "published": "2026-07-22T12:18:16.883",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57600",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record mentions input validation and data retrieval impact without naming the input, parser, policy, or failing check.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabilities-in-some-hikvision-cameras/",
          "host": "www.hikvision.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 154,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-57621",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:02.838Z",
      "date_published": "2026-07-02T11:15:24.897Z",
      "date_updated": "2026-07-02T12:42:35.622Z",
      "publisher": "Patchstack",
      "title": "WordPress Booktics plugin <= 1.0.21 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "Arraytics"
        ],
        "products": [
          {
            "vendor": "Arraytics",
            "product": "Booktics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25156
      },
      "nvd": {
        "published": "2026-07-02T12:17:37.043",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57621",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Booktics path permits attacker-controlled serialized data or a dangerous object graph to reach a deserializer.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/booktics/vulnerability/wordpress-booktics-plugin-1-0-21-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 68,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57623",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:02.838Z",
      "date_published": "2026-07-02T11:15:25.775Z",
      "date_updated": "2026-07-02T14:37:19.947Z",
      "publisher": "Patchstack",
      "title": "WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability",
      "affected": {
        "vendors": [
          "BoldGrid"
        ],
        "products": [
          {
            "vendor": "BoldGrid",
            "product": "W3 Total Cache"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24714
      },
      "nvd": {
        "published": "2026-07-02T12:17:37.163",
        "lastModified": "2026-07-02T15:17:09.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57623",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record states unauthenticated code execution in W3 Total Cache but does not identify the request, interpreter boundary, included file, command, or code path that enables it.",
        "basis": [
          "CNA",
          "CWE-1284",
          "WordPress.org W3 Total Cache changelog"
        ],
        "deepDive": true,
        "notes": "Inspected https://wordpress.org/plugins/w3-total-cache/; the official 2.10.0 changelog broadly lists strengthened code, command, file-inclusion, dynamic-content, authorization, and request protections after 2.9.4, but it does not map CVE-2026-57623 to a request or code path."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/w3-total-cache/vulnerability/wordpress-w3-total-cache-plugin-2-9-4-arbitrary-code-execution-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 77,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57624",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:02.838Z",
      "date_published": "2026-07-02T11:15:26.664Z",
      "date_updated": "2026-07-02T19:39:14.229Z",
      "publisher": "Patchstack",
      "title": "WordPress Blocksy Companion Pro plugin <= 2.1.46 - Remote Code Execution (RCE) vulnerability",
      "affected": {
        "vendors": [
          "Creative Themes"
        ],
        "products": [
          {
            "vendor": "Creative Themes",
            "product": "Blocksy Companion Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00677,
        "percentile": 0.48752
      },
      "nvd": {
        "published": "2026-07-02T12:17:37.277",
        "lastModified": "2026-07-02T20:17:04.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57624",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public Patchstack entry reports unauthenticated code execution in Blocksy Companion Pro through 2.1.46 but does not disclose the request handler, attacker-controlled value, or interpreter sink.",
        "basis": [
          "CNA",
          "CWE-94",
          "Patchstack PSID 01683290412b"
        ],
        "deepDive": true,
        "notes": "Inspected https://patchstack.com/database/wordpress/plugin/blocksy-companion-pro/vulnerability/wordpress-blocksy-companion-pro-plugin-2-1-46-remote-code-execution-rce-vulnerability. The entry confirms affected <=2.1.46 and fixed 2.1.47 but publishes no handler, value, or sink. Its page displays a \"Known to be exploited! (KEV)\" badge while the shard CISA KEV field is false and an official CISA catalog search returned no matching entry; do not silently reinterpret the Patchstack badge as CISA KEV status."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/blocksy-companion-pro/vulnerability/wordpress-blocksy-companion-pro-plugin-2-1-46-remote-code-execution-rce-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 88,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57625",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:02.838Z",
      "date_published": "2026-07-02T11:15:27.684Z",
      "date_updated": "2026-07-02T19:44:52.133Z",
      "publisher": "Patchstack",
      "title": "WordPress Admin and Site Enhancements (ASE) Pro plugin <= 8.8.5 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "ASE"
        ],
        "products": [
          {
            "vendor": "ASE",
            "product": "Admin and Site Enhancements (ASE) Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17732
      },
      "nvd": {
        "published": "2026-07-02T12:17:37.393",
        "lastModified": "2026-07-02T20:17:04.670",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57625",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Admin and Site Enhancements Pro renders unauthenticated input as active HTML or script without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/admin-site-enhancements-pro/vulnerability/wordpress-admin-and-site-enhancements-ase-pro-plugin-8-8-5-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57626",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:02.838Z",
      "date_published": "2026-07-23T11:46:34.433Z",
      "date_updated": "2026-07-23T14:36:37.579Z",
      "publisher": "Patchstack",
      "title": "WordPress MailPoet plugin 5.30.0-5.33.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "MailPoet"
        ],
        "products": [
          {
            "vendor": "MailPoet",
            "product": "MailPoet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00089,
        "percentile": 0.00501
      },
      "nvd": {
        "published": "2026-07-23T12:18:29.053",
        "lastModified": "2026-07-23T15:17:20.197",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57626",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mailpoet/vulnerability/wordpress-mailpoet-plugin-5-30-0-5-33-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 152,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57668",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:37.652Z",
      "date_published": "2026-07-13T08:41:24.532Z",
      "date_updated": "2026-07-13T13:50:56.456Z",
      "publisher": "Patchstack",
      "title": "WordPress NEX-Forms plugin <= 9.2.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Basix"
        ],
        "products": [
          {
            "vendor": "Basix",
            "product": "NEX-Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07171
      },
      "nvd": {
        "published": "2026-07-13T10:16:36.547",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57668",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/nex-forms-express-wp-form-builder/vulnerability/wordpress-nex-forms-plugin-9-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57669",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:37.652Z",
      "date_published": "2026-07-02T11:15:28.678Z",
      "date_updated": "2026-07-02T15:53:11.900Z",
      "publisher": "Patchstack",
      "title": "WordPress Advanced Contact form 7 DB plugin <= 2.0.9 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Vsourz Digital"
        ],
        "products": [
          {
            "vendor": "Vsourz Digital",
            "product": "Advanced Contact form 7 DB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26668
      },
      "nvd": {
        "published": "2026-07-02T12:17:37.507",
        "lastModified": "2026-07-02T16:16:34.633",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57669",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/advanced-cf7-db/vulnerability/wordpress-advanced-contact-form-7-db-plugin-2-0-9-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 81,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57670",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:37.652Z",
      "date_published": "2026-07-02T11:15:29.530Z",
      "date_updated": "2026-07-02T12:10:00.416Z",
      "publisher": "Patchstack",
      "title": "WordPress Google Maps CP plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Codepeople"
        ],
        "products": [
          {
            "vendor": "Codepeople",
            "product": "Google Maps CP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.0839
      },
      "nvd": {
        "published": "2026-07-02T12:17:37.623",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57670",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Google Maps CP page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/codepeople-post-map/vulnerability/wordpress-google-maps-cp-plugin-1-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 79,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57671",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:37.652Z",
      "date_published": "2026-07-02T11:15:30.540Z",
      "date_updated": "2026-07-02T12:39:50.501Z",
      "publisher": "Patchstack",
      "title": "WordPress perfmatters plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Perfmatters"
        ],
        "products": [
          {
            "vendor": "Perfmatters",
            "product": "perfmatters"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.0839
      },
      "nvd": {
        "published": "2026-07-02T12:17:37.753",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57671",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The plugin places unauthenticated input into generated web content without the encoding required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/perfmatters/vulnerability/wordpress-perfmatters-plugin-2-6-4-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 76,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57672",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:37.652Z",
      "date_published": "2026-07-02T11:15:31.433Z",
      "date_updated": "2026-07-02T14:34:19.764Z",
      "publisher": "Patchstack",
      "title": "WordPress wpDataTables plugin <= 6.5.1.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Melograno Venture Studio"
        ],
        "products": [
          {
            "vendor": "Melograno Venture Studio",
            "product": "wpDataTables"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08391
      },
      "nvd": {
        "published": "2026-07-02T12:17:37.873",
        "lastModified": "2026-07-02T15:17:09.997",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57672",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "wpDataTables places unauthenticated attacker-controlled content into a browser-interpreted page without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wpdatatables/vulnerability/wordpress-wpdatatables-plugin-6-5-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 79,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57673",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:37.652Z",
      "date_published": "2026-07-02T11:15:32.255Z",
      "date_updated": "2026-07-02T19:39:29.404Z",
      "publisher": "Patchstack",
      "title": "WordPress Optimole plugin <= 4.2.7 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Optimole"
        ],
        "products": [
          {
            "vendor": "Optimole",
            "product": "Optimole"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.0839
      },
      "nvd": {
        "published": "2026-07-02T12:17:37.993",
        "lastModified": "2026-07-02T20:17:04.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57673",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Optimole renders unauthenticated input as executable browser markup, although the public record does not identify the source field or sink.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/optimole-wp/vulnerability/wordpress-optimole-plugin-4-2-7-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 73,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57674",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:37.652Z",
      "date_published": "2026-07-02T11:15:33.276Z",
      "date_updated": "2026-07-02T19:45:09.915Z",
      "publisher": "Patchstack",
      "title": "WordPress Timetics plugin <= 1.0.58 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Arraytics"
        ],
        "products": [
          {
            "vendor": "Arraytics",
            "product": "Timetics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.0839
      },
      "nvd": {
        "published": "2026-07-02T12:17:38.110",
        "lastModified": "2026-07-02T20:17:04.867",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57674",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Timetics page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/timetics/vulnerability/wordpress-timetics-plugin-1-0-58-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 74,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57675",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:37.652Z",
      "date_published": "2026-07-02T11:15:34.376Z",
      "date_updated": "2026-07-02T15:53:05.993Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Photo Album Plus plugin <= 9.2.02.004 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Jacob N. Breetvelt"
        ],
        "products": [
          {
            "vendor": "Jacob N. Breetvelt",
            "product": "WP Photo Album Plus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08391
      },
      "nvd": {
        "published": "2026-07-02T12:17:38.220",
        "lastModified": "2026-07-02T16:16:34.727",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57675",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WP Photo Album Plus permits unauthenticated input to reach generated page markup as executable browser content.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-photo-album-plus/vulnerability/wordpress-wp-photo-album-plus-plugin-9-2-02-004-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 89,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57677",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:42.566Z",
      "date_published": "2026-07-02T11:15:35.175Z",
      "date_updated": "2026-07-02T12:09:37.862Z",
      "publisher": "Patchstack",
      "title": "WordPress Novalnet Payment Gateway for WooCommerce plugin <= 12.10.3 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "Novalnet"
        ],
        "products": [
          {
            "vendor": "Novalnet",
            "product": "Novalnet Payment Gateway for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25156
      },
      "nvd": {
        "published": "2026-07-02T12:17:38.340",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57677",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Novalnet Payment Gateway for WooCommerce, attacker-controlled serialized data is deserialized into live objects during security-sensitive processing.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-novalnet-gateway/vulnerability/wordpress-novalnet-payment-gateway-for-woocommerce-plugin-12-10-3-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57678",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:42.567Z",
      "date_published": "2026-07-02T11:32:06.900Z",
      "date_updated": "2026-07-02T12:21:24.825Z",
      "publisher": "Patchstack",
      "title": "WordPress Slider Revolution plugin 7.0.0-7.0.16 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "ThemePunch"
        ],
        "products": [
          {
            "vendor": "ThemePunch",
            "product": "Slider Revolution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00151,
        "percentile": 0.04746
      },
      "nvd": {
        "published": "2026-07-02T12:17:38.467",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57678",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Slider Revolution places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/revslider/vulnerability/wordpress-slider-revolution-plugin-7-0-16-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57679",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:42.567Z",
      "date_published": "2026-07-02T11:15:36.020Z",
      "date_updated": "2026-07-02T12:42:12.099Z",
      "publisher": "Patchstack",
      "title": "WordPress GeekyBot plugin <= 1.2.5 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Ahmadgb"
        ],
        "products": [
          {
            "vendor": "Ahmadgb",
            "product": "GeekyBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15155
      },
      "nvd": {
        "published": "2026-07-02T12:17:38.587",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57679",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeekyBot incorporates unauthenticated input into an SQL statement without preserving the SQL data boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/geeky-bot/vulnerability/wordpress-geekybot-plugin-1-2-5-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 60,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57680",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:42.567Z",
      "date_published": "2026-07-02T11:15:36.880Z",
      "date_updated": "2026-07-02T13:46:34.079Z",
      "publisher": "Patchstack",
      "title": "WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) vulnerability",
      "affected": {
        "vendors": [
          "Themeum"
        ],
        "products": [
          {
            "vendor": "Themeum",
            "product": "Kirki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16735
      },
      "nvd": {
        "published": "2026-07-02T12:17:38.710",
        "lastModified": "2026-07-02T15:17:10.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57680",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kirki accepts a caller-supplied object identifier without binding the selected object to the caller's ownership or authorized scope.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/kirki/vulnerability/wordpress-kirki-plugin-6-0-11-insecure-direct-object-references-idor-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 85,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57681",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:42.567Z",
      "date_published": "2026-07-02T11:15:37.858Z",
      "date_updated": "2026-07-02T19:39:43.639Z",
      "publisher": "Patchstack",
      "title": "WordPress GeoDirectory plugin <= 2.8.161 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "Paolo"
        ],
        "products": [
          {
            "vendor": "Paolo",
            "product": "GeoDirectory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13057
      },
      "nvd": {
        "published": "2026-07-02T12:17:38.843",
        "lastModified": "2026-07-02T20:17:04.967",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57681",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoDirectory lets a subscriber make the server issue a request to an attacker-selected destination.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/geodirectory/vulnerability/wordpress-geodirectory-plugin-2-8-161-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57682",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:42.567Z",
      "date_published": "2026-07-02T11:15:38.688Z",
      "date_updated": "2026-07-02T19:45:25.905Z",
      "publisher": "Patchstack",
      "title": "WordPress Simple Link Directory plugin <= 15.0.5 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "QuantumCloud"
        ],
        "products": [
          {
            "vendor": "QuantumCloud",
            "product": "Simple Link Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08395
      },
      "nvd": {
        "published": "2026-07-02T12:17:38.963",
        "lastModified": "2026-07-02T20:17:05.063",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57682",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Simple Link Directory returns unauthenticated input as active page markup without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/qc-simple-link-directory/vulnerability/wordpress-simple-link-directory-plugin-15-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 87,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57683",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:42.567Z",
      "date_published": "2026-07-02T11:15:39.645Z",
      "date_updated": "2026-07-02T15:52:58.310Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Fast Total Search plugin <= 1.80.280 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Epsiloncool"
        ],
        "products": [
          {
            "vendor": "Epsiloncool",
            "product": "WP Fast Total Search"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15155
      },
      "nvd": {
        "published": "2026-07-02T12:17:39.080",
        "lastModified": "2026-07-02T16:16:34.820",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57683",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WP Fast Total Search passes unauthenticated input into SQL without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89",
          "WordPress plugin source 1.80.280"
        ],
        "deepDive": true,
        "notes": "Inspected the official WordPress.org source archive at https://downloads.wordpress.org/plugin/fulltext-search.1.80.280.zip; the release exposes unauthenticated search-related handlers and numerous dynamic SQL paths, but the public material does not isolate the vulnerable parameter and query sink, and no runtime reproduction was performed."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/fulltext-search/vulnerability/wordpress-wp-fast-total-search-plugin-1-80-280-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:42.567Z",
      "date_published": "2026-07-02T11:15:40.513Z",
      "date_updated": "2026-07-02T12:09:10.659Z",
      "publisher": "Patchstack",
      "title": "WordPress TheFox theme <= 3.9.70 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "tranmautritam"
        ],
        "products": [
          {
            "vendor": "tranmautritam",
            "product": "TheFox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06217
      },
      "nvd": {
        "published": "2026-07-02T12:17:39.200",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57684",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/thefox/vulnerability/wordpress-thefox-theme-3-9-70-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 68,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:42.567Z",
      "date_published": "2026-07-02T11:15:41.410Z",
      "date_updated": "2026-07-02T12:41:48.874Z",
      "publisher": "Patchstack",
      "title": "WordPress Martfury - WooCommerce Marketplace WordPress theme theme <= 3.2.8 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "drfuri"
        ],
        "products": [
          {
            "vendor": "drfuri",
            "product": "Martfury - WooCommerce Marketplace WordPress Theme"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16921
      },
      "nvd": {
        "published": "2026-07-02T12:17:39.327",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57685",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Patchstack record identifies a subscriber-reachable access-control failure but does not name the protected operation or object.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/martfury/vulnerability/wordpress-martfury-woocommerce-marketplace-wordpress-theme-theme-3-2-8-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57686",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:42.567Z",
      "date_published": "2026-07-02T11:15:42.213Z",
      "date_updated": "2026-07-02T13:55:19.542Z",
      "publisher": "Patchstack",
      "title": "WordPress WowAddons plugin <= 1.6.14 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WPXPO"
        ],
        "products": [
          {
            "vendor": "WPXPO",
            "product": "WowAddons"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08394
      },
      "nvd": {
        "published": "2026-07-02T12:17:39.447",
        "lastModified": "2026-07-02T15:17:10.223",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57686",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/product-addons/vulnerability/wordpress-wowaddons-plugin-1-6-14-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:50.156Z",
      "date_published": "2026-07-02T11:15:43.062Z",
      "date_updated": "2026-07-02T19:39:57.078Z",
      "publisher": "Patchstack",
      "title": "WordPress Custom Field Template plugin <= 2.7.8 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Hiroaki Miyashita"
        ],
        "products": [
          {
            "vendor": "Hiroaki Miyashita",
            "product": "Custom Field Template"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11862
      },
      "nvd": {
        "published": "2026-07-02T12:17:39.563",
        "lastModified": "2026-07-02T20:17:05.170",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57687",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/custom-field-template/vulnerability/wordpress-custom-field-template-plugin-2-7-8-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 69,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:50.157Z",
      "date_published": "2026-07-02T11:15:44.112Z",
      "date_updated": "2026-07-02T19:45:40.946Z",
      "publisher": "Patchstack",
      "title": "WordPress POS Entegratör plugin <= 3.7.103 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Gurmehub"
        ],
        "products": [
          {
            "vendor": "Gurmehub",
            "product": "POS Entegratör"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.1446
      },
      "nvd": {
        "published": "2026-07-02T12:17:39.687",
        "lastModified": "2026-07-02T20:17:05.277",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57688",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/pos-entegrator/vulnerability/wordpress-pos-entegratoer-plugin-3-7-103-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 76,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57689",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:50.157Z",
      "date_published": "2026-07-02T11:15:45.096Z",
      "date_updated": "2026-07-02T15:52:52.711Z",
      "publisher": "Patchstack",
      "title": "WordPress Werkstatt theme <= 4.7.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Fuelthemes"
        ],
        "products": [
          {
            "vendor": "Fuelthemes",
            "product": "Werkstatt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12874
      },
      "nvd": {
        "published": "2026-07-02T12:17:39.810",
        "lastModified": "2026-07-02T16:16:34.913",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57689",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Werkstatt permits a subscriber to cross an access-control boundary, but the public record does not identify the protected action or object.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/werkstatt/vulnerability/wordpress-werkstatt-theme-4-7-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 64,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:50.157Z",
      "date_published": "2026-07-02T11:15:46.156Z",
      "date_updated": "2026-07-02T12:08:49.762Z",
      "publisher": "Patchstack",
      "title": "WordPress Werkstatt theme <= 4.7.2 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "Fuelthemes"
        ],
        "products": [
          {
            "vendor": "Fuelthemes",
            "product": "Werkstatt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00104,
        "percentile": 0.01193
      },
      "nvd": {
        "published": "2026-07-02T12:17:39.930",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57690",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A Werkstatt state-changing action trusts a cross-site browser request, but the affected action and missing anti-CSRF binding are not public.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/werkstatt/vulnerability/wordpress-werkstatt-theme-4-7-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 81,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57691",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:50.157Z",
      "date_published": "2026-07-13T08:41:24.532Z",
      "date_updated": "2026-07-13T16:07:51.627Z",
      "publisher": "Patchstack",
      "title": "WordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.23.89 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Eli"
        ],
        "products": [
          {
            "vendor": "Eli",
            "product": "Anti-Malware Security and Brute-Force Firewall"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04518
      },
      "nvd": {
        "published": "2026-07-13T10:16:36.663",
        "lastModified": "2026-07-13T17:17:55.893",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57691",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content is rendered without the browser-context separation required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/gotmls/vulnerability/wordpress-anti-malware-security-and-brute-force-firewall-plugin-4-23-89-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57692",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:50.157Z",
      "date_published": "2026-07-01T13:34:09.184Z",
      "date_updated": "2026-07-01T14:25:49.078Z",
      "publisher": "Patchstack",
      "title": "WordPress PrivateContent plugin <= 9.9.2 - Privilege Escalation vulnerability",
      "affected": {
        "vendors": [
          "LCweb"
        ],
        "products": [
          {
            "vendor": "LCweb",
            "product": "PrivateContent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20578
      },
      "nvd": {
        "published": "2026-07-01T14:16:46.800",
        "lastModified": "2026-07-01T18:22:18.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57692",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "PrivateContent assigns a privilege outside the user's intended role, allowing that user to escalate authority.",
        "basis": [
          "CNA record",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/private-content/vulnerability/wordpress-privatecontent-plugin-9-9-2-privilege-escalation-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 157,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57693",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:50.157Z",
      "date_published": "2026-07-13T08:41:24.533Z",
      "date_updated": "2026-07-13T16:07:51.470Z",
      "publisher": "Patchstack",
      "title": "WordPress Ad Inserter plugin <= 2.8.11 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Spacetime"
        ],
        "products": [
          {
            "vendor": "Spacetime",
            "product": "Ad Inserter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.0526
      },
      "nvd": {
        "published": "2026-07-13T10:16:36.780",
        "lastModified": "2026-07-13T17:17:56.750",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57693",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ad Inserter renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/ad-inserter/vulnerability/wordpress-ad-inserter-plugin-2-8-11-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57694",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:50.157Z",
      "date_published": "2026-07-13T08:41:24.530Z",
      "date_updated": "2026-07-13T13:41:02.541Z",
      "publisher": "Patchstack",
      "title": "WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerability",
      "affected": {
        "vendors": [
          "Themeum"
        ],
        "products": [
          {
            "vendor": "Themeum",
            "product": "Tutor LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14834
      },
      "nvd": {
        "published": "2026-07-13T10:16:36.893",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57694",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tutor LMS accepts a user-controlled object key without binding the selected object to the caller's authorization scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/tutor/vulnerability/wordpress-tutor-lms-plugin-3-9-13-insecure-direct-object-references-idor-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:50.157Z",
      "date_published": "2026-07-13T08:41:24.538Z",
      "date_updated": "2026-07-13T14:38:54.274Z",
      "publisher": "Patchstack",
      "title": "WordPress Document Gallery plugin <= 5.1.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Dan Rossiter"
        ],
        "products": [
          {
            "vendor": "Dan Rossiter",
            "product": "Document Gallery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07587
      },
      "nvd": {
        "published": "2026-07-13T10:16:37.020",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57695",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Document Gallery, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/document-gallery/vulnerability/wordpress-document-gallery-plugin-5-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57696",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:50.157Z",
      "date_published": "2026-07-23T11:18:05.427Z",
      "date_updated": "2026-07-23T16:01:48.198Z",
      "publisher": "Patchstack",
      "title": "WordPress Picture Gallery plugin <= 1.6.5 - Arbitrary File Deletion vulnerability",
      "affected": {
        "vendors": [
          "videowhisper"
        ],
        "products": [
          {
            "vendor": "videowhisper",
            "product": "Picture Gallery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.22982
      },
      "nvd": {
        "published": "2026-07-23T12:18:29.180",
        "lastModified": "2026-07-23T16:17:27.507",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57696",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The plugin lets a Contributor select a file for deletion outside the intended object set, but the controlling parameter and confinement check are not public.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/picture-gallery/vulnerability/wordpress-picture-gallery-plugin-1-6-5-arbitrary-file-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 73,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:56.313Z",
      "date_published": "2026-07-13T08:41:24.539Z",
      "date_updated": "2026-07-13T13:31:33.330Z",
      "publisher": "Patchstack",
      "title": "WordPress ProfileGrid  plugin <= 5.9.9.6 - Broken Authentication vulnerability",
      "affected": {
        "vendors": [
          "Metagauss"
        ],
        "products": [
          {
            "vendor": "Metagauss",
            "product": "ProfileGrid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24336
      },
      "nvd": {
        "published": "2026-07-13T10:16:37.143",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57697",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ProfileGrid exposes an alternate password-recovery path that bypasses the authentication checks enforced by the normal recovery flow.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/profilegrid-user-profiles-groups-and-communities/vulnerability/wordpress-profilegrid-plugin-5-9-9-6-broken-authentication-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:56.313Z",
      "date_published": "2026-07-13T08:41:24.541Z",
      "date_updated": "2026-07-13T13:51:17.490Z",
      "publisher": "Patchstack",
      "title": "WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken Authentication vulnerability",
      "affected": {
        "vendors": [
          "VillaTheme"
        ],
        "products": [
          {
            "vendor": "VillaTheme",
            "product": "Abandoned Cart Recovery for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15745
      },
      "nvd": {
        "published": "2026-07-13T10:16:37.260",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57698",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Patchstack record names an alternate authentication path in Abandoned Cart Recovery but does not publish the route, credential, or normal check that is skipped.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/woo-abandoned-cart-recovery/vulnerability/wordpress-abandoned-cart-recovery-for-woocommerce-plugin-1-1-12-broken-authentication-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57699",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:56.313Z",
      "date_published": "2026-07-23T11:18:06.070Z",
      "date_updated": "2026-07-23T14:53:29.699Z",
      "publisher": "Patchstack",
      "title": "WordPress Slider Pro plugin <= 4.8.13 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "bqworks"
        ],
        "products": [
          {
            "vendor": "bqworks",
            "product": "Slider Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14759
      },
      "nvd": {
        "published": "2026-07-23T12:18:29.310",
        "lastModified": "2026-07-23T16:17:27.610",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57699",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data crosses into an executable grammar without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/sliderpro/vulnerability/wordpress-slider-pro-plugin-4-8-13-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 71,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57701",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:56.313Z",
      "date_published": "2026-07-23T11:18:06.713Z",
      "date_updated": "2026-07-23T13:40:27.605Z",
      "publisher": "Patchstack",
      "title": "WordPress Real Estate Manager Pro plugin <= 12.8.5 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WebCodingPlace"
        ],
        "products": [
          {
            "vendor": "WebCodingPlace",
            "product": "Real Estate Manager Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.0775
      },
      "nvd": {
        "published": "2026-07-23T12:18:29.440",
        "lastModified": "2026-07-23T14:17:25.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57701",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Real Estate Manager Pro rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/real-estate-manager-pro/vulnerability/wordpress-real-estate-manager-pro-plugin-12-8-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 89,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57702",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:56.313Z",
      "date_published": "2026-07-13T08:41:24.612Z",
      "date_updated": "2026-07-13T16:07:51.325Z",
      "publisher": "Patchstack",
      "title": "WordPress Amelia plugin <= 2.4.2 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Melograno Venture Studio"
        ],
        "products": [
          {
            "vendor": "Melograno Venture Studio",
            "product": "Amelia"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20533
      },
      "nvd": {
        "published": "2026-07-13T10:16:37.377",
        "lastModified": "2026-07-13T17:17:57.383",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57702",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Amelia incorporates attacker-controlled input into an SQL statement without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/ameliabooking/vulnerability/wordpress-amelia-plugin-2-4-2-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57703",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:56.313Z",
      "date_published": "2026-07-23T11:18:07.347Z",
      "date_updated": "2026-07-23T13:52:33.205Z",
      "publisher": "Patchstack",
      "title": "WordPress Sunshine Photo Cart plugin <= 3.6.10.1 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "sunshinephotocart"
        ],
        "products": [
          {
            "vendor": "sunshinephotocart",
            "product": "Sunshine Photo Cart"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16311
      },
      "nvd": {
        "published": "2026-07-23T12:18:29.560",
        "lastModified": "2026-07-23T14:17:25.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57703",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Sunshine Photo Cart permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/sunshine-photo-cart/vulnerability/wordpress-sunshine-photo-cart-plugin-3-6-10-1-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 77,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57704",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:56.314Z",
      "date_published": "2026-07-23T11:18:07.981Z",
      "date_updated": "2026-07-23T15:04:01.599Z",
      "publisher": "Patchstack",
      "title": "WordPress Smart Manager plugin <= 8.90.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "StoreApps"
        ],
        "products": [
          {
            "vendor": "StoreApps",
            "product": "Smart Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07751
      },
      "nvd": {
        "published": "2026-07-23T12:18:29.680",
        "lastModified": "2026-07-23T16:17:27.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57704",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Smart Manager renders unauthenticated input as active HTML or script without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/smart-manager-for-wp-e-commerce/vulnerability/wordpress-smart-manager-plugin-8-90-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 79,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57705",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:56.314Z",
      "date_published": "2026-07-13T08:41:24.629Z",
      "date_updated": "2026-07-13T16:07:51.185Z",
      "publisher": "Patchstack",
      "title": "WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Nexcess"
        ],
        "products": [
          {
            "vendor": "Nexcess",
            "product": "Event Tickets"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14976
      },
      "nvd": {
        "published": "2026-07-13T10:16:37.493",
        "lastModified": "2026-07-13T17:17:58.030",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57705",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/event-tickets/vulnerability/wordpress-event-tickets-plugin-5-28-5-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57706",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:03:56.314Z",
      "date_published": "2026-07-13T08:41:24.672Z",
      "date_updated": "2026-07-13T13:40:24.015Z",
      "publisher": "Patchstack",
      "title": "WordPress Dokan plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Dokan, Inc."
        ],
        "products": [
          {
            "vendor": "Dokan, Inc.",
            "product": "Dokan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07168
      },
      "nvd": {
        "published": "2026-07-13T10:16:37.623",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57706",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/dokan-lite/vulnerability/wordpress-dokan-plugin-5-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57707",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:04.789Z",
      "date_published": "2026-07-13T08:41:24.686Z",
      "date_updated": "2026-07-13T14:38:50.094Z",
      "publisher": "Patchstack",
      "title": "WordPress Simple Business Directory Pro plugin <= 15.9.4 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "quantumcloud"
        ],
        "products": [
          {
            "vendor": "quantumcloud",
            "product": "Simple Business Directory Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20532
      },
      "nvd": {
        "published": "2026-07-13T10:16:37.743",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57707",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/simple-business-directory-pro/vulnerability/wordpress-simple-business-directory-pro-plugin-15-9-4-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57708",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:04.790Z",
      "date_published": "2026-07-13T08:41:24.683Z",
      "date_updated": "2026-07-13T13:31:13.641Z",
      "publisher": "Patchstack",
      "title": "WordPress Contact Form Entries plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "CRM Perks"
        ],
        "products": [
          {
            "vendor": "CRM Perks",
            "product": "Contact Form Entries"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07168
      },
      "nvd": {
        "published": "2026-07-13T10:16:37.900",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57708",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Contact Form Entries page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/contact-form-entries/vulnerability/wordpress-contact-form-entries-plugin-1-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 242,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57709",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:04.790Z",
      "date_published": "2026-07-13T08:41:24.686Z",
      "date_updated": "2026-07-13T13:51:42.927Z",
      "publisher": "Patchstack",
      "title": "WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletion vulnerability",
      "affected": {
        "vendors": [
          "WP Swings"
        ],
        "products": [
          {
            "vendor": "WP Swings",
            "product": "Membership For WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29873
      },
      "nvd": {
        "published": "2026-07-13T10:16:38.020",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57709",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A deletion path accepts traversal segments and selects a file outside the intended Membership For WooCommerce directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/membership-for-woocommerce/vulnerability/wordpress-membership-for-woocommerce-plugin-3-1-0-arbitrary-file-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57710",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:04.790Z",
      "date_published": "2026-07-13T08:41:24.688Z",
      "date_updated": "2026-07-13T16:07:51.047Z",
      "publisher": "Patchstack",
      "title": "WordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerability",
      "affected": {
        "vendors": [
          "quantumcloud"
        ],
        "products": [
          {
            "vendor": "quantumcloud",
            "product": "WoowBot Pro Max"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24311
      },
      "nvd": {
        "published": "2026-07-13T10:16:38.143",
        "lastModified": "2026-07-13T17:17:58.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57710",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WoowBot accepts a dangerous uploaded file type as a permitted server-side file object.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/woowbot-pro-max/vulnerability/wordpress-woowbot-pro-max-plugin-14-1-7-arbitrary-file-upload-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57711",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:04.790Z",
      "date_published": "2026-07-13T08:41:24.688Z",
      "date_updated": "2026-07-13T16:07:50.905Z",
      "publisher": "Patchstack",
      "title": "WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "PSM Plugins"
        ],
        "products": [
          {
            "vendor": "PSM Plugins",
            "product": "SupportCandy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05263
      },
      "nvd": {
        "published": "2026-07-13T10:16:38.267",
        "lastModified": "2026-07-13T17:17:59.307",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57711",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "SupportCandy stores attacker-controlled content and later emits it as executable browser markup without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/supportcandy/vulnerability/wordpress-supportcandy-plugin-3-4-8-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57712",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:04.790Z",
      "date_published": "2026-07-13T08:41:24.689Z",
      "date_updated": "2026-07-13T13:39:32.425Z",
      "publisher": "Patchstack",
      "title": "WordPress WPZOOM Portfolio plugin <= 1.4.29 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WPZOOM"
        ],
        "products": [
          {
            "vendor": "WPZOOM",
            "product": "WPZOOM Portfolio"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07169
      },
      "nvd": {
        "published": "2026-07-13T10:16:38.387",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57712",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WPZOOM Portfolio page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/wpzoom-portfolio/vulnerability/wordpress-wpzoom-portfolio-plugin-1-4-29-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:04.790Z",
      "date_published": "2026-07-13T08:41:24.693Z",
      "date_updated": "2026-07-13T14:38:45.658Z",
      "publisher": "Patchstack",
      "title": "WordPress Events Manager plugin <= 7.3.6 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "Marcus (aka @msykes)"
        ],
        "products": [
          {
            "vendor": "Marcus (aka @msykes)",
            "product": "Events Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00308,
        "percentile": 0.23153
      },
      "nvd": {
        "published": "2026-07-13T10:16:38.500",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57713",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Events Manager reconstructs attacker-controlled PHP objects without restricting their classes or side effects.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/events-manager/vulnerability/wordpress-events-manager-plugin-7-3-6-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57714",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:04.790Z",
      "date_published": "2026-07-13T08:41:24.759Z",
      "date_updated": "2026-07-13T13:30:52.769Z",
      "publisher": "Patchstack",
      "title": "WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "LatePoint"
        ],
        "products": [
          {
            "vendor": "LatePoint",
            "product": "LatePoint"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20533
      },
      "nvd": {
        "published": "2026-07-13T10:16:38.617",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57714",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In LatePoint, attacker-controlled values reach an SQL statement without the required escaping or parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/latepoint/vulnerability/wordpress-latepoint-plugin-5-6-3-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57715",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:04.790Z",
      "date_published": "2026-07-13T08:41:24.777Z",
      "date_updated": "2026-07-13T13:50:14.251Z",
      "publisher": "Patchstack",
      "title": "WordPress Fluent CRM plugin <= 3.1.7 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WPManageNinja"
        ],
        "products": [
          {
            "vendor": "WPManageNinja",
            "product": "Fluent CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07167
      },
      "nvd": {
        "published": "2026-07-13T10:16:38.737",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57715",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fluent CRM places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/fluent-crm/vulnerability/wordpress-fluent-crm-plugin-3-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57716",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:04.790Z",
      "date_published": "2026-07-23T11:18:08.617Z",
      "date_updated": "2026-07-23T14:23:10.923Z",
      "publisher": "Patchstack",
      "title": "WordPress Broadcast Live Video plugin <= 7.2.4 - Arbitrary File Deletion vulnerability",
      "affected": {
        "vendors": [
          "videowhisper"
        ],
        "products": [
          {
            "vendor": "videowhisper",
            "product": "Broadcast Live Video"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20063
      },
      "nvd": {
        "published": "2026-07-23T12:18:29.800",
        "lastModified": "2026-07-23T15:17:21.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57716",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Broadcast Live Video lets an unauthenticated caller select and delete a server file outside the intended object set.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/videowhisper-live-streaming-integration/vulnerability/wordpress-broadcast-live-video-plugin-7-2-4-arbitrary-file-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57717",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:13.263Z",
      "date_published": "2026-07-23T11:18:09.253Z",
      "date_updated": "2026-07-23T16:01:18.585Z",
      "publisher": "Patchstack",
      "title": "WordPress Knit Pay plugin <= 9.6.0.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "knitpay"
        ],
        "products": [
          {
            "vendor": "knitpay",
            "product": "Knit Pay"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15436
      },
      "nvd": {
        "published": "2026-07-23T12:18:29.927",
        "lastModified": "2026-07-23T16:17:27.813",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57717",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in Knit Pay, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/knit-pay/vulnerability/wordpress-knit-pay-plugin-9-6-0-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 70,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57718",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:13.263Z",
      "date_published": "2026-07-13T08:41:24.818Z",
      "date_updated": "2026-07-13T16:07:50.756Z",
      "publisher": "Patchstack",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.12 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Unlimited Elements"
        ],
        "products": [
          {
            "vendor": "Unlimited Elements",
            "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07195
      },
      "nvd": {
        "published": "2026-07-13T10:16:38.853",
        "lastModified": "2026-07-13T17:17:59.943",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57718",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unlimited Elements reflects attacker-controlled input into a page without sufficient HTML-context neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/unlimited-elements-for-elementor/vulnerability/wordpress-unlimited-elements-for-elementor-free-widgets-addons-templates-plugin-2-0-12-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 356,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57719",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:13.263Z",
      "date_published": "2026-07-13T08:41:24.849Z",
      "date_updated": "2026-07-13T16:07:50.613Z",
      "publisher": "Patchstack",
      "title": "WordPress Aimogen Pro plugin <= 2.8.3 - Arbitrary File Upload vulnerability",
      "affected": {
        "vendors": [
          "CodeRevolution"
        ],
        "products": [
          {
            "vendor": "CodeRevolution",
            "product": "Aimogen Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.274
      },
      "nvd": {
        "published": "2026-07-13T10:16:38.970",
        "lastModified": "2026-07-13T17:18:00.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57719",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Aimogen Pro accepts an attacker-supplied file type that can carry executable content into the upload store.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/aimogen-pro/vulnerability/wordpress-aimogen-pro-plugin-2-8-3-arbitrary-file-upload-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57720",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:13.263Z",
      "date_published": "2026-07-01T16:55:14.495Z",
      "date_updated": "2026-07-01T18:09:44.678Z",
      "publisher": "Patchstack",
      "title": "WordPress ThumbPress plugin <= 6.3.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Codexpert Inc"
        ],
        "products": [
          {
            "vendor": "Codexpert Inc",
            "product": "ThumbPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00203,
        "percentile": 0.10466
      },
      "nvd": {
        "published": "2026-07-01T17:16:37.630",
        "lastModified": "2026-07-01T19:16:56.230",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57720",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ThumbPress exposes an action outside the caller's configured access level, while the public record does not identify the endpoint or missing check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/image-sizes/vulnerability/wordpress-thumbpress-plugin-6-3-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57721",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:13.263Z",
      "date_published": "2026-07-01T16:56:43.766Z",
      "date_updated": "2026-07-01T18:04:55.782Z",
      "publisher": "Patchstack",
      "title": "WordPress ApplyOnline plugin <= 2.6.7.6 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "WP Reloaded"
        ],
        "products": [
          {
            "vendor": "WP Reloaded",
            "product": "ApplyOnline"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07586
      },
      "nvd": {
        "published": "2026-07-01T17:16:37.743",
        "lastModified": "2026-07-01T19:16:56.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57721",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/apply-online/vulnerability/wordpress-applyonline-plugin-2-6-7-6-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57722",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:13.263Z",
      "date_published": "2026-07-01T17:07:22.030Z",
      "date_updated": "2026-07-02T14:33:30.032Z",
      "publisher": "Patchstack",
      "title": "WordPress Enable Media Replace plugin <= 4.2.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "ShortPixel"
        ],
        "products": [
          {
            "vendor": "ShortPixel",
            "product": "Enable Media Replace"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04535
      },
      "nvd": {
        "published": "2026-07-01T18:16:35.240",
        "lastModified": "2026-07-02T15:17:10.340",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57722",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Stored XSS.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/enable-media-replace/vulnerability/wordpress-enable-media-replace-plugin-4-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:13.263Z",
      "date_published": "2026-07-01T17:08:43.612Z",
      "date_updated": "2026-07-01T17:57:59.550Z",
      "publisher": "Patchstack",
      "title": "WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Arbitrary File Deletion vulnerability",
      "affected": {
        "vendors": [
          "e4jvikwp"
        ],
        "products": [
          {
            "vendor": "e4jvikwp",
            "product": "VikBooking Hotel Booking Engine & PMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02499
      },
      "nvd": {
        "published": "2026-07-01T18:16:35.360",
        "lastModified": "2026-07-01T19:16:56.460",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57723",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The vulnerable deletion action accepts a forged cross-site request; the public record does not disclose the targeted path parameter or traversal check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/vikbooking/vulnerability/wordpress-vikbooking-hotel-booking-engine-pms-plugin-1-8-12-csrf-to-arbitrary-file-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57724",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:13.263Z",
      "date_published": "2026-07-13T08:41:24.871Z",
      "date_updated": "2026-07-13T13:38:35.873Z",
      "publisher": "Patchstack",
      "title": "WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "Themeum"
        ],
        "products": [
          {
            "vendor": "Themeum",
            "product": "Kirki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30252
      },
      "nvd": {
        "published": "2026-07-13T10:16:39.087",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57724",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application deserializes attacker-controlled object data without enforcing a safe type and behavior boundary.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/kirki/vulnerability/wordpress-kirki-plugin-6-0-12-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57725",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:13.263Z",
      "date_published": "2026-07-13T08:41:24.863Z",
      "date_updated": "2026-07-13T14:38:41.795Z",
      "publisher": "Patchstack",
      "title": "WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Themeum"
        ],
        "products": [
          {
            "vendor": "Themeum",
            "product": "Kirki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07195
      },
      "nvd": {
        "published": "2026-07-13T10:16:39.200",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57725",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/kirki/vulnerability/wordpress-kirki-plugin-6-0-11-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57726",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:13.263Z",
      "date_published": "2026-07-13T08:41:24.853Z",
      "date_updated": "2026-07-13T13:30:34.515Z",
      "publisher": "Patchstack",
      "title": "WordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Themeum"
        ],
        "products": [
          {
            "vendor": "Themeum",
            "product": "Kirki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20533
      },
      "nvd": {
        "published": "2026-07-13T10:16:39.317",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57726",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a Kirki database query without safe parameter binding, allowing query syntax injection.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/kirki/vulnerability/wordpress-kirki-plugin-6-0-12-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57727",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:20.944Z",
      "date_published": "2026-07-13T08:41:24.850Z",
      "date_updated": "2026-07-13T13:52:36.875Z",
      "publisher": "Patchstack",
      "title": "WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Themeum"
        ],
        "products": [
          {
            "vendor": "Themeum",
            "product": "Kirki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20912
      },
      "nvd": {
        "published": "2026-07-13T10:16:39.427",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57727",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Kirki exposes an action at an incorrect access-control level, but the protected object, action, and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/kirki/vulnerability/wordpress-kirki-plugin-6-0-13-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 184,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57728",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:20.944Z",
      "date_published": "2026-07-13T08:41:24.852Z",
      "date_updated": "2026-07-13T16:07:50.476Z",
      "publisher": "Patchstack",
      "title": "WordPress Flatsome theme <= 3.20.5 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "UX-themes"
        ],
        "products": [
          {
            "vendor": "UX-themes",
            "product": "Flatsome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07193
      },
      "nvd": {
        "published": "2026-07-13T10:16:39.540",
        "lastModified": "2026-07-13T17:18:01.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57728",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content is rendered without the browser-context separation required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/flatsome/vulnerability/wordpress-flatsome-theme-3-20-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:20.944Z",
      "date_published": "2026-07-13T08:41:24.881Z",
      "date_updated": "2026-07-13T16:07:50.341Z",
      "publisher": "Patchstack",
      "title": "WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "UX-themes"
        ],
        "products": [
          {
            "vendor": "UX-themes",
            "product": "Flatsome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20065
      },
      "nvd": {
        "published": "2026-07-13T10:16:39.657",
        "lastModified": "2026-07-13T17:18:01.917",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57729",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Flatsome exposes functionality without the required authorization, but the public record names no route, object, or failed ACL.",
        "basis": [
          "CNA record",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/flatsome/vulnerability/wordpress-flatsome-theme-3-20-5-broken-access-control-vulnerability-3?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:20.944Z",
      "date_published": "2026-07-02T11:15:47.270Z",
      "date_updated": "2026-07-02T12:41:30.001Z",
      "publisher": "Patchstack",
      "title": "WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "UX-themes"
        ],
        "products": [
          {
            "vendor": "UX-themes",
            "product": "Flatsome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12874
      },
      "nvd": {
        "published": "2026-07-02T12:17:40.050",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57730",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Flatsome permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/flatsome/vulnerability/wordpress-flatsome-theme-3-20-5-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 64,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:20.944Z",
      "date_published": "2026-07-02T11:15:48.309Z",
      "date_updated": "2026-07-02T13:41:12.831Z",
      "publisher": "Patchstack",
      "title": "WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "UX-themes"
        ],
        "products": [
          {
            "vendor": "UX-themes",
            "product": "Flatsome"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11259
      },
      "nvd": {
        "published": "2026-07-02T12:17:40.170",
        "lastModified": "2026-07-02T15:17:10.463",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57731",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Flatsome permits a contributor to invoke an action outside that role's intended scope, but the action and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/flatsome/vulnerability/wordpress-flatsome-theme-3-20-5-broken-access-control-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 65,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57732",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:20.944Z",
      "date_published": "2026-07-13T08:41:24.922Z",
      "date_updated": "2026-07-13T13:38:11.765Z",
      "publisher": "Patchstack",
      "title": "WordPress tagDiv Opt-In Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "tagDiv"
        ],
        "products": [
          {
            "vendor": "tagDiv",
            "product": "tagDiv Opt-In Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07162
      },
      "nvd": {
        "published": "2026-07-13T10:16:39.767",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57732",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In tagDiv Opt-In Builder, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/td-subscription/vulnerability/wordpress-tagdiv-opt-in-builder-plugin-1-7-4-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57733",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:20.944Z",
      "date_published": "2026-07-13T08:41:24.927Z",
      "date_updated": "2026-07-13T14:38:38.728Z",
      "publisher": "Patchstack",
      "title": "WordPress tagDiv Cloud Library plugin <= 3.9.4 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "tagDiv"
        ],
        "products": [
          {
            "vendor": "tagDiv",
            "product": "tagDiv Cloud Library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07761
      },
      "nvd": {
        "published": "2026-07-13T10:16:39.883",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57733",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/td-cloud-library/vulnerability/wordpress-tagdiv-cloud-library-plugin-3-9-4-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57734",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:20.944Z",
      "date_published": "2026-07-13T08:41:24.978Z",
      "date_updated": "2026-07-13T13:30:17.161Z",
      "publisher": "Patchstack",
      "title": "WordPress tagDiv Composer plugin <= 5.4.3 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "tagDiv"
        ],
        "products": [
          {
            "vendor": "tagDiv",
            "product": "tagDiv Composer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07163
      },
      "nvd": {
        "published": "2026-07-13T10:16:39.997",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57734",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "tagDiv Composer reflects attacker-controlled request content into browser-interpreted output without sufficient contextual neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/td-composer/vulnerability/wordpress-tagdiv-composer-plugin-5-4-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57735",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:20.945Z",
      "date_published": "2026-07-23T11:18:09.887Z",
      "date_updated": "2026-07-23T14:53:20.105Z",
      "publisher": "Patchstack",
      "title": "WordPress Breakdance plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Soflyy"
        ],
        "products": [
          {
            "vendor": "Soflyy",
            "product": "Breakdance"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07163
      },
      "nvd": {
        "published": "2026-07-23T12:18:30.043",
        "lastModified": "2026-07-23T16:17:27.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57735",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Breakdance rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/breakdance/vulnerability/wordpress-breakdance-plugin-2-7-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57736",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:20.945Z",
      "date_published": "2026-07-01T17:40:57.023Z",
      "date_updated": "2026-07-01T17:59:06.101Z",
      "publisher": "Patchstack",
      "title": "WordPress HubSpot plugin <= 11.3.51 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "HubSpot"
        ],
        "products": [
          {
            "vendor": "HubSpot",
            "product": "HubSpot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07216
      },
      "nvd": {
        "published": "2026-07-01T18:16:35.490",
        "lastModified": "2026-07-01T19:16:56.573",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57736",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Protected information is returned or left accessible to an observer outside its intended audience.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/leadin/vulnerability/wordpress-hubspot-plugin-11-3-51-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:29.578Z",
      "date_published": "2026-07-01T17:42:27.536Z",
      "date_updated": "2026-07-02T12:51:05.073Z",
      "publisher": "Patchstack",
      "title": "WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.16 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Averta LTD"
        ],
        "products": [
          {
            "vendor": "Averta LTD",
            "product": "Shortcodes and extra features for Phlox theme"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03363
      },
      "nvd": {
        "published": "2026-07-01T18:16:35.613",
        "lastModified": "2026-07-02T13:16:59.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57737",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Shortcodes and extra features for Phlox theme rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/auxin-elements/vulnerability/wordpress-shortcodes-and-extra-features-for-phlox-theme-plugin-2-17-16-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:29.578Z",
      "date_published": "2026-07-13T08:41:24.999Z",
      "date_updated": "2026-07-13T13:53:01.682Z",
      "publisher": "Patchstack",
      "title": "WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "axiomthemes"
        ],
        "products": [
          {
            "vendor": "axiomthemes",
            "product": "777"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30251
      },
      "nvd": {
        "published": "2026-07-13T10:16:40.110",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57738",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The 777 theme deserializes attacker-controlled PHP objects without restricting instantiated classes or gadget behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/triple-seven/vulnerability/wordpress-777-theme-1-13-0-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 155,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57739",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:29.578Z",
      "date_published": "2026-07-13T08:41:24.999Z",
      "date_updated": "2026-07-13T14:23:53.401Z",
      "publisher": "Patchstack",
      "title": "WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "AcyMailing Newsletter Team"
        ],
        "products": [
          {
            "vendor": "AcyMailing Newsletter Team",
            "product": "AcyMailing SMTP Newsletter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20538
      },
      "nvd": {
        "published": "2026-07-13T10:16:40.223",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57739",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "AcyMailing accepts unauthenticated input that becomes a blind SQL query, while Patchstack does not publish the parameter, query construction, or database sink.",
        "basis": [
          "CNA",
          "CWE-89",
          "Patchstack PSID 6350ed9913d3"
        ],
        "deepDive": true,
        "notes": "Inspected https://patchstack.com/database/Wordpress/Plugin/acymailing/vulnerability/wordpress-acymailing-smtp-newsletter-plugin-10-10-2-sql-injection-vulnerability. Patchstack confirms unauthenticated SQL injection, affected versions through 10.11.0, fixed version 10.11.1, and CVSS 9.3, but publishes no parameter, query, or sink. The stale 10.10.2 text in the URL slug conflicts with the page body and CVE record; use the page body version boundary and preserve the discrepancy in editorial notes."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/acymailing/vulnerability/wordpress-acymailing-smtp-newsletter-plugin-10-10-2-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 269,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57740",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:29.578Z",
      "date_published": "2026-07-13T08:41:24.997Z",
      "date_updated": "2026-07-13T16:07:50.199Z",
      "publisher": "Patchstack",
      "title": "WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "AcyMailing Newsletter Team"
        ],
        "products": [
          {
            "vendor": "AcyMailing Newsletter Team",
            "product": "AcyMailing SMTP Newsletter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13372
      },
      "nvd": {
        "published": "2026-07-13T10:16:40.340",
        "lastModified": "2026-07-13T17:18:02.577",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57740",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The AcyMailing record reports a missing authorization check but does not name the action, object, or required role.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/acymailing/vulnerability/wordpress-acymailing-smtp-newsletter-plugin-10-10-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57741",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:29.578Z",
      "date_published": "2026-07-13T08:41:25.005Z",
      "date_updated": "2026-07-13T13:37:41.971Z",
      "publisher": "Patchstack",
      "title": "WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "AcyMailing Newsletter Team"
        ],
        "products": [
          {
            "vendor": "AcyMailing Newsletter Team",
            "product": "AcyMailing SMTP Newsletter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07163
      },
      "nvd": {
        "published": "2026-07-13T10:16:40.457",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57741",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/acymailing/vulnerability/wordpress-acymailing-smtp-newsletter-plugin-10-10-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 260,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57743",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:29.578Z",
      "date_published": "2026-07-13T08:41:25.010Z",
      "date_updated": "2026-07-13T14:38:35.637Z",
      "publisher": "Patchstack",
      "title": "WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "stmcan"
        ],
        "products": [
          {
            "vendor": "stmcan",
            "product": "RT-Theme 18 | Extensions"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33125
      },
      "nvd": {
        "published": "2026-07-13T10:16:40.570",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57743",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-influenced filename reaches a PHP include or require operation without restricting the selected file to an approved namespace.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/rt18-extensions/vulnerability/wordpress-rt-theme-18-extensions-plugin-2-5-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 270,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57744",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:29.579Z",
      "date_published": "2026-07-13T08:41:25.019Z",
      "date_updated": "2026-07-13T13:27:11.053Z",
      "publisher": "Patchstack",
      "title": "WordPress RT-Theme 18 | Extensions plugin <= 2.5 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "stmcan"
        ],
        "products": [
          {
            "vendor": "stmcan",
            "product": "RT-Theme 18 | Extensions"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22761
      },
      "nvd": {
        "published": "2026-07-13T10:16:40.690",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57744",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application deserializes attacker-controlled bytes with object semantics that can invoke executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/rt18-extensions/vulnerability/wordpress-rt-theme-18-extensions-plugin-2-5-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57745",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:29.579Z",
      "date_published": "2026-07-13T08:41:25.029Z",
      "date_updated": "2026-07-13T13:53:26.976Z",
      "publisher": "Patchstack",
      "title": "WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "stmcan"
        ],
        "products": [
          {
            "vendor": "stmcan",
            "product": "RT-Theme 18 | Extensions"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07168
      },
      "nvd": {
        "published": "2026-07-13T10:16:40.807",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57745",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches RT-Theme 18 | Extensions page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/rt18-extensions/vulnerability/wordpress-rt-theme-18-extensions-plugin-2-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57746",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:29.579Z",
      "date_published": "2026-07-02T11:15:49.159Z",
      "date_updated": "2026-07-02T19:40:12.149Z",
      "publisher": "Patchstack",
      "title": "WordPress Booked plugin <= 3.0.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "ThemeREX"
        ],
        "products": [
          {
            "vendor": "ThemeREX",
            "product": "Booked"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14481
      },
      "nvd": {
        "published": "2026-07-02T12:17:40.290",
        "lastModified": "2026-07-02T20:17:05.370",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57746",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A subscriber can perform a Booked operation outside the intended role, but the affected object and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/booked/vulnerability/wordpress-booked-plugin-3-0-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 61,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:34.979Z",
      "date_published": "2026-07-02T11:15:49.986Z",
      "date_updated": "2026-07-02T19:45:54.787Z",
      "publisher": "Patchstack",
      "title": "WordPress Booked plugin <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "ThemeREX"
        ],
        "products": [
          {
            "vendor": "ThemeREX",
            "product": "Booked"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.025
      },
      "nvd": {
        "published": "2026-07-02T12:17:40.410",
        "lastModified": "2026-07-02T20:17:05.467",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57747",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Booked accepts a state-changing browser request from an untrusted origin without an effective anti-CSRF condition, but the action is not public.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/booked/vulnerability/wordpress-booked-plugin-3-0-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 78,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57748",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:34.979Z",
      "date_published": "2026-07-02T11:15:51.064Z",
      "date_updated": "2026-07-02T15:52:46.775Z",
      "publisher": "Patchstack",
      "title": "WordPress Shopify plugin <= 1.0.0 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "Shopify Help Center"
        ],
        "products": [
          {
            "vendor": "Shopify Help Center",
            "product": "Shopify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19745
      },
      "nvd": {
        "published": "2026-07-02T12:17:40.560",
        "lastModified": "2026-07-02T16:16:35.003",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57748",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A contributor can control the PHP file selected by an include or require operation beyond the plugin's intended file set.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/shopify-plugin/vulnerability/wordpress-shopify-plugin-1-0-0-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 62,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57749",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:34.979Z",
      "date_published": "2026-07-02T11:15:51.971Z",
      "date_updated": "2026-07-02T12:08:23.080Z",
      "publisher": "Patchstack",
      "title": "WordPress SportsPress Pro plugin <= 2.7.29 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "ThemeBoy"
        ],
        "products": [
          {
            "vendor": "ThemeBoy",
            "product": "SportsPress Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.19006
      },
      "nvd": {
        "published": "2026-07-02T12:17:40.687",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57749",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SportsPress Pro include path lets an attacker select a local file outside the intended include namespace.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/sportspress-pro/vulnerability/wordpress-sportspress-pro-plugin-2-7-29-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 71,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57750",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:34.979Z",
      "date_published": "2026-07-02T11:15:53.121Z",
      "date_updated": "2026-07-02T12:41:08.990Z",
      "publisher": "Patchstack",
      "title": "WordPress ez Form Calculator Premium plugin <= 2.14.1.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Keksdieb"
        ],
        "products": [
          {
            "vendor": "Keksdieb",
            "product": "ez Form Calculator Premium"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07586
      },
      "nvd": {
        "published": "2026-07-02T12:17:40.823",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57750",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ez Form Calculator Premium exposes an unauthenticated operation, but the public record does not identify the protected object or missing check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ez-form-calculator-premium/vulnerability/wordpress-ez-form-calculator-premium-plugin-2-14-1-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 89,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57751",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:34.979Z",
      "date_published": "2026-07-02T11:15:54.093Z",
      "date_updated": "2026-07-02T13:48:48.500Z",
      "publisher": "Patchstack",
      "title": "WordPress Heateor Social Login plugin <= 1.1.39 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "Heateor Support"
        ],
        "products": [
          {
            "vendor": "Heateor Support",
            "product": "Heateor Social Login"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03753
      },
      "nvd": {
        "published": "2026-07-02T12:17:40.947",
        "lastModified": "2026-07-02T15:17:10.573",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57751",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The state-changing action accepts a cross-site request without a session-bound anti-CSRF token or equivalent origin validation.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/heateor-social-login/vulnerability/wordpress-heateor-social-login-plugin-1-1-39-cross-site-request-forgery-csrf-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57752",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:34.979Z",
      "date_published": "2026-07-02T11:15:55.041Z",
      "date_updated": "2026-07-02T19:40:26.895Z",
      "publisher": "Patchstack",
      "title": "WordPress iNET Webkit plugin 1.2.4 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "iNET"
        ],
        "products": [
          {
            "vendor": "iNET",
            "product": "iNET Webkit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20392
      },
      "nvd": {
        "published": "2026-07-02T12:17:41.073",
        "lastModified": "2026-07-02T20:17:05.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57752",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "iNET Webkit incorporates attacker-controlled values or identifiers into a SQL statement without preserving the boundary between query syntax and data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/inet-webkit/vulnerability/wordpress-inet-webkit-plugin-1-2-4-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 56,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57753",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:34.979Z",
      "date_published": "2026-07-02T11:15:56.022Z",
      "date_updated": "2026-07-02T19:46:08.227Z",
      "publisher": "Patchstack",
      "title": "WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.1.5 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Nathanbarry"
        ],
        "products": [
          {
            "vendor": "Nathanbarry",
            "product": "Kit (formerly ConvertKit) for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.10082
      },
      "nvd": {
        "published": "2026-07-02T12:17:41.197",
        "lastModified": "2026-07-02T20:17:05.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57753",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Kit integration returns sensitive data to an unauthenticated caller through a publicly reachable output path.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/convertkit-for-woocommerce/vulnerability/wordpress-kit-formerly-convertkit-for-woocommerce-plugin-2-1-5-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:34.980Z",
      "date_published": "2026-07-02T11:15:57.039Z",
      "date_updated": "2026-07-02T15:52:41.535Z",
      "publisher": "Patchstack",
      "title": "WordPress Livemesh Addons for WPBakery Page Builder plugin <= 3.9.4 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Livemesh"
        ],
        "products": [
          {
            "vendor": "Livemesh",
            "product": "Livemesh Addons for WPBakery Page Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03353
      },
      "nvd": {
        "published": "2026-07-02T12:17:41.320",
        "lastModified": "2026-07-02T16:16:35.097",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57754",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Livemesh Addons for WPBakery Page Builder renders attacker-controlled content without the required HTML sanitization or output escaping, allowing cross-site scripting.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/addons-for-visual-composer/vulnerability/wordpress-livemesh-addons-for-wpbakery-page-builder-plugin-3-9-4-cross-site-scripting-xss-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:34.980Z",
      "date_published": "2026-07-02T11:15:57.949Z",
      "date_updated": "2026-07-02T12:01:36.871Z",
      "publisher": "Patchstack",
      "title": "WordPress Mosaic Gallery &#8211; Advanced Gallery plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Misbah WP"
        ],
        "products": [
          {
            "vendor": "Misbah WP",
            "product": "Mosaic Gallery &#8211; Advanced Gallery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03353
      },
      "nvd": {
        "published": "2026-07-02T12:17:41.437",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57755",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mosaic Gallery stores contributor-controlled content and renders it without sufficient HTML-context neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mosaic-gallery-advanced-gallery/vulnerability/wordpress-mosaic-gallery-8211-advanced-gallery-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:34.980Z",
      "date_published": "2026-07-02T11:15:58.829Z",
      "date_updated": "2026-07-02T12:40:12.344Z",
      "publisher": "Patchstack",
      "title": "WordPress nicen-localize-image plugin <= 1.4.9 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "友人a丶"
        ],
        "products": [
          {
            "vendor": "友人a丶",
            "product": "nicen-localize-image"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11862
      },
      "nvd": {
        "published": "2026-07-02T12:17:41.563",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57756",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "nicen-localize-image allows a contributor-controlled value to alter the structure of an SQL query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/nicen-localize-image/vulnerability/wordpress-nicen-localize-image-plugin-1-4-9-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 68,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57757",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:41.579Z",
      "date_published": "2026-07-02T11:15:59.819Z",
      "date_updated": "2026-07-02T13:54:01.273Z",
      "publisher": "Patchstack",
      "title": "WordPress pCloud WP Backup plugin <= 2.0.2 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "ploudapp"
        ],
        "products": [
          {
            "vendor": "ploudapp",
            "product": "pCloud WP Backup"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01845
      },
      "nvd": {
        "published": "2026-07-02T12:17:41.687",
        "lastModified": "2026-07-02T15:17:10.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57757",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "pCloud WP Backup accepts a cross-site request, but the record does not identify the state-changing action or missing request-verification check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/pcloud-wp-backup/vulnerability/wordpress-pcloud-wp-backup-plugin-2-0-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 88,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57758",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:41.580Z",
      "date_published": "2026-07-02T11:16:00.814Z",
      "date_updated": "2026-07-02T19:40:41.935Z",
      "publisher": "Patchstack",
      "title": "WordPress Permalink Manager for WooCommerce plugin <= 1.0.8.2 - CSRF to Stored XSS vulnerability",
      "affected": {
        "vendors": [
          "BeRocket"
        ],
        "products": [
          {
            "vendor": "BeRocket",
            "product": "Permalink Manager for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00094,
        "percentile": 0.00737
      },
      "nvd": {
        "published": "2026-07-02T12:17:41.810",
        "lastModified": "2026-07-02T20:17:05.760",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57758",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/permalink-manager-for-woocommerce/vulnerability/wordpress-permalink-manager-for-woocommerce-plugin-1-0-8-2-csrf-to-stored-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57759",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:41.580Z",
      "date_published": "2026-07-02T11:16:02.057Z",
      "date_updated": "2026-07-02T19:46:27.354Z",
      "publisher": "Patchstack",
      "title": "WordPress ProfileGrid  plugin <= 5.9.9.7 - CSRF to Account Takeover vulnerability",
      "affected": {
        "vendors": [
          "Metagauss"
        ],
        "products": [
          {
            "vendor": "Metagauss",
            "product": "ProfileGrid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04006
      },
      "nvd": {
        "published": "2026-07-02T12:17:41.930",
        "lastModified": "2026-07-02T20:17:05.853",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57759",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/profilegrid-user-profiles-groups-and-communities/vulnerability/wordpress-profilegrid-plugin-5-9-9-7-csrf-to-account-takeover-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 86,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:41.580Z",
      "date_published": "2026-07-02T11:33:08.861Z",
      "date_updated": "2026-07-02T12:40:30.782Z",
      "publisher": "Patchstack",
      "title": "WordPress Sendcloud Shipping plugin <= 1.0.29 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Sendcloud"
        ],
        "products": [
          {
            "vendor": "Sendcloud",
            "product": "Sendcloud Shipping"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07586
      },
      "nvd": {
        "published": "2026-07-02T12:17:42.050",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57760",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/sendcloud-connected-shipping/vulnerability/wordpress-sendcloud-shipping-plugin-1-0-28-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:41.580Z",
      "date_published": "2026-07-02T11:16:02.973Z",
      "date_updated": "2026-07-02T15:52:36.393Z",
      "publisher": "Patchstack",
      "title": "WordPress SEOWP theme <= 3.12.2 - CSRF to Stored XSS vulnerability",
      "affected": {
        "vendors": [
          "BlueAstralThemes"
        ],
        "products": [
          {
            "vendor": "BlueAstralThemes",
            "product": "SEOWP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00094,
        "percentile": 0.00737
      },
      "nvd": {
        "published": "2026-07-02T12:17:42.170",
        "lastModified": "2026-07-02T16:16:35.190",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57761",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Patchstack identifies a cross-site request forgery in SEOWP, but does not publish the state-changing action or missing request check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/seowp/vulnerability/wordpress-seowp-theme-3-12-2-csrf-to-stored-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 78,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57762",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:41.580Z",
      "date_published": "2026-07-02T11:16:04.073Z",
      "date_updated": "2026-07-02T11:58:18.447Z",
      "publisher": "Patchstack",
      "title": "WordPress Simple URLs plugin <= 151 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Andrew Fiebert"
        ],
        "products": [
          {
            "vendor": "Andrew Fiebert",
            "product": "Simple URLs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04164
      },
      "nvd": {
        "published": "2026-07-02T12:17:42.293",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57762",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/simple-urls/vulnerability/wordpress-simple-urls-plugin-151-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 65,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:41.580Z",
      "date_published": "2026-07-02T11:16:05.094Z",
      "date_updated": "2026-07-02T12:40:47.096Z",
      "publisher": "Patchstack",
      "title": "WordPress Structured Content plugin <= 1.7.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Gordon Böhme"
        ],
        "products": [
          {
            "vendor": "Gordon Böhme",
            "product": "Structured Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03353
      },
      "nvd": {
        "published": "2026-07-02T12:17:42.420",
        "lastModified": "2026-07-02T13:58:23.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57763",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Structured Content page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/structured-content/vulnerability/wordpress-structured-content-plugin-1-7-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 79,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:41.580Z",
      "date_published": "2026-07-02T11:16:05.895Z",
      "date_updated": "2026-07-02T13:58:17.905Z",
      "publisher": "Patchstack",
      "title": "WordPress Surbma | Yoast SEO Breadcrumb Shortcode plugin <= 1.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Surbma"
        ],
        "products": [
          {
            "vendor": "Surbma",
            "product": "Surbma | Yoast SEO Breadcrumb Shortcode"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03353
      },
      "nvd": {
        "published": "2026-07-02T12:17:42.540",
        "lastModified": "2026-07-02T15:17:10.773",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57764",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Contributor-controlled breadcrumb data is rendered without the required browser-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/surbma-yoast-breadcrumb-shortcode/vulnerability/wordpress-surbma-yoast-seo-breadcrumb-shortcode-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:41.580Z",
      "date_published": "2026-07-02T11:16:06.637Z",
      "date_updated": "2026-07-02T19:41:12.121Z",
      "publisher": "Patchstack",
      "title": "WordPress WP EasyCart plugin <= 5.9.0 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Levelfourdevelopment"
        ],
        "products": [
          {
            "vendor": "Levelfourdevelopment",
            "product": "WP EasyCart"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11862
      },
      "nvd": {
        "published": "2026-07-02T12:17:42.660",
        "lastModified": "2026-07-02T20:17:05.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57765",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-easycart/vulnerability/wordpress-wp-easycart-plugin-5-9-0-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 59,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57766",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:41.580Z",
      "date_published": "2026-07-02T11:16:07.503Z",
      "date_updated": "2026-07-02T19:46:43.276Z",
      "publisher": "Patchstack",
      "title": "WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.6 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "XplodedThemes"
        ],
        "products": [
          {
            "vendor": "XplodedThemes",
            "product": "WPIDE – File Manager & Code Editor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04006
      },
      "nvd": {
        "published": "2026-07-02T12:17:42.780",
        "lastModified": "2026-07-02T20:17:06.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57766",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WPIDE accepts a cross-site request, but the public record does not identify the state-changing operation or missing request-origin control.",
        "basis": [
          "CNA record",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wpide/vulnerability/wordpress-wpide-file-manager-code-editor-plugin-3-5-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:47.959Z",
      "date_published": "2026-07-23T11:18:10.525Z",
      "date_updated": "2026-07-23T13:32:56.022Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Google Maps Pro plugin <= 10.1.02 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "CodeCabin.io"
        ],
        "products": [
          {
            "vendor": "CodeCabin.io",
            "product": "WP Google Maps Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07165
      },
      "nvd": {
        "published": "2026-07-23T12:18:30.167",
        "lastModified": "2026-07-23T14:17:26.277",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57767",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WP Google Maps Pro renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-google-maps-pro/vulnerability/wordpress-wp-google-maps-pro-plugin-10-1-02-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 85,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:47.959Z",
      "date_published": "2026-07-13T08:41:25.067Z",
      "date_updated": "2026-07-13T14:07:21.069Z",
      "publisher": "Patchstack",
      "title": "WordPress Houzez Login Register plugin <= 3.3.3 - Privilege Escalation vulnerability",
      "affected": {
        "vendors": [
          "favethemes"
        ],
        "products": [
          {
            "vendor": "favethemes",
            "product": "Houzez Login Register"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12734
      },
      "nvd": {
        "published": "2026-07-13T10:16:40.923",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57768",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The registration component assigns a privilege level above the registrant's intended role, but the exact assignment branch is not public.",
        "basis": [
          "CNA",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/houzez-login-register/vulnerability/wordpress-houzez-login-register-plugin-3-3-3-privilege-escalation-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:47.959Z",
      "date_published": "2026-07-23T11:18:11.165Z",
      "date_updated": "2026-07-23T13:51:37.275Z",
      "publisher": "Patchstack",
      "title": "WordPress Grand Photography theme <= 5.7.8 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "ThemeGoods"
        ],
        "products": [
          {
            "vendor": "ThemeGoods",
            "product": "Grand Photography"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07762
      },
      "nvd": {
        "published": "2026-07-23T12:18:30.283",
        "lastModified": "2026-07-23T14:17:26.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57769",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Grand Photography, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/grandphotography/vulnerability/wordpress-grand-photography-theme-5-7-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:47.959Z",
      "date_published": "2026-07-13T08:41:25.073Z",
      "date_updated": "2026-07-13T16:07:50.018Z",
      "publisher": "Patchstack",
      "title": "WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "ThemeGoods"
        ],
        "products": [
          {
            "vendor": "ThemeGoods",
            "product": "Grand Photography"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22762
      },
      "nvd": {
        "published": "2026-07-13T10:16:41.040",
        "lastModified": "2026-07-13T17:18:03.320",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57770",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled serialized data is passed to a native object deserializer that can instantiate executable object graphs.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/grandphotography/vulnerability/wordpress-grand-photography-theme-5-7-8-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:47.959Z",
      "date_published": "2026-07-13T08:41:25.125Z",
      "date_updated": "2026-07-13T13:34:08.233Z",
      "publisher": "Patchstack",
      "title": "WordPress GD Rating System plugin <= 3.7 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Milan Petrovic"
        ],
        "products": [
          {
            "vendor": "Milan Petrovic",
            "product": "GD Rating System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16731
      },
      "nvd": {
        "published": "2026-07-13T10:16:41.157",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57771",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GD Rating System incorporates attacker-controlled input into an SQL statement without preserving the SQL data boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/gd-rating-system/vulnerability/wordpress-gd-rating-system-plugin-3-7-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57772",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:47.959Z",
      "date_published": "2026-07-13T08:41:25.144Z",
      "date_updated": "2026-07-13T14:38:31.763Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Inventory Manager plugin <= 2.4.0 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "WP Inventory"
        ],
        "products": [
          {
            "vendor": "WP Inventory",
            "product": "WP Inventory Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16732
      },
      "nvd": {
        "published": "2026-07-13T10:16:41.277",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57772",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WP Inventory Manager data path incorporates attacker-controlled text into a database query without parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/wp-inventory-manager/vulnerability/wordpress-wp-inventory-manager-plugin-2-4-0-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57773",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:47.959Z",
      "date_published": "2026-07-13T08:41:25.149Z",
      "date_updated": "2026-07-13T13:23:28.120Z",
      "publisher": "Patchstack",
      "title": "WordPress Advanced Shipment Tracking for WooCommerce plugin <= 4.0 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Zorem"
        ],
        "products": [
          {
            "vendor": "Zorem",
            "product": "Advanced Shipment Tracking for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00271,
        "percentile": 0.19087
      },
      "nvd": {
        "published": "2026-07-13T10:16:41.393",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57773",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted input is interpreted as syntax because the implementation fails to separate it from executable grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/woo-advanced-shipment-tracking/vulnerability/wordpress-advanced-shipment-tracking-for-woocommerce-plugin-4-0-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 296,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57774",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:47.959Z",
      "date_published": "2026-07-13T08:41:25.150Z",
      "date_updated": "2026-07-13T13:53:45.683Z",
      "publisher": "Patchstack",
      "title": "WordPress VW Food Corner theme <= 1.1.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "vowelweb"
        ],
        "products": [
          {
            "vendor": "vowelweb",
            "product": "VW Food Corner"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.2156
      },
      "nvd": {
        "published": "2026-07-13T10:16:41.523",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57774",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The VW Food Corner operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/vw-food-corner/vulnerability/wordpress-vw-food-corner-theme-1-1-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57776",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:47.960Z",
      "date_published": "2026-07-13T08:41:25.154Z",
      "date_updated": "2026-07-13T14:27:26.750Z",
      "publisher": "Patchstack",
      "title": "WordPress VW Wedding theme <= 1.3.7 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "vowelweb"
        ],
        "products": [
          {
            "vendor": "vowelweb",
            "product": "VW Wedding"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.2156
      },
      "nvd": {
        "published": "2026-07-13T10:16:41.680",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57776",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component omits an authorization decision, but the protected action, object, and caller binding are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/vw-wedding/vulnerability/wordpress-vw-wedding-theme-1-3-7-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57778",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:53.458Z",
      "date_published": "2026-07-13T08:41:25.158Z",
      "date_updated": "2026-07-13T16:07:49.879Z",
      "publisher": "Patchstack",
      "title": "WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "wpdevart"
        ],
        "products": [
          {
            "vendor": "wpdevart",
            "product": "Booking calendar, Appointment Booking System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11043
      },
      "nvd": {
        "published": "2026-07-13T10:16:41.810",
        "lastModified": "2026-07-13T17:18:03.987",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57778",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Booking calendar, Appointment Booking System permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/booking-calendar/vulnerability/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-36-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57779",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:53.458Z",
      "date_published": "2026-07-13T08:41:25.168Z",
      "date_updated": "2026-07-13T13:32:54.093Z",
      "publisher": "Patchstack",
      "title": "WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "themebeez"
        ],
        "products": [
          {
            "vendor": "themebeez",
            "product": "Fascinate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11044
      },
      "nvd": {
        "published": "2026-07-13T10:16:41.930",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57779",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Fascinate record reports a missing authorization check but does not name the action, object, or required role.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/fascinate/vulnerability/wordpress-fascinate-theme-1-1-5-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57780",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:53.458Z",
      "date_published": "2026-07-13T08:41:25.176Z",
      "date_updated": "2026-07-13T14:38:28.696Z",
      "publisher": "Patchstack",
      "title": "WordPress Envision Page Builder plugin <= 0.22 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Plugin Envision"
        ],
        "products": [
          {
            "vendor": "Plugin Envision",
            "product": "Envision Page Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05266
      },
      "nvd": {
        "published": "2026-07-13T10:16:42.050",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57780",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/envision-page-builder/vulnerability/wordpress-envision-page-builder-plugin-0-22-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57781",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:53.458Z",
      "date_published": "2026-07-13T08:41:25.215Z",
      "date_updated": "2026-07-13T13:23:09.459Z",
      "publisher": "Patchstack",
      "title": "WordPress MeetingHub plugin <= 1.25.10 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Sovlix"
        ],
        "products": [
          {
            "vendor": "Sovlix",
            "product": "MeetingHub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11043
      },
      "nvd": {
        "published": "2026-07-13T10:16:42.170",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57781",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/meetinghub/vulnerability/wordpress-meetinghub-plugin-1-25-10-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57782",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:53.458Z",
      "date_published": "2026-07-13T08:41:25.219Z",
      "date_updated": "2026-07-13T13:52:10.603Z",
      "publisher": "Patchstack",
      "title": "WordPress Universal Clocks plugin <= 1.2.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "PressTigers"
        ],
        "products": [
          {
            "vendor": "PressTigers",
            "product": "Universal Clocks"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11041
      },
      "nvd": {
        "published": "2026-07-13T10:16:42.290",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57782",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/universal-clocks/vulnerability/wordpress-universal-clocks-plugin-1-2-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57783",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:53.458Z",
      "date_published": "2026-07-13T08:41:25.276Z",
      "date_updated": "2026-07-13T14:55:25.034Z",
      "publisher": "Patchstack",
      "title": "WordPress Speaker plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "merkulove"
        ],
        "products": [
          {
            "vendor": "merkulove",
            "product": "Speaker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05265
      },
      "nvd": {
        "published": "2026-07-13T10:16:42.410",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57783",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Speaker page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/speaker/vulnerability/wordpress-speaker-plugin-4-1-13-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57784",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:53.458Z",
      "date_published": "2026-07-23T11:18:11.801Z",
      "date_updated": "2026-07-23T15:11:48.466Z",
      "publisher": "Patchstack",
      "title": "WordPress  Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "Ninja Forms"
        ],
        "products": [
          {
            "vendor": "Ninja Forms",
            "product": "Ninja Forms File Uploads Extension"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03057
      },
      "nvd": {
        "published": "2026-07-23T12:18:30.407",
        "lastModified": "2026-07-23T16:17:28.043",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57784",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A file-upload administration action can be triggered from another site without a reliable request-origin token.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ninja-forms-uploads/vulnerability/wordpress-ninja-forms-file-uploads-extension-plugin-3-3-26-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57785",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:53.458Z",
      "date_published": "2026-07-23T11:18:12.442Z",
      "date_updated": "2026-07-23T14:23:47.952Z",
      "publisher": "Patchstack",
      "title": "WordPress ApusListing theme <= 1.2.63 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "ApusTheme"
        ],
        "products": [
          {
            "vendor": "ApusTheme",
            "product": "ApusListing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04007
      },
      "nvd": {
        "published": "2026-07-23T12:18:30.540",
        "lastModified": "2026-07-23T15:17:21.920",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57785",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ApusListing accepts a state-changing browser request from an untrusted origin and reaches an authentication action, but the request and check are not public.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/apuslisting/vulnerability/wordpress-apuslisting-theme-1-2-46-cross-site-request-forgery-csrf-to-broken-authentication-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 84,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57786",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:04:53.459Z",
      "date_published": "2026-07-13T08:41:25.295Z",
      "date_updated": "2026-07-13T16:07:49.745Z",
      "publisher": "Patchstack",
      "title": "WordPress WorkScout-Core plugin <= 1.7.08 - Cross Site Request Forgery (CSRF) to Broken Authentication vulnerability",
      "affected": {
        "vendors": [
          "purethemes"
        ],
        "products": [
          {
            "vendor": "purethemes",
            "product": "WorkScout-Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06042
      },
      "nvd": {
        "published": "2026-07-13T10:16:42.527",
        "lastModified": "2026-07-13T17:18:04.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57786",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WorkScout-Core exposes an authentication-bypass path through a cross-site request, but the public record does not identify the state-changing operation or request validation failure.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/workscout-core/vulnerability/wordpress-workscout-core-plugin-1-7-08-cross-site-request-forgery-csrf-to-broken-authentication-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57787",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:02.626Z",
      "date_published": "2026-07-13T08:41:25.295Z",
      "date_updated": "2026-07-13T13:31:32.655Z",
      "publisher": "Patchstack",
      "title": "WordPress CWS SVGicons plugin <= 1.5.5 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "CreativeWS"
        ],
        "products": [
          {
            "vendor": "CreativeWS",
            "product": "CWS SVGicons"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16732
      },
      "nvd": {
        "published": "2026-07-13T10:16:42.657",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57787",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CWS SVGicons query path incorporates attacker-controlled input into SQL without parameter separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/cws-svgicons/vulnerability/wordpress-cws-svgicons-plugin-1-5-5-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57788",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:02.627Z",
      "date_published": "2026-07-13T08:41:25.301Z",
      "date_updated": "2026-07-13T14:38:24.370Z",
      "publisher": "Patchstack",
      "title": "WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "Edge-Themes"
        ],
        "products": [
          {
            "vendor": "Edge-Themes",
            "product": "Aalto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29743
      },
      "nvd": {
        "published": "2026-07-13T10:16:42.777",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57788",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Aalto lets an attacker-controlled include filename select a PHP file outside the intended include set.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/aalto/vulnerability/wordpress-aalto-theme-1-8-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57789",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:02.627Z",
      "date_published": "2026-07-13T08:41:25.306Z",
      "date_updated": "2026-07-13T13:19:25.793Z",
      "publisher": "Patchstack",
      "title": "WordPress Aqua theme <= 5.1.2 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "jwsthemes"
        ],
        "products": [
          {
            "vendor": "jwsthemes",
            "product": "Aqua"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29741
      },
      "nvd": {
        "published": "2026-07-13T10:16:42.903",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57789",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The include operation in Aqua accepts an attacker-controlled filename without confining it to the intended template directory.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/aqua/vulnerability/wordpress-aqua-theme-5-1-2-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 224,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57790",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:02.627Z",
      "date_published": "2026-07-13T08:41:25.305Z",
      "date_updated": "2026-07-13T13:54:12.104Z",
      "publisher": "Patchstack",
      "title": "WordPress Billey theme <= 2.1.8 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "ThemeMove"
        ],
        "products": [
          {
            "vendor": "ThemeMove",
            "product": "Billey"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.2974
      },
      "nvd": {
        "published": "2026-07-13T10:16:43.030",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57790",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Billey allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/billey/vulnerability/wordpress-billey-theme-2-1-8-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57791",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:02.627Z",
      "date_published": "2026-07-13T08:41:25.316Z",
      "date_updated": "2026-07-13T14:56:36.466Z",
      "publisher": "Patchstack",
      "title": "WordPress Brook theme <= 2.9.0 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "ThemeMove"
        ],
        "products": [
          {
            "vendor": "ThemeMove",
            "product": "Brook"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29743
      },
      "nvd": {
        "published": "2026-07-13T10:16:43.147",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57791",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Brook accepts an attacker-influenced PHP include filename and loads a local file outside the intended include set.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/brook/vulnerability/wordpress-brook-theme-2-9-0-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 227,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57792",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:02.627Z",
      "date_published": "2026-07-13T08:41:25.324Z",
      "date_updated": "2026-07-13T16:07:49.607Z",
      "publisher": "Patchstack",
      "title": "WordPress Dør theme <= 2.4.1 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "Mikado-Themes"
        ],
        "products": [
          {
            "vendor": "Mikado-Themes",
            "product": "Dør"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29743
      },
      "nvd": {
        "published": "2026-07-13T10:16:43.270",
        "lastModified": "2026-07-13T17:18:05.283",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57792",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dør lets attacker-controlled path data select a PHP include target outside the intended template set.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/dor/vulnerability/wordpress-doer-theme-2-4-1-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:02.627Z",
      "date_published": "2026-07-13T08:41:25.360Z",
      "date_updated": "2026-07-13T12:27:00.497Z",
      "publisher": "Patchstack",
      "title": "WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "Elated-Themes"
        ],
        "products": [
          {
            "vendor": "Elated-Themes",
            "product": "Flow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29741
      },
      "nvd": {
        "published": "2026-07-13T10:16:43.390",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57793",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Flow theme accepts an attacker-influenced PHP include filename and loads a local file outside the intended include set.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/flow/vulnerability/wordpress-flow-theme-1-8-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57794",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:02.627Z",
      "date_published": "2026-07-13T08:41:25.368Z",
      "date_updated": "2026-07-13T14:38:20.157Z",
      "publisher": "Patchstack",
      "title": "WordPress Golo Framework plugin <= 1.7.3 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "uxper"
        ],
        "products": [
          {
            "vendor": "uxper",
            "product": "Golo Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29743
      },
      "nvd": {
        "published": "2026-07-13T10:16:43.517",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57794",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Golo Framework allows a caller-selected local path to reach a PHP include operation.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/golo-framework/vulnerability/wordpress-golo-framework-plugin-1-7-3-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57795",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:02.628Z",
      "date_published": "2026-07-13T08:41:25.421Z",
      "date_updated": "2026-07-13T13:18:09.257Z",
      "publisher": "Patchstack",
      "title": "WordPress Kitchor theme <= 1.4.3 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "themelexus"
        ],
        "products": [
          {
            "vendor": "themelexus",
            "product": "Kitchor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29744
      },
      "nvd": {
        "published": "2026-07-13T10:16:43.643",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57795",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kitchor permits attacker-controlled input to select a PHP include target outside the intended template namespace.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/kitchor/vulnerability/wordpress-kitchor-theme-1-4-3-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57796",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:02.628Z",
      "date_published": "2026-07-13T08:41:25.446Z",
      "date_updated": "2026-07-13T13:54:34.800Z",
      "publisher": "Patchstack",
      "title": "WordPress Leedo theme <= 3.0.0 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "VLThemes"
        ],
        "products": [
          {
            "vendor": "VLThemes",
            "product": "Leedo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.2974
      },
      "nvd": {
        "published": "2026-07-13T10:16:43.760",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57796",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VLThemes Leedo leedo allows PHP Local File Inclusion.This issue affects Leedo: from n/a through <= 3.0.0.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/leedo/vulnerability/wordpress-leedo-theme-3-0-0-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57797",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:08.366Z",
      "date_published": "2026-07-13T08:41:25.447Z",
      "date_updated": "2026-07-13T14:01:36.352Z",
      "publisher": "Patchstack",
      "title": "WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "ThemeMove"
        ],
        "products": [
          {
            "vendor": "ThemeMove",
            "product": "EduMall"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15185
      },
      "nvd": {
        "published": "2026-07-13T10:16:43.877",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57797",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Patchstack record identifies a subscriber-reachable access-control failure but does not name the protected operation or object.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/edumall/vulnerability/wordpress-edumall-theme-4-5-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57798",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:08.366Z",
      "date_published": "2026-07-13T08:41:25.447Z",
      "date_updated": "2026-07-13T16:07:49.469Z",
      "publisher": "Patchstack",
      "title": "WordPress NewsPlus Shortcodes plugin <= 4.2.0 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "SaurabhSharma"
        ],
        "products": [
          {
            "vendor": "SaurabhSharma",
            "product": "NewsPlus Shortcodes"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.2974
      },
      "nvd": {
        "published": "2026-07-13T10:16:43.993",
        "lastModified": "2026-07-13T17:18:05.927",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57798",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/newsplus-shortcodes/vulnerability/wordpress-newsplus-shortcodes-plugin-4-2-0-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:08.366Z",
      "date_published": "2026-07-13T08:41:25.453Z",
      "date_updated": "2026-07-13T12:26:22.696Z",
      "publisher": "Patchstack",
      "title": "WordPress Nuss theme <= 1.3.6 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "uxper"
        ],
        "products": [
          {
            "vendor": "uxper",
            "product": "Nuss"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29745
      },
      "nvd": {
        "published": "2026-07-13T10:16:44.110",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57799",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-influenced filename reaches a PHP include or require operation without restricting the selected file to an approved namespace.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/nuss/vulnerability/wordpress-nuss-theme-1-3-6-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:08.367Z",
      "date_published": "2026-07-13T08:41:25.455Z",
      "date_updated": "2026-07-13T14:38:16.254Z",
      "publisher": "Patchstack",
      "title": "WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "Edge-Themes"
        ],
        "products": [
          {
            "vendor": "Edge-Themes",
            "product": "Overworld"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29744
      },
      "nvd": {
        "published": "2026-07-13T10:16:44.223",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57800",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled PHP include filename can select a local file outside the theme's intended template namespace.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/overworld/vulnerability/wordpress-overworld-theme-1-5-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:08.367Z",
      "date_published": "2026-07-13T08:41:25.460Z",
      "date_updated": "2026-07-13T13:15:53.331Z",
      "publisher": "Patchstack",
      "title": "WordPress SetSail theme <= 2.1 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "Select-Themes"
        ],
        "products": [
          {
            "vendor": "Select-Themes",
            "product": "SetSail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29745
      },
      "nvd": {
        "published": "2026-07-13T10:16:44.337",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57801",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SetSail lets a caller influence the PHP file selected by an include operation outside the intended template set.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/setsail/vulnerability/wordpress-setsail-theme-2-1-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:08.367Z",
      "date_published": "2026-07-13T08:41:25.474Z",
      "date_updated": "2026-07-13T13:57:58.819Z",
      "publisher": "Patchstack",
      "title": "WordPress Struktur theme <= 2.5.1 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "Select-Themes"
        ],
        "products": [
          {
            "vendor": "Select-Themes",
            "product": "Struktur"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29741
      },
      "nvd": {
        "published": "2026-07-13T10:16:44.453",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57802",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller can select a local PHP file outside the intended template set for inclusion by the Struktur theme.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/struktur/vulnerability/wordpress-struktur-theme-2-5-1-local-file-inclusion-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57803",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:08.367Z",
      "date_published": "2026-07-13T08:41:25.507Z",
      "date_updated": "2026-07-13T14:08:50.346Z",
      "publisher": "Patchstack",
      "title": "WordPress Struktur Core plugin <= 2.5.1 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "Select-Themes"
        ],
        "products": [
          {
            "vendor": "Select-Themes",
            "product": "Struktur Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29741
      },
      "nvd": {
        "published": "2026-07-13T10:16:44.567",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57803",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled path selects a local PHP file for inclusion outside the intended file set.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/struktur-core/vulnerability/wordpress-struktur-core-plugin-2-5-1-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:08.367Z",
      "date_published": "2026-07-13T08:41:25.514Z",
      "date_updated": "2026-07-21T16:57:14.917Z",
      "publisher": "Patchstack",
      "title": "WordPress TheGem theme Elements (for Elementor) plugin <= 5.11.1 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "CodexThemes"
        ],
        "products": [
          {
            "vendor": "CodexThemes",
            "product": "TheGem Theme Elements (for Elementor)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29742
      },
      "nvd": {
        "published": "2026-07-13T10:16:44.687",
        "lastModified": "2026-07-21T17:17:12.240",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57804",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TheGem passes an attacker-influenced filename to a PHP include operation without confining it to an intended file set.",
        "basis": [
          "CNA record",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/thegem-elements-elementor/vulnerability/wordpress-thegem-theme-elements-for-elementor-plugin-5-11-1-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 314,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57805",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:08.367Z",
      "date_published": "2026-07-13T08:41:25.570Z",
      "date_updated": "2026-07-13T10:25:52.142Z",
      "publisher": "Patchstack",
      "title": "WordPress Tonda theme <= 2.5 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "Select-Themes"
        ],
        "products": [
          {
            "vendor": "Select-Themes",
            "product": "Tonda"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22301
      },
      "nvd": {
        "published": "2026-07-13T10:16:44.807",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57805",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tonda lets attacker-controlled include data select executable content outside the intended template namespace.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Theme/tonda/vulnerability/wordpress-tonda-theme-2-5-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:16.223Z",
      "date_published": "2026-07-10T20:35:07.181Z",
      "date_updated": "2026-07-21T14:11:27.317Z",
      "publisher": "Patchstack",
      "title": "WordPress OAuth Single Sign On - SSO (OAuth Client) plugin <= 38.5.8 - Broken Authentication vulnerability",
      "affected": {
        "vendors": [
          "miniOrange Security Software Pvt Ltd."
        ],
        "products": [
          {
            "vendor": "miniOrange Security Software Pvt Ltd.",
            "product": "OAuth Single Sign On - SSO (OAuth Client)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00448,
        "percentile": 0.36822
      },
      "nvd": {
        "published": "2026-07-10T21:16:59.947",
        "lastModified": "2026-07-21T15:16:36.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57807",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OAuth client plugin exposes a password-recovery path that bypasses the normal authentication channel.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/miniorange-oauth-oidc-single-sign-on/vulnerability/wordpress-oauth-single-sign-on-sso-oauth-client-plugin-38-5-8-broken-authentication-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 280,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57808",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:16.223Z",
      "date_published": "2026-07-23T11:18:13.077Z",
      "date_updated": "2026-07-23T16:00:36.785Z",
      "publisher": "Patchstack",
      "title": "WordPress WP EasyPay plugin <= 4.5.0 - Arbitrary Content Deletion vulnerability",
      "affected": {
        "vendors": [
          "Saad Iqbal"
        ],
        "products": [
          {
            "vendor": "Saad Iqbal",
            "product": "WP EasyPay"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.2223
      },
      "nvd": {
        "published": "2026-07-23T12:18:30.663",
        "lastModified": "2026-07-23T16:17:28.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57808",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "WP EasyPay lets a subscriber delete content without checking that the caller may delete the selected object.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-easy-pay/vulnerability/wordpress-wp-easypay-plugin-4-5-0-arbitrary-content-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 70,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57809",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:16.223Z",
      "date_published": "2026-07-23T11:18:13.725Z",
      "date_updated": "2026-07-23T14:53:09.458Z",
      "publisher": "Patchstack",
      "title": "WordPress AffiliateWP plugin <= 2.34.0 - Reflected Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "AffiliateWP"
        ],
        "products": [
          {
            "vendor": "AffiliateWP",
            "product": "AffiliateWP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07756
      },
      "nvd": {
        "published": "2026-07-23T12:18:30.810",
        "lastModified": "2026-07-23T15:17:22.743",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57809",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/affiliate-wp/vulnerability/wordpress-affiliatewp-plugin-2-34-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 77,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57810",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:16.223Z",
      "date_published": "2026-07-13T08:41:25.595Z",
      "date_updated": "2026-07-13T14:38:12.921Z",
      "publisher": "Patchstack",
      "title": "WordPress APIExperts Square for WooCommerce plugin <= 4.7.4 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Saad Iqbal"
        ],
        "products": [
          {
            "vendor": "Saad Iqbal",
            "product": "APIExperts Square for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10658
      },
      "nvd": {
        "published": "2026-07-13T10:16:44.923",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57810",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "APIExperts Square for WooCommerce incorporates attacker-controlled input into an SQL statement without preserving the SQL data boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/woosquare/vulnerability/wordpress-apiexperts-square-for-woocommerce-plugin-4-7-4-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 264,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57811",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:16.223Z",
      "date_published": "2026-07-13T08:41:25.597Z",
      "date_updated": "2026-07-13T13:15:28.359Z",
      "publisher": "Patchstack",
      "title": "WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution (RCE) vulnerability",
      "affected": {
        "vendors": [
          "Realtyna"
        ],
        "products": [
          {
            "vendor": "Realtyna",
            "product": "Realtyna Organic IDX plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23472
      },
      "nvd": {
        "published": "2026-07-13T10:16:45.040",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57811",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Realtyna Organic IDX plugin path allows attacker-controlled content to cross into an executable code context.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/real-estate-listing-realtyna-wpl/vulnerability/wordpress-realtyna-organic-idx-plugin-plugin-5-2-0-remote-code-execution-rce-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:16.223Z",
      "date_published": "2026-07-13T08:41:25.598Z",
      "date_updated": "2026-07-13T13:58:26.493Z",
      "publisher": "Patchstack",
      "title": "WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "NSquared"
        ],
        "products": [
          {
            "vendor": "NSquared",
            "product": "Simply Schedule Appointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00191,
        "percentile": 0.08957
      },
      "nvd": {
        "published": "2026-07-13T10:16:45.157",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57812",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A sensitive action is reachable without the required access-control binding, whose exact check is not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/simply-schedule-appointments/vulnerability/wordpress-simply-schedule-appointments-plugin-1-6-12-4-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57813",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:16.224Z",
      "date_published": "2026-07-13T08:41:25.602Z",
      "date_updated": "2026-07-13T13:58:18.279Z",
      "publisher": "Patchstack",
      "title": "WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability",
      "affected": {
        "vendors": [
          "properfraction"
        ],
        "products": [
          {
            "vendor": "properfraction",
            "product": "MailOptin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17703
      },
      "nvd": {
        "published": "2026-07-13T10:16:45.270",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57813",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MailOptin privilege path permits a lower-trust actor to acquire or exercise a role beyond the actor's assigned authority.",
        "basis": [
          "CNA",
          "CWE-266",
          "Patchstack disclosure"
        ],
        "deepDive": true,
        "notes": "Read Patchstack disclosure https://patchstack.com/database/Wordpress/Plugin/mailoptin/vulnerability/wordpress-mailoptin-plugin-1-2-77-3-privilege-escalation-vulnerability?_s_id=cve; it confirms unauthenticated privilege escalation and the fixed version, but the public page does not disclose the assignment path or affected role field."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/mailoptin/vulnerability/wordpress-mailoptin-plugin-1-2-77-3-privilege-escalation-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57814",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:16.224Z",
      "date_published": "2026-07-13T08:41:25.605Z",
      "date_updated": "2026-07-13T14:20:16.879Z",
      "publisher": "Patchstack",
      "title": "WordPress Forminator plugin <= 1.55.0.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WPMU DEV - Your All-in-One WordPress Platform"
        ],
        "products": [
          {
            "vendor": "WPMU DEV - Your All-in-One WordPress Platform",
            "product": "Forminator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03955
      },
      "nvd": {
        "published": "2026-07-13T10:16:45.393",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57814",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected DOM path interprets attacker-controlled data as executable browser markup without scheme or context validation.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/forminator/vulnerability/wordpress-forminator-plugin-1-55-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57815",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:16.224Z",
      "date_published": "2026-07-13T08:41:25.609Z",
      "date_updated": "2026-07-13T10:25:20.611Z",
      "publisher": "Patchstack",
      "title": "WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability",
      "affected": {
        "vendors": [
          "WPMU DEV - Your All-in-One WordPress Platform"
        ],
        "products": [
          {
            "vendor": "WPMU DEV - Your All-in-One WordPress Platform",
            "product": "Forminator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.2507
      },
      "nvd": {
        "published": "2026-07-13T10:16:45.507",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57815",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Forminator accepts a filesystem or upload target outside its intended namespace, while the path field and selection check are not public.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/forminator/vulnerability/wordpress-forminator-plugin-1-55-0-2-arbitrary-file-download-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57816",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T08:05:16.224Z",
      "date_published": "2026-07-13T08:41:25.624Z",
      "date_updated": "2026-07-13T14:38:09.832Z",
      "publisher": "Patchstack",
      "title": "WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.8 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "FunnelKit"
        ],
        "products": [
          {
            "vendor": "FunnelKit",
            "product": "Funnel Builder by FunnelKit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03955
      },
      "nvd": {
        "published": "2026-07-13T10:16:45.620",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57816",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Funnel Builder reflects attacker-controlled input into HTML without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/funnel-builder/vulnerability/wordpress-funnel-builder-by-funnelkit-plugin-3-15-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T11:47:18.920Z",
      "date_published": "2026-07-15T09:20:09.239Z",
      "date_updated": "2026-07-15T12:26:10.244Z",
      "publisher": "apache",
      "title": "Apache Fineract: Office list: SQL Injection via Subquery in orderBy",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Fineract"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00844,
        "percentile": 0.54424
      },
      "nvd": {
        "published": "2026-07-15T10:16:47.620",
        "lastModified": "2026-07-15T20:15:16.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57821",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/fineract/pull/6048",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/lb7zwdv7qntzy6z05gzf7m8mxw9cbgsj",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/rj5vwh3z2xcvsf0rqwj8kokpbrxkhq4n",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 848,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57827",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T16:55:04.093Z",
      "date_published": "2026-07-11T09:29:03.863Z",
      "date_updated": "2026-07-23T15:01:02.375Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12",
      "affected": {
        "vendors": [
          "rsjoomla.com"
        ],
        "products": [
          {
            "vendor": "rsjoomla.com",
            "product": "rsjoomla.com RSFiles extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00405,
        "percentile": 0.3329
      },
      "nvd": {
        "published": "2026-07-11T10:16:34.057",
        "lastModified": "2026-07-23T16:17:28.243",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57827",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path accepts a dangerous executable file type and stores it where the application can use or execute it.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.rsjoomla.com/joomla-extensions/joomla-download-manager.html",
          "host": "www.rsjoomla.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57828",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T16:55:04.094Z",
      "date_published": "2026-07-11T09:27:16.840Z",
      "date_updated": "2026-07-23T14:58:47.235Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3",
      "affected": {
        "vendors": [
          "phoca.cz"
        ],
        "products": [
          {
            "vendor": "phoca.cz",
            "product": "phoca.cz Phoca Download extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29915
      },
      "nvd": {
        "published": "2026-07-11T10:16:35.710",
        "lastModified": "2026-07-23T16:17:28.373",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57828",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path accepts a file type that can become executable content at the selected storage destination.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.phoca.cz/phocadownload",
          "host": "www.phoca.cz",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/phoca-download-authenticated-file-upload-rce/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57829",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T16:55:04.094Z",
      "date_published": "2026-07-13T07:28:57.141Z",
      "date_updated": "2026-07-23T14:55:42.290Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7",
      "affected": {
        "vendors": [
          "joomshaper.com"
        ],
        "products": [
          {
            "vendor": "joomshaper.com",
            "product": "Helix Ultimate extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00182,
        "percentile": 0.08051
      },
      "nvd": {
        "published": "2026-07-13T08:16:21.547",
        "lastModified": "2026-07-23T16:17:28.497",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57829",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Helix Ultimate extension for Joomla page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomshaper.com/joomla-templates/helixultimate",
          "host": "www.joomshaper.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 174,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57830",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T16:55:04.094Z",
      "date_published": "2026-07-13T07:30:12.286Z",
      "date_updated": "2026-07-23T14:57:30.551Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7",
      "affected": {
        "vendors": [
          "joomshaper.com"
        ],
        "products": [
          {
            "vendor": "joomshaper.com",
            "product": "Helix Ultimate extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.29999999999999893,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22593
      },
      "nvd": {
        "published": "2026-07-13T08:16:21.713",
        "lastModified": "2026-07-23T16:17:28.620",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57830",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Helix Ultimate exposes recursive file deletion without authentication, but the vendor page does not identify the failing endpoint or check.",
        "basis": [
          "CNA",
          "CWE-862",
          "vendor product page"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.joomshaper.com/joomla-templates/helixultimate; the official product page reports version 2.2.9 but provides no advisory, endpoint, or failing check, and no reproduction was performed."
      },
      "references": [
        {
          "url": "https://www.joomshaper.com/joomla-templates/helixultimate",
          "host": "www.joomshaper.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57831",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T16:55:04.094Z",
      "date_published": "2026-07-15T08:08:04.874Z",
      "date_updated": "2026-07-23T14:56:19.709Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2",
      "affected": {
        "vendors": [
          "digital-peak.com"
        ],
        "products": [
          {
            "vendor": "digital-peak.com",
            "product": "DP Calendar extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14761
      },
      "nvd": {
        "published": "2026-07-15T09:16:33.310",
        "lastModified": "2026-07-23T16:17:28.747",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57831",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DP Calendar incorporates an unauthenticated request value into SQL without preserving the query grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://joomla.digital-peak.com/products/dpcalendar",
          "host": "joomla.digital-peak.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/dpcalendar-sql-injection-disclosure/",
          "host": "mysites.guru",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57832",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T16:55:04.094Z",
      "date_published": "2026-07-15T08:09:51.707Z",
      "date_updated": "2026-07-23T14:58:56.001Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9",
      "affected": {
        "vendors": [
          "joomdonation.com"
        ],
        "products": [
          {
            "vendor": "joomdonation.com",
            "product": "EDocman extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14761
      },
      "nvd": {
        "published": "2026-07-15T09:16:33.450",
        "lastModified": "2026-07-23T16:17:28.853",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57832",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated EDocman value is incorporated into a SQL query without safe parameter binding, although the exact parameter is not public.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://joomdonation.com/joomla-extensions/edocman-joomla-download-manager.html",
          "host": "joomdonation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/edocman-sql-injection-disclosure/",
          "host": "mysites.guru",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 172,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57833",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T16:55:04.094Z",
      "date_published": "2026-07-15T08:59:09.532Z",
      "date_updated": "2026-07-23T14:57:14.800Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2",
      "affected": {
        "vendors": [
          "weeblr.com"
        ],
        "products": [
          {
            "vendor": "weeblr.com",
            "product": "4Analytics extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00318,
        "percentile": 0.24181
      },
      "nvd": {
        "published": "2026-07-15T10:16:47.737",
        "lastModified": "2026-07-23T16:17:28.963",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57833",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The 4Analytics extension for Joomla page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://weeblr.com/joomla-seo/4analytics-private-analytics-for-joomla",
          "host": "weeblr.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57834",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T17:14:10.028Z",
      "date_published": "2026-07-29T07:25:49.384Z",
      "date_updated": "2026-07-30T03:55:16.378Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Malformed chunked message body allows request smuggling",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 3,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26472
      },
      "nvd": {
        "published": "2026-07-29T08:16:31.563",
        "lastModified": "2026-08-03T13:42:28.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57834",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Traffic Server and its peer disagree on malformed chunked-message boundaries, allowing one request to be interpreted as another.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-57848",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T18:48:00.282Z",
      "date_published": "2026-07-18T19:15:18.458Z",
      "date_updated": "2026-07-20T17:45:52.377Z",
      "publisher": "VulnCheck",
      "title": "Stoat for Android Internal File Disclosure via Exported ShareTargetActivity URI Validation",
      "affected": {
        "vendors": [
          "stoatchat"
        ],
        "products": [
          {
            "vendor": "stoatchat",
            "product": "Stoat for Android"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-926",
          "name": "Improper Export of Android Application Components",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04164
      },
      "nvd": {
        "published": "2026-07-18T20:17:30.427",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57848",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An exported Android share activity accepts a caller-supplied file URI and treats an internal application file as a user-selected attachment.",
        "basis": [
          "CNA",
          "CWE-926"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/stoatchat/for-android",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/stoatchat/for-android/commit/50d5f5143940809ebb5a61e5f507c956c33aa970",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/stoat-for-android-internal-file-disclosure-via-exported-sharetargetactivity-uri-validation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1421,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57850",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T18:48:00.282Z",
      "date_published": "2026-07-10T19:53:21.336Z",
      "date_updated": "2026-08-03T16:26:36.974Z",
      "publisher": "VulnCheck",
      "title": "RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection",
      "affected": {
        "vendors": [
          "RustDesk"
        ],
        "products": [
          {
            "vendor": "RustDesk",
            "product": "RustDesk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0.3999999999999986,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31663
      },
      "nvd": {
        "published": "2026-07-10T20:16:48.663",
        "lastModified": "2026-08-03T17:16:38.823",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57850",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "RustDesk fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rustdesk/rustdesk/pull/15469",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/rustdesk/rustdesk/commit/493b14ba78abc3dfb33f109c7f93c1c95a1dabc4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/rustdesk/rustdesk/releases/tag/1.4.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/rustdesk/rustdesk",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rustdesk-missing-session-scope-enforcement-allows-out-of-scope-control-message-injection",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57851",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T18:48:00.282Z",
      "date_published": "2026-07-07T16:02:05.937Z",
      "date_updated": "2026-07-28T01:49:47.441Z",
      "publisher": "VulnCheck",
      "title": "MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers",
      "affected": {
        "vendors": [
          "Micro-Star International (MSI)"
        ],
        "products": [
          {
            "vendor": "Micro-Star International (MSI)",
            "product": "KernCoreLib64.sys"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-782",
          "name": "Exposed IOCTL with Insufficient Access Control",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06623
      },
      "nvd": {
        "published": "2026-07-07T17:16:36.880",
        "lastModified": "2026-07-10T18:22:49.657",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57851",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "KernCoreLib64 exposes physical-memory and I/O-port IOCTLs to ordinary local users instead of restricting the device to administrators.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-782"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/readmsr/MSI_FeatureManager_CVE",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/msi-gamegaraj-kerncorelib64-sys-privilege-escalation-via-ioctl-handlers",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 518,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57852",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T18:48:00.282Z",
      "date_published": "2026-07-20T22:09:01.640Z",
      "date_updated": "2026-07-21T14:55:56.254Z",
      "publisher": "VulnCheck",
      "title": "Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check",
      "affected": {
        "vendors": [
          "Trilby Media"
        ],
        "products": [
          {
            "vendor": "Trilby Media",
            "product": "Grav CMS scheduler-webhook plugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-303",
          "name": "Incorrect Implementation of Authentication Algorithm",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00424,
        "percentile": 0.34911
      },
      "nvd": {
        "published": "2026-07-20T22:17:17.243",
        "lastModified": "2026-07-21T18:57:45.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57852",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Grav CMS scheduler-webhook plugin reaches a protected operation without completing the authentication state or credential validation required for that path.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-303"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-xwv3-2mv2-w33x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.vulncheck.com/advisories/authentication-bypass-via-null-short-circuit-in-grav-cms-scheduler-webhook-token-check",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57855",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T18:48:00.282Z",
      "date_published": "2026-07-13T22:33:39.717Z",
      "date_updated": "2026-07-14T21:34:35.253Z",
      "publisher": "VulnCheck",
      "title": "Cockpit CMS Missing Authorization in Bucket File Storage API",
      "affected": {
        "vendors": [
          "Cockpit HQ"
        ],
        "products": [
          {
            "vendor": "Cockpit HQ",
            "product": "Cockpit CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20575
      },
      "nvd": {
        "published": "2026-07-13T23:16:46.743",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57855",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The bucket API executes listing, upload, delete, rename, and folder commands for any authenticated user without an ACL or role check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cockpit-hq/cockpit",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/Cockpit-HQ/Cockpit/commit/dde2d1d74f5f4e11de42a298918ea8c9684f932c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://gist.github.com/sermikr0/821c4edd3c34e98a62a50b07707785bd",
          "host": "gist.github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cockpit-cms-missing-authorization-in-bucket-file-storage-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57856",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T18:48:00.282Z",
      "date_published": "2026-07-13T22:41:23.183Z",
      "date_updated": "2026-07-14T21:34:35.949Z",
      "publisher": "VulnCheck",
      "title": "Cockpit CMS Path Traversal via Bucket Name in Bucket File Storage API",
      "affected": {
        "vendors": [
          "Cockpit HQ"
        ],
        "products": [
          {
            "vendor": "Cockpit HQ",
            "product": "Cockpit CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31677
      },
      "nvd": {
        "published": "2026-07-13T23:16:46.883",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57856",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cockpit permits dot-dot in bucket names and resolves the resulting Flysystem path to the uploads root outside the selected bucket.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cockpit-hq/cockpit",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/Cockpit-HQ/Cockpit/commit/dde2d1d74f5f4e11de42a298918ea8c9684f932c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://gist.github.com/sermikr0/821c4edd3c34e98a62a50b07707785bd",
          "host": "gist.github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cockpit-cms-missing-authorization-in-bucket-file-storage-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cockpit-cms-path-traversal-via-bucket-name-in-bucket-file-storage-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 764,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57857",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T18:48:00.282Z",
      "date_published": "2026-07-18T20:33:06.674Z",
      "date_updated": "2026-07-20T17:45:54.451Z",
      "publisher": "VulnCheck",
      "title": "Flow Payment Plugin for WordPress Reflected Cross-Site Scripting via error_message Parameter",
      "affected": {
        "vendors": [
          "Flow"
        ],
        "products": [
          {
            "vendor": "Flow",
            "product": "Flow Payment"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13139
      },
      "nvd": {
        "published": "2026-07-18T21:17:03.687",
        "lastModified": "2026-07-23T15:14:51.013",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57857",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Flow Payment reflects an order-cancellation value into the WooCommerce checkout page without browser-context encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.flow.cl/",
          "host": "www.flow.cl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/flow-payment-plugin-for-wordpress-reflected-cross-site-scripting-via-error-message-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 812,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57859",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T18:48:00.283Z",
      "date_published": "2026-07-30T13:41:34.196Z",
      "date_updated": "2026-07-31T11:54:03.332Z",
      "publisher": "VulnCheck",
      "title": "e107 Second-Order Code Execution via eval()-Based Deserialization in e_array::unserialize()",
      "affected": {
        "vendors": [
          "e107inc"
        ],
        "products": [
          {
            "vendor": "e107inc",
            "product": "e107"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00399,
        "percentile": 0.32621
      },
      "nvd": {
        "published": "2026-07-30T14:16:59.923",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57859",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs column.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/e107inc/e107/security/advisories/GHSA-568x-w5qj-vr7c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/e107inc/e107/commit/40e73cefde85b32e1227dfac9956a5cb87046277",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/e107inc/e107",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/e107-second-order-code-execution-via-eval-based-deserialization-in-e-array-unserialize",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 540,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57860",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T18:48:00.283Z",
      "date_published": "2026-07-17T16:16:09.573Z",
      "date_updated": "2026-07-20T17:45:55.116Z",
      "publisher": "VulnCheck",
      "title": "ForgeCode Arbitrary Code Execution via Unvetted .mcp.json in Untrusted Repository",
      "affected": {
        "vendors": [
          "tailcallhq"
        ],
        "products": [
          {
            "vendor": "tailcallhq",
            "product": "forgecode"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03336
      },
      "nvd": {
        "published": "2026-07-17T17:17:16.777",
        "lastModified": "2026-07-17T18:28:39.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57860",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json file on startup without user confirmation.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tailcallhq/forgecode/issues/3022",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/tailcallhq/forgecode/issues/3252",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/tailcallhq/forgecode",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/tailcallhq/forgecode/commit/68ca3a3a26c73c38a700453d3d021b5bbdc15dbd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/forgecode-arbitrary-code-execution-via-unvetted-mcp-json-in-untrusted-repository",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 695,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57862",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-25T18:48:00.283Z",
      "date_published": "2026-07-30T15:26:23.187Z",
      "date_updated": "2026-07-31T11:54:04.005Z",
      "publisher": "VulnCheck",
      "title": "Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation",
      "affected": {
        "vendors": [
          "Kanboard"
        ],
        "products": [
          {
            "vendor": "Kanboard",
            "product": "Kanboard"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.09999999999999964,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21559
      },
      "nvd": {
        "published": "2026-07-30T16:17:14.607",
        "lastModified": "2026-07-31T12:16:52.293",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57862",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SSRF filter rejects only dotted-decimal private addresses, while cURL accepts hexadecimal encodings of the same destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kanboard/kanboard",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://gist.github.com/sermikr0/67c8acfc395e465127e729dc309da3ae",
          "host": "gist.github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/kanboard-and-prior-ssrf-filter-bypass-via-hexadecimal-ip-notation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 621,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57867",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T00:40:34.057Z",
      "date_published": "2026-07-07T05:11:05.945Z",
      "date_updated": "2026-07-07T13:35:02.868Z",
      "publisher": "TML",
      "title": "MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management.",
      "affected": {
        "vendors": [
          "MicroRealEstate"
        ],
        "products": [
          {
            "vendor": "MicroRealEstate",
            "product": "MicroRealEstate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vdp@themissinglink.com.au",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00374,
        "percentile": 0.30152
      },
      "nvd": {
        "published": "2026-07-07T06:16:22.473",
        "lastModified": "2026-07-07T14:16:33.097",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57867",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OTP login flow lacks token-state and attempt controls, allowing an attacker to repeatedly guess one-time passwords for another user.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microrealestate/microrealestate",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.themissinglink.com.au/security-advisories/cve-2026-57867",
          "host": "www.themissinglink.com.au",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57868",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T00:40:34.057Z",
      "date_published": "2026-07-07T05:18:54.645Z",
      "date_updated": "2026-07-07T13:31:57.313Z",
      "publisher": "TML",
      "title": "MicroRealEstate is affected by broken object-level access controls in PDF generator functionality.",
      "affected": {
        "vendors": [
          "MicroRealEstate"
        ],
        "products": [
          {
            "vendor": "MicroRealEstate",
            "product": "MicroRealEstate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vdp@themissinglink.com.au",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14545
      },
      "nvd": {
        "published": "2026-07-07T06:16:22.633",
        "lastModified": "2026-07-07T14:16:33.210",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57868",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microrealestate/microrealestate",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.themissinglink.com.au/security-advisories/cve-2026-57868",
          "host": "www.themissinglink.com.au",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 157,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57869",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T00:40:34.057Z",
      "date_published": "2026-07-07T05:24:38.925Z",
      "date_updated": "2026-07-07T13:32:42.313Z",
      "publisher": "TML",
      "title": "Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization.",
      "affected": {
        "vendors": [
          "MicroRealEstate"
        ],
        "products": [
          {
            "vendor": "MicroRealEstate",
            "product": "MicroRealEstate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1241",
          "name": "Use of Predictable Algorithm in Random Number Generator",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vdp@themissinglink.com.au",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11999
      },
      "nvd": {
        "published": "2026-07-07T06:16:22.750",
        "lastModified": "2026-07-07T14:16:33.317",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57869",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Predictable document identifiers are accepted without binding the requested landlord or tenant document to the caller.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-1241"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microrealestate/microrealestate",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.themissinglink.com.au/security-advisories/cve-2026-57869",
          "host": "www.themissinglink.com.au",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57870",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T00:40:34.057Z",
      "date_published": "2026-07-07T05:28:57.708Z",
      "date_updated": "2026-07-07T13:33:17.528Z",
      "publisher": "TML",
      "title": "Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization.",
      "affected": {
        "vendors": [
          "MicroRealEstate"
        ],
        "products": [
          {
            "vendor": "MicroRealEstate",
            "product": "MicroRealEstate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vdp@themissinglink.com.au",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11997
      },
      "nvd": {
        "published": "2026-07-07T06:16:22.890",
        "lastModified": "2026-07-07T14:16:33.430",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57870",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Template API does not bind a requested document template to the caller's organization.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microrealestate/microrealestate",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.themissinglink.com.au/security-advisories/cve-2026-57870",
          "host": "www.themissinglink.com.au",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 231,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57871",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T00:40:34.057Z",
      "date_published": "2026-07-07T05:34:07.508Z",
      "date_updated": "2026-07-07T13:33:51.133Z",
      "publisher": "TML",
      "title": "Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files.",
      "affected": {
        "vendors": [
          "MicroRealEstate"
        ],
        "products": [
          {
            "vendor": "MicroRealEstate",
            "product": "MicroRealEstate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vdp@themissinglink.com.au",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28805
      },
      "nvd": {
        "published": "2026-07-07T06:16:23.017",
        "lastModified": "2026-07-07T14:16:33.533",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57871",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A relative traversal path writes a file outside the intended destination directory.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microrealestate/microrealestate",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.themissinglink.com.au/security-advisories/cve-2026-57871",
          "host": "www.themissinglink.com.au",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57895",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-28T23:50:03.923Z",
      "date_published": "2026-07-08T04:38:14.053Z",
      "date_updated": "2026-07-08T12:57:19.539Z",
      "publisher": "jpcert",
      "title": "Incorrect default permissions issue exists in Pupsman versions prior to 3.",
      "affected": {
        "vendors": [
          "Fuji Electric Co.,Ltd."
        ],
        "products": [
          {
            "vendor": "Fuji Electric Co.,Ltd.",
            "product": "Pupsman"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.0011,
        "percentile": 0.01468
      },
      "nvd": {
        "published": "2026-07-08T06:16:22.900",
        "lastModified": "2026-07-08T15:07:37.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57895",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The installer leaves its program directory writable enough for an attacker to plant an executable later launched with SYSTEM authority.",
        "basis": [
          "CNA record",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.fujielectric.co.jp/products/power_supply/ups/product_detail/software_pupsman.html",
          "host": "www.fujielectric.co.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jvn.jp/en/jp/JVN62347140/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57896",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:00:24.538Z",
      "date_published": "2026-07-16T20:06:50.140Z",
      "date_updated": "2026-07-17T13:16:50.596Z",
      "publisher": "icscert",
      "title": "AutomationDirect Productivity Suite Out-of-bounds Read",
      "affected": {
        "vendors": [
          "AutomationDirect"
        ],
        "products": [
          {
            "vendor": "AutomationDirect",
            "product": "Productivity Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01274
      },
      "nvd": {
        "published": "2026-07-16T21:17:21.617",
        "lastModified": "2026-07-17T18:31:44.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57896",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Productivity Suite reads beyond an allocated buffer because the input length or boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.automationdirect.com/support/software-downloads",
          "host": "www.automationdirect.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-04",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-04.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57898",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T14:11:22.756Z",
      "date_published": "2026-07-14T07:51:19.002Z",
      "date_updated": "2026-07-14T12:29:18.068Z",
      "publisher": "eclipse",
      "title": "In Eclipse BaSyx Java Server SDK versions 2.",
      "affected": {
        "vendors": [
          "Eclipse Foundation"
        ],
        "products": [
          {
            "vendor": "Eclipse Foundation",
            "product": "Eclipse BaSyx - Java Server SDK"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:emo@eclipse.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00447,
        "percentile": 0.36744
      },
      "nvd": {
        "published": "2026-07-14T09:16:41.173",
        "lastModified": "2026-07-14T16:38:41.077",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57898",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MongoDB thumbnail backend treats a client filename as an opaque key and later as a local path, allowing traversal or absolute-path writes.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/159",
          "host": "gitlab.eclipse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1146,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57916",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T10:47:10.593Z",
      "date_published": "2026-07-27T10:29:30.612Z",
      "date_updated": "2026-07-27T14:41:43.080Z",
      "publisher": "CERT-PL",
      "title": "Arbitrary Path Execution via CPS URI in proCertum SmartSign",
      "affected": {
        "vendors": [
          "Asseco"
        ],
        "products": [
          {
            "vendor": "Asseco",
            "product": "proCertum SmartSign"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00085,
        "percentile": 0.00393
      },
      "nvd": {
        "published": "2026-07-27T12:16:46.243",
        "lastModified": "2026-07-30T16:29:42.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57916",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SmartSign opens an attacker-selected CPS URI without restricting its scheme, allowing the certificate to select a local executable or remote URL.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-57916",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://pomoc.certum.pl/pl/oprogramowanie/procertum-smartsign/",
          "host": "pomoc.certum.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57917",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T10:47:10.593Z",
      "date_published": "2026-07-27T10:29:31.529Z",
      "date_updated": "2026-07-27T14:41:24.317Z",
      "publisher": "CERT-PL",
      "title": "Improper Restriction of XML External Entity Reference in proCertum SmartSign",
      "affected": {
        "vendors": [
          "Asseco"
        ],
        "products": [
          {
            "vendor": "Asseco",
            "product": "proCertum SmartSign"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-611",
          "name": "Improper Restriction of XML External Entity Reference",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.0336
      },
      "nvd": {
        "published": "2026-07-27T12:16:46.400",
        "lastModified": "2026-07-30T16:29:42.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57917",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The XML parser resolves attacker-supplied external entities, allowing the document to select local files or outbound request targets.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-611"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/posts/2026/07/CVE-2026-57916",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://pomoc.certum.pl/pl/oprogramowanie/procertum-smartsign/",
          "host": "pomoc.certum.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57961",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T13:59:33.048Z",
      "date_published": "2026-07-10T13:58:00.282Z",
      "date_updated": "2026-07-10T15:14:32.391Z",
      "publisher": "VulnCheck",
      "title": "phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths Function",
      "affected": {
        "vendors": [
          "phpMyFAQ"
        ],
        "products": [
          {
            "vendor": "phpMyFAQ",
            "product": "phpMyFAQ"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 2.3999999999999995,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18984
      },
      "nvd": {
        "published": "2026-07-10T15:16:47.057",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57961",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The phpMyFAQ path accepts an attacker-controlled path that can escape the intended filesystem root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-88g4-74f3-63x9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/phpmyfaq-authenticated-path-traversal-in-pdf-export-via-concatenatepaths-function",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 719,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57962",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T15:27:32.831Z",
      "date_published": "2026-07-01T00:58:32.777Z",
      "date_updated": "2026-07-01T14:40:26.466Z",
      "publisher": "mozilla",
      "title": "Denial-of-service via malicious LDAP address-book server",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12575
      },
      "nvd": {
        "published": "2026-07-01T02:17:00.597",
        "lastModified": "2026-07-06T15:21:36.847",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57962",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A malicious LDAP server can cause arbitrary response data to be retained until process memory is exhausted.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2042872",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-63/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-64/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57963",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T15:27:32.832Z",
      "date_published": "2026-07-01T00:58:33.922Z",
      "date_updated": "2026-07-01T14:09:10.035Z",
      "publisher": "mozilla",
      "title": "Chat UI manipulation by injection",
      "affected": {
        "vendors": [
          "Mozilla"
        ],
        "products": [
          {
            "vendor": "Mozilla",
            "product": "Thunderbird"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00191,
        "percentile": 0.09037
      },
      "nvd": {
        "published": "2026-07-01T02:17:00.700",
        "lastModified": "2026-07-06T15:21:12.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57963",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Thunderbird rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2042910",
          "host": "bugzilla.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-63/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-64/",
          "host": "www.mozilla.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57968",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.853Z",
      "date_published": "2026-07-14T17:09:39.716Z",
      "date_updated": "2026-08-03T22:58:07.961Z",
      "publisher": "microsoft",
      "title": "Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows Subsystem for Linux (WSL2)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23479
      },
      "nvd": {
        "published": "2026-07-14T18:18:35.273",
        "lastModified": "2026-07-20T18:39:51.057",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57968",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Subsystem for Linux reads beyond the end of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57968",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57969",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.853Z",
      "date_published": "2026-07-14T17:05:17.707Z",
      "date_updated": "2026-08-03T22:53:37.199Z",
      "publisher": "microsoft",
      "title": "Azure CycleCloud Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure CycleCloud 8.9.1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00526,
        "percentile": 0.41646
      },
      "nvd": {
        "published": "2026-07-14T17:17:10.980",
        "lastModified": "2026-07-22T16:21:20.293",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57969",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Azure CycleCloud 8.9.1 permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57969",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57973",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.853Z",
      "date_published": "2026-07-14T17:09:40.251Z",
      "date_updated": "2026-08-03T22:58:08.510Z",
      "publisher": "microsoft",
      "title": "Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows Subsystem for Linux (WSL2)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06003
      },
      "nvd": {
        "published": "2026-07-14T18:18:35.460",
        "lastModified": "2026-07-20T18:39:35.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57973",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Subsystem for Linux checks a target and later uses it in a separate step, allowing the target to change between those operations.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57973",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 140,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57974",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.853Z",
      "date_published": "2026-07-03T20:35:19.152Z",
      "date_updated": "2026-08-03T22:58:08.976Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00577,
        "percentile": 0.44293
      },
      "nvd": {
        "published": "2026-07-03T21:17:00.957",
        "lastModified": "2026-07-07T13:43:32.083",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57974",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unchecked integer calculation wraps before the result is used for a memory or bounds decision.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57974",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 129,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57975",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.853Z",
      "date_published": "2026-07-03T20:35:08.786Z",
      "date_updated": "2026-08-03T22:58:09.444Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00445,
        "percentile": 0.36601
      },
      "nvd": {
        "published": "2026-07-03T21:17:01.077",
        "lastModified": "2026-07-07T13:42:46.433",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57975",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge (Chromium-based) accesses an object through an incompatible type, invalidating the layout or lifetime assumptions used by the access.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57975",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57976",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.853Z",
      "date_published": "2026-07-14T17:05:18.257Z",
      "date_updated": "2026-08-03T22:53:37.758Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00755,
        "percentile": 0.51582
      },
      "nvd": {
        "published": "2026-07-14T17:17:11.120",
        "lastModified": "2026-07-22T16:18:32.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57976",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A crafted input reaches a path that dereferences a null pointer instead of rejecting the invalid state.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57976",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-57977",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.853Z",
      "date_published": "2026-07-03T20:35:19.684Z",
      "date_updated": "2026-08-03T22:58:09.997Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00412,
        "percentile": 0.33924
      },
      "nvd": {
        "published": "2026-07-03T21:17:01.193",
        "lastModified": "2026-07-07T13:14:18.280",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57977",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Microsoft Edge (Chromium-based) page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57977",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57978",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.853Z",
      "date_published": "2026-07-26T17:17:21.079Z",
      "date_updated": "2026-08-03T22:53:58.904Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11564
      },
      "nvd": {
        "published": "2026-07-26T18:18:23.780",
        "lastModified": "2026-08-03T14:56:36.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57978",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Edge accepts an origin identity that is not correctly bound to the network content being presented.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57978",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57979",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-14T17:05:18.756Z",
      "date_updated": "2026-08-03T22:53:38.249Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00651,
        "percentile": 0.47698
      },
      "nvd": {
        "published": "2026-07-14T17:17:11.317",
        "lastModified": "2026-07-22T16:18:32.887",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57979",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows RDP reads beyond a valid buffer and returns adjacent memory to a remote unauthenticated peer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57979",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-57980",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-17T21:29:27.541Z",
      "date_updated": "2026-08-03T22:53:58.272Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Tampering Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.12941
      },
      "nvd": {
        "published": "2026-07-17T22:17:59.917",
        "lastModified": "2026-07-21T15:18:28.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57980",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Edge exposes an alternate request path that reaches a protected operation without satisfying the normal authentication channel.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57980",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-03T20:35:20.280Z",
      "date_updated": "2026-08-03T22:53:38.776Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00568,
        "percentile": 0.43848
      },
      "nvd": {
        "published": "2026-07-03T21:17:01.313",
        "lastModified": "2026-07-07T15:12:44.373",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57981",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Microsoft Edge (Chromium-based) path can dereference an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57981",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-14T17:09:42.250Z",
      "date_updated": "2026-08-03T22:58:10.549Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00953,
        "percentile": 0.57905
      },
      "nvd": {
        "published": "2026-07-14T18:18:36.133",
        "lastModified": "2026-07-22T16:18:33.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57982",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows RDP exposes residual data from an uninitialized resource to an authenticated network peer.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57982",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-57983",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-03T20:35:10.166Z",
      "date_updated": "2026-08-03T22:53:39.351Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00472,
        "percentile": 0.38386
      },
      "nvd": {
        "published": "2026-07-03T21:17:01.433",
        "lastModified": "2026-07-07T15:15:02.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57983",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft identifies an Edge authorization failure that bypasses a network security feature, but the public page does not disclose the protected action or check.",
        "basis": [
          "CNA",
          "CWE-285",
          "MSRC"
        ],
        "deepDive": true,
        "notes": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57983 - the official page is JavaScript-only in the retrieved response and exposed no causal detail beyond the embedded authorization/security-feature-bypass record."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57983",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57984",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-03T20:35:10.727Z",
      "date_updated": "2026-08-03T22:53:39.867Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00429,
        "percentile": 0.35309
      },
      "nvd": {
        "published": "2026-07-03T21:17:01.550",
        "lastModified": "2026-07-07T15:17:01.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57984",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge (Chromium-based) retains or reuses an object after its storage has been freed, allowing later processing to access invalid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57984",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57985",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-03T20:35:11.415Z",
      "date_updated": "2026-08-03T22:53:40.434Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.200000000000001,
      "epss": {
        "score": 0.00479,
        "percentile": 0.38821
      },
      "nvd": {
        "published": "2026-07-03T21:17:01.663",
        "lastModified": "2026-07-07T15:22:29.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57985",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Edge advisory reports improper input validation leading to remote code execution but does not identify the input grammar, parser, state, or memory failure.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57985",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57986",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-03T20:35:20.815Z",
      "date_updated": "2026-08-03T22:53:40.978Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00429,
        "percentile": 0.35309
      },
      "nvd": {
        "published": "2026-07-03T21:17:01.780",
        "lastModified": "2026-07-07T12:50:49.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57986",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge (Chromium-based) continues to access an object after its storage has been released, allowing invalid heap use and possible corruption.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57986",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57987",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-03T20:35:11.933Z",
      "date_updated": "2026-08-03T22:53:41.510Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00617,
        "percentile": 0.46153
      },
      "nvd": {
        "published": "2026-07-03T21:17:01.903",
        "lastModified": "2026-07-07T12:44:32.567",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57987",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Edge makes a server-side request to an attacker-selected destination and exposes the resulting browser context to spoofing.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57987",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 137,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57988",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-03T20:35:12.756Z",
      "date_updated": "2026-08-03T22:53:42.055Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00532,
        "percentile": 0.41959
      },
      "nvd": {
        "published": "2026-07-03T21:17:02.023",
        "lastModified": "2026-07-07T12:43:36.940",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57988",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge permits a relative traversal path to select content outside its intended network-accessible directory.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57988",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57989",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-26T17:22:08.118Z",
      "date_updated": "2026-08-03T22:59:06.471Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00429,
        "percentile": 0.35312
      },
      "nvd": {
        "published": "2026-07-26T18:18:25.033",
        "lastModified": "2026-08-03T14:56:02.713",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57989",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft Edge validates a network origin incorrectly and discloses information, but the compared origins and failing rule are not public.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57989",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57990",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-26T17:22:14.608Z",
      "date_updated": "2026-08-03T22:53:59.533Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-552",
          "name": "Files or Directories Accessible to External Parties",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00923,
        "percentile": 0.56923
      },
      "nvd": {
        "published": "2026-07-26T18:18:25.153",
        "lastModified": "2026-08-03T14:54:26.487",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57990",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft says Edge exposes files or directories over the network but does not identify the storage boundary or access path.",
        "basis": [
          "CNA",
          "CWE-552"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57990",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 158,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57991",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.854Z",
      "date_published": "2026-07-03T20:35:21.276Z",
      "date_updated": "2026-08-03T22:53:43.031Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00745,
        "percentile": 0.51252
      },
      "nvd": {
        "published": "2026-07-03T21:17:02.180",
        "lastModified": "2026-07-07T12:43:02.303",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57991",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57991",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57992",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.855Z",
      "date_published": "2026-07-03T20:35:13.349Z",
      "date_updated": "2026-08-03T22:53:43.560Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00608,
        "percentile": 0.45698
      },
      "nvd": {
        "published": "2026-07-03T21:17:02.310",
        "lastModified": "2026-07-07T12:41:39.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57992",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge (Chromium-based) can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57992",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57993",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:45:44.855Z",
      "date_published": "2026-07-03T20:35:13.823Z",
      "date_updated": "2026-08-03T22:58:11.144Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00626,
        "percentile": 0.46555
      },
      "nvd": {
        "published": "2026-07-03T21:17:02.443",
        "lastModified": "2026-07-06T19:23:34.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-57993",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The server accepts an attacker-controlled destination without constraining the resolved request target to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57993",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 137,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-57994",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:58:05.796Z",
      "date_published": "2026-07-10T13:58:00.962Z",
      "date_updated": "2026-07-10T14:55:58.886Z",
      "publisher": "VulnCheck",
      "title": "phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endpoints",
      "affected": {
        "vendors": [
          "phpMyFAQ"
        ],
        "products": [
          {
            "vendor": "phpMyFAQ",
            "product": "phpMyFAQ"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00214,
        "percentile": 0.1188
      },
      "nvd": {
        "published": "2026-07-10T15:16:47.850",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57994",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Public FAQ API routes omit the active and publication-date predicates before returning draft content.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-mf8r-wm2w-f8c5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/phpmyfaq-information-disclosure-of-inactive-faq-content-via-public-api-endpoints",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 469,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-57996",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-26T17:58:05.796Z",
      "date_published": "2026-07-15T11:25:33.496Z",
      "date_updated": "2026-07-16T15:16:54.873Z",
      "publisher": "VulnCheck",
      "title": "phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add Endpoint",
      "affected": {
        "vendors": [
          "phpMyFAQ"
        ],
        "products": [
          {
            "vendor": "phpMyFAQ",
            "product": "phpMyFAQ"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15894
      },
      "nvd": {
        "published": "2026-07-15T12:18:16.143",
        "lastModified": "2026-07-16T16:19:14.350",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-57996",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The user-add endpoint accepts isSuperAdmin from a delegated administrator without enforcing the separate SuperAdmin guard.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-r2f4-v277-hvw9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/phpmyfaq-privilege-escalation-via-missing-superadmin-guard-in-user-add-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58023",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T11:41:12.546Z",
      "date_published": "2026-07-27T11:12:40.875Z",
      "date_updated": "2026-07-27T13:07:33.262Z",
      "publisher": "apache",
      "title": "Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 2.1999999999999993,
      "epss": {
        "score": 0.01083,
        "percentile": 0.61916
      },
      "nvd": {
        "published": "2026-07-27T12:16:46.547",
        "lastModified": "2026-07-27T19:51:16.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58023",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The c_glib transport leftover-bytes path reads beyond the end of a heap allocation.",
        "basis": [
          "CNA record",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/z2myopbovxngfvchdz8hddots9p5ffbt",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/43",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58024",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:37.577Z",
      "date_published": "2026-07-01T14:34:47.214Z",
      "date_updated": "2026-07-01T15:47:10.351Z",
      "publisher": "wikimedia-foundation",
      "title": "API identification of users on private wikis",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "MediaWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20362
      },
      "nvd": {
        "published": "2026-07-01T16:16:49.583",
        "lastModified": "2026-07-09T16:15:50.727",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58024",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record associates MediaWiki with sensitive output exposure but does not identify the disclosed field, output path, or missing disclosure check.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T422085",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58025",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:37.577Z",
      "date_published": "2026-07-01T15:23:29.787Z",
      "date_updated": "2026-07-01T15:51:56.096Z",
      "publisher": "wikimedia-foundation",
      "title": "Remote Code Execution via Unsafe Deserialization in LogItem Import",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "MediaWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 3.9000000000000004,
      "epss": {
        "score": 0.00325,
        "percentile": 0.24959
      },
      "nvd": {
        "published": "2026-07-01T16:16:49.703",
        "lastModified": "2026-07-09T19:34:14.067",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58025",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MediaWiki deserializes untrusted import or logging data into PHP object state.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T422244",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 318,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58026",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:37.577Z",
      "date_published": "2026-07-01T15:10:34.559Z",
      "date_updated": "2026-07-01T15:50:17.256Z",
      "publisher": "wikimedia-foundation",
      "title": "$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "MediaWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 5.7,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14195
      },
      "nvd": {
        "published": "2026-07-01T16:16:49.820",
        "lastModified": "2026-07-09T19:34:47.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58026",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MediaWiki applies the non-includable namespace rule to a redirect wrapper but not to the redirect target embedded from another namespace.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T299359",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58027",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:37.577Z",
      "date_published": "2026-07-01T15:01:00.948Z",
      "date_updated": "2026-07-01T15:49:32.627Z",
      "publisher": "wikimedia-foundation",
      "title": "QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "AbuseFilter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14329
      },
      "nvd": {
        "published": "2026-07-01T16:16:49.947",
        "lastModified": "2026-07-09T19:35:02.897",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58027",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "QueryAbuseFilter returns hit counts for private filters without applying the UI's private-filter visibility rule.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T406954",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 280,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58028",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:37.577Z",
      "date_published": "2026-07-01T15:15:17.250Z",
      "date_updated": "2026-07-01T15:50:39.761Z",
      "publisher": "wikimedia-foundation",
      "title": "Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "MediaWiki"
          },
          {
            "vendor": "Wikimedia Foundation",
            "product": "CentralAuth"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 5.4,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06733
      },
      "nvd": {
        "published": "2026-07-01T16:16:50.077",
        "lastModified": "2026-07-09T19:37:07.557",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58028",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MediaWiki's pretty-printed API path combines centralauthtoken-influenced data with gadget output without sufficient browser-context neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T422306",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 568,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58029",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:37.577Z",
      "date_published": "2026-07-01T15:19:11.810Z",
      "date_updated": "2026-07-01T15:51:32.133Z",
      "publisher": "wikimedia-foundation",
      "title": "Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "MediaWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12759
      },
      "nvd": {
        "published": "2026-07-01T16:16:50.197",
        "lastModified": "2026-07-09T19:37:39.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58029",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "MediaWiki account-management APIs can lead to account takeover, but the record lists files and impact without disclosing the identity transition or failing authentication check.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T422676",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 394,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58030",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:37.577Z",
      "date_published": "2026-07-01T14:58:19.707Z",
      "date_updated": "2026-07-01T15:48:58.797Z",
      "publisher": "wikimedia-foundation",
      "title": "SyntaxHighlight stored XSS via unsanitized 'linelinks' attribute",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "SyntaxHighlight_GeSHi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06896
      },
      "nvd": {
        "published": "2026-07-01T16:16:50.310",
        "lastModified": "2026-07-09T19:38:01.093",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58030",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker input enters an interpreted context without safe parameterization or output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T427167",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 327,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58031",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:37.577Z",
      "date_published": "2026-07-01T14:24:21.084Z",
      "date_updated": "2026-07-01T14:45:46.186Z",
      "publisher": "wikimedia-foundation",
      "title": "Stored i18n XSS in Special:ApiSandbox when a deprecated module is selected",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "MediaWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 5.4,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05392
      },
      "nvd": {
        "published": "2026-07-01T15:17:11.020",
        "lastModified": "2026-07-09T17:21:35.417",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58031",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MediaWiki rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T426889",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 323,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58032",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:37.577Z",
      "date_published": "2026-07-01T14:56:27.223Z",
      "date_updated": "2026-07-01T15:48:38.393Z",
      "publisher": "wikimedia-foundation",
      "title": "mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "MediaWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00191,
        "percentile": 0.09032
      },
      "nvd": {
        "published": "2026-07-01T16:16:50.520",
        "lastModified": "2026-07-09T19:42:23.293",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58032",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MediaWiki renders attacker-controlled content as executable browser markup without the required context separation.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T426867",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58033",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:37.577Z",
      "date_published": "2026-07-01T14:54:15.263Z",
      "date_updated": "2026-07-01T15:48:16.722Z",
      "publisher": "wikimedia-foundation",
      "title": "\"Total number of distinct authors\" statistic at action=info does not exclude revisions where the author name was deleted",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "MediaWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17012
      },
      "nvd": {
        "published": "2026-07-01T16:16:50.627",
        "lastModified": "2026-07-09T19:42:39.933",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58033",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "MediaWiki InfoAction exposes protected information to an unauthorized reader, while the public record does not identify the field, response path, or missing permission check.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T427235",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58034",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:41.613Z",
      "date_published": "2026-07-01T14:21:04.398Z",
      "date_updated": "2026-07-01T14:46:05.002Z",
      "publisher": "wikimedia-foundation",
      "title": "Stored XSS through a system message when blocking a temporary account that's related to other temporary accounts",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "CheckUser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 4.8,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06516
      },
      "nvd": {
        "published": "2026-07-01T15:17:11.150",
        "lastModified": "2026-07-09T17:20:38.083",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58034",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MediaWiki CheckUser renders attacker-controlled input as active HTML or script without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T428820",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58035",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:41.613Z",
      "date_published": "2026-07-01T14:17:41.643Z",
      "date_updated": "2026-07-01T14:54:43.230Z",
      "publisher": "wikimedia-foundation",
      "title": "Stored XSS through a system message in the codex version of Special:Block",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "MediaWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 4.8,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06515
      },
      "nvd": {
        "published": "2026-07-01T15:17:11.263",
        "lastModified": "2026-07-09T16:02:02.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58035",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T428809",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58036",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:41.613Z",
      "date_published": "2026-07-01T14:48:07.691Z",
      "date_updated": "2026-07-01T15:47:29.719Z",
      "publisher": "wikimedia-foundation",
      "title": "Users API leaks whether privileged users have their user groups disabled for lack of 2FA",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "MediaWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 5.4,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15644
      },
      "nvd": {
        "published": "2026-07-01T16:16:50.950",
        "lastModified": "2026-07-09T19:46:01.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58036",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected interface returns, embeds or leaves protected information visible to an observer who is not entitled to receive it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T425406",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58037",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:41.613Z",
      "date_published": "2026-07-01T14:51:27.027Z",
      "date_updated": "2026-07-01T15:46:44.776Z",
      "publisher": "wikimedia-foundation",
      "title": "Core log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled input",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "MediaWiki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 6.1,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06562
      },
      "nvd": {
        "published": "2026-07-01T16:16:51.063",
        "lastModified": "2026-07-09T19:46:19.747",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58037",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T422995",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Permissions Required"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58038",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T13:32:41.613Z",
      "date_published": "2026-07-01T15:04:01.989Z",
      "date_updated": "2026-07-01T15:47:50.725Z",
      "publisher": "wikimedia-foundation",
      "title": "Stored XSS through javascript URLs in SVGs generated by EasyTimeline",
      "affected": {
        "vendors": [
          "Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "Wikimedia Foundation",
            "product": "timeline"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 0,
          "severity": "NONE",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 6.1,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06535
      },
      "nvd": {
        "published": "2026-07-01T16:16:51.173",
        "lastModified": "2026-07-09T19:46:55.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58038",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches timeline page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T427611",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58039",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T15:00:00.779Z",
      "date_published": "2026-07-31T00:18:49.050Z",
      "date_updated": "2026-07-31T16:01:49.630Z",
      "publisher": "hackerone",
      "title": "A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configu...",
      "affected": {
        "vendors": [
          "nodejs"
        ],
        "products": [
          {
            "vendor": "nodejs",
            "product": "node"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06599
      },
      "nvd": {
        "published": "2026-07-31T01:16:31.530",
        "lastModified": "2026-07-31T16:17:08.120",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58039",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "process.report writes to a caller-selected path without enforcing the Permission Model's --allow-fs-write containment rule.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nodejs.org/en/blog/vulnerability",
          "host": "nodejs.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58040",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T15:00:00.779Z",
      "date_published": "2026-07-30T06:02:49.942Z",
      "date_updated": "2026-07-30T12:50:20.213Z",
      "publisher": "hackerone",
      "title": "An incomplete fix has been identified in Node.",
      "affected": {
        "vendors": [
          "nodejs"
        ],
        "products": [
          {
            "vendor": "nodejs",
            "product": "node"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-297",
          "name": "Improper Validation of Certificate with Host Mismatch",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19337
      },
      "nvd": {
        "published": "2026-07-30T06:25:55.190",
        "lastModified": "2026-07-30T14:17:00.073",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58040",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Node.js reuses an HTTPS TLS session across identity policies without rechecking that the session certificate is valid for the new hostname.",
        "basis": [
          "CNA",
          "CWE-297"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nodejs.org/en/blog/vulnerability/july-2026-security-releases",
          "host": "nodejs.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58043",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T15:00:00.780Z",
      "date_published": "2026-07-30T06:02:50.095Z",
      "date_updated": "2026-07-31T03:55:48.673Z",
      "publisher": "hackerone",
      "title": "A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to...",
      "affected": {
        "vendors": [
          "nodejs"
        ],
        "products": [
          {
            "vendor": "nodejs",
            "product": "node"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03769
      },
      "nvd": {
        "published": "2026-07-30T06:25:55.310",
        "lastModified": "2026-07-31T04:17:23.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58043",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Permission Model compares filesystem grants across radix-tree prefix boundaries without a component boundary, so a granted path authorizes neighboring paths.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://nodejs.org/en/blog/vulnerability/july-2026-security-releases",
          "host": "nodejs.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58046",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T15:00:00.780Z",
      "date_published": "2026-07-30T06:02:50.017Z",
      "date_updated": "2026-07-30T12:38:20.183Z",
      "publisher": "hackerone",
      "title": "Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.",
      "affected": {
        "vendors": [
          "WebPros"
        ],
        "products": [
          {
            "vendor": "WebPros",
            "product": "Plesk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.2695
      },
      "nvd": {
        "published": "2026-07-30T06:25:55.430",
        "lastModified": "2026-07-30T13:16:53.260",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58046",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Plesk query path incorporates attacker-controlled input into SQL without parameter separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.plesk.com/hc/en-us/articles/42139500580119-Vulnerability-CVE-2026-58046-Blind-SQL-injection-in-Plesk-s-XML-RPC-API",
          "host": "support.plesk.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58047",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T15:00:00.780Z",
      "date_published": "2026-07-31T16:35:56.600Z",
      "date_updated": "2026-07-31T17:17:56.499Z",
      "publisher": "hackerone",
      "title": "HTTP Smuggling in cPanel allows potential leak of credentials.",
      "affected": {
        "vendors": [
          "WebPros"
        ],
        "products": [
          {
            "vendor": "WebPros",
            "product": "cPanel"
          },
          {
            "vendor": "WebPros",
            "product": "WP Squared"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00445,
        "percentile": 0.36542
      },
      "nvd": {
        "published": "2026-07-31T17:16:34.023",
        "lastModified": "2026-07-31T18:17:18.247",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58047",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "cPanel parses an HTTP request boundary differently from an upstream or downstream peer, permitting a smuggled request.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.cpanel.net/hc/en-us/articles/42285024734743-Security-CVE-2026-58047-HTTP-Request-Smuggling",
          "host": "support.cpanel.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://docs.cpanel.net/changelogs/138-change-log",
          "host": "docs.cpanel.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 62,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-58048",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-27T15:00:00.780Z",
      "date_published": "2026-07-31T16:35:56.665Z",
      "date_updated": "2026-08-01T03:56:21.794Z",
      "publisher": "hackerone",
      "title": "Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.",
      "affected": {
        "vendors": [
          "WebPros"
        ],
        "products": [
          {
            "vendor": "WebPros",
            "product": "cPanel"
          },
          {
            "vendor": "WebPros",
            "product": "WP Squared"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00503,
        "percentile": 0.40283
      },
      "nvd": {
        "published": "2026-07-31T17:16:34.190",
        "lastModified": "2026-08-01T05:16:57.057",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58048",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The database-rename workflow fails to preserve the SQL mode required for safe parsing when it later executes SQL with root authority.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.cpanel.net/hc/en-us/articles/42285745783703-CVE-2026-58048-Database-Privilege-Escalation",
          "host": "support.cpanel.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://docs.cpanel.net/changelogs/138-change-log",
          "host": "docs.cpanel.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-58065",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-28T14:39:59.245Z",
      "date_published": "2026-07-13T15:00:49.159Z",
      "date_updated": "2026-07-14T13:38:58.471Z",
      "publisher": "apache",
      "title": "Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow Git provider"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-322",
          "name": "Key Exchange without Entity Authentication",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00477,
        "percentile": 0.38706
      },
      "nvd": {
        "published": "2026-07-13T16:16:41.757",
        "lastModified": "2026-07-14T14:16:35.757",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58065",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache Airflow Git provider establishes an encrypted connection without validating the peer certificate or host key, allowing an active network attacker to substitute its own endpoint.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-322"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/airflow/pull/69103",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/fjmclngfksz2kp7llpcjxzdz568h0zhc",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/13/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 605,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58066",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-28T15:00:00.719Z",
      "date_published": "2026-07-30T06:03:45.178Z",
      "date_updated": "2026-07-31T03:55:47.931Z",
      "publisher": "hackerone",
      "title": "Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wr...",
      "affected": {
        "vendors": [
          "Rocket.Chat"
        ],
        "products": [
          {
            "vendor": "Rocket.Chat",
            "product": "Rocket.Chat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.0",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15699
      },
      "nvd": {
        "published": "2026-07-30T06:25:55.540",
        "lastModified": "2026-07-31T04:17:23.877",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58066",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Rocket.Chat verifies an XML signature without binding the verified node to the SAML Response or Assertion whose identity attributes it trusts.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://hackerone.com/reports/3827674",
          "host": "hackerone.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/RocketChat/Rocket.Chat/pull/41233",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-58077",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-28T18:39:37.301Z",
      "date_published": "2026-07-15T09:01:15.804Z",
      "date_updated": "2026-07-23T15:00:14.727Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2",
      "affected": {
        "vendors": [
          "weeblr.com"
        ],
        "products": [
          {
            "vendor": "weeblr.com",
            "product": "4Analytics extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00318,
        "percentile": 0.24181
      },
      "nvd": {
        "published": "2026-07-15T10:16:47.870",
        "lastModified": "2026-07-23T16:17:29.073",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58077",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "4Analytics extension for Joomla stores attacker-controlled content and later renders it without sufficient output escaping, allowing script execution in a visitor's browser.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://weeblr.com/joomla-seo/4analytics-private-analytics-for-joomla",
          "host": "weeblr.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58078",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-28T18:39:37.301Z",
      "date_published": "2026-07-16T08:14:15.183Z",
      "date_updated": "2026-07-23T14:54:58.873Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1",
      "affected": {
        "vendors": [
          "themexpert.com"
        ],
        "products": [
          {
            "vendor": "themexpert.com",
            "product": "Quix Page Builder Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14761
      },
      "nvd": {
        "published": "2026-07-16T09:16:19.140",
        "lastModified": "2026-07-23T16:17:29.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58078",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Quix Page Builder accepts unauthenticated input as SQL syntax instead of binding it as data.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.themexpert.com/quix-pagebuilder",
          "host": "www.themexpert.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/quix-sql-injection-disclosure/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58101",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T06:35:04.717Z",
      "date_published": "2026-07-13T22:17:48.375Z",
      "date_updated": "2026-07-14T12:45:11.194Z",
      "publisher": "CPANSec",
      "title": "Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference",
      "affected": {
        "vendors": [
          "JONASBN"
        ],
        "products": [
          {
            "vendor": "JONASBN",
            "product": "Crypt::OpenSSL::X509"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10575
      },
      "nvd": {
        "published": "2026-07-13T23:16:47.020",
        "lastModified": "2026-07-14T16:45:02.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58101",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crypt OpenSSL X509 dereferences null extension-parser results and a null key identifier from a malformed certificate.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dsully/perl-crypt-openssl-x509/commit/4c1e2370556097c253ae27abe9e1097ea377fbd2.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/release/JONASBN/Crypt-OpenSSL-X509-2.1.3/source/Changes.md",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 520,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58102",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T06:35:04.718Z",
      "date_published": "2026-07-13T22:22:48.618Z",
      "date_updated": "2026-07-14T13:03:15.979Z",
      "publisher": "CPANSec",
      "title": "Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts",
      "affected": {
        "vendors": [
          "JONASBN"
        ],
        "products": [
          {
            "vendor": "JONASBN",
            "product": "Crypt::OpenSSL::X509"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.1182
      },
      "nvd": {
        "published": "2026-07-13T23:16:47.127",
        "lastModified": "2026-07-14T16:45:02.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58102",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crypt::OpenSSL::X509 copies or indexes a long extension OID beyond the heap buffer allocated for it.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dsully/perl-crypt-openssl-x509/commit/757289bfce095455c104d4adfe9312e7b339620f.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/release/JONASBN/Crypt-OpenSSL-X509-2.1.3/source/Changes.md",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 661,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58122",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:13:18.384Z",
      "date_published": "2026-07-09T21:30:17.166Z",
      "date_updated": "2026-07-14T21:34:49.210Z",
      "publisher": "VulnCheck",
      "title": "Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing",
      "affected": {
        "vendors": [
          "nesquena"
        ],
        "products": [
          {
            "vendor": "nesquena",
            "product": "hermes-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-348",
          "name": "Use of Less Trusted Source",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21531
      },
      "nvd": {
        "published": "2026-07-09T22:17:09.363",
        "lastModified": "2026-07-14T22:17:26.557",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58122",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Hermes WebUI treats a caller-supplied X-Forwarded-For loopback value as proof of local origin and skips onboarding authentication.",
        "basis": [
          "CNA",
          "CWE-348"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nesquena/hermes-webui/releases/tag/v0.51.307",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/nesquena/hermes-webui/pull/3758",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nesquena/hermes-webui/commit/70596e6993be0d4cee083c1c1a86f5e7ad5d57b7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/hermes-webui-authentication-bypass-via-x-forwarded-for-header-spoofing",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58123",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:13:18.384Z",
      "date_published": "2026-07-09T21:14:06.078Z",
      "date_updated": "2026-07-14T21:34:49.899Z",
      "publisher": "VulnCheck",
      "title": "Hermes WebUI < 0.51.788 Unauthenticated RCE via Terminal API",
      "affected": {
        "vendors": [
          "nesquena"
        ],
        "products": [
          {
            "vendor": "nesquena",
            "product": "hermes-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00928,
        "percentile": 0.57064
      },
      "nvd": {
        "published": "2026-07-09T22:17:09.517",
        "lastModified": "2026-07-14T22:17:26.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58123",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without credentials.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nesquena/hermes-webui/releases/tag/v0.51.788",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/nesquena/hermes-webui/pull/5268",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nesquena/hermes-webui/commit/d257e5f36cfa9328600c8bde6f0de09a6ad9b6f4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/hermes-webui-unauthenticated-rce-via-terminal-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 456,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58126",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:13:18.384Z",
      "date_published": "2026-07-01T14:39:01.640Z",
      "date_updated": "2026-07-01T16:06:12.873Z",
      "publisher": "VulnCheck",
      "title": "PACSgear PACS Scan 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service",
      "affected": {
        "vendors": [
          "Hyland"
        ],
        "products": [
          {
            "vendor": "Hyland",
            "product": "PACSgear PACS Scan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.01205,
        "percentile": 0.65285
      },
      "nvd": {
        "published": "2026-07-01T16:16:51.283",
        "lastModified": "2026-07-09T02:38:07.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58126",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unauthenticated .NET Remoting service exposes arbitrary file writes that can plant a DLL loaded by the privileged service after restart.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/VAMorales/6dc232729cdd517fa30d581fbcd98d8f",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.hyland.com/en/solutions/products/pacsgear",
          "host": "www.hyland.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/pacsgear-pacs-scan-unauthenticated-rce-via-net-remoting-tcp-service",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58127",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:13:18.384Z",
      "date_published": "2026-07-01T14:41:04.970Z",
      "date_updated": "2026-07-01T17:25:29.591Z",
      "publisher": "VulnCheck",
      "title": "PACSgear MediaWriter 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service",
      "affected": {
        "vendors": [
          "Hyland"
        ],
        "products": [
          {
            "vendor": "Hyland",
            "product": "PACSgear MediaWriter"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.01271,
        "percentile": 0.66978
      },
      "nvd": {
        "published": "2026-07-01T16:16:51.417",
        "lastModified": "2026-07-09T02:37:28.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58127",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A .NET Remoting service listens on a fixed TCP port with stable object URIs and no authentication, exposing file read and write methods to remote callers.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/VAMorales/dc679ecab30b7045fa07bf3249a034d8",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.hyland.com/en/solutions/products/pacsgear",
          "host": "www.hyland.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/pacsgear-mediawriter-unauthenticated-rce-via-net-remoting-tcp-service",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 774,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:13:18.385Z",
      "date_published": "2026-07-09T22:04:22.946Z",
      "date_updated": "2026-07-14T21:34:51.284Z",
      "publisher": "VulnCheck",
      "title": "Cotonti Siena 0.9.26 CSRF via admin.php Config Update Endpoint",
      "affected": {
        "vendors": [
          "Cotonti"
        ],
        "products": [
          {
            "vendor": "Cotonti",
            "product": "Cotonti"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07141
      },
      "nvd": {
        "published": "2026-07-09T22:17:09.663",
        "lastModified": "2026-07-14T22:17:26.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58143",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A state-changing browser request is accepted without a valid origin-bound anti-forgery check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/sermikr0/75686815e441c07462cfdea2fed5d305",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cotonti-siena-csrf-via-admin-php-config-update-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 525,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:13:18.385Z",
      "date_published": "2026-07-09T22:07:11.370Z",
      "date_updated": "2026-07-14T21:34:51.965Z",
      "publisher": "VulnCheck",
      "title": "Cotonti Siena 0.9.26 Stored XSS via PFS Module ntitle Parameter",
      "affected": {
        "vendors": [
          "Cotonti"
        ],
        "products": [
          {
            "vendor": "Cotonti",
            "product": "Cotonti"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03455
      },
      "nvd": {
        "published": "2026-07-09T22:17:09.817",
        "lastModified": "2026-07-14T22:17:27.043",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58144",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Cotonti page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/sermikr0/75686815e441c07462cfdea2fed5d305",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 482,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58148",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:35:29.745Z",
      "date_published": "2026-07-17T15:48:37.359Z",
      "date_updated": "2026-07-23T15:01:28.668Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52",
      "affected": {
        "vendors": [
          "chronoengine.com"
        ],
        "products": [
          {
            "vendor": "chronoengine.com",
            "product": "ChronoForms extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00318,
        "percentile": 0.2418
      },
      "nvd": {
        "published": "2026-07-17T16:17:15.897",
        "lastModified": "2026-07-23T16:17:29.297",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58148",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ChronoForms stores unauthenticated input and later renders it as executable browser content.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.chronoengine.com/",
          "host": "www.chronoengine.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58149",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T14:35:29.745Z",
      "date_published": "2026-07-17T15:45:07.385Z",
      "date_updated": "2026-07-23T14:56:50.809Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0",
      "affected": {
        "vendors": [
          "joomdonation.com"
        ],
        "products": [
          {
            "vendor": "joomdonation.com",
            "product": "Events Booking extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.1084
      },
      "nvd": {
        "published": "2026-07-17T16:17:16.017",
        "lastModified": "2026-07-23T16:17:29.410",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58149",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unauthenticated response reveals whether supplied usernames and email addresses exist.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://joomdonation.com/joomla-extensions/events-booking-joomla-events-registration.html",
          "host": "joomdonation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58150",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:31:25.334Z",
      "date_published": "2026-07-29T07:30:25.800Z",
      "date_updated": "2026-07-30T03:55:15.616Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24007
      },
      "nvd": {
        "published": "2026-07-29T08:16:31.710",
        "lastModified": "2026-08-03T13:42:21.757",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58150",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Traffic Server accepts Transfer-Encoding on HTTP/2 and its downgrade path interprets the request boundary differently from the upstream protocol.",
        "basis": [
          "CNA record",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58151",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:32:29.686Z",
      "date_published": "2026-07-29T08:15:45.681Z",
      "date_updated": "2026-07-29T13:17:53.932Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the server",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00474,
        "percentile": 0.38512
      },
      "nvd": {
        "published": "2026-07-29T09:16:29.327",
        "lastModified": "2026-08-03T13:42:15.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58151",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Abusive HTTP/2 framing and flow-control can drive Apache Traffic Server into unbounded work or allocation until it crashes.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58152",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:33:14.929Z",
      "date_published": "2026-07-29T08:16:21.178Z",
      "date_updated": "2026-07-29T13:28:57.938Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrupt memory",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24778
      },
      "nvd": {
        "published": "2026-07-29T09:16:29.480",
        "lastModified": "2026-08-03T13:42:08.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58152",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Traffic Server mishandles an integer while decoding HPACK or XPACK headers and corrupts memory.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58153",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:34:03.148Z",
      "date_published": "2026-07-29T08:17:11.785Z",
      "date_updated": "2026-07-29T13:29:30.157Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 2.000000000000001,
      "epss": {
        "score": 0.00472,
        "percentile": 0.38345
      },
      "nvd": {
        "published": "2026-07-29T09:16:29.613",
        "lastModified": "2026-08-03T13:41:54.987",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58153",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Traffic Server converts HTTP/2 trailers to HTTP/1 without the chunked framing required for the downstream client to preserve message boundaries.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 291,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58154",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:34:55.761Z",
      "date_published": "2026-07-29T08:24:02.078Z",
      "date_updated": "2026-07-29T12:19:51.923Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Memory-safety errors in MIME and header parsing",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0.29999999999999893,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29989
      },
      "nvd": {
        "published": "2026-07-29T09:16:29.743",
        "lastModified": "2026-08-03T13:40:26.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58154",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser can write beyond the destination allocation because the computed length or boundary is not enforced.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58155",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:45:54.687Z",
      "date_published": "2026-07-29T08:24:37.320Z",
      "date_updated": "2026-07-29T12:19:05.151Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31368
      },
      "nvd": {
        "published": "2026-07-29T09:16:29.877",
        "lastModified": "2026-08-03T13:40:19.433",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58155",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Traffic Server truncates overlong header names, causing distinct client header names to alias and be interpreted differently by downstream policy or request parsers.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 327,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58156",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:46:44.742Z",
      "date_published": "2026-07-29T08:25:12.013Z",
      "date_updated": "2026-07-29T12:17:15.486Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: URL and port parsing errors allow access-control bypass",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12836
      },
      "nvd": {
        "published": "2026-07-29T09:16:30.023",
        "lastModified": "2026-08-03T13:40:10.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58156",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Apache Traffic Server parses URL ports differently across URL and userinfo forms, so an access-control decision can evaluate a different port from the request path it forwards.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58157",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:47:23.719Z",
      "date_published": "2026-07-29T08:25:52.434Z",
      "date_updated": "2026-07-30T03:55:14.728Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Improper server-session reuse can expose data across client connections",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.799999999999999,
      "epss": {
        "score": 0.00452,
        "percentile": 0.37086
      },
      "nvd": {
        "published": "2026-07-29T10:16:41.173",
        "lastModified": "2026-08-03T19:50:55.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58157",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Server-session and tunnel state is reused across clients, allowing one client's data to appear in another client's sequence.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:48:04.596Z",
      "date_published": "2026-07-29T08:26:32.138Z",
      "date_updated": "2026-07-29T12:15:33.223Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: PROXY protocol parsing has port truncation and a stack overflow",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.0056,
        "percentile": 0.43413
      },
      "nvd": {
        "published": "2026-07-29T10:16:41.347",
        "lastModified": "2026-08-03T19:38:13.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58158",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Apache Traffic Server parser or handler can copy attacker-controlled data beyond the bounds of a stack allocation.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58159",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:48:48.053Z",
      "date_published": "2026-07-29T08:32:04.660Z",
      "date_updated": "2026-07-29T12:15:11.832Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Listener and ACL handling allow access-control bypass",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00525,
        "percentile": 0.41566
      },
      "nvd": {
        "published": "2026-07-29T10:16:41.490",
        "lastModified": "2026-08-03T19:36:49.213",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58159",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Apache Traffic Server applies an IP access rule to the listener rather than the Unix-domain-socket peer that performs the request.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 309,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58160",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:49:51.058Z",
      "date_published": "2026-07-29T08:34:34.990Z",
      "date_updated": "2026-07-29T12:14:46.499Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Out-of-bounds reads while parsing DNS responses",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00552,
        "percentile": 0.43025
      },
      "nvd": {
        "published": "2026-07-29T10:16:41.637",
        "lastModified": "2026-08-03T19:36:23.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58160",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Apache Traffic Server, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58161",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:50:27.621Z",
      "date_published": "2026-07-29T08:35:39.379Z",
      "date_updated": "2026-07-29T13:17:07.852Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.00636,
        "percentile": 0.46991
      },
      "nvd": {
        "published": "2026-07-29T10:16:41.780",
        "lastModified": "2026-08-03T19:35:56.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58161",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache Traffic Server retains null or dangling references while handling TLS and SNI state.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58162",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:51:05.609Z",
      "date_published": "2026-07-29T08:36:17.272Z",
      "date_updated": "2026-07-29T13:41:05.355Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25771
      },
      "nvd": {
        "published": "2026-07-29T10:16:41.927",
        "lastModified": "2026-08-03T19:35:27.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58162",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Traffic Server certifier treats attacker-controlled SNI as sufficient authority to choose the name for a newly generated certificate.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 314,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58163",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:51:48.436Z",
      "date_published": "2026-07-29T08:36:57.160Z",
      "date_updated": "2026-07-29T13:40:44.563Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Cache deserialization and lifetime errors can corrupt state or crash the server",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00652,
        "percentile": 0.4771
      },
      "nvd": {
        "published": "2026-07-29T10:16:42.073",
        "lastModified": "2026-08-03T19:34:28.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58163",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apache Traffic Server groups malformed on-disk cache fields with object-lifetime errors, and the official advisory does not isolate one deserialization check or lifetime transition.",
        "basis": [
          "CNA",
          "CWE-502",
          "Apache Traffic Server security advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d through the official lists.apache.org thread API. It confirms cache deserialization plus lifetime errors and fixes 9.2.15/10.1.4, but groups multiple faults without a specific field, function, or lifetime transition."
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 313,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58164",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T15:52:27.090Z",
      "date_published": "2026-07-29T08:37:42.478Z",
      "date_updated": "2026-07-29T13:39:55.405Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-free",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00636,
        "percentile": 0.46991
      },
      "nvd": {
        "published": "2026-07-29T10:16:42.217",
        "lastModified": "2026-08-03T19:32:31.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58164",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Traffic Server remap configuration handling has a check/use and object-lifetime window that permits a configuration object to be used after release.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 318,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58175",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:23:38.554Z",
      "date_published": "2026-07-29T08:41:50.764Z",
      "date_updated": "2026-07-29T13:39:21.198Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: HostDB SRV handling leaks memory",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00636,
        "percentile": 0.4699
      },
      "nvd": {
        "published": "2026-07-29T10:16:42.360",
        "lastModified": "2026-07-31T20:55:06.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58175",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache Traffic Server fails to release memory after the corresponding operation completes, allowing repeated use to exhaust memory.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58177",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:24:10.975Z",
      "date_published": "2026-07-29T08:42:41.254Z",
      "date_updated": "2026-07-29T13:33:06.611Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts framework",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00547,
        "percentile": 0.42772
      },
      "nvd": {
        "published": "2026-07-29T10:16:42.510",
        "lastModified": "2026-07-31T20:54:52.427",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58177",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Cripts framework contains bundled out-of-bounds-write, use-after-free, and path-selection defects, with memory safety as the primary reported failure family.",
        "basis": [
          "CNA",
          "CWE-787",
          "Apache vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d through the official Apache archive API; the vendor advisory confirms bundled memory-safety and path-traversal errors but does not separate their individual patches, and no reproduction was performed."
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 256,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58178",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:24:49.430Z",
      "date_published": "2026-07-29T08:43:25.421Z",
      "date_updated": "2026-07-29T13:30:21.898Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgery",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00636,
        "percentile": 0.4699
      },
      "nvd": {
        "published": "2026-07-29T10:16:42.657",
        "lastModified": "2026-07-31T20:54:14.823",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58178",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Traffic Server ESI plugin follows nested inclusions without a recursion bound, allowing attacker-controlled URLs to exhaust work or stack space.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58179",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:25:24.383Z",
      "date_published": "2026-07-29T08:44:33.338Z",
      "date_updated": "2026-07-30T03:55:13.976Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: regex_remap plugin overflows the stack from attacker input",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00554,
        "percentile": 0.4315
      },
      "nvd": {
        "published": "2026-07-29T10:16:42.803",
        "lastModified": "2026-07-31T20:54:05.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58179",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The regex_remap plugin permits attacker-controlled substitution processing to overflow stack storage and related integer bounds.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 310,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58180",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:26:04.850Z",
      "date_published": "2026-07-29T08:45:15.088Z",
      "date_updated": "2026-07-29T13:30:48.275Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: txn_box plugin overflows the stack from attacker input",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00636,
        "percentile": 0.46991
      },
      "nvd": {
        "published": "2026-07-29T10:16:42.947",
        "lastModified": "2026-07-31T20:53:48.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58180",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Apache Traffic Server path copies attacker-influenced data beyond a fixed-size stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 300,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58181",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:26:44.061Z",
      "date_published": "2026-07-29T08:46:04.829Z",
      "date_updated": "2026-07-29T12:17:46.752Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00492,
        "percentile": 0.39624
      },
      "nvd": {
        "published": "2026-07-29T10:16:43.087",
        "lastModified": "2026-07-31T20:53:33.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58181",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The uri_signing and url_sig plugins let attacker input consume the process stack without an effective depth bound.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58182",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:27:23.942Z",
      "date_published": "2026-07-29T08:54:49.308Z",
      "date_updated": "2026-07-29T12:14:25.368Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00542,
        "percentile": 0.42522
      },
      "nvd": {
        "published": "2026-07-29T10:16:43.230",
        "lastModified": "2026-07-31T20:53:21.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58182",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected path in Apache Traffic Server accepts or retains attacker-controlled work or memory without an effective upper bound or release condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 317,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:28:06.552Z",
      "date_published": "2026-07-29T08:55:52.927Z",
      "date_updated": "2026-07-29T12:13:54.210Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: prefetch plugin can crash on attacker-influenced input",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.00512,
        "percentile": 0.40836
      },
      "nvd": {
        "published": "2026-07-29T10:16:43.373",
        "lastModified": "2026-07-31T20:53:07.187",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58183",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apache Traffic Server accepts a specifically malformed value or unsupported operation without the validation required by that interface, driving the component into an unsafe condition outside the other mechanism families.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:28:43.256Z",
      "date_published": "2026-07-29T08:56:51.696Z",
      "date_updated": "2026-07-29T12:13:32.044Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00457,
        "percentile": 0.3743
      },
      "nvd": {
        "published": "2026-07-29T10:16:43.520",
        "lastModified": "2026-07-31T20:52:52.623",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58184",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Traffic Server header_rewrite plugin writes beyond valid memory during cookie or CIDR processing.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58185",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:29:26.190Z",
      "date_published": "2026-07-29T08:57:48.774Z",
      "date_updated": "2026-07-29T12:13:02.420Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Use-after-free in the intercept plugin",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 3.9000000000000004,
      "epss": {
        "score": 0.00446,
        "percentile": 0.36662
      },
      "nvd": {
        "published": "2026-07-29T10:16:43.663",
        "lastModified": "2026-07-31T20:52:12.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58185",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache Traffic Server continues to access an object after its storage has been released, allowing invalid heap use and possible corruption.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58186",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:35:07.500Z",
      "date_published": "2026-07-29T09:01:39.548Z",
      "date_updated": "2026-07-29T12:11:57.125Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responses",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00545,
        "percentile": 0.42688
      },
      "nvd": {
        "published": "2026-07-29T10:16:43.807",
        "lastModified": "2026-07-31T20:51:59.187",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58186",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public advisory says webp_transform decodes unsafely and mislabels cacheable responses but does not identify the parser failure or state rule.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 318,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:35:39.110Z",
      "date_published": "2026-07-29T09:03:22.659Z",
      "date_updated": "2026-07-29T12:11:35.420Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of service",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37112
      },
      "nvd": {
        "published": "2026-07-29T10:16:43.950",
        "lastModified": "2026-07-31T20:51:17.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58187",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Traffic Server multiplexer chunk decoder writes beyond its upstream decode buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 332,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:36:12.204Z",
      "date_published": "2026-07-29T09:04:24.836Z",
      "date_updated": "2026-07-29T12:11:13.386Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00598,
        "percentile": 0.45276
      },
      "nvd": {
        "published": "2026-07-29T10:16:44.093",
        "lastModified": "2026-08-03T13:39:15.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58188",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Several Apache Traffic Server experimental plugins contain memory-safety failures, but the shared record does not identify one primary bounds or lifetime transition.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58189",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T16:36:42.316Z",
      "date_published": "2026-07-29T09:05:19.468Z",
      "date_updated": "2026-07-29T12:10:43.244Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amplification",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00487,
        "percentile": 0.39335
      },
      "nvd": {
        "published": "2026-07-29T10:16:44.243",
        "lastModified": "2026-08-03T13:38:49.833",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58189",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Traffic Server plugins can reset the redirect counter, defeating the redirect limit and extending server-side requests to attacker-chosen destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:09:25.871Z",
      "date_published": "2026-07-08T20:57:43.237Z",
      "date_updated": "2026-07-09T14:40:38.011Z",
      "publisher": "GitHub_M",
      "title": "Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes",
      "affected": {
        "vendors": [
          "appium"
        ],
        "products": [
          {
            "vendor": "appium",
            "product": "appium"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-489",
          "name": "Active Debug Code",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16634
      },
      "nvd": {
        "published": "2026-07-08T21:16:52.013",
        "lastModified": "2026-07-15T20:31:32.807",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58191",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 10.7.0, Appium's base-driver unconditionally mounts the /test/guinea-pig, /test/guinea-pig-scrollable, and /test/guinea-pig-app-banner routes, and compileLodashTemplate reflects the throwError query parameter, comments POST field, and User-Agent request header into HTML without escaping, allowing reflected cross-site scripting and arbitrary JavaScript execution on the server origin.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-489"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/appium/appium/security/advisories/GHSA-3wgp-x9p5-c7cc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:09:25.871Z",
      "date_published": "2026-07-08T20:56:30.810Z",
      "date_updated": "2026-07-09T14:12:23.522Z",
      "publisher": "GitHub_M",
      "title": "Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin",
      "affected": {
        "vendors": [
          "appium"
        ],
        "products": [
          {
            "vendor": "appium",
            "product": "appium"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27106
      },
      "nvd": {
        "published": "2026-07-08T21:16:52.150",
        "lastModified": "2026-07-10T17:49:57.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58192",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The delete endpoint joins an untrusted name to its storage root and recursively removes the result without proving containment.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/appium/appium/security/advisories/GHSA-jwgx-mp9m-jwcr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/appium/appium/pull/22362",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/appium/appium/commit/5fee01752f2782e96fbe64fd13520b433d4a7535",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/appium/appium/releases/tag/%40appium/storage-plugin%401.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58195",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:09:25.871Z",
      "date_published": "2026-07-17T18:47:05.179Z",
      "date_updated": "2026-07-17T19:19:01.284Z",
      "publisher": "GitHub_M",
      "title": "Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync",
      "affected": {
        "vendors": [
          "ruvnet"
        ],
        "products": [
          {
            "vendor": "ruvnet",
            "product": "agentic-flow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00456,
        "percentile": 0.37375
      },
      "nvd": {
        "published": "2026-07-17T19:17:17.410",
        "lastModified": "2026-07-23T16:04:11.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58195",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MCP tool parameters are interpolated into strings passed to execSync(), allowing shell syntax in those parameters to execute as the server user.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ruvnet/agentic-flow/security/advisories/GHSA-vcv2-r9jh-99m5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ruvnet/agentic-flow/issues/169",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ruvnet/ruflo/issues/2414",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ruvnet/agentic-flow/pull/170",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ruvnet/ruflo/pull/2415",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ruvnet/agentic-flow/commit/0c2ec967736a8b6b85832c6bae2a3e74989705ec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ruvnet/ruflo/releases/tag/v3.12.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 765,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58198",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:09:25.872Z",
      "date_published": "2026-07-09T18:32:16.074Z",
      "date_updated": "2026-07-09T19:12:29.625Z",
      "publisher": "GitHub_M",
      "title": "ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer",
      "affected": {
        "vendors": [
          "gunthercox"
        ],
        "products": [
          {
            "vendor": "gunthercox",
            "product": "ChatterBot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00095,
        "percentile": 0.00791
      },
      "nvd": {
        "published": "2026-07-09T19:17:06.933",
        "lastModified": "2026-07-09T20:16:30.030",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58198",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The trainer checks and then creates a predictable extraction directory, allowing a pre-planted symlink to redirect subsequent archive writes.",
        "basis": [
          "CNA",
          "CWE-367",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gunthercox/ChatterBot/security/advisories/GHSA-wvrh-2f4m-924v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gunthercox/ChatterBot/pull/2445",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gunthercox/ChatterBot/commit/82817b5c28bfd43e682b991bcc76e6f780726dbf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gunthercox/ChatterBot/releases/tag/1.2.14",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58203",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:09:25.872Z",
      "date_published": "2026-07-06T14:24:15.740Z",
      "date_updated": "2026-07-06T16:19:59.090Z",
      "publisher": "GitHub_M",
      "title": "NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size",
      "affected": {
        "vendors": [
          "pydantic"
        ],
        "products": [
          {
            "vendor": "pydantic",
            "product": "pydantic-settings"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07698
      },
      "nvd": {
        "published": "2026-07-06T16:16:35.590",
        "lastModified": "2026-07-27T17:37:56.730",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58203",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NestedSecretsSettingsSource follows a directory symlink outside secrets_dir and reads the selected external files into settings values.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-59",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pydantic/pydantic-settings/security/advisories/GHSA-4xgf-cpjx-pc3j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 766,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58207",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:09:25.872Z",
      "date_published": "2026-07-08T20:15:31.082Z",
      "date_updated": "2026-07-09T14:41:02.162Z",
      "publisher": "GitHub_M",
      "title": "NATS Server: Remote crash via integer overflow in Connz pagination",
      "affected": {
        "vendors": [
          "nats-io"
        ],
        "products": [
          {
            "vendor": "nats-io",
            "product": "nats-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00397,
        "percentile": 0.32497
      },
      "nvd": {
        "published": "2026-07-08T21:16:52.293",
        "lastModified": "2026-07-09T19:13:49.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58207",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Connz pagination adds attacker-controlled Offset and Limit values before bounding the window, allowing integer overflow.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-q59r-vq66-pxc2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/2ae047139e37a38cb01e259a67909e7a39fa38e9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/894d9411927681d66ce349bf1afe49608dc0c1a3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.12.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.14.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58208",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:09:25.872Z",
      "date_published": "2026-07-08T20:17:39.187Z",
      "date_updated": "2026-07-09T14:04:28.045Z",
      "publisher": "GitHub_M",
      "title": "NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled",
      "affected": {
        "vendors": [
          "nats-io"
        ],
        "products": [
          {
            "vendor": "nats-io",
            "product": "nats-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26236
      },
      "nvd": {
        "published": "2026-07-08T21:16:52.440",
        "lastModified": "2026-07-09T19:08:52.507",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58208",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A WebSocket path enters the MQTT handler before MQTT state has been initialized.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-p957-7v2w-g93g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/73b3dd9a5ea0fa7bf08b702338676355b29b5fb4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/837536b98b3a9280b993282155ff2bdd3ca38c30",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.12.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.14.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 444,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58209",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:09:25.872Z",
      "date_published": "2026-07-08T20:12:11.240Z",
      "date_updated": "2026-07-09T13:31:07.445Z",
      "publisher": "GitHub_M",
      "title": "NATS Server: MQTT retained and QoS replay bypass subscribe deny filters",
      "affected": {
        "vendors": [
          "nats-io"
        ],
        "products": [
          {
            "vendor": "nats-io",
            "product": "nats-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16511
      },
      "nvd": {
        "published": "2026-07-08T20:16:53.800",
        "lastModified": "2026-07-13T14:15:23.213",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58209",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MQTT retained and durable replay paths send a concrete topic without rechecking the subscriber's deny rule for that topic.",
        "basis": [
          "CNA record",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-7qmq-8cc4-hxwg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/181b1f51f40b9954c57e9d478e051fb257679356",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/1c429b6fdc5afd4188cc5faf1127f6334896cd87",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.12.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.14.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58210",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:09:25.872Z",
      "date_published": "2026-07-08T20:13:37.082Z",
      "date_updated": "2026-07-09T13:29:36.341Z",
      "publisher": "GitHub_M",
      "title": "NATS Server: MQTT partial CONNECT packets can exhaust pre-auth memory",
      "affected": {
        "vendors": [
          "nats-io"
        ],
        "products": [
          {
            "vendor": "nats-io",
            "product": "nats-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00505,
        "percentile": 0.40384
      },
      "nvd": {
        "published": "2026-07-08T20:16:53.950",
        "lastModified": "2026-07-13T15:14:12.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58210",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "NATS retains an attacker-declared incomplete MQTT CONNECT packet before authentication with no effective per-connection memory bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-r72h-j7qq-v6qg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/bce9ef39469e610aeddb819194ceb7f7edfc0861",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/e016e47bbf70304945f2ae9dc397e4862adefaf5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.12.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.14.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 400,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58211",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:09:25.872Z",
      "date_published": "2026-07-08T20:16:25.262Z",
      "date_updated": "2026-07-09T14:27:25.118Z",
      "publisher": "GitHub_M",
      "title": "NATS Server: `no_auth_user` pre-CONNECT fast path bypasses user connection restrictions",
      "affected": {
        "vendors": [
          "nats-io"
        ],
        "products": [
          {
            "vendor": "nats-io",
            "product": "nats-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10949
      },
      "nvd": {
        "published": "2026-07-08T21:16:52.610",
        "lastModified": "2026-07-09T19:00:21.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58211",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "NATS registers no_auth_user through a pre-CONNECT parser path that skips the connection-type and proxy restrictions enforced by normal authentication.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-hmmp-q8cx-v964",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 450,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58213",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:09:25.873Z",
      "date_published": "2026-07-08T19:52:12.148Z",
      "date_updated": "2026-07-09T13:33:07.155Z",
      "publisher": "GitHub_M",
      "title": "NATS Server: MQTT SUBSCRIBE Protocol Injection via Leaf Node/Route Forwarding allows arbitrary NATS command injection",
      "affected": {
        "vendors": [
          "nats-io"
        ],
        "products": [
          {
            "vendor": "nats-io",
            "product": "nats-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24829
      },
      "nvd": {
        "published": "2026-07-08T20:16:54.180",
        "lastModified": "2026-07-13T15:16:22.260",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58213",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MQTT subscription filters retain protocol control characters when forwarded onto a NATS route or leafnode stream, allowing command framing injection.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-qrcv-3558-gj4f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/pull/8163",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/pull/8164",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/366837cfc65ab9ccb4f98193c65e8daf238582d8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/64ebae40051ee497c481e10f316238faf0de1736",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/f14856b9e57a36818f43851cb69b6e33670885c9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.12.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.14.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58214",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T17:09:25.873Z",
      "date_published": "2026-07-08T20:06:34.794Z",
      "date_updated": "2026-07-09T13:32:36.057Z",
      "publisher": "GitHub_M",
      "title": "NATS Server: MQTT subscribe ACL bypass via $MQTT.deliver.pubrel prefix (incomplete fix for CVE-2026-33217)",
      "affected": {
        "vendors": [
          "nats-io"
        ],
        "products": [
          {
            "vendor": "nats-io",
            "product": "nats-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17156
      },
      "nvd": {
        "published": "2026-07-08T20:16:54.347",
        "lastModified": "2026-07-13T15:17:13.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58214",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MQTT subscription check permits clients to subscribe to the internal $MQTT.deliver.pubrel subject family despite configured subscribe ACLs.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-4g68-3pwx-5vfj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/297b166be60fe13144084eed4b25201ead03204a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/34b09657bb596d5f850eaa5cfc97ea6b2f989a97",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.12.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.14.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58216",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T18:13:08.159Z",
      "date_published": "2026-07-30T15:40:11.673Z",
      "date_updated": "2026-07-31T22:57:42.253Z",
      "publisher": "redhat",
      "title": "Samba: kpasswd service: kpasswd packet that contains malformed asn.1 might cause the server to access 6 bytes of unallocated memory leading server to crash",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00515,
        "percentile": 0.4102
      },
      "nvd": {
        "published": "2026-07-30T16:17:14.767",
        "lastModified": "2026-07-31T23:17:25.703",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58216",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Red Hat Enterprise Linux 10 path reads beyond the validated extent of an attacker-influenced buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58216",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502721",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.samba.org/show_bug.cgi?id=16087",
          "host": "bugzilla.samba.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.samba.org/samba/security/CVE-2026-58216.html",
          "host": "www.samba.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 690,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-58218",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T18:13:08.160Z",
      "date_published": "2026-07-30T14:01:13.468Z",
      "date_updated": "2026-07-30T17:37:18.466Z",
      "publisher": "redhat",
      "title": "Samba: dns signing dos via tkey name cache exhaustion",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-410",
          "name": "Insufficient Resource Pool",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.011,
        "percentile": 0.62453
      },
      "nvd": {
        "published": "2026-07-30T14:17:00.307",
        "lastModified": "2026-07-30T19:18:26.480",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58218",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Rejected unauthenticated TKEY names are inserted before validation, enabling cache exhaustion and eviction of legitimate entries.",
        "basis": [
          "CNA",
          "CWE-410"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58218",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502728",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.samba.org/show_bug.cgi?id=16115",
          "host": "bugzilla.samba.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.samba.org/samba/security/CVE-2026-58218.html",
          "host": "www.samba.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 444,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-58222",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T18:18:00.439Z",
      "date_published": "2026-07-30T15:11:03.064Z",
      "date_updated": "2026-07-30T16:12:35.604Z",
      "publisher": "redhat",
      "title": "Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-90",
          "name": "Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00839,
        "percentile": 0.5428
      },
      "nvd": {
        "published": "2026-07-30T16:17:14.933",
        "lastModified": "2026-07-30T17:16:33.617",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58222",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Red Hat Enterprise Linux 10 directory path incorporates attacker-controlled attribute syntax into an LDAP filter without grammar-safe construction.",
        "basis": [
          "CNA",
          "CWE-90"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58222",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502722",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.samba.org/show_bug.cgi?id=16148",
          "host": "bugzilla.samba.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.samba.org/samba/security/CVE-2026-58222.html",
          "host": "www.samba.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 957,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-58225",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T18:54:08.633Z",
      "date_published": "2026-07-10T10:51:46.978Z",
      "date_updated": "2026-07-10T12:50:40.297Z",
      "publisher": "EEF",
      "title": "SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service",
      "affected": {
        "vendors": [
          "elixir-ecto"
        ],
        "products": [
          {
            "vendor": "elixir-ecto",
            "product": "postgrex"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05927
      },
      "nvd": {
        "published": "2026-07-10T11:16:36.300",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58225",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Postgrex replays a caller-controlled LISTEN channel name after reconnect without preserving the SQL identifier boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/elixir-ecto/ecto/security/advisories/GHSA-4mw9-4qgj-m97w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-58225.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-58225",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/elixir-ecto/postgrex/commit/795c6062f62c4394272ff4b89170688857b4f841",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1744,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T18:54:08.633Z",
      "date_published": "2026-07-06T09:03:47.374Z",
      "date_updated": "2026-07-06T14:04:14.632Z",
      "publisher": "EEF",
      "title": "Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax",
      "affected": {
        "vendors": [
          "elixir-mint"
        ],
        "products": [
          {
            "vendor": "elixir-mint",
            "product": "hpax"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00438,
        "percentile": 0.36034
      },
      "nvd": {
        "published": "2026-07-06T11:16:31.143",
        "lastModified": "2026-07-06T19:37:48.003",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58226",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Because BEAM integers are arbitrary precision, a run of N continuation octets builds an O(N)-bit bignum and re-adds into an ever-larger bignum on each step, so the total decoding cost is superlinear (about O(N^2)).",
        "basis": [
          "CNA",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/elixir-mint/hpax/security/advisories/GHSA-jj2p-32j7-whj2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-58226.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-58226",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/elixir-mint/hpax/commit/1ba4bb2dc91e80089cf89c73970ac3ded76f17eb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1084,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58227",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T18:54:08.633Z",
      "date_published": "2026-07-27T14:39:44.609Z",
      "date_updated": "2026-07-28T09:53:23.614Z",
      "publisher": "EEF",
      "title": "TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27675
      },
      "nvd": {
        "published": "2026-07-27T16:17:56.953",
        "lastModified": "2026-07-30T17:01:07.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58227",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-r5jr-mq46-vmhw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-58227.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-58227",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/0307bff2c72b685c6bd952daaac6bd661c247d62",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/241d43703989fec4b6bf637beaeb366d92dcc4c2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/7db64720177961e04545681480d691c4be81c54d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1195,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58228",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T18:54:08.633Z",
      "date_published": "2026-07-13T18:04:30.636Z",
      "date_updated": "2026-07-14T04:15:01.996Z",
      "publisher": "EEF",
      "title": "Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>",
      "affected": {
        "vendors": [
          "phoenixframework"
        ],
        "products": [
          {
            "vendor": "phoenixframework",
            "product": "phoenix_live_view"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30902
      },
      "nvd": {
        "published": "2026-07-13T19:17:30.317",
        "lastModified": "2026-07-13T20:37:48.157",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58228",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Phoenix validates URL schemes before browsers strip leading C0 controls and spaces, so a value treated as relative becomes a javascript: URL after browser normalization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/phoenixframework/phoenix_live_view/security/advisories/GHSA-5cgh-g58j-m9cq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-58228.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-58228",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/phoenixframework/phoenix_live_view/commit/86165533e311469a1b62093fd182d9d874de8106",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1167,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58229",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T18:54:08.633Z",
      "date_published": "2026-07-14T08:36:54.616Z",
      "date_updated": "2026-07-14T15:07:57.359Z",
      "publisher": "EEF",
      "title": "Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS",
      "affected": {
        "vendors": [
          "elixir-mint"
        ],
        "products": [
          {
            "vendor": "elixir-mint",
            "product": "mint"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22833
      },
      "nvd": {
        "published": "2026-07-14T09:16:41.313",
        "lastModified": "2026-07-15T20:17:21.813",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58229",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Mint accumulates response headers and trailers across TCP segments without a count or byte limit until a blank line arrives, allowing a peer to grow the buffer indefinitely.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/elixir-mint/mint/security/advisories/GHSA-qrfr-wh4c-3qhw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-58229.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-58229",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/elixir-mint/mint/commit/566d702e6f29105f77522ca7aabb9f64f2f4e333",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1249,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58233",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T19:34:28.222Z",
      "date_published": "2026-07-14T00:21:45.702Z",
      "date_updated": "2026-07-14T12:51:14.067Z",
      "publisher": "sap",
      "title": "Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach)",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP Change and Transport System Attach Tool (ctsattach)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23818
      },
      "nvd": {
        "published": "2026-07-14T01:16:18.710",
        "lastModified": "2026-07-14T16:46:49.030",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58233",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application deserializes attacker-controlled bytes with object semantics that can invoke executable behavior.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3773304",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 614,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T19:35:04.186Z",
      "date_published": "2026-07-28T09:51:55.180Z",
      "date_updated": "2026-07-28T19:16:55.291Z",
      "publisher": "sap",
      "title": "Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform",
      "affected": {
        "vendors": [
          "SAP_SE"
        ],
        "products": [
          {
            "vendor": "SAP_SE",
            "product": "SAP NetWeaver Application Server for ABAP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 11,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:cna@sap.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.0472
      },
      "nvd": {
        "published": "2026-07-28T10:16:49.943",
        "lastModified": "2026-07-28T20:17:27.347",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58246",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Diagnostic tracing records live session identifiers in a form accessible to trace readers, enabling reuse during the identifiers' validity period.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://me.sap.com/notes/3413033",
          "host": "me.sap.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://url.sap/sapsecuritypatchday",
          "host": "url.sap",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-58250",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:54:30.330Z",
      "date_published": "2026-07-08T19:48:55.058Z",
      "date_updated": "2026-07-09T13:33:45.059Z",
      "publisher": "GitHub_M",
      "title": "NATS Server: Pre-auth server crash via double INFO in leafnode handshake",
      "affected": {
        "vendors": [
          "nats-io"
        ],
        "products": [
          {
            "vendor": "nats-io",
            "product": "nats-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00505,
        "percentile": 0.40384
      },
      "nvd": {
        "published": "2026-07-08T20:16:54.483",
        "lastModified": "2026-07-13T15:18:46.507",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58250",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Repeated pre-authentication leafnode INFO messages reach uninitialized handshake state and dereference an invalid pointer.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-3g5q-cfh2-cq67",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/8dcb26eaea78fdcbe96dbee5986d6019fd5cb94a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/fc5fe39177533e9dbdd651d2458285bfae1dde27",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.11.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.12.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 445,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:54:30.330Z",
      "date_published": "2026-07-08T19:40:28.308Z",
      "date_updated": "2026-07-09T13:40:28.073Z",
      "publisher": "GitHub_M",
      "title": "NATS Server: Queue Subscribe Authz Bypass",
      "affected": {
        "vendors": [
          "nats-io"
        ],
        "products": [
          {
            "vendor": "nats-io",
            "product": "nats-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26569
      },
      "nvd": {
        "published": "2026-07-08T20:16:54.630",
        "lastModified": "2026-07-13T15:23:31.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58251",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "NATS lets a queue-specific decision override a subject-level subscription deny when the queue name itself is not denied.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-jx8g-9g95-6322",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/013586288078def45a6788096924eb4d150db65c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/79c2f6e9ff87f594596337b6427dda85c38d1fe1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/b9ffb63b85e7db3d25a13b2e234f5f7f7c13164d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.11.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.12.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.14.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 450,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:54:30.330Z",
      "date_published": "2026-07-08T19:46:10.380Z",
      "date_updated": "2026-07-09T13:34:28.023Z",
      "publisher": "GitHub_M",
      "title": "NATS Server: Subscribe Authz Bypass via Wildcard-Overlap",
      "affected": {
        "vendors": [
          "nats-io"
        ],
        "products": [
          {
            "vendor": "nats-io",
            "product": "nats-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00341,
        "percentile": 0.26688
      },
      "nvd": {
        "published": "2026-07-08T20:16:54.793",
        "lastModified": "2026-07-13T15:24:56.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58252",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "NATS evaluates wildcard deny rules incorrectly when a requested wildcard overlaps but is not a subset, delivering subjects the user is denied.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-wh7g-5m82-pmhr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/8ced85a11497f86704a95d960281480ce037386b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/a42a6d1e258eb5c3a2190384d31965a4b715e854",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/e611ca9604697b02d8f22beb76037400a9cf72e6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.11.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.12.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.14.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58253",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:54:30.330Z",
      "date_published": "2026-07-08T19:43:13.776Z",
      "date_updated": "2026-07-09T13:35:24.068Z",
      "publisher": "GitHub_M",
      "title": "NATS Server: Route API Auth Bypass",
      "affected": {
        "vendors": [
          "nats-io"
        ],
        "products": [
          {
            "vendor": "nats-io",
            "product": "nats-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13382
      },
      "nvd": {
        "published": "2026-07-08T20:16:54.943",
        "lastModified": "2026-07-13T15:25:44.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58253",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A parser fast path for no_auth_user client connections is incorrectly reused on route and leafnode listeners, bypassing inter-server authentication.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-38x3-76xf-cq45",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/7b81dd455ea95960090a84858c7662827948d1b6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/8b8e1ad4ceed32321e00d4fc6e76be05bc13bca6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/b86147e81710a52b72a7f7275f91d69f723f5cb3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.11.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.12.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.14.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58254",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:54:30.330Z",
      "date_published": "2026-07-08T19:56:58.311Z",
      "date_updated": "2026-07-09T13:38:17.588Z",
      "publisher": "GitHub_M",
      "title": "NATS Server: Incomplete fix for CVE-2026-33249: Leaf node connections bypass Nats-Trace-Dest permission check",
      "affected": {
        "vendors": [
          "nats-io"
        ],
        "products": [
          {
            "vendor": "nats-io",
            "product": "nats-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07729
      },
      "nvd": {
        "published": "2026-07-08T20:16:55.107",
        "lastModified": "2026-07-13T15:28:33.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58254",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "NATS applies trace-destination permissions to ordinary clients but omits the equivalent check for leafnode messages.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-p3j5-5hrq-p75h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/commit/cbe845932980b71563efac5cfa4cc751c88936cd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.12.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nats-io/nats-server/releases/tag/v2.14.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58263",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:54:30.331Z",
      "date_published": "2026-07-01T20:35:35.364Z",
      "date_updated": "2026-07-31T19:07:55.917Z",
      "publisher": "GitHub_M",
      "title": "Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier",
      "affected": {
        "vendors": [
          "xdan"
        ],
        "products": [
          {
            "vendor": "xdan",
            "product": "jodit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-83",
          "name": "Improper Neutralization of Script in Attributes in a Web Page",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07696
      },
      "nvd": {
        "published": "2026-07-01T21:17:04.340",
        "lastModified": "2026-07-31T20:16:52.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58263",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In jodit, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-83"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/xdan/jodit/security/advisories/GHSA-rxcw-mc6f-6hr3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 729,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58266",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:54:30.331Z",
      "date_published": "2026-07-07T21:13:42.650Z",
      "date_updated": "2026-07-08T13:23:46.962Z",
      "publisher": "GitHub_M",
      "title": "Anki: User scripts in iframes have access to the internal Anki API",
      "affected": {
        "vendors": [
          "ankitects"
        ],
        "products": [
          {
            "vendor": "ankitects",
            "product": "anki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06267
      },
      "nvd": {
        "published": "2026-07-07T22:16:54.207",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58266",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "anki trusts an origin, proxy header, cache key, or cross-origin channel without validating that it represents the same security principal and destination used by the policy decision.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ankitects/anki/security/advisories/GHSA-cw6h-ffmh-x6vh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ankitects/anki/commit/b2b68d829e853da51b5de8aad6c13b53e90bc20d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ankitects/anki/releases/tag/25.09.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 555,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58275",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.869Z",
      "date_published": "2026-07-24T00:01:14.647Z",
      "date_updated": "2026-08-03T22:59:17.238Z",
      "publisher": "microsoft",
      "title": "Azure DNS Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure DNS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00673,
        "percentile": 0.48598
      },
      "nvd": {
        "published": "2026-07-24T01:17:40.863",
        "lastModified": "2026-07-25T05:16:35.740",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58275",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Azure DNS permits an unauthenticated network caller to perform a privileged integrity or availability action, while Microsoft does not publish the resource or missing check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Microsoft's official MSRC page at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58275; it confirms CWE-862, unauthenticated network reachability, service-side remediation, and no customer action, while the Azure DNS resource and missing check remain undisclosed."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58275",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58276",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.870Z",
      "date_published": "2026-07-03T20:35:22.006Z",
      "date_updated": "2026-08-03T22:53:44.135Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00429,
        "percentile": 0.35308
      },
      "nvd": {
        "published": "2026-07-03T21:17:02.573",
        "lastModified": "2026-07-07T05:16:54.107",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58276",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge (Chromium-based) continues to access an object after its storage has been released, allowing invalid heap use and possible corruption.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58276",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58277",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.870Z",
      "date_published": "2026-07-14T17:09:43.419Z",
      "date_updated": "2026-08-03T22:58:16.691Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00894,
        "percentile": 0.56013
      },
      "nvd": {
        "published": "2026-07-14T18:18:36.873",
        "lastModified": "2026-07-15T15:13:22.683",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58277",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "SharePoint grants an authenticated caller privileges beyond its assigned role, but the public record does not identify the operation or check.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58277",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58278",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.870Z",
      "date_published": "2026-07-03T20:35:22.461Z",
      "date_updated": "2026-08-03T22:53:44.781Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20461
      },
      "nvd": {
        "published": "2026-07-03T21:17:02.707",
        "lastModified": "2026-07-06T19:19:04.183",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58278",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge can be induced to issue a server-side request to an attacker-selected destination.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58278",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 137,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58279",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.870Z",
      "date_published": "2026-07-14T17:05:26.016Z",
      "date_updated": "2026-08-03T22:53:45.311Z",
      "publisher": "microsoft",
      "title": "Azure CycleCloud Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure CycleCloud 8.9.1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28907
      },
      "nvd": {
        "published": "2026-07-14T17:17:12.110",
        "lastModified": "2026-07-22T16:23:14.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58279",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Azure CycleCloud permits an authenticated caller to exercise greater network authority than assigned, while the missing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58279",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58281",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.870Z",
      "date_published": "2026-07-11T20:55:40.750Z",
      "date_updated": "2026-08-03T22:58:17.457Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00704,
        "percentile": 0.49764
      },
      "nvd": {
        "published": "2026-07-11T21:16:23.903",
        "lastModified": "2026-07-14T05:16:18.870",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58281",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58281",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 132,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58282",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.870Z",
      "date_published": "2026-07-03T20:35:14.923Z",
      "date_updated": "2026-08-03T22:58:18.080Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24891
      },
      "nvd": {
        "published": "2026-07-03T21:17:02.820",
        "lastModified": "2026-07-06T19:17:59.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58282",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft identifies an Edge access-control failure that enables spoofing but does not publish the object or origin check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58282",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58283",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.870Z",
      "date_published": "2026-07-03T20:35:15.564Z",
      "date_updated": "2026-08-03T22:58:18.620Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00342,
        "percentile": 0.26837
      },
      "nvd": {
        "published": "2026-07-03T21:17:02.943",
        "lastModified": "2026-07-06T19:16:20.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58283",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected runtime uses an object through an incompatible type and therefore applies the wrong memory layout.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58283",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 164,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58284",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.870Z",
      "date_published": "2026-07-03T20:35:22.999Z",
      "date_updated": "2026-08-03T22:58:19.246Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00421,
        "percentile": 0.34631
      },
      "nvd": {
        "published": "2026-07-03T21:17:03.057",
        "lastModified": "2026-07-07T05:16:54.207",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58284",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58284",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58285",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.870Z",
      "date_published": "2026-07-03T20:35:23.474Z",
      "date_updated": "2026-08-03T22:58:19.876Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00455,
        "percentile": 0.37256
      },
      "nvd": {
        "published": "2026-07-03T21:17:03.180",
        "lastModified": "2026-07-07T05:16:54.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58285",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge interprets a resource as an incompatible type on a network-reachable path, corrupting the assumptions used for later memory access.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58285",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58286",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.870Z",
      "date_published": "2026-07-03T20:35:24.011Z",
      "date_updated": "2026-08-03T22:58:20.421Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24891
      },
      "nvd": {
        "published": "2026-07-03T21:17:03.293",
        "lastModified": "2026-07-07T04:17:55.037",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58286",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Edge permits a network spoofing result through improper access control, but Microsoft does not disclose the protected UI or missing decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58286",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58287",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.870Z",
      "date_published": "2026-07-03T20:35:16.144Z",
      "date_updated": "2026-08-03T22:58:20.980Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00455,
        "percentile": 0.37256
      },
      "nvd": {
        "published": "2026-07-03T21:17:03.413",
        "lastModified": "2026-07-07T12:40:42.487",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58287",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58287",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58288",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:24.560Z",
      "date_updated": "2026-08-03T22:58:24.161Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00438,
        "percentile": 0.36038
      },
      "nvd": {
        "published": "2026-07-03T21:17:03.523",
        "lastModified": "2026-07-07T05:16:54.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58288",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation can dereference an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58288",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58289",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:29.711Z",
      "date_updated": "2026-08-03T22:58:29.435Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00507,
        "percentile": 0.40528
      },
      "nvd": {
        "published": "2026-07-03T21:17:03.640",
        "lastModified": "2026-07-07T12:40:04.297",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58289",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge accesses a resource through an incompatible runtime type.",
        "basis": [
          "CNA record",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58290",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:30.311Z",
      "date_updated": "2026-08-03T22:58:29.977Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16356
      },
      "nvd": {
        "published": "2026-07-03T21:17:03.770",
        "lastModified": "2026-07-07T14:16:33.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58290",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge (Chromium-based) accesses a resource through an incompatible type and applies invalid memory assumptions.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58290",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58291",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:37.453Z",
      "date_updated": "2026-08-03T22:58:30.440Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-672",
          "name": "Operation on a Resource after Expiration or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00586,
        "percentile": 0.44714
      },
      "nvd": {
        "published": "2026-07-03T21:17:03.890",
        "lastModified": "2026-07-06T19:52:00.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58291",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Edge operates on a resource after its expiration or release, but Microsoft does not identify the object or lifetime transition.",
        "basis": [
          "CNA",
          "CWE-672"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58291",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 158,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58292",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:30.853Z",
      "date_updated": "2026-08-03T22:58:31.074Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20172
      },
      "nvd": {
        "published": "2026-07-03T21:17:04.013",
        "lastModified": "2026-07-07T12:37:27.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58292",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Edge record reports network code execution from improper input validation but does not identify the parsed object, invalid value, bound, or interpreter transition.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58292",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58293",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:31.401Z",
      "date_updated": "2026-08-03T22:58:31.615Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00438,
        "percentile": 0.36039
      },
      "nvd": {
        "published": "2026-07-03T21:17:04.143",
        "lastModified": "2026-07-07T12:36:37.217",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58293",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation uses an externally controlled filename or path without binding it to the intended storage location.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58293",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58294",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:31.928Z",
      "date_updated": "2026-08-03T22:58:32.238Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26665
      },
      "nvd": {
        "published": "2026-07-03T21:17:04.293",
        "lastModified": "2026-07-07T12:33:42.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58294",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge accesses a freed object while processing network content.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58294",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58295",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:32.479Z",
      "date_updated": "2026-08-03T22:58:32.702Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29904
      },
      "nvd": {
        "published": "2026-07-03T21:17:04.417",
        "lastModified": "2026-07-07T12:32:13.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58295",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Microsoft Edge (Chromium-based) path treats an object as an incompatible type, invalidating the memory layout expected by the consumer.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58295",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 173,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58296",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:33.018Z",
      "date_updated": "2026-08-03T22:58:33.251Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge for Android Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-359",
          "name": "Exposure of Private Personal Information to an Unauthorized Actor",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22602
      },
      "nvd": {
        "published": "2026-07-03T21:17:04.547",
        "lastModified": "2026-07-07T14:49:01.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58296",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Private personal information is returned to an observer who should not receive it.",
        "basis": [
          "CNA",
          "CWE-359"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58296",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 167,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58297",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:33.630Z",
      "date_updated": "2026-08-03T22:58:33.890Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge for Android Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-359",
          "name": "Exposure of Private Personal Information to an Unauthorized Actor",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00309,
        "percentile": 0.23245
      },
      "nvd": {
        "published": "2026-07-03T21:17:04.663",
        "lastModified": "2026-07-07T14:48:05.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58297",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Edge for Android exposes private personal data to an unauthorized network requester, while the public record does not identify the surface or field.",
        "basis": [
          "CNA",
          "CWE-359"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58297",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 167,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58298",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:34.186Z",
      "date_updated": "2026-08-03T22:58:35.681Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15121
      },
      "nvd": {
        "published": "2026-07-03T21:17:04.790",
        "lastModified": "2026-07-07T14:50:40.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58298",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Microsoft Edge renders attacker-controlled content across a browser markup boundary, enabling script execution or spoofed content.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58298",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58299",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:16.879Z",
      "date_updated": "2026-08-03T22:58:36.243Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge for Android Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18954
      },
      "nvd": {
        "published": "2026-07-03T21:17:04.907",
        "lastModified": "2026-07-07T14:42:37.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58299",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an unsafe state transition in Microsoft Edge (Chromium-based), while the stale or reordered state and enforcing check are not public.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58299",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 143,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58300",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-29T21:59:30.871Z",
      "date_published": "2026-07-03T20:35:34.726Z",
      "date_updated": "2026-08-03T22:58:37.011Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge for Android Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-36",
          "name": "Absolute Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26316
      },
      "nvd": {
        "published": "2026-07-03T21:17:05.023",
        "lastModified": "2026-07-07T22:48:09.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58300",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Edge for Android accepts an absolute path that selects a file outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-36"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58300",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 118,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58303",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T01:49:44.822Z",
      "date_published": "2026-07-09T09:47:00.455Z",
      "date_updated": "2026-07-09T12:17:48.514Z",
      "publisher": "samsung.tv_appliance",
      "title": "Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.",
      "affected": {
        "vendors": [
          "Samsung Open Source"
        ],
        "products": [
          {
            "vendor": "Samsung Open Source",
            "product": "Escargot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:PSIRT@samsung.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01887
      },
      "nvd": {
        "published": "2026-07-09T11:16:41.120",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58303",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler copies attacker-controlled data beyond a fixed-size stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Samsung/escargot/issues/1571",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/Samsung/escargot/pull/1585",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 177,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58304",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T01:49:44.822Z",
      "date_published": "2026-07-09T09:53:19.962Z",
      "date_updated": "2026-07-09T12:15:36.208Z",
      "publisher": "samsung.tv_appliance",
      "title": "Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.",
      "affected": {
        "vendors": [
          "Samsung Open Source"
        ],
        "products": [
          {
            "vendor": "Samsung Open Source",
            "product": "Escargot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:PSIRT@samsung.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01246
      },
      "nvd": {
        "published": "2026-07-09T11:16:41.233",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58304",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Escargot can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Samsung/escargot/issues/1573",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/Samsung/escargot/pull/1580",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58305",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T01:49:44.822Z",
      "date_published": "2026-07-09T09:55:06.689Z",
      "date_updated": "2026-07-09T12:13:38.936Z",
      "publisher": "samsung.tv_appliance",
      "title": "Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.",
      "affected": {
        "vendors": [
          "Samsung Open Source"
        ],
        "products": [
          {
            "vendor": "Samsung Open Source",
            "product": "Escargot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:PSIRT@samsung.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01246
      },
      "nvd": {
        "published": "2026-07-09T11:16:41.340",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58305",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The program accesses a resource through an incompatible type and then applies invalid memory assumptions.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Samsung/escargot/issues/1574",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/Samsung/escargot/pull/1580",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58306",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T01:49:44.822Z",
      "date_published": "2026-07-09T09:56:20.576Z",
      "date_updated": "2026-07-09T12:10:29.268Z",
      "publisher": "samsung.tv_appliance",
      "title": "Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.",
      "affected": {
        "vendors": [
          "Samsung Open Source"
        ],
        "products": [
          {
            "vendor": "Samsung Open Source",
            "product": "Escargot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:PSIRT@samsung.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01888
      },
      "nvd": {
        "published": "2026-07-09T11:16:41.447",
        "lastModified": "2026-07-09T17:00:11.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58306",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Escargot writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Samsung/escargot/issues/1576",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/Samsung/escargot/pull/1584",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58307",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T01:49:44.822Z",
      "date_published": "2026-07-09T10:33:01.635Z",
      "date_updated": "2026-07-09T12:04:20.924Z",
      "publisher": "samsung.tv_appliance",
      "title": "Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation.",
      "affected": {
        "vendors": [
          "Samsung Open Source"
        ],
        "products": [
          {
            "vendor": "Samsung Open Source",
            "product": "Escargot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:PSIRT@samsung.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01343
      },
      "nvd": {
        "published": "2026-07-09T11:16:41.550",
        "lastModified": "2026-07-09T17:00:11.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58307",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Escargot reads beyond a buffer and can reach an assertion while processing crafted input.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Samsung/escargot/issues/1577",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/Samsung/escargot/pull/1586",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 214,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58315",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T01:18:28.835Z",
      "date_published": "2026-07-07T05:33:26.274Z",
      "date_updated": "2026-07-24T09:15:32.321Z",
      "publisher": "jpcert",
      "title": "Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config.",
      "affected": {
        "vendors": [
          "SEIKO EPSON CORPORATION"
        ],
        "products": [
          {
            "vendor": "SEIKO EPSON CORPORATION",
            "product": "Web Config"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "3.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00102,
        "percentile": 0.01124
      },
      "nvd": {
        "published": "2026-07-07T06:16:23.147",
        "lastModified": "2026-07-24T10:16:31.823",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58315",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Web Config accepts a state-changing browser request from a malicious origin while the victim remains authenticated.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.epson.co.uk/en_GB/faq/KA-02075/contents?loc=en-us&ot_preferences=C0004%3A1%2CC0003%3A1%2CC0002%3A1%2CC0001%3A1&adobe_mc=MCMID%3D92155711048749840274153414272266649988%7CMCORGID%3DC6DD45815AE6DFFD0A495D24%40AdobeOrg%7CTS%3D1784703080",
          "host": "www.epson.co.uk",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jvn.jp/en/jp/JVN87285119/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 177,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58317",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T02:15:08.138Z",
      "date_published": "2026-07-17T04:14:03.592Z",
      "date_updated": "2026-07-17T13:06:39.880Z",
      "publisher": "jpcert",
      "title": "Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project.",
      "affected": {
        "vendors": [
          "TeraTerm Project"
        ],
        "products": [
          {
            "vendor": "TeraTerm Project",
            "product": "TTSSH2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-196",
          "name": "Unsigned to Signed Conversion Error",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07911
      },
      "nvd": {
        "published": "2026-07-17T05:16:40.180",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58317",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TTSSH2 converts an attacker-controlled unsigned SSH length or index to a signed value and then reads or writes outside the intended buffer.",
        "basis": [
          "CNA",
          "CWE-196"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://teratermproject.github.io/SA/JVN65294474-en.html",
          "host": "teratermproject.github.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://teratermproject.github.io/SA/JVN65294474.html",
          "host": "teratermproject.github.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jvn.jp/en/jp/JVN65294474/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 400,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58319",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T03:29:32.156Z",
      "date_published": "2026-07-14T09:36:41.043Z",
      "date_updated": "2026-07-14T16:03:35.174Z",
      "publisher": "apache",
      "title": "Apache Doris: Improper Authentication in Frontend HTTP API",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Doris"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00508,
        "percentile": 0.4059
      },
      "nvd": {
        "published": "2026-07-14T10:16:33.430",
        "lastModified": "2026-07-14T16:56:51.260",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58319",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Some Frontend REST administrative operations execute without authenticating the network caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/cob5mxkyr1k81o8v91hox2hld6zh25b4",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/14/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 459,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T15:25:14.279Z",
      "date_published": "2026-07-09T17:46:00.635Z",
      "date_updated": "2026-07-21T17:05:27.203Z",
      "publisher": "cisa-cg",
      "title": "Allwinner TV Box TV98 ADB exposed on network",
      "affected": {
        "vendors": [
          "Allwinner"
        ],
        "products": [
          {
            "vendor": "Allwinner",
            "product": "H616"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-489",
          "name": "Active Debug Code",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15398
      },
      "nvd": {
        "published": "2026-07-09T18:16:54.847",
        "lastModified": "2026-07-21T18:17:03.070",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58378",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The production TV box ships with network ADB enabled, exposing a root-capable debug interface after user approval.",
        "basis": [
          "CNA",
          "CWE-489"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58378",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-03.json",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58379",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T16:54:04.312Z",
      "date_published": "2026-07-03T18:29:22.302Z",
      "date_updated": "2026-07-13T10:55:42.400Z",
      "publisher": "redhat",
      "title": "Gimp: gimp: heap buffer overflow in read_channel_data()",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14255
      },
      "nvd": {
        "published": "2026-07-03T19:16:37.040",
        "lastModified": "2026-07-13T12:16:34.790",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58379",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Red Hat Enterprise Linux 9, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:38496",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58379",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2495997",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/commit/b630f167",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/issues/16205",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 427,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T16:54:04.312Z",
      "date_published": "2026-07-06T13:58:43.680Z",
      "date_updated": "2026-07-16T14:00:19.748Z",
      "publisher": "redhat",
      "title": "Gimp: gimp: stack buffer overflow in pnmscanner_gettoken()",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-193",
          "name": "Off-by-one Error",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00257,
        "percentile": 0.1732
      },
      "nvd": {
        "published": "2026-07-06T15:16:40.020",
        "lastModified": "2026-07-16T15:16:34.383",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58380",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Red Hat Enterprise Linux 9 copies, writes, or indexes attacker-influenced data without enforcing the destination buffer or object bounds required by the operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-193"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40751",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58380",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496135",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Third Party Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/commit/83699817",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/issues/16206",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 368,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58381",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T16:54:04.312Z",
      "date_published": "2026-07-02T19:45:33.777Z",
      "date_updated": "2026-07-07T17:02:18.749Z",
      "publisher": "redhat",
      "title": "Gimp: gimp: double-free in read_layer_block()",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01986
      },
      "nvd": {
        "published": "2026-07-02T20:17:06.170",
        "lastModified": "2026-07-07T18:16:39.803",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58381",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "read_layer_block frees the same PSP-parser allocation twice while processing a crafted file.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58381",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496166",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/commit/b22e147b",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/issues/16207",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-58384",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T16:54:04.312Z",
      "date_published": "2026-07-07T07:44:28.139Z",
      "date_updated": "2026-07-16T13:55:28.248Z",
      "publisher": "redhat",
      "title": "Gimp: gimp: integer overflow in read_rle_channel()",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17321
      },
      "nvd": {
        "published": "2026-07-07T09:16:30.003",
        "lastModified": "2026-07-16T14:16:55.733",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58384",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Red Hat Enterprise Linux 9 performs unchecked integer arithmetic that wraps and produces an invalid allocation size, offset, or length.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:40751",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-58384",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497431",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Third Party Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/commit/da29e217",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/issues/16216",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T17:05:24.724Z",
      "date_published": "2026-07-27T11:14:30.062Z",
      "date_updated": "2026-07-27T13:07:38.103Z",
      "publisher": "apache",
      "title": "Apache Thrift: Rust binary protocol non-strict path missing string size limit",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.01097,
        "percentile": 0.62373
      },
      "nvd": {
        "published": "2026-07-27T12:16:46.673",
        "lastModified": "2026-07-27T19:51:26.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58389",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The non-strict Rust binary protocol path accepts a string length without enforcing a maximum allocation size.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/ht2mjt8m3vz9v0h5pqzvc4r4nzfxwtrw",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/44",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 224,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:19:58.378Z",
      "date_published": "2026-07-01T14:25:44.452Z",
      "date_updated": "2026-07-02T14:26:00.684Z",
      "publisher": "GitHub_M",
      "title": "@acastellon/auth has an authentication bypass via spoofable headers in validateToken()",
      "affected": {
        "vendors": [
          "antonio-castellon"
        ],
        "products": [
          {
            "vendor": "antonio-castellon",
            "product": "module-auth"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00543,
        "percentile": 0.42543
      },
      "nvd": {
        "published": "2026-07-01T15:17:11.377",
        "lastModified": "2026-07-02T17:54:15.243",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58399",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "validateToken trusts a client-supplied auth-user value after a client-controlled Host prefix check and skips token validation.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/antonio-castellon/module-auth/security/advisories/GHSA-gfj5-979r-92pw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/antonio-castellon/module-auth/issues/6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://www.npmjs.com/package/@acastellon/auth/v/2.3.0",
          "host": "www.npmjs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 734,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58402",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:19:58.378Z",
      "date_published": "2026-07-06T19:19:58.754Z",
      "date_updated": "2026-07-06T20:54:38.775Z",
      "publisher": "GitHub_M",
      "title": "Hugo default code block renderer XSS via unescaped code-fence language",
      "affected": {
        "vendors": [
          "gohugoio"
        ],
        "products": [
          {
            "vendor": "gohugoio",
            "product": "hugo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06862
      },
      "nvd": {
        "published": "2026-07-06T20:16:38.040",
        "lastModified": "2026-07-08T03:06:03.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58402",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Hugo inserts an unescaped code-fence info string into class and data-lang HTML attributes, so a quote can terminate the attribute and inject script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gohugoio/hugo/security/advisories/GHSA-q76j-gcg9-vxc6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/pull/15051",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/commit/ce1a7e0bce3713af40496ded3c2c0ceeed49231d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/releases/tag/v0.163.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 381,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:19:58.379Z",
      "date_published": "2026-07-06T19:25:45.971Z",
      "date_updated": "2026-07-06T20:51:27.624Z",
      "publisher": "GitHub_M",
      "title": "Hugo symlink confinement bypass in os.ReadFile",
      "affected": {
        "vendors": [
          "gohugoio"
        ],
        "products": [
          {
            "vendor": "gohugoio",
            "product": "hugo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00318,
        "percentile": 0.24211
      },
      "nvd": {
        "published": "2026-07-06T20:16:38.173",
        "lastModified": "2026-07-08T03:05:34.933",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58403",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Hugo checks a mount root with Stat, which follows an attacker-planted symlink and lets os.ReadFile escape the virtual filesystem root.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gohugoio/hugo/security/advisories/GHSA-c3wq-j5vh-68rc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/pull/15020",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/commit/cf9c8f93ca2a2838ce378f9e36d052ac2f79e229",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/releases/tag/v0.163.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:19:58.379Z",
      "date_published": "2026-07-06T19:16:15.945Z",
      "date_updated": "2026-07-07T15:08:53.514Z",
      "publisher": "GitHub_M",
      "title": "Hugo security.http.urls deny rules bypassed by alternate IPv4 encodings",
      "affected": {
        "vendors": [
          "gohugoio"
        ],
        "products": [
          {
            "vendor": "gohugoio",
            "product": "hugo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11013
      },
      "nvd": {
        "published": "2026-07-06T20:16:38.307",
        "lastModified": "2026-07-08T03:05:00.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58404",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Hugo blocks only dotted-decimal internal IPv4 literals, so integer, hexadecimal, or octal forms and redirect hops can resolve into protected address space.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gohugoio/hugo/security/advisories/GHSA-r46f-3rpw-hxrv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/pull/15020",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/commit/a00b5c72ac57afe26df6688ece3ca544a56df372",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/gohugoio/hugo/releases/tag/v0.163.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 770,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58408",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:19:58.379Z",
      "date_published": "2026-07-13T19:43:48.352Z",
      "date_updated": "2026-07-14T12:57:34.313Z",
      "publisher": "GitHub_M",
      "title": "ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privileged Users to Export All Members' PII",
      "affected": {
        "vendors": [
          "ChurchCRM"
        ],
        "products": [
          {
            "vendor": "ChurchCRM",
            "product": "CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12261
      },
      "nvd": {
        "published": "2026-07-13T20:16:49.770",
        "lastModified": "2026-07-14T13:18:59.790",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58408",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The CSV export endpoint treats any legacy permission flag as sufficient and omits the dedicated authorization required for bulk PII export.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ChurchCRM/CRM/security/advisories/GHSA-4vj2-gm78-3q63",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 825,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:19:58.380Z",
      "date_published": "2026-07-13T20:05:56.086Z",
      "date_updated": "2026-07-14T13:06:18.072Z",
      "publisher": "GitHub_M",
      "title": "ChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin Upload",
      "affected": {
        "vendors": [
          "ChurchCRM"
        ],
        "products": [
          {
            "vendor": "ChurchCRM",
            "product": "CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00456,
        "percentile": 0.37373
      },
      "nvd": {
        "published": "2026-07-13T21:16:48.450",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58409",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The plugin installer explicitly accepts PHP files and extracts them beneath the web root, so an administrator-supplied archive immediately installs executable server code.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ChurchCRM/CRM/security/advisories/GHSA-37mf-vq43-5qp9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 944,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:19:58.380Z",
      "date_published": "2026-07-13T20:26:17.070Z",
      "date_updated": "2026-07-14T13:07:30.546Z",
      "publisher": "GitHub_M",
      "title": "ChurchCRM: Improper object-level authorization allows low-privileged users to read and modify other families’ records",
      "affected": {
        "vendors": [
          "ChurchCRM"
        ],
        "products": [
          {
            "vendor": "ChurchCRM",
            "product": "CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07133
      },
      "nvd": {
        "published": "2026-07-13T21:16:48.573",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58410",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ChurchCRM/CRM/security/advisories/GHSA-jjcj-h3cm-p7x7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 768,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58411",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:19:58.380Z",
      "date_published": "2026-07-13T21:05:18.739Z",
      "date_updated": "2026-07-21T19:05:39.783Z",
      "publisher": "GitHub_M",
      "title": "ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request parameter names and values",
      "affected": {
        "vendors": [
          "ChurchCRM"
        ],
        "products": [
          {
            "vendor": "ChurchCRM",
            "product": "CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27371
      },
      "nvd": {
        "published": "2026-07-13T22:16:48.270",
        "lastModified": "2026-07-21T20:17:02.973",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58411",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches CRM page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ChurchCRM/CRM/security/advisories/GHSA-p6j6-vrpg-4pp8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 845,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58413",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:19:58.380Z",
      "date_published": "2026-07-20T16:26:07.531Z",
      "date_updated": "2026-07-20T17:20:47.976Z",
      "publisher": "GitHub_M",
      "title": "EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data",
      "affected": {
        "vendors": [
          "Jovancoding"
        ],
        "products": [
          {
            "vendor": "Jovancoding",
            "product": "Network-AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03091
      },
      "nvd": {
        "published": "2026-07-20T17:18:15.570",
        "lastModified": "2026-07-21T19:49:44.020",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58413",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "EnvironmentManager.restore joins an unvalidated backup ID and copies a directory selected outside the environment's backup root.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-48x2-6pr9-2jjf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/commit/a59c13a1f0ce0e8a0779a90343eef92fac5ab4c3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/releases/tag/v5.12.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 847,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58414",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:19:58.380Z",
      "date_published": "2026-07-20T16:28:29.809Z",
      "date_updated": "2026-07-20T19:00:05.188Z",
      "publisher": "GitHub_M",
      "title": "Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups",
      "affected": {
        "vendors": [
          "Jovancoding"
        ],
        "products": [
          {
            "vendor": "Jovancoding",
            "product": "Network-AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03091
      },
      "nvd": {
        "published": "2026-07-20T17:18:15.720",
        "lastModified": "2026-07-21T19:49:44.020",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58414",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A stat operation follows a symlink outside the intended root directory.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-6x2m-p4xp-wg22",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/commit/a59c13a1f0ce0e8a0779a90343eef92fac5ab4c3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/releases/tag/v5.12.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 898,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:57:20.613Z",
      "date_published": "2026-07-03T20:54:51.149Z",
      "date_updated": "2026-07-06T15:14:53.799Z",
      "publisher": "Gitea",
      "title": "SSRF via HTTP Redirect in Repository Migration",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15634
      },
      "nvd": {
        "published": "2026-07-03T21:17:05.140",
        "lastModified": "2026-07-06T18:18:46.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58418",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Repository migration follows an HTTP redirect without reapplying the destination trust check, allowing requests to internal services.",
        "basis": [
          "CNA record",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-rqhx-647v-wx32",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38108",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 46,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58419",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:57:20.613Z",
      "date_published": "2026-07-03T20:54:51.523Z",
      "date_updated": "2026-07-06T15:14:06.910Z",
      "publisher": "Gitea",
      "title": "Notification API leaks private issue metadata after access revocation",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22127
      },
      "nvd": {
        "published": "2026-07-03T21:17:05.243",
        "lastModified": "2026-07-06T18:18:46.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58419",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The notification API continues returning private issue metadata after the recipient's access has been revoked.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-44qc-pgvp-wx7v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38108",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 69,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58421",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:57:20.614Z",
      "date_published": "2026-07-03T20:54:51.884Z",
      "date_updated": "2026-07-06T15:12:29.175Z",
      "publisher": "Gitea",
      "title": "Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.2516
      },
      "nvd": {
        "published": "2026-07-03T21:17:05.347",
        "lastModified": "2026-07-06T18:18:46.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58421",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unauthenticated CODEOWNERS matching applies a pathological pattern without bounding regular-expression work.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-v96j-25gv-g2w9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38011",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 78,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:57:20.614Z",
      "date_published": "2026-07-03T20:54:52.236Z",
      "date_updated": "2026-07-06T15:11:20.064Z",
      "publisher": "Gitea",
      "title": "Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26488
      },
      "nvd": {
        "published": "2026-07-03T21:17:05.447",
        "lastModified": "2026-07-06T18:18:46.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58422",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gitea's OAuth callback re-enables an administrator-disabled account instead of preserving the disabled state across external sign-in.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-g9g6-qhrc-p3qc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38009",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:57:20.614Z",
      "date_published": "2026-07-03T20:54:52.580Z",
      "date_updated": "2026-07-06T15:09:55.924Z",
      "publisher": "Gitea",
      "title": "LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23452
      },
      "nvd": {
        "published": "2026-07-03T21:17:05.550",
        "lastModified": "2026-07-06T18:18:46.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58423",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A malformed LFS SSH sub-verb reaches private repository reads without completing the expected authentication check.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-7wvc-rvp7-w99x",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38008",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 108,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:57:20.614Z",
      "date_published": "2026-07-03T20:54:52.923Z",
      "date_updated": "2026-07-06T15:09:01.188Z",
      "publisher": "Gitea",
      "title": "Permanent Fork PR Workflow Approval Gate Bypass",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10251
      },
      "nvd": {
        "published": "2026-07-03T21:17:05.660",
        "lastModified": "2026-07-06T18:18:46.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58424",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Gitea permits a permanent-fork pull request to bypass workflow approval, but the public record does not identify the permission or state check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-285",
          "CWE-732",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-777r-4v59-6486",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/38010",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.3-and-1.26.4/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 47,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58426",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T18:57:20.615Z",
      "date_published": "2026-07-03T20:54:53.283Z",
      "date_updated": "2026-07-06T15:07:18.210Z",
      "publisher": "Gitea",
      "title": "Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write",
      "affected": {
        "vendors": [
          "Gitea"
        ],
        "products": [
          {
            "vendor": "Gitea",
            "product": "Gitea Open Source Git Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:88ee5874-cf24-4952-aea0-31affedb7ff2",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08627
      },
      "nvd": {
        "published": "2026-07-03T21:17:05.770",
        "lastModified": "2026-07-06T18:17:26.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58426",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Gitea Open Source Git Server verification path accepts signed or MAC-protected data without validating the required authentic bytes.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-hg5r-vq93-9fv6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/37707",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v1.26.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-1.26.2/",
          "host": "blog.gitea.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58451",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.789Z",
      "date_published": "2026-07-01T18:16:09.328Z",
      "date_updated": "2026-07-14T22:03:05.643Z",
      "publisher": "VulnCheck",
      "title": "Horde IMP < 7.0.1 Path Traversal via Compose.php img src",
      "affected": {
        "vendors": [
          "horde"
        ],
        "products": [
          {
            "vendor": "horde",
            "product": "imp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00409,
        "percentile": 0.33637
      },
      "nvd": {
        "published": "2026-07-01T19:16:56.690",
        "lastModified": "2026-07-14T23:17:30.543",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58451",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Attacker-controlled path data selects a filesystem object outside the operation's intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/horde/imp/releases/tag/v7.0.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/horde/imp/pull/85",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/horde/imp/commit/fba972fab72ee6871e5d56e6390bee38593085de",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.horde.org/apps/imp",
          "host": "www.horde.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/horde-imp-path-traversal-via-compose-php-img-src",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://blog.evan.lat/posts/CVE-2026-58451/",
          "host": "blog.evan.lat",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "http://seclists.org/fulldisclosure/2026/Jul/8",
          "host": "seclists.org",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 596,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58452",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.789Z",
      "date_published": "2026-07-01T15:31:51.463Z",
      "date_updated": "2026-07-01T17:54:19.386Z",
      "publisher": "VulnCheck",
      "title": "JAIOTlink C492A-W6 4.8.30.57701411 OS Command Injection via SetMAC Endpoint",
      "affected": {
        "vendors": [
          "JAIOTlink"
        ],
        "products": [
          {
            "vendor": "JAIOTlink",
            "product": "C492A-W6 Wi-Fi IP Camera"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.02422,
        "percentile": 0.82562
      },
      "nvd": {
        "published": "2026-07-01T17:16:40.347",
        "lastModified": "2026-07-02T17:42:23.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58452",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The C492A-W6 Wi-Fi IP Camera command path concatenates attacker-controlled data into an operating-system command without preserving the shell grammar boundary.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rwprimitives/jaiotlink-c492a-wifi-camera/blob/main/writeups/01-setmac-command-injection.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.amazon.com/stores/JAIOTlink/page/3B00DC41-70C3-4BAA-925C-3D222C2633D5?lp_asin=B0GX1BNZ78&ref_=ast_bln&store_ref=bl_ast_dp_brandlogo_sto",
          "host": "www.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/jaiotlink-c492a-w6-os-command-injection-via-setmac-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 521,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58453",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.789Z",
      "date_published": "2026-07-01T15:33:41.819Z",
      "date_updated": "2026-07-01T16:25:22.366Z",
      "publisher": "VulnCheck",
      "title": "JAIOTlink C492A-W6 4.8.30.57701411 Hard-coded Credentials via anyka_ipc",
      "affected": {
        "vendors": [
          "JAIOTlink"
        ],
        "products": [
          {
            "vendor": "JAIOTlink",
            "product": "C492A-W6 Wi-Fi IP Camera"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1392",
          "name": "Use of Default Credentials",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.0169,
        "percentile": 0.74811
      },
      "nvd": {
        "published": "2026-07-01T17:16:40.517",
        "lastModified": "2026-07-02T17:42:23.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58453",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The camera's HTTP service ships with a default administrator account that accepts an empty password.",
        "basis": [
          "CNA",
          "CWE-1392"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rwprimitives/jaiotlink-c492a-wifi-camera/blob/main/writeups/02-default-http-credentials.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.amazon.com/stores/JAIOTlink/page/3B00DC41-70C3-4BAA-925C-3D222C2633D5?lp_asin=B0GX1BNZ78&ref_=ast_bln&store_ref=bl_ast_dp_brandlogo_sto",
          "host": "www.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/jaiotlink-c492a-w6-hard-coded-credentials-via-anyka-ipc",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 498,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.789Z",
      "date_published": "2026-07-01T15:36:15.363Z",
      "date_updated": "2026-07-01T18:10:47.836Z",
      "publisher": "VulnCheck",
      "title": "JAIOTlink C492A-W6 4.8.30.57701411 RCE via /Anyka/config Endpoint",
      "affected": {
        "vendors": [
          "JAIOTlink"
        ],
        "products": [
          {
            "vendor": "JAIOTlink",
            "product": "C492A-W6 Wi-Fi IP Camera"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00523,
        "percentile": 0.41447
      },
      "nvd": {
        "published": "2026-07-01T17:16:40.693",
        "lastModified": "2026-07-02T17:42:23.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58454",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The JAIOTlink camera lets an authenticated caller write a shell script to persistent JFFS2 storage and invoke it through a configuration endpoint that passes the script to popen.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rwprimitives/jaiotlink-c492a-wifi-camera/blob/main/writeups/03-anyka-config-execution-trigger.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.amazon.com/stores/JAIOTlink/page/3B00DC41-70C3-4BAA-925C-3D222C2633D5?lp_asin=B0GX1BNZ78&ref_=ast_bln&store_ref=bl_ast_dp_brandlogo_sto",
          "host": "www.amazon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/jaiotlink-c492a-w6-rce-via-anyka-config-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 513,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58455",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.789Z",
      "date_published": "2026-07-02T15:12:10.383Z",
      "date_updated": "2026-07-14T22:03:06.336Z",
      "publisher": "VulnCheck",
      "title": "Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php",
      "affected": {
        "vendors": [
          "Notifiarr"
        ],
        "products": [
          {
            "vendor": "Notifiarr",
            "product": "dockwatch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-698",
          "name": "Execution After Redirect (EAR)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.04856,
        "percentile": 0.91163
      },
      "nvd": {
        "published": "2026-07-02T16:16:35.287",
        "lastModified": "2026-07-14T23:17:30.677",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58455",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to shell_exec() in ajax/compose.php.",
        "basis": [
          "CNA",
          "CWE-78",
          "CWE-698"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Notifiarr/dockwatch/pull/135",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dockwatch-unauthenticated-os-command-injection-via-ajax-compose-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58457",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.789Z",
      "date_published": "2026-07-01T19:22:42.559Z",
      "date_updated": "2026-07-06T14:01:11.887Z",
      "publisher": "VulnCheck",
      "title": "Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp",
      "affected": {
        "vendors": [
          "Shenzhen Aitemi E Commerce Co. Ltd."
        ],
        "products": [
          {
            "vendor": "Shenzhen Aitemi E Commerce Co. Ltd.",
            "product": "M300 Wi-Fi Repeater"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.01657,
        "percentile": 0.74306
      },
      "nvd": {
        "published": "2026-07-01T20:17:11.427",
        "lastModified": "2026-07-06T15:16:40.160",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58457",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected handler places caller-controlled data in an operating-system command without safe argument separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/IEATASICS/m300-repeater-bugs#",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.aliexpress.us/item/3256806767641280.html",
          "host": "www.aliexpress.us",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/shenzhen-aitemi-m300-mt02-unauthenticated-os-command-injection-via-protocol-csp",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 547,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.789Z",
      "date_published": "2026-07-09T16:14:02.757Z",
      "date_updated": "2026-07-28T01:49:48.157Z",
      "publisher": "VulnCheck",
      "title": "gpsd gpsprof Command Injection via gnuplot plot title subtype field",
      "affected": {
        "vendors": [
          "ntpsec"
        ],
        "products": [
          {
            "vendor": "ntpsec",
            "product": "gpsd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 1.7999999999999998,
      "epss": {
        "score": 0.01796,
        "percentile": 0.7628
      },
      "nvd": {
        "published": "2026-07-09T17:17:01.493",
        "lastModified": "2026-07-14T23:17:30.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58459",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "gpsprof writes the GPS subtype into a gnuplot title while escaping only double quotes, allowing backticks in the subtype to execute shell commands when the plot is rendered.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gpsd/gpsd/-/work_items/404#note_3534119267",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Third Party Advisory",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/ntpsec/gpsd/commit/5581ba196d826a984fbfaf792b7d58535f9911ce",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/ntpsec/gpsd/commit/1a6bb7bcbdf58aa940132e630870af061dc88537",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://github.com/ntpsec/gpsd/commit/4c06658e988f4ced1a7a574ce082a22ef625df56",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gpsd-gpsprof-command-injection-via-gnuplot-plot-title-subtype-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58460",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.789Z",
      "date_published": "2026-07-02T20:10:40.633Z",
      "date_updated": "2026-07-14T22:03:07.670Z",
      "publisher": "VulnCheck",
      "title": "react-native-receive-sharing-intent Path Traversal via _display_name",
      "affected": {
        "vendors": [
          "ajith-ab"
        ],
        "products": [
          {
            "vendor": "ajith-ab",
            "product": "react-native-receive-sharing-intent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03619
      },
      "nvd": {
        "published": "2026-07-02T21:16:57.080",
        "lastModified": "2026-07-14T23:17:30.940",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58460",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "react-native-receive-sharing-intent accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ajith-ab/react-native-receive-sharing-intent/pull/192",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/react-native-receive-sharing-intent-path-traversal-via-display-name",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58465",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.790Z",
      "date_published": "2026-07-02T17:55:12.038Z",
      "date_updated": "2026-07-14T22:03:08.363Z",
      "publisher": "VulnCheck",
      "title": "Eclipse Wakaama CoAP Block1 Handler Unbounded Memory Allocation DoS",
      "affected": {
        "vendors": [
          "eclipse-wakaama"
        ],
        "products": [
          {
            "vendor": "eclipse-wakaama",
            "product": "wakaama"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00555,
        "percentile": 0.43163
      },
      "nvd": {
        "published": "2026-07-02T19:16:59.993",
        "lastModified": "2026-07-14T23:17:31.063",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58465",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CoAP Block1 handler repeatedly reallocates its accumulation buffer for increasing block numbers without a maximum total message size.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/eclipse-wakaama/wakaama/releases/tag/snapshots%2F2026-05-26",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/eclipse-wakaama/wakaama/pull/881",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/eclipse-wakaama/wakaama/commit/a83f1ca28fa090fbc03c3669fef40daf4f89cd03",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/eclipse-wakaama-coap-block1-handler-unbounded-memory-allocation-dos",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58466",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.790Z",
      "date_published": "2026-07-02T19:56:47.347Z",
      "date_updated": "2026-07-14T22:03:08.998Z",
      "publisher": "VulnCheck",
      "title": "AutoBangumi < 3.2.8 - Hard-coded Default Credentials via add_default_user()",
      "affected": {
        "vendors": [
          "EstrellaXD"
        ],
        "products": [
          {
            "vendor": "EstrellaXD",
            "product": "Auto_Bangumi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1392",
          "name": "Use of Default Credentials",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00505,
        "percentile": 0.40403
      },
      "nvd": {
        "published": "2026-07-02T20:17:06.593",
        "lastModified": "2026-07-14T23:17:31.187",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58466",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AutoBangumi seeds a publicly known administrator credential whenever its user table is empty.",
        "basis": [
          "CNA",
          "CWE-1392"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/EstrellaXD/Auto_Bangumi/releases/tag/3.2.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/EstrellaXD/Auto_Bangumi/issues/1041",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/EstrellaXD/Auto_Bangumi/commit/487bdfec545e805ae416e6ddf28651bd274d6a73",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/autobangumi-hard-coded-default-credentials-via-add-default-user",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 523,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58467",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.790Z",
      "date_published": "2026-07-02T20:04:56.875Z",
      "date_updated": "2026-07-14T22:03:09.658Z",
      "publisher": "VulnCheck",
      "title": "Cockpit CMS 2.14.0 - Path Traversal Local File Inclusion via index.php",
      "affected": {
        "vendors": [
          "cockpit-hq"
        ],
        "products": [
          {
            "vendor": "cockpit-hq",
            "product": "cockpit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00407,
        "percentile": 0.33451
      },
      "nvd": {
        "published": "2026-07-02T20:17:06.733",
        "lastModified": "2026-07-14T23:17:31.310",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58467",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Cockpit derives a filesystem include path from unvalidated PATH_INFO and permits traversal outside the spaces directory into arbitrary local files.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/cockpit.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cockpit-cms-path-traversal-local-file-inclusion-via-index-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 614,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58468",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.790Z",
      "date_published": "2026-07-07T19:27:58.922Z",
      "date_updated": "2026-07-14T22:03:10.298Z",
      "publisher": "VulnCheck",
      "title": "NocoBase 2.1.20 Server-Side Request Forgery via serverRequest wrapper",
      "affected": {
        "vendors": [
          "nocobase"
        ],
        "products": [
          {
            "vendor": "nocobase",
            "product": "nocobase"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.002,
        "percentile": 0.10087
      },
      "nvd": {
        "published": "2026-07-07T20:16:29.240",
        "lastModified": "2026-07-14T23:17:31.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58468",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The nocobase request path lets a caller choose a server-side destination outside the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nocobase/nocobase/issues/9962",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/nocobase/nocobase/pull/9966",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/nocobase/nocobase/commit/5706fb48d9bbe190f9e0044c6d5c87fc5b68c7f1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.vulncheck.com/advisories/nocobase-server-side-request-forgery-via-serverrequest-wrapper",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 617,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58469",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.790Z",
      "date_published": "2026-07-07T19:43:34.767Z",
      "date_updated": "2026-07-14T22:03:10.940Z",
      "publisher": "VulnCheck",
      "title": "GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing",
      "affected": {
        "vendors": [
          "gnuwget"
        ],
        "products": [
          {
            "vendor": "gnuwget",
            "product": "wget"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27776
      },
      "nvd": {
        "published": "2026-07-07T21:17:28.383",
        "lastModified": "2026-07-09T15:59:43.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58469",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "clean_metalink_string decrements a pointer before the buffer start when a Metalink URL contains only whitespace.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-underread-via-metalink-url-parsing",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 466,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58470",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.790Z",
      "date_published": "2026-07-07T19:45:53.170Z",
      "date_updated": "2026-07-14T22:03:11.587Z",
      "publisher": "VulnCheck",
      "title": "GNU Wget 1.25.0 Integer Overflow via Content-Range Header Parsing",
      "affected": {
        "vendors": [
          "gnuwget"
        ],
        "products": [
          {
            "vendor": "gnuwget",
            "product": "wget"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16048
      },
      "nvd": {
        "published": "2026-07-07T21:17:28.553",
        "lastModified": "2026-07-09T16:01:18.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58470",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "parse_content_range performs signed arithmetic on server-controlled header values without checking whether the result fits the destination integer type.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-integer-overflow-via-content-range-header-parsing",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58471",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.790Z",
      "date_published": "2026-07-07T19:47:47.662Z",
      "date_updated": "2026-07-14T22:03:12.273Z",
      "publisher": "VulnCheck",
      "title": "GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c",
      "affected": {
        "vendors": [
          "gnuwget"
        ],
        "products": [
          {
            "vendor": "gnuwget",
            "product": "wget"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12733
      },
      "nvd": {
        "published": "2026-07-07T21:17:28.710",
        "lastModified": "2026-07-09T16:02:07.273",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58471",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "wget copies, writes, or indexes attacker-influenced data without enforcing the destination buffer or object bounds required by the operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 499,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58472",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.790Z",
      "date_published": "2026-07-07T19:50:53.967Z",
      "date_updated": "2026-07-14T22:03:12.957Z",
      "publisher": "VulnCheck",
      "title": "GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding",
      "affected": {
        "vendors": [
          "gnuwget"
        ],
        "products": [
          {
            "vendor": "gnuwget",
            "product": "wget"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12733
      },
      "nvd": {
        "published": "2026-07-07T21:17:28.873",
        "lastModified": "2026-07-09T15:58:45.663",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58472",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "html_quote_string overflows a signed output-size counter, allocates too little heap memory, and then copies encoded attribute data past the allocation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 518,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58473",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.790Z",
      "date_published": "2026-07-07T20:34:54.943Z",
      "date_updated": "2026-07-14T22:03:13.601Z",
      "publisher": "VulnCheck",
      "title": "Cognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settings",
      "affected": {
        "vendors": [
          "topoteretes"
        ],
        "products": [
          {
            "vendor": "topoteretes",
            "product": "cognee"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29947
      },
      "nvd": {
        "published": "2026-07-07T21:17:29.007",
        "lastModified": "2026-07-14T23:17:31.830",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58473",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The settings endpoint checks neither administrator status nor tenant scope before changing a process-wide LLM provider configuration.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/topoteretes/cognee/releases/tag/v1.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/topoteretes/cognee/issues/3084",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/topoteretes/cognee/commit/d10b1b77e2157c6238fd4d1acb1923a048991699",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cognee-unauthorized-llm-configuration-overwrite-via-api-v1-settings",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58475",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.791Z",
      "date_published": "2026-07-14T14:19:19.512Z",
      "date_updated": "2026-07-15T14:46:26.312Z",
      "publisher": "VulnCheck",
      "title": "Sustainable Irrigation Platform 5.2.16 Stored XSS via Program Name",
      "affected": {
        "vendors": [
          "Dan-in-CA"
        ],
        "products": [
          {
            "vendor": "Dan-in-CA",
            "product": "SIP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11915
      },
      "nvd": {
        "published": "2026-07-14T15:17:06.340",
        "lastModified": "2026-07-15T15:16:45.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58475",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SIP stores unauthenticated program names and renders them without output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zeroscience.mk/#/advisories/ZSL-2026-5994",
          "host": "www.zeroscience.mk",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/sustainable-irrigation-platform-stored-xss-via-program-name",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.791Z",
      "date_published": "2026-07-14T14:25:41.659Z",
      "date_updated": "2026-07-14T22:03:14.963Z",
      "publisher": "VulnCheck",
      "title": "Sustainable Irrigation Platform 5.2.16 CSRF via Administrative GET Requests",
      "affected": {
        "vendors": [
          "Dan-in-CA"
        ],
        "products": [
          {
            "vendor": "Dan-in-CA",
            "product": "SIP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13694
      },
      "nvd": {
        "published": "2026-07-14T15:17:06.477",
        "lastModified": "2026-07-14T23:17:32.067",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58476",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Administrative GET endpoints accept state-changing cross-site requests without a CSRF token or origin check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zeroscience.mk/#/advisories/ZSL-2026-5995",
          "host": "www.zeroscience.mk",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/sustainable-irrigation-platform-csrf-via-administrative-get-requests",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 620,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58477",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.791Z",
      "date_published": "2026-07-14T14:39:51.652Z",
      "date_updated": "2026-07-14T22:03:15.674Z",
      "publisher": "VulnCheck",
      "title": "Sustainable Irrigation Platform 5.2.16 Mass Assignment via HTTP Parameters",
      "affected": {
        "vendors": [
          "Dan-in-CA"
        ],
        "products": [
          {
            "vendor": "Dan-in-CA",
            "product": "SIP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00357,
        "percentile": 0.28419
      },
      "nvd": {
        "published": "2026-07-14T15:17:06.620",
        "lastModified": "2026-07-14T23:17:32.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58477",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SIP binds unauthenticated request fields directly onto a configuration object, allowing protected configuration keys to be changed without per-field authority.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zeroscience.mk/#/advisories/ZSL-2026-5997",
          "host": "www.zeroscience.mk",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/sustainable-irrigation-platform-mass-assignment-via-http-parameters",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58478",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.791Z",
      "date_published": "2026-07-14T14:41:54.079Z",
      "date_updated": "2026-07-15T18:11:54.117Z",
      "publisher": "VulnCheck",
      "title": "Sustainable Irrigation Platform 5.2.16 SSRF via Node-RED Callback URL",
      "affected": {
        "vendors": [
          "Dan-in-CA"
        ],
        "products": [
          {
            "vendor": "Dan-in-CA",
            "product": "SIP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17729
      },
      "nvd": {
        "published": "2026-07-14T15:17:06.753",
        "lastModified": "2026-07-15T19:18:09.747",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58478",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optional Node-RED plugin is installed.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zeroscience.mk/#/advisories/ZSL-2026-5998",
          "host": "www.zeroscience.mk",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/sustainable-irrigation-platform-ssrf-via-node-red-callback-url",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 491,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58479",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.791Z",
      "date_published": "2026-07-14T14:44:49.018Z",
      "date_updated": "2026-07-14T22:03:17.020Z",
      "publisher": "VulnCheck",
      "title": "Sustainable Irrigation Platform 5.2.16 RCE via cli_control Plugin Command Injection",
      "affected": {
        "vendors": [
          "Dan-in-CA"
        ],
        "products": [
          {
            "vendor": "Dan-in-CA",
            "product": "SIP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.02766,
        "percentile": 0.84856
      },
      "nvd": {
        "published": "2026-07-14T15:17:06.893",
        "lastModified": "2026-07-14T23:17:32.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58479",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zeroscience.mk/#/advisories/ZSL-2026-5999",
          "host": "www.zeroscience.mk",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/sustainable-irrigation-platform-rce-via-cli-control-plugin-command-injection",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58480",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:20:33.791Z",
      "date_published": "2026-07-08T13:05:02.727Z",
      "date_updated": "2026-07-14T22:03:17.700Z",
      "publisher": "VulnCheck",
      "title": "Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments",
      "affected": {
        "vendors": [
          "Creative Themes"
        ],
        "products": [
          {
            "vendor": "Creative Themes",
            "product": "Blocksy Companion"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.00605,
        "percentile": 0.45569
      },
      "nvd": {
        "published": "2026-07-08T14:17:19.977",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58480",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload validator uses a substring extension check, so a double-extension PHP file is stored as web-executable content.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blocksy-companion/blocksy-companion-2146-unauthenticated-arbitrary-file-upload-via-blc-review-images-parameter",
          "host": "www.wordfence.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://patchstack.com/database/wordpress/plugin/blocksy-companion/vulnerability/wordpress-blocksy-companion-plugin-2-1-46-unauthenticated-arbitrary-file-upload-vulnerability",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://wordpress.org/plugins/blocksy-companion/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/blocksy-companion-pro-unauthenticated-file-upload-via-save-attachments",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 564,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.811Z",
      "date_published": "2026-07-20T16:30:15.220Z",
      "date_updated": "2026-07-20T17:42:43.376Z",
      "publisher": "GitHub_M",
      "title": "Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory",
      "affected": {
        "vendors": [
          "Jovancoding"
        ],
        "products": [
          {
            "vendor": "Jovancoding",
            "product": "Network-AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03091
      },
      "nvd": {
        "published": "2026-07-20T17:18:15.857",
        "lastModified": "2026-07-21T19:49:44.020",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58481",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The sandbox uses a raw string-prefix test for path containment, so a sibling directory sharing the base-name prefix is treated as inside the sandbox.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-jvcm-f35g-w78p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/commit/a59c13a1f0ce0e8a0779a90343eef92fac5ab4c3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/releases/tag/v5.12.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 967,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.811Z",
      "date_published": "2026-07-20T16:38:55.576Z",
      "date_updated": "2026-07-20T17:33:23.241Z",
      "publisher": "GitHub_M",
      "title": "Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions",
      "affected": {
        "vendors": [
          "Jovancoding"
        ],
        "products": [
          {
            "vendor": "Jovancoding",
            "product": "Network-AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03197
      },
      "nvd": {
        "published": "2026-07-20T17:18:15.997",
        "lastModified": "2026-07-21T19:49:44.020",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58482",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ApprovalInbox exposes state-changing approval routes without authentication, allowing an untrusted requester to approve a gated agent action.",
        "basis": [
          "CNA",
          "CWE-352",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-mxjx-28vx-xjjj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/commit/a59c13a1f0ce0e8a0779a90343eef92fac5ab4c3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/releases/tag/v5.12.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1398,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58484",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.811Z",
      "date_published": "2026-07-20T17:00:56.125Z",
      "date_updated": "2026-07-20T18:52:43.854Z",
      "publisher": "GitHub_M",
      "title": "Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning",
      "affected": {
        "vendors": [
          "Jovancoding"
        ],
        "products": [
          {
            "vendor": "Jovancoding",
            "product": "Network-AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03293
      },
      "nvd": {
        "published": "2026-07-20T17:18:16.160",
        "lastModified": "2026-07-21T19:49:44.020",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58484",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Network-AI accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-2fmp-9rvw-hc96",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/commit/a59c13a1f0ce0e8a0779a90343eef92fac5ab4c3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Jovancoding/Network-AI/releases/tag/v5.12.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 970,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58486",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.812Z",
      "date_published": "2026-07-13T22:12:37.837Z",
      "date_updated": "2026-07-14T12:48:39.469Z",
      "publisher": "GitHub_M",
      "title": "HedgeDoc: Denial-of-service via YAML alias expansion in note frontmatter",
      "affected": {
        "vendors": [
          "hedgedoc"
        ],
        "products": [
          {
            "vendor": "hedgedoc",
            "product": "hedgedoc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14458
      },
      "nvd": {
        "published": "2026-07-13T23:16:47.233",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58486",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HedgeDoc expands recursively aliased YAML frontmatter without an effective expansion bound and monopolizes the Node.js event loop.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-qj78-mjch-wwrv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hedgedoc/hedgedoc/commit/c489497e451887bfe400434c5a010940051e9890",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1036,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58487",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.812Z",
      "date_published": "2026-07-13T21:59:27.436Z",
      "date_updated": "2026-07-15T14:28:06.634Z",
      "publisher": "GitHub_M",
      "title": "HedgeDoc: Stored HTML injection via email local-part",
      "affected": {
        "vendors": [
          "hedgedoc"
        ],
        "products": [
          {
            "vendor": "hedgedoc",
            "product": "hedgedoc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00358,
        "percentile": 0.28518
      },
      "nvd": {
        "published": "2026-07-13T22:16:48.410",
        "lastModified": "2026-07-15T15:16:45.970",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58487",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An email local part is rendered without sufficient browser-context escaping and can execute as script.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-6c2w-8w96-3pcv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1029,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.812Z",
      "date_published": "2026-07-13T21:43:14.830Z",
      "date_updated": "2026-07-14T12:47:03.169Z",
      "publisher": "GitHub_M",
      "title": "HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing",
      "affected": {
        "vendors": [
          "hedgedoc"
        ],
        "products": [
          {
            "vendor": "hedgedoc",
            "product": "hedgedoc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21798
      },
      "nvd": {
        "published": "2026-07-13T22:16:48.550",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58488",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HedgeDoc trusts an attacker-supplied CF-Connecting-IP header from non-Cloudflare requests and uses it as the rate-limit identity.",
        "basis": [
          "CNA record",
          "CWE-290",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-2f9f-w8xq-276v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 626,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.812Z",
      "date_published": "2026-07-13T22:34:51.730Z",
      "date_updated": "2026-07-14T12:59:49.853Z",
      "publisher": "GitHub_M",
      "title": "HedgeDoc: CSRF in GitHub Gist export callback",
      "affected": {
        "vendors": [
          "hedgedoc"
        ],
        "products": [
          {
            "vendor": "hedgedoc",
            "product": "hedgedoc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02692
      },
      "nvd": {
        "published": "2026-07-13T23:16:47.373",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58489",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OAuth callback checks only that a state parameter exists and never compares it with the value bound to the user's session.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-8v9p-5j95-826j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hedgedoc/hedgedoc/commit/fbd7307f162754212046ec343cbe691223a48c8d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 805,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.812Z",
      "date_published": "2026-07-10T16:22:37.052Z",
      "date_updated": "2026-07-10T16:48:28.515Z",
      "publisher": "GitHub_M",
      "title": "grav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name Interpolation",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22543
      },
      "nvd": {
        "published": "2026-07-10T17:17:01.670",
        "lastModified": "2026-07-10T17:35:11.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58492",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PDO::tableExists interpolates its table argument directly into raw SQL without quoting, escaping, or parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-8jxg-4pw9-xcwf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav-plugin-database/commit/f6d058785c9e23df7efc5ea7556f8746fef286df",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav-plugin-database/releases/tag/1.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58493",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.812Z",
      "date_published": "2026-07-10T16:24:32.595Z",
      "date_updated": "2026-07-13T18:06:28.730Z",
      "publisher": "GitHub_M",
      "title": "grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String Construction",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-74",
          "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21057
      },
      "nvd": {
        "published": "2026-07-10T17:17:01.860",
        "lastModified": "2026-07-13T19:17:30.487",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58493",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Grav database plugin concatenates administrator-controlled YAML values into PDO DSN syntax without validating or escaping DSN attributes and paths.",
        "basis": [
          "CNA",
          "CWE-74"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-jm58-p4pv-qcwc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav-plugin-database/commit/f6d058785c9e23df7efc5ea7556f8746fef286df",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav-plugin-database/releases/tag/1.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 438,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58494",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.812Z",
      "date_published": "2026-07-08T20:22:16.039Z",
      "date_updated": "2026-07-09T13:28:57.055Z",
      "publisher": "GitHub_M",
      "title": "Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination",
      "affected": {
        "vendors": [
          "bytecodealliance"
        ],
        "products": [
          {
            "vendor": "bytecodealliance",
            "product": "wasmtime"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-281",
          "name": "Improper Preservation of Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02108
      },
      "nvd": {
        "published": "2026-07-08T21:16:54.000",
        "lastModified": "2026-07-10T19:10:59.333",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58494",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A filesystem link or rename operation preserves directory access while failing to preserve the source and destination file-permission restrictions.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-281"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bytecodealliance/wasmtime/commit/5ddfd5f1ef28f2041fa07d237ad0336e167b0e0c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bytecodealliance/wasmtime/commit/7db94cdcf0c79cb3dfde884b534b653f2dd83367",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bytecodealliance/wasmtime/commit/8a250aac0962ca1364b5f16525720e9d0b39edcd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bytecodealliance/wasmtime/commit/d3ceb56ec35f39e02496eeb4e2d9c7f4fb964d9e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bytecodealliance/wasmtime/releases/tag/v24.0.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bytecodealliance/wasmtime/releases/tag/v36.0.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bytecodealliance/wasmtime/releases/tag/v45.0.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bytecodealliance/wasmtime/releases/tag/v46.0.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 462,
        "referenceCount": 9,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-58499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.813Z",
      "date_published": "2026-07-10T20:53:24.196Z",
      "date_updated": "2026-07-13T16:18:18.609Z",
      "publisher": "GitHub_M",
      "title": "Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id",
      "affected": {
        "vendors": [
          "EverMind-AI"
        ],
        "products": [
          {
            "vendor": "EverMind-AI",
            "product": "EverOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00356,
        "percentile": 0.28339
      },
      "nvd": {
        "published": "2026-07-10T21:17:00.197",
        "lastModified": "2026-07-13T19:49:37.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58499",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The memory-add endpoint joins an unvalidated sender_id into the persistence path, allowing traversal sequences to write Markdown outside the configured memory root.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/EverMind-AI/EverOS/security/advisories/GHSA-c795-2g9c-j48m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/EverMind-AI/EverOS/commit/a10cdcd197747f371b7879a32c2cc3f77471e9c2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/EverMind-AI/EverOS/releases/tag/v1.0.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 706,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58500",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.813Z",
      "date_published": "2026-07-13T21:17:29.497Z",
      "date_updated": "2026-07-14T14:31:14.587Z",
      "publisher": "GitHub_M",
      "title": "MCP Appium: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)",
      "affected": {
        "vendors": [
          "appium"
        ],
        "products": [
          {
            "vendor": "appium",
            "product": "appium-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.1973
      },
      "nvd": {
        "published": "2026-07-13T22:16:48.677",
        "lastModified": "2026-07-15T20:18:23.677",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58500",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The appium-mcp rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/appium/appium-mcp/security/advisories/GHSA-x975-rgx4-5fh4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/appium/appium-mcp/commit/e222bbbd6fe2b656a320efcd143563f08061a83d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 869,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.813Z",
      "date_published": "2026-07-08T19:31:55.937Z",
      "date_updated": "2026-07-09T13:20:46.160Z",
      "publisher": "GitHub_M",
      "title": "Zeep SSRF because Settings.forbid_external is not enforced",
      "affected": {
        "vendors": [
          "mvantellingen"
        ],
        "products": [
          {
            "vendor": "mvantellingen",
            "product": "python-zeep"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18694
      },
      "nvd": {
        "published": "2026-07-08T20:16:55.323",
        "lastModified": "2026-07-10T18:15:45.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58501",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server trusts an attacker-controlled request destination or cross-domain channel without the required restriction.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mvantellingen/python-zeep/security/advisories/GHSA-4cc2-g9w2-fhf6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/mvantellingen/python-zeep/commit/83eb07bc6c84d841329d4f88856fecdba86f753e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mvantellingen/python-zeep/releases/tag/4.3.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 318,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58503",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-06-30T20:21:25.813Z",
      "date_published": "2026-07-10T21:12:28.742Z",
      "date_updated": "2026-07-13T18:55:05.081Z",
      "publisher": "GitHub_M",
      "title": "Frappe: Unauthenticated User Enumeration via reset_password",
      "affected": {
        "vendors": [
          "frappe"
        ],
        "products": [
          {
            "vendor": "frappe",
            "product": "frappe"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-203",
          "name": "Observable Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28175
      },
      "nvd": {
        "published": "2026-07-10T22:16:44.783",
        "lastModified": "2026-07-13T19:17:31.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58503",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The frappe endpoint returns observably different responses that reveal whether a protected account exists.",
        "basis": [
          "CNA",
          "CWE-203"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/frappe/frappe/security/advisories/GHSA-3vqc-c545-w7jg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/38625",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/pull/38626",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/1ff64d4a67f9a6d8819ac059dc69f023fb9ea264",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/commit/d3becf5672cbb5c7150447161941aeebeeb84ae8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/releases/tag/v15.106.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/frappe/frappe/releases/tag/v16.16.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58517",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T03:40:44.768Z",
      "date_published": "2026-07-01T18:23:02.161Z",
      "date_updated": "2026-07-01T18:35:06.496Z",
      "publisher": "wikimedia-foundation",
      "title": "Blocked users can create and edit WikiLambda objects",
      "affected": {
        "vendors": [
          "The Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "The Wikimedia Foundation",
            "product": "Mediawiki - WikiLambda Extension"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 2.6000000000000005,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09379
      },
      "nvd": {
        "published": "2026-07-01T19:16:57.063",
        "lastModified": "2026-07-10T13:50:41.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58517",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WikiLambda accepts crafted terminator input through an alternate parsing path that bypasses the normal authentication check.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T428833",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://gerrit.wikimedia.org/r/c/1305376",
          "host": "gerrit.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58518",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T03:40:44.769Z",
      "date_published": "2026-07-01T03:52:29.450Z",
      "date_updated": "2026-07-01T12:31:23.619Z",
      "publisher": "wikimedia-foundation",
      "title": "Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery.",
      "affected": {
        "vendors": [
          "The Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "The Wikimedia Foundation",
            "product": "Mediawiki - RedirectManager Extension"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00088,
        "percentile": 0.00486
      },
      "nvd": {
        "published": "2026-07-01T05:16:22.970",
        "lastModified": "2026-07-09T17:39:47.107",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58518",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Mediawiki - RedirectManager Extension accepts a request across an unintended network or origin boundary, while the request field and validation step are not public.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T423826",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/RedirectManager/+/1275494",
          "host": "gerrit.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58519",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T03:40:44.769Z",
      "date_published": "2026-07-01T03:59:33.932Z",
      "date_updated": "2026-07-01T12:29:57.811Z",
      "publisher": "wikimedia-foundation",
      "title": "Stored XSS through Cargo's map format",
      "affected": {
        "vendors": [
          "The Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "The Wikimedia Foundation",
            "product": "Mediawiki - Cargo Extension"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:A"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03281
      },
      "nvd": {
        "published": "2026-07-01T05:16:23.110",
        "lastModified": "2026-07-06T20:25:36.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58519",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Cargo extension stores attacker-controlled content and later renders it without HTML-context neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T424140",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "exploit"
          ]
        },
        {
          "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1277612",
          "host": "gerrit.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58520",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T03:40:44.769Z",
      "date_published": "2026-07-01T17:14:06.292Z",
      "date_updated": "2026-07-01T17:56:06.753Z",
      "publisher": "wikimedia-foundation",
      "title": "UrlShortener defaults to ineffective validation open to third-party redirects",
      "affected": {
        "vendors": [
          "The Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "The Wikimedia Foundation",
            "product": "Mediawiki - UrlShortener Extension"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00176,
        "percentile": 0.0738
      },
      "nvd": {
        "published": "2026-07-01T18:16:35.983",
        "lastModified": "2026-07-09T18:45:14.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58520",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T418431",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        },
        {
          "url": "https://gerrit.wikimedia.org/r/q/I7a59cc4c351b5aa47ed46f7a14a1105fd1ecc5b5",
          "host": "gerrit.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58521",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T03:40:44.769Z",
      "date_published": "2026-07-01T17:30:50.009Z",
      "date_updated": "2026-07-01T17:58:23.995Z",
      "publisher": "wikimedia-foundation",
      "title": "SQLi in Cargo extension via year range filter",
      "affected": {
        "vendors": [
          "The Wikimedia Foundation"
        ],
        "products": [
          {
            "vendor": "The Wikimedia Foundation",
            "product": "Mediawiki - Cargo Extension"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:c4f26cc8-17ff-4c99-b5e2-38fc1793eacc",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 2.9000000000000004,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20574
      },
      "nvd": {
        "published": "2026-07-01T18:16:36.107",
        "lastModified": "2026-07-07T18:40:36.247",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58521",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://phabricator.wikimedia.org/T428274",
          "host": "phabricator.wikimedia.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://gerrit.wikimedia.org/r/c/1298854",
          "host": "gerrit.wikimedia.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 261,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58522",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.869Z",
      "date_published": "2026-07-03T20:35:17.493Z",
      "date_updated": "2026-08-03T22:58:37.551Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge for Android Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24728
      },
      "nvd": {
        "published": "2026-07-03T21:17:05.883",
        "lastModified": "2026-07-07T22:52:45.193",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58522",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A relative path accepted by Microsoft Edge for Android can escape the intended directory and select a local file outside that namespace.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58522",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 118,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58523",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.869Z",
      "date_published": "2026-07-03T21:26:27.550Z",
      "date_updated": "2026-08-03T22:58:38.098Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge for Android Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00475,
        "percentile": 0.38591
      },
      "nvd": {
        "published": "2026-07-03T22:16:55.740",
        "lastModified": "2026-07-07T22:58:03.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58523",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft Edge (Chromium-based) permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58523",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58524",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.869Z",
      "date_published": "2026-07-03T20:35:35.191Z",
      "date_updated": "2026-08-03T22:58:38.757Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15121
      },
      "nvd": {
        "published": "2026-07-03T21:17:06.000",
        "lastModified": "2026-07-06T19:38:50.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58524",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Edge inserts attacker-controlled page input into generated web content without sufficient script-context neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58524",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58525",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.869Z",
      "date_published": "2026-07-08T20:43:49.795Z",
      "date_updated": "2026-08-03T22:58:39.398Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29758
      },
      "nvd": {
        "published": "2026-07-08T21:16:54.300",
        "lastModified": "2026-07-09T17:16:53.867",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58525",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft Edge permits a remote unauthenticated caller to cross an access-control boundary, but the protected object and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58525",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 135,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58526",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.869Z",
      "date_published": "2026-07-14T17:05:26.560Z",
      "date_updated": "2026-08-03T22:53:45.950Z",
      "publisher": "microsoft",
      "title": "Windows Storage Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00148,
        "percentile": 0.045
      },
      "nvd": {
        "published": "2026-07-14T17:17:12.387",
        "lastModified": "2026-07-22T16:18:35.737",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58526",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Storage accesses an object after it has been freed during a local privileged operation.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58526",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-58527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.869Z",
      "date_published": "2026-07-14T17:09:57.011Z",
      "date_updated": "2026-08-03T22:58:39.961Z",
      "publisher": "microsoft",
      "title": "Windows Runtime Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09939
      },
      "nvd": {
        "published": "2026-07-14T18:18:39.207",
        "lastModified": "2026-07-22T16:18:35.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58527",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent Windows 11 Version 24H2 operations can observe or mutate shared state without the synchronization required to preserve the security invariant.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58527",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 171,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-58528",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.869Z",
      "date_published": "2026-07-14T17:09:57.639Z",
      "date_updated": "2026-08-03T22:58:40.507Z",
      "publisher": "microsoft",
      "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00488,
        "percentile": 0.39403
      },
      "nvd": {
        "published": "2026-07-14T18:18:39.360",
        "lastModified": "2026-07-22T16:18:36.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58528",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows USB audio driver reads beyond an allocated buffer during a physical attack path.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58528",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 147,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-58529",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.869Z",
      "date_published": "2026-07-14T17:10:18.062Z",
      "date_updated": "2026-08-03T22:59:12.527Z",
      "publisher": "microsoft",
      "title": "Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00948,
        "percentile": 0.5774
      },
      "nvd": {
        "published": "2026-07-14T18:18:39.550",
        "lastModified": "2026-07-16T13:45:02.420",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58529",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 11 version 26H1, an attacker-controlled index or length permits a read beyond the valid memory region.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58529",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.869Z",
      "date_published": "2026-07-14T17:09:58.279Z",
      "date_updated": "2026-08-03T22:58:41.048Z",
      "publisher": "microsoft",
      "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26398
      },
      "nvd": {
        "published": "2026-07-14T18:18:39.697",
        "lastModified": "2026-07-22T16:18:36.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58530",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 copies, writes, or indexes attacker-influenced data without enforcing the destination buffer or object bounds required by the operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58530",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-58531",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.869Z",
      "date_published": "2026-07-14T17:10:02.177Z",
      "date_updated": "2026-08-03T22:58:49.750Z",
      "publisher": "microsoft",
      "title": "Windows SMB Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00599,
        "percentile": 0.45301
      },
      "nvd": {
        "published": "2026-07-14T18:18:39.853",
        "lastModified": "2026-07-22T16:18:36.417",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58531",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A synchronization race in Windows SMB leaves an object reachable after it has been freed.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58531",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 174,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58532",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.869Z",
      "date_published": "2026-07-14T17:10:02.727Z",
      "date_updated": "2026-08-03T22:58:50.232Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23479
      },
      "nvd": {
        "published": "2026-07-14T18:18:40.027",
        "lastModified": "2026-07-22T16:18:36.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58532",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 performs unchecked integer arithmetic that wraps and produces an invalid allocation size, offset, or length.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58532",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58533",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:09:59.251Z",
      "date_updated": "2026-08-03T22:58:42.156Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00868,
        "percentile": 0.55233
      },
      "nvd": {
        "published": "2026-07-14T18:18:40.203",
        "lastModified": "2026-07-22T16:18:36.783",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58533",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows RDP client uses an uninitialized resource and returns residual data over the network.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58533",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58534",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:10:03.702Z",
      "date_updated": "2026-08-03T22:58:51.498Z",
      "publisher": "microsoft",
      "title": "Windows Input Method Editor (IME) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.0000000000000009,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24116
      },
      "nvd": {
        "published": "2026-07-14T18:18:40.380",
        "lastModified": "2026-07-22T16:18:36.963",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58534",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Input Method Editor writes beyond a heap buffer during a local authorized operation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58534",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-58535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:09:59.810Z",
      "date_updated": "2026-08-03T22:58:47.484Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00868,
        "percentile": 0.55232
      },
      "nvd": {
        "published": "2026-07-14T18:18:40.563",
        "lastModified": "2026-07-22T17:39:38.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58535",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows RDP exposes residual data from an uninitialized resource over the network.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58535",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:10:04.340Z",
      "date_updated": "2026-08-03T22:58:52.005Z",
      "publisher": "microsoft",
      "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0195,
        "percentile": 0.78237
      },
      "nvd": {
        "published": "2026-07-14T18:18:40.770",
        "lastModified": "2026-07-22T17:40:48.370",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58536",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58536",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-58537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:10:03.226Z",
      "date_updated": "2026-08-03T22:58:50.959Z",
      "publisher": "microsoft",
      "title": "Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.2344
      },
      "nvd": {
        "published": "2026-07-14T18:18:40.927",
        "lastModified": "2026-07-23T05:16:38.073",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58537",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58537",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 125,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-58538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:09:58.755Z",
      "date_updated": "2026-08-03T22:58:41.587Z",
      "publisher": "microsoft",
      "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23436
      },
      "nvd": {
        "published": "2026-07-14T18:18:41.060",
        "lastModified": "2026-07-22T16:18:37.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58538",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected handler writes attacker-controlled data beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58538",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-58539",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:10:01.003Z",
      "date_updated": "2026-08-03T22:58:48.672Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00868,
        "percentile": 0.55232
      },
      "nvd": {
        "published": "2026-07-14T18:18:41.200",
        "lastModified": "2026-07-22T16:18:37.980",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58539",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 can read beyond the valid bounds of an input or object allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58539",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58540",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:10:01.622Z",
      "date_updated": "2026-08-03T22:58:49.283Z",
      "publisher": "microsoft",
      "title": "Windows Installer Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.2
      },
      "nvd": {
        "published": "2026-07-14T18:18:41.377",
        "lastModified": "2026-07-22T16:18:38.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58540",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58540",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58541",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:10:07.732Z",
      "date_updated": "2026-08-03T22:58:55.132Z",
      "publisher": "microsoft",
      "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21177
      },
      "nvd": {
        "published": "2026-07-14T18:18:41.560",
        "lastModified": "2026-07-22T16:18:38.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58541",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 interprets a memory object through an incompatible type and then performs an invalid access.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58541",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 137,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-58542",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:10:06.641Z",
      "date_updated": "2026-08-03T22:58:54.102Z",
      "publisher": "microsoft",
      "title": "Windows Media Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00341,
        "percentile": 0.26722
      },
      "nvd": {
        "published": "2026-07-14T18:18:42.153",
        "lastModified": "2026-07-22T16:18:38.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58542",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Media copies attacker-influenced data beyond a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58542",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-58543",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:10:07.185Z",
      "date_updated": "2026-08-03T22:58:54.574Z",
      "publisher": "microsoft",
      "title": "Universal Print Management Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06772
      },
      "nvd": {
        "published": "2026-07-14T18:18:42.280",
        "lastModified": "2026-07-22T16:18:38.640",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58543",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A race permits an object to be used after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58543",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-58544",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:10:06.008Z",
      "date_updated": "2026-08-03T22:58:53.537Z",
      "publisher": "microsoft",
      "title": "Windows Management Services Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13784
      },
      "nvd": {
        "published": "2026-07-14T18:18:42.400",
        "lastModified": "2026-07-22T16:18:38.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58544",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Management Services dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA record",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58544",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-58545",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:10:05.509Z",
      "date_updated": "2026-08-03T22:58:53.062Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15254
      },
      "nvd": {
        "published": "2026-07-14T18:18:42.543",
        "lastModified": "2026-07-22T16:18:38.890",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58545",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Windows 10 Version 1607 permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58545",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58546",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.870Z",
      "date_published": "2026-07-14T17:10:00.447Z",
      "date_updated": "2026-08-03T22:58:48.060Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00503,
        "percentile": 0.40262
      },
      "nvd": {
        "published": "2026-07-14T18:18:42.720",
        "lastModified": "2026-07-22T16:18:39.067",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58546",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows RDP returns data from an uninitialized resource to a remote caller.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58546",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58547",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T04:33:41.871Z",
      "date_published": "2026-07-14T17:10:04.889Z",
      "date_updated": "2026-08-03T22:58:52.585Z",
      "publisher": "microsoft",
      "title": "Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00353,
        "percentile": 0.28019
      },
      "nvd": {
        "published": "2026-07-14T18:18:42.907",
        "lastModified": "2026-07-22T16:18:39.250",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58547",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows 10 Version 1809, an attacker-controlled index or length permits a write beyond the destination memory region.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58547",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 125,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-58549",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T10:03:11.402Z",
      "date_published": "2026-07-15T12:04:34.945Z",
      "date_updated": "2026-07-15T13:45:36.672Z",
      "publisher": "huawei",
      "title": "Out-of-bounds read vulnerability in the image codec module.",
      "affected": {
        "vendors": [
          "Huawei"
        ],
        "products": [
          {
            "vendor": "Huawei",
            "product": "HarmonyOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:psirt@huawei.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00089,
        "percentile": 0.00499
      },
      "nvd": {
        "published": "2026-07-15T13:17:27.550",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58549",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The image codec reads beyond a valid buffer boundary, while the structured record maps the flaw to a copy overflow rather than an out-of-bounds read.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://consumer.huawei.com/en/support/bulletin/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinvision/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinwearables/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinlaptops/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58550",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T10:03:11.402Z",
      "date_published": "2026-07-15T12:06:55.860Z",
      "date_updated": "2026-07-15T13:47:15.223Z",
      "publisher": "huawei",
      "title": "Out-of-bounds read vulnerability in the image codec module.",
      "affected": {
        "vendors": [
          "Huawei"
        ],
        "products": [
          {
            "vendor": "Huawei",
            "product": "HarmonyOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:psirt@huawei.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00089,
        "percentile": 0.005
      },
      "nvd": {
        "published": "2026-07-15T13:17:28.587",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58550",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The image codec reads beyond a valid buffer boundary, although the structured buffer-copy CWE does not match the disclosed read operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://consumer.huawei.com/en/support/bulletin/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinvision/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinwearables/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinlaptops/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58551",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T10:03:11.402Z",
      "date_published": "2026-07-15T12:11:05.102Z",
      "date_updated": "2026-07-15T13:44:54.421Z",
      "publisher": "huawei",
      "title": "Out-of-bounds read vulnerability in the image codec module.",
      "affected": {
        "vendors": [
          "Huawei"
        ],
        "products": [
          {
            "vendor": "Huawei",
            "product": "HarmonyOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:psirt@huawei.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00088,
        "percentile": 0.00472
      },
      "nvd": {
        "published": "2026-07-15T13:17:28.783",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58551",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Huawei's image codec reads beyond an input buffer, while the supplied CWE-120 label describes a generic buffer copy rather than the disclosed read boundary.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://consumer.huawei.com/en/support/bulletin/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinvision/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinwearables/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinlaptops/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58552",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T10:03:11.403Z",
      "date_published": "2026-07-15T12:13:08.618Z",
      "date_updated": "2026-07-15T13:14:22.767Z",
      "publisher": "huawei",
      "title": "Out-of-bounds read vulnerability in the image codec module.",
      "affected": {
        "vendors": [
          "Huawei"
        ],
        "products": [
          {
            "vendor": "Huawei",
            "product": "HarmonyOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:psirt@huawei.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00088,
        "percentile": 0.00472
      },
      "nvd": {
        "published": "2026-07-15T13:17:28.917",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58552",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A crafted input permits a read beyond the end of the allocated buffer.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://consumer.huawei.com/en/support/bulletin/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinvision/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinwearables/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinlaptops/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58553",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T10:03:11.403Z",
      "date_published": "2026-07-15T12:16:27.819Z",
      "date_updated": "2026-07-15T13:09:03.769Z",
      "publisher": "huawei",
      "title": "Out-of-bounds read vulnerability in the image codec module.",
      "affected": {
        "vendors": [
          "Huawei"
        ],
        "products": [
          {
            "vendor": "Huawei",
            "product": "HarmonyOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:psirt@huawei.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00089,
        "percentile": 0.005
      },
      "nvd": {
        "published": "2026-07-15T13:17:29.307",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58553",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The HarmonyOS path processes attacker-controlled data without a sufficient memory-boundary check.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://consumer.huawei.com/en/support/bulletin/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinvision/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinwearables/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinlaptops/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58554",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T10:03:11.403Z",
      "date_published": "2026-07-15T12:23:35.218Z",
      "date_updated": "2026-07-15T13:07:20.431Z",
      "publisher": "huawei",
      "title": "Permission control vulnerability in the Settings module.",
      "affected": {
        "vendors": [
          "Huawei"
        ],
        "products": [
          {
            "vendor": "Huawei",
            "product": "HarmonyOS"
          },
          {
            "vendor": "Huawei",
            "product": "EMUI"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:psirt@huawei.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00077,
        "percentile": 0.00144
      },
      "nvd": {
        "published": "2026-07-15T13:17:29.730",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58554",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Settings component exposes information through a permission-control failure, but the protected object and failing authorization check are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://consumer.huawei.com/en/support/bulletin/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-58555",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T10:03:11.403Z",
      "date_published": "2026-07-15T12:18:07.236Z",
      "date_updated": "2026-07-15T13:07:59.827Z",
      "publisher": "huawei",
      "title": "Permission bypass vulnerability in the card module.",
      "affected": {
        "vendors": [
          "Huawei"
        ],
        "products": [
          {
            "vendor": "Huawei",
            "product": "HarmonyOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-264",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:psirt@huawei.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0008,
        "percentile": 0.0023
      },
      "nvd": {
        "published": "2026-07-15T13:17:30.233",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58555",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Huawei reports that the card module permits an operation outside its permission boundary, while the public record does not identify the role, object, or action check.",
        "basis": [
          "CNA",
          "CWE-264"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://consumer.huawei.com/en/support/bulletin/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinlaptops/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58556",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T10:03:11.403Z",
      "date_published": "2026-07-15T12:38:23.731Z",
      "date_updated": "2026-07-15T13:04:22.387Z",
      "publisher": "huawei",
      "title": "Permission control vulnerability in the Bluetooth module.",
      "affected": {
        "vendors": [
          "Huawei"
        ],
        "products": [
          {
            "vendor": "Huawei",
            "product": "Harmony OS"
          },
          {
            "vendor": "Huawei",
            "product": "EMUI"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-264",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:psirt@huawei.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0008,
        "percentile": 0.00206
      },
      "nvd": {
        "published": "2026-07-15T13:17:30.510",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58556",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Huawei reports a Bluetooth permission-control failure affecting availability but does not disclose the subject, operation, or permission rule.",
        "basis": [
          "CNA",
          "CWE-264"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://consumer.huawei.com/en/support/bulletin/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-58557",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T10:03:11.403Z",
      "date_published": "2026-07-15T12:31:38.012Z",
      "date_updated": "2026-07-15T13:06:57.722Z",
      "publisher": "huawei",
      "title": "Design defect vulnerability in Expedition mode.",
      "affected": {
        "vendors": [
          "Huawei"
        ],
        "products": [
          {
            "vendor": "Huawei",
            "product": "HarmonyOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-701",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:psirt@huawei.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0007,
        "percentile": 0.00051
      },
      "nvd": {
        "published": "2026-07-15T13:17:30.617",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58557",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports only an Expedition-mode design defect and availability impact, without a state, input, resource, or failed invariant that supports cause classification.",
        "basis": [
          "CNA",
          "CWE-701"
        ],
        "deepDive": false,
        "notes": "The public record does not expose enough implementation detail to classify the enabling cause."
      },
      "references": [
        {
          "url": "https://consumer.huawei.com/en/support/bulletin/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58558",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T10:03:11.403Z",
      "date_published": "2026-07-15T12:40:08.766Z",
      "date_updated": "2026-07-15T13:03:58.948Z",
      "publisher": "huawei",
      "title": "Permission control vulnerability in the file system.",
      "affected": {
        "vendors": [
          "Huawei"
        ],
        "products": [
          {
            "vendor": "Huawei",
            "product": "Harmony OS"
          },
          {
            "vendor": "Huawei",
            "product": "EMUI"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-840",
          "name": "",
          "abstraction": "",
          "status": "",
          "mappingUsage": "",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:psirt@huawei.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00084,
        "percentile": 0.00338
      },
      "nvd": {
        "published": "2026-07-15T13:17:31.053",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58558",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Huawei identifies a filesystem permission-control failure affecting confidentiality, while the public record does not disclose the selected object or permission comparison.",
        "basis": [
          "CNA",
          "CWE-840"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://consumer.huawei.com/en/support/bulletin/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://consumer.huawei.com/en/support/bulletinvision/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-58559",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T10:03:11.403Z",
      "date_published": "2026-07-15T12:42:28.974Z",
      "date_updated": "2026-07-15T13:03:19.123Z",
      "publisher": "huawei",
      "title": "DoS vulnerability in the vibration service.",
      "affected": {
        "vendors": [
          "Huawei"
        ],
        "products": [
          {
            "vendor": "Huawei",
            "product": "Harmony OS"
          },
          {
            "vendor": "Huawei",
            "product": "EMUI"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:psirt@huawei.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03977
      },
      "nvd": {
        "published": "2026-07-15T13:17:31.283",
        "lastModified": "2026-07-15T16:24:31.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58559",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The service accepts an allocation size without an effective upper bound.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://consumer.huawei.com/en/support/bulletin/2026/7/",
          "host": "consumer.huawei.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-58578",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T15:00:11.163Z",
      "date_published": "2026-07-02T19:38:21.378Z",
      "date_updated": "2026-07-14T22:03:18.391Z",
      "publisher": "VulnCheck",
      "title": "LobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub Skill Import",
      "affected": {
        "vendors": [
          "lobehub"
        ],
        "products": [
          {
            "vendor": "lobehub",
            "product": "lobehub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22827
      },
      "nvd": {
        "published": "2026-07-02T20:17:06.870",
        "lastModified": "2026-07-14T23:17:32.610",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58578",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "lobehub applies an algorithm with attacker-triggered worst-case complexity without a work bound, allowing CPU exhaustion.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lobehub/lobehub/releases/tag/v2.2.10-canary.15",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/lobehub/lobehub/issues/16494",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/lobehub/lobehub/pull/16548",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/lobehub/lobehub/commit/349bbe326eb8635d6d9c6a96d12702681ae3a84a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/lobechat-canary-15-regular-expression-denial-of-service-in-github-skill-import",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 635,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58579",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T15:00:11.163Z",
      "date_published": "2026-07-02T19:38:51.314Z",
      "date_updated": "2026-07-14T22:03:19.038Z",
      "publisher": "VulnCheck",
      "title": "RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name",
      "affected": {
        "vendors": [
          "infiniflow"
        ],
        "products": [
          {
            "vendor": "infiniflow",
            "product": "ragflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00182,
        "percentile": 0.07965
      },
      "nvd": {
        "published": "2026-07-02T20:17:07.003",
        "lastModified": "2026-07-14T23:17:32.730",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58579",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Narrator Braille path places attacker-controlled elements into a privileged command without command-context neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/infiniflow/ragflow/releases/tag/v0.26.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/infiniflow/ragflow/issues/16507",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/infiniflow/ragflow/pull/16516",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/infiniflow/ragflow/commit/572f1ea9f4eba6a60e64f7437dee60aa1c0913f1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ragflow-stored-cross-site-scripting-via-agent-pipeline-node-name",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 777,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58580",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T15:00:11.164Z",
      "date_published": "2026-07-02T19:39:19.653Z",
      "date_updated": "2026-07-14T22:03:19.695Z",
      "publisher": "VulnCheck",
      "title": "LobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource Writes",
      "affected": {
        "vendors": [
          "lobehub"
        ],
        "products": [
          {
            "vendor": "lobehub",
            "product": "lobehub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0.09999999999999964,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05108
      },
      "nvd": {
        "published": "2026-07-02T20:17:07.133",
        "lastModified": "2026-07-14T23:17:32.857",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58580",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LobeChat updates message subresources by message ID alone and omits the userId owner scope applied by sibling methods.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lobehub/lobehub/issues/16534",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/lobechat-broken-object-level-authorization-in-message-sub-resource-writes",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 757,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58583",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T15:47:30.055Z",
      "date_published": "2026-07-07T20:33:38.658Z",
      "date_updated": "2026-07-21T17:04:11.426Z",
      "publisher": "cisa-cg",
      "title": "FluxInk Color Management Driver local privilege escalation",
      "affected": {
        "vendors": [
          "FluxInk"
        ],
        "products": [
          {
            "vendor": "FluxInk",
            "product": "Color Management Driver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00101,
        "percentile": 0.0108
      },
      "nvd": {
        "published": "2026-07-07T21:17:29.163",
        "lastModified": "2026-07-21T18:17:03.207",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58583",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The driver lets a standard user map arbitrary physical memory without restricting that privileged mapping operation to an authorized principal.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/b3s3da/TcnPeripheral64_PoC/security/advisories/GHSA-x4rw-h4v2-v83h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/b3s3da/TcnPeripheral64_PoC",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-58583",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-188-01.json",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58586",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T16:57:56.074Z",
      "date_published": "2026-07-24T15:02:22.783Z",
      "date_updated": "2026-07-31T19:19:15.967Z",
      "publisher": "CPANSec",
      "title": "Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp",
      "affected": {
        "vendors": [
          "ZAPAD"
        ],
        "products": [
          {
            "vendor": "ZAPAD",
            "product": "Image::WebP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1395",
          "name": "Dependency on Vulnerable Third-Party Component",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00408,
        "percentile": 0.33546
      },
      "nvd": {
        "published": "2026-07-24T15:18:44.997",
        "lastModified": "2026-07-31T20:16:52.737",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58586",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Perl module statically bundles a vulnerable 2013 libwebp decoder, so system-library upgrades do not replace the reachable decoder.",
        "basis": [
          "CNA",
          "CWE-1395"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/ZAPAD/Image-WebP-0.2/source/webp-src/NEWS",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4863",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://metacpan.org/release/ZAPAD/Image-WebP-0.3.0/source/Changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 459,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58587",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T17:08:05.252Z",
      "date_published": "2026-07-10T21:46:15.116Z",
      "date_updated": "2026-07-13T16:08:13.354Z",
      "publisher": "drupal",
      "title": "Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Drupal Canvas"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04581
      },
      "nvd": {
        "published": "2026-07-10T22:16:44.953",
        "lastModified": "2026-07-21T15:41:23.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58587",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Drupal Canvas allows attacker input to reach generated page markup without sufficient browser-context neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-065",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-58588",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T17:08:05.253Z",
      "date_published": "2026-07-10T21:46:15.991Z",
      "date_updated": "2026-07-13T16:03:49.195Z",
      "publisher": "drupal",
      "title": "Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Drupal Canvas"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.0486
      },
      "nvd": {
        "published": "2026-07-10T22:16:45.070",
        "lastModified": "2026-07-21T15:40:25.577",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58588",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Drupal Canvas, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-066",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-58589",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T17:08:05.253Z",
      "date_published": "2026-07-10T21:46:16.889Z",
      "date_updated": "2026-07-13T17:47:17.164Z",
      "publisher": "drupal",
      "title": "FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "FlowDrop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03869
      },
      "nvd": {
        "published": "2026-07-10T22:16:45.183",
        "lastModified": "2026-07-14T19:26:37.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58589",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "FlowDrop fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-067",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58590",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T17:08:05.253Z",
      "date_published": "2026-07-10T21:46:17.722Z",
      "date_updated": "2026-07-13T17:48:20.835Z",
      "publisher": "drupal",
      "title": "FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "FlowDrop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00141,
        "percentile": 0.0387
      },
      "nvd": {
        "published": "2026-07-10T22:16:45.277",
        "lastModified": "2026-07-14T18:55:16.783",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58590",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "FlowDrop functionality is reachable by direct navigation without enforcing the authorization required for the requested action.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-068",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 139,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58591",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T17:08:05.253Z",
      "date_published": "2026-07-10T21:46:18.632Z",
      "date_updated": "2026-07-13T18:16:59.392Z",
      "publisher": "drupal",
      "title": "Colorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069",
      "affected": {
        "vendors": [
          "Drupal"
        ],
        "products": [
          {
            "vendor": "Drupal",
            "product": "Colorbox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03454
      },
      "nvd": {
        "published": "2026-07-10T22:16:45.387",
        "lastModified": "2026-07-14T18:33:02.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58591",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Colorbox renders attacker-controlled content without the required HTML sanitization or output escaping, allowing cross-site scripting.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.drupal.org/sa-contrib-2026-069",
          "host": "www.drupal.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58592",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T17:20:57.549Z",
      "date_published": "2026-07-01T19:27:22.629Z",
      "date_updated": "2026-07-02T15:55:07.091Z",
      "publisher": "VulnCheck",
      "title": "Ladybird - Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssembly ESM Integration",
      "affected": {
        "vendors": [
          "LadybirdBrowser"
        ],
        "products": [
          {
            "vendor": "LadybirdBrowser",
            "product": "Ladybird"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-825",
          "name": "Expired Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23488
      },
      "nvd": {
        "published": "2026-07-01T20:17:11.600",
        "lastModified": "2026-07-02T17:42:23.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58592",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A host callback retains a reference to a stack-local FunctionType after it is destroyed, leading to stale type data and an arbitrary write.",
        "basis": [
          "CNA",
          "CWE-787",
          "CWE-825",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/ladybird-wasm-esm-host-function-rce-poc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/LadybirdBrowser/ladybird/blob/master/Libraries/LibWeb/WebAssembly/WebAssemblyModule.cpp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ladybird-web-reachable-code-execution-via-dangling-functiontype-reference-in-webassembly-esm-integration",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1061,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58593",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T17:20:57.549Z",
      "date_published": "2026-07-01T19:27:23.367Z",
      "date_updated": "2026-07-07T12:50:17.730Z",
      "publisher": "VulnCheck",
      "title": "NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User",
      "affected": {
        "vendors": [
          "NodeBB"
        ],
        "products": [
          {
            "vendor": "NodeBB",
            "product": "NodeBB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11431
      },
      "nvd": {
        "published": "2026-07-01T20:17:11.750",
        "lastModified": "2026-07-07T13:16:32.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58593",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NodeBB verifies the remote ActivityPub actor but does not bind attributedTo to that actor before mapping it to a local user ID.",
        "basis": [
          "CNA",
          "CWE-290",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bikini/exploitarium/tree/main/nodebb-activitypub-attributedto-local-uid-spoof-poc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/NodeBB/NodeBB/blob/v4.13.2/src/activitypub/mocks.js",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/nodebb-activitypub-author-spoofing-via-unvalidated-attributedto-mapped-to-local-user",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 792,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58594",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.124Z",
      "date_published": "2026-07-14T17:10:08.306Z",
      "date_updated": "2026-08-03T22:58:55.680Z",
      "publisher": "microsoft",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00767,
        "percentile": 0.51995
      },
      "nvd": {
        "published": "2026-07-14T18:18:43.067",
        "lastModified": "2026-07-22T16:18:39.420",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58594",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows RDP permits integer arithmetic to wrap and corrupt a memory-size or bounds calculation used on network input.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58594",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58595",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.124Z",
      "date_published": "2026-07-14T17:05:27.106Z",
      "date_updated": "2026-08-03T22:53:46.529Z",
      "publisher": "microsoft",
      "title": "Microsoft Bing App for IOS Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Bing Search for iOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1021",
          "name": "Improper Restriction of Rendered UI Layers or Frames",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00459,
        "percentile": 0.37516
      },
      "nvd": {
        "published": "2026-07-14T17:17:12.530",
        "lastModified": "2026-07-24T12:42:22.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58595",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.",
        "basis": [
          "CNA",
          "CWE-1021"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58595",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 150,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58596",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.124Z",
      "date_published": "2026-07-12T15:22:59.392Z",
      "date_updated": "2026-08-03T22:58:56.181Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-822",
          "name": "Untrusted Pointer Dereference",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0048,
        "percentile": 0.3886
      },
      "nvd": {
        "published": "2026-07-12T16:16:31.350",
        "lastModified": "2026-07-14T05:16:18.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58596",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.",
        "basis": [
          "CNA",
          "CWE-822"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58596",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58597",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.124Z",
      "date_published": "2026-07-03T20:35:35.815Z",
      "date_updated": "2026-08-03T22:58:56.721Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-357",
          "name": "Insufficient UI Warning of Dangerous Operations",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00398,
        "percentile": 0.32577
      },
      "nvd": {
        "published": "2026-07-03T21:17:06.127",
        "lastModified": "2026-07-06T19:44:18.837",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58597",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-357"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58597",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 150,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58598",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.124Z",
      "date_published": "2026-07-16T21:57:56.220Z",
      "date_updated": "2026-08-03T22:53:57.725Z",
      "publisher": "microsoft",
      "title": "Windows Backup Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08671
      },
      "nvd": {
        "published": "2026-07-16T22:17:50.330",
        "lastModified": "2026-07-22T18:19:14.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58598",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A race in the Windows Backup Engine permits one path to free shared state while another path still uses it during a local privilege-sensitive operation.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58598",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 177,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-58601",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.125Z",
      "date_published": "2026-07-14T17:05:29.543Z",
      "date_updated": "2026-08-03T22:53:48.721Z",
      "publisher": "microsoft",
      "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 16,
        "versionEntryCount": 16,
        "versionRangeCount": 16,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.13024
      },
      "nvd": {
        "published": "2026-07-14T17:17:12.657",
        "lastModified": "2026-07-22T16:18:39.953",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58601",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data is written beyond the boundary of a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58601",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 16,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-58602",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.125Z",
      "date_published": "2026-07-14T17:05:30.180Z",
      "date_updated": "2026-08-03T22:53:49.267Z",
      "publisher": "microsoft",
      "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.13023
      },
      "nvd": {
        "published": "2026-07-14T17:17:12.817",
        "lastModified": "2026-07-22T16:18:40.123",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58602",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 11 Version 24H2 accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58602",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-58608",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.125Z",
      "date_published": "2026-07-14T17:05:30.868Z",
      "date_updated": "2026-08-03T22:53:49.724Z",
      "publisher": "microsoft",
      "title": "Windows Print Spooler Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00425,
        "percentile": 0.34966
      },
      "nvd": {
        "published": "2026-07-14T17:17:12.930",
        "lastModified": "2026-07-22T16:18:40.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58608",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Concurrent Print Spooler operations access a shared resource without sufficient synchronization, but the raced object and invalid transition are not public.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58608",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58609",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.125Z",
      "date_published": "2026-07-14T17:05:31.418Z",
      "date_updated": "2026-08-03T22:53:50.274Z",
      "publisher": "microsoft",
      "title": "Windows Graphics Component Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23643
      },
      "nvd": {
        "published": "2026-07-14T17:17:13.097",
        "lastModified": "2026-07-22T16:18:40.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58609",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can cause a read beyond the bounds of a valid buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58609",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58610",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.125Z",
      "date_published": "2026-07-14T17:05:32.082Z",
      "date_updated": "2026-08-03T22:53:50.746Z",
      "publisher": "microsoft",
      "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23644
      },
      "nvd": {
        "published": "2026-07-14T17:17:13.260",
        "lastModified": "2026-07-22T16:18:40.657",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58610",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted Media Foundation input writes beyond a heap buffer.",
        "basis": [
          "CNA record",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58610",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-58613",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.125Z",
      "date_published": "2026-07-14T17:10:10.648Z",
      "date_updated": "2026-08-03T22:58:57.825Z",
      "publisher": "microsoft",
      "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00447,
        "percentile": 0.36756
      },
      "nvd": {
        "published": "2026-07-14T18:18:44.007",
        "lastModified": "2026-07-22T16:18:40.823",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58613",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1809 retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58613",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2426",
          "host": "www.talosintelligence.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-58614",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.126Z",
      "date_published": "2026-07-14T17:05:32.689Z",
      "date_updated": "2026-08-03T22:53:51.206Z",
      "publisher": "microsoft",
      "title": "Windows Kernel Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20026
      },
      "nvd": {
        "published": "2026-07-14T17:17:13.413",
        "lastModified": "2026-07-22T16:18:40.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58614",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows kernel reads beyond an allocated buffer during a local security-feature check.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58614",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58617",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.126Z",
      "date_published": "2026-07-14T17:10:11.205Z",
      "date_updated": "2026-08-03T22:58:58.408Z",
      "publisher": "microsoft",
      "title": "M365 Copilot for iOS Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Copilot for iOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.00736,
        "percentile": 0.50946
      },
      "nvd": {
        "published": "2026-07-14T18:18:44.260",
        "lastModified": "2026-07-16T20:09:34.043",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58617",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft reports network privilege escalation in M365 Copilot for iOS, but the official surface does not disclose the protected action, subject, object, or access-control check.",
        "basis": [
          "CNA",
          "CWE-284",
          "MSRC"
        ],
        "deepDive": true,
        "notes": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58617 - the official page returned a JavaScript application shell in the inspected response and exposed no causal detail beyond the embedded improper-access-control record."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58617",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58618",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.126Z",
      "date_published": "2026-07-14T17:05:33.929Z",
      "date_updated": "2026-08-03T22:53:52.229Z",
      "publisher": "microsoft",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft 365 Apps for Enterprise"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Excel 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office 365 for Mac"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2021"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft Office LTSC for Mac 2024"
          },
          {
            "vendor": "Microsoft",
            "product": "Office Online Server"
          }
        ],
        "affectedBlockCount": 9,
        "versionEntryCount": 9,
        "versionRangeCount": 9,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20458
      },
      "nvd": {
        "published": "2026-07-14T17:17:13.587",
        "lastModified": "2026-07-16T11:49:17.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58618",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input exceeds a heap allocation because the write is not bounded to the allocated size.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58618",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 109,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 9,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-58619",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T18:03:43.126Z",
      "date_published": "2026-07-14T17:10:11.842Z",
      "date_updated": "2026-08-03T22:58:58.951Z",
      "publisher": "microsoft",
      "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13785
      },
      "nvd": {
        "published": "2026-07-14T18:18:44.497",
        "lastModified": "2026-07-22T16:18:41.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58619",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Sensor Data Service accesses a freed object on a local authorized path.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58619",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-58624",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T19:10:57.224Z",
      "date_published": "2026-07-20T20:27:39.070Z",
      "date_updated": "2026-07-21T17:15:42.543Z",
      "publisher": "apache",
      "title": "Apache MINA SSHD: Remote execution of JGit commands can write files on the server",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache MINA SSHD"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00424,
        "percentile": 0.34933
      },
      "nvd": {
        "published": "2026-07-20T21:16:49.283",
        "lastModified": "2026-07-27T14:25:52.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58624",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GitPgmCommandFactory exposes the full JGit command set, including git archive --output, allowing an authenticated SSH user to choose arbitrary server file destinations.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7c3cry6pdy6hj1q0f28rc72x4o4tlyjo",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/18",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1145,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58626",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.616Z",
      "date_published": "2026-07-14T17:10:12.387Z",
      "date_updated": "2026-08-03T22:58:59.421Z",
      "publisher": "microsoft",
      "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00852,
        "percentile": 0.54673
      },
      "nvd": {
        "published": "2026-07-14T18:18:44.650",
        "lastModified": "2026-07-22T16:18:41.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58626",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Invalid bounds or lifetime handling permits access outside valid memory.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58626",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 111,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-58627",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.616Z",
      "date_published": "2026-07-14T17:10:12.940Z",
      "date_updated": "2026-08-03T22:59:00.055Z",
      "publisher": "microsoft",
      "title": "Windows DHCP Server Denial of Service Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 13,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00871,
        "percentile": 0.55338
      },
      "nvd": {
        "published": "2026-07-14T18:18:44.790",
        "lastModified": "2026-07-17T02:30:37.987",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58627",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Windows DHCP Server accepts network input that consumes resources without an effective bound, while the public record does not identify the resource or trigger.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58627",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 13,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-58628",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.616Z",
      "date_published": "2026-07-14T17:10:13.408Z",
      "date_updated": "2026-08-03T22:59:00.682Z",
      "publisher": "microsoft",
      "title": "Windows Wireless Network Manager Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.0793
      },
      "nvd": {
        "published": "2026-07-14T18:18:44.953",
        "lastModified": "2026-07-22T16:18:41.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58628",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent execution updates shared security state without the synchronization required to preserve the intended invariant.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58628",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-58629",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.616Z",
      "date_published": "2026-07-14T17:10:13.891Z",
      "date_updated": "2026-08-03T22:59:01.234Z",
      "publisher": "microsoft",
      "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 20,
        "versionEntryCount": 20,
        "versionRangeCount": 20,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13784
      },
      "nvd": {
        "published": "2026-07-14T18:18:45.093",
        "lastModified": "2026-07-29T19:16:47.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58629",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in Windows 10 Version 1607, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58629",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 20,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-58630",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.616Z",
      "date_published": "2026-07-24T14:36:54.192Z",
      "date_updated": "2026-08-03T22:59:16.760Z",
      "publisher": "microsoft",
      "title": "Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure App Service for Linux"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00815,
        "percentile": 0.53557
      },
      "nvd": {
        "published": "2026-07-24T15:18:47.847",
        "lastModified": "2026-07-25T05:16:35.847",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58630",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft reports an Azure App Service access-control failure but does not publish the affected object, principal binding, or permission check.",
        "basis": [
          "CNA",
          "CWE-284",
          "MSRC SUG API"
        ],
        "deepDive": true,
        "notes": "https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2026-58630 was inspected; Microsoft confirms CWE-284, a cloud-side mitigation, and no known exploitation but publishes no affected object or failed permission check."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58630",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58631",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.616Z",
      "date_published": "2026-07-14T17:05:34.500Z",
      "date_updated": "2026-08-03T22:53:52.692Z",
      "publisher": "microsoft",
      "title": "Windows Admin Center (WAC) Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows Admin Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21152
      },
      "nvd": {
        "published": "2026-07-14T17:17:13.717",
        "lastModified": "2026-07-17T02:36:56.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58631",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58631",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58632",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.617Z",
      "date_published": "2026-07-14T17:10:14.379Z",
      "date_updated": "2026-08-03T22:59:01.786Z",
      "publisher": "microsoft",
      "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 14,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21177
      },
      "nvd": {
        "published": "2026-07-14T18:18:45.370",
        "lastModified": "2026-07-22T16:18:42.137",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58632",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 10 Version 1607 can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58632",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 14,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-58633",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.617Z",
      "date_published": "2026-07-14T17:10:15.029Z",
      "date_updated": "2026-08-03T22:59:02.411Z",
      "publisher": "microsoft",
      "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23716
      },
      "nvd": {
        "published": "2026-07-14T18:18:45.530",
        "lastModified": "2026-07-15T17:52:11.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58633",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A reachable path retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58633",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58634",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.617Z",
      "date_published": "2026-07-14T17:10:15.507Z",
      "date_updated": "2026-08-03T22:59:02.967Z",
      "publisher": "microsoft",
      "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21177
      },
      "nvd": {
        "published": "2026-07-14T18:18:45.650",
        "lastModified": "2026-07-15T17:51:46.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58634",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows 11 version 26H1 accesses an object after its lifetime has ended and its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58634",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58635",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.617Z",
      "date_published": "2026-07-14T17:05:35.347Z",
      "date_updated": "2026-08-03T22:53:53.240Z",
      "publisher": "microsoft",
      "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 11,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.31445
      },
      "nvd": {
        "published": "2026-07-14T17:17:13.833",
        "lastModified": "2026-07-22T16:18:42.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58635",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Windows Narrator Braille places attacker-controlled elements into a privileged command without separating them from command syntax.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58635",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 172,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 11,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-58636",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.617Z",
      "date_published": "2026-07-14T17:05:36.008Z",
      "date_updated": "2026-08-03T22:53:53.870Z",
      "publisher": "microsoft",
      "title": "Microsoft PC Manager Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft PC Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18633
      },
      "nvd": {
        "published": "2026-07-14T17:17:13.970",
        "lastModified": "2026-07-17T02:35:05.437",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58636",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows PC Manager follows an attacker-controlled link before privileged file access, selecting a target outside the intended object.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58636",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 144,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58637",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.617Z",
      "date_published": "2026-07-14T17:10:15.986Z",
      "date_updated": "2026-08-03T22:59:03.531Z",
      "publisher": "microsoft",
      "title": "Windows Client-Side Caching Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 18,
        "versionEntryCount": 18,
        "versionRangeCount": 18,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13784
      },
      "nvd": {
        "published": "2026-07-14T18:18:45.947",
        "lastModified": "2026-07-22T16:18:42.647",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58637",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Client-Side Caching service accesses an object after it has been freed during a local operation.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58637",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 18,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-58638",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.618Z",
      "date_published": "2026-07-14T17:10:16.475Z",
      "date_updated": "2026-08-03T22:59:04.159Z",
      "publisher": "microsoft",
      "title": "Windows Boot Loader Security Feature Bypass Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 17,
        "versionEntryCount": 17,
        "versionRangeCount": 17,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-325",
          "name": "Missing Cryptographic Step",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13815
      },
      "nvd": {
        "published": "2026-07-14T18:18:46.137",
        "lastModified": "2026-07-22T16:18:42.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58638",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Windows 10 Version 1809 security flow omits a cryptographic verification step required before accepting the protected object.",
        "basis": [
          "CNA",
          "CWE-325"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58638",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 17,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-58640",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.618Z",
      "date_published": "2026-07-14T17:05:36.699Z",
      "date_updated": "2026-08-03T22:53:54.534Z",
      "publisher": "microsoft",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 10 Version 22H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 23H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 24H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 Version 25H2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2012 R2 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2016 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2019 (Server Core installation)"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2022"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025"
          },
          {
            "vendor": "Microsoft",
            "product": "Windows Server 2025 (Server Core installation)"
          }
        ],
        "affectedBlockCount": 20,
        "versionEntryCount": 20,
        "versionRangeCount": 20,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15256
      },
      "nvd": {
        "published": "2026-07-14T17:17:14.083",
        "lastModified": "2026-07-22T16:18:43.180",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58640",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NTFS writes beyond a heap allocation while processing attacker-controlled local input.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58640",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 20,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-58643",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.618Z",
      "date_published": "2026-07-16T21:57:55.681Z",
      "date_updated": "2026-08-03T22:53:57.164Z",
      "publisher": "microsoft",
      "title": "Windows Admin Center Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows Admin Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.1447
      },
      "nvd": {
        "published": "2026-07-16T22:17:52.370",
        "lastModified": "2026-07-22T16:31:09.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58643",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Windows Admin Center, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58643",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 176,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58644",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.618Z",
      "date_published": "2026-07-14T17:05:37.431Z",
      "date_updated": "2026-08-03T22:53:55.087Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.05985,
        "percentile": 0.92581
      },
      "official_kev": {
        "cveID": "CVE-2026-58644",
        "vendorProject": "Microsoft",
        "product": "SharePoint",
        "vulnerabilityName": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
        "dateAdded": "2026-07-16",
        "shortDescription": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-07-19",
        "knownRansomwareCampaignUse": "Unknown",
        "notes": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-58644",
        "cwes": [
          "CWE-502"
        ]
      },
      "nvd": {
        "published": "2026-07-14T17:17:14.257",
        "lastModified": "2026-07-17T05:16:40.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58644",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SharePoint deserializes attacker-controlled data as trusted object state, allowing crafted serialized content to invoke code-capable behavior on the server.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-502",
          "Microsoft CVRF and CISA KEV"
        ],
        "deepDive": true,
        "notes": "Inspected Microsoft's official July 2026 CVRF at https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jul, the advisory entry https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644, and CISA KEV at https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-58644; Microsoft and CISA confirm CWE-502 and exploitation, but the CVRF description/CVSS say no privileges while its FAQ says at least Site Owner, and no deserialization call site or patch diff is public."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58644",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 128,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58647",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:14:44.619Z",
      "date_published": "2026-07-14T17:05:38.090Z",
      "date_updated": "2026-08-03T22:53:55.550Z",
      "publisher": "microsoft",
      "title": "Microsoft PowerBI Report Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Power BI Report Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27454
      },
      "nvd": {
        "published": "2026-07-14T17:17:14.370",
        "lastModified": "2026-07-17T02:34:01.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58647",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Power BI renders an authorized attacker's input into a web page without correctly neutralizing browser script syntax.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58647",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 162,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58652",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:54:37.945Z",
      "date_published": "2026-07-02T12:28:34.022Z",
      "date_updated": "2026-07-02T13:16:44.529Z",
      "publisher": "VulnCheck",
      "title": "luci-app-travelmate - Arbitrary Command Execution via UCI Script Parameter",
      "affected": {
        "vendors": [
          "openwrt"
        ],
        "products": [
          {
            "vendor": "openwrt",
            "product": "luci-app-travelmate"
          },
          {
            "vendor": "openwrt",
            "product": "travelmate"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00482,
        "percentile": 0.3898
      },
      "nvd": {
        "published": "2026-07-02T13:17:00.300",
        "lastModified": "2026-07-02T18:02:15.983",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58652",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "travelmate executes a UCI-configured script and arguments as root even though the backend does not enforce the UI's script-path restriction.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openwrt/luci/security/advisories/GHSA-p35r-3323-6g7g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/openwrt/luci/commit/f85102548ee8325bfd581a0327b210b5f7670829",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/openwrt/luci/commit/491f1df06645c4e0757fed4a9f0622e9ce0d300c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/openwrt/luci/commit/71d92bcc9edbc8f95858ce82a8ff5d52500005a2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/openwrt/luci/commit/0627b412ee3a760cc4bca9fc8a5b73de8f33ac10",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/openwrt/luci/commit/d6e457a1a70a9010195edeafdc0b8eb6e3b0f7f1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/luci-app-travelmate-arbitrary-command-execution-via-uci-script-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 875,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-58653",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:54:37.945Z",
      "date_published": "2026-07-02T12:34:00.914Z",
      "date_updated": "2026-07-02T13:15:55.445Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/Update",
      "affected": {
        "vendors": [
          "PraisonAI"
        ],
        "products": [
          {
            "vendor": "PraisonAI",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05434
      },
      "nvd": {
        "published": "2026-07-02T13:17:00.453",
        "lastModified": "2026-07-02T18:47:12.757",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58653",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PraisonAI accepts a project_id without verifying that the project belongs to the workspace in the request URL.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2fjj-qqg8-fg7x",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-authorization-bypass-via-unvalidated-project-id-in-issue-create-update",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58654",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:54:37.946Z",
      "date_published": "2026-07-08T13:49:08.711Z",
      "date_updated": "2026-07-08T17:05:11.960Z",
      "publisher": "VulnCheck",
      "title": "Grav - Arbitrary File Upload via Avatar Endpoint",
      "affected": {
        "vendors": [
          "Grav"
        ],
        "products": [
          {
            "vendor": "Grav",
            "product": "Grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00261,
        "percentile": 0.1774
      },
      "nvd": {
        "published": "2026-07-08T14:17:20.153",
        "lastModified": "2026-07-08T18:16:33.873",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58654",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Grav avatar endpoint trusts a client-declared image MIME type and stores arbitrary content with an attacker-controlled effective extension.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-xc64-vh46-vph6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-arbitrary-file-upload-via-avatar-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 784,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58655",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:54:37.946Z",
      "date_published": "2026-07-15T11:25:34.186Z",
      "date_updated": "2026-07-28T13:02:09.024Z",
      "publisher": "VulnCheck",
      "title": "Grav Flex Objects - Server-Side Template Injection via Dynamic Titles",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.01084,
        "percentile": 0.61969
      },
      "nvd": {
        "published": "2026-07-15T12:18:17.367",
        "lastModified": "2026-07-15T21:02:13.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58655",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Grav Flex Objects stores attacker-controlled template syntax and evaluates it in the server-side Twig context.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-623v-m3c4-3pw8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-flex-objects-server-side-template-injection-via-dynamic-titles",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 728,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58656",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:54:37.946Z",
      "date_published": "2026-07-08T13:49:11.408Z",
      "date_updated": "2026-07-08T15:44:42.513Z",
      "publisher": "VulnCheck",
      "title": "Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parameter",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-598",
          "name": "Use of HTTP Request With Sensitive Query String",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00271,
        "percentile": 0.19296
      },
      "nvd": {
        "published": "2026-07-08T14:17:20.297",
        "lastModified": "2026-07-08T17:17:25.530",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58656",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The API accepts JWTs in URL query parameters and allows every CORS origin, so a leaked token can authorize credentialed requests from an attacker's site.",
        "basis": [
          "CNA",
          "CWE-598"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-hqm9-5xxw-4qxp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-api-plugin-cross-origin-admin-account-takeover-via-cors-wildcard-and-jwt-query-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 470,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-58657",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:54:37.946Z",
      "date_published": "2026-07-08T13:49:12.183Z",
      "date_updated": "2026-07-08T14:21:36.356Z",
      "publisher": "VulnCheck",
      "title": "Grav - Stored CSS Injection via Markdown Image resize() Action",
      "affected": {
        "vendors": [
          "Grav"
        ],
        "products": [
          {
            "vendor": "Grav",
            "product": "Grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12248
      },
      "nvd": {
        "published": "2026-07-08T14:17:20.440",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58657",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Grav writes attacker-controlled resize() arguments directly into an image style attribute, allowing stored CSS declarations.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-ffmg-hfvg-jhg9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/commit/6582166173bb8eb5869d96aea384e0e73777c94c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/commit/e03d29aa0d3ece16d73c1ffccfa78df8bf5f28b8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-stored-css-injection-via-markdown-image-resize-action",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 827,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58658",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:54:37.946Z",
      "date_published": "2026-07-15T17:00:30.407Z",
      "date_updated": "2026-07-15T18:12:23.313Z",
      "publisher": "VulnCheck",
      "title": "GPUStack Unauthenticated Information Disclosure via Worker Endpoints",
      "affected": {
        "vendors": [
          "gpustack"
        ],
        "products": [
          {
            "vendor": "gpustack",
            "product": "gpustack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.0039,
        "percentile": 0.31715
      },
      "nvd": {
        "published": "2026-07-15T18:16:48.607",
        "lastModified": "2026-07-15T21:02:41.590",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58658",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Worker log and debug endpoints expose prompts, completions, profiling data, and configuration changes without authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gpustack/gpustack/issues/5836",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/gpustack/gpustack/commit/4e20551b5aaf76f93a8769d32b7fef999e22a4d3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gpustack-unauthenticated-information-disclosure-via-worker-endpoints",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 476,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58659",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:54:37.946Z",
      "date_published": "2026-07-15T17:02:40.640Z",
      "date_updated": "2026-07-18T01:03:17.592Z",
      "publisher": "VulnCheck",
      "title": "PyTorch Lightning Arbitrary Code Execution via _instantiator Hyperparameter",
      "affected": {
        "vendors": [
          "Lightning-AI"
        ],
        "products": [
          {
            "vendor": "Lightning-AI",
            "product": "pytorch-lightning"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15226
      },
      "nvd": {
        "published": "2026-07-15T18:16:48.743",
        "lastModified": "2026-07-18T02:17:10.147",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58659",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Checkpoint hyperparameters select module names that _load_state imports and executes, bypassing the intended weights-only checkpoint boundary.",
        "basis": [
          "CNA",
          "CWE-470"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Lightning-AI/pytorch-lightning/issues/21822",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/Lightning-AI/pytorch-lightning/pull/21832",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/Lightning-AI/pytorch-lightning/commit/d710d689510d50e800f53b3cd773cbca20b1f86f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/pytorch-lightning-arbitrary-code-execution-via-instantiator-hyperparameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58660",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:54:37.946Z",
      "date_published": "2026-07-15T17:03:17.834Z",
      "date_updated": "2026-07-15T17:54:24.732Z",
      "publisher": "VulnCheck",
      "title": "Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop",
      "affected": {
        "vendors": [
          "kanboard"
        ],
        "products": [
          {
            "vendor": "kanboard",
            "product": "kanboard"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00355,
        "percentile": 0.2823
      },
      "nvd": {
        "published": "2026-07-15T18:16:48.880",
        "lastModified": "2026-07-15T21:02:41.590",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-58660",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kanboard/kanboard/issues/5852",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/kanboard/kanboard/pull/5853",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/kanboard/kanboard/commit/564cc30e1e360959572e01e158734d9475c05903",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/kanboard-boardajaxcontroller-missing-ownership-check-via-drag-and-drop",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-58661",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T21:54:37.946Z",
      "date_published": "2026-07-10T13:58:01.635Z",
      "date_updated": "2026-07-10T16:43:29.322Z",
      "publisher": "VulnCheck",
      "title": "n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13347
      },
      "nvd": {
        "published": "2026-07-10T15:16:47.987",
        "lastModified": "2026-07-13T16:57:20.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58661",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "n8n accepts attacker-driven work or allocation without an effective size, rate, release, or termination bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-w867-jm58-p9pv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-disk-space-exhaustion-via-data-table-file-upload-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 422,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-58662",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-01T22:13:52.362Z",
      "date_published": "2026-07-27T11:17:26.018Z",
      "date_updated": "2026-07-27T13:07:59.960Z",
      "publisher": "apache",
      "title": "Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.01148,
        "percentile": 0.63684
      },
      "nvd": {
        "published": "2026-07-27T12:16:46.807",
        "lastModified": "2026-07-27T19:51:48.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-58662",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "THeaderTransport::readString accepts an info-header length that bypasses quantity bounds and reads outside the input buffer.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/13mzvylr3r3nktxrh5k1h30ng1t1sw1d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/45",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59083",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T10:39:12.023Z",
      "date_published": "2026-07-14T08:13:04.861Z",
      "date_updated": "2026-07-14T12:19:54.438Z",
      "publisher": "apache",
      "title": "Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Tomcat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-177",
          "name": "Improper Handling of URL Encoding (Hex Encoding)",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29704
      },
      "nvd": {
        "published": "2026-07-14T09:16:41.483",
        "lastModified": "2026-07-14T16:57:31.103",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59083",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RewriteValve and authorization logic decode the URL differently, allowing a protected route constraint to be bypassed.",
        "basis": [
          "CNA",
          "CWE-177"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/3g63zos2gkjo5vgnrk8kxmosv47w6wbq",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/14/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-59084",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T10:42:32.668Z",
      "date_published": "2026-07-14T08:24:21.531Z",
      "date_updated": "2026-07-14T13:51:52.489Z",
      "publisher": "apache",
      "title": "Apache Tomcat: EncryptInterceptor requirements not clearly documented",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Tomcat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1059",
          "name": "Insufficient Technical Documentation",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Prohibited",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00506,
        "percentile": 0.40478
      },
      "nvd": {
        "published": "2026-07-14T09:16:41.607",
        "lastModified": "2026-07-14T16:57:03.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59084",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "Tomcat did not clearly document the requirements for a secure EncryptInterceptor deployment, but the missing requirement and unsafe configuration are not public.",
        "basis": [
          "CNA record",
          "CWE-1059",
          "Apache security advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7 through the official archive API; the advisory adds no configuration detail and labels severity Low, conflicting with the embedded CVSS 9.1 critical rating."
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/14/8",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-59089",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:11:12.820Z",
      "date_published": "2026-07-06T19:38:16.905Z",
      "date_updated": "2026-07-06T19:48:53.313Z",
      "publisher": "redhat",
      "title": "Gimp: gimp: denial of service via integer overflow in playstation tim loader",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16074
      },
      "nvd": {
        "published": "2026-07-06T20:16:38.433",
        "lastModified": "2026-07-10T16:09:55.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59089",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Red Hat Enterprise Linux 6 uses an unchecked integer result after arithmetic can overflow its representable range.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59089",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2496583",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Third Party Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/work_items/16493",
          "host": "gitlab.gnome.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Vendor Advisory",
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-59092",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:38:18.928Z",
      "date_published": "2026-07-02T19:39:57.471Z",
      "date_updated": "2026-07-14T22:03:20.357Z",
      "publisher": "VulnCheck",
      "title": "JuiceFS - Authentication Bypass via pprof and metrics Endpoints",
      "affected": {
        "vendors": [
          "juicedata"
        ],
        "products": [
          {
            "vendor": "juicedata",
            "product": "juicefs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-489",
          "name": "Active Debug Code",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18378
      },
      "nvd": {
        "published": "2026-07-02T20:17:07.270",
        "lastModified": "2026-07-14T23:17:32.973",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59092",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "JuiceFS registers pprof and metrics handlers on a shared default mux without authentication, leaving production debug state publicly reachable.",
        "basis": [
          "CNA",
          "CWE-489"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/juicedata/juicefs/issues/7213",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/juicedata/juicefs/pull/7214",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/juicedata/juicefs/commit/a46979cdd4082217081ee99b931ddc53d038e47a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/juicefs-authentication-bypass-via-pprof-and-metrics-endpoints",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59093",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:38:18.928Z",
      "date_published": "2026-07-02T19:40:22.778Z",
      "date_updated": "2026-07-14T22:03:21.017Z",
      "publisher": "VulnCheck",
      "title": "Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Role Assignment",
      "affected": {
        "vendors": [
          "weaviate"
        ],
        "products": [
          {
            "vendor": "weaviate",
            "product": "weaviate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31617
      },
      "nvd": {
        "published": "2026-07-02T20:17:07.410",
        "lastModified": "2026-07-14T23:17:33.100",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59093",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Weaviate authorizes assignment to a user or group but does not ensure the caller already holds every permission carried by the assigned role.",
        "basis": [
          "CNA",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/weaviate/weaviate/releases/tag/v1.38.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/weaviate/weaviate/pull/11493",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/weaviate/weaviate/commit/2c75f6fb217631f7751c4b2a7d37a488cef13edb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/weaviate-privilege-escalation-via-unchecked-permissions-in-rbac-role-assignment",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Release Notes",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 752,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59094",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:38:18.928Z",
      "date_published": "2026-07-02T19:40:50.961Z",
      "date_updated": "2026-07-14T22:03:21.697Z",
      "publisher": "VulnCheck",
      "title": "Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Store",
      "affected": {
        "vendors": [
          "pathwaycom"
        ],
        "products": [
          {
            "vendor": "pathwaycom",
            "product": "pathway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.0047,
        "percentile": 0.38231
      },
      "nvd": {
        "published": "2026-07-02T20:17:07.540",
        "lastModified": "2026-07-14T23:17:33.227",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59094",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A recursive glob matcher branches twice for each double-star token without memoization, creating exponential CPU work per indexed document.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pathwaycom/pathway/issues/241",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/pathwaycom/pathway/pull/250",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/pathwaycom/pathway/commit/d09722eef03fd94bba701836eb4c7fbfa3d3b88e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/pathway-unauthenticated-denial-of-service-via-exponential-glob-pattern-matching-in-document-store",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 682,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59095",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:38:18.928Z",
      "date_published": "2026-07-02T19:41:16.367Z",
      "date_updated": "2026-07-14T22:03:22.385Z",
      "publisher": "VulnCheck",
      "title": "LobeChat < 2.2.10-canary.18 - SSRF via importFromUrl and fetchImageFromUrl",
      "affected": {
        "vendors": [
          "lobehub"
        ],
        "products": [
          {
            "vendor": "lobehub",
            "product": "lobehub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14609
      },
      "nvd": {
        "published": "2026-07-02T20:17:07.673",
        "lastModified": "2026-07-14T23:17:33.350",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59095",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The importFromUrl and fetchImageFromUrl endpoints pass attacker-selected URLs to global fetch without the project's internal-address filtering wrapper.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lobehub/lobehub/issues/16536",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/lobehub/lobehub/pull/16601",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/lobechat-canary-18-ssrf-via-importfromurl-and-fetchimagefromurl",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 560,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59096",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:38:18.928Z",
      "date_published": "2026-07-02T19:41:40.984Z",
      "date_updated": "2026-07-14T22:03:23.087Z",
      "publisher": "VulnCheck",
      "title": "Dapr - OIDC Discovery Issuer and JWKS URI Injection via Unvalidated X-Forwarded-Host",
      "affected": {
        "vendors": [
          "dapr"
        ],
        "products": [
          {
            "vendor": "dapr",
            "product": "dapr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15928
      },
      "nvd": {
        "published": "2026-07-02T20:17:07.847",
        "lastModified": "2026-07-14T23:17:33.460",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59096",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Dapr Sentry derives OIDC issuer and jwks_uri values from an attacker-controlled forwarded Host header, causing clients to trust metadata that points at the attacker's origin.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dapr/dapr/pull/10027",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/dapr/dapr/pull/10028",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/dapr/dapr/pull/10029",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dapr-oidc-discovery-issuer-and-jwks-uri-injection-via-unvalidated-x-forwarded-host",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 660,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59097",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:38:18.929Z",
      "date_published": "2026-07-02T19:42:04.588Z",
      "date_updated": "2026-07-14T22:03:23.816Z",
      "publisher": "VulnCheck",
      "title": "Taiga < 6.10.2 - Unauthorized Due-Date Creation via API Viewsets",
      "affected": {
        "vendors": [
          "taiga"
        ],
        "products": [
          {
            "vendor": "taiga",
            "product": "taiga-back"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00344,
        "percentile": 0.26996
      },
      "nvd": {
        "published": "2026-07-02T20:17:07.990",
        "lastModified": "2026-07-14T23:17:33.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59097",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An AllowAny API endpoint lets an unauthenticated caller change arbitrary project due dates.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/taigaio/taiga-back/releases/tag/6.10.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/taigaio/taiga-back/issues/244",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/taigaio/taiga-back/pull/245",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/taigaio/taiga-back/commit/f925af424623350e04d4abc45bf1dc70e70c48a9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/taiga-unauthorized-due-date-creation-via-api-viewsets",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 513,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59098",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:38:18.929Z",
      "date_published": "2026-07-02T19:42:27.458Z",
      "date_updated": "2026-07-14T22:03:24.480Z",
      "publisher": "VulnCheck",
      "title": "LobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search",
      "affected": {
        "vendors": [
          "lobehub"
        ],
        "products": [
          {
            "vendor": "lobehub",
            "product": "lobehub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00238,
        "percentile": 0.1497
      },
      "nvd": {
        "published": "2026-07-02T20:17:08.120",
        "lastModified": "2026-07-14T23:17:33.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59098",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The lobehub request path accepts an attacker-selected object identifier without binding that object to the caller's tenant, owner, or permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lobehub/lobehub/issues/16535",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/lobehub/lobehub/pull/16594",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/lobehub/lobehub/commit/4a7931a4e66832947dba11afdffae2918a56b6a0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/lobechat-cross-user-document-disclosure-via-unscoped-rag-semantic-search",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59099",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:38:18.929Z",
      "date_published": "2026-07-02T19:42:51.897Z",
      "date_updated": "2026-07-14T22:03:25.158Z",
      "publisher": "VulnCheck",
      "title": "Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure",
      "affected": {
        "vendors": [
          "apereo"
        ],
        "products": [
          {
            "vendor": "apereo",
            "product": "cas"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-323",
          "name": "Reusing a Nonce, Key Pair in Encryption",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00356,
        "percentile": 0.28314
      },
      "nvd": {
        "published": "2026-07-02T20:17:08.240",
        "lastModified": "2026-07-14T23:17:33.830",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59099",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apereo CAS reuses an all-zero AES-GCM initialization vector with the same key across webflow tokens.",
        "basis": [
          "CNA",
          "CWE-323"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://apereo.github.io/2026/06/18/vuln/",
          "host": "apereo.github.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/apereo/cas/releases/tag/v8.0.0-RC6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/geo-chen/oss/blob/main/cas.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/apereo/cas/commit/22c6f4adf738852782309b523b4e80371057f2d0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/apereo-cas-rc6-aes-gcm-nonce-reuse-information-disclosure",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59100",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:38:18.929Z",
      "date_published": "2026-07-02T19:43:16.068Z",
      "date_updated": "2026-07-14T22:03:25.830Z",
      "publisher": "VulnCheck",
      "title": "LobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Operations",
      "affected": {
        "vendors": [
          "lobehub"
        ],
        "products": [
          {
            "vendor": "lobehub",
            "product": "lobehub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 2.7,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07832
      },
      "nvd": {
        "published": "2026-07-02T20:17:08.380",
        "lastModified": "2026-07-14T23:17:33.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59100",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attackers can invoke the getGroupAgents, updateAgentInGroup, and removeAgentsFromGroup operations without user-scoped predicates to read agent listings, modify agent roles and ordering, and remove agents from chat groups belonging to other users.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lobehub/lobehub/issues/16537",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/lobehub/lobehub/pull/16586",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/lobehub/lobehub/commit/9ed5a7e20d8a67c431265f5a252e9559d9920907",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/lobechat-broken-object-level-authorization-via-chat-group-agent-operations",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 462,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59101",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:38:18.929Z",
      "date_published": "2026-07-02T19:43:41.668Z",
      "date_updated": "2026-07-14T22:03:26.509Z",
      "publisher": "VulnCheck",
      "title": "AutoBangumi < 3.2.8 - SSRF via /api/v1/setup/test-downloader",
      "affected": {
        "vendors": [
          "EstrellaXD"
        ],
        "products": [
          {
            "vendor": "EstrellaXD",
            "product": "Auto_Bangumi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24591
      },
      "nvd": {
        "published": "2026-07-02T20:17:08.507",
        "lastModified": "2026-07-14T23:17:34.077",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59101",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal network services by supplying arbitrary host values to an unprotected setup endpoint.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/EstrellaXD/Auto_Bangumi/releases/tag/3.2.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/EstrellaXD/Auto_Bangumi/issues/1041",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/EstrellaXD/Auto_Bangumi/commit/487bdfec545e805ae416e6ddf28651bd274d6a73",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/autobangumi-ssrf-via-api-v1-setup-test-downloader",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59102",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T15:38:18.929Z",
      "date_published": "2026-07-02T19:44:07.617Z",
      "date_updated": "2026-07-06T13:30:13.629Z",
      "publisher": "VulnCheck",
      "title": "Forgejo < 15.0.3 - Stored XSS via Actions Run Full Name Rendering",
      "affected": {
        "vendors": [
          "forgejo"
        ],
        "products": [
          {
            "vendor": "forgejo",
            "product": "forgejo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 3.3000000000000003,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09889
      },
      "nvd": {
        "published": "2026-07-02T20:17:08.683",
        "lastModified": "2026-07-06T19:01:14.993",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59102",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Forgejo interpolates an unescaped full name into an HTML translation string and renders the result with Vue v-html on the Actions page.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/15.0.3.md",
          "host": "codeberg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/geo-chen/oss/blob/main/forgejo.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://codeberg.org/forgejo/forgejo/pulls/13002",
          "host": "codeberg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/forgejo-stored-xss-via-actions-run-full-name-rendering",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 612,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59117",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:05:24.069Z",
      "date_published": "2026-07-16T21:56:37.746Z",
      "date_updated": "2026-08-03T22:52:43.260Z",
      "publisher": "microsoft",
      "title": "Windows Terminal Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Windows Terminal App"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36345
      },
      "nvd": {
        "published": "2026-07-16T22:17:52.597",
        "lastModified": "2026-07-30T19:18:33.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59117",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Windows Terminal App performs security-relevant size arithmetic without rejecting an integer overflow or wraparound.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59117",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59139",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:24:17.912Z",
      "date_published": "2026-07-21T19:02:43.033Z",
      "date_updated": "2026-07-22T19:16:27.039Z",
      "publisher": "CPANSec",
      "title": "Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::ReqRep::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00349,
        "percentile": 0.27603
      },
      "nvd": {
        "published": "2026-07-21T19:17:11.467",
        "lastModified": "2026-07-22T20:17:02.053",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59139",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "reqrep_recv_locked copies from an mmap arena using file-controlled offset and length fields that were never bounded against req_arena_cap.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-ReqRep-Shared-0.05/diff/EGOR/Data-ReqRep-Shared-0.04#reqrep.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-ReqRep-Shared-0.05/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 765,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59140",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:24:17.912Z",
      "date_published": "2026-07-21T19:03:16.345Z",
      "date_updated": "2026-07-22T19:18:01.325Z",
      "publisher": "CPANSec",
      "title": "Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::SortedSet::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26328
      },
      "nvd": {
        "published": "2026-07-21T19:17:11.583",
        "lastModified": "2026-07-22T20:17:02.207",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59140",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Rank and min/max queries follow mmap-backed child indices without bounding them to node_capacity before dereferencing the node pool.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-SortedSet-Shared-0.03/diff/EGOR/Data-SortedSet-Shared-0.02#sortedset.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-SortedSet-Shared-0.03/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 781,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59141",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:24:17.912Z",
      "date_published": "2026-07-21T19:03:34.453Z",
      "date_updated": "2026-07-22T19:20:48.641Z",
      "publisher": "CPANSec",
      "title": "Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::RadixTree::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26328
      },
      "nvd": {
        "published": "2026-07-21T19:17:11.697",
        "lastModified": "2026-07-22T20:17:02.357",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59141",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "rdx_find_locked trusts mmap node and arena indices that attach-time validation never checks against their allocation bounds.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-RadixTree-Shared-0.02/diff/EGOR/Data-RadixTree-Shared-0.01#radix.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-RadixTree-Shared-0.02/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 705,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59142",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:24:17.912Z",
      "date_published": "2026-07-21T19:03:48.428Z",
      "date_updated": "2026-07-22T19:21:55.788Z",
      "publisher": "CPANSec",
      "title": "Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::HashMap::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26328
      },
      "nvd": {
        "published": "2026-07-21T19:17:11.800",
        "lastModified": "2026-07-22T20:17:02.507",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59142",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Shared-map iteration trusts file-controlled arena offsets and lengths and copies from those locations without bounding them to the mapped arena.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-HashMap-Shared-0.14/diff/EGOR/Data-HashMap-Shared-0.13#shm_generic.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-HashMap-Shared-0.14/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 824,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:24:17.912Z",
      "date_published": "2026-07-21T19:04:04.057Z",
      "date_updated": "2026-07-23T12:14:48.600Z",
      "publisher": "CPANSec",
      "title": "Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::RoaringBitmap::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14611
      },
      "nvd": {
        "published": "2026-07-21T20:17:03.083",
        "lastModified": "2026-07-23T13:16:28.107",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59143",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "rb_contains_locked trusts file-stored container offsets and cardinalities without bounding them to the mapped container pool and slot size.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-RoaringBitmap-Shared-0.02/diff/EGOR/Data-RoaringBitmap-Shared-0.01#roaring.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-RoaringBitmap-Shared-0.02/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 829,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:24:17.913Z",
      "date_published": "2026-07-21T19:04:20.191Z",
      "date_updated": "2026-07-22T19:33:34.869Z",
      "publisher": "CPANSec",
      "title": "Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::RingBuffer::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00459,
        "percentile": 0.37554
      },
      "nvd": {
        "published": "2026-07-21T20:17:03.193",
        "lastModified": "2026-07-22T20:17:02.663",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59144",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Data::RingBuffer::Shared path copies attacker-influenced data beyond a fixed-size stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-RingBuffer-Shared-0.04/diff/EGOR/Data-RingBuffer-Shared-0.03#ring.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-RingBuffer-Shared-0.04/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 749,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:24:17.913Z",
      "date_published": "2026-07-21T19:04:39.549Z",
      "date_updated": "2026-07-22T19:35:08.720Z",
      "publisher": "CPANSec",
      "title": "Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::Intern::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00416,
        "percentile": 0.34247
      },
      "nvd": {
        "published": "2026-07-21T20:17:03.300",
        "lastModified": "2026-07-22T20:17:02.813",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59145",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "si_idx_find trusts attacker-controlled slot, reverse, and arena indices and follows them beyond the mapped segment.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-Intern-Shared-0.02/diff/EGOR/Data-Intern-Shared-0.01#intern.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-Intern-Shared-0.02/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 946,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59146",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:24:17.913Z",
      "date_published": "2026-07-21T19:04:56.729Z",
      "date_updated": "2026-07-22T19:36:54.589Z",
      "publisher": "CPANSec",
      "title": "Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::SpatialHash::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03712
      },
      "nvd": {
        "published": "2026-07-21T20:17:03.407",
        "lastModified": "2026-07-22T20:17:02.970",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59146",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The shared-file validator checks only layout metadata and then trusts attacker-controlled bucket, link, and free-list indices for memory reads and writes.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-SpatialHash-Shared-0.02/diff/EGOR/Data-SpatialHash-Shared-0.01#sphash.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-SpatialHash-Shared-0.02/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 838,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:24:17.913Z",
      "date_published": "2026-07-21T19:05:11.638Z",
      "date_updated": "2026-07-23T12:17:04.895Z",
      "publisher": "CPANSec",
      "title": "Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::DisjointSet::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00416,
        "percentile": 0.34247
      },
      "nvd": {
        "published": "2026-07-21T20:17:03.513",
        "lastModified": "2026-07-23T13:16:28.693",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59147",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Data::DisjointSet::Shared uses an attacker-influenced length or index without proving it lies inside the backing object, allowing a read beyond valid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-DisjointSet-Shared-0.02/diff/EGOR/Data-DisjointSet-Shared-0.01#dsu.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-DisjointSet-Shared-0.02/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 727,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59148",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:50:27.886Z",
      "date_published": "2026-07-09T18:27:18.579Z",
      "date_updated": "2026-07-09T19:24:49.203Z",
      "publisher": "GitHub_M",
      "title": "Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft",
      "affected": {
        "vendors": [
          "mockoon"
        ],
        "products": [
          {
            "vendor": "mockoon",
            "product": "mockoon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-942",
          "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06994
      },
      "nvd": {
        "published": "2026-07-09T19:17:07.067",
        "lastModified": "2026-07-10T19:15:15.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59148",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Mockoon mounts an unauthenticated administration API on the public mock listener and permits any origin to read or change its state.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306",
          "CWE-352",
          "CWE-732",
          "CWE-942"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mockoon/mockoon/security/advisories/GHSA-rqx4-3f6q-3x2v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/mockoon/mockoon/pull/2254",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mockoon/mockoon/commit/c420b5a56918475b8663977b51e5f986e45b3299",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mockoon/mockoon/releases/tag/v9.7.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://mockoon.com/releases/9.7.0",
          "host": "mockoon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 700,
        "referenceCount": 5,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59149",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:50:27.886Z",
      "date_published": "2026-07-09T18:28:35.693Z",
      "date_updated": "2026-07-09T18:41:45.833Z",
      "publisher": "GitHub_M",
      "title": "Mockoon: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)",
      "affected": {
        "vendors": [
          "mockoon"
        ],
        "products": [
          {
            "vendor": "mockoon",
            "product": "mockoon"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25513
      },
      "nvd": {
        "published": "2026-07-09T19:17:07.207",
        "lastModified": "2026-07-10T19:15:15.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59149",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mockoon checks a resolved file path with a separator-free string prefix, allowing request-derived traversal into sibling directories.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mockoon/mockoon/security/advisories/GHSA-8wqc-v2q8-vff2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/mockoon/mockoon/pull/2255",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mockoon/mockoon/commit/b42bdfb7f82e83f0e81bea8e6fe41adf5ec82585",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/mockoon/mockoon/releases/tag/v9.7.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://mockoon.com/releases/9.7.0",
          "host": "mockoon.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 562,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59151",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:50:27.886Z",
      "date_published": "2026-07-10T17:50:07.303Z",
      "date_updated": "2026-07-13T18:03:20.394Z",
      "publisher": "GitHub_M",
      "title": "Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover",
      "affected": {
        "vendors": [
          "prowler-cloud"
        ],
        "products": [
          {
            "vendor": "prowler-cloud",
            "product": "prowler"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21848
      },
      "nvd": {
        "published": "2026-07-10T19:17:26.780",
        "lastModified": "2026-07-13T19:17:32.477",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59151",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prowler recomputes the tenant from an asserted email domain instead of binding token issuance to the SAML configuration that was validated.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/prowler-cloud/prowler/security/advisories/GHSA-h8m9-jgf8-vwvp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/prowler-cloud/prowler/pull/11650",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/prowler-cloud/prowler/commit/bf3b5c2ba713e533014927141b64948c82c8f32e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/prowler-cloud/prowler/commit/f5ff30ad175bd2edf02cd28872653c1cda5867b7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/prowler-cloud/prowler/releases/tag/5.30.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 715,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59152",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:50:27.886Z",
      "date_published": "2026-07-06T14:26:55.765Z",
      "date_updated": "2026-07-07T15:17:40.993Z",
      "publisher": "GitHub_M",
      "title": "Arbitrary server-side file read in LangSmith SDK TracingMiddleware",
      "affected": {
        "vendors": [
          "langchain-ai"
        ],
        "products": [
          {
            "vendor": "langchain-ai",
            "product": "langsmith-sdk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07029
      },
      "nvd": {
        "published": "2026-07-06T16:16:37.413",
        "lastModified": "2026-07-07T16:16:41.340",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59152",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "TracingMiddleware accepts a request-selected local file path and uploads that file as a trace attachment.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-346",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-f4xh-w4cj-qxq8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 894,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59153",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:50:27.886Z",
      "date_published": "2026-07-07T21:11:01.808Z",
      "date_updated": "2026-07-08T13:50:15.783Z",
      "publisher": "GitHub_M",
      "title": "Anki's local HTTP server does not sufficiently validate requests",
      "affected": {
        "vendors": [
          "ankitects"
        ],
        "products": [
          {
            "vendor": "ankitects",
            "product": "anki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07612
      },
      "nvd": {
        "published": "2026-07-07T22:16:54.363",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59153",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Anki's local HTTP server accepts cross-origin browser requests that can trigger local side effects without validating the requesting origin.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ankitects/anki/security/advisories/GHSA-869j-r97x-hx2g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ankitects/anki/commit/858e5689d0e4fd24f74856c7e8f245412694a219",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ankitects/anki/releases/tag/25.09.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://x.com/taviso/status/2051310678800253318",
          "host": "x.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59154",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:50:27.886Z",
      "date_published": "2026-07-10T15:45:20.012Z",
      "date_updated": "2026-07-10T20:59:04.865Z",
      "publisher": "GitHub_M",
      "title": "Wekan: Checklist direct DDP updates can write checklist data into private boards",
      "affected": {
        "vendors": [
          "wekan"
        ],
        "products": [
          {
            "vendor": "wekan",
            "product": "wekan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11125
      },
      "nvd": {
        "published": "2026-07-10T17:17:02.113",
        "lastModified": "2026-07-10T21:17:00.340",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59154",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Wekan authorizes a checklist update against the source card without validating the destination card or board carried in the update modifier.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wekan/wekan/security/advisories/GHSA-gv8h-5p3p-6hx7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/commit/b1ca76007b9a295fd029dfefc1a2d1d6f1920835",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/wekan/wekan/releases/tag/v9.64",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 599,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59155",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:50:27.886Z",
      "date_published": "2026-07-10T21:31:34.313Z",
      "date_updated": "2026-07-13T17:56:44.683Z",
      "publisher": "GitHub_M",
      "title": "Nezha Monitoring: DDNS and Notification credential exposure via unredacted list API",
      "affected": {
        "vendors": [
          "nezhahq"
        ],
        "products": [
          {
            "vendor": "nezhahq",
            "product": "nezha"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22709
      },
      "nvd": {
        "published": "2026-07-10T22:16:45.487",
        "lastModified": "2026-07-13T19:49:37.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59155",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API credentials, including Cloudflare API tokens, TencentCloud SecretKeys, Slack, Discord, and Telegram webhook URLs with embedded bot tokens, and Authorization header values, without any field-level redaction.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nezhahq/nezha/security/advisories/GHSA-ww5p-j6cj-6mqq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nezhahq/nezha/commit/39d398066d8c644fe452f74704e34ada6c7ab61e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nezhahq/nezha/releases/tag/v2.2.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 674,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59161",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:50:27.887Z",
      "date_published": "2026-07-10T15:47:38.604Z",
      "date_updated": "2026-07-14T01:55:21.372Z",
      "publisher": "GitHub_M",
      "title": "Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation",
      "affected": {
        "vendors": [
          "qax-os"
        ],
        "products": [
          {
            "vendor": "qax-os",
            "product": "excelize"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00398,
        "percentile": 0.32616
      },
      "nvd": {
        "published": "2026-07-10T17:17:02.250",
        "lastModified": "2026-07-16T14:10:24.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59161",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The streaming XLSX reader trusts an attacker-controlled row number above Excel's maximum and appends empty rows up to that index.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/qax-os/excelize/security/advisories/GHSA-q5j5-6p94-4gwc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/qax-os/excelize/pull/2331",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/qax-os/excelize/commit/93f0b3caed37f21ef5079e3259c6c21dcfe68453",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/qax-os/excelize/releases/tag/v2.11.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 450,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59162",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T16:50:27.887Z",
      "date_published": "2026-07-10T15:51:26.078Z",
      "date_updated": "2026-07-10T18:40:25.481Z",
      "publisher": "GitHub_M",
      "title": "Excelize: Negative shared-string index causes panic in GetCellValue and GetRows",
      "affected": {
        "vendors": [
          "qax-os"
        ],
        "products": [
          {
            "vendor": "qax-os",
            "product": "excelize"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-755",
          "name": "Improper Handling of Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0039,
        "percentile": 0.31779
      },
      "nvd": {
        "published": "2026-07-10T17:17:02.377",
        "lastModified": "2026-07-16T13:44:56.260",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59162",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Excelize checks only the upper bound of a parsed shared-string index, so a negative index reaches a slice access and panics.",
        "basis": [
          "CNA",
          "CWE-248",
          "CWE-755"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/qax-os/excelize/security/advisories/GHSA-fx5j-qcqg-grpf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/qax-os/excelize/pull/2331",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/qax-os/excelize/commit/93f0b3caed37f21ef5079e3259c6c21dcfe68453",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/qax-os/excelize/releases/tag/v2.11.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 420,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59173",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T17:22:51.439Z",
      "date_published": "2026-07-18T12:52:18.923Z",
      "date_updated": "2026-07-20T13:41:03.319Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditions",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00505,
        "percentile": 0.40396
      },
      "nvd": {
        "published": "2026-07-18T13:17:06.150",
        "lastModified": "2026-07-20T17:14:58.043",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59173",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Attacker-controlled work or allocation lacks an effective bound, release, or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/lhlbhphmv5dsfgx1fx84mgonzbocpzhd",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/17/5",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59180",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:53:48.830Z",
      "date_published": "2026-07-10T16:02:15.409Z",
      "date_updated": "2026-07-10T16:54:32.408Z",
      "publisher": "GitHub_M",
      "title": "Apprise forwards configured auth headers across cross-origin HTTP redirects",
      "affected": {
        "vendors": [
          "caronc"
        ],
        "products": [
          {
            "vendor": "caronc",
            "product": "apprise"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09402
      },
      "nvd": {
        "published": "2026-07-10T17:17:02.503",
        "lastModified": "2026-07-10T19:22:24.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59180",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "apprise accepts a caller-controlled redirect target without restricting it to a trusted origin.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/caronc/apprise/security/advisories/GHSA-856c-92hv-3vxx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/caronc/apprise/pull/1610",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/caronc/apprise/commit/68c0aef218055e4586cf4605fd6b56358f5f462d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/caronc/apprise/releases/tag/v1.11.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 615,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59190",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:53:48.831Z",
      "date_published": "2026-07-10T16:33:47.077Z",
      "date_updated": "2026-07-10T18:16:10.554Z",
      "publisher": "GitHub_M",
      "title": "Grav Admin Plugin — IDOR Privilege Escalation via saveUser()",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11999
      },
      "nvd": {
        "published": "2026-07-10T17:17:02.647",
        "lastModified": "2026-07-10T19:17:27.090",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59190",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "saveUser checks general user-management permission but does not verify that the caller may edit the selected higher-privileged account.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-p97c-g455-q447",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav-plugin-admin/commit/88f7ce8e50324472f492965caa42fb709a4f791a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 545,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59193",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:53:48.831Z",
      "date_published": "2026-07-10T16:35:48.124Z",
      "date_updated": "2026-07-10T19:04:53.166Z",
      "publisher": "GitHub_M",
      "title": "Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.0039,
        "percentile": 0.31765
      },
      "nvd": {
        "published": "2026-07-10T17:17:02.773",
        "lastModified": "2026-07-10T20:16:48.807",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59193",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Archive extraction lacks effective limits on expanded size, entry count, and nesting depth.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-2vcx-h8p2-9pg9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/commit/23d6f2adf4ce11889c088ac8557c8314baeef781",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/releases/tag/2.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 354,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59194",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:53:48.831Z",
      "date_published": "2026-07-06T15:16:28.485Z",
      "date_updated": "2026-07-07T16:57:59.326Z",
      "publisher": "GitHub_M",
      "title": "pnpm: patch-remove could delete project-selected files outside the patches directory",
      "affected": {
        "vendors": [
          "pnpm"
        ],
        "products": [
          {
            "vendor": "pnpm",
            "product": "pnpm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20985
      },
      "nvd": {
        "published": "2026-07-06T16:16:37.550",
        "lastModified": "2026-07-07T19:08:57.837",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59194",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "pnpm patch-remove resolves a crafted patch entry outside the patches directory and deletes the selected external file.",
        "basis": [
          "CNA record",
          "CWE-22",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pnpm/pnpm/security/advisories/GHSA-72r4-9c5j-mj57",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59195",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:53:48.831Z",
      "date_published": "2026-07-06T15:21:03.101Z",
      "date_updated": "2026-07-07T14:06:17.178Z",
      "publisher": "GitHub_M",
      "title": "pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config",
      "affected": {
        "vendors": [
          "pnpm"
        ],
        "products": [
          {
            "vendor": "pnpm",
            "product": "pnpm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20986
      },
      "nvd": {
        "published": "2026-07-06T16:16:37.683",
        "lastModified": "2026-07-07T19:09:30.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59195",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "pnpm accepts an attacker-controlled path that can resolve outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pnpm/pnpm/security/advisories/GHSA-qrv3-253h-g69c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59196",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:53:48.831Z",
      "date_published": "2026-07-06T15:18:53.881Z",
      "date_updated": "2026-07-06T15:40:34.708Z",
      "publisher": "GitHub_M",
      "title": "pnpm: hoisted install imports lockfile alias outside node_modules",
      "affected": {
        "vendors": [
          "pnpm"
        ],
        "products": [
          {
            "vendor": "pnpm",
            "product": "pnpm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21604
      },
      "nvd": {
        "published": "2026-07-06T16:16:37.810",
        "lastModified": "2026-07-07T19:09:15.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59196",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "pnpm joins a lockfile alias beneath node_modules without rejecting traversal or reserved names, allowing writes outside the intended layout.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pnpm/pnpm/security/advisories/GHSA-fr4h-3cph-29xv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 324,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59197",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:53:48.831Z",
      "date_published": "2026-07-14T16:25:23.520Z",
      "date_updated": "2026-07-21T18:50:40.019Z",
      "publisher": "GitHub_M",
      "title": "Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00436,
        "percentile": 0.35899
      },
      "nvd": {
        "published": "2026-07-14T17:17:14.487",
        "lastModified": "2026-07-21T19:17:11.907",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59197",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImagingExpand adds attacker-selected filter padding with unchecked signed integer arithmetic, allocates the wrapped size, and then writes beyond the heap buffer.",
        "basis": [
          "CNA",
          "CWE-190",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9695",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59198",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:53:48.831Z",
      "date_published": "2026-07-14T16:07:56.562Z",
      "date_updated": "2026-07-14T19:55:56.380Z",
      "publisher": "GitHub_M",
      "title": "Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23707
      },
      "nvd": {
        "published": "2026-07-14T16:17:01.797",
        "lastModified": "2026-07-14T20:18:43.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59198",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the end of an allocated buffer because the available length is not enforced.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-fj7v-r99m-22gq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9709",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/eada3cbd7fb9963ee90673fb7b5270124a0d5f4b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59199",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:53:48.831Z",
      "date_published": "2026-07-14T15:42:15.071Z",
      "date_updated": "2026-07-15T14:53:39.590Z",
      "publisher": "GitHub_M",
      "title": "Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.31303
      },
      "nvd": {
        "published": "2026-07-14T16:17:01.937",
        "lastModified": "2026-07-15T16:16:49.487",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59199",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Signed coordinate arithmetic near 32-bit limits overflows in Pillow image operations and drives a native write outside the heap buffer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-190",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-6r8x-57c9-28j4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9703",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59200",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T19:53:48.831Z",
      "date_published": "2026-07-14T16:09:05.091Z",
      "date_updated": "2026-07-14T19:52:06.407Z",
      "publisher": "GitHub_M",
      "title": "Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.31304
      },
      "nvd": {
        "published": "2026-07-14T17:17:14.620",
        "lastModified": "2026-07-21T15:52:40.107",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59200",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Pillow path allocates attacker-driven resources without an effective bound or throttle.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9718",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/f7a31ea75e460e108c37126da1f47812f21f6b09",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 346,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59203",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.923Z",
      "date_published": "2026-07-14T15:43:58.333Z",
      "date_updated": "2026-07-15T13:52:17.491Z",
      "publisher": "GitHub_M",
      "title": "Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00399,
        "percentile": 0.32684
      },
      "nvd": {
        "published": "2026-07-14T16:17:02.063",
        "lastModified": "2026-07-15T14:18:32.727",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59203",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A negative BeginBinary length leaves the parser in a loop with no effective termination condition.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-pg7v-jwj7-p798",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9708",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59204",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.923Z",
      "date_published": "2026-07-14T15:38:29.545Z",
      "date_updated": "2026-07-21T18:41:18.660Z",
      "publisher": "GitHub_M",
      "title": "Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00393,
        "percentile": 0.3209
      },
      "nvd": {
        "published": "2026-07-14T16:17:02.227",
        "lastModified": "2026-07-21T19:17:12.020",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59204",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Pillow conversion path allocates memory from an attacker-controlled size without enforcing a safe upper bound.",
        "basis": [
          "CNA",
          "CWE-770",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9704",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 383,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59205",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.924Z",
      "date_published": "2026-07-14T15:48:39.962Z",
      "date_updated": "2026-07-14T17:31:36.064Z",
      "publisher": "GitHub_M",
      "title": "Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch",
      "affected": {
        "vendors": [
          "python-pillow"
        ],
        "products": [
          {
            "vendor": "python-pillow",
            "product": "Pillow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.31304
      },
      "nvd": {
        "published": "2026-07-14T16:17:02.370",
        "lastModified": "2026-07-14T20:09:27.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59205",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pillow uses mismatched image modes to size and copy data, producing writes beyond the allocated heap buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/pull/9715",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/python-pillow/Pillow/releases/tag/12.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 299,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59206",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.924Z",
      "date_published": "2026-07-09T15:30:28.166Z",
      "date_updated": "2026-07-09T18:38:07.061Z",
      "publisher": "GitHub_M",
      "title": "n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0038,
        "percentile": 0.30779
      },
      "nvd": {
        "published": "2026-07-09T16:16:46.323",
        "lastModified": "2026-07-09T19:41:15.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59206",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unauthenticated n8n request can modify inherited object prototype state, causing later authorization logic to observe attacker-created privileged properties.",
        "basis": [
          "CNA",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-75qm-gp28-rcq9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/n8n-io/n8n/releases/tag/n8n%402.27.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/n8n-io/n8n/releases/tag/n8n%402.28.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 445,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-59207",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.924Z",
      "date_published": "2026-07-09T15:16:36.276Z",
      "date_updated": "2026-07-09T15:51:27.024Z",
      "publisher": "GitHub_M",
      "title": "n8n: \"Allowed HTTP Request Domains\" Restriction Bypass via AI Agents MCP Connector",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17957
      },
      "nvd": {
        "published": "2026-07-09T16:16:46.470",
        "lastModified": "2026-07-09T19:37:19.377",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59207",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MCP transport does not enforce its configured HTTP-domain restriction before making the request.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-h44j-f5r5-ph73",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/n8n-io/n8n/releases/tag/n8n%402.27.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/n8n-io/n8n/releases/tag/n8n%402.28.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 417,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59208",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.924Z",
      "date_published": "2026-07-09T15:27:28.126Z",
      "date_updated": "2026-07-14T00:20:06.366Z",
      "publisher": "GitHub_M",
      "title": "n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23797
      },
      "nvd": {
        "published": "2026-07-09T16:16:46.610",
        "lastModified": "2026-07-14T01:16:18.827",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59208",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "n8n binds an external identity to a local account using sub alone, so equal subject strings from different trusted issuers resolve to the same user.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-mq3m-f8x3-579w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/n8n-io/n8n/releases/tag/n8n%402.27.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/n8n-io/n8n/releases/tag/n8n%402.28.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 473,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59209",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.924Z",
      "date_published": "2026-07-09T15:32:27.537Z",
      "date_updated": "2026-07-09T17:28:23.567Z",
      "publisher": "GitHub_M",
      "title": "n8n: Shared Credential Header Leak via HTTP Request Pagination Expression",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00295,
        "percentile": 0.2172
      },
      "nvd": {
        "published": "2026-07-09T17:17:01.780",
        "lastModified": "2026-07-13T15:28:25.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59209",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "n8n exposes credential-bearing request headers through the $request object to workflow code that is not entitled to receive those secrets.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-q3j5-8vrg-4p9q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/n8n-io/n8n/releases/tag/n8n%402.27.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/n8n-io/n8n/releases/tag/n8n%402.28.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 395,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-59212",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.924Z",
      "date_published": "2026-07-09T17:04:43.488Z",
      "date_updated": "2026-07-09T17:21:32.128Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.2551
      },
      "nvd": {
        "published": "2026-07-09T17:17:01.903",
        "lastModified": "2026-07-10T19:59:36.867",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59212",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "File write and delete routes reuse a knowledge-object access result that proves only read permission, upgrading a read-only grant into mutation authority.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-2xwm-4h2q-ggfx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/26032",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/17df0264929514599dbcb21c6578bcdfa204b04d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59213",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.924Z",
      "date_published": "2026-07-09T16:55:00.032Z",
      "date_updated": "2026-07-09T17:52:21.479Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-524",
          "name": "Use of Cache Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00297,
        "percentile": 0.21944
      },
      "nvd": {
        "published": "2026-07-09T17:17:02.030",
        "lastModified": "2026-07-10T19:49:23.313",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59213",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "get_all_models uses one static cache key for permission-filtered results, allowing one user's model list to be returned to another user during the TTL.",
        "basis": [
          "CNA",
          "CWE-524"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-3wp3-xxj9-5jqq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/25783",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/0fc630b34b2899599dabffffa012afd47599aa75",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 429,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59214",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.924Z",
      "date_published": "2026-07-09T15:51:38.001Z",
      "date_updated": "2026-07-09T17:13:10.879Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: Stored web worker XSS via Pyodide",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.7000000000000002,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20791
      },
      "nvd": {
        "published": "2026-07-09T17:17:02.177",
        "lastModified": "2026-07-10T19:24:29.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59214",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A stored chat payload runs Python in a same-origin Pyodide worker and can issue authenticated requests to privileged server tools.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-4r2p-27mh-5m22",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59215",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.924Z",
      "date_published": "2026-07-09T16:57:24.325Z",
      "date_updated": "2026-07-09T18:40:04.871Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17056
      },
      "nvd": {
        "published": "2026-07-09T17:17:02.340",
        "lastModified": "2026-07-13T12:27:12.263",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59215",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Open WebUI accepts a thread parent_id without binding that message to the channel named in the request URL.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-73x5-h92w-xc2j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/25766",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/a66477b7104c5d141ce7bffaea424b43e7666ef1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59216",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.924Z",
      "date_published": "2026-07-09T16:48:55.663Z",
      "date_updated": "2026-07-10T03:55:47.517Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00308,
        "percentile": 0.23181
      },
      "nvd": {
        "published": "2026-07-09T17:17:02.467",
        "lastModified": "2026-07-13T12:24:30.137",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59216",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Socket.IO event dispatch checks only that a caller-supplied session_id is connected and never binds that session to the authenticated event caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-74h3-cxq7-vc5q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/25763",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/386ac958144dbbbf0aa6e268070d72b681a318aa",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 4,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59217",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.924Z",
      "date_published": "2026-07-09T16:51:32.637Z",
      "date_updated": "2026-07-14T01:03:10.558Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.2144
      },
      "nvd": {
        "published": "2026-07-09T17:17:02.613",
        "lastModified": "2026-07-14T02:16:57.147",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59217",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The upload path auto-links metadata.knowledge_id to a knowledge base without applying the target knowledge base write-access check.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-7r7x-gjvr-448g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/26001",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/b7626f05fb92b24ab923ad81a037071ebd5623d1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 392,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59218",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.924Z",
      "date_published": "2026-07-09T15:53:54.653Z",
      "date_updated": "2026-07-09T17:50:41.900Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: Account enumeration via observable login timing discrepancy",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-208",
          "name": "Observable Timing Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.1524
      },
      "nvd": {
        "published": "2026-07-09T17:17:02.750",
        "lastModified": "2026-07-10T18:30:58.837",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59218",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The sign-in endpoint skips bcrypt for unknown emails, creating a timing oracle that reveals registered accounts.",
        "basis": [
          "CNA",
          "CWE-208"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-7rw5-9f7q-xj36",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/26385",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/993e74912199c66c522f08ec81abe31d76985e39",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 400,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59219",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.925Z",
      "date_published": "2026-07-09T16:43:24.542Z",
      "date_updated": "2026-07-09T17:30:39.130Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22789
      },
      "nvd": {
        "published": "2026-07-09T17:17:02.877",
        "lastModified": "2026-07-10T18:17:21.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59219",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Realtime authentication decodes a JWT without consulting the Redis revocation state checked by ordinary HTTP authentication.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-855v-hq7w-jmjw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/33b91bd8ae8a100a5a306c91441a7d0b422c4cde",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.925Z",
      "date_published": "2026-07-09T16:09:41.127Z",
      "date_updated": "2026-07-09T18:45:06.768Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29987
      },
      "nvd": {
        "published": "2026-07-09T17:17:03.040",
        "lastModified": "2026-07-10T18:15:48.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59220",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Overlapping quantifiers in skill-mention regular expressions cause quadratic backtracking that blocks the shared asyncio event loop.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-ffpj-xv5c-p3gw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/61a26722155ec6ee1b629cf8dfcf975098c18331",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 456,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59221",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.925Z",
      "date_published": "2026-07-09T17:13:36.193Z",
      "date_updated": "2026-07-09T18:09:19.712Z",
      "publisher": "GitHub_M",
      "title": "open-webui terminal proxy path traversal guard bypass via 9x encoded traversal",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.289
      },
      "nvd": {
        "published": "2026-07-09T18:16:55.613",
        "lastModified": "2026-07-10T02:37:15.007",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59221",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Open WebUI decodes a proxy path only eight times, allowing a ninth encoding layer to hide traversal until the upstream terminal server decodes it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-frvj-c5qp-xj4w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/26050",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/05098d25a58d03738e01c4e85e8852c3b4ad849c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59222",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.925Z",
      "date_published": "2026-07-09T16:59:10.208Z",
      "date_updated": "2026-07-09T17:29:39.729Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24655
      },
      "nvd": {
        "published": "2026-07-09T17:17:03.353",
        "lastModified": "2026-07-10T17:43:06.180",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59222",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The channel-members endpoint serializes the full user model, including credentials and webhook settings, to ordinary channel participants.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-gh7p-78x6-jw6m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/fbcdcf146b99b5002705060a8243eee769108f9e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59223",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.925Z",
      "date_published": "2026-07-09T17:00:08.976Z",
      "date_updated": "2026-07-09T17:53:06.003Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.1301
      },
      "nvd": {
        "published": "2026-07-09T17:17:03.603",
        "lastModified": "2026-07-10T17:39:40.083",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59223",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Open WebUI compares host policy entries against URL strings and non-label suffixes instead of the parsed hostname.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-qg3f-8x3j-ggf2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/25949",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/087878ce848a4d828012068b5997dac480f43656",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59224",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.925Z",
      "date_published": "2026-07-09T17:09:31.980Z",
      "date_updated": "2026-07-10T03:55:48.312Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.208
      },
      "nvd": {
        "published": "2026-07-09T17:17:03.770",
        "lastModified": "2026-07-10T15:22:04.010",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59224",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Open WebUI derives terminal identity from query and forwarded-header values without canonical encoding, allowing the proxy and backend to interpret different identities.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-j657-m4c4-24jq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/26042",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/5f3a628a8d291bb5d33e1a0b0c89fb62a2927934",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 458,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59225",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.925Z",
      "date_published": "2026-07-09T17:12:14.141Z",
      "date_updated": "2026-07-09T18:08:12.064Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: Arena task endpoints can bypass underlying model access controls",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11467
      },
      "nvd": {
        "published": "2026-07-09T17:17:03.903",
        "lastModified": "2026-07-10T02:44:19.193",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59225",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Arena task endpoints authorize only the wrapper model, then resolve a restricted underlying model with bypass_filter enabled and skip its access check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-m3qf-58wf-w979",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/26046",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/dc4924b66e655b315e3be4430a3e51b7d5c20acc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 703,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.925Z",
      "date_published": "2026-07-09T16:06:55.927Z",
      "date_updated": "2026-07-09T18:08:30.890Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 1.1999999999999997,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22699
      },
      "nvd": {
        "published": "2026-07-09T17:17:04.067",
        "lastModified": "2026-07-10T02:42:18.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59226",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Scheduled automation execution rehydrates an owner without rechecking account activation, automation entitlement, or the current private-model grant.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-mvx4-532p-xfm9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/26047",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/920b655f4689e2118de928fbc936f6ebd4fed396",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59227",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-02T21:05:02.925Z",
      "date_published": "2026-07-09T15:56:44.042Z",
      "date_updated": "2026-07-14T00:58:25.667Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17522
      },
      "nvd": {
        "published": "2026-07-09T17:17:04.223",
        "lastModified": "2026-07-14T02:16:57.267",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59227",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The image-edit endpoint requires only a verified account and skips both the global feature switch and the user's generation permission.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-rqj7-6wrp-6g2g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/26009",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/e038bab66dec8d17212eec35b5cb6d6b785a4200",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 417,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59231",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T11:24:39.241Z",
      "date_published": "2026-07-31T15:06:05.441Z",
      "date_updated": "2026-07-31T17:41:34.238Z",
      "publisher": "Secur0",
      "title": "Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs",
      "affected": {
        "vendors": [
          "ccyl13"
        ],
        "products": [
          {
            "vendor": "ccyl13",
            "product": "Pentestify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:4daa8cea-433a-44bd-9456-53b127fc289a",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17476
      },
      "nvd": {
        "published": "2026-07-31T16:17:08.227",
        "lastModified": "2026-07-31T18:17:18.503",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59231",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server accepts an attacker-controlled destination without constraining the resolved request target to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ccyl13/Pentestify/commit/a058a22b42c6311895622645265df79a60265b1d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/ccyl13/Pentestify/releases/tag/v1.1.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://secur0.com/en/cna/cve-list/cve-2026-59231-ssrf-in-pentestify-via-unvalidated-image-urls-cve-id-cve-2026-59231",
          "host": "secur0.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 375,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T11:24:39.241Z",
      "date_published": "2026-07-31T16:00:45.422Z",
      "date_updated": "2026-07-31T16:57:56.183Z",
      "publisher": "Secur0",
      "title": "Stored Cross-site Scripting in Prospero Flow CRM lead name field",
      "affected": {
        "vendors": [
          "Roskus"
        ],
        "products": [
          {
            "vendor": "Roskus",
            "product": "Prospero Flow CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:4daa8cea-433a-44bd-9456-53b127fc289a",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22795
      },
      "nvd": {
        "published": "2026-07-31T16:17:08.360",
        "lastModified": "2026-07-31T18:17:18.643",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59232",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Prospero Flow CRM page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/commit/8b2633ddb2178c2f79718efdfb906e051ba2f03c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://secur0.com/en/cna/cve-list/cve-2026-59232-stored-xss-in-prospero-flow-crm-lead-name-field",
          "host": "secur0.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59234",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T11:24:39.241Z",
      "date_published": "2026-07-03T12:47:38.445Z",
      "date_updated": "2026-07-06T15:57:11.131Z",
      "publisher": "Secur0",
      "title": "Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calendar event deletion",
      "affected": {
        "vendors": [
          "Roskus"
        ],
        "products": [
          {
            "vendor": "Roskus",
            "product": "Prospero Flow CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:4daa8cea-433a-44bd-9456-53b127fc289a",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33081
      },
      "nvd": {
        "published": "2026-07-03T13:17:30.353",
        "lastModified": "2026-07-06T19:48:46.577",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59234",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The calendar delete handler resolves a caller-supplied event ID without owner or company scoping before deletion.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/commit/8c26eed4d80544c30e55448e12a8e999af6d2b70",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://secur0.com/en/cna/cve-list/cve-2026-59234-idor-in-prospero-flow-crm-allows-deletion-of-other-users-calendar-events",
          "host": "secur0.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 635,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59235",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T11:24:39.242Z",
      "date_published": "2026-07-15T10:38:20.180Z",
      "date_updated": "2026-07-15T12:23:58.603Z",
      "publisher": "Secur0",
      "title": "Missing authorization in Prospero Flow CRM allows low-privileged users to read all bank accounts",
      "affected": {
        "vendors": [
          "Roskus"
        ],
        "products": [
          {
            "vendor": "Roskus",
            "product": "Prospero Flow CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:4daa8cea-433a-44bd-9456-53b127fc289a",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00413,
        "percentile": 0.33987
      },
      "nvd": {
        "published": "2026-07-15T11:16:33.493",
        "lastModified": "2026-07-15T20:58:48.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59235",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The API applies authentication middleware but omits the separate permission required to read the selected bank.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/commit/57bb57212af03151c989d67d6723d5ddb3e81e7b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/releases#release-v5.5.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://secur0.com/en/cna/cve-list/cve-2026-59235-missing-authorization-in-prospero-flow-crm-allows-low-privileged-users-to-read-all-bank-accounts",
          "host": "secur0.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 968,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59236",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T11:24:39.242Z",
      "date_published": "2026-07-15T11:09:38.866Z",
      "date_updated": "2026-07-15T12:22:50.492Z",
      "publisher": "Secur0",
      "title": "Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection",
      "affected": {
        "vendors": [
          "Roskus"
        ],
        "products": [
          {
            "vendor": "Roskus",
            "product": "Prospero Flow CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:4daa8cea-433a-44bd-9456-53b127fc289a",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0047,
        "percentile": 0.38206
      },
      "nvd": {
        "published": "2026-07-15T12:18:17.520",
        "lastModified": "2026-07-15T20:58:48.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59236",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Excel import trusts a spreadsheet company_id without binding it to the authenticated user's company.",
        "basis": [
          "CNA record",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/commit/bdd6c9770a7435a45f0411154671b8a3e94dcdaa",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.14.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://secur0.com/en/cna/cve-list/cve-2026-59236-authorization-bypass-in-prospero-flow-crm-excel-import-allows-cross-tenant-record-injection",
          "host": "secur0.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59237",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T11:24:39.242Z",
      "date_published": "2026-07-16T14:35:46.702Z",
      "date_updated": "2026-07-16T14:55:43.519Z",
      "publisher": "Secur0",
      "title": "IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification of orders",
      "affected": {
        "vendors": [
          "Roskus"
        ],
        "products": [
          {
            "vendor": "Roskus",
            "product": "Prospero Flow CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:4daa8cea-433a-44bd-9456-53b127fc289a",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00369,
        "percentile": 0.2956
      },
      "nvd": {
        "published": "2026-07-16T15:16:34.730",
        "lastModified": "2026-07-16T17:47:59.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59237",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prospero Flow CRM trusts an attacker-supplied object identifier without checking that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/commit/9a859c4de3d49674916773d346c60d89ad7febe0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://secur0.com/en/cna/cve-list/cve-2026-59237-idor-in-prospero-flow-crm-order-api-allows-cross-tenant-read-and-modification-of-orders",
          "host": "secur0.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 575,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59238",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T11:24:39.242Z",
      "date_published": "2026-07-20T13:58:01.643Z",
      "date_updated": "2026-07-20T15:06:54.041Z",
      "publisher": "Secur0",
      "title": "Stored XSS in Pentestify via unsanitized finding images and report client logo",
      "affected": {
        "vendors": [
          "maalfer"
        ],
        "products": [
          {
            "vendor": "maalfer",
            "product": "Pentestify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:4daa8cea-433a-44bd-9456-53b127fc289a",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25715
      },
      "nvd": {
        "published": "2026-07-20T15:16:44.707",
        "lastModified": "2026-07-23T18:28:35.280",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59238",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Report arrays are interpolated into img src attributes without escaping, so stored values execute as browser markup.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/maalfer/pentestify/commit/a058a22b42c6311895622645265df79a60265b1d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://secur0.com/en/cna/cve-list/cve-2026-59238-stored-xss-in-pentestify-via-unsanitized-finding-images-and-report-client-logo",
          "host": "secur0.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59239",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T11:24:39.242Z",
      "date_published": "2026-07-27T17:56:08.882Z",
      "date_updated": "2026-07-27T18:31:10.854Z",
      "publisher": "Secur0",
      "title": "Stored XSS in Prospero Flow CRM email body allows administrator account takeover",
      "affected": {
        "vendors": [
          "Roskus"
        ],
        "products": [
          {
            "vendor": "Roskus",
            "product": "Prospero Flow CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:4daa8cea-433a-44bd-9456-53b127fc289a",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00383,
        "percentile": 0.31065
      },
      "nvd": {
        "published": "2026-07-27T18:16:57.300",
        "lastModified": "2026-07-27T19:17:17.970",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59239",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Prospero Flow CRM, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/commit/32efcd5c395ee55119fb9aea502a9d06e4c5adb8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/releases",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://secur0.com/en/cna/cve-list/cve-2026-59239-stored-xss-in-prospero-flow-crm-email-body-allows-administrator-account-takeover",
          "host": "secur0.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59240",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-03T11:24:39.242Z",
      "date_published": "2026-07-27T21:37:33.747Z",
      "date_updated": "2026-07-28T14:19:25.325Z",
      "publisher": "Secur0",
      "title": "IDOR in Prospero Flow CRM allows deletion of other users' notifications",
      "affected": {
        "vendors": [
          "Roskus"
        ],
        "products": [
          {
            "vendor": "Roskus",
            "product": "Prospero Flow CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:4daa8cea-433a-44bd-9456-53b127fc289a",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21094
      },
      "nvd": {
        "published": "2026-07-27T22:17:54.713",
        "lastModified": "2026-07-28T15:17:19.920",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59240",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The request accepts an object or tenant identifier without binding that identifier to the authenticated caller's authorized scope.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/commit/eaee2ae018701d116164976cbfa37fa9294ab4cc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://secur0.com/en/cna/cve-list/cve-2026-59240-idor-in-prospero-flow-crm-allows-deletion-of-other-users-notifications",
          "host": "secur0.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 798,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T00:18:03.606Z",
      "date_published": "2026-07-29T08:35:37.644Z",
      "date_updated": "2026-07-29T15:30:08.817Z",
      "publisher": "apache",
      "title": "Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow FAB provider"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00527,
        "percentile": 0.41669
      },
      "nvd": {
        "published": "2026-07-29T10:16:44.390",
        "lastModified": "2026-07-30T14:49:41.840",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59243",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Azure AD OAuth path decodes ID tokens with signature verification disabled by default, accepting forged or unsigned identity claims.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/airflow/pull/69374",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/x4784l7z00tl3gw4tv2dmvoon77rxgpl",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/10",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 655,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59245",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T01:50:50.590Z",
      "date_published": "2026-07-13T15:05:21.156Z",
      "date_updated": "2026-07-14T13:37:49.557Z",
      "publisher": "apache",
      "title": "Apache Airflow FAB provider: FAB auth manager: a DAG named \"DAGs\" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow FAB provider"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28666
      },
      "nvd": {
        "published": "2026-07-13T16:16:41.880",
        "lastModified": "2026-07-14T14:16:36.033",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59245",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Airflow maps a DAG literally named DAGs onto the global all-DAGs permission resource, turning a per-DAG grant into access across all DAGs.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/airflow/pull/69106",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/70f37q3mwov1vm3zolrfxlzds278c78h",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/13/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 587,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:24:03.652Z",
      "date_published": "2026-07-14T08:37:04.609Z",
      "date_updated": "2026-07-14T15:08:39.463Z",
      "publisher": "EEF",
      "title": "Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory",
      "affected": {
        "vendors": [
          "elixir-mint"
        ],
        "products": [
          {
            "vendor": "elixir-mint",
            "product": "mint"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22833
      },
      "nvd": {
        "published": "2026-07-14T09:16:41.727",
        "lastModified": "2026-07-15T20:17:21.813",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59246",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Zero-length continuation frames grow per-message accumulator state without a byte or frame-count cap.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/elixir-mint/mint/security/advisories/GHSA-8pf6-g464-h6h9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-59246.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-59246",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/elixir-mint/mint/commit/5779de1666344b32aefc4354184ea07f902f73ce",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1406,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59247",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:24:03.652Z",
      "date_published": "2026-07-29T14:24:55.499Z",
      "date_updated": "2026-07-30T04:15:30.182Z",
      "publisher": "EEF",
      "title": "Insufficient verification of Hex package metadata in Gleam",
      "affected": {
        "vendors": [
          "gleam-lang"
        ],
        "products": [
          {
            "vendor": "gleam-lang",
            "product": "gleam"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 13,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03
      },
      "nvd": {
        "published": "2026-07-29T15:16:26.780",
        "lastModified": "2026-07-30T19:14:09.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59247",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The gleam dependency resolver replaces signed repository metadata with unsigned API metadata before verifying the downloaded package.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gleam-lang/gleam/security/advisories/GHSA-4vvc-458m-r82g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-59247.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-59247",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/gleam-lang/gleam/commit/c9c0d48c123c8abae6db8dd61b25ccb427ed3d35",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/hexpm/specifications/blob/main/registry-v2.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1679,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-59248",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:24:03.652Z",
      "date_published": "2026-07-28T09:54:19.579Z",
      "date_updated": "2026-07-29T04:18:17.483Z",
      "publisher": "EEF",
      "title": "Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS",
      "affected": {
        "vendors": [
          "ninenines"
        ],
        "products": [
          {
            "vendor": "ninenines",
            "product": "cowlib"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21381
      },
      "nvd": {
        "published": "2026-07-28T10:16:50.083",
        "lastModified": "2026-07-30T19:14:09.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59248",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "cowlib's HPACK and QPACK integer decoder permits an encoded value to drive an allocation without an effective bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-59248.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-59248",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/ninenines/cowlib/commit/f582430498072a0c65ad338030321576dc13a343",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1781,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59249",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:24:03.652Z",
      "date_published": "2026-07-16T11:39:29.939Z",
      "date_updated": "2026-07-17T10:11:36.783Z",
      "publisher": "EEF",
      "title": "Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections",
      "affected": {
        "vendors": [
          "elixir-mint"
        ],
        "products": [
          {
            "vendor": "elixir-mint",
            "product": "mint"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22418
      },
      "nvd": {
        "published": "2026-07-16T12:18:07.170",
        "lastModified": "2026-07-16T13:49:40.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59249",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on the same pooled connection, enabling response-queue poisoning against subsequent requests that share the connection.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/elixir-mint/mint/security/advisories/GHSA-x3x7-96vm-6h2w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-59249.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-59249",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/elixir-mint/mint/commit/fc7d16538db7e40b56ed489f08683225cb0197fa",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1240,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59250",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:24:03.653Z",
      "date_published": "2026-07-27T15:25:03.106Z",
      "date_updated": "2026-07-28T09:55:21.416Z",
      "publisher": "EEF",
      "title": "Megaco flex scanner buffer overflow via oversized property parm name",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0073,
        "percentile": 0.50741
      },
      "nvd": {
        "published": "2026-07-27T16:18:03.330",
        "lastModified": "2026-07-30T17:01:07.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59250",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a single text-encoded H.248/Megaco message containing an oversized property parm name.",
        "basis": [
          "CNA",
          "CWE-120",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-7xgh-gmgf-q2g7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-59250.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-59250",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/8704c8f550a11ed5f825e3c011ecb03565b79c4f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1860,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-59251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:24:03.653Z",
      "date_published": "2026-07-27T15:30:47.097Z",
      "date_updated": "2026-07-28T09:54:59.169Z",
      "publisher": "EEF",
      "title": "Denial of service via exponential certificate policy tree growth in path validation",
      "affected": {
        "vendors": [
          "Erlang"
        ],
        "products": [
          {
            "vendor": "Erlang",
            "product": "OTP"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17671
      },
      "nvd": {
        "published": "2026-07-27T16:18:03.517",
        "lastModified": "2026-07-30T17:01:07.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59251",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Erlang certificate-policy processing grows its policy tree approximately M^K across policies and certificates without a node or work bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-622p-qfh6-c352",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-59251.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-59251",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
          "host": "www.erlang.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_version-scheme"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/f8580fc117098c08165f46c26fd0750c5cfb2a90",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/erlang/otp/commit/f04c6bba38de1cf1b1836a7d9a9fbe239bd939e8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1524,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-59252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T04:24:03.653Z",
      "date_published": "2026-07-17T10:11:54.436Z",
      "date_updated": "2026-07-18T04:12:42.459Z",
      "publisher": "EEF",
      "title": "Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain",
      "affected": {
        "vendors": [
          "ZenHive"
        ],
        "products": [
          {
            "vendor": "ZenHive",
            "product": "mpp"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28937
      },
      "nvd": {
        "published": "2026-07-17T11:17:13.803",
        "lastModified": "2026-07-17T18:09:55.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59252",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mpp accepts a caller-selected gas limit without bounding the fee-payer exposure, allowing a transaction to consume an excessive sponsored fee budget.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ZenHive/mpp/security/advisories/GHSA-vj8p-hp9x-gh47",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-59252.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-59252",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/ZenHive/mpp/commit/d84e3e528db39654540c2035ea0fbdf7b950d3d1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1349,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59253",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:17:14.301Z",
      "date_published": "2026-07-08T13:49:12.902Z",
      "date_updated": "2026-07-08T14:31:44.900Z",
      "publisher": "VulnCheck",
      "title": "n8n - Improper Authorization in Workflow Assignment to Folders",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06212
      },
      "nvd": {
        "published": "2026-07-08T14:17:20.683",
        "lastModified": "2026-07-08T19:25:45.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59253",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts a caller-supplied object identifier without verifying that the selected object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-2xgm-wc4g-5jvg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-improper-authorization-in-workflow-assignment-to-folders",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 348,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59254",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:17:14.301Z",
      "date_published": "2026-07-15T11:25:34.866Z",
      "date_updated": "2026-07-15T13:25:43.797Z",
      "publisher": "VulnCheck",
      "title": "n8n - External Secrets Disclosure via Workflow Node Expressions",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18303
      },
      "nvd": {
        "published": "2026-07-15T12:18:17.663",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59254",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Workflow expressions resolve external secrets outside credential scope without checking the editor's explicit secret-access permission.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-2434-3x6q-8r99",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-external-secrets-disclosure-via-workflow-node-expressions",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-59255",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:17:14.301Z",
      "date_published": "2026-07-15T17:03:38.361Z",
      "date_updated": "2026-07-28T01:49:48.861Z",
      "publisher": "VulnCheck",
      "title": "BloodHound Missing Authorization on Custom Node Management API",
      "affected": {
        "vendors": [
          "SpecterOps"
        ],
        "products": [
          {
            "vendor": "SpecterOps",
            "product": "BloodHound"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.1591
      },
      "nvd": {
        "published": "2026-07-15T18:16:49.017",
        "lastModified": "2026-07-15T21:02:41.590",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59255",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Custom-node mutation endpoints accept any authenticated session without checking the role required to alter the global graph schema.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/SpecterOps/BloodHound/issues/2910",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/SpecterOps/BloodHound/pull/2989",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/SpecterOps/BloodHound/commit/8f790351349fd87bcb04377aba84cba6495825b3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/bloodhound-missing-authorization-on-custom-node-management-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 405,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59257",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:17:14.302Z",
      "date_published": "2026-07-08T13:49:13.618Z",
      "date_updated": "2026-07-09T13:39:51.132Z",
      "publisher": "VulnCheck",
      "title": "n8n - SQL Injection in MySQL v1 executeQuery Operation via Expression Interpolation",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 3.500000000000001,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23835
      },
      "nvd": {
        "published": "2026-07-08T14:17:20.807",
        "lastModified": "2026-07-09T15:16:39.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59257",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The legacy MySQL node substitutes evaluated workflow expression values directly into raw SQL instead of using parameters.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-hwmj-qg4v-cvg9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-sql-injection-in-mysql-v1-executequery-operation-via-expression-interpolation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 661,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-59258",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:17:14.302Z",
      "date_published": "2026-07-15T17:03:57.291Z",
      "date_updated": "2026-07-28T01:49:49.582Z",
      "publisher": "VulnCheck",
      "title": "immich < 3.0.3 Shared Album Editor Ownership Takeover via updateUser",
      "affected": {
        "vendors": [
          "immich-app"
        ],
        "products": [
          {
            "vendor": "immich-app",
            "product": "immich"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23842
      },
      "nvd": {
        "published": "2026-07-15T18:16:49.150",
        "lastModified": "2026-07-15T21:02:41.590",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59258",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The album membership update lets an editor assign owner roles without enforcing the owner-only role-transition rule.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/immich-app/immich/issues/29857",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/immich-app/immich/releases/tag/v3.0.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/immich-app/immich/pull/29883",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/immich-app/immich/commit/84dff19ca9a467752d848ff54763d62c04ebf960",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/immich-shared-album-editor-ownership-takeover-via-updateuser",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59259",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:17:14.302Z",
      "date_published": "2026-07-15T11:25:35.530Z",
      "date_updated": "2026-07-15T18:47:38.895Z",
      "publisher": "VulnCheck",
      "title": "n8n - Permission Bypass via Expression Parser Mismatch in External Secrets",
      "affected": {
        "vendors": [
          "n8n"
        ],
        "products": [
          {
            "vendor": "n8n",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23924
      },
      "nvd": {
        "published": "2026-07-15T12:18:17.797",
        "lastModified": "2026-07-16T20:08:36.057",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59259",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Static validation misses an external-secret reference form that the runtime expression engine later resolves with broader secret access.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-jp7m-xcgx-57qm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-permission-bypass-via-expression-parser-mismatch-in-external-secrets",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 657,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-59260",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:17:14.302Z",
      "date_published": "2026-07-12T12:06:35.592Z",
      "date_updated": "2026-07-14T22:03:27.226Z",
      "publisher": "VulnCheck",
      "title": "OpenWrt luci-app-samba4 read ACL remote code execution via smbd",
      "affected": {
        "vendors": [
          "openwrt"
        ],
        "products": [
          {
            "vendor": "openwrt",
            "product": "luci"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00714,
        "percentile": 0.50123
      },
      "nvd": {
        "published": "2026-07-12T12:16:45.977",
        "lastModified": "2026-07-13T20:03:31.703",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59260",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The LuCI read ACL grants file.exec on root-run smbd, letting delegated users supply command-triggering daemon options.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openwrt/luci/security/advisories/GHSA-vx64-mmp7-h36c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openwrt-luci-app-samba4-read-acl-remote-code-execution-via-smbd",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-59261",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:17:14.302Z",
      "date_published": "2026-07-08T16:01:14.371Z",
      "date_updated": "2026-07-20T17:45:55.824Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.00192,
        "percentile": 0.09143
      },
      "nvd": {
        "published": "2026-07-08T17:17:25.640",
        "lastModified": "2026-07-09T19:34:08.973",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59261",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A lower-trust workspace dotenv file is allowed to override provider credentials that should come only from the trusted process environment.",
        "basis": [
          "CNA",
          "CWE-184",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-4pqj-3c56-5fqq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-credential-override-via-workspace-dotenv-files",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 282,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59262",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T12:17:14.302Z",
      "date_published": "2026-07-08T15:44:07.878Z",
      "date_updated": "2026-07-20T17:45:56.523Z",
      "publisher": "VulnCheck",
      "title": "AFFiNE - Unauthorized Document Edit History Access via GraphQL histories Field",
      "affected": {
        "vendors": [
          "affine"
        ],
        "products": [
          {
            "vendor": "affine",
            "product": "monorepo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00238,
        "percentile": 0.1497
      },
      "nvd": {
        "published": "2026-07-08T16:16:31.430",
        "lastModified": "2026-07-10T18:46:32.250",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59262",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "monorepo fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/toeverything/AFFiNE/issues/15179",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/toeverything/AFFiNE",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/toeverything/AFFiNE/commit/1f0bcd01a37a522393fc1b288395e3a72a79ccad",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/affine-unauthorized-document-edit-history-access-via-graphql-histories-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 351,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59269",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T18:13:09.972Z",
      "date_published": "2026-07-09T07:12:10.791Z",
      "date_updated": "2026-07-09T12:45:41.171Z",
      "publisher": "vmware",
      "title": "Privilege Escalation via Active Directory LDAP injection in Pinniped Supervisor can be executed by an attacker who can edit LDAP Group DN entries",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Pinniped"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06656
      },
      "nvd": {
        "published": "2026-07-09T08:16:49.093",
        "lastModified": "2026-07-09T16:39:17.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59269",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A group distinguished name controlled in Active Directory is interpreted in Pinniped's group mapping without the required LDAP-context separation.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vmware/pinniped/security/advisories/GHSA-7xq8-m6h6-2xg8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 850,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T18:13:57.026Z",
      "date_published": "2026-07-30T12:19:52.390Z",
      "date_updated": "2026-07-30T15:08:05.176Z",
      "publisher": "vmware",
      "title": "vCenter authentication-bypass vulnerability",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Cloud Foundation"
          },
          {
            "vendor": "VMware",
            "product": "vSphere Foundation"
          },
          {
            "vendor": "VMware",
            "product": "vCenter"
          },
          {
            "vendor": "VMware",
            "product": "Telco Cloud Infrastructure"
          },
          {
            "vendor": "VMware",
            "product": "Telco Cloud Platform"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 13,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-303",
          "name": "Incorrect Implementation of Authentication Algorithm",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00744,
        "percentile": 0.512
      },
      "nvd": {
        "published": "2026-07-30T13:16:53.870",
        "lastModified": "2026-07-30T16:17:15.073",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59309",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in Cloud Foundation, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-303",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Read https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017; Broadcom identifies VMware Directory Service and fixed releases but does not disclose the authentication transition or failed validation."
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-59310",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T18:13:57.026Z",
      "date_published": "2026-07-30T12:19:25.296Z",
      "date_updated": "2026-07-30T15:03:36.898Z",
      "publisher": "vmware",
      "title": "vCenter directory-traversal vulnerability",
      "affected": {
        "vendors": [
          "VMware"
        ],
        "products": [
          {
            "vendor": "VMware",
            "product": "Cloud Foundation"
          },
          {
            "vendor": "VMware",
            "product": "vSphere Foundation"
          },
          {
            "vendor": "VMware",
            "product": "vCenter"
          },
          {
            "vendor": "VMware",
            "product": "Telco Cloud Infrastructure"
          },
          {
            "vendor": "VMware",
            "product": "Telco Cloud Platform"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 13,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0114,
        "percentile": 0.63478
      },
      "nvd": {
        "published": "2026-07-30T13:16:53.993",
        "lastModified": "2026-07-30T16:17:15.183",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59310",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The vCenter Syslog server accepts a traversal path that selects a location outside its intended directory and reaches code execution.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017",
          "host": "support.broadcom.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-59326",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T18:14:10.167Z",
      "date_published": "2026-07-30T05:34:08.304Z",
      "date_updated": "2026-07-30T13:37:06.802Z",
      "publisher": "vmware",
      "title": "HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server",
      "affected": {
        "vendors": [
          "Spring"
        ],
        "products": [
          {
            "vendor": "Spring",
            "product": "Spring Tools for Eclipse"
          },
          {
            "vendor": "Spring",
            "product": "Spring Tools for VSCode / Cursor / Theia"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00095,
        "percentile": 0.00797
      },
      "nvd": {
        "published": "2026-07-30T06:25:55.677",
        "lastModified": "2026-07-30T14:17:00.483",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59326",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Spring Boot language server logs proxy environment variables including embedded credentials without redaction.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://spring.io/security/cve-2026-59326",
          "host": "spring.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 734,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59327",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T18:14:10.167Z",
      "date_published": "2026-07-30T05:29:20.138Z",
      "date_updated": "2026-07-30T13:43:41.610Z",
      "publisher": "vmware",
      "title": "Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations",
      "affected": {
        "vendors": [
          "Spring"
        ],
        "products": [
          {
            "vendor": "Spring",
            "product": "Spring Tools for Eclipse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-312",
          "name": "Cleartext Storage of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00085,
        "percentile": 0.00382
      },
      "nvd": {
        "published": "2026-07-30T06:25:55.797",
        "lastModified": "2026-07-30T14:17:01.037",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59327",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Spring Tools stores the DevTools remote secret as plaintext in an Eclipse launch configuration.",
        "basis": [
          "CNA",
          "CWE-312"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://spring.io/security/cve-2026-59327",
          "host": "spring.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 894,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-04T18:14:10.167Z",
      "date_published": "2026-07-30T05:29:20.996Z",
      "date_updated": "2026-07-30T13:45:05.145Z",
      "publisher": "vmware",
      "title": "Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips",
      "affected": {
        "vendors": [
          "Spring"
        ],
        "products": [
          {
            "vendor": "Spring",
            "product": "Spring Tools for Eclipse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security@vmware.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.059
      },
      "nvd": {
        "published": "2026-07-30T06:25:55.920",
        "lastModified": "2026-07-30T14:17:01.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59328",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Eclipse starter wizard renders untrusted Initializr tooltip content in a JavaScript-enabled embedded browser without separating it from executable markup.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://spring.io/security/cve-2026-59328",
          "host": "spring.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 579,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59509",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T12:01:53.145Z",
      "date_published": "2026-07-05T12:02:06.985Z",
      "date_updated": "2026-07-06T13:28:15.975Z",
      "publisher": "CIRCL",
      "title": "Unauthenticated arbitrary MongoDB collection read in cve-search",
      "affected": {
        "vendors": [
          "cve-search"
        ],
        "products": [
          {
            "vendor": "cve-search",
            "product": "cve-search"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00349,
        "percentile": 0.27613
      },
      "nvd": {
        "published": "2026-07-05T13:16:56.127",
        "lastModified": "2026-07-06T19:36:05.123",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59509",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The fetch_cve_data endpoint lets an unauthenticated caller choose the MongoDB collection, projected fields, and regular-expression filter.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cve-search/cve-search/pull/1218",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/cve-search/cve-search/issues/1217",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 475,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59510",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T17:52:20.396Z",
      "date_published": "2026-07-05T17:52:29.429Z",
      "date_updated": "2026-07-06T13:22:56.591Z",
      "publisher": "CIRCL",
      "title": "Authenticated Path Traversal in AIL Framework PDF Object Handling Enables Potential Arbitrary File Read",
      "affected": {
        "vendors": [
          "ail-project"
        ],
        "products": [
          {
            "vendor": "ail-project",
            "product": "ail-framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/U:Clear"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29967
      },
      "nvd": {
        "published": "2026-07-05T18:16:57.080",
        "lastModified": "2026-07-06T19:36:05.123",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59510",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PDF.get_filepath() joins an object identifier to the PDF root without proving the canonical result remains under that root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ail-project/ail-framework/commit/14c618fce4d1df02358717c48ea903706abecdf2.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1008,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59511",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:29.080Z",
      "date_published": "2026-07-05T21:36:39.476Z",
      "date_updated": "2026-07-06T13:48:03.312Z",
      "publisher": "Patchstack",
      "title": "WordPress Exclusive Addons Elementor plugin <= 2.7.9.9 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Tim Strifler"
        ],
        "products": [
          {
            "vendor": "Tim Strifler",
            "product": "Exclusive Addons Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.095
      },
      "nvd": {
        "published": "2026-07-05T22:16:53.223",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59511",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected interface returns, embeds or leaves protected information visible to an observer who is not entitled to receive it.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/exclusive-addons-for-elementor/vulnerability/wordpress-exclusive-addons-elementor-plugin-2-7-9-9-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59512",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:29.080Z",
      "date_published": "2026-07-23T11:18:14.369Z",
      "date_updated": "2026-07-23T13:32:28.902Z",
      "publisher": "Patchstack",
      "title": "WordPress Product Enquiry for WooCommerce plugin <= 2.2.34.43 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "PI Web Solution"
        ],
        "products": [
          {
            "vendor": "PI Web Solution",
            "product": "Product Enquiry for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00191,
        "percentile": 0.09019
      },
      "nvd": {
        "published": "2026-07-23T12:18:31.860",
        "lastModified": "2026-07-23T14:17:27.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59512",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/enquiry-quotation-for-woocommerce/vulnerability/wordpress-product-enquiry-for-woocommerce-plugin-2-2-34-43-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59513",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:29.080Z",
      "date_published": "2026-07-23T11:18:15.028Z",
      "date_updated": "2026-07-23T13:44:09.148Z",
      "publisher": "Patchstack",
      "title": "WordPress Masteriyo - LMS plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "masteriyo"
        ],
        "products": [
          {
            "vendor": "masteriyo",
            "product": "Masteriyo - LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11502
      },
      "nvd": {
        "published": "2026-07-23T12:18:31.983",
        "lastModified": "2026-07-23T14:17:28.120",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59513",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Masteriyo - LMS page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/learning-management-system/vulnerability/wordpress-masteriyo-lms-plugin-2-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59514",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:29.080Z",
      "date_published": "2026-07-23T11:18:15.675Z",
      "date_updated": "2026-07-23T14:57:17.658Z",
      "publisher": "Patchstack",
      "title": "WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "MightyNetworks vs BuddyBoss"
        ],
        "products": [
          {
            "vendor": "MightyNetworks vs BuddyBoss",
            "product": "Buddyboss Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13849
      },
      "nvd": {
        "published": "2026-07-23T12:18:32.103",
        "lastModified": "2026-07-23T16:17:29.547",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59514",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BuddyBoss accepts unauthenticated input into an SQL statement without separating data from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/buddyboss-platform/vulnerability/wordpress-buddyboss-platform-plugin-3-0-5-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 70,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59515",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:29.080Z",
      "date_published": "2026-07-13T08:41:25.653Z",
      "date_updated": "2026-07-13T13:15:13.545Z",
      "publisher": "Patchstack",
      "title": "WordPress AIWU plugin <= 1.5.4 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Sergey"
        ],
        "products": [
          {
            "vendor": "Sergey",
            "product": "AIWU"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.1551
      },
      "nvd": {
        "published": "2026-07-13T10:16:45.737",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59515",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/ai-copilot-content-generator/vulnerability/wordpress-aiwu-plugin-1-5-4-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:29.080Z",
      "date_published": "2026-07-13T08:41:25.661Z",
      "date_updated": "2026-07-13T13:58:51.072Z",
      "publisher": "Patchstack",
      "title": "WordPress ICS Calendar plugin <= 12.1.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Room 34 Creative Services, LLC"
        ],
        "products": [
          {
            "vendor": "Room 34 Creative Services, LLC",
            "product": "ICS Calendar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03958
      },
      "nvd": {
        "published": "2026-07-13T10:16:45.860",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59516",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ICS Calendar reflects attacker input into an HTML page without context-appropriate neutralization.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/ics-calendar/vulnerability/wordpress-ics-calendar-plugin-12-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59517",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:29.080Z",
      "date_published": "2026-07-23T11:18:16.315Z",
      "date_updated": "2026-07-23T14:24:48.990Z",
      "publisher": "Patchstack",
      "title": "WordPress Easy Form Builder plugin <= 4.0.12 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "hassantafreshi"
        ],
        "products": [
          {
            "vendor": "hassantafreshi",
            "product": "Easy Form Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07745
      },
      "nvd": {
        "published": "2026-07-23T12:18:32.227",
        "lastModified": "2026-07-23T15:17:23.660",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59517",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Easy Form Builder renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/easy-form-builder/vulnerability/wordpress-easy-form-builder-plugin-4-0-12-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59518",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:29.080Z",
      "date_published": "2026-07-13T08:41:25.715Z",
      "date_updated": "2026-07-13T14:28:56.172Z",
      "publisher": "Patchstack",
      "title": "WordPress Directorist plugin <= 8.8.2 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "wpWax"
        ],
        "products": [
          {
            "vendor": "wpWax",
            "product": "Directorist"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22762
      },
      "nvd": {
        "published": "2026-07-13T10:16:45.977",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59518",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Directorist deserializes attacker-controlled PHP object data.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/directorist/vulnerability/wordpress-directorist-plugin-8-8-2-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 163,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59519",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:29.081Z",
      "date_published": "2026-07-05T21:42:33.988Z",
      "date_updated": "2026-07-07T02:53:38.126Z",
      "publisher": "Patchstack",
      "title": "WordPress FormLayer plugin <= 1.0.6 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Softaculous"
        ],
        "products": [
          {
            "vendor": "Softaculous",
            "product": "FormLayer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09499
      },
      "nvd": {
        "published": "2026-07-05T22:16:53.357",
        "lastModified": "2026-07-07T04:17:55.610",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59519",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "FormLayer sends protected embedded data beyond its intended audience, while the Patchstack record does not identify the data field, response, or recipient boundary.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/formlayer/vulnerability/wordpress-formlayer-plugin-1-0-6-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 184,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59520",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:29.081Z",
      "date_published": "2026-07-05T21:44:29.015Z",
      "date_updated": "2026-07-06T15:14:38.329Z",
      "publisher": "Patchstack",
      "title": "WordPress CrawlWP SEO plugin <= 3.0.16 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "properfraction"
        ],
        "products": [
          {
            "vendor": "properfraction",
            "product": "CrawlWP SEO"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.01004
      },
      "nvd": {
        "published": "2026-07-05T22:16:53.473",
        "lastModified": "2026-07-06T18:02:49.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59520",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The record identifies a cross-site request-forgery path in CrawlWP SEO but does not disclose the state-changing request or missing nonce or origin check.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mihdan-index-now/vulnerability/wordpress-index-now-plugin-3-0-16-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59521",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:42.076Z",
      "date_published": "2026-07-13T08:41:25.743Z",
      "date_updated": "2026-07-13T14:20:03.736Z",
      "publisher": "Patchstack",
      "title": "WordPress Real Testimonials plugin <= 3.1.15 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "ShapedPlugin LLC"
        ],
        "products": [
          {
            "vendor": "ShapedPlugin LLC",
            "product": "Real Testimonials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21348
      },
      "nvd": {
        "published": "2026-07-13T10:16:46.093",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59521",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Real Testimonials deserializes attacker-controlled PHP object data, allowing serialized input to select object behavior.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/testimonial-free/vulnerability/wordpress-real-testimonials-plugin-3-1-15-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59522",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:42.076Z",
      "date_published": "2026-07-23T11:18:16.958Z",
      "date_updated": "2026-07-23T16:00:09.956Z",
      "publisher": "Patchstack",
      "title": "WordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "weDevs"
        ],
        "products": [
          {
            "vendor": "weDevs",
            "product": "WP ERP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24043
      },
      "nvd": {
        "published": "2026-07-23T12:18:32.347",
        "lastModified": "2026-07-23T16:17:29.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59522",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Patchstack record reports Subscriber-level broken access control in WP ERP but does not identify the handler, protected object, or omitted capability check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/erp/vulnerability/wordpress-wp-erp-plugin-1-17-5-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 62,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59523",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:42.076Z",
      "date_published": "2026-07-13T08:41:25.749Z",
      "date_updated": "2026-07-13T10:09:02.786Z",
      "publisher": "Patchstack",
      "title": "WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "NSquared"
        ],
        "products": [
          {
            "vendor": "NSquared",
            "product": "Simply Schedule Appointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05145
      },
      "nvd": {
        "published": "2026-07-13T10:16:46.207",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59523",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected action is available without a sufficient authorization decision, but the omitted check is not disclosed.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/simply-schedule-appointments/vulnerability/wordpress-simply-schedule-appointments-plugin-1-6-11-11-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59524",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:42.076Z",
      "date_published": "2026-07-23T11:18:17.600Z",
      "date_updated": "2026-07-23T14:52:58.253Z",
      "publisher": "Patchstack",
      "title": "WordPress Easy Digital Downloads plugin <= 3.6.7 - Broken Authentication vulnerability",
      "affected": {
        "vendors": [
          "Sandhills Development, LLC"
        ],
        "products": [
          {
            "vendor": "Sandhills Development, LLC",
            "product": "Easy Digital Downloads"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21808
      },
      "nvd": {
        "published": "2026-07-23T12:18:32.467",
        "lastModified": "2026-07-23T15:17:24.497",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59524",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive Easy Digital Downloads operation is reachable through a path that does not enforce the required authentication.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/easy-digital-downloads/vulnerability/wordpress-easy-digital-downloads-plugin-3-6-7-broken-authentication-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59525",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:42.077Z",
      "date_published": "2026-07-23T11:18:18.247Z",
      "date_updated": "2026-07-23T13:32:09.728Z",
      "publisher": "Patchstack",
      "title": "WordPress Participants Database plugin <= 2.7.8.3 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Roland Barker"
        ],
        "products": [
          {
            "vendor": "Roland Barker",
            "product": "Participants Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14723
      },
      "nvd": {
        "published": "2026-07-23T12:18:32.590",
        "lastModified": "2026-07-23T14:17:28.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59525",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Participants Database incorporates unauthenticated input into an SQL statement without preserving the SQL grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/participants-database/vulnerability/wordpress-participants-database-plugin-2-7-8-3-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59526",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:42.077Z",
      "date_published": "2026-07-23T11:18:18.903Z",
      "date_updated": "2026-07-23T13:51:11.045Z",
      "publisher": "Patchstack",
      "title": "WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "RomanCode"
        ],
        "products": [
          {
            "vendor": "RomanCode",
            "product": "MapSVG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14723
      },
      "nvd": {
        "published": "2026-07-23T12:18:32.707",
        "lastModified": "2026-07-23T14:17:28.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59526",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "MapSVG accepts unauthenticated input that becomes a SQL query, while Patchstack does not publish the parameter, query construction, or database sink.",
        "basis": [
          "CNA",
          "CWE-89",
          "Patchstack PSID 053d1ebd6c1d"
        ],
        "deepDive": true,
        "notes": "Inspected https://patchstack.com/database/wordpress/plugin/mapsvg/vulnerability/wordpress-mapsvg-plugin-8-14-0-sql-injection-vulnerability-3. Patchstack confirms unauthenticated SQL injection, affected versions through 8.14.0, fixed version 8.14.1, and CVSS 9.3, but publishes no parameter, query construction, or database sink."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mapsvg/vulnerability/wordpress-mapsvg-plugin-8-14-0-sql-injection-vulnerability-3?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 59,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:42.077Z",
      "date_published": "2026-07-27T13:59:00.507Z",
      "date_updated": "2026-07-27T16:18:29.631Z",
      "publisher": "Patchstack",
      "title": "WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "RomanCode"
        ],
        "products": [
          {
            "vendor": "RomanCode",
            "product": "MapSVG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14723
      },
      "nvd": {
        "published": "2026-07-27T15:17:03.017",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59527",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MapSVG passes unauthenticated input into an SQL statement without SQL grammar separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mapsvg-lite-interactive-vector-maps/vulnerability/wordpress-mapsvg-plugin-8-14-0-sql-injection-vulnerability-4?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 59,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59528",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:42.077Z",
      "date_published": "2026-07-27T13:59:01.165Z",
      "date_updated": "2026-07-27T16:10:08.411Z",
      "publisher": "Patchstack",
      "title": "WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "shiptime"
        ],
        "products": [
          {
            "vendor": "shiptime",
            "product": "ShipTime: Discounted Shipping Rates"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00398,
        "percentile": 0.32561
      },
      "nvd": {
        "published": "2026-07-27T15:17:03.177",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59528",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/shiptime-discount-shipping/vulnerability/wordpress-shiptime-discounted-shipping-rates-plugin-1-1-1-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 92,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59529",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:42.077Z",
      "date_published": "2026-07-27T13:59:01.811Z",
      "date_updated": "2026-07-27T14:54:15.014Z",
      "publisher": "Patchstack",
      "title": "WordPress Ebook Store plugin <= 6.19 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "motov.net"
        ],
        "products": [
          {
            "vendor": "motov.net",
            "product": "Ebook Store"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.2091
      },
      "nvd": {
        "published": "2026-07-27T15:17:03.310",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59529",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Ebook Store exposes sensitive data to an unauthenticated caller, while the public record does not identify the endpoint, object, or missing ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ebook-store/vulnerability/wordpress-ebook-store-plugin-6-19-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 72,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:42.077Z",
      "date_published": "2026-07-27T13:59:02.453Z",
      "date_updated": "2026-07-27T15:08:50.487Z",
      "publisher": "Patchstack",
      "title": "WordPress Stripe For WooCommerce plugin <= 4.0.7 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Payment Plugins"
        ],
        "products": [
          {
            "vendor": "Payment Plugins",
            "product": "Stripe For WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15854
      },
      "nvd": {
        "published": "2026-07-27T15:17:03.433",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59530",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/woo-stripe-payment/vulnerability/wordpress-stripe-for-woocommerce-plugin-4-0-7-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59531",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:50.222Z",
      "date_published": "2026-07-27T13:59:03.100Z",
      "date_updated": "2026-07-27T18:10:17.414Z",
      "publisher": "Patchstack",
      "title": "WordPress Falcon – WordPress Optimizations & Tweaks plugin <= 2.10.0 - Unknown vulnerability",
      "affected": {
        "vendors": [
          "Anh Tran"
        ],
        "products": [
          {
            "vendor": "Anh Tran",
            "product": "Falcon – WordPress Optimizations & Tweaks"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24867
      },
      "nvd": {
        "published": "2026-07-27T15:17:03.560",
        "lastModified": "2026-07-27T19:17:18.440",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59531",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The publisher labels the issue unknown and provides no operation, state transition, parser, or failing security check to classify.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/falcon/vulnerability/wordpress-falcon-wordpress-optimizations-tweaks-plugin-2-10-0-unknown-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 88,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59532",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:50.222Z",
      "date_published": "2026-07-27T13:59:03.746Z",
      "date_updated": "2026-07-27T16:38:02.934Z",
      "publisher": "Patchstack",
      "title": "WordPress Booking and Rental Manager plugin <= 2.7.2 - Price Manipulation vulnerability",
      "affected": {
        "vendors": [
          "magepeopleteam"
        ],
        "products": [
          {
            "vendor": "magepeopleteam",
            "product": "Booking and Rental Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17511
      },
      "nvd": {
        "published": "2026-07-27T15:17:03.687",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59532",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The booking workflow accepts a client-supplied price-related value without validating it against the server's allowed purchase terms.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/booking-and-rental-manager-for-woocommerce/vulnerability/wordpress-booking-and-rental-manager-plugin-2-7-2-price-manipulation-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 89,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59533",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:50.222Z",
      "date_published": "2026-07-27T13:59:04.398Z",
      "date_updated": "2026-07-27T16:18:21.075Z",
      "publisher": "Patchstack",
      "title": "WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Christoph Vielgrader"
        ],
        "products": [
          {
            "vendor": "Christoph Vielgrader",
            "product": "Relevanssi Light"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14723
      },
      "nvd": {
        "published": "2026-07-27T15:17:03.817",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59533",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Relevanssi Light incorporates an unauthenticated request value into SQL without preserving the query grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/relevanssi-light/vulnerability/wordpress-relevanssi-light-plugin-1-2-2-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 68,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59534",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:50.222Z",
      "date_published": "2026-07-27T13:59:05.037Z",
      "date_updated": "2026-07-27T16:09:44.216Z",
      "publisher": "Patchstack",
      "title": "WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Aurovrata Venet"
        ],
        "products": [
          {
            "vendor": "Aurovrata Venet",
            "product": "Post My CF7 Form"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15854
      },
      "nvd": {
        "published": "2026-07-27T15:17:03.943",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59534",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated caller can invoke a protected plugin operation, but the endpoint, object, and missing authorization check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/post-my-contact-form-7/vulnerability/wordpress-post-my-cf7-form-plugin-6-2-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 76,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:50.222Z",
      "date_published": "2026-07-27T13:59:05.678Z",
      "date_updated": "2026-07-27T14:54:48.414Z",
      "publisher": "Patchstack",
      "title": "WordPress Thrive Product Manager plugin <= 10.9.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Thrive Themes Coupon"
        ],
        "products": [
          {
            "vendor": "Thrive Themes Coupon",
            "product": "Thrive Product Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00219,
        "percentile": 0.12474
      },
      "nvd": {
        "published": "2026-07-27T15:17:04.070",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59535",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Thrive Product Manager operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/thrive-product-manager/vulnerability/wordpress-thrive-product-manager-plugin-10-9-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:50.222Z",
      "date_published": "2026-07-27T13:59:06.324Z",
      "date_updated": "2026-07-27T15:06:23.333Z",
      "publisher": "Patchstack",
      "title": "WordPress CoCart – Headless ecommerce plugin <= 4.8.4 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "CoCart Headless"
        ],
        "products": [
          {
            "vendor": "CoCart Headless",
            "product": "CoCart – Headless ecommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15855
      },
      "nvd": {
        "published": "2026-07-27T15:17:04.203",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59536",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "CoCart exposes an unauthenticated operation, but the public record does not identify the protected resource or missing authorization check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/cart-rest-api-for-woocommerce/vulnerability/wordpress-cocart-headless-ecommerce-plugin-4-8-4-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 87,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:50.222Z",
      "date_published": "2026-07-27T13:59:06.968Z",
      "date_updated": "2026-07-27T18:11:10.853Z",
      "publisher": "Patchstack",
      "title": "WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin <= 2.10.22 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Sender"
        ],
        "products": [
          {
            "vendor": "Sender",
            "product": "Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20116
      },
      "nvd": {
        "published": "2026-07-27T15:17:04.333",
        "lastModified": "2026-07-27T19:17:18.550",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59537",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce, attacker-controlled values reach an SQL statement without the required escaping or parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/sender-net-automated-emails/vulnerability/wordpress-sender-newsletter-sms-and-email-marketing-automation-for-woocommerce-plugin-2-10-22-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:50.222Z",
      "date_published": "2026-07-27T13:59:07.615Z",
      "date_updated": "2026-07-27T16:36:29.284Z",
      "publisher": "Patchstack",
      "title": "WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Ruben Garcia"
        ],
        "products": [
          {
            "vendor": "Ruben Garcia",
            "product": "GamiPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14725
      },
      "nvd": {
        "published": "2026-07-27T15:17:04.460",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59538",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GamiPress incorporates attacker-controlled values or identifiers into a SQL statement without preserving the boundary between query syntax and data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/gamipress/vulnerability/wordpress-gamipress-plugin-7-9-7-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 61,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59539",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:50.223Z",
      "date_published": "2026-07-27T13:59:08.257Z",
      "date_updated": "2026-07-27T16:18:13.296Z",
      "publisher": "Patchstack",
      "title": "WordPress Paid Member Subscriptions plugin <= 3.0.7 - Insecure Direct Object References (IDOR) vulnerability",
      "affected": {
        "vendors": [
          "Cozmoslabs"
        ],
        "products": [
          {
            "vendor": "Cozmoslabs",
            "product": "Paid Member Subscriptions"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24748
      },
      "nvd": {
        "published": "2026-07-27T15:17:04.583",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59539",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Paid Member Subscriptions accepts a subscriber-controlled object reference without verifying that the referenced object belongs to that subscriber.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/paid-member-subscriptions/vulnerability/wordpress-paid-member-subscriptions-plugin-3-0-7-insecure-direct-object-references-idor-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59540",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:50.223Z",
      "date_published": "2026-07-23T11:18:19.570Z",
      "date_updated": "2026-07-23T14:53:46.102Z",
      "publisher": "Patchstack",
      "title": "WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalation vulnerability",
      "affected": {
        "vendors": [
          "Cozy Vision Technologies Pvt. Ltd."
        ],
        "products": [
          {
            "vendor": "Cozy Vision Technologies Pvt. Ltd.",
            "product": "SMS Alert Order Notifications"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18802
      },
      "nvd": {
        "published": "2026-07-23T12:18:32.830",
        "lastModified": "2026-07-23T16:17:29.753",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59540",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in SMS Alert Order Notifications, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-266",
          "Vendor changelog"
        ],
        "deepDive": true,
        "notes": "Read the vendor-hosted plugin changelog at https://wordpress.org/plugins/sms-alert/; version 3.9.7 records a security fix for admin-settings updates but does not identify the vulnerable handler or missing capability check."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/sms-alert/vulnerability/wordpress-sms-alert-order-notifications-plugin-3-9-6-privilege-escalation-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 88,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59541",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:56.024Z",
      "date_published": "2026-07-23T11:18:20.227Z",
      "date_updated": "2026-07-23T14:25:27.109Z",
      "publisher": "Patchstack",
      "title": "WordPress WP BASE Booking plugin <= 6.3.1 - Privilege Escalation vulnerability",
      "affected": {
        "vendors": [
          "Hakan Ozevin"
        ],
        "products": [
          {
            "vendor": "Hakan Ozevin",
            "product": "WP BASE Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23931
      },
      "nvd": {
        "published": "2026-07-23T12:18:32.943",
        "lastModified": "2026-07-23T15:17:25.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59541",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "WP BASE Booking lets a subscriber obtain privileges that the subscriber role should not be able to assign.",
        "basis": [
          "CNA",
          "CWE-266"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-base-booking-of-appointments-services-and-events/vulnerability/wordpress-wp-base-booking-plugin-6-3-1-privilege-escalation-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 69,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59542",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:56.024Z",
      "date_published": "2026-07-23T11:18:20.877Z",
      "date_updated": "2026-07-23T15:59:52.700Z",
      "publisher": "Patchstack",
      "title": "WordPress Kali Forms plugin <= 2.4.18 - Arbitrary File Deletion vulnerability",
      "affected": {
        "vendors": [
          "WP Chill"
        ],
        "products": [
          {
            "vendor": "WP Chill",
            "product": "Kali Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0045,
        "percentile": 0.369
      },
      "nvd": {
        "published": "2026-07-23T12:18:33.067",
        "lastModified": "2026-07-23T16:17:29.853",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59542",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kali Forms lets a subscriber select a file outside the intended deletion namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/kali-forms/vulnerability/wordpress-kali-forms-plugin-2-4-18-arbitrary-file-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 68,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59543",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:56.024Z",
      "date_published": "2026-07-23T11:18:21.530Z",
      "date_updated": "2026-07-23T14:52:46.087Z",
      "publisher": "Patchstack",
      "title": "WordPress Advanced Views plugin <= 3.8.11 - Remote Code Execution (RCE) vulnerability",
      "affected": {
        "vendors": [
          "WPLake"
        ],
        "products": [
          {
            "vendor": "WPLake",
            "product": "Advanced Views"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00597,
        "percentile": 0.45166
      },
      "nvd": {
        "published": "2026-07-23T12:18:33.193",
        "lastModified": "2026-07-23T15:17:26.207",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59543",
        "family": "AUTHORITY_BINDING",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "Advanced Views let any logged-in user reach Layout and Selection preview REST routes and let unguarded ACF save hooks persist executable controller fields that those previews evaluate.",
        "basis": [
          "CNA",
          "CWE-94",
          "WordPress plugin source 3.8.11/3.9.0/3.9.2"
        ],
        "deepDive": true,
        "notes": "Inspected official WordPress.org archives 3.8.11, 3.9.0, 3.9.1, and 3.9.2: 3.8.11 used is_user_logged_in on the preview route, 3.9.0 wrapped save hooks with Avf_User::can_manage, and 3.9.2 changed the preview permission callback to Avf_User::can_manage; no runtime reproduction was performed. Sources: https://downloads.wordpress.org/plugin/acf-views.3.8.11.zip and https://downloads.wordpress.org/plugin/acf-views.3.9.2.zip."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/acf-views/vulnerability/wordpress-advanced-views-plugin-3-8-11-remote-code-execution-rce-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 76,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59544",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:56.024Z",
      "date_published": "2026-07-23T11:18:22.172Z",
      "date_updated": "2026-07-23T13:31:49.098Z",
      "publisher": "Patchstack",
      "title": "WordPress Thrive Quiz Builder plugin <= 10.9.3.0 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "Thrive Themes Coupon"
        ],
        "products": [
          {
            "vendor": "Thrive Themes Coupon",
            "product": "Thrive Quiz Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23732
      },
      "nvd": {
        "published": "2026-07-23T12:18:33.313",
        "lastModified": "2026-07-23T14:17:29.417",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59544",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/thrive-quiz-builder/vulnerability/wordpress-thrive-quiz-builder-plugin-10-9-3-0-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 81,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59545",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:56.024Z",
      "date_published": "2026-07-23T11:18:22.825Z",
      "date_updated": "2026-07-23T13:50:43.295Z",
      "publisher": "Patchstack",
      "title": "WordPress miniOrange Discord Integration plugin <= 2.2.4 - Broken Authentication vulnerability",
      "affected": {
        "vendors": [
          "miniOrange"
        ],
        "products": [
          {
            "vendor": "miniOrange",
            "product": "miniOrange Discord Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18725
      },
      "nvd": {
        "published": "2026-07-23T12:18:33.433",
        "lastModified": "2026-07-23T14:17:29.857",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59545",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Patchstack record identifies broken authentication in the Discord integration but does not disclose the accepted credential or endpoint.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/miniorange-discord-integration/vulnerability/wordpress-miniorange-discord-integration-plugin-2-2-4-broken-authentication-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 90,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59546",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:56.024Z",
      "date_published": "2026-07-27T13:59:08.900Z",
      "date_updated": "2026-07-27T16:09:14.102Z",
      "publisher": "Patchstack",
      "title": "WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass vulnerability",
      "affected": {
        "vendors": [
          "John Darrel"
        ],
        "products": [
          {
            "vendor": "John Darrel",
            "product": "Hide My WP Ghost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.2879
      },
      "nvd": {
        "published": "2026-07-27T15:17:04.710",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59546",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/hide-my-wp/vulnerability/wordpress-hide-my-wp-ghost-plugin-7-0-06-2fa-bypass-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 72,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59547",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:56.024Z",
      "date_published": "2026-07-23T11:18:23.445Z",
      "date_updated": "2026-07-23T14:55:59.346Z",
      "publisher": "Patchstack",
      "title": "WordPress Payment Gateway for PayPal on WooCommerce plugin <= 9.1.4 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Easy Payment"
        ],
        "products": [
          {
            "vendor": "Easy Payment",
            "product": "Payment Gateway for PayPal on WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15856
      },
      "nvd": {
        "published": "2026-07-23T12:18:33.557",
        "lastModified": "2026-07-23T16:17:29.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59547",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/woo-paypal-gateway/vulnerability/wordpress-payment-gateway-for-paypal-on-woocommerce-plugin-9-1-4-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59548",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:56.024Z",
      "date_published": "2026-07-27T13:59:09.542Z",
      "date_updated": "2026-07-27T14:57:50.345Z",
      "publisher": "Patchstack",
      "title": "WordPress Byteflows Travel & Hotel Booking plugin <= 1.0.0 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Byteflows"
        ],
        "products": [
          {
            "vendor": "Byteflows",
            "product": "Byteflows Travel &amp; Hotel Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22577
      },
      "nvd": {
        "published": "2026-07-27T15:17:04.837",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59548",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Sensitive data is returned, stored, or left readable through an output path that lacks the required disclosure boundary.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/byteflows-travel-hotel-booking/vulnerability/wordpress-byteflows-travel-hotel-booking-plugin-1-0-0-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59549",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:56.024Z",
      "date_published": "2026-07-27T13:59:10.192Z",
      "date_updated": "2026-07-27T15:09:35.438Z",
      "publisher": "Patchstack",
      "title": "WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "rtCamp"
        ],
        "products": [
          {
            "vendor": "rtCamp",
            "product": "rtMedia for WordPress, BuddyPress and bbPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14724
      },
      "nvd": {
        "published": "2026-07-27T15:17:04.960",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59549",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a rtMedia for WordPress, BuddyPress and bbPress database query without safe parameter binding, allowing query syntax injection.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/buddypress-media/vulnerability/wordpress-rtmedia-for-wordpress-buddypress-and-bbpress-plugin-4-7-10-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59550",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:27:56.024Z",
      "date_published": "2026-07-27T13:59:10.839Z",
      "date_updated": "2026-07-27T18:11:52.196Z",
      "publisher": "Patchstack",
      "title": "WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Strategy11 Team"
        ],
        "products": [
          {
            "vendor": "Strategy11 Team",
            "product": "AWP Classifieds"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14724
      },
      "nvd": {
        "published": "2026-07-27T15:17:05.090",
        "lastModified": "2026-07-27T19:17:18.660",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59550",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/another-wordpress-classifieds-plugin/vulnerability/wordpress-awp-classifieds-plugin-4-4-7-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 67,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59551",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:28:04.586Z",
      "date_published": "2026-07-27T13:59:11.486Z",
      "date_updated": "2026-07-27T16:33:38.797Z",
      "publisher": "Patchstack",
      "title": "WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "rtCamp"
        ],
        "products": [
          {
            "vendor": "rtCamp",
            "product": "rtMedia for WordPress, BuddyPress and bbPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19969
      },
      "nvd": {
        "published": "2026-07-27T15:17:05.223",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59551",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A subscriber-controlled rtMedia value reaches an SQL query without separating data from SQL syntax.",
        "basis": [
          "CNA record",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/buddypress-media/vulnerability/wordpress-rtmedia-for-wordpress-buddypress-and-bbpress-plugin-4-7-10-sql-injection-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59552",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:28:04.586Z",
      "date_published": "2026-07-27T13:59:12.131Z",
      "date_updated": "2026-07-27T16:18:02.783Z",
      "publisher": "Patchstack",
      "title": "WordPress 3D Flipbook PDF Viewer & Embedder plugin <= 1.4.2 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "Shahadat Hossain"
        ],
        "products": [
          {
            "vendor": "Shahadat Hossain",
            "product": "3D Flipbook PDF Viewer &amp; Embedder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09323
      },
      "nvd": {
        "published": "2026-07-27T15:17:05.350",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59552",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "3D Flipbook PDF Viewer &amp; Embedder accepts an attacker-controlled server request target without constraining it to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/pdf-embed-viewer/vulnerability/wordpress-3d-flipbook-pdf-viewer-embedder-plugin-1-4-2-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 110,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59553",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:28:04.587Z",
      "date_published": "2026-07-27T13:59:12.758Z",
      "date_updated": "2026-07-27T16:08:49.896Z",
      "publisher": "Patchstack",
      "title": "WordPress Product Feed Manager plugin <= 7.6.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "RexTheme"
        ],
        "products": [
          {
            "vendor": "RexTheme",
            "product": "Product Feed Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07758
      },
      "nvd": {
        "published": "2026-07-27T15:17:05.483",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59553",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Product Feed Manager emits unauthenticated input into page markup without neutralizing executable script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/best-woocommerce-feed/vulnerability/wordpress-product-feed-manager-plugin-7-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 85,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59554",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:28:04.587Z",
      "date_published": "2026-07-23T11:18:24.085Z",
      "date_updated": "2026-07-23T14:26:03.408Z",
      "publisher": "Patchstack",
      "title": "WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability",
      "affected": {
        "vendors": [
          "Ziina"
        ],
        "products": [
          {
            "vendor": "Ziina",
            "product": "Ziina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1390",
          "name": "Weak Authentication",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21649
      },
      "nvd": {
        "published": "2026-07-23T12:18:33.680",
        "lastModified": "2026-07-23T15:17:27.027",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59554",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Ziina permits unauthenticated use of an authentication-sensitive function, while the Patchstack record does not identify the credential, endpoint, or failing validation step.",
        "basis": [
          "CNA",
          "CWE-1390"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ziina/vulnerability/wordpress-ziina-plugin-1-2-21-broken-authentication-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 66,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59555",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:28:04.587Z",
      "date_published": "2026-07-23T11:18:24.720Z",
      "date_updated": "2026-07-23T16:05:31.206Z",
      "publisher": "Patchstack",
      "title": "WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerability",
      "affected": {
        "vendors": [
          "Roland Barker"
        ],
        "products": [
          {
            "vendor": "Roland Barker",
            "product": "Participants Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0038,
        "percentile": 0.30789
      },
      "nvd": {
        "published": "2026-07-23T12:18:33.803",
        "lastModified": "2026-07-23T16:17:30.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59555",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The plugin permits an unauthenticated caller to select an arbitrary file for deletion, but the public advisory does not disclose the path parameter or confinement check.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-22",
          "Patchstack advisory"
        ],
        "deepDive": true,
        "notes": "Inspected the primary Patchstack page https://patchstack.com/database/wordpress/plugin/participants-database/vulnerability/wordpress-participants-database-plugin-2-7-8-3-arbitrary-file-deletion-vulnerability; it confirms the unauthenticated arbitrary-file-deletion title, affected version, and severity, but exposes no filename parameter, confinement check, or patch details."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/participants-database/vulnerability/wordpress-participants-database-plugin-2-7-8-3-arbitrary-file-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 85,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59556",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:28:04.587Z",
      "date_published": "2026-07-27T13:59:13.565Z",
      "date_updated": "2026-07-27T14:58:18.183Z",
      "publisher": "Patchstack",
      "title": "WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.11 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "acowebs"
        ],
        "products": [
          {
            "vendor": "acowebs",
            "product": "Dynamic Pricing With Discount Rules for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.0776
      },
      "nvd": {
        "published": "2026-07-27T15:17:05.620",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59556",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dynamic Pricing stores or reflects unauthenticated input into browser-interpreted output without sufficient contextual neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/aco-woo-dynamic-pricing/vulnerability/wordpress-dynamic-pricing-with-discount-rules-for-woocommerce-plugin-4-5-11-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59557",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:28:04.587Z",
      "date_published": "2026-07-27T13:59:14.237Z",
      "date_updated": "2026-07-27T14:56:59.308Z",
      "publisher": "Patchstack",
      "title": "WordPress Events Made Easy plugin <= 3.1.3 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Franky"
        ],
        "products": [
          {
            "vendor": "Franky",
            "product": "Events Made Easy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15431
      },
      "nvd": {
        "published": "2026-07-27T15:17:05.750",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59557",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Patchstack record reports unauthenticated broken access control in Events Made Easy but does not identify the handler, protected object, or omitted gate.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/events-made-easy/vulnerability/wordpress-events-made-easy-plugin-3-1-3-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 76,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59558",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:28:04.587Z",
      "date_published": "2026-07-27T13:59:14.892Z",
      "date_updated": "2026-07-27T18:12:48.121Z",
      "publisher": "Patchstack",
      "title": "WordPress Booking Calendar plugin <= 11.4.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "wpdevelop"
        ],
        "products": [
          {
            "vendor": "wpdevelop",
            "product": "Booking Calendar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07747
      },
      "nvd": {
        "published": "2026-07-27T15:17:05.883",
        "lastModified": "2026-07-27T19:17:18.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59558",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted content enters an executable grammar without contextual neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/booking/vulnerability/wordpress-booking-calendar-plugin-11-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59559",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:28:04.587Z",
      "date_published": "2026-07-27T13:59:15.530Z",
      "date_updated": "2026-07-27T16:30:45.174Z",
      "publisher": "Patchstack",
      "title": "WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "themewant"
        ],
        "products": [
          {
            "vendor": "themewant",
            "product": "RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11501
      },
      "nvd": {
        "published": "2026-07-27T15:17:06.170",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59559",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/rt-mega-menu/vulnerability/wordpress-rt-mega-menu-mega-menu-builder-for-elementor-gutenberg-plugin-1-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 122,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59560",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-05T21:28:04.587Z",
      "date_published": "2026-07-27T13:59:16.161Z",
      "date_updated": "2026-07-27T16:17:54.008Z",
      "publisher": "Patchstack",
      "title": "WordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Roxnor"
        ],
        "products": [
          {
            "vendor": "Roxnor",
            "product": "FundEngine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27909
      },
      "nvd": {
        "published": "2026-07-27T15:17:06.303",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59560",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected endpoint omits an authorization decision, but the public record does not identify the protected action or object binding.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-fundraising-donation/vulnerability/wordpress-fundengine-plugin-1-7-8-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 65,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59674",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T11:59:28.118Z",
      "date_published": "2026-07-14T07:32:35.363Z",
      "date_updated": "2026-07-15T04:00:53.092Z",
      "publisher": "suse",
      "title": "LPE from suricata user to root due to chown in %post in suricata packaging",
      "affected": {
        "vendors": [
          "SUSE"
        ],
        "products": [
          {
            "vendor": "SUSE",
            "product": "openSUSE Tumbleweed"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-61",
          "name": "UNIX Symbolic Link (Symlink) Following",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/S:N"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02985
      },
      "nvd": {
        "published": "2026-07-14T08:16:22.963",
        "lastModified": "2026-07-15T21:00:44.900",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59674",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The openSUSE Tumbleweed Suricata package follows a filesystem symlink controlled by the suricata user during privileged package operation, allowing the target to be replaced or written as root.",
        "basis": [
          "CNA",
          "CWE-61"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-59674",
          "host": "bugzilla.suse.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59676",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T11:59:28.118Z",
      "date_published": "2026-07-23T06:40:22.453Z",
      "date_updated": "2026-07-23T14:02:37.379Z",
      "publisher": "suse",
      "title": "Local File Deletion Attack Vector in rm_rf() in seunshare",
      "affected": {
        "vendors": [
          "SELinuxProject"
        ],
        "products": [
          {
            "vendor": "SELinuxProject",
            "product": "selinux"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00087,
        "percentile": 0.00438
      },
      "nvd": {
        "published": "2026-07-23T07:16:32.540",
        "lastModified": "2026-07-23T15:26:19.260",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59676",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "seunshare checks a target path and later deletes it in a separate step, allowing a local user to replace it before the root-owned deletion.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=1268256",
          "host": "bugzilla.suse.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://security.opensuse.org/2026/07/15/selinux-seunshare.html",
          "host": "security.opensuse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59677",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T11:59:28.118Z",
      "date_published": "2026-07-23T06:43:53.717Z",
      "date_updated": "2026-07-23T14:02:15.778Z",
      "publisher": "suse",
      "title": "Process Kill Attack Vector in killall() in seunshare",
      "affected": {
        "vendors": [
          "SELinuxProject"
        ],
        "products": [
          {
            "vendor": "SELinuxProject",
            "product": "selinux"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01316
      },
      "nvd": {
        "published": "2026-07-23T08:16:24.737",
        "lastModified": "2026-07-23T15:26:19.260",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59677",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=1268256",
          "host": "bugzilla.suse.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://security.opensuse.org/2026/07/15/selinux-seunshare.html",
          "host": "security.opensuse.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59678",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T11:59:28.118Z",
      "date_published": "2026-07-23T06:48:56.680Z",
      "date_updated": "2026-07-23T14:01:55.520Z",
      "publisher": "suse",
      "title": "portprotonqt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager",
      "affected": {
        "vendors": [
          "Linux-Gaming"
        ],
        "products": [
          {
            "vendor": "Linux-Gaming",
            "product": "PortProtonQt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:meissner@suse.de",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01893
      },
      "nvd": {
        "published": "2026-07-23T08:16:25.003",
        "lastModified": "2026-07-23T15:26:39.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59678",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PortProton's polkit action authorizes an unprivileged caller for a privileged operation without binding the request to the required administrative identity.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-59678",
          "host": "bugzilla.suse.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59686",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T13:14:43.248Z",
      "date_published": "2026-07-27T12:22:05.699Z",
      "date_updated": "2026-07-28T03:55:37.387Z",
      "publisher": "ProgressSoftware",
      "title": "Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "LoadMaster"
          },
          {
            "vendor": "Progress Software",
            "product": "ECS Connection Manager"
          },
          {
            "vendor": "Progress Software",
            "product": "Object Scale Connection Manager"
          },
          {
            "vendor": "Progress Software",
            "product": "MOVEit WAF"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00734,
        "percentile": 0.50874
      },
      "nvd": {
        "published": "2026-07-27T13:18:21.947",
        "lastModified": "2026-07-28T16:22:01.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59686",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application places attacker-controlled data into an operating-system command without separating the data from command syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690",
          "host": "community.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 352,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-59687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T13:14:43.248Z",
      "date_published": "2026-07-27T12:23:15.683Z",
      "date_updated": "2026-07-28T03:55:35.706Z",
      "publisher": "ProgressSoftware",
      "title": "Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "LoadMaster"
          },
          {
            "vendor": "Progress Software",
            "product": "ECS Connection Manager"
          },
          {
            "vendor": "Progress Software",
            "product": "Object Scale Connection Manager"
          },
          {
            "vendor": "Progress Software",
            "product": "MOVEit WAF"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00717,
        "percentile": 0.50242
      },
      "nvd": {
        "published": "2026-07-27T13:18:22.080",
        "lastModified": "2026-07-28T16:22:01.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59687",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value reaches operating-system command construction in LoadMaster without separating it from command or argument syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690",
          "host": "community.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 365,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-59688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T13:14:43.248Z",
      "date_published": "2026-07-27T12:24:23.139Z",
      "date_updated": "2026-07-28T03:55:34.913Z",
      "publisher": "ProgressSoftware",
      "title": "Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "LoadMaster"
          },
          {
            "vendor": "Progress Software",
            "product": "ECS Connection Manager"
          },
          {
            "vendor": "Progress Software",
            "product": "Object Scale Connection Manager"
          },
          {
            "vendor": "Progress Software",
            "product": "MOVEit WAF"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00717,
        "percentile": 0.50242
      },
      "nvd": {
        "published": "2026-07-27T13:18:22.203",
        "lastModified": "2026-07-28T16:22:01.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59688",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Backup restore data reaches an operating-system command without separating attacker-controlled values from shell syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690",
          "host": "community.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 360,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-59689",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T13:14:43.248Z",
      "date_published": "2026-07-27T12:25:22.245Z",
      "date_updated": "2026-07-28T03:55:34.119Z",
      "publisher": "ProgressSoftware",
      "title": "Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "LoadMaster"
          },
          {
            "vendor": "Progress Software",
            "product": "ECS Connection Manager"
          },
          {
            "vendor": "Progress Software",
            "product": "Object Scale Connection Manager"
          },
          {
            "vendor": "Progress Software",
            "product": "MOVEit WAF"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06595
      },
      "nvd": {
        "published": "2026-07-27T13:18:22.327",
        "lastModified": "2026-07-28T16:22:01.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59689",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "LoadMaster and related appliances allow a low-privileged authenticated role to reach root authority, but the protected action and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690",
          "host": "community.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-59690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T13:14:43.248Z",
      "date_published": "2026-07-27T12:26:27.980Z",
      "date_updated": "2026-07-28T03:55:33.063Z",
      "publisher": "ProgressSoftware",
      "title": "Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API",
      "affected": {
        "vendors": [
          "Progress Software"
        ],
        "products": [
          {
            "vendor": "Progress Software",
            "product": "LoadMaster"
          },
          {
            "vendor": "Progress Software",
            "product": "ECS Connection Manager"
          },
          {
            "vendor": "Progress Software",
            "product": "Object Scale Connection Manager"
          },
          {
            "vendor": "Progress Software",
            "product": "MOVEit WAF"
          },
          {
            "vendor": "Progress Software",
            "product": "Multi Tenant"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security@progress.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.0723
      },
      "nvd": {
        "published": "2026-07-27T13:18:22.457",
        "lastModified": "2026-07-28T16:22:01.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59690",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged REST API user can invoke administrative operations outside that role's permission set, but the affected routes and checks are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690",
          "host": "community.progress.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-59691",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T13:40:46.923Z",
      "date_published": "2026-07-09T09:34:47.743Z",
      "date_updated": "2026-08-03T09:33:06.930Z",
      "publisher": "redhat",
      "title": "Gstreamer: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16bpp framebuffer",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.1746
      },
      "nvd": {
        "published": "2026-07-09T11:16:41.657",
        "lastModified": "2026-08-03T10:16:31.780",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59691",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Red Hat Enterprise Linux 10 path can write beyond the end of its allocated buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47179",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47180",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47731",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59691",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497343",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/100",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5173",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 441,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-59692",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T13:40:46.923Z",
      "date_published": "2026-07-09T09:35:31.557Z",
      "date_updated": "2026-08-03T09:33:08.428Z",
      "publisher": "redhat",
      "title": "Gstreamer: gstreamer: dtls certificate subject dn stack buffer overflow in openssl_verify_callback",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28146
      },
      "nvd": {
        "published": "2026-07-09T11:16:41.783",
        "lastModified": "2026-08-03T10:16:31.953",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59692",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The DTLS plugin prints an oversized certificate subject into a fixed 2048-byte stack buffer without a size check.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47179",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47180",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:47731",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59692",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497344",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/99",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5172",
          "host": "gitlab.freedesktop.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-59694",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T14:05:47.003Z",
      "date_published": "2026-07-17T10:11:49.192Z",
      "date_updated": "2026-07-18T04:12:36.335Z",
      "publisher": "EEF",
      "title": "Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment",
      "affected": {
        "vendors": [
          "ZenHive"
        ],
        "products": [
          {
            "vendor": "ZenHive",
            "product": "mpp"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22419
      },
      "nvd": {
        "published": "2026-07-17T11:17:13.960",
        "lastModified": "2026-07-17T18:09:55.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59694",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The fee payer co-signs an attacker-sized EIP-2930 access list without a length bound, paying intrinsic gas for every fabricated entry.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ZenHive/mpp/security/advisories/GHSA-qpxh-ff8m-c62v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-59694.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-59694",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/ZenHive/mpp/commit/5d6338e2334084c5f2a78cfcca474830733ed7e8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1411,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T14:05:47.003Z",
      "date_published": "2026-07-17T10:11:43.674Z",
      "date_updated": "2026-07-18T04:12:26.916Z",
      "publisher": "EEF",
      "title": "Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain",
      "affected": {
        "vendors": [
          "ZenHive"
        ],
        "products": [
          {
            "vendor": "ZenHive",
            "product": "mpp"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22418
      },
      "nvd": {
        "published": "2026-07-17T11:17:14.117",
        "lastModified": "2026-07-17T18:09:55.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59695",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mpp accepts an attacker-controlled size, count, recursion depth, or work request without the quota or upper bound needed to keep resource use finite.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ZenHive/mpp/security/advisories/GHSA-vv77-66rf-pm86",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-59695.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-59695",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/ZenHive/mpp/commit/5d6338e2334084c5f2a78cfcca474830733ed7e8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1019,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59702",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:31:46.187Z",
      "date_published": "2026-07-08T15:07:19.285Z",
      "date_updated": "2026-07-20T17:45:57.219Z",
      "publisher": "VulnCheck",
      "title": "repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST /api/pack",
      "affected": {
        "vendors": [
          "repomix"
        ],
        "products": [
          {
            "vendor": "repomix",
            "product": "repomix"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24864
      },
      "nvd": {
        "published": "2026-07-08T16:16:31.577",
        "lastModified": "2026-07-10T18:22:49.657",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59702",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The pack endpoint passes unvalidated HTTP, HTTPS, and file repository URLs to git clone, allowing requests to internal, metadata, or local-file targets.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yamadashy/repomix/issues/1703",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/yamadashy/repomix",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/CrazyForks/repomix/commit/c748b524f41225e7fc6f89ad0084520901a453cf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/repomix-server-side-request-forgery-via-unvalidated-repository-urls-in-post-api-pack",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 382,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59703",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:31:46.187Z",
      "date_published": "2026-07-08T14:55:33.342Z",
      "date_updated": "2026-07-20T17:45:57.900Z",
      "publisher": "VulnCheck",
      "title": "repomix - Local File Inclusion via file:// URL Scheme in Git Clone Endpoint",
      "affected": {
        "vendors": [
          "repomix"
        ],
        "products": [
          {
            "vendor": "repomix",
            "product": "repomix"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-552",
          "name": "Files or Directories Accessible to External Parties",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00386,
        "percentile": 0.3136
      },
      "nvd": {
        "published": "2026-07-08T15:16:32.173",
        "lastModified": "2026-07-10T18:22:49.657",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59703",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "repomix exposes a filesystem location through an external interface without restricting it to the intended directory or callers.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-552"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yamadashy/repomix/issues/1704",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/yamadashy/repomix",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/CrazyForks/repomix/commit/c748b524f41225e7fc6f89ad0084520901a453cf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/repomix-local-file-inclusion-via-file-url-scheme-in-git-clone-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 450,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59704",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:31:46.187Z",
      "date_published": "2026-07-07T22:18:48.724Z",
      "date_updated": "2026-07-20T17:45:58.593Z",
      "publisher": "VulnCheck",
      "title": "Cap - Missing Access Control in Video AI Metadata Endpoint",
      "affected": {
        "vendors": [
          "Cap"
        ],
        "products": [
          {
            "vendor": "Cap",
            "product": "Cap"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12137
      },
      "nvd": {
        "published": "2026-07-07T23:16:55.850",
        "lastModified": "2026-07-10T18:22:49.657",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59704",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Cap video endpoint returns an arbitrary video selected by ID without checking that the caller owns it or belongs to its workspace.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CapSoftware/Cap/issues/1981",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/CapSoftware/Cap",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/CapSoftware/Cap/commit/8d48642b6e7938af238386383ef1c273be4110dd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cap-missing-access-control-in-video-ai-metadata-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/CapSoftware/Cap/pull/1926",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59705",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:31:46.187Z",
      "date_published": "2026-07-07T22:11:25.795Z",
      "date_updated": "2026-07-20T17:45:59.306Z",
      "publisher": "VulnCheck",
      "title": "mem0 - OpenMemory API Unauthenticated Access via Memory Endpoints",
      "affected": {
        "vendors": [
          "mem0"
        ],
        "products": [
          {
            "vendor": "mem0",
            "product": "mem0"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00498,
        "percentile": 0.39937
      },
      "nvd": {
        "published": "2026-07-07T23:16:55.997",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59705",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenMemory registers memory read, write, delete, and pause routes without authentication middleware.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mem0ai/mem0/issues/6080",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mem0ai/mem0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/mem0ai/mem0/commit/a3154d59e52386d4e1189c1f5f44819868f76514",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/mem0-openmemory-api-unauthenticated-access-via-memory-endpoints",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 464,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59706",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:31:46.187Z",
      "date_published": "2026-07-07T21:02:22.766Z",
      "date_updated": "2026-07-20T17:45:59.970Z",
      "publisher": "VulnCheck",
      "title": "mem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_url",
      "affected": {
        "vendors": [
          "mem0"
        ],
        "products": [
          {
            "vendor": "mem0",
            "product": "mem0"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17514
      },
      "nvd": {
        "published": "2026-07-07T22:16:54.503",
        "lastModified": "2026-07-08T15:28:15.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59706",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mem0 exposes configuration endpoints without authentication, allowing anyone to read API keys or change the server-side Ollama destination.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mem0ai/mem0/issues/6081",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mem0ai/mem0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/mem0ai/mem0/commit/a3154d59e52386d4e1189c1f5f44819868f76514",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/mem0-server-side-request-forgery-and-plaintext-api-key-exposure-via-unauthenticated-config-endpoints",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 407,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59707",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:31:46.187Z",
      "date_published": "2026-07-07T20:37:53.194Z",
      "date_updated": "2026-07-20T17:46:00.654Z",
      "publisher": "VulnCheck",
      "title": "LocalAI - Server-Side Request Forgery via POST /models/apply",
      "affected": {
        "vendors": [
          "LocalAI"
        ],
        "products": [
          {
            "vendor": "LocalAI",
            "product": "LocalAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28743
      },
      "nvd": {
        "published": "2026-07-07T21:17:29.340",
        "lastModified": "2026-07-10T18:22:49.657",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59707",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The endpoint passes unsanitized gallery URL fields directly to gallery.GetGalleryConfigFromURLWithContext without proper validation, enabling attackers to force the server to issue HTTP GET requests to private and loopback ranges with partial response content leaked through error messages.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mudler/LocalAI/issues/10665",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/mudler/LocalAI",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/mudler/LocalAI/commit/f9b968e19d7cbc556d59dceb2e0e450b828a3fda",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/localai-server-side-request-forgery-via-post-models-apply",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 459,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59708",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:31:46.188Z",
      "date_published": "2026-07-07T18:38:50.482Z",
      "date_updated": "2026-07-20T17:46:01.364Z",
      "publisher": "VulnCheck",
      "title": "Ghostfolio - Unauthorized Portfolio Data Exposure via Public Endpoint",
      "affected": {
        "vendors": [
          "ghostfolio"
        ],
        "products": [
          {
            "vendor": "ghostfolio",
            "product": "ghostfolio"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26945
      },
      "nvd": {
        "published": "2026-07-07T19:16:55.130",
        "lastModified": "2026-07-10T18:48:55.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59708",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ghostfolio/ghostfolio/issues/7197",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/ghostfolio/ghostfolio",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/ghostfolio/ghostfolio/commit/697ef59e3b58bebc5c21a9e482e4f5643390f316",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ghostfolio-unauthorized-portfolio-data-exposure-via-public-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 364,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59709",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:31:46.188Z",
      "date_published": "2026-07-07T14:12:23.972Z",
      "date_updated": "2026-07-20T17:46:02.037Z",
      "publisher": "VulnCheck",
      "title": "Ghostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Permission Check",
      "affected": {
        "vendors": [
          "Ghostfolio"
        ],
        "products": [
          {
            "vendor": "Ghostfolio",
            "product": "Ghostfolio"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.002,
        "percentile": 0.10035
      },
      "nvd": {
        "published": "2026-07-07T15:16:49.430",
        "lastModified": "2026-07-10T18:48:55.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59709",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The holding-tag endpoint honors an impersonation header but does not enforce the grantee's read-only permission.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ghostfolio/ghostfolio/issues/7196",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/ghostfolio/ghostfolio",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/ghostfolio/ghostfolio/commit/697ef59e3b58bebc5c21a9e482e4f5643390f316",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ghostfolio-unauthorized-portfolio-holding-tag-modification-via-missing-permission-check",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 370,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59710",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:31:46.188Z",
      "date_published": "2026-07-06T21:15:45.900Z",
      "date_updated": "2026-07-07T13:47:54.393Z",
      "publisher": "VulnCheck",
      "title": "showdown - Stored XSS via Unescaped Table Header ID Attribute Injection",
      "affected": {
        "vendors": [
          "showdown"
        ],
        "products": [
          {
            "vendor": "showdown",
            "product": "showdown"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00198,
        "percentile": 0.0978
      },
      "nvd": {
        "published": "2026-07-06T22:16:50.977",
        "lastModified": "2026-07-07T13:57:49.473",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59710",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Markdown table-header renderer fails to escape quotes in an HTML id attribute, allowing markup and SVG script elements to break into the output.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/showdownjs/showdown/issues/1046",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/showdownjs/showdown",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/showdownjs/showdown/commit/e5cab1e9a5dcea2bb3cbf888863fa7e65ab37edf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/showdown-stored-xss-via-unescaped-table-header-id-attribute-injection",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 417,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59711",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:31:46.188Z",
      "date_published": "2026-07-06T21:00:38.491Z",
      "date_updated": "2026-07-07T14:06:55.895Z",
      "publisher": "VulnCheck",
      "title": "showdown - Cross-Site Scripting via Unescaped Metadata Title in completeHTMLDocument",
      "affected": {
        "vendors": [
          "showdown"
        ],
        "products": [
          {
            "vendor": "showdown",
            "product": "showdown"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08583
      },
      "nvd": {
        "published": "2026-07-06T21:16:58.660",
        "lastModified": "2026-07-07T15:16:49.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59711",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/showdownjs/showdown/issues/1047",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/showdownjs/showdown",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/showdown-cross-site-scripting-via-unescaped-metadata-title-in-completehtmldocument",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59712",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:31:46.188Z",
      "date_published": "2026-07-06T20:43:50.296Z",
      "date_updated": "2026-07-28T17:46:44.060Z",
      "publisher": "VulnCheck",
      "title": "Leantime - JSON-RPC API Broken Access Control via users.getUser",
      "affected": {
        "vendors": [
          "Leantime"
        ],
        "products": [
          {
            "vendor": "Leantime",
            "product": "Leantime"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16455
      },
      "nvd": {
        "published": "2026-07-06T21:16:58.793",
        "lastModified": "2026-07-07T14:16:34.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59712",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Leantime resolves a caller-controlled object identifier without binding the selected object to the caller's authorized scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Leantime/leantime/issues/3556",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/Leantime/leantime",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/Leantime/leantime/commit/4f2612d13e0e8a2093092a846b44506cf133b671",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/leantime-credential-disclosure-via-unauthenticated-json-rpc-users-getuser-method",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:31:46.188Z",
      "date_published": "2026-07-06T20:36:24.795Z",
      "date_updated": "2026-07-20T17:46:03.417Z",
      "publisher": "VulnCheck",
      "title": "Leantime - OIDC Login CSRF via Unconditional State Verification Stub",
      "affected": {
        "vendors": [
          "Leantime"
        ],
        "products": [
          {
            "vendor": "Leantime",
            "product": "Leantime"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00153,
        "percentile": 0.05024
      },
      "nvd": {
        "published": "2026-07-06T21:16:58.930",
        "lastModified": "2026-07-07T15:16:49.700",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59713",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OIDC callback's verifyState method always returns true, allowing an attacker-controlled authorization response to be bound to a victim's browser session.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Leantime/leantime/issues/3535",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/Leantime/leantime",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/Leantime/leantime/commit/9630eb7db682fb1b4e23cdabf3428d03ec6f5094",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/leantime-oidc-login-csrf-via-unconditional-state-verification-stub",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59715",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.916Z",
      "date_published": "2026-07-09T16:16:02.977Z",
      "date_updated": "2026-07-09T17:29:46.103Z",
      "publisher": "GitHub_M",
      "title": "Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)",
      "affected": {
        "vendors": [
          "open-webui"
        ],
        "products": [
          {
            "vendor": "open-webui",
            "product": "open-webui"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 3.4,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12919
      },
      "nvd": {
        "published": "2026-07-09T17:17:04.353",
        "lastModified": "2026-07-10T02:41:47.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59715",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebSocket document handlers process protected operations without authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-gmfw-g93r-vg53",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/pull/25946",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/commit/22f2fe1ffb66c993dad1e0b2b35514acaed2370e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.10.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 429,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59720",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.916Z",
      "date_published": "2026-07-09T17:27:34.067Z",
      "date_updated": "2026-07-09T18:28:44.107Z",
      "publisher": "GitHub_M",
      "title": "Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server",
      "affected": {
        "vendors": [
          "hoppscotch"
        ],
        "products": [
          {
            "vendor": "hoppscotch",
            "product": "hoppscotch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00336,
        "percentile": 0.26189
      },
      "nvd": {
        "published": "2026-07-09T18:16:57.063",
        "lastModified": "2026-07-10T19:15:15.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59720",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Mock-server creation omits the isPublic field and therefore inherits a schema default of public even for a private collection.",
        "basis": [
          "CNA record",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-c68f-wr5p-j6jf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hoppscotch/hoppscotch/pull/6410",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hoppscotch/hoppscotch/commit/e4332110d455a3012d5c77a9186bc4aa096e34f2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hoppscotch/hoppscotch/releases/tag/2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 394,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59721",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.916Z",
      "date_published": "2026-07-09T17:24:46.098Z",
      "date_updated": "2026-07-09T19:13:03.635Z",
      "publisher": "GitHub_M",
      "title": "Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection",
      "affected": {
        "vendors": [
          "hoppscotch"
        ],
        "products": [
          {
            "vendor": "hoppscotch",
            "product": "hoppscotch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00518,
        "percentile": 0.412
      },
      "nvd": {
        "published": "2026-07-09T18:16:57.200",
        "lastModified": "2026-07-10T19:15:15.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59721",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "hoppscotch places attacker-controlled data into an operating-system command without separating it from command syntax.",
        "basis": [
          "CNA",
          "CWE-77",
          "CWE-78",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-v7q6-r45w-2c6r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/hoppscotch/hoppscotch/pull/6413",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hoppscotch/hoppscotch/commit/73a88c82b1b2cada26cc4b2bc095b54554242239",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/hoppscotch/hoppscotch/releases/tag/2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.916Z",
      "date_published": "2026-07-08T22:25:01.453Z",
      "date_updated": "2026-07-10T03:55:42.182Z",
      "publisher": "GitHub_M",
      "title": "Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)",
      "affected": {
        "vendors": [
          "cline"
        ],
        "products": [
          {
            "vendor": "cline",
            "product": "cline"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04226
      },
      "nvd": {
        "published": "2026-07-08T23:16:56.440",
        "lastModified": "2026-07-10T19:17:58.040",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59723",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The local dashboard accepts WebSocket browser connections without validating Origin and then honors desktopCommand frames.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cline/cline/security/advisories/GHSA-3cj3-hqcr-g934",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cline/cline/pull/11724",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cline/cline/commit/d09270940f5746f288cfc4a5039b46a2f4d5d01e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cline/cline/releases/tag/cli-v3.0.30",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59724",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.916Z",
      "date_published": "2026-07-08T15:35:39.813Z",
      "date_updated": "2026-07-08T19:41:18.905Z",
      "publisher": "GitHub_M",
      "title": "Socket.IO: Engine.IO WebTransport SID DoS",
      "affected": {
        "vendors": [
          "socketio"
        ],
        "products": [
          {
            "vendor": "socketio",
            "product": "socket.io"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26486
      },
      "nvd": {
        "published": "2026-07-08T16:16:32.980",
        "lastModified": "2026-07-13T15:08:37.150",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59724",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Engine.IO resolves a crafted WebTransport session ID such as __proto__ through an inherited object property and then crashes on the unexpected value.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/socketio/socket.io/security/advisories/GHSA-gr94-w7qr-f4j3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/socketio/socket.io/commit/1fa1f46cd420ac5b57bb4c04c959b58f3c79158c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/socketio/socket.io/releases/tag/engine.io@6.6.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 372,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59725",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.916Z",
      "date_published": "2026-07-08T15:37:52.293Z",
      "date_updated": "2026-07-08T17:00:32.946Z",
      "publisher": "GitHub_M",
      "title": "Socket.IO: Engine.IO Polling Transport Connection Exhaustion",
      "affected": {
        "vendors": [
          "socketio"
        ],
        "products": [
          {
            "vendor": "socketio",
            "product": "socket.io"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28132
      },
      "nvd": {
        "published": "2026-07-08T16:16:33.133",
        "lastModified": "2026-07-13T15:07:44.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59725",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Engine.IO leaves the HTTP response open for invalid binary POST requests in protocol-v4 polling transport, allowing unauthenticated clients to exhaust connections and sockets.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/socketio/socket.io/security/advisories/GHSA-r635-g3xr-vw7x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/socketio/socket.io/commit/fc11285e14964c2132d122164bf130c355f60671",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/socketio/socket.io/releases/tag/engine.io@6.6.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59726",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.917Z",
      "date_published": "2026-07-09T17:31:20.627Z",
      "date_updated": "2026-07-09T18:43:24.749Z",
      "publisher": "GitHub_M",
      "title": "Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment",
      "affected": {
        "vendors": [
          "ruvnet"
        ],
        "products": [
          {
            "vendor": "ruvnet",
            "product": "ruflo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-942",
          "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00478,
        "percentile": 0.38794
      },
      "nvd": {
        "published": "2026-07-09T18:16:57.337",
        "lastModified": "2026-07-10T19:15:15.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59726",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The default MCP bridge exposes terminal_execute through unauthenticated network endpoints, allowing any remote caller to invoke a critical command tool.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-78",
          "CWE-306",
          "CWE-942"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ruvnet/ruflo/security/advisories/GHSA-c4hm-4h84-2cf3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ruvnet/ruflo/pull/2521",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ruvnet/ruflo/commit/d00a0a40cd8bdbca877ac7f675f416bdc69accd1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/ruvnet/ruflo/releases/tag/v3.16.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 438,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59727",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.917Z",
      "date_published": "2026-07-27T19:42:32.222Z",
      "date_updated": "2026-07-28T15:20:18.915Z",
      "publisher": "GitHub_M",
      "title": "Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands",
      "affected": {
        "vendors": [
          "withastro"
        ],
        "products": [
          {
            "vendor": "withastro",
            "product": "astro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-83",
          "name": "Improper Neutralization of Script in Attributes in a Web Page",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23325
      },
      "nvd": {
        "published": "2026-07-27T20:16:40.153",
        "lastModified": "2026-07-28T16:19:23.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59727",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The astro rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-83",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/withastro/astro/security/advisories/GHSA-7pw4-f3q4-r2p2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/pull/17212",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/commit/7ba0bb1dc7516e88caff9abd7767322af44b0294",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/releases/tag/astro@7.0.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 872,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59728",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.917Z",
      "date_published": "2026-07-27T19:54:23.009Z",
      "date_updated": "2026-07-28T14:27:56.334Z",
      "publisher": "GitHub_M",
      "title": "@astrojs/rss: XML Injection via Unescaped RSS Feed Fields",
      "affected": {
        "vendors": [
          "withastro"
        ],
        "products": [
          {
            "vendor": "withastro",
            "product": "astro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-91",
          "name": "XML Injection (aka Blind XPath Injection)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18898
      },
      "nvd": {
        "published": "2026-07-27T21:17:05.700",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59728",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "XML field values are interpolated directly into XML syntax without escaping delimiter characters.",
        "basis": [
          "CNA",
          "CWE-91"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/withastro/astro/security/advisories/GHSA-8j5q-mfj2-5q9q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/pull/17209",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/commit/fbcfa039dfe3d700b239f595a6c55ee35e45bd06",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/releases/tag/@astrojs/rss@4.0.19",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1002,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.917Z",
      "date_published": "2026-07-27T19:38:40.372Z",
      "date_updated": "2026-07-28T13:48:46.640Z",
      "publisher": "GitHub_M",
      "title": "Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)",
      "affected": {
        "vendors": [
          "withastro"
        ],
        "products": [
          {
            "vendor": "withastro",
            "product": "astro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25254
      },
      "nvd": {
        "published": "2026-07-27T20:16:40.303",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59729",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The astro rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/withastro/astro/security/advisories/GHSA-f48w-9m4c-m7f5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/pull/17251",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/commit/5240e26c9dd91f9bc7140dcfacdb48d5a132830d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/releases/tag/astro@7.0.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 788,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.917Z",
      "date_published": "2026-07-27T20:00:28.662Z",
      "date_updated": "2026-07-28T13:49:13.730Z",
      "publisher": "GitHub_M",
      "title": "@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect",
      "affected": {
        "vendors": [
          "withastro"
        ],
        "products": [
          {
            "vendor": "withastro",
            "product": "astro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00364,
        "percentile": 0.29085
      },
      "nvd": {
        "published": "2026-07-27T21:17:05.843",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59730",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Astro echoes a slash-backslash request path into Location, and browsers reinterpret the backslash so the redirect resolves to an external host.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/withastro/astro/security/advisories/GHSA-r557-wffq-wvrc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/pull/17252",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/commit/eb6f97e391ee587747e37609c255c7cd4b9cce3c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/releases/tag/@astrojs/node@11.0.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 809,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.917Z",
      "date_published": "2026-07-08T16:27:18.496Z",
      "date_updated": "2026-07-09T14:38:54.995Z",
      "publisher": "GitHub_M",
      "title": "Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch",
      "affected": {
        "vendors": [
          "withastro"
        ],
        "products": [
          {
            "vendor": "withastro",
            "product": "astro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-647",
          "name": "Use of Non-Canonical URL Paths for Authorization Decisions",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.1872
      },
      "nvd": {
        "published": "2026-07-08T17:17:25.937",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59731",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Astro authorizes one URL representation before partial decoding changes the routed path, allowing the decoded request to reach a resource that the authorization check did not evaluate.",
        "basis": [
          "CNA",
          "CWE-647"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/withastro/astro/security/advisories/GHSA-vj59-8hwv-xxmv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/pull/17109",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/commit/27c80ea92248993e5fce94b2c26d87d611ab6785",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/withastro/astro/releases/tag/astro@6.4.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 348,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59732",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.917Z",
      "date_published": "2026-07-14T21:36:21.030Z",
      "date_updated": "2026-07-21T14:43:46.387Z",
      "publisher": "GitHub_M",
      "title": "rclone archive extract allows S3 destination prefix escape via crafted archive paths",
      "affected": {
        "vendors": [
          "rclone"
        ],
        "products": [
          {
            "vendor": "rclone",
            "product": "rclone"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11661
      },
      "nvd": {
        "published": "2026-07-14T22:17:29.920",
        "lastModified": "2026-07-21T16:17:18.697",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59732",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path components such as ../, allowing creation or overwrite of sibling objects in the same bucket or path scope.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rclone/rclone/security/advisories/GHSA-4vr5-p2gc-h23p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rclone/rclone/commit/1a746732441e8158f32fab35924b23701e719a8c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rclone/rclone/commit/d11efe0d58fe6a2d6d90675bb9d8ee5840c51e1d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rclone/rclone/releases/tag/v1.74.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59733",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.917Z",
      "date_published": "2026-07-14T21:38:37.116Z",
      "date_updated": "2026-07-29T19:26:44.815Z",
      "publisher": "GitHub_M",
      "title": "rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories",
      "affected": {
        "vendors": [
          "rclone"
        ],
        "products": [
          {
            "vendor": "rclone",
            "product": "rclone"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00422,
        "percentile": 0.34768
      },
      "nvd": {
        "published": "2026-07-14T22:17:30.050",
        "lastModified": "2026-07-29T20:17:04.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59733",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "rclone authorizes a normalized routed user path but builds the backend key from the raw path, allowing dot-dot components to select another private repository.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rclone/rclone/security/advisories/GHSA-fqj9-69pf-6pjg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rclone/rclone/commit/015fd0eba1cb138eef081517795fed47a2873f2d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rclone/rclone/commit/dade21c1616035b044df0eef7ee6a85aeb06a139",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rclone/rclone/releases/tag/v1.74.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 514,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59734",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-06T15:34:16.917Z",
      "date_published": "2026-07-09T17:35:05.368Z",
      "date_updated": "2026-07-09T18:16:19.863Z",
      "publisher": "GitHub_M",
      "title": "Coolify: OS Command Injection in Health Check Configuration Allows Remote Code Execution",
      "affected": {
        "vendors": [
          "coollabsio"
        ],
        "products": [
          {
            "vendor": "coollabsio",
            "product": "coolify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00524,
        "percentile": 0.41518
      },
      "nvd": {
        "published": "2026-07-09T18:16:57.473",
        "lastModified": "2026-07-09T19:21:34.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59734",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Coolify concatenates an attacker-controlled health-check value into a shell command without safe argument separation.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coollabsio/coolify/security/advisories/GHSA-4fhp-xqqp-w7vv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/pull/9007",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/commit/0ffcee7a4dcd24f92b5fab8c9c7be140b9532733",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.469",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59762",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:49:43.031Z",
      "date_published": "2026-07-15T14:33:44.468Z",
      "date_updated": "2026-07-15T15:35:16.895Z",
      "publisher": "f5",
      "title": "BIG-IP HTTP/2 vulnerability",
      "affected": {
        "vendors": [
          "F5"
        ],
        "products": [
          {
            "vendor": "F5",
            "product": "BIG-IP"
          },
          {
            "vendor": "F5",
            "product": "BIG-IP Next for Kubernetes"
          },
          {
            "vendor": "F5",
            "product": "BIG-IP Next SPK"
          },
          {
            "vendor": "F5",
            "product": "BIG-IP Next CNF"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.0046,
        "percentile": 0.37564
      },
      "nvd": {
        "published": "2026-07-15T15:16:46.200",
        "lastModified": "2026-07-15T16:23:03.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59762",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Undisclosed HTTP/2 requests cause TMM memory use to grow until restart, while F5 does not publish the allocated object or missing per-connection bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://my.f5.com/manage/s/article/K000162231",
          "host": "my.f5.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-59764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T01:43:55.938Z",
      "date_published": "2026-07-28T08:40:33.557Z",
      "date_updated": "2026-07-28T16:08:58.531Z",
      "publisher": "jpcert",
      "title": "ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI.",
      "affected": {
        "vendors": [
          "ELECOM CO.,LTD."
        ],
        "products": [
          {
            "vendor": "ELECOM CO.,LTD.",
            "product": "WRC-X3000GS3-B"
          },
          {
            "vendor": "ELECOM CO.,LTD.",
            "product": "WRC-X3000GS3A-B"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.01129,
        "percentile": 0.63204
      },
      "nvd": {
        "published": "2026-07-28T09:16:42.417",
        "lastModified": "2026-07-28T16:19:23.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59764",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value reaches operating-system command construction in WRC-X3000GS3-B without separating it from command or argument syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.elecom.co.jp/news/security/20260728-01/",
          "host": "www.elecom.co.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jvn.jp/en/jp/JVN56870912/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 231,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59776",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T08:23:34.922Z",
      "date_published": "2026-07-21T03:06:56.344Z",
      "date_updated": "2026-07-21T13:26:02.801Z",
      "publisher": "jpcert",
      "title": "Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017.",
      "affected": {
        "vendors": [
          "Sony Corporation"
        ],
        "products": [
          {
            "vendor": "Sony Corporation",
            "product": "FeliCa IC chips"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-325",
          "name": "Missing Cryptographic Step",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "3.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04046
      },
      "nvd": {
        "published": "2026-07-21T04:16:51.480",
        "lastModified": "2026-07-21T18:34:07.370",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59776",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected FeliCa chips omit a required cryptographic step before allowing stored data to be read or changed.",
        "basis": [
          "CNA",
          "CWE-325"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.sony.co.jp/en/Products/felica/business/information/2025001.html",
          "host": "www.sony.co.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jvn.jp/en/jp/JVN40509781/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59791",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:41:06.835Z",
      "date_published": "2026-07-10T14:18:56.699Z",
      "date_updated": "2026-07-10T17:00:21.132Z",
      "publisher": "JetBrains",
      "title": "In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "YouTrack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1021",
          "name": "Improper Restriction of Rendered UI Layers or Frames",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03373
      },
      "nvd": {
        "published": "2026-07-10T15:16:48.110",
        "lastModified": "2026-07-10T18:58:17.853",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59791",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "YouTrack accepts CSS-capable content from a Mermaid diagram and renders it in the application's trusted UI context.",
        "basis": [
          "CNA",
          "CWE-1021"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59792",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:41:07.385Z",
      "date_published": "2026-07-10T14:18:57.311Z",
      "date_updated": "2026-07-14T03:55:40.249Z",
      "publisher": "JetBrains",
      "title": "In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "IntelliJ IDEA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00461,
        "percentile": 0.37663
      },
      "nvd": {
        "published": "2026-07-10T15:16:48.240",
        "lastModified": "2026-07-14T05:16:19.107",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59792",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A project workspace identifier permits relative traversal that selects executable content outside the intended IntelliJ workspace location.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:41:07.789Z",
      "date_published": "2026-07-10T14:18:57.861Z",
      "date_updated": "2026-07-14T03:55:41.755Z",
      "publisher": "JetBrains",
      "title": "In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "TeamCity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30429
      },
      "nvd": {
        "published": "2026-07-10T15:16:48.350",
        "lastModified": "2026-07-14T05:16:19.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59793",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The TeamCity file operation accepts an attacker-controlled path that escapes the intended directory or storage target.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59794",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:41:08.333Z",
      "date_published": "2026-07-10T14:18:58.518Z",
      "date_updated": "2026-07-10T16:59:55.131Z",
      "publisher": "JetBrains",
      "title": "In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "TeamCity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 1.8999999999999995,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11034
      },
      "nvd": {
        "published": "2026-07-10T15:16:48.463",
        "lastModified": "2026-07-10T18:49:04.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59794",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TeamCity renders agent-reported data on the cloud profile page without sufficient escaping from browser script grammar.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 111,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59795",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:41:08.700Z",
      "date_published": "2026-07-10T14:18:59.039Z",
      "date_updated": "2026-07-10T16:59:47.774Z",
      "publisher": "JetBrains",
      "title": "In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "TeamCity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18167
      },
      "nvd": {
        "published": "2026-07-10T15:16:48.573",
        "lastModified": "2026-07-13T15:27:58.543",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59795",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In TeamCity, attacker-controlled markup is stored and later rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59796",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T09:41:09.010Z",
      "date_published": "2026-07-10T14:18:59.634Z",
      "date_updated": "2026-07-14T03:55:42.656Z",
      "publisher": "JetBrains",
      "title": "In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "TeamCity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19412
      },
      "nvd": {
        "published": "2026-07-10T15:16:48.683",
        "lastModified": "2026-07-14T05:16:19.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59796",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "TeamCity fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T14:39:14.062Z",
      "date_published": "2026-07-07T18:19:17.154Z",
      "date_updated": "2026-07-07T19:08:07.806Z",
      "publisher": "VulnCheck",
      "title": "9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.01338,
        "percentile": 0.68488
      },
      "nvd": {
        "published": "2026-07-07T19:16:55.260",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59800",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unauthenticated Tailscale endpoint writes sudoPassword to a sudo sh process where no prompt causes the value to be interpreted as shell commands.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-g6g7-pvmx-m74p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/9router-os-command-injection-via-sudopassword-parameter-in-tailscale-install-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 708,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T14:39:14.062Z",
      "date_published": "2026-07-13T21:30:07.257Z",
      "date_updated": "2026-07-14T13:00:25.203Z",
      "publisher": "VulnCheck",
      "title": "9Router 0.4.41 - Unauthenticated API Exposure via /api/providers",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9Router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.02244,
        "percentile": 0.81136
      },
      "nvd": {
        "published": "2026-07-13T22:16:48.840",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59801",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "9Router registers provider-management API routes without authentication middleware, allowing anonymous callers to read or replace provider configuration.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-vjc7-jrh9-9j86",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/9router-unauthenticated-api-exposure-via-api-providers",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 558,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T14:39:14.062Z",
      "date_published": "2026-07-08T19:42:07.906Z",
      "date_updated": "2026-07-14T22:03:28.588Z",
      "publisher": "VulnCheck",
      "title": "PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload",
      "affected": {
        "vendors": [
          "PasswordPusher"
        ],
        "products": [
          {
            "vendor": "PasswordPusher",
            "product": "PasswordPusher"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-183",
          "name": "Permissive List of Allowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 1.8999999999999995,
      "epss": {
        "score": 0.00192,
        "percentile": 0.0909
      },
      "nvd": {
        "published": "2026-07-08T20:16:55.737",
        "lastModified": "2026-07-14T23:17:34.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59802",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The URL validator accepts a data URI and lets the browser navigate to attacker-controlled executable content.",
        "basis": [
          "CNA",
          "CWE-183"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-76c2-66pg-fj2f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/passwordpusher-redirect-based-xss-via-data-uri-in-url-push-payload",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59803",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T14:39:14.062Z",
      "date_published": "2026-07-08T19:42:29.448Z",
      "date_updated": "2026-07-09T13:30:22.468Z",
      "publisher": "VulnCheck",
      "title": "rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol",
      "affected": {
        "vendors": [
          "smallnest"
        ],
        "products": [
          {
            "vendor": "smallnest",
            "product": "rpcx"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00408,
        "percentile": 0.3354
      },
      "nvd": {
        "published": "2026-07-08T20:16:55.913",
        "lastModified": "2026-07-10T18:46:32.250",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59803",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "rpcx checks only the compressed frame length and imposes no bound on the gzip-expanded payload before allocation.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/smallnest/rpcx/issues/942",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/smallnest/rpcx/pull/943",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/smallnest/rpcx/commit/047aec18efa7d037105e2b72c36dd2ae05e1acc6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rpcx-denial-of-service-via-gzip-decompression-bomb-in-wire-protocol",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 733,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T14:39:14.062Z",
      "date_published": "2026-07-08T19:42:52.336Z",
      "date_updated": "2026-07-09T14:02:48.724Z",
      "publisher": "VulnCheck",
      "title": "Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket",
      "affected": {
        "vendors": [
          "web-infra-dev"
        ],
        "products": [
          {
            "vendor": "web-infra-dev",
            "product": "midscene"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1385",
          "name": "Missing Origin Validation in WebSockets",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11712
      },
      "nvd": {
        "published": "2026-07-08T20:16:56.077",
        "lastModified": "2026-07-10T17:56:00.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59804",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Midscene Bridge Server accepts WebSocket control without authentication or a restrictive Origin policy, allowing a remote web origin to seize the local channel.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-1385"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/web-infra-dev/midscene/issues/2752",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/web-infra-dev/midscene/pull/2759",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/web-infra-dev/midscene/commit/86f4118d1d847041c63d79e347e08c87c3f1a882",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/midscene-bridge-server-session-hijack-via-unauthenticated-websocket",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 646,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59805",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T14:39:14.062Z",
      "date_published": "2026-07-08T19:43:10.711Z",
      "date_updated": "2026-07-09T14:41:10.816Z",
      "publisher": "VulnCheck",
      "title": "Gumroad < 2026.07.06.2 - Insecure Direct Object Reference in PurchasesController",
      "affected": {
        "vendors": [
          "antiwork"
        ],
        "products": [
          {
            "vendor": "antiwork",
            "product": "gumroad"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12664
      },
      "nvd": {
        "published": "2026-07-08T20:16:56.250",
        "lastModified": "2026-07-10T18:46:32.250",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59805",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by sending PUT requests to the revoke_access and undo_revoke_access actions without seller ownership validation.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/antiwork/gumroad/issues/5725",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/antiwork/gumroad/releases/tag/v2026.07.06.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/antiwork/gumroad/pull/5731",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/antiwork/gumroad/commit/e7fd0e610e73135ecf1aa07c197a36fa524832e1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gumroad-insecure-direct-object-reference-in-purchasescontroller",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T14:39:14.062Z",
      "date_published": "2026-07-08T19:43:32.730Z",
      "date_updated": "2026-07-09T18:18:16.061Z",
      "publisher": "VulnCheck",
      "title": "Gradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpoint",
      "affected": {
        "vendors": [
          "gradio-app"
        ],
        "products": [
          {
            "vendor": "gradio-app",
            "product": "gradio"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 2.5,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16021
      },
      "nvd": {
        "published": "2026-07-08T20:16:56.973",
        "lastModified": "2026-07-10T18:48:55.817",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59806",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the file_fetch() function in the /gradio_api/file= endpoint.",
        "basis": [
          "CNA",
          "CWE-601",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gradio-app/gradio/issues/13593",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/gradio-app/gradio/releases/tag/gradio%406.20.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/gradio-app/gradio/pull/13596",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/gradio-app/gradio/commit/1c5c53842df9c2750552d85c19a92e7e732cff3f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gradio-open-redirect-and-ssrf-via-gradio-api-file-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 464,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T14:39:14.062Z",
      "date_published": "2026-07-08T19:43:51.506Z",
      "date_updated": "2026-07-09T14:28:25.191Z",
      "publisher": "VulnCheck",
      "title": "Composio SDK < 0.2.32-beta.283 - Sensitive File Upload via tool-file-uploads.ts",
      "affected": {
        "vendors": [
          "ComposioHQ"
        ],
        "products": [
          {
            "vendor": "ComposioHQ",
            "product": "composio"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 2.1000000000000005,
      "epss": {
        "score": 0.00289,
        "percentile": 0.2115
      },
      "nvd": {
        "published": "2026-07-08T20:16:57.123",
        "lastModified": "2026-07-10T18:22:49.657",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59807",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path reads a prompt-selected local filename without the SDK's safe-upload-path assertion.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ComposioHQ/composio/issues/3746",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/ComposioHQ/composio/releases/tag/%40composio%2Fcli%400.2.32-beta.283",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/ComposioHQ/composio/pull/3763",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/ComposioHQ/composio/commit/fc17c37bf95b7ece5c038cb7e2ab7e3e4a064e3a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/composio-sdk-beta-283-sensitive-file-upload-via-tool-file-uploads-ts",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 471,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59817",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.978Z",
      "date_published": "2026-07-09T17:40:15.629Z",
      "date_updated": "2026-07-14T01:04:55.237Z",
      "publisher": "GitHub_M",
      "title": "Ghost: Paid gift memberships obtainable at minimal cost via the donations feature",
      "affected": {
        "vendors": [
          "TryGhost"
        ],
        "products": [
          {
            "vendor": "TryGhost",
            "product": "Ghost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-472",
          "name": "External Control of Assumed-Immutable Web Parameter",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17252
      },
      "nvd": {
        "published": "2026-07-09T18:16:57.603",
        "lastModified": "2026-07-14T02:16:57.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59817",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The donation checkout trusts caller-controlled metadata when assigning a paid gift membership, allowing a minimal payment to authorize the full membership.",
        "basis": [
          "CNA",
          "CWE-472",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/TryGhost/Ghost/security/advisories/GHSA-xm43-3m56-w3wf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/TryGhost/Ghost/pull/28351",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/TryGhost/Ghost/pull/28352",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/TryGhost/Ghost/commit/cab716cd015ac04b7ee50c7a405478d97bc7b1e0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/TryGhost/Ghost/commit/ee7b991b466a7849c70f9d1caed8e491ee4113c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 370,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59818",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.978Z",
      "date_published": "2026-07-08T21:00:18.207Z",
      "date_updated": "2026-07-09T13:13:10.463Z",
      "publisher": "GitHub_M",
      "title": "etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation",
      "affected": {
        "vendors": [
          "etcd-io"
        ],
        "products": [
          {
            "vendor": "etcd-io",
            "product": "etcd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24341
      },
      "nvd": {
        "published": "2026-07-08T21:16:54.503",
        "lastModified": "2026-07-13T14:50:12.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59818",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The split gRPC listener omits the configured certificate-revocation-list check and accepts a revoked client certificate.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/etcd-io/etcd/security/advisories/GHSA-3wh4-j44w-pg92",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/etcd-io/etcd/pull/22007",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/etcd-io/etcd/pull/22021",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/etcd-io/etcd/pull/22025",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/etcd-io/etcd/commit/2308ce1578064641d4d67c40f0487309267d1bef",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/etcd-io/etcd/commit/24838af5a53dd0245adced920e42a9bf0e7a267f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/etcd-io/etcd/commit/8221ae82bc25d4d55ca64382207b69be71038cbb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/etcd-io/etcd/releases/tag/v3.5.32",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/etcd-io/etcd/releases/tag/v3.6.13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59819",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.978Z",
      "date_published": "2026-07-08T19:33:32.816Z",
      "date_updated": "2026-07-09T14:30:14.779Z",
      "publisher": "GitHub_M",
      "title": "LiteLLM: Local file read via request-supplied OIDC file references",
      "affected": {
        "vendors": [
          "BerriAI"
        ],
        "products": [
          {
            "vendor": "BerriAI",
            "product": "litellm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 2.8000000000000003,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17417
      },
      "nvd": {
        "published": "2026-07-08T20:16:57.277",
        "lastModified": "2026-07-13T13:20:24.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59819",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "litellm lets a caller select a file or path outside the operation's intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/BerriAI/litellm/security/advisories/GHSA-4g5m-c9r5-49xf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/BerriAI/litellm/pull/25592",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/BerriAI/litellm/releases/tag/v1.83.10-stable",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 453,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59820",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.978Z",
      "date_published": "2026-07-08T19:32:11.739Z",
      "date_updated": "2026-07-09T14:37:09.457Z",
      "publisher": "GitHub_M",
      "title": "LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
      "affected": {
        "vendors": [
          "BerriAI"
        ],
        "products": [
          {
            "vendor": "BerriAI",
            "product": "litellm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23735
      },
      "nvd": {
        "published": "2026-07-08T20:16:57.413",
        "lastModified": "2026-07-13T13:23:26.020",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59820",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Skills archive extraction accepts traversal entries and writes them outside the staging or extraction directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/BerriAI/litellm/security/advisories/GHSA-5jmr-gcrj-2c9q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/BerriAI/litellm/pull/25475",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/BerriAI/litellm/commit/6a15adcd64137d37f73dee76dfe7481f8c2d9196",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 564,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.978Z",
      "date_published": "2026-07-08T19:14:13.265Z",
      "date_updated": "2026-07-09T14:38:09.991Z",
      "publisher": "GitHub_M",
      "title": "LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks",
      "affected": {
        "vendors": [
          "BerriAI"
        ],
        "products": [
          {
            "vendor": "BerriAI",
            "product": "litellm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 5.1,
      "epss": {
        "score": 0.00355,
        "percentile": 0.28231
      },
      "nvd": {
        "published": "2026-07-08T20:16:57.547",
        "lastModified": "2026-07-13T13:46:42.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59821",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The production custom-code path executes user code without the validation and sandboxing applied by the test path.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/BerriAI/litellm/security/advisories/GHSA-72m8-9m7m-h278",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/BerriAI/litellm/commit/e50b4486d0f7aa0497185a1ebcdd2c91f1769eba",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/BerriAI/litellm/releases/tag/v1.82.0-stable",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 496,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59822",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.978Z",
      "date_published": "2026-07-08T19:32:18.611Z",
      "date_updated": "2026-07-09T14:31:08.962Z",
      "publisher": "GitHub_M",
      "title": "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback",
      "affected": {
        "vendors": [
          "BerriAI"
        ],
        "products": [
          {
            "vendor": "BerriAI",
            "product": "litellm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16152
      },
      "nvd": {
        "published": "2026-07-08T20:16:57.683",
        "lastModified": "2026-07-13T13:32:04.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59822",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A fabricated Authorization header triggers an OAuth fallback that replaces failed key validation with an empty authenticated-principal object.",
        "basis": [
          "CNA record",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/BerriAI/litellm/pull/26463",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/BerriAI/litellm/commit/73869f0faf7d11ee21adcb5f91b8c33a340b6c2c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/BerriAI/litellm/releases/tag/v1.84.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59826",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.979Z",
      "date_published": "2026-07-09T17:46:36.365Z",
      "date_updated": "2026-07-10T03:55:49.067Z",
      "publisher": "GitHub_M",
      "title": "Metabase: Arbitrary Code Execution via Database Connection Detail Bypass",
      "affected": {
        "vendors": [
          "metabase"
        ],
        "products": [
          {
            "vendor": "metabase",
            "product": "metabase"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00391,
        "percentile": 0.31843
      },
      "nvd": {
        "published": "2026-07-09T18:16:57.757",
        "lastModified": "2026-07-30T14:32:02.257",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59826",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "metabase lets attacker-controlled text cross into an executable code or template grammar.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/metabase/metabase/security/advisories/GHSA-8wx2-rxp2-4x35",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/metabase/metabase/commit/74032e5e0a5a70dc45a6a744d37b9ba24eee8d01",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/metabase/metabase/releases/tag/v0.58.15.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/metabase/metabase/releases/tag/v0.59.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/metabase/metabase/releases/tag/v0.60.6.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/metabase/metabase/releases/tag/v0.61.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 446,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-59827",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.979Z",
      "date_published": "2026-07-09T17:43:57.546Z",
      "date_updated": "2026-07-09T18:24:48.433Z",
      "publisher": "GitHub_M",
      "title": "Metabase: Unsafe Deserialization of H2 Query Results",
      "affected": {
        "vendors": [
          "metabase"
        ],
        "products": [
          {
            "vendor": "metabase",
            "product": "metabase"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00622,
        "percentile": 0.46409
      },
      "nvd": {
        "published": "2026-07-09T18:16:57.893",
        "lastModified": "2026-07-13T14:31:08.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59827",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Metabase deserializes arbitrary Java objects returned from attacker-controlled H2 native-query columns of type OTHER.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/metabase/metabase/security/advisories/GHSA-w95f-x9v9-wv36",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/metabase/metabase/commit/00f42511fe3bc4385652a2e96862ee6fd7d42cf8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/metabase/metabase/releases/tag/v0.58.15",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/metabase/metabase/releases/tag/v0.59.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/metabase/metabase/releases/tag/v0.60.6.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/metabase/metabase/releases/tag/v0.61.1.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 505,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-59828",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.979Z",
      "date_published": "2026-07-09T22:04:50.777Z",
      "date_updated": "2026-07-10T14:17:45.659Z",
      "publisher": "GitHub_M",
      "title": "Discourse: Hidden post revisions leak through adjacent visible diffs",
      "affected": {
        "vendors": [
          "discourse"
        ],
        "products": [
          {
            "vendor": "discourse",
            "product": "discourse"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.2378
      },
      "nvd": {
        "published": "2026-07-09T22:17:09.973",
        "lastModified": "2026-07-13T15:22:59.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59828",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PostRevisionSerializer includes content from a hidden revision in the visible diff of an adjacent revision.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/discourse/discourse/security/advisories/GHSA-q456-4f8q-42vx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/1f26c1163ce87a2abbd1d01780ab1b5fb16e75f6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/8b773332b0f937dfcd894ed56d56fc5a81578d9d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/8d36da1b68c906592abde3f2e94d505cdf097435",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/commit/d58988d46bb1019bfa8b8330ae81a1a134e08511",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/discourse/discourse/releases/tag/v2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 9,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-59831",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.979Z",
      "date_published": "2026-07-09T22:11:05.418Z",
      "date_updated": "2026-07-14T01:20:59.985Z",
      "publisher": "GitHub_M",
      "title": "GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace",
      "affected": {
        "vendors": [
          "cli"
        ],
        "products": [
          {
            "vendor": "cli",
            "product": "cli"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17515
      },
      "nvd": {
        "published": "2026-07-09T23:17:05.483",
        "lastModified": "2026-07-14T02:16:57.493",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59831",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A URL supplied by an untrusted remote environment is passed to a privileged local URL handler without restricting its scheme and destination.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cli/cli/security/advisories/GHSA-8cg3-r6g9-fpg2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cli/cli/commit/b300f2ec7ec9dc9addc39b2ad88c54097ded7ca0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cli/cli/releases/tag/v2.96.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59832",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.979Z",
      "date_published": "2026-07-09T22:18:15.776Z",
      "date_updated": "2026-07-10T14:41:54.043Z",
      "publisher": "GitHub_M",
      "title": "SiYuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24036
      },
      "nvd": {
        "published": "2026-07-09T23:17:05.627",
        "lastModified": "2026-07-10T16:16:38.187",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59832",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "serveSnippets joins a single-decoded request path to the snippets directory without subpath containment, allowing traversal to workspace secrets.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-275h-v5h9-vr82",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/commit/68cc0f537dfa4502496dfa794e71835421c25c09",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.7.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 447,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59833",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.979Z",
      "date_published": "2026-07-09T22:17:05.933Z",
      "date_updated": "2026-07-10T14:17:16.135Z",
      "publisher": "GitHub_M",
      "title": "SiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG xlink:href)",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31566
      },
      "nvd": {
        "published": "2026-07-09T23:17:05.773",
        "lastModified": "2026-07-10T15:49:19.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59833",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The siyuan rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-94",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-97xv-3v84-h358",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/commit/ebe252e61fb93f258d083b9da0fa403679fdf94a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.7.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 484,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59834",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:00:50.979Z",
      "date_published": "2026-07-09T22:15:48.674Z",
      "date_updated": "2026-07-10T13:33:27.562Z",
      "publisher": "GitHub_M",
      "title": "SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0038,
        "percentile": 0.30776
      },
      "nvd": {
        "published": "2026-07-09T23:17:05.900",
        "lastModified": "2026-07-10T15:49:19.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59834",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input is interpreted as executable syntax without grammar-safe separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-h89q-4j2h-7h88",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/commit/57bcad4b331836880bfe6be25d4180bdcf10db0d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/commit/d0f0fe146fb07d594fcadc4f48d4f7c30ac01d1e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.7.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 430,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59835",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:21:25.057Z",
      "date_published": "2026-07-14T15:12:20.855Z",
      "date_updated": "2026-07-16T07:35:10.603Z",
      "publisher": "fortinet",
      "title": "A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.",
      "affected": {
        "vendors": [
          "Fortinet"
        ],
        "products": [
          {
            "vendor": "Fortinet",
            "product": "FortiSandbox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-668",
          "name": "Exposure of Resource to Wrong Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:psirt@fortinet.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.0046,
        "percentile": 0.37588
      },
      "nvd": {
        "published": "2026-07-14T16:17:02.593",
        "lastModified": "2026-07-15T15:00:41.437",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59835",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "FortiSandbox exposes the VNC servers of scanning virtual machines to unauthenticated network requests instead of restricting them to the scanning environment.",
        "basis": [
          "CNA",
          "CWE-668"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-145",
          "host": "fortiguard.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59836",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:21:26.614Z",
      "date_published": "2026-07-14T15:15:08.063Z",
      "date_updated": "2026-07-15T03:59:06.023Z",
      "publisher": "fortinet",
      "title": "A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.",
      "affected": {
        "vendors": [
          "Fortinet"
        ],
        "products": [
          {
            "vendor": "Fortinet",
            "product": "FortiClientEMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:psirt@fortinet.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 3.1000000000000005,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02658
      },
      "nvd": {
        "published": "2026-07-14T16:17:02.727",
        "lastModified": "2026-07-15T15:00:03.010",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59836",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FortiClientEMS accepts a peer certificate without completing the required certificate validation.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-147",
          "host": "fortiguard.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-59837",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:21:27.537Z",
      "date_published": "2026-07-14T15:06:31.443Z",
      "date_updated": "2026-07-15T03:59:04.454Z",
      "publisher": "fortinet",
      "title": "A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.",
      "affected": {
        "vendors": [
          "Fortinet"
        ],
        "products": [
          {
            "vendor": "Fortinet",
            "product": "FortiPAM"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiSASE"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiProxy"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:psirt@fortinet.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00578,
        "percentile": 0.44355
      },
      "nvd": {
        "published": "2026-07-14T16:17:02.853",
        "lastModified": "2026-07-15T14:50:00.397",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59837",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in FortiPAM, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-148",
          "host": "fortiguard.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-59838",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:21:29.438Z",
      "date_published": "2026-07-15T13:43:36.794Z",
      "date_updated": "2026-07-15T14:23:20.174Z",
      "publisher": "fortinet",
      "title": "A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.",
      "affected": {
        "vendors": [
          "Fortinet"
        ],
        "products": [
          {
            "vendor": "Fortinet",
            "product": "FortiSIEM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 11,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-80",
          "name": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:psirt@fortinet.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04019
      },
      "nvd": {
        "published": "2026-07-15T14:18:33.057",
        "lastModified": "2026-07-15T18:47:38.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59838",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "low",
        "mechanism": "FortiSIEM does not neutralize script-related HTML tags before page generation, although the vendor record leaves the attack vector as a placeholder.",
        "basis": [
          "CNA",
          "CWE-80"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-149",
          "host": "fortiguard.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-59839",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:21:31.715Z",
      "date_published": "2026-07-14T15:19:46.961Z",
      "date_updated": "2026-07-14T16:02:10.053Z",
      "publisher": "fortinet",
      "title": "A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.",
      "affected": {
        "vendors": [
          "Fortinet"
        ],
        "products": [
          {
            "vendor": "Fortinet",
            "product": "FortiProxy"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiOS"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiPAM"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 18,
        "versionRangeCount": 16,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:psirt@fortinet.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11085
      },
      "nvd": {
        "published": "2026-07-14T16:17:03.047",
        "lastModified": "2026-07-15T14:48:08.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59839",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-151",
          "host": "fortiguard.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 689,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-59840",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:21:36.593Z",
      "date_published": "2026-07-14T15:19:51.309Z",
      "date_updated": "2026-07-16T14:00:37.212Z",
      "publisher": "fortinet",
      "title": "A buffer over-read vulnerability in Fortinet FortiOS 7.",
      "affected": {
        "vendors": [
          "Fortinet"
        ],
        "products": [
          {
            "vendor": "Fortinet",
            "product": "FortiOS"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiPAM"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiSwitchManager"
          },
          {
            "vendor": "Fortinet",
            "product": "FortiProxy"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 19,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:psirt@fortinet.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07837
      },
      "nvd": {
        "published": "2026-07-14T16:17:03.297",
        "lastModified": "2026-07-16T15:16:34.923",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59840",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FortiOS reads beyond the end of an attacker-influenced buffer because the operation's length exceeds the available bytes.",
        "basis": [
          "CNA",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-154",
          "host": "fortiguard.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 379,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 19
      }
    },
    {
      "cve_id": "CVE-2026-59841",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:21:38.323Z",
      "date_published": "2026-07-14T15:15:08.048Z",
      "date_updated": "2026-07-15T03:59:10.652Z",
      "publisher": "fortinet",
      "title": "A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.",
      "affected": {
        "vendors": [
          "Fortinet"
        ],
        "products": [
          {
            "vendor": "Fortinet",
            "product": "FortiSIEMWindowsAgent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-923",
          "name": "Improper Restriction of Communication Channel to Intended Endpoints",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C"
        },
        {
          "source": "NVD:psirt@fortinet.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04447
      },
      "nvd": {
        "published": "2026-07-14T16:17:03.520",
        "lastModified": "2026-07-15T05:17:23.870",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59841",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Windows agent accepts communication outside its intended endpoint set, but the vendor record retains a placeholder attack vector and does not identify the trusted channel decision.",
        "basis": [
          "CNA",
          "CWE-923"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-155",
          "host": "fortiguard.fortinet.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 215,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59842",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:40:24.560Z",
      "date_published": "2026-07-21T11:08:30.540Z",
      "date_updated": "2026-07-22T19:07:19.005Z",
      "publisher": "redhat",
      "title": "Libssh: libssh: information disclosure via short gssapi curve25519 public key",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.0042,
        "percentile": 0.3457
      },
      "nvd": {
        "published": "2026-07-21T12:18:57.727",
        "lastModified": "2026-07-30T13:13:06.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59842",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "During server-side GSSAPI key exchange, libssh copies a client-supplied Curve25519 public key without first requiring the expected length, causing a heap read past the supplied key.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59842",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498168",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 318,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59843",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:40:24.561Z",
      "date_published": "2026-07-21T11:16:12.061Z",
      "date_updated": "2026-07-22T19:07:08.289Z",
      "publisher": "redhat",
      "title": "Libssh: libssh: denial of service via zero advertised channel packet size",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00506,
        "percentile": 0.40434
      },
      "nvd": {
        "published": "2026-07-21T12:18:57.860",
        "lastModified": "2026-07-30T13:13:28.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59843",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "libssh accepts a peer-advertised channel packet size of zero and later loops indefinitely while trying to make write progress.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59843",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498176",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 218,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59844",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:40:24.561Z",
      "date_published": "2026-07-21T11:32:16.816Z",
      "date_updated": "2026-07-22T19:07:10.508Z",
      "publisher": "redhat",
      "title": "Libssh: libssh: denial of service via oversized sftp read length",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00506,
        "percentile": 0.40434
      },
      "nvd": {
        "published": "2026-07-21T12:18:57.973",
        "lastModified": "2026-07-30T13:12:44.153",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59844",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The libssh SFTP server allocates memory from an attacker-chosen SSH_FXP_READ length without an effective upper bound.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59844",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498177",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59845",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:40:24.561Z",
      "date_published": "2026-07-21T11:26:43.884Z",
      "date_updated": "2026-07-23T14:30:03.721Z",
      "publisher": "redhat",
      "title": "Libssh: libssh: denial of service via unchecked proxycommand fork() failure",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-390",
          "name": "Detection of Error Condition Without Action",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01292
      },
      "nvd": {
        "published": "2026-07-21T12:18:58.103",
        "lastModified": "2026-07-30T13:12:16.230",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59845",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libssh stores a failed ProxyCommand fork result as PID minus one and later sends cleanup signals using that invalid process identifier.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-390"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59845",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498178",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59846",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:40:24.561Z",
      "date_published": "2026-07-21T12:55:56.532Z",
      "date_updated": "2026-07-23T13:40:22.734Z",
      "publisher": "redhat",
      "title": "Libssh: libssh: information disclosure via proxycommand %r username expansion",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-77",
          "name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01799
      },
      "nvd": {
        "published": "2026-07-21T13:17:18.143",
        "lastModified": "2026-07-30T13:12:01.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59846",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ProxyCommand expands an attacker-controlled username through %r and passes the resulting shell metacharacters to the shell.",
        "basis": [
          "CNA",
          "CWE-77"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59846",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498179",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59847",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:40:24.561Z",
      "date_published": "2026-07-21T13:18:18.146Z",
      "date_updated": "2026-07-22T19:07:12.443Z",
      "publisher": "redhat",
      "title": "Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1310",
          "name": "Missing Ability to Patch ROM Code",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22736
      },
      "nvd": {
        "published": "2026-07-21T14:16:34.657",
        "lastModified": "2026-07-30T13:11:47.560",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59847",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OpenSSL backend accepts AES-GCM finalization without enforcing the authentication result, removing ciphertext integrity protection.",
        "basis": [
          "CNA",
          "CWE-1310"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59847",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498180",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59848",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:40:24.561Z",
      "date_published": "2026-07-21T13:21:50.027Z",
      "date_updated": "2026-07-23T14:28:28.830Z",
      "publisher": "redhat",
      "title": "Libssh: libssh: denial of service via sftp responses with unknown request ids",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21742
      },
      "nvd": {
        "published": "2026-07-21T14:16:34.790",
        "lastModified": "2026-07-30T13:11:26.973",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59848",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SFTP client queues responses for unknown request identifiers indefinitely instead of discarding or bounding them.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59848",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498181",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 207,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59849",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:40:24.561Z",
      "date_published": "2026-07-21T14:08:15.016Z",
      "date_updated": "2026-07-22T19:07:23.331Z",
      "publisher": "redhat",
      "title": "Libssh: libssh: denial of service via automatic certificate authentication loop",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 4.4,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14699
      },
      "nvd": {
        "published": "2026-07-21T15:16:37.647",
        "lastModified": "2026-07-30T16:33:49.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59849",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Red Hat Hardened Images can enter a loop whose exit condition is never reached for the crafted input or state, consuming CPU indefinitely.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59849",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498182",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59850",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:40:24.561Z",
      "date_published": "2026-07-21T14:15:58.793Z",
      "date_updated": "2026-07-22T19:07:15.638Z",
      "publisher": "redhat",
      "title": "Libssh: libssh: use-after-free via data callbacks on closed channels",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 3.2,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22637
      },
      "nvd": {
        "published": "2026-07-21T15:16:37.773",
        "lastModified": "2026-07-30T16:23:58.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59850",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libssh invokes channel data callbacks after the associated channel data has been freed.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59850",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498183",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59851",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:40:24.561Z",
      "date_published": "2026-07-21T14:20:47.001Z",
      "date_updated": "2026-07-22T19:06:52.468Z",
      "publisher": "redhat",
      "title": "Libssh: libssh: authentication bypass via missing gssapi principal check",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19523
      },
      "nvd": {
        "published": "2026-07-21T15:16:37.897",
        "lastModified": "2026-07-30T16:08:49.223",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59851",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "libssh authenticates a Kerberos principal on the GSSAPI key-exchange path without checking that it may log in as the requested local user.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:42922",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "vendor-advisory",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-59851",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498184",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59853",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.606Z",
      "date_published": "2026-07-09T22:20:52.898Z",
      "date_updated": "2026-07-10T13:47:41.946Z",
      "publisher": "GitHub_M",
      "title": "SiYuan: Publish-mode Reader can exfiltrate private saved-search Criteria via /api/storage/getCriteria (missing publish-access filter)",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.1461
      },
      "nvd": {
        "published": "2026-07-09T23:17:06.030",
        "lastModified": "2026-07-10T15:49:19.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59853",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The getCriteria operation returns criteria without applying the required publication-access check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-px3c-cf92-9g83",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/commit/0049d0f04ffe9837760d29248b9ef31605077d36",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.7.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 446,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59854",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.606Z",
      "date_published": "2026-07-09T22:25:39.675Z",
      "date_updated": "2026-07-10T20:59:30.307Z",
      "publisher": "GitHub_M",
      "title": "SiYuan: Incomplete IsSensitivePath denylist: globalCopyFiles reads home-dir credential dotfiles into the workspace",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20067
      },
      "nvd": {
        "published": "2026-07-09T23:17:06.163",
        "lastModified": "2026-07-10T21:17:00.433",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59854",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SiYuan relies on an incomplete sensitive-path denylist while copying arbitrary absolute source paths into the workspace.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-vmm8-3ccv-ppvw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/commit/914c5180a88d17f6d38716a56483327b367ef55f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/commit/b54fee401799d987d2fd2888220938ad599b8c5e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.7.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 563,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59855",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.606Z",
      "date_published": "2026-07-09T22:19:42.755Z",
      "date_updated": "2026-07-14T01:24:09.004Z",
      "publisher": "GitHub_M",
      "title": "SiYuan: Store XSS To Rce via Asset.render",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-80",
          "name": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22795
      },
      "nvd": {
        "published": "2026-07-09T23:17:06.293",
        "lastModified": "2026-07-14T02:16:57.623",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59855",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SiYuan Asset.render interpolates an unsanitized path into HTML assigned to innerHTML.",
        "basis": [
          "CNA",
          "CWE-80"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-w3gq-5j72-36vc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/commit/efbe3a557720034782643e55c9e0282530cb6bbb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/releases/tag/v3.7.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59856",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.606Z",
      "date_published": "2026-07-09T22:39:01.803Z",
      "date_updated": "2026-07-14T03:55:39.477Z",
      "publisher": "GitHub_M",
      "title": "Vim: Arbitrary Code Execution via PHP Omni-Completion",
      "affected": {
        "vendors": [
          "vim"
        ],
        "products": [
          {
            "vendor": "vim",
            "product": "vim"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12094
      },
      "nvd": {
        "published": "2026-07-09T23:17:06.420",
        "lastModified": "2026-07-14T05:16:19.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59856",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Vim interpolates a PHP class name from the edited buffer into an Ex search command without escaping quotes or command separators, allowing the name to inject shell-capable Ex commands.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vim/vim/security/advisories/GHSA-fh26-8f79-wj97",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vim/vim/commit/43afc581a37a35762dd0ef292f038b9dc5680a24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 664,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59857",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.606Z",
      "date_published": "2026-07-09T22:34:54.698Z",
      "date_updated": "2026-07-10T14:14:40.735Z",
      "publisher": "GitHub_M",
      "title": "Vim: Out-of-bounds Write in SAL Soundfolding",
      "affected": {
        "vendors": [
          "vim"
        ],
        "products": [
          {
            "vendor": "vim",
            "product": "vim"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0.09999999999999964,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01365
      },
      "nvd": {
        "published": "2026-07-09T23:17:06.580",
        "lastModified": "2026-07-10T19:23:21.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59857",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vim/vim/security/advisories/GHSA-m3hf-xcm3-xhm2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vim/vim/commit/d22ff1c955ff87e8273210eae125aab0e85b6c30",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 690,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59858",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.606Z",
      "date_published": "2026-07-09T22:37:52.789Z",
      "date_updated": "2026-07-14T03:55:38.697Z",
      "publisher": "GitHub_M",
      "title": "Vim: Arbitrary Code Execution via C Omni-Completion",
      "affected": {
        "vendors": [
          "vim"
        ],
        "products": [
          {
            "vendor": "vim",
            "product": "vim"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03574
      },
      "nvd": {
        "published": "2026-07-09T23:17:06.740",
        "lastModified": "2026-07-14T05:16:19.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59858",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "C omni-completion interpolates a crafted tags field into an executed vimgrep command without escaping Vim's command separator.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 599,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59859",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.606Z",
      "date_published": "2026-07-16T14:40:27.319Z",
      "date_updated": "2026-07-29T18:29:05.321Z",
      "publisher": "GitHub_M",
      "title": "Kiota: Code Generation Literal Injection in the PHP Generator",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "kiota"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01016,
        "percentile": 0.59928
      },
      "nvd": {
        "published": "2026-07-16T15:16:35.167",
        "lastModified": "2026-07-29T19:16:48.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59859",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kiota escapes quotes but not dollar-sign interpolation when embedding schema strings in PHP double-quoted literals, allowing generated source code to be injected.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/kiota/security/advisories/GHSA-jqwh-526h-c92j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/pull/7863",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/commit/5e2a211ac4261988fbdc72c3b268596ea8837b87",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/releases/tag/v1.32.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 502,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59860",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.606Z",
      "date_published": "2026-07-16T14:34:24.549Z",
      "date_updated": "2026-07-29T19:26:44.335Z",
      "publisher": "GitHub_M",
      "title": "Kiota: XML Doc-Comment Newline Breakout Code Injection",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "kiota"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01016,
        "percentile": 0.59928
      },
      "nvd": {
        "published": "2026-07-16T15:16:35.310",
        "lastModified": "2026-07-29T20:17:04.897",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59860",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kiota writes OpenAPI text into C# XML comment lines without removing line terminators, allowing comment breakout into generated source code.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/kiota/security/advisories/GHSA-3hrf-2gc2-mx32",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/pull/7831",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/commit/ebb632db90aa8e3c20949337d9faa2720d64ca44",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/releases/tag/v1.32.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59861",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.606Z",
      "date_published": "2026-07-16T14:36:32.010Z",
      "date_updated": "2026-07-29T19:26:44.162Z",
      "publisher": "GitHub_M",
      "title": "Kiota: Code Generation Literal Injection in Kiota Ruby Generator",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "kiota"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01471,
        "percentile": 0.71214
      },
      "nvd": {
        "published": "2026-07-16T15:16:35.440",
        "lastModified": "2026-07-29T20:17:05.010",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59861",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "kiota places caller-influenced data into dynamically evaluated or generated code without restricting executable syntax.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/kiota/security/advisories/GHSA-xg2h-5xr2-29jw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/pull/7746",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/commit/fee1b648bb4394ba7ba72de9c0ce4f2a0bad0cb6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/releases/tag/v1.32.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59862",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.606Z",
      "date_published": "2026-07-16T14:38:59.471Z",
      "date_updated": "2026-07-29T19:26:43.989Z",
      "publisher": "GitHub_M",
      "title": "Kiota: Code Generation Literal Injection in the Python Generator",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "kiota"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0102,
        "percentile": 0.6002
      },
      "nvd": {
        "published": "2026-07-16T15:16:35.570",
        "lastModified": "2026-07-29T20:17:05.117",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59862",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Python generator emits attacker-controlled multiline enum documentation into source without newline separation, allowing module-level code insertion.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/kiota/security/advisories/GHSA-7f3j-j7jj-r3vr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/releases/tag/v1.32.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59863",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-16T14:42:02.337Z",
      "date_updated": "2026-07-16T15:33:19.970Z",
      "publisher": "GitHub_M",
      "title": "Kiota: Workspace-config poisoning: out-of-repo file write + generation-time SSRF",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "kiota"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01123,
        "percentile": 0.63057
      },
      "nvd": {
        "published": "2026-07-16T15:16:35.707",
        "lastModified": "2026-07-16T17:13:54.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59863",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A poisoned workspace outputPath writes generated files outside the repository root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/kiota/security/advisories/GHSA-4rj6-vrwv-wr8m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/pull/7885",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/commit/4049327872db7846ace35c9003774d3e3878e4e9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/releases/tag/v1.32.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 547,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59864",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-16T14:45:36.247Z",
      "date_updated": "2026-07-17T03:56:38.964Z",
      "publisher": "GitHub_M",
      "title": "Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "kiota"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01275,
        "percentile": 0.67076
      },
      "nvd": {
        "published": "2026-07-16T16:19:15.240",
        "lastModified": "2026-07-17T05:16:41.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59864",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kiota writes unvalidated static-template paths into generated plugin manifests, allowing traversal or an external resource to be selected.",
        "basis": [
          "CNA record",
          "CWE-22",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/kiota/security/advisories/GHSA-4jwf-m4wg-8p66",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/pull/7892",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/commit/9a185994a4e549b7bba3cc2beffb9736aa902e79",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/releases/tag/v1.32.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 574,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59865",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-16T14:43:40.058Z",
      "date_updated": "2026-07-29T18:26:17.378Z",
      "publisher": "GitHub_M",
      "title": "Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "kiota"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0319,
        "percentile": 0.86837
      },
      "nvd": {
        "published": "2026-07-16T16:19:15.373",
        "lastModified": "2026-07-29T19:16:48.503",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59865",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "kiota lets attacker-controlled text cross into an executable code or template grammar.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/kiota/security/advisories/GHSA-hq9q-27g5-qwpj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/pull/7883",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/commit/e1d6d76c6eecbe50785429166faaf8c831e036c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/releases/tag/v1.32.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 562,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59866",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-16T14:46:50.738Z",
      "date_updated": "2026-07-29T18:26:17.236Z",
      "publisher": "GitHub_M",
      "title": "Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "kiota"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01355,
        "percentile": 0.68899
      },
      "nvd": {
        "published": "2026-07-16T16:19:15.493",
        "lastModified": "2026-07-29T19:16:48.617",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59866",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kiota uses untrusted class and namespace names as output path components without sanitization, allowing generated files to escape the output directory.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/kiota/security/advisories/GHSA-4vv7-jj25-4gh6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/pull/7884",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/commit/dc812dbbf88ef7edf53a890d36b2f9d1460e947d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/releases/tag/v1.32.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 646,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59867",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-16T14:48:11.958Z",
      "date_updated": "2026-07-16T15:37:02.124Z",
      "publisher": "GitHub_M",
      "title": "Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref",
      "affected": {
        "vendors": [
          "microsoft"
        ],
        "products": [
          {
            "vendor": "microsoft",
            "product": "kiota"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01921,
        "percentile": 0.77895
      },
      "nvd": {
        "published": "2026-07-16T16:19:15.620",
        "lastModified": "2026-07-16T17:13:54.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59867",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kiota follows attacker-controlled OpenAPI references to arbitrary HTTP origins and local paths during generation without an origin or filesystem allowlist.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-829",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/kiota/security/advisories/GHSA-rg4h-fpcp-2qm8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/pull/7888",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/commit/cccd798027f0a20db796b3df6c64f9897a39d7b1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/microsoft/kiota/releases/tag/v1.32.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 562,
        "referenceCount": 4,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59868",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-08T15:18:19.422Z",
      "date_updated": "2026-07-09T13:42:54.035Z",
      "publisher": "GitHub_M",
      "title": "js-yaml: YAML merge-key chains can force quadratic CPU consumption",
      "affected": {
        "vendors": [
          "nodeca"
        ],
        "products": [
          {
            "vendor": "nodeca",
            "product": "js-yaml"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33677
      },
      "nvd": {
        "published": "2026-07-08T16:16:33.270",
        "lastModified": "2026-07-13T15:06:34.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59868",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A chain of YAML merge keys repeatedly copies the prior mapping, producing quadratic parse work from linearly growing input.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nodeca/js-yaml/security/advisories/GHSA-g796-fgmg-93mv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nodeca/js-yaml/commit/3105455b81dee69e0fd36e09ac0b2ccfdb54adc1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nodeca/js-yaml/releases/tag/5.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59869",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-08T15:15:54.675Z",
      "date_updated": "2026-07-09T15:14:29.753Z",
      "publisher": "GitHub_M",
      "title": "js-yaml: YAML merge-key chains can force quadratic CPU consumption",
      "affected": {
        "vendors": [
          "nodeca"
        ],
        "products": [
          {
            "vendor": "nodeca",
            "product": "js-yaml"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00423,
        "percentile": 0.34878
      },
      "nvd": {
        "published": "2026-07-08T16:16:33.423",
        "lastModified": "2026-07-13T15:05:34.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59869",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Each YAML merge-key mapping recopies the preceding mapping, making a linear chain consume quadratic CPU time.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nodeca/js-yaml/security/advisories/GHSA-52cp-r559-cp3m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nodeca/js-yaml/releases/tag/3.15.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nodeca/js-yaml/releases/tag/4.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 323,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59870",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-08T15:13:20.308Z",
      "date_updated": "2026-07-08T15:50:55.378Z",
      "publisher": "GitHub_M",
      "title": "js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing",
      "affected": {
        "vendors": [
          "nodeca"
        ],
        "products": [
          {
            "vendor": "nodeca",
            "product": "js-yaml"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33678
      },
      "nvd": {
        "published": "2026-07-08T16:16:33.580",
        "lastModified": "2026-07-10T19:20:49.153",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59870",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The js-yaml path allocates attacker-driven resources without an effective bound or throttle.",
        "basis": [
          "CNA",
          "CWE-407",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/nodeca/js-yaml/security/advisories/GHSA-724g-mxrg-4qvm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/nodeca/js-yaml/commit/39f3211a2f01b3c6982710cf21434ab7060acefe",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/nodeca/js-yaml/releases/tag/5.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 348,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59871",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-08T15:25:09.519Z",
      "date_updated": "2026-07-08T16:13:05.563Z",
      "publisher": "GitHub_M",
      "title": "node-tar: Process crash via PAX numeric path type confusion",
      "affected": {
        "vendors": [
          "isaacs"
        ],
        "products": [
          {
            "vendor": "isaacs",
            "product": "node-tar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-704",
          "name": "Incorrect Type Conversion or Cast",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33679
      },
      "nvd": {
        "published": "2026-07-08T16:16:33.723",
        "lastModified": "2026-07-10T19:02:55.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59871",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A numeric PAX path is coerced to the wrong type and then passed to a string method, raising an uncaught TypeError.",
        "basis": [
          "CNA",
          "CWE-704"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/isaacs/node-tar/releases/tag/v7.5.18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59873",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-08T15:22:40.077Z",
      "date_updated": "2026-07-08T19:41:26.372Z",
      "publisher": "GitHub_M",
      "title": "node-tar: Decompression/parse DoS via unlimited input",
      "affected": {
        "vendors": [
          "isaacs"
        ],
        "products": [
          {
            "vendor": "isaacs",
            "product": "node-tar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.00424,
        "percentile": 0.34933
      },
      "nvd": {
        "published": "2026-07-08T16:16:33.867",
        "lastModified": "2026-07-10T18:57:17.907",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59873",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The node-tar request path allocates work or memory from attacker-controlled input without an effective item or byte limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/isaacs/node-tar/releases/tag/v7.5.19",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 346,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59874",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-08T15:23:47.527Z",
      "date_updated": "2026-07-08T17:00:42.937Z",
      "publisher": "GitHub_M",
      "title": "node-tar: Negative tar entry size causes infinite loop in archive replace",
      "affected": {
        "vendors": [
          "isaacs"
        ],
        "products": [
          {
            "vendor": "isaacs",
            "product": "node-tar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34419
      },
      "nvd": {
        "published": "2026-07-08T16:16:33.990",
        "lastModified": "2026-07-10T18:54:12.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59874",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "node-tar processes a negative entry size without advancing the scanner, leaving the parsing loop unable to terminate.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/isaacs/node-tar/releases/tag/v7.5.18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 298,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59875",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-08T15:20:29.997Z",
      "date_updated": "2026-07-09T13:45:44.160Z",
      "publisher": "GitHub_M",
      "title": "node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records",
      "affected": {
        "vendors": [
          "isaacs"
        ],
        "products": [
          {
            "vendor": "isaacs",
            "product": "node-tar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21408
      },
      "nvd": {
        "published": "2026-07-08T16:16:34.107",
        "lastModified": "2026-07-10T19:10:59.333",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59875",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/isaacs/node-tar/releases/tag/v7.5.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59876",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-08T15:31:11.421Z",
      "date_updated": "2026-07-09T14:41:45.107Z",
      "publisher": "GitHub_M",
      "title": "protobufjs: Text Format string map parsing can mutate returned map object prototype",
      "affected": {
        "vendors": [
          "protobufjs"
        ],
        "products": [
          {
            "vendor": "protobufjs",
            "product": "protobuf.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00219,
        "percentile": 0.1252
      },
      "nvd": {
        "published": "2026-07-08T16:16:34.233",
        "lastModified": "2026-07-13T15:02:37.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59876",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __proto__ to change the prototype of the returned map object instead of creating an own map entry in protobufjs/ext/textformat.",
        "basis": [
          "CNA",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-jfj6-75fj-8934",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/protobufjs/protobuf.js/pull/2335",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/protobufjs/protobuf.js/commit/9f97fe413072d3beb52c74e62d88ea8adc9444d8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.6.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T15:41:53.607Z",
      "date_published": "2026-07-08T15:28:07.696Z",
      "date_updated": "2026-07-08T15:49:27.814Z",
      "publisher": "GitHub_M",
      "title": "protobufjs: Denial of Service via infinite loop in .proto option parsing",
      "affected": {
        "vendors": [
          "protobufjs"
        ],
        "products": [
          {
            "vendor": "protobufjs",
            "product": "protobuf.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29749
      },
      "nvd": {
        "published": "2026-07-08T16:16:34.363",
        "lastModified": "2026-07-10T18:53:14.377",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59877",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "protobufjs scans an unfinished option declaration for an equals token without checking end of input, leaving the parser in an infinite loop.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-j3f2-48v5-ccww",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/protobufjs/protobuf.js/pull/2352",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/protobufjs/protobuf.js/commit/10fba6d54815ceecca8a06b9a6db490c8f5d2217",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/protobufjs/protobuf.js/commit/fa5c73add738ceb471e74da8cc2f3727c3d0a69f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.6.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.6.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 422,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59878",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:19:11.276Z",
      "date_published": "2026-07-28T13:33:54.909Z",
      "date_updated": "2026-07-28T14:05:06.447Z",
      "publisher": "apache",
      "title": "Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache ActiveMQ AMQP"
          },
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache ActiveMQ"
          },
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache ActiveMQ All"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00548,
        "percentile": 0.428
      },
      "nvd": {
        "published": "2026-07-28T14:16:38.283",
        "lastModified": "2026-07-28T16:20:53.010",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59878",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ActiveMQ's AMQP NIO connector accepts a malicious frame-size value that kills NIO threads, allowing rapid requests to exhaust the connector's worker pool.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/dnyx4d2oldshcj4lthso7b53y4bqmjvn",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/27/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-59879",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.982Z",
      "date_published": "2026-07-08T15:47:24.885Z",
      "date_updated": "2026-07-08T19:41:12.330Z",
      "publisher": "GitHub_M",
      "title": "Immutable.js `List` 32-bit trie overflow → unrecoverable DoS",
      "affected": {
        "vendors": [
          "immutable-js"
        ],
        "products": [
          {
            "vendor": "immutable-js",
            "product": "immutable-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00438,
        "percentile": 0.36056
      },
      "nvd": {
        "published": "2026-07-08T17:17:26.370",
        "lastModified": "2026-07-10T18:48:54.280",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59879",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "List bounds in the 2^30-to-2^31 range wrap internal size arithmetic, producing an infinite loop or allocation growth without a practical bound.",
        "basis": [
          "CNA",
          "CWE-1284",
          "CWE-190",
          "CWE-400",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/immutable-js/immutable-js/security/advisories/GHSA-v56q-mh7h-f735",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/immutable-js/immutable-js/commit/a1a1ee412dcaa380ab325196283d06594ffe4b84",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/immutable-js/immutable-js/commit/f0bc997d8eb9886aff2236635aa210a95a04304a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/immutable-js/immutable-js/releases/tag/v4.3.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/immutable-js/immutable-js/releases/tag/v5.1.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 5,
        "cweCount": 4,
        "cnaCweCount": 4,
        "adpCweCount": 0,
        "nvdCweCount": 4,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59880",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.982Z",
      "date_published": "2026-07-08T15:44:23.414Z",
      "date_updated": "2026-07-08T16:13:46.106Z",
      "publisher": "GitHub_M",
      "title": "Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set",
      "affected": {
        "vendors": [
          "immutable-js"
        ],
        "products": [
          {
            "vendor": "immutable-js",
            "product": "immutable-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35569
      },
      "nvd": {
        "published": "2026-07-08T16:16:34.517",
        "lastModified": "2026-07-10T18:49:51.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59880",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "immutable-js applies an algorithm with attacker-triggered worst-case complexity without a work bound, allowing CPU exhaustion.",
        "basis": [
          "CNA",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/immutable-js/immutable-js/security/advisories/GHSA-xvcm-6775-5m9r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/immutable-js/immutable-js/commit/3dd7e5655012597a41873e328bf9142a8901527b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/immutable-js/immutable-js/commit/e51d49fc612ded5ec4dfb94ff294d22074269b0f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/immutable-js/immutable-js/releases/tag/v4.3.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/immutable-js/immutable-js/releases/tag/v5.1.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59881",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.982Z",
      "date_published": "2026-07-30T17:34:32.415Z",
      "date_updated": "2026-07-30T18:35:40.624Z",
      "publisher": "GitHub_M",
      "title": "AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate",
      "affected": {
        "vendors": [
          "aio-libs"
        ],
        "products": [
          {
            "vendor": "aio-libs",
            "product": "aiohttp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22469
      },
      "nvd": {
        "published": "2026-07-30T19:18:33.597",
        "lastModified": "2026-07-30T20:03:32.983",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59881",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The AIOHTTP client honors and decompresses RSV1 frames even though the peer never negotiated permessage-deflate.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/aio-libs/aiohttp/pull/12978",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "http://github.com/aio-libs/aiohttp/releases/tag/v3.14.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59882",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.982Z",
      "date_published": "2026-07-08T15:50:03.077Z",
      "date_updated": "2026-07-08T17:00:22.945Z",
      "publisher": "GitHub_M",
      "title": "guzzlehttp/psr7: Host Confusion via Weak URI Host Validation",
      "affected": {
        "vendors": [
          "guzzle"
        ],
        "products": [
          {
            "vendor": "guzzle",
            "product": "psr7"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 2.3,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08409
      },
      "nvd": {
        "published": "2026-07-08T17:17:26.597",
        "lastModified": "2026-07-17T14:29:51.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59882",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "guzzlehttp/psr7 accepts authority delimiters and malformed brackets in a host, so security checks and URI routing can derive different authorities.",
        "basis": [
          "CNA",
          "CWE-436"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/guzzle/psr7/security/advisories/GHSA-c2w2-prh8-qm98",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/guzzle/psr7/pull/811",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/guzzle/psr7/commit/ddd64f17d4cc1f7e5ffe6fd2c989ec7221712580",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/guzzle/psr7/releases/tag/2.12.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 361,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59883",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.982Z",
      "date_published": "2026-07-08T15:56:03.689Z",
      "date_updated": "2026-07-09T13:49:43.875Z",
      "publisher": "GitHub_M",
      "title": "Guzzle: Cookie Disclosure and Injection via IP-Address Domains",
      "affected": {
        "vendors": [
          "guzzle"
        ],
        "products": [
          {
            "vendor": "guzzle",
            "product": "guzzle"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-384",
          "name": "Session Fixation",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01975
      },
      "nvd": {
        "published": "2026-07-08T17:17:26.737",
        "lastModified": "2026-07-13T14:01:39.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59883",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cookie domain matching applies ordinary suffix rules to IP-address and bare-numeric domains instead of requiring an exact host match.",
        "basis": [
          "CNA",
          "CWE-346",
          "CWE-384"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/guzzle/guzzle/security/advisories/GHSA-g446-98w2-8p5w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/guzzle/guzzle/pull/3694",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/guzzle/guzzle/commit/b9944c161b12d9ee9c9334cfc5b9659ecd7451f8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/guzzle/guzzle/releases/tag/7.12.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59884",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.982Z",
      "date_published": "2026-07-14T16:41:10.277Z",
      "date_updated": "2026-07-15T13:50:29.814Z",
      "publisher": "GitHub_M",
      "title": "pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs",
      "affected": {
        "vendors": [
          "pyasn1"
        ],
        "products": [
          {
            "vendor": "pyasn1",
            "product": "pyasn1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00349,
        "percentile": 0.2762
      },
      "nvd": {
        "published": "2026-07-14T17:17:14.750",
        "lastModified": "2026-07-21T14:37:52.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59884",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The BER decoder accumulates unbounded long-form tag continuation octets into an arbitrarily large integer, causing quadratic CPU work and error-path failures.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59885",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.983Z",
      "date_published": "2026-07-14T16:40:00.515Z",
      "date_updated": "2026-07-14T17:32:43.678Z",
      "publisher": "GitHub_M",
      "title": "pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service",
      "affected": {
        "vendors": [
          "pyasn1"
        ],
        "products": [
          {
            "vendor": "pyasn1",
            "product": "pyasn1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26028
      },
      "nvd": {
        "published": "2026-07-14T17:17:14.880",
        "lastModified": "2026-07-21T14:38:21.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59885",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "pyasn1 decodes attacker-controlled object identifiers with quadratic work in the number of arcs.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59886",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.983Z",
      "date_published": "2026-07-14T16:38:29.691Z",
      "date_updated": "2026-07-15T15:44:02.717Z",
      "publisher": "GitHub_M",
      "title": "pyasn1: Uncontrolled resource consumption when converting decoded REAL values",
      "affected": {
        "vendors": [
          "pyasn1"
        ],
        "products": [
          {
            "vendor": "pyasn1",
            "product": "pyasn1"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.2603
      },
      "nvd": {
        "published": "2026-07-14T17:17:15.010",
        "lastModified": "2026-07-21T14:38:13.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59886",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A tiny encoded REAL value can request enormous exact integer exponentiation when the decoded object is printed, compared, or converted.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59887",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.983Z",
      "date_published": "2026-07-08T15:58:12.114Z",
      "date_updated": "2026-07-09T14:41:02.113Z",
      "publisher": "GitHub_M",
      "title": "linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text",
      "affected": {
        "vendors": [
          "markdown-it"
        ],
        "products": [
          {
            "vendor": "markdown-it",
            "product": "linkify-it"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00342,
        "percentile": 0.26792
      },
      "nvd": {
        "published": "2026-07-08T17:17:26.883",
        "lastModified": "2026-07-10T19:13:03.283",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59887",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "linkify-it repeatedly rescans attacker-controlled input with quadratic work, allowing input length to consume disproportionate CPU time.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/markdown-it/linkify-it/security/advisories/GHSA-v245-v573-v5vm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/markdown-it/linkify-it/commit/105e5d77f7d119871d2b2d86ed208568eb3e7ffe",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/markdown-it/linkify-it/releases/tag/5.0.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 343,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59888",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.983Z",
      "date_published": "2026-07-14T16:44:20.091Z",
      "date_updated": "2026-07-14T17:52:03.675Z",
      "publisher": "GitHub_M",
      "title": "jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy",
      "affected": {
        "vendors": [
          "FasterXML"
        ],
        "products": [
          {
            "vendor": "FasterXML",
            "product": "jackson-databind"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16039
      },
      "nvd": {
        "published": "2026-07-14T17:17:15.137",
        "lastModified": "2026-07-15T20:18:23.677",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59888",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Jackson removes ignored Record properties before applying the naming strategy, so the renamed key escapes the earlier ignore decision.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/5974",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-59889",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.983Z",
      "date_published": "2026-07-14T19:57:48.473Z",
      "date_updated": "2026-07-16T14:50:17.517Z",
      "publisher": "GitHub_M",
      "title": "jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization",
      "affected": {
        "vendors": [
          "FasterXML"
        ],
        "products": [
          {
            "vendor": "FasterXML",
            "product": "jackson-databind"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27242
      },
      "nvd": {
        "published": "2026-07-14T21:17:06.160",
        "lastModified": "2026-07-16T16:19:15.790",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59889",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Jackson replays an unwrapped property without checking visibleInView(), allowing a lower-privileged JSON view to set a hidden property.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/issues/6060",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/pull/6056",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-59890",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.983Z",
      "date_published": "2026-07-08T16:02:07.519Z",
      "date_updated": "2026-07-08T16:44:52.269Z",
      "publisher": "GitHub_M",
      "title": "setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+",
      "affected": {
        "vendors": [
          "pypa"
        ],
        "products": [
          {
            "vendor": "pypa",
            "product": "setuptools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-176",
          "name": "Improper Handling of Unicode Encoding",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-697",
          "name": "Incorrect Comparison",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33297
      },
      "nvd": {
        "published": "2026-07-08T17:17:27.020",
        "lastModified": "2026-07-13T17:04:58.427",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59890",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The source-distribution builder compares filenames without Unicode normalization, so an NFD spelling bypasses an NFC exclusion rule and enters the archive.",
        "basis": [
          "CNA",
          "CWE-176",
          "CWE-697"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pypa/setuptools/releases/tag/v83.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59891",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.983Z",
      "date_published": "2026-07-14T16:54:50.608Z",
      "date_updated": "2026-07-21T18:43:52.659Z",
      "publisher": "GitHub_M",
      "title": "Credential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registry",
      "affected": {
        "vendors": [
          "sigstore"
        ],
        "products": [
          {
            "vendor": "sigstore",
            "product": "sigstore-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24063
      },
      "nvd": {
        "published": "2026-07-14T17:17:15.270",
        "lastModified": "2026-07-21T19:17:12.150",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59891",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Sigstore OCI selects registry credentials by substring rather than exact host match and can send them to a different registry.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/sigstore/sigstore-js/security/advisories/GHSA-pf56-329r-95rw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-js/commit/85c58380758b97ce1b74ef470e55cc21f9d3aa89",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/sigstore/sigstore-js/releases/tag/%40sigstore%2Foci%400.7.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 547,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59892",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.983Z",
      "date_published": "2026-07-08T16:03:58.439Z",
      "date_updated": "2026-07-08T19:41:27.498Z",
      "publisher": "GitHub_M",
      "title": "OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header",
      "affected": {
        "vendors": [
          "open-telemetry"
        ],
        "products": [
          {
            "vendor": "open-telemetry",
            "product": "opentelemetry-js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00455,
        "percentile": 0.3729
      },
      "nvd": {
        "published": "2026-07-08T17:17:27.190",
        "lastModified": "2026-07-10T18:56:03.583",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59892",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Jaeger propagator passes malformed percent-encoded header values to decodeURIComponent without catching the resulting exception.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-telemetry/opentelemetry-js/security/advisories/GHSA-45rx-2jwx-cxfr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-js/commit/b1c196d49d54caae59741cca0a9d57d101d7ea88",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-telemetry/opentelemetry-js/releases/tag/v2.9.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 474,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59895",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.983Z",
      "date_published": "2026-07-08T16:09:51.273Z",
      "date_updated": "2026-07-08T19:41:04.292Z",
      "publisher": "GitHub_M",
      "title": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility",
      "affected": {
        "vendors": [
          "honojs"
        ],
        "products": [
          {
            "vendor": "honojs",
            "product": "hono"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09818
      },
      "nvd": {
        "published": "2026-07-08T17:17:27.353",
        "lastModified": "2026-07-10T19:53:22.957",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59895",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/honojs/hono/security/advisories/GHSA-w62v-xxxg-mg59",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/honojs/hono/commit/cd3f6f7194f0e5c9d4b26ae0cf232018d0f388fc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/honojs/hono/releases/tag/v4.12.27",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 436,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59896",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.984Z",
      "date_published": "2026-07-08T16:08:07.975Z",
      "date_updated": "2026-07-08T16:59:09.169Z",
      "publisher": "GitHub_M",
      "title": "hono/jsx does not isolate context per request, leading to cross-request data disclosure",
      "affected": {
        "vendors": [
          "honojs"
        ],
        "products": [
          {
            "vendor": "honojs",
            "product": "hono"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00191,
        "percentile": 0.09038
      },
      "nvd": {
        "published": "2026-07-08T17:17:27.493",
        "lastModified": "2026-07-10T19:50:53.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59896",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/honojs/hono/security/advisories/GHSA-hvrm-45r6-mjfj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/honojs/hono/commit/fab3b13639339cbd5ba1166a5b23d9ac30c5f64f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/honojs/hono/releases/tag/v4.12.27",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 394,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59897",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.984Z",
      "date_published": "2026-07-08T16:06:11.369Z",
      "date_updated": "2026-07-09T13:51:31.335Z",
      "publisher": "GitHub_M",
      "title": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication",
      "affected": {
        "vendors": [
          "honojs"
        ],
        "products": [
          {
            "vendor": "honojs",
            "product": "hono"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-348",
          "name": "Use of Less Trusted Source",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02649
      },
      "nvd": {
        "published": "2026-07-08T17:17:27.637",
        "lastModified": "2026-07-10T19:50:16.717",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59897",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The API Gateway adapter de-duplicates repeated headers with substring matching, dropping a distinct value that security logic may need.",
        "basis": [
          "CNA",
          "CWE-348"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/honojs/hono/security/advisories/GHSA-xgm2-5f3f-mvvc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/honojs/hono/commit/aa921770d09bc35970362d5a2630a878f6d982fd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/honojs/hono/releases/tag/v4.12.27",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59898",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.984Z",
      "date_published": "2026-07-29T18:02:07.415Z",
      "date_updated": "2026-07-30T15:19:36.357Z",
      "publisher": "GitHub_M",
      "title": "Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18378
      },
      "nvd": {
        "published": "2026-07-29T19:16:48.740",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59898",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WebSocket V07/V08 handshaker switches protocols without requiring standard Upgrade headers, creating a proxy/backend interpretation conflict.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 521,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59899",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.984Z",
      "date_published": "2026-07-29T18:00:37.588Z",
      "date_updated": "2026-07-30T14:01:48.362Z",
      "publisher": "GitHub_M",
      "title": "Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21408
      },
      "nvd": {
        "published": "2026-07-29T18:16:56.137",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59899",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HttpContentEncoder enqueues one attacker-controlled encoding value per pipelined request without a per-connection queue limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 743,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.984Z",
      "date_published": "2026-07-29T17:58:35.543Z",
      "date_updated": "2026-07-29T18:07:24.906Z",
      "publisher": "GitHub_M",
      "title": "Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21408
      },
      "nvd": {
        "published": "2026-07-29T18:16:56.320",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59900",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "netty interprets HTTP message boundaries differently from an adjacent proxy or backend, allowing request desynchronization.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.1.136.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/netty/netty/releases/tag/netty-4.2.16.Final",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 673,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59901",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T16:40:07.984Z",
      "date_published": "2026-07-29T17:48:39.621Z",
      "date_updated": "2026-07-29T18:09:41.130Z",
      "publisher": "GitHub_M",
      "title": "Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15873
      },
      "nvd": {
        "published": "2026-07-29T18:16:56.467",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59901",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A malformed bzip2 stream traps the RLE decoder in an infinite loop on a Netty event-loop thread.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 514,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59919",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.125Z",
      "date_published": "2026-07-29T17:37:49.812Z",
      "date_updated": "2026-07-29T18:06:11.495Z",
      "publisher": "GitHub_M",
      "title": "Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00109,
        "percentile": 0.01447
      },
      "nvd": {
        "published": "2026-07-29T18:16:56.610",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59919",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CRLF characters in an AF_UNIX address are interpreted as additional PROXY protocol header lines.",
        "basis": [
          "CNA",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-wh89-7897-x99h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 845,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59920",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.125Z",
      "date_published": "2026-07-29T17:32:46.835Z",
      "date_updated": "2026-07-29T19:24:41.740Z",
      "publisher": "GitHub_M",
      "title": "Netty: STOMP CONNECT Frame Header Injection",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16351
      },
      "nvd": {
        "published": "2026-07-29T18:16:56.757",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59920",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The STOMP encoder writes a raw newline from a header value into CONNECT frames, where the broker parses it as a new header.",
        "basis": [
          "CNA record",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-3g8r-4pfx-jmfh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 932,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59921",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.125Z",
      "date_published": "2026-07-28T22:28:51.267Z",
      "date_updated": "2026-07-29T17:32:31.931Z",
      "publisher": "GitHub_M",
      "title": "Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder",
      "affected": {
        "vendors": [
          "netty"
        ],
        "products": [
          {
            "vendor": "netty",
            "product": "netty"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20353
      },
      "nvd": {
        "published": "2026-07-28T23:17:09.923",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59921",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "netty accepts CRLF bytes that terminate the intended field and inject an additional protocol field.",
        "basis": [
          "CNA",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 763,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59922",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.125Z",
      "date_published": "2026-07-08T16:12:00.545Z",
      "date_updated": "2026-07-09T14:40:22.315Z",
      "publisher": "GitHub_M",
      "title": "Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)",
      "affected": {
        "vendors": [
          "lepture"
        ],
        "products": [
          {
            "vendor": "lepture",
            "product": "mistune"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34419
      },
      "nvd": {
        "published": "2026-07-08T17:17:27.770",
        "lastModified": "2026-07-09T19:36:00.010",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59922",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Formatting plugins rescan marker runs from each possible start position, producing quadratic CPU work on crafted Markdown.",
        "basis": [
          "CNA",
          "CWE-407",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/commit/96d0f57f8fe9eeb06bb4cff521962a27d7c402e7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59923",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.125Z",
      "date_published": "2026-07-08T16:14:39.266Z",
      "date_updated": "2026-07-08T16:41:52.111Z",
      "publisher": "GitHub_M",
      "title": "Mistune: XSS via percent-encoded javascript URI bypass in safe_url()",
      "affected": {
        "vendors": [
          "lepture"
        ],
        "products": [
          {
            "vendor": "lepture",
            "product": "mistune"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.1499
      },
      "nvd": {
        "published": "2026-07-08T17:17:27.910",
        "lastModified": "2026-07-09T19:35:14.273",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59923",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In mistune, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lepture/mistune/security/advisories/GHSA-8c25-4j27-2rv3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59924",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.125Z",
      "date_published": "2026-07-08T16:22:11.116Z",
      "date_updated": "2026-07-08T17:10:47.834Z",
      "publisher": "GitHub_M",
      "title": "Mistune: Arbitrary File Read via Include directive path traversal",
      "affected": {
        "vendors": [
          "lepture"
        ],
        "products": [
          {
            "vendor": "lepture",
            "product": "mistune"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00399,
        "percentile": 0.32754
      },
      "nvd": {
        "published": "2026-07-08T17:17:28.050",
        "lastModified": "2026-07-09T19:34:54.647",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59924",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled path is used without confinement to the intended directory, allowing file access outside that namespace.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 385,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59925",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.126Z",
      "date_published": "2026-07-08T16:18:43.786Z",
      "date_updated": "2026-07-08T19:44:48.084Z",
      "publisher": "GitHub_M",
      "title": "inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs",
      "affected": {
        "vendors": [
          "lepture"
        ],
        "products": [
          {
            "vendor": "lepture",
            "product": "mistune"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33677
      },
      "nvd": {
        "published": "2026-07-08T17:17:28.183",
        "lastModified": "2026-07-09T19:39:58.870",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59925",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The inline parser scans forward for a closing emphasis marker from every opening asterisk run, causing quadratic work on repeated emphasis pairs.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-407",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lepture/mistune/security/advisories/GHSA-4j32-57v6-6g45",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/commit/5de41fb8e527004dbc363e047a3c380c9288c74f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 418,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59926",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.126Z",
      "date_published": "2026-07-08T16:16:15.681Z",
      "date_updated": "2026-07-08T19:40:52.229Z",
      "publisher": "GitHub_M",
      "title": "Mistune: XSS via unescaped class option in Admonition directive",
      "affected": {
        "vendors": [
          "lepture"
        ],
        "products": [
          {
            "vendor": "lepture",
            "product": "mistune"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00189,
        "percentile": 0.0872
      },
      "nvd": {
        "published": "2026-07-08T17:17:28.323",
        "lastModified": "2026-07-09T19:38:07.183",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59926",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The mistune rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lepture/mistune/security/advisories/GHSA-g97x-gvcm-x72h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/commit/a3cb6e5655308797e8be021d6c7b5bab13cbace2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/releases/tag/v3.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 379,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59927",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.126Z",
      "date_published": "2026-07-08T16:24:37.985Z",
      "date_updated": "2026-07-08T19:45:20.799Z",
      "publisher": "GitHub_M",
      "title": "Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files",
      "affected": {
        "vendors": [
          "lepture"
        ],
        "products": [
          {
            "vendor": "lepture",
            "product": "mistune"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-755",
          "name": "Improper Handling of Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27851
      },
      "nvd": {
        "published": "2026-07-08T17:17:28.450",
        "lastModified": "2026-07-09T19:30:14.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59927",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An indirect include cycle recurses without cycle detection or a depth bound.",
        "basis": [
          "CNA",
          "CWE-674",
          "CWE-755"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lepture/mistune/security/advisories/GHSA-8mpj-m6qm-5qr8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 374,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59928",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.126Z",
      "date_published": "2026-07-08T16:23:21.000Z",
      "date_updated": "2026-07-08T19:40:43.968Z",
      "publisher": "GitHub_M",
      "title": "Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions",
      "affected": {
        "vendors": [
          "lepture"
        ],
        "products": [
          {
            "vendor": "lepture",
            "product": "mistune"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00413,
        "percentile": 0.33954
      },
      "nvd": {
        "published": "2026-07-08T17:17:28.600",
        "lastModified": "2026-07-09T19:29:34.207",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59928",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The mistune parser performs superlinear work on attacker-controlled input without an effective work bound.",
        "basis": [
          "CNA",
          "CWE-407",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lepture/mistune/security/advisories/GHSA-ffq3-xpv3-j92q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/commit/2b04d7ba341c16ac78fe82d3076bdd5c3de87c69",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 356,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59929",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.126Z",
      "date_published": "2026-07-08T16:20:38.139Z",
      "date_updated": "2026-07-09T14:41:36.793Z",
      "publisher": "GitHub_M",
      "title": "Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution",
      "affected": {
        "vendors": [
          "lepture"
        ],
        "products": [
          {
            "vendor": "lepture",
            "product": "mistune"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13291
      },
      "nvd": {
        "published": "2026-07-08T17:17:28.737",
        "lastModified": "2026-07-09T19:29:01.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59929",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mistune's URL filter misses legacy or chained script schemes and emits them into executable browser markup.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-184"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lepture/mistune/security/advisories/GHSA-qfrw-5rxm-mhh2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 444,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59930",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.126Z",
      "date_published": "2026-07-08T16:13:21.999Z",
      "date_updated": "2026-07-09T13:54:33.627Z",
      "publisher": "GitHub_M",
      "title": "Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id=\"toc_N\"` content",
      "affected": {
        "vendors": [
          "lepture"
        ],
        "products": [
          {
            "vendor": "lepture",
            "product": "mistune"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03667
      },
      "nvd": {
        "published": "2026-07-08T17:17:28.867",
        "lastModified": "2026-07-09T19:28:30.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59930",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Mistune assigns predictable toc_N identifiers without incorporating heading text, allowing attacker-authored identifiers to collide with generated anchors and redirect same-page consumers.",
        "basis": [
          "CNA",
          "CWE-345",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/lepture/mistune/security/advisories/GHSA-2hm2-hc3v-44h9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/commit/c4093c4742ed0d10d9332fb8edb455869b7b581b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/lepture/mistune/releases/tag/v3.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 404,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59931",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.126Z",
      "date_published": "2026-07-28T17:27:27.300Z",
      "date_updated": "2026-07-28T18:13:17.566Z",
      "publisher": "GitHub_M",
      "title": "PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist",
      "affected": {
        "vendors": [
          "PHPOffice"
        ],
        "products": [
          {
            "vendor": "PHPOffice",
            "product": "PhpSpreadsheet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00531,
        "percentile": 0.41873
      },
      "nvd": {
        "published": "2026-07-28T18:17:22.873",
        "lastModified": "2026-07-30T19:19:45.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59931",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PhpSpreadsheet validates the initial WEBSERVICE host but follows redirects without validating the destination host.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-6hq5-7373-42rg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/commit/7ef7b25e8548a6ded79dac74e2e2c7acdac38d8d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/1.30.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.1.18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.4.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/3.10.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/5.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1261,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-59932",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.126Z",
      "date_published": "2026-07-28T17:59:17.404Z",
      "date_updated": "2026-07-29T13:56:46.333Z",
      "publisher": "GitHub_M",
      "title": "PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion",
      "affected": {
        "vendors": [
          "PHPOffice"
        ],
        "products": [
          {
            "vendor": "PHPOffice",
            "product": "PhpSpreadsheet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00691,
        "percentile": 0.4929
      },
      "nvd": {
        "published": "2026-07-28T19:17:39.590",
        "lastModified": "2026-07-30T19:33:00.343",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59932",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PhpSpreadsheet calls gzdecode() on an entire attacker-supplied Gnumeric file without limiting decompressed size during file-type detection.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-2mrg-gjxq-2gvr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/commit/85f2556b0bf5269061bf45932ecda8a128d81750",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/1.30.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.1.18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.4.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/3.10.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/5.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 880,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-59933",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.126Z",
      "date_published": "2026-07-28T17:29:27.129Z",
      "date_updated": "2026-07-28T17:57:30.912Z",
      "publisher": "GitHub_M",
      "title": "PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion",
      "affected": {
        "vendors": [
          "PHPOffice"
        ],
        "products": [
          {
            "vendor": "PHPOffice",
            "product": "PhpSpreadsheet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00691,
        "percentile": 0.4929
      },
      "nvd": {
        "published": "2026-07-28T18:17:23.033",
        "lastModified": "2026-07-30T19:19:45.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59933",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PhpSpreadsheet follows attacker-controlled OLE sector chains without cycle detection or a maximum chain length, repeatedly appending the same sector until memory is exhausted.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-xh5m-36r6-47m3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/commit/85f2556b0bf5269061bf45932ecda8a128d81750",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/1.30.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.1.18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.4.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/3.10.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/5.8.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 885,
        "referenceCount": 7,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-59935",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.126Z",
      "date_published": "2026-07-08T19:34:15.078Z",
      "date_updated": "2026-07-09T13:36:17.854Z",
      "publisher": "GitHub_M",
      "title": "pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)",
      "affected": {
        "vendors": [
          "py-pdf"
        ],
        "products": [
          {
            "vendor": "py-pdf",
            "product": "pypdf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00367,
        "percentile": 0.29445
      },
      "nvd": {
        "published": "2026-07-08T20:16:59.260",
        "lastModified": "2026-07-09T20:42:14.150",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59935",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted value reaches a loop whose progress or termination condition can never be satisfied.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-g867-7843-wf8q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/py-pdf/pypdf/pull/3892",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/py-pdf/pypdf/commit/5a33a46416aa1ae6c025ff90a3cca57631fdafd2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/py-pdf/pypdf/releases/tag/6.14.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59936",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.127Z",
      "date_published": "2026-07-08T19:34:22.610Z",
      "date_updated": "2026-07-09T13:28:21.161Z",
      "publisher": "GitHub_M",
      "title": "pypdf: Possible infinite loop for not terminated inline images",
      "affected": {
        "vendors": [
          "py-pdf"
        ],
        "products": [
          {
            "vendor": "py-pdf",
            "product": "pypdf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26679
      },
      "nvd": {
        "published": "2026-07-08T20:16:59.403",
        "lastModified": "2026-07-09T20:41:41.110",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59936",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "pypdf scans an unterminated inline-image stream for an end marker without reaching a progress or exit condition, causing an infinite loop during operations such as text extraction.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-5xf7-4p34-54qr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/py-pdf/pypdf/pull/3891",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/py-pdf/pypdf/commit/ec3b14596186c40caca7cf8ab9b2155203e01b5b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/py-pdf/pypdf/releases/tag/6.14.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 310,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59937",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.127Z",
      "date_published": "2026-07-08T17:25:34.026Z",
      "date_updated": "2026-07-09T14:41:30.071Z",
      "publisher": "GitHub_M",
      "title": "pypdf: Possible long runtimes for repeated malformed cross-reference entries",
      "affected": {
        "vendors": [
          "py-pdf"
        ],
        "products": [
          {
            "vendor": "py-pdf",
            "product": "pypdf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26679
      },
      "nvd": {
        "published": "2026-07-08T18:16:34.963",
        "lastModified": "2026-07-09T20:39:31.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59937",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Repeated malformed cross-reference streams repeatedly invoke expensive PDF recovery work without an effective work bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-55h5-xmcq-c37v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/py-pdf/pypdf/pull/3887",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/py-pdf/pypdf/commit/b5fc5aa714f4b696fb9b1deaa35a9e4a4eb50dae",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/py-pdf/pypdf/releases/tag/6.14.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 277,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59938",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.127Z",
      "date_published": "2026-07-08T17:24:29.959Z",
      "date_updated": "2026-07-09T13:58:17.678Z",
      "publisher": "GitHub_M",
      "title": "pypdf: Possible large memory usage for wrong image dimensions",
      "affected": {
        "vendors": [
          "py-pdf"
        ],
        "products": [
          {
            "vendor": "py-pdf",
            "product": "pypdf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00303,
        "percentile": 0.2264
      },
      "nvd": {
        "published": "2026-07-08T18:16:35.097",
        "lastModified": "2026-07-09T20:41:11.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59938",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "pypdf sizes image allocations from attacker-controlled declared dimensions without bounding them to the actual image data.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-5qjq-93h5-hrgp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/py-pdf/pypdf/pull/3888",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/py-pdf/pypdf/commit/c64583be16b8e8763d8777075f8ecbf382014b7a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/py-pdf/pypdf/releases/tag/6.14.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59939",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.127Z",
      "date_published": "2026-07-08T19:34:05.150Z",
      "date_updated": "2026-07-10T14:55:12.554Z",
      "publisher": "GitHub_M",
      "title": "httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling",
      "affected": {
        "vendors": [
          "httplib2"
        ],
        "products": [
          {
            "vendor": "httplib2",
            "product": "httplib2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33677
      },
      "nvd": {
        "published": "2026-07-08T20:16:59.557",
        "lastModified": "2026-07-13T12:31:52.673",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59939",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "httplib2 expands gzip or deflate response bodies without a decompressed-size limit, allowing a small response to consume the client heap.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/httplib2/httplib2/security/advisories/GHSA-j5g9-f88f-gfj3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/httplib2/httplib2/commit/87581ad6cf752fe3da2090c59058261d2d00a427",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/httplib2/httplib2/releases/tag/v0.32.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 466,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59941",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.127Z",
      "date_published": "2026-07-28T20:42:57.010Z",
      "date_updated": "2026-07-29T12:41:45.875Z",
      "publisher": "GitHub_M",
      "title": "Dompdf: Uncontrolled resource consumption based on declared BMP dimensions",
      "affected": {
        "vendors": [
          "dompdf"
        ],
        "products": [
          {
            "vendor": "dompdf",
            "product": "dompdf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00507,
        "percentile": 0.40513
      },
      "nvd": {
        "published": "2026-07-28T21:17:29.003",
        "lastModified": "2026-07-30T16:33:59.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59941",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The BMP converter trusts declared width and height without bounding their product before allocating a full pixel canvas.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dompdf/dompdf/security/advisories/GHSA-8hg6-c449-896m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/commit/7c65e7bbeccf146b2409740405af73949ad129d0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/releases/tag/v3.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 912,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59942",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.128Z",
      "date_published": "2026-07-28T20:41:02.553Z",
      "date_updated": "2026-07-29T14:07:52.931Z",
      "publisher": "GitHub_M",
      "title": "Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps",
      "affected": {
        "vendors": [
          "dompdf"
        ],
        "products": [
          {
            "vendor": "dompdf",
            "product": "dompdf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00395,
        "percentile": 0.32308
      },
      "nvd": {
        "published": "2026-07-28T21:17:29.143",
        "lastModified": "2026-08-04T15:54:55.953",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59942",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Dompdf allocates excessive rendering memory for a huge image after its earlier dimension checks have been bypassed.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dompdf/dompdf/security/advisories/GHSA-f5gf-2cj8-52g2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/commit/7c65e7bbeccf146b2409740405af73949ad129d0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/commit/89164eaabe0bb50c462f0b24f740044ba5fb0f99",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/releases/tag/v3.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1125,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59943",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:20:06.128Z",
      "date_published": "2026-07-28T20:19:22.746Z",
      "date_updated": "2026-07-29T12:37:56.940Z",
      "publisher": "GitHub_M",
      "title": "Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem",
      "affected": {
        "vendors": [
          "dompdf"
        ],
        "products": [
          {
            "vendor": "dompdf",
            "product": "dompdf"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00308,
        "percentile": 0.23177
      },
      "nvd": {
        "published": "2026-07-28T21:17:29.280",
        "lastModified": "2026-08-04T15:21:31.393",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59943",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dompdf returns observably different results for existing and absent file URLs embedded in an SVG, creating a filesystem-existence oracle.",
        "basis": [
          "CNA",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dompdf/dompdf/security/advisories/GHSA-j8qw-6jw8-r297",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/commit/6a58996865db05d8fede748507e50ac4b8c5bfd0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/dompdf/dompdf/releases/tag/v3.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 687,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59946",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:49:15.607Z",
      "date_published": "2026-07-08T19:32:38.089Z",
      "date_updated": "2026-07-09T14:41:23.436Z",
      "publisher": "GitHub_M",
      "title": "Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files",
      "affected": {
        "vendors": [
          "composer"
        ],
        "products": [
          {
            "vendor": "composer",
            "product": "composer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03974
      },
      "nvd": {
        "published": "2026-07-08T20:16:59.707",
        "lastModified": "2026-07-10T19:14:18.563",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59946",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "composer allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/composer/composer/security/advisories/GHSA-gjfg-22fp-rrxx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/composer/composer/commit/502c6c4f699802d9cf464728b3e8a95674f919a0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/commit/c50b1efd13ebd73f6dca19b31424c5a02bf93cc1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/releases/tag/2.10.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/releases/tag/2.2.29",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 408,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59947",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:49:15.607Z",
      "date_published": "2026-07-08T19:33:56.009Z",
      "date_updated": "2026-07-09T14:01:42.612Z",
      "publisher": "GitHub_M",
      "title": "Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)",
      "affected": {
        "vendors": [
          "composer"
        ],
        "products": [
          {
            "vendor": "composer",
            "product": "composer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02146
      },
      "nvd": {
        "published": "2026-07-08T20:16:59.843",
        "lastModified": "2026-07-10T19:10:59.333",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59947",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Composer's verbose logging sanitizers miss a credential stored in the URL username slot and print that reusable secret.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/composer/composer/security/advisories/GHSA-g6xq-892h-64w3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/composer/composer/commit/6bd66874ae523ecb69aca5964487a0cdfda03ef8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/commit/8887ad76fbd830cb1861a2b1fd8ead78ed1fa1ec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/releases/tag/2.10.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/releases/tag/2.2.29",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 453,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59948",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:49:15.607Z",
      "date_published": "2026-07-08T19:33:48.414Z",
      "date_updated": "2026-07-09T14:32:07.719Z",
      "publisher": "GitHub_M",
      "title": "Composer: Arbitrary file write outside vendor via malicious transitive package name",
      "affected": {
        "vendors": [
          "composer"
        ],
        "products": [
          {
            "vendor": "composer",
            "product": "composer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03602
      },
      "nvd": {
        "published": "2026-07-08T20:16:59.980",
        "lastModified": "2026-07-10T19:14:18.563",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59948",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Composer accepts an invalid package name from an untrusted repository and uses it in install paths, allowing writes outside the vendor directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/composer/composer/security/advisories/GHSA-499r-g7pc-vmp9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/composer/composer/commit/502c6c4f699802d9cf464728b3e8a95674f919a0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/commit/c50b1efd13ebd73f6dca19b31424c5a02bf93cc1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/releases/tag/2.10.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/composer/composer/releases/tag/2.2.29",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 498,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-59950",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:49:15.607Z",
      "date_published": "2026-07-15T20:08:54.095Z",
      "date_updated": "2026-07-17T12:28:19.431Z",
      "publisher": "GitHub_M",
      "title": "MCP Python SDK: WebSocket server transport does not support Host/Origin validation",
      "affected": {
        "vendors": [
          "modelcontextprotocol"
        ],
        "products": [
          {
            "vendor": "modelcontextprotocol",
            "product": "python-sdk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1385",
          "name": "Missing Origin Validation in WebSockets",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04609
      },
      "nvd": {
        "published": "2026-07-15T21:16:55.683",
        "lastModified": "2026-07-17T18:07:38.087",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59950",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WebSocket transport accepts the Host and Origin headers without validating that they identify an allowed peer.",
        "basis": [
          "CNA",
          "CWE-346",
          "CWE-1385"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-vj7q-gjh5-988w",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/pull/2992",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/commit/777b8d06710c140e3606b0d4598e2aa48546c266",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.28.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 413,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59952",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:49:15.607Z",
      "date_published": "2026-07-30T00:10:32.598Z",
      "date_updated": "2026-07-30T14:42:29.575Z",
      "publisher": "GitHub_M",
      "title": "Valibot: record() issue paths can make flatten() throw for inherited Object property names",
      "affected": {
        "vendors": [
          "open-circle"
        ],
        "products": [
          {
            "vendor": "open-circle",
            "product": "valibot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-755",
          "name": "Improper Handling of Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00524,
        "percentile": 0.41543
      },
      "nvd": {
        "published": "2026-07-30T01:17:06.840",
        "lastModified": "2026-07-30T20:07:01.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59952",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Valibot flatten resolves attacker-controlled error keys through Object.prototype and calls push on an inherited function instead of an error array.",
        "basis": [
          "CNA",
          "CWE-755"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/open-circle/valibot/security/advisories/GHSA-5qjj-4xww-7phc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/open-circle/valibot/pull/1522",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-circle/valibot/commit/1bd01c304657cd0809cc92694360b6cc60f700bf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/open-circle/valibot/releases/tag/v1.4.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1126,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59954",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:49:15.607Z",
      "date_published": "2026-07-15T16:27:48.825Z",
      "date_updated": "2026-07-15T17:28:40.310Z",
      "publisher": "GitHub_M",
      "title": "Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching",
      "affected": {
        "vendors": [
          "apolloconfig"
        ],
        "products": [
          {
            "vendor": "apolloconfig",
            "product": "apollo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00409,
        "percentile": 0.33627
      },
      "nvd": {
        "published": "2026-07-15T17:16:50.960",
        "lastModified": "2026-07-15T18:16:49.287",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59954",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Apollo authenticates one noncanonical appId representation while a downstream lookup canonicalizes it to a different application's configuration.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apolloconfig/apollo/security/advisories/GHSA-4w3q-qpfq-v992",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/apolloconfig/apollo/commit/310809d557e01c6803051736cd525e333ffe00ec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/apolloconfig/apollo/releases/tag/v2.5.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 609,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59955",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-07T18:49:15.607Z",
      "date_published": "2026-07-15T16:26:05.005Z",
      "date_updated": "2026-07-15T18:11:39.238Z",
      "publisher": "GitHub_M",
      "title": "Apollo ConfigService access key authentication bypass via raw config file appId parsing",
      "affected": {
        "vendors": [
          "apolloconfig"
        ],
        "products": [
          {
            "vendor": "apolloconfig",
            "product": "apollo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00409,
        "percentile": 0.33627
      },
      "nvd": {
        "published": "2026-07-15T17:16:51.087",
        "lastModified": "2026-07-15T19:18:34.287",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-59955",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Apollo parses the literal raw path segment as the appId during AccessKey verification, so the signature check is detached from the actual appId whose configuration is returned.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apolloconfig/apollo/security/advisories/GHSA-h4pc-58cc-hc95",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/apolloconfig/apollo/commit/310809d557e01c6803051736cd525e333ffe00ec",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/apolloconfig/apollo/releases/tag/v2.5.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 631,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59995",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T00:04:49.591Z",
      "date_published": "2026-07-08T00:04:49.995Z",
      "date_updated": "2026-07-08T12:52:35.500Z",
      "publisher": "mitre",
      "title": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
      "affected": {
        "vendors": [
          "OpenBSD"
        ],
        "products": [
          {
            "vendor": "OpenBSD",
            "product": "OpenSSH"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16452
      },
      "nvd": {
        "published": "2026-07-08T01:16:28.390",
        "lastModified": "2026-07-09T17:14:47.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59995",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/06/5",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Release Notes"
          ]
        },
        {
          "url": "https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2",
          "host": "marc.info",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://www.openssh.org/releasenotes.html#10.4p1",
          "host": "www.openssh.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 159,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59996",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T00:07:07.370Z",
      "date_published": "2026-07-08T00:07:07.759Z",
      "date_updated": "2026-07-08T13:03:41.694Z",
      "publisher": "mitre",
      "title": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
      "affected": {
        "vendors": [
          "OpenBSD"
        ],
        "products": [
          {
            "vendor": "OpenBSD",
            "product": "OpenSSH"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16452
      },
      "nvd": {
        "published": "2026-07-08T01:16:28.557",
        "lastModified": "2026-07-09T17:14:27.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59996",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "scp fails to constrain a remote-to-remote destination path and can place the received file in the intended directory's parent.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/06/5",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Release Notes"
          ]
        },
        {
          "url": "https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2",
          "host": "marc.info",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://www.openssh.org/releasenotes.html#10.4p1",
          "host": "www.openssh.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59997",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T00:09:04.544Z",
      "date_published": "2026-07-08T00:09:04.920Z",
      "date_updated": "2026-07-08T12:52:08.430Z",
      "publisher": "mitre",
      "title": "internal-sftp in sshd in OpenSSH before 10.",
      "affected": {
        "vendors": [
          "OpenBSD"
        ],
        "products": [
          {
            "vendor": "OpenBSD",
            "product": "OpenSSH"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07141
      },
      "nvd": {
        "published": "2026-07-08T01:16:28.727",
        "lastModified": "2026-07-09T17:11:49.987",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59997",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "internal-sftp stops processing after nine command-line arguments, silently ignoring later options that may carry required connection restrictions.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/06/5",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Release Notes"
          ]
        },
        {
          "url": "https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2",
          "host": "marc.info",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://www.openssh.org/releasenotes.html#10.4p1",
          "host": "www.openssh.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59998",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T00:11:04.817Z",
      "date_published": "2026-07-08T00:11:05.183Z",
      "date_updated": "2026-07-08T13:48:01.134Z",
      "publisher": "mitre",
      "title": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
      "affected": {
        "vendors": [
          "OpenBSD"
        ],
        "products": [
          {
            "vendor": "OpenBSD",
            "product": "OpenSSH"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-573",
          "name": "Improper Following of Specification by Caller",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.7000000000000002,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07713
      },
      "nvd": {
        "published": "2026-07-08T01:16:28.870",
        "lastModified": "2026-07-09T16:55:00.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59998",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "OpenSSH silently ignores GSSAPIStrictAcceptorCheck in Windows Active Directory deployments, but the public record does not disclose the configuration path that defeats it.",
        "basis": [
          "CNA",
          "CWE-573"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/06/5",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Release Notes"
          ]
        },
        {
          "url": "https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2",
          "host": "marc.info",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://www.openssh.org/releasenotes.html#10.4p1",
          "host": "www.openssh.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-59999",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T00:13:08.024Z",
      "date_published": "2026-07-08T00:13:08.397Z",
      "date_updated": "2026-07-08T13:07:51.541Z",
      "publisher": "mitre",
      "title": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
      "affected": {
        "vendors": [
          "OpenBSD"
        ],
        "products": [
          {
            "vendor": "OpenBSD",
            "product": "OpenSSH"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-348",
          "name": "Use of Less Trusted Source",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 1.5999999999999996,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05567
      },
      "nvd": {
        "published": "2026-07-08T01:16:29.010",
        "lastModified": "2026-07-09T16:52:29.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-59999",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenSSH applies PermitTunnel despite DisableForwarding being configured to take precedence, violating the intended configuration priority.",
        "basis": [
          "CNA",
          "CWE-348"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/06/5",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Release Notes"
          ]
        },
        {
          "url": "https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2",
          "host": "marc.info",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://www.openssh.org/releasenotes.html#10.4p1",
          "host": "www.openssh.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 121,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60000",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T00:14:30.824Z",
      "date_published": "2026-07-08T00:14:31.230Z",
      "date_updated": "2026-07-08T13:06:54.687Z",
      "publisher": "mitre",
      "title": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
      "affected": {
        "vendors": [
          "OpenBSD"
        ],
        "products": [
          {
            "vendor": "OpenBSD",
            "product": "OpenSSH"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36262
      },
      "nvd": {
        "published": "2026-07-08T01:16:29.153",
        "lastModified": "2026-07-09T16:51:43.727",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60000",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenSSH mishandles MaxAuthTries for GSSAPI and permits excessive authentication work without the configured attempt bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/06/5",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Release Notes"
          ]
        },
        {
          "url": "https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2",
          "host": "marc.info",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://www.openssh.org/releasenotes.html#10.4p1",
          "host": "www.openssh.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60001",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T00:16:15.139Z",
      "date_published": "2026-07-08T00:16:15.497Z",
      "date_updated": "2026-07-08T13:03:51.222Z",
      "publisher": "mitre",
      "title": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
      "affected": {
        "vendors": [
          "OpenBSD"
        ],
        "products": [
          {
            "vendor": "OpenBSD",
            "product": "OpenSSH"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21301
      },
      "nvd": {
        "published": "2026-07-08T01:16:29.290",
        "lastModified": "2026-07-09T16:37:12.743",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60001",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "OpenSSH does not consistently enforce the minimum authentication delay intended to reduce credential-guessing information.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/06/5",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Release Notes"
          ]
        },
        {
          "url": "https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2",
          "host": "marc.info",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://www.openssh.org/releasenotes.html#10.4p1",
          "host": "www.openssh.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60002",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T00:17:32.675Z",
      "date_published": "2026-07-08T00:17:33.058Z",
      "date_updated": "2026-07-08T13:02:27.583Z",
      "publisher": "mitre",
      "title": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
      "affected": {
        "vendors": [
          "OpenBSD"
        ],
        "products": [
          {
            "vendor": "OpenBSD",
            "product": "OpenSSH"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 1.7000000000000002,
      "epss": {
        "score": 0.003,
        "percentile": 0.22259
      },
      "nvd": {
        "published": "2026-07-08T01:16:29.430",
        "lastModified": "2026-07-09T16:36:21.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60002",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An OpenSSH client can retain and reuse freed host-key state when the server changes keys during re-exchange.",
        "basis": [
          "CNA record",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/06/5",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Release Notes"
          ]
        },
        {
          "url": "https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2",
          "host": "marc.info",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://www.openssh.org/releasenotes.html#10.4p1",
          "host": "www.openssh.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60005",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:49:43.059Z",
      "date_published": "2026-07-15T15:04:21.040Z",
      "date_updated": "2026-07-15T15:41:06.279Z",
      "publisher": "f5",
      "title": "NGINX ngx_http_slice_module vulnerability",
      "affected": {
        "vendors": [
          "F5"
        ],
        "products": [
          {
            "vendor": "F5",
            "product": "NGINX Plus"
          },
          {
            "vendor": "F5",
            "product": "NGINX Open Source"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Primary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.0071,
        "percentile": 0.49984
      },
      "nvd": {
        "published": "2026-07-15T16:16:49.820",
        "lastModified": "2026-07-15T16:23:03.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60005",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "NGINX Plus uses an incompletely initialized resource before all security-relevant fields are established.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://my.f5.com/manage/s/article/K000162100",
          "host": "my.f5.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 833,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60024",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T05:31:35.889Z",
      "date_published": "2026-07-17T15:47:09.871Z",
      "date_updated": "2026-07-23T14:59:25.448Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0",
      "affected": {
        "vendors": [
          "joomdonation.com"
        ],
        "products": [
          {
            "vendor": "joomdonation.com",
            "product": "Events Booking extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22642
      },
      "nvd": {
        "published": "2026-07-17T16:17:16.113",
        "lastModified": "2026-07-23T16:17:30.153",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60024",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Events Booking ships with a default configuration that permits unauthenticated media uploads.",
        "basis": [
          "CNA",
          "CWE-1188"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://joomdonation.com/joomla-extensions/events-booking-joomla-events-registration.html",
          "host": "joomdonation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60025",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T05:31:35.889Z",
      "date_published": "2026-07-17T15:44:32.443Z",
      "date_updated": "2026-07-23T14:55:59.397Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0",
      "affected": {
        "vendors": [
          "joomdonation.com"
        ],
        "products": [
          {
            "vendor": "joomdonation.com",
            "product": "Events Booking extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03058
      },
      "nvd": {
        "published": "2026-07-17T16:17:16.230",
        "lastModified": "2026-07-23T16:17:30.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60025",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Events Booking upload endpoint accepts a cross-site request without a session-bound anti-CSRF token; the title's user-enumeration label does not match that described mechanism.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://joomdonation.com/joomla-extensions/events-booking-joomla-events-registration.html",
          "host": "joomdonation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60026",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T05:31:35.889Z",
      "date_published": "2026-07-20T18:11:57.386Z",
      "date_updated": "2026-07-23T14:58:19.690Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1",
      "affected": {
        "vendors": [
          "themexpert.com"
        ],
        "products": [
          {
            "vendor": "themexpert.com",
            "product": "Quix Page Builder Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.2351
      },
      "nvd": {
        "published": "2026-07-20T19:17:26.920",
        "lastModified": "2026-07-23T16:17:30.423",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60026",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Quix writes builder-controlled PHP tags into a cached view and later includes that cache file as executable PHP.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.themexpert.com/quix-pagebuilder",
          "host": "www.themexpert.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 364,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60027",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T05:31:35.889Z",
      "date_published": "2026-07-20T18:14:30.884Z",
      "date_updated": "2026-07-23T15:01:40.243Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1",
      "affected": {
        "vendors": [
          "themexpert.com"
        ],
        "products": [
          {
            "vendor": "themexpert.com",
            "product": "Quix Page Builder Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27267
      },
      "nvd": {
        "published": "2026-07-20T19:17:27.060",
        "lastModified": "2026-07-23T16:17:30.527",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60027",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The published Quix form path accepts traversal segments and reads the resolved file outside the intended page-builder directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.themexpert.com/quix-pagebuilder",
          "host": "www.themexpert.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 359,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60028",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T05:31:35.889Z",
      "date_published": "2026-07-20T18:09:33.059Z",
      "date_updated": "2026-07-23T14:55:21.661Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1",
      "affected": {
        "vendors": [
          "themexpert.com"
        ],
        "products": [
          {
            "vendor": "themexpert.com",
            "product": "Quix Page Builder Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.15996
      },
      "nvd": {
        "published": "2026-07-20T19:17:27.177",
        "lastModified": "2026-07-23T16:17:30.627",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60028",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Quix Page Builder Pro extension for Joomla rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.themexpert.com/quix-pagebuilder",
          "host": "www.themexpert.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60029",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T05:31:35.889Z",
      "date_published": "2026-07-20T18:11:58.374Z",
      "date_updated": "2026-07-23T14:58:21.542Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1",
      "affected": {
        "vendors": [
          "themexpert.com"
        ],
        "products": [
          {
            "vendor": "themexpert.com",
            "product": "Quix Page Builder Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.15996
      },
      "nvd": {
        "published": "2026-07-20T19:17:27.297",
        "lastModified": "2026-07-23T16:17:30.737",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60029",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted bytes are embedded in an interpreter context without the required encoding or parameterization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.themexpert.com/quix-pagebuilder",
          "host": "www.themexpert.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60030",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T05:31:35.889Z",
      "date_published": "2026-07-20T18:11:08.106Z",
      "date_updated": "2026-07-23T14:57:16.645Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1",
      "affected": {
        "vendors": [
          "themexpert.com"
        ],
        "products": [
          {
            "vendor": "themexpert.com",
            "product": "Quix Page Builder Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15114
      },
      "nvd": {
        "published": "2026-07-20T19:17:27.417",
        "lastModified": "2026-07-23T16:17:30.853",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60030",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Quix Page Builder Pro extension for Joomla operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.themexpert.com/quix-pagebuilder",
          "host": "www.themexpert.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60031",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T05:31:35.889Z",
      "date_published": "2026-07-20T18:12:00.724Z",
      "date_updated": "2026-07-23T14:58:26.686Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1",
      "affected": {
        "vendors": [
          "themexpert.com"
        ],
        "products": [
          {
            "vendor": "themexpert.com",
            "product": "Quix Page Builder Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16739
      },
      "nvd": {
        "published": "2026-07-20T19:17:27.543",
        "lastModified": "2026-07-23T16:17:30.977",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60031",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Quix returns raw server exceptions through an AJAX response, disclosing internal error data to the requester.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.themexpert.com/quix-pagebuilder",
          "host": "www.themexpert.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60032",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T05:31:35.890Z",
      "date_published": "2026-07-20T18:09:34.012Z",
      "date_updated": "2026-07-23T14:55:23.506Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0",
      "affected": {
        "vendors": [
          "themexpert.com"
        ],
        "products": [
          {
            "vendor": "themexpert.com",
            "product": "JMedia extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15417
      },
      "nvd": {
        "published": "2026-07-20T19:17:27.660",
        "lastModified": "2026-07-23T16:17:31.090",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60032",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "JMedia permits an authenticated user to upload executable or polyglot files and preserves executable permission bits, allowing the uploaded object to become server-side code.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.themexpert.com/joomla-extensions/joomla-media-manager",
          "host": "www.themexpert.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60033",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T05:31:35.890Z",
      "date_published": "2026-07-20T18:10:37.750Z",
      "date_updated": "2026-07-23T14:56:38.458Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0",
      "affected": {
        "vendors": [
          "themexpert.com"
        ],
        "products": [
          {
            "vendor": "themexpert.com",
            "product": "JMedia extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13801
      },
      "nvd": {
        "published": "2026-07-20T19:17:27.780",
        "lastModified": "2026-07-23T16:17:31.210",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60033",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "JMedia accepts a remote-download URL that can address internal or reserved network destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.themexpert.com/joomla-extensions/joomla-media-manager",
          "host": "www.themexpert.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60034",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T05:31:35.890Z",
      "date_published": "2026-07-20T18:11:53.622Z",
      "date_updated": "2026-07-23T14:58:13.057Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0",
      "affected": {
        "vendors": [
          "themexpert.com"
        ],
        "products": [
          {
            "vendor": "themexpert.com",
            "product": "JMedia extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.15997
      },
      "nvd": {
        "published": "2026-07-20T19:17:27.910",
        "lastModified": "2026-07-23T16:17:31.330",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60034",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.themexpert.com/joomla-extensions/joomla-media-manager",
          "host": "www.themexpert.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 244,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60060",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T02:15:09.033Z",
      "date_published": "2026-07-17T04:13:38.109Z",
      "date_updated": "2026-07-17T13:09:30.703Z",
      "publisher": "jpcert",
      "title": "Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project.",
      "affected": {
        "vendors": [
          "TeraTerm Project"
        ],
        "products": [
          {
            "vendor": "TeraTerm Project",
            "product": "TTSSH2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-130",
          "name": "Improper Handling of Length Parameter Inconsistency",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "3.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07911
      },
      "nvd": {
        "published": "2026-07-17T05:16:41.360",
        "lastModified": "2026-07-17T17:56:08.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60060",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "TTSSH trusts a declared length that is inconsistent with the available message bytes and accesses beyond the received buffer.",
        "basis": [
          "CNA",
          "CWE-130"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://teratermproject.github.io/SA/JVN65294474-en.html",
          "host": "teratermproject.github.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://teratermproject.github.io/SA/JVN65294474.html",
          "host": "teratermproject.github.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jvn.jp/en/jp/JVN65294474/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60062",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:49:43.045Z",
      "date_published": "2026-07-15T14:33:45.486Z",
      "date_updated": "2026-07-15T15:37:18.438Z",
      "publisher": "f5",
      "title": "NGINX Agent Vulnerability",
      "affected": {
        "vendors": [
          "F5"
        ],
        "products": [
          {
            "vendor": "F5",
            "product": "NGINX Agent"
          },
          {
            "vendor": "F5",
            "product": "NGINX Instance Manager"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09673
      },
      "nvd": {
        "published": "2026-07-15T15:16:47.190",
        "lastModified": "2026-07-15T16:23:03.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60062",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An attacker-controlled path or reference can select a file outside the intended storage namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://my.f5.com/manage/s/article/K000161971",
          "host": "my.f5.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 614,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60063",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:00:24.526Z",
      "date_published": "2026-07-16T19:59:16.196Z",
      "date_updated": "2026-07-17T13:25:08.344Z",
      "publisher": "icscert",
      "title": "AutomationDirect Productivity Suite Out-of-bounds Write",
      "affected": {
        "vendors": [
          "AutomationDirect"
        ],
        "products": [
          {
            "vendor": "AutomationDirect",
            "product": "Productivity Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01305
      },
      "nvd": {
        "published": "2026-07-16T20:16:45.953",
        "lastModified": "2026-07-17T18:31:44.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60063",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Productivity Suite writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.automationdirect.com/support/software-downloads",
          "host": "www.automationdirect.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-04",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-04.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60065",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:49:43.065Z",
      "date_published": "2026-07-15T14:33:46.469Z",
      "date_updated": "2026-07-15T15:39:17.208Z",
      "publisher": "f5",
      "title": "NGINX Plus ngx_stream_mqtt_filter_module vulnerability",
      "affected": {
        "vendors": [
          "F5"
        ],
        "products": [
          {
            "vendor": "F5",
            "product": "NGINX Plus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:f5sirt@f5.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18226
      },
      "nvd": {
        "published": "2026-07-15T15:16:47.320",
        "lastModified": "2026-07-15T16:23:03.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60065",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MQTT filter reads beyond a heap buffer while parsing a crafted data-plane request.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://my.f5.com/manage/s/article/K000162101",
          "host": "my.f5.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 600,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60073",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:00:24.541Z",
      "date_published": "2026-07-16T20:22:36.036Z",
      "date_updated": "2026-07-17T13:15:30.223Z",
      "publisher": "icscert",
      "title": "AutomationDirect Productivity Suite Out-of-bounds Read",
      "affected": {
        "vendors": [
          "AutomationDirect"
        ],
        "products": [
          {
            "vendor": "AutomationDirect",
            "product": "Productivity Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00167,
        "percentile": 0.06334
      },
      "nvd": {
        "published": "2026-07-16T21:17:21.773",
        "lastModified": "2026-07-17T18:31:44.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60073",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Productivity Suite trusts a physical attacker's USB data length and reads past the valid buffer into kernel memory.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.automationdirect.com/support/software-downloads",
          "host": "www.automationdirect.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-04",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-04.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60074",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T10:28:02.310Z",
      "date_published": "2026-07-30T13:42:03.068Z",
      "date_updated": "2026-07-31T17:57:36.087Z",
      "publisher": "CPANSec",
      "title": "Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check",
      "affected": {
        "vendors": [
          "SBECK"
        ],
        "products": [
          {
            "vendor": "SBECK",
            "product": "Date::Manip"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1289",
          "name": "Improper Validation of Unsafe Equivalence in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.31498
      },
      "nvd": {
        "published": "2026-07-30T14:17:02.587",
        "lastModified": "2026-07-31T18:17:18.787",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60074",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The date parser accepts Unicode decimal digits under one grammar and then numerically converts them under ASCII-prefix semantics, silently changing the parsed date.",
        "basis": [
          "CNA",
          "CWE-1289"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60074-r1.patch",
          "host": "security.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Base.pm#L602-614",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Date.pm#L1536-1539",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/19",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1398,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60075",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T10:28:02.310Z",
      "date_published": "2026-07-30T13:42:17.896Z",
      "date_updated": "2026-07-31T17:56:04.469Z",
      "publisher": "CPANSec",
      "title": "Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time",
      "affected": {
        "vendors": [
          "SBECK"
        ],
        "products": [
          {
            "vendor": "SBECK",
            "product": "Date::Manip"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.31498
      },
      "nvd": {
        "published": "2026-07-30T14:17:02.710",
        "lastModified": "2026-07-31T18:17:18.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60075",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Date::Manip parser applies a backtracking regular expression to unbounded attacker input, allowing disproportionate CPU work.",
        "basis": [
          "CNA",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60075-r1.patch",
          "host": "security.metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Date.pm#L1811",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Date.pm#L1526",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/20",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1182,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60080",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T11:03:34.462Z",
      "date_published": "2026-07-21T10:54:19.298Z",
      "date_updated": "2026-07-22T16:12:10.640Z",
      "publisher": "apache",
      "title": "Apache Fory: Rust MetaString heap use-after-free",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Fory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00424,
        "percentile": 0.34941
      },
      "nvd": {
        "published": "2026-07-21T12:18:58.697",
        "lastModified": "2026-07-27T13:47:47.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60080",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache Fory's Rust deserializer uses an object after its lifetime ends when processing a crafted payload.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/svnq03f3ls7vsgk8md4hjmmw1z6stbvy",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/21/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T11:45:04.838Z",
      "date_published": "2026-07-14T15:34:35.483Z",
      "date_updated": "2026-07-15T14:03:34.263Z",
      "publisher": "CPANSec",
      "title": "DBI::ProfileData versions before 1.651 for Perl do not limit the path index",
      "affected": {
        "vendors": [
          "HMBRAND"
        ],
        "products": [
          {
            "vendor": "HMBRAND",
            "product": "DBI::ProfileData"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30703
      },
      "nvd": {
        "published": "2026-07-14T16:17:03.647",
        "lastModified": "2026-07-15T14:18:33.300",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60081",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The profile parser uses an attacker-supplied path index directly to size an array without an upper bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ww49-w4mv-jrr4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://metacpan.org/release/HMBRAND/DBI-1.651/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/perl5-dbi/dbi/commit/6764e755e83ee1ebb1b40760e5b53eb50960bd7a.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/14/14",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 267,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T11:45:04.838Z",
      "date_published": "2026-07-14T15:35:00.730Z",
      "date_updated": "2026-07-15T14:08:02.262Z",
      "publisher": "CPANSec",
      "title": "DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row",
      "affected": {
        "vendors": [
          "HMBRAND"
        ],
        "products": [
          {
            "vendor": "HMBRAND",
            "product": "DBI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.31434
      },
      "nvd": {
        "published": "2026-07-14T16:17:03.750",
        "lastModified": "2026-07-15T15:16:47.443",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60082",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DBI uses an attacker-influenced length or index without proving it lies inside the backing object, allowing a read beyond valid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/perl5-dbi/dbi/security/advisories/GHSA-rwhc-hhmv-cjvg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://metacpan.org/release/HMBRAND/DBI-1.651/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/perl5-dbi/dbi/commit/397868704291bbf0989b97e2c0661189890653e2.patch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/14/13",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 339,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T12:14:28.344Z",
      "date_published": "2026-07-15T11:25:36.195Z",
      "date_updated": "2026-07-15T12:40:35.347Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-273",
          "name": "Improper Check for Dropped Privileges",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15344
      },
      "nvd": {
        "published": "2026-07-15T12:18:17.933",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60085",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The default subprocess sandbox advertises blocked-command, path, import, subprocess, and write policies but does not enforce any of them.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-273"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5r6c-gj4g-r697",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-unenforced-security-policy-in-subprocess-sandbox",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 408,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60086",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T12:14:28.344Z",
      "date_published": "2026-07-10T13:58:02.299Z",
      "date_updated": "2026-07-14T01:46:54.788Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Prompt Injection Defense Bypass",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12604
      },
      "nvd": {
        "published": "2026-07-10T15:16:49.417",
        "lastModified": "2026-07-14T02:16:57.743",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60086",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PraisonAI blocks prompt injection only when three detector families raise the score to critical, allowing high-rated one- or two-vector prompts to reach the model.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4r3p-w3mc-5v34",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-prompt-injection-defense-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 369,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60087",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T12:14:28.344Z",
      "date_published": "2026-07-15T11:25:36.892Z",
      "date_updated": "2026-07-15T13:48:59.749Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 1.6.78 Tool Approval Cache Bypass",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08767
      },
      "nvd": {
        "published": "2026-07-15T12:18:18.083",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60087",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Tool approval is bound only to the tool name, so a later call with different arguments or an unauthorized action inherits the approval.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-29r9-67vg-qj56",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-tool-approval-cache-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60088",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T12:14:28.344Z",
      "date_published": "2026-07-11T13:00:59.744Z",
      "date_updated": "2026-07-13T17:26:03.291Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Path Traversal via Custom Commands",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04391
      },
      "nvd": {
        "published": "2026-07-11T14:16:22.210",
        "lastModified": "2026-07-13T18:16:29.003",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60088",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PraisonAI expands relative or absolute file references in project command templates without confining them to the workspace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-xpx6-x8c2-mw5w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/3aa9cbc2bd49c23a32be0a89a5e620d13d843eab",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-path-traversal-via-custom-commands",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60089",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T12:14:28.344Z",
      "date_published": "2026-07-10T13:58:02.968Z",
      "date_updated": "2026-07-10T15:03:45.373Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 1.6.78 Path Traversal via config.toml",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03892
      },
      "nvd": {
        "published": "2026-07-10T15:16:49.567",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60089",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PraisonAI automatically selects and loads a project-local configuration file without constraining which defaults may enter a newly constructed agent.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qjw5-xwrp-xwpq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/3aa9cbc2bd49c23a32be0a89a5e620d13d843eab",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-path-traversal-via-config-toml",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60090",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T12:14:28.344Z",
      "date_published": "2026-07-11T13:01:00.392Z",
      "date_updated": "2026-07-14T14:34:18.574Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 SQL/CQL Injection via vector dimension",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.0041,
        "percentile": 0.33748
      },
      "nvd": {
        "published": "2026-07-11T14:16:22.353",
        "lastModified": "2026-07-14T15:17:07.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60090",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-wf65-4jjx-q444",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/3aa9cbc2bd49c23a32be0a89a5e620d13d843eab",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-sql-cql-injection-via-vector-dimension",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 578,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60091",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T12:14:28.344Z",
      "date_published": "2026-07-10T13:58:03.638Z",
      "date_updated": "2026-07-10T17:00:48.794Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07793
      },
      "nvd": {
        "published": "2026-07-10T15:16:49.700",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60091",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The webhook_url parameter is validated at request time but re-resolved at connection time, allowing attackers to use DNS rebinding to reach internal services with a blind SSRF attack.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4w49-gwv8-fpjg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-unauthenticated-ssrf-via-webhook-url",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60092",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T12:14:28.345Z",
      "date_published": "2026-07-08T13:51:30.509Z",
      "date_updated": "2026-07-14T22:03:29.271Z",
      "publisher": "VulnCheck",
      "title": "AVideo - Stored Cross-Site Scripting via Unescaped User-Agent in Participants Panel",
      "affected": {
        "vendors": [
          "AVideo"
        ],
        "products": [
          {
            "vendor": "AVideo",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.002,
        "percentile": 0.09996
      },
      "nvd": {
        "published": "2026-07-08T14:17:22.370",
        "lastModified": "2026-07-10T18:22:49.657",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60092",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Meet plugin stores a raw User-Agent and later emits it into an administrative HTML view without output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-7cqp-7cfv-6c3q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/WWBN/AVideo/commit/e8d6119f3cb1b849149906efeb0a41fc024f59f8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/avideo-stored-cross-site-scripting-via-unescaped-user-agent-in-participants-panel",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 892,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-60094",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.029Z",
      "date_published": "2026-07-09T13:25:32.439Z",
      "date_updated": "2026-07-09T14:43:18.397Z",
      "publisher": "VulnCheck",
      "title": "Vinchin Backup & Recovery 9.0.0.86562 Heap Buffer Overflow via agentlink_server",
      "affected": {
        "vendors": [
          "Vinchin"
        ],
        "products": [
          {
            "vendor": "Vinchin",
            "product": "Backup & Recovery 9.0"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00411,
        "percentile": 0.33805
      },
      "nvd": {
        "published": "2026-07-09T14:16:35.247",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60094",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The agentlink service passes an unchecked packet body_len to recv() for a smaller heap buffer, allowing a remote packet to overrun the allocation.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code-white.com/public-vulnerability-list/",
          "host": "code-white.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "https://www.vinchin.com/news/vinchin-backup-recovery-9-0.html",
          "host": "www.vinchin.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/vinchin-backup-recovery-heap-buffer-overflow-via-agentlink-server",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60095",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.029Z",
      "date_published": "2026-07-09T13:26:03.424Z",
      "date_updated": "2026-07-09T13:37:55.073Z",
      "publisher": "VulnCheck",
      "title": "Vinchin Backup & Recovery 9.0.0.86562 Stack Buffer Overflow via ModuleHandShake",
      "affected": {
        "vendors": [
          "Vinchin"
        ],
        "products": [
          {
            "vendor": "Vinchin",
            "product": "Backup & Recovery 9.0"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00463,
        "percentile": 0.37813
      },
      "nvd": {
        "published": "2026-07-09T14:16:35.390",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60095",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is copied beyond the boundary of a stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code-white.com/public-vulnerability-list/",
          "host": "code-white.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.vinchin.com/news/vinchin-backup-recovery-9-0.html",
          "host": "www.vinchin.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/vinchin-backup-recovery-stack-buffer-overflow-via-modulehandshake",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60102",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.030Z",
      "date_published": "2026-07-08T16:25:19.153Z",
      "date_updated": "2026-07-14T22:03:29.942Z",
      "publisher": "VulnCheck",
      "title": "Horde VFS < 3.0.1 OS Command Injection via Horde_Vfs_Smb Driver",
      "affected": {
        "vendors": [
          "horde"
        ],
        "products": [
          {
            "vendor": "horde",
            "product": "Vfs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.01761,
        "percentile": 0.75797
      },
      "nvd": {
        "published": "2026-07-08T17:17:28.997",
        "lastModified": "2026-07-14T23:17:34.847",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60102",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value reaches operating-system command construction in Vfs without separation from command or argument syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/horde/Vfs/releases/tag/v3.0.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/horde/Vfs/pull/10",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/horde/Vfs/commit/41f74b4acfc144e09013d04dd121e0a5da808361",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/horde-vfs-os-command-injection-via-horde-vfs-smb-driver",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 681,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.030Z",
      "date_published": "2026-07-13T17:44:14.051Z",
      "date_updated": "2026-07-15T19:06:31.453Z",
      "publisher": "VulnCheck",
      "title": "Blender 3.0.0 - 5.1.2 Out-of-Bounds Read via crafted .blend SDNA block",
      "affected": {
        "vendors": [
          "blender"
        ],
        "products": [
          {
            "vendor": "blender",
            "product": "blender"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01932
      },
      "nvd": {
        "published": "2026-07-13T18:16:29.353",
        "lastModified": "2026-07-15T19:18:35.747",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60103",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Blender uses a signed SDNA member_index as an array index without bounds validation and reads beyond the members allocation.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://projects.blender.org/blender/blender/pulls/161273",
          "host": "projects.blender.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://projects.blender.org/blender/blender/commit/968972a918b5ed2d534295b639c54449d7de11cd",
          "host": "projects.blender.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/blender-out-of-bounds-read-via-crafted-blend-sdna-block",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60104",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.030Z",
      "date_published": "2026-07-08T19:34:49.127Z",
      "date_updated": "2026-07-14T22:03:31.357Z",
      "publisher": "VulnCheck",
      "title": "Bitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request",
      "affected": {
        "vendors": [
          "bitwarden"
        ],
        "products": [
          {
            "vendor": "bitwarden",
            "product": "server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13278
      },
      "nvd": {
        "published": "2026-07-08T20:17:00.413",
        "lastModified": "2026-07-20T14:34:32.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60104",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An email body is accepted without binding the protected action to the authenticated caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://sanjokkarki.com.np/blog/bitwarden-vault-key-heist",
          "host": "sanjokkarki.com.np",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/bitwarden/server/releases#release-v2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/bitwarden/server/pull/7615",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/bitwarden/server/commit/dcf4c486b2b5bedecc03a48b427243328cc74a9a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/bitwarden-server-authorization-bypass-via-admin-auth-request",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 502,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60105",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.030Z",
      "date_published": "2026-07-08T21:02:37.204Z",
      "date_updated": "2026-07-14T22:03:32.053Z",
      "publisher": "VulnCheck",
      "title": "Monsta FTP < 2.14.5 SSRF via IPv4-Mapped IPv6 Address Bypass",
      "affected": {
        "vendors": [
          "Monsta Limited of New Zealand"
        ],
        "products": [
          {
            "vendor": "Monsta Limited of New Zealand",
            "product": "Monsta FTP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00474,
        "percentile": 0.38503
      },
      "nvd": {
        "published": "2026-07-08T21:16:54.813",
        "lastModified": "2026-07-14T16:17:03.853",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60105",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SSRF blocklist does not recognize IPv4 embedded in an IPv4-mapped IPv6 address before the server fetches that destination.",
        "basis": [
          "CNA record",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.vulncheck.com/blog/monsta-ftp-ssrf-ipv6-blocklist-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.monstaftp.com/notes/",
          "host": "www.monstaftp.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/monsta-ftp-ssrf-via-ipv4-mapped-ipv6-address-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 630,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60108",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.030Z",
      "date_published": "2026-07-09T14:16:57.988Z",
      "date_updated": "2026-07-14T22:03:32.780Z",
      "publisher": "VulnCheck",
      "title": "Zeek < 8.0.9 Uncontrolled Memory Consumption DoS via FTP Analyzer",
      "affected": {
        "vendors": [
          "zeek"
        ],
        "products": [
          {
            "vendor": "zeek",
            "product": "zeek"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00436,
        "percentile": 0.35892
      },
      "nvd": {
        "published": "2026-07-09T15:16:41.627",
        "lastModified": "2026-07-14T23:17:35.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60108",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "zeek allocates or queues attacker-driven work without a per-request or per-connection limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zeek/zeek/releases/tag/v8.0.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/zeek/zeek/commit/93ff6950a90cfa9d00c1062cde429313a0402a01",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/zeek-uncontrolled-memory-consumption-dos-via-ftp-analyzer",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60109",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.030Z",
      "date_published": "2026-07-09T14:19:17.970Z",
      "date_updated": "2026-07-14T22:03:33.470Z",
      "publisher": "VulnCheck",
      "title": "Zeek < 8.0.9 Null Pointer Dereference DoS via Kerberos KRB_ERROR Parsing",
      "affected": {
        "vendors": [
          "zeek"
        ],
        "products": [
          {
            "vendor": "zeek",
            "product": "zeek"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00502,
        "percentile": 0.40184
      },
      "nvd": {
        "published": "2026-07-09T15:16:41.757",
        "lastModified": "2026-07-14T23:17:35.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60109",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A Kerberos parser and analyzer choose different PA-DATA arms, leaving pa_data_element uninitialized before it is dereferenced.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zeek/zeek/releases/tag/v8.0.9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/zeek/zeek/commit/c82e3c734893d932e94310aec0dbeb1ffcea169d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/zeek-null-pointer-dereference-dos-via-kerberos-krb-error-parsing",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60112",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.031Z",
      "date_published": "2026-07-29T15:35:44.966Z",
      "date_updated": "2026-07-29T17:57:58.293Z",
      "publisher": "VulnCheck",
      "title": "AIT-GUI < 2.5.1 Missing Authentication via Sessions.create()",
      "affected": {
        "vendors": [
          "NASA-AMMOS"
        ],
        "products": [
          {
            "vendor": "NASA-AMMOS",
            "product": "AIT-GUI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00408,
        "percentile": 0.33592
      },
      "nvd": {
        "published": "2026-07-29T16:17:55.413",
        "lastModified": "2026-07-30T20:10:04.770",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60112",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AIT-GUI Sessions.create issues a valid session without credentials, and handle_cmd accepts that session to forward arbitrary commands to the command bus.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/NASA-AMMOS/AIT-GUI/releases/tag/2.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/NASA-AMMOS/AIT-GUI/blob/2.5.1/CHANGELOG.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/NASA-AMMOS/AIT-GUI/commit/beb8fc0813eded89f985d3eb9a73535dd327726d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ait-gui-missing-authentication-via-sessions-create",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60113",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.031Z",
      "date_published": "2026-07-29T15:40:26.747Z",
      "date_updated": "2026-07-30T13:54:24.751Z",
      "publisher": "VulnCheck",
      "title": "AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes",
      "affected": {
        "vendors": [
          "NASA-AMMOS"
        ],
        "products": [
          {
            "vendor": "NASA-AMMOS",
            "product": "AIT-DSN"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00408,
        "percentile": 0.33591
      },
      "nvd": {
        "published": "2026-07-29T16:17:55.560",
        "lastModified": "2026-07-30T20:10:04.770",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60113",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable security-sensitive operation is exposed without the authentication step required before invoking it.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/NASA-AMMOS/AIT-DSN/releases/tag/2.2.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/NASA-AMMOS/AIT-DSN/blob/master/CHANGELOG.md#222---2026-07-13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/NASA-AMMOS/AIT-DSN/security/advisories/GHSA-gj83-67wr-82mv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/NASA-AMMOS/AIT-DSN/commit/06d07d1a525602c62c6eaeaeff2544196f430340",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ait-dsn-missing-authentication-via-sle-api-routes",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 511,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60114",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.031Z",
      "date_published": "2026-07-14T14:37:27.894Z",
      "date_updated": "2026-07-14T22:03:34.158Z",
      "publisher": "VulnCheck",
      "title": "Sustainable Irrigation Platform 5.2.16 Path Traversal via JSON Backup Restore",
      "affected": {
        "vendors": [
          "Dan-in-CA"
        ],
        "products": [
          {
            "vendor": "Dan-in-CA",
            "product": "SIP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00369,
        "percentile": 0.29553
      },
      "nvd": {
        "published": "2026-07-14T15:17:08.017",
        "lastModified": "2026-07-16T18:22:05.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60114",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The backup restore process uses unvalidated JSON keys as path components, allowing a crafted backup to write JSON outside the data directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zeroscience.mk/#/advisories/ZSL-2026-5996",
          "host": "www.zeroscience.mk",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/sustainable-irrigation-platform-path-traversal-via-json-backup-restore",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 555,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60118",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.031Z",
      "date_published": "2026-07-14T15:42:31.865Z",
      "date_updated": "2026-07-15T15:42:42.390Z",
      "publisher": "VulnCheck",
      "title": "Hi.Events < 1.11.0 Hidden Ticket Enumeration via Order Creation Endpoint",
      "affected": {
        "vendors": [
          "HiEventsDev"
        ],
        "products": [
          {
            "vendor": "HiEventsDev",
            "product": "Hi.Events"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14486
      },
      "nvd": {
        "published": "2026-07-14T16:17:04.090",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60118",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Hi.Events checks product visibility while listing tickets but not while purchasing by identifier, allowing a public buyer to acquire a hidden ticket.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/HiEventsDev/Hi.Events/releases/tag/v.1.11.0-beta",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/HiEventsDev/Hi.Events/security/advisories/GHSA-2h54-cprv-vj74",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/HiEventsDev/Hi.Events/pull/1259",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/HiEventsDev/Hi.Events/commit/9eec95e6176f500b71bf633986243045ca78cefb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/hi-events-beta-hidden-ticket-enumeration-via-order-creation-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60119",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.031Z",
      "date_published": "2026-07-14T15:44:34.636Z",
      "date_updated": "2026-07-14T22:03:35.556Z",
      "publisher": "VulnCheck",
      "title": "Hi.Events < 1.11.0 XSS via Event Title JSON.stringify Injection",
      "affected": {
        "vendors": [
          "HiEventsDev"
        ],
        "products": [
          {
            "vendor": "HiEventsDev",
            "product": "Hi.Events"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06703
      },
      "nvd": {
        "published": "2026-07-14T16:17:04.250",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60119",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "JSON.stringify output containing </script is embedded in a script element without escaping the closing-tag sequence.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/HiEventsDev/Hi.Events/releases/tag/v.1.11.0-beta",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/HiEventsDev/Hi.Events/security/advisories/GHSA-2ggx-79g6-2jmj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/HiEventsDev/Hi.Events/pull/1260",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/HiEventsDev/Hi.Events/commit/1e36b070771801ed7113255ef7b3a7f271a2a794",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/hi-events-beta-xss-via-event-title-json-stringify-injection",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 650,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60120",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.031Z",
      "date_published": "2026-07-09T20:43:07.388Z",
      "date_updated": "2026-07-14T22:03:36.229Z",
      "publisher": "VulnCheck",
      "title": "Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php",
      "affected": {
        "vendors": [
          "Webkul"
        ],
        "products": [
          {
            "vendor": "Webkul",
            "product": "Bagisto"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10187
      },
      "nvd": {
        "published": "2026-07-09T21:16:56.410",
        "lastModified": "2026-07-14T23:17:35.953",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60120",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Bagisto rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bagisto/bagisto/releases/tag/v2.4.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/bagisto/bagisto/commit/49d0c3fc90dedf8782c45c5979df4f4595d6bb97",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/bagisto-stored-xss-via-csti-in-create-blade-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 540,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60121",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.031Z",
      "date_published": "2026-07-13T13:11:15.443Z",
      "date_updated": "2026-07-28T01:49:50.309Z",
      "publisher": "VulnCheck",
      "title": "Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php",
      "affected": {
        "vendors": [
          "VITEC"
        ],
        "products": [
          {
            "vendor": "VITEC",
            "product": "Flamingo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.01405,
        "percentile": 0.69921
      },
      "nvd": {
        "published": "2026-07-13T14:16:32.067",
        "lastModified": "2026-07-13T19:28:17.967",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60121",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ping endpoint escapes host once, then a wrapper decodes it and interpolates it into a second shell_exec call without escaping.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://damiri.fr/en/cve/CVE-2026-60121",
          "host": "damiri.fr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vitec.com/solutions/iptv-distribution",
          "host": "www.vitec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/vitec-flamingo-unauthenticated-os-command-injection-via-ping-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60122",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:27:53.031Z",
      "date_published": "2026-07-23T19:18:14.138Z",
      "date_updated": "2026-07-28T01:49:51.071Z",
      "publisher": "VulnCheck",
      "title": "gpsd gpsprof Code Injection via SKY.satellites used Field",
      "affected": {
        "vendors": [
          "gpsd"
        ],
        "products": [
          {
            "vendor": "gpsd",
            "product": "gpsd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07088
      },
      "nvd": {
        "published": "2026-07-23T20:17:09.207",
        "lastModified": "2026-07-30T20:04:51.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60122",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gitlab.com/gpsd/gpsd/-/work_items/406",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://gitlab.com/gpsd/gpsd/-/commit/5a9c44a42136b9bb98d460a8a716e9fd344a8d93",
          "host": "gitlab.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gpsd-gpsprof-code-injection-via-sky-satellites-used-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60124",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:30:08.370Z",
      "date_published": "2026-07-08T13:30:14.637Z",
      "date_updated": "2026-07-08T14:36:23.494Z",
      "publisher": "CIRCL",
      "title": "MISP importModule missing authorization allows read-only users to modify events via misp_standard imports",
      "affected": {
        "vendors": [
          "misp"
        ],
        "products": [
          {
            "vendor": "misp",
            "product": "misp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12554
      },
      "nvd": {
        "published": "2026-07-08T14:17:22.510",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60124",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MISP importModule saves misp_standard output into an event without checking that the read-only caller may modify that event.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MISP/MISP/commit/d0725fc34fda256cc57e5a8f0543cd541033e008",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 621,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60125",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T13:36:48.024Z",
      "date_published": "2026-07-08T13:36:53.507Z",
      "date_updated": "2026-07-08T14:31:14.444Z",
      "publisher": "CIRCL",
      "title": "importModule function in MISP ignores per-organisation import module restrictions",
      "affected": {
        "vendors": [
          "misp"
        ],
        "products": [
          {
            "vendor": "misp",
            "product": "misp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:L"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10929
      },
      "nvd": {
        "published": "2026-07-08T14:17:22.640",
        "lastModified": "2026-07-09T16:29:14.203",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60125",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MISP's single-module lookup omits the per-organisation restriction enforced by the module-list path, allowing direct invocation by name.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MISP/MISP/commit/0ed79b4d3177f4b9e44040962161a1a436d2587d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 690,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60134",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T16:04:55.188Z",
      "date_published": "2026-07-24T22:20:20.024Z",
      "date_updated": "2026-07-27T14:30:33.224Z",
      "publisher": "icscert",
      "title": "Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision",
      "affected": {
        "vendors": [
          "Weintek"
        ],
        "products": [
          {
            "vendor": "Weintek",
            "product": "cMT3092X firmware"
          },
          {
            "vendor": "Weintek",
            "product": "EasyWeb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-784",
          "name": "Reliance on Cookies without Validation and Integrity Checking in a Security Decision",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23865
      },
      "nvd": {
        "published": "2026-07-24T23:16:50.890",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60134",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The HMI trusts a caller-modifiable cookie as a privilege indicator without validating it against server-side authorization state.",
        "basis": [
          "CNA",
          "CWE-784"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf",
          "host": "dl.weintek.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-03.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60135",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T16:04:55.177Z",
      "date_published": "2026-07-24T22:06:12.337Z",
      "date_updated": "2026-07-27T14:32:32.622Z",
      "publisher": "icscert",
      "title": "Weintek cMT3092X Incorrect User Management",
      "affected": {
        "vendors": [
          "Weintek"
        ],
        "products": [
          {
            "vendor": "Weintek",
            "product": "cMT3092X firmware"
          },
          {
            "vendor": "Weintek",
            "product": "EasyWeb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-286",
          "name": "Incorrect User Management",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11735
      },
      "nvd": {
        "published": "2026-07-24T23:16:51.037",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60135",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A caller can modify data whose granted access is read-only, but the record does not identify the object, operation, role, or missing authorization check.",
        "basis": [
          "CNA",
          "CWE-286"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf",
          "host": "dl.weintek.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-03.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 74,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60137",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T17:17:24.479Z",
      "date_published": "2026-07-17T19:14:12.159Z",
      "date_updated": "2026-07-29T19:26:43.785Z",
      "publisher": "WPScan",
      "title": "WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query",
      "affected": {
        "vendors": [
          "WordPress"
        ],
        "products": [
          {
            "vendor": "WordPress",
            "product": "WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:contact@wpscan.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 3.1999999999999993,
      "epss": {
        "score": 0.79029,
        "percentile": 0.99559
      },
      "official_kev": {
        "cveID": "CVE-2026-60137",
        "vendorProject": "WordPress",
        "product": "Core",
        "vulnerabilityName": "WordPress Core SQL Injection Vulnerability",
        "dateAdded": "2026-07-21",
        "shortDescription": "WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-08-04",
        "knownRansomwareCampaignUse": "Unknown",
        "notes": "https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-60137",
        "cwes": [
          "CWE-89"
        ]
      },
      "nvd": {
        "published": "2026-07-17T20:17:27.790",
        "lastModified": "2026-07-29T20:17:06.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60137",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "WP_Query previously applied absint only when author__not_in was already an array; scalar input was cast to an array and interpolated into SQL NOT IN, while the fix unconditionally parses an integer ID list before query construction.",
        "basis": [
          "CNA",
          "CWE-89",
          "WordPress GHSA",
          "WordPress release advisory",
          "WordPress fixed source commit"
        ],
        "deepDive": true,
        "notes": "Inspected https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf, https://wordpress.org/news/2026/07/wordpress-7-0-2-release/, and fixed commit https://github.com/WordPress/wordpress-develop/commit/74d37a344cbf28e9187a1a5ca71b33d186bcd333. The source diff in src/wp-includes/class-wp-query.php shows scalar author__not_in values bypassed the array-only absint loop before raw NOT IN construction; the fix applies wp_parse_id_list unconditionally. The separate 6.9+ code-execution chain also requires a REST API batch-route confusion. No reproduction was performed."
      },
      "references": [
        {
          "url": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://wordpress.org/news/2026/07/wordpress-7-0-2-release/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60140",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:00:24.535Z",
      "date_published": "2026-07-16T20:03:14.898Z",
      "date_updated": "2026-07-17T13:45:18.561Z",
      "publisher": "icscert",
      "title": "AutomationDirect Productivity Suite Out-of-bounds Read",
      "affected": {
        "vendors": [
          "AutomationDirect"
        ],
        "products": [
          {
            "vendor": "AutomationDirect",
            "product": "Productivity Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01274
      },
      "nvd": {
        "published": "2026-07-16T20:16:46.110",
        "lastModified": "2026-07-17T18:31:44.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60140",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted IOCTL makes the Productivity Suite driver read beyond a kernel buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.automationdirect.com/support/software-downloads",
          "host": "www.automationdirect.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-04",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-04.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 275,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.514Z",
      "date_published": "2026-07-21T21:33:20.969Z",
      "date_updated": "2026-07-23T17:05:48.836Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Workflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.2174
      },
      "nvd": {
        "published": "2026-07-21T22:17:14.940",
        "lastModified": "2026-07-28T14:08:17.117",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60143",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports unauthenticated read, write, and partial denial-of-service impact in Workflow Notification Mailer but discloses no engineering cause.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 763,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.514Z",
      "date_published": "2026-07-21T21:33:21.305Z",
      "date_updated": "2026-07-23T17:05:38.701Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Workflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00109,
        "percentile": 0.01461
      },
      "nvd": {
        "published": "2026-07-21T22:17:15.050",
        "lastModified": "2026-07-28T14:07:48.623",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60144",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged local Workflow user can modify protected data or disrupt the mailer outside that role's intended authority, but the failing check is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 698,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.514Z",
      "date_published": "2026-07-21T21:33:21.654Z",
      "date_updated": "2026-07-23T17:05:32.239Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00398,
        "percentile": 0.32608
      },
      "nvd": {
        "published": "2026-07-21T22:17:15.167",
        "lastModified": "2026-07-27T14:51:30.553",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60145",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Oracle optimizer record reports a repeatable crash but does not disclose the malformed input, exceptional state, or resource failure.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 679,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60146",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.514Z",
      "date_published": "2026-07-21T21:33:22.017Z",
      "date_updated": "2026-07-23T17:05:22.751Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07613
      },
      "nvd": {
        "published": "2026-07-21T22:17:15.287",
        "lastModified": "2026-07-27T13:24:07.763",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60146",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Access Manager permits unauthorized HTTP actions, but Oracle does not publish the failing Authentication Engine check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 893,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.514Z",
      "date_published": "2026-07-21T21:33:22.374Z",
      "date_updated": "2026-07-23T15:24:57.217Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM for JDK"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM Enterprise Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 10,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18769
      },
      "nvd": {
        "published": "2026-07-21T22:17:15.407",
        "lastModified": "2026-08-03T18:49:46.977",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60147",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1433,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-60149",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.514Z",
      "date_published": "2026-07-21T21:33:22.721Z",
      "date_updated": "2026-07-23T15:20:32.963Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Workflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02608
      },
      "nvd": {
        "published": "2026-07-21T22:17:15.530",
        "lastModified": "2026-07-28T14:02:54.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60149",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60149 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 811,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60150",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.514Z",
      "date_published": "2026-07-21T21:33:23.066Z",
      "date_updated": "2026-07-28T03:56:55.328Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04697
      },
      "nvd": {
        "published": "2026-07-21T22:17:15.650",
        "lastModified": "2026-07-28T05:17:07.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60150",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "VirtualBox grants a low-privilege local user authority sufficient for platform takeover, while Oracle does not disclose the object or privilege check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 545,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60152",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.514Z",
      "date_published": "2026-07-21T21:33:23.397Z",
      "date_updated": "2026-07-23T15:19:04.155Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise PeopleTools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13978
      },
      "nvd": {
        "published": "2026-07-21T22:17:15.760",
        "lastModified": "2026-07-27T19:33:12.150",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60152",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to PeopleSoft Enterprise PeopleTools in its Panel Processor component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 791,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60153",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.514Z",
      "date_published": "2026-07-21T21:33:23.737Z",
      "date_updated": "2026-07-28T03:55:48.228Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37139
      },
      "nvd": {
        "published": "2026-07-21T22:17:15.873",
        "lastModified": "2026-07-28T05:17:07.413",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60153",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The WebLogic console exposes a critical function without the required authentication, although the public record does not name the function or check.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60154",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.515Z",
      "date_published": "2026-07-21T21:33:24.087Z",
      "date_updated": "2026-08-01T03:56:24.003Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Object Library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12845
      },
      "nvd": {
        "published": "2026-07-21T22:17:15.983",
        "lastModified": "2026-08-01T05:16:57.237",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60154",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Application Object Library permits a low-privileged HTTP user to access or modify data outside the intended scope, but the failing authorization check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 701,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60155",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.515Z",
      "date_published": "2026-07-21T21:33:24.432Z",
      "date_updated": "2026-07-28T03:56:56.086Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01718
      },
      "nvd": {
        "published": "2026-07-21T22:17:16.097",
        "lastModified": "2026-07-28T05:17:07.537",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60155",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle VM VirtualBox permits a high-privileged infrastructure user to take over the product, while the public record does not disclose the failing authority check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 670,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60156",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.515Z",
      "date_published": "2026-07-21T21:33:24.768Z",
      "date_updated": "2026-07-23T15:17:05.118Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle APEX (component: General).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle APEX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24001
      },
      "nvd": {
        "published": "2026-07-21T22:17:16.210",
        "lastModified": "2026-07-23T18:30:41.573",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60156",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle APEX returns protected data to an unintended caller; the exposed field and output path are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 473,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60157",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.515Z",
      "date_published": "2026-07-21T21:33:25.276Z",
      "date_updated": "2026-07-23T15:16:24.563Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle GoldenGate (component: Service Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GoldenGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33079
      },
      "nvd": {
        "published": "2026-07-21T22:17:16.320",
        "lastModified": "2026-07-28T01:35:27.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60157",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a low-privileged HTTP path to GoldenGate takeover but does not publish the Service Manager authorization failure.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.515Z",
      "date_published": "2026-07-21T21:33:25.621Z",
      "date_updated": "2026-07-23T15:15:36.323Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00091,
        "percentile": 0.00604
      },
      "nvd": {
        "published": "2026-07-21T22:17:16.433",
        "lastModified": "2026-07-28T01:36:13.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60158",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 836,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60159",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.515Z",
      "date_published": "2026-07-21T21:33:25.965Z",
      "date_updated": "2026-07-28T03:56:56.832Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01723
      },
      "nvd": {
        "published": "2026-07-21T22:17:16.547",
        "lastModified": "2026-07-28T05:17:07.653",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60159",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 670,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60160",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.515Z",
      "date_published": "2026-07-21T21:33:26.311Z",
      "date_updated": "2026-07-23T15:14:23.405Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02928
      },
      "nvd": {
        "published": "2026-07-21T22:17:16.660",
        "lastModified": "2026-07-30T20:16:15.297",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60160",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Sensitive data is returned, stored, or left readable through an output path that lacks the required disclosure boundary.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 685,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60161",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.515Z",
      "date_published": "2026-07-21T21:33:26.644Z",
      "date_updated": "2026-07-23T15:13:47.118Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02296
      },
      "nvd": {
        "published": "2026-07-21T22:17:16.777",
        "lastModified": "2026-07-30T20:16:01.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60161",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle attributes VirtualBox integrity and availability impact to a race but does not disclose the shared object or unsafe transition.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 792,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60162",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.516Z",
      "date_published": "2026-07-21T21:33:26.981Z",
      "date_updated": "2026-07-29T19:26:41.491Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle VM VirtualBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03311
      },
      "nvd": {
        "published": "2026-07-21T22:17:16.890",
        "lastModified": "2026-07-30T20:15:52.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60162",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged VirtualBox caller can cross an additional product or data boundary, but the misbound authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 827,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60163",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.516Z",
      "date_published": "2026-07-21T21:33:27.340Z",
      "date_updated": "2026-07-28T03:56:08.986Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07355
      },
      "nvd": {
        "published": "2026-07-21T22:17:17.003",
        "lastModified": "2026-07-28T05:17:07.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60163",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Group Replication permits a takeover across an authority boundary, but the public record does not identify the subject, object, or failed check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60164",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.516Z",
      "date_published": "2026-07-21T21:33:27.681Z",
      "date_updated": "2026-07-23T15:21:19.686Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Java SE (component: JavaFX).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00192,
        "percentile": 0.09093
      },
      "nvd": {
        "published": "2026-07-21T22:17:17.120",
        "lastModified": "2026-08-03T18:39:36.207",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60164",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record states only that a JavaFX sandbox can expose data and does not identify the failed protection mechanism.",
        "basis": [
          "CNA record",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1008,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60165",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.516Z",
      "date_published": "2026-07-21T21:33:28.018Z",
      "date_updated": "2026-07-23T15:11:27.340Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Enterprise Command Center).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Cost Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28821
      },
      "nvd": {
        "published": "2026-07-21T22:17:17.237",
        "lastModified": "2026-07-23T18:30:41.573",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60165",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Cost Management permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 716,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60166",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.516Z",
      "date_published": "2026-07-21T21:33:28.374Z",
      "date_updated": "2026-07-23T15:10:46.494Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Java SE (component: JavaFX).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14315
      },
      "nvd": {
        "published": "2026-07-21T22:17:17.350",
        "lastModified": "2026-08-03T18:39:11.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60166",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports a JavaFX sandbox protection failure with limited data disclosure but does not disclose an engineering cause.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1008,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60167",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.516Z",
      "date_published": "2026-07-21T21:33:28.713Z",
      "date_updated": "2026-07-23T15:07:50.712Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Hospitality Simphony"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34445
      },
      "nvd": {
        "published": "2026-07-21T22:17:17.467",
        "lastModified": "2026-08-03T20:24:16.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60167",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated disclosure of all Simphony-accessible POS data, but the CPU does not identify the response, object, or missing access decision.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 609,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60168",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.516Z",
      "date_published": "2026-07-21T21:33:29.066Z",
      "date_updated": "2026-07-23T15:06:52.906Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Hospitality Simphony"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00416,
        "percentile": 0.34281
      },
      "nvd": {
        "published": "2026-07-21T22:17:17.590",
        "lastModified": "2026-08-03T20:23:46.427",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60168",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle publishes unauthenticated POS modification and denial-of-service impact but no request, parser, or access-control predicate that explains the cause.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html; its row confirms Simphony POS over HTTP, unauthenticated reachability, CVSS 9.1, and affected versions, but no request, predicate, or implementation cause is public."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 754,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60169",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.517Z",
      "date_published": "2026-07-21T21:33:29.448Z",
      "date_updated": "2026-07-23T19:33:40.454Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Hospitality Simphony"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.2928
      },
      "nvd": {
        "published": "2026-07-21T22:17:17.703",
        "lastModified": "2026-08-03T20:22:33.257",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60169",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An undisclosed Simphony POS critical function is reachable over HTTP without authentication, allowing takeover under the published conditions.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60170",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.517Z",
      "date_published": "2026-07-21T21:33:29.788Z",
      "date_updated": "2026-07-23T16:22:37.096Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Hospitality Simphony"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32427
      },
      "nvd": {
        "published": "2026-07-21T22:17:17.817",
        "lastModified": "2026-08-03T20:21:20.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60170",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Hospitality Simphony path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 609,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60171",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.517Z",
      "date_published": "2026-07-21T21:33:30.133Z",
      "date_updated": "2026-07-23T16:22:00.963Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00431,
        "percentile": 0.35442
      },
      "nvd": {
        "published": "2026-07-21T22:17:17.933",
        "lastModified": "2026-07-27T14:50:29.640",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60171",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled activity can exhaust a finite resource, but the missing work or storage bound is not public.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 550,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60172",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.517Z",
      "date_published": "2026-07-21T21:33:30.483Z",
      "date_updated": "2026-07-23T16:21:28.641Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Autonomous Health Framework (component: Developer triaging platform).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Autonomous Health Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01898
      },
      "nvd": {
        "published": "2026-07-21T22:17:18.050",
        "lastModified": "2026-07-23T18:30:41.573",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60172",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Autonomous Health Framework operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 692,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60173",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.517Z",
      "date_published": "2026-07-21T21:33:30.834Z",
      "date_updated": "2026-07-23T17:05:14.718Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle BI Publisher"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38438
      },
      "nvd": {
        "published": "2026-07-21T22:17:18.167",
        "lastModified": "2026-08-03T20:19:50.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60173",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP caller can take over Oracle BI Publisher, but Oracle does not publish the protected operation or failing access-control check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; Oracle confirms BI Platform Security, HTTP, no authentication, CVSS 9.8, affected versions, and takeover, but publishes no protected operation or failing access-control check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60174",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.517Z",
      "date_published": "2026-07-21T21:33:31.169Z",
      "date_updated": "2026-07-23T16:15:31.784Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33259
      },
      "nvd": {
        "published": "2026-07-21T22:17:18.283",
        "lastModified": "2026-07-27T14:50:04.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60174",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says MySQL Server can be driven into resource exhaustion or termination, while the unbounded operation and limit are not public.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 632,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60175",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.517Z",
      "date_published": "2026-07-21T21:33:31.503Z",
      "date_updated": "2026-07-23T16:14:46.949Z",
      "publisher": "oracle",
      "title": "Vulnerability in the RDBMS component of Oracle Database Server.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Database Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31696
      },
      "nvd": {
        "published": "2026-07-21T22:17:18.397",
        "lastModified": "2026-07-23T18:30:41.573",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60175",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that an authenticated database user can take over RDBMS through Oracle Net but does not publish the privileged operation or permission failure.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 521,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60176",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.518Z",
      "date_published": "2026-07-21T21:33:31.863Z",
      "date_updated": "2026-07-23T16:14:13.327Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Payments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.32951
      },
      "nvd": {
        "published": "2026-07-21T22:17:18.513",
        "lastModified": "2026-08-03T20:18:37.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60176",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 663,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60177",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.518Z",
      "date_published": "2026-07-21T21:33:32.200Z",
      "date_updated": "2026-07-23T16:13:38.427Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.2696
      },
      "nvd": {
        "published": "2026-07-21T22:17:18.617",
        "lastModified": "2026-07-27T14:49:41.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60177",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled input can consume finite work or memory without an effective bound, release or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60178",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.518Z",
      "date_published": "2026-07-21T21:33:32.550Z",
      "date_updated": "2026-07-28T03:56:09.729Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27672
      },
      "nvd": {
        "published": "2026-07-21T22:17:18.730",
        "lastModified": "2026-07-28T05:17:08.043",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60178",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60179",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.518Z",
      "date_published": "2026-07-21T21:33:33.247Z",
      "date_updated": "2026-07-25T03:56:14.065Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Connectors"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23349
      },
      "nvd": {
        "published": "2026-07-21T22:17:18.847",
        "lastModified": "2026-07-25T05:16:35.957",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60179",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "MySQL Connectors permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 691,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60180",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.518Z",
      "date_published": "2026-07-21T21:33:33.585Z",
      "date_updated": "2026-07-23T15:06:08.886Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Connectors"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37136
      },
      "nvd": {
        "published": "2026-07-21T22:17:18.960",
        "lastModified": "2026-07-23T18:30:41.573",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60180",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A remote unauthenticated input can hang or repeatedly crash Connector/C++, but Oracle does not publish the unbounded operation or resource.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 554,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60181",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.519Z",
      "date_published": "2026-07-21T21:33:33.927Z",
      "date_updated": "2026-07-28T03:56:10.647Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Configurator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00098,
        "percentile": 0.009
      },
      "nvd": {
        "published": "2026-07-21T22:17:19.070",
        "lastModified": "2026-07-28T05:17:08.167",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60181",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports a local low-privileged takeover of the MySQL Configurator with victim interaction but discloses no input, trust boundary, or failed check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 711,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60182",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.519Z",
      "date_published": "2026-07-21T21:33:34.274Z",
      "date_updated": "2026-07-23T15:03:51.886Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.2696
      },
      "nvd": {
        "published": "2026-07-21T22:17:19.183",
        "lastModified": "2026-07-27T14:47:50.577",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60182",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged Clone Plugin request can drive MySQL into a repeatable hang or crash, but the unbounded work or resource is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.519Z",
      "date_published": "2026-07-21T21:33:34.624Z",
      "date_updated": "2026-07-28T03:56:31.774Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03503
      },
      "nvd": {
        "published": "2026-07-21T22:17:19.290",
        "lastModified": "2026-07-28T05:17:08.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60183",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The MySQL Server operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 674,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.519Z",
      "date_published": "2026-07-21T21:33:34.970Z",
      "date_updated": "2026-07-23T15:02:23.352Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.2696
      },
      "nvd": {
        "published": "2026-07-21T22:17:19.407",
        "lastModified": "2026-07-27T17:36:04.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60184",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A privileged replication request can hang or repeatedly crash MySQL, but Oracle does not disclose the missing bound or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 683,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60185",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.519Z",
      "date_published": "2026-07-21T21:33:35.317Z",
      "date_updated": "2026-07-23T15:01:47.556Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.2696
      },
      "nvd": {
        "published": "2026-07-21T22:17:19.520",
        "lastModified": "2026-07-27T17:35:28.540",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60185",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected path in MySQL Server accepts or retains attacker-controlled work or memory without an effective upper bound or release condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 683,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60186",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.519Z",
      "date_published": "2026-07-21T21:33:35.653Z",
      "date_updated": "2026-07-23T14:53:24.957Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26959
      },
      "nvd": {
        "published": "2026-07-21T22:17:19.647",
        "lastModified": "2026-07-27T17:33:52.237",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60186",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "MySQL Server accepts an attacker-controlled size, count, recursion depth, or work request without the quota or upper bound needed to keep resource use finite.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 696,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.520Z",
      "date_published": "2026-07-21T21:33:36.053Z",
      "date_updated": "2026-07-23T14:51:07.690Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26959
      },
      "nvd": {
        "published": "2026-07-21T22:17:19.800",
        "lastModified": "2026-07-27T17:30:06.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60187",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privilege replication request can leave MySQL hung or repeatedly crashed, while Oracle does not disclose the unbounded resource or termination condition.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 683,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.520Z",
      "date_published": "2026-07-21T21:33:36.400Z",
      "date_updated": "2026-07-23T17:04:57.325Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16698
      },
      "nvd": {
        "published": "2026-07-21T22:17:19.920",
        "lastModified": "2026-07-27T17:29:21.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60188",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to MySQL Server in its Server: Replication component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 683,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60189",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.520Z",
      "date_published": "2026-07-21T21:33:36.746Z",
      "date_updated": "2026-07-23T17:04:50.063Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.2416
      },
      "nvd": {
        "published": "2026-07-21T22:17:20.050",
        "lastModified": "2026-07-27T17:28:44.427",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60189",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Oracle advisory reports a remotely triggerable replication denial of service but does not identify the failing check, resource bound, or state transition.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 683,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60190",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.520Z",
      "date_published": "2026-07-21T21:33:37.096Z",
      "date_updated": "2026-07-23T17:04:41.342Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20678
      },
      "nvd": {
        "published": "2026-07-21T22:17:20.157",
        "lastModified": "2026-07-27T17:16:56.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60190",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "Oracle MySQL permits a high-privileged network action to cause partial denial of service, but the access-control record does not disclose the failing operation check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 672,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.520Z",
      "date_published": "2026-07-21T21:33:37.455Z",
      "date_updated": "2026-07-23T17:04:34.080Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02605
      },
      "nvd": {
        "published": "2026-07-21T22:17:20.270",
        "lastModified": "2026-07-27T17:16:23.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60191",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports a replication hang or repeatable crash but does not disclose the input, resource, state, or memory failure that causes it.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 716,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.520Z",
      "date_published": "2026-07-21T21:33:37.798Z",
      "date_updated": "2026-07-23T17:04:23.105Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Connectors"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00376,
        "percentile": 0.30356
      },
      "nvd": {
        "published": "2026-07-21T22:17:20.383",
        "lastModified": "2026-08-03T20:13:25.833",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60192",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle MySQL Connector/Net permits an unauthenticated network caller to cross its access boundary, while Oracle does not disclose the failing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 513,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60193",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.520Z",
      "date_published": "2026-07-21T21:33:38.139Z",
      "date_updated": "2026-07-25T03:56:14.842Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Connectors"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16108
      },
      "nvd": {
        "published": "2026-07-21T22:17:20.497",
        "lastModified": "2026-08-03T15:17:44.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60193",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a low-privileged network path to Connector/Net takeover but does not publish the authorization boundary that fails.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 630,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60194",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.521Z",
      "date_published": "2026-07-21T21:33:38.479Z",
      "date_updated": "2026-07-23T17:04:05.514Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON Duality).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00398,
        "percentile": 0.32607
      },
      "nvd": {
        "published": "2026-07-21T22:17:20.620",
        "lastModified": "2026-07-27T17:15:41.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60194",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60195",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.521Z",
      "date_published": "2026-07-21T21:33:38.813Z",
      "date_updated": "2026-07-23T17:03:57.285Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON Duality).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00398,
        "percentile": 0.32607
      },
      "nvd": {
        "published": "2026-07-21T22:17:20.727",
        "lastModified": "2026-07-27T17:15:13.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60195",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60196",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.521Z",
      "date_published": "2026-07-21T21:33:39.145Z",
      "date_updated": "2026-07-28T03:55:47.459Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25492
      },
      "nvd": {
        "published": "2026-07-21T22:17:20.840",
        "lastModified": "2026-07-28T14:20:52.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60196",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle WebLogic Server but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 745,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60197",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.521Z",
      "date_published": "2026-07-21T21:33:39.485Z",
      "date_updated": "2026-07-23T16:11:46.913Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38448
      },
      "nvd": {
        "published": "2026-07-21T22:17:20.957",
        "lastModified": "2026-07-24T17:14:15.260",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60197",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a critical operation without completing the authentication check required for that operation.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60198",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.521Z",
      "date_published": "2026-07-21T21:33:39.828Z",
      "date_updated": "2026-07-28T03:55:46.579Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00522,
        "percentile": 0.41415
      },
      "nvd": {
        "published": "2026-07-21T22:17:21.073",
        "lastModified": "2026-07-28T14:20:30.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60198",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A remotely reachable WebLogic T3 or IIOP critical function lacks the authentication required before takeover-capable processing.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60199",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.521Z",
      "date_published": "2026-07-21T21:33:40.167Z",
      "date_updated": "2026-07-28T03:55:43.788Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0039,
        "percentile": 0.3173
      },
      "nvd": {
        "published": "2026-07-21T22:17:21.180",
        "lastModified": "2026-07-28T14:20:12.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60199",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A critical WebLogic operation is exposed without the authentication required for that function.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60200",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.522Z",
      "date_published": "2026-07-21T21:33:40.508Z",
      "date_updated": "2026-07-28T03:55:43.031Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00508,
        "percentile": 0.40579
      },
      "nvd": {
        "published": "2026-07-21T22:17:21.297",
        "lastModified": "2026-07-28T14:19:46.757",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60200",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A SOAP-reachable WebLogic Core function executes without authenticating the caller.",
        "basis": [
          "CNA record",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60201",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.522Z",
      "date_published": "2026-07-21T21:33:40.858Z",
      "date_updated": "2026-07-25T03:56:20.766Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29326
      },
      "nvd": {
        "published": "2026-07-21T22:17:21.410",
        "lastModified": "2026-07-28T14:19:22.837",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60201",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle WebLogic Server exposes a security-sensitive endpoint without requiring caller authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 563,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60202",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.522Z",
      "date_published": "2026-07-21T21:33:41.208Z",
      "date_updated": "2026-07-29T19:26:42.648Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00508,
        "percentile": 0.4058
      },
      "nvd": {
        "published": "2026-07-21T22:17:21.520",
        "lastModified": "2026-07-29T20:17:06.597",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60202",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebLogic exposes a T3 or IIOP compromise path without authenticating the network caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60203",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.522Z",
      "date_published": "2026-07-21T21:33:41.536Z",
      "date_updated": "2026-07-25T03:56:18.893Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33079
      },
      "nvd": {
        "published": "2026-07-21T22:17:21.623",
        "lastModified": "2026-07-28T14:15:56.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60203",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports low-privileged HTTP takeover of WebLogic Core, but the CPU does not disclose which critical function lacks the required authentication or authorization gate.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60204",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.522Z",
      "date_published": "2026-07-21T21:33:41.877Z",
      "date_updated": "2026-07-25T03:56:12.486Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00508,
        "percentile": 0.4058
      },
      "nvd": {
        "published": "2026-07-21T22:17:21.730",
        "lastModified": "2026-07-28T14:15:25.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60204",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable security-sensitive operation is exposed without the authentication step required before invoking it.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60205",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.522Z",
      "date_published": "2026-07-21T21:33:42.208Z",
      "date_updated": "2026-07-25T03:56:11.679Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00522,
        "percentile": 0.41415
      },
      "nvd": {
        "published": "2026-07-21T22:17:21.847",
        "lastModified": "2026-07-28T14:14:58.373",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60205",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An undisclosed WebLogic Core critical function is reachable over TCP without authentication, allowing takeover under the published conditions.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60206",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:42.557Z",
      "date_updated": "2026-07-25T03:56:10.887Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00486,
        "percentile": 0.39262
      },
      "nvd": {
        "published": "2026-07-21T22:17:21.953",
        "lastModified": "2026-07-28T14:14:37.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60206",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged network caller can reach WebLogic Server Core over SAML and take over the server, but Oracle does not disclose the message or failing authorization decision.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle's July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms that a low-privileged network caller can reach WebLogic Server Core over SAML with CVSS 9.9 and takeover impact, but publishes no SAML message, handler, authorization transition, or failing check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 680,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60207",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:42.902Z",
      "date_updated": "2026-07-25T03:56:10.057Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00414,
        "percentile": 0.34081
      },
      "nvd": {
        "published": "2026-07-21T22:17:22.070",
        "lastModified": "2026-07-28T14:14:07.393",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60207",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected Oracle operation can be reached with insufficient authority, but the record does not identify the authentication or authorization check.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "The structured CWE-306 missing-authentication label conflicts with the embedded CVSS requirement for low privileges; the public record does not resolve whether authentication or a post-authentication authorization gate failed."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60208",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:43.254Z",
      "date_updated": "2026-07-25T03:56:09.247Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37703
      },
      "nvd": {
        "published": "2026-07-21T22:17:22.180",
        "lastModified": "2026-07-28T14:13:47.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60208",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle identifies an unauthenticated WebLogic Core vulnerability over HTTP, while the published weakness and impact fields do not reveal a coherent engineering cause.",
        "basis": [
          "CNA",
          "CWE-400",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Read Oracle July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html; it confirms unauthenticated HTTP reachability in WebLogic Core but adds no causal mechanism, and the resource-consumption CWE remains inconsistent with confidentiality/integrity-only impact."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 741,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60209",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:43.603Z",
      "date_updated": "2026-07-23T15:54:19.566Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38453
      },
      "nvd": {
        "published": "2026-07-21T22:17:22.297",
        "lastModified": "2026-07-24T19:22:06.143",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60209",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a critical Core function over TCP without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60210",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:44.031Z",
      "date_updated": "2026-07-23T15:53:39.431Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38454
      },
      "nvd": {
        "published": "2026-07-21T22:17:22.407",
        "lastModified": "2026-07-24T19:22:02.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60210",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle exposes Coherence Core over TCP to unauthenticated takeover, while the July CPU does not publish the missing authentication gate or reachable handler.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms unauthenticated TCP exposure in Coherence Core, CVSS 9.8, and the affected release trains but publishes no handler, request grammar, or missing check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 526,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60211",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:44.371Z",
      "date_updated": "2026-07-23T15:52:59.613Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28153
      },
      "nvd": {
        "published": "2026-07-21T22:17:22.517",
        "lastModified": "2026-07-24T19:22:01.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60211",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports adjacent-network takeover of Coherence Core without authentication but does not publish the service or failing access check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 621,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60212",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:44.718Z",
      "date_updated": "2026-07-23T15:52:24.879Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38438
      },
      "nvd": {
        "published": "2026-07-21T22:17:22.633",
        "lastModified": "2026-07-24T19:21:59.263",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60212",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an unauthenticated Coherence Core takeover over TCP but does not publish the reachable operation or missing authentication check.",
        "basis": [
          "CNA",
          "CWE-306",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.oracle.com/security-alerts/cpujul2026.html. Oracle's CPU matrix confirms unauthenticated TCP reachability and takeover impact for Coherence Core but publishes no reachable operation or missing authentication check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60213",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:45.085Z",
      "date_updated": "2026-07-23T15:56:54.368Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.2368
      },
      "nvd": {
        "published": "2026-07-21T22:17:22.750",
        "lastModified": "2026-07-24T19:21:57.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60213",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled input can consume finite work or memory without an effective bound, release or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 687,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60214",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:45.434Z",
      "date_updated": "2026-07-23T15:51:48.424Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17062
      },
      "nvd": {
        "published": "2026-07-21T22:17:22.863",
        "lastModified": "2026-07-24T19:21:55.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60214",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged adjacent-network caller can cross an undisclosed Coherence Core authorization boundary into critical data operations.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 916,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60215",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:45.793Z",
      "date_updated": "2026-07-23T15:51:14.077Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.3844
      },
      "nvd": {
        "published": "2026-07-21T22:17:22.977",
        "lastModified": "2026-07-24T20:40:50.647",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60215",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a security-sensitive operation without verifying that the network caller is authenticated.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60216",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:46.145Z",
      "date_updated": "2026-07-23T15:50:36.428Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.3844
      },
      "nvd": {
        "published": "2026-07-21T22:17:23.097",
        "lastModified": "2026-07-24T20:40:59.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60216",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A critical Oracle Coherence function is reachable over TCP without the authentication required to protect it.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60217",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:46.482Z",
      "date_updated": "2026-07-23T16:42:31.622Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00474,
        "percentile": 0.38497
      },
      "nvd": {
        "published": "2026-07-21T22:17:23.207",
        "lastModified": "2026-07-24T20:41:08.940",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60217",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a critical TCP function without requiring authentication before the operation executes.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 657,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60218",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.523Z",
      "date_published": "2026-07-21T21:33:46.822Z",
      "date_updated": "2026-07-23T16:43:15.509Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22443
      },
      "nvd": {
        "published": "2026-07-21T22:17:23.320",
        "lastModified": "2026-07-24T20:41:15.897",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60218",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged TCP caller can reach a critical Coherence operation without the authentication that operation requires, although the function is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60219",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:47.152Z",
      "date_updated": "2026-07-23T16:45:30.263Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38445
      },
      "nvd": {
        "published": "2026-07-21T22:17:23.430",
        "lastModified": "2026-07-24T20:41:23.870",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60219",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A TCP-exposed Oracle Coherence Core operation is reachable without the authentication required for takeover-capable actions, although the exact operation is not public.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms Coherence Core over TCP, no privileges, affected versions, and takeover impact, but publishes no endpoint, authentication check, or patch source."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 526,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:47.490Z",
      "date_updated": "2026-07-23T17:03:38.774Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27771
      },
      "nvd": {
        "published": "2026-07-21T22:17:23.540",
        "lastModified": "2026-07-24T20:41:33.393",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60220",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated TCP client can obtain broad Coherence data access after victim interaction, but Oracle does not disclose the failing control.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the Oracle risk matrix confirms Coherence Core over TCP, no privileges, required user interaction, and changed scope but does not disclose the failing access-control check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 920,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60221",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:47.847Z",
      "date_updated": "2026-07-23T17:03:30.077Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28167
      },
      "nvd": {
        "published": "2026-07-21T22:17:23.667",
        "lastModified": "2026-07-24T20:41:50.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60221",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated TCP takeover of Coherence Core, but the CPU table does not disclose the function, parser, or authorization check that fails.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html - Oracle confirms Coherence Core, TCP reachability, no prior privileges, affected versions, and impact, but publishes no failing function, parser, or authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60222",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:48.177Z",
      "date_updated": "2026-07-23T17:03:24.471Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.2928
      },
      "nvd": {
        "published": "2026-07-21T22:17:23.777",
        "lastModified": "2026-07-24T19:53:06.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60222",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60222 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 545,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60223",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:48.517Z",
      "date_updated": "2026-07-23T17:03:15.131Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00416,
        "percentile": 0.34281
      },
      "nvd": {
        "published": "2026-07-21T22:17:23.897",
        "lastModified": "2026-07-24T20:42:01.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60223",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Coherence permits unauthenticated TCP input to reach a denial-of-service action through an access-control failure, while the protected operation is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 581,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60224",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:49.870Z",
      "date_updated": "2026-07-23T17:03:08.919Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38445
      },
      "nvd": {
        "published": "2026-07-21T22:17:24.010",
        "lastModified": "2026-07-24T20:35:50.880",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60224",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle Coherence in its Core component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Read https://www.oracle.com/security-alerts/cpujul2026.html; Oracle's CPU confirms unauthenticated TCP reachability and takeover impact but provides no operation or failed access-control check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60225",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:50.251Z",
      "date_updated": "2026-07-23T17:02:58.580Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00474,
        "percentile": 0.38497
      },
      "nvd": {
        "published": "2026-07-21T22:17:24.120",
        "lastModified": "2026-07-24T20:37:02.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60225",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Coherence Core permits an unauthenticated network action over HTTP, but the public advisory does not identify the operation or missing authorization check.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Primary source inspected: https://www.oracle.com/security-alerts/cpujul2026.html. Oracle identifies Coherence Core, HTTP, no authentication, and CVSS 9.8, but publishes no affected operation or causal check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:51.236Z",
      "date_updated": "2026-07-23T17:02:50.666Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38452
      },
      "nvd": {
        "published": "2026-07-21T22:17:24.233",
        "lastModified": "2026-07-24T20:37:14.263",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60226",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Coherence permits an unauthenticated TCP client to take over the service, but neither the record nor the CPU identifies the failing access-control check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Read https://www.oracle.com/security-alerts/cpujul2026.html; Oracle confirms an unauthenticated TCP path into Coherence Core and full impact but publishes no failing check, patch diff, or source."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60227",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:51.615Z",
      "date_updated": "2026-07-23T17:02:41.565Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38452
      },
      "nvd": {
        "published": "2026-07-21T22:17:24.343",
        "lastModified": "2026-07-24T20:37:26.267",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60227",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports unauthenticated TCP takeover of Coherence Core but does not disclose an authentication check, deserialization boundary, parser, or other causal mechanism.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official July CPU confirms affected Coherence versions, TCP reachability, no authentication, and complete impact, but publishes no failing check, patch diff, or source path."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60228",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:51.958Z",
      "date_updated": "2026-07-23T15:49:59.954Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38455
      },
      "nvd": {
        "published": "2026-07-21T22:17:24.457",
        "lastModified": "2026-07-24T20:38:38.093",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60228",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Coherence exposes a TCP path that permits takeover without authentication, while the July CPU does not disclose the missing gate or handler.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the CPU confirms unauthenticated TCP reachability and affected Coherence versions without publishing the missing authentication gate."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60229",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:52.327Z",
      "date_updated": "2026-07-23T15:48:41.045Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38441
      },
      "nvd": {
        "published": "2026-07-21T22:17:24.567",
        "lastModified": "2026-07-24T20:38:47.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60229",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle states that Coherence Core accepts an unauthenticated TCP attack leading to takeover but does not disclose the endpoint or missing authentication check.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html was inspected; Oracle exposes the component, protocol, versions, and CVSS conditions but no endpoint or failing authentication check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60230",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:52.670Z",
      "date_updated": "2026-07-23T15:48:02.876Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38442
      },
      "nvd": {
        "published": "2026-07-21T22:17:24.690",
        "lastModified": "2026-07-24T20:38:59.283",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60230",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an unauthenticated Coherence Core takeover over TCP but does not publish the missing authentication check or reachable operation.",
        "basis": [
          "CNA",
          "CWE-306",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.oracle.com/security-alerts/cpujul2026.html. Oracle's public risk matrix confirms unauthenticated TCP reachability and takeover impact but intentionally does not disclose the failing Core check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60231",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:53.043Z",
      "date_updated": "2026-07-23T15:47:28.022Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12802
      },
      "nvd": {
        "published": "2026-07-21T22:17:24.813",
        "lastModified": "2026-07-24T20:39:19.143",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60231",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 670,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:53.381Z",
      "date_updated": "2026-07-23T15:45:17.744Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28167
      },
      "nvd": {
        "published": "2026-07-21T22:17:24.953",
        "lastModified": "2026-07-27T13:27:34.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60232",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A security-sensitive endpoint performs its operation without requiring the caller to authenticate.",
        "basis": [
          "CNA",
          "CWE-306",
          "https://www.oracle.com/security-alerts/cpujul2026.html",
          "https://www.oracle.com/security-alerts/cpujul2026verbose.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July CPU confirms unauthenticated HTTP reachability into Coherence Core, affected releases, and full takeover impact, but publishes no route, handler, credential decision, or omitted authentication check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60233",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:53.731Z",
      "date_updated": "2026-07-23T15:46:51.155Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28077
      },
      "nvd": {
        "published": "2026-07-21T22:17:25.060",
        "lastModified": "2026-07-27T13:27:58.673",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60233",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged TCP caller can cause partial Coherence denial of service, but Oracle does not disclose the finite resource or missing bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60234",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:54.069Z",
      "date_updated": "2026-07-23T15:44:35.827Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38459
      },
      "nvd": {
        "published": "2026-07-21T22:17:25.170",
        "lastModified": "2026-07-27T13:28:26.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60234",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A remotely reachable Coherence TCP critical function lacks the authentication required before takeover-capable processing.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60235",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.524Z",
      "date_published": "2026-07-21T21:33:54.412Z",
      "date_updated": "2026-07-23T15:43:51.315Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00329,
        "percentile": 0.25401
      },
      "nvd": {
        "published": "2026-07-21T22:17:25.280",
        "lastModified": "2026-07-27T13:28:41.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60235",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A critical Coherence operation is exposed without the authentication required for that function.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 753,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60236",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:33:55.064Z",
      "date_updated": "2026-07-23T15:43:14.375Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38456
      },
      "nvd": {
        "published": "2026-07-21T22:17:25.397",
        "lastModified": "2026-07-24T20:39:28.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60236",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A TCP-reachable Oracle Coherence Core function executes without authenticating the caller.",
        "basis": [
          "CNA record",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60237",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:33:55.408Z",
      "date_updated": "2026-07-23T15:42:28.015Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24732
      },
      "nvd": {
        "published": "2026-07-21T22:17:25.500",
        "lastModified": "2026-07-24T20:39:37.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60237",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle identifies unauthenticated TCP access to a subset of Coherence data but does not disclose the request, data path, or missing disclosure or authority check.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60238",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:33:55.761Z",
      "date_updated": "2026-07-23T16:50:18.345Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07203
      },
      "nvd": {
        "published": "2026-07-21T22:17:25.610",
        "lastModified": "2026-07-27T13:29:02.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60238",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Coherence permits an unauthenticated HTTP caller to read or modify data, but the failing access-control check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 791,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60239",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:33:56.103Z",
      "date_updated": "2026-07-23T16:51:14.764Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26311
      },
      "nvd": {
        "published": "2026-07-21T22:17:25.717",
        "lastModified": "2026-07-24T17:14:24.940",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60239",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged HTTP caller can read and modify critical Coherence data, but the CPU does not disclose the protected object or permission check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html - Oracle confirms Coherence Core, HTTP reachability, low privileges, scope change, affected versions, and confidentiality/integrity impact, but publishes no failing permission or object check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 834,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60240",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:33:56.439Z",
      "date_updated": "2026-07-23T16:53:12.627Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38457
      },
      "nvd": {
        "published": "2026-07-21T22:17:25.827",
        "lastModified": "2026-07-24T17:14:37.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60240",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable security-sensitive operation is exposed without the authentication step required before invoking it.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60241",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:33:56.789Z",
      "date_updated": "2026-07-23T16:54:07.092Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28161
      },
      "nvd": {
        "published": "2026-07-21T22:17:25.937",
        "lastModified": "2026-07-24T17:14:48.597",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60241",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An undisclosed Oracle Coherence Core critical function is reachable over HTTP without authentication, allowing takeover under the published conditions.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60242",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:33:57.133Z",
      "date_updated": "2026-07-23T16:54:44.146Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38445
      },
      "nvd": {
        "published": "2026-07-21T22:17:26.043",
        "lastModified": "2026-07-24T17:14:56.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60242",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP caller can take over Coherence Core, but Oracle does not disclose the endpoint, handler, or missing authentication gate.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle's July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms unauthenticated HTTP reachability of Coherence Core, CVSS 9.8, and takeover impact, but publishes no endpoint, request grammar, handler, or missing authentication gate."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:33:57.481Z",
      "date_updated": "2026-07-23T16:55:43.659Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.3326
      },
      "nvd": {
        "published": "2026-07-21T22:17:26.153",
        "lastModified": "2026-07-24T17:15:04.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60243",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A finite resource can be exhausted without an effective bound, whose allocation path is not disclosed.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 580,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60244",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:33:57.833Z",
      "date_updated": "2026-07-23T16:59:42.067Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28162
      },
      "nvd": {
        "published": "2026-07-21T22:17:26.267",
        "lastModified": "2026-07-24T17:15:12.797",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60244",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive Oracle Coherence operation is reachable through a path that does not enforce the required authentication.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Read Oracle July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html; it confirms unauthenticated HTTP reachability in Coherence Core but does not name the critical operation left unauthenticated."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60245",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:33:58.167Z",
      "date_updated": "2026-07-23T15:41:53.218Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01756
      },
      "nvd": {
        "published": "2026-07-21T22:17:26.377",
        "lastModified": "2026-07-24T17:15:23.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60245",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged local Oracle Coherence user can cross an access boundary, but the protected operation and failing check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 958,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:33:58.513Z",
      "date_updated": "2026-07-23T15:41:10.629Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28162
      },
      "nvd": {
        "published": "2026-07-21T22:17:26.490",
        "lastModified": "2026-07-24T17:15:31.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60246",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle exposes Coherence Core over TCP to unauthenticated takeover, while the July CPU does not publish the missing authentication gate or reachable handler.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms unauthenticated TCP exposure in Coherence Core, CVSS 9.8, and the affected release trains but publishes no handler, request grammar, or missing check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60247",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:33:58.843Z",
      "date_updated": "2026-07-23T15:40:26.574Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38458
      },
      "nvd": {
        "published": "2026-07-21T22:17:26.597",
        "lastModified": "2026-07-24T17:15:43.227",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60247",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle says Coherence Core accepts an unauthenticated HTTP path to takeover but does not publish the endpoint or missing authentication check.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html was inspected; Oracle confirms unauthenticated HTTP reachability to Coherence Core, versions, and impact but publishes no endpoint or missing authentication check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60248",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:34:00.198Z",
      "date_updated": "2026-07-23T15:39:40.063Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.0385
      },
      "nvd": {
        "published": "2026-07-21T22:17:26.700",
        "lastModified": "2026-07-24T17:04:53.037",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60248",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a local unauthenticated Coherence Core takeover with scope change but does not publish the privilege transition or failing control.",
        "basis": [
          "CNA",
          "CWE-269",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.oracle.com/security-alerts/cpujul2026.html. Oracle's CPU matrix confirms a local unauthenticated Coherence Core takeover with scope change but publishes no privilege transition or failing control."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 693,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60249",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:34:00.603Z",
      "date_updated": "2026-07-23T15:38:53.953Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00219,
        "percentile": 0.12525
      },
      "nvd": {
        "published": "2026-07-21T22:17:26.813",
        "lastModified": "2026-07-24T17:05:04.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60249",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Coherence Core has an access-control failure reachable over HTTP by a low-privileged adjacent-network caller, while the CPU does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle Critical Patch Update July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. The CPU identifies Coherence Core over HTTP, adjacent-network low-privilege access, scope change, and affected 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0/15.1.1.0.0, but no endpoint or authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 738,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60250",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:34:00.956Z",
      "date_updated": "2026-07-23T15:38:12.204Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28166
      },
      "nvd": {
        "published": "2026-07-21T22:17:26.923",
        "lastModified": "2026-07-24T17:05:13.497",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60250",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Coherence exposes a takeover path to an unauthenticated TCP peer, but Oracle does not publish the handler, credential path, or omitted authentication decision.",
        "basis": [
          "CNA",
          "CWE-306",
          "https://www.oracle.com/security-alerts/cpujul2026.html",
          "https://www.oracle.com/security-alerts/cpujul2026verbose.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July CPU confirms Coherence Core, affected releases, unauthenticated TCP reachability, and takeover impact but no handler, credential flow, or missing check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:34:01.319Z",
      "date_updated": "2026-07-23T17:12:57.669Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28162
      },
      "nvd": {
        "published": "2026-07-21T22:17:27.033",
        "lastModified": "2026-07-24T17:12:23.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60251",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a security-sensitive operation without verifying that the network caller is authenticated.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.525Z",
      "date_published": "2026-07-21T21:34:01.647Z",
      "date_updated": "2026-07-23T17:00:52.154Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0045,
        "percentile": 0.36945
      },
      "nvd": {
        "published": "2026-07-21T22:17:27.147",
        "lastModified": "2026-07-24T17:12:34.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60252",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A remote unauthenticated TCP input can hang or repeatedly crash Coherence, but Oracle does not publish the unbounded operation.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 581,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60253",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:02.002Z",
      "date_updated": "2026-07-23T17:01:51.055Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38456
      },
      "nvd": {
        "published": "2026-07-21T22:17:27.257",
        "lastModified": "2026-07-24T17:12:44.273",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60253",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a critical TCP function without requiring authentication before the operation executes.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60254",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:02.350Z",
      "date_updated": "2026-07-23T17:02:25.875Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38455
      },
      "nvd": {
        "published": "2026-07-21T22:17:27.370",
        "lastModified": "2026-07-24T17:13:00.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60254",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated TCP caller can reach a critical Coherence Core operation without an authentication gate, although the function is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60255",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:02.742Z",
      "date_updated": "2026-07-23T17:05:19.088Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00363,
        "percentile": 0.29012
      },
      "nvd": {
        "published": "2026-07-21T22:17:27.480",
        "lastModified": "2026-07-24T17:13:10.043",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60255",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive Oracle Coherence operation can run without authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 696,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60256",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:03.100Z",
      "date_updated": "2026-07-23T17:06:10.399Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38456
      },
      "nvd": {
        "published": "2026-07-21T22:17:27.593",
        "lastModified": "2026-07-24T17:13:17.967",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60256",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a critical TCP operation without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 526,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60257",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:03.527Z",
      "date_updated": "2026-07-23T17:16:17.715Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38459
      },
      "nvd": {
        "published": "2026-07-21T22:17:27.717",
        "lastModified": "2026-07-24T17:13:25.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60257",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 526,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60258",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:03.870Z",
      "date_updated": "2026-07-23T17:17:54.374Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38441
      },
      "nvd": {
        "published": "2026-07-21T22:17:27.823",
        "lastModified": "2026-07-27T13:29:15.783",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60258",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable Oracle Coherence Core operation over TCP can be invoked without the authentication required for a takeover-capable function.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle's July 2026 CPU at https://www.oracle.com/security-alerts/cpujul2026.html; the row confirms Coherence Core, TCP, no authentication, CVSS 9.8, and high confidentiality/integrity/availability impact, but it does not identify the operation, authentication gate, or patch logic."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60259",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:04.218Z",
      "date_updated": "2026-07-23T17:21:31.773Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38439
      },
      "nvd": {
        "published": "2026-07-21T22:17:27.933",
        "lastModified": "2026-07-27T13:29:29.283",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60259",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A critical Oracle Coherence HTTP function is reachable without authenticating the remote caller.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60260",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:04.555Z",
      "date_updated": "2026-07-27T14:07:44.947Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24731
      },
      "nvd": {
        "published": "2026-07-21T22:17:28.043",
        "lastModified": "2026-07-27T20:26:43.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60260",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle says Oracle Coherence in its Core component returns protected data to an unauthorized caller, but does not disclose the endpoint or output path.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60261",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:04.899Z",
      "date_updated": "2026-07-27T14:07:45.113Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28153
      },
      "nvd": {
        "published": "2026-07-21T22:17:28.153",
        "lastModified": "2026-07-27T20:26:24.800",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60261",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle product permits access beyond the caller's assigned authority, but the public record does not identify the protected operation or failing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 621,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60262",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:05.248Z",
      "date_updated": "2026-07-23T17:24:10.853Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38439
      },
      "nvd": {
        "published": "2026-07-21T22:17:28.267",
        "lastModified": "2026-07-27T13:29:44.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60262",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a critical TCP function without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60263",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:05.603Z",
      "date_updated": "2026-07-23T17:25:10.256Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32427
      },
      "nvd": {
        "published": "2026-07-21T22:17:28.383",
        "lastModified": "2026-07-27T13:30:00.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60263",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence Core exposes critical data over TCP without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 566,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60264",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:05.969Z",
      "date_updated": "2026-07-23T17:26:19.481Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00383,
        "percentile": 0.31051
      },
      "nvd": {
        "published": "2026-07-21T22:17:28.490",
        "lastModified": "2026-07-27T13:30:12.280",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60264",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports unauthenticated HTTP/2 takeover of Coherence and labels the issue as information exposure, leaving the enabling engineering failure unresolved in public material.",
        "basis": [
          "CNA",
          "CWE-200",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the CPU confirms HTTP/2 reachability and takeover impact, while the CWE-200 label and public text do not identify the enabling cause."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 529,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60265",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:06.323Z",
      "date_updated": "2026-07-23T17:29:30.606Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06272
      },
      "nvd": {
        "published": "2026-07-21T22:17:28.603",
        "lastModified": "2026-07-27T13:30:27.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60265",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a privileged local path to Coherence data disclosure but does not publish the failing access-control rule.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 733,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60266",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:06.665Z",
      "date_updated": "2026-07-23T17:36:56.339Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00334,
        "percentile": 0.26008
      },
      "nvd": {
        "published": "2026-07-21T22:17:28.713",
        "lastModified": "2026-07-27T13:30:42.747",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60266",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 580,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60267",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:07.114Z",
      "date_updated": "2026-07-23T17:34:55.331Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32425
      },
      "nvd": {
        "published": "2026-07-21T22:17:28.827",
        "lastModified": "2026-07-27T13:30:54.467",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60267",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an access-control failure in Coherence Core reachable over TLS, while its public CPU does not disclose the affected operation or missing check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official table confirms Coherence Core, TLS, affected versions and CVSS conditions but publishes no implementation path or missing access-control check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 716,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60268",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.526Z",
      "date_published": "2026-07-21T21:34:07.466Z",
      "date_updated": "2026-07-23T17:43:18.744Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33022
      },
      "nvd": {
        "published": "2026-07-21T22:17:28.933",
        "lastModified": "2026-07-24T13:42:10.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60268",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle Coherence but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60269",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:07.813Z",
      "date_updated": "2026-07-27T14:07:52.347Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25613
      },
      "nvd": {
        "published": "2026-07-21T22:17:29.053",
        "lastModified": "2026-07-24T18:17:55.357",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60269",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated TCP caller can take over Coherence, but Oracle does not disclose the protected Core operation or failed access-control decision.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; Oracle confirms Coherence Core over TCP, unauthenticated network reachability, affected versions, and 9.8 impact but does not disclose the protected operation or failed authorization decision."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60270",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:08.179Z",
      "date_updated": "2026-07-23T17:46:10.980Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24771
      },
      "nvd": {
        "published": "2026-07-21T22:17:29.173",
        "lastModified": "2026-07-24T13:42:00.537",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60270",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged Coherence caller can read all data and modify some data beyond its intended authority, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 694,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60271",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:08.514Z",
      "date_updated": "2026-07-23T19:32:54.222Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04683
      },
      "nvd": {
        "published": "2026-07-21T22:17:29.350",
        "lastModified": "2026-07-27T20:25:51.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60271",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle product permits a privilege escalation, but the public record does not identify the protected operation or authorization transition.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 574,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60272",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:08.880Z",
      "date_updated": "2026-07-23T19:32:12.512Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38443
      },
      "nvd": {
        "published": "2026-07-21T22:17:29.463",
        "lastModified": "2026-07-27T20:25:06.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60272",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An HTTP-reachable Oracle Coherence Core function executes without authenticating the caller.",
        "basis": [
          "CNA record",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60273",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:09.222Z",
      "date_updated": "2026-07-23T19:30:14.407Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21314
      },
      "nvd": {
        "published": "2026-07-21T22:17:29.573",
        "lastModified": "2026-07-27T20:24:31.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60273",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a security-sensitive endpoint without requiring caller authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 540,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60274",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:09.565Z",
      "date_updated": "2026-07-23T19:26:03.706Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38459
      },
      "nvd": {
        "published": "2026-07-21T22:17:29.680",
        "lastModified": "2026-07-27T20:23:53.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60274",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a TCP takeover path without authenticating the network caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60275",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:09.898Z",
      "date_updated": "2026-07-23T19:25:09.619Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38446
      },
      "nvd": {
        "published": "2026-07-21T22:17:29.793",
        "lastModified": "2026-07-27T20:23:24.597",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60275",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated HTTP takeover of Coherence Core, but the CPU does not disclose the critical function or authentication gate that fails.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html - Oracle confirms unauthenticated HTTP takeover of Coherence Core and the affected versions, but publishes no critical function or missing authentication gate."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60276",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:10.272Z",
      "date_updated": "2026-07-24T17:45:16.332Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25613
      },
      "nvd": {
        "published": "2026-07-21T22:17:29.903",
        "lastModified": "2026-07-24T18:17:55.510",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60276",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable security-sensitive operation is exposed without the authentication step required before invoking it.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 540,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60277",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:10.699Z",
      "date_updated": "2026-07-23T17:50:59.995Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21315
      },
      "nvd": {
        "published": "2026-07-21T22:17:30.050",
        "lastModified": "2026-07-24T13:55:17.777",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60277",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An undisclosed Oracle Coherence Core critical function lacks the authentication required to restrict it beyond a network caller.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 540,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60278",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:11.038Z",
      "date_updated": "2026-07-23T17:51:52.726Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28162
      },
      "nvd": {
        "published": "2026-07-21T22:17:30.163",
        "lastModified": "2026-07-24T13:55:27.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60278",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP caller can take over Coherence Core, but Oracle does not disclose the endpoint, handler, or missing authentication gate.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle's July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms unauthenticated HTTP reachability of Coherence Core, CVSS 9.8, and takeover impact, but publishes no endpoint, request grammar, handler, or missing authentication gate."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60279",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:11.381Z",
      "date_updated": "2026-07-24T17:54:49.260Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25614
      },
      "nvd": {
        "published": "2026-07-21T22:17:30.270",
        "lastModified": "2026-07-24T18:17:55.663",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60279",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP request can take over Oracle Coherence, but Oracle does not publish the failing access-control check in Core.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html",
          "https://www.oracle.com/security-alerts/cpujul2026verbose.html"
        ],
        "deepDive": true,
        "notes": "Oracle CPU confirms unauthenticated HTTP reachability, affected releases, and total impact, but explicitly publishes only its risk matrix and no request, function, or failed check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60280",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:11.725Z",
      "date_updated": "2026-07-23T17:55:28.803Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38437
      },
      "nvd": {
        "published": "2026-07-21T22:17:30.383",
        "lastModified": "2026-07-24T13:39:41.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60280",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive Oracle Coherence operation is reachable through a path that does not enforce the required authentication.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Read Oracle July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html; it confirms unauthenticated HTTP/2 reachability in Coherence Core but does not name the critical operation left unauthenticated."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 529,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60281",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:12.063Z",
      "date_updated": "2026-07-23T17:56:13.757Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.2414
      },
      "nvd": {
        "published": "2026-07-21T22:17:30.490",
        "lastModified": "2026-07-24T13:39:52.263",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60281",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated adjacent-network caller can modify or read Oracle Coherence data, but the protected operation and failing check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 799,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60282",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.527Z",
      "date_published": "2026-07-21T21:34:12.417Z",
      "date_updated": "2026-07-27T14:07:47.271Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06396
      },
      "nvd": {
        "published": "2026-07-21T22:17:30.607",
        "lastModified": "2026-07-24T18:17:55.827",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60282",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Coherence permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 669,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60283",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:12.776Z",
      "date_updated": "2026-07-23T19:23:49.187Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24732
      },
      "nvd": {
        "published": "2026-07-21T22:17:30.723",
        "lastModified": "2026-07-24T19:21:47.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60283",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle says Coherence Core returns data to an unauthenticated HTTP caller but does not publish the output path or missing data boundary.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60284",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:13.463Z",
      "date_updated": "2026-07-23T19:22:45.833Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26355
      },
      "nvd": {
        "published": "2026-07-21T22:17:30.833",
        "lastModified": "2026-07-24T19:21:44.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60284",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 694,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60285",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:13.795Z",
      "date_updated": "2026-07-23T19:22:01.579Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38437
      },
      "nvd": {
        "published": "2026-07-21T22:17:30.947",
        "lastModified": "2026-07-24T19:21:41.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60285",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive function can be invoked without enforcing the caller authentication required for that operation.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60286",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:14.129Z",
      "date_updated": "2026-07-23T18:00:06.273Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38446
      },
      "nvd": {
        "published": "2026-07-21T22:17:31.053",
        "lastModified": "2026-07-24T13:40:04.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60286",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Coherence exposes a takeover path to an unauthenticated HTTP caller, but Oracle does not publish the route or omitted authentication decision.",
        "basis": [
          "CNA",
          "CWE-306",
          "https://www.oracle.com/security-alerts/cpujul2026.html",
          "https://www.oracle.com/security-alerts/cpujul2026verbose.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July CPU confirms Coherence Core, affected releases, unauthenticated HTTP reachability, and takeover impact but no route, credential flow, or missing check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60287",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:14.465Z",
      "date_updated": "2026-07-23T18:03:22.108Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38439
      },
      "nvd": {
        "published": "2026-07-21T22:17:31.163",
        "lastModified": "2026-07-24T13:40:16.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60287",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a security-sensitive operation without verifying that the network caller is authenticated.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60288",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:14.813Z",
      "date_updated": "2026-07-23T18:04:43.332Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38447
      },
      "nvd": {
        "published": "2026-07-21T22:17:31.273",
        "lastModified": "2026-07-24T13:40:30.607",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60288",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A critical Oracle Coherence function is reachable over TCP without the authentication required to protect it.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60289",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:15.142Z",
      "date_updated": "2026-07-23T18:07:58.724Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38447
      },
      "nvd": {
        "published": "2026-07-21T22:17:31.387",
        "lastModified": "2026-07-24T13:40:38.260",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60289",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a critical HTTP function without requiring authentication before the operation executes.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60290",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:15.479Z",
      "date_updated": "2026-07-23T19:10:37.999Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38454
      },
      "nvd": {
        "published": "2026-07-21T22:17:31.497",
        "lastModified": "2026-07-27T20:22:52.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60290",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP caller can reach a critical Coherence Core operation without an authentication gate, although the function is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60291",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:15.832Z",
      "date_updated": "2026-07-25T03:56:08.458Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00508,
        "percentile": 0.40579
      },
      "nvd": {
        "published": "2026-07-21T22:17:31.603",
        "lastModified": "2026-07-28T14:13:19.493",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60291",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An HTTP-exposed WebLogic Core operation is reachable without the authentication required for takeover-capable actions, although the exact operation is not public.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms WebLogic Core over HTTP, no privileges, affected versions, and takeover impact, but publishes no endpoint, authentication check, or patch source."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60292",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:16.171Z",
      "date_updated": "2026-07-25T03:56:07.666Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00522,
        "percentile": 0.41415
      },
      "nvd": {
        "published": "2026-07-21T22:17:31.713",
        "lastModified": "2026-07-28T14:11:56.257",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60292",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle WebLogic Server exposes a critical HTTP operation without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60293",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:16.519Z",
      "date_updated": "2026-07-23T18:33:51.610Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS - Web Services).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34493
      },
      "nvd": {
        "published": "2026-07-21T22:17:31.827",
        "lastModified": "2026-07-28T14:11:34.730",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60293",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated HTTP data exposure in WebLogic Web Services, but the CPU table does not identify the response or data-selection error.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 735,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60294",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:16.865Z",
      "date_updated": "2026-07-25T03:56:06.895Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00508,
        "percentile": 0.40579
      },
      "nvd": {
        "published": "2026-07-21T22:17:31.940",
        "lastModified": "2026-07-28T14:11:12.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60294",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable Oracle WebLogic Core SOAP operation can be invoked without the authentication required for a takeover-capable function.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle's July 2026 CPU at https://www.oracle.com/security-alerts/cpujul2026.html; the row confirms WebLogic Core, SOAP, no authentication, CVSS 9.8, and high confidentiality/integrity/availability impact, but it does not identify the SOAP action, authentication gate, or patch logic."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60295",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:17.200Z",
      "date_updated": "2026-07-23T18:37:48.700Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23503
      },
      "nvd": {
        "published": "2026-07-21T22:17:32.050",
        "lastModified": "2026-07-24T13:41:36.687",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60295",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Coherence grants a low-privilege TCP caller authority sufficient for takeover, while the object and failing access check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 645,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60296",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:17.595Z",
      "date_updated": "2026-07-30T16:53:29.515Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0045,
        "percentile": 0.36921
      },
      "nvd": {
        "published": "2026-07-21T22:17:32.160",
        "lastModified": "2026-07-30T19:18:34.000",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60296",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence reaches a protected operation without completing the authentication state or credential validation required for that path.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60297",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:17.927Z",
      "date_updated": "2026-07-23T18:41:24.655Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38451
      },
      "nvd": {
        "published": "2026-07-21T22:17:32.277",
        "lastModified": "2026-07-24T13:13:08.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60297",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Coherence exposes a critical function over TCP without the required authentication, although the function is not public.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60298",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:18.264Z",
      "date_updated": "2026-07-23T18:42:29.857Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.3845
      },
      "nvd": {
        "published": "2026-07-21T22:17:32.387",
        "lastModified": "2026-07-24T13:29:22.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60298",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence exposes a critical TCP function without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 526,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60299",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.528Z",
      "date_published": "2026-07-21T21:34:18.600Z",
      "date_updated": "2026-07-23T18:43:35.621Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38451
      },
      "nvd": {
        "published": "2026-07-21T22:17:32.493",
        "lastModified": "2026-07-24T13:29:34.767",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60299",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Coherence Core exposes takeover-capable functionality over TCP without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 526,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60300",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:18.944Z",
      "date_updated": "2026-07-23T18:44:55.409Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38452
      },
      "nvd": {
        "published": "2026-07-21T22:17:32.603",
        "lastModified": "2026-07-24T13:41:43.377",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60300",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Coherence exposes a TCP path that permits takeover without authentication, while the July CPU does not disclose the missing gate or handler.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the CPU confirms unauthenticated TCP reachability and affected Coherence versions without publishing the missing authentication gate."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60301",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:19.299Z",
      "date_updated": "2026-07-23T18:46:44.180Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0045,
        "percentile": 0.36945
      },
      "nvd": {
        "published": "2026-07-21T22:17:32.707",
        "lastModified": "2026-07-24T13:41:51.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60301",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthenticated TCP-triggered resource exhaustion in Coherence Core but does not publish the unbounded operation.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 581,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60302",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:19.670Z",
      "date_updated": "2026-07-23T18:50:10.849Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38451
      },
      "nvd": {
        "published": "2026-07-21T22:17:32.817",
        "lastModified": "2026-07-27T20:22:31.167",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60302",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an unauthenticated Coherence Core takeover over TCP but does not publish the missing authentication check or reachable operation.",
        "basis": [
          "CNA",
          "CWE-306",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.oracle.com/security-alerts/cpujul2026.html. Oracle's public risk matrix confirms unauthenticated TCP reachability and takeover impact but intentionally does not disclose the failing Core check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60303",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:20.013Z",
      "date_updated": "2026-07-23T18:48:24.009Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.2093
      },
      "nvd": {
        "published": "2026-07-21T22:17:32.930",
        "lastModified": "2026-07-27T20:21:58.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60303",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled input can consume finite work or memory without an effective bound, release or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60304",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:20.359Z",
      "date_updated": "2026-07-23T18:47:33.771Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20968
      },
      "nvd": {
        "published": "2026-07-21T22:17:33.037",
        "lastModified": "2026-07-24T19:21:53.743",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60304",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle Coherence but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 580,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60305",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:20.694Z",
      "date_updated": "2026-07-23T18:45:08.398Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11802
      },
      "nvd": {
        "published": "2026-07-21T22:17:33.153",
        "lastModified": "2026-07-27T20:21:30.640",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60305",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged TCP caller can read and modify Coherence data beyond its authority, but Oracle does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 692,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60306",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:21.063Z",
      "date_updated": "2026-07-23T18:41:55.156Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31112
      },
      "nvd": {
        "published": "2026-07-21T22:17:33.263",
        "lastModified": "2026-07-27T20:20:59.953",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60306",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A remotely reachable Coherence TCP critical function lacks the authentication required before takeover-capable processing.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60307",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:21.401Z",
      "date_updated": "2026-07-23T18:40:02.887Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14962
      },
      "nvd": {
        "published": "2026-07-21T22:17:33.380",
        "lastModified": "2026-07-27T20:20:38.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60307",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle product exposes protected data, but the public record does not identify the endpoint, condition, or observer.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 555,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60308",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:21.739Z",
      "date_updated": "2026-07-23T18:38:34.320Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31112
      },
      "nvd": {
        "published": "2026-07-21T22:17:33.490",
        "lastModified": "2026-07-27T20:20:15.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60308",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An HTTP-reachable Oracle Coherence Core function executes without authenticating the caller.",
        "basis": [
          "CNA record",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:22.080Z",
      "date_updated": "2026-07-23T18:37:18.394Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Coherence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25524
      },
      "nvd": {
        "published": "2026-07-21T22:17:33.603",
        "lastModified": "2026-07-27T20:19:50.853",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60309",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Coherence permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 621,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60310",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:22.418Z",
      "date_updated": "2026-07-23T17:47:47.144Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Performance Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03606
      },
      "nvd": {
        "published": "2026-07-21T22:17:33.720",
        "lastModified": "2026-07-23T18:30:41.573",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60310",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Performance Management lets a low-privileged HTTP caller cross its intended data scope, but the failing decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 691,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60311",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:22.759Z",
      "date_updated": "2026-07-23T17:46:32.772Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25327
      },
      "nvd": {
        "published": "2026-07-21T22:17:33.837",
        "lastModified": "2026-07-27T17:14:49.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60311",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports repeatable MySQL optimizer hangs or crashes, but the CPU does not identify the attacker-controlled work, memory, or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60312",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:23.093Z",
      "date_updated": "2026-07-25T03:56:05.295Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14698
      },
      "nvd": {
        "published": "2026-07-21T22:17:33.950",
        "lastModified": "2026-07-28T14:10:44.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60312",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable security-sensitive operation is exposed without the authentication step required before invoking it.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 563,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60313",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:23.427Z",
      "date_updated": "2026-07-25T03:56:04.466Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15756
      },
      "nvd": {
        "published": "2026-07-21T22:17:34.063",
        "lastModified": "2026-07-28T14:10:18.210",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60313",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An undisclosed WebLogic Core critical function lacks the authentication required to restrict it beyond a low-privileged RMI caller.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 555,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60314",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:23.773Z",
      "date_updated": "2026-07-23T19:18:34.907Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00365,
        "percentile": 0.29219
      },
      "nvd": {
        "published": "2026-07-21T22:17:34.173",
        "lastModified": "2026-07-28T17:19:35.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60314",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The MySQL Router path lets attacker-controlled work exhaust or terminate a finite service resource.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60315",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:24.115Z",
      "date_updated": "2026-07-23T19:26:52.260Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16864
      },
      "nvd": {
        "published": "2026-07-21T22:17:34.283",
        "lastModified": "2026-07-27T17:14:16.147",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60315",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle publishes denial-of-service and read impact for X Plugin without the input, parser, state transition, or failing check.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 787,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60316",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.529Z",
      "date_published": "2026-07-21T21:34:24.466Z",
      "date_updated": "2026-07-28T03:56:33.319Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00368,
        "percentile": 0.29458
      },
      "nvd": {
        "published": "2026-07-21T22:17:34.400",
        "lastModified": "2026-07-28T05:17:08.993",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60316",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The MySQL Server operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 635,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60317",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:24.797Z",
      "date_updated": "2026-07-25T03:56:15.746Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Connectors"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17273
      },
      "nvd": {
        "published": "2026-07-21T22:17:34.510",
        "lastModified": "2026-08-03T15:17:36.597",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60317",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated network caller can modify or read MySQL Connector/Net data, but the protocol operation and failing access check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 691,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60318",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:25.408Z",
      "date_updated": "2026-07-23T19:35:26.416Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Data Integrator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03622
      },
      "nvd": {
        "published": "2026-07-21T22:17:34.630",
        "lastModified": "2026-07-30T20:12:22.497",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60318",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Data Integrator exposes protected data to an unintended observer, while the field and output path are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 605,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60319",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:25.764Z",
      "date_updated": "2026-07-23T19:36:10.978Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Data Integrator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.0361
      },
      "nvd": {
        "published": "2026-07-21T22:17:34.737",
        "lastModified": "2026-07-30T20:14:24.313",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60319",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged local user can read all Patchset Assistant data but does not publish the object or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 752,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60320",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:26.121Z",
      "date_updated": "2026-07-27T14:07:51.905Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Data Integrator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24535
      },
      "nvd": {
        "published": "2026-07-21T22:17:34.853",
        "lastModified": "2026-07-30T20:15:07.833",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60320",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 587,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60321",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:26.829Z",
      "date_updated": "2026-07-23T18:50:37.851Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Manufacturing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02616
      },
      "nvd": {
        "published": "2026-07-21T22:17:34.967",
        "lastModified": "2026-07-31T13:28:42.080",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60321",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 783,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60322",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:27.170Z",
      "date_updated": "2026-07-23T18:52:31.231Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11902
      },
      "nvd": {
        "published": "2026-07-21T22:17:35.103",
        "lastModified": "2026-08-03T17:50:35.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60322",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A security-sensitive operation is reachable without authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 703,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60323",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:27.525Z",
      "date_updated": "2026-08-01T03:55:56.134Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19468
      },
      "nvd": {
        "published": "2026-07-21T22:17:35.250",
        "lastModified": "2026-08-01T05:16:57.417",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60323",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Identity Manager permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 729,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60324",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:27.895Z",
      "date_updated": "2026-07-23T18:57:56.235Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15885
      },
      "nvd": {
        "published": "2026-07-21T22:17:35.363",
        "lastModified": "2026-07-27T17:12:43.713",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60324",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege optimizer request can repeatedly crash or hang MySQL, but Oracle does not publish the unbounded query path.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 632,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60325",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:28.346Z",
      "date_updated": "2026-07-28T03:57:01.780Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20314
      },
      "nvd": {
        "published": "2026-07-21T22:17:35.480",
        "lastModified": "2026-07-28T05:17:09.117",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60325",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports that an adjacent low-privileged caller can take over Access Manager but discloses no request, identity binding, or failed control.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60326",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:28.686Z",
      "date_updated": "2026-07-28T03:57:02.829Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24535
      },
      "nvd": {
        "published": "2026-07-21T22:17:35.593",
        "lastModified": "2026-07-28T05:17:09.237",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60326",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Access Manager Authentication Engine accepts an unauthenticated HTTP path to protected data operations, but Oracle does not publish the failing identity check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-287",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official table confirms the component, HTTP exposure, unauthenticated reachability, score, and versions but gives no causal check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 730,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60327",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:29.046Z",
      "date_updated": "2026-07-29T19:26:41.147Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24535
      },
      "nvd": {
        "published": "2026-07-21T22:17:35.707",
        "lastModified": "2026-07-29T20:17:06.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60327",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Access Manager operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 710,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:29.398Z",
      "date_updated": "2026-07-28T03:57:04.649Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28166
      },
      "nvd": {
        "published": "2026-07-21T22:17:35.810",
        "lastModified": "2026-07-28T05:17:09.463",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60328",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A network caller can bypass Oracle Access Manager authentication, but Oracle does not disclose the failed identity proof or session check.",
        "basis": [
          "CNA",
          "CWE-287",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the Oracle risk matrix confirms an unauthenticated HTTP path in the Access Manager Authentication Engine but gives no identity-proof or session-check detail."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 547,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60329",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:29.751Z",
      "date_updated": "2026-08-01T03:55:57.264Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.2816
      },
      "nvd": {
        "published": "2026-07-21T22:17:35.920",
        "lastModified": "2026-08-01T05:16:57.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60329",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60330",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:30.090Z",
      "date_updated": "2026-08-01T03:55:58.336Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23501
      },
      "nvd": {
        "published": "2026-07-21T22:17:36.033",
        "lastModified": "2026-08-01T05:16:57.670",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60330",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60330 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 671,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60331",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:30.433Z",
      "date_updated": "2026-07-28T03:56:37.339Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03504
      },
      "nvd": {
        "published": "2026-07-21T22:17:36.143",
        "lastModified": "2026-07-28T05:17:09.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60331",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "MySQL replication grants a high-privilege local caller authority beyond its assigned role, while Oracle does not disclose the operation or check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 673,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60332",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.530Z",
      "date_published": "2026-07-21T21:34:30.791Z",
      "date_updated": "2026-07-28T03:56:38.228Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication GCS).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03504
      },
      "nvd": {
        "published": "2026-07-21T22:17:36.250",
        "lastModified": "2026-07-28T05:17:09.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60332",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to MySQL Server in its Server: Group Replication GCS component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 683,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60333",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:31.206Z",
      "date_updated": "2026-07-28T03:57:05.529Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33022
      },
      "nvd": {
        "published": "2026-07-21T22:17:36.360",
        "lastModified": "2026-07-28T05:17:09.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60333",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Access Manager authentication engine lets a low-privileged remote user cross an authorization boundary, but the advisory does not disclose the causal check.",
        "basis": [
          "CNA",
          "CWE-287",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Primary source inspected: https://www.oracle.com/security-alerts/cpujul2026.html. Oracle identifies the Access Manager Authentication Engine, HTTP, low privileges, and CVSS 9.9, but publishes no affected operation or causal check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 669,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60334",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:31.546Z",
      "date_updated": "2026-07-29T19:26:42.324Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31654
      },
      "nvd": {
        "published": "2026-07-21T22:17:36.473",
        "lastModified": "2026-07-29T20:17:06.833",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60334",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle WebCenter Content lets a low-privileged HTTP user take over the service, but the missing critical-function authorization boundary is not public.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60335",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:31.892Z",
      "date_updated": "2026-07-28T03:55:59.753Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24042
      },
      "nvd": {
        "published": "2026-07-21T22:17:36.587",
        "lastModified": "2026-07-28T05:17:10.057",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60335",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports a high-privileged HTTP takeover of WebCenter Content while the assigned missing-authentication CWE conflicts with the stated prerequisite and no causal check is public.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:32.232Z",
      "date_updated": "2026-07-24T17:27:58.339Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Manufacturing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03349
      },
      "nvd": {
        "published": "2026-07-21T22:17:36.707",
        "lastModified": "2026-07-31T13:28:31.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60336",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Project Manufacturing permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 783,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60337",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:32.580Z",
      "date_updated": "2026-07-24T17:31:18.424Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Manufacturing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03122
      },
      "nvd": {
        "published": "2026-07-21T22:17:36.807",
        "lastModified": "2026-07-31T13:29:51.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60337",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized Project Manufacturing data access by a privileged local user but does not publish the failing data check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 760,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60338",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:32.936Z",
      "date_updated": "2026-07-24T17:32:38.769Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Manufacturing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00091,
        "percentile": 0.00608
      },
      "nvd": {
        "published": "2026-07-21T22:17:36.920",
        "lastModified": "2026-07-31T13:28:15.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60338",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 744,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60339",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:33.282Z",
      "date_updated": "2026-07-24T17:35:52.081Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Manufacturing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14792
      },
      "nvd": {
        "published": "2026-07-21T22:17:37.030",
        "lastModified": "2026-07-31T13:28:04.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60339",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected interface returns, embeds or leaves protected information visible to an observer who is not entitled to receive it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60340",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:33.616Z",
      "date_updated": "2026-07-24T17:37:26.454Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Costing product of Oracle E-Business Suite (component: Enterprise Command Center).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Costing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24042
      },
      "nvd": {
        "published": "2026-07-21T22:17:37.137",
        "lastModified": "2026-07-24T18:17:57.457",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60340",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle Project Costing but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 541,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60342",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:33.961Z",
      "date_updated": "2026-07-24T17:40:14.256Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00306,
        "percentile": 0.22913
      },
      "nvd": {
        "published": "2026-07-21T22:17:37.250",
        "lastModified": "2026-07-27T13:23:09.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60342",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP caller can read Access Manager data, but Oracle does not disclose the privilege assignment or protected object.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 564,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60343",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:34.303Z",
      "date_updated": "2026-07-25T03:56:03.557Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.004,
        "percentile": 0.32802
      },
      "nvd": {
        "published": "2026-07-21T22:17:37.363",
        "lastModified": "2026-07-25T05:16:38.037",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60343",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged WebLogic HTTP caller can reach takeover-capable authority, but the missing subject, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60344",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:34.654Z",
      "date_updated": "2026-07-27T10:47:11.929Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (France)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12844
      },
      "nvd": {
        "published": "2026-07-21T22:17:37.467",
        "lastModified": "2026-07-27T17:48:21.007",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60344",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle HRMS allows access beyond the intended role boundary, but the public record does not disclose the failed authorization decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 662,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60345",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:34.986Z",
      "date_updated": "2026-07-27T10:53:19.899Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle JDeveloper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0043,
        "percentile": 0.35411
      },
      "nvd": {
        "published": "2026-07-21T22:17:37.577",
        "lastModified": "2026-07-27T12:16:47.397",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60345",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privilege HTTP user can acquire takeover authority in ADF Shared Components, but the exact failed authorization rule is not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60346",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:35.339Z",
      "date_updated": "2026-07-27T10:55:12.871Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Tools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21317
      },
      "nvd": {
        "published": "2026-07-21T22:17:37.690",
        "lastModified": "2026-07-27T12:16:47.820",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60346",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle identifies a JDENET-triggered partial denial of service in Interoperability Security but does not disclose the input, parser, resource, or termination failure.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 591,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60347",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:35.676Z",
      "date_updated": "2026-07-27T10:56:11.581Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Tools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00101,
        "percentile": 0.01059
      },
      "nvd": {
        "published": "2026-07-21T22:17:37.807",
        "lastModified": "2026-07-27T12:16:48.237",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60347",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "JD Edwards Tools lets a low-privileged local user modify data or availability beyond the role's scope, but the failing control is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 769,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:36.018Z",
      "date_updated": "2026-07-27T11:01:56.148Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle JDeveloper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22436
      },
      "nvd": {
        "published": "2026-07-21T22:17:37.920",
        "lastModified": "2026-07-27T12:16:48.643",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60348",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated access to all JDeveloper ADF Faces data, but the CPU does not identify the protected object or access-control decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:36.383Z",
      "date_updated": "2026-07-27T14:07:50.317Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle JDeveloper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23445
      },
      "nvd": {
        "published": "2026-07-21T22:17:38.030",
        "lastModified": "2026-07-31T21:14:44.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60349",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports JDeveloper disclosure and partial denial of service but does not identify the request or failing engineering rule.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 690,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60350",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.531Z",
      "date_published": "2026-07-21T21:34:37.085Z",
      "date_updated": "2026-07-24T18:46:05.485Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle JDeveloper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05741
      },
      "nvd": {
        "published": "2026-07-21T22:17:38.143",
        "lastModified": "2026-07-31T21:08:14.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60350",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ADF Faces returns critical data to a low-privileged local user, but the data object and output path are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 718,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:37.437Z",
      "date_updated": "2026-07-24T18:45:01.424Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle JDeveloper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11652
      },
      "nvd": {
        "published": "2026-07-21T22:17:38.250",
        "lastModified": "2026-07-31T21:08:03.013",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60351",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle JDeveloper path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 658,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:37.774Z",
      "date_updated": "2026-07-24T18:43:10.410Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle JDeveloper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18073
      },
      "nvd": {
        "published": "2026-07-21T22:17:38.363",
        "lastModified": "2026-07-31T21:07:53.263",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60352",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthorized data access but does not publish the output path, protected field, or causal access decision.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:40.730Z",
      "date_updated": "2026-07-24T18:41:16.169Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle JDeveloper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11623
      },
      "nvd": {
        "published": "2026-07-21T22:17:38.480",
        "lastModified": "2026-07-31T21:07:44.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60353",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle JDeveloper operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 541,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60354",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:42.221Z",
      "date_updated": "2026-07-24T18:40:36.033Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle JDeveloper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18074
      },
      "nvd": {
        "published": "2026-07-21T22:17:38.590",
        "lastModified": "2026-07-31T21:07:33.230",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60354",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle JDeveloper returns a subset of protected data to an unauthenticated HTTP caller, but the data path and missing protection are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60355",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:43.097Z",
      "date_updated": "2026-07-28T03:57:09.316Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.3846
      },
      "nvd": {
        "published": "2026-07-21T22:17:38.713",
        "lastModified": "2026-07-28T20:00:08.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60355",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Access Manager exposes its Authentication Engine over HTTP to unauthenticated takeover, while the July CPU does not publish the failing gate or request path.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms unauthenticated HTTP exposure in the Access Manager Authentication Engine, CVSS 9.8, and affected versions but publishes no endpoint or failing authentication decision."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 547,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60356",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:43.447Z",
      "date_updated": "2026-07-29T19:26:40.999Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32429
      },
      "nvd": {
        "published": "2026-07-21T22:17:38.830",
        "lastModified": "2026-07-29T20:17:06.967",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60356",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated HTTP access to Authentication Engine data but does not publish the endpoint or authentication failure.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 710,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60357",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:43.792Z",
      "date_updated": "2026-07-24T18:33:41.548Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel Server Sync for Exchange).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14142
      },
      "nvd": {
        "published": "2026-07-21T22:17:38.940",
        "lastModified": "2026-07-24T19:17:00.917",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60357",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60358",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:44.139Z",
      "date_updated": "2026-07-28T03:57:11.590Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.3844
      },
      "nvd": {
        "published": "2026-07-21T22:17:39.057",
        "lastModified": "2026-07-28T19:58:58.563",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60358",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Access Manager's Authentication Engine exposes an unauthenticated HTTP access-control failure, while the CPU does not disclose the endpoint or authentication transition.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle Critical Patch Update July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. The CPU identifies Access Manager Authentication Engine over HTTP, unauthenticated access, score 10, and affected 12.2.1.4.0/14.1.2.1.0, but no endpoint or failing authentication check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 671,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:44.480Z",
      "date_updated": "2026-07-29T19:14:23.231Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32429
      },
      "nvd": {
        "published": "2026-07-21T22:17:39.177",
        "lastModified": "2026-07-29T20:17:07.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60359",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A security-sensitive operation is reachable without authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 709,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60360",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:44.816Z",
      "date_updated": "2026-07-24T18:29:01.416Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38439
      },
      "nvd": {
        "published": "2026-07-21T22:17:39.293",
        "lastModified": "2026-07-28T19:08:59.577",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60360",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Unified Directory exposes a security-sensitive operation without verifying that the network caller is authenticated.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 670,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60361",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:45.162Z",
      "date_updated": "2026-07-29T03:55:45.494Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33033
      },
      "nvd": {
        "published": "2026-07-21T22:17:39.407",
        "lastModified": "2026-07-29T05:16:50.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60361",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A critical Unified Directory operation is reachable by a low-privilege LDAP caller without the authentication level required for that function.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 668,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60362",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:45.507Z",
      "date_updated": "2026-07-29T03:55:47.052Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38438
      },
      "nvd": {
        "published": "2026-07-21T22:17:39.527",
        "lastModified": "2026-07-29T05:16:50.890",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60362",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Unified Directory exposes a critical LDAP function without requiring authentication before the operation executes.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60363",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:45.872Z",
      "date_updated": "2026-08-01T03:55:46.279Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HTTP Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00355,
        "percentile": 0.28195
      },
      "nvd": {
        "published": "2026-07-21T22:17:39.633",
        "lastModified": "2026-08-01T05:16:57.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60363",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle HTTP Server Apache Plugin exposes protected HTTP functionality to an unauthenticated caller, but the missing access decision is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official table confirms the Apache Plugin, HTTP protocol, unauthenticated reachability, score, and versions but no implementation mechanism."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60364",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:46.229Z",
      "date_updated": "2026-08-01T03:55:47.494Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HTTP Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Weblogic Server Proxy Plug-in"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25657
      },
      "nvd": {
        "published": "2026-07-21T22:17:39.747",
        "lastModified": "2026-08-01T05:16:57.913",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60364",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An HTTP path in the WebLogic proxy plug-in or Oracle HTTP Server accepts a caller that can modify protected data, but the exact access-control check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. Oracle lists this CVE for both Oracle HTTP Server Core at CVSS 9.8 and the WebLogic proxy plug-in at CVSS 7.5, but publishes no failing access-control check or patch source."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 678,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-60365",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.532Z",
      "date_published": "2026-07-21T21:34:46.574Z",
      "date_updated": "2026-08-01T03:55:48.639Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HTTP Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Weblogic Server Proxy Plug-in"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30471
      },
      "nvd": {
        "published": "2026-07-21T22:17:39.860",
        "lastModified": "2026-08-01T05:16:58.043",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60365",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The WebLogic proxy plug-in exposes a critical HTTP operation without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 951,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60366",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-22T22:23:50.502Z",
      "date_updated": "2026-07-23T14:37:07.291Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Platform Security for Java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23413
      },
      "nvd": {
        "published": "2026-07-22T23:16:35.757",
        "lastModified": "2026-07-23T19:01:53.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60366",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports unauthenticated HTTP takeover of Platform Security for Java, but the public record's disparate CWE labels do not identify the first failing check or parser.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306",
          "CWE-502",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html - Oracle confirms the Platform Security for Java component and HTTP attack surface, but the advisory does not resolve the record's disparate authentication, authorization, privilege, and deserialization labels into one causal path."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 725,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60367",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-22T22:24:08.141Z",
      "date_updated": "2026-07-23T14:36:14.349Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Platform Security for Java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24086
      },
      "nvd": {
        "published": "2026-07-22T23:16:35.870",
        "lastModified": "2026-07-24T15:17:53.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60367",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record identifies an unauthenticated HTTP takeover path in centralized third-party jars, but it does not disclose whether missing authentication, unsafe deserialization, or another flaw is the enabling cause.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-269",
          "CWE-287",
          "CWE-306",
          "CWE-502",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle's July 2026 CPU at https://www.oracle.com/security-alerts/cpujul2026.html; it confirms Platform Security for Java, Centralized Thirdparty Jars, HTTP, no authentication, and CVSS 9.8, while the embedded CWE set spans privilege, authentication, and deserialization and the CPU supplies no operation or check that resolves the ambiguity."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60368",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-22T22:24:25.128Z",
      "date_updated": "2026-07-23T14:35:26.958Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Platform Security for Java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1104",
          "name": "Use of Unmaintained Third Party Components",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.2335
      },
      "nvd": {
        "published": "2026-07-22T23:16:35.980",
        "lastModified": "2026-07-24T15:17:48.807",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60368",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Platform Security depends on an unmaintained third-party component whose inherited behavior permits platform takeover.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-1104"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 588,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60369",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-22T22:24:25.451Z",
      "date_updated": "2026-07-23T14:34:44.889Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Platform Security for Java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20154
      },
      "nvd": {
        "published": "2026-07-22T23:16:36.087",
        "lastModified": "2026-07-24T15:17:44.540",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60369",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle's record associates Oracle Platform Security for Java in its Centralized Thirdparty Jars component with unsafe interpreted input, but does not disclose the parser, object format, or sink.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-269",
          "CWE-284",
          "CWE-502",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Read https://www.oracle.com/security-alerts/cpujul2026.html; Oracle's CPU identifies the Centralized Thirdparty Jars component and HTTP access but does not disclose the serialized object or sink behind the aggregated CWE data."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 723,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60370",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-22T22:24:25.772Z",
      "date_updated": "2026-07-23T14:33:59.271Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Platform Security for Java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1021",
          "name": "Improper Restriction of Rendered UI Layers or Frames",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10133
      },
      "nvd": {
        "published": "2026-07-22T23:16:36.203",
        "lastModified": "2026-07-24T15:17:40.567",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60370",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component does not enforce the intended restriction on which external site may frame or navigate its rendered interface.",
        "basis": [
          "CNA",
          "CWE-1021"
        ],
        "deepDive": false,
        "notes": "Editor attention: CWE-1021 indicates a frame or navigation restriction, while the embedded CVSS says no user interaction and the prose mentions takeover; confirm that the impact and vector belong to the same analysis."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-22T22:24:26.099Z",
      "date_updated": "2026-07-23T14:29:43.268Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Platform Security for Java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06683
      },
      "nvd": {
        "published": "2026-07-22T23:16:36.317",
        "lastModified": "2026-07-24T15:17:35.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60371",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Oracle record reports takeover through centralized third-party jars but lists only broad impact-oriented weaknesses and no defensible engineering cause.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 824,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60372",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-22T22:24:26.428Z",
      "date_updated": "2026-07-23T14:32:58.133Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Platform Security for Java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23412
      },
      "nvd": {
        "published": "2026-07-22T23:16:36.420",
        "lastModified": "2026-07-24T15:17:31.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60372",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports unauthenticated HTTP takeover of Platform Security for Java but provides several incompatible weakness classes and no causal path.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306",
          "CWE-502",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official table confirms the Centralized Thirdparty Jars component, HTTP, no authentication, and takeover, but does not distinguish authorization, missing authentication, unsafe deserialization, or another cause."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60373",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-22T22:24:26.756Z",
      "date_updated": "2026-07-23T14:32:06.647Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Platform Security for Java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20154
      },
      "nvd": {
        "published": "2026-07-22T23:16:36.530",
        "lastModified": "2026-07-24T15:17:27.373",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60373",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle attributes Platform Security for Java takeover to a bundled third-party deserialization weakness, while the public CPU omits the object type and reachable deserializer.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-306",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 588,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60374",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-21T21:34:49.517Z",
      "date_updated": "2026-07-24T17:03:39.382Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28163
      },
      "nvd": {
        "published": "2026-07-21T22:17:39.980",
        "lastModified": "2026-07-28T17:47:18.873",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60374",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle states that the Messaging Enabler accepts an unauthenticated T3 or IIOP attack leading to takeover but does not disclose the endpoint or missing authentication check.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html was inspected; Oracle exposes the component, T3/IIOP channel, versions, and CVSS conditions but no endpoint or failing authentication check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60375",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-21T21:34:52.217Z",
      "date_updated": "2026-07-24T17:02:41.624Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38447
      },
      "nvd": {
        "published": "2026-07-21T22:17:40.097",
        "lastModified": "2026-07-28T17:54:43.887",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60375",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an unauthenticated Messaging Enabler takeover over T3/IIOP but does not publish the missing authentication check or operation.",
        "basis": [
          "CNA",
          "CWE-306",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.oracle.com/security-alerts/cpujul2026.html. Oracle's public risk matrix confirms unauthenticated T3/IIOP reachability and takeover impact but does not disclose the failing Messaging Enabler check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60376",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-21T21:34:52.558Z",
      "date_updated": "2026-07-24T16:58:52.842Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.3846
      },
      "nvd": {
        "published": "2026-07-21T22:17:40.207",
        "lastModified": "2026-07-28T17:54:54.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60376",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive function can be invoked without enforcing the caller authentication required for that operation.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-21T21:34:54.688Z",
      "date_updated": "2026-07-24T16:57:12.826Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28746
      },
      "nvd": {
        "published": "2026-07-21T22:17:40.350",
        "lastModified": "2026-07-28T17:55:03.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60377",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle's Messaging Enabler lets a low-privileged T3 or IIOP caller cross an undisclosed authorization boundary into broader Service Delivery Platform data and actions.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July CPU adds the Messaging Enabler component, T3/IIOP route, low required privilege, and affected versions, but no failing authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 991,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-21T21:34:56.624Z",
      "date_updated": "2026-07-24T16:55:08.181Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38457
      },
      "nvd": {
        "published": "2026-07-21T22:17:40.480",
        "lastModified": "2026-07-28T17:55:15.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60378",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Service Delivery Platform exposes a critical operation without completing the authentication check required for that operation.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 555,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60379",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-21T21:34:56.962Z",
      "date_updated": "2026-07-24T13:57:23.026Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38458
      },
      "nvd": {
        "published": "2026-07-21T22:17:40.597",
        "lastModified": "2026-07-28T17:56:02.137",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60379",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A remotely reachable Service Delivery Platform SOAP critical function lacks the authentication required before takeover-capable processing.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 683,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-21T21:34:57.319Z",
      "date_updated": "2026-07-24T13:58:19.808Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28164
      },
      "nvd": {
        "published": "2026-07-21T22:17:40.713",
        "lastModified": "2026-07-28T17:55:25.047",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60380",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A critical Oracle operation is exposed without the authentication required for that function.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 555,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60381",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-21T21:34:57.662Z",
      "date_updated": "2026-07-24T14:00:10.227Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22443
      },
      "nvd": {
        "published": "2026-07-21T22:17:40.827",
        "lastModified": "2026-07-28T17:56:15.487",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60381",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege T3 or IIOP user can acquire takeover authority in Messaging Enabler, but the failing authorization check is not public.",
        "basis": [
          "CNA record",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official matrix confirms Service Delivery Platform Messaging Enabler, T3/IIOP, low privileges, and affected versions but provides no causal check or code path."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 685,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.533Z",
      "date_published": "2026-07-21T21:34:58.012Z",
      "date_updated": "2026-07-24T14:00:53.249Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0045,
        "percentile": 0.36945
      },
      "nvd": {
        "published": "2026-07-21T22:17:40.940",
        "lastModified": "2026-07-28T17:56:24.007",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60382",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says attacker-driven input can exhaust or stop Service Delivery Platform but does not identify the unbounded allocation, queue, loop, or unreleased resource.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 598,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:34:58.352Z",
      "date_updated": "2026-07-24T14:01:46.828Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01985
      },
      "nvd": {
        "published": "2026-07-21T22:17:41.053",
        "lastModified": "2026-07-28T17:56:30.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60383",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Service Delivery Platform grants a low-privileged local user access to critical data beyond the role's scope, but the failing control is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 913,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60384",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:34:58.688Z",
      "date_updated": "2026-07-24T16:52:37.277Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38448
      },
      "nvd": {
        "published": "2026-07-21T22:17:41.167",
        "lastModified": "2026-07-28T17:56:37.273",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60384",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated T3/IIOP takeover of the Service Delivery Platform Messaging Enabler, but the CPU does not disclose the message handler or missing authentication gate.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html - Oracle confirms unauthenticated T3/IIOP takeover of the Service Delivery Platform Messaging Enabler, but publishes no endpoint, message type, or authentication gate."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60385",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:34:59.028Z",
      "date_updated": "2026-07-24T16:51:56.185Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38457
      },
      "nvd": {
        "published": "2026-07-21T22:17:41.280",
        "lastModified": "2026-07-28T17:56:43.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60385",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable security-sensitive operation is exposed without the authentication step required before invoking it.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60386",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:34:59.364Z",
      "date_updated": "2026-07-24T16:51:02.029Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38457
      },
      "nvd": {
        "published": "2026-07-21T22:17:41.387",
        "lastModified": "2026-07-28T17:56:49.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60386",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An undisclosed Messaging Enabler critical function is reachable over HTTP without authentication, allowing takeover under the published conditions.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 555,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60387",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:34:59.688Z",
      "date_updated": "2026-07-24T16:49:59.938Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.2816
      },
      "nvd": {
        "published": "2026-07-21T22:17:41.500",
        "lastModified": "2026-07-30T17:33:20.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60387",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated T3/IIOP caller can take over the Service Delivery Platform Messaging Enabler, but Oracle does not disclose the message, handler, or missing gate.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle's July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms unauthenticated T3/IIOP reachability of the Service Delivery Platform Messaging Enabler, CVSS 9.8, and takeover impact, but publishes no message type, deserializer, handler, or missing authentication gate."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60388",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:35:00.051Z",
      "date_updated": "2026-07-24T16:46:34.292Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28161
      },
      "nvd": {
        "published": "2026-07-21T22:17:41.610",
        "lastModified": "2026-07-30T17:33:29.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60388",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected Oracle endpoint permits a protected operation without authenticating the remote caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:35:00.447Z",
      "date_updated": "2026-07-24T18:28:26.101Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38444
      },
      "nvd": {
        "published": "2026-07-21T22:17:41.717",
        "lastModified": "2026-07-31T21:10:02.543",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60389",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive Service Delivery Platform operation is reachable through a path that does not enforce the required authentication.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Read Oracle July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html; it identifies the Service Delivery Platform Messaging Enabler over HTTP but does not publish the critical operation left unauthenticated."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 683,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:35:00.788Z",
      "date_updated": "2026-07-24T16:44:25.915Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle GoldenGate (component: Admin Server Executable).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GoldenGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24731
      },
      "nvd": {
        "published": "2026-07-21T22:17:41.827",
        "lastModified": "2026-07-31T18:48:58.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60394",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle GoldenGate returns a subset of protected data to an unauthenticated HTTPS caller, but the data path and missing protection are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 517,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:35:01.131Z",
      "date_updated": "2026-07-24T16:40:01.691Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle GoldenGate (component: Admin Server Executable).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GoldenGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21229
      },
      "nvd": {
        "published": "2026-07-21T22:17:41.940",
        "lastModified": "2026-07-31T18:47:20.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60395",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle GoldenGate exposes protected data to an unintended observer, while the field and output path are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:35:01.463Z",
      "date_updated": "2026-07-25T03:55:32.397Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle GoldenGate (component: Distribution Server executable).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GoldenGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26499
      },
      "nvd": {
        "published": "2026-07-21T22:17:42.053",
        "lastModified": "2026-07-31T18:13:47.013",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60396",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a high-privileged HTTPS user can take over the GoldenGate Distribution Server but does not publish the operation or permission check.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 507,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:35:01.803Z",
      "date_updated": "2026-07-24T16:29:55.190Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle GoldenGate (component: Admin Server Executable).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GoldenGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00227,
        "percentile": 0.13576
      },
      "nvd": {
        "published": "2026-07-21T22:17:42.163",
        "lastModified": "2026-07-31T18:12:55.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60397",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation lets attacker-controlled work or allocation grow without an effective per-request bound or termination condition.",
        "basis": [
          "CNA",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:35:02.134Z",
      "date_updated": "2026-07-24T16:29:11.741Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservices).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GoldenGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33077
      },
      "nvd": {
        "published": "2026-07-21T22:17:42.277",
        "lastModified": "2026-08-03T19:02:32.783",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60398",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle GoldenGate permits a low-privileged HTTP caller to take over the service, while the public CPU does not support the record's missing-authentication label with an endpoint or authentication transition.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:35:02.477Z",
      "date_updated": "2026-07-24T16:28:26.061Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle GoldenGate (component: Receiver Service Executable).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GoldenGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22632
      },
      "nvd": {
        "published": "2026-07-21T22:17:42.383",
        "lastModified": "2026-07-31T18:11:18.263",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60399",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled work or allocation lacks an effective bound, release, or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 567,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.534Z",
      "date_published": "2026-07-21T21:35:02.866Z",
      "date_updated": "2026-07-27T14:07:44.488Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle GoldenGate (component: Admin Server Executable).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GoldenGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22487
      },
      "nvd": {
        "published": "2026-07-21T22:17:42.497",
        "lastModified": "2026-07-31T18:06:14.640",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60400",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle GoldenGate permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 521,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60401",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:03.202Z",
      "date_updated": "2026-07-24T16:23:02.553Z",
      "publisher": "oracle",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "TimesTen In-Memory Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.045
      },
      "nvd": {
        "published": "2026-07-21T22:17:42.607",
        "lastModified": "2026-07-31T17:59:04.210",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60401",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege local user can read all Kubernetes Operator-accessible TimesTen data, but Oracle does not publish the missing object check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 774,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60402",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:03.540Z",
      "date_updated": "2026-07-24T16:22:11.276Z",
      "publisher": "oracle",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "TimesTen In-Memory Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22442
      },
      "nvd": {
        "published": "2026-07-21T22:17:42.717",
        "lastModified": "2026-07-31T17:54:27.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60402",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle identifies a low-privileged HTTPS takeover of the TimesTen Kubernetes Operator but does not disclose the operation or engineering failure.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the risk matrix names the TimesTen Kubernetes Operator, HTTPS, low privileges, and affected version but publishes no failing operation, check, or patch detail."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 688,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:03.892Z",
      "date_updated": "2026-07-24T16:18:19.367Z",
      "publisher": "oracle",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "TimesTen In-Memory Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22633
      },
      "nvd": {
        "published": "2026-07-21T22:17:42.830",
        "lastModified": "2026-07-31T17:53:33.370",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60403",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Kubernetes Operator request can force TimesTen into a repeatable hang or crash, but the exhausted resource or termination failure is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 602,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:04.222Z",
      "date_updated": "2026-07-24T14:02:19.207Z",
      "publisher": "oracle",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "TimesTen In-Memory Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33259
      },
      "nvd": {
        "published": "2026-07-21T22:17:42.943",
        "lastModified": "2026-07-31T20:10:58.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60404",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The TimesTen In-Memory Database path lets attacker-controlled work, memory, recursion, or retained resources grow without an effective bound or release condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 602,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60405",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:04.557Z",
      "date_updated": "2026-07-24T14:03:04.329Z",
      "publisher": "oracle",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "TimesTen In-Memory Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04516
      },
      "nvd": {
        "published": "2026-07-21T22:17:43.050",
        "lastModified": "2026-07-31T20:17:12.223",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60405",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports that a low-privileged local user can read TimesTen data but does not disclose the output path or enabling engineering failure.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 751,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60406",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:04.894Z",
      "date_updated": "2026-07-24T16:17:32.835Z",
      "publisher": "oracle",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "TimesTen In-Memory Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03338
      },
      "nvd": {
        "published": "2026-07-21T22:17:43.160",
        "lastModified": "2026-07-31T20:16:50.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60406",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that TimesTen In-Memory Database permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 606,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60407",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:05.247Z",
      "date_updated": "2026-07-24T16:16:20.911Z",
      "publisher": "oracle",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "TimesTen In-Memory Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.01001
      },
      "nvd": {
        "published": "2026-07-21T22:17:43.277",
        "lastModified": "2026-07-31T20:16:12.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60407",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60407 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 776,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60408",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:05.585Z",
      "date_updated": "2026-07-24T16:13:35.400Z",
      "publisher": "oracle",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "TimesTen In-Memory Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00225,
        "percentile": 0.13202
      },
      "nvd": {
        "published": "2026-07-21T22:17:43.390",
        "lastModified": "2026-07-31T20:15:53.097",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60408",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The TimesTen Kubernetes Operator returns a subset of protected data to a low-privilege HTTPS caller, while the output path is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:05.963Z",
      "date_updated": "2026-07-24T16:10:13.125Z",
      "publisher": "oracle",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "TimesTen In-Memory Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02037
      },
      "nvd": {
        "published": "2026-07-21T22:17:43.503",
        "lastModified": "2026-07-31T20:14:43.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60409",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to TimesTen In-Memory Database in its Kubernetes Operator component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 999,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:06.429Z",
      "date_updated": "2026-07-24T16:09:22.733Z",
      "publisher": "oracle",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "TimesTen In-Memory Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19548
      },
      "nvd": {
        "published": "2026-07-21T22:17:43.627",
        "lastModified": "2026-07-31T20:13:05.957",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60410",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Kubernetes Operator accepts work that can exhaust service capacity, but the public record does not identify the missing bound or release condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 591,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60411",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:06.764Z",
      "date_updated": "2026-07-24T16:08:12.140Z",
      "publisher": "oracle",
      "title": "Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "TimesTen In-Memory Database"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15969
      },
      "nvd": {
        "published": "2026-07-21T22:17:43.743",
        "lastModified": "2026-07-31T20:11:20.870",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60411",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle TimesTen accepts unauthenticated adjacent-network input that repeatedly hangs or crashes the server, but the unbounded resource is not public.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 685,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60416",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:07.104Z",
      "date_updated": "2026-07-28T03:57:12.332Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21313
      },
      "nvd": {
        "published": "2026-07-21T22:17:43.860",
        "lastModified": "2026-07-28T19:58:29.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60416",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Access Manager's Authentication Engine permits unauthenticated takeover, while the public record does not identify the credential or authentication decision that fails.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60417",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:07.445Z",
      "date_updated": "2026-07-29T03:55:48.571Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29279
      },
      "nvd": {
        "published": "2026-07-21T22:17:43.980",
        "lastModified": "2026-07-29T05:16:51.307",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60417",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Unified Directory permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 545,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.535Z",
      "date_published": "2026-07-21T21:35:07.784Z",
      "date_updated": "2026-07-29T03:55:50.090Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26501
      },
      "nvd": {
        "published": "2026-07-21T22:17:44.090",
        "lastModified": "2026-07-29T05:16:51.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60418",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a privileged LDAP path to Unified Directory takeover but does not publish the privilege assignment or authorization failure.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60419",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:08.133Z",
      "date_updated": "2026-07-29T03:55:50.897Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22443
      },
      "nvd": {
        "published": "2026-07-21T22:17:44.207",
        "lastModified": "2026-07-29T05:16:52.133",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60419",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60420",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:09.156Z",
      "date_updated": "2026-07-24T14:03:53.283Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20963
      },
      "nvd": {
        "published": "2026-07-21T22:17:44.320",
        "lastModified": "2026-07-28T13:27:54.433",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60420",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 831,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60421",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:11.486Z",
      "date_updated": "2026-07-29T03:55:51.942Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.128
      },
      "nvd": {
        "published": "2026-07-21T22:17:44.443",
        "lastModified": "2026-07-29T05:16:52.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60421",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle Unified Directory but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 856,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:12.578Z",
      "date_updated": "2026-07-29T03:55:53.471Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20161
      },
      "nvd": {
        "published": "2026-07-21T22:17:44.557",
        "lastModified": "2026-07-29T05:16:53.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60422",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged LDAP caller can alter and read Unified Directory data across a changed scope, but Oracle does not disclose the failed authorization decision.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; Oracle confirms OUD Core over LDAP, low privileges, scope change, affected 14.1.2.1.0, and 9.9 impact but does not disclose the authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 958,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:12.923Z",
      "date_updated": "2026-07-29T03:55:54.232Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22441
      },
      "nvd": {
        "published": "2026-07-21T22:17:44.680",
        "lastModified": "2026-07-29T05:16:53.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60423",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Unified Directory accepts an LDAP caller's authentication context for takeover-capable operations beyond that account's authority.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:13.288Z",
      "date_updated": "2026-07-29T03:55:55.020Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21314
      },
      "nvd": {
        "published": "2026-07-21T22:17:44.797",
        "lastModified": "2026-07-29T05:16:53.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60424",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A critical Oracle Unified Directory operation is exposed without the authentication required for that function.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 671,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:13.633Z",
      "date_updated": "2026-07-24T15:35:08.185Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26301
      },
      "nvd": {
        "published": "2026-07-21T22:17:44.910",
        "lastModified": "2026-07-28T13:26:59.593",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60425",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated LDAP request can exhaust Oracle Unified Directory availability, but the consumed resource or missing bound is not public.",
        "basis": [
          "CNA record",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60426",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:13.980Z",
      "date_updated": "2026-07-24T15:34:27.529Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12932
      },
      "nvd": {
        "published": "2026-07-21T22:17:45.017",
        "lastModified": "2026-07-28T13:26:45.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60426",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Unified Directory permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 831,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:14.338Z",
      "date_updated": "2026-07-29T03:55:58.563Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17701
      },
      "nvd": {
        "published": "2026-07-21T22:17:45.130",
        "lastModified": "2026-07-29T05:16:54.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60427",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Unified Directory permits an unauthenticated LDAP caller to read or modify critical data, but the failing authorization path is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 857,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:14.678Z",
      "date_updated": "2026-07-24T15:50:38.958Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.1782
      },
      "nvd": {
        "published": "2026-07-21T22:17:45.247",
        "lastModified": "2026-07-28T13:26:14.867",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60428",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated LDAP read and write access in Unified Directory Core, but the CPU does not identify the directory object or access-control decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 706,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60429",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:15.318Z",
      "date_updated": "2026-07-30T03:55:32.457Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22444
      },
      "nvd": {
        "published": "2026-07-21T22:17:45.357",
        "lastModified": "2026-07-30T05:16:36.407",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60429",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle publishes low-privilege LDAP takeover impact for OUD Core but no operation or authorization predicate that explains the boundary failure.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html; its row confirms OUD Core over LDAP, low privileges, scope change, CVSS 9.9, and affected versions, but no operation or authorization predicate is public."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 668,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:15.729Z",
      "date_updated": "2026-07-30T03:55:33.208Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33032
      },
      "nvd": {
        "published": "2026-07-21T22:17:45.500",
        "lastModified": "2026-07-30T05:16:36.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60430",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged LDAP caller can exceed its authority in Oracle Unified Directory, but the protected object and failing check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60431",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:16.065Z",
      "date_updated": "2026-07-24T15:33:10.581Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_proxy).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HTTP Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24878
      },
      "nvd": {
        "published": "2026-07-21T22:17:45.617",
        "lastModified": "2026-07-30T17:34:58.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60431",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle HTTP Server output path exposes protected data or state to an unintended observer.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 686,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:16.407Z",
      "date_updated": "2026-07-24T15:32:34.816Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Integration).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Transportation Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30688
      },
      "nvd": {
        "published": "2026-07-21T22:17:45.720",
        "lastModified": "2026-08-03T17:59:24.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60433",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected Oracle action is reachable with insufficient authority, but the failing subject, object, or role check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 740,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:16.808Z",
      "date_updated": "2026-07-24T14:26:33.321Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Transportation Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10253
      },
      "nvd": {
        "published": "2026-07-21T22:17:45.833",
        "lastModified": "2026-08-03T17:56:09.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60434",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Transportation Management access path accepts an identity or request signal that is insufficient to authenticate the actor for the requested operation.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:17.143Z",
      "date_updated": "2026-07-28T03:56:00.828Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28166
      },
      "nvd": {
        "published": "2026-07-21T22:17:45.947",
        "lastModified": "2026-07-28T05:17:10.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60435",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle WebCenter Content exposes a critical Content Server function over HTTP without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.536Z",
      "date_published": "2026-07-21T21:35:17.473Z",
      "date_updated": "2026-07-24T14:09:49.727Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26301
      },
      "nvd": {
        "published": "2026-07-21T22:17:46.057",
        "lastModified": "2026-07-28T19:08:42.767",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60436",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Unified Directory can be driven into resource exhaustion or termination, while the unbounded operation and limit are not public.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60437",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:17.818Z",
      "date_updated": "2026-07-24T14:11:58.915Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22126
      },
      "nvd": {
        "published": "2026-07-21T22:17:46.170",
        "lastModified": "2026-07-28T19:08:36.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60437",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthorized OUD Core changes and service loss through LDAP but does not publish the protected operation or authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 851,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60438",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:18.153Z",
      "date_updated": "2026-08-01T03:55:49.817Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HTTP Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23029
      },
      "nvd": {
        "published": "2026-07-21T22:17:46.283",
        "lastModified": "2026-08-01T05:16:58.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60438",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthenticated read/write compromise through Oracle HTTP Server mod_ssl but does not publish the protected object or access-control check.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.oracle.com/security-alerts/cpujul2026.html. Oracle's CPU matrix confirms unauthenticated HTTP reachability and full confidentiality and integrity impact in mod_ssl but publishes no failing access-control decision."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 704,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60439",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-22T22:24:27.087Z",
      "date_updated": "2026-07-23T14:31:19.102Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Platform Security for Java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18938
      },
      "nvd": {
        "published": "2026-07-22T23:16:36.640",
        "lastModified": "2026-07-24T15:17:22.563",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60439",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Platform Security for Java permits a low-privileged HTTP caller to take over the service, while its grouped privilege, authentication, and deserialization CWEs do not identify one supported failing check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-306",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 588,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60440",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:18.802Z",
      "date_updated": "2026-07-24T14:17:04.011Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.19014
      },
      "nvd": {
        "published": "2026-07-21T22:17:46.400",
        "lastModified": "2026-08-04T14:33:34.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60440",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can receive critical Messaging Enabler data, but Oracle does not disclose the response path or missing disclosure control.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 721,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60441",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:19.136Z",
      "date_updated": "2026-07-24T14:17:45.834Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25612
      },
      "nvd": {
        "published": "2026-07-21T22:17:46.513",
        "lastModified": "2026-08-04T14:34:04.687",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60441",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Service Delivery Platform exposes a security-sensitive operation without verifying that the network caller is authenticated.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60442",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:19.462Z",
      "date_updated": "2026-07-24T14:18:25.052Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0045,
        "percentile": 0.36922
      },
      "nvd": {
        "published": "2026-07-21T22:17:46.623",
        "lastModified": "2026-08-04T14:34:21.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60442",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A critical Messaging Enabler function is reachable over T3 or IIOP without authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60443",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:19.801Z",
      "date_updated": "2026-07-24T14:18:59.378Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22134
      },
      "nvd": {
        "published": "2026-07-21T22:17:46.747",
        "lastModified": "2026-07-24T18:42:11.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60443",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports that a low-privileged WebCenter Content user can read and alter critical data with victim interaction but discloses no enabling cause.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 946,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60444",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:20.154Z",
      "date_updated": "2026-07-29T19:26:42.154Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20962
      },
      "nvd": {
        "published": "2026-07-21T22:17:46.853",
        "lastModified": "2026-07-29T20:17:07.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60444",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Content Server user can read or modify data outside the role's intended scope, but Oracle does not identify the affected object or check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 837,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:20.489Z",
      "date_updated": "2026-07-24T15:17:12.599Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22441
      },
      "nvd": {
        "published": "2026-07-21T22:17:46.967",
        "lastModified": "2026-07-24T18:40:45.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60445",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged T3 or IIOP caller receives WebCenter Enterprise Capture authority beyond its assigned role, but the exact check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms the Client Bundle, T3/IIOP, low privileges, scope change, and takeover impact, but publishes no action, object, or authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 721,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60446",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:20.813Z",
      "date_updated": "2026-07-24T15:16:17.616Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28165
      },
      "nvd": {
        "published": "2026-07-21T22:17:47.077",
        "lastModified": "2026-07-24T18:40:43.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60446",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebCenter Enterprise Capture exposes a critical T3 or IIOP operation without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60447",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:21.141Z",
      "date_updated": "2026-07-24T15:14:25.105Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22441
      },
      "nvd": {
        "published": "2026-07-21T22:17:47.190",
        "lastModified": "2026-07-24T18:40:34.893",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60447",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebCenter Enterprise Capture permits a low-privileged HTTP caller to reach takeover-level operations, while Oracle does not publish the failing permission or object check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html - Oracle confirms the WebCenter Enterprise Capture Client Bundle, HTTP vector, low privileges, and affected versions, but publishes no failing permission or object check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 717,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:21.477Z",
      "date_updated": "2026-07-28T03:56:05.809Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24089
      },
      "nvd": {
        "published": "2026-07-21T22:17:47.300",
        "lastModified": "2026-07-28T05:17:11.013",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60448",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60448 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 863,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60449",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:21.809Z",
      "date_updated": "2026-07-29T19:26:41.968Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04359
      },
      "nvd": {
        "published": "2026-07-21T22:17:47.417",
        "lastModified": "2026-07-29T20:17:07.320",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60449",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebCenter Content returns critical data to an unauthenticated local caller, while Oracle does not disclose the object or output path.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 759,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60450",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:22.143Z",
      "date_updated": "2026-07-28T03:56:07.487Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21314
      },
      "nvd": {
        "published": "2026-07-21T22:17:47.523",
        "lastModified": "2026-07-31T21:14:33.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60450",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle WebCenter Content reaches a protected operation without completing the authentication state or credential validation required for that path.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60451",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:22.478Z",
      "date_updated": "2026-07-24T14:21:54.362Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20963
      },
      "nvd": {
        "published": "2026-07-21T22:17:47.637",
        "lastModified": "2026-07-28T14:23:04.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60451",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle product grants a remote caller authority beyond its role, but the public record does not identify the operation or failing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 709,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60452",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:22.819Z",
      "date_updated": "2026-07-24T14:27:20.197Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20963
      },
      "nvd": {
        "published": "2026-07-21T22:17:47.747",
        "lastModified": "2026-07-28T14:22:48.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60452",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebCenter Content Imaging lets a low-privileged HTTP user read critical data and modify protected data, but the failing authorization binding is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 837,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.537Z",
      "date_published": "2026-07-21T21:35:23.145Z",
      "date_updated": "2026-08-01T03:55:53.864Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HTTP Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02101
      },
      "nvd": {
        "published": "2026-07-21T22:17:47.857",
        "lastModified": "2026-08-01T05:16:58.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60454",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle HTTP Server permits a low-privileged local user to take over the product, while the missing privilege boundary is not public.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 558,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60455",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-22T22:24:27.427Z",
      "date_updated": "2026-07-23T15:07:51.270Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Platform Security for Java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-1395",
          "name": "Dependency on Vulnerable Third-Party Component",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15726
      },
      "nvd": {
        "published": "2026-07-22T23:16:36.753",
        "lastModified": "2026-07-24T15:17:17.297",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60455",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Platform Security for Java bundles a third-party component with a known exploited vulnerability instead of a repaired dependency.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-1395"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 588,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60456",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:24.162Z",
      "date_updated": "2026-07-24T14:24:25.047Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33019
      },
      "nvd": {
        "published": "2026-07-21T22:17:47.967",
        "lastModified": "2026-07-24T18:41:49.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60456",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a low-privileged HTTP path through the WebCenter Enterprise Capture Client Bundle but does not disclose the failing authorization check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html was inspected; Oracle exposes the Client Bundle component and HTTP attack conditions but no causal authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 717,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60457",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:24.495Z",
      "date_updated": "2026-07-24T14:28:58.627Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33018
      },
      "nvd": {
        "published": "2026-07-21T22:17:48.087",
        "lastModified": "2026-07-24T18:41:44.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60457",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a low-privilege Client Bundle takeover over T3/IIOP but does not publish the incorrect access-control decision.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.oracle.com/security-alerts/cpujul2026.html. Oracle's public risk matrix confirms low-privilege T3/IIOP reachability and takeover impact but does not disclose the access-control failure."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 721,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:24.829Z",
      "date_updated": "2026-07-24T20:04:04.920Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33019
      },
      "nvd": {
        "published": "2026-07-21T22:17:48.197",
        "lastModified": "2026-07-31T21:22:55.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60458",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle maps the Client Bundle issue to missing authentication but describes a low-privilege T3/IIOP path, without publishing the critical function or check that fails.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official table confirms WebCenter Enterprise Capture Client Bundle, T3/IIOP and affected versions but does not resolve the low-privilege versus missing-authentication wording or expose the failing function."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 721,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:25.174Z",
      "date_updated": "2026-07-24T14:33:45.216Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33018
      },
      "nvd": {
        "published": "2026-07-21T22:17:48.310",
        "lastModified": "2026-07-24T18:41:23.503",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60459",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle WebCenter Enterprise Capture lets a low-privileged HTTP caller cross an undisclosed Client Bundle authorization boundary and take over the product.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July CPU adds the Client Bundle component, HTTP route, low required privilege, and affected versions, but no failing authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 717,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60460",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:25.503Z",
      "date_updated": "2026-07-24T14:34:25.112Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28166
      },
      "nvd": {
        "published": "2026-07-21T22:17:48.420",
        "lastModified": "2026-07-24T18:40:52.823",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60460",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle WebCenter Enterprise Capture exposes a critical operation without completing the authentication check required for that operation.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60461",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:25.839Z",
      "date_updated": "2026-07-24T14:35:49.508Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33027
      },
      "nvd": {
        "published": "2026-07-21T22:17:48.530",
        "lastModified": "2026-07-24T18:40:48.497",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60461",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged T3 or IIOP caller can reach takeover-capable Client Bundle authority, but the failed authorization check is not public.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html on 2026-08-05; Oracle lists Client Bundle over T3/IIOP, Remote Exploit without Auth. No, and CVSS privileges required Low, which conflicts with the embedded CWE-306 Missing Authentication assignment, so the family is retained only at broad authorization precision."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 721,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60462",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:26.179Z",
      "date_updated": "2026-07-28T03:56:11.408Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21314
      },
      "nvd": {
        "published": "2026-07-21T22:17:48.640",
        "lastModified": "2026-07-31T21:14:22.397",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60462",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A critical WebCenter operation is exposed without the authentication required for that function.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 551,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60463",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:26.508Z",
      "date_updated": "2026-07-24T18:12:21.826Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28163
      },
      "nvd": {
        "published": "2026-07-21T22:17:48.743",
        "lastModified": "2026-07-28T14:18:18.907",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60463",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A T3 or IIOP reachable Imaging Core function executes without authenticating the caller.",
        "basis": [
          "CNA record",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60464",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:26.863Z",
      "date_updated": "2026-07-30T16:47:33.755Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22445
      },
      "nvd": {
        "published": "2026-07-21T22:17:48.853",
        "lastModified": "2026-07-30T19:18:34.140",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60464",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that WebCenter Content: Imaging permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60465",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:27.236Z",
      "date_updated": "2026-07-25T03:55:43.092Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33035
      },
      "nvd": {
        "published": "2026-07-21T22:17:48.963",
        "lastModified": "2026-07-28T13:30:56.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60465",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebCenter Content Imaging permits a low-privileged T3 or IIOP caller to take over the component, but the privilege transition is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60466",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:27.668Z",
      "date_updated": "2026-07-25T03:55:42.292Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37108
      },
      "nvd": {
        "published": "2026-07-21T22:17:49.080",
        "lastModified": "2026-07-28T13:30:34.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60466",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports high-privileged HTTP takeover of WebCenter Content Imaging, but the CPU does not identify the operation or permission check that fails.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 545,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60467",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:27.999Z",
      "date_updated": "2026-07-25T03:55:41.488Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22401
      },
      "nvd": {
        "published": "2026-07-21T22:17:49.190",
        "lastModified": "2026-07-28T13:30:20.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60467",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unsigned or unvalidated return target is used for redirection, allowing navigation to an attacker-controlled origin.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 631,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60468",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.538Z",
      "date_published": "2026-07-21T21:35:28.328Z",
      "date_updated": "2026-07-25T03:55:40.667Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12932
      },
      "nvd": {
        "published": "2026-07-21T22:17:49.300",
        "lastModified": "2026-07-28T13:30:07.800",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60468",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read or modify WebCenter Imaging data beyond its role, but the object and check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 709,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60469",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.539Z",
      "date_published": "2026-07-21T21:35:28.667Z",
      "date_updated": "2026-07-25T03:55:39.766Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22134
      },
      "nvd": {
        "published": "2026-07-21T22:17:49.413",
        "lastModified": "2026-07-28T13:29:56.507",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60469",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The WebCenter Content: Imaging path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 946,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60470",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.539Z",
      "date_published": "2026-07-21T21:35:29.002Z",
      "date_updated": "2026-07-25T03:55:38.994Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14057
      },
      "nvd": {
        "published": "2026-07-21T22:17:49.527",
        "lastModified": "2026-07-28T13:29:44.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60470",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthorized access without identifying the missing authentication, role, or object-ownership decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 946,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60471",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.539Z",
      "date_published": "2026-07-21T21:35:29.330Z",
      "date_updated": "2026-07-25T03:55:35.708Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18241
      },
      "nvd": {
        "published": "2026-07-21T22:17:49.640",
        "lastModified": "2026-07-28T13:29:29.960",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60471",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The WebCenter Content: Imaging operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 767,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60472",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.539Z",
      "date_published": "2026-07-21T21:35:29.670Z",
      "date_updated": "2026-07-25T03:55:34.884Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.2244
      },
      "nvd": {
        "published": "2026-07-21T22:17:49.760",
        "lastModified": "2026-07-28T13:29:18.393",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60472",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can take over WebCenter Content Imaging, but the protected operation and failing authorization check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.540Z",
      "date_published": "2026-07-21T21:35:30.023Z",
      "date_updated": "2026-07-25T03:55:37.397Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne CRM Foundation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20834
      },
      "nvd": {
        "published": "2026-07-21T22:17:49.873",
        "lastModified": "2026-07-25T05:16:39.440",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60489",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says JD Edwards EnterpriseOne CRM Foundation permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.540Z",
      "date_published": "2026-07-21T21:35:30.375Z",
      "date_updated": "2026-07-25T03:55:38.170Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne CRM Foundation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20835
      },
      "nvd": {
        "published": "2026-07-21T22:17:49.987",
        "lastModified": "2026-07-25T05:16:39.550",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60490",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged HTTP user can take over CRM Foundation but does not publish the operation or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60491",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.540Z",
      "date_published": "2026-07-21T21:35:30.708Z",
      "date_updated": "2026-07-24T18:21:00.532Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: SDK client integration).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Inbound Telephony"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16309
      },
      "nvd": {
        "published": "2026-07-21T22:17:50.097",
        "lastModified": "2026-07-24T19:17:03.083",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60491",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 846,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.540Z",
      "date_published": "2026-07-21T21:35:31.137Z",
      "date_updated": "2026-07-24T18:19:49.076Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: OW HR PR Foundation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne HCM Foundation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25157
      },
      "nvd": {
        "published": "2026-07-21T22:17:50.210",
        "lastModified": "2026-07-24T19:17:03.203",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60492",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The component assigns or permits a privilege beyond the authority granted to the invoking user.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 734,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60493",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.540Z",
      "date_published": "2026-07-21T21:35:31.687Z",
      "date_updated": "2026-07-25T03:55:55.746Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Human Resources Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31655
      },
      "nvd": {
        "published": "2026-07-21T22:17:50.327",
        "lastModified": "2026-07-25T05:16:39.663",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60493",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 602,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60494",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.540Z",
      "date_published": "2026-07-21T21:35:32.048Z",
      "date_updated": "2026-07-29T19:26:42.966Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne General Ledger"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09836
      },
      "nvd": {
        "published": "2026-07-21T22:17:50.437",
        "lastModified": "2026-07-29T20:17:07.440",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60494",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "JD Edwards EnterpriseOne General Ledger permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 866,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60495",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.540Z",
      "date_published": "2026-07-21T21:35:32.377Z",
      "date_updated": "2026-07-25T03:55:58.952Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Requirements Planning product of Oracle JD Edwards (component: Requirements Planning).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Requirements Planning"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22369
      },
      "nvd": {
        "published": "2026-07-21T22:17:50.577",
        "lastModified": "2026-07-25T05:16:39.883",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60495",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A critical Requirements Planning function is reachable by a low-privilege JDENET caller without the function-level authentication it requires.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 597,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.541Z",
      "date_published": "2026-07-21T21:35:32.712Z",
      "date_updated": "2026-07-25T03:55:36.589Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Advanced Pricing - Procurement product of Oracle JD Edwards (component: Advanced Pricing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Advanced Pricing - Procurement"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22369
      },
      "nvd": {
        "published": "2026-07-21T22:17:50.693",
        "lastModified": "2026-07-25T05:16:39.993",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60496",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged JDENET user can invoke a critical Advanced Pricing operation without the function-level authentication it requires, although Oracle does not name the function.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 619,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60497",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.541Z",
      "date_published": "2026-07-21T21:35:33.062Z",
      "date_updated": "2026-07-25T03:55:50.124Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne CRM Foundation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22368
      },
      "nvd": {
        "published": "2026-07-21T22:17:50.803",
        "lastModified": "2026-07-25T05:16:40.103",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60497",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged JDENET caller can reach a critical CRM Foundation operation without the authentication required for that operation, although the function is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60498",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.541Z",
      "date_published": "2026-07-21T21:35:33.401Z",
      "date_updated": "2026-07-25T03:55:57.368Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Human Resources Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22368
      },
      "nvd": {
        "published": "2026-07-21T22:17:50.917",
        "lastModified": "2026-07-25T05:16:40.210",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60498",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive JD Edwards EnterpriseOne Human Resources Management operation can run without authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 606,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.541Z",
      "date_published": "2026-07-21T21:35:33.743Z",
      "date_updated": "2026-07-25T03:56:00.707Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Solution Advisor product of Oracle JD Edwards (component: Solution Advisor).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Solution Advisor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31655
      },
      "nvd": {
        "published": "2026-07-21T22:17:51.023",
        "lastModified": "2026-07-25T05:16:40.337",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60499",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Solution Advisor does not require the stronger authentication or authorization needed before a low-privileged user can take over the product.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.541Z",
      "date_published": "2026-07-21T21:35:34.077Z",
      "date_updated": "2026-07-24T15:41:57.809Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Service Delivery Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02471
      },
      "nvd": {
        "published": "2026-07-21T22:17:51.140",
        "lastModified": "2026-08-04T14:33:11.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60501",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged local caller can exceed assigned authority in Java VM, but the CPU table does not identify the protected operation or failing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 867,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60502",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.541Z",
      "date_published": "2026-07-21T21:35:34.409Z",
      "date_updated": "2026-07-25T03:55:34.006Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37107
      },
      "nvd": {
        "published": "2026-07-21T22:17:51.253",
        "lastModified": "2026-07-28T14:23:29.030",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60502",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60502 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60503",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.541Z",
      "date_published": "2026-07-21T21:35:34.748Z",
      "date_updated": "2026-07-25T03:55:33.186Z",
      "publisher": "oracle",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "WebCenter Content: Imaging"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33022
      },
      "nvd": {
        "published": "2026-07-21T22:17:51.370",
        "lastModified": "2026-07-28T14:23:19.193",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60503",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebCenter Content Imaging grants a low-privilege HTTP caller authority sufficient for takeover, while the protected operation and check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60519",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.542Z",
      "date_published": "2026-07-21T21:35:35.098Z",
      "date_updated": "2026-07-30T03:55:33.955Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37109
      },
      "nvd": {
        "published": "2026-07-21T22:17:51.490",
        "lastModified": "2026-07-30T05:16:36.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60519",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle Unified Directory in its OUD Core component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60520",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.542Z",
      "date_published": "2026-07-21T21:35:35.438Z",
      "date_updated": "2026-07-30T03:55:34.986Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Unified Directory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26314
      },
      "nvd": {
        "published": "2026-07-21T22:17:51.603",
        "lastModified": "2026-07-30T05:16:36.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60520",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle component permits a privileged caller to cross an access-control boundary, but the public record does not identify the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 728,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60521",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.542Z",
      "date_published": "2026-07-21T21:35:35.776Z",
      "date_updated": "2026-07-24T18:14:19.245Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Pricing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17055
      },
      "nvd": {
        "published": "2026-07-21T22:17:51.723",
        "lastModified": "2026-07-24T19:17:03.933",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60521",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Advanced Pricing permits an unauthenticated HTTP caller to read and modify protected pricing data, but the missing check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 668,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60522",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.542Z",
      "date_published": "2026-07-21T21:35:36.225Z",
      "date_updated": "2026-07-24T18:13:49.824Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16928
      },
      "nvd": {
        "published": "2026-07-21T22:17:51.840",
        "lastModified": "2026-07-31T21:06:17.193",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60522",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle WebCenter Content permits a low-privileged HTTP caller to access and modify data beyond that role, while the object or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 923,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60523",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.542Z",
      "date_published": "2026-07-21T21:35:36.575Z",
      "date_updated": "2026-07-28T03:56:12.160Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22134
      },
      "nvd": {
        "published": "2026-07-21T22:17:51.953",
        "lastModified": "2026-07-31T21:15:28.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60523",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle WebCenter Content permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 946,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60524",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.542Z",
      "date_published": "2026-07-21T21:35:36.999Z",
      "date_updated": "2026-07-24T18:12:48.844Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33034
      },
      "nvd": {
        "published": "2026-07-21T22:17:52.067",
        "lastModified": "2026-07-31T21:05:55.607",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60524",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a low-privileged T3 or IIOP path through the WebCenter Enterprise Capture Client Bundle but does not disclose the failing authorization check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html was inspected; Oracle exposes the Client Bundle component and T3/IIOP attack conditions but no causal authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 721,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60525",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.542Z",
      "date_published": "2026-07-21T21:35:37.344Z",
      "date_updated": "2026-07-28T03:56:12.910Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18943
      },
      "nvd": {
        "published": "2026-07-21T22:17:52.177",
        "lastModified": "2026-07-28T05:17:11.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60525",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 862,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60526",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.542Z",
      "date_published": "2026-07-21T21:35:37.683Z",
      "date_updated": "2026-08-01T03:56:48.634Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle Java SE (component: Installation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03779
      },
      "nvd": {
        "published": "2026-07-21T22:17:52.290",
        "lastModified": "2026-08-03T18:38:25.127",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60526",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle identifies only improper input validation in the Java installer and a sandboxed-code takeover impact, without publishing the input, parser or failing invariant.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1017,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.542Z",
      "date_published": "2026-07-21T21:35:38.031Z",
      "date_updated": "2026-07-25T03:55:59.747Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07629
      },
      "nvd": {
        "published": "2026-07-21T22:17:52.400",
        "lastModified": "2026-07-31T21:15:54.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60527",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle WebLogic Server but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 742,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60528",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:38.373Z",
      "date_updated": "2026-07-25T03:55:56.546Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22394
      },
      "nvd": {
        "published": "2026-07-21T22:17:52.510",
        "lastModified": "2026-07-31T21:15:45.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60528",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged WebLogic Console caller can read or modify data outside its authority, but Oracle does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 821,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60529",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:39.726Z",
      "date_updated": "2026-07-25T03:55:54.936Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebLogic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00466,
        "percentile": 0.37949
      },
      "nvd": {
        "published": "2026-07-21T22:17:52.623",
        "lastModified": "2026-07-31T21:15:34.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60529",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged WebLogic Console caller can reach takeover-capable authority beyond its intended role, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 536,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:40.096Z",
      "date_updated": "2026-08-01T03:55:55.048Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HTTP Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04683
      },
      "nvd": {
        "published": "2026-07-21T22:17:52.720",
        "lastModified": "2026-08-01T05:16:58.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60530",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle product permits a privilege transition, but the public record does not identify the protected operation or failed check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60531",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:40.441Z",
      "date_updated": "2026-07-27T14:07:45.518Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager Connector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33032
      },
      "nvd": {
        "published": "2026-07-21T22:17:52.833",
        "lastModified": "2026-07-28T19:27:09.843",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60531",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An HTTP-reachable Identity Manager Connector function performs a critical action without the required authentication.",
        "basis": [
          "CNA record",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 700,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60532",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:40.783Z",
      "date_updated": "2026-07-24T18:10:11.025Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager Connector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38458
      },
      "nvd": {
        "published": "2026-07-21T22:17:52.940",
        "lastModified": "2026-07-28T19:27:24.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60532",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Identity Manager Connector permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-269",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July 2026 CPU at https://www.oracle.com/security-alerts/cpujul2026.html confirms the PeopleSoft Applications component, unauthenticated HTTP reachability, affected versions, and takeover impact but publishes no route, identity decision, or patch source."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60533",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:41.117Z",
      "date_updated": "2026-07-27T14:07:44.784Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager Connector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15585
      },
      "nvd": {
        "published": "2026-07-21T22:17:53.053",
        "lastModified": "2026-07-28T19:26:07.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60533",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Generic Unix Connector accepts an adjacent unauthenticated action beyond its intended authority, but the failing control is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1011,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60534",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:41.448Z",
      "date_updated": "2026-07-24T18:07:58.587Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager Connector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22658
      },
      "nvd": {
        "published": "2026-07-21T22:17:53.170",
        "lastModified": "2026-07-28T19:28:19.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60534",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports cross-product read and write impact through an Identity Manager PeopleSoft connector, but the CPU does not identify the object or authorization decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 917,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:41.784Z",
      "date_updated": "2026-07-24T18:06:19.060Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager Connector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38441
      },
      "nvd": {
        "published": "2026-07-21T22:17:53.280",
        "lastModified": "2026-07-28T19:28:34.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60535",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable security-sensitive operation is exposed without the authentication step required before invoking it.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:42.115Z",
      "date_updated": "2026-07-24T18:03:52.182Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager Connector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32428
      },
      "nvd": {
        "published": "2026-07-21T22:17:53.393",
        "lastModified": "2026-07-28T19:28:48.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60536",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP caller can read Identity Manager Connector data, but the endpoint, object, and missing access check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 760,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:42.462Z",
      "date_updated": "2026-07-24T18:03:05.702Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Managed File Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33019
      },
      "nvd": {
        "published": "2026-07-21T22:17:53.500",
        "lastModified": "2026-07-28T19:29:04.887",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60537",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can take over the Managed File Transfer Runtime Server, but Oracle does not disclose the endpoint or failing authorization decision.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle's July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms that a low-privileged HTTP caller can reach the Managed File Transfer Runtime Server with CVSS 9.9 and takeover impact, but publishes no endpoint, operation, object-scope decision, or failing check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 694,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:42.803Z",
      "date_updated": "2026-07-24T18:01:33.440Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle SOA Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38461
      },
      "nvd": {
        "published": "2026-07-21T22:17:53.613",
        "lastModified": "2026-07-29T17:49:35.503",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60538",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected Oracle interface accepts a protected request without authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60539",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:43.158Z",
      "date_updated": "2026-07-27T14:07:52.194Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle SOA Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33027
      },
      "nvd": {
        "published": "2026-07-21T22:17:53.733",
        "lastModified": "2026-07-29T17:47:04.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60539",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive Oracle SOA Suite operation is reachable through a path that does not enforce the required authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60540",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:43.495Z",
      "date_updated": "2026-07-27T11:05:04.388Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle SOA Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26309
      },
      "nvd": {
        "published": "2026-07-21T22:17:53.847",
        "lastModified": "2026-07-29T17:46:39.097",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60540",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can cross the Oracle SOA Suite data-access boundary, but Oracle does not publish the protected object or failing permission check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; Oracle confirms Integration Business Insight, low-privileged HTTP reachability, CVSS 9.6, affected versions, and cross-scope data impact, but publishes no protected object or failing permission check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 834,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60541",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:43.862Z",
      "date_updated": "2026-07-27T11:07:19.390Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle SOA Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38461
      },
      "nvd": {
        "published": "2026-07-21T22:17:53.960",
        "lastModified": "2026-07-29T17:46:09.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60541",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle SOA Suite exposes Enterprise Scheduling System functionality over HTTP to unauthenticated takeover, while the July CPU does not publish the failing access-control decision.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms unauthenticated HTTP exposure in SOA Suite Enterprise Scheduling System, CVSS 9.8, and affected versions but publishes no endpoint or failing authorization decision."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60542",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:44.223Z",
      "date_updated": "2026-07-27T11:07:59.482Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Business Process Management Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31696
      },
      "nvd": {
        "published": "2026-07-21T22:17:54.060",
        "lastModified": "2026-07-27T12:16:50.347",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60542",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged T3 or IIOP caller can take over Human Workflow but does not publish the operation or failing authorization check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html was inspected; Oracle confirms the Human Workflow component and low-privileged T3/IIOP reachability but publishes no operation or failing authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 742,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60543",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:44.550Z",
      "date_updated": "2026-07-24T17:57:26.171Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle SOA Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29279
      },
      "nvd": {
        "published": "2026-07-21T22:17:54.173",
        "lastModified": "2026-07-29T17:45:44.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60543",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 523,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60544",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:44.884Z",
      "date_updated": "2026-07-27T11:09:21.609Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle SOA Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00424,
        "percentile": 0.34911
      },
      "nvd": {
        "published": "2026-07-21T22:17:54.287",
        "lastModified": "2026-07-29T17:45:23.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60544",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive function can be invoked without enforcing the caller authentication required for that operation.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 674,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60545",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:45.221Z",
      "date_updated": "2026-07-27T11:10:47.062Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Managed File Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33034
      },
      "nvd": {
        "published": "2026-07-21T22:17:54.393",
        "lastModified": "2026-07-28T19:25:46.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60545",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle Managed File Transfer but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 564,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60546",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.543Z",
      "date_published": "2026-07-21T21:35:45.556Z",
      "date_updated": "2026-07-27T11:12:59.395Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle SOA Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37108
      },
      "nvd": {
        "published": "2026-07-21T22:17:54.507",
        "lastModified": "2026-07-29T17:44:57.100",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60546",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle SOA Suite lets a lower-privileged caller exercise a higher-privileged operation because privilege assignment or enforcement is incomplete.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60547",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:45.899Z",
      "date_updated": "2026-07-27T11:22:07.503Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Managed File Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33028
      },
      "nvd": {
        "published": "2026-07-21T22:17:54.613",
        "lastModified": "2026-07-28T19:29:23.553",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60547",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege HTTP caller can take over Managed File Transfer, but Oracle publishes no failing object, role, or action check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; Oracle confirms the MFT Runtime Server, HTTP vector, low privileges, and affected versions but publishes no causal check, and no reproduction was performed."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 694,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60548",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:46.249Z",
      "date_updated": "2026-07-27T11:14:58.636Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle SOA Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00376,
        "percentile": 0.30325
      },
      "nvd": {
        "published": "2026-07-21T22:17:54.737",
        "lastModified": "2026-07-29T17:44:29.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60548",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle SOA Suite returns critical Integration Business Insight data to a low-privileged user, but the endpoint and disclosure condition are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 696,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60549",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:46.724Z",
      "date_updated": "2026-07-27T11:18:49.525Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Managed File Transfer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33029
      },
      "nvd": {
        "published": "2026-07-21T22:17:54.850",
        "lastModified": "2026-07-28T19:25:57.627",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60549",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can reach a critical Managed File Transfer runtime operation without the authentication required for it, although the function is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 564,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60550",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:47.083Z",
      "date_updated": "2026-07-27T11:20:16.221Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Sites"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32424
      },
      "nvd": {
        "published": "2026-07-21T22:17:54.957",
        "lastModified": "2026-07-30T20:13:30.047",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60550",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle WebCenter Sites operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 708,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60551",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:47.425Z",
      "date_updated": "2026-08-01T03:56:35.112Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Sites"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38459
      },
      "nvd": {
        "published": "2026-07-21T22:17:55.070",
        "lastModified": "2026-08-01T05:16:58.693",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60551",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebCenter Sites exposes a critical HTTP operation without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60552",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:47.810Z",
      "date_updated": "2026-08-01T03:56:36.197Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Sites"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.3303
      },
      "nvd": {
        "published": "2026-07-21T22:17:55.183",
        "lastModified": "2026-08-01T05:16:58.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60552",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebCenter Sites permits a low-privileged HTTP caller to reach takeover-level operations, while Oracle does not publish the failing permission or object check.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html - Oracle confirms the WebCenter Sites component, HTTP vector, low privileges, and affected versions, but publishes no failing permission or object check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 667,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60553",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:48.492Z",
      "date_updated": "2026-08-01T03:56:37.335Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Sites"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17701
      },
      "nvd": {
        "published": "2026-07-21T22:17:55.290",
        "lastModified": "2026-08-01T05:16:58.950",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60553",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60553 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "NVD",
          "ADP",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 854,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60554",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:48.836Z",
      "date_updated": "2026-07-27T11:27:38.825Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Sites"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34444
      },
      "nvd": {
        "published": "2026-07-21T22:17:55.407",
        "lastModified": "2026-07-30T20:14:47.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60554",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebCenter Sites returns all accessible critical data to an unauthenticated HTTP caller, while Oracle does not disclose the endpoint or output condition.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60555",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:49.166Z",
      "date_updated": "2026-08-01T03:56:44.052Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Sites"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38461
      },
      "nvd": {
        "published": "2026-07-21T22:17:55.517",
        "lastModified": "2026-08-01T05:16:59.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60555",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle WebCenter Sites in its WebCenter Sites component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-200",
          "CWE-284",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Read https://www.oracle.com/security-alerts/cpujul2026.html; Oracle's CPU confirms unauthenticated HTTP reachability and takeover impact but provides no endpoint or failed access-control check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60556",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:49.498Z",
      "date_updated": "2026-07-27T11:29:15.272Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Sites"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34444
      },
      "nvd": {
        "published": "2026-07-21T22:17:55.637",
        "lastModified": "2026-07-30T20:15:28.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60556",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record reports unauthorized access to information but does not reveal whether the cause is authorization, output exposure, or another engineering failure.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 708,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60557",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:49.855Z",
      "date_updated": "2026-07-27T14:46:54.566Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Sites"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27771
      },
      "nvd": {
        "published": "2026-07-21T22:17:55.770",
        "lastModified": "2026-07-30T20:15:40.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60557",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle WebCenter Sites exposes a critical data-reading function to an unauthenticated caller.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 668,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60558",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:50.192Z",
      "date_updated": "2026-08-01T03:56:45.138Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Sites"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29279
      },
      "nvd": {
        "published": "2026-07-21T22:17:55.887",
        "lastModified": "2026-08-01T05:16:59.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60558",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle WebCenter Sites permits an unauthenticated HTTP caller to take over the product, while the authentication decision that fails is not public.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60559",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:50.541Z",
      "date_updated": "2026-07-29T19:26:40.825Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32426
      },
      "nvd": {
        "published": "2026-07-21T22:17:55.997",
        "lastModified": "2026-07-29T20:17:07.557",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60559",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Access Manager permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 710,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60560",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:50.897Z",
      "date_updated": "2026-08-01T03:55:59.435Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26309
      },
      "nvd": {
        "published": "2026-07-21T22:17:56.110",
        "lastModified": "2026-08-01T05:16:59.313",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60560",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized Identity Manager data access through REST services but does not publish the missing permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 732,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60561",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:51.231Z",
      "date_updated": "2026-08-01T03:56:27.278Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33078
      },
      "nvd": {
        "published": "2026-07-21T22:17:56.227",
        "lastModified": "2026-08-01T05:16:59.437",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60561",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a low-privilege Runtime Tools takeover over HTTP but does not publish the incorrect access-control decision.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.oracle.com/security-alerts/cpujul2026.html. Oracle's public risk matrix confirms low-privilege HTTP reachability and takeover impact but does not disclose the Runtime Tools access-control failure."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 669,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60562",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:51.567Z",
      "date_updated": "2026-08-01T03:56:28.404Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22487
      },
      "nvd": {
        "published": "2026-07-21T22:17:56.350",
        "lastModified": "2026-08-01T05:16:59.613",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60562",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an access-control failure in WebCenter Portal Runtime Tools, while its public CPU does not disclose the affected HTTP operation or permission check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official table confirms WebCenter Portal Runtime Tools, HTTP and affected versions but publishes no implementation path or permission check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 669,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60563",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:51.896Z",
      "date_updated": "2026-08-01T03:56:29.497Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22443
      },
      "nvd": {
        "published": "2026-07-21T22:17:56.460",
        "lastModified": "2026-08-01T05:16:59.740",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60563",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle WebCenter Portal but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60564",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.544Z",
      "date_published": "2026-07-21T21:35:52.283Z",
      "date_updated": "2026-08-01T03:56:30.683Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26309
      },
      "nvd": {
        "published": "2026-07-21T22:17:56.570",
        "lastModified": "2026-08-01T05:16:59.863",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60564",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read and modify WebCenter Portal data across a changed scope, but Oracle does not disclose the Runtime Tools authorization decision.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; Oracle confirms WebCenter Portal Runtime Tools over HTTP, low privileges, scope change, affected versions, and 9.6 impact but does not disclose the privileged operation or check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 854,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60565",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:52.623Z",
      "date_updated": "2026-08-01T03:56:31.798Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33078
      },
      "nvd": {
        "published": "2026-07-21T22:17:56.697",
        "lastModified": "2026-08-01T05:16:59.987",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60565",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged WebCenter Portal HTTP caller can reach takeover-capable Runtime Tools authority, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html on 2026-08-05; Oracle confirms WebCenter Portal Runtime Tools over HTTP, Remote Exploit without Auth. No, CVSS 9.9, and affected versions, but publishes no endpoint or authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 669,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60566",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:52.996Z",
      "date_updated": "2026-08-01T03:56:32.925Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28164
      },
      "nvd": {
        "published": "2026-07-21T22:17:56.813",
        "lastModified": "2026-08-01T05:17:00.113",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60566",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle WebCenter Portal Runtime Tools permits an unauthenticated HTTP takeover, but the public material does not identify the missing authorization check or protected operation.",
        "basis": [
          "CNA",
          "CWE-269",
          "Oracle Critical Patch Update July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html on 2026-08-05; Oracle confirms WebCenter Portal Runtime Tools, HTTP reachability, no required privileges, affected versions 12.2.1.4.0 and 14.1.2.0.0, and takeover impact, but the CPU matrix does not disclose the protected operation or failing check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 545,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60567",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:54.610Z",
      "date_updated": "2026-08-01T03:56:00.795Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23028
      },
      "nvd": {
        "published": "2026-07-21T22:17:56.927",
        "lastModified": "2026-08-01T05:17:00.233",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60567",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The OIM Legacy UI grants an unauthenticated HTTP caller read and write authority over critical identity data, but the failing privilege check is not public.",
        "basis": [
          "CNA record",
          "CWE-269",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official matrix confirms the Legacy UI, HTTP, no authentication, and affected versions but discloses no endpoint or authorization rule."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 730,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60568",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:54.947Z",
      "date_updated": "2026-08-01T03:56:34.001Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22445
      },
      "nvd": {
        "published": "2026-07-21T22:17:57.033",
        "lastModified": "2026-08-01T05:17:00.357",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60568",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle WebCenter Portal permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-287",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July 2026 CPU at https://www.oracle.com/security-alerts/cpujul2026.html confirms Runtime Tools, low-privileged HTTP reachability, scope change, affected versions, and takeover impact but publishes no protected operation or failing authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 669,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60569",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:55.279Z",
      "date_updated": "2026-07-29T18:19:35.776Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03866
      },
      "nvd": {
        "published": "2026-07-21T22:17:57.147",
        "lastModified": "2026-08-03T15:18:04.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60569",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MySQL NDB Operator exposes sensitive cluster data to a local caller without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 602,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60570",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:55.622Z",
      "date_updated": "2026-07-27T14:52:05.424Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle GoldenGate (component: Libraries).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GoldenGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01251
      },
      "nvd": {
        "published": "2026-07-21T22:17:57.260",
        "lastModified": "2026-07-27T16:18:06.330",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60570",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports local low-privileged takeover of GoldenGate Libraries, but the CPU does not identify the operation or authority transition that fails.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 505,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60571",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:55.950Z",
      "date_updated": "2026-07-27T15:06:40.892Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Installation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle SDP Number Portability"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.19669
      },
      "nvd": {
        "published": "2026-07-21T22:17:57.373",
        "lastModified": "2026-07-27T16:18:06.473",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60571",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports unauthorized data changes and partial denial of service but does not identify the failing check or transition.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 701,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60572",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:56.299Z",
      "date_updated": "2026-07-27T15:13:29.323Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product of Oracle E-Business Suite (component: Web Service Provider).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle E-Business Suite Integrated SOA Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16341
      },
      "nvd": {
        "published": "2026-07-21T22:17:57.487",
        "lastModified": "2026-07-27T16:18:06.583",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60572",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read, modify, or disrupt Integrated SOA Gateway state beyond its role, but the protected object and check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 909,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60573",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:56.655Z",
      "date_updated": "2026-07-27T15:17:25.393Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Partner Dashboard).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Partner Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.1631
      },
      "nvd": {
        "published": "2026-07-21T22:17:57.600",
        "lastModified": "2026-07-27T16:18:06.693",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60573",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Partner Management path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 802,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60574",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:56.993Z",
      "date_updated": "2026-07-27T15:20:16.803Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Cover Letter).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Content Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16311
      },
      "nvd": {
        "published": "2026-07-21T22:17:57.700",
        "lastModified": "2026-07-27T16:18:06.800",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60574",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged caller can reach a protected Oracle operation, but the record labels missing authentication and does not identify the actual authorization check.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "The structured CWE-306 missing-authentication label conflicts with the embedded low-privilege attack prerequisite, so the row remains broad rather than claiming an absent login gate."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 781,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60575",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:57.334Z",
      "date_updated": "2026-07-27T15:21:15.980Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Workflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16341
      },
      "nvd": {
        "published": "2026-07-21T22:17:57.810",
        "lastModified": "2026-07-27T16:18:06.903",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60575",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Workflow operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 762,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60576",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:57.680Z",
      "date_updated": "2026-07-27T15:22:02.514Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Command Center Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37138
      },
      "nvd": {
        "published": "2026-07-21T22:17:57.917",
        "lastModified": "2026-07-30T20:18:36.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60576",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged HTTP caller can take over Oracle Enterprise Command Center Framework, but the additional authority gained and failing check are not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60577",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:58.023Z",
      "date_updated": "2026-07-27T15:24:51.099Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Command Center Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20962
      },
      "nvd": {
        "published": "2026-07-21T22:17:58.030",
        "lastModified": "2026-07-30T20:18:22.940",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60577",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Enterprise Command Center Framework permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 751,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60578",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:58.387Z",
      "date_updated": "2026-07-27T15:25:35.520Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Command Center Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24816
      },
      "nvd": {
        "published": "2026-07-21T22:17:58.140",
        "lastModified": "2026-07-30T20:18:02.377",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60578",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthorized reads and writes in Enterprise Command Center Core but does not publish the object or permission check.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 896,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60579",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:58.728Z",
      "date_updated": "2026-07-27T15:26:25.880Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Command Center Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15538
      },
      "nvd": {
        "published": "2026-07-21T22:17:58.253",
        "lastModified": "2026-07-30T20:17:35.757",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60579",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1029,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60580",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:59.069Z",
      "date_updated": "2026-07-27T18:43:22.969Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Command Center Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16623
      },
      "nvd": {
        "published": "2026-07-21T22:17:58.363",
        "lastModified": "2026-07-27T19:17:18.883",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60580",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive function can be invoked without enforcing the caller authentication required for that operation.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 679,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60581",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:59.405Z",
      "date_updated": "2026-07-27T12:28:18.329Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Command Center Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09955
      },
      "nvd": {
        "published": "2026-07-21T22:17:58.480",
        "lastModified": "2026-07-27T13:18:25.063",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60581",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle Enterprise Command Center Framework but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 681,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60582",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:35:59.740Z",
      "date_updated": "2026-07-27T12:29:00.994Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Command Center Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17617
      },
      "nvd": {
        "published": "2026-07-21T22:17:58.593",
        "lastModified": "2026-07-27T13:18:25.220",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60582",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value is incorporated into a Oracle Enterprise Command Center Framework database query without safe parameter binding, allowing SQL syntax injection.",
        "basis": [
          "CNA",
          "CWE-89",
          "CWE-284",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 898,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60583",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.545Z",
      "date_published": "2026-07-21T21:36:00.082Z",
      "date_updated": "2026-07-27T12:29:55.133Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Install).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Transportation Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31658
      },
      "nvd": {
        "published": "2026-07-21T22:17:58.710",
        "lastModified": "2026-07-27T13:18:25.383",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60583",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An installation function can be reached by a low-privilege HTTP caller without the authentication level required for that critical operation.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 541,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60584",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.546Z",
      "date_published": "2026-07-21T21:36:00.440Z",
      "date_updated": "2026-07-27T15:27:38.136Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: CSV Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Transportation Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23339
      },
      "nvd": {
        "published": "2026-07-21T22:17:58.823",
        "lastModified": "2026-07-27T16:18:07.777",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60584",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports broad data access and modification through Transportation Management CSV processing but does not disclose the input or failed control.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 845,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60585",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.546Z",
      "date_published": "2026-07-21T21:36:00.898Z",
      "date_updated": "2026-07-28T03:56:38.972Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27673
      },
      "nvd": {
        "published": "2026-07-21T22:17:58.933",
        "lastModified": "2026-07-28T17:09:57.577",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60585",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged replication user can obtain authority beyond the assigned MySQL role, but the affected permission decision is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 640,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60586",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.546Z",
      "date_published": "2026-07-21T21:36:01.242Z",
      "date_updated": "2026-07-29T18:19:01.584Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Connectors"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27345
      },
      "nvd": {
        "published": "2026-07-21T22:17:59.050",
        "lastModified": "2026-08-03T14:13:38.337",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60586",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive MySQL Connectors operation can run without authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 666,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60587",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.546Z",
      "date_published": "2026-07-21T21:36:01.579Z",
      "date_updated": "2026-07-27T15:29:17.728Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Project Definition).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Foundation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16311
      },
      "nvd": {
        "published": "2026-07-21T22:17:59.160",
        "lastModified": "2026-07-27T16:18:08.003",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60587",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Project Foundation user can exceed its assigned access, but Oracle does not identify the missing object or action check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 802,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60588",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.546Z",
      "date_published": "2026-07-21T21:36:01.936Z",
      "date_updated": "2026-07-27T15:30:32.161Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition Issues).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Asset Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12845
      },
      "nvd": {
        "published": "2026-07-21T22:17:59.273",
        "lastModified": "2026-08-03T13:53:32.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60588",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Enterprise Asset Management permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 724,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60593",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.546Z",
      "date_published": "2026-07-21T21:36:02.298Z",
      "date_updated": "2026-07-30T13:02:38.662Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office product of Oracle PeopleSoft (component: Staffing Front Office).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Staffing Front Office"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24748
      },
      "nvd": {
        "published": "2026-07-21T22:17:59.383",
        "lastModified": "2026-07-27T16:18:08.237",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60593",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60593 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 647,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60594",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.546Z",
      "date_published": "2026-07-21T21:36:02.638Z",
      "date_updated": "2026-07-30T03:55:10.225Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Campus Community"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33033
      },
      "nvd": {
        "published": "2026-07-21T22:17:59.500",
        "lastModified": "2026-07-31T20:06:53.280",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60594",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Campus Community grants a low-privilege HTTP caller authority sufficient for takeover, while Oracle does not disclose the operation or check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60595",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.546Z",
      "date_published": "2026-07-21T21:36:02.976Z",
      "date_updated": "2026-07-27T15:34:18.995Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Pay/Bill Management product of Oracle PeopleSoft (component: Paybill Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Pay/Bill Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03708
      },
      "nvd": {
        "published": "2026-07-21T22:17:59.613",
        "lastModified": "2026-07-27T16:18:08.490",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60595",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to PeopleSoft Enterprise FIN Pay/Bill Management in its Paybill Management component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 692,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60596",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.546Z",
      "date_published": "2026-07-21T21:36:03.317Z",
      "date_updated": "2026-07-27T15:34:53.612Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN eSettlements"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03749
      },
      "nvd": {
        "published": "2026-07-21T22:17:59.727",
        "lastModified": "2026-07-27T16:18:08.597",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60596",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "low",
        "mechanism": "The record maps the issue to missing authentication for a critical function, although its local high-privilege precondition leaves the exact boundary unclear.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "Editor attention: CWE-306 indicates missing authentication, while the embedded vector requires local access and high privileges; the precise trust boundary remains unclear."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60597",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.546Z",
      "date_published": "2026-07-21T21:36:03.661Z",
      "date_updated": "2026-07-27T15:36:33.420Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Cash Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22437
      },
      "nvd": {
        "published": "2026-07-21T22:17:59.840",
        "lastModified": "2026-07-27T16:18:08.707",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60597",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Cash Management permits an unauthenticated HTTP caller to read and modify critical data, but the failing authority check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 921,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60598",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.546Z",
      "date_published": "2026-07-21T21:36:04.008Z",
      "date_updated": "2026-07-30T03:55:44.345Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Student Records"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23499
      },
      "nvd": {
        "published": "2026-07-21T22:17:59.957",
        "lastModified": "2026-07-31T20:06:30.227",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60598",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Research Tracking permits a low-privileged HTTP caller to take over the application, while the missing role or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60599",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.547Z",
      "date_published": "2026-07-21T21:36:04.438Z",
      "date_updated": "2026-07-30T03:55:45.134Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Student Records"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26308
      },
      "nvd": {
        "published": "2026-07-21T22:18:00.070",
        "lastModified": "2026-07-31T20:05:59.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60599",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says PeopleSoft Enterprise CS Student Records permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 777,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60600",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.547Z",
      "date_published": "2026-07-21T21:36:04.767Z",
      "date_updated": "2026-07-27T15:43:56.357Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Project Costing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04731
      },
      "nvd": {
        "published": "2026-07-21T22:18:00.180",
        "lastModified": "2026-07-27T16:18:09.110",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60600",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an unauthenticated local path to PeopleSoft Project Costing takeover but does not publish the authentication failure.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 711,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60601",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.547Z",
      "date_published": "2026-07-21T21:36:05.118Z",
      "date_updated": "2026-07-27T16:39:34.868Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00104,
        "percentile": 0.01187
      },
      "nvd": {
        "published": "2026-07-21T22:18:00.300",
        "lastModified": "2026-07-27T17:16:37.973",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60601",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 758,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60602",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.547Z",
      "date_published": "2026-07-21T21:36:05.456Z",
      "date_updated": "2026-07-30T03:55:43.617Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Billing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Student Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31657
      },
      "nvd": {
        "published": "2026-07-21T22:18:00.413",
        "lastModified": "2026-07-30T05:16:37.420",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60602",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle maps the PeopleSoft Billing issue to missing authentication while describing a low-privilege HTTP path, without publishing the function or validation step that fails.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60603",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.547Z",
      "date_published": "2026-07-21T21:36:05.785Z",
      "date_updated": "2026-07-27T15:45:39.387Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Australian Features).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Student Records"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33028
      },
      "nvd": {
        "published": "2026-07-21T22:18:00.530",
        "lastModified": "2026-07-31T20:04:24.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60603",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60604",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.547Z",
      "date_published": "2026-07-21T21:36:06.113Z",
      "date_updated": "2026-07-30T03:55:38.198Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Campus Community"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23501
      },
      "nvd": {
        "published": "2026-07-21T22:18:00.650",
        "lastModified": "2026-07-31T20:04:33.007",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60604",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can take over Campus Community, but Oracle does not disclose the critical operation or authentication and authorization check.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60605",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.547Z",
      "date_published": "2026-07-21T21:36:06.446Z",
      "date_updated": "2026-07-30T13:02:38.985Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Higher Ed Statistics Agency - UK HESA).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Student Records"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32424
      },
      "nvd": {
        "published": "2026-07-21T22:18:00.757",
        "lastModified": "2026-07-31T20:05:05.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60605",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A remotely reachable PeopleSoft Student Records HTTP function lacks the authentication required before returning critical data.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 635,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60606",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.547Z",
      "date_published": "2026-07-21T21:36:06.780Z",
      "date_updated": "2026-07-30T03:55:35.737Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CC Common Application Objects"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30427
      },
      "nvd": {
        "published": "2026-07-21T22:18:00.903",
        "lastModified": "2026-07-30T05:16:37.687",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60606",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Common Application Objects permits unauthenticated HTTP data access and modification, but the public material does not identify the failed authorization check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle Critical Patch Update July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html on 2026-08-05; Oracle confirms PeopleSoft CC Common Application Objects 9.2, HTTP reachability, no required privileges, and full data access or modification impact, but the CPU matrix does not disclose the protected operation or failing check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 827,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60607",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.547Z",
      "date_published": "2026-07-21T21:36:07.115Z",
      "date_updated": "2026-07-27T12:27:37.606Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: FM Need Analysis Calculator).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Financial Aid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04239
      },
      "nvd": {
        "published": "2026-07-21T22:18:01.020",
        "lastModified": "2026-07-27T13:18:25.493",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60607",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege local user can read all Financial Aid data, but the public record does not identify the output, storage location, or failed authority check.",
        "basis": [
          "CNA record",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 676,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60608",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.547Z",
      "date_published": "2026-07-21T21:36:07.656Z",
      "date_updated": "2026-07-27T12:26:58.093Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Institutional Methodology Need Analysis).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Financial Aid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02676
      },
      "nvd": {
        "published": "2026-07-21T22:18:01.130",
        "lastModified": "2026-07-27T13:18:25.607",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60608",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that PeopleSoft Enterprise CS Financial Aid permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 825,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60609",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:07.995Z",
      "date_updated": "2026-07-27T12:26:07.477Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Communication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Campus Community"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00376,
        "percentile": 0.30325
      },
      "nvd": {
        "published": "2026-07-21T22:18:01.240",
        "lastModified": "2026-07-31T20:03:43.993",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60609",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Campus Community returns critical communication data to a low-privileged user, but the exposed field and output path are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 614,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60610",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:08.343Z",
      "date_updated": "2026-07-27T12:31:32.703Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Campus Community"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00334,
        "percentile": 0.26008
      },
      "nvd": {
        "published": "2026-07-21T22:18:01.347",
        "lastModified": "2026-07-31T20:02:39.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60610",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated disclosure of all Campus Community data, but the CPU does not identify the response or data-selection error.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 612,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60611",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:08.675Z",
      "date_updated": "2026-07-29T14:40:18.534Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Campus Community"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24731
      },
      "nvd": {
        "published": "2026-07-21T22:18:01.463",
        "lastModified": "2026-07-31T20:02:12.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60611",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports unauthenticated access to Campus Community data but does not identify the endpoint or missing authorization rule.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60612",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:09.011Z",
      "date_updated": "2026-07-30T03:55:41.328Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Financial Aid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17702
      },
      "nvd": {
        "published": "2026-07-21T22:18:01.573",
        "lastModified": "2026-07-30T05:16:37.813",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60612",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read and modify Financial Aid data beyond its role, but the object and failing check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 769,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60613",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:09.344Z",
      "date_updated": "2026-07-27T16:15:43.123Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Student Records"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00374,
        "percentile": 0.30103
      },
      "nvd": {
        "published": "2026-07-21T22:18:01.690",
        "lastModified": "2026-07-31T20:01:49.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60613",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The PeopleSoft Enterprise CS Student Records path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60614",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:09.678Z",
      "date_updated": "2026-07-27T16:19:54.106Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Person Data).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Campus Community"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17519
      },
      "nvd": {
        "published": "2026-07-21T22:18:01.793",
        "lastModified": "2026-07-31T20:00:49.807",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60614",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected operation is available to a caller without sufficient authority, but Oracle does not disclose the failing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 899,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60615",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:10.022Z",
      "date_updated": "2026-07-27T16:41:32.799Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Campus Community"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26356
      },
      "nvd": {
        "published": "2026-07-21T22:18:01.910",
        "lastModified": "2026-07-31T19:55:48.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60615",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The PeopleSoft Enterprise CS Campus Community access path accepts an identity or request signal that is insufficient to authenticate the actor for the requested operation.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 749,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60616",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:10.365Z",
      "date_updated": "2026-07-28T12:03:40.083Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Campus Community"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18985
      },
      "nvd": {
        "published": "2026-07-21T22:18:02.020",
        "lastModified": "2026-07-31T19:54:20.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60616",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PeopleSoft Campus Community exposes a critical Security function over HTTP without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 751,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60617",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:10.770Z",
      "date_updated": "2026-07-27T16:47:39.797Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Campus Community"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16374
      },
      "nvd": {
        "published": "2026-07-21T22:18:02.137",
        "lastModified": "2026-07-31T19:21:35.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60617",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says PeopleSoft Enterprise CS Campus Community permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 751,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60618",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:11.122Z",
      "date_updated": "2026-07-29T18:20:27.697Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Procurement and Subcontract Management product of Oracle JD Edwards (component: Procurement).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Procurement and Subcontract Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31654
      },
      "nvd": {
        "published": "2026-07-21T22:18:02.253",
        "lastModified": "2026-07-29T19:16:49.470",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60618",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged HTTP user can take over JD Edwards Procurement but does not publish the endpoint or permission check.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 634,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60619",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:11.453Z",
      "date_updated": "2026-07-27T12:32:24.359Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: Time Accounting and HRM Base).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne HCM Foundation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22369
      },
      "nvd": {
        "published": "2026-07-21T22:18:02.363",
        "lastModified": "2026-07-27T13:18:26.067",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60619",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 581,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60620",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:11.782Z",
      "date_updated": "2026-07-27T12:33:23.273Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Configurator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14434
      },
      "nvd": {
        "published": "2026-07-21T22:18:02.480",
        "lastModified": "2026-07-27T13:18:26.207",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60620",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle groups input validation, data exposure, access control, and resource effects in one record without enough implementation detail to select one engineering cause.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-200",
          "CWE-284",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 866,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60621",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:12.114Z",
      "date_updated": "2026-07-29T18:20:54.249Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Tools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27455
      },
      "nvd": {
        "published": "2026-07-21T22:18:02.593",
        "lastModified": "2026-07-29T19:16:49.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60621",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A security-sensitive operation is reachable without authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60622",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:12.439Z",
      "date_updated": "2026-07-27T12:34:05.832Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle JDeveloper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32425
      },
      "nvd": {
        "published": "2026-07-21T22:18:02.717",
        "lastModified": "2026-07-31T21:15:18.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60622",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle JDeveloper permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60623",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:12.777Z",
      "date_updated": "2026-07-29T18:19:17.682Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Connectors"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13837
      },
      "nvd": {
        "published": "2026-07-21T22:18:02.830",
        "lastModified": "2026-08-03T13:45:17.257",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60623",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A Connector/J critical operation accepts a low-privilege network caller without the function-level authentication it requires.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 798,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60624",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:13.118Z",
      "date_updated": "2026-07-27T12:34:37.391Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Connectors"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27773
      },
      "nvd": {
        "published": "2026-07-21T22:18:02.943",
        "lastModified": "2026-08-03T13:42:00.433",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60624",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A remote MySQL Connector interaction leaves or releases a resource incorrectly and repeatedly crashes the process, but Oracle does not disclose the resource.",
        "basis": [
          "CNA",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60625",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.548Z",
      "date_published": "2026-07-21T21:36:13.480Z",
      "date_updated": "2026-07-27T12:30:44.412Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Data Integrator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05723
      },
      "nvd": {
        "published": "2026-07-21T22:18:03.060",
        "lastModified": "2026-08-03T13:39:55.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60625",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged local Studio user can obtain higher Data Integrator authority, but the public record does not identify the role transition or missing check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60626",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:13.814Z",
      "date_updated": "2026-07-27T12:36:41.787Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Tools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01257
      },
      "nvd": {
        "published": "2026-07-21T22:18:03.177",
        "lastModified": "2026-07-27T14:16:55.890",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60626",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The JD Edwards EnterpriseOne Tools operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 783,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60627",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:14.153Z",
      "date_updated": "2026-07-29T18:20:12.535Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Tools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31657
      },
      "nvd": {
        "published": "2026-07-21T22:18:03.290",
        "lastModified": "2026-07-29T19:16:49.793",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60627",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "EnterpriseOne Installation Security omits the stronger authentication required before a low-privileged user can take over the tools service.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 682,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60628",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:14.480Z",
      "date_updated": "2026-07-27T12:37:26.558Z",
      "publisher": "oracle",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "JD Edwards EnterpriseOne Tools"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04174
      },
      "nvd": {
        "published": "2026-07-21T22:18:03.403",
        "lastModified": "2026-07-27T14:16:56.007",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60628",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 879,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60629",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:14.814Z",
      "date_updated": "2026-07-27T12:38:07.940Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle JDeveloper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18986
      },
      "nvd": {
        "published": "2026-07-21T22:18:03.510",
        "lastModified": "2026-07-31T21:15:14.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60629",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60629 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 815,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60630",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:15.156Z",
      "date_updated": "2026-08-01T03:56:22.917Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle APEX (component: Installation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle APEX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04511
      },
      "nvd": {
        "published": "2026-07-21T22:18:03.627",
        "lastModified": "2026-08-03T13:12:55.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60630",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle APEX permits a low-privilege local caller to read data beyond its assigned authority, while the object and failing access check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60631",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:15.483Z",
      "date_updated": "2026-07-28T03:56:16.893Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05729
      },
      "nvd": {
        "published": "2026-07-21T22:18:03.733",
        "lastModified": "2026-07-29T19:18:04.333",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60631",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle's record associates Oracle WebCenter Content in its Content Server component with a request-channel trust failure, but does not disclose the vulnerable endpoint or validation rule.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284",
          "CWE-352",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Read https://www.oracle.com/security-alerts/cpujul2026.html; Oracle's CPU confirms the WebCenter Content Server component, HTTP access, no required privileges, required user interaction, and impact, but provides no endpoint or request-forgery validation rule."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 947,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60632",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:15.826Z",
      "date_updated": "2026-07-28T03:56:14.491Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27771
      },
      "nvd": {
        "published": "2026-07-21T22:18:03.850",
        "lastModified": "2026-07-29T19:18:17.047",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60632",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebCenter Content permits an attacker-influenced redirect across an HTTP trust boundary, but the advisory does not identify the redirect parameter or validation path.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-601",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Primary source inspected: https://www.oracle.com/security-alerts/cpujul2026.html. Oracle identifies WebCenter Content Server, HTTP, no authentication, user interaction, and CVSS 9.3; CWE-601 supports a redirect family, but no redirect parameter or validation path is public."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 947,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60633",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:16.172Z",
      "date_updated": "2026-07-28T03:56:18.041Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06541
      },
      "nvd": {
        "published": "2026-07-21T22:18:03.967",
        "lastModified": "2026-07-29T19:18:31.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60633",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Oracle record lists input validation, XSS, CSRF, and redirect weaknesses for one takeover outcome without identifying which mechanism belongs to this CVE.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-79",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60634",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:16.807Z",
      "date_updated": "2026-07-28T03:56:18.779Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09492
      },
      "nvd": {
        "published": "2026-07-21T22:18:04.077",
        "lastModified": "2026-07-29T19:18:39.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60634",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports an unauthenticated user-interaction takeover and assigns input-validation, XSS, CSRF, and redirect CWEs without identifying which mechanism is primary.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-79",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60635",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:17.254Z",
      "date_updated": "2026-07-28T03:56:27.187Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05148
      },
      "nvd": {
        "published": "2026-07-21T22:18:04.190",
        "lastModified": "2026-07-29T19:18:47.277",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60635",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle WebCenter Content accepts a cross-site or redirect-assisted web flow that can end in takeover, while the CPU does not identify the exact request boundary.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60636",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:17.577Z",
      "date_updated": "2026-07-28T03:56:27.969Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05149
      },
      "nvd": {
        "published": "2026-07-21T22:18:04.297",
        "lastModified": "2026-07-29T19:18:55.143",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60636",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle lists input validation, XSS, CSRF, and redirect weaknesses for one user-assisted takeover without enough public detail to select a single causal family.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-79",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60637",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:17.911Z",
      "date_updated": "2026-07-28T03:56:28.728Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09491
      },
      "nvd": {
        "published": "2026-07-21T22:18:04.410",
        "lastModified": "2026-07-29T19:19:01.537",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60637",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-79",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60638",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:18.242Z",
      "date_updated": "2026-07-28T03:56:29.500Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.1175
      },
      "nvd": {
        "published": "2026-07-21T22:18:04.520",
        "lastModified": "2026-07-29T19:19:07.977",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60638",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle records multiple browser/request-boundary weaknesses for WebCenter Content, while the public CPU does not identify which request transition enables takeover.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-79",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60639",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:18.579Z",
      "date_updated": "2026-07-28T03:56:30.268Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05148
      },
      "nvd": {
        "published": "2026-07-21T22:18:04.633",
        "lastModified": "2026-07-29T19:19:15.823",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60639",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports a user-interaction-dependent HTTP trust-boundary failure spanning request forgery, redirect, and script contexts without identifying the first accepted input.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-352",
          "CWE-601",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60640",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:18.919Z",
      "date_updated": "2026-07-28T03:56:30.999Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05635
      },
      "nvd": {
        "published": "2026-07-21T22:18:04.750",
        "lastModified": "2026-07-29T19:19:27.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60640",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle record combines an open redirect and CSRF with takeover impact but does not disclose the request fields or state sequence connecting them.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 763,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60641",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:19.259Z",
      "date_updated": "2026-07-27T12:56:07.019Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20951
      },
      "nvd": {
        "published": "2026-07-21T22:18:04.863",
        "lastModified": "2026-07-31T21:14:08.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60641",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "WebCenter Content accepts an attacker-selected redirect destination that can route a user through an untrusted HTTP location.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 914,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60642",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:40.549Z",
      "date_published": "2026-07-21T21:36:19.609Z",
      "date_updated": "2026-07-27T12:57:12.680Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01934
      },
      "nvd": {
        "published": "2026-07-21T22:18:04.973",
        "lastModified": "2026-07-31T21:14:01.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60642",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle request can cross a CSRF or redirect trust boundary, but the public record does not identify the action, redirect, or origin rule.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 914,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60643",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.574Z",
      "date_published": "2026-07-21T21:36:19.953Z",
      "date_updated": "2026-07-28T03:56:32.558Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00185,
        "percentile": 0.08311
      },
      "nvd": {
        "published": "2026-07-21T22:18:05.083",
        "lastModified": "2026-07-29T19:19:35.927",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60643",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebCenter Content accepts a user-mediated cross-site request, but the public record does not identify the state-changing endpoint or missing request-origin control.",
        "basis": [
          "CNA record",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 632,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60644",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.574Z",
      "date_published": "2026-07-21T21:36:20.315Z",
      "date_updated": "2026-07-28T03:56:34.068Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28165
      },
      "nvd": {
        "published": "2026-07-21T22:18:05.193",
        "lastModified": "2026-07-29T19:19:44.057",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60644",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle WebCenter Content exposes a security-sensitive endpoint without requiring caller authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60645",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.574Z",
      "date_published": "2026-07-21T21:36:20.661Z",
      "date_updated": "2026-07-28T03:56:34.858Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37109
      },
      "nvd": {
        "published": "2026-07-21T22:18:05.303",
        "lastModified": "2026-07-29T19:19:56.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60645",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebCenter Content lets a high-privileged HTTP user cross into a takeover action, but Oracle does not disclose the missing authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60646",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.574Z",
      "date_published": "2026-07-21T21:36:21.014Z",
      "date_updated": "2026-07-28T03:56:35.694Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07422
      },
      "nvd": {
        "published": "2026-07-21T22:18:05.417",
        "lastModified": "2026-07-29T19:20:03.883",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60646",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Oracle record lists XSS, CSRF, open redirect, and password-recovery weaknesses for one takeover impact without identifying which mechanism begins the demonstrated path.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-352",
          "CWE-601",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 640,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60647",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.574Z",
      "date_published": "2026-07-21T21:36:21.414Z",
      "date_updated": "2026-07-27T12:47:17.612Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28747
      },
      "nvd": {
        "published": "2026-07-21T22:18:05.533",
        "lastModified": "2026-07-31T21:13:52.407",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60647",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports WebCenter data disclosure and partial denial of service but does not identify a request, check, or resource invariant.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 717,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60648",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.575Z",
      "date_published": "2026-07-21T21:36:21.756Z",
      "date_updated": "2026-07-28T03:56:36.549Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08108
      },
      "nvd": {
        "published": "2026-07-21T22:18:05.643",
        "lastModified": "2026-07-29T19:20:11.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60648",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Oracle record lists several unrelated weakness classes and takeover impact without identifying which mechanism applies to Web Content Management.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20",
          "CWE-295",
          "CWE-352",
          "CWE-601",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 640,
        "referenceCount": 1,
        "cweCount": 5,
        "cnaCweCount": 0,
        "adpCweCount": 5,
        "nvdCweCount": 5,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60649",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.575Z",
      "date_published": "2026-07-21T21:36:22.099Z",
      "date_updated": "2026-07-28T03:56:42.887Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32426
      },
      "nvd": {
        "published": "2026-07-21T22:18:05.757",
        "lastModified": "2026-07-29T19:20:17.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60649",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP caller can read or modify all WebCenter Content data, but Oracle does not disclose the endpoint, protected object, or failing authorization decision.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle's July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms unauthenticated HTTP reachability of WebCenter Content Web Content Management, CVSS 9.1, and complete read/write impact, but publishes no endpoint, protected object, or failing authorization decision."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 743,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60650",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.575Z",
      "date_published": "2026-07-21T21:36:22.435Z",
      "date_updated": "2026-07-28T03:56:43.619Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07422
      },
      "nvd": {
        "published": "2026-07-21T22:18:05.870",
        "lastModified": "2026-07-29T19:20:27.150",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60650",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record combines XSS, CSRF, open redirect, and password-recovery impacts without enough mechanism detail to select one primary cause.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-79",
          "CWE-352",
          "CWE-601",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 640,
        "referenceCount": 1,
        "cweCount": 5,
        "cnaCweCount": 0,
        "adpCweCount": 5,
        "nvdCweCount": 5,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60651",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.575Z",
      "date_published": "2026-07-21T21:36:22.781Z",
      "date_updated": "2026-07-29T18:18:40.632Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23511
      },
      "nvd": {
        "published": "2026-07-21T22:18:06.010",
        "lastModified": "2026-07-31T21:13:47.760",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60651",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle WebCenter Content operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60652",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.575Z",
      "date_published": "2026-07-21T21:36:23.126Z",
      "date_updated": "2026-07-29T18:18:25.184Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24869
      },
      "nvd": {
        "published": "2026-07-21T22:18:06.137",
        "lastModified": "2026-07-31T21:13:37.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60652",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can take over WebCenter Content after another user's interaction, but the protected operation and failing check are not public.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 640,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60653",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.575Z",
      "date_published": "2026-07-21T21:36:23.466Z",
      "date_updated": "2026-07-29T18:18:00.187Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17785
      },
      "nvd": {
        "published": "2026-07-21T22:18:06.253",
        "lastModified": "2026-07-31T21:13:26.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60653",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle WebCenter Content permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 742,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60654",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.575Z",
      "date_published": "2026-07-21T21:36:23.826Z",
      "date_updated": "2026-07-28T03:56:47.429Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.2244
      },
      "nvd": {
        "published": "2026-07-21T22:18:06.370",
        "lastModified": "2026-07-29T12:34:08.390",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60654",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged HTTP user can take over Web Content Management but does not publish the endpoint or permission check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60655",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.575Z",
      "date_published": "2026-07-21T21:36:24.171Z",
      "date_updated": "2026-07-28T03:56:48.207Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.3302
      },
      "nvd": {
        "published": "2026-07-21T22:18:06.487",
        "lastModified": "2026-07-29T12:34:31.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60655",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60656",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.575Z",
      "date_published": "2026-07-21T21:36:24.514Z",
      "date_updated": "2026-07-28T03:56:48.969Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33021
      },
      "nvd": {
        "published": "2026-07-21T22:18:06.597",
        "lastModified": "2026-07-29T12:34:56.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60656",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60657",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.575Z",
      "date_published": "2026-07-21T21:36:24.869Z",
      "date_updated": "2026-07-29T19:26:41.653Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.14992
      },
      "nvd": {
        "published": "2026-07-21T22:18:06.700",
        "lastModified": "2026-07-29T20:17:07.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60657",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle WebCenter Content but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 948,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60658",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.575Z",
      "date_published": "2026-07-21T21:36:25.201Z",
      "date_updated": "2026-07-28T03:56:50.771Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04673
      },
      "nvd": {
        "published": "2026-07-21T22:18:06.817",
        "lastModified": "2026-07-29T13:06:02.540",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60658",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle record combines CSRF, open redirect, weak password recovery, and critical-UI misrepresentation with a takeover impact but does not disclose the operation or state sequence connecting those labels.",
        "basis": [
          "CNA",
          "CWE-352",
          "CWE-451",
          "CWE-601",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 635,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60659",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.575Z",
      "date_published": "2026-07-21T21:36:25.550Z",
      "date_updated": "2026-07-24T19:32:34.027Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Solaris"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03296
      },
      "nvd": {
        "published": "2026-07-21T22:18:06.923",
        "lastModified": "2026-07-31T21:23:12.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60659",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege local user can modify protected Solaris filesystem data, but Oracle does not publish the unsafe permission or filesystem object.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 691,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60661",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.576Z",
      "date_published": "2026-07-21T21:36:25.879Z",
      "date_updated": "2026-07-28T03:56:58.388Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Solaris"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02272
      },
      "nvd": {
        "published": "2026-07-21T22:18:07.040",
        "lastModified": "2026-07-31T21:23:55.593",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60661",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports a local low-privileged Solaris filesystem takeover but does not disclose the path, object, privilege transition, or engineering cause.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 637,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60663",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.576Z",
      "date_published": "2026-07-21T21:36:26.259Z",
      "date_updated": "2026-07-28T03:56:51.553Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22444
      },
      "nvd": {
        "published": "2026-07-21T22:18:07.150",
        "lastModified": "2026-07-29T13:06:27.617",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60663",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Web Content Management user can take over WebCenter Content, but Oracle does not publish the privileged operation or authorization check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official table confirms Web Content Management, HTTP, low privileges, scope change, score, and versions but no causal authorization path."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 682,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60664",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.576Z",
      "date_published": "2026-07-21T21:36:26.603Z",
      "date_updated": "2026-07-28T03:56:53.034Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Content"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.1175
      },
      "nvd": {
        "published": "2026-07-21T22:18:07.270",
        "lastModified": "2026-07-29T13:06:52.227",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60664",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record assigns XSS, CSRF, and open-redirect weaknesses to one takeover outcome without identifying which request path is primary.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60665",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.576Z",
      "date_published": "2026-07-21T21:36:26.942Z",
      "date_updated": "2026-07-24T19:21:17.668Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise HCM Global Payroll Switzerland"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18942
      },
      "nvd": {
        "published": "2026-07-21T22:18:07.380",
        "lastModified": "2026-08-03T12:51:02.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60665",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged payroll user can obtain broad data access, but Oracle does not identify the failing authorization binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 990,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60666",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.576Z",
      "date_published": "2026-07-21T21:36:27.336Z",
      "date_updated": "2026-07-24T19:24:21.290Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise HCM Human Resources"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12801
      },
      "nvd": {
        "published": "2026-07-21T22:18:07.500",
        "lastModified": "2026-08-03T12:50:14.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60666",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that PeopleSoft Enterprise HCM Human Resources permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 776,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60667",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.576Z",
      "date_published": "2026-07-21T21:36:27.686Z",
      "date_updated": "2026-07-24T19:25:05.965Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise HCM Human Resources"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25731
      },
      "nvd": {
        "published": "2026-07-21T22:18:07.620",
        "lastModified": "2026-08-03T12:49:02.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60667",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Enterprise HCM Human Resources accepts an attacker-controlled size, count, recursion depth, or work request without the quota or upper bound needed to keep resource use finite.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 762,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60668",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.576Z",
      "date_published": "2026-07-21T21:36:28.038Z",
      "date_updated": "2026-07-24T19:25:43.198Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: French Public Sector Specific).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise HCM Human Resources"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26356
      },
      "nvd": {
        "published": "2026-07-21T22:18:07.747",
        "lastModified": "2026-08-03T12:48:14.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60668",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Human Resources permits an unauthenticated HTTP caller to read and modify protected data, while the authorization boundary is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 767,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60669",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.576Z",
      "date_published": "2026-07-21T21:36:28.392Z",
      "date_updated": "2026-07-24T19:26:19.494Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Payroll for Mexico).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise HCM Global Payroll Mexico"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11041
      },
      "nvd": {
        "published": "2026-07-21T22:18:07.867",
        "lastModified": "2026-08-03T12:38:59.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60669",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record reports attacker-triggered denial of service in PeopleSoft Enterprise HCM Global Payroll Mexico, but does not identify the unbounded work or unreleased resource.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 796,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60670",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.576Z",
      "date_published": "2026-07-21T21:36:28.843Z",
      "date_updated": "2026-07-24T19:27:10.169Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications Technology Stack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00271,
        "percentile": 0.19302
      },
      "nvd": {
        "published": "2026-07-21T22:18:07.980",
        "lastModified": "2026-07-24T20:18:15.910",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60670",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle component exposes a critical function without the required authentication, although the public record does not name the function.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60671",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.576Z",
      "date_published": "2026-07-21T21:36:29.185Z",
      "date_updated": "2026-07-24T19:17:09.191Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Business Intelligence Enterprise Edition"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14745
      },
      "nvd": {
        "published": "2026-07-21T22:18:08.093",
        "lastModified": "2026-07-24T20:18:16.047",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60671",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle BI permits an unauthenticated HTTP caller to read, modify, and disrupt protected data, but the exact missing critical-function check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 931,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60673",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.577Z",
      "date_published": "2026-07-21T21:36:29.526Z",
      "date_updated": "2026-07-24T19:20:32.773Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle BI Publisher"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00355,
        "percentile": 0.28256
      },
      "nvd": {
        "published": "2026-07-21T22:18:08.213",
        "lastModified": "2026-07-24T20:18:16.187",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60673",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle BI Publisher XML Services returns protected data to a low-privileged caller, while the public record does not identify the field or output path.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 575,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60674",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.577Z",
      "date_published": "2026-07-21T21:36:29.874Z",
      "date_updated": "2026-07-24T19:33:32.746Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Business Intelligence Enterprise Edition"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15692
      },
      "nvd": {
        "published": "2026-07-21T22:18:08.330",
        "lastModified": "2026-07-24T20:18:16.303",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60674",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Business Intelligence Enterprise Edition permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 802,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60675",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.577Z",
      "date_published": "2026-07-21T21:36:30.218Z",
      "date_updated": "2026-07-24T19:19:57.729Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22487
      },
      "nvd": {
        "published": "2026-07-21T22:18:08.453",
        "lastModified": "2026-07-31T21:23:28.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60675",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a low-privileged HTTP path to Applications Framework takeover but does not publish the Search Bean authorization failure.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 547,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60676",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.577Z",
      "date_published": "2026-07-21T21:36:30.562Z",
      "date_updated": "2026-07-24T19:19:21.896Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33077
      },
      "nvd": {
        "published": "2026-07-21T22:18:08.573",
        "lastModified": "2026-07-31T21:23:36.097",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60676",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 547,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60677",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.577Z",
      "date_published": "2026-07-21T21:36:30.909Z",
      "date_updated": "2026-07-28T14:56:31.758Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Common Application Components product of Oracle E-Business Suite (component: Oracle Common Modules).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Common Application Components"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18955
      },
      "nvd": {
        "published": "2026-07-21T22:18:08.680",
        "lastModified": "2026-07-28T16:19:24.467",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60677",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1046,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60678",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.577Z",
      "date_published": "2026-07-21T21:36:31.261Z",
      "date_updated": "2026-07-24T19:18:44.898Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle General Ledger"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34352
      },
      "nvd": {
        "published": "2026-07-21T22:18:08.793",
        "lastModified": "2026-07-24T20:18:16.730",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60678",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A security-sensitive endpoint performs its operation without requiring the caller to authenticate.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60681",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.578Z",
      "date_published": "2026-07-21T21:36:31.756Z",
      "date_updated": "2026-07-24T15:25:46.317Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Regulatory Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20834
      },
      "nvd": {
        "published": "2026-07-21T22:18:08.910",
        "lastModified": "2026-07-24T16:16:37.060",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60681",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can take over Process Manufacturing Regulatory Management, but Oracle does not disclose the protected operation or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 618,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60683",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.578Z",
      "date_published": "2026-07-21T21:36:32.088Z",
      "date_updated": "2026-07-24T15:25:38.535Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Regulatory Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25102
      },
      "nvd": {
        "published": "2026-07-21T22:18:09.017",
        "lastModified": "2026-07-24T16:16:37.200",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60683",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged E-Business Suite caller can read complete regulatory-management data beyond its intended role, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 810,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.578Z",
      "date_published": "2026-07-21T21:36:32.431Z",
      "date_updated": "2026-07-24T19:13:07.259Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09564
      },
      "nvd": {
        "published": "2026-07-21T22:18:09.130",
        "lastModified": "2026-07-31T21:23:42.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60684",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle product allows an action beyond the caller's intended authority, but the public record does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 783,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.578Z",
      "date_published": "2026-07-21T21:36:32.869Z",
      "date_updated": "2026-07-24T19:12:22.142Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iSupport"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02582
      },
      "nvd": {
        "published": "2026-07-21T22:18:09.240",
        "lastModified": "2026-07-24T20:18:17.017",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60685",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record lists access control, CSRF, and open redirect weaknesses without identifying which mechanism enables the reported iSupport data access.",
        "basis": [
          "CNA record",
          "CWE-284",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": "The structured weaknesses span different cause families and the description contains only access consequences."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 848,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60686",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.578Z",
      "date_published": "2026-07-21T21:36:33.190Z",
      "date_updated": "2026-07-24T19:10:01.994Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged atta...",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle U.S. Federal Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25136
      },
      "nvd": {
        "published": "2026-07-21T22:18:09.360",
        "lastModified": "2026-07-24T20:18:17.173",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60686",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle U.S. Federal Financials permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 750,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.578Z",
      "date_published": "2026-07-21T21:36:33.520Z",
      "date_updated": "2026-07-24T19:10:44.666Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated a...",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle U.S. Federal Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15623
      },
      "nvd": {
        "published": "2026-07-21T22:18:09.473",
        "lastModified": "2026-07-24T20:18:17.310",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60687",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle U.S. Federal Financials exposes critical data to an unauthenticated HTTPS caller, but the failing access-control path is not public.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 734,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.578Z",
      "date_published": "2026-07-21T21:36:33.885Z",
      "date_updated": "2026-07-24T19:11:33.952Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Scheduler product of Oracle E-Business Suite (component: Rules UI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Scheduler"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16312
      },
      "nvd": {
        "published": "2026-07-21T22:18:09.587",
        "lastModified": "2026-07-24T20:18:17.443",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60688",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports low-privileged read, write, and partial denial-of-service impact in Scheduler Rules UI, but the CPU does not identify the protected object or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 747,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60689",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.578Z",
      "date_published": "2026-07-21T21:36:35.231Z",
      "date_updated": "2026-07-25T03:55:48.486Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Cloud Applications"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00414,
        "percentile": 0.34092
      },
      "nvd": {
        "published": "2026-07-21T22:18:09.703",
        "lastModified": "2026-08-03T20:32:48.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60689",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable security-sensitive operation is exposed without the authentication step required before invoking it.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.578Z",
      "date_published": "2026-07-21T21:36:35.604Z",
      "date_updated": "2026-07-29T19:26:43.296Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Cloud Applications"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27908
      },
      "nvd": {
        "published": "2026-07-21T22:18:09.817",
        "lastModified": "2026-08-03T20:37:36.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60690",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read Siebel Cloud Manager data beyond its role, but the protected object and failing check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 716,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60691",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.578Z",
      "date_published": "2026-07-21T21:36:35.960Z",
      "date_updated": "2026-07-24T15:25:25.148Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Content Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16127
      },
      "nvd": {
        "published": "2026-07-21T22:18:09.923",
        "lastModified": "2026-07-24T16:16:37.453",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60691",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Content Manager path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 718,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60692",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.578Z",
      "date_published": "2026-07-21T21:36:36.308Z",
      "date_updated": "2026-07-24T15:25:18.149Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Asset Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33077
      },
      "nvd": {
        "published": "2026-07-21T22:18:10.037",
        "lastModified": "2026-07-28T17:19:45.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60692",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle operation is reachable with insufficient caller authority, but the public advisory withholds the exact access decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60694",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.579Z",
      "date_published": "2026-07-21T21:36:36.653Z",
      "date_updated": "2026-07-24T15:25:09.543Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Asset Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09564
      },
      "nvd": {
        "published": "2026-07-21T22:18:10.150",
        "lastModified": "2026-07-28T17:19:53.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60694",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Enterprise Asset Management operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 942,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.579Z",
      "date_published": "2026-07-21T21:36:36.986Z",
      "date_updated": "2026-07-24T15:25:00.502Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Asset Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22706
      },
      "nvd": {
        "published": "2026-07-21T22:18:10.260",
        "lastModified": "2026-07-28T17:20:03.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60695",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged HTTP caller can cross an Oracle Enterprise Asset Management data boundary, but the protected operation and failing check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 769,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.579Z",
      "date_published": "2026-07-21T21:36:37.325Z",
      "date_updated": "2026-07-24T15:24:53.789Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy Flows).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Site Hub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08817
      },
      "nvd": {
        "published": "2026-07-21T22:18:10.373",
        "lastModified": "2026-07-24T16:16:37.937",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60697",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Site Hub permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 754,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60700",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.579Z",
      "date_published": "2026-07-21T21:36:37.704Z",
      "date_updated": "2026-07-24T15:24:44.374Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: UWQ Server Issues).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Universal Work Queue"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27772
      },
      "nvd": {
        "published": "2026-07-21T22:18:10.483",
        "lastModified": "2026-07-30T17:35:32.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60700",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 821,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60701",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.579Z",
      "date_published": "2026-07-21T21:36:38.237Z",
      "date_updated": "2026-07-24T15:24:37.195Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Universal Work Queue"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20048
      },
      "nvd": {
        "published": "2026-07-21T22:18:10.597",
        "lastModified": "2026-07-30T17:35:39.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60701",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60703",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.580Z",
      "date_published": "2026-07-21T21:36:38.670Z",
      "date_updated": "2026-07-24T15:24:30.797Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Interaction Blending"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01572
      },
      "nvd": {
        "published": "2026-07-21T22:18:10.713",
        "lastModified": "2026-07-24T16:16:38.293",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60703",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle Interaction Blending but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 785,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60704",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.580Z",
      "date_published": "2026-07-21T21:36:39.009Z",
      "date_updated": "2026-07-29T19:26:43.143Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Cloud Applications"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24506
      },
      "nvd": {
        "published": "2026-07-21T22:18:10.830",
        "lastModified": "2026-08-03T20:32:02.737",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60704",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Siebel CRM Cloud Applications exposes a security-sensitive operation without verifying that the network caller is authenticated.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60705",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.580Z",
      "date_published": "2026-07-21T21:36:39.360Z",
      "date_updated": "2026-07-24T19:15:27.475Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Cloud Applications"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21384
      },
      "nvd": {
        "published": "2026-07-21T22:18:10.940",
        "lastModified": "2026-08-03T20:37:23.877",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60705",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Siebel Cloud Manager exposes critical data and mutations through an HTTP path that lacks authentication for the affected function.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 839,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60706",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.580Z",
      "date_published": "2026-07-21T21:36:39.711Z",
      "date_updated": "2026-07-24T19:14:44.643Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Inventory product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Inventory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25098
      },
      "nvd": {
        "published": "2026-07-21T22:18:11.053",
        "lastModified": "2026-07-24T20:18:17.700",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60706",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports that a low-privileged Process Manufacturing user can read and alter critical inventory data but discloses no enabling cause.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 782,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60708",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.580Z",
      "date_published": "2026-07-21T21:36:40.089Z",
      "date_updated": "2026-07-24T19:13:57.444Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16171
      },
      "nvd": {
        "published": "2026-07-21T22:18:11.210",
        "lastModified": "2026-07-24T20:18:17.830",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60708",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Process Manufacturing Financials user can read or modify critical data outside the role's intended scope, but the failing access check is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 786,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60709",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.580Z",
      "date_published": "2026-07-21T21:36:40.420Z",
      "date_updated": "2026-07-24T19:05:40.311Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Cloud Applications"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00185,
        "percentile": 0.08331
      },
      "nvd": {
        "published": "2026-07-21T22:18:11.323",
        "lastModified": "2026-08-03T18:55:21.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60709",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Siebel CRM Cloud Applications operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 788,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60710",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.581Z",
      "date_published": "2026-07-21T21:36:40.749Z",
      "date_updated": "2026-07-24T19:06:21.699Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle EDI Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17783
      },
      "nvd": {
        "published": "2026-07-21T22:18:11.440",
        "lastModified": "2026-08-03T17:09:21.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60710",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged EDI Gateway user can exceed assigned data access, but Oracle does not disclose the missing authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 702,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60711",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.581Z",
      "date_published": "2026-07-21T21:36:41.081Z",
      "date_updated": "2026-07-25T03:55:46.526Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Cloud Applications"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33023
      },
      "nvd": {
        "published": "2026-07-21T22:18:11.553",
        "lastModified": "2026-08-03T20:36:20.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60711",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Siebel Cloud Manager permits a low-privileged HTTP caller to reach takeover-level operations, while Oracle does not publish the missing authority transition.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html - Oracle confirms Siebel Cloud Manager, HTTP reachability, low privileges, and affected versions, but publishes no authentication or authorization transition that explains takeover."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 676,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60712",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.581Z",
      "date_published": "2026-07-21T21:36:41.423Z",
      "date_updated": "2026-07-30T16:48:14.516Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Cloud Applications"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05117
      },
      "nvd": {
        "published": "2026-07-21T22:18:11.670",
        "lastModified": "2026-08-03T20:31:33.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60712",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Siebel CRM Cloud Applications fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-306",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 765,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.581Z",
      "date_published": "2026-07-21T21:36:41.763Z",
      "date_updated": "2026-07-24T18:15:58.541Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Cloud Applications"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03718
      },
      "nvd": {
        "published": "2026-07-21T22:18:11.790",
        "lastModified": "2026-08-03T20:36:09.070",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60713",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Siebel Cloud Manager permits a low-privilege local caller to read and modify data beyond its role, while the operation and check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 739,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60714",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.581Z",
      "date_published": "2026-07-21T21:36:42.125Z",
      "date_updated": "2026-07-24T19:06:59.604Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Price Protection"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26313
      },
      "nvd": {
        "published": "2026-07-21T22:18:11.903",
        "lastModified": "2026-07-29T18:13:10.937",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60714",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle Price Protection in its Internal Operations component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 722,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60717",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.582Z",
      "date_published": "2026-07-21T21:36:42.639Z",
      "date_updated": "2026-07-24T19:07:34.944Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Common Utilities).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Complex Maintenance, Repair and Overhaul"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12802
      },
      "nvd": {
        "published": "2026-07-21T22:18:12.020",
        "lastModified": "2026-08-03T16:53:08.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60717",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle component lets a remote caller exceed its assigned authority, but the public record does not identify the object, action, or failing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 769,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60718",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.582Z",
      "date_published": "2026-07-21T21:36:43.081Z",
      "date_updated": "2026-07-24T19:08:16.398Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00422,
        "percentile": 0.34814
      },
      "nvd": {
        "published": "2026-07-21T22:18:12.133",
        "lastModified": "2026-07-27T17:59:04.533",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60718",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle MySQL JSON processing lets a low-privileged network query repeatedly hang or crash the server, but the exhausted resource is not public.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 627,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60719",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.582Z",
      "date_published": "2026-07-21T21:36:43.416Z",
      "date_updated": "2026-07-24T19:09:09.345Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle BI Publisher"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00387,
        "percentile": 0.3143
      },
      "nvd": {
        "published": "2026-07-21T22:18:12.250",
        "lastModified": "2026-08-03T16:46:47.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60719",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports broad confidentiality, integrity, and availability impact in the BI Publisher Web Service API but provides several incompatible weakness classes and no causal path.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-269",
          "CWE-284",
          "CWE-400",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official table confirms a low-privileged HTTP path and broad impact, but does not distinguish input validation, privilege management, access control, or resource consumption as the primary cause."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 953,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-60723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.583Z",
      "date_published": "2026-07-21T21:36:43.765Z",
      "date_updated": "2026-07-24T15:24:23.885Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Data Integrator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05495
      },
      "nvd": {
        "published": "2026-07-21T22:18:12.363",
        "lastModified": "2026-08-03T16:40:20.960",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60723",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Data Integrator permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 890,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60724",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.583Z",
      "date_published": "2026-07-21T21:36:44.100Z",
      "date_updated": "2026-07-24T15:24:16.253Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Customer Interaction History"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12689
      },
      "nvd": {
        "published": "2026-07-21T22:18:12.490",
        "lastModified": "2026-07-24T16:16:38.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60724",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized Customer Interaction History reads and writes but does not publish the object or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 719,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60725",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.583Z",
      "date_published": "2026-07-21T21:36:44.439Z",
      "date_updated": "2026-07-28T03:56:08.238Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.2409
      },
      "nvd": {
        "published": "2026-07-21T22:18:12.617",
        "lastModified": "2026-07-28T16:57:37.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60725",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 681,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-60732",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.584Z",
      "date_published": "2026-07-21T21:36:44.772Z",
      "date_updated": "2026-07-24T15:23:53.154Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iReceivables"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17819
      },
      "nvd": {
        "published": "2026-07-21T22:18:13.587",
        "lastModified": "2026-07-30T17:35:53.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60732",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 703,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60734",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.585Z",
      "date_published": "2026-07-21T21:36:45.115Z",
      "date_updated": "2026-07-24T15:23:44.896Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Trading Community"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00431,
        "percentile": 0.35457
      },
      "nvd": {
        "published": "2026-07-21T22:18:13.867",
        "lastModified": "2026-07-24T16:16:38.977",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60734",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle Trading Community but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60735",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.585Z",
      "date_published": "2026-07-21T21:36:45.455Z",
      "date_updated": "2026-07-24T15:23:35.037Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Sales Offline"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17819
      },
      "nvd": {
        "published": "2026-07-21T22:18:13.987",
        "lastModified": "2026-07-27T17:33:30.217",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60735",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read and modify Sales Offline data beyond its authority, but Oracle does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 710,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60736",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.585Z",
      "date_published": "2026-07-21T21:36:45.806Z",
      "date_updated": "2026-07-24T15:23:28.218Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle E-Business Intelligence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26311
      },
      "nvd": {
        "published": "2026-07-21T22:18:14.103",
        "lastModified": "2026-08-03T11:47:42.873",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60736",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged E-Business Intelligence caller can read and modify critical data beyond its intended role, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 741,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.585Z",
      "date_published": "2026-07-21T21:36:46.155Z",
      "date_updated": "2026-07-24T15:23:21.241Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Installed Base"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33031
      },
      "nvd": {
        "published": "2026-07-21T22:18:14.227",
        "lastModified": "2026-07-30T17:36:03.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60738",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle product allows an action beyond the caller's intended authority, but the public record does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60739",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.585Z",
      "date_published": "2026-07-21T21:36:46.487Z",
      "date_updated": "2026-07-24T15:23:12.820Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Field Service"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.12959
      },
      "nvd": {
        "published": "2026-07-21T22:18:14.347",
        "lastModified": "2026-08-03T16:34:37.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60739",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege Field Service user can read critical data and modify some data, but the object and failing permission check are not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 687,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60740",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.585Z",
      "date_published": "2026-07-21T21:36:46.837Z",
      "date_updated": "2026-07-24T15:23:04.556Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Cash Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Cash Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16173
      },
      "nvd": {
        "published": "2026-07-21T22:18:14.460",
        "lastModified": "2026-07-24T16:16:39.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60740",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Cash Management permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 718,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60741",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.586Z",
      "date_published": "2026-07-21T21:36:47.163Z",
      "date_updated": "2026-07-24T19:01:04.714Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Cost Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26352
      },
      "nvd": {
        "published": "2026-07-21T22:18:14.577",
        "lastModified": "2026-07-29T15:52:49.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60741",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Cost Management lets a low-privileged HTTP user read and modify critical data beyond the role's scope, but the failing check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 718,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60744",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.586Z",
      "date_published": "2026-07-21T21:36:47.498Z",
      "date_updated": "2026-07-24T19:00:13.347Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Cost Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18941
      },
      "nvd": {
        "published": "2026-07-21T22:18:14.690",
        "lastModified": "2026-07-28T21:03:23.257",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60744",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports low-privileged access to all Cost Management data, but the CPU does not identify the protected object or missing authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 720,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.587Z",
      "date_published": "2026-07-21T21:36:47.847Z",
      "date_updated": "2026-07-24T19:01:57.160Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03616
      },
      "nvd": {
        "published": "2026-07-21T22:18:14.807",
        "lastModified": "2026-07-27T17:58:38.883",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60747",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports a local MySQL replication crash but does not identify the malformed state or resource failure.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-60749",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.587Z",
      "date_published": "2026-07-21T21:36:48.190Z",
      "date_updated": "2026-07-24T19:02:41.692Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Assets"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25138
      },
      "nvd": {
        "published": "2026-07-21T22:18:14.917",
        "lastModified": "2026-07-24T19:17:07.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60749",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read and modify Oracle Assets data beyond its role, but the protected object and failing check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 682,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60750",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.587Z",
      "date_published": "2026-07-21T21:36:48.528Z",
      "date_updated": "2026-07-24T19:17:54.845Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26351
      },
      "nvd": {
        "published": "2026-07-21T22:18:15.040",
        "lastModified": "2026-07-27T18:23:21.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60750",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Payroll path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 666,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.587Z",
      "date_published": "2026-07-21T21:36:48.876Z",
      "date_updated": "2026-07-24T15:22:56.112Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Assets"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24042
      },
      "nvd": {
        "published": "2026-07-21T22:18:15.153",
        "lastModified": "2026-07-24T16:16:39.710",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60755",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected Oracle action is reachable without sufficient privilege, but the exact role or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.587Z",
      "date_published": "2026-07-21T21:36:49.217Z",
      "date_updated": "2026-07-24T15:22:48.553Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: All Miscellaneous EDI Issues).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle EDI Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29325
      },
      "nvd": {
        "published": "2026-07-21T22:18:15.263",
        "lastModified": "2026-08-03T16:26:41.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60756",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle EDI Gateway operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 534,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.588Z",
      "date_published": "2026-07-21T21:36:49.577Z",
      "date_updated": "2026-07-24T15:22:41.168Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Asset Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04567
      },
      "nvd": {
        "published": "2026-07-21T22:18:15.380",
        "lastModified": "2026-08-03T16:18:24.837",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60760",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read and modify Oracle Enterprise Asset Management data, but the object and permission check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 722,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.588Z",
      "date_published": "2026-07-21T21:36:49.970Z",
      "date_updated": "2026-08-01T03:56:50.879Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications DBA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02474
      },
      "nvd": {
        "published": "2026-07-21T22:18:15.493",
        "lastModified": "2026-08-01T05:17:00.640",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60761",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Applications DBA permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 745,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60762",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.588Z",
      "date_published": "2026-07-21T21:36:50.313Z",
      "date_updated": "2026-07-24T15:22:25.353Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications Technology Stack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04187
      },
      "nvd": {
        "published": "2026-07-21T22:18:15.610",
        "lastModified": "2026-08-03T16:12:04.627",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60762",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a high-privileged local user can read and modify Applications Technology Stack configuration data but does not publish the object or rule.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 827,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.588Z",
      "date_published": "2026-07-21T21:36:50.656Z",
      "date_updated": "2026-07-24T15:22:18.143Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03088
      },
      "nvd": {
        "published": "2026-07-21T22:18:15.720",
        "lastModified": "2026-07-24T16:16:40.293",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60763",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 603,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.588Z",
      "date_published": "2026-07-21T21:36:50.999Z",
      "date_updated": "2026-07-24T15:22:11.292Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Financials Common Modules"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16172
      },
      "nvd": {
        "published": "2026-07-21T22:18:15.840",
        "lastModified": "2026-07-24T16:16:40.420",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60764",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 756,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.589Z",
      "date_published": "2026-07-21T21:36:51.329Z",
      "date_updated": "2026-07-24T15:22:01.950Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Graph / Charting).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17786
      },
      "nvd": {
        "published": "2026-07-21T22:18:15.957",
        "lastModified": "2026-07-30T17:36:45.883",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60768",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle Applications Framework but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 743,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.589Z",
      "date_published": "2026-07-21T21:36:51.690Z",
      "date_updated": "2026-07-24T15:21:54.902Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Object Library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23541
      },
      "nvd": {
        "published": "2026-07-21T22:18:16.067",
        "lastModified": "2026-07-30T17:37:02.933",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60770",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Application Object Library permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 554,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.589Z",
      "date_published": "2026-07-21T21:36:52.039Z",
      "date_updated": "2026-07-24T15:21:48.156Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Complex Maintenance, Repair and Overhaul"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25134
      },
      "nvd": {
        "published": "2026-07-21T22:18:16.183",
        "lastModified": "2026-07-24T16:16:40.810",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60771",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege HTTP caller can read and modify critical maintenance data, but Oracle does not publish the missing object or role check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 818,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60772",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.589Z",
      "date_published": "2026-07-21T21:36:52.365Z",
      "date_updated": "2026-07-24T19:03:22.188Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Financials Common Modules"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09677
      },
      "nvd": {
        "published": "2026-07-21T22:18:16.327",
        "lastModified": "2026-07-24T20:18:18.867",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60772",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports that a low-privileged Financials user can read and alter protected data but discloses no operation or failed check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 733,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60773",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.589Z",
      "date_published": "2026-07-21T21:36:52.716Z",
      "date_updated": "2026-08-01T03:56:25.095Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Object Library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26094
      },
      "nvd": {
        "published": "2026-07-21T22:18:16.443",
        "lastModified": "2026-08-01T05:17:00.763",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60773",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Application Object Library user can read or modify critical data beyond the assigned role, but Oracle does not publish the affected object or permission check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official table confirms the Core component, HTTPS, low privileges, scope change, score, and versions but no implementation mechanism."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 883,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60774",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.589Z",
      "date_published": "2026-07-21T21:36:53.061Z",
      "date_updated": "2026-07-24T19:04:47.930Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.20993
      },
      "nvd": {
        "published": "2026-07-21T22:18:16.560",
        "lastModified": "2026-07-30T17:37:11.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60774",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Applications Framework operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 733,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60775",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.589Z",
      "date_published": "2026-07-21T21:36:53.403Z",
      "date_updated": "2026-07-24T18:59:15.418Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Pasta product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Pasta"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05639
      },
      "nvd": {
        "published": "2026-07-21T22:18:16.680",
        "lastModified": "2026-07-24T19:17:07.783",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60775",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged local user can take over Pasta, but Oracle does not disclose the additional authority boundary that fails.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 509,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60776",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.589Z",
      "date_published": "2026-07-21T21:36:53.742Z",
      "date_updated": "2026-08-01T03:56:38.435Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Object Library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07874
      },
      "nvd": {
        "published": "2026-07-21T22:18:16.800",
        "lastModified": "2026-08-01T05:17:00.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60776",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Application Object Library permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 620,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60777",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.589Z",
      "date_published": "2026-07-21T21:36:54.112Z",
      "date_updated": "2026-07-24T15:21:33.893Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Object Library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.1652
      },
      "nvd": {
        "published": "2026-07-21T22:18:16.913",
        "lastModified": "2026-07-29T15:33:55.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60777",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60777 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 828,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60778",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.589Z",
      "date_published": "2026-07-21T21:36:54.450Z",
      "date_updated": "2026-07-24T15:21:25.806Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Payments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26312
      },
      "nvd": {
        "published": "2026-07-21T22:18:17.030",
        "lastModified": "2026-07-29T15:32:04.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60778",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Payments permits a low-privilege HTTP caller to read and modify critical data beyond its role, while the failing access check is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 688,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60780",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.590Z",
      "date_published": "2026-07-21T21:36:54.795Z",
      "date_updated": "2026-07-24T15:21:17.242Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Workflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29325
      },
      "nvd": {
        "published": "2026-07-21T22:18:17.150",
        "lastModified": "2026-07-28T14:02:27.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60780",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle Workflow in its Internal Operations component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60783",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.590Z",
      "date_published": "2026-07-21T21:36:55.137Z",
      "date_updated": "2026-07-24T15:21:08.595Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iReceivables"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.3303
      },
      "nvd": {
        "published": "2026-07-21T22:18:17.260",
        "lastModified": "2026-07-29T15:26:07.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60783",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle component permits access outside the caller's authorization scope, but the public record does not disclose the protected operation or causal check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60784",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.590Z",
      "date_published": "2026-07-21T21:36:55.575Z",
      "date_updated": "2026-07-24T15:20:58.408Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Trading Community"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.2631
      },
      "nvd": {
        "published": "2026-07-21T22:18:17.383",
        "lastModified": "2026-07-29T15:21:58.963",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60784",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Trading Community lets a low-privileged HTTP user read and modify critical data outside the intended scope, but the failing check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 722,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60785",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.590Z",
      "date_published": "2026-07-21T21:36:55.930Z",
      "date_updated": "2026-07-24T15:20:50.871Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iReceivables"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29278
      },
      "nvd": {
        "published": "2026-07-21T22:18:17.500",
        "lastModified": "2026-07-29T15:03:10.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60785",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle iReceivables permits an unauthenticated HTTP caller to take over the application, while the public record does not disclose the failing authority decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 525,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60786",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.590Z",
      "date_published": "2026-07-21T21:36:56.276Z",
      "date_updated": "2026-07-24T15:20:41.980Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Receivables"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00486,
        "percentile": 0.39226
      },
      "nvd": {
        "published": "2026-07-21T22:18:17.617",
        "lastModified": "2026-07-28T17:11:18.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60786",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Receivables permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 523,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60787",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.590Z",
      "date_published": "2026-07-21T21:36:56.605Z",
      "date_updated": "2026-07-24T15:20:32.895Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Receivables"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26501
      },
      "nvd": {
        "published": "2026-07-21T22:18:17.733",
        "lastModified": "2026-07-28T17:11:29.787",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60787",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a privileged HTTP path to Receivables takeover but does not publish the failing authorization rule.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 523,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60788",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.590Z",
      "date_published": "2026-07-21T21:36:56.936Z",
      "date_updated": "2026-07-24T15:20:25.925Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Sales Offline"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28746
      },
      "nvd": {
        "published": "2026-07-21T22:18:17.847",
        "lastModified": "2026-07-27T17:33:26.663",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60788",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 824,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60789",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.590Z",
      "date_published": "2026-07-21T21:36:57.282Z",
      "date_updated": "2026-07-24T15:29:38.545Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Sales Offline"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35526
      },
      "nvd": {
        "published": "2026-07-21T22:18:17.960",
        "lastModified": "2026-07-27T17:33:22.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60789",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60790",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.590Z",
      "date_published": "2026-07-21T21:36:57.626Z",
      "date_updated": "2026-07-24T15:26:57.408Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Sales Offline"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27673
      },
      "nvd": {
        "published": "2026-07-21T22:18:18.070",
        "lastModified": "2026-07-27T17:33:18.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60790",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle Sales Offline but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 653,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.591Z",
      "date_published": "2026-07-21T21:36:58.066Z",
      "date_updated": "2026-07-24T15:24:08.730Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle TeleSales product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle TeleSales"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26311
      },
      "nvd": {
        "published": "2026-07-21T22:18:18.187",
        "lastModified": "2026-07-29T18:05:42.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60793",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read and modify TeleSales data beyond its authority, but Oracle does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 694,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60794",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.591Z",
      "date_published": "2026-07-21T21:36:58.390Z",
      "date_updated": "2026-07-24T15:21:11.622Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle TeleSales product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle TeleSales"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12802
      },
      "nvd": {
        "published": "2026-07-21T22:18:18.303",
        "lastModified": "2026-07-29T18:06:04.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60794",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged TeleSales caller can read and modify data beyond its intended role, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 648,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60795",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.591Z",
      "date_published": "2026-07-21T21:36:58.745Z",
      "date_updated": "2026-07-24T15:20:18.845Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iSetup"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18983
      },
      "nvd": {
        "published": "2026-07-21T22:18:18.420",
        "lastModified": "2026-07-29T14:51:25.210",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60795",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle product allows an action beyond the caller's intended authority, but the public record does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 705,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.591Z",
      "date_published": "2026-07-21T21:36:59.087Z",
      "date_updated": "2026-07-24T15:20:10.955Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Compensation Workbench"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20013
      },
      "nvd": {
        "published": "2026-07-21T22:18:18.533",
        "lastModified": "2026-07-24T16:16:42.957",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60799",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege Compensation Workbench user can read critical data and modify some data, but the object and failing permission check are not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 726,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.591Z",
      "date_published": "2026-07-21T21:36:59.518Z",
      "date_updated": "2026-07-24T15:20:01.925Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Compensation Workbench"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19979
      },
      "nvd": {
        "published": "2026-07-21T22:18:18.650",
        "lastModified": "2026-07-24T16:16:43.073",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60800",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Compensation Workbench permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 726,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.591Z",
      "date_published": "2026-07-21T21:36:59.870Z",
      "date_updated": "2026-07-24T15:19:54.776Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle E-Business Intelligence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22706
      },
      "nvd": {
        "published": "2026-07-21T22:18:18.753",
        "lastModified": "2026-08-03T11:47:31.210",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60801",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle E-Business Intelligence lets a high-privileged HTTP user cross the product's intended data scope, but the failing check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 753,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.592Z",
      "date_published": "2026-07-21T21:37:00.209Z",
      "date_updated": "2026-07-24T15:19:46.790Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle E-Business Intelligence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13979
      },
      "nvd": {
        "published": "2026-07-21T22:18:18.870",
        "lastModified": "2026-08-03T11:45:32.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60802",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated cross-product read and write impact in E-Business Intelligence, but the CPU does not identify the protected action or authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 923,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.592Z",
      "date_published": "2026-07-21T21:37:00.551Z",
      "date_updated": "2026-07-24T15:19:39.529Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle E-Business Intelligence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10144
      },
      "nvd": {
        "published": "2026-07-21T22:18:18.983",
        "lastModified": "2026-08-03T11:47:15.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60804",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports an integrity impact in E-Business Intelligence but does not identify the request or failing access check.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 663,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60805",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.592Z",
      "date_published": "2026-07-21T21:37:00.879Z",
      "date_updated": "2026-07-24T15:19:31.435Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Cost Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23784
      },
      "nvd": {
        "published": "2026-07-21T22:18:19.097",
        "lastModified": "2026-07-29T14:47:24.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60805",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged HTTP caller can exceed its authority over Cost Planning data, but the protected object and failing check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 831,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.592Z",
      "date_published": "2026-07-21T21:37:01.215Z",
      "date_updated": "2026-07-24T15:19:25.299Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Costing Transaction Errors).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Cost Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23502
      },
      "nvd": {
        "published": "2026-07-21T22:18:19.213",
        "lastModified": "2026-07-29T14:43:20.087",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60806",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Cost Management path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.592Z",
      "date_published": "2026-07-21T21:37:01.575Z",
      "date_updated": "2026-07-28T14:56:25.744Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Bills of Material"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24869
      },
      "nvd": {
        "published": "2026-07-21T22:18:19.330",
        "lastModified": "2026-07-29T14:43:06.097",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60807",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports a privileged operation available to the wrong caller without identifying the failing access-control decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 624,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60810",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.592Z",
      "date_published": "2026-07-21T21:37:02.016Z",
      "date_updated": "2026-07-30T13:02:38.827Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Supply Chain Trading Connector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15692
      },
      "nvd": {
        "published": "2026-07-21T22:18:19.443",
        "lastModified": "2026-07-30T14:17:03.083",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60810",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive Oracle Supply Chain Trading Connector operation is reachable through a path that does not enforce the required authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 758,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60811",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.592Z",
      "date_published": "2026-07-21T21:37:02.361Z",
      "date_updated": "2026-07-24T15:18:45.518Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Supply Chain Trading Connector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16339
      },
      "nvd": {
        "published": "2026-07-21T22:18:19.560",
        "lastModified": "2026-07-24T16:16:43.797",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60811",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read or alter Oracle Supply Chain Trading Connector state, but the object and permission check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 865,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.592Z",
      "date_published": "2026-07-21T21:37:02.701Z",
      "date_updated": "2026-07-24T15:15:50.528Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Supply Chain Trading Connector"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.19015
      },
      "nvd": {
        "published": "2026-07-21T22:18:19.670",
        "lastModified": "2026-07-24T16:16:43.910",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60812",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Supply Chain Trading Connector exposes protected data to an unintended observer, while the field and output path are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 621,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60813",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.592Z",
      "date_published": "2026-07-21T21:37:03.055Z",
      "date_updated": "2026-07-24T15:14:03.646Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iStore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26498
      },
      "nvd": {
        "published": "2026-07-21T22:18:19.780",
        "lastModified": "2026-07-29T14:10:20.877",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60813",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a high-privileged HTTP user can take over iStore Shopping Cart but does not publish the operation or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 502,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60815",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.593Z",
      "date_published": "2026-07-21T21:37:03.396Z",
      "date_updated": "2026-07-24T15:19:18.115Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iStore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13978
      },
      "nvd": {
        "published": "2026-07-21T22:18:19.890",
        "lastModified": "2026-07-30T17:37:20.183",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60815",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 832,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60816",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.593Z",
      "date_published": "2026-07-21T21:37:03.723Z",
      "date_updated": "2026-07-24T15:19:11.680Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iStore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12843
      },
      "nvd": {
        "published": "2026-07-21T22:18:20.003",
        "lastModified": "2026-07-30T17:37:30.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60816",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60817",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.593Z",
      "date_published": "2026-07-21T21:37:04.058Z",
      "date_updated": "2026-07-24T15:19:04.297Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iStore"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26311
      },
      "nvd": {
        "published": "2026-07-21T22:18:20.113",
        "lastModified": "2026-07-30T17:37:35.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60817",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle iStore but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 676,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60823",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.593Z",
      "date_published": "2026-07-21T21:37:04.434Z",
      "date_updated": "2026-07-24T15:18:55.992Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iSupport"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17701
      },
      "nvd": {
        "published": "2026-07-21T22:18:20.227",
        "lastModified": "2026-07-30T17:37:41.133",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60823",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle iSupport permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 693,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60824",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.593Z",
      "date_published": "2026-07-21T21:37:04.782Z",
      "date_updated": "2026-07-24T15:18:48.316Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iSupport"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17819
      },
      "nvd": {
        "published": "2026-07-21T22:18:20.340",
        "lastModified": "2026-07-30T17:37:49.083",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60824",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege HTTP caller can read all iSupport-accessible data, but Oracle does not publish the missing object or tenant check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 670,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60825",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.593Z",
      "date_published": "2026-07-21T21:37:05.219Z",
      "date_updated": "2026-07-24T15:18:39.526Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iSupport"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27673
      },
      "nvd": {
        "published": "2026-07-21T22:18:20.450",
        "lastModified": "2026-07-30T17:38:01.497",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60825",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports a high-privileged network takeover of iSupport but does not disclose the input or engineering failure.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60826",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.593Z",
      "date_published": "2026-07-21T21:37:05.561Z",
      "date_updated": "2026-07-24T15:18:32.489Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iSupport"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27672
      },
      "nvd": {
        "published": "2026-07-21T22:18:20.567",
        "lastModified": "2026-07-31T17:46:57.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60826",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged iSupport user can obtain authority beyond the assigned role, but Oracle does not identify the operation or authorization error.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60827",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.593Z",
      "date_published": "2026-07-21T21:37:05.931Z",
      "date_updated": "2026-07-24T15:18:24.780Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iSupport"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21457
      },
      "nvd": {
        "published": "2026-07-21T22:18:20.670",
        "lastModified": "2026-07-31T17:42:54.163",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60827",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle iSupport operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 767,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60828",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.593Z",
      "date_published": "2026-07-21T21:37:06.277Z",
      "date_updated": "2026-07-24T15:18:17.518Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Interaction Blending"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37107
      },
      "nvd": {
        "published": "2026-07-21T22:18:20.780",
        "lastModified": "2026-07-31T17:40:10.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60828",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged HTTP user can take over Interaction Blending, but Oracle does not identify the failing authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 550,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60829",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.594Z",
      "date_published": "2026-07-21T21:37:06.614Z",
      "date_updated": "2026-07-29T03:55:39.857Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Outbound Telephony"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33076
      },
      "nvd": {
        "published": "2026-07-21T22:18:20.890",
        "lastModified": "2026-07-31T17:39:02.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60829",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Advanced Outbound Telephony permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60832",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.594Z",
      "date_published": "2026-07-21T21:37:06.963Z",
      "date_updated": "2026-07-24T18:28:14.659Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Interaction Blending"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14183
      },
      "nvd": {
        "published": "2026-07-21T22:18:21.007",
        "lastModified": "2026-07-31T17:28:45.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60832",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60832 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 815,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60833",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.594Z",
      "date_published": "2026-07-21T21:37:07.299Z",
      "date_updated": "2026-07-28T03:56:59.169Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Solaris"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03028
      },
      "nvd": {
        "published": "2026-07-21T22:18:21.120",
        "lastModified": "2026-07-31T17:25:30.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60833",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Solaris permits a low-privilege local caller to gain takeover authority, while the privileged transition and missing check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 517,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60834",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.594Z",
      "date_published": "2026-07-21T21:37:07.646Z",
      "date_updated": "2026-07-29T19:26:41.334Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Solaris"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09698
      },
      "nvd": {
        "published": "2026-07-21T22:18:21.237",
        "lastModified": "2026-07-31T17:18:00.213",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60834",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle Solaris in its Utility component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 751,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60835",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.594Z",
      "date_published": "2026-07-21T21:37:07.988Z",
      "date_updated": "2026-07-24T18:26:10.201Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Price Protection"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00376,
        "percentile": 0.30365
      },
      "nvd": {
        "published": "2026-07-21T22:18:21.367",
        "lastModified": "2026-07-31T17:12:30.940",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60835",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record describes the resulting impact without identifying a failing check, parser, lifetime transition, or state rule.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60836",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.594Z",
      "date_published": "2026-07-21T21:37:08.341Z",
      "date_updated": "2026-07-24T18:25:13.652Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HCM Common Architecture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.2654
      },
      "nvd": {
        "published": "2026-07-21T22:18:21.533",
        "lastModified": "2026-07-31T17:02:42.027",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60836",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle HCM lets a high-privileged HTTP user cross an additional privilege boundary and take over the component, but the operation binding is not public.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60837",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.594Z",
      "date_published": "2026-07-21T21:37:08.677Z",
      "date_updated": "2026-07-24T18:23:37.789Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Price Protection"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05495
      },
      "nvd": {
        "published": "2026-07-21T22:18:21.647",
        "lastModified": "2026-07-31T17:00:11.343",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60837",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Price Protection permits a low-privileged local user to read and modify data beyond the assigned role, while the exact privilege check is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 890,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60838",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.594Z",
      "date_published": "2026-07-21T21:37:09.035Z",
      "date_updated": "2026-07-24T18:21:27.170Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Price Protection"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17658
      },
      "nvd": {
        "published": "2026-07-21T22:18:21.760",
        "lastModified": "2026-07-31T16:43:01.053",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60838",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Price Protection permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 699,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60840",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.594Z",
      "date_published": "2026-07-21T21:37:09.370Z",
      "date_updated": "2026-07-24T17:56:46.562Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Demand Signal Repository"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27679
      },
      "nvd": {
        "published": "2026-07-21T22:18:21.867",
        "lastModified": "2026-07-24T18:18:00.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60840",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized Demand Signal Repository reads and writes through SQL but does not publish the privilege boundary that fails.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 753,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60842",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.595Z",
      "date_published": "2026-07-21T21:37:09.727Z",
      "date_updated": "2026-07-24T17:55:59.004Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Knowledge Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02582
      },
      "nvd": {
        "published": "2026-07-21T22:18:21.977",
        "lastModified": "2026-07-24T18:18:00.723",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60842",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 895,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60843",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.595Z",
      "date_published": "2026-07-21T21:37:10.078Z",
      "date_updated": "2026-07-24T17:57:38.921Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Citizen Interaction Center product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Citizen Interaction Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28782
      },
      "nvd": {
        "published": "2026-07-21T22:18:22.090",
        "lastModified": "2026-07-24T19:17:09.013",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60843",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 763,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60844",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.595Z",
      "date_published": "2026-07-21T21:37:10.412Z",
      "date_updated": "2026-07-24T17:58:28.481Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Customer Support"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25098
      },
      "nvd": {
        "published": "2026-07-21T22:18:22.200",
        "lastModified": "2026-07-24T19:17:09.140",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60844",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle Customer Support but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 725,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60845",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.595Z",
      "date_published": "2026-07-21T21:37:10.748Z",
      "date_updated": "2026-07-24T17:59:09.584Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA General Bugs).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Mobile Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37713
      },
      "nvd": {
        "published": "2026-07-21T22:18:22.307",
        "lastModified": "2026-07-24T19:17:09.267",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60845",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged HTTP caller can take over Mobile Application Server, but Oracle does not disclose the additional privilege boundary or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 562,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60846",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.595Z",
      "date_published": "2026-07-21T21:37:11.085Z",
      "date_updated": "2026-07-24T17:59:52.440Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Mobile Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31317
      },
      "nvd": {
        "published": "2026-07-21T22:18:22.423",
        "lastModified": "2026-07-30T19:08:45.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60846",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged MWA Terminal Server caller can cross the intended data and operation boundary, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 873,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60847",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.595Z",
      "date_published": "2026-07-21T21:37:12.424Z",
      "date_updated": "2026-07-24T18:03:49.778Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Order Entry product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Order Entry"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03342
      },
      "nvd": {
        "published": "2026-07-21T22:18:22.537",
        "lastModified": "2026-07-24T19:17:09.513",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60847",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle product allows an action beyond the caller's intended authority, but the public record does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 703,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60848",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.595Z",
      "date_published": "2026-07-21T21:37:12.734Z",
      "date_updated": "2026-07-24T17:55:05.103Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Contracts"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28933
      },
      "nvd": {
        "published": "2026-07-21T22:18:22.647",
        "lastModified": "2026-07-31T12:50:58.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60848",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege Project Contracts user can read and modify critical data, but the object and failing permission check are not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 726,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60852",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.596Z",
      "date_published": "2026-07-21T21:37:13.064Z",
      "date_updated": "2026-07-24T18:05:53.142Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Lease and Finance Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20299
      },
      "nvd": {
        "published": "2026-07-21T22:18:22.770",
        "lastModified": "2026-07-30T18:46:02.557",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60852",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Lease and Finance Management permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 770,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60854",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.596Z",
      "date_published": "2026-07-21T21:37:13.379Z",
      "date_updated": "2026-07-24T18:10:26.795Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Quality"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.2881
      },
      "nvd": {
        "published": "2026-07-21T22:18:22.877",
        "lastModified": "2026-07-30T18:40:14.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60854",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Quality lets a high-privileged HTTP user affect resources outside the intended product scope, but the privilege mapping is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 888,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60855",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.596Z",
      "date_published": "2026-07-21T21:37:13.703Z",
      "date_updated": "2026-07-24T18:19:21.442Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Quality"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00334,
        "percentile": 0.25957
      },
      "nvd": {
        "published": "2026-07-21T22:18:22.993",
        "lastModified": "2026-07-30T18:36:25.420",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60855",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports low-privileged takeover of Oracle Quality, but the CPU does not reconcile the missing-authentication label with required credentials or identify the failing gate.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60857",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.596Z",
      "date_published": "2026-07-21T21:37:14.023Z",
      "date_updated": "2026-07-24T18:18:14.083Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Contracts Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.203
      },
      "nvd": {
        "published": "2026-07-21T22:18:23.107",
        "lastModified": "2026-07-27T17:44:28.507",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60857",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports unauthorized Contracts Integration data access but does not identify the operation or authorization predicate.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 742,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60859",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.597Z",
      "date_published": "2026-07-21T21:37:14.378Z",
      "date_updated": "2026-07-24T18:14:01.434Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Quoting"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00334,
        "percentile": 0.25993
      },
      "nvd": {
        "published": "2026-07-21T22:18:23.220",
        "lastModified": "2026-07-30T18:25:11.127",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60859",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An undisclosed Oracle Quoting critical function lacks the authentication required to restrict it beyond a low-privileged HTTP caller.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60862",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.597Z",
      "date_published": "2026-07-21T21:37:14.683Z",
      "date_updated": "2026-07-24T17:41:29.756Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Order Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00379,
        "percentile": 0.30689
      },
      "nvd": {
        "published": "2026-07-21T22:18:23.330",
        "lastModified": "2026-07-30T18:22:47.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60862",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Order Management path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 708,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60863",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.597Z",
      "date_published": "2026-07-21T21:37:14.999Z",
      "date_updated": "2026-07-29T03:55:42.189Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Pricing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35527
      },
      "nvd": {
        "published": "2026-07-21T22:18:23.440",
        "lastModified": "2026-07-29T05:16:55.233",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60863",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged caller can reach a protected Oracle operation, while the public record does not resolve its conflicting missing-authentication label.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "The structured CWE-306 missing-authentication label conflicts with the embedded low-privilege attack prerequisite, and Oracle does not publish the access-control path."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60864",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.597Z",
      "date_published": "2026-07-21T21:37:15.321Z",
      "date_updated": "2026-07-24T17:52:09.638Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Order Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12846
      },
      "nvd": {
        "published": "2026-07-21T22:18:23.560",
        "lastModified": "2026-07-30T18:19:00.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60864",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Order Management operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 806,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60867",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.597Z",
      "date_published": "2026-07-21T21:37:15.638Z",
      "date_updated": "2026-07-29T03:55:44.551Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Pricing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26353
      },
      "nvd": {
        "published": "2026-07-21T22:18:23.677",
        "lastModified": "2026-07-29T05:16:55.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60867",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read or alter Oracle Advanced Pricing data, but the object and permission check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 723,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60868",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.597Z",
      "date_published": "2026-07-21T21:37:15.974Z",
      "date_updated": "2026-07-29T19:13:48.379Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Pricing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13863
      },
      "nvd": {
        "published": "2026-07-21T22:18:23.800",
        "lastModified": "2026-07-29T20:17:08.293",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60868",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Advanced Pricing permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 828,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60870",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.597Z",
      "date_published": "2026-07-21T21:37:16.300Z",
      "date_updated": "2026-07-29T03:55:47.802Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Pricing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.20993
      },
      "nvd": {
        "published": "2026-07-21T22:18:23.910",
        "lastModified": "2026-07-29T05:16:56.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60870",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthorized Advanced Pricing reads and writes by a low-privileged HTTP user but does not publish the object or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 700,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60871",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.597Z",
      "date_published": "2026-07-21T21:37:16.629Z",
      "date_updated": "2026-07-24T17:42:14.933Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Risk Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27638
      },
      "nvd": {
        "published": "2026-07-21T22:18:24.020",
        "lastModified": "2026-07-24T18:18:01.867",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60871",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 718,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60872",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.597Z",
      "date_published": "2026-07-21T21:37:17.320Z",
      "date_updated": "2026-07-24T17:35:19.301Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Order Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35574
      },
      "nvd": {
        "published": "2026-07-21T22:18:24.130",
        "lastModified": "2026-07-30T18:17:02.717",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60872",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Order Management permits a low-privileged HTTP caller to take over Product Diagnostic Tools, while the grouped authentication and privilege labels do not identify the failing check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60875",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.598Z",
      "date_published": "2026-07-21T21:37:17.634Z",
      "date_updated": "2026-07-24T17:40:06.909Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Trade Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25134
      },
      "nvd": {
        "published": "2026-07-21T22:18:24.243",
        "lastModified": "2026-07-24T18:18:02.130",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60875",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle Trade Management but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 712,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.598Z",
      "date_published": "2026-07-21T21:37:18.026Z",
      "date_updated": "2026-07-24T17:39:09.037Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Trade Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25102
      },
      "nvd": {
        "published": "2026-07-21T22:18:24.353",
        "lastModified": "2026-07-24T18:18:02.260",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60877",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Trade Management permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 712,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60880",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.598Z",
      "date_published": "2026-07-21T21:37:18.351Z",
      "date_updated": "2026-07-24T17:38:19.341Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Work in Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00395,
        "percentile": 0.323
      },
      "nvd": {
        "published": "2026-07-21T22:18:24.480",
        "lastModified": "2026-07-28T20:18:01.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60880",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A critical Work in Process function is reachable over HTTP without authentication.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60886",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.598Z",
      "date_published": "2026-07-21T21:37:18.673Z",
      "date_updated": "2026-07-24T17:37:30.028Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Work in Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.0371
      },
      "nvd": {
        "published": "2026-07-21T22:18:24.593",
        "lastModified": "2026-07-28T19:46:34.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60886",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Work in Process accepts a cross-site state-changing request in a logged-in user's browser context, but the action and anti-CSRF failure are not public.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-269",
          "CWE-285",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 905,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60888",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.599Z",
      "date_published": "2026-07-21T21:37:18.988Z",
      "date_updated": "2026-07-24T17:36:09.147Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Work in Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23804
      },
      "nvd": {
        "published": "2026-07-21T22:18:24.700",
        "lastModified": "2026-07-28T19:46:01.073",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60888",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Work in Process exposes critical data to a low-privileged HTTP user, but the public record does not identify the response, cache, log, or oracle that leaks it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60890",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.599Z",
      "date_published": "2026-07-21T21:37:19.316Z",
      "date_updated": "2026-07-24T17:28:10.457Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.3439
      },
      "nvd": {
        "published": "2026-07-21T22:18:24.810",
        "lastModified": "2026-07-24T18:18:02.870",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60890",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Payroll omits the stronger authentication or authorization needed before a low-privileged user can take over the service.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 510,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60891",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.599Z",
      "date_published": "2026-07-21T21:37:19.644Z",
      "date_updated": "2026-07-24T17:33:33.749Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Work in Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 1.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.00984
      },
      "nvd": {
        "published": "2026-07-21T22:18:24.920",
        "lastModified": "2026-07-24T18:18:03.000",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60891",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports local data exposure in Work in Process, but the CPU table does not identify the protected output or data-selection error.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 596,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60892",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.599Z",
      "date_published": "2026-07-21T21:37:19.946Z",
      "date_updated": "2026-07-24T17:32:18.272Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (Norway)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30293
      },
      "nvd": {
        "published": "2026-07-21T22:18:25.030",
        "lastModified": "2026-07-27T17:48:31.953",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60892",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60892 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 526,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60893",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.599Z",
      "date_published": "2026-07-21T21:37:20.291Z",
      "date_updated": "2026-07-24T17:31:14.677Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03245
      },
      "nvd": {
        "published": "2026-07-21T22:18:25.137",
        "lastModified": "2026-07-24T18:18:03.287",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60893",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Payroll permits a low-privilege local caller to read critical data outside its assigned authority, while the object and check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 700,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60894",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.599Z",
      "date_published": "2026-07-21T21:37:20.696Z",
      "date_updated": "2026-07-24T17:30:01.200Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24764
      },
      "nvd": {
        "published": "2026-07-21T22:18:25.247",
        "lastModified": "2026-07-24T18:18:03.423",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60894",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle Payroll in its Internal Operations component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-269",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60896",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.600Z",
      "date_published": "2026-07-21T21:37:21.033Z",
      "date_updated": "2026-07-24T17:21:18.533Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Work in Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01643
      },
      "nvd": {
        "published": "2026-07-21T22:18:25.350",
        "lastModified": "2026-07-24T18:18:03.570",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60896",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Work in Process mishandles shutdown or release of a finite resource, but the public record does not identify that resource or transition.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60897",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.600Z",
      "date_published": "2026-07-21T21:37:21.362Z",
      "date_updated": "2026-07-24T17:26:54.081Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34389
      },
      "nvd": {
        "published": "2026-07-21T22:18:25.463",
        "lastModified": "2026-07-24T18:18:03.970",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60897",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Payroll lets a low-privileged HTTP user take over the component, but the public record does not identify the missing authentication or authorization check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 510,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60898",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.600Z",
      "date_published": "2026-07-21T21:37:21.687Z",
      "date_updated": "2026-07-24T17:25:51.011Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Warehouse Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23001
      },
      "nvd": {
        "published": "2026-07-21T22:18:25.570",
        "lastModified": "2026-07-24T18:18:04.100",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60898",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Warehouse Management permits a low-privileged HTTP caller to take over the application, while the missing authentication or authorization check is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60899",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.600Z",
      "date_published": "2026-07-21T21:37:21.999Z",
      "date_updated": "2026-07-24T17:24:37.407Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HCM Configuration Workbench"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.19014
      },
      "nvd": {
        "published": "2026-07-21T22:18:25.683",
        "lastModified": "2026-07-24T18:18:04.233",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60899",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle HCM Configuration Workbench returns protected data to an unintended caller; the exposed field and output path are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 611,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.600Z",
      "date_published": "2026-07-21T21:37:22.314Z",
      "date_updated": "2026-07-24T17:28:59.537Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HCM Configuration Workbench"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37757
      },
      "nvd": {
        "published": "2026-07-21T22:18:25.797",
        "lastModified": "2026-07-24T18:18:04.360",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60900",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a privileged HTTP path to HCM Configuration Workbench takeover but does not publish the privilege-assignment failure.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60901",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.600Z",
      "date_published": "2026-07-21T21:37:22.649Z",
      "date_updated": "2026-07-24T17:23:33.788Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Intelligence"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.3439
      },
      "nvd": {
        "published": "2026-07-21T22:18:25.910",
        "lastModified": "2026-07-24T18:18:04.493",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60901",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60904",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.601Z",
      "date_published": "2026-07-21T21:37:22.986Z",
      "date_updated": "2026-07-24T17:22:07.860Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Installed Base"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.251
      },
      "nvd": {
        "published": "2026-07-21T22:18:26.020",
        "lastModified": "2026-07-24T18:18:04.620",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60904",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 715,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60907",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.601Z",
      "date_published": "2026-07-21T21:37:23.326Z",
      "date_updated": "2026-07-24T17:14:56.452Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Installed Base"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09652
      },
      "nvd": {
        "published": "2026-07-21T22:18:26.130",
        "lastModified": "2026-07-24T18:18:04.787",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60907",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle Installed Base but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 786,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60908",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.601Z",
      "date_published": "2026-07-21T21:37:23.629Z",
      "date_updated": "2026-07-24T17:20:04.995Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Installed Base"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20014
      },
      "nvd": {
        "published": "2026-07-21T22:18:26.233",
        "lastModified": "2026-07-24T18:18:04.950",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60908",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read and modify Installed Base data beyond its authority, but Oracle does not disclose the Create Item Instance check.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 692,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60910",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.601Z",
      "date_published": "2026-07-21T21:37:23.943Z",
      "date_updated": "2026-07-24T17:18:31.761Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Property Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26576
      },
      "nvd": {
        "published": "2026-07-21T22:18:26.347",
        "lastModified": "2026-07-24T18:18:05.110",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60910",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged Property Manager caller can reach takeover-capable authority beyond its intended role, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60911",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.601Z",
      "date_published": "2026-07-21T21:37:24.355Z",
      "date_updated": "2026-07-24T17:17:42.955Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Property Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01636
      },
      "nvd": {
        "published": "2026-07-21T22:18:26.457",
        "lastModified": "2026-07-24T18:18:05.270",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60911",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle request can cross a CSRF or redirect trust boundary, but the public record does not identify the action, redirect, or origin rule.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 887,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60912",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.601Z",
      "date_published": "2026-07-21T21:37:24.674Z",
      "date_updated": "2026-07-24T17:16:42.683Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Property Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13936
      },
      "nvd": {
        "published": "2026-07-21T22:18:26.560",
        "lastModified": "2026-07-24T18:18:05.427",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60912",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege Property Manager user can read and modify data outside intended authority, but the failed permission check is not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 676,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60913",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.601Z",
      "date_published": "2026-07-21T21:37:24.984Z",
      "date_updated": "2026-07-24T17:15:46.155Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Property Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 1.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02277
      },
      "nvd": {
        "published": "2026-07-21T22:18:26.707",
        "lastModified": "2026-07-24T18:18:05.587",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60913",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle identifies local read access to a subset of Property Manager data but does not disclose the object, output path, or missing authority check.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 600,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60917",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.601Z",
      "date_published": "2026-07-21T21:37:25.323Z",
      "date_updated": "2026-07-24T17:09:02.247Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Core Receiving).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Inventory Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25102
      },
      "nvd": {
        "published": "2026-07-21T22:18:26.817",
        "lastModified": "2026-07-24T18:18:05.750",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60917",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Inventory Management lets a low-privileged HTTP user read and modify critical data beyond the role's scope, but the failing check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 733,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60918",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.601Z",
      "date_published": "2026-07-21T21:37:25.642Z",
      "date_updated": "2026-07-24T17:07:14.987Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Shipping Execution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37713
      },
      "nvd": {
        "published": "2026-07-21T22:18:26.923",
        "lastModified": "2026-07-24T18:18:05.870",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60918",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports high-privileged takeover of Shipping Execution, but the CPU does not reconcile the missing-authentication label with required credentials or identify the failing gate.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 545,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60919",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.602Z",
      "date_published": "2026-07-21T21:37:25.972Z",
      "date_updated": "2026-07-24T17:13:52.481Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iSupplier Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.1738
      },
      "nvd": {
        "published": "2026-07-21T22:18:27.030",
        "lastModified": "2026-07-24T18:18:05.997",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60919",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports limited iSupplier data disclosure but does not identify the endpoint or output rule that fails.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60920",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.602Z",
      "date_published": "2026-07-21T21:37:26.290Z",
      "date_updated": "2026-07-24T17:13:04.808Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Customer Care"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34351
      },
      "nvd": {
        "published": "2026-07-21T22:18:27.140",
        "lastModified": "2026-07-24T18:18:06.123",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60920",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An undisclosed Customer Care critical function lacks the authentication required to restrict it beyond a low-privileged HTTP caller.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60922",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.602Z",
      "date_published": "2026-07-21T21:37:26.600Z",
      "date_updated": "2026-07-24T17:12:14.775Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iSupplier Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13939
      },
      "nvd": {
        "published": "2026-07-21T22:18:27.250",
        "lastModified": "2026-07-24T18:18:06.253",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60922",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle iSupplier Portal output path exposes protected data or state to an unintended observer.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60923",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.602Z",
      "date_published": "2026-07-21T21:37:26.925Z",
      "date_updated": "2026-07-24T17:11:02.544Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Capacity product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Capacity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29837
      },
      "nvd": {
        "published": "2026-07-21T22:18:27.360",
        "lastModified": "2026-07-24T18:18:06.380",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60923",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthorized disclosure but does not publish the returned field, output path, or causal check.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 670,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60924",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.602Z",
      "date_published": "2026-07-21T21:37:27.253Z",
      "date_updated": "2026-07-24T17:10:15.350Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.3439
      },
      "nvd": {
        "published": "2026-07-21T22:18:27.470",
        "lastModified": "2026-07-24T18:18:06.507",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60924",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A security-sensitive Oracle Public Sector Payroll operation is reachable through a path that does not enforce the required authentication.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60925",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.602Z",
      "date_published": "2026-07-21T21:37:27.558Z",
      "date_updated": "2026-07-24T16:59:35.806Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37714
      },
      "nvd": {
        "published": "2026-07-21T22:18:27.577",
        "lastModified": "2026-07-24T18:18:06.630",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60925",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged HTTP caller can take over Oracle Public Sector Payroll, but the additional authority gained and failing check are not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 553,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60926",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.602Z",
      "date_published": "2026-07-21T21:37:27.892Z",
      "date_updated": "2026-07-24T17:05:07.555Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37714
      },
      "nvd": {
        "published": "2026-07-21T22:18:27.687",
        "lastModified": "2026-07-24T18:18:06.763",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60926",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Public Sector Payroll permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 553,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60927",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.602Z",
      "date_published": "2026-07-21T21:37:28.234Z",
      "date_updated": "2026-07-24T17:04:17.021Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00334,
        "percentile": 0.25992
      },
      "nvd": {
        "published": "2026-07-21T22:18:27.783",
        "lastModified": "2026-07-29T15:54:30.033",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60927",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged HTTP user can take over Public Sector Financials Internal Operations but does not publish the operation or permission check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 563,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60929",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.602Z",
      "date_published": "2026-07-21T21:37:28.575Z",
      "date_updated": "2026-07-24T17:02:59.056Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11397
      },
      "nvd": {
        "published": "2026-07-21T22:18:27.893",
        "lastModified": "2026-07-29T15:55:27.957",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60929",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60930",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.602Z",
      "date_published": "2026-07-21T21:37:28.908Z",
      "date_updated": "2026-07-24T16:52:27.200Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14793
      },
      "nvd": {
        "published": "2026-07-21T22:18:28.000",
        "lastModified": "2026-07-29T15:59:24.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60930",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected interface returns, embeds or leaves protected information visible to an observer who is not entitled to receive it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 580,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60931",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.602Z",
      "date_published": "2026-07-21T21:37:29.226Z",
      "date_updated": "2026-07-24T17:02:04.525Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00334,
        "percentile": 0.25993
      },
      "nvd": {
        "published": "2026-07-21T22:18:28.113",
        "lastModified": "2026-07-29T15:59:41.297",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60931",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle Public Sector Financials but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 563,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60932",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.602Z",
      "date_published": "2026-07-21T21:37:29.544Z",
      "date_updated": "2026-07-24T17:00:56.946Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Labor Distribution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35527
      },
      "nvd": {
        "published": "2026-07-21T22:18:28.227",
        "lastModified": "2026-07-29T17:17:59.467",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60932",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can reach a critical Oracle Labor Distribution operation without the authentication check required for that operation, although Oracle does not disclose the operation.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60936",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.603Z",
      "date_published": "2026-07-21T21:37:30.024Z",
      "date_updated": "2026-07-24T16:55:09.178Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Labor Distribution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20453
      },
      "nvd": {
        "published": "2026-07-21T22:18:28.330",
        "lastModified": "2026-07-29T17:16:13.110",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60936",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege request can partially deny Labor Distribution service, but Oracle does not publish the exhausted resource or work loop.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60937",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.603Z",
      "date_published": "2026-07-21T21:37:30.435Z",
      "date_updated": "2026-07-24T16:54:25.025Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Labor Distribution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11397
      },
      "nvd": {
        "published": "2026-07-21T22:18:28.440",
        "lastModified": "2026-07-29T17:09:59.503",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60937",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports that a low-privileged Labor Distribution user can modify data but does not disclose the operation or engineering failure.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60938",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.603Z",
      "date_published": "2026-07-21T21:37:30.754Z",
      "date_updated": "2026-07-24T16:53:40.723Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Labor Distribution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.025
      },
      "nvd": {
        "published": "2026-07-21T22:18:28.553",
        "lastModified": "2026-07-29T17:04:26.743",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60938",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged local Labor Distribution user can modify data outside the role's intended authority, but the privilege boundary is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60939",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.603Z",
      "date_published": "2026-07-21T21:37:31.074Z",
      "date_updated": "2026-07-24T16:44:40.419Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Contracts"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14765
      },
      "nvd": {
        "published": "2026-07-21T22:18:28.660",
        "lastModified": "2026-07-31T13:04:40.330",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60939",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Oracle record reports unauthorized data exposure but provides only the consequence and no failing authorization or output-control mechanism.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60940",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.603Z",
      "date_published": "2026-07-21T21:37:31.457Z",
      "date_updated": "2026-07-24T16:51:16.854Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Service Contracts"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17081
      },
      "nvd": {
        "published": "2026-07-21T22:18:28.783",
        "lastModified": "2026-07-24T18:18:08.040",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60940",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged Service Contracts user can exceed assigned data access after victim interaction, but Oracle does not disclose the failing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 813,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60941",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.603Z",
      "date_published": "2026-07-21T21:37:31.773Z",
      "date_updated": "2026-07-24T16:49:13.890Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Service Fulfillment Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28821
      },
      "nvd": {
        "published": "2026-07-21T22:18:28.900",
        "lastModified": "2026-07-24T17:17:32.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60941",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a high-privileged HTTP caller can exceed assigned authority in E-Business Suite Installation, but the CPU table does not identify the protected operation or failing check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 902,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60942",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.603Z",
      "date_published": "2026-07-21T21:37:32.094Z",
      "date_updated": "2026-07-24T16:47:18.072Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Service Fulfillment Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26353
      },
      "nvd": {
        "published": "2026-07-21T22:18:29.027",
        "lastModified": "2026-07-29T17:03:32.673",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60942",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-60942 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 765,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60943",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.603Z",
      "date_published": "2026-07-21T21:37:32.408Z",
      "date_updated": "2026-07-24T16:46:28.884Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Service Fulfillment Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00334,
        "percentile": 0.25992
      },
      "nvd": {
        "published": "2026-07-21T22:18:29.150",
        "lastModified": "2026-07-29T16:53:23.767",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60943",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Service Fulfillment Manager permits a low-privilege HTTP caller to gain takeover authority, while Oracle does not disclose the protected operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60945",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.603Z",
      "date_published": "2026-07-21T21:37:32.727Z",
      "date_updated": "2026-07-24T16:45:38.053Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Learning Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22166
      },
      "nvd": {
        "published": "2026-07-21T22:18:29.263",
        "lastModified": "2026-07-29T16:51:18.847",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60945",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle's record associates Oracle Learning Management in its Internal Operations component with a request-channel trust failure, but does not disclose the vulnerable endpoint or validation rule.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 818,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60948",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.603Z",
      "date_published": "2026-07-21T21:37:33.053Z",
      "date_updated": "2026-07-24T16:38:05.119Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Learning Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28902
      },
      "nvd": {
        "published": "2026-07-21T22:18:29.380",
        "lastModified": "2026-07-29T16:46:29.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60948",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle component grants access beyond the caller's assigned privileges, but the public record does not identify the protected operation or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 734,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60950",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.603Z",
      "date_published": "2026-07-21T21:37:33.364Z",
      "date_updated": "2026-07-24T16:43:33.042Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (Ireland)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16688
      },
      "nvd": {
        "published": "2026-07-21T22:18:29.483",
        "lastModified": "2026-07-27T17:48:26.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60950",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle HRMS returns a subset of protected data to a high-privileged caller through an undisclosed output path.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 551,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60951",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.603Z",
      "date_published": "2026-07-21T21:37:33.670Z",
      "date_updated": "2026-07-24T16:42:41.953Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Time and Labor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28933
      },
      "nvd": {
        "published": "2026-07-21T22:18:29.600",
        "lastModified": "2026-07-29T16:03:15.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60951",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Time and Labor permits a low-privileged HTTP caller to read and modify data beyond the assigned role, while the object or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60952",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.604Z",
      "date_published": "2026-07-21T21:37:33.995Z",
      "date_updated": "2026-07-24T16:41:47.939Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Transportation Execution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35528
      },
      "nvd": {
        "published": "2026-07-21T22:18:29.770",
        "lastModified": "2026-07-29T15:55:34.953",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60952",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Transportation Execution permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60953",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.604Z",
      "date_published": "2026-07-21T21:37:34.321Z",
      "date_updated": "2026-07-24T16:40:34.270Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Telecommunications Billing Integrator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00362,
        "percentile": 0.28901
      },
      "nvd": {
        "published": "2026-07-21T22:18:29.880",
        "lastModified": "2026-07-29T15:48:00.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60953",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized Billing Integrator reads and writes but does not publish the missing endpoint authorization check.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 806,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60957",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.604Z",
      "date_published": "2026-07-21T21:37:34.663Z",
      "date_updated": "2026-07-24T16:39:48.550Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Transportation Execution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01646
      },
      "nvd": {
        "published": "2026-07-21T22:18:29.997",
        "lastModified": "2026-07-24T17:17:33.833",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60957",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-285",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 927,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60959",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.604Z",
      "date_published": "2026-07-21T21:37:35.022Z",
      "date_updated": "2026-07-24T15:25:07.448Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle SDP Number Portability"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25098
      },
      "nvd": {
        "published": "2026-07-21T22:18:30.117",
        "lastModified": "2026-07-24T16:16:45.463",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60959",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 746,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60960",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.604Z",
      "date_published": "2026-07-21T21:37:35.423Z",
      "date_updated": "2026-07-24T15:28:00.554Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle SDP Number Portability"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03375
      },
      "nvd": {
        "published": "2026-07-21T22:18:30.223",
        "lastModified": "2026-07-24T16:16:45.580",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60960",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle SDP Number Portability but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 735,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60962",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.604Z",
      "date_published": "2026-07-21T21:37:35.734Z",
      "date_updated": "2026-07-24T15:27:24.477Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Flow Manufacturing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01637
      },
      "nvd": {
        "published": "2026-07-21T22:18:30.337",
        "lastModified": "2026-07-24T16:16:45.707",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60962",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle maps the Flow Manufacturing issue to CSRF but does not disclose the state-changing request or missing origin proof.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 897,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60963",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.604Z",
      "date_published": "2026-07-21T21:37:36.050Z",
      "date_updated": "2026-07-24T15:26:40.911Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Treasury product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Treasury"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25136
      },
      "nvd": {
        "published": "2026-07-21T22:18:30.453",
        "lastModified": "2026-07-24T16:16:45.823",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60963",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Oracle Treasury caller can read and modify critical data beyond its intended role, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 690,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60965",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.604Z",
      "date_published": "2026-07-21T21:37:36.370Z",
      "date_updated": "2026-07-24T15:25:57.225Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (France)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26308
      },
      "nvd": {
        "published": "2026-07-21T22:18:30.567",
        "lastModified": "2026-07-24T18:34:18.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60965",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle product allows an action beyond the caller's intended authority, but the public record does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 700,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60966",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.604Z",
      "date_published": "2026-07-21T21:37:36.687Z",
      "date_updated": "2026-07-24T15:19:49.114Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Human Resources"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25102
      },
      "nvd": {
        "published": "2026-07-21T22:18:30.673",
        "lastModified": "2026-07-24T16:16:46.090",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60966",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege Public Sector Human Resources user can read and modify critical data, but the object and failing permission check are not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 773,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60972",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.605Z",
      "date_published": "2026-07-21T21:37:37.012Z",
      "date_updated": "2026-07-24T15:24:02.570Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle E-Business Tax"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26312
      },
      "nvd": {
        "published": "2026-07-21T22:18:30.777",
        "lastModified": "2026-07-31T19:53:04.467",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60972",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle E-Business Tax permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60973",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.605Z",
      "date_published": "2026-07-21T21:37:37.320Z",
      "date_updated": "2026-07-24T15:23:13.972Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle E-Business Tax"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04698
      },
      "nvd": {
        "published": "2026-07-21T22:18:30.890",
        "lastModified": "2026-07-31T19:50:11.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60973",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle E-Business Tax permits a low-privileged local user to take over the component, but the privilege transition is not public.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60974",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.605Z",
      "date_published": "2026-07-21T21:37:37.640Z",
      "date_updated": "2026-07-24T15:22:27.397Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle E-Business Tax"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26312
      },
      "nvd": {
        "published": "2026-07-21T22:18:31.000",
        "lastModified": "2026-07-31T19:36:07.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60974",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports low-privileged read and write access to critical E-Business Tax data, but the CPU does not identify the protected object or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60978",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.605Z",
      "date_published": "2026-07-21T21:37:37.958Z",
      "date_updated": "2026-07-24T15:21:27.960Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Scripting"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0038,
        "percentile": 0.30723
      },
      "nvd": {
        "published": "2026-07-21T22:18:31.110",
        "lastModified": "2026-07-31T19:33:53.233",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60978",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports high-privilege Scripting data access but does not identify the protected operation or failing check.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 695,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60979",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.605Z",
      "date_published": "2026-07-21T21:37:38.272Z",
      "date_updated": "2026-07-24T15:20:36.942Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Scripting"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21313
      },
      "nvd": {
        "published": "2026-07-21T22:18:31.217",
        "lastModified": "2026-07-31T19:29:18.033",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60979",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An undisclosed Oracle Scripting critical function is reachable over HTTP without authentication, allowing takeover under the published conditions.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 519,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.606Z",
      "date_published": "2026-07-21T21:37:38.591Z",
      "date_updated": "2026-07-24T15:12:59.172Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle US Federal Human Resources"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27638
      },
      "nvd": {
        "published": "2026-07-21T22:18:31.330",
        "lastModified": "2026-07-24T16:16:46.843",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60982",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle US Federal Human Resources path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 762,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60984",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.606Z",
      "date_published": "2026-07-21T21:37:38.915Z",
      "date_updated": "2026-07-24T15:17:45.072Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Portfolio Analysis"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17699
      },
      "nvd": {
        "published": "2026-07-21T22:18:31.440",
        "lastModified": "2026-07-31T19:23:54.273",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60984",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected Oracle action is available with insufficient authority, but the failing caller-to-action binding is not disclosed.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 739,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60985",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.606Z",
      "date_published": "2026-07-21T21:37:39.231Z",
      "date_updated": "2026-07-24T15:16:49.125Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Portfolio Analysis"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15924
      },
      "nvd": {
        "published": "2026-07-21T22:18:31.547",
        "lastModified": "2026-07-31T19:20:48.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60985",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Project Portfolio Analysis operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 747,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60986",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.606Z",
      "date_published": "2026-07-21T21:37:39.541Z",
      "date_updated": "2026-07-24T15:15:40.578Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Portfolio Analysis"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26313
      },
      "nvd": {
        "published": "2026-07-21T22:18:31.660",
        "lastModified": "2026-07-31T19:19:17.723",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60986",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read or alter Oracle Project Portfolio Analysis data, but the object and permission check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 762,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60987",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.606Z",
      "date_published": "2026-07-21T21:37:39.872Z",
      "date_updated": "2026-07-24T15:14:42.847Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Portfolio Analysis"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10283
      },
      "nvd": {
        "published": "2026-07-21T22:18:31.797",
        "lastModified": "2026-07-31T19:10:29.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60987",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Project Portfolio Analysis permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 739,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60988",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.606Z",
      "date_published": "2026-07-21T21:37:40.190Z",
      "date_updated": "2026-07-24T15:13:56.558Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Portfolio Analysis"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24715
      },
      "nvd": {
        "published": "2026-07-21T22:18:31.910",
        "lastModified": "2026-07-24T16:16:47.427",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60988",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged HTTP user can take over Project Portfolio Analysis Internal Operations but does not publish the operation or permission check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60989",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.606Z",
      "date_published": "2026-07-21T21:37:40.508Z",
      "date_updated": "2026-07-29T03:55:39.109Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Collections product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Collections"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.3439
      },
      "nvd": {
        "published": "2026-07-21T22:18:32.017",
        "lastModified": "2026-07-29T05:16:56.913",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60989",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60997",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.606Z",
      "date_published": "2026-07-21T21:37:40.818Z",
      "date_updated": "2026-07-24T15:08:27.134Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Non-Media Integration issues).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Universal Work Queue"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26353
      },
      "nvd": {
        "published": "2026-07-21T22:18:32.130",
        "lastModified": "2026-07-30T17:38:14.230",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-60997",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 747,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-60999",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.607Z",
      "date_published": "2026-07-21T21:37:41.137Z",
      "date_updated": "2026-07-24T15:09:19.578Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Data Integrator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25614
      },
      "nvd": {
        "published": "2026-07-21T22:18:32.240",
        "lastModified": "2026-07-24T16:16:47.780",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-60999",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Data Integrator's REST service exposes a takeover path to an unauthenticated HTTPS caller, but Oracle does not disclose the route or omitted authentication decision.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306",
          "https://www.oracle.com/security-alerts/cpujul2026.html",
          "https://www.oracle.com/security-alerts/cpujul2026verbose.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July CPU confirms the Data Integrator REST Service, version 14.1.2.0.0, unauthenticated HTTPS reachability, and takeover impact but no route or missing check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 528,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61000",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.607Z",
      "date_published": "2026-07-21T21:37:41.460Z",
      "date_updated": "2026-07-24T15:10:14.827Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Systems"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25137
      },
      "nvd": {
        "published": "2026-07-21T22:18:32.350",
        "lastModified": "2026-07-24T16:16:47.957",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61000",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Process Manufacturing Systems permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 774,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61004",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.607Z",
      "date_published": "2026-07-21T21:37:41.788Z",
      "date_updated": "2026-07-24T15:11:12.861Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Landed Cost Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25137
      },
      "nvd": {
        "published": "2026-07-21T22:18:32.460",
        "lastModified": "2026-07-24T16:16:48.070",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61004",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege HTTP caller can read and modify critical Landed Cost data, but Oracle does not publish the missing object or role check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 746,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61005",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.607Z",
      "date_published": "2026-07-21T21:37:42.109Z",
      "date_updated": "2026-07-24T15:12:05.493Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Logistics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25136
      },
      "nvd": {
        "published": "2026-07-21T22:18:32.570",
        "lastModified": "2026-07-24T16:16:48.183",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61005",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports that a low-privileged Process Manufacturing user can read and alter critical logistics data but discloses no enabling cause.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 782,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61006",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.607Z",
      "date_published": "2026-07-21T21:37:42.432Z",
      "date_updated": "2026-07-24T14:57:29.712Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Logistics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37714
      },
      "nvd": {
        "published": "2026-07-21T22:18:32.680",
        "lastModified": "2026-07-24T15:18:55.183",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61006",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged Process Manufacturing Logistics user can take over the product, but the excessive privilege or missing check is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61009",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.607Z",
      "date_published": "2026-07-21T21:37:42.757Z",
      "date_updated": "2026-07-24T15:06:25.311Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Logistics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00357,
        "percentile": 0.28423
      },
      "nvd": {
        "published": "2026-07-21T22:18:32.803",
        "lastModified": "2026-07-24T16:16:48.303",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61009",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Process Manufacturing Logistics operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 725,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61010",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.607Z",
      "date_published": "2026-07-21T21:37:43.074Z",
      "date_updated": "2026-07-24T15:05:35.986Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Systems"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34351
      },
      "nvd": {
        "published": "2026-07-21T22:18:32.907",
        "lastModified": "2026-07-24T15:18:55.350",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61010",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Process Manufacturing Systems permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61012",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.607Z",
      "date_published": "2026-07-21T21:37:44.417Z",
      "date_updated": "2026-07-24T14:53:14.719Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Time and Labor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00318,
        "percentile": 0.2417
      },
      "nvd": {
        "published": "2026-07-21T22:18:33.020",
        "lastModified": "2026-08-03T18:53:04.390",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61012",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Time and Labor fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 699,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61013",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.607Z",
      "date_published": "2026-07-21T21:37:44.783Z",
      "date_updated": "2026-07-24T15:02:44.435Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Time and Labor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17452
      },
      "nvd": {
        "published": "2026-07-21T22:18:33.130",
        "lastModified": "2026-08-03T18:47:45.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61013",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Time and Labor permits a high-privilege HTTP caller to read and modify data outside its remaining authority, while the check is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 817,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.607Z",
      "date_published": "2026-07-21T21:37:45.108Z",
      "date_updated": "2026-07-24T14:54:02.339Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Inventory Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00376,
        "percentile": 0.30365
      },
      "nvd": {
        "published": "2026-07-21T22:18:33.243",
        "lastModified": "2026-08-03T18:44:37.427",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61014",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle says Oracle Inventory Management in its Internal Operations component returns protected data to an unauthorized caller, but does not disclose the endpoint or output path.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 718,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61015",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.608Z",
      "date_published": "2026-07-21T21:37:45.412Z",
      "date_updated": "2026-07-24T14:54:49.183Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Time and Labor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18074
      },
      "nvd": {
        "published": "2026-07-21T22:18:33.353",
        "lastModified": "2026-08-03T18:42:24.267",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61015",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record states an impact and affected Oracle component without exposing a defensible engineering cause.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 551,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61019",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.608Z",
      "date_published": "2026-07-21T21:37:45.743Z",
      "date_updated": "2026-07-24T14:55:38.181Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Customers Online"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26352
      },
      "nvd": {
        "published": "2026-07-21T22:18:33.467",
        "lastModified": "2026-08-03T18:39:33.827",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61019",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Customers Online lets a low-privileged HTTP user read and modify critical data outside the intended scope, but the failing check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 722,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61020",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.608Z",
      "date_published": "2026-07-21T21:37:46.079Z",
      "date_updated": "2026-07-24T15:00:59.737Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Customers Online"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17818
      },
      "nvd": {
        "published": "2026-07-21T22:18:33.573",
        "lastModified": "2026-08-03T18:39:24.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61020",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Customers Online permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 722,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61023",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.608Z",
      "date_published": "2026-07-21T21:37:46.392Z",
      "date_updated": "2026-07-24T14:58:34.818Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Inventory Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03503
      },
      "nvd": {
        "published": "2026-07-21T22:18:33.690",
        "lastModified": "2026-08-03T18:27:52.940",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61023",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a privileged local path to Inventory Management takeover but does not publish the privilege-assignment failure.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 599,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61024",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.608Z",
      "date_published": "2026-07-21T21:37:46.711Z",
      "date_updated": "2026-07-24T14:47:13.923Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iRecruitment"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26312
      },
      "nvd": {
        "published": "2026-07-21T22:18:33.807",
        "lastModified": "2026-08-03T18:16:53.293",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61024",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 706,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61025",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.608Z",
      "date_published": "2026-07-21T21:37:47.029Z",
      "date_updated": "2026-07-24T14:52:21.928Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iRecruitment"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37139
      },
      "nvd": {
        "published": "2026-07-21T22:18:33.920",
        "lastModified": "2026-08-03T18:15:21.883",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61025",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 526,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61026",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.608Z",
      "date_published": "2026-07-21T21:37:47.345Z",
      "date_updated": "2026-07-24T14:51:32.703Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iRecruitment"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30471
      },
      "nvd": {
        "published": "2026-07-21T22:18:34.037",
        "lastModified": "2026-07-24T15:18:56.937",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61026",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle iRecruitment but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 566,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61027",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.608Z",
      "date_published": "2026-07-21T21:37:47.657Z",
      "date_updated": "2026-07-24T14:50:25.139Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Inventory Costing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Cost Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24042
      },
      "nvd": {
        "published": "2026-07-21T22:18:34.150",
        "lastModified": "2026-07-24T15:18:57.070",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61027",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged HTTP caller can take over Cost Management, but Oracle does not disclose the additional privilege boundary or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61028",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.608Z",
      "date_published": "2026-07-21T21:37:47.971Z",
      "date_updated": "2026-07-24T14:49:28.227Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Inventory Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 1.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01994
      },
      "nvd": {
        "published": "2026-07-21T22:18:34.257",
        "lastModified": "2026-07-24T15:18:57.207",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61028",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Inventory Management can leave a finite resource unreleased and suffer partial denial of service, but the resource and error path are not public.",
        "basis": [
          "CNA",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 631,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61030",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.608Z",
      "date_published": "2026-07-21T21:37:48.289Z",
      "date_updated": "2026-07-24T14:48:02.734Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Product Development"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.251
      },
      "nvd": {
        "published": "2026-07-21T22:18:34.370",
        "lastModified": "2026-07-24T15:18:57.347",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61030",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle product allows an action beyond the caller's intended authority, but the public record does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 822,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61031",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.609Z",
      "date_published": "2026-07-21T21:37:48.609Z",
      "date_updated": "2026-07-24T14:42:00.655Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Financials Common Country product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Financials Common Country"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25137
      },
      "nvd": {
        "published": "2026-07-21T22:18:34.490",
        "lastModified": "2026-07-24T15:18:57.467",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61031",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege Financials Common Country user can read and modify critical data, but the object and failing permission check are not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 758,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61035",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.609Z",
      "date_published": "2026-07-21T21:37:48.931Z",
      "date_updated": "2026-07-24T14:43:02.893Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Financials for the Americas product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Financials for the Americas"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00431,
        "percentile": 0.35456
      },
      "nvd": {
        "published": "2026-07-21T22:18:34.607",
        "lastModified": "2026-07-24T15:18:57.590",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61035",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Financials for the Americas permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61036",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.609Z",
      "date_published": "2026-07-21T21:37:49.243Z",
      "date_updated": "2026-07-24T14:46:17.564Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (Norway)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16333
      },
      "nvd": {
        "published": "2026-07-21T22:18:34.720",
        "lastModified": "2026-07-24T18:34:22.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61036",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Norway Payroll lets a high-privileged HTTP user access data outside the intended action scope, but the failing decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 660,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61037",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.609Z",
      "date_published": "2026-07-21T21:37:49.556Z",
      "date_updated": "2026-07-24T14:45:34.109Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Loans"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.251
      },
      "nvd": {
        "published": "2026-07-21T22:18:34.827",
        "lastModified": "2026-07-24T15:18:57.827",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61037",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports low-privileged read and write access to critical Loans data, but the CPU does not identify the protected object or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 678,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61039",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.609Z",
      "date_published": "2026-07-21T21:37:49.877Z",
      "date_updated": "2026-07-29T03:55:49.340Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Supply Chain Planning"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0043,
        "percentile": 0.35411
      },
      "nvd": {
        "published": "2026-07-21T22:18:34.937",
        "lastModified": "2026-07-29T05:16:57.360",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61039",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports takeover of Advanced Supply Chain Planning but does not identify the invoked operation or engineering cause.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61041",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.609Z",
      "date_published": "2026-07-21T21:37:50.197Z",
      "date_updated": "2026-07-24T14:43:52.136Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Demantra Demand Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31657
      },
      "nvd": {
        "published": "2026-07-21T22:18:35.047",
        "lastModified": "2026-07-24T15:18:58.070",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61041",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can exceed its authority in Demantra Product Security, but Oracle does not publish the protected object, action, or failing check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle's July 2026 text risk matrix at https://www.oracle.com/security-alerts/cpujul2026verbose.html; it confirms Demantra Demand Management Product Security, versions 12.2.3 through 12.2.15, low-privileged HTTP reachability, scope change, CVSS 9.9, and takeover impact, but Oracle publishes no protected object, action, or failing access-control check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 695,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61043",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.609Z",
      "date_published": "2026-07-21T21:37:50.511Z",
      "date_updated": "2026-07-24T14:34:06.317Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Production Scheduling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.0218
      },
      "nvd": {
        "published": "2026-07-21T22:18:35.163",
        "lastModified": "2026-07-24T15:18:58.210",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61043",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Production Scheduling path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 983,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61044",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.609Z",
      "date_published": "2026-07-21T21:37:50.834Z",
      "date_updated": "2026-07-24T14:34:57.681Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Production Scheduling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19736
      },
      "nvd": {
        "published": "2026-07-21T22:18:35.283",
        "lastModified": "2026-07-24T15:18:58.340",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61044",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle operation can be invoked by a caller lacking the intended authority, but the precise check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 819,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61046",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.609Z",
      "date_published": "2026-07-21T21:37:51.157Z",
      "date_updated": "2026-07-24T14:35:56.490Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Production Scheduling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14385
      },
      "nvd": {
        "published": "2026-07-21T22:18:35.390",
        "lastModified": "2026-07-24T15:18:58.490",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61046",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Production Scheduling operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 852,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61047",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:51.480Z",
      "date_updated": "2026-07-24T14:41:03.822Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Production Scheduling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 1.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01608
      },
      "nvd": {
        "published": "2026-07-21T22:18:35.503",
        "lastModified": "2026-07-24T15:18:58.623",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61047",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged local caller can modify Oracle Production Scheduling data, but the protected object and failing check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 630,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61048",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:51.796Z",
      "date_updated": "2026-07-24T14:39:47.708Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component: User Interface).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Inventory Optimization"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19567
      },
      "nvd": {
        "published": "2026-07-21T22:18:35.617",
        "lastModified": "2026-07-24T15:18:58.740",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61048",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Inventory Optimization can be driven into resource exhaustion or termination, while the unbounded operation and limit are not public.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61049",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:52.121Z",
      "date_updated": "2026-07-24T14:38:55.663Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Production Scheduling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07703
      },
      "nvd": {
        "published": "2026-07-21T22:18:35.730",
        "lastModified": "2026-07-24T15:18:58.867",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61049",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports an unauthenticated adjacent-network path to Production Scheduling takeover with victim interaction but does not publish the authentication workflow.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-287",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 733,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61050",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:52.537Z",
      "date_updated": "2026-07-24T14:37:53.226Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: User Interface).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Production Scheduling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20641
      },
      "nvd": {
        "published": "2026-07-21T22:18:35.843",
        "lastModified": "2026-07-24T15:18:58.987",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61050",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61051",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:52.873Z",
      "date_updated": "2026-07-24T14:36:59.873Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Concurrent Processing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16341
      },
      "nvd": {
        "published": "2026-07-21T22:18:35.957",
        "lastModified": "2026-07-24T15:18:59.137",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61051",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 823,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61052",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:53.215Z",
      "date_updated": "2026-07-24T14:23:52.364Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Solaris"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.0427
      },
      "nvd": {
        "published": "2026-07-21T22:18:36.067",
        "lastModified": "2026-07-30T17:38:21.767",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61052",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled work or allocation lacks an effective bound, release, or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 562,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61053",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:53.523Z",
      "date_updated": "2026-07-24T14:24:56.679Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Diameter Gateway and SDK).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Communications BRM - Elastic Charging Engine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03363
      },
      "nvd": {
        "published": "2026-07-21T22:18:36.177",
        "lastModified": "2026-07-24T15:18:59.387",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61053",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Communications BRM - Elastic Charging Engine lets a lower-privileged caller exercise a higher-privileged operation because privilege assignment or enforcement is incomplete.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 731,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61055",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:53.881Z",
      "date_updated": "2026-07-24T14:31:33.753Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise SCM Order Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03361
      },
      "nvd": {
        "published": "2026-07-21T22:18:36.290",
        "lastModified": "2026-07-24T15:18:59.507",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61055",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege local user can take over PeopleSoft Order Management, but Oracle does not publish the privilege transition or check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 630,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61056",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:54.192Z",
      "date_updated": "2026-07-24T14:32:25.845Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Grants product of Oracle PeopleSoft (component: Grants).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Grants"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.1106
      },
      "nvd": {
        "published": "2026-07-21T22:18:36.407",
        "lastModified": "2026-07-24T15:18:59.623",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61056",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports unauthenticated read and write access in PeopleSoft Grants but does not disclose the request, object, or failed control.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 687,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61057",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:54.506Z",
      "date_updated": "2026-07-24T14:26:37.270Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN eSettlements"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.1106
      },
      "nvd": {
        "published": "2026-07-21T22:18:36.517",
        "lastModified": "2026-07-24T15:18:59.747",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61057",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated eSettlements caller can read or modify protected data, but Oracle does not publish the request or access-control decision.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 717,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61059",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:54.819Z",
      "date_updated": "2026-07-24T14:25:48.753Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise SCM Order Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30429
      },
      "nvd": {
        "published": "2026-07-21T22:18:36.620",
        "lastModified": "2026-07-24T15:18:59.873",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61059",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A network-reachable PeopleSoft Order Management operation permits unauthenticated reads and writes of protected data, but the exact endpoint and check are not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms the Security component, HTTP exposure, no privileges, and confidentiality/integrity impact, but publishes no endpoint or access-control check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 773,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61060",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:55.156Z",
      "date_updated": "2026-07-24T14:19:23.242Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle E-Business Suite Secure Enterprise Search"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12688
      },
      "nvd": {
        "published": "2026-07-21T22:18:36.723",
        "lastModified": "2026-07-24T15:18:59.997",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61060",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged search user can read and modify data outside its role, but Oracle does not disclose the failing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 782,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61061",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:55.520Z",
      "date_updated": "2026-07-24T14:20:08.802Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle JDeveloper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00109,
        "percentile": 0.01436
      },
      "nvd": {
        "published": "2026-07-21T22:18:36.843",
        "lastModified": "2026-07-24T15:19:00.127",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61061",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle JDeveloper permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61062",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:55.929Z",
      "date_updated": "2026-07-24T14:20:53.323Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Cash Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03362
      },
      "nvd": {
        "published": "2026-07-21T22:18:36.977",
        "lastModified": "2026-07-24T15:19:00.260",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61062",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Enterprise FIN Cash Management fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 776,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61063",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.610Z",
      "date_published": "2026-07-21T21:37:56.246Z",
      "date_updated": "2026-07-24T14:21:41.816Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Supplier Contract Management product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise SCM Supplier Contract Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01251
      },
      "nvd": {
        "published": "2026-07-21T22:18:37.090",
        "lastModified": "2026-07-24T15:19:00.397",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61063",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Supplier Contract Management permits a low-privilege local caller to gain takeover authority, while the privileged transition is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 834,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61064",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.611Z",
      "date_published": "2026-07-21T21:37:56.807Z",
      "date_updated": "2026-07-24T14:22:17.953Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iRecruitment"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12657
      },
      "nvd": {
        "published": "2026-07-21T22:18:37.203",
        "lastModified": "2026-07-24T15:19:00.547",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61064",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle iRecruitment in its Install / Upgrade Issues component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 665,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61065",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.611Z",
      "date_published": "2026-07-21T21:37:57.172Z",
      "date_updated": "2026-07-28T03:57:14.612Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.3845
      },
      "nvd": {
        "published": "2026-07-21T22:18:37.313",
        "lastModified": "2026-07-28T05:17:16.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61065",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Access Manager authentication engine accepts an unauthenticated remote action over HTTP, but the advisory does not disclose the missing check.",
        "basis": [
          "CNA",
          "CWE-287",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Primary source inspected: https://www.oracle.com/security-alerts/cpujul2026.html. Oracle identifies the Access Manager Authentication Engine, HTTP, no authentication, and CVSS 9.8, but publishes no affected operation or causal check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 547,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61067",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.611Z",
      "date_published": "2026-07-21T21:37:57.787Z",
      "date_updated": "2026-07-28T03:57:16.147Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Access Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22433
      },
      "nvd": {
        "published": "2026-07-21T22:18:37.423",
        "lastModified": "2026-07-28T05:17:16.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61067",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Access Manager authenticates an adjacent-network caller incorrectly and permits takeover, but the failing authentication step is not public.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61068",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.611Z",
      "date_published": "2026-07-21T21:37:58.109Z",
      "date_updated": "2026-07-24T14:17:45.204Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Billing Argentina product of Oracle PeopleSoft (component: Billing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Billing Argentina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0043,
        "percentile": 0.35412
      },
      "nvd": {
        "published": "2026-07-21T22:18:37.533",
        "lastModified": "2026-07-24T15:19:01.130",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61068",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Billing permits a high-privileged HTTP user to take over the component, while the missing authority boundary is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61069",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.611Z",
      "date_published": "2026-07-21T21:37:58.422Z",
      "date_updated": "2026-07-24T14:16:59.904Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN General Ledger Argentina product of Oracle PeopleSoft (component: General Ledger).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN General Ledger Argentina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16586
      },
      "nvd": {
        "published": "2026-07-21T22:18:37.647",
        "lastModified": "2026-07-24T15:19:01.253",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61069",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says PeopleSoft Enterprise FIN General Ledger Argentina permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 797,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61070",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.611Z",
      "date_published": "2026-07-21T21:37:58.734Z",
      "date_updated": "2026-07-24T14:07:48.574Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Cash Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Argentina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00394,
        "percentile": 0.32101
      },
      "nvd": {
        "published": "2026-07-21T22:18:37.763",
        "lastModified": "2026-07-31T15:23:42.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61070",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthenticated HTTP-triggered resource loss in PeopleSoft Cash Management but does not publish the unbounded operation.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 632,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61071",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.611Z",
      "date_published": "2026-07-21T21:37:59.056Z",
      "date_updated": "2026-07-24T14:16:10.628Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineering).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Engineering Argentina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09926
      },
      "nvd": {
        "published": "2026-07-21T22:18:37.873",
        "lastModified": "2026-07-24T15:19:01.507",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61071",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 752,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61072",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.611Z",
      "date_published": "2026-07-21T21:37:59.379Z",
      "date_updated": "2026-07-24T14:15:23.836Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (component: Staffing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Staffing Front Office Brazil"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31656
      },
      "nvd": {
        "published": "2026-07-21T22:18:37.980",
        "lastModified": "2026-07-24T15:19:01.627",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61072",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an access-control failure in PeopleSoft Staffing, while its public CPU does not disclose the affected HTTP operation or permission check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official table confirms the PeopleSoft Staffing component, HTTP and version 9.1 but publishes no endpoint or authorization rule."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 760,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61073",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.611Z",
      "date_published": "2026-07-21T21:37:59.715Z",
      "date_updated": "2026-07-24T14:11:51.823Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Purchasing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Brazil"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32429
      },
      "nvd": {
        "published": "2026-07-21T22:18:38.090",
        "lastModified": "2026-07-31T15:23:36.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61073",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 626,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61074",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.611Z",
      "date_published": "2026-07-21T21:38:00.056Z",
      "date_updated": "2026-07-24T14:10:41.312Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Brazil"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29278
      },
      "nvd": {
        "published": "2026-07-21T22:18:38.193",
        "lastModified": "2026-07-31T15:23:29.817",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61074",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PeopleSoft Enterprise FIN Common Objects Brazil exposes a critical operation without completing the authentication check required for that operation.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61075",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.611Z",
      "date_published": "2026-07-21T21:38:00.390Z",
      "date_updated": "2026-07-24T14:08:55.001Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Self-Service Human Resources"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12803
      },
      "nvd": {
        "published": "2026-07-21T22:18:38.303",
        "lastModified": "2026-07-27T16:58:47.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61075",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Self-Service Human Resources caller can read and modify data beyond its intended role, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 724,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61076",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.611Z",
      "date_published": "2026-07-21T21:38:00.722Z",
      "date_updated": "2026-07-24T14:00:32.016Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise HCM Talent Acquisition Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31658
      },
      "nvd": {
        "published": "2026-07-21T22:18:38.410",
        "lastModified": "2026-07-24T15:19:02.177",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61076",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Talent Acquisition Manager lets a low-privileged HTTP caller take over the product, but the public material does not identify the misbound Job Opening operation or check.",
        "basis": [
          "CNA",
          "CWE-269",
          "Oracle Critical Patch Update July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html on 2026-08-05; Oracle confirms PeopleSoft HCM Talent Acquisition Manager 9.2, the Job Opening component, HTTP reachability, low required privileges, scope change, and takeover impact, but the CPU matrix does not disclose the misbound operation or failing check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 755,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61077",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:01.058Z",
      "date_updated": "2026-07-24T14:06:48.805Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Mobile Inventory Management product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise SCM Mobile Inventory Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01367
      },
      "nvd": {
        "published": "2026-07-21T22:18:38.523",
        "lastModified": "2026-07-24T15:19:02.300",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61077",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege local Mobile Inventory user can read and modify critical data, but the object and failing permission check are not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1046,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61078",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:01.390Z",
      "date_updated": "2026-07-30T03:55:36.656Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CC Common Application Objects"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21092
      },
      "nvd": {
        "published": "2026-07-21T22:18:38.637",
        "lastModified": "2026-07-30T05:16:37.927",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61078",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PeopleSoft Enterprise CC Common Application Objects accepts an attacker-controlled redirect destination without restricting navigation to an approved host.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1065,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61079",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:01.717Z",
      "date_updated": "2026-07-24T14:05:11.147Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle GoldenGate (component: Libraries).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GoldenGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00076,
        "percentile": 0.00122
      },
      "nvd": {
        "published": "2026-07-21T22:18:38.747",
        "lastModified": "2026-07-24T15:19:02.547",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61079",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle GoldenGate reports a race in its libraries that can violate data and availability state, but the competing operations are not public.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-284",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 908,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-61080",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:02.044Z",
      "date_updated": "2026-07-24T13:55:51.035Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Human Resources"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12657
      },
      "nvd": {
        "published": "2026-07-21T22:18:38.860",
        "lastModified": "2026-07-24T15:19:02.673",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61080",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports low-privileged read and write access in Public Sector Human Resources, but the CPU does not identify the protected object or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 727,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:02.369Z",
      "date_updated": "2026-07-23T19:14:08.540Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15118
      },
      "nvd": {
        "published": "2026-07-21T22:18:38.980",
        "lastModified": "2026-07-27T17:49:51.677",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61081",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports limited Performance Schema disclosure but does not identify the exposed field or output path.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 662,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-61082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:02.687Z",
      "date_updated": "2026-07-29T19:26:42.805Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Connectors"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04467
      },
      "nvd": {
        "published": "2026-07-21T22:18:39.093",
        "lastModified": "2026-08-03T15:17:26.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61082",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Oracle record lists disclosure, authorization, CSRF, and redirect weaknesses without identifying which mechanism applies to Connector/J.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200",
          "CWE-285",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61083",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:03.015Z",
      "date_updated": "2026-07-23T19:15:44.203Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Performance Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12656
      },
      "nvd": {
        "published": "2026-07-21T22:18:39.217",
        "lastModified": "2026-07-23T20:17:13.810",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61083",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Performance Management path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 691,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61084",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:03.340Z",
      "date_updated": "2026-07-23T19:16:24.661Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle GoldenGate (component: Libraries).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GoldenGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02471
      },
      "nvd": {
        "published": "2026-07-21T22:18:39.323",
        "lastModified": "2026-07-23T20:17:13.923",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61084",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected operation accepts a caller with insufficient privilege, while Oracle withholds the role or object-level decision.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 676,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-61085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:03.666Z",
      "date_updated": "2026-07-23T19:13:25.627Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise SCM Inventory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30428
      },
      "nvd": {
        "published": "2026-07-21T22:18:39.440",
        "lastModified": "2026-07-23T20:17:14.040",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61085",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The PeopleSoft Enterprise SCM Inventory operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61086",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:04.004Z",
      "date_updated": "2026-07-23T19:41:00.354Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise SCM Order Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30428
      },
      "nvd": {
        "published": "2026-07-21T22:18:39.550",
        "lastModified": "2026-07-23T20:17:14.153",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61086",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTPS caller can read protected PeopleSoft Order Management data, but the endpoint and failing access check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 610,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61087",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:04.334Z",
      "date_updated": "2026-07-23T19:12:33.607Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Payables"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30427
      },
      "nvd": {
        "published": "2026-07-21T22:18:39.663",
        "lastModified": "2026-07-23T20:17:14.273",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61087",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says PeopleSoft Enterprise FIN Payables permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61088",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:04.662Z",
      "date_updated": "2026-07-23T19:18:18.936Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise SCM Manufacturing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30428
      },
      "nvd": {
        "published": "2026-07-21T22:18:39.763",
        "lastModified": "2026-07-23T20:17:14.387",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61088",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated HTTP access to PeopleSoft Manufacturing data but does not publish the endpoint or authentication check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 600,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61089",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:04.973Z",
      "date_updated": "2026-07-24T14:02:13.360Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Inventory product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise SCM Inventory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24549
      },
      "nvd": {
        "published": "2026-07-21T22:18:39.880",
        "lastModified": "2026-07-24T15:19:02.797",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61089",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 722,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61090",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:05.294Z",
      "date_updated": "2026-07-24T14:01:26.223Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Miscellaneous).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Foundation"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03362
      },
      "nvd": {
        "published": "2026-07-21T22:18:39.997",
        "lastModified": "2026-07-24T15:19:02.920",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61090",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The component assigns or permits a privilege beyond the authority granted to the invoking user.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61091",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:05.606Z",
      "date_updated": "2026-07-24T13:59:28.536Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: BRM Server).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Communications Billing and Revenue Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03362
      },
      "nvd": {
        "published": "2026-07-21T22:18:40.110",
        "lastModified": "2026-07-24T15:19:03.037",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61091",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle Communications Billing and Revenue Management but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 721,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61092",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.612Z",
      "date_published": "2026-07-21T21:38:05.923Z",
      "date_updated": "2026-07-23T19:19:11.166Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.2928
      },
      "nvd": {
        "published": "2026-07-21T22:18:40.220",
        "lastModified": "2026-07-24T18:42:38.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61092",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle WebCenter Enterprise Capture exposes a security-sensitive operation without verifying that the network caller is authenticated.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61093",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:06.242Z",
      "date_updated": "2026-07-23T19:19:55.630Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33258
      },
      "nvd": {
        "published": "2026-07-21T22:18:40.333",
        "lastModified": "2026-07-27T17:49:21.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61093",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege optimizer request can repeatedly crash or hang MySQL, but Oracle does not publish the unbounded query path.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 632,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61094",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:06.566Z",
      "date_updated": "2026-07-28T03:56:39.713Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37138
      },
      "nvd": {
        "published": "2026-07-21T22:18:40.443",
        "lastModified": "2026-07-28T05:17:16.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61094",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged replication session can invoke a critical MySQL operation without the function-level authentication it requires, although Oracle does not name the operation.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 638,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-61095",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:06.911Z",
      "date_updated": "2026-07-23T19:21:29.943Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Communications Unified Inventory Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19979
      },
      "nvd": {
        "published": "2026-07-21T22:18:40.557",
        "lastModified": "2026-07-23T20:17:14.847",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61095",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged inventory-management user can read or modify data outside the assigned role, but the affected object and check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 824,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-61096",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:07.239Z",
      "date_updated": "2026-07-23T19:17:21.843Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02948
      },
      "nvd": {
        "published": "2026-07-21T22:18:40.670",
        "lastModified": "2026-07-27T17:48:09.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61096",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The MySQL Server operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 703,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-61097",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:07.567Z",
      "date_updated": "2026-07-23T19:23:31.309Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Banking Trade Finance Process Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00167,
        "percentile": 0.06309
      },
      "nvd": {
        "published": "2026-07-21T22:18:40.790",
        "lastModified": "2026-07-23T20:17:15.087",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61097",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP flow can induce a victim-mediated cross-origin action or redirect, but Oracle does not disclose the exact channel check.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-352",
          "CWE-601",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the Oracle risk matrix confirms unauthenticated HTTP reachability with required user interaction and changed scope but does not distinguish the CSRF and redirect roles in the causal path."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1196,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61098",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:07.936Z",
      "date_updated": "2026-07-23T19:24:46.884Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33025
      },
      "nvd": {
        "published": "2026-07-21T22:18:40.910",
        "lastModified": "2026-07-24T18:43:33.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61098",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle WebCenter Enterprise Capture permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 580,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61099",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:08.255Z",
      "date_updated": "2026-07-23T19:26:23.371Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33025
      },
      "nvd": {
        "published": "2026-07-21T22:18:41.023",
        "lastModified": "2026-07-24T18:43:42.283",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61099",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle WebCenter Enterprise Capture fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 580,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61100",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:08.624Z",
      "date_updated": "2026-07-23T19:41:39.271Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Enterprise Capture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38453
      },
      "nvd": {
        "published": "2026-07-21T22:18:41.140",
        "lastModified": "2026-07-24T18:43:38.143",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61100",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A critical WebCenter Enterprise Capture HTTP function is reachable without authenticating the remote caller.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 581,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61101",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:09.101Z",
      "date_updated": "2026-07-23T19:27:07.578Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle MES for Process Manufacturing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02088
      },
      "nvd": {
        "published": "2026-07-21T22:18:41.247",
        "lastModified": "2026-07-23T20:17:15.557",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61101",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle's record associates Oracle MES for Process Manufacturing in its Internal Operations component with a request-channel trust failure, but does not disclose the vulnerable endpoint or validation rule.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 976,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61102",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:09.560Z",
      "date_updated": "2026-07-24T13:57:31.523Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Banking Trade Finance"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25103
      },
      "nvd": {
        "published": "2026-07-21T22:18:41.360",
        "lastModified": "2026-07-24T15:19:03.160",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61102",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle component allows access beyond the caller's intended authority, but the public record does not identify the object, action, or failing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 751,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:10.891Z",
      "date_updated": "2026-07-24T13:56:38.031Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Campus Community"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14542
      },
      "nvd": {
        "published": "2026-07-21T22:18:41.467",
        "lastModified": "2026-07-31T19:21:15.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61103",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Campus Community permits an unauthenticated adjacent-network caller to read and modify protected data, but the access-control failure is not public.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 858,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61104",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:11.239Z",
      "date_updated": "2026-07-23T19:25:24.032Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CS Student Records"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.1738
      },
      "nvd": {
        "published": "2026-07-21T22:18:41.580",
        "lastModified": "2026-07-23T20:17:15.677",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61104",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Research Tracking returns a subset of protected records to an unauthenticated HTTP caller, while the exposed object and output path are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 594,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61105",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:11.649Z",
      "date_updated": "2026-07-23T19:22:28.901Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Banking Trade Finance"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25101
      },
      "nvd": {
        "published": "2026-07-21T22:18:41.690",
        "lastModified": "2026-07-23T20:17:15.790",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61105",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Banking Trade Finance permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 751,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61106",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:12.060Z",
      "date_updated": "2026-07-23T19:28:45.355Z",
      "publisher": "oracle",
      "title": "Vulnerability in Oracle GoldenGate (component: Config Service Executable).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GoldenGate"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29277
      },
      "nvd": {
        "published": "2026-07-21T22:18:41.793",
        "lastModified": "2026-07-28T02:12:33.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61106",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an unauthenticated HTTP path to GoldenGate takeover but does not publish the Config Service authentication failure.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61107",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:12.422Z",
      "date_updated": "2026-08-01T03:56:51.956Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications DBA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37138
      },
      "nvd": {
        "published": "2026-07-21T22:18:41.900",
        "lastModified": "2026-08-01T05:17:01.053",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61107",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61108",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:12.761Z",
      "date_updated": "2026-07-23T19:30:04.274Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: GIS).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22633
      },
      "nvd": {
        "published": "2026-07-21T22:18:42.037",
        "lastModified": "2026-07-27T17:41:46.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61108",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled input can consume finite work or memory without an effective bound, release or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 626,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61109",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.613Z",
      "date_published": "2026-07-21T21:38:13.077Z",
      "date_updated": "2026-07-23T19:30:42.535Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33259
      },
      "nvd": {
        "published": "2026-07-21T22:18:42.150",
        "lastModified": "2026-07-27T17:41:28.193",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61109",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Attacker-controlled work or allocation lacks an effective bound, release, or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 673,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-61110",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:13.407Z",
      "date_updated": "2026-08-01T03:56:53.043Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications DBA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.3302
      },
      "nvd": {
        "published": "2026-07-21T22:18:42.260",
        "lastModified": "2026-08-01T05:17:01.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61110",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can take over Applications DBA, but Oracle does not disclose the ADPatch operation or authentication and authorization check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 525,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61111",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:13.739Z",
      "date_updated": "2026-08-01T03:56:39.574Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Object Library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.0451
      },
      "nvd": {
        "published": "2026-07-21T22:18:42.370",
        "lastModified": "2026-08-01T05:17:01.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61111",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged local Application Object Library caller can read critical data beyond its intended role, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 780,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61112",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:14.085Z",
      "date_updated": "2026-07-23T19:37:19.649Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Order Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26352
      },
      "nvd": {
        "published": "2026-07-21T22:18:42.483",
        "lastModified": "2026-07-28T17:31:24.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61112",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle product allows an action beyond the caller's intended authority, but the public record does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61113",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:14.489Z",
      "date_updated": "2026-08-01T03:56:40.654Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Object Library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24089
      },
      "nvd": {
        "published": "2026-07-21T22:18:42.593",
        "lastModified": "2026-08-01T05:17:01.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61113",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated Application Object Library caller can read and modify critical data, but the endpoint and failing permission check are not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 750,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61114",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:14.798Z",
      "date_updated": "2026-08-01T03:56:41.734Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Object Library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23499
      },
      "nvd": {
        "published": "2026-07-21T22:18:42.707",
        "lastModified": "2026-08-01T05:17:01.593",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61114",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Application Object Library permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 563,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61115",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:15.337Z",
      "date_updated": "2026-07-23T19:38:44.708Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Order Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37137
      },
      "nvd": {
        "published": "2026-07-21T22:18:42.810",
        "lastModified": "2026-07-28T17:30:57.420",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61115",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Order Management lets a high-privileged HTTP user reach a takeover action, but the missing action-level check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61116",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:16.010Z",
      "date_updated": "2026-08-01T03:56:42.941Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Application Object Library"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24917
      },
      "nvd": {
        "published": "2026-07-21T22:18:42.923",
        "lastModified": "2026-08-01T05:17:01.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61116",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated disclosure of all Application Object Library data, but the CPU does not identify the response or data-selection error.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 593,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61117",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:16.326Z",
      "date_updated": "2026-07-23T19:36:40.828Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (UK)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18983
      },
      "nvd": {
        "published": "2026-07-21T22:18:43.037",
        "lastModified": "2026-07-24T18:34:25.843",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61117",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports cross-scope HRMS data disclosure but does not identify the endpoint or access-control predicate.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 676,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61119",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:16.644Z",
      "date_updated": "2026-07-23T19:32:17.440Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (UK)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00318,
        "percentile": 0.2417
      },
      "nvd": {
        "published": "2026-07-21T22:18:43.153",
        "lastModified": "2026-07-24T18:34:29.157",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61119",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can modify or disrupt UK Payroll data beyond its role, but the protected object and failing check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 670,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61120",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:16.948Z",
      "date_updated": "2026-07-23T19:35:58.771Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (US)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02272
      },
      "nvd": {
        "published": "2026-07-21T22:18:43.263",
        "lastModified": "2026-07-24T18:35:01.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61120",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle HRMS (US) path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 554,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61121",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:17.253Z",
      "date_updated": "2026-07-23T19:35:21.003Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (UK)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33029
      },
      "nvd": {
        "published": "2026-07-21T22:18:43.380",
        "lastModified": "2026-07-24T18:34:37.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61121",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged caller reaches a protected Oracle operation despite a missing-authentication label, and the exact gate is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "The structured CWE-306 missing-authentication label conflicts with the embedded low-privilege attack prerequisite, and the exact Oracle access gate is not public."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 507,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61122",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:17.563Z",
      "date_updated": "2026-07-23T19:34:29.208Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (UK)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26309
      },
      "nvd": {
        "published": "2026-07-21T22:18:43.487",
        "lastModified": "2026-07-24T18:34:39.797",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61122",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle HRMS (UK) operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 685,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61123",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:17.883Z",
      "date_updated": "2026-07-23T19:33:35.241Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (US)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11663
      },
      "nvd": {
        "published": "2026-07-21T22:18:43.600",
        "lastModified": "2026-07-24T18:35:04.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61123",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports both data disclosure and partial denial of service but does not disclose whether one access-control, output, or resource defect causes them.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 648,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61125",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.614Z",
      "date_published": "2026-07-21T21:38:18.441Z",
      "date_updated": "2026-07-23T19:32:55.386Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Configure to Order"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00356,
        "percentile": 0.28286
      },
      "nvd": {
        "published": "2026-07-21T22:18:43.710",
        "lastModified": "2026-07-23T20:17:17.883",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61125",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Configure to Order exposes protected data to an unintended observer, while the field and output path are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 716,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61126",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:18.754Z",
      "date_updated": "2026-07-23T19:40:19.085Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Communications Billing and Revenue Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03362
      },
      "nvd": {
        "published": "2026-07-21T22:18:43.827",
        "lastModified": "2026-07-23T20:17:18.000",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61126",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged local user can take over the Billing and Revenue Management platform but does not publish the privileged operation.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 717,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61127",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:19.078Z",
      "date_updated": "2026-07-23T19:11:33.081Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solution Designer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Communications Service Catalog and Design"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31656
      },
      "nvd": {
        "published": "2026-07-21T22:18:43.940",
        "lastModified": "2026-07-23T20:17:18.113",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61127",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 613,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61128",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:19.400Z",
      "date_updated": "2026-07-23T19:10:20.474Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24712
      },
      "nvd": {
        "published": "2026-07-21T22:18:44.050",
        "lastModified": "2026-07-27T17:41:00.117",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61128",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled input can consume finite work or memory without an effective bound, release or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61129",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:19.716Z",
      "date_updated": "2026-07-23T18:52:16.836Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38443
      },
      "nvd": {
        "published": "2026-07-21T22:18:44.167",
        "lastModified": "2026-07-27T13:46:04.370",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61129",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "ATG Portals exposes a takeover path to an unauthenticated HTTP caller, but Oracle does not publish the route, identity flow, or omitted authentication decision.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306",
          "https://www.oracle.com/security-alerts/cpujul2026.html",
          "https://www.oracle.com/security-alerts/cpujul2026verbose.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July CPU confirms ATG Portals 11.4.0, unauthenticated HTTP reachability, and takeover impact but no route, credential flow, or missing check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 519,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61130",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:20.083Z",
      "date_updated": "2026-07-23T18:50:12.677Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28165
      },
      "nvd": {
        "published": "2026-07-21T22:18:44.280",
        "lastModified": "2026-07-27T13:45:20.160",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61130",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Commerce Platform exposes a security-sensitive operation without verifying that the network caller is authenticated.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 708,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61131",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:20.401Z",
      "date_updated": "2026-07-23T18:51:14.722Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38449
      },
      "nvd": {
        "published": "2026-07-21T22:18:44.393",
        "lastModified": "2026-07-27T13:44:49.867",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61131",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A critical Oracle Commerce function is reachable over HTTP without authentication.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 536,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61132",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:20.711Z",
      "date_updated": "2026-07-23T18:49:28.330Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04264
      },
      "nvd": {
        "published": "2026-07-21T22:18:44.500",
        "lastModified": "2026-07-27T13:41:41.547",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61132",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Commerce accepts a cross-site state-changing request in a logged-in user's browser context, but the action and anti-CSRF failure are not public.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 910,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61133",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:21.038Z",
      "date_updated": "2026-07-23T18:48:44.685Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34444
      },
      "nvd": {
        "published": "2026-07-21T22:18:44.617",
        "lastModified": "2026-07-27T13:41:09.277",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61133",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Commerce exposes critical data to an unauthenticated LDAP caller, but the public record does not reveal the output or storage path.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61134",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:21.567Z",
      "date_updated": "2026-07-23T18:48:06.910Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18942
      },
      "nvd": {
        "published": "2026-07-21T22:18:44.737",
        "lastModified": "2026-07-27T13:38:34.397",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61134",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Commerce Platform operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 723,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61135",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:21.895Z",
      "date_updated": "2026-07-23T18:47:20.938Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24089
      },
      "nvd": {
        "published": "2026-07-21T22:18:44.847",
        "lastModified": "2026-07-27T13:37:44.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61135",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Commerce Platform exposes critical HTTP functionality without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 724,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61136",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:22.211Z",
      "date_updated": "2026-07-23T18:42:25.977Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21704
      },
      "nvd": {
        "published": "2026-07-21T22:18:44.960",
        "lastModified": "2026-07-27T13:37:23.073",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61136",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 794,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61137",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:22.528Z",
      "date_updated": "2026-07-23T18:46:27.007Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21313
      },
      "nvd": {
        "published": "2026-07-21T22:18:45.070",
        "lastModified": "2026-07-27T13:36:46.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61137",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Commerce Platform exposes the affected function without establishing the authentication identity required to invoke it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61138",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.615Z",
      "date_published": "2026-07-21T21:38:22.835Z",
      "date_updated": "2026-07-23T18:45:27.998Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Complex Maintenance, Repair and Overhaul"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17295
      },
      "nvd": {
        "published": "2026-07-21T22:18:45.187",
        "lastModified": "2026-07-23T19:16:57.797",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61138",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Complex Maintenance permits an unauthenticated HTTP caller to read and modify protected data, while the exact access-control failure is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 947,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61140",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.616Z",
      "date_published": "2026-07-21T21:38:23.157Z",
      "date_updated": "2026-08-01T03:56:46.234Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle WebCenter Sites"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38449
      },
      "nvd": {
        "published": "2026-07-21T22:18:45.300",
        "lastModified": "2026-08-01T05:17:01.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61140",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle WebCenter Sites reaches a protected operation without completing the authentication state or credential validation required for that path.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61141",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.616Z",
      "date_published": "2026-07-21T21:38:24.485Z",
      "date_updated": "2026-07-28T03:57:16.909Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Affordable Care Act).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Benefits"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22397
      },
      "nvd": {
        "published": "2026-07-21T22:18:45.420",
        "lastModified": "2026-07-28T05:17:16.550",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61141",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The affected Oracle function is reachable without the authentication required for that operation, although the function is not named publicly.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 542,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61142",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:51:55.616Z",
      "date_published": "2026-07-21T21:38:24.801Z",
      "date_updated": "2026-07-23T18:44:08.049Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17784
      },
      "nvd": {
        "published": "2026-07-21T22:18:45.527",
        "lastModified": "2026-07-27T18:23:34.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61142",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Payroll returns critical data to a low-privileged user outside the intended authorization scope, but the failing object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 666,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.736Z",
      "date_published": "2026-07-21T21:38:25.225Z",
      "date_updated": "2026-07-23T18:43:22.489Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Communications Convergent Charging Controller"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-304",
          "name": "Missing Critical Step in Authentication",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11815
      },
      "nvd": {
        "published": "2026-07-21T22:18:45.640",
        "lastModified": "2026-07-23T19:16:58.143",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61143",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle assigns access-control, weak-verification, redirect, and password-recovery CWEs to a user-interaction takeover without identifying which mechanism is primary.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-304",
          "CWE-601",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 709,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:25.537Z",
      "date_updated": "2026-07-23T18:41:42.788Z",
      "publisher": "oracle",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Server"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "MySQL Cluster"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00431,
        "percentile": 0.35443
      },
      "nvd": {
        "published": "2026-07-21T22:18:45.763",
        "lastModified": "2026-07-27T17:40:37.907",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61144",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says MySQL Server can be driven into a hang or repeatable crash; the unbounded operation and triggering input are not public.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 633,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:25.864Z",
      "date_updated": "2026-07-23T18:37:11.762Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38461
      },
      "nvd": {
        "published": "2026-07-21T22:18:45.880",
        "lastModified": "2026-07-24T14:23:43.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61145",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle states that the Content Acquisition System accepts an unauthenticated HTTP attack leading to takeover but does not disclose the endpoint or missing authentication check.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html was inspected; Oracle exposes the Content Acquisition System component and HTTP attack conditions but no endpoint or failing authentication check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 660,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61146",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:26.191Z",
      "date_updated": "2026-07-23T18:41:01.364Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33031
      },
      "nvd": {
        "published": "2026-07-21T22:18:45.990",
        "lastModified": "2026-07-24T14:24:09.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61146",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a low-privilege Content Acquisition System takeover over HTTP but does not publish the missing privilege or authentication check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.oracle.com/security-alerts/cpujul2026.html. Oracle's public risk matrix confirms low-privilege HTTP reachability and takeover impact but does not disclose the Content Acquisition System check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 827,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:26.506Z",
      "date_updated": "2026-07-23T18:40:16.443Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03161
      },
      "nvd": {
        "published": "2026-07-21T22:18:46.093",
        "lastModified": "2026-07-24T14:24:14.123",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61147",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled input can consume finite work or memory without an effective bound, release or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 789,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61148",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:26.832Z",
      "date_updated": "2026-07-23T18:39:40.786Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22442
      },
      "nvd": {
        "published": "2026-07-21T22:18:46.207",
        "lastModified": "2026-07-24T14:24:23.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61148",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle Commerce Guided Search / Oracle Commerce Experience Manager but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 651,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61149",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:27.228Z",
      "date_updated": "2026-07-23T18:39:00.302Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33032
      },
      "nvd": {
        "published": "2026-07-21T22:18:46.320",
        "lastModified": "2026-07-24T14:24:30.783",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61149",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can take over Commerce Experience Manager, but Oracle does not disclose the protected operation or check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 651,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61150",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:27.548Z",
      "date_updated": "2026-07-23T18:37:55.605Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17783
      },
      "nvd": {
        "published": "2026-07-21T22:18:46.430",
        "lastModified": "2026-07-24T14:24:40.243",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61150",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Experience Manager caller can read and modify critical data beyond its intended role, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 879,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61151",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:27.894Z",
      "date_updated": "2026-07-23T18:31:31.881Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20963
      },
      "nvd": {
        "published": "2026-07-21T22:18:46.547",
        "lastModified": "2026-07-24T14:24:49.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61151",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle product allows an action beyond the caller's intended authority, but the public record does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 856,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61152",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:28.212Z",
      "date_updated": "2026-07-23T18:54:06.806Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12803
      },
      "nvd": {
        "published": "2026-07-21T22:18:46.660",
        "lastModified": "2026-07-24T14:24:56.957",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61152",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege Experience Manager user can read and modify data outside intended authority, but the failed permission check is not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 833,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61153",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:28.547Z",
      "date_updated": "2026-07-23T18:32:22.106Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32427
      },
      "nvd": {
        "published": "2026-07-21T22:18:46.760",
        "lastModified": "2026-07-24T14:25:05.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61153",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Commerce Guided Search / Oracle Commerce Experience Manager permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July 2026 CPU at https://www.oracle.com/security-alerts/cpujul2026.html confirms Experience Manager, unauthenticated HTTP reachability, affected version 11.4.0, and full confidentiality and integrity impact but publishes no endpoint or omitted access-control check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 880,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61154",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:28.961Z",
      "date_updated": "2026-07-23T18:33:36.908Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search Platform Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28164
      },
      "nvd": {
        "published": "2026-07-21T22:18:46.870",
        "lastModified": "2026-08-03T20:00:38.467",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61154",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Forge component exposes a network takeover path without authenticating the HTTP caller.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 582,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61155",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:29.277Z",
      "date_updated": "2026-07-23T18:34:42.164Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search Platform Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38442
      },
      "nvd": {
        "published": "2026-07-21T22:18:46.977",
        "lastModified": "2026-08-03T19:50:33.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61155",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports unauthenticated confidentiality and availability impact in Commerce Guided Search Forge, but its access-control, authentication, resource, and permission labels do not resolve to one engineering cause.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306",
          "CWE-400",
          "CWE-732",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html - Oracle confirms unauthenticated HTTP confidentiality and availability impact in Commerce Guided Search Forge, but does not resolve the record's access-control, authentication, resource, and permission labels into one causal path."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 777,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61156",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.737Z",
      "date_published": "2026-07-21T21:38:29.613Z",
      "date_updated": "2026-07-23T18:36:18.421Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search Platform Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32427
      },
      "nvd": {
        "published": "2026-07-21T22:18:47.110",
        "lastModified": "2026-08-03T19:49:49.817",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61156",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle publishes unauthenticated Forge data access impact but no request or access-control predicate that explains the cause.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html; its row confirms Guided Search Forge over HTTPS, unauthenticated reachability, CVSS 9.1, and version 11.4.0, but no request or access-control predicate is public."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 792,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61157",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:29.944Z",
      "date_updated": "2026-07-23T18:35:21.953Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32424
      },
      "nvd": {
        "published": "2026-07-21T22:18:47.243",
        "lastModified": "2026-07-24T14:25:25.037",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61157",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP caller can read Experience Manager data, but the endpoint, object, and missing access check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 692,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:30.281Z",
      "date_updated": "2026-07-23T18:25:29.122Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32426
      },
      "nvd": {
        "published": "2026-07-21T22:18:47.357",
        "lastModified": "2026-07-24T14:25:32.913",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61158",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Commerce Guided Search / Oracle Commerce Experience Manager path exposes a privileged operation without first authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 691,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61159",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:30.621Z",
      "date_updated": "2026-07-23T18:30:40.025Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34444
      },
      "nvd": {
        "published": "2026-07-21T22:18:47.463",
        "lastModified": "2026-07-24T14:25:40.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61159",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports complete data access without identifying which response path or protected field exposes it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 692,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61160",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:30.944Z",
      "date_updated": "2026-07-23T18:29:55.576Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33026
      },
      "nvd": {
        "published": "2026-07-21T22:18:47.573",
        "lastModified": "2026-07-24T14:25:45.713",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61160",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle lists input validation, access control, and resource-consumption classes but publishes no failing check or causal path that selects among them.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-284",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 865,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61161",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:31.278Z",
      "date_updated": "2026-07-23T18:27:56.363Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38453
      },
      "nvd": {
        "published": "2026-07-21T22:18:47.687",
        "lastModified": "2026-07-24T14:25:53.993",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61161",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Commerce Endeca Application Controller exposes a critical HTTP function without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; Oracle confirms Endeca Application Controller, unauthenticated HTTP reachability, CVSS 9.8, version 11.4.0, and takeover, while the exact critical function remains undisclosed."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 663,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61162",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:31.647Z",
      "date_updated": "2026-07-23T18:27:06.738Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.045
      },
      "nvd": {
        "published": "2026-07-21T22:18:47.793",
        "lastModified": "2026-07-24T14:25:59.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61162",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Commerce Guided Search / Oracle Commerce Experience Manager permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 976,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61163",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:32.328Z",
      "date_updated": "2026-07-23T18:26:24.289Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29278
      },
      "nvd": {
        "published": "2026-07-21T22:18:47.910",
        "lastModified": "2026-07-24T14:26:05.877",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61163",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports an unauthenticated HTTP path to Commerce Forge takeover but does not publish the endpoint or authentication check.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61164",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:32.642Z",
      "date_updated": "2026-07-23T18:20:51.012Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24088
      },
      "nvd": {
        "published": "2026-07-21T22:18:48.020",
        "lastModified": "2026-07-24T14:26:11.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61164",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 891,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61165",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:32.968Z",
      "date_updated": "2026-07-23T18:24:42.282Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Commerce Guided Search Platform Services"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30237
      },
      "nvd": {
        "published": "2026-07-21T22:18:48.140",
        "lastModified": "2026-08-03T19:44:44.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61165",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle groups information exposure and resource-consumption impacts without publishing the input, output, or limit failure needed to select one cause.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 753,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61166",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:33.297Z",
      "date_updated": "2026-07-29T03:55:59.323Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile PLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.3302
      },
      "nvd": {
        "published": "2026-07-21T22:18:48.250",
        "lastModified": "2026-07-29T05:16:57.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61166",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle Agile PLM but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 505,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61167",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:33.619Z",
      "date_updated": "2026-07-29T03:56:00.131Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile PLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38449
      },
      "nvd": {
        "published": "2026-07-21T22:18:48.367",
        "lastModified": "2026-07-29T05:16:58.253",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61167",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Agile PLM exposes a security-sensitive operation without verifying that the network caller is authenticated.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 495,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61168",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:33.940Z",
      "date_updated": "2026-07-29T03:56:08.869Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile PLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33021
      },
      "nvd": {
        "published": "2026-07-21T22:18:48.477",
        "lastModified": "2026-07-29T05:16:58.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61168",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "A critical Agile PLM security function accepts a low-privilege HTTP caller without the authentication level it requires.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 494,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61169",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:34.253Z",
      "date_updated": "2026-07-29T03:56:09.631Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile PLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04499
      },
      "nvd": {
        "published": "2026-07-21T22:18:48.590",
        "lastModified": "2026-07-29T05:16:59.103",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61169",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports that a local low-privileged Agile PLM user can access critical data but does not disclose the object or failed control.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 688,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61170",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:34.566Z",
      "date_updated": "2026-07-29T03:56:10.431Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile PLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00366,
        "percentile": 0.29278
      },
      "nvd": {
        "published": "2026-07-21T22:18:48.700",
        "lastModified": "2026-07-29T05:16:59.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61170",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP caller can reach a critical Agile PLM operation without the authentication gate required for it, although the function is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61171",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:34.893Z",
      "date_updated": "2026-07-29T03:56:11.177Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile PLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32426
      },
      "nvd": {
        "published": "2026-07-21T22:18:48.817",
        "lastModified": "2026-07-29T05:16:59.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61171",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An HTTP-accessible Agile PLM critical operation can execute without authenticating the caller, although the exact endpoint is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms Agile PLM Security over HTTP with no privileges, but publishes no critical function, authentication check, or patch source."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 673,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61172",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:35.215Z",
      "date_updated": "2026-07-29T19:13:25.821Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile PLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32429
      },
      "nvd": {
        "published": "2026-07-21T22:18:48.940",
        "lastModified": "2026-07-29T20:17:09.707",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61172",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated Agile PLM client can read critical data, but Oracle does not identify the missing access-control check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61173",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:35.531Z",
      "date_updated": "2026-07-29T03:56:12.726Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile PLM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24088
      },
      "nvd": {
        "published": "2026-07-21T22:18:49.057",
        "lastModified": "2026-07-29T05:17:00.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61173",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 675,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61174",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.738Z",
      "date_published": "2026-07-21T21:38:35.872Z",
      "date_updated": "2026-07-23T15:34:02.987Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Lifecycle Analytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07049
      },
      "nvd": {
        "published": "2026-07-21T22:18:49.170",
        "lastModified": "2026-08-03T19:34:01.923",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61174",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record identifies a local unauthenticated installation issue in Product Lifecycle Analytics, but it does not name the file, permission, configuration, or state transition that enables compromise.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle's July 2026 CPU at https://www.oracle.com/security-alerts/cpujul2026.html; it confirms Product Lifecycle Analytics 3.6.1, Installation Issues, local access, no privileges, and CVSS 9.0, but it publishes only broad CWE-284 and no failing installation control or patch detail."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 946,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61175",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:36.205Z",
      "date_updated": "2026-07-23T15:32:39.871Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Lifecycle Analytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00424,
        "percentile": 0.3491
      },
      "nvd": {
        "published": "2026-07-21T22:18:49.290",
        "lastModified": "2026-08-03T19:05:25.067",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61175",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A critical Product Lifecycle Analytics HTTP function is reachable without authentication and returns protected data while degrading service.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 867,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61176",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:36.518Z",
      "date_updated": "2026-07-23T15:25:50.730Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Lifecycle Analytics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31322
      },
      "nvd": {
        "published": "2026-07-21T22:18:49.407",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61176",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Product Lifecycle Analytics reaches a protected operation without completing the authentication state or credential validation required for that path.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-269",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 884,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61178",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:36.849Z",
      "date_updated": "2026-07-29T03:56:13.489Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Product Lifecycle Management for Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.3845
      },
      "nvd": {
        "published": "2026-07-21T22:18:49.523",
        "lastModified": "2026-07-31T21:13:16.227",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61178",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The affected Oracle function is exposed without the required authentication, although the public record does not identify the function or code path.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 609,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61179",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:37.162Z",
      "date_updated": "2026-08-01T03:56:04.910Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Product Lifecycle Management for Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33026
      },
      "nvd": {
        "published": "2026-07-21T22:18:49.637",
        "lastModified": "2026-08-01T05:17:01.957",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61179",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Agile PLM lets a low-privileged HTTP user take over the product, but the missing authentication or authorization boundary is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 623,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61180",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:37.484Z",
      "date_updated": "2026-08-01T03:56:06.032Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Product Lifecycle Management for Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33026
      },
      "nvd": {
        "published": "2026-07-21T22:18:49.753",
        "lastModified": "2026-08-01T05:17:02.090",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61180",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Agile Product Lifecycle Management permits a low-privileged HTTP caller to take over the application, while the missing authentication or privilege check is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 623,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61181",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:37.845Z",
      "date_updated": "2026-08-01T03:56:07.115Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Product Lifecycle Management for Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16929
      },
      "nvd": {
        "published": "2026-07-21T22:18:49.870",
        "lastModified": "2026-08-01T05:17:02.217",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61181",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Agile PLM accepts a user-influenced password-recovery or redirect flow that can cross the intended origin boundary, while the exact parameter is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-601",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1056,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61182",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:38.145Z",
      "date_updated": "2026-08-01T03:56:16.033Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Product Lifecycle Management for Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03338
      },
      "nvd": {
        "published": "2026-07-21T22:18:49.990",
        "lastModified": "2026-08-01T05:17:02.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61182",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a privileged local path to Agile PLM takeover but does not publish the privilege-assignment failure.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 682,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:38.460Z",
      "date_updated": "2026-08-01T03:56:17.173Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Product Lifecycle Management for Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38448
      },
      "nvd": {
        "published": "2026-07-21T22:18:50.110",
        "lastModified": "2026-08-01T05:17:02.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61183",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an unauthenticated Reporting takeover over HTTP but does not publish the missing authentication check or operation.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.oracle.com/security-alerts/cpujul2026.html. Oracle's public risk matrix confirms unauthenticated HTTP reachability and takeover impact but does not disclose the Reporting authentication failure."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 607,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:38.776Z",
      "date_updated": "2026-08-01T03:56:18.256Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Product Lifecycle Management for Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.32425
      },
      "nvd": {
        "published": "2026-07-21T22:18:50.233",
        "lastModified": "2026-08-01T05:17:02.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61184",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an access-control failure in Agile PLM Product Quality Management, while its public CPU does not disclose the affected HTTP operation or permission check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official table confirms Product Quality Management, HTTP and version 6.2.4 but publishes no endpoint or authorization rule."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 839,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61185",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:39.100Z",
      "date_updated": "2026-08-01T03:56:19.354Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Product Lifecycle Management for Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00297,
        "percentile": 0.21973
      },
      "nvd": {
        "published": "2026-07-21T22:18:50.353",
        "lastModified": "2026-08-01T05:17:02.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61185",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Sensitive data is returned, stored, or left readable through an output path that lacks the required disclosure boundary.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 924,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61186",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:39.417Z",
      "date_updated": "2026-07-29T03:55:52.694Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Engineering Data Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00386,
        "percentile": 0.31365
      },
      "nvd": {
        "published": "2026-07-21T22:18:50.470",
        "lastModified": "2026-07-29T05:17:01.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61186",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Agile Engineering Data Management Install component exposes a critical operation to an unauthenticated HTTP caller.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306",
          "CWE-400",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 890,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:39.737Z",
      "date_updated": "2026-07-23T15:22:16.988Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Engineering Data Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-404",
          "name": "Improper Resource Shutdown or Release",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03325
      },
      "nvd": {
        "published": "2026-07-21T22:18:50.590",
        "lastModified": "2026-07-28T02:11:26.967",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61187",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Agile Engineering Data Management installer can leave a finite resource unreleased and suffer partial denial of service, but the resource and path are not public.",
        "basis": [
          "CNA",
          "CWE-404"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 741,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:40.040Z",
      "date_updated": "2026-08-01T03:56:20.668Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Product Lifecycle Management for Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23501
      },
      "nvd": {
        "published": "2026-07-21T22:18:50.700",
        "lastModified": "2026-08-01T05:17:02.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61188",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A protected function is exposed without the authentication required for that function.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 611,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61189",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:40.351Z",
      "date_updated": "2026-07-29T03:55:55.750Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Engineering Data Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04499
      },
      "nvd": {
        "published": "2026-07-21T22:18:50.830",
        "lastModified": "2026-07-29T05:17:02.063",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61189",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege local Agile Engineering Data Management user can read critical data, but the object and failed permission check are not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 807,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61190",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:40.677Z",
      "date_updated": "2026-07-29T03:55:56.546Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Engineering Data Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.14992
      },
      "nvd": {
        "published": "2026-07-21T22:18:50.943",
        "lastModified": "2026-07-29T05:17:02.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61190",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Agile Engineering Data Management permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 853,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:41.091Z",
      "date_updated": "2026-07-23T15:18:23.809Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Engineering Data Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03107
      },
      "nvd": {
        "published": "2026-07-21T22:18:51.060",
        "lastModified": "2026-07-28T02:11:03.473",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61191",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Agile Engineering Data Management lets a low-privileged local user modify documents or availability beyond the role's scope, but the failing control is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 801,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.739Z",
      "date_published": "2026-07-21T21:38:41.416Z",
      "date_updated": "2026-07-23T15:17:39.343Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Engineering Data Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24694
      },
      "nvd": {
        "published": "2026-07-21T22:18:51.177",
        "lastModified": "2026-07-28T02:10:58.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61192",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports repeatable hangs or crashes in Agile EDM Install, but the CPU does not identify the attacker-controlled work, memory, or termination condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 610,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61194",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.740Z",
      "date_published": "2026-07-21T21:38:41.721Z",
      "date_updated": "2026-07-23T15:15:49.527Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Engineering Data Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33259
      },
      "nvd": {
        "published": "2026-07-21T22:18:51.290",
        "lastModified": "2026-07-28T02:10:51.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61194",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports repeatable Agile EDM denial of service but does not identify the input or exhausted resource.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 604,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61195",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.740Z",
      "date_published": "2026-07-21T21:38:42.041Z",
      "date_updated": "2026-07-23T15:11:30.975Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Agile Engineering Data Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33258
      },
      "nvd": {
        "published": "2026-07-21T22:18:51.400",
        "lastModified": "2026-07-28T02:10:24.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61195",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Agile Engineering Data Management permits an authenticated request to consume an undisclosed resource until the service repeatedly crashes.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 604,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61196",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.740Z",
      "date_published": "2026-07-21T21:38:42.354Z",
      "date_updated": "2026-08-01T03:56:02.465Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38441
      },
      "nvd": {
        "published": "2026-07-21T22:18:51.510",
        "lastModified": "2026-08-01T05:17:02.943",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61196",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP caller can take over the Identity Manager Legacy UI, but Oracle does not disclose the endpoint, handler, or missing authentication gate.",
        "basis": [
          "CNA",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected Oracle's July 2026 CPU https://www.oracle.com/security-alerts/cpujul2026.html. Oracle confirms unauthenticated HTTP reachability of the Identity Manager Legacy UI, CVSS 9.8, and takeover impact, but publishes no endpoint, request field, handler, or missing authentication gate."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 545,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61197",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.740Z",
      "date_published": "2026-07-21T21:38:42.665Z",
      "date_updated": "2026-08-01T03:56:03.714Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Identity Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00396,
        "percentile": 0.3243
      },
      "nvd": {
        "published": "2026-07-21T22:18:51.620",
        "lastModified": "2026-08-01T05:17:03.067",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61197",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP request can read or modify all Oracle Identity Manager data, but Oracle does not publish the failing Legacy UI check.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html",
          "https://www.oracle.com/security-alerts/cpujul2026verbose.html"
        ],
        "deepDive": true,
        "notes": "Oracle CPU confirms unauthenticated HTTP access, affected OIM versions, and full confidentiality and integrity impact, but does not disclose the Legacy UI route, operation, or failing check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 730,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61200",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.740Z",
      "date_published": "2026-07-21T21:38:42.984Z",
      "date_updated": "2026-07-22T18:26:47.912Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Labor Distribution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12655
      },
      "nvd": {
        "published": "2026-07-21T22:18:51.730",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61200",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Labor Distribution operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61201",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.740Z",
      "date_published": "2026-07-21T21:38:43.295Z",
      "date_updated": "2026-07-30T03:55:37.439Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise CRM Common Objects"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27456
      },
      "nvd": {
        "published": "2026-07-21T22:18:51.837",
        "lastModified": "2026-07-30T05:16:38.050",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61201",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PeopleSoft CRM Common Objects exposes a critical HTTP function without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; Oracle confirms PeopleSoft Common Objects, unauthenticated HTTP reachability, CVSS 9.0, version 9.2.23, and takeover, while the exact critical function remains undisclosed."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 716,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61202",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.740Z",
      "date_published": "2026-07-21T21:38:43.605Z",
      "date_updated": "2026-07-28T03:57:00.911Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Solaris"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.01016
      },
      "nvd": {
        "published": "2026-07-21T22:18:51.947",
        "lastModified": "2026-07-28T05:17:16.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61202",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Solaris permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 817,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61203",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.740Z",
      "date_published": "2026-07-21T21:38:43.915Z",
      "date_updated": "2026-07-22T19:26:27.580Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Expenses"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33089
      },
      "nvd": {
        "published": "2026-07-21T22:18:52.063",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61203",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated HTTP reads, writes, and partial service loss in PeopleSoft Expenses but does not publish the endpoint or authentication check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html was inspected; Oracle confirms unauthenticated HTTP reachability to PeopleSoft Expenses and the impact profile but publishes no endpoint or missing authentication check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 869,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61204",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.740Z",
      "date_published": "2026-07-21T21:38:44.230Z",
      "date_updated": "2026-07-22T19:27:15.837Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Program Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05883
      },
      "nvd": {
        "published": "2026-07-21T22:18:52.180",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61204",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies a low-privilege, victim-assisted HTTP path to cross-scope takeover but does not publish the forged request or authorization transition.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-352",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Reviewed https://www.oracle.com/security-alerts/cpujul2026.html. Oracle's CPU matrix confirms a low-privilege HTTP path requiring another user's interaction and cross-scope takeover impact but publishes no request or authorization transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 819,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61205",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.740Z",
      "date_published": "2026-07-21T21:38:44.547Z",
      "date_updated": "2026-07-22T19:27:48.395Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise SCM Purchasing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00299,
        "percentile": 0.22217
      },
      "nvd": {
        "published": "2026-07-21T22:18:52.303",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61205",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 728,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61207",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.740Z",
      "date_published": "2026-07-21T21:38:44.866Z",
      "date_updated": "2026-07-22T18:27:39.491Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise SCM eProcurement"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24549
      },
      "nvd": {
        "published": "2026-07-21T22:18:52.447",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61207",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Manage Requisition Status lets an unauthenticated HTTP caller cross an undisclosed authorization boundary into PeopleSoft data reads and updates.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html",
          "https://www.oracle.com/security-alerts/cpujul2026verbose.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July CPU confirms Manage Requisition Status, PeopleSoft 9.2, unauthenticated HTTP reachability, and cross-scope confidentiality and integrity impact but no route or access-control check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 891,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61209",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:45.215Z",
      "date_updated": "2026-07-22T18:25:58.899Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft In-Memory Project Discovery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31654
      },
      "nvd": {
        "published": "2026-07-21T22:18:52.560",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61209",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP user can take over Project Discovery, but Oracle's public matrix does not identify the privilege assignment or authorization decision that fails.",
        "basis": [
          "CNA",
          "CWE-269",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official matrix gives Project Discovery, HTTP, low privilege, scope change, affected 9.2, and takeover impact but does not identify the privilege assignment or authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 705,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61210",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:45.524Z",
      "date_updated": "2026-07-22T18:28:56.982Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise SCM Manufacturing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22436
      },
      "nvd": {
        "published": "2026-07-21T22:18:52.677",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61210",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "An unauthenticated HTTPS caller can read and modify Manufacturing data, but Oracle does not publish the missing object or action check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 764,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61211",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:45.843Z",
      "date_updated": "2026-07-22T18:29:56.432Z",
      "publisher": "oracle",
      "title": "Vulnerability in the RDBMS component of Oracle Database Server.",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Database Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00424,
        "percentile": 0.34959
      },
      "nvd": {
        "published": "2026-07-21T22:18:52.790",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61211",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle identifies a DBMS_CLOUD privilege holder who can take over RDBMS through Oracle Net but does not disclose the operation or engineering failure.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the risk matrix names RDBMS, Execute DBMS_CLOUD, Oracle Net, and affected versions but publishes no failing operation, check, or patch detail."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 616,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61214",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:46.205Z",
      "date_updated": "2026-07-22T18:30:52.293Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (UK)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.2,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16657
      },
      "nvd": {
        "published": "2026-07-21T22:18:52.903",
        "lastModified": "2026-07-24T18:34:43.297",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61214",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle HRMS exposes a subset of protected payroll data to a high-privileged HTTP user, but the leaking response or query is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61216",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:46.526Z",
      "date_updated": "2026-07-22T18:32:35.286Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16521
      },
      "nvd": {
        "published": "2026-07-21T22:18:53.013",
        "lastModified": "2026-07-27T18:23:25.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61216",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Payroll operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 736,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61217",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:46.876Z",
      "date_updated": "2026-07-22T18:34:50.397Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Security Service"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02879
      },
      "nvd": {
        "published": "2026-07-21T22:18:53.127",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61217",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle SSL API accepts a spoofed or victim-mediated TLS request path, but Oracle does not disclose the failed peer or origin validation.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-290",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 801,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61218",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:47.219Z",
      "date_updated": "2026-07-22T18:31:36.733Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle E-Business Suite Secure Enterprise Search"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16172
      },
      "nvd": {
        "published": "2026-07-21T22:18:53.240",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61218",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle E-Business Suite Secure Enterprise Search permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 828,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:47.575Z",
      "date_updated": "2026-07-22T18:19:45.425Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Banking Origination"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06801
      },
      "nvd": {
        "published": "2026-07-21T22:18:53.347",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61220",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-61220 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 911,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61221",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:47.901Z",
      "date_updated": "2026-07-22T18:24:54.052Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Item Master product of Oracle E-Business Suite (component: iSet-up bugs).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Item Master"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12657
      },
      "nvd": {
        "published": "2026-07-21T22:18:53.460",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61221",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Item Master permits a low-privilege HTTP caller to read and modify data beyond its role, while the operation and check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 649,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61223",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:48.227Z",
      "date_updated": "2026-07-22T19:19:57.655Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Communications Converged Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27455
      },
      "nvd": {
        "published": "2026-07-21T22:18:53.577",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61223",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle Communications Converged Application Server in its Security component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Read https://www.oracle.com/security-alerts/cpujul2026.html; Oracle's CPU confirms unauthenticated TCP/IP reachability and takeover impact but provides no operation or failed access-control check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 760,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61224",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:48.550Z",
      "date_updated": "2026-07-22T19:22:02.543Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Communications Converged Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25844
      },
      "nvd": {
        "published": "2026-07-21T22:18:53.687",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61224",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle component lets a caller exceed its assigned authority, but the public record does not identify the protected object or missing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 750,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61225",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:48.894Z",
      "date_updated": "2026-07-22T19:23:21.875Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Communications Converged Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00348,
        "percentile": 0.27456
      },
      "nvd": {
        "published": "2026-07-21T22:18:53.800",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61225",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Communications Converged Application Server permits unauthenticated TCP/IP takeover, but the missing authentication or privilege step is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 604,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.741Z",
      "date_published": "2026-07-21T21:38:49.227Z",
      "date_updated": "2026-07-22T19:22:36.260Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: RTP Proxy).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Communications Converged Application Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02193
      },
      "nvd": {
        "published": "2026-07-21T22:18:53.917",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61226",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Converged Application Server permits a high-privileged local user to take over the RTP Proxy component, while the relevant authority boundary is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 822,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.742Z",
      "date_published": "2026-07-21T21:38:49.552Z",
      "date_updated": "2026-07-22T19:21:26.710Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Objects).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Brazil"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23029
      },
      "nvd": {
        "published": "2026-07-21T22:18:54.023",
        "lastModified": "2026-07-31T15:23:22.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61232",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says PeopleSoft Enterprise FIN Common Objects Brazil permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 630,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61233",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.742Z",
      "date_published": "2026-07-21T21:38:49.881Z",
      "date_updated": "2026-07-22T19:20:52.161Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Brazil"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38442
      },
      "nvd": {
        "published": "2026-07-21T22:18:54.133",
        "lastModified": "2026-07-31T15:23:13.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61233",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle states that the PeopleSoft Integration component accepts an unauthenticated HTTP attack leading to takeover but does not disclose the endpoint or missing authentication check.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284",
          "CWE-287",
          "CWE-306",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html was inspected; Oracle exposes the Integration component and HTTP attack conditions but no endpoint or failing authentication check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 587,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61234",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.742Z",
      "date_published": "2026-07-21T21:38:50.218Z",
      "date_updated": "2026-07-22T19:16:06.716Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcurement).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Brazil"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24089
      },
      "nvd": {
        "published": "2026-07-21T22:18:54.243",
        "lastModified": "2026-07-31T15:23:06.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61234",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 799,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61235",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.742Z",
      "date_published": "2026-07-21T21:38:50.543Z",
      "date_updated": "2026-07-22T19:29:05.816Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise HCM Global Payroll Switzerland"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0043,
        "percentile": 0.35411
      },
      "nvd": {
        "published": "2026-07-21T22:18:54.357",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61235",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies an access-control failure in PeopleSoft Global Payroll Switzerland, while its public CPU does not disclose the affected HTTP operation or permission check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official table confirms Global Payroll for Switzerland, HTTP and version 9.2 but publishes no endpoint or authorization rule."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 775,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61236",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.742Z",
      "date_published": "2026-07-21T21:38:50.870Z",
      "date_updated": "2026-07-22T19:17:26.070Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Staffing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Brazil"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23028
      },
      "nvd": {
        "published": "2026-07-21T22:18:54.460",
        "lastModified": "2026-07-31T15:22:59.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61236",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 624,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61237",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.742Z",
      "date_published": "2026-07-21T21:38:51.188Z",
      "date_updated": "2026-07-22T18:23:49.119Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Argentina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28795
      },
      "nvd": {
        "published": "2026-07-21T22:18:54.573",
        "lastModified": "2026-07-31T15:22:54.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61237",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated HTTP caller can read, modify, and disrupt PeopleSoft Argentina data across a changed scope, but Oracle does not disclose the Integration access-control decision.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; Oracle confirms PeopleSoft Argentina Integration over HTTP, unauthenticated reachability, scope change, affected 9.1, and 9.9 impact but does not disclose the access-control decision."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1081,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61238",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.742Z",
      "date_published": "2026-07-21T21:38:51.603Z",
      "date_updated": "2026-07-22T18:22:41.709Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Argentina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.23028
      },
      "nvd": {
        "published": "2026-07-21T22:18:54.687",
        "lastModified": "2026-07-31T15:22:48.850",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61238",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated eProcurement caller can read and modify critical PeopleSoft data, but the missing endpoint authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html on 2026-08-05; Oracle confirms PeopleSoft FIN Common Objects Argentina eProcurement over HTTP, Remote Exploit without Auth. Yes, CVSS 9.1, and version 9.1, but publishes no endpoint or missing access-control check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 809,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61239",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.742Z",
      "date_published": "2026-07-21T21:38:51.924Z",
      "date_updated": "2026-07-22T18:21:56.959Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Argentina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18748
      },
      "nvd": {
        "published": "2026-07-21T22:18:54.793",
        "lastModified": "2026-07-31T15:22:39.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61239",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A critical eProcurement operation is exposed without the authentication required for that function.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1082,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61240",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.742Z",
      "date_published": "2026-07-21T21:38:52.232Z",
      "date_updated": "2026-07-22T18:21:05.938Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eSettlements).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Argentina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00219,
        "percentile": 0.12458
      },
      "nvd": {
        "published": "2026-07-21T22:18:54.907",
        "lastModified": "2026-07-31T15:22:30.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61240",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "An adjacent unauthenticated caller can read and modify PeopleSoft data, but the public record does not identify the exposed interface or failed access rule.",
        "basis": [
          "CNA record",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1054,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61242",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.742Z",
      "date_published": "2026-07-21T21:38:52.538Z",
      "date_updated": "2026-07-22T18:20:25.177Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Argentina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22442
      },
      "nvd": {
        "published": "2026-07-21T22:18:55.010",
        "lastModified": "2026-07-31T15:22:24.467",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61242",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that PeopleSoft Enterprise FIN Common Objects Argentina permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284",
          "https://www.oracle.com/security-alerts/cpujul2026.html"
        ],
        "deepDive": true,
        "notes": "Oracle's July 2026 CPU at https://www.oracle.com/security-alerts/cpujul2026.html confirms the Staffing component, low-privileged HTTP reachability, scope change, affected version 9.1, and takeover impact but publishes no action, object, or failing authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 744,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.742Z",
      "date_published": "2026-07-21T21:38:52.856Z",
      "date_updated": "2026-07-22T18:15:12.114Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Common Objects Argentina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.33032
      },
      "nvd": {
        "published": "2026-07-21T22:18:55.123",
        "lastModified": "2026-07-31T15:22:13.413",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61243",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PeopleSoft Staffing lets a low-privileged HTTP user take over the component, but its mixed authentication and privilege records do not identify one failing check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 592,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61244",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:53.183Z",
      "date_updated": "2026-07-22T18:19:02.045Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Manufacturing Argentina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20915
      },
      "nvd": {
        "published": "2026-07-21T22:18:55.230",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61244",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated read and write access to all PeopleSoft FIN Manufacturing Argentina data, but the CPU does not identify the protected object or permission check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html - Oracle confirms unauthenticated HTTP read/write impact in PeopleSoft FIN Manufacturing Argentina, but publishes no protected object or missing permission check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 806,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61245",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:53.494Z",
      "date_updated": "2026-07-22T18:34:08.784Z",
      "publisher": "oracle",
      "title": "Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "PeopleSoft Enterprise FIN Manufacturing Brazil"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25613
      },
      "nvd": {
        "published": "2026-07-21T22:18:55.343",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61245",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A network-reachable security-sensitive operation is exposed without the authentication step required before invoking it.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-22T22:24:27.765Z",
      "date_updated": "2026-07-23T14:30:34.222Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Platform Security for Java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18148
      },
      "nvd": {
        "published": "2026-07-22T23:16:36.867",
        "lastModified": "2026-07-24T15:17:11.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61246",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Oracle record lists privilege, missing-authentication, and deserialization weaknesses without identifying which mechanism causes the Platform Security takeover.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269",
          "CWE-306",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 588,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61247",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:54.106Z",
      "date_updated": "2026-07-22T18:17:11.228Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Workflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.1751
      },
      "nvd": {
        "published": "2026-07-21T22:18:55.457",
        "lastModified": "2026-07-28T14:00:24.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61247",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Workflow path exposes a privileged operation without first authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 664,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61249",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:54.440Z",
      "date_updated": "2026-07-22T18:18:22.802Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Learning Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00355,
        "percentile": 0.28256
      },
      "nvd": {
        "published": "2026-07-21T22:18:55.563",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61249",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Protected Oracle data is disclosed to an unintended caller, but the output path and causal control are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61250",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:54.764Z",
      "date_updated": "2026-07-22T19:19:17.599Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.1782
      },
      "nvd": {
        "published": "2026-07-21T22:18:55.680",
        "lastModified": "2026-07-27T18:23:36.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61250",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Payroll operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 538,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:55.171Z",
      "date_updated": "2026-07-22T19:18:44.698Z",
      "publisher": "oracle",
      "title": "Vulnerability in the HRMS (Australia) product of Oracle E-Business Suite (component: Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "HRMS (Australia)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00376,
        "percentile": 0.30365
      },
      "nvd": {
        "published": "2026-07-21T22:18:55.787",
        "lastModified": "2026-07-24T18:34:45.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61251",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle HRMS returns protected payroll data to a low-privileged HTTP caller, but the data path and missing protection are not public.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:55.477Z",
      "date_updated": "2026-07-22T19:18:02.631Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (Hong Kong) product of Oracle E-Business Suite (component: Hong Kong Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (Hong Kong)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12845
      },
      "nvd": {
        "published": "2026-07-21T22:18:55.900",
        "lastModified": "2026-07-24T18:34:47.653",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61252",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle HRMS (Hong Kong) permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 675,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61253",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:55.804Z",
      "date_updated": "2026-07-22T19:16:43.976Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suite (component: Oracle Payroll Japanese).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (Japanese)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02629
      },
      "nvd": {
        "published": "2026-07-21T22:18:56.013",
        "lastModified": "2026-07-24T18:34:49.477",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61253",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle maps a victim-assisted HRMS Japanese Payroll request to CSRF but does not publish the state-changing endpoint or request-token failure.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 762,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61254",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:56.120Z",
      "date_updated": "2026-07-22T18:16:32.422Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite (component: Korean Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (Republic of Korea)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00179,
        "percentile": 0.07631
      },
      "nvd": {
        "published": "2026-07-21T22:18:56.127",
        "lastModified": "2026-07-24T18:34:51.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61254",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 788,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61255",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:56.429Z",
      "date_updated": "2026-07-22T15:29:02.044Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (New Zealand) product of Oracle E-Business Suite (component: New Zealand Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (New Zealand)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12802
      },
      "nvd": {
        "published": "2026-07-21T22:18:56.240",
        "lastModified": "2026-07-24T18:34:53.503",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61255",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61256",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:56.754Z",
      "date_updated": "2026-07-22T15:26:43.011Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Servers).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Inbound Telephony"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.1634
      },
      "nvd": {
        "published": "2026-07-21T22:18:56.360",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61256",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle Advanced Inbound Telephony but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 831,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61257",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:57.071Z",
      "date_updated": "2026-07-22T15:24:58.103Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Call Back).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle iSupport"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12658
      },
      "nvd": {
        "published": "2026-07-21T22:18:56.470",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61257",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle iSupport permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 635,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61260",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:57.382Z",
      "date_updated": "2026-07-22T15:20:46.672Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (UK)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12846
      },
      "nvd": {
        "published": "2026-07-21T22:18:56.587",
        "lastModified": "2026-07-24T18:34:55.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61260",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege HTTP caller can read or change UK Payroll records beyond its role, but Oracle does not publish the failing authorization predicate.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 639,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61261",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:57.786Z",
      "date_updated": "2026-07-22T15:16:04.774Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: User Interface).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Knowledge Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12689
      },
      "nvd": {
        "published": "2026-07-21T22:18:56.700",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61261",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports that a low-privileged Knowledge Management user can read and alter data but discloses no operation or failed check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 687,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61262",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.743Z",
      "date_published": "2026-07-21T21:38:58.103Z",
      "date_updated": "2026-07-22T18:15:49.608Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Teleservice"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17021
      },
      "nvd": {
        "published": "2026-07-21T22:18:56.803",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61262",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated Teleservice caller can read or modify protected data, but Oracle does not publish the endpoint or missing access decision.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 664,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61263",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.744Z",
      "date_published": "2026-07-21T21:38:58.411Z",
      "date_updated": "2026-07-22T18:10:33.205Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Scripting"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12689
      },
      "nvd": {
        "published": "2026-07-21T22:18:56.917",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61263",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Scripting operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 644,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61264",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.744Z",
      "date_published": "2026-07-21T21:38:58.729Z",
      "date_updated": "2026-07-22T18:14:12.588Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: RDBMS and UI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Call Center Technology"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12656
      },
      "nvd": {
        "published": "2026-07-21T22:18:57.030",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61264",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Call Center user can exceed assigned data access, but Oracle does not identify the missing object or action check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 693,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61266",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.744Z",
      "date_published": "2026-07-21T21:38:59.048Z",
      "date_updated": "2026-07-22T18:13:34.697Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Supply Chain Globalization product of Oracle E-Business Suite (component: Copy Inventory Organization).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Supply Chain Globalization"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09627
      },
      "nvd": {
        "published": "2026-07-21T22:18:57.133",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61266",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle assigns SQL injection to the Copy Inventory Organization component, but the public record does not identify the query, input, or missing parameter binding.",
        "basis": [
          "CNA",
          "CWE-89",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 851,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61267",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.744Z",
      "date_published": "2026-07-21T21:38:59.369Z",
      "date_updated": "2026-07-22T18:12:45.113Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HCM Configuration Workbench"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21058
      },
      "nvd": {
        "published": "2026-07-21T22:18:57.247",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61267",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle HCM Configuration Workbench exposes the affected function without establishing the authentication identity required to invoke it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-200",
          "CWE-284",
          "CWE-306",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 849,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61269",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.744Z",
      "date_published": "2026-07-21T21:38:59.692Z",
      "date_updated": "2026-07-22T15:12:59.263Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Workbench"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16339
      },
      "nvd": {
        "published": "2026-07-21T22:18:57.360",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61269",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Product Workbench permits a low-privilege HTTP caller to read, modify, and disrupt data beyond its role, while the check is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 784,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61271",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.744Z",
      "date_published": "2026-07-21T21:39:00.039Z",
      "date_updated": "2026-07-22T15:09:29.458Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Document Management and Collaboration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21059
      },
      "nvd": {
        "published": "2026-07-21T22:18:57.477",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61271",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle Document Management and Collaboration in its Attachments component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 891,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61274",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.744Z",
      "date_published": "2026-07-21T21:39:00.376Z",
      "date_updated": "2026-07-22T14:58:33.285Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Hub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16312
      },
      "nvd": {
        "published": "2026-07-21T22:18:57.623",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61274",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle component permits access outside the caller's role, but the public record does not identify the operation or causal authorization check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 761,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61275",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.744Z",
      "date_published": "2026-07-21T21:39:00.692Z",
      "date_updated": "2026-07-22T15:06:18.268Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Role Based Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Hub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16338
      },
      "nvd": {
        "published": "2026-07-21T22:18:57.743",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61275",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Product Hub role-based security permits a low-privileged HTTP user to exceed the intended data and action scope, but the failing role check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 768,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61277",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.744Z",
      "date_published": "2026-07-21T21:39:01.020Z",
      "date_updated": "2026-07-22T14:56:23.309Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Marketing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.1634
      },
      "nvd": {
        "published": "2026-07-21T22:18:57.850",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61277",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Marketing permits a low-privileged HTTP caller to read, modify, and disrupt resources outside the assigned role, while the exact check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 747,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61278",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.744Z",
      "date_published": "2026-07-21T21:39:01.351Z",
      "date_updated": "2026-07-22T14:51:26.537Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Workflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16521
      },
      "nvd": {
        "published": "2026-07-21T22:18:57.967",
        "lastModified": "2026-07-28T13:59:47.420",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61278",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Workflow permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 762,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61279",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.744Z",
      "date_published": "2026-07-21T21:39:01.669Z",
      "date_updated": "2026-07-22T14:46:45.296Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Proposals).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Proposals"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19304
      },
      "nvd": {
        "published": "2026-07-21T22:18:58.080",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61279",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports confidentiality, integrity, and availability impact in Proposals while providing only an exposure CWE, so the public material does not support one engineering cause.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 748,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61280",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.745Z",
      "date_published": "2026-07-21T21:39:01.988Z",
      "date_updated": "2026-07-22T14:44:14.845Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Outlook Sync Win 32).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Sales for Handhelds"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.1631
      },
      "nvd": {
        "published": "2026-07-21T22:18:58.190",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61280",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 808,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61282",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.745Z",
      "date_published": "2026-07-21T21:39:02.298Z",
      "date_updated": "2026-07-22T14:42:50.858Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self Service Benefits).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Benefits"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16339
      },
      "nvd": {
        "published": "2026-07-21T22:18:58.300",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61282",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 800,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61283",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.745Z",
      "date_published": "2026-07-21T21:39:02.614Z",
      "date_updated": "2026-07-22T14:41:32.389Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Web Services).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Bills of Material"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.1634
      },
      "nvd": {
        "published": "2026-07-21T22:18:58.417",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61283",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure in Oracle Bills of Material but does not disclose the missing or mismatched check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 791,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61285",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.745Z",
      "date_published": "2026-07-21T21:39:02.934Z",
      "date_updated": "2026-07-22T14:39:17.214Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Systems"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24086
      },
      "nvd": {
        "published": "2026-07-21T22:18:58.520",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61285",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged HTTP caller can take over Process Manufacturing Systems, but Oracle does not disclose the critical operation or additional privilege check.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 578,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61287",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.745Z",
      "date_published": "2026-07-21T21:39:03.260Z",
      "date_updated": "2026-07-22T18:11:51.472Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Systems"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25135
      },
      "nvd": {
        "published": "2026-07-21T22:18:58.640",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61287",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Process Manufacturing Systems caller can read and modify critical data beyond its intended role, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 774,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61289",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.745Z",
      "date_published": "2026-07-21T21:39:03.582Z",
      "date_updated": "2026-07-22T18:11:14.862Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Product Development"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31656
      },
      "nvd": {
        "published": "2026-07-21T22:18:58.747",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61289",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Oracle product allows an action beyond the caller's intended authority, but the public record does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 612,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61292",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.745Z",
      "date_published": "2026-07-21T21:39:03.893Z",
      "date_updated": "2026-07-22T18:33:22.611Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged atta...",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle U.S. Federal Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20478
      },
      "nvd": {
        "published": "2026-07-21T22:18:58.860",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61292",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege Federal Financials user receives data outside intended visibility, but the public record does not identify the output path.",
        "basis": [
          "CNA record",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 575,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61294",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.745Z",
      "date_published": "2026-07-21T21:39:04.216Z",
      "date_updated": "2026-07-22T18:05:31.859Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Common Applications Calendar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17455
      },
      "nvd": {
        "published": "2026-07-21T22:18:58.973",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61294",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Common Applications Calendar builds an SQL statement from attacker-controlled text without parameterization or SQL-context separation.",
        "basis": [
          "CNA",
          "CWE-89",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 859,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61297",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.745Z",
      "date_published": "2026-07-21T21:39:04.527Z",
      "date_updated": "2026-07-22T18:09:42.935Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Customers Online"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25135
      },
      "nvd": {
        "published": "2026-07-21T22:18:59.090",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61297",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Customers Online lets a low-privileged HTTP user read and modify critical data beyond the role's scope, but the failing check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 722,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61299",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.746Z",
      "date_published": "2026-07-21T21:39:18.405Z",
      "date_updated": "2026-07-22T18:09:00.487Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Logistics"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.19978
      },
      "nvd": {
        "published": "2026-07-21T22:18:59.200",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61299",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports low-privileged read and write access in Process Manufacturing Logistics, but the CPU does not identify the protected object or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 759,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61301",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.746Z",
      "date_published": "2026-07-21T21:39:18.707Z",
      "date_updated": "2026-07-22T18:08:24.150Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25136
      },
      "nvd": {
        "published": "2026-07-21T22:18:59.317",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61301",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports unauthorized Process Manufacturing data access but does not identify the operation or failing check.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 786,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61303",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.746Z",
      "date_published": "2026-07-21T21:39:20.024Z",
      "date_updated": "2026-07-22T18:07:27.520Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle EDI Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 1.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 1.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02282
      },
      "nvd": {
        "published": "2026-07-21T22:18:59.430",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61303",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle EDI Gateway returns protected data to a high-privileged local user, but the data object and output path are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 580,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61304",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.746Z",
      "date_published": "2026-07-21T21:39:20.327Z",
      "date_updated": "2026-07-22T18:06:34.229Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Price Protection"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16482
      },
      "nvd": {
        "published": "2026-07-21T22:18:59.540",
        "lastModified": "2026-07-29T15:57:27.550",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61304",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Price Protection path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 793,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.746Z",
      "date_published": "2026-07-21T21:39:20.650Z",
      "date_updated": "2026-07-22T17:57:55.139Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle In-Memory Cost Management for Discrete Industries"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30427
      },
      "nvd": {
        "published": "2026-07-21T22:18:59.650",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61309",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected Oracle operation is reachable without sufficient caller authority, but the exact access-control failure is withheld.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 677,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61310",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.746Z",
      "date_published": "2026-07-21T21:39:20.970Z",
      "date_updated": "2026-08-01T03:55:44.841Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Hub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25133
      },
      "nvd": {
        "published": "2026-07-21T22:18:59.760",
        "lastModified": "2026-08-01T05:17:03.187",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61310",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Product Hub operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 702,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61311",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.746Z",
      "date_published": "2026-07-21T21:39:21.294Z",
      "date_updated": "2026-08-01T03:55:43.401Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Hub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31695
      },
      "nvd": {
        "published": "2026-07-21T22:18:59.873",
        "lastModified": "2026-08-01T05:17:03.347",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61311",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can take over Oracle Product Hub, but the protected operation and failing authorization check are not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61312",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.746Z",
      "date_published": "2026-07-21T21:39:21.616Z",
      "date_updated": "2026-08-01T03:55:41.915Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Hub"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.2237
      },
      "nvd": {
        "published": "2026-07-21T22:18:59.983",
        "lastModified": "2026-08-01T05:17:03.507",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61312",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Product Hub permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 644,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61314",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.746Z",
      "date_published": "2026-07-21T21:39:21.943Z",
      "date_updated": "2026-07-22T18:01:38.606Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: All Miscellaneous EDI Issues).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle EDI Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00431,
        "percentile": 0.35457
      },
      "nvd": {
        "published": "2026-07-21T22:19:00.090",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61314",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a high-privileged HTTP user can take over EDI Gateway but does not publish the operation or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61315",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.747Z",
      "date_published": "2026-07-21T21:39:22.254Z",
      "date_updated": "2026-07-22T18:02:19.866Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle EDI Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20449
      },
      "nvd": {
        "published": "2026-07-21T22:19:00.207",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61315",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 523,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61316",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.747Z",
      "date_published": "2026-07-21T21:39:22.565Z",
      "date_updated": "2026-07-22T17:57:06.203Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle EDI Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20477
      },
      "nvd": {
        "published": "2026-07-21T22:19:00.317",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61316",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected interface returns, embeds or leaves protected information visible to an observer who is not entitled to receive it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 523,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61320",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.747Z",
      "date_published": "2026-07-21T21:39:22.924Z",
      "date_updated": "2026-07-22T17:51:32.865Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Payables"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31655
      },
      "nvd": {
        "published": "2026-07-21T22:19:00.430",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61320",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle Payables but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 513,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61322",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.747Z",
      "date_published": "2026-07-21T21:39:23.239Z",
      "date_updated": "2026-07-22T17:56:16.918Z",
      "publisher": "oracle",
      "title": "Vulnerability in the TeleSales product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "TeleSales"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00403,
        "percentile": 0.33079
      },
      "nvd": {
        "published": "2026-07-21T22:19:00.543",
        "lastModified": "2026-07-29T18:05:13.853",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61322",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can reach a critical Oracle TeleSales operation without the authentication check required for that operation, although Oracle does not disclose the operation.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 495,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61323",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.747Z",
      "date_published": "2026-07-21T21:39:23.562Z",
      "date_updated": "2026-07-29T19:26:40.670Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Benefits"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25135
      },
      "nvd": {
        "published": "2026-07-21T22:19:00.663",
        "lastModified": "2026-07-29T20:17:09.847",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61323",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege HTTP caller can read all Advanced Benefits data, but Oracle does not publish the missing object or role check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 575,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61324",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.747Z",
      "date_published": "2026-07-21T21:39:23.877Z",
      "date_updated": "2026-07-22T17:54:33.254Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Benefits"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20158
      },
      "nvd": {
        "published": "2026-07-21T22:19:00.787",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61324",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports that a low-privileged Advanced Benefits user can alter critical data but does not disclose the operation or engineering failure.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 711,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61325",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.747Z",
      "date_published": "2026-07-21T21:39:24.291Z",
      "date_updated": "2026-07-28T03:57:18.429Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Benefits"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00308,
        "percentile": 0.2308
      },
      "nvd": {
        "published": "2026-07-21T22:19:00.897",
        "lastModified": "2026-07-28T05:17:16.980",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61325",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged Advanced Benefits user can read or modify data beyond the assigned role, but the excessive permission or missing check is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 825,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61327",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.747Z",
      "date_published": "2026-07-21T21:39:24.602Z",
      "date_updated": "2026-07-22T17:53:10.774Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Bills of Material"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25134
      },
      "nvd": {
        "published": "2026-07-21T22:19:01.010",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61327",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Bills of Material operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 727,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.747Z",
      "date_published": "2026-07-21T21:39:24.917Z",
      "date_updated": "2026-07-22T17:52:13.302Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Cost Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25844
      },
      "nvd": {
        "published": "2026-07-21T22:19:01.127",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61328",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privileged Cost Management user can take over the product, but Oracle does not disclose the additional authority boundary that fails.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61329",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.747Z",
      "date_published": "2026-07-21T21:39:25.231Z",
      "date_updated": "2026-07-22T17:44:30.252Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Price Protection"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25134
      },
      "nvd": {
        "published": "2026-07-21T22:19:01.240",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61329",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Price Protection permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 722,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61333",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.748Z",
      "date_published": "2026-07-21T21:39:25.550Z",
      "date_updated": "2026-07-22T17:49:52.273Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Workbench"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25103
      },
      "nvd": {
        "published": "2026-07-21T22:19:01.353",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61333",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-61333 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 726,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61334",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.748Z",
      "date_published": "2026-07-21T21:39:25.870Z",
      "date_updated": "2026-07-22T17:49:05.547Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Price Protection"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.177
      },
      "nvd": {
        "published": "2026-07-21T22:19:01.467",
        "lastModified": "2026-07-29T15:58:52.753",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61334",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Price Protection permits a low-privilege HTTP caller to read and modify data beyond its role, while the object and check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 699,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61335",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.748Z",
      "date_published": "2026-07-21T21:39:26.187Z",
      "date_updated": "2026-07-22T17:46:26.671Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Product Workbench"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25099
      },
      "nvd": {
        "published": "2026-07-21T22:19:01.583",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61335",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle Product Workbench in its Internal Operations component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 726,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.748Z",
      "date_published": "2026-07-21T21:39:26.503Z",
      "date_updated": "2026-07-22T17:45:33.624Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Lease and Finance Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0043,
        "percentile": 0.35412
      },
      "nvd": {
        "published": "2026-07-21T22:19:01.700",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61336",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle component allows a remote caller to cross an access-control boundary, but the public record does not disclose the protected action or check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 575,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61337",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.748Z",
      "date_published": "2026-07-21T21:39:26.861Z",
      "date_updated": "2026-07-22T17:34:30.540Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Lease and Finance Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.2237
      },
      "nvd": {
        "published": "2026-07-21T22:19:01.813",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61337",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Lease and Finance Management lets a low-privileged HTTP user take over the component, but the access-control failure is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61338",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T15:52:20.748Z",
      "date_published": "2026-07-21T21:39:27.184Z",
      "date_updated": "2026-07-22T17:39:09.138Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Contracts Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26352
      },
      "nvd": {
        "published": "2026-07-21T22:19:01.930",
        "lastModified": "2026-07-27T17:44:21.593",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61338",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Contracts Integration permits a low-privileged HTTP caller to read and modify data beyond the assigned role, while the object or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 742,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61343",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:00:29.404Z",
      "date_published": "2026-07-09T17:46:05.221Z",
      "date_updated": "2026-07-30T16:51:37.950Z",
      "publisher": "cisa-cg",
      "title": "LibreBooking path traversal",
      "affected": {
        "vendors": [
          "LibreBooking"
        ],
        "products": [
          {
            "vendor": "LibreBooking",
            "product": "LibreBooking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.0084,
        "percentile": 0.54318
      },
      "nvd": {
        "published": "2026-07-09T18:16:58.030",
        "lastModified": "2026-07-30T19:18:34.423",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61343",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/LibreBooking/librebooking/pull/1456",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/LibreBooking/librebooking/releases/tag/v5.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/LibreBooking/librebooking/commit/cb9b7ad9da0243bd105809f6a4a8a6b9147c71ea",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-01.json",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-61343",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 274,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61344",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T17:07:47.785Z",
      "date_published": "2026-07-09T17:46:24.779Z",
      "date_updated": "2026-07-21T17:06:15.001Z",
      "publisher": "cisa-cg",
      "title": "Superior Court of California Hearing Reminder Service unauthenticated information disclosure",
      "affected": {
        "vendors": [
          "Superior Court of California, County of Los Angeles"
        ],
        "products": [
          {
            "vendor": "Superior Court of California, County of Los Angeles",
            "product": "Hearing Reminder Service"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19353
      },
      "nvd": {
        "published": "2026-07-09T18:16:58.163",
        "lastModified": "2026-07-21T18:17:03.820",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61344",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder records containing potentially sensitive information without authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.hrs.courts.ca.gov",
          "host": "www.hrs.courts.ca.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-02.json",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-61344",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-08T00:00:00.000Z",
      "date_published": "2026-07-15T00:00:00.000Z",
      "date_updated": "2026-07-15T19:26:26.306Z",
      "publisher": "mitre",
      "title": "Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target. The destructive effect is performed at open-time via O_TRUNC, and can happen before ...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28758
      },
      "nvd": {
        "published": "2026-07-15T16:16:50.307",
        "lastModified": "2026-07-15T20:56:32.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61371",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AVML opens a caller-selected output path through a followed symlink with O_TRUNC before completing input validation.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microsoft/avml/pull/754",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/microsoft/avml/releases/tag/v0.17.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://gist.github.com/thesmartshadow/2d099071f847de8db3dc4bbaf4dfa6df",
          "host": "gist.github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61376",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T01:43:55.012Z",
      "date_published": "2026-07-28T08:40:42.075Z",
      "date_updated": "2026-07-28T16:08:35.015Z",
      "publisher": "jpcert",
      "title": "ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings.",
      "affected": {
        "vendors": [
          "ELECOM CO.,LTD."
        ],
        "products": [
          {
            "vendor": "ELECOM CO.,LTD.",
            "product": "WAB-M1775-PS"
          },
          {
            "vendor": "ELECOM CO.,LTD.",
            "product": "WAB-S1775"
          },
          {
            "vendor": "ELECOM CO.,LTD.",
            "product": "WAB-M2133"
          },
          {
            "vendor": "ELECOM CO.,LTD.",
            "product": "WAB-I1750-PS"
          },
          {
            "vendor": "ELECOM CO.,LTD.",
            "product": "WAB-S1167-PS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "3.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.01129,
        "percentile": 0.63204
      },
      "nvd": {
        "published": "2026-07-28T09:16:42.553",
        "lastModified": "2026-07-28T16:19:27.750",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61376",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled command data reaches a command interpreter without safe argument separation or complete command-language neutralization.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.elecom.co.jp/news/security/20260728-01/",
          "host": "www.elecom.co.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jvn.jp/en/jp/JVN56870912/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 242,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-61378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:00:24.544Z",
      "date_published": "2026-07-16T20:30:30.723Z",
      "date_updated": "2026-07-17T13:22:08.813Z",
      "publisher": "icscert",
      "title": "AutomationDirect Productivity Suite Divide By Zero",
      "affected": {
        "vendors": [
          "AutomationDirect"
        ],
        "products": [
          {
            "vendor": "AutomationDirect",
            "product": "Productivity Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-369",
          "name": "Divide By Zero",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00113,
        "percentile": 0.0164
      },
      "nvd": {
        "published": "2026-07-16T21:17:21.950",
        "lastModified": "2026-07-17T18:31:44.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61378",
        "family": "OTHER_SPECIFIC",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A local input reaches an arithmetic division without first rejecting a zero divisor.",
        "basis": [
          "CNA",
          "CWE-369"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.automationdirect.com/support/software-downloads",
          "host": "www.automationdirect.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-04",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-04.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:00:24.531Z",
      "date_published": "2026-07-16T20:00:55.078Z",
      "date_updated": "2026-07-17T13:46:16.909Z",
      "publisher": "icscert",
      "title": "AutomationDirect Productivity Suite Out-of-bounds Write",
      "affected": {
        "vendors": [
          "AutomationDirect"
        ],
        "products": [
          {
            "vendor": "AutomationDirect",
            "product": "Productivity Suite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01305
      },
      "nvd": {
        "published": "2026-07-16T20:16:46.270",
        "lastModified": "2026-07-17T18:31:44.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61389",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Productivity Suite writes past a valid buffer because attacker-influenced data is not bounded to the destination allocation.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.automationdirect.com/support/software-downloads",
          "host": "www.automationdirect.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-04",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-04.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:51:16.530Z",
      "date_published": "2026-07-22T11:02:00.804Z",
      "date_updated": "2026-07-22T12:34:30.832Z",
      "publisher": "hikvision",
      "title": "There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.",
      "affected": {
        "vendors": [
          "Hikvision"
        ],
        "products": [
          {
            "vendor": "Hikvision",
            "product": "DS-2CD Series"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-2DE Series"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:hsrc@hikvision.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13594
      },
      "nvd": {
        "published": "2026-07-22T12:18:18.137",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61390",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted unauthenticated packet makes a Hikvision camera write beyond a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabilities-in-some-hikvision-cameras/",
          "host": "www.hikvision.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:51:16.531Z",
      "date_published": "2026-07-22T11:02:27.332Z",
      "date_updated": "2026-07-22T12:31:18.388Z",
      "publisher": "hikvision",
      "title": "There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.",
      "affected": {
        "vendors": [
          "Hikvision"
        ],
        "products": [
          {
            "vendor": "Hikvision",
            "product": "DS-2CD Series"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-2DE Series"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:hsrc@hikvision.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00304,
        "percentile": 0.2276
      },
      "nvd": {
        "published": "2026-07-22T12:18:18.247",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61391",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can overflow a stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabilities-in-some-hikvision-cameras/",
          "host": "www.hikvision.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T05:51:16.531Z",
      "date_published": "2026-07-22T11:03:11.533Z",
      "date_updated": "2026-07-22T12:29:21.886Z",
      "publisher": "hikvision",
      "title": "There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.",
      "affected": {
        "vendors": [
          "Hikvision"
        ],
        "products": [
          {
            "vendor": "Hikvision",
            "product": "DS-2CD Series"
          },
          {
            "vendor": "Hikvision",
            "product": "DS-2DE Series"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:hsrc@hikvision.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00206,
        "percentile": 0.10841
      },
      "nvd": {
        "published": "2026-07-22T12:18:18.350",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61392",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated camera request returns partial device-memory contents, but the public record does not identify the response or memory-selection path.",
        "basis": [
          "CNA record",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabilities-in-some-hikvision-cameras/",
          "host": "www.hikvision.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 165,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T13:39:11.897Z",
      "date_published": "2026-07-20T18:34:51.203Z",
      "date_updated": "2026-07-23T14:58:24.757Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2",
      "affected": {
        "vendors": [
          "dj-extensions.com"
        ],
        "products": [
          {
            "vendor": "dj-extensions.com",
            "product": "DJ-Classifieds extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17942
      },
      "nvd": {
        "published": "2026-07-20T19:17:28.027",
        "lastModified": "2026-07-23T16:17:45.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61424",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DJ-Classifieds extension for Joomla stores an uploaded dangerous file without restricting its type and executable destination.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://dj-extensions.com/dj-classifieds",
          "host": "dj-extensions.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/dj-classifieds-unauthenticated-file-upload/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T13:39:11.897Z",
      "date_published": "2026-07-20T18:45:51.191Z",
      "date_updated": "2026-07-23T15:01:22.667Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Gridbox extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25281
      },
      "nvd": {
        "published": "2026-07-20T19:17:28.150",
        "lastModified": "2026-07-23T16:17:45.973",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61425",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Gridbox exposes an alternate authentication path that can grant full administrator access.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.balbooa.com/gridbox",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/gridbox-critical-authentication-bypass/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 185,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61426",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:21.470Z",
      "date_published": "2026-07-11T13:01:01.057Z",
      "date_updated": "2026-07-13T15:05:01.782Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24698
      },
      "nvd": {
        "published": "2026-07-11T14:16:22.483",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61426",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PraisonAI defaults to all-interface binding with no API key and wildcard CORS, exposing agent instructions and invocation routes to unauthenticated clients.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6wjp-v33h-5cvq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-unauthenticated-agent-access-via-insecure-defaults",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 298,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:21.470Z",
      "date_published": "2026-07-15T11:25:37.581Z",
      "date_updated": "2026-07-16T15:18:17.077Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Authentication Bypass via HTTP-stream",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.39999999999999947,
      "epss": {
        "score": 0.00338,
        "percentile": 0.2641
      },
      "nvd": {
        "published": "2026-07-15T12:18:18.260",
        "lastModified": "2026-07-16T16:19:15.987",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61427",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HTTP-stream mode defaults to no API key and enforces bearer authentication only when an operator explicitly configures one.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hc5v-gxvj-58wh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-authentication-bypass-via-http-stream",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 796,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:21.470Z",
      "date_published": "2026-07-11T13:01:01.759Z",
      "date_updated": "2026-07-13T16:10:29.816Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI AgentMail before 4.6.78 Message Injection via Webhook",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.39999999999999947,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15869
      },
      "nvd": {
        "published": "2026-07-11T14:16:22.610",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61428",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The AgentMail webhook accepts message.received events without verifying a sender signature, allowing spoofed sender identities to enter the agent.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qj9c-59p6-8cgx",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-agentmail-before-message-injection-via-webhook",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61429",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:21.470Z",
      "date_published": "2026-07-11T13:01:02.429Z",
      "date_updated": "2026-07-13T14:37:28.127Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 1.6.78 SSRF via Crawl4AI Chromium backend",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.09999999999999964,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12759
      },
      "nvd": {
        "published": "2026-07-11T14:16:22.740",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61429",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PraisonAI server fetches an attacker-selected network destination without enforcing the intended destination policy.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6g59-gm2v-qhvq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-ssrf-via-crawl4ai-chromium-backend",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:21.470Z",
      "date_published": "2026-07-15T11:25:38.279Z",
      "date_updated": "2026-07-15T12:17:13.357Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.09999999999999964,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10667
      },
      "nvd": {
        "published": "2026-07-15T12:18:18.410",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61430",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The service accepts an attacker-controlled server-side request destination without constraining it to trusted endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qg25-6gc4-48mg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-dns-rebinding-ssrf-via-web-crawl",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 333,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61431",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:21.470Z",
      "date_published": "2026-07-10T13:58:04.296Z",
      "date_updated": "2026-07-10T15:19:27.432Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Path Traversal via ContextGatherer",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17458
      },
      "nvd": {
        "published": "2026-07-10T15:16:49.947",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61431",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ContextGatherer accepts absolute and parent-traversal paths from .praisoncontext and .praisoninclude files, reading files beyond the workspace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-q7m5-3jmv-vm48",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/1620b49f36945d8cc8ee5635b906c960df5097a0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-path-traversal-via-contextgatherer",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61432",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:21.471Z",
      "date_published": "2026-07-10T13:58:04.955Z",
      "date_updated": "2026-07-10T14:51:23.323Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI FastContext before 1.6.78 Path Traversal",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.2000000000000002,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20006
      },
      "nvd": {
        "published": "2026-07-10T15:16:50.077",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61432",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Praison FastContext accepts absolute or traversing workspace paths that escape the intended storage root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4xxv-6wmf-xf45",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/1620b49f36945d8cc8ee5635b906c960df5097a0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-fastcontext-before-path-traversal",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 687,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:21.471Z",
      "date_published": "2026-07-15T11:25:38.970Z",
      "date_updated": "2026-07-15T13:25:34.001Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Code Injection via API deployment generator",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04125
      },
      "nvd": {
        "published": "2026-07-15T12:18:18.553",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61433",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-79fv-7hq9-w7xg",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/1620b49f36945d8cc8ee5635b906c960df5097a0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-code-injection-via-api-deployment-generator",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:21.471Z",
      "date_published": "2026-07-10T13:58:05.604Z",
      "date_updated": "2026-07-10T14:46:22.280Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Allowlist Bypass via find -exec",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00579,
        "percentile": 0.44384
      },
      "nvd": {
        "published": "2026-07-10T15:16:50.213",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61434",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PraisonAI treats find as allowed without rejecting its -exec, -execdir, and -delete actions.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-cv3g-hj65-pcfh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-allowlist-bypass-via-find-exec",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 395,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:21.471Z",
      "date_published": "2026-07-15T11:25:39.670Z",
      "date_updated": "2026-07-15T17:58:50.469Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31092
      },
      "nvd": {
        "published": "2026-07-15T12:18:18.700",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61435",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PraisonAI derives its localhost bind decision from the client-controlled Host header, so Host: 127.0.0.1 disables authentication for a remote caller.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2gpf-2492-q9jh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-authentication-bypass-via-host-header-spoofing",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 672,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:47.928Z",
      "date_published": "2026-07-15T11:25:40.377Z",
      "date_updated": "2026-07-15T12:39:30.217Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Missing Webhook Signature Verification",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.0029,
        "percentile": 0.2122
      },
      "nvd": {
        "published": "2026-07-15T12:18:18.847",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61436",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PraisonAI accepts AgentMail webhook JSON without verifying its Svix signature, allowing a remote caller to forge message.received events.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7c92-x8vg-4258",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-missing-webhook-signature-verification",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61437",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:47.928Z",
      "date_published": "2026-07-10T13:58:06.305Z",
      "date_updated": "2026-07-14T01:47:45.326Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 1.6.78 Remote Code Execution via tools.py",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02977
      },
      "nvd": {
        "published": "2026-07-10T15:16:50.350",
        "lastModified": "2026-07-14T02:16:57.863",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61437",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "AgentFlow locates and executes a workflow-adjacent tools.py with importlib before applying the environment controls intended to authorize tool code.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4gfv-wg42-7jw5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-tools-py",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 673,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61438",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:47.928Z",
      "date_published": "2026-07-15T11:25:41.036Z",
      "date_updated": "2026-07-15T13:53:15.502Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10265
      },
      "nvd": {
        "published": "2026-07-15T12:18:18.993",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61438",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The workflow AST validator permits import and os.system constructs, allowing YAML script steps to escape the intended Python sandbox.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-26mh-57q7-jfvr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-broken-ast-sandbox",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 369,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61439",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:47.928Z",
      "date_published": "2026-07-11T13:01:03.106Z",
      "date_updated": "2026-07-14T14:31:26.402Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Prompt Injection Defense Bypass",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17619
      },
      "nvd": {
        "published": "2026-07-11T14:16:22.870",
        "lastModified": "2026-07-14T15:17:08.340",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61439",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The prompt-injection control defaults its block threshold to CRITICAL, so detections classified HIGH are logged and allowed to continue.",
        "basis": [
          "CNA",
          "CWE-1188"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-fj8f-m44g-c479",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-prompt-injection-defense-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 451,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61440",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:47.928Z",
      "date_published": "2026-07-15T11:25:41.736Z",
      "date_updated": "2026-07-18T01:01:50.264Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11735
      },
      "nvd": {
        "published": "2026-07-15T12:18:19.170",
        "lastModified": "2026-07-18T02:17:10.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61440",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PraisonAI lets ordinary workspace members mutate shared labels and owner issue-label associations without owner or administrator authorization.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-xxgv-vgvj-qvxh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-platform-before-authorization-bypass-via-label-endpoints",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 401,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61441",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:47.928Z",
      "date_published": "2026-07-10T13:58:06.970Z",
      "date_updated": "2026-07-10T14:52:53.935Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15117
      },
      "nvd": {
        "published": "2026-07-10T15:16:50.480",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61441",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The dependency-delete route authorizes only the caller-selected endpoint issue, allowing the same edge to be deleted through a related issue the caller owns.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-mxmx-rh57-jx58",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-platform-before-authorization-bypass-via-dependencies",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 623,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61442",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:47.928Z",
      "date_published": "2026-07-11T13:01:03.789Z",
      "date_updated": "2026-07-13T17:17:43.342Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17151
      },
      "nvd": {
        "published": "2026-07-11T14:16:23.017",
        "lastModified": "2026-07-13T18:16:29.513",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61442",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PATCH routes for projects, issues, and agents require only workspace membership and omit owner or administrator authorization before modifying owner-created records.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-c78w-2q4r-68r7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-platform-before-authorization-bypass-via-patch",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 411,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61443",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:47.928Z",
      "date_published": "2026-07-15T11:25:42.438Z",
      "date_updated": "2026-07-15T12:14:45.603Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 1.6.78 Remote Code Execution via SkillTools",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00499,
        "percentile": 0.40051
      },
      "nvd": {
        "published": "2026-07-15T12:18:19.467",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61443",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "run_skill_script accepts an absolute script path without containing it to the intended working directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-c44f-37qr-gw3f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-skilltools",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 318,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61444",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:47.929Z",
      "date_published": "2026-07-10T13:58:07.639Z",
      "date_updated": "2026-07-10T20:30:58.059Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Code Injection via f-string",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00392,
        "percentile": 0.31962
      },
      "nvd": {
        "published": "2026-07-10T15:16:50.610",
        "lastModified": "2026-07-10T21:17:00.530",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61444",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The deployment path interpolates agents_file into generated Python source, which is later executed by a subprocess.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-g6j7-pffp-8whg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-code-injection-via-f-string",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:05:47.929Z",
      "date_published": "2026-07-11T13:01:04.470Z",
      "date_updated": "2026-07-14T14:34:11.901Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 4.6.78 Arbitrary File Write and Command Execution",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00538,
        "percentile": 0.42289
      },
      "nvd": {
        "published": "2026-07-11T14:16:23.240",
        "lastModified": "2026-07-14T15:17:08.617",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61445",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "PraisonAI passes LLM-selected paths and command text into filesystem and shell-capable AICoder tools without validating path containment or neutralizing command syntax.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-9mp3-24cc-77mg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-arbitrary-file-write-and-command-execution",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 365,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61446",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:06:14.016Z",
      "date_published": "2026-07-15T11:25:43.130Z",
      "date_updated": "2026-07-15T13:25:26.252Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12699
      },
      "nvd": {
        "published": "2026-07-15T12:18:19.607",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61446",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The plugin manager automatically loads Python files from project and user search paths without signing, integrity verification, or sandboxing.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-m6wp-h223-4c8g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-plugin-auto-discovery",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 575,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61447",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:06:14.016Z",
      "date_published": "2026-07-11T13:01:05.162Z",
      "date_updated": "2026-07-13T15:21:34.593Z",
      "publisher": "VulnCheck",
      "title": "PraisonAI before 1.6.78 Remote Code Execution via CodeAgent",
      "affected": {
        "vendors": [
          "MervinPraison"
        ],
        "products": [
          {
            "vendor": "MervinPraison",
            "product": "PraisonAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00742,
        "percentile": 0.51134
      },
      "nvd": {
        "published": "2026-07-11T14:16:23.377",
        "lastModified": "2026-07-13T18:05:36.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61447",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CodeAgent executes LLM-generated Python without syntax restrictions or a sandbox, so prompt-controlled output becomes host code.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2xv2-w8cq-5gxw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-codeagent",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:06:14.016Z",
      "date_published": "2026-07-11T13:01:05.852Z",
      "date_updated": "2026-07-14T22:03:36.889Z",
      "publisher": "VulnCheck",
      "title": "Parse Server 9.0.0 Stored XSS via malformed Content-Type",
      "affected": {
        "vendors": [
          "parse-community"
        ],
        "products": [
          {
            "vendor": "parse-community",
            "product": "parse-server"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15763
      },
      "nvd": {
        "published": "2026-07-11T14:16:23.510",
        "lastModified": "2026-07-13T20:03:31.703",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61448",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An upload with a malformed Content-Type bypasses the extension blocklist and is stored as HTML that a browser later MIME-sniffs into executable content.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/parse-community/parse-server/security/advisories/GHSA-r899-h629-j84r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/parse-server-stored-xss-via-malformed-content-type",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 903,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61449",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:06:14.016Z",
      "date_published": "2026-07-15T11:25:43.802Z",
      "date_updated": "2026-07-15T17:52:57.760Z",
      "publisher": "VulnCheck",
      "title": "Grav before 2.0.2 Decompression Bomb via Forged ZIP Size",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16037
      },
      "nvd": {
        "published": "2026-07-15T12:18:19.747",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61449",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Grav trusts forgeable ZIP central-directory sizes when enforcing its uncompressed-size cap before extraction.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-8h9x-89f2-m7x3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-decompression-bomb-via-forged-zip-size",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 752,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61450",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:06:14.016Z",
      "date_published": "2026-07-10T13:58:08.307Z",
      "date_updated": "2026-07-10T15:46:20.929Z",
      "publisher": "VulnCheck",
      "title": "Grav before 2.0.2 Config Exfiltration via offsetGet Filter",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00246,
        "percentile": 0.1596
      },
      "nvd": {
        "published": "2026-07-10T15:16:50.740",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61450",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Grav's Twig sandbox allowlist permits a page author to traverse container offsets into configuration objects that should be outside sandbox authority.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-mc5q-6hpj-rp7j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-config-exfiltration-via-offsetget-filter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 755,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61451",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:06:14.016Z",
      "date_published": "2026-07-15T11:25:44.506Z",
      "date_updated": "2026-07-28T13:02:09.692Z",
      "publisher": "VulnCheck",
      "title": "Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15661
      },
      "nvd": {
        "published": "2026-07-15T12:18:19.897",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61451",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-5xc4-j99p-cp4m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-password-reset-token-poisoning-via-admin-base-url",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 717,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61452",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:06:14.017Z",
      "date_published": "2026-07-15T11:25:45.185Z",
      "date_updated": "2026-07-28T13:02:10.360Z",
      "publisher": "VulnCheck",
      "title": "Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00194,
        "percentile": 0.0937
      },
      "nvd": {
        "published": "2026-07-15T12:18:20.037",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61452",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-m8g9-wxhx-6f86",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-improper-session-invalidation-jwt-access-tokens",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 499,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61453",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:06:14.017Z",
      "date_published": "2026-07-15T11:25:45.830Z",
      "date_updated": "2026-07-15T17:59:04.551Z",
      "publisher": "VulnCheck",
      "title": "Grav before 2.0.1 XSS via Twig String Concatenation",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05133
      },
      "nvd": {
        "published": "2026-07-15T12:18:20.177",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61453",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The XSS validator scans raw Twig text before concatenation, while later rendering constructs active markup and emits it through a raw output sink.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-2c4f-86xc-cr74",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-xss-via-twig-string-concatenation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 758,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:06:14.017Z",
      "date_published": "2026-07-11T13:01:06.507Z",
      "date_updated": "2026-07-13T14:34:09.121Z",
      "publisher": "VulnCheck",
      "title": "Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 3.3999999999999995,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15068
      },
      "nvd": {
        "published": "2026-07-11T14:16:23.630",
        "lastModified": "2026-07-13T20:03:31.703",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61454",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The unauthenticated Admin2 bootstrap page embeds runtime, version, path and API details in a global JavaScript configuration object.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-pfjq-chp8-3vgh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-information-disclosure-via-grav-config",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 506,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61455",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:06:14.017Z",
      "date_published": "2026-07-10T13:58:08.990Z",
      "date_updated": "2026-07-10T14:49:27.015Z",
      "publisher": "VulnCheck",
      "title": "Grav before 2.0.1 Decompression Bomb via ZipArchiver",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16258
      },
      "nvd": {
        "published": "2026-07-10T15:16:50.877",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61455",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Archive extraction enforces no uncompressed-size, file-count, or nesting limit before consuming storage.",
        "basis": [
          "CNA",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-928x-9mpw-8h56",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-decompression-bomb-via-ziparchiver",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61456",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:07:55.624Z",
      "date_published": "2026-07-10T13:58:09.670Z",
      "date_updated": "2026-07-10T14:45:32.763Z",
      "publisher": "VulnCheck",
      "title": "Grav before 1.0.3 Stored XSS via SVG Upload API",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03899
      },
      "nvd": {
        "published": "2026-07-10T15:16:51.023",
        "lastModified": "2026-07-10T17:41:47.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61456",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The media endpoint checks only an SVG filename extension and skips SVG sanitization before serving active script inline.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-7vhm-8x52-2r5p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-stored-xss-via-svg-upload-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 639,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61457",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:07:55.624Z",
      "date_published": "2026-07-15T11:25:46.519Z",
      "date_updated": "2026-07-28T13:02:11.039Z",
      "publisher": "VulnCheck",
      "title": "Grav before 1.0.3 Remote Code Execution via File Upload Extension Bypass",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 3.500000000000001,
      "epss": {
        "score": 0.00464,
        "percentile": 0.37868
      },
      "nvd": {
        "published": "2026-07-15T12:18:20.480",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61457",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload validator checks only the final extension, allowing a double-extension file to be placed where the web server may execute it.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-66v2-vxxf-xc3v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-remote-code-execution-via-file-upload-extension-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:07:55.624Z",
      "date_published": "2026-07-13T21:30:07.937Z",
      "date_updated": "2026-07-14T22:03:37.558Z",
      "publisher": "VulnCheck",
      "title": "PasswordPusher < 2.9.2 Passphrase Brute-Force via Unthrottled Endpoint",
      "affected": {
        "vendors": [
          "pglombardo"
        ],
        "products": [
          {
            "vendor": "pglombardo",
            "product": "PasswordPusher"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22749
      },
      "nvd": {
        "published": "2026-07-13T22:16:49.177",
        "lastModified": "2026-07-15T21:02:13.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61458",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Passphrase authentication permits unlimited attempts without throttling or account lockout.",
        "basis": [
          "CNA",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-59w3-h5v2-c4xw",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/passwordpusher-passphrase-brute-force-via-unthrottled-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 407,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:07:55.624Z",
      "date_published": "2026-07-10T18:34:27.969Z",
      "date_updated": "2026-07-14T22:03:38.209Z",
      "publisher": "VulnCheck",
      "title": "MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools",
      "affected": {
        "vendors": [
          "Flux159"
        ],
        "products": [
          {
            "vendor": "Flux159",
            "product": "mcp-server-kubernetes"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00456,
        "percentile": 0.37334
      },
      "nvd": {
        "published": "2026-07-10T19:17:27.450",
        "lastModified": "2026-07-17T12:27:18.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61459",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Structured kubectl tools accept leading-dash resource values that become new command arguments and redirect kubectl to an attacker server.",
        "basis": [
          "CNA record",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Flux159/mcp-server-kubernetes/releases/tag/3.9.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/Flux159/mcp-server-kubernetes/issues/328",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/Flux159/mcp-server-kubernetes/pull/329",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/Flux159/mcp-server-kubernetes/commit/d7890f50a4567bf5d9842541ba6f41e180227f9a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/mcp-server-kubernetes-argument-injection-via-kubectl-structured-tools",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61460",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:07:55.624Z",
      "date_published": "2026-07-10T18:24:49.586Z",
      "date_updated": "2026-07-10T19:10:15.675Z",
      "publisher": "VulnCheck",
      "title": "Krayin CRM Insecure Direct Object Reference via Controllers",
      "affected": {
        "vendors": [
          "krayin"
        ],
        "products": [
          {
            "vendor": "krayin",
            "product": "laravel-crm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20214
      },
      "nvd": {
        "published": "2026-07-10T19:17:27.587",
        "lastModified": "2026-07-10T20:16:49.030",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61460",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "laravel-crm trusts an attacker-supplied object identifier without checking that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/krayin/laravel-crm/issues/2559",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/krayin/laravel-crm/pull/2567",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/krayin-crm-insecure-direct-object-reference-via-controllers",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61461",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:07:55.624Z",
      "date_published": "2026-07-10T18:10:35.462Z",
      "date_updated": "2026-07-14T22:03:38.857Z",
      "publisher": "VulnCheck",
      "title": "Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text",
      "affected": {
        "vendors": [
          "langgenius"
        ],
        "products": [
          {
            "vendor": "langgenius",
            "product": "dify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27858
      },
      "nvd": {
        "published": "2026-07-10T19:17:27.713",
        "lastModified": "2026-07-17T14:35:14.383",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61461",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dify's search_by_full_text inserts unsanitized search parameters into a MyScale SQL statement.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/langgenius/dify/releases/tag/1.16.0-rc1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/langgenius/dify/issues/38281",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/langgenius/dify/pull/38295",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/langgenius/dify/commit/d9884efaeea8322706e24c560d2c17e5bf3fab5f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dify-rc1-sql-injection-via-myscale-vector-store-search-by-full-text",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 395,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61462",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:07:55.624Z",
      "date_published": "2026-07-13T17:17:26.026Z",
      "date_updated": "2026-07-20T17:46:04.069Z",
      "publisher": "VulnCheck",
      "title": "mcp-gitlab Path Traversal via job_id Parameter",
      "affected": {
        "vendors": [
          "zereight"
        ],
        "products": [
          {
            "vendor": "zereight",
            "product": "mcp-gitlab"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0038,
        "percentile": 0.30776
      },
      "nvd": {
        "published": "2026-07-13T18:16:29.633",
        "lastModified": "2026-07-13T20:03:31.703",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61462",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mcp-gitlab joins an attacker-controlled job_id into a GitLab API path, allowing traversal to unrelated endpoints under the operator's token.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zereight/gitlab-mcp/issues/587",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/zereight/gitlab-mcp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/zereight/gitlab-mcp/commit/e2a81a047ab8750fa5bfa1763b5d85e5616f3994",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/mcp-gitlab-path-traversal-via-job-id-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 353,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61463",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:07:55.624Z",
      "date_published": "2026-07-13T17:22:59.313Z",
      "date_updated": "2026-07-20T17:46:04.746Z",
      "publisher": "VulnCheck",
      "title": "Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account",
      "affected": {
        "vendors": [
          "go-shiori"
        ],
        "products": [
          {
            "vendor": "go-shiori",
            "product": "shiori"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00368,
        "percentile": 0.29532
      },
      "nvd": {
        "published": "2026-07-13T18:16:29.770",
        "lastModified": "2026-07-13T19:49:37.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61463",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The account update endpoint accepts owner=true from an ordinary authenticated user without checking administrator authority.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/go-shiori/shiori/issues/1196",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/go-shiori/shiori",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/go-shiori/shiori/commit/6c8a7dbc11b131609bfda736b14d61c51f9027b2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/shiori-authenticated-privilege-escalation-via-patch-api-v1-auth-account",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 346,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61464",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:07:55.625Z",
      "date_published": "2026-07-15T11:25:47.202Z",
      "date_updated": "2026-07-15T13:25:15.287Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 1.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 1.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 1.8,
      "cvss_source_score_spread": 0.8,
      "epss": {
        "score": 0.00092,
        "percentile": 0.00616
      },
      "nvd": {
        "published": "2026-07-15T12:18:20.623",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61464",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick writes beyond a heap allocation when an X11 import processes a crafted window title.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-76q6-2p6h-xjqr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-heap-buffer-over-write-via-x11",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61465",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T14:07:55.625Z",
      "date_published": "2026-07-11T13:01:07.209Z",
      "date_updated": "2026-07-14T14:33:06.308Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 3.2,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06928
      },
      "nvd": {
        "published": "2026-07-11T14:16:23.767",
        "lastModified": "2026-07-14T15:17:09.260",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61465",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ImageMagick path allocates attacker-driven resources without an effective bound or throttle.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvhp-75f6-9jqh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-memory-allocation-policy-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61474",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-09T15:05:55.590Z",
      "date_published": "2026-07-09T15:06:00.805Z",
      "date_updated": "2026-07-09T16:08:18.550Z",
      "publisher": "CIRCL",
      "title": "MISP: Improper sharing group authorization check when adding attributes",
      "affected": {
        "vendors": [
          "misp"
        ],
        "products": [
          {
            "vendor": "misp",
            "product": "misp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15667
      },
      "nvd": {
        "published": "2026-07-09T16:16:49.250",
        "lastModified": "2026-07-09T17:17:04.483",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61474",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A protected action is executed without binding the caller's identity or role to the requested object and operation.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MISP/MISP/commit/df612166538e2979fae9f7eda88345ccc8fee761",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 812,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61487",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T12:48:59.563Z",
      "date_published": "2026-07-28T13:32:40.768Z",
      "date_updated": "2026-07-28T14:07:13.139Z",
      "publisher": "apache",
      "title": "Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache ActiveMQ Broker"
          },
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache ActiveMQ All"
          },
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache ActiveMQ"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29787
      },
      "nvd": {
        "published": "2026-07-28T14:16:38.453",
        "lastModified": "2026-07-28T16:20:53.010",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61487",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Apache ActiveMQ Broker operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/6rwn6cq65dy4lhmsmjf2bxnhbmhkcswz",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/27/8",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 808,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-61492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T13:56:26.656Z",
      "date_published": "2026-07-10T14:19:00.074Z",
      "date_updated": "2026-07-10T16:59:33.210Z",
      "publisher": "JetBrains",
      "title": "In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "YouTrack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00391,
        "percentile": 0.31825
      },
      "nvd": {
        "published": "2026-07-10T15:16:51.153",
        "lastModified": "2026-07-10T18:57:39.147",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61492",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "YouTrack renders attacker-controlled email content as executable browser markup without the required context encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61498",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T15:43:36.625Z",
      "date_published": "2026-07-13T13:12:36.552Z",
      "date_updated": "2026-07-28T01:49:51.768Z",
      "publisher": "VulnCheck",
      "title": "Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php",
      "affected": {
        "vendors": [
          "VITEC"
        ],
        "products": [
          {
            "vendor": "VITEC",
            "product": "Flamingo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.02188,
        "percentile": 0.80654
      },
      "nvd": {
        "published": "2026-07-13T14:16:32.213",
        "lastModified": "2026-07-14T15:17:09.390",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61498",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having passwordless sudo access.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://damiri.fr/en/cve/CVE-2026-61498",
          "host": "damiri.fr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vitec.com/solutions/iptv-distribution",
          "host": "www.vitec.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/vitec-flamingo-unauthenticated-os-command-injection-via-gen-graphs-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61500",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T15:43:36.625Z",
      "date_published": "2026-07-13T17:21:55.747Z",
      "date_updated": "2026-07-15T14:14:33.696Z",
      "publisher": "VulnCheck",
      "title": "Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key",
      "affected": {
        "vendors": [
          "rejetto"
        ],
        "products": [
          {
            "vendor": "rejetto",
            "product": "hfs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00747,
        "percentile": 0.51323
      },
      "nvd": {
        "published": "2026-07-13T18:16:29.903",
        "lastModified": "2026-07-15T15:16:47.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61500",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HFS derives its session signing key from recoverable Math.random output that is also exposed during login.",
        "basis": [
          "CNA",
          "CWE-338"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rejetto/hfs/releases/tag/v3.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rejetto-hfs-session-forgery-via-predictable-signing-key",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 486,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T15:43:36.625Z",
      "date_published": "2026-07-13T17:22:39.316Z",
      "date_updated": "2026-07-14T22:03:40.215Z",
      "publisher": "VulnCheck",
      "title": "Rejetto HFS < 3.2.1 Stored XSS in Admin Log Viewer",
      "affected": {
        "vendors": [
          "rejetto"
        ],
        "products": [
          {
            "vendor": "rejetto",
            "product": "hfs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00308,
        "percentile": 0.23182
      },
      "nvd": {
        "published": "2026-07-13T18:16:30.043",
        "lastModified": "2026-07-14T23:17:36.550",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61501",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rejetto/hfs/releases/tag/v3.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rejetto-hfs-stored-xss-in-admin-log-viewer",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 414,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61502",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T15:43:36.625Z",
      "date_published": "2026-07-13T17:22:59.734Z",
      "date_updated": "2026-07-14T22:03:40.884Z",
      "publisher": "VulnCheck",
      "title": "Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests",
      "affected": {
        "vendors": [
          "rejetto"
        ],
        "products": [
          {
            "vendor": "rejetto",
            "product": "hfs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00182,
        "percentile": 0.07992
      },
      "nvd": {
        "published": "2026-07-13T18:16:30.173",
        "lastModified": "2026-07-14T23:17:36.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61502",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Rejetto HFS permits state-changing API calls through GET and exempts GET requests from its anti-CSRF header check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rejetto/hfs/releases/tag/v3.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rejetto-hfs-cross-site-request-forgery-via-get-requests",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 470,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61503",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T15:43:36.626Z",
      "date_published": "2026-07-13T17:23:20.688Z",
      "date_updated": "2026-07-15T19:07:20.991Z",
      "publisher": "VulnCheck",
      "title": "Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences",
      "affected": {
        "vendors": [
          "rejetto"
        ],
        "products": [
          {
            "vendor": "rejetto",
            "product": "hfs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-204",
          "name": "Observable Response Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26972
      },
      "nvd": {
        "published": "2026-07-13T18:16:30.307",
        "lastModified": "2026-07-15T19:18:36.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61503",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The login response varies according to whether the submitted username exists, creating a remotely observable account-enumeration oracle.",
        "basis": [
          "CNA",
          "CWE-204"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rejetto/hfs/releases/tag/v3.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rejetto-hfs-username-enumeration-via-login-response-differences",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61504",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T15:43:36.626Z",
      "date_published": "2026-07-13T17:23:40.045Z",
      "date_updated": "2026-07-14T22:03:42.271Z",
      "publisher": "VulnCheck",
      "title": "Rejetto HFS < 3.2.1 Stored XSS via File Names in Basic Web Listing",
      "affected": {
        "vendors": [
          "rejetto"
        ],
        "products": [
          {
            "vendor": "rejetto",
            "product": "hfs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06933
      },
      "nvd": {
        "published": "2026-07-13T18:16:30.437",
        "lastModified": "2026-07-14T23:17:36.907",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61504",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches hfs page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rejetto/hfs/releases/tag/v3.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rejetto-hfs-stored-xss-via-file-names-in-basic-web-listing",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 368,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61505",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T15:43:36.626Z",
      "date_published": "2026-07-13T17:23:58.901Z",
      "date_updated": "2026-07-14T22:03:42.947Z",
      "publisher": "VulnCheck",
      "title": "Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter",
      "affected": {
        "vendors": [
          "rejetto"
        ],
        "products": [
          {
            "vendor": "rejetto",
            "product": "hfs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00452,
        "percentile": 0.3705
      },
      "nvd": {
        "published": "2026-07-13T18:16:30.563",
        "lastModified": "2026-07-14T23:17:37.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61505",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The lang parameter accepts traversal segments and selects JSON files outside HFS shared folders.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rejetto/hfs/releases/tag/v3.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rejetto-hfs-limited-file-disclosure-via-path-traversal-in-lang-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 296,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61511",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T15:43:36.627Z",
      "date_published": "2026-07-27T12:39:16.085Z",
      "date_updated": "2026-07-29T19:26:41.811Z",
      "publisher": "VulnCheck",
      "title": "vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php",
      "affected": {
        "vendors": [
          "vBulletin"
        ],
        "products": [
          {
            "vendor": "vBulletin",
            "product": "vBulletin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-95",
          "name": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.01274,
        "percentile": 0.67048
      },
      "nvd": {
        "published": "2026-07-27T14:16:59.177",
        "lastModified": "2026-07-29T20:17:10.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61511",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "vBulletin's runMaths filter admits a restricted-character encoding that reaches eval as attacker-controlled PHP code.",
        "basis": [
          "CNA",
          "CWE-95"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://karmainsecurity.com/KIS-2026-13",
          "host": "karmainsecurity.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/",
          "host": "ssd-disclosure.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509358-security-patch-released-for-vbulletin-6-2-1-6-2-0-and-6-1-6",
          "host": "forum.vbulletin.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4509404-vbulletin-6-2-2-is-available",
          "host": "forum.vbulletin.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.vulncheck.com/advisories/vbulletin-eval-injection-rce-via-vb5-template-runtime-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 554,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-61520",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T15:43:36.628Z",
      "date_published": "2026-07-14T20:17:15.901Z",
      "date_updated": "2026-07-28T01:49:53.198Z",
      "publisher": "VulnCheck",
      "title": "Simple Machines Forum SSRF via image proxy",
      "affected": {
        "vendors": [
          "SimpleMachines"
        ],
        "products": [
          {
            "vendor": "SimpleMachines",
            "product": "SMF"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16525
      },
      "nvd": {
        "published": "2026-07-14T21:17:06.290",
        "lastModified": "2026-07-15T21:02:41.590",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61520",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The image proxy fetches signed attacker-selected URLs without checking resolved addresses for loopback, private, link-local, or metadata destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/SimpleMachines/SMF/commit/4bf35cf9e45573a5f55a6f52995086c1da89c096",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/SimpleMachines/SMF/commit/b4d23dfd74a511587c605f9d294cefc3a75b4b26",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/simple-machines-forum-ssrf-via-image-proxy",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 678,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61526",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T16:27:03.092Z",
      "date_published": "2026-07-30T20:55:43.406Z",
      "date_updated": "2026-07-31T19:20:48.817Z",
      "publisher": "GitHub_M",
      "title": "AdonisJS HTTP Server is vulnerable to reflected XSS through its exception handler",
      "affected": {
        "vendors": [
          "adonisjs"
        ],
        "products": [
          {
            "vendor": "adonisjs",
            "product": "http-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.093
      },
      "nvd": {
        "published": "2026-07-30T21:18:12.030",
        "lastModified": "2026-07-31T20:16:52.970",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61526",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The http-server page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/adonisjs/http-server/security/advisories/GHSA-cwm9-gfhc-46f6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/adonisjs/http-server/commit/5d7465d599753b1fce8a36da18955f2c273e4f87",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/adonisjs/http-server/commit/71a0a8e375c375e3588ba44ef68b0ef5a993c3d3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/adonisjs/http-server/releases/tag/v8.2.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/adonisjs/http-server/releases/tag/v9.1.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 616,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T16:27:03.093Z",
      "date_published": "2026-07-30T16:50:01.730Z",
      "date_updated": "2026-07-31T23:01:03.395Z",
      "publisher": "GitHub_M",
      "title": "Banks: Unsafe importlib.import_module of attacker-controlled Tool.import_path in CompletionExtension allows RCE",
      "affected": {
        "vendors": [
          "masci"
        ],
        "products": [
          {
            "vendor": "masci",
            "product": "banks"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22272
      },
      "nvd": {
        "published": "2026-07-30T19:18:34.553",
        "lastModified": "2026-07-31T23:17:25.930",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61536",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Banks resolves an attacker-supplied import_path to any importable Python callable and invokes it with model-supplied arguments.",
        "basis": [
          "CNA",
          "CWE-94",
          "CWE-470"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/masci/banks/security/advisories/GHSA-64vx-6h2c-rjh7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1191,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61609",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T17:36:04.597Z",
      "date_published": "2026-07-28T15:45:57.570Z",
      "date_updated": "2026-07-28T19:28:14.470Z",
      "publisher": "GitHub_M",
      "title": "Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)",
      "affected": {
        "vendors": [
          "pterodactyl"
        ],
        "products": [
          {
            "vendor": "pterodactyl",
            "product": "panel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00394,
        "percentile": 0.32143
      },
      "nvd": {
        "published": "2026-07-28T16:19:28.693",
        "lastModified": "2026-07-30T19:29:19.027",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61609",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The login and two-factor endpoints share one global rate-limit key, so a few unauthenticated requests consume the bucket for every user.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pterodactyl/panel/security/advisories/GHSA-xvc3-826v-xf47",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/pterodactyl/panel/commit/98079a01660a61980fe62a72b2c1d48f99c35a5e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/pterodactyl/panel/releases/tag/v1.13.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 896,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61613",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T17:36:04.598Z",
      "date_published": "2026-07-15T14:18:23.635Z",
      "date_updated": "2026-07-21T14:04:46.303Z",
      "publisher": "GitHub_M",
      "title": "Cursor: Cloud Agent Browser Sandbox Escape",
      "affected": {
        "vendors": [
          "cursor"
        ],
        "products": [
          {
            "vendor": "cursor",
            "product": "cursor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31525
      },
      "nvd": {
        "published": "2026-07-15T15:16:47.700",
        "lastModified": "2026-07-21T15:16:38.030",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61613",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "cursor exposes the affected function without establishing the authentication identity required to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cursor/cursor/security/advisories/GHSA-whx2-4gvm-m3r3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 574,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61643",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T17:38:57.112Z",
      "date_published": "2026-07-15T17:03:22.325Z",
      "date_updated": "2026-07-20T14:32:04.031Z",
      "publisher": "GitHub_M",
      "title": "FastGPT: workflow runtime can execute another user's private HTTP toolset",
      "affected": {
        "vendors": [
          "labring"
        ],
        "products": [
          {
            "vendor": "labring",
            "product": "FastGPT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05108
      },
      "nvd": {
        "published": "2026-07-15T18:16:49.510",
        "lastModified": "2026-07-20T16:17:06.297",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61643",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The workflow save and runtime paths resolve another user's private HTTP tool identifier without applying the ownership check used by normal tool routes.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/labring/FastGPT/security/advisories/GHSA-93r3-wqq3-c5ch",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/releases/tag/v4.15.0-beta5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61644",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T17:38:57.112Z",
      "date_published": "2026-07-15T14:30:26.693Z",
      "date_updated": "2026-07-15T16:32:44.414Z",
      "publisher": "GitHub_M",
      "title": "FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an unbound initialId lookup",
      "affected": {
        "vendors": [
          "labring"
        ],
        "products": [
          {
            "vendor": "labring",
            "product": "FastGPT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15604
      },
      "nvd": {
        "published": "2026-07-15T15:16:47.833",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61644",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "FastGPT authorizes the surrounding chat and collection but looks up initialId without binding it to that tenant context.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/labring/FastGPT/security/advisories/GHSA-mmg6-2g54-j896",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/pull/7173",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/commit/0c1840c7773c5be5d777f86228651479e02155db",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/releases/tag/v4.15.0-beta5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 595,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61646",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T17:38:57.112Z",
      "date_published": "2026-07-15T14:32:08.767Z",
      "date_updated": "2026-07-15T17:43:36.851Z",
      "publisher": "GitHub_M",
      "title": "FastGPT: Shared axios SSRF guard validates only the initial URL before following redirects",
      "affected": {
        "vendors": [
          "labring"
        ],
        "products": [
          {
            "vendor": "labring",
            "product": "FastGPT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16218
      },
      "nvd": {
        "published": "2026-07-15T15:16:47.973",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61646",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server validates only the initial URL and lets axios follow a redirect to an internal destination.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/labring/FastGPT/security/advisories/GHSA-g969-67mv-2qxq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/releases/tag/v4.15.0-beta5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T18:36:58.849Z",
      "date_published": "2026-07-15T14:28:22.480Z",
      "date_updated": "2026-07-15T15:07:19.325Z",
      "publisher": "GitHub_M",
      "title": "FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')",
      "affected": {
        "vendors": [
          "labring"
        ],
        "products": [
          {
            "vendor": "labring",
            "product": "FastGPT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21733
      },
      "nvd": {
        "published": "2026-07-15T15:16:48.100",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61684",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FastGPT signs plugin-invoke JWTs with a constant default secret omitted from official deployment templates.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/labring/FastGPT/security/advisories/GHSA-w732-rq8c-chc8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/pull/7170",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/commit/f5f1e58b25571b7107ca49d9bf96bb2b0e0a620a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/labring/FastGPT/releases/tag/v4.15.0-beta5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 579,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61718",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T18:51:13.920Z",
      "date_published": "2026-07-16T19:15:39.183Z",
      "date_updated": "2026-07-17T18:06:41.071Z",
      "publisher": "GitHub_M",
      "title": "bunkerweb: Read-only Web UI users can delete job cache files due to missing authorization on /cache/ routes",
      "affected": {
        "vendors": [
          "bunkerity"
        ],
        "products": [
          {
            "vendor": "bunkerity",
            "product": "bunkerweb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00306,
        "percentile": 0.22962
      },
      "nvd": {
        "published": "2026-07-16T20:16:46.420",
        "lastModified": "2026-07-17T19:17:17.670",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61718",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "BunkerWeb's authorization-bypass list includes the /cache/ prefix and skips the normal permission check for protected cache routes.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/bunkerity/bunkerweb/security/advisories/GHSA-q7rm-935c-v39g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/bunkerity/bunkerweb/commit/685ccbbe7d204132a843a7b7fd802d1bdb3f20a9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/bunkerity/bunkerweb/releases/tag/v1.6.12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61736",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T18:59:00.047Z",
      "date_published": "2026-07-15T14:12:45.960Z",
      "date_updated": "2026-07-15T14:59:40.255Z",
      "publisher": "GitHub_M",
      "title": "LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests",
      "affected": {
        "vendors": [
          "HKUDS"
        ],
        "products": [
          {
            "vendor": "HKUDS",
            "product": "LightRAG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-942",
          "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22845
      },
      "nvd": {
        "published": "2026-07-15T15:16:48.217",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61736",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LightRAG combines a wildcard CORS origin with credentialed requests, allowing any visited origin to invoke the authenticated API.",
        "basis": [
          "CNA",
          "CWE-942"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/HKUDS/LightRAG/security/advisories/GHSA-6x6h-qqr7-855w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/HKUDS/LightRAG/pull/3317",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/HKUDS/LightRAG/commit/09567a4c983f580050db63569dd477122c058c3d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/HKUDS/LightRAG/commit/df68d75f9dc29dd340ffb6794b48f48c4fdc9a2d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/HKUDS/LightRAG/commit/ebba6548639c0f2e8919100eff76b401f1222252",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/HKUDS/LightRAG/releases/tag/v1.5.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61740",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T18:59:00.047Z",
      "date_published": "2026-07-15T14:14:41.064Z",
      "date_updated": "2026-07-15T15:30:39.185Z",
      "publisher": "GitHub_M",
      "title": "LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection",
      "affected": {
        "vendors": [
          "HKUDS"
        ],
        "products": [
          {
            "vendor": "HKUDS",
            "product": "LightRAG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00402,
        "percentile": 0.3304
      },
      "nvd": {
        "published": "2026-07-15T15:16:48.350",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61740",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed because lightrag/api/auth.py falls back to a hardcoded DEFAULT_TOKEN_SECRET, /auth-status and /login can mint guest JWTs, and combined_dependency in lightrag/api/utils_api.py accepts a valid guest token before checking the API key.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/HKUDS/LightRAG/security/advisories/GHSA-f4vv-55c2-5789",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/HKUDS/LightRAG/pull/3319",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/HKUDS/LightRAG/commit/f7819aa3a49a9d8d92eed8251d82d6ebcafa8cba",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/HKUDS/LightRAG/releases/tag/v1.5.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 624,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61828",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T20:17:57.993Z",
      "date_published": "2026-07-15T14:52:35.212Z",
      "date_updated": "2026-07-15T16:32:36.992Z",
      "publisher": "GitHub_M",
      "title": "nixos/mysql : `services.mysql` is configured with insecure authentication by default when used with `mysql` or `percona-server`",
      "affected": {
        "vendors": [
          "NixOS"
        ],
        "products": [
          {
            "vendor": "NixOS",
            "product": "nixpkgs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-276",
          "name": "Incorrect Default Permissions",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01325
      },
      "nvd": {
        "published": "2026-07-15T16:16:50.800",
        "lastModified": "2026-07-15T20:49:41.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61828",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The NixOS MySQL initialization default permits local users to authenticate as database root without a password.",
        "basis": [
          "CNA",
          "CWE-276"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/NixOS/nixpkgs/security/advisories/GHSA-6qxx-6rg8-c4p8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/NixOS/nixpkgs/pull/534254",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/NixOS/nixpkgs/pull/534482",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/NixOS/nixpkgs/pull/534484",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/NixOS/nixpkgs/commit/3f68d7ad2a6865ff8b4910d89f173d7258bad8dd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/NixOS/nixpkgs/commit/4aed47116a8734922763cd8f477467b0a0bcd6d7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/NixOS/nixpkgs/commit/f8ee41468a7a8f9ed3a8cc7d017151c2ca6f90b5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61835",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T20:28:17.511Z",
      "date_published": "2026-07-15T14:16:11.524Z",
      "date_updated": "2026-07-21T14:07:42.434Z",
      "publisher": "GitHub_M",
      "title": "Directus: SSRF Protection Bypass via 0.0.0.0 in File Import",
      "affected": {
        "vendors": [
          "directus"
        ],
        "products": [
          {
            "vendor": "directus",
            "product": "directus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14386
      },
      "nvd": {
        "published": "2026-07-15T15:16:48.470",
        "lastModified": "2026-07-28T15:47:21.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61835",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Directus omits the literal 0.0.0.0 address from its SSRF deny logic even though that address reaches localhost on supported hosts.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/directus/directus/security/advisories/GHSA-j5h6-vqc3-phqh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/directus/directus/pull/27606",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/directus/directus/commit/f75b25fa44b05c6022b20f231c20bc6e50f021d7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/directus/directus/releases/tag/v12.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 614,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61836",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T20:28:17.511Z",
      "date_published": "2026-07-15T14:17:21.034Z",
      "date_updated": "2026-07-15T16:32:52.619Z",
      "publisher": "GitHub_M",
      "title": "Directus: Authorization-dependent response served from unsegmented cache key",
      "affected": {
        "vendors": [
          "directus"
        ],
        "products": [
          {
            "vendor": "directus",
            "product": "directus"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-524",
          "name": "Use of Cache Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19384
      },
      "nvd": {
        "published": "2026-07-15T15:16:48.603",
        "lastModified": "2026-07-28T15:46:30.503",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61836",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The response cache key omits role, policy, share, and administrator context, so a response filtered for one authority can be served to another.",
        "basis": [
          "CNA",
          "CWE-524",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/directus/directus/security/advisories/GHSA-c6w9-5g5j-jh2p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/directus/directus/pull/27707",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/directus/directus/commit/7ba4efb97525d3af33570537c76e44baea767f13",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/directus/directus/releases/tag/v12.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 604,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61857",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:53:55.768Z",
      "date_published": "2026-07-11T13:01:07.926Z",
      "date_updated": "2026-07-13T17:09:23.626Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-252",
          "name": "Unchecked Return Value",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18315
      },
      "nvd": {
        "published": "2026-07-11T14:16:23.893",
        "lastModified": "2026-07-13T22:11:46.303",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61857",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The XMP parser omits a required null check and later accesses the resulting freed heap object.",
        "basis": [
          "CNA",
          "CWE-252"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh5g-q395-cx4j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-heap-use-after-free-via-xmp",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61858",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:53:55.768Z",
      "date_published": "2026-07-11T13:01:08.621Z",
      "date_updated": "2026-07-14T14:34:06.527Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15958
      },
      "nvd": {
        "published": "2026-07-11T14:16:24.020",
        "lastModified": "2026-07-14T15:17:09.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61858",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The APNG encoder bypasses path policy and follows an attacker-influenced file target into a disallowed location.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v3j6-27vc-7pw2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-policy-bypass-via-apng-encoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61859",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:53:55.769Z",
      "date_published": "2026-07-15T11:25:47.918Z",
      "date_updated": "2026-07-15T17:56:16.565Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Policy Bypass via script operation",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02543
      },
      "nvd": {
        "published": "2026-07-15T12:18:20.780",
        "lastModified": "2026-07-16T20:01:34.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61859",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The -script option bypasses the file policy checks and selects a file outside the permitted namespace.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-policy-bypass-via-script-operation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61860",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:53:55.769Z",
      "date_published": "2026-07-15T11:25:48.586Z",
      "date_updated": "2026-07-15T12:22:16.832Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Use-After-Free via freetype",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12805
      },
      "nvd": {
        "published": "2026-07-15T12:18:20.937",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61860",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "When FreeType initialization fails, image processing continues with memory that the failure path already freed.",
        "basis": [
          "CNA record",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6jwg-7q3p-5fqm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-use-after-free-via-freetype",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61861",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:53:55.769Z",
      "date_published": "2026-07-11T13:01:09.306Z",
      "date_updated": "2026-07-13T15:07:54.308Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 3.8,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24813
      },
      "nvd": {
        "published": "2026-07-11T14:16:24.143",
        "lastModified": "2026-07-13T22:09:54.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61861",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qvxh-prvr-85w2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-use-after-free-in-formatmagickcaption",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61862",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:53:55.769Z",
      "date_published": "2026-07-15T11:25:49.276Z",
      "date_updated": "2026-07-15T13:51:41.638Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Information Disclosure via identify",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.9,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01236
      },
      "nvd": {
        "published": "2026-07-15T12:18:21.080",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61862",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick identify reads one byte beyond a nonprintable profile buffer when debug output is enabled.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-information-disclosure-via-identify",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61863",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:53:55.769Z",
      "date_published": "2026-07-15T11:25:49.962Z",
      "date_updated": "2026-07-15T17:42:28.945Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 5.4,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08599
      },
      "nvd": {
        "published": "2026-07-15T12:18:21.233",
        "lastModified": "2026-07-16T20:01:21.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61863",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick's TIFF error path fails to release encoder memory when temporary-file creation fails, allowing repeated failures to accumulate allocations.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6vxp-gfwf-hcr9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-in-tiff-encoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 184,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61864",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:53:55.769Z",
      "date_published": "2026-07-15T11:25:50.648Z",
      "date_updated": "2026-07-15T12:09:45.303Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in Log Colorspace",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.9,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00102,
        "percentile": 0.01104
      },
      "nvd": {
        "published": "2026-07-15T12:18:21.383",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61864",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An error path fails to release allocated memory after its effective lifetime, leaking memory on each trigger.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7c7m-fpjw-gwcq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-in-log-colorspace",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 179,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61865",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:53:55.769Z",
      "date_published": "2026-07-15T11:25:51.311Z",
      "date_updated": "2026-07-15T13:25:02.727Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in Hough Lines",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.9,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00102,
        "percentile": 0.01104
      },
      "nvd": {
        "published": "2026-07-15T12:18:21.533",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61865",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Hough-lines failure path omits release of an allocated memory object, leaking memory on each failed operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j8rh-v2r8-v94x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-in-hough-lines",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 155,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61866",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:53:55.769Z",
      "date_published": "2026-07-15T11:25:51.999Z",
      "date_updated": "2026-07-15T17:54:18.204Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in JNG encoder",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 5.4,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08599
      },
      "nvd": {
        "published": "2026-07-15T12:18:21.673",
        "lastModified": "2026-07-16T03:01:45.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61866",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ImageMagick error or repeat path acquires memory without releasing it, allowing attacker-driven resource exhaustion.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-99w9-hv66-rfv7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-in-jng-encoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61867",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:54:26.759Z",
      "date_published": "2026-07-15T11:25:52.678Z",
      "date_updated": "2026-07-15T12:21:43.606Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.9,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00102,
        "percentile": 0.01104
      },
      "nvd": {
        "published": "2026-07-15T12:18:21.817",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61867",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A bounds or lifetime error permits an invalid memory access.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jfq9-q63x-rc63",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-in-tiff-encoder-2",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61868",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:54:26.759Z",
      "date_published": "2026-07-15T11:25:53.358Z",
      "date_updated": "2026-07-15T13:51:10.322Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in YUV Decoder",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12804
      },
      "nvd": {
        "published": "2026-07-15T12:18:21.953",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61868",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ImageMagick error path fails to release allocated memory, allowing repeated inputs to exhaust the process.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h7f2-f9cc-h2gv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-in-yuv-decoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61869",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:54:26.759Z",
      "date_published": "2026-07-15T11:25:54.057Z",
      "date_updated": "2026-07-15T18:03:42.319Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in MIFF Encoder",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.9,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00102,
        "percentile": 0.01104
      },
      "nvd": {
        "published": "2026-07-15T12:18:22.093",
        "lastModified": "2026-07-15T19:18:36.430",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61869",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick fails to release an allocation after an allocation-failure path ends its effective use.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r628-69v2-2f9c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-in-miff-encoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61870",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:54:26.760Z",
      "date_published": "2026-07-11T13:01:09.995Z",
      "date_updated": "2026-07-13T16:09:19.684Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.9,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 5.4,
      "epss": {
        "score": 0.00191,
        "percentile": 0.09042
      },
      "nvd": {
        "published": "2026-07-11T14:16:24.270",
        "lastModified": "2026-07-13T22:07:31.147",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-61870",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m596-67p7-69wh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-via-viff-encoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Broken Link",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61871",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:54:26.760Z",
      "date_published": "2026-07-15T11:25:54.748Z",
      "date_updated": "2026-07-15T12:04:51.151Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in ICON decoder",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14097
      },
      "nvd": {
        "published": "2026-07-15T12:18:22.233",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61871",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h58x-r7f7-rh84",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-in-icon-decoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61872",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:54:26.760Z",
      "date_published": "2026-07-15T11:25:55.435Z",
      "date_updated": "2026-07-15T13:24:51.572Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-26 Memory Leak via TIFF Encoder",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 2.5,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00096,
        "percentile": 0.00833
      },
      "nvd": {
        "published": "2026-07-15T12:18:22.380",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61872",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected operation lets attacker-controlled work or allocation grow without an effective per-request bound or termination condition.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h5r4-w88w-7ccr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-via-tiff-encoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 270,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-61873",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:54:26.760Z",
      "date_published": "2026-07-15T11:25:56.100Z",
      "date_updated": "2026-07-28T13:02:11.740Z",
      "publisher": "VulnCheck",
      "title": "Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00256,
        "percentile": 0.1712
      },
      "nvd": {
        "published": "2026-07-15T12:18:22.533",
        "lastModified": "2026-07-15T19:50:11.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61873",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Grav validates a path before rendering it through Twig but does not revalidate the transformed path before selecting the final filesystem target.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-q532-mvx7-42qg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-arbitrary-file-write-via-twig-processed-filename",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 444,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61874",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:54:26.760Z",
      "date_published": "2026-07-12T12:06:36.293Z",
      "date_updated": "2026-07-14T22:03:44.276Z",
      "publisher": "VulnCheck",
      "title": "filebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete",
      "affected": {
        "vendors": [
          "filebrowser"
        ],
        "products": [
          {
            "vendor": "filebrowser",
            "product": "filebrowser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0.8000000000000003,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09792
      },
      "nvd": {
        "published": "2026-07-12T12:16:46.117",
        "lastModified": "2026-07-13T20:03:31.703",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61874",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DeleteWithPathPrefix queries the share index before normalizing a trailing-slash path, so delete and recreate can leave a stale public share bound to new content.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-pp88-jhwj-5qh5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/filebrowser/filebrowser/commit/be23ab3a15bf957928ecfed88de5ab67850c1b9c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/filebrowser-before-stale-public-share-via-trailing-slash-delete",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61875",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:54:26.760Z",
      "date_published": "2026-07-12T12:06:36.956Z",
      "date_updated": "2026-07-14T22:03:44.956Z",
      "publisher": "VulnCheck",
      "title": "luci-app-upnp Stored XSS via UPnP Port Mapping Description",
      "affected": {
        "vendors": [
          "openwrt"
        ],
        "products": [
          {
            "vendor": "openwrt",
            "product": "luci"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21165
      },
      "nvd": {
        "published": "2026-07-12T12:16:46.260",
        "lastModified": "2026-07-13T19:28:49.830",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61875",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches luci page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openwrt/luci/security/advisories/GHSA-8v49-6387-7f89",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/luci-app-upnp-stored-xss-via-upnp-port-mapping-description",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-61876",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-10T21:54:26.760Z",
      "date_published": "2026-07-12T12:07:55.788Z",
      "date_updated": "2026-07-14T22:03:45.641Z",
      "publisher": "VulnCheck",
      "title": "LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting",
      "affected": {
        "vendors": [
          "openwrt"
        ],
        "products": [
          {
            "vendor": "openwrt",
            "product": "luci"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.002,
        "percentile": 0.10116
      },
      "nvd": {
        "published": "2026-07-12T12:16:46.400",
        "lastModified": "2026-07-14T15:17:09.767",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61876",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LuCI renders an attacker-controlled DHCPv6 Client FQDN in the lease table without HTML encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openwrt/luci/security/advisories/GHSA-686p-p8p9-x6fh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/luci-dhcpv6-lease-hostname-stored-cross-site-scripting",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-61884",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T18:17:10.040Z",
      "date_published": "2026-07-24T21:40:40.449Z",
      "date_updated": "2026-07-27T14:33:00.776Z",
      "publisher": "icscert",
      "title": "Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel",
      "affected": {
        "vendors": [
          "Tycon Systems"
        ],
        "products": [
          {
            "vendor": "Tycon Systems",
            "product": "TPDIN-Monitor-WEB2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-288",
          "name": "Authentication Bypass Using an Alternate Path or Channel",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00664,
        "percentile": 0.48198
      },
      "nvd": {
        "published": "2026-07-24T22:16:50.963",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61884",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The device login accepts empty username and password fields as valid credentials and creates an administrative session.",
        "basis": [
          "CNA",
          "CWE-288"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tyconsystems.com/contact",
          "host": "www.tyconsystems.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-01.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 575,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61886",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T16:04:55.182Z",
      "date_published": "2026-07-24T22:10:03.065Z",
      "date_updated": "2026-07-27T14:32:07.257Z",
      "publisher": "icscert",
      "title": "Weintek cMT3092X Plaintext Storage of a Password",
      "affected": {
        "vendors": [
          "Weintek"
        ],
        "products": [
          {
            "vendor": "Weintek",
            "product": "cMT3092X firmware"
          },
          {
            "vendor": "Weintek",
            "product": "EasyWeb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-256",
          "name": "Plaintext Storage of a Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13986
      },
      "nvd": {
        "published": "2026-07-24T23:16:51.197",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61886",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HMI stores user account passwords as plaintext instead of a one-way password verifier.",
        "basis": [
          "CNA",
          "CWE-256"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf",
          "host": "dl.weintek.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-03.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 64,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-61892",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T16:04:55.185Z",
      "date_published": "2026-07-24T22:16:58.155Z",
      "date_updated": "2026-07-27T14:31:09.468Z",
      "publisher": "icscert",
      "title": "Weintek cMT3092X Incorrect Permission Assignment for Critical Resource",
      "affected": {
        "vendors": [
          "Weintek"
        ],
        "products": [
          {
            "vendor": "Weintek",
            "product": "cMT3092X firmware"
          },
          {
            "vendor": "Weintek",
            "product": "EasyWeb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00274,
        "percentile": 0.1957
      },
      "nvd": {
        "published": "2026-07-24T23:16:51.333",
        "lastModified": "2026-07-30T14:12:18.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61892",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The HMI accepts attacker-modified authorization tokens without preserving the integrity of their privilege claims.",
        "basis": [
          "CNA",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf",
          "host": "dl.weintek.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-03.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 90,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-61893",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T22:10:53.022Z",
      "date_published": "2026-07-30T22:58:32.226Z",
      "date_updated": "2026-07-31T16:00:07.592Z",
      "publisher": "icscert",
      "title": "MZ Automation lib60870 Out-of-bounds Read",
      "affected": {
        "vendors": [
          "MZ Automation"
        ],
        "products": [
          {
            "vendor": "MZ Automation",
            "product": "lib60870"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18089
      },
      "nvd": {
        "published": "2026-07-30T23:16:51.760",
        "lastModified": "2026-07-31T16:17:08.637",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61893",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TestCommand_getFromBuffer trusts an inflated object count and reads one byte beyond the message heap buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-11.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-61900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T05:35:55.728Z",
      "date_published": "2026-07-20T18:34:32.512Z",
      "date_updated": "2026-07-23T14:58:00.984Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6",
      "affected": {
        "vendors": [
          "dj-extensions.com"
        ],
        "products": [
          {
            "vendor": "dj-extensions.com",
            "product": "jDownloads extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17942
      },
      "nvd": {
        "published": "2026-07-20T19:17:28.267",
        "lastModified": "2026-07-23T16:17:46.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61900",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path in jDownloads extension for Joomla accepts an attacker-selected file type or destination outside the intended executable-file policy.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jdownloads.com/",
          "host": "www.jdownloads.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/jdownloads-4-1-unauthenticated-upload-flaw/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61901",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-12T05:35:55.729Z",
      "date_published": "2026-07-20T18:33:34.540Z",
      "date_updated": "2026-07-23T14:56:45.755Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2",
      "affected": {
        "vendors": [
          "hikashop.com"
        ],
        "products": [
          {
            "vendor": "hikashop.com",
            "product": "Hikashop extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03905
      },
      "nvd": {
        "published": "2026-07-20T19:17:28.383",
        "lastModified": "2026-07-23T16:17:46.193",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61901",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Hikashop extension for Joomla accepts an attacker-controlled redirect target without constraining it to an approved origin, allowing a trusted entry point to send users to an untrusted site.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.hikashop.com/",
          "host": "www.hikashop.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61943",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:34.178Z",
      "date_published": "2026-07-23T11:18:25.373Z",
      "date_updated": "2026-07-23T14:52:34.324Z",
      "publisher": "Patchstack",
      "title": "WordPress WPDM – Premium Packages plugin <= 6.2.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Shahjada"
        ],
        "products": [
          {
            "vendor": "Shahjada",
            "product": "WPDM – Premium Packages"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20064
      },
      "nvd": {
        "published": "2026-07-23T12:18:33.930",
        "lastModified": "2026-07-23T15:17:39.163",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61943",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A Premium Packages function is reachable without authentication or the authorization required for that action, while the exact endpoint is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wpdm-premium-packages/vulnerability/wordpress-wpdm-premium-packages-plugin-6-2-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61944",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:34.178Z",
      "date_published": "2026-07-23T11:18:26.009Z",
      "date_updated": "2026-07-23T13:31:29.688Z",
      "publisher": "Patchstack",
      "title": "WordPress Bookly plugin <= 27.7 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Bookly"
        ],
        "products": [
          {
            "vendor": "Bookly",
            "product": "Bookly"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08389
      },
      "nvd": {
        "published": "2026-07-23T12:18:34.053",
        "lastModified": "2026-07-23T14:17:31.977",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61944",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Bookly renders attacker-controlled content without the required HTML sanitization or output escaping, allowing cross-site scripting.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/bookly-responsive-appointment-booking-tool/vulnerability/wordpress-bookly-plugin-27-7-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 70,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61945",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:34.178Z",
      "date_published": "2026-07-23T11:50:37.837Z",
      "date_updated": "2026-07-23T15:26:43.238Z",
      "publisher": "Patchstack",
      "title": "WordPress WooCommerce Product Stock Alert plugin <= 3.0.6 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "MultiVendorX"
        ],
        "products": [
          {
            "vendor": "MultiVendorX",
            "product": "WooCommerce Product Stock Alert"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11631
      },
      "nvd": {
        "published": "2026-07-23T12:18:34.180",
        "lastModified": "2026-07-23T16:17:46.340",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61945",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "The component returns embedded sensitive system information to an unauthorized observer, although the public record does not identify the exact field.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-product-stock-alert/vulnerability/wordpress-woocommerce-product-stock-alert-plugin-3-0-6-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61946",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:34.178Z",
      "date_published": "2026-07-23T11:18:26.659Z",
      "date_updated": "2026-07-23T13:46:40.876Z",
      "publisher": "Patchstack",
      "title": "WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability",
      "affected": {
        "vendors": [
          "Easy Appointments"
        ],
        "products": [
          {
            "vendor": "Easy Appointments",
            "product": "Easy Appointments"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.1452
      },
      "nvd": {
        "published": "2026-07-23T12:18:34.307",
        "lastModified": "2026-07-23T14:17:32.427",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61946",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Easy Appointments accepts a caller-controlled object identifier without binding it to an authorized appointment object.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/easy-appointments/vulnerability/wordpress-easy-appointments-plugin-3-12-27-insecure-direct-object-references-idor-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61947",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:34.178Z",
      "date_published": "2026-07-23T11:18:27.322Z",
      "date_updated": "2026-07-23T14:54:39.122Z",
      "publisher": "Patchstack",
      "title": "WordPress Form Vibes – Database Manager for Forms plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WPVibes"
        ],
        "products": [
          {
            "vendor": "WPVibes",
            "product": "Form Vibes – Database Manager for Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.0719
      },
      "nvd": {
        "published": "2026-07-23T12:18:34.433",
        "lastModified": "2026-07-23T16:17:46.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61947",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Form Vibes renders unauthenticated attacker input as active browser markup without the required output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/form-vibes/vulnerability/wordpress-form-vibes-database-manager-for-forms-plugin-1-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 104,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61948",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:34.178Z",
      "date_published": "2026-07-23T11:18:27.968Z",
      "date_updated": "2026-07-23T14:27:46.400Z",
      "publisher": "Patchstack",
      "title": "WordPress WPDM – Premium Packages plugin <= 6.2.0 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Shahjada"
        ],
        "products": [
          {
            "vendor": "Shahjada",
            "product": "WPDM – Premium Packages"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20542
      },
      "nvd": {
        "published": "2026-07-23T12:18:34.560",
        "lastModified": "2026-07-23T15:17:40.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61948",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wpdm-premium-packages/vulnerability/wordpress-wpdm-premium-packages-plugin-6-2-0-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61949",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:34.178Z",
      "date_published": "2026-07-23T11:18:28.614Z",
      "date_updated": "2026-07-23T15:59:35.105Z",
      "publisher": "Patchstack",
      "title": "WordPress Bookly plugin <= 27.7 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Bookly"
        ],
        "products": [
          {
            "vendor": "Bookly",
            "product": "Bookly"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20542
      },
      "nvd": {
        "published": "2026-07-23T12:18:34.680",
        "lastModified": "2026-07-23T16:17:46.573",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61949",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unauthenticated SQL Injection in Bookly <= 27.7 versions.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/bookly-responsive-appointment-booking-tool/vulnerability/wordpress-bookly-plugin-27-7-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 57,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61950",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:34.178Z",
      "date_published": "2026-07-23T11:18:29.256Z",
      "date_updated": "2026-07-23T14:52:23.970Z",
      "publisher": "Patchstack",
      "title": "WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "themetechmount"
        ],
        "products": [
          {
            "vendor": "themetechmount",
            "product": "TrueBooker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20542
      },
      "nvd": {
        "published": "2026-07-23T12:18:34.803",
        "lastModified": "2026-07-23T15:17:40.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61950",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-89",
          "https://patchstack.com/database/wordpress/plugin/truebooker-appointment-booking/vulnerability/wordpress-truebooker-plugin-1-2-3-sql-injection-vulnerability?_s_id=cve"
        ],
        "deepDive": true,
        "notes": "Reviewed https://patchstack.com/database/wordpress/plugin/truebooker-appointment-booking/vulnerability/wordpress-truebooker-plugin-1-2-3-sql-injection-vulnerability?_s_id=cve. The linked Patchstack entry was not publicly readable through the review client, and no official source diff was discoverable, so the injected parameter remains undisclosed."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/truebooker-appointment-booking/vulnerability/wordpress-truebooker-plugin-1-2-3-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 62,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61951",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:34.178Z",
      "date_published": "2026-07-23T11:18:29.900Z",
      "date_updated": "2026-07-23T13:30:42.286Z",
      "publisher": "Patchstack",
      "title": "WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability",
      "affected": {
        "vendors": [
          "themetechmount"
        ],
        "products": [
          {
            "vendor": "themetechmount",
            "product": "TrueBooker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-266",
          "name": "Incorrect Privilege Assignment",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24568
      },
      "nvd": {
        "published": "2026-07-23T12:18:34.923",
        "lastModified": "2026-07-23T14:17:32.853",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61951",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public advisory states that unauthenticated callers can gain higher WordPress privileges, while it does not disclose the endpoint, input, or missing assignment check.",
        "basis": [
          "CNA",
          "CWE-266",
          "Patchstack PSID 60fd4ad3d153"
        ],
        "deepDive": true,
        "notes": "Inspected https://patchstack.com/database/wordpress/plugin/truebooker-appointment-booking/vulnerability/wordpress-truebooker-plugin-1-2-3-privilege-escalation-vulnerability; the primary disclosure confirms unauthenticated privilege escalation and the 1.2.4 fix, but withholds the endpoint, field and failing privilege assignment."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/truebooker-appointment-booking/vulnerability/wordpress-truebooker-plugin-1-2-3-privilege-escalation-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 69,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61952",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:34.179Z",
      "date_published": "2026-07-13T08:41:25.747Z",
      "date_updated": "2026-07-13T14:38:06.766Z",
      "publisher": "Patchstack",
      "title": "WordPress WooCommerce Bulk Edit Products – WP Sheet Editor plugin <= 1.8.21 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Jose Vega"
        ],
        "products": [
          {
            "vendor": "Jose Vega",
            "product": "WooCommerce Bulk Edit Products – WP Sheet Editor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.0922
      },
      "nvd": {
        "published": "2026-07-13T10:16:46.330",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61952",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/woo-bulk-edit-products/vulnerability/wordpress-woocommerce-bulk-edit-products-wp-sheet-editor-plugin-1-8-21-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61953",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:44.977Z",
      "date_published": "2026-07-27T22:43:59.066Z",
      "date_updated": "2026-07-28T16:06:50.705Z",
      "publisher": "Patchstack",
      "title": "WordPress Simple Link Directory Pro plugin <= 15.0.6 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "QuantumCloud"
        ],
        "products": [
          {
            "vendor": "QuantumCloud",
            "product": "Simple Link Directory Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05566
      },
      "nvd": {
        "published": "2026-07-27T23:16:41.280",
        "lastModified": "2026-07-28T16:19:28.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61953",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Simple Link Directory Pro follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/simple-link-directory-pro/vulnerability/wordpress-simple-link-directory-pro-plugin-15-0-6-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61954",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:44.977Z",
      "date_published": "2026-07-23T11:18:30.542Z",
      "date_updated": "2026-07-23T13:58:59.403Z",
      "publisher": "Patchstack",
      "title": "WordPress PayU India plugin <= 3.8.9 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "PayU India"
        ],
        "products": [
          {
            "vendor": "PayU India",
            "product": "PayU India"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15855
      },
      "nvd": {
        "published": "2026-07-23T12:18:35.047",
        "lastModified": "2026-07-23T14:17:33.277",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61954",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "PayU India exposes an unauthenticated action outside its intended access level, but the protected object and action are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/payu-india/vulnerability/wordpress-payu-india-plugin-3-8-9-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 70,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61955",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:44.978Z",
      "date_published": "2026-07-13T08:41:25.753Z",
      "date_updated": "2026-07-13T13:14:55.632Z",
      "publisher": "Patchstack",
      "title": "WordPress گرویتی فرم فارسی plugin <= 3.0.2 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Hannan"
        ],
        "products": [
          {
            "vendor": "Hannan",
            "product": "گرویتی فرم فارسی"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13418
      },
      "nvd": {
        "published": "2026-07-13T10:16:46.450",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61955",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/persian-gravity-forms/vulnerability/wordpress-ro-t-frm-f-rs-plugin-3-0-2-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61956",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:44.978Z",
      "date_published": "2026-07-13T08:41:25.755Z",
      "date_updated": "2026-07-13T13:46:55.384Z",
      "publisher": "Patchstack",
      "title": "WordPress ووسلام – همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "hamsalam"
        ],
        "products": [
          {
            "vendor": "hamsalam",
            "product": "ووسلام &#8211; همگام سازی ووکامرس و باسلام"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01347
      },
      "nvd": {
        "published": "2026-07-13T10:16:46.573",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61956",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The plugin accepts a cross-site request, but the public record does not identify the state-changing action or missing request-origin control.",
        "basis": [
          "CNA record",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/sync-basalam/vulnerability/wordpress-oosl-m-hm-m-s-z-oo-mrs-o-b-sl-m-plugin-1-9-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 239,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61957",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:44.978Z",
      "date_published": "2026-07-27T22:43:59.716Z",
      "date_updated": "2026-07-28T13:52:46.643Z",
      "publisher": "Patchstack",
      "title": "WordPress miniorange otp verification plugin <= 5.5.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "miniOrange"
        ],
        "products": [
          {
            "vendor": "miniOrange",
            "product": "miniorange otp verification"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04351
      },
      "nvd": {
        "published": "2026-07-27T23:16:41.410",
        "lastModified": "2026-07-28T16:19:12.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61957",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "miniorange otp verification renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/miniorange-otp-verification/vulnerability/wordpress-miniorange-otp-verification-plugin-5-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 92,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61958",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:44.978Z",
      "date_published": "2026-07-13T08:41:25.760Z",
      "date_updated": "2026-07-13T14:12:13.745Z",
      "publisher": "Patchstack",
      "title": "WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Content Deletion vulnerability",
      "affected": {
        "vendors": [
          "Saad Iqbal"
        ],
        "products": [
          {
            "vendor": "Saad Iqbal",
            "product": "License Manager for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06619
      },
      "nvd": {
        "published": "2026-07-13T10:16:46.697",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61958",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The license manager permits deletion without the required authorization, but the target object and failing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/license-manager-for-woocommerce/vulnerability/wordpress-license-manager-for-woocommerce-plugin-3-0-17-arbitrary-content-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61968",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:50.885Z",
      "date_published": "2026-07-13T08:41:25.772Z",
      "date_updated": "2026-07-13T14:19:50.158Z",
      "publisher": "Patchstack",
      "title": "WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Saad Iqbal"
        ],
        "products": [
          {
            "vendor": "Saad Iqbal",
            "product": "myCred"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.0662
      },
      "nvd": {
        "published": "2026-07-13T10:16:46.813",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61968",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "myCred permits an operation outside the caller's assigned authority, while the Patchstack record does not identify the endpoint, object, or missing check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/mycred/vulnerability/wordpress-mycred-plugin-3-1-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 189,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61970",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:50.885Z",
      "date_published": "2026-07-13T08:41:25.801Z",
      "date_updated": "2026-07-13T10:08:07.875Z",
      "publisher": "Patchstack",
      "title": "WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "Themeisle"
        ],
        "products": [
          {
            "vendor": "Themeisle",
            "product": "Auto Featured Image (Auto Post Thumbnail)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.021
      },
      "nvd": {
        "published": "2026-07-13T10:16:46.923",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61970",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server follows an attacker-controlled outbound URL without constraining its destination to the intended remote service.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/auto-post-thumbnail/vulnerability/wordpress-auto-featured-image-auto-post-thumbnail-plugin-5-0-4-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 247,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61971",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:50.885Z",
      "date_published": "2026-07-13T08:41:25.805Z",
      "date_updated": "2026-07-13T14:38:02.877Z",
      "publisher": "Patchstack",
      "title": "WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object References (IDOR) vulnerability",
      "affected": {
        "vendors": [
          "Cozmoslabs"
        ],
        "products": [
          {
            "vendor": "Cozmoslabs",
            "product": "User Profile Picture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00192,
        "percentile": 0.09112
      },
      "nvd": {
        "published": "2026-07-13T10:16:47.040",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61971",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User Profile Picture accepts an attacker-controlled object key without binding the referenced profile-picture operation to the caller's authority.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/metronet-profile-picture/vulnerability/wordpress-user-profile-picture-plugin-2-6-3-insecure-direct-object-references-idor-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61972",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:50.885Z",
      "date_published": "2026-07-23T11:18:31.192Z",
      "date_updated": "2026-07-23T14:46:17.148Z",
      "publisher": "Patchstack",
      "title": "WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "WooLentor"
        ],
        "products": [
          {
            "vendor": "WooLentor",
            "product": "ShopLentor Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11855
      },
      "nvd": {
        "published": "2026-07-23T12:18:35.163",
        "lastModified": "2026-07-23T15:17:41.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61972",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Patchstack record reports unauthenticated broken access control in ShopLentor Pro but does not identify the handler, protected object, or omitted gate.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/woolentor-addons-pro/vulnerability/wordpress-shoplentor-pro-plugin-2-8-5-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 74,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61973",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:55.443Z",
      "date_published": "2026-07-23T11:18:31.839Z",
      "date_updated": "2026-07-23T14:34:37.091Z",
      "publisher": "Patchstack",
      "title": "WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "WooLentor"
        ],
        "products": [
          {
            "vendor": "WooLentor",
            "product": "ShopLentor Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15606
      },
      "nvd": {
        "published": "2026-07-23T12:18:35.287",
        "lastModified": "2026-07-23T15:17:42.587",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61973",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The application exposes a protected operation to an insufficiently authorized caller, but the missing check is not disclosed.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/woolentor-addons-pro/vulnerability/wordpress-shoplentor-pro-plugin-2-8-5-broken-access-control-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 69,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61975",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:55.444Z",
      "date_published": "2026-07-13T08:41:25.863Z",
      "date_updated": "2026-07-13T13:13:44.946Z",
      "publisher": "Patchstack",
      "title": "WordPress JetReviews plugin <= 3.0.1 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Crocoblock"
        ],
        "products": [
          {
            "vendor": "Crocoblock",
            "product": "JetReviews"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09729
      },
      "nvd": {
        "published": "2026-07-13T10:16:47.160",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61975",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "JetReviews embeds sensitive system information in data retrievable from an unauthorized control sphere, while the public record does not name the field or surface.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/jet-reviews/vulnerability/wordpress-jetreviews-plugin-3-0-1-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61976",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:55.444Z",
      "date_published": "2026-07-13T08:41:25.892Z",
      "date_updated": "2026-07-13T13:46:29.399Z",
      "publisher": "Patchstack",
      "title": "WordPress JetBlocks For Elementor plugin <= 1.5.0 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Crocoblock"
        ],
        "products": [
          {
            "vendor": "Crocoblock",
            "product": "JetBlocks For Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.0973
      },
      "nvd": {
        "published": "2026-07-13T10:16:47.280",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61976",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "JetBlocks embeds sensitive system information in output visible outside its intended control sphere.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/jet-blocks/vulnerability/wordpress-jetblocks-for-elementor-plugin-1-5-0-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61977",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:55.444Z",
      "date_published": "2026-07-13T08:41:25.897Z",
      "date_updated": "2026-07-13T14:30:13.175Z",
      "publisher": "Patchstack",
      "title": "WordPress JetSearch plugin <= 3.6.1.2 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Crocoblock"
        ],
        "products": [
          {
            "vendor": "Crocoblock",
            "product": "JetSearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09728
      },
      "nvd": {
        "published": "2026-07-13T10:16:47.400",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61977",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says JetSearch exposes protected data to an unintended observer, while the field and output path are not public.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/jet-search/vulnerability/wordpress-jetsearch-plugin-3-6-1-2-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:13:55.444Z",
      "date_published": "2026-07-23T11:18:32.486Z",
      "date_updated": "2026-07-23T15:58:55.127Z",
      "publisher": "Patchstack",
      "title": "WordPress Simple Link Directory Pro plugin <= 15.0.8 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "QuantumCloud"
        ],
        "products": [
          {
            "vendor": "QuantumCloud",
            "product": "Simple Link Directory Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00104,
        "percentile": 0.01195
      },
      "nvd": {
        "published": "2026-07-23T12:18:35.407",
        "lastModified": "2026-07-23T16:17:46.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61981",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Simple Link Directory Pro accepts a victim browser request that changes server state without an effective anti-CSRF check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/simple-link-directory-pro/vulnerability/wordpress-simple-link-directory-pro-plugin-15-0-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61983",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:14:00.716Z",
      "date_published": "2026-07-13T08:41:25.897Z",
      "date_updated": "2026-07-13T14:19:36.054Z",
      "publisher": "Patchstack",
      "title": "WordPress Church Admin plugin <= 5.0.30 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "andy_moyle"
        ],
        "products": [
          {
            "vendor": "andy_moyle",
            "product": "Church Admin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.0731
      },
      "nvd": {
        "published": "2026-07-13T10:16:47.510",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61983",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/church-admin/vulnerability/wordpress-church-admin-plugin-5-0-30-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-61985",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T06:14:00.716Z",
      "date_published": "2026-07-13T08:41:25.902Z",
      "date_updated": "2026-07-13T10:07:35.856Z",
      "publisher": "Patchstack",
      "title": "WordPress Car Rental Manager plugin <= 1.3.7 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "magepeopleteam"
        ],
        "products": [
          {
            "vendor": "magepeopleteam",
            "product": "Car Rental Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07311
      },
      "nvd": {
        "published": "2026-07-13T10:16:47.633",
        "lastModified": "2026-07-13T16:57:56.050",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-61985",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation runs without enforcing the required caller permission or object-ownership check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/Wordpress/Plugin/car-rental-manager/vulnerability/wordpress-car-rental-manager-plugin-1-3-7-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T07:52:02.284Z",
      "date_published": "2026-07-13T07:52:08.643Z",
      "date_updated": "2026-07-14T14:32:41.437Z",
      "publisher": "CIRCL",
      "title": "Server-Side Request Forgery protection bypass in misp-modules html_to_markdown via IPv4-mapped IPv6 addresses",
      "affected": {
        "vendors": [
          "misp"
        ],
        "products": [
          {
            "vendor": "misp",
            "product": "misp-modules"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/RE:M/U:Green"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:Green"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15054
      },
      "nvd": {
        "published": "2026-07-13T09:16:24.700",
        "lastModified": "2026-07-14T15:17:09.890",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62143",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SSRF filter compares IPv4-mapped IPv6 addresses without first normalizing them to IPv4, so restricted IPv4 destinations miss the blocked ranges.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MISP/misp-modules/commit/3bae4108a3ba1e507727d5264697fd7303ba0b89",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1288,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T10:24:07.648Z",
      "date_published": "2026-07-22T13:53:35.969Z",
      "date_updated": "2026-07-24T03:56:14.016Z",
      "publisher": "checkpoint",
      "title": "Management Authentication Bypass and Privilege Escalation",
      "affected": {
        "vendors": [
          "checkpoint"
        ],
        "products": [
          {
            "vendor": "checkpoint",
            "product": "Quantum Security Management"
          },
          {
            "vendor": "checkpoint",
            "product": "Multi-Domain Security Management"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.20623,
        "percentile": 0.97269
      },
      "nvd": {
        "published": "2026-07-22T14:17:22.807",
        "lastModified": "2026-07-24T05:16:45.793",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62144",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated management client can reach administrative commands, but Check Point does not publish the bypassed credential or role check.",
        "basis": [
          "CNA",
          "CWE-287",
          "Check Point vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/ and the linked support page; the vendor confirms affected management products and mitigation but does not publish the bypassed check, and no reproduction was performed."
      },
      "references": [
        {
          "url": "https://support.checkpoint.com/results/sk/sk185152",
          "host": "support.checkpoint.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-62145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T10:24:07.648Z",
      "date_published": "2026-07-22T13:53:53.656Z",
      "date_updated": "2026-07-24T03:56:05.075Z",
      "publisher": "checkpoint",
      "title": "Local Privilege Escalation in Gaia Portal",
      "affected": {
        "vendors": [
          "checkpoint"
        ],
        "products": [
          {
            "vendor": "checkpoint",
            "product": "Quantum Security Gateway"
          },
          {
            "vendor": "checkpoint",
            "product": "Quantum Security Management"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@checkpoint.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0754,
        "percentile": 0.93896
      },
      "nvd": {
        "published": "2026-07-22T14:17:22.920",
        "lastModified": "2026-07-24T05:16:45.940",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62145",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Gaia Portal permits a read-only authenticated role to execute root commands, but the command path and missing privilege check are not public.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.checkpoint.com/results/sk/sk185153",
          "host": "support.checkpoint.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 155,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-62147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T11:29:50.979Z",
      "date_published": "2026-07-13T11:43:59.024Z",
      "date_updated": "2026-07-13T13:43:50.023Z",
      "publisher": "redhat",
      "title": "Tempo-operator: tempo operator: query rbac bypass",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift distributed tracing 3"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11129
      },
      "nvd": {
        "published": "2026-07-13T12:16:34.927",
        "lastModified": "2026-07-13T17:01:11.600",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62147",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Some Tempo query response paths omit namespace-scoped redaction and return span attributes belonging to other tenants despite query RBAC.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-62147",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499635",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-62183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T14:30:10.801Z",
      "date_published": "2026-07-20T14:23:20.294Z",
      "date_updated": "2026-07-21T14:57:08.107Z",
      "publisher": "apache",
      "title": "Apache Syncope: User self-service privilege escalation",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Syncope"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00411,
        "percentile": 0.33832
      },
      "nvd": {
        "published": "2026-07-20T15:16:44.860",
        "lastModified": "2026-07-27T14:59:50.457",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62183",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The configured self-service workflow lets a user assign defined roles to their own account without administrator approval.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/6r8cngvy43y2yk4jj3w060dt8vx0yzpr",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/9",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 800,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-62184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:36:32.094Z",
      "date_published": "2026-07-13T21:30:09.248Z",
      "date_updated": "2026-07-15T18:45:50.565Z",
      "publisher": "VulnCheck",
      "title": "luci-app-banip Log Monitor IP Extraction Bypass",
      "affected": {
        "vendors": [
          "openwrt"
        ],
        "products": [
          {
            "vendor": "openwrt",
            "product": "luci-app-banip"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00445,
        "percentile": 0.36592
      },
      "nvd": {
        "published": "2026-07-13T22:16:49.310",
        "lastModified": "2026-07-15T21:02:41.590",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62184",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The log parser treats the first IPv4-looking username fragment as a source address instead of preserving log-field boundaries.",
        "basis": [
          "CNA",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openwrt/luci/security/advisories/GHSA-r6hx-4f83-vp8m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/openwrt/luci/commit/d9bbc372e29618a8807b693a1ccf6d0e42cd196c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/luci-app-banip-log-monitor-ip-extraction-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 419,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62185",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:36:32.095Z",
      "date_published": "2026-07-13T21:31:23.660Z",
      "date_updated": "2026-07-14T22:03:46.962Z",
      "publisher": "VulnCheck",
      "title": "Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE",
      "affected": {
        "vendors": [
          "argoproj"
        ],
        "products": [
          {
            "vendor": "argoproj",
            "product": "argo-helm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20611
      },
      "nvd": {
        "published": "2026-07-13T22:16:49.453",
        "lastModified": "2026-07-15T20:29:17.680",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62185",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Helm chart omits network policies by default, leaving repo-server and other Argo APIs reachable from every cluster pod.",
        "basis": [
          "CNA",
          "CWE-1188"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/argoproj/argo-helm/security/advisories/GHSA-47m3-95c7-g2g8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/argo-cd-helm-chart-missing-network-policy-rce",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62186",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:36:32.095Z",
      "date_published": "2026-07-13T21:30:10.654Z",
      "date_updated": "2026-07-14T13:04:34.632Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0.39999999999999947,
      "epss": {
        "score": 0.00192,
        "percentile": 0.0908
      },
      "nvd": {
        "published": "2026-07-13T22:16:49.607",
        "lastModified": "2026-07-14T18:19:17.093",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62186",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenClaw fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-jhfx-v2j8-x3m6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-http-model-override",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:36:32.095Z",
      "date_published": "2026-07-13T21:30:11.350Z",
      "date_updated": "2026-07-28T01:49:53.885Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.9 Feishu tools Authorization Bypass",
      "affected": {
        "vendors": [
          "openclaw"
        ],
        "products": [
          {
            "vendor": "openclaw",
            "product": "feishu"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00213,
        "percentile": 0.1168
      },
      "nvd": {
        "published": "2026-07-13T22:16:49.753",
        "lastModified": "2026-07-15T11:16:33.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62187",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Feishu tool dispatch can ignore per-account disablement and execute an operation from a lower-trust input path without the configured policy check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-2q7j-2vhx-56g8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-feishu-tools-authorization-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 439,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:36:32.095Z",
      "date_published": "2026-07-13T21:30:12.024Z",
      "date_updated": "2026-07-28T01:49:54.754Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.9 Feishu Authorization Bypass",
      "affected": {
        "vendors": [
          "openclaw"
        ],
        "products": [
          {
            "vendor": "openclaw",
            "product": "feishu"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00213,
        "percentile": 0.1168
      },
      "nvd": {
        "published": "2026-07-13T22:16:49.893",
        "lastModified": "2026-07-15T05:17:24.227",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62188",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Feishu permission tools ignore per-account disablement settings, allowing a lower-trust caller to invoke actions that the account policy disabled.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-w8wf-3qvj-6xqf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-feishu-authorization-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62189",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:36:32.095Z",
      "date_published": "2026-07-13T21:30:12.700Z",
      "date_updated": "2026-07-15T04:00:15.635Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.9 Symlink Following via Mirror Sync",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15976
      },
      "nvd": {
        "published": "2026-07-13T22:16:50.037",
        "lastModified": "2026-07-15T05:17:24.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62189",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The mirror synchronization path follows attacker-controlled remote symlink parents and writes outside the intended destination namespace.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-m38g-vpwj-mpg9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-symlink-following-via-mirror-sync",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62190",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:36:32.095Z",
      "date_published": "2026-07-13T21:30:13.408Z",
      "date_updated": "2026-07-15T10:30:55.054Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-706",
          "name": "Use of Incorrectly-Resolved Name or Reference",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20756
      },
      "nvd": {
        "published": "2026-07-13T22:16:50.173",
        "lastModified": "2026-07-15T11:16:33.883",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62190",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenClaw resolves configured flock input paths in a way that breaks the durable binding between an approved command and the action later executed.",
        "basis": [
          "CNA",
          "CWE-706",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-3fp5-v549-9v66",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-flock-wrapper",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 359,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:36:32.095Z",
      "date_published": "2026-07-13T21:30:14.078Z",
      "date_updated": "2026-07-14T12:52:39.220Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message Mutations",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10953
      },
      "nvd": {
        "published": "2026-07-13T22:16:50.310",
        "lastModified": "2026-07-14T18:17:36.077",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62191",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenClaw message mutation handling lets a lower-trust caller invoke actions that require a stronger authorization level.",
        "basis": [
          "CNA",
          "CWE-862",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-v7hx-r36p-f68m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-message-mutations",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 375,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:36:32.095Z",
      "date_published": "2026-07-13T21:30:14.760Z",
      "date_updated": "2026-07-14T13:04:03.447Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14256
      },
      "nvd": {
        "published": "2026-07-13T22:16:50.457",
        "lastModified": "2026-07-14T18:17:30.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62192",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization checks.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-3pmr-x9g8-m55r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 335,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62193",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:36:32.095Z",
      "date_published": "2026-07-13T21:30:15.450Z",
      "date_updated": "2026-07-15T14:26:14.293Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin Install",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08214
      },
      "nvd": {
        "published": "2026-07-13T22:16:50.600",
        "lastModified": "2026-07-15T15:16:48.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62193",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-wgq8-x5wm-g4rw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authentication-bypass-via-plugin-install",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 470,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62194",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:38:58.353Z",
      "date_published": "2026-07-13T21:30:16.154Z",
      "date_updated": "2026-07-15T04:00:18.676Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16543
      },
      "nvd": {
        "published": "2026-07-13T22:16:50.943",
        "lastModified": "2026-07-15T05:17:24.593",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62194",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-732",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-7vrr-rp4x-4g76",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-plugin-install",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 369,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62195",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:38:58.353Z",
      "date_published": "2026-07-13T21:30:16.836Z",
      "date_updated": "2026-07-15T04:00:19.465Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0.3999999999999986,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13885
      },
      "nvd": {
        "published": "2026-07-13T22:16:51.100",
        "lastModified": "2026-07-15T05:17:24.713",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62195",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Configured MCP loopback input paths bypass the owner-only tool check, allowing lower-trust callers to invoke privileged tools.",
        "basis": [
          "CNA",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-52xj-c9p8-78cv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-mcp-loopback",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62196",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:38:58.353Z",
      "date_published": "2026-07-13T21:30:17.506Z",
      "date_updated": "2026-07-15T19:07:59.623Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0.3999999999999986,
      "epss": {
        "score": 0.0023,
        "percentile": 0.13885
      },
      "nvd": {
        "published": "2026-07-13T22:16:51.243",
        "lastModified": "2026-07-15T19:18:36.757",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62196",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-fh38-965w-f6c3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-whatsapp-group-ids",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 300,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62197",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:38:58.353Z",
      "date_published": "2026-07-13T21:30:18.191Z",
      "date_updated": "2026-07-14T12:58:20.059Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00199,
        "percentile": 0.09898
      },
      "nvd": {
        "published": "2026-07-13T22:16:51.380",
        "lastModified": "2026-07-14T17:46:43.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62197",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenClaw follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-3x84-qq85-fj65",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-policy-bypass-via-cdp-discovery",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 277,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62198",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:38:58.353Z",
      "date_published": "2026-07-13T21:30:18.863Z",
      "date_updated": "2026-07-14T12:54:47.585Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05688
      },
      "nvd": {
        "published": "2026-07-13T22:16:51.533",
        "lastModified": "2026-07-14T17:46:31.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62198",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Native web search permits a lower-trust caller to invoke restricted operations, but the precise policy check and bypassing input path are not public.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-v4f6-x5g5-2g4g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-web-search",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 320,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62199",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:38:58.353Z",
      "date_published": "2026-07-13T21:30:19.540Z",
      "date_updated": "2026-07-15T10:30:15.429Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21727
      },
      "nvd": {
        "published": "2026-07-13T22:16:51.673",
        "lastModified": "2026-07-15T11:16:34.003",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62199",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The environment filter omits interpreter startup variables that can alter code loading or execution.",
        "basis": [
          "CNA",
          "CWE-184"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-hjr6-g723-hmfm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authentication-bypass-via-environment-filtering",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 341,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62200",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:38:58.353Z",
      "date_published": "2026-07-13T21:30:20.226Z",
      "date_updated": "2026-07-15T04:00:24.757Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21727
      },
      "nvd": {
        "published": "2026-07-13T22:16:51.813",
        "lastModified": "2026-07-15T05:17:24.953",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62200",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An incomplete environment denylist leaves Git's ext transport available and permits a lower-trust input to invoke external commands.",
        "basis": [
          "CNA record",
          "CWE-184"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-9969-8g9h-rxwm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authentication-bypass-via-git-ext-transport",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 307,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62201",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:38:58.353Z",
      "date_published": "2026-07-17T00:06:48.164Z",
      "date_updated": "2026-07-17T10:45:41.782Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.6 Network Policy Bypass via exec-server",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 2.8,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17598
      },
      "nvd": {
        "published": "2026-07-17T02:18:06.170",
        "lastModified": "2026-07-20T17:01:14.873",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62201",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenClaw accepts an attacker-controlled server request target without constraining it to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-mgvr-6gvw-3rgr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-network-policy-bypass-via-exec-server",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62202",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:38:58.353Z",
      "date_published": "2026-07-17T00:06:48.818Z",
      "date_updated": "2026-07-18T03:55:30.253Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via Cron",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22115
      },
      "nvd": {
        "published": "2026-07-17T02:18:06.430",
        "lastModified": "2026-07-21T19:59:58.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62202",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Isolated cron jobs accept input paths that let lower-trust callers regain execution tools explicitly denied to them.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-mm9g-83wh-mhwj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-cron",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62203",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:38:58.353Z",
      "date_published": "2026-07-17T00:06:49.475Z",
      "date_updated": "2026-07-29T18:26:17.089Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.6 Environment Variable Injection via rustup",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00289,
        "percentile": 0.21119
      },
      "nvd": {
        "published": "2026-07-17T02:18:06.587",
        "lastModified": "2026-07-29T19:16:50.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62203",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenClaw's host-exec environment filter omits rustup startup variables, allowing lower-trust values to alter executable startup behavior.",
        "basis": [
          "CNA",
          "CWE-184"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-wxh3-g47h-q3mc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-environment-variable-injection-via-rustup",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62205",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:22.250Z",
      "date_published": "2026-07-17T00:06:50.105Z",
      "date_updated": "2026-07-17T13:02:13.887Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16334
      },
      "nvd": {
        "published": "2026-07-17T02:18:06.747",
        "lastModified": "2026-07-21T20:00:45.830",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62205",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Teams message-action path permits lower-trust input to invoke actions without the stronger policy check required by that feature.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-p5xh-frrh-cmgj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-beta-1-authorization-bypass-via-message-actions",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 465,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62206",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:22.251Z",
      "date_published": "2026-07-17T00:06:50.753Z",
      "date_updated": "2026-07-17T14:17:25.499Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.9 Authentication Bypass via Moderation Actions",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16334
      },
      "nvd": {
        "published": "2026-07-17T02:18:06.887",
        "lastModified": "2026-07-20T17:00:58.307",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62206",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Discord moderation actions accept a lower-trust caller or input path without the stronger authorization and policy check required for that action.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-f6p7-6326-vf7v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authentication-bypass-via-moderation-actions",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 395,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62207",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:22.251Z",
      "date_published": "2026-07-17T00:06:51.394Z",
      "date_updated": "2026-07-29T18:26:16.950Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00301,
        "percentile": 0.224
      },
      "nvd": {
        "published": "2026-07-17T02:18:07.040",
        "lastModified": "2026-07-29T19:16:50.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62207",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenClaw input-path policy checks allow a lower-trust caller to route a request to admin-scoped tools.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-cf2p-f286-mphf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authentication-bypass-via-admin-tools",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62208",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:22.251Z",
      "date_published": "2026-07-17T00:06:52.026Z",
      "date_updated": "2026-07-17T10:45:09.754Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17348
      },
      "nvd": {
        "published": "2026-07-17T02:18:07.187",
        "lastModified": "2026-07-20T17:00:44.503",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62208",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SSE client forwards an Authorization header across redirects to a different destination.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-9c3v-684m-579c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-header-forwarding-via-sse",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 367,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62209",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:22.251Z",
      "date_published": "2026-07-17T00:06:52.811Z",
      "date_updated": "2026-07-18T03:55:32.532Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode dispatch",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.0021,
        "percentile": 0.1135
      },
      "nvd": {
        "published": "2026-07-17T02:18:07.327",
        "lastModified": "2026-07-21T19:59:43.903",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62209",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The OpenClaw operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-wp73-f3gg-w4vr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-beta-1-authorization-bypass-via-agent-mode-dispatch",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 365,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62210",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:22.251Z",
      "date_published": "2026-07-17T00:06:53.449Z",
      "date_updated": "2026-07-23T19:29:26.150Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23749
      },
      "nvd": {
        "published": "2026-07-17T02:18:07.470",
        "lastModified": "2026-07-23T20:17:19.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62210",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenClaw permits slow remote-media reads to hold worker resources without an effective duration or concurrency bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-4xwj-mcc7-x7x5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-denial-of-service-via-remote-media-urls",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62211",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:22.251Z",
      "date_published": "2026-07-17T00:06:54.132Z",
      "date_updated": "2026-07-29T20:13:58.980Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00111,
        "percentile": 0.01538
      },
      "nvd": {
        "published": "2026-07-17T02:18:07.620",
        "lastModified": "2026-07-29T21:17:47.590",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62211",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says OpenClaw exposes protected data to an unintended observer, while the field and output path are not public.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-j4cx-jvq7-79vm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-credential-redaction-bypass-via-trajectory-export",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62212",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:22.251Z",
      "date_published": "2026-07-17T00:06:54.838Z",
      "date_updated": "2026-07-17T14:16:41.103Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.5.28 Authentication Bypass via safeFetch",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06832
      },
      "nvd": {
        "published": "2026-07-17T02:18:07.783",
        "lastModified": "2026-07-20T16:59:11.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62212",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenClaw validates a DNS result and later uses it in a separate step, leaving a DNS-rebinding race between check and use.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-wxm8-ghhq-q688",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authentication-bypass-via-safefetch",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 457,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62213",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:22.251Z",
      "date_published": "2026-07-17T00:06:55.533Z",
      "date_updated": "2026-07-20T23:34:19.682Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests",
      "affected": {
        "vendors": [
          "openclaw"
        ],
        "products": [
          {
            "vendor": "openclaw",
            "product": "msteams"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17348
      },
      "nvd": {
        "published": "2026-07-17T02:18:07.943",
        "lastModified": "2026-07-21T00:17:48.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62213",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenClaw permits lower-trust callers to select an input path that causes a Bot Framework token to leave the trusted Teams outbound-request boundary.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-v54h-q2vx-vgg4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-token-leakage-via-ms-teams-outbound-requests",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 282,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62214",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:44.419Z",
      "date_published": "2026-07-17T00:06:56.206Z",
      "date_updated": "2026-07-17T10:44:22.179Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter Validation",
      "affected": {
        "vendors": [
          "openclaw"
        ],
        "products": [
          {
            "vendor": "openclaw",
            "product": "msteams"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00308,
        "percentile": 0.23169
      },
      "nvd": {
        "published": "2026-07-17T02:18:08.097",
        "lastModified": "2026-07-20T16:58:47.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62214",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenClaw follows a caller-controlled serviceUrl and forwards an authentication token to the selected destination.",
        "basis": [
          "CNA",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-prwc-c6w5-mmgr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-bot-framework-ssrf-via-serviceurl-parameter-validation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 376,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62215",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:44.419Z",
      "date_published": "2026-07-17T00:06:56.885Z",
      "date_updated": "2026-07-17T18:06:01.918Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 2.9000000000000004,
      "epss": {
        "score": 0.00173,
        "percentile": 0.0695
      },
      "nvd": {
        "published": "2026-07-17T02:18:08.243",
        "lastModified": "2026-07-20T16:58:30.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62215",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HTTP Canvas accepts lower-trust input as a trusted A2UI action without binding the action to the stronger authorization context it requires.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-vr7j-7684-7gm5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authentication-bypass-via-http-canvas",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62216",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:44.419Z",
      "date_published": "2026-07-17T00:06:57.567Z",
      "date_updated": "2026-07-23T19:26:02.159Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 2.7,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11434
      },
      "nvd": {
        "published": "2026-07-17T02:18:08.420",
        "lastModified": "2026-07-23T20:17:19.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62216",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The QQBot media-upload path can send lower-trust input to network destinations that the surrounding OpenClaw policy should block.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-fwgr-fpv9-vf5x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-policy-bypass-via-media-upload",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62217",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:44.419Z",
      "date_published": "2026-07-17T00:06:58.228Z",
      "date_updated": "2026-07-18T03:55:33.359Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15894
      },
      "nvd": {
        "published": "2026-07-17T02:18:08.553",
        "lastModified": "2026-07-21T19:59:25.813",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62217",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "QQBot exec approvals accept actions from non-allowlisted lower-trust senders instead of binding approval to the intended caller.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-7jx6-764p-fgg9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-beta-1-authentication-bypass-via-exec-approvals",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62218",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:44.419Z",
      "date_published": "2026-07-17T00:06:58.909Z",
      "date_updated": "2026-07-18T03:55:34.111Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16131
      },
      "nvd": {
        "published": "2026-07-17T02:18:08.693",
        "lastModified": "2026-07-21T19:58:34.633",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62218",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenClaw's device.pair.approve path lets a lower-trust caller bypass the stronger role-management authorization required for the action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-8v95-qqcm-qp9h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-device-pair-approve",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 310,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62219",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:44.420Z",
      "date_published": "2026-07-17T00:06:59.594Z",
      "date_updated": "2026-07-21T01:19:51.688Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06975
      },
      "nvd": {
        "published": "2026-07-17T02:18:08.847",
        "lastModified": "2026-07-21T19:58:07.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62219",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The allowedAgentIds policy treats a blank agent identifier as acceptable and thereby fails to bind a hook action to an authorized agent.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-724r-v4wf-mqc5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-blank-agent-ids",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 310,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:44.420Z",
      "date_published": "2026-07-17T00:07:00.275Z",
      "date_updated": "2026-07-17T10:37:19.676Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00293,
        "percentile": 0.21518
      },
      "nvd": {
        "published": "2026-07-17T02:18:08.990",
        "lastModified": "2026-07-21T20:01:26.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62220",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OpenClaw authentication path lacks an effective attempt limit, allowing repeated requests to bypass or exhaust the control.",
        "basis": [
          "CNA",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-5p6w-wmh3-frfr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-websocket-rate-limit-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 300,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62221",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:44.420Z",
      "date_published": "2026-07-17T00:07:00.968Z",
      "date_updated": "2026-07-17T18:05:57.721Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 3.1000000000000005,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04075
      },
      "nvd": {
        "published": "2026-07-17T02:18:09.133",
        "lastModified": "2026-07-21T20:00:31.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62221",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ClickClack allowFrom lets a lower-trust caller run or persist actions outside the configured command allowlist.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-fh8v-vgcv-pwh4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-allowfrom",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 340,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62222",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:44.420Z",
      "date_published": "2026-07-17T00:07:01.643Z",
      "date_updated": "2026-07-29T18:26:16.783Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01988
      },
      "nvd": {
        "published": "2026-07-17T02:18:09.273",
        "lastModified": "2026-07-29T19:16:50.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62222",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Setup-mode discovery loads executable plugins from a lower-trust workspace path without establishing trusted provenance.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-rh6r-vvfc-86jq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-untrusted-plugin-loading-via-setup-mode",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62223",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:39:44.420Z",
      "date_published": "2026-07-17T00:07:02.286Z",
      "date_updated": "2026-07-18T03:55:35.754Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.5.18 Authorization Bypass via Device-pair",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16132
      },
      "nvd": {
        "published": "2026-07-17T02:18:09.440",
        "lastModified": "2026-07-20T16:57:40.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62223",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenClaw fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-hx85-fgcw-9vrc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-device-pair",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62224",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:40:10.961Z",
      "date_published": "2026-07-17T00:07:02.933Z",
      "date_updated": "2026-07-17T14:10:22.850Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw MS Teams < 2026.5.12 Authorization Bypass",
      "affected": {
        "vendors": [
          "openclaw"
        ],
        "products": [
          {
            "vendor": "openclaw",
            "product": "msteams"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 3.1000000000000005,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05195
      },
      "nvd": {
        "published": "2026-07-17T02:18:09.603",
        "lastModified": "2026-07-17T18:08:08.140",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62224",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Teams allowFrom policy binds authority to a mutable display name instead of an immutable account identity.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-290",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-7w4v-g4m6-j88v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-ms-teams-authorization-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 299,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62225",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:40:10.961Z",
      "date_published": "2026-07-17T00:07:03.616Z",
      "date_updated": "2026-07-21T01:20:34.252Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 3.1000000000000005,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04473
      },
      "nvd": {
        "published": "2026-07-17T02:18:09.750",
        "lastModified": "2026-07-21T02:16:23.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62225",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenClaw dispatches skill commands from lower-trust input paths without applying the tool policy required for the resulting action.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-mhm4-93fw-4qr2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-skill-command-dispatch",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:40:10.961Z",
      "date_published": "2026-07-17T00:07:04.373Z",
      "date_updated": "2026-07-17T10:53:19.719Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 3.4000000000000004,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15353
      },
      "nvd": {
        "published": "2026-07-17T02:18:09.887",
        "lastModified": "2026-07-21T19:57:34.353",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62226",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The browser action route operates on the current tab without verifying that its URL remains within the authorized origin.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-x863-pqjw-hmgf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-browser-act-route",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62227",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:40:10.961Z",
      "date_published": "2026-07-17T00:07:05.015Z",
      "date_updated": "2026-07-17T18:05:54.201Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 2.8,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13748
      },
      "nvd": {
        "published": "2026-07-17T02:18:10.027",
        "lastModified": "2026-07-21T20:00:20.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62227",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenClaw validates the initial browser destination but not the post-navigation destination used for the snapshot request.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-2x93-h3hg-2xfp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-ssrf-via-browser-snapshot",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62228",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:40:10.961Z",
      "date_published": "2026-07-17T00:07:05.678Z",
      "date_updated": "2026-07-29T18:21:31.975Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16132
      },
      "nvd": {
        "published": "2026-07-17T02:18:10.153",
        "lastModified": "2026-07-29T19:16:50.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62228",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenClaw applies different authorization semantics across gateway and node execution environments, allowing a lower-trust caller to bypass an exec approval.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-8f46-3xx3-8c9m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-node-exec-approvals",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 367,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62229",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:40:10.961Z",
      "date_published": "2026-07-17T00:07:06.340Z",
      "date_updated": "2026-07-18T03:55:37.415Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching",
      "affected": {
        "vendors": [
          "OpenClaw"
        ],
        "products": [
          {
            "vendor": "OpenClaw",
            "product": "OpenClaw"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00446,
        "percentile": 0.36613
      },
      "nvd": {
        "published": "2026-07-17T02:18:10.290",
        "lastModified": "2026-07-30T14:49:36.710",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62229",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Exec allowlist glob matching accepts traversal-shaped input paths that resolve outside the operations granted to the caller.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-34mr-7r3m-gfg7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-glob-matching",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 340,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62230",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:40:10.961Z",
      "date_published": "2026-07-17T00:07:06.995Z",
      "date_updated": "2026-07-17T14:09:15.233Z",
      "publisher": "VulnCheck",
      "title": "Grav < 2.0.4 File Access Bypass via Case Variation",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-178",
          "name": "Improper Handling of Case Sensitivity",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00282,
        "percentile": 0.20459
      },
      "nvd": {
        "published": "2026-07-17T02:18:10.433",
        "lastModified": "2026-07-17T15:44:29.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62230",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The default web-server rules match sensitive extensions case-sensitively, so case variants bypass them on case-insensitive filesystems.",
        "basis": [
          "CNA",
          "CWE-178"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-vwg3-w8w3-pc79",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-file-access-bypass-via-case-variation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62231",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:40:10.961Z",
      "date_published": "2026-07-17T00:07:07.666Z",
      "date_updated": "2026-07-21T01:21:38.952Z",
      "publisher": "VulnCheck",
      "title": "Grav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticator",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12766
      },
      "nvd": {
        "published": "2026-07-17T02:18:10.587",
        "lastModified": "2026-07-21T02:16:23.543",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62231",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ApiKeyAuthenticator ignores a key's scopes and returns the owning account's full authority for every API operation.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-x7hm-jc32-v39j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-api-key-scope-bypass-via-apikeyauthenticator",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 444,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:40:10.961Z",
      "date_published": "2026-07-17T00:07:08.361Z",
      "date_updated": "2026-07-17T10:29:09.539Z",
      "publisher": "VulnCheck",
      "title": "Grav < 2.0.4 2FA Bypass via Secret Regeneration",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20214
      },
      "nvd": {
        "published": "2026-07-17T02:18:10.743",
        "lastModified": "2026-07-17T15:44:29.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62232",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The pending 2FA flow lets a password-authenticated caller replace another user's TOTP secret without authorization or a CSRF nonce.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-7mgc-c7pq-3rr3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-2fa-bypass-via-secret-regeneration",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 462,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62233",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:40:10.962Z",
      "date_published": "2026-07-17T00:07:09.028Z",
      "date_updated": "2026-07-17T18:05:50.649Z",
      "publisher": "VulnCheck",
      "title": "grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15895
      },
      "nvd": {
        "published": "2026-07-17T02:18:10.890",
        "lastModified": "2026-07-17T19:17:18.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62233",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-8gg4-rvvv-cq96",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-plugin-api-privilege-escalation-via-createapikey",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62234",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:41:09.007Z",
      "date_published": "2026-07-17T00:07:09.697Z",
      "date_updated": "2026-07-23T19:27:48.492Z",
      "publisher": "VulnCheck",
      "title": "Grav < 2.0.4 SSRF via Unrestricted cURL Protocols",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00297,
        "percentile": 0.21974
      },
      "nvd": {
        "published": "2026-07-17T02:18:11.040",
        "lastModified": "2026-07-23T20:17:19.703",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62234",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "grav follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-58q8-f7v4-w2vf",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-ssrf-via-unrestricted-curl-protocols",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 348,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62235",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:41:09.007Z",
      "date_published": "2026-07-17T00:07:10.397Z",
      "date_updated": "2026-07-17T12:06:27.960Z",
      "publisher": "VulnCheck",
      "title": "Grav Flex-Objects < 1.4.3 Authorization Bypass via API",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-636",
          "name": "Not Failing Securely ('Failing Open')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 4,
      "epss": {
        "score": 0.00169,
        "percentile": 0.06598
      },
      "nvd": {
        "published": "2026-07-17T02:18:11.183",
        "lastModified": "2026-07-17T15:44:29.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62235",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The admin-next API treats a directory with no explicit permissions configuration as writable by any api.access credential.",
        "basis": [
          "CNA",
          "CWE-636",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-23vq-365v-qcmh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-flex-objects-authorization-bypass-via-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 448,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62236",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:41:09.007Z",
      "date_published": "2026-07-17T00:07:11.106Z",
      "date_updated": "2026-07-17T14:15:05.443Z",
      "publisher": "VulnCheck",
      "title": "grav-plugin-login < 3.8.11 CSRF via regenerate2FASecret",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 3.1000000000000005,
      "epss": {
        "score": 0.00099,
        "percentile": 0.00951
      },
      "nvd": {
        "published": "2026-07-17T02:18:11.327",
        "lastModified": "2026-07-17T15:44:29.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62236",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A state-changing request lacks a nonce, origin check, or equivalent cross-site request proof.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-4px8-7p53-282r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-plugin-login-csrf-via-regenerate2fasecret",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 698,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62237",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:41:09.007Z",
      "date_published": "2026-07-17T00:07:11.756Z",
      "date_updated": "2026-07-21T01:22:52.319Z",
      "publisher": "VulnCheck",
      "title": "Grav < 2.0.4 ReDoS via regex_replace in Sandbox",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1333",
          "name": "Inefficient Regular Expression Complexity",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16257
      },
      "nvd": {
        "published": "2026-07-17T02:18:11.477",
        "lastModified": "2026-07-21T02:16:23.660",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62237",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Twig sandbox passes an attacker-selected catastrophically backtracking pattern to preg_replace without a complexity bound.",
        "basis": [
          "CNA record",
          "CWE-1333"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-37f3-6p89-6qr9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-redos-via-regex-replace-in-sandbox",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 513,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62238",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:41:09.007Z",
      "date_published": "2026-07-17T00:07:12.425Z",
      "date_updated": "2026-07-17T10:28:10.902Z",
      "publisher": "VulnCheck",
      "title": "OpenRemote < 1.26.0 SQL Injection via Crosstab Export",
      "affected": {
        "vendors": [
          "openremote"
        ],
        "products": [
          {
            "vendor": "openremote",
            "product": "openremote"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25906
      },
      "nvd": {
        "published": "2026-07-17T02:18:11.613",
        "lastModified": "2026-07-30T14:26:39.323",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62238",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "openremote builds an SQL statement from attacker-controlled text without parameterization or SQL-context separation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openremote/openremote/security/advisories/GHSA-cgfv-jrfp-2r7v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openremote-sql-injection-via-crosstab-export",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 414,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62239",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:41:09.007Z",
      "date_published": "2026-07-13T21:03:32.262Z",
      "date_updated": "2026-07-14T12:53:45.093Z",
      "publisher": "VulnCheck",
      "title": "FlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py",
      "affected": {
        "vendors": [
          "Dao-AILab"
        ],
        "products": [
          {
            "vendor": "Dao-AILab",
            "product": "flash-attention"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 1.2999999999999998,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02897
      },
      "nvd": {
        "published": "2026-07-13T22:16:51.967",
        "lastModified": "2026-07-15T21:02:13.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62239",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The build extractor follows a pre-planted symlink in a predictable cache path and writes archive members at the link target.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Dao-AILab/flash-attention/issues/2637",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/Dao-AILab/flash-attention/pull/2702",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/Dao-AILab/flash-attention/commit/0816ef12f424c6ec94b057a72c275b14f6e6edb2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/flashattention-symlink-attack-via-tarfile-extractall-in-hopper-setup-py",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 464,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62240",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:41:09.007Z",
      "date_published": "2026-07-13T21:04:03.774Z",
      "date_updated": "2026-07-14T13:06:13.692Z",
      "publisher": "VulnCheck",
      "title": "CrewAI < 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape Tools",
      "affected": {
        "vendors": [
          "crewAIInc"
        ],
        "products": [
          {
            "vendor": "crewAIInc",
            "product": "crewAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23826
      },
      "nvd": {
        "published": "2026-07-13T22:16:52.117",
        "lastModified": "2026-07-14T18:52:40.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62240",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CrewAI validates only the initial URL and returns it unchanged, allowing redirects or DNS rebinding to move the eventual request to an internal address.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/crewAIInc/crewAI/releases/tag/1.15.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/crewAIInc/crewAI/issues/6520",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Patch",
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/crewAIInc/crewAI/pull/6331",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "Vendor Advisory",
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/crewAIInc/crewAI/commit/5d4851eac797cafc45b726f65747fe2c9520fc42",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/crewai-ssrf-filter-bypass-via-http-redirect-in-scrape-tools",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62241",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:41:09.007Z",
      "date_published": "2026-07-17T00:07:13.098Z",
      "date_updated": "2026-07-17T18:05:46.735Z",
      "publisher": "VulnCheck",
      "title": "clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery",
      "affected": {
        "vendors": [
          "MohibShaikh"
        ],
        "products": [
          {
            "vendor": "MohibShaikh",
            "product": "clawvet"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-321",
          "name": "Use of Hard-coded Cryptographic Key",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31707
      },
      "nvd": {
        "published": "2026-07-17T02:18:11.740",
        "lastModified": "2026-07-17T19:17:18.647",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62241",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The service falls back to a publicly known cryptographic key, allowing attackers to forge tokens that the server accepts.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MohibShaikh/clawvet/security/advisories/GHSA-9mww-p953-jfc9",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/clawvet-hard-coded-jwt-secret-session-forgery",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 574,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62242",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T16:41:09.007Z",
      "date_published": "2026-07-13T21:04:26.002Z",
      "date_updated": "2026-07-15T14:21:56.098Z",
      "publisher": "VulnCheck",
      "title": "Spring Boot Admin Server < 4.1.2 SSRF via Unauthenticated Instance Registration",
      "affected": {
        "vendors": [
          "codecentric"
        ],
        "products": [
          {
            "vendor": "codecentric",
            "product": "spring-boot-admin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20561
      },
      "nvd": {
        "published": "2026-07-13T22:16:52.260",
        "lastModified": "2026-07-15T21:02:41.590",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62242",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unauthenticated instance registration accepts arbitrary healthUrl and managementUrl destinations without blocking internal or metadata addresses, and the proxy returns their responses.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/codecentric/spring-boot-admin/releases/tag/4.1.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/codecentric/spring-boot-admin/issues/5452",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/codecentric/spring-boot-admin/pull/5464",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/spring-boot-admin-server-ssrf-via-unauthenticated-instance-registration",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T17:09:57.573Z",
      "date_published": "2026-07-30T21:06:14.556Z",
      "date_updated": "2026-07-31T23:12:53.619Z",
      "publisher": "GitHub_M",
      "title": "Kamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL datastore schema + DB user, breaking per-tenant isolation",
      "affected": {
        "vendors": [
          "clastix"
        ],
        "products": [
          {
            "vendor": "clastix",
            "product": "kamaji"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-653",
          "name": "Improper Isolation or Compartmentalization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.1892
      },
      "nvd": {
        "published": "2026-07-30T22:16:55.300",
        "lastModified": "2026-08-01T00:17:17.480",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62246",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kamaji's lossy namespace-and-name normalization can map distinct tenants to the same database user, schema, and etcd prefix, merging their control-plane authority.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-653"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/clastix/kamaji/security/advisories/GHSA-4f3f-65vx-r34f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/clastix/kamaji/commit/4232a9df7ccd08075c26191f59566202042543a9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 481,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62290",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T18:37:08.488Z",
      "date_published": "2026-07-16T19:37:40.255Z",
      "date_updated": "2026-07-18T03:10:55.978Z",
      "publisher": "GitHub_M",
      "title": "cert-manager: Direct ACME Challenge resources can bypass Issuer DNS01 solver policy and use ClusterIssuer DNS credentials",
      "affected": {
        "vendors": [
          "cert-manager"
        ],
        "products": [
          {
            "vendor": "cert-manager",
            "product": "cert-manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00104,
        "percentile": 0.01197
      },
      "nvd": {
        "published": "2026-07-16T20:16:46.550",
        "lastModified": "2026-07-30T14:27:48.843",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62290",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Challenge operation does not bind the requested action to the authorized owner, issuer, or solver.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cert-manager/cert-manager/pull/8940",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cert-manager/cert-manager/pull/8941",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cert-manager/cert-manager/commit/6bda47297c8fbc6b121b8b76624b668d26f1a155",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cert-manager/cert-manager/commit/b37dbf01ecea50a0b3a19df0a7fe4c5ad6803f16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cert-manager/cert-manager/releases/tag/v1.19.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cert-manager/cert-manager/releases/tag/v1.20.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 809,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62294",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T18:37:08.488Z",
      "date_published": "2026-07-15T14:20:43.746Z",
      "date_updated": "2026-07-15T18:00:42.038Z",
      "publisher": "GitHub_M",
      "title": "Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot \"Open With\"",
      "affected": {
        "vendors": [
          "flameshot-org"
        ],
        "products": [
          {
            "vendor": "flameshot-org",
            "product": "flameshot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-377",
          "name": "Insecure Temporary File",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00101,
        "percentile": 0.01056
      },
      "nvd": {
        "published": "2026-07-15T15:16:49.010",
        "lastModified": "2026-07-15T20:56:21.653",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62294",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The flameshot file operation follows an attacker-influenced symlink or predictable temporary path outside the intended file object.",
        "basis": [
          "CNA",
          "CWE-362",
          "CWE-377"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/flameshot-org/flameshot/security/advisories/GHSA-fqqf-4rj8-c392",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/flameshot-org/flameshot/pull/4716",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/flameshot-org/flameshot/commit/936716b8d8b7052be461c3d5e2f88492b6eb3b96",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/flameshot-org/flameshot/releases/tag/v14.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62299",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T18:37:08.489Z",
      "date_published": "2026-07-16T19:44:36.475Z",
      "date_updated": "2026-07-17T18:06:37.349Z",
      "publisher": "GitHub_M",
      "title": "CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record",
      "affected": {
        "vendors": [
          "coredns"
        ],
        "products": [
          {
            "vendor": "coredns",
            "product": "coredns"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23512
      },
      "nvd": {
        "published": "2026-07-16T20:16:46.693",
        "lastModified": "2026-07-22T20:18:57.970",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62299",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CoreDNS dereferences a null EDNS0 object when a response rule assumes the request contains that option.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coredns/coredns/security/advisories/GHSA-9pmm-cxww-rrr7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coredns/coredns/pull/8190",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coredns/coredns/commit/fc447d0658b093edc8cd29a6b171216a44a644c2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coredns/coredns/releases/tag/v1.14.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 770,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:27:58.314Z",
      "date_published": "2026-07-16T19:42:17.867Z",
      "date_updated": "2026-07-18T03:14:46.896Z",
      "publisher": "GitHub_M",
      "title": "CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS",
      "affected": {
        "vendors": [
          "coredns"
        ],
        "products": [
          {
            "vendor": "coredns",
            "product": "coredns"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30415
      },
      "nvd": {
        "published": "2026-07-16T20:16:47.030",
        "lastModified": "2026-07-22T20:17:31.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62309",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CoreDNS logs addr.String after a PROXY v2 parse failure has replaced addr with a nil value.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coredns/coredns/security/advisories/GHSA-9rvv-m5g5-wc8r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coredns/coredns/pull/8154",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coredns/coredns/commit/60a439dd4febfcd78e3779e952fe3fbf3c16bb1f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coredns/coredns/releases/tag/v1.14.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 483,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62312",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:27:58.314Z",
      "date_published": "2026-07-15T20:53:18.302Z",
      "date_updated": "2026-07-16T18:51:28.371Z",
      "publisher": "GitHub_M",
      "title": "9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00719,
        "percentile": 0.50316
      },
      "nvd": {
        "published": "2026-07-15T21:16:55.810",
        "lastModified": "2026-07-16T19:16:51.010",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62312",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "9Router trusts a spoofable Host header as proof of localhost origin, exposing an MCP route that launches attacker-selected plugin arguments.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-63p9-g54h-prrp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/commit/da667836cc7584bea0edd893de1d590c9ea279dc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/decolua/9router/releases/tag/v0.5.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62314",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:27:58.314Z",
      "date_published": "2026-07-15T21:18:00.355Z",
      "date_updated": "2026-07-16T12:48:35.586Z",
      "publisher": "GitHub_M",
      "title": "Anubis: Policy bypass via client controlled X-Original-URI header",
      "affected": {
        "vendors": [
          "TecharoHQ"
        ],
        "products": [
          {
            "vendor": "TecharoHQ",
            "product": "anubis"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.19029
      },
      "nvd": {
        "published": "2026-07-15T22:17:38.050",
        "lastModified": "2026-07-16T14:16:56.427",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62314",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Anubis trusts X-Original-URI from an untrusted request as the canonical protected path, allowing the caller to select a different authorization target.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/TecharoHQ/anubis/security/advisories/GHSA-6wcg-mqvh-fcvg",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/TecharoHQ/anubis/pull/1630",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/TecharoHQ/anubis/commit/276b537776b281b1c4e01421435bc03ade3d8fc4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/TecharoHQ/anubis/releases/tag/v1.26.0-pre1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 477,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62323",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:27:58.315Z",
      "date_published": "2026-07-31T03:43:14.900Z",
      "date_updated": "2026-07-31T19:28:19.622Z",
      "publisher": "GitHub_M",
      "title": "Cloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ignored",
      "affected": {
        "vendors": [
          "cloudreve"
        ],
        "products": [
          {
            "vendor": "cloudreve",
            "product": "cloudreve"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00306,
        "percentile": 0.22928
      },
      "nvd": {
        "published": "2026-07-31T04:17:24.160",
        "lastModified": "2026-07-31T20:16:53.080",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62323",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "WOPI validation checks only the session-ID prefix and ignores the action-bearing token suffix, allowing a view session to authorize write routes.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-c3jm-gv5r-9wcp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/commit/f3347130ac48f2ff996af9ef66c97be2dda9cba9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/cloudreve/cloudreve/releases/tag/4.17.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 395,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62324",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:27:58.315Z",
      "date_published": "2026-07-31T19:08:03.043Z",
      "date_updated": "2026-08-03T17:26:47.204Z",
      "publisher": "GitHub_M",
      "title": "Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS",
      "affected": {
        "vendors": [
          "xdan"
        ],
        "products": [
          {
            "vendor": "xdan",
            "product": "jodit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-83",
          "name": "Improper Neutralization of Script in Attributes in a Web Page",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07724
      },
      "nvd": {
        "published": "2026-07-31T20:16:53.197",
        "lastModified": "2026-08-03T18:16:40.340",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62324",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Jodit checks href schemes without canonicalizing case and embedded control bytes, allowing javascript URLs to survive sanitization.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-83"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/xdan/jodit/security/advisories/GHSA-j839-gqq4-gf9j",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/xdan/jodit/commit/5fba6ef2381d151d7cb8e3c5ad0b9996af0f97b0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/xdan/jodit/releases/tag/4.12.31",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 462,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62325",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T19:27:58.315Z",
      "date_published": "2026-07-28T21:52:05.595Z",
      "date_updated": "2026-07-29T13:25:38.846Z",
      "publisher": "GitHub_M",
      "title": "goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)",
      "affected": {
        "vendors": [
          "goshs-labs"
        ],
        "products": [
          {
            "vendor": "goshs-labs",
            "product": "goshs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27041
      },
      "nvd": {
        "published": "2026-07-28T23:17:10.077",
        "lastModified": "2026-07-30T19:19:45.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62325",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SFTP password handler registers no authentication callback when the configured password is empty, leaving file access unauthenticated.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/goshs-labs/goshs/security/advisories/GHSA-rjrw-mjq6-hpmm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/goshs-labs/goshs/commit/32f4a0e1790a709f722d0f3b2341f139d003180a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/goshs-labs/goshs/releases/tag/v2.1.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62327",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:36:08.380Z",
      "date_published": "2026-07-13T21:37:51.416Z",
      "date_updated": "2026-07-14T14:30:46.008Z",
      "publisher": "VulnCheck",
      "title": "9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9Router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29796
      },
      "nvd": {
        "published": "2026-07-13T22:16:52.403",
        "lastModified": "2026-07-14T16:42:11.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62327",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The usage statistics API route omits authentication middleware and returns full plaintext provider API keys to any remote requester.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-vjc7-jrh9-9j86",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/9router-unauthenticated-api-key-exposure-via-api-usage-stats",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:36:08.380Z",
      "date_published": "2026-07-13T21:37:52.094Z",
      "date_updated": "2026-07-15T18:10:21.082Z",
      "publisher": "VulnCheck",
      "title": "9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9Router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-359",
          "name": "Exposure of Private Personal Information to an Unauthorized Actor",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29796
      },
      "nvd": {
        "published": "2026-07-13T22:16:52.550",
        "lastModified": "2026-07-15T19:18:36.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62328",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Request-log and request-detail API routes omit authentication middleware and return complete conversation records to anonymous callers.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-vjc7-jrh9-9j86",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/9router-unauthenticated-information-disclosure-via-api-usage-endpoints",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 495,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62343",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:42:50.095Z",
      "date_published": "2026-07-29T23:57:51.105Z",
      "date_updated": "2026-07-30T13:56:44.621Z",
      "publisher": "GitHub_M",
      "title": "ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02507
      },
      "nvd": {
        "published": "2026-07-30T00:16:24.200",
        "lastModified": "2026-08-03T16:27:26.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62343",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unchecked integer calculation in ImageMagick can wrap and produce an invalid memory size or position.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f5m7-cqgw-8hm7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:42:50.096Z",
      "date_published": "2026-07-15T19:07:07.692Z",
      "date_updated": "2026-07-16T19:12:45.290Z",
      "publisher": "GitHub_M",
      "title": "TDengine: KILL SSMIGRATE missing authorization lets low-privilege users interrupt shared-storage migrations",
      "affected": {
        "vendors": [
          "taosdata"
        ],
        "products": [
          {
            "vendor": "taosdata",
            "product": "TDengine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11208
      },
      "nvd": {
        "published": "2026-07-15T19:18:37.107",
        "lastModified": "2026-07-16T20:16:47.320",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62348",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mndProcessKillSsMigrateReq calls the migration-kill operation while its required database privilege check is disabled.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/taosdata/TDengine/security/advisories/GHSA-67g2-ffwr-7x9h",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:42:50.096Z",
      "date_published": "2026-07-15T18:55:07.774Z",
      "date_updated": "2026-07-15T19:37:03.649Z",
      "publisher": "GitHub_M",
      "title": "TDengine: Off-by-One Buffer Overflow",
      "affected": {
        "vendors": [
          "taosdata"
        ],
        "products": [
          {
            "vendor": "taosdata",
            "product": "TDengine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00401,
        "percentile": 0.32856
      },
      "nvd": {
        "published": "2026-07-15T19:18:37.347",
        "lastModified": "2026-07-15T20:18:01.557",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62349",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "trimString reserves one output byte for an escape sequence that can emit two, causing a one-byte stack overwrite.",
        "basis": [
          "CNA",
          "CWE-121",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/taosdata/TDengine/security/advisories/GHSA-4v5h-fxjw-vrmq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62350",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:42:50.096Z",
      "date_published": "2026-07-15T18:54:26.320Z",
      "date_updated": "2026-07-18T01:18:49.611Z",
      "publisher": "GitHub_M",
      "title": "TDengine: UDF lead to RCE",
      "affected": {
        "vendors": [
          "taosdata"
        ],
        "products": [
          {
            "vendor": "taosdata",
            "product": "TDengine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29726
      },
      "nvd": {
        "published": "2026-07-15T19:18:37.810",
        "lastModified": "2026-07-18T02:17:10.390",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62350",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TDengine lets attacker-controlled schema, metadata, code text, or file content cross into a code-generation or execution interpreter without the quoting, allowlisting, or neutralization needed to keep it as data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/taosdata/TDengine/security/advisories/GHSA-f7wh-p233-87xv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 362,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:42:50.096Z",
      "date_published": "2026-07-15T19:08:06.126Z",
      "date_updated": "2026-07-15T19:33:42.747Z",
      "publisher": "GitHub_M",
      "title": "TDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read in transDecompressMsg",
      "affected": {
        "vendors": [
          "taosdata"
        ],
        "products": [
          {
            "vendor": "taosdata",
            "product": "TDengine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24867
      },
      "nvd": {
        "published": "2026-07-15T19:18:37.947",
        "lastModified": "2026-07-15T20:18:01.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62351",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "transDecompressMsg reads an eight-byte compression header before verifying that the packet contains it, then derives invalid allocation arithmetic from those bytes.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/taosdata/TDengine/security/advisories/GHSA-8pc4-p252-f5m7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 444,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T21:42:50.096Z",
      "date_published": "2026-07-15T19:08:55.160Z",
      "date_updated": "2026-07-15T19:28:51.733Z",
      "publisher": "GitHub_M",
      "title": "TDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetToken",
      "affected": {
        "vendors": [
          "taosdata"
        ],
        "products": [
          {
            "vendor": "taosdata",
            "product": "TDengine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.1609
      },
      "nvd": {
        "published": "2026-07-15T19:18:38.073",
        "lastModified": "2026-07-15T20:18:01.763",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62353",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TDengine increments past a trailing backslash in a SQL string token and reads one byte beyond the terminator.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125",
          "CWE-126"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/taosdata/TDengine/security/advisories/GHSA-5r9p-3j4f-gmgp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62355",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T22:04:59.676Z",
      "date_published": "2026-07-15T18:51:50.872Z",
      "date_updated": "2026-07-15T19:23:31.376Z",
      "publisher": "GitHub_M",
      "title": "TDengine: Standard User permission unexpect",
      "affected": {
        "vendors": [
          "taosdata"
        ],
        "products": [
          {
            "vendor": "taosdata",
            "product": "TDengine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03607
      },
      "nvd": {
        "published": "2026-07-15T19:18:38.200",
        "lastModified": "2026-07-15T20:18:01.860",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62355",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A user assigned the Data Reader role can create a user-defined function even though that role is intended to be read-only.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/taosdata/TDengine/security/advisories/GHSA-fmp7-rf4r-8q7p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 359,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62361",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T22:04:59.677Z",
      "date_published": "2026-07-15T20:56:45.832Z",
      "date_updated": "2026-07-16T15:12:24.544Z",
      "publisher": "GitHub_M",
      "title": "listmonk: SQL Injection in `/api/subscribers/export` bypasses table access control, leaking admin password hashes and SMTP credentials",
      "affected": {
        "vendors": [
          "knadh"
        ],
        "products": [
          {
            "vendor": "knadh",
            "product": "listmonk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15096
      },
      "nvd": {
        "published": "2026-07-15T21:16:55.933",
        "lastModified": "2026-07-16T16:19:16.103",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62361",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "listmonk passes an export query into SQL without the table validation used by the ordinary subscriber query endpoint.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/knadh/listmonk/security/advisories/GHSA-xgjr-7j9q-2h4r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/knadh/listmonk/commit/c0a6525009a65265230185f16e8674dcc83aa024",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/knadh/listmonk/releases/tag/v6.2.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62363",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T22:04:59.677Z",
      "date_published": "2026-07-30T00:02:33.876Z",
      "date_updated": "2026-07-30T13:08:51.019Z",
      "publisher": "GitHub_M",
      "title": "ImageMagick: Heap Buffer Over-Write in fx operation",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.032
      },
      "nvd": {
        "published": "2026-07-30T00:16:25.213",
        "lastModified": "2026-08-03T16:25:12.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62363",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick's fx operation writes beyond a heap buffer while processing a crafted expression argument.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-422r-8c97-xcg4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T22:04:59.678Z",
      "date_published": "2026-07-15T16:50:13.127Z",
      "date_updated": "2026-07-16T19:19:40.699Z",
      "publisher": "GitHub_M",
      "title": "RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeover",
      "affected": {
        "vendors": [
          "rustfs"
        ],
        "products": [
          {
            "vendor": "rustfs",
            "product": "console"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25752
      },
      "nvd": {
        "published": "2026-07-15T17:16:53.020",
        "lastModified": "2026-07-16T20:16:47.430",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62378",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx extension-based PDF preview path can render HTML content uploaded as .pdf, allowing stored cross-site scripting in the management console and exposure of administrator AccessKeyId, SecretAccessKey, and SessionToken values.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rustfs/rustfs/security/advisories/GHSA-7gcx-wg4x-q9x6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rustfs/console/commit/49630dc140e6818aaee8879ade038a129838a2f2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rustfs/console/releases/tag/v0.1.10",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 511,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62386",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T22:40:54.412Z",
      "date_published": "2026-07-17T00:07:13.741Z",
      "date_updated": "2026-07-23T19:22:08.990Z",
      "publisher": "VulnCheck",
      "title": "Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-598",
          "name": "Use of HTTP Request With Sensitive Query String",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18889
      },
      "nvd": {
        "published": "2026-07-17T02:18:11.903",
        "lastModified": "2026-07-23T20:17:19.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62386",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback).",
        "basis": [
          "CNA",
          "CWE-598"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-4hpj-wmpw-ghwq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-rc-16-authentication-bypass-via-token-url-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 592,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62387",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-13T22:40:54.412Z",
      "date_published": "2026-07-17T00:07:14.426Z",
      "date_updated": "2026-07-17T12:03:54.826Z",
      "publisher": "VulnCheck",
      "title": "Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-942",
          "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17494
      },
      "nvd": {
        "published": "2026-07-17T02:18:12.053",
        "lastModified": "2026-07-17T15:44:29.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62387",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The API plugin sends wildcard CORS permission on token-authenticated endpoints, allowing any origin to submit authorized cross-origin requests when it has a token.",
        "basis": [
          "CNA",
          "CWE-942"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-93px-98wh-6fj2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-rc-16-cors-misconfiguration-via-api-plugin",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 668,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62389",
      "id_year": 2026,
      "state": "REJECTED",
      "date_reserved": "2026-07-13T22:40:54.412Z",
      "date_published": "2026-07-15T17:04:26.250Z",
      "date_rejected": "2026-07-29T17:23:48.982Z",
      "date_updated": "2026-07-29T17:23:48.982Z",
      "publisher": "VulnCheck",
      "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate of CVE-2026-48779.",
      "rejected_reason": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate of CVE-2026-48779."
    },
    {
      "cve_id": "CVE-2026-62390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T02:39:25.817Z",
      "date_published": "2026-07-14T12:09:40.980Z",
      "date_updated": "2026-07-14T16:12:57.844Z",
      "publisher": "apache",
      "title": "Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Kylin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00409,
        "percentile": 0.33644
      },
      "nvd": {
        "published": "2026-07-14T13:19:08.307",
        "lastModified": "2026-07-14T17:17:15.407",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62390",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data is incorporated into an SQL statement without parameter binding or equivalent grammar separation, allowing it to alter the query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/zdrj93txvdjj07f88s43d2pcg2gomvjc",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/14/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T02:46:17.386Z",
      "date_published": "2026-07-31T09:58:15.033Z",
      "date_updated": "2026-07-31T16:29:28.224Z",
      "publisher": "apache",
      "title": "Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Kyuubi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-27",
          "name": "Path Traversal: 'dir/../../filename'",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00401,
        "percentile": 0.32918
      },
      "nvd": {
        "published": "2026-07-31T11:17:11.593",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62391",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kyuubi's local-directory allowlist can be bypassed with unprefixed Spark file-configuration aliases that select the same path outside the checked namespace.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-27"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/vo4k4nxz23kfzrpp120nsojb0vrkx4w1",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 369,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T03:10:04.408Z",
      "date_published": "2026-07-14T12:18:57.308Z",
      "date_updated": "2026-07-15T04:00:58.707Z",
      "publisher": "apache",
      "title": "Apache Kylin: OS Command Injection via Async Query API",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Kylin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.01321,
        "percentile": 0.68074
      },
      "nvd": {
        "published": "2026-07-14T13:19:08.447",
        "lastModified": "2026-07-15T05:17:25.077",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62392",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value reaches operating-system command construction in Apache Kylin without separation from command or argument syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/9hof8lxo3mzshsh5r77mskzqlkns09gn",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/14/5",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 318,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62393",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T03:33:13.944Z",
      "date_published": "2026-07-14T12:19:27.705Z",
      "date_updated": "2026-07-15T15:13:25.772Z",
      "publisher": "apache",
      "title": "Apache Kylin: Improper authorization in job information retrieval",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Kylin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-280",
          "name": "Improper Handling of Insufficient Permissions or Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00288,
        "percentile": 0.20989
      },
      "nvd": {
        "published": "2026-07-14T13:19:08.663",
        "lastModified": "2026-07-15T16:16:50.933",
        "vulnStatus": "Modified",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62393",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Job retrieval fails to enforce project permissions and returns jobs belonging to other projects.",
        "basis": [
          "CNA",
          "CWE-280"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/xg8dcyjw0nkq5y8dhq3r25x3rxc62x9j",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/14/6",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62414",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T05:16:10.070Z",
      "date_published": "2026-07-20T18:34:39.117Z",
      "date_updated": "2026-07-23T14:58:08.452Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2",
      "affected": {
        "vendors": [
          "joomlack.fr"
        ],
        "products": [
          {
            "vendor": "joomlack.fr",
            "product": "Page Builder CK extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14169
      },
      "nvd": {
        "published": "2026-07-20T19:17:28.603",
        "lastModified": "2026-07-23T16:17:46.810",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62414",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Frontend page-list views do not apply the required access control, but the public material does not identify the caller, object, or failed predicate.",
        "basis": [
          "CNA",
          "CWE-284",
          "JoomlaCK Page Builder CK release notes"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.joomlack.fr/en/joomla-extensions/page-builder-ck on 2026-08-05; the vendor release notes describe version 3.6.2 only as improving frontend security, while 3.6.3 separately mentions Joomla media-manager authorization for uploads. They do not expose the access-control predicate for the frontend page-list views named by the CVE, so that mechanism remains broad."
      },
      "references": [
        {
          "url": "https://www.joomlack.fr/",
          "host": "www.joomlack.fr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62415",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T05:16:10.070Z",
      "date_published": "2026-07-21T09:19:19.754Z",
      "date_updated": "2026-07-23T15:01:08.350Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2",
      "affected": {
        "vendors": [
          "joomdonation.com"
        ],
        "products": [
          {
            "vendor": "joomdonation.com",
            "product": "Membership Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.19056
      },
      "nvd": {
        "published": "2026-07-21T10:16:24.727",
        "lastModified": "2026-07-23T16:17:46.990",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62415",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Membership Pro defaults its media-upload operation to unauthenticated access.",
        "basis": [
          "CNA record",
          "CWE-1188"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://joomdonation.com/joomla-extensions/membership-pro-joomla-membership-subscription.html",
          "host": "joomdonation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T08:22:25.966Z",
      "date_published": "2026-07-20T14:27:04.679Z",
      "date_updated": "2026-07-21T14:57:00.487Z",
      "publisher": "apache",
      "title": "Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Syncope"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22428
      },
      "nvd": {
        "published": "2026-07-20T15:16:44.983",
        "lastModified": "2026-07-27T14:58:20.017",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62418",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apache Syncope accepts an attacker-controlled server request target without constraining it to approved endpoints.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/n632drbsmfr6t3p6jt6jwbjvokqdyszb",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/10",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-62422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:16:43.594Z",
      "date_published": "2026-07-14T10:17:59.267Z",
      "date_updated": "2026-07-15T04:00:57.907Z",
      "publisher": "JetBrains",
      "title": "In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "YouTrack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00346,
        "percentile": 0.2724
      },
      "nvd": {
        "published": "2026-07-14T11:16:48.367",
        "lastModified": "2026-07-15T20:08:02.787",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62422",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "YouTrack permits direct database access to bypass application authentication and obtain administrative access.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.654Z",
      "date_published": "2026-07-28T12:31:41.801Z",
      "date_updated": "2026-07-28T14:51:03.684Z",
      "publisher": "XEN",
      "title": "buffer overruns in libfsimage iso9660 handling",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-130",
          "name": "Improper Handling of Length Parameter Inconsistency",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10686
      },
      "nvd": {
        "published": "2026-07-28T13:19:01.210",
        "lastModified": "2026-07-28T16:19:29.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62423",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The libfsimage Rock Ridge loop trusts an attacker-controlled inner record length without checking it against the remaining ISO9660 data.",
        "basis": [
          "CNA",
          "CWE-130"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-497.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 767,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.654Z",
      "date_published": "2026-07-28T12:31:41.862Z",
      "date_updated": "2026-07-28T14:53:51.529Z",
      "publisher": "XEN",
      "title": "buffer overruns in libfsimage iso9660 handling",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-130",
          "name": "Improper Handling of Length Parameter Inconsistency",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10685
      },
      "nvd": {
        "published": "2026-07-28T13:19:01.310",
        "lastModified": "2026-07-28T16:19:30.730",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62424",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled record length is used without validating that it is consistent with the enclosing buffer.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-130"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-497.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 767,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.654Z",
      "date_published": "2026-07-28T12:31:41.918Z",
      "date_updated": "2026-07-28T15:40:37.904Z",
      "publisher": "XEN",
      "title": "buffer overruns in libfsimage iso9660 handling",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10685
      },
      "nvd": {
        "published": "2026-07-28T13:19:01.410",
        "lastModified": "2026-07-28T16:19:31.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62425",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ISO9660 Rock Ridge CE parser trusts attacker-controlled size and offset fields without checking that the requested extent remains inside the image buffer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-497.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 767,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62426",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.655Z",
      "date_published": "2026-07-28T12:31:57.586Z",
      "date_updated": "2026-07-28T15:55:11.598Z",
      "publisher": "XEN",
      "title": "sysctl and platform-op locks open to abuse",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-412",
          "name": "Unrestricted Externally Accessible Lock",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-667",
          "name": "Improper Locking",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13724
      },
      "nvd": {
        "published": "2026-07-28T13:19:01.517",
        "lastModified": "2026-07-28T16:19:32.697",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62426",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Xen path lets an untrusted caller hold a system-wide lock before permission is established, starving other operations.",
        "basis": [
          "CNA",
          "CWE-412",
          "CWE-667"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-499.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 612,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.655Z",
      "date_published": "2026-07-28T12:31:57.645Z",
      "date_updated": "2026-07-28T15:54:19.508Z",
      "publisher": "XEN",
      "title": "sysctl and platform-op locks open to abuse",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-305",
          "name": "Authentication Bypass by Primary Weakness",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16336
      },
      "nvd": {
        "published": "2026-07-28T13:19:01.613",
        "lastModified": "2026-07-28T16:19:33.823",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62427",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The service acquires a global lock before checking permission, allowing unauthorized requests to monopolize work for all callers.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-305"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-499.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 612,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.655Z",
      "date_published": "2026-07-28T12:32:07.573Z",
      "date_updated": "2026-07-28T16:33:28.183Z",
      "publisher": "XEN",
      "title": "grant-table: type confusion in grant-copy",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.001,
        "percentile": 0.00989
      },
      "nvd": {
        "published": "2026-07-28T13:19:01.713",
        "lastModified": "2026-07-28T17:16:53.687",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62428",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A pinned Xen grant can supply different guest pages to the permission check and the subsequent copy operation.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-500.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://xenbits.xen.org/xsa/advisory-500.html",
          "host": "xenbits.xen.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/16",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 496,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62429",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.655Z",
      "date_published": "2026-07-28T12:32:24.333Z",
      "date_updated": "2026-07-28T16:33:29.286Z",
      "publisher": "XEN",
      "title": "vNUMA domain cleanup may race other operations",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14256
      },
      "nvd": {
        "published": "2026-07-28T13:19:01.810",
        "lastModified": "2026-07-28T17:16:54.440",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62429",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Xen can destroy a guest concurrently with vNUMA retrieval, allowing one path to use lifecycle state being removed by the other.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-502.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://xenbits.xen.org/xsa/advisory-502.html",
          "host": "xenbits.xen.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/18",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.655Z",
      "date_published": "2026-07-28T12:32:33.150Z",
      "date_updated": "2026-07-28T16:33:30.367Z",
      "publisher": "XEN",
      "title": "x86: Out-of-bounds read in vRTC emulation",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16699
      },
      "nvd": {
        "published": "2026-07-28T13:19:01.913",
        "lastModified": "2026-07-28T17:16:55.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62430",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Xen validates a guest-selected CMOS index without holding the lock through its later use, allowing another vCPU to change the index after validation and cause an out-of-bounds array read.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-503.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://xenbits.xen.org/xsa/advisory-503.html",
          "host": "xenbits.xen.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/19",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 373,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62431",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.655Z",
      "date_published": "2026-07-28T12:32:43.849Z",
      "date_updated": "2026-07-28T16:33:31.447Z",
      "publisher": "XEN",
      "title": "Viridian STIMER division by zero",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-369",
          "name": "Divide By Zero",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00375,
        "percentile": 0.30217
      },
      "nvd": {
        "published": "2026-07-28T13:19:02.010",
        "lastModified": "2026-07-28T17:16:55.977",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62431",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Viridian STIMER path divides by an unchecked guest-controlled divisor that may be zero.",
        "basis": [
          "CNA",
          "CWE-369"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-504.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://xenbits.xen.org/xsa/advisory-504.html",
          "host": "xenbits.xen.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/20",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62432",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.655Z",
      "date_published": "2026-07-28T12:32:52.043Z",
      "date_updated": "2026-07-28T16:33:32.509Z",
      "publisher": "XEN",
      "title": "evtchn: Race between FIFO expand and reset",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11599
      },
      "nvd": {
        "published": "2026-07-28T13:19:02.110",
        "lastModified": "2026-07-28T17:16:56.733",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62432",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "EVTCHNOP_expand_array checks FIFO state without the lock used by EVTCHNOP_reset, allowing reset to clear the pointer before it is dereferenced.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-505.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://xenbits.xen.org/xsa/advisory-505.html",
          "host": "xenbits.xen.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/21",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.655Z",
      "date_published": "2026-07-28T12:32:59.802Z",
      "date_updated": "2026-07-28T16:33:33.573Z",
      "publisher": "XEN",
      "title": "correct buffer checks for DM_OP hypercalls",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-665",
          "name": "Improper Initialization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17957
      },
      "nvd": {
        "published": "2026-07-28T13:19:02.207",
        "lastModified": "2026-07-28T17:16:57.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62433",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Xen's DM_OP handler assumes a minimum buffer count before indexing the caller-provided array, allowing a short request to access invalid memory.",
        "basis": [
          "CNA",
          "CWE-665"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-506.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://xenbits.xen.org/xsa/advisory-506.html",
          "host": "xenbits.xen.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/22",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 253,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.655Z",
      "date_published": "2026-07-28T12:33:08.540Z",
      "date_updated": "2026-07-28T16:33:34.668Z",
      "publisher": "XEN",
      "title": "PoD: Don't try to reclaim special pages",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25192
      },
      "nvd": {
        "published": "2026-07-28T13:19:02.317",
        "lastModified": "2026-07-28T17:16:58.200",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62434",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Xen permits a PoD guest to reclaim pages that are not regular guest RAM, corrupting the hypervisor's page-management state.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-507.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://xenbits.xen.org/xsa/advisory-507.html",
          "host": "xenbits.xen.org",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/23",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 177,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.655Z",
      "date_published": "2026-07-28T12:32:16.287Z",
      "date_updated": "2026-07-28T15:19:30.368Z",
      "publisher": "XEN",
      "title": "grant-table: version change racing with other operations",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09484
      },
      "nvd": {
        "published": "2026-07-28T13:19:02.433",
        "lastModified": "2026-07-28T16:19:40.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62435",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Grant-table code drops and reacquires its lock while assuming the table version and valid reference range cannot change during that window.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-501.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 766,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T10:28:12.655Z",
      "date_published": "2026-07-28T12:32:16.344Z",
      "date_updated": "2026-07-28T15:17:33.705Z",
      "publisher": "XEN",
      "title": "grant-table: version change racing with other operations",
      "affected": {
        "vendors": [
          "Xen"
        ],
        "products": [
          {
            "vendor": "Xen",
            "product": "Xen"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09485
      },
      "nvd": {
        "published": "2026-07-28T13:19:02.553",
        "lastModified": "2026-07-28T16:19:41.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62436",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Grant-table code drops its lock and later assumes the table version and status-frame layout did not change during the unlocked window.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://xenbits.xenproject.org/xsa/advisory-501.html",
          "host": "xenbits.xenproject.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 766,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62443",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.731Z",
      "date_published": "2026-07-21T21:39:27.492Z",
      "date_updated": "2026-07-22T17:39:59.652Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Contracts Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05047
      },
      "nvd": {
        "published": "2026-07-21T22:19:02.043",
        "lastModified": "2026-07-27T17:44:19.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62443",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Contracts Integration accepts a cross-site state-changing request in a victim's browser context, but the operation and anti-CSRF failure are not public.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 812,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62444",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.731Z",
      "date_published": "2026-07-21T21:39:27.803Z",
      "date_updated": "2026-07-22T17:43:10.245Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Contracts Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13978
      },
      "nvd": {
        "published": "2026-07-21T22:19:02.160",
        "lastModified": "2026-07-27T17:44:17.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62444",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Contracts Integration accepts an untrusted redirect destination and can steer another user's browser outside the trusted application origin, although the endpoint is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 913,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.731Z",
      "date_published": "2026-07-21T21:39:28.123Z",
      "date_updated": "2026-07-22T17:42:26.211Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Order Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25133
      },
      "nvd": {
        "published": "2026-07-21T22:19:02.280",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62445",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Order Management operation does not enforce the authentication, role, ownership, or scope check required before the protected action.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 727,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62447",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.731Z",
      "date_published": "2026-07-21T21:39:28.445Z",
      "date_updated": "2026-07-22T17:41:35.786Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Trade Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31658
      },
      "nvd": {
        "published": "2026-07-21T22:19:02.393",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62447",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Trade Management omits the stronger authentication or authorization needed before a low-privileged user can take over the service.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62451",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.732Z",
      "date_published": "2026-07-21T21:39:28.867Z",
      "date_updated": "2026-07-22T17:25:53.743Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Work in Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16125
      },
      "nvd": {
        "published": "2026-07-21T22:19:02.507",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62451",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Work in Process permits an operation outside the caller's assigned authority, while the exact failing permission check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 719,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62453",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.732Z",
      "date_published": "2026-07-21T21:39:29.196Z",
      "date_updated": "2026-07-22T17:33:35.216Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (UK)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09362
      },
      "nvd": {
        "published": "2026-07-21T22:19:02.633",
        "lastModified": "2026-07-24T18:34:57.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62453",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle HRMS (UK) fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-200",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 758,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62456",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.732Z",
      "date_published": "2026-07-21T21:39:29.519Z",
      "date_updated": "2026-07-22T17:32:51.926Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (UK)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12801
      },
      "nvd": {
        "published": "2026-07-21T22:19:02.770",
        "lastModified": "2026-07-24T18:34:59.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62456",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle HRMS permits a low-privilege HTTPS caller to read and modify critical data beyond its role, while the object and access check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 815,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62464",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.733Z",
      "date_published": "2026-07-21T21:39:30.185Z",
      "date_updated": "2026-07-22T17:32:07.011Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.2244
      },
      "nvd": {
        "published": "2026-07-21T22:19:02.883",
        "lastModified": "2026-07-27T18:23:30.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62464",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized access to Oracle Payroll in its Internal Operations component, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 510,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62465",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.733Z",
      "date_published": "2026-07-21T21:39:30.505Z",
      "date_updated": "2026-07-22T17:31:08.413Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (US)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00108,
        "percentile": 0.01369
      },
      "nvd": {
        "published": "2026-07-21T22:19:02.990",
        "lastModified": "2026-07-24T18:35:09.240",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62465",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Human Resources permits a caller to exceed its assigned privileges, but the public record does not identify the protected operation or check.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 805,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62466",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.733Z",
      "date_published": "2026-07-21T21:39:30.845Z",
      "date_updated": "2026-07-22T17:29:56.315Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Human Resources"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37111
      },
      "nvd": {
        "published": "2026-07-21T22:19:03.103",
        "lastModified": "2026-07-27T16:58:56.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62466",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Human Resources lets a high-privileged HTTP user cross an additional authority boundary and take over the component, but the failing check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 533,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62468",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.733Z",
      "date_published": "2026-07-21T21:39:31.163Z",
      "date_updated": "2026-07-22T17:27:09.652Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Enterprise Command Center).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Human Resources"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26314
      },
      "nvd": {
        "published": "2026-07-21T22:19:03.213",
        "lastModified": "2026-07-27T16:58:59.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62468",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Human Resources permits a low-privileged HTTP caller to act beyond the assigned role, while the missing object or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 725,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62469",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.733Z",
      "date_published": "2026-07-21T21:39:31.475Z",
      "date_updated": "2026-07-22T16:14:58.796Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Enterprise Command Center).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Human Resources"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01984
      },
      "nvd": {
        "published": "2026-07-21T22:19:03.330",
        "lastModified": "2026-07-27T16:58:49.490",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62469",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Human Resources permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 767,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62470",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.733Z",
      "date_published": "2026-07-21T21:39:31.789Z",
      "date_updated": "2026-07-22T16:15:35.907Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Manager Self-Service).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Self-Service Human Resources"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21388
      },
      "nvd": {
        "published": "2026-07-21T22:19:03.443",
        "lastModified": "2026-07-27T16:58:44.407",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62470",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies low-privileged access to all Self-Service HR data but does not publish the object or authorization check.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 614,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62472",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.733Z",
      "date_published": "2026-07-21T21:39:32.115Z",
      "date_updated": "2026-07-22T16:16:16.364Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Installed Base"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00248,
        "percentile": 0.16172
      },
      "nvd": {
        "published": "2026-07-21T22:19:03.557",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62472",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 715,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62473",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.733Z",
      "date_published": "2026-07-21T21:39:32.518Z",
      "date_updated": "2026-07-22T16:18:24.417Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Installed Base"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18237
      },
      "nvd": {
        "published": "2026-07-21T22:19:03.677",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62473",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle publishes a low-privilege HTTP path and broad confidentiality, integrity and availability impacts for Installed Base, without identifying the failing authorization rule.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 830,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62474",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.734Z",
      "date_published": "2026-07-21T21:39:32.832Z",
      "date_updated": "2026-07-22T16:29:54.379Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Lease and Finance Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08844
      },
      "nvd": {
        "published": "2026-07-21T22:19:03.800",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62474",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A security-sensitive endpoint performs its operation without requiring the caller to authenticate.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 849,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.734Z",
      "date_published": "2026-07-21T21:39:33.143Z",
      "date_updated": "2026-07-22T16:31:40.115Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Payroll"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14146
      },
      "nvd": {
        "published": "2026-07-21T22:19:03.913",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62476",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can take over Public Sector Payroll, but Oracle does not disclose the protected operation or check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62478",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.734Z",
      "date_published": "2026-07-21T21:39:33.551Z",
      "date_updated": "2026-07-22T16:33:11.446Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14178
      },
      "nvd": {
        "published": "2026-07-21T22:19:04.027",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62478",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Public Sector Financials caller can reach takeover-capable authority beyond its intended role, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62479",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.734Z",
      "date_published": "2026-07-21T21:39:33.865Z",
      "date_updated": "2026-07-22T15:55:54.992Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09467
      },
      "nvd": {
        "published": "2026-07-21T22:19:04.137",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62479",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The product permits an action beyond the caller's intended authority, but the public record does not disclose the protected object or failed check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 927,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62480",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.734Z",
      "date_published": "2026-07-21T21:39:34.179Z",
      "date_updated": "2026-07-22T15:57:11.623Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00326,
        "percentile": 0.25133
      },
      "nvd": {
        "published": "2026-07-21T22:19:04.250",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62480",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privilege Public Sector Financials user can read critical data, but the object and failing permission check are not public.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.735Z",
      "date_published": "2026-07-21T21:39:34.492Z",
      "date_updated": "2026-07-22T15:59:06.747Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Public Sector Financials"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.0681
      },
      "nvd": {
        "published": "2026-07-21T22:19:04.363",
        "lastModified": "2026-07-29T15:45:37.650",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62482",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that Oracle Public Sector Financials permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 708,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62483",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.735Z",
      "date_published": "2026-07-21T21:39:34.799Z",
      "date_updated": "2026-07-22T16:02:40.157Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Project Contracts"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.0884
      },
      "nvd": {
        "published": "2026-07-21T22:19:04.477",
        "lastModified": "2026-07-31T13:09:34.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62483",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Project Contracts lets a low-privileged HTTP user modify data outside the role's scope, but the failing check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 567,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62484",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.735Z",
      "date_published": "2026-07-21T21:39:35.115Z",
      "date_updated": "2026-07-22T16:03:35.537Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Contracts Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13056
      },
      "nvd": {
        "published": "2026-07-21T22:19:04.587",
        "lastModified": "2026-07-27T17:44:14.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62484",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports unauthenticated modification of critical Contracts Integration data, but the CPU does not identify the protected object or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 605,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62486",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.735Z",
      "date_published": "2026-07-21T21:39:35.434Z",
      "date_updated": "2026-07-22T16:05:18.192Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Contracts Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00151,
        "percentile": 0.0474
      },
      "nvd": {
        "published": "2026-07-21T22:19:04.700",
        "lastModified": "2026-07-27T17:44:12.283",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62486",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The Oracle Contracts Integration record reports user-assisted confidentiality, integrity, and availability impact but does not identify a recovery flow, request, or failing engineering rule.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 905,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62487",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.735Z",
      "date_published": "2026-07-21T21:39:35.753Z",
      "date_updated": "2026-07-22T15:46:25.471Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Contracts Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02629
      },
      "nvd": {
        "published": "2026-07-21T22:19:04.820",
        "lastModified": "2026-07-27T17:44:09.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62487",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Contracts Integration accepts a cross-site authenticated request, but the public record does not identify the state-changing action or missing token check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 913,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.735Z",
      "date_published": "2026-07-21T21:39:36.072Z",
      "date_updated": "2026-07-22T15:47:15.720Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Contracts Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00217,
        "percentile": 0.12262
      },
      "nvd": {
        "published": "2026-07-21T22:19:04.933",
        "lastModified": "2026-07-27T17:44:05.847",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62488",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Contracts Integration path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 602,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.735Z",
      "date_published": "2026-07-21T21:39:36.614Z",
      "date_updated": "2026-07-22T15:48:00.444Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Contracts Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04567
      },
      "nvd": {
        "published": "2026-07-21T22:19:05.050",
        "lastModified": "2026-07-27T17:21:52.253",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62489",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected action is available without a sufficient caller-to-operation authorization check, whose exact form is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 698,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.735Z",
      "date_published": "2026-07-21T21:39:36.929Z",
      "date_updated": "2026-07-22T15:49:00.617Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Contracts Integration"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16073
      },
      "nvd": {
        "published": "2026-07-21T22:19:05.157",
        "lastModified": "2026-07-27T17:44:01.777",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62490",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Oracle Contracts Integration user can read critical or complete accessible data, while the public record does not name the operation or object.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 594,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62493",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.736Z",
      "date_published": "2026-07-21T21:39:37.243Z",
      "date_updated": "2026-07-22T15:52:31.891Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Purchasing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.1448
      },
      "nvd": {
        "published": "2026-07-21T22:19:05.270",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62493",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can take over Oracle Purchasing, but the protected operation and failing authorization check are not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62494",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.736Z",
      "date_published": "2026-07-21T21:39:37.556Z",
      "date_updated": "2026-07-22T15:49:48.322Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Time and Labor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11528
      },
      "nvd": {
        "published": "2026-07-21T22:19:05.387",
        "lastModified": "2026-07-28T18:10:31.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62494",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Time and Labor permits an operation outside the caller's authority, while the failing identity, role, object, or action check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62495",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.736Z",
      "date_published": "2026-07-21T21:39:37.878Z",
      "date_updated": "2026-07-22T15:28:25.028Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Process Execution product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Process Execution"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14536
      },
      "nvd": {
        "published": "2026-07-21T22:19:05.497",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62495",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged HTTP user can take over Process Manufacturing Internal Operations but does not publish the operation or permission check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 603,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.736Z",
      "date_published": "2026-07-21T21:39:38.184Z",
      "date_updated": "2026-07-22T15:31:19.567Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Yard Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15726
      },
      "nvd": {
        "published": "2026-07-21T22:19:05.603",
        "lastModified": "2026-07-28T18:10:22.967",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62496",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 534,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62497",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.736Z",
      "date_published": "2026-07-21T21:39:38.492Z",
      "date_updated": "2026-07-22T15:35:16.840Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Flow Manufacturing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11528
      },
      "nvd": {
        "published": "2026-07-21T22:19:05.720",
        "lastModified": "2026-07-28T18:10:14.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62497",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 731,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62498",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.736Z",
      "date_published": "2026-07-21T21:39:38.804Z",
      "date_updated": "2026-07-22T15:36:45.833Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Flow Manufacturing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25188
      },
      "nvd": {
        "published": "2026-07-21T22:19:05.830",
        "lastModified": "2026-07-28T18:10:07.843",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62498",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a privilege boundary failure in Oracle Flow Manufacturing but does not disclose the missing or mismatched authorization check.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62503",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.737Z",
      "date_published": "2026-07-21T21:39:39.117Z",
      "date_updated": "2026-07-22T15:41:38.320Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Time and Labor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00314,
        "percentile": 0.23795
      },
      "nvd": {
        "published": "2026-07-21T22:19:05.933",
        "lastModified": "2026-07-28T18:09:47.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62503",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Time and Labor permits an unauthorized caller to perform a protected operation, but the exact authorization decision is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 830,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62504",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.737Z",
      "date_published": "2026-07-21T21:39:39.437Z",
      "date_updated": "2026-07-22T15:42:18.447Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Time and Labor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11529
      },
      "nvd": {
        "published": "2026-07-21T22:19:06.047",
        "lastModified": "2026-07-28T18:09:40.777",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62504",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "A low-privilege HTTP caller can read and modify critical Time and Labor data, but Oracle does not publish the missing object or role check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62505",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.737Z",
      "date_published": "2026-07-21T21:39:39.752Z",
      "date_updated": "2026-07-22T15:21:52.127Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Time and Labor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14011
      },
      "nvd": {
        "published": "2026-07-21T22:19:06.160",
        "lastModified": "2026-07-28T18:09:30.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62505",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Oracle reports unauthenticated read and write impact in Time and Labor with victim interaction but does not disclose the request or engineering cause.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 878,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62507",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.737Z",
      "date_published": "2026-07-21T21:39:40.059Z",
      "date_updated": "2026-07-22T15:22:35.666Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Time and Labor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08934
      },
      "nvd": {
        "published": "2026-07-21T22:19:06.263",
        "lastModified": "2026-07-28T18:09:23.233",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62507",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Time and Labor user can modify critical data outside the assigned role, but the affected object or authorization rule is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62508",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.737Z",
      "date_published": "2026-07-21T21:39:40.376Z",
      "date_updated": "2026-07-22T15:23:48.498Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Time and Labor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14115
      },
      "nvd": {
        "published": "2026-07-21T22:19:06.380",
        "lastModified": "2026-07-28T18:09:14.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62508",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle Time and Labor path lets attacker-controlled work, memory, recursion, or retained resources grow without an effective bound or release condition.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62513",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.737Z",
      "date_published": "2026-07-21T21:39:40.692Z",
      "date_updated": "2026-07-22T15:24:40.424Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Regulatory Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06755
      },
      "nvd": {
        "published": "2026-07-21T22:19:06.493",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62513",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged HTTP caller can exceed assigned authority in Oracle Scripting, but the CPU table does not identify the protected operation or failing check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 959,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62514",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.738Z",
      "date_published": "2026-07-21T21:39:41.005Z",
      "date_updated": "2026-07-22T15:25:23.455Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Process Manufacturing Regulatory Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18129
      },
      "nvd": {
        "published": "2026-07-21T22:19:06.610",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62514",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-62514 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 830,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62515",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.738Z",
      "date_published": "2026-07-21T21:39:41.334Z",
      "date_updated": "2026-07-29T19:14:38.057Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Planning Command Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00308,
        "percentile": 0.2308
      },
      "nvd": {
        "published": "2026-07-21T22:19:06.723",
        "lastModified": "2026-07-29T20:17:10.473",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62515",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Advanced Planning Command Center permits a high-privilege HTTP caller to read and modify data beyond its remaining authority, while the check is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 905,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.738Z",
      "date_published": "2026-07-21T21:39:41.655Z",
      "date_updated": "2026-07-22T15:27:26.762Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Demantra Demand Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16518
      },
      "nvd": {
        "published": "2026-07-21T22:19:06.827",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62516",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Demantra Demand Management incorporates attacker-controlled input into an SQL statement without parameterization, allowing input syntax to alter the database query.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-89",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62517",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.738Z",
      "date_published": "2026-07-21T21:39:41.965Z",
      "date_updated": "2026-07-22T14:06:09.753Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Production Scheduling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03981
      },
      "nvd": {
        "published": "2026-07-21T22:19:06.937",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62517",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record combines authenticity, redirect, and password-recovery weakness classes without describing a concrete path that selects one primary cause.",
        "basis": [
          "CNA",
          "CWE-345",
          "CWE-601",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": "Editor attention: CWE-345, CWE-601, and CWE-640 imply different mechanisms, and the description does not resolve which one is primary."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 679,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62518",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.738Z",
      "date_published": "2026-07-21T21:39:42.277Z",
      "date_updated": "2026-07-22T15:18:58.967Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Production Scheduling"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21494
      },
      "nvd": {
        "published": "2026-07-21T22:19:07.053",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62518",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Production Scheduling lets a low-privileged HTTP user read, modify, and disrupt protected data outside the intended scope, but the failing check is not public.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 841,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62519",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.738Z",
      "date_published": "2026-07-21T21:39:42.589Z",
      "date_updated": "2026-07-22T15:18:15.682Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Succession planning"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.1634
      },
      "nvd": {
        "published": "2026-07-21T22:19:07.167",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62519",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle Succession Planning permits a low-privileged HTTP caller to access protected data outside the intended permissions, while the exact validation and permission check are not public.",
        "basis": [
          "CNA",
          "CWE-20",
          "CWE-200",
          "CWE-284",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 804,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62521",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.738Z",
      "date_published": "2026-07-21T21:39:43.253Z",
      "date_updated": "2026-07-22T15:17:13.644Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (US)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00397,
        "percentile": 0.32472
      },
      "nvd": {
        "published": "2026-07-21T22:19:07.280",
        "lastModified": "2026-07-27T17:56:46.123",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62521",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle HRMS (US) permits an operation beyond the caller's authority; the exact failing identity, role, or object check is not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 558,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62524",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.739Z",
      "date_published": "2026-07-21T21:39:43.559Z",
      "date_updated": "2026-07-22T15:16:24.806Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (US)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09343
      },
      "nvd": {
        "published": "2026-07-21T22:19:07.397",
        "lastModified": "2026-07-27T17:56:36.473",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62524",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle identifies unauthorized HRMS reads, writes, and service loss but does not publish the privilege or object binding that fails.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 759,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62525",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.739Z",
      "date_published": "2026-07-21T21:39:43.888Z",
      "date_updated": "2026-07-22T15:15:28.255Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Quality"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00189,
        "percentile": 0.08817
      },
      "nvd": {
        "published": "2026-07-21T22:19:07.503",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62525",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 758,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.739Z",
      "date_published": "2026-07-21T21:39:44.205Z",
      "date_updated": "2026-07-22T13:46:56.854Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Learning Management"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09626
      },
      "nvd": {
        "published": "2026-07-21T22:19:07.617",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62527",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle maps the Learning Management issue to SQL injection, while the public CPU does not identify the query, input or construction path.",
        "basis": [
          "CNA",
          "CWE-89",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 806,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62528",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.739Z",
      "date_published": "2026-07-21T21:39:44.539Z",
      "date_updated": "2026-07-22T13:49:10.653Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HCM Configuration Workbench"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09627
      },
      "nvd": {
        "published": "2026-07-21T22:19:07.730",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62528",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 836,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.739Z",
      "date_published": "2026-07-21T21:39:44.860Z",
      "date_updated": "2026-07-22T13:54:21.846Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (France)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11528
      },
      "nvd": {
        "published": "2026-07-21T22:19:07.877",
        "lastModified": "2026-07-24T18:34:34.897",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62530",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read and modify HRMS France data beyond its authority, but Oracle does not disclose the protected object or check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 700,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62534",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.739Z",
      "date_published": "2026-07-21T21:39:45.175Z",
      "date_updated": "2026-07-22T14:04:00.468Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14178
      },
      "nvd": {
        "published": "2026-07-21T22:19:07.990",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62534",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged Applications Framework caller can reach takeover-capable Web Utilities authority, but the failed check is not public.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-284",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 550,
        "referenceCount": 1,
        "cweCount": 4,
        "cnaCweCount": 0,
        "adpCweCount": 4,
        "nvdCweCount": 4,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62542",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.740Z",
      "date_published": "2026-07-21T21:39:45.501Z",
      "date_updated": "2026-07-22T14:02:28.564Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self Service Benefits).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Advanced Benefits"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08844
      },
      "nvd": {
        "published": "2026-07-21T22:19:08.100",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62542",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The product permits an action beyond the caller's intended authority, but the public record does not disclose the protected object or failed check.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 800,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62546",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.740Z",
      "date_published": "2026-07-21T21:39:45.820Z",
      "date_updated": "2026-07-22T14:01:39.868Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Applications Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18632
      },
      "nvd": {
        "published": "2026-07-21T22:19:08.213",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62546",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A high-privilege Web Utilities user can cross into takeover authority, but the exact authorization boundary and failed check are not public.",
        "basis": [
          "CNA record",
          "CWE-284",
          "Oracle July 2026 CPU"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.oracle.com/security-alerts/cpujul2026.html; the official matrix confirms Oracle Applications Framework Web Utilities, HTTP, high privileges, changed scope, and affected versions but publishes no endpoint or authorization rule."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 681,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62547",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.740Z",
      "date_published": "2026-07-21T21:39:46.137Z",
      "date_updated": "2026-07-22T13:20:14.622Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Workflow"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14698
      },
      "nvd": {
        "published": "2026-07-21T22:19:08.323",
        "lastModified": "2026-07-28T13:59:02.953",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62547",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Oracle Workflow exposes a security-sensitive endpoint without requiring caller authentication.",
        "basis": [
          "CNA",
          "CWE-287",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 525,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62548",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.740Z",
      "date_published": "2026-07-21T21:39:46.454Z",
      "date_updated": "2026-07-22T13:22:10.601Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (US)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.265
      },
      "nvd": {
        "published": "2026-07-21T22:19:08.433",
        "lastModified": "2026-07-27T17:56:32.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62548",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle U.S. HRMS lets a high-privileged HTTP user reach a takeover action, but the missing action-level check is not public.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 517,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62549",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.740Z",
      "date_published": "2026-07-21T21:39:46.786Z",
      "date_updated": "2026-07-22T13:23:02.526Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (UK)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19492
      },
      "nvd": {
        "published": "2026-07-21T22:19:08.543",
        "lastModified": "2026-07-27T17:56:28.583",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62549",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged HTTP caller can read and modify critical HRMS UK Payroll data, but the CPU does not disclose the object or authorization check.",
        "basis": [
          "CNA",
          "CWE-284",
          "Oracle CPU July 2026"
        ],
        "deepDive": true,
        "notes": "https://www.oracle.com/security-alerts/cpujul2026.html - Oracle confirms low-privileged HTTP read/write impact in HRMS UK Payroll with scope change, but publishes no protected object or failing authorization check."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 803,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62556",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.741Z",
      "date_published": "2026-07-21T21:39:47.103Z",
      "date_updated": "2026-07-22T13:23:59.525Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (US)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00261,
        "percentile": 0.17784
      },
      "nvd": {
        "published": "2026-07-21T22:19:08.653",
        "lastModified": "2026-07-27T17:56:24.447",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62556",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public Oracle record reports HRMS data disclosure but does not identify the endpoint or failing access-control predicate.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62557",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.741Z",
      "date_published": "2026-07-21T21:39:47.421Z",
      "date_updated": "2026-07-22T13:40:24.424Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (UK)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12932
      },
      "nvd": {
        "published": "2026-07-21T22:19:08.763",
        "lastModified": "2026-07-27T17:56:20.223",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62557",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can read and modify UK Payroll data beyond its role, but the protected object and failing check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 662,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62559",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.741Z",
      "date_published": "2026-07-21T21:39:47.737Z",
      "date_updated": "2026-07-22T13:42:34.817Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (US)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14904
      },
      "nvd": {
        "published": "2026-07-21T22:19:08.877",
        "lastModified": "2026-07-27T17:56:14.927",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62559",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle HRMS (US) path authorizes a caller, role, or object without enforcing the required identity and scope binding.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 675,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62560",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.741Z",
      "date_published": "2026-07-21T21:39:48.101Z",
      "date_updated": "2026-07-22T13:07:44.907Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (Norway)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11527
      },
      "nvd": {
        "published": "2026-07-21T22:19:08.987",
        "lastModified": "2026-07-27T17:56:03.920",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62560",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A caller can reach protected data or functionality without the required access-control binding, but the omitted check is not disclosed.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 690,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62561",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.741Z",
      "date_published": "2026-07-21T21:39:48.412Z",
      "date_updated": "2026-07-22T13:08:37.793Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (US)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03824
      },
      "nvd": {
        "published": "2026-07-21T22:19:09.103",
        "lastModified": "2026-07-27T17:55:59.177",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62561",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Oracle HRMS (US) privilege path permits a lower-trust actor to acquire or exercise a role beyond the actor's assigned authority.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62562",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.741Z",
      "date_published": "2026-07-21T21:39:48.786Z",
      "date_updated": "2026-07-22T13:12:58.543Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (US)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11556
      },
      "nvd": {
        "published": "2026-07-21T22:19:09.213",
        "lastModified": "2026-07-27T17:55:54.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62562",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A low-privileged HTTP caller can cross an Oracle HRMS data boundary, but the protected object and failing authorization check are not public.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62563",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.741Z",
      "date_published": "2026-07-21T21:39:50.112Z",
      "date_updated": "2026-07-22T13:12:14.180Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Work in Process"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00083,
        "percentile": 0.00298
      },
      "nvd": {
        "published": "2026-07-21T22:19:09.327",
        "lastModified": "2026-07-23T18:29:34.653",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62563",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Oracle Work in Process accepts a request across an unintended network or origin boundary, while the request field and validation step are not public.",
        "basis": [
          "CNA",
          "CWE-285",
          "CWE-352",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 882,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62565",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.741Z",
      "date_published": "2026-07-21T21:39:50.522Z",
      "date_updated": "2026-07-22T13:11:02.753Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (US)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07805
      },
      "nvd": {
        "published": "2026-07-21T22:19:09.440",
        "lastModified": "2026-07-27T17:55:49.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62565",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Oracle reports that a low-privileged HRMS user can read and modify data but does not publish the object or failing permission check.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-269",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 671,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 0,
        "adpCweCount": 3,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62567",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.742Z",
      "date_published": "2026-07-21T21:39:50.836Z",
      "date_updated": "2026-07-22T13:09:59.043Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle HRMS (UK)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11555
      },
      "nvd": {
        "published": "2026-07-21T22:19:09.553",
        "lastModified": "2026-07-27T17:47:58.280",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62567",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 665,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 0,
        "adpCweCount": 2,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62574",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T14:54:48.742Z",
      "date_published": "2026-07-21T21:39:51.149Z",
      "date_updated": "2026-08-01T03:56:49.775Z",
      "publisher": "oracle",
      "title": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Install).",
      "affected": {
        "vendors": [
          "Oracle Corporation"
        ],
        "products": [
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle Java SE"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM for JDK"
          },
          {
            "vendor": "Oracle Corporation",
            "product": "Oracle GraalVM Enterprise Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 9,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert_us@oracle.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01574
      },
      "nvd": {
        "published": "2026-07-21T22:19:09.667",
        "lastModified": "2026-08-03T18:37:03.210",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62574",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an access-control failure but does not disclose the exact caller, object, action or permission check that is bound incorrectly.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "host": "www.oracle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 899,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-62641",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T15:46:28.729Z",
      "date_published": "2026-07-14T15:46:29.138Z",
      "date_updated": "2026-07-14T17:27:50.013Z",
      "publisher": "mitre",
      "title": "In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.",
      "affected": {
        "vendors": [
          "Roundcube"
        ],
        "products": [
          {
            "vendor": "Roundcube",
            "product": "Webmail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16658
      },
      "nvd": {
        "published": "2026-07-14T16:17:04.377",
        "lastModified": "2026-07-20T12:56:55.210",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62641",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Roundcube TNEF decoder trusts a crafted compressed-RTF size as work or allocation without an effective upper bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2",
          "host": "roundcube.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.7.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/commit/6d1004fd3764a9606c53130b322c0f295c38be64",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.6.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/commit/bf253c72d4293c93fda511b8464fe9cb34b522c1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 143,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62642",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T15:49:17.389Z",
      "date_published": "2026-07-14T15:49:17.798Z",
      "date_updated": "2026-07-14T17:18:18.192Z",
      "publisher": "mitre",
      "title": "In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.",
      "affected": {
        "vendors": [
          "Roundcube"
        ],
        "products": [
          {
            "vendor": "Roundcube",
            "product": "Webmail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19892
      },
      "nvd": {
        "published": "2026-07-14T16:17:04.530",
        "lastModified": "2026-07-20T12:55:28.270",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62642",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Webmail accepts input that leaves a processing loop without a reachable progress or exit condition.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2",
          "host": "roundcube.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.7.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/commit/877269c79359d959a94f13c9070cab0f3389c193",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/commit/fb952956c6eaf29e963f1a718d028d66e7957ce0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.6.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/commit/a007321346380136b3de2bd75b486b04f63c0d38",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/commit/132ac8dd5a55c8466be12de1daf84355697ffa89",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 193,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62643",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T15:51:46.593Z",
      "date_published": "2026-07-14T15:51:46.996Z",
      "date_updated": "2026-07-14T17:17:16.894Z",
      "publisher": "mitre",
      "title": "In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts....",
      "affected": {
        "vendors": [
          "Roundcube"
        ],
        "products": [
          {
            "vendor": "Roundcube",
            "product": "Webmail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 2.8,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15962
      },
      "nvd": {
        "published": "2026-07-14T16:17:04.670",
        "lastModified": "2026-07-20T12:50:11.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62643",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Insufficient CSS sanitization lets an email stylesheet URL direct Roundcube's server-side fetches to local network hosts.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2",
          "host": "roundcube.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.7.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/commit/6d69e094d55d3a9a84dfb36edf6ca985311f0c1c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.6.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/commit/294c7da6e7284166f040cef8607b677d459e0786",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62644",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T15:55:22.524Z",
      "date_published": "2026-07-14T15:55:22.925Z",
      "date_updated": "2026-07-14T17:15:20.139Z",
      "publisher": "mitre",
      "title": "In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.",
      "affected": {
        "vendors": [
          "Roundcube"
        ],
        "products": [
          {
            "vendor": "Roundcube",
            "product": "Webmail"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 3.4000000000000004,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17504
      },
      "nvd": {
        "published": "2026-07-14T16:17:04.810",
        "lastModified": "2026-07-20T12:41:22.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62644",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Roundcube's password plugin trusts a username taken from spoofable session data rather than binding the password action to the authenticated account.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2",
          "host": "roundcube.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.7.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/commit/7414fef51cd2407d39faab99680763f10ed5231d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/commit/9a96c20d8c7c9135876b68bebd6960af3ee60923",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.6.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/commit/83150ce04d689a70f92d511bcae40adba8d55476",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035f4491e877e4c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62655",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T16:31:02.508Z",
      "date_published": "2026-07-14T17:46:14.452Z",
      "date_updated": "2026-07-15T16:52:24.542Z",
      "publisher": "NETGEAR",
      "title": "A DoS vulnerability due to stack overflow exists in certain NETGEAR Orbi models",
      "affected": {
        "vendors": [
          "NETGEAR"
        ],
        "products": [
          {
            "vendor": "NETGEAR",
            "product": "RBR860"
          },
          {
            "vendor": "NETGEAR",
            "product": "RBRE950"
          },
          {
            "vendor": "NETGEAR",
            "product": "RBRE960"
          },
          {
            "vendor": "NETGEAR",
            "product": "RBE970"
          },
          {
            "vendor": "NETGEAR",
            "product": "RBE971"
          },
          {
            "vendor": "NETGEAR",
            "product": "RBS860"
          },
          {
            "vendor": "NETGEAR",
            "product": "RBSE950"
          },
          {
            "vendor": "NETGEAR",
            "product": "RBSE960"
          }
        ],
        "affectedBlockCount": 8,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "NVD:a2826606-91e7-4eb6-899e-8484bd4575d5",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10954
      },
      "nvd": {
        "published": "2026-07-14T18:18:47.510",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62655",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Certain Orbi firmware processes adjacent-network input into a fixed stack buffer without a sufficient length bound.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.netgear.com/support/product/rbr860/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.netgear.com/support/product/rbre950/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.netgear.com/support/product/rbs860/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.netgear.com/support/product/rbre960/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.netgear.com/support/product/rbse950/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.netgear.com/support/product/rbse960/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory",
          "host": "kb.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 8,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-62656",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T16:31:02.508Z",
      "date_published": "2026-07-14T17:46:15.194Z",
      "date_updated": "2026-07-15T16:53:59.077Z",
      "publisher": "NETGEAR",
      "title": "Post-authenticated command injection vulnerability found in certain NETGEAR RAX models",
      "affected": {
        "vendors": [
          "NETGEAR"
        ],
        "products": [
          {
            "vendor": "NETGEAR",
            "product": "RAXE450"
          },
          {
            "vendor": "NETGEAR",
            "product": "RAXE500"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "NVD:a2826606-91e7-4eb6-899e-8484bd4575d5",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05958
      },
      "nvd": {
        "published": "2026-07-14T18:18:47.707",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62656",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A crafted authenticated router request reaches an operating-system command without separating the supplied data from command syntax.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.netgear.com/support/product/raxe450/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.netgear.com/support/product/raxe500/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory",
          "host": "kb.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 278,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62657",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T16:31:02.508Z",
      "date_published": "2026-07-14T17:46:13.757Z",
      "date_updated": "2026-07-15T16:56:03.166Z",
      "publisher": "NETGEAR",
      "title": "Certificate validation vulnerability in NETGEAR Gaming Router and certain Nighthawk models",
      "affected": {
        "vendors": [
          "NETGEAR"
        ],
        "products": [
          {
            "vendor": "NETGEAR",
            "product": "MR70"
          },
          {
            "vendor": "NETGEAR",
            "product": "MS70"
          },
          {
            "vendor": "NETGEAR",
            "product": "RAXE500"
          },
          {
            "vendor": "NETGEAR",
            "product": "XR1000"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-599",
          "name": "Missing Validation of OpenSSL Certificate",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber"
        },
        {
          "source": "NVD:a2826606-91e7-4eb6-899e-8484bd4575d5",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00105,
        "percentile": 0.01237
      },
      "nvd": {
        "published": "2026-07-14T18:18:47.857",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62657",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The router accepts a remote certificate without completing the required certificate validation before granting control.",
        "basis": [
          "CNA",
          "CWE-599"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.netgear.com/support/product/mr70/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.netgear.com/support/product/raxe500/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.netgear.com/support/product/ms70/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.netgear.com/support/product/xr1000/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory",
          "host": "kb.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-62658",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T16:31:02.509Z",
      "date_published": "2026-07-14T17:46:12.018Z",
      "date_updated": "2026-07-15T17:01:41.135Z",
      "publisher": "NETGEAR",
      "title": "Post-authentication Command Injection Vulnerability in certain Nighthawk RAX series models",
      "affected": {
        "vendors": [
          "NETGEAR"
        ],
        "products": [
          {
            "vendor": "NETGEAR",
            "product": "RAX43"
          },
          {
            "vendor": "NETGEAR",
            "product": "RAX45"
          },
          {
            "vendor": "NETGEAR",
            "product": "RAX50"
          },
          {
            "vendor": "NETGEAR",
            "product": "RAX54S"
          },
          {
            "vendor": "NETGEAR",
            "product": "RAX54Sv2"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"
        },
        {
          "source": "NVD:a2826606-91e7-4eb6-899e-8484bd4575d5",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00193,
        "percentile": 0.0921
      },
      "nvd": {
        "published": "2026-07-14T18:18:48.013",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62658",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The authenticated router handler passes attacker-controlled data into an operating-system command without shell-context neutralization.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.netgear.com/support/product/rax43/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.netgear.com/support/product/rax45/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.netgear.com/support/product/rax50/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://www.netgear.com/support/product/rax54sv2/",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory",
          "host": "kb.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 187,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-62659",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T16:31:02.509Z",
      "date_published": "2026-07-14T17:48:45.532Z",
      "date_updated": "2026-07-15T16:04:55.710Z",
      "publisher": "NETGEAR",
      "title": "Authenticated users can make unauthorized changes on NETGEAR WAX333 Access Points",
      "affected": {
        "vendors": [
          "NETGEAR"
        ],
        "products": [
          {
            "vendor": "NETGEAR",
            "product": "WAX333"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/V:D/RE:L/U:Amber"
        },
        {
          "source": "NVD:a2826606-91e7-4eb6-899e-8484bd4575d5",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09389
      },
      "nvd": {
        "published": "2026-07-14T18:18:48.177",
        "lastModified": "2026-07-15T18:20:21.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62659",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The public record for CVE-2026-62659 states affected scope and impact but does not identify a failing check, parser boundary, state transition, resource limit, object selection, or memory-lifetime error that supports a mechanism family.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.netgear.com/support/product/wax333",
          "host": "www.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory",
          "host": "kb.netgear.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62663",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T20:22:04.394Z",
      "date_published": "2026-07-30T16:16:34.159Z",
      "date_updated": "2026-07-30T17:38:15.444Z",
      "publisher": "GitHub_M",
      "title": "Banks: Arbitrary File Read via Path Traversal in Media Filters (image/audio/video/document)",
      "affected": {
        "vendors": [
          "masci"
        ],
        "products": [
          {
            "vendor": "masci",
            "product": "banks"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26109
      },
      "nvd": {
        "published": "2026-07-30T17:16:33.900",
        "lastModified": "2026-07-30T19:26:51.190",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62663",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The media filters pass template-controlled paths directly to open without canonicalization or confinement to an approved directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/masci/banks/security/advisories/GHSA-98rr-gvc9-3cjh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 879,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62683",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T20:22:04.395Z",
      "date_published": "2026-07-15T15:40:56.485Z",
      "date_updated": "2026-07-15T18:02:39.173Z",
      "publisher": "GitHub_M",
      "title": "File Browser: Trailing-slash delete leaves a stale public share behind",
      "affected": {
        "vendors": [
          "filebrowser"
        ],
        "products": [
          {
            "vendor": "filebrowser",
            "product": "filebrowser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09793
      },
      "nvd": {
        "published": "2026-07-15T16:16:51.637",
        "lastModified": "2026-07-15T19:18:38.437",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62683",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Path normalization occurs after a database prefix query, so a trailing slash can leave a stale share record outside the normalized-path invariant.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-pp88-jhwj-5qh5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/filebrowser/filebrowser/commit/f30fca636c1af9ef401e9a82ff60391cb3db97e1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/filebrowser/filebrowser/releases/tag/v2.63.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 663,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T20:22:04.395Z",
      "date_published": "2026-07-15T15:47:23.539Z",
      "date_updated": "2026-07-20T14:51:55.327Z",
      "publisher": "GitHub_M",
      "title": "File Browser: Colliding username normalization gives two users the same home directory",
      "affected": {
        "vendors": [
          "filebrowser"
        ],
        "products": [
          {
            "vendor": "filebrowser",
            "product": "filebrowser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-647",
          "name": "Use of Non-Canonical URL Paths for Authorization Decisions",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-706",
          "name": "Use of Incorrectly-Resolved Name or Reference",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24719
      },
      "nvd": {
        "published": "2026-07-15T16:16:51.783",
        "lastModified": "2026-07-20T16:17:06.420",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62685",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "File Browser normalizes distinct signup usernames to the same home-directory scope without checking for a collision.",
        "basis": [
          "CNA",
          "CWE-647",
          "CWE-706"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7rc3-g7h6-22m7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/filebrowser/filebrowser/commit/883a36f02fcb69566a8628cb47f18fdc73348387",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/filebrowser/filebrowser/releases/tag/v2.63.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 594,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T21:02:12.369Z",
      "date_published": "2026-07-17T08:35:57.234Z",
      "date_updated": "2026-07-17T10:07:38.455Z",
      "publisher": "apache",
      "title": "Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Accumulo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-274",
          "name": "Improper Handling of Insufficient Privileges",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Green"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:L/U:Green"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21744
      },
      "nvd": {
        "published": "2026-07-17T09:16:41.853",
        "lastModified": "2026-07-17T18:08:44.860",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62764",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Apache Accumulo accepts a graceful-shutdown command from an authenticated user who lacks the required system permission.",
        "basis": [
          "CNA",
          "CWE-274"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/accumulo/issues/6478",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://accumulo.apache.org/release/accumulo-2.1.6/",
          "host": "accumulo.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://accumulo.apache.org/downloads/",
          "host": "accumulo.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/qclg736k93oqn4qrpw9wxjbb3jhn6gm1",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/17/6",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 455,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62825",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T21:10:38.082Z",
      "date_published": "2026-07-24T00:01:13.490Z",
      "date_updated": "2026-08-03T22:59:16.291Z",
      "publisher": "microsoft",
      "title": "Azure Key Vault Elevation of Privilege Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure Key Vault"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00697,
        "percentile": 0.49503
      },
      "nvd": {
        "published": "2026-07-24T01:17:47.030",
        "lastModified": "2026-07-25T05:16:42.430",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62825",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Microsoft confirms an unauthenticated Azure Key Vault privilege-escalation path but does not disclose the credential, tenant, or object binding that fails.",
        "basis": [
          "CNA",
          "CWE-287",
          "MSRC SUG API"
        ],
        "deepDive": true,
        "notes": "https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2026-62825 was inspected; Microsoft confirms CWE-287, the critical score, and no known exploitation, but publishes no failing identity check."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62825",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62826",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T21:10:38.082Z",
      "date_published": "2026-07-16T22:02:45.447Z",
      "date_updated": "2026-08-03T22:59:05.813Z",
      "publisher": "microsoft",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Enterprise Server 2016"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server 2019"
          },
          {
            "vendor": "Microsoft",
            "product": "Microsoft SharePoint Server Subscription Edition"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.8000000000000007,
      "epss": {
        "score": 0.00331,
        "percentile": 0.25615
      },
      "nvd": {
        "published": "2026-07-16T22:17:52.720",
        "lastModified": "2026-07-22T11:15:03.833",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62826",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62826",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-62828",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T21:10:38.082Z",
      "date_published": "2026-07-28T15:07:06.891Z",
      "date_updated": "2026-08-03T22:59:07.109Z",
      "publisher": "microsoft",
      "title": "Microsoft Edge for Android (Chromium-based) Tampering Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Microsoft Edge for Android"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.1517
      },
      "nvd": {
        "published": "2026-07-28T16:19:42.337",
        "lastModified": "2026-07-28T16:22:01.443",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62828",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Microsoft identifies only improper input validation and remote tampering in Edge for Android, without publishing the input, parser or state transition that fails.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62828",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62835",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T21:10:38.083Z",
      "date_published": "2026-07-24T19:21:31.995Z",
      "date_updated": "2026-08-03T22:59:17.865Z",
      "publisher": "microsoft",
      "title": "Azure Portal Information Disclosure Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure Portal"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 1.8000000000000007,
      "epss": {
        "score": 0.00973,
        "percentile": 0.58597
      },
      "nvd": {
        "published": "2026-07-24T20:18:19.410",
        "lastModified": "2026-07-29T15:01:25.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62835",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated network caller can read protected Azure Portal information, but Microsoft does not disclose the object or failed authorization check.",
        "basis": [
          "CNA",
          "CWE-285",
          "Microsoft Security Update Guide API"
        ],
        "deepDive": true,
        "notes": "Inspected https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability?$filter=cveNumber%20eq%20'CVE-2026-62835' and https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62835; Microsoft confirms improper authorization, network information disclosure, score 9.3, and completed service mitigation, but does not disclose the protected Azure Portal object or missing check."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62835",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 110,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62843",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T21:10:50.031Z",
      "date_published": "2026-07-15T15:42:19.122Z",
      "date_updated": "2026-07-15T16:32:21.438Z",
      "publisher": "GitHub_M",
      "title": "File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)",
      "affected": {
        "vendors": [
          "filebrowser"
        ],
        "products": [
          {
            "vendor": "filebrowser",
            "product": "filebrowser"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17471
      },
      "nvd": {
        "published": "2026-07-15T16:16:52.160",
        "lastModified": "2026-07-15T18:15:13.373",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62843",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Archive creation converts backslashes in a POSIX filename into separators and emits traversal entries that escape a recipient's extraction directory.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-83xp-526h-j3ww",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/filebrowser/filebrowser/commit/8503ba61ff51d48a7313896483d130eb6a5abfe0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/filebrowser/filebrowser/releases/tag/v2.63.17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 554,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62845",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T21:10:50.031Z",
      "date_published": "2026-07-30T21:10:10.512Z",
      "date_updated": "2026-07-31T11:18:41.336Z",
      "publisher": "GitHub_M",
      "title": "Kamaji: SQL injection via unescaped datastore identifiers in PostgreSQL/MySQL drivers",
      "affected": {
        "vendors": [
          "clastix"
        ],
        "products": [
          {
            "vendor": "clastix",
            "product": "kamaji"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09514
      },
      "nvd": {
        "published": "2026-07-30T22:16:55.457",
        "lastModified": "2026-07-31T12:16:53.010",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62845",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled SQL identifiers are interpolated directly into a query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/clastix/kamaji/security/advisories/GHSA-r47v-ppwp-fh4r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/clastix/kamaji/commit/6a9f3e10ae408e7948e2aca2db694791a299e79c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/clastix/kamaji/releases/tag/26.7.4-edge",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62946",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T22:32:17.731Z",
      "date_published": "2026-07-30T00:06:16.176Z",
      "date_updated": "2026-07-30T14:14:23.353Z",
      "publisher": "GitHub_M",
      "title": "ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0.39999999999999947,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02466
      },
      "nvd": {
        "published": "2026-07-30T00:16:25.353",
        "lastModified": "2026-08-03T16:19:22.763",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62946",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A JNX dimension calculation overflows on 32-bit builds and produces a heap buffer smaller than the subsequent write.",
        "basis": [
          "CNA record",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h22j-f9xw-xjjm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 333,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-62947",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T22:32:17.731Z",
      "date_published": "2026-07-15T17:55:12.240Z",
      "date_updated": "2026-07-15T19:31:18.877Z",
      "publisher": "GitHub_M",
      "title": "OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download",
      "affected": {
        "vendors": [
          "openwrt"
        ],
        "products": [
          {
            "vendor": "openwrt",
            "product": "openwrt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00401,
        "percentile": 0.32856
      },
      "nvd": {
        "published": "2026-07-15T19:18:38.533",
        "lastModified": "2026-07-21T16:06:10.347",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62947",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "openwrt accepts an attacker-controlled path that can resolve outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openwrt/openwrt/security/advisories/GHSA-jw5r-xhf5-2xcq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/openwrt/cgi-io/pull/4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openwrt/cgi-io/commit/72990b7489872112df31c94032637c907760bae4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openwrt/openwrt/releases/tag/v25.12.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62948",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T22:32:17.731Z",
      "date_published": "2026-07-15T17:50:43.790Z",
      "date_updated": "2026-07-15T18:08:36.882Z",
      "publisher": "GitHub_M",
      "title": "OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI",
      "affected": {
        "vendors": [
          "openwrt"
        ],
        "products": [
          {
            "vendor": "openwrt",
            "product": "openwrt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-117",
          "name": "Improper Output Neutralization for Logs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-150",
          "name": "Improper Neutralization of Escape, Meta, or Control Sequences",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00358,
        "percentile": 0.28459
      },
      "nvd": {
        "published": "2026-07-15T18:16:50.293",
        "lastModified": "2026-07-21T16:06:30.357",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62948",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "odhcpd writes an unescaped DHCPv6 hostname into a line-oriented lease file, allowing forged records that LuCI later renders as live HTML.",
        "basis": [
          "CNA",
          "CWE-79",
          "CWE-117",
          "CWE-150"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openwrt/openwrt/security/advisories/GHSA-hhmc-92hw-535f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/openwrt/odhcpd/pull/404",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openwrt/luci/commit/55379d04fcc3c605003a5001d6135cf02ae6048a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openwrt/odhcpd/commit/68f382690bfaec56d5b1f31c3c31c48bcb642e3a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/openwrt/openwrt/releases/tag/v25.12.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 567,
        "referenceCount": 5,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62959",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T22:32:17.732Z",
      "date_published": "2026-07-31T19:57:06.394Z",
      "date_updated": "2026-07-31T23:34:33.361Z",
      "publisher": "GitHub_M",
      "title": "Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)",
      "affected": {
        "vendors": [
          "coturn"
        ],
        "products": [
          {
            "vendor": "coturn",
            "product": "coturn"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-195",
          "name": "Signed to Unsigned Conversion Error",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31111
      },
      "nvd": {
        "published": "2026-07-31T20:16:53.357",
        "lastModified": "2026-08-01T00:17:17.610",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62959",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Coturn converts a negative length to an unsigned size and copies uninitialized receive-buffer residue into the ACME redirect Location header.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-195"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coturn/coturn/security/advisories/GHSA-m23x-5qf5-988g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coturn/coturn/pull/1965",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coturn/coturn/commit/960835886692fa04cf63ddd970c3f330740c87f4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coturn/coturn/releases/tag/4.15.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 664,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62963",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T22:32:17.732Z",
      "date_published": "2026-07-16T19:34:48.882Z",
      "date_updated": "2026-07-17T13:46:40.652Z",
      "publisher": "GitHub_M",
      "title": "Centrifugo: Decompression bomb DoS via permessage-deflate in unidirectional WebSocket transport",
      "affected": {
        "vendors": [
          "centrifugal"
        ],
        "products": [
          {
            "vendor": "centrifugal",
            "product": "centrifugo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-409",
          "name": "Improper Handling of Highly Compressed Data (Data Amplification)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22416
      },
      "nvd": {
        "published": "2026-07-16T20:16:47.533",
        "lastModified": "2026-07-17T18:44:13.257",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62963",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected decompression path limits compressed input without imposing a corresponding limit on expanded output.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-409"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/centrifugal/centrifugo/security/advisories/GHSA-q6mr-3g59-5m8x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/centrifugal/centrifugo/pull/1162",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/centrifugal/centrifugo/commit/46d40e4ac3a5446c9745f8b219197166ae12a6e5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/centrifugal/centrifugo/releases/tag/v6.8.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 510,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62994",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T23:10:57.031Z",
      "date_published": "2026-07-16T19:39:05.582Z",
      "date_updated": "2026-07-17T11:12:51.792Z",
      "publisher": "GitHub_M",
      "title": "CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin",
      "affected": {
        "vendors": [
          "coredns"
        ],
        "products": [
          {
            "vendor": "coredns",
            "product": "coredns"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-755",
          "name": "Improper Handling of Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21752
      },
      "nvd": {
        "published": "2026-07-16T20:16:47.657",
        "lastModified": "2026-07-22T20:14:36.067",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-62994",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The CoreDNS transfer plugin indexes records[0] without checking whether k8s_external emitted an empty AXFR batch.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-248",
          "CWE-755"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coredns/coredns/security/advisories/GHSA-74w3-63xv-x9mv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coredns/coredns/pull/8207",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coredns/coredns/commit/ab318db7b4a3a19273852ed627f54888198c8efb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/coredns/coredns/releases/tag/v1.14.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 603,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62995",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T23:10:57.032Z",
      "date_published": "2026-07-29T18:27:06.518Z",
      "date_updated": "2026-07-30T14:32:13.148Z",
      "publisher": "GitHub_M",
      "title": "joserfc accepts JWT with padding, leading to JWT malleability",
      "affected": {
        "vendors": [
          "authlib"
        ],
        "products": [
          {
            "vendor": "authlib",
            "product": "joserfc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00106,
        "percentile": 0.01282
      },
      "nvd": {
        "published": "2026-07-29T19:16:50.837",
        "lastModified": "2026-07-30T19:59:01.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62995",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "joserfc accepts JWT compact encodings with trailing base64 padding that the relevant canonical encoding rules reject, weakening verification of the serialized token form.",
        "basis": [
          "CNA",
          "CWE-345"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/authlib/joserfc/security/advisories/GHSA-5jhw-7jv7-qcqq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 875,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-62999",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-14T23:10:57.032Z",
      "date_published": "2026-07-31T19:41:55.494Z",
      "date_updated": "2026-07-31T19:59:30.346Z",
      "publisher": "GitHub_M",
      "title": "Copier: Percent-encoded dot segments in template URLs can allow trusted-prefix escape (Incomplete fix for trust-prefix bypass)",
      "affected": {
        "vendors": [
          "copier-org"
        ],
        "products": [
          {
            "vendor": "copier-org",
            "product": "copier"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-180",
          "name": "Incorrect Behavior Order: Validate Before Canonicalize",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21709
      },
      "nvd": {
        "published": "2026-07-31T20:16:53.523",
        "lastModified": "2026-07-31T20:16:53.523",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-62999",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The implementation validates a trusted prefix before decoding and canonicalizing the path, then uses the changed path afterward.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-180"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/copier-org/copier/security/advisories/GHSA-34mv-rjq9-5mch",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/copier-org/copier/commit/7408f0d6287a7bf452715fd9f25dc54eaba3c295",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/copier-org/copier/releases/tag/v9.17.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 433,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63030",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T17:17:24.474Z",
      "date_published": "2026-07-17T19:14:12.910Z",
      "date_updated": "2026-07-22T03:55:46.565Z",
      "publisher": "WPScan",
      "title": "WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution",
      "affected": {
        "vendors": [
          "WordPress"
        ],
        "products": [
          {
            "vendor": "WordPress",
            "product": "WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:contact@wpscan.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 2.3000000000000007,
      "epss": {
        "score": 0.98417,
        "percentile": 0.99915
      },
      "official_kev": {
        "cveID": "CVE-2026-63030",
        "vendorProject": "WordPress",
        "product": "Core",
        "vulnerabilityName": "WordPress Core Interpretation Conflict Vulnerability",
        "dateAdded": "2026-07-21",
        "shortDescription": "WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "dueDate": "2026-07-24",
        "knownRansomwareCampaignUse": "Unknown",
        "notes": "https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-63030",
        "cwes": [
          "CWE-436"
        ]
      },
      "nvd": {
        "published": "2026-07-17T20:17:28.490",
        "lastModified": "2026-07-22T23:10:00.110",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63030",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The REST batch endpoint and downstream router interpret the selected route differently, making a separately vulnerable SQL query reachable in a chain.",
        "basis": [
          "CNA",
          "CWE-436",
          "WordPress GHSA",
          "WordPress release notice",
          "CISA KEV JSON"
        ],
        "deepDive": true,
        "notes": "Read WordPress maintainer advisory https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q, release notice https://wordpress.org/news/2026/07/wordpress-7-0-2-release/, and CISA KEV JSON https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; they confirm a REST batch-route interpretation conflict chained with CVE-2026-60137, but no fixed source path is public in those pages."
      },
      "references": [
        {
          "url": "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "technical-description",
            "vdb-entry"
          ]
        },
        {
          "url": "https://wordpress.org/news/2026/07/wordpress-7-0-2-release/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030",
          "host": "www.cisa.gov",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "US Government Resource",
            "government-resource"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63033",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T22:10:53.026Z",
      "date_published": "2026-07-30T22:54:25.681Z",
      "date_updated": "2026-07-31T19:23:47.085Z",
      "publisher": "icscert",
      "title": "MZ Automation lib60870 Out-of-bounds Read",
      "affected": {
        "vendors": [
          "MZ Automation"
        ],
        "products": [
          {
            "vendor": "MZ Automation",
            "product": "lib60870"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18088
      },
      "nvd": {
        "published": "2026-07-30T23:16:51.917",
        "lastModified": "2026-07-31T20:16:53.713",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63033",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The IEC parser trusts an I-frame count that drives a read beyond the available frame buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mz-automation/lib60870/security/advisories/GHSA-7v97-jmwv-w5j7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-11.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63035",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T15:02:47.801Z",
      "date_published": "2026-07-30T21:56:04.345Z",
      "date_updated": "2026-07-31T15:45:48.062Z",
      "publisher": "icscert",
      "title": "o6 Automation open62541 Use After Free",
      "affected": {
        "vendors": [
          "o6 Automation"
        ],
        "products": [
          {
            "vendor": "o6 Automation",
            "product": "open62541"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00572,
        "percentile": 0.44044
      },
      "nvd": {
        "published": "2026-07-30T23:16:52.070",
        "lastModified": "2026-07-31T16:17:08.760",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63035",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies a memory-safety failure in open62541, while the invalid access and object transition are not public.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.o6-automation.com/contact",
          "host": "www.o6-automation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-08.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-63047",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T08:12:23.735Z",
      "date_published": "2026-07-22T07:05:06.645Z",
      "date_updated": "2026-07-23T15:00:12.897Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1",
      "affected": {
        "vendors": [
          "joomdonation.com"
        ],
        "products": [
          {
            "vendor": "joomdonation.com",
            "product": "Events Booking extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.1417
      },
      "nvd": {
        "published": "2026-07-22T08:16:23.950",
        "lastModified": "2026-07-23T16:17:47.157",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63047",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Events Booking lets a caller download invoice data without checking that the invoice belongs to an event the caller may access.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://joomdonation.com/joomla-extensions/events-booking-joomla-events-registration.html",
          "host": "joomdonation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 261,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63048",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T08:12:23.736Z",
      "date_published": "2026-07-22T07:15:25.988Z",
      "date_updated": "2026-07-23T14:57:05.572Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2",
      "affected": {
        "vendors": [
          "joomlack.fr"
        ],
        "products": [
          {
            "vendor": "joomlack.fr",
            "product": "Page Builder CK extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13361
      },
      "nvd": {
        "published": "2026-07-22T08:16:24.063",
        "lastModified": "2026-07-23T16:17:47.320",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63048",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path accepts attacker-controlled file content or names without enforcing the intended storage and executable-content boundary.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomlack.fr/",
          "host": "www.joomlack.fr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 195,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63071",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T12:33:03.203Z",
      "date_published": "2026-07-20T14:19:19.065Z",
      "date_updated": "2026-07-21T14:57:32.285Z",
      "publisher": "apache",
      "title": "Apache Syncope: RCE via Groovy Sandbox bypass",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Syncope"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-653",
          "name": "Improper Isolation or Compartmentalization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00439,
        "percentile": 0.36119
      },
      "nvd": {
        "published": "2026-07-20T15:16:45.093",
        "lastModified": "2026-07-27T14:58:11.113",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63071",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Apache Syncope lets an administrator create a Groovy class that crosses the sandbox boundary and executes operations the sandbox policy intended to deny.",
        "basis": [
          "CNA",
          "CWE-653"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/2236mlm6hbvs6g16yqz5y9s8bb7q1lo1",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/11",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 489,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-63077",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:12:38.892Z",
      "date_published": "2026-07-27T16:44:32.290Z",
      "date_updated": "2026-07-28T03:56:41.288Z",
      "publisher": "JetBrains",
      "title": "In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "TeamCity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00649,
        "percentile": 0.47564
      },
      "nvd": {
        "published": "2026-07-27T17:16:38.830",
        "lastModified": "2026-07-28T16:17:58.820",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63077",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The TeamCity agent polling protocol permits an unauthenticated HTTP(S) peer to bypass server authentication checks before reaching operating-system command execution.",
        "basis": [
          "CNA",
          "CWE-502",
          "https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/",
          "https://www.jetbrains.com/privacy-security/issues-fixed/"
        ],
        "deepDive": true,
        "notes": "JetBrains confirms that an unauthenticated HTTP(S) peer can use the TeamCity agent polling protocol to bypass authentication and execute operating-system commands, but does not publish the request fields, handler, or patch lines."
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63080",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.600Z",
      "date_published": "2026-07-21T21:02:08.641Z",
      "date_updated": "2026-07-22T18:24:56.728Z",
      "publisher": "VulnCheck",
      "title": "Aptabase SQL Injection via ClickHouse query backend",
      "affected": {
        "vendors": [
          "aptabase"
        ],
        "products": [
          {
            "vendor": "aptabase",
            "product": "aptabase"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14854
      },
      "nvd": {
        "published": "2026-07-21T21:16:52.567",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63080",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Aptabase inserts attacker-controlled filter values into Liquid-generated ClickHouse SQL without safe binding, allowing the app_id tenant predicate to be bypassed.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://yoyochaud.fr/en/chaud/cve-2026-63080-aptabase-sql-injection/",
          "host": "yoyochaud.fr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/aptabase-sql-injection-via-clickhouse-query-backend",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 506,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.600Z",
      "date_published": "2026-07-16T15:33:54.972Z",
      "date_updated": "2026-07-18T02:54:07.692Z",
      "publisher": "VulnCheck",
      "title": "Perfect Support Ticketing System 1.7 Stored XSS via Ticket Notes Field",
      "affected": {
        "vendors": [
          "Ultimate Fosters"
        ],
        "products": [
          {
            "vendor": "Ultimate Fosters",
            "product": "Perfect Support Ticketing & Document Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03639
      },
      "nvd": {
        "published": "2026-07-16T16:19:16.210",
        "lastModified": "2026-07-18T03:16:37.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63081",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Ticket notes accept agent-controlled script content and later render it to other users without HTML-context encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-63081",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/perfect-support-ticketing-system-stored-xss-via-ticket-notes-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 489,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.600Z",
      "date_published": "2026-07-16T15:35:50.782Z",
      "date_updated": "2026-07-16T16:15:50.464Z",
      "publisher": "VulnCheck",
      "title": "Perfect Support Ticketing System 1.7 Broken Access Control via Agent Assignment",
      "affected": {
        "vendors": [
          "Ultimate Fosters"
        ],
        "products": [
          {
            "vendor": "Ultimate Fosters",
            "product": "Perfect Support Ticketing & Document Management System"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05195
      },
      "nvd": {
        "published": "2026-07-16T16:19:16.343",
        "lastModified": "2026-07-16T17:16:58.317",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63082",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An agent can add or remove arbitrary users in a ticket's support-agent field without the role permission required to manage that assignment.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aaronamran/CVE-Disclosures/blob/main/CVE-2026/CVE-2026-63082",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/perfect-support-ticketing-system-broken-access-control-via-agent-assignment",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 463,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.600Z",
      "date_published": "2026-07-16T15:56:34.573Z",
      "date_updated": "2026-07-17T18:13:14.938Z",
      "publisher": "VulnCheck",
      "title": "Axelor Open Platform 8.x < 8.2.2 Authorization Bypass via Nested Relational Record Persistence",
      "affected": {
        "vendors": [
          "axelor"
        ],
        "products": [
          {
            "vendor": "axelor",
            "product": "axelor-open-platform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29792
      },
      "nvd": {
        "published": "2026-07-16T17:16:58.420",
        "lastModified": "2026-07-17T19:17:18.893",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63085",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Nested relational saves bypass restricted User fields and let the persistence layer commit attacker-supplied administrator role and group assignments.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/axelor-open-platform.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/axelor/axelor-open-platform/releases/tag/v8.2.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/axelor-open-platform-8-x-authorization-bypass-via-nested-relational-record-persistence",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63086",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.600Z",
      "date_published": "2026-07-16T15:59:45.871Z",
      "date_updated": "2026-07-16T17:41:55.297Z",
      "publisher": "VulnCheck",
      "title": "text-generation-inference 3.3.7 SSRF via fetch_image in multimodal chat completions",
      "affected": {
        "vendors": [
          "huggingface"
        ],
        "products": [
          {
            "vendor": "huggingface",
            "product": "text-generation-inference"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24743
      },
      "nvd": {
        "published": "2026-07-16T17:16:58.553",
        "lastModified": "2026-07-16T18:16:44.453",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63086",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The text-generation-inference request path lets a caller choose a server-side destination outside the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/text-generation-inference.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/text-generation-inference-ssrf-via-fetch-image-in-multimodal-chat-completions",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 714,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63087",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.600Z",
      "date_published": "2026-07-16T16:03:55.866Z",
      "date_updated": "2026-07-23T13:25:46.253Z",
      "publisher": "VulnCheck",
      "title": "Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint",
      "affected": {
        "vendors": [
          "grafana-cold-storage"
        ],
        "products": [
          {
            "vendor": "grafana-cold-storage",
            "product": "oncall"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00427,
        "percentile": 0.35149
      },
      "nvd": {
        "published": "2026-07-16T17:16:58.703",
        "lastModified": "2026-07-17T14:17:27.073",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63087",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The plugin install endpoint issues an authentication token without authenticating the caller and relies on public default identifiers.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/oncall.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grafana-oncall-unauthenticated-token-hijack-via-plugin-install-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 630,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63088",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.600Z",
      "date_published": "2026-07-16T16:40:56.120Z",
      "date_updated": "2026-07-16T18:00:29.429Z",
      "publisher": "VulnCheck",
      "title": "stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass",
      "affected": {
        "vendors": [
          "stoatchat"
        ],
        "products": [
          {
            "vendor": "stoatchat",
            "product": "stoatchat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29799
      },
      "nvd": {
        "published": "2026-07-16T17:16:58.833",
        "lastModified": "2026-07-16T19:16:51.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63088",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The URL blocklist validates only the first DNS address while the HTTP client may connect to a later private or metadata address.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-4mcc-p83c-r77q",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/stoatchat/stoatchat/releases/tag/v0.14.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-xhww-5g9p-vvq5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.vulncheck.com/advisories/stoatchat-ssrf-via-dns-based-ip-blocklist-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 368,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63089",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.600Z",
      "date_published": "2026-07-16T19:28:37.500Z",
      "date_updated": "2026-07-18T03:08:24.596Z",
      "publisher": "VulnCheck",
      "title": "WireGuard Easy Weak Token Generation Information Disclosure via OTL Route",
      "affected": {
        "vendors": [
          "wg-easy"
        ],
        "products": [
          {
            "vendor": "wg-easy",
            "product": "wg-easy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14903
      },
      "nvd": {
        "published": "2026-07-16T20:16:47.800",
        "lastModified": "2026-07-18T03:16:37.597",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63089",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "wg-easy derives an authentication token or login key from a non-cryptographic generator with too little entropy to resist guessing.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-338",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/wg-easy/wg-easy/pull/2661",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/wg-easy/wg-easy/commit/66b292b11bde3664f05ffb016c8082665d261ded",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/wireguard-easy-weak-token-generation-information-disclosure-via-otl-route",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 626,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63090",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.600Z",
      "date_published": "2026-07-20T14:22:03.712Z",
      "date_updated": "2026-07-28T01:49:57.243Z",
      "publisher": "VulnCheck",
      "title": "ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly",
      "affected": {
        "vendors": [
          "proftpd"
        ],
        "products": [
          {
            "vendor": "proftpd",
            "product": "proftpd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00455,
        "percentile": 0.37256
      },
      "nvd": {
        "published": "2026-07-20T15:16:45.213",
        "lastModified": "2026-07-30T17:19:14.403",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63090",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mod_sftp reassembles oversized packet fragments into a fixed 16 KB heap buffer under an incorrect reallocation condition.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/proftpd/proftpd/releases/tag/v1.3.10rc3-3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/proftpd/proftpd/releases/tag/v1.3.9c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/proftpd/proftpd/issues/2190",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/proftpd/proftpd/commit/4ee8701bcf425f11b3b2116e634ff3e655d918b1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/proftpd-mod-sftp-heap-buffer-overflow-via-sftp-packet-reassembly",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Release Notes",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 574,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63091",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.600Z",
      "date_published": "2026-07-20T14:22:29.202Z",
      "date_updated": "2026-07-28T01:49:57.949Z",
      "publisher": "VulnCheck",
      "title": "ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser",
      "affected": {
        "vendors": [
          "proftpd"
        ],
        "products": [
          {
            "vendor": "proftpd",
            "product": "proftpd"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-126",
          "name": "Buffer Over-read",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21267
      },
      "nvd": {
        "published": "2026-07-20T15:16:45.363",
        "lastModified": "2026-07-30T17:18:19.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63091",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ProFTPD converts an overflowing SCP size into a huge unsigned read length and writes process memory beyond the channel data into the uploaded file.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-126",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/proftpd/proftpd/releases/tag/v1.3.10rc3-3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/proftpd/proftpd/releases/tag/v1.3.9c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/proftpd/proftpd/pull/2201",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/proftpd/proftpd/commit/b9b7dde1bcd74bc23366484d53856b67b8d6d95e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/proftpd-mod-sftp-signed-integer-overflow-via-scp-size-record-parser",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Release Notes",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 789,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63092",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.600Z",
      "date_published": "2026-07-21T20:50:18.823Z",
      "date_updated": "2026-07-23T18:18:19.099Z",
      "publisher": "VulnCheck",
      "title": "kirby-modules License Key Disclosure via modules/activate Dialog",
      "affected": {
        "vendors": [
          "medienbaecker"
        ],
        "products": [
          {
            "vendor": "medienbaecker",
            "product": "kirby-modules"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06449
      },
      "nvd": {
        "published": "2026-07-21T21:16:52.703",
        "lastModified": "2026-07-23T19:17:03.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63092",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The activation dialog relies on access.system defaulting to true and therefore executes without an explicit administrator authorization check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/medienbaecker/kirby-modules/commit/315417e4fa9f18682e4382c9f44c04bd0913ce96",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/kirby-modules-license-key-disclosure-via-modules-activate-dialog",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 636,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63093",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.601Z",
      "date_published": "2026-07-17T14:23:41.848Z",
      "date_updated": "2026-07-28T01:49:58.652Z",
      "publisher": "VulnCheck",
      "title": "Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace",
      "affected": {
        "vendors": [
          "Anysphere, Inc."
        ],
        "products": [
          {
            "vendor": "Anysphere, Inc.",
            "product": "Cursor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-426",
          "name": "Untrusted Search Path",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37135
      },
      "nvd": {
        "published": "2026-07-17T15:16:47.817",
        "lastModified": "2026-07-17T18:28:53.707",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63093",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Cursor searches the untrusted workspace for git.exe and automatically executes the planted binary before establishing trust.",
        "basis": [
          "CNA",
          "CWE-426"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left",
          "host": "mindgard.ai",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://cursor.com/",
          "host": "cursor.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cursor-for-windows-rce-via-malicious-git-exe-in-workspace",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63094",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.601Z",
      "date_published": "2026-07-17T14:22:22.677Z",
      "date_updated": "2026-07-27T17:17:11.454Z",
      "publisher": "VulnCheck",
      "title": "SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft",
      "affected": {
        "vendors": [
          "SigNoz"
        ],
        "products": [
          {
            "vendor": "SigNoz",
            "product": "signoz"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-345",
          "name": "Insufficient Verification of Data Authenticity",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06802
      },
      "nvd": {
        "published": "2026-07-17T15:16:47.960",
        "lastModified": "2026-07-27T18:16:57.610",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63094",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SigNoz accepts an attacker-selected SSO return destination and redirects a victim's session token to that external location.",
        "basis": [
          "CNA",
          "CWE-345",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/SigNoz/signoz/issues/11746",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/SigNoz/signoz/releases/tag/v0.134.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/SigNoz/signoz/pull/12172",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/SigNoz/signoz/commit/253ca7dd7eb4f7a32a694c249eb0d5d0804d5619",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/signoz-sso-oauth-state-manipulation-session-token-theft",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 496,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63095",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.601Z",
      "date_published": "2026-07-17T15:27:44.640Z",
      "date_updated": "2026-07-28T01:49:59.362Z",
      "publisher": "VulnCheck",
      "title": "Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint",
      "affected": {
        "vendors": [
          "matrix-org"
        ],
        "products": [
          {
            "vendor": "matrix-org",
            "product": "dendrite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00182,
        "percentile": 0.08004
      },
      "nvd": {
        "published": "2026-07-17T16:17:16.467",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63095",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account deletion endpoint without ownership verification.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/dendrite.md#finding-1-idor-in-post-account3piddelete-allows-any-authenticated-user-to-remove-any-other-users-third-party-identifier",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dendrite-improper-authorization-via-post-account-3pid-delete-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63096",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.601Z",
      "date_published": "2026-07-17T15:30:28.771Z",
      "date_updated": "2026-07-28T01:50:00.068Z",
      "publisher": "VulnCheck",
      "title": "Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint",
      "affected": {
        "vendors": [
          "matrix-org"
        ],
        "products": [
          {
            "vendor": "matrix-org",
            "product": "dendrite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00212,
        "percentile": 0.11594
      },
      "nvd": {
        "published": "2026-07-17T16:17:16.630",
        "lastModified": "2026-07-17T19:17:19.017",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63096",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the legacy media download endpoint.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/dendrite.md#finding-2-unauthenticated-ssrf-and-internal-port-scanner-via-legacy-_matrixmediar0download",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dendrite-ssrf-via-unauthenticated-legacy-media-download-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63097",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.601Z",
      "date_published": "2026-07-17T15:32:45.411Z",
      "date_updated": "2026-07-28T01:50:00.775Z",
      "publisher": "VulnCheck",
      "title": "Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure",
      "affected": {
        "vendors": [
          "matrix-org"
        ],
        "products": [
          {
            "vendor": "matrix-org",
            "product": "dendrite"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05626
      },
      "nvd": {
        "published": "2026-07-17T16:17:16.783",
        "lastModified": "2026-07-23T20:17:19.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63097",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The room-context membership check tests only that the room exists and ignores whether the requester is still in the room.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/dendrite.md#finding-3-context-returns-current-room-state-to-non-members-and-left-users-history-visibility-bypass",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dendrite-syncapi-context-endpoint-post-leave-state-exposure",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63098",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.601Z",
      "date_published": "2026-07-17T15:38:08.061Z",
      "date_updated": "2026-07-28T01:50:01.477Z",
      "publisher": "VulnCheck",
      "title": "TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint",
      "affected": {
        "vendors": [
          "TheHive-Project"
        ],
        "products": [
          {
            "vendor": "TheHive-Project",
            "product": "TheHive"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24085
      },
      "nvd": {
        "published": "2026-07-17T16:17:16.947",
        "lastModified": "2026-07-30T14:25:41.573",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63098",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TheHive's status handler returns passwords and authentication, MFA and cluster configuration without enforcing authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/TheHive.md#finding-1-get-apistatus-exposes-attachment-protection-password-without-authentication",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/thehive-unauthenticated-information-disclosure-via-api-status-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63099",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.601Z",
      "date_published": "2026-07-17T15:39:44.235Z",
      "date_updated": "2026-07-28T01:05:27.422Z",
      "publisher": "VulnCheck",
      "title": "TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endpoints",
      "affected": {
        "vendors": [
          "TheHive-Project"
        ],
        "products": [
          {
            "vendor": "TheHive-Project",
            "product": "TheHive"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11132
      },
      "nvd": {
        "published": "2026-07-17T16:17:17.107",
        "lastModified": "2026-07-17T18:04:04.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63099",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/TheHive.md#finding-2-cross-organisation-attachment-disclosure-via-unauthorized-datastore-endpoint-missing-object-level-authorization",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/thehive-broken-object-level-authorization-via-attachment-download-endpoints",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 433,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63100",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.601Z",
      "date_published": "2026-07-17T15:45:05.695Z",
      "date_updated": "2026-07-21T01:40:13.213Z",
      "publisher": "VulnCheck",
      "title": "Maybe 0.6.0 Missing Authorization via HostingsController show/update",
      "affected": {
        "vendors": [
          "maybe-finance"
        ],
        "products": [
          {
            "vendor": "maybe-finance",
            "product": "maybe"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11133
      },
      "nvd": {
        "published": "2026-07-17T16:17:17.263",
        "lastModified": "2026-07-21T03:16:42.337",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63100",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "maybe exposes a protected action without checking the caller's required permission.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/maybe.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/maybe-missing-authorization-via-hostingscontroller-show-update",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 608,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63101",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.601Z",
      "date_published": "2026-07-17T15:51:06.118Z",
      "date_updated": "2026-07-17T18:05:19.803Z",
      "publisher": "VulnCheck",
      "title": "Open Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export Endpoint",
      "affected": {
        "vendors": [
          "fossasia"
        ],
        "products": [
          {
            "vendor": "fossasia",
            "product": "open-event-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22571
      },
      "nvd": {
        "published": "2026-07-17T17:17:17.283",
        "lastModified": "2026-07-17T19:17:19.147",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63101",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An export endpoint and its task-status endpoint omit authentication and return any enumerated group's member roster.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/open-event-server.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/open-event-server-unauthenticated-member-roster-export-via-csv-export-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 580,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63102",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.601Z",
      "date_published": "2026-07-20T15:31:17.648Z",
      "date_updated": "2026-07-28T01:05:28.145Z",
      "publisher": "VulnCheck",
      "title": "rConfig Core < 8.2.8 Privilege Escalation via Users API role field",
      "affected": {
        "vendors": [
          "rConfig"
        ],
        "products": [
          {
            "vendor": "rConfig",
            "product": "rConfig v8 Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15944
      },
      "nvd": {
        "published": "2026-07-20T16:17:06.540",
        "lastModified": "2026-07-23T15:25:33.113",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63102",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A role field is mass-assigned without enforcing the administrator authority required to grant it.",
        "basis": [
          "CNA",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rconfig/rconfig/releases/tag/core-8.2.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/rconfig/rconfig/pull/325",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/rconfig/rconfig/commit/84822f4051ed97d651b1b4d191c6da2aa8c3c037",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rconfig-privilege-escalation-via-users-api-role-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 508,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63107",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.602Z",
      "date_published": "2026-07-20T18:14:01.625Z",
      "date_updated": "2026-07-28T01:05:28.861Z",
      "publisher": "VulnCheck",
      "title": "LimeSurvey SSRF via REST API Survey Template Host Header",
      "affected": {
        "vendors": [
          "LimeSurvey"
        ],
        "products": [
          {
            "vendor": "LimeSurvey",
            "product": "LimeSurvey"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11132
      },
      "nvd": {
        "published": "2026-07-20T19:17:28.913",
        "lastModified": "2026-07-23T20:17:20.100",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63107",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "getTemplateData trusts the HTTP Host header when selecting the server-side request destination.",
        "basis": [
          "CNA record",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/limesurvey.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/limesurvey-ssrf-via-rest-api-survey-template-host-header",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 503,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63108",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T15:45:44.602Z",
      "date_published": "2026-07-20T18:24:14.583Z",
      "date_updated": "2026-07-28T01:05:29.570Z",
      "publisher": "VulnCheck",
      "title": "Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing",
      "affected": {
        "vendors": [
          "RooCodeInc"
        ],
        "products": [
          {
            "vendor": "RooCodeInc",
            "product": "Roo-Code"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-184",
          "name": "Incomplete List of Disallowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.01919,
        "percentile": 0.77872
      },
      "nvd": {
        "published": "2026-07-20T19:17:29.057",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63108",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Roo-Code uses an incomplete disallowed-input rule that misses executable syntax.",
        "basis": [
          "CNA",
          "CWE-184"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/Roo-Code.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/roo-code-command-injection-via-parameter-expansion-parsing",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 593,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63118",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T16:54:55.816Z",
      "date_published": "2026-07-29T19:07:33.452Z",
      "date_updated": "2026-07-29T19:35:10.375Z",
      "publisher": "GitHub_M",
      "title": "MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection",
      "affected": {
        "vendors": [
          "modelcontextprotocol"
        ],
        "products": [
          {
            "vendor": "modelcontextprotocol",
            "product": "ruby-sdk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-350",
          "name": "Reliance on Reverse DNS Resolution for a Security-Critical Action",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09819
      },
      "nvd": {
        "published": "2026-07-29T20:17:10.630",
        "lastModified": "2026-07-30T19:30:33.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63118",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The streamable HTTP transport accepts browser requests without validating Host or Origin, allowing DNS rebinding into a local MCP server.",
        "basis": [
          "CNA",
          "CWE-346",
          "CWE-350"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-rjr6-rcgv-9m7m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/commit/ba543083a7594e7892b29464b89091816446ff7a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63119",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T16:54:55.816Z",
      "date_published": "2026-07-29T19:12:07.687Z",
      "date_updated": "2026-07-29T19:28:41.352Z",
      "publisher": "GitHub_M",
      "title": "MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)",
      "affected": {
        "vendors": [
          "modelcontextprotocol"
        ],
        "products": [
          {
            "vendor": "modelcontextprotocol",
            "product": "ruby-sdk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02945
      },
      "nvd": {
        "published": "2026-07-29T20:17:10.790",
        "lastModified": "2026-07-30T19:30:33.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63119",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Ruby MCP stdio transports call IO.gets without a byte limit, allowing a peer that withholds a newline to grow the line buffer without bound.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-7683-3w9x-ch42",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/commit/267b8fa6285453525c81ce43db6b7dcd7a8a8c2f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63136",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:23:57.165Z",
      "date_published": "2026-07-21T20:20:07.409Z",
      "date_updated": "2026-07-22T19:41:00.574Z",
      "publisher": "elastic",
      "title": "Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Elasticsearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14516
      },
      "nvd": {
        "published": "2026-07-21T21:16:52.850",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63136",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A crafted authenticated Elasticsearch query can drive heap allocation until a data node exhausts memory, but the allocating query feature is not public.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/elasticsearch-8-19-15-9-2-9-9-3-4-security-update-esa-2026-60/388559",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-63139",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:23:57.166Z",
      "date_published": "2026-07-21T20:35:06.391Z",
      "date_updated": "2026-07-22T19:40:41.549Z",
      "publisher": "elastic",
      "title": "Uncontrolled Resource Consumption in Kibana Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18095
      },
      "nvd": {
        "published": "2026-07-21T21:16:52.957",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63139",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A crafted Canvas request consumes an undisclosed Kibana resource until the server process terminates.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-63/388560",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-63140",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:23:57.166Z",
      "date_published": "2026-07-21T21:04:01.143Z",
      "date_updated": "2026-07-22T19:40:22.260Z",
      "publisher": "elastic",
      "title": "Reachable Assertion in Elasticsearch Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Elasticsearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00235,
        "percentile": 0.14515
      },
      "nvd": {
        "published": "2026-07-21T21:16:53.073",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63140",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Elasticsearch request path lets attacker-controlled input reach a process-terminating assertion.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-security-update-esa-2026-64/388565",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 697,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-63141",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:23:57.166Z",
      "date_published": "2026-07-21T21:08:36.423Z",
      "date_updated": "2026-07-22T19:39:06.627Z",
      "publisher": "elastic",
      "title": "Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management Functions",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10341
      },
      "nvd": {
        "published": "2026-07-21T22:19:09.787",
        "lastModified": "2026-07-22T20:37:38.603",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63141",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A protected operation lacks the role, ownership, or object-scope check required for the requesting caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-9-3-8-9-4-4-security-update-esa-2026-65/388566",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63142",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:23:57.166Z",
      "date_published": "2026-07-21T22:04:28.699Z",
      "date_updated": "2026-07-22T13:35:35.459Z",
      "publisher": "elastic",
      "title": "Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06803
      },
      "nvd": {
        "published": "2026-07-21T23:18:02.110",
        "lastModified": "2026-08-03T17:57:11.103",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63142",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Kibana Reporting omits inputs from its outbound-request deny-list, allowing an authenticated user to reach destinations that policy explicitly denies.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-66/388568",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-63143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:23:57.166Z",
      "date_published": "2026-07-21T22:09:42.735Z",
      "date_updated": "2026-07-22T13:31:18.863Z",
      "publisher": "elastic",
      "title": "Missing Authorization in Kibana Leading to Unauthorized Information Disclosure",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.002,
        "percentile": 0.09997
      },
      "nvd": {
        "published": "2026-07-21T23:18:02.230",
        "lastModified": "2026-08-03T17:49:47.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63143",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kibana lets a limited user retrieve workflow outputs without the permission required for those output objects.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-9-3-8-9-4-4-security-update-esa-2026-67/388569",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 480,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:23:57.166Z",
      "date_published": "2026-07-21T22:26:43.138Z",
      "date_updated": "2026-07-22T13:27:01.544Z",
      "publisher": "elastic",
      "title": "Uncontrolled Recursion in Elasticsearch Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Elasticsearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15212
      },
      "nvd": {
        "published": "2026-07-21T23:18:02.343",
        "lastModified": "2026-08-03T16:07:28.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63144",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-security-update-esa-2026-68/388571",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-63145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T18:23:57.166Z",
      "date_published": "2026-07-21T22:31:16.741Z",
      "date_updated": "2026-07-22T13:21:54.722Z",
      "publisher": "elastic",
      "title": "Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromise",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05726
      },
      "nvd": {
        "published": "2026-07-21T23:18:02.460",
        "lastModified": "2026-08-03T17:49:02.370",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63145",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The endpoint validates only a coarse privilege level but does not verify that the requesting user has access to the specific Machine Learning job or notification resources provided in the request.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-69/388572",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 927,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-63175",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T21:26:19.040Z",
      "date_published": "2026-07-15T21:26:26.659Z",
      "date_updated": "2026-07-16T12:51:47.951Z",
      "publisher": "CIRCL",
      "title": "Cross-Capture Session Data Leakage Due to Shared Mutable State in Looklyloo - PlaywrightCapture",
      "affected": {
        "vendors": [
          "Lookyloo"
        ],
        "products": [
          {
            "vendor": "Lookyloo",
            "product": "PlaywrightCapture"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21743
      },
      "nvd": {
        "published": "2026-07-15T22:17:38.193",
        "lastModified": "2026-07-16T14:16:56.717",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63175",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PlaywrightCapture stores per-capture credentials, cookies, headers, and results in mutable class variables shared by concurrent instances.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Lookyloo/PlaywrightCapture/commit/1e354b9d8566f49dbb331410be24c7c295645d43",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1142,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T22:19:06.907Z",
      "date_published": "2026-07-31T03:50:27.294Z",
      "date_updated": "2026-07-31T13:58:31.522Z",
      "publisher": "GitHub_M",
      "title": "CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()",
      "affected": {
        "vendors": [
          "codeigniter4"
        ],
        "products": [
          {
            "vendor": "codeigniter4",
            "product": "CodeIgniter4"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-348",
          "name": "Use of Less Trusted Source",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03415
      },
      "nvd": {
        "published": "2026-07-31T04:17:24.337",
        "lastModified": "2026-07-31T14:16:50.750",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63220",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CodeIgniter trusts forwarding headers from an untrusted peer when deriving the request's client or scheme identity.",
        "basis": [
          "CNA",
          "CWE-348"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-7wmf-pw8j-mc78",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/commit/ecbf044666bed41d23f07518096d9843fe6c08b0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 788,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63221",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T22:19:06.907Z",
      "date_published": "2026-07-31T04:03:34.352Z",
      "date_updated": "2026-07-31T13:52:40.376Z",
      "publisher": "GitHub_M",
      "title": "CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions",
      "affected": {
        "vendors": [
          "codeigniter4"
        ],
        "products": [
          {
            "vendor": "codeigniter4",
            "product": "CodeIgniter4"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00377,
        "percentile": 0.30429
      },
      "nvd": {
        "published": "2026-07-31T06:16:31.603",
        "lastModified": "2026-07-31T14:16:50.873",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63221",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-c9w5-rwh3-7pm9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/commit/f5e463b9a3e986389ce285963e51a7f1fab6559f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63222",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T22:19:06.907Z",
      "date_published": "2026-07-31T04:06:19.448Z",
      "date_updated": "2026-07-31T15:58:43.539Z",
      "publisher": "GitHub_M",
      "title": "CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames",
      "affected": {
        "vendors": [
          "codeigniter4"
        ],
        "products": [
          {
            "vendor": "codeigniter4",
            "product": "CodeIgniter4"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0045,
        "percentile": 0.36907
      },
      "nvd": {
        "published": "2026-07-31T06:16:31.953",
        "lastModified": "2026-07-31T16:17:08.903",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63222",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CodeIgniter4 accepts a caller-controlled path without confining resolution to the intended directory namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-hhmc-q9hp-r662",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/commit/20ebcf4694d96d3c97fbc3938e360730e4f54618",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 372,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63223",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-15T22:19:06.907Z",
      "date_published": "2026-07-31T04:10:28.179Z",
      "date_updated": "2026-07-31T23:16:24.574Z",
      "publisher": "GitHub_M",
      "title": "CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules",
      "affected": {
        "vendors": [
          "codeigniter4"
        ],
        "products": [
          {
            "vendor": "codeigniter4",
            "product": "CodeIgniter4"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00493,
        "percentile": 0.39665
      },
      "nvd": {
        "published": "2026-07-31T06:16:32.297",
        "lastModified": "2026-08-01T00:17:17.750",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63223",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Upload validation trusts MIME or image checks without independently restricting the client filename extension before web-accessible storage.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-mmj4-63m4-r6h5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/commit/b6e9a4fa1dca2df3d3f261bdf61532df8c6420aa",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/codeigniter4/CodeIgniter4/releases/tag/v4.7.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 677,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T01:18:29.934Z",
      "date_published": "2026-07-23T05:28:37.714Z",
      "date_updated": "2026-07-23T14:14:15.963Z",
      "publisher": "jpcert",
      "title": "Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd.",
      "affected": {
        "vendors": [
          "Ricoh Company"
        ],
        "products": [
          {
            "vendor": "Ricoh Company",
            "product": "Ricoh printers and Multifunction Printers (MFPs)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-923",
          "name": "Improper Restriction of Communication Channel to Intended Endpoints",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vultures@jpcert.or.jp",
          "type": "Secondary",
          "version": "3.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00223,
        "percentile": 0.13024
      },
      "nvd": {
        "published": "2026-07-23T06:16:49.037",
        "lastModified": "2026-07-23T15:17:43.437",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63226",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Ricoh devices allow authenticated SSH users to open port-forwarding channels to arbitrary LAN destinations without a destination policy.",
        "basis": [
          "CNA",
          "CWE-923"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2026-000006",
          "host": "www.ricoh.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jp.ricoh.com/security/products/vulnerabilities/vul?id=ricoh-2026-000006",
          "host": "jp.ricoh.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://jvn.jp/en/jp/JVN32082029/",
          "host": "jvn.jp",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63227",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:33:02.673Z",
      "date_published": "2026-07-29T06:05:49.837Z",
      "date_updated": "2026-07-29T15:23:37.653Z",
      "publisher": "CSA",
      "title": "Unrestricted SCORM file upload vulnerability",
      "affected": {
        "vendors": [
          "An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server."
        ],
        "products": [
          {
            "vendor": "An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25339
      },
      "nvd": {
        "published": "2026-07-29T07:16:41.967",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63227",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The LMS accepts a SCORM archive containing a PHP file and stores it in a web-accessible executable directory without a dangerous-type restriction.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63228",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:33:02.673Z",
      "date_published": "2026-07-29T06:08:36.350Z",
      "date_updated": "2026-07-29T15:23:31.886Z",
      "publisher": "CSA",
      "title": "Unrestricted image upload vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.6,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.0288
      },
      "nvd": {
        "published": "2026-07-29T07:16:42.160",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63228",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Koollab LMS upload path accepts a dangerous file type without enforcing the intended executable-file boundary.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 243,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63229",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:33:02.673Z",
      "date_published": "2026-07-29T06:09:59.344Z",
      "date_updated": "2026-07-29T19:25:12.904Z",
      "publisher": "CSA",
      "title": "Pre-authentication blind SQL injection vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21854
      },
      "nvd": {
        "published": "2026-07-29T07:16:42.267",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63229",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SSO OAuth endpoint incorporates unauthenticated input into SQL and exposes the result through a timing oracle.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63230",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:33:02.673Z",
      "date_published": "2026-07-29T06:11:58.862Z",
      "date_updated": "2026-07-29T15:23:22.173Z",
      "publisher": "CSA",
      "title": "Pre-authentication error-based SQL injection vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21854
      },
      "nvd": {
        "published": "2026-07-29T07:16:42.373",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63230",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Koollab LMS, attacker-controlled values reach an SQL statement without the required escaping or parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63231",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:33:02.674Z",
      "date_published": "2026-07-29T06:13:49.303Z",
      "date_updated": "2026-07-29T15:23:14.267Z",
      "publisher": "CSA",
      "title": "Post-authentication SQL injection vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16689
      },
      "nvd": {
        "published": "2026-07-29T07:16:42.490",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63231",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Koollab LMS incorporates attacker-controlled values or identifiers into a SQL statement without preserving the boundary between query syntax and data.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:33:02.674Z",
      "date_published": "2026-07-29T06:16:25.752Z",
      "date_updated": "2026-07-29T15:23:07.824Z",
      "publisher": "CSA",
      "title": "SQL injection and unsafe deserialisation vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21699
      },
      "nvd": {
        "published": "2026-07-29T07:16:42.600",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63232",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The assessment reinforcement endpoint accepts attacker-controlled SQL syntax, which then lets the attacker control bytes passed to PHP unserialize.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63233",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:33:02.674Z",
      "date_published": "2026-07-29T06:19:14.193Z",
      "date_updated": "2026-07-29T15:22:58.114Z",
      "publisher": "CSA",
      "title": "SQL injection and unsafe deserialisation vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21699
      },
      "nvd": {
        "published": "2026-07-29T07:16:42.710",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63233",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Koollab lets SQL-controlled data reach unserialize(), enabling an authenticated attacker to construct an object chain and write an executable webshell.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63234",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:33:02.674Z",
      "date_published": "2026-07-29T06:22:01.996Z",
      "date_updated": "2026-07-29T15:22:51.961Z",
      "publisher": "CSA",
      "title": "SQL injection and unsafe deserialisation vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21699
      },
      "nvd": {
        "published": "2026-07-29T07:16:42.817",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63234",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled SQL syntax reaches a query and selects serialized data that is then passed to an unsafe deserializer.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 292,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63235",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:33:02.674Z",
      "date_published": "2026-07-29T06:23:33.494Z",
      "date_updated": "2026-07-29T14:32:09.066Z",
      "publisher": "CSA",
      "title": "Improper access control vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09497
      },
      "nvd": {
        "published": "2026-07-29T07:16:42.923",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63235",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The login kickout endpoint terminates any account session based only on a supplied email address and no caller authorization.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63236",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:33:02.674Z",
      "date_published": "2026-07-29T06:24:45.818Z",
      "date_updated": "2026-07-29T14:30:56.238Z",
      "publisher": "CSA",
      "title": "Improper access control vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06285
      },
      "nvd": {
        "published": "2026-07-29T07:16:43.027",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63236",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Koollab LMS accepts another user's SCORM object identifier without checking that the unauthenticated caller owns or may read that learning state.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 233,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63237",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:35:54.249Z",
      "date_published": "2026-07-29T06:25:52.341Z",
      "date_updated": "2026-07-29T14:29:57.945Z",
      "publisher": "CSA",
      "title": "TOTP two-factor authentication bypass vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.0192
      },
      "nvd": {
        "published": "2026-07-29T07:16:43.133",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63237",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor, potentially enabling unauthorised access to administrator accounts.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 277,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63238",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:35:54.249Z",
      "date_published": "2026-07-29T06:27:03.705Z",
      "date_updated": "2026-07-29T14:28:37.043Z",
      "publisher": "CSA",
      "title": "Authentication bypass vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00216,
        "percentile": 0.12138
      },
      "nvd": {
        "published": "2026-07-29T07:16:43.237",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63238",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID without providing primary credentials via the 2FA validation endpoint.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 251,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63239",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:35:54.249Z",
      "date_published": "2026-07-29T06:28:44.920Z",
      "date_updated": "2026-07-29T14:24:06.894Z",
      "publisher": "CSA",
      "title": "Hard-coded AWS IAM credentials vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02308
      },
      "nvd": {
        "published": "2026-07-29T07:16:43.343",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63239",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The LMS embeds reusable AWS IAM credentials that authorize access to shared multi-tenant S3 and SQS resources.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63240",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:35:54.249Z",
      "date_published": "2026-07-29T06:29:53.671Z",
      "date_updated": "2026-07-29T14:22:33.939Z",
      "publisher": "CSA",
      "title": "Information disclosure vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.0735
      },
      "nvd": {
        "published": "2026-07-29T07:16:43.460",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63240",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The course-status endpoint returns correct quiz answers to an authenticated learner before the assessment state entitles that learner to receive them.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63241",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:35:54.249Z",
      "date_published": "2026-07-29T06:30:57.071Z",
      "date_updated": "2026-07-29T14:21:35.225Z",
      "publisher": "CSA",
      "title": "Insecure direct object reference vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03834
      },
      "nvd": {
        "published": "2026-07-29T07:16:43.567",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63241",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation trusts an attacker-supplied object identifier without verifying that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63242",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T02:35:54.249Z",
      "date_published": "2026-07-29T06:32:03.383Z",
      "date_updated": "2026-07-29T14:38:01.902Z",
      "publisher": "CSA",
      "title": "Business logic vulnerability",
      "affected": {
        "vendors": [
          "Three Learning"
        ],
        "products": [
          {
            "vendor": "Three Learning",
            "product": "Koollab LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04889
      },
      "nvd": {
        "published": "2026-07-29T07:16:43.680",
        "lastModified": "2026-07-30T16:54:05.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63242",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SCORM commit endpoint accepts a completed lesson state without enforcing the prerequisite that the learner viewed the lesson.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
          "host": "www.csa.gov.sg",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 242,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63259",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T03:26:51.579Z",
      "date_published": "2026-07-21T22:37:09.404Z",
      "date_updated": "2026-07-22T13:19:33.341Z",
      "publisher": "elastic",
      "title": "Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07933
      },
      "nvd": {
        "published": "2026-07-21T23:18:02.580",
        "lastModified": "2026-08-03T17:43:23.987",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63259",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Kibana accepts a user-supplied scheduled-result identifier without binding it to the requester's authorized Space.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-9-4-4-security-update-esa-2026-70/388573",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 238,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63260",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T03:26:51.579Z",
      "date_published": "2026-07-21T22:53:44.242Z",
      "date_updated": "2026-07-22T13:08:57.152Z",
      "publisher": "elastic",
      "title": "Uncontrolled Resource Consumption in Kibana Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18946
      },
      "nvd": {
        "published": "2026-07-21T23:18:02.697",
        "lastModified": "2026-08-03T17:42:28.500",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63260",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An oversized request payload consumes heap memory without an effective size bound.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-71/388574",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 489,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-63261",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T03:26:51.579Z",
      "date_published": "2026-07-21T22:58:45.488Z",
      "date_updated": "2026-07-22T14:35:50.832Z",
      "publisher": "elastic",
      "title": "Uncontrolled Resource Consumption in Kibana Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0027,
        "percentile": 0.18945
      },
      "nvd": {
        "published": "2026-07-21T23:18:02.817",
        "lastModified": "2026-08-03T16:38:28.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63261",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A low-privilege request to a machine-learning feature triggers excessive server-memory allocation without an effective bound.",
        "basis": [
          "CNA record",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-72/388575",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-63262",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T03:26:51.579Z",
      "date_published": "2026-07-21T23:07:18.534Z",
      "date_updated": "2026-07-22T13:08:28.548Z",
      "publisher": "elastic",
      "title": "Missing Authorization in Kibana Leading to Information Disclosure",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Kibana"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06289
      },
      "nvd": {
        "published": "2026-07-22T00:17:31.173",
        "lastModified": "2026-08-03T16:37:35.217",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63262",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Kibana accepts user input that bypasses the current space boundary and returns information from another space.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/kibana-9-4-4-security-update-esa-2026-73/388576",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 170,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63263",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T03:26:51.579Z",
      "date_published": "2026-07-21T23:10:49.155Z",
      "date_updated": "2026-07-22T13:07:01.561Z",
      "publisher": "elastic",
      "title": "Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service",
      "affected": {
        "vendors": [
          "Elastic"
        ],
        "products": [
          {
            "vendor": "Elastic",
            "product": "Elasticsearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security@elastic.co",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15212
      },
      "nvd": {
        "published": "2026-07-22T00:17:31.283",
        "lastModified": "2026-08-03T15:58:28.060",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63263",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An ES|QL query can trigger exponential CPU work that persists beyond completion and consumes all query workers.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-security-update-esa-2026-74/388577",
          "host": "discuss.elastic.co",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 483,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-63264",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T05:24:31.923Z",
      "date_published": "2026-07-22T08:32:25.762Z",
      "date_updated": "2026-07-23T15:00:32.227Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3",
      "affected": {
        "vendors": [
          "joomshopping.com"
        ],
        "products": [
          {
            "vendor": "joomshopping.com",
            "product": "JoomShopping extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.1737
      },
      "nvd": {
        "published": "2026-07-22T09:16:29.060",
        "lastModified": "2026-07-23T16:17:47.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63264",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In JoomShopping extension for Joomla, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomshopping.com/",
          "host": "www.joomshopping.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63265",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T05:24:31.924Z",
      "date_published": "2026-07-22T20:44:05.164Z",
      "date_updated": "2026-07-28T05:35:26.645Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Advanced Module Manager extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Articles Anywhere extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Articles Field extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Better Frontend Link extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Cache Cleaner extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "CDN for Joomla extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Conditional Content extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Content Templater extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "DB Replacer extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Email Protector extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Regular Labs Extension Manager extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "GeoIP extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "IP Login extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Keyboard Shortcuts extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Modals extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Modules Anywhere extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Quick Index extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "ReReplacer extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Snippets extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Sourcerer extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Tooltips extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Users Anywhere extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "What? Nothing! extension for Joomla"
          }
        ],
        "affectedBlockCount": 23,
        "versionEntryCount": 23,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01817
      },
      "nvd": {
        "published": "2026-07-22T21:18:09.547",
        "lastModified": "2026-07-27T19:17:19.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63265",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Regular Labs AJAX endpoints inconsistently enforce both CSRF tokens and the component or item permissions required for privileged mutations.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 425,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 23,
        "affectedVersionEntryCount": 23
      }
    },
    {
      "cve_id": "CVE-2026-63280",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T08:19:40.115Z",
      "date_published": "2026-07-22T20:43:01.914Z",
      "date_updated": "2026-07-28T05:34:22.469Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Advanced Module Manager extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Conditional Content extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Content Templater Pro extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "ReReplacer extension Pro for Joomla"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02779
      },
      "nvd": {
        "published": "2026-07-22T21:18:09.687",
        "lastModified": "2026-07-27T19:17:19.517",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63280",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The conditions manager inconsistently enforces CSRF tokens and component or mapped-item permissions, but the affected action and exact checks are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 224,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-63281",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T08:19:40.115Z",
      "date_published": "2026-07-22T20:40:29.002Z",
      "date_updated": "2026-07-27T13:28:27.279Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Advanced Module Manager extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Conditional Content extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Content Templater Pro extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "ReReplacer extension Pro for Joomla"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.04004
      },
      "nvd": {
        "published": "2026-07-22T21:18:09.800",
        "lastModified": "2026-07-27T14:16:59.343",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63281",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Advanced Module Manager extension for Joomla rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-63301",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T10:27:23.339Z",
      "date_published": "2026-07-28T10:42:56.589Z",
      "date_updated": "2026-07-28T12:29:31.097Z",
      "publisher": "CERT-PL",
      "title": "Denial of Service in Quick.CMS",
      "affected": {
        "vendors": [
          "OpenSolution"
        ],
        "products": [
          {
            "vendor": "OpenSolution",
            "product": "Quick.CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00361,
        "percentile": 0.2876
      },
      "nvd": {
        "published": "2026-07-28T11:17:03.823",
        "lastModified": "2026-07-30T16:29:42.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63301",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The user interface blocks primary-language deletion, while the API omits the same authorization and state restriction.",
        "basis": [
          "CNA",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-63301",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://opensolution.org/",
          "host": "opensolution.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 935,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63302",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T10:27:23.339Z",
      "date_published": "2026-07-28T10:43:01.601Z",
      "date_updated": "2026-07-28T12:26:32.768Z",
      "publisher": "CERT-PL",
      "title": "Local File Inclusion in Quick.CMS",
      "affected": {
        "vendors": [
          "OpenSolution"
        ],
        "products": [
          {
            "vendor": "OpenSolution",
            "product": "Quick.CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00307,
        "percentile": 0.22998
      },
      "nvd": {
        "published": "2026-07-28T11:17:03.963",
        "lastModified": "2026-07-30T16:29:42.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63302",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Quick.CMS include path accepts an attacker-controlled filename that can select a local file outside the intended include set.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-63301",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://opensolution.org/",
          "host": "opensolution.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63303",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T10:27:23.339Z",
      "date_published": "2026-07-28T10:43:05.695Z",
      "date_updated": "2026-07-28T12:21:07.313Z",
      "publisher": "CERT-PL",
      "title": "Path Traversal in Quick.CMS",
      "affected": {
        "vendors": [
          "OpenSolution"
        ],
        "products": [
          {
            "vendor": "OpenSolution",
            "product": "Quick.CMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-23",
          "name": "Relative Path Traversal",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00391,
        "percentile": 0.31854
      },
      "nvd": {
        "published": "2026-07-28T11:17:04.100",
        "lastModified": "2026-07-30T16:29:42.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63303",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Quick.CMS accepts relative traversal segments that select a file outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-23"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-63301",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://opensolution.org/",
          "host": "opensolution.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 536,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63304",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:13:18.732Z",
      "date_published": "2026-07-16T12:19:16.071Z",
      "date_updated": "2026-07-20T22:14:13.986Z",
      "publisher": "VulnCheck",
      "title": "AVideo through 29.0 OS Command Injection via listFFmpegProcesses",
      "affected": {
        "vendors": [
          "WWBN"
        ],
        "products": [
          {
            "vendor": "WWBN",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.01355,
        "percentile": 0.68894
      },
      "nvd": {
        "published": "2026-07-16T13:16:33.320",
        "lastModified": "2026-07-20T23:16:57.243",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63304",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-j44m-77cc-p3cc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/avideo-through-os-command-injection-via-listffmpegprocesses",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63305",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:13:18.732Z",
      "date_published": "2026-07-16T12:19:16.734Z",
      "date_updated": "2026-07-20T22:14:14.623Z",
      "publisher": "VulnCheck",
      "title": "AVideo through 29.0 OS Command Injection via ffmpeg.json.php",
      "affected": {
        "vendors": [
          "WWBN"
        ],
        "products": [
          {
            "vendor": "WWBN",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.01383,
        "percentile": 0.69488
      },
      "nvd": {
        "published": "2026-07-16T13:16:33.460",
        "lastModified": "2026-07-20T23:16:57.367",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63305",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ffmpeg.json.php concatenates notifyCode and callback into a shell command without escaping shell metacharacters.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-g9x9-q7qj-6mv5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/avideo-through-os-command-injection-via-ffmpeg-json-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 352,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63306",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:13:18.732Z",
      "date_published": "2026-07-16T12:19:17.351Z",
      "date_updated": "2026-07-16T13:17:25.249Z",
      "publisher": "VulnCheck",
      "title": "stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints",
      "affected": {
        "vendors": [
          "stoatchat"
        ],
        "products": [
          {
            "vendor": "stoatchat",
            "product": "stoatchat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15344
      },
      "nvd": {
        "published": "2026-07-16T13:16:33.597",
        "lastModified": "2026-07-16T14:16:56.960",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63306",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/stoatchat/stoatchat/security/advisories/GHSA-xhww-5g9p-vvq5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/stoatchat-before-unauthenticated-ssrf-via-proxy-and-embed-endpoints",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 420,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63307",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:13:18.733Z",
      "date_published": "2026-07-17T16:13:57.232Z",
      "date_updated": "2026-07-23T19:23:46.047Z",
      "publisher": "VulnCheck",
      "title": "Chat2DB < 5.3.0 Insecure Direct Object Reference via GET /api/connection/datasource",
      "affected": {
        "vendors": [
          "OtterMind"
        ],
        "products": [
          {
            "vendor": "OtterMind",
            "product": "Chat2DB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13987
      },
      "nvd": {
        "published": "2026-07-17T17:17:17.433",
        "lastModified": "2026-07-23T20:17:20.247",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63307",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation accepts a caller-supplied object identifier without binding the selected object to the authenticated caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OtterMind/Chat2DB/issues/1839",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/OtterMind/Chat2DB/releases/tag/v5.3.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/forgecode-arbitrary-code-execution-via-unvetted-mcp-json-in-untrusted-repository",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 411,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63308",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:13:18.733Z",
      "date_published": "2026-07-17T16:14:15.472Z",
      "date_updated": "2026-07-17T17:25:42.234Z",
      "publisher": "VulnCheck",
      "title": "Helm Files.Lines Denial of Service via Empty Chart Files",
      "affected": {
        "vendors": [
          "helm"
        ],
        "products": [
          {
            "vendor": "helm",
            "product": "helm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-129",
          "name": "Improper Validation of Array Index",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00275,
        "percentile": 0.1966
      },
      "nvd": {
        "published": "2026-07-17T17:17:17.577",
        "lastModified": "2026-07-30T18:11:32.207",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63308",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-influenced array index is used without checking it against the destination array's bounds.",
        "basis": [
          "CNA",
          "CWE-129"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/helm/helm/issues/32279",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/helm/helm/pull/32290",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/helm/helm/commit/ba6c9a29efa7bf9198dad6a5ec12b4fb30c96017",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/chat2db-insecure-direct-object-reference-via-get-api-connection-datasource",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Not Applicable",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 422,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:13:18.733Z",
      "date_published": "2026-07-17T16:14:51.248Z",
      "date_updated": "2026-07-28T01:05:30.275Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB < 3.1.5 Information Disclosure via ORDER BY",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09209
      },
      "nvd": {
        "published": "2026-07-17T17:17:17.717",
        "lastModified": "2026-07-17T18:28:39.220",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63309",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SurrealDB applies field-level SELECT permission to returned values but not to ORDER BY, exposing the relative order of restricted values.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-h4h3-3rfj-x6fq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/surrealdb/surrealdb/releases/tag/v3.1.5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-information-disclosure-via-order-by",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 353,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63313",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T12:13:18.733Z",
      "date_published": "2026-07-23T21:16:45.573Z",
      "date_updated": "2026-07-24T11:13:06.717Z",
      "publisher": "VulnCheck",
      "title": "9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00336,
        "percentile": 0.26181
      },
      "nvd": {
        "published": "2026-07-23T22:16:52.877",
        "lastModified": "2026-07-28T20:37:39.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63313",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The fetch endpoint validates only URL syntax and forwards the URL to a scraper without excluding internal, loopback, or metadata destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-qj3v-64wj-q825",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/9router-before-server-side-request-forgery-via-v1-web-fetch",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 762,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63317",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T13:23:13.170Z",
      "date_published": "2026-07-24T08:07:57.463Z",
      "date_updated": "2026-07-24T18:04:05.691Z",
      "publisher": "apache",
      "title": "Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache OpenNLP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19516
      },
      "nvd": {
        "published": "2026-07-24T09:16:25.273",
        "lastModified": "2026-07-24T20:47:41.790",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63317",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenNLP passes untrusted class names from model descriptors or format values to Class.forName and a constructor without a package allowlist.",
        "basis": [
          "CNA",
          "CWE-470"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/myr446n8t3gv8gq8wbpxm41olx16d8yj",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/7",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2512,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63358",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T14:46:57.734Z",
      "date_published": "2026-07-21T20:13:07.624Z",
      "date_updated": "2026-07-30T17:30:09.151Z",
      "publisher": "cisa-cg",
      "title": "FileGator privilege escalation",
      "affected": {
        "vendors": [
          "FileGator"
        ],
        "products": [
          {
            "vendor": "FileGator",
            "product": "FileGator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01574
      },
      "nvd": {
        "published": "2026-07-21T21:16:53.193",
        "lastModified": "2026-07-30T19:18:35.093",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63358",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The chmoditems endpoint accepts arbitrary Unix mode values from a user with chmod permission and applies them without restricting privilege-bearing permission bits.",
        "basis": [
          "CNA",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/filegator/filegator/blob/master/CHANGELOG.md#7142---2026-05-18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/filegator/filegator/commit/4a44ed9a43f84505703dce669c68fb55270c3f2c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/filegator/filegator/tree/master",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63358",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-03.json",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 296,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T14:56:43.960Z",
      "date_published": "2026-07-23T18:48:43.984Z",
      "date_updated": "2026-07-31T18:02:41.249Z",
      "publisher": "cisa-cg",
      "title": "Appriss Insights VINE SQLI",
      "affected": {
        "vendors": [
          "Appriss Insights"
        ],
        "products": [
          {
            "vendor": "Appriss Insights",
            "product": "Victim Information Notification Exchange (VINE)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00418,
        "percentile": 0.34421
      },
      "nvd": {
        "published": "2026-07-23T20:17:20.367",
        "lastModified": "2026-07-31T19:17:11.600",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63359",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted unauthenticated request reaches a database query without SQL parameter separation, enabling login bypass and database reads.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63359",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-204-01.json",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63362",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T15:02:47.793Z",
      "date_published": "2026-07-30T22:01:48.523Z",
      "date_updated": "2026-07-31T15:48:40.485Z",
      "publisher": "icscert",
      "title": "o6 Automation open62541 Integer Underflow",
      "affected": {
        "vendors": [
          "o6 Automation"
        ],
        "products": [
          {
            "vendor": "o6 Automation",
            "product": "open62541"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.01528,
        "percentile": 0.72225
      },
      "nvd": {
        "published": "2026-07-30T23:16:52.263",
        "lastModified": "2026-07-31T16:17:09.013",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63362",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PubSub signature verification subtracts attacker-controlled lengths without checking for unsigned underflow before using the result.",
        "basis": [
          "CNA",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.o6-automation.com/contact",
          "host": "www.o6-automation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-08.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-63397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T18:33:57.457Z",
      "date_published": "2026-07-16T19:14:30.532Z",
      "date_updated": "2026-07-21T17:08:22.419Z",
      "publisher": "cisa-cg",
      "title": "remorses/genql code injection",
      "affected": {
        "vendors": [
          "remorses"
        ],
        "products": [
          {
            "vendor": "remorses",
            "product": "genql"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16908
      },
      "nvd": {
        "published": "2026-07-16T20:16:47.950",
        "lastModified": "2026-07-21T18:17:04.170",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63397",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "genql lets attacker-controlled schema, metadata, code text, or file content cross into a code-generation or execution interpreter without the quoting, allowlisting, or neutralization needed to keep it as data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/remorses/genql/releases/tag/%40genql%2Fcli%406.3.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63397",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://github.com/remorses/genql",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-197-01.json",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 298,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T19:35:57.766Z",
      "date_published": "2026-07-20T15:50:14.065Z",
      "date_updated": "2026-07-20T16:13:26.732Z",
      "publisher": "GitHub_M",
      "title": "HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's declared hidden-field set",
      "affected": {
        "vendors": [
          "heyform"
        ],
        "products": [
          {
            "vendor": "heyform",
            "product": "heyform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-915",
          "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16337
      },
      "nvd": {
        "published": "2026-07-20T16:17:06.680",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63428",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "completeSubmission persists arbitrary submitter-supplied hidden-field identifiers and values without validating them against the form's declared schema.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-20",
          "CWE-915"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/heyform/heyform/security/advisories/GHSA-r7vg-xh87-v4w3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/heyform/heyform/commit/092e255e9e02565de1b3c057f3dad849160952d2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 649,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63429",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T19:35:57.766Z",
      "date_published": "2026-07-20T15:54:22.075Z",
      "date_updated": "2026-07-20T17:45:35.044Z",
      "publisher": "GitHub_M",
      "title": "HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context",
      "affected": {
        "vendors": [
          "heyform"
        ],
        "products": [
          {
            "vendor": "heyform",
            "product": "heyform"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00298,
        "percentile": 0.22083
      },
      "nvd": {
        "published": "2026-07-20T16:17:06.810",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63429",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HeyForm accepts uploads without authentication, session, token, or form-context binding and returns a permanent public URL.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/heyform/heyform/security/advisories/GHSA-432x-54v2-p7p7",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/heyform/heyform/commit/092e255e9e02565de1b3c057f3dad849160952d2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 619,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63453",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T19:47:44.513Z",
      "date_published": "2026-07-21T18:02:19.929Z",
      "date_updated": "2026-07-24T03:55:51.615Z",
      "publisher": "hpe",
      "title": "Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX",
      "affected": {
        "vendors": [
          "Hewlett Packard Enterprise (HPE)"
        ],
        "products": [
          {
            "vendor": "Hewlett Packard Enterprise (HPE)",
            "product": "AOS-CX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-alert@hpe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27916
      },
      "nvd": {
        "published": "2026-07-21T19:17:12.357",
        "lastModified": "2026-07-24T05:16:46.053",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63453",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A command-line input overruns a buffer in the affected AOS-CX component.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05081en_us&docLocale=en_US",
          "host": "support.hpe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-63454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-16T19:47:44.513Z",
      "date_published": "2026-07-21T18:02:25.136Z",
      "date_updated": "2026-07-24T03:55:52.403Z",
      "publisher": "hpe",
      "title": "Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX",
      "affected": {
        "vendors": [
          "Hewlett Packard Enterprise (HPE)"
        ],
        "products": [
          {
            "vendor": "Hewlett Packard Enterprise (HPE)",
            "product": "AOS-CX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-alert@hpe.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00547,
        "percentile": 0.42788
      },
      "nvd": {
        "published": "2026-07-21T19:17:12.467",
        "lastModified": "2026-07-24T05:16:46.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63454",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "AOS-CX permits an authenticated CLI user to copy an arbitrary path into a user-readable location.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05081en_us&docLocale=en_US",
          "host": "support.hpe.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 291,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-63550",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T19:32:49.393Z",
      "date_published": "2026-07-30T22:43:21.063Z",
      "date_updated": "2026-07-31T15:57:05.901Z",
      "publisher": "icscert",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "affected": {
        "vendors": [
          "MZ Automation GmbH"
        ],
        "products": [
          {
            "vendor": "MZ Automation GmbH",
            "product": "libiec61850"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16259
      },
      "nvd": {
        "published": "2026-07-30T23:16:52.443",
        "lastModified": "2026-07-31T16:17:09.170",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63550",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position incorrectly, leading to a heap out-of-bounds read.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 435,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63559",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T15:02:47.789Z",
      "date_published": "2026-07-30T21:47:21.231Z",
      "date_updated": "2026-07-31T15:42:40.025Z",
      "publisher": "icscert",
      "title": "o6 Automation open62541 Integer Overflow or Wraparound",
      "affected": {
        "vendors": [
          "o6 Automation"
        ],
        "products": [
          {
            "vendor": "o6 Automation",
            "product": "open62541"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00434,
        "percentile": 0.35691
      },
      "nvd": {
        "published": "2026-07-30T22:16:55.717",
        "lastModified": "2026-07-31T16:17:09.290",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63559",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.o6-automation.com/contact",
          "host": "www.o6-automation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-08.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 197,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-63683",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T15:49:15.531Z",
      "date_published": "2026-07-22T20:42:06.811Z",
      "date_updated": "2026-07-28T05:33:18.651Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Advanced Module Manager extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Conditional Content extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Content Templater Pro extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "ReReplacer extension Pro for Joomla"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13338
      },
      "nvd": {
        "published": "2026-07-22T21:18:09.910",
        "lastModified": "2026-07-27T19:17:20.760",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63683",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The location policy trusts client-spoofable forwarded IP headers as the caller's network address.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-63684",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T15:49:15.531Z",
      "date_published": "2026-07-22T20:39:55.373Z",
      "date_updated": "2026-07-28T05:30:32.698Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Content Templater extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "ReReplacer extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Snippets extension for Joomla"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.0278
      },
      "nvd": {
        "published": "2026-07-22T21:18:10.020",
        "lastModified": "2026-07-27T18:16:58.690",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63684",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Joomla extension administration, editor and import/export handlers enforce CSRF tokens, item permissions and input validation inconsistently across related actions.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 405,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-63685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T15:49:15.531Z",
      "date_published": "2026-07-22T20:43:30.967Z",
      "date_updated": "2026-07-28T05:34:50.869Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "DB Replacer extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13818
      },
      "nvd": {
        "published": "2026-07-22T21:18:10.130",
        "lastModified": "2026-07-27T19:17:20.923",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63685",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The implementation evaluates identity or privilege without binding it to the exact object, action, or security state being requested.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 343,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63720",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T21:21:58.624Z",
      "date_published": "2026-07-26T03:51:18.553Z",
      "date_updated": "2026-07-27T14:40:06.743Z",
      "publisher": "VulnCheck",
      "title": "datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field",
      "affected": {
        "vendors": [
          "koxudaxi"
        ],
        "products": [
          {
            "vendor": "koxudaxi",
            "product": "datamodel-code-generator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34473
      },
      "nvd": {
        "published": "2026-07-26T05:16:23.927",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63720",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A schema customBasePath is emitted verbatim into a Python import statement, allowing newlines to introduce executable code.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator/commit/545a96c5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://github.com/koxudaxi/datamodel-code-generator",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/datamodel-code-generator-code-injection-via-unvalidated-custombasepath-schema-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 476,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63727",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T21:21:58.625Z",
      "date_published": "2026-07-28T14:25:35.625Z",
      "date_updated": "2026-07-28T14:38:12.982Z",
      "publisher": "VulnCheck",
      "title": "Anchore Enterprise Privilege Escalation via User Management API",
      "affected": {
        "vendors": [
          "Anchore"
        ],
        "products": [
          {
            "vendor": "Anchore",
            "product": "Anchore Enterprise"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-648",
          "name": "Incorrect Use of Privileged APIs",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17625
      },
      "nvd": {
        "published": "2026-07-28T15:17:26.063",
        "lastModified": "2026-07-28T16:19:43.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63727",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A user-management API allows the caller to modify permissions without the required administrative authorization.",
        "basis": [
          "CNA",
          "CWE-648"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.anchore.com/5.27/docs/release_notes/enterprise/5272/",
          "host": "docs.anchore.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/anchore-enterprise-privilege-escalation-via-user-management-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63728",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T21:21:58.625Z",
      "date_published": "2026-07-20T23:32:34.476Z",
      "date_updated": "2026-07-22T13:55:50.277Z",
      "publisher": "VulnCheck",
      "title": "Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature",
      "affected": {
        "vendors": [
          "gitleaks"
        ],
        "products": [
          {
            "vendor": "gitleaks",
            "product": "gitleaks"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1336",
          "name": "Improper Neutralization of Special Elements Used in a Template Engine",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1.7999999999999998,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04257
      },
      "nvd": {
        "published": "2026-07-21T00:17:48.953",
        "lastModified": "2026-07-22T16:27:18.220",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63728",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A report template can invoke non-hermetic Sprig functions that read environment variables and perform DNS lookups.",
        "basis": [
          "CNA record",
          "CWE-1336"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/gitleaks/gitleaks",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/gitleaks/gitleaks/commit/83d9cd684c87d95d656c1458ef04895a7f1cbd8e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://fatihhcelik.github.io/posts/gitleaks-abusing-sprig-for-exfiltration/#the-fix",
          "host": "fatihhcelik.github.io",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gitleaks-secret-exfiltration-via-non-hermetic-sprig-template-functions-in-report-template-feature",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 520,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-17T21:21:58.625Z",
      "date_published": "2026-07-21T01:35:41.899Z",
      "date_updated": "2026-07-28T01:05:30.992Z",
      "publisher": "VulnCheck",
      "title": "TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File",
      "affected": {
        "vendors": [
          "TeX Live"
        ],
        "products": [
          {
            "vendor": "TeX Live",
            "product": "TeX Live"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02501
      },
      "nvd": {
        "published": "2026-07-21T03:16:42.470",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63729",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TeX Live retains or dereferences an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/TeX-Live/texlive-source/",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/TeX-Live/texlive-source/commit/002dcd3eac30db5c352f53d4181737961cc7ee9a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://fatihhcelik.github.io/posts/evince-synctex-heap-use-after-free/",
          "host": "fatihhcelik.github.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.vulncheck.com/advisories/tex-live-synctex-parser-heap-use-after-free-via-malformed-synctex-file",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:03:27.584Z",
      "date_published": "2026-07-20T18:44:22.835Z",
      "date_updated": "2026-07-21T11:08:18.399Z",
      "publisher": "VulnCheck",
      "title": "HyperDX < 2.31.0 SSRF via Webhook Test Endpoint",
      "affected": {
        "vendors": [
          "hyperdxio"
        ],
        "products": [
          {
            "vendor": "hyperdxio",
            "product": "hyperdx"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0.2999999999999998,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14254
      },
      "nvd": {
        "published": "2026-07-20T19:17:29.213",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63730",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The webhook test endpoint accepts a caller-selected URL and an insufficient hostname blacklist, allowing requests to internal and metadata addresses.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hyperdxio/hyperdx/issues/2588",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/hyperdxio/hyperdx/releases/tag/%40hyperdx%2Fapp%402.31.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/hyperdxio/hyperdx/pull/2593",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/hyperdxio/hyperdx/commit/1705b37ac68acc222cd038327ed79e167e256a1b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/hyperdx-ssrf-via-webhook-test-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:03:27.584Z",
      "date_published": "2026-07-20T18:45:14.088Z",
      "date_updated": "2026-07-28T14:29:46.336Z",
      "publisher": "VulnCheck",
      "title": "HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint",
      "affected": {
        "vendors": [
          "hyperdxio"
        ],
        "products": [
          {
            "vendor": "hyperdxio",
            "product": "hyperdx"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14971
      },
      "nvd": {
        "published": "2026-07-20T19:17:29.360",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63731",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ClickHouse proxy test endpoint accepts a caller-controlled host without validation or an allowlist and returns internal response bodies through its errors.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/hyperdxio/hyperdx/issues/2588",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/hyperdxio/hyperdx/releases/tag/%40hyperdx%2Fapp%402.31.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/hyperdxio/hyperdx/pull/2593",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/hyperdxio/hyperdx/commit/1705b37ac68acc222cd038327ed79e167e256a1b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/hyperdx-ssrf-via-clickhouse-proxy-test-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 513,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63732",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:19:06.903Z",
      "date_published": "2026-07-23T21:16:46.266Z",
      "date_updated": "2026-07-27T16:19:25.094Z",
      "publisher": "VulnCheck",
      "title": "9router before 0.4.60 Remote Code Execution via default password",
      "affected": {
        "vendors": [
          "decolua"
        ],
        "products": [
          {
            "vendor": "decolua",
            "product": "9router"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00744,
        "percentile": 0.51198
      },
      "nvd": {
        "published": "2026-07-23T22:16:53.023",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63732",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Fresh 9router installations accept the public default password 123456, giving remote callers the credential needed to enter the later exploit chain.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/decolua/9router/security/advisories/GHSA-4922-8r65-fq26",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/9router-before-remote-code-execution-via-default-password",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63733",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:19:06.903Z",
      "date_published": "2026-07-20T12:04:30.055Z",
      "date_updated": "2026-07-28T01:05:31.722Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.2.0 Permissions Bypass via PERMISSIONS Clause",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00201,
        "percentile": 0.10246
      },
      "nvd": {
        "published": "2026-07-20T12:19:42.243",
        "lastModified": "2026-07-22T15:53:24.560",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63733",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SurrealDB executes data-modifying statements embedded in PERMISSIONS clauses with enforcement disabled, allowing the guard expression to write outside its table authority.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-66r2-5gwj-gxm2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-permissions-bypass-via-permissions-clause",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 402,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63734",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:19:06.903Z",
      "date_published": "2026-07-20T12:04:30.773Z",
      "date_updated": "2026-07-28T01:05:32.443Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.2.0 Denial of Service via malformed SurrealML import",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00329,
        "percentile": 0.25381
      },
      "nvd": {
        "published": "2026-07-20T12:19:42.413",
        "lastModified": "2026-07-22T15:52:42.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63734",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SurrealML header parser accepts a malformed uploaded model header and reaches a server-crashing failure instead of rejecting the file.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-jwr6-6444-28xv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-malformed-surrealml-import",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63735",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:19:06.903Z",
      "date_published": "2026-07-20T12:04:31.479Z",
      "date_updated": "2026-07-28T01:05:33.142Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.2.0 Authentication Bypass via Custom API",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17981
      },
      "nvd": {
        "published": "2026-07-20T12:19:42.563",
        "lastModified": "2026-07-23T20:17:20.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63735",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled object key is accepted without verifying that the object belongs to the authenticated caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-848m-r628-vrxw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-authentication-bypass-via-custom-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 400,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63736",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:19:06.903Z",
      "date_published": "2026-07-20T12:04:32.124Z",
      "date_updated": "2026-07-28T01:05:33.864Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.2.0 SSRF via JWKS URL hostname resolution",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13439
      },
      "nvd": {
        "published": "2026-07-20T12:19:42.707",
        "lastModified": "2026-07-22T15:51:26.100",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63736",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The surrealdb request path accepts an attacker-controlled destination or redirect without constraining the resolved server-side network target.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-5x4x-2946-qr67",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-ssrf-via-jwks-url-hostname-resolution",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:19:06.903Z",
      "date_published": "2026-07-20T12:04:32.829Z",
      "date_updated": "2026-07-28T01:05:34.574Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.5 Denial of Service via deep operator chains",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27261
      },
      "nvd": {
        "published": "2026-07-20T12:19:42.857",
        "lastModified": "2026-07-22T15:50:35.560",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63737",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SurrealDB recursively evaluates an attacker-controlled operator chain without an effective depth bound.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-jv2j-mqmw-xvv5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-deep-operator-chains",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:19:06.903Z",
      "date_published": "2026-07-20T12:04:33.530Z",
      "date_updated": "2026-07-28T01:05:35.271Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB 3.1.0 before 3.1.5 Field Permission Bypass via Traversal",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10613
      },
      "nvd": {
        "published": "2026-07-20T12:19:43.000",
        "lastModified": "2026-07-22T15:49:56.960",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63738",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through graph-edge or back-reference traversals.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-hv6h-hc26-q48p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-field-permission-bypass-via-traversal",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63739",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:19:06.903Z",
      "date_published": "2026-07-20T12:04:34.209Z",
      "date_updated": "2026-07-28T01:05:35.993Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.5 Arbitrary File Read via DEFINE ANALYZER",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00356,
        "percentile": 0.28327
      },
      "nvd": {
        "published": "2026-07-20T12:19:43.143",
        "lastModified": "2026-07-22T15:49:10.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63739",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SurrealDB accepts an arbitrary mapper path in DEFINE ANALYZER and returns the opened file content through query errors when the file allowlist is empty.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-cc8f-fcx3-gpjr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-arbitrary-file-read-via-define-analyzer",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63740",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:19:06.903Z",
      "date_published": "2026-07-20T12:04:34.904Z",
      "date_updated": "2026-07-28T01:05:36.685Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.4 Array Element Permission Bypass",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17347
      },
      "nvd": {
        "published": "2026-07-20T12:19:43.287",
        "lastModified": "2026-07-22T15:48:36.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63740",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SurrealDB applies SELECT filtering to an array field without enforcing the separate permission on each field.* element.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-8rw6-p7m8-63jp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-array-element-permission-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63741",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:19:06.904Z",
      "date_published": "2026-07-20T12:04:35.585Z",
      "date_updated": "2026-07-28T01:05:37.401Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Authentication Bypass via USE statement",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00266,
        "percentile": 0.1833
      },
      "nvd": {
        "published": "2026-07-20T12:19:43.430",
        "lastModified": "2026-07-23T20:17:20.647",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63741",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SurrealDB's USE operation creates namespaces or databases without enforcing the permission required for that state-changing operation.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-wp87-mgvq-5j93",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-authentication-bypass-via-use-statement",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63742",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:26:19.866Z",
      "date_published": "2026-07-20T12:04:36.415Z",
      "date_updated": "2026-07-28T01:05:38.097Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Field Permission Bypass via Indexed COUNT",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11435
      },
      "nvd": {
        "published": "2026-07-20T12:19:43.573",
        "lastModified": "2026-07-22T15:47:01.527",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63742",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The indexed COUNT fast path answers queries without enforcing field-level SELECT permission, creating an oracle for restricted field values.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-c8jx-96c9-8xrp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-field-permission-bypass-via-indexed-count",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63743",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:26:19.866Z",
      "date_published": "2026-07-20T12:04:37.125Z",
      "date_updated": "2026-07-28T01:05:38.777Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Port-Specific Deny Rule Bypass via HTTP Redirect",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07706
      },
      "nvd": {
        "published": "2026-07-20T12:19:43.713",
        "lastModified": "2026-07-22T15:46:28.590",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63743",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Redirect policy evaluation drops the destination port, so an allowed redirect hop can reach a host-port pair denied by the network capability rule.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-97vg-427p-8hx5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-port-specific-deny-rule-bypass-via-http-redirect",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 368,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63744",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:26:19.866Z",
      "date_published": "2026-07-20T12:04:37.892Z",
      "date_updated": "2026-07-28T01:05:39.475Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.5 SSRF via JWKS URL Redirect",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14313
      },
      "nvd": {
        "published": "2026-07-20T12:19:43.860",
        "lastModified": "2026-07-22T15:45:46.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63744",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The JWKS fetcher validates the initial URL but follows redirects without revalidating each target against network capability restrictions.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-h5rg-8p7f-47g2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-ssrf-via-jwks-url-redirect",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 356,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63745",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:26:19.866Z",
      "date_published": "2026-07-20T12:04:38.681Z",
      "date_updated": "2026-07-28T01:05:40.179Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Authorization Bypass via Composite Record-id",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07707
      },
      "nvd": {
        "published": "2026-07-20T12:19:44.003",
        "lastModified": "2026-07-22T15:45:14.860",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63745",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SurrealDB permission rules read spoofable body fields instead of immutable composite record-ID fields when deciding tenant access.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-6vg3-hgrw-p5gf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-authorization-bypass-via-composite-record-id",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 401,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63746",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:26:19.866Z",
      "date_published": "2026-07-20T12:04:39.370Z",
      "date_updated": "2026-07-28T01:05:40.917Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Permission Bypass via Graph Traversal",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20946
      },
      "nvd": {
        "published": "2026-07-20T12:19:44.143",
        "lastModified": "2026-07-22T15:43:42.097",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63746",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Graph-edge and back-reference traversal reads target-table records without applying the target table's SELECT permission clause.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-vjjx-rfw4-rmfc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-permission-bypass-via-graph-traversal",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 266,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:26:19.866Z",
      "date_published": "2026-07-20T12:04:40.140Z",
      "date_updated": "2026-07-28T01:05:41.626Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Denial of Service via malformed RPC use",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00359,
        "percentile": 0.28568
      },
      "nvd": {
        "published": "2026-07-20T12:19:44.300",
        "lastModified": "2026-07-23T20:17:20.770",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63747",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The RPC use handler accepts a database selection without a namespace and panics on that invalid state instead of rejecting it.",
        "basis": [
          "CNA",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-wjjj-24cx-f28g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-malformed-rpc-use",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63748",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:26:19.867Z",
      "date_published": "2026-07-20T12:04:40.925Z",
      "date_updated": "2026-07-28T01:05:42.327Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Information Disclosure via Error Messages",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00193,
        "percentile": 0.09223
      },
      "nvd": {
        "published": "2026-07-20T12:19:44.440",
        "lastModified": "2026-07-22T15:42:28.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63748",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SurrealDB includes hidden field operands in arithmetic error responses despite field-level SELECT restrictions.",
        "basis": [
          "CNA",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-6g9v-7gq3-p2c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-information-disclosure-via-error-messages",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 369,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63749",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:26:19.867Z",
      "date_published": "2026-07-20T12:04:41.628Z",
      "date_updated": "2026-07-28T01:05:43.061Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Authentication Bypass via LIVE SELECT",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11371
      },
      "nvd": {
        "published": "2026-07-20T12:19:44.590",
        "lastModified": "2026-07-22T15:42:06.667",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63749",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "LIVE SELECT evaluates permission expressions against subscriber-supplied bindings instead of the actual before and after documents.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-6wqw-vhfr-9999",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-authentication-bypass-via-live-select",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 462,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63750",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:26:19.867Z",
      "date_published": "2026-07-20T12:04:42.403Z",
      "date_updated": "2026-07-28T01:05:43.776Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Memory Amplification via /sql WebSocket",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20085
      },
      "nvd": {
        "published": "2026-07-20T12:19:44.730",
        "lastModified": "2026-07-22T15:41:31.027",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63750",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "surrealdb accepts an attacker-controlled size, count, recursion depth, or work request without the quota or upper bound needed to keep resource use finite.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-65rj-r9fh-jp2v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-memory-amplification-via-sql-websocket",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 381,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63751",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:26:19.867Z",
      "date_published": "2026-07-20T12:04:43.103Z",
      "date_updated": "2026-07-28T01:05:44.483Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Field Permission Bypass via JSON Patch",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06974
      },
      "nvd": {
        "published": "2026-07-20T12:19:44.873",
        "lastModified": "2026-07-22T15:39:37.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63751",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "JSON Patch copy and move with an empty from pointer duplicate fields before field-level SELECT permissions remove protected values.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-fpxg-5xmv-922m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-field-permission-bypass-via-json-patch",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 388,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63752",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:30:08.354Z",
      "date_published": "2026-07-20T12:04:43.796Z",
      "date_updated": "2026-07-28T01:05:45.214Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 RELATE Statement Record Overwrite",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06192
      },
      "nvd": {
        "published": "2026-07-20T12:19:45.007",
        "lastModified": "2026-07-22T15:39:07.867",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63752",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SurrealDB lets CREATE-authorized RELATE statements name an existing edge ID and overwrite it without requiring UPDATE permission.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-f82j-v89j-mf86",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-relate-statement-record-overwrite",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 405,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63753",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:30:08.354Z",
      "date_published": "2026-07-20T12:04:44.546Z",
      "date_updated": "2026-07-28T01:05:45.882Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Authentication Bypass via LIVE Query",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10564
      },
      "nvd": {
        "published": "2026-07-20T12:19:45.150",
        "lastModified": "2026-07-23T20:17:20.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63753",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A live subscription retains authorization state after the underlying permission is revoked or expires.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-4m82-p8cx-f94j",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-authentication-bypass-via-live-query",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 248,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:30:08.354Z",
      "date_published": "2026-07-20T12:04:45.256Z",
      "date_updated": "2026-07-28T01:05:46.549Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Denial of Service via LIVE Query",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16939
      },
      "nvd": {
        "published": "2026-07-20T12:19:45.293",
        "lastModified": "2026-07-22T15:20:06.707",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63754",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SurrealDB keeps an error-producing LIVE query active and propagates its evaluation failure into every later write on the watched table.",
        "basis": [
          "CNA",
          "CWE-754"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-4v76-cw68-4vc9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-live-query",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 450,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:30:08.354Z",
      "date_published": "2026-07-20T12:04:46.096Z",
      "date_updated": "2026-07-28T01:05:47.203Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Permission Bypass via WHERE Clause",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11351
      },
      "nvd": {
        "published": "2026-07-20T12:19:45.433",
        "lastModified": "2026-07-22T15:19:27.620",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63755",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SurrealDB evaluates user-supplied clauses against full records before applying field and record permissions, allowing the pre-authorization evaluation to observe protected values.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-98fx-66cf-fc7c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-permission-bypass-via-where-clause",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 827,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:30:08.354Z",
      "date_published": "2026-07-20T12:04:46.863Z",
      "date_updated": "2026-07-28T01:05:47.907Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.0027,
        "percentile": 0.19056
      },
      "nvd": {
        "published": "2026-07-20T12:19:45.590",
        "lastModified": "2026-07-22T15:18:35.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63756",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state.",
        "basis": [
          "CNA",
          "CWE-362"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-4vgr-h27g-cf9p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-privilege-escalation-via-rpc-session-race-condition",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 363,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63757",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:30:08.354Z",
      "date_published": "2026-07-20T12:04:47.616Z",
      "date_updated": "2026-07-28T01:05:48.619Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Session Hijacking via /rpc sessions",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28179
      },
      "nvd": {
        "published": "2026-07-20T12:19:45.747",
        "lastModified": "2026-07-22T15:17:47.373",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63757",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arbitrary session fields with no ownership verification.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-5qfp-32cf-69jh",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-session-hijacking-via-rpc-sessions",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 378,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63758",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:30:08.354Z",
      "date_published": "2026-07-20T12:04:48.367Z",
      "date_updated": "2026-07-28T01:05:49.302Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Authorization Bypass via KILL Statement",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.00181,
        "percentile": 0.0785
      },
      "nvd": {
        "published": "2026-07-20T12:19:45.900",
        "lastModified": "2026-07-22T15:10:45.730",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63758",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The KILL statement accepts another user's live-query UUID without verifying subscription ownership.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-gcwr-5mrf-fvch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-authorization-bypass-via-kill-statement",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63759",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:30:08.354Z",
      "date_published": "2026-07-20T12:04:49.105Z",
      "date_updated": "2026-07-28T01:05:50.034Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Denial of Service nested type annotations",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16938
      },
      "nvd": {
        "published": "2026-07-20T12:19:46.047",
        "lastModified": "2026-07-23T20:17:21.027",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63759",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The type parser accepts arbitrarily nested annotations without a recursion-depth limit, allowing one query to exhaust memory and crash the server.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-q8qp-67f9-wr3f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-nested-type-annotations",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 252,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:30:08.354Z",
      "date_published": "2026-07-20T12:04:49.892Z",
      "date_updated": "2026-07-28T01:05:50.760Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Denial of Service via JSON Parser",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00359,
        "percentile": 0.28568
      },
      "nvd": {
        "published": "2026-07-20T12:19:46.187",
        "lastModified": "2026-07-22T15:08:06.867",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63760",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Attacker-controlled work or allocation lacks an effective bound, release, or termination condition.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-q729-696q-g9pq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-json-parser",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:30:08.354Z",
      "date_published": "2026-07-20T12:04:50.878Z",
      "date_updated": "2026-07-28T01:05:51.441Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 3.1.0 Algorithm Downgrade via ES512",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-327",
          "name": "Use of a Broken or Risky Cryptographic Algorithm",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00163,
        "percentile": 0.0594
      },
      "nvd": {
        "published": "2026-07-20T12:19:46.330",
        "lastModified": "2026-07-22T15:07:25.043",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63761",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SurrealDB silently maps configured ES512 JWT verification to ES384, causing a curve mismatch and authentication failure rather than the requested algorithm.",
        "basis": [
          "CNA",
          "CWE-327"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-fwg2-gr34-q3w8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-algorithm-downgrade-via-es512",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63762",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:34:08.780Z",
      "date_published": "2026-07-20T12:04:51.673Z",
      "date_updated": "2026-07-28T01:05:52.215Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before v2.6.1 Denial of Service via scripting",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00254,
        "percentile": 0.16939
      },
      "nvd": {
        "published": "2026-07-20T12:19:46.477",
        "lastModified": "2026-07-22T19:41:01.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63762",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A constructed large string reaches QuickJS-NG compilation and triggers a null-pointer dereference that terminates the server.",
        "basis": [
          "CNA",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-xx7m-69ff-9crp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-denial-of-service-via-scripting",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 709,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-63763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:34:08.780Z",
      "date_published": "2026-07-20T12:04:52.407Z",
      "date_updated": "2026-07-28T01:05:52.965Z",
      "publisher": "VulnCheck",
      "title": "SurrealDB before 2.5.0 Privilege Escalation via Future Fields",
      "affected": {
        "vendors": [
          "surrealdb"
        ],
        "products": [
          {
            "vendor": "surrealdb",
            "product": "surrealdb"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.3000000000000007,
      "epss": {
        "score": 0.00273,
        "percentile": 0.19457
      },
      "nvd": {
        "published": "2026-07-20T12:19:46.623",
        "lastModified": "2026-07-22T19:40:00.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63763",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A deferred closure executes with the reader's authority instead of preserving the creator's authority context.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-3v2x-9xcv-2v2v",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/surrealdb-before-privilege-escalation-via-future-fields",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 591,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-63764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:34:08.780Z",
      "date_published": "2026-07-21T20:36:58.372Z",
      "date_updated": "2026-07-23T17:47:23.951Z",
      "publisher": "VulnCheck",
      "title": "LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass",
      "affected": {
        "vendors": [
          "InternLM"
        ],
        "products": [
          {
            "vendor": "InternLM",
            "product": "lmdeploy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00302,
        "percentile": 0.22509
      },
      "nvd": {
        "published": "2026-07-21T21:16:53.350",
        "lastModified": "2026-07-23T18:17:00.877",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63764",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "_load_http_url validates only the initial host and follows a redirect to an unvalidated private destination.",
        "basis": [
          "CNA record",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/InternLM/lmdeploy/issues/4761",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/InternLM/lmdeploy/pull/4734",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/InternLM/lmdeploy/commit/03c313006d17cc3feae86b633c44206a997c44db",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/lmdeploy-server-side-request-forgery-via-http-redirect-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 595,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:34:08.780Z",
      "date_published": "2026-07-23T17:52:10.785Z",
      "date_updated": "2026-07-27T16:19:41.519Z",
      "publisher": "VulnCheck",
      "title": "Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation",
      "affected": {
        "vendors": [
          "chatwoot"
        ],
        "products": [
          {
            "vendor": "chatwoot",
            "product": "chatwoot"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.00381,
        "percentile": 0.30819
      },
      "nvd": {
        "published": "2026-07-23T19:17:03.560",
        "lastModified": "2026-07-27T17:16:39.083",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63765",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "chatwoot exposes a security-sensitive endpoint without requiring caller authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/chatwoot/chatwoot/issues/15072",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/chatwoot/chatwoot/releases/tag/v4.16.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/chatwoot/chatwoot/pull/15039",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/chatwoot/chatwoot/commit/8dd0d08322edafaec24624b72ed2f6045921cb7b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/chatwoot-unauthenticated-activestorage-direct-upload-arbitrary-blob-creation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63766",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:34:08.780Z",
      "date_published": "2026-07-20T19:18:09.685Z",
      "date_updated": "2026-07-28T01:05:53.752Z",
      "publisher": "VulnCheck",
      "title": "GPT-SoVITS 20250606v2pro OS Command Injection via webui.py",
      "affected": {
        "vendors": [
          "RVC-Boss"
        ],
        "products": [
          {
            "vendor": "RVC-Boss",
            "product": "GPT-SoVITS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.01749,
        "percentile": 0.75624
      },
      "nvd": {
        "published": "2026-07-20T20:16:46.170",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63766",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GPT-SoVITS interpolates unauthenticated Gradio path values into shell=True commands without neutralizing metacharacters.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/RVC-Boss/GPT-SoVITS/issues/2793",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/gpt-sovits-20250606v2pro-os-command-injection-via-webui-py",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 388,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:34:08.780Z",
      "date_published": "2026-07-20T19:13:43.160Z",
      "date_updated": "2026-07-21T12:42:40.500Z",
      "publisher": "VulnCheck",
      "title": "ktransformers Unauthenticated Pickle Deserialization RCE via ZMQ",
      "affected": {
        "vendors": [
          "kvcache-ai"
        ],
        "products": [
          {
            "vendor": "kvcache-ai",
            "product": "ktransformers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00742,
        "percentile": 0.51139
      },
      "nvd": {
        "published": "2026-07-20T20:16:46.323",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63767",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In ktransformers, attacker-controlled serialized data is converted into live objects without restricting the permitted types or behaviors.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kvcache-ai/ktransformers/issues/2087",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/kvcache-ai/ktransformers/pull/2091",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/kvcache-ai/ktransformers/commit/def0f9313d6e063b5c5ccdfa1f6707f7a40dfdca",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ktransformers-unauthenticated-pickle-deserialization-rce-via-zmq",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-63768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:34:08.780Z",
      "date_published": "2026-07-20T19:08:21.751Z",
      "date_updated": "2026-07-21T11:08:21.861Z",
      "publisher": "VulnCheck",
      "title": "cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State",
      "affected": {
        "vendors": [
          "calcom"
        ],
        "products": [
          {
            "vendor": "calcom",
            "product": "cal.diy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09574
      },
      "nvd": {
        "published": "2026-07-20T19:17:29.497",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63768",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unsigned or unvalidated return target is used for redirection, allowing navigation to an attacker-controlled origin.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/calcom/cal.diy/issues/29679",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/calcom/cal.diy/pull/29681",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cal-diy-conferencing-oauth-callback-open-redirect-via-unsigned-state",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 384,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:34:08.780Z",
      "date_published": "2026-07-20T19:05:41.298Z",
      "date_updated": "2026-07-21T14:56:38.359Z",
      "publisher": "VulnCheck",
      "title": "Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method",
      "affected": {
        "vendors": [
          "huginn"
        ],
        "products": [
          {
            "vendor": "huginn",
            "product": "huginn"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13986
      },
      "nvd": {
        "published": "2026-07-20T19:17:29.633",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63769",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ScenarioImport.fetch_url follows an authenticated user's arbitrary URL without restricting internal, metadata, or other sensitive destinations.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/huginn/huginn/issues/3679",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/huginn/huginn/pull/3684",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/huginn-ssrf-via-scenarioimport-fetch-url-method",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 368,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:34:08.780Z",
      "date_published": "2026-07-20T19:02:36.910Z",
      "date_updated": "2026-07-28T01:05:54.548Z",
      "publisher": "VulnCheck",
      "title": "Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass",
      "affected": {
        "vendors": [
          "glanceapp"
        ],
        "products": [
          {
            "vendor": "glanceapp",
            "product": "glance"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-348",
          "name": "Use of Less Trusted Source",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09749
      },
      "nvd": {
        "published": "2026-07-20T19:17:29.770",
        "lastModified": "2026-07-23T20:17:21.150",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63770",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The glance request path trusts a caller-controlled network-origin value when enforcing an address-based control.",
        "basis": [
          "CNA",
          "CWE-348"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/glanceapp/glance/issues/1031",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/glanceapp/glance/pull/1033",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/glance-ip-spoofing-authentication-brute-force-protection-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 595,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-18T12:34:08.781Z",
      "date_published": "2026-07-20T18:57:15.799Z",
      "date_updated": "2026-07-28T01:05:55.238Z",
      "publisher": "VulnCheck",
      "title": "Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header",
      "affected": {
        "vendors": [
          "vrana"
        ],
        "products": [
          {
            "vendor": "vrana",
            "product": "adminer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-113",
          "name": "Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15563
      },
      "nvd": {
        "published": "2026-07-20T19:17:29.910",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63771",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unescaped proxy-header value injects additional syntax into a Set-Cookie attribute.",
        "basis": [
          "CNA",
          "CWE-113"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vrana/adminer/issues/1298",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/vrana/adminer/security/advisories/GHSA-c533-9qwm-8w5h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/vrana/adminer/releases#release-v5.4.3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/adminer-cookie-injection-via-x-forwarded-prefix-header",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-63793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.012Z",
      "date_published": "2026-07-19T12:02:02.946Z",
      "date_updated": "2026-07-20T13:40:05.579Z",
      "publisher": "Linux",
      "title": "ntfs: serialize volume label accesses",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02246
      },
      "nvd": {
        "published": "2026-07-19T12:16:51.650",
        "lastModified": "2026-07-30T17:41:21.747",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63793",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FS_IOC_SETFSLABEL can replace and free volume_label while FS_IOC_GETFSLABEL copies it because the two accesses are not serialized.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/acd744019460bad22e43d4569a502f9c88d331ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e9e50ce4f13dc721014af622613409455c734942",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63794",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.012Z",
      "date_published": "2026-07-19T12:02:03.488Z",
      "date_updated": "2026-07-19T12:02:03.488Z",
      "publisher": "Linux",
      "title": "KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03968
      },
      "nvd": {
        "published": "2026-07-19T12:16:51.757",
        "lastModified": "2026-07-30T17:40:39.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63794",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "KVM's SEV debug path writes to a destination page without bounding the operation to that page's length.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f701ae476cb92a3a3d8844bb39bb63b4512684c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/64f2449841ffc7d203183aa4c748c9c77951ecc5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/9349b50f4b11f135fe73b56cb2c2c872d8bc71d7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/889c2a9c59897ca912bf39df5bb92555a0a13df4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e1a0fe288dee07b7da25a71e007c1ecd1080315b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/720949ed666f34ff28ffdfe1471a5861d1e41fdf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2753a097d1fe24c4351c608048612c74108aa89f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/78ee2d50185a037b3d2452a97f3dad69c3f7f389",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2923,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63795",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.012Z",
      "date_published": "2026-07-19T12:02:04.069Z",
      "date_updated": "2026-07-20T13:40:06.613Z",
      "publisher": "Linux",
      "title": "9p: avoid putting oldfid in p9_client_walk() error path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00477,
        "percentile": 0.38723
      },
      "nvd": {
        "published": "2026-07-19T12:16:51.910",
        "lastModified": "2026-07-30T17:39:34.503",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63795",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "p9_client_walk with clone=false aliases fid to caller-owned oldfid, but its failure path decrements fid as though it were distinct, allowing oldfid to be destroyed before the caller reuses it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/99c379ca1e221c3d75c7c804ebbf4e5ee37a3070",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b84f46179c806450b89821221ea5bd9a1698aba8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a61bdcba4f64c2f90d01461913f429ab151f1ca6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/6dbe9443d9f5f7fb6d319a7b77108853ae6c6bea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a7656d368265d085ac9bb85ab31b0cdb72ad8c38",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1a3860d46e3eb47dbd60339783cdad7904486b9f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 987,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63796",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.012Z",
      "date_published": "2026-07-19T12:02:04.634Z",
      "date_updated": "2026-07-20T13:40:07.618Z",
      "publisher": "Linux",
      "title": "ocfs2: reject oversized group bitmap descriptors",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00455,
        "percentile": 0.37298
      },
      "nvd": {
        "published": "2026-07-19T12:16:52.033",
        "lastModified": "2026-07-30T17:38:47.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63796",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ocfs2 validates bitmap geometry against allocator metadata but not against the bytes physically available in the group descriptor block.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/336340a0f8a141df8a4eb21a5a86f8ffb87769f6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/296c6a42b1174395935ca4cfe8f393e37b698d54",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/d2cd59fa848f9f13796ef214d3b1b5ca9a3fe21e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c5a125eadba05ba421c4b55e68da22b4a40d32b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8f9903b0cdbb3155a8899410330b4b4d583a7a5c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/4cd57ebee395041099fcdfcabb00749ce38d8b27",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/99c21e7263248c3f084756bfae08163cc5d6c62f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/9bd541e09dffff27e5bec0f9f45b0228173a5375",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2829,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63797",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.012Z",
      "date_published": "2026-07-19T12:02:05.227Z",
      "date_updated": "2026-07-24T14:34:04.279Z",
      "publisher": "Linux",
      "title": "rpmsg: char: Fix use-after-free on probe error path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03656
      },
      "nvd": {
        "published": "2026-07-19T12:16:52.190",
        "lastModified": "2026-07-30T17:35:28.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63797",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "rpmsg_chrdev_probe() publishes eptdev in an endpoint callback pointer before add succeeds, so an error path frees an object callbacks can still reach.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1306fc4f76f765727a6d5aefbf08ef0c8f32996f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ddf13f91ca82c94ef7ad9c41a434a03313f8eb1b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c5ebb06c7e24d531b68707168e04698859d642bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/104d100212396801f1d9d388282f746e23e2bfd6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ff268cd9ccbce6472a0658791b417bf11c31ee39",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1ff3f528e67d20e2b1483dcaba899dc7832b2e6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 725,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63798",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.012Z",
      "date_published": "2026-07-19T12:02:05.783Z",
      "date_updated": "2026-07-19T12:02:05.783Z",
      "publisher": "Linux",
      "title": "irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02692
      },
      "nvd": {
        "published": "2026-07-19T12:16:52.303",
        "lastModified": "2026-07-29T20:15:02.737",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63798",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A Linux error path drops ownership of an allocated resource without releasing it, allowing repeated operations to leak the resource.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8176773dfceae7978b01c20b233693e072053700",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c2c7733101bb8c0b29ac9ee41073eaf602821a59",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/83d7ec14b0938ad8cae008058fd6f912f4a9a312",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/44567537a2623dcd2b4018a7f043cf8069579e5d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/41826e5297e67cd96a0a46fde06a5069a8ce436a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b3a3831b2eb884641906fc5e46207b205b6aea13",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0405a65e4ebd9eac13a765f9f02ac05851ca5421",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/37738fdf2ab1e504d1c63ce5bc0aeb6452d8f057",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1073,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:06.341Z",
      "date_updated": "2026-07-20T13:40:09.516Z",
      "publisher": "Linux",
      "title": "sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02246
      },
      "nvd": {
        "published": "2026-07-19T12:16:52.433",
        "lastModified": "2026-07-29T20:12:31.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63799",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The mm CID fixup marks the MM_CID_UNSET sentinel as in transit and later uses the fixed sentinel value as clear_bit's index beyond the CID bitmap.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8d32856fb72ba976d9c87ba405fd17e80419934c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/de3ab9bd3133899efb92e4cd05ba4203e58fc0a3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2614,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:06.897Z",
      "date_updated": "2026-07-20T13:40:10.522Z",
      "publisher": "Linux",
      "title": "pNFS: Fix use-after-free in pnfs_update_layout()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 21,
        "versionRangeCount": 19,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.005,
        "percentile": 0.40064
      },
      "nvd": {
        "published": "2026-07-19T12:16:52.553",
        "lastModified": "2026-07-29T20:12:04.853",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63800",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "pnfs_update_layout drops the layout-header reference before a tracepoint finishes reading fields from that header.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4ad8b9a85dbf57ca532ee9e65ad7e6498bfbbf98",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1f24b8302c77dcaf79c64c073877a3b9f4dd25d2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/9c0fb5c09ae5bd68dc0038692af8127029cb0385",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/7e37e9b3e82ade881e1798e2f4fcc54aff7793c1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2883ddd7542b4437a2ab4908fe2773f690e20889",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/200e7637f4d6a1342987045eea72641524f909dc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/9645aaf689aff57427ece3b9fa47d5b5399417f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/13e198a90ca4050f4bee8a3f23680389a6563ccc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 498,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 21
      }
    },
    {
      "cve_id": "CVE-2026-63801",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:07.457Z",
      "date_updated": "2026-07-20T13:40:11.527Z",
      "publisher": "Linux",
      "title": "tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00486,
        "percentile": 0.39256
      },
      "nvd": {
        "published": "2026-07-19T12:16:52.680",
        "lastModified": "2026-07-29T20:05:45.040",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63801",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The asynchronous decrypt path starts without pinning the network namespace, so its completion callback can dereference per-net crypto state after teardown frees it.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/171d31245d11bf84836fad3b394cb465a4d008ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/2d1f21419ec121232c916d3a3fc9b6766473a0e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0a780653b2a7569a7af9be7d0b00b1251baca63a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/eaca7dae02fab70c8d223cffe03cec1b93249ce2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/dca7713fe044a2067387948557ea099056e1679e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/e18769616fd5a90ec1e12aabbba544c488284292",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/1eea5e1820a2f5164d706bd1277bc97ff31ce32d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/bda3348872a2ef0d19f2df6aa8cb5025adce2f20",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 3643,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:08.020Z",
      "date_updated": "2026-07-20T13:40:12.508Z",
      "publisher": "Linux",
      "title": "blk-cgroup: fix UAF in __blkcg_rstat_flush()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02601
      },
      "nvd": {
        "published": "2026-07-19T12:16:52.847",
        "lastModified": "2026-07-29T20:05:01.213",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63802",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Concurrent block-group releases let one flush remove another group's entries and free that group while the first thread still iterates its memory.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/96e545410c4f74c89d496c1d5d9ef8d08f14368b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/bbebd9425cad3573d1527441753899b926525a0f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5e5b7f2ef854936e95dceb6a2fdfefcb7152d2c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/afebe44facc48a61761e885bbb7f0380d4a603ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/0ab5ee5a1badb58cbb2242617cb01a4972b1f2a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 646,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63803",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:08.574Z",
      "date_updated": "2026-07-24T14:34:05.294Z",
      "publisher": "Linux",
      "title": "hdlc_ppp: sync per-proto timers before freeing hdlc state",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03213
      },
      "nvd": {
        "published": "2026-07-19T12:16:52.980",
        "lastModified": "2026-07-29T20:03:51.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63803",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PPP timers can continue running after detach frees the containing HDLC state because teardown does not synchronously shut down every timer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/86d80a231bde4cfb64bfbfbfffd83056fc93628f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8308122bc9c065b1f376e081ed300129a2ac9545",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ce8f9ddca0c9f217342a8b49efd309aa35b81a36",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/508a0139d3bf60f6a03d2fbfb63a89a9463d983a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c64dbef1c0fbd36f9530aa75112acdf6a6d3cfd8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5a84398101bf9f11e84b176343e4e3ba83e668c0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/a594debfd4e7ec39413647458907f689ef57fd2f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c78a4e41ab5ead6193ad8a2dd92e8906bae659fa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2167,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:09.111Z",
      "date_updated": "2026-07-19T12:02:09.111Z",
      "publisher": "Linux",
      "title": "gfs2: fix use-after-free in gfs2_qd_dealloc",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03567
      },
      "nvd": {
        "published": "2026-07-19T12:16:53.120",
        "lastModified": "2026-07-29T20:02:30.647",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63804",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Linux path can dereference an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4fe388218826df8607ae41a6305df67db08a9093",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/8745d9f7e1682c39f0a1578895ac74205e2a6757",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b85ef03f726b15047a6fa6d11b639bdf6c0ee4f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/9d0d5ba20cad661f7f287d4c66d2c19022ce2fd0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f9c9ec2c319f843b70ecdf939d48b52d189bc081",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1018,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 1,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63805",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:09.669Z",
      "date_updated": "2026-07-20T13:40:14.519Z",
      "publisher": "Linux",
      "title": "crypto: nx - fix nx_crypto_ctx_exit argument",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02767
      },
      "nvd": {
        "published": "2026-07-19T12:16:53.230",
        "lastModified": "2026-07-29T20:01:46.657",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63805",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The NX crypto exit path treats a context pointer as a crypto_tfm pointer and dereferences the resulting invalid address.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8d8507a457667f23477a15496b91908a5b5b7cf3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/833033e6e55acf11304ff7bbbdf18351d139c281",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/4e67f504ee9ded15e256b64f4fde150e917381d7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1211,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:10.209Z",
      "date_updated": "2026-07-24T14:34:06.318Z",
      "publisher": "Linux",
      "title": "KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04437
      },
      "nvd": {
        "published": "2026-07-19T12:16:53.340",
        "lastModified": "2026-07-29T20:00:51.267",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63806",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A guest-controlled unaligned MMIO fragment reaches a BUG_ON alignment assertion and terminates the host kernel.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2426c15c1395b7d5ccf1e5025ca898af7f3decb6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/4186c850789906b875a1d263377a4d37c078e317",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/36ff44fb3d89960391e013fb9d91e23dbc48be47",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/92fc631b69deb1c7d56aec2663003600799dcd75",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/bf89e3738480d33cd515b4a18900e8443d40cd2e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5da9b1a87ec7cc3489c27016313524769f12d9e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5c87b47374682f69686068ad0a7779365a527b1c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/f1edbed787ba67988ed34e0132ca128b052b6ce8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 3057,
        "referenceCount": 8,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:10.759Z",
      "date_updated": "2026-07-20T13:40:16.637Z",
      "publisher": "Linux",
      "title": "KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.02998
      },
      "nvd": {
        "published": "2026-07-19T12:16:53.470",
        "lastModified": "2026-07-29T19:57:30.487",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-63807",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Linux uses an attacker-influenced length or index without proving it lies inside the backing object, allowing a read beyond valid memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7b52008023b7facf40fba3ebe92449bda8ea53b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/5cab1c989f938f5e1b9a0de66486f1fc2c28479b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/48b91ed7e22bb82571c34f8b80b6ecdc90a6fab8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/c5c29b3c268332afe67d598a034c58344540ed92",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/18587f9831612e24cd8f24be1ec15478feff7abc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/b2ae3245ea44dccaa9af676b6747476951883318",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://git.kernel.org/stable/c/ef057cbf825e03b63f6edf5980f96abf3c53089d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 2778,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-63808",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:11.323Z",
      "date_updated": "2026-07-20T13:40:17.638Z",
      "publisher": "Linux",
      "title": "exfat: fix potential use-after-free in exfat_find_dir_entry()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.005,
        "percentile": 0.40064
      },
      "nvd": {
        "published": "2026-07-19T12:16:53.620",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63808",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "exfat_find_dir_entry releases the buffer_head and then dereferences an entry pointer into the released bh data on the TYPE_EXTEND path.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e6f1a11cfb808441a43ffae9b476cc135732cd27",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e48f413c2815787b8cade2795e194e3c4cd782ef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/06c4e1e9967d332ac33ba38b7819851089ff9359",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8e0abc17fbd7e305802e84fe98b4950d50f9c433",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4d101016d5e587f820b3ae2d5bb6770d86342649",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/adfacfbaeae2cb760f492357cc36b41f84ef7f86",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/708b97e792945d3e4653939fd3405d71a61ad065",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3f5f8ee9917cc2b9076ac533492d8a200edcabb8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1738,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63809",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:11.905Z",
      "date_updated": "2026-07-20T13:40:18.658Z",
      "publisher": "Linux",
      "title": "bpf: use kvfree() for replaced sysctl write buffer",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 21,
        "versionRangeCount": 19,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05068
      },
      "nvd": {
        "published": "2026-07-19T12:16:53.757",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63809",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The BPF sysctl path may allocate with vmalloc fallback but frees the buffer with kfree(), corrupting memory when the allocation is not kmalloc-backed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d0a81ed5ff5d0f9c3f63a4f9e5a4642c363ecd3e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/77355ef7a9f6b0d2bdf65be3b37f2c1f365e20d2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e1d1e203a6000804c5d3b8a4aa4e52303c0c7ab2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/81fc9a13acae99966232f0e055eb2e445263b89a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/838fe9c28121777c59a9406710a68fcf77bb8017",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/65bd0c0afb0e1bf3287458e342429b069624f7d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/70df4de46577fab5e25418f014583155a147c902",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4c21b5927d4364bfe7365f2700da5fea0ed0d004",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2403,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 21
      }
    },
    {
      "cve_id": "CVE-2026-63810",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:12.484Z",
      "date_updated": "2026-07-24T14:34:07.309Z",
      "publisher": "Linux",
      "title": "block: Avoid mounting the bdev pseudo-filesystem in userspace",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06965
      },
      "nvd": {
        "published": "2026-07-19T12:16:53.910",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63810",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An internal block-device pseudo-filesystem remains mountable from user space and reaches an inode with a null operations table.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3d3fcf23993bb756de2f912ab631cfdcc4746554",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/99cde0a7b1e98fd3970aabef1300918e91698dd5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1a02a5028bd6dead1f8503854ef3168d651cd417",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/197971e6ffc0a6356b2ba2b22beb42bc0f7e412d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3804e6de30ae7b053d53341d9d6944356cf23b40",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/717f721eb67d2dacd3ed5f7495aef2f442e84ce4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f73aa66dffcb8e61e78f01b56163ec16a15d06d2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1614,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-63811",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:13.057Z",
      "date_updated": "2026-07-19T12:02:13.057Z",
      "publisher": "Linux",
      "title": "f2fs: read COW data with the original inode during atomic write",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00106,
        "percentile": 0.01262
      },
      "nvd": {
        "published": "2026-07-19T12:16:54.023",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63811",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "F2FS chooses post-read decryption from the COW inode even though the folio and stored data use the original inode's encryption context.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a92332f32a8d31a7eee47b1dc1d751cb3319908f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a41075acde0124d2f8a5f563068a5d63e8ffd57b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2712,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:13.606Z",
      "date_updated": "2026-07-20T13:40:19.633Z",
      "publisher": "Linux",
      "title": "f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 17,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02135
      },
      "nvd": {
        "published": "2026-07-19T12:16:54.137",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63812",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "F2FS sets FI_NO_EXTENT while leaving the cached largest-extent state intact, so later operations consume stale extent metadata.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7e4d8f98be63f98856a5176b9188dada6e7ba9ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/58a5deb220bcac4c73bf58954c0845644c997487",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/20190e498057997532c7f186d081011f18e0a462",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/edf12cbeeeabe799bd2ee21fdb5c336cce6fbad7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1f70ddb28a3c71df124da5fa4040c808116d6bb9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 950,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-63813",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.013Z",
      "date_published": "2026-07-19T12:02:14.205Z",
      "date_updated": "2026-07-20T13:40:20.628Z",
      "publisher": "Linux",
      "title": "Revert \"f2fs: remove non-uptodate folio from the page cache in move_data_block\"",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 7,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02072
      },
      "nvd": {
        "published": "2026-07-19T12:16:54.253",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63813",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "F2FS page-cache eviction races folio splitting and LRU isolation, allowing a page to be freed while its links remain in the LRU list.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1991d49433e90b2202de2fe90be3c24161873d7c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6e035dae44154af4dd7bdb8ef7a1118c0b5f17b6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ccaba785821970f422c47770331c7e3271763f17",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3998,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-63814",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:14.771Z",
      "date_updated": "2026-07-20T13:40:21.598Z",
      "publisher": "Linux",
      "title": "f2fs: validate ACL entry sizes in f2fs_acl_from_disk()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.0275
      },
      "nvd": {
        "published": "2026-07-19T12:16:54.390",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63814",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A malformed ACL can still place ACL_USER or ACL_GROUP in a slot that only contains struct f2fs_acl_entry_short bytes, and f2fs_acl_from_disk() then reads entry->e_id before verifying that a full entry fits.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/733cd8474e6d763d75ed96f3f2b98a25480cf2b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4e2a96ec7236e248e706850568e0a925fd21b588",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/442ca20c54038e2400cf28aaa944cf1de2c8e65d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1ddf3fd21c4c652f9cab5552515c04a166662306",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aba4f94ac1832c7299c33e1b4fe5f87eef6dc8f1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ff83de56882cb8466184d322abece2589258ca56",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5d8a39649947a4e86c8fbc682d7fc0041b8d109a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c4810ada31e80cbe4011467c4f3b1e93f94134f3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1846,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63815",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:15.345Z",
      "date_updated": "2026-07-24T14:34:08.336Z",
      "publisher": "Linux",
      "title": "f2fs: bound i_inline_xattr_size for non-inline-xattr inodes",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03179
      },
      "nvd": {
        "published": "2026-07-19T12:16:54.527",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63815",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unchecked on-disk inline-xattr size makes F2FS directory geometry underflow and drives reads beyond the inline dentry area.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3c8d6b4093aea40a20596f452289e7c22d84e6d5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a08ee30dcbeff6b97df75c38c2589603ddde53a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c3e05522daae4e7348a1ea81eeb321d25aa0fd3b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/76e1a05cf6d4051931d7fa4ead51a05786a62918",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2a9f9791653ba5ed3fb45bbffa8d63a7cd5cf706",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4ce2d52f680c1d8bfdad7cce05b815ea7ca9790d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/16bc237ce3c483b75575abea53cfb639745311ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/378acf3cf19b6af6cba55e8dd1154c4e1504bae8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1946,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63816",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:15.907Z",
      "date_updated": "2026-07-24T14:34:09.322Z",
      "publisher": "Linux",
      "title": "f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02135
      },
      "nvd": {
        "published": "2026-07-19T12:16:54.643",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63816",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Garbage collection uses atomic_inode->i_mapping without holding an object reference while eviction can free that inode.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7d3ae21783e5914c1761ac7d63f882d3d70800e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/56038756aae68312df00d4aa1d97e51ef3aca725",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a499f77c06050a28c897bdbd86cd2f0721ae0743",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a805fec35c201c59643ddcde713bce4051c8ee27",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e0288584baa5dc41df4a829a023c4c1b33fe53d7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 855,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63817",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:16.441Z",
      "date_updated": "2026-07-24T14:34:10.308Z",
      "publisher": "Linux",
      "title": "f2fs: validate compress cache inode only when enabled",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 16,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03308
      },
      "nvd": {
        "published": "2026-07-19T12:16:54.757",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63817",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "F2FS treats the synthetic compressed-cache inode as metadata even when that feature is disabled, bypassing the normal inode-range validation path.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fcc051d377a9701a452e7663a1a8223c26225df9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/29115b8c9172d34e67ab26cc4f6c209b7a236d7a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/13e4b59d3a9413f66f116fa6c4828519b960a5ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/16161444c30d8dff9428abbae42b72ce4e32a932",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/77f216ff9ce5cde8eed9f6d12707e906dffdc9f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0969926d987bbde9a1aa49da317582ba37095805",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5073c66a96a9c23c0c2533ed4ed06e42f9021208",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 915,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63818",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:17.022Z",
      "date_updated": "2026-07-24T14:34:11.320Z",
      "publisher": "Linux",
      "title": "f2fs: validate orphan inode entry count",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.0321
      },
      "nvd": {
        "published": "2026-07-19T12:16:54.873",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63818",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "f2fs orphan recovery trusts entry_count beyond the ino array and reads footer or following data as inode numbers.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/210c210c92d78fdf5051bc55c5c69044b1a2150a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ad101d15716f5a24d1fa82a849f80430c805a3dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d18c81f5d0ecd5796aa47d66d98f2dd54d8d0f70",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d2f236196d542ccd8505736e41c3a1d3f0305f6f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/550511a2470f6d204fa07b331f048bd2d3c51280",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8aad54746c251f2c2370118df766c0c82e2d2091",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2e12381d4495dc8b0ff042c6856022b2e359835c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/846c499a65816d13f1186e3090e825e8bb8bcb8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 914,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63819",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:17.613Z",
      "date_updated": "2026-07-20T13:40:26.536Z",
      "publisher": "Linux",
      "title": "f2fs: fix to do sanity check on f2fs_get_node_folio_ra()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02034
      },
      "nvd": {
        "published": "2026-07-19T12:16:54.980",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63819",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "F2FS accepts a corrupted direct-node footer whose inode and node identifiers conflict, leading truncation arithmetic to hit a kernel assertion.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/406c28af75123432d38cf9bbaa6f1476f7b14770",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0cc21c1ffe15b4156b0bf744f32fd1faef0b7c73",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8712353ed80f87271d732297567dcdbe4b84e8c7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2872,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63820",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:18.211Z",
      "date_updated": "2026-07-19T12:02:18.211Z",
      "publisher": "Linux",
      "title": "f2fs: fix missing read bio submission on large folio error",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00145,
        "percentile": 0.04281
      },
      "nvd": {
        "published": "2026-07-19T12:16:55.103",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63820",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An error before adding a later folio returns without submitting the already accumulated bio, leaving earlier folios locked without completion.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/48c92559e7b66fdc3cbc74f6e152e66ec0150a0a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/74c8d2ec95c59a5651ecd975c466998af1961fd4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 795,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:18.751Z",
      "date_updated": "2026-07-19T12:02:18.751Z",
      "publisher": "Linux",
      "title": "wifi: rtw88: usb: fix memory leaks on USB write failures",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00157,
        "percentile": 0.05333
      },
      "nvd": {
        "published": "2026-07-19T12:16:55.203",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63821",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "USB submission failures skip the completion callback, and the unchecked error paths therefore never release the skb, txcb, or aggregated buffers.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2b2060c2075a72bc2de43ce5e1b9347d6c5e27bb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/53fed4061a09755de99c89fdc7fae5b794da455f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/200d58c851b8f63f77a05570072dd20f79bc3681",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8206d173d18ef5a077423119f4e9a93cb3a6f4eb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6b964941bbfe6e0f18b1a5e008486dbb62df440a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1127,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63822",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:19.286Z",
      "date_updated": "2026-07-19T12:02:19.286Z",
      "publisher": "Linux",
      "title": "wifi: ath11k: fix warning when unbinding",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00174,
        "percentile": 0.07033
      },
      "nvd": {
        "published": "2026-07-19T12:16:55.330",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63822",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ath11k failure path frees transmit-status buffers without clearing their pointers, so device unbind frees the same allocations again.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e569a5cb401a267168621aa9a1e7f07fcc9612c3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0aa097a370277deab5337030b9e2d395742f469c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0a946abb82f29abe9a15173b707a449cb039b43e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/318703b6f71d1a29ee0ac46c32a38f7734d4cfb2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7b2e62b9080bf4a5f4e70cfe47156df8d93a4f13",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/40aa3c2b0cb8e34e0576fc94cc70e4e33db03c0a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/051f954b94479d72222c9fbc82a3eef4777bca01",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8b7a26b6681922a38cd5a7829ace61f8e54df9b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 681,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63823",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:19.847Z",
      "date_updated": "2026-07-20T13:40:27.567Z",
      "publisher": "Linux",
      "title": "keys: Pin request_key_auth payload in instantiate paths",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.0252
      },
      "nvd": {
        "published": "2026-07-19T12:16:55.457",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63823",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The request-key instantiate path loads request_key_auth without retaining its payload reference across a sleep, allowing the helper to free it before target_key is used.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d8274181b0f28d450b42489723a5ba81042158d7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4982bfabce6b33b3c9eddb4fb900fe5568b7cf91",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/708709c65a1832a99b0eef8ae46e343ddaca3d06",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/35ab4db86774d82389e4b9559e26ab7f68d8e395",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f9b68632ac93cc742f2e411021c4dbfe452ea0c2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7216ce8cb12fee44e309503955bb83806b106129",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/83c0a1cb296d955d5f4d1f0bd8a769ba8ed8c29f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fd15b457a86939c38aa12116adabd8ff686c5e51",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 956,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63824",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:20.406Z",
      "date_updated": "2026-07-20T13:40:28.600Z",
      "publisher": "Linux",
      "title": "KEYS: fix overflow in keyctl_pkey_params_get_2()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02788
      },
      "nvd": {
        "published": "2026-07-19T12:16:55.583",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63824",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The kernel sizes an internal public-key output buffer from the caller's too-small length instead of the primitive's maximum output length.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/622ec2dcd59f21623f2a7ab773c80ceb7d555e3a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b1e247338bc71826a2d2def3e0874c34749df69a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0f3058d7d26f81df9b68a18ddbe164bdc3c5eff3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5966e4e2ba213ab7ad559166152eb4f1f170dd2c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5165f1cc727f1322456735df212d8e26ec237a8d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b11c1fa32667692a2c0566e10163758e786e430c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/670fc6a311ed321522b7fff92cf0fc376b4f6e78",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cb481e59ea6cae3b7796ac1d7a22b6b24c3f3c0b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 393,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63825",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:20.968Z",
      "date_updated": "2026-07-20T13:40:29.626Z",
      "publisher": "Linux",
      "title": "gcov: use atomic counter updates to fix concurrent access crashes",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00414,
        "percentile": 0.34128
      },
      "nvd": {
        "published": "2026-07-19T12:16:55.720",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63825",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent CPUs update a shared non-atomic GCOV counter between the compiler's loop-bound loads, producing inconsistent indices and an out-of-bounds write in inflate_fast.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/49d893b9cbcfc5802a32e53a64c6c6956670d65b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5b959c1dbb4522b9e3ac4e26ad638b8784869841",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/56cb9b7d96b28a1173a510ab25354b6599ad3a33",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2635,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63826",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:21.518Z",
      "date_updated": "2026-07-20T06:41:29.792Z",
      "publisher": "Linux",
      "title": "fbdev: fix use-after-free in store_modes()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00157,
        "percentile": 0.05333
      },
      "nvd": {
        "published": "2026-07-19T12:16:55.833",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63826",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "store_modes frees the old framebuffer modelist and leaves concurrent readers able to dereference those released mode entries.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5267eab88fa4c684459504b8be577ad64953b9a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c6765f39ed27014ff877b00a2efa494233404e17",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0d35f9f194a858567a21017d69318a51e3a822b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/70f1e000b88cfa8ca3fd7f4d082647fc089a7769",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2c1c805c65fb7dc7524e20376d6987721e73a0b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1509,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63827",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:22.083Z",
      "date_updated": "2026-07-24T14:34:12.274Z",
      "publisher": "Linux",
      "title": "apparmor: fix use-after-free in rawdata dedup loop",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 26,
        "versionRangeCount": 24,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.0252
      },
      "nvd": {
        "published": "2026-07-19T12:16:55.960",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63827",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Deduplication unconditionally increments a reference whose count is zero or whose object is already dying.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/643221da57dbb1a8fd800610331cf1ec27969f71",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b17f0c59cc1525765625cf07d0391b7f9c1ed7e5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a7a2890028f16e5b0af0bb005d80fcb32559cca3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/15fd83a1e42ede15070968806bb6c8b1a5170688",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ce261a20b41db522e320a41bbf1292bf85af66df",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c3ca2631073b2cef06824fd2bfc452ff7a1023de",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5e34fa9f6f7cd688ae153fff13139a5cf2d42339",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6f060496d03e4dc560a40f73770bd08335cb7a27",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1851,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 26
      }
    },
    {
      "cve_id": "CVE-2026-63828",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:22.644Z",
      "date_updated": "2026-07-24T14:34:13.317Z",
      "publisher": "Linux",
      "title": "apparmor: mediate the implicit connect of TCP fast open sendmsg",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03095
      },
      "nvd": {
        "published": "2026-07-19T12:16:56.110",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63828",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Linux operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a16714e7cf2baa98ba2efddd5d6cbac641f4e76b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/20383429b56974507c465d016e5238b189f7a246",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7f57428ce00891d26b0f087ef754a4d820ec83aa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/faea60deaa05c76f0772650f42eafde12bd39d93",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/07b71c342382b854ab8030b244aeab6a7228ad7d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4a69b83045d3195d5b9a9b053ad840ddb2998b4e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/45ebb934ea50b436ce49b2f159f090dab0d7fa28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4d587cd8a72155089a627130bbd4716ec0856e21",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 831,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63829",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:23.191Z",
      "date_updated": "2026-07-24T14:34:14.296Z",
      "publisher": "Linux",
      "title": "net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02484
      },
      "nvd": {
        "published": "2026-07-19T12:16:56.230",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63829",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The GRE changelink path checks CAP_NET_ADMIN in the wrong network namespace and therefore authorizes the caller against the wrong authority domain.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/19275943d8fe903eb7b9aa53e380e41efd042ada",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/866b0f5ae599490bd496fd84581c68ac8b94e6af",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/92b766fc55156e0da2ecd0c2302c971118f8a229",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e54c05ed3d9c28733fb9e5837219aca3691defa3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9831bc9ecb402957810c2045c663fbfe9b09e296",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1697957eb0971d420dde42862b88eb43506a1105",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/47b5d3d506609b08b2e1f7c14f0b681a1953d572",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8165f7ff57d9667d2bb477ef6af83ede7fed4ad7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1173,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63830",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.014Z",
      "date_published": "2026-07-19T12:02:23.741Z",
      "date_updated": "2026-07-24T14:34:15.323Z",
      "publisher": "Linux",
      "title": "net: skmsg: preserve sg.copy across SG transforms",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00352,
        "percentile": 0.27936
      },
      "nvd": {
        "published": "2026-07-19T12:16:56.337",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63830",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "sk_msg transforms move scatterlist entries without moving the corresponding sg.copy ownership bit, so a later BPF verdict can expose an external page-cache page as writable.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f126eed589eec6f201405abbc398844042ef6d57",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/31a110642b5fb5e61940cbcfb503445ac4f28017",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9bb86d8184b37503816150c4a6ad3c17dfdbe827",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0eb4c16c4adb262763bda870a8ed38a1a9dec7ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d22cc92bc41290e5783a72375e0843d9435f6001",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1acdd14c0990dd1cd4b6534f00366d2e6dfce05f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/406e8a651a7b854c41fecd5117bb282b3a6c2c6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1147,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63831",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T12:02:24.320Z",
      "date_updated": "2026-07-20T13:40:34.698Z",
      "publisher": "Linux",
      "title": "mac802154: llsec: add skb_cow_data() before in-place crypto",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15602
      },
      "nvd": {
        "published": "2026-07-19T12:16:56.460",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63831",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "IEEE 802.15.4 security code performs in-place cryptography on a cloned skb without first obtaining a private writable buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3a2b378b3a9ca75d3518d879148d2ad25b5714a9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7a831bcd0486788283ef35e396d4282ee01bb0d5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ff976ef7c39199ebff33c18034636595016db9f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e28e7fd34c449028325322a3f5127b92594b7396",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/993fd674fe85d114e6a8d3963033d4fbbc2170a8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bd968bdd568beacfdf98ec537a87527e85f1d0cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/86d531337ea1ba02d9f2bc830d07c683d9bfaade",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/84a04eb5b210643bd67aab81ff805d32f62aa865",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1963,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63832",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T12:02:24.908Z",
      "date_updated": "2026-07-20T13:40:35.633Z",
      "publisher": "Linux",
      "title": "wifi: mt76: add wcid publish check in mt76_sta_add",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.13025
      },
      "nvd": {
        "published": "2026-07-19T12:16:56.600",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63832",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mt76_sta_add() reinitializes a poll-list node after another path has already published it, corrupting the shared station list.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3c499851753a24d2e148d4e9ca51764c0c51554e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/55e014aaec650ede08b693ba59c8d0443f13f11c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/20b126920a259df4d7dcae19fcfe2c57a74d6b2e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 985,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63833",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T12:02:25.469Z",
      "date_updated": "2026-07-20T13:40:36.626Z",
      "publisher": "Linux",
      "title": "ntfs3: reject direct userspace writes to reserved $LX* xattrs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02586
      },
      "nvd": {
        "published": "2026-07-19T12:16:56.713",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63833",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ntfs3 permits a user-controlled reserved $LX extended attribute to preserve or manufacture SUID state outside the intended privilege rules.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e574af95234afc3c725988bbc1fdeb46b9f386a4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2c3cd6da4a14380ef79e34bd9dff7caf46687477",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e8852ae29868e449fdb47eebc28f35fb80741a5f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f8d420949b335a4b51d06ab276beee6b8dfdc909",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5e658b9245a52d838ef93729a7bc07de8e19deb7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/293a84fa40b3a1b3471c0545722724bc10973f76",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5b08dccecf825cbf905f348bc6ccb497507e28e2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 798,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-63834",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T12:02:26.045Z",
      "date_updated": "2026-07-19T12:02:26.045Z",
      "publisher": "Linux",
      "title": "batman-adv: tp_meter: restrict number of unacked list entries",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00174,
        "percentile": 0.07093
      },
      "nvd": {
        "published": "2026-07-19T12:16:56.840",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63834",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "batman-adv accepts sequence gaps that create an unbounded unacked_list, allowing attacker-driven memory and lookup work to grow without limit.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/31a88792bfba142be3c9521538c1db805677381f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1111a3381bca2d1f084a07686bc783af5ab23df7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1c616b0be4bd8399d485e25e91859373b95d6013",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f8c499fd275e59203b77fca76ae6ef2d096c2133",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c6231d628d06d841bc1617b2f7034f5f39876b16",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2233787658db859f0a9b83cb397cf783bb8be865",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1fb8762600a393d1caccd63be5d07e1756982d68",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e7c775110e1858e5a7471a23a9c9658c0af9df89",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 928,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63835",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T12:02:26.574Z",
      "date_updated": "2026-07-19T12:02:26.574Z",
      "publisher": "Linux",
      "title": "batman-adv: v: prevent OGM aggregation on disabled hardif",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00174,
        "percentile": 0.07092
      },
      "nvd": {
        "published": "2026-07-19T12:16:56.970",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63835",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The disabled batman-adv interface can still receive newly queued SKBs after its aggregation worker and prior list have been torn down, leaving those buffers permanently unconsumed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d462ced79dd430200cf888984e8005da77fc810b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f79deaaf822ab0ee2424cf28781f9ab91576bea3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d3569327fc7395b2b0461a0a0cb77a0bb74786c0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/97644fdaaf6446ffbe182c5eb804fceb5b1a51b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f04dde74399431fb07abbdd9cd5d0ed624771d04",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3d4548c96d6f21ac1a9b06c5f82f3ef439c87023",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/86ab6b6fb5b82163bf6c45780bb72150021d7349",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d11c00b95b2a3b3934007fc003dccc6fdcc061ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 707,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63836",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T12:02:27.166Z",
      "date_updated": "2026-07-19T12:02:27.166Z",
      "publisher": "Linux",
      "title": "batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00174,
        "percentile": 0.07093
      },
      "nvd": {
        "published": "2026-07-19T12:16:57.103",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63836",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A left shift wraps the congestion-window divisor to zero and the following calculation divides by zero.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/35264c4d46067d6312871488c810cef387f8c1f6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1381b021bf886b793fa5ffb895a8efae7ba0318f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d08b69da40a101df1e28bfe1e8fa7a09ffa41107",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cd74176cf1685f35a2e5f212d15748bbfecb53b6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ac229c86e49fdb96d91f51bc2fa37a9c4f58c44f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7d2a44bc6bbe39aed03c68864aa0e54e04a50278",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/585616dab0aa9c45bc11b2c8082ca78533bc00e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/33ccd52f3cc9ed46ce395199f89aa3234dc83314",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1158,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63837",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T14:04:33.781Z",
      "date_updated": "2026-07-19T14:04:33.781Z",
      "publisher": "Linux",
      "title": "net: ena: PHC: Check return code before setting timestamp output",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00167,
        "percentile": 0.063
      },
      "nvd": {
        "published": "2026-07-19T15:16:50.480",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63837",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ENA PHC path copies a timestamp to userspace even after the hardware read fails, exposing uninitialized stack or stale device values.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bddf59818ae5102e6d82a4dae5add6df8da38fb0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/edcb049d836e175e7b3d5e0d05657104545b5e65",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/24a08d7d6218d60c033015cf4870b6096446e734",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 670,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63838",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T14:04:34.454Z",
      "date_updated": "2026-07-19T14:04:34.454Z",
      "publisher": "Linux",
      "title": "ASoC: rsnd: Fix potential out-of-bounds access of component_dais[]",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.065
      },
      "nvd": {
        "published": "2026-07-19T15:16:50.583",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63838",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The driver allocates at most six component_dais entries but a boundary condition can make later iteration read one element past that allocation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9f1daac27ca28e98c8c0e4450de42bb68d547250",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/15e7b2ac2455995a6af02b9d3da7a432837aaf72",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/134c61925e9e9ee0f4fdbab5c3984d5bb024f5f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a62b3e6e42359a79158c134e3cf5c74fe160c3f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f9e437cddf6cf9e603bdaefe148c1f4792aaf39c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 566,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63839",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T14:04:35.146Z",
      "date_updated": "2026-07-19T14:04:35.146Z",
      "publisher": "Linux",
      "title": "platform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00156,
        "percentile": 0.05254
      },
      "nvd": {
        "published": "2026-07-19T15:16:50.693",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63839",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "lwmi_dev_evaluate_int leaves output.pointer outside cleanup when retval is NULL, leaking one allocation on that path.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/40a984dd0602e238ad893b167751620e751d1199",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0c3887a134f191723b53e2a47e501b534c8723ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63840",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T14:04:35.890Z",
      "date_updated": "2026-07-20T13:40:37.642Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v5.3.0 ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02246
      },
      "nvd": {
        "published": "2026-07-19T15:16:50.787",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63840",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The AMD JPEG ring accepts a 64-bit user-fence mode that the hardware path does not support.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/46ad73aec27d020f103b4262e4da2d2c22f54799",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3b0ea2021351b6b813b34fac940957f1f4fad85b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63841",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T14:04:36.591Z",
      "date_updated": "2026-07-20T13:40:38.619Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.1 ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02816
      },
      "nvd": {
        "published": "2026-07-19T15:16:50.883",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63841",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The JPEG ring accepts user-fence submissions even though that ring cannot perform the required 64-bit fence write.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d0f6ae14c0452be4fc3aa5cf81c74e68b3243050",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/869ce148c0d953570f8307c3e206b47bd5d3be99",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f8e3da71a1b469b6e157aa3972f1448b3157840",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63842",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T14:04:37.212Z",
      "date_updated": "2026-07-20T13:40:39.593Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02955
      },
      "nvd": {
        "published": "2026-07-19T15:16:50.987",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63842",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The AMD JPEG v5.0.0 ring accepts user-fence submissions even though the ring cannot perform the required 64-bit user-fence write, allowing an unsupported operation to reach hardware execution.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3a55ff19a6ff5e046d6a4a18e36deec5d95d9a2e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a7e63bb93a7fde3c8920984c3deee9acfe461562",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/69ab75c7c5f378eb46f4c918aa848bb5c5603924",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ea7c61c5f895e8f9ea0ffffa180498ef9c740152",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63843",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T14:04:37.815Z",
      "date_updated": "2026-07-20T13:40:40.562Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02955
      },
      "nvd": {
        "published": "2026-07-19T15:16:51.093",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63843",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The JPEG v4.0.5 ring accepts user-fence submissions even though that ring cannot perform the required 64-bit fence writes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/424510b60d4698a75a6ff71acdd88b528f0f39af",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f26e3f7186cd6ecc93e6af102744d64c798dea7e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f9bc5633b761cff200c428f61ed0df6212b1c721",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b65b7f3f3c18f797f81a2af7c97e2079900ad6db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63844",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.015Z",
      "date_published": "2026-07-19T14:04:38.452Z",
      "date_updated": "2026-07-20T13:40:41.608Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02952
      },
      "nvd": {
        "published": "2026-07-19T15:16:51.187",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63844",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The JPEG ring accepts user-fence submissions even though that hardware path cannot perform the required 64-bit fence writes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b884ff67d62ef514eee9d5f605c03101c8b6bc98",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d6bd2a5fd611ec9c8a2411f084cff2435c709608",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8549b3933038e68dc61cb934b9a54223dd244a78",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/249fa7549736de1c8e327d7ca6b32fa148a40bd6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/83e37c0987ca92f9e87789b46dd311dcf5a4a6c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 287,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63845",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:39.084Z",
      "date_updated": "2026-07-20T13:40:42.584Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02954
      },
      "nvd": {
        "published": "2026-07-19T15:16:51.290",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63845",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The JPEG v4 command ring accepts unsupported 64-bit user fence values, although the public record does not state the resulting invalid operation precisely.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d4e0172a1b614373385e9b7111b580f8d2e0b98f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a676f16ea9a7df96d69f405afb6eb349571b3382",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6876d05b899102f4dfdb9ad560132126144c1c72",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af4b458daa597dae707bf3f1f74745f5fc133ca2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e7e90b5839aeb8805ec83bb4da610b8dab8e184d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 285,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63846",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:39.674Z",
      "date_updated": "2026-07-20T13:40:43.573Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02954
      },
      "nvd": {
        "published": "2026-07-19T15:16:51.393",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63846",
        "family": "HARDWARE_PHYSICAL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The JPEG v3 ring accepts user-fence submissions even though that hardware ring cannot perform the required 64-bit fence writes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ee035a9d3eed3a9f5a3e83c31a10b321c9598861",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/303da8279f195cc741adc52c1b44d6b64de63bb0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5ada37d7f736f9feeaa06a25e470a4c74e67a61a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/48ce00787e3fddd2b45692fc991b8ab128343da5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a2baf12eec41f246689e6a3f8619af1200031576",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 285,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63847",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:40.248Z",
      "date_updated": "2026-07-20T13:40:44.592Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02905
      },
      "nvd": {
        "published": "2026-07-19T15:16:51.497",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63847",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The AMDGPU JPEG ring accepts a 64-bit user-fence submission even though that ring cannot perform the requested fence write.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/63691e396105611173072ad548fc2b68831ecf23",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4d96e3cbfc66e4d66ea0096bde858e28ab62da00",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3a96fee676fc0caf08f03ad915bec6fcd144d551",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/694fe016969c5e5a24b9e0ef7c1307eedec8ddf8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/79405e774ede411c6b47ed41c651e40b92de64a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 285,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63848",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:40.798Z",
      "date_updated": "2026-07-20T13:40:45.585Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02954
      },
      "nvd": {
        "published": "2026-07-19T15:16:51.600",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63848",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The AMD JPEG v2.0 ring accepts command submissions with 64-bit user fences even though that ring cannot perform those fence writes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f675801889b265634aefd30aa4503fc2b9e6ce1c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2e216c2ff159b2eb1da6e9c716d727efc73c64b5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b41248d1c18384835f6532e68592ee07605da283",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/41c4f3f68a343d62bd352a95ace93a11c4ad92ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e5f612dc91650561fe2b5b76dd6d2898ec9ad480",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 285,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63849",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:41.395Z",
      "date_updated": "2026-07-20T13:40:46.622Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/vcn: set no_user_fence for VCN v5.0.1 enc ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02816
      },
      "nvd": {
        "published": "2026-07-19T15:16:51.703",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63849",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The AMDGPU driver accepts user-fence submissions on a ring that cannot perform the required 64-bit fence writes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/081ef0e46c9cdd26c0db0ef721470393d36b6655",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5a4bffd67e94944ed3db26a959346cfb7fabaecd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8f4954722eab88e10c4ea0c0d3b1269c31421d3a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63850",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:41.975Z",
      "date_updated": "2026-07-20T13:40:47.581Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02954
      },
      "nvd": {
        "published": "2026-07-19T15:16:51.803",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63850",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The VCN ring accepts unsupported 64-bit user-fence writes instead of rejecting those command submissions.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9f5a1459ecc3195282be617639d710b54779c9dc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/139a8a52ef4349c62129703b3a3e3a6ae4d634eb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2c350f3cd94be847ac216e1358ec7001eaaf0934",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8cae0ce77de492d7c31c1532a2e80c0c6e7e58cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63851",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:42.581Z",
      "date_updated": "2026-07-20T13:40:48.563Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02161
      },
      "nvd": {
        "published": "2026-07-19T15:16:51.907",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63851",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The AMDGPU VCN rings accept user-fence submissions even though that ring version cannot safely perform the required 64-bit user-fence writes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/75091030f07b7957cc0646cd52e2d9d15f611483",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6d9a98c5ed65ba92a09e4ca5a5f6941448145529",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7f23b5c420b9f68a210c29c5123bace670aa8cc9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/589a254bf3e88204c8402b9cbccd5e23a0af990f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63852",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:43.258Z",
      "date_updated": "2026-07-20T13:40:49.533Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.0216
      },
      "nvd": {
        "published": "2026-07-19T15:16:52.003",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63852",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The VCN encoder ring accepts a 64-bit user-fence submission even though that ring cannot perform the requested fence write.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c12a5d35033c0640c57c10d7111c010c7b9c2c8e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/387b7c7667bd5c53549350ddad866d2fcf75a529",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9076a83e5adefd10dc5c967c7b8bde601c4c512a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0177ac6141c8857130cf365369c74dee7b6b1f7f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4532b52b34e4e4310386e6fdf6a643368599f522",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63853",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:43.885Z",
      "date_updated": "2026-07-20T13:40:50.539Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02071
      },
      "nvd": {
        "published": "2026-07-19T15:16:52.113",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63853",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The VCN v4 encoder ring accepts unsupported 64-bit user-fence submissions because it is not marked no_user_fence.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1286b6872de0aee1feeeaa6dbac86369806de9a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6bdd2ed6458d35c368fbe9550a4d7f342abd3a92",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/51f694221047c84fa185be98210eb2c354ffb8c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63854",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:44.487Z",
      "date_updated": "2026-07-20T13:40:51.515Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02162
      },
      "nvd": {
        "published": "2026-07-19T15:16:52.217",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63854",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "VCN v3 encoder and decoder rings are not marked no_user_fence even though they cannot support 64-bit user-fence writes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e74fc9c72c1ba78d0de0b849f5929c3b39a8e20c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/26c4f38529ac78930c9c4713e16ebc5b689bb0a3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2d6525e7b2504f5bbfe9417cddc1e8da858791dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b076e45e6f757a2829e80d0144c1b5f201bee5af",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f1e5a6660d7cbf006079126d9babbf0ccf538c6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63855",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:45.096Z",
      "date_updated": "2026-07-20T13:40:52.507Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02161
      },
      "nvd": {
        "published": "2026-07-19T15:16:52.337",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63855",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The VCN ring accepts an unsupported 64-bit user fence because the required no_user_fence restriction is absent.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2c6fb056567efb49f8674108b86088a1cfaa86d0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8f0ea4524dc71c6c9ec97f2711f46e12f624140f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/602d4c5872b25ddd4d82fb2025efb9a05b187bb3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5a3c6f76cab164a5d803084908d7050f649ab7f9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4f317863a3ab212a027d8c8c3cc3af4e3fb95704",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63856",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:45.716Z",
      "date_updated": "2026-07-20T13:40:53.515Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02162
      },
      "nvd": {
        "published": "2026-07-19T15:16:52.440",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63856",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The VCN v2 ring accepts a 64-bit user-fence request even though that ring cannot perform the requested fence write.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f264019be80de79f84f464846451445923bffea0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5e777bc4cbe928ac0fd95e368fee1540f2ce4db2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ac06ce5cac9e711281585d09d00c6efcd9b86396",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c71aecae98e42dcf2baf462df50b3a2cf1a93fe4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8d80b293b41fcb5e9396db93e788b0f4ebcbafb7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63857",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:46.339Z",
      "date_updated": "2026-07-20T13:40:54.471Z",
      "publisher": "Linux",
      "title": "net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27389
      },
      "nvd": {
        "published": "2026-07-19T15:16:52.543",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63857",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The final airoha transmit-loop iteration reads fragment address and length after the index has reached nr_frags, where the fragment entry is uninitialized.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f670fa4b19ceddc6d215dda4997888ccba9bbc61",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d78c8ab7bd84952e053d0c622b7fc1b4ad8a19a3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bde34e84edc8b5571fbde7e941e175a4293ee1eb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 694,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63858",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:46.967Z",
      "date_updated": "2026-07-20T13:40:55.475Z",
      "publisher": "Linux",
      "title": "netfilter: nf_tables: add hook transactions for device deletions",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01602
      },
      "nvd": {
        "published": "2026-07-19T15:16:52.643",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63858",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "nf_tables moves hooks between lists during transaction preparation while RCU readers can still traverse the original list.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4e69bfb32b2db323d9205fdb30e284481b37817c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/10f79dbd7719d1da9f5884d13060322d8729f091",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1123,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63859",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.016Z",
      "date_published": "2026-07-19T14:04:47.572Z",
      "date_updated": "2026-07-19T14:04:47.572Z",
      "publisher": "Linux",
      "title": "net: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.05141
      },
      "nvd": {
        "published": "2026-07-19T15:16:52.750",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63859",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Airoha TX cleanup path leaves DMA descriptors and producer indices stale instead of resetting the ring to an empty state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c0cfce4d76702dba9601a4020df1a0bc35806efc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9b5d56fe389d68ede080c716e6f10895facaf7db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3309965fe44c00fd65af7cef5016e9e782c021a7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63860",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:04:48.153Z",
      "date_updated": "2026-07-20T13:40:56.441Z",
      "publisher": "Linux",
      "title": "RDMA/core: Prefer NLA_NUL_STRING",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.0321
      },
      "nvd": {
        "published": "2026-07-19T15:16:52.850",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63860",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "RDMA attributes are treated as C strings even though NLA_STRING does not require a terminating null byte, allowing reads past the attribute.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fcd07d3b8ee7a39b344d73aed69c1a68cd9eacdf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/87111356d58d86edb221ba144d261ed83a5b8bbe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/abda65bdd13084c771842adaac1f652d0660dd82",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/137b5918931d4d05aa8ea8d3adf67f7224eef63c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5877c043398d5fa0e93919a3d837e5cd7a98a961",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f2c7b39dde2e61df8157066969cc2a408cd3dcd9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c26a0052cceed4c4d380ee5808b699f937fb58d8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ed3d14fc45d3da6025e7fe4a6a09066856698e2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 574,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63861",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:04:48.793Z",
      "date_updated": "2026-07-19T14:04:48.793Z",
      "publisher": "Linux",
      "title": "spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00161,
        "percentile": 0.05785
      },
      "nvd": {
        "published": "2026-07-19T15:16:52.973",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63861",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mtk_snand_probe registers a NAND ECC engine but omits unregister cleanup on probe unwind and device removal.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6aea4a99410615912d80a4ba0827c4e8d4a8312d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3e79a563377a319d016ed0d3cd8c43171670c0f3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/86357e1d0157d8408b78f8768a69ab263d010316",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e0b049bd7b279d7b6ad22a637cddced93198a51b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/98cf4b58299e0c6a537c68cd32155d9e7569e7cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ab00febad191d7a4400aa1c3468279fb508258d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 438,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63862",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:04:49.380Z",
      "date_updated": "2026-07-19T14:04:49.380Z",
      "publisher": "Linux",
      "title": "PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00161,
        "percentile": 0.05728
      },
      "nvd": {
        "published": "2026-07-19T15:16:53.097",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63862",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mtk_pcie_setup_irq allocates IRQ domains before discovering that the controller IRQ is absent and returns without releasing those domains.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/abd3c1927d33766aef39c4640880e3d2637429c2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/07a5ecb94768cbf76fe659e9924000e9ced0c8a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/946b31b5a699a2760ee52af0055e5ebf29c5f4cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0a2d60edc3e57c9512e239ebdfd12204d3368560",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/215d4273347b9010a9deae378b0df79c163f707d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5573c44cb3fd01a9f62d569ae9ac870ef5f0e0ba",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63863",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:04:49.967Z",
      "date_updated": "2026-07-20T13:40:57.433Z",
      "publisher": "Linux",
      "title": "drm/gpusvm: Fix unbalanced unlock in drm_gpusvm_scan_mm()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01631
      },
      "nvd": {
        "published": "2026-07-19T15:16:53.200",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63863",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An error path jumps to an unlock operation before the corresponding lock has been acquired.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8efaa47a871662a8c21b819cec60786f7ef17ab4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d287dee565c3c32e1ed76ec1847af46809c29b90",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 826,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63864",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:04:50.605Z",
      "date_updated": "2026-07-20T13:40:58.369Z",
      "publisher": "Linux",
      "title": "bpf: Propagate error from visit_tailcall_insn",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02442
      },
      "nvd": {
        "published": "2026-07-19T15:16:53.303",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63864",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The BPF verifier ignores an error returned by visit_tailcall_insn and continues with an invalid tail-call analysis result.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/945816e63c8677cf4bfde963a0774432ce8afc85",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6bd96e40f31dde8f8cd79772b4df0f171cf8a915",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63865",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:04:51.215Z",
      "date_updated": "2026-07-20T13:40:59.327Z",
      "publisher": "Linux",
      "title": "bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02238
      },
      "nvd": {
        "published": "2026-07-19T15:16:53.400",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63865",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Linux permits sleepable BPF hooks to run inside RCU or softirq contexts where sleeping violates the execution-state invariant.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/452a927cddcd67478d030e646f41cb904a93156f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f0fc2a9828171205244a28013f02889f50b71c9f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/26b380a3ca0b605fd8860995ed6a208f276dd316",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0d918263c9bfc86078edb2e2f7302a0c6ce42b7c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/281f2a214565a5cbf8b7355a65738d80bd19b8c5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/989f1b93907de1753a814996222da375f07e579b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/beaf0e96b1da74549a6cabd040f9667d83b2e97e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 323,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-63866",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:04:51.806Z",
      "date_updated": "2026-07-20T13:41:00.311Z",
      "publisher": "Linux",
      "title": "wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.13026
      },
      "nvd": {
        "published": "2026-07-19T15:16:53.517",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63866",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "mt7996 link teardown removes a station link without clearing its WCID pointer, leaving later code able to observe a stale station association.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/455a48685feebf2d9c1656caad77f9ba1da7b06e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c575459b485c47615491b1fd29f04b43fdc3da56",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/88973240dc7c976dd320b36a9e6d925c9be083ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 220,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63867",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:18:37.234Z",
      "date_updated": "2026-07-20T13:41:01.328Z",
      "publisher": "Linux",
      "title": "mptcp: close TOCTOU race while computing rcv_wnd",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24581
      },
      "nvd": {
        "published": "2026-07-19T15:16:53.617",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63867",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MPTCP reads ack_seq more than once without synchronization, allowing one packet to encode inconsistent acknowledgement state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/301a33fd590c408a05c5df800e0cc1e6a8a2f8f8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/68364963e5baf03f16b4420292291f75c8f66497",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/907ac6b1658e0277f979fcdfae2a753b495c1510",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c4f4cf60797974873dbc8e100144682a6f2f861f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3b8cbba7c0ed31189c89f90be247b8973ffa79ef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8f4f0a157e8436a05bf8c3670b24dbc258911c43",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8ab24fdebc369c0dfb90f82c1650b1e66662bb45",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 507,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-63868",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:18:37.823Z",
      "date_updated": "2026-07-19T14:18:37.823Z",
      "publisher": "Linux",
      "title": "net: garp: fix unsigned integer underflow in garp_pdu_parse_attr",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06139
      },
      "nvd": {
        "published": "2026-07-19T15:16:53.740",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63868",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "garp_pdu_parse_attr() subtracts the on-wire length in reverse and then truncates the unsigned underflow to u8, corrupting attribute-length comparisons.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/29f28172afb2ae7b31e9bf3e978396f20b381688",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/973cf7c433d27f4d9556d0b7c332543be7ed7a6e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d8dcd14aa886b8effd83022c550669f4f262854b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/74e02121be1dcc0efcd56ebdf0171d6129105659",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d4c86ea09ae3e63ee5aa86e941fcc38e0e39874a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/04e22fefac1af3e32f245e9045382348773b5d59",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a11f1a671b1361f0f1278dc0041374f2730df73f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/16e408e607a94b646fb14a2a98422c6877ae4b3c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 880,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63869",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:18:38.426Z",
      "date_updated": "2026-07-20T13:41:02.356Z",
      "publisher": "Linux",
      "title": "wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00211,
        "percentile": 0.11449
      },
      "nvd": {
        "published": "2026-07-19T15:16:53.873",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63869",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ieee80211_parse_tx_radiotap() uses an 8-bit attacker-supplied antenna index directly as a BIT() shift count, permitting shifts beyond the integer width.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f6d3dc8e8492bf8435e0b23c99472af7bafd6b44",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9b40c59bab08f2a99abf969cc0bb92fa49de004b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/033ce021a220913ac02416fcb5ac883a9ff8b6c7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c0cf89f36ac0c0fd8687a4ccdce2efb23a9c663",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1079,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63870",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:18:39.113Z",
      "date_updated": "2026-07-20T13:41:03.365Z",
      "publisher": "Linux",
      "title": "ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02484
      },
      "nvd": {
        "published": "2026-07-19T15:16:53.990",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63870",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A non-IPv6 frame skips initialization of lowpan_addr_info, while lowpan_xmit later copies and consumes that uninitialized headroom state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/af07fffbd53ddc3ec3c2a4ca914f27899fa89bca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3150e6d3223dfc356308125cabf9c34169842d2a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8da95cb6ad7d656c871e776a9c7b77e894d6d89c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1a827b95e62b4cbe851ae7cc9c961cdfa769cca4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c1819c8defa235c7beda859bc185b1c429a55ecd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/285b0842f2e01c3edf805f1fd64da11d9b7f6b4c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/87172cc8dc49aaf54407a31edffb0232f8cb93ab",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3a5f3f7aff18bcc36a57839cf50cf0cc8de707f3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 824,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63871",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:18:39.787Z",
      "date_updated": "2026-07-19T14:18:39.787Z",
      "publisher": "Linux",
      "title": "Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00157,
        "percentile": 0.05334
      },
      "nvd": {
        "published": "2026-07-19T15:16:54.133",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63871",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Bluetooth ISO route selection reads source and destination fields without the socket lock while concurrent calls can modify those fields.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9798f7d41d85ff763afd1f1cc0533b5c416c8348",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ab84fd7779a2a7ff5d2c8eac212c43733f56216e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/859bb1f4cb615d98c9c1ab2bd76ebb0b8fe46020",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9ca7053d6215d89c33f28893bfd1625a32919d3f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 982,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63872",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:18:40.499Z",
      "date_updated": "2026-07-20T13:41:04.348Z",
      "publisher": "Linux",
      "title": "esp: fix page frag reference leak on skb_to_sgvec failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.2012
      },
      "nvd": {
        "published": "2026-07-19T15:16:54.247",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63872",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An esp_output_tail error path frees scatterlist storage without releasing the old page-fragment references captured in it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e705b8ff4dd38fb8fe4e6fdc5378a86acea4feb5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2982e599fff6faa21c8df147d96fc7af6c1a2f24",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1436,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63873",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:18:41.197Z",
      "date_updated": "2026-07-19T14:18:41.197Z",
      "publisher": "Linux",
      "title": "accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.05179
      },
      "nvd": {
        "published": "2026-07-19T15:16:54.347",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63873",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "aie2_populate_range retries without dropping its mm_struct reference, leaking a reference on every trip through the loop.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e83fc4c28226be75fbc0c41f2846935ba2b5f949",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/21dfec59939120b20d2c7794caaa421f9450be0a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f41af638c92bac6f1f9275ea2d1901baef578f3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63874",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:18:41.907Z",
      "date_updated": "2026-07-20T13:41:05.329Z",
      "publisher": "Linux",
      "title": "net: mctp: usb: fix race between urb completion and rx_retry cancellation",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02072
      },
      "nvd": {
        "published": "2026-07-19T15:16:54.450",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63874",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ndo_stop can set the stopped state and cancel retry work while a concurrent retry queues a new URB, allowing completion to reschedule work after shutdown.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9c46f3ee1837f6881cb99a52ffecb2760f11dc73",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d90feaa3f74bea8dafb6494631a194c70e547d94",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/54665dce982689e2fd99b32e9a0dcc204fda8a51",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 961,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63875",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.017Z",
      "date_published": "2026-07-19T14:54:48.842Z",
      "date_updated": "2026-07-20T13:41:06.339Z",
      "publisher": "Linux",
      "title": "arm64: tlb: Flush walk cache when unsharing PMD tables",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 24,
        "versionRangeCount": 23,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06038
      },
      "nvd": {
        "published": "2026-07-19T16:17:04.357",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63875",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unsharing a PMD table leaves a stale page-table entry in the walk cache because the flush path ignores the unshared_tables state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/dced308d7d6a0de1c09d2058f38f1aaaf5cbb914",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/47490bbb05c8c0e09cc3cfd237d8934ffc340583",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0199c9d57861f17b556b6cba1f765c7cce79745b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d766a49d9b55705c4737cd8bb5d3faa2d31330fd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8ca7284da0e67b3e71d90ec17f08286774245ad9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fe93e907b1af03cc229a80aa64a570a103d2b279",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/48125cd9c55cbe297b59fd1f9bda48b0960bd181",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c2ff4764e03e7a8d758352f4aceb8fe1be6ac971",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1251,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 24
      }
    },
    {
      "cve_id": "CVE-2026-63876",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:54:49.549Z",
      "date_updated": "2026-07-19T14:54:49.549Z",
      "publisher": "Linux",
      "title": "serial: zs: Convert to use a platform device",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00209,
        "percentile": 0.11182
      },
      "nvd": {
        "published": "2026-07-19T16:17:04.500",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63876",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The legacy serial driver dereferences a parent-device pointer even though legacy probing never supplied that device.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bb2040484f90f91b717060e1a66026cc4287bcf0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6a83d5e24a84e746425cd93539130e5f7381ef47",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/237dc8c08de3cb293b6607aaee8b13b3a671e267",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4dc9f1517503c883d5ce25b7ab29d177d05edc6a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7cac59d08a73cb866ec51a483a6f3fe0f531947c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3657,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:54:50.257Z",
      "date_updated": "2026-07-19T14:54:50.257Z",
      "publisher": "Linux",
      "title": "serial: dz: Convert to use a platform device",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00209,
        "percentile": 0.11182
      },
      "nvd": {
        "published": "2026-07-19T16:17:04.653",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63877",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Legacy probing leaves the serial port without a parent device and initialization dereferences a pointer derived from that null parent.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c9e78361fe92fb64662fc3c8f34e2cdbb8c25bc6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6f59646229490a93cda950017ad4bdfbfe770a1d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2ff0401ffddaccc85f758c8259912d686d052b31",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5c9fb95c8d6430d11dbb7b44fbe23222585cda86",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5d7a49d60b8fda66da60e240fd7315232fa1754f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3734,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63878",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:54:50.977Z",
      "date_updated": "2026-07-19T14:54:50.977Z",
      "publisher": "Linux",
      "title": "drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09803
      },
      "nvd": {
        "published": "2026-07-19T16:17:04.800",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63878",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "amdgpu GEM_OP GET_MAPPING_INFO passes the user-supplied num_entries directly to allocation without an upper bound, allowing a request to demand an allocation larger than the supported size.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f059b4c493df3e54fe3ffe4658009c31864275da",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/967a00b8e06a7734aded23861faba9ee2462be87",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a1ba4594232c87c3b8defd6f89a2e40f8b08395d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 734,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63879",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:54:51.698Z",
      "date_updated": "2026-07-20T13:41:07.319Z",
      "publisher": "Linux",
      "title": "drm/amdgpu: fix amdgpu_hmm_range_get_pages",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06154
      },
      "nvd": {
        "published": "2026-07-19T16:17:04.903",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63879",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "amdgpu_hmm_range_get_pages reads the notifier sequence more than once and can continue with pages invalidated between those observations.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2fd24407457a6b181ba827705678da70e528dcd0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/962d684b5dc0741dcd93485d41b450de402d5592",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63880",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:54:52.397Z",
      "date_updated": "2026-07-19T14:54:52.397Z",
      "publisher": "Linux",
      "title": "drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09802
      },
      "nvd": {
        "published": "2026-07-19T16:17:05.007",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63880",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An ENOMEM return bypasses the shared cleanup path and leaves GEM references and VM locks held indefinitely.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1eb86334e391695d4a40743b114afc15df4dc506",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8f643d534ffc6f1b6182e4f3acff8f04890504b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2e7f55eb408c3f72ee1957a0d0ad11d8648a6379",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1976,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63881",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:54:53.676Z",
      "date_updated": "2026-07-20T13:41:08.305Z",
      "publisher": "Linux",
      "title": "drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00177,
        "percentile": 0.07417
      },
      "nvd": {
        "published": "2026-07-19T16:17:05.120",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63881",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An integer multiplication of the queue count overflows and produces an allocation smaller than the queue data later written into it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4e5f808b454167cc58d7084a407a554d8ddc694d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/de70a80992396ee306ee3a2810ad28aa1608ba9b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5cf4a41aa0d74e4c83f82d2ce233b5189ed4b43c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4f9eeedc3d3151f8a226fd676c314a813edda5a1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/93f5534b35a05ef8a0109c1eefa800062fee810a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63882",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:54:55.027Z",
      "date_updated": "2026-07-20T06:41:35.719Z",
      "publisher": "Linux",
      "title": "drm/amdkfd: fix NULL pointer bug in svm_range_set_attr",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00206,
        "percentile": 0.10772
      },
      "nvd": {
        "published": "2026-07-19T16:17:05.230",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63882",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SVM ioctl path dereferences process_info even when the required acquire_vm lifecycle step has not occurred.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e4dcb5d6360319609bc5b05fb40e98b0af6bc674",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6495cc09f7e6c2af571b3e2e4640283b3792ebf2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d4e73a047d4ea866b75ee4b879d0d787dfa2704c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f9c3c161692f5bf1436e869a651bed10936e071",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c24eee21f9a943374fd64260a6e17dc3984e3d0e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e984d61d92e702096058f0f828f4b2b8563b88ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 297,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63883",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:54:56.356Z",
      "date_updated": "2026-07-20T13:41:09.305Z",
      "publisher": "Linux",
      "title": "serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05547
      },
      "nvd": {
        "published": "2026-07-19T16:17:05.343",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63883",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Qualcomm serial driver flushes its FIFO before a pending DMA-completion interrupt and then lets the late interrupt decrement already-cleared state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c91ea13375f70f6271a0183445e34e83b8f4d8f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b1159dce10b38eb795e4c96cdc4d34b83cec81c5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/654f45a8569f3cd6ff20bd724a18e0cce65893ba",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0d2c41a8b00934ddf8a7c1b4cf72dffa1e629c46",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/452d6fa37ae9b021f4f6d397dbae077f7296f6f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1193,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63884",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:54:57.520Z",
      "date_updated": "2026-07-20T13:41:10.346Z",
      "publisher": "Linux",
      "title": "drm/i915: Fix potential UAF in TTM object purge",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06039
      },
      "nvd": {
        "published": "2026-07-19T16:17:05.463",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63884",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "ttm_bo_validate can replace bo->ttm, after which the purge path casts and dereferences the stale pre-move object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/df73f3bc731af1c39ac5405bc59c4e7c6f8e9117",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/28b22dbaf407598cb3bb1d2c586a6f8018690ac2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/073bcbc95e9648c976da1654c7590a8d6ee12c2d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c9ae7e7e3bc98615364313b08d7acea5239ded0b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a29654d451bbffe63d584a4cf64ad0efce6bcf1c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5c4063c87a619e4df954c179d24628636f5db15f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3998,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63885",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:54:58.590Z",
      "date_updated": "2026-07-20T13:41:11.345Z",
      "publisher": "Linux",
      "title": "drm/gem: fix race between change_handle and handle_delete",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05794
      },
      "nvd": {
        "published": "2026-07-19T16:17:05.623",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63885",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "drm_gem_change_handle_ioctl leaves the old handle live while dropping table_lock, so a concurrent delete can free the GEM object before the new handle is safe.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0dfa42cfe4dbe114533480503934f43e33c1e83d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cde2c9257cbe8463b9dcf7b1075177b72b5fd938",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7164d78559b0ff29931a366a840a9e5dd53d4b7c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 668,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-63886",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:54:59.395Z",
      "date_updated": "2026-07-20T13:41:12.282Z",
      "publisher": "Linux",
      "title": "scsi: target: iscsi: Validate CHAP_R length before base64 decode",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00664,
        "percentile": 0.48194
      },
      "nvd": {
        "published": "2026-07-19T16:17:05.723",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63886",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The iSCSI CHAP path base64-decodes up to 127 input characters into a 16- or 32-byte digest buffer before checking decoded length.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/82454e6f21e56ea9a0a9de7d0ff7e1dfb83e34d6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/edd06675a02376ea8347dba7c29ad982ba5b36ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bf154c657828ed05399bca5d98cf1611bb048b12",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4a3a19c98a8207ad08bec554703d90f2c34a8cc6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c04e85799356120209b351a148ac2db888d5ffd9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/85db7391310b1304d2dc8ae3b0b12105a9567147",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1808,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63887",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:55:00.114Z",
      "date_updated": "2026-07-20T13:41:13.237Z",
      "publisher": "Linux",
      "title": "scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00745,
        "percentile": 0.51244
      },
      "nvd": {
        "published": "2026-07-19T16:17:05.853",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63887",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "iSCSI login response records can expand beyond the fixed 8 KiB response buffer because three append sites do not check remaining capacity.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cb84e974fb172bc71386289f37b78ea679410b39",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b19382dfc6e7dee6d3859ba44b6ca29e97a51627",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/efe633e600a0ac68357206fede21b1ac8178f3b8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4e9f0c4a645c995bc75c06c7b3644254ffb4c76b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/30bf335e8fe170322080ee001f05ca29c50680b3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/594a40360012ce5f94c715d5e3b20fa3af7d525a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/26e4a304b7e6f1338c675d527608d32549c091db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bf33e01f88388c43e285492a63e539df6ffed64c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1792,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63888",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:55:00.803Z",
      "date_updated": "2026-07-20T13:41:14.224Z",
      "publisher": "Linux",
      "title": "scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00745,
        "percentile": 0.51243
      },
      "nvd": {
        "published": "2026-07-19T16:17:05.997",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63888",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The iSCSI Text handler hashes four bytes beyond its allocation and leaves text_in_ptr referencing freed memory on the ERL greater-than-zero digest-mismatch path.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f7948af0dd03de84079dcd4dc215a69fd6fbb95d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/badf178b76b0690851df00f4ca9cf2eb8eb0f963",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6e22a1cdcc8277af4acc43710577157b77a02c5d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d3e9b79aa794f7a23e82de4d710e7d2df610e349",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ec9f19d52074a191ed1756ed4a7d39fff1a2085c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/89c81d1228c00fa6dd91de6c1c5aa1ef8a7875e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5118ea225fe63b44207ba88047e4866e1ea43812",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/778c2ab142c625a8a8afa570e0f9b7873f445d99",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3569,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63889",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:55:01.515Z",
      "date_updated": "2026-07-20T13:41:15.239Z",
      "publisher": "Linux",
      "title": "scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00334,
        "percentile": 0.25989
      },
      "nvd": {
        "published": "2026-07-19T16:17:06.163",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63889",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An 8-bit FPIN walker counter is compared with an unbounded 32-bit pname_count, so a count of 256 wraps the counter and prevents loop termination.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/07776b7779c9426982c1ad74aad91bd531593790",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/29f126f09e34a425b376b3646c89aa7cc18b142c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/163bd704d7515c3df6c2e03bcba93d1db79edbff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ee57b89e5da9fffbe0d26647e4ff0750dacb9943",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/35461d23744175a78b6280293892cca357c22793",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bdff76dff6ec23d6fe35812fa33e5c4ce2cdb770",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a9a39233ec1fc9f97ea1340a4d09bb7ec2be5153",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1007,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-63890",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.018Z",
      "date_published": "2026-07-19T14:55:02.195Z",
      "date_updated": "2026-07-19T14:55:02.195Z",
      "publisher": "Linux",
      "title": "scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11392
      },
      "nvd": {
        "published": "2026-07-19T16:17:06.300",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63890",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The FIP CVL walker accepts a zero-length noncritical descriptor and advances its loop cursor by zero forever.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d179949d2175d2857d1c3a275a22bea58bcc5d36",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fda976f7390bb5d1e9b84ef11ebb17323038e0c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/80a0cd307205236ca28aa49bc553f58edcb9bf3a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e3c6e5a8fc15a74dfb1e0c1df9f1da73600a81a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/549859a1131052b07dff11a448e9f3221a40f260",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/14dd80a20a72ce334adcc2d67402360527065948",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d537d29d51c8b808469e5adacf3e5a0092700738",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9eed1bd59937e6828b00d2f2dfef631d964f3636",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1294,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63891",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:02.840Z",
      "date_updated": "2026-07-19T14:55:02.840Z",
      "publisher": "Linux",
      "title": "thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00263,
        "percentile": 0.18075
      },
      "nvd": {
        "published": "2026-07-19T16:17:06.440",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63891",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A recursive DIRECTORY backreference has no effective recursion-depth limit.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2b5f47a710172c962ef42d1b732b04d2ad0dce21",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/95839a67ea56ca35732aad7f711404a3127cfe2d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0a84ab9271936c11e84e511bb52fc5682f8b6726",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b4621e5ef63405c317a84b711faf3bd75b3c6a94",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f31c6d220f455b5af63590302b30e1b932d14599",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/830c8a9b467e7d3a158483d37fa7dc13892b293a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ed9455ef4bd9babc90f92e526abe3fb68c1a8709",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/928abe19fbf0127003abcb1ea69cabc1c897d0ab",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 958,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63892",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:03.568Z",
      "date_updated": "2026-07-19T14:55:03.568Z",
      "publisher": "Linux",
      "title": "thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0022,
        "percentile": 0.12574
      },
      "nvd": {
        "published": "2026-07-19T16:17:06.577",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63892",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A directory length below four both underflows size_t arithmetic and permits UUID copying beyond the property block.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/37abc4504fa19d8f9f1e87792e8a2b8fdb308e40",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e2d4d51cf5785815fa4e91e0c019e3eb2506a84c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/de618299190b418291609e6921557253bd417e25",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5506c825f14d810f0690b1f4367cb7249ebb387a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/542a13890b742099c461d70920e97b14e568f6ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d548179adcc87e1bc66b17e00352a1f536e76065",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3bec49ca55e08fb085cc4318f24b1b37eaab28cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/de21b59c29e31c5108ddc04210631bbfab81b997",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1419,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63893",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:04.288Z",
      "date_updated": "2026-07-20T13:41:16.262Z",
      "publisher": "Linux",
      "title": "thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28695
      },
      "nvd": {
        "published": "2026-07-19T16:17:06.710",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63893",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A 32-bit property offset-plus-length calculation wraps and passes the block-length check before an attacker-directed out-of-bounds read.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6a63623621639acbb39bc2d9fb09559681716695",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e8a0b0a93a6ef958e70b1dd4930beb6dc0026b36",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9fee50c4e1e42f6d3cbe30df584f9f648f626071",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8d4a758b407ab3de3be86d1ceadfa35d717d30c7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5c06a3043ad944f087bb2ae0aae28d820bb9f460",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/31b98e503ecca8077e5247253dd5425ab84bc96d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a47784aee77f33f786dc5d7375db821bdae68792",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/01deda0152066c6c955f0619114ea6afa070aaec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1011,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63894",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:04.882Z",
      "date_updated": "2026-07-20T13:41:17.296Z",
      "publisher": "Linux",
      "title": "usb: gadget: f_fs: serialize DMABUF cancel against request completion",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05513
      },
      "nvd": {
        "published": "2026-07-19T16:17:06.850",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63894",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "FunctionFS completion frees a USB request but leaves priv->req pointing to it for a later detach or close dequeue.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c872d8a065b3b499ce4c3ad168b5d34b68524f66",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c7d421123b98d5e9c1c84bd9957aba36f1cbb4ca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/552dae28dbeb5f7c4fafcda43962dc46569f58a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2796646f6d892c1eb6818c7ca41fdfa12568e8d1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3948,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63895",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:05.479Z",
      "date_updated": "2026-07-19T14:55:05.479Z",
      "publisher": "Linux",
      "title": "usb: gadget: f_fs: copy only received bytes on short ep0 read",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00244,
        "percentile": 0.15653
      },
      "nvd": {
        "published": "2026-07-19T16:17:06.990",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63895",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "FunctionFS allocates an uninitialized buffer for the requested control-transfer length and copies that full length to userspace even when fewer bytes were received.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/90ccf5fb63243fae1b4b3200f3310500500ecf2e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af32dbb2ca0b3d09271ab718d13857a457fa16f2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e835bf9a055f71874065a40780ca5560b7df8b33",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/88874a19b2b093bfaaa1c0090fa536c44da8c08b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/607730a414773a7cbe3037a64a6c64e72689ff5e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/23c1f7deb9dd8447ecde749850676302aa1e2bd3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4e036c10e7f4df5d951c69cc3697bc8e209c6d02",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2165,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-63896",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:06.152Z",
      "date_updated": "2026-07-19T14:55:06.152Z",
      "publisher": "Linux",
      "title": "usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10055
      },
      "nvd": {
        "published": "2026-07-19T16:17:07.130",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63896",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "WebUSB subtracts the descriptor-header size from a smaller unsigned wLength, wrapping the later memcpy length to nearly UINT_MAX.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/046870ff6b6f7b743c953c061043a9b30700d491",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f5869dfaa89854dcf34121036294d42d6c7acb8f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f8f5a8f48c7cae3fac85e04b593bd47939f9725f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a20f0ccf45708af6e063c7234c215d364b00de25",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c5dbc104dadd79fc2923497c20bae759a18758c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1379,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63897",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:06.845Z",
      "date_updated": "2026-07-19T14:55:06.845Z",
      "publisher": "Linux",
      "title": "USB: serial: mct_u232: fix missing interrupt-in transfer sanity check",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11396
      },
      "nvd": {
        "published": "2026-07-19T16:17:07.243",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63897",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mct_u232 parses interrupt-in data without first verifying the transfer size, allowing stale or uninitialized slab bytes to reach user space.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/82b48d70bced1ec8e5f676d1fd5eccc7a44dc418",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8b93ee5baeef6efabee2c3381907733ad2dbc883",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a093f3e0c03d25a86d747a655d4b9322ffb2ed87",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/70bb9a2661d34b93a9b83cf83e2b76289a712ef0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/631b8b7c456567f7a8d26f6fc354c8dd9cc9f832",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f06bcaba29707f060706483b2020d3cafbe98f9f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ed260b56bc9fc878e5dcbb866eab8af0688e0e67",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/245aba83e3c288e176ed037a1f6b618b09e92ed8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63898",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:07.452Z",
      "date_updated": "2026-07-19T14:55:07.452Z",
      "publisher": "Linux",
      "title": "USB: serial: mct_u232: fix memory corruption with small endpoint",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11395
      },
      "nvd": {
        "published": "2026-07-19T16:17:07.370",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63898",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mct_u232 raises the transfer length beyond a small endpoint's allocated buffer and lets USB input overwrite the receive slab.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/94edbbc5fe00d03cfe1d4e690d7d2cd36317a935",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bd2ddb3fe9052ad8703593bbec26ecc7ca92869e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/39e295a91e80f3b91f61c7ada2bde434dcaba20d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/90dbad14b109e5fdfb4934ff61e561d11ba3742d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6cb48f8890f9b2051d7c34823057296a536a31c5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d8fdf33d6fcfb90cbec26299baf2352c84b2d768",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57f332af1745014cd7e40414814ffaa6bc7d3b5b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/915b36d701950503c4ea0f6e314b10868e59fce3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 438,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63899",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:08.116Z",
      "date_updated": "2026-07-19T14:55:08.116Z",
      "publisher": "Linux",
      "title": "USB: serial: mxuport: fix memory corruption with small endpoint",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11395
      },
      "nvd": {
        "published": "2026-07-19T16:17:07.497",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63899",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An endpoint packet shorter than eight bytes drives a copy or offset calculation that corrupts the user slab.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/086b858b5f5125bc9d967ea2bd825f83d9f8f29d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f3661eb2446e1ef593da45e01a3b21a906768ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ccbec56f2f9af008f1574335cc6a668f16603e47",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be3a1ed4ae51fa8dde57383277d336ce834f2cd9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e906545641d34fb1a09a65b4b5cfdff40eb09681",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c0cf56f00f280d72180bb6ce79741bc787a6269",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b40166b4ef96067620a0f248e74ad9658c8f680c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4085f0dbb1ce2251c9a5938d693de6593f0ab2bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 300,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:08.847Z",
      "date_updated": "2026-07-19T14:55:08.847Z",
      "publisher": "Linux",
      "title": "USB: serial: keyspan: fix missing indat transfer sanity check",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11395
      },
      "nvd": {
        "published": "2026-07-19T16:17:07.623",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63900",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The USB path accepts an unchecked transfer length and parses stale or uninitialized bytes beyond the valid payload.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bd6c5fe59f374b63173afe5cf0ab38a9a370f2c1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e124120e89b61a967e40dee6b5e1ecafc45c09d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/41d9673941eebdde62ee73848fcfe4ae1105c979",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0bde5431037a076ff3750da2165fd77a6f5ff058",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3759a40738b83bb61699c85f063202b514b94f77",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ea2b792330b44b6d7ce671c3e1d59d0c121f7ed1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f7f566ad7519c7ca3bc9071350002940a2b0e22a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ab8336a7e414f018430aa1af3a46944032f7ff96",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63901",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:09.553Z",
      "date_updated": "2026-07-19T14:55:09.553Z",
      "publisher": "Linux",
      "title": "USB: serial: digi_acceleport: fix memory corruption with small endpoints",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11394
      },
      "nvd": {
        "published": "2026-07-19T16:17:07.743",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63901",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "digi_acceleport trusts device-reported bulk endpoint sizes and can access beyond a buffer when a malicious device supplies an endpoint smaller than the driver expects.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fd34198c2e5d164b57a7dcd4692626fece319225",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/25b93d0f229a115ab120106f37b9454170d4cfd4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ab1e9ae099577a1019312088309ecbad2da9a91",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8a65db5edd7b63365e9c5b7d9f4b8f314696dc49",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/41b645e791099f0038225da5e2ca3ca31f00d435",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/062dcc0b324afd03b1406f157190804f105718bb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9469419b12a100e7e2ccdda64ab45b8368456c8a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cb3560e8eab1dfa1cac1ed52631adf8ec6ff2cd5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63902",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:10.267Z",
      "date_updated": "2026-07-19T14:55:10.267Z",
      "publisher": "Linux",
      "title": "USB: serial: cypress_m8: validate interrupt packet headers",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11392
      },
      "nvd": {
        "published": "2026-07-19T16:17:07.867",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63902",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Cypress serial driver reads a format-specific header before checking that a short USB interrupt packet contains that header.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fcef31a5a85ccf3c313449a866ec6ed7e4132425",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aaa66708bfb1dca2acd219d1c1582f9f6d5492cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/44f9bab8df7750a1e2a4d6cc22d7c9c2dc096aed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be50533fe7068e86eb7adb81988e6d6a3f6dfe53",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/90664556916de22467097d4c8ceb716d597a5c32",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ae03453f2c809ca3cf73753269fa6184dea7160f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4a4cb0021ebe1fcadb52e04d19ed8d71470a530b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9f9bfc80c67f35a275820da7e83a35dface08281",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1040,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63903",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:10.905Z",
      "date_updated": "2026-07-19T14:55:10.905Z",
      "publisher": "Linux",
      "title": "USB: serial: belkin_sa: validate interrupt status length",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11396
      },
      "nvd": {
        "published": "2026-07-19T16:17:08.000",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63903",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "belkin_sa_read_int_callback() reads fixed status offsets 2 and 3 without requiring the completed interrupt transfer to contain four bytes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f1617539ab90e67da788959bfd314076f093a11a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f361359a952da15e70e693c2d7dca5c5843eae3e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/37e54d1b986df35c936d81e5b59a7aa3ec6938f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ffb739a49186ea784bbd9cb91b647f062395b419",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6a4602221cba7a738442328d66a2f0b1c9bf6e17",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/22823a319fb2afdf02cacafbed8b613b757efbc8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/db1e7eb6203d534dad64cac2c793b69e561e657b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4ce058df2ee02cc2a0f0fd5cd64ce6f1482a0b65",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 879,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63904",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.019Z",
      "date_published": "2026-07-19T14:55:11.547Z",
      "date_updated": "2026-07-19T14:55:11.547Z",
      "publisher": "Linux",
      "title": "usb: usbtmc: check URB actual_length for interrupt-IN notifications",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11394
      },
      "nvd": {
        "published": "2026-07-19T16:17:08.130",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63904",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "usbtmc accepts a short USB transfer while later code still consumes fields from the full expected structure, exposing stale or out-of-bounds data.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e794bd67b3faf98af46f958897f6b91412c7d2a9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e3eec3005de44e7f37d8d7724be636446516ab42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ae87f505917e703ae3b487d9663d78826ff43608",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5de7df75ef3a2756b25fe3d582a4a2970444fe5a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/69020fa089f1bf0e1a10a15265f31b143a846409",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/75f6d3da2cc646983f41807ef98851569c12bca9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f141b01eaa58ac7e323931d670318aa247bff087",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/52f2ad3f7e5eb3b5908e1d685d4342519dc9cfcd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 691,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63905",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:12.270Z",
      "date_updated": "2026-07-19T14:55:12.270Z",
      "publisher": "Linux",
      "title": "usbip: vudc: Fix use after free bug in vudc_remove due to race condition",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11394
      },
      "nvd": {
        "published": "2026-07-19T16:17:08.260",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63905",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "vudc_remove frees the enclosing vudc while its embedded timer can remain pending or executing against the freed object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/61704e5cf9cd7464b510eb606e7e2978b1160a64",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dcc1c90b28b28b7c493547506297e78653f81952",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1036ac6148995feaf486014d32bf26bf993c06a9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a0638db2340ee053ab0450656a763fd111475e54",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d07ed707467ce05ea9c03412d0c5ee9d0fe386a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/88d459e5b5a46da1ef9fd6f52d9439343edeec88",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/207bf80362df3fce8ebc9723351dcb1bc6d9ed0f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d96209626a29ea64666be98c30b30ac82e5f1be6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1592,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63906",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:12.982Z",
      "date_updated": "2026-07-20T13:41:18.250Z",
      "publisher": "Linux",
      "title": "usb: musb: omap2430: Fix use-after-free in omap2430_probe()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 17,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07229
      },
      "nvd": {
        "published": "2026-07-19T16:17:08.400",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63906",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "omap2430_probe drops the device-tree node reference before its final access, so the node can be freed while still in use.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/632fd888fe33083927e29ef651ac1aba345edd9e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b987f380620b38c84f054d5ff5c05861a7c2203b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/27e62532228dc42367bb43ebbcd7bf49d8db2b0d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/69f9f2b30af03d9b6e83f78fb0f734b6066d4678",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d53e4c41331f57b9fd78cbf3e480c6ce20aea07b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e194ce048f5a6c549b3a23a8c568c6470f40f772",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 382,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-63907",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:13.652Z",
      "date_updated": "2026-07-19T14:55:13.652Z",
      "publisher": "Linux",
      "title": "uio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00189,
        "percentile": 0.08822
      },
      "nvd": {
        "published": "2026-07-19T16:17:08.517",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63907",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The driver explicitly frees devm-managed allocation memory and device teardown frees the same object again.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e344865bfca4eb37ed8d7ac5917226e49fcec7ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f74c8696f14149d5e43cc28b015326a759c48f00",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 964,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63908",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:14.349Z",
      "date_updated": "2026-07-19T14:55:14.349Z",
      "publisher": "Linux",
      "title": "Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11394
      },
      "nvd": {
        "published": "2026-07-19T16:17:08.620",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63908",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An off-by-one greater-than check processes the first byte beyond an object's valid size and overwrites the adjacent configuration byte.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/862a1a32b5190241fce7a7d20229539a3926f31e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5c3681c3abc35cfac6b702251382312c60d96bc2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1017e1c6c6c49cccbcda9bbcfa49e50b0b6dad39",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e9b62996ba537774f68fecfd7eecb5aec1713952",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ae92e334544263a02d9f99e18385e718c44392c9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7f95f4792c0dc767fcb8e405391e779ab419d55a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c6b989b4ebf22b086fdfcac2163b5cb55e34d8f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/baa0210fb6a9dc3882509a9411b6d284d88fe30e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 926,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63909",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:15.060Z",
      "date_updated": "2026-07-20T13:41:19.196Z",
      "publisher": "Linux",
      "title": "ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 11,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00628,
        "percentile": 0.46661
      },
      "nvd": {
        "published": "2026-07-19T16:17:08.747",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63909",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A transposed ACE-size comparison is dead code and lets the DACL walker read ace size bytes even when fewer than four bytes remain.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5500ba1d410aed1eded3eb04a76b10cfb4409334",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f6324b4240cf0b26a84c33f68a1222d727ff4af2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0fe08c5776a798f46df1fd74b331be26bdd644d6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d333af32e4451285e427f2d9c29de3a39f6f6d48",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/94215d55b09445993929f4fc966061d61de74929",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4f7c131d2bdd7cd64b96f60d10be5ea72253f520",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e60dafe97eca61721f3db456f97d97a80c6c8ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 944,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-63910",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:15.770Z",
      "date_updated": "2026-07-20T13:41:20.122Z",
      "publisher": "Linux",
      "title": "dma-buf: fix UAF in dma_buf_fd() tracepoint",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05071
      },
      "nvd": {
        "published": "2026-07-19T16:17:08.857",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63910",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The file descriptor becomes visible before tracing finishes, allowing a concurrent close to free the dma_buf before the tracepoint dereferences it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b569f86e2f8dbf6f11d31d3de794d22e18098b23",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ead6680f354f83966c796fc7f9463a3171789616",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 928,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63911",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:16.496Z",
      "date_updated": "2026-07-20T13:41:21.102Z",
      "publisher": "Linux",
      "title": "xfrm: iptfs: reset runtime state when cloning SAs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.0535
      },
      "nvd": {
        "published": "2026-07-19T16:17:08.987",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63911",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "IPTFS clones embedded queues and timers by value, causing the failed clone to free objects still owned by the original state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9327252e04626d4bb02ca8c0c108fbe8eabf0c5a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dfb9f6cbfa9826655a49698cf90eb800fce2178e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7f83d174073234839aea176f265e517e0d50a1d2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1070,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63912",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:17.188Z",
      "date_updated": "2026-07-20T13:41:22.064Z",
      "publisher": "Linux",
      "title": "xfrm: esp: restore combined single-frag length gate",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 28,
        "versionRangeCount": 23,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00704,
        "percentile": 0.49761
      },
      "nvd": {
        "published": "2026-07-19T16:17:09.097",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63912",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ESP fast path checks trailer and data lengths separately, then allocates one page for their larger combined aligned length.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/566295735530ee513326049b0540f32ec050bf2e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5d7ab86e2b6bc23054616bf6ac562013bf60af8c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/36519e3d941fc99d3b52c134dbaf311f987a4708",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/322e48187e0245ab2fff6fec2220b0cae677dbec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b84091ceddc9f133229dceab3ccc930bf27f9cba",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c093468aea8277f77272a4f199b2e15e19cabb59",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/65f3b3fc2347b89fe21db1e92c7681368415f095",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dfa0d7b0ff1eb6b2c416b8fdb9b4f2cefba57a40",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 702,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 28
      }
    },
    {
      "cve_id": "CVE-2026-63913",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:17.917Z",
      "date_updated": "2026-07-20T13:41:23.046Z",
      "publisher": "Linux",
      "title": "netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00618,
        "percentile": 0.4621
      },
      "nvd": {
        "published": "2026-07-19T16:17:09.237",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63913",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "TCP conntrack accepts an invalid-sequence RST as a closing reply without checking packet direction or a matching opposite-direction SYN, allowing the packet to force the entry into CLOSE.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2006979a15af5404bf932a325357683c0bac1656",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6476c17d536dbd321c073242e762ddb2713a1238",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f5547bebc416d56f56fb5b86dc20aabfa42165a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2bb6d82b586ea5a4cb73bbdd6b7432e96096bc77",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f206def4e86d810f927ba1d8e322ea72b29bce58",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b98ab51c45c5608a1c19ce7fd17a3032469bb83f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d67c6adee8d1b65330d0174c4c367faba14e80a8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bed6e04be8e6b9133d8b16d5a42d0e0ce674fa9a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1100,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63914",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:18.618Z",
      "date_updated": "2026-07-20T13:41:24.004Z",
      "publisher": "Linux",
      "title": "xfrm: route MIGRATE notifications to caller's netns",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05214
      },
      "nvd": {
        "published": "2026-07-19T16:17:09.373",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63914",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The XFRM migrate path hardcodes init_net and publishes one network namespace's notification to listeners in another namespace.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bafc7d0774b9bf52909c70ed990bc5ccf7ec4bad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6df8157547347b5257bf640a0ae3dfc4411e06cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fe463798343382c8fe9416a95959f005a3c30aa5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/00f2c451e57df50b1151d9b2254878f106b7c892",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a306cf2ac8849c487791369fad6f216399d000f6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/448bb92ca101dde8a6e88b4dc824044b4e341604",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/26ce8dbf2e23fe4fcc3351d19ef6d3fb703ed126",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7e2a4f7ca0952820731ef7bdadfc9a9e9d3571b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1892,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63915",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:19.305Z",
      "date_updated": "2026-07-20T13:41:25.039Z",
      "publisher": "Linux",
      "title": "nfc: hci: fix out-of-bounds read in HCP header parsing",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27117
      },
      "nvd": {
        "published": "2026-07-19T16:17:09.517",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63915",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The NFC HCI receive paths read an HCP header before confirming the frame contains one byte, and a zero-length fragment can also underflow the reassembly length.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ed6d5d97dad0334a7f43d218753429cbe2f70a4f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b99366d74b535d0cadb1ef73e04639415d9ff3b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/37382293f174b82a0616c8295e32b1fc8e13d1ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c4cc6b3b0013acb3ed0b2b60e57dfae98647fe98",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1905f5ec3641b2b234bb63549c8ca11ab85466eb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/22d41b176b9989efd21c3b2d3abf6728f05b9d9a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/83b1362edc9d6ae376c6f36da116e2c70f2e70a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f040e590c035bfd9553fe79ee9585caf1b14d67b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 925,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63916",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:20.015Z",
      "date_updated": "2026-07-20T13:41:26.033Z",
      "publisher": "Linux",
      "title": "HID: wacom: Fix OOB write in wacom_hid_set_device_mode()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27118
      },
      "nvd": {
        "published": "2026-07-19T16:17:09.657",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63916",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The HID path assumes every usage belongs to field zero, so a larger usage index writes beyond that field's array.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2add311d99646c9d235b2c44f9c169ba30f5db3a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/83bd8a5756a3c4a413ed8f6253f9eb2821e1ccaf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5716a293fb19d382ca2336e08fd28a619a5f3c25",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ed598de9f61582902406d352d99f2073d8e00298",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/43e7c02d6090a82fd60d63491f6871aec906345e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b8338111e14183972359009c12d0dbd81d2e1e16",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5db3fca0cec7b33bc5379411d0a60d792c9f9bc0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c0a8899e02ddebd51e2589835182c239c2e224ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 857,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63917",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:20.703Z",
      "date_updated": "2026-07-20T13:41:27.007Z",
      "publisher": "Linux",
      "title": "ip6: vti: Use ip6_tnl.net in vti6_changelink().",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06039
      },
      "nvd": {
        "published": "2026-07-19T16:17:09.783",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63917",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Moving a VTI6 tunnel changes dev_net but leaves t->net at the creation namespace, so later relinking and cleanup use inconsistent state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0cdce7618464f7fb06f461e8f4ad575cb1d570f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f5c68875e25f331e497ddfbe81e2d8163a87f136",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d9c5eecdb3c740e65038651db7c686b10d76d1bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f1e89a943ee574d0f2f16246eb3f2d7330fdeb03",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/225b467e3b631f38be22e4b38062a1fed02fdd21",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fc32be9ac2788524c6b24efd681cce7a6e731a92",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ee1778ba0f5cb53be771f97017d01eb356c797bf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/11b326fb0a374f4654f9be22d0f0f7abd9f7d3fe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1078,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63918",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:21.414Z",
      "date_updated": "2026-07-20T13:41:28.058Z",
      "publisher": "Linux",
      "title": "l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05513
      },
      "nvd": {
        "published": "2026-07-19T16:17:09.917",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63918",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "l2tp_session_get_by_ifname increments a session reference after another thread can drop the last reference and free the session.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ee80455feffb9cb62b5b58715cabeff495e666b2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/947013fd7c8c35dd5856557b215840098a3f67f8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/782d60a6596aee9b29c2eecfa70033899278bf65",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/05f95729ca844704d15e49ce14868af4b403b32b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1914,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63919",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:22.121Z",
      "date_updated": "2026-07-20T13:41:29.060Z",
      "publisher": "Linux",
      "title": "xfrm: input: hold netns during deferred transport reinjection",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00633,
        "percentile": 0.46885
      },
      "nvd": {
        "published": "2026-07-19T16:17:10.030",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63919",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Deferred XFRM transport reinjection stores a network-namespace pointer without retaining a reference until the callback runs.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7ee59eda8820b758ed29e1cd3222359c7b97302c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2df7059a18afb7d3aee6c36cad5d371c198111d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8dfabcba6a943a7a02ebe1e1637c361ba96acbaa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/48ce101cd630d6745b6923b5bad8358bc4c119da",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/55ddfc41451f01c588089cd74957a05311b6f202",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9f7ebb45a83afc3216e855e57d51bb4bc9b5232e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9f67a36e91bb50d358760f381f233913fe5c09f8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c16f74dc1d75d0e2e7670076d5375deda110ebeb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 648,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63920",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:22.813Z",
      "date_updated": "2026-07-20T13:41:30.071Z",
      "publisher": "Linux",
      "title": "ipv6: validate extension header length before copying to cmsg",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05579
      },
      "nvd": {
        "published": "2026-07-19T16:17:10.153",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63920",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ip6_datagram_recv_specific_ctl() builds IPV6_{HOPOPTS,DSTOPTS,RTHDR} cmsgs (and their IPV6_2292* legacy counterparts) by trusting the on-wire hdrlen byte (ptr[1]) when computing the put_cmsg() length.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/81394827dfb72772c50d0ae3bdfa094428a5d76d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/931b4a1f13408c2507719890f78f7227c34a0282",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/08464413e628803bd10cb1df68d0138665f2f885",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a29768d56eb3798c052ad3281b05596e695a17af",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0d330eff318c0f44d4fb0ad2c2aef38f87f24c90",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a35daeabb433686234b010ebf7b53778dbd6c9b8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eb18a1b1644e4cad978df2131e2bb9a2e6886992",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dd433671fef381fdaf7b530c631e6b782d66e224",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1794,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63921",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.020Z",
      "date_published": "2026-07-19T14:55:23.539Z",
      "date_updated": "2026-07-20T13:41:31.106Z",
      "publisher": "Linux",
      "title": "ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.0733
      },
      "nvd": {
        "published": "2026-07-19T16:17:10.300",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63921",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Tunnel migration leaves authority and collision checks in the attacker's namespace while vti6_update mutates the creation namespace's hash.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/94ff740a7f9ef5c010784a325dca00cbf228f941",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/df42ac708acc3399bbb6dc5ca16e0540adda7bbf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/44d2ff7d2178503b93151140a45dfa2ad49c9906",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1acfb7d9c6fc7e209ed7789392697e97e03edd33",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d2236348414bdd6558385f35aa7fdc9bf5634011",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/853f6ea482dfcd3404bbef458ab4d68364eed838",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/596f6354c96a891e58c04a09cbfb7b0d1ec00dab",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8b484efd5cb4eeef9021a661e198edc5349dacf6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1834,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63922",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.021Z",
      "date_published": "2026-07-19T14:55:24.268Z",
      "date_updated": "2026-07-28T13:41:19.238Z",
      "publisher": "Linux",
      "title": "ipv6: exthdrs: refresh nh after handling HAO option",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00695,
        "percentile": 0.49429
      },
      "nvd": {
        "published": "2026-07-19T16:17:10.440",
        "lastModified": "2026-07-28T14:16:39.443",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63922",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The IPv6 TLV parser keeps a network-header pointer across a helper that can reallocate the skb head, then uses the stale pointer for later options.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b3ac54e5c905f86d22b502eacb5686a282c5659f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f8aabed3ff3e986920cf02a2a2785e08e586b234",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1a11eb7431e3d2882f5bd5939c5a9bbc65ccf4d1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/12d957979e4a800167842f1b42be6a606d227ebe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ff375ed1cba81392346c5bfbf0bb7a13b2946f99",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/751db1b802a067b7fff25880f4e9f9152a171538",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9b6dcc0a39fd71752937f0b6b3973e1416085dcf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f7b52afe3592eae66e160586b45a3f2242972c63",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 560,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63923",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.021Z",
      "date_published": "2026-07-19T14:55:24.985Z",
      "date_updated": "2026-08-03T09:32:36.909Z",
      "publisher": "Linux",
      "title": "octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05815
      },
      "nvd": {
        "published": "2026-07-19T16:17:10.560",
        "lastModified": "2026-08-03T10:16:32.130",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63923",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The representor event handler uses an attacker-controlled nested pcifunc as an array and mailbox index without validating its PF/VF range.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4467fa514482bbce82f73788943c815f3d126ab3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/68be0260e2a02ff9b18a8678d5f8d1715fa20138",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2156a29aecfffa2eb7c558255690084efbe9f3b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1539,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63924",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.021Z",
      "date_published": "2026-07-19T14:55:25.702Z",
      "date_updated": "2026-07-20T13:41:34.095Z",
      "publisher": "Linux",
      "title": "ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00695,
        "percentile": 0.49429
      },
      "nvd": {
        "published": "2026-07-19T16:17:10.667",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63924",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ipv6_hop_jumbo retains a network-header pointer across pskb_trim_rcsum even though that call can relocate the packet buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b3ac54e5c905f86d22b502eacb5686a282c5659f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/645b99b1a185c91a79bdac4c5de0f91b212d64f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9e883eaa878f4337b5873c706efb5a192364ed18",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bddaa4dfc7f36e1ee343a0622f69288af2b9ace9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/72af7beae774e46ed543f3f2f267bf0a141bfcdd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c512e1c819dfbf6ae95ee7a44b65b9ad98979157",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2b56bbd928c030894c270cd33d60286326919458",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d47548a36639095939f4747d4c43f2271366f565",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63925",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.021Z",
      "date_published": "2026-07-19T14:55:26.442Z",
      "date_updated": "2026-07-20T13:41:35.092Z",
      "publisher": "Linux",
      "title": "macsec: fix replay protection at XPN lower-PN wrap",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00341,
        "percentile": 0.26688
      },
      "nvd": {
        "published": "2026-07-19T16:17:10.787",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63925",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MACsec XPN replay window fails to advance when the lower packet number wraps, so the captured terminal packet remains acceptable indefinitely.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/dd7306779c6ce1238f4cdc34f3c1f2246b854457",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d15130461df388136b62a7b0ce9f66e7e2fa9ff1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/23c0e230eab397d7f68be2538790ac41d3bb91fd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/679e13a65e68a67c8b3c0467c02ee89157ec6f0f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/79495a1b0944fe31ffd54b54b00211b493590d62",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6d00f5c7e5ff7ec4795b7f5f8ed88bd346641652",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d55acbe577db892b60547b6ef1c020b359331a6d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e68842b3356471ba56c882209f324613dac47f64",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 742,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63926",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.021Z",
      "date_published": "2026-07-19T14:55:27.154Z",
      "date_updated": "2026-07-20T13:41:36.086Z",
      "publisher": "Linux",
      "title": "bpf: sockmap: fix tail fragment offset in bpf_msg_push_data",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07796
      },
      "nvd": {
        "published": "2026-07-19T16:17:10.913",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63926",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A global offset is confused with a fragment-local offset and corrupts the scatterlist.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f14609d8146707452e0822f3c8154674ce677251",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d81b323af2dcee47573907ccb89c0df9b45cb2e2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aeb95146848d12206e1b2cfacd4f40e21ce81d94",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/96b72672ce849a1402730238e64d9b20bf06a96d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3075c21d2d76c0067f4a382765b43d6cc10470f1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5e19028667963fb371ebb00cecc2a473ef92056b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/63f64a510c7917658ddf4d073ece73914ee25346",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f72eed9b84fb771019a955908132410a9ba9ea3f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 667,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63927",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.021Z",
      "date_published": "2026-07-19T14:55:27.864Z",
      "date_updated": "2026-07-20T13:41:37.085Z",
      "publisher": "Linux",
      "title": "usb: dwc2: Fix use after free in debug code",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05596
      },
      "nvd": {
        "published": "2026-07-19T16:17:11.040",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63927",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Debug code dereferences urb after usb_hcd_giveback_urb has transferred ownership and may have freed it.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d5fc183ed614aeba6779cc992325be560f9a4451",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/63b0dafa676aad4d0c3f01a61ad8e2990907660c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9fe1d84f7e2cf33634e8afb7f4b7f8de182dd913",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0584af4fe40fa5e254a05d69ce658746de641708",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a15eeeceb94cbc04edef395e4d777ff554bdc27d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/84ea928ed584756e59c6ac09736f12d1db95ded0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6d0b79d1d1118145e48a68192b6d733e39387053",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9ea06a3fbf9f16e0d98c52cb3b99642be15ec281",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63928",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.021Z",
      "date_published": "2026-07-19T14:55:28.593Z",
      "date_updated": "2026-07-19T14:55:28.593Z",
      "publisher": "Linux",
      "title": "USB: serial: omninet: fix memory corruption with small endpoint",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11392
      },
      "nvd": {
        "published": "2026-07-19T16:17:11.163",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63928",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The omninet driver allocates bulk-out buffers from a device-reported packet size but later performs a larger hardcoded transfer into them.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/180996f0ca774001944e4afa452d569ba2f6455c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b496e25ead5976bce2891dacaed09beb53a54f9f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4e7d32189d6219beb7db37cd0ea36b6bac7dfedb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9a3860454bdfb765f936965e975c594352602ffc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0bda1893e4cc4ad2b7dcdbaca246f2af688c6c2a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0fee0ccac29e088d4bfab7e2d075725dcecd803d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f34cf2928387fba01a78381f3258c7e1428897d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/60df93d30f9bdd27db17c4d80ed80ef718d7226b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 346,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63929",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.021Z",
      "date_published": "2026-07-19T14:55:29.309Z",
      "date_updated": "2026-07-19T14:55:29.309Z",
      "publisher": "Linux",
      "title": "iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10054
      },
      "nvd": {
        "published": "2026-07-19T16:17:11.277",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63929",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The IIO enqueue path retains the initial DMA-fence reference after reservation ownership is established, leaking one allocation per enqueue.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9678aeed8b77d495a417dd057d479f3733094019",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3412a95afaa5d3262008dfc34f3c7be33d8151dc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/96cdeaba6a008503455b78a9641c05c2a886a7ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a093999355084bdbfe6e97f1dd232e58a1525f0b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1236,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63930",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.021Z",
      "date_published": "2026-07-19T14:55:30.016Z",
      "date_updated": "2026-07-20T13:41:38.070Z",
      "publisher": "Linux",
      "title": "iio: buffer: hw-consumer: fix use-after-free in error path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05597
      },
      "nvd": {
        "published": "2026-07-19T16:17:11.380",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63930",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The IIO cleanup loop frees its current buffer and then reads that freed entry's next pointer to continue iteration.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b71893c57730809c222766e5718bb33610f11963",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2ff615fc455acda5425c4900160cbe11cfea4449",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d2759d49860b9a39b5cde2fb88e4b822ddf5f58f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/29783e6b6ec0b7152a15e53a063f17537e81177d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e965627f0d442bfcae3f496c90cb653fb0917a61",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a3763ae33476328cf8d661742deb9daec78eac96",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9319c94f63ed10723afd738d79f5617daba87cc8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6f5ed4f2c7c83f33344e0ba179f72a12e5dad4a4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 514,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63931",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.021Z",
      "date_published": "2026-07-19T14:55:30.718Z",
      "date_updated": "2026-07-19T14:55:30.718Z",
      "publisher": "Linux",
      "title": "iio: chemical: scd30: fix division by zero in write_raw",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11392
      },
      "nvd": {
        "published": "2026-07-19T16:17:11.507",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63931",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The sampling-frequency sysfs path divides by a user-controlled fractional value without rejecting zero.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4748bce423a363bb8a85a624faeb8f54fe331611",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6308b812acdcac38cbfe1af0b1524c3375f408a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c7a740bf75554b051fabb17596ca6e483d6e6d90",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e85bc501947f5ae16dd9adc01162b76d55ab7962",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d98c2e69aab905d1b19a69ffe584efa46a9efd42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5e4d34092a5ebfbc3a45a180c76ecb1cdbbedd53",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2c50c017df97bfb425038efdfb8514c7bcd08564",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5aba4f94b225617a55fed442a70329b2ee19c0a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 340,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63932",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.021Z",
      "date_published": "2026-07-19T14:55:31.460Z",
      "date_updated": "2026-07-19T14:55:31.460Z",
      "publisher": "Linux",
      "title": "iio: chemical: mhz19b: reject oversized serial replies",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09802
      },
      "nvd": {
        "published": "2026-07-19T16:17:11.633",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63932",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mhz19b_receive_buf appends a serial chunk to a fixed buffer without checking remaining capacity, allowing an oversized reply to overwrite adjacent memory.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a5a05410cb34bfa486d63684cdc1f87a3b13f20a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ea69e7a6efa88ef32090a91064c362738cc19ddd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/673478bc29cf72010faaf293c1c8c667393335a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 627,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63933",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:32.071Z",
      "date_updated": "2026-07-19T14:55:32.071Z",
      "publisher": "Linux",
      "title": "iio: gyro: adis16260: fix division by zero in write_raw",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.1139
      },
      "nvd": {
        "published": "2026-07-19T16:17:11.737",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63933",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "adis16260 write_raw accepts a zero sampling frequency and uses it as a divisor.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d2b83995759cfe5d06567bbcb600fe16d4048da3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/19eb8565c4500f9af17ec65eaf952365e2893351",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/59f80b945f2ca645064074d8507785c26ea16d2d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/86298fb6829cab983910810959f85d4b4fd0f5c1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aa8a5e118e97d2cfd0da5ea4f8f0f488efdea4b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aaf9d640e9ae1172d0a9c659ecb245a50a10850a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5a42e39606b9bd6b40ed02bdfd04fe179d6173f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/761e8b489e6cf166c574034b70637f8a7eadd0ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 316,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63934",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:32.681Z",
      "date_updated": "2026-07-19T14:55:32.681Z",
      "publisher": "Linux",
      "title": "iio: gyro: itg3200: fix i2c read into the wrong stack location",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0021,
        "percentile": 0.11358
      },
      "nvd": {
        "published": "2026-07-19T16:17:11.857",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63934",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Passing &buf overwrites the stack pointer slot and can expose uninitialized bytes from the scan buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/90e809376b0f0d1ddec2eec954aecdd2a5b40b0e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8654b5e2617819ff4f7c78071dfd0275e971a9b6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b64dd5f3b38911054cbcc570df617e3e8e75e562",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/31bbd4b87dd6701fa10e03ba7f6268e49e178d16",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/63203bd072b613c18c237b906b1c9d2dc4527337",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/15a0b3f33ffb6c78b3de6f69b026ceb09b973dd1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cfc3283859cfdeacadf80d5e6880bdf871ffeaa6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6bdc3023d62ed5c7d591f0eb27a5adb37fb892ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1182,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63935",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:33.321Z",
      "date_updated": "2026-07-19T14:55:33.321Z",
      "publisher": "Linux",
      "title": "iio: adc: nxp-sar-adc: fix division by zero in write_raw",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00189,
        "percentile": 0.08821
      },
      "nvd": {
        "published": "2026-07-19T16:17:11.987",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63935",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The ADC sysfs handler accepts zero or negative sampling frequencies as a divisor and also permits unsigned cycle-count underflow.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cb6ea15e7d3c7518f806975a06b7d4c0a26402ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a9aba21a539c668a66b58eeb08ad3909e5a54c2a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 497,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63936",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:33.942Z",
      "date_updated": "2026-07-19T14:55:33.942Z",
      "publisher": "Linux",
      "title": "iio: adc: mt6359: fix unchecked return value in mt6358_read_imp",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10054
      },
      "nvd": {
        "published": "2026-07-19T16:17:12.080",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63936",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A regmap read error is ignored and an uninitialized value is subsequently consumed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6258bfec51e894ea97b8e69f3cde7af269b37de9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/944082fdb0284a31c0b37a88c8a1d4404da3a6d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a72f8e51d6ee66c255a8a93a4421b8a538d112a8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f9bbd943c34a9ad60e593a4b99ce2394e4e2381b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 599,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63937",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:34.554Z",
      "date_updated": "2026-07-20T13:41:39.071Z",
      "publisher": "Linux",
      "title": "KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05978
      },
      "nvd": {
        "published": "2026-07-19T16:17:12.193",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63937",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "KVM reads guest-writable PSC entries more than once without stable snapshots, allowing the guest to change indices or values between validation and use.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bd232801ef1d1fd985d2d4ca3cd1d888303ca86f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b1dfaa6f7a957726a6800135be3659fbe4bbf2a4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/edbbe88f83b524434974e84808d3093199d67c24",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c8cc238093ca6c99267032f6cfe78f59389f3157",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63938",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:35.168Z",
      "date_updated": "2026-07-20T13:41:40.069Z",
      "publisher": "Linux",
      "title": "KVM: SEV: Check PSC request indices against the actual size of the buffer",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07795
      },
      "nvd": {
        "published": "2026-07-19T16:17:12.323",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63938",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KVM validates guest PSC indices against the maximum scratch size instead of the smaller effective buffer size.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5198f70c09a5f6e9e5f5a0a2c6b388f24294b176",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/75c8d1d7291268b479794fba5808971dc2f5eaf3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/505a3b94535583e4265360e2621734e355ef263d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/121d88de56bc5c0ba0ce2f6381af67f948a7e7c1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63939",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:35.743Z",
      "date_updated": "2026-07-20T13:41:41.058Z",
      "publisher": "Linux",
      "title": "KVM: SEV: Compute the correct max length of the in-GHCB scratch area",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09702
      },
      "nvd": {
        "published": "2026-07-19T16:17:12.433",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63939",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KVM treats the PSC scratch length as a maximum even though it is only a minimum header length, permitting processing beyond the remaining GHCB shared buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6ca9400d36005ffdca25f80186bea781c7e1dc4c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9f0a9e780f02c02d025a190f1885e1d1d73b87bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6644565527c4c5f507088b1c9ddf72de47790b68",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5867d7e202e09f037cefe77f7af4413c7c0fa088",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 827,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63940",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:36.408Z",
      "date_updated": "2026-07-20T13:41:42.039Z",
      "publisher": "Linux",
      "title": "KVM: SEV: Ignore Port I/O requests of length '0'",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07796
      },
      "nvd": {
        "published": "2026-07-19T16:17:12.540",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63940",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KVM's SEV port-I/O path subtracts from a zero-length request, underflowing the transfer size before the memory access.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3b6035bc6bff20e89752ce4358bc4c9a9d5883f2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2254972d4d69e279ba4e87bf0968eb08ad0d3c92",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c30cde934c7813b4e3069765dac64ce3d31e34f2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3988bd2723de407ae90fa7a6f6029b4e60238c58",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63941",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:37.047Z",
      "date_updated": "2026-07-20T13:41:43.069Z",
      "publisher": "Linux",
      "title": "KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05072
      },
      "nvd": {
        "published": "2026-07-19T16:17:12.643",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63941",
        "family": "HARDWARE_PHYSICAL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KVM restores a guest hypervisor's uncapped ZCR_EL2 vector-length value into the physical register when the value was written through the untrapped ZCR_EL1 path.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/742a9b5ccd8c46caf983ca90c94f855466968e34",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/83726330748981372bde86ed5411d7b306612991",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1491,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63942",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:37.717Z",
      "date_updated": "2026-07-20T13:41:44.057Z",
      "publisher": "Linux",
      "title": "parport: Fix race between port and client registration",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06038
      },
      "nvd": {
        "published": "2026-07-19T16:17:12.747",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63942",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "parport publishes port devices before initialization completes, allowing concurrently registering clients to attach to a partial or tearing-down port.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f3378b0d7bd4605de89b083b2900788157a181cc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/290f515c5e3b3900bc2fe24f179999fd08d23bfa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d16548be2ea5058227d79799e81dab61c9bca8ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/15b1723c1472e802f9f7e69ae4e64f7dbf588848",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/51026cff1f4f3b762a0b5a07c727bd59cef45320",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/74d6aae1df45d3414178986be743f946988fddf6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a1e81b58da0179531bedf0b9f2811f5f992d5c4b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ef15ccbb3e8640a723c42ad90eaf81d66ae02017",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1400,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63943",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:38.411Z",
      "date_updated": "2026-07-19T14:55:38.411Z",
      "publisher": "Linux",
      "title": "Input: xpad - fix out-of-bounds access for Share button",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 14,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10058
      },
      "nvd": {
        "published": "2026-07-19T16:17:12.880",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63943",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "xpadone_process_packet derives a Share-button index from an attacker-controlled packet length without checking the minimum offset.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bcfb4833cd4078a1a356ef451838b75cd233099e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/37ec54abfdd63a63fd50734a9c4e4cbc1e5795af",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9749db57233b396353ad5dee81eec9d9880c9246",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6346b0895b574ce45f3747b9c508c72f70e6abef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6cdc46b38cf146ce81d4831b6472dbf7731849a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-63944",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:39.105Z",
      "date_updated": "2026-07-20T13:41:45.061Z",
      "publisher": "Linux",
      "title": "Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24879
      },
      "nvd": {
        "published": "2026-07-19T16:17:12.990",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63944",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Bluetooth path dereferences conn after releasing its RCU and device locks, allowing a concurrent disconnect to free the object first.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a55618c0f4cead9e59c63f5ee030d393fd70d861",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a921957d39290143629eb38c4f74b9bef8035d0a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d9019210c8c30d40eb20094274cc647e352f48f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/380e67b1794a9a281a0cb592b4e62077fbd0c8ca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bfea6091e0fffb270c20e74384b660910277eb6c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1411,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63945",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.022Z",
      "date_published": "2026-07-19T14:55:39.859Z",
      "date_updated": "2026-07-20T13:41:46.058Z",
      "publisher": "Linux",
      "title": "Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05598
      },
      "nvd": {
        "published": "2026-07-19T16:17:13.107",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63945",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "iso_sock_clear_timer reads a connection pointer without the socket lock while iso_conn_del can clear and free that connection.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d9cbf7144ec589a3f0cc91f74a1a1af2d2b14afa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/35f68f36d9883d56dec21cf85f7556d4657fc393",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/996c2104d0726a8fe584f85b3d6327197374a348",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bc08c15746f25f41dd0508b25780d1e84acbb2ef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/51cb9dcfdf9a1bccf312ab2ae4b62db629f7dcd5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4b5f8e608749b7e8fa386c6e4301cf9272595859",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1190,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63946",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:40.577Z",
      "date_updated": "2026-07-20T13:41:47.085Z",
      "publisher": "Linux",
      "title": "Bluetooth: ISO: fix UAF in iso_recv_frame",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25258
      },
      "nvd": {
        "published": "2026-07-19T16:17:13.223",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63946",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "iso_recv_frame drops its lock while retaining an unreferenced socket pointer that a concurrent teardown can free.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c57ea90f203c8b8b41a474f19a09000d0f841436",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/119fb6f80c44dc1c65d604cf28e64c56bd9b6568",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b04ec131325baf4ea4577d6c6e6b86cf092e3731",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c318aa51830a3d2cc1229968fe521441c97356cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1a6b803b00ccdd7666506adbe01ddae1c72d1ca9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/47f23a259517abbdb8032c057a1e8a6bf3734878",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 610,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63947",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:41.306Z",
      "date_updated": "2026-07-20T13:41:48.101Z",
      "publisher": "Linux",
      "title": "Bluetooth: HIDP: fix missing length checks in hidp_input_report()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26259
      },
      "nvd": {
        "published": "2026-07-19T16:17:13.337",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63947",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "hidp_input_report reads keyboard or mouse fields without first verifying that the packet contains those bytes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1f08a90013e1e632b34321334e861fcefc056505",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cc3832b19f863e3677c5651f001a2e3795f39eb8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d313683d6ccdd8c01e0562270a2ae25b86d8461d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d7d6a81b8dd1a8d084a1b755db9406041d53adb5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6348dfed5b0f9c6074f14322332e97493d32fef0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b83dcacd2ec7fcc5a48be215f82d573759f87ec2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2a3ac9ee11dbb9845f3947cef4a79dba658cf6f6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 824,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-63948",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:41.985Z",
      "date_updated": "2026-07-19T14:55:41.985Z",
      "publisher": "Linux",
      "title": "Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 28,
        "versionRangeCount": 24,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11389
      },
      "nvd": {
        "published": "2026-07-19T16:17:13.460",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63948",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The L2CAP timeout's null-connection return skips the reference release paired with timer scheduling.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/50f1bcaaaa3a80bb1c3472044bc146e8d49d51ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b5c59a5b469e2a809a2d57eda4ded94235971060",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8894c2010435a56ce7c6c2a8785860c13554df2f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/63cd225cc13d782a85e2a73c04d0d350153eada1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/107c826e4ef9ec5ad8f60e6fe64d8d5325ba508f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e8a5baff5be273ca07771fd2b9bb1f2a4152917b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/08d81fe96f80a8e20c7acb573b6a45d901fcf2cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9dbd84990394c51f5cee1e8871bb5ff8af5ed939",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 482,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 28
      }
    },
    {
      "cve_id": "CVE-2026-63949",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:42.679Z",
      "date_updated": "2026-07-19T14:55:42.679Z",
      "publisher": "Linux",
      "title": "auxdisplay: line-display: fix OOB read on zero-length message_store()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00172,
        "percentile": 0.06878
      },
      "nvd": {
        "published": "2026-07-19T16:17:13.600",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63949",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "linedisp_display reads msg[count - 1] before checking whether count is zero, so a zero-byte sysfs write reads one byte before the allocated buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ca5b0781946d5083ceafa752141f47f085853620",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8776032fe989a9b5fc77f2de5e03e4adb44c630e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3859960daeb9b7b39b9847b5b0113bc6081eb735",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/197476b126010bac1b3199833c6966cd6f54c2a9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ad4f75ef9f3372fce8cad494e789ac6a5507bef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1532,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63950",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:43.404Z",
      "date_updated": "2026-07-20T13:41:49.078Z",
      "publisher": "Linux",
      "title": "mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05815
      },
      "nvd": {
        "published": "2026-07-19T16:17:13.730",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63950",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "try_to_unmap_one reuses a prior loop iteration's nr_pages value and applies the stale count to reference and map-count updates for a different folio.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0fcc34d0d8fefca4fea349e45c10e3a3d90350eb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f611db9b771b2b6775357555d2517af044fca4f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3f8968e9cbf95d5d87d32218906cab0b9b9eddbe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1518,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63951",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:44.105Z",
      "date_updated": "2026-07-20T13:41:50.089Z",
      "publisher": "Linux",
      "title": "zram: fix use-after-free in zram_writeback_endio",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06115
      },
      "nvd": {
        "published": "2026-07-19T16:17:13.837",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63951",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The zram completion handler releases its lock before wake_up(), allowing the writeback task to free wb_ctl in that window.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ebe2cbefc86291fa7f386447a81995640df4e2fd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bf62f69574b19720ae5fbbbcdf24a0c4e3e05e43",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2062,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63952",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:44.809Z",
      "date_updated": "2026-07-20T13:41:51.115Z",
      "publisher": "Linux",
      "title": "memfd: deny writeable mappings when implying SEAL_WRITE",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05656
      },
      "nvd": {
        "published": "2026-07-19T16:17:13.950",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63952",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The code applies the implied write seal only after checking for writable mappings, violating the required sealing order.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b3f4f82d1315f1439059a83d1c22c51a5b43d99e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3be2a24f7f72ad7321ed6ad1715b956a4527bcf4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0995d1f79aed8ccbf62056189dd53fd19726ea08",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/555702282d4536a865dfffb1cd4f6028f196e7e8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3b041514cb6eae45869b020f743c14d983363222",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 639,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63953",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:45.509Z",
      "date_updated": "2026-07-19T14:55:45.509Z",
      "publisher": "Linux",
      "title": "mm/migrate_device: fix pgtable leak in migrate_vma_insert_huge_pmd_page",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00189,
        "percentile": 0.08822
      },
      "nvd": {
        "published": "2026-07-19T16:17:14.060",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63953",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The huge-PMD migration abort path returns without freeing a page table allocated earlier in the operation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/24861d04f197bb651e9dfb211978271c15f75a98",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2c6f81d58741349298f51ff697d988cb42881453",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 382,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63954",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:46.183Z",
      "date_updated": "2026-07-20T13:41:52.092Z",
      "publisher": "Linux",
      "title": "hpfs: fix a crash if hpfs_map_dnode_bitmap fails",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06039
      },
      "nvd": {
        "published": "2026-07-19T16:17:14.183",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63954",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HPFS calls hpfs_brelse4 on uninitialized buffer-head pointers after hpfs_map_dnode_bitmap fails.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/010b08084000ef018f1a8de5197087f3b91d8cfe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d98d8562b3284b5a5c8eb67e71b794508e46e288",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1648a3c7f4e18f46a4881920133fc4f2494185a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7c58c55a2a16f7274772507bd1637be609351b4f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1d73a533760bc5abb83b3cc759133596f7bb708f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0886c6f257fe3663f80218aa1919b0f3f21bf22c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4f37bb30b57d6d403d02673074555bd3c3602bef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/974820a59efde7c1a7e1260bcfe9bb81f833cc9f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63955",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:46.903Z",
      "date_updated": "2026-07-20T13:41:53.082Z",
      "publisher": "Linux",
      "title": "mm/vmalloc: do not trigger BUG() on BH disabled context",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00468,
        "percentile": 0.38063
      },
      "nvd": {
        "published": "2026-07-19T16:17:14.307",
        "lastModified": "2026-07-27T17:44:23.777",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63955",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "__get_vm_area_node treats a bottom-half-disabled caller as interrupt context and triggers BUG even though vmalloc is valid in that execution context.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ad7eff07b625f53c3fb513b30d7a8c5a79fbc7ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/04aa71da5f35aacdc9ae9cb5150947daa624f641",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 810,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63956",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:47.597Z",
      "date_updated": "2026-07-19T14:55:47.597Z",
      "publisher": "Linux",
      "title": "USB: serial: cypress_m8: fix memory corruption with small endpoint",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11391
      },
      "nvd": {
        "published": "2026-07-19T16:17:14.410",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63956",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Cypress USB serial driver accepts an interrupt-out endpoint smaller than eight bytes and then writes beyond the allocated endpoint buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4fcb22218f0a7229b7ce3b3952fb644def293fa5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ad3d1628a46134276546d7a12fedf04be9979158",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/52e18ae0c47c5c89e18fcd8022f287f7cc8802ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4bcaa59f403dbde6328604a500d65ee8d40975d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1ef25704bd3b625fd151c09feee459479f71ee64",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/284105c40fc31fff90cdab8a0377aaeb92f87f0e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c13f3bb652bc8665e709ba07122612586aea648",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e1a9d791fd66ab2431b9e6f6f835823809869047",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63957",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:48.196Z",
      "date_updated": "2026-07-19T14:55:48.196Z",
      "publisher": "Linux",
      "title": "USB: serial: safe_serial: fix memory corruption with small endpoint",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11391
      },
      "nvd": {
        "published": "2026-07-19T16:17:14.533",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63957",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The USB serial driver trusts a device-reported bulk endpoint smaller than its eight-byte safe-mode write and corrupts the slab buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e3a1d6eee25dc96b1d2db0ecd9d8741e92056476",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c7336c0fba5c959249f3d793d33076b992ec3ee4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/161ea0e5236f5f051d2d85d6c54dd08ee9dc7ba4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9b3145b3001fb24de1da72d1deb0bea70e5a078b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a550ed2117ca4709d38f713933ff924a83942e41",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f793b67d41e5fab719c5a90baa77cbd2fe259517",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/857b3cc73f91871ae4433f8b97c4670b78f8dc96",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/438061ed1ad85e6743e2dce826671772d81089ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63958",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:48.835Z",
      "date_updated": "2026-07-20T06:41:38.075Z",
      "publisher": "Linux",
      "title": "usb: typec: ucsi: validate connector number in ucsi_connector_change()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00206,
        "percentile": 0.10771
      },
      "nvd": {
        "published": "2026-07-19T16:17:14.667",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63958",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A PPM-supplied connector number indexes the UCSI connector array without checking for zero or the reported connector count.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cea949203faef9cb783adc7b978cce056271e057",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/156b6f0aec6108909b0c4aedc78865b12766b347",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bd24d92af4ae021b6209f28e9a57e1bf2260d4fd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0edd1e21587b0483c7ceb993b9fb9668bbef7433",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5af2719b460ab904c504fc069d1dd2a3aa2b22b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/288a81a8507052bcfbf884d39a463c44c42c5fd9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 662,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63959",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:49.553Z",
      "date_updated": "2026-07-20T06:41:39.202Z",
      "publisher": "Linux",
      "title": "usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10057
      },
      "nvd": {
        "published": "2026-07-19T16:17:14.780",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63959",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The TCPM driver trusts the header's data-object count without confirming that RX_BYTE_CNT contains the advertised body, exposing uninitialized stack bytes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0af00f1459f5dd757f0d392f8caa38039561ac62",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dc17721d42e6d89f63572e63add8306a0e15eb3c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9b496e3371c04f0a03b7faa5d2442536d00e3998",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c4ab8e2d4432abb646c5c0687f8dab173da901f9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aa2f716327be1818e1cb156da8a2844804aaec2f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-63960",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:50.282Z",
      "date_updated": "2026-07-20T06:41:40.389Z",
      "publisher": "Linux",
      "title": "usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11389
      },
      "nvd": {
        "published": "2026-07-19T16:17:14.897",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63960",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "wcove_read_rx_buffer accepts up to 31 wire bytes for a 30-byte structure and also passes a byte pointer to a four-byte regmap_read output.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3e632098d0521257ea965bbd6fde807d9bee5c8a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f2a1edc0bd142edabc6c85d88713f2bc178dd317",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6899f5b6d7b83ce79a3d331dc61dd31bf73f9c22",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5cd0e7ac4eefbdb330f8c72694fe74e63df65552",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d0e4b8b3c6b7607a16932556eaaca5d5cf69f192",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e94933dc41b87503bf585c8c6d53d740620eceb9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3f9d50c8b02b4af0646aa892465080f9061fc89c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4af7ad0e6d7aa4403dbb1dac7b9659b0421efcaa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1485,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63961",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.023Z",
      "date_published": "2026-07-19T14:55:50.993Z",
      "date_updated": "2026-07-20T06:41:41.563Z",
      "publisher": "Linux",
      "title": "usb: typec: altmodes/displayport: validate count before reading Status Update VDO",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11391
      },
      "nvd": {
        "published": "2026-07-19T16:17:15.033",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63961",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The DisplayPort status handler trusts an incorrect object count, reads uninitialized stack bytes, and sends them elsewhere.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/74aabe9ea30fdfba924fce9594e6aa69a596a4bb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dd7118c010f324497c275e8fd7a35c9baaa2a00f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ffdbcd7a02f3af8fff9b6519830369f574ed44c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/70e7045849e954e56dcbf441b6330e66bc996306",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/64bd6ccc5799f8473d1f37d4d8f53093dfec5c02",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b10eff5abe6aa2a5af10ed17bddff76e3b6e6b9b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/77a759ec30bc5fb0dd9c867b711d0acfed6c7faa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8a18f896e667df491331371b55d4ad644dc51d60",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 388,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63962",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:51.682Z",
      "date_updated": "2026-07-20T06:41:42.766Z",
      "publisher": "Linux",
      "title": "usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10057
      },
      "nvd": {
        "published": "2026-07-19T16:17:15.163",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63962",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An SVID array bound is checked only once before a loop, allowing an unsolicited ACK to write past the array.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/845598b154b9a92e9d279fafafa9405c121ae805",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4505f33dab56c274e82f47f94bf60a8cbf8f4b42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cbad85b446c06adbc5e5bed565871bb918ce9d32",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3389c149c68c3fea61910ad5d34f7bf3bff44e32",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1336,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63963",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:52.388Z",
      "date_updated": "2026-07-20T06:41:43.925Z",
      "publisher": "Linux",
      "title": "usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10057
      },
      "nvd": {
        "published": "2026-07-19T16:17:15.270",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63963",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A device-controlled VDO count indexes beyond fixed Discover Identity arrays because handlers do not validate the count.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/569f7971542eb10025d8a0989b83f28a29d8ba20",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f9d787fbe83127105e42088cca40e5118db0d810",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ed8649f3822e211d025bcab5158af6f8a38c8705",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8fbc349e8383125dd2d8de1c1e926279d398ab17",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63964",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:53.115Z",
      "date_updated": "2026-07-20T06:41:45.132Z",
      "publisher": "Linux",
      "title": "usb: typec: ucsi: ccg: reject firmware images without a ':' record header",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11389
      },
      "nvd": {
        "published": "2026-07-19T16:17:15.370",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63964",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A firmware image without a colon makes strnchr return NULL, yet do_flash compares and increments that pointer before rejecting the image.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b41dfc033fe594e152648050e95b9489cd53e9e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f395ca1263bd181995eb829f5943a83a20db213",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6526f8684f72391138353642af908803ba70795e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3f432b8203066c26770fe6ea591361f10021dd6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c4ee519b06389e59ba2d6aa722fcc4a02a8bbcbb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a38ed87818b2419090fb1a6338ddce6842b65dfa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c8460de584fe5415d212cfdd127d4db90835a450",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d7486952bf74e546ee3748fb14b2d07881fa6273",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 903,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63965",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:53.809Z",
      "date_updated": "2026-07-19T14:55:53.809Z",
      "publisher": "Linux",
      "title": "iio: pressure: bmp280: fix stack leak in bmp580 trigger handler",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.098
      },
      "nvd": {
        "published": "2026-07-19T16:17:15.500",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63965",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The bmp580 trigger handler copies three sensor bytes into each four-byte stack field without initializing the remaining bytes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a58400f58f82f3d8de9c067aa7cda690228c1ecc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/58dfb6fe9dc80270cf7cc014837af4cbf928e3aa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/387c86b582e0782ab332e7bfcd4e6e3f93922961",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 811,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63966",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:54.391Z",
      "date_updated": "2026-07-19T14:55:54.391Z",
      "publisher": "Linux",
      "title": "iio: imu: adis16550: fix stack leak in trigger handler",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.098
      },
      "nvd": {
        "published": "2026-07-19T16:17:15.600",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63966",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "adis16550_trigger_handler leaves four bytes of its stack scan record uninitialized and pushes them to userspace with every trigger.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ce582b22dd2ff15ac99101c22ec1559d1febe2ff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c2c255444392872cbbf46d640cb3a938e8000309",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/474f8928d50b09f7dcf507049f08732640b88b49",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63967",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:54.999Z",
      "date_updated": "2026-07-19T14:55:54.999Z",
      "publisher": "Linux",
      "title": "iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.1139
      },
      "nvd": {
        "published": "2026-07-19T16:17:15.700",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63967",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The tagged FIFO copies a stack structure containing an uninitialized padding hole to userspace.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ff8d3c088b77b11782f2c3b97e37425be050e8de",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fe1a7f99e72ebd2880515332b79b8c256be22aca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/babf1943a40bb5669db57d30ca16c22504b18e07",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d42ac0bfb6a16617c62a59d53706579c7fadbfa6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3147b303b8c7d9f91da4b849ece33b45048f5eaf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e6bb3a49c5f9de870ea95e69775df785728e3366",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/890d0312d5f94be43eac21f5a34d3bccc60d051b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c9d8e9adaa63150ef7e833480b799d0bab83a276",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 704,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-63968",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:55.620Z",
      "date_updated": "2026-07-20T13:41:54.077Z",
      "publisher": "Linux",
      "title": "ipv6: fix possible infinite loop in fib6_select_path()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 19,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00647,
        "percentile": 0.47483
      },
      "nvd": {
        "published": "2026-07-19T16:17:15.830",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63968",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An RCU writer removes the first IPv6 sibling while a reader still follows the old ring, so the reader never reaches its original termination node.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3948a7d92f7678e89e1776bb2d169afcad63b1ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c87cd3cb309634bc8f50a54e2079424f219ac21f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0f7b73c3452635de83b8711b31abdda8e49aad7b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ab9a10969a907b472a0196d999c08ff7144172e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9b9d5bd6e3d4c9cecab5407604b690684b2532d2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9c7da87c2dc860bb17ca1ece942495d28b1ce3b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 775,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 19
      }
    },
    {
      "cve_id": "CVE-2026-63969",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:56.330Z",
      "date_updated": "2026-07-19T14:55:56.330Z",
      "publisher": "Linux",
      "title": "ipv6: fix possible infinite loop in rt6_fill_node()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 19,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00206,
        "percentile": 0.10771
      },
      "nvd": {
        "published": "2026-07-19T16:17:15.947",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63969",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "rt6_fill_node can retain a detached route while iterating under RCU and repeatedly revisit it, leaving the traversal in an infinite loop.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b014a63d2f2c2c767762b548381882dfb1655529",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/279853aec9f58d5cd723e6e5617c1c3337b30383",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c65b1f60237daac7c56c2652e064cc566a45dc81",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dc36a04621dcc2447dae428709207810b6c06e14",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5e40de719ee76b8d96e2556ce36dbd3bd07bf37d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9f72412bcf60144f252b0d6205106abf14344abc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 718,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 19
      }
    },
    {
      "cve_id": "CVE-2026-63970",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:57.067Z",
      "date_updated": "2026-07-24T14:34:16.307Z",
      "publisher": "Linux",
      "title": "vsock/virtio: bind uarg before filling zerocopy skb",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05977
      },
      "nvd": {
        "published": "2026-07-19T16:17:16.063",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63970",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The path binds uarg after filling fragments, so rollback frees managed fragments that no longer have a valid lifetime owner.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/72194f65050958e4c8e069adb6c5d89ef81ca197",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b62e2b2b4a50953ca952f3cd3f77dd62dc50fd5d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5d317573f1d48e76cce5fb6250452b6e4102e0fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1e584c304cfb94a759417130b1fc6d30b30c4cce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 815,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63971",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:57.792Z",
      "date_updated": "2026-07-20T13:41:56.086Z",
      "publisher": "Linux",
      "title": "sctp: fix race between sctp_wait_for_connect and peeloff",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06041
      },
      "nvd": {
        "published": "2026-07-19T16:17:16.163",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63971",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "sctp_wait_for_connect releases the socket lock while peeloff can move the association, then resumes under the old lock without rechecking asoc->base.sk.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0e0d5bc76fd4267a71334fcc8f1a5fbcf997845d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bcfeac79af740735ace44008b4a11b8e5add20f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8e9b56051d24540cfbf39194618708c4a7633549",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/634a9af8a26a84d8b0d7b3b643204b344b42d9fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7d2038d4b80166f7bead8d07eba3b97405816c21",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/68667ee4c7dadf7f63167234e2a1af09b3f7874e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6140cfa721451fa6e18e134e709703c2bf34d0fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f14fe6395a8b3d961a61e138ad7b36ba3626dd4e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 743,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63972",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:58.503Z",
      "date_updated": "2026-07-20T13:41:57.080Z",
      "publisher": "Linux",
      "title": "net: mana: Skip redundant detach on already-detached port",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 9,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00576,
        "percentile": 0.44227
      },
      "nvd": {
        "published": "2026-07-19T16:17:16.283",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63972",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MANA error path detaches an object again after a failed attachment has already transitioned it to the detached state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c4152b4e28b3e550ec99351bf900e2c24c2608cc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7ae590797f9b5c240aaea5773f5f00977a42a846",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5b05aa36ee24297d7296ca58dfd8c448d0e4cda3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 697,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-63973",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:59.263Z",
      "date_updated": "2026-07-19T14:55:59.263Z",
      "publisher": "Linux",
      "title": "net: mana: Add NULL guards in teardown path to prevent panic on attach failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00206,
        "percentile": 0.10771
      },
      "nvd": {
        "published": "2026-07-19T16:17:16.383",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63973",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Partial queue allocation frees and nulls MANA queue pointers, but later teardown paths dereference those pointers without checking the failed-allocation state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/da7e4a1aaf397af6a094f640c92d6bc7564c10db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/95e414f8324385771bdfd6d497a01d5593813ccb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/26a96fa81496afe7d162d172ccdc8cb9dbc685d2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/da87896f34e0a51489811d1a684e2953099ca98f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0a9c520fdcb1cb2e79c163c12d359b5e1ee40007",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/17bfe0a8c014ee1d542ad352cd6a0a505361664a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1049,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63974",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:55:59.994Z",
      "date_updated": "2026-07-20T13:41:58.081Z",
      "publisher": "Linux",
      "title": "Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.2414
      },
      "nvd": {
        "published": "2026-07-19T16:17:16.500",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63974",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Bluetooth close can drain the workqueue without marking commands for draining, allowing new timeout work during teardown.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9cebe4680bb9a72f80c6541eb24af06db7a1fbc9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/47330cc875b36a1cf7b3543cb2cf90a7c603ce0e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/525daaea459fc215f432de1b8debbd9144bf97b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-63975",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:56:00.662Z",
      "date_updated": "2026-07-20T13:41:59.074Z",
      "publisher": "Linux",
      "title": "Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27118
      },
      "nvd": {
        "published": "2026-07-19T16:17:16.603",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63975",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The duplicate-CID error path deletes channels while iterating the same list, invalidating the saved cursor and permitting a crash.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3c8eaa91eb433c450426539290be4ffe282e9f00",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ecfed1e0d8efecad6737a0d83e21d2fd021d8c48",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e6833e737a51db1e5ea0401322acf5e22abd8be6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6319b38fe69f56ed95680ade485b957a53fff642",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/291eec1041c918c460dc9702e44edd17794b4a4b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/41e29548b5e8b5e5fcf708786b3bea67cab107fa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d153b8898c0051eb8b6a083b35cbe304a5886bd5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/41c2713b204e6cb6a94587bc6bf6935107df5479",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 613,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63976",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:56:01.284Z",
      "date_updated": "2026-07-20T13:42:00.067Z",
      "publisher": "Linux",
      "title": "Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00443,
        "percentile": 0.36455
      },
      "nvd": {
        "published": "2026-07-19T16:17:16.733",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63976",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Linux L2CAP accepts a stale signaling identifier and applies the replayed response to a newer channel, deleting the wrong channel state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/59f5ecf6ad5c4db6ae81965a96156954a3b0d89a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ae0152d77d101c920769934fb102b18de0c6f526",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c2afd2613fda90107c5e2fe8e855627451749c78",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cc2b4f749de09975bfa06e58bbbad2f6acd4c79c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3b5b5f423b4fd23404a393bda8adba3cd6f74ef1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f39049304ba655ffcbb92edbdf8c51a1f1210bed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8e7977afaef37c6bd2b2654f1bce6ab40d471147",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/00e1950716c6ed67d74777b2db286b0fa23b4be9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 893,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63977",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.024Z",
      "date_published": "2026-07-19T14:56:01.889Z",
      "date_updated": "2026-07-20T13:42:01.088Z",
      "publisher": "Linux",
      "title": "dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.0219
      },
      "nvd": {
        "published": "2026-07-19T16:17:16.860",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63977",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Device teardown can cancel change_work and then race with a callback that reschedules the same work against a freed or null dpll_dev.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e7a33807fb3f87a855993474ac21684ce105927b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d733f519f6443540f8359461a34e3b0042099bbe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63978",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:02.484Z",
      "date_updated": "2026-07-20T13:42:02.047Z",
      "publisher": "Linux",
      "title": "net/handshake: Drain pending requests at net namespace exit",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00598,
        "percentile": 0.45256
      },
      "nvd": {
        "published": "2026-07-19T16:17:16.957",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63978",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Network-namespace teardown transfers the pending handshake list in the wrong direction and lacks ownership coordination with concurrent cancellation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9ec20c9a5a04f2c3f1cf65d21f886d7aaa6189cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8c35539db0ab0bfa1ea44efab00b053261a69469",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ea5fe6a73ca57e5150b8a38b341aef2636eb72f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2316,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63979",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:03.177Z",
      "date_updated": "2026-07-20T13:42:03.030Z",
      "publisher": "Linux",
      "title": "net/handshake: hand off the pinned file reference to accept_doit",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00516,
        "percentile": 0.41086
      },
      "nvd": {
        "published": "2026-07-19T16:17:17.070",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63979",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The handshake accept path dereferences socket and file objects after dropping the pending-list lock without first taking an independent file reference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c06876d4fac38f35820946ee3b1be7d7da799cd4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f4251190e58b209999c1ba9e6d2976136a1be055",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1919,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-63980",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:03.887Z",
      "date_updated": "2026-07-20T13:42:03.955Z",
      "publisher": "Linux",
      "title": "net/handshake: Use spin_lock_bh for hn_lock",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36232
      },
      "nvd": {
        "published": "2026-07-19T16:17:17.170",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63980",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A bottom-half callback can acquire hn_lock while process context holds it with softirqs enabled, deadlocking the same CPU.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/06ab5978866fc2221b910347fd3e510ca8e7b1a4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0866569fc36a56f568acd3900d354e3505932e09",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/91898de9501a047ba67c6b864dcd403e00bdfbf5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cc993e0927ec8bd98ea33377ada03295fcda0f24",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1249,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:04.580Z",
      "date_updated": "2026-07-19T14:56:04.580Z",
      "publisher": "Linux",
      "title": "net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 7,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00188,
        "percentile": 0.0862
      },
      "nvd": {
        "published": "2026-07-19T16:17:17.283",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63981",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The blockcast path returns before incrementing the mirred recursion counter, allowing two devices to mirror a packet recursively until the kernel stack is exhausted.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/25fc9352590f5ef21ebf290432bd768b336693bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/34457de389fb64a01fdcc71177dfebe65fd2d362",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a005fa5d7502eefec7ee6e1c01adadc06de2f9ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2078,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-63982",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:05.329Z",
      "date_updated": "2026-07-19T14:56:05.329Z",
      "publisher": "Linux",
      "title": "net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 7,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09803
      },
      "nvd": {
        "published": "2026-07-19T16:17:17.390",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63982",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Ingress redirection defers the packet and clears loop-tracking state, so a two-interface mirred cycle is never terminated.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/66f4607fe788fc7d81bce0e2f7b3726ed2f71284",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/45ac526a0d5733c3695946bd84ec57f24d8f5e66",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/db875221ab08d213a83bf30196ae8b64d55a3403",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 797,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-63983",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:06.047Z",
      "date_updated": "2026-07-19T14:56:06.047Z",
      "publisher": "Linux",
      "title": "net/sched: fix packet loop on netem when duplicate is on",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06235
      },
      "nvd": {
        "published": "2026-07-19T16:17:17.490",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63983",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Nested netem duplication re-enqueues packet copies without a per-packet recursion guard and can exhaust stack or memory.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1a298a514ce766c6d0c232991a390fec67af81ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cfb2616042767ab31260d4f39190c381bec8b12e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9552b11e3edabc97cfcd9f29103d5afbce7ae183",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 864,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63984",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:06.786Z",
      "date_updated": "2026-07-20T13:42:04.995Z",
      "publisher": "Linux",
      "title": "ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00514,
        "percentile": 0.40948
      },
      "nvd": {
        "published": "2026-07-19T16:17:17.590",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63984",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A decompressed RPL header length overflows an 8-bit field and places the compressed header over the output region that is still being written.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/75b3680047bf09af8e7e471a7a6ddf2ce5847f56",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fd238c51b0fa5390cceca9f1ac5a9ffda8063eed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3618b34942b76471d044369bfd30d58c39068bf1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/97e06791368c01f0ad2a4b3269c2abe19485ca32",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/de02fc049352af5a9595f015511222d0a85c326b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6fe1cb312038516cb4d9fa089d700af7059f1a64",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c0487a9c1e116cf349e2d1f302d9019670460858",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9d5e7a46a9f6d8f503b41bfefef70659845f1679",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1373,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63985",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:07.527Z",
      "date_updated": "2026-07-20T13:42:05.985Z",
      "publisher": "Linux",
      "title": "ethtool: eeprom: add more safeties to EEPROM Netlink fallback",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02968
      },
      "nvd": {
        "published": "2026-07-19T16:17:17.723",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63985",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ethtool EEPROM Netlink fallback checks offset alone but not offset plus length against the EEPROM size, allowing a request range to extend beyond the backing object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0e182689831277faf2ef683573a60474c208f690",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ed7ebe22e9c3e3e946b6973c1ce43d3c38aeac1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/65674d2489a12b8efd2ca0effb3de1d12224b596",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d81376053a00865c70b8d8506a1cb93f2943d413",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fd0de51c54fa8474a0ddeedd71c65ad09fada390",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4fe1bc4b3603f621240d5b401742f302190db769",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/67cfdd9210b99f260b3e0afeb9525e0acc7be31e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 864,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-63986",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:08.203Z",
      "date_updated": "2026-07-19T14:56:08.203Z",
      "publisher": "Linux",
      "title": "ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06234
      },
      "nvd": {
        "published": "2026-07-19T16:17:17.847",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63986",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ethtool error path passes an ERR_PTR as a message header to genlmsg_cancel after preparation failed before any message began.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2008f9bb1ede9b688624a241228b8e54fc74f0f6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d0d2c5ccd1de28368cebeef74d9c530a60eff9a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c3fc9976f686f9a95baf87db9d387f218fd65394",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63987",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:08.940Z",
      "date_updated": "2026-07-20T13:42:06.953Z",
      "publisher": "Linux",
      "title": "ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02913
      },
      "nvd": {
        "published": "2026-07-19T16:17:17.953",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63987",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ethtool handler writes every user-supplied nested profile into a fixed five-entry array without bounding the entry count.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d4c9cc7c47781c6f4fa29d80a1193a8bcd1525bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0c02c190bcd9822477038ff2cee10ea584ac1b1d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6205f7166d2dd14a017a5802c81e5bd1421a8635",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7281b096b072f6c6e30420e3467d738f2e4c4b57",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63988",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:09.677Z",
      "date_updated": "2026-07-19T14:56:09.677Z",
      "publisher": "Linux",
      "title": "bridge: Fix sleep in atomic context in sysfs path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06219
      },
      "nvd": {
        "published": "2026-07-19T16:17:18.060",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63988",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The bridge-port update path holds a spinlock while calling dev_set_promiscuity, which may sleep.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e976e3f2f2005c6267089a1a3b6344f234a59a55",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f9cb30d97e45686f3119fff3b30f12259950910",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6d34594cc619d0d4b07d5afcad8b5984f3526dcf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3016,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63989",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:10.396Z",
      "date_updated": "2026-07-19T14:56:10.396Z",
      "publisher": "Linux",
      "title": "bridge: Fix sleep in atomic context in netlink path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06219
      },
      "nvd": {
        "published": "2026-07-19T16:17:18.260",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63989",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The bridge netlink path calls a sleepable promiscuity update while holding a spinlock in atomic context.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c9c2e609e8397bb57b4d73675f33a99183c4a0bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/803d39accfbdf223ccbb49684d5b5069b4c44586",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5eec4427b89c2fb2beac54920101e55a2f1c0c21",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3226,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63990",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:11.111Z",
      "date_updated": "2026-07-19T14:56:11.111Z",
      "publisher": "Linux",
      "title": "bonding: refuse to enslave CAN devices",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00181,
        "percentile": 0.07896
      },
      "nvd": {
        "published": "2026-07-19T16:17:18.610",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63990",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Linux bonding accepts a CAN device as a slave even though the CAN networking path cannot satisfy the bonding lifecycle assumptions.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/69b78b5f3033272e53a2dc2dad675962654a5b38",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/41e8478c4cd896d3abbe33d41afc90c84ac66602",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f4d78a81f57df82e9d82a2c07471fed1a1235893",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/02f1c87ded33b43d48b4a1d665da15f2157b30d8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9ea8a648d9120f7652bcde1ce2c4ad66871af707",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/563090e5d450c665f70d955a39f9587afc7842eb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8ba68464e4787b6a7ec938826e16124df20fd23d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1668,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-63991",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:11.824Z",
      "date_updated": "2026-07-19T14:56:11.824Z",
      "publisher": "Linux",
      "title": "Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07403
      },
      "nvd": {
        "published": "2026-07-19T16:17:37.783",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63991",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "send_mcast_pkt passes an unchecked NULL result from skb_clone to send_pkt, which dereferences it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9afcb5ea080af13aab37930da627db43bd277665",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9903a04becf059e44cccf625e23689b7d4378384",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d630c4b25f36e0e68461561e4c70957ec37fdedd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b06203ac5f12929d79146bb9f063c2af1d679e63",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3d5d81d294ba09487c86bc4ba33dc4a4bec5d215",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e673889a35a5e4c586d0fae67d8755ca4367d3e2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2061d080a013c0ec0a56162cd501fb36d2befc26",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3c40d381ce04f9575a5d8b542898183c3b4b38dc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63992",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:12.528Z",
      "date_updated": "2026-07-20T13:42:07.956Z",
      "publisher": "Linux",
      "title": "tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00514,
        "percentile": 0.4095
      },
      "nvd": {
        "published": "2026-07-19T16:17:38.700",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63992",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "iptunnel_pmtud_check_icmp can run without a transport header, treating the unset-header sentinel as an offset and reading out of bounds.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5a92cb45e34749865d03daf8d3500f77b5f6644c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c7b7ec3e69e673c0d6b57f74d21da50c485c598e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7f4f7efe7f30edd29c4988de01728bf2398217e4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e917d0c69f01af2bb4fbea2b66d560a53b3ac7ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a096b6e34f602950af9a2b0856cd93a5f4c276d7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/43368636c663cff6e59dde93cf4b8e43ac28eb93",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cb549df9ce4ee15c9d5b19ddab12cf2128e4313c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/509323077ef79a26ba0c60bb556e45c12c398b2d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63993",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.025Z",
      "date_published": "2026-07-19T14:56:13.218Z",
      "date_updated": "2026-07-20T13:42:08.907Z",
      "publisher": "Linux",
      "title": "vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00514,
        "percentile": 0.40951
      },
      "nvd": {
        "published": "2026-07-19T16:17:38.823",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63993",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "skb_tunnel_check_pmtu() can move the packet head, but VXLAN reuses a cached IP-header pointer into the old allocation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6b8bfce9d2f774d2c2243e0248e03efb99bba6c0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9257f56ac47ef1976bcd056cf986a9988eeec67a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8d435d68d71fb875876b722f4136caf74f2f48bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dc3bfa050f873371e745bdf478b1f5b738e5733d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/609e63312c29aad18026a1d3222e123d4b6b0feb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5303925e360527243b46a440a04667826bbc72b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a493efd4336cf19122ae0e4cbb3d31b32d70deea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7d9ef0cb271555d8cf39fefe6c981e1493b25ecf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 354,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63994",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:13.896Z",
      "date_updated": "2026-07-20T13:42:09.911Z",
      "publisher": "Linux",
      "title": "tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00521,
        "percentile": 0.41343
      },
      "nvd": {
        "published": "2026-07-19T16:17:38.943",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63994",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The tunnel PMTU code caches a packet-header pointer before skb_cow(), which can move the skb head and leave that pointer dangling.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/95b6d772bfe788331d9742d73eaa12e113b2adc4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7254aef4d1a7e18e887af9010e2f2dc34806789b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bf8b3f34c37c162357138e7c0942723b8b94fed1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/76cd9398a0470257ab765bdf5f358a2af2e17934",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/50750d86a2e5266aba0c295483b3397843198b11",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6dff77899b9e9fe5d854abda3a98ad04e7229ef7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f3f204541f280a6ecb04503a0d6794d93990ca43",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b4bc94353050b1fa7b702bd4c6600710dd926cff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 474,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-63995",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:14.580Z",
      "date_updated": "2026-07-20T13:42:10.891Z",
      "publisher": "Linux",
      "title": "ethtool: cmis: validate start_cmd_payload_size from module",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02909
      },
      "nvd": {
        "published": "2026-07-19T16:17:39.067",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63995",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The CMIS firmware updater uses a module-supplied payload size as a memcpy length into a 112-byte destination without an upper-bound check.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/63112b4515469d00008452d9cfe3fb3bf1aa2df3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0696709e951be54c699664adf546d16e28974d53",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a46340da00385be7fb16c62425ebc20006f2d5d8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/12c2496a71f82f63617971ca9b730dffa05cf58b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 654,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63996",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:15.256Z",
      "date_updated": "2026-07-20T13:42:11.911Z",
      "publisher": "Linux",
      "title": "ethtool: cmis: require exact CDB reply length",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02911
      },
      "nvd": {
        "published": "2026-07-19T16:17:39.170",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63996",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The CMIS reply path accepts a response longer than its fixed-size allocation and writes the excess payload beyond that allocation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2f818cc98fd2c63a08239cb48995f6c3bfe9d9b3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4d42fb88ec61f2e98c33a9e3a2de371d5edbc6b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eb5dcd740cd7fa27bc2caeff2d28ef28e93ff4d3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c3f999a9d1338c6c89a9ff4549eafe72bc2e7b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1341,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63997",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:15.965Z",
      "date_updated": "2026-07-19T14:56:15.965Z",
      "publisher": "Linux",
      "title": "ethtool: module: avoid leaking a netdev ref on module flash errors",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06417
      },
      "nvd": {
        "published": "2026-07-19T16:17:39.270",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63997",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A module-flash scheduling error leaves the in-progress flag set and a netdev reference unreleased.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f7b4513e77f9571dc1041a798b93b5c4a4bfc191",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/61848c83b9132ab839809fe415ba7802a0aca4f6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/956b134d917fd7e014dc7e39a9b7610c04fcc9ba",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fb7f511d62692661846c47f199e0afe25c2982db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 326,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-63998",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:16.664Z",
      "date_updated": "2026-07-19T14:56:16.664Z",
      "publisher": "Linux",
      "title": "ethtool: module: call ethnl_ops_complete() on module flash errors",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06238
      },
      "nvd": {
        "published": "2026-07-19T16:17:39.370",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63998",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A validation failure returns after begin without calling the matching completion operation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d9defbf8b62bde89e206d74c2a2b445b9ed66108",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e96ef1a40dda5b637b1911cd950b11e9848de939",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/84371fb58423f997939aacdcbc02d128d76a54e5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 245,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-63999",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:17.383Z",
      "date_updated": "2026-07-19T14:56:17.383Z",
      "publisher": "Linux",
      "title": "ethtool: rss: fix indir_table and hkey leak on get_rxfh failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06234
      },
      "nvd": {
        "published": "2026-07-19T16:17:39.477",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-63999",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "rss_prepare_get returns after get_rxfh failure without releasing its allocated indirection table and hash-key buffer.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/33d05c22d6f227c5ae171c46df2f6f8bf48047ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/80d95d92f828cfcace955d673637d944178b435f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/266297692f97008ca48bc311775c087c59bd7fe3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64000",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:18.116Z",
      "date_updated": "2026-07-20T13:42:12.905Z",
      "publisher": "Linux",
      "title": "net: hsr: fix potential OOB access in supervision frame handling",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00491,
        "percentile": 0.39549
      },
      "nvd": {
        "published": "2026-07-19T16:17:39.590",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64000",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The HSR parser can access a complete supervision TLV header after linearizing fewer bytes than that header requires.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/09a37dca090c55ffb1a33f52d8667f1c2367ef48",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a4b64f3e9c7b8259f7dd251a0313420ba7c01852",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/71c986c0ba45b7dc574fae27c83e7b6671556f37",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fbd0662f9c9a66e8cc3df3099cca8ed6d3837cc7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/78607a6854a22a2502f68092202e75a39af4865d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f229426072fc865654a60978bb7fda790a051ff3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 327,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64001",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:18.816Z",
      "date_updated": "2026-07-19T14:56:18.816Z",
      "publisher": "Linux",
      "title": "ALSA: pcm: oss: Fix setup list UAF on proc write error",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06422
      },
      "nvd": {
        "published": "2026-07-19T16:17:39.700",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64001",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The OSS setup path links an entry before allocating its task name and frees it on failure without removing the published list node.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8be4efd0dc0093eb7a02ad1aac936bca2a1f04ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e13922bb97b4e6f94f8ac02d034f2d4bd65eeb3c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be387230dc22d870afd0e5d35912b07c2bc323bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4cc54bdd54b337e77115be5b55577d1c58608eae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 731,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64002",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:19.495Z",
      "date_updated": "2026-07-20T13:42:13.909Z",
      "publisher": "Linux",
      "title": "ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02968
      },
      "nvd": {
        "published": "2026-07-19T16:17:39.807",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64002",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The IPv4 namespace teardown frees sysctl_local_reserved_ports before unregistering the sysctl table that can still access it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ecf45080a4d3f4526cacb8b14060fe3b49a6913b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a0ffc6081a8b27082dd5eae5aa1e3f59bbecf06c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5b23a2ff379e70b6b9ff744a972b63e1f8f4d996",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8e59d4d0dcde2dfb07a7ef855c849a2a0560aa57",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6512c57c4638ddec113bf42439361ba85a12048d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a7f4eefb6e1458431eef9fa20fb363320d185f76",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/155f90be5ee8be5b110ebc0b7da33c54c83b0208",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/87a1e0fe7776da7ab411be332b4be58ac8840d10",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64003",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:20.172Z",
      "date_updated": "2026-07-20T13:42:14.910Z",
      "publisher": "Linux",
      "title": "scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36232
      },
      "nvd": {
        "published": "2026-07-19T16:17:39.933",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64003",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SCSI recovery skips partially removed devices when restarting queues, leaving their requeued requests permanently stuck.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/15fb19af49f2073ed77fad16aaabc648b0ca6800",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d4dddfecdbb5467bef158d4e1486459808357fef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/475f2b37a78f4c698967a7f14f325f04e24c9175",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c740e13e7fe32d8e4d9a1699f65b8daf6709895a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7205b58702273baf21d6ba7992e6ba15852325f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1064,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64004",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:20.895Z",
      "date_updated": "2026-07-20T13:42:15.900Z",
      "publisher": "Linux",
      "title": "net/iucv: fix locking in .getsockopt",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02965
      },
      "nvd": {
        "published": "2026-07-19T16:17:40.043",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64004",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "recvmsg can close and clear hs_dev while getsockopt reads it without the socket lock, causing a concurrent null dereference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/884eb247b74d86db97e3a37f0d6fc8e1e83590dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/45bb8de8c95d8899f4b8f61bd9bceb8132af73cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1fc30bd4e55e2dd622d2d366cecd732c1841bbee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cd691beafea0dd779e69e81ccc26b0ab50efcb5e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6e792b8dd3002bbc4136745928a9605df1a72b8a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9817369243380e287ebe5525411557eaa3aa2a79",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/69554adc7a6fa04ede3ad7512321d83748e3c920",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3589d20a666caf30ad100c960a2de7de390fce88",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64005",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:21.608Z",
      "date_updated": "2026-07-20T13:42:16.855Z",
      "publisher": "Linux",
      "title": "net/smc: Do not re-initialize smc hashtables",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02948
      },
      "nvd": {
        "published": "2026-07-19T16:17:40.170",
        "lastModified": "2026-07-30T14:51:11.223",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64005",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SMC reinitializes hash-list heads after those tables have already been published to protocol and socket users, corrupting the live list state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cdc79c05cc375f68ae87b0c74fdaac1a5c93155a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2006605006e5a4a11d93e1ebdbbe95764d24276f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/64c96e497d5ada0b90e99bf58f893aa2b73dcfbc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ed7a758313011885347b854e97cb95903ef3c3f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0cc9d0ac22d02f1ba1884de5d6de9eaf8b45d82d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/55cba6b883b41e5922c00ba9d4e3262131f46f1b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5ec939367e700722ffbb1b7cacccbb1a3cf0ebd1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9e4389b0038781f19f97895186ed941ff8ac1678",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 554,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64006",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:22.321Z",
      "date_updated": "2026-07-19T14:56:22.321Z",
      "publisher": "Linux",
      "title": "netfilter: nf_tables: fix dst corruption in same register operation",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00171,
        "percentile": 0.0678
      },
      "nvd": {
        "published": "2026-07-19T16:17:40.297",
        "lastModified": "2026-07-30T14:51:20.077",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64006",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "When source and destination share a word, the write occurs before the carry read and destroys state still needed by the calculation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b80ef316e978de2ef81d5bee9c19800b4cf96fb8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/96bea2a7baac4a1137c188dc7610184487ab30a7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a391afe74398b70107f111aa731eab608624949d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/18014147d3ee7831dce53fe65d7fc8d428b02552",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1361,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64007",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:23.049Z",
      "date_updated": "2026-07-20T13:42:17.862Z",
      "publisher": "Linux",
      "title": "netfilter: synproxy: refresh tcphdr after skb_ensure_writable",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00514,
        "percentile": 0.40949
      },
      "nvd": {
        "published": "2026-07-19T16:17:40.407",
        "lastModified": "2026-07-30T14:51:20.077",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64007",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "synproxy_tstamp_adjust caches a TCP-header pointer before skb_ensure_writable can reallocate the skb head and then writes a checksum through that stale pointer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9902a1058992de5d95656b64a3bd95c077f7ba2c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d3019c61799adc21811af4b521f11f3dc77f8e04",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dd206819f210522579010d889d45a9530bb494bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af2c22ccb1f621aff487ff47a040e38e058541e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c7f945f7da097245a2f8ed7775ce48421047ee96",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f0fea2b6d5453a11ad11713bbf37561b9b3a7edf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a91887a5b6ee4b98dfbf1db657ed2b879430149e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/92170e6afe927ab2792a3f71902845789c8e31b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1721,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64008",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:23.746Z",
      "date_updated": "2026-07-20T13:42:18.897Z",
      "publisher": "Linux",
      "title": "accel/rocket: fix UAF via dangling GEM handle in create_bo",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02768
      },
      "nvd": {
        "published": "2026-07-19T16:17:40.557",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64008",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The GEM error path frees an object after publishing its handle, leaving the handle table able to dereference the freed object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/18abd88d19ea195e2e1547fca0970c2f91d77a42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/451f1ccbbdb7b65021646704b15902655f8d228a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f706e6a4ce75585af979aec3dcbdce68bc76306b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1011,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64009",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:24.448Z",
      "date_updated": "2026-07-20T13:42:19.937Z",
      "publisher": "Linux",
      "title": "xfrm: Check for underflow in xfrm_state_mtu",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04122
      },
      "nvd": {
        "published": "2026-07-19T16:17:40.663",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64009",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "xfrm_state_mtu subtracts attacker-influenced overhead using unsigned arithmetic, underflows to a huge value, and eventually supplies a negative length that becomes a near-SIZE_MAX memset.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8014f70c4e6e5ab101ae3860a614e65e988372e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1021d2877b689a648b27815c854557a917122e93",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2a41b1b31c61c52b972278ce1732a1443f5e89ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fccd685b32df5aaf6bad4381eeda216468e283f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/820e501be8aee4b365d218d83227b314309c5fda",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/82ac903e0b519849647657b8c48d21237ada06a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3db50ceeacb52806d8fe86fb1dfe944df0b9f789",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/742b04d0550b0ec89dcbc99537ec88653bd1ad90",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1259,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64010",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.026Z",
      "date_published": "2026-07-19T14:56:25.162Z",
      "date_updated": "2026-07-20T13:42:20.923Z",
      "publisher": "Linux",
      "title": "nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17024
      },
      "nvd": {
        "published": "2026-07-19T16:17:40.803",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64010",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "NFC connection acceptance can move a socket between lists concurrently with socket release and relink a freed socket.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/dce85215a6c7b0fd753f577a4c487f647119884c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bd08bb7443c501d2f2a71d529e4afcf11c9b07d2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0b45c31746e1523d5d482fda8fcf54a35ac417f1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ee2d1a8a1833c5e56e9a1745e64b0b4edda732c2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ad8a27d63cac96bac441edd002209ebd996e12fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/650bdd8fdfab64a09ee474150313dbc48c374795",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b2a60f7f846faaf5c2cdad4ea6d3a33e5f863183",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b493ea2765cc17cb8aa7e7544a4b6dcb05b6ed77",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1007,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64011",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T14:56:25.901Z",
      "date_updated": "2026-07-20T13:42:21.937Z",
      "publisher": "Linux",
      "title": "nfc: llcp: Fix use-after-free in llcp_sock_release()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02641
      },
      "nvd": {
        "published": "2026-07-19T16:17:40.933",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64011",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "llcp_sock_release() unlinks a connecting socket from the established-socket list instead of the connecting list, leaving stale lifetime state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/89ba026747019ee643d29407435ddc118e6ca908",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fb29f6bbe433f3decad227588809636c25f2a287",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2dfdaaf7d933b676124aadec6698825e95f94fe9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e00f50f8697724a6f1d2d35744c1332c9912dac5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cdc17e09a636c7f936f771902535a7515a7608fc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/912ebc49d4406a17fe73e5671d674fbc2f6b2634",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bc421d0826dedbba37580a25405eafb599e76d42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f4268b466190dae95a7585f69b4f1f8ad097632c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 366,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64012",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T14:56:26.608Z",
      "date_updated": "2026-07-19T14:56:26.608Z",
      "publisher": "Linux",
      "title": "net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07403
      },
      "nvd": {
        "published": "2026-07-19T16:17:41.060",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64012",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A qdisc peek path and dequeue path update shared queue state inconsistently, allowing a later operation to consume an object under stale assumptions.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e5ea51e5f3fbba41d50cd84a530f33bc1c8f4d57",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1e70274d3b81de28973bcdbce40a512bcb181ff9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e125f5980b730c67c92a30cf150ec8c3d6777318",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c153d97c100f5b282c424101d8ff63122306997",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/84bfbfc0c48731bcce74cdf4f9c497547ec525e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dbc560858da8b77dd9e4ef0cd93d421e0e4d7e0e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9ad3288632c859cf84183199832d822e7a70bdae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1b9bc71153b01dbde8045b9edede4240f4f5520e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3030,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64013",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T14:56:27.365Z",
      "date_updated": "2026-07-19T14:56:27.365Z",
      "publisher": "Linux",
      "title": "ACPI: button: Fix ACPI GPE handler leak during removal",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.05194
      },
      "nvd": {
        "published": "2026-07-19T16:17:41.220",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64013",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Driver removal unregisters the wrong ACPI notify-handler type, leaving a callback installed after its button device has been removed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/614cb8c26c5aa53196ee9b211b76ee618b147d32",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fe80251152fed5b185f795ef2cd9f7fe9c3162e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 710,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T14:56:27.995Z",
      "date_updated": "2026-07-19T14:56:27.995Z",
      "publisher": "Linux",
      "title": "Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07406
      },
      "nvd": {
        "published": "2026-07-19T16:17:41.320",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64014",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The NEXIO parser trusts 16-bit device-reported lengths that can exceed the 1017-byte payload area and then reads beyond the DMA buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/45c829e5eb3b974282bae50b7cca2cc891f74f0b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e7cdcb266ba06d8480809b78ab8bb2bf8ff51ccb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/95f47331dfde243f93e679ce70bd0c24b37c683d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d883312061ccde8c536595998aaf687ec070077c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/103d2de9f505f56da173e43f12dba62f92620278",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0ca809ea8e0355299266c46e5f1755040aa8dcf3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7585b6aa55d8ac85ad22f522e1059f93507727b6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2905281cbda52ec9df540113b35b835feb5fafd3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1255,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64015",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T15:39:10.557Z",
      "date_updated": "2026-07-20T13:42:22.981Z",
      "publisher": "Linux",
      "title": "security/keys: fix missed RCU read section on lookup",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02974
      },
      "nvd": {
        "published": "2026-07-19T16:17:41.467",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64015",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A persistent-key lookup walks an RCU-managed associative array without an RCU read section while garbage collection can remove and free nodes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4c5d407ba3ff7f30561ff73ba1b07ed70c864edc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cefa4265b11176c897a7d9e8e54d89e3701c5584",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5659e6923cb72f8e18e8b539109ab512455fe195",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/50bb3435a5e627bfbdc52eb4536f49f88b3486b8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/66288dcadf80974436250e9f70ed848836b835b5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/43a1e3744548e6fd85873e6fb43e293eb4010694",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 667,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64016",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T15:39:11.266Z",
      "date_updated": "2026-07-20T13:42:24.006Z",
      "publisher": "Linux",
      "title": "ksmbd: fix durable reconnect error path file lifetime",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36355
      },
      "nvd": {
        "published": "2026-07-19T16:17:41.577",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64016",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The durable reconnect error path drops the same file through two cleanup paths and can free it while its volatile ID remains published.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a1a39f227c80cbf369767badc32cba2b225147d1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6cb0b9385320110fe24a5d5ac0000ade4bb3a3f3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3515503322f4819277091839eed46b695096aca5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 991,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64017",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T15:39:11.989Z",
      "date_updated": "2026-07-20T13:42:25.031Z",
      "publisher": "Linux",
      "title": "blk-mq: pop cached request if it is usable",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02188
      },
      "nvd": {
        "published": "2026-07-19T16:17:41.680",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64017",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A task can sleep after peeking a cached request, allowing plug flush to free that request before the task later pops and uses it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/388468f7e7d1eab092cf2a39fdfb502e52019ec6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dc278e9bf2b9513a763353e6b9cc21e0f532954e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1111,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64018",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T15:39:12.704Z",
      "date_updated": "2026-07-20T13:42:26.010Z",
      "publisher": "Linux",
      "title": "net: mana: validate rx_req_idx to prevent out-of-bounds array access",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03951
      },
      "nvd": {
        "published": "2026-07-19T16:17:41.790",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64018",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A hardware-controlled DMA value is used as reqs array index without a bounds check.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5ddc715324badd7f2641bc177db1d027b402adae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ff1d5af207bcea857d45fe81505f1bc4b29eaef0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/01f7f893d5e1baae995beeb86cd0f3e6bb2a3b01",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/763a372d344fb12fae566d36ddb46e92454ad58c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fa627a5eaa83fc0261f44ef3769693b886ca6e27",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/355e9f2b2a7887ca38100127989af3e422ba71d0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b809d0409991b75a6cff846a5ac27c3062953f84",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64019",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T15:39:13.400Z",
      "date_updated": "2026-07-19T15:39:13.400Z",
      "publisher": "Linux",
      "title": "nvme-pci: fix dma mapping leak on data setup error",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.05212
      },
      "nvd": {
        "published": "2026-07-19T16:17:41.907",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64019",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The NVMe error path leaves a DMA mapping active when descriptor allocation or PRP validation fails.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e50db059ec8e63bc50b1cc039e2502cb5ea75a70",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1bf86336e4b6cf40873fda47a7fe191446864937",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64020",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T15:39:14.115Z",
      "date_updated": "2026-07-20T13:42:26.964Z",
      "publisher": "Linux",
      "title": "nvme-pci: fix dma_vecs leak on p2p memory",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00344,
        "percentile": 0.27007
      },
      "nvd": {
        "published": "2026-07-19T16:17:42.007",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64020",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The NVMe completion path leaves its dma_vec allocation unreleased for peer-to-peer memory mappings.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/24ea0de233d9ebb5ebd6f6018eaf2084af25e3dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/85686c72966c5ee637893f124ddb31a1cace7bee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64021",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T15:39:14.741Z",
      "date_updated": "2026-07-19T15:39:14.741Z",
      "publisher": "Linux",
      "title": "drm/xe/oa: Fix exec_queue leak on width check in stream open",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06237
      },
      "nvd": {
        "published": "2026-07-19T16:17:42.107",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64021",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "xe_oa_stream_open_ioctl returns directly on an unsupported queue width and skips the cleanup path for the looked-up exec_queue reference, pinning the queue and file state indefinitely.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/04ef7592eaadd9ca8f8f66e76452f73525cff819",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4b0c4f0c1b133d4bfa31c167200bcda646873328",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4d25342543c01310fc4e0cba7cb17c775e2421e2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 769,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64022",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T15:39:15.345Z",
      "date_updated": "2026-07-19T15:39:15.345Z",
      "publisher": "Linux",
      "title": "gpio: aggregator: remove the software node when deactivating the aggregator",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06237
      },
      "nvd": {
        "published": "2026-07-19T16:17:42.210",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64022",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GPIO aggregator deactivation leaves its dynamically created software node allocated after the platform device is torn down.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3e657619cf7258cb53b1beaf0d02998297695cde",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9870ea9a4a25abef3e7af3445bfce2472528a546",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/61fef83f239ecace1cce716135762a2d9b7b1fc6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64023",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T15:39:15.980Z",
      "date_updated": "2026-07-20T13:42:27.952Z",
      "publisher": "Linux",
      "title": "gpio: aggregator: fix a potential use-after-free",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02505
      },
      "nvd": {
        "published": "2026-07-19T16:17:42.317",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64023",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GPIO aggregator cleanup frees dev_id before unlinking its lookup entry, allowing a concurrent lookup to dereference the freed string.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ea28b286649b70618e9dd3e895812417a7712a11",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7ac4183a41ba048af89eddd82fe8be64619d0871",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/30c073cab97afb31901f94de9605177b6b84367e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 438,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64024",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T15:39:16.598Z",
      "date_updated": "2026-07-20T13:42:28.932Z",
      "publisher": "Linux",
      "title": "tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.31314
      },
      "nvd": {
        "published": "2026-07-19T16:17:42.413",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64024",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A dropped packet leaves a per-CPU TCP time-wait initial sequence number that the next SYN consumes as predictable stale state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e47f7060eaf60894e3e4d0e3c4fe6e1f2eacfbdd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4affe063fa56c880cbea8d0bfded0bb80751579d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1bbf0ced1d9db73ac7893c2187f3459288603e0d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1654,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64025",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.027Z",
      "date_published": "2026-07-19T15:39:17.178Z",
      "date_updated": "2026-07-20T13:42:29.894Z",
      "publisher": "Linux",
      "title": "bpf, skmsg: fix verdict sk_data_ready racing with ktls rx",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00444,
        "percentile": 0.36519
      },
      "nvd": {
        "published": "2026-07-19T16:17:42.527",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64025",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The sockmap verdict callback races TLS receive ownership and drains a queue while TLS retains a pointer to an skb that can be freed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c9ea01768903ae47f210cd457af1dead6de7a9c3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7c8cf21bc4efb4af18d6096db3f8bd06d622251c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1861d369efd62d67796563bf3e01fc22e5626f8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8a52139560f833c3975032e1f5762611e3a36d71",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ddf8029623a1af20e984c040e89ff918158397ab",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1538,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64026",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:17.783Z",
      "date_updated": "2026-07-20T13:42:30.880Z",
      "publisher": "Linux",
      "title": "rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02912
      },
      "nvd": {
        "published": "2026-07-19T16:17:42.643",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64026",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "RXRPC decrypts DATA in place on shared page-cache storage, allowing decrypted writes to corrupt bytes concurrently exposed through splice.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a05bf6d9e621fa71e89ccebe3047ba45218d7b38",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b94a6ccbaf1104dd980150a65fdeb2f69d17d2f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/46cb765e2e5ad52303ea157e10d370bb6b7acbbf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c580087743712112778a06d65a4074053072d7bf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d2bc90cf6c75cb96d2ce549be6c35efa3099d25b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1981,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64027",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:18.470Z",
      "date_updated": "2026-07-20T13:42:31.821Z",
      "publisher": "Linux",
      "title": "net: shaper: rework the VALID marking (again)",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02772
      },
      "nvd": {
        "published": "2026-07-19T16:17:42.777",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64027",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The shaper VALID mark and XArray pointer are updated separately, allowing a reader to validate one entry and dereference its freed replacement.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2417df5e7bb4184b9d3a2988036bf2c46e594545",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/96ea960dd40fd55302e0fd755176f26a95e6a50c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b8d7519352ba8c6df83259295d4a3bad093cae90",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 863,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64028",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:19.102Z",
      "date_updated": "2026-07-19T15:39:19.102Z",
      "publisher": "Linux",
      "title": "tracing: Avoid NULL return from hist_field_name() on truncation",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00185,
        "percentile": 0.08361
      },
      "nvd": {
        "published": "2026-07-19T16:17:42.877",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64028",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "hist_field_name() returns \"\" everywhere except the fully-qualified VAR_REF/EXPR case, where snprintf() truncation returns NULL early and bypasses the bottom NULL->\"\" guard.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e3f5d42cdc2f167719564693675f1eead81378ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/37377b39ff86dacbc533275c1155210d4fd5dc91",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0402a1d3ddec565132867337ed44514a09d84728",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e91687643c440ca3997d67646e6f80b92edc6703",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be4e99038c1603fa6b329d8ee3e364825e17c353",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d6c8b3ebdcdb12b59ad4212acb137cc56cae453d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/915c1254fe0788abddc31095b360e9dc98907a34",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/576ec047d20b368b43c4d5db98c4f2e0f3c101ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 810,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64029",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:20.368Z",
      "date_updated": "2026-07-20T13:42:32.790Z",
      "publisher": "Linux",
      "title": "ALSA: seq: Serialize UMP output teardown with event_input",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02601
      },
      "nvd": {
        "published": "2026-07-19T16:17:42.997",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64029",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The UMP event path borrows the rawmidi output file without synchronizing against last-close teardown.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8ba1c4ddbb1c67d34bb440aecb9f5690ed3f64cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0cb1ad795570167558530d6194297ac2396a1991",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3aab4a58d23fb22dac5b558bbe5df1a8dad00b4b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ef46b616a4c219185bbf10ebcbacb571583fd0e4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/60a1969fae6209644698fca91c185d153674f631",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3547,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64030",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:20.982Z",
      "date_updated": "2026-07-20T13:42:33.826Z",
      "publisher": "Linux",
      "title": "wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00239,
        "percentile": 0.15031
      },
      "nvd": {
        "published": "2026-07-19T16:17:43.147",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64030",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A Wi-Fi 7 link identifier can take the value 15 while the link array ends at index 14, leading to an out-of-bounds pointer dereference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2d8379834800c30602f24c71ab7c40f5fe84d200",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/863f1f02a3bd70dbd857b8ac4070292fde8cb4e2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f718506edd2d9c6a308ded9d13c632bf7b7d5a2c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1154,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64031",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:21.609Z",
      "date_updated": "2026-07-20T13:42:34.848Z",
      "publisher": "Linux",
      "title": "erofs: fix managed cache race for unaligned extents",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02773
      },
      "nvd": {
        "published": "2026-07-19T16:17:43.250",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64031",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A compressed folio becomes visible in the managed cache before its private state is cleared, allowing another pcluster to add the same folio concurrently.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/425d32d6288d7d845e486af9419bbedccd8c9103",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/038166f873c4caf6e85cfd4ea0c5a5ba297b4e8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/649932fc3815eda2f24eb4de4b3a5e94886ee0b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1451,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64032",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:22.228Z",
      "date_updated": "2026-07-20T13:42:35.854Z",
      "publisher": "Linux",
      "title": "bridge: mcast: Fix a possible use-after-free when removing a bridge port",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 22,
        "versionRangeCount": 20,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02627
      },
      "nvd": {
        "published": "2026-07-19T16:17:43.350",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64032",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Conflicting multicast-snooping transitions can leave a per-port context active when the bridge port is freed, allowing its timer to use freed memory.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ddefd1b8e5eb58933a697ab38334f0fd82e7fb8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ed3b69e60385a03df11c6d12e5d7bdf0f4a11b70",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1900ca8acb92fbea8bf9abef9927c7fed03db7fc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ebe5561154c823b323bd06e350b55e0b8604d851",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a9224862d597d0eed0a34bbb27343f703fc4113f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7213256c91ed778a0997c2029c152b18dc50e4fd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4df78ff02629c7729168f0696a7a2123c389818d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2624,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 22
      }
    },
    {
      "cve_id": "CVE-2026-64033",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:22.872Z",
      "date_updated": "2026-07-20T13:42:36.830Z",
      "publisher": "Linux",
      "title": "RDMA/rtrs: Fix use-after-free in path file creation cleanup",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 17,
        "versionRangeCount": 16,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00488,
        "percentile": 0.39392
      },
      "nvd": {
        "published": "2026-07-19T16:17:43.493",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64033",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An error path drops the final kobject reference and frees srv_path before the next cleanup helper dereferences it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/01e42aabaf7632beb4bf235c7238b96c746d4144",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/548f3956e53a7f7bde912d8129010b8986d5e602",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/00904a73272b9f3ef3952fe69a833909dccad1ef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/92060ab1c5115674cf319175550f85f68405121f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eae62c5451e67e8b033c1681fd3b85d7e9a9a28f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b0e9706fb2859064bb6c677554c4d20c713aa8e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5b74373390113fba798a76b483837029ab010fef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1084,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-64034",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:23.470Z",
      "date_updated": "2026-07-20T13:42:37.820Z",
      "publisher": "Linux",
      "title": "net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00151,
        "percentile": 0.04751
      },
      "nvd": {
        "published": "2026-07-19T16:17:43.620",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64034",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A DMA identifier is fetched twice across a validation window, allowing its value to change before use.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a201c66edf2ebc6cfdc3813a889ba20fecebfae3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/70ad2dff8d052a85dfef15715b531f38a29108cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/566f42fb67a7ebfed6650e407e5b72e6b3e83bf7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6180a06bbc99fd9114b8db4be6c4d46e40f046ef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/09ec063d87c2dd3fa6f3561361a017bd882e9f37",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3c4db56ccd13dd020fbf43afabaee74a40ec75e4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/35f0f0a2536a4d604b4dbad92c85c4a8fdebb870",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 813,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64035",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:24.128Z",
      "date_updated": "2026-07-20T13:42:38.824Z",
      "publisher": "Linux",
      "title": "igc: set tx buffer type for SMD frames",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36356
      },
      "nvd": {
        "published": "2026-07-19T16:17:43.740",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64035",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A reused transmit-buffer entry retains a stale XDP or XSK type, causing completion to apply the wrong ownership cleanup to an SKB.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1f83545f432d106d5fc71d3997b2d382104ebcc4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1c8587bd025244aa52061f5ceecbf5e68a1063d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5acc641e590e008caaed480ed9ffae47cf7ecbdf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 488,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64036",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:24.783Z",
      "date_updated": "2026-07-20T13:42:39.799Z",
      "publisher": "Linux",
      "title": "cgroup/rstat: validate cpu before css_rstat_cpu() access",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02771
      },
      "nvd": {
        "published": "2026-07-19T16:17:43.847",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64036",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The BPF-facing css_rstat_updated function uses a caller-provided CPU index for per-CPU lookup without first validating that the CPU exists.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6a01413a4e8fcb0263d7bef5075c5f8f4eb3a8b6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fd2bd9fa7700ddf28296486b2598cff2f80cc819",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8817005efbdfdf5d4e4814cb5dc52b53d12917d7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 862,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64037",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:25.435Z",
      "date_updated": "2026-07-20T13:42:40.761Z",
      "publisher": "Linux",
      "title": "wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0043,
        "percentile": 0.35369
      },
      "nvd": {
        "published": "2026-07-19T16:17:43.947",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64037",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The iwlwifi MLD path treats the AMSDU-disabled sentinel as a length, computes zero subframes, and drives a segmentation burst that corrupts TCP object lifetime.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9e360e610a73f62432e986775023d5382773f045",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cbe1c8245e4469d1aa6e12e5d913611376d23788",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/92cee08dc4f00e77fd1317e4343c5d458b0abab7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1539,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64038",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:26.071Z",
      "date_updated": "2026-07-19T15:39:26.071Z",
      "publisher": "Linux",
      "title": "hwmon: (lm90) Stop work before releasing hwmon device",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06233
      },
      "nvd": {
        "published": "2026-07-19T16:17:44.053",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64038",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "lm90 releases its hwmon device before canceling delayed workers that can still dereference the freed device.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c98107817b0f6cdf51adc5e84e75c39ee25d8b28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/479e297526aeb19c745eac5c1897f455f83dc5f8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b09a45601094c7f4ec4db8090b825fa61e169d93",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1040,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64039",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.028Z",
      "date_published": "2026-07-19T15:39:26.695Z",
      "date_updated": "2026-07-20T13:42:41.722Z",
      "publisher": "Linux",
      "title": "drm/msm/snapshot: fix dumping of the unaligned regions",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07795
      },
      "nvd": {
        "published": "2026-07-19T16:17:44.153",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64039",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The display snapshot code aligns an already shifted DSI region and miscomputes the final register span, causing invalid memory access.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8fb070cf95847b29ef6cb15ec2c0de2bf4704676",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cecd34e046121d788a70b5c8b4f8a88916637953",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/070e40acc59ef7bedba0314f59971ba87fcc8ab0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1ef79be774706dddcfcace0331fa7ff32a73c73e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cdd1aaf0ee962f50810b9aef7928f2313989d55f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0c90ececfad3fc5c4c43a75ece0e2d736ab3def1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/76824d2467feb1828b745d6add2541918d7be3da",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 606,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64040",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:27.348Z",
      "date_updated": "2026-07-19T15:39:27.348Z",
      "publisher": "Linux",
      "title": "cachefiles: Fix error return when vfs_mkdir() fails",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00189,
        "percentile": 0.08788
      },
      "nvd": {
        "published": "2026-07-19T16:17:44.270",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64040",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The cachefiles mkdir failure path leaves ret as zero instead of extracting the error pointer, returning NULL as apparent success.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0940108d27c6995e02819ff832be11892f0b208b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8a220d1c312c66194f4a33dd52d1fba42bc2b341",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64041",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:27.967Z",
      "date_updated": "2026-07-20T13:42:42.714Z",
      "publisher": "Linux",
      "title": "ASoC: codecs: fs210x: fix possible buffer overflow",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00175,
        "percentile": 0.072
      },
      "nvd": {
        "published": "2026-07-19T16:17:44.367",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64041",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "fs210x_effect_scene_info supplies a source-derived copy size instead of the destination capacity, allowing the string copy to overrun its buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1ddf678bb75b6383c775ece61d40956c441d8a26",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6daefdf1cd3c56483f61970a76c0ad6028e4118f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0d435a7ebcd4e97e47673c1ab6fb27f973a053ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 416,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64042",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:28.604Z",
      "date_updated": "2026-07-20T13:42:43.720Z",
      "publisher": "Linux",
      "title": "vfio/pci: Check BAR resources before exporting a DMABUF",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05061
      },
      "nvd": {
        "published": "2026-07-19T16:17:44.480",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64042",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The driver exports a BAR-backed DMA buffer without confirming that the caller owns a reserved resource.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8443cd4497a4498c4b01058d76a92116244cb605",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/702809dabdecca807bdd50cfdcc1c980feb2ba62",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64043",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:29.225Z",
      "date_updated": "2026-07-19T15:39:29.225Z",
      "publisher": "Linux",
      "title": "ovpn: fix race between deleting interface and adding new peer",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09802
      },
      "nvd": {
        "published": "2026-07-19T16:17:44.580",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64043",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "ovpn_dellink releases peers and queues device deregistration while a concurrent CMD_PEER_NEW can reacquire a netdev reference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/097d62df38314c14b88fab9096f3461baf158e2b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/de9fec2a6645f5b4d23398cd870a33e2703728d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/982422b11e6f95f766a8cd2c2b1cbdb77e234a61",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1174,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64044",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:29.869Z",
      "date_updated": "2026-07-20T13:42:44.713Z",
      "publisher": "Linux",
      "title": "ovpn: respect peer refcount in CMD_NEW_PEER error path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.068
      },
      "nvd": {
        "published": "2026-07-19T16:17:44.690",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64044",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ovpn release path bypasses the reference-counted lifetime and frees an object while references remain.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8298834912d76dbc82c12b6b4ab7590ed2bb8ae5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0c3ef71879c0264de6c42463031d9e057da87840",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1fef6614673ff0846d30acdeeaf3cf98bb5f6116",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2086,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64045",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:30.526Z",
      "date_updated": "2026-07-20T13:42:45.723Z",
      "publisher": "Linux",
      "title": "ovpn: tcp - use cached peer pointer in ovpn_tcp_close()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00154,
        "percentile": 0.05028
      },
      "nvd": {
        "published": "2026-07-19T16:17:44.803",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64045",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "ovpn_tcp_close rereads sock->peer after leaving its RCU read section, allowing concurrent socket release to free the containing object before the second dereference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e5460eb7238c19d651a9b22b2378b587033a4095",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d3ef441907fca7c340979e577a3db3bb634bf166",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/775d8d7ad02aa345e1588424a6a8b9ae49fb9012",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2191,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64046",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:31.129Z",
      "date_updated": "2026-07-20T13:42:46.777Z",
      "publisher": "Linux",
      "title": "net: tls: prevent chain-after-chain in plain text SG",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00514,
        "percentile": 0.40948
      },
      "nvd": {
        "published": "2026-07-19T16:17:44.920",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64046",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The TLS scatterlist builder can place one chain link directly after another, which the scatterlist iterator cannot resolve.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/49a5faaa471ddcd37b6893970c9916eb836e7c31",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/91359966e247c0244c66d50bbb8e74aefa4321c3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/410351158dfef2d67fea6603680b3a6013c6ed9d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/acdc12b71c9aa4be5dcd2c8062753c6d2033e235",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/929b1548e63ac72e104c07d8ee8cbbeeba2fa89a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af855f4c966afafef74faf8390c7b86568c0d46d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b9c015ef1a7bf1e8dc67f21c6381f36deb2c3a36",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ff26a0e8377dec07e4a7230db7675bed1b9a6d03",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1047,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64047",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:31.960Z",
      "date_updated": "2026-07-20T13:42:47.774Z",
      "publisher": "Linux",
      "title": "net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00514,
        "percentile": 0.40951
      },
      "nvd": {
        "published": "2026-07-19T16:17:45.053",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64047",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "tls_push_record() places an sg_chain pointer one entry early when a scatterlist ring wraps, so crypto traversal follows the wrong array entry.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/73963a375885d5ccb7def39fd0b4f542e0f343dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/47110c3a9ac247b688657337f5981efcfcb240dc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/84158c2997159df4a0d70cd9c46774512d32a522",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/131ef12057d92b77b636321b7849c69222405a97",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/66339b71f105e6f83e0da3b9583d95077534fe1d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eca989eab4b2599dcb02f72140a7c08f08838520",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2fb0dc7e0099686c4e9d2732745d8a31b18c3628",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/285943c6e7ca309bbea84b253745154241d9788a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1396,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64048",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:32.664Z",
      "date_updated": "2026-07-20T13:42:48.799Z",
      "publisher": "Linux",
      "title": "net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00479,
        "percentile": 0.38812
      },
      "nvd": {
        "published": "2026-07-19T16:17:45.190",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64048",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SMC path consumes an empty slot as though it contained a valid CHID, advancing the connection state with an invalid identifier.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6927cacf2b10d4fa80c1a2d407512ef9397c59c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d38ba387244e5c5f7db3e11ea98bc2c7beccb0c0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/53eb7bd09aace72fa17510d80e0caf5ca058c231",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/afa9036b8c9963947b487c36e332df6a42c96fcb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/65edb3b0822cfe5041be8fbabebd57e2e5ad9f4e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/277740023def559a4a2ddc3e8e784ee37a0f16a9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1205,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64049",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:33.308Z",
      "date_updated": "2026-07-19T15:39:33.308Z",
      "publisher": "Linux",
      "title": "drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06236
      },
      "nvd": {
        "published": "2026-07-19T16:17:45.310",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64049",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Userspace can query UBWC parameters on pre-a5xx hardware where no UBWC configuration object exists, causing a null dereference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/eea43d5ed45089705bc5d70971c39076962d5951",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/22fc33d9b67694b24e0deb3f08c622464338cecb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2b4abf879360ea00a9e2b46d2d15dcdbc0687eed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 514,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64050",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:33.942Z",
      "date_updated": "2026-07-20T13:42:49.733Z",
      "publisher": "Linux",
      "title": "drm/msm/dpu: don't mix devm and drmm functions",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02503
      },
      "nvd": {
        "published": "2026-07-19T16:17:45.413",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64050",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The driver allocates writeback connector state with devm lifetime while userspace-visible DRM references can outlive device teardown.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ff58e5ef1b46ce614af048d2d04986df05ffab90",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/95048a12f48c627bc2ccc4d84f87640630ba2bdb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c0c70a11365cba7fba25a77463582bcec0f7846e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 532,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64051",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:34.608Z",
      "date_updated": "2026-07-20T13:42:50.752Z",
      "publisher": "Linux",
      "title": "accel/qaic: Add overflow check to remap_pfn_range during mmap",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02912
      },
      "nvd": {
        "published": "2026-07-19T16:17:45.517",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64051",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "qaic_gem_object_mmap can map a buffer beyond the VMA length, leaving extra mappings alive after the VMA is unmapped.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9baafc2fea096279e75480f93fd5942e8336b510",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8dd6edbe26770df147136c3f2ac976c873b82650",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/97a8e89cdef36207a8776edc03d6931763a06ad0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8c795012d0e06b7740e40319b86ff8d2a435098d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aa16b2bc0f02709919e2435f531406531e5bcc69",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 540,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64052",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:35.223Z",
      "date_updated": "2026-07-19T15:39:35.223Z",
      "publisher": "Linux",
      "title": "block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06421
      },
      "nvd": {
        "published": "2026-07-19T16:17:45.623",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64052",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "bio_integrity_map_user treats a partial page-pin result as complete and passes an unpinned null page into bvec construction.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/77c059f41e9395793917d067476f549a911d77d3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/76410790f1491c8e06a451045ae223a61c652455",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8fa244738641d95ea4d70e6f9a62778bba42a5b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8582792cf23b3d94674d4d838f7cde9a28d0fcaf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1042,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64053",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:35.854Z",
      "date_updated": "2026-07-20T13:42:51.761Z",
      "publisher": "Linux",
      "title": "block: don't overwrite bip_vcnt in bio_integrity_copy_user()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02902
      },
      "nvd": {
        "published": "2026-07-19T16:17:45.730",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64053",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "bio_integrity_copy_user overwrites bip_vcnt with nr_vecs beyond the one-entry flexible array and makes later merge checks read past bip_vec.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d18160c9525c63c203656fefd847e94b538cd4a4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0d48654af4d1390c888389206cc13b51b82c30e6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/066be1439593a381b1a29663becfcfe0c92363e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/637ad3a56a3b889527d1dacea6fea2a8bd648140",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64054",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.029Z",
      "date_published": "2026-07-19T15:39:36.475Z",
      "date_updated": "2026-07-19T15:39:36.475Z",
      "publisher": "Linux",
      "title": "net: shaper: reject duplicate leaves in GROUP request",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06233
      },
      "nvd": {
        "published": "2026-07-19T16:17:45.830",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64054",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Duplicate leaf handles place the same parent pointer into cleanup twice and cause that object to be freed twice.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5098b223f0f0c5c18a3884a8b0ea5bd4a0c7bd75",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/31767bf852b59f05125b58a17007e4cd1ea9eb2e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a9a2fa1da619f276580b0d4c5d12efac89e8642b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 556,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64055",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:37.077Z",
      "date_updated": "2026-07-20T13:42:52.779Z",
      "publisher": "Linux",
      "title": "net: ethernet: cortina: Carry over frag counter",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00514,
        "percentile": 0.4095
      },
      "nvd": {
        "published": "2026-07-19T16:17:45.930",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64055",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "gmac_rx resets its fragment counter between poll calls even when the current packet remains only partly assembled.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/df31e3b64455293df1ea89c7da7d5c9bfbcdd253",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7af1fabdee744b7995fe01b30b77dfc397657cb5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/75105fcf73f1ce7d9f769aaefec6e6d6645d5ac0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/78cf08b3be47c28f07008a76c932bad7cdffa9d8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7123cf481e21b54eb6adc4cb0d8dc2876aeaee41",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c373b34877afea61c89e0dd2e38948c624249b9b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/46806096f35b8d3dfa2f321ddd77f597edcdb85f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ebd8ec2b309e3a447851b456ccaf8fb39f3661e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 810,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64056",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:37.673Z",
      "date_updated": "2026-07-20T13:42:53.741Z",
      "publisher": "Linux",
      "title": "net: ethernet: cortina: Make RX SKB per-port",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00552,
        "percentile": 0.43022
      },
      "nvd": {
        "published": "2026-07-19T16:17:46.057",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64056",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Two Ethernet ports share one static receive-packet pointer, allowing their concurrent fragment assembly to race over the same object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/27856d533eca3804008695f61c1e4d5ff984196b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b6b22824b30e48ce1df3a2e80990f4b8505deb50",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6bba24e9ebe6f1c0b356cd471e36bdc7fa434897",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3b249988d774dacf13b203817e971934a42243c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/72158ea185b27afae163949b0e86164cb6b64e55",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cfd62907f3cdbc3b6da8f49ba907c0390018fe5e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/67a35e7da7ef9d2f000aa758552a128324c604a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/06937db21ee311ed07eba47954447245041a982d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 681,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64057",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:38.321Z",
      "date_updated": "2026-07-20T13:42:54.729Z",
      "publisher": "Linux",
      "title": "afs: Fix the locking used by afs_get_link()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02188
      },
      "nvd": {
        "published": "2026-07-19T16:17:46.187",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64057",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "AFS symbolic-link reads lack the locking and RCU lifetime barriers needed across concurrent get_link calls, allowing buffers and link state to be leaked or observed outside their valid lifetime.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/77ea917cbed62882a33114b1e23ededb977e4287",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c0410adf3da6db46f3513411fcf95e63c2f1d1ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1418,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64058",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:38.978Z",
      "date_updated": "2026-07-20T13:42:55.717Z",
      "publisher": "Linux",
      "title": "netfs: Fix netfs_read_folio() to wait on writeback",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02773
      },
      "nvd": {
        "published": "2026-07-19T16:17:46.290",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64058",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "netfs_read_folio reads dirty and private folio state without first waiting for an ongoing writeback that can clean that state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f17b9121bb99f88188ec9be2db5da1d561f4c01b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b8271cccdd5e43cc8d738afb8b51f6ad05b1cb4b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ded0c6f1606061148c202825f7e53d711f9f84cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64059",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:39.607Z",
      "date_updated": "2026-07-19T15:39:39.607Z",
      "publisher": "Linux",
      "title": "netfs: Fix folio->private handling in netfs_perform_write()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06415
      },
      "nvd": {
        "published": "2026-07-19T16:17:46.407",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64059",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "netfs transitions folio private data among incompatible owner forms without consistently releasing the previous attachment and references.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7f040243c74d72b45b22246c7d9e621fbeab44ac",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/551b5c71ee312ca7646ddb605231c1016e8cbb18",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0969ea8370bad0e4fb6131b6a7bed9e7ec522ac7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ccde2ac757c713535b224233a296de40efe5212d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1293,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64060",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:40.243Z",
      "date_updated": "2026-07-19T15:39:40.243Z",
      "publisher": "Linux",
      "title": "netfs: Fix leak of request in netfs_write_begin() error handling",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06235
      },
      "nvd": {
        "published": "2026-07-19T16:17:46.513",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64060",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An error path fails to release a request reference and leaks it on each failure.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/22ae28aae43623be235ff455558cdd13fbe2daeb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/28686d6d8b60dc5bbae9ef6023ab2051d6c66cdf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5046a34f0643441f05b0253ea64e1a3af87efe14",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 255,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64061",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:40.913Z",
      "date_updated": "2026-07-20T13:42:56.725Z",
      "publisher": "Linux",
      "title": "netfs: Fix early put of sink folio in netfs_read_gaps()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00444,
        "percentile": 0.36518
      },
      "nvd": {
        "published": "2026-07-19T16:17:46.613",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64061",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "netfs_read_gaps releases its sink folio before the asynchronous read request finishes writing through the iterator.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2a39d49c8d97df8cb8fa80c10859bc1ba7358c6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d4f4bc87c76511cf2532448b0fa40c25e894bd7d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/412e8bad48967fd34295866636c028befd27d8b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3e5dd91b87a8b1450217b56a336bee315f40da7d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1352,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64062",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:41.523Z",
      "date_updated": "2026-07-19T15:39:41.523Z",
      "publisher": "Linux",
      "title": "netfs: Fix potential deadlock in write-through mode",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06415
      },
      "nvd": {
        "published": "2026-07-19T16:17:46.720",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64062",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "netfs_advance_writethrough can leave a supplied folio locked on an error path, allowing write-through processing to deadlock.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1468f39243ccb155b6d97f9a9932f610d1205d75",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/003aa0dd26c964025acd6d1213bcdbd674db2ca9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e40e9cbf3ee4d30ee9a97bd128c85500b6ad0da1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b6a4ae1634b3ad2aaa05222e53d36da532852faf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 782,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64063",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:42.123Z",
      "date_updated": "2026-07-19T15:39:42.123Z",
      "publisher": "Linux",
      "title": "netfs: Fix streaming write being overwritten",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.0642
      },
      "nvd": {
        "published": "2026-07-19T16:17:46.820",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64063",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A full overwrite of a streaming-write folio leaves the old netfs_folio dirty-region state attached, so later processing can overwrite the new data.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/20195925c768626dc901a4781a51e508702c88ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ef9b521212e4863814ef7dfe19889abaf55ca840",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cdae00e8e215d95911d95f100599e187b6560de5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7b4dcf1b9455a6e52ac7478b4057dbe10359576d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2105,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64064",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:42.770Z",
      "date_updated": "2026-07-19T15:39:42.770Z",
      "publisher": "Linux",
      "title": "netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.0642
      },
      "nvd": {
        "published": "2026-07-19T16:17:46.937",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64064",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Truncation discards netfs_folio state without clearing the dirty bit, so a later mmap read follows a dirty-state path that dereferences the missing metadata.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/31ba145faceb378fa01afcb8349e15ea7d95e542",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fb6ec883b48b8789e5e690dcd440d2db941e840c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/65ae8717abf36202fef02260b64b781d2d44a9bf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/156ac2ec2ee77c44c4eb7439d6d165247ba12247",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2167,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64065",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:43.397Z",
      "date_updated": "2026-07-19T15:39:43.397Z",
      "publisher": "Linux",
      "title": "netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06417
      },
      "nvd": {
        "published": "2026-07-19T16:17:47.053",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64065",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "netfs_write_begin() can return an unlocked folio to a caller path that unconditionally invokes folio_unlock().",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/51ffb788f074c0a61953086f49008028c1e7b645",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b63971238beb79cf701dac33c6cefc56c07c89fa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5ad05b6f5df296ef046589f222bb2587495b991e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dc7832d05deb4d632e8035e3299e31a3528fa0d0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3998,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64066",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:44.032Z",
      "date_updated": "2026-07-20T13:42:57.695Z",
      "publisher": "Linux",
      "title": "netfs: Fix netfs_read_to_pagecache() to pause on subreq failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36356
      },
      "nvd": {
        "published": "2026-07-19T16:17:47.190",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64066",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "netfs_read_to_pagecache() continues issuing new subrequests after an earlier subrequest has failed instead of pausing the operation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/884c4c4f35e577aba6a0593c80cbea9ca5e6e2b8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0256e79ce42101ad036edd4205bccca621ea0927",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8a8c0cfdf4658fc5b295b7fc87be56e0d76741f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 254,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64067",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:44.660Z",
      "date_updated": "2026-07-20T13:42:58.657Z",
      "publisher": "Linux",
      "title": "netfs: Fix missing barriers when accessing stream->subrequests locklessly",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0038,
        "percentile": 0.30706
      },
      "nvd": {
        "published": "2026-07-19T16:17:47.290",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64067",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Lockless readers can observe a newly linked netfs subrequest before its flags because list publication and consumption lack release and acquire barriers.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/293a4532c36f38458e38b8879b174ab797718b9d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b5782e2d462c028096f922abca46318cec890670",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1192,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64068",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:45.306Z",
      "date_updated": "2026-07-20T13:42:59.631Z",
      "publisher": "Linux",
      "title": "netfs: Fix missing locking around retry adding new subreqs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0038,
        "percentile": 0.30706
      },
      "nvd": {
        "published": "2026-07-19T16:17:47.390",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64068",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Netfs retry paths add new subrequests to a shared stream list without taking the lock that protects concurrent list updates.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/393f3f0d7353a94b1e0bc4ca89c683fe983e5fd2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cce18c263e9623872327ba3c956012f73c1179cc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64069",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:45.932Z",
      "date_updated": "2026-07-20T13:43:00.616Z",
      "publisher": "Linux",
      "title": "netfs: Fix cancellation of a DIO and single read subrequests",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36356
      },
      "nvd": {
        "published": "2026-07-19T16:17:47.483",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64069",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Failed DIO and single-read preparation abandons a subrequest with list visibility and reference ownership inconsistent with the collector.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5366199be46fb53de62861721d34ba816e7e440e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f73372a4c6900d117f8e903fe10b62692f95e6c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6f0f7ac1915abc0d202f0eb4b003a6548a5ba60d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1174,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64070",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.030Z",
      "date_published": "2026-07-19T15:39:46.536Z",
      "date_updated": "2026-07-19T15:39:46.536Z",
      "publisher": "Linux",
      "title": "powerpc/hv-gpci: fix preempt count leak in sysfs show paths",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.05213
      },
      "nvd": {
        "published": "2026-07-19T16:17:47.583",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64070",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Successful sysfs paths omit put_cpu_var and leave preemption disabled after the operation returns.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/903409000a07ac8e31ffedeb8516f4f8d67150c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dbc30a57bd8e026995e9fa8e8c31cffd18542c01",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1393,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64071",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:47.162Z",
      "date_updated": "2026-07-19T15:39:47.162Z",
      "publisher": "Linux",
      "title": "nvme-pci: fix use-after-free in nvme_free_host_mem()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.07001
      },
      "nvd": {
        "published": "2026-07-19T16:17:47.687",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64071",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "nvme_free_host_mem frees hmb_sgt without clearing the pointer, so a later cleanup dereferences and frees the stale object again.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9525e3a6fbb1d126a22ab2ee86ddea25af581a7c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7c89f474005d8377525d2991930b7432ee193a52",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b35a13036755c5803168a7cb93bc66035c3e65b8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2019,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64072",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:47.823Z",
      "date_updated": "2026-07-19T15:39:47.823Z",
      "publisher": "Linux",
      "title": "nvme: fix bio leak on mapping failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.07002
      },
      "nvd": {
        "published": "2026-07-19T16:17:47.793",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64072",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The NVMe integrity-mapping failure path loses the request's bio because it consults a local pointer that is always NULL.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fea4b46f84c50caf93c6c0f2a54b1be2edfb4491",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/51ec7fc4e10c5e332bf4007bdb7e4c6bf03c14c9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2279cd9c61a330e5de4d6eb0bc422820dd6fdf36",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 230,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64073",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:48.463Z",
      "date_updated": "2026-07-20T13:43:01.595Z",
      "publisher": "Linux",
      "title": "irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03184
      },
      "nvd": {
        "published": "2026-07-19T16:17:47.893",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64073",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "irq_work clears BUSY before its final object accesses, allowing another CPU to free the work before those accesses finish.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2dc79362302922cb18f35e262712b5e58de65442",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eef4f71b46a9929ac33e968538c9dd5d96a02460",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/684a78183c54c23e70d1cba320f7fc184604210b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/18c0456ea2615b1a743a6db739c74411c3b42bc6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/81b582784518196eff1050212a046bc29d3a05dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/91840be8f710370607f949a627e070896faeddb8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 911,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64074",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:49.076Z",
      "date_updated": "2026-07-20T13:43:02.576Z",
      "publisher": "Linux",
      "title": "fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02772
      },
      "nvd": {
        "published": "2026-07-19T16:17:48.010",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64074",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "statmount increments an already-overflowed seq count past the buffer size, defeats the overflow test, and writes a terminating null one byte out of bounds.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e37ea2c6f17f273813ea4e8e94c102591d598ce1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/93614949dc86f068e3c32c32cf1ee2a2323177a7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a3bf0f28d4ba16e1f35f8c983bb04426b87e2a78",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 716,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64075",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:49.679Z",
      "date_updated": "2026-07-19T15:39:49.679Z",
      "publisher": "Linux",
      "title": "fprobe: Fix unregister_fprobe() to wait for RCU grace period",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06239
      },
      "nvd": {
        "published": "2026-07-19T16:17:48.113",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64075",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "unregister_fprobe removes an object from an RCU list without waiting for a grace period before the object can be freed.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/56b4cfcf1518245493c60fd39c56978f508f1816",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a4f6a9005ed6cfd360ef2520430927f05f92ffb0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/657b594b2084b39a4bc6d8493aa2140cb00cea49",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 876,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64076",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:50.346Z",
      "date_updated": "2026-07-20T13:43:03.553Z",
      "publisher": "Linux",
      "title": "netfilter: bridge: eb_tables: close module init race",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02771
      },
      "nvd": {
        "published": "2026-07-19T16:17:48.213",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64076",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ebtables registers globally reachable socket options before core module initialization is complete, allowing a request to race partially initialized state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c647e2a21bbbaceda6cdb8a44a56f44d231dc4b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/02d999dc69b3918dba2414932b5d95f1f75c76cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/27414ff1b287ea9a2a11675149ec28e05539f3cc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 381,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64077",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:50.966Z",
      "date_updated": "2026-07-20T13:43:04.526Z",
      "publisher": "Linux",
      "title": "netfilter: ebtables: move to two-stage removal scheme",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02767
      },
      "nvd": {
        "published": "2026-07-19T16:17:48.313",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64077",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ebtables removal can expose a partially replaced table to concurrent readers before the old table's references are safely retired.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/739d5dac7b2da44a756aa4d758ee3f1ccf5a27f1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ef395579a7631a06d61969fc712eb80402231b89",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b7f0544d86d439cb946515d2ef6a0a75e8626710",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64078",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:51.582Z",
      "date_updated": "2026-07-20T13:43:05.475Z",
      "publisher": "Linux",
      "title": "netfilter: x_tables: add and use xtables_unregister_table_exit",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02767
      },
      "nvd": {
        "published": "2026-07-19T16:17:48.407",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64078",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Teardown omits the second-stage dying-list and hook cleanup, leaving state active after its lifecycle transition.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/86ee5bc9c0f0e652e19f395675a432de11b75514",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8026e5163cca1d1db436c7bfb89ddea8b5e8c2cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b4597d5fd7d2f8cebfffd40dffb5e003cc78964c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 680,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64079",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:52.192Z",
      "date_updated": "2026-07-19T15:39:52.192Z",
      "publisher": "Linux",
      "title": "netfilter: x_tables: allocate hook ops while under mutex",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.05211
      },
      "nvd": {
        "published": "2026-07-19T16:17:48.503",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64079",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "xt_register_table publishes a table before allocating its hook operations, so concurrent namespace teardown can pass a null operations pointer to nf_unregister_net_hooks.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2f92c5f923979f37ab1d5445381e4b8378a196cc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b62eb8dcf2c47d4d676a434efbd57c4f776f7829",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1296,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64080",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:52.818Z",
      "date_updated": "2026-07-20T13:43:06.417Z",
      "publisher": "Linux",
      "title": "firmware: arm_ffa: Snapshot notifier callbacks under lock",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04281
      },
      "nvd": {
        "published": "2026-07-19T16:17:48.607",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64080",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "FFA notification handlers drop notify_lock before copying a callback entry, allowing concurrent unregister to free the entry before dereference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d1e38551fadea230649bc428f0f35c9ee062a072",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e7be42ef2490f19d859a6146324d48cafdc9d5c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/38290b180a4d5746baed796d49f88d56d2f336cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 675,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64081",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:53.433Z",
      "date_updated": "2026-07-20T13:43:07.436Z",
      "publisher": "Linux",
      "title": "firmware: arm_ffa: Validate framework notification message layout",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03845
      },
      "nvd": {
        "published": "2026-07-19T16:17:48.707",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64081",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The FF-A framework-notification path uses firmware-supplied message offsets and sizes without validating that they remain within the shared RX buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3c51d99449dc5a01c08a7fce6071d6721f5aac83",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/76eb90e2b03de147e12ab68ea8afd8ea0342df0a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4a1cc9e96b311d2609a6f963a5e35bd4ae730d97",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64082",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:54.074Z",
      "date_updated": "2026-07-20T13:43:08.413Z",
      "publisher": "Linux",
      "title": "riscv: Fix register corruption from uninitialized cregs on error",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02186
      },
      "nvd": {
        "published": "2026-07-19T16:17:48.807",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64082",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "RISC-V error paths copy an uninitialized compatibility-register buffer into task registers after a failed user copy.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9e020156833f1ad0d425a1e3d85b65639f1c1c50",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ebcbb53fc9bc30843054ed99fd60b8e542628f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 707,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64083",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:54.756Z",
      "date_updated": "2026-07-19T15:39:54.756Z",
      "publisher": "Linux",
      "title": "hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.0827
      },
      "nvd": {
        "published": "2026-07-19T16:17:48.910",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64083",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ADM1266 GPIO accessors accept zero- or one-byte block reads and combine uninitialized stack bytes into values returned to user space.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fd9196aad9e5a3845cea17de3405ebc700382142",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ee4799becf7d2af3778007e22c2e55c4009a49c7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c603b6c6840ac0c6285f5eefea0de6242710af21",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a2d1c819348b36fccbbfcf37c5fa7a50a9b4528f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ae25cf2ea9ebd06d7ad416647dbdc7b5d0172946",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eb3cd9bb590460c6127145cb245be925d23f5232",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/64fa9328948ddcc0f7f3c23ea1756c126d9dffac",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a7232f68c43ca62f545049b7f5fbfc75137b843b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1080,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64084",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.031Z",
      "date_published": "2026-07-19T15:39:55.417Z",
      "date_updated": "2026-07-20T13:43:09.375Z",
      "publisher": "Linux",
      "title": "hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03687
      },
      "nvd": {
        "published": "2026-07-19T16:17:49.043",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64084",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The adm1266 parser uses the wrong bound constant for an attacker-influenced index and accesses beyond the intended array.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d0593e15fdeb56048a72c5c6e720f702759d0ccd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/17cee2f59029039416e8f6303050038eb59ba149",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/299efd14c2eda7e5fd40025e54addd4151a01081",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4d1da9a6be5a8156c532d571c2ed237169f99244",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b96c7f0bc0713dc6403912f6527d4ff9168d6fe6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fa7ca363069a70b0d1aa51e8892e3095fe2ac1ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2aef8f08c479f4cbc83e1e6b19d1c94d4dd24f17",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d7834d92251baade796812876e95555e2066fa9f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1035,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64085",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.032Z",
      "date_published": "2026-07-19T15:39:56.067Z",
      "date_updated": "2026-07-19T15:39:56.067Z",
      "publisher": "Linux",
      "title": "hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.0827
      },
      "nvd": {
        "published": "2026-07-19T16:17:49.173",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64085",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The PMBus helper copies a device-supplied length of up to 255 bytes directly into a 64-byte trailing blackbox-record slot before validating the returned size.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7896d87cbb05e097efc113243d4e38f9f8cea16c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9d5309500b4607b7198e19f0a3fa13eb864cd5fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6098634cfa711f11a8d65368dc51ec8f7c8241ba",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/60c4b9fe1a3dd012014b1f561a6928a0b5db1126",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/83e039f0a43e0708515b0479cb7690fb93faaaa0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/97a9cf2a8217ca1cdaf48cb9ab26e471632c7e7f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dd47b8c4a0a8ced442da3f008db28fbbd31feaf0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/43cae21424ff8e33894a0f86c6b80b840c049fd7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1202,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64086",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.032Z",
      "date_published": "2026-07-19T15:39:56.749Z",
      "date_updated": "2026-07-20T13:43:10.387Z",
      "publisher": "Linux",
      "title": "hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03691
      },
      "nvd": {
        "published": "2026-07-19T16:17:49.300",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64086",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "adm1266_pmbus_block_xfer requests a 257-byte maximum response into a 256-byte read_buf and then indexes the PEC byte at the same out-of-range position.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/397d3f523bfff2f4e3dacf9b1339bd76dc207f78",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/472744f69d25a2d5111ad62f1d62579dce2c13c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/528a9f88e88502d0c2f2052a279415074cd83715",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d94ceb16e55b6d8019ab069e357c76ac42f0ffbc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bd5be3fa5de6dbf61f1b3cec6b79c2c2f8065694",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2279c342d94eca225bf9f301c8806a05a1c81619",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6c802145a8de0830bca803c6d415f7e9e683624",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/487566cb1ccdf3756fdd7bf8d875e612ff3169bb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 865,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64087",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.032Z",
      "date_published": "2026-07-19T15:39:57.371Z",
      "date_updated": "2026-07-19T15:39:57.371Z",
      "publisher": "Linux",
      "title": "hwmon: (pmbus/adm1266) reject implausible blackbox record_count",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.08269
      },
      "nvd": {
        "published": "2026-07-19T16:17:49.433",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64087",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A device-controlled blackbox record count can exceed the 32-record destination allocation and drive the copy loop beyond that buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/adcb163ad7cacca317872fc62bd8885e842e45e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c2c56092710fe8a893b67b5a3d7e62808d02d84d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5469e1e7c411acc15fdd8262c99c3ebd9defd594",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f85c81e93dbd6915970bd5f3bffcf62633c4c54c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e791cd0140fb136083565aadfbe0f705aa260d0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/75c862adf3d3caab4f49bb3530723c215376e37c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/231db52a5b64d0a9769e298dadc148e1f79b26a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4afca954622d672ea65ed961bed01cf91caa034e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 846,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64088",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.032Z",
      "date_published": "2026-07-19T15:39:58.084Z",
      "date_updated": "2026-07-20T13:43:11.384Z",
      "publisher": "Linux",
      "title": "batman-adv: tt: fix negative tt_buff_len",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00281,
        "percentile": 0.20391
      },
      "nvd": {
        "published": "2026-07-19T16:17:49.557",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64088",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A translation-table length stored in signed 16-bit form wraps negative and leaves most of an allocated response buffer uninitialized.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4c4c2f340f4c27373bfcac8dc5032ce7bb474e47",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/33e5ede7ce6d92e531920d4bbd6d3e18ef1c6430",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3c96dff00998314983b68a3e7caac07a66ebe496",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/32edd2a28e112064020a2f319a8cb8a9e5a09767",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4dab98961426d0cf6a1599cda6950b7596ca2fcd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/730de8733dd90f70d7580a9b329b971f8e1474a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ed28ead3420c373a7928622f114bc6168075d1e1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b64963a2ceeb7529310b6cf253a1e540784422f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 770,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64089",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.032Z",
      "date_published": "2026-07-19T15:39:58.729Z",
      "date_updated": "2026-07-20T13:43:12.374Z",
      "publisher": "Linux",
      "title": "batman-adv: tt: fix negative last_changeset_len",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00552,
        "percentile": 0.43023
      },
      "nvd": {
        "published": "2026-07-19T16:17:49.697",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64089",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A translation-table changeset length stored as signed 16-bit wraps negative, sign-extends during buffer preparation, and leaves most of an allocated response uninitialized.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6314089acf0ddf64376fdc0b1420695504c73f52",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/55dc41fe8821e9a849e147255ad572bc933a9d15",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c424e8519ac78eac5d9f4eecf06208a0d619ec14",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/22d59c72f4a47ffec121d0610f70d0d70c3c11c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eb235472b52ef36981c5aad330485eaf2382c53b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/179eb62506a02d00370bd6478898cb632e10986c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d29abf70c665730e249d2ec8e1402095ae26bcee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fc92cdfcb295cefa4344d71a527d61b638b7bfc4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 785,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64090",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.032Z",
      "date_published": "2026-07-19T15:39:59.392Z",
      "date_updated": "2026-07-19T15:39:59.392Z",
      "publisher": "Linux",
      "title": "batman-adv: tt: avoid empty VLAN responses",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.08267
      },
      "nvd": {
        "published": "2026-07-19T16:17:49.837",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64090",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The indirect translation-table reply path can send empty VLAN state because it lacks the consistency check used by direct replies.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1f467d9a095211d3f77e8ff1bee90e73ffe01c64",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9a02c8fc963ddeecb5d8788be0740c1869fc54b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ea4f757641430bcc8322772e161453c4db5ecb64",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/99f17d1cdb371cbd037975239b321f346d38f6d2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cfb30645280a2131e46cbd1b9a38cfd3ff893f12",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b93ca6012712ecab2b551e120d7c95038d6a89e5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ab26e346322648f5c39de017d9723c9256284fce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fa1bd704940b5bcbc32c0b28db9167405c8ee5e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 490,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64091",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.032Z",
      "date_published": "2026-07-19T15:40:00.030Z",
      "date_updated": "2026-07-20T13:43:13.369Z",
      "publisher": "Linux",
      "title": "batman-adv: tt: fix TOCTOU race for reported vlans",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 26,
        "versionRangeCount": 21,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00552,
        "percentile": 0.43023
      },
      "nvd": {
        "published": "2026-07-19T16:17:49.967",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64091",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The VLAN list can gain qualifying entries between size calculation and buffer fill, so the later write exceeds the allocation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e4236bf3ec8d6bb15d0d8d825dcf9933a7d6666b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/724a8eb4155669797c96b70d70e354284ae3b5a8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/211ea59988e1cba43cb0367ad65d379b56f9c3bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/65a1e67339aa8c95ac544b796946af388930ee23",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b4d4efd4e351593c81e9293d4b4408d244fa5ee7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4cc85aec8d3c9ab4dc716dc9f1ed36fca16b227f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9a9c859457bc440a55773e01ff18b1bb5bab6836",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/94d27005016be15ffc638b2ecbc4d58805ad7b48",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 980,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 26
      }
    },
    {
      "cve_id": "CVE-2026-64092",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.032Z",
      "date_published": "2026-07-19T15:40:00.603Z",
      "date_updated": "2026-07-19T15:40:00.603Z",
      "publisher": "Linux",
      "title": "batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 13,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0018,
        "percentile": 0.07823
      },
      "nvd": {
        "published": "2026-07-19T16:17:50.110",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64092",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Two shutdown paths can each assume the other released the timer-held reference, leaving it permanently retained.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7715c73f33260af724d734c41b794457e9be8dbc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/297e1bc4a915b7cd3e65a79ed906b23fb3d7aaae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0b1bedf114ea93fef929b31f0d70a9eedcc601de",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a9f0bfd624ee8a286d6fd2bf0f796e730efb49b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b285bc0a97f43823a4967fb6d286de4c7f53d541",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d078501dde9b57210f1808cdef4b59463d1f5fc8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/77098e4bea37af51d3962efa88a5af2ea5e1ac57",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1082,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-64093",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.032Z",
      "date_published": "2026-07-19T15:40:01.172Z",
      "date_updated": "2026-07-20T13:43:14.395Z",
      "publisher": "Linux",
      "title": "batman-adv: tp_meter: directly shut down timer on cleanup",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26259
      },
      "nvd": {
        "published": "2026-07-19T16:17:50.230",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64093",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "batadv_tp_sender_cleanup deletes a timer without permanently preventing the handler from rearming it during teardown, allowing timer activity to outlive the sender state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/00bf4bb9947b1190a8be8d9b6a1bcbfa3707785c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/74a76634055462833446684fd526d73c290ea43a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5bc2d50fb66b46f86543d5153a188eb1486d0b6e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f86b20ec8d17d77bddc02c5c86cfa2389d84ecff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/770bf0a35f0620b526fd4193889d1e77084e4c43",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/933880a8bc9b4042223a79255c0b1021cdc36991",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d5487249a81ea658717614009c8f46acc5b7101a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1119,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64094",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.032Z",
      "date_published": "2026-07-19T15:40:01.772Z",
      "date_updated": "2026-07-19T15:40:01.772Z",
      "publisher": "Linux",
      "title": "batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0021,
        "percentile": 0.11358
      },
      "nvd": {
        "published": "2026-07-19T16:17:50.353",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64094",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The batman-adv path can lose its mesh-interface association concurrently and then dereference the now-null pointer while sending an ARP request.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4f6266735a0ba6a568b6d4c9fa51c33a5a7f2d70",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/53cb3511f6eda37d3bd923545fdba6013b6d7bb7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/efb62458c94db1fe3a287e7e89c31b0cfb03f938",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2a8c9e86529156c62d9187b9ed9454c31665ad33",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0f3ebd7bb417aabc44853cc7c2a184ebb0e05b45",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6921a7683ae9ad0208d829e71f725a9e25ccff49",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/555b8d3f5c313d81d46274fd0976352dafc80124",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f80d3d98d2ff78d9e2fe5d68b1f45948c4f7bd24",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 529,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64095",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.033Z",
      "date_published": "2026-07-19T15:40:02.360Z",
      "date_updated": "2026-07-20T13:43:15.413Z",
      "publisher": "Linux",
      "title": "batman-adv: bla: avoid double decrement of bla.num_requests",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18687
      },
      "nvd": {
        "published": "2026-07-19T16:17:50.470",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64095",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent bridge-loop-avoidance paths update request state and its counter separately, allowing the counter to be decremented twice.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1f013bc94154f2e78e97d0296175664224c796e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5328b95960774f2e189f22485616bc7b8eb2f7e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8ff9c59d1b7b48c2596878341a5310f32895d52b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a9393751ecf7e9096f93cb6eed02db4f79125765",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/461f1e3dfb888701895b766446c55db2b10db705",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/45384612f29692fbf0c770200361a7acff90125c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/65497ad155a3246df177b5ef662cd6e5a32cb470",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/83ab69bd12b80f6ea169c8bea6977701b53a043d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1267,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64096",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.033Z",
      "date_published": "2026-07-19T15:40:02.969Z",
      "date_updated": "2026-07-20T13:43:16.405Z",
      "publisher": "Linux",
      "title": "batman-adv: mcast: fix use-after-free in orig_node RCU release",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17025
      },
      "nvd": {
        "published": "2026-07-19T16:17:50.600",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64096",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The purge path removes entries visible to RCU readers without waiting for a grace period, permitting access after removal.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ff3a4487ead475e27b43280b8ee3d8464fe280e1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/78a63fb2f7d5630d1c1f2859a20d4e4226863b41",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ced48f55bac73f0822eae90509e51b42b4f646c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/70bcb678561f0fb58f33270fc73f12f3be72b878",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aef897c9d2dd0d9339167fb82b62beff68d076cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8a3707653ab658e082ccd992e92594e01b09a3fc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/edfb1e094104a50f931553dc82ac59246569fd32",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/20c2d6a20ca936f5aaa6dd40f73f262ac45c87cc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 708,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64097",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.033Z",
      "date_published": "2026-07-19T15:40:03.599Z",
      "date_updated": "2026-07-20T13:43:17.391Z",
      "publisher": "Linux",
      "title": "drm/amd/display: Validate GPIO pin LUT table size before iterating",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02964
      },
      "nvd": {
        "published": "2026-07-19T16:17:50.727",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64097",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The AMD GPIO parsers trust a VBIOS structuresize and iterate beyond the mapped image without validating that the full table is present.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9900f6954be779011e7c2cd42addd87baf028bc5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fb30a3890d62fd50a95aef684faf64a307592e42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/67461e0c15335894cc5d3b84cda823bf8cbdc886",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7ca695b3122297b06a3ed605bbe1cd32c85d9f5a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f2a4827e980ba07de4391fa84d9c39a12726bdd7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/86d2b20644b11d21fe52c596e6e922b4590a3e3f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 823,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64098",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.033Z",
      "date_published": "2026-07-19T15:40:04.264Z",
      "date_updated": "2026-07-20T13:43:18.356Z",
      "publisher": "Linux",
      "title": "drm/virtio: use uninterruptible resv lock for plane updates",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04335
      },
      "nvd": {
        "published": "2026-07-19T16:17:50.843",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64098",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "virtio-gpu continues modifying fence and reservation state after an interruptible lock acquisition fails.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c86077d512ee980cc91322211d35dbcd3175f64c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/21ab64c77a30d56efc506c8fa2ad8959f8ce3d36",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7930eee22cd3df61e85be8aa512032ab303b7167",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8fadd01cf461fee5bb11506621339c548447e5c7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a2359a411b15f495d12cfda6a7db6855ebb7f90f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9af1b6e175c82daf4b423da339a722d8e67a735a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2704,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64099",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.033Z",
      "date_published": "2026-07-19T15:40:04.925Z",
      "date_updated": "2026-07-20T13:43:19.332Z",
      "publisher": "Linux",
      "title": "drm/v3d: Fix use-after-free of CPU job query arrays on error path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00134,
        "percentile": 0.03334
      },
      "nvd": {
        "published": "2026-07-19T16:17:50.983",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64099",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The V3D CPU-job error path releases the job and then reads query-array fields through the freed cpu_job object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/acd55ea40d03e06f20a9986363019e0e5173990e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0f8efc45740b0628a787d1b0be8a0ddabd700625",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/69c2a1fec2e7ca25598180816f3bc56e1842eb41",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b0fe80c0b9250b35e2211bf3117e7aca814a21b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1487,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64100",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.033Z",
      "date_published": "2026-07-19T15:40:05.530Z",
      "date_updated": "2026-07-19T15:40:05.530Z",
      "publisher": "Linux",
      "title": "drm/msm: Fix shrinker deadlock",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.07002
      },
      "nvd": {
        "published": "2026-07-19T16:17:51.140",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64100",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MSM shrinker acquires a dma_resv lock while memory reclaim already holds fs_reclaim, creating a circular lock dependency and deadlock.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/942968260e61d4a5d7552b20814b6277f9c553df",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/928788566c79046f71a211fc32c115400be76402",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3392291fc509d8ad6e4ad90f15b0a193f721cbc9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3998,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64101",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.033Z",
      "date_published": "2026-07-19T15:40:06.185Z",
      "date_updated": "2026-07-19T15:40:06.185Z",
      "publisher": "Linux",
      "title": "fwctl: pds: Validate RPC input size before parsing",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.07001
      },
      "nvd": {
        "published": "2026-07-19T16:17:51.273",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64101",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The PDS firmware RPC handler casts and reads a caller-sized buffer as a full request structure before checking its length.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9e3f18883a98420a3b8873c6f894bc57e9b98e41",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0d470d36551058e3f728574308b815a80bca710f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e7537735028c3ad4b0bfc02ff8fa2a1a28aa04fe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 622,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64102",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.033Z",
      "date_published": "2026-07-19T15:40:06.776Z",
      "date_updated": "2026-07-20T13:43:20.335Z",
      "publisher": "Linux",
      "title": "RDMA/siw: Reject MPA FPDU length underflow before signed receive math",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.005,
        "percentile": 0.40065
      },
      "nvd": {
        "published": "2026-07-19T16:17:51.383",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64102",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Soft-iWARP subtracts an unchecked peer MPA length from the fixed header size, turning an underflow into a negative signed copy length and then a huge size_t read.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/683f7cfbf514193d63c0efa079f3352bde84c2e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4a331582011d9e8089af8aa2a61ec6b4443bb245",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/33a8b5e971e294ec2a7b74211c545e09efd8e9ac",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/14553be882d9ce91749c9d64041de66e34ad8e70",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c7c0c0f4379dedec12d24dbb9dded5d2db7fd9f2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1012896f4225e8f801ff3c1648023845b66dfb11",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/775b4dc9618a99a1fa48b57554041a5dc17e1336",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0ce1bc9e46ecabe84772bb561e373c0d9876d6f2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2504,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64103",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.034Z",
      "date_published": "2026-07-19T15:40:07.372Z",
      "date_updated": "2026-07-19T15:40:07.372Z",
      "publisher": "Linux",
      "title": "scsi: isci: Fix use-after-free in device removal path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07404
      },
      "nvd": {
        "published": "2026-07-19T16:17:51.533",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64103",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ISCI teardown does not kill the completion tasklet after interrupt scheduling is quiesced, so a queued callback can access the freed host.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1412995e10c74644b47f242aea6e4f3d4180e806",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a83d3e4daba40d49324cec1c51ed261e1ea48cf1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ab2266601a875982f2d2033f41e070a6d5e615e2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/309c6058622d080fe8c2fab87c30da82d834d989",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cb9e72c50e6c81a5903f27e0b397ce8525d7539b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b9ff8631006233ba246828ac70409d2cb2da38d3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6d40f2f103bb30f52f3dbadbe2c3fdf274a9763c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b52a8d52c3125ec9a93106ed816582368de34426",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1472,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64104",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.034Z",
      "date_published": "2026-07-19T15:40:07.994Z",
      "date_updated": "2026-07-20T13:43:21.343Z",
      "publisher": "Linux",
      "title": "virt: sev-guest: Explicitly leak pages in unknown state",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03239
      },
      "nvd": {
        "published": "2026-07-19T16:17:51.677",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64104",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A failed encrypted or decrypted page-state transition leaves pages in an unknowable state, so returning them to the allocator could expose unencrypted pages for unsafe reuse.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bee400ad4f4259c9c0758e4f1960a1eed6f6f9f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3d0cd0065deeb054b4b29236432e851806b7cc81",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fd948c3f96b18ff9ba7d3e8eae13d196593e1aaf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64105",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.034Z",
      "date_published": "2026-07-19T15:40:08.605Z",
      "date_updated": "2026-07-19T15:40:08.605Z",
      "publisher": "Linux",
      "title": "KVM: arm64: vgic: Free private_irqs when init fails after allocation",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06419
      },
      "nvd": {
        "published": "2026-07-19T16:17:51.780",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64105",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A vGIC initialization failure frees the vCPU without releasing private IRQ allocations made earlier in initialization.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/173fb86e5519dbe7aabed1f5fa7456152a4a2e38",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7023900b4988fb6f4a59d304d878003ff562e98d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e690caa54a6139d98495ac69626807623520babd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f19c354dbd457759dfcf1195ab4bdba2bb568323",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 639,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64106",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.034Z",
      "date_published": "2026-07-19T15:40:09.344Z",
      "date_updated": "2026-07-20T13:43:22.355Z",
      "publisher": "Linux",
      "title": "KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04507
      },
      "nvd": {
        "published": "2026-07-19T16:17:51.887",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64106",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The restore path accepts DTE state that the live path rejects, allowing an oversized scan state to be installed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1716b7fea2ead941a0dfac06c4504a3437cdf00d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dab9f93251b2c86a033de6098d0c73afddd55d4a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b94538186a3eae3763b8f96dacd610920a865aa7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0680f511926589206f81f57f76ce131d7741a316",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8bcd15b690a390241179516af1b6ae49ebfd9d95",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9ce754ed8e7ab4e3999767ce1505f85c449ccb07",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64107",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.034Z",
      "date_published": "2026-07-19T15:40:10.079Z",
      "date_updated": "2026-07-19T15:40:10.079Z",
      "publisher": "Linux",
      "title": "ASoC: codecs: pcm512x: fix null-ptr dereference in pcm512x_overclock_xxx_put()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00162,
        "percentile": 0.05904
      },
      "nvd": {
        "published": "2026-07-19T16:17:52.000",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64107",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "pcm512x_overclock_xxx_put derives a DAPM context from a general mixer control and dereferences the resulting null pointer.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/285159ca199cbbe424223d4b14db227b279b5767",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/09e8f9a9aa19aa8c1b0cc7a0ebc68f6ecf86a660",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 463,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64108",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.034Z",
      "date_published": "2026-07-19T15:40:10.784Z",
      "date_updated": "2026-07-20T13:43:23.343Z",
      "publisher": "Linux",
      "title": "cifs: Fix busy dentry used after unmounting",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02965
      },
      "nvd": {
        "published": "2026-07-19T16:17:52.100",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64108",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Deferred CIFS close work can outlive unmount and retain a dentry reference past generic_shutdown_super because the workqueue is not flushed first.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c7364cea52531534676b9f7dbc0a477c11f4c050",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bdc349a87f1fb02c18c4071858a06542bfea783d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f2deaa2f409a4598eaa10f2a93a676c0632af248",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5e7d9d0805e58fa3760894e73115b7a74024fd07",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e1ffa6cf662383f95816eed1b623429d82675e75",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c68337442f03953237a94577beb468ab2662a851",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1591,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64109",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.034Z",
      "date_published": "2026-07-19T15:40:11.510Z",
      "date_updated": "2026-07-20T13:43:24.366Z",
      "publisher": "Linux",
      "title": "af_unix: Fix UAF read of tail->len in unix_stream_data_wait()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02902
      },
      "nvd": {
        "published": "2026-07-19T16:17:52.233",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64109",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "unix_stream_data_wait reads tail->len after another thread can dequeue and free the tail socket buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/26342087fac93b3932e6af61dc91ec029cb8a623",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/38bccb927d83d7d52e5b20015a172a0b6101d11e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/acdff9907478e82208475b1151700d0b71dcdc63",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5f162f95a95834f06a8ec6140889272ad12e842f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be309f8eae8b474a4a617eaae01324da996fc719",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3261,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64110",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.034Z",
      "date_published": "2026-07-19T15:40:12.224Z",
      "date_updated": "2026-07-19T15:40:12.224Z",
      "publisher": "Linux",
      "title": "igc: fix potential skb leak in igc_fpe_xmit_smd_frame()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06235
      },
      "nvd": {
        "published": "2026-07-19T16:17:52.370",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64110",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "igc_fpe_xmit_smd_frame leaves its allocated skb unreleased when transmit-descriptor initialization fails.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f1bafd35f11b3aca1c7bb38da173b8787364a04c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3ebf056556138e74c640e6dc2b3848abd398b460",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e935c37b8a94bb256fada6395a5d05e1c0c6bdaf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 749,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64111",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.035Z",
      "date_published": "2026-07-19T15:40:13.007Z",
      "date_updated": "2026-07-20T13:43:25.360Z",
      "publisher": "Linux",
      "title": "lsm: hold cred_guard_mutex for lsm_set_self_attr()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03411
      },
      "nvd": {
        "published": "2026-07-19T16:17:52.463",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64111",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "lsm_set_self_attr checks ptrace-sensitive credential transitions without holding cred_guard_mutex across the decision.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/82d3acee88593e3d9e71cad4b7d6b3cf70de9d07",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5b906f31e977286888a9e31282589b545b249139",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a010cadaf5727b8417f62fe9021fcef14a5f9b51",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4a9b16541ad3faf8bccb398532bf3f8b6bbf1188",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 328,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64112",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.035Z",
      "date_published": "2026-07-19T15:40:13.652Z",
      "date_updated": "2026-07-20T13:43:26.331Z",
      "publisher": "Linux",
      "title": "rbd: eliminate a race in lock_dwork draining on unmap",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02906
      },
      "nvd": {
        "published": "2026-07-19T16:17:52.567",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64112",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "maybe_kick_acquire can requeue lock_dwork after a concurrent cancellation during unmap, allowing lock work to run after image state is released.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3427d7ae38337066ce88b68302e285d344ab756b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9dcd4f5c99b491c37be90b0bd9988db48225fb75",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9400efc76b42c751211974a25c91d2c19c65b01b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9fc75b71fdd38465c76c6f6a884cdd4ae3c72d90",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2009,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64113",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.035Z",
      "date_published": "2026-07-19T15:40:14.251Z",
      "date_updated": "2026-07-20T13:43:27.336Z",
      "publisher": "Linux",
      "title": "ixgbevf: fix use-after-free in VEPA multicast source pruning",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.005,
        "percentile": 0.40064
      },
      "nvd": {
        "published": "2026-07-19T16:17:52.680",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64113",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ixgbevf multicast pruning dereferences a receive-buffer object after the cleaning path has released it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ef30384a50a50e4a484cddf341bc27de31aa3de",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/add70e2682c0ad3be2a5810bcf1bc13963ba4df9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a244395d8c563ed1bb26c3ef708db6aeeaa08084",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dfef79e09ed2f5df975c98547f97f5d7f8982a24",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e8768bcbe5cd30c4ea36a22022c9ffaa66903693",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5d49b568c188dc77199d8d2b959c91da8cc27cf1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1561,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64114",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.035Z",
      "date_published": "2026-07-19T15:40:14.854Z",
      "date_updated": "2026-07-20T13:43:28.323Z",
      "publisher": "Linux",
      "title": "ipv4: raw: reject IP_HDRINCL packets with ihl < 5",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03449
      },
      "nvd": {
        "published": "2026-07-19T16:17:52.820",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64114",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An IPv4 header length below five yields a negative length that becomes a large size_t and drives an out-of-bounds access.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1065b9efa4126df559b03a849c139ecfae92cd25",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bc20dbd48c26e743f7e0845020c11ed2ce8b15ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5a564f737ec54d63e8ee221d3ff396d07586d464",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3c5411fa4944ed99af3d9d1de750ea8169b6dac9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/145e9afa5b905229b4788bb72c3255f5a5f77508",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7725cd3b471740fd23d25ed1da722c671fb2a5d3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bbe0be67de296176e7243c76e3d9f02f6ae9ff0b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/915fab69823a14c170dbaa3b41978768e0fe62fc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2502,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64115",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.035Z",
      "date_published": "2026-07-19T15:40:15.513Z",
      "date_updated": "2026-07-20T13:43:29.298Z",
      "publisher": "Linux",
      "title": "vsock/vmci: fix UAF when peer resets connection during handshake",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03371
      },
      "nvd": {
        "published": "2026-07-19T16:17:52.967",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64115",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A peer reset is treated as success and leaves a pending socket linked while cleanup drops references twice, causing the delayed worker to touch freed storage.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1e19f08552b90070ed18bafb1763c78297823af6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1dd531e28f61edd286edc486ab068f135b5ae1eb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ecda37f8faab3220da199335e42564cb7a9ad145",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cc27e989a5dfdfcfc1cca7c3be27a0c7532b46cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/47e63077605c6c2aa45b3df9847a8cdc1f1f6ef9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/440447699c681e26ed58e9c309cad718270a18b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9fe74e42914c851d68069713b7b917a9c33faf26",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/99e22ddf4edb63dc8382bc028af928056d3450cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1634,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64116",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.035Z",
      "date_published": "2026-07-19T15:40:16.240Z",
      "date_updated": "2026-07-20T13:43:30.328Z",
      "publisher": "Linux",
      "title": "ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00511,
        "percentile": 0.40776
      },
      "nvd": {
        "published": "2026-07-19T16:17:53.103",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64116",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The network path dereferences idev without first establishing that the pointer is non-null.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c7e8971abd70e9d022f1c251ba2508f8dc7f2db8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/09cbfd4b81ae90963dadb1de99b63b702e73290a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1dca7e491f070ac49b3d934f16ee953a53b37f38",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/902daac307eb7e1955ce05b071950f3cba88c963",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/abdd03229414b5a52943b65a60f34b84cea5ac59",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cf75eb6617042c8cff6112daeed7791809fc9dd2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d4ea0dfd75011b78cebf3808f98ac4c4f51a6fb9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 560,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64117",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.035Z",
      "date_published": "2026-07-19T15:40:16.941Z",
      "date_updated": "2026-07-20T13:43:31.348Z",
      "publisher": "Linux",
      "title": "wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14433
      },
      "nvd": {
        "published": "2026-07-19T16:17:53.217",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64117",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Mesh forwarding reuses and may free skb->cb before the RX path reads the aliased status, producing stale data or a use-after-free in rate accounting.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2fb64f94f9afb774f2fa0c7835727d7a67f89f07",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d71c841be5d9e586ee7f36c0dc8ed4db0d9a1349",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 971,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64118",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.035Z",
      "date_published": "2026-07-19T15:40:17.643Z",
      "date_updated": "2026-07-20T13:43:32.317Z",
      "publisher": "Linux",
      "title": "qed: fix double free in qed_cxt_tables_alloc()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.0488
      },
      "nvd": {
        "published": "2026-07-19T16:17:53.320",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64118",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An allocation-failure path frees CID bitmaps and leaves their pointers live for a second cleanup pass.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9fe030719bd083b766602692ee96c8c985798e3c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/06fa8e69019fd3c41a7b0ea8c5f509c3a33dc227",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8cf5e4d2ca6b101d163c7423a426fb0aec34f7bb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3904b993cc17ec5d7c5d3b57dbd0b775dafb9684",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bdf678a273cadbccc347f331ae2e93ff4d14834c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e47fc1c9181ae029e0e35a865cbf2adcbae626c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a04c207f0801abdd23a169b5f902a9845059a65a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2bccfb8476ca5f3548afbd623dc7a6980d4e77de",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 880,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64119",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.035Z",
      "date_published": "2026-07-19T15:40:18.331Z",
      "date_updated": "2026-07-19T15:40:18.331Z",
      "publisher": "Linux",
      "title": "l2tp: use list_del_rcu in l2tp_session_unhash",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00167,
        "percentile": 0.06382
      },
      "nvd": {
        "published": "2026-07-19T16:17:53.450",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64119",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "l2tp_session_unhash() uses list_del_init() on a list traversed under RCU, making a concurrently deleted entry point to itself and trapping readers forever.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5e40919a40cb3e590ed45c2a54a4a2518aa88a99",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e0c3dd7b30cc5ee42ab502da140cda93d794a20b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/acab6314bb75be994f720ed13e9d9139cbf828a8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/979c017803c40829b03acd9e5236e354b7622360",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1819,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64120",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:19.044Z",
      "date_updated": "2026-07-19T15:40:19.044Z",
      "publisher": "Linux",
      "title": "net: ethtool: fix NULL pointer dereference in phy_reply_size",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06239
      },
      "nvd": {
        "published": "2026-07-19T16:17:53.563",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64120",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A Linux allocation result can be null on an error path that dereferences it before checking whether allocation succeeded.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/61f53c1e58d68723bc1db10912a53f1991f08719",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3dbe20a3809347bacda890822e7ca013bd85a18c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4908f1395fb1b832ceec11584af649874a2732ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 975,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64121",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:19.745Z",
      "date_updated": "2026-07-19T15:40:19.745Z",
      "publisher": "Linux",
      "title": "net: ifb: report ethtool stats over num_tx_queues",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06903
      },
      "nvd": {
        "published": "2026-07-19T16:17:53.663",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64121",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The IFB ethtool callback walks stats by the larger RX queue count although tx_private was allocated by the TX queue count, reading beyond the array and returning adjacent slab data.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6afdb8113cb007f9332f59a9b7fd45731b8a9de5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/16bd798cb6d8337d7c3eea1adc412f31b5181d5b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/301a554e458e2f5ec47f2c336a7cb03b877f9fd6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f8a5a76b4a683043c6eff2a060bcaa17f9316ad5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2638e1773904d7aa8f24c6e7fda2ed7d69df6fa4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5db89c99566fc4728cc92e941d8e1975711e24b5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1669,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64122",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:20.446Z",
      "date_updated": "2026-07-20T13:43:33.309Z",
      "publisher": "Linux",
      "title": "net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 11,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00461,
        "percentile": 0.3768
      },
      "nvd": {
        "published": "2026-07-19T16:17:53.790",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64122",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The TX recovery path reads sq->netdev after channel reopen has freed the channel containing that send queue.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1604a2d68414aa4cc34faac0b7faa9c14455e8d3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/152295aa7dc2c5e046606f7dadc84fce41136446",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7d260c5d2d89eb2c8c528d54b576b3aae3e20231",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1142,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-64123",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:21.161Z",
      "date_updated": "2026-07-20T13:43:34.311Z",
      "publisher": "Linux",
      "title": "net: hsr: defer node table free until after RCU readers",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 16,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02638
      },
      "nvd": {
        "published": "2026-07-19T16:17:53.907",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64123",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HSR teardown frees node-table entries immediately while generic-netlink readers still hold those entries under RCU.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0ea70fb46940620848c08d9d399455c9e82fecdb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8be6685cdd1255bcc85f9b59e4bfc313aefc5c1b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c5580114e0492bcd2e0a37613ed4c311e3fa3d4d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7713f4aafb577ff49fa67f0488d9c7dddc64d6ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6324423a8e6591f41a16c09a8f9a84e554ac147c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8c3af18bb0d7c921a5219194037509463eb2ffde",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aaec7096f9961eb223b5b149abe9495525c205d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 916,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64124",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:21.879Z",
      "date_updated": "2026-07-20T13:43:35.329Z",
      "publisher": "Linux",
      "title": "net: devmem: reject dma-buf bind with non-page-aligned size or SG length",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.0277
      },
      "nvd": {
        "published": "2026-07-19T16:17:54.030",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64124",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The device-memory bind path assumes page-aligned DMA sizes and indexes one entry past tx_vec or desynchronizes scatter-gather regions when that invariant is false.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/134c517dfa63203287b2aad6558017f42435a02e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d5008e4e4ee6b739256b796702a7d1aae1b5c3b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4eb82ba543421e9e38cc14e4e82058b78850df50",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1048,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64125",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:22.590Z",
      "date_updated": "2026-07-20T13:43:36.374Z",
      "publisher": "Linux",
      "title": "net: bcmgenet: keep RBUF EEE/PM disabled",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00552,
        "percentile": 0.43022
      },
      "nvd": {
        "published": "2026-07-19T16:17:54.130",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64125",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The driver enables incompatible RBUF EEE and power-management control bits, causing the hardware receive path to stop forwarding frames and sometimes corrupt receive processing.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2040eb83f6ada148fb32dd98b943a498005d79f2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f2782ddac82c70df313012da5f71f1f06b5553ca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b579f3a73da7a7e74213558f4cc3d865c30aaa78",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/289499907399c5a9f2ed82cb34df49112bb8488f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a212fc08f5c48a16a94092bf0a9a8b7cf4483b11",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3d4ef05266ab16d8ef7dd21658a557801eb78704",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/49bdf6bbb21b9c6e3f4d0c1910bf0ef98424be95",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9a1730245e416d11ad5c0f2c100061d61cc43f60",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1177,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64126",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:23.276Z",
      "date_updated": "2026-07-20T13:43:37.349Z",
      "publisher": "Linux",
      "title": "Bluetooth: MGMT: validate Add Extended Advertising Data length",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03388
      },
      "nvd": {
        "published": "2026-07-19T16:17:54.260",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64126",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Bluetooth management trusts two embedded lengths without confirming that the command payload contains those bytes, enabling an out-of-bounds read.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0d5104390b445e7bd664ad583837e4c04d892c9d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/14b01b9cba04e6ce82825f68fc4c4322fa4ffa43",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a143ce77a5292f2c9285137433d879ce71d190a7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6c75a3fad226ccbd8ef9110dee87c92c299f2ab",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f1febe93ef075314615f970a87681d9ab86691d1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0bc1a5a69f541859293d79db72bd7854ac48df51",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d3f7d17960ed50df3a6709c5158caff989c8c905",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 975,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64127",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:23.960Z",
      "date_updated": "2026-07-19T15:40:23.960Z",
      "publisher": "Linux",
      "title": "Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00175,
        "percentile": 0.07257
      },
      "nvd": {
        "published": "2026-07-19T16:17:54.387",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64127",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "l2cap_ecred_reconfigure passes the size and address of a local pointer instead of the packed request object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ed5fcd2a26f0c16fc289c8cd6b03328a0582a687",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/051922ab709c0a6917eae765c22481dfc68379e5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/356c9d1a1cbacd2a1640fff3c050e1c3472e924f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3374ef8cf99368a40f7efd51a2a375a4c5dc6f0d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2714,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64128",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:24.678Z",
      "date_updated": "2026-07-19T15:40:24.678Z",
      "publisher": "Linux",
      "title": "Bluetooth: ISO: drop ISO_END frames received without prior ISO_START",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0018,
        "percentile": 0.07823
      },
      "nvd": {
        "published": "2026-07-19T16:17:54.510",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64128",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Bluetooth ISO receiver accepts an END fragment before any START fragment and appends it through a null receive buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1c3d1e1696b72579b970e17999c503a14535205b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3af41ee7ebecb0d5c8a504861f6cfad31345310f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/39f4a82e80c8f5ed2d6952d73fbafc895721a728",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/61f2410a96dee808029e2ae4d6ef2dd635f3477f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e3a799881c12d27596232636a607e2e3fa448d63",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/84c24fb151fc1179355296d7ff29129ac7c42129",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 788,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64129",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:25.385Z",
      "date_updated": "2026-07-19T15:40:25.385Z",
      "publisher": "Linux",
      "title": "mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00172,
        "percentile": 0.06878
      },
      "nvd": {
        "published": "2026-07-19T16:17:54.627",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64129",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "migrate_vma_insert_huge_pmd_page jumps to its abort path after acquiring the PMD spinlock but skips the unlock label when address-space validation fails, leaving the lock held.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c715f7ccf7a294c058667b678a4ba50fad933c62",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/63451de16e0a08be40f9ab5e7c5c8f5c79676fb1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64130",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:26.108Z",
      "date_updated": "2026-07-19T15:40:26.108Z",
      "publisher": "Linux",
      "title": "mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06236
      },
      "nvd": {
        "published": "2026-07-19T16:17:54.723",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64130",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The huge zero folio skips clearing allocation tags under init_on_free and exposes stale tag state on its first user mapping.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/738d18f1da3513d17b6f7bf30146cc4ac2480ffd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f2aec5120b93a8f8b52dc50cdc60dbb8aec72f6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6a288a4ddb4a994490505ab5f41c445f8e6b6467",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2156,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64131",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:26.854Z",
      "date_updated": "2026-07-19T15:40:26.854Z",
      "publisher": "Linux",
      "title": "mm/memory: fix spurious warning when unmapping device-private/exclusive pages",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00172,
        "percentile": 0.06878
      },
      "nvd": {
        "published": "2026-07-19T16:17:54.853",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64131",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The unmap path tests whether the VMA is anonymous instead of whether the folio is anonymous, violating the device-private-page invariant and triggering warnings.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e81446b559db4c98a6c2c5e039ac9cb23658432e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e7af1b15c884ed12bb69da11aec095045d861ee8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a825691b804b35141aaf4eac91003a70846e316d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2fff0cdd942261497fb8922a194b4da3315ae864",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/52f72b3f8f6fa64abb71b711962b97f1f6aced1c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be3f38d05cc5a7c3f13e51994c5dd043ab604d28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3998,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64132",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:27.590Z",
      "date_updated": "2026-07-20T13:43:38.348Z",
      "publisher": "Linux",
      "title": "ipv6: ioam: refresh hdr pointer before ioam6_event()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00491,
        "percentile": 0.3952
      },
      "nvd": {
        "published": "2026-07-19T16:17:55.000",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64132",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Reallocating the socket buffer invalidates a saved header pointer, while the code refreshes only the trace pointer before reuse.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/769723124b7c3b2bfea4cf68ad292698b87c8d01",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/24de676da63c1122d2c13b0d546238b66d1b4e62",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5af905aa8e91ff8d94572a1e089558f21dcf24ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e46e6bc97fb1f339730ff1ba74267fbf48e7a422",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1153,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64133",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:28.277Z",
      "date_updated": "2026-07-20T13:43:39.352Z",
      "publisher": "Linux",
      "title": "ALSA: asihpi: Fix potential OOB array access at reading cache",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02973
      },
      "nvd": {
        "published": "2026-07-19T16:17:55.103",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64133",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ALSA find_control indexes its cached control array without validating the supplied index.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e060e21fe9cca1e5eafd8a1c597026577771e8d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/34d0d492a2812b9289af14bca3573a89275965b2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ffa29cea7bf9a4ef2ea8084967f142e0301ac670",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7b6f8c8eb93f02a74b1de8e521c0952af10d1f43",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8778386e4387b28f2bf8425d7ffc667c6294457f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/61c5017c64e2ac9e10b70b14b17a079dbc0a805f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7d107239935793995bdc6cf29bb99e180bde4c28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7b7d6572145c1dab2dd9bfb550b188e5f0ff3c3f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 296,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64134",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:28.974Z",
      "date_updated": "2026-07-20T13:43:40.344Z",
      "publisher": "Linux",
      "title": "ALSA: pcm: Don't setup bogus iov_iter for silencing",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02908
      },
      "nvd": {
        "published": "2026-07-19T16:17:55.227",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64134",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ALSA constructs an iov_iter for a silence path that has no backing user buffer and later dereferences the bogus iterator.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/41a766c647294842c9b17672449f8e011048cba9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ce836587e594af39ff048d9b29dee0f5f10692c9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/feff0251386aa6bb180a0a1cf7c1f91ba868113d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c9f6768515818d71bdfc20119a81f3332c53b9c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e4d3386b74fba8e01280484b67ee481ece00201e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 615,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64135",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:29.676Z",
      "date_updated": "2026-07-19T15:40:29.676Z",
      "publisher": "Linux",
      "title": "hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07403
      },
      "nvd": {
        "published": "2026-07-19T16:17:55.333",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64135",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The ADM1266 driver passes a five-byte stack buffer to a helper that may copy an SMBus block of up to 32 bytes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/33251abb9c9dd62943be76f0427c5527ee39188f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ba09f4baa5bd96c5d26c942defa546a72dbbe5bf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ed16a40b162e9d87d9ac8bed4d7f0e3e807700e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0dbf64c502443c08c2e28a77ecbfcc5479d93228",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2b7a698d5093b548c464828d984f05ced5f3fd2a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ca560f7566df7e2826c2999e959e6b94eb938f76",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7f705e581ef3e6bb308a121a89adf5237d968204",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eee213daa1e1b402eb631bcd1b8c5aa340a6b081",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 978,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64136",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.036Z",
      "date_published": "2026-07-19T15:40:30.351Z",
      "date_updated": "2026-07-20T13:43:41.329Z",
      "publisher": "Linux",
      "title": "smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 17,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00491,
        "percentile": 0.39521
      },
      "nvd": {
        "published": "2026-07-19T16:17:55.463",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64136",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "There was missing lock around tc_count increment inside smb2_find_smb_sess_tcon_unlocked().",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7df1df6f40c0720d30206aa35c0343b962350e0d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/13fb413ae22a37c69341918a6d651d19a9b0b9b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bf4ebdb19ff9b3cdf992b50715fe61633327416a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e374f4e496fef8168784f93a4477d67be34485fd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4d8690dace005a38e6dbde9ecce2da3ad85c7c41",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-64137",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:31.045Z",
      "date_updated": "2026-07-20T13:43:42.369Z",
      "publisher": "Linux",
      "title": "smb: client: require net admin for CIFS SWN netlink",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02967
      },
      "nvd": {
        "published": "2026-07-19T16:17:55.570",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64137",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The CIFS witness netlink command and multicast group omit CAP_NET_ADMIN gates, exposing privileged notifications and session attributes to local users.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9cf7eb8919344932f909b2fac76296f7656fda8d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9919021a3b7974ae66a5f9915e3a48c10cfd409b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/969bc6370334a5b4720c5470783295d6484bbc95",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a3238b09c58f323e40743ce174cd0ab81b5c09ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a8d17d22db591099519a89f14dd24810daba74c3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c2397b93fbb6f44a788fff30f99be2c20cc5e50f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d1ebfce2c1d161186a82e77590bf7da2ea1bce91",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1060,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64138",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:31.760Z",
      "date_updated": "2026-07-20T13:43:43.352Z",
      "publisher": "Linux",
      "title": "ksmbd: validate SID in parent security descriptor during ACL inheritance",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00415,
        "percentile": 0.34159
      },
      "nvd": {
        "published": "2026-07-19T16:17:55.680",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64138",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SMB ACL inheritance path consumes owner and group SID encodings from a parent security descriptor without first validating their structure, while the public record does not state the downstream failure mode.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f0e5c9c663badc9982e6941322eef1cb17de0f11",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/18d8db24b0a5b7be4829238dd4022236df02d421",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1c9d0646a9959752f11ca1080dc1ff26bd1756cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/69f030cf95488ae1186c72ac8c66fd279664ea7f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64139",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:32.459Z",
      "date_updated": "2026-07-19T15:40:32.459Z",
      "publisher": "Linux",
      "title": "ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 11,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.08223
      },
      "nvd": {
        "published": "2026-07-19T16:17:55.780",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64139",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Overflow exits in the ksmbd ACL-building loops bypass the per-iteration SID free, leaking kernel memory on every crafted request.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9d378e17c864da08c3a4df41dae92cfa6468b00a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/519fb0a42ce5d7e46935577309fb282a5f2c6ea3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e198f09cb2a554c04de0fea4e790f1250a943ca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eced48cb08f07393a5ea770fdd1026452883c3ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af92ee994cc7f7e83a41c2025f32257a2f82a7ef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1087,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-64140",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:33.194Z",
      "date_updated": "2026-07-20T13:43:44.317Z",
      "publisher": "Linux",
      "title": "ksmbd: fix null pointer dereference in proc_show_files()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00359,
        "percentile": 0.28599
      },
      "nvd": {
        "published": "2026-07-19T16:17:55.887",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64140",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SESSION_LOGOFF clears a durable file pointer tcon while leaving the pointer globally registered, and proc_show_files later dereferences that null tcon.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8eab081627b67216d1c8f638b68289b500dc9a6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/904901561e61a2b559070b20c74a8c95491f30aa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1223,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64141",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:33.890Z",
      "date_updated": "2026-07-20T13:43:45.317Z",
      "publisher": "Linux",
      "title": "ksmbd: fix null pointer dereference in compare_guid_key()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 13,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36231
      },
      "nvd": {
        "published": "2026-07-19T16:17:55.983",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64141",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Session logoff clears a lease entry's connection pointer but leaves the entry linked for a later lookup that dereferences the null pointer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e43cb36d4d7827710cfcd48e95e29a507f0d87be",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0836081b394ca074d1b910f2b990ff7b4b4404c7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cd5c1b75d2f454f625d7dc55bd3ae21d0855f6ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af86896ca3239e25a6bd7d352213371265073d38",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4b83cbc4c15f09b000cc06f033f64b0824b6dc87",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1827,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-64142",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:34.605Z",
      "date_updated": "2026-07-20T13:43:46.278Z",
      "publisher": "Linux",
      "title": "ksmbd: close durable scavenger races against m_fp_list lookups",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 11,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0048,
        "percentile": 0.38881
      },
      "nvd": {
        "published": "2026-07-19T16:17:56.103",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64142",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent list-head reuse and reference-count updates allow an object to be freed while another path still uses it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3a436932eb397e909d0607d76a8325abd9d85a35",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/95f072ef934ca00711d510676b8792cbf59a5aae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5da69a65b282d2276de22e5194ba0f88c836170c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1f8f3246d55f89350a1a67bdf3744b7241048e4e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bf736184d063da1a552ffeff0481813599a182cc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3998,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-64143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:35.337Z",
      "date_updated": "2026-07-19T15:40:35.337Z",
      "publisher": "Linux",
      "title": "platform/x86: uniwill-laptop: Do not enable the charging limit even when forced",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00162,
        "percentile": 0.05903
      },
      "nvd": {
        "published": "2026-07-19T16:17:56.243",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64143",
        "family": "HARDWARE_PHYSICAL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The force option enables a charging-limit mode on older hardware where that electrical state can permanently damage the battery.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c832a00c9b929b9ad26772833d425f520b2e09cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/26cbe119f99c86dcb4a0136d2bc73c0c716d80e4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:36.041Z",
      "date_updated": "2026-07-19T15:40:36.041Z",
      "publisher": "Linux",
      "title": "Bluetooth: btmtk: fix urb->setup_packet leak in error paths",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00175,
        "percentile": 0.07257
      },
      "nvd": {
        "published": "2026-07-19T16:17:56.347",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64144",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Bluetooth driver fails to free an URB setup_packet when submission fails or the submitted URB is killed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2a1905730e0c771b999906a7b509722f795563c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/68c027c2003b0a8a1439d0301c59c6fd1eb3b844",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a0f5268c77eb73f84ba7c210ddfc54b1c73ff80c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0d2572bafea33c7cd1d77c6a25f25ff31a432482",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dd1dda6b8d6e1f4376a5b3055a04f0ecbdb4d6bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64145",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:36.767Z",
      "date_updated": "2026-07-19T15:40:36.767Z",
      "publisher": "Linux",
      "title": "wifi: wilc1000: fix dma_buffer leak on bus acquire failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06235
      },
      "nvd": {
        "published": "2026-07-19T16:17:56.443",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64145",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The wilc1000 firmware-download error path returns after bus acquisition fails without freeing its previously allocated DMA buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/95c82d498d74c4e587db30021ca1aec90e29b5a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/32d7584441b9ecb279a03653b432612546e5efbe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dd7b6a8671939708cc4b7a46786d8c11297e8f69",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 738,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64146",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:37.474Z",
      "date_updated": "2026-07-19T15:40:37.474Z",
      "publisher": "Linux",
      "title": "erofs: fix metabuf leak in inode xattr initialization",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00162,
        "percentile": 0.05903
      },
      "nvd": {
        "published": "2026-07-19T16:17:56.547",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64146",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "EROFS xattr initialization exits through error paths without dropping the acquired metabuffer folio reference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/492c73b21fefa36f3869cb2b188ffb7fe37b3a9b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/79b09c54c6563df9846ca3094bcfd72082c3e1d7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 695,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64147",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:38.198Z",
      "date_updated": "2026-07-19T15:40:38.198Z",
      "publisher": "Linux",
      "title": "pds_core: fix debugfs_lookup dentry leak and error handling",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 15,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00175,
        "percentile": 0.07257
      },
      "nvd": {
        "published": "2026-07-19T16:17:56.643",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64147",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Firmware-reset recovery drops the referenced dentry returned by debugfs_lookup without dput and also treats an error pointer as a valid dentry.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/60ef1675b652e912f3eb064767af4432393291fd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/26e19622c485e53c3fdb299e822068a0542ddf0c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/91d13e92b983e6c6d7631012c2e20ae8057de9f2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d7f4dd4c8fb380898fef7a77d48fce7ccdb4fc32",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dc416e32baaeb620b9809e9e25fc7b30889686e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 568,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 15
      }
    },
    {
      "cve_id": "CVE-2026-64148",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:38.816Z",
      "date_updated": "2026-07-20T13:43:47.299Z",
      "publisher": "Linux",
      "title": "pds_core: fix error handling in pdsc_devcmd_wait",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00475,
        "percentile": 0.38564
      },
      "nvd": {
        "published": "2026-07-19T16:17:56.753",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64148",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "pdsc_devcmd_wait returns stale success after firmware stops or a command times out because its failure state is skipped or overwritten before recovery.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3231aff8ab26111c54e630b1a200fc43a729dd14",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/10ae3180095bbe2d378c5b1d6f2f2fd74dda3cc2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/784dd2bdc622ed3cc6ef8e113aa1852e252de36f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/560d559324169fe0583d54c475b5329550a86f71",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e46b6635b03d29807f810c3b415c4755a3f958d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 770,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64149",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:39.423Z",
      "date_updated": "2026-07-19T15:40:39.423Z",
      "publisher": "Linux",
      "title": "dma-mapping: move dma_map_resource() sanity check into debug code",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.07003
      },
      "nvd": {
        "published": "2026-07-19T16:17:56.860",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64149",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "dma_map_resource applies a pfn_valid sanity test to device MMIO in normal builds, misclassifying valid resource mappings as RAM.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/181e67bc11c5ec5b87c6c512c2078752b23ca8d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/004a777879ff629f6e0ca3d09ad09fa3452bcc4d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af0c3f05866237f7592219bfe05387bc3bfc99b5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1553,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64150",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:40.027Z",
      "date_updated": "2026-07-20T13:43:48.295Z",
      "publisher": "Linux",
      "title": "netfilter: nft_inner: release local_lock before re-enabling softirqs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00442,
        "percentile": 0.36357
      },
      "nvd": {
        "published": "2026-07-19T16:17:56.970",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64150",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An error path enables bottom halves before releasing the local lock, violating the required lock-state order.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/df19b6af171695a1352314597c9a4311d48d5171",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6fecd39c6401134b58505bc4eb1adc8a0e2fe992",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6cb3ff979855f7f0ee9450a947fe8f96c2ba37a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64151",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:40.643Z",
      "date_updated": "2026-07-20T13:43:49.434Z",
      "publisher": "Linux",
      "title": "iommupt: Check for missing PAGE_SIZE in the pgsize_bitmap",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02048
      },
      "nvd": {
        "published": "2026-07-19T16:17:57.070",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64151",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The IOMMU page-table fast path proceeds even when the driver page-size bitmap omits PAGE_SIZE, violating the path assumption.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/00850f41da24423587abd6124a790dd4f12bcef3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8ef3f77c440005c7f04229a75976bfc078364247",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64152",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.037Z",
      "date_published": "2026-07-19T15:40:41.354Z",
      "date_updated": "2026-07-20T13:43:52.224Z",
      "publisher": "Linux",
      "title": "iommu: Handle unmap error when iommu_debug is enabled",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00108,
        "percentile": 0.01411
      },
      "nvd": {
        "published": "2026-07-19T16:17:57.170",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64152",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The IOMMU map-error path performs debug unmap bookkeeping before a matching debug map state has been established.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0cd028806efc148a75d4acf711d21db335a89661",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0735c54804c709d1b292f3b6947cfb560b2ce552",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 667,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64153",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:42.102Z",
      "date_updated": "2026-07-20T13:43:53.289Z",
      "publisher": "Linux",
      "title": "drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03691
      },
      "nvd": {
        "published": "2026-07-19T16:17:57.270",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64153",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The MSM DRM path stores a signed iommu_map_sgtable error result in the wrong type and treats the changed negative-return contract as a successful mapping length.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3c2cdb7c07f664b77e2a75b50793b845d5742efa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3e3c3c95ef4fe17231a9149e27bcfc9dae2dd89f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7256e54583aee21e23929e7554278c2f5c1a08b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3457807aeb88077712f0a7cb65c3ca5120773d75",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f4e37f3df436c2bdd2621c21f9c72c8f149a221d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3a45af37733446e114bf19b0209fe7d8089bdb8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/55e0f0d1c1a4ee1e46da7da4d443eb3044fb3851",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 483,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64154",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:42.807Z",
      "date_updated": "2026-07-19T15:40:42.807Z",
      "publisher": "Linux",
      "title": "drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06132
      },
      "nvd": {
        "published": "2026-07-19T16:17:57.390",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64154",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "a6xx_gpu_init returns through error paths without releasing the device-node reference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2be24c945e76cd538ce5dd2e50f5d3e7d848c175",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e64bca63647db1d5518198d6c5ca2dbcc66b182b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 519,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64155",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:43.545Z",
      "date_updated": "2026-07-19T15:40:43.545Z",
      "publisher": "Linux",
      "title": "wifi: ath11k: fix error path leaks in some WMI WOW calls",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06967
      },
      "nvd": {
        "published": "2026-07-19T16:17:57.483",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64155",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Two ath11k WOW command error paths return after a failed send without freeing the allocated skb.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d6c7b8d0dc22c0a8743435db8f42d98524b70df3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cd43d587dd333517c806cd24696e6e1a26b9951e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3d675896ea03aca631852a2a7e91e6cb8f664967",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/008955b1348452de25bc19d6e0f0f673d4cb9a3c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/acde4692afcdaea6de3e2996ddfaeaa7ae6b0130",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d618d322b95c80d5ad7091f35a7193e4050dcc27",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/55dda532bbc261aef495e403c8900c5e2ab5fa34",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 308,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64156",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:44.277Z",
      "date_updated": "2026-07-19T15:40:44.277Z",
      "publisher": "Linux",
      "title": "netfs, afs: Fix write skipping in dir/link writepages",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06234
      },
      "nvd": {
        "published": "2026-07-19T16:17:57.603",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64156",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A network-filesystem write path skipped because of lock contention fails to re-mark the inode dirty, losing the pending-write state after VFS cleared it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/77bb293049d61e04c12b24ebbffafaf5ab36af90",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f91e10435c0dd37c48b1b25e6236284f656ddc0c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9871938f99cc6cb266a77265491660e2375271f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 648,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64157",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:44.964Z",
      "date_updated": "2026-07-19T15:40:44.964Z",
      "publisher": "Linux",
      "title": "netfs: Fix partial invalidation of streaming-write folio",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.0642
      },
      "nvd": {
        "published": "2026-07-19T16:17:57.703",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64157",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Partial invalidation advances a streaming-write folio's dirty offset to the start instead of the end of the invalidated region, leaving stale dirty-state boundaries.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f6b2569ae29b666fd15ff2848684c445ba442a39",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3d9601c029b934b5b6a10f99791467b10eb6b211",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6a3d27116be2c5fb9a03d5cf37c486ac517f3689",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6d91acc7fb85d33ea58fca9b964a32a453937f4b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 611,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64158",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:45.692Z",
      "date_updated": "2026-07-20T13:43:54.323Z",
      "publisher": "Linux",
      "title": "netfs: Fix write streaming disablement if fd open O_RDWR",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00085,
        "percentile": 0.00377
      },
      "nvd": {
        "published": "2026-07-19T16:17:57.807",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64158",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "netfs disables write streaming based only on the current descriptor being O_RDWR even though reads can arrive through other descriptors and gaps are already filled on demand.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9adf8e47d73d5e3c2fe77dea649dcde350ccd65c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/616578e40dcba3f94810d841c5a52b7e3bc8ede7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7a9fa5b020a3a40f8291a71cd44c08d931da430d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/70a7b9193bbbfceaab5974de66834c64ccc875dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1075,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64159",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:46.400Z",
      "date_updated": "2026-07-19T15:40:46.400Z",
      "publisher": "Linux",
      "title": "netfs: Fix zeropoint update where i_size > remote_i_size",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.05213
      },
      "nvd": {
        "published": "2026-07-19T16:17:57.913",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64159",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "netfs updates the zero point from the larger local i_size instead of the server's remote_i_size and later treats unwritten remote data as zero.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5cd5207de519ef0c085f4f559adf5eefcb4c5202",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4543a4d737944134a1394afe797622546fbcc98a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1612,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64160",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:47.063Z",
      "date_updated": "2026-07-20T13:43:55.325Z",
      "publisher": "Linux",
      "title": "netfs: Fix potential for tearing in ->remote_i_size and ->zero_point",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00407,
        "percentile": 0.33504
      },
      "nvd": {
        "published": "2026-07-19T16:17:58.010",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64160",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent netfs size reads and writes lack the shared seqcount and inode lock needed to prevent torn remote_i_size and zero_point values.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/55970f238d495517edc961d55c44c772594d0969",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2c8f4742bb76117d735f92a3932d85239b16c494",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 460,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64161",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:47.761Z",
      "date_updated": "2026-07-19T15:40:47.761Z",
      "publisher": "Linux",
      "title": "net: ti: icssm-prueth: fix eth_ports_node leak in probe",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00167,
        "percentile": 0.063
      },
      "nvd": {
        "published": "2026-07-19T16:17:58.113",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64161",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An error return from icssm_prueth_probe omits the matching node release and leaks the eth_ports_node reference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/994358adc0982d17731ffea7dfacd25afcc89773",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ca029dde6ad732a5aba28d6b107d7a84ba5e302b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6635fa84403c3a59455b66007c019a7cc632db30",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64162",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:48.461Z",
      "date_updated": "2026-07-20T13:43:56.296Z",
      "publisher": "Linux",
      "title": "idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27389
      },
      "nvd": {
        "published": "2026-07-19T16:17:58.213",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64162",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The PTP worker can run before read_dev_clk_lock is initialized and then operate on the uninitialized lock.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/eb5991d4c8ba2e8153dfcda3e66a9608377b7dce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3122d70b7c0101d897fb795658a7b93f854935f2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/da4f76b6a84ede14a71282ef841768299ead0221",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2057,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64163",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:49.172Z",
      "date_updated": "2026-07-19T15:40:49.172Z",
      "publisher": "Linux",
      "title": "test_kprobes: clear kprobes between test runs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00164,
        "percentile": 0.06019
      },
      "nvd": {
        "published": "2026-07-19T16:17:58.327",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64163",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Repeated kprobe tests reuse static probe objects without clearing state left by the prior unregister cycle.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/08d355936fcf70c81c94f9fe7310450b65c53399",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/accc0004c501a9918313142282b094d408af06fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1c24cf1fd67f6702c719ab73499392cb7af956ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/96515819d79f356f40da5540968d838ea570fab9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ef5581bb30efb939cc2bf093475c6cc85258e5cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1342,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64164",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:49.894Z",
      "date_updated": "2026-07-19T15:40:49.894Z",
      "publisher": "Linux",
      "title": "btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06085
      },
      "nvd": {
        "published": "2026-07-19T16:17:58.450",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64164",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A Btrfs trace event calls a potentially sleeping dput operation while running in atomic trace context.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d78b0a80eac36879ef5478707135c446920e134b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4361954f0e158af0530caa1e57f12b531be4658f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6279992c9ba2774901c9d4dd4a481162e2534714",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/26b2290baaf6da6add0f782a100766e686a33f4f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/12a0487945c09760a5968d9333383014ea294117",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c32a7e0e3c73c1c0768556a56bd78de9f7b83780",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0a96d9a85cd2240481297156b9bb72e10b7a8036",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c73370c677646e86fc4b1780fb07027bdf847375",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1892,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64165",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:50.585Z",
      "date_updated": "2026-07-19T15:40:50.585Z",
      "publisher": "Linux",
      "title": "ARM: integrator: Fix early initialization",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00172,
        "percentile": 0.0686
      },
      "nvd": {
        "published": "2026-07-19T16:17:58.587",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64165",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ARM Integrator early initialization calls an allocating syscon registration path before memory management is initialized, so the required initialization state cannot be established.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/22c738fb51f2d8b23ddff5cc0ccb2dd685bb39d3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/812103fb6da904bd03d62cf6a9826e537318ceed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6624854554c4c2bdfed3559e5c11bb03b16e7bd1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/508b1193d63b5e073a3fe103eeb785fcba2d368c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/58a112b0973f6cd6bcb8c503d1ff88be411ed0f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e984dc22e2c24dc34d6728e338c82b1ce7862753",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/33ad014abec90f37dade0e00560f28864187e21a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/90d77b30a666049ad24df463f52e5d529c44e8cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1743,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64166",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:51.305Z",
      "date_updated": "2026-07-19T15:40:51.305Z",
      "publisher": "Linux",
      "title": "firmware: arm_ffa: Check for NULL FF-A ID table while driver registration",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06511
      },
      "nvd": {
        "published": "2026-07-19T16:17:58.723",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64166",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The FF-A bus match callback unconditionally dereferences a driver's absent id_table instead of rejecting that driver during registration.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f98f131256beaddd51ad468e95d90d857fef12bf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bc499d1acddbb75b5b4bce05f5296dd8ef9611fd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/adfff93d08a2e12ecf2a1eba272d18bc749f13c0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/34f59211984f66788390e7469f3e99d3796db4a8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/820245d86ce58898fb48b4fefc77d0cafc02801d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/198f6c86d508ed562f07dc00276cac6dbb5dd3bf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0a5e695095c557d2380131b613dea4e8d90371be",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 358,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64167",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:52.023Z",
      "date_updated": "2026-07-19T15:40:52.023Z",
      "publisher": "Linux",
      "title": "kho: skip KHO for crash kernel",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00161,
        "percentile": 0.05767
      },
      "nvd": {
        "published": "2026-07-19T16:17:58.833",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64167",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KHO metadata is added to a crash-kernel image even when its scratch regions lie outside the crash kernel's reserved memory.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a6ac6721326a75ff2d14c68db05f93b576d8762f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6715d7ec472a476db17787697a4abda62962284",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1101,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64168",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:52.741Z",
      "date_updated": "2026-07-19T15:40:52.741Z",
      "publisher": "Linux",
      "title": "spi: sprd: fix error pointer deref after DMA setup failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06116
      },
      "nvd": {
        "published": "2026-07-19T16:17:58.937",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64168",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A DMA setup failure leaves an error-valued pointer reachable by a later release path, causing invalid or repeated cleanup.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/be74e276111f3c23b8e040c8c5e308f67a573add",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a8f233fb0c7be29b97cd249f64120bf35ce72805",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0cdea166c1a07c200caf9d0b722224fca43b23ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/450c319dd04d0eeff4184889768f7ada826a2e35",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b6f1acf4e57ccf708cdc0cb70f5bb5b65162963b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be409d2bbe9ca7da7b05cc7dde7499bc481f0766",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c33b4496e95d04722055446c0a31213639438536",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3d67fffb74267772d461c02c67f1eff893ad547d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 484,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64169",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.038Z",
      "date_published": "2026-07-19T15:40:54.092Z",
      "date_updated": "2026-07-19T15:40:54.092Z",
      "publisher": "Linux",
      "title": "spi: ep93xx: fix error pointer deref after DMA setup failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00156,
        "percentile": 0.05287
      },
      "nvd": {
        "published": "2026-07-19T16:17:59.060",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64169",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The EP93xx SPI fallback leaves DMA channel error pointers installed and later dereferences them during cleanup.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b6c0dabea07e25bd7db19a77ebfd0d02b9e2671a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8e027db9fa310b1d5e7ad928510be800c4f004d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e2189ab095e3657f37b8295f3f2bbcde0f27529",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5e121a81667a83e9a01d62b429e340f5a4a84abc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64170",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:40:54.999Z",
      "date_updated": "2026-07-19T15:40:54.999Z",
      "publisher": "Linux",
      "title": "spi: qup: fix error pointer deref after DMA setup failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06086
      },
      "nvd": {
        "published": "2026-07-19T16:17:59.163",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64170",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The QUP SPI driver falls back after DMA setup failure without clearing the error pointer and later dereferences it as a valid DMA object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0bb3bd442f0bdad3932739a61dd6c580c9c1955e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d577c55d189e7ae150973058d13e299b6855633f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9e673affb92c29d9ba879bf4ea81c5e840166b56",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/45760b72e84c1a1498f1a8a9047184c85299da20",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8f9b61d255b1e989b8913b06c8ebe0aba5e1b238",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4bb4764f2c51f03f657a28029eb0595d8223aab5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4f4051e9d644c371c50de4a042b85bba6727d5c3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a7e8f3efd50a165ba0189f6dc57f7e51a7d149db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 479,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64171",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:40:56.071Z",
      "date_updated": "2026-07-19T15:40:56.071Z",
      "publisher": "Linux",
      "title": "i2c: tegra: fix pm_runtime leak on mutex_lock failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00145,
        "percentile": 0.0428
      },
      "nvd": {
        "published": "2026-07-19T16:17:59.283",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64171",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Tegra I2C mutex-failure path returns without releasing the runtime-power reference acquired immediately beforehand.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8f7ed203b39004c02479a9156089d87d1ac2c1d8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57cf4e8d6a57dc2ef5810f4852a23ba4c71b74bb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 422,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64172",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:40:57.153Z",
      "date_updated": "2026-07-20T13:43:57.277Z",
      "publisher": "Linux",
      "title": "KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03413
      },
      "nvd": {
        "published": "2026-07-19T16:17:59.383",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64172",
        "family": "HARDWARE_PHYSICAL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Hygon Family 18h CPUs are derived from AMD Family 17h (Zen1) silicon and share the same erratum #1235: hardware may read a stale IsRunning=1 bit during ICR write emulation and silently fail to generate an AVIC_IPI_FAILURE_TARGET_NOT_RUNNING VM-Exit on the sending vCPU.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/94ade38f317ea086a181db0e6b69c574b3b70a5e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9560e6fee887a9594a89fa265b5b9c79b1591803",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9a12fa5213cfc391e0eed63902d3be98f0913765",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 823,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64173",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:40:58.251Z",
      "date_updated": "2026-07-19T15:40:58.251Z",
      "publisher": "Linux",
      "title": "tracing: Do not call map->ops->elt_free() if elt_alloc() fails",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06086
      },
      "nvd": {
        "published": "2026-07-19T16:17:59.493",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64173",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The tracing cleanup path calls elt_free() even when the corresponding element allocation never succeeded.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/49332e49ad5b20262cc719b03d4123b9362de701",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b559a218eece132de0c58d444877b5627cbee524",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b427e9f6d81c9341cba23ef92f860f99f830d91d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f383cff9fb382139980bac1bcd3f3f5d59f68435",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1a150947f8480262a46c860f1acb9c6597ca7097",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/798183376d9d3e278a270ea0e75a5769c8f145d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b6723339736320b2e1784258ad4490cec7aac11a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8f0f5c4fb9df0e19a341e0c6ed8dc4fda9124f03",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 309,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64174",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:40:59.360Z",
      "date_updated": "2026-07-19T15:40:59.360Z",
      "publisher": "Linux",
      "title": "wifi: cfg80211: advance loop vars in cfg80211_merge_profile()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00172,
        "percentile": 0.06882
      },
      "nvd": {
        "published": "2026-07-19T16:17:59.617",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64174",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Multi-BSSID merge loop does not advance its element variables, repeatedly copying the same continuation until the buffer or CPU budget is consumed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5817e1e5205498a5df66eba2b34e817f4210fd0f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cedbb608494ba1e7a5c6c56b7f1d3fd470094f28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c0bc4c8bd556cbe036a5b9ed333c0aab9aadfcb8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1ced0f5a851f9cae274545a42a06c459b7fd8881",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/67915715fd3874057457363c87c63e18829527df",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6cfae4914439878b8acb35c7e3b40096eeb2ad9c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1343a480f84b80c1249133a90ef87f8751d65cbb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7666dbb1bacc4ba522b96740cba7283d243d16e1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1114,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64175",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:41:00.157Z",
      "date_updated": "2026-07-20T13:43:58.293Z",
      "publisher": "Linux",
      "title": "wifi: iwlwifi: mld: stop TX during firmware restart",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00349,
        "percentile": 0.27619
      },
      "nvd": {
        "published": "2026-07-19T16:17:59.750",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64175",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The iwlwifi transmit path keeps dequeuing, submitting, failing, and freeing frames after firmware restart begins, creating an unbounded CPU and allocation-churn loop.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/dc31c69476520bb4c2a208211a8d3c310a62c4d0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/13f1786395dbbf3df73337063c798f1266be6151",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2becb38a3e217ef2b2f42fddd7db7a25905ec291",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1393,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64176",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:41:00.830Z",
      "date_updated": "2026-07-20T13:43:59.291Z",
      "publisher": "Linux",
      "title": "wifi: iwlwifi: mvm: fix driver-set TX rates on old devices",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11225
      },
      "nvd": {
        "published": "2026-07-19T16:17:59.853",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64176",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The driver converts old-device TX rates with the wrong rate representation, sending an index where the firmware expects a PLCP value.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6fe92651b44fd3cfc8dcfdaad0e82885c384dada",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6b58a79f2cd98156856eb49e8b55db5facdd7e6d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fb84b5cbcaab3ca0f4e961d92a40ed7f3aac483b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1155,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64177",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:41:01.534Z",
      "date_updated": "2026-07-19T15:41:01.534Z",
      "publisher": "Linux",
      "title": "phonet/pep: disable BH around forwarded sk_receive_skb()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06086
      },
      "nvd": {
        "published": "2026-07-19T16:17:59.977",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64177",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The PEP receive path acquires a child socket lock with bottom halves enabled in process context and disabled in softirq context, permitting self-deadlock.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f08c45076e4fd8b0adbc5eb186d6e6a3e7350d7b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b2606c302d7f2b4ee48da05e32ed60aed1b0cd53",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/02c04df84de709060f63e1d52ec67488c4f6f212",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8420aa4900417797323dd567ba9d1512280c2dc3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bd795f106b3889fb0706c6e4831c4b27e2b5666b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/84bc87beb4cd77670939b446326788e4c9b3db37",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a3fc8f2dacd1c37325977fc1fbbf3d52141df99e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dbc81608e3a653dea6cf403f20cae35468b8ab9c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2801,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64178",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:41:02.293Z",
      "date_updated": "2026-07-20T13:44:00.259Z",
      "publisher": "Linux",
      "title": "Bluetooth: bnep: Fix UAF read of dev->name",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.163
      },
      "nvd": {
        "published": "2026-07-19T16:18:00.147",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64178",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A network device can be freed while another path is still reading its name.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a75bbcb10cb21acc169b785e9804f57d97873a9c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4907596f25b1720fa948371ac5f6c1f8da10a5bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/915a92182e2cda9cd7d2479020a44c6eda986f7c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fe69f634b076ae3ca81c5a5b845d9bba527036f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b21805258d7e926adfd455fc820a447b90da3b82",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5506aec795135cdd4cbf4e845929155663b25055",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e7578529b97e5d4e439cf8f3e637c2303015338f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/59e932ded949fa6f0340bf7c6d7818f962fa4fd2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 616,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64179",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:41:03.019Z",
      "date_updated": "2026-07-19T15:41:03.019Z",
      "publisher": "Linux",
      "title": "net: wwan: iosm: fix potential memory leaks in ipc_imem_init()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00161,
        "percentile": 0.05785
      },
      "nvd": {
        "published": "2026-07-19T16:18:00.277",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64179",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ipc_imem_init omits ipc_protocol_deinit on later error paths and leaks the protocol allocation.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f1a4d57847813fae42fbb7eb35f2dd48b9cff8a9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ba6d8643019c33428f7c0658863e80e0b04a70f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6f63a60580ebdd9a1f22f89a84814d1fefe16b1c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/583fd5a8fc797c8ecf2e1a7b923740c5e5734e85",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ffb6dbb49c96be82f07c7b112e3ebc3e6fdd8dd5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8f764a7810a9f114313c439d25b11f4417c6e0dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c5d93b2c40355e999715262a824965aac025a427",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 336,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64180",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:41:03.751Z",
      "date_updated": "2026-07-19T15:41:03.751Z",
      "publisher": "Linux",
      "title": "mm/memory_hotplug: fix memory block reference leak on remove",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00157,
        "percentile": 0.05333
      },
      "nvd": {
        "published": "2026-07-19T16:18:00.397",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64180",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Memory-block removal acquires a device reference with find_memory_block and never drops it after clearing the altmap.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b8ab30c79fc00147125b9c39f928561d9dd13d06",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/09ce923071e7852ece60d7368e05249bf32c7967",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/df64c0d21c3f85f844b2f656333e43d97e6ffa74",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/93866f55f7e292fe3d47d36c9efe5ee10213a06b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 730,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64181",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:41:04.455Z",
      "date_updated": "2026-07-20T13:44:01.228Z",
      "publisher": "Linux",
      "title": "mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02811
      },
      "nvd": {
        "published": "2026-07-19T16:18:00.493",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64181",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The memory manager treats huge zero mappings as special even on architectures that do not implement the required PMD or PUD special marker.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/62153767e8fc3889bc6508e9ffe927aaf64c4334",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9052ea2ee2233be5d4786b8909151ca2bfbedf99",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c0c6ccd9828c3a1950623b546fa57292a77b5c73",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1471,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64182",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:41:05.186Z",
      "date_updated": "2026-07-19T15:41:05.186Z",
      "publisher": "Linux",
      "title": "drivers/base/memory: fix memory block reference leak in poison accounting",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00157,
        "percentile": 0.05334
      },
      "nvd": {
        "published": "2026-07-19T16:18:00.600",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64182",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The poison-accounting helpers acquire a memory-block device reference on every successful lookup and never release it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/686b4283f82cd630fafd7ca9b03dfc080b3ec8fa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ce60d9452a0f2effa72fd20ea270c59ca691d455",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/24840b3139d7415144b81e4f9f4c44670d15bed9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8502e2c2d0633f99d94d22ae8dabc10caae1fc2a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/03a2cc1756a0570f887d624cd6c535ea0cbd4951",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 483,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:41:05.896Z",
      "date_updated": "2026-07-19T15:41:05.896Z",
      "publisher": "Linux",
      "title": "efi: Allocate runtime workqueue before ACPI init",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00164,
        "percentile": 0.06019
      },
      "nvd": {
        "published": "2026-07-19T16:18:00.703",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64183",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ACPI PRM can invoke the EFI runtime sandbox before the workqueue it requires has been allocated.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/29cd94e678fcb3c4fd0f359deeac6d61334323fc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6996e954ae830f5b793ba6cf449885ca519dbdd2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c32a1fbe0f9a48453a552bb315cc4f1e7a74084e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e871549f7894ad4114b3dd53f241aa25a268ba8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/13c6da02e767152c9ac4330962247a5e47011035",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1026,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:41:06.615Z",
      "date_updated": "2026-07-19T15:41:06.615Z",
      "publisher": "Linux",
      "title": "mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00157,
        "percentile": 0.05334
      },
      "nvd": {
        "published": "2026-07-19T16:18:00.817",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64184",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "damon_sysfs_memcg_path_to_id exits mem_cgroup_iter without its required break operation, retaining a cgroup reference past the iteration lifetime.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/082351f9d40007414ad6af062b3a26fa02fd4b5f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/30a361be33f3793b9ecbd10ab7be6d0564819b79",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/302e02f9ba49f81418ec2a749ae6f5cac1d424e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1bd31386ec3b9ccec10c04429948a306ec5897c0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d4e7b5c4cc353f154d5ab8bb2e1ce7714d77a6e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 376,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64185",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:41:07.340Z",
      "date_updated": "2026-07-19T15:41:07.340Z",
      "publisher": "Linux",
      "title": "sysfs: don't remove existing directory on update failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06444
      },
      "nvd": {
        "published": "2026-07-19T16:18:00.917",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64185",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "sysfs_update_group removes a pre-existing named directory when creation of one updated file fails, turning an update failure into deletion of prior state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c5e125c828b701afaf7493b42a14aa89362ff36d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ccadd32cc1263802a5969c9efe0e96225450428c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/14f2c14ae86c4af17a0a9f8ab46dacf2d5fd1d8a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/31527d80234caf83dc96ad478645e57df9de4472",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57b285e0368290aa55f79ba11419b96d0ebdb418",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/48fa96538bd2868034d33429e4565fda384d0736",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/708f6926f61f71e09b5e9fd668b9882ccd46e69f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/237557b8a81ab948e8332f7c0058e758f081c0a3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 690,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64186",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.039Z",
      "date_published": "2026-07-19T15:41:08.054Z",
      "date_updated": "2026-07-19T15:41:08.054Z",
      "publisher": "Linux",
      "title": "iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.0518
      },
      "nvd": {
        "published": "2026-07-19T16:18:01.037",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64186",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A u32 value converted to int can become negative and later form an out-of-bounds index or length.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/488d2c76bd9f78433a70690d1054bfae3d39a407",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/62f9dfbf1aceae88b03c5ca08f7d36e943939dec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8dfd3d8d74435344ee8dc9237596959c8b2a6cbe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1158,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64187",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.040Z",
      "date_published": "2026-07-20T16:27:46.653Z",
      "date_updated": "2026-07-24T14:34:17.271Z",
      "publisher": "Linux",
      "title": "xfs: fail recovery on a committed log item with no regions",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00161,
        "percentile": 0.05729
      },
      "nvd": {
        "published": "2026-07-20T17:18:21.743",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64187",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "XFS recovery accepts a committed log item with no regions and later dereferences its null ri_buf array through ITEM_TYPE.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5105426424ad6981db827cc1ada835a488fab035",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/226a3c8bea7163c39fe0a1c0ffc7ab7410ef3ba4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d0ae7ec3aa61db5140b107f0a63e017f63e56a96",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d50b1fd066d66ceb548ba43e332cfe8a47e5e55a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d98f22d2e11e0a36493aeb25b2933571ee90d9a4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cccbabeb9a18fcb978d76d6047f2b59214aa7749",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2094dab19d45c487285617b7b68913d0cc0c1211",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1467,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64188",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.040Z",
      "date_published": "2026-07-20T16:27:47.216Z",
      "date_updated": "2026-07-27T04:58:35.734Z",
      "publisher": "Linux",
      "title": "net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01961
      },
      "nvd": {
        "published": "2026-07-20T17:18:21.853",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64188",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "rmnet frees an object immediately after removing it from an RCU-protected structure, before readers have passed a grace period.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c4e676c3505c5058922dc1a6f1ded795f6758135",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9918698cf3aee4032e12bb42fd5a951dc465339b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/310b93246bfec7d4452507e0c15477377ed9f025",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1078ae8175777e80c9637996fb4a46c55f0ce576",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/41e06fcc5df0774d212e70c5b503fc769492bce3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8b17adf6d4fb6bf61fa4c3f58366a7c082799a71",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f193e38cb257d033060b63f1cfd94af076b3a2ab",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d00c953a8f69921f484b629801766da68f27f658",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1644,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64189",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.040Z",
      "date_published": "2026-07-20T16:27:47.767Z",
      "date_updated": "2026-07-27T04:58:47.094Z",
      "publisher": "Linux",
      "title": "netfilter: ipset: fix race between dump and ip_set_list resize",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02277
      },
      "nvd": {
        "published": "2026-07-20T17:18:21.997",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64189",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The ipset dump path reads a resizable array outside an RCU read-side critical section, allowing a concurrent resize to free the array while the dump still indexes it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a7a299277959683204d73333c32c092fd69327d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1bc67c3fc98e9fc07032cc56afcdbc690c47d11e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e8a9976b61f1bc4aa7fd25fa26726dfdf2adf710",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/96fbafc20ebd9a613736c2998b89c539fe3042f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ff86ea9b7fdf70564e60436fbee68c96bc459943",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/81d54c766337b923eec26da0a13406760b091093",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e8ee198bbc04a32d336e79160fde980e0235b39f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7cd9103283b26b917360ec99d7d2f2d761bcf1ab",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1632,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64190",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.040Z",
      "date_published": "2026-07-20T16:27:48.314Z",
      "date_updated": "2026-07-20T16:27:48.314Z",
      "publisher": "Linux",
      "title": "net: team: fix NULL pointer dereference in team_xmit during mode change",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0015,
        "percentile": 0.04718
      },
      "nvd": {
        "published": "2026-07-20T17:18:22.117",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64190",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A mode-change path temporarily clears the team transmit callback while another CPU can call it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/03e9405c518c4d61f28079492f252d6d4e2bac5c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/25fe708bbc59289d3d1ea4b126fbc1b460a072a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1565,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.040Z",
      "date_published": "2026-07-20T16:27:51.120Z",
      "date_updated": "2026-07-27T04:58:48.249Z",
      "publisher": "Linux",
      "title": "i2c: stub: Reject I2C block transfers with invalid length",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.0276
      },
      "nvd": {
        "published": "2026-07-20T17:18:22.217",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64191",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "i2c-stub trusts an ioctl-supplied block length above the 32-byte union capacity and reads or writes beyond the stack object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7e9072dbd5f2f17934751873450d2c22080ead80",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/21e87f336ac6303fed54a69b1d0d79a23b25c8d0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3fd225f3e4cd67ec8ddab1afed9da03c7c43537c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1c4ffe6b4f04365485ed58d64c9bb86b46fc9037",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4bd8635f28c135a08aac6badcd7d9b5cdb34335f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5f4d2bd028ebb6e4c09a9d64842546022321d4a7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0526931b16e5a118d367b7bfce7d797e63f7ac69",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6036b5067a8199ba7a2dc7b377d4b9dd276d5f9e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1892,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T07:54:57.040Z",
      "date_published": "2026-07-20T16:27:51.720Z",
      "date_updated": "2026-08-03T09:32:37.971Z",
      "publisher": "Linux",
      "title": "bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00162,
        "percentile": 0.0587
      },
      "nvd": {
        "published": "2026-07-20T17:18:22.367",
        "lastModified": "2026-08-03T10:16:32.263",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64192",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Linux permits BPF inode-storage maps before the BPF LSM initializes its security-blob offset, so later writes alias and clear an RCU callback pointer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5337eebdf8c5d4810b1913047f078d2815d5645f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/de984ea883405420fdc416ae8964b752df586970",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/267fdd9b6530c399dfd996e1a0a7628b45baf9f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c76b8abce575e0c6e4096957220b4515ed847d89",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6f0643e4f63cfaa0d5d4a69de4f132eac4b8fe4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1674,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64193",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T10:13:00.756Z",
      "date_published": "2026-07-20T17:54:42.087Z",
      "date_updated": "2026-07-21T18:55:09.291Z",
      "publisher": "CPANSec",
      "title": "Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR",
      "affected": {
        "vendors": [
          "NLNETLABS"
        ],
        "products": [
          {
            "vendor": "NLNETLABS",
            "product": "Net::DNS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-95",
          "name": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00828,
        "percentile": 0.53963
      },
      "nvd": {
        "published": "2026-07-20T19:17:30.047",
        "lastModified": "2026-07-21T19:35:17.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64193",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text crosses into an executable or interpreted grammar without the required context separation.",
        "basis": [
          "CNA",
          "CWE-95"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.net-dns.org/blog/#release-candidate-for-netdns-1.56",
          "host": "www.net-dns.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://rt.cpan.org/Ticket/Display.html?id=179945",
          "host": "rt.cpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://metacpan.org/release/NLNETLABS/Net-DNS-1.55_01/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/12",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64194",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T10:13:00.756Z",
      "date_published": "2026-07-20T17:55:05.169Z",
      "date_updated": "2026-07-21T18:56:01.149Z",
      "publisher": "CPANSec",
      "title": "Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains",
      "affected": {
        "vendors": [
          "NLNETLABS"
        ],
        "products": [
          {
            "vendor": "NLNETLABS",
            "product": "Net::DNS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00433,
        "percentile": 0.35621
      },
      "nvd": {
        "published": "2026-07-20T19:17:30.157",
        "lastModified": "2026-07-21T19:35:17.130",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64194",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Net::DNS recursively processes attacker-controlled structure without an effective depth limit, allowing stack exhaustion.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.net-dns.org/blog/#release-candidate-for-netdns-1.56",
          "host": "www.net-dns.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://rt.cpan.org/Ticket/Display.html?id=179946",
          "host": "rt.cpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://metacpan.org/release/NLNETLABS/Net-DNS-1.55_01/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/20/13",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1338,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64205",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.769Z",
      "date_published": "2026-07-20T16:27:53.310Z",
      "date_updated": "2026-08-03T09:32:39.050Z",
      "publisher": "Linux",
      "title": "i2c: i801: fix hardware state machine corruption in error path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0017,
        "percentile": 0.06682
      },
      "nvd": {
        "published": "2026-07-20T17:18:22.487",
        "lastModified": "2026-08-03T10:16:32.430",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64205",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The i801 error path clears hardware ownership and status registers even when its pre-check failed and it never acquired the SMBus controller.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2ef69871b313aa0f02182795f5e0f5aa455f203c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ef5a347532932f58748dad485c15039f5168c377",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bb5133a7d5f3fe5c387770e25f2e00e682ce11ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/00904687b9c5527d569d9a1ca72119823e735a61",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/10dd1a736d557e310a77117832874729a0175d57",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1512,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64206",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.769Z",
      "date_published": "2026-07-20T16:27:53.885Z",
      "date_updated": "2026-07-27T04:58:49.469Z",
      "publisher": "Linux",
      "title": "Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.179
      },
      "nvd": {
        "published": "2026-07-20T17:18:22.620",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64206",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "L2CAP teardown holds conn->lock while synchronously cancelling work whose handler needs the same lock, creating a circular wait.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fc0c3b9cf27cfa2a06f66dae1d08c668fe0a2faa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9901f847a762a5d953871dd95767ce2aed3d684d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4a0bb0fd63fe2b0c62e1072cd1811d6f61e0081c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8daaf7f73fe998631a160d1a5a7e1b0b0480eef8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8de7b386ffad480ca59222b688c94a2da8f0d805",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d5616beb3355b5fca2280d796c1cf7ada4ee6551",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e96fbac8d3a73b0bc165383c092a30628561d320",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2641a9e0a1dd4af2e21995470a21d55dd35e5203",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1123,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64207",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.769Z",
      "date_published": "2026-07-20T16:27:54.447Z",
      "date_updated": "2026-07-20T16:27:54.447Z",
      "publisher": "Linux",
      "title": "net/sched: dualpi2: fix GSO backlog accounting",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.0518
      },
      "nvd": {
        "published": "2026-07-20T17:18:22.733",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64207",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DualPI2 overcounts a segmented packet in its parent queue, leaving qlen nonzero after all real packets are gone and causing QFQ to dereference a null aggregate.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c4b70c1512b8f9f33f23c2c8196dfd1210207681",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/806586e33891066487db1f002be3d455cda6b516",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/05ed733b65ab977dd931e7f7ac0f62fdb81205c2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 888,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64208",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.769Z",
      "date_published": "2026-07-24T15:23:00.113Z",
      "date_updated": "2026-07-27T04:58:50.652Z",
      "publisher": "Linux",
      "title": "crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35519
      },
      "nvd": {
        "published": "2026-07-24T16:16:48.420",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64208",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "RxRPC passes a message to Kerberos decrypt or verify processing without first enforcing that the packet has the required cryptographic length.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/585f9f6aef5c4542ac9d6ec45cd7dbc7df9af3ff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9217017f4bce53dddb8d547837f1f707045d64ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2b50aceafe6606ea52ed42aadd1b4d44a188aade",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 342,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64209",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.769Z",
      "date_published": "2026-07-24T15:23:00.691Z",
      "date_updated": "2026-07-24T15:23:00.691Z",
      "publisher": "Linux",
      "title": "phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.05194
      },
      "nvd": {
        "published": "2026-07-24T16:16:48.523",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64209",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The DisplayPort swing check accepts index four for a four-element array because it uses greater-than instead of greater-than-or-equal.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cb35af6e7f3d5628178b58c631e305b1def8edf7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ea17fc4d7dc2ba6459b1a318962960520201baf1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64210",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.769Z",
      "date_published": "2026-07-24T15:23:01.328Z",
      "date_updated": "2026-07-27T04:58:51.772Z",
      "publisher": "Linux",
      "title": "net/mlx5e: xsk: Fix unlocked writing to ICOSQ",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.2697
      },
      "nvd": {
        "published": "2026-07-24T16:16:48.623",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64210",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "After NAPI affinity changes, two CPUs write and advance the same ICOSQ without a lock.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8d3b91e7d81000d295cd914d4d9d6f860252e2bf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c326f9c68921e2f14dfcecb2f6b4216313d50248",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3126,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64211",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.769Z",
      "date_published": "2026-07-24T15:23:01.889Z",
      "date_updated": "2026-07-24T15:23:01.889Z",
      "publisher": "Linux",
      "title": "srcu: Don't queue workqueue handlers to never-online CPUs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.05194
      },
      "nvd": {
        "published": "2026-07-24T16:16:48.747",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64211",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SRCU queues per-CPU work while switching modes without restricting targets to possible CPUs, allowing callbacks to be assigned to CPUs that can never run them.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a4153538fcd2361c4e0039eb103265492d26044e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/593889c401426004bd0ea0f6d4fcece728b03420",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1126,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64212",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:02.449Z",
      "date_updated": "2026-07-24T15:23:02.449Z",
      "publisher": "Linux",
      "title": "wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.0622
      },
      "nvd": {
        "published": "2026-07-24T16:16:48.843",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64212",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "iwl_mld_remove_link reads link->fw_id before checking whether link is null.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3a74aaad047353da3344aed32e9042d4f334f926",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b6b4db85c7baf0788c5e7ec61350c1ff2bb775e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d733ed481fd20a8e7bfe5119c4e77761ba3f87ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64213",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:02.987Z",
      "date_updated": "2026-07-24T15:23:02.987Z",
      "publisher": "Linux",
      "title": "hwmon: (lm90) Add lock protection to lm90_alert",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06219
      },
      "nvd": {
        "published": "2026-07-24T16:16:48.950",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64213",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The lm90 alert handler updates shared configuration without the lock used by sysfs writers, allowing a concurrent write to re-enable an active alert line.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bed1fc32e0eb653806fa98afcf55f9a311fc4ce2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b0b66aae8a94c3663d47e4000b0e81b89ce32186",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/873e919e3101063a7a75989510ccfc125a4391cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 773,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64214",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:03.529Z",
      "date_updated": "2026-07-24T15:23:03.529Z",
      "publisher": "Linux",
      "title": "powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06943
      },
      "nvd": {
        "published": "2026-07-24T16:16:49.053",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64214",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A redundant preemption-disable operation in the real-mode machine-check path dereferences a preemption counter that is inaccessible in that execution mode.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/51860e423592893cd7bfa7287d99a3aff4dc3a9d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a09d07ac45e283c9861a9ceea06f56d0ba851d22",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/72d8d1c36452a4d3ee134b1da48de7518c1329f9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6dcd072a5ae3aed336e4a67a7d4cc5205b240065",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8079acc5ee5235a627e4586d4f42082a9000ea64",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/31467b23823ffec1f6fff407f8e3ca9af8b7491a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2307,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64215",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:04.085Z",
      "date_updated": "2026-07-24T15:23:04.085Z",
      "publisher": "Linux",
      "title": "drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00156,
        "percentile": 0.05233
      },
      "nvd": {
        "published": "2026-07-24T16:16:49.193",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64215",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "a8xx_hfi_send_perf_table dereferences the result of kzalloc without checking for allocation failure.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/17c993bf44a54afd1fde184ba7f9c287dfc2632e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b5c7a7f452b885bfbe102bd3a057a5f496802f8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64216",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:04.673Z",
      "date_updated": "2026-07-27T04:58:52.969Z",
      "publisher": "Linux",
      "title": "netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00448,
        "percentile": 0.36786
      },
      "nvd": {
        "published": "2026-07-24T16:16:49.310",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64216",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "netfs_unlock_abandoned_read_pages reads folio indexes from a request after another path can release that request.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6080fa3ecfbb4448a3b47368629534c09b6ec750",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3866d015f33aeedf81338dd99154703bef33faef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dbe556972100fabb8e5a1b3d2163831ff07b1e8e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 764,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64217",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:05.261Z",
      "date_updated": "2026-07-27T04:58:54.092Z",
      "publisher": "Linux",
      "title": "netfs: Fix overrun check in netfs_extract_user_iter()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02942
      },
      "nvd": {
        "published": "2026-07-24T16:16:49.417",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64217",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "netfs_extract_user_iter permits iov_iter_extract_pages to write more page pointers than the pages array can hold.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/00efe58bbdcc93272d579ca24bfc912563f4a204",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/96cc3beb2390ba9f9c128c5733c0ccfe450dd4f9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/afeb32d9bf9aaeea51d0f723a19f14afb73bd94d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f48b9157f0f611fa436c360648603d5ded719b12",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0ef37eef83fad3542ee06db2940433ae1a92b39d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 367,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64218",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:05.814Z",
      "date_updated": "2026-07-27T04:58:55.344Z",
      "publisher": "Linux",
      "title": "batman-adv: bla: fix report_work leak on backbone_gw purge",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02992
      },
      "nvd": {
        "published": "2026-07-24T16:16:49.520",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64218",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The backbone-gateway purge can free an entry while its report_work is running or leave a pending work reference uncancelled.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ce2c0ee4d76d5ee4b391fe0e31334361e25030ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3423a45e5c3d3c5129f88143a9a969787d7d5a0a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f1303adb1e59582f76c22798a2e2e150e054a9e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/48663158222b3b7f6ee6791a67d512ede7fc94bb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eeddd7bab3d59c1e98642a204141f8c5d6194707",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c6de1a5a9c406e30b91f1515a6ce05cc84023baa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/95a7034661274cf5985708bd2f6d86ee46f88fa9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0459430add32ea41f3e2ef9351610e6d33627a6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1032,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64219",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:06.379Z",
      "date_updated": "2026-07-27T04:58:56.757Z",
      "publisher": "Linux",
      "title": "drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03374
      },
      "nvd": {
        "published": "2026-07-24T16:16:49.670",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64219",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The display handler copies an unchecked payload length into a 16-byte stack array and indexes dc->links without checking link_count.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d6590e3f766e3111dd1beaf88b9384d117acfa6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/16a5fa57565afb6bf37e18129921c270c93d8e2b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/90c398e822ca76e40548df0c061dd4f93ea92d71",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3265f3ed373fb8048be713aadcdf702579a0e53d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1ecde19bfce6535bffddad1139ff466b6d401b8e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1c8c6e912f2945b2a3e669afca6b52174b88e86e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c92f6d9600efa3ef0d9e560a2b52776d9803c29",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 829,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64220",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:06.931Z",
      "date_updated": "2026-07-24T15:23:06.931Z",
      "publisher": "Linux",
      "title": "device property: set fwnode->secondary to NULL in fwnode_init()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06943
      },
      "nvd": {
        "published": "2026-07-24T16:16:49.797",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64220",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "fwnode_init() leaves the secondary pointer uninitialized, allowing later firmware-node traversal to dereference stale stack or heap contents.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f0e211d6539fae800217c10797993b7592d6ab01",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3f1024deeab3b5443c29b3de4fe475e87309b8fa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/371f53925a6714d0aa35f1aefdffc3e8cd62f480",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/34bf74b1fd2e4a44e27821a329204caf09df2976",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/508fd8ab158abd04b7f7d0f707cd6d6c405df4ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f59e686c778cb41b8f7aa8fab2afd6a01afb3d47",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/215c90ee656114f5e8c32408228d97082f8e0eef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 568,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64221",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:07.502Z",
      "date_updated": "2026-07-27T04:58:59.450Z",
      "publisher": "Linux",
      "title": "spi: ti-qspi: fix use-after-free after DMA setup failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02667
      },
      "nvd": {
        "published": "2026-07-24T16:16:49.923",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64221",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A DMA setup failure releases the channel but leaves its pointer live for later DMA use or a second free.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9c6f306a8140962c7284197db54b96fdb5f468d6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3bbbe7ae3fdada0df4157c1ffe989f92dfa8dcd6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d6f422b122922d1abee907d673bcc990e5f3672d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f2dc841d7dc9063fe9b47ced869b1271e55052ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1cd927002120678bd5d23c760246639caa53040e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d7a076fb596c7b408ed6df74793a597990a6d860",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/178b9b570c0f75fa7e691490520328b20d19138e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ea6ec3343e05f7937a53eb6d7617b3abdb4abc19",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 511,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64222",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:08.072Z",
      "date_updated": "2026-07-27T04:59:00.636Z",
      "publisher": "Linux",
      "title": "octeontx2-pf: avoid double free of pool->stack on AQ init failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02292
      },
      "nvd": {
        "published": "2026-07-24T16:16:50.053",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64222",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An AQ initialization failure frees pool->stack without clearing the pointer, and shared unwind cleanup frees the same allocation again.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e6e9bc0bf963662b7042048ab0281014625d4cb4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b92e7ea408b6f1144648909c9c49a55d245d7300",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/94192b0579333c3deee2441379aab8ca98fc2e6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4c29603498b05c049dbbbc47e882f2fbf0193cd7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0488a0bb344fb1992853b60082acff6be8164d74",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0d9b9d7dbef976ae7f855b6358f1d703014e96ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c4b8c5d51632538b19ee01cf6d70cbceeefbd3ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9b244c242bec48b37e82b89787afd6a4c43457e1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1032,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64223",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:08.629Z",
      "date_updated": "2026-07-27T04:59:02.025Z",
      "publisher": "Linux",
      "title": "wifi: mac80211: consume only present negotiated TTLM maps",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.172
      },
      "nvd": {
        "published": "2026-07-24T16:16:50.197",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64223",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The negotiated TTLM parser advances for absent map entries and later reads a present entry beyond the validated element.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f7d395dc5008168ac5b9c1ac2791e59a6078cca1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2dd9304727c7041df0a599595910bdbe02ad03c5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2becaaeebe230ade1fcd5d0f1cde4d6ee93ec78f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6e6ccd5bd07155c2add6c74ce1a5e68ad3b95ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 991,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64224",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.770Z",
      "date_published": "2026-07-24T15:23:09.209Z",
      "date_updated": "2026-07-24T15:23:09.209Z",
      "publisher": "Linux",
      "title": "octeontx2-pf: fix double free in rvu_rep_rsrc_init()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06277
      },
      "nvd": {
        "published": "2026-07-24T16:16:51.320",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64224",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A hardware-initialization error path releases resources that the caller then releases a second time.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8864b664d0443ecb8e56690e5546fcda5fe5e81b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eb72a65f2bb2cc059e2ca5d83de01fdf3ea602ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e8fb3de2a8effcaf62bec2c56b93d8bb480371d1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1109,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64225",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:23:09.785Z",
      "date_updated": "2026-07-24T15:23:09.785Z",
      "publisher": "Linux",
      "title": "octeontx2-af: CGX: add bounds check to cgx_speed_mbps index",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00176,
        "percentile": 0.07379
      },
      "nvd": {
        "published": "2026-07-24T16:16:51.440",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64225",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A link-speed value can index positions 13 through 15 of a 13-element cgx_speed_mbps array.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/94071141f00bc414e8f8f7f5db3b5143d535299f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/985b5e38ac4f4d5ff03c8bfd8484353b440a1579",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/93d3dc81098cd60fb74d434ba7985ddfd9de5acb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e043017ac429caee73bd30c5a725659f1a3a4568",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8201bf45cc7c1c1a09290c4db8ab1e19801f8fec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/47a4cf2229be379cf88f92e32e1240337cd6273f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2c3d26b4a62454945ba9ef3af3174d3e40e7afef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c0bf0a4f3f1f5f57aa83e1400ba4f56f0abfd542",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 351,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64226",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:23:10.388Z",
      "date_updated": "2026-07-27T04:59:03.180Z",
      "publisher": "Linux",
      "title": "sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02941
      },
      "nvd": {
        "published": "2026-07-24T16:16:51.673",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64226",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "scx_root_enable_workfn drops the last task reference before scx_error reads the task's command and PID.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cf396941901858b0de426cdcd3974eea6a02c98c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/45c7c4e3db8b700307313c035ea08be829a7f21b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57e19ba3f58a67eb924022a5a60b67fd08e5cbbd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9a415cc53711f2238e0f0ca8a6bcc796c003b127",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 395,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64227",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:23:10.936Z",
      "date_updated": "2026-07-27T04:37:25.776Z",
      "publisher": "Linux",
      "title": "ACPI: driver: Check ACPI_COMPANION() against NULL during probe",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06472
      },
      "nvd": {
        "published": "2026-07-24T16:16:51.793",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64227",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A forced platform-driver match can enter probe without an ACPI companion and dereference the absent object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a9451bf561232314755baf69a5916e0ac77f33fc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/34f4d0e4e5065237d15651df759a99e81b7f9f51",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/612ddab8fce04394bd7aebe8e0f2599642e30859",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e4865a56d013e86e46ea6acea15bb6eae01898ff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 681,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64228",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:23:11.510Z",
      "date_updated": "2026-07-24T15:23:11.510Z",
      "publisher": "Linux",
      "title": "net: ethtool: phy: avoid NULL deref when PHY driver is unbound",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.0622
      },
      "nvd": {
        "published": "2026-07-24T16:16:51.913",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64228",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ethtool PHY reply path dereferences phydev->drv after sysfs unbind can clear that pointer while leaving the PHY attached.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3586924625559e6f9876d726c80ff0a75f0d5849",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/17fe2381f967d353183f374a1c0181a6d194158c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e3adf69f8eb121a9128c2b0029efd050d3649153",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 753,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64229",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:23:12.069Z",
      "date_updated": "2026-07-24T15:23:12.069Z",
      "publisher": "Linux",
      "title": "x86/mm: Disable broadcast TLB flush when PCID is disabled",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06278
      },
      "nvd": {
        "published": "2026-07-24T16:16:52.023",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64229",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Booting with nopcid disables PCID but leaves INVLPGB broadcast flushing enabled, violating the feature dependency required for nonzero PCIDs.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fed725cace3ab1c4f7f8182e35029a603d953187",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d2d6d21286719b454d5d87a8758c23d2377d88a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/44126343d58c68adaa8343fbf1c07dd20078c35e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1544,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64230",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:23:12.616Z",
      "date_updated": "2026-07-24T15:23:12.616Z",
      "publisher": "Linux",
      "title": "regulator: tps65219: fix irq_data.rdev not being assigned",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06278
      },
      "nvd": {
        "published": "2026-07-24T16:16:52.140",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64230",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The TPS65219 regulator IRQ path calls the notifier through irq_data.rdev even though the earlier helper removal left that pointer uninitialized.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6827647fd2dcf4e7f355478a42e82f51e0b5344c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b986f88b22a5374191c195c073350bbeb1bb6518",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f9b2d3b703d13df50c630997dfdc25648e96db0d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1250,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64231",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:23:13.175Z",
      "date_updated": "2026-07-24T15:23:13.175Z",
      "publisher": "Linux",
      "title": "drm/msm/dsi: don't dump registers past the mapped region",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06943
      },
      "nvd": {
        "published": "2026-07-24T16:16:52.250",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64231",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The dump size is not reduced by the I/O offset, so the operation accesses an unmapped region past the available buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5e2c196c3430fb94225c4102b1028d0146544761",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/567b5e976e2e15280d78c9ef2add1954a0bbb5b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9f8274749d9010a1a72f97e547b7eb9ebb82345b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a184aec790135938b0fadb415e55accd1f8685a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ab871d5882953e5574ae2bc47bec88c2e3d22663",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5b49a46baa853b26dbefa65c6c75dd9ff69f63d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 868,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64232",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:23:13.729Z",
      "date_updated": "2026-07-27T04:59:04.371Z",
      "publisher": "Linux",
      "title": "block: recompute nr_integrity_segments in blk_insert_cloned_request",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00463,
        "percentile": 0.37809
      },
      "nvd": {
        "published": "2026-07-24T16:16:52.367",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64232",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "blk_insert_cloned_request reuses the top queue's cached integrity-segment count without recomputing it under tighter bottom-queue limits.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/53a01bcc0242590eda4c452a5bd996f62457113b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0943f81e1b3176f27dbaf6db268fc69d8a94f0ba",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/42929c98d044f126508baf54a65b0f87f932fa75",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2c6e6a18a37b905cb584eb0dda3ae482162a81ca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1535,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64233",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:27:39.710Z",
      "date_updated": "2026-07-24T15:27:39.710Z",
      "publisher": "Linux",
      "title": "usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00157,
        "percentile": 0.05315
      },
      "nvd": {
        "published": "2026-07-24T16:16:52.490",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64233",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The UVC extension-unit walk reads shared descriptors without the lock required to keep concurrent mutation from changing the traversal state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e15c414092b3c24610cc771e481a723b0f645eca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2c9e0905ef7e69f7b814cd709613f6b3b5b98805",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/caec0145e5974e85fe5192fc6a6f5aa1a98f82a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5f1b9cff88982e2a2053d8b1fd983f7ccb9f03cc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/68aa70648b625fa684bc0b71bbfd905f4943ca20",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1525,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64234",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:27:40.263Z",
      "date_updated": "2026-07-24T15:27:40.263Z",
      "publisher": "Linux",
      "title": "tty: serial: pch_uart: add check for dma_alloc_coherent()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06117
      },
      "nvd": {
        "published": "2026-07-24T16:16:52.610",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64234",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The pch_uart driver dereferences the result of dma_alloc_coherent without checking whether allocation returned NULL.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/760df81763b391bb5f0dcb0b7597b736da753ae4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5f2e2a240dc1846e049bc67e9c3cdf5b031d08bf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/daea997bb244aeb50cbb2e5e075fb446a6cf068f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6dd5c0ea139b586ad5a091677056dafd405cfe82",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d846df2dfbc2469a688833b4cc4f8aa80672bde8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/66f8bfea055b23719b4fd6ce207c44de37d82a59",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d8d53a343ebe74274ca17b1e1993042e99f8c863",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6fe472c1bbbe238e91141f7cabc1226e96a60d43",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64235",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:27:40.814Z",
      "date_updated": "2026-07-27T04:59:05.504Z",
      "publisher": "Linux",
      "title": "x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25714
      },
      "nvd": {
        "published": "2026-07-24T16:16:52.737",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64235",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Dynamic ftrace trampolines copy a RIP-relative per-CPU instruction without relocating its displacement to the trampoline address.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8093442a2d1d4b42b9340a86023ccb2afb30b93a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d59cc66b702757e3c5a711e78a38583eac0c2738",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9edff632ca216169846f8a63a5a3dc467e239c7a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a17dc12bfed8868e6a86f3b45c16065a70641acb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2654,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64236",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:27:41.371Z",
      "date_updated": "2026-07-24T15:27:41.371Z",
      "publisher": "Linux",
      "title": "i2c: davinci: fix division by zero on missing clock-frequency",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.05166
      },
      "nvd": {
        "published": "2026-07-24T16:16:52.860",
        "lastModified": "2026-07-30T14:59:47.950",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64236",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The fallback I2C frequency is expressed in kilohertz but processed as hertz, truncating it to zero before a divider calculation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3f43865cb64dd7cb50efae1281a95585617b12a1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9b694bc0e1831cbc5c3bbfd1b156ec719128f7d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/030675aa54cf757769b3db65642433d626b3ed7c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 782,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64237",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.771Z",
      "date_published": "2026-07-24T15:27:41.937Z",
      "date_updated": "2026-07-27T04:37:26.944Z",
      "publisher": "Linux",
      "title": "Input: elan_i2c - validate firmware size before use",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06117
      },
      "nvd": {
        "published": "2026-07-24T16:16:52.960",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64237",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The firmware parser trusts an attacker-controlled size when indexing or copying firmware data and can access beyond the supplied image.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/47b52b98edfe34d0249e72f815215ef24311c3a3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c2c3b33b3c0bf2c9427c0926817ef5ffac50de6f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/331d49b4e1c9efe4479bbd22922dfcdd8c64be7b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/48b0aa9c08a3ac8e0c0345b7ca581f552324e460",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3b37190ad3ded3a15fb1dbfc4f26df520a3e59bb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bf769358419e00344c1b16fa034d058f563d46a1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d97baee9590edf303b3eca432e61de9320834fe1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/76b0d0baa9ae9c60e726bbe1b6ff0bec2c993634",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 337,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64238",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.772Z",
      "date_published": "2026-07-24T15:27:42.482Z",
      "date_updated": "2026-07-24T15:27:42.482Z",
      "publisher": "Linux",
      "title": "gpio: shared: fix deadlock on shared proxy's parent removal",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00145,
        "percentile": 0.04269
      },
      "nvd": {
        "published": "2026-07-24T16:16:53.090",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64238",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An overly broad lock is held across an operation that re-enters the same synchronization domain, allowing a reachable deadlock.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a554dfcd30dd5e41d1d67387b3bb85cea83e12e1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a1b836607304f71051f9f9dcccf8b5097b86a1fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 694,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64239",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.772Z",
      "date_published": "2026-07-24T15:27:43.057Z",
      "date_updated": "2026-07-24T15:27:43.057Z",
      "publisher": "Linux",
      "title": "mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00156,
        "percentile": 0.05275
      },
      "nvd": {
        "published": "2026-07-24T16:16:53.193",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64239",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Delayed kobject release leaves a soon-to-be-freed DAMON region on the linked list while refresh can reuse that list.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c0e37017a452addec873865c94cf7a665663a9b2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a5fa42214de55e43d165144727ce9facb9fc6b08",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0ba6c05156d9ff9fc6ca22b7690e2eec9eca66f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2c33177023c92e76806c535ddbffaa3d3fc37777",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/441f92f7d386b85bad16de49db95a307cba048a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1688,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64240",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.772Z",
      "date_published": "2026-07-24T15:27:43.590Z",
      "date_updated": "2026-07-24T15:27:43.590Z",
      "publisher": "Linux",
      "title": "media: rc: igorplugusb: fix control request setup packet",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06117
      },
      "nvd": {
        "published": "2026-07-24T16:16:53.323",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64240",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The USB driver passes the address of a request pointer as the control setup packet, causing pointer bytes to be interpreted as protocol fields.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e823e4294511989f5962e7ad85bf4d179ba74f52",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2243ad78ce64d344754260533ae7730c2174a34a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aa22590a16e51455c6db802c774b31aadc604a9a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/060fca8e098387f949e4eedaf215d952e477ac12",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0d880d2db9856e94127ab09331363bef59f98005",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f33b5a61673bd220fdaaf4202cf1013d6d66c943",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5cc3f6db72f77d1a8f7f1cf4ac01803927ffdf15",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/171022c7d594c133a45f92357a2a91475edabe20",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 787,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64241",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.772Z",
      "date_published": "2026-07-24T15:27:44.144Z",
      "date_updated": "2026-07-24T15:27:44.144Z",
      "publisher": "Linux",
      "title": "gpio: rockchip: teardown bugs and resource leaks",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00156,
        "percentile": 0.05276
      },
      "nvd": {
        "published": "2026-07-24T16:16:53.443",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64241",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Driver removal leaves a chained interrupt handler registered after its owning state is torn down, so a later interrupt can call stale code and panic.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": "The record also describes clock-reference and IRQ-domain leaks; the stale handler is the selected primary safety failure."
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cdc603ce3118232712ba443dd8b414d8f25ca467",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7f945f7f10f442270518dfd768d230227c495fcf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6be81e77e1748665d7ddab9128ff1d35eb75b87d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9500077678230e36d22bf16d2b9539c13e59a801",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1182,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64242",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.772Z",
      "date_published": "2026-07-24T15:27:44.730Z",
      "date_updated": "2026-07-24T15:27:44.730Z",
      "publisher": "Linux",
      "title": "usb: gadget: net2280: Fix double free in probe error path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06118
      },
      "nvd": {
        "published": "2026-07-24T16:16:53.553",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64242",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The probe error path frees an object explicitly after its gadget release callback has already taken ownership of the final free.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/71b3391dc81655ff058492f8e9d013b2c6e5747b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/550fa4d071a8c8e53072900869d37ae6abf4999d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c5b9fdb1e8ddf50bc6272927edb118679f170350",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/085652fda7f38040d1a2c42d72614f418feb843f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/48f89ead20e48d447ad29fa937b43b9fa981cf28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e6f8be12f0307145b9a6010f044925952b37de8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/db2b72e83a0208ae2b3b270bf91662b1c6849a9b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c8547c74988e0b5f4cbb1b895e2a57aae084f070",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 732,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64243",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.772Z",
      "date_published": "2026-07-24T15:27:45.311Z",
      "date_updated": "2026-07-27T04:59:06.667Z",
      "publisher": "Linux",
      "title": "ASoC: codecs: simple-mux: Fix enum control bounds check",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01957
      },
      "nvd": {
        "published": "2026-07-24T16:16:53.680",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64243",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The mux bounds check accepts e->items as an index even though valid zero-based values end at e->items minus one.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6fb653b62f169f6050fac45b56bf21ad097e19f6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d8cc3e747b002a8b965c529de79c0654675b9a1a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5fe860af8630cf7c78523cbd68e5a234743585aa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2ff3ac6f7664fe5639cad01712ac5e021fa7939c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/164dcbec9632ca93ae313e6da6e4e05584fa0f02",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/05ef77f02607a3dc5d7f9762cb990f76843315d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f63ad68e18d774a5d15cd7e405ead63f6b322679",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 575,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64244",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.772Z",
      "date_published": "2026-07-24T15:29:59.891Z",
      "date_updated": "2026-07-24T15:29:59.891Z",
      "publisher": "Linux",
      "title": "drivers/base/memory: set mem->altmap after successful device registration",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00161,
        "percentile": 0.05765
      },
      "nvd": {
        "published": "2026-07-24T16:16:53.803",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64244",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A failed memory-block registration publishes altmap state early enough that cleanup observes an invalid lifecycle state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/802e113cf120df7208e4c7e604950a85e87120a8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/22dc0d042f02ce82aa61422ea5f232628bfd9e9c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c25bf4e44a2b6a14332f952bba0974521f5b72d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bc3dd82a0ffd488bb902f4c69c3d28fd4088d973",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/059ac6252a63edf1cea79bf30bd860a8c264b62c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a2b8d7827f48ee54a686cb80e4a1d0ff954ec42a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64245",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.772Z",
      "date_published": "2026-07-24T15:31:14.142Z",
      "date_updated": "2026-07-27T04:37:28.079Z",
      "publisher": "Linux",
      "title": "fbdev: modedb: fix a possible UAF in fb_find_mode()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0016,
        "percentile": 0.05656
      },
      "nvd": {
        "published": "2026-07-24T16:16:53.917",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64245",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "fb_find_mode frees mode_option_buf while name still aliases that buffer and then continues to compare through name, producing a use-after-free.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c7dc382439f7b019e207055b52e9cec051d42fa9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f906347d75c7fc377041c6d3c535d0f08846aada",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4d418cf8daf57e454b4d855bf9b2419fd8e6a540",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/13b6f0cdd5cd5e60f682ec43134ab0e2024bd356",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/85b6256469cebdac395e7447147e06b2e151014f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 752,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.772Z",
      "date_published": "2026-07-24T15:31:14.709Z",
      "date_updated": "2026-07-24T15:31:14.709Z",
      "publisher": "Linux",
      "title": "power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00161,
        "percentile": 0.05765
      },
      "nvd": {
        "published": "2026-07-24T16:16:54.030",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64246",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "linkstation_poweroff_init releases the device-tree node reference before of_match_node finishes using the node pointer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/93c7ee139721936b6fa717572e74d3994603ae13",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cdda7d384c05485a232ae9a849f6445accb095bf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c04d606f8b35ee7d3ed243f63893a607e9d6c0bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3928ae803dee044b01076c478c279c0bd54164cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2205275be9be981e70ff29610b0117d8853fac70",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d109e72f3fbccb540473285d17d7519584f7f76e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8eec545cde69e46e9a1d2b7d915ce4f5df85b3bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 300,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64247",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.772Z",
      "date_published": "2026-07-24T15:31:15.304Z",
      "date_updated": "2026-07-27T04:59:07.831Z",
      "publisher": "Linux",
      "title": "KVM: x86: hyper-v: Bound the bank index when querying sparse banks",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00114,
        "percentile": 0.01689
      },
      "nvd": {
        "published": "2026-07-24T16:16:54.147",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64247",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KVM uses an unbounded virtual-processor ID to index a fixed sparse-bank set during a nested Hyper-V TLB flush.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d18756b12aab30d07794446445c93112e5c69a2e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/83c2f52c6a78b1590034e955cff3fe0b052fe4ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e36095d8d922bb26ce860231aacf0cd14edea07c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f636cf6a1e7b7f40d48d8d08bd5f152aa61dd130",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4721f8160f17554b003e8928bb61e6c9b2fe92a3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2753,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64248",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.772Z",
      "date_published": "2026-07-24T15:31:15.892Z",
      "date_updated": "2026-07-24T15:31:15.892Z",
      "publisher": "Linux",
      "title": "MIPS: smp: report dying CPU to RCU in stop_this_cpu()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00161,
        "percentile": 0.05765
      },
      "nvd": {
        "published": "2026-07-24T16:16:54.280",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64248",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CPU teardown marks the processor offline for the scheduler without first making it offline to RCU, so a grace period can wait forever.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f8a1ef884013dc99f712d3eb75624c7cd3fd94f6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e1919d026706544cb6e7251ec06e908edd6f34ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6eda71977ee11c222f8ad4cae4d18d50448e56f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f9b57a0015c241274651f4b36627f56b1b5a8651",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9fef09df42df55ab819b285ea892e0fc1b95a9c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9f3f3bdc6d9dac1a5a8262ee7ad0f2ff1527a7e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2064,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64249",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.772Z",
      "date_published": "2026-07-24T15:31:16.458Z",
      "date_updated": "2026-07-24T15:31:16.458Z",
      "publisher": "Linux",
      "title": "fpga: region: fix use-after-free in child_regions_with_firmware()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06118
      },
      "nvd": {
        "published": "2026-07-24T16:16:54.450",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64249",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "child_regions_with_firmware releases child_region before an error message reads from that object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e918942bcc5355ad5b44ba557935dffc0727b0eb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/866184fc7ae42a0070f1141ae8c5dca7c24a59e2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/070b0ce947b18fa3dec0729695147f7e19599649",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fbaf509ad7cb2f7dafe73ca20c956104cfcc9d68",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e79afcb0a66d2b3c33e510eade902537e656fc00",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/369496d885b4cf6e8647cf4dc5cf3ac68fdf37a1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5e098e40e8bac43ed58645c10d5fad781966efe4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/54f3c5643ec523a04b6ec0e7c19eb10f5ebebdd3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64250",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.773Z",
      "date_published": "2026-07-24T15:31:17.021Z",
      "date_updated": "2026-07-24T15:31:17.021Z",
      "publisher": "Linux",
      "title": "LoongArch: Report dying CPU to RCU in stop_this_cpu()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00161,
        "percentile": 0.05764
      },
      "nvd": {
        "published": "2026-07-24T16:16:54.577",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64250",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "LoongArch offlines a CPU without reporting the dying transition to RCU, leaving RCU with stale CPU-liveness state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/262dadc619e69ebeb97affd334cd1078a9704e98",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1fa22de588a65880d6fe54c38c87fffe7d519f60",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a0269e928728f970c782319fee53d92d4ea4e512",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/90e254f18b8c224460082329dd5c42fd30995c2f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0833b2b84c2fc1387f8165f0cbf6a02d67f647a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f2539c56c74691e7a88af6372ba2b48c06ed2fe4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1738,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64251",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.773Z",
      "date_published": "2026-07-24T15:31:17.601Z",
      "date_updated": "2026-07-27T04:59:08.978Z",
      "publisher": "Linux",
      "title": "pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01924
      },
      "nvd": {
        "published": "2026-07-24T16:16:54.713",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64251",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "pwrseq_debugfs_seq_next drops the device reference when its scoped variable exits, then returns the now-unreferenced pointer to seq_file.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ba0b9f04c7a5f9887b8ce672eaf049502c0548ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e91df6d273445c03f5aa302bfe147eda33d45794",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/73569a44fca2992f0ca4a4c0104069741b9873a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/257595adf9dac15ae1edd9d07753fbc576a7583d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1214,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64252",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.773Z",
      "date_published": "2026-07-24T15:31:19.344Z",
      "date_updated": "2026-07-24T15:31:19.344Z",
      "publisher": "Linux",
      "title": "MIPS: DEC: Prevent initial console buffer from landing in XKPHYS",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06117
      },
      "nvd": {
        "published": "2026-07-24T16:16:54.833",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64252",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "In 64-bit configurations calling the initial console output handler from a kernel thread other than the initial one will result in a situation where the stack has been placed in the XKPHYS 64-bit memory segment and consequently so has been the buffer allocated there that is used as the argument corresponding to the `%s' output conversion specifier for the firmware's printf() entry point.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9e22b6fc6532cd566dad6d89d8fb3885248e364a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1c80327dedf05b8c8ca025b76c21235b19dd3a86",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8a15826e5d3bdcfbef2f8e9330c69ea9ee7282e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ab465495b1ed5efb7d2f9b90d8b20b1e0473e26f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/35212f2adc2cf15122b96b987519de235b855e46",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6e61fc2e06e44b6d30248cc5bc47a58e75c2b43e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/07c245bc39f94481fd75ff1ed54f7ab97111f3dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7fb13fd35110ebe95eb053faf79d018f51144d85",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3943,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64253",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.773Z",
      "date_published": "2026-07-24T15:31:21.378Z",
      "date_updated": "2026-07-24T15:31:21.378Z",
      "publisher": "Linux",
      "title": "kernel/fork: clear PF_BLOCK_TS in copy_process()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00157,
        "percentile": 0.05315
      },
      "nvd": {
        "published": "2026-07-24T16:16:55.017",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64253",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "copy_process() inherits PF_BLOCK_TS while clearing the child's plug pointer, violating the flag-to-object lifetime invariant.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ee0801aceabdf583392477baf69a290b09448b8f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/99e6c712cc300883b8cbf03347d5359ec1a4d6dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/77bba61a20f1b3d206f4f90e10a7bb3cd90b9619",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fd38b75c4b43295b10d69772a46d1c74dbd6fc81",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 561,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64254",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.773Z",
      "date_published": "2026-07-24T15:31:22.293Z",
      "date_updated": "2026-07-24T15:31:22.293Z",
      "publisher": "Linux",
      "title": "NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00161,
        "percentile": 0.05695
      },
      "nvd": {
        "published": "2026-07-24T16:16:55.130",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64254",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Teardown unmaps an offset pointer when peer scratchpad and configuration share one BAR, violating the lifetime and base-address contract of pci_iounmap().",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/eb47b9bffd07a47b84910847cb5ea066ce184055",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/06f6dd2ff2bd07eaf7178a807407ff27e85122b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a4be4a1308f02bff79a30eea2d04ead5b63685f2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/81371dbd23601f67f01372817fdbab42c5601e43",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9764a786ba98db58f0725913c369e721253aba33",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d876153680e3d721d385e554def919bce3d18c74",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 992,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64255",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.773Z",
      "date_published": "2026-07-24T15:31:22.870Z",
      "date_updated": "2026-07-27T04:59:10.160Z",
      "publisher": "Linux",
      "title": "wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13415
      },
      "nvd": {
        "published": "2026-07-24T16:16:55.257",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64255",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The BA handlers subtract one from ffs(0), wrapping the station index and accessing fw_id_to_link_sta outside its bounds.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1de92789ce31e46fa7e7d8e89c90b19cdb1c103b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fe7f339f63c9dc4ca546ed7ac38ba4bb3a99dcfc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f056fc2b927448d37eca6b6cacc3d1b0f67b20d2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 536,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64256",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.773Z",
      "date_published": "2026-07-25T08:49:08.676Z",
      "date_updated": "2026-07-25T08:49:08.676Z",
      "publisher": "Linux",
      "title": "xfs: don't wrap around quota ids in dqiterate",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10055
      },
      "nvd": {
        "published": "2026-07-25T10:17:04.630",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64256",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Incrementing an unsigned 32-bit quota ID at its maximum wraps to zero and restarts iteration.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/249e311c2ba392ceaf9ebfc145a46922946f069a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d1c4c40599c376aeb0c93068a2ae344e79ee4b90",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2b14fe1e0924c6b901f4256456342569c5397abe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d766e4e5e85d829629c3ba503802fe1303d7b591",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 372,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64257",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.773Z",
      "date_published": "2026-07-25T08:49:09.345Z",
      "date_updated": "2026-07-27T04:59:11.315Z",
      "publisher": "Linux",
      "title": "smb: client: reject overlapping data areas in SMB2 responses",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 13,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00672,
        "percentile": 0.48525
      },
      "nvd": {
        "published": "2026-07-25T10:17:05.817",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64257",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SMB2 overlap handling clears data_length and lets an overlapping response masquerade as having no data area for a length exception.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/445ece263131780dee273d727a4d6f11934feec7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/36bfa52459e45c0d5b668de2f1c91f6dc5c67775",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4a9d2657d3e05f6ed09c148cb127b4e58702275f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fdafa1e68dc75045b7b617e6e7d2854950804d83",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57cba95f0e97c6f6e45e6731da30aff091bd7460",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8986c932905ea508d66da421eb2eb6e676ace1fe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 597,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-64258",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.773Z",
      "date_published": "2026-07-25T08:49:10.093Z",
      "date_updated": "2026-07-25T08:49:10.093Z",
      "publisher": "Linux",
      "title": "fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09799
      },
      "nvd": {
        "published": "2026-07-25T10:17:05.930",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64258",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A failed ring copy clears the request but leaves its queue entry active for later processing.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0b466cf1b96e191b06b496c4de79da15315c3a9a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0a7f33010c0e4cd92937e088a54350381fd0fbf2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1c57a69be962d459c5e705f5cb4355b841b3461c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 624,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64259",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.773Z",
      "date_published": "2026-07-25T08:49:10.756Z",
      "date_updated": "2026-07-27T04:59:12.431Z",
      "publisher": "Linux",
      "title": "fuse-uring: make a fuse_req on SQE commit only findable after memcpy",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.0535
      },
      "nvd": {
        "published": "2026-07-25T10:17:06.033",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64259",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A FUSE request becomes discoverable before its initialization copy finishes, allowing a concurrent commit to free it during memcpy.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e1711479e9068ea31b31353a702a51e639c3d059",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a635f427d57e2012102ae4886b48d8955c59fb86",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1efd3d474fc0ba74dfd984249bca78807d739812",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 940,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64260",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.774Z",
      "date_published": "2026-07-25T08:49:11.395Z",
      "date_updated": "2026-07-27T04:59:13.568Z",
      "publisher": "Linux",
      "title": "fuse-uring: Avoid queue->stopped races and set/read that value under lock",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05816
      },
      "nvd": {
        "published": "2026-07-25T10:17:06.137",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64260",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "FUSE reads and writes queue->stopped outside the required lock, allowing teardown to free a request while another CPU still processes it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/39c8e925b207afceffaa5382416ed405e0223a03",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4021a3a79eee551d95fe1e1e7c1b195d34ba8c08",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b70a3aca16934c196f92abb17b01c1647b9bb63c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 560,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64261",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.774Z",
      "date_published": "2026-07-25T08:49:11.999Z",
      "date_updated": "2026-07-27T04:59:14.752Z",
      "publisher": "Linux",
      "title": "fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.0535
      },
      "nvd": {
        "published": "2026-07-25T10:17:06.243",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64261",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "fuse_uring_async_stop_queues can run after the final queue reference is dropped because it does not hold a connection lifetime reference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/23a356e0bd96c8d5fb3ddff069f692bf10cab5c1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/95d7f50aff2a5f71557263ff25b97b2951f32bf8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d351da75066955144515cb2f9aa959f24a04287a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 449,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64262",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.774Z",
      "date_published": "2026-07-25T08:49:12.599Z",
      "date_updated": "2026-07-25T08:49:12.599Z",
      "publisher": "Linux",
      "title": "fuse-uring: end fuse_req on io-uring cancel task work",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.098
      },
      "nvd": {
        "published": "2026-07-25T10:17:06.350",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64262",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The fuse-uring cancel path completes the command without ending the owning fuse_req or releasing its queue entry, allowing requests and background capacity to remain stuck.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bb476ef8e1027a9d509fbaaf81f5061a07e9e5a7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4f45f276d5b4412eade6f74f2e37f3adba0473ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bea4fe98204b6ce7eb8e29f7bf867dd7619b3ddd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2004,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64263",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.774Z",
      "date_published": "2026-07-25T08:49:13.217Z",
      "date_updated": "2026-07-25T08:49:13.217Z",
      "publisher": "Linux",
      "title": "fuse-uring: fix moving cancelled entry to ent_in_userspace list",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09804
      },
      "nvd": {
        "published": "2026-07-25T10:17:06.460",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64263",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "fuse-uring cancellation moves an entry with no attached request onto a list whose expiry path unconditionally dereferences that request.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/50f3e03db823cabc41fe35c27d77c2bdb112baad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e8afc85acdf329361b2d8df2ad9b52364686235f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/198f45eeb9f78b2a2d6d8be95e4e43468eb2c6bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 999,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64264",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.774Z",
      "date_published": "2026-07-25T08:49:13.891Z",
      "date_updated": "2026-07-25T08:49:13.891Z",
      "publisher": "Linux",
      "title": "fuse-uring: fix EFAULT clobber in fuse_uring_commit",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09799
      },
      "nvd": {
        "published": "2026-07-25T10:17:06.563",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64264",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "fuse_uring_commit sets -EFAULT after a partial copy but later overwrites it with the positive residual, causing callers to treat uninitialized or partial output as success.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0483fffdeeb363f320e6bf5fc0f0306007507306",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fe604c08d874648a69187f6380e5c7858627dc04",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3a0a8bc51a13951c5141262bf770eeea3e0b6228",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1204,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64265",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.774Z",
      "date_published": "2026-07-25T08:49:14.548Z",
      "date_updated": "2026-07-27T04:59:15.923Z",
      "publisher": "Linux",
      "title": "fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05512
      },
      "nvd": {
        "published": "2026-07-25T10:17:06.667",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64265",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "FUSE moves an interrupted request back to pending without unlinking intr_entry, then can free the request while the interrupt list still holds that entry.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1d8ecd0cd696a5df0b2f72046a4ccee5d2a8ec2c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7366e6f4d2b4c7002b13fb01219e83679dad4127",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/893479015cb6442fd389d3b553ab3036c9541715",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f8fce75fedf73ac72aa09163deb8f4291fdcaad2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1050,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64266",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.775Z",
      "date_published": "2026-07-25T08:49:15.142Z",
      "date_updated": "2026-07-27T04:59:17.096Z",
      "publisher": "Linux",
      "title": "fuse: re-lock request before returning from fuse_ref_folio()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05596
      },
      "nvd": {
        "published": "2026-07-25T10:17:06.783",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64266",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unlocked asynchronous request can be freed before a later copy accesses its arguments.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1f9156714592356b4fda57beac7eab9c2a462dd3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5630da218a45ba80f0aba0846cbe8aa655da122b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1ca605cfa59377f0143fb35b5b01360f37d1b7c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e4a5a000123d81234e27a2f8187688cf608f755",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e6aa539720c3d8def69683ed0c07cf9faea4e8be",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be353caffa8640f5e25fb3714ce8b0cef5e410e5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/65a1c2551f7e16085acbb54aedde1feaa559ba7a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b5befa80fdbe287a98480effed9564712924add5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64267",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.775Z",
      "date_published": "2026-07-25T08:49:15.720Z",
      "date_updated": "2026-07-25T08:49:15.720Z",
      "publisher": "Linux",
      "title": "fuse: avoid 32-bit prune notification count wrap",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09801
      },
      "nvd": {
        "published": "2026-07-25T10:17:06.910",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64267",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "FUSE_NOTIFY_PRUNE multiplies an attacker-controlled count in 32-bit size_t, allowing wraparound to validate a payload shorter than the ensuing copy loop expects.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6e2d84fdeac05bfd858e84a76353fdb84f23a43e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c78c4b242299bc581e4987e5c2786c6f4760c516",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/54243797cedf55447b4c5d560e8cd709900061ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 776,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64268",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.775Z",
      "date_published": "2026-07-25T08:49:16.336Z",
      "date_updated": "2026-07-27T04:59:18.262Z",
      "publisher": "Linux",
      "title": "RDMA/siw: bound Read Response placement to the RREAD length",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00695,
        "percentile": 0.4943
      },
      "nvd": {
        "published": "2026-07-25T10:17:07.013",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64268",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "siw_proc_rresp accumulates continuation-segment lengths without comparing the total to the RREAD sink buffer before placement.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a31b6d18ded3cc32d9ee85a6ff0726d4274887b2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/595e6537ad1a210da32cbb9a7f91aa73090915ba",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3ef7e052cbd05a8b13a51a07b185a39ec93ee1cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b2e26c955f8dd7e8d3f16c858db05245ea4fa817",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6bc89f34a4597f9f6d41f7a60c67a3153bfe8851",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/423a78ff7928c2601013f73ec6d896f5597d0df5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/75c93cd3c421890f49ea93f0b978b9b7bb10e5e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7d29f7e9dbd844cae4d3e559cf78324b9642fd6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1667,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64269",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.775Z",
      "date_published": "2026-07-25T08:49:16.946Z",
      "date_updated": "2026-07-27T04:59:19.367Z",
      "publisher": "Linux",
      "title": "RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00679,
        "percentile": 0.48821
      },
      "nvd": {
        "published": "2026-07-25T10:17:07.160",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64269",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "RTRS uses a peer-controlled descriptor length for an RDMA write from a fixed chunk without bounding that length to max_chunk_size, permitting a read beyond the mapped chunk.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/68c09762172f6224e9ddf9b0a60bacbb36e443eb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6cada540150894e81042a0ae0c796a21a9a877da",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2912f3d40355dabc08fdbaaf2764d02445fe88dc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6f40246f4312fdbab5a13cc440adebf95eb2aa66",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5a45d0aa1fa50a333ce5763ade744e2d89838667",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/da3e44add94b05dfde56f898421922f5cf35705f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/963af8d97a8c6a117134a8d0db1415e0489200b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1872,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64270",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.775Z",
      "date_published": "2026-07-25T08:49:17.541Z",
      "date_updated": "2026-07-25T08:49:17.541Z",
      "publisher": "Linux",
      "title": "Input: mms114 - reject an oversized device packet size",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10055
      },
      "nvd": {
        "published": "2026-07-25T10:17:07.293",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64270",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The touchscreen driver trusts a device-reported packet length up to 255 bytes when writing into an 80-byte stack array.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5d2ea15ba03bf17ed143ff1a0995a4206edc3fb6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b78150729762d47c14fe29a2582bdca5568e62b8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8301c335305344d4da4ab9442b6a399dacfe5b8d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f3d5e77b27fded71dcb97f409262bf0abba0410e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/66725039f7090afe14c31bd259e2059a68f04023",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1306,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64271",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.775Z",
      "date_published": "2026-07-25T08:49:18.160Z",
      "date_updated": "2026-07-25T08:49:18.160Z",
      "publisher": "Linux",
      "title": "Input: touchwin - reset the packet index on every complete packet",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11393
      },
      "nvd": {
        "published": "2026-07-25T10:17:07.410",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64271",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "touchwin resets its three-byte packet index only when two device-controlled bytes match, so mismatched packets make subsequent bytes overwrite the heap object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ed9b66905407eb3d02df1aaeed82eb7a7f0eb508",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/044167cba2384bcd783547ad5e30ecd292b30919",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c9f29f128dd4057404838259af4c645318487e1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/431ad239f2924dff337c3fccb9246597c1b63185",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/70e4248793762df9832fd4fc2fc6ac7924572c36",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3e6f007b43e2fc6546e21fa74ee62c38984a6672",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a8d87184576c889759e3aab899799a482f1e1a5b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/478cdd736f2ce3114f90e775d7358136d3977b94",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1089,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64272",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.775Z",
      "date_published": "2026-07-25T08:49:18.766Z",
      "date_updated": "2026-07-25T08:49:18.766Z",
      "publisher": "Linux",
      "title": "Input: mms114 - fix touch indexing for MMS134S and MMS136",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10056
      },
      "nvd": {
        "published": "2026-07-25T10:17:07.550",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64272",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A touch-input driver advances through records with a structure stride that does not match the actual record layout, causing out-of-bounds access.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/112666835071d935fef764aab590339e97216d4a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7c00a0787af7164438bdbc97fcae9733cfc58d21",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/75b12874b4172533b9efc349db328cb1a59c3981",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a747c4eb02656afdbd92eea83b88e92715a23977",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6ac4e24c1a8a533bb61035184fdcc7eede4cc8d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 747,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64273",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.776Z",
      "date_published": "2026-07-25T08:49:19.416Z",
      "date_updated": "2026-07-25T08:49:19.416Z",
      "publisher": "Linux",
      "title": "Input: iforce - bound the device-reported force-feedback effect index",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11389
      },
      "nvd": {
        "published": "2026-07-25T10:17:07.660",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64273",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A device-supplied force-feedback effect index is used for a bit read-modify-write without checking it against the core_effects array dimension.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b1b79e89bc33e4c682d3df7ae2aadc62b5a0c310",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d10b0507fa0f5b46764b178e3271f9012f2df677",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c0f2901c9d325d4a0574c4237fd507810d225ff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c21295616a8a52b9a5f18cd4ca8c73030eda3d4f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e5fa31f0550b55d80045669ae9080dd5b88abffa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/70019779325f2bb5f5a4098e91e79c655f50fcef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a40250f97c312e000e3616c9074022311a0efbc3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e9943d2e4c63496b6ca84bc66fd3c71d40558e2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1726,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64274",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.776Z",
      "date_published": "2026-07-25T08:49:20.040Z",
      "date_updated": "2026-07-25T08:49:20.040Z",
      "publisher": "Linux",
      "title": "Input: goodix - clamp the device-reported contact count",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.1139
      },
      "nvd": {
        "published": "2026-07-25T10:17:07.797",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64274",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Goodix driver accepts a device-advertised contact count up to 15 while its stack buffer is sized for only 10 contacts.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e825f352ef5271255cd08cc994b0dc25648a2f38",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4bfea9c3a0981c1c7fc5d1a1b27197b2de247902",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/98b2caef249183b572c04451365246f919707845",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/719d1a2c83a46be6bf81af905e4f6adb3d32dc28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/46addbd13dbf4aacb71cfbca964a5e552d0f45ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3b32303460155603d25444274856013d211d5e1f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2a67668690129953e898923260a2dd1c7c196495",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5ed62a96e06be4e94b8296b7932afee550a70e04",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1210,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64275",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.776Z",
      "date_published": "2026-07-25T08:49:20.669Z",
      "date_updated": "2026-07-25T08:49:20.669Z",
      "publisher": "Linux",
      "title": "Input: elan_i2c - prevent division by zero and arithmetic underflow",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.1139
      },
      "nvd": {
        "published": "2026-07-25T10:17:07.927",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64275",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Zero trace counts reach a resolution division and small widths reach unsigned subtraction without zero or lower-bound checks.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/59d4cc5e7a9785e4bdc9c55273274c6b49d4b58d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f6d10af2036d1d4a847a74fe47ebbf93bce3c84c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f281ff0163a38fdc4cb4061f0c241e643283a5e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8c1db3418a419e788691746b9c47f863c2fd4890",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/feb4866a42ec94764c7eb58012256f6f37664727",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/01e0317c256c560d8dcce2e9825eb6142ee34611",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6bac57d8fe2a077b8a85b4140eeb7999078158eb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/df2b818fa009c10ff6ba875a1663ff001cda9558",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1186,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64276",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.776Z",
      "date_published": "2026-07-25T08:49:21.300Z",
      "date_updated": "2026-07-27T04:59:20.488Z",
      "publisher": "Linux",
      "title": "Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06041
      },
      "nvd": {
        "published": "2026-07-25T10:17:08.060",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64276",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Synaptics driver allocates at most six keymap entries but indexes up to the device-reported count of thirty-one.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8c6d18d61bb6fe0e6edf848413391c590552e8a9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d162a1ead7de404d8b41a093c83ed0db6487cded",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f0be9eba946e9200b43265e0a748d38bd0a56954",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/26c895928d7118436a24f564587cb4aefc40cdd8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4e3689c26854356f41fbaa1eafa382e58ac79e00",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e849c6f51e6877104c765da084e001ec37c8e119",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bfe622efecd4ff0a792d0ecd1a8dce535a902f50",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d577e46785d45484b2ab7e7309c49b18764bf56c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 964,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64277",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.776Z",
      "date_published": "2026-07-25T08:49:21.936Z",
      "date_updated": "2026-07-27T04:59:21.704Z",
      "publisher": "Linux",
      "title": "Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06041
      },
      "nvd": {
        "published": "2026-07-25T10:17:08.197",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64277",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The F3A device-reported GPIO count can exceed the six-entry keymap allocation while interrupt and ioctl paths index the full reported count.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/502ad7caaa1a445b734c827fa256e5311df67e3d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3480e24bc4e178aaa009edb25b6ee12df199e210",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/35ed74d32d8260bdfb14a94caf402bf0866bdeec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ba57f430328534501962d60d651e385ffd7af9ca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/850117b637bcb1dcc14be0cf09ac819a8707b42c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8db211aed83733073b0814adaeeab61d4521474e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/64fb0e1161ccc6b9e48b8df61f07d3c34c01ec42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57c10915f2c16c90e0d46ad00876bf39ece40fc2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1311,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64278",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.776Z",
      "date_published": "2026-07-25T08:49:22.535Z",
      "date_updated": "2026-07-25T08:49:22.535Z",
      "publisher": "Linux",
      "title": "i2c: imx-lpi2c: mark I2C adapter when hardware is powered down",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09804
      },
      "nvd": {
        "published": "2026-07-25T10:17:08.330",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64278",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A periodic I2C worker can issue transfers after suspend has powered down controller resources and before resume restores them.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b2523f26979e0b5bd1422772176b2233fcd1f6d0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5800647d19d3f1f747fda4dc67e55d6afa6ee119",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/218cfe364b55b2768221629bd4a69ad190b7fbbc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 891,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64279",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.777Z",
      "date_published": "2026-07-25T08:49:23.145Z",
      "date_updated": "2026-07-27T04:59:23.086Z",
      "publisher": "Linux",
      "title": "i2c: core: fix adapter deregistration race",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06038
      },
      "nvd": {
        "published": "2026-07-25T10:17:08.437",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64279",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Adapter deregistration leaves the object discoverable by ID while its resources are being freed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d39282f552dd6c35b9b84b4af78f1198c24f3373",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/11dfa37bf544cc806f21742ca2fd2d841bd7032e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9882a9bd74db08e7bae5821a7050627ae92d3380",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bb234487a447a99315add1b46aa57b72e163e1eb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b6d2af6fe9c1f5ec0484536753c979cbd40a8ac3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/35dbd1f1f603401155cbd3a180bb18e3a3b675b8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b1a58ed9eab146b36f41a55db8f5d7ce9fdedf3f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 429,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64280",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.777Z",
      "date_published": "2026-07-25T08:49:23.753Z",
      "date_updated": "2026-08-03T09:32:40.118Z",
      "publisher": "Linux",
      "title": "fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00163,
        "percentile": 0.05978
      },
      "nvd": {
        "published": "2026-07-25T10:17:08.553",
        "lastModified": "2026-08-03T10:16:32.577",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64280",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A 64-bit user-supplied DMA length is converted to an int page count without rejecting values above INT_MAX.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/16381bda90b261a656ded0568630c1b857b2ebc8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b50e6cd2395cde615f59b624819998d28c0668d6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/59070040fd12e0b78d7b4d341d9f9a183237c5ff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fb2c0eab51ae5b02d2bae7d67c2cfbec39b57231",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 597,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64281",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.777Z",
      "date_published": "2026-07-25T08:49:24.399Z",
      "date_updated": "2026-07-27T04:59:25.308Z",
      "publisher": "Linux",
      "title": "svcrdma: wake sq waiters when the transport closes",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00468,
        "percentile": 0.38064
      },
      "nvd": {
        "published": "2026-07-25T10:17:08.667",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64281",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The svcrdma close path marks the transport closed without waking send-queue waiters, leaving threads blocked indefinitely and pinning transport references during teardown.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/40eedc4253dbda0b29b7961200534dfcecb48ace",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e5248a7426030db1e126363f72afdb3b71339a5c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2145,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64282",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.777Z",
      "date_published": "2026-07-25T08:49:25.011Z",
      "date_updated": "2026-07-25T08:49:25.011Z",
      "publisher": "Linux",
      "title": "KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09804
      },
      "nvd": {
        "published": "2026-07-25T10:17:08.787",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64282",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "kvm_translate_vncr returns after an MMU-notifier race without releasing its reference to the faulted-in page frame.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0c93681aea0a1b8be14730a88abe77c840272e41",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cd1067ccc0dbc18890a74db116d00a4bc3c7f2f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9f76b039a72d7e06374aa96862f0232ed53f7787",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 348,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64283",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.777Z",
      "date_published": "2026-07-25T08:49:25.642Z",
      "date_updated": "2026-07-25T08:49:25.642Z",
      "publisher": "Linux",
      "title": "KVM: guest_memfd: Treat memslot binding offset+size as unsigned values",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0021,
        "percentile": 0.11358
      },
      "nvd": {
        "published": "2026-07-25T10:17:08.910",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64283",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KVM adds guest_memfd offset and size as signed values, allowing a large positive sum to become negative and pass the file-size bound.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f3a98d5881b9bd4807f49156143565f6aabcef1e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eba85fee7fc6cf28fec38a5bf3c378bef9a79ca6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2381,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64284",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.777Z",
      "date_published": "2026-07-25T08:49:26.270Z",
      "date_updated": "2026-07-27T04:59:26.374Z",
      "publisher": "Linux",
      "title": "KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05571
      },
      "nvd": {
        "published": "2026-07-25T10:17:09.033",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64284",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A virtualization fast path returns to user space before the vendor exit handler flushes dirty-state and page-modification-log updates.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b3436d9b9b1affe1c3191ac9831308923f5f03c3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4ad73ef0e7966ecfe67de0060537b4cb14d9acd4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f2ca2b5326211bd38490f0497eb583721ce0bbc0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0ffedf43910e44b76c2c1db4e9fbf12b268190c1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 699,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64285",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.777Z",
      "date_published": "2026-07-25T08:49:26.898Z",
      "date_updated": "2026-07-25T08:49:26.898Z",
      "publisher": "Linux",
      "title": "KVM: SEV: Pin source page for write when adding CPUID data for SNP guest",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00189,
        "percentile": 0.08822
      },
      "nvd": {
        "published": "2026-07-25T10:17:09.140",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64285",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KVM pins a source page as read-only even though rejected SNP CPUID data can be written back through a kernel mapping.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/dcdb476f5fc5701ec06c23efe3e3529f07ca391e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f13e900599089b10113ceb36013423f0837c6792",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 784,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64286",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:27.542Z",
      "date_updated": "2026-07-27T04:59:27.373Z",
      "publisher": "Linux",
      "title": "KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06679
      },
      "nvd": {
        "published": "2026-07-25T10:17:09.243",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64286",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KVM arm64 leaves __hyp_running_vcpu pointing at a stale private vCPU while flushing and copying host vCPU context.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/477145860dba4c30f0b4e36f02f4c5291c1c888b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dfaef40d8a1533940fc1af788d70fce07362b4ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6bea2f8becdb20d34378493c3b77a9b9cf8c6cfa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d4f4d61715d1061ba83b88196a3605662be30750",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e8042f6e1d7befb2fb6b10a75918642bcd0acf9a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 621,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64287",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:28.168Z",
      "date_updated": "2026-07-27T04:59:28.711Z",
      "publisher": "Linux",
      "title": "KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0017,
        "percentile": 0.06679
      },
      "nvd": {
        "published": "2026-07-25T10:17:09.353",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64287",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The pKVM flush path copies host-controlled used_lrs without clamping it before indexing the EL2 list-register array.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2c5e72b9fbf83fdfa724e9f1af0f418ccf8739b8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9fa301d8298778dd799fa4dcf7a7f440715d146e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c646431865f4b1a5b14067233fa27b11e05e0d46",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7fca3fcef81c713bc82a37bf741e0f28e6d04a6f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8cc8bbbfab14c22c5551d0dd19b208a44b141c76",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 888,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64288",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:28.789Z",
      "date_updated": "2026-07-25T08:49:28.789Z",
      "publisher": "Linux",
      "title": "KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09803
      },
      "nvd": {
        "published": "2026-07-25T10:17:09.473",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64288",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "VNCR TLB invalidation occurs from MMU notifiers or TLBI instructions, and either can race against a vcpu not being onlined yet (no pseudo-TLB allocated).",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7c73a269a880b1399baacfb9d521415e6ef7ecc2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5fd30133af864a1de0a0bd87d3fe3cf23205fbc7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4be6cbeb93d26994bd1827ddbce391e3c4395c8f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 733,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64289",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:29.434Z",
      "date_updated": "2026-07-25T08:49:29.434Z",
      "publisher": "Linux",
      "title": "iommufd: Set upper bounds on cache invalidation entry_num and entry_len",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10056
      },
      "nvd": {
        "published": "2026-07-25T10:17:09.603",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64289",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The cache-invalidation ioctl accepts multi-gigabyte entry lengths and huge entry counts that drive uninterruptible scans and non-preemptible loops.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d2bd041e0efaf7d81789779b135279d18b33d6d5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/32ca4aed2a66205b072fcfecabe220289a8149ff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2c6381d90898089287e0a358f06f89f6b4b389f2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4d70986002f2f3eaaed89124fb2522bded38b016",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 926,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64290",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:30.049Z",
      "date_updated": "2026-08-03T09:32:41.191Z",
      "publisher": "Linux",
      "title": "iommufd: Break the loop on failure in iommufd_fault_fops_read()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10056
      },
      "nvd": {
        "published": "2026-07-25T10:17:09.730",
        "lastModified": "2026-08-03T10:16:32.710",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64290",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "After copy_to_user() fails, only the inner fault-list loop exits and the outer loop retries the same restored fault forever while holding the mutex.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a38e0714affc5c0bbb40cba5a65d6d32a5e72a71",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5539da127d03c1f6c2e2a49fdfbe331a0ccbdea8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f66c16b175509642ee7082df57c9bf3deaebae1a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/172fc8b19825a0f5884c38f2289188284e2d45ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 454,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64291",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:30.686Z",
      "date_updated": "2026-07-25T08:49:30.686Z",
      "publisher": "Linux",
      "title": "iommufd: Set veventq_depth upper bound",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09802
      },
      "nvd": {
        "published": "2026-07-25T10:17:09.837",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64291",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "iommufd accepts an almost U32-sized userspace queue depth without a practical upper bound, allowing excessive kernel-memory allocation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f565297edf316016be4a1a9e2eb9f39359313f43",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e7b5e55652746b1221b9c10ff80eae8a154101ba",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ebf2eb46fbd5b40393ff8fbb847ba96925beaff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 478,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64292",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:31.325Z",
      "date_updated": "2026-07-25T08:49:31.325Z",
      "publisher": "Linux",
      "title": "iommufd: Move vevent memory allocation outside spinlock",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09801
      },
      "nvd": {
        "published": "2026-07-25T10:17:09.937",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64292",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "iommufd allocates a user-sized event queue while holding a spinlock with atomic-reserve semantics, allowing large queues to exhaust atomic memory reserves.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/779480ea79551c31964e74b9aef0e730faa3aa11",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c5fc40200cd0a87d66a368eee00df4d1cca946e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/47443565d10c51366c9382dbc8597cd6c460b8a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 968,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64293",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:31.945Z",
      "date_updated": "2026-07-27T04:59:30.042Z",
      "publisher": "Linux",
      "title": "iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05816
      },
      "nvd": {
        "published": "2026-07-25T10:17:10.047",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64293",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A vEVENT read bound uses the pointer size instead of the header size and can copy beyond a 32-bit caller's supplied buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/04a177f91160ee18da98f5689482cf0f589ec869",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0cdbb97a4dbd69abdd2ab998b4fbc7803d4b0b72",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be93d186ae88a92e7aa77e122d4e661fa57b1e39",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1485,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64294",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:32.570Z",
      "date_updated": "2026-07-25T08:49:32.570Z",
      "publisher": "Linux",
      "title": "mm: do file ownership checks with the proper mount idmap",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10056
      },
      "nvd": {
        "published": "2026-07-25T10:17:10.160",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64294",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An ownership check uses the nop idmap instead of the mount idmap and therefore evaluates the wrong identity mapping.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/744b23aa430d52f5c8e4dbff7d71496d6643bed2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8344bdf0629457e532797b42d9d2bbf2a2900bbf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5c942ad7df75925ee166e7f0fb36892d8dde376b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/04ba248d02d9eaa3d9077b00a6134caa75fa3e90",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e187bc02f8fa4226d62814592cf064ee4557c470",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1199,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64295",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:33.194Z",
      "date_updated": "2026-07-25T08:49:33.194Z",
      "publisher": "Linux",
      "title": "mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00203,
        "percentile": 0.10472
      },
      "nvd": {
        "published": "2026-07-25T10:17:10.277",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64295",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "page_ext iteration advances one PFN past its requested count and dereferences an uninitialized memory section.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8dcaa0f87a88d720d13106f3a306c6b61d189d86",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/377b1cd6bbcf327338cd951cc2fd74bc75540235",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ffd017237cfe99e6e5602ab14179b0e6878a0840",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1860,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64296",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:33.847Z",
      "date_updated": "2026-07-27T04:59:31.233Z",
      "publisher": "Linux",
      "title": "exfat: bound uniname advance in exfat_find_dir_entry()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.0604
      },
      "nvd": {
        "published": "2026-07-25T10:17:10.390",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64296",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "exfat_find_dir_entry advances its output pointer by fixed filename slots while its guard counts shorter extracted fragments, allowing the pointer to pass the output buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/72a2589d82eb001c94b74bcfe6f9a599bd9bef60",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fae76a94b35ee8c0e2eb6f64caca01d75c6d34e4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cf85180b8a015029ee147694eaf4e0b3537e9432",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ce4736c1e6c4cfbf1ac409a8c328a0b69546c9a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/727bf7783a2936ffd55c628dddfd69343e511dcf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/33c0b96d7e1672be1de0053786637ea46fb81507",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c8e041c68c0bbb73aa62371ee63947bb6949d8b2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3a1230e7b043c62737b05a3e9275ca83a43ad20a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1418,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64297",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:34.486Z",
      "date_updated": "2026-07-25T08:49:34.486Z",
      "publisher": "Linux",
      "title": "module: decompress: check return value of module_extend_max_pages()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00206,
        "percentile": 0.10771
      },
      "nvd": {
        "published": "2026-07-25T10:17:10.530",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64297",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Module decompression ignores a failed page-array expansion and later dereferences ZERO_SIZE_PTR as though allocation succeeded.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e7f174715f9f0cbcb9e87b52e4fc4ef149baac98",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/afcc0515bbdd28d509a2b5870faaa89b137f5d53",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/168072baf9ad516d5a06046514c7fea4c0671990",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a82e170637e050a803b4f37542371ef216bf66d2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e7da02659c229f73492fb1ed87ceda4090153aaa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/786d2d84416a9a1c1a47b71a68d679d886284be2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 919,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64298",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:35.101Z",
      "date_updated": "2026-07-27T04:59:32.362Z",
      "publisher": "Linux",
      "title": "NFSv4: include MAY_WRITE in open permission mask for O_TRUNC",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05657
      },
      "nvd": {
        "published": "2026-07-25T10:17:10.657",
        "lastModified": "2026-07-30T15:00:27.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64298",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The NFS delegated-open permission mask derives access only from O_ACCMODE and omits MAY_WRITE for O_TRUNC, allowing read-only open to truncate a non-writable file.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4817c8974315b666e895b7d1bb83cd3664c323b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cb148a2762d644bff1894728e8835a9a4b84f9ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/30fdf4df6c3c00efec947e4ddf97f0fdd4473628",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/22c1fd1355ad4ca27aa7f0fa02719122dd92d9de",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6bd7d0a06b53c4e797e1a9cea0d2d41aa1b26230",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a937e92c1d00534b5c2e3e9f4381b7e988180797",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e36501b7d4abdcd6d69a7cb901b2f286b7a3d041",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5140f099ecd8a2f2808b7f7b720ee1bad8468974",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1071,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64299",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:35.742Z",
      "date_updated": "2026-07-27T04:59:33.536Z",
      "publisher": "Linux",
      "title": "tracing: Prevent out-of-bounds read in glob matching",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05612
      },
      "nvd": {
        "published": "2026-07-25T10:17:10.793",
        "lastModified": "2026-07-27T05:16:40.550",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64299",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The tracing glob matcher ignores the supplied field length and scans a non-null-terminated event string past its boundary.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/265f3a690f6c7d69ef7d2ca50b04b4853a211df3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ee5b8888d3248618251fb69a2fad92afcb81557e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/56d4c9ab84714eebb285a2fee68aaedf81e3ef15",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/35ae19764eabfe9c29029d3b5713c86e6855acdf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ebb55902856973906c8bb339a3a34824ed4a5086",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2dad64a97e1df47f5d9ccb17fa319aa348617226",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e5d5f3bd053a5f14787526c9f0f55ef900d43ac6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0a6070839b1ef276d5b05bedfb787743e140fb17",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1101,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64300",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:36.372Z",
      "date_updated": "2026-07-27T04:59:34.711Z",
      "publisher": "Linux",
      "title": "perf/aux: Fix page UAF in map_range()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05815
      },
      "nvd": {
        "published": "2026-07-25T10:17:10.930",
        "lastModified": "2026-07-27T05:16:40.693",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64300",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "map_range walks shared AUX pages without rb->aux_mutex while another event reallocates and frees them, leaving a mapping to a freed physical page.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c8b7e113f7b61eef2f017e6329c27c2331058c5a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0cff05bd2186020f8706233e261016d149cc24db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5948aaf64f81f217a25dcc2bf6c0779bca19566c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1084,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64301",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.778Z",
      "date_published": "2026-07-25T08:49:36.999Z",
      "date_updated": "2026-07-25T08:49:36.999Z",
      "publisher": "Linux",
      "title": "regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00206,
        "percentile": 0.10772
      },
      "nvd": {
        "published": "2026-07-25T10:17:11.043",
        "lastModified": "2026-07-25T10:17:11.043",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64301",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "scmi_regulator_probe returns from a child-node processing failure without dropping the device-tree node reference acquired by of_find_node_by_name.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1e446e8f8c763be3de7d0362e024cdf46194ffef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/637c11e3d8d43a7ee654591cda8d17c55a9234fa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e2baf8ea13fb4b10bec2c4751aea05c00dabcd0f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3e1441a4d06d35a314961e40057bd1f0106bbc14",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/22cb337370e6539b0418832c6040e9b00c1b74ca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a935b64548fcfe1d5b4dbdd31dddfb0d7019367f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fa11039d6cdff84584a3ef8cc1f5e1b56e045da2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 474,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64302",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:37.621Z",
      "date_updated": "2026-07-25T08:49:37.621Z",
      "publisher": "Linux",
      "title": "x86/mm: Fix freeing of PMD-sized vmemmap pages",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 9,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09801
      },
      "nvd": {
        "published": "2026-07-25T10:17:11.170",
        "lastModified": "2026-07-25T10:17:11.170",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64302",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Only the first page in a PMD vmemmap allocation is freed, leaking the remaining pages on each affected teardown.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/add1e4112e00b619614784bf630aeebfdefa23e1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/03f6ecbc446c33b38fd452cd3c494092a8116967",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/39406c05f8f150f1685839acd38ffdd69ff92031",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1131,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-64303",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:38.223Z",
      "date_updated": "2026-07-27T04:59:35.874Z",
      "publisher": "Linux",
      "title": "spi: fsl-lpspi: terminate the RX channel on TX prepare failure path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00675,
        "percentile": 0.48684
      },
      "nvd": {
        "published": "2026-07-25T10:17:11.277",
        "lastModified": "2026-07-27T05:16:40.813",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64303",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A transmit-DMA preparation failure leaves the issued receive-DMA channel running while the SPI core unmaps its buffers.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ad370d1c7a9a832f77b2341513cd31188c9443af",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cce2063404b2341e7b2bbf85eddfcd70a31a0033",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af39a2698f69b584d14a00cffe0f51a2caa15337",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e65505d91fa036a238968e4c10744244d1b968c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d5c1060218a3749c8a18b36f8169d910fce20639",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/808033d80d5c9f8adf7e8de9317389270ce13430",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9d000bdd250d649a11cd7f733175686877344582",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/01980b5da56e573d62798d0ff6c86bcaa2b22cbe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 613,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64304",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:38.873Z",
      "date_updated": "2026-07-27T04:59:37.100Z",
      "publisher": "Linux",
      "title": "crypto: qat - validate RSA CRT component lengths",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.0604
      },
      "nvd": {
        "published": "2026-07-25T10:17:11.403",
        "lastModified": "2026-07-27T05:16:40.950",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64304",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The QAT RSA CRT path copies key components into hardware buffers without first bounding each component length.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6d99c5fadd2df488103f64d6475b63ba6852202b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c34369473bfe92a0b46ec78d6358e30341c7f481",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1002719d13072a5e4be1e993aa61dffb4a604e82",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/500319830d76911c120dc0b9605f8c16d7702844",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3d61a214fdcda41f1ebfabbb483404032a7b4d91",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6fb62b767f3e27661e8f8d2f7b85f4e098fcdb1a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ce42224487c504aee4b7ff3a7342e7b4d7e28cc9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b3ac78756588059729b9195fcc9f4b37d54057a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 708,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64305",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:39.536Z",
      "date_updated": "2026-07-25T08:49:39.536Z",
      "publisher": "Linux",
      "title": "crypto: qat - protect service table iterations with service_lock",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06421
      },
      "nvd": {
        "published": "2026-07-25T10:17:11.530",
        "lastModified": "2026-07-25T10:17:11.530",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64305",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "QAT service-table traversal runs without service_lock while concurrent registration or removal can mutate and free entries in the same list.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/222fa7b453b612f4407f260146d89a2ce2bc831d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c3c5925791cff3b84d313293fd60f384d877d793",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0dbcecea740d943002c1cbdafa39bdfc108e32a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5c6f845e77ec35f9b7b047cc8f9789bf397cdd3e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 976,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64306",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:40.153Z",
      "date_updated": "2026-07-25T08:49:40.153Z",
      "publisher": "Linux",
      "title": "crypto: drbg - Fix returning success on failure in CTR_DRBG",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11388
      },
      "nvd": {
        "published": "2026-07-25T10:17:11.653",
        "lastModified": "2026-07-25T10:17:11.653",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64306",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CTR_DRBG reports success after generation fails, leaving callers to consume an uninitialized output buffer as random bytes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/074db6db03a0aaa78f05ca9d4838053713796665",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7b03312491f9fe6ba4d60c4023e7e61d2d1fed96",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/75597e8774f319152744d24e0683d9393540a951",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cc42fb40171c249bb859071d81b4eb007398a0bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bbbac12083eff489b35d848332f0dff311131344",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/23b8b188cb32e5531d0f8d3af9506f8959cb369e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a9e886f73dd717027028bb7e3bbca93601ecdfc7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/39a31ad9e2a5ed7e9c9c6f711dca96c8c8f5f26b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 240,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64307",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:40.782Z",
      "date_updated": "2026-07-25T08:49:40.782Z",
      "publisher": "Linux",
      "title": "crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 11,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00215,
        "percentile": 0.12026
      },
      "nvd": {
        "published": "2026-07-25T10:17:11.800",
        "lastModified": "2026-07-25T10:17:11.800",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64307",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SNP_CONFIG can retry failed SNP initialization while normal VMs are active and clear global HSAVE state needed by their next VMRUN.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/345a6e869b33687e9268044bcaeeefd7c61da675",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/441ea32cf2755a0dc593557056b00b7caa0651f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/20f548cdac94860a164e5ebba4f7e4a01051cb06",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/08f0e65e784c4b20e6e620dd4f68d8636073a3d2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1078,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-64308",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:41.411Z",
      "date_updated": "2026-07-25T08:49:41.411Z",
      "publisher": "Linux",
      "title": "crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 11,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00215,
        "percentile": 0.12027
      },
      "nvd": {
        "published": "2026-07-25T10:17:11.917",
        "lastModified": "2026-07-25T10:17:11.917",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64308",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SEV-SNP initialization and shutdown paths permit lifecycle operations in an invalid order, leaving resources reachable after teardown.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/61cf5eef20657bff9ca235fe938a99ce5ff65c06",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/92567ed9306d5a3d1b007eb4faeff30cc3ffc3e4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8836801847b9479ac046cb18a24981e1b0b05e9d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f91e9dbb5845d1e5abf1028e6df57dcf61583e1b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 952,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-64309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:42.035Z",
      "date_updated": "2026-07-25T08:49:42.035Z",
      "publisher": "Linux",
      "title": "crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 11,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00215,
        "percentile": 0.12026
      },
      "nvd": {
        "published": "2026-07-25T10:17:12.030",
        "lastModified": "2026-07-25T10:17:12.030",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64309",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SNP_COMMIT ioctl unnecessarily initializes SEV-SNP, so an initialization failure can zero global MSR_VM_HSAVE_PA while ordinary VMs are still active.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/74768f73854d647a6462f252dc8782ab8a835211",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7a361c74bb12f3398c388905f1d325be642cd36e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/67ed191b4c8bdf432a3f32d1eb302880b4795cd1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5a1364da2f04217a36e2fdfa2db4ee025b383a20",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 808,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-64310",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:42.683Z",
      "date_updated": "2026-07-25T08:49:42.683Z",
      "publisher": "Linux",
      "title": "crypto: ccp - Do not initialize SNP for SEV ioctls",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 11,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00215,
        "percentile": 0.12027
      },
      "nvd": {
        "published": "2026-07-25T10:17:12.147",
        "lastModified": "2026-07-25T10:17:12.147",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64310",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SEV-only ioctls unnecessarily initialize and shut down SNP, allowing a failed transition to clear host-save state used by running virtual machines.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5181e88da99c3d1d41e25db3472a62b8d4b42cdd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9e983d0a74a6a2348e4ce61647ec8a4dfbe198ac",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d51207735e7c224cf591fa260c557a451a69a5cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fb1758e74b8061aacfbce7bbb7a7cc650537e167",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1380,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-64311",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:43.318Z",
      "date_updated": "2026-07-27T04:59:38.278Z",
      "publisher": "Linux",
      "title": "crypto: loongson - Remove broken and unused loongson-rng",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00157,
        "percentile": 0.05351
      },
      "nvd": {
        "published": "2026-07-25T10:17:12.263",
        "lastModified": "2026-07-27T05:16:41.087",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64311",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Loongson RNG driver lacks forward security and also contains a completion-related lifetime error, with the random-generation design as the primary reported failure.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/037ec8353711c79353b12d5634e0c9ff363a9efa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/43de8b9f01b7dd2f6ca5360c6bf2f203c02288dc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af3d1bb9a09daf928fc3f173689fb7904d6a6d4f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1192,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64312",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:43.940Z",
      "date_updated": "2026-07-27T04:59:39.447Z",
      "publisher": "Linux",
      "title": "crypto: pcrypt - restore callback for non-parallel fallback",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 29,
        "versionRangeCount": 25,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00501,
        "percentile": 0.40145
      },
      "nvd": {
        "published": "2026-07-25T10:17:12.373",
        "lastModified": "2026-07-27T05:16:41.210",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64312",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The nonparallel fallback retains the padata completion callback even though the request was never enrolled in padata.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/81ce16d938db9b88cdc231522c0358395ae8c6b5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3920c5f6edc341729d20d0507e466c6d3b11f372",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ae93c5b3e2a2968b56d772ca1d06615927b7cc36",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/82789a44415e3e31168229421b138278dfb16412",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4711ca06bd169a2cbc9cc59a6de2ed512c41a880",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c4bd2f4c35b0e15b6040c2f7e7e7986780c066cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/83fa1397d5853de1e27dd52ec44b068ff358ca18",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ed459fe319376e876de433d12b6c6772e612ca36",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 710,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 29
      }
    },
    {
      "cve_id": "CVE-2026-64313",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:44.546Z",
      "date_updated": "2026-07-27T04:59:40.630Z",
      "publisher": "Linux",
      "title": "crypto: ecc - Fix carry overflow in vli multiplication",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27118
      },
      "nvd": {
        "published": "2026-07-25T10:17:12.517",
        "lastModified": "2026-07-27T05:16:41.360",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64313",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ECC multi-precision multiplication drops a carry when the high word is saturated and the low-word addition also overflows, producing an incorrect cryptographic result.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d11b2bb99bec1f5557c01cac42231e23745f49b8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b709e0e768766abe29a49e1c1922a1604be602f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/24a54dfa06d09813b4802a374fad3d2c0e16a884",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/677450e5ef850c4d28b7956aa01104548c2a894e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5275e0fca256d081e2e7d4ba3dd8216c6e50d44e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/774ddddf5eb26eeca177350413e3e2bc50930ee9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ebaae7c4251cc0cdb2602f334d4f08a3e82d271e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/27b536a2ec8e2f85a0380c2d13c9ecbc7aaab406",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 746,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64314",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:45.170Z",
      "date_updated": "2026-07-25T08:49:45.170Z",
      "publisher": "Linux",
      "title": "crypto: chacha20poly1305 - validate poly1305 template argument",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.098
      },
      "nvd": {
        "published": "2026-07-25T10:17:12.647",
        "lastModified": "2026-07-25T10:17:12.647",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64314",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A missing crypto-template argument is returned as an error pointer and passed directly to strcmp.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0016d3c21c6ab60a20be7f565cefb5999f3adeb6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e74df53b36cdc6b6b9e5488ec883d1d55624737f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/265b861bece38318b8e0fc8fac0643d4ef906d31",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 696,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64315",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:45.787Z",
      "date_updated": "2026-07-27T04:59:41.861Z",
      "publisher": "Linux",
      "title": "crypto: caam - use print_hex_dump_devel to guard key hex dumps",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04267
      },
      "nvd": {
        "published": "2026-07-25T10:17:12.750",
        "lastModified": "2026-07-27T05:16:41.510",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64315",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CAAM setkey paths print cryptographic key bytes when dynamic debug is enabled.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1ec775f6a124cce6278ae58b7d1c78a3bc6eef23",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bcf3cf74dfb6981e18b22cbf561f859a0f7faa26",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6407dc85d0a4306681cf6c9be7f05e05dcb67a37",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c8cfe11e48b2a4646fa662fcaa92e14810a28d46",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8904b425cfcafe6a820c94b9bdf4b10f7d70f9d7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d0b8cafd529b4ec759190c6081f7a76efb563a8f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/59057f5d4e9a195c6dd61695ad3bc4481ddf4f14",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8005dc808bcce7d6cc2ae015a3cde1683bee602d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 282,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64316",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:46.415Z",
      "date_updated": "2026-07-25T08:49:46.415Z",
      "publisher": "Linux",
      "title": "crypto: caam - use print_hex_dump_devel to guard key hex dumps",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07402
      },
      "nvd": {
        "published": "2026-07-25T10:17:12.877",
        "lastModified": "2026-07-25T10:17:12.877",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64316",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Runtime debug logging can print cryptographic key bytes from setkey and split-key generation paths.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/45c0e3615e5bca5f1fc93357af8d19975c092d4f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8b56ba10105ca34a4b75f7e33d41d96a63815591",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9a53dc0a0ae0486e164e5af3de5f99ab42c5a23e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ebd37eef6e4f435e18829c0c0c9ba3a6618cb2dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cea7302d5d05df74cfb4107897b1ca34163c06b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6f7b8e0321f3a8fbbd267d2ac15c671ab59e919e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8cf5fb0503129e53052fe29302379cf83891d0fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3f57657b6ea23f933371f2c2846322f441773cee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 302,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64317",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:47.067Z",
      "date_updated": "2026-07-27T04:59:43.002Z",
      "publisher": "Linux",
      "title": "isofs: bound Rock Ridge symlink components to the SL record",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05613
      },
      "nvd": {
        "published": "2026-07-25T10:17:13.010",
        "lastModified": "2026-07-27T05:16:41.640",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64317",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ISOFS Rock Ridge symlink parser reads each component length and copies its text without first proving the component fits inside the SL record, allowing an out-of-bounds read.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1015e1c4b2fadd9c09704e24738e46598778c869",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/36fe7d25dbc40da0c6b1dd4513a4f69ac6164eee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a22cb6bb54dc167047ea9e70d97dfbc2c15649e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b736b12108fd116c41777628f5a333791604df26",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6bf41db09ef935d76fcc84ccf213b42c18de95ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b5699642640d6cff357638738c5293985cd5a53d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9830725078c8483c6831ec10222ae724806ea36b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5fa1d6a5ec2356d2107dead614437c66fa7138b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1643,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64318",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.779Z",
      "date_published": "2026-07-25T08:49:47.690Z",
      "date_updated": "2026-07-27T04:59:44.420Z",
      "publisher": "Linux",
      "title": "partitions: aix: bound the pp_count scan to the ppe array",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05613
      },
      "nvd": {
        "published": "2026-07-25T10:17:13.147",
        "lastModified": "2026-07-27T05:16:41.787",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64318",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The AIX partition scanner trusts an on-disk pp_count up to 65535 while the allocated ppe array contains only 1016 entries.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/09861651617ba0fec089e8b9477439e68398c110",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5eacdb1967378f5e5591cd27a2d8cdee2df1a599",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b5e9c09309e18fd9839ad007c238120353ca0cc4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fd94a779020f2ecc8b2607f4c20b34acb1763b9a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4671bb74bba05fdd4acf670a35758c29e8c97b83",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ce93228e2193a17d2c58b656e439bb39fe5c3af8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/44f37ee92fdcd377c41bdf6a31cdd8cc7d4c410e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2dc0bfd2fe355fb930de63c2f2eb8ced8570c579",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1130,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64319",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.780Z",
      "date_published": "2026-07-25T08:49:48.291Z",
      "date_updated": "2026-07-27T04:59:45.613Z",
      "publisher": "Linux",
      "title": "nvmet-auth: validate reply message payload bounds against transfer length",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00524,
        "percentile": 0.41525
      },
      "nvd": {
        "published": "2026-07-25T10:17:13.290",
        "lastModified": "2026-07-27T05:16:41.930",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64319",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "nvmet-auth uses attacker-controlled hash and DH lengths to address a variable reply payload before checking that those fields fit the transfer buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/999f6205ede984a786f35f727b01f971b98e215d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6d7649c1231dac14d906985d2936967e23041c26",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/caa71b3a43ea5c13fe7141cb019ebcb03b8ac857",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3a413ece2504c70aa34a20be4dafec04e8c741f9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1001,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64320",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.780Z",
      "date_published": "2026-07-25T08:49:48.908Z",
      "date_updated": "2026-07-27T04:59:46.816Z",
      "publisher": "Linux",
      "title": "nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00728,
        "percentile": 0.5064
      },
      "nvd": {
        "published": "2026-07-25T10:17:13.407",
        "lastModified": "2026-07-27T05:16:42.073",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64320",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The copy path checks only offset alignment and then reads buffer plus offset for data_len bytes without validating the source bound.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/33b974eb626154ae9348f2bac7de84cb2a3d9dd4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/56c021a0869260d04c4b65d1471936aaf9177114",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a29b316b9bbfd269f323ab4ba9906a894025680f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/53cd102a7a56079b11b897835bd9b94c14e6322c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2360,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64321",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.780Z",
      "date_published": "2026-07-25T08:49:49.541Z",
      "date_updated": "2026-07-25T08:49:49.541Z",
      "publisher": "Linux",
      "title": "nvme: target: rdma: fix ndev refcount leak on queue connect",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06422
      },
      "nvd": {
        "published": "2026-07-25T10:17:13.530",
        "lastModified": "2026-07-25T10:17:13.530",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64321",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The NVMe RDMA busy return path omits the kref release acquired for ndev during queue connection.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d65fe42820b890a6a4644de0a95a812471f79ad3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a8803c4f0ac3fa7df5551bbb5a8800c434a94357",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5828517d17eda27f21d29ea14800c9e0a57bad11",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/badc53620fe813b3a9f727ef9526f98567c2c898",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 498,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64322",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.780Z",
      "date_published": "2026-07-25T08:49:50.180Z",
      "date_updated": "2026-07-27T04:59:48.014Z",
      "publisher": "Linux",
      "title": "udf: validate sparing table length as an entry count, not a byte count",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 28,
        "versionRangeCount": 22,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.0604
      },
      "nvd": {
        "published": "2026-07-25T10:17:13.640",
        "lastModified": "2026-07-27T05:16:42.210",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64322",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "UDF validates a sparing-table entry count as though it were a byte length and then accesses entries beyond the supplied table.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/eeb0f3e193f8e523d03e4c9e084f6b4875f50e8e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0a9b79a951cfd70a9d31ca01ae2d08a20bb730e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2d726135099313958f8975532a2e15322ff150ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7285276aa50d2839afb5957ffd491ad282dc8f72",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2a219acb2ce674d99bbd1b7b35ed8c384dac7200",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/04f4599a9efb90992d072a814960edf0cd62805d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7f7774b9da0ef17b87bfa238cf966ad0b3376150",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3ec997bd5508e9b25210b5bbec89031629cdb093",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1176,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 28
      }
    },
    {
      "cve_id": "CVE-2026-64323",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.780Z",
      "date_published": "2026-07-25T08:49:51.097Z",
      "date_updated": "2026-07-27T04:59:49.230Z",
      "publisher": "Linux",
      "title": "udf: validate VAT header length against the VAT inode size",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05613
      },
      "nvd": {
        "published": "2026-07-25T10:17:13.790",
        "lastModified": "2026-07-27T05:16:42.370",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64323",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A crafted UDF VAT header length can exceed the inode size, underflow the entry count, and drive an out-of-bounds read of inline inode data.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/883962731420ec271ed8c1cd76524f4b17faa982",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/55287a3555ff0515b3aff181d2c08c0462a41709",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/74580fdf022909e184223cacc364feb826982d96",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d8202786b3d75125c84ebc4de6d946f92fde0ee8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1086,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64324",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.780Z",
      "date_published": "2026-07-25T08:49:52.063Z",
      "date_updated": "2026-07-27T04:59:50.432Z",
      "publisher": "Linux",
      "title": "udf: validate free block extents against the partition length",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 28,
        "versionRangeCount": 24,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05237
      },
      "nvd": {
        "published": "2026-07-25T10:17:13.923",
        "lastModified": "2026-07-27T05:16:42.513",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64324",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "udf_free_blocks omits the extent offset from its partition-length bound, allowing a crafted extent to index past the space-bitmap array.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fdd6229d2ae9914c1f25d1041db0f4f312a4fa76",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b54aee5652fcd7c23a0904a4623ec462c3edc70c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/12af328d2ee8d68e81ba612246d0b54b22d23e1f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fb49099206c5c57af28a157249fa7bcb5518f99e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9442d75429b0c556292a7454fe888d54259f5240",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/335202ab25b01fdd45889ff25eab70864686dea3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be87de7789a82a030a4896bc7683415ec9fa6f2b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5f0419457f89dce1a3f1c8e62a3adf2f39ab8168",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1283,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 28
      }
    },
    {
      "cve_id": "CVE-2026-64325",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.780Z",
      "date_published": "2026-07-25T08:49:53.238Z",
      "date_updated": "2026-07-25T08:49:53.238Z",
      "publisher": "Linux",
      "title": "wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00189,
        "percentile": 0.08822
      },
      "nvd": {
        "published": "2026-07-25T10:17:14.097",
        "lastModified": "2026-07-25T10:17:14.097",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64325",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A queued channel-switch callback can run after disconnect clears dev->new_ctx and dereference the stale NULL state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/77e7b127472a191e086e1e0b1b051703f33b1801",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/351dd7d2c80d23e56dcce6faa4e62bea5b0877c7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1401,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64326",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.780Z",
      "date_published": "2026-07-25T08:49:54.327Z",
      "date_updated": "2026-07-25T08:49:54.327Z",
      "publisher": "Linux",
      "title": "block: skip sync_blockdev() on surprise removal in bdev_mark_dead()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10053
      },
      "nvd": {
        "published": "2026-07-25T10:17:14.207",
        "lastModified": "2026-07-25T10:17:14.207",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64326",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Surprise removal still calls sync_blockdev() even though the device is gone, leaving writeback waits with no completion path.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d6998ddd507c81e3829489a6ead23f17f5acb7fe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f41cf35ee2a1e31374b3f54e7579c55153506e70",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9818bcae3c0ca1dde4b9a334125c46676e0a9b29",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aa4c4a9315764b2b7a7182e72cc5ea87520436b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/49f06cff50a4ccf3b7a1a662ceb892b3b21a527a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1016,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64327",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.780Z",
      "date_published": "2026-07-25T08:49:55.426Z",
      "date_updated": "2026-07-25T08:49:55.426Z",
      "publisher": "Linux",
      "title": "usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10054
      },
      "nvd": {
        "published": "2026-07-25T10:17:14.327",
        "lastModified": "2026-07-25T10:17:14.327",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64327",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "FunctionFS initializes endpoint direction only after host connection, so earlier userspace DMA ioctls operate with the wrong direction state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/82cf1142e5ccf2b6d6d22ef713aaf3e5f2b5716b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9e04055ab5fc0470a0031ee6934739f9aa8f34a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f99f32ea9aa976afcbec20647ed33b50a52002c1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/82cfd4739011bdc7e87b5d585703427e89ddfaa5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 671,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64328",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.780Z",
      "date_published": "2026-07-25T08:49:56.340Z",
      "date_updated": "2026-07-25T08:49:56.340Z",
      "publisher": "Linux",
      "title": "usb: gadget: f_fs: Fix DMA fence leak",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.002,
        "percentile": 0.10054
      },
      "nvd": {
        "published": "2026-07-25T10:17:14.430",
        "lastModified": "2026-07-25T10:17:14.430",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64328",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ffs_dmabuf_transfer retains the initial DMA-fence reference after adding a second reservation reference, leaking each completed fence.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b7475b2dce5e121e687280ba5732ccefe77ffd2f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e086c16962a1b0142e2675610e9c06fcfcd4c3a8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0cae3d6109427c455bad0a18dfb3e2a91657e38a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/baa6b6068a3f2bf2ed525a1cb37975905dadc658",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 984,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64329",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.780Z",
      "date_published": "2026-07-25T08:49:57.098Z",
      "date_updated": "2026-07-25T08:49:57.098Z",
      "publisher": "Linux",
      "title": "usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07406
      },
      "nvd": {
        "published": "2026-07-25T10:17:14.540",
        "lastModified": "2026-07-25T10:17:14.540",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64329",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Device removal frees the UCSI object before disabling an in-flight IRQ handler that can still dereference it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f1adeb1ff8bef1467d6961059810795d02bbad5d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/99381e762273a2410a3f0216000be32b013c0ea9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1a160076d3d0dcd4a98a4599ad96eec0790b099b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c32df11147822d22facee8fa30c2e8971d12f426",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/86c9ee928c4a370e323e432aaf8dca79c4ba7c85",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f5c772b76bbd95de8be51cf849c6098f6af6fcf9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dbb500bad02146b388041877574829016591ddc8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1f0bdc2884b67de337215079bba166df0cdf4ac5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1107,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64330",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:49:57.734Z",
      "date_updated": "2026-07-25T08:49:57.734Z",
      "publisher": "Linux",
      "title": "usb: typec: tcpm: Validate SVID index in svdm_consume_modes()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07408
      },
      "nvd": {
        "published": "2026-07-25T10:17:14.673",
        "lastModified": "2026-07-25T10:17:14.673",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64330",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unchecked SVID index permits a read beyond the array bounds.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d638ec188e95fe60f4b01106ffd41958f8fb3c2c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f8163c414de8640f2ca82ce4dc93409d4cdc2fad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/012406f89abc52d1d5f07aa5653b519ebf6d2407",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c6d2af3b217a525741c472f0ab45d7d274b8468f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3e1b1ac47e8163627f159f30d80d51b914620dd4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/313ca06e7e224ca1dfadd5722fe71fb8bc276b8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7b681dd5fbf60b24a13c14661e5b7735759fb491",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1145,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64331",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:49:58.370Z",
      "date_updated": "2026-07-25T08:49:58.370Z",
      "publisher": "Linux",
      "title": "usbip: vudc: fix NULL deref in vep_dequeue()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07409
      },
      "nvd": {
        "published": "2026-07-25T10:17:14.813",
        "lastModified": "2026-07-25T10:17:14.813",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64331",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The FunctionFS request lacks a valid UDC reference and vep_dequeue dereferences it during AIO cancellation.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9858c91d9ee6a13c45311569039413729fc9b757",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1226293ec9bed3d4cc5b05eeeb811d315ca51652",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3750f75f29f99c0223601e2ee73ad084adec47bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d0ebf9cc7c2ddf95a7cfc654b940bdacb7edde97",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0025276175fbbe0dcbf3f84d090b0adee769e9d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/347b59e9f96719d89b6ef555d02a18ada1a5846f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0443e4416aa1ee97748d1ed904eaf3352c60045e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c5371e0b91b24159a3ebaa61e70b0980bcf03c0a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1011,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64332",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:49:59.005Z",
      "date_updated": "2026-07-25T08:49:59.005Z",
      "publisher": "Linux",
      "title": "USB: ulpi: fix memory leak on registration failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07411
      },
      "nvd": {
        "published": "2026-07-25T10:17:14.950",
        "lastModified": "2026-07-25T10:17:14.950",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64332",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Early ULPI registration failures leave the allocated device name and its initial reference unreleased.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d5b32f36c50894ac2df8fa184e6f35f3a6665ecd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/691e61e5d4cfc5a1b061e937f8cbf2126bfc19a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/88187a43135c79d0e43573b4d8f880bbb919eceb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5c098f20f15db7f9126129686d1c6da2ce8bbeb0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/624c57147df1977e0d3da53f1da7117861b9cf19",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1967a7f0cd5c08eb479196daa5aaa4b7b7a7bd04",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e5493c9a98ffe083acf13ac064828ae598ba3c16",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8af6812795869a66e9b26044f455b13deecdb69c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64333",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:49:59.616Z",
      "date_updated": "2026-07-27T04:59:51.692Z",
      "publisher": "Linux",
      "title": "USB: serial: digi_acceleport: fix write buffer corruption",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06039
      },
      "nvd": {
        "published": "2026-07-25T10:17:15.080",
        "lastModified": "2026-07-27T05:16:42.670",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64333",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The serial command timeout path updates and resubmits a write URB that is still unavailable instead of returning or waiting.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5d9dc88bdf8897788b0eed57113e9eca7fd42ea9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f296974acc279f05f284441bfe3064074958d11",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e60e4873e9178da9f4f2674e4c2ff085d5a84f79",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/699dfb6917503b3cda4d5da6941cf79c3c1b4c8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a274b3794fe1852c3d9fe6d900b94053c0b03410",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1243f120790042c2ac92e84e797dacc75fff4366",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a3a13fdc53103b07335918e2cdeb465038a71725",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/24ca1fea8f2753bf33e1d458ec1ae5d9b7796a65",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 788,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64334",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:50:00.229Z",
      "date_updated": "2026-07-25T08:50:00.229Z",
      "publisher": "Linux",
      "title": "USB: serial: digi_acceleport: fix hard lockup on disconnect",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.0741
      },
      "nvd": {
        "published": "2026-07-25T10:17:15.207",
        "lastModified": "2026-07-25T10:17:15.207",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64334",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Digi USB serial driver retries persistent OOB URB submission failures indefinitely while interrupts are disabled.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6e51147c2744d15730084dc89cc99180d3de4184",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6a8592ace932081ea11aea41c460a1ca0f6344a4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5a82d842e8c35227d7227f19e5e654df1451782c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bcfeae431db9986c2b313e6a760f2ac8df61e138",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2067b3838da6e4af03bae3630414193188d754b2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2b7dc482f859f2d027db07ff0efc1c5df5b3451a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/79bc131df0e50f8f663c1fdbbe952aaf193a8d39",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5c1ea24b53bf3bfb859f0a05573997487975da23",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64335",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:50:00.835Z",
      "date_updated": "2026-07-25T08:50:00.835Z",
      "publisher": "Linux",
      "title": "USB: serial: digi_acceleport: fix broken rx after throttle",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07402
      },
      "nvd": {
        "published": "2026-07-25T10:17:15.337",
        "lastModified": "2026-07-25T10:17:15.337",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64335",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Closing a throttled serial port leaves throttle state set and the read URB unsubmitted when the port is reopened.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4f3f6f44db71e469933a7c36c5d57d937ba0a21b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d5d2660caef78d4c996d34d123574c8e86f5b5ac",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/61954033326fc7e637ed2aeeb4b52021e0ee4657",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8d50a910194f66566a5eb252b33283855c8d5203",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/abacd67e6f689c62d8a13e3da25f4272bc9ad4af",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eab394781e9321c0c7e97a24fd092387cb262f40",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/92fa3e1a49848509ea3f7995751963fc65095998",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/83a3dfc018943b05b6daf3a6f891833e1aabfa1f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 386,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64336",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:50:01.444Z",
      "date_updated": "2026-07-25T08:50:01.444Z",
      "publisher": "Linux",
      "title": "USB: serial: keyspan_pda: fix information leak",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06905
      },
      "nvd": {
        "published": "2026-07-25T10:17:15.463",
        "lastModified": "2026-07-25T10:17:15.463",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64336",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "keyspan_pda_write reports more accepted characters than the caller supplied, causing the line discipline to continue reading beyond the tty write buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b069b7029862fafaff331d4c664d97d4ae828d6d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e52ca411f50539ff1d0c877b9312771ca8a858c1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f7a6b8ab3845bd1da02604f1a874b52a4555a72",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e1494191a3aac665d3a2fce16169a97c346253ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cf6ca0aefae03958cfb5b189b0adbfb25c06bfac",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d4b12b6b395e43a2b1d80be3745631fcaa9c047b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6bfc8d01ac4068eced509f8fc74d0cd205e4dcec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 652,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64337",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:50:02.066Z",
      "date_updated": "2026-07-25T08:50:02.066Z",
      "publisher": "Linux",
      "title": "usb: mtu3: unmap request DMA on queue failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11393
      },
      "nvd": {
        "published": "2026-07-25T10:17:15.590",
        "lastModified": "2026-07-25T10:17:15.590",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64337",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "mtu3_gadget_queue maps a DMA request before checking ring capacity and returns EAGAIN on failure without unmapping it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3cee30f1138281a1d247bb053a1ad4f7c5b04e98",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f3c4026524d3660c73ef2838b99776d37631e039",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e8f739a3860d043dcc135371637e82f53132efe5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4183874b7925f4a98b400cf857bea26ee87da236",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/00c3fef4c2dc2c7cbd8281f8fda09d1913420f09",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8c29d9cfab1c3cf0d0b7fcdf9255597be30aa3e1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/835b0596d4c9bdef93f842d8f826978fb4956b74",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0bddda5a11665c210339de76d27ebbd1a2e0b43c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64338",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:50:02.673Z",
      "date_updated": "2026-07-25T08:50:02.673Z",
      "publisher": "Linux",
      "title": "USB: misc: uss720: unregister parport on probe failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 28,
        "versionRangeCount": 24,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.0741
      },
      "nvd": {
        "published": "2026-07-25T10:17:15.717",
        "lastModified": "2026-07-25T10:17:15.717",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64338",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "After registering a parport, a later failure frees its private state without unregistering the still-referenced port.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6bbb98bec71b577fda4f4b48f7aea5874b04a576",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/93563243377f8e9b46cc94d9c4f06533dd31b141",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1712fd71a5aaf81e47c747f180535fa963ad7830",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0b3073f40cc9f95d5ff0037eb0a06f5c1725a7ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5e62d7857fd51b908b8371062ee839739a086bbe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/729b68a5bad71220ae0914c8bdab9488ad5be6c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/48dd0b2ec9f2e97c486eb68cd0a64b25c1c3df3e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b4ecbdc4f8830f5586c4a5cfc384c00f20f8f8b3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 999,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 28
      }
    },
    {
      "cve_id": "CVE-2026-64339",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:50:03.272Z",
      "date_updated": "2026-07-25T08:50:03.272Z",
      "publisher": "Linux",
      "title": "usb: misc: usbio: bound bulk IN response length to the received transfer",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00198,
        "percentile": 0.09804
      },
      "nvd": {
        "published": "2026-07-25T10:17:15.870",
        "lastModified": "2026-07-25T10:17:15.870",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64339",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Linux path trusts a length or offset that can read beyond the initialized input buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/48394f94211cf8fe0ea8604fc441633abf90fc94",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fc1b546973c1442d5b947fcdd03581f20ecc5bd2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8c6314489550fa81d41723a0ff33f655b5b6c7b6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1982,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64340",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:50:03.896Z",
      "date_updated": "2026-07-25T08:50:03.896Z",
      "publisher": "Linux",
      "title": "USB: legousbtower: fix use-after-free on disconnect race",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07404
      },
      "nvd": {
        "published": "2026-07-25T10:17:15.983",
        "lastModified": "2026-07-25T10:17:15.983",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64340",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "legousbtower releases a mutex through an object whose lifetime can already have ended.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/11d069f85851997b4ea0adf242ed9672dc749b8f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b4222c05066b252b451f9c8c4730b5b60824ea66",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6462de75d2e370c7e74dcfb7b4ae79eb5a6a55ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0b57e5ddbd89df3bc367463de3d2ca66f99a1a5e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ab2bfd7bec4f134b377ec42f513e90c35db94160",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/766738ecf2b819e54d38763c8d1c8ae6cff14b39",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9ba62966461a8e3cc593b62c56ec62eb2d80436d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/62fc8eb1b1481051f7bab4aa93d79809053dd09f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 710,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64341",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:50:04.512Z",
      "date_updated": "2026-07-25T08:50:04.512Z",
      "publisher": "Linux",
      "title": "USB: iowarrior: fix use-after-free on disconnect race",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06234
      },
      "nvd": {
        "published": "2026-07-25T10:17:16.117",
        "lastModified": "2026-07-25T10:17:16.117",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64341",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The iowarrior disconnect and release paths use mutex_unlock as if it ended object lifetime, allowing one path to free the mutex-containing object while the other still accesses it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3c0a7b29ebb391d5f50b115e86f842b709195b08",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/71590982700fdeb39a37a500c877228b0140978e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c602254ba4c10f60a73cd99d147874f86a3f485c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 688,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64342",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:50:05.169Z",
      "date_updated": "2026-07-25T08:50:05.169Z",
      "publisher": "Linux",
      "title": "USB: iowarrior: fix use-after-free on disconnect",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.0741
      },
      "nvd": {
        "published": "2026-07-25T10:17:16.227",
        "lastModified": "2026-07-25T10:17:16.227",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64342",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "USB write completions can run after disconnect because submitted URBs are not stopped during teardown.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d058d377291567b72aea33b017215cbfb383b0ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a7bbe946ca3a6eeb6f364d5e84b05e02c7c0d595",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/97ad9337127be04ca0b027c2b01e69302353f404",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/164398601a7f160bc3df1efa454f983302cef03f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f328b0e9a0dbd162f5db1b83026b689f2fea2241",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b748f97aff339e7f08dca9cf38a05b980fb66fea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e4596816984efc537e7c04c1af0c639394f967f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bc0e4f16c44e50daa0b1ea729934baa3b4815dee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 282,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64343",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:50:05.828Z",
      "date_updated": "2026-07-25T08:50:05.828Z",
      "publisher": "Linux",
      "title": "USB: ldusb: fix use-after-free on disconnect race",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07407
      },
      "nvd": {
        "published": "2026-07-25T10:17:16.353",
        "lastModified": "2026-07-25T10:17:16.353",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64343",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ldusb releases driver data while mutex_unlock() can still access the embedded mutex during a disconnect/release race.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fc55923a972e715f9a27187b47d4920709e23d85",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e5a9bdce4bfd3e2226b5f3df5fb8385d6935ee69",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af59829e67e11ba2511a9f8e4b9111afc7d1f550",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/02ca08fff74cf9b0a3c4d2cacde1c6edeeb95bb4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d8f69404e1d671326f86d378b9f5bfbd56490e9d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2107a4fc8ff1cf1d52f416c1e5cc8e97413a5915",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a3e794136ab5e3ad1e7019175a4b837aec86db4b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/19bdfc7b3c179331eafa423d87e1336f43bbfeb8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 703,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64344",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:50:06.461Z",
      "date_updated": "2026-07-25T08:50:06.461Z",
      "publisher": "Linux",
      "title": "USB: idmouse: fix use-after-free on disconnect race",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.0741
      },
      "nvd": {
        "published": "2026-07-25T10:17:16.487",
        "lastModified": "2026-07-25T10:17:16.487",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64344",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The idmouse release path relies on mutex_unlock() for lifetime while disconnect can free the same driver data, causing a use-after-free after the unlock.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/31e75fed8f90cfea9f8285e7ed135b0e452bf872",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8d53b14ad4ccbff6d306b3a39c812303f4a87d41",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f62622e947f82a3854a8502d09492ffbdeb252b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/60fc5ef4ecea3e3d1fe556cecf53ddd13096ef09",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d0f61acb51a8c8f3fd41c303ddb7770cd83e7ed4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/54c2b7356b4aeea467f9fb13b85e9e036bc428cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e88cff5fbaa629f3cab45c8b46f395d62c2eb515",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ff002c153f9722caece3983cc23dc4d9d4652cb4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 705,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64345",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.781Z",
      "date_published": "2026-07-25T08:50:07.069Z",
      "date_updated": "2026-07-25T08:50:07.069Z",
      "publisher": "Linux",
      "title": "usb: gadget: f_printer: take kref only for successful open",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 28,
        "versionRangeCount": 20,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06905
      },
      "nvd": {
        "published": "2026-07-25T10:17:16.623",
        "lastModified": "2026-07-25T10:17:16.623",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64345",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "printer_open increments the device reference before discovering that the device is busy, and the failed open has no release callback to drop it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/94ec20d97aa51547965a539f660a1fe79c6929a3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/75c0ad13e136961328253742501b4efc3988a587",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bf20c94fa6aaff945f0ae3a23f3212cd299f28d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8a5eba992c862b0c94411eecf9b7121e8636db38",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7f1f24c367938c5537e2308bf9a965f051d14774",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/30adce93d5c4a5a1ec29d9249e3fdfcc391d406b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 28
      }
    },
    {
      "cve_id": "CVE-2026-64346",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:07.680Z",
      "date_updated": "2026-07-27T04:37:30.473Z",
      "publisher": "Linux",
      "title": "usb: gadget: udc: Fix use-after-free in gadget_match_driver",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00206,
        "percentile": 0.10772
      },
      "nvd": {
        "published": "2026-07-25T10:17:16.757",
        "lastModified": "2026-07-27T05:16:42.813",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64346",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "USB gadget teardown can free the UDC management object while a concurrent driver match still dereferences it because their reference lifetimes are decoupled.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/50eeb8e8a4f389efc91b93cff14a683e714ec194",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7a5214dae906d9f58e07bc4995e8181ee74439f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d026f71df141c9b064ff32a78af5391a31ef75c2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b52476a83d9e12df00765359d728a875b128bef1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/54fa390aae393eb130f307a85562e3001cc39a52",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/67e511d2989eb1c8c588b599ce2fcc6bb8e6f7ea",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1525,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64347",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:08.338Z",
      "date_updated": "2026-07-25T08:50:08.338Z",
      "publisher": "Linux",
      "title": "usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07408
      },
      "nvd": {
        "published": "2026-07-25T10:17:16.893",
        "lastModified": "2026-07-25T10:17:16.893",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64347",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "list_first_entry on an empty configuration list yields a fabricated container pointer that the OTG handler later dereferences and copies from.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2454264b2ab4cf0055c0bfd39e79f830452bd0db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d3e72cfef2e38bd588055739a8100d14f9773b17",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8ac463fe6c0f85bdb1ce8c30e8c9e060802e4483",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/56add2b9b2e89ec61c0761165d758f73004fdfdf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/91b3ecd34b60f950c50c560974945b6596a6f207",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/01feaf024f29618d5ffa7ab0fd858e0579dcbf7b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fcb21bf747640c9d6bd1eda9da85420f076d59c1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f8f680609c2b3ab795ffcd6f21585b6dfc46d395",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1143,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:08.983Z",
      "date_updated": "2026-07-25T08:50:08.983Z",
      "publisher": "Linux",
      "title": "usb: free iso schedules on failed submit",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.069
      },
      "nvd": {
        "published": "2026-07-25T10:17:17.040",
        "lastModified": "2026-07-25T10:17:17.040",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64348",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A failed isochronous USB submit exits before linking the URB and never frees the staged schedule stored in hcpriv.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b0d00d077f9738d215af9b50c74dffab7a1de19f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be5004395dfd0b6ec310db359f887fa396fd0dd2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8890699eea19027ef6e4f9cbcf27cba5e789793f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6bc17a78a05671d303820224fb37ca339c1dc2cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4bb88aee6b868cbf73bf453f62497802f5fe4769",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b9399d25fbb34a05bbe76eeedd730f62ff2670e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1112,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:09.647Z",
      "date_updated": "2026-07-25T08:50:09.647Z",
      "publisher": "Linux",
      "title": "usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 9,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06239
      },
      "nvd": {
        "published": "2026-07-25T10:17:17.170",
        "lastModified": "2026-07-25T10:17:17.170",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64349",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "dwc3_ulpi_setup passes a register-space pointer to helpers that expect the enclosing dwc3 structure, causing incompatible pointer interpretation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/41a4e80d5af04855e68ac88f5e2cd07fa67287f8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4349e487a1149ff33b65d53427b8aca57f2e4578",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e0f844d9d74200d311c6438a0f04270834ba5365",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 846,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 9
      }
    },
    {
      "cve_id": "CVE-2026-64350",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:10.270Z",
      "date_updated": "2026-07-25T08:50:10.270Z",
      "publisher": "Linux",
      "title": "usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.069
      },
      "nvd": {
        "published": "2026-07-25T10:17:17.280",
        "lastModified": "2026-07-25T10:17:17.280",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64350",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A later allocation failure frees stream rings but leaves the previously allocated stream context array unreleased.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/37283f5a47127fbdea567749a2110766af53d18d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cb8e9391b7f4f77d112c51910cd7c355a337ef76",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fde3c095e1d48e0ac3ab8bc32905da42fe58a36a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d9643bbe93a6aee24edee1a86e0303aa74bcd320",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c00826e87bb75e14e0381b05da5f18ffd0241ab6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/963075c4da0cd43b3d17b107c355e1eb0ee64a58",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3348f444a4ce43dd5c2d1aa41634cb6eff33aa64",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 502,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:10.882Z",
      "date_updated": "2026-07-25T08:50:10.882Z",
      "publisher": "Linux",
      "title": "net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00185,
        "percentile": 0.08361
      },
      "nvd": {
        "published": "2026-07-25T10:17:17.407",
        "lastModified": "2026-07-25T10:17:17.407",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64351",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "kalmia_rx_fixup subtracts two headers from a short frame, underflows the length, and reads past the receive buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/391706889a5112feafdc0c68db3ecc7ed325d09c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aa4eef2cbb66ea3dfcfc24bdce798dd78a81b54b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2d04c37ed4e1d0f733ad39ec35b5a5d8818b4f4a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/46ab32870d010e9a057bc5659cea22b7e728ca88",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c466097d85d52f3aa200736cb4759e66d4bbf6e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e24eb271061db384a3c3ef6f107fe515e68ef222",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/51e65f1d78457ea4f9513d90ab22c9dccbb35110",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/47b6bcef6e679593d2e86e04ee72c46a4e2f7139",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 975,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64352",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:11.522Z",
      "date_updated": "2026-07-25T08:50:11.522Z",
      "publisher": "Linux",
      "title": "bpf: Allow LPM map access from sleepable BPF programs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06906
      },
      "nvd": {
        "published": "2026-07-25T10:17:17.547",
        "lastModified": "2026-07-25T10:17:17.547",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64352",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "LPM trie code uses RCU annotations that reject the Tasks Trace RCU context held by sleepable BPF programs, producing a lockdep-only warning.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f0967d4f1ba4323a3cb7dc8fdba74dd3a8caaf04",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/304ca50582f0c047370f85e13caec456f78c9fcc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ec662a8b2cde01e76b37ccd4b992d0342299e69c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9bfdf4b81b0e56d47bc6c46c34a46638be716695",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57454944737f3ad9a8703aecbbb79713b513a94b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bd6ad9a6b30498d845413e863fb95c6fab3babe3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f884d371fafea137afea504d49ee4a7c8d7985b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2660,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64353",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:12.120Z",
      "date_updated": "2026-07-25T08:50:12.120Z",
      "publisher": "Linux",
      "title": "bpf: Keep dynamic inner array lookups nullable",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06238
      },
      "nvd": {
        "published": "2026-07-25T10:17:17.700",
        "lastModified": "2026-07-25T10:17:17.700",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64353",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The BPF verifier uses an inner-map template size to mark a dynamic concrete-array lookup non-null even when the concrete map is smaller, allowing an out-of-range lookup result to be treated as valid.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0b92ad64d6e4bde85e6b9888404f9a7a2b65d269",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d57db0d975053e01410c54e708a85b6d32ef2ebd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/53040a81ae57cdca8af8ac36fe4e661730cf7c6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 741,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64354",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:12.752Z",
      "date_updated": "2026-07-27T04:59:52.875Z",
      "publisher": "Linux",
      "title": "bpf: Validate BTF repeated field counts before expansion",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02907
      },
      "nvd": {
        "published": "2026-07-25T10:17:17.810",
        "lastModified": "2026-07-27T05:16:42.943",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64354",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "BTF repeated-field count arithmetic wraps in 32 bits and lets memcpy write beyond the fixed BTF_FIELDS_MAX scratch array.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c5ff816d5f13900c3f1f3298cfcc61339e056e56",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cd407de2ef5dc70f1970b343ffaa16186340fdfd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ff77d013b737c0f77d925e2f2c59f0cf3d76bd35",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b9452b594fd3aecbfd4aa0a6a1f741330a37dab7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 729,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64355",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:13.410Z",
      "date_updated": "2026-07-27T04:59:54.016Z",
      "publisher": "Linux",
      "title": "bpf: Reject fragmented frames in devmap",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00502,
        "percentile": 0.40222
      },
      "nvd": {
        "published": "2026-07-25T10:17:17.920",
        "lastModified": "2026-07-27T05:16:43.060",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64355",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "devmap clones only the linear part of a fragmented XDP frame but preserves the fragment flag, so the free path interprets uninitialized tail data as metadata.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/47baddc856ae7e93a565dd9deeb797999b179466",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/07a4c11ee8ef4abcb39d922e9e410ae269671cdf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bccbab36ff228e0825eb85d9b0f9b8434cd0a399",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c5b4f5efcb55c1af3fe44ff712d31b7fb098a831",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a9bb2d9c798cb62a4050a991c27b752770c33afe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/51d07c12ca411e692c424ecdabf077f1e61a61be",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aa496720618f1a6054f1c870bf10b4f6c99bf656",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 875,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64356",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:14.049Z",
      "date_updated": "2026-07-25T08:50:14.049Z",
      "publisher": "Linux",
      "title": "xfs: fix memory leak in xfs_dqinode_metadir_create()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00179,
        "percentile": 0.07617
      },
      "nvd": {
        "published": "2026-07-25T10:17:18.040",
        "lastModified": "2026-07-25T10:17:18.040",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64356",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Create and commit failure paths omit releases for update, transaction, or inode references.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c3d3d2212c2966973dd7d603c6c6e6ed6fc7fbe1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/06a2e6dbaa26c0740ac76dfa66b0aedc78d05820",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/45de375b25060edf46e20abb36521ba530336ceb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1325,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64357",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:14.676Z",
      "date_updated": "2026-07-25T08:50:14.676Z",
      "publisher": "Linux",
      "title": "xfs: fix exchmaps reservation limit check",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06422
      },
      "nvd": {
        "published": "2026-07-25T10:17:18.150",
        "lastModified": "2026-07-25T10:17:18.150",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64357",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "XFS checks the pre-overhead reservation instead of the computed value before storing it in an unsigned-int transaction reservation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c597c8580d50127fc1221b5a5b653a94d49e23e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a62ef2d13d6e7270dd5e88c6082bf2d0edcd5112",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4707344b0d36d1012c8a1716e20167cd3afdd5f1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0a5213bbff62b51c7d4999ac8c7e11ea57d00d45",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 563,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64358",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:15.303Z",
      "date_updated": "2026-07-25T08:50:15.303Z",
      "publisher": "Linux",
      "title": "media: mtk-jpeg: cancel workqueue on release for supported platforms only",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 17,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06422
      },
      "nvd": {
        "published": "2026-07-25T10:17:18.253",
        "lastModified": "2026-07-25T10:17:18.253",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64358",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MediaTek JPEG release path cancels a workqueue on platforms where that work item was never initialized.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0fed0fc34ce734b4b8c2f6a467d38bddcb21dda9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ac0774961a6ea174a71d4ffa39966edafbf7662d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/973408ceab14555a8548b97c8cc7b54208c3f251",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4c4b4af4a9f278da096f0dbdb6b59594701d29bf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b1845a227fda37b2fe5327df3ca0015d7e290235",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 927,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-64359",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.782Z",
      "date_published": "2026-07-25T08:50:15.947Z",
      "date_updated": "2026-07-25T08:50:15.947Z",
      "publisher": "Linux",
      "title": "nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07401
      },
      "nvd": {
        "published": "2026-07-25T10:17:18.377",
        "lastModified": "2026-07-25T10:17:18.377",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64359",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "NILFS2 validates attacker-supplied segment numbers only after entering the locked cleaning path, allowing repeated invalid entries and warning output to hold the segment lock long enough to stall other operations.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3ed388ec3b8922383d1e2d4432d7bd4cbbf8364e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/876c98e0fc65f071680c03c2e2ee3ef7ff9ca078",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/39607452b1400c7bf748f15122df4d058b768c5b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/286f77d002a337735c0846d7480a82d9cda2aa31",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0789f0a6710713254a08f3a7d2ecbb6d1cbcf0aa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/223463c488b0554212a94de971ea538eb2805fc7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d26aef771b4f6923da9f89d6d5b70d8def5853de",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e7a690fe435f8d5ea3feb7c1d8d73ba7e8b8aa9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2397,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64360",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:16.573Z",
      "date_updated": "2026-07-25T08:50:16.573Z",
      "publisher": "Linux",
      "title": "hfs/hfsplus: zero-initialize buffer in hfs_bnode_read",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 29,
        "versionRangeCount": 25,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07411
      },
      "nvd": {
        "published": "2026-07-25T10:17:18.530",
        "lastModified": "2026-07-25T10:17:18.530",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64360",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "hfs_bnode_read() can return early without writing to the output buffer when is_bnode_offset_valid() fails or when check_and_correct_requested_ length() corrects the length to zero.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/34684a04777358b2b40ac729e54c8e45359e46b3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0b189b2204f1a2612dc68f8d139fb5b80539e710",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8f72fd25a57a457866350359ddd27a43caa62c95",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/16ca053c2be5f4f3044dccf7fc19237dc820d394",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d2afc7ecee476f9251dd87444f7fb6a424410922",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f3461b84a4865d9b5e70fbb71da72ae044a3bcd2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d5b45bad75cd2730b8452aed4d3b20a2b2a12576",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d67aadee19ffdf3cc8520c5a4f4d5b2916d30baf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 735,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 29
      }
    },
    {
      "cve_id": "CVE-2026-64361",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:17.345Z",
      "date_updated": "2026-07-27T04:59:55.178Z",
      "publisher": "Linux",
      "title": "hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 29,
        "versionRangeCount": 25,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02972
      },
      "nvd": {
        "published": "2026-07-25T10:17:18.677",
        "lastModified": "2026-07-27T05:16:43.193",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64361",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A 32-bit off-plus-length bounds calculation wraps, allowing an underflowed length to pass before a multi-gigabyte memmove.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c8dd112173c02adf539fe2ad34a45f5e0068780d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fc9d1447ca3cdc78d2e4ace1ce1f3a7c77ca08b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/671c3fcc2ad31c1311ea6414382a2d95104ae1b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b6a481642ea1977be2f84dc08c5affd742c177e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7399c3baee7bb622a92f0b895cd4d3009a693f2b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/607217f7ad419b53926f71e3f75001813bbc08ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c25d3c931a63e762fcaa9cb125b901c53b62403f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/966cb76fb2857a4242cab6ea2ea17acf818a3da7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 857,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 29
      }
    },
    {
      "cve_id": "CVE-2026-64362",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:18.008Z",
      "date_updated": "2026-07-25T08:50:18.008Z",
      "publisher": "Linux",
      "title": "HID: lg-g15: cancel pending work on remove to fix a use-after-free",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07407
      },
      "nvd": {
        "published": "2026-07-25T10:17:18.820",
        "lastModified": "2026-07-25T10:17:18.820",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64362",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The HID driver frees device-managed state on unplug without cancelling work items that later recover and dereference that state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3b9a3919aac6977262f04d5365c0456877522a44",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4aef9676c26dff8723b56834951cfc6b618f0986",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/acce9dee807f21184fff19ad17c8ed464247e7f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/33cd1a000daf929356aacf2b191d31714ff0615e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dfc6e61f83113cc18346b6988f07271c0063357d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4d0d51bc12d246accbfbb94de05d729c68c9b8fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8131f4226688c4be5f30874d167e44dab838eb09",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7705b4140d188ce22656f6e541ae7ef834c7e11a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1096,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64363",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:18.824Z",
      "date_updated": "2026-07-25T08:50:18.824Z",
      "publisher": "Linux",
      "title": "HID: appleir: fix UAF on pending key_up_timer in remove()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00211,
        "percentile": 0.11393
      },
      "nvd": {
        "published": "2026-07-25T10:17:18.960",
        "lastModified": "2026-07-25T10:17:18.960",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64363",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Apple IR teardown can free input_dev while a timer or raw-event callback remains able to dereference and rearm work against it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/89ef67359672bf4cd6921524e39f61648fe38c0f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3d30a0bb0e79621ae921b487835c56198adfafa3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/37a52c61d4f78153c38ae1f7491dfcc8ac828dcf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/05e3decc55d1deca9410e0eb36466651fcbe57a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3755f6e25776b8b12ddf062f9b573f05090e4034",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b363d964ca829c1761c9f04188dfa28f90b0f2d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6b0838e86da88b1d3bff86f19761ff25af73eaca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/75fe87e19d8aff81eb2c64d15d244ab8da4de945",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2145,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64364",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:19.441Z",
      "date_updated": "2026-07-27T04:59:56.321Z",
      "publisher": "Linux",
      "title": "HID: multitouch: fix out-of-bounds bit access on mt_io_flags",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 25,
        "versionRangeCount": 23,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00345,
        "percentile": 0.27118
      },
      "nvd": {
        "published": "2026-07-25T10:17:19.110",
        "lastModified": "2026-07-27T05:16:43.347",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64364",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The HID driver treats one unsigned long as a bitmap indexed by an attacker-reported contact count up to 255, corrupting adjacent structure members past that word.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/12e90656e330ff8bbaf2f29c535fdb8a11cc6f55",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/152983d87387f6a8ae72b73474cfa55fbcf1ec75",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b5c037d6b807017e74a115288f81bc9cd5a5aab8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e24918ee67c4dc3d20d4670750e46e9b160365f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/37daa8c96bd563d03150e23f094cb60703594a6d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6493ebf9489efef0105078377b973ab33d51af22",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8813b0612275cc61fe9e6603d0ee019247ade6be",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1920,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 25
      }
    },
    {
      "cve_id": "CVE-2026-64365",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:20.039Z",
      "date_updated": "2026-07-25T08:50:20.039Z",
      "publisher": "Linux",
      "title": "HID: letsketch: fix UAF on inrange_timer at driver unbind",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06905
      },
      "nvd": {
        "published": "2026-07-25T10:17:19.280",
        "lastModified": "2026-07-25T10:17:19.280",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64365",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Driver teardown frees device and input objects without draining a timer whose callback still dereferences them.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2bb6e7143cf70ed281822d26c1848b2897ac36e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/523db788c0f84612707638e266e8957ca7e3a756",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/17f5928d7010bc9e002930326b59e60e40c09ee3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3eca1a8165b5e7996e699e9df76cb4645e184d42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/df3d8aa1a9392da3de66398e7a03422463806b21",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/46c8beeccd8ab2c863827254a85ea877654a3534",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1656,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64366",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:20.612Z",
      "date_updated": "2026-07-27T04:59:57.437Z",
      "publisher": "Linux",
      "title": "HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16832
      },
      "nvd": {
        "published": "2026-07-25T10:17:19.403",
        "lastModified": "2026-07-27T05:16:43.517",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64366",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An empty FIFO path reuses a stale length, corrupting parser state and allowing an out-of-bounds write.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ca899a926c11a59211b764b0155d9a1cdcc32b81",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57bdd10ad50d68341f500a7b330f0d8949e510ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6b3014ec0e9a390ca563030b2d7689921f0daef5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 962,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64367",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:21.214Z",
      "date_updated": "2026-07-27T04:59:58.577Z",
      "publisher": "Linux",
      "title": "HID: hid-goodix-spi: validate report size to prevent stack buffer overflow",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.03976
      },
      "nvd": {
        "published": "2026-07-25T10:17:19.510",
        "lastModified": "2026-07-27T05:16:43.640",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64367",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "goodix_hid_set_raw_report copies a caller-sized report into a fixed 128-byte stack buffer without checking the remaining capacity.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ad47ad624f2fce0bc44bbadb664242461a97d774",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dae1d000ddfd5c2140b036e47fff0c497ae9c64b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/835fcc8655569737e3f057d42875a96259db74c2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/db0a0768d09273aadadeb76730cd658d720333a4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 806,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64368",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:21.831Z",
      "date_updated": "2026-07-27T04:59:59.923Z",
      "publisher": "Linux",
      "title": "mm/slab: do not limit zeroing to orig_size when only red zoning is enabled",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.3433
      },
      "nvd": {
        "published": "2026-07-25T10:17:19.613",
        "lastModified": "2026-07-27T05:16:43.820",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64368",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "With red zoning enabled but requested-size tracking disabled, the slab allocator zeros only orig_size and violates the full-object __GFP_ZERO guarantee used by krealloc.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6256899c3a34674bba6076884aedbba49fc695e4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7e706d50fa119eead6376bf0ef973e8d73a96030",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2382971aaaef5bf85a651234c64906f59580b8be",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0d18ccef142f04433dfb2a0c120cf223d2b8a42c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/648927ceb84021a25a0fbd5673740956f318d534",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1105,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64369",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:22.543Z",
      "date_updated": "2026-07-25T08:50:22.543Z",
      "publisher": "Linux",
      "title": "s390: Revert support for DCACHE_WORD_ACCESS",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00181,
        "percentile": 0.07852
      },
      "nvd": {
        "published": "2026-07-25T10:17:19.743",
        "lastModified": "2026-07-25T10:17:19.743",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64369",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An unaligned cross-page access to donated secure memory enters an exception path that cannot resolve and loops indefinitely.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c9e0f1517631ac08987f8385817119bccf2f1f12",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be79d285bea70d0edd5015bd487311bfa8cbebc9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c94806905e02cc8e17a69c822d93c41743b7ffc5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/37540b8c287fc817bdbd0c62bb75ad6eab0e5d03",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1011,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64370",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:23.257Z",
      "date_updated": "2026-07-25T08:50:23.257Z",
      "publisher": "Linux",
      "title": "posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07405
      },
      "nvd": {
        "published": "2026-07-25T10:17:19.880",
        "lastModified": "2026-07-25T10:17:19.880",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64370",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The CPU nanosleep error path returns after timer setup failure without releasing the pid reference acquired during timer creation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/afed3cdc1cca133f804fcf57ff228974f424b23a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8a270b1258797f61b61da44f8bfd41a581b5c85b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d605d00085adc3fddf67de01dc2a44aebf1a3fb5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e5ffc638faf5dc7d9dc85c9a95e10bf97442e0c0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eb4cec29a78334d09bcfb41c0660cdd62ba05843",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7776f9226e99eb49d97492b0b445027cfcb189da",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8f06363446c5d043c9a7c008b250040e9de98cf9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/87bd2ad568e15b90d5f7d4bcd70342d05dad649c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 578,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64371",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:23.981Z",
      "date_updated": "2026-07-25T08:50:23.981Z",
      "publisher": "Linux",
      "title": "proc: protect ptrace_may_access() with exec_update_lock (part 1)",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 22,
        "versionRangeCount": 19,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07405
      },
      "nvd": {
        "published": "2026-07-25T10:17:20.010",
        "lastModified": "2026-07-25T10:17:20.010",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64371",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Procfs authorization checks race process exec state because several ptrace_may_access call sites omit exec_update_lock protection.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ae1e630bcaac739f625822078edbaea98366930d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d54f14655fd7d7b293698a8b6918563c4c0465e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bb43679356f1f2a4c6b1c88aec4f021e5b5c74e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7456ae990a9738962b33146916fabca62ae3d4e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4bfe8c481846cee52473a2f7d7b30ee8e6749fc4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f9b4b03ccc9c69bf7f7298d4559906ebea7143b3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c1cfd63326f5d09999134e9052c353faf738286e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6650527444dadc63d84aa939d14ecba4fadb2f69",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 619,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 22
      }
    },
    {
      "cve_id": "CVE-2026-64372",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.783Z",
      "date_published": "2026-07-25T08:50:24.733Z",
      "date_updated": "2026-07-27T05:00:01.364Z",
      "publisher": "Linux",
      "title": "cpufreq: pcc: fix use-after-free and double free in _OSC evaluation",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02635
      },
      "nvd": {
        "published": "2026-07-25T10:17:20.147",
        "lastModified": "2026-07-27T05:16:43.950",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64372",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "pcc_cpufreq_do_osc frees the first ACPI result but retains its pointer and length, so the second evaluation writes into freed memory and later frees it again.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8e454e9d0bc03446d610ee49abec9dfd424f6541",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/632666a63116d8061c62a988d1ca39dcd6d27c9b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5cdb25f144b101083d8bf3fd023ad87fbe6850d7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/982c9f92d57bda2b769851ff6d90d43dcf5f3734",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a36ca93a8ba57464e521d70a337d37f069064111",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ba6f6783be2ffeb2cbcdc9321c4b9f708f796f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e3c739a2f6fc1de5b19a8839ab80696b9cb2a29",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/266d3dd8b757b48a576e90f018b51f7b7563cc32",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 757,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64373",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:25.427Z",
      "date_updated": "2026-07-25T08:50:25.427Z",
      "publisher": "Linux",
      "title": "cpufreq: Fix hotplug-suspend race during reboot",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 28,
        "versionRangeCount": 22,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07407
      },
      "nvd": {
        "published": "2026-07-25T10:17:20.283",
        "lastModified": "2026-07-25T10:17:20.283",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64373",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "CPU hotplug can free cpufreq governor_data while the reboot-time suspend path accesses it because that path lacked the CPU read lock.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6d5dd354c37abaf4d60400c55c71f23ba2b33639",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9103078c7b3091a2fbb52af176f95982ee7dd7f8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cd4524ff6567fa4458a5bec4b017105e671d393e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/73255d702c7560185fd5951aadcf7eb057c2f453",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a0ef2fc89d28ca62923376c4b8ffaa57136a36be",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6e175c00c62dca3d91b987015808b5d52e8db2b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a0106b41f9a724868d390b8b3b4ea5ca0e04ea53",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a9029dd55696c651ee46912afa2a166fa456bb3e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1053,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 28
      }
    },
    {
      "cve_id": "CVE-2026-64374",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:26.130Z",
      "date_updated": "2026-07-27T05:00:02.525Z",
      "publisher": "Linux",
      "title": "sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00501,
        "percentile": 0.40145
      },
      "nvd": {
        "published": "2026-07-25T10:17:20.433",
        "lastModified": "2026-07-27T05:16:44.083",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64374",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Repeated RT_PUSH_IPIs indefinitely postpone softirq completion and keep the CPU in a livelock.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b99f04ae3d200d2f8844aa29145bd18eccbeecde",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d8312a56d9a162e3ec76476aa487e7d20bc602e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/44aae426dbfd51286f7eb601cfa14bc32164812a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/860aaff72c8446fed5e576249e19952883a18885",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/89237c8fc15d8016a194076e648ccb57d75e65ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4bd0da48fbc1dbef6774175129107fbbdd353e26",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a18f80bf5359238c4f067d691b96af00286fdd89",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dd29c017aed628076e915fe4cdfb5392fd4c5cab",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3572,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64375",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:26.869Z",
      "date_updated": "2026-07-27T05:00:03.722Z",
      "publisher": "Linux",
      "title": "proc: protect ptrace_may_access() with exec_update_lock (FD links)",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02972
      },
      "nvd": {
        "published": "2026-07-25T10:17:20.593",
        "lastModified": "2026-07-27T05:16:44.250",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64375",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The proc file-descriptor link path checks ptrace access on one task lookup and performs access through a second lookup without locking the task across both.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6253dfee5afba536bb54fc6fe6c091c3758fafe1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/65bf0d2b6e914f1448d6a2fde193dcf60936a651",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/de497d7aa2fae453a7e7c8f7d3e8682e565e3aaf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/138c692d2b2d63d26f2eb957d0e4fcc5d61f9ff2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/83b17872e3166c295c599279fc9562ac3840c638",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/497c6bae5167428596575f20af6613ff5671f383",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dfd1894cb64cbd8758b461ed713800fe73db4f82",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6255da28d4bb5349fe18e84cb043ccd394eba75d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 606,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64376",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:27.577Z",
      "date_updated": "2026-07-25T08:50:27.577Z",
      "publisher": "Linux",
      "title": "firmware_loader: fix device reference leak in firmware_upload_register()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06905
      },
      "nvd": {
        "published": "2026-07-25T10:17:20.717",
        "lastModified": "2026-07-25T10:17:20.717",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64376",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The firmware loader retains a device reference after the operation ends and never releases it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/517676ec7dfca064e08f94007a4abd21969de0a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/46d403da376a8b7c1187193294953816e1a8d7fe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2619b47a0c8114eef980a56ade7e3ef4b58eb384",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/92f41769e5fd16bcd9ba97500d0517332e0a5b45",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/15432f19562fdb9199cce6d9fc24db12c71ed574",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/896df22ee57648b0c505bd76ddbc6b2341834696",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1039,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64377",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:28.299Z",
      "date_updated": "2026-07-25T08:50:28.299Z",
      "publisher": "Linux",
      "title": "cpufreq: qcom-cpufreq-hw: Fix possible double free",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06423
      },
      "nvd": {
        "published": "2026-07-25T10:17:20.837",
        "lastModified": "2026-07-25T10:17:20.837",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64377",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "qcom_cpufreq frees a devm-managed array element manually, allowing device detach to free the same allocation again or freeing a pointer that is not the allocation base.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/28a03a3f6e6cda0b0da3b43761d175dec5d14d13",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e904961332801c87355f5d11c65bb433e717c489",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9de568ef6cdfc7912d5ea8db02843c0e4ef0c75d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bcb8889c4981fdde42d4fd2c29a77d510fe21da2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 864,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64378",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:29.006Z",
      "date_updated": "2026-07-27T05:00:04.907Z",
      "publisher": "Linux",
      "title": "writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 16,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02962
      },
      "nvd": {
        "published": "2026-07-25T10:17:20.940",
        "lastModified": "2026-07-27T05:16:44.393",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64378",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unmount can destroy writeback state after an inode switch passes its active check but before that switch queues its work.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/087d5b8b501c570f84bf655164e6698c3ce146e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3c9c9648f77e4d14e50676bc51c2174ba9c8d361",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5c3265f3252b2ee50707adaaa3f9bd0df3df72de",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c923cc3cb5cd8945ceaf08252754110643446593",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/685fc15a410885b6d4dee64de0dce721b9428b12",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/53eeaf4d63068dbc7708b0c7adb20151c812feca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3274,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64379",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:29.717Z",
      "date_updated": "2026-07-27T05:00:07.664Z",
      "publisher": "Linux",
      "title": "smb: client: mask server-provided mode to 07777 in modefromsid",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00309,
        "percentile": 0.23242
      },
      "nvd": {
        "published": "2026-07-25T10:17:21.090",
        "lastModified": "2026-07-27T05:16:44.557",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64379",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SMB client applies an unmasked server-supplied NFS mode SID, permitting bits outside the intended 07777 permission domain.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5f6f2241034f189c69d4d0b5f8fe24a0c25b0c14",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ee2216dbdf0c677e89bb43e03247dba590ed00ef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f511807feee7cb29b61bdfa86472c7e9e2e5df94",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/08c600b7e1818539ba5efee4cdb06215c245ca78",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b84e002e0df26bbc6cbd3ca01b8212601fe0ae7d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c6c484a7d5bff6b929a86d7ed5130f29834c6a0d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f80add1bfb3425100a325b14f19648e75669a954",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e3d9c7160d483fc8f9e225aafad8ecbbc43f3151",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64380",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:30.476Z",
      "date_updated": "2026-07-27T05:00:08.926Z",
      "publisher": "Linux",
      "title": "smb: client: harden POSIX SID length parsing",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00443,
        "percentile": 0.36426
      },
      "nvd": {
        "published": "2026-07-25T10:17:21.220",
        "lastModified": "2026-07-27T05:16:44.690",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64380",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SID parser trusts an encoded length that exceeds the available object and reads beyond the supplied buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/171605aed68380c2fa75dff9b3a1ed427c50065b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4213c1208978483021d7d125c131de3985d38f61",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/96e889bc1e759c83f25093e8c2f3da31b4973f30",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0de5b8e76847f5de26f364a82c6602c4881c30da",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/427eb7eb46425fec845a43e861f3d6e2899cae59",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/86c5d470f5d42e61123b2f4b4f0b91f4eee5b980",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/46a84715a015cb48e1b9c219dc88c03d8a541ea4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7ad2bcf2441430bb2e918fb3ef9a90d775a6e422",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 385,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64381",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:31.209Z",
      "date_updated": "2026-07-25T08:50:31.209Z",
      "publisher": "Linux",
      "title": "smb: client: Fix next buffer leak in receive_encrypted_standard()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07405
      },
      "nvd": {
        "published": "2026-07-25T10:17:21.347",
        "lastModified": "2026-07-25T10:17:21.347",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64381",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "receive_encrypted_standard allocates next_buffer before enforcing MAX_COMPOUND and returns on the limit path without attaching or freeing the buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/94e4f672db029414b9888b5137a7559f1febf2d8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/68fc0b6cc03ca58060c0f36454e169f5fe258974",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/07e0ab81df1790afa35732a4e8e07ff831b29008",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9136a08dc29328edd9867f2545e73906ac9df93b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/67097772df7791c53d608f04bd31c676ccf79b83",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/297243e365fc9fe2f8e9b7dd535a65d922cd108b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/927d4805aea0a287d36dd4f826ee24d69a2afee3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1c6267a1d5cf4c73b656f8181b310cbbb3e4767b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64382",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:31.937Z",
      "date_updated": "2026-07-27T05:00:10.074Z",
      "publisher": "Linux",
      "title": "smb: client: fix double-free in SMB2_open() replay",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 13,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28115
      },
      "nvd": {
        "published": "2026-07-25T10:17:21.477",
        "lastModified": "2026-07-27T05:16:44.823",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64382",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SMB2_open retry cleanup retains stale response-buffer state and can free the same response a second time after initialization fails.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/02bc2896bdc3e29362d6e40d404006944a159c25",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3196b5192f246df4272072f61a2f4a3e9967f55d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/14498ff5ce0f272ce0ef988721413e06b7038972",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ff2d30927bc3bf3c629f0768d2068096e64ef5ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b55e182f2324bc6a604c21a47aa6c448f719a532",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 402,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-64383",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:32.634Z",
      "date_updated": "2026-07-27T05:00:11.278Z",
      "publisher": "Linux",
      "title": "smb: client: fix double-free in SMB2_flush() replay",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 13,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00457,
        "percentile": 0.37417
      },
      "nvd": {
        "published": "2026-07-25T10:17:21.587",
        "lastModified": "2026-07-27T05:16:44.947",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64383",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SMB2_flush carries a response pointer across replay attempts and frees the stale pointer again when the retry fails before replacing it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6e27f40b682a5e42a2daae3ce6d96f0e0e16dedb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/878757163eea684750107a31ea134c103863515d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3407240cde132a4b72d6429a2625a09a2f78adaf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/013a9a3da46c5dabcf18f65ea6a47874ba12a15d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4be31c943a3a27a5a0251dbb8f5cb89059ec3d5a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 606,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-64384",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:33.306Z",
      "date_updated": "2026-07-27T05:00:12.445Z",
      "publisher": "Linux",
      "title": "smb: client: fix change notify replay double-free",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 13,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00457,
        "percentile": 0.37417
      },
      "nvd": {
        "published": "2026-07-25T10:17:21.700",
        "lastModified": "2026-07-27T05:16:45.087",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64384",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SMB change-notify replay path retains stale response bookkeeping and frees the same response buffer again after a later initialization failure.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5821f9dbb8b5b24391850a13418e633edd0fb003",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d684f4134998085702009b94c35c2003fc9e72d3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/52af1975f0dfae990c5a0e85872cc41be0e88a68",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/901891513951bc8322ece754863909ea45af95c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/145f820dcbb2cced374f2532f8a61a44dce4a615",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-64385",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:33.997Z",
      "date_updated": "2026-07-27T05:00:13.594Z",
      "publisher": "Linux",
      "title": "smb: client: fix double-free in SMB2_ioctl() replay",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 13,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00457,
        "percentile": 0.3742
      },
      "nvd": {
        "published": "2026-07-25T10:17:21.810",
        "lastModified": "2026-07-27T05:16:45.203",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64385",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An SMB2 ioctl retry frees a response but retains stale response bookkeeping, so initialization failure on the next attempt frees the same buffer again.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0be4bc64882edaefaaee8d1e27d083643eb778e6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/96fcfc8ae7359346156e492ca610e830d2649ad6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/276c8efbc49f9303ac76d0d4deab7128581b0f3b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fc65ffb4ef1bf540da16b17c225ae51091e07d72",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f9bbadb6c94583e3b4af1afc449bfceb1d1ddec9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 404,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-64386",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:34.729Z",
      "date_updated": "2026-07-27T05:00:14.821Z",
      "publisher": "Linux",
      "title": "smb: client: fix query_info() replay double-free",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 13,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00457,
        "percentile": 0.37416
      },
      "nvd": {
        "published": "2026-07-25T10:17:21.917",
        "lastModified": "2026-07-27T05:16:45.323",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64386",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A replayable SMB error frees a response buffer while stale response bookkeeping causes cleanup to free the same buffer again.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/100fb7c455fa86d248b8bd7bb9de757c192870b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3c81dda84799f76b42aec598564316e2964440db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f1add4acb656f5a82806a1ab0e63fed3d8b1bfca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/89234773e8348918111aa15f6922b58cf3843364",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2a88561d66eb855813cf004a0abe648bbb17de5e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-64387",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:35.543Z",
      "date_updated": "2026-07-27T05:00:15.962Z",
      "publisher": "Linux",
      "title": "smb: client: fix query directory replay double-free",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 13,
        "versionRangeCount": 12,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00457,
        "percentile": 0.37417
      },
      "nvd": {
        "published": "2026-07-25T10:17:22.020",
        "lastModified": "2026-07-27T05:16:45.450",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64387",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SMB query-directory retry cleanup retains stale response bookkeeping and frees the same response buffer twice.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3409aedf3c81a810243da94164f6621c9d205c98",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1665f25b1dea30bf2d02e16245d203a944c9d994",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/00b0fa425941438b664950a8ee65dfba2def4336",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3317a5d015fca976475aa71df224056777316fde",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9647492b5e41954be59d5157eddbcd4cdc1656f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 414,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 13
      }
    },
    {
      "cve_id": "CVE-2026-64388",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.784Z",
      "date_published": "2026-07-25T08:50:36.202Z",
      "date_updated": "2026-07-27T05:00:17.102Z",
      "publisher": "Linux",
      "title": "smb/client: fix chown/chgrp with SMB3 POSIX Extensions",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02187
      },
      "nvd": {
        "published": "2026-07-25T10:17:22.127",
        "lastModified": "2026-07-27T05:16:45.570",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64388",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SMB3 POSIX setattr path ignores requested UID and GID changes unless unrelated CIFS mount flags are also set.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/550cfb8a81181331d4d0f76ab75ee58a0bf41e3e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/760ef2c579c2609cf17fb1cd5392f64d42d43d33",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 518,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64389",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:36.817Z",
      "date_updated": "2026-07-27T05:00:18.260Z",
      "publisher": "Linux",
      "title": "ksmbd: validate NTLMv2 response before updating session key",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37147
      },
      "nvd": {
        "published": "2026-07-25T10:17:22.227",
        "lastModified": "2026-07-27T05:16:45.683",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64389",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ksmbd stores a derived NTLMv2 session key before validating the NTLMv2 response and continues key exchange after validation failure, allowing rejected authentication data to alter an existing session.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b56400364aed5c34d6e1a0b493081290a5328a9c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/89ca7756d5566ba636bb9092cdbe57dab095e136",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/954d196bebb2b50151cb96454c72dc113b2af1ac",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1305,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:37.406Z",
      "date_updated": "2026-07-27T05:00:19.433Z",
      "publisher": "Linux",
      "title": "ksmbd: track the connection owning a byte-range lock",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00467,
        "percentile": 0.38058
      },
      "nvd": {
        "published": "2026-07-25T10:17:22.330",
        "lastModified": "2026-07-27T05:16:45.810",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64390",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SMB multichannel removes a byte-range lock under a different connection's spinlock from the list that owns it, allowing concurrent access after free.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/22d38cf75b556c20b039743bdf3654d535b858be",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/66eb3643164e5e1029907793926c132f8b5c6148",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ea5c9bf99f626a15cc59f645dc895f2b3f01992e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fe20d492a69a6f79e637f438072b212e21ed3b78",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/427faaa52b0b399940c1a88065a5c310d10dad15",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5fecc15a30cb9ebd310f7b52c1ab607edcea78f6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c1016dd1d8b2bcd1158bbaabe94a31bb7e7431fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 999,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:38.013Z",
      "date_updated": "2026-07-27T05:00:20.631Z",
      "publisher": "Linux",
      "title": "ksmbd: use opener credentials for ADS I/O",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00457,
        "percentile": 0.37416
      },
      "nvd": {
        "published": "2026-07-25T10:17:22.453",
        "lastModified": "2026-07-27T05:16:45.943",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64391",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ksmbd performs alternate-data-stream xattr I/O with the current worker credentials instead of the credentials captured when the SMB handle was opened.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a8f5d39971bbad9340d49cd41b0e2da9452a649d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2b4592cea214683de0f2ce6f8c22c097fb0ea1ab",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/52a56cf53ec834c44ac1b4d16d585f26613ee5ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/baa5e094886fffa7e6272edcb5e08be5ce28262c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64392",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:38.634Z",
      "date_updated": "2026-07-27T05:00:21.820Z",
      "publisher": "Linux",
      "title": "ksmbd: use opener credentials for delete-on-close",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00469,
        "percentile": 0.3813
      },
      "nvd": {
        "published": "2026-07-25T10:17:22.557",
        "lastModified": "2026-07-27T05:16:46.063",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64392",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Deferred delete-on-close teardown runs under worker credentials instead of the credentials of the opener who requested deletion.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f08b3f451f12eee4abd8a5981803bc36db84458b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/18c59109bb6fb816d5102171666f87cf1e29901d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e72c15085b6d86f45d224d98aa75b5cace4aaab9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4b7059974549d278e30fe70e2a4e421f9839817d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/52e2f21911158ec961cd5aae19c56460db382af0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 589,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64393",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:39.239Z",
      "date_updated": "2026-07-27T05:00:22.986Z",
      "publisher": "Linux",
      "title": "ksmbd: run set info with opener credentials",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00479,
        "percentile": 0.38811
      },
      "nvd": {
        "published": "2026-07-25T10:17:22.663",
        "lastModified": "2026-07-27T05:16:46.190",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64393",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ksmbd SET_INFO validates the SMB handle but runs path-based VFS permission checks with worker credentials instead of the opener's credentials.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5cbabf3a71575cd31bc7785d92d4ab42338a654b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b35afd5cf8fab236ef21117e42ee45691d4ffa7b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0ce682867fd506f61f40c76bde7e4205bde34e87",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/20ee516a62989a8d505ee432f9e59525ea23984e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8cc9ec711f5255167247a9ab6a7179b787426ed7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b383bcad3d2fe634b26efbce53e22bbb5753a520",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 687,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:39.797Z",
      "date_updated": "2026-07-27T05:00:24.660Z",
      "publisher": "Linux",
      "title": "ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0047,
        "percentile": 0.38207
      },
      "nvd": {
        "published": "2026-07-25T10:17:22.790",
        "lastModified": "2026-07-27T05:16:46.327",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64394",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ksmbd processes SMB2 SET_INFO SECURITY without requiring WRITE_DAC or WRITE_OWNER on the selected object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0848b1d8b403f530878195dcbe241a2fddb9d0e1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e6aa731f1b4b3e08caebf66a99f04b22bdab2e99",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9ab2ffd3ed3d4ca1667c52de27026ddabc11e537",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f56535db508ead8dec1c481ad93d7d8acd8f8f1e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aae600cdaffc6d9ce97645f129799a103a97d06d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/44df157a1183a7f746caa970c169255da5ac61f8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1734,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:40.393Z",
      "date_updated": "2026-07-27T05:00:25.842Z",
      "publisher": "Linux",
      "title": "ksmbd: require source read access for duplicate extents",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00406,
        "percentile": 0.33388
      },
      "nvd": {
        "published": "2026-07-25T10:17:22.923",
        "lastModified": "2026-07-27T05:16:46.473",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64395",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "ksmbd clones file contents from a source handle without requiring FILE_READ_DATA on that handle.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2d2ab6983620c2d60ce7db72133984ca3873b929",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/67bdad9cf01b25030e3bf00bbce6c309319d6663",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b0d4d5cb846a1ddb7aaab9adfb5986e4540e6e5f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/db231af842868268839f9f9619c68cb27830d8be",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a10942af27832c2761d020863a46e79bebe0567d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cedff600f1642aa982178503552f0d007bc829c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 543,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:40.993Z",
      "date_updated": "2026-07-27T05:00:26.968Z",
      "publisher": "Linux",
      "title": "ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00435,
        "percentile": 0.35785
      },
      "nvd": {
        "published": "2026-07-25T10:17:23.040",
        "lastModified": "2026-07-27T05:16:46.603",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64396",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "If the lock waiter is subsequently woken up but the work state is no longer KSMBD_WORK_ACTIVE (e.g., due to a concurrent cancellation), the cleanup path calls locks_free_lock(flock) without dequeuing the work from the async_requests list.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/367c42a611fe488b7b03f1f6737f4dee0e8b20a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7703fd9aba1f2483c8e55f9ff73b7663e0761ed9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/463bbd79698513af4dad50fe1c573825f297ca2e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5aa1cb01155f96824003baf7997cdf1f150caba3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5c75275c0fc9a2deb0d8f5604edcb16f288171c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d20d1c8ba5765d1d12eefc0aee6385ab3f240e1e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1268,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:41.620Z",
      "date_updated": "2026-07-27T05:00:28.217Z",
      "publisher": "Linux",
      "title": "ksmbd: serialize QUERY_DIRECTORY requests per file",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00477,
        "percentile": 0.38723
      },
      "nvd": {
        "published": "2026-07-25T10:17:23.160",
        "lastModified": "2026-07-27T05:16:46.740",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64397",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrent QUERY_DIRECTORY calls replace a shared pointer to stack-private enumeration state while an earlier callback still uses it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1426fd79102539bc0ab5c8fced047ad4313b9908",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2a64dbf9c739ddf7a25a066507597bf89f8f73d2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/64dac2d486ec1eb18dc00968b16a230b6b75ec24",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a1d5d31cad593ea5e1b637f2f39c9ef6d09d1199",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fd22b039a5a05bc1d6818e9dcd1001fb432a829d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be6d26bf27499977c746abc163659915082348d8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 759,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:42.221Z",
      "date_updated": "2026-07-27T05:00:29.523Z",
      "publisher": "Linux",
      "title": "ksmbd: add a permission check for FSCTL_SET_ZERO_DATA",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00464,
        "percentile": 0.37869
      },
      "nvd": {
        "published": "2026-07-25T10:17:23.280",
        "lastModified": "2026-07-27T05:16:46.877",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64398",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SMB SET_ZERO_DATA path checks only share writability and not the handle's FILE_WRITE_DATA right before zeroing file contents.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/25377f369688dd0bd814dc8965ed26d44238ecaa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3072d82461f498c85daea8766e9d8bfbada31605",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ca53bb17f4e8232cfaece3953d3cef62c559b039",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57f2042fd87d7ce8fc3ac8b6c176e554df68b1a7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/deffa929086d7902e30918adf3dd27ccfe9c08b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3320ba068198adc144c89d6661b805acce01735b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1089,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:42.925Z",
      "date_updated": "2026-07-27T05:00:30.802Z",
      "publisher": "Linux",
      "title": "ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00491,
        "percentile": 0.3955
      },
      "nvd": {
        "published": "2026-07-25T10:17:23.397",
        "lastModified": "2026-07-27T05:16:47.010",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64399",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ksmbd duplicate-extents ioctl writes destination data without checking either share writability or FILE_WRITE_DATA on the destination handle.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bf460ad5958d506492de4524a656439da3f99c51",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/620d133d469295ee7c017ca6aafac335f65c4a5a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9b9cf7e65cbeaae1b6636144bacee611cdd7a5d6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/baae7b39673ec21073a25e3d14f8feaada01d5df",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c917e4522d251071dde9871b9142d8ea1186ebfe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/388e4139db27a9e3612c9d356b826f5b1ff6a9e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 755,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:43.655Z",
      "date_updated": "2026-07-27T05:00:31.935Z",
      "publisher": "Linux",
      "title": "ksmbd: prevent path traversal bypass by restricting caseless retry",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00357,
        "percentile": 0.28392
      },
      "nvd": {
        "published": "2026-07-25T10:17:23.510",
        "lastModified": "2026-07-27T05:16:47.173",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64400",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The caseless retry treats a LOOKUP_BENEATH traversal rejection like a missing file and reconstructs a path outside the share root.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8c9a4f1327eb71efbf14842e7b8a6d965077eb67",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/54bab9ba5a9f156ffa9324fcbe5a356fd0242f95",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1067,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64401",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:44.361Z",
      "date_updated": "2026-07-27T05:00:33.097Z",
      "publisher": "Linux",
      "title": "smb: client: resolve SWN tcon from live registrations",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02636
      },
      "nvd": {
        "published": "2026-07-25T10:17:23.610",
        "lastModified": "2026-07-27T05:16:47.303",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64401",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A cached tcon raw pointer outlives the mount that owns it and is later dereferenced.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/51d18db392e5386a7bb9e816d611f14e600cca3c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aa3c0cab4b28c5007ec570c63e1d6ad6943ed0fd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/945b4a4a54497db1dcb2f20ef801a84e884dac21",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/91b8a58c6ac15c7db6518f696389933282f88da7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0700f946659d0ab2352ec8a9b1c6fc74b13a27d7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ec457f9afe5ae9538bdcd58fd4cb442b9787e183",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2013,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64402",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:45.075Z",
      "date_updated": "2026-07-27T05:00:34.312Z",
      "publisher": "Linux",
      "title": "coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02901
      },
      "nvd": {
        "published": "2026-07-25T10:17:23.737",
        "lastModified": "2026-07-27T05:16:47.443",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64402",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "smb_sync_perf_buffer derives its first destination page index from an unnormalized head value and writes beyond dst_pages.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/38dbc8db8341ccdf8e1e1a067453d33ad751864b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4c5a0a946373da99a80398289b28845b5ae40cd1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/661a019ac0413ecec9e5d1dfcc12fbca8e78d5fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/daf6246ab988fc8bdc82ad7c8d0b1c182d11b15f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/98495b5a4d77dd22e106f462b76e1093a55b29a7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 775,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64403",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:45.796Z",
      "date_updated": "2026-07-27T05:00:37.177Z",
      "publisher": "Linux",
      "title": "Bluetooth: L2CAP: validate option length before reading conf opt value",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 32,
        "versionRangeCount": 24,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00265,
        "percentile": 0.18236
      },
      "nvd": {
        "published": "2026-07-25T10:17:23.850",
        "lastModified": "2026-07-27T05:16:47.560",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64403",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "l2cap_get_conf_opt dereferences the attacker-sized option value before callers establish that the full option remains inside the packet buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cca81b4bc672604a84f6d224a55cc77ec7dee619",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f70d4aa88068096f35d73e3a05eff33c0a16b9cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7d871e969b941ce25653f7716203a0ea4d07ad4b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/98d93c226bdfaa79bbdd86981921d7f106374225",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/996d3da39899aceb8f4910911a3f19a45a7d9d1b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/73abbaf91aa33da87c008fb62c148ade561bb606",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6b47bdaacfd0045687880177e0987055d8f4765a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/687617555cedfb74c9e3cb85d759b908dcb17856",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1294,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 32
      }
    },
    {
      "cve_id": "CVE-2026-64404",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.785Z",
      "date_published": "2026-07-25T08:50:46.523Z",
      "date_updated": "2026-07-25T08:50:46.523Z",
      "publisher": "Linux",
      "title": "Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 11,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06423
      },
      "nvd": {
        "published": "2026-07-25T10:17:24.003",
        "lastModified": "2026-07-25T10:17:24.003",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64404",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "iso_conn_big_sync drops the socket lock and later dereferences conn without rechecking whether controller-driven teardown cleared it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b3e647a4aa4d2d054f86a783f5c426035e1dc237",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b84eeb7636d6962dd882d5e0b31475e4f404313c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/01afd198c2c286cd3b81f44d4e33a2e638711550",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d5541eb148da72d5e0a1bca8ecd171f9fc8b366f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1115,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-64405",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:47.262Z",
      "date_updated": "2026-07-25T08:50:47.262Z",
      "publisher": "Linux",
      "title": "Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 19,
        "versionRangeCount": 16,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06903
      },
      "nvd": {
        "published": "2026-07-25T10:17:24.110",
        "lastModified": "2026-07-25T10:17:24.110",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64405",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "hci_abort_conn dereferences hdev->sent_cmd while that pointer can be null even though the request status remains pending.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/903227b6168bb99fd57d4e3c9c1b5014986198e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/83b22d7f7c384564fa42c3cf19bec715c693d7a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/70c397b62ee015e19b3924d9da741c8dda017819",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/61701912c58a05f6a043f097cc177a964abef348",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b42cb640a0493d16b61ddd267420274be15efdc1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/12917f591cea1af36087dba5b9ec888652f0b42a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1767,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 19
      }
    },
    {
      "cve_id": "CVE-2026-64406",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:47.978Z",
      "date_updated": "2026-07-27T05:00:38.367Z",
      "publisher": "Linux",
      "title": "Bluetooth: fix UAF in bt_accept_dequeue()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 26,
        "versionRangeCount": 24,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19591
      },
      "nvd": {
        "published": "2026-07-25T10:17:24.243",
        "lastModified": "2026-07-27T05:16:47.730",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64406",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Bluetooth dequeue drops its temporary socket reference before unlink drops the queue reference, allowing the final later hold to touch freed storage.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c0577c55219be42b6ea2ea8db11e85bfab6f4e8d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/96ad400d5132eb333f28f6f1e2d58f0728ca9547",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c66a95e60b65d876a927123b0ed36bd6177d9ca6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6303ed4bbe0095f4cc195225479bf506e010d1db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/26168db1ce5a9766cde021b18e590a101c056614",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/50c662bdcd51b03033a0abed6716bfd377ba1049",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4bd0b274054f2679f28b70222b607bb0afc3ab9a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 661,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 26
      }
    },
    {
      "cve_id": "CVE-2026-64407",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:48.912Z",
      "date_updated": "2026-07-25T08:50:48.912Z",
      "publisher": "Linux",
      "title": "Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06417
      },
      "nvd": {
        "published": "2026-07-25T10:17:24.407",
        "lastModified": "2026-07-25T10:17:24.407",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64407",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "nxp_recv_fw_req_v3 checks only an offset's lower bound and sends offset-plus-length data without verifying that it remains inside the firmware image.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/21e60eb4d95854196e7c0e77383f35e7ac95df61",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/441088792ffec3ca01f4efe2934060570eb11eb8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2a68a773089204af1c8581dc79668b775418c5ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/49bcb39e3a041ce26021f77971eaccb49a275118",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/badff6c3bed8923a1257a853f137d447976eec30",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1044,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64408",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:49.807Z",
      "date_updated": "2026-07-27T05:00:39.563Z",
      "publisher": "Linux",
      "title": "Bluetooth: bnep: pin L2CAP connection during netdev registration",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.1791
      },
      "nvd": {
        "published": "2026-07-25T10:17:24.517",
        "lastModified": "2026-07-27T05:16:47.873",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64408",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "bnep_add_connection reads an L2CAP connection without pinning it while controller teardown can free the same parent before netdev registration uses it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/390b5db3ff8745187f094c4e915663b7b1f98944",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/46a88784c4c9b96954dd86f747ce93f65efa1302",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/551ae773ec64045b4e72099132654887e0270bcc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ae215c5b6422d8eda443b861b124bd1be6969c31",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/df22adc7eafc22e651561813c11dc51a796b12ee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6b22dbd80926556290ad2243be25218d6956a19",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/563a8573047182f550b1e1e030615755cd8c41da",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bb067a99a0356196c0b89a95721985485ebce5a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 568,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64409",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:50.604Z",
      "date_updated": "2026-07-25T08:50:50.604Z",
      "publisher": "Linux",
      "title": "Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06901
      },
      "nvd": {
        "published": "2026-07-25T10:17:24.633",
        "lastModified": "2026-07-25T10:17:24.633",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64409",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An OR condition makes the timeout predicate permanently true, so the loop retains the host lock and never terminates.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f6682c23b6fac4780d297ae4662053d17e58fd52",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/466540e045d01fcacf383a5beb8a2dad2fc53a26",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7b429d611060e87752e848851815537963726493",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0039bdde36b23ccf1196635f1d52c5490481544d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0f0a83e26a9c7fd4b243c315ce07161d2496d83d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a257407e2bbbb099ed427719a50563f67fa366d8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1210,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64410",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:51.377Z",
      "date_updated": "2026-07-27T05:00:40.745Z",
      "publisher": "Linux",
      "title": "netfilter: flowtable: IPIP tunnel hardware offload is not yet support",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0038,
        "percentile": 0.30707
      },
      "nvd": {
        "published": "2026-07-25T10:17:24.753",
        "lastModified": "2026-07-27T05:16:48.003",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64410",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SOURCE_TRACED",
        "confidence": "high",
        "mechanism": "The flowtable path queues unsupported IPIP tunnels for hardware offload and gates retries only after the unsupported work has been enqueued.",
        "basis": [
          "CNA",
          "Linux upstream patch"
        ],
        "deepDive": true,
        "notes": "Read the upstream Linux patch via the kernel source mirror https://kernel.googlesource.com/pub/scm/linux/kernel/git/axboe/linux/+/6c5dcab95f4cd42a1648739ec9300fbb4b1a021f%5E%21/ after git.kernel.org presented an anti-bot gate; the diff adds an explicit IPIP hardware-offload support check and moves NF_FLOW_HW retry gating, while the public patch does not state a security impact commensurate with the shard CVSS 9.8."
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9efe838c13133acb70c78d04c49e8362fe533566",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c5dcab95f4cd42a1648739ec9300fbb4b1a021f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 869,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64411",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:52.143Z",
      "date_updated": "2026-07-27T05:00:41.895Z",
      "publisher": "Linux",
      "title": "netfilter: ebtables: terminate table name before find_table_lock()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02654
      },
      "nvd": {
        "published": "2026-07-25T10:17:24.853",
        "lastModified": "2026-07-27T05:16:48.123",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64411",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ebtables path consumes a table name without guaranteed NUL termination and can read beyond the user-supplied buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4c046ca4e35a83ea32f6e748f54139f5fe2a1d01",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ab63ccefb9c71627f957a0724c2b9ebc869c6f20",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c6f539311e58e76aa96feef0f1572b13a564f8a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2664f537ca5bcb2ef3fac2683dcca602e51fad24",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7436da6c1bc44654b7f11a17e746f6999fd37250",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6fe8d3cecd20bfaaaf440db3a06ba674d2f2e322",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b6183b1b88a722b6d8ea0cecc99eba168a15e0be",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a622d2e9608c9dff47fc2e5759ac7aa3a836b45d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1390,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64412",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:52.946Z",
      "date_updated": "2026-07-27T05:00:43.047Z",
      "publisher": "Linux",
      "title": "netfilter: ebtables: module names must be null-terminated",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02654
      },
      "nvd": {
        "published": "2026-07-25T10:17:24.990",
        "lastModified": "2026-07-27T05:16:48.263",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64412",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "ebtables passes an attacker-influenced module-name buffer to request_module without first requiring a terminating NUL byte.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/43dd2332b8a27b3ac5108791680cade654ab0f96",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5777c8f1c3610786d8482b8f620f40fccaf1542b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0ddca0f90fa3395111d078ae4399615cf3ea94aa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d2367d99f2455f373996d9ddbe833dbe9f942213",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/da32e78bbb187ed7b137e0007034185570a3a172",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/13a5f532e3a4fc75c33060a026def1572c208643",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/084d23f818321390509e9738a0b08bbf46df6425",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 232,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64413",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:53.759Z",
      "date_updated": "2026-07-27T05:00:44.228Z",
      "publisher": "Linux",
      "title": "netfilter: ebtables: zero chainstack array",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02298
      },
      "nvd": {
        "published": "2026-07-25T10:17:25.110",
        "lastModified": "2026-07-27T05:16:48.390",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64413",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A sparse CPU mask leaves an uninitialized chainstack pointer that an allocation-failure cleanup path can free.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2ade612967e2cdfb9290ebcb773f302c82f311fa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/42bef500d07b5769d916e9122a3e3fa3fd2245ef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fc7f105451044501a50cfd530cfa3b472c54acbc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9e6c5169db423e51dcc66a73fd15409c0d38e088",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/29bf41a9b59aff9f6197df58641a00037d567ca8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9f74d28e903fa4fdf82f870d0aeadddc8196e41c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5ee856e4208acafaaaf7b84824d39b78c21345d6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cbfe53599eebffd188938ab6774cc41794f6f9d5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 575,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64414",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:54.495Z",
      "date_updated": "2026-07-27T05:00:45.364Z",
      "publisher": "Linux",
      "title": "netfilter: handle unreadable frags",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00441,
        "percentile": 0.36229
      },
      "nvd": {
        "published": "2026-07-25T10:17:25.237",
        "lastModified": "2026-07-27T05:16:48.540",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64414",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Several netfilter paths continue handling fragment payload after skb_copy_bits() reports that the fragments are unreadable instead of dropping or limiting processing.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3b13e7635795394705920cca1e1db7e4ca2e334b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fc5bfe63bacf8a3ae307b62b34206406ca733354",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57056be3ec12e7d9ecd20a60d4060f510e4f284c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/da5b58478a9c1b85608c9e40a3b8432d071b409e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 666,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64415",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:55.226Z",
      "date_updated": "2026-07-25T08:50:55.226Z",
      "publisher": "Linux",
      "title": "mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06418
      },
      "nvd": {
        "published": "2026-07-25T10:17:25.343",
        "lastModified": "2026-07-25T10:17:25.343",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64415",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "swap_reclaim_full_clusters() can scan a very large full-cluster list without cond_resched(), monopolizing a CPU until the watchdog reports a soft lockup.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/60cbe67d1342f34b66df1c2ee328e3cd333767d7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/69c0e6246575b780ae0d3f411c749bcf13c221f3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2a55fdf9f746a1a6ced7fd62ea1080b8a917e0b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/66366d291f666ddeda5f8c84f253e308de3e6b55",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1342,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64416",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:55.997Z",
      "date_updated": "2026-07-25T08:50:55.997Z",
      "publisher": "Linux",
      "title": "mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06416
      },
      "nvd": {
        "published": "2026-07-25T10:17:25.453",
        "lastModified": "2026-07-25T10:17:25.453",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64416",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "On a swapless host, lookup_swap_cgroup_id passes an unregistered null map to the lookup helper for a corrupted swap-like PTE.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/818416fef38759f23210de449663cd9d7e293d39",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b415c00bf23df577a4a95673d00ae76687bcc1d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6a4196d19f477524d2f92adca90fc1fbe9a0420a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/63b02a9409cb5180398491b093e48bcb5315f5fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1556,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64417",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:56.800Z",
      "date_updated": "2026-07-25T08:50:56.800Z",
      "publisher": "Linux",
      "title": "mm: shrinker: fix NULL pointer dereference in debugfs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06904
      },
      "nvd": {
        "published": "2026-07-25T10:17:25.567",
        "lastModified": "2026-07-25T10:17:25.567",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64417",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "debugfs creates scan and count files without checking that the corresponding shrinker callback exists, allowing a call through a null function pointer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ebb45c2648b1f60715fd283700f651e05e431231",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/09d2407985b8ce3e831f9d4310fe7ac06a6b3ae9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/36f8534f461222291a74156ab91f3ba9f09b6f93",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/006467ab932698612398f853344a7405164541f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b9beed2322f3538b0d2d53307062da4102b8d8d8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e30453c61e185e914fde83c650e268067b140218",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1117,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:57.594Z",
      "date_updated": "2026-07-27T05:00:46.575Z",
      "publisher": "Linux",
      "title": "mm: shrinker: fix shrinker_info teardown race with expansion",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02601
      },
      "nvd": {
        "published": "2026-07-25T10:17:25.727",
        "lastModified": "2026-07-27T05:16:48.697",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64418",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Shrinker teardown drops shrinker_mutex while expansion can still copy and later free the same published shrinker_info array.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b9a280a9a454ed514636351d53fe2a233dc5054b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6465ff3ce65131c774a312d450abe10f4b9f3875",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/284c267f013e45d8c89d9fb9373105dc8e6c0947",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/65476d31d8056e859c48580f82295ce159196ffe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2234,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64419",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:58.342Z",
      "date_updated": "2026-07-25T08:50:58.342Z",
      "publisher": "Linux",
      "title": "mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06902
      },
      "nvd": {
        "published": "2026-07-25T10:17:25.847",
        "lastModified": "2026-07-25T10:17:25.847",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64419",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The shrinker debug path invokes a callback that can sleep while inside an RCU read-side critical section.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/de5f69b8dae8698ac5e48dfcd30017887cdf4e5a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e441cbfbd0eaa6404278e985033c33caba4db767",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2fed79f0fe8c8d28a972c290dbfd693c3546c8c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/560e21e8ccff813e84d05f6500907c549a3d6985",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/86237e56091e70f09c0fbf217f9d9c0e08f556c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b902890c62d200b3509cb5e09cf1e0a66553c128",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1251,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64420",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:59.115Z",
      "date_updated": "2026-07-27T05:00:47.741Z",
      "publisher": "Linux",
      "title": "mfd: cros_ec: Delay dev_set_drvdata() until probe success",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.02009
      },
      "nvd": {
        "published": "2026-07-25T10:17:25.963",
        "lastModified": "2026-07-27T05:16:48.827",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64420",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Probe publishes drvdata before initialization succeeds, allowing subdrivers to retrieve and use the pointer after failure frees its cros_ec_dev object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/24522713034d521ea4b5f5f36342e2b2f7e73bd6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f7e81dc181d9fe8ab977158042cd193e8cc12091",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/257203d83204b192d1265a916b42ca0d499bb117",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/729ae27dc2503a7c1f92da1859efb45da03e4fa0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ed2941e5db016a0c600b25f1972620e6e223d9fa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b5f41d5bf08e7b1b14fa0bd640975e6d78dc006d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fc030c5b116f668d4ca86dca63742ddbc98d1665",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8b2c1d41bc36c100b38ce5ee6def246c527eaf8a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1349,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64421",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.786Z",
      "date_published": "2026-07-25T08:50:59.926Z",
      "date_updated": "2026-07-25T08:50:59.926Z",
      "publisher": "Linux",
      "title": "media: nxp: imx8-isi: Fix use-after-free on remove",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06419
      },
      "nvd": {
        "published": "2026-07-25T10:17:26.097",
        "lastModified": "2026-07-25T10:17:26.097",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64421",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The remove path frees crossbar pads before unregistering media links that still reference those pads.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d22fb719654bfde6f682c9f14629f5f9534175b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ba2aa5d325270cd965c44458c5ff5ab555e6af51",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ef382a6baf0a95cf199fdf6bba2fd08e58b0a249",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c12a5b2261351cd3b03921ce4720332ff5184b50",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b670bf89824ede5d07d20bb9bfbafb754846081d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1407,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64422",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:00.671Z",
      "date_updated": "2026-07-27T05:00:48.900Z",
      "publisher": "Linux",
      "title": "net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00132,
        "percentile": 0.03164
      },
      "nvd": {
        "published": "2026-07-25T10:17:26.213",
        "lastModified": "2026-07-27T05:16:48.970",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64422",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A negative TCP reordering value wraps to a large unsigned value and overflows the MTU probe size calculation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f0d88a4cd03affff6c08adf6c63964e235aede43",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/27ddf4486c7dbf5bdd393fa8bef6b67179796d98",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/782708ca1ea1f68b8cbb5ea3a7f5f18d0000efae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e81f805824a8109504fce090641b17d135b48cd1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/99206ce2244f8a3ed64298d0667c9055845a5dc7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bbae351c0f32f7c200249e4aa6561b2b419dcf69",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a094ac95d3b69adfa1676eb9c8eae6835d4f1671",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/efb8763d7bbb40cff4cc55a6b62c3095a038149c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1090,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:01.485Z",
      "date_updated": "2026-07-27T05:00:50.059Z",
      "publisher": "Linux",
      "title": "ipv4: igmp: remove multicast group from hash table on device destruction",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02636
      },
      "nvd": {
        "published": "2026-07-25T10:17:26.350",
        "lastModified": "2026-07-27T05:16:49.113",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64423",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Device destruction schedules multicast memberships for reclamation without first unlinking them from the hash table traversed by RCU readers.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/412ba7def06ffe974ba9a1d862b022362c54ffa5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c6cb5f8ebe1c1a78710c19f102db9fe48b9e6ba9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5f42729d74bd6c61306d864423290d92962de4e1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/76d030ac95e17f91d69a595f17ebc5979700cf9a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8820b530cb2388503d7418228d03ba074bf7a03e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2ca18df1c2611f70eb3eb487e02ae85eb703b284",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f91883031e5a62877a29ce139442973cbea769f1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7993211bde166471dffac074dc965489f86531f8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1834,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:02.276Z",
      "date_updated": "2026-07-25T08:51:02.276Z",
      "publisher": "Linux",
      "title": "netpoll: fix a use-after-free on shutdown path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06419
      },
      "nvd": {
        "published": "2026-07-25T10:17:26.483",
        "lastModified": "2026-07-25T10:17:26.483",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64424",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Netpoll cleanup frees npinfo after a non-synchronous work cancellation, allowing the pending TX worker to resume and dereference the freed object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/95ecc5b58042f6b6743b589e6588f1cd7ba336aa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a33f37f8d079da7236ed7b7e2aed2a34ab81e7cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5ed09a108d93a3b002cc79823d9455b50c4a8be7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/45f1458a85017a023f138b22ac5c76abd477db42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1804,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:03.036Z",
      "date_updated": "2026-07-25T08:51:03.036Z",
      "publisher": "Linux",
      "title": "io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 24,
        "versionRangeCount": 23,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07409
      },
      "nvd": {
        "published": "2026-07-25T10:17:26.600",
        "lastModified": "2026-07-25T10:17:26.600",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64425",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The io-wq worker snapshots the exit bit once for a linked-work chain and continues later linked items after exit begins.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/14b7ecad2ec56699325180a744f4b19f046401bb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d179533c610e1b4c6aa436e3c1fd1b719d2c727c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6e2f51f3e06773c2ee98ad09738f0908b48f76f9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ea61b04e1d7242cb37f5ed2cc91cf21a493f6597",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b6f179a653a934736c88d820fe0098c3c2532549",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1636d85dc139b07c0449308f2bb5e0c7a2e0da99",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ab85765cbe3258b43dc6729af0e6ce3a87a133d8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/29bef9934b2521f787bb15dd1985d4c0d12ae02a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1012,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 24
      }
    },
    {
      "cve_id": "CVE-2026-64426",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:03.867Z",
      "date_updated": "2026-07-25T08:51:03.867Z",
      "publisher": "Linux",
      "title": "io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06238
      },
      "nvd": {
        "published": "2026-07-25T10:17:26.737",
        "lastModified": "2026-07-25T10:17:26.737",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64426",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "io_uring marks a NOP as fixed-file from one flag but acquires a normal file reference from another, causing completion to skip the required put.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/722869fcff598fad20d5ab79c305897a7534708b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7267717f35787167fcce4bc14f6ef3fa06682dcf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2564ca2e31bd8ee8348362941af2ee4671e487ca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1238,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:04.686Z",
      "date_updated": "2026-07-25T08:51:04.686Z",
      "publisher": "Linux",
      "title": "HID: logitech-dj: Fix maxfield check in DJ short report validation",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.05212
      },
      "nvd": {
        "published": "2026-07-25T10:17:26.843",
        "lastModified": "2026-07-25T10:17:26.843",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64427",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An error path dereferences field zero even when maxfield is zero and no field exists.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7a89ad762fad53d56b7002d7ffc923a4b7f4006f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/590cc4d782487632a52f37c2171bee1eeea29627",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1505,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:05.460Z",
      "date_updated": "2026-07-25T08:51:05.460Z",
      "publisher": "Linux",
      "title": "gpio: sch: use raw_spinlock_t in the irq startup path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.069
      },
      "nvd": {
        "published": "2026-07-25T10:17:26.947",
        "lastModified": "2026-07-25T10:17:26.947",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64428",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SCH GPIO interrupt startup path takes a PREEMPT_RT sleeping spinlock from a non-sleepable callback.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3b1aa05ec27eeccc889ecaa3f2d9baa9f453e50d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4f03a15cc73c83740fc355ee22b336492d17b4da",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7a550256d68bbdfa0903ab1c4595c04a6815493a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a235cec779bb39ec8f961a935b28a2ce278c6c64",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4508366ab7dd0c2917a51a9c2e23cc1b9d35157a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/41cad91a09d69e8fff4e936db29b1054b4e9f9f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/286533cb14a3c8a8bd39ff64ea2fc8e1aa0f638b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1419,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64429",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:06.016Z",
      "date_updated": "2026-07-25T08:51:06.016Z",
      "publisher": "Linux",
      "title": "gpio: eic-sprd: use raw_spinlock_t in the irq startup path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07406
      },
      "nvd": {
        "published": "2026-07-25T10:17:27.070",
        "lastModified": "2026-07-25T10:17:27.070",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64429",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Spreadtrum GPIO IRQ-startup path uses a sleeping lock while executing in atomic interrupt context.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/96612bf2712cd961dbd9b52f3a9b4ab668f57628",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/581ac2ad001ff1128931191f249a7f2074672b7a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e244cd8b51001ba480f274c44dba9002813a4739",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/19d63fd528719ce7d06d9aeb88d25b7d6478198a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6112fba4150039ccd90e29f2d1b788c73ad7b3dd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4750909a40da9016185e0ac991510a278cecb1e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5c3c9ec1172a4c3384b8b800b3a8896cc2c1b20e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/90f0109019e6817eb40a486671b7722d1544ae29",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1332,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:06.612Z",
      "date_updated": "2026-07-27T05:00:51.212Z",
      "publisher": "Linux",
      "title": "NTB: epf: Avoid calling pci_irq_vector() from hardirq context",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0049,
        "percentile": 0.39476
      },
      "nvd": {
        "published": "2026-07-25T10:17:27.203",
        "lastModified": "2026-07-27T05:16:49.260",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64430",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The NTB interrupt handler calls pci_irq_vector in hard-IRQ context even though the downstream path acquires a mutex and may sleep.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/33bba331a4a5fee8b6026fe72eca13cceeec1b7b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aff271b12a1eb8c8b3da19223ae1a6abe1e8168b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1dba8444ac0100133d72374634f6d7451fff1ccc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/174a97f21bf9c54fa37ec0f321692e862ea130a3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f71e8d9875069fa73e335f63f02ec6e52e3aaa51",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6350df503897d57c5634f71b0767d48c3b837583",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4dcddc1c794d1c65eda68f1f8dd04a0fecc0870f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1009,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64431",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:07.194Z",
      "date_updated": "2026-07-27T05:00:52.351Z",
      "publisher": "Linux",
      "title": "ntfs: avoid calling post_write_mst_fixup() for invalid index_block",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02466
      },
      "nvd": {
        "published": "2026-07-25T10:17:27.327",
        "lastModified": "2026-07-27T05:16:49.397",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64431",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "After pre_write_mst_fixup rejects an invalid NTFS index block, the caller still invokes post_write_mst_fixup and accesses attacker-controlled offsets out of bounds.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e2018628301a6d9f54e34b0cb417f1688c66df1d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5b6eedd7cc2936f9238e852b553a1b326105bde8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2744,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64432",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:07.791Z",
      "date_updated": "2026-07-27T05:00:53.540Z",
      "publisher": "Linux",
      "title": "fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.0338
      },
      "nvd": {
        "published": "2026-07-25T10:17:27.437",
        "lastModified": "2026-07-27T05:16:49.527",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64432",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "NTFS journal replay copies attacker-counted LCN entries into a smaller Dirty Page Table array without validating capacity or VCN subtraction.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/964c3fae1dfc49dde5468eace940f199cda234e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3aa96956ca2200674e2a8f9c23ec6ecd45e5010f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/946046841013ebac8492ef49651c53638d7a9a6a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c6f9e804f73ef809529865fbc7256dd189ff8c33",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cf28fc1658463d768657cf1c27a83980d4ba7ef2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f433acc85b86f327d03ba8b03a33c105c51053de",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57382ec6ac63b63dce2789e835fded28b698ae79",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1224,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:08.432Z",
      "date_updated": "2026-07-25T08:51:08.432Z",
      "publisher": "Linux",
      "title": "Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 14,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06415
      },
      "nvd": {
        "published": "2026-07-25T10:17:27.567",
        "lastModified": "2026-07-25T10:17:27.567",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64433",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Bluetooth reads connection parameters without the device lock while a concurrent remove operation can delete and free the same object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/caed4a96d55757c139a899744657c032b6186665",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e4369e4e970f3fa4676b76be14c1d315c87f22b6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b346efa825b5e4386f19bc63f81141652d496ec4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9531014c60c804e16099885d4a98aedcf31bce8d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fa85d985f614bc3feb343000f14a1072e99b0df1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3998,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:09.066Z",
      "date_updated": "2026-07-27T05:00:54.711Z",
      "publisher": "Linux",
      "title": "Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 23,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00247,
        "percentile": 0.15996
      },
      "nvd": {
        "published": "2026-07-25T10:17:27.717",
        "lastModified": "2026-07-27T05:16:49.667",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64434",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An asynchronous L2CAP channel timeout retains chan->conn without a reference, so connection teardown can free it before the timeout locks it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/91047a4396a8b1857a6f712a90cf33ec0012b189",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0b0e2bf39cf99e458d991b9df253727e036a7d7d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d3b739db5dc6f688a60d56da872fabaf65246032",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/50c38d9f42a529691e4e67ea9cedf4f0bfc8d277",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b66774b48dd98f07254951f74ea6f513efe7ff8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3998,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 23
      }
    },
    {
      "cve_id": "CVE-2026-64435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:09.688Z",
      "date_updated": "2026-07-27T05:00:55.915Z",
      "publisher": "Linux",
      "title": "audit: Fix data races of skb_queue_len() readers on audit_queue",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00424,
        "percentile": 0.34935
      },
      "nvd": {
        "published": "2026-07-25T10:17:27.873",
        "lastModified": "2026-07-27T05:16:49.843",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64435",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Audit queue length readers access qlen without a lock or READ_ONCE while dequeue updates the same field concurrently.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/69f98fff30bdaa72b0cb0e7e078ab6456a0a59b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b35597bdae1a5d8395da4b9baa993b9b71f74d68",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e575dabb805252e3113fdc3f56f6ecacfde422d0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7ff42312ccde549f8c698723822c7db35107a39b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a3d85dec60bb0622360fc176b2a51abdbe2ff0ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fe997a84a385f840b593ead92e575503a5046cee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c5186201fa7030289cc4fe23fae87a3fcb566856",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c9a71daaecb2fb1d8c704545cc0b1c920b9bf5d7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1726,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.787Z",
      "date_published": "2026-07-25T08:51:10.370Z",
      "date_updated": "2026-07-27T05:00:57.092Z",
      "publisher": "Linux",
      "title": "net: af_key: initialize alg_key_len for IPComp states",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02109
      },
      "nvd": {
        "published": "2026-07-25T10:17:28.010",
        "lastModified": "2026-07-27T05:16:50.033",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64436",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PF_KEY leaves the IPComp algorithm key length uninitialized and a later clone uses the garbage value to read past the allocation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/58e82fc3dedb57b1432292504415b224fd2d6acb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/01b9115b55018123ef2449ac4951f89147a8428e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3f63d1752d90c0e28be931a48ab5d89bc97d637d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/273c06b81d2e902b21acc801ae18c8276c8a9b69",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6de2a650917bedaaefd65b17cede83c5e2c1dedd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e8417353cbd078d10531ba3928e609c84ab09e6b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d129c3177d7b1138fd5066fcc63a698b3ba415b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3023,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64437",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:11.072Z",
      "date_updated": "2026-07-27T05:00:58.240Z",
      "publisher": "Linux",
      "title": "ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00435,
        "percentile": 0.35785
      },
      "nvd": {
        "published": "2026-07-25T10:17:28.160",
        "lastModified": "2026-07-27T05:16:50.213",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64437",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cancellation guards only the CANCELLED state, so work already CLOSED can fire a freed cancellation target again.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a796ba4e61d5e14e07b79a359faac69f8f9b22a3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b8e274e69ab09222c7a552c7c0c1eef9ce627fc1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ddb9239828336b36d8a3ef5943fdffb2f55b6508",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/94083db751930b1540ddff2b54d4677549c57f81",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/12c36c99655f325befe50c26842f7deca414c381",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/10f293a07f9e10e988b0ae44e2e99c631f5a68e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2202,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64438",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:11.740Z",
      "date_updated": "2026-07-27T05:00:59.389Z",
      "publisher": "Linux",
      "title": "crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.0337
      },
      "nvd": {
        "published": "2026-07-25T10:17:28.303",
        "lastModified": "2026-07-27T05:16:50.363",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64438",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SR-IOV teardown frees per-VF state before queued VF2PF workers and interrupts have stopped using its raw pointer.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/218c2836b3987f3fa1d9eac505462cded0821e4c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/446b4d77599cf1a168573f7fb32a4a6aa4f09219",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5d916c1eae1933511a69bffe243b4ee5d7da399c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f344a369d0380d54c8d6c8d24734a78dd5a89817",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/51144032248cc4ea22917370565650670b8b4e9b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/49cd5ac6de8de39a14ead609bb552d372d5602cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6e92b28cd74fa433658efeadf21b9d4b01023d7d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/277281c10c63791067d24d421f7c43a15faa9096",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1750,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64439",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:12.422Z",
      "date_updated": "2026-07-27T05:01:00.563Z",
      "publisher": "Linux",
      "title": "crypto: krb5 - filter out async aead implementations at alloc",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0043,
        "percentile": 0.35368
      },
      "nvd": {
        "published": "2026-07-25T10:17:28.447",
        "lastModified": "2026-07-27T05:16:50.527",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64439",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Synchronous Kerberos AEAD helpers accept an asynchronous implementation, treat EINPROGRESS as terminal, and free the buffer while the backend still uses it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ef6feb77e2d91761427c5b773edc9c97e1b706ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2b7bd6dccff14b8b632c5244f1fd506918077221",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c9dddeb582fde005360f4fe02c760d45ca05fb5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1093,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64440",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:13.138Z",
      "date_updated": "2026-07-27T05:01:01.733Z",
      "publisher": "Linux",
      "title": "staging: rtl8723bs: fix OOB write in HT_caps_handler()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18331
      },
      "nvd": {
        "published": "2026-07-25T10:17:28.547",
        "lastModified": "2026-07-27T05:16:50.640",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64440",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HT_caps_handler copies an untrusted 802.11 element length into a fixed 26-byte array without truncating the iteration count.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/37f642d47c3648a707df3ceb092eee1adffbfd28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8c872b47c7fc32e95e0da1db7512388794adcd69",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/918537a0fbed85aab61fa28ad75e6279070610c9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6f91621fc45025ad3c0be796b70e6e4cee22fc69",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f8001e1a516ba3b495728c65b61f799cbfad6bd0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 970,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64441",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:13.834Z",
      "date_updated": "2026-07-27T05:01:02.935Z",
      "publisher": "Linux",
      "title": "staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17211
      },
      "nvd": {
        "published": "2026-07-25T10:17:28.670",
        "lastModified": "2026-07-27T05:16:50.777",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64441",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The rtl8723bs IE parsers read headers, OUIs, and attributes without first checking that the required bytes remain in the buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/efa27d487abcdec79669a60a6d94d5d6eceb7c1d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2ea1ce30ead61589214240e8d33d96310fd613e5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b27ecba3196f6c14e3809595ebd69c0c2392512a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ab1161e539fb7a1c8b35ff5a6ced4702e855b9c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4b51ee8a40fe47864197d73cc02b191de7a6b072",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/729c4e72563bda0f1725db1db9ea08df06f41d9b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1463ca3ec6601cbb097d8d87dbf5dcf1cb86a344",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1230,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64442",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:14.535Z",
      "date_updated": "2026-07-27T05:01:04.117Z",
      "publisher": "Linux",
      "title": "staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20842
      },
      "nvd": {
        "published": "2026-07-25T10:17:28.793",
        "lastModified": "2026-07-27T05:16:50.923",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64442",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Two rtl8723bs information-element loops read the length byte before checking that a complete element header remains.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bc881c9915c4468747d0ca5fd1abd7b313cfb0f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/605ebd94d0f469204f3c9f2f84acc71e43e2780f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a830bdc82461353bf7b1f8a2ad2689bf5d2de444",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4c21eec80cf502d9ea18e0b946246b2376452786",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ad2637c46ef8b8ae0894372a2d39fdfcdc420a1e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c38d16b1ffac385c9e4b38447cd5c46af1114b58",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/402f13ec95945f34a210b28df1f8740d3d4a58c5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ef61d628dfad38fead1fd2e08979ae9126d011d5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 913,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64443",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:15.234Z",
      "date_updated": "2026-07-27T05:01:05.323Z",
      "publisher": "Linux",
      "title": "staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20184
      },
      "nvd": {
        "published": "2026-07-25T10:17:28.930",
        "lastModified": "2026-07-27T05:16:51.063",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64443",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "update_beacon_info reads the final information-element length byte and payload without confirming that the header and declared data remain inside the beacon buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5e8db4cff5b45c7c4edc8ae3f302027c3bb32b25",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6dd5e8c3011ebabf417257d7f07901a7c4311539",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9193c34f75fd9e1ea8a590d7cced464c3380dc29",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bd953d52d587d42365e399b96c52dbdb13032070",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/69f174a0673b6b7a29b851adb60bc450cdc0ecc4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b5cc2f999927f69723ca53f1f2a3aa37dbeda907",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ed51de4a86e173c3b0ef78e039c2e49e08b11f16",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 923,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64444",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:15.968Z",
      "date_updated": "2026-07-27T05:01:06.448Z",
      "publisher": "Linux",
      "title": "staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0028,
        "percentile": 0.20184
      },
      "nvd": {
        "published": "2026-07-25T10:17:29.053",
        "lastModified": "2026-07-27T05:16:51.200",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64444",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OnAssocRsp reads an information-element length before ensuring the two-byte header and declared element body remain inside the received frame.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/889ca6000ac7fa73457b041848fcb08e0d51b809",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1a52a05471494546f955a58e8c170c0c796c52d5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0406d746574e875d8778552eb674fcfbf5330bfb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0970dd47726a57e52013594e9fbf667586eb3673",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/04f612dc03427e0b1ac80a2611b5ac0ba93ac446",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7e7741c8315e4160aead00a60cdd6f81ab880717",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f9654207e92283e0acac5d64fe5f8835383b5a23",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 834,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:16.670Z",
      "date_updated": "2026-07-27T05:01:07.584Z",
      "publisher": "Linux",
      "title": "staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24016
      },
      "nvd": {
        "published": "2026-07-25T10:17:29.177",
        "lastModified": "2026-07-27T05:16:51.337",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64445",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A short WEP element underflows its length to size_t and then drives a fixed 128-byte comparison beyond the element.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/665e1ecb68b4e8419604e70a33f02d1c8b0222c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/87cccc2a767f17dcab71e3b9fe5ae29b5516c5ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c9000c93078e5c0a5a651b077c0ec92a4bc7d580",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1f6c9d255bdda41216b6e34c96aa2b1abee0bb84",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3e44a7665f3abd320a80d9c64ee4a93317041b8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/64ec4192d9c10e96922245d4a6747304cc76b19d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d90b9f39f375c9826ef145605dfe97765d0ecb91",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a1fc19d61f661d47204f095b593de507884849f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1086,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64446",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:17.402Z",
      "date_updated": "2026-07-25T08:51:17.402Z",
      "publisher": "Linux",
      "title": "staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00195,
        "percentile": 0.09394
      },
      "nvd": {
        "published": "2026-07-25T10:17:29.310",
        "lastModified": "2026-07-25T10:17:29.310",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64446",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The Linux path computes or trusts a write extent that can exceed the destination buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a94a643a80a84ceb8139061c3d6bf988d75e45a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2131621986c62c86109ce4d84cf73a73757eb8a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6f20d7b0ee47c470734a69379b0fc6647c519603",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5d7812360abf3143afcbf5efe4ef242448fa1f28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/46f66c16a95191d9aca07a72ae6b1252a244e26c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b9c4bf133c3c47e23baf4f5403b98a953bf58606",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/138cd190efd56ab36c9fdd8fef8749d06937f24b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5a752a616e756844388a1a45404db9fc29fec655",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 941,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64447",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:18.096Z",
      "date_updated": "2026-07-27T05:01:08.819Z",
      "publisher": "Linux",
      "title": "staging: media: ipu7: fix double-free and use-after-free in error paths",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03219
      },
      "nvd": {
        "published": "2026-07-25T10:17:29.437",
        "lastModified": "2026-07-27T05:16:51.487",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64447",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An ipu7 error path frees the same object twice and leaves a stale reference available for later use.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b5ddc7257bee71f5b8cf9083e2b0ac0427e9fbb3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/837c1f9655421055f751ed34745e820a54a27642",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d3a9a8cf2d7fd61a2f63df61f6cbc0a9bb007cc0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1500,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:18.796Z",
      "date_updated": "2026-07-27T05:01:09.984Z",
      "publisher": "Linux",
      "title": "smb: client: restrict implied bcc[0] exemption to responses without data area",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00463,
        "percentile": 0.37799
      },
      "nvd": {
        "published": "2026-07-25T10:17:29.557",
        "lastModified": "2026-07-27T05:16:51.610",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64448",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "SMB accepts a response one byte shorter than its declared length even when it carries a data area, allowing subsequent decoders to read beyond the receive buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8d0bbc78046d264bbf6a574ea6f9072258a43e35",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/31c6312608c60b72a1feb99a5afb680645a3e8a3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/573e502d14714d2947e22e7eff40ec20a6a44a42",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/419ec1b604d7fb60c10aec2dc062371f9fcd4940",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ceb875a375dedbf51c9425c1d13a2d7a8435c08c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6e9d10f62773b99bd927940fd9cbdfe7207e23ff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/53b7c271f06be4dd5cfc8c6ef552a8355c891a7f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3998,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64449",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:19.537Z",
      "date_updated": "2026-07-27T05:01:11.154Z",
      "publisher": "Linux",
      "title": "staging: vme_user: bound slave read/write to the kern_buf size",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03689
      },
      "nvd": {
        "published": "2026-07-25T10:17:29.727",
        "lastModified": "2026-07-27T05:16:51.783",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64449",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "VME slave reads and writes bound count to the VME window but not to the smaller fixed kern_buf allocation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/65358d89dc9f1c25d9364b2b3ef0f3b47717f9ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/adc8b9c30d716c362646edb45662aa1c641a154a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8eff7cd4817e14dbe3b9952cce55ef52d1d38940",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e99f2df433c63c86c93de1e5f08f16e404388756",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1b495fa0d4927c88d88bf346bf311f2e26e860ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9f32f38265014fac7f5dc9490fb01a638ce6e121",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1519,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64450",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:20.319Z",
      "date_updated": "2026-07-27T05:01:12.346Z",
      "publisher": "Linux",
      "title": "tipc: fix out-of-bounds read in broadcast Gap ACK blocks",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00537,
        "percentile": 0.42234
      },
      "nvd": {
        "published": "2026-07-25T10:17:29.850",
        "lastModified": "2026-07-27T05:16:51.920",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64450",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The broadcast TIPC path checks a Gap ACK record against its own count but not the containing message size, then kmemdup() reads the attacker-sized record beyond the skb.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/055663d21dc4336f67933ab26bef3c5934be6324",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/016f5995c37a5a2c45198308f830f244517d70b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/74b45af86a767594ba52330cd440ea84e24d700d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9a51115fcdc78687c8852bf93a1db3951dbb223b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a21ed5064217cc33726da6c7ef1a520eba43aea1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2de42e268174766cb2e2b90721afdfdff70e0d8d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f333b6851bdf326fd2134133272dbbed0c94d921",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2b66974a1b6134a4bbc3bfed181f7418f688eb54",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2462,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64451",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:21.020Z",
      "date_updated": "2026-07-25T08:51:21.020Z",
      "publisher": "Linux",
      "title": "tracing: Fix NULL pointer dereference in func_set_flag()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00162,
        "percentile": 0.05903
      },
      "nvd": {
        "published": "2026-07-25T10:17:30.013",
        "lastModified": "2026-07-25T10:17:30.013",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64451",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "func_set_flag() dereferences current_trace_flags before checking that the current tracer is the function tracer, allowing a stale option file to trigger a null dereference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/69f17ac132a38974cf1defb480cef6b79d1ab768",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c3e94604675e3db186111b8942650d86577df9b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2210,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64452",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.788Z",
      "date_published": "2026-07-25T08:51:21.754Z",
      "date_updated": "2026-07-27T05:01:13.528Z",
      "publisher": "Linux",
      "title": "6lowpan: fix NHC entry use-after-free on error path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00219,
        "percentile": 0.12446
      },
      "nvd": {
        "published": "2026-07-25T10:17:30.140",
        "lastModified": "2026-07-27T05:16:52.080",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64452",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The 6LoWPAN error path drops lowpan_nhc_lock before reading nhc->name, allowing concurrent unregister to free the descriptor first.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9c2f5c0829a8c8b904dae36be6d8056b719ac605",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/80b5c8779acee0550845394fb3e5176a398aa24c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cc27aea4d454abfb385ee2c9499c78b96db9b728",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a8e3a94711134e898c6021a6b77374efa91b3639",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/593b78bb3c7ef0c6e9ae6fdf5afa80a5f7573168",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0beccbcf50de125be5520d0ffc59af4bb8655482",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b713aa0cc344f10f7a9928a230b5f5e780d04078",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1720db928e5a58ca7d75ac1d514c3b73fd7061a7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1319,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64453",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.789Z",
      "date_published": "2026-07-25T08:51:22.478Z",
      "date_updated": "2026-07-25T08:51:22.478Z",
      "publisher": "Linux",
      "title": "usb: misc: usbio: fix disconnect UAF in client teardown",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.07001
      },
      "nvd": {
        "published": "2026-07-25T10:17:30.273",
        "lastModified": "2026-07-25T10:17:30.273",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64453",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Reverse USB client teardown advances its list iterator through the current client after uninitialization can release and free that client.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c40090f8d19b415e2925b22be964b5d1f695666f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1947b6411460d68b54b13c536961933166937d05",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0bfeec21984fedd32987f4e4c0cde34b445af404",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3797,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.789Z",
      "date_published": "2026-07-25T08:51:23.212Z",
      "date_updated": "2026-07-25T08:51:23.212Z",
      "publisher": "Linux",
      "title": "usb: dwc3: run gadget disconnect from sleepable suspend context",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0018,
        "percentile": 0.07823
      },
      "nvd": {
        "published": "2026-07-25T10:17:30.407",
        "lastModified": "2026-07-25T10:17:30.407",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64454",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The DWC3 suspend path invokes a sleepable disconnect callback while holding a spinlock with interrupts disabled.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b399be2958456efe1b64b19c55a54a24e9035769",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/48958478cb8dbc429a5b19f36e866b63d6297d1d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5e5798880eb1533a7de6fb68eb14b2d8202ebf76",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e0e4f15d4225fb7156cc0e3c21eb8953114f9b89",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c4e232bd07fe2b69a6e5c380db41dd36b95e0524",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/642e04f5c292d04070ae6e4374fbf14cc40a2465",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/010382937fb69892b3469ac4d30af072262f59e8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1086,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64455",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.789Z",
      "date_published": "2026-07-25T08:51:23.952Z",
      "date_updated": "2026-07-25T08:51:23.952Z",
      "publisher": "Linux",
      "title": "USB: chaoskey: Fix slab-use-after-free in chaoskey_release()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.08271
      },
      "nvd": {
        "published": "2026-07-25T10:17:30.537",
        "lastModified": "2026-07-25T10:17:30.537",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64455",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "chaoskey_release logs through a USB interface pointer after the final reference has freed that interface.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fe7a0f4be283b40dd592540027279735120d0d6f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5ec61fbef9ec5635c492ae63dfb5d13f2bdf1023",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f3e409476ad0703c54c14f245e4e143c8124e1bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c82f88bc7a8458d5c60f9b354c4d32d233f0cac",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3ad5fbcced4e9c2b0fee3c1b76289a147fc35b89",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2a52d55c86a429dac47886b8424e67f90b001e67",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8f50613bff228272577893aa10a346a2f3063e49",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/abf76d3239dee97b66e7241ad04811f1ce562e28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1791,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64456",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.789Z",
      "date_published": "2026-07-25T08:51:24.659Z",
      "date_updated": "2026-07-27T05:01:14.705Z",
      "publisher": "Linux",
      "title": "hwrng: virtio: clamp device-reported used.len at copy_data()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04507
      },
      "nvd": {
        "published": "2026-07-25T10:17:30.677",
        "lastModified": "2026-07-27T05:16:52.227",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64456",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The virtio-rng driver trusts a backend-reported used length larger than its inline buffer and copies bytes past the end of that buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3aa3e89cf80721c8d382b4c1a2b70a0449dad4a5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/63335e7b638ae70028ae285bb95153874a8bc852",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2e788948ff2a13358a303af112497a63201c5739",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fde19b0d4eeabae042519313c843fe6f27d41e9d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/81dd21b5f0c299cc7b5bf84f04a61938559d20e6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/285e17c44e3873a73460f294acbd64018ff64385",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/92d5736a62040ec1cfff23ea57e6599301690ad5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e3046eeada299f917a8ad883af4434bfb86556b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2844,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64457",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.789Z",
      "date_published": "2026-07-25T08:51:25.364Z",
      "date_updated": "2026-07-25T08:51:25.364Z",
      "publisher": "Linux",
      "title": "virtio_pci: fix vq info pointer lookup via wrong index",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00175,
        "percentile": 0.07258
      },
      "nvd": {
        "published": "2026-07-25T10:17:30.830",
        "lastModified": "2026-07-25T10:17:30.830",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64457",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A dense virtqueue index is used to look up a sparsely populated info array, selecting NULL when optional queues create holes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/41e6dc1a10036c9f47057033f19af7e52ec464b6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/075bc3c779e1ea7294afabdcb7e0a49536959b28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/64a4c0befa77bcc01076aec9f93863ffd4ed06b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f7d380fb525c13bdd114369a1979c80c346e6abc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1913,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.789Z",
      "date_published": "2026-07-25T08:51:26.072Z",
      "date_updated": "2026-07-25T08:51:26.072Z",
      "publisher": "Linux",
      "title": "mm/damon/ops-common: handle extreme intervals in damon_hot_score()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0018,
        "percentile": 0.07822
      },
      "nvd": {
        "published": "2026-07-25T10:17:30.943",
        "lastModified": "2026-07-25T10:17:30.943",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64458",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Zero or extreme DAMON intervals drive divide-by-zero arithmetic or an out-of-range histogram index.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/58321b4e6e4f0f412069ab27ccdd56292757343a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/74fef68d521150281e36cdaa20e9e1ee3e3aa146",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ef2ae10a4582bc92b7e944181bbd2f87f3d30f3a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9c8f31eaae6140ecadec0c07320498a944556de2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/76e415ea88d20f022ed5cfcf78c50e156a267e91",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/35d4a3cf70a855b50e53189ac2f8463e20a02046",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1869,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64459",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.789Z",
      "date_published": "2026-07-25T08:51:26.879Z",
      "date_updated": "2026-07-27T05:01:15.877Z",
      "publisher": "Linux",
      "title": "tcp: restore RCU grace period in tcp_ao_destroy_sock",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00475,
        "percentile": 0.38555
      },
      "nvd": {
        "published": "2026-07-25T10:17:31.073",
        "lastModified": "2026-07-27T05:16:52.403",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64459",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "tcp_ao_destroy_sock frees authentication state synchronously while an RCU packet reader can still hold and traverse that pointer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/657646c08c94ef7b9dbe468fe7828032216f9841",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4caf12c778fed3dc3824cf36263be5e2c491fbd0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8bc4d43bccbd60efe85d0a44d5bf41762f2f0c30",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2881,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64460",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.789Z",
      "date_published": "2026-07-25T08:51:27.568Z",
      "date_updated": "2026-07-27T05:01:17.015Z",
      "publisher": "Linux",
      "title": "PCI/IOV: Skip VF Resizable BAR restore on read error",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01987
      },
      "nvd": {
        "published": "2026-07-25T10:17:31.193",
        "lastModified": "2026-07-27T05:16:52.540",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64460",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "VF Resizable BAR restore treats a failed configuration read as valid three-bit fields, producing bar index 7 for a six-entry array and reading outside that array.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b77524621250407386f44c6eea7e5e4619ada1ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/55fd485e66d0ad5c762c23dba1461fe9c741cd96",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f34f1712229d71ce4286440fef12526fd4590b37",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1273,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64461",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.789Z",
      "date_published": "2026-07-25T08:51:28.309Z",
      "date_updated": "2026-07-25T08:51:28.309Z",
      "publisher": "Linux",
      "title": "PCI: mediatek: Fix IRQ domain leak when port fails to enable",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.0827
      },
      "nvd": {
        "published": "2026-07-25T10:17:31.293",
        "lastModified": "2026-07-25T10:17:31.293",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64461",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A failed MediaTek PCIe port enable frees the port structure without tearing down the IRQ domains allocated earlier in probe.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e23da72ef202654a7d5269885c4fa39a8404db76",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ec7c05eed47d8b15c45380aee7ca168a82e15035",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1fbe8972a39548a633d06d7b03a01b7b119a2c12",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fe8c701a53c2816cd82301f66c671d952003c1b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ce52e494a7555bdae1d990a2654fd7547ef6d986",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6e6a529d6f779413379b4404c9ef6a36c0337225",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/df77314b3bedbd9ad5d6f0682f98b99e3c5f7e2e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f865a57896bd92d7662eb2818d8f48872e2cbbc7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 894,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64462",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.789Z",
      "date_published": "2026-07-25T08:51:29.013Z",
      "date_updated": "2026-07-25T08:51:29.013Z",
      "publisher": "Linux",
      "title": "PCI: altera: Fix resource leaks on probe failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.08269
      },
      "nvd": {
        "published": "2026-07-25T10:17:31.420",
        "lastModified": "2026-07-25T10:17:31.420",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64462",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A failed PCI probe leaves an enabled chained interrupt handler pointing to devm storage that is subsequently released.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/af7cf5d56d7d57c4fbfdb7b5b693790f331b07b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9cf0cc481e1645ec65e61486ae41c486c59781cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/99fc088d6cc6890ae35fa2f29c50ebe027844c20",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a25bfa2a6665a1d77324d4a609e7513b87680227",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0db9aa9ec51be0a0ffdcdfd9af2b7bf3aeb7911a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/09c43b7b7d29c6fadb27f32cdf7f3bb6598befa9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6864c789b570e57f932847fa83f6b56917182d73",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7a94138caeb27f3c49c1dbd93bf422098925bb28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 828,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64463",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.789Z",
      "date_published": "2026-07-25T08:51:29.720Z",
      "date_updated": "2026-07-27T05:01:18.146Z",
      "publisher": "Linux",
      "title": "usb: typec: tcpci_rt1711h: unregister TCPCI port with devres",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 14,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03623
      },
      "nvd": {
        "published": "2026-07-25T10:17:31.543",
        "lastModified": "2026-07-27T05:16:52.667",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64463",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The probe path registers a port and then exits on a later failure without unregistering it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ce2e36e8759dfbfe546723810c306f42f484866d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/94b1abf1af94aa5a355e9f03675e07bccfc41c4b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e5406c8fb71cd2f89a46300a746f6e7972e621e8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/569f18a83eed0b0be4615f0c7bed40fb5c50e2e6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e8da46d99d3710106e7c44db14566bf9b57386b5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 733,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64464",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.790Z",
      "date_published": "2026-07-25T08:51:30.443Z",
      "date_updated": "2026-07-25T08:51:30.443Z",
      "publisher": "Linux",
      "title": "xhci: sideband: fix ring sg table pages leak",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.07003
      },
      "nvd": {
        "published": "2026-07-25T10:17:31.660",
        "lastModified": "2026-07-25T10:17:31.660",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64464",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "xhci_ring_to_sgtable leaves its temporary page-pointer array allocated after successful scatterlist construction.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/99d00a9e35e311a91d258029d5bb584377296c34",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a3eaf82ff842d6ca95937ea584417e04828235a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/49f6e3c3ef19f04f6657ed8dce550e36c763abb8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 631,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64465",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.790Z",
      "date_published": "2026-07-25T08:51:31.160Z",
      "date_updated": "2026-07-25T08:51:31.160Z",
      "publisher": "Linux",
      "title": "usb: xhci: Fix sleep in atomic context in xhci_free_streams()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.08269
      },
      "nvd": {
        "published": "2026-07-25T10:17:31.763",
        "lastModified": "2026-07-25T10:17:31.763",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64465",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "xhci_free_streams performs a sleeping operation while the disconnect cleanup path still holds an atomic spinlock.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e623e4a203f56d5c57519a9a3cb29600551534ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d107eb316144c5fb958486e7fe604cd7f1b35cda",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1e45aa722c4ce5663e987102aac18c8ad6a83fdd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/10666ac9c552990204e791af653abf8e9d9ff619",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f7b022ae07685e7526fc39f387ce65b5d309dd3b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f90586129cf9e1fbdb718ef602eea3f15dc1c31c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/93cd037da94fcb93183bfb2457e3a56d3eb4c8f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/42c37c4b75d38b51d84f31a8e29427f5e06a7c2a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1170,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64466",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.790Z",
      "date_published": "2026-07-25T08:51:31.887Z",
      "date_updated": "2026-07-25T08:51:31.887Z",
      "publisher": "Linux",
      "title": "rust_binder: clear freeze listener on node removal",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.07003
      },
      "nvd": {
        "published": "2026-07-25T10:17:31.893",
        "lastModified": "2026-07-25T10:17:31.893",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64466",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Rust Binder leaves a freeze listener linked after its node reference reaches zero, creating a reference cycle and memory leak.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/91b27f8172cdbf265240104772fd042a461a7767",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0644da3621ddd8e146280675a2a31d1e06634a1d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bc4a9828897871ff3e5a1f8a1d346decbf4ee95e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 599,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64467",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.790Z",
      "date_published": "2026-07-25T08:51:32.626Z",
      "date_updated": "2026-07-27T05:01:19.393Z",
      "publisher": "Linux",
      "title": "rust_binder: use a u64 stride when cleaning up the offsets array",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03518
      },
      "nvd": {
        "published": "2026-07-25T10:17:32.003",
        "lastModified": "2026-07-27T05:16:52.793",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64467",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Allocation's Drop walks the offsets array (binder_size_t = u64 entries), cleaning up the objects, but it used usize instead of u64 for both the stride and the per-entry read.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/89b8cc948dce661af87527623b3a41cdd115e2f9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/74920b1b4e474ba7a4de4323c0458deec49d210b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/803c8a9502e9b97cd6ae937618ef4a8fd6274343",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1133,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64468",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.790Z",
      "date_published": "2026-07-25T08:51:33.364Z",
      "date_updated": "2026-07-27T05:01:22.679Z",
      "publisher": "Linux",
      "title": "binder: fix UAF in binder_free_transaction()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 24,
        "versionRangeCount": 20,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03371
      },
      "nvd": {
        "published": "2026-07-25T10:17:32.103",
        "lastModified": "2026-07-27T05:16:52.920",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64468",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "binder_free_transaction() drops its transaction lock without pinning the target process, which can be freed before its inner lock is acquired.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5602a43f251c3d75312df91a422675fc00ca3dce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0be901ab1dcc4af59b88f2e324493bb283850167",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/48aeda9f8039e4a6971d1804578efde7f2c01eda",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/45df558c543bb5543bacc8065fd7c567740781e5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d45ef513eed1abebfec90c3cfb6ae50c2a4182db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/328ccf32acb87e8bbb1fe2b065068c574e4db2bf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0f15f0f6ca5df566275ce517f257af2559528b41",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f223d27a546c1e1f48d38fd67760e78f068fe8c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1517,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 24
      }
    },
    {
      "cve_id": "CVE-2026-64469",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.790Z",
      "date_published": "2026-07-25T08:51:34.025Z",
      "date_updated": "2026-07-27T05:01:23.812Z",
      "publisher": "Linux",
      "title": "binder: fix UAF in binder_thread_release()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03369
      },
      "nvd": {
        "published": "2026-07-25T10:17:32.247",
        "lastModified": "2026-07-27T05:16:53.463",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64469",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Binder releases transactions concurrently without reading to_proc under the transaction lock, allowing another path to free a transaction still being accessed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1f96f8c0a6ed4f6d01d3dd29ad0cbf08dde96082",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/df1a17abba8d6fac5f965adcb8113ceace6e4949",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/38e1a71728e5795b670cc159c18e286a40aeebb4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/faa070c7ad8ba25dcd0b12d7cdbb419e336f5391",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e63032dc715026a96bcaa13d375a8e15c91caa84",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ea02df466df60ecd758eb3b4df3f0cadc5c886ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ef5439ba5b9ac93349f5df12ef88b42a0ce26340",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/114a116aaa5f0295376cdf12da743c5bce3b20ce",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1879,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64470",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.790Z",
      "date_published": "2026-07-25T08:51:34.673Z",
      "date_updated": "2026-07-25T08:51:34.673Z",
      "publisher": "Linux",
      "title": "Bluetooth: btusb: fix use-after-free on marvell probe failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.0827
      },
      "nvd": {
        "published": "2026-07-25T10:17:32.390",
        "lastModified": "2026-07-25T10:17:32.390",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64470",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A Marvell Bluetooth probe failure leaves submitted transmit URBs active after their callback context is freed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1edd524de5cc8143ece9c42c466346983dc5b5ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0ccb1cb0a464dab78284c34196cd3e8e18bab4c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/631de465aba7f8ae46478bf5f598111412e8eff8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6e1b10df890f4663cb38af9fc1c93d36747b75af",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/92c736866244340497a8a65afe2ac25354c2bf5e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a7e941a395711791c7e98d9870c6562c2c9e9ef2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/838c917a2f16eefe68def800ebf48a2af591149a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c5b600a3c05b1a7a110d558df935a8fc8a471c79",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64471",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.790Z",
      "date_published": "2026-07-25T08:51:35.245Z",
      "date_updated": "2026-07-25T08:51:35.245Z",
      "publisher": "Linux",
      "title": "Bluetooth: btusb: fix use-after-free on registration failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.08271
      },
      "nvd": {
        "published": "2026-07-25T10:17:32.510",
        "lastModified": "2026-07-25T10:17:32.510",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64471",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A Bluetooth registration-failure path leaves sibling interfaces referencing a freed controller until disconnect, enabling use-after-free and double-free.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e09ac7d0c6859a360bf36e7104aef03f88184e0b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/468fcdfaeb937163dd250773a9fed17ab1fa203c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1ce5012944afaddbda939ec6bae9800fce84abbc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e6313b800da61a26c2fdd5eba0105e197c0ab3bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/14e02f1449ba425a44dedbec9a21efafb056e09f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8db0ce3de78367f61c2970c0f16d9adee8830a23",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/da7d7758fe884b256ddc9fef562e5ddef7952383",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eedc6867ebad73edbfaf9a0a65fbef7115cc4753",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 407,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64472",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.790Z",
      "date_published": "2026-07-25T08:51:35.978Z",
      "date_updated": "2026-07-25T08:51:35.978Z",
      "publisher": "Linux",
      "title": "vfio/mlx5: Fix racy bitfields and tighten struct layout",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00181,
        "percentile": 0.07871
      },
      "nvd": {
        "published": "2026-07-25T10:17:32.630",
        "lastModified": "2026-07-25T10:17:32.630",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64472",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Concurrently updated runtime flags share non-atomic bitfield storage, so read-modify-write operations can overwrite one another's state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1dd99b8f4e143592e12e5a77e7b538bc698116cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f1db80a67da928a92ba460ede1be52d8941f46be",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/399d806f998f7a25405fc1b97227e579aead24af",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7ed120b1a007bace57c461805519d70e1af44e59",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/39d163627b51886492bf31f66cb02c94613d2287",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f2365a63b02ddea32e7db78b742c2503ec7b81f1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1448,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64473",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.790Z",
      "date_published": "2026-07-25T08:51:36.702Z",
      "date_updated": "2026-07-25T08:51:36.702Z",
      "publisher": "Linux",
      "title": "vfio: Remove device debugfs before releasing devres",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00175,
        "percentile": 0.07257
      },
      "nvd": {
        "published": "2026-07-25T10:17:32.757",
        "lastModified": "2026-07-25T10:17:32.757",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64473",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Device-managed resources are freed before their debugfs entries are removed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6cc60b41d61657dc469893d14e8e55d160056ff1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a53109ffb6b5148e11a27fb7670355b92db12dd3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a5df401dc84f091e20b045560569f0736758fea7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dc7fe87de492ea7f33a72b78d26650b75bf37f4f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 988,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64474",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.790Z",
      "date_published": "2026-07-25T08:51:37.405Z",
      "date_updated": "2026-07-25T08:51:37.405Z",
      "publisher": "Linux",
      "title": "vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00176,
        "percentile": 0.07315
      },
      "nvd": {
        "published": "2026-07-25T10:17:32.863",
        "lastModified": "2026-07-25T10:17:32.863",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64474",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The migration-state skip loop treats the ERROR sentinel as another unsupported state and repeats forever without changing state.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8e872c07e40d51a66dee7b280a23a460a2e1e3fa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ed7d5599e6c398da74845767cd1e6a8370a160fc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7f2d6b31089e48db4653df832c9a6afdde9a1c29",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a3a8afa2f6e7f0dc266d08f02be3f3054241ba47",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a26b499b757cfc8bbff1088bb1b844639e250893",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1045,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64475",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.791Z",
      "date_published": "2026-07-25T08:51:38.154Z",
      "date_updated": "2026-07-27T05:01:25.012Z",
      "publisher": "Linux",
      "title": "vfio/pci: Release the VGA arbiter client on register_device() failure",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 23,
        "versionRangeCount": 20,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.0369
      },
      "nvd": {
        "published": "2026-07-25T10:17:32.980",
        "lastModified": "2026-07-27T05:16:53.927",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64475",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A registration-failure reorder omits the VGA-arbiter unwind and can leave a callback registered with a freed vfio device cookie.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0f2a35a0c7ea7da347b814750eaa78adf3582381",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8d65decde9afd2bd78bcfffdc0df73b82a0b5509",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ef4c38d30b3744e89eb5048218904bb629ea8d47",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9e0a3f642e607848669235f5069f35640abbfc88",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/42d758a09d2c46c42357ecde9a5492f015bde2e5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/52adb2dff7ce3d8430e2bdc5988b618a430def85",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/278a5659c391fe5afe5f9ce1bad1fd24e90144f1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/daedde7f024ecf88bc8e832ed40cf2c795f0796a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 663,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 23
      }
    },
    {
      "cve_id": "CVE-2026-64476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.791Z",
      "date_published": "2026-07-25T08:51:38.865Z",
      "date_updated": "2026-07-25T08:51:38.865Z",
      "publisher": "Linux",
      "title": "vfio/pci: Latch disable_idle_d3 per device",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0018,
        "percentile": 0.07824
      },
      "nvd": {
        "published": "2026-07-25T10:17:33.113",
        "lastModified": "2026-07-25T10:17:33.113",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64476",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A writable global idle-power flag can change while existing VFIO devices retain operations that require balanced per-device runtime-PM state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/332d785f9ae426eeeb92527872adf09d84101ba3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/654710ef3135c4546b20a903bc23a51b0c44d6c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b98296816d31441b307ef9fa8670dcf5a55e5505",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f6c67cf0051f96ba61d186731d3d9409b9927db2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/062b820290bcb9778e43a73597df76e9bb08acfb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4575e9aac5336d1365138c0284773bf8da4b1fa3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1939,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64477",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.791Z",
      "date_published": "2026-07-25T08:51:39.558Z",
      "date_updated": "2026-07-25T08:51:39.558Z",
      "publisher": "Linux",
      "title": "x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00176,
        "percentile": 0.07315
      },
      "nvd": {
        "published": "2026-07-25T10:17:33.243",
        "lastModified": "2026-07-25T10:17:33.243",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64477",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The resctrl offlining path queries a NUMA node through nr_cpu_ids after the monitoring domain's CPU mask becomes empty, causing an out-of-bounds access.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ebc300b7ee0c669fa76a7a8858298ff32e296103",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be1567992417dc92133e74126de7a6066c825ac9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/58c5ec23b1a238eb75cb0aba6f69d8f9e68ef0b2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fc16126cc11d9f507130bf84ab137ee0938c900e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1469,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64478",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.791Z",
      "date_published": "2026-07-25T08:51:40.299Z",
      "date_updated": "2026-07-25T08:51:40.299Z",
      "publisher": "Linux",
      "title": "ALSA: usb-audio: avoid kobject path lookup in DualSense match",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 27,
        "versionRangeCount": 24,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.08268
      },
      "nvd": {
        "published": "2026-07-25T10:17:33.350",
        "lastModified": "2026-07-25T10:17:33.350",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64478",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DualSense hotplug code walks kobject names while the USB device can concurrently disconnect and invalidate an ancestor name.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e4c66a149c408e44e60bfec3fabf08b6b7abbc60",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4566bf8ae9dbfe81bdc2ff1702d59db8a233b06e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/662a1d7b5affc424ea4f4bc20dd99be29e687886",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a47ecd904c51ae6a42957feb3cf2f4266adee2e5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c1da6d3f45036fa63672ee04ad97cb526b40b987",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a263eb12cbe2e208e6e637df0f9b0be9a484158e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4246dd043b7a4f8e3bc1d2896e81d11220610eda",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7693c0cc415f3a16a7a3355f245474a5e661be4e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1275,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 27
      }
    },
    {
      "cve_id": "CVE-2026-64479",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.791Z",
      "date_published": "2026-07-25T08:51:41.006Z",
      "date_updated": "2026-07-25T08:51:41.006Z",
      "publisher": "Linux",
      "title": "ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00181,
        "percentile": 0.0787
      },
      "nvd": {
        "published": "2026-07-25T10:17:33.493",
        "lastModified": "2026-07-25T10:17:33.493",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64479",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "snd_seq_event_dup compares a legacy event size against the smaller event member and leaves the UMP trailing word uninitialized before copying it to user space.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d7649aa11089a93ea2285c210397aa67e5800766",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a224c84e5d3d35708c082c84ad12d81d90762195",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ea672a9f6cc38f06fe69dd2c257ef8a3d4db179a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fb1aa5082847b98f44f9c6272aee9d0dca9244f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/651ba82fe2a144bc7356d940bfd235c3810b0549",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ded42615fa1f4949925afd0a8a9e1ab3bf96202",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/435990e25bf1f4af3e6df12a6fbfd1f7ba4a97d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1259,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64480",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.791Z",
      "date_published": "2026-07-25T08:51:41.691Z",
      "date_updated": "2026-07-25T08:51:41.691Z",
      "publisher": "Linux",
      "title": "ALSA: ice1712: check snd_ctl_new1() return value",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 17,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00181,
        "percentile": 0.07871
      },
      "nvd": {
        "published": "2026-07-25T10:17:33.617",
        "lastModified": "2026-07-25T10:17:33.617",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64480",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ice1712 driver dereferences the result of snd_ctl_new1 without checking whether allocation returned NULL.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/57d59be545b309d4bb54ac472b15d1e67f254d95",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/69bf1dfa3215524c4ae255bb9dce0770875abbeb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d34ad480b8896d2b486e2cf29ce1790326cad205",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/71b87108ad93d433cdb20704a8dc8852304cf2c2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/38a7cc46370a57122fb29c4bfe48a851c0c64459",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2b929b91b0f3bc6de8a844370049cd99ee8e31ff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 461,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-64481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.791Z",
      "date_published": "2026-07-25T08:51:42.430Z",
      "date_updated": "2026-07-27T05:01:26.179Z",
      "publisher": "Linux",
      "title": "ALSA: hda/cs35l41: Fix firmware load work teardown",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03679
      },
      "nvd": {
        "published": "2026-07-25T10:17:33.733",
        "lastModified": "2026-07-27T05:16:54.210",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64481",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A queued firmware worker survives device teardown and later accesses invalid driver state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8947215c0136c9d905e4a46d824824f8b48a2e5b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ce0a903d0591e3e2c790c5b628802b08d1b287cc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d6a40a4d083ef74d00c8f9516cb5ff07ac70720b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b65020d5398f499c09498c9786dba6d67ae57664",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 987,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.791Z",
      "date_published": "2026-07-25T08:51:43.128Z",
      "date_updated": "2026-07-25T08:51:43.128Z",
      "publisher": "Linux",
      "title": "ALSA: gus: check snd_ctl_new1() return value",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 17,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00181,
        "percentile": 0.07871
      },
      "nvd": {
        "published": "2026-07-25T10:17:33.843",
        "lastModified": "2026-07-25T10:17:33.843",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64482",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "snd_gf1_pcm_volume_control dereferences the result of snd_ctl_new1 without checking for allocation failure.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/97f6bdf5d5ded2e37f358cacb5a95f1393356604",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eccf8e91266e39f6f15637702a04a1d344833fe2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fc5d4f27ca1293bc1379ef8fff691c30d9803ca2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5e74e5e8cb7cc25f7a89f59abaf3489bf0c6f4a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/465075c6835103821d725c13f8c545898e5f2636",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c7fa99d30c7a166a5e5db5a585ce7501ff68326b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 390,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-64483",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.791Z",
      "date_published": "2026-07-25T08:51:43.851Z",
      "date_updated": "2026-07-25T08:51:43.851Z",
      "publisher": "Linux",
      "title": "ALSA: firewire: isight: bound the sample count to the packet payload",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.08268
      },
      "nvd": {
        "published": "2026-07-25T10:17:33.957",
        "lastModified": "2026-07-25T10:17:33.957",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64483",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ALSA FireWire path trusts a sample count that exceeds the received payload and accesses bytes beyond it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/24423e0a9251d348c3f1fb0bb0e61b879e1e976c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ebbffacda6733dcbcef601b5b523460f8d8b671e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57e4d9043afc1eaddee8f50d11def6e65415d273",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3ed2fa1ed8cc65f910b8bbc0be3cc366b30f8478",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/31da82b9676c6b112e7c72c7529e6812b919742a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8e48a29813df8dd71503800b7acf69c12c035045",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/31a01b70bb90e3ef3147f308e2ea899e1d2485ca",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/29b9667982e4df2ed7744f86b1144f8bb58eb698",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1121,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64484",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.791Z",
      "date_published": "2026-07-25T08:51:44.591Z",
      "date_updated": "2026-07-25T08:51:44.591Z",
      "publisher": "Linux",
      "title": "ALSA: es1938: check snd_ctl_new1() return value",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00185,
        "percentile": 0.0833
      },
      "nvd": {
        "published": "2026-07-25T10:17:34.083",
        "lastModified": "2026-07-25T10:17:34.083",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64484",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The ES1938 mixer dereferences the result of snd_ctl_new1 without checking whether memory allocation returned NULL.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/96cad5bd7d0a176db3fdc06717a41271247336bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c4efebaf73e217efbd08cdbda805758a7db3680",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/41759affbcfe3d51a32900da9547a1ffd744a85f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7531a37720c2545a480fd0fa464978569bf9d6a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af01c48e17a66fa038af210a5c49d6cdefd210bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9e53e99b6fa3cd82992d963cbff58dbbd1df8651",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1949163dee39e0e4a1468f37dd7302962f6af45a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1edd1f02dddd20aeb6066ded41017615766ea42f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 380,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64485",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.791Z",
      "date_published": "2026-07-25T08:51:45.301Z",
      "date_updated": "2026-07-27T05:01:27.427Z",
      "publisher": "Linux",
      "title": "ALSA: compress: Fix task creation error unwind",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03555
      },
      "nvd": {
        "published": "2026-07-25T10:17:34.203",
        "lastModified": "2026-07-27T05:16:54.570",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64485",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "ALSA task-creation cleanup omits the driver task_free callback and can also preserve a stale success return value.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b27a75d42044d9d4709095617730b91b1c4af423",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/426a9947a38d272d0e19c031658da68e31128667",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4a60127debb9e370d6c0e22a307326b624a141f3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 843,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64486",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:45.982Z",
      "date_updated": "2026-07-25T08:51:45.982Z",
      "publisher": "Linux",
      "title": "ALSA: cmipci: check snd_ctl_new1() return value",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 17,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0018,
        "percentile": 0.07822
      },
      "nvd": {
        "published": "2026-07-25T10:17:34.310",
        "lastModified": "2026-07-25T10:17:34.310",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64486",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "snd_cmipci_spdif_controls() dereferences snd_ctl_new1() results without checking allocation failure for NULL.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b44888c33c4f11277d0e5e023338f2740232a4ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8825a06bfa7932a7a74dec01669d405df0b47286",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4dd5b0b1a52a8d6e59a3f217204817228ce0238b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af2b009b773bc42995546507963e5e78970dc3ed",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/67e9ea92cd598cba1783ff701553c776a6cedee9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c205bd1b28fb7e5f1061a4e78813fad7d315cb3e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 399,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-64487",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:46.711Z",
      "date_updated": "2026-07-25T08:51:46.711Z",
      "publisher": "Linux",
      "title": "ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.08268
      },
      "nvd": {
        "published": "2026-07-25T10:17:34.423",
        "lastModified": "2026-07-25T10:17:34.423",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64487",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The caiaq S4 parser loops while any bytes remain, so a final block shorter than 16 bytes is read out of bounds and its unsigned length subtraction wraps to a huge value.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/de5f9edc705497b1b2c6b173b22f283486d2fd91",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/70d6d4cfa4ad09688aed2ec8a0cfa72c31f60334",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/884f575cc6acb136eb4a161d925147f85b59c27e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/05df59b9a61f7ca66548df079d306c41da23845d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3cad86197c7bf8b45bb1d8adc1099d0913e80469",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a5fd3122283bf75c04f6414bf610100beb0565b0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0680413f2f10aab43878dd3db711a6a9e45bab7c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f7f3f9fd81e7adbaa12c2e62ee07f0e094a543fd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1187,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:47.436Z",
      "date_updated": "2026-07-25T08:51:47.436Z",
      "publisher": "Linux",
      "title": "ALSA: aoa: check snd_ctl_new1() return value",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00184,
        "percentile": 0.08268
      },
      "nvd": {
        "published": "2026-07-25T10:17:34.553",
        "lastModified": "2026-07-25T10:17:34.553",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64488",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ALSA AOA setup path dereferences snd_ctl_new1's result without checking whether allocation returned null.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b0154ebc6dc552c389a574b1e221d728e10346e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d62624fe256b2d0d13454c78cbfc70ff5d954dc7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e5e8c4508d95af82f9b4d065f658e5476a8e9bc8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2ee9c46fd2dcd529cef18e37636ee12f5c3dbedd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d73067e2bbf3775a495d9f38e38d0a3cf53ee790",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fd786466889e4a6e6de0f4462bd0068edea63960",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e47f2a341adbac001b6f5d0211b0cd1c1668637b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8df560fefe6fed6a20b7e06720eeaeccec349ac0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:48.161Z",
      "date_updated": "2026-07-25T08:51:48.161Z",
      "publisher": "Linux",
      "title": "ALSA: ymfpci: check snd_ctl_new1() return value",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 17,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0018,
        "percentile": 0.07822
      },
      "nvd": {
        "published": "2026-07-25T10:17:34.687",
        "lastModified": "2026-07-25T10:17:34.687",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64489",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SPDIF control setup dereferences snd_ctl_new1's result without checking whether allocation returned null.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d7c71dfd4b80f0eacac2c157a8a3a4c6e8b2e0d1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/91095474eea29b95c9a8bceb9b501a2702b6c55f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/02f33c2062c75e28abc7ad58ce86451cf3140455",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f6538a318947b627710b08a268bc80a48c23bde7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/18ec7d7785be7a4ee8ea11e355122282caad4267",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e64d170346d00b580c0043de3e5ccb3e331c47d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 17
      }
    },
    {
      "cve_id": "CVE-2026-64490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:48.877Z",
      "date_updated": "2026-07-27T05:01:28.678Z",
      "publisher": "Linux",
      "title": "ALSA: virtio: Validate control metadata from the device",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00153,
        "percentile": 0.04935
      },
      "nvd": {
        "published": "2026-07-25T10:17:34.807",
        "lastModified": "2026-07-27T05:16:54.790",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64490",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "virtio-snd trusts device-supplied control type and count values as array indices and copy lengths without validating their bounds.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3243563f99ef5d3949b934bd6390a5679405d0e1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5da9742de22db0dbaa8d414214ab5e1bedde00f9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/21584672fd699abe1768241d6c501b2de6139b6a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c77a6cbb36ff8cbc1f084d94f8dcda5250935271",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 751,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64491",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:49.601Z",
      "date_updated": "2026-07-25T08:51:49.601Z",
      "publisher": "Linux",
      "title": "ALSA: usx2y: us144mkii: fix work UAF on disconnect",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00174,
        "percentile": 0.07065
      },
      "nvd": {
        "published": "2026-07-25T10:17:34.910",
        "lastModified": "2026-07-25T10:17:34.910",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64491",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The disconnect path cancels work before killing self-resubmitting URBs, allowing a completion to rearm the work after its only cancellation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c071df05bcda0e47aac581d4b564b2bebcb1ff60",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/27161c68d5e78807c9d897db222a775b298d05fd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/147996e7e7c9e8339c0e04f6fa7ccb3e4d448ff7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 728,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:50.313Z",
      "date_updated": "2026-07-25T08:51:50.313Z",
      "publisher": "Linux",
      "title": "iio: temperature: tmp006: use devm_iio_trigger_register",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.07002
      },
      "nvd": {
        "published": "2026-07-25T10:17:35.017",
        "lastModified": "2026-07-25T10:17:35.017",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64492",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The tmp006 driver registers a devm-allocated trigger with a non-devm API, leaving a global-list pointer after module unload frees the trigger.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a4f8491da9563ba6eb77969ac26fc7052114c476",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d90f868f56a16e10eedc6552f48d99dff4d275b7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3c5eed894efd93d68d7f6a359a81ddef0e928774",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 524,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64493",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:51.036Z",
      "date_updated": "2026-07-25T08:51:51.036Z",
      "publisher": "Linux",
      "title": "iio: pressure: mpl115: fix runtime PM leak on read error",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06418
      },
      "nvd": {
        "published": "2026-07-25T10:17:35.120",
        "lastModified": "2026-07-25T10:17:35.120",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64493",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The sensor read error path returns without dropping its runtime power-management reference, leaking one reference per failed read.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5022f4ed5aae974ec530e3cbf0bd223be13055f7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aab0fed636b14a5fd52fcae58b484f1cb96b841d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b3f1af4ba8e9cf33aa08c4cdcaa5a17b140521ec",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/46e69d3dd429b33e50e2731913239f6af4ea2705",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fbe67ff37a6fd855a6c097f84f3738bd13d0a898",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 546,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64494",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:51.747Z",
      "date_updated": "2026-07-25T08:51:51.747Z",
      "publisher": "Linux",
      "title": "iio: light: gp2ap002: fix runtime PM leak on read error",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 18,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07408
      },
      "nvd": {
        "published": "2026-07-25T10:17:35.230",
        "lastModified": "2026-07-25T10:17:35.230",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64494",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "gp2ap002_read_raw returns on a sensor read error without releasing its runtime power-management reference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/62e0d74821a02f0e0c5c79b99ae64dc83a9a90f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7110201c6b21455240c63388f30113f3baafacfc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2593f0c6ea37df168975694a3b17e7086f11453e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f350883989ced96d6da7f582f9a6f9c6ffc94e34",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/29137052c4485c74bc2d1b0717f69ca4de14274f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0c655d067ac69ee24e2e9d706c54179ea58a43db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2ebaea7f3089decb01a8294d89d7e0cf288146c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/38b72267b7e22768a1f26d9935de4e1752a1dc85",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 524,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64495",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:52.468Z",
      "date_updated": "2026-07-25T08:51:52.468Z",
      "publisher": "Linux",
      "title": "iio: gyro: bmg160: bail out when bandwidth/filter is not in table",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00195,
        "percentile": 0.09441
      },
      "nvd": {
        "published": "2026-07-25T10:17:35.360",
        "lastModified": "2026-07-25T10:17:35.360",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64495",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The gyro filter lookup reads one element past its table when no bandwidth or filter entry matches.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1dc3a833be11e5d503038e3c701745fd0e03903c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/77e56ebb1786f4296afd5fa46975a989b285ae65",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/029481cddb98697716f4bf3021d035eaf2ca0e1f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8d202515baea4e2e3be448d1590099af28f2346d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d85ee50f58dd83fe74f6d0bf8bd345c657b216e8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7bbf02b63961fc1768c9c654392c11f2077d4c59",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6c8675468862161d1c59130266852b66867d3861",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8320c77e67382d5d55d77043a5f60a867d408a2b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1126,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:53.194Z",
      "date_updated": "2026-07-27T05:01:29.899Z",
      "publisher": "Linux",
      "title": "iio: event: Fix event FIFO reset race",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02689
      },
      "nvd": {
        "published": "2026-07-25T10:17:35.490",
        "lastModified": "2026-07-27T05:16:54.923",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64496",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "IIO installs the event file descriptor before resetting its FIFO, allowing another thread to queue an event that the post-publication reset then discards.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9dc84ba4be5bbeb29ee49efe6cea2cb32c461424",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d16a702ca7d29c0b7a9b509339d1b044a1cadb32",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a13ef1adbc62085b21b546b07b0be7e2fbf52150",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0d4a646d7f87ea3625fafe387043fddc6a2f5e7f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/72c6aa8e0d74eab91b8694cde97dec088c248fee",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9edefd4c56bee3fe331e0355d1f10a533134999d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f187dc5a4c4846ffa07d9bda6e760837ed005574",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/af791d295737ea6b6ff2c8d8488462a49c14af01",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1641,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64497",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:53.917Z",
      "date_updated": "2026-07-25T08:51:53.917Z",
      "publisher": "Linux",
      "title": "iio: chemical: scd30: Cleanup initializations and fix sign-extension bug",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07463
      },
      "nvd": {
        "published": "2026-07-25T10:17:35.623",
        "lastModified": "2026-07-25T10:17:35.623",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64497",
        "family": "OTHER_SPECIFIC",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SCD30 conversion clears the sign bit with an incorrectly widened mask and corrupts the floating-point exponent.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0ccff849bde90973e6c13a666f6ceab5c55b30d4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1821bcacd8ac5b214c53be16cbb8172bf193f0b6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/40bb0fdb37f441c9c9f52bf58bbd8a0ca3cc9598",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b131f0011dfef72350f4e3f11df94dc3e6b46065",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8d4a46e971cf846bda98b20d4cabfa21c1276e5f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/82accdd57404399eddf3d56fd9beda7c61307388",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d49ff54b2784aa56a7c97982de713604de89d23a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/60d877910a43c305b5165131b258a17b1d772d57",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 729,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64498",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.792Z",
      "date_published": "2026-07-25T08:51:54.625Z",
      "date_updated": "2026-07-25T08:51:54.625Z",
      "publisher": "Linux",
      "title": "iio: buffer: hw-consumer: free scan_mask on buffer release",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00155,
        "percentile": 0.05214
      },
      "nvd": {
        "published": "2026-07-25T10:17:35.753",
        "lastModified": "2026-07-25T10:17:35.753",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64498",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The IIO hardware-consumer release path frees the wrapper but omits the separately allocated scan-mask bitmap.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fb8e18f8ca724bd4de4643cad5b7c7230b9a5a71",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6325d6e2204327965b849c0a16efb6ac9202e5a8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 648,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:51:55.336Z",
      "date_updated": "2026-07-25T08:51:55.336Z",
      "publisher": "Linux",
      "title": "iio: adc: ti-ads1119: fix PM reference leak in buffer preenable",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00157,
        "percentile": 0.05333
      },
      "nvd": {
        "published": "2026-07-25T10:17:35.860",
        "lastModified": "2026-07-25T10:17:35.860",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64499",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An I2C error during pre-enable returns without releasing the runtime power-management reference.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f40292fb19399a3c3f82de698023ba87c01e66cf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ffb2195921c3d629194b9807de589578df9f9cb8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6537f08100189d12bec4975000244e6ac4873c28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/adf4bc07f814da8329278d32600147f5a150938c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 639,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64500",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:51:56.053Z",
      "date_updated": "2026-07-25T08:51:56.053Z",
      "publisher": "Linux",
      "title": "iio: adc: lpc32xx: Initialize completion before requesting IRQ",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06138
      },
      "nvd": {
        "published": "2026-07-25T10:17:35.957",
        "lastModified": "2026-07-25T10:17:35.957",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64500",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The LPC32xx ADC driver registers an interrupt handler before initializing the completion object that the handler uses.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7090c0d29708ee305022d0ea7b37612b33242fa2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0e33587967b356519aa6f220b5b43c6976320397",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1ddf7b6ffb8ebb22b92a184a9eaa76277ef0c7cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/820c4f15353efe9a9429ae86ccceeaf4e0e4e585",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/48eccc6caed4e62c0f199ab3a3772fa969cd3b2d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9e2e8b8cdfd37ae7c7a8a5c96c59e98a768731c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f18c5551aa97ca7f39dbb151c67c9053ccadc17",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e561b35633f450ee607e87a6401d97f156a0cd54",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1400,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:51:56.768Z",
      "date_updated": "2026-07-27T05:01:31.056Z",
      "publisher": "Linux",
      "title": "iio: adc: ad_sigma_delta: fix CS held asserted and state leaks",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00116,
        "percentile": 0.01843
      },
      "nvd": {
        "published": "2026-07-25T10:17:36.090",
        "lastModified": "2026-07-27T05:16:55.100",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64501",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The sigma-delta ADC error path exits without returning the converter to idle and releasing chip select, leaking bus and device state into the next operation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c313bb7c38855e94ceef939d152dd75e5a904b5f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f1de829ee87a1198d3465493ce430d36c5fa029c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c72da0688575e5ef39c36bb44fed53aa18f8ae65",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1397,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64502",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:51:57.477Z",
      "date_updated": "2026-07-27T05:01:32.289Z",
      "publisher": "Linux",
      "title": "iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02073
      },
      "nvd": {
        "published": "2026-07-25T10:17:36.200",
        "lastModified": "2026-07-27T05:16:55.223",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64502",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The sigma-delta driver enters a register-status drain path on a registerless device and can underflow a zero data length into a SIZE_MAX memset.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3394e0b3328422431cadaf314fa58d3717ed4936",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3bceb26dfaf7ba805b459e41c1d0ba916862dade",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/91bc6767a4f55dc470d8a56b55b9f2ea09094efe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1921,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64503",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:51:58.186Z",
      "date_updated": "2026-07-25T08:51:58.186Z",
      "publisher": "Linux",
      "title": "iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07403
      },
      "nvd": {
        "published": "2026-07-25T10:17:36.317",
        "lastModified": "2026-07-25T10:17:36.317",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64503",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "kxsd9_write_raw() takes a runtime PM reference with pm_runtime_get_sync() but returns -EINVAL directly when a scale with a non-zero integer part is requested, skipping the matching pm_runtime_put_autosuspend().",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a93fd69c1ab0854ac4f5b8439c26dfadb25dfd20",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eeece4a85ece6f3837c75ef26a9b2bf5a1d0fcfc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/191fcfeb729ededd8dd2a999c6bf351ddfa0cec7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/36154171385a8a2444a4b3c6eaa0c5294cb02478",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/223703d6e8bed50b6a0b47e160877909518d94b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6293211d142605bec435229ef0aa3668b8964164",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/13a91e8631cfeb68e5b7fd6687f194f5a86e83fe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/44a5fd874bb6873bdaec59f722c1d57832fbc9df",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64504",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:51:58.887Z",
      "date_updated": "2026-07-25T08:51:58.887Z",
      "publisher": "Linux",
      "title": "iio: accel: bmc150: clamp the device-reported FIFO frame count",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00165,
        "percentile": 0.06138
      },
      "nvd": {
        "published": "2026-07-25T10:17:36.443",
        "lastModified": "2026-07-25T10:17:36.443",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64504",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The accelerometer driver trusts a 0-to-127 device FIFO count when its stack buffer holds only 32 frames.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b5a9f521e0a49a0266200fd535b32a9668ecb33b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2fe0531dd73eff1de0f2584cb77716d645e548d5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d0e6d924a5484e005cae5aff6a0aa07a22f3c9ff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bfffc98f3de92e0f76be7c7b72e63ac1776a6dbc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/89f4a4ca0ac3a933c750569a771c079a290b0721",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3e766526827acd542bcd36c20c4d5f397e0f6521",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/35a3cd8fd65e15029eb90f1e510045b1bb071175",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ce0e1cae26096fe959a0da5563a6d6d5a801d5fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1532,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64505",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:51:59.618Z",
      "date_updated": "2026-07-27T04:37:44.365Z",
      "publisher": "Linux",
      "title": "usb: gadget: function: rndis: add length check for header",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0022,
        "percentile": 0.12543
      },
      "nvd": {
        "published": "2026-07-25T10:17:36.583",
        "lastModified": "2026-07-27T05:16:55.357",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64505",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The RNDIS parser accesses MessageType, MessageLength, DataOffset and DataLength before confirming that the received header contains those fields.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/200dd5092296ad4d5ae47f8445a2fb1edd1da973",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9ffd567d7bf269824dfac06f8ab9a32fef72699b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b73c0142e3acdc063b50c33afb7be19cdb2cd410",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d6ef5af7d0fe1ac31e5653a77e6d775dd36bc433",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ba2cc601e59fe68716646199a33303493513e2e3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7515a6d4a9e9e4838b833825882efa00e85f8901",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9facd79028a7807879eb441d12f0e00720980aa3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/21b5bf155435008e0fb0736795289788e63d426f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 299,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64506",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:52:00.322Z",
      "date_updated": "2026-07-25T08:52:00.322Z",
      "publisher": "Linux",
      "title": "wifi: rtw89: correct drop logic for malformed AMPDU frames",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00161,
        "percentile": 0.05789
      },
      "nvd": {
        "published": "2026-07-25T10:17:36.710",
        "lastModified": "2026-07-25T10:17:36.710",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64506",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The malformed-AMPDU drop state mishandles the first packet during pairwise rekey and resets state at the wrong point in the sequence.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/994994cfadaf1fd362dea9b8d9d633f85dc1b3c3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/63ccdfac8677387dfdbd9d4336089e9823280704",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 572,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64507",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:52:01.008Z",
      "date_updated": "2026-07-27T04:37:45.561Z",
      "publisher": "Linux",
      "title": "x86/bugs: Enable IBPB flush on BPF JIT allocation",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00157,
        "percentile": 0.05335
      },
      "nvd": {
        "published": "2026-07-25T10:17:36.810",
        "lastModified": "2026-07-27T05:16:55.487",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64507",
        "family": "HARDWARE_PHYSICAL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "BPF JIT memory reuse omits the IBPB flush needed to clear branch-predictor state when Spectre-v2 mitigations are active.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cb27f3bf915cc0f20fc0c48da9059304e39ebd35",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9354248fc1c33a844ca1872761f6668b393e8c37",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8a4c8af9ae67eb072d90d1b339f14d27a82bd2a1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/52440e15d9628f8f239373c0f2e5e8f92feea2df",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a3af84b0fa00ead01fcd0e28b5d773ff25990a0d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 490,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64508",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:52:01.732Z",
      "date_updated": "2026-07-27T04:37:46.726Z",
      "publisher": "Linux",
      "title": "bpf: Support for hardening against JIT spraying",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00157,
        "percentile": 0.05335
      },
      "nvd": {
        "published": "2026-07-25T10:17:36.920",
        "lastModified": "2026-07-27T05:16:55.600",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64508",
        "family": "HARDWARE_PHYSICAL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Reused executable BPF JIT memory retains indirect-branch predictor state from the previous program and enables cross-program speculative steering.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6e52c240c43a601b681e3a4e58fc5685114d4726",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/eed774da601268dae674e14d54a15e3624691f52",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8ff183ee4d8c452960df58175a094828c0513b2e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7a6c171c6a1ac6d1509752dac131d941a3de0b37",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/96cce16e26dd02a8678f1e87f88a4b5cdb63b995",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1151,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64509",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:52:02.486Z",
      "date_updated": "2026-07-25T08:52:02.486Z",
      "publisher": "Linux",
      "title": "rust: block: fix GenDisk cleanup paths",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00157,
        "percentile": 0.05332
      },
      "nvd": {
        "published": "2026-07-25T10:17:37.030",
        "lastModified": "2026-07-25T10:17:37.030",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64509",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cleanup paths omit put_disk and leak the gendisk and queue resources.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d1dcaa5229a63a6b6df7e0f673fe576cf3d6e8cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e7636f26f77070a529c26d65afd217514ce85ce4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6822a2685b4da9a87efd1fce4b042678a31ff734",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2957771379fa335103a4b539db57bb2271e12142",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 862,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64510",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:52:03.208Z",
      "date_updated": "2026-07-27T05:01:33.494Z",
      "publisher": "Linux",
      "title": "ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00111,
        "percentile": 0.0152
      },
      "nvd": {
        "published": "2026-07-25T10:17:37.137",
        "lastModified": "2026-07-27T05:16:55.720",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64510",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "NFIT initialization failure frees acpi_desc without removing it from the global list, leaving later machine-check handling to dereference a dangling pointer.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ee82078e776ae31266cc70fdf62ac17c3c6f100a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6ff054cc02a763914773b026cacb429e5fbf64fa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b07d22a2d17ad6465c87bd5752bc70e4c16e0ee4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c127dbd832bd4b9aef8a749d9f491b74042f9b47",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/df7c92216a1583a76cb0cbf2f21cd68870609b05",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3b2628f7682aea8d9ce09ad4b9a3bd144b451eaa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7d69235bdc581a4346e9bcd6a8bea37d3e1abd25",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/38bf27511ef41bffebd157ec3eba41fc89ba59cd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1836,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64511",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:52:03.818Z",
      "date_updated": "2026-07-25T08:52:03.818Z",
      "publisher": "Linux",
      "title": "ACPI: NFIT: core: Fix possible NULL pointer dereference",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00156,
        "percentile": 0.05287
      },
      "nvd": {
        "published": "2026-07-25T10:17:37.273",
        "lastModified": "2026-07-25T10:17:37.273",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64511",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The NFIT notify handler can run after probe returns without allocating acpi_desc and then dereference the absent driver-data pointer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a44343fe230aa48c74ef09830f3c5c90848b257e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3c8f73b0fbdf956c98e2329d5aaea3ad09a9cfb6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/452945662fd8e9862a2d2043239c7ee1815d1ac4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/873576e585da5d0fc5debbab74eed565c0acea99",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/027e128abb82788189d6d45b68e3e8e7329b67be",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 753,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64512",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:52:04.423Z",
      "date_updated": "2026-07-25T08:52:04.423Z",
      "publisher": "Linux",
      "title": "ACPI: CPPC: Suppress UBSAN warning caused by field misuse",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 21,
        "versionRangeCount": 19,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00173,
        "percentile": 0.06966
      },
      "nvd": {
        "published": "2026-07-25T10:17:37.380",
        "lastModified": "2026-07-25T10:17:37.380",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64512",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ACPI CPPC path interprets access_width under the wrong address-space meaning and shifts a 32-bit value by an out-of-range count.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b54c4632946ae42f2b39ed38abd909bbf78cbcc2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e904596ba6dd108534ffa15e3e46b2fe245145e2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2fb80e962029000959f651665baa4838cc92eb99",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/37f28bf8f14672dfa395994e41fd778a63f0bf5c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f29dc6132d4968e39d8fa575d1a12e2c718ce57b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dc066bd13c860bb27d6ace511210e18b8064c1d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1050,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 21
      }
    },
    {
      "cve_id": "CVE-2026-64513",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:52:05.119Z",
      "date_updated": "2026-07-25T08:52:05.119Z",
      "publisher": "Linux",
      "title": "KVM: x86: Unconditionally recompute CR8 intercept on PPR update",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00171,
        "percentile": 0.06699
      },
      "nvd": {
        "published": "2026-07-25T10:17:37.510",
        "lastModified": "2026-07-25T10:17:37.510",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64513",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "KVM updates the guest PPR without always recomputing the CR8 intercept, leaving a stale TPR threshold that can make the next VM entry fail.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ff9c4c6428883182960cfe5c78928f0896d80ebc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8c8e8ac22ee17d52f9eb2bc814bca7fab90fb8df",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bb365a506b1e6fb050c0fceaad354fe395385ef0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2305,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64514",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T08:52:05.878Z",
      "date_updated": "2026-07-25T08:52:05.878Z",
      "publisher": "Linux",
      "title": "userfaultfd: gate must_wait writability check on pte_present()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00177,
        "percentile": 0.07462
      },
      "nvd": {
        "published": "2026-07-25T10:17:37.633",
        "lastModified": "2026-07-25T10:17:37.633",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64514",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "userfaultfd interprets write bits from non-present swap or migration entries, which can leave a fault waiting for a wake that never arrives.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/a5700a4c1c9099ac2ac73fe8a09cf059972e0d2f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d4026417e8184d13850a0bad4d96ceb6ed9f7152",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/29e6f952c5fb7dc1d6b90fe5b7f36063d44ddae0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/5f4dbdb0a87596214076b20b94f2b71b522170b3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6e9a4939e359599701b1da351e84f72e021443a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/60d696a037eeeedfb57756dfe7ec08a1587c8631",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/710183888174639a15fcec16cd1af766b8480bb7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8e80af52db652fbc41320eee45a4f73bc029faf2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1157,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64515",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.793Z",
      "date_published": "2026-07-25T09:14:42.418Z",
      "date_updated": "2026-07-27T05:01:34.611Z",
      "publisher": "Linux",
      "title": "wifi: mac80211: fix MLE defragmentation",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14898
      },
      "nvd": {
        "published": "2026-07-25T10:17:37.763",
        "lastModified": "2026-07-27T05:16:55.870",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64515",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The MLE defragmenter pairs a pointer to a defragmented copy with the original element container, making offsets refer to mismatched buffers and enabling an overread.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1f573e17bcb7275ddd1c8f47f46ae0faf0e902a4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/55c479aae99b120489a432db9c717484e523dfd6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/722b3f86df80644463d29fe5451e30a617f74500",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a74e893f30db64cdce0fc7a96d3baa417bcd55f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 825,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:14:43.142Z",
      "date_updated": "2026-07-27T05:01:35.782Z",
      "publisher": "Linux",
      "title": "drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 6,
        "versionRangeCount": 5,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00112,
        "percentile": 0.01593
      },
      "nvd": {
        "published": "2026-07-25T10:17:37.870",
        "lastModified": "2026-07-27T05:16:55.983",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64516",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The amdgpu VCE1 buffer size omits the firmware offset, allowing firmware, stack, or data placement to extend beyond the reserved object.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ce0de178ef08408f6ba8f2e9a13bf52fbe5852f4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3e5a1d5bb2ff061e64c7992f8e5404dfd4c2d0f3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 520,
        "referenceCount": 2,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64517",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:14:43.863Z",
      "date_updated": "2026-07-25T09:14:43.863Z",
      "publisher": "Linux",
      "title": "drm/xe/gsc: Fix double-free of managed BO in error path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06472
      },
      "nvd": {
        "published": "2026-07-25T10:17:37.973",
        "lastModified": "2026-07-25T10:17:37.973",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64517",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An explicit free is followed by device-managed unwind freeing the same allocation a second time.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7cb975fcd4777e7bad688f66aa0c10c16dd8276b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2c890e71ae26fa32f5a96c3694b71a2c310940e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/889f70de2b51a877339e1979aab95111b41bed75",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d3ded53fab90996e7d94a39049e11962dd066725",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 587,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64518",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:14:44.603Z",
      "date_updated": "2026-07-25T09:14:44.603Z",
      "publisher": "Linux",
      "title": "tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 11,
        "versionRangeCount": 10,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.064
      },
      "nvd": {
        "published": "2026-07-25T10:17:38.080",
        "lastModified": "2026-07-25T10:17:38.080",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64518",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "tcp_ao_established_key calls lockdep_sock_is_held on a shorter tcp_timewait_sock object and reads sk_lock beyond that object's layout.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/87bb3e719042f0030a6dad39118c6a6b2a491ad9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/510db031ba6eb40134f84c90ef963ea4b6dfb878",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/29cf64d128c94cf98d1c69d8b2962d39db5ff4c6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/03cb001ef87b3f8d859cf7f96329acf3d6235d29",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 638,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 11
      }
    },
    {
      "cve_id": "CVE-2026-64519",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:14:45.322Z",
      "date_updated": "2026-07-25T09:14:45.322Z",
      "publisher": "Linux",
      "title": "NFSD: Fix infinite loop in layout state revocation",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06473
      },
      "nvd": {
        "published": "2026-07-25T10:17:38.187",
        "lastModified": "2026-07-25T10:17:38.187",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64519",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "NFSD skips a failed revoke without marking progress, causing the same entry to be retried indefinitely.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d1fc00ec02e9deb3f8d2bd59caf938c554fbc576",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fe59ae27d7346245f5d8d97220f374e63efd28b5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/44e5e4eb3a07bf3e1d931dd9f96f3edcfa376605",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4f8ef58c10bfe5f86a643c7c8331b37e69e3dae1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64520",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:14:46.005Z",
      "date_updated": "2026-07-27T05:01:37.019Z",
      "publisher": "Linux",
      "title": "firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03063
      },
      "nvd": {
        "published": "2026-07-25T10:17:38.290",
        "lastModified": "2026-07-27T05:16:56.093",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64520",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The FF-A register response uses firmware-provided indices to copy partition descriptors without validating count and index progression against the destination array.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f39bc7ebe75e2186b417a024a7f7e2fd4cc7eb95",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/79d95c02ae0a95e6e80e8e92b7ca74ecee02854f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3974ea1938406f9bfa7c1f48d4e43533f447bb08",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64521",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:14:46.709Z",
      "date_updated": "2026-07-25T09:14:46.709Z",
      "publisher": "Linux",
      "title": "pinctrl: meson: amlogic-a4: fix deadlock issue",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00166,
        "percentile": 0.06278
      },
      "nvd": {
        "published": "2026-07-25T10:17:38.393",
        "lastModified": "2026-07-25T10:17:38.393",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64521",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The pinconf-pins path reacquires the same mutex already held by its caller and deadlocks.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e917713f013423069782ff554935c7a5d4266783",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/744ac926c0e55267a10b49b5b72582afef4ad49f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e72ce029810390eb987a036fb2c8a5da9a23b685",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 411,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64522",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:14:47.404Z",
      "date_updated": "2026-07-27T05:01:38.188Z",
      "publisher": "Linux",
      "title": "net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 8,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27374
      },
      "nvd": {
        "published": "2026-07-25T10:17:38.497",
        "lastModified": "2026-07-27T05:16:56.213",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64522",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The temporary IPsec acquire-SA path decrements the eswitch mode-block counter even though that path never incremented it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b5bd4249e430f5963d559708ee96a671716d2400",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ecafd8284e527666e83261e6e57a7c7341d591cb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/abe003b33223ff33552f291644bf35d9c2f992fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 717,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64523",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:20:47.606Z",
      "date_updated": "2026-07-27T05:01:39.425Z",
      "publisher": "Linux",
      "title": "net/handshake: Take a long-lived file reference at submit",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27389
      },
      "nvd": {
        "published": "2026-07-25T10:17:38.597",
        "lastModified": "2026-07-27T05:16:56.327",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64523",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The kernel handshake request stores a file pointer without taking the long-lived reference required for asynchronous use, allowing the file to be freed first.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/685b10dd0e32c7782cead16c8cf055c609678583",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/16eaba5aa89c04eea125905bb8f988c1897f4f29",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/09dba37eee70d0596e26645015f1aa95a9848e9d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1423,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64524",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:20:48.193Z",
      "date_updated": "2026-07-27T05:01:40.599Z",
      "publisher": "Linux",
      "title": "drm/hyperv: validate resolution_count and fix WIN8 fallback",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04128
      },
      "nvd": {
        "published": "2026-07-25T10:17:38.713",
        "lastModified": "2026-07-27T05:16:56.447",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64524",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Hyper-V display parser walks a fixed 64-entry resolution array using an unbounded device-supplied resolution_count.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/96f7de3172d4aa878b7f87173b2b3507c350fcd6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bc573752f3dac0d1ab8df7078c1851bc76717653",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1fb565b77b8f44afabb02de6310065f109d89e94",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a321c908f2eeea01539668eb270d074d9b88e490",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9c698b2c43c2667c34f5336bf46ad5786216ac2a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8a114b25b5521eae451b13bce98ae978624962e5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/13d33b9ef67066c77c84273fac5a1d3fde3533d1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 820,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64525",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:20:49.256Z",
      "date_updated": "2026-07-25T09:20:49.256Z",
      "publisher": "Linux",
      "title": "xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00156,
        "percentile": 0.05276
      },
      "nvd": {
        "published": "2026-07-25T10:17:38.830",
        "lastModified": "2026-07-25T10:17:38.830",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64525",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "xfrm teardown performs one blocking RCU grace period per network namespace instead of batching the synchronization, allowing cleanup queues and per-CPU memory to grow without an effective bound.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bca6386dc08750fc7cdcbc7683473748ba3114b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/91cc13978ab0bc6f669139f53e7e613a860d10e0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d14ae8ef88c2c6590e107db61b6adce148cec7b3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3e52417318473782012b236d0325bf7d2266a597",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1642,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64526",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:20:50.394Z",
      "date_updated": "2026-07-25T09:20:50.394Z",
      "publisher": "Linux",
      "title": "ethtool: tsconfig: fix missing ethnl_ops_complete()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 8,
        "versionRangeCount": 7,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00154,
        "percentile": 0.05121
      },
      "nvd": {
        "published": "2026-07-25T10:17:38.950",
        "lastModified": "2026-07-25T10:17:38.950",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64526",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The tsconfig error path returns after ethnl_ops_begin without calling the matching ethnl_ops_complete cleanup.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d02342d9bb4f0ab682f1846a4fbc15dd2955f7e6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d53fe379d1f9a92e8a1bb2556084c8c177ebf8fd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6386bd772de64e6760306eb91c7e86163af6c22f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 3,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-64527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:20:51.078Z",
      "date_updated": "2026-07-25T09:20:51.078Z",
      "publisher": "Linux",
      "title": "drm/hyperv: validate VMBus packet size in receive callback",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00161,
        "percentile": 0.05695
      },
      "nvd": {
        "published": "2026-07-25T10:17:39.053",
        "lastModified": "2026-07-25T10:17:39.053",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64527",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Hyper-V graphics receive callback reads type fields and copies a packet without first proving that the host supplied the required bytes within the receive buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/57d5d697642e05d5dd2d40660817765943dd709f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f5251226551bfec98c4705641b6f94ff1f238d91",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/049a6b474823049fe60212f25f26e4b30f44ee8f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/588c84b461393ff1998ac7b97b04f953f642e0df",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/164dc7bf17609340233c6bf4f66bb7c7008a0511",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c8974d96b6a5496f33dc69a3ce28a7bf5078def4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7f87763f47a3c22fb50265a00619ef10f2394b18",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 2072,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64528",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:20:51.774Z",
      "date_updated": "2026-07-25T09:20:51.774Z",
      "publisher": "Linux",
      "title": "tty: serial: samsung: Remove redundant port lock acquisition in rx helpers",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06412
      },
      "nvd": {
        "published": "2026-07-25T10:17:39.187",
        "lastModified": "2026-07-25T10:17:39.187",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64528",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Serial callbacks invoked with port lock already held call receive helpers that acquire the same non-recursive spinlock again and deadlock.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ee9eb72be95490602c493db050c73d925c3a4d74",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/10014eb7eee351f7b587f8ac85830f0c9343cb9a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f4c3e63fa8639aedf96fb200d9939945a9eed51e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a9c22e0f93ba18322a6623ecdda2f0cd858ca350",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/14143ec10d69f42806b5d7b046f0fd1b835831ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9fd48937046efc9abb89379d63ee9cc5c661d711",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9c92b42207978559e32903c3098aaf5c5b5788b2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a3bb136bff5e6a5e48cdd813246c9c4686feaaa9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1145,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64529",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-25T09:24:18.750Z",
      "date_updated": "2026-07-27T05:01:41.855Z",
      "publisher": "Linux",
      "title": "crypto: qat - remove unused character device and IOCTLs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 19,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03379
      },
      "nvd": {
        "published": "2026-07-25T10:17:39.317",
        "lastModified": "2026-07-27T05:16:56.580",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64529",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "The record removes an unused ioctl surface and mentions unspecified bug reports but does not identify a concrete vulnerable operation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/071590a44cbc38483fceb1ab943363ec26868e1b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1de076f43e64bf65fbe7280a269c70e0e60518df",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a4999664a5ef77bdb0c6e6b935f581ac8ce6b63a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6848a6e39cac44fdb7cb88f0f777df62172d1551",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b1ea97076bd0a5196290deba172034e480646727",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b8ebf008696de1ec08c90d51f94d7e40bd448be1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/de2cc38489b629927910b1aeff69bba7bd5c6f1b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3ae49dd04dbb11fb73f17f58a982dba128abe83a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d237230728c567297f2f98b425d63156ab2ed17f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1177,
        "referenceCount": 9,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-26T06:28:42.970Z",
      "date_updated": "2026-07-27T05:01:43.021Z",
      "publisher": "Linux",
      "title": "net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 21,
        "versionRangeCount": 19,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00509,
        "percentile": 0.40613
      },
      "nvd": {
        "published": "2026-07-26T07:16:41.680",
        "lastModified": "2026-07-27T05:16:56.730",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64530",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The qevent path continues using an skb after TC_ACT_CONSUMED transferred ownership to the defragmentation engine.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5ed3d6f85991656667059d3fa5a1d683ac58c447",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f42e8134a3a1074b834a574d404352f867ba994a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/447d493034a9cf7bf13a2abac86d0573d907ec2f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e1270e69dcf2c3512c453484178f2e9dc0db3f05",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2140c2f3f2e7b066e1ae616ede8856cafd8015e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e28aedab9488343924d227b5a896faed67ce84d5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a8a02897f2b479127db261de05cbf0c28b98d159",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1291,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 21
      }
    },
    {
      "cve_id": "CVE-2026-64531",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-27T06:32:32.596Z",
      "date_updated": "2026-08-01T06:50:00.893Z",
      "publisher": "Linux",
      "title": "net: openvswitch: reject oversized nested action attrs",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 22,
        "versionRangeCount": 20,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02936
      },
      "nvd": {
        "published": "2026-07-27T08:16:22.243",
        "lastModified": "2026-08-01T08:16:29.920",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64531",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An oversized nested Open vSwitch action truncates its 16-bit length, so later walkers reinterpret bytes outside the validated structure.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ab855641241387db062a5e41d9ad6b8561542572",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c66bd2626c2764f23764ff0f8277f44a9cfe8349",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d573250d228401f707f4dbc09d11227a6215ee5f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f1efff8858403191361a01269c6fe8dd7f55a385",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dbd14f736be02cfe73049bd801af89becd1a0749",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1b41cbe05b184f8861712f0806cc0c4f5d8c6dfe",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3f1f755366687d051174739fb99f7d560202f60b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/8",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/31/17",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/01/1",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/01/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1558,
        "referenceCount": 11,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 22
      }
    },
    {
      "cve_id": "CVE-2026-64532",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.794Z",
      "date_published": "2026-07-27T06:32:33.159Z",
      "date_updated": "2026-07-30T06:06:27.947Z",
      "publisher": "Linux",
      "title": "fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03024
      },
      "nvd": {
        "published": "2026-07-27T08:16:22.383",
        "lastModified": "2026-07-30T06:25:57.087",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64532",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "NTFS3 uses the on-disk view.data_off as a memmove destination without checking view.data_off plus data length against the containing entry size, allowing an out-of-bounds write.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b20e5a709d8bd190d6e4645606763c7423e694c1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d41b382068ca4e64e421f736cdd700095464b6ac",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/429d653ca641d38a78609b8f62e81a0a5c780a2d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/315d3a9a48b49f889da3d858a9307e677cb9e1bd",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/be306b8d9143a9c076c804a7ca025d69caf9c448",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/36feda687afebae24c472202694448738809c411",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3e127829e57f5190f612412ece4541cb96d5ec7a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1273,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64533",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T06:32:33.740Z",
      "date_updated": "2026-07-30T06:06:29.019Z",
      "publisher": "Linux",
      "title": "fs/ntfs3: validate lcns_follow in log_replay conversion",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03539
      },
      "nvd": {
        "published": "2026-07-27T08:16:22.510",
        "lastModified": "2026-07-30T06:25:57.223",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64533",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "NTFS3 derives a memmove length from an unconstrained on-disk lcns_follow count and accesses beyond the restart-table buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ca343a99806b4fc8e27c48f08be3445c5fcd1445",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ddfc8683e1a627dbf1b83bacf8961443dd654258",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57c071e2c4f30b9c6f5aacb6679aab1269fbae99",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/159f694d682e4215b3822ae31ed3a4631628fe55",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7adb38279812c9c06b0e3fa7382f4d7887f3fa2d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/32b9f8733feb241627fa5f564b1a99b5cae974c5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6a4c53a2e26a865565bd6a460961e8d6fcb32329",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1265,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64534",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T06:32:34.301Z",
      "date_updated": "2026-07-30T06:06:30.094Z",
      "publisher": "Linux",
      "title": "nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 20,
        "versionRangeCount": 20,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00384,
        "percentile": 0.31103
      },
      "nvd": {
        "published": "2026-07-27T08:16:22.643",
        "lastModified": "2026-07-30T06:25:57.350",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64534",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The digest-error path uninitializes a request whose initialization already failed, underflowing a reference count and leading to use-after-free behavior.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c7874dad84b20433c0fe3919f291a762d40de08b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d306da8833e75f669d93424fd84940236f3850bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2ed3c9d955e8cd6361f130623baa664a75fb345f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4606467a75cfc16721937272ed29462a750b60c8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 792,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 20
      }
    },
    {
      "cve_id": "CVE-2026-64535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T06:32:34.859Z",
      "date_updated": "2026-07-30T06:06:31.160Z",
      "publisher": "Linux",
      "title": "nvmet-tcp: Fix potential UAF when ddgst mismatch",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 14,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00473,
        "percentile": 0.38414
      },
      "nvd": {
        "published": "2026-07-27T08:16:22.773",
        "lastModified": "2026-07-30T06:25:57.470",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64535",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A digest mismatch uninitializes a command without marking it complete, so teardown later uninitializes the same command again.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/96fe2513df590e74b04253a45089cae75569570e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e091ff83d962f9ed00d9bd70443676de9fe98bdc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6f9442983a3e4227afd1c83a5251ddbca585ea21",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/088ee46c18d99baef453afd74181dd40ade044ad",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dbbd07d0a7020b80f6a7028e561908f7b83b3d5a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1000,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T06:36:04.736Z",
      "date_updated": "2026-07-30T06:06:32.237Z",
      "publisher": "Linux",
      "title": "staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16708
      },
      "nvd": {
        "published": "2026-07-27T08:16:22.890",
        "lastModified": "2026-07-30T06:25:57.580",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64536",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "is_ap_in_tkip reads IE headers and vendor payload offsets without first checking the remaining buffer and element length.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ea3809f7e20bdff282b8cc1e94937d5fb9fb32c7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d2055332297e24c63fffda943ef7a5eefc0a6019",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6f26cc55affd9d7f88ae2f5d12db4ecf9072c209",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/204b22c8df115370037248859bf0fa62db73a396",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6105ea8ca6ebbc04beaf3bcbf7dbb5985f5d395",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4380b3860d887a13555ff024a58dfc05b490dfd6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3bf39f711ff27c64be8680a8938bcc5001982e81",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 823,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:32.210Z",
      "date_updated": "2026-07-27T20:10:32.210Z",
      "publisher": "Linux",
      "title": "bridge: cfm: reject invalid CCM interval at configuration time",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00172,
        "percentile": 0.06879
      },
      "nvd": {
        "published": "2026-07-27T21:17:05.987",
        "lastModified": "2026-07-27T21:17:05.987",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64537",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The bridge CFM transmitter accepts a zero CCM interval and continuously requeues its work with no delay.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2870056a78961e0fecd652362ee9d3fcfd24a8a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f0f5eb59a97ece0d85de8cfa95dc18c609302a8b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/53788b134519e995699ea3721969c96a08d64575",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b42aeb58317f12024734759ff745856b53948873",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a090880c1f544589427e5b7050c40fb211ccecb4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/865643640b5b5c4579b32d7a55ac9ad648362eaa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f3e02edd8322b31b8e6517faa6ba053bf29d1e26",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 823,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:32.779Z",
      "date_updated": "2026-07-27T20:10:32.779Z",
      "publisher": "Linux",
      "title": "ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00176,
        "percentile": 0.07379
      },
      "nvd": {
        "published": "2026-07-27T21:17:06.130",
        "lastModified": "2026-07-27T21:17:06.130",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64538",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "fib6_nh_mtu_change re-fetches the IPv6 device state after interface teardown and dereferences the resulting NULL pointer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d08d019f2f43a6f9a71e81868bbc326b3afaf37b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1451deca9896957159f0666520a792c1b861af4f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b2c70dd3326809429b709a9c7e9220d29923051a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/302d57ed7872838b40e56a868fb4c7da7da606e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/80600b5d0f3ecb9324120dc95b5e915130f516c5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b0d0eb13a0441a8ebf4f227843deaf494f1e2c33",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6428634f7a0b7878144b4925c37856bef3224967",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/46c3b8191aad3d032776bf3bebf03efdf5f4b905",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1116,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64539",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:33.363Z",
      "date_updated": "2026-07-30T06:06:33.307Z",
      "publisher": "Linux",
      "title": "Bluetooth: eir: Fix stack OOB write when prepending the Flags AD",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02356
      },
      "nvd": {
        "published": "2026-07-27T21:17:06.277",
        "lastModified": "2026-07-30T06:25:57.697",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64539",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "It may prepend a 3-byte \"Flags\" AD structure (LE_AD_NO_BREDR on an LE-only controller) and then copies the per-instance data without checking that it still fits: memcpy(ptr, adv->adv_data, adv->adv_data_len); tlv_data_max_len() only reserves those 3 bytes when the user-supplied flags carry a managed-flags bit, so an instance added with flags == 0 is accepted with adv_data_len up to the full buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0f0b6232af56441d0a2dcb173cc4f8d8aab39014",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/09301f1fdf2aef8cce34d0c4650c30e7edb1ced9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f1b4df9c260c51726da2e86e19322825fddeefd0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/57077eeb586c42f124bc09e018449362223067b3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6f5fb689fdf80bdd143f22a502f9eb1f3c85e286",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1613,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64540",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:33.905Z",
      "date_updated": "2026-07-30T06:06:34.381Z",
      "publisher": "Linux",
      "title": "usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19952
      },
      "nvd": {
        "published": "2026-07-27T21:17:06.407",
        "lastModified": "2026-07-30T06:25:57.817",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64540",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The GeneLink receive path trusts a device-supplied packet length without comparing it with the bytes actually received, copying beyond the receive buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/255d03551f94c7bdd86c7d9181a70b21917d829f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4359376e6238d89977a35086e47ca3b07f43e850",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8624e179fa3ce23c2fbd1a198ce30764b73f054a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/573418f7ea8f859a841417eb4b915594094fd967",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0575599e451aff3c5329922562374a2cab25fc51",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0a7d9c7c5f1f208c523abbb4db6aea7bc1fad3db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3ef79fa3860e644c8de7834fa7300e1c58f38862",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8ff7f2a6da4fccaa5cc9be7251a24e71e29fbd1a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1728,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64541",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:34.439Z",
      "date_updated": "2026-07-30T06:06:35.458Z",
      "publisher": "Linux",
      "title": "net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00521,
        "percentile": 0.41343
      },
      "nvd": {
        "published": "2026-07-27T21:17:06.570",
        "lastModified": "2026-07-30T06:25:57.950",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64541",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SMC receive handler drops conns_lock before taking a socket reference, allowing concurrent unregister and close to free the socket first.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8de4f665d0febfb92803dece377791a563fc7041",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8145b432136285e01091815b48ceb2dae261f262",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1951bffbc6493ec34cff3956b29d4bc6606904a6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/647b19e5cc145a2f1f685ae8ff3805a17356888c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/472e9d7c0d5b03be3ff91ff941f57da822b031bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3bfb96d9bc6a7ed0b99c7db329cc2e22a28d84bb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ce5aa8084329351086894aa34d77e40301d5bd3d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9d160b35cc34a2ba8229d07651468a7848325135",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1608,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64542",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:34.994Z",
      "date_updated": "2026-08-03T09:32:42.268Z",
      "publisher": "Linux",
      "title": "ipv6: ndisc: fix NULL deref in accept_untracked_na()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00168,
        "percentile": 0.06399
      },
      "nvd": {
        "published": "2026-07-27T21:17:06.730",
        "lastModified": "2026-08-03T10:16:32.820",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64542",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "accept_untracked_na re-fetches an IPv6 device pointer after a concurrent interface-down path can clear it, then dereferences the null result.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/160d3f0d7a556ceae505dcab521a37057b4ce28f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/62c719203cb521b64fab74da94a81bdde5c18808",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6450f7cfae57b382cbaf66a577765c9a88b3c58",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/63d1c23764de2309cedbb779c75188d257a09d9b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d186e942365acece7c56d39da05dd63bf95b280a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1359,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64543",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:35.565Z",
      "date_updated": "2026-07-30T06:06:36.526Z",
      "publisher": "Linux",
      "title": "tipc: fix use-after-free of the discoverer in tipc_disc_rcv()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02591
      },
      "nvd": {
        "published": "2026-07-27T21:17:06.850",
        "lastModified": "2026-07-30T06:25:58.083",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64543",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "UDP bearer teardown frees a TIPC discoverer without an RCU grace period while an RX softirq may still dereference it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5e215bf1c47fdddf8203a0fe80a0ed594065f101",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ec7d54d8cc1723921d671e3272b427c96366506f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b65289e1c3f352a9f92c6e19713ddd647e033253",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1579342d71133da7f00daa02c75cebec7372097b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1693,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64544",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:36.101Z",
      "date_updated": "2026-07-27T20:10:36.101Z",
      "publisher": "Linux",
      "title": "crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00176,
        "percentile": 0.07378
      },
      "nvd": {
        "published": "2026-07-27T21:17:06.980",
        "lastModified": "2026-07-27T21:17:06.980",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64544",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Unsigned hash-length arithmetic underflows and produces a very large out-of-bounds read.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/89efd998470a93284b7ad5a20d4e0e3c6858ae8e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7016377699b5b25b7ec3c0bf2ec3f983c7e95f7c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b798ada5a5d1cb4cc4cfa72074b1b463eca6c506",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/627938383761fb4334b41ebe7ef438d6b8b19d60",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e162bc386e71b5412425a38ee048e8d2185491b9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6acd2fbd00f9c72aebefce63fc2e73e8f3d79061",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/803591785d33cf13b6f73ce2796e8b9e6d5e6526",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f7dd32c5179d7755de18e21d5674b08f9e5cb180",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1217,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64545",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:36.659Z",
      "date_updated": "2026-07-30T06:06:37.589Z",
      "publisher": "Linux",
      "title": "net, bpf: check master for NULL in xdp_master_redirect()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00496,
        "percentile": 0.39845
      },
      "nvd": {
        "published": "2026-07-27T21:17:07.130",
        "lastModified": "2026-07-30T06:25:58.200",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64545",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Bond teardown removes the upper-master link before clearing the slave flag, so XDP can observe a slave state with a null master and dereference it.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c99ca049e910d61ddbd28cc2c47242f2bfbb4970",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e2a56441233131fe18a76001de347ecda217e40c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3876318ea54e83eb70982b8280a3c5e4e32269bf",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4edbcacca09f92b85d3951b6add11894b20a84bc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/03b743586a2469744e96e9c1015096d07240935d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/89c103d702b25ceb2d097faf854deb47b53b17ff",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e82d8cc4321c373dc46e741cd2dfdaa7921fddb7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1662,
        "referenceCount": 7,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64546",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:37.217Z",
      "date_updated": "2026-07-30T06:06:38.661Z",
      "publisher": "Linux",
      "title": "drm/edid: fix OOB read in drm_parse_tiled_block()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02632
      },
      "nvd": {
        "published": "2026-07-27T21:17:07.270",
        "lastModified": "2026-07-30T06:25:58.330",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64546",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "drm_parse_tiled_block reads the fixed tiled-display structure without first requiring the declared DisplayID payload to contain all 22 bytes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c4ab04ca1bbf87eefa9fec5c80e1880450d2e7c0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9acd5c1ddc17ca4c5ffa0c373e3fdf480506e061",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/157727131ce8a52d8d9bc676c372ef82db6436c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bfa05d89dc3ca3fb1a9099ef5185549a5ec8490d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4f5484d25f85ad6c989bad5f6a43450cecfcfd28",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9cc0f8e63e8c34cf43def35cbd305ba711181a1f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4137e1ecec9c8cb6c4fcee28ffabbbc7409eb7fb",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/faaa1e1155833e7d4ce7e3cfaf64c0d636b190db",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1421,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64547",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:37.786Z",
      "date_updated": "2026-07-30T06:06:39.748Z",
      "publisher": "Linux",
      "title": "net: usb: net1080: validate packet_len before pad-byte access in rx_fixup",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19953
      },
      "nvd": {
        "published": "2026-07-27T21:17:07.427",
        "lastModified": "2026-07-30T06:25:58.463",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64547",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "net1080_rx_fixup reads a pad byte at a device-declared packet length before checking that the offset lies within the received socket buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f42217fa7d535e9ec4151f7971f06f6ea65e850a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c087749815379e9af2fdbeb08bfc33870b103958",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e4a87126c085b097d29e17e3b7647295bba8be7c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/685e92934f11d5e215dad58813e2f9955ac2f436",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4dc8484be3302d187274364820d3bef6c62bde32",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b153cfe84b1340c69a13d0957665a2bfcf21239c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ea866cab12db1a2100b400a8b03569e5bc0ee29a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/03f384bc0cb8d4a1301d4f5b0baef2d980258383",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 956,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64548",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:38.355Z",
      "date_updated": "2026-07-30T06:06:40.825Z",
      "publisher": "Linux",
      "title": "bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04128
      },
      "nvd": {
        "published": "2026-07-27T21:17:07.570",
        "lastModified": "2026-07-30T06:25:58.590",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64548",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "bpf_msg_push_data adds two u32 lengths without an overflow check, allocates the wrapped size, and then copies beyond the allocation.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f1644c9508d24f50dd9e8ebe8d3ba86e0996d2f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a12b1575f9feabd91695a9e9d004862f7195fa25",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ff39d0e3b4feeb65ca43c453d7c75fdf872ded0d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/888706a76286c547bd035432602571e8024b5305",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/db77b6bb6e6edb79b10b4efcce346eec5582d588",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4e40056bb5c829f0423f0a6694a0477726d2147e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bd004716ba75fed6d185795c85cdc92540ebeaab",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/0c0a8ed85349dae298712d79cb276acfeb794d82",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1050,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64549",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.795Z",
      "date_published": "2026-07-27T20:10:38.894Z",
      "date_updated": "2026-07-27T20:10:38.894Z",
      "publisher": "Linux",
      "title": "Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.0018,
        "percentile": 0.07805
      },
      "nvd": {
        "published": "2026-07-27T21:17:07.720",
        "lastModified": "2026-07-27T21:17:07.720",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64549",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "bpa10x prints a device response as a null-terminated string without checking that bytes remain after the status byte or contain a terminator.",
        "basis": [
          "CNA record"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1813add71e386f77b3040e6c8dc9b7b3ff965a6c",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bd56c23f1f8681a2857ee924a8bd3abf87c8913b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7a64f39ebe1bacd9004a62eceadac0b122ec3cc2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f80b4afe893dffa9fabdbf80fb4d6782b24a6793",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4b4008dda1d0c6e598d7865631ad4eda63a560f0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bfc9e7be289df11e8e38c98cd78019d67fdd0bd5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a8e169d308775039200bb9c905c7ce420db6e8c5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dd068ef044128db655f48323a4acfd5907e04903",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1024,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64550",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.796Z",
      "date_published": "2026-07-27T20:10:39.459Z",
      "date_updated": "2026-07-30T06:06:41.902Z",
      "publisher": "Linux",
      "title": "net: qualcomm: rmnet: validate MAP frame length before ingress parsing",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02631
      },
      "nvd": {
        "published": "2026-07-27T21:17:07.867",
        "lastModified": "2026-07-30T06:25:58.720",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64550",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The non-deaggregation ingress path skips MAP frame-length validation and dereferences header and checksum fields beyond a short packet.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ed25befc8c36f896b5878f9078faddb67fd7e2d0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a54d76d176e50d2fdbd39b7231efe256170339e4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/00f4c366dbca16a40772c3b7ec2d8cba839e9724",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/3868c3244369ab709a90c9aad7534d406009b824",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/14eb0c9491385d5361a292ea4974aec0e6887299",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1b12612c367e4be9b0814c0468e7e687835315b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/231a8a4b76cb1b1827b3b19d7b3603642f5aaaef",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f0f1887a9e30712a1df03e152dce6fb91344b1f3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1500,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64551",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.796Z",
      "date_published": "2026-07-27T20:10:40.012Z",
      "date_updated": "2026-07-30T06:06:42.965Z",
      "publisher": "Linux",
      "title": "sctp: validate STALE_COOKIE cause length before reading staleness",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00521,
        "percentile": 0.41343
      },
      "nvd": {
        "published": "2026-07-27T21:17:08.020",
        "lastModified": "2026-07-30T06:25:58.853",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64551",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The SCTP stale-cookie handler reads a four-byte staleness value without first requiring that the selected cause contains those bytes.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/6022da37786701df1fc5dd946a6dcba59d5473b1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/861f884f5471632c731cbbd612a1c072e391a624",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/588706ebaf8cdb4a4161602949eba365514b1db1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a257b41ddfe9e327b26581ad2777f04b23ac73f5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/08a8f2d13f703924316e9aeac863a88ef50990c7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ebe0a55d954fa8da383b6192edb8f763dcb002d5",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/bbd6b2ea966cf57b6ae095cf5a8dbc993cd197a0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1cd23ca80784223fa2204e16203f754da4e821f8",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1304,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64552",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.796Z",
      "date_published": "2026-07-27T20:10:40.570Z",
      "date_updated": "2026-07-30T06:06:44.048Z",
      "publisher": "Linux",
      "title": "virtio-net: fix len check in receive_big()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 19,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04128
      },
      "nvd": {
        "published": "2026-07-27T21:17:08.173",
        "lastModified": "2026-07-30T06:25:58.987",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64552",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A permissive length check lets page_to_skb advance one fragment past the end of the fragment array.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f9451d0fd5ba635dcabb49bfe456a6db734a8986",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/38e94d63e29f4a5c6eae87ee2c02101aaa321502",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/fbeb65154583879d556ea94cb2f15888e9470f3d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c7fc9adf4e006155f7f2aeda052fbcde25cdcc49",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e6b8463b7d791f3886d7584259d6e9f06a69f12e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/9e5ad06ea826322ce8c58b4a68442a96f600c3c4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 882,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 19
      }
    },
    {
      "cve_id": "CVE-2026-64553",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.796Z",
      "date_published": "2026-07-27T20:10:41.159Z",
      "date_updated": "2026-07-27T20:10:41.159Z",
      "publisher": "Linux",
      "title": "net: psample: fix info leak in PSAMPLE_ATTR_DATA",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "epss": {
        "score": 0.00176,
        "percentile": 0.07379
      },
      "nvd": {
        "published": "2026-07-27T21:17:08.307",
        "lastModified": "2026-07-27T21:17:08.307",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64553",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The psample implementation omits zeroing netlink alignment padding, disclosing up to three bytes of uninitialized kernel data.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0d3ea2ccddda442077fc44f11d873209c97ec50b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7fe7e6949964aa8ee6305f09db2dc9eede977bb3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e2fa322782a2d7d8078f7bb20817e0aa9f7c32e9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/befe1ebe7fc2c65c80074bc34ceeb0a721ed3cd2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/48930f6c59fd0056c2de46ce52bfe27d9c9e5eb6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a6cfb924ad74efce254e99c197d2e3863de70868",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/794a0d8bdbb39e083ed42caccb86d687a9b53570",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/aedd02af1f8b0bceb7f42f5a21c41634ca9ed390",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 359,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 0,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64554",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.796Z",
      "date_published": "2026-07-27T20:10:41.726Z",
      "date_updated": "2026-07-30T06:06:45.125Z",
      "publisher": "Linux",
      "title": "netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00258,
        "percentile": 0.17427
      },
      "nvd": {
        "published": "2026-07-27T21:17:08.437",
        "lastModified": "2026-07-30T06:25:59.110",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64554",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A checksum reallocation replaces the skb data area while code retains and later uses the previous header pointer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8c10778ec674b67a07ea042fcba64270f3f38a5a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2731efa6364e47934c96eb69e01ea131e8af8030",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/00c06ef8c018493943891a7d0ca82b71b24f3180",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/c141f69d0a0fb16964dbc293650047e69bda8af7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/f2e6596d10783557aeb9668da2a3b4d19deb2001",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1c4f67c89fd27c4df4c70b135c2c59627698b3c0",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/4ac981a8b7ce7aec99a52d08f8a8953e8e120067",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/86f3ce81dd2b4b0aa2c3016c989a943e4b1b643d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1524,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64555",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.796Z",
      "date_published": "2026-07-27T20:10:42.259Z",
      "date_updated": "2026-07-30T06:06:46.197Z",
      "publisher": "Linux",
      "title": "KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02893
      },
      "nvd": {
        "published": "2026-07-27T21:17:08.580",
        "lastModified": "2026-07-30T06:25:59.240",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64555",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Nested KVM writes a synthetic vCPU status value directly to SPSR_EL2 without translating it into hardware state during MOPS exception rewind.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/10a568010e827108d149779908850afaec898846",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/884b44256041ec6b2dcbe8e6a67384d26145cba1",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/dd3b237eb7780d65eae296d3d3a70012b6e7a02f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ff1022c3de46753eb7eba2f6efd990569e66ff95",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 718,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64556",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.796Z",
      "date_published": "2026-07-29T08:01:46.864Z",
      "date_updated": "2026-07-30T06:06:47.272Z",
      "publisher": "Linux",
      "title": "perf/core: Detach event groups during remove_on_exec",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 12,
        "versionRangeCount": 11,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02154
      },
      "nvd": {
        "published": "2026-07-29T09:16:30.153",
        "lastModified": "2026-07-30T06:25:59.350",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64556",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "remove_on_exec can delete a perf group leader without detaching surviving siblings from the stale group state.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4cdb1b3ab96eb1b7eb70bc5c82fede334bd60df2",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/39358e856fb89e62e3c8d7389a2dc4ec33dbe90e",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/a2d5d3ee7b6e3953114726b1521e62123ab5b043",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/06ccef0434e98058ddae7bcebc901f93d22b7653",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/037a3c43edfb597665dd34457cd22b14692f2ba3",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1189,
        "referenceCount": 5,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 12
      }
    },
    {
      "cve_id": "CVE-2026-64557",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.796Z",
      "date_published": "2026-07-29T08:01:47.462Z",
      "date_updated": "2026-07-30T06:06:48.348Z",
      "publisher": "Linux",
      "title": "Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 14,
        "versionRangeCount": 13,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14672
      },
      "nvd": {
        "published": "2026-07-29T09:16:30.280",
        "lastModified": "2026-07-30T06:25:59.477",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64557",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The L2CAP callback drops the parent lock before dereferencing a newly queued child that another thread can accept and free.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b39298044e5534612511a2ff5de03ba5f6e7a820",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/8c37e4338c801ebb8cee52436c01c41e009f6e87",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/84e718b6a814edc84159361f9f454a4e92ae91ae",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/36da806f7fbaee56ad9e81859deec203f9728700",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/733e76e74e406c1d1ddc7369420dd8a47f48bb8a",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6fef032af0092ed5ccb767239a9ac1bc38c08a40",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 1123,
        "referenceCount": 6,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 14
      }
    },
    {
      "cve_id": "CVE-2026-64558",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.796Z",
      "date_published": "2026-07-29T16:31:21.591Z",
      "date_updated": "2026-07-30T06:06:49.426Z",
      "publisher": "Linux",
      "title": "s390/pkey: Check length in pkey_pckmo handler implementation",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02132
      },
      "nvd": {
        "published": "2026-07-29T17:16:53.410",
        "lastModified": "2026-07-30T06:25:59.600",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64558",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A target handler trusts a caller-provided buffer length and can access beyond the supplied command buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/02028a24e26d85262ab9c8fc4344e1f3503007fc",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/433e5e70cdc1edf382d28d08a885b22e2b98b7da",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/614aa0491c7a190556c2345dddee0b6f5ed90989",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/1ac287e2af9a9112fe271427ef45eceb26bce8b4",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 361,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64559",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.796Z",
      "date_published": "2026-07-29T16:31:22.195Z",
      "date_updated": "2026-07-30T06:06:50.520Z",
      "publisher": "Linux",
      "title": "s390/pkey: Check length in PKEY_VERIFYPROTK ioctl",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 10,
        "versionRangeCount": 9,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02134
      },
      "nvd": {
        "published": "2026-07-29T17:16:53.523",
        "lastModified": "2026-07-30T06:25:59.707",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64559",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The PKEY_VERIFYPROTK ioctl trusts a userspace length that can exceed the fixed request buffer.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0a9e34ccbe772b8f321388cdbdf4f22b94e513e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/693bf91d4db134f9b1c2840c8e287eee3d993bac",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/7e7e03848c918aa0acad5ffd75d929e3afec1554",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b3d4ab2d7df9426f7f1d3671d7e2108f2ca6e970",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 236,
        "referenceCount": 4,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 10
      }
    },
    {
      "cve_id": "CVE-2026-64560",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.796Z",
      "date_published": "2026-07-29T16:47:17.602Z",
      "date_updated": "2026-07-30T11:10:46.176Z",
      "publisher": "Linux",
      "title": "posix-cpu-timers: Prevent UAF caused by non-leader exec() race",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 18,
        "versionRangeCount": 17,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02172
      },
      "nvd": {
        "published": "2026-07-29T17:16:53.637",
        "lastModified": "2026-07-30T12:19:03.630",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64560",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A non-leader exec can replace and release the task leader while timer deletion still acts on the old task, leaving an armed timer node after its object is freed.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/67aa823e3e8c229c6d374df79c804f6721cb83b6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/d8bcb28abad857f1415da7656f19b2ada90af04f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/cc35ddbc497311e0b6b9a6a6a4f4d1217d6ab1aa",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/12a891c773aeb5823d63dbd0cb2ab931d6c21c9b",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e74443f5db0037c556ef436fa64b88bf4ea08f83",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/6a7ecc25abe6f0fecc6e62a05096987200edbd02",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/ad1cafa1bdaa71da85d71cac053838bbe97852b6",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/920f893f735e92ba3a1cd9256899a186b161928d",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 3998,
        "referenceCount": 8,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 18
      }
    },
    {
      "cve_id": "CVE-2026-64600",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-19T15:36:31.799Z",
      "date_published": "2026-07-23T05:46:56.149Z",
      "date_updated": "2026-08-03T20:31:20.507Z",
      "publisher": "Linux",
      "title": "xfs: resample the data fork mapping after cycling ILOCK",
      "affected": {
        "vendors": [
          "Linux"
        ],
        "products": [
          {
            "vendor": "Linux",
            "product": "Linux"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 16,
        "versionRangeCount": 15,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00507,
        "percentile": 0.40507
      },
      "nvd": {
        "published": "2026-07-23T06:16:50.493",
        "lastModified": "2026-08-03T21:16:41.060",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64600",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "XFS cycles its inode lock and then continues with a stale data-fork mapping even though concurrent work may have changed it.",
        "basis": [
          "CNA"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/dc11be133efca5fe3a2fb02b016dee825cc12f18",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/b8c9aa832b52680ee40d6cab0efb081f9a69df05",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/50f0012da1040f69a4e788cd9aed587c9a04983f",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/e705d81a7193dd19e69b8e2bad4696d78a4ea075",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/206c09b04dc5469c7ff14d8aceff2d47c88078d9",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/44f891bc088958399eec27f7604928694aa35581",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://git.kernel.org/stable/c/2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7",
          "host": "git.kernel.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt",
          "host": "cdn2.qualys.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/22/14",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/22/18",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/22/19",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/31/3",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/03/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/03/8",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 872,
        "referenceCount": 14,
        "cweCount": 0,
        "cnaCweCount": 0,
        "adpCweCount": 0,
        "nvdCweCount": 0,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 16
      }
    },
    {
      "cve_id": "CVE-2026-64606",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T08:21:55.786Z",
      "date_published": "2026-07-21T10:43:51.436Z",
      "date_updated": "2026-07-21T18:28:15.293Z",
      "publisher": "apache",
      "title": "Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Fory"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00634,
        "percentile": 0.46911
      },
      "nvd": {
        "published": "2026-07-21T11:16:27.973",
        "lastModified": "2026-07-27T13:47:41.580",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64606",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Java lambda deserialization auto-admits a SerializedLambda capture interface and thereby bypasses the class-registration boundary for untrusted serialized data.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/py6fbvm9nk1gxdd85rbzbozwzfh0jrsc",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/21/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 305,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64607",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T08:23:45.493Z",
      "date_published": "2026-07-31T10:12:18.035Z",
      "date_updated": "2026-07-31T16:25:02.593Z",
      "publisher": "apache",
      "title": "Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache HttpComponents Client"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-772",
          "name": "Missing Release of Resource after Effective Lifetime",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14889
      },
      "nvd": {
        "published": "2026-07-31T11:17:11.710",
        "lastModified": "2026-08-04T12:31:51.160",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64607",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Apache HttpComponents Client error path does not release a resource after use, so repeated requests exhaust the available pool.",
        "basis": [
          "CNA",
          "CWE-772"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 387,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64608",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T08:33:04.879Z",
      "date_published": "2026-07-21T09:34:12.817Z",
      "date_updated": "2026-07-21T18:28:16.365Z",
      "publisher": "apache",
      "title": "Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Fory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00372,
        "percentile": 0.29938
      },
      "nvd": {
        "published": "2026-07-21T10:16:24.923",
        "lastModified": "2026-07-21T19:17:13.040",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64608",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Fory's compatible deserializer skips fields without validating declared types and reaches type-confused out-of-bounds access.",
        "basis": [
          "CNA",
          "CWE-502",
          "CWE-787",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/wl05slf57zzoq1s4pg4tk6nx6mjyjr4b",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/21/5",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64609",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T08:46:26.713Z",
      "date_published": "2026-07-21T09:34:57.010Z",
      "date_updated": "2026-07-21T18:28:17.440Z",
      "publisher": "apache",
      "title": "Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Fory"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00476,
        "percentile": 0.38643
      },
      "nvd": {
        "published": "2026-07-21T10:16:25.057",
        "lastModified": "2026-07-27T13:47:44.540",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64609",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Apache Fory, an attacker-controlled index or length permits a read beyond the valid memory region.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/rdv22ks3b0cxh0r52w3ghxgkxqso3f1b",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/21/6",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 539,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64611",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:15:34.675Z",
      "date_published": "2026-07-23T10:46:49.957Z",
      "date_updated": "2026-07-23T20:15:01.235Z",
      "publisher": "redhat",
      "title": "Libcupsfilters: cups-filters: libcupsfilters: cpu exhaustion via infinite loop in cfieee1284normalizemakemodel()",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26486
      },
      "nvd": {
        "published": "2026-07-23T11:16:40.680",
        "lastModified": "2026-07-23T21:17:05.330",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64611",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Red Hat Enterprise Linux 10 can enter a loop whose exit condition is never reached for the crafted input or state, consuming CPU indefinitely.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-64611",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502799",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 358,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-64612",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:15:34.675Z",
      "date_published": "2026-07-20T17:33:01.878Z",
      "date_updated": "2026-07-21T17:31:26.245Z",
      "publisher": "redhat",
      "title": "Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malformed png",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unaffected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0035,
        "percentile": 0.27628
      },
      "nvd": {
        "published": "2026-07-20T18:16:56.273",
        "lastModified": "2026-07-21T18:31:51.680",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64612",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The PNG reader omits libpng's error-recovery handler, so a malformed print image aborts the active filter process.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-64612",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502801",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-64613",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:30:10.287Z",
      "date_published": "2026-07-21T19:05:49.579Z",
      "date_updated": "2026-07-23T12:25:36.375Z",
      "publisher": "CPANSec",
      "title": "Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::Buffer::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04448
      },
      "nvd": {
        "published": "2026-07-21T20:17:03.967",
        "lastModified": "2026-07-23T13:16:29.300",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64613",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Data::Buffer::Shared creates shared backing files world-readable and follows a pre-existing symlink when attaching to a named segment.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-Buffer-Shared-0.05/diff/EGOR/Data-Buffer-Shared-0.04#buf_generic.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-Buffer-Shared-0.05/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 699,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64614",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:30:10.287Z",
      "date_published": "2026-07-21T19:06:15.526Z",
      "date_updated": "2026-07-23T12:40:40.462Z",
      "publisher": "CPANSec",
      "title": "Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::Deque::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02074
      },
      "nvd": {
        "published": "2026-07-21T20:17:04.070",
        "lastModified": "2026-07-23T13:16:29.927",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64614",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The shared-memory path creates a world-writable file without exclusive creation or symlink refusal, so a preplanted path can redirect the object selected.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-Deque-Shared-0.06/diff/EGOR/Data-Deque-Shared-0.05#deque.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-Deque-Shared-0.06/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 742,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64615",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:30:10.287Z",
      "date_published": "2026-07-21T19:06:32.520Z",
      "date_updated": "2026-07-23T12:32:41.256Z",
      "publisher": "CPANSec",
      "title": "Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::Graph::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.02074
      },
      "nvd": {
        "published": "2026-07-21T20:17:04.187",
        "lastModified": "2026-07-23T13:16:30.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64615",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Data Graph Shared creates its mmap file with world-readable permissions and without exclusive or no-follow protections in a shared namespace.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-Graph-Shared-0.04/diff/EGOR/Data-Graph-Shared-0.03#graph.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-Graph-Shared-0.04/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 742,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64616",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:30:10.287Z",
      "date_published": "2026-07-21T19:06:50.604Z",
      "date_updated": "2026-07-30T16:53:56.277Z",
      "publisher": "CPANSec",
      "title": "Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::NDArray::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01926
      },
      "nvd": {
        "published": "2026-07-21T20:17:04.290",
        "lastModified": "2026-07-30T19:18:35.227",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64616",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Data::NDArray::Shared creates a predictable world-readable backing path without O_EXCL or O_NOFOLLOW, allowing precreation or symlink substitution of the selected file.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-NDArray-Shared-0.02/diff/EGOR/Data-NDArray-Shared-0.01#ndarray.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-NDArray-Shared-0.02/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 746,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64617",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:30:10.287Z",
      "date_published": "2026-07-21T19:07:06.617Z",
      "date_updated": "2026-07-23T12:46:23.202Z",
      "publisher": "CPANSec",
      "title": "Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::PubSub::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01928
      },
      "nvd": {
        "published": "2026-07-21T20:17:04.403",
        "lastModified": "2026-07-23T13:16:31.193",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64617",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-PubSub-Shared-0.07/diff/EGOR/Data-PubSub-Shared-0.06#pubsub.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-PubSub-Shared-0.07/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 744,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64619",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:58:54.523Z",
      "date_published": "2026-07-20T18:50:12.359Z",
      "date_updated": "2026-07-28T01:05:55.926Z",
      "publisher": "VulnCheck",
      "title": "FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers",
      "affected": {
        "vendors": [
          "vastsa"
        ],
        "products": [
          {
            "vendor": "vastsa",
            "product": "FileCodeBox"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-348",
          "name": "Use of Less Trusted Source",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10299
      },
      "nvd": {
        "published": "2026-07-20T19:17:30.373",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64619",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and X-Forwarded-For headers without verification of trusted reverse proxy origin.",
        "basis": [
          "CNA",
          "CWE-348"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vastsa/FileCodeBox/issues/479",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/vastsa/FileCodeBox/releases/tag/V2.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/vastsa/FileCodeBox/commit/1b6d8e7277d3cfa34dc7a85803731d927b2147da",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/filecodebox-anti-bruteforce-rate-limit-bypass-via-spoofed-headers",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64620",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:58:54.524Z",
      "date_published": "2026-07-20T12:04:53.105Z",
      "date_updated": "2026-07-21T11:08:25.119Z",
      "publisher": "VulnCheck",
      "title": "FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common",
      "affected": {
        "vendors": [
          "FreeRDP"
        ],
        "products": [
          {
            "vendor": "FreeRDP",
            "product": "FreeRDP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.7000000000000011,
      "epss": {
        "score": 0.00851,
        "percentile": 0.54654
      },
      "nvd": {
        "published": "2026-07-20T12:19:46.760",
        "lastModified": "2026-07-28T15:38:19.810",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64620",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "crypto_rsa_common() writes the full RSA result into a caller buffer before comparing the result length with that buffer's capacity.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjqx-v446-x7fc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/commit/1f7a716d39b5605bb8a83b0c3c97a6ce386609ef",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/freerdp-before-heap-buffer-overflow-via-crypto-rsa-common",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 797,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64621",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:58:54.524Z",
      "date_published": "2026-07-20T12:04:53.788Z",
      "date_updated": "2026-07-23T18:52:59.996Z",
      "publisher": "VulnCheck",
      "title": "FreeRDP before 3.28.0 Double-Free via selectedmonitors",
      "affected": {
        "vendors": [
          "FreeRDP"
        ],
        "products": [
          {
            "vendor": "FreeRDP",
            "product": "FreeRDP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 2.000000000000001,
      "epss": {
        "score": 0.00304,
        "percentile": 0.22709
      },
      "nvd": {
        "published": "2026-07-20T12:19:46.910",
        "lastModified": "2026-07-28T15:34:52.930",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64621",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The selectedmonitors error path frees a non-owning settings pointer without clearing the owner, so teardown frees the same allocation a second time.",
        "basis": [
          "CNA",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f27x-frr8-j9hc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Mitigation",
            "Vendor Advisory",
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/FreeRDP/FreeRDP/commit/1f7a716d39b5605bb8a83b0c3c97a6ce386609ef",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/freerdp-before-double-free-via-selectedmonitors",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 707,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64622",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:58:54.524Z",
      "date_published": "2026-07-20T12:04:54.541Z",
      "date_updated": "2026-07-21T11:08:26.395Z",
      "publisher": "VulnCheck",
      "title": "Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox",
      "affected": {
        "vendors": [
          "Jovancoding"
        ],
        "products": [
          {
            "vendor": "Jovancoding",
            "product": "Network-AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 1.8000000000000007,
      "epss": {
        "score": 0.00408,
        "percentile": 0.33584
      },
      "nvd": {
        "published": "2026-07-20T12:19:47.057",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64622",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-m4jg-6w3q-gm86",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/network-ai-through-missing-authorization-via-approvalinbox",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 711,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64623",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:58:54.524Z",
      "date_published": "2026-07-20T12:04:55.262Z",
      "date_updated": "2026-07-20T13:49:02.553Z",
      "publisher": "VulnCheck",
      "title": "Network-AI before 5.13.4 Cryptographic Signature Verification Bypass",
      "affected": {
        "vendors": [
          "Jovancoding"
        ],
        "products": [
          {
            "vendor": "Jovancoding",
            "product": "Network-AI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.002,
        "percentile": 0.09987
      },
      "nvd": {
        "published": "2026-07-20T12:19:47.200",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64623",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Network-AI accepts signed material without completing the cryptographic signature verification required for authenticity.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-3jf7-33vc-hgf4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/network-ai-before-cryptographic-signature-verification-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 393,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64624",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:58:54.524Z",
      "date_published": "2026-07-20T21:50:53.693Z",
      "date_updated": "2026-07-24T20:17:15.015Z",
      "publisher": "VulnCheck",
      "title": "FreeRDP RDP File Parser Remote Code Execution via CLI Options",
      "affected": {
        "vendors": [
          "FreeRDP"
        ],
        "products": [
          {
            "vendor": "FreeRDP",
            "product": "FreeRDP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-88",
          "name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07835
      },
      "nvd": {
        "published": "2026-07-20T22:17:18.600",
        "lastModified": "2026-07-29T15:21:10.700",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64624",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The RDP file parser treats slash-prefixed file lines as raw command-line options and exposes privileged CLI behaviors to untrusted documents.",
        "basis": [
          "CNA",
          "CWE-88"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rq8f-9xjh-pr3m",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/freerdp-rdp-file-parser-remote-code-execution-via-cli-options",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 367,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64625",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:58:54.524Z",
      "date_published": "2026-07-20T21:50:54.340Z",
      "date_updated": "2026-07-23T14:35:06.225Z",
      "publisher": "VulnCheck",
      "title": "AVideo before 29.0 OS Command Injection via execAsync",
      "affected": {
        "vendors": [
          "WWBN"
        ],
        "products": [
          {
            "vendor": "WWBN",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00351,
        "percentile": 0.27831
      },
      "nvd": {
        "published": "2026-07-20T22:17:18.740",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64625",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Rewrapping a command through sh -c preserves command-substitution syntax despite escapeshellarg.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-rc5x-vh5v-473f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/avideo-before-os-command-injection-via-execasync",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 313,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64626",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:58:54.524Z",
      "date_published": "2026-07-20T21:50:54.991Z",
      "date_updated": "2026-07-22T14:17:17.491Z",
      "publisher": "VulnCheck",
      "title": "AVideo Encoder downloadURL SSRF via unpinned retry fallback",
      "affected": {
        "vendors": [
          "WWBN"
        ],
        "products": [
          {
            "vendor": "WWBN",
            "product": "AVideo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00186,
        "percentile": 0.08437
      },
      "nvd": {
        "published": "2026-07-20T22:17:18.873",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64626",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The encoder's retry path follows redirects without preserving the DNS-pinned destination validation.",
        "basis": [
          "CNA record",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-fr98-mjq9-7jmj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/WWBN/AVideo/commit/0dbadbcaaa1b415c7db078a72dc4b26d9fac0485",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/avideo-encoder-downloadurl-ssrf-via-unpinned-retry-fallback",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64627",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:58:54.524Z",
      "date_published": "2026-07-21T11:39:55.087Z",
      "date_updated": "2026-07-28T01:05:56.657Z",
      "publisher": "VulnCheck",
      "title": "Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion",
      "affected": {
        "vendors": [
          "parse-community"
        ],
        "products": [
          {
            "vendor": "parse-community",
            "product": "parse-server"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.2011
      },
      "nvd": {
        "published": "2026-07-21T12:19:00.450",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64627",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "parse-server returns internal error details to an observer who should not receive them.",
        "basis": [
          "CNA",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/parse-community/parse-server/security/advisories/GHSA-9g8f-h8f3-hjcm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/parse-server-schema-disclosure-via-graphql-variable-coercion",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 879,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-64628",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T11:58:54.524Z",
      "date_published": "2026-07-21T11:39:55.742Z",
      "date_updated": "2026-07-23T18:22:05.939Z",
      "publisher": "VulnCheck",
      "title": "Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04687
      },
      "nvd": {
        "published": "2026-07-21T12:19:00.633",
        "lastModified": "2026-07-23T19:17:03.740",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64628",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Grav's shortcode scan looks only for literal angle brackets, allowing executable shortcode attributes to reach rendered HTML.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-q5fw-vpqc-fgph",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-stored-cross-site-scripting-via-shortcode-attribute-handlers",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 445,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64635",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T15:00:00.696Z",
      "date_published": "2026-07-30T06:02:49.984Z",
      "date_updated": "2026-07-30T12:44:36.592Z",
      "publisher": "hackerone",
      "title": "Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link.",
      "affected": {
        "vendors": [
          "Veeam"
        ],
        "products": [
          {
            "vendor": "Veeam",
            "product": "Service Provider Console"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-640",
          "name": "Weak Password Recovery Mechanism for Forgotten Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:support@hackerone.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0019,
        "percentile": 0.08922
      },
      "nvd": {
        "published": "2026-07-30T06:25:59.930",
        "lastModified": "2026-07-30T13:16:54.110",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64635",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The forgot-password flow accepts an attacker-controlled returnUrl domain and places the reset code in a link sent to the victim.",
        "basis": [
          "CNA",
          "CWE-640"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.veeam.com/kb4853",
          "host": "www.veeam.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 374,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64641",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:11:30.895Z",
      "date_published": "2026-07-27T17:40:01.137Z",
      "date_updated": "2026-07-27T18:54:59.134Z",
      "publisher": "GitHub_M",
      "title": "Next.js: Denial of Service in App Router using Server Actions",
      "affected": {
        "vendors": [
          "vercel"
        ],
        "products": [
          {
            "vendor": "vercel",
            "product": "next.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-834",
          "name": "Excessive Iteration",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00599,
        "percentile": 0.45313
      },
      "nvd": {
        "published": "2026-07-27T18:16:58.850",
        "lastModified": "2026-07-29T14:36:32.130",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64641",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The record ties crafted Next.js App Router Server Action requests to excessive CPU in one process but does not disclose the repeated operation or missing work bound.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-834"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vercel/next.js/security/advisories/GHSA-m99w-x7hq-7vfj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/pull/96013",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/019628571641dec57aaf349ba0c360e3964e6f12",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v15.5.21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v16.2.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 382,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64642",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:11:30.895Z",
      "date_published": "2026-07-27T17:45:40.761Z",
      "date_updated": "2026-07-28T15:20:33.639Z",
      "publisher": "GitHub_M",
      "title": "Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale",
      "affected": {
        "vendors": [
          "vercel"
        ],
        "products": [
          {
            "vendor": "vercel",
            "product": "next.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00948,
        "percentile": 0.57745
      },
      "nvd": {
        "published": "2026-07-27T18:16:59.010",
        "lastModified": "2026-07-29T14:36:59.730",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64642",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Crafted requests can bypass middleware authentication in a specific App Router, Turbopack, and single-locale configuration, but the causal routing mismatch is not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vercel/next.js/security/advisories/GHSA-6gpp-xcg3-4w24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/pull/96014",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/6bf4df14508ad6c0cd46af50c6051ee42f2d9151",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v16.2.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64643",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:11:30.895Z",
      "date_published": "2026-07-27T17:48:17.575Z",
      "date_updated": "2026-07-27T18:21:55.549Z",
      "publisher": "GitHub_M",
      "title": "Next.js: Unauthenticated Disclosure of Internal Server Function endpoints",
      "affected": {
        "vendors": [
          "vercel"
        ],
        "products": [
          {
            "vendor": "vercel",
            "product": "next.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00516,
        "percentile": 0.41102
      },
      "nvd": {
        "published": "2026-07-27T18:16:59.160",
        "lastModified": "2026-07-29T14:37:25.703",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64643",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Next.js publishes Server Action identifiers in public client artifacts even when the corresponding pages require authentication, enabling unauthenticated action enumeration.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vercel/next.js/security/advisories/GHSA-955p-x3mx-jcvp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/1b0c3ae912a3ad925c60065cc8d55b070fa8bcd3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/ff12a6124e1504f17b62de948b8a553fdecaef7b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v15.5.21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v16.2.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 744,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64644",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:11:30.895Z",
      "date_published": "2026-07-27T17:54:52.530Z",
      "date_updated": "2026-07-27T18:35:41.443Z",
      "publisher": "GitHub_M",
      "title": "Next.js: Denial of Service in the Image Optimization API using SVGs",
      "affected": {
        "vendors": [
          "vercel"
        ],
        "products": [
          {
            "vendor": "vercel",
            "product": "next.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00675,
        "percentile": 0.48687
      },
      "nvd": {
        "published": "2026-07-27T18:16:59.307",
        "lastModified": "2026-07-29T14:39:23.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64644",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A crafted remote SVG triggers computation with no effective complexity bound and can exhaust CPU.",
        "basis": [
          "CNA",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vercel/next.js/security/advisories/GHSA-q8wf-6r8g-63ch",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/pull/96006",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/93cb90891402fa4c47798d03cb9e05c13233766c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v15.5.21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v16.2.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 637,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64645",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:11:30.895Z",
      "date_published": "2026-07-27T17:37:07.695Z",
      "date_updated": "2026-07-28T14:02:21.877Z",
      "publisher": "GitHub_M",
      "title": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname",
      "affected": {
        "vendors": [
          "vercel"
        ],
        "products": [
          {
            "vendor": "vercel",
            "product": "next.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 2.200000000000001,
      "epss": {
        "score": 0.00782,
        "percentile": 0.52447
      },
      "nvd": {
        "published": "2026-07-27T18:16:59.453",
        "lastModified": "2026-07-29T14:39:12.173",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64645",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The next.js request path accepts an attacker-controlled destination or redirect without constraining the resolved server-side network target.",
        "basis": [
          "CNA",
          "CWE-601",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vercel/next.js/security/advisories/GHSA-p9j2-gv94-2wf4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/35f501357e9b0fe7c950b0d6aa8fcf5343f707e9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/d3033266c6dff23f7be71e19341fe3a8c6e2c599",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v15.5.21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v16.2.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 620,
        "referenceCount": 5,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64646",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:11:30.895Z",
      "date_published": "2026-07-27T18:54:59.466Z",
      "date_updated": "2026-07-27T20:22:18.086Z",
      "publisher": "GitHub_M",
      "title": "Next.js: Unbounded Server Action payload in Edge runtime",
      "affected": {
        "vendors": [
          "vercel"
        ],
        "products": [
          {
            "vendor": "vercel",
            "product": "next.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00531,
        "percentile": 0.41875
      },
      "nvd": {
        "published": "2026-07-27T19:17:21.477",
        "lastModified": "2026-07-29T14:39:00.200",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64646",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Next.js App Router permits Edge-runtime Server Action requests to consume memory without an effective request bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vercel/next.js/security/advisories/GHSA-4c39-4ccg-62r3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/57c31f724d746e86a9e8b92aa8be538a922446a4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/9a4651e754f70b12e397694ffc41f44c3ba8cc17",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v15.5.21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v16.2.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 368,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64647",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:11:30.895Z",
      "date_published": "2026-07-27T19:11:28.477Z",
      "date_updated": "2026-07-27T19:27:13.932Z",
      "publisher": "GitHub_M",
      "title": "Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies",
      "affected": {
        "vendors": [
          "vercel"
        ],
        "products": [
          {
            "vendor": "vercel",
            "product": "next.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-116",
          "name": "Improper Encoding or Escaping of Output",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00339,
        "percentile": 0.2644
      },
      "nvd": {
        "published": "2026-07-27T19:17:21.627",
        "lastModified": "2026-07-29T14:38:45.417",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64647",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Next.js derives the server-fetch cache key from request bodies through a lossy charset conversion, allowing different non-UTF-8 bodies to share one cached response.",
        "basis": [
          "CNA",
          "CWE-116"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vercel/next.js/security/advisories/GHSA-4633-3j49-mh5q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/pull/96008",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/025bf4a5f7b47fb7758c4ebf1c931a61c451c082",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v15.5.21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v16.2.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 661,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64648",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:11:30.895Z",
      "date_published": "2026-07-27T19:20:42.623Z",
      "date_updated": "2026-07-28T14:14:16.051Z",
      "publisher": "GitHub_M",
      "title": "Next.js: Response Body Cache Confusion for Requests Containing Bodies",
      "affected": {
        "vendors": [
          "vercel"
        ],
        "products": [
          {
            "vendor": "vercel",
            "product": "next.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-524",
          "name": "Use of Cache Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00336,
        "percentile": 0.26185
      },
      "nvd": {
        "published": "2026-07-27T20:16:40.563",
        "lastModified": "2026-07-29T14:38:20.310",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64648",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Next.js keys a server-side response-body cache without including a differing request body, allowing one request to receive another response.",
        "basis": [
          "CNA",
          "CWE-524"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vercel/next.js/security/advisories/GHSA-68g3-v927-f742",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/062f66700b52a5d6bba2c0605d55577ab7ad262c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/73b94872bc343d09494b50394d8c08eb9fc8e56a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v15.5.21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v16.2.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 694,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64649",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:11:30.895Z",
      "date_published": "2026-07-27T19:27:58.865Z",
      "date_updated": "2026-07-28T14:12:06.654Z",
      "publisher": "GitHub_M",
      "title": "Next.js: Server-Side Request Forgery in Server Actions on Custom Servers",
      "affected": {
        "vendors": [
          "vercel"
        ],
        "products": [
          {
            "vendor": "vercel",
            "product": "next.js"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 1.8000000000000007,
      "epss": {
        "score": 0.00448,
        "percentile": 0.36817
      },
      "nvd": {
        "published": "2026-07-27T20:16:40.703",
        "lastModified": "2026-07-29T14:38:03.600",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64649",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Next.js derives a Server Action forwarding destination from attacker-controlled Host-associated headers instead of a pinned trusted host.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vercel/next.js/security/advisories/GHSA-89xv-2m56-2m9x",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/b51206321854193208c0805ba42acc49287f942b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/commit/e3e5666ccead3a15162793d697af5e48b7cc0498",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v15.5.21",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/vercel/next.js/releases/tag/v16.2.11",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Product",
            "Release Notes",
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 888,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64650",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:11:30.895Z",
      "date_published": "2026-07-20T20:27:41.349Z",
      "date_updated": "2026-07-20T21:45:44.027Z",
      "publisher": "GitHub_M",
      "title": "AI SDK Codex Harness Tool Relay Authorization Bypass",
      "affected": {
        "vendors": [
          "vercel"
        ],
        "products": [
          {
            "vendor": "vercel",
            "product": "@ai-sdk/harness-codex"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01638
      },
      "nvd": {
        "published": "2026-07-20T21:16:50.520",
        "lastModified": "2026-07-23T18:14:09.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64650",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The harness falls back from a verified executable identity to a caller-controlled process path, allowing an untrusted binary to satisfy the authorization rule.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vercel/ai/security/advisories/GHSA-qw9h-448j-6rph",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vercel/ai/pull/17105",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1260,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64651",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:11:30.896Z",
      "date_published": "2026-07-20T20:26:07.497Z",
      "date_updated": "2026-07-21T12:49:47.977Z",
      "publisher": "GitHub_M",
      "title": "AI SDK OpenCode Harness Tool Relay Authorization Bypass",
      "affected": {
        "vendors": [
          "vercel"
        ],
        "products": [
          {
            "vendor": "vercel",
            "product": "@ai-sdk/harness-opencode"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00113,
        "percentile": 0.01638
      },
      "nvd": {
        "published": "2026-07-20T21:16:50.677",
        "lastModified": "2026-07-23T18:14:09.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64651",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The relay treats any process whose command line merely contains an allowed helper path as authorized to call host tools, without a matching model-approved event.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vercel/ai/security/advisories/GHSA-g48p-5rr5-8rgq",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/vercel/ai/pull/17105",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1224,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64685",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T17:12:12.892Z",
      "date_published": "2026-07-29T23:47:21.587Z",
      "date_updated": "2026-07-30T15:17:50.345Z",
      "publisher": "GitHub_M",
      "title": "ImageMagick: Heap Buffer Over-Read in BGR decoder due to mising end-of-file check",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09733
      },
      "nvd": {
        "published": "2026-07-30T00:16:25.490",
        "lastModified": "2026-08-03T15:20:03.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64685",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ImageMagick reads beyond a valid memory object because an input length or pointer is not validated against the available buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7rgw-xg25-prjm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 301,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64691",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:01.158Z",
      "date_published": "2026-07-27T20:14:52.091Z",
      "date_updated": "2026-07-28T14:54:23.822Z",
      "publisher": "apple",
      "title": "A buffer overflow was addressed with improved size validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26894
      },
      "nvd": {
        "published": "2026-07-27T21:17:08.797",
        "lastModified": "2026-07-28T20:01:00.563",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64691",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An app-controlled operation copies more data than a fixed destination buffer can hold.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 162,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64692",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:01.158Z",
      "date_published": "2026-07-27T20:12:13.066Z",
      "date_updated": "2026-07-28T16:31:00.192Z",
      "publisher": "apple",
      "title": "An out-of-bounds read was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.02996
      },
      "nvd": {
        "published": "2026-07-27T21:17:08.893",
        "lastModified": "2026-07-29T19:56:01.607",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64692",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An Apple system component reads beyond the valid bounds of a memory buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 265,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64693",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:01.158Z",
      "date_published": "2026-07-27T20:12:28.075Z",
      "date_updated": "2026-07-28T14:28:45.679Z",
      "publisher": "apple",
      "title": "A type confusion issue was addressed with improved checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02707
      },
      "nvd": {
        "published": "2026-07-27T21:17:08.993",
        "lastModified": "2026-07-28T20:00:42.897",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64693",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Image processing accesses a resource through an incompatible runtime type, allowing crafted input to drive invalid object interpretation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 280,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64694",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:01.158Z",
      "date_published": "2026-07-27T20:12:51.061Z",
      "date_updated": "2026-07-28T14:41:45.630Z",
      "publisher": "apple",
      "title": "An integer overflow was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34298
      },
      "nvd": {
        "published": "2026-07-27T21:17:09.097",
        "lastModified": "2026-07-28T17:58:33.637",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64694",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted Disk Images input can overflow an integer used during processing and terminate the affected component.",
        "basis": [
          "CNA",
          "CWE-190",
          "Apple security notes 128067/128071/128072"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.apple.com/en-us/128067, https://support.apple.com/en-us/128071, and https://support.apple.com/en-us/128072. Apple identifies the Disk Images component and an integer overflow fixed by input validation, but publishes no calculation, input field, or patch diff."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:01.158Z",
      "date_published": "2026-07-27T20:13:30.416Z",
      "date_updated": "2026-07-28T15:59:00.087Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00513,
        "percentile": 0.40895
      },
      "nvd": {
        "published": "2026-07-27T21:17:09.193",
        "lastModified": "2026-07-28T17:58:26.340",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64695",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple reports remotely triggerable APFS memory corruption but does not disclose the allocation, bounds, or lifetime error.",
        "basis": [
          "CNA",
          "CWE-119",
          "Apple macOS Tahoe 26.6 security content"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.apple.com/en-us/128067; Apple identifies APFS, remote kernel-memory corruption, and improved memory handling but does not publish the allocation, bounds, or lifetime error."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64696",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:01.158Z",
      "date_published": "2026-07-27T20:13:41.994Z",
      "date_updated": "2026-07-28T15:58:50.760Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00513,
        "percentile": 0.40895
      },
      "nvd": {
        "published": "2026-07-27T21:17:09.290",
        "lastModified": "2026-07-28T17:58:18.120",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64696",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The SMB component mishandles memory reachable by a remote user, but Apple does not disclose the allocation, bound, pointer, or lifetime transition involved.",
        "basis": [
          "CNA",
          "CWE-119",
          "Apple Security Releases"
        ],
        "deepDive": true,
        "notes": "https://support.apple.com/en-us/128067 ; https://support.apple.com/en-us/128071 - Apple's Tahoe and Sequoia notices identify SMB and remote kernel-memory corruption but disclose no allocation, bound, pointer, or lifetime transition."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:01.158Z",
      "date_published": "2026-07-27T20:14:13.203Z",
      "date_updated": "2026-07-28T13:33:35.932Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34298
      },
      "nvd": {
        "published": "2026-07-27T21:17:09.393",
        "lastModified": "2026-07-28T17:58:07.833",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64697",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The HFS implementation mishandles kernel memory while processing app-reachable filesystem input, allowing an app to terminate the system or corrupt kernel memory.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-119",
          "Apple security release"
        ],
        "deepDive": true,
        "notes": "Inspected Apple security release https://support.apple.com/en-us/128067; the HFS entry confirms improved memory handling and the fixed macOS releases, but it does not identify the buffer, index, object lifetime, triggering filesystem structure, or source patch."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:01.158Z",
      "date_published": "2026-07-27T20:13:04.254Z",
      "date_updated": "2026-07-28T16:11:25.974Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00417,
        "percentile": 0.34299
      },
      "nvd": {
        "published": "2026-07-27T21:17:09.490",
        "lastModified": "2026-07-30T14:35:12.950",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64698",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The macOS cd9660 component mishandles memory and can expose kernel bytes or terminate the system, while Apple does not publish the memory operation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-119",
          "Vendor advisory"
        ],
        "deepDive": true,
        "notes": "Inspected Apple's macOS Tahoe 26.6 security page at https://support.apple.com/en-us/128067; it identifies cd9660 and improved memory handling but does not publish the failing memory operation or patch."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64699",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:01.158Z",
      "date_published": "2026-07-27T20:13:15.783Z",
      "date_updated": "2026-07-28T14:26:22.858Z",
      "publisher": "apple",
      "title": "A memory initialization issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-457",
          "name": "Use of Uninitialized Variable",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03674
      },
      "nvd": {
        "published": "2026-07-27T21:17:09.587",
        "lastModified": "2026-07-28T20:00:14.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64699",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "macOS reads memory before initializing it, allowing stale process data or an invalid value to influence execution.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-457"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64700",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:01.158Z",
      "date_published": "2026-07-27T20:14:27.460Z",
      "date_updated": "2026-07-28T15:45:12.712Z",
      "publisher": "apple",
      "title": "A use after free issue was addressed with improved memory management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0046,
        "percentile": 0.37592
      },
      "nvd": {
        "published": "2026-07-27T21:17:09.680",
        "lastModified": "2026-07-28T19:59:29.443",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64700",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected Apple component reuses an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 278,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64702",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:24.049Z",
      "date_published": "2026-07-27T20:12:17.318Z",
      "date_updated": "2026-07-28T18:40:13.829Z",
      "publisher": "apple",
      "title": "An access issue was addressed with additional sandbox restrictions.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.313
      },
      "nvd": {
        "published": "2026-07-27T21:17:09.780",
        "lastModified": "2026-07-30T14:35:03.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64702",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The macOS Audio sandbox grants an app access outside its sandbox, but Apple's advisory does not disclose the missing sandbox rule or object binding.",
        "basis": [
          "CNA",
          "CWE-284",
          "Apple advisory"
        ],
        "deepDive": true,
        "notes": "Read https://support.apple.com/en-us/128067; Apple identifies the Audio component and additional sandbox restrictions but does not disclose the vulnerable rule, call path, or patch."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 199,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64703",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:24.049Z",
      "date_published": "2026-07-27T20:12:23.223Z",
      "date_updated": "2026-07-28T14:12:37.724Z",
      "publisher": "apple",
      "title": "A use after free issue was addressed with improved memory management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00405,
        "percentile": 0.33292
      },
      "nvd": {
        "published": "2026-07-27T21:17:09.877",
        "lastModified": "2026-07-28T17:58:02.000",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64703",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An Apple application path uses an object after its storage has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64704",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:24.049Z",
      "date_published": "2026-07-27T20:12:56.133Z",
      "date_updated": "2026-07-28T14:35:07.515Z",
      "publisher": "apple",
      "title": "A type confusion issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00443,
        "percentile": 0.364
      },
      "nvd": {
        "published": "2026-07-27T21:17:09.977",
        "lastModified": "2026-07-28T17:57:55.483",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64704",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A type confusion issue was addressed with improved memory handling.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 210,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64707",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:24.049Z",
      "date_published": "2026-07-27T20:14:16.526Z",
      "date_updated": "2026-07-28T15:58:16.874Z",
      "publisher": "apple",
      "title": "A permissions issue was addressed with improved validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02115
      },
      "nvd": {
        "published": "2026-07-27T21:17:10.073",
        "lastModified": "2026-07-28T19:57:32.517",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64707",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple reports a permissions-validation failure that lets an app delete files outside its authority but does not disclose the checked object or rule.",
        "basis": [
          "CNA",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64708",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:24.049Z",
      "date_published": "2026-07-27T20:13:09.235Z",
      "date_updated": "2026-07-28T14:31:07.991Z",
      "publisher": "apple",
      "title": "A file quarantine bypass was addressed with additional checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00128,
        "percentile": 0.02868
      },
      "nvd": {
        "published": "2026-07-27T21:17:10.170",
        "lastModified": "2026-07-28T17:57:48.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64708",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Apple reports a Gatekeeper quarantine bypass fixed with additional checks but does not identify the trusted metadata or omitted validation.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": "The public record does not expose enough implementation detail to classify the enabling cause."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64709",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:24.049Z",
      "date_published": "2026-07-27T20:13:11.581Z",
      "date_updated": "2026-07-28T14:29:18.017Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02988
      },
      "nvd": {
        "published": "2026-07-27T21:17:10.267",
        "lastModified": "2026-07-28T19:56:28.267",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64709",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected interface returns, embeds or leaves protected information visible to an observer who is not entitled to receive it.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64710",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:24.049Z",
      "date_published": "2026-07-27T20:13:37.914Z",
      "date_updated": "2026-07-28T14:09:14.924Z",
      "publisher": "apple",
      "title": "A privacy issue was addressed by removing sensitive data.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.0304
      },
      "nvd": {
        "published": "2026-07-27T21:17:10.370",
        "lastModified": "2026-07-28T18:06:00.097",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64710",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A macOS application can leak sensitive user information, but Apple's public record does not identify the data or output path.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 196,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64711",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:35.083Z",
      "date_published": "2026-07-27T20:14:15.730Z",
      "date_updated": "2026-07-28T15:56:53.311Z",
      "publisher": "apple",
      "title": "This issue was addressed with additional entitlement checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.02362
      },
      "nvd": {
        "published": "2026-07-27T21:17:10.467",
        "lastModified": "2026-07-28T19:55:57.883",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64711",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An application can cross an Apple entitlement boundary and expose user data, but Apple does not disclose the entitlement or protected data path.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-64713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:35.084Z",
      "date_published": "2026-07-27T20:13:27.168Z",
      "date_updated": "2026-07-28T19:11:08.015Z",
      "publisher": "apple",
      "title": "This issue was addressed with improved checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "Safari"
          },
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-203",
          "name": "Observable Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00328,
        "percentile": 0.25272
      },
      "nvd": {
        "published": "2026-07-27T21:17:10.560",
        "lastModified": "2026-07-30T14:34:30.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64713",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A website can distinguish whether a link is in the user's visited history through an observable browser response.",
        "basis": [
          "CNA",
          "CWE-203"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128073",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64716",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:35.084Z",
      "date_published": "2026-07-27T20:14:29.040Z",
      "date_updated": "2026-07-28T15:07:20.794Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03256
      },
      "nvd": {
        "published": "2026-07-27T21:17:10.657",
        "lastModified": "2026-07-28T19:55:35.817",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64716",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A crafted image corrupts memory, but the public record does not identify the bounds, type, ownership, or lifetime failure.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64718",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:35.084Z",
      "date_published": "2026-07-27T20:12:07.210Z",
      "date_updated": "2026-07-28T18:40:21.814Z",
      "publisher": "apple",
      "title": "A use-after-free issue was addressed with improved memory management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "Safari"
          },
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01323
      },
      "nvd": {
        "published": "2026-07-27T21:17:10.753",
        "lastModified": "2026-07-29T19:55:37.530",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64718",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Malicious web content causes Safari to dereference an object after its lifetime has ended.",
        "basis": [
          "CNA record",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128073",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64719",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:35.084Z",
      "date_published": "2026-07-27T20:12:33.758Z",
      "date_updated": "2026-07-28T14:42:03.068Z",
      "publisher": "apple",
      "title": "An out-of-bounds access issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "Safari"
          },
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20719
      },
      "nvd": {
        "published": "2026-07-27T21:17:10.853",
        "lastModified": "2026-07-28T19:54:39.373",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64719",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Safari reads beyond an allocated buffer because the input length or boundary is not enforced.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128073",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 277,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64720",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:35.084Z",
      "date_published": "2026-07-27T20:14:25.797Z",
      "date_updated": "2026-07-28T15:49:11.712Z",
      "publisher": "apple",
      "title": "A race condition was addressed with improved state handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-362",
          "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00333,
        "percentile": 0.25823
      },
      "nvd": {
        "published": "2026-07-27T21:17:10.950",
        "lastModified": "2026-07-28T19:53:51.337",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64720",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A race in the Apple kernel permits an application-triggered invalid state, but the competing operations and invariant are not public.",
        "basis": [
          "CNA",
          "CWE-362",
          "Apple security advisories 128066 and 128067"
        ],
        "deepDive": true,
        "notes": "Primary-source deep dive: https://support.apple.com/en-us/128066 and https://support.apple.com/en-us/128067 ; Apple identifies the Kernel component and a race addressed by state handling, but not the competing operations or invariant."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-64721",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:47.192Z",
      "date_published": "2026-07-27T20:14:56.204Z",
      "date_updated": "2026-07-28T14:20:45.002Z",
      "publisher": "apple",
      "title": "This issue was addressed through improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-664",
          "name": "Improper Control of a Resource Through its Lifetime",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.0294
      },
      "nvd": {
        "published": "2026-07-27T21:17:11.053",
        "lastModified": "2026-07-28T19:53:13.287",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64721",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple reports that stale or incorrect resource state lets an app access sensitive user data, but does not disclose the resource or lifecycle transition.",
        "basis": [
          "CNA",
          "CWE-664"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64722",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:47.192Z",
      "date_published": "2026-07-27T20:11:57.933Z",
      "date_updated": "2026-07-28T16:32:06.031Z",
      "publisher": "apple",
      "title": "A buffer overflow issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04424
      },
      "nvd": {
        "published": "2026-07-27T21:17:11.153",
        "lastModified": "2026-07-30T14:34:12.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64722",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A copy into a fixed memory region proceeds without a sufficient input-size check, allowing the destination bounds to be exceeded.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 223,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:47.192Z",
      "date_published": "2026-07-27T20:12:41.997Z",
      "date_updated": "2026-07-28T15:03:27.881Z",
      "publisher": "apple",
      "title": "A logic issue was addressed with improved checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02494
      },
      "nvd": {
        "published": "2026-07-27T21:17:11.253",
        "lastModified": "2026-07-28T18:05:49.877",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64723",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A macOS application can read protected user data because of an undisclosed access-control logic error.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 183,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64724",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:47.192Z",
      "date_published": "2026-07-27T20:12:58.667Z",
      "date_updated": "2026-07-28T14:33:16.085Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02707
      },
      "nvd": {
        "published": "2026-07-27T21:17:11.350",
        "lastModified": "2026-07-28T19:52:06.387",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64724",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Apple network-reachable path mishandles memory and can cause denial of service, while the public record does not disclose the allocation, bounds, or lifetime operation.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 279,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64725",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:47.192Z",
      "date_published": "2026-07-27T20:13:23.660Z",
      "date_updated": "2026-07-28T19:08:25.360Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03016
      },
      "nvd": {
        "published": "2026-07-27T21:17:11.447",
        "lastModified": "2026-07-29T19:54:56.290",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64725",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A crafted input permits a write beyond the end of an allocated memory region.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 272,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64726",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:47.192Z",
      "date_published": "2026-07-27T20:13:56.070Z",
      "date_updated": "2026-07-28T13:51:33.889Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00431,
        "percentile": 0.35439
      },
      "nvd": {
        "published": "2026-07-27T21:17:11.543",
        "lastModified": "2026-07-28T19:51:24.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64726",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The iOS and iPadOS path processes attacker-controlled data without a sufficient memory-boundary check.",
        "basis": [
          "CNA",
          "CWE-119",
          "Apple security notices"
        ],
        "deepDive": true,
        "notes": "Read Apple security notices https://support.apple.com/en-us/128066 and https://support.apple.com/en-us/128067; they identify the Wi-Fi component and physical-proximity memory corruption but do not disclose the memory operation or failing bounds/lifetime rule."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64727",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:47.192Z",
      "date_published": "2026-07-27T20:13:58.610Z",
      "date_updated": "2026-07-28T18:50:21.318Z",
      "publisher": "apple",
      "title": "A type confusion issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-843",
          "name": "Access of Resource Using Incompatible Type ('Type Confusion')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00358,
        "percentile": 0.28464
      },
      "nvd": {
        "published": "2026-07-27T21:17:11.640",
        "lastModified": "2026-07-29T19:54:12.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64727",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apple code accesses a resource through an incompatible runtime type and corrupts memory.",
        "basis": [
          "CNA",
          "CWE-843"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64728",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:47.192Z",
      "date_published": "2026-07-27T20:12:44.436Z",
      "date_updated": "2026-07-28T15:10:57.316Z",
      "publisher": "apple",
      "title": "A permissions issue was addressed with improved validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "Safari"
          },
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.17845
      },
      "nvd": {
        "published": "2026-07-27T21:17:11.737",
        "lastModified": "2026-07-28T18:55:20.553",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64728",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A WebKit permission check permits crafted web content to act outside an iframe sandbox, while Apple does not identify the sandbox flag or validation branch.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128073",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 249,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:47.193Z",
      "date_published": "2026-07-27T20:13:36.159Z",
      "date_updated": "2026-07-28T14:10:17.009Z",
      "publisher": "apple",
      "title": "A use after free issue was addressed with improved memory management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00419,
        "percentile": 0.34478
      },
      "nvd": {
        "published": "2026-07-27T21:17:11.837",
        "lastModified": "2026-07-28T18:54:39.683",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64729",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Apple component accesses an object after it has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:47.193Z",
      "date_published": "2026-07-27T20:13:50.343Z",
      "date_updated": "2026-07-28T14:04:05.762Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved UI.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "Safari"
          },
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 6,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0034,
        "percentile": 0.26653
      },
      "nvd": {
        "published": "2026-07-27T21:17:11.930",
        "lastModified": "2026-07-28T18:48:50.317",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64730",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128073",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 235,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 6,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:54.848Z",
      "date_published": "2026-07-27T20:14:03.683Z",
      "date_updated": "2026-07-28T13:46:13.871Z",
      "publisher": "apple",
      "title": "A path handling issue was addressed with improved validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00467,
        "percentile": 0.38034
      },
      "nvd": {
        "published": "2026-07-27T21:17:12.030",
        "lastModified": "2026-07-28T18:48:20.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64731",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled path or object-name data is resolved without proving that the final target remains inside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 181,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64732",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:54.848Z",
      "date_published": "2026-07-27T20:13:03.490Z",
      "date_updated": "2026-07-28T16:08:12.326Z",
      "publisher": "apple",
      "title": "This issue was addressed through improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0015,
        "percentile": 0.04702
      },
      "nvd": {
        "published": "2026-07-27T21:17:12.130",
        "lastModified": "2026-07-28T18:47:51.380",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64732",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "iPhone Mirroring permits physical access to protected data through an undisclosed state-bound authorization failure.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 208,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64733",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:54.848Z",
      "date_published": "2026-07-27T20:13:15.015Z",
      "date_updated": "2026-07-28T14:27:21.282Z",
      "publisher": "apple",
      "title": "This issue was addressed with improved data protection.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00462,
        "percentile": 0.37741
      },
      "nvd": {
        "published": "2026-07-27T21:17:12.223",
        "lastModified": "2026-07-28T18:47:32.557",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64733",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Accounts Framework exposes a user-fingerprinting signal to an application, but Apple does not identify the data source or observable oracle.",
        "basis": [
          "CNA",
          "CWE-200",
          "Apple security advisory"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.apple.com/en-us/128066 and the linked Apple platform advisories; Apple identifies Accounts Framework, fingerprinting impact, and improved data protection but does not disclose the exposed signal or the causal data-flow check. That official impact statement is materially narrower than the embedded shard's 9.8 score."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64734",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:54.848Z",
      "date_published": "2026-07-27T20:12:04.763Z",
      "date_updated": "2026-07-28T16:31:23.757Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00135,
        "percentile": 0.03361
      },
      "nvd": {
        "published": "2026-07-27T21:17:12.327",
        "lastModified": "2026-07-29T19:53:42.203",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64734",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "low",
        "mechanism": "Processing a crafted contact can disclose sensitive data, but the public record does not identify the missing bounds, access, or output check.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 250,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64735",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:54.848Z",
      "date_published": "2026-07-27T20:12:36.312Z",
      "date_updated": "2026-07-28T14:48:32.125Z",
      "publisher": "apple",
      "title": "An inconsistent user interface issue was addressed with improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-451",
          "name": "User Interface (UI) Misrepresentation of Critical Information",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00392,
        "percentile": 0.31919
      },
      "nvd": {
        "published": "2026-07-27T21:17:12.463",
        "lastModified": "2026-07-28T18:47:06.750",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64735",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Apple's UI state can become inconsistent with the active network-filter state, allowing a remote peer to bypass the displayed or expected filter policy.",
        "basis": [
          "CNA",
          "CWE-451"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64737",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:54.848Z",
      "date_published": "2026-07-27T20:15:00.930Z",
      "date_updated": "2026-07-28T14:16:38.168Z",
      "publisher": "apple",
      "title": "An authorization issue was addressed with improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00115,
        "percentile": 0.01838
      },
      "nvd": {
        "published": "2026-07-27T21:17:12.573",
        "lastModified": "2026-07-28T18:00:10.010",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64737",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A malicious application can escape its macOS sandbox because an authorization state is managed incorrectly, but the state transition and check are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64738",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:54.848Z",
      "date_published": "2026-07-27T20:12:13.838Z",
      "date_updated": "2026-07-28T16:30:54.198Z",
      "publisher": "apple",
      "title": "A permissions issue was addressed with additional restrictions.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.313
      },
      "nvd": {
        "published": "2026-07-27T21:17:12.677",
        "lastModified": "2026-07-30T14:33:37.440",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64738",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Maps component grants a sandboxed app permissions beyond its sandbox boundary, but the exact permission check is not public.",
        "basis": [
          "CNA",
          "CWE-284",
          "Apple security notes 128067/128071/128072"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.apple.com/en-us/128067, https://support.apple.com/en-us/128071, and https://support.apple.com/en-us/128072. Apple identifies the Maps component and additional permission restrictions, but publishes no permission, object, call path, or patch diff."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64739",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:54.848Z",
      "date_published": "2026-07-27T20:12:28.898Z",
      "date_updated": "2026-07-28T14:34:02.115Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00364,
        "percentile": 0.29155
      },
      "nvd": {
        "published": "2026-07-27T21:17:12.777",
        "lastModified": "2026-07-28T18:46:34.450",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64739",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An Apple component writes beyond an allocated buffer because the vulnerable path lacks sufficient bounds checking.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 284,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64740",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:09:54.848Z",
      "date_published": "2026-07-27T20:14:53.836Z",
      "date_updated": "2026-07-28T16:12:52.208Z",
      "publisher": "apple",
      "title": "A parsing issue in the handling of directory paths was addressed with improved path validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06174
      },
      "nvd": {
        "published": "2026-07-27T21:17:12.877",
        "lastModified": "2026-07-28T18:45:58.623",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64740",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file operation in iOS and iPadOS uses an attacker-controlled path without confining the resolved object to the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 273,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64741",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:18.985Z",
      "date_published": "2026-07-27T20:14:29.891Z",
      "date_updated": "2026-07-28T15:29:01.656Z",
      "publisher": "apple",
      "title": "A permissions issue was addressed with additional restrictions.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02988
      },
      "nvd": {
        "published": "2026-07-27T21:17:12.980",
        "lastModified": "2026-07-28T18:45:38.337",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64741",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected Apple permission check allows an app to read a persistent device identifier that should be restricted to a narrower authority scope.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 211,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-64742",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:18.985Z",
      "date_published": "2026-07-27T20:12:26.427Z",
      "date_updated": "2026-07-28T14:22:18.182Z",
      "publisher": "apple",
      "title": "This issue was addressed by using HTTPS when sending information over the network.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-319",
          "name": "Cleartext Transmission of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.0954
      },
      "nvd": {
        "published": "2026-07-27T21:17:13.080",
        "lastModified": "2026-07-28T19:50:44.020",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64742",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected Apple path sends sensitive information over plaintext HTTP instead of an authenticated and encrypted HTTPS channel.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-319"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-64743",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:18.985Z",
      "date_published": "2026-07-27T20:12:14.717Z",
      "date_updated": "2026-07-28T16:30:48.141Z",
      "publisher": "apple",
      "title": "An authorization issue was addressed with improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20757
      },
      "nvd": {
        "published": "2026-07-27T21:17:13.187",
        "lastModified": "2026-07-29T19:52:00.697",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64743",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in iOS and iPadOS, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "ADP",
          "NVD",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 225,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64744",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:18.985Z",
      "date_published": "2026-07-27T20:13:28.734Z",
      "date_updated": "2026-07-28T16:02:33.051Z",
      "publisher": "apple",
      "title": "An information leakage was addressed with additional validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00131,
        "percentile": 0.03084
      },
      "nvd": {
        "published": "2026-07-27T21:17:13.283",
        "lastModified": "2026-07-28T18:00:02.887",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64744",
        "family": "UNDETERMINED",
        "precision": "UNDETERMINED",
        "confidence": "low",
        "mechanism": "Apple states that additional validation prevents disclosure of kernel memory but does not identify the invalid input, boundary, or lifetime error.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 194,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64745",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:18.985Z",
      "date_published": "2026-07-27T20:12:54.533Z",
      "date_updated": "2026-07-28T14:37:05.070Z",
      "publisher": "apple",
      "title": "This issue was addressed with additional restrictions on the lock screen.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 2.4,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 2.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00136,
        "percentile": 0.03462
      },
      "nvd": {
        "published": "2026-07-27T21:17:13.377",
        "lastModified": "2026-07-28T18:44:46.630",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64745",
        "family": "HARDWARE_PHYSICAL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The lock-screen interface permits a person with physical device access to reach contacts and photos despite the locked state.",
        "basis": [
          "CNA",
          "CWE-287"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64746",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:18.985Z",
      "date_published": "2026-07-27T20:14:14.856Z",
      "date_updated": "2026-07-28T15:55:13.450Z",
      "publisher": "apple",
      "title": "An authorization issue was addressed with improved validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00398,
        "percentile": 0.32605
      },
      "nvd": {
        "published": "2026-07-27T21:17:13.487",
        "lastModified": "2026-07-28T18:43:51.407",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64746",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An Apple application can add contacts without user authorization, while the public advisory does not disclose the permission or consent validation that fails.",
        "basis": [
          "CNA",
          "CWE-862",
          "Apple security content 128066"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.apple.com/en-us/128066; Apple identifies the Contacts component and says improved validation fixed unauthorized contact creation, but the permission check and call path are not public."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-64747",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:18.985Z",
      "date_published": "2026-07-27T20:13:38.693Z",
      "date_updated": "2026-07-29T03:55:30.754Z",
      "publisher": "apple",
      "title": "A buffer overflow was addressed with improved size validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00142,
        "percentile": 0.0398
      },
      "nvd": {
        "published": "2026-07-27T21:17:13.613",
        "lastModified": "2026-07-29T05:17:03.413",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64747",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "A buffer overflow was addressed with improved size validation.",
        "basis": [
          "CNA",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 281,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64749",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:18.985Z",
      "date_published": "2026-07-27T20:13:06.794Z",
      "date_updated": "2026-07-28T17:55:31.873Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02566
      },
      "nvd": {
        "published": "2026-07-27T21:17:13.727",
        "lastModified": "2026-07-29T19:51:14.167",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64749",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple reports memory corruption or termination from deficient memory handling but does not disclose the bound, object, or lifetime error.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 242,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-64751",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:30.632Z",
      "date_published": "2026-07-27T20:13:37.035Z",
      "date_updated": "2026-07-28T14:12:15.384Z",
      "publisher": "apple",
      "title": "A use after free issue was addressed with improved memory management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00329,
        "percentile": 0.25397
      },
      "nvd": {
        "published": "2026-07-27T21:17:13.823",
        "lastModified": "2026-07-28T18:42:37.177",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64751",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path continues using an object after its lifetime has ended.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 258,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:30.632Z",
      "date_published": "2026-07-27T20:12:20.455Z",
      "date_updated": "2026-07-28T18:39:53.073Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00118,
        "percentile": 0.01996
      },
      "nvd": {
        "published": "2026-07-27T21:17:13.920",
        "lastModified": "2026-07-29T19:50:43.773",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64754",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "iOS and iPadOS can write beyond the valid bounds of an allocation while processing attacker-influenced data.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 294,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:30.632Z",
      "date_published": "2026-07-27T20:12:19.342Z",
      "date_updated": "2026-07-28T17:56:01.516Z",
      "publisher": "apple",
      "title": "An authorization issue was addressed with improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02275
      },
      "nvd": {
        "published": "2026-07-27T21:17:14.020",
        "lastModified": "2026-07-29T19:50:20.133",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64755",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An iOS application can cross an undisclosed state-dependent authorization boundary and access sensitive user data.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 167,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64757",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:30.633Z",
      "date_published": "2026-07-27T20:14:26.672Z",
      "date_updated": "2026-07-28T15:48:04.441Z",
      "publisher": "apple",
      "title": "A memory corruption issue was addressed with improved state management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "Safari"
          },
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11864
      },
      "nvd": {
        "published": "2026-07-27T21:17:14.120",
        "lastModified": "2026-07-28T18:42:01.177",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64757",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple reports web-triggered memory corruption and a Safari crash but does not disclose the invalid bound, pointer, or lifetime transition.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128073",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64758",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:30.633Z",
      "date_published": "2026-07-27T20:12:32.193Z",
      "date_updated": "2026-07-28T14:40:02.145Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved bounds checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00124,
        "percentile": 0.02566
      },
      "nvd": {
        "published": "2026-07-27T21:17:14.220",
        "lastModified": "2026-07-28T18:40:51.680",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64758",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Processing a crafted file crosses a memory bound and terminates the app, but the public record does not identify the affected buffer or operation.",
        "basis": [
          "CNA",
          "CWE-119"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 237,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64762",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:43.924Z",
      "date_published": "2026-07-27T20:12:37.967Z",
      "date_updated": "2026-07-28T14:52:08.582Z",
      "publisher": "apple",
      "title": "An out-of-bounds read was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25226
      },
      "nvd": {
        "published": "2026-07-27T21:17:14.317",
        "lastModified": "2026-07-28T17:59:53.360",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64762",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Crafted input can cause a read beyond the bounds of a valid buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 209,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:43.924Z",
      "date_published": "2026-07-27T20:12:01.967Z",
      "date_updated": "2026-07-29T03:55:26.731Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed by removing the vulnerable code.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02916
      },
      "nvd": {
        "published": "2026-07-27T21:17:14.427",
        "lastModified": "2026-07-29T19:50:10.873",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64763",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted file drives a write beyond the bounds of a memory object.",
        "basis": [
          "CNA record",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 331,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:43.924Z",
      "date_published": "2026-07-27T20:13:17.354Z",
      "date_updated": "2026-07-29T03:55:29.922Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02917
      },
      "nvd": {
        "published": "2026-07-27T21:17:14.523",
        "lastModified": "2026-07-29T05:17:04.350",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64764",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "iOS and iPadOS lets attacker-controlled input reach an out-of-bounds write.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:43.924Z",
      "date_published": "2026-07-27T20:13:01.023Z",
      "date_updated": "2026-07-29T03:55:29.152Z",
      "publisher": "apple",
      "title": "An integer overflow was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02917
      },
      "nvd": {
        "published": "2026-07-27T21:17:14.623",
        "lastModified": "2026-07-29T19:49:33.180",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64765",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SceneKit performs overflowing integer arithmetic while sizing or indexing data from a crafted file.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64766",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:43.924Z",
      "date_published": "2026-07-27T20:14:02.814Z",
      "date_updated": "2026-07-29T03:55:33.822Z",
      "publisher": "apple",
      "title": "An integer overflow was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02917
      },
      "nvd": {
        "published": "2026-07-27T21:17:14.727",
        "lastModified": "2026-07-29T05:17:05.237",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64766",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In iOS and iPadOS, unchecked integer arithmetic wraps before its result controls a memory size, offset, or copy.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 321,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64767",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:43.924Z",
      "date_published": "2026-07-27T20:13:51.882Z",
      "date_updated": "2026-07-28T14:02:09.025Z",
      "publisher": "apple",
      "title": "A buffer overflow was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-120",
          "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00445,
        "percentile": 0.36568
      },
      "nvd": {
        "published": "2026-07-27T21:17:14.823",
        "lastModified": "2026-07-28T17:59:45.307",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64767",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A copy into a fixed memory region proceeds without a sufficient input-size check, allowing the destination bounds to be exceeded.",
        "basis": [
          "CNA record",
          "ADP",
          "NVD",
          "CWE-120"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 241,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64768",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:43.924Z",
      "date_published": "2026-07-27T20:13:32.837Z",
      "date_updated": "2026-07-28T14:13:21.871Z",
      "publisher": "apple",
      "title": "An out-of-bounds read issue was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00317,
        "percentile": 0.24123
      },
      "nvd": {
        "published": "2026-07-27T21:17:14.920",
        "lastModified": "2026-07-28T18:40:04.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64768",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An Apple media or input-processing path reads beyond a valid buffer boundary while handling network-controlled data.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 268,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64769",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:43.924Z",
      "date_published": "2026-07-27T20:12:46.870Z",
      "date_updated": "2026-07-28T15:14:55.234Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35584
      },
      "nvd": {
        "published": "2026-07-27T21:17:15.020",
        "lastModified": "2026-07-28T18:39:55.780",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64769",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The iOS and iPadOS path writes attacker-influenced data beyond the capacity of its destination buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:43.924Z",
      "date_published": "2026-07-27T20:14:00.344Z",
      "date_updated": "2026-07-28T13:49:40.111Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35584
      },
      "nvd": {
        "published": "2026-07-27T21:17:15.117",
        "lastModified": "2026-07-28T18:39:45.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64770",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A crafted input permits an out-of-bounds heap write in the affected Apple component.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:53.025Z",
      "date_published": "2026-07-27T20:13:54.442Z",
      "date_updated": "2026-07-28T14:00:16.924Z",
      "publisher": "apple",
      "title": "A buffer overflow was addressed with improved bounds checking.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-119",
          "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0045,
        "percentile": 0.36927
      },
      "nvd": {
        "published": "2026-07-27T21:17:15.213",
        "lastModified": "2026-07-28T18:39:12.377",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64771",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The iOS and iPadOS path processes attacker-controlled data without a sufficient memory-boundary check.",
        "basis": [
          "CNA",
          "CWE-119",
          "Apple security notices"
        ],
        "deepDive": true,
        "notes": "Read Apple security notices https://support.apple.com/en-us/128066 and https://support.apple.com/en-us/128067; they identify a Model I/O buffer overflow fixed by bounds checking but publish no input field or source path."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 271,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64772",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:53.025Z",
      "date_published": "2026-07-27T20:13:20.490Z",
      "date_updated": "2026-07-28T17:55:19.538Z",
      "publisher": "apple",
      "title": "An out-of-bounds write issue was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00407,
        "percentile": 0.33518
      },
      "nvd": {
        "published": "2026-07-27T21:17:15.317",
        "lastModified": "2026-07-29T19:49:04.220",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64772",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Apple code writes beyond an allocated buffer while processing remote input.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 283,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64774",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:53.025Z",
      "date_published": "2026-07-27T20:12:40.417Z",
      "date_updated": "2026-07-28T14:58:31.732Z",
      "publisher": "apple",
      "title": "An integer overflow was addressed with improved input validation.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          }
        ],
        "affectedBlockCount": 4,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35584
      },
      "nvd": {
        "published": "2026-07-27T21:17:15.420",
        "lastModified": "2026-07-28T18:37:14.757",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64774",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple identifies an integer overflow while Model I/O processes remote content, but its security notice does not identify the arithmetic operation, field, or allocation affected.",
        "basis": [
          "CNA",
          "CWE-190",
          "Apple iOS and iPadOS 26.6 security content"
        ],
        "deepDive": true,
        "notes": "Inspected https://support.apple.com/en-us/128066 and the linked parallel 26.6 platform notices. Apple places the issue in Model I/O and says an integer overflow was fixed through improved input validation, but publishes no parsed field, arithmetic operation, or allocation. Apple supplies no CVSS score on that page; the shard maximum 9.8 is attributed to an ADP source."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 295,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 4,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-64775",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:53.025Z",
      "date_published": "2026-07-27T20:11:58.713Z",
      "date_updated": "2026-07-28T16:31:59.267Z",
      "publisher": "apple",
      "title": "A memory initialization issue was addressed with improved memory handling.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "tvOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 7,
        "versionRangeCount": 7,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-665",
          "name": "Improper Initialization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00367,
        "percentile": 0.29418
      },
      "nvd": {
        "published": "2026-07-27T21:17:15.517",
        "lastModified": "2026-07-29T19:48:46.097",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64775",
        "family": "MEMORY_LIFETIME",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apple identifies uninitialized Kernel memory that can terminate the system but does not disclose the object or initialization path.",
        "basis": [
          "CNA",
          "CWE-665",
          "Apple July 2026 security notes"
        ],
        "deepDive": true,
        "notes": "Apple security notes https://support.apple.com/en-us/128066 through https://support.apple.com/en-us/128071 were inspected; they identify the Kernel and a memory-initialization issue but do not disclose the object or initialization path."
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128069",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 283,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64776",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:10:53.025Z",
      "date_published": "2026-07-27T20:14:57.773Z",
      "date_updated": "2026-07-28T15:52:25.405Z",
      "publisher": "apple",
      "title": "The issue was addressed with improved bounds checks.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "macOS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00122,
        "percentile": 0.023
      },
      "nvd": {
        "published": "2026-07-27T21:17:15.620",
        "lastModified": "2026-07-28T17:59:37.613",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64776",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The public record identifies a memory-safety failure but does not disclose the exact buffer, lifetime transition, or invalid access.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128071",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128072",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 182,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-64783",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:11:03.397Z",
      "date_published": "2026-07-27T20:14:39.670Z",
      "date_updated": "2026-07-28T15:00:38.071Z",
      "publisher": "apple",
      "title": "A use-after-free issue was addressed with improved memory management.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "Safari"
          },
          {
            "vendor": "Apple",
            "product": "iOS and iPadOS"
          },
          {
            "vendor": "Apple",
            "product": "macOS"
          },
          {
            "vendor": "Apple",
            "product": "visionOS"
          },
          {
            "vendor": "Apple",
            "product": "watchOS"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 5,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-416",
          "name": "Use After Free",
          "abstraction": "Variant",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11068
      },
      "nvd": {
        "published": "2026-07-27T21:17:15.720",
        "lastModified": "2026-07-28T18:35:42.410",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64783",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Safari can dereference an object after the allocation backing that object has been freed.",
        "basis": [
          "CNA",
          "CWE-416"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128067",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128068",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128070",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://support.apple.com/en-us/128073",
          "host": "support.apple.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 261,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64785",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:11:03.398Z",
      "date_published": "2026-07-23T18:50:40.468Z",
      "date_updated": "2026-07-24T20:06:58.518Z",
      "publisher": "apple",
      "title": "SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.",
      "affected": {
        "vendors": [
          "Apple"
        ],
        "products": [
          {
            "vendor": "Apple",
            "product": "swift-nio-http2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00181,
        "percentile": 0.07847
      },
      "nvd": {
        "published": "2026-07-23T20:17:21.440",
        "lastModified": "2026-07-24T21:16:45.877",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64785",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HTTP/2-to-HTTP/1 codec forwards control characters that HTTP/1 treats as message delimiters, creating a cross-protocol request-boundary ambiguity.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apple/swift-nio-http2/security/advisories/GHSA-q3g2-m552-3r9c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 309,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64791",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:16:31.592Z",
      "date_published": "2026-07-22T20:40:15.641Z",
      "date_updated": "2026-07-28T05:30:57.646Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Regular Labs Extension Manager extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02779
      },
      "nvd": {
        "published": "2026-07-22T21:18:10.230",
        "lastModified": "2026-07-27T18:16:59.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64791",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Extension-management routes inconsistently enforce both CSRF tokens and installation permissions before install, update, or uninstall actions.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 351,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64792",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:16:31.592Z",
      "date_published": "2026-07-22T20:40:58.877Z",
      "date_updated": "2026-07-28T05:31:54.131Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Articles Anywhere extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Conditional Content extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Modules Anywhere extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "ReReplacer extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Sourcerer extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Tabs & Accordions Pro extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Snippets Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 7,
        "versionEntryCount": 7,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-524",
          "name": "Use of Cache Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16319
      },
      "nvd": {
        "published": "2026-07-22T21:18:10.337",
        "lastModified": "2026-07-27T18:16:59.767",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64792",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Smart Search renders content under the indexing administrator's identity and stores restricted output in a public search index.",
        "basis": [
          "CNA",
          "CWE-524"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 7,
        "affectedVersionEntryCount": 7
      }
    },
    {
      "cve_id": "CVE-2026-64793",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:16:31.592Z",
      "date_published": "2026-07-22T20:45:25.099Z",
      "date_updated": "2026-07-27T13:34:13.847Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Articles Anywhere extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Modules Anywhere extension for Joomla"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15966
      },
      "nvd": {
        "published": "2026-07-22T21:18:10.447",
        "lastModified": "2026-07-27T14:16:59.510",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64793",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Content tags can set ignore flags or property overrides that render articles or modules outside the visitor's publication and access permissions.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 334,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64794",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:16:31.592Z",
      "date_published": "2026-07-22T20:45:24.135Z",
      "date_updated": "2026-07-27T13:34:11.997Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Articles Anywhere extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Users Anywhere extension for Joomla"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00244,
        "percentile": 0.15649
      },
      "nvd": {
        "published": "2026-07-22T21:18:10.553",
        "lastModified": "2026-07-27T15:17:08.047",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64794",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "User tags, filters, and conditions read authentication data, raw parameters, or restricted contacts without enforcing the field-level access policy.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 319,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64795",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:16:31.592Z",
      "date_published": "2026-07-22T20:41:19.007Z",
      "date_updated": "2026-07-27T13:29:26.815Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Modals extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Tooltips extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Articles Anywhere Pro extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Users Anywhere Pro extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Modules Anywhere Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 5,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03231
      },
      "nvd": {
        "published": "2026-07-22T21:18:10.660",
        "lastModified": "2026-07-27T14:16:59.660",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64795",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Modals extension for Joomla page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 5
      }
    },
    {
      "cve_id": "CVE-2026-64796",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:16:31.593Z",
      "date_published": "2026-07-22T20:42:49.934Z",
      "date_updated": "2026-07-28T05:34:08.793Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Sourcerer extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00285,
        "percentile": 0.20712
      },
      "nvd": {
        "published": "2026-07-22T21:18:10.763",
        "lastModified": "2026-07-27T19:17:21.777",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64796",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Sourcerer executes article code without consistently requiring the configured creator, modifier, and language permissions.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 473,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64797",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:16:31.593Z",
      "date_published": "2026-07-22T20:44:08.843Z",
      "date_updated": "2026-07-29T05:39:44.152Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "IP Login extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10277
      },
      "nvd": {
        "published": "2026-07-22T21:18:10.870",
        "lastModified": "2026-07-28T16:20:04.800",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64797",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The login extension trusts forwarded client-IP headers without requiring that they came from a configured proxy.",
        "basis": [
          "CNA",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64798",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:16:31.593Z",
      "date_published": "2026-07-22T20:41:53.448Z",
      "date_updated": "2026-07-28T05:33:04.140Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "IP Login extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-338",
          "name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15773
      },
      "nvd": {
        "published": "2026-07-22T21:18:10.970",
        "lastModified": "2026-07-27T18:16:59.920",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64798",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "IP Login extension for Joomla derives an authentication token or login key from a non-cryptographic generator with too little entropy to resist guessing.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-338"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 200,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64799",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:16:31.593Z",
      "date_published": "2026-07-23T09:11:12.311Z",
      "date_updated": "2026-07-28T05:32:38.511Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Articles Anywhere Pro extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Users Anywhere Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23677
      },
      "nvd": {
        "published": "2026-07-23T10:16:51.867",
        "lastModified": "2026-07-27T17:16:39.207",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64799",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The extensions fetch content-controlled image URLs without rejecting reserved networks or unsafe redirects and save responses without image validation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64800",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:19:58.408Z",
      "date_published": "2026-07-23T11:36:55.317Z",
      "date_updated": "2026-07-23T13:18:50.674Z",
      "publisher": "JetBrains",
      "title": "In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "GoLand"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.5,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 2.2,
      "epss": {
        "score": 0.00491,
        "percentile": 0.39537
      },
      "nvd": {
        "published": "2026-07-23T12:18:35.527",
        "lastModified": "2026-07-28T17:05:43.917",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64800",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GoLand writes credentials or other protected configuration values into a log readable beyond their intended audience.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64802",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:27.708Z",
      "date_published": "2026-07-23T11:36:55.809Z",
      "date_updated": "2026-07-24T03:56:13.219Z",
      "publisher": "JetBrains",
      "title": "In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "GoLand"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04084
      },
      "nvd": {
        "published": "2026-07-23T12:18:35.647",
        "lastModified": "2026-07-28T17:05:55.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64802",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Go Modules integration executes project-controlled behavior before the user grants trust to the project.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64803",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:28.058Z",
      "date_published": "2026-07-23T11:36:56.235Z",
      "date_updated": "2026-07-24T03:56:14.836Z",
      "publisher": "JetBrains",
      "title": "In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "GoLand"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04085
      },
      "nvd": {
        "published": "2026-07-23T12:18:35.753",
        "lastModified": "2026-07-28T17:06:09.587",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64803",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GoLand executes the configured Go SDK from an untrusted project before the user grants project trust.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 127,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64804",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:28.432Z",
      "date_published": "2026-07-23T11:36:56.637Z",
      "date_updated": "2026-07-24T03:56:21.618Z",
      "publisher": "JetBrains",
      "title": "In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "WebStorm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03794
      },
      "nvd": {
        "published": "2026-07-23T12:18:35.880",
        "lastModified": "2026-07-28T17:06:18.890",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64804",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WebStorm executes project-local linter tooling before the user grants trust to the project.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 136,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64805",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:28.785Z",
      "date_published": "2026-07-23T11:36:56.997Z",
      "date_updated": "2026-07-24T03:56:22.762Z",
      "publisher": "JetBrains",
      "title": "In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "WebStorm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03794
      },
      "nvd": {
        "published": "2026-07-23T12:18:35.993",
        "lastModified": "2026-07-28T17:06:27.437",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64805",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "WebStorm executes project-local package-manager tooling before the user has granted trust to the project.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 145,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64806",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:29.006Z",
      "date_published": "2026-07-23T11:36:57.338Z",
      "date_updated": "2026-07-24T03:56:23.574Z",
      "publisher": "JetBrains",
      "title": "In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "WebStorm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03793
      },
      "nvd": {
        "published": "2026-07-23T12:18:36.103",
        "lastModified": "2026-07-28T17:06:35.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64806",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64807",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:29.287Z",
      "date_published": "2026-07-23T11:36:57.740Z",
      "date_updated": "2026-07-24T03:56:24.355Z",
      "publisher": "JetBrains",
      "title": "In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "WebStorm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.0266
      },
      "nvd": {
        "published": "2026-07-23T12:18:36.217",
        "lastModified": "2026-07-28T17:08:25.513",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64807",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "WebStorm loads a project-supplied linter configuration as executable tooling configuration without an adequate trust boundary.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64808",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:29.509Z",
      "date_published": "2026-07-23T11:36:58.090Z",
      "date_updated": "2026-07-24T03:56:25.146Z",
      "publisher": "JetBrains",
      "title": "In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "PhpStorm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03793
      },
      "nvd": {
        "published": "2026-07-23T12:18:36.323",
        "lastModified": "2026-07-28T17:08:41.140",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64808",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PhpStorm project tooling can execute project-controlled code before the user has granted that project trust.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 123,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64809",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:29.741Z",
      "date_published": "2026-07-23T11:36:58.428Z",
      "date_updated": "2026-07-24T03:56:25.961Z",
      "publisher": "JetBrains",
      "title": "In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "PhpStorm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03793
      },
      "nvd": {
        "published": "2026-07-23T12:18:36.437",
        "lastModified": "2026-07-28T17:09:00.080",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64809",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "PhpStorm invokes a configured interpreter before the project-trust decision has authorized project-controlled execution.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 134,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64810",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:29.976Z",
      "date_published": "2026-07-23T11:36:58.739Z",
      "date_updated": "2026-07-23T13:20:00.344Z",
      "publisher": "JetBrains",
      "title": "In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "IntelliJ IDEA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1.7999999999999998,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04582
      },
      "nvd": {
        "published": "2026-07-23T12:18:36.553",
        "lastModified": "2026-07-28T17:09:16.960",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64810",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches IntelliJ IDEA page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64811",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:30.270Z",
      "date_published": "2026-07-23T11:36:59.173Z",
      "date_updated": "2026-07-24T03:56:15.755Z",
      "publisher": "JetBrains",
      "title": "In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "IntelliJ IDEA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02661
      },
      "nvd": {
        "published": "2026-07-23T12:18:36.663",
        "lastModified": "2026-07-28T17:09:51.890",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64811",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "IntelliJ executes development-container configuration from an untrusted project before the user grants project trust.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 148,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64812",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:30.497Z",
      "date_published": "2026-07-23T11:36:59.500Z",
      "date_updated": "2026-07-24T03:56:16.546Z",
      "publisher": "JetBrains",
      "title": "In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "IntelliJ IDEA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00363,
        "percentile": 0.29065
      },
      "nvd": {
        "published": "2026-07-23T12:18:36.783",
        "lastModified": "2026-07-28T17:10:06.610",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64812",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Remote Development input action is exposed without authenticating the caller.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 114,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64813",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:30.707Z",
      "date_published": "2026-07-23T11:36:59.917Z",
      "date_updated": "2026-07-24T03:56:17.355Z",
      "publisher": "JetBrains",
      "title": "In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "IntelliJ IDEA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00393,
        "percentile": 0.3204
      },
      "nvd": {
        "published": "2026-07-23T12:18:36.897",
        "lastModified": "2026-07-28T17:10:41.343",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64813",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A Remote Development session relies on client-side enforcement for a settings authorization boundary, but the exact setting and server-side check are not public.",
        "basis": [
          "CNA record",
          "CWE-602",
          "JetBrains fixed-issues data"
        ],
        "deepDive": true,
        "notes": "Inspected https://www.jetbrains.com/privacy-security/issues-fixed/ and its official data source https://resources.jetbrains.com/storage/issues-fixed/data.json; the entry confirms IJPL-245849, Critical severity, and resolution in 2026.2 but adds no implementation detail."
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 120,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64814",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:30.920Z",
      "date_published": "2026-07-23T11:37:00.248Z",
      "date_updated": "2026-07-23T13:21:25.814Z",
      "publisher": "JetBrains",
      "title": "In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "IntelliJ IDEA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23889
      },
      "nvd": {
        "published": "2026-07-23T12:18:37.010",
        "lastModified": "2026-07-28T17:10:52.127",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64814",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that IntelliJ IDEA permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 110,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64815",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:20:31.114Z",
      "date_published": "2026-07-23T11:37:00.625Z",
      "date_updated": "2026-07-24T03:56:18.148Z",
      "publisher": "JetBrains",
      "title": "In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "IntelliJ IDEA"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1.700000000000001,
      "epss": {
        "score": 0.0033,
        "percentile": 0.25548
      },
      "nvd": {
        "published": "2026-07-23T12:18:37.120",
        "lastModified": "2026-07-28T17:11:02.603",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64815",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "IntelliJ IDEA interprets attacker-controlled UI Designer form content in a way that permits arbitrary code injection.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64816",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.160Z",
      "date_published": "2026-07-30T21:32:27.105Z",
      "date_updated": "2026-07-31T11:10:30.940Z",
      "publisher": "VulnCheck",
      "title": "RapidRAW < 1.6.0 NTLMv2 Credential Leak via UNC Path in lutPath",
      "affected": {
        "vendors": [
          "CyberTimon"
        ],
        "products": [
          {
            "vendor": "CyberTimon",
            "product": "RapidRAW"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18616
      },
      "nvd": {
        "published": "2026-07-30T22:16:55.920",
        "lastModified": "2026-07-31T11:17:11.830",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64816",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "RapidRAW passes an unvalidated preset lutPath to File.open, allowing a Windows UNC path to select an attacker-controlled SMB server.",
        "basis": [
          "CNA",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/CyberTimon/RapidRAW/releases/tag/v1.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/CyberTimon/RapidRAW/commit/83852f36ba4a260be",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rapidraw-ntlmv2-credential-leak-via-unc-path-in-lutpath",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 773,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64821",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.160Z",
      "date_published": "2026-07-21T20:31:35.885Z",
      "date_updated": "2026-07-22T14:49:56.056Z",
      "publisher": "VulnCheck",
      "title": "djangoSIGE 1.10 CSRF via GET-based Order Cancellation Views",
      "affected": {
        "vendors": [
          "thiagopena"
        ],
        "products": [
          {
            "vendor": "thiagopena",
            "product": "djangoSIGE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04636
      },
      "nvd": {
        "published": "2026-07-21T21:16:53.497",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64821",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The four order-cancellation views perform state changes from HTTP GET handlers, so cross-origin image requests bypass Django's unsafe-method CSRF checks while carrying the victim's session.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/americooo/pentest-writeups/tree/main/djangoSIGE-CVE-2026-64821-64822",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/thiagopena/djangoSIGE/pull/163",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/djangosige-csrf-via-get-based-order-cancellation-views",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 721,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64822",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.160Z",
      "date_published": "2026-07-21T20:28:03.702Z",
      "date_updated": "2026-07-22T14:30:16.973Z",
      "publisher": "VulnCheck",
      "title": "djangoSIGE 1.10 User Enumeration via ForgotPasswordView",
      "affected": {
        "vendors": [
          "thiagopena"
        ],
        "products": [
          {
            "vendor": "thiagopena",
            "product": "djangoSIGE"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-203",
          "name": "Observable Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00247,
        "percentile": 0.16022
      },
      "nvd": {
        "published": "2026-07-21T21:16:53.640",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64822",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ForgotPasswordView returns distinguishable responses for existing and nonexistent usernames, creating an account-existence oracle.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-203"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/americooo/pentest-writeups/tree/main/djangoSIGE-CVE-2026-64821-64822",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/thiagopena/djangoSIGE/pull/163",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/djangosige-user-enumeration-via-forgotpasswordview",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 507,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64823",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.160Z",
      "date_published": "2026-07-21T15:16:03.790Z",
      "date_updated": "2026-07-22T14:12:16.922Z",
      "publisher": "VulnCheck",
      "title": "Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI",
      "affected": {
        "vendors": [
          "home-assistant"
        ],
        "products": [
          {
            "vendor": "home-assistant",
            "product": "Home Assistant Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 2.6,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08059
      },
      "nvd": {
        "published": "2026-07-21T16:17:21.230",
        "lastModified": "2026-07-22T15:17:21.770",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64823",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Home Assistant Core rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/home-assistant/core/releases/tag/2026.5.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/home-assistant/core/pull/171585",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/home-assistant/core/commit/894a68acb678afc382fe5ea9002e61ab7f862011",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/home-assistant-core-xss-via-shelly-media-player-py-thumb-uri",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64824",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.160Z",
      "date_published": "2026-07-21T15:39:52.162Z",
      "date_updated": "2026-07-28T01:05:57.907Z",
      "publisher": "VulnCheck",
      "title": "Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore",
      "affected": {
        "vendors": [
          "home-assistant"
        ],
        "products": [
          {
            "vendor": "home-assistant",
            "product": "Home Assistant Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00576,
        "percentile": 0.44258
      },
      "nvd": {
        "published": "2026-07-21T16:17:21.433",
        "lastModified": "2026-07-21T20:28:41.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64824",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A SYMTYPE archive entry supplies an absolute link target that a following regular file uses to write outside the extraction root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/home-assistant/core/releases/tag/2026.7.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/home-assistant/core/pull/172252",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/home-assistant/core/commit/1e457600f1093c15e1325742d03e2b76498c79c1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/home-assistant-core-symlink-path-traversal-rce-via-backup-restore",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-78r8-wwqv-r299",
          "host": "github.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 660,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64825",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.160Z",
      "date_published": "2026-07-21T15:40:18.756Z",
      "date_updated": "2026-07-28T01:06:00.415Z",
      "publisher": "VulnCheck",
      "title": "Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload",
      "affected": {
        "vendors": [
          "home-assistant"
        ],
        "products": [
          {
            "vendor": "home-assistant",
            "product": "Home Assistant Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00482,
        "percentile": 0.39022
      },
      "nvd": {
        "published": "2026-07-21T16:17:21.633",
        "lastModified": "2026-07-21T20:28:41.683",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64825",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Backup restore uses the backup.json name in a path join, so an absolute value discards the configured backup directory and selects an arbitrary write target.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/home-assistant/core/releases/tag/2026.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/home-assistant/core/pull/172368",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/home-assistant/core/commit/567fe858289876b68b8162a77bd46e1e1af79752",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/home-assistant-core-path-traversal-file-write-via-backup-upload",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64828",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.161Z",
      "date_published": "2026-07-22T15:39:34.424Z",
      "date_updated": "2026-07-22T16:30:19.557Z",
      "publisher": "VulnCheck",
      "title": "Froiden TableTrack 1.3.10 Stored XSS via Order Notes Field",
      "affected": {
        "vendors": [
          "Froiden"
        ],
        "products": [
          {
            "vendor": "Froiden",
            "product": "TableTrack"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10545
      },
      "nvd": {
        "published": "2026-07-22T16:18:50.487",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64828",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TableTrack stores order notes and renders them in the administrator view without sanitizing executable HTML or JavaScript.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-64828",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://codecanyon.net/item/tabletrack-the-complete-saas-restaurant-management-solution/55116396",
          "host": "codecanyon.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/froiden-tabletrack-stored-xss-via-order-notes-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 424,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64829",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.161Z",
      "date_published": "2026-07-22T19:57:29.754Z",
      "date_updated": "2026-07-28T01:06:01.111Z",
      "publisher": "VulnCheck",
      "title": "Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow",
      "affected": {
        "vendors": [
          "q2a"
        ],
        "products": [
          {
            "vendor": "q2a",
            "product": "question2answer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18777
      },
      "nvd": {
        "published": "2026-07-22T20:17:08.423",
        "lastModified": "2026-07-23T16:17:49.240",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64829",
        "family": "CRYPTO_SECRET",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in qa-include/app/users-edit.php.",
        "basis": [
          "CNA",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/q2a/question2answer/pull/1017",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/question2answer-session-fixation-via-forgot-password-flow",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 647,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64830",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.161Z",
      "date_published": "2026-07-22T16:33:05.724Z",
      "date_updated": "2026-07-28T01:06:01.869Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle Demuxer",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27384
      },
      "nvd": {
        "published": "2026-07-22T17:16:58.557",
        "lastModified": "2026-07-28T17:00:32.043",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64830",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The VobSub demuxer writes more distinct stream IDs into the fixed vobsub->q array than that array can hold.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 571,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64831",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.161Z",
      "date_published": "2026-07-22T16:35:43.775Z",
      "date_updated": "2026-07-28T01:06:02.677Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg 8.0 - 8.1.2 Stack Buffer Overflow in Vulkan HEVC Decoder",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00457,
        "percentile": 0.37439
      },
      "nvd": {
        "published": "2026-07-22T17:16:58.697",
        "lastModified": "2026-07-28T17:00:51.803",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64831",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "vk_hevc_end_frame() trusts vps_num_hrd_parameters above HEVC_MAX_SUB_LAYERS and overwrites fixed stack arrays while decoding HEVC.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 489,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64832",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.161Z",
      "date_published": "2026-07-22T17:01:16.181Z",
      "date_updated": "2026-07-28T01:06:03.370Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg 4.4 - 8.1.2 Double-Free in NVDEC Hardware Decoder via nvdec.c",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00332,
        "percentile": 0.25781
      },
      "nvd": {
        "published": "2026-07-22T18:17:05.483",
        "lastModified": "2026-07-28T17:01:21.170",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64832",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FFmpeg can release the same allocation twice along one error and teardown path.",
        "basis": [
          "CNA",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 544,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64833",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.161Z",
      "date_published": "2026-07-22T17:03:20.875Z",
      "date_updated": "2026-07-28T01:06:04.055Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg 0.7.1 - 8.1.2 Out-of-Bounds Read via S/PDIF Muxer spdifenc.c",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11845
      },
      "nvd": {
        "published": "2026-07-22T18:17:05.627",
        "lastModified": "2026-07-28T17:01:39.307",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64833",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A length, offset, or termination error makes the program read beyond the end of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 471,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64834",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.161Z",
      "date_published": "2026-07-22T17:06:07.659Z",
      "date_updated": "2026-07-28T01:06:04.724Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg 0.6.3 - 8.1.2 Infinite Loop DoS via RTP/ASF Demuxer",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00503,
        "percentile": 0.40236
      },
      "nvd": {
        "published": "2026-07-22T18:17:05.780",
        "lastModified": "2026-07-28T17:01:56.720",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64834",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The RTP/ASF demuxer accepts an object chunksize below the 24-byte header minimum, so its loop cursor does not advance.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 513,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64835",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:27:48.161Z",
      "date_published": "2026-07-22T17:24:05.477Z",
      "date_updated": "2026-07-28T01:06:05.429Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio Decoder",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00332,
        "percentile": 0.2578
      },
      "nvd": {
        "published": "2026-07-22T18:17:05.917",
        "lastModified": "2026-07-28T17:02:06.783",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-64835",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ADX header re-parsing accepts a mid-stream channel change but leaves the internal channel count stale before indexing the prev array.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-64863",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:31:39.291Z",
      "date_published": "2026-07-28T22:02:15.887Z",
      "date_updated": "2026-07-29T12:48:07.346Z",
      "publisher": "GitHub_M",
      "title": "goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite",
      "affected": {
        "vendors": [
          "goshs-labs"
        ],
        "products": [
          {
            "vendor": "goshs-labs",
            "product": "goshs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26229
      },
      "nvd": {
        "published": "2026-07-28T23:17:10.213",
        "lastModified": "2026-07-30T19:19:45.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64863",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The WebDAV guard classifies MOVE only as a write and therefore skips the no-delete policy before a move deletes or overwrites a destination.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/goshs-labs/goshs/security/advisories/GHSA-hq33-8jgp-8qq3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/goshs-labs/goshs/commit/0444ac6b1a8176ddae70d940adf7a26b2e5a6c29",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/goshs-labs/goshs/releases/tag/v2.1.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 325,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64870",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:31:39.292Z",
      "date_published": "2026-07-30T17:01:18.102Z",
      "date_updated": "2026-07-30T17:42:51.968Z",
      "publisher": "GitHub_M",
      "title": "MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation",
      "affected": {
        "vendors": [
          "1Panel-dev"
        ],
        "products": [
          {
            "vendor": "1Panel-dev",
            "product": "MaxKB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11999
      },
      "nvd": {
        "published": "2026-07-30T19:18:35.397",
        "lastModified": "2026-07-30T19:29:19.027",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64870",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "UpdateStoreTool sends requests to caller-supplied download and callback URLs without trusted-host, redirect, or internal-address validation.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-7xxm-gqxv-ph3v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/1Panel-dev/MaxKB/commit/a96a4fc17051d80e5b90a632ad8ec851d7d24b58",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 472,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64871",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:35:16.486Z",
      "date_published": "2026-07-23T09:14:27.579Z",
      "date_updated": "2026-07-25T05:34:34.817Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Cache Cleaner extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00093,
        "percentile": 0.007
      },
      "nvd": {
        "published": "2026-07-23T10:16:51.980",
        "lastModified": "2026-07-24T20:18:19.543",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64871",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cache-purge URLs are accepted without consistently requiring a valid CSRF token or the cache-management permission.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64872",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:35:16.486Z",
      "date_published": "2026-07-23T09:12:05.620Z",
      "date_updated": "2026-07-25T05:32:14.906Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Cache Cleaner Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13079
      },
      "nvd": {
        "published": "2026-07-23T10:16:52.087",
        "lastModified": "2026-07-24T20:18:19.690",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64872",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Cache Cleaner Pro accepts purge and log paths that can traverse outside the Joomla site webroot.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 152,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64873",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:35:16.486Z",
      "date_published": "2026-07-23T09:14:50.435Z",
      "date_updated": "2026-07-25T05:34:58.799Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Cache Cleaner Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18803
      },
      "nvd": {
        "published": "2026-07-23T10:16:52.193",
        "lastModified": "2026-07-24T20:18:19.837",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64873",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The URL validation in Cache Cleaner Pro extension for Joomla permits an attacker-selected destination to reach private, loopback, metadata, or otherwise restricted services.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 144,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64874",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:35:16.486Z",
      "date_published": "2026-07-23T09:11:18.832Z",
      "date_updated": "2026-07-27T13:29:53.752Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Cache Cleaner Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21236
      },
      "nvd": {
        "published": "2026-07-23T10:16:52.297",
        "lastModified": "2026-07-27T14:16:59.813",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64874",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Cache Cleaner Pro places CDN credentials in administrator request URLs, exposing the secrets through the URL channel and its observers.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64875",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:46:40.119Z",
      "date_published": "2026-07-23T09:13:55.404Z",
      "date_updated": "2026-07-27T13:32:38.703Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "GeoIP extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-290",
          "name": "Authentication Bypass by Spoofing",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11922
      },
      "nvd": {
        "published": "2026-07-23T10:16:52.400",
        "lastModified": "2026-07-27T14:16:59.970",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64875",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GeoIP trusts spoofable forwarded client-IP headers as the request's network identity and applies location policy to the forged address.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-290"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 180,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64876",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T18:46:40.119Z",
      "date_published": "2026-07-23T09:12:50.726Z",
      "date_updated": "2026-07-29T05:38:42.253Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks  in GeoIP extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "GeoIP extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00127,
        "percentile": 0.02779
      },
      "nvd": {
        "published": "2026-07-23T10:16:52.510",
        "lastModified": "2026-07-28T16:20:05.543",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64876",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GeoIP database-update requests inconsistently enforce both CSRF tokens and the Super User capability, permitting unauthorized updates.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-284",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 219,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T19:19:24.798Z",
      "date_published": "2026-07-21T18:06:22.276Z",
      "date_updated": "2026-07-24T03:55:53.208Z",
      "publisher": "tenable",
      "title": "An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.",
      "affected": {
        "vendors": [
          "Tenable, Inc."
        ],
        "products": [
          {
            "vendor": "Tenable, Inc.",
            "product": "Security Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00191,
        "percentile": 0.0905
      },
      "nvd": {
        "published": "2026-07-21T19:17:13.340",
        "lastModified": "2026-07-24T05:16:47.993",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64877",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The ticket API concatenates attacker-controlled input into SQL syntax despite the record's generic input-validation mapping.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tenable.com/security/tns-2026-19",
          "host": "www.tenable.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 149,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64878",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T19:19:24.798Z",
      "date_published": "2026-07-21T19:41:36.053Z",
      "date_updated": "2026-07-24T03:55:54.040Z",
      "publisher": "tenable",
      "title": "Command Injection",
      "affected": {
        "vendors": [
          "Tenable, Inc."
        ],
        "products": [
          {
            "vendor": "Tenable, Inc.",
            "product": "Security Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00542,
        "percentile": 0.42478
      },
      "nvd": {
        "published": "2026-07-21T20:17:04.630",
        "lastModified": "2026-07-24T05:16:48.117",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64878",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Analysis REST endpoint places asset-filter input into a shell command without neutralizing shell metacharacters.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tenable.com/security/tns-2026-19",
          "host": "www.tenable.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 204,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64879",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T19:19:24.798Z",
      "date_published": "2026-07-21T19:54:06.008Z",
      "date_updated": "2026-07-24T03:55:54.833Z",
      "publisher": "tenable",
      "title": "Command Injection",
      "affected": {
        "vendors": [
          "Tenable, Inc."
        ],
        "products": [
          {
            "vendor": "Tenable, Inc.",
            "product": "Security Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.9,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.9,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.0259,
        "percentile": 0.83749
      },
      "nvd": {
        "published": "2026-07-21T20:17:04.763",
        "lastModified": "2026-07-24T05:16:48.240",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64879",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The audit upload path embeds an unsanitized filename in a system command, allowing shell metacharacters to alter the command.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tenable.com/security/tns-2026-19",
          "host": "www.tenable.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 234,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64880",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T19:19:24.798Z",
      "date_published": "2026-07-21T20:01:28.800Z",
      "date_updated": "2026-07-22T18:25:28.118Z",
      "publisher": "tenable",
      "title": "Blind SQL Injection",
      "affected": {
        "vendors": [
          "Tenable, Inc."
        ],
        "products": [
          {
            "vendor": "Tenable, Inc.",
            "product": "Security Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08177
      },
      "nvd": {
        "published": "2026-07-21T20:17:04.900",
        "lastModified": "2026-07-22T20:35:40.827",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64880",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tenable.com/security/tns-2026-19",
          "host": "www.tenable.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-64881",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-20T19:19:24.798Z",
      "date_published": "2026-07-21T20:09:50.741Z",
      "date_updated": "2026-07-24T03:55:55.735Z",
      "publisher": "tenable",
      "title": "Command Injection",
      "affected": {
        "vendors": [
          "Tenable, Inc."
        ],
        "products": [
          {
            "vendor": "Tenable, Inc.",
            "product": "Security Center"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:vulnreport@tenable.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.0144,
        "percentile": 0.70583
      },
      "nvd": {
        "published": "2026-07-21T21:16:53.880",
        "lastModified": "2026-07-24T05:16:48.357",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-64881",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tenable.com/security/tns-2026-19",
          "host": "www.tenable.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65007",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T11:32:54.896Z",
      "date_published": "2026-07-21T11:39:56.387Z",
      "date_updated": "2026-07-23T14:29:10.593Z",
      "publisher": "VulnCheck",
      "title": "Grav before 1.0.8 Missing Authorization on API Key Generation",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18305
      },
      "nvd": {
        "published": "2026-07-21T12:19:00.910",
        "lastModified": "2026-07-23T15:17:46.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65007",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The API-key task requires only baseline admin.login and lets the caller mint a key bound to any account.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-7v74-m76q-8wf3",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-missing-authorization-on-api-key-generation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 638,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65008",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T11:32:54.897Z",
      "date_published": "2026-07-21T11:39:57.075Z",
      "date_updated": "2026-07-22T14:20:53.883Z",
      "publisher": "VulnCheck",
      "title": "Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00838,
        "percentile": 0.54248
      },
      "nvd": {
        "published": "2026-07-21T12:19:01.183",
        "lastModified": "2026-07-22T15:17:21.973",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65008",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Blueprint::dynamicData() invokes an attacker-selected Class::method string with call_user_func_array() without an allowed-callable list.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-fj2p-qj2f-74v5",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-remote-code-execution-via-blueprint-dynamicdata",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 590,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65009",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T11:32:54.897Z",
      "date_published": "2026-07-21T11:39:57.774Z",
      "date_updated": "2026-07-22T14:02:21.095Z",
      "publisher": "VulnCheck",
      "title": "OpenRemote before 1.26.2 Information Disclosure via Syslog REST API",
      "affected": {
        "vendors": [
          "openremote"
        ],
        "products": [
          {
            "vendor": "openremote",
            "product": "openremote"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00183,
        "percentile": 0.08123
      },
      "nvd": {
        "published": "2026-07-21T12:19:01.327",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65009",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SyslogResource filters access by role but does not bind returned operational logs to the requested realm.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openremote/openremote/security/advisories/GHSA-fv8q-rwj8-2c55",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openremote-before-information-disclosure-via-syslog-rest-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 415,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65010",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T11:32:54.897Z",
      "date_published": "2026-07-23T17:55:52.165Z",
      "date_updated": "2026-07-24T21:35:11.441Z",
      "publisher": "VulnCheck",
      "title": "Datasets Symlink-following Arbitrary File Write via Extractor.extract()",
      "affected": {
        "vendors": [
          "huggingface"
        ],
        "products": [
          {
            "vendor": "huggingface",
            "product": "datasets"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-61",
          "name": "UNIX Symbolic Link (Symlink) Following",
          "abstraction": "Compound",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 2.1999999999999993,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03224
      },
      "nvd": {
        "published": "2026-07-23T19:17:03.890",
        "lastModified": "2026-07-23T20:17:21.540",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65010",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "datasets follows an attacker-influenced link or pre-planted path without verifying the final filesystem object.",
        "basis": [
          "CNA",
          "CWE-61"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/huggingface/datasets/issues/8296",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/huggingface/datasets/pull/8303",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/huggingface/datasets/commit/ad2d853ae2ce41d8068c23b44c2e29004312ccee",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/datasets-symlink-following-arbitrary-file-write-via-extractor-extract",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 418,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65011",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T11:32:54.897Z",
      "date_published": "2026-07-22T16:13:35.244Z",
      "date_updated": "2026-07-24T21:35:12.085Z",
      "publisher": "VulnCheck",
      "title": "Graylog2 Server Missing Permission Check on Event Definition Duplicate",
      "affected": {
        "vendors": [
          "Graylog2"
        ],
        "products": [
          {
            "vendor": "Graylog2",
            "product": "graylog2-server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12311
      },
      "nvd": {
        "published": "2026-07-22T17:16:58.837",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65011",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The event-definition duplicate endpoint checks create capability but omits permission on the selected source definition.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Graylog2/graylog2-server/issues/26590",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/Graylog2/graylog2-server/pull/26706",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/Graylog2/graylog2-server/commit/46a2eeba4cdbc1408ff4cbf7b466853a8acfb38d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Graylog2/graylog2-server/pull/26718",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/Graylog2/graylog2-server/pull/26719",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/graylog2-server-missing-permission-check-on-event-definition-duplicate",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 444,
        "referenceCount": 6,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-65012",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T11:32:54.897Z",
      "date_published": "2026-07-22T16:13:58.807Z",
      "date_updated": "2026-07-24T21:35:12.778Z",
      "publisher": "VulnCheck",
      "title": "InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder",
      "affected": {
        "vendors": [
          "invoke-ai"
        ],
        "products": [
          {
            "vendor": "invoke-ai",
            "product": "InvokeAI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17239
      },
      "nvd": {
        "published": "2026-07-22T17:16:58.990",
        "lastModified": "2026-07-23T16:17:50.107",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65012",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An arbitrary scan_path recursively enumerates server files outside the intended scan root.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/invoke-ai/InvokeAI/issues/9365",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/invoke-ai/InvokeAI/releases/tag/v6.13.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/invoke-ai/InvokeAI/pull/9367",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/invoke-ai/InvokeAI/commit/d315b8967f548732912bd9b390853ed4af97d8cb",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/invokeai-unauthenticated-directory-enumeration-via-scan-folder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65013",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T11:32:54.897Z",
      "date_published": "2026-07-22T16:14:23.346Z",
      "date_updated": "2026-07-24T21:35:13.457Z",
      "publisher": "VulnCheck",
      "title": "Onlook tRPC Insecure Direct Object Reference via multiple procedures",
      "affected": {
        "vendors": [
          "onlook"
        ],
        "products": [
          {
            "vendor": "onlook",
            "product": "repo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.003,
        "percentile": 0.22232
      },
      "nvd": {
        "published": "2026-07-22T17:16:59.143",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65013",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Multiple tRPC procedures accept a caller-supplied project or conversation UUID without binding that object to the authenticated user.",
        "basis": [
          "CNA record",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/onlook-dev/onlook/issues/3122",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/onlook-dev/onlook/pull/3129",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/onlook-dev/onlook/commit/423e2e924366419e418ee049093872d535eea41a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/onlook-trpc-insecure-direct-object-reference-via-multiple-procedures",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 506,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T11:32:54.897Z",
      "date_published": "2026-07-22T11:21:37.350Z",
      "date_updated": "2026-07-22T12:26:12.006Z",
      "publisher": "VulnCheck",
      "title": "n8n before 2.28.0 Authentication Bypass via test-webhook",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00334,
        "percentile": 0.25944
      },
      "nvd": {
        "published": "2026-07-22T12:18:18.453",
        "lastModified": "2026-07-27T19:00:42.247",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65014",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "n8n exposes a security-sensitive endpoint without requiring caller authentication.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-33q9-f52j-gc75",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-authentication-bypass-via-test-webhook",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 440,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-65015",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T11:32:54.897Z",
      "date_published": "2026-07-22T11:21:38.034Z",
      "date_updated": "2026-07-22T18:24:22.671Z",
      "publisher": "VulnCheck",
      "title": "n8n before 2.30.1 Privilege Escalation via run_node_tool",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00324,
        "percentile": 0.24881
      },
      "nvd": {
        "published": "2026-07-22T12:18:18.587",
        "lastModified": "2026-07-28T18:17:25.740",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65015",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The AI Agents run-node tool lets a Project Viewer execute nodes and access credential secrets without checking that role's authorization.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-x5vx-c2c8-m3w9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-privilege-escalation-via-run-node-tool",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "VDB Entry",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 364,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-65016",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T11:32:54.897Z",
      "date_published": "2026-07-22T11:21:38.704Z",
      "date_updated": "2026-07-24T21:35:14.139Z",
      "publisher": "VulnCheck",
      "title": "n8n before 1.123.64, 2.29.8, and 2.30.1 Privilege Escalation via SSO Instance-Role",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00308,
        "percentile": 0.2315
      },
      "nvd": {
        "published": "2026-07-22T12:18:18.733",
        "lastModified": "2026-07-27T19:08:16.213",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65016",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The n8n SSO provisioning path accepts an IdP instance-role claim that maps to global:owner without applying the owner-role rejection used by token exchange.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-35q8-9mj6-wjmf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-privilege-escalation-via-sso-instance-role",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 780,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65048",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T14:05:53.719Z",
      "date_published": "2026-07-21T14:16:08.414Z",
      "date_updated": "2026-07-22T14:56:24.647Z",
      "publisher": "VulnCheck",
      "title": "Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index",
      "affected": {
        "vendors": [
          "Saturday Drive"
        ],
        "products": [
          {
            "vendor": "Saturday Drive",
            "product": "Ninja Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00313,
        "percentile": 0.23662
      },
      "nvd": {
        "published": "2026-07-21T15:16:38.813",
        "lastModified": "2026-07-21T18:55:23.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65048",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wordpress.org/plugins/ninja-forms/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://wordpress.org/plugins/ninja-forms/changelog/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ninja-forms-unauthenticated-stored-cross-site-scripting-via-repeatable-fieldset-submission-index",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 728,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65049",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T14:05:53.719Z",
      "date_published": "2026-07-21T14:22:08.297Z",
      "date_updated": "2026-07-22T14:56:16.047Z",
      "publisher": "VulnCheck",
      "title": "Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action",
      "affected": {
        "vendors": [
          "Saturday Drive"
        ],
        "products": [
          {
            "vendor": "Saturday Drive",
            "product": "Ninja Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00275,
        "percentile": 0.1962
      },
      "nvd": {
        "published": "2026-07-21T15:16:38.970",
        "lastModified": "2026-07-21T18:55:23.673",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65049",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "nf_delete_all_data accepts a subsite administrator's site-scoped capability and nonce before running a migration that deletes Ninja Forms data across every blog.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wordpress.org/plugins/ninja-forms/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://wordpress.org/plugins/ninja-forms/changelog/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ninja-forms-cross-site-network-wide-data-deletion-on-wordpress-multisite-via-nf-delete-all-data-ajax-action",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 682,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65050",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T14:05:53.719Z",
      "date_published": "2026-07-21T14:26:53.210Z",
      "date_updated": "2026-07-23T18:15:32.340Z",
      "publisher": "VulnCheck",
      "title": "Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Submissions to Unauthenticated Visitors",
      "affected": {
        "vendors": [
          "Saturday Drive"
        ],
        "products": [
          {
            "vendor": "Saturday Drive",
            "product": "Ninja Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00343,
        "percentile": 0.26973
      },
      "nvd": {
        "published": "2026-07-21T15:16:39.147",
        "lastModified": "2026-07-23T19:17:04.233",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65050",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Ninja Forms submissions-table block accepts an arbitrary formID from an Author and publishes a bearer token that exposes the selected form's submissions to visitors.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wordpress.org/plugins/ninja-forms/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://wordpress.org/plugins/ninja-forms/changelog/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ninja-forms-missing-authorization-in-submissions-table-gutenberg-block-discloses-form-submissions-to-unauthenticated-visitors",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 699,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65051",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T14:05:53.719Z",
      "date_published": "2026-07-21T14:31:55.558Z",
      "date_updated": "2026-07-23T14:27:47.196Z",
      "publisher": "VulnCheck",
      "title": "Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in AJAX Submission Handler",
      "affected": {
        "vendors": [
          "Saturday Drive"
        ],
        "products": [
          {
            "vendor": "Saturday Drive",
            "product": "Ninja Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-602",
          "name": "Client-Side Enforcement of Server-Side Security",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00283,
        "percentile": 0.20495
      },
      "nvd": {
        "published": "2026-07-21T15:16:39.290",
        "lastModified": "2026-07-23T15:17:47.920",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65051",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Client-supplied metadata overwrites server-defined form controls and their enforcement checks.",
        "basis": [
          "CNA",
          "CWE-602"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wordpress.org/plugins/ninja-forms/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://wordpress.org/plugins/ninja-forms/changelog/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ninja-forms-server-side-validation-bypass-via-client-controlled-field-metadata-merge-in-ajax-submission-handler",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 568,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65052",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T14:05:53.719Z",
      "date_published": "2026-07-21T14:36:07.284Z",
      "date_updated": "2026-07-22T14:57:13.781Z",
      "publisher": "VulnCheck",
      "title": "Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields",
      "affected": {
        "vendors": [
          "Saturday Drive"
        ],
        "products": [
          {
            "vendor": "Saturday Drive",
            "product": "Ninja Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-472",
          "name": "External Control of Assumed-Immutable Web Parameter",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00364,
        "percentile": 0.29149
      },
      "nvd": {
        "published": "2026-07-21T15:16:39.430",
        "lastModified": "2026-07-22T15:17:22.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65052",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The calculation handler treats an option value absent from the configured choice list as a valid attacker-supplied numeric price.",
        "basis": [
          "CNA",
          "CWE-472"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wordpress.org/plugins/ninja-forms/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://wordpress.org/plugins/ninja-forms/changelog/",
          "host": "wordpress.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ninja-forms-calculation-and-payment-total-tampering-via-fail-open-get-calc-value-in-listselect-and-listradio-fields",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 600,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65054",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T14:05:53.719Z",
      "date_published": "2026-07-21T20:28:30.111Z",
      "date_updated": "2026-07-22T15:41:48.448Z",
      "publisher": "VulnCheck",
      "title": "MediaCMS Private Media Metadata Disclosure via Playlist Ownership Loophole",
      "affected": {
        "vendors": [
          "MediaCMS"
        ],
        "products": [
          {
            "vendor": "MediaCMS",
            "product": "MediaCMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.1,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 5.1,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10363
      },
      "nvd": {
        "published": "2026-07-21T21:16:54.020",
        "lastModified": "2026-07-23T15:13:11.420",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65054",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MediaCMS lets a user add another owner's media token to a playlist and then returns private metadata without validating ownership.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mediacms-io/mediacms/issues/1548",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/mediacms-io/mediacms",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/mediacms-private-media-metadata-disclosure-via-playlist-ownership-loophole",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 601,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65055",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T14:05:53.720Z",
      "date_published": "2026-07-21T20:43:53.144Z",
      "date_updated": "2026-07-23T14:11:24.318Z",
      "publisher": "VulnCheck",
      "title": "Taiga taiga-back Private Project Member Roster Disclosure via Unauthenticated filters_data Endpoints",
      "affected": {
        "vendors": [
          "Taiga"
        ],
        "products": [
          {
            "vendor": "Taiga",
            "product": "taiga-back"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16533
      },
      "nvd": {
        "published": "2026-07-21T21:16:54.157",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65055",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project by supplying a project ID to the filters_data API endpoints on UserStory, Task, Issue, and Epic viewsets.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/taigaio/taiga-back/issues/246",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "product"
          ]
        },
        {
          "url": "https://github.com/taigaio/taiga-back",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/taiga-taiga-back-private-project-member-roster-disclosure-via-unauthenticated-filters-data-endpoints",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 595,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65056",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T14:05:53.720Z",
      "date_published": "2026-07-21T20:48:50.681Z",
      "date_updated": "2026-07-22T15:01:19.864Z",
      "publisher": "VulnCheck",
      "title": "mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering",
      "affected": {
        "vendors": [
          "mzxrai"
        ],
        "products": [
          {
            "vendor": "mzxrai",
            "product": "mcp-webresearch"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00231,
        "percentile": 0.1401
      },
      "nvd": {
        "published": "2026-07-21T21:16:54.287",
        "lastModified": "2026-07-23T15:24:59.880",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65056",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering private or reserved IP ranges.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/mcp-webresearch.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "product"
          ]
        },
        {
          "url": "https://www.npmjs.com/package/@mzxrai/mcp-webresearch",
          "host": "www.npmjs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/mcp-webresearch-server-side-request-forgery-in-visit-page-due-to-missing-internal-ip-filtering",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 598,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65057",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T14:05:53.720Z",
      "date_published": "2026-07-21T20:56:10.062Z",
      "date_updated": "2026-07-28T01:06:06.066Z",
      "publisher": "VulnCheck",
      "title": "Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck",
      "affected": {
        "vendors": [
          "keephq"
        ],
        "products": [
          {
            "vendor": "keephq",
            "product": "keep"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00246,
        "percentile": 0.15857
      },
      "nvd": {
        "published": "2026-07-21T21:16:54.427",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65057",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected component trusts attacker-controlled request, origin, redirect, or channel metadata without validating the final security boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/keephq/keep/issues/6630",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/keephq/keep",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/keep-unauthenticated-server-side-request-forgery-via-post-providers-healthcheck",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 493,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65058",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T14:35:48.323Z",
      "date_published": "2026-07-21T20:13:00.560Z",
      "date_updated": "2026-07-30T17:29:43.291Z",
      "publisher": "cisa-cg",
      "title": "Trezor Safe improper security check in on-device display",
      "affected": {
        "vendors": [
          "Trezor"
        ],
        "products": [
          {
            "vendor": "Trezor",
            "product": "Safe 3"
          },
          {
            "vendor": "Trezor",
            "product": "Safe 7"
          },
          {
            "vendor": "Trezor",
            "product": "Safe 5"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-358",
          "name": "Improperly Implemented Security Check for Standard",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:9119a7d8-5eab-497f-8521-727c672e3725",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0.6000000000000005,
      "epss": {
        "score": 0.00279,
        "percentile": 0.2017
      },
      "nvd": {
        "published": "2026-07-21T21:16:54.567",
        "lastModified": "2026-07-30T19:18:35.550",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65058",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Trezor signs the full transaction tail while the confirmation screen presents only the first chunk, so the user authorization is not bound to all signed bytes.",
        "basis": [
          "CNA",
          "CWE-358"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/trezor/trezor-firmware/commit/70c9b0c07748",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-65058",
          "host": "www.cve.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-02.json",
          "host": "raw.githubusercontent.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 3,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65061",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:29:37.116Z",
      "date_published": "2026-07-21T19:07:41.644Z",
      "date_updated": "2026-07-23T12:48:19.771Z",
      "publisher": "CPANSec",
      "title": "Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::ReqRep::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01927
      },
      "nvd": {
        "published": "2026-07-21T20:17:05.030",
        "lastModified": "2026-07-23T14:17:42.040",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65061",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The shared mmap file is created without O_EXCL or O_NOFOLLOW, allowing a local peer to pre-create or redirect the path before the process opens it.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-ReqRep-Shared-0.05/diff/EGOR/Data-ReqRep-Shared-0.04#reqrep.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-ReqRep-Shared-0.05/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 807,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65062",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:29:37.116Z",
      "date_published": "2026-07-21T19:08:01.856Z",
      "date_updated": "2026-07-23T12:49:16.777Z",
      "publisher": "CPANSec",
      "title": "Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::SortedSet::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01926
      },
      "nvd": {
        "published": "2026-07-21T20:17:05.190",
        "lastModified": "2026-07-23T14:17:42.913",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65062",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The shared backing file is created mode 0666 and opened without O_EXCL or O_NOFOLLOW, exposing contents and accepting a pre-planted file or symlink.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-SortedSet-Shared-0.03/diff/EGOR/Data-SortedSet-Shared-0.02#sortedset.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-SortedSet-Shared-0.03/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 750,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65063",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:29:37.116Z",
      "date_published": "2026-07-21T19:08:19.927Z",
      "date_updated": "2026-07-23T12:50:22.071Z",
      "publisher": "CPANSec",
      "title": "Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::RadixTree::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01927
      },
      "nvd": {
        "published": "2026-07-21T20:17:05.313",
        "lastModified": "2026-07-23T14:17:43.680",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65063",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The shared mmap file is created world-readable and opened without exclusive-create or no-follow safeguards in a shared directory.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-RadixTree-Shared-0.02/diff/EGOR/Data-RadixTree-Shared-0.01#radix.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-RadixTree-Shared-0.02/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 746,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65064",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:29:37.116Z",
      "date_published": "2026-07-21T19:08:34.479Z",
      "date_updated": "2026-07-23T12:59:03.694Z",
      "publisher": "CPANSec",
      "title": "Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::HashMap::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01926
      },
      "nvd": {
        "published": "2026-07-21T20:17:05.430",
        "lastModified": "2026-07-23T14:17:44.167",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65064",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The shared-map backing file is opened without O_EXCL or O_NOFOLLOW and with a world-readable mode, allowing a planted path or symlink to select the file object.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-HashMap-Shared-0.14/diff/EGOR/Data-HashMap-Shared-0.13#shm_generic.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-HashMap-Shared-0.14/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 764,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65065",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:29:37.116Z",
      "date_published": "2026-07-21T19:08:49.522Z",
      "date_updated": "2026-07-27T14:07:43.749Z",
      "publisher": "CPANSec",
      "title": "Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::RoaringBitmap::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02484
      },
      "nvd": {
        "published": "2026-07-21T20:17:05.537",
        "lastModified": "2026-07-24T18:18:08.287",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65065",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The shared segment open omits O_EXCL and O_NOFOLLOW, so a preplanted file or symlink can redirect the mmap backing object to an attacker-selected target.",
        "basis": [
          "CNA",
          "CWE-59"
        ],
        "deepDive": false,
        "notes": "The record also describes mode 0666 and world-readable data; the symlink and pre-creation target failure is the selected primary family."
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-RoaringBitmap-Shared-0.02/diff/EGOR/Data-RoaringBitmap-Shared-0.01#roaring.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-RoaringBitmap-Shared-0.02/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 752,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65066",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:29:37.116Z",
      "date_published": "2026-07-21T19:09:03.992Z",
      "date_updated": "2026-07-23T13:08:00.634Z",
      "publisher": "CPANSec",
      "title": "Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::RingBuffer::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01927
      },
      "nvd": {
        "published": "2026-07-21T20:17:05.637",
        "lastModified": "2026-07-23T14:17:45.217",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65066",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The shared-segment open follows a pre-planted symlink and reuses an existing path because O_NOFOLLOW and O_EXCL are absent.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-RingBuffer-Shared-0.04/diff/EGOR/Data-RingBuffer-Shared-0.03#ring.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-RingBuffer-Shared-0.04/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 746,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65067",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:29:37.116Z",
      "date_published": "2026-07-21T19:09:26.950Z",
      "date_updated": "2026-07-23T13:16:50.281Z",
      "publisher": "CPANSec",
      "title": "Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::Intern::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01925
      },
      "nvd": {
        "published": "2026-07-21T20:17:05.733",
        "lastModified": "2026-07-23T14:17:45.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65067",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The shared segment open follows a pre-planted symlink and reuses an existing attacker-selected path instead of creating a new file exclusively.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-Intern-Shared-0.02/diff/EGOR/Data-Intern-Shared-0.01#intern.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-Intern-Shared-0.02/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 744,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65068",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:29:37.116Z",
      "date_published": "2026-07-21T19:09:41.280Z",
      "date_updated": "2026-07-23T13:18:33.180Z",
      "publisher": "CPANSec",
      "title": "Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::SpatialHash::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.8,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 3.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00117,
        "percentile": 0.01926
      },
      "nvd": {
        "published": "2026-07-21T20:17:05.837",
        "lastModified": "2026-07-23T14:17:46.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65068",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The shared mmap file is opened with world-readable permissions and follows a pre-planted symlink because O_EXCL and O_NOFOLLOW are absent.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-SpatialHash-Shared-0.02/diff/EGOR/Data-SpatialHash-Shared-0.01#sphash.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-SpatialHash-Shared-0.02/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 749,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65069",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T15:29:37.117Z",
      "date_published": "2026-07-21T19:10:00.536Z",
      "date_updated": "2026-07-23T13:22:20.294Z",
      "publisher": "CPANSec",
      "title": "Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW",
      "affected": {
        "vendors": [
          "EGOR"
        ],
        "products": [
          {
            "vendor": "EGOR",
            "product": "Data::DisjointSet::Shared"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00137,
        "percentile": 0.03556
      },
      "nvd": {
        "published": "2026-07-21T20:17:05.940",
        "lastModified": "2026-07-23T14:17:46.607",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65069",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Data::DisjointSet::Shared opens an attacker-selectable filesystem path without preventing symbolic-link substitution or exclusive-create races, so the operation can target a different object.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-59",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://metacpan.org/release/EGOR/Data-DisjointSet-Shared-0.02/diff/EGOR/Data-DisjointSet-Shared-0.01#dsu.h",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://metacpan.org/release/EGOR/Data-DisjointSet-Shared-0.02/changes",
          "host": "metacpan.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 746,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65100",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T17:10:18.202Z",
      "date_published": "2026-07-29T09:06:17.226Z",
      "date_updated": "2026-07-29T12:10:22.340Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-696",
          "name": "Incorrect Behavior Order",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00449,
        "percentile": 0.36877
      },
      "nvd": {
        "published": "2026-07-29T10:16:44.523",
        "lastModified": "2026-08-03T19:31:56.333",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65100",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Traffic Server mutates its HPACK dynamic table before confirming encoding succeeds, leaving subsequent headers out of sync with the peer decoder.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-696"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 456,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-65309",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T20:33:52.962Z",
      "date_published": "2026-07-31T07:17:40.473Z",
      "date_updated": "2026-07-31T16:36:34.930Z",
      "publisher": "CyberDanube",
      "title": "Storage of passwords in a reversible format",
      "affected": {
        "vendors": [
          "ANDRITZ"
        ],
        "products": [
          {
            "vendor": "ANDRITZ",
            "product": "HIPASE-250"
          },
          {
            "vendor": "ANDRITZ",
            "product": "250 SCALA"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-257",
          "name": "Storing Passwords in a Recoverable Format",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-327",
          "name": "Use of a Broken or Risky Cryptographic Algorithm",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:office@cyberdanube.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04895
      },
      "nvd": {
        "published": "2026-07-31T08:16:28.330",
        "lastModified": "2026-07-31T17:16:34.640",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65309",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "HIPASE-250 stores and transmits passwords in a reversible encrypted form instead of a one-way password hash.",
        "basis": [
          "CNA",
          "CWE-257",
          "CWE-327"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.andritz.com/",
          "host": "www.andritz.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 276,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-65310",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T20:33:52.962Z",
      "date_published": "2026-07-31T07:26:29.954Z",
      "date_updated": "2026-07-31T16:34:44.010Z",
      "publisher": "CyberDanube",
      "title": "Missing authentication and permissive CORS policy",
      "affected": {
        "vendors": [
          "ANDRITZ"
        ],
        "products": [
          {
            "vendor": "ANDRITZ",
            "product": "HIPASE-250"
          },
          {
            "vendor": "ANDRITZ",
            "product": "250 SCALA"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-942",
          "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:office@cyberdanube.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00318,
        "percentile": 0.24237
      },
      "nvd": {
        "published": "2026-07-31T09:16:58.447",
        "lastModified": "2026-07-31T17:16:34.750",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65310",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HIPASE-250 data and configuration endpoint is exposed without authentication in the default configuration, permitting unauthenticated reads of process values and server settings.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-942"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.andritz.com/",
          "host": "www.andritz.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 304,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-65311",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T20:33:52.962Z",
      "date_published": "2026-07-31T07:30:07.250Z",
      "date_updated": "2026-07-31T16:33:32.293Z",
      "publisher": "CyberDanube",
      "title": "Missing authentication for logging-configuration endpoint",
      "affected": {
        "vendors": [
          "ANDRITZ"
        ],
        "products": [
          {
            "vendor": "ANDRITZ",
            "product": "HIPASE-250"
          },
          {
            "vendor": "ANDRITZ",
            "product": "250 SCALA"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:office@cyberdanube.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00269,
        "percentile": 0.18847
      },
      "nvd": {
        "published": "2026-07-31T09:16:58.960",
        "lastModified": "2026-07-31T17:16:34.860",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65311",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-306",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.andritz.com/",
          "host": "www.andritz.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 358,
        "referenceCount": 1,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-65313",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T20:33:52.962Z",
      "date_published": "2026-07-31T07:34:11.400Z",
      "date_updated": "2026-07-31T16:32:44.345Z",
      "publisher": "CyberDanube",
      "title": "Use of hard-coded VNC credentials in the engineering-workstation provisioning",
      "affected": {
        "vendors": [
          "ANDRITZ"
        ],
        "products": [
          {
            "vendor": "ANDRITZ",
            "product": "HIPASE-250"
          },
          {
            "vendor": "ANDRITZ",
            "product": "250 SCALA"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1392",
          "name": "Use of Default Credentials",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:office@cyberdanube.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07363
      },
      "nvd": {
        "published": "2026-07-31T09:16:59.090",
        "lastModified": "2026-07-31T17:16:34.970",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65313",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The workstation provisioning script installs the same fixed x11vnc password on every engineering workstation.",
        "basis": [
          "CNA",
          "CWE-798",
          "CWE-1392"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.andritz.com/",
          "host": "www.andritz.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 333,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-65314",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T20:57:44.879Z",
      "date_published": "2026-07-21T21:05:44.377Z",
      "date_updated": "2026-07-22T15:35:06.428Z",
      "publisher": "VulnCheck",
      "title": "Electric Postgres Sync Excluded-Column Value Inference via Subset Where Clauses",
      "affected": {
        "vendors": [
          "ElectricSQL"
        ],
        "products": [
          {
            "vendor": "ElectricSQL",
            "product": "Electric Postgres Sync"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-203",
          "name": "Observable Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13693
      },
      "nvd": {
        "published": "2026-07-21T22:19:09.907",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65314",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Attackers can place excluded-column predicates in shape filters and infer hidden values from whether each predicate returns a row.",
        "basis": [
          "CNA",
          "CWE-203"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/electric-sql/electric/security/advisories/GHSA-c82q-v86f-c87f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/electric-sql/electric",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/electric-postgres-sync-excluded-column-value-inference-via-subset-where-clauses",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 426,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65315",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T20:57:44.879Z",
      "date_published": "2026-07-21T21:18:24.567Z",
      "date_updated": "2026-07-28T01:06:06.852Z",
      "publisher": "VulnCheck",
      "title": "Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parser",
      "affected": {
        "vendors": [
          "Ollama"
        ],
        "products": [
          {
            "vendor": "Ollama",
            "product": "Ollama"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-789",
          "name": "Memory Allocation with Excessive Size Value",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00572,
        "percentile": 0.4406
      },
      "nvd": {
        "published": "2026-07-21T22:19:10.050",
        "lastModified": "2026-07-22T20:40:02.810",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65315",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The GGUF parser trusts file-supplied lengths and counts as allocation sizes without checking them against the remaining file size.",
        "basis": [
          "CNA",
          "CWE-789"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ollama/ollama/issues/17042",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/ollama/ollama",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ollama-remote-denial-of-service-via-attacker-controlled-allocation-in-gguf-metadata-parser",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 649,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65316",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T20:57:44.880Z",
      "date_published": "2026-07-21T21:23:55.384Z",
      "date_updated": "2026-07-28T01:06:07.545Z",
      "publisher": "VulnCheck",
      "title": "xxl-job Cross-Job-Group Log Disclosure via Missing Authorization Check in /joblog/logDetailCat",
      "affected": {
        "vendors": [
          "xuxueli"
        ],
        "products": [
          {
            "vendor": "xuxueli",
            "product": "xxl-job"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30903
      },
      "nvd": {
        "published": "2026-07-21T22:19:10.197",
        "lastModified": "2026-07-23T19:17:04.387",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65316",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "xxl-job resolves a caller-controlled object identifier without binding the selected object to the caller's authorized scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/xuxueli/xxl-job/issues/3983",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/xuxueli/xxl-job",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/xxl-job-cross-job-group-log-disclosure-via-missing-authorization-check-in-joblog-logdetailcat",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 541,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65317",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T20:57:44.880Z",
      "date_published": "2026-07-21T21:31:01.979Z",
      "date_updated": "2026-07-23T14:02:13.652Z",
      "publisher": "VulnCheck",
      "title": "Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass",
      "affected": {
        "vendors": [
          "Weaviate"
        ],
        "products": [
          {
            "vendor": "Weaviate",
            "product": "Verba"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00481,
        "percentile": 0.38935
      },
      "nvd": {
        "published": "2026-07-21T22:19:10.340",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65317",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A prefix-based Origin check can be forged and the connect endpoint then issues a server-side request to caller-selected host and port values.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/verba.md#finding-2-ssrf--same-origin-middleware-bypass-in-apiconnect----goldenverba",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/weaviate/Verba",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/verba-goldenverba-server-side-request-forgery-via-api-connect-and-same-origin-middleware-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 611,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65318",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T20:57:44.880Z",
      "date_published": "2026-07-21T21:36:23.960Z",
      "date_updated": "2026-07-22T14:12:42.416Z",
      "publisher": "VulnCheck",
      "title": "Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader",
      "affected": {
        "vendors": [
          "Weaviate"
        ],
        "products": [
          {
            "vendor": "Weaviate",
            "product": "Verba"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00424,
        "percentile": 0.34964
      },
      "nvd": {
        "published": "2026-07-21T22:19:10.490",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65318",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A server-side request accepts an attacker-selected destination without enforcing the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/verba.md#finding-1-unauthenticated-ssrf-in-verba-websocket-import-endpoint-htmlreader",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/weaviate/Verba",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/verba-goldenverba-unauthenticated-server-side-request-forgery-via-websocket-import-endpoint-htmlreader",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 581,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65319",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T20:57:44.880Z",
      "date_published": "2026-07-21T21:40:53.529Z",
      "date_updated": "2026-07-22T15:09:30.443Z",
      "publisher": "VulnCheck",
      "title": "Feedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/text",
      "affected": {
        "vendors": [
          "Feedbin"
        ],
        "products": [
          {
            "vendor": "Feedbin",
            "product": "Feedbin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00371,
        "percentile": 0.29807
      },
      "nvd": {
        "published": "2026-07-21T22:19:10.630",
        "lastModified": "2026-07-23T15:23:01.470",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65319",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The entry-text API omits authentication before resolving a sequential entry identifier.",
        "basis": [
          "CNA record",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/feedbin.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://github.com/feedbin/feedbin/commit/04b89b84189e4727ea19d84ea4a44015859b29cc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://github.com/feedbin/feedbin",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/feedbin-unauthenticated-entry-content-disclosure-via-get-api-v2-entries-id-text",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 558,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65324",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T20:59:11.713Z",
      "date_published": "2026-07-29T08:17:46.795Z",
      "date_updated": "2026-07-29T12:20:42.788Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0.6999999999999993,
      "epss": {
        "score": 0.00474,
        "percentile": 0.38512
      },
      "nvd": {
        "published": "2026-07-29T09:16:30.410",
        "lastModified": "2026-08-03T13:40:01.187",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65324",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "HTTP/2 and HTTP/3 dechunking drops the per-stream buffer cap, so a slow client can retain unbounded response data in memory.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 350,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-65325",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-21T20:59:59.103Z",
      "date_published": "2026-07-29T08:23:28.374Z",
      "date_updated": "2026-07-29T12:19:26.906Z",
      "publisher": "apache",
      "title": "Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate re-verification",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Traffic Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-295",
          "name": "Improper Certificate Validation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06161
      },
      "nvd": {
        "published": "2026-07-29T09:16:30.543",
        "lastModified": "2026-08-03T13:39:52.730",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65325",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Traffic Server reuses an HTTP/2 origin connection for a new hostname without checking that the server certificate covers that hostname.",
        "basis": [
          "CNA",
          "CWE-295"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 322,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65421",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T19:32:49.396Z",
      "date_published": "2026-07-30T22:35:14.668Z",
      "date_updated": "2026-07-31T15:55:36.578Z",
      "publisher": "icscert",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "affected": {
        "vendors": [
          "MZ Automation GmbH"
        ],
        "products": [
          {
            "vendor": "MZ Automation GmbH",
            "product": "libiec61850"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07148
      },
      "nvd": {
        "published": "2026-07-30T23:16:52.597",
        "lastModified": "2026-07-31T16:17:09.443",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65421",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MMS BER decoder trusts an attacker-supplied fixed-width field length and reads past the end of its heap buffer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 278,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65423",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T15:02:47.797Z",
      "date_published": "2026-07-30T21:59:06.093Z",
      "date_updated": "2026-07-31T15:47:55.815Z",
      "publisher": "icscert",
      "title": "o6 Automation open62541 Integer Overflow or Wraparound",
      "affected": {
        "vendors": [
          "o6 Automation"
        ],
        "products": [
          {
            "vendor": "o6 Automation",
            "product": "open62541"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00605,
        "percentile": 0.45555
      },
      "nvd": {
        "published": "2026-07-30T23:16:52.743",
        "lastModified": "2026-07-31T16:17:09.560",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65423",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The open62541 path performs attacker-influenced integer arithmetic that can overflow and invalidate a later memory bound.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.o6-automation.com/contact",
          "host": "www.o6-automation.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-08.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 151,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-65430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T07:06:47.089Z",
      "date_published": "2026-07-23T09:10:32.150Z",
      "date_updated": "2026-07-27T13:47:43.782Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "GeoIP extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15777
      },
      "nvd": {
        "published": "2026-07-23T10:16:52.613",
        "lastModified": "2026-07-27T14:17:00.237",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65430",
        "family": "EXPOSURE_OUTPUT",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "MaxMind credentials are placed in request URLs where logs, proxies, and other observers can read them.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65431",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T07:06:47.089Z",
      "date_published": "2026-07-23T09:09:37.365Z",
      "date_updated": "2026-07-28T05:30:43.017Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Zipslip in GeoIP extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "GeoIP extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0038,
        "percentile": 0.30789
      },
      "nvd": {
        "published": "2026-07-23T10:16:52.723",
        "lastModified": "2026-07-27T17:16:39.360",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65431",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The GeoIP updater extracts archive members without validating their ZIP paths, allowing entries to escape the destination directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 186,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:52:41.029Z",
      "date_published": "2026-07-27T13:59:16.794Z",
      "date_updated": "2026-07-27T16:08:28.023Z",
      "publisher": "Patchstack",
      "title": "WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "themewant"
        ],
        "products": [
          {
            "vendor": "themewant",
            "product": "RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20157
      },
      "nvd": {
        "published": "2026-07-27T15:17:08.480",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65433",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "RT Mega Menu permits a subscriber to cross an access-control boundary, but the protected action and failing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/rt-mega-menu/vulnerability/wordpress-rt-mega-menu-mega-menu-builder-for-elementor-gutenberg-plugin-1-5-1-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 117,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:52:41.029Z",
      "date_published": "2026-07-27T13:59:17.436Z",
      "date_updated": "2026-07-27T14:58:43.451Z",
      "publisher": "Patchstack",
      "title": "WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "yoomoney"
        ],
        "products": [
          {
            "vendor": "yoomoney",
            "product": "ЮKassa для WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00355,
        "percentile": 0.28257
      },
      "nvd": {
        "published": "2026-07-27T15:17:08.620",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65434",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says a WooCommerce subscriber can receive sensitive data, while it does not identify the endpoint, field, or missing object check.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/yookassa/vulnerability/wordpress-yukassa-dlya-woocommerce-plugin-2-16-1-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 80,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:52:41.029Z",
      "date_published": "2026-07-27T13:59:18.082Z",
      "date_updated": "2026-07-27T14:59:07.324Z",
      "publisher": "Patchstack",
      "title": "WordPress Thrive Leads Version plugin <= 10.9.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Thrive Themes Coupon"
        ],
        "products": [
          {
            "vendor": "Thrive Themes Coupon",
            "product": "Thrive Leads Version"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15434
      },
      "nvd": {
        "published": "2026-07-27T15:17:08.760",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65435",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Patchstack record reports an unauthenticated protected operation but does not name the action, object, or missing capability check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/thrive-leads/vulnerability/wordpress-thrive-leads-version-plugin-10-9-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 81,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:52:41.029Z",
      "date_published": "2026-07-27T13:59:18.729Z",
      "date_updated": "2026-07-27T18:14:29.455Z",
      "publisher": "Patchstack",
      "title": "WordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerability",
      "affected": {
        "vendors": [
          "Themeum"
        ],
        "products": [
          {
            "vendor": "Themeum",
            "product": "Kirki"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00325,
        "percentile": 0.24996
      },
      "nvd": {
        "published": "2026-07-27T15:17:08.910",
        "lastModified": "2026-07-27T19:17:21.930",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65436",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected file operation accepts attacker-controlled path or link components without proving the resolved target remains in the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/kirki/vulnerability/wordpress-kirki-plugin-6-0-13-arbitrary-file-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 59,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65437",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:52:41.029Z",
      "date_published": "2026-07-27T22:44:00.867Z",
      "date_updated": "2026-07-28T13:52:02.436Z",
      "publisher": "Patchstack",
      "title": "WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 6.82 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "CleanTalk Inc"
        ],
        "products": [
          {
            "vendor": "CleanTalk Inc",
            "product": "Spam protection, AntiSpam, FireWall by CleanTalk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.0435
      },
      "nvd": {
        "published": "2026-07-27T23:16:41.540",
        "lastModified": "2026-07-28T16:19:12.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65437",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/cleantalk-spam-protect/vulnerability/wordpress-spam-protection-antispam-firewall-by-cleantalk-plugin-6-82-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65438",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:52:41.029Z",
      "date_published": "2026-07-27T22:44:01.949Z",
      "date_updated": "2026-07-28T13:35:00.094Z",
      "publisher": "Patchstack",
      "title": "WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.9 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Kofi Mokome"
        ],
        "products": [
          {
            "vendor": "Kofi Mokome",
            "product": "Message Filter for Contact Form 7"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.0435
      },
      "nvd": {
        "published": "2026-07-27T23:16:41.673",
        "lastModified": "2026-07-28T16:19:12.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65438",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/cf7-message-filter/vulnerability/wordpress-message-filter-for-contact-form-7-plugin-1-6-3-9-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 100,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65439",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:52:41.029Z",
      "date_published": "2026-07-27T22:44:02.584Z",
      "date_updated": "2026-07-28T14:54:16.153Z",
      "publisher": "Patchstack",
      "title": "WordPress Ultimate Addons for Contact Form 7 plugin <=3.5.45 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Themefic"
        ],
        "products": [
          {
            "vendor": "Themefic",
            "product": "Ultimate Addons for Contact Form 7"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.0435
      },
      "nvd": {
        "published": "2026-07-27T23:16:41.807",
        "lastModified": "2026-07-28T16:20:06.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65439",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Ultimate Addons for Contact Form 7 page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ultimate-addons-for-contact-form-7/vulnerability/wordpress-ultimate-addons-for-contact-form-7-plugin-3-5-45-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65440",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:52:41.030Z",
      "date_published": "2026-07-27T22:44:03.223Z",
      "date_updated": "2026-07-28T13:32:17.246Z",
      "publisher": "Patchstack",
      "title": "WordPress GetGenie plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Roxnor"
        ],
        "products": [
          {
            "vendor": "Roxnor",
            "product": "GetGenie"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04349
      },
      "nvd": {
        "published": "2026-07-27T23:16:41.933",
        "lastModified": "2026-07-28T16:19:12.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65440",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "GetGenie places unauthenticated input into generated web content without the encoding required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/getgenie/vulnerability/wordpress-getgenie-plugin-4-4-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 73,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65441",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:52:41.030Z",
      "date_published": "2026-07-27T22:44:03.877Z",
      "date_updated": "2026-07-28T16:07:09.463Z",
      "publisher": "Patchstack",
      "title": "WordPress GiveWP plugin <= 4.16.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Nexcess"
        ],
        "products": [
          {
            "vendor": "Nexcess",
            "product": "GiveWP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04351
      },
      "nvd": {
        "published": "2026-07-27T23:16:42.060",
        "lastModified": "2026-07-28T16:20:06.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65441",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GiveWP places unauthenticated attacker-controlled content into a browser-interpreted page without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 72,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65442",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:52:41.030Z",
      "date_published": "2026-07-27T22:44:04.517Z",
      "date_updated": "2026-07-28T13:54:28.356Z",
      "publisher": "Patchstack",
      "title": "WordPress FormCraft plugin <= 3.9.15 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "Subtle Web Inc"
        ],
        "products": [
          {
            "vendor": "Subtle Web Inc",
            "product": "FormCraft"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00159,
        "percentile": 0.05566
      },
      "nvd": {
        "published": "2026-07-27T23:16:42.207",
        "lastModified": "2026-07-28T16:19:12.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65442",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated FormCraft request can choose a server-side request destination outside the intended trust boundary, although the input field is not public.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/formcraft/vulnerability/wordpress-formcraft-plugin-3-9-15-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65443",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:04.434Z",
      "date_published": "2026-07-27T22:44:05.155Z",
      "date_updated": "2026-07-28T13:52:36.711Z",
      "publisher": "Patchstack",
      "title": "WordPress BackWPup  plugin <= 5.7.4 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WP Media"
        ],
        "products": [
          {
            "vendor": "WP Media",
            "product": "BackWPup"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04352
      },
      "nvd": {
        "published": "2026-07-27T23:16:42.330",
        "lastModified": "2026-07-28T16:19:12.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65443",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The BackWPup page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/backwpup/vulnerability/wordpress-backwpup-plugin-5-7-4-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 74,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:04.434Z",
      "date_published": "2026-07-27T22:44:05.796Z",
      "date_updated": "2026-07-28T13:33:21.768Z",
      "publisher": "Patchstack",
      "title": "WordPress Ad Invalid Click Protector (AICP) plugin <= 1.3.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "iSaumya"
        ],
        "products": [
          {
            "vendor": "iSaumya",
            "product": "Ad Invalid Click Protector (AICP)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09572
      },
      "nvd": {
        "published": "2026-07-27T23:16:42.460",
        "lastModified": "2026-07-28T16:19:12.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65445",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "AICP exposes an unauthenticated operation, but the public record does not identify the protected resource or missing check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ad-invalid-click-protector/vulnerability/wordpress-ad-invalid-click-protector-aicp-plugin-1-3-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65446",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:04.434Z",
      "date_published": "2026-07-27T22:44:06.432Z",
      "date_updated": "2026-07-28T14:54:09.482Z",
      "publisher": "Patchstack",
      "title": "WordPress Kali Forms plugin <= 2.4.18 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WP Chill"
        ],
        "products": [
          {
            "vendor": "WP Chill",
            "product": "Kali Forms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04344
      },
      "nvd": {
        "published": "2026-07-27T23:16:42.590",
        "lastModified": "2026-07-28T16:20:07.700",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65446",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In Kali Forms, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/kali-forms/vulnerability/wordpress-kali-forms-plugin-2-4-18-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 76,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65447",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:04.434Z",
      "date_published": "2026-07-27T22:44:07.069Z",
      "date_updated": "2026-07-28T13:31:41.593Z",
      "publisher": "Patchstack",
      "title": "WordPress Contest Gallery plugin <= 30.0.6 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Wasiliy Strecker / ContestGallery developer"
        ],
        "products": [
          {
            "vendor": "Wasiliy Strecker / ContestGallery developer",
            "product": "Contest Gallery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00146,
        "percentile": 0.04345
      },
      "nvd": {
        "published": "2026-07-27T23:16:42.720",
        "lastModified": "2026-07-28T16:19:12.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65447",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Contest Gallery places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/contest-gallery/vulnerability/wordpress-contest-gallery-plugin-30-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 81,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:04.434Z",
      "date_published": "2026-07-27T22:44:07.710Z",
      "date_updated": "2026-07-28T16:07:25.050Z",
      "publisher": "Patchstack",
      "title": "WordPress Anti Spam and list cleaner – AcyChecker plugin <= 1.8.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "AcyMailing Newsletter Team"
        ],
        "products": [
          {
            "vendor": "AcyMailing Newsletter Team",
            "product": "Anti Spam and list cleaner &#8211; AcyChecker"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03054
      },
      "nvd": {
        "published": "2026-07-27T23:16:42.850",
        "lastModified": "2026-07-28T16:20:08.387",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65448",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AcyChecker renders unauthenticated input into a browser-interpreted page without sufficient contextual neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/acychecker/vulnerability/wordpress-anti-spam-and-list-cleaner-acychecker-plugin-1-8-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 110,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65449",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:04.434Z",
      "date_published": "2026-07-23T11:18:33.123Z",
      "date_updated": "2026-07-23T14:52:16.480Z",
      "publisher": "Patchstack",
      "title": "WordPress MapSVG plugin <= 8.14.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "RomanCode"
        ],
        "products": [
          {
            "vendor": "RomanCode",
            "product": "MapSVG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05715
      },
      "nvd": {
        "published": "2026-07-23T12:18:37.230",
        "lastModified": "2026-07-23T15:17:53.107",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65449",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MapSVG renders attacker-controlled content without the required HTML sanitization or output escaping, allowing cross-site scripting.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mapsvg-lite-interactive-vector-maps/vulnerability/wordpress-mapsvg-plugin-8-14-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 68,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65450",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:04.434Z",
      "date_published": "2026-07-23T11:18:33.759Z",
      "date_updated": "2026-07-23T13:29:51.219Z",
      "publisher": "Patchstack",
      "title": "WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "RomanCode"
        ],
        "products": [
          {
            "vendor": "RomanCode",
            "product": "MapSVG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17656
      },
      "nvd": {
        "published": "2026-07-23T12:18:37.350",
        "lastModified": "2026-07-23T14:17:47.530",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65450",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected query treats attacker-controlled input as SQL syntax instead of binding it as data.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mapsvg-lite-interactive-vector-maps/vulnerability/wordpress-mapsvg-plugin-8-14-0-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 55,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65451",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:04.434Z",
      "date_published": "2026-07-23T11:18:34.387Z",
      "date_updated": "2026-07-23T13:46:15.520Z",
      "publisher": "Patchstack",
      "title": "WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "RomanCode"
        ],
        "products": [
          {
            "vendor": "RomanCode",
            "product": "MapSVG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17654
      },
      "nvd": {
        "published": "2026-07-23T12:18:37.467",
        "lastModified": "2026-07-23T14:17:47.953",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65451",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "MapSVG allows a contributor-controlled value to alter the structure of an SQL query.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mapsvg/vulnerability/wordpress-mapsvg-plugin-8-14-0-sql-injection-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 55,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65452",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:04.434Z",
      "date_published": "2026-07-23T11:18:35.032Z",
      "date_updated": "2026-07-23T14:48:39.833Z",
      "publisher": "Patchstack",
      "title": "WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "motov.net"
        ],
        "products": [
          {
            "vendor": "motov.net",
            "product": "Ebook Store"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13612
      },
      "nvd": {
        "published": "2026-07-23T12:18:37.590",
        "lastModified": "2026-07-23T15:17:54.827",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65452",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Ebook Store exposes a protected operation to an unauthenticated caller, while the affected object and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ebook-store/vulnerability/wordpress-ebook-store-plugin-6-19-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 70,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65453",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:17.416Z",
      "date_published": "2026-07-23T11:18:35.652Z",
      "date_updated": "2026-07-23T14:35:12.530Z",
      "publisher": "Patchstack",
      "title": "WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "motov.net"
        ],
        "products": [
          {
            "vendor": "motov.net",
            "product": "Ebook Store"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.1186
      },
      "nvd": {
        "published": "2026-07-23T12:18:37.710",
        "lastModified": "2026-07-23T15:17:55.430",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65453",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ebook-store/vulnerability/wordpress-ebook-store-plugin-6-19-broken-access-control-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 70,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65454",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:17.417Z",
      "date_published": "2026-07-23T11:18:36.289Z",
      "date_updated": "2026-07-23T15:58:40.224Z",
      "publisher": "Patchstack",
      "title": "WordPress Quiz And Survey Master plugin <= 11.2.0 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "ExpressTech Systems"
        ],
        "products": [
          {
            "vendor": "ExpressTech Systems",
            "product": "Quiz And Survey Master"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17654
      },
      "nvd": {
        "published": "2026-07-23T12:18:37.827",
        "lastModified": "2026-07-23T16:17:50.400",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65454",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/quiz-master-next/vulnerability/wordpress-quiz-and-survey-master-plugin-11-2-0-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 71,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65455",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:17.417Z",
      "date_published": "2026-07-23T11:18:36.950Z",
      "date_updated": "2026-07-23T14:52:08.214Z",
      "publisher": "Patchstack",
      "title": "WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability",
      "affected": {
        "vendors": [
          "MapSVG"
        ],
        "products": [
          {
            "vendor": "MapSVG",
            "product": "MapSVG"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00367,
        "percentile": 0.29426
      },
      "nvd": {
        "published": "2026-07-23T12:18:37.950",
        "lastModified": "2026-07-23T15:17:56.303",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65455",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The upload path accepts attacker-controlled file content or names without enforcing the intended storage and executable-content boundary.",
        "basis": [
          "CNA",
          "CWE-434",
          "https://patchstack.com/database/wordpress/plugin/mapsvg-lite-interactive-vector-maps/vulnerability/wordpress-mapsvg-plugin-8-14-0-arbitrary-file-upload-vulnerability?_s_id=cve"
        ],
        "deepDive": true,
        "notes": "Reviewed https://patchstack.com/database/wordpress/plugin/mapsvg-lite-interactive-vector-maps/vulnerability/wordpress-mapsvg-plugin-8-14-0-arbitrary-file-upload-vulnerability?_s_id=cve. The linked Patchstack entry was not publicly readable through the review client, and the CVE record does not identify the upload handler or missing file-type check."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mapsvg-lite-interactive-vector-maps/vulnerability/wordpress-mapsvg-plugin-8-14-0-arbitrary-file-upload-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 65,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65456",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:17.417Z",
      "date_published": "2026-07-23T11:18:37.593Z",
      "date_updated": "2026-07-23T13:30:15.810Z",
      "publisher": "Patchstack",
      "title": "WordPress Product Slider for WooCommerce plugin <= 1.13.62 - Insecure Direct Object References (IDOR) vulnerability",
      "affected": {
        "vendors": [
          "PickPlugins"
        ],
        "products": [
          {
            "vendor": "PickPlugins",
            "product": "Product Slider for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09641
      },
      "nvd": {
        "published": "2026-07-23T12:18:38.067",
        "lastModified": "2026-07-23T14:17:48.383",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65456",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The operation accepts a caller-supplied object identifier without binding the selected object to the authenticated caller.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-products-slider/vulnerability/wordpress-product-slider-for-woocommerce-plugin-1-13-62-insecure-direct-object-references-idor-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65457",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:17.417Z",
      "date_published": "2026-07-23T11:18:38.242Z",
      "date_updated": "2026-07-23T13:45:53.390Z",
      "publisher": "Patchstack",
      "title": "WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "yoomoney"
        ],
        "products": [
          {
            "vendor": "yoomoney",
            "product": "ЮKassa для WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00243,
        "percentile": 0.15605
      },
      "nvd": {
        "published": "2026-07-23T12:18:38.203",
        "lastModified": "2026-07-23T14:17:48.863",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65457",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/yookassa/vulnerability/wordpress-yukassa-dlya-woocommerce-plugin-2-16-1-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 78,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65458",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:17.417Z",
      "date_published": "2026-07-23T11:18:38.882Z",
      "date_updated": "2026-07-23T14:47:10.605Z",
      "publisher": "Patchstack",
      "title": "WordPress Polylang plugin <= 3.8.5 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Chouby"
        ],
        "products": [
          {
            "vendor": "Chouby",
            "product": "Polylang"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.11923
      },
      "nvd": {
        "published": "2026-07-23T12:18:38.357",
        "lastModified": "2026-07-23T15:17:56.947",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65458",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Polylang exposes sensitive system information to a contributor, but the record does not identify the data or output surface.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/polylang/vulnerability/wordpress-polylang-plugin-3-8-5-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 66,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65460",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:17.417Z",
      "date_published": "2026-07-23T11:18:39.523Z",
      "date_updated": "2026-07-23T14:35:52.112Z",
      "publisher": "Patchstack",
      "title": "WordPress Zarinpal Gateway plugin <= 5.1.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "zarinpal"
        ],
        "products": [
          {
            "vendor": "zarinpal",
            "product": "Zarinpal Gateway"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00107,
        "percentile": 0.01334
      },
      "nvd": {
        "published": "2026-07-23T12:18:38.483",
        "lastModified": "2026-07-23T15:17:57.520",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65460",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A Zarinpal state-changing action trusts a cross-site browser request, but the affected action and missing anti-CSRF binding are not public.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/zarinpal-woocommerce-payment-gateway/vulnerability/wordpress-zarinpal-gateway-plugin-5-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 88,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65461",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:17.417Z",
      "date_published": "2026-07-23T11:18:40.167Z",
      "date_updated": "2026-07-23T15:58:22.142Z",
      "publisher": "Patchstack",
      "title": "WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vulnerability",
      "affected": {
        "vendors": [
          "Webの相談所"
        ],
        "products": [
          {
            "vendor": "Webの相談所",
            "product": "Really Simple CSV Importer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00367,
        "percentile": 0.29426
      },
      "nvd": {
        "published": "2026-07-23T12:18:38.610",
        "lastModified": "2026-07-23T16:17:50.500",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65461",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path accepts a dangerous file type or destination beyond the intended file namespace.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/really-simple-csv-importer/vulnerability/wordpress-really-simple-csv-importer-plugin-1-3-arbitrary-file-upload-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65462",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:17.417Z",
      "date_published": "2026-07-23T11:18:40.815Z",
      "date_updated": "2026-07-23T14:51:57.770Z",
      "publisher": "Patchstack",
      "title": "WordPress Uncanny Automator plugin <= 7.3.2 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Uncanny Owl"
        ],
        "products": [
          {
            "vendor": "Uncanny Owl",
            "product": "Uncanny Automator"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00279,
        "percentile": 0.20116
      },
      "nvd": {
        "published": "2026-07-23T12:18:38.730",
        "lastModified": "2026-07-23T15:17:58.053",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65462",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An administrator-controlled Uncanny Automator value reaches an SQL query without separating data from SQL syntax.",
        "basis": [
          "CNA record",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/uncanny-automator/vulnerability/wordpress-uncanny-automator-plugin-7-3-2-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 67,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65463",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:23.246Z",
      "date_published": "2026-07-23T11:18:41.468Z",
      "date_updated": "2026-07-23T13:29:30.902Z",
      "publisher": "Patchstack",
      "title": "WordPress Masteriyo - LMS plugin <= 2.3.1 - Insecure Direct Object References (IDOR) vulnerability",
      "affected": {
        "vendors": [
          "masteriyo"
        ],
        "products": [
          {
            "vendor": "masteriyo",
            "product": "Masteriyo - LMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.20962
      },
      "nvd": {
        "published": "2026-07-23T12:18:38.850",
        "lastModified": "2026-07-23T14:17:49.290",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65463",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Masteriyo - LMS trusts an attacker-supplied object identifier without checking that the object belongs to the caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/learning-management-system/vulnerability/wordpress-masteriyo-lms-plugin-2-3-1-insecure-direct-object-references-idor-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 89,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65464",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:23.246Z",
      "date_published": "2026-07-23T11:18:42.106Z",
      "date_updated": "2026-07-23T13:41:23.004Z",
      "publisher": "Patchstack",
      "title": "WordPress GiveWP plugin <= 4.16.3 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "Nexcess"
        ],
        "products": [
          {
            "vendor": "Nexcess",
            "product": "GiveWP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00104,
        "percentile": 0.01194
      },
      "nvd": {
        "published": "2026-07-23T12:18:38.970",
        "lastModified": "2026-07-23T14:17:49.713",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65464",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "GiveWP accepts a state-changing request sent cross-site under the victim's browser credentials.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 79,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65465",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:23.246Z",
      "date_published": "2026-07-23T11:18:42.738Z",
      "date_updated": "2026-07-23T14:45:22.492Z",
      "publisher": "Patchstack",
      "title": "WordPress JetElements For Elementor plugin <= 2.9.1.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Crocoblock. Jetimpex Inc."
        ],
        "products": [
          {
            "vendor": "Crocoblock. Jetimpex Inc.",
            "product": "JetElements For Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05714
      },
      "nvd": {
        "published": "2026-07-23T12:18:39.090",
        "lastModified": "2026-07-23T15:17:58.543",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65465",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In JetElements For Elementor, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/jet-elements/vulnerability/wordpress-jetelements-for-elementor-plugin-2-9-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 88,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65466",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:23.246Z",
      "date_published": "2026-07-23T11:18:43.365Z",
      "date_updated": "2026-07-23T14:39:49.472Z",
      "publisher": "Patchstack",
      "title": "WordPress JetBooking plugin <= 4.1.2 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "Crocoblock. Jetimpex Inc."
        ],
        "products": [
          {
            "vendor": "Crocoblock. Jetimpex Inc.",
            "product": "JetBooking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04838
      },
      "nvd": {
        "published": "2026-07-23T12:18:39.220",
        "lastModified": "2026-07-23T15:17:59.037",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65466",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server follows an attacker-controlled outbound URL without constraining its destination to the intended remote service.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/jet-booking/vulnerability/wordpress-jetbooking-plugin-4-1-2-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 79,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65467",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:23.246Z",
      "date_published": "2026-07-23T11:18:44.003Z",
      "date_updated": "2026-07-23T15:57:57.723Z",
      "publisher": "Patchstack",
      "title": "WordPress JetEngine plugin <= 3.8.11 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "Crocoblock. Jetimpex Inc."
        ],
        "products": [
          {
            "vendor": "Crocoblock. Jetimpex Inc.",
            "product": "JetEngine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04271
      },
      "nvd": {
        "published": "2026-07-23T12:18:39.347",
        "lastModified": "2026-07-23T16:17:50.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65467",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "JetEngine lets a contributor direct a server-side fetch to a destination outside the intended network trust boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/jet-engine/vulnerability/wordpress-jetengine-plugin-3-8-11-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 79,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65468",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:23.247Z",
      "date_published": "2026-07-23T11:18:44.638Z",
      "date_updated": "2026-07-23T14:51:48.962Z",
      "publisher": "Patchstack",
      "title": "WordPress JetBooking plugin <= 4.1.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Crocoblock. Jetimpex Inc."
        ],
        "products": [
          {
            "vendor": "Crocoblock. Jetimpex Inc.",
            "product": "JetBooking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11855
      },
      "nvd": {
        "published": "2026-07-23T12:18:39.470",
        "lastModified": "2026-07-23T15:17:59.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65468",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Patchstack record reports unauthenticated broken access control in JetBooking but does not identify the handler, protected object, or omitted gate.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/jet-booking/vulnerability/wordpress-jetbooking-plugin-4-1-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 70,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65469",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:23.247Z",
      "date_published": "2026-07-23T11:18:45.293Z",
      "date_updated": "2026-07-23T13:29:09.929Z",
      "publisher": "Patchstack",
      "title": "WordPress AWP Classifieds plugin <= 4.4.7 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Strategy11 Team"
        ],
        "products": [
          {
            "vendor": "Strategy11 Team",
            "product": "AWP Classifieds"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11853
      },
      "nvd": {
        "published": "2026-07-23T12:18:39.600",
        "lastModified": "2026-07-23T14:17:50.140",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65469",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A protected action is reachable without sufficient authorization, but the public record does not identify the missing check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/another-wordpress-classifieds-plugin/vulnerability/wordpress-awp-classifieds-plugin-4-4-7-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65470",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:23.247Z",
      "date_published": "2026-07-23T11:18:45.941Z",
      "date_updated": "2026-07-23T13:43:37.316Z",
      "publisher": "Patchstack",
      "title": "WordPress Fluent Support plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WPManageNinja"
        ],
        "products": [
          {
            "vendor": "WPManageNinja",
            "product": "Fluent Support"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05712
      },
      "nvd": {
        "published": "2026-07-23T12:18:39.723",
        "lastModified": "2026-07-23T14:17:50.573",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65470",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Fluent Support rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/fluent-support/vulnerability/wordpress-fluent-support-plugin-2-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65471",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:23.247Z",
      "date_published": "2026-07-23T11:18:46.575Z",
      "date_updated": "2026-07-23T14:33:46.791Z",
      "publisher": "Patchstack",
      "title": "WordPress Avada Core plugin <= 5.15.6 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "Avada Studio"
        ],
        "products": [
          {
            "vendor": "Avada Studio",
            "product": "Avada Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04039
      },
      "nvd": {
        "published": "2026-07-23T12:18:39.857",
        "lastModified": "2026-07-23T15:18:00.250",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65471",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A cross-site request can cause Avada Core to perform an unspecified action under the victim's session because the required request-verification boundary is absent.",
        "basis": [
          "CNA",
          "CWE-352",
          "Avada Core security update"
        ],
        "deepDive": true,
        "notes": "Inspected https://avada.com/blog/avada-core-security-update/; Avada confirms that versions through 5.15.6 are affected and 5.15.7 is the standalone fix, but does not identify the state-changing action, request-verification check, or code path."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/fusion-core/vulnerability/wordpress-avada-core-plugin-5-15-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65472",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:23.247Z",
      "date_published": "2026-07-23T11:18:47.217Z",
      "date_updated": "2026-07-23T14:40:21.477Z",
      "publisher": "Patchstack",
      "title": "WordPress Kit (formerly ConvertKit) plugin <= 3.3.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Kit"
        ],
        "products": [
          {
            "vendor": "Kit",
            "product": "Kit (formerly ConvertKit)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11852
      },
      "nvd": {
        "published": "2026-07-23T12:18:39.980",
        "lastModified": "2026-07-23T15:18:00.893",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65472",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says Kit exposes a protected operation without authentication, while it does not identify the endpoint or credential decision.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/convertkit/vulnerability/wordpress-kit-formerly-convertkit-plugin-3-3-5-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 85,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65473",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:30.833Z",
      "date_published": "2026-07-23T11:18:47.853Z",
      "date_updated": "2026-07-23T15:57:44.103Z",
      "publisher": "Patchstack",
      "title": "WordPress Virtue/Ascend/Pinnacle Toolkit plugin <= 4.9.12 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Nexcess"
        ],
        "products": [
          {
            "vendor": "Nexcess",
            "product": "Virtue/Ascend/Pinnacle Toolkit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00171,
        "percentile": 0.06726
      },
      "nvd": {
        "published": "2026-07-23T12:18:40.110",
        "lastModified": "2026-07-23T16:17:50.700",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65473",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Virtue, Ascend, or Pinnacle Toolkit renders contributor-controlled input as active HTML or script without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/virtue-toolkit/vulnerability/wordpress-virtue-ascend-pinnacle-toolkit-plugin-4-9-12-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 92,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65474",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:30.833Z",
      "date_published": "2026-07-23T11:18:48.491Z",
      "date_updated": "2026-07-23T14:51:38.883Z",
      "publisher": "Patchstack",
      "title": "WordPress Ninja Tables plugin <= 5.2.10 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "WPManageNinja"
        ],
        "products": [
          {
            "vendor": "WPManageNinja",
            "product": "Ninja Tables"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15215
      },
      "nvd": {
        "published": "2026-07-23T12:18:40.230",
        "lastModified": "2026-07-23T15:18:01.420",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65474",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected response, log, or client-visible object emits sensitive data without the required redaction or audience restriction.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ninja-tables/vulnerability/wordpress-ninja-tables-plugin-5-2-10-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65475",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:30.834Z",
      "date_published": "2026-07-23T11:53:14.158Z",
      "date_updated": "2026-07-23T15:47:33.645Z",
      "publisher": "Patchstack",
      "title": "WordPress Modula Image Gallery plugin 2.14.25-2.14.30 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WP Chill"
        ],
        "products": [
          {
            "vendor": "WP Chill",
            "product": "Modula Image Gallery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03054
      },
      "nvd": {
        "published": "2026-07-23T12:18:40.350",
        "lastModified": "2026-07-23T16:17:50.797",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65475",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/modula-best-grid-gallery/vulnerability/wordpress-modula-image-gallery-plugin-2-14-25-2-14-30-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:30.834Z",
      "date_published": "2026-07-23T11:18:49.155Z",
      "date_updated": "2026-07-23T13:40:00.430Z",
      "publisher": "Patchstack",
      "title": "WordPress Civi theme <= 2.2.4 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "uxper"
        ],
        "products": [
          {
            "vendor": "uxper",
            "product": "Civi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11852
      },
      "nvd": {
        "published": "2026-07-23T12:18:40.470",
        "lastModified": "2026-07-23T14:17:51.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65476",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/civi/vulnerability/wordpress-civi-theme-2-2-4-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 64,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65477",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:30.834Z",
      "date_published": "2026-07-23T11:18:49.794Z",
      "date_updated": "2026-07-23T13:43:06.979Z",
      "publisher": "Patchstack",
      "title": "WordPress Tonda Core plugin <= 2.1.2 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "Select-Themes"
        ],
        "products": [
          {
            "vendor": "Select-Themes",
            "product": "Tonda Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24377
      },
      "nvd": {
        "published": "2026-07-23T12:18:40.593",
        "lastModified": "2026-07-23T14:17:51.477",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65477",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Tonda Core lets a caller influence the PHP file selected by an include operation outside the intended template set.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/tonda-core/vulnerability/wordpress-tonda-core-plugin-2-1-2-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 65,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65478",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:30.834Z",
      "date_published": "2026-07-23T11:18:50.446Z",
      "date_updated": "2026-07-23T14:32:40.795Z",
      "publisher": "Patchstack",
      "title": "WordPress ListingPro plugin <= 2.9.10 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "CridioStudio"
        ],
        "products": [
          {
            "vendor": "CridioStudio",
            "product": "ListingPro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0022,
        "percentile": 0.12656
      },
      "nvd": {
        "published": "2026-07-23T12:18:40.707",
        "lastModified": "2026-07-23T15:18:01.967",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65478",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A subscriber can perform a ListingPro operation outside the intended role, but the affected object and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/listingpro-plugin/vulnerability/wordpress-listingpro-plugin-2-9-10-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 66,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65479",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:30.834Z",
      "date_published": "2026-07-23T11:18:51.090Z",
      "date_updated": "2026-07-23T15:04:51.859Z",
      "publisher": "Patchstack",
      "title": "WordPress Reviewer plugin <= 3.14.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "MVP Themes"
        ],
        "products": [
          {
            "vendor": "MVP Themes",
            "product": "Reviewer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00275,
        "percentile": 0.1967
      },
      "nvd": {
        "published": "2026-07-23T12:18:40.830",
        "lastModified": "2026-07-23T16:17:50.900",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65479",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Reviewer lets a subscriber perform an operation beyond that role's authority, but the object, action, and failed check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/reviewer/vulnerability/wordpress-reviewer-plugin-3-14-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 64,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65480",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:30.834Z",
      "date_published": "2026-07-23T11:18:51.737Z",
      "date_updated": "2026-07-23T15:57:26.561Z",
      "publisher": "Patchstack",
      "title": "WordPress TheGem theme <= 5.11.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "CodexThemes"
        ],
        "products": [
          {
            "vendor": "CodexThemes",
            "product": "TheGem"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05712
      },
      "nvd": {
        "published": "2026-07-23T12:18:40.973",
        "lastModified": "2026-07-23T16:17:51.007",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65480",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Contributor-controlled theme content is rendered as executable browser markup without sufficient context separation, although the affected field is not public.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/thegem/vulnerability/wordpress-thegem-theme-5-11-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 68,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65481",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:30.834Z",
      "date_published": "2026-07-23T11:18:52.377Z",
      "date_updated": "2026-07-23T14:51:28.879Z",
      "publisher": "Patchstack",
      "title": "WordPress Vino theme <= 1.9 - Local File Inclusion vulnerability",
      "affected": {
        "vendors": [
          "Elated-Themes"
        ],
        "products": [
          {
            "vendor": "Elated-Themes",
            "product": "Vino"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-98",
          "name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24377
      },
      "nvd": {
        "published": "2026-07-23T12:18:41.100",
        "lastModified": "2026-07-23T15:18:02.513",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65481",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Vino include path lets an attacker select a local file outside the intended include namespace.",
        "basis": [
          "CNA",
          "CWE-98"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/vino/vulnerability/wordpress-vino-theme-1-9-local-file-inclusion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 57,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65482",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:30.834Z",
      "date_published": "2026-07-23T11:18:53.013Z",
      "date_updated": "2026-07-23T13:28:48.738Z",
      "publisher": "Patchstack",
      "title": "WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "LA-Studio"
        ],
        "products": [
          {
            "vendor": "LA-Studio",
            "product": "LA-Studio Element Kit for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.0572
      },
      "nvd": {
        "published": "2026-07-23T12:18:41.220",
        "lastModified": "2026-07-23T14:17:51.903",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65482",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LA-Studio Element Kit lets contributor input reach generated page markup without sufficient browser-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/lastudio-element-kit/vulnerability/wordpress-la-studio-element-kit-for-elementor-plugin-1-6-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65483",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:35.326Z",
      "date_published": "2026-07-23T11:18:53.649Z",
      "date_updated": "2026-07-23T13:42:43.335Z",
      "publisher": "Patchstack",
      "title": "WordPress HashThemes Demo Importer plugin <= 1.4.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "hashthemes"
        ],
        "products": [
          {
            "vendor": "hashthemes",
            "product": "HashThemes Demo Importer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06854
      },
      "nvd": {
        "published": "2026-07-23T12:18:41.347",
        "lastModified": "2026-07-23T14:17:52.327",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65483",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "In HashThemes Demo Importer, attacker-controlled markup is rendered without the required HTML-context sanitization or output escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/hashthemes-demo-importer/vulnerability/wordpress-hashthemes-demo-importer-plugin-1-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 80,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65484",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:35.326Z",
      "date_published": "2026-07-23T11:18:54.280Z",
      "date_updated": "2026-07-23T14:42:47.774Z",
      "publisher": "Patchstack",
      "title": "WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "AnalogWP"
        ],
        "products": [
          {
            "vendor": "AnalogWP",
            "product": "Style Kits"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00198,
        "percentile": 0.09793
      },
      "nvd": {
        "published": "2026-07-23T12:18:41.470",
        "lastModified": "2026-07-23T15:18:03.603",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65484",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Style Kits fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/analogwp-templates/vulnerability/wordpress-style-kits-plugin-2-6-5-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 66,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65485",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:35.327Z",
      "date_published": "2026-07-23T11:18:54.913Z",
      "date_updated": "2026-07-23T15:06:40.370Z",
      "publisher": "Patchstack",
      "title": "WordPress Content Control plugin <= 2.6.5 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Daniel Iser"
        ],
        "products": [
          {
            "vendor": "Daniel Iser",
            "product": "Content Control"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13609
      },
      "nvd": {
        "published": "2026-07-23T12:18:41.590",
        "lastModified": "2026-07-23T16:17:51.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65485",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Content Control exposes an action without authenticating or authorizing the caller, while the exact object and endpoint are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/content-control/vulnerability/wordpress-content-control-plugin-2-6-5-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65486",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:35.327Z",
      "date_published": "2026-07-23T11:18:55.544Z",
      "date_updated": "2026-07-23T15:57:06.027Z",
      "publisher": "Patchstack",
      "title": "WordPress Event post plugin <= 6.0.1 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Bastien Ho"
        ],
        "products": [
          {
            "vendor": "Bastien Ho",
            "product": "Event post"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.1361
      },
      "nvd": {
        "published": "2026-07-23T12:18:41.713",
        "lastModified": "2026-07-23T16:17:51.210",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65486",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies an authentication or authorization bypass in Event post, but does not disclose the operation or failing identity, role, or object-scope check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/event-post/vulnerability/wordpress-event-post-plugin-6-0-1-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 70,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65487",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:35.327Z",
      "date_published": "2026-07-23T11:18:56.183Z",
      "date_updated": "2026-07-23T14:51:19.862Z",
      "publisher": "Patchstack",
      "title": "WordPress Photography theme <= 7.7.6 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "ThemeGoods"
        ],
        "products": [
          {
            "vendor": "ThemeGoods",
            "product": "Photography"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11852
      },
      "nvd": {
        "published": "2026-07-23T12:18:41.823",
        "lastModified": "2026-07-23T15:18:05.490",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65487",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated request reaches a protected operation without the required access-control check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/photography/vulnerability/wordpress-photography-theme-7-7-6-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 71,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:35.327Z",
      "date_published": "2026-07-23T11:18:56.816Z",
      "date_updated": "2026-07-23T13:28:27.843Z",
      "publisher": "Patchstack",
      "title": "WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability",
      "affected": {
        "vendors": [
          "LA-Studio"
        ],
        "products": [
          {
            "vendor": "LA-Studio",
            "product": "LA-Studio Element Kit for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00097,
        "percentile": 0.0088
      },
      "nvd": {
        "published": "2026-07-23T12:18:41.943",
        "lastModified": "2026-07-23T14:17:52.750",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65488",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Elementor extension accepts a cross-site state-changing request, while the public record does not identify the endpoint or missing request-binding control.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/lastudio-element-kit/vulnerability/wordpress-la-studio-element-kit-for-elementor-plugin-1-6-2-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 107,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:35.327Z",
      "date_published": "2026-07-23T11:18:57.444Z",
      "date_updated": "2026-07-23T13:42:22.886Z",
      "publisher": "Patchstack",
      "title": "WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "LA-Studio"
        ],
        "products": [
          {
            "vendor": "LA-Studio",
            "product": "LA-Studio Element Kit for Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13613
      },
      "nvd": {
        "published": "2026-07-23T12:18:42.067",
        "lastModified": "2026-07-23T14:17:53.173",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65489",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "LA-Studio Element Kit exposes a protected operation to an unauthenticated caller, while the affected object and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/lastudio-element-kit/vulnerability/wordpress-la-studio-element-kit-for-elementor-plugin-1-6-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 95,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:35.327Z",
      "date_published": "2026-07-23T11:18:58.080Z",
      "date_updated": "2026-07-23T14:37:44.167Z",
      "publisher": "Patchstack",
      "title": "WordPress Create by Mediavine plugin <= 2.5.3 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "mischiefmarmot"
        ],
        "products": [
          {
            "vendor": "mischiefmarmot",
            "product": "Create by Mediavine"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.16531
      },
      "nvd": {
        "published": "2026-07-23T12:18:42.187",
        "lastModified": "2026-07-23T15:18:06.230",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65490",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mediavine-create/vulnerability/wordpress-create-by-mediavine-plugin-2-5-3-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 81,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65491",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:35.327Z",
      "date_published": "2026-07-23T11:18:58.714Z",
      "date_updated": "2026-07-23T15:07:19.770Z",
      "publisher": "Patchstack",
      "title": "WordPress Query Wrangler plugin <= 1.5.57 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Jonathan Daggerhart"
        ],
        "products": [
          {
            "vendor": "Jonathan Daggerhart",
            "product": "Query Wrangler"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00259,
        "percentile": 0.17475
      },
      "nvd": {
        "published": "2026-07-23T12:18:42.313",
        "lastModified": "2026-07-23T16:17:51.307",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65491",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Query Wrangler record identifies subscriber-level access to a protected operation but does not name that operation or the missing capability check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/query-wrangler/vulnerability/wordpress-query-wrangler-plugin-1-5-57-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 70,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65492",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:35.327Z",
      "date_published": "2026-07-23T11:18:59.356Z",
      "date_updated": "2026-07-23T15:56:46.675Z",
      "publisher": "Patchstack",
      "title": "WordPress Dokan Pro plugin <= 5.0.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Dokan WordPress Plugin"
        ],
        "products": [
          {
            "vendor": "Dokan WordPress Plugin",
            "product": "Dokan Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07759
      },
      "nvd": {
        "published": "2026-07-23T12:18:42.430",
        "lastModified": "2026-07-23T16:17:51.417",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65492",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/dokan-pro/vulnerability/wordpress-dokan-pro-plugin-5-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 74,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65493",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:43.311Z",
      "date_published": "2026-07-23T11:18:59.986Z",
      "date_updated": "2026-07-23T14:51:07.788Z",
      "publisher": "Patchstack",
      "title": "WordPress Dokan Pro plugin <= 5.0.2 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "Dokan"
        ],
        "products": [
          {
            "vendor": "Dokan",
            "product": "Dokan Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00373,
        "percentile": 0.30046
      },
      "nvd": {
        "published": "2026-07-23T12:18:42.553",
        "lastModified": "2026-07-23T15:18:06.870",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65493",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application deserializes attacker-controlled object data without enforcing a safe type and behavior boundary.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/dokan-pro/vulnerability/wordpress-dokan-pro-plugin-5-0-2-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 63,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65494",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:43.312Z",
      "date_published": "2026-07-23T11:19:00.620Z",
      "date_updated": "2026-07-23T13:28:09.284Z",
      "publisher": "Patchstack",
      "title": "WordPress Dokan Pro plugin <= 5.0.2 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Dokan"
        ],
        "products": [
          {
            "vendor": "Dokan",
            "product": "Dokan Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00274,
        "percentile": 0.19517
      },
      "nvd": {
        "published": "2026-07-23T12:18:42.677",
        "lastModified": "2026-07-23T14:17:53.600",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65494",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected query incorporates attacker-controlled input without parameterization or context-appropriate SQL escaping.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/dokan-pro/vulnerability/wordpress-dokan-pro-plugin-5-0-2-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 56,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65495",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:43.312Z",
      "date_published": "2026-07-23T11:19:01.262Z",
      "date_updated": "2026-07-23T13:41:55.388Z",
      "publisher": "Patchstack",
      "title": "WordPress Dokan Pro plugin <= 5.0.3 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Dokan Multivendor Plugin"
        ],
        "products": [
          {
            "vendor": "Dokan Multivendor Plugin",
            "product": "Dokan Pro"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22236
      },
      "nvd": {
        "published": "2026-07-23T12:18:42.790",
        "lastModified": "2026-07-23T14:17:54.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65495",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Dokan Pro exposes an unauthenticated operation without adequate access control, but the public record does not identify the action or object.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/dokan-pro/vulnerability/wordpress-dokan-pro-plugin-5-0-3-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 69,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65496",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:43.312Z",
      "date_published": "2026-07-23T11:19:01.901Z",
      "date_updated": "2026-07-23T14:52:46.291Z",
      "publisher": "Patchstack",
      "title": "WordPress Complianz plugin <= 7.5.0 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "Complianz"
        ],
        "products": [
          {
            "vendor": "Complianz",
            "product": "Complianz"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05707
      },
      "nvd": {
        "published": "2026-07-23T12:18:42.910",
        "lastModified": "2026-07-23T15:18:07.640",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65496",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An authenticated author can make Complianz issue a server-side request to a caller-selected destination.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/complianz-gdpr/vulnerability/wordpress-complianz-plugin-7-5-0-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 73,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65497",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:43.312Z",
      "date_published": "2026-07-23T11:19:02.535Z",
      "date_updated": "2026-07-23T15:08:01.311Z",
      "publisher": "Patchstack",
      "title": "WordPress Complianz plugin <= 7.5.0 - PHP Object Injection vulnerability",
      "affected": {
        "vendors": [
          "Complianz"
        ],
        "products": [
          {
            "vendor": "Complianz",
            "product": "Complianz"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29687
      },
      "nvd": {
        "published": "2026-07-23T12:18:43.040",
        "lastModified": "2026-07-23T16:17:51.517",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65497",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Untrusted serialized data is instantiated as application objects without a safe type boundary.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/complianz-gdpr/vulnerability/wordpress-complianz-plugin-7-5-0-php-object-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 66,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65498",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:43.312Z",
      "date_published": "2026-07-23T11:19:03.170Z",
      "date_updated": "2026-07-23T15:55:57.946Z",
      "publisher": "Patchstack",
      "title": "WordPress Complianz plugin <= 7.5.0 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Complianz"
        ],
        "products": [
          {
            "vendor": "Complianz",
            "product": "Complianz"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15217
      },
      "nvd": {
        "published": "2026-07-23T12:18:43.160",
        "lastModified": "2026-07-23T16:17:51.617",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65498",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Complianz returns sensitive system information to an unauthenticated caller outside the intended control sphere.",
        "basis": [
          "CNA record",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/complianz-gdpr/vulnerability/wordpress-complianz-plugin-7-5-0-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 71,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:43.312Z",
      "date_published": "2026-07-23T11:19:03.852Z",
      "date_updated": "2026-07-23T14:50:56.515Z",
      "publisher": "Patchstack",
      "title": "WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Pepro Dev. Group"
        ],
        "products": [
          {
            "vendor": "Pepro Dev. Group",
            "product": "PeproDev Ultimate Invoice"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09323
      },
      "nvd": {
        "published": "2026-07-23T12:18:43.280",
        "lastModified": "2026-07-23T15:18:08.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65499",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows that PeproDev Ultimate Invoice permits an unauthorized operation but does not identify the endpoint, protected object, or failing identity or privilege check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/pepro-ultimate-invoice/vulnerability/wordpress-peprodev-ultimate-invoice-plugin-2-2-6-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 85,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65500",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:43.312Z",
      "date_published": "2026-07-23T11:19:04.485Z",
      "date_updated": "2026-07-23T13:27:48.081Z",
      "publisher": "Patchstack",
      "title": "WordPress Manual - Documentation, Knowledge Base & Education WordPress theme theme <= 7.5.4 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "pixelacehq"
        ],
        "products": [
          {
            "vendor": "pixelacehq",
            "product": "Manual - Documentation, Knowledge Base & Education WordPress Theme"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00287,
        "percentile": 0.2091
      },
      "nvd": {
        "published": "2026-07-23T12:18:43.397",
        "lastModified": "2026-07-23T14:17:54.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65500",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Manual theme exposes an unauthenticated action beyond public authority, but the affected action and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/manual/vulnerability/wordpress-manual-documentation-knowledge-base-education-wordpress-theme-theme-7-5-4-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 126,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:43.312Z",
      "date_published": "2026-07-23T11:19:05.175Z",
      "date_updated": "2026-07-23T13:35:22.051Z",
      "publisher": "Patchstack",
      "title": "WordPress Shiptastic for WooCommerce plugin <= 5.1.0 - Insecure Direct Object References (IDOR) vulnerability",
      "affected": {
        "vendors": [
          "vendidero"
        ],
        "products": [
          {
            "vendor": "vendidero",
            "product": "Shiptastic for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13614
      },
      "nvd": {
        "published": "2026-07-23T12:18:43.520",
        "lastModified": "2026-07-23T14:17:54.967",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65501",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Shiptastic accepts an unauthenticated caller-controlled object identifier without binding the selected object to an authorized user.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/shiptastic-for-woocommerce/vulnerability/wordpress-shiptastic-for-woocommerce-plugin-5-1-0-insecure-direct-object-references-idor-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65503",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:52.509Z",
      "date_published": "2026-07-23T11:19:05.898Z",
      "date_updated": "2026-07-23T14:06:22.698Z",
      "publisher": "Patchstack",
      "title": "WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "bdthemes"
        ],
        "products": [
          {
            "vendor": "bdthemes",
            "product": "Ultimate Store Kit Elementor Addons"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.0571
      },
      "nvd": {
        "published": "2026-07-23T12:18:43.643",
        "lastModified": "2026-07-23T15:18:08.837",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65503",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled text is placed into an HTML or script context without context-appropriate escaping, allowing browser script execution.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ultimate-store-kit/vulnerability/wordpress-ultimate-store-kit-elementor-addons-plugin-3-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65505",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:52.510Z",
      "date_published": "2026-07-23T11:19:06.553Z",
      "date_updated": "2026-07-23T15:08:47.236Z",
      "publisher": "Patchstack",
      "title": "WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "bdthemes"
        ],
        "products": [
          {
            "vendor": "bdthemes",
            "product": "Ultimate Store Kit Elementor Addons"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15218
      },
      "nvd": {
        "published": "2026-07-23T12:18:43.763",
        "lastModified": "2026-07-23T16:17:51.720",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65505",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Ultimate Store Kit exposes protected system information through an unauthenticated output path, although the exact fields are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/ultimate-store-kit/vulnerability/wordpress-ultimate-store-kit-elementor-addons-plugin-3-0-5-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65506",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:52.510Z",
      "date_published": "2026-07-23T11:19:07.185Z",
      "date_updated": "2026-07-23T16:05:10.926Z",
      "publisher": "Patchstack",
      "title": "WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.12 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "sonaar"
        ],
        "products": [
          {
            "vendor": "sonaar",
            "product": "MP3 Audio Player for Music, Radio & Podcast by Sonaar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11853
      },
      "nvd": {
        "published": "2026-07-23T12:18:43.887",
        "lastModified": "2026-07-23T16:17:51.820",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65506",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Patchstack record reports unauthenticated broken access control in MP3 Audio Player but does not identify the handler, protected object, or omitted gate.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mp3-music-player-by-sonaar/vulnerability/wordpress-mp3-audio-player-for-music-radio-podcast-by-sonaar-plugin-5-12-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 112,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65510",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:52.510Z",
      "date_published": "2026-07-23T11:19:07.828Z",
      "date_updated": "2026-07-23T14:50:44.301Z",
      "publisher": "Patchstack",
      "title": "WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Pepro Dev. Group"
        ],
        "products": [
          {
            "vendor": "Pepro Dev. Group",
            "product": "PeproDev Ultimate Invoice"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07756
      },
      "nvd": {
        "published": "2026-07-23T12:18:44.010",
        "lastModified": "2026-07-23T15:18:09.497",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65510",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input crosses into executable syntax without context-safe neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/pepro-ultimate-invoice/vulnerability/wordpress-peprodev-ultimate-invoice-plugin-2-2-6-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 90,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65511",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:52.510Z",
      "date_published": "2026-07-23T11:19:08.475Z",
      "date_updated": "2026-07-23T13:26:54.308Z",
      "publisher": "Patchstack",
      "title": "WordPress Manual - Documentation, Knowledge Base & Education WordPress Theme theme <= 7.5.4 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "pixelacehq"
        ],
        "products": [
          {
            "vendor": "pixelacehq",
            "product": "Manual - Documentation, Knowledge Base & Education WordPress Theme"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07763
      },
      "nvd": {
        "published": "2026-07-23T12:18:44.130",
        "lastModified": "2026-07-23T14:17:55.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65511",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Manual - Documentation, Knowledge Base & Education WordPress Theme rendering path places attacker-controlled data into executable browser markup without context-appropriate sanitization or escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/manual/vulnerability/wordpress-manual-documentation-knowledge-base-education-wordpress-theme-theme-7-5-4-cross-site-scripting-xss-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 131,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65512",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:53:52.510Z",
      "date_published": "2026-07-23T11:19:09.110Z",
      "date_updated": "2026-07-23T13:40:50.020Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Activity Log plugin <= 5.6.4 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "Melapress"
        ],
        "products": [
          {
            "vendor": "Melapress",
            "product": "WP Activity Log"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00104,
        "percentile": 0.01194
      },
      "nvd": {
        "published": "2026-07-23T12:18:44.253",
        "lastModified": "2026-07-23T14:17:56.357",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65512",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A cross-site request can cause WP Activity Log to perform an unspecified action under the victim's session because the required request-verification boundary is absent.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-security-audit-log/vulnerability/wordpress-wp-activity-log-plugin-5-6-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 87,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65514",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:01.673Z",
      "date_published": "2026-07-23T11:19:09.754Z",
      "date_updated": "2026-07-23T14:04:49.364Z",
      "publisher": "Patchstack",
      "title": "WordPress Appointment Hour Booking plugin <= 1.5.86 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "codepeople"
        ],
        "products": [
          {
            "vendor": "codepeople",
            "product": "Appointment Hour Booking"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05711
      },
      "nvd": {
        "published": "2026-07-23T12:18:44.383",
        "lastModified": "2026-07-23T15:18:10.253",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65514",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says attacker-controlled input reaches executable syntax in Appointment Hour Booking, while the input field and interpreter sink are not public.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/appointment-hour-booking/vulnerability/wordpress-appointment-hour-booking-plugin-1-5-86-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 86,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65516",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:01.673Z",
      "date_published": "2026-07-23T11:19:10.392Z",
      "date_updated": "2026-07-23T15:09:52.250Z",
      "publisher": "Patchstack",
      "title": "WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "Pepro Dev. Group"
        ],
        "products": [
          {
            "vendor": "Pepro Dev. Group",
            "product": "PeproDev Ultimate Invoice"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00194,
        "percentile": 0.09323
      },
      "nvd": {
        "published": "2026-07-23T12:18:44.510",
        "lastModified": "2026-07-23T16:17:51.937",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65516",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PeproDev Ultimate Invoice makes a server-side request to an unauthenticated caller-selected destination.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/pepro-ultimate-invoice/vulnerability/wordpress-peprodev-ultimate-invoice-plugin-2-2-6-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65518",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:01.673Z",
      "date_published": "2026-07-23T11:19:11.027Z",
      "date_updated": "2026-07-23T15:55:23.460Z",
      "publisher": "Patchstack",
      "title": "WordPress Accept Donations with PayPal & Stripe plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Scott Paterson"
        ],
        "products": [
          {
            "vendor": "Scott Paterson",
            "product": "Accept Donations with PayPal & Stripe"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05721
      },
      "nvd": {
        "published": "2026-07-23T12:18:44.630",
        "lastModified": "2026-07-23T16:17:52.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65518",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/easy-paypal-donation/vulnerability/wordpress-accept-donations-with-paypal-stripe-plugin-1-5-5-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 98,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65519",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:01.673Z",
      "date_published": "2026-07-23T11:19:11.667Z",
      "date_updated": "2026-07-23T14:50:33.382Z",
      "publisher": "Patchstack",
      "title": "WordPress Photo Gallery plugin <= 2.7.7.29 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "gt3themes"
        ],
        "products": [
          {
            "vendor": "gt3themes",
            "product": "Photo Gallery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.0572
      },
      "nvd": {
        "published": "2026-07-23T12:18:44.760",
        "lastModified": "2026-07-23T15:18:10.837",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65519",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/gt3-photo-video-gallery/vulnerability/wordpress-photo-gallery-plugin-2-7-7-29-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 72,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65521",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:01.673Z",
      "date_published": "2026-07-23T11:19:12.301Z",
      "date_updated": "2026-07-23T13:26:33.284Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Social Ninja plugin <= 4.3.0 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Mahmudul Hasan Arif"
        ],
        "products": [
          {
            "vendor": "Mahmudul Hasan Arif",
            "product": "WP Social Ninja"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0024,
        "percentile": 0.15217
      },
      "nvd": {
        "published": "2026-07-23T12:18:44.887",
        "lastModified": "2026-07-23T14:17:57.040",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65521",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "An unauthenticated response exposes system or application data that should remain inside the protected context.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-social-reviews/vulnerability/wordpress-wp-social-ninja-plugin-4-3-0-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 77,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65522",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:01.673Z",
      "date_published": "2026-07-23T11:19:12.937Z",
      "date_updated": "2026-07-23T13:40:24.896Z",
      "publisher": "Patchstack",
      "title": "WordPress Manual - Documentation, Knowledge Base & Education WordPress theme theme <= 7.5.4 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "pixelacehq"
        ],
        "products": [
          {
            "vendor": "pixelacehq",
            "product": "Manual - Documentation, Knowledge Base & Education WordPress Theme"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.0571
      },
      "nvd": {
        "published": "2026-07-23T12:18:45.013",
        "lastModified": "2026-07-23T14:17:57.563",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65522",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Manual - Documentation, Knowledge Base & Education WordPress Theme page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/manual/vulnerability/wordpress-manual-documentation-knowledge-base-education-wordpress-theme-theme-7-5-4-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 127,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65524",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:08.234Z",
      "date_published": "2026-07-23T11:19:13.568Z",
      "date_updated": "2026-07-23T14:07:15.288Z",
      "publisher": "Patchstack",
      "title": "WordPress Avada Custom Branding plugin <= 1.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "ThemeFusion"
        ],
        "products": [
          {
            "vendor": "ThemeFusion",
            "product": "Avada Custom Branding"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05821
      },
      "nvd": {
        "published": "2026-07-23T12:18:45.137",
        "lastModified": "2026-07-23T15:18:11.360",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65524",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A contributor can perform an Avada Custom Branding operation outside the intended role, but the affected object and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/fusion-white-label-branding/vulnerability/wordpress-avada-custom-branding-plugin-1-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65525",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:08.234Z",
      "date_published": "2026-07-23T11:19:14.202Z",
      "date_updated": "2026-07-23T15:11:16.484Z",
      "publisher": "Patchstack",
      "title": "WordPress Civi Framework plugin <= 2.2.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "uxper"
        ],
        "products": [
          {
            "vendor": "uxper",
            "product": "Civi Framework"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07311
      },
      "nvd": {
        "published": "2026-07-23T12:18:45.263",
        "lastModified": "2026-07-23T16:17:52.167",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65525",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Civi Framework exposes an operation without requiring the intended authorization, but the object, action, and failed check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/civi-framework/vulnerability/wordpress-civi-framework-plugin-2-2-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 74,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65526",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:08.234Z",
      "date_published": "2026-07-23T11:19:14.846Z",
      "date_updated": "2026-08-03T09:14:14.010Z",
      "publisher": "Patchstack",
      "title": "WordPress Visualizer plugin <= 4.0.1 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "Themeisle"
        ],
        "products": [
          {
            "vendor": "Themeisle",
            "product": "Visualizer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0026,
        "percentile": 0.17655
      },
      "nvd": {
        "published": "2026-07-23T12:18:45.393",
        "lastModified": "2026-08-03T10:16:32.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65526",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "An authenticated Visualizer value is incorporated into a SQL query without safe parameter binding, enabling blind query manipulation.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/visualizer/vulnerability/wordpress-visualizer-plugin-4-0-6-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:08.235Z",
      "date_published": "2026-07-23T11:19:15.479Z",
      "date_updated": "2026-07-23T14:50:24.030Z",
      "publisher": "Patchstack",
      "title": "WordPress LIQUID SPEECH BALLOON plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "lqd"
        ],
        "products": [
          {
            "vendor": "lqd",
            "product": "LIQUID SPEECH BALLOON"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03054
      },
      "nvd": {
        "published": "2026-07-23T12:18:45.517",
        "lastModified": "2026-07-23T15:18:11.890",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65527",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The LIQUID SPEECH BALLOON page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/liquid-speech-balloon/vulnerability/wordpress-liquid-speech-balloon-plugin-1-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65528",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:08.235Z",
      "date_published": "2026-07-23T11:19:16.111Z",
      "date_updated": "2026-07-23T13:26:07.357Z",
      "publisher": "Patchstack",
      "title": "WordPress BSK PDF Manager plugin <= 3.8 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "bannersky"
        ],
        "products": [
          {
            "vendor": "bannersky",
            "product": "BSK PDF Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03681
      },
      "nvd": {
        "published": "2026-07-23T12:18:45.640",
        "lastModified": "2026-07-23T14:17:58.047",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65528",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BSK PDF Manager lets contributor input reach generated page markup without sufficient browser-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/bsk-pdf-manager/vulnerability/wordpress-bsk-pdf-manager-plugin-3-8-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 74,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65529",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:08.235Z",
      "date_published": "2026-07-23T11:19:16.755Z",
      "date_updated": "2026-07-23T13:39:58.992Z",
      "publisher": "Patchstack",
      "title": "WordPress Graphina plugin <= 3.1.12 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Iqonic Design"
        ],
        "products": [
          {
            "vendor": "Iqonic Design",
            "product": "Graphina"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09473
      },
      "nvd": {
        "published": "2026-07-23T12:18:45.760",
        "lastModified": "2026-07-23T14:17:58.570",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65529",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/graphina-elementor-charts-and-graphs/vulnerability/wordpress-graphina-plugin-3-1-12-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 69,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:08.235Z",
      "date_published": "2026-07-23T11:19:17.398Z",
      "date_updated": "2026-07-23T14:08:47.141Z",
      "publisher": "Patchstack",
      "title": "WordPress TemplateSpare plugin <= 4.2.2 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Templatespare"
        ],
        "products": [
          {
            "vendor": "Templatespare",
            "product": "TemplateSpare"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12874
      },
      "nvd": {
        "published": "2026-07-23T12:18:45.880",
        "lastModified": "2026-07-23T15:18:12.427",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65530",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "TemplateSpare fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/templatespare/vulnerability/wordpress-templatespare-plugin-4-2-2-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 68,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65531",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:08.235Z",
      "date_published": "2026-07-23T11:19:18.064Z",
      "date_updated": "2026-07-23T15:12:18.787Z",
      "publisher": "Patchstack",
      "title": "WordPress Qubely plugin <= 1.8.14 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Themeum"
        ],
        "products": [
          {
            "vendor": "Themeum",
            "product": "Qubely"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00144,
        "percentile": 0.04171
      },
      "nvd": {
        "published": "2026-07-23T12:18:46.017",
        "lastModified": "2026-07-23T16:17:52.380",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65531",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Qubely exposes an action without authenticating or authorizing the caller, while the exact object and endpoint are not public.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/qubely/vulnerability/wordpress-qubely-plugin-1-8-14-broken-access-control-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 67,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65532",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:08.235Z",
      "date_published": "2026-07-23T11:19:18.696Z",
      "date_updated": "2026-07-23T15:53:28.095Z",
      "publisher": "Patchstack",
      "title": "WordPress Persian Woocommerce SMS plugin <= 7.2.2 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "PersianScript"
        ],
        "products": [
          {
            "vendor": "PersianScript",
            "product": "Persian Woocommerce SMS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13418
      },
      "nvd": {
        "published": "2026-07-23T12:18:46.143",
        "lastModified": "2026-07-23T16:17:52.483",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65532",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Persian Woocommerce SMS incorporates attacker-controlled input into an SQL statement without parameterization, allowing input syntax to alter the database query.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/persian-woocommerce-sms/vulnerability/wordpress-persian-woocommerce-sms-plugin-7-2-2-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 72,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65533",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:12.816Z",
      "date_published": "2026-07-23T11:19:19.336Z",
      "date_updated": "2026-07-23T14:50:11.064Z",
      "publisher": "Patchstack",
      "title": "WordPress Smart SEO Tool plugin <= 4.1.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "wbolt.com"
        ],
        "products": [
          {
            "vendor": "wbolt.com",
            "product": "Smart SEO Tool"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00139,
        "percentile": 0.03682
      },
      "nvd": {
        "published": "2026-07-23T12:18:46.263",
        "lastModified": "2026-07-23T15:18:12.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65533",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application inserts attacker-controlled input into an HTML execution context without the required output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/smart-seo-tool/vulnerability/wordpress-smart-seo-tool-plugin-4-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65534",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:12.816Z",
      "date_published": "2026-07-23T11:19:19.964Z",
      "date_updated": "2026-07-23T13:25:45.530Z",
      "publisher": "Patchstack",
      "title": "WordPress Custom links in Elementor Image Carousel plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Charlie Etienne"
        ],
        "products": [
          {
            "vendor": "Charlie Etienne",
            "product": "Custom links in Elementor Image Carousel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04536
      },
      "nvd": {
        "published": "2026-07-23T12:18:46.377",
        "lastModified": "2026-07-23T14:17:59.047",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65534",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The image-carousel extension emits author-controlled input as executable page markup without sufficient neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/custom-links-in-elementor-image-carousel/vulnerability/wordpress-custom-links-in-elementor-image-carousel-plugin-1-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65535",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:12.816Z",
      "date_published": "2026-07-23T11:19:20.599Z",
      "date_updated": "2026-07-23T13:37:26.146Z",
      "publisher": "Patchstack",
      "title": "WordPress TinyMCE Templates plugin <= 4.8.1 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Takayuki Miyauchi"
        ],
        "products": [
          {
            "vendor": "Takayuki Miyauchi",
            "product": "TinyMCE Templates"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00184,
        "percentile": 0.08229
      },
      "nvd": {
        "published": "2026-07-23T12:18:46.497",
        "lastModified": "2026-07-23T14:17:59.510",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65535",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "TinyMCE Templates exposes protected data to a contributor, while the public record does not identify the data field or output path.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/tinymce-templates/vulnerability/wordpress-tinymce-templates-plugin-4-8-1-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65536",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:12.816Z",
      "date_published": "2026-07-23T11:19:21.247Z",
      "date_updated": "2026-07-23T14:03:30.708Z",
      "publisher": "Patchstack",
      "title": "WordPress افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin <= 4.4.5 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "Mahdi Yousefi"
        ],
        "products": [
          {
            "vendor": "Mahdi Yousefi",
            "product": "افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری)"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00123,
        "percentile": 0.02444
      },
      "nvd": {
        "published": "2026-07-23T12:18:46.617",
        "lastModified": "2026-07-23T14:17:59.933",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65536",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/persian-woocommerce-shipping/vulnerability/wordpress-fzonh-hml-o-nkl-oo-mrs-st-sht-z-o-sf-rsh-motor-plugin-4-4-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65537",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:12.816Z",
      "date_published": "2026-07-23T11:19:21.892Z",
      "date_updated": "2026-07-23T15:22:08.465Z",
      "publisher": "Patchstack",
      "title": "WordPress Cyr to Lat reloaded – transliteration of links and file names plugin <= 1.3.3 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Themeisle"
        ],
        "products": [
          {
            "vendor": "Themeisle",
            "product": "Cyr to Lat reloaded – transliteration of links and file names"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11168
      },
      "nvd": {
        "published": "2026-07-23T12:18:46.737",
        "lastModified": "2026-07-23T16:17:52.597",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65537",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The Cyr to Lat record identifies subscriber-level access to a protected operation but does not name that operation or the missing capability check.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/cyr-and-lat/vulnerability/wordpress-cyr-to-lat-reloaded-transliteration-of-links-and-file-names-plugin-1-3-3-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65538",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:12.816Z",
      "date_published": "2026-07-23T11:19:22.531Z",
      "date_updated": "2026-07-23T15:48:44.017Z",
      "publisher": "Patchstack",
      "title": "WordPress Machete plugin <= 5.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Nilo Velez"
        ],
        "products": [
          {
            "vendor": "Nilo Velez",
            "product": "Machete"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04535
      },
      "nvd": {
        "published": "2026-07-23T12:18:46.863",
        "lastModified": "2026-07-23T16:17:52.693",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65538",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Attacker-controlled data reaches an HTML or DOM sink without context-appropriate sanitization and output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, or state transition."
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/machete/vulnerability/wordpress-machete-plugin-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 61,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65539",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:12.816Z",
      "date_published": "2026-07-23T11:19:23.165Z",
      "date_updated": "2026-07-23T14:49:58.989Z",
      "publisher": "Patchstack",
      "title": "WordPress Kwayy HTML Sitemap plugin <= 4.0 - CSRF to Stored XSS vulnerability",
      "affected": {
        "vendors": [
          "Bimal Rekhadiya"
        ],
        "products": [
          {
            "vendor": "Bimal Rekhadiya",
            "product": "Kwayy HTML Sitemap"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00094,
        "percentile": 0.00738
      },
      "nvd": {
        "published": "2026-07-23T12:18:46.983",
        "lastModified": "2026-07-23T15:18:13.577",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65539",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Patchstack identifies a cross-site request forgery in Kwayy HTML Sitemap, but does not publish the state-changing action or missing request check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/kwayy-html-sitemap/vulnerability/wordpress-kwayy-html-sitemap-plugin-4-0-csrf-to-stored-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 88,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65540",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:12.816Z",
      "date_published": "2026-07-23T11:19:23.800Z",
      "date_updated": "2026-07-23T13:24:19.102Z",
      "publisher": "Patchstack",
      "title": "WordPress Popup for CF7 with Sweet Alert plugin <= 1.6.5 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "Metin Saraç"
        ],
        "products": [
          {
            "vendor": "Metin Saraç",
            "product": "Popup for CF7 with Sweet Alert"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00094,
        "percentile": 0.00738
      },
      "nvd": {
        "published": "2026-07-23T12:18:47.110",
        "lastModified": "2026-07-23T14:18:00.523",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65540",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A state-changing browser request is accepted without a valid origin-bound anti-forgery check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/cf7-sweet-alert-popup/vulnerability/wordpress-popup-for-cf7-with-sweet-alert-plugin-1-6-5-cross-site-request-forgery-csrf-vulnerability-2?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 102,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65550",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:17.066Z",
      "date_published": "2026-07-23T11:19:24.434Z",
      "date_updated": "2026-07-23T13:35:46.597Z",
      "publisher": "Patchstack",
      "title": "WordPress Tabs plugin <= 2.5 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "wpshopmart"
        ],
        "products": [
          {
            "vendor": "wpshopmart",
            "product": "Tabs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00148,
        "percentile": 0.04535
      },
      "nvd": {
        "published": "2026-07-23T12:18:47.230",
        "lastModified": "2026-07-23T14:18:01.160",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65550",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Tabs page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/tabs-responsive/vulnerability/wordpress-tabs-plugin-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 64,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65557",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:23.962Z",
      "date_published": "2026-07-27T13:59:19.377Z",
      "date_updated": "2026-07-27T16:30:02.069Z",
      "publisher": "Patchstack",
      "title": "WordPress Abandoned Cart Lite for WooCommerce plugin <= 6.8.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Tychesoftwares"
        ],
        "products": [
          {
            "vendor": "Tychesoftwares",
            "product": "Abandoned Cart Lite for WooCommerce"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03783
      },
      "nvd": {
        "published": "2026-07-27T15:17:09.060",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65557",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Shop-manager-controlled cart data is rendered without the required browser-context separation.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-abandoned-cart/vulnerability/wordpress-abandoned-cart-lite-for-woocommerce-plugin-6-8-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 97,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65558",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:23.962Z",
      "date_published": "2026-07-27T13:59:20.025Z",
      "date_updated": "2026-07-27T16:17:44.977Z",
      "publisher": "Patchstack",
      "title": "WordPress AffiliateX plugin <= 2.3.5 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "WPCenter"
        ],
        "products": [
          {
            "vendor": "WPCenter",
            "product": "AffiliateX"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00138,
        "percentile": 0.03625
      },
      "nvd": {
        "published": "2026-07-27T15:17:09.210",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65558",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A server-side request accepts an attacker-selected destination without enforcing the intended network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/affiliatex/vulnerability/wordpress-affiliatex-plugin-2-3-5-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 83,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65561",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:23.962Z",
      "date_published": "2026-07-27T13:59:20.665Z",
      "date_updated": "2026-07-27T16:07:44.552Z",
      "publisher": "Patchstack",
      "title": "WordPress WordPress Social Login and Register plugin <= 7.8.0 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "miniOrange"
        ],
        "products": [
          {
            "vendor": "miniOrange",
            "product": "WordPress Social Login and Register"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03049
      },
      "nvd": {
        "published": "2026-07-27T15:17:09.357",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65561",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Contributor-controlled Social Login data reaches a browser-executable context without sufficient HTML neutralization.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/miniorange-login-openid/vulnerability/wordpress-wordpress-social-login-and-register-plugin-7-8-0-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65562",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:23.962Z",
      "date_published": "2026-07-27T13:59:21.316Z",
      "date_updated": "2026-07-27T14:59:56.545Z",
      "publisher": "Patchstack",
      "title": "WordPress BetterDocs plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WPDeveloper"
        ],
        "products": [
          {
            "vendor": "WPDeveloper",
            "product": "BetterDocs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03053
      },
      "nvd": {
        "published": "2026-07-27T15:17:09.507",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65562",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "BetterDocs renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/betterdocs/vulnerability/wordpress-betterdocs-plugin-4-6-2-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 71,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65563",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:32.759Z",
      "date_published": "2026-07-27T13:59:21.954Z",
      "date_updated": "2026-07-27T15:01:58.458Z",
      "publisher": "Patchstack",
      "title": "WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Themeisle"
        ],
        "products": [
          {
            "vendor": "Themeisle",
            "product": "Orbit Fox by ThemeIsle"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03784
      },
      "nvd": {
        "published": "2026-07-27T15:17:09.657",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65563",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Orbit Fox lets author-controlled content reach page markup without neutralizing executable script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/themeisle-companion/vulnerability/wordpress-orbit-fox-by-themeisle-plugin-3-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 78,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65564",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:32.759Z",
      "date_published": "2026-07-27T13:59:22.589Z",
      "date_updated": "2026-07-27T18:15:15.556Z",
      "publisher": "Patchstack",
      "title": "WordPress MapPress Maps for WordPress plugin <= 2.97.6 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "chrisvrichardson"
        ],
        "products": [
          {
            "vendor": "chrisvrichardson",
            "product": "MapPress Maps for WordPress"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09729
      },
      "nvd": {
        "published": "2026-07-27T15:17:09.807",
        "lastModified": "2026-07-27T19:17:22.047",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65564",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "MapPress exposes sensitive system information to unauthenticated callers, while the Patchstack record does not identify the data, endpoint, or response.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/mappress-google-maps-for-wordpress/vulnerability/wordpress-mappress-maps-for-wordpress-plugin-2-97-6-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 90,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65567",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:32.759Z",
      "date_published": "2026-07-27T13:59:23.233Z",
      "date_updated": "2026-07-27T16:29:36.731Z",
      "publisher": "Patchstack",
      "title": "WordPress Event Tickets plugin <= 5.29.0.1 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Nexcess"
        ],
        "products": [
          {
            "vendor": "Nexcess",
            "product": "Event Tickets"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.0731
      },
      "nvd": {
        "published": "2026-07-27T15:17:09.990",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65567",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record shows an unauthenticated Event Tickets action crosses an authorization boundary but does not identify the action or missing check.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/event-tickets/vulnerability/wordpress-event-tickets-plugin-5-29-0-1-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 76,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65568",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T08:54:32.759Z",
      "date_published": "2026-07-27T13:59:23.873Z",
      "date_updated": "2026-07-27T16:17:37.177Z",
      "publisher": "Patchstack",
      "title": "WordPress Visual Composer Website Builder plugin <= 45.15.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Visual Composer"
        ],
        "products": [
          {
            "vendor": "Visual Composer",
            "product": "Visual Composer Website Builder"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06175
      },
      "nvd": {
        "published": "2026-07-27T15:17:10.217",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65568",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Visual Composer permits a contributor to perform an undisclosed action without the required authorization check.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/visualcomposer/vulnerability/wordpress-visual-composer-website-builder-plugin-45-15-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 89,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65589",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:45:44.832Z",
      "date_published": "2026-07-22T11:21:39.365Z",
      "date_updated": "2026-07-23T13:53:56.061Z",
      "publisher": "VulnCheck",
      "title": "n8n before 1.123.64 Credential Exposure via LLM Node Execution Data",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-532",
          "name": "Insertion of Sensitive Information into Log File",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00371,
        "percentile": 0.2989
      },
      "nvd": {
        "published": "2026-07-22T12:18:18.857",
        "lastModified": "2026-07-27T19:09:14.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65589",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The n8n execution path writes secrets into records or logs readable by users who are not entitled to those secret values.",
        "basis": [
          "CNA",
          "CWE-532"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-89gh-3pgc-v5h2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-credential-exposure-via-llm-node-execution-data",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65590",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:45:44.832Z",
      "date_published": "2026-07-22T11:21:40.040Z",
      "date_updated": "2026-07-22T13:03:15.692Z",
      "publisher": "VulnCheck",
      "title": "n8n before 2.30.1 Shell Sandbox Bypass on Linux Windows",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 4.300000000000001,
      "epss": {
        "score": 0.00322,
        "percentile": 0.24604
      },
      "nvd": {
        "published": "2026-07-22T12:18:18.987",
        "lastModified": "2026-07-27T19:10:27.807",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65590",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The computer-use shell applies its sandbox only on macOS, leaving Linux and Windows commands unrestricted on the host.",
        "basis": [
          "CNA",
          "CWE-78",
          "https://github.com/n8n-io/n8n/security/advisories/GHSA-fpg6-x68q-5793"
        ],
        "deepDive": true,
        "notes": "The official n8n advisory rates the issue Moderate at CVSS 4.0 5.5 with PR:H and no CWE, while the embedded VulnCheck/NVD row reports CVSS 3.1 9.8 with PR:N and CWE-78; the advisory describes missing platform sandbox enforcement rather than command injection."
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-fpg6-x68q-5793",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-shell-sandbox-bypass-on-linux-windows",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 530,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-65591",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:45:44.832Z",
      "date_published": "2026-07-22T11:21:40.743Z",
      "date_updated": "2026-07-22T15:51:37.174Z",
      "publisher": "VulnCheck",
      "title": "n8n before 1.123.64 Sanitizer Bypass Remote Code Execution",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-917",
          "name": "Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 0.09999999999999964,
      "epss": {
        "score": 0.00471,
        "percentile": 0.38303
      },
      "nvd": {
        "published": "2026-07-22T12:18:19.117",
        "lastModified": "2026-07-27T19:11:06.293",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65591",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The n8n evaluator permits attacker-controlled expression syntax to cross its sanitizer and execute in the host context.",
        "basis": [
          "CNA",
          "CWE-917"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-pm35-fqvh-cq5g",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-sanitizer-bypass-remote-code-execution",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65592",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:45:44.832Z",
      "date_published": "2026-07-22T11:21:41.381Z",
      "date_updated": "2026-07-22T12:23:52.475Z",
      "publisher": "VulnCheck",
      "title": "n8n before 1.123.64 Stored DOM XSS via cachedResultUrl",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 3,
      "epss": {
        "score": 0.00172,
        "percentile": 0.06833
      },
      "nvd": {
        "published": "2026-07-22T12:18:19.253",
        "lastModified": "2026-07-27T19:11:30.983",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65592",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "n8n passes workflow-persisted cachedResultUrl to window.open without rejecting executable URL schemes.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-9wcp-9r3j-383q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-stored-dom-xss-via-cachedresulturl",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 498,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65593",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:45:44.832Z",
      "date_published": "2026-07-22T11:21:42.062Z",
      "date_updated": "2026-07-24T21:35:14.789Z",
      "publisher": "VulnCheck",
      "title": "n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00143,
        "percentile": 0.04086
      },
      "nvd": {
        "published": "2026-07-22T12:18:19.390",
        "lastModified": "2026-07-27T19:12:13.733",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65593",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The n8n dynamic-node-parameters endpoints lack authorization scopes and accept absolute routing URLs that override baseURL restrictions, allowing an authenticated caller to reach internal targets when SSRF protection is disabled.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-9w78-79q7-r4fp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-ssrf-via-dynamic-node-parameters",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 388,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65594",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:45:44.832Z",
      "date_published": "2026-07-22T11:21:42.750Z",
      "date_updated": "2026-07-23T18:01:35.800Z",
      "publisher": "VulnCheck",
      "title": "n8n before 2.30.1 Missing OAuth Authorization Check",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00268,
        "percentile": 0.1878
      },
      "nvd": {
        "published": "2026-07-22T12:18:19.527",
        "lastModified": "2026-07-27T19:13:07.460",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65594",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-q5xf-xhwf-cwqf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-missing-oauth-authorization-check",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 724,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-65595",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:45:44.832Z",
      "date_published": "2026-07-22T11:21:43.411Z",
      "date_updated": "2026-07-24T21:35:15.441Z",
      "publisher": "VulnCheck",
      "title": "n8n before 2.29.8 and 2.30.1 Privilege Escalation via Token Exchange",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 0.09999999999999964,
      "epss": {
        "score": 0.0047,
        "percentile": 0.38214
      },
      "nvd": {
        "published": "2026-07-22T12:18:19.660",
        "lastModified": "2026-07-27T19:14:35.053",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65595",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "n8n token exchange grants every Public API scope to the issued JWT without intersecting the scopes with the acting user's role.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-777w-rpr6-c52h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-privilege-escalation-via-token-exchange",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 611,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-65596",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:45:44.833Z",
      "date_published": "2026-07-22T11:21:44.064Z",
      "date_updated": "2026-07-22T13:03:54.789Z",
      "publisher": "VulnCheck",
      "title": "n8n before 1.123.64 Credential Exfiltration via GraphQL Node",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 3,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11159
      },
      "nvd": {
        "published": "2026-07-22T12:18:19.790",
        "lastModified": "2026-07-27T19:15:28.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65596",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "n8n permits a GraphQL credential operation outside the credential's configured domain restriction, applying authorization to the wrong destination scope.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-gq66-9cw5-j5jm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-credential-exfiltration-via-graphql-node",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 501,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65597",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:45:44.833Z",
      "date_published": "2026-07-22T11:21:44.721Z",
      "date_updated": "2026-07-22T15:58:12.717Z",
      "publisher": "VulnCheck",
      "title": "n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.799999999999999,
      "epss": {
        "score": 0.00214,
        "percentile": 0.11816
      },
      "nvd": {
        "published": "2026-07-22T12:18:19.913",
        "lastModified": "2026-07-27T19:15:45.820",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65597",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-p3rg-hrf9-w9gj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-dom-based-xss-via-unsandboxed-iframe",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 462,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65598",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:45:44.833Z",
      "date_published": "2026-07-22T11:21:45.418Z",
      "date_updated": "2026-07-22T12:22:51.683Z",
      "publisher": "VulnCheck",
      "title": "n8n before 1.123.64 Remote Code Execution via Git Clone",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.9,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.9,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15376
      },
      "nvd": {
        "published": "2026-07-22T12:18:20.037",
        "lastModified": "2026-07-27T19:18:06.673",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65598",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Git clone path is validated before use, allowing an authenticated user to replace the checked directory with a symlink before cloning.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-g3r5-9h93-4j2c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-remote-code-execution-via-git-clone",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 492,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65599",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:48:36.000Z",
      "date_published": "2026-07-22T11:21:46.100Z",
      "date_updated": "2026-07-24T21:35:16.181Z",
      "publisher": "VulnCheck",
      "title": "n8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT Header",
      "affected": {
        "vendors": [
          "n8n-io"
        ],
        "products": [
          {
            "vendor": "n8n-io",
            "product": "n8n"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-312",
          "name": "Cleartext Storage of Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 1.4000000000000004,
      "epss": {
        "score": 0.00153,
        "percentile": 0.0501
      },
      "nvd": {
        "published": "2026-07-22T12:18:20.167",
        "lastModified": "2026-07-27T19:18:25.940",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65599",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "n8n places an entire PEM private key in the readable kid field of a JWT header instead of placing only a key identifier there.",
        "basis": [
          "CNA",
          "CWE-312"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-9r8p-h6cc-6qhm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mitigation",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/n8n-before-credential-exposure-via-jwt-header",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 616,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65600",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:48:36.000Z",
      "date_published": "2026-07-22T11:21:46.783Z",
      "date_updated": "2026-07-23T19:08:19.233Z",
      "publisher": "VulnCheck",
      "title": "Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex",
      "affected": {
        "vendors": [
          "traefik"
        ],
        "products": [
          {
            "vendor": "traefik",
            "product": "traefik"
          }
        ],
        "affectedBlockCount": 3,
        "versionEntryCount": 6,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00674,
        "percentile": 0.48618
      },
      "nvd": {
        "published": "2026-07-22T12:18:20.297",
        "lastModified": "2026-07-23T20:17:21.667",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65600",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Traefik forwards an unnormalized replacement path that the backend later normalizes to a protected route, so middleware and backend authorize different paths.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/traefik/traefik/security/advisories/GHSA-cxjq-mrr5-89rv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/traefik-before-authentication-bypass-via-replacepathregex",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 736,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65601",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:48:36.000Z",
      "date_published": "2026-07-22T11:21:47.468Z",
      "date_updated": "2026-07-24T21:35:16.899Z",
      "publisher": "VulnCheck",
      "title": "Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef",
      "affected": {
        "vendors": [
          "traefik"
        ],
        "products": [
          {
            "vendor": "traefik",
            "product": "traefik"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00238,
        "percentile": 0.14917
      },
      "nvd": {
        "published": "2026-07-22T12:18:20.430",
        "lastModified": "2026-07-23T14:18:02.560",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65601",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Traefik resolves an HTTPRoute extensionRef in the backend Service namespace and therefore applies the Service grant to a Middleware that requires a separate namespace authorization.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/traefik/traefik/security/advisories/GHSA-qq9q-x9w4-chhj",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/traefik/traefik/commit/26c96a3935cafb473f4a5bae1886560d9aa4e4f0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/traefik-before-namespace-confusion-via-httproute-extensionref",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 599,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65602",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:48:36.000Z",
      "date_published": "2026-07-22T11:21:48.127Z",
      "date_updated": "2026-07-24T21:35:17.581Z",
      "publisher": "VulnCheck",
      "title": "Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass",
      "affected": {
        "vendors": [
          "traefik"
        ],
        "products": [
          {
            "vendor": "traefik",
            "product": "traefik"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.05746
      },
      "nvd": {
        "published": "2026-07-22T12:18:20.560",
        "lastModified": "2026-07-22T16:27:18.220",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65602",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The TCP route path omits the crossProviderNamespaces allowlist applied to HTTP and accepts a forbidden cross-provider transport reference.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/traefik/traefik/security/advisories/GHSA-42cj-m3vj-89wv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/traefik/traefik/commit/26c96a3935cafb473f4a5bae1886560d9aa4e4f0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/traefik-before-ingressroutetcp-serverstransport-namespace-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 632,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-65603",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:48:36.000Z",
      "date_published": "2026-07-22T11:21:48.928Z",
      "date_updated": "2026-07-22T16:00:38.403Z",
      "publisher": "VulnCheck",
      "title": "Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00303,
        "percentile": 0.22647
      },
      "nvd": {
        "published": "2026-07-22T12:18:20.683",
        "lastModified": "2026-07-22T17:16:59.437",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65603",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The profile update handler persists attacker-supplied groups and access fields instead of stripping privilege attributes.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-h33v-82r9-v8pm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-login-plugin-privilege-escalation-via-profile-update",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 725,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65604",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:48:36.000Z",
      "date_published": "2026-07-23T21:16:47.608Z",
      "date_updated": "2026-07-24T14:04:07.992Z",
      "publisher": "VulnCheck",
      "title": "Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass",
      "affected": {
        "vendors": [
          "zalando"
        ],
        "products": [
          {
            "vendor": "zalando",
            "product": "skipper"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21239
      },
      "nvd": {
        "published": "2026-07-23T22:16:53.170",
        "lastModified": "2026-07-30T19:53:34.757",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65604",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Skipper forwards an oversized request body while presenting an empty parsed_body to OPA, so body-dependent deny rules inspect different data from the upstream request.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zalando/skipper/security/advisories/GHSA-8qqm-fp2q-v734",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/skipper-incomplete-fix-for-cve-2026-50197-policy-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 496,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-65605",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:48:36.000Z",
      "date_published": "2026-07-23T11:42:13.521Z",
      "date_updated": "2026-07-28T01:06:08.238Z",
      "publisher": "VulnCheck",
      "title": "SiYuan before v3.7.2 Stored XSS to RCE via Attribute View",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00516,
        "percentile": 0.41056
      },
      "nvd": {
        "published": "2026-07-23T12:18:47.357",
        "lastModified": "2026-07-23T16:17:52.793",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65605",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "siyuan places attacker-controlled markup, attributes, or URLs into an HTML or DOM rendering context without the required sanitization or output encoding.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-pw5c-qhf3-jhwh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/commit/41f2861c87575ff5ac4b50a0520b1a4fe55b4a70",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/siyuan-before-stored-xss-to-rce-via-attribute-view",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 641,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65606",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:48:36.000Z",
      "date_published": "2026-07-23T11:42:14.200Z",
      "date_updated": "2026-07-28T01:06:08.923Z",
      "publisher": "VulnCheck",
      "title": "SiYuan before v3.7.2 Cross-Site Scripting to RCE",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00516,
        "percentile": 0.41056
      },
      "nvd": {
        "published": "2026-07-23T12:18:47.493",
        "lastModified": "2026-07-23T16:17:52.913",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65606",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SiYuan protocol handler inserts the icon parameter through innerHTML, and nodeIntegration lets the resulting script invoke operating-system commands.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-wp64-x7qh-h728",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/commit/41f2861c87575ff5ac4b50a0520b1a4fe55b4a70",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/siyuan-before-cross-site-scripting-to-rce",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 646,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65607",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:48:36.000Z",
      "date_published": "2026-07-23T11:42:14.890Z",
      "date_updated": "2026-07-28T01:06:09.636Z",
      "publisher": "VulnCheck",
      "title": "SiYuan before v3.7.2 Path Traversal via /export/temp/",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00399,
        "percentile": 0.32674
      },
      "nvd": {
        "published": "2026-07-23T12:18:47.633",
        "lastModified": "2026-07-27T17:16:40.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65607",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "siyuan resolves attacker-controlled path components without confirming that the final path remains beneath the intended root.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-gw25-m53r-qh88",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/commit/bb481e1290c4a34255652ede85a546504505d2a7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/siyuan-before-path-traversal-via-export-temp",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 715,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65608",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T10:48:36.000Z",
      "date_published": "2026-07-23T11:42:15.534Z",
      "date_updated": "2026-07-24T21:35:20.322Z",
      "publisher": "VulnCheck",
      "title": "Grav before 2.0.9 Remote Code Execution via FlexDirectory",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-470",
          "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00849,
        "percentile": 0.54582
      },
      "nvd": {
        "published": "2026-07-23T12:18:47.770",
        "lastModified": "2026-07-23T19:17:04.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65608",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application passes an attacker-selected callable to call_user_func_array after only an is_callable check, allowing dangerous functions to execute.",
        "basis": [
          "CNA",
          "CWE-470"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-c4wf-2xxc-68qm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/commit/fae9e1bf2c40ce0b50d0dfce647aaa1d22f98969",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-before-remote-code-execution-via-flexdirectory",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 731,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65616",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T12:02:46.789Z",
      "date_published": "2026-07-27T19:34:17.137Z",
      "date_updated": "2026-07-27T20:05:20.710Z",
      "publisher": "JFROG",
      "title": "Potential privilege escalation to JFrog administrator privileges",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-347",
          "name": "Improper Verification of Cryptographic Signature",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08596
      },
      "nvd": {
        "published": "2026-07-27T20:16:40.843",
        "lastModified": "2026-07-30T14:49:28.900",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65616",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Artifactory validates a refresh-token signature incorrectly and issues a signed administrator token to a non-administrator.",
        "basis": [
          "CNA",
          "CWE-347"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 130,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65617",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T12:02:46.789Z",
      "date_published": "2026-07-27T19:37:27.983Z",
      "date_updated": "2026-07-27T19:59:29.655Z",
      "publisher": "JFROG",
      "title": "Potential remote code execution on an Artifactory package service container.",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00312,
        "percentile": 0.2357
      },
      "nvd": {
        "published": "2026-07-27T20:16:40.953",
        "lastModified": "2026-07-30T14:49:42.093",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65617",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "JFrog Artifactory deserializes attacker-influenced package data into executable object behavior without a safe serialization boundary.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 191,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65618",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T12:02:46.789Z",
      "date_published": "2026-07-27T19:32:29.202Z",
      "date_updated": "2026-07-27T20:06:56.305Z",
      "publisher": "JFROG",
      "title": "Improper URL validation when handling specific URLs Pub, Terraform and Docker packages might lead to SSRF vulnerability",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.11129
      },
      "nvd": {
        "published": "2026-07-27T20:16:41.077",
        "lastModified": "2026-07-30T14:51:10.990",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65618",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 217,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65623",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T13:55:59.401Z",
      "date_published": "2026-07-24T16:32:24.923Z",
      "date_updated": "2026-07-25T04:16:42.726Z",
      "publisher": "EEF",
      "title": "Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit",
      "affected": {
        "vendors": [
          "mtrudel"
        ],
        "products": [
          {
            "vendor": "mtrudel",
            "product": "bandit"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00392,
        "percentile": 0.31919
      },
      "nvd": {
        "published": "2026-07-24T17:17:34.107",
        "lastModified": "2026-07-30T17:01:07.343",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65623",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly.",
        "basis": [
          "CNA",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/mtrudel/bandit/security/advisories/GHSA-vg8x-66vg-5pxh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-65623.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-65623",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/mtrudel/bandit/commit/418ef7e906192a230ddba112f7a669c87b6b0e3a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1238,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65624",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T13:55:59.401Z",
      "date_published": "2026-07-28T10:01:01.811Z",
      "date_updated": "2026-07-29T04:17:22.788Z",
      "publisher": "EEF",
      "title": "Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion",
      "affected": {
        "vendors": [
          "ninenines"
        ],
        "products": [
          {
            "vendor": "ninenines",
            "product": "cowboy"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00383,
        "percentile": 0.3105
      },
      "nvd": {
        "published": "2026-07-28T10:16:50.500",
        "lastModified": "2026-07-30T19:14:09.213",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65624",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Cowboy counts distinct header names while concatenating unlimited duplicate values, so max_headers never caps total header memory.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-65624.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "third-party-advisory"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-65624",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/ninenines/cowboy/commit/3a34d8c1cfd94326466aa16a9017236691dc9c55",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1375,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65635",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T13:58:26.233Z",
      "date_published": "2026-07-30T14:17:02.942Z",
      "date_updated": "2026-07-31T04:20:15.914Z",
      "publisher": "EEF",
      "title": "Boruta dynamic client registration allows creation of over-privileged OAuth clients",
      "affected": {
        "vendors": [
          "malach-it"
        ],
        "products": [
          {
            "vendor": "malach-it",
            "product": "boruta"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-653",
          "name": "Improper Isolation or Compartmentalization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00301,
        "percentile": 0.22417
      },
      "nvd": {
        "published": "2026-07-30T15:16:35.017",
        "lastModified": "2026-07-30T17:16:34.043",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65635",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Public dynamic client registration forwards caller-supplied fields into the administrative client-creation path without separating operator-only controls.",
        "basis": [
          "CNA",
          "CWE-653"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/malach-it/boruta_auth/security/advisories/GHSA-w869-fcf2-68vp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-65635.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-65635",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/malach-it/boruta_auth/commit/82584c854a332482232fd25301ab12a835f9f643",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/malach-it/boruta_auth/commit/95619a1beaff68fa766cca9b388e7c780d182525",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1028,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65636",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T13:58:26.233Z",
      "date_published": "2026-07-31T13:29:31.198Z",
      "date_updated": "2026-08-01T04:18:38.726Z",
      "publisher": "EEF",
      "title": "YAML injection via unescaped newlines in ymlr document comments",
      "affected": {
        "vendors": [
          "ufirstgroup"
        ],
        "products": [
          {
            "vendor": "ufirstgroup",
            "product": "ymlr"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-93",
          "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"
        },
        {
          "source": "NVD:6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 2.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00141,
        "percentile": 0.03896
      },
      "nvd": {
        "published": "2026-07-31T14:16:51.240",
        "lastModified": "2026-08-04T14:52:54.493",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65636",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unescaped line break ends the intended comment context and turns the remaining attacker text into YAML document content.",
        "basis": [
          "CNA",
          "CWE-93"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ufirstgroup/ymlr/security/advisories/GHSA-p8qx-7cp9-v6c9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://cna.erlef.org/cves/CVE-2026-65636.html",
          "host": "cna.erlef.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-65636",
          "host": "osv.dev",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/ufirstgroup/ymlr/commit/7e53061fb2809b787fba0373c46b78e253c83adc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/ufirstgroup/ymlr/commit/42a0bf8b2af44b0e7c42d0b7044c8588ca5866dc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1292,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65650",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T17:07:58.054Z",
      "date_published": "2026-07-22T17:07:58.988Z",
      "date_updated": "2026-07-22T18:49:19.203Z",
      "publisher": "mitre",
      "title": "Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.",
      "affected": {
        "vendors": [
          "Elgg"
        ],
        "products": [
          {
            "vendor": "Elgg",
            "product": "Elgg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0039,
        "percentile": 0.31761
      },
      "nvd": {
        "published": "2026-07-22T18:17:06.047",
        "lastModified": "2026-07-22T20:50:36.493",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65650",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Elgg accepts attacker-driven work or allocation without an effective size, rate, release, or termination bound.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Elgg/Elgg/compare/7.0.0-rc.1...7.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/Elgg/Elgg/commit/ab91d59dc2caaa3fdbfe7e9b916fc0cc7e6b323a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/Elgg/Elgg/pull/15041",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 105,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65687",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.979Z",
      "date_published": "2026-07-23T13:24:44.107Z",
      "date_updated": "2026-07-24T14:32:12.957Z",
      "publisher": "VulnCheck",
      "title": "Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via SVG Processing",
      "affected": {
        "vendors": [
          "Bold Reports (By SyncFusion)"
        ],
        "products": [
          {
            "vendor": "Bold Reports (By SyncFusion)",
            "product": "Standalone Report Designer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00581,
        "percentile": 0.4449
      },
      "nvd": {
        "published": "2026-07-23T14:18:02.993",
        "lastModified": "2026-07-28T15:57:12.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65687",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SVG processing accepts an unauthenticated file path without confining it to an allowed report directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.boldreports.com/resources/release-history/standalone-report-designer/14-1#14-1-12",
          "host": "www.boldreports.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/bold-reports-standalone-report-designer-arbitrary-file-read-via-svg-processing",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-65688",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.979Z",
      "date_published": "2026-07-23T13:25:42.187Z",
      "date_updated": "2026-07-24T14:32:24.855Z",
      "publisher": "VulnCheck",
      "title": "Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font Processing",
      "affected": {
        "vendors": [
          "Bold Reports (By SyncFusion)"
        ],
        "products": [
          {
            "vendor": "Bold Reports (By SyncFusion)",
            "product": "Standalone Report Designer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00594,
        "percentile": 0.45039
      },
      "nvd": {
        "published": "2026-07-23T14:18:03.163",
        "lastModified": "2026-07-28T15:56:12.793",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65688",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A traversal path selects an arbitrary file outside the intended root for reading.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.boldreports.com/resources/release-history/standalone-report-designer/14-1#14-1-12",
          "host": "www.boldreports.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/bold-reports-standalone-report-designer-arbitrary-file-read-via-font-processing",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 584,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-65689",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.979Z",
      "date_published": "2026-07-23T13:28:35.327Z",
      "date_updated": "2026-07-27T16:20:25.316Z",
      "publisher": "VulnCheck",
      "title": "Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database Download",
      "affected": {
        "vendors": [
          "Bold Reports (By SyncFusion)"
        ],
        "products": [
          {
            "vendor": "Bold Reports (By SyncFusion)",
            "product": "Standalone Report Designer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00581,
        "percentile": 0.4449
      },
      "nvd": {
        "published": "2026-07-23T14:18:03.340",
        "lastModified": "2026-07-28T15:55:34.947",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65689",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The unauthenticated database-download feature accepts a traversal path and reads the selected file outside its intended directory.",
        "basis": [
          "CNA record",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.boldreports.com/resources/release-history/standalone-report-designer/14-1#14-1-12",
          "host": "www.boldreports.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/bold-reports-standalone-report-designer-arbitrary-file-read-via-database-download",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-65690",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.979Z",
      "date_published": "2026-07-23T13:30:16.990Z",
      "date_updated": "2026-07-24T14:34:37.299Z",
      "publisher": "VulnCheck",
      "title": "Bold Reports Standalone Report Designer < 14.1.12 Path Traversal RCE via File Upload",
      "affected": {
        "vendors": [
          "Bold Reports (By SyncFusion)"
        ],
        "products": [
          {
            "vendor": "Bold Reports (By SyncFusion)",
            "product": "Standalone Report Designer"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 8,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00599,
        "percentile": 0.45324
      },
      "nvd": {
        "published": "2026-07-23T14:18:03.503",
        "lastModified": "2026-07-28T15:55:00.480",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65690",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Standalone Report Designer accepts an attacker-controlled path that can resolve outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.boldreports.com/resources/release-history/standalone-report-designer/14-1#14-1-12",
          "host": "www.boldreports.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/bold-reports-standalone-report-designer-path-traversal-rce-via-file-upload",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 515,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 8
      }
    },
    {
      "cve_id": "CVE-2026-65693",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.979Z",
      "date_published": "2026-07-24T15:33:35.973Z",
      "date_updated": "2026-07-28T01:06:10.301Z",
      "publisher": "VulnCheck",
      "title": "Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates",
      "affected": {
        "vendors": [
          "microweber"
        ],
        "products": [
          {
            "vendor": "microweber",
            "product": "microweber"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00484,
        "percentile": 0.391
      },
      "nvd": {
        "published": "2026-07-24T16:16:55.360",
        "lastModified": "2026-07-28T20:37:39.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65693",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Microweber renders stored administrator mail templates in an unsandboxed Twig environment that exposes command-capable filters.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/W40X/584f4b088d310bc5280cc74bbf97831a",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/microweber-cms-server-side-template-injection-via-mail-templates",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 570,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65694",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.979Z",
      "date_published": "2026-07-23T21:20:29.159Z",
      "date_updated": "2026-07-28T01:06:10.984Z",
      "publisher": "VulnCheck",
      "title": "Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController",
      "affected": {
        "vendors": [
          "microweber"
        ],
        "products": [
          {
            "vendor": "microweber",
            "product": "microweber"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.02456,
        "percentile": 0.8283
      },
      "nvd": {
        "published": "2026-07-23T22:16:53.313",
        "lastModified": "2026-07-30T19:56:33.480",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65694",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ServeStaticFileController passes path query traversal through normalize_path and reads files outside the static-file root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/microweber/microweber/pull/1181",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "patch",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/microweber-cms-path-traversal-via-servestaticfilecontroller",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 482,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65695",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.979Z",
      "date_published": "2026-07-23T16:20:44.117Z",
      "date_updated": "2026-07-23T18:05:41.254Z",
      "publisher": "VulnCheck",
      "title": "Office-Word-MCP-Server 1.1.11 Path Traversal via document tools",
      "affected": {
        "vendors": [
          "GongRzhe"
        ],
        "products": [
          {
            "vendor": "GongRzhe",
            "product": "Office-Word-MCP-Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24546
      },
      "nvd": {
        "published": "2026-07-23T17:16:29.610",
        "lastModified": "2026-07-23T19:17:04.857",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65695",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An attacker-controlled path is used without confinement to the intended directory, allowing file access outside that namespace.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/Office-Word-MCP-Server.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/office-word-mcp-server-path-traversal-via-document-tools",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 514,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65696",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.979Z",
      "date_published": "2026-07-23T16:24:27.966Z",
      "date_updated": "2026-07-23T17:44:18.635Z",
      "publisher": "VulnCheck",
      "title": "Overseerr 1.35.0 Authorization Bypass via pushSubscriptions API",
      "affected": {
        "vendors": [
          "sct"
        ],
        "products": [
          {
            "vendor": "sct",
            "product": "overseerr"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.00164,
        "percentile": 0.06053
      },
      "nvd": {
        "published": "2026-07-23T17:16:29.763",
        "lastModified": "2026-07-23T18:17:01.017",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65696",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Push-subscription handlers trust an arbitrary userId path value without an ownership check, allowing one user to list, read, or delete another user's records.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/overseerr.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/overseerr-authorization-bypass-via-pushsubscriptions-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65697",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.979Z",
      "date_published": "2026-07-23T16:29:20.087Z",
      "date_updated": "2026-07-23T18:12:34.036Z",
      "publisher": "VulnCheck",
      "title": "Fathom Lite 1.3.1 Stored XSS via /collect Endpoint",
      "affected": {
        "vendors": [
          "usefathom"
        ],
        "products": [
          {
            "vendor": "usefathom",
            "product": "fathom"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.0016,
        "percentile": 0.05683
      },
      "nvd": {
        "published": "2026-07-23T17:16:29.907",
        "lastModified": "2026-07-23T19:17:05.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65697",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The fathom rendering path places attacker-controlled data into executable browser markup without context-appropriate neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/fathom.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/fathom-lite-stored-xss-via-collect-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 651,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65698",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.980Z",
      "date_published": "2026-07-23T16:37:42.944Z",
      "date_updated": "2026-07-24T22:00:16.889Z",
      "publisher": "VulnCheck",
      "title": "Void 1.3.4 Path Traversal via AI Agent File-Reading Tools",
      "affected": {
        "vendors": [
          "voideditor"
        ],
        "products": [
          {
            "vendor": "voideditor",
            "product": "void"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00347,
        "percentile": 0.27393
      },
      "nvd": {
        "published": "2026-07-23T17:16:30.050",
        "lastModified": "2026-07-24T23:16:51.503",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65698",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "AI file-reading tools accept absolute paths and file URIs without confining resolution to the open workspace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/void.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/void-path-traversal-via-ai-agent-file-reading-tools",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 549,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65699",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.980Z",
      "date_published": "2026-07-23T16:59:46.107Z",
      "date_updated": "2026-07-23T18:17:32.104Z",
      "publisher": "VulnCheck",
      "title": "AgentGPT 1.0.0 Authorization Bypass via Agent Task Creation",
      "affected": {
        "vendors": [
          "reworkd"
        ],
        "products": [
          {
            "vendor": "reworkd",
            "product": "AgentGPT"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.2,
      "cvss_source_score_spread": 1.9000000000000004,
      "epss": {
        "score": 0.00222,
        "percentile": 0.12816
      },
      "nvd": {
        "published": "2026-07-23T18:17:01.153",
        "lastModified": "2026-07-23T19:17:05.160",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65699",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The AgentGPT request path accepts an attacker-selected object identifier without binding that object to the caller's tenant, owner, or permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/AgentGPT.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/agentgpt-authorization-bypass-via-agent-task-creation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 586,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65700",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.980Z",
      "date_published": "2026-07-23T17:02:24.458Z",
      "date_updated": "2026-07-27T16:19:50.766Z",
      "publisher": "VulnCheck",
      "title": "h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API",
      "affected": {
        "vendors": [
          "h2oai"
        ],
        "products": [
          {
            "vendor": "h2oai",
            "product": "h2ogpt"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.01269,
        "percentile": 0.66911
      },
      "nvd": {
        "published": "2026-07-23T18:17:01.327",
        "lastModified": "2026-07-27T17:16:40.310",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65700",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "h2oGPT uses the bearer token as an unsanitized path component, allowing file API operations to escape the intended user directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/h2ogpt.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/h2ogpt-path-traversal-via-openai-compatible-files-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 690,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65701",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.980Z",
      "date_published": "2026-07-23T17:05:47.594Z",
      "date_updated": "2026-07-23T18:04:13.633Z",
      "publisher": "VulnCheck",
      "title": "SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route",
      "affected": {
        "vendors": [
          "svc-develop-team"
        ],
        "products": [
          {
            "vendor": "svc-develop-team",
            "product": "so-vits-svc"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00582,
        "percentile": 0.44537
      },
      "nvd": {
        "published": "2026-07-23T18:17:01.480",
        "lastModified": "2026-07-23T19:17:05.310",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65701",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the audio_path field of an unauthenticated POST request to the /wav2wav route.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/so-vits-svc.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/softvc-vits-singing-voice-conversion-path-traversal-via-wav2wav-flask-route",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 643,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65702",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.980Z",
      "date_published": "2026-07-23T17:09:37.574Z",
      "date_updated": "2026-07-23T17:43:42.379Z",
      "publisher": "VulnCheck",
      "title": "Vanna 2.0.2 Path Traversal via FileSystemConversationStore",
      "affected": {
        "vendors": [
          "vanna-ai"
        ],
        "products": [
          {
            "vendor": "vanna-ai",
            "product": "vanna"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00487,
        "percentile": 0.39336
      },
      "nvd": {
        "published": "2026-07-23T18:17:01.630",
        "lastModified": "2026-07-23T18:26:28.517",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65702",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FileSystemConversationStore joins an attacker-controlled conversation_id without containing the result under its base directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/vanna.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/vanna-path-traversal-via-filesystemconversationstore",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 631,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65703",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.980Z",
      "date_published": "2026-07-23T18:52:19.441Z",
      "date_updated": "2026-07-28T01:06:11.716Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10902
      },
      "nvd": {
        "published": "2026-07-23T20:17:21.803",
        "lastModified": "2026-07-27T20:34:24.887",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65703",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "tdsc_parse_tdsf() keeps an undersized reference frame across a dimension change, so later pixel conversion writes beyond that frame's heap buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 554,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65704",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.981Z",
      "date_published": "2026-07-23T18:55:41.842Z",
      "date_updated": "2026-07-28T01:06:12.410Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02681
      },
      "nvd": {
        "published": "2026-07-23T20:17:21.973",
        "lastModified": "2026-07-27T20:34:24.887",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65704",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FFmpeg subtracts an attacker-influenced value without rejecting underflow and uses the wrapped result in a memory operation.",
        "basis": [
          "CNA",
          "CWE-191",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 527,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65705",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.981Z",
      "date_published": "2026-07-23T19:00:36.133Z",
      "date_updated": "2026-07-28T01:06:13.065Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame()",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-131",
          "name": "Incorrect Calculation of Buffer Size",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03223
      },
      "nvd": {
        "published": "2026-07-23T20:17:22.120",
        "lastModified": "2026-07-27T20:34:24.887",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65705",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "vf_floodfill allocates its traversal stack for the initial frame dimensions and reuses it when a later frame is larger, so neighbor pushes exceed the allocation.",
        "basis": [
          "CNA",
          "CWE-131",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 623,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65706",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.981Z",
      "date_published": "2026-07-23T19:05:11.560Z",
      "date_updated": "2026-07-28T01:06:13.738Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-131",
          "name": "Incorrect Calculation of Buffer Size",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00133,
        "percentile": 0.03222
      },
      "nvd": {
        "published": "2026-07-23T20:17:22.257",
        "lastModified": "2026-07-27T20:34:24.887",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65706",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "vf_swaprect reuses a temporary row buffer sized for the one-byte luma plane when copying the two-byte interleaved chroma plane.",
        "basis": [
          "CNA",
          "CWE-131",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 569,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65707",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.981Z",
      "date_published": "2026-07-24T15:43:35.413Z",
      "date_updated": "2026-07-28T01:06:14.405Z",
      "publisher": "VulnCheck",
      "title": "Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint",
      "affected": {
        "vendors": [
          "likeadmin-likeshop"
        ],
        "products": [
          {
            "vendor": "likeadmin-likeshop",
            "product": "likeshop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18357
      },
      "nvd": {
        "published": "2026-07-24T17:17:34.290",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65707",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "adjustAccount concatenates money, integral, growth, and earnings values into Db::raw SQL fragments without validation or binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/peoz14/794521dc40f5bb7e6a6ec6630d894be6",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/likeshop-authenticated-sql-injection-via-adjustaccount-endpoint",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 568,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65708",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.981Z",
      "date_published": "2026-07-24T15:57:26.326Z",
      "date_updated": "2026-07-28T01:06:15.083Z",
      "publisher": "VulnCheck",
      "title": "sysPass 3.2.11 Insecure Direct Object Reference via AccountFileController",
      "affected": {
        "vendors": [
          "nuxsmin"
        ],
        "products": [
          {
            "vendor": "nuxsmin",
            "product": "sysPass"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00221,
        "percentile": 0.12767
      },
      "nvd": {
        "published": "2026-07-24T17:17:34.433",
        "lastModified": "2026-07-27T20:36:13.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65708",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AccountFileController accepts a numeric attachment ID without checking the caller's ACL on the owning account.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Caycon/cve-advisories/blob/main/2026/sysPass/CVE-2026-65708.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/syspass-insecure-direct-object-reference-via-accountfilecontroller",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 507,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65709",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.981Z",
      "date_published": "2026-07-24T15:59:26.627Z",
      "date_updated": "2026-07-28T01:06:15.783Z",
      "publisher": "VulnCheck",
      "title": "sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API",
      "affected": {
        "vendors": [
          "nuxsmin"
        ],
        "products": [
          {
            "vendor": "nuxsmin",
            "product": "sysPass"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0.3999999999999986,
      "epss": {
        "score": 0.00223,
        "percentile": 0.13029
      },
      "nvd": {
        "published": "2026-07-24T17:17:34.573",
        "lastModified": "2026-07-27T20:36:13.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65709",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "JSON-RPC AccountController methods act on caller-selected account IDs without applying AccountFilterUser to bind each account to the token's permitted scope.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Caycon/cve-advisories/blob/main/2026/sysPass/CVE-2026-65709.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/syspass-missing-object-level-authorization-via-json-rpc-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 500,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65710",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.982Z",
      "date_published": "2026-07-24T16:00:50.584Z",
      "date_updated": "2026-07-28T01:06:16.444Z",
      "publisher": "VulnCheck",
      "title": "sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption",
      "affected": {
        "vendors": [
          "nuxsmin"
        ],
        "products": [
          {
            "vendor": "nuxsmin",
            "product": "sysPass"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00178,
        "percentile": 0.07505
      },
      "nvd": {
        "published": "2026-07-24T17:17:34.713",
        "lastModified": "2026-07-27T20:36:13.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65710",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Public-link creation decrypts the account selected by caller-controlled ID without applying the selected account ACL.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Caycon/cve-advisories/blob/main/2026/sysPass/CVE-2026-65710.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/syspass-missing-authorization-via-publiclinkcontroller-account-decryption",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 718,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65711",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:26:09.982Z",
      "date_published": "2026-07-24T16:12:57.797Z",
      "date_updated": "2026-07-28T01:06:17.122Z",
      "publisher": "VulnCheck",
      "title": "sysPass 3.2.11 Authenticated OS Command Injection via Backup Path",
      "affected": {
        "vendors": [
          "nuxsmin"
        ],
        "products": [
          {
            "vendor": "nuxsmin",
            "product": "sysPass"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.02406,
        "percentile": 0.82436
      },
      "nvd": {
        "published": "2026-07-24T17:17:34.857",
        "lastModified": "2026-07-27T20:36:13.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65711",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FileBackupService concatenates the configured backup path into a tar command and passes it to exec without shell escaping.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://gist.github.com/sermikr0/16bcbc799dc33d39d5714db9bbcbdb77",
          "host": "gist.github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/syspass-authenticated-os-command-injection-via-backup-path",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 536,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65712",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:27:32.365Z",
      "date_published": "2026-07-23T09:11:52.342Z",
      "date_updated": "2026-07-25T05:32:00.664Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "CDN for Joomla Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00145,
        "percentile": 0.04258
      },
      "nvd": {
        "published": "2026-07-23T10:16:52.820",
        "lastModified": "2026-07-24T20:18:19.980",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65712",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The file operation in CDN for Joomla Pro extension for Joomla uses an attacker-controlled path without confining the resolved object to the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 216,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:27:32.366Z",
      "date_published": "2026-07-23T09:15:13.463Z",
      "date_updated": "2026-07-25T05:35:22.795Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Modals Pro extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00224,
        "percentile": 0.13079
      },
      "nvd": {
        "published": "2026-07-23T10:16:52.930",
        "lastModified": "2026-07-24T20:18:20.123",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65713",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Modals Pro extension for Joomla allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 146,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-23T09:13:56.352Z",
      "date_updated": "2026-07-29T05:39:51.063Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "ReReplacer PRo extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26109
      },
      "nvd": {
        "published": "2026-07-23T10:16:53.037",
        "lastModified": "2026-07-28T16:20:09.080",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65754",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ReReplacer accepts an XML include path that resolves outside the Joomla site directory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 163,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-23T09:14:11.923Z",
      "date_updated": "2026-07-29T05:40:11.634Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Articles Anywhere extension for Joomla"
          },
          {
            "vendor": "regularlabs.com",
            "product": "Users Anywhere extension for Joomla"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-524",
          "name": "Use of Cache Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15774
      },
      "nvd": {
        "published": "2026-07-23T10:16:53.143",
        "lastModified": "2026-07-28T16:20:09.810",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65755",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The query-cache key omits a bounded time component, allowing an old result to remain valid after a publication or expiry boundary.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-524"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-23T09:11:48.636Z",
      "date_updated": "2026-07-24T07:17:56.388Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Keyboard Shortcuts extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04573
      },
      "nvd": {
        "published": "2026-07-23T10:16:53.253",
        "lastModified": "2026-07-23T20:17:22.407",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65756",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Shortcut configuration accepts attacker-controlled inline JavaScript and executes it in the application context.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 142,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65757",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-23T09:14:12.872Z",
      "date_updated": "2026-07-25T05:34:17.823Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension",
      "affected": {
        "vendors": [
          "regularlabs.com"
        ],
        "products": [
          {
            "vendor": "regularlabs.com",
            "product": "Modules Anywhere extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03059
      },
      "nvd": {
        "published": "2026-07-23T10:16:53.353",
        "lastModified": "2026-07-24T20:18:20.277",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65757",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Modules Anywhere editor popup returns restricted module data without consistently enforcing module permission and request-token checks.",
        "basis": [
          "CNA",
          "CWE-284",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://regularlabs.com/",
          "host": "regularlabs.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 259,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65758",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-23T09:24:44.471Z",
      "date_updated": "2026-07-24T07:16:36.665Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2",
      "affected": {
        "vendors": [
          "tassos.gr"
        ],
        "products": [
          {
            "vendor": "tassos.gr",
            "product": "Convert Forms extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09615
      },
      "nvd": {
        "published": "2026-07-23T10:16:53.467",
        "lastModified": "2026-07-23T20:17:22.560",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65758",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Convert Forms exposes its front-end Submissions view without enforcing the access control required to list form submissions.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.tassos.gr/joomla-extensions/convert-forms",
          "host": "www.tassos.gr",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 228,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65759",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-23T16:42:54.627Z",
      "date_updated": "2026-07-24T07:20:09.614Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1",
      "affected": {
        "vendors": [
          "joomshaper.com"
        ],
        "products": [
          {
            "vendor": "joomshaper.com",
            "product": "Easy Store extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00257,
        "percentile": 0.17282
      },
      "nvd": {
        "published": "2026-07-23T17:16:30.190",
        "lastModified": "2026-07-23T20:17:22.667",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65759",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Easy Store accepts client-supplied payment and order states without binding them to a server-verified payment result or order owner.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomshaper.com/easystore",
          "host": "www.joomshaper.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/easystore-security-disclosure/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 303,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65760",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-23T16:38:21.882Z",
      "date_updated": "2026-07-24T07:15:33.699Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1",
      "affected": {
        "vendors": [
          "joomshaper.com"
        ],
        "products": [
          {
            "vendor": "joomshaper.com",
            "product": "Easy Store extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.1628
      },
      "nvd": {
        "published": "2026-07-23T17:16:30.310",
        "lastModified": "2026-07-23T20:17:22.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65760",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomshaper.com/easystore",
          "host": "www.joomshaper.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/easystore-security-disclosure/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 246,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65761",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-23T16:38:58.787Z",
      "date_updated": "2026-07-24T07:16:11.356Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1",
      "affected": {
        "vendors": [
          "joomshaper.com"
        ],
        "products": [
          {
            "vendor": "joomshaper.com",
            "product": "Easy Store extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.1476
      },
      "nvd": {
        "published": "2026-07-23T17:16:30.433",
        "lastModified": "2026-07-23T20:17:22.897",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65761",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "EasyStore returns an unchecked filter_sortby direction from FilterHelper.php and concatenates it into ProductsModel.php's ORDER BY clause.",
        "basis": [
          "CNA",
          "CWE-89",
          "https://mysites.guru/blog/easystore-security-disclosure/"
        ],
        "deepDive": true,
        "notes": "Reviewed https://mysites.guru/blog/easystore-security-disclosure/. The discoverer's report identifies filter_sortby, FilterHelper.php:741, ProductsModel.php:923, and the ASC/DESC allowlist fix, but the proprietary source was not independently inspected."
      },
      "references": [
        {
          "url": "https://www.joomshaper.com/easystore",
          "host": "www.joomshaper.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/easystore-security-disclosure/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 263,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65762",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-23T17:01:04.967Z",
      "date_updated": "2026-07-24T07:20:31.602Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0",
      "affected": {
        "vendors": [
          "phoca.cz"
        ],
        "products": [
          {
            "vendor": "phoca.cz",
            "product": "Phoca Guestbook extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26488
      },
      "nvd": {
        "published": "2026-07-23T18:17:01.903",
        "lastModified": "2026-07-24T08:16:27.293",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65762",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled content reaches an HTML, SVG or DOM output context without context-appropriate escaping, so the browser can interpret it as active script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.phoca.cz/phocaguestbook",
          "host": "www.phoca.cz",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 165,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65763",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-23T16:57:49.345Z",
      "date_updated": "2026-07-24T07:17:15.853Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4",
      "affected": {
        "vendors": [
          "phoca.cz"
        ],
        "products": [
          {
            "vendor": "phoca.cz",
            "product": "Phoca Maps extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26489
      },
      "nvd": {
        "published": "2026-07-23T18:17:02.023",
        "lastModified": "2026-07-24T08:16:27.413",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65763",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.phoca.cz/phocamaps",
          "host": "www.phoca.cz",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 160,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65764",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-27T07:57:38.356Z",
      "date_updated": "2026-07-27T12:56:14.032Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.1.1",
      "affected": {
        "vendors": [
          "phoca.cz"
        ],
        "products": [
          {
            "vendor": "phoca.cz",
            "product": "Phoca Commander extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00318,
        "percentile": 0.24181
      },
      "nvd": {
        "published": "2026-07-27T09:16:37.790",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65764",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Phoca Commander extension for Joomla page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.phoca.cz/phocacommander",
          "host": "www.phoca.cz",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 165,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65765",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-27T08:01:19.270Z",
      "date_updated": "2026-07-27T12:59:43.593Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.1",
      "affected": {
        "vendors": [
          "phoca.cz"
        ],
        "products": [
          {
            "vendor": "phoca.cz",
            "product": "Phoca Commander extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00347,
        "percentile": 0.2736
      },
      "nvd": {
        "published": "2026-07-27T09:16:37.923",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65765",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Phoca Commander save and download actions do not confine caller-selected paths to their intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.phoca.cz/phocacommander",
          "host": "www.phoca.cz",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 190,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65766",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T20:46:13.953Z",
      "date_published": "2026-07-27T12:55:11.623Z",
      "date_updated": "2026-07-28T05:31:25.460Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated SQL injection  in SP Page Builder < 6.7.1",
      "affected": {
        "vendors": [
          "joomshaper.com"
        ],
        "products": [
          {
            "vendor": "joomshaper.com",
            "product": "SP Page Builder extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.1476
      },
      "nvd": {
        "published": "2026-07-27T14:17:00.533",
        "lastModified": "2026-07-27T21:17:16.120",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65766",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input reaches an SQL statement without separation from SQL grammar.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomshaper.com/page-builder",
          "host": "www.joomshaper.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/sp-page-builder-sql-injection-mail-relay-disclosure/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 201,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65834",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T23:16:47.753Z",
      "date_published": "2026-07-30T19:48:55.027Z",
      "date_updated": "2026-07-31T11:29:43.998Z",
      "publisher": "GitHub_M",
      "title": "Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests",
      "affected": {
        "vendors": [
          "projectcapsule"
        ],
        "products": [
          {
            "vendor": "projectcapsule",
            "product": "capsule"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-248",
          "name": "Uncaught Exception",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00266,
        "percentile": 0.18625
      },
      "nvd": {
        "published": "2026-07-30T20:18:13.107",
        "lastModified": "2026-07-31T12:16:53.700",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65834",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The admission webhook accepts a malformed regex that later reaches regexp.MustCompile as an uncaught exception and terminates node admission handling.",
        "basis": [
          "CNA record",
          "CWE-248"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/projectcapsule/capsule/security/advisories/GHSA-68cj-mvg9-rgm2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/projectcapsule/capsule/releases/tag/v0.13.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 563,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65835",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T23:16:47.753Z",
      "date_published": "2026-07-30T19:53:52.769Z",
      "date_updated": "2026-07-31T19:17:25.535Z",
      "publisher": "GitHub_M",
      "title": "Capsule: Incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)",
      "affected": {
        "vendors": [
          "projectcapsule"
        ],
        "products": [
          {
            "vendor": "projectcapsule",
            "product": "capsule"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00192,
        "percentile": 0.09125
      },
      "nvd": {
        "published": "2026-07-30T20:18:13.267",
        "lastModified": "2026-07-31T20:16:53.843",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65835",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "TenantResource RawItems and Generators omit the namespaced-kind guard and let a tenant owner create cluster-scoped resources through a cluster-admin client.",
        "basis": [
          "CNA",
          "CWE-269",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/projectcapsule/capsule/security/advisories/GHSA-jr6p-8pjj-mfx6",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/projectcapsule/capsule/releases/tag/v0.13.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 602,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65841",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-22T23:16:47.753Z",
      "date_published": "2026-07-31T19:16:05.952Z",
      "date_updated": "2026-07-31T20:05:10.590Z",
      "publisher": "GitHub_M",
      "title": "Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization",
      "affected": {
        "vendors": [
          "xdan"
        ],
        "products": [
          {
            "vendor": "xdan",
            "product": "jodit"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-80",
          "name": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.003,
        "percentile": 0.22332
      },
      "nvd": {
        "published": "2026-07-31T20:16:53.967",
        "lastModified": "2026-07-31T20:16:53.967",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65841",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Jodit's denyTags filter fails to normalize SVG or MathML script node names, leaving script elements in sanitized editor content.",
        "basis": [
          "CNA",
          "CWE-80"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/xdan/jodit/security/advisories/GHSA-45qg-252v-3f7p",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/xdan/jodit/commit/49a31f451f6b686f5610022a1d4406ee85138dc5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/xdan/jodit/releases/tag/4.13.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 349,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65876",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.408Z",
      "date_published": "2026-07-27T13:00:48.354Z",
      "date_updated": "2026-07-28T05:37:01.282Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated SQL injection  in SP Page Builder < 6.7.1",
      "affected": {
        "vendors": [
          "joomshaper.com"
        ],
        "products": [
          {
            "vendor": "joomshaper.com",
            "product": "SP Page Builder extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00228,
        "percentile": 0.13624
      },
      "nvd": {
        "published": "2026-07-27T14:17:00.680",
        "lastModified": "2026-07-27T21:17:16.230",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65876",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SP Page Builder inserts the unauthenticated loadMoreArticles catid parameter into an SQL query without the required validation or parameter binding.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomshaper.com/page-builder",
          "host": "www.joomshaper.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65877",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.409Z",
      "date_published": "2026-07-27T12:56:06.965Z",
      "date_updated": "2026-07-28T05:32:24.083Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomshaper.com - Authenticated SQL injection  in SP Page Builder < 6.7.1",
      "affected": {
        "vendors": [
          "joomshaper.com"
        ],
        "products": [
          {
            "vendor": "joomshaper.com",
            "product": "SP Page Builder extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13449
      },
      "nvd": {
        "published": "2026-07-27T14:17:00.823",
        "lastModified": "2026-07-27T21:17:16.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65877",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled query text is concatenated into an SQL statement without parameter binding or equivalent grammar separation.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomshaper.com/page-builder",
          "host": "www.joomshaper.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/sp-page-builder-sql-injection-mail-relay-disclosure/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 213,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65878",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.409Z",
      "date_published": "2026-07-27T12:54:54.589Z",
      "date_updated": "2026-07-28T05:31:08.139Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1",
      "affected": {
        "vendors": [
          "joomshaper.com"
        ],
        "products": [
          {
            "vendor": "joomshaper.com",
            "product": "SP Page Builder extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00325,
        "percentile": 0.24973
      },
      "nvd": {
        "published": "2026-07-27T14:17:00.960",
        "lastModified": "2026-07-27T21:17:16.457",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65878",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SP Page Builder accepts a media path outside its intended namespace and deletes the selected file without sufficient path or ACL validation.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomshaper.com/page-builder",
          "host": "www.joomshaper.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/sp-page-builder-sql-injection-mail-relay-disclosure/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 192,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65879",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.409Z",
      "date_published": "2026-07-27T12:55:19.542Z",
      "date_updated": "2026-07-29T05:35:53.282Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1",
      "affected": {
        "vendors": [
          "joomshaper.com"
        ],
        "products": [
          {
            "vendor": "joomshaper.com",
            "product": "SP Page Builder extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-798",
          "name": "Use of Hard-coded Credentials",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00284,
        "percentile": 0.2068
      },
      "nvd": {
        "published": "2026-07-27T14:17:01.103",
        "lastModified": "2026-07-28T16:20:10.530",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65879",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SP Page Builder extension for Joomla path relies on one hard-coded product-wide secret that any observer can reuse to forge trusted requests.",
        "basis": [
          "CNA",
          "CWE-798"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomshaper.com/page-builder",
          "host": "www.joomshaper.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/sp-page-builder-sql-injection-mail-relay-disclosure/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 206,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65880",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.409Z",
      "date_published": "2026-07-28T10:27:16.149Z",
      "date_updated": "2026-07-28T12:34:03.658Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Balbooa Forms component for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00456,
        "percentile": 0.37344
      },
      "nvd": {
        "published": "2026-07-28T11:17:04.233",
        "lastModified": "2026-07-28T16:17:16.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65880",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A form containing the signature field can reach code execution, but the public material does not identify the value-to-code transformation.",
        "basis": [
          "CNA",
          "CWE-94",
          "https://www.balbooa.com/joomla-forms"
        ],
        "deepDive": true,
        "notes": "The only linked first-party page is a product page that contains no advisory, patch, or vulnerable code; it adds no mechanism beyond the CNA statement that signature-field form processing can execute code."
      },
      "references": [
        {
          "url": "https://www.balbooa.com/joomla-forms",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 203,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65881",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.409Z",
      "date_published": "2026-07-28T12:38:21.817Z",
      "date_updated": "2026-07-29T05:41:34.671Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1",
      "affected": {
        "vendors": [
          "joomdle.com"
        ],
        "products": [
          {
            "vendor": "joomdle.com",
            "product": "Joomdle component for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00245,
        "percentile": 0.15773
      },
      "nvd": {
        "published": "2026-07-28T13:19:06.207",
        "lastModified": "2026-07-28T20:17:27.910",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65881",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The default Joomdle component for Joomla configuration grants broader access or searches a broader authority scope than a secure deployment requires.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-1188"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomdle.com/",
          "host": "www.joomdle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 221,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65882",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.409Z",
      "date_published": "2026-07-28T12:35:06.238Z",
      "date_updated": "2026-07-29T05:38:09.278Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1",
      "affected": {
        "vendors": [
          "joomdle.com"
        ],
        "products": [
          {
            "vendor": "joomdle.com",
            "product": "Joomdle component for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.0458
      },
      "nvd": {
        "published": "2026-07-28T13:19:06.330",
        "lastModified": "2026-07-28T20:17:28.057",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65882",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Joomdle reflects the goto URL parameter into browser markup without the required output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomdle.com/",
          "host": "www.joomdle.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 167,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65883",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.409Z",
      "date_published": "2026-07-29T09:34:14.491Z",
      "date_updated": "2026-07-29T14:39:53.741Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0",
      "affected": {
        "vendors": [
          "aimy-extensions.com"
        ],
        "products": [
          {
            "vendor": "aimy-extensions.com",
            "product": "Aimy Captcha-Less Form Guard plugin for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00499,
        "percentile": 0.40034
      },
      "nvd": {
        "published": "2026-07-29T11:16:50.297",
        "lastModified": "2026-07-30T14:06:56.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65883",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.aimy-extensions.com/joomla/captcha-less-form-guard.html",
          "host": "www.aimy-extensions.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 202,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65884",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.409Z",
      "date_published": "2026-07-29T12:09:08.021Z",
      "date_updated": "2026-07-30T05:31:33.288Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Gridbox extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16281
      },
      "nvd": {
        "published": "2026-07-29T13:19:10.677",
        "lastModified": "2026-07-30T14:06:56.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65884",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gridbox accepts a caller-supplied user-group ID during registration and can assign a new account to the administrator group.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.balbooa.com/gridbox",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 226,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65885",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.409Z",
      "date_published": "2026-07-29T12:05:48.262Z",
      "date_updated": "2026-07-30T05:27:40.484Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Gridbox extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00251,
        "percentile": 0.1657
      },
      "nvd": {
        "published": "2026-07-29T13:19:10.820",
        "lastModified": "2026-07-30T14:06:56.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65885",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The upload path accepts attacker-controlled file content or names without enforcing the intended storage and executable-content boundary.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.balbooa.com/gridbox",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 288,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65886",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.409Z",
      "date_published": "2026-07-29T13:58:16.967Z",
      "date_updated": "2026-07-29T17:43:40.646Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Gridbox extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0036,
        "percentile": 0.28678
      },
      "nvd": {
        "published": "2026-07-29T15:16:28.467",
        "lastModified": "2026-07-30T14:06:56.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65886",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled path or object-name data is resolved without proving that the final target remains inside the intended namespace.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.balbooa.com/gridbox",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 165,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65887",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.409Z",
      "date_published": "2026-07-29T13:58:23.450Z",
      "date_updated": "2026-08-01T05:42:06.840Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in  Gridbox < 2.20.2",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Gridbox extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16282
      },
      "nvd": {
        "published": "2026-07-29T15:16:28.613",
        "lastModified": "2026-07-31T16:17:09.737",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65887",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gridbox exposes resetPassword without authenticating the requester or binding the requested account to an authorized reset grant.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.balbooa.com/gridbox",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 229,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65888",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.409Z",
      "date_published": "2026-07-29T13:59:27.209Z",
      "date_updated": "2026-08-01T05:43:09.873Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Gridbox extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.16281
      },
      "nvd": {
        "published": "2026-07-29T15:16:28.813",
        "lastModified": "2026-07-31T16:17:09.887",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65888",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Gridbox socialLogin accepts a selected user identity without proving that the caller controls that account.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.balbooa.com/gridbox",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 169,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65889",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.410Z",
      "date_published": "2026-07-29T13:54:52.621Z",
      "date_updated": "2026-07-29T14:51:25.322Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Gridbox extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/AU:Y"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00323,
        "percentile": 0.24779
      },
      "nvd": {
        "published": "2026-07-29T14:16:33.757",
        "lastModified": "2026-07-30T14:06:56.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65889",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "generateNewApp accepts a path that can escape the intended Gridbox directory and recursively deletes the selected target.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.balbooa.com/gridbox",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 163,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65890",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:17:01.410Z",
      "date_published": "2026-07-29T13:56:21.373Z",
      "date_updated": "2026-07-29T14:53:17.004Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Gridbox extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security@joomla.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.1476
      },
      "nvd": {
        "published": "2026-07-29T14:16:33.883",
        "lastModified": "2026-07-30T14:06:56.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65890",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Gridbox incorporates unauthenticated request values into SQL without preserving the query grammar boundary.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.balbooa.com/gridbox",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 161,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65891",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T09:31:17.506Z",
      "date_published": "2026-07-29T12:37:47.658Z",
      "date_updated": "2026-07-31T05:43:27.735Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.9.99.10",
      "affected": {
        "vendors": [
          "joomlacontenteditor.net"
        ],
        "products": [
          {
            "vendor": "joomlacontenteditor.net",
            "product": "Joomla Content Editor (JCE) extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00195,
        "percentile": 0.09481
      },
      "nvd": {
        "published": "2026-07-29T13:19:10.980",
        "lastModified": "2026-07-30T14:17:03.483",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65891",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The rename function accepts otherwise invalid destination names and does not prevent selection of hidden names or an already existing destination file.",
        "basis": [
          "CNA",
          "CWE-20"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.joomlacontenteditor.net/",
          "host": "www.joomlacontenteditor.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 464,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65893",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T10:19:33.207Z",
      "date_published": "2026-07-27T07:12:43.940Z",
      "date_updated": "2026-07-27T10:37:56.515Z",
      "publisher": "CERT-In",
      "title": "Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera",
      "affected": {
        "vendors": [
          "CP-Plus"
        ],
        "products": [
          {
            "vendor": "CP-Plus",
            "product": "EZ-P21 IP Camera"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-489",
          "name": "Active Debug Code",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vdisclose@cert-in.org.in",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00158,
        "percentile": 0.05477
      },
      "nvd": {
        "published": "2026-07-27T08:16:23.010",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65893",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Production firmware leaves a debug execution mechanism enabled for code placed on removable media.",
        "basis": [
          "CNA",
          "CWE-489"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0380",
          "host": "www.cert-in.org.in",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 431,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65894",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T10:19:33.207Z",
      "date_published": "2026-07-27T07:16:33.504Z",
      "date_updated": "2026-07-27T10:25:55.518Z",
      "publisher": "CERT-In",
      "title": "Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera",
      "affected": {
        "vendors": [
          "CP-Plus"
        ],
        "products": [
          {
            "vendor": "CP-Plus",
            "product": "EZ-P21 IP Camera"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-307",
          "name": "Improper Restriction of Excessive Authentication Attempts",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:vdisclose@cert-in.org.in",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00378,
        "percentile": 0.30527
      },
      "nvd": {
        "published": "2026-07-27T08:16:23.157",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65894",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The camera's HTTP authentication endpoint permits effectively unbounded password attempts and can be brute-forced remotely.",
        "basis": [
          "CNA",
          "CWE-307"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0380",
          "host": "www.cert-in.org.in",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 385,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65895",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T11:03:13.092Z",
      "date_published": "2026-07-23T11:42:16.163Z",
      "date_updated": "2026-07-24T21:35:22.367Z",
      "publisher": "VulnCheck",
      "title": "Grav API Plugin before 1.0.10 Broken Access Control",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00234,
        "percentile": 0.14439
      },
      "nvd": {
        "published": "2026-07-23T12:18:47.910",
        "lastModified": "2026-07-23T15:13:11.420",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65895",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Grav accepts api.config.write for rate-limit and CORS namespaces even though those security-critical settings require a stronger configuration authority.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-4pqv-2qj5-38fp",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/commit/f9438d4e71389b1041ac60b69b0b5714ecfa3bdd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-api-plugin-before-broken-access-control",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 406,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65896",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T11:03:13.092Z",
      "date_published": "2026-07-23T11:42:16.817Z",
      "date_updated": "2026-07-24T21:35:23.057Z",
      "publisher": "VulnCheck",
      "title": "Grav API Plugin before 1.0.10 Path Traversal via move",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00267,
        "percentile": 0.18646
      },
      "nvd": {
        "published": "2026-07-23T12:18:48.050",
        "lastModified": "2026-07-23T15:13:11.420",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65896",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "grav allows attacker-controlled path or filename components to escape the intended directory or select a different file object than the operation was authorized to access.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-qjq4-jp55-4mx2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/commit/f9438d4e71389b1041ac60b69b0b5714ecfa3bdd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-api-plugin-before-path-traversal-via-move",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 591,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65897",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T11:03:13.092Z",
      "date_published": "2026-07-23T11:42:17.453Z",
      "date_updated": "2026-07-24T21:35:23.723Z",
      "publisher": "VulnCheck",
      "title": "Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00361,
        "percentile": 0.28797
      },
      "nvd": {
        "published": "2026-07-23T12:18:48.180",
        "lastModified": "2026-07-23T16:17:54.233",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65897",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "InvitationsController accepts arbitrary groups from an api.users.write caller without checking whether the inviter may grant each group's authority.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-m86m-jjcg-gcvv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/commit/f9438d4e71389b1041ac60b69b0b5714ecfa3bdd",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/getgrav/grav/commit/345e79e3abf8c15f80e612a09f6643300071324b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-api-plugin-privilege-escalation-via-invitations-groups",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 414,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65898",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T11:03:13.092Z",
      "date_published": "2026-07-23T13:16:17.715Z",
      "date_updated": "2026-07-23T15:47:13.882Z",
      "publisher": "VulnCheck",
      "title": "DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 2.1000000000000005,
      "epss": {
        "score": 0.00167,
        "percentile": 0.06304
      },
      "nvd": {
        "published": "2026-07-23T14:18:04.517",
        "lastModified": "2026-07-28T15:54:05.790",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65898",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DOMPurify shares the caller's ALLOWED_ATTR object instead of cloning it, allowing a hook to permanently add dangerous attributes for later content.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-cmwh-pvxp-8882",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dompurify-before-permanent-attribute-allowlist-pollution-via-setconfig",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 410,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65899",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T11:03:13.092Z",
      "date_published": "2026-07-23T13:16:18.389Z",
      "date_updated": "2026-07-27T16:20:48.288Z",
      "publisher": "VulnCheck",
      "title": "DOMPurify before 3.4.9 Trusted Types Policy State Contamination",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00231,
        "percentile": 0.13992
      },
      "nvd": {
        "published": "2026-07-23T14:18:04.683",
        "lastModified": "2026-07-28T15:53:23.400",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65899",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "clearConfig retains a Trusted Types policy and reuses it after the surrounding trust configuration has been reset.",
        "basis": [
          "CNA",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-vxr8-fq34-vvx9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/cure53/DOMPurify/commit/825e617753ac1169306a542d3174a77f717a0cf6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dompurify-before-trusted-types-policy-state-contamination",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 537,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65900",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T11:03:13.092Z",
      "date_published": "2026-07-23T13:16:19.045Z",
      "date_updated": "2026-07-23T18:02:48.345Z",
      "publisher": "VulnCheck",
      "title": "DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.0018,
        "percentile": 0.07819
      },
      "nvd": {
        "published": "2026-07-23T14:18:04.843",
        "lastModified": "2026-07-28T15:52:37.367",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65900",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DOMPurify's template scrubber does not traverse template.content after text-node normalization, leaving newly formed template expressions for downstream evaluation.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-gvmj-g25r-r7wr",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dompurify-before-template-expression-injection-via-return-dom",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 659,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65901",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T11:03:13.092Z",
      "date_published": "2026-07-23T13:16:19.721Z",
      "date_updated": "2026-07-23T13:39:31.433Z",
      "publisher": "VulnCheck",
      "title": "DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06248
      },
      "nvd": {
        "published": "2026-07-23T14:18:05.000",
        "lastModified": "2026-07-28T15:52:12.423",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65901",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DOMPurify IN_PLACE mode trusts an attacker-controlled nodeName on a live DOM object and preserves executable script children.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-x4vx-rjvf-j5p4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dompurify-cross-site-scripting-via-in-place-nodename",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 378,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65902",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T11:03:13.092Z",
      "date_published": "2026-07-23T13:16:20.528Z",
      "date_updated": "2026-07-24T21:35:25.085Z",
      "publisher": "VulnCheck",
      "title": "DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-501",
          "name": "Trust Boundary Violation",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11293
      },
      "nvd": {
        "published": "2026-07-23T14:18:05.453",
        "lastModified": "2026-07-28T15:51:48.907",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65902",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DOMPurify gives hooks direct references to module-level default allowlists, allowing one hook mutation to poison later default-config sanitization calls.",
        "basis": [
          "CNA",
          "CWE-501"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-76mc-f452-cxcm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/cure53/DOMPurify/commit/7996f1dc78eb8b7922388aed75d94a9f8fad9a36",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dompurify-before-hook-mutation-pollution-via-allowedtags",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 750,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65903",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T11:03:13.092Z",
      "date_published": "2026-07-23T13:16:21.187Z",
      "date_updated": "2026-07-23T15:35:54.823Z",
      "publisher": "VulnCheck",
      "title": "DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-697",
          "name": "Incorrect Comparison",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.002,
        "percentile": 0.10026
      },
      "nvd": {
        "published": "2026-07-23T14:18:05.903",
        "lastModified": "2026-07-28T15:51:38.570",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65903",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions.",
        "basis": [
          "CNA",
          "CWE-697"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-39q2-94rc-95cp",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dompurify-before-add-tags-function-bypasses-forbid-tags",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 315,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65904",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T11:03:13.093Z",
      "date_published": "2026-07-23T13:16:22.069Z",
      "date_updated": "2026-07-24T21:35:25.747Z",
      "publisher": "VulnCheck",
      "title": "DOMPurify through 3.3.3 Cross-Site Scripting via IN_PLACE mode",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-754",
          "name": "Improper Check for Unusual or Exceptional Conditions",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.3,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.7,
      "cvss_source_score_spread": 2.4000000000000004,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06123
      },
      "nvd": {
        "published": "2026-07-23T14:18:06.063",
        "lastModified": "2026-07-28T15:51:19.363",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65904",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A cross-realm instanceof test rejects a foreign DOM node, causing IN_PLACE mode to return the original unsanitized element.",
        "basis": [
          "CNA",
          "CWE-754"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-4w3q-35jp-p934",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dompurify-before-cross-site-scripting-via-in-place-mode",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 468,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65906",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:24:36.330Z",
      "date_published": "2026-07-23T12:24:44.489Z",
      "date_updated": "2026-07-24T03:56:18.917Z",
      "publisher": "JetBrains",
      "title": "In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "TeamCity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00404,
        "percentile": 0.33193
      },
      "nvd": {
        "published": "2026-07-23T13:16:31.733",
        "lastModified": "2026-07-24T05:16:49.090",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65906",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TeamCity's Kotlin DSL sandbox can be escaped so DSL input executes outside the intended code restrictions.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65907",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:24:36.571Z",
      "date_published": "2026-07-23T12:28:40.781Z",
      "date_updated": "2026-07-24T03:56:19.827Z",
      "publisher": "JetBrains",
      "title": "In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "TeamCity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.1,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00421,
        "percentile": 0.34674
      },
      "nvd": {
        "published": "2026-07-23T13:16:31.860",
        "lastModified": "2026-07-24T05:16:49.210",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65907",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "TeamCity permits code execution through Git VCS roots, but JetBrains' public fixed-issues surface does not disclose the input-to-code transition.",
        "basis": [
          "CNA",
          "CWE-94",
          "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "https://www.jetbrains.com/help/teamcity/teamcity-2026-1-2-release-notes.html"
        ],
        "deepDive": true,
        "notes": "JetBrains' fixed-issues page did not render the issue data during review; the 2026.1.2 release notes confirm a security fix but disclose no Git VCS root mechanism."
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 93,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65908",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:24:36.889Z",
      "date_published": "2026-07-23T12:25:02.885Z",
      "date_updated": "2026-07-24T03:56:20.785Z",
      "publisher": "JetBrains",
      "title": "In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open",
      "affected": {
        "vendors": [
          "JetBrains"
        ],
        "products": [
          {
            "vendor": "JetBrains",
            "product": "PyCharm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@jetbrains.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02696
      },
      "nvd": {
        "published": "2026-07-23T13:16:31.983",
        "lastModified": "2026-08-03T18:10:04.377",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65908",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "PyCharm executes a project-selected Python executable when an untrusted project is opened without treating that load target as untrusted code.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.jetbrains.com/privacy-security/issues-fixed/",
          "host": "www.jetbrains.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 140,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65911",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:51:09.595Z",
      "date_published": "2026-07-23T13:16:22.748Z",
      "date_updated": "2026-07-27T16:20:37.732Z",
      "publisher": "VulnCheck",
      "title": "DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00191,
        "percentile": 0.08953
      },
      "nvd": {
        "published": "2026-07-23T14:18:06.260",
        "lastModified": "2026-07-28T15:50:57.303",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65911",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A function-valued DOMPurify allow rule persists into a later sanitize call and silently authorizes tags or attributes in the wrong invocation.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-9p3w-6h5p-cv75",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dompurify-before-xss-via-add-attr-add-tags-state-leakage",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 749,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65912",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:51:09.595Z",
      "date_published": "2026-07-23T13:16:23.406Z",
      "date_updated": "2026-07-23T15:46:09.055Z",
      "publisher": "VulnCheck",
      "title": "DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07152
      },
      "nvd": {
        "published": "2026-07-23T14:18:06.417",
        "lastModified": "2026-07-28T15:50:27.430",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65912",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An ADD_ATTR predicate bypass lets a javascript URI survive sanitization and execute in the browser.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-cjmm-f4jc-qw8r",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dompurify-before-uri-validation-bypass-via-add-attr",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65913",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:51:09.595Z",
      "date_published": "2026-07-23T13:16:24.097Z",
      "date_updated": "2026-07-23T13:38:31.668Z",
      "publisher": "VulnCheck",
      "title": "DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00185,
        "percentile": 0.08309
      },
      "nvd": {
        "published": "2026-07-23T14:18:06.573",
        "lastModified": "2026-07-28T15:50:09.337",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65913",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Polluted Array.prototype attributes are mistaken for USE_PROFILES allowlist entries and let event handlers survive sanitization.",
        "basis": [
          "CNA record",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-cj63-jhhr-wcxv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dompurify-before-prototype-pollution-via-use-profiles",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 383,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65914",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:51:09.595Z",
      "date_published": "2026-07-23T13:16:24.784Z",
      "date_updated": "2026-07-23T13:57:53.241Z",
      "publisher": "VulnCheck",
      "title": "DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0.7999999999999998,
      "epss": {
        "score": 0.00166,
        "percentile": 0.06264
      },
      "nvd": {
        "published": "2026-07-23T14:18:07.057",
        "lastModified": "2026-07-28T15:49:47.713",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65914",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DOMPurify renders attacker-controlled content into a browser-interpreted context without context-appropriate encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dompurify-before-mutation-xss-via-re-contextualization",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 393,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65916",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:51:09.595Z",
      "date_published": "2026-07-23T15:53:05.934Z",
      "date_updated": "2026-07-28T01:06:17.797Z",
      "publisher": "VulnCheck",
      "title": "CyberPanel Missing Authorization in cancelBackupCreation Handler",
      "affected": {
        "vendors": [
          "usmannasir"
        ],
        "products": [
          {
            "vendor": "usmannasir",
            "product": "cyberpanel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00336,
        "percentile": 0.26214
      },
      "nvd": {
        "published": "2026-07-23T16:17:54.883",
        "lastModified": "2026-07-23T19:17:05.617",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65916",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "cancelBackupCreation accepts arbitrary domain and filename values without verifying that the selected backup belongs to the caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/usmannasir/cyberpanel/issues/1829",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/usmannasir/cyberpanel/commit/b1984603f9b0099b39bca46fea176e53b6d4d601",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cyberpanel-missing-authorization-in-cancelbackupcreation-handler",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 463,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65917",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:51:09.595Z",
      "date_published": "2026-07-23T15:59:48.986Z",
      "date_updated": "2026-07-28T01:06:18.482Z",
      "publisher": "VulnCheck",
      "title": "CyberPanel IncBackups IDOR via Sequential Backup ID",
      "affected": {
        "vendors": [
          "usmannasir"
        ],
        "products": [
          {
            "vendor": "usmannasir",
            "product": "cyberpanel"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00356,
        "percentile": 0.28355
      },
      "nvd": {
        "published": "2026-07-23T16:17:55.020",
        "lastModified": "2026-07-27T17:16:40.893",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65917",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "CyberPanel looks up incremental backups by a global sequential IncJob ID without constraining the record to the caller's authorized domain.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/usmannasir/cyberpanel/issues/1828",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/usmannasir/cyberpanel/commit/b1984603f9b0099b39bca46fea176e53b6d4d601",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cyberpanel-incbackups-idor-via-sequential-backup-id",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 680,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65918",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:51:09.596Z",
      "date_published": "2026-07-23T17:36:42.799Z",
      "date_updated": "2026-07-24T21:35:27.812Z",
      "publisher": "VulnCheck",
      "title": "PyTorch torchvision GIF Decoder Out-of-bounds Heap Read",
      "affected": {
        "vendors": [
          "pytorch"
        ],
        "products": [
          {
            "vendor": "pytorch",
            "product": "vision"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00312,
        "percentile": 0.23632
      },
      "nvd": {
        "published": "2026-07-23T18:17:02.143",
        "lastModified": "2026-07-23T19:17:05.763",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65918",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected parser reads beyond the end of an allocated buffer because the available length is not enforced.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pytorch/vision/issues/9551",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/pytorch/vision/pull/9520",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/pytorch/vision/commit/4e05dc22f5f050a9528cc0ea09ceca6cdaf8f4ed",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/pytorch-torchvision-gif-decoder-out-of-bounds-heap-read",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65919",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:51:09.596Z",
      "date_published": "2026-07-23T17:39:27.501Z",
      "date_updated": "2026-07-28T01:06:19.159Z",
      "publisher": "VulnCheck",
      "title": "Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload",
      "affected": {
        "vendors": [
          "meshery"
        ],
        "products": [
          {
            "vendor": "meshery",
            "product": "meshery"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00606,
        "percentile": 0.45616
      },
      "nvd": {
        "published": "2026-07-23T18:17:02.290",
        "lastModified": "2026-07-24T23:16:51.630",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65919",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "fileView and fileDownload pass an unauthenticated file parameter directly to os.Open without restricting absolute paths or traversal segments.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/meshery/meshery/issues/20076",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/meshery/meshery/releases/tag/v1.0.57",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/meshery/meshery/pull/20133",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/meshery/meshery/commit/ea83a26cb090b13be36c07cf24a99f8c637cc765",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/meshery-unauthenticated-arbitrary-file-read-via-fileview-and-filedownload",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65920",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T12:51:09.596Z",
      "date_published": "2026-07-23T17:43:56.238Z",
      "date_updated": "2026-07-24T21:35:29.163Z",
      "publisher": "VulnCheck",
      "title": "Diffusers Path Traversal via weight_map Arbitrary File Read",
      "affected": {
        "vendors": [
          "huggingface"
        ],
        "products": [
          {
            "vendor": "huggingface",
            "product": "diffusers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00325,
        "percentile": 0.25005
      },
      "nvd": {
        "published": "2026-07-23T18:17:02.427",
        "lastModified": "2026-07-23T19:17:05.900",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65920",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The diffusers path accepts an attacker-controlled path that can escape the intended filesystem root.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/huggingface/diffusers/issues/14175",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/huggingface/diffusers/pull/14182",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/huggingface/diffusers/commit/cee298c1f37c439a9a408396b8283a921238a1c6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/diffusers-path-traversal-via-weight-map-arbitrary-file-read",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 423,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-65921",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T13:34:38.372Z",
      "date_published": "2026-07-27T19:27:31.034Z",
      "date_updated": "2026-07-27T20:16:10.894Z",
      "publisher": "JFROG",
      "title": "Potential path traversal leading to unauthorized file writes",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00374,
        "percentile": 0.30186
      },
      "nvd": {
        "published": "2026-07-27T20:16:41.190",
        "lastModified": "2026-07-30T14:51:26.233",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65921",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Archive entries containing traversal sequences are written outside the intended build-artifact directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 164,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65922",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T13:34:38.372Z",
      "date_published": "2026-07-27T19:44:44.293Z",
      "date_updated": "2026-07-27T19:56:50.101Z",
      "publisher": "JFROG",
      "title": "Potential unauthorized modification of Artifactory internal metadata",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 1.6999999999999993,
      "epss": {
        "score": 0.00176,
        "percentile": 0.07353
      },
      "nvd": {
        "published": "2026-07-27T20:16:41.310",
        "lastModified": "2026-07-30T14:43:18.453",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65922",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The artifactory operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 311,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65923",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T13:34:38.372Z",
      "date_published": "2026-07-27T19:43:46.128Z",
      "date_updated": "2026-07-27T19:57:38.021Z",
      "publisher": "JFROG",
      "title": "Potential server-side request forgery in Artifactory Ansible repository handling",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00188,
        "percentile": 0.08617
      },
      "nvd": {
        "published": "2026-07-27T20:16:41.433",
        "lastModified": "2026-07-30T14:44:14.643",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65923",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Artifactory's Ansible repository URL validation permits an authorized repository user to direct server-side requests to unintended destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 293,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65924",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T13:34:38.372Z",
      "date_published": "2026-07-27T19:36:35.616Z",
      "date_updated": "2026-07-27T20:00:35.816Z",
      "publisher": "JFROG",
      "title": "Server-Side Request Forgery (SSRF) via Terraform Remote repository",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00215,
        "percentile": 0.12018
      },
      "nvd": {
        "published": "2026-07-27T20:16:41.553",
        "lastModified": "2026-07-30T14:44:38.863",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65924",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record says artifactory accepts a request across an unintended network or origin boundary, while the request field and validation step are not public.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 346,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65925",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T13:34:38.372Z",
      "date_published": "2026-07-27T19:35:17.879Z",
      "date_updated": "2026-07-27T20:03:14.377Z",
      "publisher": "JFROG",
      "title": "Server-Side Request Forgery (SSRF) via JFrog Artifactory Cargo remote repository",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00209,
        "percentile": 0.1113
      },
      "nvd": {
        "published": "2026-07-27T20:16:41.677",
        "lastModified": "2026-07-30T14:45:18.260",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65925",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Artifactory Cargo remote repositories accept a destination URL that can make the server fetch and return unintended resources.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 137,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-65943",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T16:45:51.220Z",
      "date_published": "2026-07-29T12:39:32.715Z",
      "date_updated": "2026-07-29T17:41:24.347Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0",
      "affected": {
        "vendors": [
          "rolandd.com"
        ],
        "products": [
          {
            "vendor": "rolandd.com",
            "product": "RO CSVI extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14165
      },
      "nvd": {
        "published": "2026-07-29T13:19:11.087",
        "lastModified": "2026-07-30T14:06:56.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65943",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation does not bind the requested object, action, or privilege to the authenticated caller's permitted scope.",
        "basis": [
          "CNA",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": "The public record supports the family and impact but does not identify the failing check, parser rule, resource, or state transition."
      },
      "references": [
        {
          "url": "https://rolandd.com/products/ro-csvi",
          "host": "rolandd.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 84,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65944",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T16:45:51.220Z",
      "date_published": "2026-07-29T12:40:29.246Z",
      "date_updated": "2026-07-31T05:46:05.625Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0",
      "affected": {
        "vendors": [
          "rolandd.com"
        ],
        "products": [
          {
            "vendor": "rolandd.com",
            "product": "RO CSVI extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03057
      },
      "nvd": {
        "published": "2026-07-29T13:19:11.190",
        "lastModified": "2026-07-30T14:17:03.647",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65944",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The record identifies cross-site request forgery in RO CSVI AJAX handlers, but does not publish the affected action or missing request check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://rolandd.com/products/ro-csvi",
          "host": "rolandd.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 88,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65946",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T17:02:52.157Z",
      "date_published": "2026-07-29T12:38:01.153Z",
      "date_updated": "2026-07-29T14:50:58.298Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0",
      "affected": {
        "vendors": [
          "rolandd.com"
        ],
        "products": [
          {
            "vendor": "rolandd.com",
            "product": "RO CSVI extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00149,
        "percentile": 0.04577
      },
      "nvd": {
        "published": "2026-07-29T13:19:11.293",
        "lastModified": "2026-07-30T14:06:56.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65946",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://rolandd.com/products/ro-csvi",
          "host": "rolandd.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 87,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65947",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T17:02:52.158Z",
      "date_published": "2026-07-29T14:00:50.372Z",
      "date_updated": "2026-07-31T05:49:36.354Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Gridbox extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00126,
        "percentile": 0.02702
      },
      "nvd": {
        "published": "2026-07-29T15:16:29.500",
        "lastModified": "2026-07-30T19:18:35.687",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65947",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Gridbox has multiple CSRF paths in its administrative interface, but the public record does not identify the state-changing actions or failed request-origin checks.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.balbooa.com/gridbox",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 96,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-65975",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T18:15:14.581Z",
      "date_published": "2026-07-29T20:06:09.177Z",
      "date_updated": "2026-07-30T13:54:35.306Z",
      "publisher": "GitHub_M",
      "title": "Pydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute when a trailing message is dropped during `sanitize_messages`",
      "affected": {
        "vendors": [
          "pydantic"
        ],
        "products": [
          {
            "vendor": "pydantic",
            "product": "pydantic-ai"
          },
          {
            "vendor": "pydantic",
            "product": "pydantic-ai-slim"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00207,
        "percentile": 0.10995
      },
      "nvd": {
        "published": "2026-07-29T21:17:47.723",
        "lastModified": "2026-08-04T12:43:40.373",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-65975",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "sanitize_messages records the tail index before dropping an empty trailing message, so a preceding unverified tool call becomes the new tail and executes.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-jpr8-2v3g-wgf9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "x_refsource_CONFIRM"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1447,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-65981",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T18:54:15.832Z",
      "date_published": "2026-07-31T21:00:02.893Z",
      "date_updated": "2026-08-04T03:56:20.209Z",
      "publisher": "GitHub_M",
      "title": "Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover",
      "affected": {
        "vendors": [
          "coturn"
        ],
        "products": [
          {
            "vendor": "coturn",
            "product": "coturn"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0025,
        "percentile": 0.16368
      },
      "nvd": {
        "published": "2026-07-31T21:17:31.857",
        "lastModified": "2026-08-04T05:16:39.933",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-65981",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Coturn authenticates a resumed mobility request as the resuming user but never binds that identity to the original allocation owner.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/coturn/coturn/security/advisories/GHSA-69wx-x7x6-pjj8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/coturn/coturn/commit/37df0513168f830a7c9ce0a411db0300fa182f05",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 979,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66004",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:22:30.642Z",
      "date_published": "2026-07-24T14:44:48.686Z",
      "date_updated": "2026-07-27T16:19:16.197Z",
      "publisher": "VulnCheck",
      "title": "BlenderMCP Path Traversal via download_polyhaven_asset API",
      "affected": {
        "vendors": [
          "ahujasid"
        ],
        "products": [
          {
            "vendor": "ahujasid",
            "product": "blender-mcp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00295,
        "percentile": 0.2182
      },
      "nvd": {
        "published": "2026-07-24T15:19:07.050",
        "lastModified": "2026-07-30T19:56:33.480",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66004",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "download_polyhaven_asset treats an API response include key as a local path without containing traversal segments to the asset directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ahujasid/blender-mcp/issues/257",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/ahujasid/blender-mcp/pull/258",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/ahujasid/blender-mcp/commit/30a3308446cd8f81a9446e5a2ed657c0d8d86072",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/blendermcp-path-traversal-via-download-polyhaven-asset-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 391,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66005",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:22:30.643Z",
      "date_published": "2026-07-24T14:57:33.054Z",
      "date_updated": "2026-07-25T10:30:04.900Z",
      "publisher": "VulnCheck",
      "title": "Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding",
      "affected": {
        "vendors": [
          "janhq"
        ],
        "products": [
          {
            "vendor": "janhq",
            "product": "jan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-183",
          "name": "Permissive List of Allowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-942",
          "name": "Permissive Cross-domain Security Policy with Untrusted Domains",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00187,
        "percentile": 0.08546
      },
      "nvd": {
        "published": "2026-07-24T15:19:07.203",
        "lastModified": "2026-07-30T20:16:05.187",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66005",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The local API replaces configured trusted hosts with a credentialed wildcard policy that reflects arbitrary web origins.",
        "basis": [
          "CNA",
          "CWE-183",
          "CWE-942"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/janhq/jan/issues/8453",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/janhq/jan/pull/8506",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/janhq/jan/commit/3e1c1e724f696620d89bb4a9cc18a380e0753757",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/jan-local-api-server-cors-origin-reflection-via-binding",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 524,
        "referenceCount": 4,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66006",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:22:30.643Z",
      "date_published": "2026-07-24T14:57:50.268Z",
      "date_updated": "2026-07-28T01:06:19.820Z",
      "publisher": "VulnCheck",
      "title": "lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs",
      "affected": {
        "vendors": [
          "treeverse"
        ],
        "products": [
          {
            "vendor": "treeverse",
            "product": "lakeFS"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23935
      },
      "nvd": {
        "published": "2026-07-24T15:19:07.353",
        "lastModified": "2026-07-30T15:45:04.190",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-66006",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The setup_comm_prefs endpoint remains callable without authentication after setup and permits operator-metadata changes.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/treeverse/lakeFS/issues/10465",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Issue Tracking",
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/treeverse/lakeFS/pull/10499",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/treeverse/lakeFS/commit/71a45eeb1639d146d34b8effd7e86d077160ed7c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/lakefs-unauthenticated-operator-metadata-overwrite-via-setup-comm-prefs",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 442,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66007",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:22:30.643Z",
      "date_published": "2026-07-24T14:58:10.035Z",
      "date_updated": "2026-07-25T10:30:06.287Z",
      "publisher": "VulnCheck",
      "title": "Datasets Path Traversal via Unsanitized file_name Metadata",
      "affected": {
        "vendors": [
          "huggingface"
        ],
        "products": [
          {
            "vendor": "huggingface",
            "product": "datasets"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00515,
        "percentile": 0.41011
      },
      "nvd": {
        "published": "2026-07-24T15:19:07.493",
        "lastModified": "2026-07-30T20:16:16.213",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66007",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A dataset file_name is joined to the dataset directory without rejecting traversal segments, allowing it to select local files outside that directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/huggingface/datasets/issues/8324",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/huggingface/datasets/pull/8325",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/huggingface/datasets/commit/f989ef9b4cc6c0039a7a82458eebca49e2b58b4b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/datasets-path-traversal-via-unsanitized-file-name-metadata",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 420,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66008",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:22:30.643Z",
      "date_published": "2026-07-24T12:07:55.967Z",
      "date_updated": "2026-07-28T01:06:20.506Z",
      "publisher": "VulnCheck",
      "title": "Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages",
      "affected": {
        "vendors": [
          "parse-community"
        ],
        "products": [
          {
            "vendor": "parse-community",
            "product": "parse-server"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0032,
        "percentile": 0.24378
      },
      "nvd": {
        "published": "2026-07-24T13:18:28.450",
        "lastModified": "2026-07-27T20:32:11.620",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66008",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "parse-server includes security-relevant internal data in an error, debug log, or diagnostic output that a lower-trust caller or local user can read.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/parse-community/parse-server/security/advisories/GHSA-r2g6-4f6j-f6rf",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/parse-server-information-disclosure-via-graphql-error-messages",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 694,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-66009",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:22:30.643Z",
      "date_published": "2026-07-24T12:07:56.720Z",
      "date_updated": "2026-07-28T01:06:21.175Z",
      "publisher": "VulnCheck",
      "title": "Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages",
      "affected": {
        "vendors": [
          "parse-community"
        ],
        "products": [
          {
            "vendor": "parse-community",
            "product": "parse-server"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 4,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-209",
          "name": "Generation of Error Message Containing Sensitive Information",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00263,
        "percentile": 0.17944
      },
      "nvd": {
        "published": "2026-07-24T13:18:28.580",
        "lastModified": "2026-07-30T19:53:34.757",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66009",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GraphQL validation errors name required custom fields even when public introspection is disabled.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-209"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/parse-community/parse-server/security/advisories/GHSA-2fgh-8j2g-w354",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/parse-server-information-disclosure-via-graphql-error-messages-2",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 684,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-66010",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:22:30.643Z",
      "date_published": "2026-07-24T12:07:57.374Z",
      "date_updated": "2026-07-24T14:14:08.456Z",
      "publisher": "VulnCheck",
      "title": "DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING",
      "affected": {
        "vendors": [
          "cure53"
        ],
        "products": [
          {
            "vendor": "cure53",
            "product": "DOMPurify"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00168,
        "percentile": 0.06412
      },
      "nvd": {
        "published": "2026-07-24T13:18:28.720",
        "lastModified": "2026-07-30T19:54:38.997",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66010",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "DOMPurify skips afterSanitizeElements for allowed custom elements, letting attributes evade the application's post-sanitization policy.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-c2j3-45gr-mqc4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/dompurify-before-hook-bypass-via-custom-element-handling",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66011",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:22:30.643Z",
      "date_published": "2026-07-25T10:45:55.405Z",
      "date_updated": "2026-07-27T16:18:39.262Z",
      "publisher": "VulnCheck",
      "title": "ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options",
      "affected": {
        "vendors": [
          "ImageMagick"
        ],
        "products": [
          {
            "vendor": "ImageMagick",
            "product": "ImageMagick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 3.3,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00103,
        "percentile": 0.01162
      },
      "nvd": {
        "published": "2026-07-25T11:17:18.347",
        "lastModified": "2026-08-04T13:52:56.537",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-66011",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Invalid command-line options allocate memory that the error path never releases.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cvhv-g4rq-3hmw",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/imagemagick-before-27-memory-leak-via-invalid-cli-options",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 262,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66012",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:22:30.643Z",
      "date_published": "2026-07-25T10:45:56.085Z",
      "date_updated": "2026-07-28T01:06:21.864Z",
      "publisher": "VulnCheck",
      "title": "SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00437,
        "percentile": 0.35982
      },
      "nvd": {
        "published": "2026-07-25T11:17:19.053",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66012",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "SiYuan gates the MCP endpoint only on general authentication and omits the administrator-role and read-only checks required for its privileged tools.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-cvhv-7xhj-xjp8",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/siyuan-note/siyuan/commit/c72ca4cd09019e5f64afdee8f8c6ec5ef34858db",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/siyuan-before-unauthenticated-administrator-takeover-via-mcp",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 900,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66013",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:22:30.643Z",
      "date_published": "2026-07-25T10:45:56.772Z",
      "date_updated": "2026-07-29T19:26:42.479Z",
      "publisher": "VulnCheck",
      "title": "OpenRemote before 1.26.2 Authentication Bypass via Console Registration",
      "affected": {
        "vendors": [
          "openremote"
        ],
        "products": [
          {
            "vendor": "openremote",
            "product": "openremote"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00388,
        "percentile": 0.31594
      },
      "nvd": {
        "published": "2026-07-25T11:17:19.193",
        "lastModified": "2026-07-30T20:11:09.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66013",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenRemote's console registration API accepts a known existing asset identifier from an unauthenticated caller and updates that asset without an ownership check.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/openremote/openremote/security/advisories/GHSA-gpfc-h59v-63cv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openremote-before-authentication-bypass-via-console-registration",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66014",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:59:51.587Z",
      "date_published": "2026-07-27T19:29:47.318Z",
      "date_updated": "2026-07-27T20:15:18.293Z",
      "publisher": "JFROG",
      "title": "Potential authentication bypass leading to privilege escalation in Artifactory",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 6,
        "versionRangeCount": 6,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-287",
          "name": "Improper Authentication",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24309
      },
      "nvd": {
        "published": "2026-07-27T20:16:41.790",
        "lastModified": "2026-07-30T14:45:38.510",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-66014",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Artifactory high-availability authentication can fail open and grant elevated privileges during internal request processing.",
        "basis": [
          "CNA",
          "CWE-287",
          "JFrog Artifactory 7.161.15 release notes"
        ],
        "deepDive": true,
        "notes": "Inspected https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases; the 7.161.15 CVE table identifies HA authentication fail-open behavior, while implementation source and the exact failed dependency remain private."
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 6
      }
    },
    {
      "cve_id": "CVE-2026-66015",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:59:51.587Z",
      "date_published": "2026-07-27T19:33:27.302Z",
      "date_updated": "2026-07-27T20:06:10.218Z",
      "publisher": "JFROG",
      "title": "JFrog Platform contains an authorization flaw that may allow authenticated privilege escalation.",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00335,
        "percentile": 0.26121
      },
      "nvd": {
        "published": "2026-07-27T20:16:41.907",
        "lastModified": "2026-07-30T14:46:12.300",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-66015",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "JFrog reports an authorization flaw that can temporarily grant platform-administrator access but does not publish the affected action or permission check.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 205,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66018",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T19:59:51.588Z",
      "date_published": "2026-07-27T19:31:34.491Z",
      "date_updated": "2026-07-27T20:12:51.252Z",
      "publisher": "JFROG",
      "title": "JFrog Artifactory build environment properties exposure",
      "affected": {
        "vendors": [
          "jfrog"
        ],
        "products": [
          {
            "vendor": "jfrog",
            "product": "artifactory"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:reefs@jfrog.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14196
      },
      "nvd": {
        "published": "2026-07-27T20:16:42.027",
        "lastModified": "2026-07-30T14:46:20.967",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-66018",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The build-environment API authorizes a caller through one readable repository parameter without binding access to the protected build's repository.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
          "host": "docs.jfrog.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 338,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66027",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-24T15:27:04.682Z",
      "date_updated": "2026-07-25T10:30:06.975Z",
      "publisher": "VulnCheck",
      "title": "Suna < 0.9.102 Broken Access Control via Message Queue API",
      "affected": {
        "vendors": [
          "kortix-ai"
        ],
        "products": [
          {
            "vendor": "kortix-ai",
            "product": "suna"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 0.3999999999999986,
      "epss": {
        "score": 0.00255,
        "percentile": 0.17055
      },
      "nvd": {
        "published": "2026-07-24T16:16:55.983",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66027",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Message-queue APIs omit user and account ownership checks, allowing one authenticated tenant to read, delete or inject prompts into another tenant's sessions.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/geo-chen/oss/blob/main/suna.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/kortix-ai/suna/releases/tag/v0.9.102",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/kortix-ai/suna/pull/4373",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/kortix-ai/suna/commit/7536a7d47fc93abcb66e677fcc993b390c81296a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/suna-broken-access-control-via-message-queue-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 551,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66028",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-27T18:00:54.581Z",
      "date_updated": "2026-07-28T01:06:22.634Z",
      "publisher": "VulnCheck",
      "title": "Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email",
      "affected": {
        "vendors": [
          "Creativeitem"
        ],
        "products": [
          {
            "vendor": "Creativeitem",
            "product": "Ekushey Project Manager CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-303",
          "name": "Incorrect Implementation of Authentication Algorithm",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.39999999999999947,
      "epss": {
        "score": 0.00321,
        "percentile": 0.24565
      },
      "nvd": {
        "published": "2026-07-27T18:17:00.090",
        "lastModified": "2026-07-28T20:37:39.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66028",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The account store does not enforce email uniqueness, so authentication can resolve one asserted identity to conflicting account records and passwords.",
        "basis": [
          "CNA",
          "CWE-303"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-66028",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ekushey-project-manager-crm-missing-uniqueness-constraint-via-client-email",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://codecanyon.net/item/ekushey-project-manager-crm/9492104",
          "host": "codecanyon.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 495,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66029",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-27T18:02:41.989Z",
      "date_updated": "2026-07-28T14:07:29.468Z",
      "publisher": "VulnCheck",
      "title": "Ekushey Project Manager CRM 5.0 Stored XSS via Client Name Field",
      "affected": {
        "vendors": [
          "Creativeitem"
        ],
        "products": [
          {
            "vendor": "Creativeitem",
            "product": "Ekushey Project Manager CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06176
      },
      "nvd": {
        "published": "2026-07-27T18:17:00.250",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66029",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Ekushey Project Manager CRM page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-66029",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://codecanyon.net/item/ekushey-project-manager-crm/9492104",
          "host": "codecanyon.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ekushey-project-manager-crm-stored-xss-via-client-name-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 506,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66030",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-27T18:06:31.407Z",
      "date_updated": "2026-07-28T15:20:26.176Z",
      "publisher": "VulnCheck",
      "title": "Ekushey Project Manager CRM 5.0 Stored XSS via Ticket Title Field",
      "affected": {
        "vendors": [
          "Creativeitem"
        ],
        "products": [
          {
            "vendor": "Creativeitem",
            "product": "Ekushey Project Manager CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06175
      },
      "nvd": {
        "published": "2026-07-27T18:17:00.390",
        "lastModified": "2026-07-28T20:37:39.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66030",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A client-controlled ticket title is stored and rendered in staff pages without the required browser-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-66030",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://codecanyon.net/item/ekushey-project-manager-crm/9492104",
          "host": "codecanyon.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ekushey-project-manager-crm-stored-xss-via-ticket-title-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 466,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66031",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-27T18:09:41.087Z",
      "date_updated": "2026-07-28T13:02:13.107Z",
      "publisher": "VulnCheck",
      "title": "Ekushey Project Manager CRM 5.0 Stored XSS via Reply Ticket Field",
      "affected": {
        "vendors": [
          "Creativeitem"
        ],
        "products": [
          {
            "vendor": "Creativeitem",
            "product": "Ekushey Project Manager CRM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.3000000000000007,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06176
      },
      "nvd": {
        "published": "2026-07-27T19:17:22.540",
        "lastModified": "2026-07-28T20:37:39.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66031",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Stored input is rendered without the browser-context separation required to prevent script execution.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-66031",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://codecanyon.net/item/ekushey-project-manager-crm/9492104",
          "host": "codecanyon.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ekushey-project-manager-crm-stored-xss-via-reply-ticket-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66032",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-24T16:32:39.596Z",
      "date_updated": "2026-07-28T01:06:24.681Z",
      "publisher": "VulnCheck",
      "title": "libssh2 Double-Free Heap Corruption via sftp_open()",
      "affected": {
        "vendors": [
          "libssh2"
        ],
        "products": [
          {
            "vendor": "libssh2",
            "product": "libssh2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21051
      },
      "nvd": {
        "published": "2026-07-24T17:17:35.120",
        "lastModified": "2026-07-30T16:43:03.817",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66032",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SFTP error sequence frees the same response buffer twice, corrupting heap allocator state.",
        "basis": [
          "CNA record",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/libssh2/libssh2/pull/2180",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/libssh2-double-free-heap-corruption-via-sftp-open",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 623,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66033",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-24T16:35:28.607Z",
      "date_updated": "2026-07-28T01:06:25.504Z",
      "publisher": "VulnCheck",
      "title": "libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation",
      "affected": {
        "vendors": [
          "libssh2"
        ],
        "products": [
          {
            "vendor": "libssh2",
            "product": "libssh2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-191",
          "name": "Integer Underflow (Wrap or Wraparound)",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29725
      },
      "nvd": {
        "published": "2026-07-24T17:17:35.263",
        "lastModified": "2026-07-30T15:44:47.257",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-66033",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "AES-GCM size arithmetic underflows before memcpy, producing an out-of-bounds read and a near-SIZE_MAX copy length.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-191"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/libssh2/libssh2/pull/2401",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/libssh2-integer-underflow-dos-via-aes-gcm-cipher-negotiation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66034",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-24T16:42:18.764Z",
      "date_updated": "2026-07-28T01:06:26.204Z",
      "publisher": "VulnCheck",
      "title": "libssh2 Heap Out-of-Bounds Read via publickey subsystem",
      "affected": {
        "vendors": [
          "libssh2"
        ],
        "products": [
          {
            "vendor": "libssh2",
            "product": "libssh2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00252,
        "percentile": 0.1669
      },
      "nvd": {
        "published": "2026-07-24T17:17:35.407",
        "lastModified": "2026-07-30T15:44:38.170",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-66034",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libssh2 advances by a server-controlled comment length without checking the remaining buffer and later frees an uninitialized pointer on error.",
        "basis": [
          "CNA",
          "CWE-125",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/libssh2/libssh2/pull/2202",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/libssh2-heap-out-of-bounds-read-via-publickey-subsystem",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 683,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66035",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-24T16:45:24.405Z",
      "date_updated": "2026-07-28T01:06:26.873Z",
      "publisher": "VulnCheck",
      "title": "libssh2 Heap Buffer Overflow via ETM Cipher Negotiation",
      "affected": {
        "vendors": [
          "libssh2"
        ],
        "products": [
          {
            "vendor": "libssh2",
            "product": "libssh2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.7,
      "cvss_source_score_spread": 0.20000000000000018,
      "epss": {
        "score": 0.00318,
        "percentile": 0.24185
      },
      "nvd": {
        "published": "2026-07-24T17:17:35.547",
        "lastModified": "2026-07-30T15:41:05.690",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-66035",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libssh2 allocates packet_length bytes on the ETM path but copies blocksize minus one bytes when the server supplies a smaller packet length.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/libssh2/libssh2/pull/2198",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Issue Tracking",
            "Patch",
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/libssh2-heap-buffer-overflow-via-etm-cipher-negotiation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 724,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66036",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-24T19:34:16.223Z",
      "date_updated": "2026-07-29T03:55:35.961Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00288,
        "percentile": 0.21051
      },
      "nvd": {
        "published": "2026-07-24T20:18:20.433",
        "lastModified": "2026-07-29T05:17:05.800",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66036",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled input exceeds a heap allocation because the write is not bounded to the allocated size.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 615,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66037",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-24T19:36:53.859Z",
      "date_updated": "2026-07-28T01:06:28.161Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00282,
        "percentile": 0.2047
      },
      "nvd": {
        "published": "2026-07-24T20:18:20.573",
        "lastModified": "2026-07-27T20:34:24.887",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66037",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "mix_presentation_obu allocates count_label entries before validating remaining OBU data, allowing 17 bytes to request multi-gigabyte memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 629,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66038",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-24T19:39:27.448Z",
      "date_updated": "2026-07-28T01:06:28.780Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-908",
          "name": "Use of Uninitialized Resource",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00256,
        "percentile": 0.17212
      },
      "nvd": {
        "published": "2026-07-24T20:18:20.727",
        "lastModified": "2026-07-27T20:34:24.887",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66038",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The FFmpeg decoder copies uninitialized allocation bytes into attacker-observable output.",
        "basis": [
          "CNA",
          "CWE-908"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 707,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66039",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.816Z",
      "date_published": "2026-07-24T19:42:42.453Z",
      "date_updated": "2026-07-29T03:55:37.612Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00423,
        "percentile": 0.34853
      },
      "nvd": {
        "published": "2026-07-24T20:18:20.880",
        "lastModified": "2026-07-29T05:17:06.280",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66039",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Signed sample-count arithmetic overflows, underallocates the MACE6 output buffer, and permits a heap out-of-bounds write.",
        "basis": [
          "CNA",
          "CWE-122",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66040",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.817Z",
      "date_published": "2026-07-24T19:46:25.959Z",
      "date_updated": "2026-07-29T03:55:38.351Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00546,
        "percentile": 0.42719
      },
      "nvd": {
        "published": "2026-07-24T20:18:21.063",
        "lastModified": "2026-07-29T05:17:06.757",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66040",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The FFmpeg parser or handler can write attacker-controlled data beyond the bounds of a heap allocation.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 666,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66041",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.817Z",
      "date_published": "2026-07-24T19:54:11.426Z",
      "date_updated": "2026-07-29T03:55:36.839Z",
      "publisher": "VulnCheck",
      "title": "FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter",
      "affected": {
        "vendors": [
          "FFmpeg"
        ],
        "products": [
          {
            "vendor": "FFmpeg",
            "product": "FFmpeg"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-787",
          "name": "Out-of-bounds Write",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 1.1000000000000005,
      "epss": {
        "score": 0.00423,
        "percentile": 0.34853
      },
      "nvd": {
        "published": "2026-07-24T20:18:21.240",
        "lastModified": "2026-07-29T05:17:07.230",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66041",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FFmpeg's vf_quirc filter allocates from the first subtitle frame dimensions and later copies a larger frame beyond that heap buffer.",
        "basis": [
          "CNA",
          "CWE-787"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5",
          "host": "code.ffmpeg.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-vf-quirc-filter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 567,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66050",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:45:17.817Z",
      "date_published": "2026-07-27T14:19:10.801Z",
      "date_updated": "2026-07-27T16:17:16.936Z",
      "publisher": "VulnCheck",
      "title": "NitroShare Desktop 0.3.4 Path Traversal via LAN File Transfer Server",
      "affected": {
        "vendors": [
          "nitroshare"
        ],
        "products": [
          {
            "vendor": "nitroshare",
            "product": "nitroshare-desktop"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00737,
        "percentile": 0.50979
      },
      "nvd": {
        "published": "2026-07-27T15:17:10.487",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66050",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/cduram/NotCVE-2026-0009",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/nitroshare-desktop-path-traversal-via-lan-file-transfer-server",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 550,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66053",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T20:49:51.666Z",
      "date_published": "2026-07-27T11:18:49.830Z",
      "date_updated": "2026-07-27T13:08:21.318Z",
      "publisher": "apache",
      "title": "Apache Thrift: Python TSSLSocket Hostname Matcher Import",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-297",
          "name": "Improper Validation of Certificate with Host Mismatch",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22811
      },
      "nvd": {
        "published": "2026-07-27T12:16:55.027",
        "lastModified": "2026-07-27T19:52:47.110",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-66053",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Python TLS hostname matcher accepts a certificate whose host identity does not match the requested server.",
        "basis": [
          "CNA",
          "CWE-297"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Release Notes",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/w4k5dnv1x58knwlhpo9x0or5xh220y65",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 257,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66063",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T23:25:28.897Z",
      "date_published": "2026-07-28T22:07:15.558Z",
      "date_updated": "2026-07-29T14:10:09.074Z",
      "publisher": "GitHub_M",
      "title": "goshs has a Path Traversal issue",
      "affected": {
        "vendors": [
          "goshs-labs"
        ],
        "products": [
          {
            "vendor": "goshs-labs",
            "product": "goshs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00233,
        "percentile": 0.14227
      },
      "nvd": {
        "published": "2026-07-28T23:17:10.353",
        "lastModified": "2026-07-30T19:23:14.707",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66063",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The upload handler strips slash-separated filename components but accepts .. as the final name, placing the file outside the served tree.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/goshs-labs/goshs/security/advisories/GHSA-wg2q-39h6-66x9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/goshs-labs/goshs/commit/f3ef599e409151d1380866e47de8b1afb0bb54fa",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 329,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66064",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T23:25:28.897Z",
      "date_published": "2026-07-28T22:12:04.830Z",
      "date_updated": "2026-07-29T15:24:11.484Z",
      "publisher": "GitHub_M",
      "title": "goshs has ACL Bypass & Path Traversal",
      "affected": {
        "vendors": [
          "goshs-labs"
        ],
        "products": [
          {
            "vendor": "goshs-labs",
            "product": "goshs"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-41",
          "name": "Improper Resolution of Path Equivalence",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00308,
        "percentile": 0.2318
      },
      "nvd": {
        "published": "2026-07-28T23:17:10.490",
        "lastModified": "2026-07-30T19:19:45.637",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66064",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "An ACL checks one textual form of a path while the filesystem resolves a different cleaned form, allowing the final selected object to escape the authorized namespace.",
        "basis": [
          "CNA",
          "CWE-41",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/goshs-labs/goshs/security/advisories/GHSA-964w-f6gj-5236",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/goshs-labs/goshs/pull/222",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/goshs-labs/goshs/commit/f3ef599e409151d1380866e47de8b1afb0bb54fa",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 357,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66066",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-23T23:25:28.897Z",
      "date_published": "2026-07-30T18:32:11.419Z",
      "date_updated": "2026-08-04T03:56:18.767Z",
      "publisher": "GitHub_M",
      "title": "Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing",
      "affected": {
        "vendors": [
          "rails"
        ],
        "products": [
          {
            "vendor": "rails",
            "product": "rails"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.5,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01701,
        "percentile": 0.7496
      },
      "nvd": {
        "published": "2026-07-30T19:18:35.843",
        "lastModified": "2026-08-04T05:16:40.060",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66066",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Active Storage leaves libvips operations marked unsafe enabled for attacker-supplied images, allowing image processing to read Rails-process files and secrets.",
        "basis": [
          "CNA",
          "CWE-1188"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rails/rails/releases/tag/v7.2.3.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rails/rails/releases/tag/v8.0.5.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rails/rails/releases/tag/v8.1.3.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-66066.yml",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html",
          "host": "thehackernews.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/29/9",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066",
          "host": "ethiack.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/08/01/6",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 744,
        "referenceCount": 12,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-66138",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T03:53:11.727Z",
      "date_published": "2026-07-24T03:53:12.142Z",
      "date_updated": "2026-07-24T23:22:05.285Z",
      "publisher": "mitre",
      "title": "In OpenStack Ironic Python Agent through 11.",
      "affected": {
        "vendors": [
          "OpenStack"
        ],
        "products": [
          {
            "vendor": "OpenStack",
            "product": "Ironic Python Agent"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 3,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00423,
        "percentile": 0.34872
      },
      "nvd": {
        "published": "2026-07-24T05:16:49.433",
        "lastModified": "2026-07-30T19:32:25.133",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66138",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A caller-controlled value reaches operating-system command construction in Ironic Python Agent without separating it from command or argument syntax.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://bugs.launchpad.net/ironic-python-agent/+bug/2160050",
          "host": "bugs.launchpad.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://security.openstack.org/ossa/OSSA-2026-027.html",
          "host": "security.openstack.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/26",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 261,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-66139",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T04:14:41.411Z",
      "date_published": "2026-07-24T04:14:41.795Z",
      "date_updated": "2026-07-24T23:22:06.300Z",
      "publisher": "mitre",
      "title": "OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.",
      "affected": {
        "vendors": [
          "OpenStack"
        ],
        "products": [
          {
            "vendor": "OpenStack",
            "product": "Zaqar"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 4.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00294,
        "percentile": 0.21635
      },
      "nvd": {
        "published": "2026-07-24T05:16:49.577",
        "lastModified": "2026-07-30T19:32:25.133",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66139",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Zaqar accepts a known queue UUID through the EXTRA-SPEC path without applying the authentication required for that queue.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/23/7",
          "host": "www.openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://bugs.launchpad.net/ossa/+bug/2161254",
          "host": "bugs.launchpad.net",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/27",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-66140",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T04:32:08.386Z",
      "date_published": "2026-07-24T04:32:08.764Z",
      "date_updated": "2026-07-24T12:25:04.081Z",
      "publisher": "mitre",
      "title": "Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.",
      "affected": {
        "vendors": [
          "Exim"
        ],
        "products": [
          {
            "vendor": "Exim",
            "product": "Exim"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-24",
          "name": "Path Traversal: '../filedir'",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00272,
        "percentile": 0.19391
      },
      "nvd": {
        "published": "2026-07-24T05:16:49.747",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66140",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Exim mishandles queue-name arguments so traversal segments select files outside the spool directory.",
        "basis": [
          "CNA",
          "CWE-24"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://openwall.com/lists/oss-security/2026/07/22/9",
          "host": "openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 178,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66141",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T04:37:45.699Z",
      "date_published": "2026-07-24T04:37:46.099Z",
      "date_updated": "2026-07-24T18:42:19.559Z",
      "publisher": "mitre",
      "title": "Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.",
      "affected": {
        "vendors": [
          "Exim"
        ],
        "products": [
          {
            "vendor": "Exim",
            "product": "Exim"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-829",
          "name": "Inclusion of Functionality from Untrusted Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00102,
        "percentile": 0.01101
      },
      "nvd": {
        "published": "2026-07-24T05:16:49.890",
        "lastModified": "2026-07-30T14:15:31.167",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66141",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Exim pipe transport mishandles force_command while processing a user's .forward file, allowing the user-controlled pipe action to run with unintended privilege.",
        "basis": [
          "CNA",
          "CWE-829"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://openwall.com/lists/oss-security/2026/07/22/9",
          "host": "openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 113,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66142",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T07:16:40.533Z",
      "date_published": "2026-07-24T12:07:26.323Z",
      "date_updated": "2026-07-24T18:38:17.880Z",
      "publisher": "apache",
      "title": "Apache Neethi: Uncontrolled recursion in policy processing",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Neethi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00478,
        "percentile": 0.38755
      },
      "nvd": {
        "published": "2026-07-24T13:18:29.237",
        "lastModified": "2026-07-27T14:35:32.197",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-66142",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The policy parser recurses without a depth bound when policies omit IDs or contain deeply nested structures.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/fomwtwt4pzzhxn4fyn3skykto913vfzt",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/8",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 306,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66143",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T07:26:50.294Z",
      "date_published": "2026-07-24T12:07:52.657Z",
      "date_updated": "2026-07-24T18:40:12.434Z",
      "publisher": "apache",
      "title": "Apache Neethi: Missing global alternative-output budget across policy computation paths",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Neethi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00513,
        "percentile": 0.40851
      },
      "nvd": {
        "published": "2026-07-24T13:18:29.350",
        "lastModified": "2026-07-27T14:35:07.563",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-66143",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Neethi enforces an alternatives limit on individual policy paths but lacks a global budget across normalization paths.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/s6o6p5pvcbcsk54dlg6j699t5gxol28w",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/9",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 296,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66144",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T07:32:05.484Z",
      "date_published": "2026-07-24T12:08:27.992Z",
      "date_updated": "2026-07-24T18:42:19.733Z",
      "publisher": "apache",
      "title": "Apache Neethi: Remote PolicyReference fetch lacks resource bounds",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Neethi"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00478,
        "percentile": 0.38755
      },
      "nvd": {
        "published": "2026-07-24T13:18:29.467",
        "lastModified": "2026-07-27T14:32:06.660",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-66144",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The manual PolicyReference fetch reads a remote policy without a size limit, allowing one response to exhaust memory.",
        "basis": [
          "CNA",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/80xwwbhkqvbwkkmco6yl6fr5xkpdysjf",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Vendor Advisory",
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/24/10",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 347,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66299",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T14:53:11.561Z",
      "date_published": "2026-07-28T14:29:05.810Z",
      "date_updated": "2026-07-28T17:40:03.853Z",
      "publisher": "apache",
      "title": "Apache Tomcat: DoS via WebSocket chat example",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Tomcat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 4,
        "versionRangeCount": 4,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:1",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23396
      },
      "nvd": {
        "published": "2026-07-28T15:17:50.210",
        "lastModified": "2026-07-28T18:17:23.193",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66299",
        "family": "RESOURCE_CONTROL",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apache Tomcat accepts an attacker-controlled size, count, recursion depth, or work request without the quota or upper bound needed to keep resource use finite.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/8owczcc1o8qw1rxmg9gvfk4w2jnh4l5k",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/25",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 4
      }
    },
    {
      "cve_id": "CVE-2026-66337",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T22:32:18.748Z",
      "date_published": "2026-07-24T23:01:20.983Z",
      "date_updated": "2026-07-27T16:01:20.262Z",
      "publisher": "redhat",
      "title": "Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until()",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13762
      },
      "nvd": {
        "published": "2026-07-24T23:16:51.760",
        "lastModified": "2026-07-27T20:37:16.927",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66337",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Unsigned arithmetic underflows in soup_filter_input_stream_read_until and drives a heap read beyond the multipart-response buffer.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-66337",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506949",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 351,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-66338",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T22:32:18.748Z",
      "date_published": "2026-07-24T23:01:20.503Z",
      "date_updated": "2026-07-27T14:35:12.458Z",
      "publisher": "redhat",
      "title": "Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked()",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00174,
        "percentile": 0.07021
      },
      "nvd": {
        "published": "2026-07-24T23:16:52.040",
        "lastModified": "2026-07-27T20:37:16.927",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66338",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "libsoup accepts nonstandard chunk-size syntax that a stricter frontend parses differently, creating an HTTP request-boundary disagreement.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-66338",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506950",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 371,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-66339",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-24T22:32:18.748Z",
      "date_published": "2026-07-24T23:01:15.634Z",
      "date_updated": "2026-07-28T14:55:26.084Z",
      "publisher": "redhat",
      "title": "Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13797
      },
      "nvd": {
        "published": "2026-07-24T23:16:52.187",
        "lastModified": "2026-07-28T16:20:11.980",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66339",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The proxy retains a Proxy-Authorization header after CONNECT and forwards those credentials to the destination server.",
        "basis": [
          "CNA",
          "CWE-201"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-66339",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506951",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 330,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-66349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T19:32:49.401Z",
      "date_published": "2026-07-30T22:31:32.618Z",
      "date_updated": "2026-07-31T15:54:00.925Z",
      "publisher": "icscert",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "affected": {
        "vendors": [
          "MZ Automation GmbH"
        ],
        "products": [
          {
            "vendor": "MZ Automation GmbH",
            "product": "libiec61850"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00181,
        "percentile": 0.0786
      },
      "nvd": {
        "published": "2026-07-30T23:16:52.920",
        "lastModified": "2026-07-31T16:17:10.367",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66349",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The MMS BER decoder advances past its buffer on an extended tag because it omits the required bounds check.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 437,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66360",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T19:32:49.407Z",
      "date_published": "2026-07-30T22:25:54.454Z",
      "date_updated": "2026-07-31T15:50:41.354Z",
      "publisher": "icscert",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "affected": {
        "vendors": [
          "MZ Automation GmbH"
        ],
        "products": [
          {
            "vendor": "MZ Automation GmbH",
            "product": "libiec61850"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00278,
        "percentile": 0.20084
      },
      "nvd": {
        "published": "2026-07-30T23:16:53.070",
        "lastModified": "2026-07-31T16:17:10.493",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66360",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ISO Presentation parser processes an attacker-controlled field without first proving that the encoded presentation data contains the required bytes.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 507,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66364",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T19:32:49.399Z",
      "date_published": "2026-07-30T22:33:28.104Z",
      "date_updated": "2026-07-31T15:55:15.546Z",
      "publisher": "icscert",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "affected": {
        "vendors": [
          "MZ Automation GmbH"
        ],
        "products": [
          {
            "vendor": "MZ Automation GmbH",
            "product": "libiec61850"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07149
      },
      "nvd": {
        "published": "2026-07-30T23:16:53.223",
        "lastModified": "2026-07-31T16:17:10.617",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66364",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The GOOSE parser accepts an inner element length greater than its enclosing payload length and reads one byte beyond the buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 433,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66369",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T19:32:49.390Z",
      "date_published": "2026-07-30T22:45:29.375Z",
      "date_updated": "2026-07-31T19:22:19.970Z",
      "publisher": "icscert",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "affected": {
        "vendors": [
          "MZ Automation GmbH"
        ],
        "products": [
          {
            "vendor": "MZ Automation GmbH",
            "product": "libiec61850"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07148
      },
      "nvd": {
        "published": "2026-07-30T23:16:53.377",
        "lastModified": "2026-07-31T20:16:54.120",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66369",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 426,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66373",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T00:08:35.560Z",
      "date_published": "2026-07-25T00:08:35.982Z",
      "date_updated": "2026-07-28T03:55:42.278Z",
      "publisher": "mitre",
      "title": "Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting...",
      "affected": {
        "vendors": [
          "Redis"
        ],
        "products": [
          {
            "vendor": "Redis",
            "product": "Redis"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-415",
          "name": "Double Free",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00472,
        "percentile": 0.38374
      },
      "nvd": {
        "published": "2026-07-25T01:16:26.277",
        "lastModified": "2026-07-28T05:17:17.507",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66373",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A crafted stream payload makes two consumers reference the same pending entry, so deleting both consumers frees that entry twice.",
        "basis": [
          "CNA",
          "CWE-415"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/redis/redis/pull/15081",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/redis/redis/compare/8.6.4...8.8.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://x.com/Fried_rice/status/2080059356322918777",
          "host": "x.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/berabuddies/redis-poc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://news.ycombinator.com/item?id=49024938",
          "host": "news.ycombinator.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 372,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66374",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T00:28:33.968Z",
      "date_published": "2026-07-25T00:28:34.320Z",
      "date_updated": "2026-07-27T14:36:16.215Z",
      "publisher": "mitre",
      "title": "Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.",
      "affected": {
        "vendors": [
          "nic"
        ],
        "products": [
          {
            "vendor": "nic",
            "product": "Knot Resolver"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1284",
          "name": "Improper Validation of Specified Quantity in Input",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L"
        },
        {
          "source": "NVD:cve@mitre.org",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00389,
        "percentile": 0.31645
      },
      "nvd": {
        "published": "2026-07-25T01:16:26.423",
        "lastModified": "2026-07-30T19:32:25.133",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66374",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The DNS-over-QUIC receive path mishandles a peer-supplied length and can overflow a heap buffer before Knot Resolver 6.4.1.",
        "basis": [
          "CNA",
          "CWE-1284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://openwall.com/lists/oss-security/2026/07/23/6",
          "host": "openwall.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/venglin/knot-doq",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 129,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66390",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T22:06:33.013Z",
      "date_published": "2026-07-27T16:39:11.789Z",
      "date_updated": "2026-07-28T14:49:16.289Z",
      "publisher": "apache",
      "title": "Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Wicket"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00173,
        "percentile": 0.06963
      },
      "nvd": {
        "published": "2026-07-27T17:16:41.643",
        "lastModified": "2026-07-28T16:20:12.723",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66390",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/67814fo0zocv3161bk1cr0ypvrkxky43",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/27/4",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 283,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66391",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-25T22:12:36.649Z",
      "date_published": "2026-07-27T16:45:17.483Z",
      "date_updated": "2026-07-28T14:49:47.331Z",
      "publisher": "apache",
      "title": "Apache Wicket: leaked and missing CSP headers",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Wicket"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-330",
          "name": "Use of Insufficiently Random Values",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00196,
        "percentile": 0.09501
      },
      "nvd": {
        "published": "2026-07-27T17:16:41.750",
        "lastModified": "2026-07-28T16:20:13.733",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66391",
        "family": "CRYPTO_SECRET",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Apache Wicket uses insufficiently random security values, but the public record does not identify the value, generator, entropy source, or prediction path.",
        "basis": [
          "CNA",
          "CWE-330",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/hfzcgjsbmmthzchtb8b8nv47d95scmqk",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/27/5",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 264,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66394",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-26T12:22:34.139Z",
      "date_published": "2026-07-27T15:43:45.397Z",
      "date_updated": "2026-07-28T01:06:31.527Z",
      "publisher": "VulnCheck",
      "title": "SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.6000000000000014,
      "epss": {
        "score": 0.00266,
        "percentile": 0.1861
      },
      "nvd": {
        "published": "2026-07-27T16:18:11.947",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66394",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An HTML-based cleaner treats script text inside SVG elements as inert while the browser later interprets it as executable SVG content.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-99rq-75j6-5j9f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/siyuan-before-stored-and-reflected-xss-via-svg-sanitizer-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 451,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66395",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-26T12:22:34.139Z",
      "date_published": "2026-07-27T15:43:46.073Z",
      "date_updated": "2026-07-28T01:06:32.165Z",
      "publisher": "VulnCheck",
      "title": "SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.6,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.6,
      "cvss_source_score_spread": 0.1999999999999993,
      "epss": {
        "score": 0.00327,
        "percentile": 0.25168
      },
      "nvd": {
        "published": "2026-07-27T16:18:12.083",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66395",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A deep-link parameter is inserted with insertAdjacentHTML without browser-context separation.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6gx2-8gcr-x83f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/siyuan-desktop-before-reflected-xss-to-rce-via-siyuan-protocol",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 400,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66396",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-26T12:22:34.139Z",
      "date_published": "2026-07-27T15:43:46.717Z",
      "date_updated": "2026-07-28T01:06:32.817Z",
      "publisher": "VulnCheck",
      "title": "SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL",
      "affected": {
        "vendors": [
          "siyuan-note"
        ],
        "products": [
          {
            "vendor": "siyuan-note",
            "product": "siyuan"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.9000000000000004,
      "epss": {
        "score": 0.00296,
        "percentile": 0.21844
      },
      "nvd": {
        "published": "2026-07-27T16:18:12.220",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66396",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "SiYuan interpolates an unescaped title-img attribute into style markup where an event handler executes with Electron Node.js authority.",
        "basis": [
          "CNA record",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-5rxg-wh59-mg34",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/siyuan-before-stored-xss-to-rce-via-title-img-ial",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 389,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66397",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-26T12:22:34.139Z",
      "date_published": "2026-07-27T15:43:47.391Z",
      "date_updated": "2026-07-28T01:06:33.479Z",
      "publisher": "VulnCheck",
      "title": "phpMyFAQ before 4.1.6 Path Traversal via category image deletion",
      "affected": {
        "vendors": [
          "thorsten"
        ],
        "products": [
          {
            "vendor": "thorsten",
            "product": "phpMyFAQ"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00325,
        "percentile": 0.24973
      },
      "nvd": {
        "published": "2026-07-27T16:18:12.363",
        "lastModified": "2026-07-28T20:37:39.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66397",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "phpMyFAQ accepts an attacker-controlled path that can resolve outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-mh9w-5hr8-3272",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/phpmyfaq-before-path-traversal-via-category-image-deletion",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66398",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-26T12:22:34.139Z",
      "date_published": "2026-07-27T15:43:48.063Z",
      "date_updated": "2026-07-28T01:06:34.143Z",
      "publisher": "VulnCheck",
      "title": "phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API",
      "affected": {
        "vendors": [
          "thorsten"
        ],
        "products": [
          {
            "vendor": "thorsten",
            "product": "phpMyFAQ"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-494",
          "name": "Download of Code Without Integrity Check",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.4,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15323
      },
      "nvd": {
        "published": "2026-07-27T16:18:12.493",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66398",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "phpMyFAQ lets an administrator point the updater at an uploaded archive and extract it into the application root without enforcing trusted package provenance.",
        "basis": [
          "CNA",
          "CWE-494"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-4fv7-8rr6-rf2w",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/phpmyfaq-before-remote-code-execution-via-configuration-api",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 480,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66399",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-26T12:22:34.139Z",
      "date_published": "2026-07-27T15:43:48.767Z",
      "date_updated": "2026-07-28T14:54:36.075Z",
      "publisher": "VulnCheck",
      "title": "phpMyFAQ before 4.1.6 Privilege Escalation via Group Membership",
      "affected": {
        "vendors": [
          "thorsten"
        ],
        "products": [
          {
            "vendor": "thorsten",
            "product": "phpMyFAQ"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-269",
          "name": "Improper Privilege Management",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 2,
      "epss": {
        "score": 0.00231,
        "percentile": 0.14009
      },
      "nvd": {
        "published": "2026-07-27T16:18:12.633",
        "lastModified": "2026-07-28T16:20:14.670",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66399",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "phpMyFAQ lets a group-management administrator add themselves to a group whose inherited permissions exceed their own authority.",
        "basis": [
          "CNA",
          "CWE-269"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-28cc-v39j-vr95",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/phpmyfaq-before-privilege-escalation-via-group-membership",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 396,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66400",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-26T12:22:34.139Z",
      "date_published": "2026-07-29T13:32:00.837Z",
      "date_updated": "2026-07-29T14:47:35.149Z",
      "publisher": "VulnCheck",
      "title": "Grav Login Plugin before 3.8.13 Insufficient Session Expiration",
      "affected": {
        "vendors": [
          "getgrav"
        ],
        "products": [
          {
            "vendor": "getgrav",
            "product": "grav"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-613",
          "name": "Insufficient Session Expiration",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 1.5,
      "epss": {
        "score": 0.00152,
        "percentile": 0.04881
      },
      "nvd": {
        "published": "2026-07-29T14:16:34.017",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66400",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Remember-me tokens remain accepted beyond their configured lifetime because the expiry value is compared using the wrong type.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-613"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-mj78-8gwc-vxjj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/grav-login-plugin-before-insufficient-session-expiration",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66412",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T05:16:45.792Z",
      "date_published": "2026-07-27T05:23:20.773Z",
      "date_updated": "2026-07-28T01:06:35.536Z",
      "publisher": "VulnCheck",
      "title": "Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone JSON-RPC",
      "affected": {
        "vendors": [
          "Leantime"
        ],
        "products": [
          {
            "vendor": "Leantime",
            "product": "Leantime"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00238,
        "percentile": 0.1497
      },
      "nvd": {
        "published": "2026-07-27T07:16:30.317",
        "lastModified": "2026-07-28T16:07:15.840",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66412",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "tickets.getMilestone accepts an arbitrary milestone ID without binding the referenced project to the authenticated user's membership.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Leantime/leantime/security/advisories/GHSA-wv69-xr82-phr6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/Leantime/leantime/pull/3657",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/Leantime/leantime/commit/68898eeb914882a21797523f2782914795bc67ae",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/leantime-all-versions-prior-to-and-broken-access-control-via-tickets-getmilestone-json-rpc",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 484,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66414",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T05:16:45.792Z",
      "date_published": "2026-07-30T16:36:21.177Z",
      "date_updated": "2026-07-31T11:54:04.685Z",
      "publisher": "VulnCheck",
      "title": "Leantime Open Redirect in Login Controller via redirectUrl Parameter",
      "affected": {
        "vendors": [
          "Leantime"
        ],
        "products": [
          {
            "vendor": "Leantime",
            "product": "Leantime"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00197,
        "percentile": 0.09748
      },
      "nvd": {
        "published": "2026-07-30T17:16:34.210",
        "lastModified": "2026-07-31T12:16:54.393",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66414",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Leantime navigation flow accepts an attacker-selected external destination without restricting it to trusted origins.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Leantime/leantime/pull/3658",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/javokhir-sec/CVE-PoC-Hub/security/advisories/GHSA-wprg-q8m6-jhp9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/Leantime/leantime",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/leantime-open-redirect-in-login-controller-via-redirecturl-parameter",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 428,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66415",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T05:16:45.792Z",
      "date_published": "2026-07-30T16:49:54.626Z",
      "date_updated": "2026-07-31T11:54:05.397Z",
      "publisher": "VulnCheck",
      "title": "Leantime Server-Side Request Forgery and Local File Inclusion in Blueprints::import()",
      "affected": {
        "vendors": [
          "Leantime"
        ],
        "products": [
          {
            "vendor": "Leantime",
            "product": "Leantime"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.4,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.09999999999999964,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20688
      },
      "nvd": {
        "published": "2026-07-30T19:18:36.190",
        "lastModified": "2026-07-31T12:16:55.093",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66415",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Blueprints::import passes an attacker-controlled URL wrapper to file_get_contents without restricting the server-side destination.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Leantime/leantime/pull/3656",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/javokhir-sec/CVE-PoC-Hub/security/advisories/GHSA-gphg-6h4g-mg22",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/Leantime/leantime",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/leantime-server-side-request-forgery-and-local-file-inclusion-in-blueprints-import",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 496,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66416",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T05:16:45.792Z",
      "date_published": "2026-07-30T17:00:10.215Z",
      "date_updated": "2026-07-31T23:04:13.471Z",
      "publisher": "VulnCheck",
      "title": "Leantime CSRF Protection Globally Disabled by Omission of Laravel VerifyCsrfToken Middleware",
      "affected": {
        "vendors": [
          "Leantime"
        ],
        "products": [
          {
            "vendor": "Leantime",
            "product": "Leantime"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00162,
        "percentile": 0.05905
      },
      "nvd": {
        "published": "2026-07-30T19:18:36.340",
        "lastModified": "2026-07-31T23:17:26.043",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66416",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Leantime excludes VerifyCsrfToken from its global middleware stack, allowing cross-site POST, PUT, and DELETE requests to execute under the victim's session.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Leantime/leantime/pull/3659",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/javokhir-sec/CVE-PoC-Hub/security/advisories/GHSA-x8vx-9g5w-w5rr",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/Leantime/leantime",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/leantime-csrf-protection-globally-disabled-by-omission-of-laravel-verifycsrftoken-middleware",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 522,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66418",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T05:16:45.792Z",
      "date_published": "2026-07-30T20:55:24.766Z",
      "date_updated": "2026-07-31T23:11:48.679Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field",
      "affected": {
        "vendors": [
          "tugcantopaloglu"
        ],
        "products": [
          {
            "vendor": "tugcantopaloglu",
            "product": "openclaw-dashboard"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00338,
        "percentile": 0.26382
      },
      "nvd": {
        "published": "2026-07-30T21:18:12.490",
        "lastModified": "2026-07-31T23:17:26.170",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66418",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenClaw records an unauthenticated username verbatim and later inserts it into the administrator notification panel with innerHTML.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tugcantopaloglu/openclaw-dashboard",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/theopaid/Unauthenticated-Stored-Cross-Site-Scripting-Leading-To-Administrator-Account-Takeover",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-dashboard-stored-xss-via-failed-login-username-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 645,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66420",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T05:16:45.792Z",
      "date_published": "2026-07-30T21:52:28.914Z",
      "date_updated": "2026-07-31T15:58:57.183Z",
      "publisher": "VulnCheck",
      "title": "MeshCentral Cross-Site WebSocket Hijacking via Origin Validation Bypass on Self-Signed Certificate Deployments",
      "affected": {
        "vendors": [
          "Ylianst"
        ],
        "products": [
          {
            "vendor": "Ylianst",
            "product": "MeshCentral"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-346",
          "name": "Origin Validation Error",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.20000000000000107,
      "epss": {
        "score": 0.00165,
        "percentile": 0.06123
      },
      "nvd": {
        "published": "2026-07-30T23:16:53.527",
        "lastModified": "2026-07-31T16:17:10.740",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66420",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "MeshCentral returns early for a self-signed certificate before completing the normal origin validation, allowing an untrusted channel to pass the abbreviated check.",
        "basis": [
          "CNA",
          "CWE-346"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Ylianst/MeshCentral/pull/7882",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "product"
          ]
        },
        {
          "url": "https://github.com/Ylianst/MeshCentral/commit/f04c9f4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/Ylianst/MeshCentral",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/meshcentral-cross-site-websocket-hijacking-via-origin-validation-bypass-on-self-signed-certificate-deployments",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 655,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66421",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T05:16:45.792Z",
      "date_published": "2026-07-30T22:16:58.960Z",
      "date_updated": "2026-07-31T15:09:09.811Z",
      "publisher": "VulnCheck",
      "title": "OpenClaw Dashboard Stored XSS via lastMessage Session Field",
      "affected": {
        "vendors": [
          "tugcantopaloglu"
        ],
        "products": [
          {
            "vendor": "tugcantopaloglu",
            "product": "openclaw-dashboard"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00363,
        "percentile": 0.28971
      },
      "nvd": {
        "published": "2026-07-30T23:16:53.687",
        "lastModified": "2026-07-31T16:17:10.863",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66421",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The dashboard interpolates stored transcript text into innerHTML without HTML-context neutralization.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/tugcantopaloglu/openclaw-dashboard",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/theopaid/Stored-Cross-Site-Scripting-Via-Agent-Messages-Leading-To-Session-Token-Theft-openclaw-dashboard-",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openclaw-dashboard-stored-xss-via-lastmessage-session-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 697,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:00:08.212Z",
      "date_published": "2026-07-27T13:59:24.521Z",
      "date_updated": "2026-07-27T16:07:16.533Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Google Review Slider plugin <= 18.4 - SQL Injection vulnerability",
      "affected": {
        "vendors": [
          "jgwhite33"
        ],
        "products": [
          {
            "vendor": "jgwhite33",
            "product": "WP Google Review Slider"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-89",
          "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00226,
        "percentile": 0.13417
      },
      "nvd": {
        "published": "2026-07-27T15:17:10.650",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66427",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected endpoint incorporates caller-controlled data into an SQL statement without parameterization.",
        "basis": [
          "CNA",
          "CWE-89"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-google-places-review-slider/vulnerability/wordpress-wp-google-review-slider-plugin-18-4-sql-injection-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 72,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:00:08.213Z",
      "date_published": "2026-07-27T13:59:25.165Z",
      "date_updated": "2026-07-27T14:59:35.991Z",
      "publisher": "Patchstack",
      "title": "WordPress WP Google Review Slider plugin <= 18.4 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "jgwhite33"
        ],
        "products": [
          {
            "vendor": "jgwhite33",
            "product": "WP Google Review Slider"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00098,
        "percentile": 0.00906
      },
      "nvd": {
        "published": "2026-07-27T15:17:10.780",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66428",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Patchstack identifies a cross-site request forgery in WP Google Review Slider, but does not publish the state-changing action or missing request check.",
        "basis": [
          "CNA",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/wp-google-places-review-slider/vulnerability/wordpress-wp-google-review-slider-plugin-18-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 94,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:00:08.213Z",
      "date_published": "2026-07-27T13:59:25.811Z",
      "date_updated": "2026-07-27T15:07:40.751Z",
      "publisher": "Patchstack",
      "title": "WordPress Location Weather plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "ShapedPlugin LLC"
        ],
        "products": [
          {
            "vendor": "ShapedPlugin LLC",
            "product": "Location Weather"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03051
      },
      "nvd": {
        "published": "2026-07-27T15:17:10.917",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66433",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The application renders attacker-controlled content into an HTML or JavaScript context without context-appropriate output encoding.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/location-weather/vulnerability/wordpress-location-weather-plugin-3-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 77,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66434",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:00:18.436Z",
      "date_published": "2026-07-27T13:59:26.453Z",
      "date_updated": "2026-07-27T18:15:48.787Z",
      "publisher": "Patchstack",
      "title": "WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= 3.33 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "Sayontan Sinha"
        ],
        "products": [
          {
            "vendor": "Sayontan Sinha",
            "product": "Photonic Gallery & Lightbox for Flickr, SmugMug & Others"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03053
      },
      "nvd": {
        "published": "2026-07-27T15:17:11.047",
        "lastModified": "2026-07-27T19:17:23.127",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66434",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "User-controlled content reaches Photonic Gallery & Lightbox for Flickr, SmugMug & Others page output without context-appropriate sanitization or escaping, so the browser interprets it as script.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/photonic/vulnerability/wordpress-photonic-gallery-lightbox-for-flickr-smugmug-others-plugin-3-33-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 116,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66437",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:00:18.436Z",
      "date_published": "2026-07-27T13:59:27.073Z",
      "date_updated": "2026-07-27T16:24:34.394Z",
      "publisher": "Patchstack",
      "title": "WordPress Feedzy plugin <= 5.2.4 - Server Side Request Forgery (SSRF) vulnerability",
      "affected": {
        "vendors": [
          "Themeisle"
        ],
        "products": [
          {
            "vendor": "Themeisle",
            "product": "Feedzy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00119,
        "percentile": 0.021
      },
      "nvd": {
        "published": "2026-07-27T15:17:11.190",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66437",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "medium",
        "mechanism": "Feedzy accepts a contributor-supplied fetch destination without enforcing the intended internal-network boundary.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/feedzy-rss-feeds/vulnerability/wordpress-feedzy-plugin-5-2-4-server-side-request-forgery-ssrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66438",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:00:18.436Z",
      "date_published": "2026-07-27T13:59:27.715Z",
      "date_updated": "2026-07-27T16:17:29.817Z",
      "publisher": "Patchstack",
      "title": "WordPress Exclusive Addons Elementor plugin <= 2.8.0 - Sensitive Data Exposure vulnerability",
      "affected": {
        "vendors": [
          "Tim Strifler"
        ],
        "products": [
          {
            "vendor": "Tim Strifler",
            "product": "Exclusive Addons Elementor"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-497",
          "name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00197,
        "percentile": 0.0973
      },
      "nvd": {
        "published": "2026-07-27T15:17:11.313",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66438",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Exclusive Addons exposes protected application data through a public WordPress request path.",
        "basis": [
          "CNA",
          "CWE-497"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/exclusive-addons-for-elementor/vulnerability/wordpress-exclusive-addons-elementor-plugin-2-8-0-sensitive-data-exposure-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 88,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66442",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:00:18.436Z",
      "date_published": "2026-07-27T13:59:28.368Z",
      "date_updated": "2026-07-27T16:06:36.751Z",
      "publisher": "Patchstack",
      "title": "WordPress YayPricing plugin <= 3.5.6 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "YayCommerce"
        ],
        "products": [
          {
            "vendor": "YayCommerce",
            "product": "YayPricing"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00223,
        "percentile": 0.13009
      },
      "nvd": {
        "published": "2026-07-27T15:17:11.443",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66442",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "A subscriber can perform a YayPricing operation outside that role's intended authority, but the endpoint, object, and missing check are not public.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/yaypricing/vulnerability/wordpress-yaypricing-plugin-3-5-6-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 65,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66445",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:00:28.156Z",
      "date_published": "2026-07-27T13:59:29.014Z",
      "date_updated": "2026-07-27T14:59:13.003Z",
      "publisher": "Patchstack",
      "title": "WordPress Open User Map plugin <= 1.4.46 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "100plugins"
        ],
        "products": [
          {
            "vendor": "100plugins",
            "product": "Open User Map"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03049
      },
      "nvd": {
        "published": "2026-07-27T15:17:11.573",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66445",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Open User Map page renders attacker-controlled data as HTML or JavaScript without context-appropriate escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/open-user-map/vulnerability/wordpress-open-user-map-plugin-1-4-46-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 75,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66448",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:00:28.156Z",
      "date_published": "2026-07-27T13:59:29.665Z",
      "date_updated": "2026-07-27T15:00:25.170Z",
      "publisher": "Patchstack",
      "title": "WordPress Gallery PhotoBlocks plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "WP Chill"
        ],
        "products": [
          {
            "vendor": "WP Chill",
            "product": "Gallery PhotoBlocks"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0013,
        "percentile": 0.03052
      },
      "nvd": {
        "published": "2026-07-27T15:17:11.703",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66448",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Gallery PhotoBlocks lets contributor input reach generated page markup without sufficient browser-context escaping.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/photoblocks-grid-gallery/vulnerability/wordpress-gallery-photoblocks-plugin-1-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 80,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66473",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:00:40.310Z",
      "date_published": "2026-07-27T22:43:58.434Z",
      "date_updated": "2026-07-28T13:55:36.659Z",
      "publisher": "Patchstack",
      "title": "WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Xendit"
        ],
        "products": [
          {
            "vendor": "Xendit",
            "product": "Xendit Payment"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00202,
        "percentile": 0.10277
      },
      "nvd": {
        "published": "2026-07-27T23:16:42.970",
        "lastModified": "2026-07-28T16:19:12.780",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66473",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation is reachable without the authentication or authorization decision required for its protected action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/woo-xendit-virtual-accounts/vulnerability/wordpress-xendit-payment-plugin-7-1-0-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 74,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66474",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:50:27.375Z",
      "date_published": "2026-07-27T13:59:30.332Z",
      "date_updated": "2026-07-27T18:16:25.406Z",
      "publisher": "Patchstack",
      "title": "WordPress Insert Headers and Footers Code – HT Script plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) vulnerability",
      "affected": {
        "vendors": [
          "HT Plugins"
        ],
        "products": [
          {
            "vendor": "HT Plugins",
            "product": "Insert Headers and Footers Code – HT Script"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-352",
          "name": "Cross-Site Request Forgery (CSRF)",
          "abstraction": "Compound",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00098,
        "percentile": 0.00906
      },
      "nvd": {
        "published": "2026-07-27T15:17:11.833",
        "lastModified": "2026-07-27T19:17:23.240",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66474",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Insert Headers and Footers Code – HT Script accepts a browser-carried state-changing request without a CSRF token or equivalent origin binding, allowing another site to submit the request with the user's authority.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-352"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/insert-headers-and-footers-script/vulnerability/wordpress-insert-headers-and-footers-code-ht-script-plugin-1-1-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 115,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66475",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:50:27.375Z",
      "date_published": "2026-07-27T13:59:30.985Z",
      "date_updated": "2026-07-27T16:22:36.892Z",
      "publisher": "Patchstack",
      "title": "WordPress Checkout Field Editor for WooCommerce &#8211; Checkout Manager plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability",
      "affected": {
        "vendors": [
          "acowebs"
        ],
        "products": [
          {
            "vendor": "acowebs",
            "product": "Checkout Field Editor for WooCommerce &#8211; Checkout Manager"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0014,
        "percentile": 0.03785
      },
      "nvd": {
        "published": "2026-07-27T15:17:11.963",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66475",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Checkout Field Editor renders shop-manager-controlled input into a browser context without the required contextual neutralization.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/checkout-field-editor-and-manager-for-woocommerce/vulnerability/wordpress-checkout-field-editor-for-woocommerce-8211-checkout-manager-plugin-3-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 124,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66476",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:50:27.375Z",
      "date_published": "2026-07-27T13:59:31.622Z",
      "date_updated": "2026-07-27T16:17:23.498Z",
      "publisher": "Patchstack",
      "title": "WordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vulnerability",
      "affected": {
        "vendors": [
          "Syed Balkhi"
        ],
        "products": [
          {
            "vendor": "Syed Balkhi",
            "product": "Easy Digital Downloads"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 4.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00325,
        "percentile": 0.24995
      },
      "nvd": {
        "published": "2026-07-27T15:17:12.090",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66476",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The public record identifies unintended file access in Easy Digital Downloads, but does not disclose how the selected path escapes its intended namespace.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/plugin/easy-digital-downloads/vulnerability/wordpress-easy-digital-downloads-plugin-3-6-9-arbitrary-file-deletion-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 82,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66477",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T09:50:27.375Z",
      "date_published": "2026-07-27T13:59:32.265Z",
      "date_updated": "2026-07-27T16:06:08.418Z",
      "publisher": "Patchstack",
      "title": "WordPress Gillion theme <= 4.13 - Broken Access Control vulnerability",
      "affected": {
        "vendors": [
          "Shufflehound"
        ],
        "products": [
          {
            "vendor": "Shufflehound",
            "product": "Gillion"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:audit@patchstack.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00176,
        "percentile": 0.0731
      },
      "nvd": {
        "published": "2026-07-27T15:17:12.223",
        "lastModified": "2026-07-27T17:46:02.447",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66477",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "The affected operation is reachable without the authorization check required for the requested action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://patchstack.com/database/wordpress/theme/gillion/vulnerability/wordpress-gillion-theme-4-13-broken-access-control-vulnerability?_s_id=cve",
          "host": "patchstack.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 66,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66488",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T12:46:59.195Z",
      "date_published": "2026-07-29T13:55:19.393Z",
      "date_updated": "2026-07-31T05:44:37.479Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Gridbox extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-285",
          "name": "Improper Authorization",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00204,
        "percentile": 0.10591
      },
      "nvd": {
        "published": "2026-07-29T14:16:34.167",
        "lastModified": "2026-07-30T19:18:36.483",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66488",
        "family": "STATE_SEQUENCE",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Gridbox permits a payment-protected action to complete without payment, but the public record does not disclose the missing workflow transition.",
        "basis": [
          "CNA",
          "CWE-285"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.balbooa.com/gridbox",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 67,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66489",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T12:46:59.195Z",
      "date_published": "2026-07-29T13:55:28.801Z",
      "date_updated": "2026-07-31T05:44:48.057Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Gridbox extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10683
      },
      "nvd": {
        "published": "2026-07-29T14:16:34.270",
        "lastModified": "2026-07-30T20:18:13.560",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66489",
        "family": "EXPOSURE_OUTPUT",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Gridbox exposes filesystem data to an unauthenticated observer, while the public record does not identify the path selector, access check, or returned objects.",
        "basis": [
          "CNA",
          "CWE-200"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.balbooa.com/gridbox",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 99,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66490",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T13:01:42.270Z",
      "date_published": "2026-07-29T13:54:24.941Z",
      "date_updated": "2026-07-29T15:09:31.680Z",
      "publisher": "Joomla",
      "title": "Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2",
      "affected": {
        "vendors": [
          "balbooa.com"
        ],
        "products": [
          {
            "vendor": "balbooa.com",
            "product": "Gridbox extension for Joomla"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00155,
        "percentile": 0.05133
      },
      "nvd": {
        "published": "2026-07-29T14:16:34.373",
        "lastModified": "2026-07-30T14:06:56.363",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66490",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.balbooa.com/gridbox",
          "host": "www.balbooa.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/",
          "host": "mysites.guru",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 101,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66713",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T14:49:00.907Z",
      "date_published": "2026-07-28T13:44:29.702Z",
      "date_updated": "2026-07-29T03:55:41.433Z",
      "publisher": "apache",
      "title": "Apache Axis2/Java: deserialization of untrusted Data",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Axis2/Java"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.01195,
        "percentile": 0.65008
      },
      "nvd": {
        "published": "2026-07-28T15:17:50.430",
        "lastModified": "2026-07-29T05:17:07.703",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66713",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Tribes cluster listener deserializes attacker-controlled Java objects received on an unauthenticated clustering channel.",
        "basis": [
          "CNA",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/apache/axis-axis2-java-core/commit/e6f53b230bddcb40577c84ff290ba51e7265fa15",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://lists.apache.org/thread/fgggbv3sjjqw7p6q0j88gspt9b2rb728",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/28/2",
          "host": "www.openwall.com",
          "sources": [
            "adp:1",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 646,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66720",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T19:32:49.387Z",
      "date_published": "2026-07-30T22:46:52.453Z",
      "date_updated": "2026-07-31T15:58:46.395Z",
      "publisher": "icscert",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "affected": {
        "vendors": [
          "MZ Automation GmbH"
        ],
        "products": [
          {
            "vendor": "MZ Automation GmbH",
            "product": "libiec61850"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:ics-cert@hq.dhs.gov",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00175,
        "percentile": 0.07148
      },
      "nvd": {
        "published": "2026-07-30T23:16:53.830",
        "lastModified": "2026-07-31T16:17:10.990",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66720",
        "family": "MEMORY_LIFETIME",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The GOOSE parser accepts an undersized UTC timestamp field and reads past its heap buffer while processing the unauthenticated frame.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10",
          "host": "www.cisa.gov",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 377,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66723",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T15:50:32.128Z",
      "date_published": "2026-07-29T14:12:35.422Z",
      "date_updated": "2026-07-29T15:06:22.512Z",
      "publisher": "CERT-PL",
      "title": "Missing authentication requirement in Remote Instances proxy API in MWDB Core",
      "affected": {
        "vendors": [
          "CERT.PL"
        ],
        "products": [
          {
            "vendor": "CERT.PL",
            "product": "MWDB Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00494,
        "percentile": 0.3973
      },
      "nvd": {
        "published": "2026-07-29T15:16:29.877",
        "lastModified": "2026-07-30T16:29:42.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66723",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The affected action runs without the capability or object-level authorization check required for that caller.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-66723",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/CERT-Polska/mwdb-core/security/advisories/GHSA-942c-r7qj-w895",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/CERT-Polska/mwdb-core/releases/tag/v2.19.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 651,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66724",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T15:50:32.128Z",
      "date_published": "2026-07-29T14:12:25.620Z",
      "date_updated": "2026-07-29T15:04:34.830Z",
      "publisher": "CERT-PL",
      "title": "Permission Bypass Via Undocumented HTTP Methods In MWDB Core",
      "affected": {
        "vendors": [
          "CERT.PL"
        ],
        "products": [
          {
            "vendor": "CERT.PL",
            "product": "MWDB Core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:cvd@cert.pl",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00268,
        "percentile": 0.18807
      },
      "nvd": {
        "published": "2026-07-29T15:16:30.010",
        "lastModified": "2026-07-30T16:29:42.347",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66724",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Deprecated POST upload routes bypass the capability checks applied to the documented PUT routes.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://cert.pl/en/posts/2026/07/CVE-2026-66723",
          "host": "cert.pl",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/CERT-Polska/mwdb-core/security/advisories/GHSA-8fv8-wffg-4323",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/CERT-Polska/mwdb-core/releases/tag/v2.19.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 514,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66729",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:27:47.646Z",
      "date_published": "2026-07-27T16:52:34.776Z",
      "date_updated": "2026-07-31T18:19:06.846Z",
      "publisher": "VulnCheck",
      "title": "facil.io 0.6.0 - 0.7.6 Integer Underflow DoS via Multipart MIME Body Parser",
      "affected": {
        "vendors": [
          "boazsegev"
        ],
        "products": [
          {
            "vendor": "boazsegev",
            "product": "facil.io"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00596,
        "percentile": 0.45126
      },
      "nvd": {
        "published": "2026-07-27T17:16:42.517",
        "lastModified": "2026-07-31T19:17:11.753",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66729",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An empty multipart field name underflows unsigned arithmetic and makes the MIME parser read beyond the name buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://tpaidakis.com/writeups/facilio-parser-dos/",
          "host": "tpaidakis.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/theopaid/Out-of-Bounds-Read-in-facil.io-MIME-Parser-leads-to-Server-Crash",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/facil-io-integer-underflow-dos-via-multipart-mime-body-parser",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 465,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66730",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:27:47.646Z",
      "date_published": "2026-07-27T16:55:27.200Z",
      "date_updated": "2026-07-31T18:19:33.702Z",
      "publisher": "VulnCheck",
      "title": "facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser",
      "affected": {
        "vendors": [
          "boazsegev"
        ],
        "products": [
          {
            "vendor": "boazsegev",
            "product": "facil.io"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00596,
        "percentile": 0.45127
      },
      "nvd": {
        "published": "2026-07-27T17:16:42.660",
        "lastModified": "2026-07-31T19:17:11.890",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66730",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The parser can return zero progress without setting done or error, causing its caller to loop forever.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://tpaidakis.com/writeups/facilio-parser-dos/",
          "host": "tpaidakis.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/theopaid/Infinite-Loop-DoS-in-facil.io-MIME-Parser",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/facil-io-infinite-loop-dos-via-multipart-mime-body-parser",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 573,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66731",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:27:47.646Z",
      "date_published": "2026-07-27T16:57:01.077Z",
      "date_updated": "2026-07-31T18:20:09.600Z",
      "publisher": "VulnCheck",
      "title": "facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS",
      "affected": {
        "vendors": [
          "boazsegev"
        ],
        "products": [
          {
            "vendor": "boazsegev",
            "product": "facil.io"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00596,
        "percentile": 0.45127
      },
      "nvd": {
        "published": "2026-07-27T17:16:42.793",
        "lastModified": "2026-07-31T19:17:12.020",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66731",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A negative HTTP chunk size becomes a large positive value and advances the parser read pointer beyond mapped memory.",
        "basis": [
          "CNA record",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://tpaidakis.com/writeups/facilio-parser-dos/",
          "host": "tpaidakis.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/theopaid/Negative-Chunk-Size-Parsing-Causes-Memory-Corruption-in-facil.io-leading-to-Server-Crash",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/facil-io-http-chunked-transfer-encoding-parser-crash-dos",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 558,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66745",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:27:47.647Z",
      "date_published": "2026-07-28T18:10:46.904Z",
      "date_updated": "2026-07-29T14:00:09.264Z",
      "publisher": "VulnCheck",
      "title": "Artica Proxy 4.50 Session Fixation via fw.login.php",
      "affected": {
        "vendors": [
          "ArticaTech"
        ],
        "products": [
          {
            "vendor": "ArticaTech",
            "product": "Artica Proxy"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00316,
        "percentile": 0.24033
      },
      "nvd": {
        "published": "2026-07-28T19:17:41.440",
        "lastModified": "2026-07-30T20:11:09.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66745",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The login path does not rotate a caller-chosen PHP session identifier after authentication, so the attacker can reuse the now-administrative session.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://wiki.articatech.com/maintenance/upgrade-artica/hotfix-450000000",
          "host": "wiki.articatech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.articatech.com/hotfixes.php?main=4.50.000000&sp=7",
          "host": "www.articatech.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/artica-proxy-session-fixation-via-fw-login-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 470,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66746",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:27:47.647Z",
      "date_published": "2026-07-28T16:06:18.551Z",
      "date_updated": "2026-07-29T13:50:46.539Z",
      "publisher": "VulnCheck",
      "title": "Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection",
      "affected": {
        "vendors": [
          "tomaka"
        ],
        "products": [
          {
            "vendor": "tomaka",
            "product": "rouille"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-113",
          "name": "Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.00241,
        "percentile": 0.15336
      },
      "nvd": {
        "published": "2026-07-28T16:20:16.160",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66746",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Rouille accepts carriage-return or line-feed bytes in response-header values and emits them as new HTTP header grammar.",
        "basis": [
          "CNA",
          "CWE-113"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/theopaid/HTTP-Response-Splitting-via-Unvalidated-Response-Header-Values-rouille-",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rouille-http-response-splitting-via-header-injection",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 565,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66748",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:27:47.648Z",
      "date_published": "2026-07-28T15:19:52.609Z",
      "date_updated": "2026-07-31T20:59:55.287Z",
      "publisher": "VulnCheck",
      "title": "Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field",
      "affected": {
        "vendors": [
          "owen2345"
        ],
        "products": [
          {
            "vendor": "owen2345",
            "product": "camaleon-cms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00805,
        "percentile": 0.53255
      },
      "nvd": {
        "published": "2026-07-28T16:20:16.310",
        "lastModified": "2026-07-31T21:17:32.010",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66748",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Camaleon stores a custom-field command and later passes it to instance_eval inside an ERB view.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://tpaidakis.com/writeups/camaleon-cms-rce-select-eval/",
          "host": "tpaidakis.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://enrik-m.github.io/posts/Camaleon-CMS-Vulnerabilties/",
          "host": "enrik-m.github.io",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/theopaid/Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/owen2345/camaleon-cms/releases/tag/2.9.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/owen2345/camaleon-cms/pull/1136",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/owen2345/camaleon-cms/commit/158823668e2e5c3114a69b34cf1c96cb41533c5f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/camaleon-cms-authenticated-rce-via-select-eval-custom-field",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 535,
        "referenceCount": 7,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66749",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:27:47.648Z",
      "date_published": "2026-07-28T15:30:46.773Z",
      "date_updated": "2026-07-28T16:43:43.566Z",
      "publisher": "VulnCheck",
      "title": "Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup",
      "affected": {
        "vendors": [
          "sdelements"
        ],
        "products": [
          {
            "vendor": "sdelements",
            "product": "lets-chat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00311,
        "percentile": 0.23513
      },
      "nvd": {
        "published": "2026-07-28T16:20:16.457",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66749",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The affected path dereferences a missing object after a failed lookup without checking for a null result.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/theopaid/Unchecked-Room-Lookup-Leads-to-Server-Crash-Let-s-Chat-",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/let-s-chat-denial-of-service-via-null-dereference-in-room-lookup",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 486,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66750",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:27:47.648Z",
      "date_published": "2026-07-28T15:33:04.344Z",
      "date_updated": "2026-07-28T17:07:53.332Z",
      "publisher": "VulnCheck",
      "title": "Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files route",
      "affected": {
        "vendors": [
          "sdelements"
        ],
        "products": [
          {
            "vendor": "sdelements",
            "product": "lets-chat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 1,
      "epss": {
        "score": 0.00263,
        "percentile": 0.18077
      },
      "nvd": {
        "published": "2026-07-28T16:20:16.603",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66750",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The file retrieval route checks login but omits room membership and Room.canJoin, allowing adjacent attachment IDs to expose private-room files.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/theopaid/Insufficient-Access-Controls-Allow-for-Unauthorized-File-Downloads-Let-s-Chat-",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/let-s-chat-broken-access-control-file-disclosure-via-get-files-route",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 564,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66751",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:27:47.648Z",
      "date_published": "2026-07-28T15:36:15.896Z",
      "date_updated": "2026-07-28T17:23:26.914Z",
      "publisher": "VulnCheck",
      "title": "Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room",
      "affected": {
        "vendors": [
          "sdelements"
        ],
        "products": [
          {
            "vendor": "sdelements",
            "product": "lets-chat"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.4,
      "cvss_source_score_spread": 0.10000000000000053,
      "epss": {
        "score": 0.00213,
        "percentile": 0.11712
      },
      "nvd": {
        "published": "2026-07-28T16:20:16.747",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66751",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Let's Chat's DELETE room handler accepts any enumerated room ID without verifying that the authenticated caller owns or can access that room.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/theopaid/Insufficient-Access-Controls-Allow-for-Unauthorized-Room-Deletion-Let-s-Chat-",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/let-s-chat-improper-authorization-via-delete-rooms-room",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 464,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66752",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:27:47.648Z",
      "date_published": "2026-07-28T15:44:41.573Z",
      "date_updated": "2026-07-28T17:31:58.190Z",
      "publisher": "VulnCheck",
      "title": "tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling",
      "affected": {
        "vendors": [
          "tiny-http"
        ],
        "products": [
          {
            "vendor": "tiny-http",
            "product": "tiny-http"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00237,
        "percentile": 0.1481
      },
      "nvd": {
        "published": "2026-07-28T16:20:16.887",
        "lastModified": "2026-07-30T20:03:32.983",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66752",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "tiny-http treats every Transfer-Encoding value as chunked and discards Content-Length, disagreeing with a front-end proxy about request boundaries.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/theopaid/HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http-/tree/master",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/tiny-http-http-request-smuggling-via-transfer-encoding-handling",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 745,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66753",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:27:47.648Z",
      "date_published": "2026-07-28T15:46:28.786Z",
      "date_updated": "2026-07-28T19:30:13.132Z",
      "publisher": "VulnCheck",
      "title": "tiny-http 0.12.0 HTTP Response Splitting via Header Injection",
      "affected": {
        "vendors": [
          "tiny-http"
        ],
        "products": [
          {
            "vendor": "tiny-http",
            "product": "tiny-http"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-113",
          "name": "Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 3.7,
          "severity": "LOW",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 2.5999999999999996,
      "epss": {
        "score": 0.00218,
        "percentile": 0.12314
      },
      "nvd": {
        "published": "2026-07-28T16:20:17.093",
        "lastModified": "2026-07-30T20:03:32.983",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66753",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The tiny-http HTTP path accepts carriage-return or line-feed bytes inside header values, allowing a new protocol field or message to be injected.",
        "basis": [
          "CNA",
          "CWE-113"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/theopaid/HTTP-Header-Injection-via-Unvalidated-CR-and-LF-in-Header-Values-tiny_http-/tree/master",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/tiny-http-http-response-splitting-via-header-injection",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 504,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66754",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:27:47.648Z",
      "date_published": "2026-07-28T16:04:29.604Z",
      "date_updated": "2026-07-29T13:49:13.429Z",
      "publisher": "VulnCheck",
      "title": "Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding",
      "affected": {
        "vendors": [
          "tomaka"
        ],
        "products": [
          {
            "vendor": "tomaka",
            "product": "rouille"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-617",
          "name": "Reachable Assertion",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.00401,
        "percentile": 0.32929
      },
      "nvd": {
        "published": "2026-07-28T16:20:17.267",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66754",
        "family": "OTHER_SPECIFIC",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Rouille compares a decoded prefix but asserts against the raw encoded path, making a crafted percent-encoded URL reach a failing assertion.",
        "basis": [
          "CNA",
          "CWE-617"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/theopaid/Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille-",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rouille-reachable-assertion-dos-via-remove-prefix-percent-encoding",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 467,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66755",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T16:42:27.573Z",
      "date_published": "2026-07-30T19:16:42.370Z",
      "date_updated": "2026-07-30T19:34:10.134Z",
      "publisher": "apache",
      "title": "Apache Tika: Arbitrary Local File Read in ISArchiveParser",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Tika"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00161,
        "percentile": 0.0573
      },
      "nvd": {
        "published": "2026-07-30T20:18:13.717",
        "lastModified": "2026-07-30T20:26:03.723",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66755",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output, via a \"Study Assay File Name\" value in the ISA-Tab investigation file that traverses outside the dataset directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/0hcctcp9s5lxgq2ookp4o6chltk99f8r",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/23",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 551,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-66756",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T17:13:07.869Z",
      "date_published": "2026-07-30T19:18:07.900Z",
      "date_updated": "2026-07-30T19:33:01.657Z",
      "publisher": "apache",
      "title": "Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false",
      "affected": {
        "vendors": [
          "Apache Software Foundation"
        ],
        "products": [
          {
            "vendor": "Apache Software Foundation",
            "product": "Apache Tika"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-424",
          "name": "Improper Protection of Alternate Path",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@apache.org",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00315,
        "percentile": 0.23866
      },
      "nvd": {
        "published": "2026-07-30T20:18:13.877",
        "lastModified": "2026-07-30T20:26:03.723",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66756",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The Tika unpack endpoint remains reachable when unsecureFeatures is false, leaving an alternate processing path outside the intended setting.",
        "basis": [
          "CNA",
          "CWE-424"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://lists.apache.org/thread/ynjg5lxwhqpc83pczf5y5561o2l4o568",
          "host": "lists.apache.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "http://www.openwall.com/lists/oss-security/2026/07/30/24",
          "host": "www.openwall.com",
          "sources": [
            "adp:0",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 222,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66757",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T17:24:27.249Z",
      "date_published": "2026-07-27T19:07:13.384Z",
      "date_updated": "2026-07-31T15:19:36.468Z",
      "publisher": "redhat",
      "title": "Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi images",
      "affected": {
        "vendors": [
          "GNOME",
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "GNOME",
            "product": "GIMP"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected",
          "unknown"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0012,
        "percentile": 0.02113
      },
      "nvd": {
        "published": "2026-07-27T19:17:23.473",
        "lastModified": "2026-07-31T16:17:11.113",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66757",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unchecked integer calculation wraps before the result is used for a memory or bounds decision.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-66757",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507465",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/work_items/16494",
          "host": "gitlab.gnome.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 512,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-66758",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T17:24:27.249Z",
      "date_published": "2026-07-27T19:07:12.789Z",
      "date_updated": "2026-07-31T15:10:06.999Z",
      "publisher": "redhat",
      "title": "Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits images",
      "affected": {
        "vendors": [
          "GNOME",
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "GNOME",
            "product": "GIMP"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-190",
          "name": "Integer Overflow or Wraparound",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00147,
        "percentile": 0.04391
      },
      "nvd": {
        "published": "2026-07-27T19:17:23.613",
        "lastModified": "2026-07-31T16:17:11.283",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66758",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "GIMP performs security-relevant size arithmetic without rejecting an integer overflow or wraparound.",
        "basis": [
          "CNA",
          "CWE-190"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-66758",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507475",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/issues/16528",
          "host": "gitlab.gnome.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        }
      ],
      "record_shape": {
        "descriptionChars": 568,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-66759",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T17:24:27.249Z",
      "date_published": "2026-07-27T19:12:27.455Z",
      "date_updated": "2026-08-03T17:54:12.000Z",
      "publisher": "redhat",
      "title": "Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns images",
      "affected": {
        "vendors": [
          "GNOME",
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "GNOME",
            "product": "GIMP"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 5,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected",
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00125,
        "percentile": 0.02576
      },
      "nvd": {
        "published": "2026-07-27T19:17:23.747",
        "lastModified": "2026-08-03T19:16:49.817",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66759",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A length, offset, or termination error makes the program read beyond the end of an allocated buffer.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-66759",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507557",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/issues/16528",
          "host": "gitlab.gnome.org",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 585,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 5,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66803",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T19:02:26.600Z",
      "date_published": "2026-07-30T20:28:04.898Z",
      "date_updated": "2026-08-03T22:59:07.731Z",
      "publisher": "microsoft",
      "title": "Azure Cosmos DB Remote Code Execution Vulnerability",
      "affected": {
        "vendors": [
          "Microsoft"
        ],
        "products": [
          {
            "vendor": "Microsoft",
            "product": "Azure Cosmos DB"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"
        },
        {
          "source": "NVD:secure@microsoft.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00494,
        "percentile": 0.39728
      },
      "nvd": {
        "published": "2026-07-30T21:18:12.743",
        "lastModified": "2026-08-04T00:17:39.977",
        "vulnStatus": "Undergoing Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66803",
        "family": "AUTHORITY_BINDING",
        "precision": "BROAD_RECORD",
        "confidence": "medium",
        "mechanism": "Azure Cosmos DB permits an unauthenticated network caller to reach a code-execution path, but Microsoft does not publish the protected operation or missing authorization decision.",
        "basis": [
          "CNA",
          "CWE-284",
          "Microsoft Security Update Guide"
        ],
        "deepDive": true,
        "notes": "Inspected https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803; the accessible Microsoft page adds no technical detail beyond improper access control and network code execution, so the protected Cosmos DB operation remains non-public."
      },
      "references": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803",
          "host": "msrc.microsoft.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 106,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66824",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T19:56:54.970Z",
      "date_published": "2026-07-27T19:58:28.248Z",
      "date_updated": "2026-07-28T15:20:13.121Z",
      "publisher": "CIRCL",
      "title": "Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding",
      "affected": {
        "vendors": [
          "lookyloo"
        ],
        "products": [
          {
            "vendor": "lookyloo",
            "product": "lookyloo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19912
      },
      "nvd": {
        "published": "2026-07-27T21:17:17.500",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66824",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Lookyloo embeds attacker-derived serialized capture data into an inline script with the safe filter, allowing a value to close the script element and inject code.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Lookyloo/lookyloo/commit/395187b57322ab311363ccc290c010b180389009",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1067,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66825",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-27T20:19:38.433Z",
      "date_published": "2026-07-27T20:20:05.051Z",
      "date_updated": "2026-07-28T14:18:25.699Z",
      "publisher": "CIRCL",
      "title": "Cross-Site Scripting via Unsafe URL Schemes in Pivotick Property Links",
      "affected": {
        "vendors": [
          "pivotick"
        ],
        "products": [
          {
            "vendor": "pivotick",
            "product": "pivotick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19912
      },
      "nvd": {
        "published": "2026-07-27T21:17:17.667",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66825",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pivotick renders property values as clickable links without normalizing and allowlisting URL schemes, so a javascript URL becomes executable browser code.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Pivotick/Pivotick/commit/84ddc064d53e9e20cce4077d1192bfdb3aecf17b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 906,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66913",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T12:19:10.431Z",
      "date_published": "2026-07-28T12:19:20.977Z",
      "date_updated": "2026-07-28T19:20:16.204Z",
      "publisher": "CIRCL",
      "title": "Zip Bomb in Lookyloo Capture Upload Allows Denial of Service",
      "affected": {
        "vendors": [
          "lookyloo"
        ],
        "products": [
          {
            "vendor": "lookyloo",
            "product": "lookyloo"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.1674
      },
      "nvd": {
        "published": "2026-07-28T13:19:06.530",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66913",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Lookyloo decompresses uploaded archives and HAR data in memory without an output-size limit, allowing compressed input to exhaust memory.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Lookyloo/lookyloo/commit/96589da290f018e356db7c0eaddf1aa501630ca7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1103,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66918",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T12:42:08.604Z",
      "date_published": "2026-07-28T12:42:11.043Z",
      "date_updated": "2026-07-28T19:23:50.988Z",
      "publisher": "CIRCL",
      "title": "DOM-Based Cross-Site Scripting via Unsanitized SVG Node Icons",
      "affected": {
        "vendors": [
          "pivotick"
        ],
        "products": [
          {
            "vendor": "pivotick",
            "product": "pivotick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19911
      },
      "nvd": {
        "published": "2026-07-28T13:19:06.693",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66918",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The application assigns attacker-controlled SVG markup to innerHTML and executes it in the page context.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Pivotick/Pivotick/commit/8dbfe4ca3582e715535d261535a0d632ce271dea",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 915,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66919",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T12:47:54.448Z",
      "date_published": "2026-07-28T12:48:05.640Z",
      "date_updated": "2026-07-28T19:25:34.607Z",
      "publisher": "CIRCL",
      "title": "Stored DOM-Based Cross-Site Scripting in Node Modal Headers",
      "affected": {
        "vendors": [
          "Pivotick"
        ],
        "products": [
          {
            "vendor": "Pivotick",
            "product": "Pivotick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00262,
        "percentile": 0.1787
      },
      "nvd": {
        "published": "2026-07-28T13:19:06.847",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66919",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pivotick interpolates graph labels and descriptions directly into modal-header HTML instead of assigning them as text.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Pivotick/Pivotick/commit/71d72d59234c65c423cb8d45eaa291a7b2a9b5e1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 836,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66920",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T12:57:17.742Z",
      "date_published": "2026-07-28T12:57:21.098Z",
      "date_updated": "2026-07-28T19:26:22.732Z",
      "publisher": "CIRCL",
      "title": "Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data",
      "affected": {
        "vendors": [
          "Pivotick"
        ],
        "products": [
          {
            "vendor": "Pivotick",
            "product": "Pivotick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16738
      },
      "nvd": {
        "published": "2026-07-28T13:19:07.030",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66920",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Pivotick recursively traverses attacker-controlled graph and JSON structures without an effective depth or cycle bound.",
        "basis": [
          "CNA",
          "CWE-400",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Pivotick/Pivotick/commit/66373141eb7892fc29a3b42cfb2c160af16765fe",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1002,
        "referenceCount": 1,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66921",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T13:05:10.153Z",
      "date_published": "2026-07-28T13:05:19.166Z",
      "date_updated": "2026-07-28T14:18:44.783Z",
      "publisher": "CIRCL",
      "title": "Pivotick - Stored DOM-Based Cross-Site Scripting via Unescaped Markdown Node References",
      "affected": {
        "vendors": [
          "pivotick"
        ],
        "products": [
          {
            "vendor": "pivotick",
            "product": "pivotick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:H/SA:H"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19912
      },
      "nvd": {
        "published": "2026-07-28T14:16:40.367",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66921",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pivotick interpolates an unescaped nodeName into both an HTML attribute and element body, allowing markup metacharacters to inject script-capable DOM.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Pivotick/Pivotick/commit/4c13ff2b0ec769881b5526feddef37c0c5a08885",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1218,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-66922",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T13:20:04.049Z",
      "date_published": "2026-07-28T13:20:08.962Z",
      "date_updated": "2026-07-28T14:18:05.141Z",
      "publisher": "CIRCL",
      "title": "Pivotick Prototype-Key Collision in Tree Layout and Cycle Detection Allows Graph Manipulation and Denial of Service",
      "affected": {
        "vendors": [
          "pivotick"
        ],
        "products": [
          {
            "vendor": "pivotick",
            "product": "pivotick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-1321",
          "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
          "abstraction": "Variant",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00284,
        "percentile": 0.20638
      },
      "nvd": {
        "published": "2026-07-28T14:16:40.533",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-66922",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-layout and cycle-detection components.",
        "basis": [
          "CNA",
          "CWE-1321"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Pivotick/Pivotick/commit/4e12922627029af77476c6f1ab8a14e98d5ef451",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1443,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67173",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T13:32:08.981Z",
      "date_published": "2026-07-28T13:32:13.651Z",
      "date_updated": "2026-07-28T14:17:26.690Z",
      "publisher": "CIRCL",
      "title": "Pivotick Unvalidated Node Image URLs Allow Unintended Client-Side Requests",
      "affected": {
        "vendors": [
          "pivotick"
        ],
        "products": [
          {
            "vendor": "pivotick",
            "product": "pivotick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.1,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00341,
        "percentile": 0.26749
      },
      "nvd": {
        "published": "2026-07-28T14:16:40.690",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67173",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The graph renderer assigns an unvalidated imagePath scheme to an SVG image resource, allowing unintended client-side requests or protocol handling.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Pivotick/Pivotick/commit/2a6ad284e7ed69ab845087febe47f4cc82f13e1c",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 903,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67174",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T13:53:32.327Z",
      "date_published": "2026-07-28T13:53:41.527Z",
      "date_updated": "2026-07-28T14:49:00.996Z",
      "publisher": "CIRCL",
      "title": "DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick",
      "affected": {
        "vendors": [
          "pivotick"
        ],
        "products": [
          {
            "vendor": "pivotick",
            "product": "pivotick"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-79",
          "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00385,
        "percentile": 0.31307
      },
      "nvd": {
        "published": "2026-07-28T15:17:51.073",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67174",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Pivotick assigns untrusted strings and SVG icon markup to template.innerHTML without sanitization, allowing those values to create active DOM content.",
        "basis": [
          "CNA",
          "CWE-79"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Pivotick/Pivotick/commit/67c597cdf7f6910f97a4c73905a7b845e0d039f1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1407,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67178",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T14:30:17.943Z",
      "date_published": "2026-07-28T14:30:22.103Z",
      "date_updated": "2026-07-28T14:44:14.153Z",
      "publisher": "CIRCL",
      "title": "Open Redirect in MISP Installer-Generated Apache Configuration",
      "affected": {
        "vendors": [
          "misp"
        ],
        "products": [
          {
            "vendor": "misp",
            "product": "misp"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:H"
        },
        {
          "source": "NVD:5a6e4751-2f3f-4070-9419-94fb35b644e8",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.8,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 7.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00493,
        "percentile": 0.39641
      },
      "nvd": {
        "published": "2026-07-28T15:17:51.213",
        "lastModified": "2026-07-30T16:55:34.270",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67178",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The generated Apache redirect omits the slash after the HTTPS host, allowing attacker-controlled path bytes to become URL userinfo and a new destination host.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/MISP/MISP/commit/15becd3b21245ddc6a8b5dad46e983ade405ddf8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 1650,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67181",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.773Z",
      "date_published": "2026-07-28T16:10:29.527Z",
      "date_updated": "2026-07-28T16:35:34.542Z",
      "publisher": "VulnCheck",
      "title": "Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header",
      "affected": {
        "vendors": [
          "tomaka"
        ],
        "products": [
          {
            "vendor": "tomaka",
            "product": "rouille"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.3,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 5.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.3,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21404
      },
      "nvd": {
        "published": "2026-07-28T16:20:20.103",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67181",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Rouille forwards Transfer-Encoding after its frontend has already de-chunked the body, allowing frontend and backend request boundaries to disagree.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/theopaid/HTTP-Request-Smuggling-via-Transfer-Encoding-Desynchronization-rouille-",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rouille-http-request-smuggling-via-proxy-transfer-encoding-header",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 494,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67182",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.773Z",
      "date_published": "2026-07-28T16:18:08.550Z",
      "date_updated": "2026-07-28T17:10:35.695Z",
      "publisher": "VulnCheck",
      "title": "Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection",
      "affected": {
        "vendors": [
          "tomaka"
        ],
        "products": [
          {
            "vendor": "tomaka",
            "product": "rouille"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-444",
          "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:L/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00415,
        "percentile": 0.34208
      },
      "nvd": {
        "published": "2026-07-28T17:17:07.587",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67182",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Rouille copies a bare line feed in a client header to the upstream stream, where the backend parses the injected bytes as a second request.",
        "basis": [
          "CNA",
          "CWE-444"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/theopaid/HTTP-Request-Smuggling-Enables-Front-End-Access-Control-Bypass-rouille-",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/rouille-http-request-smuggling-via-proxy-header-injection",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 623,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67183",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.773Z",
      "date_published": "2026-07-28T16:26:09.306Z",
      "date_updated": "2026-07-28T17:22:18.525Z",
      "publisher": "VulnCheck",
      "title": "TinyWeb 0.0.8 Memory Leak DoS via HTTP Request Handling",
      "affected": {
        "vendors": [
          "GeneralSandman"
        ],
        "products": [
          {
            "vendor": "GeneralSandman",
            "product": "TinyWeb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00367,
        "percentile": 0.2944
      },
      "nvd": {
        "published": "2026-07-28T17:17:07.737",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67183",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Per-request objects are allocated without a corresponding release path.",
        "basis": [
          "CNA",
          "CWE-401"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/theopaid/Unauthenticated-Memory-Leak-Leads-To-Memory-Exhaustion-TinyWeb-",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/tinyweb-memory-leak-dos-via-http-request-handling",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67184",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.773Z",
      "date_published": "2026-07-28T16:28:48.056Z",
      "date_updated": "2026-07-28T17:38:17.829Z",
      "publisher": "VulnCheck",
      "title": "TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request",
      "affected": {
        "vendors": [
          "GeneralSandman"
        ],
        "products": [
          {
            "vendor": "GeneralSandman",
            "product": "TinyWeb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-476",
          "name": "NULL Pointer Dereference",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00432,
        "percentile": 0.35517
      },
      "nvd": {
        "published": "2026-07-28T17:17:07.880",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67184",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Failed HTTP-version parsing leaves url null and buildResponse dereferences it without checking valid_requ.",
        "basis": [
          "CNA record",
          "CWE-476"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/theopaid/Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb-",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/tinyweb-null-pointer-dereference-dos-via-malformed-http-request",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 600,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67185",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.773Z",
      "date_published": "2026-07-28T16:30:45.229Z",
      "date_updated": "2026-07-28T19:34:14.583Z",
      "publisher": "VulnCheck",
      "title": "TinyWeb 0.0.8 Path Traversal via URL Path Component",
      "affected": {
        "vendors": [
          "GeneralSandman"
        ],
        "products": [
          {
            "vendor": "GeneralSandman",
            "product": "TinyWeb"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00453,
        "percentile": 0.37112
      },
      "nvd": {
        "published": "2026-07-28T17:17:08.013",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67185",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "TinyWeb accepts an attacker-controlled path that can resolve outside the intended directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/theopaid/Unauthenticated-Path-Traversal-Allows-Arbitrary-File-Read-TinyWeb-",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/tinyweb-path-traversal-via-url-path-component",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 583,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67191",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.773Z",
      "date_published": "2026-07-29T15:50:53.320Z",
      "date_updated": "2026-07-29T16:32:49.768Z",
      "publisher": "VulnCheck",
      "title": "Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser",
      "affected": {
        "vendors": [
          "Xlight"
        ],
        "products": [
          {
            "vendor": "Xlight",
            "product": "Xlight FTP Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-122",
          "name": "Heap-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00579,
        "percentile": 0.44367
      },
      "nvd": {
        "published": "2026-07-29T16:17:57.540",
        "lastModified": "2026-07-30T20:04:51.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67191",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SSH identification receive loop uses an OR where termination requires AND, allowing an unauthenticated line to overrun a heap buffer.",
        "basis": [
          "CNA",
          "CWE-122"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.xlightftpd.com/whatsnew.htm",
          "host": "www.xlightftpd.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/xlight-ftp-server-pre-auth-heap-buffer-overflow-via-ssh-parser",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 438,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67192",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.773Z",
      "date_published": "2026-07-29T15:51:17.712Z",
      "date_updated": "2026-07-29T19:25:06.692Z",
      "publisher": "VulnCheck",
      "title": "Xlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher",
      "affected": {
        "vendors": [
          "Xlight"
        ],
        "products": [
          {
            "vendor": "Xlight",
            "product": "Xlight FTP Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00616,
        "percentile": 0.46107
      },
      "nvd": {
        "published": "2026-07-29T16:17:57.683",
        "lastModified": "2026-07-30T20:04:51.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67192",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Xlight passes an unvalidated SSH packet length to GCM decryption, allowing pre-authentication data to overwrite the stack buffer and return state.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.xlightftpd.com/whatsnew.htm",
          "host": "www.xlightftpd.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/xlight-ftp-server-pre-auth-stack-buffer-overflow-via-ssh-gcm-cipher",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 457,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67193",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.774Z",
      "date_published": "2026-07-29T15:51:42.675Z",
      "date_updated": "2026-07-29T17:53:59.797Z",
      "publisher": "VulnCheck",
      "title": "Xlight FTP Server < 3.9.5 Information Disclosure via USER Command",
      "affected": {
        "vendors": [
          "Xlight"
        ],
        "products": [
          {
            "vendor": "Xlight",
            "product": "Xlight FTP Server"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-203",
          "name": "Observable Discrepancy",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00264,
        "percentile": 0.18138
      },
      "nvd": {
        "published": "2026-07-29T16:17:57.833",
        "lastModified": "2026-07-30T20:04:51.110",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67193",
        "family": "EXPOSURE_OUTPUT",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Authentication or protocol handling produces an observable response difference that reveals otherwise protected state.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-203"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.xlightftpd.com/whatsnew.htm",
          "host": "www.xlightftpd.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/xlight-ftp-server-information-disclosure-via-user-command",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 448,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67194",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.774Z",
      "date_published": "2026-07-29T16:39:09.617Z",
      "date_updated": "2026-07-29T18:07:09.182Z",
      "publisher": "VulnCheck",
      "title": "Courier IMAP < 6.0.1 Mail Server < 2.0.2 Stack Overflow DoS via Nested SEARCH Queries",
      "affected": {
        "vendors": [
          "svarshavchik"
        ],
        "products": [
          {
            "vendor": "svarshavchik",
            "product": "Courier IMAP"
          },
          {
            "vendor": "svarshavchik",
            "product": "Courier Mail Server"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00305,
        "percentile": 0.22854
      },
      "nvd": {
        "published": "2026-07-29T17:16:54.017",
        "lastModified": "2026-07-30T20:11:09.180",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67194",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "alloc_search_key and its mutually recursive helpers parse nested SEARCH groups without a depth or command-length bound, exhausting the process stack.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/svarshavchik/courier/releases/tag/courier-imap%2F6.0.1%2F20260627214444",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/svarshavchik/courier/releases/tag/courier%2F2.0.2%2F20260627214309",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/svarshavchik/courier-libs/commit/b5b5581aabea3efadf5e2944947ff0214aa3533e",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://packages.debian.org/sid/courier-imap",
          "host": "packages.debian.org",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/courier-imap-mail-server-stack-overflow-dos-via-nested-search-queries",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 576,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67201",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.774Z",
      "date_published": "2026-07-29T18:12:34.162Z",
      "date_updated": "2026-07-29T18:58:43.767Z",
      "publisher": "VulnCheck",
      "title": "V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http",
      "affected": {
        "vendors": [
          "vlang"
        ],
        "products": [
          {
            "vendor": "vlang",
            "product": "v"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-436",
          "name": "Interpretation Conflict",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.00391,
        "percentile": 0.31848
      },
      "nvd": {
        "published": "2026-07-29T19:16:51.330",
        "lastModified": "2026-07-30T20:16:05.187",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67201",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The V allowlist parser treats a backslash-containing URL as having a trusted host while the HTTP client normalizes the same URL and connects to an internal host.",
        "basis": [
          "CNA",
          "CWE-436"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vlang/v/issues/27945",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/vlang/v/pull/27947",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/vlang/v/commit/85859f0f3498d4091b38009c45ed390a97eeedc2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/v-ssrf-bypass-via-parser-differential-in-net-urllib-and-net-http",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 557,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67206",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.775Z",
      "date_published": "2026-07-30T19:27:45.722Z",
      "date_updated": "2026-08-03T19:09:26.136Z",
      "publisher": "VulnCheck",
      "title": "Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload",
      "affected": {
        "vendors": [
          "wolfcms"
        ],
        "products": [
          {
            "vendor": "wolfcms",
            "product": "wolfcms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-434",
          "name": "Unrestricted Upload of File with Dangerous Type",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00437,
        "percentile": 0.35975
      },
      "nvd": {
        "published": "2026-07-30T20:18:14.030",
        "lastModified": "2026-07-31T16:17:11.450",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67206",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "FileManagerController accepts an arbitrary PHP extension and writes executable content into the web-accessible FILES_DIR.",
        "basis": [
          "CNA",
          "CWE-434"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Caycon/cve-advisories/blob/main/2026/WolfCms/CVE-2026-67206.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/wolf-cms-authenticated-rce-via-filemanagercontroller-file-upload",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 435,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67207",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.775Z",
      "date_published": "2026-07-30T19:30:45.125Z",
      "date_updated": "2026-08-03T19:09:39.604Z",
      "publisher": "VulnCheck",
      "title": "Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController",
      "affected": {
        "vendors": [
          "wolfcms"
        ],
        "products": [
          {
            "vendor": "wolfcms",
            "product": "wolfcms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-697",
          "name": "Incorrect Comparison",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.003,
        "percentile": 0.22242
      },
      "nvd": {
        "published": "2026-07-30T20:18:14.180",
        "lastModified": "2026-07-31T20:16:54.253",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67207",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The wolfcms operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-697"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Caycon/cve-advisories/blob/main/2026/WolfCms/CVE-2026-67207.md",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/wolf-cms-authorization-bypass-via-backuprestorecontroller",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 421,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67208",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T16:06:49.775Z",
      "date_published": "2026-07-30T19:17:42.126Z",
      "date_updated": "2026-07-31T11:54:07.540Z",
      "publisher": "VulnCheck",
      "title": "Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console",
      "affected": {
        "vendors": [
          "somta"
        ],
        "products": [
          {
            "vendor": "somta",
            "product": "Juggle"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-1188",
          "name": "Initialization of a Resource with an Insecure Default",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Primary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.01097,
        "percentile": 0.62388
      },
      "nvd": {
        "published": "2026-07-30T20:18:14.323",
        "lastModified": "2026-07-30T20:27:26.867",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67208",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Juggle exposes the H2 console with shipped default credentials, allowing its command-capable database features to be reached remotely.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-1188"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/somta/Juggle/issues/86",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/juggle-unauthenticated-rce-via-exposed-h2-console",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 496,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67213",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T18:13:39.684Z",
      "date_published": "2026-07-29T13:32:01.534Z",
      "date_updated": "2026-07-29T14:42:00.426Z",
      "publisher": "VulnCheck",
      "title": "nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customRandom",
      "affected": {
        "vendors": [
          "nanoid_project"
        ],
        "products": [
          {
            "vendor": "nanoid_project",
            "product": "nanoid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24321
      },
      "nvd": {
        "published": "2026-07-29T14:16:34.890",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67213",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Nano ID customAlphabet and customRandom never satisfy their generation-loop exit condition when size is zero, allowing an attacker-controlled zero to spin the calling thread indefinitely.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ai/nanoid/releases/tag/5.1.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/ai/nanoid/commit/cb3626d0f3342fdf179cd425fd9c4fbb92c7d0e7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-zero-size-in-customalphabet-and-customrandom",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 412,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67214",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T18:13:39.684Z",
      "date_published": "2026-07-29T13:32:02.265Z",
      "date_updated": "2026-07-29T14:37:19.382Z",
      "publisher": "VulnCheck",
      "title": "nanoid before 5.1.16 Infinite Loop via Negative Size in non-secure module",
      "affected": {
        "vendors": [
          "nanoid_project"
        ],
        "products": [
          {
            "vendor": "nanoid_project",
            "product": "nanoid"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24321
      },
      "nvd": {
        "published": "2026-07-29T14:16:35.043",
        "lastModified": "2026-07-30T19:07:59.843",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67214",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "nanoid decrements a negative size forever because the loop terminates only when its counter reaches zero.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ai/nanoid/releases/tag/5.1.16",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/ai/nanoid/commit/6ccc67bbaba71d3d77a21d9b636f4171a268ce49",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-negative-size-in-non-secure-module",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 487,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67215",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T19:20:19.157Z",
      "date_published": "2026-07-29T13:32:02.975Z",
      "date_updated": "2026-07-29T15:59:48.983Z",
      "publisher": "VulnCheck",
      "title": "cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion",
      "affected": {
        "vendors": [
          "DaveGamble"
        ],
        "products": [
          {
            "vendor": "DaveGamble",
            "product": "cJSON"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-674",
          "name": "Uncontrolled Recursion",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00346,
        "percentile": 0.27229
      },
      "nvd": {
        "published": "2026-07-29T14:16:35.187",
        "lastModified": "2026-08-04T15:09:26.327",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-67215",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "cJSON patch add and copy operations can amplify tree depth beyond parser limits before unbounded recursive duplication and deletion exhaust the thread stack.",
        "basis": [
          "CNA",
          "CWE-674"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://joshua.hu/cjson-json-parser-cve-vulnerabilities",
          "host": "joshua.hu",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Press/Media Coverage",
            "Third Party Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON.c#L253-L261",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON_Utils.c#L906-L940",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cjson-json-patch-copy-add-uncontrolled-recursion-stack-exhaustion",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 657,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67216",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T19:20:19.157Z",
      "date_published": "2026-07-29T13:32:03.696Z",
      "date_updated": "2026-07-30T15:19:59.613Z",
      "publisher": "VulnCheck",
      "title": "cJSON cJSON_Compare Exponential Complexity Denial of Service",
      "affected": {
        "vendors": [
          "DaveGamble"
        ],
        "products": [
          {
            "vendor": "DaveGamble",
            "product": "cJSON"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-407",
          "name": "Inefficient Algorithmic Complexity",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24322
      },
      "nvd": {
        "published": "2026-07-29T14:16:35.333",
        "lastModified": "2026-08-04T15:05:11.557",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-67216",
        "family": "RESOURCE_CONTROL",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "cJSON_Compare() recursively compares each shared object subtree in both directions with no depth guard, making equal nested objects require exponential CPU time.",
        "basis": [
          "CNA",
          "CWE-407"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://joshua.hu/cjson-json-parser-cve-vulnerabilities",
          "host": "joshua.hu",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Press/Media Coverage",
            "Third Party Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON.c#L3057-L3180",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cjson-cjson-compare-exponential-complexity-denial-of-service",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 621,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 5,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67217",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-28T19:20:19.157Z",
      "date_published": "2026-07-29T13:32:04.416Z",
      "date_updated": "2026-07-29T16:00:27.693Z",
      "publisher": "VulnCheck",
      "title": "cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation",
      "affected": {
        "vendors": [
          "DaveGamble"
        ],
        "products": [
          {
            "vendor": "DaveGamble",
            "product": "cJSON"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-696",
          "name": "Incorrect Behavior Order",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 1.6000000000000005,
      "epss": {
        "score": 0.00232,
        "percentile": 0.14194
      },
      "nvd": {
        "published": "2026-07-29T14:16:35.477",
        "lastModified": "2026-08-04T15:03:41.840",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-67217",
        "family": "STATE_SEQUENCE",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "cJSON Patch detaches and deletes the target before validating the replacement value or move destination, mutating the document even when the API returns failure.",
        "basis": [
          "CNA",
          "CWE-696"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://joshua.hu/cjson-json-parser-cve-vulnerabilities",
          "host": "joshua.hu",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "Exploit",
            "Press/Media Coverage",
            "Third Party Advisory",
            "exploit"
          ]
        },
        {
          "url": "https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON_Utils.c#L887-L948",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Patch",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cjson-json-patch-non-atomic-application-destroys-data-before-validation",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Third Party Advisory",
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 685,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67244",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T01:38:34.119Z",
      "date_published": "2026-07-30T03:04:16.812Z",
      "date_updated": "2026-08-04T07:30:04.580Z",
      "publisher": "ASUSTOR1",
      "title": "A format string vulnerability was found in the Notification OAuth settings of ADM",
      "affected": {
        "vendors": [
          "ASUSTOR Inc."
        ],
        "products": [
          {
            "vendor": "ASUSTOR Inc.",
            "product": "ADM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-134",
          "name": "Use of Externally-Controlled Format String",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@asustor.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 7.2,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 1.3999999999999995,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15418
      },
      "nvd": {
        "published": "2026-07-30T03:16:25.090",
        "lastModified": "2026-08-04T14:07:36.093",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-67244",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ADM processes administrator-controlled notification configuration as a format string rather than as literal data.",
        "basis": [
          "CNA",
          "CWE-134"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asustor.com/security/security_advisory_detail?id=67",
          "host": "www.asustor.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 491,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67245",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T01:38:34.119Z",
      "date_published": "2026-07-30T03:29:03.446Z",
      "date_updated": "2026-08-04T07:30:40.779Z",
      "publisher": "ASUSTOR1",
      "title": "A path traversal vulnerability was found in the VPN Clients on the ADM",
      "affected": {
        "vendors": [
          "ASUSTOR Inc."
        ],
        "products": [
          {
            "vendor": "ASUSTOR Inc.",
            "product": "ADM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@asustor.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.1,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00208,
        "percentile": 0.11077
      },
      "nvd": {
        "published": "2026-07-30T05:16:38.713",
        "lastModified": "2026-08-04T14:07:07.470",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-67245",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ADM uses a user-controlled certificate name in the upload destination without canonicalizing and constraining the resulting path.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asustor.com/security/security_advisory_detail?id=68",
          "host": "www.asustor.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 554,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67246",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T01:38:34.119Z",
      "date_published": "2026-07-30T03:33:52.065Z",
      "date_updated": "2026-08-04T07:31:23.486Z",
      "publisher": "ASUSTOR1",
      "title": "A path traversal vulnerability was found in the Wallpaper component of ADM",
      "affected": {
        "vendors": [
          "ASUSTOR Inc."
        ],
        "products": [
          {
            "vendor": "ASUSTOR Inc.",
            "product": "ADM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@asustor.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.00314,
        "percentile": 0.2376
      },
      "nvd": {
        "published": "2026-07-30T05:16:38.877",
        "lastModified": "2026-08-04T14:06:43.520",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-67246",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ADM uses a caller-controlled wallpaper path for file access without confining it to the wallpaper directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asustor.com/security/security_advisory_detail?id=68",
          "host": "www.asustor.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 516,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67247",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T01:38:34.119Z",
      "date_published": "2026-07-30T03:42:58.354Z",
      "date_updated": "2026-08-04T07:32:11.961Z",
      "publisher": "ASUSTOR1",
      "title": "A path traversal vulnerability was found in the IHM Log handling of ADM",
      "affected": {
        "vendors": [
          "ASUSTOR Inc."
        ],
        "products": [
          {
            "vendor": "ASUSTOR Inc.",
            "product": "ADM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@asustor.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.1,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.1,
      "cvss_source_score_spread": 0.5999999999999996,
      "epss": {
        "score": 0.00292,
        "percentile": 0.21442
      },
      "nvd": {
        "published": "2026-07-30T05:16:39.017",
        "lastModified": "2026-08-04T14:06:15.050",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-67247",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ADM uses a user-controlled disk serial to construct an IHM log database path without containing the result to the intended log directory.",
        "basis": [
          "CNA",
          "CWE-22"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asustor.com/security/security_advisory_detail?id=68",
          "host": "www.asustor.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 509,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67248",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T01:38:34.119Z",
      "date_published": "2026-07-30T03:48:04.856Z",
      "date_updated": "2026-08-04T07:32:46.227Z",
      "publisher": "ASUSTOR1",
      "title": "A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM",
      "affected": {
        "vendors": [
          "ASUSTOR Inc."
        ],
        "products": [
          {
            "vendor": "ASUSTOR Inc.",
            "product": "ADM"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 2,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security@asustor.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:nvd@nist.gov",
          "type": "Primary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.00229,
        "percentile": 0.13816
      },
      "nvd": {
        "published": "2026-07-30T05:16:39.157",
        "lastModified": "2026-08-04T14:05:45.857",
        "vulnStatus": "Analyzed",
        "hasConfigurations": true
      },
      "cause_review": {
        "cveId": "CVE-2026-67248",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The ADM path copies attacker-influenced data beyond a fixed-size stack buffer.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.asustor.com/security/security_advisory_detail?id=69",
          "host": "www.asustor.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "Vendor Advisory",
            "vendor-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 548,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 3,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67345",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T13:09:45.993Z",
      "date_published": "2026-07-30T14:39:13.577Z",
      "date_updated": "2026-07-31T11:54:08.230Z",
      "publisher": "VulnCheck",
      "title": "MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft",
      "affected": {
        "vendors": [
          "dromara"
        ],
        "products": [
          {
            "vendor": "dromara",
            "product": "MaxKey"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-183",
          "name": "Permissive List of Allowed Inputs",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0.40000000000000036,
      "epss": {
        "score": 0.0031,
        "percentile": 0.23415
      },
      "nvd": {
        "published": "2026-07-30T15:16:35.583",
        "lastModified": "2026-07-30T19:18:36.823",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67345",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "hostMatches accepts any hostname suffix match without a dot boundary and redirects OAuth codes to an attacker domain.",
        "basis": [
          "CNA",
          "CWE-183"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/dromara/MaxKey/issues/269",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/dromara/MaxKey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/maxkey-defaultredirectresolver-oauth-authorization-code-theft",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 644,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67346",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T13:09:45.993Z",
      "date_published": "2026-07-30T14:39:43.337Z",
      "date_updated": "2026-07-31T11:54:08.905Z",
      "publisher": "VulnCheck",
      "title": "Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass",
      "affected": {
        "vendors": [
          "kyegomez"
        ],
        "products": [
          {
            "vendor": "kyegomez",
            "product": "swarms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 7.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.8999999999999995,
      "epss": {
        "score": 0.0029,
        "percentile": 0.21278
      },
      "nvd": {
        "published": "2026-07-30T15:16:35.953",
        "lastModified": "2026-07-30T19:18:36.957",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67346",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The SSRF safety check does not resolve and validate the hostname before the client can connect to a private or metadata address.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/kyegomez/swarms/issues/1714",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/kyegomez/swarms/pull/1734",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/kyegomez/swarms/commit/8b0fc9e4645603ad94d5fcf4da86e3b9c71f4743",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/swarms-server-side-request-forgery-via-dns-rebinding-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 398,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67347",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T13:09:45.993Z",
      "date_published": "2026-07-30T14:40:02.800Z",
      "date_updated": "2026-07-31T11:54:09.576Z",
      "publisher": "VulnCheck",
      "title": "Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset Update",
      "affected": {
        "vendors": [
          "vendurehq"
        ],
        "products": [
          {
            "vendor": "vendurehq",
            "product": "vendure"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.1,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.8,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.8,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00277,
        "percentile": 0.19907
      },
      "nvd": {
        "published": "2026-07-30T15:16:36.373",
        "lastModified": "2026-07-30T17:16:34.350",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67347",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "vendure fails to enforce the required capability, object ownership, tenant, role, or scope check at the affected operation, allowing a caller outside that authority boundary to invoke it.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/vendurehq/vendure/issues/5003",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/vendurehq/vendure/pull/5017",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/vendurehq/vendure/commit/f67ef5f621282b785a2708df468bc6d2b8d8115b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/vendure-cross-channel-authorization-bypass-via-stocklocation-and-asset-update",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 459,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67348",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T13:36:36.277Z",
      "date_published": "2026-07-30T14:40:27.338Z",
      "date_updated": "2026-07-31T11:54:10.241Z",
      "publisher": "VulnCheck",
      "title": "Julep Insecure Direct Object Reference via GET /executions/{execution_id}",
      "affected": {
        "vendors": [
          "julep-ai"
        ],
        "products": [
          {
            "vendor": "julep-ai",
            "product": "julep"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00253,
        "percentile": 0.16768
      },
      "nvd": {
        "published": "2026-07-30T15:16:36.657",
        "lastModified": "2026-07-30T18:18:25.723",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67348",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "get_execution_details accepts an execution_id without verifying that the execution belongs to the authenticated tenant.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/julep-ai/julep/issues/1615",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/julep-insecure-direct-object-reference-via-get-executions-execution-id",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 355,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67349",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T13:36:36.277Z",
      "date_published": "2026-07-30T14:40:47.996Z",
      "date_updated": "2026-07-31T22:56:13.763Z",
      "publisher": "VulnCheck",
      "title": "OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass",
      "affected": {
        "vendors": [
          "opencost"
        ],
        "products": [
          {
            "vendor": "opencost",
            "product": "opencost"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.7,
      "cvss_source_score_spread": 1.1999999999999993,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20801
      },
      "nvd": {
        "published": "2026-07-30T15:16:36.900",
        "lastModified": "2026-07-31T23:17:26.310",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67349",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "OpenCost exposes Helm values without authentication and treats an unset ADMIN_TOKEN as authorization for service-key changes.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/opencost/opencost/issues/3893",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://github.com/opencost/opencost/releases/tag/core/v1.121.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/opencost/opencost/pull/3910",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "patch"
          ]
        },
        {
          "url": "https://github.com/opencost/opencost/commit/a49a25bc2e0d6e220a131a4dc58f38ebe6ae851b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/opencost-unauthenticated-helm-values-exposure-and-admin-bypass",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 361,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67350",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T13:36:36.277Z",
      "date_published": "2026-07-31T14:19:01.218Z",
      "date_updated": "2026-07-31T23:26:27.996Z",
      "publisher": "VulnCheck",
      "title": "Serendipity < 2.6.1 Open Redirect via exit.php",
      "affected": {
        "vendors": [
          "s9y"
        ],
        "products": [
          {
            "vendor": "s9y",
            "product": "Serendipity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-601",
          "name": "URL Redirection to Untrusted Site ('Open Redirect')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 2.1,
          "severity": "LOW",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 2.1999999999999997,
      "epss": {
        "score": 0.00205,
        "percentile": 0.10632
      },
      "nvd": {
        "published": "2026-07-31T15:18:01.103",
        "lastModified": "2026-08-01T00:17:17.877",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67350",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A Base64-encoded URL parameter is decoded and used as an external redirect destination without an allowlist check.",
        "basis": [
          "CNA",
          "CWE-601"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/s9y/Serendipity/security/advisories/GHSA-77rw-27c5-4hxm",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/serendipity-open-redirect-via-exit-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 443,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67351",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T13:36:36.277Z",
      "date_published": "2026-07-30T13:57:51.756Z",
      "date_updated": "2026-07-31T22:52:50.209Z",
      "publisher": "VulnCheck",
      "title": "Serendipity < 2.6.1 Authentication Bypass via Username Collision",
      "affected": {
        "vendors": [
          "s9y"
        ],
        "products": [
          {
            "vendor": "s9y",
            "product": "Serendipity"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "unaffected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-304",
          "name": "Missing Critical Step in Authentication",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.7,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.8,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.8,
      "cvss_source_score_spread": 0.10000000000000142,
      "epss": {
        "score": 0.0037,
        "percentile": 0.29729
      },
      "nvd": {
        "published": "2026-07-30T14:17:04.503",
        "lastModified": "2026-07-31T23:17:26.430",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67351",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Serendipity validates a password against one colliding username record and loads the session identity from another record.",
        "basis": [
          "CNA",
          "CWE-304"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/s9y/Serendipity/security/advisories/GHSA-v645-243f-jwgh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/serendipity-authentication-bypass-via-username-collision",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 418,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67424",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:02:20.413Z",
      "date_published": "2026-07-29T18:32:00.887Z",
      "date_updated": "2026-07-29T19:09:10.222Z",
      "publisher": "GitHub_M",
      "title": "Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation",
      "affected": {
        "vendors": [
          "flytohub"
        ],
        "products": [
          {
            "vendor": "flytohub",
            "product": "flyto-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00236,
        "percentile": 0.14733
      },
      "nvd": {
        "published": "2026-07-29T19:16:51.480",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67424",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in src/core/modules/atomic/http/get.py, src/core/modules/atomic/http/request.py, and src/core/modules/atomic/http/batch.py validate only the initial URL, then follow redirects with allow_redirects=True and without per-hop Location revalidation, allowing a public URL to redirect into internal address space and return the internal response body.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/flytohub/flyto-core/security/advisories/GHSA-c9hr-64h3-gxpc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/flytohub/flyto-core/releases/tag/v2.26.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 531,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67425",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:02:20.413Z",
      "date_published": "2026-07-29T18:35:01.573Z",
      "date_updated": "2026-07-29T19:12:11.961Z",
      "publisher": "GitHub_M",
      "title": "Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url",
      "affected": {
        "vendors": [
          "flytohub"
        ],
        "products": [
          {
            "vendor": "flytohub",
            "product": "flyto-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-201",
          "name": "Insertion of Sensitive Information Into Sent Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00319,
        "percentile": 0.24366
      },
      "nvd": {
        "published": "2026-07-29T19:16:51.630",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67425",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "llm.chat attaches environment-held provider keys to a caller-controlled base_url that passes only the existing SSRF guard.",
        "basis": [
          "CNA",
          "CWE-201",
          "CWE-522"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/flytohub/flyto-core/security/advisories/GHSA-qq9q-xgm3-xv9g",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/flytohub/flyto-core/releases/tag/v2.26.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 402,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67426",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:02:20.413Z",
      "date_published": "2026-07-29T18:43:26.247Z",
      "date_updated": "2026-07-29T19:05:05.601Z",
      "publisher": "GitHub_M",
      "title": "Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration",
      "affected": {
        "vendors": [
          "flytohub"
        ],
        "products": [
          {
            "vendor": "flytohub",
            "product": "flyto-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 9.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21362
      },
      "nvd": {
        "published": "2026-07-29T19:16:51.770",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67426",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unauthenticated /run endpoint posts to a caller-supplied callback URL and includes the internal runner secret in that outbound request.",
        "basis": [
          "CNA",
          "CWE-306",
          "CWE-522",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/flytohub/flyto-core/security/advisories/GHSA-jx74-cqjv-2c67",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/flytohub/flyto-core/releases/tag/v2.26.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67427",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:02:20.413Z",
      "date_published": "2026-07-29T18:45:47.908Z",
      "date_updated": "2026-07-30T15:19:17.888Z",
      "publisher": "GitHub_M",
      "title": "Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted",
      "affected": {
        "vendors": [
          "flytohub"
        ],
        "products": [
          {
            "vendor": "flytohub",
            "product": "flyto-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-522",
          "name": "Insufficiently Protected Credentials",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-668",
          "name": "Exposure of Resource to Wrong Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-693",
          "name": "Protection Mechanism Failure",
          "abstraction": "Pillar",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00339,
        "percentile": 0.26507
      },
      "nvd": {
        "published": "2026-07-29T19:16:51.913",
        "lastModified": "2026-07-30T19:27:35.030",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67427",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The variable resolver expands arbitrary host environment variables without applying the capability policy that blocks the explicit environment-access APIs.",
        "basis": [
          "CNA",
          "CWE-522",
          "CWE-668",
          "CWE-693"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/flytohub/flyto-core/security/advisories/GHSA-hr7p-wg7r-hg9m",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/flytohub/flyto-core/releases/tag/v2.26.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 428,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67428",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:02:20.413Z",
      "date_published": "2026-07-29T18:48:42.087Z",
      "date_updated": "2026-07-30T14:33:40.622Z",
      "publisher": "GitHub_M",
      "title": "Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)",
      "affected": {
        "vendors": [
          "flytohub"
        ],
        "products": [
          {
            "vendor": "flytohub",
            "product": "flyto-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 8.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00337,
        "percentile": 0.26246
      },
      "nvd": {
        "published": "2026-07-29T19:16:52.087",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67428",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "flyto-core follows a caller-controlled server-side URL without restricting the resolved destination to an allowed network scope.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/flytohub/flyto-core/security/advisories/GHSA-pgwh-4jj4-qm8v",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/flytohub/flyto-core/releases/tag/v2.26.7",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 659,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67429",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:07:24.991Z",
      "date_published": "2026-07-29T18:50:43.378Z",
      "date_updated": "2026-07-29T19:04:19.327Z",
      "publisher": "GitHub_M",
      "title": "Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)",
      "affected": {
        "vendors": [
          "flytohub"
        ],
        "products": [
          {
            "vendor": "flytohub",
            "product": "flyto-core"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-22",
          "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-73",
          "name": "External Control of File Name or Path",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 10,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 10,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00494,
        "percentile": 0.39737
      },
      "nvd": {
        "published": "2026-07-29T19:16:52.240",
        "lastModified": "2026-07-30T16:41:25.650",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67429",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "File-writing modules use a caller-controlled output_dir without enforcing FLYTO_SANDBOX_DIR confinement.",
        "basis": [
          "CNA",
          "CWE-22",
          "CWE-73"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/flytohub/flyto-core/security/advisories/GHSA-2956-977x-2w3r",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/flytohub/flyto-core/releases/tag/v2.26.6",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 402,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67430",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:07:24.991Z",
      "date_published": "2026-07-29T19:10:39.552Z",
      "date_updated": "2026-07-30T15:19:09.224Z",
      "publisher": "GitHub_M",
      "title": "MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood",
      "affected": {
        "vendors": [
          "modelcontextprotocol"
        ],
        "products": [
          {
            "vendor": "modelcontextprotocol",
            "product": "ruby-sdk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 5.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00291,
        "percentile": 0.21382
      },
      "nvd": {
        "published": "2026-07-29T20:17:11.960",
        "lastModified": "2026-07-30T19:30:33.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67430",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Sessions have no expiry condition and accumulate indefinitely.",
        "basis": [
          "CNA",
          "CWE-401",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-52jp-gj8w-j6xh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/commit/afb968c468c178c4d3294b423fcce250621692f4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 345,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67431",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:07:24.991Z",
      "date_published": "2026-07-29T19:15:32.340Z",
      "date_updated": "2026-07-30T14:35:45.395Z",
      "publisher": "GitHub_M",
      "title": "MCP Ruby SDK: Ruby SSE Session Poisoning",
      "affected": {
        "vendors": [
          "modelcontextprotocol"
        ],
        "products": [
          {
            "vendor": "modelcontextprotocol",
            "product": "ruby-sdk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-284",
          "name": "Improper Access Control",
          "abstraction": "Pillar",
          "status": "Incomplete",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00276,
        "percentile": 0.19836
      },
      "nvd": {
        "published": "2026-07-29T20:17:12.120",
        "lastModified": "2026-07-30T19:30:33.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67431",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "StreamableHTTPTransport accepts a session identifier without binding that session to its owner, so a holder can invoke tools in another user's session.",
        "basis": [
          "CNA record",
          "CWE-284"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-5p9g-j988-pcwv",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/commit/35466605319a34e4c7808712ae9bb1ca1afb2356",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 364,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67432",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:07:24.991Z",
      "date_published": "2026-07-29T19:17:46.518Z",
      "date_updated": "2026-07-29T19:34:24.640Z",
      "publisher": "GitHub_M",
      "title": "MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport",
      "affected": {
        "vendors": [
          "modelcontextprotocol"
        ],
        "products": [
          {
            "vendor": "modelcontextprotocol",
            "product": "ruby-sdk"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00436,
        "percentile": 0.35893
      },
      "nvd": {
        "published": "2026-07-29T20:17:12.277",
        "lastModified": "2026-07-30T19:30:33.710",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67432",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "ruby-sdk allocates or queues attacker-driven work without a per-request or per-connection limit.",
        "basis": [
          "CNA",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-h669-8m4g-r2hc",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/commit/772e0cb1f9db69312006926eee59a7287ad50166",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 344,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67433",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:07:24.991Z",
      "date_published": "2026-07-29T19:27:41.844Z",
      "date_updated": "2026-07-30T13:07:26.335Z",
      "publisher": "GitHub_M",
      "title": "Linuxfabrik monitoring-plugins: Symlink following in logfile legacy database migration",
      "affected": {
        "vendors": [
          "Linuxfabrik"
        ],
        "products": [
          {
            "vendor": "Linuxfabrik",
            "product": "monitoring-plugins"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-59",
          "name": "Improper Link Resolution Before File Access ('Link Following')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 5.8,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 5.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0008,
        "percentile": 0.00211
      },
      "nvd": {
        "published": "2026-07-29T20:17:12.457",
        "lastModified": "2026-07-30T19:27:23.630",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67433",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "A root-run migration opens a predictable temporary database path after a local user can replace it with a symlink.",
        "basis": [
          "CNA",
          "CWE-59",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-w2gg-hx6w-24w3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Linuxfabrik/monitoring-plugins/commit/6df1f574aa9dc6541e092f1ce482ecc1315cded0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 375,
        "referenceCount": 2,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67435",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:07:24.991Z",
      "date_published": "2026-07-29T19:39:19.088Z",
      "date_updated": "2026-07-29T19:55:54.318Z",
      "publisher": "GitHub_M",
      "title": "linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect",
      "affected": {
        "vendors": [
          "Linuxfabrik"
        ],
        "products": [
          {
            "vendor": "Linuxfabrik",
            "product": "monitoring-plugins"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00286,
        "percentile": 0.20845
      },
      "nvd": {
        "published": "2026-07-29T20:17:12.647",
        "lastModified": "2026-07-30T19:27:23.630",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67435",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "linuxfabrik-lib follows a cross-origin redirect while retaining caller-supplied credential headers such as X-Auth-Token.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-4jc5-g844-4x33",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Linuxfabrik/lib/commit/6573ff9347e541200305d278d2663d2e54e052ff",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Linuxfabrik/lib/releases/tag/v6.0.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 432,
        "referenceCount": 3,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67436",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:07:24.991Z",
      "date_published": "2026-07-29T19:43:35.819Z",
      "date_updated": "2026-07-30T15:19:02.700Z",
      "publisher": "GitHub_M",
      "title": "Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidated @odata.id link in redfish-* plugins",
      "affected": {
        "vendors": [
          "Linuxfabrik"
        ],
        "products": [
          {
            "vendor": "Linuxfabrik",
            "product": "monitoring-plugins"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-20",
          "name": "Improper Input Validation",
          "abstraction": "Class",
          "status": "Stable",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.3,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        }
      ],
      "max_cvss_observed_across_sources": 8.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00249,
        "percentile": 0.1628
      },
      "nvd": {
        "published": "2026-07-29T20:17:12.827",
        "lastModified": "2026-07-30T19:27:23.630",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67436",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The server follows an attacker-controlled outbound URL without constraining its destination to the intended remote service.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-96fx-pqc3-28xv",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Linuxfabrik/monitoring-plugins/commit/ffb0a81308cbfc018da857a89e0d07a67bf89fc3",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 403,
        "referenceCount": 2,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67437",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:07:24.991Z",
      "date_published": "2026-07-29T20:43:05.167Z",
      "date_updated": "2026-07-30T14:15:32.590Z",
      "publisher": "GitHub_M",
      "title": "OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)",
      "affected": {
        "vendors": [
          "OliveTin"
        ],
        "products": [
          {
            "vendor": "OliveTin",
            "product": "OliveTin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-400",
          "name": "Uncontrolled Resource Consumption",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-401",
          "name": "Missing Release of Memory after Effective Lifetime",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-770",
          "name": "Allocation of Resources Without Limits or Throttling",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00354,
        "percentile": 0.28132
      },
      "nvd": {
        "published": "2026-07-29T21:17:47.977",
        "lastModified": "2026-07-30T19:21:23.297",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67437",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Each unauthenticated OAuth login stores a new state in registeredStates without expiration, deletion, or a size bound.",
        "basis": [
          "CNA",
          "NVD",
          "CWE-400",
          "CWE-401",
          "CWE-770"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xpxj-f2fm-rqch",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/OliveTin/OliveTin/commit/ec114e95d297b806c3ca0c37bc139b3c9c517b3f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 440,
        "referenceCount": 3,
        "cweCount": 3,
        "cnaCweCount": 3,
        "adpCweCount": 0,
        "nvdCweCount": 3,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67438",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:07:24.992Z",
      "date_published": "2026-07-29T20:53:09.524Z",
      "date_updated": "2026-07-30T15:18:25.719Z",
      "publisher": "GitHub_M",
      "title": "OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check",
      "affected": {
        "vendors": [
          "OliveTin"
        ],
        "products": [
          {
            "vendor": "OliveTin",
            "product": "OliveTin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-78",
          "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
          "abstraction": "Base",
          "status": "Stable",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.6,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00995,
        "percentile": 0.59268
      },
      "nvd": {
        "published": "2026-07-29T21:17:48.120",
        "lastModified": "2026-07-30T19:21:23.297",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67438",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The OliveTin path inserts attacker-controlled text into an operating-system command without preserving the command grammar.",
        "basis": [
          "CNA",
          "CWE-78"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xc5w-4v5w-7x65",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/OliveTin/OliveTin/commit/995ff79736f2bccc364448a3ece84087b550b232",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 452,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67439",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T15:07:24.992Z",
      "date_published": "2026-07-29T20:58:24.371Z",
      "date_updated": "2026-07-30T14:40:26.652Z",
      "publisher": "GitHub_M",
      "title": "OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output",
      "affected": {
        "vendors": [
          "OliveTin"
        ],
        "products": [
          {
            "vendor": "OliveTin",
            "product": "OliveTin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00252,
        "percentile": 0.16688
      },
      "nvd": {
        "published": "2026-07-29T21:17:48.253",
        "lastModified": "2026-07-30T19:21:23.297",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67439",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "StartActionAndWait returns full LogEntry output without enforcing the caller's logs permission.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/OliveTin/OliveTin/security/advisories/GHSA-jm28-2wcr-qf3h",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/OliveTin/OliveTin/commit/e421780c9885aa5024d2f47b4ed4898f2f18eb90",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 397,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67527",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T18:47:17.073Z",
      "date_published": "2026-07-30T19:19:25.028Z",
      "date_updated": "2026-07-31T15:59:12.286Z",
      "publisher": "GitHub_M",
      "title": "OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parameter \"fileLinks\"",
      "affected": {
        "vendors": [
          "opf"
        ],
        "products": [
          {
            "vendor": "opf",
            "product": "openproject"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.6,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 7.6,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00242,
        "percentile": 0.15439
      },
      "nvd": {
        "published": "2026-07-30T20:18:14.473",
        "lastModified": "2026-07-31T16:17:11.583",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67527",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "The openproject operation does not enforce the caller's role or permission against the requested object and action.",
        "basis": [
          "CNA",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/opf/openproject/security/advisories/GHSA-c6rc-4288-8p4f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/opf/openproject/pull/23815",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/opf/openproject/commit/db480bdeb8802e3d33e4448bb4e4b56a01de2e1f",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/opf/openproject/releases/tag/v17.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 495,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67528",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T18:47:17.073Z",
      "date_published": "2026-07-30T19:24:09.494Z",
      "date_updated": "2026-07-31T23:06:18.155Z",
      "publisher": "GitHub_M",
      "title": "OpenProject: Improper Access Control through /api/v3/custom_options/:id via Path \"id\" leads to Sensitive Data Exposure",
      "affected": {
        "vendors": [
          "opf"
        ],
        "products": [
          {
            "vendor": "opf",
            "product": "openproject"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-863",
          "name": "Incorrect Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.0021,
        "percentile": 0.11296
      },
      "nvd": {
        "published": "2026-07-30T20:18:14.613",
        "lastModified": "2026-07-31T23:17:26.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67528",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "OpenProject resolves a custom option by global numeric identifier without applying visible(current_user) to user and group custom fields.",
        "basis": [
          "CNA",
          "CWE-863"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/opf/openproject/security/advisories/GHSA-wr3w-qchj-p4cm",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/opf/openproject/commit/a13fa079bc8040449570384c19f2d98f637179f1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/opf/openproject/releases/tag/v17.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 440,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67529",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T18:47:17.073Z",
      "date_published": "2026-07-30T19:29:24.594Z",
      "date_updated": "2026-07-31T14:37:53.333Z",
      "publisher": "GitHub_M",
      "title": "OpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)",
      "affected": {
        "vendors": [
          "opf"
        ],
        "products": [
          {
            "vendor": "opf",
            "product": "openproject"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-200",
          "name": "Exposure of Sensitive Information to an Unauthorized Actor",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        },
        {
          "id": "CWE-862",
          "name": "Missing Authorization",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 4.3,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 4.3,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00237,
        "percentile": 0.14791
      },
      "nvd": {
        "published": "2026-07-30T20:18:14.750",
        "lastModified": "2026-07-31T15:18:01.293",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67529",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "medium",
        "mechanism": "OpenProject renders a private work package title in entry data without applying the visibility check used for the underlying work package.",
        "basis": [
          "CNA",
          "CWE-200",
          "CWE-862"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/opf/openproject/security/advisories/GHSA-v3j7-vqwv-5w5q",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/opf/openproject/pull/23888",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/opf/openproject/pull/23936",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/opf/openproject/commit/9e9e562e516a647f35267df715d875f58b267c18",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/opf/openproject/commit/c31c2f958c8e72a0d0d748d728221d57f3ef9001",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/opf/openproject/releases/tag/v17.6.0",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 559,
        "referenceCount": 6,
        "cweCount": 2,
        "cnaCweCount": 2,
        "adpCweCount": 0,
        "nvdCweCount": 2,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67530",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T18:47:17.073Z",
      "date_published": "2026-07-30T19:38:34.130Z",
      "date_updated": "2026-07-31T15:59:08.270Z",
      "publisher": "GitHub_M",
      "title": "WACRM: SSRF via the automation `send_webhook` action",
      "affected": {
        "vendors": [
          "ArnasDon"
        ],
        "products": [
          {
            "vendor": "ArnasDon",
            "product": "wacrm"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-918",
          "name": "Server-Side Request Forgery (SSRF)",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.4,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.4,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00156,
        "percentile": 0.05221
      },
      "nvd": {
        "published": "2026-07-30T20:18:14.887",
        "lastModified": "2026-07-31T16:17:11.690",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67530",
        "family": "REQUEST_CHANNEL_TRUST",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "WACRM send_webhook fetches an automation URL without applying the existing isDeliverableUrl guard for private and reserved destinations.",
        "basis": [
          "CNA",
          "CWE-918"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/ArnasDon/wacrm/security/advisories/GHSA-8jqh-598v-rfxc",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/ArnasDon/wacrm/commit/23838a9959550e975d732ae08a44a3a2f0cc084b",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 607,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67550",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T18:47:17.075Z",
      "date_published": "2026-07-30T19:59:55.916Z",
      "date_updated": "2026-07-31T23:07:18.352Z",
      "publisher": "GitHub_M",
      "title": "re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)",
      "affected": {
        "vendors": [
          "uhop"
        ],
        "products": [
          {
            "vendor": "uhop",
            "product": "node-re2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-125",
          "name": "Out-of-bounds Read",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.7,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 5.7,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00121,
        "percentile": 0.02205
      },
      "nvd": {
        "published": "2026-07-30T20:18:15.030",
        "lastModified": "2026-07-31T23:17:26.660",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67550",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "re2 validates lastIndex as a UTF-8 byte offset but later consumes it as a UTF-16 code-unit offset, permitting a heap read past non-ASCII subjects.",
        "basis": [
          "CNA",
          "CWE-125"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/uhop/node-re2/security/advisories/GHSA-ff84-5f28-78qj",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/uhop/node-re2/commit/56293de4fc0914d7bc35f92e98de25b0d9bb417d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/uhop/node-re2/releases/tag/1.25.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 464,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67594",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T21:07:39.201Z",
      "date_published": "2026-07-30T19:14:27.970Z",
      "date_updated": "2026-07-31T15:59:16.523Z",
      "publisher": "VulnCheck",
      "title": "Spikster Missing Authentication via API Route Group",
      "affected": {
        "vendors": [
          "yolanmees"
        ],
        "products": [
          {
            "vendor": "yolanmees",
            "product": "Spikster"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00455,
        "percentile": 0.37286
      },
      "nvd": {
        "published": "2026-07-30T20:18:15.173",
        "lastModified": "2026-07-31T16:17:11.793",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67594",
        "family": "AUTHORITY_BINDING",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Spikster registers authentication middleware but does not attach it to roughly fifty sensitive API routes, leaving those operations unauthenticated.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/yolanmees/Spikster/issues/24",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/spikster-missing-authentication-via-api-route-group",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 477,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67595",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T21:07:39.201Z",
      "date_published": "2026-07-29T21:33:25.952Z",
      "date_updated": "2026-07-30T15:17:56.308Z",
      "publisher": "VulnCheck",
      "title": "VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php",
      "affected": {
        "vendors": [
          "webreinvent"
        ],
        "products": [
          {
            "vendor": "webreinvent",
            "product": "vaahcms"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 2,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-506",
          "name": "Embedded Malicious Code",
          "abstraction": "Class",
          "status": "Incomplete",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.2,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 8.1,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.2,
      "cvss_source_score_spread": 1.0999999999999996,
      "epss": {
        "score": 0.00422,
        "percentile": 0.34762
      },
      "nvd": {
        "published": "2026-07-29T22:16:52.667",
        "lastModified": "2026-07-30T16:45:00.353",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67595",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "Released VaahCMS packages contain an obfuscated command-and-control script in the OTP email template, showing that malicious executable content crossed the build or release provenance boundary.",
        "basis": [
          "CNA",
          "CWE-506"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/webreinvent/vaahcms/pull/317",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/webreinvent/vaahcms/commit/8d7898f7a385a5fade1180a9b664ff158d873129",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/vaahcms-malicious-javascript-supply-chain-via-security-otp-blade-php",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 594,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 2
      }
    },
    {
      "cve_id": "CVE-2026-67596",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T21:07:39.201Z",
      "date_published": "2026-07-30T14:59:37.474Z",
      "date_updated": "2026-07-31T11:54:12.311Z",
      "publisher": "VulnCheck",
      "title": "CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg",
      "affected": {
        "vendors": [
          "CSL Mobile Limited"
        ],
        "products": [
          {
            "vendor": "CSL Mobile Limited",
            "product": "CSL 1010 M2M 3G WiFi Module"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-261",
          "name": "Weak Encoding for Password",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 6.9,
          "severity": "MEDIUM",
          "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.9,
      "cvss_source_score_spread": 0.7000000000000002,
      "epss": {
        "score": 0.00108,
        "percentile": 0.01401
      },
      "nvd": {
        "published": "2026-07-30T16:17:16.497",
        "lastModified": "2026-07-31T12:16:56.553",
        "vulnStatus": "Deferred",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67596",
        "family": "CRYPTO_SECRET",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Router.cfg protects stored credentials with a static single-byte XOR key that any reader can reverse.",
        "basis": [
          "CNA",
          "CWE-261"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://www.zeroscience.mk/#/advisories/ZSL-2026-6000",
          "host": "www.zeroscience.mk",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": []
        },
        {
          "url": "https://1010.com.hk/",
          "host": "1010.com.hk",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/csl-1010-m2m-3g-wifi-module-weak-encryption-via-router-cfg",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 490,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67607",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-29T21:07:39.202Z",
      "date_published": "2026-07-31T15:59:10.564Z",
      "date_updated": "2026-08-03T19:59:39.243Z",
      "publisher": "VulnCheck",
      "title": "LightFTP 2.3.1 Race Condition DoS via worker_thread_cleanup",
      "affected": {
        "vendors": [
          "hfiref0x"
        ],
        "products": [
          {
            "vendor": "hfiref0x",
            "product": "LightFTP"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-367",
          "name": "Time-of-check Time-of-use (TOCTOU) Race Condition",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 8.2,
          "severity": "HIGH",
          "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.9,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 8.2,
      "cvss_source_score_spread": 2.299999999999999,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21755
      },
      "nvd": {
        "published": "2026-07-31T16:17:11.913",
        "lastModified": "2026-08-03T20:17:28.270",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67607",
        "family": "STATE_SEQUENCE",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "worker_thread_cleanup accesses shared connection state without the required mutex while LIST and ABOR can run in a conflicting order.",
        "basis": [
          "CNA",
          "CWE-367"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/zeroscience/tuktam#real-world-case-study-lightftp-cve-2024-11144",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "technical-description"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/lightftp-race-condition-dos-via-worker-thread-cleanup",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 755,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-67822",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T00:00:00.000Z",
      "date_published": "2026-07-31T00:00:00.000Z",
      "date_updated": "2026-07-31T18:18:21.471Z",
      "publisher": "mitre",
      "title": "Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer wi...",
      "affected": {
        "vendors": [
          "n/a"
        ],
        "products": [
          {
            "vendor": "n/a",
            "product": "n/a"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-121",
          "name": "Stack-based Buffer Overflow",
          "abstraction": "Variant",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "adp",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "adp:0",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00295,
        "percentile": 0.21723
      },
      "nvd": {
        "published": "2026-07-31T17:16:35.210",
        "lastModified": "2026-07-31T19:17:12.157",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-67822",
        "family": "MEMORY_LIFETIME",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The Tenda endpoint uses sprintf to copy the GO and index parameters into a 64-byte stack buffer without a length restriction.",
        "basis": [
          "CNA",
          "CWE-121"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Tristerjh/Tenda/blob/main/Tenda_W6-S_GO_overflow.md",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 289,
        "referenceCount": 1,
        "cweCount": 1,
        "cnaCweCount": 0,
        "adpCweCount": 1,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-68499",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T16:19:08.081Z",
      "date_published": "2026-07-30T20:07:01.147Z",
      "date_updated": "2026-07-31T19:19:08.646Z",
      "publisher": "GitHub_M",
      "title": "re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)",
      "affected": {
        "vendors": [
          "uhop"
        ],
        "products": [
          {
            "vendor": "uhop",
            "product": "node-re2"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-835",
          "name": "Loop with Unreachable Exit Condition ('Infinite Loop')",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00129,
        "percentile": 0.02945
      },
      "nvd": {
        "published": "2026-07-30T21:18:12.870",
        "lastModified": "2026-07-31T20:16:54.423",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-68499",
        "family": "RESOURCE_CONTROL",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that blocks the event loop and can exhaust host memory.",
        "basis": [
          "CNA",
          "CWE-835"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/uhop/node-re2/security/advisories/GHSA-6hxr-mr5r-9836",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/uhop/node-re2/commit/56293de4fc0914d7bc35f92e98de25b0d9bb417d",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/uhop/node-re2/releases/tag/1.25.2",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 400,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-68500",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T16:19:08.081Z",
      "date_published": "2026-07-30T20:15:11.785Z",
      "date_updated": "2026-07-31T14:36:51.614Z",
      "publisher": "GitHub_M",
      "title": "Sylius Mollie Plugin: Payment status forgery via the payment webhook",
      "affected": {
        "vendors": [
          "Sylius"
        ],
        "products": [
          {
            "vendor": "Sylius",
            "product": "MolliePlugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 7.5,
          "severity": "HIGH",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 7.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00382,
        "percentile": 0.30913
      },
      "nvd": {
        "published": "2026-07-30T21:18:13.007",
        "lastModified": "2026-07-31T15:18:01.430",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-68500",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "The payment webhook accepts independent payment and order identifiers without verifying that the paid Mollie object belongs to that Sylius order.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Sylius/MolliePlugin/security/advisories/GHSA-rc52-c4hv-w89p",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/pull/351",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/pull/352",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/pull/354",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/commit/01316b3ad3cf82e3c5ad160115d0a2cf89174e49",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/commit/153c754486b1bc597b67a90ac07ef71cd7958267",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/commit/d1f7753e92106e8bf3bedcfc61b02ea7b8e1c38a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/releases/tag/v2.2.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/releases/tag/v3.2.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/releases/tag/v3.3.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 520,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-68501",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T16:19:08.081Z",
      "date_published": "2026-07-30T20:27:34.465Z",
      "date_updated": "2026-07-31T15:59:04.182Z",
      "publisher": "GitHub_M",
      "title": "Sylius Mollie Plugin: Unauthenticated IDOR leaks order token and customer PII",
      "affected": {
        "vendors": [
          "Sylius"
        ],
        "products": [
          {
            "vendor": "Sylius",
            "product": "MolliePlugin"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 3,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-639",
          "name": "Authorization Bypass Through User-Controlled Key",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"
        }
      ],
      "max_cvss_observed_across_sources": 6.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00341,
        "percentile": 0.26708
      },
      "nvd": {
        "published": "2026-07-30T21:18:13.180",
        "lastModified": "2026-07-31T16:17:12.053",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-68501",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Thank-you and QR endpoints accept sequential order IDs without ownership or session binding, exposing the token used to retrieve customer identity data.",
        "basis": [
          "CNA",
          "CWE-639"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Sylius/MolliePlugin/security/advisories/GHSA-x83g-979r-f5fh",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/pull/351",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/pull/352",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/pull/354",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/commit/01316b3ad3cf82e3c5ad160115d0a2cf89174e49",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/commit/153c754486b1bc597b67a90ac07ef71cd7958267",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/commit/d1f7753e92106e8bf3bedcfc61b02ea7b8e1c38a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/releases/tag/v2.2.8",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/releases/tag/v3.2.4",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/Sylius/MolliePlugin/releases/tag/v3.3.1",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 552,
        "referenceCount": 10,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 3
      }
    },
    {
      "cve_id": "CVE-2026-68502",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T16:19:08.081Z",
      "date_published": "2026-07-30T20:38:05.485Z",
      "date_updated": "2026-07-31T14:07:30.409Z",
      "publisher": "GitHub_M",
      "title": "LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCE",
      "affected": {
        "vendors": [
          "grisuno"
        ],
        "products": [
          {
            "vendor": "grisuno",
            "product": "LazyOwn"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-306",
          "name": "Missing Authentication for Critical Function",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00527,
        "percentile": 0.41697
      },
      "nvd": {
        "published": "2026-07-30T21:18:13.317",
        "lastModified": "2026-07-31T15:18:01.563",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-68502",
        "family": "AUTHORITY_BINDING",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "An unauthenticated Socket.IO input handler forwards attacker data into the privileged shell command dispatcher.",
        "basis": [
          "CNA",
          "CWE-306"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grisuno/LazyOwn/security/advisories/GHSA-fr84-8cfg-59w4",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grisuno/LazyOwn/commit/2e1e3a7b5da8149ae28a970b5883aefa42921652",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grisuno/LazyOwn/releases/tag/release/0.2.154",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 409,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-68503",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T16:19:08.081Z",
      "date_published": "2026-07-30T20:39:34.763Z",
      "date_updated": "2026-07-31T15:59:00.803Z",
      "publisher": "GitHub_M",
      "title": "LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard",
      "affected": {
        "vendors": [
          "grisuno"
        ],
        "products": [
          {
            "vendor": "grisuno",
            "product": "LazyOwn"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 0,
        "defaultStatuses": []
      },
      "cwes": [
        {
          "id": "CWE-1392",
          "name": "Use of Default Credentials",
          "abstraction": "Base",
          "status": "Incomplete",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:security-advisories@github.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00395,
        "percentile": 0.32301
      },
      "nvd": {
        "published": "2026-07-30T21:18:13.460",
        "lastModified": "2026-07-31T16:17:12.183",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-68503",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "LazyOwn ships known default Basic Authentication credentials and leaves them active for the network-reachable C2 operator dashboard.",
        "basis": [
          "CNA",
          "CWE-1392"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/grisuno/LazyOwn/security/advisories/GHSA-38jf-j9x7-jf6f",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/grisuno/LazyOwn/commit/2e1e3a7b5da8149ae28a970b5883aefa42921652",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/grisuno/LazyOwn/releases/tag/release/0.2.154",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 427,
        "referenceCount": 3,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-68562",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T20:29:28.829Z",
      "date_published": "2026-07-30T21:13:08.111Z",
      "date_updated": "2026-07-31T11:14:02.896Z",
      "publisher": "redhat",
      "title": "Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-610",
          "name": "Externally Controlled Reference to a Resource in Another Sphere",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Discouraged",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 6.2,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 6.2,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00219,
        "percentile": 0.12524
      },
      "nvd": {
        "published": "2026-07-30T22:16:56.213",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-68562",
        "family": "FILE_OBJECT_SELECTION",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "A managed-node report controls a controller-side file reference that the remediation task reads and copies back to the node.",
        "basis": [
          "CNA record",
          "CWE-610"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-68562",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466035",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 465,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-68563",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-30T20:29:28.829Z",
      "date_published": "2026-07-30T21:13:08.546Z",
      "date_updated": "2026-07-31T19:21:38.256Z",
      "publisher": "redhat",
      "title": "Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure of postgresql data via insecure backup permissions",
      "affected": {
        "vendors": [
          "Red Hat"
        ],
        "products": [
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10"
          },
          {
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9"
          }
        ],
        "affectedBlockCount": 2,
        "versionEntryCount": 0,
        "versionRangeCount": 0,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-732",
          "name": "Incorrect Permission Assignment for Critical Resource",
          "abstraction": "Class",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
          "source": "NVD:secalert@redhat.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 5.5,
          "severity": "MEDIUM",
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "max_cvss_observed_across_sources": 5.5,
      "cvss_source_score_spread": 0,
      "epss": {
        "score": 0.00101,
        "percentile": 0.0104
      },
      "nvd": {
        "published": "2026-07-30T22:16:56.353",
        "lastModified": "2026-08-03T16:39:02.593",
        "vulnStatus": "Awaiting Analysis",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-68563",
        "family": "CONFIG_UPDATE_DEPENDENCY",
        "precision": "DESCRIPTION_SPECIFIC",
        "confidence": "high",
        "mechanism": "The privileged remediation task creates the PostgreSQL backup archive with permissions that permit local non-root users to read it.",
        "basis": [
          "CNA",
          "CWE-732"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-68563",
          "host": "access.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ]
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2465419",
          "host": "bugzilla.redhat.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 373,
        "referenceCount": 2,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 2,
        "affectedProductCount": 2,
        "affectedVersionEntryCount": 0
      }
    },
    {
      "cve_id": "CVE-2026-68770",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-31T16:10:55.448Z",
      "date_published": "2026-07-31T20:56:06.867Z",
      "date_updated": "2026-08-03T18:16:01.639Z",
      "publisher": "VulnCheck",
      "title": "sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_code=False",
      "affected": {
        "vendors": [
          "Hugging Face"
        ],
        "products": [
          {
            "vendor": "Hugging Face",
            "product": "sentence-transformers"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-94",
          "name": "Improper Control of Generation of Code ('Code Injection')",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed-with-Review",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00521,
        "percentile": 0.41334
      },
      "nvd": {
        "published": "2026-07-31T21:17:32.440",
        "lastModified": "2026-08-03T19:16:53.307",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-68770",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "sentence-transformers treats any existing local model path as satisfying the trust gate and imports attacker-controlled Python even when trust_remote_code is false.",
        "basis": [
          "CNA",
          "CWE-94"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/huggingface/sentence-transformers/issues/3801",
          "host": "github.com",
          "sources": [
            "adp:0",
            "cna",
            "nvd"
          ],
          "tags": [
            "exploit",
            "issue-tracking"
          ]
        },
        {
          "url": "https://github.com/huggingface/sentence-transformers/pull/3807",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/huggingface/sentence-transformers",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/huggingface/sentence-transformers/commit/ae1acc3fb2aa2004577b297eb4a915ce7a03316a",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/sentence-transformers-arbitrary-code-execution-on-local-model-load-despite-trust-remote-code-false",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 859,
        "referenceCount": 5,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    },
    {
      "cve_id": "CVE-2026-68771",
      "id_year": 2026,
      "state": "PUBLISHED",
      "date_reserved": "2026-07-31T16:10:55.448Z",
      "date_published": "2026-07-31T21:16:09.970Z",
      "date_updated": "2026-08-03T17:08:03.590Z",
      "publisher": "VulnCheck",
      "title": "ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization",
      "affected": {
        "vendors": [
          "Comfy-Org"
        ],
        "products": [
          {
            "vendor": "Comfy-Org",
            "product": "ComfyUI"
          }
        ],
        "affectedBlockCount": 1,
        "versionEntryCount": 1,
        "versionRangeCount": 1,
        "defaultStatuses": [
          "affected"
        ]
      },
      "cwes": [
        {
          "id": "CWE-502",
          "name": "Deserialization of Untrusted Data",
          "abstraction": "Base",
          "status": "Draft",
          "mappingUsage": "Allowed",
          "provenance": [
            "cna",
            "nvd"
          ]
        }
      ],
      "cvss": [
        {
          "source": "cna",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        {
          "source": "cna",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "4.0",
          "score": 9.3,
          "severity": "CRITICAL",
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
          "source": "NVD:disclosure@vulncheck.com",
          "type": "Secondary",
          "version": "3.1",
          "score": 9.8,
          "severity": "CRITICAL",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        }
      ],
      "max_cvss_observed_across_sources": 9.8,
      "cvss_source_score_spread": 0.5,
      "epss": {
        "score": 0.00623,
        "percentile": 0.46464
      },
      "nvd": {
        "published": "2026-07-31T22:17:03.630",
        "lastModified": "2026-08-03T18:16:41.230",
        "vulnStatus": "Received",
        "hasConfigurations": false
      },
      "cause_review": {
        "cveId": "CVE-2026-68771",
        "family": "INTERPRETER_BOUNDARY",
        "precision": "SPECIFIC_RECORD",
        "confidence": "high",
        "mechanism": "Attacker-controlled serialized data is passed to a native object deserializer that can instantiate executable object graphs.",
        "basis": [
          "CNA record",
          "NVD",
          "CWE-502"
        ],
        "deepDive": false,
        "notes": ""
      },
      "references": [
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/pull/14543",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/Comfy-Org/ComfyUI",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://github.com/Comfy-Org/ComfyUI/commit/94ee49b1612824366a8631ea069b2a1fa5c73720",
          "host": "github.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/comfyui-unauthenticated-rce-via-loadtrainingdataset-pickle-deserialization",
          "host": "www.vulncheck.com",
          "sources": [
            "cna",
            "nvd"
          ],
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "record_shape": {
        "descriptionChars": 577,
        "referenceCount": 4,
        "cweCount": 1,
        "cnaCweCount": 1,
        "adpCweCount": 0,
        "nvdCweCount": 1,
        "cvssCount": 4,
        "affectedProductCount": 1,
        "affectedVersionEntryCount": 1
      }
    }
  ]
}
